ORM Technologies, LLC (“ORM,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you interact with our websites, applications, communications, and other services that link to this Privacy Policy.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal information ORM collects through:
- ORM’s public websites;
- ORM applications that link to this Privacy Policy;
- Services, platforms, applications, and APIs that a user or organization authorizes ORM to access;
- Marketing, sales, support, and business communications;
- Events, demonstrations, and webinars; and
- Other online or offline interactions with ORM.
The information ORM collects and uses depends on the context:
- Website Information generally includes business contact information, website activity, form submissions, cookies, and marketing interactions.
- Application Information generally includes user account information, authentication information, application activity, and information needed to operate, secure, and support an ORM application.
- Connected Service Data means information ORM receives from a third-party service, platform, application, or API at the direction of a user or organization.
- Customer-Controlled Information means information ORM processes on behalf of a customer through ORM’s products or services.
Connected Service Data may also be Customer-Controlled Information when ORM receives or processes it on behalf of a customer.
For Customer-Controlled Information, the customer generally determines why and how the information is processed, and ORM processes the information under its agreement with the customer.
This Privacy Policy does not govern the independent privacy practices of ORM customers or third-party services. Requests concerning Customer-Controlled Information should ordinarily be directed to the customer that controls the information.
2. Information We Collect
The information we collect depends on how you interact with ORM.
2.1 Website Information
When you visit an ORM website, submit a form, attend an event, or communicate with ORM, we may collect:
- Name;
- Business email address;
- Telephone number;
- Job title;
- Employer or organization;
- Information submitted through forms;
- Communications with ORM;
- Event, webinar, or demonstration registrations;
- Marketing preferences; and
- Other information you choose to provide.
We and our service providers may also automatically collect:
- Internet Protocol address;
- Browser and device type;
- Operating system;
- Pages viewed;
- Referring pages;
- Dates and times of access;
- Website activity; and
- Information collected through cookies and similar technologies.
2.2 Application Information
When you use an ORM application, we may collect:
- Name;
- Business email address;
- Employer or organization;
- Account and login information;
- User role and permissions;
- Authentication information;
- Application activity;
- Technical and diagnostic information;
- Support communications; and
- Other information needed to operate, secure, and support the application.
2.3 Connected Service Data
An ORM application may allow a user or authorized administrator to connect an account, application, or service provided by a third party.
When a connection is authorized, ORM may receive information within the permissions presented to and approved by the user or the user’s organization.
Depending on the connected service and the permissions granted, Connected Service Data may include:
- Name, email address, and account identifiers;
- Organization and account information;
- Authentication and authorization information;
- Advertising, campaign, and marketing information;
- Customer relationship management information;
- Sales, opportunity, pipeline, and account information;
- Files, records, and other information authorized by the user or organization;
- Usage, activity, and performance information; and
- Other information the user or organization expressly authorizes ORM to access.
Connected Service Data may be received through APIs and integrations provided by advertising, marketing, customer relationship management, and other technology platforms.
The specific information available to ORM depends on the connected service, the permissions authorized, and the information maintained in the connected account.
ORM requests access only to Connected Service Data reasonably necessary to provide the applicable application or integration functionality.
2.4 Information From Other Sources
We may receive business contact and professional information from:
- Publicly available sources;
- Business partners;
- Event sponsors;
- Social media and professional networking services;
- Data and marketing service providers;
- Customers and prospective customers; and
- Other parties permitted to provide the information.
3. How We Use Personal Information
We may use personal information to:
- Provide, maintain, support, and improve our websites, applications, products, services, and integrations;
- Create and manage user accounts;
- Authenticate users;
- Establish and maintain authorized integrations;
- Retrieve, process, organize, analyze, display, report on, or synchronize information as directed by a user or organization;
- Produce analytics, reports, recommendations, forecasts, and other application outputs;
- Respond to inquiries and provide customer support;
- Communicate about products, services, demonstrations, events, and other business matters;
- Personalize website, application, and marketing experiences;
- Analyze usage, performance, and business trends;
- Develop and improve ORM products and services;
- Protect against fraud, misuse, security incidents, and unlawful activity;
- Enforce our agreements and protect our rights;
- Comply with applicable legal obligations; and
- Complete a merger, acquisition, financing, reorganization, sale, or similar business transaction.
Where applicable law requires a legal basis for processing, ORM may process personal information based on consent, performance of a contract, compliance with a legal obligation, or ORM’s legitimate business interests.
4. How We Handle Connected Service Data
This section applies to information ORM receives through an integration authorized by a user or organization.
4.1 Authorization and Access
ORM accesses Connected Service Data only after a user or authorized organization administrator approves the applicable connection.
The permissions presented during the authorization process determine the categories of information the ORM application may access.
A user or organization may be able to manage, disconnect, or revoke an integration through:
- The applicable ORM application;
- The connected account;
- The connected service’s account or administrative settings; or
- A request submitted to ORM.
4.2 Use of Connected Service Data
ORM uses Connected Service Data only as reasonably necessary to:
- Authenticate or identify users;
- Establish and maintain an authorized connection;
- Retrieve information requested by the user or organization;
- Import, store, process, organize, analyze, display, report on, or synchronize authorized information;
- Provide the features and functionality of the ORM application;
- Produce analytics and outputs requested by the user or organization;
- Maintain the security, reliability, and performance of the application or integration;
- Respond to support requests and troubleshoot problems;
- Comply with documented customer instructions; and
- Meet applicable legal or contractual obligations.
ORM does not use Connected Service Data for targeted or interest-based advertising.
ORM does not use Connected Service Data to create advertising profiles unrelated to the functionality requested by the user or organization.
4.3 Disclosure of Connected Service Data
ORM does not sell Connected Service Data.
ORM may disclose Connected Service Data only:
- To service providers that process the information on ORM’s behalf and only as necessary to provide, secure, maintain, or support the applicable application or integration;
- To the customer, user, or organization that authorized the integration;
- At the direction of the user or organization;
- As required by applicable law or valid legal process;
- To investigate fraud, abuse, security threats, or violations of applicable agreements; or
- In connection with a merger, acquisition, financing, reorganization, sale, or similar business transaction, subject to applicable law and continued protection of the information.
ORM does not disclose Connected Service Data to data brokers or information resellers.
ORM does not disclose Connected Service Data to advertising platforms for targeted or interest-based advertising.
4.4 Connected Service Requirements
ORM’s access, use, storage, transfer, and disclosure of Connected Service Data will be consistent with:
- The permissions authorized by the user or organization;
- The functionality of the applicable ORM application or integration;
- Applicable agreements with ORM customers;
- Applicable law; and
- Applicable terms and user-data policies of the connected service, including limited-use requirements where applicable.
ORM’s use and transfer of information received through connected services will comply with the applicable provider’s user data policies and limited-use requirements, including the Google API Services User Data Policy where applicable.
If a connected service imposes more restrictive requirements on information received from that service, ORM will handle the information in accordance with those requirements.
4.5 Retention of Connected Service Data
ORM retains Connected Service Data only for as long as reasonably necessary to provide the applicable application or integration functionality, unless a longer retention period is required or permitted by law.
ORM may retain Connected Service Data as reasonably necessary to:
- Provide functionality requested by the user or organization;
- Maintain an authorized integration;
- Complete processing initiated by the user or organization;
- Produce or maintain requested reports, analytics, or application outputs;
- Provide customer support;
- Maintain security and prevent fraud or misuse;
- Meet contractual or legal obligations; or
- Resolve disputes and enforce applicable agreements.
The retention period may vary based on:
- The type of information;
- The purpose for which the information was obtained;
- The application and integration configuration;
- The customer’s documented instructions;
- The duration of the authorized connection or customer relationship;
- Security and support requirements;
- Contractual requirements; and
- Applicable legal obligations.
When Connected Service Data is no longer reasonably necessary for these purposes, ORM will delete or de-identify it, subject to the exceptions and backup processes described in this Privacy Policy.
4.6 Deletion of Connected Service Data
A user or authorized customer administrator may request deletion of Connected Service Data by contacting ORM using the information in Section 15.
Where available, users may also disconnect or revoke an integration through the ORM application or the connected service’s account settings.
Revoking or disconnecting an integration prevents ORM from obtaining additional information through the revoked authorization. Revocation or disconnection does not necessarily delete information previously obtained through the integration.
When ORM receives a valid deletion request, or when deletion is otherwise required, ORM will delete or de-identify the applicable Connected Service Data within a reasonable period, subject to:
- Verification of the requestor’s identity or authority;
- The instructions of the customer that controls the information;
- The operation of the applicable application or integration;
- Technical backup and recovery cycles;
- Existing contractual obligations; and
- Information ORM is required or permitted to retain for legal, security, fraud-prevention, audit, dispute-resolution, or enforcement purposes.
Information remaining in backups will remain protected and will be removed or overwritten through ORM’s normal backup lifecycle.
Where ORM processes Connected Service Data on behalf of a customer, ORM may direct the request to the customer or process the request according to the customer’s documented instructions.
5. Customer-Controlled Information
ORM customers may use ORM products and services to process information from their own systems or from services they authorize ORM to access.
Customer-Controlled Information may include:
- Sales and marketing information;
- Customer and prospect information;
- Customer relationship management records;
- Account and contact information;
- Opportunity, pipeline, forecast, and revenue information;
- Campaign and advertising information;
- Product usage and operational information;
- Communications and activity records;
- Information obtained through customer-authorized integrations; and
- Analytics, models, reports, and outputs derived from customer information.
For Customer-Controlled Information:
- The customer determines why and how the information is processed;
- ORM processes the information on the customer’s behalf;
- ORM’s processing is governed by its agreement with the customer;
- The customer is responsible for providing required notices and obtaining required permissions; and
- Privacy requests should generally be directed to the customer that controls the information.
ORM may assist its customers with privacy requests as required by applicable agreements and law.
6. How We Disclose Personal Information
ORM may disclose personal information as described below.
6.1 Service Providers
We may use service providers to perform functions such as:
- Hosting and infrastructure;
- Data processing;
- Analytics;
- Communications;
- Security;
- Payment processing;
- Customer support;
- Marketing assistance; and
- Professional services.
These providers may process personal information only as necessary to provide services to ORM or as otherwise permitted by applicable law.
6.2 Business Partners
We may disclose information to a business partner when you:
- Register for a jointly sponsored event;
- Request a partner-related offering;
- Participate in a joint program; or
- Otherwise authorize the disclosure.
6.3 Legal and Security Recipients
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law;
- Respond to valid legal process;
- Protect ORM’s rights or property;
- Protect the safety of users or others;
- Investigate misconduct;
- Prevent fraud; or
- Respond to security incidents.
6.4 Business Transaction Recipients
Information may be disclosed or transferred as part of an actual or proposed:
- Merger;
- Acquisition;
- Financing;
- Reorganization;
- Bankruptcy;
- Sale of assets; or
- Similar business transaction.
ORM does not sell Connected Service Data.
ORM does not sell personal information in exchange for money.
7. Cookies and Similar Technologies
ORM and its service providers may use cookies and similar technologies to:
- Operate and secure our websites;
- Remember user preferences;
- Understand website usage and performance;
- Improve our websites and communications; and
- Measure the effectiveness of marketing activities.
You may control cookies through available website controls or your browser settings. Disabling certain cookies may affect website functionality.
Where required by applicable law, ORM will request consent before using nonessential cookies.
8. Data Retention
ORM retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
In determining the appropriate retention period, ORM may consider:
- The reason the information was collected;
- The nature and sensitivity of the information;
- The duration of the business or customer relationship;
- The duration of an authorized application or integration connection;
- Contractual requirements;
- Security and fraud-prevention needs;
- Applicable statutes of limitation; and
- Legal, tax, accounting, and regulatory obligations.
When personal information is no longer reasonably necessary, ORM will delete, de-identify, or aggregate it, subject to applicable law and normal backup and recovery processes.
You may request deletion of personal information by contacting ORM using the information in Section 15.
9. Data Security
ORM uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction.
These safeguards may include, as appropriate:
- Access controls;
- Authentication;
- Encryption;
- Logging and monitoring;
- Personnel practices;
- Security testing;
- Backup and recovery procedures; and
- Vendor-management procedures.
No system or transmission method can be guaranteed to be completely secure.
10. Your Privacy Choices and Rights
You may unsubscribe from ORM marketing emails by using the unsubscribe link included in the message.
Depending on where you reside and subject to applicable exceptions, you may have the right to request that ORM:
- Provide access to certain personal information;
- Correct inaccurate personal information;
- Delete certain personal information;
- Provide a portable copy of certain personal information;
- Restrict or object to certain processing; or
- Withdraw consent where processing is based on consent.
You may submit a privacy request by contacting ORM using the information in Section 15.
ORM may take reasonable steps to verify your identity and authority before processing a request.
ORM will respond within the period required by applicable law.
ORM will not unlawfully discriminate against an individual for exercising an applicable privacy right.
If ORM processes your information on behalf of one of its customers, ORM may direct your request to that customer or assist the customer in responding.
11. International Processing
ORM and its service providers may process information in the United States and other countries where they operate.
When required by applicable law, ORM uses appropriate legal mechanisms and safeguards for international transfers of personal information.
12. Children’s Privacy
ORM’s websites, applications, products, and services are intended for business users and are not directed to children under 13.
ORM does not knowingly collect personal information from children under 13.
If you believe a child has provided personal information to ORM, please contact us so that we can review and address the matter.
13. Third-Party Services
Our websites and applications may contain links to or integrations with third-party services.
ORM does not control the independent privacy, security, or content practices of third-party services. Your use of a third-party service may also be subject to that provider’s terms and privacy practices.
This section does not limit ORM’s responsibilities for Connected Service Data after ORM receives that information through an authorized integration.
14. Changes to This Privacy Policy
ORM may update this Privacy Policy from time to time to reflect changes in:
- Its websites;
- Its applications;
- Its integrations;
- Its data practices; or
- Applicable legal obligations.
When ORM makes changes, it will update the “Last Updated” date above.
When required by applicable law, ORM will provide additional notice or obtain consent.
15. Contact ORM
Questions or requests regarding this Privacy Policy, including requests to access, correct, or delete personal information or Connected Service Data, may be directed to:
ORM Technologies, LLC
privacy@orm-tech.com