Last updated on October 12, 2018
Twelve South, LLC (also referred to as "we", "us", and "our") is committed to protecting the privacy and security of the personal information we receive or collect from you. We also believe in transparency and are committed to informing you about how we treat your personal information.
This Policy does not apply to information you may provide to us offline or through means other than through our Website.
PLEASE READ THIS POLICY CAREFULLY AS IT DESCRIBES OUR PRIVACY POLICIES AND PRACTICES REGARDING YOUR PERSONAL INFORMATION AND WHAT CHOICES AND RIGHTS YOU HAVE IN THIS REGARD. IF YOU DO NOT AGREE WITH THE TERMS AND CONDITIONS OF THIS POLICY, YOU SHOULD NOT ACCESS OR USE THE WEBSITE.
Who is Responsible for Your Personal Information?
Twelve South, LLC is located in Charleston, South Carolina, United States of America and we are the party responsible for your processing data through this Website. We acknowledge that we have certain responsibilities with regard to safeguarding and properly using your personal information (i.e., any information that identifies or is identifiable to a natural person) that you provide to us or we collect through our Website.
If you are accessing our Website from or are a resident of the European Union (the “EU”) or the European Economic Area (the “EEA”), Twelve South, LLC acts as the controller of the "personal data" we collect from you via our Website for purposes of the EU General Data Protection Regulation, 2016/679 (the “GDPR”).
What Information Do We Collect?
When you visit our Website, you may provide us with two types of information: personal information you individually and intentionally disclose to us and Website use information collected on an aggregate basis as you and others browse our Web site.
We may collect and process the following types of personal information from you for the purposes set forth below:
- Identity and Personal Contact. When you visit our Website or request our services, we may ask you for your name, address, telephone number, email address or other contact details in order to respond to your requests or inquiries. This includes first name, last name, username or similar identifier, title, zip code, email address, and/or telephone or cell phone number.
- User Account / Profile. When you create an account, we collect your identity and contact information, certain demographic information (location), your username and password, your relevant interests, preferences, and feedback (optional), as well as payment information, when necessary. This information enables us to provide you the account you have requested and to maintain the account and your profile. You may update your account information by editing the information associated with your account.
- Business Contact. This includes information provided in the course of the contractual or client relationship between you or your organization and us, or otherwise voluntarily provided by you or your organization in order to perform a contract or maintain the client relationship to provide services requested or agreed to by you. This may include one or more types of personal information categories listed here as well as information about your role within your organization your organization's contact information.
- Transactional. This includes details about products and services you have purchased or ordered, such as product or service type, date of transaction, and price, in addition to your user account, business, and/or identity and contact information.
- Financial and Payment. If you choose to purchase products or services from us, we request certain information necessary to authorize, process, and fulfill your purchase. This may include bank account and bank routing numbers, credit card numbers, security codes, expiration dates, and other related billing information. Different payment methods may require the collection of different categories of information. Please note that your credit card, banking, and other payment details are not stored on our servers in order to ensure your security. We use a third party payment processor, Stripe, Inc., for all payments made to us. When you transmit your credit card information to Stripe, you will select a payment method and Stripe will process your payment according to your instructions. Stripe maintains PCI compliance to securely process your cardholder data. Please refer to our Cookies Policy for more information.
- Marketing and Communications. This includes your preferences in receiving marketing from us and our third parties and your communication preferences, including how you prefer to receive our communications and the types of content you have requested.
- Cookies. When you visit our Website, we may collect cookies and use similar technologies to, among other things, provide you with a more personal and interactive experience on our Website, to improve our behavior-based advertising efforts, and for website usage analytics. This means that a third party may use technology (e.g., a cookie) to collect information about your use of our website so that they can provide advertising about products and services tailored to your interests. That advertising may appear either on our websites, or on other websites (e.g., social media platforms, search engines, etc.). See our Cookies and Similar Technologies Policy for more information.
- Email Interconnectivity. If you receive email communications from us, we may use certain tools to capture data related to when you open our messages, click on hyperlinks or banners it may contain, and make purchases. We use this information to enhance and support our marketing and sales operations.
- Job Applications and Employment. If you apply for a job through our Website, or become our employee, we collect personal information necessary to process your application or employment. This may include, among other things, your contact information, social security number, employment history, etc.
- Surveys, Questionnaires, Social Media. When you submit a survey, questionnaire, contest entry, or similar form by using the Website, social media, or other online survey tools and platforms accessible via our Website, we or third parties operating those tools, platforms, or social media websites may collect your social media handle or profile, or any other identifier that you use to be contacted online or offline. This information may also include personally identifiable and business information, but only to the extent that you voluntarily provide it to us.
- Sensitive Personal Information. We do not collect sensitive personal information from you. In the event we inadvertently receive sensitive personal information from you, without your consent or a lawful basis to store it, we will promptly delete it.
In addition to the information that we collect from you directly, we may also receive information about you from other sources, including third parties, business partners, our affiliates, or publically available sources. Please note, however, that the above list contains examples of information we may have concerning you and we do not necessarily have this information about you.
How Do We Use Your Personal Information?
Wherever possible, we seek your express consent before we collect your personal information, especially with regard to our online marketing and advertising activities. The form of consent we seek from you may vary depending on the circumstances and the type of information being requested. When determining the appropriate form of consent, we take into account the sensitivity of the personal information, the reasons we are collecting it, and your reasonable expectations.
When using personal information for a new purpose, we will document that new purpose and ask for consent again. We will not use your personal information without your consent unless it is either for the same purpose for which the information was originally collected or compiled, consistent with that purpose, or for a purpose that permits disclosure under applicable law.
In addition to the specific categories of data use previously outlined, we may with your express consent and/or under recognized legal grounds, also use your personal information for the following purposes:
- To provide you with services you have requested and to manage our relationship with you, including administering your user account, accounting, auditing, billing and collection and taking other steps necessary to the performance of our business relationship with you;
- To present and improve Website contact and functionality;
- To determine user interests, needs, and preferences;
- To provide notice of changes to our Website or the services we offer or provide through it;
- To conduct research and analysis;
- To develop new products and services;
- To manage and maintain the security of our Website and services;
- To market our services to you. We will only provide you with marketing-related information after you have, where legally required to do so, opted in to receive those communications and having provided you with the opportunity to opt-out of such communications at any time. We do not sell or distribute this information to third parties or use it for any other purpose;
- To comply with our legal and compliance obligations, including maintaining records, performing compliance audits, etc.
- For insurance purposes;
- To exercise and defend our legal rights, or to comply with court orders;
- To respond to requests from public and government authorities;
- For any other purpose related to and/or ancillary to any of the purposes and uses described in this Policy for which your personal information was provided to us;
- In any other way we may describe when you provide the information; and
- For any other purpose to which you have expressly consented.
We may process your personal information in connection with any of the purposes and uses set out in this Policy on one or more of the following legal grounds:
- because we have a necessary and legitimate interest in doing so to perform the services you have requested, to comply with your instructions or other contractual obligations between you and us;
- to comply with our legal obligations as well as to keep records of our compliance processes;
- because our legitimate interests, or those of a third party recipient of your personal information, makes the processing necessary, provided those interests are not overridden by your interests or fundamental rights and freedoms;
- because you have chosen to publish or display your personal information on a public area of the Website, such as blog or comment area;
- because it is necessary to protect your vital interests;
- because it is necessary in the public interest; or
- because you have expressly given us your consent to process your personal information in a particular manner.
We do not use your personal information for making any automated decisions affecting or creating profiles other than as described above.
Disclosure of Your Personal Information
We do not sell, rent, or lease your personally identifiable or business information to third parties. We may, however, disclose your personal data in the following contexts:
- Disclosures without your consent. We may disclose your personal data in response to subpoenas, warrants, court orders or other legal process, or to comply with relevant laws or regulatory investigations when we believe in good faith that applicable law requires it. We may also share your personal data in order to establish or exercise our legal rights, to defend against a legal claim, to investigate, prevent, enforce, or take other action regarding possible illegal activities, suspected fraud, threats to the safety of person or property, or a violation of our terms, policies, or agreements, and to collect amounts lawfully owed to us.
- Disclosures with your consent. We may ask if you would like us to share your personal information with other unaffiliated third parties who are not described elsewhere in this Policy. We will only disclose your personal information in this context with your specific and express consent.
- Job applications and employment. If you apply for a job with us, we may disclose personal information necessary to process your application or employment. This may include, among other things, your contact information, your social security number, employment history, etc. in accordance with applicable law.
- Third party support. If you provide us with feedback, contact us for support, or ask us questions via web form, telephone, email, or other method allowed by our Services, we will collect and may disclose your name, email address, other contact information and other information to third parties as needed to respond to your feedback, request for support, or answer your question.
- Employees, business affiliates, and intermediaries. We disclose your personally identifiable information to our affiliates, subsidiaries, or divisions and their respective officers, directors, employees, accountants, attorneys, and agents, or with our business partners, all of whom are bound by all of the confidentiality and other data processing protections and practices described in this Policy, use your information strictly to carry out their job duties on a need-to-know basis, and only do so as required by law and as required by our legitimate interests.
- Mailing list and newsletters. When you sign up for one of our mailing lists or newsletters, we disclose your contact information, including your name, company name, email address, postal address, and telephone, as necessary to complete and process your sign up and manage your subscription.
- Service Providers. Our Website is developed and supported by third party vendors, who may, in the course of performing such services for us (such as hosting, developing, or updating our website), have access to your personally identifiable information. We contractually require such vendors to maintain the confidentiality of your information, and take appropriate measures to keep it secure. We prohibit such vendors from using or disclosing your information for any purpose other than in performing specific services requested by us on your behalf, to administer our Website, or to comply with applicable law. We also may use Service Providers to help us administer and provide services or products requested by you as well as provide technical support, send marketing and promotions and communicate with you about our products and services, resolve payment and delivery processing issues, and other legitimate purposes permitted by law.
- Corporate change. We may sell, transfer or otherwise share some or all of our assets in connection with a merger, reorganization or sale of assets, or in the event of bankruptcy, without your permission. In such an event, personally identifiable information may among the assets transferred.
- Aggregated data. We may disclose aggregated information about you to third parties (including, without limitation, advertisers, media, and actual or potential partners or investors) for informational, new product development, marketing, and/or promotional purposes, without seeking additional consent from you, when such aggregated information does not identify you or any specific individual, as is the case with groupings of demographic data and customer preferences.
How Long Do We Store Your Personal Information?
We will retain your personal information as needed to fulfill the purposes for which it was collected. We will retain and use your personal information as long as necessary to comply with our business requirements, legal obligations, resolve disputes, protect our assets, provide our services, and enforce our agreements.
When we no longer have a purpose to retain your personal information, we will securely destroy your personal information in accordance with applicable law and our policies. We take reasonable steps to delete the personal information we collect if your registration to use our Website lapses and you opt out of receiving further communications from us, or if you ask us to delete your information, unless we determine that doing so would violate our existing, legitimate legal, regulatory, dispute resolution, contractual, or similar obligations. We may retain and use anonymous and aggregated information for performance reporting, benchmarking, and analytic purposes and for product and service improvement.
Responding to Your Personal Information Requests
We use commercially respond efforts to respond to all legitimate requests related to our processing of personal information within one month, unless a faster response is required by law. It also could take us longer than a month if your request is particularly complex or you have made a number of requests. In such cases, we will notify you and keep you updated.
There may be circumstances in which we need to ask you for more information to identify your account and verify your identity or else we may be unable to provide you with access to your personal information, including, but not limited to: where the information contains legal privilege, would compromise others’ privacy or other legitimate rights, where the burden or expense of providing access would be disproportionate to the risks to the Individual’s privacy in the case in question or where it is commercially proprietary. If we determine that access should be restricted in any particular instance, we will provide you with an explanation of why that determination has been made and contact information to address any further inquiries you may have.
The timeframes described here do not apply to our response times for addressing ordinary customer service and support requests unrelated to the exercise of personal information access rights.
Security of Your Personal Information
We maintain appropriate technical and organizational measures to prevent your personal information under our control from being accidentally lost, used or accessed in an unauthorized manner, altered or disclosed during collection, storage, and processing. The particular safeguards used to protect personal information depend on the sensitivity of the personal information, the amount, distribution and format of the information, and the method of storage.
By using the Service or providing personal information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Service. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice within the Service. Access to your account and personal data and information is restricted within our organization to employees and trusted partners that need access to your personal information in order to correspond with you and provide the products and/or services that you requested from us.
While our security measures seek to protect your personal information in our possession, no security system is perfect and we cannot guarantee that your personal information will remain absolutely secure in all circumstances or that any privacy settings or security measures used in connection with the Services cannot be circumvented. Therefore, we cannot guarantee that unauthorized third parties will not be able to circumvent those measures or other safeguards in use, or access and/or use your personal information for improper purposes.
The majority of communications on our Services, including any submissions through available forms, are sent through the standard HTTP protocol and may be delivered using regular e-mail. Information sent over HTTP is not encrypted. E-mail, while convenient, does pose some risks (e.g., e-mail is not a secure form of communication, is unreliable, can be forwarded, etc.). Any transmission of information that you make through our Services is at your own risk.
The safety and security of your personal information also depends on you. Where you use a password for access to restricted parts of the Services, you are responsible for keeping the password confidential. Do not share your password with anyone else. If a security breach causes an unauthorized intrusion into our Services or systems that compromises your data, we will notify you and any applicable regulator when we are required to do so by applicable law.
Updating Your Personal Information
If any of the personal information you have provided to us changes, please let us know. For instance, if your email changes, you wish to cancel any request you have made of us, or if you become aware of inaccurate personal information about you, please contact us to update your information. You may also edit your account details if you have a user account through our Services.
We are not responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.
Your Rights To Access And Control Your Personal Data
Absent exceptional circumstances, we offer you reasonable access to and control over your personal data at any time, at no charge. Please inform your of your rights by reviewing the list below. You may use the "Contact Us" details at the end of this Policy to exercise your rights and choices.
Right of Access. You have the right to request a copy of the personal data that we hold about you, as well as inquire about the origin, recipients, and purposes of that data. There are certain exceptions to this right, however, so that we may deny access to you as required by law or to protect the legal rights of others.
Right to Portability. You have the right to request that some of your personal data is provided to you or an authorized third party in a commonly-used, machine-readable format. You can request a download of your account information.
Accuracy. Our goal is to keep your personal information accurate, current and complete. Please contact us if you believe your information is not accurate or changes.
Right to Object. In certain circumstances, as permitted under applicable law, you have the right to object to processing of your personal information and to ask us to erase or restrict our use of your personal information. If you would like us to stop using your personal information, please contact us and we will let you know if are able to agree to your request.
Right to Erasure and Deletion of Your Personal Information. You may have a legal right (for instance, if you are located in the EU or EEA under the GDPR) to request that we delete your personal information when it is no longer necessary for the purposes for which it was collected, or when, among other things, your personal information has been unlawfully processed. We also may decide to delete your personal information if we believe it is incomplete, inaccurate or that our continued storage of your personal information is contrary to our legal obligations or business objectives. When we delete personal information, it will be removed from our active servers and databases and our Website, as applicable, but it may remain in our archive if it is not practical or possible to delete it. We may also retain your personal information as needed to comply with our legal obligations, resolve disputes, or enforce any agreements with you.
Right to Withdraw Consent. If you have provided your consent to the collection, processing and transfer of your personal information, you have the right to fully or partially withdraw your consent. To withdraw your consent, please notify us as well as follow the opt-out links available in the marketing communications sent to you.
Once we have received notice that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there are compelling legitimate grounds for further processing that override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims. Withdrawal of consent to receive marketing communications will not affect the processing of personal information for the provision of our services.
Right to Complain. If you believe that your rights relating to your personal information have been violated, you have a right to lodge a complaint with the applicable supervisory authority, or seek a remedy through the courts. We would, however, appreciate the chance to deal with your concerns before you submit a complaint to a third party, so please consider contacting us in the first instance. You may lodge a complaint with us by contacting us using the information provided in the "Contact Us" section of this Policy.
Online Tracking. We do not currently respond to browser "Do Not Track" signals as they apply a standard that remains under development.
California Residents. California Civil Code Section § 1798.83 permits users of the Services who are California residents to request certain information regarding our disclosure of personally identifiable information to third parties for their direct marketing purposes. If you are a California resident and would like a copy of such notice, please contact ususing the information provided in the "Contact Us" section of this Policy. Please note that we do not share personal information with third parties for their direct marketing purposes.
European Union or European Economic Area Residents. If you are located in the EU or EEA and believe we have not processed your personal information in accordance with applicable provisions of the EU GDPR, you may lodge a complaint with your local data protection or supervisory authority.
International Transfers of Personal Information. We arelocated and established in the United States and, therefore, your personal information may be transferred to, stored or processed in the United States. While the data protection, privacy and other laws of the United States might not be as comprehensive as those in your country, we take necessary and appropriate steps to protect the privacy and security and privacy of your personal information. By using our Website or requesting services or products from us, you understand and consent to the collection, storage, processing and transfer of your information to our facilities in the United States and those third parties with whom we share it as described in this Policy.
Residents of the EU / EEA. We rely on recognized legal bases to lawfully conduct cross-border transfers of personal information outside of the European Union (EU) and European Economic Area (EEA), such as your express informed consent (as noted above), when transfer is necessary for us to deliver services pursuant to an agreement or contract for services between us and you, or when the transfer is subject to safeguards that assure the protection of your personal information, such as the European Commission's approved standard contractual clauses.
Other Website Privacy Practices and Terms
Links To Third Party and Other Websites and Services. The Services may contain links to, and media and other content from, third party websites or services. These links are to external websites and services of third parties over which we have no control. If you click on an embedded third-party link, you will be redirected away from the Services to the external third-party website. You can check the URL to confirm whether you have been redirected away from our Services.
We cannot and do not (i) guarantee the adequacy of privacy, security, practice content or media provided by third parties or their websites, (ii) control third parties' independent collection or use or your personal information, or (iii) endorse any third party information, products, services or websites that may be reached through embedded links contained in the Services.
Protecting Children. The Children's Online Privacy Protection Act ("COPPA"), as well as other data privacy regulations, restrict the collection, use, or disclosure of personal information from and about children on the internet. Our Services are not directed to children aged 18 or younger, nor is information knowingly collected from children under the age of 18. No one under the age of 18 may access, browse, or use the Services or provide any information to or on the Services. If we learn that we have collected any personal information from children under 18 (and in certain jurisdictions under the age of 16) without a parent's or legal guardian's consent, we will promptly take steps to delete such information and terminate the child’s account.
For more information about COPPA, please visit the Federal Trade Commission's website at: https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule.
Opting Out of Email Communications. You have the right to opt out of certain uses and disclosures of your personal information. If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt-out of receiving future emails of that type. We will process your request within a reasonable time after receipt. Note that you will continue to receive transaction-related emails regarding products or services you have requested and you will not be able to opt out of those communications (e.g., communications regarding important updates to this Policy) unless you delete your entire user profile.
Changes To Our Policy. We reserve the right, in our sole discretion, to update, change, modify, add or remove portions of this Policy from time to time. If we make material changes to how we treat our users’ personal information, we will post the new Policy on this page with a notice that an update has occurred and notify you at the email address specified in your account or use an in-app alert the first time you use the mobile application after we make the change. You are responsible for providing us with an active, up-to-date, and deliverable email address for contacting you. It also is your responsibility to carefully review this Policy prior to using the Services and from time to time so you are aware of any changes. The date this Policy was last revised is identified in its header.
Governing Law. This Policy and any disputes related thereto shall be governed by and construed in accordance with the laws of the State of California, exclusive of its choice of law rules.
Contact Us. If you have questions or comments about this Policy, wish to access personal information we hold about you, believe the personal information we have about you is incorrect, or wish to lodge a complaint with us about how we have handled your personal information, please use the contact details below and we will do our best to assist you:
Twelve South, LLC