California Privacy Notice Addendum
Table of contents
- Your California Privacy Rights
- Personal Information We Collect and How We Collect It
- Use of Personal Information
- Sharing of Personal Information
- Rights of California Residents
- Verification of Consumer Request and Timeline
Your California Privacy Rights
This section applies only to California residents. Under California Civil Code Sections 1798.83-1798.84, California residents, including California PandaDoc employees and contractors, are entitled to receive: (a) information identifying any third-party companies to whom PandaDoc may have disclosed Personal Information to for direct marketing, within the past year; and (b) a description of the categories of Personal Information disclosed.
To obtain such information, please contact us here and we will provide a list of categories of Personal Information disclosed within forty-five (45) days after receiving such a request. This request may be made no more than once per calendar year. We reserve the right not to respond to requests submitted in ways other than those specified above.
Personal Information We Collect and How We Collect It
We collect the type of information described in this California Privacy Notice Addendum and in the Privacy Notice, which includes Personal Information and Sensitive Personal Information, in the manner described herein and in the Privacy Notice.
“Personal Information” means information that identifies, relates to, describes, could reasonably be associated with, or could be reasonably linked directly or indirectly with a particular California consumer or household. Personal Information does not include (i) publicly available information from government records; (ii) deidentified or aggregated consumer information; or (iii) information excluded from the scope of the California Privacy Rights Act (“CPRA”) such as:
- health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA), clinical trial data, or other qualifying research data;
- personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), the Farm Credit Act, and the Driver’s Privacy Protection Act of 1994.
If you do not provide the information that we ask for, we may not be able to provide you with the requested services. Sensitive Personal Information is a subset of Personal Information that requires greater security protections and standards of care in handling.
Sensitive Personal Information under the CPRA is defined as information that if lost, compromised, or disclosed could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual. For more information please click here and scroll to the definition of “Sensitive Personal Information.”
We collect Personal Information for the business purposes described in our Privacy Notice. The CPRA defines a “business purpose” as the use of Personal Information for the business’s operational purposes, or other notified purposes provided the use of Personal Information is reasonably necessary and proportionate to achieve the operational purpose for which the Personal Information was collected or another operational purpose that is compatible with the context in which the Personal Information was collected.
The categories of other individuals or entities with whom we may share your Personal Information are listed in our Privacy Notice under “Sharing of information”.
We have collected the following categories of Personal Information within the last twelve (12) months:
Category | Information | Data Retention |
---|---|---|
Identifiers. | First name, last name, postal address, unique personal identifier, online identifier, internet protocol address, email address, email data, website usage data, account name, or other similar identifiers. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). | First name, last name, postal address, unique personal identifier, online identifier, internet protocol address, email address, email data, website usage data, account name and login, financial information such as credit and/or debit card, or other similar identifiers. Note, some personal information included in this category may overlap with other categories. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
We collect protected classification characteristics under California or federal law | This may include age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Sensitive Personal Information | Credit Card or Debit Card Number; geolocation; account login | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Commercial information. | Records of services purchased. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
We collect sensory data. | This may include audio, electronic, visual, or similar information. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with our website. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
We collect inferences drawn from other Personal Information. | This may include Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Geolocation data. | Physical location via internet protocol address. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
Professional or employment-related information. | Current or past job history or performance evaluations, background information. | We retain the information from this Personal Information category for as long as you are our customer and we may maintain an archive copy for audit purposes. We do not sell the information from this Personal Information category and we do not share it for cross-context behavioral advertising purposes. |
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you. For example, from forms you complete or products and Services you inquire about or purchase.
- Indirectly from you. For example, from observing your actions and interactions with the Services.
- Other sources. For example, advertising networks, internet service providers, operating systems and platforms and/ or social networks.
Use of Personal Information
For more information about how we collect your Personal Information, please see the “Types of information we collect” and “Use and processing your information” sections of our Privacy Notice.
Sharing Personal Information
We share Personal Information as further described in the “Sharing of Information” section of the Privacy Notice. We also explain the categories of third-parties to whom we disclose Personal Information.
Rights of California Residents
If you are a California resident or are a California employee or contractor of PandaDoc, the CPRA provides you with specific rights regarding your Personal Information, subject to certain exceptions.
For instance, we cannot disclose specific pieces of Personal Information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the Personal Information, your account with us, or the security of our network systems.
These rights are explained below:
- Right against Discrimination. You have the right not to be discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your rights.
- Right to Access. You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. PandaDoc will provide personal information to a consumer upon request a maximum of two times in a 12-month period. Once we receive and confirm your verifiable consumer request, we will disclose the following to you: (i) the categories of Personal Information we collected about you; (ii) the categories of sources for the Personal Information we collected about you; (iii) the business purpose for collecting (or selling, if applicable) the Personal Information; (iv) the categories of third parties with whom we share such Personal Information; and (v) the specific information we collected about you.
- Right to Delete. You have the right to request that we delete any of your Personal Information we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete and will direct our service providers to delete your Personal Information from our records, unless an exception applies. Keep in mind, we may deny your request if it is necessary for us or our service providers to: (i) complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform services pursuant to our contract with you; (ii) detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities; (iii) debug our website and/or identify and repair errors that impair existing intended functionality; (iv) exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law; (v) comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.); (vi) engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent; (vii) enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us; (viii) make other internal and lawful uses of that information that are compatible with the context in which you provided it; or (xi) comply with a legal obligation.
- Right to Correct. In certain circumstances and upon the receipt of a verifiable consumer request, you have the right to request that PandaDoc correct any inaccurate Personal Information PandaDoc maintains about you. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your Personal Information as directed, taking into account the nature of the Personal Information and the purposes of maintaining your Personal Information.
- Right to Opt-Out of Sale or Sharing of Your Personal Information. You have the right to opt out of having your Personal Information, including Sensitive Personal Information, sold or shared. PandaDoc does not sell Personal Information or Sensitive Personal Information for monetary or other valuable consideration. If you wish to opt-out of sharing your Personal Information, please click here to be redirected to our “Do Not Share or Sell My Personal Information” page.
- Right to Limit the Use and Disclosure of Sensitive Personal Information. Additionally, you have the right to direct PandaDoc to limit our use of your Sensitive Personal Information to that information which is expected by an average individual as necessary to perform our Services or for your employment. If you wish to limit our use or disclosure of your Sensitive Personal Information, please click here to be redirected to our “Limit the Use of My Sensitive Personal Information.”
Verification of Consumer Request and Timeline
To assert any of your rights, please contact us as set forth below.
To confirm your identity, it is imperative that we verify the consumer request and so you must provide information that allows us to reasonably verify that you are the person about whom we collected the Personal Information or are an authorized representative. If you make a request on behalf of another person, we will need to verify that you have the authority to do so. You must also describe the request with sufficient detail that allows us to properly understand, evaluate and respond to such request. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. We will not honor your request if an exception to the law applies.
We will respond to requests within forty-five (45) days after our receipt of such verifiable request (or within such other time as required by applicable law). If we need additional time, we will notify you in writing prior to the expiration of the forty-five (45) day period and inform you of the reason for an additional forty-five (45) day extension of time. For the avoidance of doubt, any such requests for Personal Information will cover the twelve (12) month period immediately preceding the date of such verifiable request. Disclosure of Personal Information in response to such a request will be provided in a commonly used format. For more information about requests, please see the “Your rights and controlling your personal information” section of the Privacy Notice.
To exercise any of your rights, please click here or you can also send a request in writing to PandaDoc, Inc., Attention: Privacy Department, 3739 Balboa St. #1083, San Francisco, CA 94121. If you are a California resident, employee or contractor and wish to opt-out of sharing your Personal Information or wish to limit the use of your Sensitive Personal Information, please click here to be redirected to our “Do Not Share or Sell My Personal Information” page.