GalaxyWorks Legal Portal

Last updated: March, 2021

Privacy Policy

How GalaxyWorks deals with personal data of individuals.

At GalaxyWorks, our goal is to set a high standard for protecting the privacy of your data and information. We want to be clear about how we collect, use, protect, and share your information, including your personal information, and the rights and choices you have about the ways in which you can help us protect your privacy.

This Privacy Statement explains:

  • What information we collect and why we collect it;
  • How we use that information and when we disclose it;
  • Your rights regarding that information, including how to access and update your information; and
  • The steps we take to protect your information.

Scope: This Privacy Statement applies to the information that we obtain through your use of GalaxyWorks products and services, including our website (https://www.galaxyworks.io), our Galaxy Pro platform, social media, communications, and web-based tools (collectively, our "Services"). For a current list of the Services and vendors covered by this Privacy Statement, see our Subvendor Directory.

This Privacy Statement does not apply to personal information arising from GalaxyWorks’ employment-related activities. Except to the extent that a third party provides services on our behalf (such as a SaaS vendor), this Privacy Statement also does not apply to the practices of third parties to which we may link or otherwise refer you, such as consultants, pen testing firms, audit firms, and other vendors.

Geography: GalaxyWorks is a U.S.-based company that offers our Services to domestic and international customers. As a result, information that we collect, including personal information, may be transferred to our U.S. offices to permit us to comply with our legal and contractual obligations, to provide information and services to prospective and current clients, and to perform related business activities. In addition, we may provide information to third-party service providers in the U.S. and in other countries to the extent necessary to support GalaxyWorks’s business activities, and we may access personal information collected by our customers to support the Services that we provide to our customers. Thus, personal information may be transferred to and stored on servers located in the United States and in countries different from the country in which that information was initially collected. Similarly, information we collect may be accessed by GalaxyWorks and our third-party service providers and business partners from countries other than the ones in which the information is stored. For more information about how we handle personal information from EU-based individuals, see below.

If you have any questions or concerns about this Privacy Statement or about our privacy or data security practices, please contact us at legal@galaxyworks.io.

What We Mean by Personal Information

For purposes of this Privacy Statement, "Personal Information" means information from or about you that identifies you directly and information that is associated with you and thus could potentially identify you, including when combined with other information from or about you. Types of Personal Information that we may collect:

  • Names
  • Physical address
  • Email addresses
  • Telephone numbers
  • Business contact information, including names, email addresses, business addresses, telephone numbers, company name or business affiliation, and title.
  • User IDs and passwords
  • Personal information that you choose to share within our user communities, such as the Galaxy Project Slack/Gitter channel (http://gitter.im/galaxyproject) or help.galaxyproject.org
  • Payment card and financial account information
  • Identifiers of devices used to access our Services

Information that We Collect from and About You

Information that You Provide to Us Voluntarily

Account and Profile Information: We collect information about you and your company when you register for an account, create or modify your profile, and make purchases through our Services. Information we collect includes your name, username, address, email address, phone number, and payment card details. You may provide this information directly through our Services.

Content: We collect and store content that you create, input, submit, post, upload, transmit, or store while using our Services. Such content may include any personal or other sensitive information submitted using our Services, EU personal data, and other information such as source code or regulatory compliance materials.

Other submissions: We collect other data that you may submit to our Services or to us directly, such as when you request customer support or communicate with us via email or social media sites.

Information that We Collect Automatically When You Use Our Services

Web Logs and Analytics Information: We record certain information and store it in log files when you interact with our Services. This information may include Internet protocol (IP) or other device addresses or ID numbers as well as browser type, Internet service provider, URLs of referring/exit pages, operating system, date/time stamp, information that you search for, your locale and language preferences, and system configuration information. We and our analytics providers (see our Subvendor Directory), also collect and store analytics information when you use our Services to help us improve our Services.

Cookies and Other Tracking Technologies: We use various technologies to collect information, including cookies that we save to your computer or mobile device. See our Subvendor Directory. Cookies are small data files stored on your hard drive or in device memory. We use cookies to improve and customize our Services and your experience; to allow you to access and use the Services without re-entering your username or password; and to count visits and understand which areas and features of the Services are most popular. We may also associate the information we store in cookies with personal information you submit while on our Services. You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from websites you visit. If you do not accept cookies, however, you may not be able to use all aspects of our Services.

Information that We Collect from Other Sources

Information from third parties: We may obtain information, including personal information, from our business partners and service providers. This information includes, but is not limited to, information that we receive from our direct marketing providers, product referrals, and other interactions. We also may combine information we receive from third parties with other information we collect from you through our Services as described in this Privacy Statement. If we use this information to provide you with opportunities that we think may be of interest to you, you will have the ability to inform us that you do not wish to receive such offers, and you may unsubscribe from our marketing and other email communications by clicking on the link in the email, sending an email to legal@galaxyworks.io, or accessing your user account and changing your distribution preferences.

Why We Collect Information from and About You

We will not use your personal information for anything other than the following lawful purposes:

To establish and maintain contractual relationships with our customers:

  • To fulfill our obligations to current customers
  • To contact customers regarding account-related issues and business communications relating to the Services, including technical notices, updates, security alerts, and administrative messages
  • To enable individuals to access and use our Services
  • To establish relationships with new customers

To comply with our legal obligations:

  • To comply with legal obligations, including but not limited to complying with tax and financial reporting requirements
  • To demonstrate compliance with applicable privacy and data security laws and regulations, such as GDPR
  • To comply with incident monitoring, reporting, assessment, and notification requirements
  • To comply with other applicable criminal and civil law and regulatory requirements under federal, state, and international law

To provide services and information that you request and consent to receive:

  • To provide customer service and support
  • To communicate with you, including responding to your comments, questions, and requests regarding our Services
  • To process and complete transactions, and send you related information, including purchase confirmations and invoices
  • To provide direct marketing, email, and other distributed information distribution

To fulfill our other legitimate interests to the extent that they are not overridden by individual interests, fundamental rights, or freedoms:

  • To administer, operate, maintain, and secure our website and Services
  • To monitor and analyze trends, usage, and activities in connection with our Services
  • To investigate and prevent fraudulent transactions, unauthorized access to our Services, and other illegal activities
  • To verify compliance with our internal policies and procedures
  • For accounting, recordkeeping, backup, and administrative purposes
  • To customize and improve the content of our communications, websites, and social media accounts
  • To educate and train our workforce in data protection and customer support
  • To provide, operate, maintain, improve, personalize, and promote our Services
  • To develop new products, services, features, and functionality
  • To market our products and services (first-party marketing only; we do not provide personal information for use in marketing any non-GalaxyWorks, third-party goods or services)

When possible, we will use anonymized data for these purposes, but if we do not, or if we combine it with Personal Information we will treat it in accordance with this Privacy Statement.

When and Why We Share or Disclose Personal Information

Except to the extent necessary to fulfill our business obligations, to accomplish one of the lawful purposes described in this Privacy Statement, or pursuant to your express instructions, we do not sell, transfer, or otherwise disclose personal information that we collect from or about you.

We may share your information in the following ways:

With your express consent: We will share your personal information with companies, organizations, or individuals outside of GalaxyWorks when we have your consent to do so.

When you choose to directly share your information while using our Services: When you use our Services, certain features allow you to make some of your content accessible to the public or other users of the Services. We urge you to consider the sensitivity of any information prior to sharing it publicly or with other users.

With our vendors and business partners, to accomplish our business purposes: We may share your information with our service providers and other third parties who perform services on our behalf, listed in our Subvendor Directory. We provide your payment information to our service providers for payment processing and verification. Service providers such as analytics providers may collect information about your online activities over time and across different online services when you use our Services. We also work with third-party service providers to provide the cloud-based tools that our customers use to create their secure storage containers and securely store their sensitive information, including personal information.

When necessary to comply with laws and law enforcement requests, or otherwise to protect our rights or those of individuals: We may disclose your information (including your personal information) to a third party if:

  • We believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process or governmental request;
  • To enforce our agreements, policies and terms of service;
  • To protect the security or integrity of GalaxyWorks’ products and services;
  • To respond to an incident involving personal data for which GalaxyWorks has direct or indirect responsibility;
  • To protect the property, rights, and safety of GalaxyWorks, our customers or the public from harm or illegal activities;
  • To respond to an emergency which we believe in the good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person; or
  • To investigate and defend ourselves against any third-party claims or allegations.

As the result of a business transition: We may share or transfer your information (including your personal information) in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. We will take reasonable steps to assure that any other entity involved continues to comply with the terms of this Privacy Statement. We will notify you of such a change in ownership or transfer of assets by posting a notice on our website.

Sharing aggregate, anonymized, deidentified, or otherwise non-personal data: We may share aggregate, anonymized deidentified, or otherwise non-personal information that does not directly or indirectly identify you and that cannot, with reasonable effort, be used to reidentify you in order to improve the overall experience of our Services. Such aggregated, anonymized, deidentified, or otherwise not re-identifiable information is not personal information within the scope of this Privacy Statement.

Your Control Over Your Personal Information

  • You may decline to share certain personal information with us, in which case we may not be able to provide to you some of the features and functionality of our Services or fulfill your requests. For example, we need your email address to authenticate you and perform account services such as password resets, or to provide you with customer support.

  • If you wish to update your personal details, or remove your account, you may do so by contacting support@galaxyworks.io.

  • You may opt out of receiving promotional communications from GalaxyWorks by using the unsubscribe link within each email. Note that, as long as you maintain an account with us, you will continue to receive administrative messages from us regarding the Services.

  • You may request information about, and access to, the personal data that we collect from you.

  • You may ask questions or make complaints about our privacy and data security practices with regard to your personal data.

  • You may request that we delete information that we have collected about you.

  • You may ask us for a copy of the information that we collect from you.

To exercise any of these options, or for additional information about our privacy and data security practices, contact us at legal@galaxyworks.io.

Security

Unfortunately, no data transmission over the Internet or data storage system can be guaranteed to be 100% secure. That said, we certainly try very hard, employing a variety of organizational, technical and administrative measures to provide a level of security appropriate to the risk associated with the personal information you trust us with. Please see our Security Policy for more details.

GalaxyWorks protects personal information under its control, and requires its service providers (see our Subvendor Directory) to also protect against, accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to, personal data transmitted, stored, or otherwise processed.

If you have concerns about the security of your information with GalaxyWorks, please contact us immediately at security@galaxyworks.io to report an issue.

Data Retention

We retain your personal information only as long as necessary to accomplish the business purpose for which it was collected or to comply with our legal and contractual obligations and then securely dispose of that information.

Children’s Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from individuals under 18. If we become aware that a person under 18 has provided us with personal information, we will take steps to delete such information. If you become aware that a person has provided us with personal information, please contact us at legal@galaxyworks.io.

California Privacy Rights

California Civil Code Section 1798.83 permits GalaxyWorks customers who are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please contact us at legal@galaxyworks.io.

Information for Users outside the United States

The Galaxy Pro Services are hosted in the United States.

Information for EU-Based Individuals

For personal data transferred from the EU to the U.S. or other third country not determined to meet EU adequacy requirements, if we transfer your personal data to a third party, we will ensure that the third party is contractually obligated to process your data only for limited, specific purposes consistent with this policy. We will also ensure that the third party will apply the same level of protection to that data as us and will notify us if it makes a determination that it can no longer meet this obligation. GalaxyWorks may be potentially liable if these requirements are not met.

Complaints, Questions, and Arbitration

We strive to resolve all complaints about privacy and the collection or use of customer information. If you have questions about our policies or have a complaint, please send an email to legal@galaxyworks.io.

Changes to this Privacy Statement

We may change this Privacy Statement from time to time. If we make any changes, we will notify you by revising the version and date at the top of this Privacy Statement and, in some cases, where appropriate we may provide you with additional notice (such as adding a statement to the log-in screen or sending you an email notification).

Your continued use of our Services after the revised Statement has become effective indicates that you have read, understood, and agreed to the current version of this Statement.

Contact Information

Please contact us with any questions or comments about this Statement, your personal information, our use and disclosure practices, or your consent choices by email at legal@galaxyworks.io.