Promethium, Inc. (“Promethium”, “we”, “our”, “us”) is a Silicon Valley-based data software company that helps eliminate or reduce data management and analytics complexity to deliver data-driven answers in real-time in your organization. Because we take your privacy seriously (“you” or “your” as a customer organization (“Customer”), individual in such organization, or website visitor), we have developed revolutionary architecture that minimizes our involvement in the collection and processing of data, including personally identifiable information (PII) or personal data (collectively, as those terms are defined by applicable privacy laws, “personal data”). Almost all interaction with personal data using the Promethium data solution/service occurs in your organization’s environment, behind your firewall(s), or otherwise is of a minimal nature, as we will explain further in this Privacy Policy (“Policy”). Even our company website, located at www.promethium.ai (“Site”) collects very little personal data from you.
Nonetheless, we are careful to comply with applicable privacy laws. While very little personal data is collected from residents of the European Economic Area (“EEA”), Switzerland or the United Kingdom (“UK”) at present, we recognize that this may change over time, so we have adopted principles that reflect the requirements of the European laws generally referred to as the General Data Protection Regulation (“GDPR”), and post-Brexit to the UK’s version of GDPR, generally referred to as “UK-GDPR.” In addition, while we are not yet subject to California’s privacy law applicable to California residents(“CCPA”) we nonetheless follow procedures that adhere to that legislation as well with regard to your privacy rights. Toward the bottom of this Policy, we will enumerate the rights we afford to European residents whose personal data may be processed by us.
While the CCPA is intended to apply to all natural persons who are California residents, we have opted to extend the stringent California standards to all US users of the Site. You have the right to know and access what personal data we collect about you, where it was obtained/sourced and the purposes for which such information will be used, the categories of personal information that were collected in the twelve months preceding your request, and what categories of personal data were sold or disclosed for business purposes (although we do not sell your personal data), and to whom, in the 12-months preceding such a request for your information. Please review the “CCPA” section of this Policy below.
Most of the personal data we collect from you is obtained in the following ways: (1) Site visitors: personal data that you choose to provide to us during your use of certain areas of the Site, in order to download or obtain information from the Site, or in connection with your subsequent activities related to the Site, such as when you choose to subscribe to newsletters; (2) Contact information: Customer information, vendor information and similar contact information: personal data, mostly necessary contact information, that we get from Customers, vendors and their personnel via email, often stored in our email system on computers, or that is placed into contracts with Customers and vendors; (3) Analytics information: personal data we get from Google Analytics to enhance the Site experience and possibly use for promotional purposes, virtually all of it collected only in aggregate and/or anonymized manner. More specifically, we collect the following personal data from the sources listed below, and disclose it to the third parties listed below:
a. If you visit the Site and respond to one of the opportunities to obtain materials from us, e.g., to download a brochure, white paper or report, or to try the Promethium service for free, or to schedule a demonstration, or to make a sales inquiry you are asked to provide the following personal data for everything but the demonstration or sales inquiry: first name, last name and email address. If you wish to schedule a demonstration or make a sales inquiry, in addition to the personal data listed in the previous sentence, you are also asked to provide job title, company name, and phone number. This personal data is stored with a secure third-party service such as MailChimp or Wix, and is used to communicate with you about our company and products, and to fulfill your requests for information or for a product demonstration. You have the right to unsubscribe or opt out at any time (for residents of EEA, Switzerland and the UK, see GDPR-related sections below).
b. Contact information from Customers and vendors (and other business-related third parties): As mentioned, personal data from our business contacts, are mostly provided via exchange of emails, and stored in our email system. Other personal data may be found in contracts between the parties. Most personal data of this nature includes first name, last name and email address. Sometimes it includes physical address, telephone number(s) and job title.
c. Customer data and other personal information: CRM-type information, which may include personal data, is stored in Salesforce. There is a contractual basis and/or legitimate interests basis for collecting this personal data. A contest or survey could be a promotional use requiring opt-in. This data is not disclosed to any third parties.
d. The only personal data obtained by Promethium from use by Customers of its data solution/service is first name, last name and email address (required of all users). While a user of the Promethium software platform would log into Promethium using SSO and entering his or her user name and password, this information is maintained encrypted in Amazon Web Services, and we cannot access it.
e. Promethium does not track visitors to its Site, and therefore does not use nonessential cookies. Consequently, there is no need to seek opt-in consent under applicable law.
f. We do not knowingly collect personal data from users under the age of 13, nor is our service of interest to any minors. If we are made aware of that we have such personal information, we will take reasonable steps to delete that information. While consumers under 16 must opt-in to any sale of their personal data under the CCPA, we do not sell personal information.
If we process any personal data from residents of the EEA, Switzerland or the UK, please see the paragraphs below for relevant details.
a. Cookies. A cookie is a small piece of data sent from a website and stored in a user’s web browser while the user is visiting a website. When the user loads the website, the browser sends the cookie back to the server to notify the website of the user’s previous activity. Third-party cookies are used to compile records of users’ browsing history. With respect to web cookies, beacons and similar technologies that are not strictly necessary for our collection of personal data, such as cookies for marketing purposes, we are not using them. If we begin using them and expand our European presence, we will seek opt-in consent for such use to ensure compliance with applicable law. You can set your browser to notify you when a cookie is sent or to refuse cookies or delete them, but certain features of the Site may not work as a result.
b. Legal Basis of Processing.
I. The legal basis for much of Promethium’s processing of your personal data would be Article 6(1)(b) of the GDPR, which allows processing of personal data as necessary for the performance of a contract. When seek to obtain materials from the Site, or sign up to use Promethium’s data service for free, or sign up for a demo, we need to process your personal data to respond to your requests and satisfy our contractual obligations to you with respect to the other purposes listed in the Privacy Policy above. Often we also have legitimate interests in providing you with something that you have requested, such as access to our newsletter, or to schedule a demonstration.
II. Promethium also may have legitimate interests under Article 6(1)(f) of the GDPR with respect to certain situations where Promethium needs to process your personal data to comply with applicable law (for example, we are required to comply with California law, where we are based), provide adequate customer service, or improve our products and services. In these cases, we will ensure that your privacy and other fundamental interests do not override our legitimate interests.
III. Finally, if Promethium determines that it wants to target ads to you based on the limited personal information provided on the Site, we would seek your opt-in consent first. At this time, we do not knowingly collect any personal data from EEA, Swiss or UK residents.
c. Personal Data Transfers outside the EEA/UK. It is possible that some of your personal data would be transferred to servers in the United States, which may not provide adequate data protection according to the European Commission. For example, SSO data is located in Amazon Web Services data centers, subject to a high degree of security and protection. Other personal data is maintained by well-known service providers such as Salesforce for CRM data. In the event that Promethium enters into Customer contracts in the EEA, Switzerland or the UK, Promethium would enter into appropriate data transfer agreements based on language approved by the European Commission pursuant to GDPR Art. 46(5), generally the Standard Contractual Clauses, implementing appropriate physical, technical and organizational security measures to protect personal data against accidental or unlawful destruction, alteration, loss, unauthorized disclosure or access, and other unauthorized or unlawful processing; and taking other measures to provide an adequate level of protection in accordance with applicable law. Any onward transfer would be subject to onward transfer requirement per applicable law.
d. Data Retention. Promethium keeps personal data for as long as required to meet our obligations to you, often contractual requirements, and to comply with applicable law. For example, if you register with Promethium on the Site for a newsletter, brochure, free use of the service or a demonstration, we retain your personal data for as long as we believe you may be actively interested in our services, and thereafter for as long as required for us to comply with applicable law, fulfill our contractual obligations to you or defend our legal interests in connection with any claim or action we might face before a dispute resolution body. We take commercially reasonable measures to ensure that personal data is deleted, erased or anonymized as soon as possible once the purposes for which such data was collected have been fulfilled.
e. Data Subject Rights. You have a right to request from Promethium access to and rectification, updating or erasure of your personal data. You also have the right to request the restriction of processing concerning you, in which case such personal data would be marked and processed by us only for certain purposes. We will not charge a fee for this, provided the request is not excessive or unreasonable. In addition, you have the right to data portability, which allows you to receive from us personal data about you which you have provided to us in a structured, commonly used and machine-readable format, such as a CSV file. We will do this free of charge. If it is technically feasible, you can request that we transmit the personal data directly to another organization, rather than to you. We will respond to the request within 30 days, unless the request is complex or you send us multiple requests, in which case we can extend our response by another 2 months upon notice to you.
You also have the right to object to various data processing activities, including processing activities that are based exclusively on your consent or processing for the purposes of direct marketing. You can exercise such rights by accessing the information in your account and/or by emailing us at privacy@pm61data.com. Please note that these rights may be subject to limitations and conditions under the GDPR or applicable national data protection laws.
If our collection of personal data from you has been based on obtaining your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You have the right to lodge a complaint with a supervisory authority in the EEA, Switzerland or the UK, as applicable.
We may choose not to fulfill any request that we determine is illegal or incorrect, where we need to maintain the personal data because of our contractual or legal obligations (e.g., personal data in case files), where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy, or where the rights of persons other than the individual would be violated, but our intention is to comply with opt-out requests, and other requests that seek to correct, update or delete your personal data , as fully as possible in accordance with applicable law. You will also be given notice should we use your personal data for a purpose other than that for which it was originally collected or processed. We do not ask for, collect or knowingly receive sensitive personal data, i.e., personal data specifying medical or health conditions, racial or ethnic origin, political opinions, religious beliefs, or information relating to sex life.
f. Profiling. Promethium does not, and the Promethium SaaS services do not, engage in profiling as defined in Art. 4(4) of GDPR; that is, we do not engage in “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.”
This Site may contain links to third-party websites. Promethium is not responsible for the privacy practices, content or security of any other website, which are subject to the privacy policy (if any) on such website(s).
In the event that we believe that there has been a security breach involving your personal data, we would endeavor to notify you promptly in accordance with applicable law. In the event such notification is appropriate under the circumstances, we would first try to notify you at the latest email address we have for you on record, subject to legal requirements.
Promethium reserves the right to modify this Privacy Policy at any time, in order to comply with law and as deemed necessary for our Site and business. Any Policy will be effective upon posting to the Site. Please check back periodically to see any updates or changes to our Privacy Policy. To the maximum extent permitted by applicable law, your continued use of the Site following the posting of changes to these terms means you accept these changes.
For questions about this Privacy Policy or Site practices, or to contact us regarding your personal data /information, please contact us at privacy@pm61data.com. If you know that you wish to have personal data removed or updated, you may also contact us at this email address.
Or you can correspond with us by regular mail at:
Promethium, Inc.
101 Jefferson Road, Suite 236
Menlo Park, CA 94025 USA