PRIVACY POLICY

This Privacy Policy regulates how ePact manages the information it collects from the Visitors of ePact’s website (“Website”) as well as the information a Visitor of the Website has to submit to ePact in order to register an account with the Website, use ePact’s services (“Services”) and become a Customer and the information that ePact collects from the Signers and Reviewers who access and use the Website and the Services.

By accessing and using the Website and/or the Services you consent to this Privacy Policy. If you do not agree with this Privacy Policy, you must immediately leave the Website and cease using it or any of the Services and delete your account if you have registered such. For further information on the terms on which you may use the Website and the Services, please also see ePact’s Terms of Use.

ePact reserves the right to make changes to this Privacy Policy. Any changes to the Privacy Policy will be posted on this page and will enter into force on the date stated in the change. If you do not agree with the changes, you must immediately leave the Website and cease using it or any of the Services and delete your account if you have registered such.

For clarity, the terms “Customer”, “User’s Data”, “Digital Signature”, “Reviewer” “Services”, “Signer”, “Subscription Period”, “User” and “Visitor” are used as they are defined in the Terms of Use.

Irrespective of what is stated in this Privacy Policy, the processing of the part of the User’s Data which is personal data is governed by article 4 in the Terms of Use. In no way is ePact to be considered controller of the personal data which is part of the User’s Data. If anything in this Privacy Policy contradicts to article 4 in the Terms of Use, it is the Terms of Use which shall have precedence over what is stated in the Privacy Policy.



Information ePact collects


To purchase Digital Signature(s) and Subscription Period(s) you need to register an account with the Website. When registering an account, you provide ePact with the following information:

  •  • Name
  •  • E-mail
  •  • Address
  •  • Business registration number
  •  • Telephone
  •  • Credit card data
  •  • Password

In addition, ePact collects information about account registration and accepting the Terms of Use and the Privacy Policy (date and time of registration).

For every visitor of the Website and for everyone who uses the Services, regardless of whether it is a Visitor, a Signer, a Reviewer or a Customer, ePact collects the following information:

  •  • IP address
  •  • Identifier of the visitor with high degree of uniqueness
  •  • Last login time

ePact uses log files and server logs in relation to the Website’s and the Services’ security, maintenance, development, etc., including log files and server logs about:

  •  • ensuring the Website’s and the Services’ functionality and fixing technical problems;
  •  • ensuring the Website’s and the Services’ security and detecting malicious actions;
  •  • account log-in (date, hour, IP address, browser).


Purposes the information is used for


ePact uses the information described above for the following purposes:

  •  • to deliver you access to and use of the Website and the Services;
  •  • to maintain and improve the Website and the Services;
  •  • to identify you as a contracting party;
  •  • to identify you as a Visitor, Signer, Reviewer or Customer;
  •  • to invoice the Customers who have purchased Digital Signature(s) and Subscription Period(s);
  •  • to send you information about products by email after obtaining your consent.


Legal grounds for collection, storage and processing of the information


ePact collects, stores and processes your information on one or more of the following legal grounds:

  •  • your consent;
  •  • it is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract;
  •  • it is necessary for compliance with a legal obligation to which we are subject.

If your information is collected, stored and processed based solely on your consent, you may at any time withdraw your consent by contacting ePact here epact@apact.eu.



Period for which the information is stored


ePact will store your information as long as it has a legal base for such storing, including for purposes like invoicing and complying with legal obligations.

For more information about how long ePact stores the information for the purpose of tracking visitors’ behavior please see section “Cookies” below.



Cookies


The Website uses cookies. A cookie is a small text file sent from a web browser to your web browser and stored on your device.

Generally, there are two types of cookies – temporary (session) and permanent. Session cookies are temporarily stored on your device when you visit a webpage, but are deleted when you close the webpage. Permanent cookies are stored as file on your device for a longer period of time.

ePact uses cookies to personalize the content of the Website, to provide you the Services and to keep statistic about the traffic of the Website. ePact considers the use of those cookies its legitimate interest, so that it can keep the proper functioning of the Website and continue providing you with the Services.

You are hereby notified that ePact uses some trusted third party’s cookies as a part of the Website and the Services. These cookies are governed by the respective trusted third party and are not under ePact’s control. Such trusted third parties include Google. For more information about their cookies, please visit their relevant websites.

ePact uses the following types of cookies:

  •  • Necessary cookies – they make the Website and the Services usable and without them the Website and the Services will not function properly.
  •  • Statistics cookies – they help ePact to understand how you interact with the Website and the Services. These cookies are anonymized.

You can find detailed information about the cookies that we use below:


COOKIE NAME PURPOSE CATEGORY EXPIRY
__stripe_mid This cookie is necessary for making credit card transactions on the web site. The service is provided by Stripe.com which allows online transactions without storing any credit card information. Necessary 1 year
__stripe_sid This cookie is necessary for making credit card transactions on the web site. The service is provided by Stripe.com which allows online transactions without storing any credit card information. Necessary 1 day
csrftoken Helps prevent Cross-Site Request Forgery (CSRF) attacks. Necessary 1 day
sessionid Used by ePact to keep the users logged in. Necessary 14 days
session_id Used by ePact to allow not logged users to use some of the core functionality. Necessary Session
_ga Registers a unique ID that is used to generate statistical data on how the visitor uses the web site. The service is provided by Google Analytics. Statistic 2 years
_gat Used by Google Analytics to throttle request rate Statistic 1 day
_gid Registers a unique ID that is used to generate statistical data on how the visitor uses the web site. Statistic 1 day

Apart from the cookies that are necessary for the Website and the Services to function, ePact stores cookies on your device only with your consent. You can withdraw or change your consent at any time. You can do it here:




If you do not want cookies to be stored on your device, please check the settings of your browser. Each browser might have different kind of settings:

Remember that if you do that, you might not be able to use some or all features of the Website and the Services.



Location of the collected information


ePact stores the information on ePact’s webserver which is placed in Finland and is operated by a hosting provider trusted by ePact, Hetzner Online GmbH.



Disclosure of information to third parties


ePact does not disclose, sell, transfer or share information about you with third parties unless in the following cases:

  •  • it has a legal obligation to do so;
  •  • information is provided to trusted partners or subcontractors who are in contractual relations with ePact and have a duty of confidentiality. These trusted partners include Google with its respective product: Google Analytics. ePact undertakes to get into agreements only with partners and subcontractors who comply with the legal requirements about personal data protection, security and processing, including the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“Regulation (EU) 2016/679”). We hereby notify you that some of ePact’s partners might transfer personal data outside the EU. For further information, please read the privacy policies of ePact’s partners.

If you do not want ePact to send the information to its partners, you may withdraw your consent the way it is described in the section “Cookies” above.



Protection of the information

ePact strives to keep your information safe and secure, therefore it applies appropriate technical and organizational measures for personal data security and protection.



Your rights


Pursuant to Regulation (EU) 2016/679 you have the following rights:

  •  • Right of access to your personal data: You have the right to receive confirmation from ePact whether any personal data related to you is processed and, if this is the case, you have the right to access the personal data and receive information of how it is being processed.
  •  • Right to rectification: You have the right to obtain from ePact without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
  •  • Right to erasure: In certain circumstances, such as the case that your personal data has been processed unlawfully or you have withdrawn your consent (if the processing of personal data is based on consent), you may request the erasure of your personal data.
  •  • Right of restriction of processing of the personal data: In certain circumstances, such as if you have doubts about the accuracy of your personal data or have objected to ePact’s legitimate purpose for processing your personal data, you may request that ePact restrict the processing of your personal data.
  •  • Right to object to processing of personal data: In certain circumstances, such as if you have doubts about ePact’s legitimate interest in processing of your personal data, you have the right to object to such processing.
  •  • Right to personal data portability: In case that the processing is based on your consent and that the processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract and that the processing is carried out by automated means, you may request to receive a complete and machine-readable copy of your personal data and transfer it to another controller.
  •  • Right to complain: You are entitled to file a complaint regarding ePact’s processing of your personal data at the relevant supervisory authority.

Last updated: 9 January 2019