fechar
fechar

Syndigo Enterprise Data Suite (EDS) [MDM & PIM] Privacy Notice

Last updated: March 20, 2025

Introdução e Escopo

A Syndigo LLC, incluindo suas subsidiárias e afiliadas ("Syndigo", "nós", "nos", "nossos") leva muito a sério a proteção das suas informações de identificação pessoal ("Dados Pessoais").

We collect and process your Personal Data when providing you with access to and use of Enterprise Data Suite (EDS), such as the Master Data Management (MDM)/Product Information Management (PIM) solutions (the “Services”). This Privacy Notice (the “Notice”) gives you information about what Personal Data we process to provide the Services. When we refer to “you”, we mean the end-users of our Services.

In connection with the Services and for the purposes described in this Notice, we act as a storage and service provider. What this means is that we process your Personal Data at our customers’ request to provide you with access to and use of the Services.

Este aviso não se aplica a dados pessoais coletados por outros meios ou processados para outros fins, como dados pessoais que recebemos diretamente por meio do próprio site público da Syndigo (www.staging-syndigocom.kinsta.cloud). Dados pessoais que processamos para fins analíticos a fim de compreender os padrões de utilização e melhorar a usabilidade, dados pessoais que processamos para prestar-lhe apoio ao cliente, dados pessoais processados no contexto da Universidade Syndigo ou como parte do nosso trabalho de vendas e marketing, ou dados pessoais dos nossos funcionários. Nesses contextos, atuamos como controladores e nossa política geral de privacidade se aplica.

Controllership

In the context of this Notice, we act as a “data processor” or “service provider”. This means that our customers determine the type of Personal Data they provide to us to process on their behalf and what Syndigo must do with it. We typically have no direct relationship with the individuals whose Personal Data we receive from our customers.

Basis of Processing

Within the scope of this Notice, we process Personal Data based on the documented instructions of our customers. To learn about our customers’ lawful bases for processing your Personal Data, please read their privacy notices.

Como Recebemos Dados Pessoais

Recebemos os seus Dados Pessoais de duas maneiras:

1. Nossos clientes (inclusive seus funcionários, prestadores de serviços e outros representantes da empresa) nos enviam essas informações;

2. The Services record your actions while you use the Services.

Categories of Personal Data

We process the following types of Personal Data about you:

  • Identificadores: Nome de usuário para acessar os serviços;
  • Biographical information: First and last name;
  • EDS application role (e.g., Administrator or regular user);
  • Contact information: email address.
  • Company name (tenant).

Propósitos de processamento

We process your Personal Data for the following purposes:

1. Permitir o acesso e a utilização dos Serviços, incluindo a autenticação do usuário

2. Maintaining a log of actions performed by each user for customer auditing purposes.

Data Retention

We retain Personal Data for as long as instructed by the respective customer (who typically acts as a controller). In the absence of any instruction by the customer, Personal Data used for a project shall be purged once the project is complete, including from backups. As a general rule, we will delete all Personal Data associated with EDS end-users within forty-five days from the day the account with our customer was cancelled.  

Sharing Personal Data with Third Parties

Compartilhamos seus dados pessoais com nossas subsidiárias e afiliadas, bem como com nossos provedores de serviços, que processam seus dados pessoais em nosso nome e que concordam em usar esses dados pessoais somente para nos ajudar na prestação de nossos Serviços ou conforme exigido por lei. Em particular, partilhamos dados pessoais da seguinte forma:

1. Microsoft Ireland Operations, Ltd. (Ireland): They provide hosting services (Azure Cloud) for EDS.

2. Okta, Inc. (antiga Auth0) (EUA): Oferecem uma ferramenta para configurar o Single Sign On (SSO) para EDS até que nosso cliente mude para sua própria ferramenta.

Additionally, even if customer support is not within the scope of this Notice, please note that employees from other Syndigo entities, namely from Riversand Technologies Europe AG (Switzerland) and Riversand Technologies India Private Limited (India) may process Personal Data to provide you with customer support. These transfers take place in accordance with Syndigo’s Intra Group Data Transfer Agreement, which includes safeguards such as the Standard Contractual Clauses (also known as the “SCCs”) approved by the European Commission under Article 46.2 of the GDPR.

International Transfers of Personal Data

A Syndigo LLC está sediada nos EUA e nossas afiliadas estão localizadas no Reino Unido, na Índia e na Suíça. Nossos provedores de serviços operam globalmente, mas armazenam dados nos EUA e na Irlanda. Isso significa que seus dados pessoais são armazenados principalmente nos EUA por nós e nossos provedores de serviços, mas também são processados no Reino Unido, na Irlanda, na Índia e na Suíça.

For individuals whose Personal Data is safeguarded by data protection laws in the EU or UK: Before transferring your Personal Data from these regions to third parties outside the European Economic Area or the UK, we ensure that there are adequate levels of protection in place for your Personal Data as follows:

  • When we transfer data from these regions to UK, Ireland, or Switzerland, we do it in reliance on the adequacy decision for these regions.
  • In cases where we transfer your Personal Data from these regions to third parties in countries which are not recognized as providing an adequate level of protection to Personal Data, we transfer Personal Data when there are appropriate safeguards in place. These safeguards include the Data Privacy Framework, the EU 2021 SCCs, UK International Transfer Addendum, UK International Data Transfer Agreement, and any other approved data transfer mechanisms.

For individuals whose Personal Data is safeguarded by the Data Privacy Framework: Before sending your Personal Data to a third party, we will do one of two things:

  • Seek your consent; or
  • Exija privacidade e segurança: Garantiremos que terceiros mantenham o mesmo nível de privacidade e segurança dos seus dados que nós. Somos responsáveis pela proteção dos seus dados pessoais quando os transferimos para terceiros, exceto se pudermos provar que não somos responsáveis por um evento que leve a qualquer processamento não autorizado ou indevido. Podemos enviar os dados para um país, território ou setor dentro de um país reconhecido por oferecer o mesmo nível de proteção de dados pessoais que o país de origem ou o quadro de privacidade de dados, ou usar salvaguardas como a Data Privacy Framework (conforme definido abaixo) ou as Cláusulas Contratuais Padrão (SCCs) com os ajustes necessários para transferências do Reino Unido ou da Suíça, ou utilizar instrumentos de transferência específicos, como o UK International Data Transfer Agreement.

We are accountable and liable for the protection of your Personal Data when we transfer it to others except when we can prove that we are not responsible for an event that leads to any unauthorized or improper processing.

Other Disclosures of Your Personal Data

We may disclose your Personal Data to the extent required by law, or if we have a good-faith belief that we need to disclose it to comply with official investigations or legal proceedings (whether initiated by governmental/law enforcement officials or private parties). We may also disclose your Personal Data if we sell or transfer all or some of our company’s business interests, assets, or both, or in connection with a corporate restructuring. Finally, we may disclose your Personal Data to our subsidiaries or affiliates for business purposes, if necessary and as described in the section above.

We reserve the right to use aggregated, anonymous data about individuals whose Personal Data we process for any legal business purpose. Such data does not include any Personal Data. The purposes may include analyzing usage trends or seeking compatible advertisers, sponsors, and customers.

If we must disclose your Personal Data to comply with official investigation or legal processing initiated by governmental and/or law enforcement officials, we may not be able to ensure that such recipients of your Personal Data will maintain the privacy and security of your Personal Data.

Cookies

Syndigo does not use cookies to provide the Services. To learn about the use of cookies in relation to our website www.staging-syndigocom.kinsta.cloud, please review our Cookie Notice.

Data Integrity & Security

Syndigo has implemented and will maintain technical, administrative, and physical measures that are reasonably designed to help protect Personal Data from unauthorized processing such as unauthorized access, disclosure, alteration, or destruction.

Risk of Harm

Whenever Personal Data is collected and processed, there is always a slight risk that the Personal Data may be breached, misused, or otherwise result in a harm to you. However, we take several measures to ensure that this risk is mitigated as much as possible. These measures include limiting the Personal Data about you that we collect and process to solely what is necessary, not collecting sensitive Personal Data about you, and implementing appropriate security measures, as described in this Notice.

Your Privacy Rights

Caso processemos os seus dados pessoais, você poderá ter o direito de solicitar acesso a esses dados pessoais (ou de atualizá-los, corrigi-los ou excluí-los). Você também pode ter o direito de solicitar que limitemos o processamento desses dados pessoais, bem como o direito de se opor ao processamento desses dados pessoais. Você também pode ter o direito à portabilidade de dados.

Please note that requests should generally be sent directly to the Syndigo customer who provided your Personal Data to us. Syndigo has limited rights to access Personal Data our customers submit to us. If sending the request directly to the Syndigo customer is not possible for any reason and you decide to contact us with such a request, please provide the name of the Syndigo customer who submitted your Personal Data to us. We will forward your request to that customer and provide any needed assistance as they respond to your request.

In this section, we also acknowledge the right of EU, UK and Swiss individuals to access their Personal Data pursuant to the Data Privacy Framework (as defined below) and will grant individuals reasonable access to Personal Data we received pursuant to the Data Privacy Framework Principles when instructed by our customers. In addition, we will take reasonable steps to permit individuals to correct, amend, or delete such information that is demonstrated to be inaccurate or processed in violation of the Data Privacy Framework Principles. Additionally, if we have received your Personal Data in reliance on the Data Privacy Framework, you may also have the right to opt out of having your Personal Data shared with third parties and to revoke your consent to our sharing your Personal Data with third parties. You may also have the right to opt out if your Personal Data is used for any purpose that is materially different from the purpose(s) for which it was originally collected or which you originally authorized. An individual may request to access their Personal Data, or otherwise correct, amend, delete, withdraw their consent or limit the processing of their Personal Data in line with the Data Privacy Framework Principles by contacting our customer.

Estrutura de Proteção de Dados UE-EUA e Suíça-EUA e Extensão para o Reino Unido

With respect to Personal Data processed in the scope of this Notice, Syndigo LLC complies with the EU-U.S. Data Privacy Framework, its UK Extension, and Swiss-U.S. Data Privacy Framework (the “Data Privacy Framework” or “DPF”) as adopted and put forward by the U.S. Department of Commerce regarding the processing of Personal Data. Syndigo LLC commits to upholding and has certified to the Department of Commerce that it adheres to the Data Privacy Framework Principles with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Syndigo LLC has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Notice and the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern.

To learn more about the Data Privacy Framework, and to view Syndigo LLC’s certification, please visit https://www.dataprivacyframework.gov/s/ and https://www.dataprivacyframework.gov/s/participant-search (search for Syndigo LLC), respectively.

Supervisão Regulatória dos EUA

A Syndigo LLC está sujeita aos poderes de investigação e fiscalização da comissão federal de comércio dos Estados Unidos.

Dispute Resolution

Where a privacy complaint or dispute cannot be resolved through Syndigo’s internal processes, Syndigo has agreed to participate in the VeraSafe Data Privacy Framework Procedure. Subject to the terms of the VeraSafe Data Privacy Framework Dispute Resolution Procedure, VeraSafe will provide appropriate recourse free of charge to you. To file a complaint with VeraSafe and participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure, please submit the required information here: https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Syndigo LLC commits to cooperate and comply with the advice of the panel established by the EU data protection authorities (“DPAs”) and the UK Information Commissioner’s Office (“ICO”) and the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.

Binding Arbitration

If your dispute or complaint cannot be resolved by us, nor through the dispute resolution program established by VeraSafe, you may have the right to require that we enter into binding arbitration with you pursuant to the Data Privacy Framework’s Recourse, Enforcement and Liability Principle and Annex I of the Data Privacy Framework.

Privacy of Children

We do not knowingly collect Personal Data from anyone under the age of 13. In the event that we learn that we process Personal Data from a child under the age of 13, we will delete the Personal Data we have stored as quickly as possible. If you believe that we might have any Personal Data from or about a child under the age of 13, please contact us or the customer that has provided the child’s information to us.

Changes to this Notice

If we make any material change to this Notice, we will post the revised Notice to this web page. We will also update the “Last updated” date. By continuing to use the Services after we post any of these changes, you accept the modified Notice.

In our latest update as of March 06, 2025 , we implemented the following changes:

We have clarified your rights under the Data Privacy Framework and what Syndigo entity has certified under the Data Privacy Framework.

Fale conosco

Caso você tenha alguma dúvida sobre este Aviso ou sobre como tratamos seus dados pessoais, entre em contato conosco por e-mail em privacy@syndigo.com ou pelo correio em:

Syndigo LLC
Attn: Debra Osborn, Senior Counsel
141 W. Jackson Blvd., Ste 1220
Chicago, IL 60604
United States

Aguarde nossa resposta em até quatro semanas.

European Union Representative

We have appointed VeraSafe as our representative in the EU for data protection matters. While you may also contact us, VeraSafe can be contacted on matters related to the processing of Personal Data. To contact VeraSafe, please use this contact form: https://verasafe.com/public-resources/contact-data-protection-representative or via telephone at: +420 228 881 031.

Alternatively, VeraSafe can be contacted at: VeraSafe Ireland Ltd
Unit 3D North Point House
North Point Business Park
New Mallow Road
Cork T23AT2P
Ireland

United Kingdom Representative

Alternatively, VeraSafe can be contacted at: VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL
United Kingdom

Data Protection Officer

We have appointed VeraSafe as our Data Protection Officer (“DPO”). While you may contact us directly, VeraSafe can also be contacted on matters related to the processing of Personal Data. VeraSafe’s contact details are:

VeraSafe, LLC
100 M Street S.E., Suite 600
Washington, D.C. 20003 USA
Email: experts@verasafe.com
Web: https://www.verasafe.com/about-verasafe/contact-us/