StarWind Software, Inc. (“StarWind”) complies with the principles of Regulation (EU) 2016/679 of the European Parliament and of the Council “On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”). If you are a natural person of the European Union within the meaning of the GDPR, you are afforded certain additional rights by the GDPR as further described within this GDPR Policy.
StarWind complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) as set forth by the U.S. Department of Commerce. StarWind has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. If there is any conflict between the terms in the Privacy Policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, please visit https://www.dataprivacyframework.gov/. The Federal Trade Commission has jurisdiction over StarWind’s compliance with the EU-U.S. DPF. To view StarWind’s EU-US Data Privacy Framework status and listing as a participant, click the following link to view the Data Privacy Framework List of Participants.
In compliance with the EU-U.S. DPF, StarWind commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF.
StarWind does use the services of third parties, such as e-mail service providers, purchase, shipping and order processing merchants and marketing companies that act as independent contractors on behalf of StarWind. These parties are contractually prohibited from using personally identifiable information for any purpose other than for the purpose StarWind specifies and are expected to provide the same level of protection for personal information as required by the EU-US DPF Principles.
Data Controller
When and if StarWind receives your personal information directly from you, or through its licensees and affiliates, it performs the functions of a Data Controller, as defined by the GDPR, and has the ability to determine how personal data is collected, for what purposes, and how this data is to be processed. As the Data Controller, StarWind has implemented many technical and operational measures to ensure the most complete protection of personal data processed through its Website, and Services, as those terms are defined in the StarWind Privacy Policy. Contact information for the Data Protection Officer can be found below.
Data Processor
StarWind processes your data in accordance with this Privacy Policy. StarWind uses industry standard safeguards to secure your information.
Consent
If this GDPR policy applies to you, consents concerning your personal information are handled in compliance with the GDPR. Where and if consent requirements under the Privacy Policy conflict with the GDPR, the GDPR prevails if the regulation applies to you.
Legal Basis for Processing
Article 6(1)(a) of the GDPR serves as the legal basis for processing operations for which we obtain consent for a processing purpose. Where processing is based on consent as per Article 6(1)(a), you have the right to withdraw your consent at any time. To withdraw your consent, please contact our Data Protection Officer at Bohdan.zvarun@starwind.com. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
If the processing of personal data is necessary for the performance of a contract to which you are a party, as is the case, for example, when processing operations are necessary to provide a service, the processing is based on Article 6(1)(b). The same applies to such processing operations which are necessary for carrying out pre-contractual measures, for example in the case of inquiries concerning our products or services. If our company is subject to a legal obligation by which processing of personal data is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1)(c). If the processing of personal data may be necessary to protect your vital interests or of another natural person, then the processing is based on Art. 6(1)(d). Finally, processing operations could be based on Article 6(1)(f) if processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by your fundamental rights and freedoms under the GDPR.
GDPR Rights:
i. Right of Confirmation
You may obtain confirmation of whether or not your personal data is being processed. If you wish to exercise your right of confirmation, you may contact StarWind and/or its Data Protection Officer.
ii. Right of Access
You may obtain from StarWind information about your stored personal data at any time and a copy of such information. If you wish to exercise your right of access, you may contact StarWind, and/or its respective Data Protection Officer.
iii. Right to Rectification
You may request the rectification of inaccurate personal data. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, by means of providing a supplementary statement. If you wish to exercise your right of rectification, you may contact StarWind and/or its respective Data Protection Officer, as outlined below.
iv. Right to Erasure (Right to be Forgotten)
You may request the erasure of your personal information by contacting StarWind and/or its respective Data Protection Officer. Furthermore, you may delete your User Account information by accessing your User Account settings page on the Website. Please note that while any changes you make will be reflected in active user databases within a reasonable time, we may retain all information you submit for the prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so, such as for archiving purposes within the public interest.
v. Right of Restriction of Processing
You have the right to restrict processing where one of the following applies:
▪ The accuracy of the personal data is contested by the data subject, for a period enabling the Data Controller to verify the accuracy of the personal data.
▪ The processing is unlawful and the data subject opposes the erasure of the personal data and requests instead the restriction of their use instead.
▪ The Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defense of legal claims.
▪ The data subject has objected to processing pending the verification whether the legitimate grounds of the Data Controller override those of the data subject.
vi. Right of Data Portability
You may request to receive your personal data in a structured, commonly used and machine-readable format. You have the right to transmit this data to another Data Controller without interference.
Furthermore, you may have the personal data transmitted directly from one Data Controller to another, where technically feasible and does not adversely affect the rights and freedoms of others.
vii. Right to Object to Automated Decision Making
You may object to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, as long as the decision is not is necessary for entering into, or performance of, a contract between you and StarWind; or is not authorized by European Union or Member State law to which you are subject; or is not based on the data subject’s explicit consent.
viii. Right to Object to Processing
You may object to the processing of your personal data by contacting our Data Protection Officer, outlined below, unless there are legitimate grounds for the processing within the public interest, or for the establishment, exercise or defense of legal claims.
If StarWind processes personal data for direct marketing purposes, you shall have the right to object at any time to the processing of your personal data for such marketing. This applies to profiling to the extent that it is related to such direct marketing. If you object to StarWind regarding the processing for direct marketing purposes, then we will no longer process the personal data for these purposes.
ix. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement if you believe that the processing of your personal data infringes the GDPR. For more information and a list of national supervisory authorities, please visit: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Retention Policy
We only retain personally identifiable information about you for a limited period of time as long as we need it to provide you with Services or otherwise fulfill the purposes for which we have initially collected it, unless otherwise required by law. We will retain and use information as necessary to comply with our legal obligations, and archival purposes, resolve disputes, and enforce our agreements.
Cross Border Data Transfers; Storage
If and when sharing of information involves cross-border data transfers, for instance, to the United States of America and other jurisdictions, StarWind uses EU Standard Contract Clauses and other suitable safeguards to permit data transfers from the EU to other countries. Where the Website allows for users to be located in the European Union, their personal information may be transferred to countries outside of the EU. The Standard Contractual Clauses commit companies transferring and receiving your personal information to protect the privacy and security of your data.
Data Protection Officer
In compliance with the EU-U.S. DPF, StarWind commits to resolve DPF Principles-related complaints about our collection and use of your personal information. Inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF should first contact StarWind’s Data Protection Officer at:
StarWind Software Inc.
Data Protection Officer: Mr. Bohdan Zvarun
Email: Bohdan.zvarun@starwind.com
ATTN: Privacy Inquiry/Complaint
Mailing Address: 35 Village Rd. Suite 100 Middleton, MA 01949 USA
In your message, please describe in as much detail as possible the nature of your inquiry or the ways in which you believe that StarWind’s Privacy Policy has been breached. StarWind and/or the DPO will investigate your inquiry or complaint promptly.