This Privacy Notice describes the ways in which Pegasystems (“Pega”, “we”, “our”, or “us”) may collect, process, use, and disclose information about you through the websites, social media properties, phone calls, applications, contractual and precontractual activities, your visits to our office, other online services operated by us, and Pega-hosted events or contests (collectively, the “ Services”), and the choices you can make about the way your information is collected and processed through the Services. By using any Service, you consent to the processing of your information as set forth in this Privacy Notice, now and as may be amended by us from time to time.
Table of Contents
What information do we collect and receive?
We and our service providers may collect and receive both personal information and other information from a variety of sources that generally fall into three categories:
- Direct Interactions: Data from your use of, and interaction with us through, any Service, social media channel and/or other activity such as account creation, Client support requests, interactions related to a pending or signed contract or testing, submissions of registrations and posting to forums, visits to our office or sales inquiries and transactions.
- Automated Interactions: Data from the use of technologies such as electronic communication protocols, robotics and analytic tools, cookies, embedded URLs or pixels, or widgets, buttons and similar tools.
- Publicly Available Data / Data from Third Parties: Data from automated interactions on non-Pega websites, or other data you may have made publicly available, such as social media posts, or data provided by third party sources, such as marketing lists, partner referrals, or data aggregators.
1. Direct Interactions
You, or the organization you work for, may submit data that includes your name, contact information such as a physical address, email address, phone number, username, password, employer and job title, activity logs, and registration information to us when using the Services. We also collect and receive information when you:
- create a Pega account;
- participate in our message boards and discussion forums or other interactive features;
- interact with us on social media or the Services;
- apply for a job (our Candidate Privacy Notices can be found here);
- make a purchase (e.g., purchase credits for use at Pega Academy);
- participate in polls and surveys; register for events and self-study courses;
- sign up to receive electronic newsletters and other materials;
- download or request software, product upgrades, reports, and other information;
- submit a partner or reseller diligence questionnaire;
- submit an RFP or customer questionnaire;
- interact with us in relation to a pending or signed contract or testing;
- participate in PegaWorld or similar events;
- submit an application for Pega Ventures; or
- contact us with a question, comment, or request, including requests for technical support.
- visit our offices as a guest
The information that you provide us may include one or more of the following:
- your name, your photograph, your voice audio recording or your video image, your title, your company, and contact information such as your physical address, email address and phone number;
- username, password, and other registration information;
- transaction-related information;
- information you provide when you are visiting our offices
- information you provide when submitting a support request;
- information you provide when submitting a job application;
- information you provide when you make a request or otherwise contact us;
- information about your business, business plans and other items or materials contained in your application for Pega Ventures and other partner programs; and
- any other information you choose to make public on the as part of the contractual or precontractual relationship or as related to the Services (e.g., information shared with other users on MyPega, Pega Community, www.pega.com, collaboration spaces or groups, and other online communities (collectively, “Online Communities”).
Please note that due to the current COVID 19 pandemic we may ask you, to the extent allowed by and in a form permitted by privacy laws, to provide your health information, including your exposure to COVID-19 infection, your recent travels, COVID – 19 related symptoms and temperature.
When you use a Service, we will collect and store information about your use of these Services, including contracts you negotiate and sign, RFPs and questionnaires you submit, Pega and partner and event sponsor events you attend, Pega communities in which you participate, courses you have registered for, courses you have completed, and certifications that you have received. You agree that Event sponsors (which category may include our Clients or partners) may use such information in accordance with their own privacy policies, and that Pega is not responsible for the privacy practices of its sponsors.
2. Automated Interactions
Service, and the search terms you enter on the Service. This information allows us to recognize you and personalize your experience if you return to a Service, to improve the Services and the products and services we provide, and to provide you with advertisements targeted to your interests (commonly referred to as “Targeted Advertisements”). We and our service providers may collect and store this information using “cookies,” which are small text files that many websites save on your computer when you visit and access when you return, or similar technologies such as web beacons or pixel tags. We use search terms only to provide relevant search results in the moment and do not store them for any future use.
We use the following types of cookies on our website:
- required cookies which are required to enable core site functionality and tailor future content through marketing efforts
- functional cookies which allow us to analyze site usage so we can measure and improve performance
- advertising cookies - used by advertising companies to serve ads that are relevant to your interests
We and our service providers also use Google Analytics, which collects and processes certain technical information from your computer or mobile device such as the web address of the page that you are visiting and your Internet Protocol address. More information can be found at “How Google uses data when you use our partners’ sites or apps,” located at https://www.google.com/policies/privacy/partners. To opt out from collection of your information via Google Analytics, please visit https://tools.google.com/dlpage/gaoptout?hl=en.
To customize your experience, our mobile applications may collect precise information about the location of your mobile device, but only with your express consent. Once you have consented to the collection of the precise location of your mobile device, you may adjust this consent by managing your location services preferences through the settings of your mobile device.
3. Publicly Available Data / Data from Third Parties
We may collect or receive business-related information about you from public sources and various third-parties, including providers of marketing lists. We may also obtain your business contact information from individuals at your organization. Information from public sources may include business contact data obtained from search information providers such as Google or social media such as LinkedIn. On occasion, we may purchase third-party marketing lists of business contact data to send direct marketing communications.
How do we use this information?
Personal data transferred to us by a Client (“Client Data”) will be processed in accordance with the Client’s instructions as set forth in our contract with that Client (“Client Agreement”), and as required by applicable law. Client may use our cloud service to: grant and remove access to a Client Application; assign roles and configure settings, access, modify, export, share and remove Client Data; and otherwise apply its policies to the Client Application. If your personal information is being processed as Client Data and you wish to exercise any rights you may have to access, correct, update, port or delete such personal information, please inquire directly with the Client.
We may process and use your personal data and other information that we collect or receive for a number of purposes as necessary to fulfill contractual obligations and other lawful bases, such as our legitimate interest in engaging in commerce, offering products and services, performing due diligence on Clients, prospects and business partners, preventing fraud, ensuring information and network security, conducting direct marketing and complying with industry practices, including:
- delivering and performing a Services;
- providing you with the products, pricing, services, or information you request;
- supporting your Client or partner relationship with us (e.g., notifying you of a product update or for billing, account management and other administrative matters);
- processing any transactions you have authorized;
- processing an employment application;
- verifying your identity;
- evaluating your application for Pega Ventures and other partner programs;
- providing you with information about a Service or required notices;
- delivering Targeted Advertisements and other marketing communications, promotional materials, or advertisements that may be of interest to you (e.g., if you view a webpage about a particular product or service, we or a service provider of ours may later display an advertisement for a related product or service on a different webpage that you visit through an Service or on another website that has a relationship with the service provider);
- allowing us to improve a Service and the products and services we provide, such as by better tailoring our content to users’ needs and interests;
- developing new products, facilitating product, software and applications development and conducting research, analysis, studies or surveys and identifying usage trends;
- generating and analyzing statistics about your use of a Service; and
We provide social computing tools on some of our websites to enable online sharing and collaboration among members who have registered to use them. These include forums, collaboration spaces or groups, wikis, blogs and other social media platforms. Information will be subject to and protected in accordance with this Privacy Notice, except for the information that is automatically made available to other participants as part of your profile or information you post on blogs and forums. When you participate in our online sharing and collaboration spaces or groups, you profile will be visible for all participants and may be added to a given collaboration space or group.
We may combine or aggregate any of the information we collect or receive through the Services or elsewhere (e.g., through telephone, email, interactions on social media, or personal contact with us or our employees, product registration, call centers, or public events such as trade shows or seminars) for the purposes listed above.
When you make a purchase using a credit card on the Services, your credit card information is transmitted directly to our third-party payment processor. We do not store your credit card information and the third-party payment processor does not share your credit card information with us.
If you submit an application for Pega Ventures or other partner programs, we may use your application and all information and materials included in your application for conducting due diligence, evaluating potential business transactions and tracking applicants, founders, investors and companies.
To the extent that our processing of your personal data is subject to the General Data Protection Regulation or other privacy laws which so allow, we may rely on the legal bases described above to process your personal data. We may also process your personal data for direct marketing purposes and for administration of contractual and precontractual relationships and you have a right to object to our use of your personal data for this purpose at any time.
If you believe our processing of your personal data is inconsistent with applicable data protection laws, you may lodge a complaint with your local supervisory data protection authority.
Under what circumstances do we disclose this information?
We may disclose the information we collect and receive about you to:
- our affiliates and subsidiaries worldwide for business purposes, including Client support, contractual and precontractual administration, marketing, technical operations and account management purposes;
- service providers and suppliers worldwide who work on our behalf and who have agreed to keep the information confidential and use the information solely to carry out the services that they are performing for us, including hosting, storage, data analysis, implementation, and assisting us with reviewing your application for Pega Ventures and other partner programs;
- third parties and partners worldwide for our marketing, advertising, events, promotions or other similar purposes, including event sponsors and third-party data enrichment providers, who help us keep your business contact information (e.g. name, title, company, work email address, etc.) complete, current and accurate;
- your employer if it is our Client or partner;
- other users of our Services, consistent with your privacy settings;
- as required by law, such as to comply with a subpoena or other legal process, a court order, requests from regulatory or tax authorities, or government reporting obligations;
- other third parties with your consent;
- service providers, advisors, and other third parties worldwide to the extent reasonably necessary to proceed with the negotiation or completion of a merger, acquisition, financing, public offering of securities, reorganization, or sale of all or a portion of our assets.
- In addition, we may share de-identified information, such as reports on user demographics and traffic patterns, with third parties. We will not sell information that can personally identify you to others and sharing with third parties is as set forth in this Privacy notice.
We may enable you to post information to certain parts of the Services, such as the Online Communities. Information you disclose through any Online Communities may be publicly available. We urge you to exercise discretion and caution when deciding to disclose personal information, or any other information, through any Online Community. By using any Service, you agree to adhere to all applicable copyright laws.
A Service also may contain links to third-party websites and applications for your convenience and information. We do not control those third-party websites and applications or their privacy practices, which may differ from our own. You acknowledge and agree that we are not responsible for the collection and use of your information by third-party websites and applications that are not under our control, and such information is not governed by this Privacy Notice.
How is your information secured?
We strive to maintain reasonable and appropriate administrative, technical, and physical safeguards designed to safeguard the information collected by the Services from loss, misuse, and unauthorized access, disclosure, alteration and destruction, taking into account the risks involved in the processing and the nature of the information. However, no information system can be 100% secure, so we cannot guarantee the absolute security of your information. Moreover, we are not responsible for the security of information you transmit to the Services over networks that we do not control, including the Internet and wireless networks.
Where is this information processed?
Information collected through the Services will be processed using resources and servers located in various countries around the world, including Australia, Brazil, Canada, United Kingdom, Germany, Netherlands, Poland, India, Ireland, Japan, Singapore and the United States. Therefore, your personal information may be transferred, processed and stored outside the country where your information was collected by using or attending a Service. By using a Service, you consent to such transfer to, and processing and storage in, the United States and other countries.
International Transfers from the European Economic Area
Your information may be transferred by us, our affiliates and/or third parties outside the country in which you are located, including the United States. Such countries may not offer the same level of protection as in other parts of the world in terms of data protection and privacy regulations. By providing us your information and confirming your consent, you agree to such transfer and/or processing. When we transfer your data outside of EEA, we will ensure that your data is transferred and processed securely in a manner which provides a degree of protection of your personal data similar to the EU. To achieve this (i) we put in place intercompany agreements incorporating Standard Contractual Clauses with our affiliates outside of the EEA, (ii) we rely on Standard Contractual Clauses with our third-party providers outside of the EEA, (iii) we also adopted certain supplementary measures such as encryption, data pseudonymization or sharing with protected recipient .We continue to comply with the EU-U.S. and the Swiss – U.S. Privacy Shield Frameworks (Privacy Shield) as set forth by the U.S. Department of Commerce, however we do not rely on this mechanism for transfer of EEA or Swiss data as it was deemed invalid by the Court of Justice of the European Union.
To learn more about the Privacy Shield program, and to learn more how we comply with the Privacy Shield Principles please visit our Privacy & Security page here: https://www.pega.com/privacy-and-security to view our EU-US and Swiss- US Privacy Shield notice and to view our certification, please visit https://www.privacyshield.gov/.
Controller of Data
Data protection laws in certain jurisdictions differentiate between the “controller” and “processor” of personal data. In general, our Clients are the controller of Client Data and we are the processor of Client Data. For other personal data, we may be the controller of such personal data. Different Pegasystems entities provide the Services in different parts of the world. For Client Data, the processor is the entity with which the Client has contracted to provide the Client Application. Our contact information for Clients is contained in the relevant Client Agreement. For other personal data, Pegasystems Inc. is the controller, if applicable, and you may contact us at firstname.lastname@example.org. With reference to personal data regulated by Turkish privacy law – Pegasystems Ltd is the controller and may be contacted at email@example.com.
We will retain Client Data in accordance with the applicable terms in the Client Agreement, and as required by applicable law. The Client may be able to customize its retention settings and apply those customized settings depending on the Pega product.
We may retain other personal data for as long as necessary for the purposes described in this Privacy Notice. This may include keeping your personal data after you have deactivated your Pega account for the period of time needed for us to pursue legitimate business, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
Your choices/Do Not Track
You have the ability to access your Pega account and modify your Pega account information online by visiting https://accounts.pega.com/user/login. By going to our Preference Center you may also (i) manage what types of email you receive from us, (ii) update your contact information, (iii) change how we process your information, including opt-out of sharing.
As you can control your preferences via the Preference Center, we will not respond to specific ‘Do Not Track’ requests.
If you reside in certain states or in certain countries, including within the European Union, you may have one or more of the following rights available to you under data protection laws in relation to your personal data: the right to access, update, correct, receive, port, object, delete or restrict processing of your personal data.
- Access – In certain jurisdictions, you have the right to request that we disclose certain information to you about our collection and use of your personal information. To request access your personal data that we have collected, used or disclosed please contact firstname.lastname@example.org, or in states where this information can be requested by phone, by calling 1-617-866-6800.
- Update or Correct – To update or correct your personal data, you can usually do this by updating your Pega account. If you already have a Pega account go to https://accounts.pega.com/user/login. If you want to create a Pega account, go to https://accounts.pega.com/register. Otherwise, please contact email@example.com.
- Port – To request a copy of your personal data that we have collected about you in a commonly used and machine-readable format, please contact firstname.lastname@example.org.
- Object – To object to processing of your personal data please contact email@example.com.
- Delete or Restrict Processing – To delete or change how we process your personal data for marketing purposes, please go to our Preference Center and follow the instructions. To request deletion of all your personal data from our databases please email firstname.lastname@example.org.
If your personal data is processed based on your consent, you may withdraw your consent at any time, without affecting the lawfulness of our processing based on such consent before it was withdrawn.
To exercise any of the above-listed rights (with the exception of the right to lodge a complaint with a DPA, which you may do directly to a DPA), please follow the instructions above or contact us at email@example.com. We will process any requests in accordance with applicable laws and within a reasonable period of time (e.g., 30 days for certain requests under the General Data Protection Regulation). We may need to verify your identity and place of residence before processing your request.
We may take reasonable steps to authenticate your request and request information to verify you identify, considering the context of your request and your reasonable expectations. We may also reject your requests where permitted or required to do so in accordance with applicable laws.
California Consumer Privacy Act (“CCPA”)
California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year.
Effective January 1, 2020, the California Consumer Privacy Act (CCPA) allows California residents, upon a verifiable consumer request, to request that a business that collects consumers’ personal information to give consumers access, in a portable and (if technically feasible) readily usable form, to the specific pieces and categories of personal information that the business has collected about the consumer, the categories of sources for that information, the business or commercial purposes for collecting the information, and the categories of third parties with which the information was shared. California residents also have the right to submit a request for deletion of information under certain circumstances. Consistent with California law, if you choose to exercise your rights, we won’t charge you different prices or provide different quality of services unless those differences are related to your information.
We do not and will not sell your personal information to third parties. We do not and will not sell the personal information of minors (see “Children’s’ information” below). We describe how we use and share your information in section “How do we use your information”. We describe how we use search terms you enter on the Service in section “Automated Interactions."
You or your authorized agent as defined under CCPA Section 999.326 (with proof that such agent has been authorized on your behalf) can exercise your rights related to the use, transfer and sharing of your data under CCPA using contact information given in section “Your rights”.
The Services are not directed to, nor do we knowingly collect information from, children under the age of 16. If you become aware that your child or any child under your care has provided us with information without your consent, please contact us at the contact information listed below.
Changes to this Privacy Notice
If we update this Privacy Notice, we will notify you by posting a new Privacy Notice on this page and updating the revision date below. If we make any revisions that materially change the ways in which we use or disclose the information previously collected from you through a Service, we will give you the opportunity to consent to such changes before applying them to that previously collected information.
If you have any questions about this Privacy Notice or our use of your information collected through the Services, please contact firstname.lastname@example.org. Our address is Pegasystems Inc., One Rogers Street, Cambridge, MA 02142 Attn: Chief Compliance Officer.
We also provide you with the additional country – dedicated contacts:
- Brazil – Roberto Paes, Chief of Data Treatment for Brazil, Pegasystems Serviços de Software do Brasil Ltda email: email@example.com
- Singapore – please contact our Data Protection Officer for Singapore at SGDPO@pega.com
- Turkey – Pegasystems Bilgi Teknolojileri Anonim Şirketi, Palmiye Cad. B39A No:20, Göksu Evleri Anadolu, Hisarı Beykoz, Istanbul 34815, email: firstname.lastname@example.org
Revision date: December 17, 2020