Last Updated: April 27, 2020
Achievers Corp. (together with the companies owned by and in common ownership with Achievers Corp, “Achievers”, “we”, “us” or “our”) care about your personal information and is committed to protecting the privacy of users who use the Achievers public Web Site (https://www.achievers.com/) (the “Website”), mobile applications, and the services and features therein (together, the “Sites”).
PERSONAL INFORMATION WE COLLECT
Personal Information is collected by Achievers when you specifically choose to provide it to us, such as when you choose to receive program information, register for events, or engage in the service offering provided by Achievers, or automatically through our Sites and related to the services we provide, subject to applicable laws as set out below.
Achievers collects and uses your Personal Information primarily for the purpose of providing you with the information, products and services you have requested from us.
Personal Information We Collect Directly from You:
- Contact information, such as name, email address, mailing address, fax or phone number;
- Your resume, employment and education history, name and contact details, background details, and references when you apply to job postings or contact us about employment opportunities;
- Company and employment information;
- Information about your business such as company name, size, or business type; and
- Demographic information, such as age, gender, interests and ZIP or postal code.
Comments, Posts and Submissions:
When you submit online forms, participate in surveys, contests, promotions, or sweepstakes, join online chat discussions or post on a blog, request customer support, or submit testimonials, we collect your personal information, such as contact information, and other information you choose to share. Any information you provide in a blog may be read, collected, and used by others who access it. With your consent, we may use your testimonial and your name, e.g. to display personal testimonials of satisfied customers on certain Sites and in print advertisements.
Personal Information We Collect Automatically:
When you visit any Achievers Sites, we may automatically gather information about your use of the Sites through cookies, web beacons, java script, log files, pixels and other technologies which include: your domain name, browser type, browser language preference, device type and operating system, page view and links you click within the Sites, IP address, device ID or other identifier, location information, date and time stamp, and time spent on the Sites, referring URL, your activity within the Sites and device geolocation information (where permitted by your device settings). You may withdraw your consent to the processing of location-based information at any time by changing the settings on your device.
We also collect information from analytic services, to compile and analyze information derived from the use of our Services, such as aggregate usage patterns, user preferences, peak demand times, preferred content and other information.
Protecting Children’s Privacy Online
Achievers products, services and Sites are provided to employers and their employees. Our Sites are not directed to children and we do not knowingly collect personal information from children under the age of thirteen (13). We request that such individuals do not provide personal information through our Sites.
USE OF YOUR PERSONAL INFORMATION
Achievers will only collect, use, disclose, and otherwise process Personal Information for the following purposes, based on our legitimate business interests and/or compliance with law:
- Provide Our services: To provide our services, operate our Sites, respond to your enquiries, for bug and error reporting and resolution, to perform upgrades and maintenance;
- Customer Service and Support: To send you important information, such as changes to terms, conditions, and policies and/or other administrative information;
- Personalization: To personalize your experience on a Site or using the services, such as by tailoring the content we send or display to you in order to personalize help and instructions, and to otherwise personalize your experience using the Services;
- Marketing and Promotions: To send you marketing communications you have signed up for;
- Advertising and Referrals: To assist in advertising the services on third-party websites and to track referrals from partner websites;
- Analytics and Improvement: To better understand how users access and use the services, and for other research and analytical purposes, such as to evaluate and improve the services;
- Aggregated and Anonymized Information: We may also generate aggregated, pseudonymized and/or anonymized information about users for marketing, advertising, research or similar purposes.
- Verify Identity and Detect Fraud: To verify your identity and/or location in order to allow access to your accounts, conduct online transactions, and secure your personal information, and for risk control, fraud detection and prevention, and compliance with laws and regulations;
- Comply with Legal Obligations: To comply with the law or legal proceedings such as when required to disclose information in response to lawful requests by public authorities, including responding to national security or law enforcement disclosure requirements; and
- General Business Operations: Where necessary to the administration of our general business, accounting, recordkeeping and legal functions.
Purpose of Use
In the table below, we explain the purposes for which we use and process your personal information, as well as the legal bases for such use and processing under the European Union’s General Data Protection Regulation (“GDPR”) and other applicable laws.
|Purpose of Use (see list above)||Legal Bases of Processing (where applicable)|
|Provide Our services||Necessary to enter into or perform a contract with you (upon your request, or as necessary to make the Services available)|
|Customer Service and Support||Our legitimate business interest*|
|Personalization||Our legitimate business interest*|
|Marketing and Promotions||Our legitimate business interest* with your consent|
|Analytics and Improvement||Our legitimate business interest*|
|Aggregated and Anonymized Information||Our legitimate business interest*|
|Verify Identity and Detect Fraud||Compliance with law|
|Protect Our Legal Rights and Prevent Misuse||Establish, defend or protect legal interests|
|Comply with Legal Obligations||Our legitimate business interest*|
|General Business Operations||Establish, defend or protect legal interests
Compliance with law
* For personal information from the EU, the processing is in our legitimate interests, which are not overridden by your interests and fundamental rights. Our legitimate interests include our interests in verifying identity, detecting and preventing fraud, protecting and improving our products and services, in support of our general business operations, and to comply with our legal obligations. We only send marketing communications to individuals who provide opt-in consent or who are covered by “soft opt-in” exemptions.
A cookie is a small text file that is placed on your hard disk by a Website. Cookies contain a unique identification number that identifies your browser, but not you, to our systems each time you visit one of our Websites. Cookies tell us which pages of our Websites are visited and by how many people. Achievers does not collect any Personal Information about you through cookies nor can a cookie carry a damaging payload (such as malware).
There are two types of cookies in use with Achievers Websites which include:
- Session based cookies — Only used for the length of time you remain on the Website and expire when you leave the Website.
- Persistent based cookies — Are more permanent in nature and can re-used when you return to the Website from the same computer.
“Do Not Track” Browser Setting
Achievers does not respond to web browser “do not track” (DNT) settings or headers with respect to Achievers public Websites. For more information about do-not-track signals, please click here (http://www.allaboutdnt.com/). Currently no common industry standard for DNT has been adopted and there is also no consistent standard of interpreting user intent when the DNT setting is enabled. Achievers takes privacy seriously will continue to monitor policy advocates, technical experts, regulators and companies attempting to create a consensus interpretation around DNT browser technology and the implementation of a standard.
When you send us an e-mail or when you ask us to respond to you by e-mail, we collect your exact e-mail address and any information you have included in the e-mail message.
We use your e-mail address to acknowledge your comments and/or reply to your questions, and we will store your communication and our reply in case we correspond further. We may use your e-mail address to send you information about offers on products or special promotions that we believe may be of interest to you. You may choose to stop receiving our marketing emails at any time by following the unsubscribe instructions included in these emails.
Achievers uses images imbedded in e-mail messages called “web beacons”. Web beacons are clear images that allow Achievers to determine if a message has been opened. It also allows Achievers to determine the IP address of the user that opened it and to access any Achievers cookies. We may use this information in the aggregate to assess and improve our email messages.
Email web beacons can be disabled by turning off HTML display and displaying text only or by turning off image display while still using HTML within your email client.
HOW WE DISCLOSE PERSONAL INFORMATION WE COLLECT
Achievers does not sell your Personal Information to third parties.
Achievers is part of the Blackhawk global group of companies, and we may disclose personal information among our affiliated and subsidiary companies (“Affiliates”) who provide services to us or on our behalf, as part of our business operations and administration of the Services in furtherance of the purposes set out in this Policy. Any Affiliate’s processing of your personal information is subject to this Policy.
To ensure that we efficiently provide the information, products or services you have requested from us, Achievers may share your Personal Information with selected Service Providers who are acting on our behalf to assist us in carrying out the purposes identified in this policy. Service Providers may be located in the EU, United States, Canada and other jurisdictions. For example, we may work with Service Providers to track and manage the request that you have made on the Website for white papers, demos, information about Achievers Service offering, etc. Such Service Providers are provided only with information as is necessary which may include your physical mailing address, e-mail address and name. Information provided to Service Providers may be used only for the purpose stipulated and is subject to strict terms of confidentiality. Achievers represents that any third party for which Personal Information may be disclosed by Achievers is in compliance with GDPR (the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and/or the principles in the EU-U.S. and Swiss-U.S. Privacy Shield or is subject to applicable laws or contractual provisions requiring the same level of privacy protection.
We may also disclose your Personal Information in the event of the situations below:
- As permitted or required by law, such as to comply with a subpoena, or similar legal process;
- If Achievers is involved in a merger, acquisition or sale of all or a portion of its assets, or in the event of bankruptcy or dissolution of our business, your Personal Information may be transferred to an acquiring business or third party, including contemplation of or related to due diligence for such business transactions, subject to any applicable restrictions under applicable laws. You will be notified by email and/or by a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.
- Achievers may also use, or disclose your Personal Information to third parties, if Achievers has reason to believe that using or disclosing such information is necessary to: (i) conduct investigations of possible breaches of law; (ii) identify, contact, or bring legal action against someone who may be violating an agreement they have with us; (iii) investigate security breaches or cooperate with government authorities pursuant to a legal matter; or (iv) to protect our rights, safety or property, and/or the rights, safety, and property of our clients, users of our platform, and any other persons.
- We may disclose your Personal Information for any other purpose to which you consent.
Achievers has internal policies in place that govern the retention of your Personal Information. Your Personal Information will be retained when you are a prospect or customer or for a reasonable time thereafter, or as required by relevant statutory, regulatory or contractual requirements. When Achievers is no longer required to retain your Personal Information, we will securely destroy your Personal Information based on our data disposal policies and relevant regulations or return the data to your employer for destruction at their request.
Certain countries and regions, including the European Union, have enacted laws that provide for privacy rights for individuals located in the EU. Regardless of your location and jurisdiction, Achievers may at its sole discretion choose to extend these rights to all individuals, and to comply with requests as detailed below. We do not charge for these services but in certain cases we may require further proof of your identity or ask you to clarify the scope and nature of your request if it is unclear. Where you are entitled to a right, we will respond to your request within the timeframe set out by law, or where we provide answers on a voluntary basis within a reasonable timeframe.
Please note that we only respond directly to you in cases where we are the controller of your personal information. Where we are acting as a data processor on behalf of a client or partner, we will forward your request to the client or partner who is the data controller of your personal information.
ACCESS, RECTIFICATION, PORTABILITY AND DELETION
You have the right to access, rectify (correct), or delete your Personal Information held by us or may ask for a restriction of processing. You may also have the right to ask for an overview or copy of your Personal Information or to request that certain of your personal information be provided to you or to another provider in a machine-readable format where technically feasible (data portability).
You can exercise these rights by sending an email to [email protected]
Except in limited circumstances, as specifically provided by applicable privacy legislation, Achievers can tell you whether we hold Personal Information about you.
Please note that there are some limitations to these rights. For example, we will not be able to delete your personal information if we are required by law to keep it or if we hold it in connection with a contract with you. Similarly, access to your personal information may be refused if making the information available would reveal personal information about another person or if we are legally prevented from disclosing such information.
Achievers will only refuse access to your Personal Information in those circumstances permitted and required by applicable laws or regulations. If we cannot fulfill your request, we will inform you about why we cannot comply with your request.
Withdrawal of Consent
Where we process your personal information based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Object to Processing
You have the right to object to processing (including profiling) based on legitimate interest grounds, where we are relying upon legitimate interests to process personal information. If you object, we must stop that processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or we need to process the personal information for the establishment, exercise or defense of legal claims. Where we rely upon legitimate interest as a basis for processing, we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
Object to Marketing
You have the right to object to our use of your personal information (including profiling) for direct marketing purposes, such as when we use your personal information to invite you to our promotional events.
Right to Lodge a Complaint
You have the right to lodge a complaint with your supervisory authority, if you consider that the processing of your personal information infringes applicable law.
Achievers will conduct periodic assessments to validate its continued adherence to this Policy.
Where Achievers has knowledge that one of Achievers employees or Service Providers is using or disclosing Personal Information in a manner contrary to this Policy, Achievers will take reasonable steps to prevent or stop the use or disclosure. Achievers holds its employees and Service Providers accountable for maintaining the trust that employers and users place in our company.
The personal information we collect from you may be transferred to, stored at or processed in other countries, including the United States or other locations outside the European Economic Area, which may not provide equivalent levels of data protection to your home jurisdiction. We will take steps to ensure that your personal information receives an adequate level of protection in the jurisdictions in which we process it, including through appropriate written data processing terms and/or data transfer agreements.
For transfers from the EU, United Kingdom (“UK”) or Switzerland to the U.S., Achievers relies on its Privacy Shield certification (see below). Safeguards may also include adequacy decisions by the EU Commission or putting in place standard contractual clauses as approved by the European Commission (the form for the standard contractual clauses can be found here: EU Commission Standard Contractual Clauses) or another applicable supervisory body.
Blackhawk Network, Inc. and its subsidiary companies, including Achievers, complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (“Privacy Shield”) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union, the United Kingdom (“UK”) and Switzerland to the United States in reliance on Privacy Shield.
As part of the certification made by Blackhawk Network Inc., Achievers has certified to the Department of Commerce that they adhere to the Privacy Shield Principles with respect to such information. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit: https://www.privacyshield.gov/.
Achievers is responsible for the processing of your personal information that it receives under the Privacy Shield Framework and subsequently transfers to a Service Provider. Achievers complies with the Privacy Shield Principles for all onward transfers of personal information from the EU, the United Kingdom, and/or Switzerland, including the onward transfer liability provisions. To learn more about the Privacy Shield program, and to view our certification, please click here.
With respect to personal information received or transferred pursuant to the Privacy Shield Framework, Achievers is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Achievers may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Achievers will investigate and attempt to resolve complaints and disputes regarding the use and disclosure of Personal Information in accordance with the principles contained in this Policy.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. We are committed to cooperating in the resolution of disputes with individuals through this process.
Under certain conditions, more fully described on the Privacy Shield website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
QUESTIONS OR CONCERNS
By Regular Mail:
Attn: Privacy Office
c/o Blackhawk Network, Inc.
6220 Stoneridge Mall Road
Pleasanton CA 94588
This Policy may be subject to change. Please review it from time to time. If we make material changes to this Policy about how we process your personal information, we will post those changes on this page and revise the “Last Updated” date at the top and we will notify you by email or prominent notice on this Site prior to the change becoming effective. Where required by law, we will obtain your consent or give you the opportunity to opt out of such changes. Any changes will become effective when we post the revised Policy.