Privacy Policy
Last Updated : November 8th, 2018
This Privacy Policy explains the information that Impactasaurus collects when you use its products and services, how that information is used, with whom it may be shared, and your privacy choices.
By registering for, or using our services, you accept this Privacy Policy, which is part of our Terms of Use.
Who Are "You"
We refer to "you" a lot in this Privacy Policy. To better understand what information is most relevant to you, see the following definitions.
- Accountholders: You hold an account with Impactasaurus. You have the ability to create questionnaires and analyse data. You ask beneficiaries to complete questionnaires.
- Beneficiary: You do not hold an account with Impactasaurus. You complete questionnaires witin the system, either directly or indirectly through the accountholder.
Data We Collect About You
We collect information about you when you use our services. In addition, third parties may collect information about you when you use our services. Collected information may include or reflect personal information that could identify you, as well as non-personal information. We refer to your information as "your data" for short.
Account Information
To create an account, you must provide a valid email address, your name and a password
Content
Accountholders may create questionnaires and record questionnaire answers from their beneficiaries. Tags can be stored against questionnaire responses, allowing filtering.
As a beneficiary, your questionnaire answers are collected.
Automatically-Collected Information
We automatically collect certain types of data when you use our services, regardless of whether you have an account. This data includes:
- IP address
- technical information about your device (e.g., browser type, operating system, basic device information)
- the web page you visited or search query you entered before reaching us
- your activities on our website
Information Collected by Third Parties
Some third parties may collect data about you when you use our services. This includes:
- Feedback to help us improve our service
- Crash reports to record when something goes wrong with our service
- Analytics to help us understand the usage of our service
How We Use Your Data
We may use your data for the following purposes:- Operating our services: We use your data to provide our services and provide customer support.
- Improving our services: We use your data to understand how our services are being used and how we can improve them. In general, we analyze aggregated data, rather than specific user data. We may, however, need to analyze a specific case to address a specific problem (e.g., a bug that affects only a few accounts).
- Legal compliance: We use your data where we are legally required to do so. For example, we may need to gather your data to respond to a subpoena or court order.
- Protecting your information: Where appropriate, we may anonymize, backup, and delete certain data.
- Identification and authentication: We use your data to verify you when you access your account.
- Communicating with you: We use your data when we communicate with you (e.g., when we respond to a customer support or other inquiry).
- Customizing your experience: We use your data to personalize the service to you. This may include remembering your preferences for visualisations or aggregations.
With Whom We Share Your Data
We share your data with third parties as follows:- Analytics: We share your data with Google Analytics who provide analytics showing how customers are using our services.
- Data Storage: We securely store your data with MongoDB's Atlas.
- Feedback: We use Delighted to collect user feedback from accountholders.
- Error Reports: We use Sentry to capture failures within our application to allow us to diagnose and fix problems.
- Aggregated or anonymized information: We may publicly disclose non-personal aggregated or anonymized information.
For accountholders:
- Content: Any questionnaires or questionnaire responses from beneficiaries are shared with all accountholders within your organisation.
- Authentication: We use Auth0 to store account information and authenticate users.
- CRM: Hubspot is used to communicate with accountholders.
For beneficiaries:
- Responses: Any answers provided to a questionnaire are shared with all accountholders belonging to the organisation which requested you complete the questionnaire. This applies if you directly completed the questionnaire within Impactasaurus, or indirectly via an accountholder.
We use reasonable efforts to vet vendors for their privacy and data security practices. We require that such vendors agree to protect the data we share. We do not allow any third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instruction.
Data Retention
We retain your data for as long as you have an account. When you close an account, we will delete your personal information. We may retain logs of automatically collected information (for internal analytics); your email address and communications with you. When we no longer have a business reason for retaining data, we will delete or anonymize it.
We retain questionnaires and questionnaire responses for as long as the organisation is registered. When an organisation wishes to stop using our services, we will delete this content.
We retain deleted questionnaires and questionnaire responses in case you wish to reverse the deletion.
If we receive legal process pertaining to your account, we will retain your data for as long as we in good faith believe is necessary to comply with the legal process. Similarly, if we believe that your account has been involved in wrongdoing, we may preserve your data to defend or assert our rights.
Protecting Your Information
We use technical, and organizational security measures to safeguard your data from unauthorized or accidental disclosure. Despite these efforts, no information system can be 100% secure, so we cannot guarantee the absolute security of your information. Users also have a role to play in keeping their data safe. We encourage you to use a unique and hard-to-guess password for your account and to not share it with others. You should only add users to your organisation who you know and trust. You should monitor your account regularly. If you believe that someone has gained access to your account without your permission, please contact us immediately so that we can investigate.Communication
By creating an account, you consent to receive commercial emails from us. This includes newsletters. You may opt out from commerical emails by clicking the unsubscribe link in the email. Please note, you will continue to receive transactional emails from us (e.g., emails providing information about your account).Your Privacy Rights
We enable you to make numerous choices about your data:- You may choose not to provide us with certain information. For example, you may choose not to create an account or not to create a questionnaire.
- You may change or correct information we hold on you.
- You may opt out of receiving commercial emails from us.
- You may export your data or request we transfer it to another service provider.
- You may close your account.
- You may delete your data.
- You may contact us and request what information we hold on you.
Updates
We may modify this Privacy Policy from time to time. We will post any modified version of our Privacy Policy at https://impactasaurus.org/privacy. If we change the Privacy Policy in a way that materially lessens our commitments to you, we will provide notice to registered users by email or other methods.How to Contact Us
For any questions, inquiries, or complaints relating to your privacy, please contact us at: