This Privacy Policy describes the policies and procedures of Blend.io, Inc. (“we”, “our” or “us”) on the collection, use and disclosure of your personal data on www.blend.io (the “Site”) and the services, features, content or applications we offer (collectively with the Site, the “Services”). We are committed to protecting and respecting your privacy.We receive information about you from various sources, including: (i) your use of the Services generally; and (ii) from third party websites and services.

"Personal data" means any information relating to you that can identify you, directly or indirectly, in particular by reference to an identifier such as a name, email address, an identification number, location data, or an online identifier.

For the purpose of the EU General Data Protection Regulation 2016/679 (GDPR), the data controller is Blend.io, Inc., a company located in New York at C/O ROLI, 68 3rd Street, Suite 43 Brooklyn, NY 11231, USA with company number 5330561.

The Blend team is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this privacy policy including any requests to exercise your legal rights, you can contact us at support@blend.io. stating in the subject heading that your query is about “data protection”.

All your data will be held and used in accordance with the GDPR and any relevant national laws which implement the GDPR and any legislation that replaces it in whole or in part.

What Does This Privacy Policy Cover?

This Privacy Policy covers the treatment of personal data gathered when you are using or accessing the Services.

This Privacy Policy does not apply to the practices of third party data processors summarised below that we do not own or control, including but not limited to any third party websites, services and applications, such as payment, cloud service and email service providers (“Third Party Services”) that you elect to access through the Service or to individuals that we do not manage or employ. Although we take all steps reasonably necessary to ensure that your data is treated securely, with adequate protections when engaging processors on our behalf, we encourage you to carefully review the privacy policies of any Third Party Services you access.

What Information Do We Collect?

The information we gather enables us to personalize, improve and continue to operate the Services. In connection with certain aspects of the Services, we may request, collect and/or display some of your personal data. We collect the following types of information from our users.

User Content:

Some features of the Services allow you to provide content to the Services. All content submitted by you to the Services may be retained by us indefinitely, even if and after your access to the Services is terminated, but the content may not necessarily identify you indefinitely. We may continue to disclose such content to third parties in a manner that does not reveal personal data, as described in this Privacy Policy.

IP Address Information and Other Information Collected Automatically:

  • We automatically receive and record information from your web browser when you interact with the Services, including your IP address and cookie information (See Cookie Policy below). This information is used for fighting spam/malware and also to facilitate collection of data concerning your interaction with the Services (e.g., what links you have clicked on).
  • Generally, the Services automatically collect usage information, such as the number and frequency of visitors to the Site. We may use this data in aggregate form, that is, as a statistical measure, but not in a manner that would identify you personally. This type of aggregate data enables us and third parties authorized by us to figure out how often individuals use parts of the Services so that we can analyze and improve them.

Cookie Policy: Information Collected Using Cookies:

  • Cookies are pieces of text that may be provided to your computer through your web browser when you access a website. Your browser stores cookies in a manner associated with each website you visit. We use cookies to enable our servers to recognize your web browser and tell us how and when you visit the Site and otherwise use the Services through the Internet.
  • Our cookies do not, by themselves, contain personal data, and we do not combine the general information collected through cookies with other personal data to tell us who you are. As noted, however, we do use cookies to identify that your web browser has accessed aspects of the Services.
  • Most browsers have an option for turning off the cookie feature, which will prevent your browser from accepting new cookies, as well as (depending on the sophistication of your browser software) allowing you to decide on acceptance of each new cookie in a variety of ways. We strongly recommend that you leave cookies active, because they enable you to take advantage the most attractive features of the Services.
  • This Privacy Policy covers our use of cookies only and does not cover the use of cookies by third parties. We do not control when or how third parties place cookies on your computer. For example, third party websites to which a link points may set cookies on your computer.
  • In addition to our own cookies, we are also using third party cookies such as Google Analytics to analyse the use of this website. Please visit their websites and review their privacy policies for more information.

Information from Third Parties:

You may choose to connect to our Services or register a Blend account using an external third party application, such as Facebook. We may receive information from those connected third-party applications. Connecting your Blend account to third party applications or services is optional.

Information Related to Advertising and the Use of Web Beacons:

To support and enhance the Services, we may serve advertisements, and also allow third parties advertisements, through the Services. These advertisements are sometimes targeted and served to particular users and may come from third party companies called “ad networks.” Ad networks include third party ad servers, ad agencies, ad technology vendors and research firms.

Advertisements served through the Services may be targeted to users who fit a certain general profile category may be based on anonymized information inferred from information provided to us by a user, including personal data (e.g., gender or age), may be based on the Services usage patterns of particular users, or may be based on your activity on Third Party Services. We do not provide personal data to any ad networks for use outside of the Services.

To increase the effectiveness of ad delivery, we may deliver a file (known as a “web beacon”) from an ad network to you through the Services. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Because your web browser must request these advertisements and web beacons from the ad network’s servers, these companies can view, edit or set their own cookies, just as if you had requested a web page from their site.

Aggregate Information:

We collect statistical information about how users, collectively, use the Services (“Aggregate Information”). Some of this information is derived from personal data. This statistical information is not personal data and cannot be tied back to you, or your web browser.

Children and Minors:

The Services are not directed towards children 16 years of age or under, and we do not knowingly collect any information from children.

How, and With Whom, Is My Information Shared?

The Services are designed to help you share information with others. As a result, some of the information generated through the Services is shared publicly or with third parties.

Public Information about Your Activity on the Services:

Some of your activity on and through the Services is public by default. This may include, but is not limited to, content you have posted publicly on the Site or otherwise through the Services.

Information concerning your use of the Services (such as what pages you have visited) may be tracked anonymously through the use of cookies and stored by us.

Please also remember that if you choose to provide personal data using certain public features of the Services, then that information is governed by the privacy settings of those particular features and may be publicly available. Individuals reading such information may use or disclose it to other individuals or entities without our control and without your knowledge, and search engines may index that information. We therefore urge you to think carefully about including any specific information you may deem private in content that you create or information that you submit through the Services.

IP Address Information:

While we collect and store IP address information, that information is not made public. We do at times, however, share this information with our partners, service providers and other persons with whom we conduct business, and as otherwise specified in this Privacy Policy.

Information You Elect to Share:

You may access other Third Party Services through the Services, for example by clicking on links to those Third Party Services from within the Site. We are not responsible for the privacy policies and/or practices of these Third Party Services, and you are responsible for reading and understanding those Third Party Services’ privacy policies. This Privacy Policy only governs information collected on the Services.

Aggregate Information:

We share Aggregate Information with our partners, service providers and other persons with whom we conduct business. We share this type of statistical data so that our partners can understand how and how often people use our Services and their services or websites, which facilitates improving both their services and how our Services interface with them. In addition, these third parties may share with us non-private, aggregated or otherwise non personal data about you that they have independently developed or acquired.

Information Shared with Our Agents:

We employ and contract with people and other entities that perform certain tasks on our behalf and who are under our control (our “Agents”). We may need to share personal data with our Agents in order to provide products or services to you. Unless we tell you differently, our Agents do not have any right to use personal data or other information we share with them beyond what is necessary to assist us. You hereby consent to our sharing of personal data with our Agents.

Information shared with our group companies:

We may share your personal data with any member of our group, which means ROLI Ltd., as the ultimate holding company, and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.

Information Disclosed Pursuant to Business Transfers:

In some cases, we may choose to buy or sell assets. In these types of transactions, user information is typically one of the transferred business assets. Moreover, if we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your personal data as set forth in this policy.

Information Disclosed for Our Protection and the Protection of Others:

We also reserve the right to access, read, preserve, and disclose any information as it reasonably believes is necessary to (i) satisfy any applicable law, regulation, legal process or governmental request, (ii) enforce these Terms of Service, including investigation of potential violations hereof, (iii) detect, prevent, or otherwise address fraud, security or technical issues, (iv) respond to user support requests, or (v) protect our rights, property or safety, our users and the public. This includes exchanging information with other companies and organizations for fraud protection and spam/malware prevention.

Information We Share With Your Consent:

Except as set forth above, you will be notified when your personal data may be shared with third parties, and will be able to prevent the sharing of this information.

Is Information About Me Secure?

We seek to protect user information to ensure that it is kept private; however, we cannot guarantee the security of any user information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.

The data that we collect from you may be transferred to, and stored at, a destination outside the European Union, the European Economic Area and Switzerland (“the Territory”), and in particular the United States. It may also be processed by staff operating outside the Territory who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details, and the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing.

To the extent that any of your data is provided to third parties outside the EEA, or accessed by third parties from outside the EEA, we will ensure that appropriate safeguards are in place in accordance with the GDPR (such as the European Commission’s standard contractual clauses, or the EU/US Privacy Shield).

We otherwise store all of our information, including your IP address information, using industry-standard techniques and take all steps reasonably necessary to ensure that your data is treated securely. We do not guarantee or warrant that such techniques will prevent unauthorized access to information about you that we store, personal data or otherwise.

The Legal Basis for Processing your Information

In accordance with GDPR, the main grounds that we rely upon in order to process your information are as follows:

Necessary for entering into or performing a contract:

In order to perform obligations which arise under any contract we have entered into with you, it will be necessary for us to process your information.

Necessary for compliance with a legal obligation:

We are subject to certain legal requirements which may require us to process your information. We may also be obliged by law to disclose your information to a regulatory body or law enforcement agency.

Necessary for the purposes of legitimate interests:

Either we or a third party will need to process your information for the purposes of our (or a third party’s) legitimate interests, provided that we have established that those interests are not contrary to your rights and freedoms, including your rights to privacy, and to have your information protected. Our legitimate interests include responding to requests and enquiries from you or a third party, optimising our website and user experience, informing you about our services, and ensuring that our operations are conducted in an appropriate and efficient manner.

Consent

In all other circumstances, we will ask for your consent to process your information, or to communicate regularly with you.

Your rights

You have certain rights in relation to the personal data that we hold about you. Details of these rights and how to exercise them are set out below. Please note we will require evidence of your identity before we are able to respond to your request. You can exercise any of these rights at any time by contacting us at support@blend.io.

Right of Access:

You have the right at any time to ask us for a copy of the personal information that we hold about you and to check that we are lawfully processing it. Where we have good reason, and if the GDPR permits, we reserve the right to decline such a request, or certain elements of the request. If we refuse your request or any element of it, we will provide you with our reasons for doing so.

Right of Data Portability:

In certain instances, you have a right to receive any personal information that we hold about you in a structured, commonly used and machine-readable format. In such circumstances, you can ask us to transmit that information to you or directly to a third party organisation.

While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organisation's systems. We are also unable to comply with requests that relate to personal information of others without their consent.

Right of Correction or Completion:

If personal information we hold about you is not accurate or is out of date and requires amendment or correction, you have a right to have the data rectified or completed. This can usually be done by interacting with our platform.

Right of Erasure.

In certain circumstances, you have the right to request that personal information we hold about you is erased e.g. if the information is no longer necessary for the purposes for which it was collected or processed or our processing of the information is based on your consent and there are no other legal grounds on which we may process the information.

Right to Object to or Restrict Processing:

In certain circumstances, you have the right to object to our processing of your personal information e.g. if we are processing your information on the basis of our legitimate interests, but there are no compelling legitimate grounds for our processing which override your rights and interests. You may also have the right to restrict our use of your personal information, such as in circumstances where you have challenged the accuracy of the information and during the period where we are verifying its accuracy.

Right to Withdraw Consent

In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. This can usually be done by interacting with our Services or by contacting us at support@blend.io.

Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

Complaints

If you are unhappy about our use of your information, you can contact our data protection team or contact us using the details in the Contact section below. You are also entitled to lodge a complaint with the UK Information Commissioner's Office using any of the below contact methods:

  • Telephone: 0303 123 11113
  • Website: https://ico.org.uk/concerns/
  • Post:
    Information Commissioner's Office
    Wycliffe House
    Water Lane
    Wilmslow
    Cheshire
    SK9 5AF

If you live or work outside of the UK or you have a complaint concerning our activities outside of the UK, you may prefer to lodge a complaint with a different supervisory authority. A list of relevant authorities in the EEA can be accessed here.

What Information of Mine Can I Access?

Users can access and delete cookies through their web browser settings.

What Choices Do I Have Regarding My Information?

  • You can use many of the features of the Services without registering, thereby limiting the type of information that we collect.
  • You can always opt not to disclose certain information to us, even though it may be needed to take advantage of some of our features.

How long we hold your information

We will only retain your information for as long as is necessary to fulfil our purposes, including for the purposes of satisfying any legal, accounting or reporting requirements. The criteria that we use to determine retention periods will be determined by the nature of the data and the purposes for which it is kept, the sensitivity of the data and the potential risk of harm from unauthorised use or disclosure.

What Happens When There Are Changes to this Privacy Policy?

We may amend this Privacy Policy from time to time. Use of information we collect now is subject to the Privacy Policy in effect at the time such information is used. If we make changes in the way we collect or use information, we will notify you by posting an announcement on the Services. A user is bound by any changes to the Privacy Policy when he or she uses the Services after such changes have been first posted.

What If I Have Questions or Concerns?

If you have any questions or concerns regarding privacy using the Services, please send us a detailed message to support@blend.io. We will make every effort to resolve your concerns.

Effective Date: June 19, 2018.

We've updated our privacy policy. Read more here.