LEGAL STUFF

Privacy Policy

If your organization signed a GoReact Customer Terms Agreement with GoReact, that Agreement governs any conflict with the Privacy Policy below. Please contact legal@goreact.com with any questions.

 

Welcome to GoReact! Safekeeping of your data is critical to us and a responsibility that we embrace. This Privacy Policy is published by SpeakWorks, Inc. dba GoReact, 256 W. Center St, Orem UT USA (“GoReact”, “we” or “us”). We are represented in the EU by Scandinavian Trust AB, Birger Jarlsgatan 12, SE-114 34 Stockholm, Sweden, and in the UK by Jenny Gordon, Salmons Farm, Hawkspur Green, Little Bardfield, Braintree, Essex, CM7 4SH, UK.  Here we describe how we collect, use and handle your information when you use our websites, mobile applications, software and/or services (“Service”).

WHAT INFORMATION WE COLLECT

We collect and use the following information to provide, improve and protect our Service:

Account Information. We collect, and associate with your account, information such as your name, email address, phone number, address, and payment information. We collect and process this information so that we can perform our contract with you and where the processing is necessary for our legitimate interests of maintaining our relationship with you and promoting and managing our business.

Your Content. When you use our Service, we store, process and transmit your files (including items like your videos, recordings, files, comments, other content, and so on) (“Your Content”) and information related to them. This will make it easy for you to do things like share and interact with these items. We collect and process this information so that we can perform our contract with you.

Usage Information. In order to improve the Service, we collect information from and about the devices you use to access the Service. This includes things like IP addresses, the type of browser and device you use, the web page you visited before coming to our sites, how you interact with the Service, and identifiers associated with your account and your devices. Your devices (depending on their settings) may also transmit location information to the Service.

Cookies and other technologies. We use technologies like cookies and pixel tags to provide, improve, protect and promote our Service. For example, cookies and other technologies help us with things like remembering your username and preferences for your next visit, understanding how you interact with our Service including things like clicks, mouse actions, text entered, the web page you visited before coming to our sites, and other related information, and then improving the Service based on that information. You can set your browser to not accept cookies, but this will limit your ability to use the Service. We obtain your consent for use of cookies.

Video information.  You may sometimes use the Service in connection with your participation in an activity in which your image, words, or actions are recorded by the Service. You may or may not be logged in to the Service at the time, and you consent to the use of your image, words, and actions (solely in connection with the Service), regardless of whether or not you are logged in at the time your image, words, or actions are recorded. We obtain your consent for use of this data.

SHARING OF INFORMATION

On a limited basis, we may share information as described below in order to facilitate delivering the Service to you, but will never sell it to advertisers or other third parties.

Others working on behalf of GoReact. GoReact uses only certain trusted third party partners to help us provide, improve, protect, and promote our Service. These third parties will access your information, but only to perform tasks on our behalf and in compliance with this Privacy Policy. For each such third party, GoReact secures contractual data governance to ensure your data has protections and privacy in their systems consistent with this Privacy Policy and is only used for processing our direct service requests. A current list of each data subprocessor we contract with, and their function, may be found at www.goreact.com/subprocessors, and you will be notified (for example, by email) when any new subprocessor is added.

Other users. Our Service displays information like your name or email address to other users only in places where that information is configured to be shared. In the United States, the disclosure of information from student records, particularly grades and performance information, is governed by the Family Educational Rights and Privacy Act (“FERPA”), and such information is shared only with your course instructor(s) or other institutional administrators as permitted by FERPA.

Organizational Administrators. If your account is associated with a GoReact Organizational Account (as defined in the User Terms), there may be an administrator in your organization that has access to and control of your GoReact account for purposes of managing the Service. Please refer to your organization’s internal policies if you have questions about this.

Legal. We may disclose your information to third parties if we determine that such disclosure is reasonably necessary to (a) comply with the law; (b) protect any person from death or serious bodily injury; (c) prevent fraud or abuse of GoReact or our users; or (d) protect GoReact’s property rights. In the case of data subjects based in the EEA or the UK, we may otherwise disclose information to third parties only if such is necessary for compliance with a legal obligation or necessary in order to protect vital interests. Please contact legal@goreact.com with any privacy questions or concerns.

HOW WE USE AND SECURE YOUR INFORMATION

Security. We employ both an internal technical team and external security experts in order to keep your information secure and test for vulnerabilities. All database data managed by GoReact is encrypted both at rest and in transmission. We also continue to work on features to keep your information safe.

Retention and right to deletion. We’ll retain information you store on our Service for as long as we need it to provide you the Service. In most cases, that means information will be kept for at least three (3) years, which most users find helpful in order to retrieve past samples of their work. If you request to delete your account, you may also request that we delete your information, and/or you may also request a copy of your data we have stored in our system. Please note: (a) there might be some latency in deleting this information from our servers and backup storage; (b) feedback you’ve provided for others will remain, and (c) we may retain certain information if necessary to comply with our legal obligations, resolve disputes, or enforce our agreements.

WHERE INFORMATION IS STORED

United States and non-EU/UK Provisions. To provide you with the Service, we may store, process and transmit information in the United States and locations around the world — including those outside your country. Information may also be stored locally on the devices you use to access the Service. If you are a U.S. customer, your data will only be stored and processed in the United States.

EU and UK Provisions. If you are accessing your account via goreact.eu, your personal data is stored and processed on our servers based in the European Union.  GoReact observes the obligations of the EU GDPR and the UK GDPR and ensures that data is transferred subject to one of the following safeguards:

  • we will only transfer data to countries that have been deemed to provide an adequate level of protection by the relevant supervisory authority;
  • where our service providers are located outside of the EEA or UK, we will use specific contracts approved by the relevant supervisory authority for the transfer;
  • where our client services representatives who assist you are located outside of the EEA or UK, we will either seek your consent to allow the service personnel to access your data or we will allow such access on the basis that the transfer is necessary for the performance of the contract with you or we will use specific contracts approved by the relevant supervisory authority for the transfer.

 

INFORMATION RELATED TO CCPA

The California Consumer Privacy Act of 2018 (“CCPA”) relates to residents of California and requires that we make certain disclosures to you and provide you with a means to exercise the other rights residents of California have received under the CCPA.  This section makes those disclosures (in part by pointing you to the locations in this Privacy Policy where the disclosures are made) and describes how you may exercise your rights under the CCPA.

Categories of Information (Source, Collection, and Sharing).  The CCPA requires us to list the categories of information we collect about you and the commercial or business purposes for which the categories of personal information is used.  Those disclosures are made in the “What Information We Collect” section above under the categories “Account Information,” “Your Content,” and “Usage Information.” The categories of information collected and the purposes for that collection have not changed over the last twelve months.

The source of the information we receive about you is always you or the parties with whom you interact using our Service.  We do not purchase any personal information about you from third parties.

Your information is only shared in accordance with the “Sharing of Information” section above.  The commercial and business purposes for that sharing is also described in that section.  The categories of information shared and the categories of parties with whom it is shared have not changed in the last twelve months.

Your Rights under the CCPA.  If you are a California resident, you have the following rights:

  • You have the right to request that we disclose the categories and the specific items of personal information about you that we collect, use, disclose, and/or sell and that personal information about you that we have collected, used, disclosed, and/or sold during the twelve months prior to your request.
  • You have the right to not be subjected to any discrimination based on the fact that you have elected to opt out of the sale of your personal information or that you have submitted a request to know or a request to delete under the CCPA.
  • You also have the right to have the personal information we collect about you deleted.  We use a two-step process to verify your identity and to have the information deleted. Your rights to have your personal information deleted are subject to several exceptions, specifically the personal information that is necessary for us to:
    • complete your transaction;
    • provide you a good or service;
    • perform a contract between us and you;
    • protect your security and prosecute those responsible for breaching it;
    • fix our system in the case of a bug;
    • protect the free speech rights of you or other users;
    • comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.);
    • engage in public or peer-reviewed scientific, historical, or statistical research in the public interests that adheres to all other applicable ethics and privacy laws;
    • comply with a legal obligation; or
    • make other internal and lawful uses of the information that are compatible with the context in which you provided it.
  • To make any request under the CCPA, you must complete the online Data Request Form found at help.goreact.com/hc/en-us/requests/new.  Typically, your login and password are sufficient to verify your identity, but if we require further information, we will inform you.  In that event, you will be asked to give us your name, e-mail address, and any other information we reasonably require to verify your identity.  
  • We will respond to your request within 10 days after receipt of your request, and we will then take action to verify your identity and fulfill your request, as required by the CCPA.  We will provide you with a CSV copy of your stored data within 45 days of your request, assuming we are able to verify your identity in that period and so long as you provide a correct email address for successful correspondence.

For more information about your rights under the CCPA, please direct your questions to us at legal@goreact.com. You can also direct questions to our toll free number at 1-855-717-3499.

INFORMATION RELATED TO GDPR

The EU GDPR and UK GDPR give you certain rights in relation to your personal data.  If you are an or UK citizen, you have the right to:

  • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
  • Right to object to automated individual decision-making, including profiling. This will apply where perform automatic checks when determining whether to provide you with products or services. You have a right to object to such automated processing, and in that case we may either process your application manually or decline to proceed with your application on the basis that such processing would be required for the performance of a contract to provide you with our services.

No fee usually required.

You may also have the right to make a complaint to the relevant Supervisory Authority. A list of Supervisory Authorities is available here:  edpb.europa.eu/about-edpb/board/members_en or, in the case of the UK, it is the Information Commissioners Office https://ico.org.uk/global/contact-us/.

DE-IDENTIFIED INFORMATION

GoReact collects and uses certain indirect or aggregate information as a result of your use of the Service.  Such information will always be anonymized and will never contain user-identifiable data such as name, email address, or other direct identifiers. Any such de-identification will comply with U.S. FERPA and HIPAA requirements as well as GDPR and the CCPA.

HOW YOU CONTROL YOUR INFORMATION

Upon creation of your account in the Service, you will be expressly asked for your consent to how we will store and use your information. We will track that consent, and you will have the ability to withdraw your consent and delete your account at any time from within your user profile in the Service. In addition, while you use the Service, you’ll be able to see on any given activity who will have access to your content, and you may also change and update your information in your user profile.

If you are a parent of a child under the age of 13 whose information is captured in the Service, you may review and/or request deletion of your child’s data at any time by contacting us at legal@goreact.com.

ONWARD TRANSFERS OF YOUR INFORMATION

If we are involved in a reorganization, merger, acquisition or sale of our assets, your information may be transferred as part of that transaction. We will notify you (for example, via a message to the email address associated with your account) of any such transaction and outline your choices in that event.

CHANGES TO THIS PRIVACY POLICY

We may revise this Privacy Policy from time to time, and will post the most current version on our website. If a revision meaningfully reduces your rights, we will notify you through your account and provide an opportunity to consent to the changes.

CONTACT INFORMATION

Have questions or concerns about GoReact, our Service and/or privacy? Contact us at legal@goreact.com.

Effective: 10 August 2021