Protecting Data Subject privacy and maintaining the integrity of Personal Data means that: The Controller will keep Personal Data and the business between the Data Subject and the Controller in confidence; The Controller will not sell, rent or loan a Data Subject’s information to third parties; The Controller will respect a Data Subject’s privacy when the Controller may contact a Data Subject concerning various products and services which the Controller make available to a Data Subject from time to time; The Controller may have control over who obtains, uses and the circumstances to give out information about a Data Subject; A Data Subject will have access to the information that the Controller has about the Data Subject.
This Policy Privacy applies to the Controller’s products, services and websites, except where otherwise noted and does not concern any websites that a Data Subject may visit by external links.
CONTROLLERS AND PROCESSORS OF PERSONAL DATA
The Controller who determines the purposes and means of Personal Data collecting and processing is Gallery Systems with registered office at 5 Hanover Square, Suite 19, New York, New York, 10004.
The processing operations of Personal Data, whether or not by automated means, are performed on behalf of the Controller by Gallery Systems.
WHY THE CONTROLLER MAY COLLECT PERSONAL DATA
Perform necessary identity and security verifications
Process transactions and conduct business
Deliver products and services
Provide customer support and services
Provide ongoing service delivery
Provide Data Subject with information
Improve products, services and service delivery
Better understand Data Subject’s needs, interests and suitability for various products and services
Recommend specific products and services that may meet Data Subject’s needs
Respond to issues, questions, and queries
Protect Data Subject and itself against errors or fraud; and
Cooperate with law enforcement and legal authorities, where required, to comply with applicable laws and with court orders.
The Controller will collect, use and may disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances; and endeavors to collect as little information as possible as may be necessary under the circumstances.
Data Subject takes note that aggregated statistics and information, where the identity of a specific individual cannot be identified, is not Personal Data. Controller reserves the right to use aggregated information in any manner it determines, in its discretion, to be appropriate. Use of such aggregated information may include, but not be limited to, the preparation of aggregated user statistics and information summaries to improve efficiencies, more effectively describe Controller’s product and service offerings, and assist in the marketing of Controller’s products and services.
Aggregated statistics and information will not contain Personal Data.
THE TYPE OF PERSONAL DATA THE CONTROLLER MAY COLLECT
Controller collects various types of Personal Data. During the course of using Controller’s Website or doing business or interacting with Controller, or receiving products and services from or through Controller, Data Subject may, depending on the nature of the circumstances, be asked to provide Controller with:
Geographic (physical) addresses
Phone numbers or other contact information
Names (first, and last or whatever the family identifying name is)
Website usage preferences
Feedback regarding business, services, website and public relations
Source IP addresses
Times and dates of access to website servers
Language • Personal preferences
Product and service preferences
Browsers types and configurations and miscellaneous administrative and computer traffic information
Certain forms of information, such as government issued or private sector issued licenses, permits, certificates, cards, in the nature of driver’s licenses, social insurance/security number, passports, insurance cards, voucher numbers, and the like, although convenient for identification, is voluntary.
It is a Data Subject’s decision whether they want to provide this, or other suitable identification, subject to any legal requirements.
HOW DOES THE CONTROLLER COLLECT PERSONAL DATA?
Using the Controller’s Website
Using the Controller’s services
In the course of communications with the Controller (face-to-face, by email, by phone, mail or otherwise) in the course of feedback to the Controller regarding the Controller’s business, services, website and publications
When registering with the Controller for services or, where relevant, accounts, or, where relevant, for the download of the Controller’s software
Customer, membership, recipient, or service lists that have been lawfully acquired from third parties
Through the completion of manual or electronic forms
Web beacons – Web beacons are small, graphic images that allows a website operator to collect certain information and monitor user activity on its website. A web beacon is a very small pixel which is invisible to the user. The Controller uses web beacons to collect information that is not of a personal nature
Clickstreaming – Clickstreaming is a technology that allows a website operator to track the paths that surfers take as they access a website and look at the site’s pages, and as they use links to other sites. The Controller collects such information from visitors to the Controller’s Website; and
Website traffic information, which is monitored and analyzed in order to determine which products, services or features may be of interest to visitors, so the Controller may improve website, products, services, features or other offerings of the Controller.
In addition, the Controller may review and analyze a Data Subject’s use of products and services, to help it serve the Data Subject better, and to bring other products and services to the Data Subject’s attention, which the Controller feels will be of benefit to the Data Subject. The Controller also collects and analyzes information from other sources for the same purposes.
HOW THE CONTROLLER MAY DISCLOSE PERSONAL INFORMATION
The Controller does not sell any Personal Data it collects to third parties. The Controller may share Personal Data with its affiliates, subsidiaries, employees, contractors, and agents in the course of providing a Data Subject with Controller’s business services, support, or the fulfillment or delivery of products or services of the Controller.
The Controller may disclose Personal Data if is required to do so to a court of competent jurisdiction, other legal or regulatory authority, or, if there is a good faith belief, and reliance on said belief that disclosure is necessary to: comply with any legal process served on the Controller; maintain, uphold or protect the Controller’ rights or property; protect and ensure the personal safety of the public or other Controller’s clients; or protect against criminal or quasi-criminal activities, or to detect, prevent, investigate allegations of, or address, misrepresentation or fraud.
The Controller reserves the right that in the event of a bankruptcy filing, mergers with third parties, acquisition by third parties, sale of assets (all or partial), or any other transfer of all or substantially all of the Controller’s relevant assets to a third party, that the Controller shall be entitled share (or sell as an ancillary aspect of the overarching business transaction) the Personal Data provided by the Data Subject to the third party.
RETENTION AND DISPOSAL
The Controller keeps information only for so long as it is needed for the efficient and effective delivery or fulfillment of the software, products, or services using or contemplating using by the Data Subject and for a reasonable time thereafter, or to meet any legal requirements. The Controller will either destroy or remove information when it is no longer needed.
SECURITY AND STORAGE
The Controller endeavors to maintain appropriate physical, procedural, and technical security with respect to its and Processor’s offices and information storage facilities so as to prevent any loss, misuse, unauthorized access, disclosure, or modification of Personal Data. This also applies to the Controller’s disposal or destruction of Personal Data.
The Controller keeps the Personal Data collected from and about Data Subject strictly confidential. Only authorized personnel have access to this Personal Data. Personnel of the Controller and Processor who have access to Personal Data receive training regarding privacy protection.
The Controller’s security specialists build security by design by default into its computer systems. The aim is to protect information at all times, when it is stored in data files or handled by the Controller’s employees. The Controller’s systems are also designed to protect information when it is transmitted, for example, between our data processing facilities and corporate offices. Personal Information may be stored or processed in any jurisdiction in which Controller or its affiliates, suppliers, subsidiaries or agents maintain facilities. By supplying the Controller with Personal Data, you consent to any transfer of this information to other jurisdictions (including countries which have not been assessed for adequacy of privacy laws).
The Controller does, and shall continue to use, industry-standard technology to maintain the security of Personal Data, and for Controller’s connections to the internet; however, the Controller cannot and does not guarantee the privacy, security, authenticity or non-corruption of any information transmitted through the internet or any for information stored in any third-party system connected to the internet.
The Controller shall not be responsible for any claims, damages, costs or losses whatsoever arising out of or in any way related to third-party connections to or use of the Internet.
The Controller shall not be responsible for events beyond its direct control, and therefore will not be liable for any direct, indirect, incidental, consequential or punitive damages relating to the uses or releases of Personal Data.
DATA SUBJECTS’ RIGHTS
Data Subjects are entitled at any time to obtain confirmation of the existence of Personal Data and to be informed of their contents and origin, to verify their accuracy, or else request that such data be supplemented, updated or rectified.
Data Subjects have the right to request erasure, anonymization or blocking of any data that is processed in breach of the law as well as to object in all cases, on legitimate grounds, to processing of the data.
The Controller is committed to protecting the safety of children. The Controller will not knowingly request or use Personal Data from children under the age of eighteen (18) without parental consent. If the Controller receives actual knowledge that it does, not knowingly or intentionally, collect any Personal Data from children under the age of eighteen (18), the Controller will take steps to have such Personal Data eliminated. The Controller’s Website is not to be used by anyone under the age of eighteen (18). Persons under the age of eighteen (18) are not authorized to use the Controller’s Website and are directed to immediately discontinue use of the Controller’s Website.
In most cases, a Data Subject will be asked to specifically express their consent of collecting and processing of Personal Data by the Controller in accordance with this Policy Privacy. Data Subjects will not be obliged to provide such consent. If a Data Subject does not consent, the Data Subject must to immediately discontinue use of the Controller’s Website and to refrain from further use.
GOVERNING LAW AND VENUE
Where the processing of Personal Data is performed in the context of the activities of the Controller and/or Processor established in European Union. This processing may be subject to EU Regulation 2016/679 and other applicable privacy laws on the protection of natural person with regard the processing of personal data and the free movement of such data, and to the relevant EU member country national law before the competent local court.
The Controller’s Website is hosted and administered in the United States.
The Controller will disclose Personal Data without the Data Subjects permission when required by law or in good faith belief that such action is necessary to investigate or protect against harmful activities to the Controller’s company, associates, or property (including this Website), or to others.
US-EU PRIVACY SHIELD FRAMEWORK
As part of its commitment to establish and maintain an adequate level of Personal Data privacy protection, Gallery Systems has further voluntarily opted to self-certify and comply to the US-EU Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries. Please visit Gallery Systems’ Privacy Shield Statement webpage for further information.