SOLINK ACCEPTABLE USE POLICY
Personal Information Description | Source |
Contact Information: such as name, company, address, ZIP/postal code, phone number, and e-mail address. | Directly from you Third Parties |
Electronic Identification Information: such as IP addresses, device identifier, cookies. | Automatic Collection |
Location Information: such as longitude, latitude, GPS | Automatic Collection |
Billing Information: such as account details, billing address, purchase order information. | Directly from you Third Parties |
End User Information, including Audio, Electronic, Visual, and similar information: captured through Solink’s CCTV or security cameras at its own premises, including end users’ image data such as end user height, weight, hair colour, eye colour, distinctive features. | Third Parties Automatic Collection |
Professional or employment-related information: such as your company name, work email address, title, and industry | Directly from you Third Parties |
Marketing information: such as your email address and contact preferences if you subscribe to our newsletter/marketing emails | Directly from you Third Parties |
Account/Administration Information: such as log-in credentials, your email address or username and password, administrator rights, employer, job title, location. | Directly from you Third Parties |
Telemetry Information: such as service usage data, metrics, product configuration. | Automatic Collection |
Purpose/Activity | Types of Personal Information | Lawful Basis (See section below for further descriptions of lawful basis) |
Transactional considerations: To complete transactions and send you related information, including purchase confirmations and invoices, to perform our contract with you. | Contact Information | Performance of a contract with you Legal obligation Legitimate Interest (including fulfilling our obligations under contract to you or otherwise in connection with the administration of our relationship). |
To Provide our Site and products/services to you: Research, develop, manage, protect and improve our Site and services. Provide you with information about the services that you have requested or purchased, and to provide you with more relevant content and service offerings on our Site. | Contact Information Electronic Identification Information Location Information Telemetry Information | Legitimate Interest |
Service-related communications: Advise you about any updates or changes to the services that may be of interest to you, including technical and other administrative communications or notifications about product or service updates. | Contact Information Electronic Identification Information Location Information | Legitimate Interest |
Advertising: To deliver personalized advertising and marketing campaigns to you based upon your activities and interests. | Electronic Identification Information Location Information | Consent |
Customer Relationship Management: To establish you as a customer on our systems, provide you with information on products or services that you have requested or purchased, to develop and maintain our customer relationship with you, and to communicate with you. | Contact Information Billing Information Account/Administration Information Telemetry Information | Performance of a contract with you Legitimate interests (including fulfilling our obligations under contract to you or otherwise in connection with the administration of our relationship). |
Security & Compliance: To detect security incidents and protect the security of our Site and services. To investigate and prevent fraudulent transactions, unauthorized access to the Site or services, and other illegal activities such as fraud and theft. To audit compliance with Solink’s policies and contractual obligations. | Electronic Identification Information Location Information Billing Information End User Information Account/Administration Information | Legitimate Interest Legal Obligation |
Marketing and Sales: To send you marketing and sales related communications about our products and services, including surveys, features, newsletters, promotions events, research or evaluations we think may be of interest to you. | Contact Information Electronic Identification Information | Legitimate Interest Consent |
Analytics & Reporting: To analyze, aggregate and prepare reports and recommendations based on data you provide to us through your use of the services or our Site. | Telemetry Information | Legitimate Interest |
Disputes and legal proceedings: To fulfill legal, regulatory and contractual obligations, including when cooperating with government authorities, courts and regulators in accordance with applicable law. | Contact Information Electronic Identification Information Location Information Billing Information End User Information Account/Administration Information Telemetry Information | Legitimate Interest (including to defend or pursue a dispute or legal proceeding). Legal obligation (including to retain and preserve documents and evidence that relate to the dispute or proceedings). |
Third Party Recipient | Personal Information |
Our group companies and affiliates |
|
Service providers and vendors |
|
Auditors, advisors, legal representatives and similar agents in connection with the advisory services they provide to us for legitimate business purposes |
|
Law enforcement bodies, regulatory or governmental agencies, and/or courts |
|
Name: | Customer as defined in the Agreement. |
Address: | As provided for in the Agreement. |
Contact person’s name, position and contact details: | As provided for in the Agreement |
Activities relevant to the data transferred under these Clauses: | As set out in the Agreement. |
Signature and date: | See execution page above. |
Role (controller/processor): | Controller |
Name: | Solink Corp. |
Address: | 390 March Rd, Ste 110, Ottawa, ON K2K 0G7, Canada |
Contact person’s name, position and contact details: | Jamie Greenberg, General Counsel at [email protected] |
Activities relevant to the data transferred under these Clauses: | As set out in the Agreement. |
Signature and date: | See execution page above. |
Role (controller/processor): | Processor |
Categories of data subjects whose personal data is transferred: | Customer Employees, Customer Administrators, General Public |
Categories of personal data transferred: |
Customer Employees
|
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: | Not applicable – sensitive data is not processed by Solink. |
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): | Continuous for the duration of the Agreement between Solink and Customer. |
Nature of the processing: | Solink provides a cloud-based video surveillance service, as further described in the Agreement. |
Purpose(s) of the data transfer and further processing: |
Personal Data shall be processed by Solink solely as necessary for the following purposes:
|
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: | For the duration of the Agreement between Solink and Customer. |
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: | As above. |
Identify the competent supervisory authority/ies in accordance (e.g. in accordance with EU SCC Clause 13) | As stated in Clause 5.2 above. |
Measure | Brief Overview |
Measures of pseudonymization and encryption of personal data |
When anonymization is required for long-term storage, Solink will provide Customers with the ability to blur data subjects while saving defined length clips to the cloud. Customer transactional data is stored on encrypted drives. |
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services |
Data is stored in multiple availability zones, and services are spread over multiple availability zones. For Confidentiality, least privilege access control is utilized through the RBAC matrix. For Integrity, data in motion are also encrypted. |
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | Data is backed up in an encrypted Backup Vault. |
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing |
Solink is SOC2 Type2 certified and follows best practices including scheduled vulnerability scans (internal & external), annual pen tests and CIS benchmarks for security configuration. Regular-annual SOC2 evaluation control effectiveness performed by independent/authorized third party audit. |
Measures for user identification and authorisation | Best in-class authentication and authorization is used to authenticate each profile during login attempt. After a set number of failed login attempts the user will be notified by email and asked to reset their password. |
Measures for the protection of data during transmission | Data is encrypted in transit using minimum TLS 1.2. |
Measures for the protection of data during storage |
Customer transactional data is stored on encrypted drives. Solink maintains a system of controls to prevent unauthorized access, modification, destruction, or disclosure of client data. |
Measures for ensuring physical security of locations at which personal data are processed | Solink’s cloud providers have perimeter, infrastructure, data and environmental layer security. Where onsite processing occurs Solink is not responsible for the physical security of Customers’ location and Customers are expected to adhere to the SOLINK SOFTWARE LICENSE AGREEMENT. |
Measures for ensuring events logging | Solink uses best in-class tools to conduct audit and event logging. |
Measures for ensuring system configuration, including default configuration | All changes to our services are managed through an approval process. |
Measures for internal IT and IT security governance and management | Industry best practices through role based access controls (RBAC) and IAAA. |
Measures for certification/assurance of processes and products | Solink is SOC2 Type 2 certified. |
Measures for ensuring data minimization | Solink and Solink customers are required to comply with all policies limiting personal data from central or local data sources. |
Measures for ensuring data quality | All data stored within the cloud is indexed to ensure traceability. |
Measures for ensuring limited data retention | Solink policy within each contract states an agreed upon retention period for onsite storage. Video saved to the cloud is stored for the duration of the customer agreement. |
Measures for ensuring accountability | Industry best practices are followed through role based access controls (RBAC) and IAAA. |
Measures for allowing data portability and ensuring erasure | Processes are in place for the secure disposal of data when the data is no longer needed for legal, regulatory and business requirements. |
Task | Responsible Party |
---|---|
Sourcing a technician, including rate negotiation and scope confirmation | Solink |
Scheduling a technician familiar with Solink install procedures | Solink |
- Installation of Solink recording device and connecting device with Customer’s cameras and internet network | Solink-led with support from Customer |
- Submitting a confirmation of completion to Solink with photos and completion survey | Solink |
Task | Responsible Party |
---|---|
Sourcing a technician, including rate negotiation and scope confirmation | Customer |
Scheduling a technician familiar with Solink install procedures OR review Solink training materials and become familiar with Solink install procedures, including: | Customer |
- Installation of Solink recording device and connecting device with Customer’s cameras and internet network | Customer |
- Submitting a confirmation of completion to Solink with photos and completion survey | Customer |
Task | Responsible Party |
---|---|
Sourcing a technician, including rate negotiation and scope confirmation | Reseller |
Scheduling a technician familiar with Solink install procedures OR review Solink training materials and become familiar with Solink install procedures, including: | Reseller |
- Installation of Solink recording device and connecting device with Customer’s cameras and internet network | Reseller-led with support from Customer |
- Submitting a confirmation of completion to Solink with photos and completion survey | Reseller |