Newsafe Solutions Ltd. (“NLS”) offers tools and platform commercialized as “Echelon+” which provide the means to measure and increase employee engagement through gamified behavioral development tools (the “Echelon+ Platform”). NLS understands the importance of protecting Personal Information (as defined below). For this reason, NLS strives to have business procedures and security safeguards in place to protect Personal Information under its control.
- Definition of Personal Information “Personal Information” is defined as any information about an identifiable individual. This may include, for example, email addresses and contact details and any similar information provided to NLS in the course of its business operations, or which NLS may receive from business inquiries. Personal Information that is aggregated and/or de-identified or that cannot be associated with an identifiable individual is not considered to be Personal Information.
- International Compliance NLS complies with: (i) data protection laws applicable to NLS; (ii) anti-spam legislation applicable to NLS; and (iii) applicable industry standards concerning data protection, confidentiality or information security. NLS has global operations and therefore, in some cases, information managed by NLS may be transferred, processed and stored to other countries, although at all times NLS will ensure that Personal Information is protected by confidentiality and security procedures and protections that are, at a minimum, equivalent to those employed by NLS itself.
NLS complies with this Policy as well as Thailand’s Personal Data Protection Act BE 2562 (PDPA).
NLS also complies with the General Data Protection Regulation (Regulation (EU) 2016/679). Where applicable, our commitment to such regulation may be found in our Data Processing Addendum. NLS (or third parties acting on NLS’s behalf) may transfer Personal Information that NLS collects to countries outside of the European Economic Area. Where such transfer occurs, NLS will take steps to ensure that Personal Information is protected. NLS will make such transfers only if at least one of the following conditions are present:
- NLS has entered into a contract based on the “Standard Contractual Clauses”, provided that such contract, combined with technical and organizational measures, offers appropriate safeguards for the rights of the individuals whose personal data is being transferred;
- Such transfer is governed by “Binding Corporate Rules”, which have been approved by data protection authorities; or
- Such transfer is covered by a European Union Commission “adequacy decision”. You can find out more about this here.
Collection and Use of Personal Information through the Services.When providing the Services, NLS only processes Personal Information in accordance with the Terms and applicable laws. NLS generally uses Personal Information from or about its Customers and Users for the following purposes:
- to create, establish and administer Customer’s account, to process payments, to respond to Customer’s inquiries related to its account and to contact Customer about NLS’s Services or account-related matters;
- to provide Services, including to provide Customer and its Users with access and use of the Echelon+ Platform and customer support;
- to manage and develop NLS’s business and operations;
- to measure and analyze User behavior;
- to monitor, maintain and improve NLS’s Services or features;
- to understand how Users interact with NLS and ensure our services, products or features work correctly;
- to develop new services, products, features, programs and promotions;
- to understand Customers and Users’ needs and preferences and customize how we tailor and market products, programs and Services to our Customers and Users based on their interest;
- to meet legal and regulatory requirements and to allow NLS to meet contractual requirements relating to the Services provided to Customer;
- to conduct surveys on the quality of NLS’s Services or to collect feedbacks on the Services;
- to provide Customer with offers for additional services, features and products that NLS believes may be of interest to Customer;
- to conduct market or benchmarking research and data analytics by tracking and analyzing current or previously collected Personal Information; and
- to measure the effectiveness of our marketing.
When possible, NLS will use Personal Information in an aggregated and/or de-identified format.
Unless required or authorized by law, NLS will not use Personal Information for any other or new purpose without obtaining prior consent.
- Collection and Use of Personal Information through the Website NLS generally collects and uses Personal Information from or about its website Users as follows:
- Information Provided by Users. In many cases, NLS collects Personal Information directly from Users when they visit or use the website. For instance, NLS may collect the following types of information:
- Inquiries and Requests for a Trial or Service. NLS may collect Users’ name, contact information, email address and any other information provided when Users make an inquiry or contact NLS through the website, when Users sign up to receive NLS’s newsletter or when Users submit a request or an order for an NLS trial or service.
- Personalization of Website. When Users visit the website, they may, from time to time, be invited to provide information such as User’s title to help NLS personalize or customize the Users experience when using the website.
- Technical Information. When Users visit the website, NLS may collect, using electronic means such as cookies, technical information. This information may include information about visits to the website, including the IP address of the Users’ computer and which browser was used to view the website, the Users’ operating system, resolution of screen, location, language settings in browsers, the site the User came from, keywords searched (if arriving from a search engine), the number of page views, information entered, advertisements seen, etc. This data is used to measure and improve the effectiveness of the website or enhance the experience for Users. While most of the time this information is depersonalized, if this information relates to an identifiable individual, NLS will treat this information as Personal Information. NLS may also, without limitations, collect and use the following type of information when Users visit and/or interact with NLS on the website:
- Google Analytics: NLS uses Google Analytics which allows it to see information on User website activities including, but not limited to, page views, source and time spent on our website. This information is depersonalized and is displayed as numbers, meaning that it cannot be tracked back to individuals. Users may opt-out of NLS’s use of Google Analytics by visiting the Google Analytics opt-out page.
- Google AdWords: NLS uses Google AdWords Remarketing to advertise NLS across the Internet and to advertise on third party websites (including Google) to previous visitors of the website. AdWords remarketing will display ads to Users based on what parts of NLS website they have viewed by placing a cookie on the Users’ web browser. It could mean that NLS advertises to previous visitors who have not completed a task on the site, or this could be in the form of an advertisement on the Google search results page, or a site in the Google Display Network. This cookie does not in any way identify the User or give access to the Users’ computer or mobile device. The cookie is only used to indicate to other websites that the User has visited a particular page on the website, so that they may show the User ads relating to that page. If Users do not wish to participate in Google AdWords Remarketing, they can opt out by visiting Google’s Ads Preferences Manager.
- Privacy Policies of other Websites. This Policy only addresses the use and disclosure of information by NLS. Other websites that may be accessible through the website have their own privacy policies and data collection, use and disclosure practices.
- Personal Information from Other Sources. NLS may obtain from third parties additional Personal Information about a website User if such User gave permission to those third parties to share its information.
- Sharing of Personal Information NLS will not sell, rent or trade Personal Information to any third party. However, NLS may share Personal Information when authorized and/or required by law or as follows:
- Within NLS. We may share Personal Information within NLS (i.e. between our affiliates and subsidiaries) in Thailand for the purposes described in Sections 4, 5 and 6 of this Policy.
- Service Providers. NLS may grant access to Personal Information to third-party service providers in connection with the performance or the improvement of its website and Services. Before sharing any Personal Information with any of its third-party service providers, NLS will ensure that the third party maintains reasonable data management practices for maintaining the confidentiality and security of Personal Information and preventing unauthorized access.
- As Permitted or Required by Law. NLS may disclose Personal Information as required by applicable law or by proper legal or governmental authority. NLS may also disclose information to its accountants, auditors, agents and lawyers in connection with the enforcement or protection of its legal rights. NLS may also release certain Personal Information when it has reasonable grounds to believe that such release is reasonably necessary to protect the rights, property or safety of others and itself, in accordance with or as authorized by law. In the event NLS receives a governmental or other regulatory request for any Personal Information, NLS will promptly notify Customer, unless it is prohibited to do so, in order that Customer shall have the option to defend such action. NLS shall reasonably cooperate with Customer in such defense.
- Business Transaction. NLS may disclose Personal Information to a third party in connection with a sale or transfer of business or assets, an amalgamation, re-organization or financing of parts of our business. However, in the event the transaction is completed, Personal Information will remain protected by applicable data protection laws. In the event the transaction is not completed, NLS will require the other party not to use or disclose the Personal Information received in any manner whatsoever and to delete such Personal Information.
- Security of Personal Information NLS will store and process the Personal Information in a manner consistent with industry security standards, and as long as necessary for the purposes described in this Policy, unless a longer retention is required by law. NLS has implemented technical, organizational and administrative systems, policies, and procedures to help ensure the security, integrity and confidentiality of Personal Information and to mitigate the risk of unauthorized access to or use of Personal Information, including: (i) appropriate administrative, technical and physical safeguards and other security measures designed to ensure the security and confidentiality of the Personal Information it manages; (ii) a security design intended to prevent any compromise of its own information systems, computer networks or data files by unauthorized Users, viruses or malicious computer programs; (iii) appropriate internal practices including, but not limited to, encryption of data in transit; using appropriate firewall and antivirus software; maintaining these countermeasures, operating systems and other applications with appropriate reasonable up-to-date virus definitions and security patches so as to avoid any adverse impact to the Personal Information that it manages; (iv) appropriate logging and alerts to monitor access controls and to assure data integrity and confidentiality; and (v) permitting only authorized Users access to systems and applications, and all persons with authorized access to Personal Information must have a genuine business need-to-know prior to access (together, “Security Program”).
- Training and Supervision NLS maintains adequate training programs to ensure that its employees and any others acting on its behalf are aware of and adhere to its Security Program. NLS shall exercise necessary and appropriate supervision over its relevant employees to maintain appropriate confidentiality and security of the Personal Information it manages.
Data Incidents Involving Personal Information NLS shall promptly notify Customer of a data breach, of a loss of data or of a failure of NLS’s Security Program:
(a) which has resulted or is suspected to have resulted in the loss, unauthorized access, disclosure, use or acquisition of Personal Information (including hard copy records); and
(b) which, in NLS’s opinion, presents a real risk of significant harm to individuals whose Personal Information is impacted (“Data Incident”).
While the initial notice may be in a summary form, a comprehensive written notice shall be given to Customer within the legally required timeframe, where applicable. The notice shall summarize in reasonable detail the nature and scope of the Data Incident (including each data element type) and the corrective action taken or to be taken by NLS. NLS shall promptly take all necessary and advisable corrective actions and shall cooperate with Customer in all reasonable efforts to mitigate the adverse effects of Data Incidents and to prevent their recurrence.
- Users Legal Rights Regarding Personal Information To the extent that NLS’s processing of Personal Information is subject to the General Data Protection Regulation (Regulation (EU) 2016/679), NLS relies on its legitimate interests, described above, which are not overridden by your data protection interests, to process Personal Information. Subject to applicable laws, Users also have the right to: (i) access and rectification or erasure of Personal Information, to the extent that NLS may need to retain certain Personal Information, including for record keeping purposes or to comply with legal obligations; (ii) restrict or object to NLS’s use of Personal Information (though, in some cases, this may mean no longer using the Services or the website) where NLS is relying on a legitimate interest (or those of a third party) and there is something about User’s particular situation which impacts on User’s fundamental rights and freedoms; (iii) lodge a complaint with their local data protection authority (contact details for data protection authorities in the European Economic Area are available here); and (iv) data portability. Users will not have to pay a fee to exercise such rights, however, NLS may charge a reasonable fee or refuse to comply if the request is unfounded, repetitive or excessive.
How to Contact Us Any questions or complaints or requests regarding this Policy or NLS handling of Personal Information can be addressed by sending an email to email@example.com.
A User who seeks to exercise its data protection rights referred to in Section 10, in respect of Personal Information stored or processed by us on behalf of a Customer (e.g. the employer), must direct his/her query to such Customer, as being the data controller. If NLS receives such User’s request to exercise its data protection rights referred to in Section 10 (including for access to or correction of Personal Information), NLS shall redirect the User to Customer and, upon request from Customer, shall assist Customer in responding to such request, if applicable.
This Policy was last updated on April 22, 2021.