Policy and Legal

1. Executive Summary

1.1 Introduction

Aulter Ltd., A limited company incorporated in the United Kingdom with a registered office at Platform, New Station street, Leeds, West Yorkshire, LS1 4JB.

Aulter is committed to maintaining the privacy, security, and accuracy of your personal data. As a result, Aulter has developed this policy to inform you of the steps it has taken to protect your privacy.  In addition, Aulter and its employees also adhere to strict internal information security policies and procedures to safeguard your information.

Aulter complies with all applicable data protection laws, including, without limitation, the General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”). Because Aulter respects your right to privacy, it has implemented privacy practices in the provision of its services, products, and website, including in accordance with the Privacy Shield, GDPR, and other applicable law.

For individuals specifically located in the European Economic Area, Aulter commits to complying with the following principles in respect of all personal data which is received from individuals based in the European Union and transferred to the United States of America.

1) Notice:  Aulter is committed to providing you with information about its participation in and responsibilities under the Privacy Shield, the types of information that Aulter may collect from you and how they are used, your rights in relation to your personal data, and how to contact Aulter and/or the available independent dispute resolution body designated to address complaints;

2) Choice:  Where possible, Aulter will allow you to opt out of (i) disclosures of your personal data to third parties; or (ii) use of your personal data for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorised by you;

3) Accountability for Onward Transfers:  Aulter will only transfer your personal data to third parties where: (i) such transfer is only for limited and specified purposes; (ii) the third party provides at least the same level of privacy protection as the Principles; (iii) the processing is consistent with Aulter's obligations under the Principles; (iv) the third party is required to notify Aulter if it can no longer provide sufficient protection for your personal data; (v) the third party takes steps to stop and remediate unauthorised processing; and (vi) Aulter commits to provide a summary of the relevant privacy protections in place with that third party to the Federal Trade Commission upon request;

4) Security: Aulter will take reasonable and appropriate measures to protect personal data from loss, misuse or unauthorized access, disclosure, alteration or destruction;

5) Data Integrity and Purpose Limitation:  Aulter will take steps to limit the personal data that it processes about you to that which is relevant for the purposes of processing. Aulter will also take steps to hold the data it processes about you for as long as it serves the purpose of processing. Aulter will also take reasonable steps to ensure that personal data is reliable for its intended use, accurate, complete, and current;

6) Access:  You have a right to access the personal data that Aulter holds about you and to correct, amend, or delete that information where it is inaccurate or has been processed in violation of the Principles; and

7) Recourse, Enforcement and Liability:  Aulter provides robust mechanisms for assuring compliance with the Principles and recourse for individuals who are affected by non-compliance with the Principles. Further details on the recourse mechanisms available to you can be found under the “Recourse and Dispute Resolution” section below.

8) Lawful basis of processing: Aulter will process personal data on the basis of consent, out of necessity for the performance of a contract, legitimate interests for marketing purposes, and to protect our legal position in the event of legal proceedings.


2. Privacy Practises

2.1 Personal Data Collection

In general, you can access Aulter’s website(s) and use its services without giving us any personal data. However, many of Aulter’s products, services and interactions with you will involve the collection of various “personal data” about you which are explained in detail below. Personal data is information which can identify you as a living individual when used in isolation or in conjunction with other information.

In addition to any information you voluntarily provide to us or input through Aulter’s website(s), we may collect the information in the following circumstances:

Products / Services.  

Aulter may collect your personal data in connection with providing you with services and/or products.  The specific types of personal data collected from you is dependent on the services or products you select but this information may include:

- full name;
- contact details including address, phone numbers and email address;
- job role and employer name;
- bank account information including credit card number;
- tax identification number; and
- second-level domain information and IP addresses
- commercial information such as products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies records

Partners.  

Aulter may also obtain your personal data from third parties, such as partners and resellers, but only to the extent it is required to provide you with our products and/or services. This information may include:

- full name;
- contact details including address, phone numbers and email address; and
- bank account information including credit card number

Website and Subscriptions.  

Other than during your enrollment for services and/or products, Aulter also collects personal data from you if you access Aulter’s website(s) and/or you choose to register for events, subscribe to email listings throughout our website, request that we contact you, or apply for a job opening at the company. This information may include:

- full name;
- contact details including address, phone numbers and email address as well employment and educational history (if you apply for an open position);
- second-level domain information and IP addresses;
- information gathered from cookies (see “Cookies” section below)

Cookies.  

Aulter also utilises cookies when you visit its website(s), or during the use of its products, which is a piece of data used by web servers to help identify you.  A cookie is installed automatically when you use the site but you can reject or disable a cookie by changing a setting on your browser. Aulter uses session, non-persistent cookies to help offer you secure pages to our website that allow you to login automatically across sessions. A list of our cookies can be provided on request in accordance with the “Contact Details” section.

2.2 Use of Personal Data

Aulter may use your personal data as follows:

- Where collected in connection with our products and services:

- to provide you with products, services and any renewals thereof;
- to provide you with support and maintenance for products/services;
- to inform you of any new or updated services or product offerings;
- to bill you for products and services;
- to notify you of any changes to your use of our website, products, or services;
- to respond to your enquiries;
- to have a partner or independent reseller contact you to facilitate the renewal, support or purchase of products/services, but only to the extent such third party has executed a confidentiality agreement with obligations to protect your personal data  (for a list of these third parties, please contact us at the address set forth at the end of this policy);
- to authenticate your identity in order to provide you with an SSL certificate (your personal data may be provided to an independent third party resource for verification);
- to issue you an SSL certificate, some of your personal data will be published within the certificate itself or in Aulter’s SSL certificate repository as set forth in our Certification Practices Statement.  Publication of such information is germane to the widespread use of SSL certificates;
- to transfer or negotiate the transfer of ownership of Aulter or its assets during any merger, acquisition or sale, even if they are not in the same line of business as us (in such event, your personal data will be held subject to this Privacy Policy); and
- to comply with applicable law and law enforcement authorities.

- Where collected from third parties:

- to provide you with products, services and any renewals thereof;
- to provide you with support and maintenance for products/services;
- to inform you of any new or updated services or product offerings;
- to bill you for products and services;
- to notify you of any changes to your use of our website, products, or services;
- to respond to your enquiries;
- to have a partner or independent reseller contact you to facilitate the renewal, support or purchase of products/services, but only to the extent such third party has executed a confidentiality agreement with obligations to protect your personal data  (for a list of these third parties, please contact us at the address set forth at the end of this policy);
- to authenticate your identity in order to provide you with an SSL certificate (your personal data may be provided to an independent third party resource for verification);
- to issue you an SSL certificate, some of your personal data will be published within the certificate itself or in Aulter’s SSL certificate repository as set forth in our Certification Practices Statement.  Publication of such information is germane to the widespread use of SSL certificates;
- to transfer ownership of Aulter during any merger, acquisition, or sale (in such event, your personal data will be held to the same confidentiality obligations); and
- to comply with applicable law and law enforcement authorities.

- Where collected in connection with your access to Aulter’s website(s) and/or you registering for events, subscribing to email listings, requesting that we contact you or applying for a job opening:

- to inform you of any new or updated services or product offerings;
- to notify you of any changes to your use of our website, products, or services;
- to analyse the use of our website to improve its layout and services;
- to respond to your enquiries;
- to review your candidacy for a job opening at the company;
- to transfer ownership of Aulter during any merger, acquisition, or sale (in such event, your personal data will be held to the same confidentiality obligations); and
- to comply with applicable law and law enforcement authorities.

The uses listed above are not intended to be exhaustive and may be updated from time to time as business needs and legal requirements dictate. Where appropriate, you will be given a more detailed explanation as to how your personal data is used on a case by case basis. Aulter’s website(s) may link to other websites which are not within its control.  Once you have left Aulter’s website(s), Aulter cannot be responsible for the protection and privacy of any information which you provide. You should exercise caution and look at the privacy statement applicable to the website in question.


2.3 Sensitive Information

Information about you which is considered sensitive or a special category of personal data under data protection laws can include information about your medical or health conditions, racial or ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, genetic data, biometric data, sexual life and sexual orientation, and suspected or proven criminal activity and related proceedings.  If we need to process sensitive or special categories of personal data, you will be notified of such processing and asked to specifically agree to the use of such information as appropriate. Aulter asks that you do not provide any sensitive or special categories of personal data unless Aulter specifically asks for this.


2.4 Disclosures

Aulter may share your personal data with any of its subsidiaries or parent who may process your personal data for the purposes specified in this privacy policy. Sometimes Aulter will share your information with carefully selected third parties outside of Aulter’s corporate group (such as its partners, resellers, and subcontractors, such as service providers, Internet cookie information recipients, advertisers, social media companies). Aulter may do this for the following reasons:

- to carry out services for Aulter;
- to provide you with information about special promotions and offers which we think you might be interested in;
- In response to lawful requests by public authorities, including to meet national security or law enforcement requirements;
- when Aulter believes it is necessary to comply with the law or protect our or another person's rights, property, or safety; and/or
- if there is (or is to be) any change in ownership of any Aulter business or assets then Aulter may wish to share your information so that the new (prospective) owners may continue to operate our business effectively and continue to provide services to customers. This may include new shareholders or any organisation that might take an assignment or transfer of any agreements we have entered into with Aulter’s customers.

Aulter will place appropriate obligations and restrictions on third parties to protect your details.

Aulter will remain responsible to you under the Principles in the event any of its agents processes your personal data in a manner inconsistent with the Principles except where Aulter can prove that it is not responsible for the relevant event.

Some Aulter companies, and sometimes other third parties with whom we share personal data are or may be located outside the European Economic Area or the United States.


2.5 Opting Out / In


If you are a customer or you have previously asked us for information on Aulter’s products and/or services, Aulter may send you information on its range of products and services to your contact details, unless you have asked us not to do so.

You may opt out of having your personal data used for marketing purposes and/or any purpose inconsistent with the purpose it was originally collected or authorised by you. Contact us on dsar@aulter.com

If you receive marketing material from our partners or other third parties, and no longer wish to receive such material, you must opt-out directly with that party.


2.6 Rights of Data Subjects in the European Union / European Economic Area


At any time, you may have access to your personal data for any reason, including without limitation reviewing, correcting, deleting inaccuracies or updating such information by sending a request to Aulter in accordance with the “Contact Details” section below. You may also have the right to erase your personal data, restrict the processing, the right of portability and the right to object to the processing in certain circumstances. Where appropriate, Aulter will verify your identity before processing any requests. European data subjects requesting erasure of their personal data must also review the “Considerations on Data Erasure” section below.


2.7 Rights of Data Subjects Residing in the State of California, United States


Effective January 1, 2020 and unless otherwise stated in this policy, the practices and activities detailed herein also apply to you if you were considered to be a California resident during the collection of your personal data. As a California resident, you may have:

- the right to know the categories of personal data that may be collected about you and related categories of sources for collection in addition to the business purposes for which that information would be used or shared;
- the right to know the categories and specific pieces of personal data that were collected or shared for business purposes about you in the preceding 12 months of your request;
- the right to know the categories of third parties with whom your personal data was shared;
- the right to delete your personal data; and
- the right to not be discriminated against if you choose to exercise your privacy rights.

You may inform us that you want to exercise your rights in accordance with the “Contact Details” section below. Aulter will verify your identity before processing any requests and you are entitled to make such request no more than twice in a 12-month period. Please also note that the CCPA contemplates certain exemptions or exceptions for certain types of transactions or other reasons contemplated by law. If you contact Aulter regarding your personal data and an exemption or exception applies, we will inform you of that fact. California residents requesting erasure of their personal data must also review the “Considerations on Data Erasure” section below.

Businesses are also required to disclose whether they sell personal data to third parties. Aulter does not sell your personal information.


2.8 Security


Aulter utilises appropriate technical and organisational measures to ensure that the confidentiality, integrity and availability of our systems and services protect your personal data.


2.9 Considerations on Data Erasure


When processing a valid request for erasure of personal data in accordance with this privacy policy and applicable law, Aulter will promptly erase personal data from live systems based on the scope defined between the parties. Where data erasure applies to you, please also consider the following:

- depending on the extent of your relationship with Aulter, your data may be retained in Aulter’s backup systems for a longer period of time in a format that is beyond use;
- backup systems play a crucial role in Aulter’s data security program and in ensuring the availability and access to data in a timely manner in the event of a physical or technical incident;
- data erasure on certain backup systems may not be immediately possible due to existing technical controls designed to keep information temporarily available to Aulter’s information technology team solely when fully required in the event of a physical or technical incident;
- relevant data retained in certain backup systems will not be used for any other purpose and will be secured with the appropriate technical and organisational measures based on the requirements of data protection law; and
- relevant data retained in backup systems will be kept until such data is overwritten and completely erased based on Aulter’s internal backup retention schedule and policies.

Aulter will provide information where these considerations apply on a case-by-case basis.


2.10 Changes to this Privacy Policy

Aulter may amend this privacy policy from time to time. If any amendments are made, then a notice will be posted on Aulter’s website. This privacy policy was last updated on 08 January 2020.


3 Questions, Complaints and Dispute Resolution

3.1 Contact Details

All inquiries, questions and complaints regarding how Aulter processes your personal data and/or this privacy policy may be sent to Aulter’s Privacy Department: dsar@aulter.com


- - - - - -


When you use the Site, you accept the Terms of Use; if you do not agree to the Terms of Use you may not use the Site. Aulter reserves the right to modify content on the Site and these Terms of Use periodically without prior notice.

Disclaimer

Aulter publishes this Web site for our clients, friends, and other interested visitors for information purposes only. The contents of the site do not constitute Information Assurance advice and some information does not necessarily reflect the opinions of the Company, Senior Security Consultants or any of its lawyers or clients.

The site provides general information, which may or may not be correct, complete or current at the time of reading. The content is not intended to be used as a substitute for specific Information Assurance advice or opinions. No recipients of content from this site should act or refrain from acting on the basis of content of the site without seeking appropriate Information Assurance or legal advice or other professional counseling.

Aulter expressly disclaims all liability relating to actions taken or not taken based on any or all contents of the site. The transmission of information to and from this site, in part or in whole, does not create, and receipt does not constitute, a client relationship between senders and/or recipients and Aulter. Any communication through the Web site or through e-mail does not constitute or create a client relationship. In addition, information should not be sent to Aulter electronically until you speak with one of the Senior Security Consultants and receive authorisation to send the information. General information sent to Aulter via this Web site or through e-mail is not secure and is therefore not confidential.

Aulter provides clients with a mechanism to communicate information, reports, alerts and other relevant information in a secure manner, and a client should not send confidential information to Aulter via this Web site unless they have reviewed Aulter's written instructions on how to communicate securely. Once information has been securely sent and received by the client, Aulter can not be held responsible for its' safeguarding. Aulter is not responsible, and does not necessarily endorse, any third-party content that may be accessible through this Web site.

Aulter expressly disclaims all liability for any actions taken or not taken based on any or all the contents of any third-party sites.


Use of Content on the Site


You may view, download, and print contents from the Site subject to the following conditions:

- Aulter's name and copyright notice must appear in all copies
- the content may be used solely for information purposes; and
- the content may not be modified or altered in any way.

You may not republish, distribute, prepare derivative works, or otherwise use the content other than as explicitly permitted herein. You may not frame or utilise framing techniques to enclose any trademark, logo, or other proprietary information (including images, text, page layout, or form) of Aulter without the express written consent of Aulter's legal counsel.

You may not use any meta tags or any other "hidden text" utilising Aulter's name or trademarks without the express written consent of Aulter's legal counsel.

You may not use any Aulter logo or other proprietary graphic or trademark as part of the link without express written permission. You do not acquire any ownership rights to any content in the Site. Any unauthorised use terminates the permission or license granted by Aulter.


User Conduct and Obligations


You agree to follow all applicable laws and regulations when using this website. Furthermore, you agree that you shall not:

- Upload, post or otherwise transmit through or to this website any content that: - is unlawful, abusive, threatening, harmful, obscene, lewd, offensive, defamatory or otherwise objectionable; - might infringe the intellectual property rights, privacy rights, rights of publicity, or other proprietary rights of others; - contains any viruses, trojan horses, time bombs, or any other harmful programs or elements;
- Disrupt, place unreasonable burdens or excessive loads on, interfere with or attempt to gain unauthorised access to any portion of our website, its computer systems, servers or networks;
- Provide false information about yourself to us, impersonate any other person, or otherwise attempt to mislead others about your identity or the origin of any content, message or other communication;
- Transmit junk mail, chain letters, or other unsolicited bulk e-mail or duplicative messages;
- Collect information about other visitors to our website without their consent or otherwise systematically extract data or data fields, including without limitation any financial data or e-mail addresses;
- Sell access to or the use of this website, including any content contained on, downloaded or accessed from this website;
- Redistribute any content, including financial data, provided by us in any manner whatsoever including by means of printed publication, fax broadcast, Web pages, e-mail, Web newsgroups or forums, or any other electronic or paper-based service or method;
- Intentionally alter the format in which financial data is provided by us or otherwise circumvent our regular interfaces to such data; and
- Embed or import any financial data provided by us into any currency information services (whether or not Web-based), data files or application software, including without limitation accounting and payroll systems.

By uploading, posting or otherwise transmitting through or to our website any content, you grant to us, our successors and assigns, a non-exclusive, world-wide, royalty free, perpetual, non-revocable license to use or distribute such content in any manner otherwise than as stated in our Privacy Policy above.


Copyright Information


The Site and the content within the Site are the property of Aulter or its suppliers and are protected by English and Welsh copyright laws and international treaty provisions. The compilation, organisation and display of the content as well as all software and inventions used on and in connection with this Site are the exclusive property of Aulter. Aulter reserves all rights in the Site and its content not specifically granted in any agreements with Aulter.


Trademark Information


Aulter marks, graphics, logos, page headers, button icons, scripts noted on this site are Aulter service marks, trademarks and trade dress and are the sole and exclusive property of Aulter .All other trademarks not owned by Aulter or its subsidiaries that appear on this site are the property of their respective owners, who may or may not be affiliated with, connected to, or sponsored by Aulter or its subsidiaries.

Products and Services offered by Aulter on this Site

Aulter offers products and services on the Site. When you obtain a product or service from Aulter on the Site, you accept the specific agreement applicable to that product or service. Your use of any such product or service offered on the Site is governed by the terms and conditions in the agreement for that product or service. Except as provided in that agreement, Aulter does not warrant that any product descriptions or content contained in this website is accurate, current, reliable, complete, or error-free.


Disclaimer


Aulter MAKES NO REPRESENTATIONS ABOUT THE SUITABILITY OF THE INFORMATION CONTAINED AND RELATED GRAPHICS PUBLISHED ON THIS WEBSITE FOR ANY PURPOSE. ALL SUCH INFORMATION AND RELATED GRAPHICS ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. Aulter HEREBY DISCLAIMS ALL WARRANTIES AND CONDITIONS WITH REGARD TO THIS INFORMATION, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. IN NO EVENT SHALL Aulter BE LIABLE FOR ANY SPECIAL, INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF INFORMATION AVAILABLE FROM THIS WEBSITE.

Indemnity

You agree to defend, indemnify, and hold harmless Aulter, employees, lawyers, and agents ("Indemnitees") against all claims, expenses, liabilities, losses, costs, and damages, including reasonable lawyer's fees, that the Indemnitees may incur in connection with your use of the Site or any hyperlinked Web site.