REGISTER

email 14 48

Terms

PolicyExecutive IT Forums, Inc, is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org.

Record Retention Policy

Executive IT Forums will hold in its database the following information for a period of five (5) years:

  • Name of Applicant
  • Address
  • E-mail Address
  • Daytime Phone Number
  • Course Title the CPE credit was applied for
  • Certificate of Attendance

Refund Policy

CPE credits, which have not been earned, are refundable within 12 months of purchase. Refunds will be pro-rated on the purchase price per credit hour that was originally acquired. There will be a $20 cancellation fee assessed to every request for refund.

Program Cancellation Policy

Executive IT Forums may at its discretion cancel or replace a previously announced program with a program of similar content. Executive IT Forums will make every effort to provide sufficient notification of a change of title or cancellation. Executive IT Forums will provide a refund for the purchase of CPE credit only in those cases where a cancellation has occurred and no substitute program is provided.

If you are unable to attend a webcast, you may cancel up to seven days before the event and receive a full refund (if applicable). Cancellations made less than seven days prior will be refunded the course fee, less a $25 administrative fee. No shows (or cancellations made after the start of the program) will forfeit the entire registration fee. When cancelling an individual webcast purchased with discounted package pricing, your original savings will be forfeited.

Complaint Resolution Policy

Executive IT Forums will resolve complaints or answer questions regarding Executive IT Forums programs or CPE Certification questions in a professional and timely manner. If you have a complaint, please send it to This email address is being protected from spambots. You need JavaScript enabled to view it.. and we will respond within 3 days of receipt. Every attempt possible will be made to work with the submitter to come to a reasonable solution to the issue(s) at hand.

Course Update Policy

Program content will be up-to-date and will adhere to all IRS, NASBA, and CTEC requirements for CPE credits. Prior to publication, all Executive IT Forums Online Courses will be reviewed by qualified persons other than the course developer, in order to assure the online courses are accurate, timely, and consistent with currently accepted standards relating to the pertinent subject matter(s). All courses will be reviewed and revised, as appropriate, on an annual basis. During each review, staff will check technical accuracy, timeliness, and sufficiency to achieve the stated learning objectives. In addition, course evaluations will be reviewed each quarter to assess program effectiveness, and all appropriate changes will be made that are necessary to enhance online education program effectiveness.

Registrations for each webcast will be taken up to the start of each program. Executive IT Forums reserves the right to substitute speakers in the case of instructor illness. In the event that Executive IT Forums must cancel a webcast, all attendee registration fees will be refunded in full. For all webcasts that are recorded, participants will have access to the recording for three months following the live webcast.

Should Internet links and references not work, please email Executive IT Forums immediately at: This email address is being protected from spambots. You need JavaScript enabled to view it.

Enter to Win!

To be entered to win the Apple iPad 2 (a $400 Apple Gift Card) as part of this promotion, you must register and attend the IT GRC Forum live webcast 'How to Select the Right MDM and BYOD Security Solution for eGRC', being held at 2pm EST on February 21, 2013. 

To qualify you must be 18 or over and a legal resident currently living in the USA. You must provide complete and valid registration information, including your company email address (e.g. not a hotmail or yahoo account), and you must attend and view the live presentation for a minimum of 45 minutes and rate the session.

By entering this Giveaway, entrants agree to be bound by the full Official Rules and agree to release and hold harmless the Giveaway Entities (Sponsors and Administrators, and their employees, officers, agents and directors - the Sponsors and Administrators, and such others, collectively, the Released Parties) from and against any claim or cause of action arising out of participation in the Giveaway or receipt or use of any prize.

The winner will be chosen at random through a prize draw conducted by our host at the end of the live presentation. If you're chosen as the winner, the IT GRC Forum will require your photo for website-publishing. The winner will receive a brand new 16GB iPad 2 (Non-3G Version) or GiftCard with the equivalent amount. The IT GRC Forum is not responsible for wireless service, taxes, or contracts.

The IT GRC Forum is in no way associated with Apple iPad is a registered trademark of Apple, Inc.

Executive IT Forums, Inc., Data Processing Agreement

Last Modified: September 21, 2020                                                                                                           

[Need a signed copy? Click here

This Executive IT Forums Data Processing Agreement and its Annexes (“DPA”) reflects the parties’ agreement with respect to the Processing of Personal Data by us on behalf of you in connection with the Executive IT Forums Subscription Services under the Executive IT Forums Customer Terms of Service between you and us (also referred to in this DPA as the “Agreement”). 

This DPA is supplemental to, and forms an integral part of, the Agreement and is effective upon its incorporation into the Agreement, which may be specified in the Agreement, an Order or an executed amendment to the Agreement. In case of any conflict or inconsistency with the terms of the Agreement, this DPA will take precedence over the terms of the Agreement to the extent of such conflict or inconsistency.

We update these terms from time to time. If you have an active Executive IT Forums subscription, we will let you know when we do via email (if you have subscribed to receive email notifications).

The term of this DPA will follow the term of the Agreement. Terms not otherwise defined in this DPA will have the meaning as set forth in the Agreement.

1. Definitions

“California Personal Information” means Personal Data that is subject to the protection of the CCPA.

"CCPA" means California Civil Code Sec. 1798.100 et seq. (also known as the California Consumer Privacy Act of 2018).

"Consumer", "Business", "Sell" and "Service Provider" will have the meanings given to them in the CCPA. 

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

“Data Protection Laws” means all applicable worldwide legislation relating to data protection and privacy which applies to the respective party in the role of Processing Personal Data in question under the Agreement, including without limitation European Data Protection Laws, the CCPA and the data protection and privacy laws of Australia and Singapore; in each case as amended, repealed, consolidated or replaced from time to time. 

“Data Subject” means the individual to whom Personal Data relates.

"Europe" means the European Union, the European Economic Area and/or their member states, Switzerland and the United Kingdom. 

“European Data” means Personal Data that is subject to the protection of European Data Protection Laws.

"European Data Protection Laws" means data protection laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iii) in respect of the United Kingdom, any applicable national legislation that replaces or converts in domestic law the GDPR or any other law relating to data and privacy as a consequence of the United Kingdom leaving the European Union; and (iv) Swiss Federal Data Protection Act on 19 June 1992 and its Ordinance; in each case, as may be amended, superseded or replaced.  

“Instructions” means the written, documented instructions issued by a Controller to a Processor, and directing the same to perform a specific or general action with regard to Personal Data (including, but not limited to, depersonalizing, blocking, deletion, making available).

"Permitted Affiliates" means any of your Affiliates that (i) are permitted to use the Subscription Services pursuant to the Agreement, but have not signed their own separate agreement with us and are not a “Customer” as defined under the Agreement, (ii) qualify as a Controller of Personal Data Processed by us, and (iii) are subject to European Data Protection Laws.

“Personal Data” means any information relating to an identified or identifiable individual where such information is contained within Customer Data and is protected similarly as personal data, personal information or personally identifiable information under applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by us and/or our Sub-Processors in connection with the provision of the Subscription Services. "Personal Data Breach" will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

"Privacy Shield" means the EU-U.S. and Swiss-US Privacy Shield self-certification program operated by the U.S. Department of Commerce and approved by the European Commission pursuant to its Decision of July, 12 2016 and by the Swiss Federal Council on January 11, 2017 respectively; as may be amended, superseded or replaced.

"Privacy Shield Principles" means the Privacy Shield Principles (as supplemented by the Supplemental Principles) contained in Annex II to the European Commission Decision of July, 12 2016; as may be amended, superseded or replaced.

“Processing” means any operation or set of operations which is performed on Personal Data, encompassing the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction or erasure of Personal Data. The terms “Process”, “Processes” and “Processed” will be construed accordingly.

“Processor” means a natural or legal person, public authority, agency or other body which Processes Personal Data on behalf of the Controller.

“Standard Contractual Clauses” means the standard contractual clauses for Processors approved pursuant to the European Commission’s decision (C(2010)593) of 5 February 2010, in the form set out at Annex 3; as may be amended, superseded or replaced.

“Sub-Processor” means any Processor engaged by us or our Affiliates to assist in fulfilling our obligations with respect to the provision of the Subscription Services under the Agreement.  Sub-Processors may include third parties or our Affiliates but will exclude any Executive IT Forums employee or consultant.  

2. Customer Responsibilities

a. Compliance with Laws. Within the scope of the Agreement and in its use of the services, you will be responsible for complying with all requirements that apply to it under applicable Data Protection Laws with respect to its Processing of Personal Data and the Instructions it issues to us.

In particular but without prejudice to the generality of the foregoing, you acknowledge and agree that you will be solely responsible for: (i) the accuracy, quality, and legality of Customer Data and the means by which you acquired Personal Data; (ii) complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including obtaining any necessary consents and authorizations (particularly for use by Customer for marketing purposes); (iii) ensuring you have the right to transfer, or provide access to, the Personal Data to us for Processing in accordance with the terms of the Agreement (including this DPA); (iv) ensuring that your Instructions to us regarding the Processing of Personal Data comply with applicable laws, including Data Protection Laws; and (v) complying with all laws (including Data Protection Laws) applicable to any emails or other content created, sent or managed through the Subscription Services, including those relating to obtaining consents (where required) to send emails, the content of the emails and its email deployment practices. You will inform us without undue delay if it is not able to comply with its responsibilities under this sub-section (a) or applicable Data Protection Laws.

b. Controller Instructions. The parties agree that the Agreement (including this DPA), together with your use of the Subscription Service in accordance with the Agreement, constitute your complete and final Instructions to us in relation to the Processing of Personal Data, and additional instructions outside the scope of the Instructions shall require prior written agreement between us and you.

3. Executive IT Forums Obligations

a. Compliance with Instructions. We will only Process Personal Data for the purposes described in this DPA or as otherwise agreed within the scope of your lawful Instructions, except where and to the extent otherwise required by applicable law. We are not responsible for compliance with any Data Protection Laws applicable to you or your industry that are not generally applicable to us.

b. Conflict of Laws. If we become aware that we cannot Process Personal Data in accordance with your Instructions due to a legal requirement under any applicable law, we will (i) promptly notify you of that legal requirement to the extent permitted by the applicable law; and (ii) where necessary, cease all Processing (other than merely storing and maintaining the security of the affected Personal Data) until such time as you issue new Instructions with which we are able to comply. If this provision is invoked, we will not be liable to you under the Agreement for any failure to perform the applicable Subscription Services until such time as you issue new lawful Instructions with regard to the Processing.

c. Security. We will implement and maintain appropriate technical and organizational measures to protect Personal Data from Personal Data Breaches, as described under Annex 2 to this DPA ("Security Measures"). Notwithstanding any provision to the contrary, we may modify or update the Security Measures at our discretion provided that such modification or update does not result in a material degradation in the protection offered by the Security Measures. 

d. Confidentiality. We will ensure that any personnel whom we authorize to Process Personal Data on our behalf is subject to appropriate confidentiality obligations (whether a contractual or statutory duty) with respect to that Personal Data.

e. Personal Data Breaches. We will notify you without undue delay after it becomes aware of any Personal Data Breach and will provide timely information relating to the Personal Data Breach as it becomes known or reasonably requested by you. At your request, we will promptly provide you with such reasonable assistance as necessary to enable you to notify relevant Personal Data Breaches to competent authorities and/or affected Data Subjects, if you are required to do so under Data Protection Laws.

f. Deletion or Return of Personal Data. We will delete or return all Customer Data, including Personal Data (including copies thereof) Processed pursuant to this DPA, on termination or expiration of your Subscription Service in accordance with the procedures and timeframes set out in the Agreement, save that this requirement shall not apply to the extent we are required by applicable law to retain some or all of the Customer Data, or to Customer Data it has archived on back-up systems, which data we will securely isolate and protect from any further Processing and delete in accordance with its deletion practices. You may request the deletion of your Executive IT Forums account after expiration or termination of your subscription by sending a request to This email address is being protected from spambots. You need JavaScript enabled to view it.. You may retrieve your Customer Data from your account in accordance with our ‘Retrieval of Customer Data’ sections throughout our Product Specific Terms.

4. Data Subject Requests

The Subscription Service provides you with a number of controls that you can use to retrieve, correct, delete or restrict Personal Data, which you can use to assist it in connection with its obligations under Data Protection Laws, including your obligations relating to responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws ("Data Subject Requests"). 

To the extent that you are unable to independently address a Data Subject Request through the Subscription Service, then upon your written request we will provide reasonable assistance to you to respond to any Data Subject Requests or requests from data protection authorities relating to the Processing of Personal Data under the Agreement. You shall reimburse us for the commercially reasonable costs arising from this assistance.

If a Data Subject Request or other communication regarding the Processing of Personal Data under the Agreement is made directly to us, we will promptly inform you and will advise the Data Subject to submit their request to you. You will be solely responsible for responding substantively to any such Data Subject Requests or communications involving Personal Data.

5. Sub-Processors

You agree that we may engage Sub-Processors to Process Personal Data on your behalf. We have currently appointed, as Sub-Processors, the Executive IT Forums Affiliates and third parties listed in Annex 4 to this DPA.

Where we engage Sub-Processors, we will impose data protection terms on the Sub-Processors that provide at least the same level of protection for Personal Data as those in this DPA (including, where appropriate, the Standard Contractual Clauses), to the extent applicable to the nature of the services provided by such Sub-Processors. We will remain responsible for each Sub-Processor’s compliance with the obligations of this DPA and for any acts or omissions of such Sub-Processor that cause us to breach any of its obligations under this DPA.

6. Data Transfers

You acknowledge and agree that we may access and Process Personal Data on a global basis as necessary to provide the Subscription Service in accordance with the Agreement, and in particular that Personal Data will be transferred to and Processed by Executive IT Forums, Inc. in the United States and to other jurisdictions where Executive IT Forums Affiliates and Sub-Processors have operations. We will ensure such transfers are made in compliance with the requirements of Data Protection Laws.

7. Additional Provisions for European Data

a. Scope of Section 7. This 'Additional Provisions for European Data' section shall apply only with respect to European Data.

b. Roles of the Parties. When Processing European Data in accordance with your Instructions, the parties acknowledge and agree that you are the Controller of European Data and we are the Processor.

c. Instructions. If we believe that your Instruction infringes European Data Protection Laws (where applicable), we will inform you without delay.

d. Notification and Objection to New Sub-Processors. We will notify you of any changes to Sub-processors by updating Annex 4 to this DPA and will give you the opportunity to object to the engagement of the new Sub-Processor on reasonable grounds relating to the protection of Personal Data within 30 days after updating Annex 4 to this DPA. If you do notify us of such an objection, the parties will discuss your concerns in good faith with a view to achieving a commercially reasonable resolution. If no such resolution can be reached, we will, at our sole discretion, either not appoint the new Sub-Processor, or permit you to suspend or terminate the affected Subscription Service in accordance with the termination provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by you prior to suspension or termination).

e. Data Protection Impact Assessments and Consultation with Supervisory Authorities. To the extent that the required information is reasonably available to us, and you do not otherwise have access to the required information, we will provide reasonable assistance to you with any data protection impact assessments, and prior consultations with supervisory authorities or other competent data privacy authorities to the extent required by European Data Protection Laws.

f. Transfer Mechanisms for Data Transfers. 

(A) Executive IT Forums shall not transfer European Data to any country or recipient not recognized as providing an adequate level of protection for Personal Data (within the meaning of applicable European Data Protection Laws), unless it first takes all such measures as are necessary to ensure the transfer is in compliance with applicable European Data Protection Laws. Such measures may include (without limitation) transferring such data to a recipient that is covered by a suitable framework or other legally adequate transfer mechanism recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data, to a recipient that has achieved binding corporate rules authorization in accordance with European Data Protection Laws, or to a recipient that has executed appropriate standard contractual clauses in each case as adopted or approved in accordance with applicable European Data Protection Laws.

(B) You acknowledge that in connection with the performance of the Subscription Services, Executive IT Forums, Inc. is a recipient of European Data in the United States. The parties acknowledge and agree the following:

  • (a) Standard Contractual Clauses: Executive IT Forums, Inc. agrees to abide by and process European Data in compliance with the Standard Contractual Clauses.
  • (b) Privacy Shield: Although Executive IT Forums, Inc. does not rely on the EU-US Privacy Shield as a legal basis for transfers of Personal Data in light of the judgment of the Court of Justice of the EU in Case C-311/18, for as long as Executive IT Forums, Inc. is self-certified to the Privacy Shield Executive IT Forums Inc will process European Data in compliance with the Privacy Shield Principles and let you know if it is unable to comply with this requirement.
  • (C) The parties agree that (i) purely for the purposes of the descriptions in the Standard Contractual Clauses, Executive IT Forums, Inc. will be deemed the "data importer" and Customer will be deemed the "data exporter" (notwithstanding that you may yourself be located outside Europe and/or be acting as a processor on behalf of third party controllers), (ii) notwithstanding the foregoing, where the Executive IT Forums contracting entity under the Agreement is not Executive IT Forums, Inc., You provide such contracting entity with a mandate to enter into the Standard Contractual Clauses with Executive IT Forums, Inc. in its name and on its behalf, such contracting entity (not Executive IT Forums, Inc.) will remain fully and solely responsible and liable to you for the performance of the Standard Contractual Clauses by Executive IT Forums, Inc., and you will direct any instructions, claims or enquiries in relation to the Standard Contractual Clauses to such contracting entity; and (iii) if and to the extent the Standard Contractual Clauses (where applicable) conflict with any provision of this DPA, the Standard Contractual Clauses will prevail to the extent of such conflict.

g. Demonstration of Compliance. We will make all information reasonably necessary to demonstrate compliance with this DPA available to you and allow for and contribute to audits, including inspections by you in order to assess compliance with this DPA. You acknowledge and agree that you will exercise your audit rights under this DPA by instructing us to comply with the audit measures described in this sub-section (g). You acknowledge that the Subscription Service is hosted by our data center partners who maintain independently validated security programs (including SOC 2 and ISO 27001) and that our systems are regularly tested by independent third party penetration testing firms. Upon request, we will supply (on a confidential basis) a summary copy of its penetration testing report(s) to you so that you can verify our compliance with this DPA.  Further, at your written request, we will provide written responses (on a confidential basis) to all reasonable requests for information made by you necessary to confirm our compliance with this DPA, provided that you will not exercise this right more than once per calendar year.

8. Additional Provisions for California Personal Information

a. Scope of Section 8. The 'Additional Provisions for California Personal Information' section of the DPA will apply only with respect to California Personal Information.

b. Roles of the Parties. When processing California Personal Information in accordance with your Instructions, the parties acknowledge and agree that you are a Business and we are a Service Provider for the purposes of the CCPA.

c. Responsibilities. The parties agree that we will Process California Personal Information as a Service Provider strictly for the purpose of performing the Subscription Services and Consulting Services under the Agreement  (the "Business Purpose") or as otherwise permitted by the CCPA, including as described in the ‘Data Practices and Machine Learning’ section of our Product Specific Terms. 

9. General Provisions

a. Amendments. Notwithstanding anything else to the contrary in the Agreement and without prejudice to the ‘Compliance with Instructions’ or ‘Security’ sections of this DPA, we reserve the right to make any updates and changes to this DPA and the terms that apply in the ‘Amendment; No Waiver’ section of the Master Terms will apply.

b. Severability. If any individual provisions of this DPA are determined to be invalid or unenforceable, the validity and enforceability of the other provisions of this DPA will not be affected.

c. Limitation of Liability. Each party and each of their Affiliates' liability, taken in aggregate,  arising out of or related to this DPA (and any other DPAs between the parties) and the Standard Contractual Clauses (where applicable), whether in contract, tort or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the 'Limitation of Liability' section of the Master Terms and any reference in such section to the liability of a party means aggregate liability of that party and all of its Affiliates under the Agreement (including this DPA).  For the avoidance of doubt, if Executive IT Forums, Inc. is not a party to the Agreement, the ‘Limitation of Liability’ section of the Master Terms will apply as between you and Executive IT Forums, Inc., and in such respect any references to ‘Executive IT Forums’, ‘we’, ‘us’ or ‘our’ will include both Executive IT Forums, Inc. and the Executive IT Forums entity that is a party to the Agreement.

d. Governing Law. This DPA will be governed by and construed in accordance with the ‘Contacting Entity; ‘Applicable Law; Notice’ sections of the Jurisdiction Specific Terms, unless required otherwise by Data Protection Laws.

10. Parties to this DPA

a. Permitted Affiliates. By signing the Agreement, you enter into this DPA on behalf of yourself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of your Permitted Affiliates, thereby establishing a separate DPA between us and each such Permitted Affiliate subject to the Agreement and the ‘General Provisions’ and ‘Parties to this DPA’ sections of this DPA. Each Permitted Affiliate agrees to be bound by the obligations under this DPA and, to the extent applicable, the Agreement. For the purposes of this DPA only, and except where indicated otherwise, the terms “Customer”, “you” and “your” will include you and such Permitted Affiliates.

b. Authorization. The legal entity agreeing to this DPA as Customer represents that it is authorized to agree to and enter into this DPA for and on behalf of itself and, as applicable, each of its Permitted Affiliates.

c. Remedies.Except where applicable Data Protection Laws require a Permitted Affiliate to exercise a right or seek any remedy under this DPA against us directly by itself, the parties agree that (i) solely the Customer entity that is the contracting party to the Agreement will exercise any right or seek any remedy any Permitted Affiliate may have under this DPA on behalf of its Affiliates, and (ii) the Customer entity that is the contracting party to the Agreement will exercise any such rights under this DPA not separately for each Permitted Affiliate individually but in a combined manner for itself and all of its Permitted Affiliates together. The Customer entity that is the contracting entity is responsible for coordinating all communication with us under the DPA and will be entitled to make and receive any communication related to this DPA on behalf of its Permitted Affiliates.  

d. Other rights. The parties agree that you will, when reviewing our compliance with this DPA pursuant to the ‘Demonstration of Compliance’ section, take all reasonable measures to limit any impact on us and our Affiliates by combining several audit requests carried out on behalf of the Customer entity that is the contracting party to the Agreement and all of its Permitted Affiliates in one single audit.

Annex 1 - Details of Processing

This Annex forms part of the DPA. 

A.  Nature and Purpose of Processing 

We will Process Personal Data as necessary to provide the Subscription Services pursuant to the Agreement, as further specified in the Order Form, and as further instructed by you in your use of the Subscription Services.

B.  Duration of Processing 

Subject to the 'Deletion or Return of Personal Data' section of this DPA, we will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.  

C.  Categories of Data subjects

You may submit Personal Data in the course of using the Subscription Service, the extent of which is determined and controlled by you in your sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of Data Subjects:

Your Contacts and other end users including your employees, contractors, collaborators, customers, prospects, suppliers and subcontractors. Data Subjects may also include individuals attempting to communicate with or transfer Personal Data to your end users.

D.  Categories of Personal Data 

You may submit Personal Data to the Subscription Services, the extent of which is determined and controlled by you in your sole discretion, and which may include but is not limited to the following categories of Personal Data: 

  • - Contact Information (as defined in the Master Terms).
  • - Any other Personal Data submitted by, sent to, or received by you, or your end users, via the Subscription Service.

E.  Special categories of data (if appropriate)

The parties do not anticipate the transfer of special categories of data.

F.  Processing operations

Personal Data will be Processed in accordance with the Agreement (including this DPA) and may be subject to the following Processing activities: 

a. Storage and other Processing necessary to provide, maintain and improve the Subscription Services provided to you; and/or
b. Disclosure in accordance with the Agreement (including this DPA) and/or as compelled by applicable laws.

Annex 2 - Security Measures

This Annex forms part of the DPA.

We currently observe the Security Measures described in this Annex 2. All capitalized terms not otherwise defined herein shall have the meanings as set forth in the Master Terms.

a) Access Control

i)  Preventing Unauthorized Product Access

Outsourced processing: We host our Service with outsourced cloud infrastructure providers. Additionally, we maintain contractual relationships with vendors in order to provide the Service in accordance with our DPA. We rely on contractual agreements, privacy policies, and vendor compliance programs in order to protect data processed or stored by these vendors.

Physical and environmental security: We host our product infrastructure with multi-tenant, outsourced infrastructure providers. The physical and environmental security controls are audited for SOC 2 Type II and ISO 27001 compliance, among other certifications.

Authentication: We implement a uniform password policy for our customer products. Customers who interact with the products via the user interface must authenticate before accessing non-public customer data.

Authorization: Customer Data is stored in multi-tenant storage systems accessible to Customers via only application user interfaces and application programming interfaces. Customers are not allowed direct access to the underlying application infrastructure. The authorization model in each of our products is designed to ensure that only the appropriately assigned individuals can access relevant features, views, and customization options. Authorization to data sets is performed through validating the user’s permissions against the attributes associated with each data set.

Application Programming Interface (API) access: Public product APIs may be accessed using an API key or through Oauth authorization.

ii)  Preventing Unauthorized Product Use

We implement industry standard access controls and detection capabilities for the internal networks that support its products.

Access controls: Network access control mechanisms are designed to prevent network traffic using unauthorized protocols from reaching the product infrastructure. The technical measures implemented differ between infrastructure providers and include Virtual Private Cloud (VPC) implementations, security group assignment, and traditional firewall rules.

Intrusion detection and prevention: We implement a Web Application Firewall (WAF) solution to protect hosted customer websites and other internet-accessible applications. The WAF is designed to identify and prevent attacks against publicly available network services.

Static code analysis: Security reviews of code stored in our source code repositories is performed, checking for coding best practices and identifiable software flaws.

Penetration testing: We maintain relationships with industry recognized penetration testing service providers for four annual penetration tests. The intent of the penetration tests is to identify and resolve foreseeable attack vectors and potential abuse scenarios.

Bug bounty: A bug bounty program invites and incentivizes independent security researchers to ethically discover and disclose security flaws. We implement a bug bounty program in an effort to widen the available opportunities to engage with the security community and improve the product defenses against sophisticated attacks.

iii)    Limitations of Privilege & Authorization Requirements

Product access: A subset of our employees have access to the products and to customer data via controlled interfaces. The intent of providing access to a subset of employees is to provide effective customer support, to troubleshoot potential problems, to detect and respond to security incidents and implement data security. Access is enabled through “just in time” requests for access; all such requests are logged. Employees are granted access by role, and reviews of high risk privilege grants are initiated daily. Employee roles are reviewed at least once every six months.

Background checks: All Executive IT Forums employees undergo a third-party background check prior to being extended an employment offer, in accordance with and as permitted by the applicable laws. All Executive IT Forums employees are required to conduct themselves in a manner consistent with company guidelines, non-disclosure requirements, and ethical standards.

b) Transmission Control

In-transit: We make HTTPS encryption (also referred to as SSL or TLS) available on every one of its login interfaces and for free on every customer site hosted on the Executive IT Forums products. Our HTTPS implementation uses industry standard algorithms and certificates.

At-rest: We store user passwords following policies that follow industry standard practices for security.  We have implemented technologies to ensure that stored data is encrypted at rest. 

c) Input Control

Detection: We designed our infrastructure to log extensive information about the system behavior, traffic received, system authentication, and other application requests. Internal systems aggregated log data and alert appropriate employees of malicious, unintended, or anomalous activities. Our personnel, including security, operations, and support personnel, are responsive to known incidents.

Response and tracking: We maintain a record of known security incidents that includes description, dates and times of relevant activities, and incident disposition. Suspected and confirmed security incidents are investigated by security, operations, or support personnel; and appropriate resolution steps are identified and documented. For any confirmed incidents, we will take appropriate steps to minimize product and Customer damage or unauthorized disclosure. Notification to you will be in accordance with the terms of the Agreement. 

d) Availability Control

Infrastructure availability: The infrastructure providers use commercially reasonable efforts to ensure a minimum of 99.95% uptime. The providers maintain a minimum of N+1 redundancy to power, network, and HVAC services.

Fault tolerance: Backup and replication strategies are designed to ensure redundancy and fail-over protections during a significant processing failure. Customer data is backed up to multiple durable data stores and replicated across multiple availability zones.

Online replicas and backups: Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary database. All databases are backed up and maintained using at least industry standard methods.

Our products are designed to ensure redundancy and seamless failover. The server instances that support the products are also architected with a goal to prevent single points of failure. This design assists our operations in maintaining and updating the product applications and backend while limiting downtime.

Annex 3 - Standard Contractual Clauses

For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection,

The Customer, as defined in the Executive IT Forums Customer Terms of Service (the “data exporter”)

And

Executive IT Forums Inc., Suite 6272, Penn Plaza, New York, 10119 (the “data importer”)

each a ‘party’; together ‘the parties’,

HAVE AGREED on the following Contractual Clauses (the Clauses) in order to adduce adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals for the transfer by the data exporter to the data importer of the personal data specified in Appendix 1.

Clause 1

Definitions

For the purposes of the Clauses:

‘personal data’, ‘special categories of data’, ‘process/processing’, ‘controller’, ‘processor’, ‘data subject’ and ‘supervisory authority’ shall have the same meaning as in Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data;

‘the data exporter’ means the controller who transfers the personal data;

‘the data importer’ means the processor who agrees to receive from the data exporter personal data intended for processing on his behalf after the transfer in accordance with his instructions and the terms of the Clauses and who is not subject to a third country’s system ensuring adequate protection within the meaning of Article 25(1) of Directive 95/46/EC;

'the subprocessor’ means any processor engaged by the data importer or by any other subprocessor of the data importer who agrees to receive from the data importer or from any other subprocessor of the data importer personal data exclusively intended for processing activities to be carried out on behalf of the data exporter after the transfer in accordance with his instructions, the terms of the Clauses and the terms of the written subcontract;

‘the applicable data protection law’ means the legislation protecting the fundamental rights and freedoms of individuals and, in particular, their right to privacy with respect to the processing of personal data applicable to a data controller in the Member State in which the data exporter is established;

‘technical and organisational security measures’ means those measures aimed at protecting personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.

Clause 2

Details of the transfer

The details of the transfer and in particular the special categories of personal data where applicable are specified in Appendix 1 which forms an integral part of the Clauses.

Clause 3

Third-party beneficiary clause

1.  The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause 5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as third-party beneficiary.

2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has factually disappeared or has ceased to exist in law unless any successor entity has assumed the entire legal obligations of the data exporter by contract or by operation of law, as a result of which it takes on the rights and obligations of the data exporter, in which case the data subject can enforce them against such entity.

3. The data subject can enforce against the subprocessor this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter and the data importer have factually disappeared or ceased to exist in law or have become insolvent, unless any successor entity has assumed the entire legal obligations of the data exporter by contract or by operation of law as a result of which it takes on the rights and obligations of the data exporter, in which case the data subject can enforce them against such entity. Such third-party liability of the subprocessor shall be limited to its own processing operations under the Clauses.

4. The parties do not object to a data subject being represented by an association or other body if the data subject so expressly wishes and if permitted by national law.

Clause 4

Obligations of the data exporter

The data exporter agrees and warrants:

(a) that the processing, including the transfer itself, of the personal data has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law (and, where applicable, has been notified to the relevant authorities of the Member State where the data exporter is established) and does not violate the relevant provisions of that State;

(b) that it has instructed and throughout the duration of the personal data-processing services will instruct the data importer to process the personal data transferred only on the data exporter’s behalf and in accordance with the applicable data protection law and the Clauses;

(c) that the data importer will provide sufficient guarantees in respect of the technical and organisational security measures specified in Appendix 2 to this contract;

(d) that after assessment of the requirements of the applicable data protection law, the security measures are appropriate to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing, and that these measures ensure a level of security appropriate to the risks presented by the processing and the nature of the data to be protected having regard to the state of the art and the cost of their implementation;

(e) that it will ensure compliance with the security measures;

(f) that, if the transfer involves special categories of data, the data subject has been informed or will be informed before, or as soon as possible after, the transfer that its data could be transmitted to a third country not providing adequate protection within the meaning of Directive 95/46/EC;

(g) to forward any notification received from the data importer or any subprocessor pursuant to Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter decides to continue the transfer or to lift the suspension;

(h) to make available to the data subjects upon request a copy of the Clauses, with the exception of Appendix 2, and a summary description of the security measures, as well as a copy of any contract for subprocessing services which has to be made in accordance with the Clauses, unless the Clauses or the contract contain commercial information, in which case it may remove such commercial information;

(i) that, in the event of subprocessing, the processing activity is carried out in accordance with Clause 11 by a subprocessor providing at least the same level of protection for the personal data and the rights of data subject as the data importer under the Clauses; and

(j) that it will ensure compliance with Clause 4(a) to (i).

Clause 5

Obligations of the data importer

The data importer agrees and warrants:

(a) to process the personal data only on behalf of the data exporter and in compliance with its instructions and the Clauses; if it cannot provide such compliance for whatever reasons, it agrees to inform promptly the data exporter of its inability to comply, in which case the data exporter is entitled to suspend the transfer of data and/or terminate the contract;

(b) that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the instructions received from the data exporter and its obligations under the contract and that in the event of a change in this legislation which is likely to have a substantial adverse effect on the warranties and obligations provided by the Clauses, it will promptly notify the change to the data exporter as soon as it is aware, in which case the data exporter is entitled to suspend the transfer of data and/or terminate the contract;

(c) that it has implemented the technical and organisational security measures specified in Appendix 2 before processing the personal data transferred;

(d) that it will promptly notify the data exporter about:

(i) any legally binding request for disclosure of the personal data by a law enforcement authority unless otherwise prohibited, such as a prohibition under criminal law to preserve the confidentiality of a law enforcement investigation;

(ii) any accidental or unauthorised access; and

(iii) any request received directly from the data subjects without responding to that request, unless it has been otherwise authorised to do so;

(e) to deal promptly and properly with all inquiries from the data exporter relating to its processing of the personal data subject to the transfer and to abide by the advice of the supervisory authority with regard to the processing of the data transferred;

(f) at the request of the data exporter to submit its data-processing facilities for audit of the processing activities covered by the Clauses which shall be carried out by the data exporter or an inspection body composed of independent members and in possession of the required professional qualifications bound by a duty of confidentiality, selected by the data exporter, where applicable, in agreement with the supervisory authority;

(g) to make available to the data subject upon request a copy of the Clauses, or any existing contract for subprocessing, unless the Clauses or contract contain commercial information, in which case it may remove such commercial information, with the exception of Appendix 2 which shall be replaced by a summary description of the security measures in those cases where the data subject is unable to obtain a copy from the data exporter;

(h) that, in the event of subprocessing, it has previously informed the data exporter and obtained its prior written consent;

(i) that the processing services by the subprocessor will be carried out in accordance with Clause 11;

(j) to send promptly a copy of any subprocessor agreement it concludes under the Clauses to the data exporter.

Clause 6

Liability

1. The parties agree that any data subject, who has suffered damage as a result of any breach of the obligations referred to in Clause 3 or in Clause 11 by any party or subprocessor is entitled to receive compensation from the data exporter for the damage suffered.

2. If a data subject is not able to bring a claim for compensation in accordance with paragraph 1 against the data exporter, arising out of a breach by the data importer or his subprocessor of any of their obligations referred to in Clause 3 or in Clause 11, because the data exporter has factually disappeared or ceased to exist in law or has become insolvent, the data importer agrees that the data subject may issue a claim against the data importer as if it were the data exporter, unless any successor entity has assumed the entire legal obligations of the data exporter by contract or by operation of law, in which case the data subject can enforce its rights against such entity. The data importer may not rely on a breach by a subprocessor of its obligations in order to avoid its own liabilities.

3. If a data subject is not able to bring a claim against the data exporter or the data importer referred to in paragraphs 1 and 2, arising out of a breach by the subprocessor of any of their obligations referred to in Clause 3 or in Clause 11 because both the data exporter and the data importer have factually disappeared or ceased to exist in law or have become insolvent, the subprocessor agrees that the data subject may issue a claim against the data subprocessor with regard to its own processing operations under the Clauses as if it were the data exporter or the data importer, unless any successor entity has assumed the entire legal obligations of the data exporter or data importer by contract or by operation of law, in which case the data subject can enforce its rights against such entity. The liability of the subprocessor shall be limited to its own processing operations under the Clauses.

Clause 7

Mediation and jurisdiction

1. The data importer agrees that if the data subject invokes against it third-party beneficiary rights and/or claims compensation for damages under the Clauses, the data importer will accept the decision of the data subject:

(a)  to refer the dispute to mediation, by an independent person or, where applicable, by the supervisory authority;
(b)  to refer the dispute to the courts in the Member State in which the data exporter is established.

2. The parties agree that the choice made by the data subject will not prejudice its substantive or procedural rights to seek remedies in accordance with other provisions of national or international law.

Clause 8

Cooperation with supervisory authorities

1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if it so requests or if such deposit is required under the applicable data protection law.

2. The parties agree that the supervisory authority has the right to conduct an audit of the data importer, and of any subprocessor, which has the same scope and is subject to the same conditions as would apply to an audit of the data exporter under the applicable data protection law.

3. The data importer shall promptly inform the data exporter about the existence of legislation applicable to it or any subprocessor preventing the conduct of an audit of the data importer, or any subprocessor, pursuant to paragraph 2. In such a case the data exporter shall be entitled to take the measures foreseen in Clause 5(b).

Clause 9

Governing law

The Clauses shall be governed by the law of the Member State in which the data exporter is established.

Clause 10

Variation of the contract

The parties undertake not to vary or modify the Clauses. This does not preclude the parties from adding clauses on business related issues where required as long as they do not contradict the Clause.

Clause 11

Subprocessing

1. The data importer shall not subcontract any of its processing operations performed on behalf of the data exporter under the Clauses without the prior written consent of the data exporter. Where the data importer subcontracts its obligations under the Clauses, with the consent of the data exporter, it shall do so only by way of a written agreement with the subprocessor which imposes the same obligations on the subprocessor as are imposed on the data importer under the Clauses. Where the subprocessor fails to fulfil its data protection obligations under such written agreement the data importer shall remain fully liable to the data exporter for the performance of the subprocessor’s obligations under such agreement.

2. The prior written contract between the data importer and the subprocessor shall also provide for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject is not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against the data exporter or the data importer because they have factually disappeared or have ceased to exist in law or have become insolvent and no successor entity has assumed the entire legal obligations of the data exporter or data importer by contract or by operation of law. Such third-party liability of the subprocessor shall be limited to its own processing operations under the Clauses.

3. The provisions relating to data protection aspects for subprocessing of the contract referred to in paragraph 1 shall be governed by the law of the Member State in which the data exporter is established.

4. The data exporter shall keep a list of subprocessing agreements concluded under the Clauses and notified by the data importer pursuant to Clause 5(j), which shall be updated at least once a year. The list shall be available to the data exporter’s data protection supervisory authority.

Clause 12

Obligation after the termination of personal data-processing services

1. The parties agree that on the termination of the provision of data-processing services, the data importer and the subprocessor shall, at the choice of the data exporter, return all the personal data transferred and the copies thereof to the data exporter or shall destroy all the personal data and certify to the data exporter that it has done so, unless legislation imposed upon the data importer prevents it from returning or destroying all or part of the personal data transferred. In that case, the data importer warrants that it will guarantee the confidentiality of the personal data transferred and will not actively process the personal data transferred anymore.

2. The data importer and the subprocessor warrant that upon request of the data exporter and/or of the supervisory authority, it will submit its data-processing facilities for an audit of the measures referred to in paragraph 1.

Appendix 1 to the Standard Contractual Clauses

This Appendix forms part of the Standard Contractual Clauses (the 'Clauses').

Defined terms used in this Appendix 1 shall have the meaning given to them in the Agreement (including the DPA).

Data exporter

The data exporter is the legal entity specified as "Customer" in the DPA. 

Data importer

The data importer is Executive IT Forums, Inc.

Data subjects

Please see Annex 1 of the DPA, which describes the data subjects. 

Categories of data

Please see Annex 1 of the DPA, which describes the categories of data. 

Special categories of data (if appropriate)

The parties do not anticipate the transfer of special categories of data.

Purposes of Processing

Executive IT Forums, Inc. shall process personal data as necessary to provide the Subscription Services to data exporter in accordance with the Agreement.  

Processing operations

Please see Annex 1 of the DPA, which describes the processing operations. 

Appendix 2 to the Standard Contractual Clauses

This Appendix forms part of the Standard Contractual Clauses (the 'Clauses'). 

Description of the technical and organisational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached):

Please see Annex 2 of the DPA, which describes the technical and organisational security measures implemented by Executive IT Forums. 

Appendix 3 to the Standard Contractual Clauses

This Appendix forms part of the Standard Contractual Clauses (the 'Clauses').

This Appendix sets out the parties' interpretation of their respective obligations under specific terms of the Clauses. Where a party complies with the interpretations set out in this Appendix, that party shall be deemed by the other party to have complied with its commitments under the Clauses.  

For the purposes of this Appendix, "DPA" means the Data Processing Agreement in place between Customer and Executive IT Forums and to which these Clauses are incorporated and "Agreement" shall have the meaning given to it in the DPA. 

Clause 4(h) and 8: Disclosure of these Clauses  

a. Data exporter agrees that these Clauses constitute data importer's Confidential Information as that term is defined in the Agreement and may not be disclosed by data exporter to any third party without data importer's prior written consent unless permitted pursuant to Agreement.  This shall not prevent disclosure of these Clauses to a data subject pursuant to Clause 4(h) or a supervisory authority pursuant to Clause 8.

Clauses 5(a) and 5(b): Suspension of data transfers and termination

a. The parties acknowledge that data importer may process the personal data only on behalf of the data exporter and in compliance with its instructions as provided by the data exporter and the Clauses.

b. The parties acknowledge that if data importer cannot provide such compliance in accordance with Clause 5(a) and Clause 5(b) for whatever reason, the data importer agrees to inform promptly the data exporter of its inability to comply, in which case the data exporter is entitled to suspend the transfer of data and/or terminate the contract the affected parts of the Services in accordance with the terms of the Agreement.

c. If the data exporter intends to suspend the transfer of personal data and/or terminate the affected parts of the Services, it shall endeavor to provide notice to the data importer and provide data importer with a reasonable period of time to cure the non-compliance (“Cure Period”). 

d. If required, the parties shall reasonably cooperate with each other during the Cure Period to agree what additional safeguards or other measures, if any, may be reasonably required to ensure the data importer's compliance with the Clauses and applicable data protection law.

e. If after the Cure Period the data importer has not or cannot cure the non-compliance then the data exporter may suspend and/or terminate the affected part of the Services in accordance with the provisions of the Agreement without liability to either party (but without prejudice to any fees incurred by the data exporter prior to suspension or termination). The data exporter shall not be required to provide such notice in instance where it considers there is a material risk of harm to data subjects or their personal data.

Clause 5(f): Audit

a. Data exporter acknowledges and agrees that it exercises its audit right under Clause 5(f) by instructing data importer to comply with the audit measures described in the 'Demonstration of Compliance' section of the DPA.  

Clause 5(j): Disclosure of subprocessor agreements 

a. The parties acknowledge the obligation of the data importer to send promptly a copy of any onward subprocessor agreement it concludes under the Clauses to the data exporter.

b. The parties further acknowledge that, pursuant to subprocessor confidentiality restrictions, data importer may be restricted from disclosing onward subprocessor agreements to data exporter.  Notwithstanding this, data importer shall use reasonable efforts to require any subprocessor it appoints to permit it to disclose the subprocessor agreement to data exporter.

c. Even where data importer cannot disclose a subprocessor agreement to data exporter, the parties agree that, upon the request of data exporter, data importer shall (on a confidential basis) provide all information it reasonably requires in connection with such subprocessing agreement to data exporter. 

Clause 6: Liability 

a. Any claims brought under the Clauses shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement.  In no event shall any party limit its liability with respect to any data subject rights under these Clauses.

Clause 11:  Onward subprocessing 

a. The parties acknowledge that, pursuant to FAQ II.1 in Article 29 Working Party Paper WP 176 entitled "FAQs in order to address some issues raised by the entry into force of the EU Commission Decision 2010/87/EU of 5 February 2010 on standard contractual clauses for the transfer of personal data to processors established in third countries under Directive 95/46/EC" the data exporter may provide a general consent to onward subprocessing by the data importer.

b. Accordingly, data exporter provides a general consent to data importer, pursuant to Clause 11 of these Clauses, to engage onward subprocessors.  Such consent is conditional on data importer’s compliance with the requirements set out in the 'Notification and Objection to New Sub-Processors' section of the DPA. 

Clause 12: Obligation after the termination of personal data-processing services

a. Data importer agrees that the data exporter will fulfil its obligation to return or destroy all the personal data on the termination of the provision of data-processing services by complying with the 'Deletion or Return of Personal Data' section of the DPA.  

Annex 4 - List of Sub-Processors

Sub-Processor

Purpose

Location

Amazon Web Services, Inc.

Hosting & Infrastructure

United States

Google, Inc.

Regional data processing

United States

     

IContact, Inc.

Email sending infrastructure

United States

     

Mailgun, Inc

Email sending infrastructure

United States

     

BrightTalk, Inc.*

Webinar Infrastructure

United States

 

 

 

 

 

 

 

  • You need to create an account to submit blog posts on this platform.
  • Generally speaking, blog posts run 200-1200 words. Exceptions can be made on a case-by case basis.
  • We strive to represent balanced perspectives on topics of interest to the IT compliance community. The ideal submission will be educational in nature, broadly addressing IT compliance topics, or narrowly focused on particular aspects of IT compliance. User case studies, best practices, real-world examples, analysis, tutorials, perspectives and opinions are all acceptable. Please avoid commercial messages and promotions. Submissions by vendors and/or vendor representatives must be both product and vendor-neutral.
  • We reserve the right to edit, modify or reject submissions that include a favorable slant to any one vendor.
  • All submissions will be reviewed and published or rejected within 24hours. We reserve the right to edit all submissions for length and suitability to a given issue, without final and formal review of the contributor.

Terms of submission (agreed upon signup)

Contributions, whether published pseudonymously or not, are accepted on the strict understanding that the author is responsible for the accuracy of all opinion, technical comment, factual report, data, figures, illustrations and photographs. Publication does not necessarily imply that these are the opinions of the Editorial Board, Editors or the Publisher, nor do the Board, Editors or Publishers accept any liability for the accuracy of such comment, report and other technical and factual information.

The author bears the responsibility for checking whether material submitted is subject to copyright or ownership rights, eg photographs, illustrations, trade literature and data. Where use is so restricted, the Publisher must be informed with the submission of the material.

All reasonable efforts are made to ensure accurate reproduction of text, photographs and illustrations. The Publisher does not accept responsibility for mistakes, be they editorial or typographical, nor for consequences resulting from them

Any material you submit or upload to the Website will be considered non-confidential and non-proprietary, and you grant us a non-exclusive, perpetual, royalty-free, worldwide licence to publish such material in any format, including without limitation print or electronic format and to use, copy, distribute and disclose to third parties any such material for any purpose. We also have the right to disclose your identity to any third party who is claiming that any material posted or uploaded by you to the Website constitutes a violation of their intellectual property rights, or of their right to privacy or that it is defamatory of such person.

We will not be responsible, or liable to any third party, for the content or accuracy of any materials posted by you or any other user of the Website. Publication of any material you submit to us will be at our sole discretion and we have the reserve the right to make additions or deletions to the text or graphics prior to publication, or to refuse publication.

Executive IT Forums User Agreement

(date of last revision: March 2, 2018)

FOR SUBSCRIBERS (USERS ENJOYING OUR SITE SOLELY TO VIEW CONTENT) AND PRESENTERS.

PLEASE READ THIS USER AGREEMENT CAREFULLY. BY ACCEPTING THIS AGREEMENT OR ACCESSING OR USING EXECUTIVE IT FORUMS’ WEBSITE (THE “SITE”) OR THE SERVICES (AS DEFINED BELOW), YOU AGREE TO BE BOUND BY THE TERMS AND CONDITIONS DESCRIBED HEREIN. IF YOU DO NOT AGREE TO ALL OF THE TERMS OF THIS AGREEMENT, PLEASE DO NOT ACCESS THE SITE OR USE ANY OF THE SERVICES.

Welcome to Executive IT Forums. For the purposes of this Agreement, Executive IT Forums means Executive IT Forums Inc. The Site provides a network of internet-based services enabling access to live and recorded Content. Users are required to first set up an account by completing the registration process and to accept the terms and conditions of this Agreement, as well as the terms and conditions of the Executive IT Forums Privacy Policy. Capitalised terms are defined at end of this Agreement.

1. THIS AGREEMENT

This Agreement sets out the terms and conditions on which You may access and use the Site and all services provided on, through or by the Site, including the facility for all Users to post, submit, subscribe to view Content, as well as new features and services which may be introduced from time to time, and related technology (together, the “Services”).

Executive IT Forums reserves the right to modify the terms of this Agreement at any time by placing the revised terms on this website and in the case of material changes You will be notified by email to the email address of record in Your Account. Your continued use of the Services following the posting of the revised terms on this website, or the passage of fifteen (15) business days from the time of such posting, shall be deemed to constitute Your acceptance of such modification. If You do not agree to such modification, You should cease all use of the Site and the Services.

2. CONDITIONS AND RESTRICTIONS OF USE

2.1 User Eligibility

You may not set up an account on the Site if You are under the age of 18 or if You have been banned, suspended or had an account removed from the network by Executive IT Forums for any reason. If You set up an account, You are representing and warranting that You are at least 18 years of age. You may not have more than one account. You may not sell or otherwise transfer Your account to another party.

2.2 Registration and User Information

In order to use or access the Services, You are required to set up Your account by completing the registration process which requires You to provide Your Data. In providing such data, You represent and warrant that: (a) the information about Yourself is true, current, and complete, (b) You will maintain and promptly update Your Data to keep it true, current and complete; and (c) You will maintain the security of Your password and identification. You agree to accept all risks of unauthorised access, not directly caused by Executive IT Forums negligence, to Your account. If You provide inaccurate information, Executive IT Forums has the right to suspend or terminate Your account at any time. Executive IT Forums will collect information about Your use of the Services, including the Channels Summits, webinars and/or Content You choose to view.  When You attend or view Content in a Channel, You will automatically be subscribed to that Channel.  Executive IT Forums will use and reuse Your Data and information about Your viewing patterns subject to the Executive IT Forums Privacy Policy. This use may involve sharing Your Data and other information about Your viewing patterns with the owners of Channels, or the Sponsors of Summits, webinars or other Content, to which You subscribe, subject to compliance with the provisions of the Privacy Policy and the requirements of applicable law.

2.3 Licence to the Services

As between You and Executive IT Forums, Executive IT Forums is the owner or licensee of the Content. Subject to the terms and conditions of this Agreement, Executive IT Forums hereby grants You a limited, revocable, non-exclusive, non-transferable, non-sublicensable, worldwide, royalty-free licence for the duration of this Agreement, to use the Services solely for the purposes described in this Agreement, which include the right to embed a Channel or webinar on Your website, subject to compliance at all times with the provisions of this Agreement. All rights not expressly granted to You are reserved by Executive IT Forums and its licensors. Except as expressly permitted by Executive IT Forums, You shall not, and shall not permit or encourage any other party to: (a) licence, sublicence, sell, resell, rent, transfer or assign, the Services in any way; (b) reverse engineer, decompile, modify, translate, disassemble (except to the extent that this restriction is expressly prohibited by law) or create derivative works based upon the Services, including the Content, the underlying technology, and the Executive IT Forums player; (c) use any data mining, robots or similar data gathering or extraction methods or (d) use any of the Content or the Services other than for its intended purpose. Upon termination, suspension or expiration of this licence, You shall no longer have the right to use the Services or display, download or make available any Content from the Site. This licence shall terminate automatically upon termination or expiration of this Agreement.

2.4 Content

You acknowledge that Executive IT Forums does not routinely screen or review Content to determine whether, amongst other things, it contains false, inaccurate, misleading, defamatory, offensive, indecent, or objectionable material or contains errors and/or omissions. However, Executive IT Forums reserves the right, and has absolute discretion, to monitor, screen, edit or remove any Content posted on the Site or accessed through the Services at any time. Under no circumstances will Executive IT Forums be liable in any way for any User or other third-party Content, including, but not limited to, for any defamation, falsehoods, errors or omissions in any such Content, or for any loss or damage of any kind incurred as a result of the use or publication of any such Content posted, emailed or otherwise transmitted via the Services or the failure to access such Services. As set forth below in the Representations and Warranties and Limitation of Liability sections. Executive IT Forums does not guarantee that any Content will be suitable for any particular purpose, or to Your satisfaction.

2.5 Public Profiles

Your Public Profile contains details such as name, job title, organization, country, photos, Executive IT Forums.com activity and history, and comments. Other Users will be able to view Your Public Profile on Executive IT Forums.com should You so desire. You agree that all Profile Information shall be true and accurate, and You shall only create one Public Profile. You agree not to use information contained in Public Profiles to solicit Users from a competitor’s Channel. You agree that Your Public Profile shall not: (a) contain material that is defamatory, obscene, indecent, abusive, offensive, harassing, violent, hateful, inflammatory or otherwise objectionable; (b) contain material that is sexually explicit, pornographic, violent, or discriminatory; (c) promote illegal or unlawful activity; (d) impersonate or attempt to impersonate or stalk any person or entity; or (e) violate any applicable law or regulation or otherwise infringe any third parties’ right(s). Executive IT Forums reserves the right, and has absolute discretion, to remove any Public Profiles posted on Executive IT Forums.com or accessed through the Services at any time, for any or no reason, and without prior notice.

2.6 Term and Termination

This Agreement commences when accepted by You and has an Initial Term of three (3) months. Upon expiration of the initial term and each subsequent term, this Agreement will automatically renew for successive renewal terms in equal duration to the initial term unless You terminate this Agreement by providing written notice to Executive IT Forums at least 30 days prior to the end of the then-current term, or as otherwise stated below.

Executive IT Forums may terminate Your account and/or suspend Your access to the Services should You fail to comply with the terms and conditions contained in this Agreement or any other guidelines and rules published by Executive IT Forums. Executive IT Forums further reserves the right to terminate or suspend Your account with or without cause in Executive IT Forums’s sole discretion without prior notice. Termination or suspension of Your account does not terminate this Agreement. Should Executive IT Forums choose to terminate this Agreement, such termination does not constitute a waiver of any of Executive IT Forums’ rights under this Agreement or under applicable law.

THE FOLLOWING CLAUSES 2.7 TO 3, INCLUSIVE, APPLY ONLY TO USERS WHO ARE PRESENTERS

2.7 Ownership Rights

Each party retains any and all pre-existing right, title and interest in and to its website(s), trademarks, intellectual property, Your Content (in Your case), the Services (in the case of Executive IT Forums), and all components thereof. Except as expressly set out herein, this Agreement shall not be construed in any manner as transferring or creating any rights of ownership of, or licence to, the foregoing, and/or to the features or information therein. Under no circumstances will this Agreement be construed as granting, by implication, estoppel or otherwise, a licence to any intellectual or other property or components thereof other than as specifically granted in this Agreement. Executive IT Forums does not independently confirm that all Content is provided by a valid rights holder. In the event that Executive IT Forums becomes aware that Content has been provided by a person who is not a valid rights holder, Executive IT Forums may, at its discretion, disable and/or terminate the publication of such Content.

2.8 Licence to Content, Your Data and Your Performance

You hereby grant Executive IT Forums a non-transferable (except as provided herein), royalty-free, non-exclusive, worldwide licence to perform such acts in connection with Your Content as is necessary to provide the Services. The foregoing licence includes, without limitation, permission for Executive IT Forums to: (a) aggregate, publicly display, transmit, distribute, copy in its original form or in the form of an encoded work, store, archive, modify, create derivative works of, or reproduce Your Content and to perform such other acts with respect to Your Content as are necessary from time to time to provide the Services; (b) use Your Content and Your name, voice, likeness, persona and performance in connection with any webinars or other Content that You post, provide or participate in, in connection with the Service; (c) offer or provide open access to Your Content on or through the Site (or other website or service wholly-owned and/or operated by Executive IT Forums) and/or sub-domains thereof; (d) grant sublicences to Your Content to enable Your Content to be embedded and displayed on third party websites; (e) to distribute, transmit, and/or display Your Content on the Site or via such technologies as are or may in the future be supported by Executive IT Forums from time to time including without limitation, the internet and/or wireless transmission; (f) display advertisements in connection with or alongside any display of Your Content. For the avoidance of doubt, the parties expressly agree and acknowledge that the Services do not include any transfer of title to, or ownership of, any right or interest in Your Content. Such licence will survive termination of this Agreement.

2.9 Licence to Marks

Subject to the terms and conditions of this Agreement, You grant Executive IT Forums, a non-transferable (except as provided herein), non-exclusive, royalty-free, worldwide right to use, reproduce and display any logos, trademarks, trade names and other similar identifying material (the “Marks”) that You provide solely for the purposes described herein, and to grant sublicences thereto on the same terms and conditions to third parties that embed Your Content on their websites to the extent necessary in connection with the Services. This license and all sublicences thereto will survive termination of this Agreement.

2.10 Representations about Content

You specifically represent and warrant that any Content provided directly or indirectly by You, and its distribution and/or publication through the Services, the Site, or through its being embedded on any third party website, does not, and will not, infringe or misappropriate any third party’s rights, nor will Executive IT Forums’ use of such Content in accordance with the provisions of this Agreement violate any right of any person, including without limitation any copyrights, trademarks, rights of publicity and rights of privacy. You represent and warrant that You own or have obtained all necessary rights and licenses with respect to Your Content. You further represent that You have paid all licence fees and/or other fees required to be paid to third parties for performance of Your obligations or exercise of Your rights hereunder, for the grant of licences hereunder, and for any other act by You under this Agreement (“Third Party Licence Fees”) and You covenant to pay any Third Party License Fees required to be paid in the future for such actions in a timely manner. You further expressly agree that as between You, on the one hand, and Executive IT Forums on the other hand, any obligation to pay Third Party Licence Fees as a result of distribution of Your Content pursuant to this Agreement shall be Your obligation alone, and shall not be or become the obligation of Executive IT Forums.

3. INDEMNITY

You agree to indemnify and hold Executive IT Forums and its officers, directors, shareholders and employees harmless from any claim, damages, loss or liabilities (including reasonable legal costs) made by any third party due to or arising out of any Content You submit, post, transmit or otherwise make available through the Site or the Services.

4. DISCLAIMER OF WARRANTIES

THE SITE, THE SERVICE AND CONTENT PROVIDED BY EXECUTIVE IT FORUMS IS PROVIDED “AS IS”, WITH NO WARRANTIES WHATSOEVER. ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT OF PROPRIETARY RIGHTS, ARE EXPRESSLY DISCLAIMED BY EXECUTIVE IT FORUMS AND ITS LICENSORS TO THE FULLEST EXTENT PERMITTED BY LAW.

EXECUTIVE IT FORUMS AND ITS LICENSORS MAKE NO REPRESENTATION, WARRANTY, OR GUARANTEE AS TO THE RELIABILTY, TIMELINESS, QUALITY, SUITABILITY, TRUTH, AVAILABILITY, ACCURACY, NONINFRINGEMENT OR COMPLETENESS OF THE SITE, THE SERVICE OR ANY CONTENT, OR ANY USER DATA. EXECUTIVE IT FORUMS AND ITS LICENSORS DO NOT REPRESENT OR WARRANT THAT: (A) THE USE OF THE SITE OR THE SERVICE WILL BE SECURE, TIMELY, UNINTERRUPTED OR ERROR-FREE OR OPERATE IN COMBINATION WITH ANY OTHER HARDWARE, SOFTWARE, SYSTEM OR DATA; (B) THE SITE OR THE SERVICE WILL MEET YOUR REQUIREMENTS OR EXPECTATIONS; (C) ANY OF THE PRODUCTS, SERVICES, INFORMATION, OR OTHER MATERIAL PURCHASED OR OBTAINED BY YOU THROUGH THE SITE OR THE SERVICE WILL MEET YOUR REQUIREMENTS OR EXPECTATIONS; (D) ERRORS OR DEFECTS WILL BE CORRECTED; OR (E) THE SITE AND THE SERVICE ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS.

YOU EXPRESSLY ACCEPT THE FOREGOING DISCLAIMERS AS A CONDITION OF USE OF THE SITE. EXECUTIVE IT FORUMS FURTHER DISCLAIMS ANY RESPONSIBILITY FOR THE DELETION, FAILURE TO STORE, MISDELIVERY, OR UNTIMELY DELIVERY OF ANY INFORMATION OR MATERIAL. EXECUTIVE IT FORUMS DISCLAIMS ANY RESPONSIBILITHY OR LIABILITY FOR ANY HARM RESULTING FROM DOWNLOADING OR ACCESSING ANY INFORMATION OR MATERIAL THROUGH THE SITE OR THE SERVICE, INCLUDING, WITHOUT LIMITATION, FOR HARM CAUSED BY VIRUSES OR SIMILAR CONTAMINATION OR DESTRUCTIVE FEATURES, AND YOU ACCEPT SUCH RISK AS A CONDITION OF USE.

In any jurisdiction that does not allow the disclaimer of implied warranties, the foregoing disclaimers may not apply to You as they relate to implied warranties.

5. LIMITATION OF LIABILITY

YOU EXPRESSLY UNDERSTAND AND AGREE THAT UNDER NO CIRCUMSTANCES SHALL EXECUTIVE IT FORUMS OR ITS LICENSORS BE LIABLE TO ANYONE ON ACCOUNT OF USE OR MISUSE OF AND RELIANCE ON ANY PORTION OF THE SITE, THE SERVICE OR THE CONTENT. SUCH LIMITATION OF LIABILITY SHALL APPLY TO PREVENT RECOVERY OF DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, AND PUNITIVE DAMAGES (EVEN IF EXECUTIVE IT FORUMS OR ITS LICENSORS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES). SUCH LIMITATION OF LIABILITY SHALL APPLY WHETHER THE DAMAGES ARISE FROM USE OR MISUSE OF AND RELIANCE ON THE SERVICE AND/OR CONTENT, OR FROM INABILITY TO USE THE SERVICE, OR FROM THE INTERRUPTION, SUSPENSION, OR TERMINATION OF THE SERVICE (INCLUDING SUCH DAMAGES INCURRED BY THIRD PARTIES).

UNDER NO CIRCUMSTANCES SHALL EXECUTIVE IT FORUMS OR ITS LICENSORS BE HELD LIABLE FOR ANY DELAY OR FAILURE IN PERFORMANCE RESULTING DIRECTLY OR INDIRECTLY FROM ACTS OF NATURE, FORCES, OR CAUSES BEYOND ITS REASONABLE CONTROL, INCLUDING WITHOUT LIMITATION, INTERNET FAILURES, COMPUTER EQUIPMENT FAILURES, TELECOMMUNICATION EQUIPMENT FAILURES, OTHER EQUIPMENT, TECHNOLOGY OR, ELECTRICAL POWER FAILURES, NONPERFORMANCE OF THIRD PARTIES OR GOVERNMENTAL ACTIONS.

IN NO EVENT SHALL THE AGGREGATE LIABILITY OF EXECUTIVE IT FORUMS, WHETHER IN CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE, WHETHER ACTIVE, PASSIVE OR IMPUTED), PRODUCT LIABILITY, STRICT LIABILITY OR OTHER THEORY, ARISING OUT OF OR RELATING TO THE USE OF OR INABILITY TO USE THE SITE, THE SERVICES OR THE CONTENT EXCEED THE COMPENSATION YOU PAY, IF ANY, TO EXECUTIVE IT FORUMS FOR ACCESS TO OR USE OF THE SITE OR THE SERVICES IN THE TWELVE MONTHS PRECEDING THE CIRCUMSTANCES THAT GAVE RISE TO THE CLAIM.

In any jurisdiction that does not permit limitations of liability, the foregoing limitation may not apply to You.

Notwithstanding any other provision of this Agreement, nothing in this Agreement shall limit or exclude the liability of either party in respect of: (a) death or personal injury resulting from its negligence, or the negligence of its Personnel; (b) fraud or fraudulent misrepresentation; or (c) any other act or omission, liability for which cannot be limited or excluded under applicable law.

6. CHANGE OF CONTROL

In the event of a change of control of Executive IT Forums, this Agreement shall be binding upon and inure to the benefit of the parties hereto and Executive IT Forums’ heirs, successors and assigns.

7. NOTICES, GOVERNING LAW AND JURISDICTION

All notices under this Agreement should be addressed to:

Executive IT Forums Inc.
1 Penn Plaza
Suite 6272
New York, NY 10119
USA

This Agreement is governed by the laws of the State of New York, and is subject to the exclusive jurisdiction of the courts of New York, NY, USA. This does not affect Your statutory rights.

8. GENERAL DEFINITIONS APPLICABLE TO THIS AGREEMENT

In this User Agreement, the following definitions shall apply:

  • The “Site” means websites served by the Executive IT Forums technology platform;
  • Channel” means a Executive IT Forums™ embeddable webinar player on which the Channel Owner can provide You with access to upcoming, live and recorded webinars and other Content using self-service applications;
  • Channel Owner” means someone who sets up, manages, and populates a Channel;
  • Content” means all webinars and other content that is published on the Site or through the Service, including, without limitation, content in Public Profiles, video, music, audio, photographs, images, text, trade mark, copyrighted work, any digital file, any live or recorded event;
  • Presenter” means any individual who delivers a presentation in a webinar or other Content;
  • Public Profile” means a public profile that contains details including name, job title, organization, country, photos, Executive IT Forums.com activity and history, and comments that is shared with other Users;
  • Sponsor” means any person or entity that sponsors a Summit or specific Content;
  • Summit” means a Executive IT Forums™ Summit which is an online seminar, with multiple presentations and speakers, that is broadcast live and also available for later on-demand viewing and that may include webinars from more than one Channel;
  • Users” means all Channel Owners, Presenters and You;
  • You” means you, or, if you are accepting on behalf of your employer or another entity, “You” means that employer or entity;
  • Your Data” means information that You are required to provide to complete the registration process or opt to provide to Executive IT Forums;
  • Your Content” means any Content that is placed and/or provisioned by You on the Site;

Note: certain terms, including “Services,” are defined in the main body of the Agreement above.

9. COPYRIGHT COMPLAINTS AND REPEAT INFRINGERS

If You believe that any Content or materials on the Site or the Service infringes any copyright which You own or control, You may file a notification of such infringement with our Designated Agent as set forth below:

Notification of copyright infringement should be sent by mail, fax or email to:

Designated Agent: Cinthia Pilar
Address: 42 Broadway, Suite 12-415, New York, NY 10004, USA
Telephone Number: +1 646 525 4801
Fax Number: +1 646 478 9736
Email Address: 
This email address is being protected from spambots. You need JavaScript enabled to view it.

In accordance with the Digital Millennium Copyright Act (DMCA) and other applicable law, Executive IT Forums has adopted a policy of terminating, in appropriate circumstances and at Executive IT Forums’ sole discretion, the accounts of Users or account holders who are deemed to be repeat infringers. Executive IT Forums may also at its sole discretion limit access to the Site and/or terminate Your account if You infringe any intellectual property rights of others, whether or not there is any repeat infringement.

Executive IT Forums Privacy Notice

 
Last updated April 04, 2023
 
This privacy notice for Executive IT Forums, Inc ("we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
  • Visit our website at executiveitforums.org, or any website of ours that links to this privacy notice
  • Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at This email address is being protected from spambots. You need JavaScript enabled to view it..
 
 
SUMMARY OF KEY POINTS
 
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
 
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
 
Do we process any sensitive personal information? We do not process sensitive personal information.
 
Do we receive any information from third parties? We do not receive any information from third parties.
 
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
 
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more about when and with whom we share your personal information.
 
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
 
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
 
How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
 
Want to learn more about what we do with any information we collect? Review the privacy notice in full.
 
 
TABLE OF CONTENTS
 
 
 
1. WHAT INFORMATION DO WE COLLECT?
 
Personal information you disclose to us
 
In Short: We collect personal information that you provide to us.
 
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
 
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
  • names
  • phone numbers
  • email addresses
  • job titles
  • passwords
  • mailing addresses
Sensitive Information. We do not process sensitive information.
 
Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Facebook, Twitter, or other social media account. If you choose to register in this way, we will collect the information described in the section called "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below.
 
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
 
Information automatically collected
 
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.
 
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
 
Like many businesses, we also collect information through cookies and similar technologies.
The information we collect includes:
  • Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
  • Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.
 
2. HOW DO WE PROCESS YOUR INFORMATION?
 
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
 
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
  • To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
  • To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.
  • To send you marketing and promotional communications. We may process the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt out of our marketing emails at any time. For more information, see "WHAT ARE YOUR PRIVACY RIGHTS?" below.
  • To deliver targeted advertising to you. We may process your information to develop and display personalized content and advertising tailored to your interests, location, and more.
  • To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
  • To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
 
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
 
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
 
If you are located in the EU or UK, this section applies to you.
 
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
  • Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
  • Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
  • Send users information about special offers and discounts on our products and services
  • Develop and display personalized and relevant advertising content for our users
  • Analyze how our Services are used so we can improve them to engage and retain users
  • Understand how our users use our products and services so we can improve user experience
  • Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
  • Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
In legal terms, we are generally the "data controller" under European data protection laws of the personal information described in this privacy notice, since we determine the means and/or purposes of the data processing we perform. This privacy notice does not apply to the personal information we process as a "data processor" on behalf of our customers. In those situations, the customer that we provide services to and with whom we have entered into a data processing agreement is the "data controller" responsible for your personal information, and we merely process your information on their behalf in accordance with your instructions. If you want to know more about our customers' privacy practices, you should read their privacy policies and direct any questions you have to them.
 
If you are located in Canada, this section applies to you.
 
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
 
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
  • If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
  • For investigations and fraud detection and prevention
  • For business transactions provided certain conditions are met
  • If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
  • For identifying injured, ill, or deceased persons and communicating with next of kin
  • If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
  • If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
  • If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
  • If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
  • If the collection is solely for journalistic, artistic, or literary purposes
  • If the information is publicly available and is specified by the regulations
 
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
 
In Short: We may share information in specific situations described in this section and/or with the following third parties.
 
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct. The third parties we may share personal information with are as follows:
  • Advertising, Direct Marketing, and Lead Generation
Google AdSense
  • Data Backup and Security
Dropbox Backup
  • Invoice and Billing
Stripe
  • Social Media Sharing and Advertising
Twitter social plugins
 
We also may need to share your personal information in the following situations:
  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • When we use Google Maps Platform APIs. We may share your information with certain Google Maps Platform APIs (e.g., Google Maps API, Places API). We use certain Google Maps Platform APIs to retrieve certain information when you make location-specific requests. This includes: __________; and other similar information. A full list of what we use information for can be found in this section and in the previous section titled "HOW DO WE PROCESS YOUR INFORMATION?" The Google Maps Platform APIs that we use store and access cookies and other information on your devices. If you are a user currently in the European Economic Area (EU countries, Iceland, Liechtenstein, and Norway) or the United Kingdom, please take a look at our Cookie Notice.
  • Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.
  • Business Partners. We may share your information with our business partners to offer you certain products, services, or promotions.
 
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
 
In Short: We may use cookies and other tracking technologies to collect and store your information.
 
We may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
 
6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
 
In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.
 
Our Services offer you the ability to register and log in using your third-party social media account details (like your Facebook or Twitter logins). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, friends list, and profile picture, as well as other information you choose to make public on such a social media platform.
 
We will use the information we receive only for the purposes that are described in this privacy notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information, and how you can set your privacy preferences on their sites and apps.
 
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
 
In Short: We may transfer, store, and process your information in countries other than your own.
 
Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information (see "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above), in the United States, and other countries.
 
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this privacy notice and applicable law.
 
European Commission's Standard Contractual Clauses:
 
We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Our Data Processing Agreements that include Standard Contractual Clauses are available here: https://executiveitforums.org/it-grc-forum/terms/it-grc-forum-dpa. We have implemented similar appropriate safeguards with our third-party service providers and partners and further details can be provided upon request.
 
EU-US Privacy Shield Framework
 
We comply with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union (EU) and the UK to the United States. Although Privacy Shield is no longer considered a valid transfer mechanism for the purposes of EU data protection law, in light of the judgment of the Court of Justice of the European Union in Case C-311/18 and opinion of the Federal Data Protection and Information Commissioner of Switzerland dated 8 September 2020, we will continue to comply with the principles of the EU-US Privacy Shield Framework. Learn more about the Privacy Shield program. To view our certification, please visit https://executiveitforums.org/it-grc-forum/terms/it-grc-forum-dpa.
 
We adhere to and comply with the Privacy Shield Principles when processing personal information from the EU or UK. If we have received your personal information in the United States and subsequently transfer that information to a third party acting as our agent, and such third party agent processes your personal information in a manner inconsistent with the Privacy Shield Principles, we will remain liable unless we can prove we are not responsible for the event giving rise to the damage.
 
With respect to personal information received or transferred pursuant to the Privacy Shield Framework, we are subject to the investigatory and enforcement powers of the US Federal Trade Commission ("FTC"). In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
 
If you have any questions or concerns relating to our Privacy Shield certification, please write to us at the contact details below. We commit to resolving any complaints or disputes about our collection and use of your personal information under the Privacy Shield. However, if you have an unresolved complaint in connection with our certification,
 
In limited situations, EU and UK individuals may seek redress from the Privacy Shield Panel, a binding arbitration mechanism.
 
Please be sure to review the following sections of this privacy notice for additional details relevant to our participation in the EU-US Privacy Shield:
 
8. HOW LONG DO WE KEEP YOUR INFORMATION?
 
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law.
 
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than   the period of time in which users have an account with us.
 
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
 
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
 
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
 
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
 
10. DO WE COLLECT INFORMATION FROM MINORS?
 
In Short: We do not knowingly collect data from or market to children under 18 years of age.
 
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at This email address is being protected from spambots. You need JavaScript enabled to view it..
 
11. WHAT ARE YOUR PRIVACY RIGHTS?
 
In Short: In some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
 
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
 
We will consider and act upon any request in accordance with applicable data protection laws.
 
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
 
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
 
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below or updating your preferences.
 
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
 
Opting out of marketing and promotional communications:You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, replying "STOP" or "UNSUBSCRIBE" to the SMS messages that we send, or by contacting us using the details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, to respond to service requests, or for other non-marketing purposes.
 
Account Information
 
If you would at any time like to review or change the information in your account or terminate your account, you can:
  • Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.
 
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services.
 
If you have questions or comments about your privacy rights, you may email us at This email address is being protected from spambots. You need JavaScript enabled to view it..
 
12. CONTROLS FOR DO-NOT-TRACK FEATURES
 
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
 
13. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
 
In Short: If you are a resident of California, Connecticut, Colorado, Utah or Virginia, you are granted specific rights regarding access to your personal information.
 
What categories of personal information do we collect?
 
We have collected the following categories of personal information in the past twelve (12) months:
 
Category Examples Collected
A. Identifiers
Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name
 
 
 
 
B. Personal information as defined in the California Customer Records statute
Name, contact information, education, employment, employment history, and financial information
 
 
 
 
C. Protected classification characteristics under state or federal law
Gender and date of birth
 
NO
 
D. Commercial information
Transaction information, purchase history, financial details, and payment information
 
NO
 
E. Biometric information
Fingerprints and voiceprints
 
NO
 
F. Internet or other similar network activity
Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements
 
 
 
G. Geolocation data
Device location
 
NO
 
H. Audio, electronic, visual, thermal, olfactory, or similar information
Images and audio, video or call recordings created in connection with our business activities
 
NO
 
I. Professional or employment-related information
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us
 
 
 
J. Education Information
Student records and directory information
 
NO
 
K. Inferences drawn from collected personal information
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics
 
NO
 
L. Sensitive personal Information  
 
NO
 
 
We will use and retain the collected personal information as needed to provide the Services or for:
  • Category A - As long as the user has an account with us
  • Category B - As long as the user has an account with us
  • Category F - As long as the user has an account with us
  • Category I - As long as the user has an account with us
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
  • Receiving help through our customer support channels;
  • Participation in customer surveys or contests; and
  • Facilitation in the delivery of our Services and to respond to your inquiries.
How do we use and share your personal information?
 
Learn about how we use your personal information in the section, "HOW DO WE PROCESS YOUR INFORMATION?"
 
Will your information be shared with anyone else?
 
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information to in the section, "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
 
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.
 
We have disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:
  • Category A. Identifiers
  • Category B. Personal information as defined in the California Customer Records law

  • Category F. Internet or other electronic network activity information
  • Category I. Professional or employment-related information
The categories of third parties to whom we disclosed personal information for a business or commercial purpose can be found under "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
 
We have sold or shared the following categories of personal information to third parties in the preceding twelve (12) months:
The categories of third parties to whom we sold personal information are:
  • Sponsors
IT Vendors
 
The categories of third parties to whom we shared personal information with are:
 
California Residents
 
California Civil Code Section 1798.83, also known as the "Shine The Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).
 
CCPA Privacy Notice
This section applies only to California residents. Under the California Consumer Privacy Act (CCPA), you have the rights listed below.
 
The California Code of Regulations defines a "residents" as:
(1) every individual who is in the State of California for other than a temporary or transitory purpose and
(2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose
All other individuals are defined as "non-residents."
If this definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information.
 
Your rights with respect to your personal data
 
Right to request deletion of the data — Request to delete
 
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.
 
Right to be informed — Request to know
 
Depending on the circumstances, you have a right to know:
  • whether we collect and use your personal information;
  • the categories of personal information that we collect;
  • the purposes for which the collected personal information is used;
  • whether we sell or share personal information to third parties;
  • the categories of personal information that we sold, shared, or disclosed for a business purpose;
  • the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose;
  • the business or commercial purpose for collecting, selling, or sharing personal information; and
  • the specific pieces of personal information we collected about you.
In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
 
Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights
 
We will not discriminate against you if you exercise your privacy rights.
 
Right to Limit Use and Disclosure of Sensitive Personal Information
 
We do not process consumer's sensitive personal information.
 
Verification process
 
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone or email) that you have previously provided to us. We may also use other verification methods as the circumstances dictate.
 
We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.
 
Other privacy rights
  • You may object to the processing of your personal information.
  • You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.
  • You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.
You can opt out from the selling or sharing of your personal information by disabling cookies in Cookie Preference Settings and clicking on the Do Not Sell or Share My Personal Information in your user profile.
 
To exercise these rights, you can contact us by submitting a data subject access requestby email at This email address is being protected from spambots. You need JavaScript enabled to view it.or by referring to the contact details at the bottom of this document. If you have a complaint about how we handle your data, we would like to hear from you.
 
Colorado Residents
 
This section applies only to Colorado residents. Under the Colorado Privacy Act (CPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
  • Right to be informed whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Preference Settings. To submit a request to exercise any of the other rights described above, please email This email address is being protected from spambots. You need JavaScript enabled to view it. or submit a data subject access request.
 
If we decline to take action regarding your request and you wish to appeal our decision, please email us at This email address is being protected from spambots. You need JavaScript enabled to view it.. Within forty-five (45) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
 
Connecticut Residents
 
This section applies only to Connecticut residents. Under the Connecticut Data Privacy Act (CTDPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
  • Right to be informed whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Preference Settings. To submit a request to exercise any of the other rights described above, please email This email address is being protected from spambots. You need JavaScript enabled to view it. or submit a data subject access request.
 
If we decline to take action regarding your request and you wish to appeal our decision, please email us at This email address is being protected from spambots. You need JavaScript enabled to view it.. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
 
Utah Residents
 
This section applies only to Utah residents. Under the Utah Consumer Privacy Act (UCPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
  • Right to be informed whether or not we are processing your personal data
  • Right to access your personal data
  • Right to request deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to opt out of the processing of your personal data if it is used for targeted advertising or the sale of personal data
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data or targeted advertising by disabling cookies in Cookie Preference Settings. To submit a request to exercise any of the other rights described above, please email This email address is being protected from spambots. You need JavaScript enabled to view it. or submit a data subject access request.
 
Virginia Residents
 
Under the Virginia Consumer Data Protection Act (VCDPA):
 
"Consumer" means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context.
 
"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable natural person. "Personal data" does not include de-identified data or publicly available information.
 
"Sale of personal data" means the exchange of personal data for monetary consideration.
 
If this definition of "consumer" applies to you, we must adhere to certain rights and obligations regarding your personal data.
 
Your rights with respect to your personal data
 
  • Right to be informed whether or not we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to request deletion of your personal data
  • Right to obtain a copy of the personal data you previously shared with us
  • Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
We sell personal data to third parties or process personal data for targeted advertising. Please see the following section to find out how you can opt out from further selling or sharing of your personal data for targeted advertising or profiling purposes.
 
 
Exercise your rights provided under the Virginia VCDPA
 
You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Preference Settings. You may contact us by email at This email address is being protected from spambots. You need JavaScript enabled to view it. or submit a data subject access request.
 
If you are using an authorized agent to exercise your rights, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.
 
Verification process
 
We may request that you provide additional information reasonably necessary to verify you and your consumer's request. If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request.
 
Upon receiving your request, we will respond without undue delay, but in all cases, within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within the initial 45-day response period, together with the reason for the extension.
 
Right to appeal
 
If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please email us at This email address is being protected from spambots. You need JavaScript enabled to view it.. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.
 
14. DO WE MAKE UPDATES TO THIS NOTICE?
 
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
 
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
 
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
 
If you have questions or comments about this notice, you may contact our Data Protection Officer (DPO), Cinthia Pilar, by email at This email address is being protected from spambots. You need JavaScript enabled to view it., by phone at 646-525-4801, or contact us by post at:
 
Executive IT Forums, Inc
Cinthia Pilar
42 Broadway
Suite 12-415
New York 10004
United States
 
If you are a resident in the European Economic Area, we are the "data controller" of your personal information. We have appointed This email address is being protected from spambots. You need JavaScript enabled to view it. to be our representative in the EEA. You can contact them directly regarding our processing of your information, by visiting executiveitforums.org.
 
If you are a resident in the United Kingdom, we are the "data controller" of your personal information. We have appointed Cinthia Pilar to be our representative in the UK. You can contact them directly regarding our processing of your information, by email at This email address is being protected from spambots. You need JavaScript enabled to view it., by visiting executiveitforums.org.
 
 
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
 
You have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please fill out and submit a data subject access request.

HOW TO SUBMIT CONTENT
The IT GRC Forum invites esteemed and successful professionals in executive-level compliance positions to write featured articles, submit press releases, upcoming events, and white papers. New articles on compliance are posted each week and made available on the site homepage, through our RSS feed and email digest, and through search engines. We are always looking for fresh content contributions for the IT GRC Forum. A post has the opportunity to get wide exposure to over 100,000 GRC professionals.

What Can You Write About?

The ideal submission will be well crafted and educational in nature to stimulate dialogue, broadly addressing IT compliance topics, or narrowly focused on particular aspects of IT compliance.

  • User Case Studies - best practices, real-world examples, analysis, tutorials, perspectives and opinions are all acceptable.
  • Technical – These articles should include detailed instructions, how-to’s, tutorials and getting started or guides to a specific security technology, framework or concept.
  • Career – All kinds of security career topics that would appeal to: employees, managers, freelancers, entrepreneurs, and students.
  • Events – Post your upcoming events and webinars to raise awareness with the GRC community.
  • Marketing Yourself – Blogging, personal branding, speaking, networking, using social networks, podcasting. These articles should teach how to sell themselves to others, either through their current position or as a freelancer and/or entrepreneur.
  • Productivity – System, hacks, learning, etc. These articles should give IT security professionals the tools to accelerate their processes and put their best work (and selves) out to the world.
  • Products – Software, hardware, services, gadgets, reviews, recommendations. These articles should include detailed specifications and information that will advise our readers all the good, bad, and ugly about the product.
  • Research reports and White Papers - Thought leadership, best practices, real-world examples, analysis, tutorials, perspectives and opinions are all acceptable.

Content Standards

Whenever you make use of a feature that allows you to upload or submit material to our site, or to make contact with other users of our site, you must comply with the content standards set out below. You warrant that any such contribution does comply with those standards, and you indemnify us for any breach of that warranty. Authors must ensure that references to named people and/or organisations are accurate, not racist or sexist and without libellous implications. These standards apply to each part of any contribution as well as to its whole: Be accurate (where they state facts). Be relevant. Be genuinely held (where they state opinions). Be original to you. Comply with applicable law in the USA and in any country from which they are posted.

Contributions must not: Be obscene, offensive, hateful, threatening, racially offensive, inflammatory, incite violence or contain sexually explicit material. Advocate, promote or assist any illegal activity of any kind. Be defamatory of any person or violate another person's privacy rights or otherwise contain unlawful materialInfringe any copyright, database right or trade mark of any other person or party. Be made in breach of any legal duty owed to a third party, such as a contractual duty or a duty of confidence. Be used to impersonate any person, or to misrepresent your identity or affiliation with any person. Give the impression that they emanate or are endorsed by us, if this is not the case. Constitute spamming, advertising or promotion of goods or services.

Additional Content Requirements

  • Length of the post should not exceed 1,000 words
  • Any submitted images need to be rights free or author has the rights to post the image. Images cannot exceed 1MB in file size
  • Posts will be featured on the homepage banner, and latest news/events/research section for one month
  • Posts will reside on the site and can be accessed based on their tags/categories or search
  • Content is subject to approval by the IT GRC Forum. We reserve the right to reject posts for any reason
  • Content will typically be posted within 48 hours

The Submission and Editing Process

The IT GRC Forum publishes only the most well written and relevant articles into its compliance knowledge transfer forum. Each article is carefully reviewed by our editorial board to ensure the overall quality for both authors and and readers. We strive to represent balanced perspectives on topics of interest to the GRC community. After your article is approved, the publishing process can take anywhere from 1-7 days from your initial submission, and may involve your active participation in rewrites and revisions.

How To Submit an Article

To submit your content on the IT GRC Forum use the form below, or alternatively send your article to This email address is being protected from spambots. You need JavaScript enabled to view it. and we’ll be in touch about getting your content published on the site! If you have any questions, you can email us.

Processing Charges

We charge a flat processing fee of $150 per submission of sponsored content. Block-booking discounts are also available (see below).

.

Submit Your Content (Press Release, Event, or White Paper) Below...


  

Executive IT Forums Privacy Policy

(date of last revision: May 3, 2018)

1. Introduction

Executive IT Forums recognizes that privacy is important when using the Web for communications. This policy explains how Executive IT Forums collects, stores, uses and shares Personal Data.

2. This Policy

This Policy is issued by Executive IT Forums Inc. (“Executive IT Forums”) and is addressed to individuals outside our organization with whom we interact, including visitors to our website (our “Site”) and other users of our services (together, “you”). Defined terms used in this Policy are explained in Section (15) below.

For the purposes of this Policy, Executive IT Forums is the Controller. Contact details are provided in Section (14) below.

This Policy may be amended or updated from time to time to reflect changes in our practices with respect to the Processing of Personal Data, or changes in applicable law. We encourage you to read this Policy carefully, and to regularly check this page to review any changes we might make in accordance with the terms of this Policy.

3. Processing your Personal Data

Collection of Personal Data: We may collect Personal Data about you, such as your name, address and contact details. The Executive IT Forums Data Processing Agreement  and its Annexes (“DPA”) reflects the parties’ agreement with respect to the Processing of Personal Data by us on behalf of you in connection with the Executive IT Forums Subscription Services under the Executive IT Forums Customer Terms of Service between you and us (also referred to in this DPA as the “Agreement”).  Examples of sources from which we may collect Personal Data include the following:

  • We may obtain your Personal Data when you provide it to us (e.g., where you contact us via email or telephone, or by any other means).
  • We may collect your Personal Data in the ordinary course of our relationship with you (e.g., in the course of administering your Executive IT Forums account).
  • We may collect Personal Data that you manifestly choose to make public, including via our Site.
  • We may receive your Personal Data from third parties who provide it to us (e.g., social media platforms via plugins).
  • We may collect or obtain Personal Data when you visit our Site, or use any features or resources available on or through our Site. When you visit our Site, your device and browser will automatically disclose certain information, some of which may constitute Personal Data (see below).

Creation of Personal Data: We may also create Personal Data about you, such as records of your interactions using our Site, and details of your account history.

Categories of Personal Data: The categories of Personal Data about you that we may Process include:

  • Personal details: given name(s); preferred name; gender; date of birth / age; nationality; photograph; preferences; and account settings.
  • Contact details: telephone number; email address; and social media profile details.
  • Professional details: professional profile details; association memberships; qualifications and company insight data.
  • Device details: device type, operating system, browser type, browser settings, IP address, language settings, dates and times of connecting to our Site and other technical communications information.
  • Payment details: billing address; bank account number or credit card number; cardholder or accountholder name; card or account security details; card ‘valid from’ date; card expiry date.
  • Usage details: records of your use of our Site and other services, including: registrations; details of content with which you interact; votes; questions; downloads; ratings; feedback; profile views; search queries; anonymous viewings; page views; player clickstream; chapters; and favorite moments.
  • Analysis data: keywords, communities, trends, content quality and content importance.
  • Views, opinions and interests: any comments, ratings, views or opinions that you choose to send to us, post via our Site, via a survey, or publicly post via social media platforms; your community interests and solution interests.

Lawful basis for Processing Personal Data: In Processing your Personal Data in connection with the purposes set out in this Policy, we may rely on one or more of the following legal bases, depending on the circumstances:

  • we have obtained your prior express consent to the Processing (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way);
  • the Processing is necessary in connection with any contract that you may enter into with us;
  • the Processing is required by applicable law;
  • the Processing is necessary to protect the vital interests of any individual; or
  • we have a legitimate interest in carrying out the Processing for the purpose of managing, operating or promoting our business, and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms.

Processing your Sensitive Personal Data: We do not seek to collect or otherwise Process your Sensitive Personal Data, except where:

  • the Processing is required or permitted by applicable law (e.g., to comply with our diversity reporting obligations);
  • the Processing is necessary for the detection or prevention of crime (including the prevention of fraud);
  • the Processing is necessary for the establishment, exercise or defence of legal rights; or
  • we have, in accordance with applicable law, obtained your prior explicit consent prior to Processing your Sensitive Personal Data (as above, this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way).

Purposes for which we may Process your Personal Data: The purposes for which we may Process Personal Data, subject to applicable law, include:

  • Our Site:
  • Provision of services to you: providing our Site and other services to you (including suggesting content that may be of interest to you, based on your past activity); communicating with you in relation to those services; recommending content that may be of interest to you; and recommending your content to others.
  • Marketing communications: communicating with you via any means (including via email, telephone, text message, social media, post or in person) news items and other information in which you may be interested, subject to ensuring that such communications are provided to you in compliance with applicable law.
  • Disclosing Personal Data to our customers: in accordance with the provisions of this Policy and applicable law, we may disclose certain Personal Data to our customers. With your prior express consent, we may provide your personal data to our customers for the purposes of enabling them to contact you with information that may be of interest to you. Additionally, our Customers may contact you with information that may be of interest to you provided that such communication is not otherwise in breach of applicable laws.
  • Communications and IT operations: management of our communications systems; operation of IT security; and IT security audits.
  • Health and safety: health and safety assessments and record keeping; and compliance with related legal obligations.
  • Financial management: sales; finance; corporate audit; and vendor management.
  • Surveys: engaging with you for the purposes of obtaining your views on our Site or our services.
  • Improving our Site and our services: identifying issues with existing Site and our services; planning improvements to existing Site and our services; creating new Site and our services.

4. Disclosure of Personal Data to third parties

We may disclose your Personal Data to other entities within the Executive IT Forums group, for legitimate business purposes (including providing services to you and operating our Site), in accordance with applicable law. In addition, we may disclose your Personal Data to: our customers, subject always to compliance with the terms of this Policy and the requirements of applicable law;

  • legal and regulatory authorities, upon request, or for the purposes of reporting any actual or suspected breach of applicable law or regulation;
  • accountants, auditors, lawyers and other outside professional advisors to Executive IT Forums, subject to binding contractual obligations of confidentiality;
  • third party Processors (such as IT service providers; social media plugin providers;; etc.), located anywhere in the world, subject to the requirements noted below in this Section (4);
  • any relevant party, law enforcement agency or court, to the extent necessary for the establishment, exercise or defence of legal rights;
  • any relevant party for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
  • any relevant third party acquirer(s), in the event that we sell or transfer all or any relevant portion of our business or assets (including in the event of a reorganization, dissolution or liquidation); and
  • If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under applicable law.

5. International transfer of Personal Data

Because of the international nature of our business, we may need to transfer your Personal Data within the Executive IT Forums group, and to third parties as noted in Section (4) above, in connection with the purposes set out in this Policy. For this reason, we may transfer your Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.

Where we transfer your Personal Data to other countries, we do so on the basis of Standard Contractual Clauses. You may request a copy of our Standard Contractual Clauses using the contact details provided in Section (14) below.

6. Data Security

We have implemented appropriate technical and organizational security measures designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unlawful or unauthorized forms of Processing, in accordance with applicable law.

You are responsible for the ensuring that any Personal Data that you send to us are sent securely.

7. Data Accuracy

We take every reasonable step to ensure that:

  • your Personal Data that we Process are accurate and, where necessary, kept up to date; and
  • any of your Personal Data that we Process that are inaccurate (having regard to the purposes for which they are Processed) are erased or rectified without delay.

From time to time we may ask you to confirm the accuracy of your Personal Data.

8. Data Minimization

We take every reasonable step to ensure that your Personal Data that we Process are limited to the Personal Data reasonably required in connection with the purposes set out in this Policy.

9. Data Retention

The criteria for determining the duration for which we will keep your Personal data are as follows: we will retain copies of your Personal Data in a form that permits identification only for as long as is necessary in connection with the purposes set out in this Policy, unless applicable law requires a longer retention period. In particular, we may retain your Personal Data for the duration of any period necessary to establish, exercise or defend any legal rights.

10. Your legal rights

Subject to applicable law, you may have a number of rights regarding the Processing of your Personal Data, including:

  • the right to request access to, or copies of, your Personal Data that we Process or control;
  • the right to request rectification of any inaccuracies in your Personal Data that we Process or control;
  • the right to request, on legitimate grounds:
    • erasure of your Personal Data that we Process or control; or
    • restriction of Processing of your Personal Data that we Process or control;
    • the right to object, on legitimate grounds, to the Processing of your Personal Data by us or on our behalf;
    • the right to have your Personal Data that we Process or control transferred to another Controller, to the extent applicable;
    • where we Process your Personal Data on the basis of your consent, the right to withdraw that consent; and
    • the right to lodge complaints with a Data Protection Authority regarding the Processing of your Personal Data by us or on our behalf.

This does not affect your statutory rights.

To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Policy, or about our Processing of your Personal Data, please use the contact details provided in Section (14) below.

11. Cookies

A cookie is a small file that is placed on your device when you visit a website (including our Site). It records information about your device, your browser and, in some cases, your preferences and browsing habits. We may Process your Personal Data through cookie technology, in accordance with our Cookie Policy.

12. Minors

Minors under the age of eighteen years old are not eligible to use our Site and we therefore ask that minors do not submit any Personal Data to us, or use any of the services provided on, through or via our Site.

13. Terms of Use

All use of our Site is subject to our Terms of Use.

14. Contact details

If you have any comments, questions or concerns about any of the information in this Policy, or any other issues relating to the Processing of Personal Data by Executive IT Forums, please contact:

Privacy Department

Executive IT Forums Inc.
42 Broadway
Suite 12-415
New York, NY 10004
USA

This email address is being protected from spambots. You need JavaScript enabled to view it.

6465254801

15. Definitions

  • ‘Controller’ means the entity that decides how and why Personal Data is Processed. In many jurisdictions, the Controller has primary responsibility for complying with applicable data protection laws.
  • ‘Data Protection Authority’ means an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws.
  • ‘Personal Data’ means information that is about any individual, or from which any individual is identifiable. Examples of Personal Data that we may Process are provided in Section (3)
  • ‘Process’‘Processing’ or ‘Processed’ means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • ‘Processor’ means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).
  • ‘Sensitive Personal Data’ means Personal Data about race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health, sexual life, any actual or alleged criminal offences or penalties, national identification number, or any other information that may be deemed to be sensitive under applicable law.

 

 

 

 

 

 

 

CyberBanner

Log in

Please Login to download this file

Username *
Password *
Remember Me

CyberBanner

CyberBanner

CyberBanner

Go to top