Legal Notice

Legal Notice

3. Customer Data Research & Development Privacy Policy

This policy describes Qommodity’s processing of personal information in connection with Qommodity’s artificial intelligence and machine learning activities in order to analyze, develop, and improve Qommodity products and services, and for security and compliance purposes.

1. INTRODUCTION

This Qommodity Customer Data Research and Development Privacy Policy (also referred to as the ‘Privacy Policy’ or ‘policy’) informs data subjects (‘you’) on the collection and use (collectively referred to as ‘processing’ or ‘process’) of your personal information in connection with Qommodity’s artificial intelligence and machine learning (“AI/ML”) activities in order to analyze, develop, and improve Qommodity products and services, and for security and compliance purposes. This Privacy Policy also explains your privacy rights in relation to these processing activities.

 

This Privacy Policy was created on June 17, 2022. However, the Privacy Policy can change over time, for example to comply with legal requirements or to meet changing business needs. The most up-to-date version can be found on this site.

As used in this Privacy Policy, ‘personal information’ means information that relates to an identified individual or to an identifiable individual. For example, this could include among other things your name, address, email address, or information about your use of Qommodity products and services, or your interactions with Qommodity. Personal information about you that Qommodity may process is also referred to as ‘information about you.’ For more detail about the types of information about you that Qommodity may process, please refer to section 4 below.

 

2. SCOPE

This Privacy Policy applies to Qommodity’s processing of personal information that Qommodity has obtained from an Qommodity customer when agreed to by contract with that customer to use such information for AI/ML processing for the purposes specified in this Privacy Policy. The following Qommodity lines of business may process personal information under this policy: NetSuite.

 

3. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL INFORMATION

Qommodity QAA Ltd, having its registered address at Kemp House 160, City Road, EC1V 2NX, London, United Kingdom, is responsible for processing your personal information in scope of this Privacy Policy.

 

4. WHICH CATEGORIES AND SPECIFIC PIECES OF PERSONAL INFORMATION DO WE PROCESS

Personal information that can directly or indirectly identify you may include, for example:

 

  • Contact details: Name, email, phone number, mailing address, zip code;

  • Company and employment data: your employment with and role within a company, including information related to such company such as company name, size, location, as well as publicly available company information and activity;

  • Device information: Information related to a device interacting with Qommodity products, services, and websites including IP address, browser, device type, operating system, the presence or use of “apps”, screen resolution, preferred language;

  • Interactions with Qommodity services or products: Information related to the use of Qommodity services and products, such as products and services purchased, subscriptions, features used or platform preferences, or performance of Qommodity services or products;

 

Qommodity may also collect customer and systems operations data, which may incidentally contain personal information:

 

  • Customer data: Data provided by Qommodity customers (when agreed to by contract with the customer) such as transaction data, invoices or receipts, product inventory, and other customer-provided datasets;

  • Systems operations: Information related to the use, operation, and performance of Qommodity systems such as log files, event files, and other trace and diagnostic files.

 

 

5. FOR WHAT COMMERCIAL OR BUSINESS PURPOSE DO WE USE YOUR PERSONAL INFORMATION

In cases where the processing of personal information is not central to the purposes of processing for the below AI/ML activities, Qommodity will limit the use of personal information when technically possible or feasible. ‘Dataset’ refers to a set of data that may contain this limited personal information. 

We use personal information for the following business purposes:

 

  • to analyze, develop, improve, and optimize the use, function and performance of Qommodity products and services to provide our customers with a more intelligent experience.

  • to manage the security of websites, networks and systems and the products and services Qommodity provides to our customers; and

  • to comply with applicable laws and regulations and to operate our business.

These purposes are described below in further detail.

 

  • to analyze, develop, improve, and optimize the use, function and performance of Qommodity products and services to provide our customers with a more intelligent experience

    Qommodity will use these datasets for internal research for technological development and demonstration and to improve, upgrade, or enhance Qommodity products and services to provide more intelligent, automated and predictive functionalities.

    Example: Qommodity provides our eCommerce platform customers with flagging functionality that enables customers to see that inventory is low for a certain good in the customer’s product catalog. Using AI/ML processing under this Privacy Policy, Qommodity can now help predict when the inventory may be low in the near future so the customer can take action before the inventory becomes low.  

  • to manage the security of our sites, networks and systems and the products and services Qommodity provides to our customers

    Qommodity processes datasets to detect, prevent, or predict malicious, deceptive, fraudulent, or illegal activity on Qommodity sites, networks, and systems, as well as on Qommodity products and services used by our customers. AI/ML activities, subject to this policy, allow Qommodity to provide more intelligent and predictive functionalities to investigate, prevent, or predict malicious activity, fraud, or bad actors. 

  • to comply with applicable laws and regulations and to operate our business

    In some cases, we may process personal information to comply with applicable laws and regulations. For example, to respond to a request from a regulator or to defend a legal claim. We may also process personal information in the operation of our business.

    Example: Qommodity may process the datasets to conduct audits and investigations, for finance and accounting, archiving and insurance purposes, or to process individual rights requests.

 

6. CATEGORIES OF SOURCES OF PERSONAL INFORMATION

Personal information subject to this Privacy Policy is provided to Qommodity from Qommodity customers when agreed to by contract with the customer. 

 

 

 

 

7. FOR INFORMATION ABOUT YOU COLLECTED IN THE EU/EEA, WHAT IS OUR LEGAL BASIS

Qommodity will process information about you as may be necessary for internal research for technological development and demonstration and to improve, upgrade, or enhance Qommodity products and services based on our legitimate interests when such processing has a limited privacy impact on the individual. Qommodity will process information about you as may be necessary to detect, prevent, or predict malicious, deceptive, fraudulent, or illegal activity on Qommodity sites, networks, and systems based on our legitimate interests in order for Qommodity to safeguard such systems. Qommodity may also process personal information as necessary for compliance with our legal obligations.

 

 

 

8. FOR WHAT PERIOD DO WE RETAIN INFORMATION ABOUT YOU

Qommodity maintains personal information provided by Qommodity customers for processing to achieve the intended purposes described in this Privacy Policy for only as long as necessary, which is approximately 3 months but no longer than 12 months. Qommodity will maintain evidence of access, opt-out, or deletion requests as long as necessary to document Qommodity’s compliance with such requirements.

 

 

 

9. WHEN AND HOW CAN WE SHARE YOUR PERSONAL INFORMATION

Sharing within Qommodity

As a global organisation, information about you can be shared with other Qommodity entities globally throughout Qommodity’s worldwide organization as needed for the purposes of processing. Qommodity employees are authorized to access personal information only to the extent necessary to serve the applicable purpose(s) and to perform their job functions.

 

Sharing with or selling with third parties

We do not share or sell personal information subject to this Privacy Policy with third parties for any commercial purposes. We may also share such personal information with the following third parties for a business purpose:

 

  • third-party service providers (for example, IT service providers, lawyers and auditors) in order for those service providers to perform business functions on behalf of Qommodity;

  • relevant third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings);

  • as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside your country of residence, for national security and/or law enforcement purposes.

  •  

10. HOW IS PERSONAL INFORMATION PROTECTED GLOBALLY

Qommodity is a global corporation and personal information is processed globally as necessary in accordance with this policy. If personal information is transferred to an Qommodity recipient in a country that does not provide an adequate level of protection for personal information under applicable data protection law in the country where such information was collected, Qommodity will take adequate measures designed to protect the personal information, such as ensuring that such transfers are subject to EU Model Clauses or other adequate transfer mechanism as required under relevant data protection laws.

 

 

 

11. HOW IS INFORMATION ABOUT YOU SECURED

Qommodity has implemented appropriate technical, physical and organizational measures designed to protect personal information against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorized disclosure or access, as well as all other forms of unlawful processing.

 

 

 

12. WHAT ARE YOUR PRIVACY RIGHTS

Pursuant to the E.U. General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Brazilian General Data Protection Law (LGPD) and other applicable laws and regulations, individuals in certain jurisdictions may have data subject rights enabling them to opt-out of third party sharing or selling, delete or remove, or request to access and receive a copy of their personal information in Qommodity’s possession or for which Qommodity is otherwise responsible. 

 

Qommodity provides rights to individuals to access, amend, correct, or delete data for personal information that directly identifies such individuals, such as their name or email address. 

 

We will respond to your request consistent with applicable law. Qommodity will not discriminate against consumers who have exercised the deletion, opt-out, or access rights provided to them in this Privacy Policy.

 

 

 

13. WHAT ARE YOUR RIGHTS UNDER THE CALIFORNIA CONSUMER PRIVACY ACT (CCPA)

If you are a California resident, you may request that we:

  • 1. disclose to you the following information:

    • the categories and specific pieces of personal information we collected about you and the categories of personal information we sold (see section 4);

    • the categories of sources from which we collected such personal information (see section 6);

    • the business or commercial purpose for collecting or selling personal information about you (see section 5); and

    • the categories of third parties to whom we sold or otherwise disclosed personal information, if applicable (see section 9).

 

  • 2. delete personal information we collected under this Privacy Policy (see section 12); or

 

  • 3. opt-out of any future sale of personal information about you, if applicable (see section 12).

We will respond to your request consistent with applicable law. If you are an authorised agent making an access or deletion request on behalf of a Californian resident, please reach out to us and indicate that you are an authorised agent. We will provide you with instructions on how to submit a request as an authorised agent on behalf of a Californian resident.

 

 

 

14. DOES QOMMODITY PROCESS PERSONAL INFORMATION FROM CHILDREN OR OTHER SENSITIVE PERSONAL INFORMATION

We do not knowingly process personal information of children under 16 years of age or personal information that is sensitive or “special” under applicable data protection laws. 

Qommodity will not use the personal information processed under this policy to make decisions related to an individual’s eligibility for employment, credit, healthcare, or insurance purposes or to make decisions solely by automatic means where the decision has a legal or significant effect on the individual, or in any way that may or does discriminate against any person or promote bigotry, racism or harm.

 

 

End of Qommodity Customer Data Research & Development Privacy Policy. 

Version 1.20