Building Robotics 'Comfy' Privacy Policy

Effective Date: October 11, 2018

Building Robotics Privacy Policy

Welcome, and thank you for your interest in Comfy, a product of Building Robotics, Inc. (“Building Robotics”,“we,” or “us”). We provide a service through our website at www.comfyapp.com (the “Site”), and through related websites, networks, embeddable widgets, downloadable software, mobile applications, tablet applications, web applications, and other online and offline services provided by us (collectively, together with the Site, our “Service”). The Service is enabled when we have entered into an agreement with the owner, operator, tenant, or your employer (our “Customer”) to provide the Service in your workspace (the “Building(s)”).

This Privacy Policy (this “Policy”) describes the information that we gather from you on the Service, how we use and disclose such information, and the steps we take to protect such information. This Policy also describes our practices related to information of individuals with whom we communicate for marketing or promotional purposes but who may not otherwise be users of the Service (the “Marketing Recipients”). By using the Service, or by agreeing to this Policy as a Marketing Recipient, you consent to the privacy practices described in this Policy.  And, importantly, if you are a user of the Service, you consent to our Customer’s use of your Personal Data (as defined below) as described in this Policy.

The Personal Data we Collect on the Service from Users of the Service

In connection with the Service, we collect the information described below, which may, on its own, or when combined with other information be used to identify you individually (“Personal Data”):

  • User-provided Information. To sign up for the Service, we ask you to provide your name and your email address. In addition, you may choose to disclose additional Personal Data which may be used to identify you when you use the Service or send us customer service-related requests. Additionally, as you use the Service, we may collect information about your workspace preferences based on the features that are available to you and used by you, such as your requests over time for a warmer or cooler workspace, the patterns of use of the Service (such as meeting rooms that you book through the Service), as well as the location information that you may provide us when you use the Service (for example, by indicating where in the Building you are located when you want to warm or cool your space).
     
  • “Cookies" Information. When you first access the Site or Service, you may receive a message advising you that cookies and similar technologies are in use. By clicking "accept", closing the message, or continuing to browse or use the Site or Service, you signify that you understand and agree to the use of these technologies, as described in this Privacy Policy. When you use the Site or Service, we may send one or more cookies – small text files containing a string of alphanumeric characters – to your device. We may use both session cookies and persistent cookies. A session cookie disappears after you close your browser. A persistent cookie remains after you close your browser and may be used by your browser on subsequent visits to the Service. We use these cookies for the purpose of better understanding how visitors interact and engage with the Site, and in some cases we may use this information to inform our communications with you. Please review your web browser settings to learn the proper way to modify your cookie settings, to disable the use of cookies, or to delete cookies. Please note that if you delete, or choose not to accept, cookies from the Service, you may not be able to utilize the features of the Service to their fullest potential. In addition, please note that third parties such as advertisers or analytics providers may also use cookies and similar technologies while you are browsing or using the Service. We unfortunately have no control over such third parties’ use of these technologies.
     
  • Location Information.  By using the Service, you consent to our automatic collection of your location information. However, you may be able to disable such collection in the settings on your device.  When you use the Service, we may automatically record your location information from your device by using various types of technology, including “clear gifs" or “web beacons” or APIs. This “automatically collected" information may include your IP address or other device address or ID. Some aspects of the mobile applications that are provided as part of the Service may not function if you do not permit them to use your location information because they can be used to collect information regarding whether you are in one of the Building with which your account is associated regardless of whether or not the application appears to be running.
     
  • Other “Automatically Collected" Information. We may also use various types of technology to automatically collect information about your web browser and/or device type, the web pages or sites that you visit just before or just after you use the Service, the pages or other content you view or otherwise interact with on the Service, and the dates and times that you visit, access, or use the Service. We also may use these technologies to collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message.
     
  • Integrated Services. You may be given the option to access or register for the Service through the use of your user name and passwords for certain services provided by third parties (each, an “Integrated Service”), such as through the use of your Google credentials, or otherwise have the option to authorize an Integrated Service to provide Personal Data or other information to us. By authorizing us to connect with an Integrated Service, you authorize us to access and store your Personal Data that the Integrated Service makes available to us, including your name and email address, and to use and disclose such information in accordance with this Policy. You should check your privacy settings on each Integrated Service to understand and change the information sent to us through each Integrated Service. Please review each Integrated Service’s terms and privacy policies carefully before using their services and connecting to our Service.
     
  • Information from Our Customer. We may obtain information, including Personal Data, from our Customer. If we combine or associate information from other sources with Personal Data that we collect through the Service, we will treat the combined information as Personal Data in accordance with this Policy.

The Personal Data we Colled from Marketing Recipients

In addition to the Personal Data we collect from users of the Service, we collect Personal Data from Marketing Recipients who are interested in learning more about our products and services. This Personal Data consists of basic contact information such as the Marketing Recipient’s name and email address. This Personal Data is collected by us when Marketing Recipients sign up for commercial emails from us via online or offline sign up forms, and through other means such as in-person events and meetings and from the internet.

How we use the Personal Data we Collect

  • To Provide the Service. We use Personal Data we collect on the Service to provide the core functionality of the Service to users and our Customers, including the following uses:
    • We use the Personal Data that we collect on the Service to operate, maintain, enhance and provide all features of the Service to you and our Customer, to provide services and information that you request, to respond to comments and questions and otherwise to provide customer support to users and our Customer, and to process and deliver entries and rewards in connection with promotions that may be offered from time to time on the Service.
       
  • To Improve our Business. We also use Personal Data we collect on the Service to improve the Service for the broad base of users and Customers of the Service, including the following uses:
    • We use the Personal Data that we collect on the Service to understand and analyze the usage trends and preferences of our broad base of users, to improve the Service and develop new products, services, features, and functionality, and to monitor and analyze the effectiveness of the Service and our marketing activities. In some cases Personal Data may be aggregated and/or anonymized to improve the Service, while in some cases the Personal Data may not be aggregated or anonymized for such purpose.
  • To Market our Business
    • We may use your Personal Data to send communications, including updates on promotions and events, relating to products and services offered by us and by third parties we work with that are related to the Service. Generally, you have the ability to opt-out of receiving any promotional communications as described below under “Your Choices.” For Marketing Recipients who are not otherwise users of the Service, we only use your Personal Data for the purposes described in this paragraph.

When we Disclose Personal Data and Similar Information

Except as described in this Policy, we will not disclose our Personal Data that we collect on the Service to third parties without your consent. By using the Service, you consent to the following disclosure of your Personal Data:

  • At the direction of our Customer, we disclose the Personal Data described above to our Customer so that our Customer can understand how users in the Building(s) use and interact with the Service and to understand the effectiveness of the Service. Sometimes this information is provided to our Customer in aggregated and/or anonymized form, but sometimes it may not be aggregated or anonymized. For example, we will disclose analytics of users in the Building to our Customer so that they can have insights into the number of users using the Service, how users use the Service (such as heating and cooling requests and the location and time of such requests, as well as requests for users to book meeting rooms), how the Service results in energy savings for the Building, and other similar usage data, trends, and statistics. And, again, this info may be presented in aggregated and/or anonymized form or may not be aggregated or anonymized.
     
  • We work with third party service providers to provide website, application development, hosting, maintenance, data processing, marketing, and other services for us. These third parties may have access to or process your Personal Data as part of providing those services for us. However, we limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions.  In addition, they generally agree to maintain the confidentiality of such information.
     
  • We may make certain automatically-collected, aggregated, or anonymized information (i.e. non-Personal Data) available to third parties for various purposes, including (i) compliance with various reporting obligations; (ii) for business or marketing purposes; or (iii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Service.
     
  • We may disclose your Personal Data if required to do so by law or in the good-faith belief that such action is necessary to comply with state and federal laws (such as U.S. copyright law or applicable data protection laws), in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
     
  • We also reserve the right to disclose your Personal Data to the extent permitted by applicable data protection laws that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others.
     
  • To the extent permitted by applicable data protection laws, information about our users, including Personal Data, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.

Third-Party Services

The Service may contain features or links to websites and services provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Service. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

Children’s Privacy

Protecting the privacy of young children is especially important. Our Service is not directed to children under the age of 13, and we do not knowingly collect Personal Data from children under the age of 13 without obtaining parental consent. If you are under 13 years of age, then please do not use or access the Service at any time or in any manner. If we learn that Personal Data has been collected on the Service from persons under 13 years of age and without verifiable parental consent, then we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 13 years of age has obtained an account on the Service, then you may alert us at [email protected] and request that we delete that child’s Personal Data from our systems.

Data Security

We use reasonable and appropriate measures to help protect the integrity and security of Personal Data that we collect and maintain. We cannot, however, ensure or warrant the security of any Personal Data you transmit to us or store on the Service, and you do so at your own risk. We also cannot guarantee that such Personal Data may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.

If we learn of a security systems breach, then we may attempt to notify you electronically so that you can take appropriate protective steps. We may post a notice through the Service if a security breach occurs. Depending on where you live, you may have a legal right to receive notice of a security breach in writing. To receive a free written notice of a security breach you should notify us at [email protected].

Privacy Settings

Although we may allow you to adjust your privacy settings to limit access to certain Personal Data, please be aware that no security measures are perfect or impenetrable. We are not responsible for circumvention of any privacy settings or security measures on the Service. Additionally, we cannot control the actions of other users with whom you may choose to share your information. Further, even after information posted on the Service is removed, caching and archiving services may have saved that information, and other users or third parties may have copied or stored the information available on the Service. We cannot and do not guarantee that information you post on or transmit to the Service will not be viewed by unauthorized persons.

Our Compliance with Data Laws for International Users

In May 2018, a new data privacy law known as the EU General Data Protection Regulation (the "GDPR") becomes effective. The GDPR requires that we and our Customers provide users with more information about the processing of your Personal Data. Here is what you need to know:

Legal Ground for Processing your Personal Data

The GDPR requires us to tell you about the legal grounds we're relying on to process any Personal Data about you. The legal grounds for our processing, and our Customer’s processing, of your Personal Data for the purposes above are:

  • first and foremost, you provided your consent by agreeing to this Policy, which you may withdraw at any time by emailing us at [email protected];
  • it is necessary for our contractual relationship;
  • the processing is necessary for us to comply with our legal or regulatory obligations; and/or
  • the processing is in our legitimate interest as a provider of the Services (for example, to protect the security and integrity of our systems and to provide you with customer service, etc.).

Data Transfers

The Service is hosted in the United States and is intended for visitors located within the United States as well as users located outside of the United States. If you choose to use the Service from the European Economic Area, Switzerland, or the United Kingdom or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your Personal Data outside of those regions to the United States for storage and processing. By providing any information, including Personal Data, on or to the Service, you consent to such transfer, storage, and processing.

Building Robotics participates in, and complies with, the EU-US Privacy Shield Principles and the Swiss-US Privacy Shield Principles (collectively “Privacy Shield” or “Privacy Shield Principles”) regarding the collection, use, sharing, and retention of Personal Data from the European Economic Area, Switzerland, or the United Kingdom. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. Our participation in Privacy Shield applies to all Personal Data that is subject to this Policy and is received from the European Economic Area, Switzerland, or the United Kingdom. We will comply with the Privacy Shield Principles in respect of such Personal Data.

To learn more about Privacy Shield, please click here. To view the current Privacy Shield certifications for Comfy (by Building Robotics), please click here. If you have a Privacy Shield-related question or complaint, please contact us at [email protected].

As part of our participation in Privacy Shield, if you have a dispute with us about our adherence to the Privacy Shield Principles, we will seek to resolve it through JAMS, an independent alternative dispute resolution body based in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint.  The services of JAMS are provided at no cost to you.

In certain circumstances, you may have the right to invoke binding arbitration under Privacy Shield, as described in Annex I to the Privacy Shield Principles, which can be found at the following URL: https://www.privacyshield.gov/article?id=ANNEX-I-introduction.

Privacy Shield participants, such as Building Robotics, are subject to the investigatory and enforcement powers of the US Federal Trade Commission and other authorized statutory bodies. Under certain circumstances, we may be liable for the transfer of Personal Data that we receive and subsequently transfers to a third party, as described in the Privacy Shield Principles.

As described in this Policy, we may share Personal Data with third parties and may be required to disclose information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. However, we will only transfer your Personal Data outside of the European Economic Area, Switzerland, or the UK, if there are appropriate technical and organisational measures in place to protect your Personal Data as required by GDPR.

Your Choices

If you wish to access, receive a copy of, change or delete the Personal Data we hold about you, you may contact us at [email protected]. In addition, we encourage you to contact our Customer to access, receive a copy of, change or delete the Personal Data and we agree to work with our Customer in good faith to assist with your request.

You may withdraw the consent granted in this Policy for us or our Customers to use the Personal Data described in this Policy by contacting us at [email protected]. Please note that if you do so, it will not affect the lawfulness of the use of your Personal Data based on your prior consent.

In addition, you may contact us at [email protected] to request that we do not disclose your Personal Data to third parties (other than those that are acting as our agent to perform tasks on our behalf, such as data processors).

If you receive commercial email from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving commercial email from us, and any other promotional communications that we may send to you from time to time, by sending your request to us by email at [email protected] or by writing to us at the address given at the end of this Policy. Please be aware that if you opt-out of receiving commercial email from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten business days for us to process your request, and you may receive promotional communications from us that you have opted-out from during that period. Additionally, even after you opt-out from receiving commercial messages from us, you will continue to receive administrative messages from us regarding the Service.

Upon receipt of any of the above request(s), we will use reasonable efforts to reflect any changes you request in our databases to the full extent required by GDPR, Privacy Shield, or other applicable law.

If you are not happy with how we have attempted to resolve your complaint, you may contact the relevant data protection authority.

Data Retention

Subject to our obligations contained in the section above titled “Your Choices”, and unless a different retention period is required by law or by agreement with our Customer, we will retain the Personal Data of users of the Service until the first to occur of the following: five (5) years from the date of collection of such Personal Data, the date on which our contractual relationship with our Customer terminates, or ninety (90) days following the date on which we become aware that you are no longer an active user of the Service. At such time, we will delete your Personal Data.

For Marketing Recipients, we will retain your Personal Data until you request that we delete such Personal Data as described in the section above titled “Your Choices”.

We may retain other information that is not Personal Data (such as anonymized and/or aggregated data) for backups, archiving, prevention of fraud and abuse, analytics, to improve our service, or where we otherwise reasonably believe that we have a legitimate reason to do so.

Your Right to File a Complaint

If you are not happy with how we handle your Personal Data, we encourage you to contact us at [email protected]. But you also have the right to lodge a complaint with the relevant data protection authority.

Changes and Updates to this Policy

Please revisit this page periodically to stay aware of any changes to this Policy, which we may update from time to time. If we modify this Policy, we will make it available through the Service, and indicate the date of the latest revision. In the event that the modifications materially alter your rights or obligations hereunder, we will use reasonable efforts to notify you of the change and will obtain new consent from you to the extent required by GDPR or other applicable laws. For example, we may send a message to your email address, if we have one on file, or generate a pop-up or similar notification when you access the Service for the first time after such material changes are made. Your continued use of the Service after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of this Policy.

Our Contact Information

Please contact us with any questions or comments about this Policy, your Personal Data, our use and disclosure practices, or your consent choices by email at [email protected].

Building Robotics, Inc.
1504 Franklin St., Suite 200
Oakland, CA 94612

Data Protection Officer

In addition, we have appointed a Data Protection Officer (“DPO”). Our DPO can be contacted directly by email at [email protected] or by mail at:

Building Robotics, Inc.
ATTN: Data Protection Officer
1504 Franklin St., Suite 200
Oakland, CA 94612