Skan Platform Privacy Notice

Last updated : September 20, 2023
 
seal

 

This platform privacy notice of Skan Inc ("Company,"we", "us", or "our"), describes when,how, and why we may collect, store, use, and/or share ("process") your personal information when you use Skan Process Intelligence Platform's UI Portal ("Services"), specifically set up for every customer.

Skan respects and values your privacy. This privacy notice will help you understand your privacy rights and how we protect your personal information. You as a process owner or participant shall contact your organization about the purpose of collection, basis, risks to privacy, and means of exercising your privacy rights.
 

About Skan Process Intelligence Platform's UI Portal

The UI Portal is a front-end web interface accessible from the Internet securely over TLS 1.2 or later protocols. Each Portal is set up exclusively for every customer as part of Skan’s business process discovery services provided to them. The Portal allows customer’s process owners, who are pre-identified and authorized by the customer, to authenticate themselves so that they can log in to the Portal to configure how process discovery should be carried out. The Portal also allows the process owners to configure a host of other security and privacy-related configurations.

Understanding the purpose of the Portal and its use is essential to understanding the premise of this privacy notice. 

Table Of Contents

  1. What information do we collect?
  2. How do we process your information?
  3. When and with whom do we share your personal information?
  4. Do we use cookies and other tracking technologies?
  5. Do we handle your social logins?
  6. Is your information transferred internationally?
  7. How long do we keep your information?
  8. Do we collect information from minors?
  9. How do we protect personal information processed through our platform?
  10. What are your privacy rights?
  11. How can you review, update, or delete the data we collect from you?
  12. Controls for do-not-track features
  13. Do california residents have specific privacy rights?
  14. Dispute resolution
  15. Do we make updates to this notice?
  16. How can you contact us about this notice?

1. What information do we collect?

Personal information we collect
In Short:

We collect personal information as part of business process discovery.

  • Process Owners: We collect personal information such as first & last name and email ID of process owners to provide them with access to the UI portal specifically created for the customer. 
  • Participants: We collect Windows user name and host names for participants when the Virtual Assistant software agent is installed on systems, and used by participants. This Participant PII can be anonymized with privacy and security configurations.
  • Customer's end customers or consumers: When customer's business processes to be discovered would have personal or sensitive personal information about their end customers or consumers, we can collect end customer's personal and/or sensitive personal information. 
  • Sensitive Information: We do not collect or process sensitive information that belongs to process owners and participants. We may incidentally collect some sensitive personal information of customers, their end customers, or consumers if present in the business process and selected for discovery by customers.

    We do not process personal information collected to produce any particular outcome or results that we would be interested in outside the terms of the subscription agreement governing business process discovery.
Information automatically collected
In Short:

Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our UI Portal.

We automatically collect certain information when process owners access their UI portal. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, device name information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of the UI Portal.

2. How do we process your information?

In Short:

We process your information to provide access to UI Portal so that process owners can configure their business processes, include process applications for data collection, configure security and privacy controls, and access reports.

Through the Platform, we process personal, including the sensitive personal information of our customer's clients to provide B2B service and fulfill our contractual obligations with our customers to help with digital process discovery and analytical services and provide necessary actionable intelligence to respective customers for the duration of the contract/subscription agreement. Skan's primary business purpose is to fulfill contractual obligations agreed upon with the customer to help with digital process discovery of customer business processes and analytical services for the duration of the contract. So, the data collection is to provide the B2B service to the customer. The Platform is designed to capture digital processes and extract actionable intelligence that the customer is looking for, for digital transformation. Skan does not have any other secondary purposes for processing.

Customers use Skan's Platform to discover how their business processes are being executed as their staff (aka Participants) execute them through agent software, which sends discovered data to an intermediate server, which many on Customer's network or Skan's Cloud. The intermediate server aka gateway performs several tasks including security and privacy tasks such as anonymizing customer-selected data fields and region/image masking. Gateway extracts metadata from anonymized data sets and transfers only metadata to Skan Cloud. To secure the data throughout the chain from the agent to the Skan Cloud, Skan employs multiple methods such as user access control agent whitelisting for the data collection, encrypted communications, user and entity identification, access controls, data at rest encryption within Skan Cloud, processing only anonymized metadata in the Cloud.

We do not process personal and sensitive personal information for any other purposes. Personal information that gets collected about participants and process owners of customers and customer's B2C or B2B customers if any, is not processed for any personal information-based outcome or results.

3. When and with whom do we share your personal information?

In Short:

We do not share personal information.

We may need to share your personal information in the following situations:

  • Business Transfers: We may share or transfer your information in connection with or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our subsidiaries, joint venture partners, or other companies that we control or that are under common control with uAs.
  • Business Partners: We may share your information with our business partners to offer you enhanced capabilities and feature sets as part of Skan Process Intelligence Platform Services.
  • Service Providers: Skan Platform integrates with certain Cloud Service Providers. For more information about these providers, the purpose of using their services, and details of data shared with them, you may write us at support@skan.ai.
  • Legal Compliance: In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also disclose your personal information as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

4. Do we use cookies and other tracking technologies?

In Short:

We use essential & performance cookies only.

We do not use cookies and tracking technologies (like web beacons and pixels) on the UI Portal to collect and store your information for marketing and analytical purposes.

5. Do we handle your social logins?

In Short:

No.

We do not currently offer social media-based logins.

6. Is your information transferred internationally?

In Short:

We may transfer, store, and process your information in countries other than your own.

Every Cloud environment that we set up for our customers is dedicated and not shared with any other customers. All the virtual resources are usually located in the customer's geography or the United States. When customers access their specific UI Portal, please be aware that your information may be transferred to, accessed, stored, and processed by our subsidiaries and by those third parties with whom we may share your personal information (see "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above), located in other countries.

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), then these other countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures such as EU’s Standard Contractual Clauses enforced through a Data Protection Agreement along with appropriate technical and organizational safeguards to protect your personal information by this privacy notice and applicable laws. 

7. How long do we keep your information?

In Short:

 We keep your information for as long as necessary to fulfill the contractual obligations agreed upon. 

We will only keep your personal information along with business process information collected for as long as it is necessary for the purposes set out in this privacy notice and as per the respective contractual agreement with the customer. No purpose in this notice will require us to keep your personal information for longer than the contractual terms.

8. Do we collect information from minors?

In Short:

Maybe.

Our Services are designed and delivered only for enterprise customers for business process discovery. The process to be discovered, process owners to be provided access to the UI Portal, and participants whose process execution activities would be captured are all determined by the customer. It may be possible that the business processes our customers choose to study about using our product may contain personal information related to minors. However, Skan does not directly intend to or have a specific purpose for collecting and processing personal information about minors. Any information about minors collected as part of business process discovery is protected and processed in the same manner as described elsewhere in this notice. Skan also provides privacy controls to customers so that they can identify sensitive data fields that can be anonymized irreversibly.

9. How do we protect personal information processed through our platform?

We take appropriate security measures to protect personal information against loss, misuse, and unauthorized access, alteration, disclosure, or destruction. We also have implemented measures to maintain the ongoing confidentiality, integrity, and availability of the systems and services that process personal information and will restore the availability and access to data promptly in the event of a physical or technical incident."

10. What are your privacy rights?

In Short:

 Skan is committed to cooperating with customers wherever and whenever necessary. 

Skan may incidentally collect and process personal information as part of business process discovery. The legal basis for the collection is contractual obligations through the enterprise agreement signed with every customer.

Should you wish to exercise your privacy rights, you shall approach your employer, who is our enterprise customer with whom we have a legal contract/subscription agreement to perform process discovery and analytics Services through the Skan Platform.

Other than the performance of contractual obligations, Skan has no other purpose to process either business process information or the personal information collected as part of process discovery.

Account Information

Skan does not collect, process, and store personal information outside of business process discovery. Personal information collected remains embedded within the business process information based on prior security and privacy controls such as masking and anonymization configured by process owners and labels or fields selected for discovery.

If process owners wish to make any changes to account information or security controls, they can contact support@skan.ai through their customer success team representative.

The personal information of participants or end customers is not stored in any structured fashion on Skan Cloud as part of the meta-data processed. However, participants may write to support@skan.ai through the customer success team representative.

11. How can you review, update, or delete the data we collect from you?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances.

Should you wish to exercise your privacy rights, you should approach your employer, who is our enterprise customer with whom we have a legal contract to perform process discovery and analytics Services through the Skan Platform.

12. Controls for do-not-track features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. No uniform technology standard for recognizing and implementing DNT signals has been finalized at this stage. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.

13. Do california residents have specific privacy rights?

In Short:

Not applicable.

Skan Platform's UI Portal is only accessible and used by process owners, who work for enterprise customers, with whom we have signed an enterprise agreement to provide the Services for the performance of the contract.

UI Portal does not collect and cannot be used to collect personal information of any other data subject.

14. Dispute resolution

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request

15. Do we make updates to this notice?

In Short:

 Yes, we will update this notice as necessary to stay compliant with relevant laws. 

We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

16. How can you contact us about this notice?

If you have questions or comments about this notice, you may email us at support@skan.ai and reach us at 101, Jefferson Dr. Menlo Park CA 94025, and call us at +1 650-502-0006

 
TRUSTe