MetaComet Systems, Inc. — Privacy Policy
This Privacy Policy (“Policy”) explains how your information is collected, used and disclosed by MetaComet Systems, Inc. (“MetaComet Systems”, “We”, “Us”, or “Our”) with respect to the www.metacomet.com and www.royaltytracker.com sites, their subdomains, and various related services (together referred to as the “Services”). This Policy applies when you visit the Services, including where we are acting as a Data Controller with respect to the personal data of Our website visitors and service users; in other words, where we determine the purposes and means of the processing of that personal data. If you are an employee, customer or other user of one of Our business customers (“End User”), we process your personal data on behalf of the business customer. Our processing of End Users’ personal data is also governed by Our agreement with that business customer.
We are committed to safeguarding the privacy of Our website visitors and users of Our Services. We will never sell, share, or use your personal data other than as described here.
By using Our Services and agreeing to this Policy, you consent to Our use of cookies in accordance with the terms of this Policy. If you do not agree to this Policy, you may not use the Services.
About This Policy
This Policy sets out how we will use and share the information that you give us or that we collect about you. This Policy describes your relationship with MetaComet Systems.
The General Data Protection Regulation (“GDPR”) describes how organizations must collect, handle, process, and store personal data. Personal data (under some laws, personal information), means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.
These rules apply regardless of whether data is stored electronically, on paper or on other materials. To comply with the law, personal data must be collected and used fairly, stored safely and not disclosed unlawfully. GDPR is underpinned by important principles. These say that personal data must:
- Be processed fairly and lawfully
- Be obtained only for specific, lawful purposes
- Be adequate, relevant and not excessive
- Be accurate and kept up to date
- Not be held for any longer than is necessary
- Processed in accordance with the rights of the data subjects
- Be protected in appropriate ways
- Not be transferred outside the UK, unless that country or territory also ensures an adequate level of protection
We take these responsibilities seriously; this document describes Our approach to data protection. This Policy helps to protect us from data security risks, including:
- Breaches of confidentiality. For instance, information being given out inappropriately.
- Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
- Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.
Who We Are And How To Contact Us
We are registered and do business in the United States of America. The Data Protection Lead is MJ Hyndman-Benander. You can contact us in any of the following ways:
Email: [email protected]
Phone: +1 413 536 5989
Address: 47 Pleasant St, Suite 1-SW, Northampton, MA 01060
OUR ARTICLE 27 REPRESENTATIVE
We have appointed EU and UK Representatives under Article 27 of the EU GDPR and UK GDPR respectively. Our appointed representatives are:
Our UK Representative:
Under Article 27 of the UK Data Privacy Act, we have appointed a UK Representative to act as Our data protection agent. Our nominated UK Representative is:
GDPR Local Ltd.
Adam Brogden
[email protected]
Tel +44 1772 217800
1st Floor Front Suite
27-29 North Street, Brighton
England
BN1 1EB
Our EU Representative
Under Article 27 of the GDPR, we have appointed an EU Representative to act as Our data protection agent. Our nominated EU Representative is:
Instant EU GDPR Representative Ltd.
Adam Brogden
[email protected]
Tel +35315549700
Office 2, 12A Lower Main Street, Lucan Co. Dublin
K78 X5P8
Ireland
Who this Policy applies to
This Policy relates to data subjects of MetaComet Systems including clients, customers, employees, and all other individuals who visit or use the Services. Processing of your data is required in order to offer you Our products and services. This Policy applies to individuals who have shared their data with MetaComet Systems as either a customer, client, employee, supplier or in any other capacity.
It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the GDPR.
How we collect information
This section describes the lawful basis for processing your data and applies to the information about yourself that you choose to provide us with or that you allow us to collect.
We do not collect or process sensitive data about you, as that is defined in the GDPR.
1. Information you provide
Account Setup
We collect information when you create or update your account. This may include business name, a contact person’s name, mailing address, phone numbers, a valid email address, payment information (for certain paid services), demographic information, and certain other information indicated as required during account creation.
If you choose certain paid services, you will be required to identify merchant banking information. In connection with your account registration, We may also ask for additional information, including the number of employees in your company (if an entity), your annual revenues, your industry and other similar information. We use all such information to provide the Services to you, including to contact you, confirm your identity and, if applicable, to invoice you.
Information created when you use Our site, Services, Contact Us, Request a Demo, Sign Up for Information, or Request Support
If you contact Us by one of the phone numbers on the Services, We collect your phone number and may record call audio. From chat support users, We collect personal data as well as information about the device and browser you use, your network connection and your IP address. From forum users, We collect certain personal data, including your name, email address and website URL. We also collect personal data such as your name, email, phone number, and company when you complete forms on the Services, including when you request a demonstration, sign up for our newsletter, or use our contact or service request forms.
2. Information from other sources
Automatically Collected Information
We automatically collect certain information and analytical data related to your visits to and use of the Services (see “Cookies and Third-Party Technologies” below). Such automatically collected information may include the date and time of your visit, page navigation, the IP address of your computer or mobile device, your computer or mobile device browser information, the Internet address that you visited prior to and after reaching the Services, the name of the domain and host you used to access the Internet, the type of mobile device you use, your mobile device’s unique device ID or other unique identifier and the features of the Services which you accessed.
Our Partners
We collect personal data from Our partners, which include individuals and businesses that have entered into a business agreement with Us. Our partners can include referral partners, developers, technology partners and solution partners. We also collect personal data about your customers from Our partners in accordance with their applicable privacy policy. We use all such information to provide the Services to you, including to contact you and confirm your identity and to improve the Services.
Social Media
The Services may use social media features, such as the Facebook “like” button (the “Social Media Features”). These features may collect your IP address and which page you are visiting on the Services, and may set a Cookie to enable the feature to function properly. You may be given the option by such Social Media Features to post information about your activities on the Service to a profile page of yours that is provided by a third party social media network in order to share with others within your network. Social Media Features are either hosted by a third party or hosted directly on the Service. Your interactions with these features are governed by the privacy policy of the company providing the relevant Social Media Features.
3. Cookies and Third-Party Technologies
A cookie is a small file which asks permission to be placed on your computer’s hard drive (“Cookie”). Cookies allow web applications to respond to you as an individual and help us analyze web traffic and improve Our Services. We use both Session and Persistent Cookies, including Necessary/Essential, Notice Acceptance, Functionality, and Tracking and Performance cookies. You can choose to accept or decline cookies through your browser settings and through the cookie consent controls presented on Our site; declining may prevent you from taking full advantage of the Services. When you use the Service, we may also employ clear gifs (web beacons) to track online usage patterns anonymously and to measure email engagement.
How your information will be used
We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed and only where there is a lawful basis for such processing, for example:
Internal Usage
| Purpose/Activity | Type of data | Lawful basis for processing |
| To register you as a new customer |
(a) Identity, (b) Contact |
(a) Performance of a contract with you; (b) Consent |
| To process and deliver the products and services you request, and to manage payments, fees and charges. |
(a) Identity, (b) Contact, (c) Financial, (d) Transaction, (e) Marketing and Communications |
(a) Performance of a contract with you; (b) Necessary for Our legitimate interests to recover debts owed to us; (c) Consent |
| To manage Our ongoing relationship with you, including notifying you about changes to terms, services or this Policy, and to maintain Our records. |
(a) Identity, (b) Contact, (c) Profile, (d) Marketing and Communications |
(a) Performance of a contract with you; (b) Necessary to comply with a legal obligation; (c) Legitimate interests to keep records updated and study how customers use Our services; (d) Consent |
| To administer and protect Our business and Our site (troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
(a) Identity, (b) Contact, (c) Technical |
(a) Necessary for Our legitimate interests for running the business, IT services, network security, fraud prevention and business reorganisation; (b) Necessary to comply with a legal obligation; (c) Consent |
| To use data analytics to improve Our website, services, marketing, customer relationships and experiences |
(a) Technical, (b) Usage |
(a)Necessary for Our legitimate interests to develop the business and inform marketing strategy; (b) Consent |
| To make suggestions and recommendations to you about services that may be of interest to you |
(a) Identity, (b) Contact, (c) Technical, (d) Usage, (e) Profile |
(a)Necessary for Our legitimate interests to develop services and grow the business (b) Consent |
Third Parties
We may have to share your personal data with the parties set out below for the purposes described in this document:
- Service providers who provide IT and system administration services, for example AWS, Heroku/Salesforce, Mailgun.
- Third parties including equipment providers, and other third parties as required to run Our business
- Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, credit scoring, banking, legal, fraud protection, insurance and accounting services.
- HM Revenue & Customs, regulators and other authorities based in the United Kingdom and other relevant jurisdictions who require reporting of processing activities in certain circumstances.
- Third parties to whom we sell, transfer, or merge parts of Our business or Our assets.
We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with Our instructions.
How to change your preferences
We operate in line with UK GDPR data protection guidelines. We respect your rights and will respond to any request for access to personal data and requests to delete, rectify, transfer data and to stop processing. We will also advise you on how to complain to the relevant authorities, namely the Information Commissioner’s Office [for UK companies]. Any requests or objections should be made in writing to the Data Controller, or you can visit Our website, call, or email us to change your preferences at any time.
Scope of Agreement
By submitting your personal data on this site or as required for us to provide services to you, you are affirming your agreement for such information to be used in accordance with this Policy. You will be able to change your preferences at any time by the methods described in this document.
We may from time to time use your information for marketing, account management or relationship management purposes. The main purpose of this is to provide you with information about services which we think may be of interest to you and/or to maintain any existing relationship we may have with you.
Opting out at a later date
Where you give your consent for us to process your data — for example when you agree to us sending you marketing information or where you agree to us processing financial data — you can contact us to amend or withdraw your consent at any time. You can also choose to object to processing and request deletion of your data. We respect all user rights as defined in GDPR and other applicable laws. If you have any comments or wish to complain please contact us.
How we store and process your data
Your data may be collected, stored and processed in the UK, however we may also collect, store, process, or transfer your data outside the UK where the parties involved in the processing of data are located, including without limitation, to the United States. This means that this information may be transferred to, processed, and maintained on computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction. We will ensure we take appropriate precautions to protect this data. Your data will normally be stored for up to 7 years to ensure we have records of service and other interactions.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for a purpose unrelated to the purpose for which we collected the data, we will notify you and we will explain the legal ground of processing.
We may be legally obliged to disclose your personal data without your knowledge to the extent that we are required to do so by law; in connection with any ongoing or prospective legal proceedings; or in order to establish, exercise or defend Our legal rights.
You will only receive marketing communications from us if you have requested information from us; provided your details and opted in for us to send you marketing communications; and have not opted out of receiving marketing. We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Our obligations
We are a Data Controller. In relation to the information that you provide to us, we are legally responsible for how that information is handled. We will comply with the GDPR and other applicable privacy laws in the way we use and share your personal data.
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or we may refuse to comply in these circumstances. We may need specific information from you to confirm your identity and ensure your right to access. We try to respond to all legitimate requests within one month, and will notify you if we need longer.
MetaComet Systems as a Data processor
When MetaComet Systems acts as a data processor, we will store and process the data provided to us by Our clients, in order to allow us to provide the services as agreed in the contract with the controller. During the process we will ensure we meet Our obligations as defined in Our contract and in any associated Data Processing Agreement.
Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know such data. They will only process your personal data on Our instructions, and they are subject to a duty of confidentiality. We will report any breaches or potential breaches to the appropriate authorities and to anyone affected in accordance with applicable law.
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
Legitimate Interests
Under the GDPR, we are also permitted to share some information with third parties who use such data for non-marketing purposes (including credit and risk assessment and management, identification and fraud prevention, debt collection and returning assets to you).
Your Age
Our Service is not intended for use by people under 18 years of age and we do not knowingly collect information from people under the age of 18. No one under the age of 18 may provide information on the Service. By using or accessing the Service, you acknowledge that you are 18 years old and have all rights necessary to conclude an agreement with Us and to provide Us with consent for the processing of your personal data.
If we learn we have collected or received personal data from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18 please contact us at [email protected].
Your California Privacy Rights
California’s “Shine the Light” law (Civil Code Section 1798.83) permits users of the Website or Services that are California residents to request and obtain from us a list of what personal data (if any) we have shared with third parties or corporate affiliates for those entities’ direct marketing purposes in the preceding calendar year, and the names and addresses of those third parties. Requests may be made only once a year and are free of charge.
If you are a California resident and would like a copy of this notice, please submit a written request to the following address: MetaComet Systems, 47 Pleasant St. Suite 1-SW, Northampton, MA 01060. For all requests, you must put the statement “California Privacy Rights Notice” in the body of your request, as well as your name, street address, city, state, and zip code, and attest that you are a California resident. We will not accept requests via telephone, email or facsimile.
California Do Not Track Disclosures
California Business & Professions Code Section 22575(b) provides that California residents are entitled to know how a website operator responds to “Do Not Track” (DNT) browser settings. We do not currently take actions to respond to DNT signals because a uniform technological standard has not yet been developed. We continue to review new technologies and may adopt a DNT standard once one is created.
Updates to the Privacy Policy
We may occasionally update this Policy. If We make significant changes, We will notify you of the changes on the Services or through other means, such as email. To the extent permitted under applicable law, by using the Services after such notice, you consent to Our updates to this Policy. We encourage you to periodically review this Policy for the latest information on Our privacy practices.
EU-U.S. Data Privacy Framework (DPF) Statement
MetaComet Systems, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. MetaComet Systems, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
1. Data Collected and Purposes.
The personal data covered by MetaComet Systems, Inc.’s DPF self-certification is the non-HR personal data of our customers’ authors, rights holders, agents, licensees, and other business contacts that we process on behalf of our customers through our software (including Royalty Tracker and MetaComet Rights). This data may include Identity (name), Contact (email, address, phone), Transactional (royalty and licensing records), Technical (IP address, device info), and Usage data. We process this information solely to provide the services on behalf of our customers, specifically to:
- Provide and deliver the royalty and rights management services our customers request.
- Support our customers’ use of the services, including notifications and customer support.
- Administer, secure, and troubleshoot the services and systems.
- Improve the services using aggregated analytics.
Financial and payment/banking information that MetaComet collects directly from its business customers to invoice them for their subscriptions is collected in MetaComet’scapacity as a controller for its own billing purposes and is not within the scope of this DPF self-certification.
2. Third-Party Disclosures.
MetaComet Systems, Inc. discloses personal data to service providers (IT and system administration), equipment providers, professional advisers (lawyers, auditors, insurers), and regulatory authorities. MetaComet Systems, Inc. remains liable for the onward transfer of DPF personal data to third parties as described in the DPF Principles.
3. Rights to Access & Choice.
Individuals have the right to access their personal data and to limit the use and disclosure of their personal data. To exercise these rights, please contact us at the details below.
4. Investigatory and Enforcement Powers.
MetaComet Systems, Inc. is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
5. Dispute Resolution & Arbitration.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, MetaComet Systems, Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF should first contact our Data Protection Lead:
MJ Hyndman-Benander, Security Operations Manager
Email: [email protected]
Phone: 413-536-5989 x100
MetaComet Systems, Inc. has further committed to refer unresolved complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Under certain conditions, individuals may invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other DPF mechanisms. For more information, please see Annex I of the DPF Principles.
Contacting us, exercising your information rights and Complaints
If you have any questions or comments about this Policy, wish to exercise your information rights in connection with the personal data you have shared with us or wish to complain, please contact: [email protected] at MetaComet Systems, Inc. We will process data protection requests within 30 days; SAR responses are usually free but we reserve the right to charge for excessive or unfounded requests. We fully comply with Data Protection legislation and will assist in any investigation or request made by the appropriate authorities.
If you remain dissatisfied, then you have the right to apply directly to the Information Commissioner for a decision. The Information Commissioner can be contacted at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
www.ico.org.uk
