Scope of Policy
- Collected from prospective customers or suppliers while negotiating a commercial contract or agreement.
- Collected through Descartes’s publicly accessible websites, public forums, and other publicly accessible internet sites maintained by the Descartes, excluding any of Descartes ecommerce sites.
- Collected from individuals attending offices, conferences, or trade show booths run by the Descartes.
- Collected from subscribers to Descartes mailing lists, email lists, newsletters, and social media channels and feeds.
Where the personal information is related to third-parties and was received by Descartes through a customer (and not directly from the third-party itself), the handling of such personal information will be governed by the terms of the Data Processing Attachment which forms part of the commercial agreement between Descartes and that customer.
What we use personal information for
In order to provide you our products or services or to effectively make use of your products or services, we may use personal information for the following reasons:
- To manage any required billing or invoicing matters, including who and where to direct such matters to;
- To manage access to the service or product through user access management;
- To communicate with you when providing or receiving technical support on your request;
- When required by law or regulation, to identify the specific individual who interacted with a government entity through our products or services, such as by filing a customs report;
- To verify that there does not exist any conflict of interest, prohibition, or government regulation which restricts us from doing business with you;
- To provide customers information and updates about new features, bugs, and work arounds for specific products or services; and
- To provide customers information about other Descartes products or services designed to complement the existing Descartes product or service you have purchased or subscribed to.
What personal information is collected
Personal information is information about an identifiable individual. Depending on local law, publicly available information — such as a public directory listing of your name, address, telephone number, email or other electronic address — may not be considered personal information.
The following table provides a list of the categories of personal information that we may collect and process from customers, suppliers, and vendors of Descartes and why we collect it:
|Categories of information||Examples||Why we need that information|
|Information about your identity||Legal name, aliases, date of birth, governmental or national identification number||To allow us to uniquely identify every individual accessing our products or services for access management purposes.|
|Contact information||Email address, phone number, or mailing address.||To notify you of changes to your account, to notify you of the completion of any scheduled reports or tasks, to provide account reset information if requested, to communicate with you regarding account or technical support issues.|
|Employer information||Name of employer, your role or position with your employer, and any authority delegated to you by your employer for the purpose of interacting with us.||To be able to properly receive your instructions, to ensure we apply your instructions to the right customer, and to ensure we can provide evidence of your instructions to your employer / our customer.|
Duration of Processing
The Descartes maintains personal information only as long as it is required to fulfill the purpose under which it was gathered, unless required by law to retain for longer periods or other purposes. Where Descartes determines that personal information is no longer required, we will securely destroy such information as soon as it is commercially reasonable to do so.
Sharing of Information
As Descartes is a global organization, our network operations span multiple data centers across the world. Our products and services rely on this interconnected network of data centers to provide you with efficient and resilient experiences. By providing us your personal information, you consent to us transferring your personal information to the various countries that Descartes operates in.
In some limited circumstances, Descartes may use a third-party data processor to process personal information. Categories of processing may include the following:
- to organize and manage customer related information using purpose-built applications;
- to more efficiently communicate with multiple customers, suppliers, or vendors; and
- to provide customers technical support.
All third-parties are required to use industry standard security to protect any data they have access to and may only process the information for the purpose, duration, and in the manner specified by Descartes. A list of the subprocessors used by Descartes can be found in the Supplemental Privacy Information section (https://www.descartes.com/legal/privacy-center/supplemental-privacy-information). Descartes is responsible for and remains liable for the handling of personal information provided by Descartes to its subprocessors.
In the event of an emergency or valid court order, we may also share personal information with law enforcement agencies or government regulators if permitted by law to do so.
Selling of Personal Information
The Descartes does not collect any personal information for the purpose of selling that personal information. Despite this, some jurisdictions require us to make the following additional statements:
- We have not sold any personal information in the past twelve months.
- We do not sell personal information to third parties.
Additional Contractual Obligations
Further, there may be terms and conditions in our commercial agreements with you that add to our privacy commitment outlined in this document. If there is a contradiction between this policy and those commercial agreements, the obligations of the commercial agreements will prevail.
Requesting access, changes, or limits to your own Information
Under applicable law you may request from us the following:
- a copy of any of your personal information which we may have;
- to update or correct any inaccuracies in your personal information that we may have;
- to request that we limit our use of your personal information, including but not limited to instructing us not using your personal information for a specific purpose;
- to erase some or all of your personal information that we do not have a legal entitlement to keep; or
- withdraw any previously provided consent for our use of your personal information.
To make any of the above requests to access, change, or impose limits on the processing of your personal information, please contact us at [email protected] with details of your request. For the purposes of verifying your identity we may ask that you provide us sufficient personal details to allow us to identify you, which may include but may not be limited to your full legal name, your email address, your phone number, and/or your mailing or physical address. Such information will only be used for the purpose of verifying your identity.
In addition, while Descartes does not sell personal information to third parties, some jurisdictions still require that we provide you a means to opt out of the sale of your personal information to third parties.
Contacting the Data Protection Officer
Michael Verhoeve, Data Privacy Officer
Mail: 120 Randall Drive, Waterloo, Ontario, Canada, N2V 1C6
Email: [email protected]
Personal Information from European Union, European Economic Area, and Switzerland
The following Descartes affiliates or subsidiaries (collectively referred to as “Descartes US”) comply with the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Frameworks, as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States:
- Descartes Insurance Services, Inc.
- Descartes Systems (USA) LLC
- Descartes Systems VM LLC
- Descartes U.S. Holdings, Inc.
- Descartes Visual Compliance (USA) LLC
- MacroPoint LLC
- Peoplevox LLC
The Federal Trade Commission has jurisdiction over Descartes US’ compliance with Privacy Shield.
All Descartes US employees who handle personal information from the European Union or Switzerland are required to comply with the Privacy Shield Principles stated in this policy.
Disputes covered by Privacy Shield
In compliance with the Privacy Shield Principles, Descartes US commits to resolve complaints about our collection or use of your personal information. European Union and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact the Data Protection Officer using the contact information provided for in the section titled “Contacting the Data Protection Officer”.
Descartes US has further committed to refer unresolved Privacy Shield complaints to the ICDR/AAA, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not resolved your complaint, please contact or visit the ICDR/AAA (http://go.adr.org/privacyshield.html) for more information or to file a complaint. The services of the ICDR/AAA are provided at no cost to you.
If you are not satisfied with the resolution provided by the ICDR/AAA, under certain conditions you may be able to invoke binding arbitration to address complaints regarding Descartes US’ compliance with Privacy Shield. Further instructions on binding arbitration are available at https://www.privacyshield.gov/article?id=ANNEX-1-introduction.
Verification of Privacy Shield compliance
Descartes US utilizes the self-assessment approach to assure its compliance with its Privacy Shield obligations and regularly verifies that this policy is accurate, comprehensive, prominently displayed, completely implemented, and in conformity with the EU-US Privacy Shield and Swiss-US Privacy Shield. Descartes US conducts its self-assessment on an annual basis to ensure all relevant privacy practices are followed.
[End of Policy]