ERGOPS GLOBAL PRIVACY NOTICE
Version 1.0
1. About This Privacy Notice
ErgOps respects the privacy of individuals who use our website, platform, applications, integrations and related services.
This Global Privacy Notice explains how ErgOps collects, uses, stores, shares and protects personal information when you create an account, join an organization workspace, use the ErgOps platform, contact us or otherwise interact with our services.
Depending on where you are located or where your organization operates, additional regional privacy notices or rights may apply. Where applicable, those regional notices supplement this Global Privacy Notice.
This Privacy Notice is intended to provide information about our processing activities. It is not a request for general consent to process personal information.
2. Who Is Responsible for Your Personal Information?
For personal information collected directly by ErgOps for purposes such as account creation, authentication, platform administration, security, support and service communications, ErgOps acts as the organization responsible for determining how and why that information is processed.
In some situations, an organization using ErgOps may upload or otherwise provide personal information about its employees, suppliers, contractors or other individuals.
Where ErgOps processes that information solely on the instructions of the organization using our services, that organization may be responsible for determining the purposes of the processing and ErgOps may act as a service provider or processor on its behalf.
The applicable roles may also be governed by a separate Data Processing Agreement.
3. Personal Information We Collect
We may collect personal information that you provide directly to us when you create or manage an ErgOps account.
This may include your name, business email address, business telephone number, organization name, job role, workspace role, access permissions and related account information.
We may also process information about your organization membership, assigned facilities, permissions, onboarding status and preferences within the platform.
When you accept contractual terms or review privacy information, we may maintain records such as the relevant document version, date and time of the action and the associated account or organization.
When you use ErgOps, technical and security information may also be generated automatically. This may include IP address, authentication events, session information, browser or device information, access logs, security events, error information and records of important actions performed within the platform.
If you contact ErgOps for support, we may process your communications, support requests, attachments and other information you choose to provide.
ErgOps is not designed to require sensitive personal information as part of the ordinary account onboarding process. Users should avoid providing sensitive personal information unless it is specifically required for an authorized ErgOps feature.
4. Organization and Business Information
ErgOps may collect information about organizations using the platform, including company name, company type, industry, business activity, employee-size range, facilities and operational information.
Information relating solely to a company or other legal entity may not constitute personal information under every applicable privacy law.
However, where such information identifies, relates to or can reasonably be associated with an individual, sole trader or other natural person, we treat it as personal information where required by applicable law.
5. How We Use Personal Information
We may use personal information to create, authenticate and maintain user accounts; establish and administer organization workspaces; manage roles, permissions and facility access; provide ErgOps products and services; operate subscriptions and contractual relationships; provide technical and customer support; maintain platform security; prevent unauthorized access, abuse and fraud; investigate errors and security incidents; maintain audit and transaction records; improve the reliability and functionality of our services; comply with applicable legal obligations; establish, exercise or defend legal claims; and communicate important service, account, security or contractual information.
Where permitted by applicable law and where any required permission has been obtained, we may also use relevant contact information to provide product announcements or marketing communications.
Marketing communications are managed separately from essential operational and security communications.
6. Legal Bases for Processing
Where applicable data protection law requires us to identify a legal basis for processing, the legal basis will depend on the particular processing activity.
We may process personal information where processing is necessary to enter into or perform a contract, comply with a legal obligation, protect our legitimate business interests or the legitimate interests of another party where those interests are not overridden by the rights and freedoms of the individual.
Legitimate interests may include maintaining the security and integrity of ErgOps, preventing misuse, providing customer support, improving service reliability and administering business relationships.
Where consent is the appropriate or legally required basis for a specific processing activity, we will request that consent separately.
We do not treat acceptance or acknowledgement of this Global Privacy Notice as general consent to process personal information.
Under the GDPR, organizations must identify an appropriate lawful basis for processing and comply with principles including transparency, purpose limitation, data minimization and storage limitation.
7. Information Provided by Your Organization
Your employer, customer organization or another authorized organization administrator may provide us with information about you.
For example, an organization administrator may provide your name and business email address when inviting you to an ErgOps workspace or may assign you a role, facility or permission.
We process this information to provide the relevant organization with the ErgOps services it has requested and to provide you with authorized access to that workspace.
Your organization may have its own privacy obligations regarding the information it provides to ErgOps.
8. Customer Content
Organizations may upload sustainability, operational, supplier, facility, energy, carbon, water, waste, procurement or other business data to ErgOps.
Where Customer Content contains personal information and ErgOps processes that information solely on behalf of the customer organization, the customer organization determines the purposes for which the information is used.
ErgOps processes such information according to the applicable agreement with the customer and, where relevant, the Data Processing Agreement.
9. How We Share Personal Information
We may share personal information with service providers that help us operate ErgOps, such as providers of cloud infrastructure, hosting, databases, authentication, storage, email delivery, security, monitoring, technical support and other technology services.
We may also share limited information with professional advisers where reasonably necessary for legal, accounting, security or compliance purposes.
Where an organization chooses to activate an external integration, relevant information may be transmitted to that integration in order to provide the requested functionality.
We may disclose information to courts, regulators, law enforcement authorities or other public bodies where we are legally required or permitted to do so.
If ErgOps is involved in a merger, acquisition, financing, restructuring or transfer of all or part of its business, information may be disclosed where reasonably necessary for that transaction and subject to appropriate confidentiality and data protection measures.
We do not disclose personal information merely because a third party requests it. A valid legal or operational basis must exist.
10. Service Providers and Subprocessors
ErgOps relies on technology and service providers to operate portions of its platform.
Where a service provider processes personal information on our behalf, we seek to use contractual and organizational safeguards appropriate to the nature of the service and the applicable legal requirements.
Where required, information about material subprocessors may be made available through ErgOps documentation, contractual materials or our website.
11. International Data Transfers
ErgOps operates a cloud-based service. As a result, personal information may be processed in countries other than the country in which the user or customer organization is located.
Where applicable law imposes requirements on international transfers of personal information, ErgOps uses an appropriate transfer mechanism and safeguards required for the relevant transfer.
For users protected by European or UK data protection laws, this may include reliance on an applicable adequacy decision or appropriate contractual safeguards where required.
The GDPR specifically requires privacy information to explain international transfers and, where relevant, the safeguards used for those transfers.
12. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the ErgOps service, maintaining security, fulfilling contractual obligations and complying with applicable legal and record-keeping requirements.
Retention periods may differ depending on the category of information and the context in which it is processed.
For example, account information may generally be retained while the relevant account or business relationship remains active.
Security and audit records may be retained for an appropriate period after the relevant activity in order to investigate security events or establish a record of significant platform activity.
Certain contractual, billing or legal records may need to be maintained for longer periods where required by applicable law or where reasonably necessary to establish, exercise or defend legal claims.
When personal information is no longer required, it is deleted, anonymized or otherwise handled in accordance with our applicable retention procedures.
Storage limitation is a core data protection principle under the GDPR.
13. Removal From an Organization
An ErgOps user may belong to more than one organization.
If an organization administrator removes you from one workspace, your access to that organization may end without automatically deleting your ErgOps account where you remain authorized to use another organization or service.
Personal information relating to historical audit, contractual or security records may also be retained where there is a legitimate or legal reason for doing so.
14. Security
ErgOps uses technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss or destruction.
Depending on the relevant system, these measures may include authentication controls, role-based authorization, organization-level data separation, restricted access permissions, secure communications, logging, monitoring, backups and security updates.
No online service can guarantee absolute security. Users are also responsible for protecting their login credentials and promptly informing ErgOps or their organization administrator if they believe their account has been compromised.
15. Artificial Intelligence Features
Some ErgOps features may use artificial intelligence to assist with functions such as summarizing information, explaining sustainability data, generating draft text, identifying patterns or presenting recommendations.
Where personal information is processed as part of an AI-supported feature, we process the information in accordance with this Privacy Notice and applicable contractual and data protection requirements.
ErgOps is not intended to use account information to make solely automated decisions about individuals that produce legal or similarly significant effects unless such functionality is specifically introduced, disclosed and managed in accordance with applicable law.
16. Aggregated and De-Identified Information
ErgOps may generate statistical, aggregated or de-identified information to understand service performance, improve platform functionality and develop sustainability analytics or benchmarking capabilities.
Where information is treated as anonymous or de-identified, we take measures appropriate to the applicable legal framework to prevent it from being used to identify an individual.
Information that remains reasonably linkable to an identifiable individual continues to be treated as personal information.
17. Cookies and Similar Technologies
ErgOps may use cookies and similar technologies that are necessary to provide authentication, maintain sessions, protect the platform and remember user preferences.
Where non-essential analytics, advertising or similar technologies are used, additional information and controls may be provided through a Cookie Notice or consent-management interface as required by applicable law.
This Global Privacy Notice does not replace any separate Cookie Notice that applies to the ErgOps website or platform.
18. Marketing Communications
Where permitted by applicable law, users may choose to receive ErgOps product news, updates or marketing communications.
Marketing preferences are separate from the privacy information provided in this notice.
Where available, you may unsubscribe through the mechanism provided in the relevant communication or change your communication preferences.
Opting out of marketing communications does not prevent us from sending necessary account, security, contractual or service communications.
19. Your Privacy Rights
Depending on where you live, you may have rights concerning your personal information.
These may include rights to obtain information about how your personal information is used, request access to your information, correct inaccurate information, request deletion, restrict certain processing, object to certain processing, obtain certain information in a portable format, withdraw consent where processing is based on consent, and lodge a complaint with an appropriate privacy or data protection authority.
For individuals protected by the GDPR, Articles 12–22 establish transparency and data-subject rights, including access, correction, erasure, restriction, portability and objection where the applicable conditions are met.
UK data protection rules similarly require organizations to provide clear information about purposes, legal bases, retention, recipients, transfers and individual rights.
Certain United States state privacy laws may provide additional rights. For example, California law provides qualifying consumers with rights concerning access to collected information, deletion, correction, sale or sharing opt-outs and non-discrimination, subject to statutory conditions and exceptions.
Not every right applies in every jurisdiction or circumstance.
20. Exercising Your Rights
You may submit a privacy request using the privacy or contact channel made available through the ErgOps website or platform.
We may need to verify your identity before fulfilling a request in order to protect accounts and personal information from unauthorized disclosure.
Where ErgOps processes personal information solely on behalf of a customer organization, we may refer the request to that organization or assist it in responding, depending on our respective roles and applicable law.
We will respond to valid requests within the timeframe required by the applicable privacy law.
21. Complaints
If you have concerns about how ErgOps handles your personal information, you may contact ErgOps through the privacy contact channel made available on our website or platform.
Depending on your jurisdiction, you may also have the right to submit a complaint to the competent data protection, privacy or regulatory authority.
22. Children
ErgOps is a business-to-business platform and is not intended for use by children.
We do not intentionally design the standard ErgOps account service for individuals who are below the age at which they can independently use such business services under applicable law.
If we become aware that personal information relating to a child has been submitted to ErgOps in circumstances where it should not have been collected, we will take appropriate steps consistent with applicable law.
23. Changes to This Privacy Notice
We may update this Global Privacy Notice when our services, technology, processing activities or legal obligations change.
The current version will be made available through the ErgOps website or platform.
Where a change materially affects how we process personal information, we may provide an additional notice through appropriate channels.
A Privacy Notice update will not be treated as consent for a new activity where applicable law requires separate consent.
24. Regional Privacy Information
This Global Privacy Notice provides the common privacy framework for ErgOps users outside Türkiye.
Additional regional information may apply depending on the circumstances.
For users associated with organizations in the European Union or European Economic Area, ErgOps may provide an EU/EEA Privacy Addendum.
For users associated with organizations in the United Kingdom, ErgOps may provide a UK Privacy Addendum.
For users in jurisdictions within the United States where additional statutory notices apply, ErgOps may provide the relevant US or State Privacy Notice.
Regional notices supplement this Global Privacy Notice and do not replace it unless expressly stated otherwise.
25. Contacting ErgOps
Questions about this Global Privacy Notice or ErgOps privacy practices may be submitted using the current privacy or contact channel published through the ErgOps website or platform.
Onboarding'de gösterilecek metin
Global Privacy Notice
Version 1.0
Read Privacy Notice
Altında bir “I consent” kutusu koymazdım. Sistemde acknowledgement kaydı istiyorsanız şu ifade yeterli:
I confirm that I have read the ErgOps Global Privacy Notice.
Bu kayıt acknowledged olarak tutulmalı, consented olarak değil.