Privacy Policy
Welcome!
Welcome to Simplyk! We hope that you will appreciate using our “Services”, which includes visiting our “Website” at https://app.simplyk.io/ or any subdomain thereof or using our “Platform” that allows “Organizations” to obtain online donations, administer event ticketing, organize peer-to-peer campaigns, publish volunteer opportunities and receive payments from Members and Contributors. In using our Services, you will fall into one of the following categories:
- “Contributor”: You are making a payment to the benefit of an Organization via the Platform and / or you are registering for tickets to an Organization’s event.
- “End User”: You are a user authorized by an Organization to use the Services through that Organization’s Account.
- “Member”: You are a Contributor or a Volunteer who has created an Account on the Platform. Please note that as a Contributor or a Volunteer, you are not obligated to create an Account.
- “Visitor”: You are visiting an Organization’s website and you fill in your name and email address on the form that is powered by Simplyk, but you ultimately decide not to complete the form.
- “Volunteer”: You are contributing without charge or compensation to an Organization and you have been referred and matched through the Platform.
- “Website Visitor”: You are browsing our Website.
In this Policy, each of a Contributor, End User, Member, Visitor, Volunteer or Website Visitor may be referred to as “you” or “your”. Please also note that these definitions are not exclusive – for example, it is possible to be both a Contributor and a Website Visitor.
We want you to know that we take your privacy and protection of personal data very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you use the Services or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully.
Key Elements of this Policy
Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.
Personal data we collect from you but only with your consent | What we do with it | Third parties we share it with |
End User Account Information | Manage your Account and enable logging in to the Services; enable you to connect with Contributors and Volunteers | Companies providing technical infrastructure for the Services, such as Amazon Web Services; companies that permit us to manage the End User relationship, such as HubSpot |
Member Account Information | Manage your Account and enable logging in to the Services | Companies providing technical infrastructure for the Services, such as Amazon Web Services |
Contributor Information | Share it with an Organization to which you have chosen to contribute; send you tax receipts | Organizations; SendGrid, which sends you emails on an Organization’s behalf |
Donation Billing Information | Process donations from Contributors | Stripe, our payment processor |
Volunteer Information | Share it with an Organization with which you have chosen to volunteer | Organizations; SendGrid, which sends you emails on an Organization’s behalf |
Visitor Information | Share it with an Organization whose form you have filled in | Organizations; SendGrid, which sends you emails on an Organization’s behalf |
Contact Information | Communicate with you | Sendinblue, our email service provider |
Demo Information | Invite you to one of our weekly demo meetings at your request | Sendinblue, our email service provider; Zoom, the platform used to host the weekly demo meeting |
Chat Information | Communicate with you and respond to your inquiry | Companies that provide chat services, such as HubSpot |
Some Terms
Before we get started with the details, here are a few terms we think you should know as you read this Policy.
“Data Protection Laws” refers to the laws that are designed to protect your personal data and privacy in the place where you live. These include: (1) the “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council; (2) “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada; and (3) the California Consumer Privacy Act (“CCPA”) which applies to our activities in the United States in certain circumstances. Simplyk is committed to adhering to all these applicable Data Protection laws.
“Personal data” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA and the CCPA, the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information.
Additional definitions shall be made throughout this Policy, but they will be recognizable as they will be capitalized, bolded, and in quotation marks. Additional definitions may also be found in the Terms and Conditions of Use – NPO and Terms of Use - Users and will have the same meaning in this Policy as they do there.
About Us and Contacting Us
The Services are owned and operated by 9355-0861 Québec Inc., the Quebec corporation that owns and operates the Simplyk Platform (“Simplyk”) and that is located in Montreal, Canada at the address listed below. Where this Policy refers to “Simplyk”, it may refer to 9355-0861 Québec Inc. and / or its shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns, depending on the context.
Under the GDPR, Simplyk is a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way.
If you want to ask us anything about what’s in this Policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can email:
Simplyk Privacy Officer
Here is the mailing address for you as well:
Simplyk Privacy Officer
917 Mont-Royal Avenue East
Montreal, Quebec, H2J 1X3
Canada
Your Rights
You have the following rights regarding your personal data held by Simplyk, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. Nevertheless, exercising certain of these rights may affect your ability to use some or all of the Services.
- The right to withdraw your consent for Simplyk to process your personal data at any time;
- The right to have your personal data erased from Simplyk’s records;
- The right to access your personal data and any relevant information around its processing and use;
- The right to have a copy of your personal data given to you in an easy-to-read format so that you can transfer it to another data processor;
- The right to have your personal data corrected or updated if you believe it is inaccurate or out of date;
- The right to opt out of marketing communications we send you at any time;
- The right to know whether Simplyk sells or shares your personal data (and if so, who gets it). Please refer to that information elsewhere in this Policy, though you can contact our Privacy Officer if you need additional information or clarification;
- The right to demand that Simplyk not sell your personal data;
- The right to restrict the processing of your personal data if it is inaccurate or if our processing or use of it is against the law; and
- The right to refuse any marketing or advertising targeted at you by Simplyk.
If you wish to exercise any of these rights, please contact our Privacy Officer at the contact information above or refer to certain relevant sections further in this Policy.
Personal Data Collected from You and What We Use It For
In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to Simplyk.
Personal data category | Personal data processed | What we use it for (the “purpose” of processing) | Legal basis for processing under the GDPR |
End User Account Information | Name, email address, Organization name, phone number, country where you are located | To manage your Account and enable logging in to the Services | Your consent and performance of a contract between you and us |
Member Account Information | Name, email address, Organization name, phone number, country where you are located | To manage your Account and enable logging in to the Services | Your consent and performance of a contract between you and us |
Contributor Information | First name, last name, email address, address and any other information that an Organization may request from you | To share with an Organization to which you have chosen to contribute; to send you tax receipts | Your consent in giving us this information and the performance of a contract between you and us |
Donation Billing Information | Credit/Visa debit card holder name, number, expiration date, CVV number and billing address | To process donations from Contributors; to make sure an Organization to which you have decided to contribute receives your donation | Your consent in giving us this information |
Volunteer Information | First name, last name, email address and any other information that an Organization may request from you | To share with an Organization with which you have chosen to volunteer | Your consent in giving us this information |
Visitor Information | First name, last name, email address | To share with an Organization whose form you have filled in | Your consent in giving us this information |
Contact Information | Name and email address; optionally, the organization with which you are affiliated | To communicate with you | Your consent in giving us this information |
Demo Information | Name and email address; optionally, your phone number | To invite you to one of our weekly demo meetings at your request | Your consent in giving us this information |
Chat Information | Any personal data submitted via the Website’s chat function | To communicate with you and to respond to your inquiry | Your consent in giving us this information |
Where you have provided personal data further to the contract between you and us, if you fail to provide such data or withdraw your consent to use such data, we will no longer be able to provide certain Services to you.
Personal Data Collected About You from Third Parties and What We Use It For
Sometimes we get personal data about you from third parties. This table explains the details about this personal data – what it is, where it came from, what we do with it, and the legal basis for us having and processing this personal data under the GDPR. Under PIPEDA, the legal basis is your informed consent.
Personal data category | Personal data processed | Who we get the data from | What we use it for (the “purpose” of processing) | Legal basis for processing under the GDPR |
Donation Billing Information | Certain PayPal, Apple Pay or Google Pay account information | PayPal, Apple or Google | To allow you to use your PayPal, Apple Pay or Google Pay accounts to donate to an Organization via Stripe | Your consent |
End User Account Information | Name, email address, Organization name | The Organization where you are employed or volunteering can create an Account on your behalf | To create your Account so that you can use the Services as an End User | An Organization’s legitimate interest in setting up Accounts for its employees and Volunteers |
Member Information; Contributor Information; Volunteer Information | First name, last name, email address, address and any other information that an Organization had previously requested and collected from you | Other donation management platforms, if an Organization transfers its data (including all personal data) from another donation management platform to Simplyk | To permit an Organization to use your Member Information, Contributor Information and Volunteer Information in connection with the Platform and as otherwise described in this Policy | An Organization’s legitimate interest in switching between donation management platforms |
To the extent that analytics identifiers are generated from third parties, these may be considered personal data collected from third parties, and you can find details about that further below in this Policy.
Sensitive Personal Data
We do not collect any of what the GDPR considers sensitive personal data from you, unless you voluntarily submit it either via the Website’s chat function or feedback form, by sending an Organization a message via the Platform or by email, which we encourage you not to do.
Who We Transfer Your Personal Data To
We routinely share some of your personal data with certain types of third parties who are identified in the table below along with what they do with it. Some of those third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area — please see the “Transfer of Your Personal Data Outside of the European Economic Area” further down in this Policy for more information including on how we safeguard your personal data when this occurs.
We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of Simplyk’s Terms and Conditions of Use – NPO or Terms of Use – Users or other contract that governs your relationship with us; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Services infrastructure or the internet in general (such as voluminous spamming or denial of service attacks).
We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with Simplyk (in which case we will require such entities to honour this Policy); (2) if Simplyk merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).
We will never share your personal data with other third parties except under these circumstances. We do not sell your personal data to any third party for direct marketing purposes or any other purpose.
Personal data category | Who we transfer it to | What they do with it |
End User Account Information | Companies providing technical infrastructure for the Services, specifically Amazon Web Services and Heroku | Control your logging in to the Platform and record-keeping Facilitate the functioning of the Services |
End User Account Information (name and email address only) | Companies that are integrated with the Website and that allow you to provide direct feedback to us, specifically Canny | Allow you to provide feedback to us about the Services and email you to let you know we have responded to your feedback |
Member Account Information | Companies providing technical infrastructure for the Services, specifically Amazon Web Services and Heroku | Control your logging in to the Platform and record-keeping |
Member Account Information (name and email address only) | Companies that are integrated with the Website and that allow you to provide direct feedback to us, specifically Canny | Allow you to provide feedback to us about the Services and email you to let you know we have responded to your feedback |
Contributor Information | Organizations SendGrid, which provides email services on an Organization’s behalf, as detailed more fully in the Email Communications section below | Contact you and interact with you as a Contributor Send you emails |
Donation Billing Information | Process your donation to an Organization to which you have chosen to contribute | |
Volunteer Information | Organizations SendGrid, which provides email services on an Organization’s behalf, as detailed more fully in the Email Communications section below | Contact you and interact with you as a Volunteer Send you emails |
Visitor Information | Organizations SendGrid, which provides email services on an Organization’s behalf, as detailed more fully in the Email Communications section below | Contact you Send you emails |
Contact Information | Companies that provide email services, specifically Sendinblue, as detailed more fully in the Email Communications section below | Send you emails |
Demo Information | Zoom | Send you an invitation to one of our weekly demo meetings at your request Give you access to the weekly demo meeting that you signed up for |
Chat Information | Operate the chat service on the Website; email you a transcript of the chat (if you have an End User Account) | |
Advertising Identifiers | Companies that provide online advertising networks, like Google and Facebook, and as further detailed in the Simplyk Advertising section below | Show you ads for Simplyk and the Services when you are on the internet |
Analytics Identifiers (including your IP address) | Companies that provide data analytics, specifically Google Analytics, Amplitude, Hotjar, Canny and HubSpot | Provide us with analytics as to how the Services are used and trace fraudulent activities |
Tracking Technology (“Cookies” and Related Technologies)
Simplyk uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) in connection with the Services and by interacting with the Services you agree to their use. Cookies are small text files placed on your computer or device when you visit a website or use an online service, in order to track use of the site or service and to improve the user experience by storing certain data on your computer or device.
Specifically, we use cookies and related technologies for the following functions:
- to enable your signing-in to the Platform;
- to facilitate the proper functioning of the Services;
- to facilitate online advertising, as described more fully below in this Policy;
- to provide general internal and user analytics on the Services and to conduct research to improve the content of the Services using analytics programs listed above in this Policy; and
- to assist in identifying possible fraudulent activities.
Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:
Please note that deleting or blocking certain cookies may reduce your user experience by requiring you to re-enter certain information, including information required to use our Services. Furthermore, deleting certain cookies may prevent certain functions, or the entirety of the Services, from working at all.
Simplyk Advertising and Opting Out
Simplyk uses certain advertising networks to provide advertising to you. Specifically, we use Google AdWords and Display Network and Facebooks Ads and by visiting the Website, you consent to their use. Specifically, Simplyk uses the remarketing features of Google AdWords’ interest-based advertising, which displays Simplyk advertisements that should be of particular interest to you based on your browsing and activity history interacting with the Website. These advertisements will appear on third-party websites around the web. Google uses specific cookies to allow them to serve these advertisements to you. Additionally, Simplyk also uses Facebook Ads to serve you advertisements for Simplyk when you are on Facebook. You may prevent this type of advertising by deleting the appropriate Google or Facebook cookie through your browser, though this may not be permanent. For a more permanent solution, you may opt out of such Google or Facebook advertising by adjusting your Google and Facebook ad settings or by using the WebChoices online opt-out tool.
Email Communications and Compliance with Anti-Spam Laws
Simplyk uses Sendinblue (i) to manage our mailing list and send out our newsletter and promotional emails; and (ii) to send out emails related to the Services. Simplyk also allows Organizations to send you emails related to the Services directly from the Platform, including with respect to donations, ticket purchases and volunteer opportunities, which is done using SendGrid (together with Sendinblue, the “Email Service Providers”). Personal data is transferred to the Email Service Providers in order for the emails to be sent out properly. Your email address is only used to send out emails; the Email Service Providers do not use this personal data for any other purpose and will not transfer or sell your personal data to any other third party. For more information, please refer to Sendinblue's Privacy Policy and Twilio's Privacy Policy, which applies to SendGrid.
You may unsubscribe from the Simplyk mailing list or emails that you receive from Organizations via Simplyk (as described above) at any time, by following the link at the bottom of the Simplyk or Organization emails. Other types of emails, such as emails related to the Platform and emails that you will receive from Organizations with your tax receipts will not have an opt-out option as they are necessary for the use of the Services.
Simplyk’s practices with regard to its email are designed to be compliant with anti-spam laws, specifically the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23). If you believe you have received email in violation of these laws, please contact us using the contact information further up in this Policy.
How We Protect Your Personal Data
We have implemented very strict technical and organisational procedures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws require us to do so, and within the time frame required by the applicable Data Protection Law.
Simplyk uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Services, and these third parties have been selected for their high standards of security, both electronic and physical. For example, Simplyk uses Amazon Web Services and Heroku, both recognized leaders in secure data, for hosting of the Services and related data, and storage of data, including personal data.
Finally, all information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check Simplyk’s valid SSL security certificate.
Transfer of Your Personal Data Outside of the European Economic Area (EEA)
For our European users, we endeavour to keep your personal data inside the EEA. However, certain of our data processors (and Simplyk) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:
- Canada. Canada has been determined to have an “adequate level of protection” for your personal data under European data protection law.
- The United States. Your personal data is only transferred to companies in the United States that: (1) have signed agreements with us or have informed us that they are GDPR-compliant; and (2) have concluded the Standard Contractual Clauses for the transfer of personal data outside the EEA.
That’s it! You have the right, however, to refuse to have your data transferred outside the EEA. Please contact our Privacy Officer to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Services.
Supervisory Authorities and Complaints
If you are in the EEA, under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about Simplyk’s data practices, we invite you to contact the supervisory authority in your country. If you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.
The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.
Data Retention
Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your End User Account Information for as long as you have an account with us. Please note that Simplyk reserves the right to retain some of your personal data for a reasonable time in order to satisfy our legal obligations or under a legal procedure of any sort.
Automated Decision-Making
Simplyk does not use any automated decision-making processes in providing the Services.
Children’s Privacy Statement
The Services are not intended for children under the age of 16. We do not knowingly collect any personal data from a child under 16. If we become aware that we have inadvertently received personal data from a person under the age of 16 through the Services, we will delete such information from our records.
Changes to This Privacy Policy
The date at the top of this page indicates when this Policy was last updated. Every now and then, we will have to update this Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL, and we will always post a notice on the Website if we make significant changes. If you have an End User or Member Account, we will also email you to tell you the Policy has been updated, and what the important changes are.
Last modified 1yr ago