DIREQT INC.
GDPR PRIVACY ADDENDUM
Last revised: February 28, 2023
1. Introduction
This GDPR Privacy Addendum (the “GDPR Privacy Addendum”) supplements the information contained in our Privacy Policy (our “Privacy Policy”) and applies solely to the users of our Website who are located in the European Economic Area, the United Kingdom, or Switzerland. We adopt this GDPR Privacy Addendum to comply with the European Union’s General Data Protection Regulation, and any laws implementing the foregoing by any member states of the European Economic Area, the United Kingdom (including the UK Data Protection Act and the UK-GDPR), and or Switzerland (collectively, the “GDPR”). Unless otherwise defined in this GDPR Privacy Addendum, any terms defined in the GDPR or our Privacy Policy have the same meaning when used in this GDPR Privacy Addendum. When this GDPR Privacy Addendum is applicable to you, it takes precedence over anything contradictory in our Privacy Policy.
2. Data Controller, Data Protection Officer, and Representative
Direqt is the data controller of your Personal Data. Direqt has appointed a Data Protection Officer and a representative in the United Kingdom in compliance with the General Data Protection Regulation and the UK Data Protection Act and UK-GDPR. Direqt, its Data Protection Officer, or its representative may be contacted in any manner set forth below in the “Contact Information” Section of this GDPR Privacy Addendum.
3. Information We Collect About You and How We Collect It
The Personal Data we collect and the ways in which we collect it is described in our Privacy Policy.
The Personal Data we collect from you is required to enter into a contract with Direqt, for Direqt to perform under the contract, and to provide you with our products and services. If you refuse to provide such Personal Data or withdraw your consent to our processing of Personal Data (when appropriate), then in some cases we may not be able to enter into the contract or fulfill our obligations to you under it.
4. Lawful Basis for Processing Your Personal Data
The processing of your Personal Data is lawful only if it is permitted under the GDPR. We have a lawful basis for each of our processing activities (except when an exception applies as described below):
• Consent. By using our Website, you consent to our collection, use, and sharing of your Personal Data as described in our Privacy Policy and this GDPR Privacy Addendum. If you do not consent to the terms of our Privacy Policy and this GDPR Privacy Addendum, please do not use the Website.
• Legitimate Interests. We will process your Personal Data as necessary for our legitimate interests. Our legitimate interests are balanced against your interests and rights and freedoms and we do not process your Personal Data if your interests or rights and freedoms outweigh our legitimate interests. Our legitimate interests are to: facilitate communication between Direqt and you; detect and correct bugs and to improve our Website; safeguard our IT infrastructure and intellectual property; detect and prevent fraud and other crime; promote and market our business; and develop our product and services.
• To Fulfill Our Obligations to You under our Contract. We process your Personal Data in order to fulfill our obligations to you pursuant to our contract with you to deliver our goods and services to you, to the extent applicable.
• As Required by Law. We may also process your Personal Data when we are required or permitted to by law; to comply with government inspections, audits, and other valid requests from government or other public authorities; to respond to legal process such as subpoenas; or as necessary for us to protect our interests or otherwise pursue our legal rights and remedies (for instance, when necessary to prevent or detect fraud, attacks against our network, or other criminal and tortious activities), defend litigation, and manage complaints or claims.
5. Special Categories of Information
We do not ask you to provide, and we do not knowingly collect, any special categories of Personal Data from you.
6. Automated Decision Making
We do not currently use your Personal Data with any automated decision-making process or technologies including profiling, which may produce a legal effect concerning you or similarly significantly affect you. Any changes pertaining to the use of Personal Data with automated decision-making will be updated in this GDPR Privacy Addendum.
7. How We Use Your Information
We use your Personal Data as described in our Privacy Policy.
8. Disclosure of Your Information
We do not share or otherwise disclose your Personal Data for purposes other than to the entities and for the purposes described in our Privacy Policy.
9. Your Rights Regarding Your Information and Accessing and Correcting Your Information
The GDPR provides you with certain rights with regards to our processing of your Personal Data. These rights replace the similar rights provided in our Privacy Policy or are supplemental to such rights.
10. Consent to Processing of Personal Data In Other Countries Outside the European Economic Area or the United Kingdom
In order to provide our Website, products, and services to you, we may send and store your Personal Data outside of the EEA or the United Kingdom, including to the United States. Accordingly, your Personal Data may be transferred outside the country where you reside or are located, including to countries that may not or do not provide an equivalent level of protection for your Personal Data. Your information may be processed and stored in the United States and United States federal, state, and local governments, courts, or law enforcement or regulatory agencies may be able to obtain disclosure of your information through the laws of the United States. By using our Website, you represent that you have read and understood the above and hereby consent to the storage and processing of Personal Data outside the country where you reside or are located, including in the United States.
Your Personal Data is transferred by Direqt to another country only if it is required or permitted under the GDPR and provided that there are appropriate safeguards in place to protect your Personal Data. To ensure your Personal Data is treated in accordance with our Privacy Policy and this GDPR Privacy Addendum when we transfer it to a third party, Direqt uses Data Protection Agreements between Direqt and all other recipients of your data that include, where applicable, the standard contractual clauses adopted by the European Commission and/or the Information Commissioner’s Office in the United Kingdom (collectively, the “Standard Contractual Clauses”). The European Commission and the Information Commissioner’s Office in the United Kingdom have determined that the transfer of Personal Data pursuant to the Standard Contractual Clauses provides for an adequate level of protection of your Personal Data, however, the Standard Contractual Clauses may need to be supplemented in some cases with additional measures on a case-by-case basis after an analysis that such supplemental measures can provide you with an essentially equivalent level of protection as afforded in the EEA or the UK. When, as a result of this analysis, we believe this to be appropriate and necessary, the Standard Contractual Clauses have been supplemented in this way. Under these Standard Contractual Clauses, you have the same rights as if your Personal Data was not transferred to such third country. You may request a copy of the Data Protection Agreement by contacting us through the Contact Information below.
11. Data Retention Periods
Direqt will retain your Personal Data for the entire time that you keep your account open or until you request us to delete your Personal Data (subject to the above). After this period, we may retain your Personal Data for 3 years, or for any of the reasons listed below, whichever is longer:
12. Changes to This GDPR Privacy Addendum
We may change this GDPR Privacy Addendum at any time. It is our policy to post any changes we make to our GDPR Privacy Addendum on this page. If we make material changes to how we treat our users’ Personal Data, we will notify you through a notice on the Website home page. The date this GDPR Privacy Addendum was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and this GDPR Privacy Addendum to check for any changes.
13. Contact Information
If you have any questions, concerns, complaints, or suggestions regarding our Privacy Policy or this GDPR Privacy Addendum, have any requests related to your Personal Data described in the Privacy Policy or this GDPR Privacy Addendum, or otherwise need to contact us, you can do so at the contact information below or through the “Contact” page on our Website.
To Contact Direqt (Controller)
Direqt, Inc.
800 5th Ave, #101-326
Seattle, WA, 98104
United States
support@direqt.io
(206)-203-7331
To Contact Our Representative
DataRep
12 Northbrook Road.
Dublin. Ireland
info@datarep.com
To Contact Our Data Protection Officer
Email: dpo@direqt.ai