Showpad Privacy Principles
- Showpad NV / Showpad inc. (“Showpad”) operate, exploit and maintain certain SaaS Products and Services (“Products and Services”) for and on behalf of Showpad customers’ use and benefit.
- These Showpad Privacy Principles wish to explain what processing activities are taking place in respect of information relating to individuals (as being an identified or identifiable natural person) (“Personal Data”) when such individual (the “Data Subject”) is interacting, directly or indirectly (e.g. through an integration or through a software client), with the Products and Services and/or certain content of the Showpad Customer managed thereon (see FAQ B7.).
- These Showpad Privacy Principles do NOT apply in situations other than explained above, or in the specific situations where the Showpad Privacy Policy applies (showpad.com/privacy-policy).
- These Showpad Privacy Principles are always subject to i) the terms of the Agreement between Showpad and the Showpad Customer, as well, ii) the applicable polic(y)(ies) of the Showpad Customer (e.g. as being Your employer, the applicable Showpad Customer Privacy Policy, …) (“Customer Policy”) that apply to Your interaction with the Products and Services and/or certain Customer Content managed thereon (see FAQ A2.).
- Showpad may change these Privacy Principles at any time, and all such changes are effective immediately upon posting a revised version of these Privacy Principles on the Showpad website. You should review these Privacy Principles often to stay informed of changes that may affect You. Your Interactions constitute Your continuing agreement to these Privacy Principles, as they are amended from time to time.
(last update December 14, 2023)
A. General
1. Applicable data protection legislations | |||
---|---|---|---|
As a company that finds its roots in the European Union, and that considers compliance to privacy legislation a core principle of its organisation, Showpad has created these Privacy Principles based upon the foundations of the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data). As GDPR currently is the most advanced and elaborate data protection legislation in the world, Showpad uses GDPR as its main benchmark for its companywide privacy program. Seeing the global activities of Showpad, it goes without saying that with these Privacy Principles, in addition to GDPR, also want to take into account the principles of other applicable data protection laws (such as the California Consumer Privacy act of 2018, or, the Swiss Data Protection act). The principles of such other data protection legislations have either already been incorporated through GDPR (in most of the cases) or either have specifically been added to these Privacy Principles. |
|||
2. What is the aim of these Privacy Principles & relationship with the Customer Policy? | |||
These Privacy Principles are provided for convenience only and want to provide as much information as Showpad is able to provide under applicable data protection laws (e.g. sections 13/14 GDPR). Showpad is acting as “Processor” / “Service Provider” in respect of the operation of the Products and Services and not as data controller (see FAQ B12), which means that the Customer Policy shall always have priority over these Privacy Principles. In no way do these Privacy Principles or the publication thereof mean that Showpad is taking up a role as data “Controller” under these Privacy Principles or taking up additional liabilities or responsibilities than as legally applicable between a controller and processor. The publication of, or getting acceptance against, the Customer Policy (or absence thereof) occurs solely under the responsibility of the Showpad Customer. Where the Data Subject already has accepted the Customer Policy (or where such (updated) Customer Policy subsequently becomes applicable) that cover Your interaction, directly or indirectly (e.g. through an integration or through a software client), with the Products and Services and/or certain Customer Content managed thereon, the Customer Policy shall apply instead of these Privacy Principles. |
|||
3. What "Interactions" trigger these Privacy Principles to be applicable? | |||
Unless the Customer Policy applies (see FAQ A2) these Privacy Principles apply to the interactions, direct or indirect (e.g. through an integration or through a software client), that the Data Subject may have with the Products and Services and/or certain Customer Content managed thereon. These Privacy Principles are being provided under the responsibility of the Showpad Customer, who is acting as data “Controller” for the processing activities covered under these Privacy Principles (see FAQ B12). These Privacy Principles do NOT apply in situations other than explained above or in situations where the Showpad Privacy Policy applies (www.showpad.com/privacy-policy) (Showpad acting as data “Controller”, including in respect of Showpad’s use of its own Products and Services). |
B. Showpad Products and Services
1. What do the Products and Services consist of? | |||
---|---|---|---|
Showpad is offering Products and Services mainly in the field of sales enablement / guided selling that measure, analyse and report on the engagement and behaviour of individuals with content being made available to them through the Products and Services (“Customer Content”), including “Showpad Content”, “Showpad Coach”, and “MeetingIQ” (i.e. virtual human interactions for instance through online meetings). These Products and Services are offered under a “Software as a Service” model, which is a software licensing and delivery model in which software is centrally hosted and made available to multiple users over a network, including through interacting products (including front-end clients, apps, Web-Interface, plugins, or connectors to third-party applications). To the extent the Data Subject is interacting with the Products and Services (see the then current Products and Services offerings at www.showpad.com/overview), and/or the Customer Content managed thereon, the Data Subject’s engagement therewith is measured, analysed and reported back to the Showpad Customer. The aim is to provide the Showpad Customer through the Products and Services with the information, insights, analytics and tools to help the Showpad Customer to streamline and improve interactions by and between their internal collaborators (e.g. sales teams, marketing teams, …) and/or third parties (e.g. potential buyers). Except in the limited cases as explicitly stated in the Showpad Privacy Policy for which Showpad is data “Controller” (see FAQ B12), Personal Data in respect of the Products and Services is not processed for any other purpose. For avoidance of doubt, under these Privacy Principles, Showpad does NOT process the Personal Data for any other purposes than as described in this FAQ B1. |
|||
2. Does Showpad process Personal Data for other purposes than exploiting the Products and Services? | |||
Under these Privacy Principles, Showpad does NOT process the Personal Data for any other purposes than for the Products and Services (see FAQ B1) as data “Processor” on instruction and for the benefit of the Showpad Customer (as being the data “Controller”) (see FAQ B12). As Showpad is not the owner of the dataset containing the Personal Data, Showpad does NOT sell, trade or otherwise commercialise Personal Data as being processed through the Products and Services to or for the benefit of anyone else than the Showpad Customer, nor does Showpad use the Personal Data for Showpad’s direct marketing purposes. |
|||
3. What categories of Personal Data are being processed by the Products and Services? | |||
Depending on the role within the Products and Services (see FAQ B7) certain categories of Personal Data may be processed as follows:
The Products and Services process Personal Data for and on behalf of Showpad Customer. It is the Showpad Customer who is acting as data “Controller” (see FAQ B12) and therefore who determines what Personal Data of which Data Subject to process. This information is also made available to the Showpad Customer via the privacy settings within the Administrator part of the Products and Services. In case you require more input, you can contact the Showpad data protection officer via privacy@showpad.com. |
|||
4. Are the Products and Services processing regulated or so-called "sensitive” Personal Data? | |||
Seeing the scope of the Products and Services (see FAQ B1), the Products and Services are NOT intended or equipped to Process any Personal Data in respect of genetic data, biometric data, data concerning health (e.g. HIPAA regulated data) or data concerning a natural person’s sex life or sexual orientation, nor any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or such other data that the applicable data protection law indicates being “regulated” or “sensitive” (“Sensitive Personal Data”). The Showpad Customer – as being data “Controller” (see FAQ B12) – is responsible for ensuring that no such Sensitive Personal Data is being Processed through the Products and Services, or where it does, that it does so under its own assessment and responsibility. Showpad does not provide for additional means or provide additional effort in order to have Sensitive Personal Data processed through the Products and Services. |
|||
5. Are the Products and Services processing data regulated by the “PCI Security Standards Council”? | |||
Seeing the scope of the Products and Services (see FAQ B1), the Products and Services are NOT intended or equipped to Process any data that is regulated by the Payment Card Industry Security Standards Council (PCI SSC), nor do the Products and Services offer features that are subject to the Payment Card Industry Data Security Standards (PCI DSS). The Showpad Customer – as being data “Controller” (see FAQ B12) – is responsible for ensuring that no such PCI regulated data is being Processed through the Products and Services, or where it does, that it does so under its own assessment and responsibility. |
|||
6. Are the Products and Services making use of automated decision-making processes? | |||
The Products and Services are NOT intended or equipped to process Personal Data for any automated decision-making processes or techniques which create or deny rights to the Data Subject. The Showpad Customer – as being data “Controller” (see FAQ B12) – is responsible for ensuring that no automated decision-making processes or techniques are being added to the Products and Services, or where it does, that it does so under its own assessment and responsibility. |
|||
7. What Roles / interactions exist within the Products and Services? | |||
You can interact with the Products and Services through the following roles:
Each of these roles will generate their specific analytics as to the way how they interact with the Products and Services and/or Customer Content managed thereon. All roles and related user management is controlled and managed by You. |
|||
8. What about re-sharing Customer Content through the Products and Services? | |||
To the extent the Administrator – Privileged User – User enables re-sharing of Customer Content via the Products and Services by the Third-Party Data Subject, when re-sharing such Customer Content via the Products and Services with a second Third-Party Data Subject, the first Third-Party Data Subject needs to ensure:
|
|||
9. Are there third-party integrations interacting with the Products and Services? | |||
The Showpad Customer may activate or use certain integrations with third party applications, through different methods (e.g. the API of the Products and Services, iFrame, linking to third-party URL’s, …). Such integration may lead to the fact that third-party applications receive access to certain Personal Data or Customer Content either directly from the Data Subject or through the Products and Services. Such activation, implementation, combination and/or Customer Content offering occurs solely under the responsibility of the Showpad Customer and the Customer Policy. Consequently, Showpad does not take any responsibility for this. |
|||
10. Which recipients may receive access to Personal Data? | |||
Under these Privacy Principles, Personal Data of Data Subjects may be made available:
Disclosures within the functioning of the architectural set-up shall:
To the extent required as per applicable Data Protection law, Showpad shall remain responsible towards the Showpad Customer for such Sub-Processors to ensure that the processing by such Sub-Processors remain in line with the applicable data protection law. Where applicable to the Products and Services in question, Third-Party Data Subject interactions with Customer Content occurring under “Kiosk Mode” will be attributed to, and aggregated under the analytics of, the User Account linked to the “Kiosk Mode”. |
|||
11. Are the Products and Services targeted towards minors and children? | |||
The Products and Services, are typically solutions that aim at selling products, negotiating a sales transaction and/or providing learning capabilities within professional organisations. As such, the Products and Services are not aimed towards children and minors, nor should it be used for such purpose. The Products and Services do not knowingly process Personal Data of children and minors. If a parent or guardian becomes aware that his or her child has provided Personal Data that is processed by the Products and Services without their consent, he or she should contact the Showpad Customer who is the data “Controller” (see FAQ B12). |
|||
12. Is Showpad acting as Data "Processor" or Data "Controller" in respect of the Products and Services | |||
It is the Showpad Customer who:
It is therefore the Showpad Customer who legally is acting as the so-called data “Controller”. Therefore, all inquiries the Data Subject may have, or rights the Data Subject may want to exercise with regard to the processing of one’s Personal Data through the Products and Services, need to be addressed to the Showpad Customer (see FAQ E2). Should Showpad receive such request directly from a Data Subject, Showpad can legally only pass such request on to the Showpad Customer. Showpad is legally not allowed to respond to such request, unless as instructed by the Showpad Customer. Seeing the above, Showpad is only offering the means allowing the Showpad Customer to interact with the Data Subject through the Products and Services, and as Showpad is merely acting upon instructions of the Showpad Customer, this means that Showpad is processing the Data Subject’s Personal Data as a so-called data “Processor” for and on behalf of the Showpad Customer. Notwithstanding the above, in the limited cases as explicitly stated in the Showpad Privacy Policy (see FAQ A3), certain Personal Data resulting from the relationship between Showpad and the Showpad Customer, may be processed by Showpad as being the data “ Controller” (e.g. as required for Showpad as a controller to administer the (contractual) relationship between Showpad and its Customer, or, providing support). More info can be found in the Showpad Privacy Policy (Controller). |
|||
13. Do the Products and Services involve Sub-Processors? | |||
The Products and Services make use of two types of sub-processors; 1) “Core Sub-processors” and 2) “Feature dependent Sub-processors”.
To the extent required as per applicable Data Protection law, Showpad shall remain responsible towards the Showpad Customer for such Sub-Processors to ensure that the processing by such Sub-Processors remain in line with the applicable data protection law. For more information on which sub-processors are used in the Products and Services as well as the respective details of the processing activity (overview of sub-processors, location of processing, etc.), see here or see the privacy settings within the Administrator part of the Products and Services. In case you require more input on this topic, you can contact the Showpad data protection officer via privacy@showpad.com. |
|||
14. Do the Products and Services Transfer Personal Data to third countries? | |||
Showpad transfers Personal Data to third countries if and when required by:
Such disclosures shall always be limited to the Personal Data as required for the specific purpose of the recipient while taking into account the necessary provisions on confidentiality, integrity, availability and security of the data involved. In the current set-up of the Showpad organisation, such export of personal data is required to guarantee the functioning of the respective Products and Services, or to meet the contractual warranties and service levels. To the extent required as per applicable Data Protection law, where such export occurs, Showpad shall ensure that such transfer occurs under the necessary legal provisions as required by the applicable legislation. To the extent data is being (re)transferred Showpad shall ensure to that such (re)transfer occurs under such instruments as allowed per the GDPR and providing for an adequate level of protection of Your Personal Data (e.g. adequacy decision of the EU commission, binding corporate rules, or EU standard contractual clauses, …). |
|||
15. Under what legal ground is Personal Data being processed through the Products and Services? | |||
Before each Administrator’s, Privileged User’s and/or User’s Personal Data is processed, consent from those Data Subjects will be sought at the moment of creation of their account. The legal basis for processing Third-Party Data Subject’s Personal Data is dependent on the privacy setting (as determined by the Showpad Customer), for example, where processing of Third-Party Data Subject’s Personal Data uses the setting of: => Seeking prior consent from the Third-Party Data Subject:
=> Informing the Third-Party Data Subject:
In respect of EEA residents, consent is an allowed basis for the lawful processing of Personal Data (see section 6,1 (a) GDPR). Additionally, certain Personal Data is processed based on legitimate interest (e.g. see section 6,1 (f) GDPR) because: => necessary for technical reasons, e.g.:
=> used as training material for internal training purposes of the Showpad Customer, e.g.:
|
|||
16. How long is Personal Data retained on the Products and Services? | |||
Data in Showpad hosted environment (production):
Data in Showpad hosted environment (backup):
|
|||
17. Are Showpad technology providers and subprocessors vetted by Showpad? | |||
Any supplier, technology provider or subprocessor being onboarded by Showpad is subject to the Supplier review and vetting process in line with the controls of the certified Showpad information management system (ISO 27001) and privacy information management system (ISO 27701), as well as such controls being part of the Showpad SOC 2 reporting. In respect of technology providers or subprocessors that are being added to the Showpad platform stack, these are subject to the highest tier of supplier vetting by Showpad on security, privacy and compliance before being allowed by Showpad, and includes the regular re-assessment of their security, privacy and compliance posture. |
|||
18. Does the Showpad platform make use of Artificial Intelligence (AI) services | |||
Some of the Showpad services make use of artificial intelligence (AI). No AI service may be running under a third-party service or at third-party location other than as detailed here. Showpad features that make use of AI services may be using third party AI models. As Showpad is a data processor, Showpad is not allowed to share customer data with any other party outside of our subprocessing relationship. This is a principle that applies to all customer data and for all other purposes, including third party AI model training. |
C. Showpad organistion
1. What is Showpad doing in order to help its Customers comply with applicable data protection laws? | |||
---|---|---|---|
Showpad has several organisational as well as product related initiatives in that regard.
|
|||
2. What security measures are used for the Products and Services? | |||
Showpad has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident. Showpad shall thereto take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. Showpad uses industry standard encryption technologies, including application to application communication channels are TLS encrypted and data at rest is encrypted using AES 256 bits encryption. These encryption technologies are incorporated into the Showpad Product and cannot be managed by the Showpad customers themselves. While Showpad aims to implement industry-leading safeguards designed to protect Personal Data, we cannot guarantee that any Personal Data which was incidentally processed by the Showpad Customer (e.g. regulated or sensitive Personal Data, see FAQ’s B4 and B5) is maintained at levels of protection to meet specific needs or obligations the Showpad Customer may have relating to that type information. The Showpad Information security program is covered under an ISO 27001 certification (see https://www.bsigroup.com/en-GB/our-services/certification/certificate-and-client-directory/), BSI certificate n° IS653767), as well as an ISAE3402 accreditation, and is audited on a regular basis by an external audit firm. The Showpad Information security program is managed by the Showpad Information Security Team. |
|||
3. Does Showpad have a Data Processing Agreement available? | |||
To the extent the activities of the Showpad Customer are covered by the scope of an applicable data protection law, such applicable data protection law may require that the processing of the personal data by the Products and Services is covered under a data processing agreement concluded between Showpad and its Customer. Showpad thereto makes available a DPA via showpad.com/dpa that reflects the unique aspects of the Products and Services and containing all specifics – as required per the applicable data protection law – in order for the Showpad Customer to meet his legal obligations (e.g. standard contractual clauses). Where relevant or needed, the DPA shall be an integral part of the Showpad master services agreement (showpad.com/msa). |
D. Cookies
1. What are Cookies and similar technology? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
When making use of the Products and Services the following technology may be used to store information on the device you use to connect to the Products and Services (“Device”) or access information already stored on your Device:
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
2. Do the Products and Services use Cookies or similar technology? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
The Cookies/Embedded scripts/Web Beacons used within the Products and Services enables certain features and functionalities of the Products and Services. A Cookies/Embedded script/Web Beacons does not contain or collect information in isolation, but when read by a server via Your web browser or through the Products and Services, it can provide information to such server (e.g. to facilitate a more user-friendly service by registering users’ preferences, detect errors, account information, device identification, statistical data, …). The Products and Services use the following Cookies/Embedded script/Web Beacons:
Unless where otherwise indicated in the table above, these Cookies/Embedded script/Web Beacons are essential to the Products and Services, without which Showpad can’t provide the Products and Services as warranted to the Showpad Customer, or guarantee the correct functioning of the Products and Services. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
3. Can the Cookies be disabled or deleted? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Apart from the Showpad CONSENT Cookie in the Prospect microsite environment, the Cookies/Embedded scripts/Web Beacons are an inherent and essential part of the Products and Services and are necessary in order for Showpad to be able to provide for the Products and Services as warranted towards the Showpad Customer, or guarantee the correct functioning of the Products and Services. The Showpad CONSENT cookie in the Prospect microsite environment, is optional and placing this cookie on an end user Device is dependent on the applicable privacy settings as determined by the administrator of the Showpad platform at our customers. this Cookie logs whether or not consent as given by the Prospect in question to become subject to the profiling towards the Customer Content shared, and thus to allow for such profiling to take place. If consent was provided, this cookie will be placed and has a limited validity period (standardly 14 days, but can be increased to 60 days if so specifically requested from Showpad) , after which consent will be asked again to confirm continued tracking. Deleting this cookie restricts further processing of Personal Data of the Prospect in question. Deleting or disabling a Cookie can be done by using the following options:
Most web browsers (e.g. Internet Explorer, Mozilla Firefox, Safari, and Google Chrome) have cookies automatically enabled. You can decide on whether and to what extent cookies will access Your end device by changing your browser settings.
More information on cookies and the way to manage or refuse cookies per browser type (e.g. Internet Explorer, Mozilla Firefox, Chrome, Safari, …) can be found at https://www.allaboutcookies.org , https://www.aboutcookies.org or http://www.youronlinechoices.eu
Certain tools (e.g. “Ghostery”, “Disconnect”, … ) may provide you with more granular options in order to manage cookies. |
E. Rights of Data Subjects
1. What rights do Data Subjects have? | |||
---|---|---|---|
Subject to such right being entrusted by Applicable Data Protection Law, Data Subjects may have the right to:
Please check the applicable data protection legislation for the ability to exercise such rights. As Showpad is merely the data “Processor” (see FAQ B12) such rights need to be exercised towards the Showpad Customer, as being the data “Controller”. In order to exercise such rights, You may be required by the Showpad Customer to provide proof of Your identity by providing an official document (e.g. ID Card, driver’s license, …). |
|||
2. How to exercise Your rights as Data Subject? | |||
As Showpad is merely the Data “Processor” (see FAQ B12), in order to exercise Your rights (see FAQ E1), You need to contact the Showpad Customer. In order to exercise such rights, You may be required by the Showpad Customer to provide proof of Your identity by providing an official document (e.g. ID Card, driver’s license, …). Should Showpad receive such request directly from You, Showpad can legally only pass such request on to the Showpad Customer. Showpad is legally not allowed to respond to such request, unless as instructed by the Showpad Customer. |
|||
3. How does Showpad respond to a request from a Data Subject? | |||
Should Showpad receive a request directly from a Data Subject, Showpad can legally only pass such request on to the Showpad Customer. Showpad is legally not allowed to respond to such request, unless as instructed by the Showpad Customer. From the moment it is established that the Data Subject request is related to a processing activity for which the Showpad Customer is data “Controller”, and to the extent the Showpad Customer is identified, Showpad shall pass on such request without undue delay to the respective Showpad Customer, in order for the Showpad Customer to respond to such request. |
|||
4. Where to log a complaint? | |||
In case You as a Data Subject have a complaint about the way Showpad is processing Personal Data, You can always contact the Showpad DPO directly at privacy@showpad.com and we will listen to Your complaint and see if we can help You to resolve this. If You have an unresolved complaint, You always have the right to log a complaint with the competent “data protection authority”. Information on the competent data protection authority and the way of logging a complaint can be found here (or the URL as updated by the European Commission). Showpad NV, located in Belgium, acts as so-called:
As a result, the competent Data Protection Authority for Showpad NV is the Belgian DPA (Drukpersstraat 35, 1000 Brussel / +32 (0)2 274 48 00 / contact@apd-gba.be / https://www.dataprotectionauthority.be/). |
|||
5. Who can I contact if I require more information? | |||
Showpad NV, located in Belgium, is a so-called “main establishment” in the EEA under GDPR and also acts as the so-called representative in line with section 27 GDPR for and on behalf of Showpad Inc. Showpad has appointed a data protection officer for the whole Showpad Group who can be contacted at “Office of the Data Protection Officer – Showpad NV – Moutstraat 62 – 9000 Gent (Belgium)” or privacy@showpad.com. |