Privacy Policy

Last Updated: March 25, 2024

1. Introduction

Welcome to Draftt. Your privacy is important to us, and we are committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our website and platform.

Draftt, Inc., its parent company, and its affiliates (“Draftt”, “we”, “our” or “us”), offers its end users (“End User”, “you”, or “your”) a proprietary software maintenance automation platform (the “Platform”), including via our website(s) available at www.draftt.io and any of its subdomains (collectively, the “Site”) which provides information regarding our Platform and allow End Users certain functionalities pertaining to the Platform. The Site also allows End Users to receive demonstrations pertaining to the Platform. This privacy policy (“Privacy Policy”) governs and is intended to describe our practices regarding the information (including Personal Information as defined below) that we may collect from you when you use or access our Services (as defined below), the ways in which we may use and share such information, and the choices and rights available to you. The Site and the Platform are collectively referred to herein as the “Services.”  

This Privacy Policy supplements and shall be read in conjunction with our Website Terms of Service and our SaaS Agreement (the SaaS Agreement, Website Terms of Service and this Privacy Policy, shall be collectively referred to herein as the “Terms”) which you must accept prior to accessing and/or using the Services. This Privacy Policy may be supplemented by additional privacy statements, terms or notices provided to you. Capitalized terms which are not defined herein, shall have the respective meanings ascribed to them in our Terms.

Your Consent

BY ENTERING, CONNECTING TO, ACCESSING, OR USING THE SERVICE, YOU AND ANY ORGANIZATION YOU REPRESENT AGREE TO THE TERMS AND CONDITIONS SET FORTH IN THIS PRIVACY POLICY, INCLUDING THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION AS DEFINED BELOW. IF YOU DISAGREE TO ANY TERM PROVIDED HEREIN, YOU MAY NOT ACCESS AND/OR USE THE SERVICES IN ANY MANNER WHATSOEVER.

2. Information We Collect

We may collect the following types of data and information from our End Users:

Non-Personal Information: any information that is non-identifiable and anonymous information (“Non-personal Information”). Non-Personal Information is collected without particular reference to the identity of the applicable End User from or about whom such information was collected and is available to us while such End User is entering and/or using the Services. Non-Personal Information which is being collected consists of technical, behavioral and aggregated information, and may contain, amongst other, anonymous activity on our Services, type of operating system, type of browser and keyboard features, browser history, traffic patterns, including anonymized “click-stream” or “heatmap,” etc.

Personal Information: any information that identifies an individual, or may with reasonable effort, identify an individual, either alone or in combination with other information (“Personal Information”). Personal Information may be of a private or sensitive nature regarding an End User or identify an individual. End Users may be asked to provide certain Personal Information including, without limitation, the types of Personal Information listed below, and to the extent that you provide us information when contacting us we may also receive any types of Personal Information provided under such communication which you provide to us of your own volition. 

We may collect Personal Information about End Users accessing our Services, including:

  • Account registration details, including first and last names, email addresses, and login credentials, personal identifiers such as IP Address.
  • Employment details, such as the name of the organization, department, job title, workplace location, business/user ID.
  • Information on system activity, including authentication logs for customer systems and applications, identifiers of the authentication tools employed, types of multi-factor authentication, and group memberships.
  • End User identified activities and usage details, such as user behavior analytics and data on how you interact with the Services, including any personal content you upload or submit to us, session recordings and information provided while engaging with the Services' interactive features.

Automatically collected data: We routinely capture data concerning End Users' engagement with our Services and their communication details. This may include information about the operating system type and version on their devices, device manufacturer and model, browser type, screen resolution, type of device (such as a smartphone or tablet), IP address, language preferences, mobile network carrier, and connection type. We also gather general location details like city, state, or geographic region.

3. How We Collect Your Information

We receive and/or collect information from you in the following ways:

  1. Information we receive when you use the Services. When you use our Services, as an End-User we may collect the certain Personal Information about you.
  2. Draftt Account. In order to use our Platform, you will be required to create an account (“Draftt Account”). If you create a Draftt Account, you will be required to provide us with certain registration information, as described above. In addition, following the setup of your Draftt Account, we may collect information regarding your use of the Draftt Account and the Platform.  
  3. “Book a demo” Information. If you send us a “Book a demo” request, whether by submitting an online form that we make available or by sending an email to an email address that we display, you may be required to provide us with certain personal information, as described above.
  4. Through integrations with certain third-party services. We may collect Personal Information through third-party analytics tools (e.g. Google Analytics) as well as service integrations with select Third Party Service Providers (as defined below). 
  5. Log Files. We may make use of log files. The information inside the log files includes internet protocol (IP) addresses, type of browser, Internet Service Provider (ISP), date/time stamp, referring/exit pages, clicked pages and any other information your browser may send to us. We may use such information to analyze trends, administer the Services, track End Users’ movement around the Services, and gather demographic information. 
  6. Candidates. We may use a Candidate’s (as defined below) Candidate Information (as defined below) solely for our internal recruitment purposes (including for identifying Candidates, evaluating their applications, making hiring and employment decisions, and contacting Candidates by phone or in writing).
  7. Usage Data. We may store certain data and analytics information in connection with the routine operation of the Services, including, performance and usage data, and/or technical, statistical and aggregated data resulting from the provision of the Services.

Communicating with you about our Services. We use the information we collect to communicate with you about our products and services, including about product updates and changes to our policies and terms. If you’re open to hearing from us, we may also send you marketing messages from time to time.

4. How We Use Your Information

To manage our Platform and provide our Services, we:

  1. Provide, operate, maintain, secure, and enhance our Services.
  2. Offer information regarding our Services.
  3. Communicate with you about our Services by sending announcements, updates, security alerts, and support and administrative messages.
  4. Address your inquiries, requests, and feedback.
  5. For research and development purposes - we analyze and enhance our Services and develop new products and services by studying how our Services are used.
  6. To comply with legal requirements, we take actions necessary or appropriate to adhere to applicable laws, respond to lawful requests, and participate in legal processes, such as answering subpoenas or requests from government authorities.

Employment Candidates. We welcome qualified candidates for employment with Draftt (“Candidate(s)”) to apply to any of the open positions posted on our Site or via our dedicated third-party social media pages (e.g. LinkedIn) by sending us your CV or Resume and any other information you may choose to share with us (“Candidate Information”). Please note that we may retain Candidate Information submitted to us even after the applied position has been filled or closed. This is done so we could re-consider Candidates for other suitable positions and opportunities at Draftt; so, we could can use the Candidate Information as a reference for future applications; and in case the Candidate is hired, for additional employment and business purposes related to their employment with us. If you previously submitted your Candidate Information to us, and now wish to access it, update it or have it deleted from our systems, please contact us at legal@draftt.io.

5. Legal Basis for Use

We collect, process, and use your Personal Information for the purposes described in this Privacy Policy, based at least on one of the following legal grounds:

In performing our agreements with you: We collect and process your Personal Information in order to provide you with the Services, following your acceptance of this Privacy Policy and pursuant to the Servies’ Subscription Terms; to maintain and improve our Services to you; to develop new services and features for our End Users; and to personalize the use of the Services in order for you to get a better user experience.

With your consent: We ask for your consent to collect and process your information for specific purposes and you have the right to withdraw your consent at any time.

Legitimate interest: We process your information for our legitimate interests while applying appropriate safeguards that protect your privacy. This means that we process your information for things like detecting, preventing, or otherwise addressing fraud, abuse, security, usability, functionality or technical issues with our services, protecting against harm to the rights, property or safety of our properties, or our users, or the public as required or permitted by law; Enforcing legal claims, including investigation of potential violations of this Privacy Policy; in order to comply and/or fulfil our obligation under applicable laws, regulation, guidelines, industry standards and contractual requirements, legal process, subpoena or governmental request, as well as our Subscription Terms.

6. Purpose of Use

We may use the Personal Information that we collect about you for the following purposes:

• To provide, operate, and improve the Services for our End Users and to manage our business including by creating marketing campaigns.

• To send you updates, notices, notifications, and announcements related to the Services as well as newsletters, coupons, special offers and promotions, and additional marketing communications regarding the Services and similar products or services we may offer.

• To enable us to provide you with customer support services and to further develop, customize and improve the service based on End Users’ common preferences, uses, attributes and anonymized or de-identified data.

• To create cumulative statistical data and other cumulative information and/or other conclusive information that is non-personal, to enable us to improve our Services and provide End Users with a better user experience with more relevant and accurate information, services, third-party services, features and functionalities, statistical and research purposes, etc.

• To prevent, detect, mitigate, and investigate fraud, security breaches or other potentially prohibited or illegal activities.

• To comply with any applicable rule or regulation, to protect our legal interests and/or respond to or defend against (actual or potential) legal proceedings against us or our affiliates.

7. Sharing Your Information

Draftt will not share or otherwise allow access to any Personal Information it collects, or that you provide through the Services, to any third party, except in the following cases:

Law enforcement, legal proceedings, and as authorized by law: We may disclose Personal Information to satisfy any applicable law, regulation, legal process, subpoena or governmental request.

Protecting Rights and Safety: We may share Personal Information to enforce this Privacy Policy and/or the Terms, as applicable, including investigation of potential violations thereof; to detect, prevent, or otherwise address fraud, security or technical issues; to respond to claims that any content available on the Services violates the rights of third-parties; to respond to claims that contact information (e.g. name, e-mail address, etc.) of a third-party has been posted or transmitted without their consent or as a form of harassment; and to protect the rights, property, or personal safety of Draftt, its employees, any of its End Users, or the general public.

Our Affiliated Companies: We may share Personal Information internally with our family of companies for the purposes described in this Privacy Policy. In addition, when Draftt or any of our affiliated companies is undergoing any change in control, including by means of merger, acquisition, or purchase of all or substantially all of its assets, we may share Personal Information with the parties involved in such event. If we believe that such change in control might materially affect your Personal Information then stored with us, we will notify you of this event and the choices you may have via e-mail and/or prominent notice on our Services. 

Third Party Services: We partner with certain third parties to provide selected services that are used to facilitate and enhance the Services and your use thereof (“Service Providers”). Such third-party Service Providers may have access to, or process on our behalf Personal Information which we collect, hold, use, analyze, process and/or manage. These Service Providers include hosting, database and server co-location services, data analytics services (e.g., Google Analytics), remote access services, data and cyber security services, fraud detection and prevention services (e.g., Amazon Web Services), e-mail and text message distribution and monitoring services, and our business, legal and financial advisors (collectively, “Third Party Service Providers”). We remain responsible for any Personal Information processing done by Third Party Service Provider on our behalf, except for events outside of our and/or their reasonable control, and except with respect to Third Party Service Providers with which you are contractually engaged, either through a prior separate contractual engagement and/or through acceptance of their privacy policy and terms of use if such are referenced herein.

For avoidance of doubt, Draftt may transfer and disclose to third parties or otherwise use Non-personal Information at its own discretion.

8. Cookies and Tracking

Draftt and our Third Party Service Providers, such as our advertising and analytics partners, use various technologies to collect information, such as cookies, pixels, web beacons, and other technologies.

What types of technologies do we use? We use cookies, web beacons, and other technologies to improve and customize our Services and your experience; to allow you to access and use the Services without re-entering your username or password; to understand usage of our Services and the interests of our customers; to determine whether an email has been opened and acted upon; and to present you with advertising relevant to your interests.

How do we use them?

  • Where strictly necessary.  These cookies and other technologies are essential in order to enable the Services to provide the feature you have requested, such as remembering you have logged in.
  • For functionality.  These cookies and similar technologies remember choices you make such as language or search parameters. We use these cookies to provide you with an experience more appropriate with your selections and to make your use of the Services more tailored.
  • For performance and analytics.  These cookies and similar technologies collect information on how users interact with the Services and enable us to improve how the Services operate. For example, we use Google Analytics cookies to help us understand how visitors arrive at and browse our products and Site to identify areas for improvement such as navigation, user experience, and marketing campaigns. 
  • For research. We receive aggregated non-personally-identifiable information from Third Party Service Providers that they have collected using cookies and pixels. These cookies and pixels collect information about how effective our advertising campaigns may be to users who have opted in to being contacted by Draftt for internal research purposes.
  • Targeting Cookies or Advertising Cookies.  These cookies collect information about your browsing habits in order to make advertising relevant to you and your interests. They remember the websites you have visited and that information is shared with other parties such as advertising technology service providers and advertisers.
  • Social media cookies. These cookies are used when you share information using a social media sharing button or “like” button on our Sites or you link your account or engage with our content on or through a social media site. The social network will record that you have done this. This information may be linked to targeting/advertising activities.

How can you opt out? To opt out of our use of cookies on our Site, you can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from websites you visit. If you don't accept cookies, you may be unable to use all aspects of our Services. 

Many browsers include their own management tools for removing HTML5 local storage objects. To manage "flash cookies" you will have to follow a separate set of instructions. Depending on where you live, you may also have the right to opt out of targeted advertising and certain third-party cookies.

Please note you won’t be able to opt out of any cookies or other technologies (on our Site or in-product) that are “strictly necessary” for the use of the Services.

Do Not Track Disclosure. Some web browsers may transmit “do-not-track” (“DNT”) signals to applications with which the user communicates. We currently do not respond to DNT settings in your web browser. Our Third-Party Service Providers may collect information about you and your online activities over time and across online properties. These third parties may not respond to DNT settings in your web browser, and we do not obligate these parties to honor DNT settings.  

9. Where do you transfer or store my Personal Information.

Your information may be transferred to, maintained, processed and stored by us and our authorized affiliates and service providers in the US. Please note that applicable data and privacy laws may not be as comprehensive as those in your country of residence. Residents of certain countries may be subject to additional protections, as set forth below.

GDPR (EEA Users): This section applies only to natural persons residing in the European Economic Area (for the purpose of this section only, "you" or "your" shall be limited accordingly). It is Draftt's policy to comply with the EEA's General Data Protection Regulation (“GDPR”). In accordance with the GDPR, we may transfer your Personal Information from your home country to Israel (authorized by an adequacy decision of the European Commission), the U.S., and/or other countries, provided that the transferee has provided appropriate technical and organizational safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Specifically, we may cause such transfer if we ensure that at least one of the following applies:

● The country to which Personal Information has been transferred has been determined by the EU Commission to be a country providing adequate protection to the privacy rights of EU residents. 

● Application of Standard Contractual Clauses (also known as "Model Clauses") or other authorized transfer mechanism, where appropriate.

10. Access to your information

To ensure your information remains accurate, current, and complete, please contact us using the contact details provided below. We will take reasonable steps to update or correct any information in our possession that you have submitted through the Services.

Data Subject Rights

Draftt customers contracted for use of the Platform act as the data controllers for their End Users' personal information. As such, they are responsible for receiving and addressing requests from End Users aiming to exercise their rights under applicable data protection laws. Draftt supports our customers in fulfilling these requests as outlined in the customer agreements such as our SaaS Agreement. Draftt is the data controller for Personal Information collected through your use of the Site. 

Depending on the laws of your jurisdiction that are applicable to you and your interactions with the Services, you may have the right to make the following requests regarding your Personal Information to our customers:

  1. Access: Request information about the processing of your Personal Information and gain access to it.
  2. Deletion: Ask for the deletion of your Personal Information held by them.
  3. Correction: Request corrections to any inaccuracies in your Personal Information.
  4. Transfer: Ask to have a machine-readable copy of your Personal Information transferred to you or a third party of your choice.
  5. Restriction: Request a limitation on the processing (including sharing) of your Personal Information.
  6. Objection: Object to the processing of your Personal Information based on the legitimate interests of our customers that affect your rights.

Marketing Communications

We may send periodic promotional or informational emails to you in accordance with your communications preferences. At any time, you may opt out of such communications by following the opt-out instructions contained in the email. Please note that it may take up to ten (10) business days for us to process opt-out requests. If you opt out of receiving marketing and advertising emails from Draftt, we will still send you emails about your Draftt Account and any Services that you have requested or received from us.

Data Retention

Draftt retains information as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce the Terms and the terms and conditions of any other customer agreements.

External Sites and Services

Our Services may include links to third-party websites and integrations with services not under our control. These links and integrations should not be seen as an endorsement or as an indication of our affiliation with any third parties. We do not have authority over third-party websites or online services, nor are we responsible for their conduct.

Security Practices

We implement reasonable organizational, technical, and administrative measures to guard against unauthorized access, misuse, loss, exposure, alteration, and destruction of the Personal Information we hold. However, it's important to note that no internet data transmission or security measure can be guaranteed to be fully secure. Thus, despite our efforts to safeguard your Personal Information, its absolute security cannot be guaranteed.

11. Changes to this Privacy Statement

This Privacy Policy is current as of the Last Updated Date set forth above. We reserve the right to alter this Privacy Policy at any time. Should there be any significant changes having a material effect on your rights or obligations, we will inform you by updating the Privacy Policy’s date and posting the new version on our Services or in an email notice to you. If we make any changes to this Privacy Policy that materially affect our practices with regard to the Personal Information we have previously collected from you, we will endeavor to provide you with notice in advance of such change by highlighting the change on our Sites. Your continued use of the Services after notice of changes has been given will constitute acceptance of, and agreement to be bound by, those changes. If you do not agree, you may not access or use the Services. 

12. How to Contact Us

For any inquiries or feedback regarding this Privacy Policy or our privacy practices, please email us at legal@draftt.io.