Introducing Productboard Pulse. Exec-level insights into what your customers need, powered by AI. Learn more

DPF Customer Privacy Policy

Last Updated: Dec 2, 2024

Productboard, Inc. in the United States (“Productboard US,” “we,” or “our”) has created this Data Privacy Framework Customer Privacy Policy (the “DPF Customer Privacy Policy”) to help you learn about how we handle customer Personal Information that we receive from our affiliates, business customers/partners located in the European Economic Area (the “EEA”), the United Kingdom, Gibraltar, and Switzerland under the Data Privacy Framework.  This DPF Customer Privacy Policy supplements the Productboard Privacy Policy.  Unless specifically defined in this policy, the terms in this DPF Customer Privacy Policy have the same meaning as in the Productboard Privacy Policy.

Productboard US has certified to the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, and the Swiss-US Data Privacy Framework (collectively “DPF”) with regard to the processing of Personal Information received from the EEA, the UK, Gibraltar, and Switzerland, and we are committed to adhering to the DPF Principles for Personal Information covered by this DPF Customer Privacy Policy.  More information about the DPF, including the list of certified organizations, can be found at https://www.dataprivacyframework.gov/.  This DPF Customer Privacy Policy applies to Productboard US. 

Personal information that is transferred to Productboard US from the EEA, the UK, Gibraltar, and Switzerland fall into two categories:  1) Personal Information regarding personnel from Productboard US’s customers in the EEA, the UK, Gibraltar, and Switzerland; and 2) Personal Information that Productboard US processes on behalf of its customers (such as users’ name, email address, company name, and user-chosen password). In the case of the latter category, Productboard US acts as a data processor and processes such information only under the instructions from its clients.  This information is controlled by its customers in the EEA, the UK, Gibraltar, and Switzerland. 

Because the requirements of the DPF vary depending on whether Productboard US is acting as a processor on behalf of its customers or as a data controller, meaning that Productboard US makes independent decisions about how that information will be used, Productboard US’s policies and practices are described separately below.

 

Productboard US acting as a Processor on Behalf of its Customers

 

When Productboard US acts as a processor on behalf of its customers, the following policies apply to all data processing operations concerning Personal Information that has been transferred from the EEA, the UK, Gibraltar, and Switzerland to the United States.

Use of Personal Information

Productboard US will process the Personal Information only for the purposes requested by the customer.

Access and Correction.

Productboard US will assist the controller (the customer) in responding to individuals exercising their rights under the DPF Principles. 

Agents and Service Providers

Productboard US will not transfer Personal Information to third parties except where permitted or required by the customer and then in accordance with the DPF Principles. 

Notice & Choice

Because the Personal Information is under the control of Productboard US’s customers, appropriate notice and choice to the individual are provided by Productboard US’s customers.  As the data processor, Productboard US typically does not have a direct relationship with the customers’ own customers or employees.  

Productboard US Acting As A Data Controller

Productboard US may receive Personal Information from customers in the EEA, UK, Gibraltar, and Switzerland regarding their employees including name, postal address, telephone number, and e-mail address, etc. 

Use of Personal Information

Any Personal Information sent to us may be used by Productboard US and its agents for the purposes indicated in the Productboard Privacy Policy.  If we intend to use your information for a purpose that is materially different from these purposes or if we intend to disclose it to a third party (a non-agent) not previously identified, we will notify you and offer you the opportunity to opt out of such uses and/or disclosures where it involves non-sensitive information or opt-in where sensitive information is involved.  

Disclosures to Affiliates and Third Parties

Your Personal Information may be disclosed:

  • To our affiliates, which shall include Productboard UK Limited, Productboard Ireland Limited, Productboard Czechia s.r.o, and Productboard Canada, Inc., for the purposes described in this Privacy Policy 
  • To third parties, to permit them to send you marketing communications. 
  • To third-party sponsors of sweepstakes, contests and similar promotions.
  • To a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings

Disclosures to Agents and Service Providers

We sometimes contract with other companies and individuals to perform functions or services on our behalf such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, auditing and other services. They may have access to Personal Information needed to perform their functions but are restricted from using the Personal Information for purposes other than providing services for us or to us.  Productboard US requires that its agents and service providers that have access to Personal Information received from the EEA, UK, Gibraltar, and Switzerland provide the same level of protection as required by the DPF Principles.  We are responsible for ensuring that our agents process the information in a manner consistent with our obligations under the DPF Principles.  

Data Security 

We use reasonable physical, electronic, and administrative safeguards to protect your Personal Information from loss, misuse and unauthorized access, disclosure, alteration, and destruction, taking into account the nature of the Personal Information and the risks involved in the processing that information.  

Data Integrity and Purpose Limitation

We limit the collection and use of personal information to the information that is relevant for the purposes of processing and will not process personal information in a way that is incompatible with the purposes for which the information has been collected or subsequently authorized by you.  We take reasonable steps to ensure the personal information is reliable for its intended use, accurate, complete, and current to the extent necessary for the purposes for which we use the Personal Information. 

Access to Personal Data 

You can ask to review, correct and delete Personal Information that we maintain about you by sending a written request to [email protected].

DPF Enforcement and Dispute Resolution

If you have any questions or concerns, please write to us at the address listed below.  We will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with the DPF Principles. 

In the event we are unable to resolve your complaints or disputes, you may contact JAMS DPF Program, an alternative dispute resolution provider based in the U.S. and they will investigate and assist you free of charge in resolving your complaint. 

As further explained in the DPF Principles, a binding arbitration option link will also be made available to you in order to address residual complaints not resolved by any other means. Productboard US is subject to the investigatory and enforcement powers of the US Federal Trade Commission (FTC).

Disclosures Required By Law

We may need to disclose personal information in response to lawful requests by public authorities for law enforcement or national security reasons or when such action is necessary to comply with a judicial proceeding or court order, or when otherwise required by law.  

Contact Information

If you have any questions regarding this DPF Privacy Policy, please contact us by email at [email protected], or please write to the following address:

Productboard, Inc.

Attn: Privacy Officer

333 Bush Street, 20th floor

San Francisco, CA 94104

E-mail:  [email protected] 

Privacy Policy Changes

This policy may be changed from time to time, consistent with the requirements of the DPF. You can determine when this Policy was last revised by referring to the “LAST UPDATED” legend at the top of this page.  Any changes to our Policy will become effective upon our posting of the revised Policy on the Site.  

 

Previous Versions

  • Privacy Policy – 2021-03-01
  • Privacy Policy – 2018-05-25
  • Privacy Policy – 2017-08-22
  • Privacy Policy – 2017-03-08
  • Privacy Policy – 2014-07-01