Last Updated: February 2022
This policy applies where we may be considered a “Controller” (i.e., we determine why and how Personal Information is processed), including through our website at corcentric.com (the “Site”) and our Software Services (defined below) (collectively the “Site” and “Software Services”, the “Services”).
Corcentric Platform, SmartSource 9.X, SmartSource Cloud, SmartContracts, SmartAnalytics, Managed AR Billing Solution (CorConnect), COR360 Approval Workflow (COR360), Corcentric Expense, Fleet Procurement/GPO (Buyer’s Guide), COR360 Purchase Order (InfoAccess, iForms, iCube, iHub), Electronic Invoice Presentment + Payment (EIPP)/Netsend, and Corcentric Payments/Vendorin (collectively, the “Software Services”).
1. Information We Collect
Personal Information Provided by You
- Communication Information. If you contact us directly (e.g., via email, phone, etc.) or fill out information on our Services (e.g., to ask a question via our online contact form, to apply for a job on our career page etc.), we may collect your name, email address, phone number, company, job title, postal address, the content of your inquiry, the services related to your interest, date and time of your message and any attachments thereto, and other information you may directly provide to us. If you post a public comment on our Site, we ask you to provide your name and email address. Without this information we may not be able to answer your question or process your request.
- Business Contact Information. When you do business with us or use our Services, we may receive professional contact details of employees and other individuals associated with our customers, partners, and vendors, such as first and last name, email address, phone number, title and department, and other information relevant to, and necessary for us to manage a particular business relationship or provide you with access to the Services.
- Support Services Information. When you request technical support services through our support portal, via email, via an IT helpdesk ticket or via our call center, we will process your contact information, such as name, email address, phone number and the country in which you are operating as well as information on the reasons for your support request. Without this information we may not be able to answer your support request.
- Payment Transaction Information. Where you use the Corcentric Services to make, receive, record, or otherwise process a payment through our Services, we may collect information about the payment transaction and the transaction parties, including the date, time and locations of the transaction, identifying information of the sender and recipient, the payment or transfer amount(s), bank account information for the sender and/or recipient, a description of the transactions, amounts delivered, etc.
- Financial Information. When you use the Services to make or receive payments to or from third parties, we collect certain financial information from you, such as bank routing and account information, credit or debit card information, etc.
- Information about your Customers and Vendors. Depending on the Services you are utilizing, you may provide to us information about your customers and vendors, such as name, email address, phone number, contact information, and financial information.
Personal Information Provided by Customers & Partners
- Customer Data. Our Customers may provide us with your Personal Information through their use of the Software Services. As described above, each Customer is responsible for ensuring it has the necessary rights to collect and transfer the Customer Data for Corcentric’s use in providing the Services.
- Other Information from Third Party Services & Partners. Corcentric works with various partners and third parties. Such partners may provide Corcentric with your Personal Information in their provision of the services to Corcentric.
Information Collected via Automated Means
- Log Data and Usage Data. Our Services may automatically collect information about your computer hardware and software, including IP address, browser type, domain names, the files viewed, operating systems, access time, and websites or services you visited before accessing the Services. This information is gathered periodically to facilitate the improvement of the Services or to provide services or technologies to you. When you use the Services, Corcentric may also collect or measure data and information regarding your interaction with content, including, by way of example, counts of views of segments, frequency of views, bookmarks into content, links you view or interact with, and other statistical analysis.
- Third Party Buttons. We implement third party buttons (such as LinkedIn “like” or “share” buttons) on our Site that may allow third parties to collect information about you through such third parties’ browser cookies, even when you do not interact with the button. To find out how you may opt-out of these cookies, please refer to the Disabling Cookies section below.
- Third Party Advertising Companies. We also implement third-party content or advertising on the Site that may use clear gifs or other forms of web beacons, which allow the third-party content provider to read and write cookies to your browser in connection with your viewing of the third party content on the Site. Please note that there are no third party advertising cookies in our Software Services. For more information on how to opt-out of receiving web-based personalized ads, please see the Disabling Cookies section below.
2. How We Use the Information We Collect
We use Personal Information we collect on the Services in a variety of ways in providing services and operating our business, including the following:
- Facilitating and Improving Our Services. To operate, maintain, enhance and provide all features of the Services, to provide services and information that you request, to respond to comments and questions and otherwise to provide support to users.
- Analytics and Services Improvement. To understand and analyze the usage trends and preferences of our users, to improve the Services, and to develop new services, features and functionality.
- Tailored User Experience. To (i) personalize our Services, such as remembering your information so that you will not have to re-enter it during your visit or the next time you visit any of the Services; (ii) provide customized advertisements on the Services, content, and information; (iii) monitor and analyze the effectiveness of our services and third-party marketing activities; (iv) monitor aggregate usage metrics such as total number of visitors and pages viewed; and (v) track your entries, submissions, and status in any promotions or other activities on the Services.
- Communicating with You. We may use your email address or other information (i) to contact you for administrative purposes such as customer service or technical-support, (ii) to send communications, including updates on promotions and events including webinars, email marketing campaigns relating to current or new similar products and services offered by us and by third parties we work with.
- Product Development. We may use Personal Information, including information received from our customers, to learn about the use of our products, to diagnose issues, to improve our products and to develop new products and services.
- Billing, Account Management and Administrative Matters. We may need to contact you for invoicing, account management, or other related reasons and we use your information to help us keep track of billing and payments and manage our accounts.
- Legal. We may use your Personal Information to defend our legal rights, to comply with our legal obligations and internal policies, resolve disputes, and enforce our agreements.
Retention of Personal Information
3. How We May Disclose Information
We may share Personal Information with third parties in the following circumstances:
- Advertising and Analytics Partners. We may make certain information available to third parties for analytics purposes, including: (i) for business or marketing purposes, such as to track sales leads; or (ii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Services. Typically, this information is aggregated, or otherwise de-identified Personal Information.
- Social Networking and Other Websites. The Site may allow you to share information, including Personal Information, with social networking websites, such as LinkedIn and Twitter, by posting information to these websites through links available on the Site. We do not share your Personal Information with these social networking sites unless you have authorized us to do so. The use of your Personal Information by any social networking websites will be governed by their privacy policies, and you may be able to modify your privacy settings on their websites.
- Third Party Services. If third party services are enabled or integrated with the Services, Corcentric may share information with such third party services for purposes of allowing the integration and providing the Services.
- Legal. We reserve the right to disclose your Personal Information that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Services and any facilities or equipment used to make the Services available, (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others and (vi) to comply with state and federal laws, in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
- Mergers and Other Reorganizations. Information about our users, including Personal Information, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
- Affiliates. Corcentric may share your Personal Information with its corporate affiliates, parents, and subsidiaries.
Cookies and How We Use Them
Cookies are small text files containing a string of alphanumeric characters that can be stored on a device when you visit a website. When you visit or use the Services, we and our third-party service providers receive and record information on our server logs from your browser, including your IP address, and from cookies and similar technologies. This information may include Personal Information, such as your IP address, web browser and/or device type, the web pages that you visit just before or just after you use the Services, as well as information about your interactions with the Services, such as the time of your visit and where you have clicked.
Cookies help us improve your experience by allowing us to distinguish you from other users, store your preference, and otherwise personalize your Service settings. Cookies also allow us to measure and analyze your use of the Services and help us provide better services to you.
Types of Cookies
- Necessary & Functional cookies. Some cookies are strictly necessary to make our Services available to you. For example, to provide the chat and login functionality, and to remember your consent and privacy choices. We cannot provide you with the Services without these types of cookies.
- Third Party Advertising Cookies. We work with third-party advertising partners such as Google Ads to show you ads about Corcentric that we think may interest you on third party websites and apps, as well as assist us with data collection, reporting, ad-response measurement, analytical information, and delivery of marketing messages and advertisements. To do so, we and our advertising partners may place and access cookies through our Site and otherwise collect or access Personal Information collected over time and across different online services. Our advertising partners may also collect information about your use of other websites, apps, and online resources.
For a list of cookie types used in the Software Services, please click here.
- Google Analytics Cookies. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/, and opt-out by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout or via Google’s Ads Settings or Ad Settings for mobile apps.
- Third Party Advertising Cookies. Some of our advertising partners are members of the Network Advertising Initiative (NAI) or the Digital Advertising Alliance (DAA), or the European Interactive Digital Advertising Alliance’s Consumer Choice (https://www.youronlinechoices.eu). If you prefer to not receive targeted advertising, you may be able to opt out of some network advertising programs by visiting the Digital Advertising Alliance Opt-Out Page and the Network Advertising Initiative Opt-Out Page. You can visit your device’s settings or install the AppChoices app to learn more about how you may opt out of receiving personalized ads in mobile apps. Please note that even if you choose to remove your Personal Information, you will still see advertisements, but these may not be specifically tailored to you. Additionally, many network advertising programs allow you to view and manage the interest categories they have compiled from your online browsing activities. These interest categories help determine the types of targeted advertisements you may receive.
- Do Not Track. We do not specifically respond to Do Not Track (“DNT”) signals. However, some third party websites do keep track of your browsing activities, including across other websites on the Internet, which enables these websites to tailor what they present to you. Your browser may allow you to set a DNT signal on your browser so that these third parties know you do not want to be tracked.
5. Your Rights and Choices
Please be aware that if you opt out of receiving commercial emails from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten (10) business days for us to process your request, and you may receive promotional communications from us that you have opted out from during that period. Additionally, even after unsubscribing we may continue to send administrative messages as necessary for us to provide you with services.
6. Visitors from EU/EEA
If you are a visitor from the EU/EEA, you have additional rights available to you with respect to your Personal Information. This section describes Corcentric’s obligations to you with respect to our collection and use of your Personal Information and your rights related to such Personal Information.
Legal Basis For Our Use of Your Personal Information
If you are located in the EU/EEA, and where Corcentric acts as a Controller of your Personal Data, we only process your “Personal Information” based on a valid legal basis, as follows. For the purposes of this section, Personal Information has the same definition as “Personal Data” under the GDPR:
- Consent. You have consented to the use of your Personal Information, for example to send marketing communications, and to collect information via cookies and similar technologies.
- Contract. We need your Personal Information to provide you with Corcentric’s products and services, including for account registration or to respond to your inquiries.
- Legal Obligation. We have a legal obligation to use your Personal Information, for example for compliance with tax law and bookkeeping obligations.
- Legitimate Interest. We or a third party, have a legitimate interest in using your Personal Information. In particular, we have a legitimate interest in using your Personal Information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our products and services. We only rely on our or a third party’s legitimate interests to process your Personal Information when these interests are not overridden by your rights and interests.
Where Corcentric is acting as a Processor of your Personal Data on behalf of a Customer or related party, Corcentric relies on its legitimate interest to process such Personal Data and will only process the Personal Data upon the instruction of our Customers.
Where Corcentric acts as a Controller of your Personal Data, you have the following data protection rights with respect to Personal Data Corcentric collects about you:
- Access, Correction, or Deletion. You can request from Corcentric that we provide you with the Personal Information we have collected about you. You may also request that we correct or delete your Personal Information. Please note, however, that Corcentric may retain Personal Information in order for us to meet our legal or regulatory compliance requirements.
- Transfer of your Personal Data. You may ask Corcentric to provide your Personal Information to a third party in a commonly used, machine readable format.
- Objection and Restriction. Where we process your Personal Information based on legitimate interest, you may object to our processing of your Personal Information. You may also ask that Corcentric restricts from further processing your Personal Information.
- Consent Withdrawal. Where Corcentric has relied on your consent to process your Personal Information, you can withdraw your consent at any time.
To exercise any of these rights, please contact us at firstname.lastname@example.org. We will respond to your request without undue delay and notify you of the action we have taken.
The Site is hosted in the United States. If you visit the Site from outside of the United States, please note that your Personal Information will be transferred to the United States, which may not have the same data protection laws as your country. We take reasonable measures to ensure that if your Personal Information is transferred outside of the EEA and the UK appropriate controls are in place to adequately protect your Personal Information and that such protection is in accordance with applicable data protection laws and regulations. Personal Information relating to individuals in the EEA, the United Kingdom, and Switzerland is controlled by Corcentric SAS. Corcentric’s international transfer of Personal Information collected in the EEA, the United Kingdom, and Switzerland is governed by the European Commission-approved Standard Contractual Clauses (the “SCCs”). The SCCs are contractual commitments made between companies transferring Personal Information with respect to the privacy and security of such Personal Information.
As it relates to any Personal Information included in the Customer Data we may receive from our Customers, our Customer is responsible for ensuring it has all necessary rights to provide and transfer the Personal Information to us. Where our Customer is providing us with Personal Data collected in the EEA, and we are transferring such Personal Data to the United States or other jurisdiction deemed as having inadequate protections, we enter into SCCs with such Customer for the purposes of the transfer.
If you have any questions, concerns or complaints about our data practices, you may contact us at the email or address listed in the Contact Information section, or you may reach out to our Data Protection Officer (DPO), also listed in the Contact Information section.
7. Visitors from California
If you are a resident of California, you have a right to opt-out of the “sale” of your Personal Information. Corcentric does not “sell” the Personal Information we collect from you from your interactions with our Services. However, “sale” is broadly defined under the California Consumer Privacy Act (“CCPA”). Sharing of your Personal Information with our marketing partners and other third parties for advertising purposes may be considered a sale under the CCPA. To the extent this sharing of your Personal Information is considered a “sale” under the CCPA, you may opt out of such sale by clicking the “Do Not Sell My Information” text link in the footer or by clicking here. You may also opt-out of such sale by contacting us at email@example.com.
8. Other Important Information
Third Party Services
The Services may contain features or links to web sites, services, and/or applications provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Services. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Services. We encourage you to learn about third parties’ privacy and security policies before providing them with information.
Our Services are not directed to children under the age of thirteen (13), and we do not knowingly collect Personal Information from children under the age of thirteen (13). If you are under the age of thirteen, you must ask your parent or guardian for permission to use the Services. We will take steps to delete it if we learn we have collected Personal Information from children under thirteen (13). If you learn that your child has provided us with Personal Information without your consent, then you may alert us at firstname.lastname@example.org. If we learn that we have collected any Personal Information from children under thirteen (13), then we will promptly take steps to delete such Personal Information and terminate the child’s account.
9. Changes and Updates
10. Contact Information
ATTN: Senior Vice President of Marketing
200 Lake Drive East, Suite 200
Cherry Hill, NJ 08002
Data Protection Officer: Bruno Courbet; email@example.com