The privacy of your data is important to us.
When you work with Vireo, we ask for your name, company name, email address, and phone number. That's so we can send you invoices, updates, or other essential information. We’ll never sell your personal info to third parties, and we won’t use your name or company in marketing statements without your permission, either.
When you pay for our services via credit card, we ask for your credit card number and billing address. That's so we can charge you for service, calculate taxes due, and send you invoices. Your credit card is passed directly to our payment processor and doesn't ever go through our servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for account history, invoicing, and billing support. We store your billing address to calculate any sales tax due, to detect fraudulent credit card transactions, and to print on your invoices.
When you contact Vireo with a question or to ask for help, we'll keep that correspondence, and the email address, for future reference. When you browse our marketing pages, we'll track that for statistical purposes (like conversion rates and to test new designs). We also store any information you volunteer, like surveys, for as long as it makes sense.
The only times we’ll ever share your info:
- To provide products or services you've requested, with your permission.
- To investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
Your Rights With Respect to Your Information
You may have heard about the General Data Protection Regulation (GDPR) in Europe and the Protection of Personal Information and Electronic Documents Act (PIPEDA) in Canada. GDPR and PIPEDA gives people certain rights with respect to their personal information collected by us on the Site, and gives us certain responsibilities in managing that information. Accordingly, Vireo recognizes and will comply with GDPR/PIPEDA and those rights and responsibilities, except as limited by applicable law. The rights under GDPR include:
- Right of Access. This includes your right to access the personal information we gather about you, and your right to obtain information about the sharing, storage, security and processing of that information.
- Right to Correction. This is your right to request correction of your personal information.
- Right to Erasure. This is your right to request, subject to certain limitations under applicable law, that your personal information be erased from our possession (also known as the “Right to be forgotten”).
- Right to Complain. You have the right to make a complaint regarding our handling of your personal information with the appropriate supervisory authority.
- Right to Restrict Processing. This is your right to request restriction of how and why your personal information is used or processed.
- Right to Object. This is your right, in certain situations, to object to how or why your personal information is processed.
- Right to Portability. This is your right to receive the personal information we have about you and the right to transmit it to another party.
- Right to not be subject to Automated Decision-Making. This is your right to object and prevent any decision that could have a legal, or similarly significant, effect on you from being made solely based on automated processes. This right is limited, however, if the decision is necessary for performance of any contract between you and us, is allowed by applicable European law, or is based on your explicit consent.
If you have questions about exercising these rights or need assistance, please contact us at firstname.lastname@example.org.
We’ll respond to your email within 48 hours.
Processors we use
As part of the services we provide, and only to the extent necessary, we may use certain third party processors to process some or all of your personal information. For identification of these processors, and where they are located, please contact us at email@example.com. We have signed appropriate data processing contracts that comply with GDPR and/or PIPEDA with each processor.
Vireo won’t hand your data over to law enforcement unless a court order says we have to. We flat-out reject requests from local and federal law enforcement when they seek data without a court order. And unless we're legally prevented from it, we’ll always inform you when such requests are made.
Security & Encryption
All data is encrypted via SSL/TLS when transmitted from our servers to your browser. The database backups are also encrypted. Data isn’t encrypted while it's live in our database because it needs to be ready to send to you when you need it.
In order to improve our services and the website, and provide more convenient, relevant experiences to you, we and our vendors may use "cookies", "web beacons", and similar devices to track your activities.
Location of Site and Data
This Site is operated in Canada. If you are located in the European Union, United States or elsewhere, please be aware that any information you provide to us will be transferred to Canada. By using our Site, participating in any of our services and/or providing us with your information, you consent to this transfer.
Changes & questions
Vireo may update this policy once in a blue moon — we’ll notify you about significant changes by placing a prominent notice on our site. You can access, change or delete your personal information at any time by contacting our support team.