Gretel Privacy Statement
Effective date: August 4th, 2020
Thanks for entrusting Gretel Labs, Inc. (“Gretel”, “we”) with your data, your projects, and your personal information. Holding on to your private information is a serious responsibility, and we want you to know how we're handling it.
All capitalized terms have their definition in Gretel’s Terms of Service, unless otherwise noted here.
The short version
As described below: We use your personal information as this Privacy Statement describes. No matter where you are, where you live, or what your citizenship is, we provide a high standard of privacy protection to all our users around the world, regardless of their country of origin or location.
Of course, the short version and the Summary below don't tell you everything, so please read on for more details.
Gretel Privacy Statement
What information Gretel collects
"User Personal Information" is any information about one of our Users which could, alone or together with other information, personally identify them or otherwise be reasonably linked or connected with them. Information such as a username and password, an email address, a real name, an Internet protocol (IP) address, and a photograph are examples of “User Personal Information.”
User Personal Information does not include aggregated, non-personally identifying information that does not identify a User or cannot otherwise be reasonably linked or connected with them. We may use such aggregated, non-personally identifying information for research purposes and to operate, analyze, improve, and optimize our Website and Service.
Information users provide directly to Gretel
We require some basic information at the time of account creation. When you initially register for Gretel, we ask you to connect with a valid GitHub or Gmail account and email address.
If you sign on to a paid Account with us, we collect your full name, address, and credit card information or PayPal information. Please note, Gretel does not process or store your credit card information or PayPal information, but our third-party payment processor does.
You may choose to give us more information for your Account profile, such as your full name, an avatar which may include a photograph, your biography, your location, your company, and a URL to a third-party website. This information may include User Personal Information. Please note that your profile information may be visible to other Users of our Service.
Information Gretel automatically collects from your use of the Service
If you have a paid Account with us, we automatically collect certain information about your transactions on the Service, such as the date, time, and amount charged.
If you're accessing our Service or Website, we automatically collect the same basic information that most services collect, subject, where necessary, to your consent. This includes information about how you use the Service, such as the pages you view, the referring site, your IP address and session information, and the date and time of each request. This is information we collect from every visitor to the Website, whether they have an Account or not. This information may include User Personal information.
Cookies and Similar Technologies Information
As further described below, and subject, where applicable, to your consent, we automatically collect information from cookies and similar technologies (such as cookie ID and settings) to keep you logged in, to remember your preferences, and to identify you and your device.
We may collect certain information about your device, such as its IP address, browser or client application information, language preference, operating system and application version, device type and ID, and device model and manufacturer. This information may include User Personal information.
Information we collect from third parties
Gretel may collect User Personal Information from third parties. For example, we collect name and email address data when you register via a GitHub or Gmail account. Gretel does not purchase User Personal Information from third-party data brokers.
What information Gretel does not collect
We do not intentionally collect “Sensitive Personal Information”, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. If you choose to store any Sensitive Personal Information on our servers, you are responsible for complying with any regulatory controls regarding that data.
If you are a child under the age of 13, you may not have an Account on Gretel. Gretel does not knowingly collect information from or direct any of our content specifically to children under 13. If we learn or have reason to suspect that you are a User who is under the age of 13, we will have to close your Account. We don't want to discourage you from learning to code, but those are the rules. Please see our Terms of Service for information about Account termination. Different countries may have different minimum age limits, and if you are below the minimum age for providing consent for data collection in your country, you may not have an Account on Gretel.
We do not intentionally collect User Personal Information that is stored in your data projects or other free-form content inputs. Any personal information within a user's data project is the responsibility of the data project owner.
How Gretel uses your information
- We may use your information for the following purposes:
- We use your Registration Information to create your account, and to provide you the Service.
- We use your Payment Information to provide you with the Paid Account service, or any other Gretel paid service you request.
- We use your User Personal Information, specifically your username, to identify you on Gretel.
- We use your Profile Information to fill out your Account profile and to share that profile with other users if you ask us to.
- We use your email address to communicate with you, if you've said that's okay, and only for the reasons you’ve said that’s okay. Please see our section on email communication for more information.
- We use User Personal Information to respond to support requests.
- We use User Personal Information and other data to make recommendations for you, such as to suggest projects you may want to follow or contribute to.
- We may use User Personal Information to invite you to take part in surveys, beta programs, or other research projects, subject, where necessary, to your consent .
- We use Usage Information and Device Information to better understand how our Users use Gretel and to improve our Website and Service.
- We may use your User Personal Information if it is necessary for security purposes or to investigate possible fraud or attempts to harm Gretel or our Users.
- We may use your User Personal Information to comply with our legal obligations, protect our intellectual property, and enforce our Terms of Service.
- We limit our use of your User Personal Information to the purposes listed in this Privacy Statement. If we need to use your User Personal Information for other purposes, we will ask your permission first. You can always see what information we have, how we're using it, and what permissions you have given us in your user profile.
Our legal bases for processing information
To the extent that our processing of your User Personal Information is subject to certain international laws (including, but not limited to, the European Union's General Data Protection Regulation (GDPR)), Gretel is required to notify you about the legal basis on which we process User Personal Information. Gretel processes User Personal Information on the following legal bases:
- When you create a Gretel Account, you provide your Registration Information. We require this information for you to enter into the Terms of Service agreement with us, and we process that information on the basis of performing that contract. We also process your username and email address on other legal bases, as described below.
- If you have a paid Account with us, we collect and process additional Payment Information on the basis of performing that contract.
- We rely on your consent to use your User Personal Information under the following circumstances: when you fill out the information in your user profile; when you decide to participate in a Gretel training, research project, beta program, or survey; and for marketing purposes, where applicable. All of this User Personal Information is entirely optional, and you have the ability to access, modify, and delete it at any time. While you are not able to delete your email address entirely, you can make it private. You may withdraw your consent at any time.
- Generally, the remainder of the processing of User Personal Information we perform is necessary for the purposes of our legitimate interest, for example, for legal compliance purposes, security purposes, or to maintain ongoing confidentiality, integrity, availability, and resilience of Gretel’s systems, Website, and Service.
If you would like to request deletion of data we process on the basis of consent or if you object to our processing of personal information, you may contact us as firstname.lastname@example.org to delete your data. You can also force deletion of all data yourself by deleting your account and data projects via the Gretel Service.
How we share the information we collect
We may share your User Personal Information with third parties under one of the following circumstances:
With your consent
We share your User Personal Information, if you consent, after letting you know what information will be shared, with whom, and why. For example, if you purchase an application listed on our Marketplace, we share your username to allow the application Developer to provide you with services. Additionally, you may direct us through your actions on Gretel to share your User Personal Information. For example, if you join an Organization, you indicate your willingness to provide the owner of the Organization with the ability to view your activity in the Organization’s access log.
With service providers
We share User Personal Information with a limited number of service providers who process it on our behalf to provide or improve our Service, and who have agreed to privacy restrictions similar to the ones in our Privacy Statement by signing data protection agreements or making similar commitments. Our service providers perform payment processing, customer support ticketing, network data transmission, security, and other similar services. While Gretel processes all User Personal Information in the United States, our service providers may process data outside of the United States or the European Union.
For security purposes
If you are a member of an Organization, Gretel may share your username, Usage Information, and Device Information associated with that Organization with an owner and/or administrator of the Organization who has agreed to the Terms of Service or applicable customer agreements, to the extent that such information is provided only to investigate or respond to a security incident that affects or compromises the security of that particular Organization.
For legal disclosure
Gretel strives for transparency in complying with legal process and legal obligations. Unless prevented from doing so by law or court order, or in rare, exigent circumstances, we make a reasonable effort to notify users of any legally compelled or required disclosure of their information. Gretel may disclose User Personal Information or other information we collect about you to law enforcement if required in response to a valid subpoena, court order, search warrant, a similar government order, or when we believe in good faith that disclosure is necessary to comply with our legal obligations, to protect our property or rights, or those of third parties or the public at large.
We will retain your Personal Information for as long as your account is active or as long as needed to provide you the Services after which time it shall be deleted, subject to our right to retain and use such Personal Information necessary to comply with our legal obligations, resolve disputes, and to enforce our agreements.
Change in control or sale
We may share User Personal Information if we are involved in a merger, sale, or acquisition of corporate entities or business units. If any such change of ownership happens, we will ensure that it is under terms that preserve the confidentiality of User Personal Information, and we will notify you on our Website or by email before any transfer of your User Personal Information. The organization receiving any User Personal Information will have to honor any promises we made in our Privacy Statement or Terms of Service.
Aggregate, non-personally identifying information
We share certain aggregated, non-personally identifying information with others about how our users, collectively, use Gretel, or how our users respond to our other offerings and new features. For example, we may compile statistics on the API activity across Gretel.
Please note that some unrevised information may remain in our records after revision of such information or deletion of your account, or in cached and archived pages. Some information may remain viewable elsewhere to the extent that it was copied or stored by other users. We may use any aggregated data derived from or incorporate your Personal Information after you delete your information, but not in a manner that would identify you personally.
We do not sell your User Personal Information for monetary or other consideration.
Other important information
Data Project Content
Gretel personnel do not access private data projects unless required to for security purposes, to assist the data project owner with a support matter, to maintain the integrity of the Service, to comply with our legal obligations, or as otherwise described in the Terms of Service.
Tracking and analytics
We use a number of third-party analytics and service providers to help us evaluate our Users' use of Gretel, compile statistical reports on activity, and improve our content and Website performance. We use our own internal analytics software to provide features and improve our content and performance.
How Gretel secures your information
Gretel takes all measures reasonably necessary to protect User Personal Information from unauthorized access, alteration, or destruction; maintain data accuracy; and help ensure the appropriate use of User Personal Information.
Gretel enforces a written security information program. Our program:
- aligns with industry recognized frameworks;
- includes security safeguards reasonably designed to protect the confidentiality, integrity, availability, and resilience of our Users' data;
- is appropriate to the nature, size, and complexity of Gretel’s business operations;
- includes incident response and data breach notification processes; and
- complies with applicable information security-related laws and regulations in the geographic regions where Gretel does business.
In the event of a data breach that affects your User Personal Information, we will act promptly to mitigate the impact of a breach and notify any affected Users without undue delay.
Transmission of data on Gretel is encrypted using SSH, HTTPS (TLS). Our service is hosted within Amazon Web Services utilizing a high level of physical and network security, and all data stored at rest is encrypted.
No method of transmission, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security.
How we communicate with you
We use your email address to communicate with you, if you've said that's okay, and only for the reasons you’ve said that’s okay. For example, if you contact our Support team with a request, we respond to you via email.
Depending on your settings, Gretel may occasionally send notification emails about changes in a data project you’re watching, new features, requests for feedback, important policy changes, or to offer customer support. We also send marketing emails, based on your choices and in accordance with applicable laws and regulations. There's an “unsubscribe” link located at the bottom of each of the marketing emails we send you. Please note that you cannot opt out of receiving important communications from us, such as emails from our Support team or system emails, but you can configure your notifications settings in your profile to opt out of other communications.
Our emails may contain a pixel tag, which is a small, clear image that can tell us whether or not you have opened an email and what your IP address is. We use this pixel tag to make our email more effective for you and to make sure we’re not sending you unwanted email.
If you have concerns about the way Gretel is handling your User Personal Information, please let us know immediately. We want to help. You may contact us at email@example.com with the subject line "Privacy Concerns." We will respond promptly — within 15 days at the latest.
Changes to our Privacy Statement
Although most changes are likely to be minor, Gretel may change our Privacy Statement from time to time. We will provide notification to Users of material changes to this Privacy Statement through our Website at least 10 days prior to the change taking effect by posting a notice on our home page or sending email to the primary email address specified in your Gretel account. For changes to this Privacy Statement that are not material changes or that do not affect your rights, we encourage Users to check our Site Policy data project frequently.
Questions regarding Gretel's Privacy Statement or information practices should be directed to firstname.lastname@example.org.