1. Introduction to the Privacy Policy and What It Covers

H2K, Inc. (“H2K”) knows that you care about how your corporate and personal information is used and shared - and we take your privacy seriously. This privacy policy ("Privacy Policy") covers H2K’s treatment of personally identifiable information ("Personal Information") and enterprise information ("Enterprise Information") (such as: CRM data, files, email/calendar information, and contacts) that you submit, or H2K otherwise gathers, when you access or use the Service. Together, Personal Information and Enterprise Information will be referred to as "Information".

By using the www.h2klabs.com website ("Site") or any of our applications: Insightify (the "Service") you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you consent that we will collect, use, and share your information as set forth below. The use of information collected through our service shall be limited to the sole purpose of providing the service for which your organization (H2K’s “Client”) has engaged H2K. Specific services offered are governed by the H2K Master Service Agreement and business terms for the items purchased by the Client per the Order Agreement.

Remember that your use of H2K’s Services is at all times subject to our Master Service Agreement, which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Use.

This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services. “Personal Data” means any information that identifies or relates to a particular individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations. This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage.

2. Sources of Personal Data

We collect Personal Data about you from:

You:

  • when you provide such information directly to us, and
  • when Personal Data about you is automatically collected in connection with your use of our Services.

Our subsidiaries and affiliates (together, “Affiliates”), when they provide us with Personal Data about you.

Third parties, when they provide us with Personal Data about you (“Third Parties”). Third Parties that share your Personal Data with us include:

  • Service providers. For example, H2K links to other services, such as Gmail (as described in more detail in the section below titled “Google Services”) and HubSpot. H2K does not access any information from these third-party services without your authorization, or by the authorization of your organization. You grant H2K this authorization when you connect these services to H2K, or when your organization's IT team authorizes these connections on your behalf. To opt out of connecting to these services, contact H2K at support@clari.com.
  • Social media. The Site may use social media features, such as the Facebook ‘like’ button (“Social Media Features”). These features may collect your IP address and which page you are visiting, and may set a cookie to enable the feature to function properly. You may be given the option by such Social Media Features to post information about your activities on H2K’s site to a profile page of yours that is provided by a third party Social Media network in order to share with others within your network. Social Media Features are either hosted by a third party or hosted directly on H2K’s site. Your interactions with these features are governed by the privacy policy of the company providing the relevant Social Media Features.
  • Advertising partners. We receive information about you from some of our service providers who assist us with marketing or promotional services related to how you interact with our websites, applications, products, services, advertisements or communications.

2.1 Google Services

Certain features or functions of the Service may require H2K to access your Google Gmail for Business account and certain data in such account via Google’s Gmail ‘Application Programming Interface’ (“API”). We will only do this with your consent (for example, if you or the Gmail administrator in your organization authorizes H2K to connect to Gmail, you are granting such consent). Specific restrictions on our use of that data are set forth below. To the extent these terms differ or conflict with any other terms of this Privacy Policy, this Privacy Policy controls.

H2K requires read-only access to your Business Gmail account. By authorizing H2K to connect to your account, you are giving H2K read-only access (gmail.readonly) to all email content in your account as defined by Google’s Gmail API.

H2K collects email and calendar metadata for the sole business-related use of the user and H2K’s Client. The following data is stored:

  • Gmail fields (Sender, Recipient, Date, Time, Subject, Attachment Name)
  • GCalendar fields (Meeting Organizer, Guests, Date, Time, Meeting Title, Attachment Name)

The data collected is used by H2K to provide you and your business with visibility into sales opportunity activities.

We may also use the data (i) if we reasonably believe such use is required by any law, regulation, or government body or court, (ii) as necessary to help prevent a security threat to the Service, and (iii) to help internally improve the Service.

H2K will not sell your data or use it for serving advertisements.

The data obtained is subject to these additional restrictions:

  • H2K will not transfer the data to others unless (i) doing so is necessary to comply with any law, regulation, or government body or court, or (ii) as part of a merger, acquisition, or sale of H2K’s assets.
  • H2K will not use this Gmail data for serving advertisements.
  • H2K will not sell your data.
  • The Service will not allow humans to read this data unless necessary to comply with applicable laws or regulations and for occasional support purposes.
  • H2K’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

3. Categories of Personal Data We Collect

The following chart details the categories of Personal Data that we collect and have collected over the past twelve (12) months. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal DataPersonal Data CollectedWhat is the source of this Personal Data?APersonal identifiersReal name Internet Protocol address Email address Metadata of emails and calendars associated with sales opportunities (specifically, the following fields: Sender, Recipient, Date, Time, Subject and Attachment Name).You / Third PartiesBCustomer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))Real name Internet Protocol address Email address Metadata of emails and calendars associated with sales opportunities (specifically, the following fields: Recipient, Date, Time, Subject and Attachment Name).You / Third PartiesCInternet other similar network activity informationInteractions with a website, application or advertisement.You / Affiliates / Third PartiesDGeolocation dataCity, State and Country for purposes of data aggregation.

The following sections provide additional information about how we collect your Personal Data.

3.1 Information Collected Automatically

The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs, and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser and tell us how and when you visit and use our Services, to analyze trends, learn about our user base and operate and improve our Services.

You can decide whether or not to accept Cookies. To find out more about what cookies we use, your choices and further information – please refer to our Cookie Policy.

4. How We Use Your Personal Data

We process Personal Data to operate, improve, understand and personalize our Services. We use Personal Data for the following purposes:

  • To operate and maintain the Service (such as, for the purposes of fixing malfunctions, testing our security systems, etc.).
  • To provide you with the features, functions and benefits of the Service.
  • To enhance, improve and further develop the Service (such as, creating new features or functions, refining the user experience, increasing Service technical performance, etc.).
  • We will use your contact information to provide you with notices related to your use of the Service.
  • We will use your contact information (such as, your email address) to provide you with training and emails with relevant product information. You can opt-out of receiving these emails - but in such case you may not receive the full benefit of the Service. Opting-out can be done by clicking the "manage email settings" link at the bottom of every email.
  • To help personalize the Service experience for you (such as, remembering your information so you will not have to enter it each time you use the Service).
  • To comply with our legal or contractual obligations, resolve disputes, and enforce our Terms of Use.
  • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
  • For the other purposes referenced in the "How We Share Your Personal Data" section below.
  • And for any other business purpose stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act (the “CCPA”)

We disclose your Personal Data to the following categories of service providers and other parties:

  • Service providers (a full list of which can be found here), including:  Hosting and other technology and communications providers, Ad networks, Security and fraud prevention companies and Analytics providers.
  • Staff augmentation and contract personnel.
  • Our Affiliates.
  • Parties who acquire your Personal Data through an acquisition or other change of control. In some cases, we may choose to buy or sell assets. In these types of transactions, customer information is typically one of the business assets that are transferred. Moreover, if H2K, or substantially all of its assets were acquired, or in the unlikely event that H2K goes out of business or enters bankruptcy, customer information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of H2K may continue to use your Information as set forth in this Privacy Policy.
  • Other parties at your direction.
  • Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services).
  • Third-party business partners who you access through the Services.
  • Other parties authorized by you.

Over the past twelve months, we have disclosed the following categories of your Personal Data to service providers or other parties for the business purposes listed above

  1. A. Personal identifiers.
  2. B. Customer records identified by state law.
  3. C. Internet or other similar network activity information.
  4. D. Geolocation data.

4.1 Sales of Personal Data

We have never sold your Personal Data.

5. Data Security and Retention

H2K takes robust information security measures to protect your Information and to limit the risk that it will be accessed without authorization, including use of certain industry standard technologies and practices. We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once it is received. That said, we cannot guarantee the security of such Information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. No security system is perfect - so your use of the Service is at your own risk.

If we learn of a security systems breach, then we may attempt to notify you via email, phone, physical mail, or by a posting on your Service account page - so that you can take appropriate protective steps. Pursuant to our Terms of Service you have consented to receive such notice by electronic means (provided that such consent is void where prohibited by applicable law). To receive a free written notice of a security breach, or if you have any questions about the security of the Service, please contact us at support@clari.com.

In addition to the security measures referenced above, your Service account is protected by a password for your privacy and security. You must prevent unauthorized access to your account and information by selecting and protecting your password appropriately and limiting access to your computer or device and browser by signing off after you have finished accessing your account.

6. Personal Data of Children

As noted in the Terms of Use, we do not knowingly collect or solicit Personal Data from children under 16; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at support@clari.com.

7. Your Rights and Control Over Your Data

7.1 Editing Your Profile

Upon request, H2K will provide you with information about whether we hold, or process on behalf of a third party, any of your personal information. If you wish to access, correct, or request deletion of your personal information, fill out this form and a member of the Privacy Team will respond to you. H2K has no direct relationship with the individuals whose personal data it processes within its Service. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to H2K’s Client (the data controller). If the Client requests H2K to remove the data, we will respond to their request within 30 days. If as an individual, you wish to identify the specific Client who is acting as the data controller of your Information, please contact privacy@clari.com and we will provide their contact information subject to H2K receiving approval of release of that information from the data controller.

7.2 Deleting Your Account

Deletion of your account is subject to the "Limitations on Deletion" section below, when you request us to delete your account for the Service, your data may be permanently deleted from our servers and access to your account will be disabled. We may retain your information for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes and enforce our agreements.

H2K will retain personal data we process on behalf of our Clients for as long as needed to provide services to our Client. H2K will retain and use this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

7.3 Limitations on Deletion

In addition, copies of your information may remain viewable elsewhere to the extent it has been publicly published by you or otherwise shared by you with others (such as your User Submissions).

We may also indefinitely retain and use any aggregated data derived from or incorporating your Information after you update or delete it, but not in a manner that would identify you personally.

We may also retain Information collected by Third Party usage tracking services in aggregate form, for the purposes of maintaining historical information on usage of our services.

We may also retain your Information to the extent required to comply with (or we deem it reasonable in light of) any laws or regulations.

H2K has no direct relationship with the individuals whose personal data it processes within its Service. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to H2K’s Client (the data controller). If the Client requests H2K to remove the data, we will respond to their request within 30 days. If as an individual, you wish to identify the specific Client who is acting as the data controller of your Information, please contact privacy@clari.com and we will provide their contact information subject to H2K receiving approval of release of that information from the data controller.

7.4 Choice

We partner with a third party to display advertising on our website or to manage our advertising on other sites. Our third party partner may use cookies or similar technologies in order to provide you advertising based upon your browsing activities and interests. If you wish to opt out of interest-based advertising, or if located in the European Union, fill out the form in our subscription center. Please note you will continue to receive generic ads.

You may sign-up to receive email or newsletter or other communications from us. If you would like to discontinue receiving this information, you may update your email preferences by using the "Unsubscribe" link found in emails we send to you or by clicking filling out the form in our subscription center.

We collect information for our Clients, if you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the client that you interact with directly

7.5 State-Specific Privacy Rights

7.5.1 California Resident Rights

Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Data to third parties for such third parties' direct marketing purposes. In order to submit such a request, please fill out the form in our subscription center.

If you are a California resident, you also have the rights pursuant to the CCPA, as outlined in this section. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of Personal Data shall control to the extent of such conflict. If you would like to exercise those rights, please fill out this form. If you have any questions about this section, you can contact us at privacy@clari.com.

7.5.2 Access

You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information:

  • The categories of Personal Data that we have collected about you.
  • The categories of sources from which that Personal Data was collected.
  • The business or commercial purpose for collecting or selling your Personal Data.
  • The categories of third parties with whom we have shared your Personal Data.
  • The specific pieces of Personal Data that we have collected about you.

If we have disclosed your Personal Data for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient.

7.5.3 Deletion

You have the right to request that we delete the Personal Data that we have collected from you. Under the CCPA, this right is subject to certain exceptions: for example, we may need to retain your Personal Data to provide you with the Services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

7.5.4 Exercising Your Rights

To exercise the rights described above, please fill out this form. Ensure that you (1) provide sufficient information to allow us to verify that you are the person about whom we have collected Personal Data (for example, providing us your enterprise email address used to register for the Services), and (2) describe your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify you and complete your request.

We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

You may submit a Valid Request using the following methods:

  • Submit a request with this form
  • Call us at: 941-271-4915
  • Email us at: privacy@clari.com

7.5.5 We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA. However, we may offer different tiers of our Services as allowed by applicable data privacy laws (including the CCPA) with varying prices, rates, or levels of quality of the goods or services you receive related to the value of Personal Data that we receive from you.

7.5.6 Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by filling out the form in our subscription center or contacting us at privacy@clari.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account.

7.5.7 European Union Data Subject Rights

If you are located in the EU, United Kingdom, Lichtenstein, Norway, or Iceland, you may have additional rights under the EU General Data Protection Regulation (the “GDPR”). For more information about H2K’s compliance with GDPR, please visit our page dedicated to GDPR.

8. Changes to this Privacy Policy

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well, but we will alert you to changes by placing a notice on the www.h2klabs.com website, by sending you an email, and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.

9. Contact H2K About Your Privacy

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data, your choices and rights regarding such use, please do not hesitate to contact us at:

941-271-4915

www.h2klabs.com

privacy@clari.com

1358 Fruitville Road, Suite 209 Sarasota, FL 34236