Last modified: August 26, 2023
Restly, Inc., d.b.a. Fillout, together with its representatives, consultants, employees, officers, and directors (collectively “Fillout” “we,” “us,” or “our”) operates the website located at www.Fillout.com (the “Site”) and the services for building dynamic, multi-step web forms (“Forms”), and related features, content, applications, or products offered by Fillout for building the Forms (together with the Site, the “Services”).
Summary of Data Collection, Disclosure and Sale
INFORMATION THAT FILLOUT COLLECTS
Types of Information Collected
“Personal Data” is information by which you may be personally identified. Fillout may collect the following Personal Data from you:
Your payment information may be collected by third-party vendors, including our payment processor, Stripe. Such identifying information is not collected or stored by Fillout.
In addition to the Services storing the data that is submitted by third parties through the Forms, you may choose to store such data externally from the Services. With respect to the data that you or your designated data storage provider stores, you shall be solely responsible for your own data storage practices of any such data that you collect from third parties through the Forms.
Non-personal data includes any data that cannot be used on its own to identify, trace, or identify a person. We may collect feedback and your device information, including IP address, browser type, domain names, and access times.
How we collect information
We collect information about you in a couple of ways:
(1) when you provide it do us directly through an interaction with us; for example
(2) through automated collection methods like cookies or log files;
(3) when we obtain the information through a third party, including third party data verification entities, payment processors, or when you choose to login via a connected email address.
Why we collect and how we use your information. (Legal Basis)
We collect and use your Personal Data when we have a legitimate purpose to do so, including the following reasons:
Legal Bases for Processing European Information
If you are located in the European Economic Area or the United Kingdom (collectively, “Europe”), we only process your Personal Data when we have a valid legal basis to do so, including the following reasons:
We may use aggregated (anonymized) information about our End Users, and information that does not identify any individual, without restriction.
Accessing and Controlling Your Information
If you would like to prevent us from collecting your information completely, you should cease use of our Services. You can also control certain data via these other methods:
Correction capabilities: You have the ability to access and correct any inaccuracies in your personally identifiable information by emailing us at our email address provided in the Questions and Comments section below to correct such inaccuracies. We may require you to provide reasonable information to verify your identity before we respond to any of your requests.
Opt-out of non-essential electronic communications: You may opt out of receiving newsletters and other non-essential messages by using the ‘unsubscribe' function included in all such messages. However, you will continue to receive notices and essential transactional emails.
Optional information: You can always choose not to fill in non-mandatory fields when you submit any form linked to our services.
Residents of certain states in the United States have statutory data rights. We attempt to provide the same control and rights over your data no matter where you choose to live in the United States. As an End User of the Services, you have the following control over your data:
Residents of Europe have the following additional rights described below:
•You have the right to lodge a complaint with a supervisory authority, including in your country of residence, place or work or where an incident took place.
•You may withdraw any consent you previously provided to us regarding the processing of your Personal Data at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
Exercise Your Data Rights
We acknowledge your right to request access, amendment, or deletion of your data. We also recognize that you have the right to prohibit sale of your data, but we do not sell data.
You can exercise the rights described above, by sending an email or mail to the addresses listed in the Questions and Comments section below. Only you, or an agent authorized to make a request on your behalf, may make a request related to your personal information.
We cannot respond to your request if, (i) we cannot verify your identity; or (ii) your request lacks sufficient details to help us handle the request. We will make best efforts to respond to your request withing forty-five (45) days of its receipt. If we cannot respond in forty-five (45) days, we will inform you, in writing, the reason for the delay and will respond to your request within ninety (90) days. Any information we provide will only cover the twelve (12) month period preceding the request's receipt.
We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. We are not obligated to provide responses to your data requests more than twice in a twelve (12) -month period.
Automated Data Collection Methods
Cookies A cookie is a small file placed on the hard drive of your computer. Cookies are used to help us manage and report on your interaction with the Site. Through cookies, we are able to collect information that we use to improve the Services, keep track of username/password, authenticate your login credentials and tailor your experience on the Services. If you turn off cookies, your experience on the Services will be significantly impaired or prevented.
Log Files We use means through the Services to collect IP addresses, browser types, domain names, and access times. We use this information to optimize our platform, verify location, and maintain system security.
How Long do we Store Personal Data?
We will only retain your Personal Data for as long as is necessary to fulfill the purposes for which it is collected, or to comply with our legal obligations. This length of time may vary according to the nature of your relationship with us and mandatory retention periods provided by law.
Not Directed to Persons Under 18
Our Services are not intended for anyone under the age of 18, and we do not knowingly collect Personal Data from persons under 13. If we learn that we have collected or received Personal Data from a child under 13 without verification or parental consent, we will delete that information. If you believe we might have any information from or about a child under 13, please contact us at the email address listed below.
Do Not Track Settings
We do not track our Users over time and across third party websites to provide targeted advertising and do not specifically respond to Do Not Track (“DNT”) signals.
WHO WE SHARE DATA WITH
We may use aggregated (anonymized) information about our End Users and Visitors, and information that does not identify any individual, without restriction.
We do not sell or otherwise disclose Personal Data specific personal or transactional information to anyone except as described below.
We may share your Personal Data collected through the Services with other End Users (such as other End Users within your organization) or their authorized agents when you authorize us to do so, or when you complete a Form requested by such End Users through our Services.
Affiliates and Subsidiaries
Successors in Interest
Law enforcement and other governmental agencies
We may share your information when we believe in good faith that such sharing is reasonably necessary to investigate, prevent, or take action regarding possible illegal activities or to comply with legal process. This may involve the sharing of your information with law enforcement, government agencies, courts, and other organizations.
We may, for our legitimate interests, share certain information with contractors, service providers, third party authenticators, and other third parties we use to support our business and who are bound by contractual obligations to keep Personal Data confidential and use it only for the purposes for which we disclose it to them. Some of the functions that our service providers provide are as follows:
THIRD-PARTY SERVICES AND WEBSITES
Our Services may contain links to, or you may optionally integrate or connect our Services with, other websites, products, or services that we do not own or operate (“Third-Party Services”). Additionally, you may optionally self-host (on End-User premises) an agent software on your preferred cloud infrastructure provider to prevent any of your customer data collected from your use of our Services from being transferred to, or stored or processed by, Fillout.
Fillout is not responsible for the privacy policies or other practices employed by these Third-Party Services linked to, or from, our Site nor the information or content contained therein, and we encourage you to read the privacy statements of any linked third party. If you have any questions about how these Third-Party Services use your personal information, you should contact them directly.
DATA STORAGE AND HOW FILLOUT PROTECTS YOUR INFORMATION
Fillout stores basic End User data on our servers including name and email. Payments are not always required by End Users. If an End User makes a purchase and a payment is required, then payment information is processed and stored by our partners or service providers.
Fillout employs physical, electronic, and managerial control procedures to safeguard and help prevent unauthorized access to your information. We choose these safeguards based on the sensitivity of the information that we collect, process and store and the current state of technology. Our outsourced service providers who support our operations are also vetted to ensure that they too have the appropriate organizational and technical measures in place to protect your information.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee the security of your information transmitted to the Services. Any transmission of information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Services. In the event that there is breach in the information that we hold, we shall notify of such breach via email or via notice on the Services.
QUESTIONS AND COMMENTS
Restly, Inc., d.b.a. Fillout
Attn: Privacy Team
1210 S Indiana Ave. Unit 1817
Chicago, IL 60605.
REPRESENTATION FOR DATA SUBJECTS IN THE EU
We value your privacy and your rights as a data subject and have therefore appointed Prighter as our privacy representative and your point of contact in the EU.
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter or make use of your data subject rights, please visit https://prighter.com/q/11880772674
Accessing and Deleting Your Data
If you would like to access a copy of your data, you may submit a request via email at firstname.lastname@example.org We will provide you with the requested information within a reasonable time frame, in compliance with applicable laws.
Should you wish to delete your account data, please send an email to email@example.com.
Fillout™ Google APIs Limited Use Disclosure
Effective Date: Sep 4th, 2023
Fillout's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.