Last Updated: August 12, 2021
Risk Management Solutions, Inc. ("RMS", "we", "our", "us") is committed to protecting and respecting your privacy. We are a California corporation, with our principal office located at 7575 Gateway Boulevard, Suite 300, Newark, California 94560. This policy applies to www.rms.com and other websites ("Websites") owned and operated by RMS, and to the online services ("Services") available to our customers through certain restricted portions of our Websites.
If you are an RMS customer, you may have access to software or functions in restricted areas of our Websites that permit you to input information regarding your clients or insureds. The treatment of such information is governed by your (or your employer's) agreement with RMS permitting you to use the applicable software or functions. In addition to the terms of any agreement, it is your responsibility to ensure that you have the authority to input such information and that you are doing so in accordance with your (or your employer's) agreement with RMS and any applicable laws and regulations, including privacy and data protection laws and regulations.
Under the General Data Protection Regulation (“GDPR”), we act as a "Processor" for the Personal Data you provide to us through your use of our Services. We function as a “Controller” when we collect your Personal Data via our Websites, and when we send marketing materials or communications to potential or existing clients.
When you visit our Websites or use our Services, we may collect Personal Data as described below. "Personal Data" (also known as personal information) means any information that relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular data subject household.
In some cases, we will ask for your consent so that we may process your Personal Data. For example, we will request your consent before we collect your Personal Data for direct marketing purposes.
However, in other circumstances, data protection laws allow us to process your Personal Data without needing to obtain your consent. For example, we might process your Personal Data:
- To perform our contract obligations to you and your employees on whose behalf you have obtained the necessary consents, including providing you with our Services, fulfilling orders or requests you have made through the Website or Services, contacting you in relation to any issues with your orders or use of our Services, or where we need to provide your Personal Data to our service providers related to the provision of the Services.
- To comply with legal obligations, including laws, regulations, court orders or other legal processes.
- To pursue a legitimate interest, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of Personal Data. Legitimate interests may include:
- To communicate with you regarding the Website or Services, including to provide you with important notices regarding changes to our operations and to address and respond to your requests, inquiries, and complaints.
- To assist in the investigation of suspected illegal or wrongful activity, and to protect and defend our rights and property, or the rights or safety of third parties.
- To develop, provide, and improve our Websites and Services.
1. WHAT TYPES OF INFORMATION DOES RMS RECEIVE?
RMS receives Personal Data from you when you visit our Websites and Services. This might include information such as your name, e-mail address, mailing address, or telephone number that you submit to us via our “Contact Us” function, and other information that we automatically collect when you visit our Websites and use our Services, as described below.
The information you provide to RMS may include the following:
- Your login ID and password when you access and use the client area of a Website or Service limited to registered users.
- First and last name, email address, job title, phone number, company name, country and your specific questions or comments when you:
- register for an RMS event, such as a conference or webinar
- contact us to learn more about our products and services
- ask us a question or send feedback using RMS Contact Us function available on a Website
- provide feedback or reply to a blog post
- when our Website directs you to a third party's website to complete a transaction, such as a website that processes your registration and credit card information for an RMS event.
- First and last name, email address, mailing address, and phone number when you request fulfillment of an order from our Website
- First and last name, email address, resume or cv, phone number, location, referral source and any information provided in your cover letter and LinkedIn profile when you apply for a job via the "Careers" section of the Website.
We may also receive your Personal Data from third parties such as other users, advertising networks, data brokers or social media platforms.
When you visit our Websites or use our Services, we also automatically collect and store certain information, including your browser type your IP address or device ID, operating system, browser type, browsing behavior, including the pages you access on the Websites, or Services, clickstream data, the time spent on those pages, access dates and times, location data, and the page you visited before coming to our Website or Services, and demographic information.
We use this information to monitor, analyze and administer the Websites and Services, including to maintain the security of our Services, to provide you with support, determine applicable Services usage fees, report on utilization of our Services, assess Services compliance and performance commitments, and to better tailor them to your needs. On the Website, we also use this information to select content to display to you.
To collect this information, we use the following tracking technologies:
A pixel tag (also known as a "clear GIF" or "web beacon") is a tiny image – typically just one-pixel – that can be placed on a web page or in an email to you, to tell us when you have displayed that page or opened that email.
We use third parties to collect, track and analyze this information and statistical information from users, such as the user's browser type, operating system, browsing behavior and demographic information. We use this information for analytics, to select which content to display based on your network context, and for purposes of our remarketing.
Most browsers have settings that allow you to block certain types of cookies and also allow you to delete cookies. To learn more about browser cookies, including how to manage or delete them, look in the "Tools", "Help", "Settings", "Internet Options" or similar section of your web browser.
For more information about third-party advertisers and how to prevent them from using your information, or to opt out of certain tracking, visit the NAI’s consumer website at http://www.networkadvertising.org/choices or http://www.aboutads.info/choices/. If you choose to opt out using these tools, you need to opt out separately for each of your devices and for each web browser (such as Internet Explorer, Firefox or Safari) that you use on each device.
2. DO NOT TRACK
Some web browsers give the ability to prevent tracking of your online activity by setting a preference in your browser alerting websites you visit that you do not want them to track your online activities. This is referred to as a Do Not Track ("DNT") signal. This is different to blocking or deleting cookies, as browsers with an enabled DNT signal may still accept cookies.
Please note that our Websites and Services may not recognize or do not take action in response to DNT signals from your browser.
3. HOW DO WE USE THE INFORMATION WE COLLECT?
In general, we use your Personal Data to complete the transaction that you have requested from us. For example, we will use your Personal Data to:
- Deliver, maintain, monitor, protect and assess our Websites and Services and to enhance your experience;
- Communicate with you in response to or otherwise to fulfill your requests;
- Establish or verify your identity when you register for the Services;
- Deliver marketing to you regarding our products, services and events, which may also include delivery of research surveys, by way of emails or other communications;
- Match your information with other data or supplement your information with other data that we may obtain directly or through third-parties;
- Respond to you about your job application;
- Register you for an event which you have selected;
- Address the question or feedback which you have sent to us; and
4. WITH WHOM DO WE SHARE THE PERSONAL DATA WE RECEIVE ABOUT YOU?
RMS does not sell your Personal Data to anyone. Nor do we provide your Personal Data to non-RMS parties to market non-RMS products to you.
RMS will, however, share your Personal Data with the following categories of recipients:
- RMS employees, contractors and consultants (including employees, contractors and consultants of RMS subsidiaries and affiliated companies) who have a need to know your Personal Data to provide RMS services and information to you;
- Our third-party vendors, consultants and other service providers who assist RMS with the operation of the Websites and Services, including in our provision of marketing services, when they require access to such information to provide the services for us. This may include cloud computing companies, cloud communication platform as a service (PaaS), web analytics services, employment-related service providers, event registration and planning services, customer relationship management applications, marketing, research and advertising companies, social networking services and mailing and emailing services, hosting, analytics and search engine providers such as Google Analytics that assist us in the improvement and optimization of the Website.
When you submit a comment on one of our blog posts, your comments and any Personal Data that you include in that comment will be shared with other visitors to that Website.
5. WHERE DO WE STORE YOUR PERSONAL DATA?
The Websites and Services are hosted in the United States and your information will be transferred to, processed and stored in the United States, the EEA, the UK and Australia. It may also be processed by staff operating outside of your country, who work for us or one of our third-party service providers.
6. HOW DOES RMS PROTECT YOUR PERSONAL DATA?
RMS protects your Personal Data by maintaining commercially reasonable, industry standard physical, electronic and procedural safeguards. For example, we use computer safeguards such as firewalls and data encryption. In addition, we only allow employees to access Personal Data only when required to fulfill their job responsibilities. The Internet, however, is not perfectly secure, and we are not responsible for security incidents not reasonably foreseeable or reasonably within our control.
7. HOW LONG DO WE STORE YOUR PERSONAL DATA?
We will retain your Personal Data for as long as necessary to provide you with access to the Websites and Services or as long as legally permissible in accordance with applicable law, including as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, as well as to comply with applicable industry standards, and in accordance with disaster recovery procedures. As such, retention periods vary depending on the type of Personal Data and how it is used. For example, if you contact us via email we will keep your data for three years after such contact; and we will also retain the information we automatically collect when you visit our Website and Services for three years.
8. YOUR RIGHTS
In certain circumstances, when we are acting as a controller, you have rights related to the Personal Data we hold about you. Below is an outline of those rights and how to exercise those rights. Please note that we will require you to provide adequate proof of your identity before responding to any requests to exercise your rights. To exercise any of your rights, please email firstname.lastname@example.org. Please note that for each of the rights below we may have valid legal reasons to refuse your request. In such instances we will let you know if that is the case. In addition, the rules in your country may provide you with additional rights or may limit the rights noted below. In all cases, we will comply with the applicable laws.
- Access: You may have the right to know whether we process Personal Data about you, and if we do, to access data we hold about you and certain information about how we use it and who we share it with.
- Correction: You may have the right to require us to correct any Personal Data held about you that is inaccurate and have incomplete data completed.
- Erasure: Under certain circumstances, you may have the right to request that we erase the Personal Data we hold about you.
- Restriction of Processing to Storage Only: Under certain circumstances, you may have a right to require us to stop processing the Personal Data we hold about you other than for storage purposes.
- Objection to Processing: Under certain circumstances, you may have the right to object to our processing of data about you on grounds related to your particular situation, and we can be required to no longer process your Personal Data.
- Withdrawal of Consent: Where you have provided your consent to us processing your Personal Data, you can withdraw your consent at any time by emailing email@example.com.
- Objection to Marketing: At any time you have the right to object to our processing of data about you in order to send you promotions, special offers and other marketing materials, including where we build profiles for such purposes, and we will stop processing the data for that purpose. You can object to processing of your data for marketing purposes at any time by emailing firstname.lastname@example.org.
For California Residents:
California residents have certain rights with respect to their Personal Data, as described below. Before we may fulfill your requests, we are required by law to verify your identity in order to prevent unauthorized access to your data. This may require us to request that you provide us with certain data to utilize as part of our verification process.
Please note that your exercise of the above rights is subject to certain exemptions to safeguard the public interest (e.g., the prevention or detection of crime) and our interests (e.g., the maintenance of legal privilege). We will try to comply with your request as soon as reasonably practicable. Requests to exercise these rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and applicable law. Where required by applicable law, we will notify you if we reject your request and notify you of any reasons we are unable to honor your request.
We are required by law to provide you with details regarding your Personal Data and to that extent we have provided a summary below in addition to what is set out above in this Policy.
Categories of Personal Data we collect
When you participate in certain optional features, such as to register for an event, contact us to learn more, ask a question or send feedback or complete a transaction with one of our service providers we collect:
When you apply for a job via the Careers section of the Website we collect:
Categories of sources from which the Personal Data is collected
We collect the Personal Data directly from you and from third party marketing, social media, and analytics firms.
Business or commercial purpose for collecting or selling Personal Data
We collect your Personal Data for the following business purposes:
Categories of third parties with whom we share Personal Data
We share your Personal Data with advertising, marketing, social media and analytics partners to personalize our content and the advertising you see on this and other sites, and to understand how our Websites are used.
Specific pieces of Personal Data we have collected
9. SOCIAL MEDIA FEATURES AND WIDGETS
10. HOW CAN YOU CONTACT RMS ABOUT YOUR PERSONAL DATA?
Opting Out of Communications: From time to time you will receive an e-mail or other communication from us regarding RMS products, services or information which we believe to be of interest to you. If you are not interested in receiving this information, you may follow the instructions in the communication explaining how you may be removed from our distribution list. Alternatively, or if there are no instructions in the communication, you may send an e-mail to email@example.com requesting removal from our distribution list. We will endeavor to take prompt action to process your request.
Complaints: In the event that you wish to make a complaint about how we process your Personal Data, please contact us at firstname.lastname@example.org and we will endeavor to deal with your request as soon as possible. This is without prejudice to your right to raise a complaint with the appropriate data protection supervisory authority.
California Residents: If you are a resident of California, you may request certain information regarding our disclosure of personal data (if any) for marketing purposes. To make such a request, please contact us at email@example.com.