Privacy Policy
Last Modified: September 18, 2020
We have an obligation to safeguard your personal information. This privacy policy (“Privacy Policy”) applies to Chally Assessment, LLC. d/b/a Chally (hereinafter, variously “Chally”, “we”, “us”, or “our”), and our web platform, application, website, and related support services (collectively, the “Services”), and your choices about our collection, use, and retention of your personal information.
By using the Services in any manner, you indicate to Chally that you have read and accept our Privacy Policy and consent to the data practices, including without limitation the collection and use of your personal data, described in this Privacy Policy. As part of the Services we may provide assessments, and in providing such assessments we use automated decision-making. In the event you participate in an assessment, you hereby acknowledge and agree that you are aware of the use of such automated decision-making and are expressly consenting to the use of automated decision- making. In the event you desire to request human intervention, challenge a decision or withdraw consent, please contact us at [email protected]. If you do not accept this Privacy Policy or do not meet or comply with the provisions set forth herein, then you shall not use the Services. If required by applicable law, we will seek your express consent to process personal data (i) provided by you and/or (ii) collected during your use of the Services. Any consent shall be entirely voluntary. In the event you do not provide consent to us to process your personal data, then you may not access and/or use the Services.
Information We Collect
When you use the Services, you and/or your employees, independent contractors and/or candidates (collectively, the “Authorized Users”) may provide Chally with two main types of information: (i) personal information that the Authorized Users knowingly choose to disclose, which is collected on an individual basis, and (ii) general user information that does not contain personal information, which is collected on an aggregate basis as the Authorized Users use the Services. Examples of the foregoing may include, without limitation, first name, last name, e-mail address and IP address and further described herein. We collect information from you when you (a) use and/or access the Services, (b) open and/or respond to our emails, (c) contact Chally, (d) visit any page online that displays our content, (e) purchase assessments and/or services through the Services, and/or (f) provide information to any of our vendors. Please note, in the event the Authorized User is engaging in an assessment via the Services, the Authorized User acknowledges and agrees that by engaging in such assessment the Authorized User may disclose information that may make such Authorized User personally identifiable and such Authorized Users are responsible for the content such Authorized Users provide. In such case, Chally is considered a processor and does not control the personal data used or stored in the assessment and only processes it; however, Chally will not process the personal data of its Authorized Users for other purposes or by other means than instructed by the controller of the personal data. In the event you want more information regarding the protection of personal data when responding to assessments or have questions about the personal data that may have been collected during such assessment, please contact the entity that has provided the assessment to you.
Personal Information You Choose to Provide
We may ask for certain personal information from you for the purpose of providing to you content and/or Services that you request. We collect personal information such as your: (i) contact information (including name, telephone number, email, title, and job position); (ii) employment content (including information, text and/or other materials) submitted by you; (iii) financial information (such as credit card number, expiration date, verification number and billing address); (iv) data from assessments and responses to questions related to individual competencies (including performance); (v) contact information of employees or others you share with us; (vi) demographic information (including age, birthdate and gender); (vii) location information (such as geographic location of the device you are using) (viii) preferences, feedback and behavior (such as reports and performance rates) and (ix) information of third parties such as names and email addresses, as may be provided for example, in order to invite your team to take assessment tests. Once you register, you have opted in to receive electronic communications from Chally. Chally may also provide you with the opportunity to participate in surveys through the Services. If you participate, we will request certain personal information. Participation in surveys is completely voluntary and you therefore have a choice whether to disclose such information.
Personal Data We Collect
When you access or use the Services, we may automatically collect information about you, including:
Cookies: In an effort to be transparent with our data collection practice and the technologies we use to provide the Services, the following explains how we use Cookies. We use cookies and web log files to track usage and trends, to improve the quality of our Service and to customize your experience. A “Cookie” is a tiny data file that resides on your computer, mobile phone, or other device, and allows Chally to recognize you as a user when you return to our website using the same device and web browser and enables Chally to collect information about how you use our Services. Information gathered through Cookies may include the date and time of visits, the pages viewed, and time spent using the Services. If you do not agree to our use of Cookies, you should set your browser settings accordingly or not use the Services. You may remove or block Cookies using the settings in your browser; however, in some cases that may impact your ability to use the Services and/or user experience while using the Services. Chally uses Cookies and web log files for the following, which may include without limitation (i) to track usage and trends, (ii) to improve the quality of the Services, (iii) to customize your experience and/or (iv) to compile anonymous, aggregated information that allow us to understand how our Services are used.
Cookies are categorized by how long they are stored and their function. The Cookies Chally uses are as follows:
- Persistent Cookies: Persistent Cookies remain on a visitor’s device for a set period of time specified in the Cookie. They are activated each time that the visitor visits the Services that created that particular Cookie.
- Session Cookies: Session Cookies are temporary and deleted from your computer when you close your web browser. They allow Chally to link the actions of a user while using the Services.
- Strictly Necessary Cookies: Strictly necessary Cookies are essential to navigate around the Services and to use its features.
- Performance Cookies: Performance Cookies collect anonymous data for statistical purposes on how users use the Services, they don’t contain personal information and are used to improve the user experience.
- Functionality Cookies: Functionality Cookies allow Chally to operate the Services in accordance with your choices, such as ‘remembering’ you in between visits.
You can adjust the settings on your browser and reject the setting of all or some Cookies and it will alert you when a Cookie is placed on your device. You may also delete previously stored Cookies; however this will not prevent the Services from placing future Cookies on your device unless and until you adjust your settings as described above. Please note, blocking any or all Cookies may impact your use of the Services as mentioned above.
Device Data: We use device data, which is information concerning a device you use to access, use, and/or interact with the Services, such as operating system type and/or mobile device model, browser type, domain, and other system settings, the language your system uses and the country and time zone of your device, geo-location, unique device identifier and/or other device identifier, mobile phone carrier identification, and device software platform and firmware information.
Aggregate: We may collect non-identifying and statistical information about the use of the Services, such as how many visitors visit a specific page, how long they stay on that page and which links, if any, they click on. This information represents a generic overview of our users, including their collective habits. Information collected in the aggregate is not associated with you as an individual. We may share user information in the aggregate with third parties.
Analytics: Chally uses analytic software to gather statistics and usage trends for product and service improvement purposes. Our Service may record data from your phone, tablet, or computer such as how frequently you use the Service, what actions you take and performance data.
Other Tracking Technologies: We may supplement information you provide to us with information from other sources, such as information to validate and/or update your address and/or other demographic information. This information is used to maintain the accuracy of information on the Services and for internal analysis. We may also use clear gifs, pixel tags and web beacons, which are tiny graphic images placed on website pages and/or in our emails that allow us to determine whether you have performed specific actions and are further used to track online movements of our users. In contrast to Cookies, which are stored on your computer’s hard drive, clear gifs are embedded invisibly on web pages. We do not tie the information gathered by clear gifs to your personal information.
Third Party Services: To support the services we provide to you; we may use services hosted by third parties. These services may collect information sent by a browser as part of a web page request, including ‘Internet Protocol’ addresses, browser software, and/or clickstream patterns. If such third-party services collect information, they do so anonymously without identifying individual visitors. However, we may link the information we record using tracking technology to personal information we collect. In addition, we may allow third parties who list services to use Cookies in connection with your use of the Services. They may collect and store the same type of information and use it similarly to Chally, as described above.
PURPOSES AND USES OF INFORMATION WE COLLECT
General Use
We use information collected as described in this Privacy Policy to provide you with the Services and/or the information and/or content that you have requested, and, in some cases, to contact you about our products, features and/or other services. We also use the information collected to take the following actions:
- operate, maintain and improve the Services;
- answer questions and respond to your requests;
- perform analytics and conduct research;
- send you reminders, support and marketing messages;
- manage our administration of the Services;
- improve the design and content of the Services
- participate in one of our surveys or other forms of customer research;
- facilitate and process employment assessments;
- analyze programs, products and services we offer; and
- use information for other purposes about which we notify you.
The information collected in the aggregate enables Chally to better understand your use of the Services and to enhance your enjoyment. We may use financial information to process payment, enroll you in one of our accounts and/or other related services in which you elect to participate. If you use the Services, you agree to receive certain communications from us including but not limited to the following:
Special Offers, Newsletters and Updates. We will occasionally send you information on products, special deals, promotions and newsletters. You can sign up for these emails from us at any time. Out of respect for your privacy, you may elect not to receive these types of communications by contacting us or replying to our emails.
Blogs. Our Service may have links or access to publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them.
Customer Service. Based upon the personal information you provide us, we will communicate with you in response to your inquiries, to provide the services you request and to manage your account. We will communicate with you by email or telephone, as you may elect.
Third-parties with whom we may share your personal information:
Service Providers: We may share your personal information as well as information from tools like Cookies, log files, and device identifiers and location data (such as usage data, referring/exit pages and URLs, platform types, number of clicks, etc.), with employees, contractors, and/or agents that help Chally provide the Services to you (“Service Providers”). Our Service Providers will be given access to your information as is reasonably necessary to provide the Services. We strive to use commercially acceptable means to protect your personal information. If Service Providers acquire confidential or proprietary information belonging to Chally or its customers, such information is required to be handled in confidence and may not be disclosed to unauthorized third parties. Service Providers who violate our security and safe maintenance of data policies are subject to appropriate discipline including, but not limited to, termination. We take the privacy of our users very seriously, and we do not sell, rent, and/or otherwise provide your personal information to third parties for marketing purposes. We will not share your personal information in ways unrelated to those described in this Privacy Policy without providing you with an opportunity to opt out of such use or otherwise prohibit such unrelated use. We encourage our Service Providers to adopt and post privacy policies; however, such Service Provider’s use of personal information obtained through Chally is governed by such Service Provider’s privacy policies and is not subject to our control. Certain Service Providers will automatically collect non- identifying information about your use of the Services by using Cookies and other technologies as similarly used by Chally.
Corporate Accounts: If you are an individual registered Authorized User and the domain of the primary email address associated with your account is owned by your employer and was assigned to you as an employee of that organization, and such organization wishes to establish a corporate account, then certain information concerning past use of your individual account may become accessible to that organization’s administrator including your email address and/or assessment results.
For Collaboration: We may share your information, including when you choose to use certain features in the Services that by their nature support sharing with third parties who you choose. Your name, email address, and any content you choose to share will be shared with such third parties, and such third parties may communicate with you in connection with your use of the Services.
Compliance with Laws: Chally will not disclose your personal information to third parties except as set forth in this Privacy Policy and in the following circumstances: (i) to investigate and defend Chally members against any third party claims and/or allegations and/or otherwise to protect Chally from liability, (ii) to investigate, prevent and/or take action regarding suspected and/or actual illegal activities, (iii) to assist government enforcement agencies, respond to a legal process or a lawful request by public authorities, and/or to comply with the law, (iv) to exercise or protect the rights, property and/or personal safety of the users of the Services and/or (v) to protect the security and/or integrity of the Service.
Business Transfers: If we sell or otherwise transfer part or all of Chally or our assets to another organization (e.g., in the course of a transaction such as a merger, acquisition, bankruptcy, dissolution, liquidation, etc.), your information such as name and email address, user content and/or any other information collected through the Services may be among the items sold and/or transferred.
YOUR INFORMATION CHOICES REGARDING USE AND DISCLOSURE AND MEANS FOR EXERCISING CHOICE
Your consent to our collection, use, and disclosure of your personal information, as well as your receipt of information from us, can be either express or implied. Express consent will be obtained either in writing or by some affirmative act via the Services such as clicking on an icon or button. Implied consent may be obtained through your use of our assessments and related Services, or when you approach us to obtain information, or inquire about or request Services from us. You will have an opportunity to opt out of receiving announcements of certain information. You can also limit the information you provide to Chally, as well as the communications Chally sends to you. If you visit the Services and volunteer personal information, you can opt out of receiving notifications, although privacy rules may require or permit us to communicate with you in certain circumstances. In some cases, if you choose not to provide Chally with requested information, you may not be able to use and/or access all of the Services.
Your California Privacy Rights
Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to receive: (a) information identifying any third party companies to whom Chally may have disclosed personal information to for direct marketing, within the past year; and (b) a description of the categories of personal information disclosed. To obtain such information, please email your request to [email protected] and we will provide a list of categories of personal information disclosed within thirty (30) days of receiving such a request. This request may be made no more than once per calendar year. We reserve the right not to respond to requests submitted in ways other than those specified above.
SERVICE ELIGIBILITY AND CHANGES
Children and Minors. Chally does not knowingly collect personal information from children under the age of thirteen (13). If we learn that we have collected personal information from a child under age thirteen (13), we will endeavor to delete such information promptly. If you believe that a child under the age of thirteen (13) may have provided us personal information, please contact us at [email protected]. By using the Services, you represent that you are at least eighteen (18) years old and understand that you must be at least eighteen (18) years old in order to create an account and/or purchase the goods and/or services through the Services.
Changes to Privacy Policy. In general, changes will be made to this Privacy Policy to address new or modified laws, changes to ‘EU-US Privacy Shield Framework’ and/or new or modified business procedures. However, we may update this Privacy Policy at any time, with or without advance notice, so please review it periodically. We will update the ‘Last Modified’ date above and may provide you additional forms of notice of modifications and/or updates as appropriate under the circumstances. You can determine when this Privacy Policy was last revised by referring to the date it was “Last Modified” above. If you disagree with any changes to this Privacy Policy and do not wish your information to be subject to the revised Privacy Policy, you will need to stop using the Services. Your continued use of the Services after any modification to this Privacy Policy will constitute your acceptance of such modifications and/or updates.
SECURTIY
We work hard to secure your personal information from unauthorized access to and/or unauthorized alteration, disclosure and/or destruction of information we hold. Chally has adopted appropriate physical, electronic and managerial procedures to safeguard and secure the personal information we process. We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. We periodically review our information collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems. Since the internet is not a completely secure environment, Chally cannot warrant the security of any information you transmit to Chally or guarantee that information on the Services may not be accessed, disclosed, altered and/or destroyed by breach of any of our physical, technical and/or managerial safeguards; however, Chally implements and maintains appropriate technical, security and organizational measures to protect personal data against unauthorized or unlawful processing and use, and against accidental loss, damage, destruction, theft or disclosure. Please do your part to help Chally. You are responsible for maintaining the secrecy of your account information, and for controlling access to emails between you and Chally, at all times. Please limit your access to your computer and/or mobile device and/or browser by signing off after you have finished accessing the Services. We are not responsible for the functionality, privacy and/or security measures of any other organization.
OTHER WEB SITES AND SERVICES
We are not responsible for the practices employed by any websites and/or services linked to and/or from the Services, including the information and/or content contained therein. Please remember that when you use a link to go from the Services to another website and/or service, our Privacy Policy does not apply to such third-party websites and/or services. Your browsing and interaction on any third-party website and/or service, including those that have a link on our Service, are subject to such third party’s own rules and policies. In addition, you agree that we are not responsible and do not have control over any third- parties that you authorize to access your personal information. If you are using a third-party website and/or service and you allow them to access your personal information, you do so at your own risk.
DIRECTIVE 95/46/EC & GENERAL DATA PROTECTION REGULATION
Chally adheres to the Directive 95/46/EC (“Directive”) and, commencing on May 25, 2018, the European Union’s (“EU”) General Data Protection Regulation (“GDPR”).
PRIVACY CERTIFICATION: EU – U.S. PRIVACY SHIELD FRAMEWORK
Where Chally acts as a data processor, Chally has certified its compliance with the EU-U.S. Privacy Shield Framework. Chally may from time to time collect, use, and retain personal information from individuals located within the EU member countries. We are committed to subjecting all personal data received from the EU member countries in relation to the Privacy Shield Framework and its applicable ‘Principles’. To learn more about the ‘EU-US Privacy Shield Framework’, please visit https://www.privacyshield.gov. Chally is under the jurisdiction as well as the investigatory and enforcement powers of the US Federal Trade Commission for purposes of the ‘EU-US Privacy Shield Framework.’ This Privacy Policy applies to all personal information received by Chally whether in electronic, paper or verbal format.
PRIVACY SHIELD COMPLIANCE
Personal information may be transferred abroad (including outside the EU for the Authorized Users in the EU) in connection with Chally’s provision of hosted application services and related support services to our customers. Chally strives to collect and use personal information in a manner consistent with the laws of the countries in which we do business and is self-certified to the ‘EU-US Privacy Shield Framework’ developed by the U.S. Department of Commerce in coordination with European Commission. Chally is committed to cooperating with the European Data Protection Authorities or their authorized representatives in accordance with applicable law.
Chally complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. Chally has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.
DATA INTEGRITY PURPOSE LIMITATION
Chally may process personal data on your behalf in order to provide the Services, including uploading, reviewing, sharing content and sending emails on your behalf. Chally will only process personal information in a way that is set forth herein and relevant for the purpose for which it was collected and/or authorized by you. Chally will take reasonable steps to ensure that personal information is reliable for its intended use, accurate, complete and current. We may occasionally contact you to determine that your data is still accurate and current.
YOUR RIGHTS TO ACCESS AND CHANGE PERSONAL DATA
Subject to the limitations set out below, you may access, review, modify, update, and/or delete such personal information as we hold by contacting us [email protected] and/or by changing your preferences on the Service. Please be aware that even after your request for a change is processed, as well as following termination of Services, Chally may, for a time, retain residual personal information about you in its backup and/or archival copies of its database. We may also retain personal information for a commercially reasonable time for audit purposes and/or to comply with legal obligations, to resolve disputes, and to enforce agreements. Chally may deny or limit access and change requests where legitimate rights of persons other than you would be violated or where disclosure would interfere with national security, defense, or public security, or other grounds provided for by the Framework Principles. For security purposes, Chally may require verification of identity before providing access to personal information. If you wish to confirm whether Chally has personal data relating to you, please contact us at [email protected]. We will respond to your request within a reasonable time.
ONWARD TRANSFERS
Chally is responsible for the processing of personal information it receives, under the Privacy Shield Frameworks, and subsequently transfer to a third party acting as an agent on its behalf. Chally complies with the ‘Principles’ for all onward transfers of personal information from the EU, including the onward transfer liability provisions. Chally will offer Authorized Users in the EU whose personal information has been transferred to the United States the opportunity to opt out from: (a) the disclosure of personal information to a non-agent third party (other than Service Providers); and (b) the use or disclosure of personal information for a purpose other than the purposes for which the information originally was collected or subsequently authorized by the individual or a compatible purpose. Chally does not intend to receive “sensitive personal information” (which includes, without limitation, personal information specifying medical and/or health conditions, racial and/or ethnic origin,), and neither our clients nor any individuals should provide sensitive personal information to us. In the event Chally seeks to receive such information, we will request and obtain affirmative consent before disclosing such information to a non-agent third party and before using such information for a purpose other than the purpose originally disclosed and/or a compatible purpose. Chally will provide you with reasonable mechanisms to exercise your choices should such circumstances arise. Chally will not transfer personal information originating from the EU to third parties unless such third parties have entered into an agreement in writing with us requiring them to provide at least the same level of privacy protection to your personal information as required by the principles of the ‘EU-US Privacy Shield Framework’. We will only transfer data to our agents, resellers or third party Service Providers who need the information in order to provide services to or perform activities on behalf of Chally, including in connection with the delivery of services or products, Chally management, administration, or legal responsibilities. Chally will make sure that any third-party agent receiving personal information subscribes to the ‘EU- US Privacy Shield Principles’.
EXCEPTIONS TO PRIVACY SHIELD PRINCIPLES
As it relates to personal information pertaining to EU individuals, please be aware that there are certain exceptions to the EU-US Privacy Shield Principles’. For instance, our adherence to the ‘Principles’ may be limited to the extent necessary to meet national security, public interest or law enforcement requirements. Please note that where an exception applies to the ‘Privacy Shield Principles’, we may make use of such exception.
DATA TRANSFERS
Please be aware that the Services are subject to United States laws, including laws governing privacy and security of your information. By using the Services, you agree and consent (and represent that you have the authority to provide such consent) to the information collection, use and sharing practices described in this Privacy Policy and understand that the laws of the United States and other countries and territories related to the foregoing may differ from those of other countries and may not be as protective as the laws in the country where you reside. Regardless of the laws in place in such countries, we will treat the privacy of your information in accordance with this Privacy Policy.
RECOURSE, ENFORCEMENT AND LIABILITY
Chally uses a self-assessment approach to promote compliance with this Privacy Policy and periodically verifies that the attestations and assertions in the Privacy Policy are true and that the privacy practices required by the ‘EU- US Privacy Shield Principles’ have been implemented. If you believe Chally processes your personal data under reliance of the ‘EU-US Privacy Shield Framework’ and have inquiries, concerns, or complaints that you would like to discuss with us, we encourage you to raise them by contacting us at [email protected], and we will investigate and attempt to resolve any issues regarding use and disclosure of personal information in accordance with the ‘EU-US Privacy Shield Principles’. We will respond to any complaint within 45 days after its receipt. If the personal information in question has been transferred from the EU to the United States, and for some reason a complaint or dispute cannot be resolved through our internal process, we have further committed to refer unresolved ‘EU-US Privacy Shield’ complaints to an independent dispute resolution mechanism located in the United States. Any dispute, controversy and/or claim arising out of or relating to this Privacy Policy, will be referred to and finally determined via binding arbitration by Judicial Arbitration and Mediation Services (“JAMS”). If you do not receive timely acknowledgment of your complaint, and/or if your complaint is not satisfactorily addressed by Chally, please visit the JAMS website at https://www.jamsadr.com/eu-us-privacy-shield for more information and to file a complaint.
Additionally, with respect to complaints concerning human resources data that is transferred from the EU to the United States, we have agreed to participate in the dispute resolution procedures of the EU Data Protection Authorities. Contact details for the EU data protection authorities can be found at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm. Chally will cooperate as required with the appropriate EU Data Protection Authorities during investigation and resolution of complaints concerning human resources data that is transferred from the EU to the United States brought under the ‘EU-US Privacy Shield Framework’.
These recourse mechanisms are available at no cost to you. Damages may be awarded in accordance with applicable law. Under certain conditions, if you are not satisfied with the above recourse mechanism, you may be able to invoke binding arbitration.
DATA PROCESSING AGREEMENT
If you or your organization are required to enter into a contract with your data processor under the GDPR, please review Chally’s data processing agreement (“DPA”) and if the DPA is acceptable, provide the information requested and sign where indicated. Once complete, email [email protected] the countersigned version of the DPA. Please contact Chally at [email protected] with any questions. In addition, Chally has a data processing agreement in place with any sub-processors it uses to process EU personal data in compliance with the Directive and the GDPR.
LANGUAGE
The governing language of this Privacy Policy is English, which shall prevail over any other languages used in any translated document.
HOW TO CONTACT US
Chally’s Data Protection Officer (“DPO”) is Ms. Maria Rao. If you have questions and/or comments about this Privacy Policy or want to inquire or otherwise communicate about your personal data that has been collected, please email us at [email protected].