AssetFlowOnline Privacy Policy

Effective Date: 1 August 2024

1. Introduction and Scope

Welcome to AssetFlowOnline's Privacy Policy. At AssetFlowOnline, we are committed to protecting the privacy and security of our users' personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard the information you provide when using our platform.

This policy applies to all users of AssetFlowOnline, including those using our free plan and our paid subscription services. As we serve an international audience, this policy is designed to comply with privacy laws and regulations from various jurisdictions worldwide.

By using AssetFlowOnline, you agree to the collection and use of information in accordance with this policy. We encourage you to read this Privacy Policy carefully to understand our practices regarding your personal data and how we will treat it.

2. Information Collection

AssetFlowOnline collects various types of information to provide and improve our services. The information we collect depends on how you interact with our platform and whether you are using our free or paid subscription plan.

2.1 Personal Information: When you create an account or register for our services, we may collect personal information such as your name, email address, phone number, company information, and billing information (for paid subscription users). This information is collected to create and manage your account, contact you about your service, pre-populate order forms, and process payments for paid subscriptions.

2.2 Usage Data: We collect information about how you use our platform, including your device information (e.g., device type, operating system), IP address, browsing activities within our platform, and feature usage patterns. This data helps us enhance service delivery, improve platform functionality, and provide a more personalized experience.

2.3 Asset Movement Data: As part of our core services, we collect information related to asset movements, including client names and addresses, asset types and quantities, consumable types and quantities, transportation details, and timestamps of asset movements. This data is essential for providing you with accurate asset management services, analytics, and billing.

2.4 Free vs. Paid Plan Data Collection: While we collect basic account and usage information for all users, paid subscription users may provide additional data such as detailed company information, extended asset tracking history, custom fields for asset management, and integration data with other business systems.

2.5 Automatic Data Collection: We also collect some information automatically through cookies and similar technologies. Please refer to our Cookies and Tracking Technologies section for more details.

2.6 Data Minimization: We adhere to the principle of data minimization, collecting only the information necessary to provide and improve our services. You may choose not to provide certain information, but this may limit your ability to use some features of AssetFlowOnline.

3. Use of Information

AssetFlowOnline uses the collected information for various purposes to provide, maintain, and improve our services. Our use of your information includes, but is not limited to:

3.1 Service Provision: We use your information to provide and maintain our asset management services, process transactions, and send service-related communications.

3.2 Personalization: We use your data to personalize your experience, including tailoring content and features to your preferences and usage patterns.

3.3 Analytics and Improvement: We analyze user behavior and feedback to improve our platform, develop new features, and enhance user experience.

3.4 Communication: We may use your contact information to send you important updates about our services, respond to your inquiries, and provide customer support.

3.5 Marketing: With your consent, we may send promotional materials about new features, special offers, or other information we think you may find interesting. You can opt-out of these communications at any time.

3.6 Legal Compliance: We may use your information to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

3.7 Fraud Prevention and Security: We use information to detect, prevent, and address fraud, security risks, and technical issues that could harm AssetFlowOnline, our users, or the public.

4. Data Storage and Security

AssetFlowOnline takes the security of your data seriously. We implement robust measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security practices include:

4.1 Data Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols. We also encrypt sensitive data at rest using advanced encryption standards.

4.2 Secure Infrastructure: Our services are hosted on Amazon Web Services (AWS), leveraging their world-class security infrastructure. We operate within a Virtual Private Cloud (VPC) for enhanced isolation and protection.

4.3 Access Controls: We maintain strict access controls, ensuring that only authorized personnel can access user data, and only for legitimate business purposes.

4.4 Regular Security Audits: We conduct regular security assessments and penetration tests to identify and address potential vulnerabilities.

4.5 Data Backups: We perform regular backups of our databases to prevent data loss and ensure business continuity.

4.6 Employee Training: Our team undergoes regular security awareness training to stay updated on best practices for data protection.

4.7 Incident Response: We have a comprehensive incident response plan in place to quickly address any potential security breaches or data incidents.

While we implement these security measures, please note that no method of transmission over the Internet or electronic storage is 100% secure. We strive to protect your personal information but cannot guarantee its absolute security.

5. Data Sharing and Third-Party Access

AssetFlowOnline is committed to maintaining the confidentiality of your information. We do not sell, rent, or trade your personal information to third parties for their marketing purposes. However, we may share your information in the following circumstances:

5.1 Service Providers: We may share your information with third-party service providers who perform services on our behalf, such as hosting, data analysis, payment processing, and customer service. These providers have access to your information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

5.2 Business Transfers: If AssetFlowOnline is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information.

5.3 Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

5.4 Protection of Rights: We may disclose your information to protect the rights, property, or safety of AssetFlowOnline, our users, or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction.

5.5 With Your Consent: We may share your information with third parties when we have your consent to do so.

5.6 Aggregate or De-identified Data: We may share aggregate or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other purposes.

6. User Rights and Choices

AssetFlowOnline respects your rights regarding your personal information. We provide you with choices about the data we collect and how it's used. You have the following rights and options:

6.1 Access and Update: You can access and update your personal information directly through your account settings. If you need assistance, please contact our support team.

6.2 Data Portability: You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format.

6.3 Deletion: You can request the deletion of your personal information. Note that we may retain certain information as required by law or for legitimate business purposes.

6.4 Opt-out of Marketing Communications: You can opt-out of receiving promotional emails from us by following the instructions in those emails. If you opt-out, we may still send you non-promotional communications, such as those about your account or our ongoing business relations.

6.5 Cookies and Tracking Technologies: You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of the site may become inaccessible or not function properly.

6.6 Do Not Track: We do not currently respond to Do Not Track (DNT) signals. However, you can usually choose to set your browser to remove or reject browser cookies before using AssetFlowOnline's website, with the drawback that certain features may not function properly without the aid of cookies.

6.7 Data Processing Objection: In certain circumstances, you have the right to object to the processing of your personal information.

6.8 Withdraw Consent: Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.

To exercise these rights or if you have any questions or concerns about your data, please contact us using the information provided in the "Contact Us" section of this policy. We will respond to your request within a reasonable timeframe.

7. International Data Transfers

AssetFlowOnline operates globally and may transfer your personal information to different jurisdictions around the world. By using our services, you acknowledge that your personal information may be transferred to and processed in countries other than your country of residence. We take appropriate measures to ensure that your personal information remains protected in accordance with this Privacy Policy and applicable data protection laws.

7.1 Data Transfer Mechanisms: When transferring data from the European Economic Area (EEA) to countries that have not received an adequacy decision from the European Commission, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.

7.2 Data Storage Locations: Our primary data storage locations are in [specify primary locations, e.g., the United States and the European Union]. However, we may use service providers in various locations globally to process data on our behalf.

7.3 Compliance with Local Laws: We strive to comply with applicable data protection laws in all jurisdictions where we operate. This includes implementing additional measures where required by local laws, such as data localization requirements.

7.4 Cross-Border Data Protection: We have implemented measures to ensure that any international data transfers comply with applicable cross-border data transfer restrictions and requirements.

7.5 User Consent: By using our services and providing your information, you consent to the transfer, storage, and processing of your personal information in countries outside your country of residence, which may have different data protection rules than in your country.

7.6 Data Transfer Impact Assessments: We conduct regular assessments of our data transfer practices to ensure they meet the requirements of applicable data protection laws and regulations.

If you have questions about our international data transfer practices or wish to obtain more information about the safeguards we use, please contact us using the information provided in the "Contact Us" section of this policy.

8. Children's Privacy

AssetFlowOnline's services are designed for business use and are not intended for individuals under the age of 16. We do not knowingly collect or solicit personal information from children. If we learn that we have inadvertently collected personal information from a child under 16, we will promptly delete it.

9. Cookies and Tracking Technologies

AssetFlowOnline uses cookies and similar tracking technologies to enhance your experience on our platform, understand usage patterns, and improve our services. By using our website and services, you consent to our use of cookies and similar technologies as described in this policy.

9.1 What Are Cookies: Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.

9.2 Types of Cookies We Use:

- Essential Cookies: These are necessary for the website to function properly and cannot be switched off. They are usually only set in response to actions you take, such as setting your privacy preferences, logging in, or filling in forms.

- Performance Cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us know which pages are the most and least popular and see how visitors move around the site.

- Functionality Cookies: These cookies enable the website to provide enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages.

- Targeting Cookies: These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites.

9.3 Third-Party Cookies: Some cookies may be set by third-party services that appear on our pages. We do not control the dissemination of these cookies. You should check the third-party websites for more information about these cookies.

9.4 Managing Cookies: You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the website may become inaccessible or not function properly.

9.5 Other Tracking Technologies: We may also use web beacons, pixels, and other tracking technologies to gather statistics about your use of our website and services. These technologies help us analyze trends, administer the website, track users' movements around the site, and gather demographic information about our user base as a whole.

9.6 Do Not Track: Currently, various browsers offer a "Do Not Track" option, but there is no standard for how DNT should work on commercial websites. Due to lack of such standards, AssetFlowOnline's website does not respond to DNT consumer browser settings.

For more information about cookies and how to manage them, please visit www.allaboutcookies.org or consult your browser's help documentation.

10. Changes to the Privacy Policy

AssetFlowOnline reserves the right to modify this Privacy Policy at any time. We strive to keep our privacy practices current with industry standards and regulatory requirements. When we make changes to this policy, we will update the "Effective Date" at the top of this page.

10.1 Notification of Changes: For significant changes to this Privacy Policy, we will make reasonable efforts to provide notification through our website or by sending you an email.

10.2 Review of Changes: We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information. Your continued use of AssetFlowOnline after any modifications to this Privacy Policy will constitute your acknowledgment of the changes and your consent to abide and be bound by the modified Privacy Policy.

10.3 Material Changes: If we make material changes to how we treat our users' personal information, we will notify you by email to the primary email address specified in your account and/or through a notice on our website's home page.

10.4 Prior Versions: We will keep prior versions of this Privacy Policy in an archive for your review upon request. To request access to a previous version, please contact us using the information provided in the "Contact Us" section.

10.5 Acceptance of Changes: If you do not agree with the changes to this Privacy Policy, you should discontinue your use of our services. Your continued use of AssetFlowOnline after the posting of changes constitutes your acceptance of such changes.

10.6 Change Log: We may maintain a change log as part of this Privacy Policy, summarizing material changes and their effective dates. This allows you to quickly review recent updates.

10.7 Regulatory Compliance: We will update this policy as necessary to comply with relevant regulations and reflect any new practices regarding how we handle your personal information.

If you have any questions or concerns about this Privacy Policy or its changes, please contact us using the information provided in the "Contact Us" section of this policy.

11. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please visit our Contact Us page. There, you'll find our current contact information and a form to submit your inquiry.

For privacy-specific concerns, including requests to exercise your data rights, please specify "Privacy Inquiry" in your message.

We strive to respond to all inquiries within a reasonable timeframe, typically within 5-10 business days. To protect your privacy and security, we may need to verify your identity before processing your request.

12. Legal Compliance

AssetFlowOnline is committed to complying with applicable data protection laws and regulations in the jurisdictions where we operate. We implement appropriate technical and organizational measures to ensure data security and protect user privacy rights as required by various privacy laws worldwide. This includes honoring data subject rights, maintaining necessary records, and regularly reviewing our privacy practices to ensure ongoing compliance. For specific information about how we handle data protection in your jurisdiction, please contact us using the information provided in the "Contact Information" section.

13. Account Termination and Data Retention

AssetFlowOnline has established policies for account termination and data retention to ensure proper handling of user information when accounts are closed or become inactive. This section outlines our practices in these areas:

13.1 Account Termination: You may choose to terminate your AssetFlowOnline account at any time. To do so, please contact our support team or use the account deletion option in your account settings, if available.

13.2 Data Retention After Termination: Upon account termination, we will retain certain information as required by law or for legitimate business purposes. This may include:

- Financial records for tax and accounting purposes

- User data necessary to prevent fraud or future abuse

- Aggregate or anonymized data that does not identify you personally

- Backup data for a limited period as part of our disaster recovery procedures

13.3 Data Deletion: We will delete or anonymize other personal information associated with your account within 90 days of account termination, unless:

- We are required to retain it to comply with applicable laws

- There are outstanding issues, claims, or disputes requiring us to keep the relevant information

13.4 Inactive Accounts: If your account remains inactive for an extended period (typically 24 months), we may terminate it to ensure data minimization. We will attempt to notify you before such termination.

13.5 Data Portability: Before account termination, you may request a copy of your data in a structured, commonly used, and machine-readable format.

13.6 Retention for Legal Purposes: We may retain certain data for longer periods if necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

13.7 Third-Party Data: Please note that terminating your AssetFlowOnline account may not remove data stored on third-party platforms integrated with our services. You should contact those third parties directly to request data deletion.

13.8 Restoration Requests: Once your data is deleted, we may not be able to restore your account. Please consider your decision carefully before requesting account termination.

If you have questions about account termination or our data retention practices, please contact us using the information provided in the "Contact Information" section.