Ohalo Privacy Policy

At Ohalo we are dedicated to protecting your data and respecting your privacy. This policy sets out how we do that when you interact with us.



Introduction

This policy applies if you are a customer of ours or you are using our website. In either circumstance, we are the registered data controller (ICO reference ZA339181).


Your data

When you visit our website or use our services, we receive data from you. This data is either (i) provided directly by you (e.g. contact details) or is (ii) passively collected by us (e.g. how long you spend on a page).

The data that we receive from you falls into several different categories that reflect the different channels through which it is received:

Your Data: categories and channels

  • Contact and log-in details

    You provide this data to us when you fill out forms on our website, such as when you sign-up to our services. Your data here can include your name, e-mail address, company profile, and log-in details.

  • Data for analysis or governance by Ohalo’s products

    You provide this data to us when you submit a datasource for use with the Data X-Ray or Data Protection Router. The data that you provide here is up to you but typically might include employee or customer records.

    Once your data has been parsed by an Ohalo product (for example once a datasource has been scanned by the Data X-Ray) our copy of the data, technically only ever retained momentarily on our system’s memory, is immediately deleted. We do not retain custody past that point.

  • Billing and financial details

    You provide this data to us when you pay for one of our products. Your data here could include your bank account number, sort code, credit/debit card details, and billing address.

  • Data on how you use Ohalo’s website and platform

    We collect this data from you through analytics tools when you use our website or platform. Your data here can include the path you have taken through our site, the products you have viewed, how long you have spent on one of our pages, what you have done on those pages, the response time of those pages, download errors and the methods you have used to browse away from a page.

  • Technical data that identifies you

    We collect technical data from you when you use our website or platform. Your data here typically includes your IP address, browser type and version, time zone setting, browser plug-in types, geolocation information, operating system and version.


Our use of your data

We use your data for a limited number of business reasons and only where we have a legal basis to do so.

The legal bases which allow us to use your data are:

  • Consent

    You consent to us processing your data for a specific purpose.

  • Contract

    We are required to process your data either:

    • under a contract between you and us; or

    • in anticipation of a contract between you and us.

  • Legitimate interests

    We need to process your data for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests. Those legitimate interests are:

    • analysing your use of our website and/or platform;

    • providing and improving Ohalo’s services;

    • modifying our communications and services for you;

    • assessing the effectiveness of our marketing campaigns; and

    • enhancing our data security.

    In each case, these legitimate interests are only valid if they are not outweighed by your rights and interests. Further information about the balancing test that we conduct in establishing a legitimate interest is available on request from [email protected]

Business reason

The business reasons for which we use your data are:

  • Providing you with our service

    We use your data to provide you with our service. Examples include login and authentication procedures, scanning a datasource using the Data X-Ray, remembering your settings, and processing payments.

    Our legal bases for this business reason are i) contract and ii) legitimate interest.

  • Improving our service

    We use your data here to help improve our service. Examples include feedback platforms, testing new features, traffic optimisation and profiling.

    Our legal bases for this business reason are i) contract and ii) legitimate interest.

  • Customer support

    We use your data here to provide you with customer support. Examples include notifying you of changes to our service or solving issues via phone/email/live chat support.

    Our legal basis for this business reason is i) contract.

  • Marketing

    We use your data here to market our services to you but only when:

    • you have consented to us doing so; or

    • we assess that there is a legitimate interest in doing so.

    A circumstance in which we would assess there to be a legitimate interest in marketing to you is where:

    • you use an existing Ohalo product;

    • we introduce a new, complementary product that is supportive of the product that you currently use; and

    • we have a close, ongoing business relationship.

    Marketing examples where we might use your data include sending you emails or messages about new features, products, services, and/or content.

    Our legal bases for this business reason are i) consent and ii) legitimate interest.


Your rights over your data

  • Access

    You have the right to access the data that we have received from you. We will provide you with your data within one month of your request, unless doing so would adversely affect the rights and freedoms of others (e.g. confidentiality).

    Your right of access also includes supplementary information that you can request for us on:

    • categories of data that we are processing;

    • purposes of data processing;

    • categories of third parties to whom the data may be disclosed;

    • how long the data will be stored (including the criteria used to determine that period); and

    • your other rights regarding our use of your data

  • Corrections

    You have the right to make us correct inaccurate personal data about you.

  • Profiling/automated decisions

    You can object to us using your data for profiling you or making automated decisions about you.

    Examples of profiling and automated decision making that we may use are:

    • modifying our service to your requirements; and

    • determining whether we should let you know information that might be relevant to you (for example, tailoring emails to you based on your behaviour).

  • Portability

    You have the right to port your data to another service. Upon request, we will give you a copy of your data in CSV or JSON format.

  • Erasure

    You have the right to be “forgotten” by us. You can do this by asking us to erase any personal data that we hold about you.

  • Complaint

    You have the right to make a complaint about our use of your data.

    If you are unsatisfied with your data and/or privacy experience with Ohalo, please tell us first so that we have a chance to address your concerns. Failing that, you can complain to the United Kingdom’s national data protection authority, the Information Commissioner’s Office, by calling 0303 123 1113 or emailing [email protected]


Our data security

We have physical, electronic and managerial procedures to safeguard and secure the information we collect. More information is available upon request from [email protected]

However, please remember that:

  • you provide your data at your own risk;

  • you are responsible for your username and password; and

  • If you believe that you have suffered a privacy breach, please contact us immediately at [email protected]


Location

The personal data we collect is processed at our office in London and in the data processing facilities operated by the third parties identified in Schedule 1 to this policy, as set out below.

By submitting your personal data, you agree to this transfer, storing or processing by us. If we transfer or store your information outside the EEA in this way, we will take steps to ensure that your rights continue to be protected as outlined in this policy.


Length

We will archive and stop actively using any personal identifiable information about you within 6 months from the last time you used Ohalo. We will delete your personal data from our archives no later than 6 years from the last time you used Ohalo or as agreed with you in a separate contract.


Third party partners

Tech businesses often use third parties to help them host their application, communicate with customers, power their emails etc. We partner with third parties who we believe are the best in their field at what they do.

When we do this, sometimes it is necessary for us to share your data with them in order to get these services to work well. Your data is shared only when strictly necessary and according to the safeguards and good practices detailed in this data and privacy policy.

Details on our third party partners can be found below in Schedule 1 to this policy, as set out below.


Cookies

Cookies are items of data stored directly on the computer that you are using. Cookies allow us to collect information such as browser type, time spent using Ohalo’s services, pages visited, language preferences, and other anonymous traffic data.

We and our partners use cookies for security purposes, to facilitate navigation, to display information more effectively, and to personalize your experience while using Ohalo’s services.

You can block cookies by activating a setting on your browser allowing you to refuse the setting of cookies. You can also delete cookies through your browser settings. If you use your browser settings to disable, reject, or block cookies (including essential cookies), certain parts of our website will not function fully. In some cases, our website will not be accessible at all. Please note that where third parties use cookies we have no control over how those third parties use those cookies.


Contact point

Ohalo’s contact point for queries on this data and privacy policy, or data protection and privacy issues more widely, is Ed Goold and his details are as follows:

[email protected]

Ed Goold
Ohalo Limited
44 Great Marlborough Street
London
W1F 7JL

+44 (0) 20 8133 7236
+44 (0) 7909 525 871


Updates

Whenever we change our data and/or privacy practices we will update this policy and notify you directly of the changes that we have made. If you would like further information on updates, please contact [email protected]


Schedule 1 - Ohalo Third Party Partners

Ohalo uses third party partners to provide you with our services. These partners receive your data in a limited number of circumstances for specific uses.

Major Partners

The specific details of our major partners and their use of your data are set out below:

Purpose Processor Data Use Location
Infrastructure - web hosting AWS Inc
  • Contact and log-in details
  • Data for analysis or governance by Ohalo’s products
  • Technical data that identifies you
AWS is a web hosting provider: we use it to store data securely in the cloud EU
Website Analytics (Google Analytics) Google Inc
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
Google Analytics is a website analytics service: we use it track your use of Ohalo, and to prepare reports on user activity US
Communications - email provider (Gmail) Google Inc
  • Contact and log-in details
  • Technical data that identifies you
Gmail is an email service provider: we use it for sending, storing and tracking emails US
Communications - document store (Google Drive) Google Inc
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
Google Drive is a file storage service: we use it to manage our internal files, and these can contain data on our users. US
Communications - customer support Intercom Inc
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
Intercom is a customer support platform: we use it for customer communications, user interaction and helpdesk assistance. US
Communications - team communication Slack Technologies Inc
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
Slack is a team communication platform: we use it internally to collaborate on and discuss our products and services. US
Marketing - email (MailChimp) The Rocket Science Group LLC d/b/a MailChimp
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
  • Cookies
MailChimp is an email marketing platform: for those who have consented, we use MailChimp to send you marketing messages notifying you of improvements or changes to Ohalo. US
Marketing - inbound Hubspot Inc
  • Contact and log-in details
  • Data on how you use Ohalo’s website and platform
  • Technical data that identifies you
  • Cookies
Hubspot is an inbound marketing platform: for those who have consented, we use Hubspot to send you customer communications and other marketing messages. US
Payments - processing platform Stripe Inc
  • Contact and log-in details
  • Billing and financial details
  • Cookies
Stripe is a payments processing platform: we use it to process Ohalo payments. EU and US


Minor Partners - Categories

Ohalo also uses the following categories of third party, external processors:

Purpose Category of Processor Data Use Location
Development - software Development Consultants
  • Contact and log-in details
  • Data for analysis or governance by Ohalo’s products
  • Billing and financial details
  • Data on how you use Ohalo's website and platform
  • Technical data that identifies you
Ohalo uses development consultants who help us build features for our products and provide customer support. EU, US and Russia