GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
, Email:
[email protected]
for the use of the Internet platform and IT solution ExpertBox.io.
As of March 1, 2024
(A) Go Consulted acts as a Data Processor.
(B) Expert acts as a Data Controller.
(C) The Data Processor provides the right to use the ExpertBox platform, which implies the processing of user personal data for the Data Controller.
(D) The Data Controller and the Data Processor seek to implement a data processing policy that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), CCPA (California Consumer Privacy Act), The Privacy Act of 1974 (5 U.S.C. 552a) etc) and Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data as it will be amended by its Protocol CETS No. 223.
1.1 Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
1.1.1 "Policy" means this Data Processing Policy;
1.1.2 "Users Personal Data" means any Personal Data processed by the Processor on the ExpertBox platform;
1.1.3 "Contracted Controller" means the Expert;
1.1.4 "Data Protection Laws" means EU and U.S. Data Protection Laws and, to the extent applicable, the data protection or privacy laws of any other country;
1.1.5 "EEA" means the European Economic Area;
1.1.6 "EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State The Privacy Act of 1974 (5 U.S.C. 552a) etc) and Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data as it will be amended by its Protocol CETS No. 223 and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR;
1.1.7 "GDPR" means EU General Data Protection Regulation 2016/679;
1.1.8 "Data Transfer" means:
1.1.8.1 a transfer of Personal Data from users to a Contracted Processor;
1.1.9 "Services" means the services the Expert provides.
1.2 The terms, "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
2.1 Controller shall:
2.1.1 comply with all applicable Data Protection Laws in the Processing of users Personal Data; and
2.1.2 Do not process personal data of users, except in accordance with its permission.
2.2 The Controller instructs the Processor to process Users Personal Data.
3.1 ExpertBox, acting as a Processor, takes reasonable measures to ensure the reliability of any employee, agent, or contractor of any Processor under contract who may have access to Users' Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know/gain access to the relevant Users' Personal Data, strictly necessary for consultation purposes, as well as to comply with Applicable Laws in the context of that person's obligations to the Data Controller, ensuring that all such individuals are subject to confidentiality obligations or professional or legislative confidentiality obligations.
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Users Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.
4.2 In assessing the appropriate level of security, the Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
5.1 Processor shall not appoint (or disclose any Users Personal Data to) any Subprocessor unless required or authorized by the Controller.
6.1 Taking into account the nature of the Processing, Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller obligations, as reasonably understood by Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
6.2 Processor shall:
6.2.1 promptly notify Controller if it receives a request from a Data Subject under any Data Protection Law in respect of Users Personal Data; and
6.2.2 ensure that it does not respond to that request except on the documented instructions of Controller or as required by Applicable Laws to which the Processor is subject, in which case Processor shall to the extent permitted by Applicable Laws.
7.1 Processor shall notify Controller without undue delay upon Processor becoming aware of a Personal Data Breach affecting Users Personal Data, providing Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.
7.2 Processor shall cooperate with the Controller and take reasonable commercial steps as are directed by Controller to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
8.1 Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Controller reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Users Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
8.2 Subject to this section 8, Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this Policy, and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller in relation to the Processing of the Users Personal Data by the Experts.
8.3 Information and audit rights of the Controller only arise under section 8.2 to the extent that the Policy does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.
9.1 Subject to this section 9 Processor shall promptly and in any event within 10 business days of the date of cessation of any Services involving the Processing of Users Personal Data (the "Cessation Date"), delete and procure the deletion of all copies of those Users Personal Data.
9.2 Processor shall provide written certification to the Controller that it has fully complied with this section 9 within 10 business days of the Cessation Date.
10.1 If personal data processed under this Agreement is transferred from a country within the European Economic Area to a country outside the European Economic Area, the Data Controller and the Data Processor shall ensure that the personal data are adequately protected. To achieve this, the Data Controller and the Data Processor shall, unless agreed otherwise, rely on EU approved standard contractual clauses for the transfer of personal data.
11.1 This Agreement is governed by the laws of the Delaware State.
11.2 Any dispute arising in connection with this Agreement, which the Data Controller and the Data Processor will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of the Republic of Estonia.
12.1 Service Providers can choose to permit or restrict Third Party Services for their ExpertBox account. Third Party Services are software that integrate with our Services. Once enabled, the provider of a Third Party Service may share certain information with ExpertBox with the purpose to facilitate the integration. We do not, however, receive or store passwords for any of these Third Party Services when connecting them to the Services. Please check your privacy settings on the Third Party Service to review and modify what is shared with ExpertBox.
Calendar synchronisation
12.2 When using a Third Party Service (such as Google) to connect your calendar, the Third Party Service may provide us with your Third Party Service account information on your behalf, such as your name and email address (we don’t collect or store passwords you use to access Third Party Services). ExpertBox calendar integration accesses the following third-party service information to facilitate managing the availability of the Service Provider in ExpertBox:
12.3 We do receive or not store the names and email addresses of other participants, or any other details about the events in your connected calendar. Also, the above mentioned information will be displayed only in the Authorised Service Provider's profile and will not be disclosed to the public.
GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
, Email:
[email protected]
For California residents only
GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
,
Email:
[email protected]
, for the use of the Internet platform and IT solution ExpertBox.io.
As of March 1, 2024
This CCPA Privacy Policy for California Residents (this “Privacy Policy”) supplements
the information contained in Privacy Policy for Non-EU countries
(
https://expertbox.io/policies#non-eu
)
and applies solely to all
visitors, users, and others who reside in the State of California (“users” or “you”).
We adopt this Privacy Policy to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this Privacy Policy. All other terms, unless otherwise specified in this Privacy Policy, shall have the definitions assigned to them in the Privacy Policy.
This Privacy Policy does not apply to employment-related personal information collected from California-based employees, job applicants, contractors, or similar individuals.
Where noted in this Privacy Policy, the CCPA temporarily exempts personal information reflecting a written or verbal business-to-business communication (“B2B personal information”) from some of its requirements.
We collect information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“personal information”). Personal information does not include:
In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:
Category | Examples | Collected |
---|---|---|
Identifiers | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. | Yes |
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). | A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. | Yes |
Protected classification characteristics under California or federal law. | Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | No |
Commercial information. | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies | Yes |
Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | No |
Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. | Yes |
Geolocation data. | Physical location or movements. | No |
Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | No |
Professional or employment-related information. | Current or past job history or performance evaluations. | No |
Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | No |
Inferences drawn from other personal information | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | No |
We obtain the categories of personal information listed above from the following categories of sources:
We may use or disclose the personal information we collect for one or more of the following purposes:
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable user request (see EXERCISING ACCESS, DATA PORTABILITY, AND DELETION RIGHTS), we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
We do not provide these deletion rights for B2B personal information.
Service Providers can choose to permit or restrict Third Party Services for their ExpertBox account. Third Party Services are software that integrate with our Services. Once enabled, the provider of a Third Party Service may share certain information with ExpertBox with the purpose to facilitate the integration. We do not, however, receive or store passwords for any of these Third Party Services when connecting them to the Services. Please check your privacy settings on the Third Party Service to review and modify what is shared with ExpertBox.
Calendar synchronisation
When using a Third Party Service (such as Google) to connect your calendar, the Third Party Service may provide us with your Third Party Service account information on your behalf, such as your name and email address (we don’t collect or store passwords you use to access Third Party Services). ExpertBox calendar integration accesses the following third-party service information to facilitate managing the availability of the Service Provider in ExpertBox:
We do receive or not store the names and email addresses of other participants, or any other details about the events in your connected calendar. Also, the above mentioned information will be displayed only in the Authorised Service Provider's profile and will not be disclosed to the public.
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable user request (see EXERCISING ACCESS, DATA PORTABILITY, AND DELETION RIGHTS), we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
We do not provide these deletion rights for B2B personal information.
To exercise the access, data portability, and deletion rights described above, please submit a verifiable user request to us by either:
Only you, or someone legally authorized to act on your behalf, may make a verifiable user request related to your personal information. You may also make a verifiable user request on behalf of your minor child.
You may only make a verifiable user request for access or data portability twice within a 12-month period. The verifiable user request must:
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.
Making a verifiable user request does not require you to create an account with us.
We will only use personal information provided in a verifiable user request to verify the requestor’s identity or authority to make the request.
We endeavor to respond to a verifiable user request within forty-five (45) days of its receipt. If we require more time (up to 45 or 90 days), we will inform you of the reason and extension period in writing.
Any disclosures we provide will only cover the 12-month period preceding the verifiable user request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable user request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our websites that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to [email protected]
We reserve the right to amend this Privacy Policy at our discretion and at any time. When we make changes to this Privacy Policy, we will post the updated Privacy Policy on the Website and update the Privacy Policy effective date. Your continued use of our websites following the posting of changes constitutes your acceptance of such changes.
If you have any questions or comments about this Privacy Policy, the ways in which Go Consulted collects and uses your information described here and in the Privacy Policy, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at:
Phone: + 1 302 56 50 146
Website: https://expertbox.io
Email: [email protected]
Postal Address: 200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
For European Union and ЕАСТ, EFTA countries (including Great Britain, Switzerland, Norway, Iceland and Liechtenstein)
GO CONSULTED INC
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
,
Email:
[email protected]
for the use of the Internet platform and IT solution ExpertBox.io.
As of March 1, 2024
The responsible party within the meaning of the applicable data protection laws is:
GO CONSULTED INC
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
,
Email:
[email protected]
for the use of the Internet platform and IT solution ExpertBox.io.
Last updates as of: March 1, 2024
1.1. Go Consulted respects your privacy, and we will protect any information you give to us. We have developed this privacy policy to explain our practices, and this policy is incorporated into, and subject to, our Privacy Policy and Terms of Use.
You will find out what information is available when using the services of Go Consulted including the use of the ExpertBox website
(
https://expertbox.io
)
("Website")
and App
(
https://app.expertbox.io
)
("App") that are collected, processed or used.
1.2. Go Consulted will process and use the data provided by the user as part of the registration on the ExpertBox Platform and/or the use of the services solely for the purpose of providing services (contract performance) and in accordance with General Data Protection Regulation (“GDPR”).
1.3. For the use of our services, only these data protection provisions, supplemented by our terms of use, in the most recent version, are relevant.
1.4 All data stored by us or any order processor will be best protected against unauthorized access, loss, destruction, deletion, alteration or dissemination of your data by unauthorized persons using current security standards.
1.5. All personal data collected by us are processed exclusively within AWS server https://aws.amazon.com/aup/ and Stipe https://stripe.com/privacy for providing payments and are, therefore, subject to appropriate data protection provisions. Transmission of data to companies outside the European Union will not take place without your explicit consent. This also applies to service Providers commissioned by us for data processing.
2.1 GO CONSULTED INC, 200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA operates a web-based software solution called ExpertBox ("ExpertBox"), which offers service Providers ("experts") a digital customer interaction opportunity. This includes appointment management and booking, execution of video calls as well as payment and invoicing. Visitors ("visitors") as well as Customers ("clients") of the service Providers ("experts") thus have the opportunity to book appointments with experts online and to process them using ExpertBox's software solution.
2.2 In addition to the ExpertBox website and app, the software solution is also available via integration on websites of experts and on existing platforms.
When you access ExpertBox services as a visitor, even without logging in or logging in, server log files are sent from your server to ExpertBox's web server, which is technically necessary for accessing information. The following data is collected as part of the server log files:
This data can not be assigned to specific persons for ExpertBox and a merger of this data with other data sources will not be made. ExpertBox has no influence on the automatic transmission of this data. However, you can set this automatic data transfer directly in your device or browser and restrict it if necessary. The o.g. Server log files are stored for 12 days, after which all collected IP addresses are anonymized and used only for quality assurance, web site optimization and statistical purposes.
We retain your information for as long as needed for our functions or activities or to comply with our legal obligations (such as reporting to regulatory authorities), to resolve disputes and to enforce our rights. We also may retain your information to support our business operations and develop our Services. The criteria used to determine our data retention periods include: (i) how long the personal data is needed to provide the services and operate the business; (ii) the type of personal data collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the data (e.g., mandatory data retention laws, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation or disputes.) When we no longer need to use your information, we will take steps to properly anonymize or destroy it. We may retain information that is not personally identified to an individual User, including without limitation anonymized data and aggregate information, at our discretion.
Under certain circumstances, you have rights under data protection laws in relation to your personal data.
As a data subject you have the following rights:
Types of personal data we collect
ExpertBox collects and processes the following types of information:
For the purpose of maintenance of employment records:
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
First name, last name, patronymic (if applicable), tax number, registration address, personal e-mail, phone number, contact messenger details, position, performance level (seniority), bank account details, department |
1) Contract 2) Legal obligation |
1) Identification of an employee for the purpose of establishing employment relations and fulfilling payment obligations 2) Fulfillment of obligations established by law, including tax control |
No longer than 1 year after the end of the employment relationship | Data subject |
Company, cloud storage systems operated by well-known providers; Local authorities in case of legal obligation; HRM systems |
Passport scan, tax number scan, bank account details | Legal obligation | Fulfillment of obligations established by law, including tax control | No longer than 1 year after the end of the employment relationship | Data subject |
Company, cloud storage systems operated by well-known providers; Local authorities in case of legal obligation; HRM systems operated by well-known providers |
Date of birth | Legitimate interest | Organization for the birthday congratulations. | During employment | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
link to social profiles | Legitimate interest | Verification of compliance with non-compete obligations after dismissal | No longer than 1 year after the end of the employment relationship | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Education, diplomas, certificates, employment history, work experience, CV, references, contracts and amendments to the contracts, start date, end of probation date | Legitimate interest | Employee’s skill set verification | During employment | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
job satisfaction surveys, reasons for termination of the employment | Legitimate interest | Improving the process of interaction with human resources in the company | During employment | Data subject, HR department |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Emergency contacts of the employee (name and telephone of a relative) | Legitimate interest |
Communication in emergencies: In the event of a natural disaster, fire, or other emergency that affects the workplace, companies need a way to reach employees' emergency contacts to inform them of the situation and ensure their safety. Medical emergencies: If an employee becomes seriously ill or incapacitated while at work, the emergency contact information can help medical professionals get in touch with someone who can provide important medical history or consent for treatment, especially if the employee is unable to communicate. Contacting employees after hours: In cases such as schedule changes, having an emergency contact can facilitate communication with an employee when they are not at work. Family emergencies: Sometimes, employees may need to be reached in the event of a family emergency or personal crisis, and having their emergency contact information allows the company to provide support or time off as needed. |
During employment | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Sick-leave information, for example medical report (May contain diagnosis, treatment terms, test results) |
Legal obligation Processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorized by law |
Maintain accurate records of employee absences, especially for payroll, HR, and legal purposes. Sick leave and medical reports serve as documentation to support the legitimacy of the leave and to track attendance. Compliance with labor laws: Depending on local labor laws, company has legal obligations to request medical documentation for extended or frequent sick leave. This helps ensure compliance with statutory requirements and protects both the employee and the employer. |
During employment | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
For the purpose of maintenance of records for individual contractors/entrepreneurs:
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
First name, last name, patronymic (if applicable), tax number, registration address, personal e-mail, phone number, contact messenger details, position, performance level (seniority), bank account details, department |
1) Contract 2) Legal obligation |
Identification of a contractor for the purpose of establishing contractual relations and fulfilling payment obligations Fulfillment of obligations established by law, including KYC and AML |
No longer than 2 years after the end of the contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; Local authorities in case of legal obligation; HRM systems |
Passport scan, tax number scan, bank account details, individual entrepreneur documents scan | Legal obligation | Fulfillment of obligations established by law, including tax control | No longer than 2 years after the end of the contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; Local authorities in case of legal obligation; HRM systems operated by well-known providers |
Date of birth | Legitimate interest | Organization for the birthday congratulations. | During contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
link to social profiles | Legitimate interest | Verification of compliance with non-compete obligations after dismissal | No longer than 1 year after the end of the contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Education, diplomas, certificates, employment history, work experience, CV, references, contracts and amendments to the contracts, start date, end of probation date | Legitimate interest | Contractor’s skill set verification | During contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Emergency contacts of the contractor (name and telephone of a relative) | Legitimate interest |
Medical emergencies: If an employee becomes seriously ill or incapacitated, the emergency contact information can help medical professionals get in touch with someone who can provide important medical history or consent for treatment, especially if the contractor is unable to communicate. Contacting contractors in case of non-communication: In cases such as schedule changes, having an emergency contact can facilitate communication with a contractor when they are not available. Family emergencies: Sometimes, contractors may need to be reached in the event of a family emergency or personal crisis, and having their emergency contact information allows the company to provide support or time off as needed. |
During contractual relationship | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Sick-leave information, for example medical report (May contain diagnosis, treatment terms, test results) | Explicit consent | Sick Leave bonus payment | No longer than 1 month after the payment | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
For the purpose of maintenance of records for recruitment process:
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
First name, last name, patronymic (if applicable), tax number, registration address, personal e-mail, phone number, contact messenger details, position, performance level (seniority) |
1) Contract 2) Legitimate interest |
1) Identification of a candidate for the purpose of validation, communication 2) Identification of a candidate for the purpose of background check |
No longer than 2 years after the end of last communication with company | Data subject | Company, cloud storage systems operated by well-known providers; |
Passport scan, tax number scan, individual entrepreneur documents scan | Contract | Identification of a candidate for the purpose of establishing working/contractual relations | During contract conclusion/hiring process. | Data subject |
Company, cloud storage systems operated by well-known providers; Local authorities in case of legal obligation; HRM systems operated by well-known providers |
link to social profiles | Legitimate interest | Identification of a candidate for the purpose of validation, communication, to provide additional offers about open vacancies that may be interesting for you | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Education, diplomas, certificates, employment history, work experience, CV, references, contracts and amendments to the contracts, start date, end of probation date | Legitimate interest | Candidate skill set verification | During contract conclusion/hiring process. | Data subject |
Company, cloud storage systems operated by well-known providers; HRM systems operated by well-known providers |
Data from the criminal records register, data from the register of court cases, data of seizure of property and claims by authorities | Legitimate interest | Identification of a candidate for the purpose of background check. This information is very important from the point of view of establishing the candidate’s business reputation and his ability to provide services to the company | During contract conclusion/hiring process. | Official authorities information | Company, cloud storage systems operated by well-known providers |
English level test results | Legitimate interest | Candidate skill set verification | During contract conclusion/hiring process. | English level validator (tutor) | Company, cloud storage systems operated by well-known providers |
Recipients
Types of information
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
Name e-mail, phone number (optional) | Consent | Start of possible provision of business services | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
Name e-mail, phone number (optional) | Consent | Subscription to company news and promotional offers | Until consent is withdrawn | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
Browser information about visit | Legitimate interest | To improve the quality of company services and visit analytics | For the lifetime of the cookie | Data subject | Company, cloud storage systems operated by well-known providers; |
IP address in case of leaving a request for communication with a company representative | Legal obligation | To determine the country of a potential client in order to exclude business interactions with customers from countries subject to international sanctions regime | For the lifetime of the cookie | Data subject | Company, cloud storage systems operated by well-known providers; |
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
First name, last name, patronymic (if applicable), e-mail, phone number, contact messenger details, position | Contract | Identification of a potential client representative for communication | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
First name, last name, patronymic (if applicable), e-mail, phone number, contact messenger details, position | Contract | Entering personal data into draft agreements to regulate business relations | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
e-mail or messenger correspondence | Consent | Possibility of clarifying the details of negotiations to correctly offer the best service | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
Personal data | Legal basis | Purpose of processing | Storage period | Source | Categories of recipients |
---|---|---|---|---|---|
First name, last name, patronymic (if applicable), e-mail, phone number, contact messenger details, position | Contract | Identification of a potential client representative for communication | No longer than 2 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
First name, last name, patronymic (if applicable), e-mail, phone number, contact messenger details, position |
1) Contract 2) Legal obligation |
1) Personal data of the client’s representative is stored in contracts concluded with the company in order to verify at any time the powers of the representative and the procedure for fulfilling the contract 2) Fulfillment of the Company’s obligations to the authorities, during which the Company is obliged to transfer concluded contracts to government authorities |
No longer than 5 years after the agreement expiration | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
e-mail or messenger correspondence | Consent | Possibility of clarifying the details of negotiations to ensure the correct provision of services under agreement | No longer than 5 years after the end of last communication with company | Data subject |
Company, cloud storage systems operated by well-known providers; СRM systems operated by well-known providers |
The Company works only with individuals who are at least 18 years old.
This website uses cookies to better the user experience of its visitors. Where applicable, this website uses a cookie control system, allowing users to allow or disallow the use of cookies on their computer/device on their first visit to the website. This complies with recent legislative requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user’s computer/device.
Cookies are small files saved to a user’s computer/device hard drive that track, save, and store information about the user’s interactions and website use. They allow a website, through its server, to provide users with a tailored experience within the site.
Users are advised to take necessary steps within their web browser security settings to block all cookies from this website and its external serving vendors if they wish to deny the use and saving of cookies from this website to their computer’s/device’s hard drive.
This site uses the Lucky Orange analytics system to help improve usability and the customer experience. Lucky Orange may record mouse clicks, mouse movements, and scrolling activity. Lucky Orange may also record keystroke information that is voluntarily entered on this website. Lucky Orange does not track this activity on any site that does not use the Lucky Orange system. You can choose to disable the Lucky Orange service at https://www.luckyorange.com/disable.php Note that doing so will disable other features of the Lucky Orange system that this site employs, such as one-to-one support chat.
On our website (but not our app) Facebook pixels are implemented in order to present advertisements ("Facebook Ads") to prior visitors of our website as part of the Facebook Newsfeed. These Facebook pixels create a direct connection to the Facebook servers when visiting our website. It is transmitted to the Facebook server that you have visited our website. Facebook assigns this information to your personal Facebook user account. For more information on the collection and use of data by Facebook, as well as your rights in this regard and ways to protect your privacy, please refer to the privacy policy of Facebook at https://www.facebook.com/about/privacy
Alternatively, you can opt out of Facebook's remarketing feature by following this link: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen This requires registration on your personal Facebook profile.
We use the advertising tool "Google-Adwords" to promote our website. As part of this, we use the Google Analytics Conversion Tracking analytics service on our website, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA. When you reach our website through a Google ad, a cookie is placed on your device. These so-called "conversion cookies" are only valid for 30 days. If you visit certain pages of our website within this validity period, we and Google may recognize that you as a user clicked on one of our ads placed with Google and were redirected to our site. Any "conversion cookies" are only placed on our landing pages, but not on our app. The "conversion cookies" are used to generate visit statistics for our website, which informs us about the total number of users who have clicked on our ad. In addition, we learn which pages of our website were called up by the respective user afterwards. However, we do not receive any information that may conclude your personal identification.
You can prevent the transmission of data via "conversion cookies" in your browser settings and disable the automatic setting of cookies in general or just block the cookies from the domain "googleadservices.com". For more information about Google Adwords services and Google's privacy policy, please visit: https://policies.google.com/privacy
Users contacting this website or its owners do so at their own discretion and provide any personal details requested at their own risk. Your personal information is kept private and stored securely until such time that it is no longer required or has no use. Every effort has been made to ensure a safe and secure form to email submission process, but users are still advised that using such form to email processes are done at their own risk.
This website and its owners use information submitted to provide you with further information about the products and services they offer and to assist you in answering any questions or queries you may submit. This includes using your details to subscribe you to any email newsletter program the website operates, but only if this was made clear to you and your express permission was granted when submitting a form to email process or when you, the consumer, have previously purchased from or enquired about purchasing from the company a product or service that the email newsletter relates to. This is by no means an entire list of your user rights with regard to receiving email marketing material. Your details are not passed on to any third parties.
This website operates an email newsletter program to inform subscribers about products and services supplied by this website. Users can subscribe through an automated online process should they wish to do so at their own discretion. Some subscriptions may be manually processed through prior written agreement with the user.
Subscriptions are made in compliance with spam laws of the visitor’s country. All personal details relating to subscriptions are held securely and in accordance with the current data protection laws of the visitor’s country. No personal details are passed on to third parties or shared with companies or people outside of the company that operates this website.
Email marketing campaigns published by this website or its owners may contain tracking facilities within the actual email. Subscriber activity is tracked and stored in a database for future analysis and evaluation. Such tracked activity may include: opening of emails, forwarding of emails, clicking of links within email content, and times, dates, and frequency of activity. This list of tracked activities is not comprehensive.
Information tracked in emails is used to refine future email campaigns and supply users with more relevant content based on their activity.
Subscribers are given the opportunity to unsubscribe at any time through an automated system. This process is detailed at the footer of each email campaign. If an automated unsubscribe system is unavailable, clear instructions on how to unsubscribe will be detailed instead.
In order to properly use ExpertBox's services, you must register and provide specific information. In addition to these data required for use and generated by the use of the Services, you may voluntarily provide further information about yourself.
There will be no data transfer to third parties, except for the transmission of the credit card data to the processing payment service Provider Mangopay for the purpose of processing any payments (payments to experts, monthly fees by experts, payments by customers) and to our tax advisor to fulfill our tax obligations.
Upon cancellation of the registration or booking process, the data stored with us will be deleted. If a user requests a deletion of his ExpertBox account, the personal data will be deleted unless they have to be retained due to legal obligations (for example, seven years under tax law according to § 132 Abs 1 BAO).
When using ExpertBox to book appointments with experts, ExpertBox collects and uses the following personal information during the registration process.
The button raises the o.g. Data, as they are required for the booking of dates for services of experts and for the proper handling of these. In the case of a scheduled appointment booking, the button transmits the customer's data to the respective expert. The button uses the data collected from customers anonymously for the production of statistics and for the internal development of the offered software services. ExpertBox reserves the right to submit anonymous data to experts for statistical purposes. When booking appointments with an expert, ExpertBox also collects the following data in order to carry out the payment processing, which is forwarded directly to the payment service manager Stripe.
For service Providers who use ExpertBox to process their customer interaction, ExpertBox also collects and uses the following personal data for the purpose described below.
If you only use ExpertBox's appointment management solution as an expert, the following data is collected:
However, if you also use ExpertBox's accounting and payment processes, the following additional personal data will also be collected, which are required for the purpose of adequate accounting and payment processing and which comply with the required KYC regulations:
The o.a. Data is required to provide the services offered by ExpertBox. The expert agrees that much of the o.g. Data, in particular first and last name, email address, telephone number, website, title, profile picture, unit lengths and prices of the offer, address of the service provision, occupation and cancellation conditions are displayed publicly in the respective expert profile. When an invoice is created by ExpertBox, all invoice relevant data are also shared with the respective customer, in particular the billing address, the VAT rate, and any UID number. Certain data, in particular nationality, date of birth and address are collected on the basis of the statutory KYC regulations and passed on to our payment service Provider together with all other payment-relevant data.
In order to offer you all the functions of ExpertBox, we use selected service Providers who process their data in our order and name. In the process, we only pass on data to a service Provider that has been carefully selected by us and authorized in writing within the scope of a legally permissible order processing. Go Consulted and thus the ExpertBox solution uses a secured electronic payment system of the financial service Provider Stripe (Stripe, 510 Townsend Street, San Francisco, CA 94103, USA Attention: Stripe Legal) for the settlement of all payment services and cash flows. By registering on ExpertBox, the user expressly agrees to the possible ExpertBox monthly fee, the underlying pricing models and the following terms and conditions of payment and payment terms of Stripe. For the accuracy, completeness and security of the processes that are performed by Stripe, Go Consulted, and thus ExpertBox, assumes no liability.
In the event that a booking has been made incorrect, duplicate or unauthorized, Go Consulted can be contacted at
[email protected]
and a refund requested. If the Go Consulted or ExpertBox and / or Stripe terms and conditions are violated, the user may be denied the right of recourse. Go Consulted also reserves the right to post payments in this case or in the event of a breach of law.
For the video calls handled via ExpertBox, our own self-hosted video system, which is based on the open source technology WebRTC and is encrypted, is used in the first place. To prevent any connection difficulties with certain end devices or software environments, we provide the user with a backup to either one of our two Providers, Tokbox (TokBox, Inc., 501 2nd Street, Suite 310, San Francisco CA 94107) or Twilio (Twilio Inc., 375 Beale Street, Suite 300, San Francisco, CA 94105). Both Providers are DSGVO compliant. Each time you connect to the video chat server, a unique session ID is created that allows both parties to connect. In this process, no personal information is sent to the respective Provider.
Go Consulted will send automated notifications via email to users from the moment of registration at ExpertBox, which serves to facilitate the successful and easier handling of the ExpertBox functions. Emails sent via include, for example, registration confirmations, notifications of appointment requests or received messages, appointment confirmations, appointment reminders and invoice deliveries.
Because we're committed to protecting your privacy, we do not use third-party web analytics systems, such as Google Analytics. Instead, we use a self-hosted system based on open source software for statistical analysis of visitor access and log files. Cookies are used and stored on your computer, which gives us the opportunity to analyze the use of our website by you. The IP address is anonymized immediately after processing and stored on our own servers. The data are for quality assurance and statistical purposes only.
Go Consulted also provides companies with the software as a white label solution. If ExpertBox collects personal data in this context on behalf of the company, this is done only on behalf of and on the basis of a separate agreement on data processing in the order. In this case, the contracting entity, as the data protection officer, is responsible for compliance with data protection rules.
We may share your personal data with the parties set out below:
Third parties (including service providers and subcontractors) to aid us with improving, analyze and secure the Services and to develop and offer new products and services.
Third parties (including service providers and subcontractors) working on behalf of or with the Company to provide (i) information about our products or services, or (ii) the products or services requested by you. These third parties are subject to confidentiality agreements and do not have any independent or legal right to share your personal data.
Company reserves the right to disclose personal data it collects: (i) if Company believes it is necessary
to do so in order to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of the Service's Terms and Conditions, Agreements between us or as otherwise required by law; (ii) when Company believes that disclosure is necessary to protect its legal rights and/or to comply with a judicial proceeding, court order or legal process served on Company; or (iii) to transfer information in the event of a merger, acquisition, transfer of assets, or other organizational restructuring or change of control.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Withdrawing Your Consent
If you have given us consent to process your personal data, you have the right to withdraw your consent at any time.
Service Providers can choose to permit or restrict Third Party Services for their ExpertBox account. Third Party Services are software that integrate with our Services. Once enabled, the provider of a Third Party Service may share certain information with ExpertBox with the purpose to facilitate the integration. We do not, however, receive or store passwords for any of these Third Party Services when connecting them to the Services. Please check your privacy settings on the Third Party Service to review and modify what is shared with ExpertBox.
Calendar synchronisation
When using a Third Party Service (such as Google) to connect your calendar, the Third Party Service may provide us with your Third Party Service account information on your behalf, such as your name and email address (we don’t collect or store passwords you use to access Third Party Services). ExpertBox calendar integration accesses the following third-party service information to facilitate managing the availability of the Service Provider in ExpertBox:
We do receive or not store the names and email addresses of other participants, or any other details about the events in your connected calendar. Also, the above mentioned information will be displayed only in the Authorised Service Provider's profile and will not be disclosed to the public.
We store your data for the duration of your ExpertBox account. However, you can cancel or block your ExpertBox account at any time. We will then delete your data, unless we are legally obliged to further storage or retention. If the data is still required to settle outstanding transactions, the deletion will take place at the earliest after the settlement of these transactions.
You are entitled in principle to free information, correction, deletion, limitation of processing, data portability, revocation and opposition. You can claim all of these rights by contacting us at
[email protected]
The button is also available for other questions about data protection and the processing of your data under
[email protected]
All specified user data can also be updated independently in your own profile. This does not apply to the email address, which is used for identification purposes and therefore can only be changed on request by email to
[email protected]
ExpertBox reserves the right to change and supplement this privacy policy at any time. Any adjustments will be posted on www.derbutton.com and on the App and will apply from the date of publication. Therefore, you should periodically retrieve these privacy notices to keep up to date with the latest developments. By continuing to use, you agree to the most recent version with the applicable changes and/or additions.
Cookie’s name | Type | Retention period | Description | Domain. Cookie’s provider |
---|---|---|---|---|
_expertbox_session | Necessary | During session | The website session cookie is set by the server to maintain the user's session state across different pages of the website. This cookie is essential for functionalities such as login persistence, ensuring a seamless and consistent user experience. The session cookie does not store personal data and is typically deleted when the browser is closed, enhancing privacy and security. |
.expertbox.io First party. |
browser_timezone | Necessary | 1 day | The browser_timezone cookie is set by expertbox.io and is used as a general-purpose platform session cookie. It is typically used to define and store the user's timezone, enabling the website to display times and dates that are relevant to the user's local time. This helps improve the user experience by ensuring that any time-sensitive information, such as appointment schedules or event timings, is accurately adjusted to the user's timezone. |
.expertbox.io First party. |
_gat_UA-* | Analytics | 1 minute | This is a pattern type cookie set by Google Analytics, where the pattern element on the name contains the unique identity number of the account or website it relates to. It is a variation of the _gat cookie which is used to limit the amount of data recorded by Google on high traffic volume websites |
.expertbox.io First party. |
_ga_* | Analytics | 1 year 1 month 4 days | The _ga_* cookie is set by Google Analytics to store and count page views on the website. This cookie helps track the number of visits and interactions with the website, providing valuable data for performance and user behavior analysis. It belongs to the analytics category and plays a crucial role in generating detailed usage reports for site optimization. |
.expertbox.io First party. |
_ga | Analytics | 1 year 1 month 4 days | The _ga cookie is set by Google Analytics to calculate visitor, session, and campaign data for the site's analytics reports. It helps track how users interact with the website, providing insights into site usage and performance. |
.expertbox.io First party. |
_gid | Analytics | 1 day | The _gid cookie is set by Google Analytics to store information about how visitors use a website and to create an analytics report on the website's performance. This cookie collects data on visitor behavior, including pages visited, duration of the visit, and interactions with the website, helping site owners understand and improve user experience. It is part of the analytics category and typically expires after 24 hours. |
.expertbox.io First party. |
__cf_bm | Necessary | 1 hour | The __cf_bm cookie is set by Cloudflare to support Cloudflare Bot Management. This cookie helps to identify and filter requests from bots, enhancing the security and performance of the website. By distinguishing between legitimate users and automated traffic, it ensures that the site remains protected from malicious bots and potential attacks. This functionality is crucial for maintaining the integrity and reliability of the site's operations. |
.pipedrive.com Third party. |
If you have any questions regarding your personal data, feel free to contact us via [email protected]
If you choose to block or delete cookies, some functionality of the site may be unavailable and the functionality of the site may be affected.
GO CONSULTED INC
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
Email:
[email protected]
For Non-European Union countries (excluding Great Britain, Switzerland, Norway, Iceland, Liechtenstein and California state)
GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
, Email:
[email protected]
, for the use of the Internet platform and IT solution ExpertBox.io.
As of March 1, 2024
The responsible party within the meaning of the applicable data protection laws is:
GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
, Email:
[email protected]
, for the use of the Internet platform and IT solution ExpertBox.io.
Last updates as of: March 1, 2024
1.1. Go Consulted respects your privacy, and we will protect any information
you give to us. We have developed this privacy policy to explain our practices,
and this policy is incorporated into, and subject to, our Privacy Policy and
Terms of Use.
You will find out what information is available when using the services of Go
Consulted including the use of the ExpertBox website
(
https://expertbox.io
)
("Website")
and App
(
https://app.expertbox.io
)
("App") that are collected, processed or used.
1.2. Go Consulted will process and use the data provided by the user as part of the registration on the ExpertBox Platform and/or the use of the services solely for the purpose of providing services (contract performance) and in accordance with US (The Privacy Act of 1974 (5 U.S.C. 552a) etc) and Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data as it will be amended by its Protocol CETS No. 223.
1.3. For the use of our services, only these data protection provisions, supplemented by our terms of use, in the most recent version, are relevant.
1.4 All data stored by us or any order processor will be best protected against unauthorized access, loss, destruction, deletion, alteration or dissemination of your data by unauthorized persons using current security standards.
1.5. All personal data collected by us are processed exclusively within https://aws.amazon.com/aup/ and Stripe https://stripe.com/privacy for providing payments and are, therefore, subject to appropriate data protection provisions. Transmission of data to companies outside the United States of America will not take place without your explicit consent. This also applies to service Providers commissioned by us for data processing. The servers on which the personal data of our customers are stored are located in the USA.
2.1 GO CONSULTED INC, 200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA operates a web-based software solution called ExpertBox ("ExpertBox"), which offers service Providers ("experts") a digital customer interaction opportunity. This includes appointment management and booking, execution of video calls as well as payment and invoicing. Visitors ("visitors") as well as customers ("customers") of the service Providers ("experts") thus have the opportunity to book appointments with experts online and to process them using ExpertBox's software solution.
2.2 In addition to the ExpertBox website and app, the software solution is also available via integration on websites of experts and on existing platforms.
When you access ExpertBox services as a visitor, even without logging in or logging in, server log files are sent from your server to ExpertBox's web server, which is technically necessary for accessing information. The following data is collected as part of the server log files:
This data can not be assigned to specific persons for ExpertBox and a merger of this data with other data sources will not be made. ExpertBox has no influence on the automatic transmission of this data. However, you can set this automatic data transfer directly in your device or browser and restrict it if necessary. The o.g. Server log files are stored for 12 days, after which all collected IP addresses are anonymized and used only for quality assurance, web site optimization and statistical purposes. We retain your information for as long as needed for our functions or activities or to comply with our legal obligations (such as reporting to regulatory authorities), to resolve disputes and to enforce our rights. We also may retain your information to support our business operations and develop our Services. The criteria used to determine our data retention periods include: (i) how long the personal data is needed to provide the services and operate the business; (ii) the type of personal data collected; and (iii) whether we are subject to a legal, contractual or similar obligation to retain the data (e.g., mandatory data retention laws, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation or disputes.) When we no longer need to use your information, we will take steps to properly anonymize or destroy it. We may retain information that is not personally identified to an individual User, including without limitation anonymized data and aggregate information, at our discretion.
Under certain circumstances, you have rights under data protection laws in relation to your personal data.
Request access to your personal data. This enables you to receive a copy of the personal data we
hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us. Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data`s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data. Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within 45 days. Occasionally it may take us longer than 45 days if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. Maximum response time 90 days.
To exercise your rights, please contact us at [email protected]
The Company works only with individuals who are at least 18 years old.
This website uses cookies to better the user experience of its visitors. Where applicable, this website uses a cookie control system, allowing users to allow or disallow the use of cookies on their computer/device on their first visit to the website. This complies with recent legislative requirements for websites to obtain explicit consent from users before leaving behind or reading files such as cookies on a user’s computer/device.
Cookies are small files saved to a user’s computer/device hard drive that track, save, and store information about the user’s interactions and website use. They allow a website, through its server, to provide users with a tailored experience within the site.
Users are advised to take necessary steps within their web browser security settings to block all cookies from this website and its external serving vendors if they wish to deny the use and saving of cookies from this website to their computer’s/device’s hard drive.
This site uses the Lucky Orange analytics system to help improve usability and the customer experience. Lucky Orange may record mouse clicks, mouse movements, and scrolling activity. Lucky Orange may also record keystroke information that is voluntarily entered on this website. Lucky Orange does not track this activity on any site that does not use the Lucky Orange system. You can choose to disable the Lucky Orange service at https://www.luckyorange.com/disable.php Note that doing so will disable other features of the Lucky Orange system that this site employs, such as one-to-one support chat.
On our website (but not our app) Facebook pixels are implemented in order to present advertisements ("Facebook Ads") to prior visitors of our website as part of the Facebook Newsfeed. These Facebook pixels create a direct connection to the Facebook servers when visiting our website. It is transmitted to the Facebook server that you have visited our website. Facebook assigns this information to your personal Facebook user account. For more information on the collection and use of data by Facebook, as well as your rights in this regard and ways to protect your privacy, please refer to the privacy policy of Facebook at https://www.facebook.com/about/privacy
Alternatively, you can opt out of Facebook's remarketing feature by following this link: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen This requires registration on your personal Facebook profile.
We use the advertising tool "Google-Adwords" to promote our website. As part of this, we use the Google Analytics Conversion Tracking analytics service on our website, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA. When you reach our website through a Google ad, a cookie is placed on your device. These so-called "conversion cookies" are only valid for 30 days. If you visit certain pages of our website within this validity period, we and Google may recognize that you as a user clicked on one of our ads placed with Google and were redirected to our site. Any "conversion cookies" are only placed on our landing pages, but not on our app. The "conversion cookies" are used to generate visit statistics for our website, which informs us about the total number of users who have clicked on our ad. In addition, we learn which pages of our website were called up by the respective user afterwards. However, we do not receive any information that may conclude your personal identification.
You can prevent the transmission of data via "conversion cookies" in your browser settings and disable the automatic setting of cookies in general or just block the cookies from the domain "googleadservices.com". For more information about Google Adwords services and Google's privacy policy, please visit: https://policies.google.com/privacy
Users contacting this website or its owners do so at their own discretion and provide any personal details requested at their own risk. Your personal information is kept private and stored securely until such time that it is no longer required or has no use. Every effort has been made to ensure a safe and secure form to email submission process, but users are still advised that using such form to email processes are done at their own risk.
This website and its owners use information submitted to provide you with further information about the products and services they offer and to assist you in answering any questions or queries you may submit. This includes using your details to subscribe you to any email newsletter program the website operates, but only if this was made clear to you and your express permission was granted when submitting a form to email process or when you, the consumer, have previously purchased from or enquired about purchasing from the company a product or service that the email newsletter relates to. This is by no means an entire list of your user rights with regard to receiving email marketing material. Your details are not passed on to any third parties.
This website operates an email newsletter program to inform subscribers about products and services supplied by this website. Users can subscribe through an automated online process should they wish to do so at their own discretion. Some subscriptions may be manually processed through prior written agreement with the user.
Subscriptions are made in compliance with spam laws of the visitor’s country. All personal details relating to subscriptions are held securely and in accordance with the current data protection laws of the visitor’s country. No personal details are passed on to third parties or shared with companies or people outside of the company that operates this website.
Email marketing campaigns published by this website or its owners may contain tracking facilities within the actual email. Subscriber activity is tracked and stored in a database for future analysis and evaluation. Such tracked activity may include: opening of emails, forwarding of emails, clicking of links within email content, and times, dates, and frequency of activity. This list of tracked activities is not comprehensive.
Information tracked in emails is used to refine future email campaigns and supply users with more relevant content based on their activity.
Subscribers are given the opportunity to unsubscribe at any time through an automated system. This process is detailed at the footer of each email campaign. If an automated unsubscribe system is unavailable, clear instructions on how to unsubscribe will be detailed instead.
In order to properly use ExpertBox's services, you must register and provide specific
information. In addition to these data required for use and generated by the use of the
Services, you may voluntarily provide further information about yourself.
There will be no data transfer to third parties, except for the transmission of the credit card data to the processing payment service Provider Mangopay for the purpose of processing any payments (payments to experts, monthly fees by experts, payments by customers) and to our tax advisor to fulfill our tax obligations.
Upon cancellation of the registration or booking process, the data stored with us will be deleted. If a user requests a deletion of his ExpertBox account, the personal data will be deleted unless they have to be retained due to legal obligations (for example, seven years under tax law according to § 132 Abs 1 BAO).
When using ExpertBox to book appointments with experts, ExpertBox collects and uses the following personal information during the registration process.
The button raises the o.g. Data, as they are required for the booking of dates for services of experts and for the proper handling of these. In the case of a scheduled appointment booking, the button transmits the customer's data to the respective expert. The button uses the data collected from customers anonymously for the production of statistics and for the internal development of the offered software services. ExpertBox reserves the right to submit anonymous data to experts for statistical purposes. When booking appointments with an expert, ExpertBox also collects the following data in order to carry out the payment processing, which is forwarded directly to the payment service manager Stripe.
For service Providers who use ExpertBox to process their customer interaction, ExpertBox also collects and uses the following personal data for the purpose described below.
However, if you also use ExpertBox's accounting and payment processes, the following additional personal data will also be collected, which are required for the purpose of adequate accounting and payment processing and which comply with the required KYC regulations:
The o.a. Data is required to provide the services offered by ExpertBox. The expert agrees that much of the o.g. Data, in particular first and last name, email address, telephone number, website, title, profile picture, unit lengths and prices of the offer, address of the service provision, occupation and cancellation conditions are displayed publicly in the respective expert profile. When an invoice is created by ExpertBox, all invoice relevant data are also shared with the respective customer, in particular the billing address, the VAT rate, and any UID number. Certain data, in particular nationality, date of birth and address are collected on the basis of the statutory KYC regulations and passed on to our payment service Provider together with all other payment-relevant data.
In order to offer you all the functions of ExpertBox, we use selected service Providers who process their
data in our order and name. In the process, we only pass on data to a service Provider that has been carefully
selected by us and authorized in writing within the scope of a legally permissible order processing.
Go Consulted and thus the ExpertBox solution uses a secured electronic payment system of the financial service
Provider Stripe (Stripe, 510 Townsend Street, San Francisco, CA 94103, USA Attention: Stripe Legal) for the
settlement of all payment services and cash flows. By registering on ExpertBox, the user expressly agrees to
the possible ExpertBox monthly fee, the underlying pricing models and the following terms and conditions of
payment and payment terms of Stripe. For the accuracy, completeness and security of the processes that are
performed by Stripe, Go Consulted, and thus ExpertBox, assumes no liability.
In the event that a booking has been made incorrect, duplicate or unauthorized, Go Consulted can be
contacted at
[email protected]
and a refund requested. If the Go Consulted or ExpertBox and/or Stripe terms and conditions are violated,
the user may be denied the right of recourse. Go Consulted also reserves the right to post payments in this
case or in the event of a breach of law.
For the video calls handled via ExpertBox, our own self-hosted video system, which is based on the open source technology WebRTC and is encrypted, is used in the first place. To prevent any connection difficulties with certain end devices or software environments, we provide the user with a backup to either one of our two Providers, Tokbox (TokBox, Inc., 501 2nd Street, Suite 310, San Francisco CA 94107) or Twilio (Twilio Inc., 375 Beale Street, Suite 300, San Francisco, CA 94105). Both Providers are DSGVO compliant. Each time you connect to the video chat server, a unique session ID is created that allows both parties to connect. In this process, no personal information is sent to the respective Provider.
Go Consulted will send automated notifications via email to users from the moment of registration at ExpertBox, which serves to facilitate the successful and easier handling of the ExpertBox functions. Emails sent via include, for example, registration confirmations, notifications of appointment requests or received messages, appointment confirmations, appointment reminders and invoice deliveries.
Because we're committed to protecting your privacy, we do not use third-party web analytics systems, such as Google Analytics. Instead, we use a self-hosted system based on open source software for statistical analysis of visitor access and log files. Cookies are used and stored on your computer, which gives us the opportunity to analyze the use of our website by you. The IP address is anonymized immediately after processing and stored on our own servers. The data are for quality assurance and statistical purposes only.
Go Consulted also provides companies with the software as a white label solution. If ExpertBox collects personal data in this context on behalf of the company, this is done only on behalf of and on the basis of a separate agreement on data processing in the order. In this case, the contracting entity, as the data protection officer, is responsible for compliance with data protection rules.
We may share your personal data with the parties set out below:
Third parties (including service providers and subcontractors) to aid us with improving, analyze and secure
the Services and to develop and offer new products and services.
Third parties (including service providers and subcontractors) working on behalf of or with the Company to
provide (i) information about our products or services, or (ii) the products or services requested by you.
These third parties are subject to confidentiality agreements and do not have any independent or legal right
to share your personal data.
Company reserves the right to disclose personal data it collects: (i) if Company believes it is necessary
to do so in order to investigate, prevent or take action regarding illegal activities, suspected fraud,
situations involving potential threats to the physical safety of any person, violations of the Service's
Terms and Conditions, Agreements between us or as otherwise required by law; (ii) when Company believes
that disclosure is necessary to protect its legal rights and/or to comply with a judicial proceeding, court
order or legal process served on Company; or (iii) to transfer information in the event of a merger,
acquisition, transfer of assets, or other organizational restructuring or change of control.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Withdrawing Your Consent
If you have given us consent to process your personal data, you have the right to withdraw your consent at any time.
Service Providers can choose to permit or restrict Third Party Services for their ExpertBox account. Third Party Services are software that integrate with our Services. Once enabled, the provider of a Third Party Service may share certain information with ExpertBox with the purpose to facilitate the integration. We do not, however, receive or store passwords for any of these Third Party Services when connecting them to the Services. Please check your privacy settings on the Third Party Service to review and modify what is shared with ExpertBox.
Calendar synchronisation
When using a Third Party Service (such as Google) to connect your calendar, the Third Party Service may provide us with your Third Party Service account information on your behalf, such as your name and email address (we don’t collect or store passwords you use to access Third Party Services). ExpertBox calendar integration accesses the following third-party service information to facilitate managing the availability of the Service Provider in ExpertBox:
We do receive or not store the names and email addresses of other participants, or any other details about the events in your connected calendar. Also, the above mentioned information will be displayed only in the Authorised Service Provider's profile and will not be disclosed to the public.
We store your data for the duration of your ExpertBox account. However, you can cancel or block your ExpertBox account at any time. We will then delete your data, unless we are legally obliged to further storage or retention. If the data is still required to settle outstanding transactions, the deletion will take place at the earliest after the settlement of these transactions.
You are entitled in principle to free information, correction, deletion, limitation of processing, data
portability, revocation and opposition. You can claim all of these rights by contacting us at
[email protected]
The button is also available for other questions about data protection and the processing of your data under
[email protected]
All specified user data can also be updated independently in your own profile. This does not apply to
the email address, which is used for identification purposes and therefore can only be changed on request
by email to
[email protected]
ExpertBox reserves the right to change and supplement this privacy policy at any time. Any adjustments will be posted on www.derbutton.com and on the App and will apply from the date of publication. Therefore, you should periodically retrieve these privacy notices to keep up to date with the latest developments. By continuing to use, you agree to the most recent version with the applicable changes and/or additions.
GO CONSULTED INC,
200 Continental Drive, Suite 401, Newark, Delaware, 19713, USA
Phone:
+ 1 302 56 50 146
,
Email:
[email protected]