Privacy Policy

<p><i>Effective July 29, 2021</i></p><h2>Welcome!</h2><p>Welcome to Practice Ignition! We hope you will enjoy and appreciate visiting or using the Website at <a target="_blank" href="https://www.practiceignition.com" rel="noreferrer noopener">https://www.practiceignition.com</a> or any subdomain thereof (the “<strong>Website</strong>”), or using or purchasing a “<strong>Subscription</strong>” to our “<strong>Services</strong>”. <br /><br />Practice Ignition Pty Ltd, the company that owns and operates the Website and Services, <strong>wants you to know we take your privacy and protection of personal data very seriously</strong>. We are providing this Privacy Policy (the “<strong>Policy</strong>”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you visit the Website, use the Services or otherwise interact with us. The Policy also explains your privacy and data rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully. <br /> </p><h2>Key Elements of this Policy</h2><p>Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use, storage and disclosure of your personal data. By submitting personal data to us via any means, you consent to such collection, use, storage and disclosure. You can find the details in the rest of the Policy. </p><figure class="table"><table><thead><tr><th><strong>Personal data we collect from you but only with your consent</strong></th><th><strong>What we do with it</strong></th><th><strong>Third parties we share it with</strong></th></tr></thead><tbody><tr><td>Contact Information</td><td>Communicate with you </td><td>Companies that provide our communications and CRM services, such as HubSpot</td></tr><tr><td>Account Information </td><td>Manage your account, enable logging in to the Services, and customize your use of the Services </td><td>Companies that provide the infrastructure and software for the Services, such as Amazon AWS</td></tr><tr><td>Billing Information </td><td>Process the payments of your Subscription Fees and other fees</td><td>Third-Party Payment Processors, specifically Stripe and Recurly</td></tr><tr><td>Payment Information</td><td>Process payments of Professional Services Fees you make to a Professional Services Provider via the Services</td><td>Third-Party Payment Facilitators such as Stripe</td></tr></tbody></table></figure><h2><br />Some Terms</h2><p>Before we get started with the details, here are a few important terms we think you should know as you read this Policy.</p><p>“<strong>Data Protection Laws</strong>” refers to the laws that are designed to protect your personal data and privacy in the place where you live. These include: (1) the Australian <i>Privacy Act 1988</i> (as amended, the “<strong>Privacy Act</strong>”); (2) the “<strong>GDPR</strong>”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name <i>Regulation (EU) 2016/679 of the European Parliament and of the Council</i>; (3) “<strong>PIPEDA</strong>” (<i>Personal Information Protection and Electronic Documents Act</i>), which is the Canadian Data Protection Law that applies to our commercial activities in Canada; (4) the <i>California Consumer Privacy Act</i> (“<strong>CCPA</strong>”) which applies to our activities in the United States in certain circumstances; (5) South Africa’s <i>Protection of Personal Information Act, 2013</i> (“<strong>POPIA</strong>”) which applies to processing of personal data we do within the Republic of South Africa; and (6) the “<strong>UK GDPR</strong>” which applies to our activities in the United Kingdom; please note that when this Policy refers only to the “GDPR”, this includes the UK GDPR as applicable. Practice Ignition is committed to adhering to these Data Protection laws, and any other applicable Data Protection Laws. </p><p>“<strong>Personal data</strong>” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under the Privacy Act, PIPEDA, POPIA and the CCPA the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information. </p><p>Other terms and definitions used in this Policy may be found in our Terms of Use, and will have the same meaning in this Policy as they do there. </p><p> </p><h2>About Us and Contacting Us</h2><p>Practice Ignition Pty Ltd is a proprietary limited company headquartered in Sydney (Surry Hills), Australia at the specific address below that owns and operates the Website and Services. Where this Policy refers to “<strong>Practice Ignition</strong>”, it may refer to Practice Ignition Pty Ltd and its subsidiaries and affiliates, and / or their respective shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns, depending on the context.</p><p>Under the GDPR, Practice Ignition is a “data controller”, and under POPIA Practice Ignition is a “responsible party”. Either term means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way.</p><p>If you want to ask us anything about what’s in this Policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can email:</p><p>Practice Ignition Privacy Officer <br /><a href="mailto:privacy@practiceignition.com">privacy@practiceignition.com</a> </p><p> Here is the mailing address for you as well:</p><p>Practice Ignition Privacy Officer <br />Level 7, 54-66 Wentworth Ave <br />Surry Hills, NSW 2010 Australia</p><p>If you are in the Republic of South Africa, we also invite you to contact our Information Officer who is based there, with the following contact information: Will Dutton - <a href="mailto:will.dutton@practiceignition.com">will.dutton@practiceignition.com</a> | +277 6817 4974</p><p>If you have questions about the Website or Services themselves, please email support@practiceignition.com. </p><p> </p><h2>Your Rights </h2><p>You have the following rights regarding your personal data held by Practice Ignition, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. These rights may be exercised without affecting the price you pay for any of the Services. Notwithstanding that, exercising certain of these rights may affect your ability to use some or all of the Services. </p><ul><li>The right to be notified that personal data about you is being collected and to be notified when personal data has been accessed or acquired by an unauthorised person;</li><li>The right to withdraw at any time your consent for Practice Ignition to process your personal data;</li><li>The right to have your personal data erased from Practice Ignition’s records;</li><li>The right to access your personal data and any relevant information around its processing and use;</li><li>The right to have a copy of your personal data given to you in an easy-to-read format so that you can transfer it to another data processor;</li><li>The right to have your personal data corrected or updated if you believe it is inaccurate or out of date;</li><li>The right to object, on reasonable grounds, relating to your particular situation, to the processing of your personal data;</li><li>The right to opt out of marketing communications we send you, at any time;</li><li>The right to know whether Practice Ignition sells or shares your personal data (and if so, who gets it). Please refer to that information elsewhere in this Policy, though you can contact our Privacy Officer if you need additional information or clarifications;</li><li>The right to demand that Practice Ignition not sell your personal data;</li><li>The right to restrict the processing of your personal data if it is inaccurate or if our processing or use of it is against the law;</li><li>The right to refuse any marketing or advertising targeted at you by Practice Ignition; and</li><li>The right to institute civil proceedings regarding the alleged interference with the protection of your personal data.</li></ul><p>If you wish to exercise any of these rights, please contact our Privacy Officer at the contact information above, or refer to certain relevant sections further in this Policy. </p><p>Please note that if you request erasure of your personal data we shall do it to the extent feasible, however Practice Ignition reserves the right to retain some of your personal data for a reasonable time in order to satisfy certain legal obligations or under a legal procedure of any sort.</p><h3> </h3><h2>Personal Data Collected from You and What We Use It For</h2><p>In the table below, please find the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR and POPIA for us having and processing this personal data. Under the Privacy Act and PIPEDA, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to Practice Ignition. To the extent that we processed any of the below mentioned personal data before the commencement date of the data protection legislation relevant to your jurisdiction, you consent to us continuing to process such personal data in accordance with this Policy.</p><p> </p><figure class="table"><table><thead><tr><th><strong>Personal data category</strong></th><th><strong>Personal data processed</strong></th><th><strong>What we use it for (the “purpose” of processing)</strong></th><th><strong>Legal basis for processing under the GDPR and POPIA</strong></th></tr></thead><tbody><tr><td>Basic Contact Information</td><td>Email address</td><td>To communicate with you, as detailed more fully in the <i>Email Communications</i> section below</td><td>Your consent in giving us this information</td></tr><tr><td>Demo Contact Information</td><td>First name, last name, email address, company, and phone number </td><td>Communicate with you when you book a demo of the Services through the Website, and customize your demo</td><td>Your consent in giving us this information</td></tr><tr><td>Support Contact Information</td><td>Your email</td><td>Provide you with support for the Services</td><td>Your consent in giving us this information</td></tr><tr><td>Account Information</td><td>Email address, full name, company, phone number and location (country)</td><td>Manage your account and Subscription, enable logging in to the Services, and customize your use of the Services</td><td>Your consent and performance of a contract between you and us</td></tr><tr><td>Billing Information*</td><td>Credit card number, credit card expiry date, and card security code (CVC)</td><td>Process the payments of your Subscription Fees and Additional Client Fees (if applicable)</td><td>Your consent and performance of a contract between you and us</td></tr><tr><td>Payment Information* </td><td>Credit card number, credit card expiry date, and card security code (CVC) if paying by credit card, or certain bank account information if paying by debit (ACH transfer)</td><td>Process payments or debit payments for the Professional Fees, in order to transfer the Professional Fees to the Professional Services Provider</td><td>Your consent in giving us this information</td></tr><tr><td>Fraud Detection Information </td><td>Full name, company, address, email address</td><td>To validate against fraudulent transactions</td><td>Complying with our legal obligations</td></tr><tr><td>General Correspondence</td><td>Correspondence between us in any form </td><td>For record keeping purposes </td><td>Your consent and performance of a contract between you and us</td></tr></tbody></table></figure><p>*Please note that Billing Information and Payment Information is never stored on any servers or other equipment controlled by Practice Ignition. While it is collected <i>through</i> the Services, it is stored on servers and other equipment managed by the Payment Processors and Payment Facilitators described below in this Policy. </p><p>Where you have provided personal data further to the contract between you and us, if you fail to provide such data or withdraw your consent to use such data, we will no longer be able to provide certain Services to you. </p><p> </p><h2>Personal Data Collected About You from Third Parties and What We Use It For</h2><p>We generally do not get any personal data about you from third parties. Exceptionally, the following may occur:</p><ol><li>Users of the Services may import information (including personal data) about their Clients from third party applications, so that the Users can send Proposals and facilitate the payment of Professional Services Fees; and</li><li>To the extent that analytics and advertising identifiers are generated from third parties, these may be considered personal data collected from third parties, and you can find details about that further below in this Policy.</li></ol><p>If you are in the Republic of South Africa then, in relation to 1 above, we are processing such information as an Operator and not as Responsible Party (as those terms are defined in POPIA). As Operator we are obliged under POPIA to process such information only with the knowledge or authorisation of the Responsible Party (being the User who uploaded the personal data), and must not disclose it unless required by law or in the course of the proper performance of our duties. We also undertake to maintain and establish the security measures referred to in section 19 of POPIA when processing such information and to notify the User immediately where there are reasonable grounds to believe that the personal data of a data subject has been accessed or acquired by any unauthorised person.</p><p> </p><h2>Sensitive Personal Data</h2><p>We do not collect any of what the GDPR considers sensitive personal data (“special personal information” under POPIA) from you, unless you voluntarily submit it to us, which we encourage you not to do. </p><p> </p><h2>Who We Transfer Your Personal Data To</h2><p>We routinely share some of your personal data with certain types of third parties who are identified in the table below along with what they do with it. These may be referred to as “sub-processors”, and you can find the full list of all sub-processors used by Practice Ignition along with their security accreditations <a target="_blank" href="https://www.practiceignition.com/security/sub-processor-list" rel="noreferrer noopener">on our website</a>. Some of these third-party personal data recipients may be based outside your home jurisdiction. If you are in the European Economic Area or the U.K. or the Republic of South Africa, please see the “Transfer of Your Personal Data Outside of the European Economic Area, the UK or the Republic of South Africa” further down in this Policy for more information including on how we safeguard your personal data when this occurs.</p><p>We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of Practice Ignition’s Terms of Use; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Services infrastructure or the Internet in general (such as voluminous spamming or denial of service attacks). </p><p>We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with Practice Ignition (in which case we will require such entities to honour this Policy); or (2) if Practice Ignition merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).</p><p>We will never share your personal data with other third parties except under these circumstances. We do not sell or rent your personal data to any third party for direct marketing purposes or any other purpose. </p><figure class="table"><table><thead><tr><th><strong>Personal data category</strong></th><th><strong>Who we transfer it to</strong></th><th><strong>What they do with it</strong></th></tr></thead><tbody><tr><td>Basic Contact Information</td><td>Companies that provide email services such as <a target="_blank" href="https://www.hubspot.com/" rel="noreferrer noopener">HubSpot</a>, as detailed more fully in the <i>Email Communications</i> section below</td><td>Send you emails </td></tr><tr><td>Demo Contact Information</td><td>Companies providing technical infrastructure and software for the Services such as <a target="_blank" href="https://aws.amazon.com/" rel="noreferrer noopener">Amazon AWS</a>, and our CRM provider <a target="_blank" href="https://www.hubspot.com/" rel="noreferrer noopener">HubSpot</a></td><td>Store it so that we may retrieve it to contact you</td></tr><tr><td>Support Contact Information </td><td>Companies providing customer support and chat services, such as <a target="_blank" href="https://www.intercom.com/" rel="noreferrer noopener">Intercom</a> </td><td>Store it so that we may retrieve it to contact you to provide support</td></tr><tr><td>Account Information </td><td>Companies providing technical infrastructure and software for the Services, such as <a target="_blank" href="https://aws.amazon.com/" rel="noreferrer noopener">Amazon AWS</a> and <a target="_blank" href="https://www.heroku.com/home" rel="noreferrer noopener">Heroku</a> </td><td>Control your logging in to the Services so they can be provided to you, send you emails, and record-keeping</td></tr><tr><td>Account Information</td><td>Our business partners, specifically Intuit when you have been referred to us by them</td><td>Communicating with you and record-keeping</td></tr><tr><td>Billing Information </td><td>Payment processing companies, specifically <a target="_blank" href="https://stripe.com" rel="noreferrer noopener">Stripe</a></td><td>Process the payments of your Subscription Fees and Additional Client Fees (if applicable)</td></tr><tr><td>Payment Information</td><td>Payment Facilitators such as Stripe</td><td>Process payments or debit payments for the Professional Fees you are paying to a Professional Services Provider via the Services</td></tr><tr><td>Advertising identifiers</td><td>Companies that provide online advertising networks, like Google and Facebook</td><td>Show you ads for Practice Ignition and the Services when you are on the internet, as further detailed in the <i>Practice Ignition Advertising</i> section below</td></tr><tr><td>Analytics identifiers and IP addresses</td><td>Companies that provide data analytics, such as <a target="_blank" href="https://www.hubspot.com/" rel="noreferrer noopener">HubSpot</a>, <a target="_blank" href="https://analytics.google.com/" rel="noreferrer noopener">Google Analytics</a> and <a target="_blank" href="https://segment.com/" rel="noreferrer noopener">Segment</a> and <a target="_blank" href="https://www.snowflake.com/" rel="noreferrer noopener">Snowflake</a></td><td>Provide us with analytics as to how the Website and Services are used, as further detailed in the <i>Limited Gathering of Information</i> section below</td></tr></tbody></table></figure><p> </p><h2>Practice Ignition Advertising and Opting Out</h2><p>Practice Ignition is continuously evaluating and modifying our use of various advertising networks, which may change from time to time. In this section you will find all the advertising networks that Practice Ignition currently uses and instructions for opting out of them. If we do additional advertising in the future, this section will be updated. </p><p>Practice Ignition uses <a target="_blank" href="https://adwords.google.com/" rel="noreferrer noopener">Google AdWords and Display Network</a> and by visiting or using the Website you consent to this use. Specifically, Practice Ignition uses the remarketing features of interest-based advertising of Google AdWords that delivers you advertisements that will be of particular interest to you, based on your browsing and activity history interacting with the Website and Services. These advertisements will appear on third-party websites around the web. Google uses specific cookies to allow them to serve these ads around the web. You may prevent this type of advertising by deleting the appropriate Google cookie through your browser, though this may not be permanent. For a more permanent solution, you may opt out of such Google advertising by <a target="_blank" href="https://adssettings.google.com/" rel="noreferrer noopener">adjusting your Google ad settings</a> or using the <a target="_blank" href="http://optout.aboutads.info/" rel="noreferrer noopener">WebChoices online opt-out tool</a>. </p><p>Practice Ignition advertises using <a target="_blank" href="https://www.facebook.com/business/a/online-sales/custom-audiences-website" rel="noreferrer noopener">Facebook Custom Audience</a>, to display advertisements to you on Facebook or in Facebook Messenger that will be of interest to you, and by visiting or using the Website you consent to this use. Facebook may collect or receive information from the Website and Services and other applications and websites and use that information to provide measurement services and targeted ads. If you do not want to receive such Facebook advertisements, you can opt-out of such advertising by <a target="_blank" href="https://www.facebook.com/ads/preferences" rel="noreferrer noopener">adjusting your Ad Preferences settings</a> while logged in to Facebook. </p><p>Practice Ignition also advertises using <a target="_blank" href="https://business.linkedin.com/marketing-solutions/cx/17/06/advertise-on-linkedin?trk=sem_lms_gaw&amp;src=go-pa&amp;veh=LMS_NAMER_Core_USCA_Search_Google-Brand_DR-PRS_Broad_HeadTerms-Alpha_All_English_Core_378919961515__linked%20in%20advertising_c__kwd-8081142739_6458957165&amp;mcid=6612464045041733652&amp;cname=LMS_NAMER_Core_USCA_Search_Google-Brand_DR-PRS_Broad_HeadTerms-Alpha_All_English_Core&amp;camid=6458957165&amp;asid=77594803856&amp;targetid=kwd-8081142739&amp;crid=378919961515&amp;placement=&amp;dev=c&amp;ends=1&amp;gclid=CjwKCAiAi_D_BRApEiwASslbJ_iLrdWCcwulor7EYBTPZf1eI_04Vm7dxKVtvN-Xk30Ev8ArIo5cihoCGxMQAvD_BwE&amp;gclsrc=aw.ds" rel="noreferrer noopener">LinkedIn Advertising</a>, to display advertisements to you on LinkedIn that will be of interest to you, and by visiting or using the Website you consent to this use. LinkedIn may collect or receive information from our and use that information to provide measurement services and targeted ads. If you do not want to receive such LinkedIn advertisements, you can opt-out of such advertising by <a target="_blank" href="https://www.linkedin.com/help/linkedin/answer/90274/manage-your-linkedin-ads-settings" rel="noreferrer noopener">following LinkedIn's instructions</a> or using the <a target="_blank" href="http://optout.aboutads.info/" rel="noreferrer noopener">WebChoices online opt-out tool</a>.</p><p> </p><h2>Limited Gathering of Information for Statistical, Analytical and Security Purposes</h2><p>Practice Ignition automatically collects certain information using “<strong>Third-Party Analytics Programs</strong>” such as <a target="_blank" href="https://www.hubspot.com/" rel="noreferrer noopener">HubSpot</a>, <a target="_blank" href="https://analytics.google.com/" rel="noreferrer noopener">Google Analytics</a>, <a target="_blank" href="https://segment.com/" rel="noreferrer noopener">Segment</a> and <a target="_blank" href="https://www.snowflake.com/" rel="noreferrer noopener">Snowflake</a> to help us understand how our users use the Website and Services, but none of this information identifies you personally, except via an alphanumeric string. For example, each time you visit the Website, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web page(s) or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Website visitors and Services Users in the aggregate. Practice Ignition also makes use of information gathered for statistical purposes to keep track of the number of visits to the Website, the specific pages on the Website, and Users with a view to introducing improvements to the Website and Services. </p><p>Your IP address and other relevant information we collect using the Third-Party Analytics Programs may be used in order to trace any fraudulent or criminal activity, or any activity in violation of the Terms of Use.</p><p> </p><h2>Tracking Technology (“Cookies” and Related Technologies) </h2><p>Practice Ignition uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) on the Website and in the Services and by interacting with the Website and Services you agree to their use. Cookies are small text files placed on your computer or device when you visit a website or use an online service, in order to track use of the website or service and to improve the user experience by storing certain data on your computer or device. </p><p>Specifically, we use cookies and related technologies for the following functions: </p><ul><li>to enable your logging-in to the Services and track your logged-in status to the Services;</li><li>for the proper functioning of the Services, including the proper functioning of payment processing and payment facilitating;</li><li>to provide general internal and user analytics on the Website and to conduct research to improve the content of the Services using the Third-Party Analytics Programs as described above in this Policy;</li><li>to facilitate the advertising described above in this Policy; and</li><li>to assist in identifying possible fraudulent activities.</li></ul><p>Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:</p><ul><li><a target="_blank" href="https://support.google.com/accounts/answer/61416?co=GENIE.Platform%3DDesktop&amp;hl=en" rel="noreferrer noopener">Google Chrome</a></li><li><a target="_blank" href="https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences" rel="noreferrer noopener">Mozilla Firefox</a></li><li><a target="_blank" href="https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy" rel="noreferrer noopener">Microsoft Edge</a></li><li><a target="_blank" href="https://www.opera.com/help/tutorials/security/privacy/" rel="noreferrer noopener">Opera</a></li><li><a target="_blank" href="https://support.apple.com/kb/ph21411?locale=en_US" rel="noreferrer noopener">Apple Safari</a></li><li><a target="_blank" href="https://support.apple.com/en-ca/HT201265" rel="noreferrer noopener">iOS</a></li><li><a target="_blank" href="https://support.google.com/accounts/answer/32050?co=GENIE.Platform%3DAndroid&amp;hl=en" rel="noreferrer noopener">Android</a></li></ul><p>Please note that deleting or blocking certain cookies may reduce your user experience by requiring you to re-enter certain information, including information required to use our Services. Furthermore, deleting certain cookies may prevent certain functions, or the entirety of the Services, from working at all. </p><p> </p><h2>Email Communications and Compliance with Anti-Spam Laws</h2><p>Practice Ignition uses <a target="_blank" href="https://www.hubspot.com/" rel="noreferrer noopener">HubSpot</a> to manage our mailing list and send out our newsletter, and <a target="_blank" href="https://postmarkapp.com/" rel="noreferrer noopener">Postmark</a> to send out emails related to various Services functions (HubSpot and Postmark, collectively the “<strong>Email Service Providers</strong>”). Personal data is transferred to the Email Service Providers in order to manage the mailing list and for the emails to be sent out properly. Your Contact Information is only used to send out emails; the Email Service Providers do not use this personal data for any other purpose, and will not transfer or sell your personal data to any other third party. </p><p>You may unsubscribe from Practice Ignition’s mailing list at any time, by following the link at the bottom of all Practice Ignition emails. Other types of emails, such as transactional, relational, and other emails related to certain Services functions will not have an opt-out option as they are necessary for the use of the Services. </p><p>Practice Ignition’s practices in regards to its email are designed to be compliant with anti-spam laws, including Australia’s Spam Act 2003, the American CAN-SPAM Act, and the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23). If you believe you have received email in violation of these laws or any other anti-spam law, please contact us using the contact information further up in this Policy.</p><p> </p><h2>How We Protect Your Personal Data</h2><p>We have implemented very strict technical and organisational procedures for ensuring that, by default, only the personal data which is necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.</p><p>We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws requires us to do so, and within the time frame required by the applicable Data Protection Law.</p><p>Practice Ignition uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Website and Services, and these third parties have been selected for their high standards of security, both electronic and physical. For example, Practice Ignition uses <a target="_blank" href="https://aws.amazon.com/" rel="noreferrer noopener">Amazon AWS</a>, a recognized leader in secure data, for hosting of the Website and Services and related data, and storage of data including personal data.</p><p>All information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check Practice Ignition’s valid SSL security certificates on the Website.</p><p>Practice Ignition uses Stripe for processing of secured credit card payments for payments of Subscription Fees and Professional Services Fees made through the Services. Stripe is certified as a PCI-DSS (Payment Card Industry Data Security Standard) Service Provider Level 1, the highest-volume level for credit card transaction companies. </p><p>For more details about how we protect your personal data, please visit <a target="_blank" href="https://www.practiceignition.com/security" rel="noreferrer noopener">our dedicated security page</a>. </p><p> </p><h2>Transfer of Your Personal Data Outside of the European Economic Area (EEA), the U.K. or the Republic of South Africa</h2><p>For our European, UK and South African users, we endeavour to keep your personal data inside the EEA or the U.K. or the Republic of South Africa (as applicable). However, certain of our data processors (and Practice Ignition) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:</p><ul><li>The United States. Your personal data is only transferred to companies in the United States that: (1) have signed agreements with us or have informed us that they are GDPR-compliant; and (2) have concluded the <a target="_blank" href="https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en" rel="noreferrer noopener">Standard Contractual Clauses</a> for the transfer of personal data outside the EEA.</li><li>Canada. We may transfer personal data to our operations in Canada, but Canada has been determined to have an “adequate level of protection” for your personal data <a target="_blank" href="https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en" rel="noreferrer noopener">under European data protection law</a>.</li><li>Australia. We may transfer personal data to our operations in Australia, but when we do so we rely on binding corporate rules to protect your personal data.</li></ul><p>That’s it! You have the right, however, to refuse to have your data transferred outside the EEA or the U.K. or the Republic of South Africa (as applicable). Please contact our Privacy Officer to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Services.</p><p> </p><h2>Supervisory Authorities and Complaints</h2><p>If you are in the EEA or the U.K. under the GDPR or UK GDPR (as applicable) you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about Practice Ignition’s data practises, we invite you to contact the supervisory authority in your country. For example, if you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can <a target="_blank" href="https://ico.org.uk/global/contact-us/" rel="noreferrer noopener">reach them in a variety of ways</a>, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the <i>Commission Nationale de l'Informatique et des Libertés</i> who is the supervisory authority there. Their contact information <a target="_blank" href="https://www.cnil.fr/en/contact-cnil" rel="noreferrer noopener">can be found here</a>.</p><p>The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA <a target="_blank" href="https://edpb.europa.eu/about-edpb/board/members_en" rel="noreferrer noopener">can be found here</a>. </p><p>If you are in Australia, you can make a complaint to the Office of the Australian Information Commissioner <a target="_blank" href="https://www.oaic.gov.au/privacy/privacy-complaints/" rel="noreferrer noopener">here</a>. If you are in Canada, you can make a complaint to the Office of the Privacy Commissioner <a target="_blank" href="https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/file-a-complaint-about-a-business/" rel="noreferrer noopener">here</a>. If you are in the Republic of South Africa, you have the right under POPIA to make a complaint to the Information Regulator (South Africa), whose contact information can be found <a target="_blank" href="https://www.justice.gov.za/inforeg/contact.html" rel="noreferrer noopener">here</a>. </p><p> </p><h2>Data Retention</h2><p>Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your Account Information for as long as you have an account with us. We may, however, keep certain information for longer periods of time when required to by any law or regulation. </p><p> </p><h2>Automated Decision-Making</h2><p>Practice Ignition does not use any automated decision-making processes in providing the Services.</p><p> </p><h2>Children’s Privacy Statement</h2><p>The Services are not intended for children under the age of 18. We do not knowingly collect any personal data from a child under 18. If we become aware that we have inadvertently received personal data from a person under the age of 18 through the Services, we will delete such information from our records.</p><p> </p><h2>Changes to This Privacy Policy</h2><p>The date at the top of this page indicates when this Policy was last updated. Every now and then, we will have to update this Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL, and we will always post a notice on the Website and Services if we make significant changes. If you have an account, we will also email you to tell you the Policy has been updated, and what the important changes are. </p><p> </p><p>© Practice Ignition Pty Ltd 2021 </p>