Privacy Policy
Last Updated: Feb 13, 2023
Thank you for using PROTOIO Inc. We are committed to protecting your privacy and, for that reason, we have adopted this Privacy Policy to explain our data collection, use, and disclosure practices for the PROTOIO Inc. services (including the https://protoioinc.com, https://proto.io, https://overflow.io websites, and mobile and web-based applications, and any other tools, products, or services provided by PROTOIO Inc. that link to or reference this Privacy Policy) (collectively, the “Services”). The Services are owned and operated by PROTOIO Inc., a Delaware corporation (“PROTOIO INC”, “we”, “us” or “our”).
If you are a PROTOIO INC customer with which we have a contract or are otherwise associated with a PROTOIO INC customer, our use of your information may be subject to the confidentiality terms of that contract. In this case, in the event of a conflict with this Privacy Policy, the document providing for the greater degree of confidentiality and privacy will prevail and determine how your information is used.
If you reside in a country in the European Economic Area or in Switzerland, please click here to learn more about your privacy rights. To the extent that there is a conflict between this Privacy Policy and the Privacy Notice for European Residents, the Privacy Notice for European Residents will prevail with respect to European Residents (as defined below) only.
This Privacy Policy applies to information PROTOIO INC collects through the Services, as well as other information provided to us online or offline by third parties, when we associate that information with customers or users of the Services; however, it does not apply to information collected from our employees, contractors, or vendors. It also does not apply to information that you ask us to share with third parties or that is collected by certain other third parties whose software or services are featured or included in the Services (as further described below).
This Privacy Policy describes, among other things:
Personal and other information we collect about you;
How we use your information;
How we may share your information with third parties; and
Your choices regarding the personal information we collect about you.
1. Consent
By accessing or using the Services, you consent to this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Services. Information gathered through the Services may be transferred, used, and stored in the United States or in other countries where our service providers or we are located. If you use the Services, you agree to the transfer, use, and storage of your Personal Information (as defined below) in those countries. The data protection and other laws of the United States and other countries might not be as comprehensive as those in your country. You agree that all transactions relating to the Services or PROTOIO INC are deemed to occur in the United States, where our servers are located.
2. Collection of Your Personal and Other Information
When you register for or use our Services, we collect Personal Information. By “Personal Information” we mean information that can identify or reasonably be linked to an individual, such as:
First names and last names;
Email addresses; and
Information contained in any image, photograph or profile you submit to us.
When you pay for a product and/or our services, we collect certain additional Personal Information. Such Personal Information may include, without limitation:
Billing address; or
Credit card and bank account information (which you submit for payment purposes and which is collected by our third party payment gateway service providers (such as Paypal or Braintree).
We also collect non-Personal Information relating to the Services, that is, information that does not personally identify an individual. The non-Personal Information we collect includes how you interact with the Services, information generally collected or “logged” by Internet websites or Internet services when accessed or used by users, and information about your web browser or device accessing or using the Services.
Examples of the non-Personal Information we collect are:
The pages of our website(s) that you viewed during a visit or the features of a PROTOIO INC mobile app you use;
What information, content or advertisements you view or interact with using the Services;
Language preferences;
The city and state in which you are located (but not your precise geographic location); and
Unique identifiers that are not connected and cannot reasonably be connected to your identity.
We will not use non-Personal Information to try to identify you, and if we associate any non-Personal Information with information that personally identifies you, then we will treat it as Personal Information. As discussed in more detail below, we sometimes use cookies and other automatic information gathering technologies to gather Personal Information and non-Personal Information.
Information collected by the Services may be collected by us or one of the third parties we utilize in providing the Services (as further described below).
3. Use of Your Information
We may use the information we collect to:
Assist us in providing, maintaining, and protecting the Services;
Set up, maintain, and protect accounts to use the Services;
Improve our online operations;
Process transactions;
Provide customer service;
Communicate with you, such as provide you with account- or transaction-related communications, or other newsletters, and/or other communications relating to the Services;
Send or display offers and other content that is customized to your interests or preferences;
Perform research and analysis aimed at improving our products and services and developing new products or services; and
Manage and maintain the systems that provide the Services.
4. Disclosure of Your Information
We may disclose your Personal Information to third parties as described below.
We may disclose Personal Information to provide the Services, or when you authorize or instruct us to do so, for example, when you use the Services to submit content or profile information. We may also disclose Personal Information and non-Personal Information to Service Providers. By “Service Providers” we mean companies, agents, contractors, service providers, or others engaged to perform functions on our behalf (such as processing of payments, provision of data storage, hosting of our website, marketing of our products and services, and conducting audits). When we use a Service Provider, we require that the Service Provider use and disclose the Personal Information received from us only to provide their services to us or as required by applicable law.
We may disclose Personal Information with our affiliates, including PROTOIO Europe, to perform the Services and to support our other business functions.
We may also disclose Personal Information and non-Personal Information to Online Tool Providers. By “Online Tool Provider” we mean a licensor of software that we include in, or use with, the Services, including an API or SDK, that provides a specialized function or service to us and that requires the transmission of Personal Information and/or non-Personal Information to the Online Tool Provider. Online Tool Providers may have the right to use Personal Information and non-Personal Information about you for their own business purposes. Use and disclosure of Personal Information and non-Personal Information by an Online Tool Provider is described in its privacy policy. See Section 5 below for some of the key Online Tool Providers we use.
We may also disclose your Personal Information to third parties when we believe, in good faith and in our sole discretion, that such disclosure is reasonably necessary to (a) enforce or apply the terms and conditions of the Services, including investigation of potential violations thereof, (b) comply with legal or regulatory requirements or an enforceable governmental request, (c) protect the rights, property or safety of us, our users or other third parties, (d) prevent a crime or protect national security, or (e) detect, prevent or otherwise address fraud, security or technical issues.
Finally, we reserve the right to transfer information (including your Personal Information) to a third party in the event of a sale, merger, or transfer of all or substantially all of the assets of our company relating to the Services, or in the unlikely event of a bankruptcy, liquidation, or receivership of our business. We will use commercially reasonable efforts to notify you of such transfer, for example, via email or by posting notice on our website.
Lastly, we may also disclose non-Personal Information, aggregated with information about our other users, to our clients, business partners, merchants, advertisers, investors, potential buyers and other third parties if we deem such disclosure, in our sole discretion, to have sound business reasons or justifications.
5. Cookies and Automatic Information Gathering Technologies
Every time you use the Services (e.g., access a Service webpage, or navigate to a specific location within the Service mobile app), we collect Personal Information and non-Personal Information (discussed above in Section 2) regarding that use. For example, to improve our Services, we collect how, when, and which parts of the Services or their features you use, which social media platforms you connect to the Services, and when, how, and what you post to the social media platforms through the Service app. Also, we may use your device’s unique identifier (UDID) or other unique identifiers to assist us in collecting and analyzing this data.
To assist us in collecting and storing this non-Personal Information, we may employ a variety of technologies, including “Cookies,” local browser storage, and “web beacons,” “pixels,” or “tags.” A “Cookie” is a small amount of data a website operator, or a third party whose content is embedded in that website, may store in your web browser and that the website operator or, as applicable, the third party, can access when you visit the website. A web beacon, pixel or tag is a small, usually-transparent image placed on a web page that allows the operator of that image, which may be the operator of the website you visit or a third party, to read or write a Cookie.
Your operating system and web browser may allow you to erase information stored in Cookies and local browser storage. But if you do so, you may be forced to login to the Services again, and you may lose some preferences or settings. You may also be able to set your browser to refuse all website storage or to indicate when it is permitted, but some features of our Services may not function properly without it. We may use Cookies to keep you logged in, save your preferences for the Services, and to collect information about how you use our Services.
An Online Tool Provider may collect information automatically, in which case Personal Information and non-Personal Information it receives are subject to the Online Tool Provider’s privacy policy. Some Online Tool Providers may allow you to opt out of certain collection and/or uses of your information. You can read more here in our Cookie Statement.
6. Transparency and Choice; Do Not Track Signals
You may request access to your Personal Information by sending an email to dpo@proto.io. We will try to locate and provide you with your Personal Information and give you the opportunity to correct this data, if it is inaccurate, or to delete it, at your request. But, in either case, we may need to retain it for legal reasons or for legitimate business purposes. You may also remove any content that you post to the Services using the deletion or removal options within the Services. However, we (and you) are not able to control information that you have already shared with other users or made available to third parties through the Services.
If you need further assistance with removing any content you posted through the Services, you can email us at dpo@proto.io. Removal of your posted content may not ensure complete or comprehensive removal from our computer systems.
We ask individual users to identify themselves and the information requested to be accessed, corrected, or removed before processing such requests, and we may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, jeopardize the privacy of others, would be extremely impractical (for instance, requests concerning information residing on backups), or relate to information that is not associated with your Personal Information. In any case, where we provide information access and correction, we perform this service free of charge, except if doing so would require a disproportionate effort. We may also require you to verify your identity to our satisfaction before providing you with access to Personal Information.
Please be aware that if you request us to delete your Personal Information, you may not be able to continue to use the Services. Also, even if you request that we delete your Personal Information, we may need to retain certain information for a limited period of time to satisfy our legal, audit and/or dispute resolution requirements.
We may use third-party service providers that collect information for interest-based advertising purposes (advertisements that are tailored to your likely interests, based on categories in which you have shown an interest). To learn more about these third parties and the choices they offer users, please visit the Network Advertising Initiative’s choices page or the Digital Advertising Alliance’s choices page. If you are reading this Privacy Policy from a mobile device, you can learn more about the DAA's mobile choices program here.
We support the development and implementation of a standard "do not track" browser feature that provides customers with control over the collection and use of information about their web-browsing activities. Once a standardized "do not track" feature is released, we intend to adhere to the browser settings accordingly.
You can opt out of receiving marketing e-mails from us by clicking on the “unsubscribe” link in the e-mails. Please note that it may take up to ten (10) business days for your opt-out request to be processed. Also, even if you opt out of marketing e-mails, we may continue to send you certain account-related e-mails, such as notices about your account and confirmations of transactions you have requested.
7. Certain State Residents
You may have heard of the certain state laws including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (CDPA), Colorado Privacy Act (CPA), Utah Consumer Privacy Act (UCPA), and Connecticut Data Privacy Act (CTDPA) which provides certain rights to California, Virginia, Colorado, Utah, and Connecticut residents in connection with their Personal Information. Our Services are not currently subject to any state laws providing rights in connection with Personal Information. However, we do provide notice and transparency about our collection and use of Personal Information as described in this Privacy Policy.
8. Residents of Canada
If you have an objection to the use of your Personal Information as described in this Privacy Policy, you may file a complaint by sending an email to dpo@proto.io. We will attempt to accommodate your objection or complaint, but you understand that, to the extent you object to our processing of Personal Information that is necessary for us to provide the Services to you, certain features and functionalities of the Services may no longer be available to you. Nothing in this Privacy Policy prejudices your rights to file a complaint with the Office of the Privacy Commissioner of Canada, and/or with any other applicable data protection authorities.
9. Residents of Nevada
We do not sell your Personal Information. However, you may contact us at dpo@proto.io with questions.
10. Children
The Services are not intended for users under 18 years of age. We do not knowingly collect Personal Information from users under 18 years of age. We do not authorize users under 18 years of age to use the Services.
11. Information Security
We utilize reasonable information security measures to safeguard your Personal Information against unauthorized access, modification, or destruction. For example, we utilize Secure Socket Layer (SSL), Transport Layer Security (TLS), or similar encryption technology when sensitive data is transmitted over the Internet, and use firewalls to help prevent external access into our network. However, no data transmission over the Internet and no method of data storage can be guaranteed to be 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its security.
We restrict access to Personal Information in our possession to our employees, Service Providers, and Online Tool Providers who need to know that information in order to operate, develop, improve or support our Services.
12. Third Party Websites
Please note that the Services may link or integrate with third-party sites, services or apps. We are not responsible for the privacy or security policies or practices or the content of such third parties. Accordingly, we encourage you to review the privacy and security policies and terms of service of those third parties so that you understand how they collect, use, share and protect your information.
13. Changes to this Policy
We may modify or update this Privacy Policy periodically with or without prior notice by posting the updated policy on this page. You can always check the “Last Updated” date at the top of this document to see when the Privacy Policy was last changed. If we make any material changes to this Privacy Policy, we will notify you by reasonable means, which may be by posting a notice of the changes on our website or through the Services’ mobile app prior to the changes becoming effective. We encourage you to check this Privacy Policy from time to time. IF YOU DO NOT AGREE TO CHANGES TO THIS PRIVACY POLICY, YOU MUST STOP USING THE SERVICES AFTER THE EFFECTIVE DATE OF SUCH CHANGES (WHICH IS THE “LAST UPDATED” DATE OF THIS PRIVACY POLICY).
14. Questions
To ask questions about our Privacy Policy or to lodge a complaint, contact us at:
PROTOIO Inc.
44 Montgomery St. STE 300, San Francisco, CA 94104
Email: legal@proto.io
PRIVACY NOTICE FOR EUROPEAN RESIDENTS
If you reside in a country in the European Economic Area, the United Kingdom, or Switzerland (a “European Resident”), then information we collect from you may be subject to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “EU GDPR”), or the equivalent laws of the United Kingdom and Switzerland (collectively, “Data Protection Laws”), and the following additional information is provided for your benefit. For purposes of this Privacy Notice for European Residents, in addition to the meaning set forth in the Privacy Policy, “Personal Information” shall also include “personal data” as that term is defined by the GPDR, as well as “personal data” or similar terminology as defined by other applicable Data Protection Laws.
If you would like to review our Data Processing Addendum, you can request a copy of our Data Processing Addendum by emailing us at dpo@proto.io.
If you use the Services, you acknowledge that your Personal Information is being processed pursuant to the lawful bases described below, and you specifically consent to your Personal Information gathered through the Services being transferred, used, and stored in the United States or other third party countries which do not have local privacy laws that are equivalent to the Data Protection Laws. You acknowledge and agree that the local laws in such countries may be materially different from, and provide for a lesser degree of protection regarding your Personal Information (including, but not limited to, with respect to governmental and law enforcement agencies’ ability to access your Personal Information under certain conditions) than, Data Protection Laws.
1. Personal Information
If you use the Services, we may collect certain categories of Personal Information, as described in Section 2 of the Privacy Policy.
2. Your Rights
PROTOIO INC undertakes to respect the confidentiality of your Personal Information and to guarantee you can exercise your rights
You have the following rights under applicable Data Protection Laws:
You have the right to know why we collect your Personal Information, how and why it is processed by us, and what our legal bases for such processing are.
Right of access: You have the right to access your Personal Information. Whenever made possible, you can access, update or request deletion of your Personal Information directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you. This also enables you to receive a copy of the Personal Information we hold about you.
Right to rectification and deletion: you have the right to supplement or correct the Personal Information we’ve collected about you, or to direct us to delete your Personal Information. You have the right to have any incomplete or inaccurate information we hold about you corrected. You also have the right to ask us to delete or remove Personal Information when there is no good reason for us to continue processing it.
If you give us your consent to process your Personal Information, you have the right to revoke that consent.
Right to data portability: you have the right to request that we transfer all your Personal Information to another controller in a reasonably understandable format. We will provide to you, or to a third-party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Right to object to processing of your Personal Information: you may object to our processing of your Personal Information. This right exists where we are relying on a legitimate interest as the legal basis for our processing and there is something about your particular situation, which makes you want to object to our processing of your Personal Information on this ground. We will make commercially reasonable efforts to comply with your objection, unless there are legally permissible reasons why we can or must continue to process your Personal Information. You also have the right to object where we are processing your Personal Information for direct marketing purposes.
You may exercise your rights of access, rectification, cancellation and opposition by contacting us. Please note that we may ask you to verify your identity before responding to such requests. If you make a request, we will try our best to respond to you as soon as possible.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Information. For more information, if you are in the European Economic Area (EEA), please contact your local data protection authority in the EEA. For contact details of your local Data Protection Authority, please see https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.
3. Lawful Bases for Processing
Under European law, companies must have a legal basis to process data. You have particular rights available to you depending on which legal basis we use, and we've explained these above. You always have the right to request access to, rectification of, and erasure of your data under applicable Data Protection Laws. To exercise your rights, please email us at dpo@proto.io.
Pursuant to a contract with you:
We may process data as necessary to perform our contracts with you. The provision of Personal Information is necessary for the performance of an agreement with you and/or for any pre-contractual obligations thereof. We describe the contractual services for which this data processing is necessary throughout this Privacy Policy and in our Terms of Service (collectively, the “Terms”). The main uses of your data necessary to provide our contractual services are described in the Use of Your Information section of the Privacy Policy:
We'll use the Personal Information we have to provide the Services and as otherwise described in our Privacy Policy if you choose not to provide certain data, the quality of your experience using the Services may be negatively impacted.
When we process data you provide to us as necessary to perform our contracts with you, you have the right to receive a portable copy of it (meaning to receive a copy of your data in a structured, commonly used and machine-readable format) under applicable Data Protection Laws. To exercise your rights, please email us at dpo@proto.io.
The other legal bases we rely on in certain instances when processing your data are:
Your Consent:
We may process your Personal Information on the lawful basis of consent. When we process data you provide to us based on your consent, you have the right to withdraw your consent at any time and to receive a portable copy of the data you provide to us, under applicable Data Protection Laws. To exercise your rights, please email us at dpo@proto.io. You have given your consent for processing Personal Information for the specific purposes disclosed in this Privacy Policy.
Processing Personal Information is necessary for the purposes of the legitimate interests pursued by PROTOIO INC.
Legitimate Interests:
We may process your Personal Information where our legitimate interests, or the legitimate interests of a third party, are not outweighed by your interests or fundamental rights and freedoms.
The legitimate interests for our processing of Personal Information are to:
Assist us in providing, maintaining, and protecting the Services;
Set up, maintain, and protect accounts to use the Services;
Improve our online operations;
Process transactions;
Perform our responsibilities under our contract with you (e.g. processing payments for and providing the Services you have requested)
Provide customer service;
Communicate with you, such as provide you with account- or transaction-related communications, or other newsletters, RSS feeds, and/or other communications relating to the Services;
Send or display offers and other content that is customized to your interests or preferences;
Perform research and analysis aimed at improving our products and services and developing new products or services;
Manage and maintain the systems that provide the Services
Prevent and address fraud, unauthorized use of the Services, violations of our terms and policies, or other harmful or illegal activity; to protect ourselves (including our rights, property or products), our users or others, including as part of investigations or regulatory inquiries; or to prevent death or imminent bodily harm; and
Operate of our day-to-day business and planning, including executing strategic corporate transactions, such as mergers.
You have the right to object to, and seek restriction of, such processing; to exercise your rights, please email us at dpo@proto.io.
We will consider several factors when assessing an objection to our processing in furtherance of PROTOIO INC’s legitimate interests, including: our users' reasonable expectations; the benefits and risks to you, us, other users, or third parties; and other available means to achieve the same purpose that may be less invasive and do not require disproportional effort. Your objection will be upheld, and we will cease processing your information, unless the processing is based on compelling legitimate grounds or is needed for legal reasons.
Compliance with a legal or regulatory obligation:
Processing Personal Information is necessary for compliance with a legal obligation to which PROTOIO INC is subject. We need to process your Personal Information when applicable law requires it, including, for example, if there is a valid legal request for certain data.
Protecting your Vital Interests:
We may also process Personal Information when it is necessary to protect your vital interests or of another natural person.
Public Interest:
Lastly, we may also process your Personal Information where it is related to a task that is carried out in the public interest or in the exercise of official authority vested in PROTOIO INC.
In any case, PROTOIO INC will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Information is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
4. Disclosures of Your Information
“Processors” means our Service Providers and their respective service providers.
We may also disclose your Personal Information, (as well as non-Personal Information, without the same restrictions that apply to your Personal Information) to our Processors who we engage to perform certain functions for us, or on our behalf (including, but not limited to, processing of payments, provision of data storage, hosting of our website, marketing of our products and services, conducting audits, and performing web analytics). We establish data processing agreements that govern our Processors’ use of your Personal Information, but our Processors’ use of your Personal Information may also be subject to the Processors’ own privacy policies. You can request a copy of the list of our Processors by emailing us at dpo@proto.io.
5. Retention of Your Information
We retain each category of your Personal Information for no longer than is reasonably necessary for one or more of the above lawful bases for processing, subject to your right to request we delete your Personal Information. Due to the nature of the Services, it is not possible to predict the length of time that we intend to retain your Personal Information. Instead, we use the following criteria to determine whether it remains reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing: we will retain and use your Personal Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies;
When we determine that it is no longer reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing based on the above criteria, we will delete your Personal Information.