PRIVACY POLICY FOR ENTERPRISES
This Privacy Policy is entered into by and between Krisp Technologies, Inc., a Delaware corporation (“Company”, “we”, “us”, or “our”) and the Krisp enterprise plan customer named in the order form or any other document specifying the services to be provided in accordance with the Krisp Master Subscription Agreement (“MSA”), including its affiliates (“Customer”, “you” or “your”). This Privacy Policy, which is expressly incorporated to the MSA, governs the privacy practices that we employ when you use the Krisp for Enterprises product, including any content, functionality, and services offered on or through the application (“Krisp”). References herein to “you” or “your” shall also mean (a) the individual who is accepting this Privacy Policy on behalf of the Customer, and (b) your End Users (as defined in the Krisp MSA).
In order to provide Krisp for Enterprises, we collect personal data from our Customers and their End Users when they use Krisp, and we also collect certain information from third parties. This Privacy Policy applies to personal information collected by Company when you use the Krisp for Enterprises product. Please read it carefully to understand our policies and practices regarding your personal information and how we will treat it. If you do not agree with our Privacy Policy, please do not download, install, register with, access, or use Krisp. Please note that this Privacy Policy does not apply to Krisp AI Meeting Assistant product users, their Authorized Users, Site Visitors and Other Individuals (as such terms are defined in our Privacy Policy for AI Meeting Assistant) and access to and use of Krisp and the Site by such parties is subject to the Privacy Policy for AI Meeting Assistant.
WHO WE ARE
Company is a Delaware corporation with the following corporate information:
Krisp Technologies, Inc.
2150 Shattuck Ave, Suite 1300, Berkeley, CA 94704, United States
For End Users in the EEA and the U.K., note that we may collect your personal data as:
-
A “data controller” when we determine the means and purpose of processing, or as
-
A “data processor” when we collect and process End User personal data on behalf of our Customers who use our Services.
When we act as a ‘data processor’, our Customers are primarily responsible for making sure that they have properly informed End Users of their policies and practices and your rights. However, Company handles and secures your personal information as set forth in this Privacy Policy (except as noted otherwise in this Privacy Policy).
CHANGES TO THIS PRIVACY POLICY
This Privacy Policy was last updated on the date indicated above, but we suggest that you review it from time to time, as Krisp and our business may change. As a result, at times it may be necessary for Company to make changes to this Privacy Policy. Company reserves the right to update or modify this Privacy Policy at any time and from time to time without prior notice. However, if an update materially impacts your rights or how we use your personal information, we will notify you either by email or other direct communication before such updates take effect. Your continued use of Krisp after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy.
TO WHOM DOES THIS POLICY APPLY
Note at the outset that this Privacy Policy does not cover our Customers’ websites, products or services. Each Customer is responsible for posting its own terms, conditions, and privacy policies, and ensuring compliance with all applicable laws and regulations. This Privacy Policy applies to:
-
Customers: as noted above, this includes entities and organizations as well as any individuals who register or create an account on behalf of an entity or organization in order to use Krisp.
-
End Users: Company processes End User data on behalf of its Customers. While our Customers are responsible, as data controllers, for how and why they collect and process their End User personal information, this Privacy Policy also applies to any End User personal information that we process, as a data processor, in order to provide Krisp to our Customers, except where specifically indicated.
INFORMATION WE COLLECT
What personal information we process depends on how and why you use Krisp. We process personal information that we receive:
-
Directly, from you when you provide it to us, such as in connection with Krisp.
-
Indirectly, through automated technologies as described herein, or from third parties.
PLEASE NOTE AT THE OUTSET THAT COMPANY DOES NOT HAVE ACCESS TO OR STORE ANY AUDIO DATA. COMPANY PROCESSES MICROPHONE/SPEAKER AUDIO DATA ONLY ON CUSTOMERS’ DEVICES. THIS DATA DOES NOT LEAVE THE CUSTOMERS’ DEVICES AND COMPANY DOES NOT HAVE ACCESS TO THE CONTENT OF CUSTOMER AND END USER CONVERSATIONS.
Information We Collect Directly From You
You can generally visit our Site without having to submit any personal information. If you request more information, or sign up for Krisp, we will collect personal information as follows.
Contact Forms
If you contact us via the contact form on our Site, we will ask you to provide information (e.g. your name, email address, company name, title).
Account Information
When you register for a Customer account we request your email address. We may also ask you to submit your name and company name, as well as End Users who will have access to Krisp. This information is your “Account Information” for the purposes of this Privacy Policy. Account Information is required to identify you as a Customer and permit you to access your account(s).
Our Customers are responsible for ensuring that they comply with applicable privacy laws and notice requirements with respect to any individual whose name and information is submitted in connection with the Account Information.
Customer Payment Information
In order to process your payment Information, we use PCI-compliant third-party processors, as explained in the section on Payment Processing below. This information is processed by our payment service provider and we receive a confirmation of payment, which we then associate with your Account Information and any relevant transactions. Please note that other payment methods (e.g wire transfer) may be availed to you as well.
Optional Information
We may also ask you to submit personal information if you choose to use interactive features of Krisp, including participation in research studies, surveys, requesting customer support, or otherwise communicating with us. For example, if you participate in a research study or survey, we may record your participation and feedback. In accordance with the consent provided by your device or other third-party API, we may process any contact information that you choose to provide us access to when using Krisp. We may also ask you for information when you interact with us (such as when responding to notices and announcements from us), and when you report a problem with Krisp or otherwise correspond with us. This includes:
-
Records and copies of your correspondence (including email addresses, reported issues containing recordings of your noise/voice cancellation test results, which can be stored and used by us in accordance with this Privacy Policy, and the MSA), if you contact us.
-
Your responses to surveys that we might ask you to complete for research purposes.
Information We Collect Indirectly
Device and Usage Information
When you download, use or interact with the Site, even if you do not have an account, we, or authorized third parties engaged by us, may automatically collect information about your use of the Krisp and/or the Site via your device (“Device and Usage Information”). This information consists of:
-
Information About your Device: information about the devices and software you use to access Krisp — primarily your device ID (or other persistent identifier that uniquely identifies your computer on the Internet), the operating system of your computer, device screen size, and other similar technical information.
-
Usage Information: information about your interactions with Krisp, including access dates and times, hardware and software information, device event information, log data, crash data, and search queries on the Site and/or Krisp. This information allows us to understand the screens that you view, how you’ve used the Site and/or Services (which may include administrative and support), and other actions on Krisp. We, or authorized third parties, automatically collect log data when you access and use Krisp. We use this information to administer and improve the Site and/or Krisp, analyze trends.
-
Location Information: based on Device and Usage Information, we are also able to determine general location information, but we do not store IP addresses.
Information from Third Parties
In some instances, we process personal information from third parties. This consists of data from our partners, such as transactional data from providers of payment services, or information from third parties who assist us with fraud prevention.
From time to time, we may combine information we collect as described above with personal information we obtain from third parties. For example, we may combine information entered through a Krisp sales submission with information that we receive from a third-party sales intelligence platform to enhance our ability to market our Services to Customers or potential Customers.
We may receive information about you when you integrate third-party apps, or link a third-party service with Krisp. If you decide to activate an integration, the third-party may share with us some information about you that is required to ensure your experience is more seamless, such as your name, email, or other content or information needed to facilitate the integration. The information we receive when you link or integrate Krisp with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with Krisp. Additionally, if you sign up or login to Krisp using a third party authentication provider supported by us (e.g. Google, Microsoft, etc.), we may collect authentication information provided to us by such a provider to allow you to log in.
Information We Process on Behalf of Our Customers
As noted above, we will process Account Information in order to provide Krisp to our Customers. This includes End User information, in order to enable End Users to access and use Krisp, and may consist of names and/or email addresses.
As explained above, we do not have access to or store any voice content.
PAYMENT PROCESSING
We do not directly collect your payment information and we do not store your payment information. We use third-party, PCI-compliant, payment processors, which collect payment information on our behalf in order to complete transactions. While our administrators are able to view and track actual transactions via customer portals, we do not have access to, or process, your credit card information.If we availed other payment methods, we may request your bank information to process refunds, if any.
HOW & WHY WE USE PERSONAL INFORMATION
We use your personal information for a number of different reasons, as further explained below.
For End Users located in the EEA, and the U.K., we must have a valid legal basis in order to process your personal data when we are acting as a ‘data controller’. The main legal bases under the European Union’s General Data Protection Regulation (GDPR) that justify our collection and use of your personal information are:
-
Performance of a contract: when your personal information is required in order to enter into or perform our contract with you, such as when you engage us to provide Krisp.
-
Consent: when you have consented to our use of your personal information via a consent form (online or offline).
-
Legitimate interests: when we use your personal information to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights.
-
Legal obligation: when we must use your personal information to comply with our legal obligations.
-
Legal claims: when your personal information is necessary for us to defend, prosecute or make a claim.
Below are the general purposes and corresponding legal bases (in brackets) for which we may use your personal information:
-
Providing you access to and use of Krisp, including accessing content, features and functionality [depending on the context, performance of a contract, legitimate interests, or consent]
-
Providing Krisp and creating accounts [performance of a contract]
-
Processing and completing transactions, including verifying payments, and sending you related information, including purchase confirmations and invoices and important notices [depending on the context, performance of a contract or legitimate interests]
-
Developing and improving Krisp and user experience and conducting research studies, surveys. [legitimate interests or consent]
-
Responding to your queries and requests, or otherwise communicating directly with you such as to give you notices about your account [depending on the context, performance of a contract, legitimate interests, and in some cases, legal claims]
-
Detecting fraud, illegal activities or security breaches [legitimate interests]
-
Ensuring compliance with applicable laws [compliance with a legal obligation]
-
Conducting statistical analyses and analytics by monitoring and analyzing trends, usage, and activities on Krisp [consent where required, or legitimate interests]
-
Customizing Krisp experience according to your individual interests, such as through storing information about your preferences and recognizing you when you use or access the Site or Krisp [legitimate interests]
-
Managing our relationship with you, including Customer service or feedback [legitimate interests or performance of a contract]
-
Send you related information, such as updates, security alerts, and support messages [legitimate interests]
-
Increasing the number of Krisp customers through marketing and advertising [consent where required, or legitimate interests]
-
Sending commercial communications, in line with your communication preferences, about products and services, features, newsletters, offers, promotions, and events [consent and in some cases, depending on location, with existing customers, legitimate interests]
-
Carrying out our obligations and enforcing our rights arising from any contracts entered into between you and us, including for billing and collection [depending on the context, performance of a contract or legal claims]
-
Providing information to regulatory bodies when legally required, and only as outlined below in this Privacy Policy [legal obligation, legal claims, legitimate interests]
DISCLOSURE OF YOUR INFORMATION
We only disclose your personal information as described below.
Third-Party Service Providers
Company discloses personal information to our third-party agents, contractors, or service providers who are hired to perform services on our behalf. These companies do things to help us provide the Site and/or Krisp, and in some cases collect information directly, for example as explained in Payment Processing above. Below is an illustrative list of functions for which we may use third-party service providers:
-
Hosting and content delivery network services
-
Analytics services
-
Customer support services
-
Payment processors
-
Communication platforms
-
Functionality and debugging services
-
Professional service providers, such as auditors, lawyers, consultants, accountants and insurers
Business Transfers and Transactions
As we continue to grow, we may purchase websites, applications, subsidiaries, other businesses or business units. Alternatively, we may sell businesses or business units, merge with other entities and/or sell assets or stock or receive financing, in some cases as part of a reorganization or liquidation in bankruptcy. In order to evaluate or as part of these transactions, we may transfer your personal information to a successor entity upon a merger, consolidation or other corporate reorganization in which Company participates, to a purchaser or acquirer of all or a portion of Company’s assets, bankruptcy included, or to an investor.
Customers
When we act on behalf of our Customers (as a data processor or service provider), we may provide End Users’ personal information to our Customers in order to comply with their requests, End Users’ requests and/or regulator requests, among others. Occasionally, we will provide our Customers with aggregated information that does not identify End Users directly, in order to provide information about usage, demographics (such as location) or other general information.
Legal Obligations and Security
In addition, Company will preserve or disclose your personal information in limited circumstances (other than as set forth in this Privacy Policy), including: (i) with your consent; (ii) when we have a good faith belief it is required by law, such as pursuant to a subpoena, warrant or other judicial or administrative order (as further explained below); (iii) to protect the safety of any person and to protect the safety or security of Krisp or to prevent spam, abuse, or other malicious activity of actors with respect to Krisp; or (iv) to protect our rights or property or the rights or property of those who use Krisp. If we are required to disclose personal information by law, such as pursuant to a subpoena, warrant or other judicial or administrative order, our policy is to only respond to requests that are properly issued by law enforcement within the United States or via mutual legal assistance mechanism (such as a treaty) in accordance with applicable laws.
DATA SECURITY
We respect and are committed to safeguarding your privacy and have undertaken and put in place reasonable security measures.
To learn about our Security measures, please visit our Security for Enterprises page.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
General Retention Periods
We use the following criteria to determine our retention periods:
-
The amount, nature and sensitivity of your information.
-
The reasons for which we collect and process the personal data.
-
The length of time we have an ongoing relationship with you and provide you with access to our Site and/or Krisp.
-
Applicable legal requirements.
We retain personal information for as long as needed to provide Krisp. Note, however, that with respect to our Customers with active accounts, we may retain certain essential account information, but otherwise regularly delete other information that is less essential to the provision of Krisp in order to minimize our storage of data. We also will retain personal information that we’ve collected from you where we have an ongoing legitimate business need to do so (for example, to comply with applicable legal, tax or accounting requirements). Additionally, we cannot delete information when it is needed for the establishment, exercise or defense of legal claims (also known as a “litigation hold”). In this case, the information must be retained as long as needed for exercising respective potential legal claims. When we no longer have an ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), we will securely store your personal information and isolate it from any further processing until deletion is possible. For any questions about data retention, please contact [email protected].
Anonymization
In some instances, we may choose to anonymize your personal data instead of deleting it, for statistical use, for instance. When we choose to anonymize, we make sure that there is no way that the personal data can be linked back to you or any specific End User.
INTERNATIONAL DATA TRANSFERS
Company is a United States corporation, which primarily stores information in the United States. To facilitate our global operations, we may process personal information from around the world, including from other countries and in other countries in which Company has operations, in order to provide Krisp.
If you are accessing or using Krisp or otherwise providing personal information to us, you are agreeing and consenting to the processing of your personal information in the United States and other jurisdictions in which we operate.
You are responsible for informing your End Users of how and where their personal information will be processed at the time of collection. Because different countries may have different data protection laws than the United States we take steps to ensure adequate safeguards are in place to protect your data as explained in this Privacy Policy. We enter into data processing agreements with our Customers on request.
ADDITIONAL INFORMATION FOR USERS IN THE EEA AND THE U.K.
Rights and Choices
If the GDPR applies to you because you are in the EEA or the U.K., you have certain rights in relation to your personal data:
-
The right to be informed: our obligation to inform you that we process your personal data (and that’s what we’re doing in this Privacy Policy)
-
The right of access: your right to request a copy of the personal data we hold about you (also known as a ‘data subject access request’)
-
The right of rectification: your right to request that we correct personal data about you if it is incomplete or inaccurate (though we generally recommend first making any changes in your Account Settings)
-
The right to erasure (also known as the ‘right to be forgotten’): under certain circumstances, you may ask us to delete the personal data we have about you (unless it remains necessary for us to continue processing your personal data for a legitimate business need or to comply with a legal obligation as permitted under the GDPR, in which case we will inform you)
-
The right to restrict processing: your right, under certain circumstances, to ask us to suspend our processing of your personal data
-
The right to data portability: your right to ask us for a copy of your personal data in a common format (for example, a .csv file)
-
The right to object: your right to object to us processing your personal data (for example, if you object to us processing your data for direct marketing)
-
Rights in relation to automated decision-making and profiling: our obligation to be transparent about any profiling we do, or any automated decision-making. These rights are subject to certain rules around when you can exercise them.
How you may exercise these rights depends on how you use Krisp, as explained below..
End Users in the EEA or the U.K.
Company has no direct relationship with End Users. Our Customers are solely responsible for ensuring compliance with all applicable laws and regulations with respect to their End Users, and this includes handling all data subject requests. We rely on our Customers to comply with the underlying legal requirements and respond directly to End Users when End Users wish to exercise the rights set forth above. However, if an End User sends a request to Company to access, correct, update, or delete his/her information, we will direct that End User to contact the Customer’s website(s) with which he/she interacted directly, and cooperate with our Customers as required by applicable law in order to ensure that our Customers satisfy their End Users’ requests.
CONTACT US
If you have questions about data protection, or if you have any requests for resolving issues with your personal data, we encourage you to first contact us so we can reply to you more quickly.
Krisp Technologies, Inc.
2342 Shattuck Ave, Suite 367, Berkeley, CA 94704, United States
[email protected]