In this European Economic Area (“EEA”) Supplemental Privacy Statement (“Supplemental Statement”), we, Zuora, Inc. (“Zuora”), provide to residents of the EEA this Supplemental Statement, which contains additional information to supplement the Zuora Privacy Statement (“Statement”) (https://www.zuora.com/privacy-statement/). Zuora, Inc. operates the Site and is the controller of any personal data collected processed on the Site. The EU representative of Zuora, Inc. is Zuora UK Limited, 25 North Row, London, United Kingdom, W1K 6DJ, UK. Unless defined specifically in this Supplemental Statement, capitalized terms shall have the meaning set forth in the Statement.
Purposes and Legal Bases for Processing
We process your personal data based on several different legal bases, which include contract (where processing is necessary to provide you services or support, respond to your request or for the performance of a contract), legitimate interests (such as the security and safety of the Site, our IT and users of the Site, to prevent and detect fraud, and to track your activities on the Site for purposes of personalization, optimization and advertising), compliance with legal obligations and consent (for placing certain cookies on your device or sending you marketing communications).
Marketing Communications to You
On the Site, you can register to receive newsletters or other information on the products or services of Zuora and our affiliated companies. During registration, we ask you to provide us with certain information, including your contact information, company, job title and location. We may also log and store additional personal information such as the date, time and IP address associated with your registration. If you are located in certain jurisdictions such as Germany, we verify the authorized use of an email address by sending an email to confirm your registration via a contained link. You may withdraw your consent at any time by following the unsubscribe link in email communication to you or by sending us an email at email@example.com.
Types of Third Parties to Which We Disclose Personal Data and Purposes
We disclose your personal data to third parties, as required or permitted by applicable law. We share personal data of EEA residents (“EEA Data”) with our subsidiaries, affiliates and contractors, who process personal data on behalf of Zuora. We also provide information to our channel partners, such as distributors and resellers, to fulfill product and information requests, and to provide customers and prospective customers with information about Zuora and its products and services. We also share EEA Data with other third parties for the purposes for which we receive the EEA Data (e.g., performance of contractual obligations and rights), and we may also disclose EEA Data where we are legally required to disclose (e.g., under statutes, contracts or otherwise) or where the disclosure is permitted by law and we have a legitimate business interest in such disclosure.
Data Transfers to Recipients Outside of the EU/EEA
Zuora and many of our affiliated companies and third-party service providers are located outside the EU/EEA where data protection laws differ from the EU/EEA. To ensure an adequate level of protection of your personal data under EU/EEA law, Zuora participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework (https://www.privacyshield.gov) as further explained in our Privacy Shield Notice (https://www.zuora.com/privacy-shield-notice/).
We also enter into data processing and data transfer agreements with our affiliated companies and third-party service providers outside of the EU/EEA that incorporate the provisions of the Standard Contractual Clauses approved by the EU Commission or implement other appropriate safeguards with them. You can ask for more information at firstname.lastname@example.org.
We will retain your information for as long as needed to provide you services and fulfill the purposes described in this Supplemental Statement. We will retain and use your information as required or permitted by applicable law, including to comply with our legal obligations, resolve disputes, and enforce our agreements. More information about retention is available by contacting email@example.com.
Your Rights Regarding Processing of Your Personal Data
Subject to the conditions set out in the applicable law, you have the rights to understand how your personal data is processed and access, download, update or change, delete or restrict certain processing of the personal data which Zuora collects about you through the Site. If you need to update, change, remove or have any other request related to personal data that we control, you can do so by contacting firstname.lastname@example.org. In the case of concerns, you also have the right to contact the local data protection authority.
Your Provision of Personal Data to Us
Your use of the Site and your provision of personal data is purely voluntary. You can stop using the Site or, where applicable, opt out of certain processing activities while on the Site as described in this Supplemental Statement. If you ask us to provide a service or want to enter into a contract with us, providing us with your related personal information is necessary for us to be able to enter into the contract with or provide any contractual services to you.
We may update this Supplemental Statement periodically and without prior notice to you to reflect changes in our personal data practices. If we make material changes to this statement, we will notify you here, by email, or by means of a notice on our home page prior to the change becoming effective. You should review the Supplemental Statement each time you visit our Site to learn of any changes.
If you have questions related to our Supplemental Statement you may contact us at:
3050 S. Delaware Street, Suite 301
San Mateo, CA 94403
Effective May 25, 2018.