TEAMSTACK.AI CORP.

Privacy Policy

Last updated: January 24, 2024

Teamstack.Ai Corp. ( Teamstack , we , us or our ) is committed to protecting Your privacy. This Privacy Policy applies to information that we collect on the website at www.teamstack.ai ( Website or Site ) and through our product or application at tsp.teamstack.ai ( Application ), as well as in email, text, and other communications between You and us.

This Privacy Policy describes the information that we collect (directly or indirectly) and why we collect it, what we do with the information we collect and how you can manage your Personal Information (defined below). You may download a copy of this Privacy Policy here.

This Privacy Policy does not apply to data that our Customers use in their business or how our Customer use data that they collect.

Please read this Privacy Policy carefully to understand our policies and practices regarding our treatment of Personal Information. If You do not agree with our practices as described in this Privacy Policy, please contact us with any questions, and please do not access or use our Services, our Site, or any other aspect of our business.

1.               Overview

 

Please be aware that the Application is hosted on servers in the United States and the Site is hosted in India. If you are located outside of the United States, information we collect may be processed and stored in the United States or India, which may not offer the same level of privacy protection as the country where you reside or are a citizen. By using the Services and providing information to us, you consent to the transfer to and processing of the information in the United States and India.

If you provide Personal Information to our platform solutions (suite of services), we shall process this information as a data processor on behalf of our Customers. Unless Teamstack uses some of this information for marketing or business purposes (e.g. metrics), in such case, we shall be considered the data controller. Additionally, Teamstack is the controller of the Personal Information we collect through the Site. Teamstack is the processor of information input into the Application by our Customers and their Users. Any questions or concerns regarding our privacy and data protection practices can be directed to us. See the Contact Us section below.

2.               Definitions

The following terms have the following meanings for purposes of this Privacy Policy:

       Application means the Team Success Predictor platform owned and provided by Teamstack as cloud services at tsp.teamstack.ai.

       Customer means a business that contracts with Teamstack for our cloud services.

       Personal Information means information or data that directly or indirectly identifies, describes, relates to or is reasonably capable of being associated with or linked to a particular individual, consumer or household. Personal Information includes sensitive Personal Information or personal data as defined under applicable data protection laws and regulations.

       Services means:

o   our sale and provision of cloud services and the Application;

o   our performance of professional services, if any;

o   the information provided by us through our Site;

o   our marketing and business development activities, including any social media properties we create and emails that we send (collectively, Marketing Activities ); and

o   all other online services, publications and activities owned, controlled or otherwise made available or performed by us.

       User means Customer's employees and contractors who are authorized by Customer to use the Application in accordance with this Agreement and have been supplied user identifications and/or passwords in accordance with this Agreement.

       You means an individual whose Personal Information Teamstack collects, uses, shares or otherwise processes as more fully set forth in this Privacy Policy, including without limitation:

o   an employee or contractor of one of our actual or prospective Customers;

o   a user or recipient of beneficial use of our Services; or

o   a visitor to our Site.

 

3.               Information we Collect and How we Collect it

We collect information, which may be considered Personal Information when maintained in an identifiable format. The applicable Personal Information is also summarized in Annex 1 below. Below are some examples of the Personal Information we may collect through the Services:

We may link together different types of information or link information to Personal Information. If linked information directly or indirectly identifies an individual person, we treat the linked information as Personal Information. In this Privacy Policy, to process Personal Information means to perform any operation on Personal Information, whether or not by automated means, such as collection, recording, organizing, storing, adapting, use, disclosure, combining, erasing or destroying. Where we need to collect Personal Information by law, or under the terms of the contract between us and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with Services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case.

       Account registration Information of Customers and Users: When our Customers use Teamstack s cloud services, Customer personnel may create accounts, which may include a contact person s name, account log-in credentials, email address, phone number, company, job title, and other similar identifying information.

       Content and information submitted through the Services: When a user accesses or receives the Services, the user may provide information to us in connection with their use of such Services, such as their age range, ethnicity, gender, job title and other information that may include the name of other members on a team for a given project.

       Content and information submitted through the Site: When a user participates in interactive features on the Site, if any, the user may provide information to us, including without limitation through submission of contact us forms, customer support tickets or other forms.

       Communications: When You communicate with us (via email, phone, through the Services or Site, or otherwise), we may maintain a record of Your communication.

       Business contact information: We may collect or receive contact information about personnel of actual and prospective customers, vendors, contractors, business partners and other similar third parties, which may include full name, email address, phone number, company, job title, and other similar identifying information.

       Payment information of Customers: When a Customer purchases Services, we may receive, process and retain payment information relating to the transaction. We may also utilize third-party payment processors who may provide us with part or all of the applicable payment information.

       Actual and prospective employees of Teamstack: When an individual applies for employment with Teamstack, or becomes an employee of Teamstack, we collect information relating to that individual s contact details, suitability for employment, background, employment history, salary and payment details, and other similar information.

       Information collected from third parties or public sources: We may receive information from third-party sources, such as business partners, marketing service providers, third-party data aggregators, or publicly available sources, in order to make our own information more accurate and useful. Such information may include an individual s full name, email address, phone number, company, job title and other contact information.

Information we Collect Through Automatic Data Collection Technologies

       Automated technical usage data: When a user accesses the Services or the Site, we automatically generate and retain records of how the user interacts with the Services and Site. Our vendors, Google Analytics and HotJAR, collect information which may include Your IP address, device identifiers, device information (such as operating system type or browser type), cookies, referring and exit pages and URLs, interaction information (such as clickstream data), domain names, pages viewed, crash data, and other similar technical data, which they provide to Teamstack in anonymized form. We may use technologies such as cookies and/or scripts to collect this information. Please see the Cookies Notice section below for further information.

       Location information: We may receive information about an individual s approximate physical location, such as city and country, when they provide such information to us or as determined based on the individual s IP address.

 

4.               Cookies Notice

We use cookies and related technologies ( Cookies ) to provide the Services, gather information when users navigate through the Site to enhance and personalize the experience, to understand usage patterns, and to improve the Services, and the Site.

What are cookies and why are cookies used: Cookies are small text files containing a unique string of characters that are stored in Your web browser s memory when You visit a website. When You return to a website that has placed a cookie in Your browser, the cookie allows a website provider to recognize that You have visited the site before.

Cookies on our Site fall into the following categories:

5.               Purposes and Legal Bases for Use of Personal Information

We use the Personal Information we collect for our legitimate business interests, which include the following purposes:

Purposes of Processing (see above)

Legal Bases of Processing

Providing the Services and Site

       Our legitimate business interests

       Where necessary to enter into or perform a contract with You (upon Your request, or as necessary to make the Services available)

       Compliance with law

       As necessary to establish, exercise and defend legal claims

Performing contractual obligations

       Our legitimate business interests

       Where necessary to enter into or perform a contract with You (upon Your request, or as necessary to make the Services available)

       Compliance with law

       As necessary to establish, exercise and defend legal claims

Sales and business engagement

       Our legitimate business interests

       Where necessary to enter into or perform a contract with You (upon Your request, or as necessary to make the Services available)

       Compliance with law

       As necessary to establish, exercise and defend legal claims

Personalization

       Our legitimate business interests

Marketing and promotions

       Our legitimate business interests

       With Your consent

Analytics and development

       Our legitimate business interests

Compliance

       Our legitimate business interests

       Compliance with law

       As necessary to establish, exercise and defend legal claims

Business and legal operations

       Our legitimate business interests

       Compliance with law

       As necessary to establish, exercise and defend legal claims

Prevent misuse

       Our legitimate business interests

       Compliance with law

       As necessary to establish, exercise and defend legal claims

See European Economic Area, United Kingdom and Switzerland Residents Privacy Rights for more information.

We also collect and process other types of information and data which does not constitute Personal Information. For example, we may de-identify and aggregate certain Personal Information we collect such that the information no longer identifies, and cannot any longer reasonably be linked to, a particular user or individual. We may use this information to improve our Services and Site, to analyze trends, to create market research, and for other development, marketing, research and statistical purposes, and we may disclose such de-identified information to third parties for these purposes.

6.               How we Disclose Personal Information

Our Services may disclose Personal Information of individual employees or contractors who participate in using the Services to their respective employers. We may disclose Personal Information to a third party for our business purposes. We only make these business purpose disclosures under written contracts that are consistent with our own Customer agreements, requiring the recipient to keep the Personal Information confidential, and prohibit using the disclosed information for any other purpose except performing the Services and the third-party contract. Teamstack may disclose Personal Information for a business purpose to the following categories of third parties:

We may disclose de-identified or aggregated information that does not identify any individual (and therefore is not deemed to be Personal Information) without restriction.

7.               Data Security

We have implemented privacy and security measures appropriate to preserve Personal Information from loss, misuse, unauthorized access, disclosure, alteration and destruction. We use a self-assessment approach to ensure compliance with our privacy statements and verify periodically that our statements regarding our handling and use of Personal Information are accurate and reasonably complete in regard to the information covered. Although we work hard to protect Your Personal Information, we cannot guarantee the security of any information You choose to transmit to us through the Services, online forms and applications, chat rooms, or other such mechanisms, and You do so at Your own risk. Please note that email is considered a non-encrypted (and therefore nonsecure) form of communication, and it can be accessed and viewed by others without Your knowledge and permission. For that reason, to protect Your privacy, please do not use email to communicate information that You consider confidential. Unfortunately, no data transmission or storage system can be guaranteed to be secure at all times. If You have reason to believe that Your interaction with us is no longer secure, please immediately notify us in accordance with the How to Contact Us section below. In accordance with applicable law, we will let You know promptly if a breach occurs that we determine may have compromised the privacy or security of Your Personal Information.

We are not responsible for any outcome if You circumvent any privacy settings or security measures. When applicable, You are responsible for choosing a password of appropriate strength, not reusing passwords used on other websites, and keeping Your password confidential. Teamstack employees will never ask for Your password, and You should never share it with anyone.

8.               Retention of Personal Information

We will retain Your Personal Information for the period necessary to fulfill the purposes outlined in this Privacy Policy and in order to provide the Services, and for as long as Your account is active or as needed to provide Services. We will also retain Your Personal Information to comply with our legal obligations, to conduct audits, resolve disputes, and enforce our agreements.

All Personal Information we retain will be subject to this Privacy Policy and our internal retention guidelines. Teamstack will delete Your Personal Information when it is no longer required for the above-mentioned purposes. If You have a question about a specific retention period for certain types of Personal Information we process about You, please contact us in accordance with the How to Contact Us" section below.

9.               Minor s Privacy

The Services and the Site are only intended for individuals who are at least 16 years of age and we do not knowingly encourage or solicit users of the Services who are under the age of 16 or knowingly collect Personal Information from anyone under the age of 16 without parental fiduciary consent. If we learn we have collected or received Personal Information from a child under 16 without verification of parental consent, we will delete that information. If You believe we might have any information from or about a child under 16, please contact us in accordance with the How to Contact Us" section below.

California Minors: If you are a California resident who is under the age of 18 and you are unable to remove publicly-available content that you have submitted to us, you may request removal by contacting us at the Contact Us information below. When requesting removal, you must be specific about the information you want removed and provide us with specific information, such as the URL for each page where the information was entered, so that we can find it. We are not required to remove any content or information that: (1) federal or state law requires us or a third party to maintain; (2) was not posted by you; (3) is anonymized so that you cannot be identified; (4) you don t follow our instructions for removing or requesting removal; or (5) you received compensation or other consideration for providing the content or information. Removal of your content or information from the Service does not ensure complete or comprehensive removal of that content or information from our systems or the systems of our service providers. We are not required to delete the content or information posted by you; our obligations under California law are satisfied so long as we anonymize the content or information or render it invisible to other users and the public.

10.            Email Marketing

We may periodically send You relevant alerts and newsletters by email, including for the following purposes:

You may opt out of or withdraw Your consent to receive direct marketing emails from us at any time. Instructions on how to unsubscribe from relevant alerts and newsletters are included in each email, or You may opt out or withdraw Your consent by contacting us; please see the How to Contact Us section below.

11.            Your Personal Information Choices

If you are an individual User of the Application, please contact your employer about your Personal Information. If you are a Customer of Teamstack s, we will cooperate with you in responding to a verifiable consumer request regarding how such consumer s Personal Information is used and shared. To the extent that the CCPA/CPRA applies to Teamstack, it will respond directly to the consumer. In addition to the rights specified in this section, under applicable law You may have additional or more specific rights, which we will respect. You have the right to:

Account Information: If You have an account with our hosted Services, You may update or correct Your account information at any time by contacting us at support@teamstack.ai.

We may retain certain information, including cached or archived copies, as required by law or for legitimate business purposes.

How to Control Cookies:

       You can review Your Internet browser settings, typically under the sections Preferences, Help or Internet Options, to exercise choices You have for certain Cookies. If You choose to block all cookies, You may not have access to our Site, our Services will not function as intended, and You will not be able to log in. If You have blocked all cookies and wish to make full use of the features and Services we offer, we recommend enabling at least first-party cookies. Rather than blocking all cookies, You can choose to block only third-party cookies. This will allow the Services to function as intended.

       To learn more about the use of Cookies by Google for analytics, please see https://policies.google.com/technologies/cookies. To exercise choice regarding those Cookies, please see the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout. The opt-outs described above are device- and browser-specific and may not work on all devices.

Certain Exceptions to Deletion Request Rights: If you are an individual User of the Application, please contact your employer about your Personal Information. You have the right to request that we delete any of Your Personal Information that we have collected from You and retained, subject to certain exceptions. Once we receive and confirm Your verifiable request, we will delete (and direct our service providers to delete) Your Personal Information from our records, unless an exception applies. We may deny Your deletion request, including where retaining the information is necessary for us or our service provider(s) to do the following (where permitted under applicable law):

Exercising Access and Deletion Rights:

Teamstack processes data in their platform solutions on behalf of its Customers. End users of our Services may request access to their Personal Information or correct an error or omission in their Personal Information by contacting the data controller or their employer. Unless Teamstack uses some of this information for marketing or business purposes (e.g. metrics), in such case, Teamstack shall be considered the data controller and you may request access to your Personal Information or correct an error or omission in your Personal Information by contacting us as provided in the Contact Us Section below.

We will make good faith efforts to resolve requests to correct inaccurate information except where the request is unreasonable, requires disproportionate technical effort or expense, jeopardizes the privacy of others, or would be impractical. Some individuals, including residents of the European Union ( EU ), United Kingdom ( UK ), and certain US States, may have additional rights concerning the access and updating of their Personal Information

If You wish to exercise Your right to access, , and deletion rights, described above, please submit a verifiable request to us as provided in the How to Contact Us section below.

Email and Newsletter Preferences:

12.            Withdrawal of Your Consent

Where You have provided consent to process Personal Information, You have the right to withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal or the lawfulness of processing based on other lawful bases. You may do this by contacting us as set forth in the How to Contact Us section below.

13.            California Residents and Other State Privacy Rights

This Section applies only if we and You are subject to the California Consumer Privacy Act ( CCPA ) or certain other US state statutes relating to the rights of individuals regarding the processing of Personal Information (collectively State Privacy Laws ).

Information We Collect

Our Services collect Personal Information. In particular, the Services collect or may have collected in the last twelve (12) months the categories of Personal Information as described in Sections 3, 5 and 6 above.

Use of Personal Information

We may use or disclose the Personal Information we collect for one or more of the business purposes indicated in Section 5 above.

We will not collect additional categories of Personal Information or use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

Sharing Personal Information

We may disclose your Personal Information to a third party for a business purpose. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract. We share your Personal Information with the categories of third parties listed in Section 6 above.

In the preceding twelve (12) months, we have disclosed the following categories of Personal Information for a business purpose:

We do not sell Personal Information. In the event that we do sell any Personal Information, we will update this Privacy Policy to list the categories of consumers Personal Information sold.

Your Rights and Choices

Some State Privacy Laws provide consumers with specific rights regarding their Personal Information. This section describes your rights and explains how to exercise those rights.

Right to Access Specific Information and Data Portability Right

You may have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. Once we receive and confirm your verifiable consumer request, we will disclose to you:

Right to Delete

We anonymize all Personal Information collected through the Application. Customers may have the right to request that we delete any Personal Information that is not anonymized and that we collected from you and retained, if any, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies. Individual Users should contact their employers.

Exercising Your Rights

For Users to exercise the access and deletion rights described above, please contact Your employer. For Customers to exercise the access and deletion rights described above, please contact us.

Only you, or a person registered with jurisdiction s Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child.

You may only make such a request for access or twice within a 12-month period. The verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative, and describe your request with sufficient detail that allows us to properly understand, evaluate and respond to it.

We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use Personal Information provided in a verifiable consumer request to verify the requestor s identity or authority to make the request.

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response electronically. Any disclosures we provide will only cover the 12-month period preceding the receipt of the verifiable consumer request. The response we provide will also explain the reasons we cannot comply with a request, if applicable.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Non-Discrimination

We will not discriminate against you for exercising any of your rights as described above.

14.            European Economic Area, United Kingdom and Switzerland Residents Privacy Rights

Residents of the EU and UK may be entitled to other rights under the GDPR. These rights are summarized below. Customers (data controller) making a request on behalf of a user must be recognized as an authorized Teamstack Customer. These contacts with authority may make access requests on behalf of application users. Your Personal Information will be treated in a secure and confidential manner, using appropriate technical and organizational measures, in compliance with all applicable laws and regulations, including the European General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and the Swiss Federal Act on Data Protection. Depending on the context in which Personal Information is provided, we may be a data processor ( processor ) or a data controller ( controller ) of Your Personal Information.

As applicable under the GDPR and UK GDPR, individuals have additional rights including the following:

Lodging a Complaint: You also have the right to lodge a complaint with Your local supervisory authority for data protection, or privacy regulator. A list of data protection supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

Submitting a Request: To exercise the above rights or contact us with questions or complaints regarding our treatment of Your Personal Information, please contact us in accordance with the How to Contact Us" section below. Please note that we may request proof of identity, and we reserve the right to charge a fee where permitted by law, especially if Your request is manifestly unfounded or excessive. We will respond to Your request within the applicable timeframes set out by law.

International Transfers: If You are located within the European Economic Area, the United Kingdom or Switzerland, You should note that Your Personal Information may be transferred to countries outside these jurisdictions, including the United States where Teamstack or certain of our third-party service providers are located. The United States is deemed by the European Union to provide inadequate data protection. Transfers of Your Personal Information between us and a third party shall be done pursuant to adequate protections, which may include Standard Contractual Clauses, Your explicit consent, and/or other permitted mechanisms under applicable law.

In addition, please check the following sections of this Privacy Policy: Information we Collect and Receive ; Purposes and Legal Bases for Use of Personal Information ; How we Share and Disclose Personal Information ; Your Personal Information Choices ; and Withdrawal of Your Consent .

If You have any questions or concerns regarding this Privacy Policy or our privacy practices, including the processing of Your Personal Information, if You would like to exercise Your data rights under applicable laws, or if You believe Your privacy rights have been violated, please contact us as provide in the How to Contact Us section below.

15.            Links to Third-Party Site

Occasionally we may provide links to other Site for Your convenience and information. These Site operate independently from our Site and are not under our control. These Site may have their own privacy notices or terms of use, which You should review if You visit any Site linked through our Site. We are not responsible for the content or use of these unrelated Site. 

16.            Updates to this Privacy Policy

Teamstack may change this Privacy Policy from time to time, at our sole discretion. We encourage You to frequently check this page for any changes to the Privacy Policy.

17.            How to Contact Us

If You have any questions or concerns about this Privacy Policy or our Personal Information handling practices, please contact us at:

Email: support@teamstack.ai

or

Postal Address: One Broadway, 14th floor, Cambridge, MA 02142