Introduction and About this Privacy Policy.

This privacy policy describes how Jama Software Inc. (variously referred to throughout as “Jama”, “we” or “our”) collects and uses the personal data you provide on our websites: www.hfipf.com, help.hfipf.com, community.hfipf.com, support.hfipf.com, dev.hfipf.com, rest.hfipf.com and any other subdomains of hfipf.com, and when you are in contact or interacting with Jama. It also describes the choices available to you regarding our use of information that identifies you (referred to in this privacy policy as personal data) and how you can access and update your personal data.


TRUSTe

1. Personal data collection and use by Jama

1.1 Jama collects personal data about individuals for its own use. Jama is the data controller in relation to this personal data and therefore if you are an individual who seeks to access, correct, amend, or delete your personal data held by Jama or you would simply like to understand how Jama uses your personal data you should first read this privacy policy. If you have any further questions or would like to request direct a query or request to Jama please contact us at privacy@hfipf.com.

1.2 This policy applies to the following groups of individuals:

  • business contacts;
  • individuals who have signed up for a free trial;
  • on premise customers;
  • online customers; and
  • website users.

2. The detail – the key information you should be aware of is set out below

2.1 How we obtain your personal data

You may provide us with your personal data as a result of entering into a subscription for one of our services or signing up to receive information on our website. We also obtain personal data from third parties such as sellers of marketing lists or our suppliers, which we refer to as “third party sources” or “suppliers” throughout this policy. Jama also has a referral scheme whereby another individual may give us your personal data because they believe you would be interested in our services.

2.2 What personal data we collect about you

We collect and use the following personal data:

  • Contact and Role details: name; job title; business email address; telephone number; company name;
  • Network and other information: IP address; cookie ID’s; and profile picture.

If you are an online customer or website user, we will also collect the following about you:

  • Account information: username; and password.

2.3 How we use your personal data

  1. We will collect, use and store the personal data to carry out our obligations arising from any contract that exists between us, for example to correspond with you in relation to your or your company’s subscription or trial of our services.
  2. Whether or not we have a contract with you or your company, we will collect, use and store the personal data listed to contact you about our services. Your personal information is processed in accordance with our legitimate interest to run, grow and develop our business. We have undertaken a balancing test to ensure that our legitimate interests are not outweighed by your interests or fundamental rights and freedoms which require protection of the personal information. You can ask us for information on this balancing test by using the contact details listed above.
  3. Whatever our relationship with you is, we may also collect, use and store your personal data for the following additional reasons:
    • to deal with any enquiries or issues you have about how we collect, store and use your personal data, or any requests made by you for a copy of the information we hold about you. Even if we do not have a contract with you, we may process your personal data for these purposes where it is in our legitimate interests for customer services purposes;
    • for internal corporate reporting, business administration, ensuring adequate insurance coverage for our business, ensuring the security of company facilities, research and development, and to identify and implement business efficiencies. We may process your personal data for these purposes where it is in our legitimate interests to do so;
    • to comply with any procedures, laws and regulations which apply to us – this may include where we reasonably consider it is in our legitimate interests or the legitimate interests of others to comply, as well as where we are legally required to do so;
    • to establish, exercise or defend our legal rights – this may include where we reasonably consider it is in our legitimate interests or the legitimate interests of others, as well as where we are legally required to do so;

2.4 How and why we share your personal data with others

  1. Non-sensitive personal data that is stored in our marketing tools, will be shared with suppliers of customer relationship management tools and marketing agencies for the purpose of pursuing our legitimate interest of growing our business.
  2. Any third parties with whom we share your personal data are limited in their ability to use your personal data unless outlined by us or for any purpose other than to provide services on our behalf to help with our business activities. We will always ensure that any third parties with whom we share your personal data are subject to privacy and security obligations consistent with this privacy policy and applicable laws.
  3. We will also disclose your personal data to third parties in the following circumstances:
    • where it is in our legitimate interests to do so to run, grow and develop our business:
    • if Jama is involved in a merger acquisition, dissolution, sale of all or portion of its assets, or other fundamental corporate transaction, we reserve the right to sell or transfer your information as part of the transaction in which case we may disclose your personal data to the prospective seller or buyer of such business or assets and/or to their professional advisers; or
    • if all or a substantial part of Jama’s or any of its affiliates’ assets are acquired by a third party, in which case personal data held by Jama will be one of the transferred assets;
    • if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, any lawful request from government or law enforcement officials and as may be required to meet national security or law enforcement requirements or prevent illegal activity;
    • in order to enforce or apply our terms and conditions or any other agreement or to respond to any claims, to protect our rights or the rights of a third party, or to prevent any illegal activity;
    • to protect the rights, property, or safety of Jama, our staff, our customers (including residents) or other persons. This may include exchanging personal data with other organizations for the purposes of fraud protection and credit risk reduction; or
    • when we believe in good faith that disclosure is necessary to protect your safety or the safety of others.
  4. All personal data is stored and processed in the US. This transfer is governed by the principles of Privacy Shield. Details of which can be found below.

3. EU-U.S. Privacy Shield and SWISS-U.S. Privacy Shield

3.1 Jama participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework. Jama is committed to subjecting all personal data received from European Union (EU) member countries and Switzerland, respectively, in reliance on each Privacy Shield Frameworks, to the Framework’s applicable Principles. To learn more about the Privacy Shield Frameworks, and to view our certification, visit the U.S. Department of Commerce’s Privacy Shield List. https://www.privacyshield.gov/list

3.2 Jama is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. Jama complies with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.

3.3 With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, Jama is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Jama may be required to disclose personal data in response to lawful requests by public ities, including to meet national security or law enforcement requirements.

3.4 If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://www.jamsadr.com/file-an-eu-us-privacy-shield-claim.

3.5 Jama has further committed to cooperate with EU data protection ities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such ities with regard to unresolved Privacy Shield complaints concerning human resources data transferred from the EU and Switzerland in the context of the employment relationship.

3.6 Under certain conditions, more fully described on the Privacy Shield website https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.

4. User Access and Choice

4.1 Jama respects your control over your information and, upon request Jama will provide you with information about whether we hold any of your personal data. If your personal data changes, or if you no longer desire our service, you may correct, update, amend, delete/remove, ask to have it removed from a public forum, directory or testimonial on our site or deactivate it by making the change on our member information page or by emailing our Customer Care at privacy@hfipf.com or by contacting us by telephone or postal mail at the contact information listed below. We will respond to your request within 30 days.

4.2 Jama sends out various marketing material including announcements about product updates, services or the company newsletter. You may opt-out at any time and choose to stop receiving periodic email by following the unsubscribe instructions included in these emails, accessing the email preferences in your account setting page or you can contact us at privacy@hfipf.com.

5. EU citizens’ rights

5.1 If you are an EU citizen, you have certain additional rights to object to our use of your personal data. In this context personal data means any data that we hold about you which identifies you as an individual, for example your name or email address, and information connected to this would be personal data.

5.2 Information on the rights of EU citizens is set out below. If you would like further information in relation to these or would like to exercise any of them, please contact us via email at privacy@hfipf.com at any time.

5.3 We will consider all such requests to exercise the rights listed below and provide our response within a reasonable period (and in any event within one month of your request unless we tell you we are entitled to a longer period allowed by applicable law). Please note, however, that certain personal data may be exempt from such requests in certain circumstances, for example if we need to keep using the information to comply with our own legal obligations or to establish, exercise or defend legal claims.

5.4 If an exception applies, we will tell you this when responding to your request. We may request you provide us with information necessary to confirm your identity before responding to any request you make.

5.5 Right of access

You have a right to access to any personal data we hold about you.  You can ask us for any of the following:

  • a copy of your personal data;
  • confirmation whether your personal data is being used by us;
  • details about how and why it is being used; and
  • details of what safeguards are in place if we transfer your personal data outside of the European Economic Area (“EEA”).

5.6 Right to update your personal data

You have a right to request an update to any of your personal data which is out of date or incorrect. We may need to verify the accuracy of the new information you provide us.

5.7 Right to ask us to delete your personal data

You have a right to ask us to delete any personal data which we are holding about you in certain specific circumstances. If you would like further information on these specific circumstances, please contact us.

If we receive a request from you we will also pass your request onto other recipients of your personal data unless that is impossible or involves disproportionate effort. We will also tell you who the recipients of your personal data are if you would like us to.

5.8 Right to restrict use of your information

You have a right to ask us to restrict the way that we process your personal data in certain specific circumstances. If you would like further information on these specific circumstances, please contact us.

If we receive a request from you, we will also pass your request onto other recipients of your personal data unless that is impossible or involves disproportionate effort. We will also tell you who the recipients of your personal data are if you would like us to.

5.9 Right to stop receiving marketing materials

You have the right to ask us to stop using your personal data for direct-marketing purposes. If you exercise this right, we will stop using your personal data for this purpose.

5.10 Right to data portability

You have the right to ask us to provide your personal data to a third-party provider of services.

This right only applies where we use your personal data on the basis of your consent or performance of a contract; and where our use of your information is carried out by automated means.

5.11 Right to object.

You have the right to ask us to consider any valid objections which you have to our use of your personal data where we process your personal data on the basis of our or another person’s legitimate interest.

6. California Consumer Privacy Rights

6.1 If you are a California resident, you have certain additional rights under the California Consumer Privacy Act (“CCPA”). This section explains your rights regarding your personal information and how we handle your personal information. Personal information, as defined by the CCPA, does not include publicly available information from government records and de-identified or aggregated consumer information. We will not share any personal information about you to the extent prohibited by applicable California law or to the extent your prior consent to share is required by applicable California law unless we have obtained such consent.

6.2 You may have the following rights under the CCPA:

The right to request access to your personal information. You have the right to request access to your personal information and obtain from us information regarding the disclosure of your personal information that has been collected by us in the prior 12-month period.

The right to data portability of your personal information: You have a right to request to receive your personal information, when provided electronically, in a readily-useable format.

The right to know about your personal information. You have a right to be notified about our collection and use of your personal information. You have the right to request and obtain information regarding the following:

  • The categories of personal information we collect or disclose
  • The sources from which the personal information was collected
  • The business or commercial purpose for collecting the personal information
  • The categories of third parties with whom we share or disclose personal information
  • The specific pieces of personal information we collected about you

The right to opt-out of sales of your personal information.  We do not sell your personal information.

The right to delete your personal information. You have the right to request the deletion of your personal information that we have collected from you, subject to certain conditions and limitations under the law.

The right to be free from discrimination. You have the right not to be discriminated against for exercising any of your rights under the CCPA, including by:

  • Denying goods or services to you;
  • Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties;
  • Providing a different level or quality of goods or services to you; or
  • Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.

We will not discriminate against you for exercising your CCPA rights.

6.3 Collection and Use of Personal Information. The personal information we collect about you and how we use it is detailed in Section 2 above. For purposes of the CCPA, the categories of personal information we may collect include:

  • Identifiers, such as your first name, last name, alias, postal address, phone number, email address, IP address, user name, password, unique device identifiers or other online identifiers
  • Personal Information, such as name, contact information, employment
  • Interaction with our software or apps such as usage data, type and version of operating system, hardware version, device settings, software types, battery and signal strength, screen resolution, device manufacturer and model, language, and Internet browser type and version
  • Geolocation Data, such as the location of your device or computer
  • Professional or Employment Related Information, such as job title and your business contact information

As detailed in Section 2.1 above, we may collect personal information about you from the following categories of sources:

  • Directly from you
  • Through your device, product operations, or browser
  • Our affiliates and business partners
  • Third parties
  • Data verification services
  • Marketing vendors and advertising networks
  • Social media
  • Our website and services

We may use and disclose the categories of personal information we collect from and about you consistent with the business purposes detailed in Section 2.3 above. Please refer to Section 2.4 above for the categories of third parties with whom we share your personal information.

6.4 Making Requests. In order to exercise any of your rights as a California resident under the CCPA, please contact us via email at privacy@hfipf.com, or by mail at Jama Software, 135 SW Taylor St., Suite 200, Portland, OR 97204, or by calling us at or calling us at 877-703-0763. When submitting a request, please include your name, email address, account information, and purpose of the request. In compliance with CCPA, we will require certain identifying information from you to verify your request. You may designate an ized agent to request the exercise of any of these rights on your behalf if you provide us with written ization or a power of attorney signed by you. If you are using an ized agent, such requests are subject to the same verification criteria.

Requests for personal information are limited to two requests in any 12-month period. We will respond to verified requests with the required information within 45 days of receiving your verified request. If we need additional time to respond, we will let you know in advance. There may be circumstances where certain information is exempt from requests under applicable law, and we may be required to continue to retain or share portions of your personal information to comply with regulatory or legal obligations.

7. Information Related to Data Collected for our Clients

7.1 Jama collects information under the direction of its clients, and in these instances, Jama has no direct relationship with the individuals whose personal data it processes. If you are a customer of one of our clients and would no longer like to be contacted by one of our clients that use our service, please contact the client that you interact with directly.

7.2 If you wish to access, correct, amend, or delete personal data which we hold on the direction of a client you should contact that client (the data controller) directly. If the client requests Jama to remove, amend or correct your personal data, we will respond to their request within 30 days of receiving it from the client.

7.3 We will retain personal data we process on behalf of our clients for as long as we are instructed to by the relevant client.

8. Tracking Technologies / Cookies

8.1 Jama and our analytics and service providers use cookies or similar technologies for the purpose of monitoring application usage and performance. These technologies are used in analyzing trends, administering the site, tracking users’ movements around the site and to gather demographic information about our user base as a whole. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis.

8.2 We use cookies to remember users’ settings and session information. Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our site, but your ability to use some features or areas of our site may be limited.

8.3 Our website does not respond to “Do Not Track” (“DNT”) signals.

9. Log Files

9.1 As is true of most web sites, we gather certain information automatically and store it in log files. This information includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and clickstream data.

9.2 We may combine this automatically collected log information with other information we collect about you. We do this to provide support for the services we offer.

10. Advertising

We partner with a third party to either display advertising on our website or to manage our advertising on other sites. Our third-party partner may use technologies such as cookies to gather information about your activities on this website and other sites in order to provide you advertising based upon your browsing activities and interests. If you wish to not have this information used for the purpose of serving you interest-based ads, you may opt-out by clicking here (or if located in the European Union click here). Please note this does not opt you out of being served ads. You will continue to receive generic ads.

11. Security

11.1 The security of your personal data is important to us. When you enter your login information to our platform, we encrypt the transmission of that information using transport layer security (TLS).

11.2 We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once we receive it. No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security. If you have any questions about security on our Web site, you can contact us at privacy@hfipf.com.

12. Links to 3rd Party Sites

Our Site includes links to other Web sites whose privacy practices may differ from those of Jama. If you submit personal data to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any Web site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services.

13. Blog

Our Web site offers publicly accessible blogs. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal data from our blog, contact us at privacy@hfipf.com. In some cases, we may not be able to remove your personal data, in which case we will let you know if we are unable to do so and why.

14. Community Forum

Our forum is managed by a third-party application that may require you to register to post a comment. We do not have control of the information posted to the forum. You will need to contact or login into the third-party application if you want the personal data that was posted to the comments section removed. To learn how the third-party application uses your information, please review their privacy policy.

15. Testimonials

We display personal testimonials of satisfied customers on our site in addition to other endorsements. With your consent we may post your testimonial along with your name. If you wish to update or delete your testimonial, you can contact us at privacy@hfipf.com.

16. Social Media Widgets

Our Web site includes Social Media Features, such as the Facebook Like button. These Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Site. Your interactions with these Features are governed by the privacy policy of the company providing it.

17. Children’s Privacy

Our website is not directed to nor are our services offered to minors. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal information from anyone under the age of 18, we will take steps to delete and destroy this information as soon as reasonably possible.

18. Changes to This Policy

We may update this privacy policy to reflect changes to our information practices. If we make any material changes, we will update this Site prior to the changes becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

19. Product Usage Data

Our product team is committed and dedicated to providing the absolute best Jama experience. To support this initiative, we might access your anonymized usage data. Analysis of this data will inform our data-driven product development. Please see the Usage Data FAQ for more information.

20. Questions?

Jama Software
135 SW Taylor Suite 200
Portland, OR 97204

Phone Number: (877) 703-0763
Email us: privacy@hfipf.com