Privacy Policy
This Privacy Policy describes the personal information that is collected by Executive Advisors Group, LLC and its application ProcedureWorks (hereafter "ProcedureWorks"), the technologies that are used, your specific privacy rights regarding the use of ProcedureWorks, and how to contact ProcedureWorks for more information or to exercise your privacy rights.
Effective as of 1/1/2020. Last updated 3/2/2022.
About This Policy
ProcedureWorks is an application that helps organizations to document procedures, controls, policies, and risks with support to manage each. The content that is created within ProcedureWorks is owned by the Subscriber Tenant or subscribing entity. Subscribers who use ProcedureWorks may upload their own information such as policies and other documents, create their own procedures and risk assessments using ProcedureWorks, or import representative samples of risk assessments, controls, policies, or procedures from the manager instance of ProcedureWorks. None of this documentation contains personal information unless it is added by the ProcedureWorks subscriber tenant. Subscriber tenants also create named users within the application and may add or remove named users based on their subscription to ProcedureWorks.
This Privacy Policy describes how ProcedureWorks treats the Personal Information we collect or receive from subscriber tenants. This Policy also contains information about the rights you may have over your Personal Information, typically associated with your named account within ProcedureWorks.
If you maintain an account with ProcedureWorks, you agree to the terms of this Privacy Policy by continuing to use ProcedureWorks. If you do not agree, please see information about your rights below or refrain from using our Programs or interacting with us.
Information Collection, Use, and Disclosure
We collect and receive information that identifies, describes, or is reasonably capable of being associated with you ("Personal Information"). Personal Information does not include information that is publicly available in government records or any data that has been deidentified, aggregated, or otherwise anonymized.
Information provided to ProcedureWorks is used to establish an account for the application and includes user names (e.g., an email address), passwords, and security questions to verify the identities of named users using a subscriber tenant instance of ProcedureWorks. Additional detail may be collected by the subscriber tenant instance of ProcedureWorks including your first and last name, phone number, reporting relationships within the subscriber tenant organization, and other detail related to the subscriber tenant's instance of ProcedureWorks. ProcedureWorks may also collect details related to your network activity including internet protocol (IP) address, browser information, and interaction with the ProcedureWorks application. Please reference the Cookie Policy below for additional information.
Subscriber tenants function as a controller over the personal information that is collected and ProcedureWorks serves as a processor with respect to Personal Information. ProcedureWorks does not and will not sell your Personal Information to third parties.
We do not disclose this information to third parties unless those parties have a legal basis or permissible purpose to obtain your Personal Information.
Other Disclosures
Nothing in this Policy restricts ProcedureWorks' ability to collect, process, or disclose Personal Information to:
- Comply with applicable laws or regulations.
- Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or other lawful court order.
- Investigate and prevent fraud or abuse.
- Cooperate with law enforcement, government authorities, or regulatory agencies concerning conduct we reasonably and in good faith believe may violate the law.
- Exercise and/or defend legal actions or claims.
ProcedureWorks may share your information with a successor to all or part of our business, as permitted by law. In the event or a merger, acquisition, reorganization, or similar transaction, or in the event of insolvency or bankruptcy, we may sell, transfer, or otherwise share some or all of our assets, including your personal information.
Security
ProcedureWorks employs reasonable security protections to protect the information within the application. These reasonable security protections include a mix of administrative, technical, and physical safeguards and are updated and assessed from time-to-time based on different factors including new risks, changing regulations, or other considerations. Information that is stored in ProcedureWorks is stored in the U.S. within a public-cloud infrastructure as a service (IaaS) provider that provides hosting services for the ProcedureWorks application. This provider has been reviewed for its security and privacy practices as well as ProcedureWorks' use of their services. Data loaded to ProcedureWorks is protected in transit via HTTPS. All information, including business contact information and personal information loaded to ProcedureWorks is processed and stored within the United States.
Even with the reasonable security procedures established, ProcedureWorks cannot guarantee that information will be completely secure. Subscriber tenants should maintain separate, secure copies of the information that is uploaded into ProcedureWorks. Tenants are also encouraged to use complex passwords, use multi-factor authentication (MFA), log out of sessions when work within ProcedureWorks is completed, delete unneeded browser history, and use reputable endpoint protection and anti-malware software on your devices.
Cookie Policy
ProcedureWorks uses cookies and similar technologies to provide, customize, evaluate, improve, and protect our Programs.
About Cookies
A Cookie is a small piece of text that is placed on your website browser, device, or hard drive when you visit a website or use an application such as ProcedureWorks. Cookiepedia provides details related to Cookies and how they are generally used and their functionality.
ProcedureWorks uses cookies for the following purposes:
- Functional Cookies. These Cookies help us identify trusted web traffic and control data collection when there is high traffic on our site.
- Performance and Analytics. These Cookies help us analyze how you interact with ProcedureWorks. For example, we may use analytics software to monitor and improve our site performance, services, and your experience.
How to Manage Cookies
If you wish to prevent cookies from tracking your activity on ProcedureWorks or visits across multiple websites, you can set your browser to block certain cookies or notify you when a cookie is set. If you block cookies, certain features on ProcedureWorks may not work. For more information on how you can customize your browser's cookie setting please visit the websites for each browser noted below:
You may opt-out of interest-based advertising in general by visiting the Digital Advertising Alliance's or Network Advertising Initiative's websites. We are not responsible for the completeness, effectiveness, or accuracy of any third party opt-out options or programs.
Do Not Track
ProcedureWorks may collect information about your website usage and activity. Some Internet browsers enable "Do Not Track" requests to block your activity from being tracked across web pages and devices. You can adjust your Do Not Track setting by visiting the link to your web browser below:
Your Rights
Controlling Your Account
If you would like to correct, update, or amend the information in your account, you may login and update your profile or contact your employer to update your information within your employer's subscriber tenant instance of ProcedureWorks.
Opt-Out Requests
Under certain circumstances, you may also request to opt-out of ProcedureWorks or that we deactivate or delete your account. To do so please contact us at admin@procedureworks.com and provide a brief description of your request. Upon receiving such a request, we will disable your account and forward your request to your Employer or subscriber tenant for consideration. If you opt-out, this may impact your ability to access ProcedureWorks and the information you may have uploaded to your tenant instance of ProcedureWorks.
California Privacy Rights
California residents may have additional rights over their Personal Information.
Request for More Information
You may have the right to request more information about how we treated your Personal Information in the past 12 months, including:
- The categories of Personal Information we collected about you;
- The categories of sources from which we collected that information;
- Our business or commercial purpose for collecting that information;
- The categories of third parties with whom we shared that information; and/or
- The specific pieces of Personal Information we collected about you.
Request to Access Information
You also may have the right to request access to your Personal Information.
Request for Deletion
Under certain conditions, you may have the right to request that we delete your Personal Information. Logging out does not delete your account or the Personal Information we may have collected.
Third-Party Marketing or Selling
We do not provide your information to third parties for their direct marketing purposes, and we do not intend to sell your Personal Information to third parties without providing you notice and an opportunity to opt-out.
How to Exercise Your Rights
To submit a request to exercise these rights you may contact us by emailing us at admin@procedureworks.com.
Verification
Before we can respond to your request, we must verify your identity using Personal Information. If we are not able to verify your request, we will contact you for more information. If we are unable to verify your identify after a good faith attempt, we may deny the request and, if so, will explain the basis for the denial.
Designating an Authorized Agent
You may designate someone to submit requests and act on your behalf (an "Authorized Agent"). To do so, you must provide us with written permission to allow your Authorized Agent to act on your behalf.
No Discrimination
We will not unlawfully discriminate against you for exercising any of these rights.
Information Regarding Children
ProcedureWorks is a business application and is not intended to be used by minors or children, nor do we intentionally gather Personal Information about users who we actually know are under the age of 13. If ProcedureWorks becomes aware of Personal Information collected from individuals under the age of 13, ProcedureWorks will use reasonable efforts to delete the Personal Information associated with that individual.
Changes to This Policy
ProcedureWorks reserves the right to amend the terms of this Privacy Policy. If ProcedureWorks makes any material changes to this Policy or decides to use Personal Information in a manner that is materially different from the uses described in this Policy, we will use reasonable means necessary to notify you.
Contact Us
If you have any questions about this Privacy Policy, please contact us at admin@procedureworks.com and provide a brief description about your questions, concerns, or comments.