Corcentric Privacy Policy

Last Updated: April 2021

Corcentric values your privacy and is committed to protecting it. This Privacy Policy explains how Corcentric and its related subsidiaries and affiliated entities (collectively, “Corcentric”, “we”, and “us”) may collect, use, and disclose Personal Information we obtain in the provision of our Services (as defined below), as well as your rights and choices with respect to our collection and use of your Personal Information.

This policy applies where we may be considered a “Controller” (i.e., we determine why and how Personal Information is processed), including through our website at corcentric.com (the “Site”) and our Software Services (defined below) (collectively the “Site” and “Software Services”, the “Services”).

Please note that where Corcentric has entered into a contractual agreement (the “Commercial Agreement”) with an organization (such as your employer or another entity for which you may provide services) (the “Customer”), and such Customer uploads or provides to Corcentric Customer Data in relation to its use of the Software Services, Corcentric is considered a “Processor” and the Customer controls and is responsible for the Customer Data that you or it provides to us. Please visit the corresponding Customer’s privacy policy for a description of its collection practices with respect to your data. Corcentric’s use of such Customer Data is governed by the Commercial Agreement between Corcentric and such Customer.

This Privacy Policy applies to Corcentric’s online platforms, including:

Corcentric Platform, SmartSource 9.X, SmartSource Cloud, SmartContracts, SmartAnalytics, Managed AR Billing Solution (CorConnect), COR360 Approval Workflow (COR360), Corcentric Expense, Fleet Procurement/GPO (Buyer’s Guide), COR360 Purchase Order (InfoAccess, iForms, iCube, iHub), and Electronic Invoice Presentment + Payment (EIPP)/Netsend (collectively, the “Software Services”).

For the purpose of this Privacy Policy, “Personal Information” means any information relating to an identified or identifiable individual or that can reasonably be used to identify an individual.

1. Information We Collect

Personal Information Provided by You

  • Communication Information. If you contact us directly (e.g., via email, phone, etc.) or fill out information on our Services (e.g., to ask a question via our online contact form, to apply for a job on our career page etc.), we may collect your name, email address, phone number, company, job title, postal address, the content of your inquiry, the services related to your interest, date and time of your message and any attachments thereto, and other information you may directly provide to us. If you post a public comment on our Site, we ask you to provide your name and email address. Without this information we may not be able to answer your question or process your request.
  • Business Contact Information. When you do business with us or use our Services, we may receive professional contact details of employees and other individuals associated with our customers, partners, and vendors, such as first and last name, email address, phone number, title and department, and other information relevant to, and necessary for us to manage a particular business relationship or provide you with access to the Services.
  • Support Services Information. When you request technical support services through our support portal, via email, via an IT helpdesk ticket or via our call center, we will process your contact information, such as name, email address, phone number and the country in which you are operating as well as information on the reasons for your support request. Without this information we may not be able to answer your support request.

Personal Information Provided by Customers & Partners

  • Customer Data. Our Customers may provide us with your Personal Information through their use of the Software Services. As described above, each Customer is responsible for ensuring it has the necessary rights to collect and transfer the Customer Data for Corcentric’s use in providing the Services.
  • Other Information from Third Party Services & Partners. Corcentric works with various partners and third parties. Such partners may provide Corcentric with your Personal Information in their provision of the services to Corcentric.

Information Collected via Automated Means

  • Log Data and Usage Data. Our Services may automatically collect information about your computer hardware and software, including IP address, browser type, domain names, the files viewed, operating systems, access time, and websites or services you visited before accessing the Services. This information is gathered periodically to facilitate the improvement of the Services or to provide services or technologies to you. When you use the Services, Corcentric may also collect or measure data and information regarding your interaction with content, including, by way of example, counts of views of segments, frequency of views, bookmarks into content, links you view or interact with, and other statistical analysis.
  • Third Party Buttons. We implement third party buttons (such as LinkedIn “like” or “share” buttons) on our Site that may allow third parties to collect information about you through such third parties’ browser cookies, even when you do not interact with the button. To find out how you may opt-out of these cookies, please refer to the Disabling Cookies section below.
  • Third Party Advertising Companies. We also implement third-party content or advertising on the Site that may use clear gifs or other forms of web beacons, which allow the third-party content provider to read and write cookies to your browser in connection with your viewing of the third party content on the Site. Please note that there are no third party advertising cookies in our Software Services. For more information on how to opt-out of receiving web-based personalized ads, please see the Disabling Cookies section below.
  • Cookies. Our Services collect and store information that is generated automatically as you use it, including your preferences and anonymous usage statistics. Our Services may use “cookies” or similar technologies (e.g., “clear gifs” or “web beacons”) to personalize your online experience and improve our products and services. You can find more information about our use of cookies in the Cookies section.

2. How We Use the Information We Collect

We use Personal Information we collect on the Services in a variety of ways in providing services and operating our business, including the following:

  • Facilitating and Improving Our Services. To operate, maintain, enhance and provide all features of the Services, to provide services and information that you request, to respond to comments and questions and otherwise to provide support to users.
  • Analytics and Services Improvement. To understand and analyze the usage trends and preferences of our users, to improve the Services, and to develop new services, features and functionality.
  • Tailored User Experience. To (i) personalize our Services, such as remembering your information so that you will not have to re-enter it during your visit or the next time you visit any of the Services; (ii) provide customized advertisements on the Services, content, and information; (iii) monitor and analyze the effectiveness of our services and third-party marketing activities; (iv) monitor aggregate usage metrics such as total number of visitors and pages viewed; and (v) track your entries, submissions, and status in any promotions or other activities on the Services.
  • Communicating with You. We may use your email address or other information (i) to contact you for administrative purposes such as customer service or technical-support, (ii) to send communications, including updates on promotions and events including webinars, email marketing campaigns relating to current or new similar products and services offered by us and by third parties we work with.
  • Product Development. We may use Personal Information, including information received from our customers, to learn about the use of our products, to diagnose issues, to improve our products and to develop new products and services.
  • Billing, Account Management and Administrative Matters. We may need to contact you for invoicing, account management, or other related reasons and we use your information to help us keep track of billing and payments and manage our accounts.
  • Legal. We may use your Personal Information to defend our legal rights, to comply with our legal obligations and internal policies, resolve disputes, and enforce our agreements.

Retention of Personal Information

We retain Personal Information only for a reasonable period of time as required for us to provide the Services. We take measures to delete or de-identify Personal Information when it is no longer necessary for the purposes for which it was collected, unless we are required by law to keep this information for a longer period. In some cases, we may retain de-identified and aggregated information collected from you. We may also retain your Personal Information for purposes described in this Privacy Policy, including, but not limited to, pursuing legitimate business interests, complying with legal obligations, conduct audits, resolve disputes, and enforce our agreements.

3. How We May Disclose Information

We may share Personal Information with third parties in the following circumstances:

  • Service Providers. We work with third party service providers to make our Site available to visitors and provide our Services to you and our Customers. These services may include website analysis, application development, hosting, maintenance, marketing and development, among others. These third party service providers may have access to or process your Personal Information as part of providing those services for us. We require that they use your Personal Information consistent with this Privacy Policy.
  • Advertising and Analytics Partners. We may make certain information available to third parties for analytics purposes, including: (i) for business or marketing purposes, such as to track sales leads; or (ii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Services. Typically, this information is aggregated, or otherwise de-identified Personal Information.
  • Social Networking and Other Websites. The Site may allow you to share information, including Personal Information, with social networking websites, such as LinkedIn and Twitter, by posting information to these websites through links available on the Site. We do not share your Personal Information with these social networking sites unless you have authorized us to do so. The use of your Personal Information by any social networking websites will be governed by their privacy policies, and you may be able to modify your privacy settings on their websites.
  • Third Party Services. If third party services are enabled or integrated with the Services, Corcentric may share information with such third party services for purposes of allowing the integration and providing the Services.
  • Legal. We reserve the right to disclose your Personal Information that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Services and any facilities or equipment used to make the Services available, (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others and (vi) to comply with state and federal laws, in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
  • Mergers and Other Reorganizations. Information about our users, including Personal Information, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
  • Affiliates. Corcentric may share your Personal Information with its corporate affiliates, parents, and subsidiaries.

4. Cookies

Cookies and How We Use Them

Cookies are small text files containing a string of alphanumeric characters that can be stored on a device when you visit a website. When you visit or use the Services, we and our third-party service providers receive and record information on our server logs from your browser, including your IP address, and from cookies and similar technologies. This information may include Personal Information, such as your IP address, web browser and/or device type, the web pages that you visit just before or just after you use the Services, as well as information about your interactions with the Services, such as the time of your visit and where you have clicked.

Cookies help us improve your experience by allowing us to distinguish you from other users, store your preference, and otherwise personalize your Service settings. Cookies also allow us to measure and analyze your use of the Services and help us provide better services to you.

Types of Cookies

Where required by applicable law, we obtain your consent to use cookies. Below is an overview of the types of cookies we and our third parties may use to collect Personal Information.

  • Necessary & Functional cookies. Some cookies are strictly necessary to make our Services available to you. For example, to provide the chat and login functionality, and to remember your consent and privacy choices. We cannot provide you with the Services without these types of cookies.
  • Analytical cookies. We also use cookies for website analytics purposes in order to operate, maintain and improve Services. We may use our own analytics cookies or use third party analytics providers such as Hotjar, Google Analytics, Marketo, and Optimizely to collect and process certain analytics data on our behalf. These third parties may also collect information about your use of other websites, apps, and online resources.
  • Advertising cookies.
    • Third Party Advertising Cookies. We work with third-party advertising partners such as Google Ads to show you ads about Corcentric that we think may interest you on third party websites and apps, as well as assist us with data collection, reporting, ad-response measurement, analytical information, and delivery of marketing messages and advertisements. To do so, we and our advertising partners may place and access cookies through our Site and otherwise collect or access Personal Information collected over time and across different online services. Our advertising partners may also collect information about your use of other websites, apps, and online resources.
    • Corcentric Advertising Cookies. We may use cookies for purposes of providing Corcentric marketing to you across our different Software Services offerings. We do not, however, provide information collected by Corcentric Advertising Cookies to third parties for their own marketing and advertising purposes.

For a list of cookie types used in the Software Services, please click here.

Disabling Cookies

You have the following choices with regard to the use of cookies and similar technologies:

  • Browser Settings. Many web browsers allow you to manage your preferences relating to cookies. You can set your browser to refuse cookies or delete certain cookies. You may be able to manage other technologies in the same way that you manage cookies using your browser’s preferences. Please note that if you choose to block cookies, doing so may impair the use of our Services.
  • Google Analytics Cookies. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/, and opt-out by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout or via Google’s Ads Settings or Ad Settings for mobile apps.
  • Third Party Advertising Cookies. Some of our advertising partners are members of the Network Advertising Initiative (NAI) or the Digital Advertising Alliance (DAA), or the European Interactive Digital Advertising Alliance’s Consumer Choice (https://www.youronlinechoices.eu). If you prefer to not receive targeted advertising, you may be able to opt out of some network advertising programs by visiting the Digital Advertising Alliance Opt-Out Page and the Network Advertising Initiative Opt-Out Page. You can visit your device’s settings or install the AppChoices app to learn more about how you may opt out of receiving personalized ads in mobile apps. Please note that even if you choose to remove your Personal Information, you will still see advertisements, but these may not be specifically tailored to you. Additionally, many network advertising programs allow you to view and manage the interest categories they have compiled from your online browsing activities. These interest categories help determine the types of targeted advertisements you may receive.
  • Do Not Track. We do not specifically respond to Do Not Track (“DNT”) signals. However, some third party websites do keep track of your browsing activities, including across other websites on the Internet, which enables these websites to tailor what they present to you. Your browser may allow you to set a DNT signal on your browser so that these third parties know you do not want to be tracked.

5. Your Rights and Choices

Opt-Out & Unsubscribe. You may unsubscribe at any time from our marketing communications by following the instructions contained within the email. You may also opt out from receiving commercial emails from us, and any other promotional communications that we may send to you from time to time, by sending your request to us by email at privacy@corcentric.com or by writing to us at the address given at the end of this Privacy Policy.

If you are a visitor from the EU/EEA or from California, please check the sections Visitors from the EU/EEA, or Visitors from California, as applicable.

Please be aware that if you opt out of receiving commercial emails from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten (10) business days for us to process your request, and you may receive promotional communications from us that you have opted out from during that period. Additionally, even after unsubscribing we may continue to send administrative messages as necessary for us to provide you with services.

6. Visitors from EU/EEA

If you are a visitor from the EU/EEA, you have additional rights available to you with respect to your Personal Information. This section describes Corcentric’s obligations to you with respect to our collection and use of your Personal Information and your rights related to such Personal Information.

Legal Basis For Our Use of Your Personal Information

If you are located in the EU/EEA, and where Corcentric acts as a Controller of your Personal Data, we only process your “Personal Information” based on a valid legal basis, as follows. For the purposes of this section, Personal Information has the same definition as “Personal Data” under the GDPR:

  • Consent. You have consented to the use of your Personal Information, for example to send marketing communications, and to collect information via cookies and similar technologies.
  • Contract. We need your Personal Information to provide you with Corcentric’s products and services, including for account registration or to respond to your inquiries.
  • Legal Obligation. We have a legal obligation to use your Personal Information, for example for compliance with tax law and bookkeeping obligations.
  • Legitimate Interest. We or a third party, have a legitimate interest in using your Personal Information. In particular, we have a legitimate interest in using your Personal Information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our products and services. We only rely on our or a third party’s legitimate interests to process your Personal Information when these interests are not overridden by your rights and interests.

Where Corcentric is acting as a Processor of your Personal Data on behalf of a Customer or related party, Corcentric relies on its legitimate interest to process such Personal Data and will only process the Personal Data upon the instruction of our Customers.

Your Rights

Where Corcentric acts as a Controller of your Personal Data, you have the following data protection rights with respect to Personal Data Corcentric collects about you:

  • Access, Correction, or Deletion. You can request from Corcentric that we provide you with the Personal Information we have collected about you. You may also request that we correct or delete your Personal Information. Please note, however, that Corcentric may retain Personal Information in order for us to meet our legal or regulatory compliance requirements.
  • Transfer of your Personal Data. You may ask Corcentric to provide your Personal Information to a third party in a commonly used, machine readable format.
  • Objection and Restriction. Where we process your Personal Information based on legitimate interest, you may object to our processing of your Personal Information. You may also ask that Corcentric restricts from further processing your Personal Information.
  • Consent Withdrawal. Where Corcentric has relied on your consent to process your Personal Information, you can withdraw your consent at any time.

To exercise any of these rights, please contact us at privacy@corcentric.com. We will respond to your request without undue delay and notify you of the action we have taken.

If you take the view that Corcentric is not processing your Personal Data in accordance with the requirements in this Privacy Policy or under applicable data protection laws, you can at any time lodge a complaint with the data protection authority of the EEA country where you live or with the data protection authority of the country or state where Corcentric has its registered seat.

Transfers

The Site is hosted in the United States. If you visit the Site from outside of the United States, please note that your Personal Information will be transferred to the United States, which may not have the same data protection laws as your country. We take reasonable measures to ensure that if your Personal Information is transferred outside of the EEA and the UK appropriate controls are in place to adequately protect your Personal Information and that such protection is in accordance with applicable data protection laws and regulations. Personal Information relating to individuals in the EEA, the United Kingdom, and Switzerland is controlled by Corcentric SAS. Corcentric’s international transfer of Personal Information collected in the EEA, the United Kingdom, and Switzerland is governed by the European Commission-approved Standard Contractual Clauses (the “SCCs”). The SCCs are contractual commitments made between companies transferring Personal Information with respect to the privacy and security of such Personal Information.

As it relates to any Personal Information included in the Customer Data we may receive from our Customers, our Customer is responsible for ensuring it has all necessary rights to provide and transfer the Personal Information to us. Where our Customer is providing us with Personal Data collected in the EEA, and we are transferring such Personal Data to the United States or other jurisdiction deemed as having inadequate protections, we enter into SCCs with such Customer for the purposes of the transfer.

If you have any questions, concerns or complaints about our data practices, you may contact us at the email or address listed in the Contact Information section, or you may reach out to our Data Protection Officer (DPO), also listed in the Contact Information section.

7. Visitors from California

If you are a resident of California, you have a right to opt-out of the “sale” of your Personal Information. Corcentric does not “sell” the Personal Information we collect from you from your interactions with our Services. However, “sale” is broadly defined under the California Consumer Privacy Act (“CCPA”). Sharing of your Personal Information with our marketing partners and other third parties for advertising purposes may be considered a sale under the CCPA. To the extent this sharing of your Personal Information is considered a “sale” under the CCPA, you may opt out of such sale by clicking the “Do Not Sell My Information” text link in the footer or by clicking here. You may also opt-out of such sale by contacting us at privacy@corcentric.com.

8. Other Important Information

Data Security

We use physical, organizational, and technical safeguards that are designed to improve the integrity and security of Personal Information that we process. We take steps to ensure that your Personal Information is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. We do not accept liability for unintentional access, use or disclosure.

Third Party Services

The Services may contain features or links to web sites, services, and/or applications provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Services. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Services. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

Children’s Privacy

Our Services are not directed to children under the age of thirteen (13), and we do not knowingly collect Personal Information from children under the age of thirteen (13). If you are under the age of thirteen, you must ask your parent or guardian for permission to use the Services. We will take steps to delete it if we learn we have collected Personal Information from children under thirteen (13). If you learn that your child has provided us with Personal Information without your consent, then you may alert us at privacy@corcentric.com. If we learn that we have collected any Personal Information from children under thirteen (13), then we will promptly take steps to delete such Personal Information and terminate the child’s account.

9. Changes and Updates

Please revisit this page periodically to stay informed of any changes to this Privacy Policy, which we may update from time to time. If we modify this Privacy Policy, we will make it available through the Site, and indicate the date of the latest revision. If we materially change the ways in which we use or share Personal Information previously collected from you through the Services, we will notify you through the Site, through our Software Services, by email, or other communication. Your continued use of the Services after the revised Privacy Policy has become effective indicates that you have read, understood and agreed to the current version of this Privacy Policy.

10. Contact Information

Please contact us with any questions or comments about this Privacy Policy, your Personal Information, and our privacy practices by email at privacy@corcentric.com or by postal mail at:

Corcentric, LLC
ATTN: Senior Vice President of Marketing
200 Lake Drive East, Suite 200
Cherry Hill, NJ 08002

Data Protection Officer: Bruno Courbet; dpo@corcentric.com