Terms of Service, Privacy Policy and Compliance
Privacy Policy
1. Purpose
PFL Tech, Inc. (collectively, “PFL”, “we” or “us”) respects the privacy of its customers and business partners. The PFL Notice of Privacy Practices (the “Privacy Statement”) describes the information that we collect, how we obtain and store the information, and the ways we may use or share that information. This Privacy Statement also describes the measures we take to protect the security of the information and how we can be contacted about the information we collect from or about you.
2. Scope
This Privacy Statement only covers our privacy practices with respect to the collection, use, storage, and sharing of information obtained: (i) through the PFL websites (collectively, our “Website”), Customer Service, or marketing and sales initiatives; (ii) through the use of our hosted software applications (the “Subscription Services”) and related support services (“Support Services”) that we provide to Customers. In this Privacy Statement, the Subscription Services and the Support Services are collectively referred to as the “Services.”
3. Definitions
5. Third Party Websites and Applications
PFL may link to websites that are not owned or controlled by PFL. As such, this Privacy Statement does not apply to information collected when visiting any third-party site or by any third-party application that may link to or be accessible from the PFL website or Services. You should be aware that any information you provide to these sites may be read, collected, and used by others who access them. We cannot control the actions of other users of the sites with whom you may choose to share your User Data. Your interactions with these sites are governed by the privacy policy of the organization providing the site or service. This Privacy Statement also does not cover the use or disclosure of any information stored in the Subscription Service when hosted by the Customer.
6. California Privacy Rights
California Consumer Privacy Act (“CCPA”) – If you are a California resident and the processing of personal information about you is subject to the CCPA, you have certain rights with respect to that information:
7. European Data Protection Rights
If processing of your personal information is subject to European Union data protection law, you have certain rights with respect to that data:
- You can request access to, and rectification or erasure of, personal data;
- If any automated processing of personal data is based on your consent or a contract with you, you have a right to transfer or receive a copy of the personal data in a usable and portable format;
- If the processing of personal data is based on your consent, you can withdraw consent at any time for future processing;
- You can to object to, or obtain a restriction of, the processing of personal data under certain circumstances; and
- For residents of France, you can send us specific instructions regarding the use of your data after your death.
To make such requests, please refer to the below.
When we are processing data on behalf of another party that is the “data controller,” you should direct your request to that party.
8. Communication Preferences and Choices
If processing of your personal information is subject to European Union data protection law, you have certain rights with respect to that data:
We provide certain choices regarding the information Visitors provide to us. We have created some mechanisms to provide you with control over your information when using our Website. First, if you do not wish to have your e-mail address used for promotional purposes by PFL, you may withdraw consent at a later time by contacting PFLTrust@PFL.com.
Second, you may contact PFLTrust@PFL.com
to request changes to any personal information that you have provided to us in connection with the Website or Services. We will use reasonable efforts within the scope of our business and technology practices to respond to such requests for correction or updates to personal information.
9. Customer Data
We may use Customer Data to provide the Services, including updating and maintaining the Subscription Services and providing Support Services. Notwithstanding anything else to the contrary in this Privacy Statement, we will not use, disclose, review, share, distribute, transfer or reference any Customer Data except as permitted in the Customer Agreement or as required by law.
10. Retention of Personal Information
We retain personal information for as long as necessary to provide PFL Services, comply with our legal obligations, resolve disputes, enforce our agreements, and other legitimate and lawful business purposes. Because these needs can vary for different data types in the context of different products, actual retention periods can vary significantly based on criteria such as user expectations or consent, the sensitivity of the data, the availability of automated controls that enable users to delete data, and our legal or contractual obligations.
11. Location of Personal Information
The personal information we collect is stored and processed in the United States, except as otherwise permitted in the Customer Agreement for PFL to process information in a country or region outside of the United States. We take steps designed to ensure that the data we collect under this Policy is processed according to the provisions of this Policy and applicable law wherever the data is located.
In the event we transfer personal data from the European Economic Area and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level of data protection, we use a variety of legal mechanisms, including contracts, to help ensure your rights and protections. To learn more about the European Commission’s decisions on the adequacy of personal data protections, please visit: https://commission.europa.eu/law/law-topic/data-protection_en
12. Security of Personal Information
Safeguarding personal information is important to us and PFL uses industry standard procedures and processes to protect the personal information obtained through the Website and in connection with the Services. While no systems, applications, or websites are 100% secure, we take reasonable and appropriate steps to help protect personal information from unauthorized access, use, disclosure, alteration, and destruction.
13. Changes to Our Privacy Statement
PFL reserves the right to update or change this Privacy Statement when necessary to reflect changes in our Services, how we use personal information, or changes to the applicable laws. Any updates or changes to this Privacy Statement will be posted to the home page and it is the sole responsibility of the Customer, Visitor, or User to review this Privacy Statement frequently. If we make material changes to this policy, we will attempt to notify you of such change on our home page prior to the change becoming effective. Your continued use of the Website or Services is deemed to be acceptance of all updates or changes we make to this Privacy Statement and as such, we ask that you review the Privacy Statement periodically for any updates or changes that we may have made.
14. Contact Information
To inquire or comment about this Privacy Statement and our privacy practices or if you need to update, change or remove your information, contact us at:
PFL Tech, Inc
Attn: Privacy Officer
100 PFL Way
Livingston, MT 59047
www.pfl.com
1-800-930-5088
Updates as of July 2021
PFLTrust Compliance Information
GDPR Statement of Compliance
Introduction
The General Data Protection Regulation (“GDPR”), which will become enforceable on May 25th, 2018, aims to strengthen the security and protection of personal data in the European Union (“EU”). This rule clarifies how the EU personal data laws apply even beyond the borders of the EU and will replace the European Privacy Directive and national legislations accordingly. Any organization that works with EU residents’ personal data in any manner has obligations to protect the data. PFL Tech, Inc. (“PFL”) is well aware of its role in providing the right tools and processes to support its users and customers in order to meet their GDPR mandates.
PFL’s Commitment
At PFL, we have demonstrated our commitment to data privacy and protection by meeting the industry standards for PCI, HIPAA, SOC 1 and SOC 2. We recognize that the GDPR will help us move towards the highest standards of operations in protecting customer data and PFL attests that we will comply with applicable GDPR regulations as a data processor by the May 25th, 2018 enforcement date.
PFL GDPR Roles and Employees
PFL has designated Casey Bartz, Chief Technology Officer, as our Data Protection Officer (DPO) and has a dedicated internal team of cross-functional stakeholders to develop and implement our roadmap for GDPR compliance. The team is responsible for promoting awareness of the GDPR across the organization, assessing our GDPR readiness, identifying any gap areas and implementing the new policies, procedures and measures. PFL understands that continuous employee awareness and understanding is vital to the continued compliance of the GDPR. We have incorporated GDPR specific content to PFL’s onboarding and annual employee training programs.
PFL GDPR Readiness
Our readiness initiatives include:
- Designating data privacy roles;
- Building on existing security policies, processes and controls;
- Providing visibility and transparency;
- Enhancing data integrity and security;
- Portability and transferability of data;
- Identifying personal data;
- Encrypting, anonymizing or deleting user data; and
- Creating provisions for data subject’s rights.
PFL Users and Customers
Compliance with the GDPR requires a partnership between PFL and our users and customers in their use of applicable PFL services. In this context, PFL will act as a data processor and our users and customers will act as data controllers. Working together, we hope to explore opportunities within our relevant service offerings to support our users and customers in meeting their GDPR obligations. PFL encourages partners and customers to independently familiarize themselves with the GDPR. Please direct questions or comments regarding PFL’s data privacy program to
GDPR or CCPA Data Request Form
Request a copy of the data that we have stored about you or request that your data be removed from our system.