BACKPLAIN INC.

PRIVACY POLICY

Effective Date: May 31, 2023

Overview and Scope


We at Backplain Inc. (the “Company,” “Backplain,” “we,” “our,” or “us”) recognize the importance of protecting the privacy of personally identifiable information (“Personal Information” or “PII”) collected about you and other users (collectively, “Users”) through our website, www.backplain.com (the “Site”), and all related websites, applications, software, and services provided by us (collectively, with the Site, the “Service”). We are committed to ensuring that your privacy is protected. To that end, this Privacy Policy (“Policy”) discloses our practices regarding the collection, use, and disclosure of the PII we receive in connection with providing the Service. Unless otherwise expressly agreed to in writing, your PII will be processed according to the terms of this Policy. By using the Service, you accept the terms of this Policy.


Protecting the privacy of information is at the core of Backplain’s purpose. We work to help you protect information from falling into the wrong hands, so it’s only right that protecting the information we collect from you be our top priority. We only collect PII that you provide to us, and we only use that PII to provide the Service to you, with the few exceptions described below. We do not sell your PII, nor do we share your PII with third parties except as is necessary to provide you the Service. You and other Users of the Service are under no obligation to provide PII to us but, to the extent that you do, we are committed to respecting your privacy rights and using that PII to best serve you.


This Policy applies to the Service, regardless of the medium by which the Service is accessed by Users (e.g., via a web or mobile browser).


Information We Collect


To provide you with the Service, we need to collect some of your information. We are the sole owner of information that you voluntarily provide to us through the Service. We collect several types of information from and about Users of the Service, including:


Personal Information: We may collect PII from you when you register for an account with us, subscribe to receive services, request information, complete forms, or navigate web pages, and in connection with other activities, services, features, or resources we make available through the Service. PII means any information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. PII does not include publicly available information from government records, deidentified or aggregate information, or information excluded from the scope of certain data privacy laws. We do not collect Sensitive PII about you.


In particular, we have collected, used, and stored the following categories of information in the last twelve (12) months:

Category

Type(s) of Information

Identifiers

First Name, Last Name, Company or Affiliation, Email, Phone Number, Postal Address, IP Address

Financial Information

Credit/Debit Card Number, Expiration Date, Security Code

Categories of PII Listed in the CA Consumer Customer Records Law

First Name, Last Name, Address, Phone Number


Information within this category may overlap with other categories.

Commercial Information

Records of products or services purchased or obtained from us

Professional or Employment-Related Information

For job applicants, current or past job history or performance evaluations

Internet or Other Similar Network Activities

Information on your interactions with our Site or Service

Geolocation Data

Geolocation, beacon based location, GPS location


You may disable our use of certain identifiers and activities through your device or browser settings.

Deidentified Information: We may collect deidentified information from you and aggregate information that may not by itself reasonably identify you as the source that is sent to us automatically by your web browser or device when you use the Service (“Deidentified Information”). Deidentified Information may include: (i) device type, (ii) device operating system, (iii) internet browser type, (iv) internet service provider, (v) referring/exit pages, (vi) date/time stamp, and (vii) clickstream information. We will take reasonable measures to ensure that Deidentified Information we collect is not personally identifiable and may not later be easily used to identify you as required by applicable law.


Children’s Information: We do not offer the Service to, nor do we intentionally collect or retain PII from, children who are younger than 18 years of age. If we are notified that we have inadvertently collected information from a child under 18 years of age, we will promptly take all reasonable measures to delete such information from our systems.


How We Collect Information


The information we collect depends on what you do when you utilize the Service. We collect PII and Deidentified Information in various ways, including:


Directly from You: We collect PII when you voluntarily submit it to us in connection with the activities, services, features, or resources we make available in connection with the Service. The PII we collect depends on how you utilize the Service and how you choose to communicate with us.


Through Your Use of the Service: We may collect PII and Deidentified Information that your browser automatically transmits when you utilize the Service. We may also collect Deidentified Information about how you access and interact with the Service through the use of various automated tracking technologies, such as session cookies, persistent cookies, and web beacons.


A cookie is a small data file that is transferred to an internet browser, which enables the Service to remember and customize your subsequent visits. We may use session cookies to make it easier for you to navigate the Service. Session cookies expire when you close your browser. We may also use persistent cookies to enhance and personalize your experience with the Service. Persistent cookies remain on your device for an extended period of time. Additionally, we may use web beacons, which are single-pixel, electronic images embedded in the Service that allow us to track the efficiency and effectiveness of our Service and our communications.


Most internet browsers automatically accept cookies. However, you can instruct your internet browser to block cookies or to provide you with a warning prompt before you accept cookies through the Service. Please refer to your internet browser’s instructions to learn more about these functions. If you reject cookies, the functionality of the Service may be limited and you may not be able to participate in several of the Service’s features.


From Service Providers and Other Parties: We may collect PII about you from service providers and other third parties that provide us with information needed to provide core aspects of our Service, such as background check providers, insurance partners, financial service providers, and other businesses that support our ability to provide you the Service and otherwise enhance your experience. The privacy practices of these parties may differ from the practices described in this Policy. We do not make any representations or warranties concerning, and will not in any way be liable for, any informational content, products, services, software, or other materials available through third parties, your use of which is governed by the terms and conditions of those parties. We encourage you to carefully review the privacy policies and statements of such third parties and/or third party websites.


How We Use Information


When we use your information, we do so to best serve you. We may use your PII for our business purposes in providing and improving the Service, including:


Delivery of the Service: We use your PII to provide you with an efficient, intuitive, useful, and valueadded experience with the Service, and to provide you with the support and services that you have trusted us to provide.


Marketing Communications: We may use your PII to send you promotional materials about us and our services that we think may be of interest to you. You have the right to opt-out of receiving direct marketing at any time.


Customer Service and User Communications: We may use your PII to help us respond to your inquiries, questions, requests, and support needs more efficiently.


User Experience Personalization: We may use your PII and/or Deidentified Information in the aggregate to analyze Users’ browsing and usage activities and patterns in order to understand our Users’ interests and preferences with respect to our Service. This will help us optimize your experience with the Service.


Business Optimization: We may use your PII to improve the Service’s content, to customize the layout of the Service, and to otherwise manage our everyday business needs. We may also use your feedback to improve our Service. All of this is done with the intention of making the Service more useful, secure, and efficient for you.


Safety and Security: We may use your PII to promote the safety and security of the Service, our Users, and other parties. For example, we may use PII to authenticate users, facilitate secure payments, protect against fraud and abuse, respond to a legal request or claim, conduct audits, and enforce our terms and policies.


Trust and transparency are at the core of our values, and we pride ourselves on assuring that there are no surprises when it comes to our use of your PII. We will not collect additional categories of PII or use the PII we have collected for materially different, unrelated, or incompatible purposes without providing you notice.


Third-Party Use of Cookies


Some content or applications, including advertisements, available through the Service are served by third-parties that we may partner with to provide you, at your option, with additional information, resources, or services ancillary to our Service. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use the Service. The information they collect may be associated with your PII or they may collect information, including PII, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.


We do not control these third parties' tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.


How We Disclose Information


We care about your privacy, and are not in the business of selling or sharing your information for the benefit of third parties. To provide you with the Service, though, we may need to disclose your PII to third parties solely for the business purposes described below. Otherwise, we do not sell, rent, lease, or “share” PII, as that term is defined in certain data privacy laws, and will not disclose your PII to third parties without your permission.


To Our Affiliates: We may share your PII with our affiliates, including companies within the Backplain Inc. and Epik Systems Inc. groups. We will be responsible for the overall management and use of your PII by these affiliated entities.


To Our Business Partners: From time to time, we may partner with other trusted companies to offer content, products or services that are intended to enhance, amplify, and otherwise positively supplement your use of the Service. If you specifically express interest in engaging with the content, products, or services offered through one or more of our trusted business partners, we may share your PII with that business partner after we have notified you of the PII to be shared, and obtained your consent to the share that PII. We do not control our business partners’ use of your PII, and their use of such information will be in accordance with their own privacy policies.


To Contractors and Service Providers: We may share your PII with our contractors and service providers that assist us in providing user support, communicating with Users, and promoting our services, as well as third party contractors and service providers that provide other services to us relating to our Service. These parties help us with things like payment processing, data analysis, information technology and related infrastructure, customer service, professional or audit services or email delivery, among others. We contractually require these third parties to keep your PII confidential and use it only for the purposes for which we disclose it to them.


Law Enforcement, Safety, and Legal Processes: We may share your PII with law enforcement or other government officials if it relates to a criminal investigation or alleged criminal activity. We may also disclose your PII: (i) if required or permitted to do so by law; (ii) for fraud protection and credit risk reduction purposes; (iii) in the good-faith belief that such action is necessary to protect our rights, interests, or property; (iv) in the good-faith belief that such action is necessary to protect your safety or the safety of others; or (v) to comply with a judicial proceeding, court order, subpoena, or other similar legal or administrative process.


Sale or Acquisition of Assets: If we become involved in a transaction involving the sale of our assets, such as a merger or acquisition, or if we are transferred to another company, we may disclose and/or transfer your PII as part of the transaction. If the surviving entity in that transaction is not us, the surviving company may use your PII pursuant to its own privacy policies, and those policies may be different from this Policy.


Upon Your Further Direction: We may otherwise share your PII with your explicit permission or upon your direction.


Type of Information Disclosed


In the last twelve (12) months, we may have disclosed the following categories of PII to third parties for one or more of the lawful business purposes detailed above:

Identifiers

Category of Third-Party Recipients

Identifiers

Affiliates, Business Partners, Service Providers/Contractors

Financial Information

Affiliates, Service Providers/Contractors

Categories of PII Listed in the CA Consumer Customer Records Law

Affiliates, Business Partners, Service Providers/Contractors

Commercial Information

Affiliates, Business Partners, Service Providers/Contractors

Professional or Employment-Related Information

Affiliates, Service Providers/Contractors

Internet or Other Similar Network Activities

Affiliates, Service Providers/Contractors

Security


The security and confidentiality of your PII is very important to us. We use a variety of industry-standard security technologies and procedures to protect your information from loss, misuse and unauthorized access or disclosure. However, no data transmitted over or accessible through the internet can be guaranteed to be 100% secure. As a result, while we implement safeguards and take steps to protect your PII, we cannot guarantee or warrant that your PII will be completely secure (i) from misappropriation by hackers or from other nefarious or criminal activities, or (ii) in the event of a failure of computer hardware, software, or a telecommunications networks.


Data Retention


We will keep your PII for as long as required to perform the purposes for which the PII was collected or so long as we have a business purpose to do so and, thereafter, for no longer than is required or permitted by law. We will delete PII within a reasonable time after the data is no longer necessary for the business purpose for which it was collected. We will, however, retain and use PII as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.


Legal Rights


CCPA California Resident Rights


If you are a California resident, the CCPA grants you certain data privacy rights. Your rights include the:


  • Right to Access: You have the right to request a copy of the specific pieces of PII that we have collected about you in the previous twelve (12) months. The information will be delivered by mail or electronically. Upon receipt of a Verifiable Consumer Request, we will disclose:

    • The categories of PII we have collected about you;

    • The categories of sources from which PII is collected;

    • Our business purpose for collecting PII;

    • The categories of third parties with whom we share PII, if any; and

    • The specific pieces of PII we have collected about you.

  • Right to Data Portability: You have the right to receive your PII in a portable, readily usable format that allows you to transmit your information to another entity without hindrance.

  • Right to Correct Inaccurate Information: You have the right to request that we correct inaccurate information about you that we maintain.

  • Right to Deletion: You have the right request that we delete your PII.

  • Right to Be Free from Discrimination: You have the right to not be discriminated against by us for exercising any of your rights under the CCPA. Unless permitted by the CCPA, we will not:

    • Deny goods or services to you;

    • Charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;

    • Provide a different level or quality of goods or services to you; or

    • Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.


To exercise your rights, please use the Verifiable Consumer Request method described below. Please be aware that your rights (including those enumerated elsewhere in this Policy) are limited to the extent permitted by applicable law.


Additional California Privacy Rights


California’s “Shine the Light” law permits Users of the Service that are California residents to request certain information regarding our disclosure of PII to third parties for their direct marketing purposes. To make such a request, please contact us at the Contact Information provided below.


Verifiable Consumer Requests


You can exercise your legal rights by submitting a Verifiable Consumer Request to us by:



Only you, or someone legally authorized to act on your behalf, may make a Verifiable Consumer Request related to your PII.


Making a Verifiable Consumer Request does not require you to create an account with us. You may only make a Verifiable Consumer Request for access to PII twice in a 12-month period.


The Verifiable Consumer Request must:


  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative; and

  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.


We cannot respond to your request or provide you with PII if we cannot verify your identity or authority to make the request and confirm the PII relates to you. We will only use PII provided in a Verifiable Consumer Request to verify the requestor’s identity or authority to make the request.


Response Timing and Format


We will acknowledge receipt of a Verifiable Consumer Request within ten (10) days. We endeavor to respond to Verifiable Consumer Requests within thirty (30) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing. Any disclosures we provide will only cover the 12-month period preceding the Verifiable Consumer Request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.


We do not charge a fee to process or respond to Verifiable Consumer Requests, unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.


Withdraw Consent


Generally, we do not process PII based on consent. However, in the event we do, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on said consent before its withdrawal. If you would like to withdraw your consent, please contact us at the Contact Information provided below.


Do Not Track Disclosure


Some internet browsers may transmit “do-not-track” signals to websites with which the browser communicates. The Site available as part of the Service does not currently respond to these “do-nottrack” signals.


SPAM


We do not participate in bulk email solicitations that you have not consented to receiving (i.e., “Spam”). We do not sell or disclose customer lists or email address lists to unrelated third parties. Except as otherwise provided herein, we do not share PII with any third party advertisers.


Third Party Links


The Service may contain links to other content, websites or applications (“Linked Sites”) that are not owned or provided by Backplain. We do not control the collection or use of any information, including PII, which occurs while you visit Linked Sites. Therefore, we make no representations or warranties for —and will not in any way be liable for—any content, products, services, software, or other materials available on Linked Sites, even if one or more pages of the Linked Site are framed within a section of the Service.


Furthermore, we make no representations or warranties about the privacy policies or practices of the Linked Sites, and we are not responsible for the privacy practices of those Linked Sites. We encourage you to read the privacy policies of Linked Sites.


Modifications


We reserve the right to update this Policy from time-to-time in our sole discretion. If our privacy practices change materially in the future, we will post an updated version of the privacy policy through the Service. It is your responsibility to review this Policy for any changes each time you use the Service. We will not lessen your rights under this Policy without your explicit consent. If you do not agree with the changes made, we will honor any opt-out requests made after the Effective Date of a new privacy policy.


Your Privacy Choices


Personal Information: If you ever wish to access, update, change, delete, opt-out of us sharing, control your PII, or cancel your account you may do so by contacting us at the Contact Information provided below. To help us process your request, please provide sufficient information to allow us to identify you in our records. We reserve the right to ask for additional information verifying your identity prior to disclosing any PII to you. Should we ask for verification, the information you provide will be used only for verification purposes, and all copies of the information will be destroyed when the process is complete.


Promotional Communications: If you wish to opt-out of receiving update messages and/or direct marketing communications from us, you may opt-out by (i) following any instructions included in the communication or (ii) contacting us at the Contact Information provided below. Please be aware that although you may opt-out of update messages and/or direct marketing communications, we reserve the right to email you administrative notices regarding the Service, as permitted under the CAN-SPAM Act.


Cookies and Tracking: Most web browsers are set to accept cookies by default. If you prefer, you can choose to set your browser to remove or reject browser cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our Service.


We will make commercially reasonable efforts to respond to opt-out requests and handle requests to access, update, change, or delete PII without unreasonable delay and in any event within one month of receipt of a Users’ request. Please be aware that requests may be limited to the extent permitted by applicable law.


Contact Information


If you have questions about this Policy or wish to contact us with questions or comments, please contact us at:


Attn: Compliance Team

BACKPLAIN INC.

5939 DARWIN CT. STE 103

CARLSBAD, CA 92008

+1-760-279-3939

COMPLIANCE@BACKPLAIN.COM


Effective Date


This Policy was last modified as of the effective date printed above. This version of the privacy policy replaces and supersedes any prior privacy policies applicable to our Service.

© Copyright 2023 Backplain Inc.