Privacy Policy for Onit Services
(including Privacy Shield)
Last Updated: March 29, 2021.
Please note that this privacy policy will be updated on a regular basis to reflect any changes in the way we handle personal data or any changes in applicable laws.
At Onit, we know that your privacy is of the utmost importance to you. Accordingly, we treat your information confidentially and are committed to protecting your privacy and your personally identifiable information (“Personally Identifiable Information”).
Onit provides software as a service to its customers (“Services”) to help our customer automate a variety of business processes and workflows.
For purposes of this Privacy Policy for Services:
- “Personal Information” means any information that (i) is transferred from the European Union or the United Kingdom to Onit in the United States; (ii) is about an identified or identifiable individual; and (iii) is recorded in any form.
- “Data Controller” means an entity that alone or jointly with others determines the purposes and the means of the processing of Personal Information.
- “Data Processor” means an entity that processes Personal Information on behalf of a Data Controller in accordance with the Data Controller’s instructions.
As part of Onit’s Web-based applications, Onit’s customers (and their designees, including other service providers to such customers) are permitted to submit electronic data and information, including personal data, to Onit’s servers. In this context, Onit acts as a data processor and does not determine how its customers’ data is utilized in Onit’s servers and its customers are the Data Controllers. Onit does not choose or determine the types of data that are submitted to Onit’s servers, and any access to or use of such data by Onit is in connection with completing the contractual obligations of Onit, as data processor, to its customers. As part of Onit’s professional services operations, Onit processes data and information, including personal data, on behalf of its customers. In this context, Onit acts as a data processor on behalf of its customers and its customers are the Data Controllers.
Where Onit acts as a data processor, Onit does not have a direct relationship with individuals whose Personal Information Onit processes in the US. In these circumstances, Onit’s customers are responsible for providing the required notice and choice to individuals.
Privacy Shield Policy
Onit complies with the EU-U.S. Privacy Shield Framework (Privacy Shield) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Information (as defined below) within the scope of the Onit’s Privacy Shield certification and transferred from the European Union and the United Kingdom , as applicable to the United States. Onit has self-certified to the Department of Commerce that it adheres to the Privacy Shield Principles with respect to such Personal Information. While this certification, in and of itself, is not considered by the EU authorities to provide an adequate level of protection, Onit nonetheless considers that it provides protection with regard to the processing of personal data and transparency with regard to our data processing standards. If there is any conflict between the terms in this Privacy Policy for Services and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/list.
In addition to adhering to this Privacy Policy, and other policies and procedures regarding the privacy of Personal Information that Onit has in place, when we transfer your Personal Information from the EU to other entities that are our vendors or subcontractors in other countries, we require the recipient entity to enter into a contract regarding the use and processing of that information which incorporates the SCCs and necessary supplemental measures.
In compliance with applicable law, as well as the Privacy Shield Principles, Onit commits to resolve complaints about our collection or use of your personal information. See the section below titled How to Access your Personal Information And Enforcement.
Personal Information Collected by Onit
Content and information submitted by a user is controlled by Onit’s customers, as described above. Here are some examples of content and information collected by Onit (but please note, these are only examples and there may be others): first and last name, email address, phone number, other contact information, company you work for, business unit you belong to, and other types of information.
Onit also collects Non-Personally Identifiable Information from users of the services, including without limitation: Internet protocol addresses, profile information, aggregate User-data, demographic information, geographical information, browser types, operating system types, and usage statistics. This Non-Personally Identifiable Information is used to manage the services, track services usage, and improve the services. This Non-Personally Identifiable Information may be shared with third-parties to provide more relevant services and third party content to users. User IP addresses may also be recorded for security and monitoring purposes.
How does Onit Use your Personal Information?
Personal Information is used by Onit for the following purposes:
- to send you requested information on our products and services;
- to provide you with information about new features, products and services;
- to provide support to you in connection with your use of the Onit family of products, including notices of system downtime;
- to provide the services, products and support to our customers;
- to collect feedback on your use of our products and services;
- to help us improve our products and services or develop new products or services; or
- to comply with applicable laws or regulations.
Transfer of Personal Information to Other Parties
Onit does not sell any Personal Information to third parties. Onit does share Personal Information in the following circumstances:
Business Partners of our Customers
Onit discloses Personal Information to business partners of our customers as directed by our customers, or where we believe it is necessary to provide a service which a customer has requested, or as otherwise authorized or directed by you. Examples include:
- integrations to third parties which host systems for Onit customers, such as AdobeSign and Salesforce.
- if our customer is a legal department, their vendors receive information related to e-billing; or
- if our customer is a law firm or vendor, its billing information (including the names and rates of its employee) is shared with its customer.
Authorized Service Providers
Onit may disclose your Personal Information to its affiliates and service providers it has retained to perform services on its behalf as well as strategic alliance partners we are working with. We require service providers and strategic alliance partners to whom we disclose Personal Information and who are not subject to laws based on the European Union Data Protection Directive to either (i) subscribe to the Privacy Shield principles or (ii) contractually agree to provide at least the same level of protection for Personal Information as is required by the relevant Privacy Shield principles.
Legal Requirements and Business Transfers
Onit may disclose Personal Information (i) if we are required to do so by law or legal process, (ii) in response to law enforcement authority or other government official requests, (iii) in connection with an investigation of suspected or actual illegal activity or (iv) in the event that Onit is subject to a merger or acquisition to the new owner of the business. Disclosure may also be required for company audits or to investigate a complaint or security threat. When Onit discloses Personal Information to its third-parties as described above, we may be liable if these third parties process your personal information in a manner inconsistent with the Privacy Shield Principles and we are responsible for the event giving rise to the damage.
Security
Onit implements commercially reasonable security measures designed to protect your Personal Information.
How to Access your Personal Information And Enforcement
Onit reviews its compliance with this Privacy Policy for Services to verify that the assertions made in it are true and that the practices the Privacy Policy for Services contains are implemented correctly. Onit will investigate any breach of this Privacy Policy for Services that has been reported to Onit.
In circumstances where Onit acts as a Data Processor, individuals should submit any requests to access their Personal Information or complaints concerning the processing of their Personal Information to the Onit customer that originally collected their information in accordance with the customer’s relevant dispute resolution mechanism (if available). Onit will participate in the customer’s dispute resolution process at the request of the individual.
If the issue cannot be resolved through the customer’s internal dispute resolution mechanism, the individual may submit the request or complaint to Onit by emailing us at [email protected].
If our response does not address your concern, you can contact JAMs here (https://www.jamsadr.com/eu-us-privacy-shield), which provides an independent third-party dispute resolution body based in the United States. If neither Onit nor JAMs resolves your complaint, you may have the possibility to engage in binding arbitration through the Privacy Shield Panel. Also, Onit’s commitments under the Privacy Shield are subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Permitted and Required Uses and Disclosures That May Be Made Without Your Consent, Authorization, or Opportunity to Object
There are other circumstances in which we may have to use or disclose your protected Personally Identifiable Information, even without your consent or authorization. These situations include:
Disclosure Required By Law: We may use or disclose your Personally Identifiable Information to the extent that the use or disclosure is required by law. The use or disclosure will be made in compliance with the law and will be limited to the relevant requirements of the law. You will be notified, as required by law, of any such uses or disclosures.
Legal or Administrative Proceedings or Investigations: We may disclose Personally Identifiable Information in the course of any judicial or administrative proceeding or investigation, in response to an order of a court or administrative tribunal (to the extent such disclosure is expressly authorized), in certain conditions in response to a subpoena, discovery request or other lawful process or request.
Law Enforcement: We may disclose Personally Identifiable Information, so long as applicable legal requirements are met, for law enforcement purposes. These law enforcement purposes include requests: (1) pursuant to legal processes or as otherwise required by law; (2) for limited information for identification and location purposes; (3) pertaining to potential victims of a crime; (4) relating to suspicion that a death has occurred as a result of criminal conduct; (5) in the event that a crime occurs at Onit; or (6) relating to a medical emergency (not at Onit) and it is necessary to alert law enforcement regarding a potential crime.
Enforcement of Agreement: Consistent with applicable federal and state laws, we may disclose your Personally Identifiable Information to enforce this Agreement and to protect our rights herein.
Correcting/Updating or Removing Information
Users may request to modify or remove most of their Personally Identifiable Information at any time by contacting Onit at [email protected]. Removed information may persist in backup copies of the Website indefinitely, but such information will continue to be protected under the terms of this Privacy Policy.
Privacy Notice and Policy Subject to Change
From time to time we may make changes to our Privacy Policy, and we reserve the right to change our Privacy Policy at any time. If we make changes, we will post them on the Website. Unless stated otherwise, our current Privacy Policy applies to all Personally Identifiable Information. Your continued access or use of the Services after any such changes constitutes your acceptance of the new Privacy Policy.
Contact Us
Please notify us if you believe your privacy rights have been violated by us. We will not retaliate against you or you for the filing of such a complaint. You may reach our privacy contact at [email protected]. Our privacy contact can provide further information about this Privacy Policy and the policies and procedures set forth herein.