Privacy Policy
This Privacy Policy outlines how we – TRULLION Inc. (together with our affiliated companies – “Trullion”, “we”, “our” or “us”) collect, store, use and disclose the following categories of Personal Data:
(a) Customer Data: Personal Data that we collect, process and manage on behalf of our commercial customers (“Customers”), submitted to the Trullion cloud-based services, including our platforms, products, applications, application programming interface (“API”), tools, and any ancillary or supplementary Trullion products and services (collectively, our “Platform”).
We process such Customer Data on behalf and under the instruction of the respective Customer in our capacity as a “data processor”, in accordance with our Data Processing Addendum with them. For more information, please refer to Section 10 below.
This Privacy Policy – which describes Trullion’s independent privacy and data processing practices as a “data controller” – with respect to the Platform, Sites (as defined below) and any other services provided to the Customer by Trullion (“Services”), and does not apply to the processing of Customer Data. If you have any questions or requests regarding Customer Data, please contact your account administrator(s) (“Account Admin”) directly.
(b) User Data: Personal Data concerning our Customers’ internal focal point who directly engages with Trullion concerning their Trullion account (e.g. billing contacts and authorized signatories), Customers’ Account Admins, and authorized users of the Platform (collectively, “Users”);
(c) Prospect Data: data relating to visitors of our websites (including but not limited to https://trullion.com/), participants at events, and any other prospective customer, user or partner (collectively, “Prospects”) who visit or otherwise interact with our programs, marketing and social activities and our websites, digital ads and content, emails, integrations or communications under our control (“Sites”).
Specifically, this Privacy Policy describes our data processing activities regarding –
- Data Collection & Processing
- Uses of Personal Data and Legal Basis for Processing
- Data Location
- Data Retention
- Data Disclosure
- Cookies and Tracking Technologies
- Communications
- Data Security
- Data Subject Rights
- Data Controller/Processor
- Additional Notices
If you are a Customer, User or Prospect, please read this Privacy Policy carefully and make sure that you fully understand it.
You are not legally required to provide us with any of your Personal Data, and may do so (or refrain from doing so) at your own free will. If you do not wish to provide us with your Personal Data, or to have it processed by us or any of our services providers, please simply do not visit or interact with our Sites or use our Services.
You may also choose not to provide us with “optional” Personal Data (i.e. Personal Data that is marked as “not required” on forms), but please keep in mind that without it we may not be able to provide you with the full range of our Services or with the best user experience when using our Services.
Any capitalized and undefined term in this Privacy Policy shall have the meaning given to it in our Terms of Services (“Terms”).
In this privacy policy, the term “Personal Data” or “Personal Information” refers to any information that can be used to identify an individual, such as name, email address, phone number, IP address, and other data that can be reasonably linked to an individual. It does not include aggregated or anonymized information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual.
We collect or generate the following categories of Personal Data:
- Directly Collected Personal Data: We collect information you directly provide to us on our Site or on the Platform, such as full name, email address, phone number, company name and email address (“User Personal Data“). When you set up an account on our Platform we collect your name, email, phone number, position, workplace, profile picture, login credentials, contractual and billing details, and any other information submitted by Account Admins and Users or otherwise available to us when they sign up or log in to the Platform (either directly or through their social media or organizational Single-Sign-On account), when creating their individual profile (“User Profile”), or by updating their account.
- Automatically Collected Personal Data: We get information about you from other sources, such as website analytics, IP address, pages you viewed, device and application data (like type, operating system, mobile device or app id, browser version, location and language settings used), activity logs, the relevant cookies and pixels installed or utilized on your device, and the recorded activity (sessions, clicks, use of features, logged activities and other interactions), how long you spent on a page, access times and information about your use of and actions on our Site. We may add this to information we get from this Site.
- Customer Personal Data: When Users upload files and documents to our Platform for analysis, such files may contain Personal Data (“Customer Personal Data”). Note that Customer Personal Data is processed by us in our capacity as data processor, as further detailed in Section 10 below.
- Additional Personal Data: We collect Personal Data through tools and channels commonly used for connecting between companies and individual professionals in order to explore potential business and employment opportunities, such as LinkedIn, ZoomInfo and others. We also collect Personal data contained in any forms and inquiries that you submit to us, including support requests, interactions through social media channels and instant messaging apps, registrations to events that we host, organize or sponsor, and participation in our online and offline communities and activities, surveys, feedback and testimonials, needs, preferences, attributes and insights relevant to our potential or existing engagement, phone and video conference recordings (e.g., with our customer experience or product consultants), as well as written correspondences, screen recordings, screenshots, documentation and related information that may be automatically recorded, tracked, transcribed and analyzed, for purposes including analytics, technical support, quality control and improvements, training, and record-keeping purposes.
For the purposes of the California Consumer Privacy Act (“CCPA”), specifically in the last twelve (12) months, we have collected the following categories of Personal Information: Identifiers; Professional or Employment-Related Information; Internet or other Electronic Network Activity Information; Customer Records Information; and Geolocation Information. We do not use or disclose sensitive personal information as defined in the CCPA.
We use Personal Data as necessary for the performance of our Services (“Performance of Contract”); to comply with our legal and contractual obligations (“Legal Obligations”); and to support our legitimate interests in maintaining and improving our Services, e.g. in understanding how our Services are used and how our marketing campaigns are performing, and gaining insights which help us dedicate our resources and efforts more efficiently; providing customer services and technical support; and protecting and securing our Users, Customers and Prospects, Trullion and our Services (“Legitimate Interests”).
If you reside or are using the Services in a territory governed by privacy laws under which “consent” is the only or most appropriate legal basis for processing Personal Data as described in this Privacy Policy (either in general, based on the types of Personal Data you expect or elect to process or have processed by us or via the Services, or due to the nature of such processing) (“Consent”), your acceptance of our Terms and of this Privacy Policy will be deemed as your consent to the processing of your Personal Data for all purposes detailed in this Privacy Policy, unless applicable law requires a different form of consent. If you wish to revoke such consent, please contact us at privacy@trullion.com.
Specifically, we use Personal Data for the following purposes (and in reliance on the legal bases for processing noted next to them, as appropriate):
Type of Personal Data |
Type of Processing |
Purpose of Processing |
Legal Basis |
Customer and User Personal Data |
Collecting, storing, analyzing |
To provide our Services |
Legitimate Interest in delivering our Services to our Customer |
|
Collecting, storing and using for communications |
To invoice and process payments |
Legitimate Interest in receiving payment for our Services |
|
Collecting, storing, analyzing |
To personalize our Services and provide localization capabilities |
Legitimate Interest in delivering our Services to our Customer |
|
Storing, analyzing, retrieving |
To provide customer support |
Legitimate Interest in providing customer support |
|
Analyzing |
To gain an understanding of how you use and interact with our Services |
Legitimate Interest in improving our Services |
Customer, User and Prospect Personal Data |
Aggregating and pseudonymizing |
To create statistical data, inferred non-Personal Data |
Legitimate Interest in gaining insights into the use of our Services for the purpose of improving them |
|
Collecting, storing, analyzing |
To facilitate and optimize our marketing campaigns |
Legitimate interest in improving our marketing efforts, or consent where required |
|
Collecting, storing, analyzing |
To maintain and enhance our data security measures |
Legitimate interest in keeping us, our Customers, Users, Prospects and third parties safe |
|
Collecting, storing, communicating |
To facilitate, sponsor and offer events, webinars, contests and promotions |
Legitimate interest in retaining our customers, expanding our services Consent where necessary |
|
Collecting and publishing |
To publish feedback and submissions on our Sites, public forums and blogs |
Legitimate interest in providing public feedback of our Services |
|
Collecting, storing, communicating, disclosing, analyzing and deleting |
To comply with any contractual and legal obligations (such as tax reporting, fraud prevention, and responding to law enforcement requests) |
Legal obligation |
|
Storing, retrieving, sharing and deleting |
To fulfil a data subject request made by you |
Legal obligation |
We and our authorized Service Providers (defined below) maintain, store and process Personal Data in the United States (US), Europe, Israel, and the United Kingdom (UK), and other locations as reasonably necessary for the proper performance and delivery of our Services, or as may be required by applicable law.
While privacy laws vary between jurisdictions, Trullion, its affiliates and Service Providers are each committed to protect Personal Data in accordance with this Privacy Policy, customary and reasonable industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such data is transferred.
Trullion is headquartered in Israel, a jurisdiction which is considered by the European Commission, the UK Secretary of State, and the Swiss Federal Data Protection and Information Commissioner (FDPIC), to be offering an adequate level of protection for Personal Data of individuals residing in EU Member States, the UK and Switzerland, respectively. We transfer data from the European Economic Area (EEA), the UK and Switzerland to Israel on this basis.
For data transfers from the EEA, the UK and Switzerland to countries which are not considered to be offering an adequate level of data protection, we and the relevant data exporters and importers have entered into Standard Contractual Clauses as approved by the European Commission, the UK Information Commissioner’s Office (ICO), and the Swiss FDPIC, as applicable.
We may retain your Personal Data for as long as it is reasonably needed to maintain and expand our relationship and provide you with our Services and offerings; in order to comply with our legal and contractual obligations; or to protect ourselves from any potential disputes (e.g. as required by laws applicable to records-keeping and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following you ending the use of our Services), all in accordance with our data retention policy and at our reasonable discretion. To determine the appropriate retention period for Personal Data, we consider (i) whether we are required to retain your Personal Data in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, or (iii) if we reasonably believe there is a prospect of litigation relating to your personal information or dealings. We also consider the amount, nature, and sensitivity of such data, the potential risk of harm from unauthorized use or disclosure of such data, the purposes for which we process it, and the applicable legal requirements. If you have any questions about our data retention policy, please contact us at privacy@trullion.com.
We disclose Personal Data in the following instances:
Service Providers: We engage selected third parties as “Service Providers”, to perform services on our behalf or complementary to our own. These include providers such as: hosting and server co-location services, communications and content delivery networks (CDNs), data and cyber security services, billing and payment processing services, fraud detection, investigation and prevention services, web and mobile analytics, email and communication distribution and monitoring services, session or activity recording services, call recording, analytics and transcription services, event production and hosting services, remote access services, performance measurement, data optimization and marketing services, social and advertising networks, content, lead generating and data enrichment providers, email, voicemails, video conferencing solutions, support and customer relation management systems, third-party customer support providers, and our legal, compliance and financial advisors and auditors.
Our Service Providers may have access to Personal Data, depending on each of their specific roles and purposes in facilitating and enhancing our Services or other activities, and may only use the data as determined in our agreements with them.
Event Sponsors: If you register to any event that we host, organize or sponsor, then with your permission we may disclose your registration details to others, including the hosts, organizers, speakers, services providers and sponsors of that event, so that they may contact you with relevant information and offers, or to fulfill any promotions related to the event.
Customers and other Users: Your Personal Data may be disclosed to the Customer owning the Account to which you are subscribed as a User (including data and communications concerning your profile), as well as other Users of that Account. Your Personal Data and activity within the Services may also be monitored, processed and analysed by the Account Admin. This includes instances where you contact us for help in resolving an issue specific to a team of which you are a member (and which is managed by the same Customer).
Any content submitted by you to the Platform may still be accessed, copied and processed by your Account Admin(s). Your profile and Personal Data will also be made available to all the authorized Users of the same Customer as you. Please note that Trullion is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of the Customer, that itself acts as the “Data Controller” of such data (as further described in Section 10 below).
Services integrations: You or your Account Admin may choose to integrate your Account on the Services with third-party Services (provided that such integration is supported by our Services). The provider of such integrated third-party Services may receive certain Personal Data about or from your Account on the Services, or disclose certain relevant data from the account on the third-party provider’s Services with our Services, depending on the nature and purpose of such integration.
Feedback or Recommendations: If you submit a public review or feedback, note that we may (at our discretion) store and present your review publicly, on our Sites and Services. If you wish to remove your public review, please contact us at privacy@trullion.com. If you choose to send others an email or message inviting them to use the Services, we may use the contact information you provide us to automatically send such invitation email or message on your behalf. Your name and email address may be included in the invitation email or message.
Legal Compliance: In exceptional circumstances, we may disclose or allow government and law enforcement officials access to your Personal Data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations. Such disclosure or access may occur if we believe in good faith that: (a) we are legally compelled to do so; (b) disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing; or (c) such disclosure is required to protect the security or integrity of our products and Services.
Protecting Rights and Safety: We may disclose your Personal Data to others if we believe in good faith that this will help protect the rights, property or safety of Trullion, any of our Users or Customers, or any members of the general public.
Trullion Subsidiaries: We disclose Personal Data internally within our group of companies, for the purposes described in this Privacy Policy. In addition, should Trullion or any of its subsidiaries undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your Personal Data may be disclosed with the parties involved in such an event. In addition, if, in the future, Trullionsells or transfers, or considers selling or transferring, some or all of Trullion’s business, shares, or assets to a third party, we will disclose your Personal Data to such third party (whether actual or potential) in connection with the foregoing events (including, without limitation, our current or potential investors).
Analytics tools: We use various analytics tools on our Site and within the TrullionPlatform to better understand how users interact with our services. For example, our Site utilizes Google Analytics to gather insights such as visit frequency, pages viewed, and referral sources. Additionally, we use analytics tools within the Trullion Platform to assess user experience, including ease of navigation, clarity of language, and functionality of interface elements. We may add or remove analytics tools as needed to improve our services.
For the avoidance of doubt, Trullion may disclose your Personal Data in additional manners, pursuant to your explicit approval, if we are legally obligated to do so, or if we have successfully rendered such data non-personal and anonymous.
For the purposes of the CCPA, in the past twelve (12) months, we have disclosed Identifiers; Professional or Employment-Related Information; Internet or other Electronic Network Activity Information; Customer Records Information; and Geolocation Information to the third parties listed above.
Our Sites and Services (including some of our Services Providers) utilize “cookies”, anonymous identifiers, pixels, container tags and other technologies in order for us to provide and monitor our Services and Sites, to ensure that they perform properly, to analyze our performance and marketing activities, and to personalize your experience. Such cookies and similar files or tags may also be temporarily placed on your device. Certain cookies and other technologies serve to recall Personal Data, such as an IP address. To learn more about our practices concerning cookies and tracking, please see our Cookie Policy. You may also use the “Cookie settings” feature available in our Services depending on your location and activity on our Services, as applicable. You may set most browsers to notify you if you receive a cookie, or to block or remove cookies altogether.
We engage in Services and promotional communications, through email, phone, SMS and notifications.
Services Communications: We may contact you with important information regarding our Services. For example, we may send you notifications (through any of the means available to us) of changes or updates to our Services, billing issues, log-in attempts or password reset notices, etc. Our Customers, and other Users on the same Account, may also send you notifications, messages and other updates regarding their or your use of the Services. You can control your communications and notifications settings from your User Profile settings, or otherwise in accordance with the instructions that may be included in the communications sent to you. However, please note that you will not be able to opt-out of receiving certain Services communications which are integral to your use (like password resets or billing notices).
Promotional Communications: We may also notify you about new features, additional offerings, events and special opportunities or any other information we think you will find valuable, as our Customer, User, or Prospect. We may provide such notices through any of the contact means available to us (e.g. phone, mobile or email), through the Services, or through our marketing campaigns on any other sites or platforms. If you do not wish to receive such promotional communications, you may notify us at any time by sending an email to privacy@trullion.com, changing your communications preferences in your User Profile settings, or by following the “unsubscribe”, “stop”, “opt-out” or “change email preferences” instructions contained in the promotional communications you receive.
In order to protect your Personal Data held with us, we use industry-standard physical, procedural and technical security measures, including encryption as appropriate. However, please be aware that regardless of any security measures used, we cannot and do not guarantee the absolute protection and security of any Personal Data stored with us or with any third parties as described above.
Under various privacy and data protection laws, such as the GDPR (in the EU and the UK) and the CCPA (in California), you have rights regarding your Personal Data, which may include the right to:
- Access: You have the right to request access to your Personal Data and obtain a copy of it.
- Rectification: You have the right to request that we correct any inaccurate or incomplete Personal Data.
- Erasure: You have the right to request that we erase your Personal Data in certain circumstances, such as when it is no longer necessary for the purpose for which it was collected.
- Restriction of processing: You have the right to request that we restrict the processing of your Personal Data in certain circumstances, such as when you contest the accuracy of the information.
- Data portability: You have the right to request that we provide you with a copy of your Personal Data in a structured, commonly used, and machine-readable format.
- Right to object: You have the right to object to the processing of your Personal Data where the processing is based on our legitimate interests.
If any or all of these rights apply to you, and you wish to exercise any of them – please contact us by email at privacy@trullion.com. If you are a GDPR-protected individual, you also have the right to lodge a complaint with the relevant supervisory authority in the EEA or the UK, as applicable.
You may designate an authorized agent, in writing or through a power of attorney, to request to exercise your privacy rights on your behalf. The authorized agent may submit a request to exercise these rights by emailing us. In such cases, we may request further information to verify such power of attorney and authorization.
Please note that when you ask us to exercise any of your rights under this Privacy Policy or applicable law, we may instruct you on how to fulfill your request independently through your User Profile settings; refer you to your Account Admin; or require additional information and documents, including certain Personal Data and credentials in order to process your request in a proper manner (e.g. in order to authenticate and validate your identity so that we know which data in our systems relates to you, and where necessary, to better understand the nature and scope of your request). Such additional information will be then retained by us for legal purposes (e.g. as proof of the identity of the person submitting the request, and of how each request was handled), in accordance with Section 4 above.
We may redact from the data which we make available to you, any personal or confidential data related to others.
Certain data protection laws and regulations, such as the GDPR or the CCPA, typically distinguish between two main roles for parties processing Personal Data: the “data controller” (or under the CCPA, “business”), who determines the purposes and means of processing; and the “data processor” (or under the CCPA, “service provider”), who processes such data on behalf of the data controller (or business). Below we explain how these roles apply to our Services, to the extent that such laws and regulations apply.
Trullion is the “data controller” of its Prospect, User, and Customer Personal Data, as detailed in Section 1 above. Accordingly, we assume the responsibilities of a data controller (solely to the extent applicable under law), as set forth in this Privacy Policy.
Trullion is the “data processor” of any Personal Data contained within Customer Data, as submitted by our Customers and their Users to the Platform. We process such Personal Data on behalf of our Customers (who is the “data controller” of such data) and in accordance with its reasonable instructions, subject to our Terms, our Data Processing Addendum (to the extent applicable) and other commercial agreements with our Customer.
Our Customers are solely responsible for determining whether and how they wish to use our Services, and for ensuring that all individuals using the Services on the Customer’s behalf or at their request, as well as all individuals whose Personal Data may be included in Customer Data processed through the Services, have been provided with adequate notice and given informed consent to the processing of their Personal Data, where such consent is necessary, and that all legal requirements applicable to the collection, use or other processing of data through our Services are fully met by the Customer. Our Customers are also responsible for handling data subject rights requests under applicable law, by their Users and other individuals whose data they process through the Services.
If you would like to make any requests or queries regarding Personal Data we process as a data processor on our Customer’s behalf, please contact your Account Admin directly.
Updates and Amendments: We may update and amend this Privacy Policy from time to time by posting an amended version on our Services. The amended version will be effective as of the date it is published. When we make material changes to this Privacy Policy, we will give notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Services or by sending an email. Your continued use of the Services after the changes have been implemented will constitute your acceptance of the changes.
US State Law Requirements: This Privacy Policy describes the categories of personal information we may collect and the sources of such information (in Sections 1 & 2 above), and our retention and deletion (Section 4) practices. We also included information about how we may process Personal Information (in Sections 1 through 7), which includes “business purposes” under the CCPA. We do not sell your personal information for the purposes of CCPA. We do share and disclose Personal Data to third parties or allow them to collect Personal Data from our Services as described in Section 5 above, if those third parties are authorized Service Providers or business partners who have agreed to our contractual limitations as to their retention, use, and disclosure of such Personal Data, or if you integrate the Services of third parties with our Services, or direct us to disclose your Personal Data to third parties, or as otherwise described in Section 5 above.
Third Party Websites and Services: Our Services includes links to third party websites and services, and integrations with third parties. These websites and third parties, and any information you process, submit, transmit or otherwise use with websites, services and third parties, are governed by such third party’s terms and privacy practices and policies, and not by this Privacy Policy. We encourage you to carefully read the terms and privacy policies of such websites, services and third parties.
Children under the age of 16: We do not knowingly collect Personal Data from children and do not wish to do so. If we learn that a person under the age of 16 is using the Services, we will attempt to prohibit and block such use and will make our best efforts to promptly delete any Personal Data stored with us with regard to such child. If you believe that we might have any such data, please contact us by email at privacy@trullion.com.
Questions, concerns or general complaints: We welcome your comments or questions about this privacy policy. You may contact us via email at privacy@trullion.com or at our address: 154 W 14th St., New York, NY 10011