WiteSand understands your desire to protect personal information.
If you have questions or concerns about your privacy, please notify us by contacting us at firstname.lastname@example.org.
Types and Purposes of Personal Data
When you use the SaaS, we collect a minimal amount of personal data. Your personal data is used for specified and limited purposes. In this section, we explain what types of personal data we collect from you, for what purposes we use that data, and on what legal bases we rely when processing your personal data.
Personal Data Collected by Us
Portal Users, Who Register and Log in to SaaS
The SaaS portal account provides access to network, security, facility employees with admin, operator, viewer type of privileges. When you register for Portal Account, we collect your email address. And, if chosen to create a local account, we collect your password.
We use such data to (i) register and maintain your Portal Account, (ii) enable your access to the SaaS, (iii) provide you with the requested services, (iv) contact you, if necessary, and (v) maintain our business records. The legal bases on which we rely are ‘performing a contract with you’ and ‘pursuing our legitimate business interests’ (i.e., analyze, grow, and administer the SaaS).
Employees, Who Connect to Your Network Serviced by SaaS
Customers’ assigned Portal User(s), point their network(s) to WiteSand SaaS for the purpose of one or more services such as: network provisioning, network monitoring, network access control, and network flow analytics.
The Portal Users also provide read-only credentials for identity providers such as LDAP, AD, GSuite etc., through which employees can be authenticated and authorized when they connect to the customer network.
As employees connect to the customer network, authentication/authorization is performed by the WiteSand SaaS in consultation with the configured identity providers according to the authentication protocols chosen by the customer network administrators.
The following information is collected by SaaS for each employee’s endpoint (such as laptop, computer, Mobile phone) connected to network via wired or wireless connection:
- Location information
- MAC address
- IP Address
- OS version
- Patch level of various applications running on the endpoint
- Browser UserAgent
- Netflow/sFlow packet header showing source/destination IP address/ports etc., being accessed
We use such information to provide our services, i.e., to support network connectivity, enable visibility, and debug technical issues. The legal basis that we rely on when processing such information is ‘performing a contract’.
When you contact us, we collect your (i) name, (ii) email address, and (iii) any information that you decide to include in your message. We use such data to respond to your inquiries and provide you with the requested information. The legal bases on which we rely are ‘pursuing our legitimate business interests’ (i.e., to grow and promote our business) and ‘your consent’ (for optional personal data).
How Long Does WiteSand Keep My Personal Information?
Personal Information related to an individual associated with one of our customers is retained while the customer relationship is in place (and to complete any post-termination transactions or wind-down of activities) or until we are advised that the individual is no longer associated with that customer.
How Can I Manage My Personal Information Retained by WiteSand?
You are in control of whether or not you give us Personal Information and can delete any Personal Information you have provided from the SaaS portal.
- Portal Users can delete their data anytime from the portal.
- Portal Users (typically admins or whichever role has authority in your organization) can delete any employee data at any time.
After your personal data is no longer necessary for its purposes and there is no other legal basis for storing it, we will immediately securely delete your personal data from our systems. We do not store any personal data longer than necessary.
Sharing of Personal Information
We do not sell or rent your Personal Information to third parties for purposes unconnected to our uses of the information described above.
We may also provide Personal Information to third parties in connection with legal matters, which includes:
- providing information where we are legally obligated to do so (such as subpoenas or court orders), and
- in connection with the investigation, prevention or assisting law enforcement with respect to suspected or known illegal activities, fraud, threats, violations of our terms of service, or as otherwise required by law.
How Does WiteSand Secure My Information?
WiteSand is committed to protecting the Personal Information you share with us. We utilize a combination of industry-standard security technologies, procedures, and organizational measures to help protect your Personal Information from unauthorized access, use or disclosure.
We implement technical and organizational information security measures that protect your personal data from loss, misuse, unauthorized access and disclosure. The security measures taken by us include secured networks, encryption, strong passwords, no access to your personal data by our staff, anonymization of personal data (when possible), and security certificates.
If you have questions or information related to any actual or potential security incident, or unauthorized disclosure access or breach of security, related to our maintenance of information, please notify us by contacting us at email@example.com.
When you use the SaaS, we automatically collect certain non-personal data related to the services used by you. The non-personal data includes the following information:
- Your activity on the SaaS;
- Your browser type and version;
- Your operating system;
- The date and time when you access the SaaS;
Provisions Specific to EU Citizens
Rights of EU Citizens Under the GDPR
If you are a citizen of the European Union you have certain rights relating to how others handle your personal information. These rights are:
- The right to be informed how your personal information is being used.
- The right of access your personal information and how it is processed.
- The right to rectify personal information which is inaccurate or incomplete.
- The right to erasure – also known as ‘the right to be forgotten,’ this refers to an individual’s right to having their personal data deleted or removed.
- The right to restrict processing, that is, the right to block or suppress processing of your personal data.
- The right to data portability – this allows individuals to retain and reuse their personal data for their own purpose.
- The right to object, in certain circumstances, to use of your personal data in a manner different from the purpose for which it was provided.
- Right to prevent automated decision making or profiling based on your data without human intervention.
Identity of Data Controller
When an individual is providing personal information in connection with use of our Service in their capacity as an authorized user of a company which does business with WiteSand, the data controller is generally going to be that company.
If an individual is providing personal information directly to WiteSand, for example, as a WiteSand employee, a visitor to WiteSand’s website, or a party consenting to receive information regarding WiteSand and its Service, then WiteSand is generally going to be the data controller. In circumstances where WiteSand is the data controller, you can contact us at the email and physical addresses provided above in the section named “How can I manage my personal information retained by WiteSand?”
Exporting Personal Data
In the event it becomes necessary to export personal data from the EU or the UK, WiteSand will enter into the Standard Contractual Clauses with the customer applicable to such export.
Compliance with the California Consumer Privacy Act
WiteSand complies with the California Consumer Privacy Act of 2018 (“CCPA”).
We will comply with a request from a consumer to delete information concerning them subject to the exceptions in the CCPA. We do not sell personal information, as “sell” is defined in the CCPA. We will not discriminate in a manner which violates the CCPA against a consumer exercising his or her rights under the CCPA.
In some instances, WiteSand may collect non-personal aggregate or demographic data through cookies. This information may be used to better understand and improve the usability, performance, and effectiveness of the website.
In addition, by using some of our Service, anonymous network information (not including Personal Information) may be transmitted back to us such as Product usage information. This information is transmitted back to us so we can determine how users are interacting with our Service, to assist us as we consistently improve our Service and to correct any problems that may occur.
Consent to the Transfer, Processing, and Storage of Personal Information
WiteSand is required to disclose personal information to public authorities if they provide lawful requests for reasons of national security or law enforcement.
We will ask for your consent before we use or share your Personal Information for any purpose other than the reason you provided it or as otherwise provided by this policy.
The SaaS is not intended for use by persons under the age of 18. We do not knowingly collect minors’ personal data.
Term, Termination, and Amendments
To contact us via the postal service, send a letter to:
WiteSand Systems, Inc.
2860 Zanker Road, Suite 109
San Jose, CA 95134