Effective Date / Last updated: March 25th, 2024
Privacy Policy
Effective Date / Last updated: March 25th, 2024
Fortenberry Risk Management (“we”, “our”, “us”) values and respects the privacy of individuals. This Privacy Policy (“Privacy Policy”) describes the types of information, including Personal Data, that we process as part of our websites, including https://www.fortenberryrisk.com/ and other online tools.
This Privacy Policy outlines individual rights regarding our collection, use, and disclosure of Personal Data related to the Services. As used in this Privacy Policy, the term “Personal Data” means information that identifies an individual or a household directly or indirectly, by reference to identifier(s) such as name, identification number, location data, online identifier, or one or more factors specific to an individual’s physical, physiological, genetic, mental, economic, cultural, educational, commercial, professional or social identity. The terms of this Privacy Notice are not intended to supersede any corporate agreements in place with your employer or other organization that you are affiliated with which has contracted to use our services (“Agreement(s)”). In the event of a conflict between this Privacy Notice and such Agreement(s), the terms of the Agreement(s) will prevail.
If there are questions about our privacy practices, please refer to the end of this Privacy Policy for information about how to contact us.
- PERSONAL DATA COLLECTION
- Some Personal Data is collected from Users through the Services.
b. Types of Personal Data Collected.
• Among the types of Personal Data collected through the Services are Cookies; Usage Data; email address; first name; last name; phone number; and IP address.
• Details of each type of Personal Data collected are provided in the dedicated sections of this Privacy Policy or through explanatory messages displayed before the data collection.
• Personal Data may be freely provided by the User, or, in the case of Usage Data, collected automatically when using the Services.
• Unless specified otherwise, all Personal Data requested by the Services is required for a User to use the Services and failure to provide this data may make it impossible for us to provide the Services. In cases where the Services indicate that some Personal Data is not required, Users are free not to communicate this data without impacting the availability or the functionality of the Services.
• Users who are uncertain about which Personal Data is required for the Services are welcome to contact us.
c. Users are responsible for any third-party Personal Data obtained, published, or shared by such Users through the Services and confirm that they have the third party’s consent to provide such data to us.
d. In addition to the information contained in this Privacy Policy, we may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request. - USE OF PERSONAL DATA AND PURPOSE OF PROCESSING
- We process Personal Data, where processing is necessary for our legitimate commercial interests and performance of the Services as further described in this Section. We do not sell Personal Data that we collect.
b. The purposes for which each type of Personal Data is collected through the Services are as follows:
• Providing the Services to Users
• Performing analytics on the Services
• Contacting the User
• Displaying content from external platforms
• Managing contacts and sending messages
• Performing platform services and hosting
• Managing registration and authentication
• Performing tag management
• Managing System logs and maintenance
• Performing internal operations, such as improving the effectiveness of our Services
• Conducting audits
• Transferring information as part of a merger or sale of the business
• Resolving disputes between Users, customers, and we
• Protecting the rights, safety, and information of us, our customers and their members.
• Complying with our legal obligations, responding to enforcement requests, protecting our rights and interests, and detecting any malicious or fraudulent activity - A User’s Personal Data may be used for legal purposes by us in court or in the stages leading to possible legal action arising from improper use of the Services. The User acknowledges and agrees that we may be required to reveal Personal Data upon request of public authorities.
d. we may aggregate, combine, anonymize, and/or pseudonymous any data that we collect and process, including Personal Data. This may be done for the purpose of performing the Services, correcting data currently held by us, expanding data sets and research.
III. WHO CAN ACCESS PERSONAL DATA COLLECTED
- we will only disclose Personal Data as set forth in this Privacy Policy, as permitted by law, or with the User’s consent. Where third parties are processing Personal Data on our behalf, they will be required to agree, by contractual means or otherwise, to process the Personal Data in accordance with applicable law and to act only on our instructions.
b. In addition to being accessible by us, in some cases, Personal Data may be accessible to certain types of persons involved with the operation of the Services (administration, sales, marketing, legal, system administration) or external parties (such as third party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by us.
c. we may disclose Personal Data to the following entities and for the listed purposes:
• Customers and Other Authorized Business Partners. For the purpose of providing the Services, we will share Personal Data with a User’s designated organization (i.e., we’re a customer).
• Employees. Only authorized employees have access to Personal Data
• To Comply with Legal Processes, Protect the Company, or Enforce our Rights. we may further disclose Personal Data when it is necessary to: (i) conform to legal requirements or comply with legal processes; (ii) enforce or apply our conditions of use and other agreements; (iii) protect the rights, safety, or property of we, our affiliates, our customers, service providers, Users or the public, or (iv) prevent a crime or protect national security (including exchanging information with other companies and organizations for fraud protection and credit risk reduction).
• As Part of a Merger or Sale of Business. We may disclose or transfer Personal Data in connection with a substantial corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy. - WE DO NOT SHARE YOUR INFORMATION WITH THIRD PARTIES FOR ANY MARKETING PURPOSE AND WE EXPLICITLY PROHIBIT ANY THIRD PARTY FROM ACCESSING OUR DATA FOR THE PURPOSES OF CONTACTING YOU IN ANY WAY. WHEN YOU OPT-IN TO RECEIVE COMMUNICATION FROM US, THAT INFORMATION STAYS WITH US.
- MODE AND PLACE OF PROCESSING DATA
- We take appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of Personal Data. We utilize industry-accepted reasonable security practices and have implemented reasonable technical and organizational measures to protect the confidentiality, security and integrity of User’s Personal Data. The measures that we have implemented take into account the current available security technologies, cost, and risk presented by the type of Personal Data we process. Although we use reasonable security measures to help protect Personal Data against unauthorized disclosure or loss, we cannot guarantee the security of Personal Data transmitted to us over the Internet. While we strive to use commercially acceptable means to protect Personal Data, there is no guarantee that information may not be accessed, disclosed, altered or destroyed.
b. The processing of Personal Data is carried out using computers and/or IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated herein or through the Services.
c. we may process Personal Data relating to Users if one of the following applies:
• Users have given their consent for one or more specific purposes. Note: Under some legislation, we may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any of the other legal bases specified herein. This, however, does not apply whenever the processing of Personal Data is subject to European data protection law;
• provision of data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
• processing is necessary for compliance with a legal obligation to which we is subject;
• processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in we; or
• processing is necessary for the purposes of the legitimate interests pursued by us
d. In any case, we will gladly help to clarify the specific legal basis that applies to the processing of a User’s Personal Data, and in particular whether the processing of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
e. The Personal Data is processed at our operating offices and in any other places where the parties involved in the processing are located.
f. Depending on the User’s location, data transfers may involve transferring the User’s Personal Data to a country other than their own.
g. Users are entitled to learn about the legal basis of Personal Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by we to safeguard their Personal Data. - RETENTION OF PERSONAL DATA
- Personal Data shall be processed and stored for as long as required by the purpose(s) it has been collected for.
• Personal Data collected for purposes related to the performance of a contract between us and the User (or User’s employer) shall be retained until such contract has been fully performed.
• Personal Data collected for the purposes of our legitimate business interests shall be retained as long as needed to fulfill such purposes.
• we may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn.
• we may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
b. Once the applicable retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to correct and the right to data portability cannot be enforced after expiration of the applicable retention period. - RIGHTS OF USERS
- Users may exercise certain rights regarding their Personal Data processed by we.
b. In particular, Users have the right to do the following:
• Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
• Object to processing of their Personal Data. Users have the right to object to the processing of their Personal Data if the processing is carried out on a legal basis other than consent.
• Access their Personal Data. Users have the right to learn if their Personal Data is being processed by us, obtain disclosures regarding certain aspects of such processing and obtain a copy of the Personal Data undergoing processing.
• Verify and seek rectification. Users have the right to verify the accuracy of their Personal Data and ask for it to be updated or corrected.
• Restrict the processing of their Personal Data. Users have the right, under certain circumstances, to restrict the processing of their Personal Data. Where Users have and exercise such rights, we will not process a User’s Personal Data for any purpose other than storing it.
• Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Personal Data from us.
• Receive their Personal Data and have it transferred to another controller. Users have the right to receive their Personal Data in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Personal Data is processed by automated means and that the processing is based on the User’s consent, on a contract which the User is part of or on pre-contractual obligations thereof.
• Lodge a complaint. Users have the right to bring a claim before their competent data protection authority.
c. Where Personal Data is processed for a public interest, in the exercise of an official authority vested in us or for the purposes of the legitimate interests pursued by we, Users may object to such processing by providing grounds related to their particular situation to justify the objection.
d. Should a User’s Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification. We do not process Personal Data collected for direct marketing purposes.
e. Any requests to exercise User rights can be directed to us through the contact details provided in this Privacy Policy.
VII. COOKIE POLICY
When a User first accesses the Services from certain jurisdictions, the User will receive a message advising the User that cookies are in use. By clicking “accept”, the User agrees to the use of cookies as described in this Privacy Policy. If the User does not wish to receive cookies, the User may withdraw their consent or set their browser to reject cookies or to alert the User when a cookie is placed on their device. If the User withdraws consent, limits or disables the use of cookies when the User visits or uses the Services, the User may not be able to use the full functionality of the Services. For more information about our specific use of cookies, please reference our “Cookie Policy,” which is attached as Schedule 1 (Cookie Policy) and incorporated herein by reference. We may also permit select third parties to use cookies to collect information about Users’ online activities across other websites or over time in order to assist us with Services analytics.
VIII. HOW “DO NOT TRACK” REQUESTS ARE HANDLED
The Services do not support “Do Not Track” requests. To determine whether any third-party services used by or linked to the Services honor “Do Not Track” requests, please read the privacy policies for those services.
- THIRD PARTY SERVICES
The Services may contain links to third-party websites, applications and services not operated by us. These links are provided as a service and do not imply any endorsement by us of the activities or content of these websites, applications, or services nor any association with their operators. We are not responsible for the privacy policies or practices of any third party including websites or services directly linked to or from our Services.
- INFORMATION FOR CALIFORNIA CONSUMERS
The California Consumer Privacy Act of 2018 (“CCPA”) provides several rights to California residents with regard to the collection, disclosure, sale, and deletion of their Personal Data. The Campaign Registry California Privacy Notice set forth in Schedule 2 (California Privacy Notice) describes in more detail our compliance with CCPA and how residents of California may exercise their CCPA Rights. If a User has questions about exercising their CCPA Rights, please contact us as set out below.
- USERS BASED IN THE EUROPEAN UNION OR THE UNITED KINGDOM
For purposes of the EU’s General Data Protection Regulation (“GDPR”), and the UK GDPR, the data controller is The Campaign Registry Inc., with an office at 1775 Tysons Blvd 5th Floor, McLean, Virginia 22102, USA.
We are headquartered in the United States. By using any of the Services from outside the United States, Users acknowledge that their Personal Data will be accessed by us or transferred to us in the United States and to those entities listed in Section III of this Privacy Policy who are located around the world; and that User Personal Data will be transferred to, and stored and processed in, the United States or elsewhere in the world where we servers are located.
XII. MINORS AND CHILDREN PRIVACY
We do not knowingly collect Personal Data from children under the age of 18. If we learn that Personal Data of persons younger than 18 years of age has been collected through the Services, we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child or a minor under the age of 13 has posted, submitted, or otherwise communicated Personal Data to us without your consent, then you may alert us at info@campaignregistry.com so that we may take appropriate action to remove the minor’s Personal Data from our systems.
XIII. DEFINITIONS
- “Data Processor”: The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the controller, as described in this privacy policy.
b. “Data Subject”: The natural person to whom the Personal Data refers.
c. “European Union” or “EU”: Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
d. “Usage Data”: Information collected automatically through the Services (or third-party services utilized for the Services), which can include: the IP addresses or domain names of the computers utilized by the Users who use the Services, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Services) and the details about the path followed within the Services with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
e. “User”: The individual using the Services who, unless otherwise specified, coincides with the Data Subject.
XIV. MISCELLANEOUS
- This privacy statement has been prepared based on provisions of multiple legislation, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
- More details concerning the collection or processing of Personal Data may be requested from us at any time. Please see our contact information for inquiries.
- Changes to this Privacy Policy
• We reserve the right to make changes to this Privacy Policy at any time by notifying its Users through the Services and/or – as far as technically and legally feasible – sending a notice to Users via any contact information available to us. Users are strongly recommended to check the Services often, referring to the date at the top of this Privacy Policy for the last modification date.
• Should changes to this Privacy Policy affect processing activities performed on the basis of the User’s consent, we shall collect new consent from the User, where required.
d. Contact Information for us/Data Controller
Fortenberry Risk Management 6240 Poplar Ave, Memphis, TN 38119
Our contact email: jonathan@fortenberryrisk.com