Piwik PRO Privacy Policy

Privacy Policy last updated on: 24.05.2018

Your privacy is very important to us – after all “Take control of your data” is our credo. Our products were built on a foundation of security and privacy. They are compliant with General Data Protection Regulation (GDPR) requirements and other legal provisions for data protection. Below you’ll find all necessary information to make educated decisions about how you want us to process your personal data.

Summary

Want to change your consent status? Use the following settings:

Privacy settings

Want more information about what your consents mean? Go to privacy and consent settings.

Want to submit a data subject request? Go to our data subject request form

We use your data only when you consent to it directly or when we need to based on what you ask of us. If you’d like more details, we invite you to read on.

This information applies to visitors of our website, clients and job applicants. We’ve broken it down into three main sections:

  1. Our Marketing and Sales activities
  2. Piwik PRO product and data that we process on behalf of our clients
  3. Recruitment by our Human Resources team

If you feel something is not addressed in this Privacy Policy or have further questions, our Data Protection Officer (DPO) can be reached at gdpr@piwik.pro.

The data controller for (1) Marketing and Sales and (2) Piwik PRO product-related activities is: Piwik PRO group, that includes Piwik PRO Sp. z o.o. (ul. Św. Antoniego 2/4, 50-073 Wrocław, Poland), Piwik PRO GmbH (Lina-Bommer-Weg 6, 51149 Cologne, Germany) and Piwik PRO LLC (222 Broadway, 19th Floor, New York, NY 10038, United States). Learn more about the Piwik PRO group at https://piwik.pro/about/.

The data controller for (3) Recruitment is: Clearcode group, that includes Clearcode SA (holding company, ul. Św. Antoniego 2/4, 50-073 Wrocław, Poland), Clearcode LLC (222 Broadway, 19th Floor, New York, NY 10038, United States), Piwik PRO Sp. z o.o. (ul. Św. Antoniego 2/4, 50-073 Wrocław, Poland), Piwik PRO GmbH (Lina-Bommer-Weg 6, 51149 Cologne, Germany) and Piwik PRO LLC (222 Broadway, 19th Floor, New York, NY 10038, United States). Learn more about the Clearcode group at https://clearcode.cc/about/.

Marketing and Sales

We work hard to find and introduce new people to our product as well as improve the quality of our website. We want to communicate clearly and directly with everyone that visits. To do this we need data. However, we practice privacy by design, privacy by default and data minimization so we’ll take the smallest amount of data we can while still providing our visitors an enjoyable experience.

We request processing of personal data of visitors, such as IP address, a cookie identifier and email address (but only in the case that visitors request information be sent by email). We also collect non-personal data to learn how visitors found our website, what kind of device they’re using, how long they stayed, which pages they visited, etc. This non-personal data is tied to a temporary identifier that is removed after the end of each browsing session.

Privacy and consent settings

Here’s how we use your data when you give us the following consents:

Analytics

Purpose: improve site user interface, optimize sales and marketing content
Personal data used: browser cookie, browsing behavior on piwik.pro, device information, IP address
First party involved: Piwik PRO
Third parties involved: Hotjar, HubSpot, Google AdWords (Conversion Pixel)

A/B testing and personalization

Purpose: A/B tests, content personalization, improve site user interface, optimize sales and marketing content
Personal data used: browser cookie, browsing behavior on piwik.pro, device information, IP address
Third parties involved: VWO

Marketing automation

Purpose: send marketing materials relevant to your interests
Personal data used: browser cookie, browsing behavior on piwik.pro, IP address, other data you give us will be added to your visitor profile
Third parties involved: Hubspot

Remarketing

Purpose: display our advertisements on other websites
Personal data used: browser cookie, browsing behavior on piwik.pro, IP address
Third parties involved: Facebook Ads, Google AdWords, LinkedIn Ads, Twitter Ads

We process personal data based on consent according to Art. 6(1)(a) GDPR, which you are free to give or refuse. You’ll see consent options when you visit our website for the first time. You can change your decisions at anytime by clicking the button below. If you change your decision it will not affect the lawfulness of processing based on consent before its withdrawal.

Privacy settings

Individual data subject right (Your rights)

Remember there are number of rights you can exercise:

You have the right to lodge a complaint with a supervisory authority (in Poland, the President of the Data Protection Office).

If you would like to exercise your individual rights, send us a message via the form below. The form collects cookies that identify you as a returning visitor so we know what data the request concerns. We will then adjust or remove data about you from our database and pass the request to our partners. We require your email to communicate with you during processing of your request.

Data Subject Request Form

Data requests

Select the type of data request and note any special requests. We’ll do our best to fulfill your request to the letter. We need your email address to contact you about your request. We won’t use this email address for any purpose other than the completion of your request.

Access data
Access data
Data erasure
Data rectification

Our partners - tools we use for Marketing and what we use them for.

Piwik PRO Marketing Suite is our own analytics and customer data platform. We collect first-party data about website visitors based on cookies, IP and fingerprinting; we create user profiles based on user browsing history and calculate metrics related to website usage such as bounce rate, depth of visits, page views etc. We host our solution on Microsoft Azure infrastructure in the Netherlands and the data is stored for a period of 2 years for raw data and 3 years for aggregated data in reports. (Purpose of processing data: Analytics, Conversion tracking based on consent, Legal basis: Art. 6 (1)(a) GDPR).

HubSpot is an inbound marketing and sales platform that we use for email marketing, marketing automation, website personalization and integrating CRM data about leads with their behavioral data. HubSpot collects browsing history (only from our site) and user personal data acquired via lead capture forms. HubSpot products are hosted in U.S.-based data centers, and HubSpot stores user data for 12 months. (Purpose of processing data: Marketing Automation based on consent, Legal basis: Art. 6 (1)(a) GDPR)

Hotjar is a tool we use for analyzing and visually representing online user behavior. We use Hotjar heatmaps, polls and surveys to improve user experience on our website. Hotjar collects responses in real-time from any device. It retains data for 365 days from the date the data was captured and stores it in Ireland. (Purpose of processing data: Analytics based on consent, Legal basis: Art. 6 (1)(a) GDPR)

VWO is a testing and optimization platform we use to create A/B tests on our websites. VWO collects aggregate data for goals, tests, surveys, and website reviews. VWO is hosted on SSAE16-certified Bare Metal Servers. All production data is stored in IBM SoftLayer data centers spread across different locations. Data is retained for 45-90 days. (Purpose of processing data: A/B testing and personalization based on consent, Legal basis: Art. 6 (1)(a) GDPR)

Google AdWords is an advertising system. We use it to display Piwik PRO ads in Google's search results (or in the Google Display Network), run ad or remarketing campaigns, track conversions, and create campaign performance reports. Google AdWords collects cookie-based behavioral data about users. Data collected by Google AdWords is retained for 30 days. (Purpose of processing data: Remarketing based on consent, Legal basis: Art. 6 (1)(a) GDPR)

Facebook Ads is an advertisement system we use to serve Piwik PRO ads to Facebook users. We use it to run remarketing and ad campaigns in Facebook Ad Network, to create campaign performance reports, and conversion tracking. Facebook Ads collects cookie-based behavioral data about users and retains data in their data centers including in Lulea, Sweden in the European Union. (Purpose of processing data: Remarketing based on consent, Legal basis: Art. 6 (1)(a) GDPR)

LinkedIn Ads is an advertisement system we use to serve ads to LinkedIn users. We run ad and remarketing campaigns in the LinkedIn Ad Network and compile data for reports about campaign performance and conversion tracking. LinkedIn Ads collects cookie-based behavioral data about users. The data is retained for 365 days and then deleted. LinkedIn's data centers are currently located in the U.S. and Singapore. (Purpose of processing data: Remarketing based on consent, Legal basis: Art. 6 (1)(a) GDPR)

Twitter Ads serves advertisements to Twitter users. We use Twitter Ads to run ad and remarketing campaigns, for conversion tracking and to create campaign performance reports. Twitter Ads collects cookie-based behavioral data about users. Twitter keeps Log Data for a maximum of 18 months and the data may be transferred to and stored in the US, Ireland, and other countries where Twitter operates. (Purpose of processing data: Remarketing based on consent, Legal basis: Art. 6 (1)(a) GDPR)

Piwik PRO product

Our clients own 100% of the data we gather on their behalf.

A Data Processing Agreement (DPA) is available for both Piwik PRO Marketing Suite Cloud (SaaS) and Piwik PRO Marketing Suite On-Premises – our Account executives or customer success team members can provide details.

Piwik PRO Marketing Suite Cloud is hosted on Microsoft Azure Netherlands and Microsoft Azure Germany. The older version of the platform is hosted by Leaseweb in the US and Germany.

Piwik PRO On-Premises is hosted on the client's infrastructure.

We do NOT send collected data to other sub-processors or third parties nor do we use it for our own purposes.

For Piwik PRO Marketing Suite Cloud, data is stored for a period of 2 years for raw data and 3 years for aggregated data. Data retention periods are set by the client for Piwik PRO Marketing Suite On-Premises.

The full scope of data that can be gathered by our platform is described here.

All cookies used by the Piwik PRO platform are listed here.

We want all clients to be fully compliant so those who are using Piwik PRO Marketing Suite with Tag Manager can also take advantage of Consent Manager. But it's the client's responsibility to configure their Consent Manager instance according to their own privacy policy.

Requests to exercise any individual data subject rights of visitors to a website tracked by one of the instances of Piwik PRO Cloud should be sent by a Client to support@piwik.pro so we can remove the record from our database.

For users of any Piwik PRO instance, it's important to know that we use third-party tools:

If your team would like to contact our support, keep in mind the hosting location of Intercom and Freshdesk. To keep the data within the EEA, send us datasets or screenshots using your own secure channel or our secure tool. We provide all information about this during the onboarding process or details can be requested directly via support@piwik.pro.

If you request a database export, it will be placed on a secure server on Amazon EU in Frankfurt, Germany.

Recruitment

The recruitment process is shared within the Clearcode group, that includes Clearcode S.A. (mother company), Clearcode LLC, Piwik PRO Sp. z o.o., Piwik PRO GmbH and Piwik PRO LLC. During recruitment we will gather and process personal data such as employment history, education and projects you’ve worked on. We get this information from your CV, the application form and from links or other information you provide us. To submit your application to us you must first agree to processing of your personal data (a check box on the application page) in accordance with Art. 6(1)(a) GDPR. Sending us your job application via jobs@piwik.pro means that you acknowledge our privacy policy. The provision of your personal data is neither a statutory nor a contractual requirement, but we can't consider you for a position without the ability to process your personal data.

Only HR and team members who are directly involved in your recruitment process, usually representatives of the team you are applying to, have access to your data. Each team member has been trained in data security and is formally obliged by their contract to keep it private. All who would have access to your recruitment data have such a contract with the Clearcode group (defined at the beginning of this privacy policy).

We collect and use personal information you have provided only for the purposes of recruitment process. Data that we collect throughout recruitment is used only for the communication with candidates, to evaluate their qualifications and to make a final hiring decision. During the recruitment process we use software from external partners such as Google Suite and Dropbox. The maximum time your data is held is 36 months.

You have a right to access your data, correct or remove it, or completely withdraw your consent for processing it at any time. Such requests should be sent to our DPO: gdpr@piwik.pro. The withdrawal of a consent does not affect the lawfulness of processing based on consent before its withdrawal.

Third-Party Websites

Links from our site to external websites do not operate under this Privacy Policy. For example, if you click on a referrer website link on our site, you may be taken to a website that we do not control. These third-party websites may independently solicit and collect information from you, including personal and financial data. We recommend that you consult the privacy statements of all third-party websites you visit by clicking on the “privacy” link typically located at the bottom of the webpage you are visiting.

Children’s Privacy

We forbid the use of the website to individuals age 18 and below, without the consent of a parent or guardian over the age of 18. We do not knowingly collect personal data from children under the age of 13.

Notice to California Users

Subject to the limitations under California Civil Code § 1798.83, if you are a California resident and have an established business relationship with us, you may ask us to provide you with a list of certain categories of personal information that we have disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year. You may also request the identity of certain third parties that received your personal information from us for their direct marketing purposes during the immediately preceding calendar year. You may make a request as described hereinabove once a year.

To make such a request, you can contact us at legal@piwik.pro or mailing us at: Piwik PRO, 222 Broadway, New York, NY 10038. Please mention in your communication that you are making a “California Shine the Light” inquiry. We will respond within 30 days.

Changes to the Privacy Policy

We will occasionally update this Privacy Policy. When changes to this Privacy Policy will be posted, the date at the top of this Privacy Policy will be revised. We recommend to check the website from time to time to inform yourself of any changes in this Privacy Policy or any of other policies.