The Right Five LLC (“The Right Five” or “we” or “us” or “our”) is committed to protecting and respecting your privacy. With this policy, we set out your privacy rights and how we collect, use, disclose, transfer, and store your personal data.
When we say, “The Right Five”, “we”, “our”, or “us”, we mean The Right Five LLC, 485 South Logan Street Apt 6, Denver CO 80209, which is the entity responsible for handling and processing your personal data.
When we say “Website” or “Platform”, we mean all of The Right Five’s Website and applications.
General Data Protection Regulation (GDPR):
The Right Five is a US based company that has international operations and reach. As such, we do comply with The General Data Protection Regulation (GDPR) wherever and whenever such compliance is required including: gathering consent from data subjects; disclosing why information is collected and how it is used; and keeping the data secure.
California Privacy Rights Act (CPRA):
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about the Personally Identifying Information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of the Personally Identifying Information that was shared and the names and addresses of all third parties with which we shared Personally Identifying Information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to our privacy officer, contact details are provided in Section 18.
Our platform contains links to other Websites, but that doesn’t mean we advocate or represent those Websites. We encourage you to review the respective privacy policies for these third-party Websites because their procedures for collecting, handling, and processing personal data may be different to ours.
2. COLLECTION OF PERSONAL DATA – GENERAL NOTICE
Collection and use of Personal Data:
During the course of our interactions, we may collect or obtain Personal Data about you: directly from you (e.g., where you contact us); in the course of our relationship with you (e.g., if you enter into a business arrangement with us); when you visit our Website; when you register to use our Website, or services; or when you interact with any third-party content. We may also receive Personal Data about you from third parties (e.g., a government agency).
We may collect Personal Data about you from the following sources:
- Data you provide: We may obtain your Personal Data when you provide it to us (e.g., where you contact us via email or telephone).
- Relationship data: We may collect or obtain your Personal Data in the ordinary course of our relationship with you (e.g., we provide a service to you, or to your employer).
- Registration details: We may collect or obtain your Personal Data when you use, or register to use, any of our Website or services.
Wherever required, we will provide an individual opt-out choice, or opt-in for Sensitive Personal Data, before we share your data with third parties, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, please submit a written request to: support@TheRightFive.com.
In certain situations, we may be required to disclose personal data in response to lawful requests by federal government agencies or public authorities, including to meet national security or law enforcement requirements.
3. COLLECTION, USE AND DISCLOSURE OF PERSONALLY IDENTIFYING INFORMATION
“Personally Identifying Information” is information that can be directly associated with a specific person and is one part of Personal Data (refer also to Section 4.). The Right Five may collect a range of Personally Identifying Information from and about Platform users. Much of the Personally Identifying Information collected by us about users is information provided by users themselves when:
- registering on the Platform as a customer;
- registering on the Platform as an applicant to take a specific customer assessment;
- signing up to receive free newsletters and other such content.
That information may include each user’s name, address, email address and telephone number, and, for customers, financial information such as your payment method (valid credit card number, type, expiration date or other financial information). We also may request information about your location and other demographic or relevant information as determined by The Right Five from time to time.
Users of the Platform are under no obligation to provide The Right Five with Personally Identifying Information of any kind, with the caveat that a user’s refusal to do so may prevent the user from using certain Platform features.
4. COLLECTION, USE AND DISCLOSURE OF NON-PERSONALLY IDENTIFYING INFORMATION
“Non-Personally Identifying Information” is information that, without the aid of additional information, cannot be directly associated with a specific person and is one part of Personal Data (refer also to Section 3.). “Personally Identifying Information”, as described in Section 3, by contrast, is information such as a name or email address that can be directly associated with a specific person.
The Right Five gathers from users of our Platform Non-Personally Identifying Information of the sort that Web browsers, depending on their settings, may make available. That information can include: the user’s Internet Protocol (IP) address; operating system; browser type; and the locations of the Websites the user views right before arriving at, while navigating and immediately after leaving the Platform.
Although such information is not Personally Identifying Information, it may be possible for The Right Five to determine from an IP address a user’s Internet service provider and the geographic location of the visitor’s point of connectivity as well as other statistical usage data. The Right Five analyzes Non-Personally Identifying Information gathered from users of the Platform to help The Right Five better understand how the Platform is being used. By identifying patterns and trends in usage, The Right Five is able to better design the Platform to improve users’ experiences, both in terms of content and ease of use.
From time to time, The Right Five may also release the Non-Personally Identifying Information gathered from Platform users in the aggregate, such as by publishing a report on trends in the usage of the Platform.
5. CREATION OF PERSONAL DATA
We may create Personal Data about you, such as records of your interactions with us, our Website, our Platform, our clients, or our authorized personnel.
6. CATEGORIES OF PERSONAL DATA WE MAY PROCESS
Through interaction with our Website and Platform, we may Process: your personal details (e.g., your name, and other biographical information); demographic data; your contact details; records of your consents; payment details; information about our Website (e.g., the type of device you are using); details of your employer (where relevant); information about your interactions with our content; and any views or opinions you provide to us.
Such personal data about you could include:
- Personal details: family and birth name(s); preferred name; previous name; preferred username(s); greeting name; and photograph (if provided).
- Demographic information: date of birth; salutation; title; any language preferences.
- Contact details: address; telephone number; email address; and details of your public business networking profile(s) or online biographies.
- Professional and commercial data: professional biography; other Profiling information pertaining to your experience and expertise, vocational and non-vocational; payment information.
- Employer information: name, address, telephone number and email address of your employer, to the extent relevant.
- Consent records: records of any consents you may give, including date and time, means of consent and any related information (e.g., the purpose of the consent).
- Other assorted views and opinions: any views and opinions that you may choose to send to us.
7. LEGAL BASIS FOR PROCESSING PERSONAL DATA
- Consent: where we have obtained your prior, express consent to such processing only used in relation to the Purpose and it is given entirely voluntarily when using the Website and the Platform;
- Contractual necessity: where it is necessary in connection with any contract that you may enter into with us either directly as a client of The Right Five or indirectly as an Applicant or other user of the Platform;
- Compliance with applicable law: where such processing is required by applicable law or an instruction of a government agency legitimately operating and fulfilling its duty under the applicable law;
- Vital interests: where it is necessary to protect the vital interests of any individual; or
8. SENSITIVE PERSONAL DATA
If you provide Sensitive Personal Data to us, it is your responsibility to ensure that it is lawful for you to disclose such data to us, including compliance with the criteria and reasons set out below. In the ordinary course of our business, we do not set out to collect or Process Sensitive Personal Data. Where it is required to Process your Sensitive Personal Data, we rely on the following legitimate grounds:
- Compliance with applicable law: where it is required and permitted by applicable law;
- Detection and prevention of illegal activity: where it is necessary for the detection or prevention of illegal activity including the prevention of fraud;
- Establishment, exercise or defense of legal rights where it is necessary for such; or
- Consent: where we have, in accordance with applicable law, obtained your prior, express consent prior to processing your Sensitive Personal Data.
9. PURPOSES FOR WHICH WE MAY PROCESS YOUR PERSONAL DATA
We may Process your Personal Data, subject to applicable law, for the following purposes:
- Our Website: operating and managing our Website; providing content to you; displaying any other information to you; communicating and interacting with you via our Website; and notifying you of changes to any of our Website, or our services.
- Our Platform: operating and managing our Platform; providing content to you; displaying any other information to you; communicating and interacting with you via our Website; and notifying you of changes to any of our Platform, or our services.
- Provision of services: including our Website and Platform related services; providing bespoke services; and communicating with you in relation to those services.
- Communications: communicating with you via any means (including via email, telephone, text message, social media, post or in person) information in which you may be interested (e.g., The Right Five events or campaigns, Blogs; new product offerings, information relevant to you as a client of The Right Five), subject to ensuring that such communications are provided to you in compliance with applicable law; maintaining and updating your contact information where appropriate; and obtaining your prior, opt-in consent where required.
- Communications and IT operations: management of our IT and other communications systems; IT security systems; and IT security audits.
- Commercial management: sales; marketing; product development; finance; contracts; corporate audit; and vendor management.
- Feedback: engaging with you when receiving or obtaining your views and comments on our blogs and services.
- Electronic security: login records; access to and use of our Platform; permissions; and access details.
- Third-Party Processors: payment services providers; development partners; cloud service providers; investment partners.
- Legal investigations: detecting, investigating and preventing breaches, fraud, and infringements of law, in accordance with applicable law.
- Legal proceedings: establishing, exercising and defending legal rights.
- Legal compliance: compliance with our legal and regulatory obligations under applicable law.
- Improving our Website, Platform and services: identifying issues with our Website, Platform or our services; planning improvements to our Website, Platform or our services; and creating new Websites, Platforms or services.
10. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
When we believe disclosure is appropriate, we may disclose your Personal Data to third parties: legal and regulatory authorities to protect rights; our external advisors and investors; any party or government agency as required in connection with legal proceedings; any party as necessary for investigating, detecting or preventing illegal activities; any acquirer of our business; and any third-party providers of advertising, plugins or content used on our Website.
For legitimate business purposes, including operating our Website, Platform and providing those services to you, in accordance with applicable law, we may disclose your Personal Data to:
- You and, where applicable, your appointed delegates and agents;
- Any relevant party, law enforcement agency or court, to the extent necessary to protect and defend the rights, property or safety of The Right Five, our users, our employees or others;
- Any relevant party, law enforcement agency or court, to the extent necessary for the establishment, exercise or defense of our legal rights to and to defend legal claims against us. In such cases, we reserve the right to raise or waive any legal objection or right available to us;
- Accountants, auditors, lawyers and other outside professional consultants to The Right Five, subject to binding contractual obligations of confidentiality;
- Third party Processors (such as payment services providers, development partners, cloud service providers, investment partners etc.), located anywhere in the world, subject to the requirements noted below in this Section 10¹;
- Any relevant party for the purposes of prevention, investigation, detection or prosecution of illegal activity, suspected fraud or other wrongdoing or the execution of court orders and rulings;
- Legal and government appointed regulatory authorities and agencies, upon request, or for the purposes of reporting any actual or suspected breach of applicable law or regulations;
Any relevant party, law enforcement agency or court in response to a subpoena or similar investigative demand, a court order or a request for cooperation from a law enforcement or other government agency;
- Any relevant party if we believe disclosure is necessary and appropriate to prevent physical, financial, or other harm, injury, or loss;
- Any relevant third-party acquirers, in the event that we sell or transfer all or any relevant portion of our business or assets including in the event of reorganization, dissolution or liquidation²;
- Third-Party Service Providers, that are authorized, to perform certain services on our behalf. These services may include fulfilling orders, providing customer service and marketing assistance, performing business and sales analysis, and supporting the Platform’s functionality.
¹ If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: only Process the Personal Data in accordance with our prior written instructions; and use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under applicable law.
For clarification: the results of an applicant’s assessment and their Personal Data will only be disclosed to the customer or client for whom they completed the assessment using the Platform. In the eventuality that an applicant wants to apply for a role with multiple of our customers or clients, concurrently or otherwise, the applicant will need to register on the Platform separately for each customer or client and retake the assessment for each application they wish to make.
11. TRACKING CONCEPTS
We may Process your Personal Data in conjunction with the following tracking concepts and constructs which may, in some circumstances, be provided by third-party partners including:
A “Web Cookie” is a string of information which assigns to you a unique identification that a website stores on a user’s computer, and that the user’s browser provides to the website each time the user submits a query to the website.
As with other Non-Personally Identifying Information (refer to Section 4.) gathered from users of the Platform, The Right Five analyzes and discloses, in aggregated form, information gathered using Web Cookies, in order to help The Right Five, our partners, affiliates and other authorized third-parties to better understand how the Platform is being used.
THE RIGHT FIVE USERS WHO DO NOT WISH TO HAVE WEB COOKIES PLACED ON THEIR COMPUTERS SHOULD SET THEIR BROWSERS TO REFUSE WEB COOKIES BEFORE ACCESSING THE PLATFORM, WITH THE UNDERSTANDING THAT CERTAIN FEATURES OF THE PLATFORM MAY NOT FUNCTION PROPERLY WITHOUT THE AID OF WEB COOKIES. PLATFORM USERS WHO REFUSE WEB COOKIES ASSUME ALL RESPONSIBILITY FOR ANY RESULTING LOSS OF FUNCTIONALITY.
A “Web Beacon” is an object that is embedded in a web page or email that is usually invisible to the user and allows website operators to check whether a user has viewed a particular web page or an email.
The Right Five may use Web Beacons on the Platform and in emails to count and collate users who have visited particular pages, viewed emails and to deliver co-branded services.
Web Beacons are not used to access users’ Personally-Identifying Information (refer to Section 3.). They are a technique we may use to compile aggregated statistics about Platform usage. Web Beacons collect only a limited set of information, including a Web Cookie number, time and date of a page or email view and a description of the page or email on which the Web Beacon resides. You may not decline Web Beacons. However, they can be rendered ineffective by declining all Web Cookies or modifying your browser setting to notify you each time a Web Cookie is tendered, permitting you to accept or decline Web Cookies on an individual basis.
We may partner with selected third parties to allow tracking technology on the Platform, which will enable them to collect data about how you interact with the Platform and our services over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity.
Aggregated and Non-Personally Identifying Information:
We may share aggregated and Non-Personally Identifying Information (refer to Section 4.) we collect under any of the above circumstances. We may also share it with third-parties and our affiliate companies to develop and deliver targeted advertising on the Platform and on websites of third-parties. We may combine Non-Personally Identifying Information we collect with additional Non-Personally Identifying Information collected from other sources. We also may share aggregated information with third parties, including advisors, advertisers and investors, for the purpose of conducting general business analysis. For example, we may tell our advertisers the number of visitors to the Platform and the most popular features or services accessed. This information does not contain any Personally-Identifying Information (refer to Section 3.) and may be used to develop Platform content and services with the objective that you and other users will find interesting, and to target content and advertising.
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. Because there is not yet a common standard or understanding of how to interpret the DNT signal, the Website and Platform currently does not respond to DNT browser signals or mechanisms.
12. INTERNATIONAL TRANSFER OF PERSONAL DATA
In the operation and execution of our normal business, we may transfer your Personal Data to recipients in other countries. Where we transfer Personal Data that is in a different jurisdiction to your own, we will do so on the basis of binding contractual obligations of confidentiality.
13. DATA SECURITY
We take the security of your Personal Data seriously and have implemented a range of organizational and technical security measures designed to protect your Personal Data against accidental or unlawful destruction, loss, theft, alteration, misuse, unauthorized disclosure, unauthorized access, unauthorized use, and other unlawful or unauthorized forms of processing, in accordance with applicable law.
Because the internet is an open system with no single entity ownership or end-to-end control, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Although we will implement all reasonable measures to protect your Personal Data during transmission, we cannot guarantee the security of your Personal Data transmitted to us via the internet. For the avoidance of doubt, any such transmission of Personal Data is at your own risk, and you are responsible for ensuring that any Personal Data that you send to us is sent securely.
We have required any vendors with which we share your Personal Data to implement similar measures. However, please note that, while we strive to use commercially reasonable means to protect your Personal Data, we cannot guarantee its absolute security. In the event that The Right Five becomes aware of a data breach impacting your Personal Data, we will provide notification in compliance with all applicable laws.
14. DATA MANAGEMENT
We take every reasonable step to ensure that your Personal Data that we Process is accurate and, where necessary, kept up to date. If we discover that any of your Personal Data that we Process, consistent with the Purpose, is inaccurate, it will be erased or rectified without delay. From time to time we may ask you to confirm the accuracy of your Personal Data, both in terms of content, currentness and correctness.
- We will maintain copies of your Personal Data in a form that permits identification only for the period:
- We maintain an ongoing relationship with you, for example where you are a user of our services, or you are lawfully included in our mailing list and have not unsubscribed; or
- It is required to fulfil any legal or regulatory obligations placed on us by applicable legislation, regional legislatures, federal government agencies, or private legal actions, the duration of which adequately covers:
- Any applicable limitation period under applicable law, for example any period during which any person could bring a legal action against us in connection with your Personal Data, or to which your Personal Data may be relevant; and
- A reasonable period, not to exceed one year, following the end of such applicable limitation period so that, if a person brings an action at the end of the limitation period, we still have a reasonable amount of time in which to identify any Personal Data that is relevant to that claim, and;
- In addition, if any relevant legal claims are brought, we may continue to Process your Personal Data for such additional periods as are necessary in connection with that action.
During the periods defined and explained in this Section 14., we will restrict our processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal action, or any obligation under applicable law. Upon the conclusion or expiry of these periods, to the extent applicable, we will either: permanently delete or destroy the Relevant Personal Data; or anonymize the Relevant Personal Data to the level of Non-Personally Identifying Information.
15. YOUR LEGAL RIGHTS
Under applicable law, and on legitimate grounds, you may have a number of rights, including:
- The right not to provide your Personal Data to us. Please note that in this case, we may be unable to provide you with the full functionality of our Website, Platform or our services;
- The right not to provide your Personal Data to us including: the right of access to your Personal Data; the right to request alteration of inaccuracies; the right to request the deletion, or restriction of processing of your Personal Data; the right to object to the processing of your Personal Data; the right to have your Personal Data transferred to another party; the right to withdraw consent; and the right to lodge complaints with legitimate and recognized Data Protection Authority. We may require proof of your identity before we can give effect to these rights;
- The right to request access to, or electronic versions of, your Relevant Personal Data, together with information regarding the nature, Processing and disclosure of those Relevant Personal Data;
- The right to have certain Personal Data transferred to another party, in a structured, commonly used and machine-readable format, where relevant;
- The right to lodge complaints regarding the processing of your Personal Data with legitimate and recognized Data Protection Authority.
Changing Personal Data & Account Termination:
You may at any time review or change your Personal Data either directly by going to your account settings (if applicable) or through request by contacting us using the contact information in Section 18 below. Upon your request, we will deactivate or delete your account and contact information from our active databases. Such information will be deactivated or deleted as soon as reasonably possible based on your account activity and accordance with our deactivation policy and applicable law.
Please note that we may require proof of your identity before we can give effect to these rights. Furthermore, where your request requires the establishment of additional facts in request of the assertion of your rights, we will investigate your request as promptly as is reasonable before deciding what actions to take.
16. GENERAL USE STATEMENTS
The Right Five uses the Personal Data from the information you provide to us and which we maintain about you, together with other information we obtain from your current and past activities on the Platform in order to:
- Deliver the products and services that you have requested;
Manage your account and provide you with support;
Communicate with you by email, postal mail, telephone and/or mobile devices about products or services that may be of interest to you either from us, our affiliate companies, authorized partners or other third parties;
- Develop and display content and advertising tailored to your interests on the Platform and other sites;
- Resolve disputes and troubleshoot problems;
- Measure customer interest in our services;
- Inform you of updates;
- Customize your experience;
- Detect and protect us against error, fraud and other criminal activity;
- Perform other activities as described to you at the time of collection;
- Perform assessment across multiple users in order to identify problems. In particular, we may examine your Personal Data to identify users using multiple user IDs or aliases;
- Compare and review your Personal Data for accuracy and to detect errors and omissions;
- Process payment for any purchases made on the Platform. Specifically, we may use your financial information or your payment method to enroll you in the discount, rebate, and other programs in which you elect to participate; and
- Protect against or identify possible fraudulent transactions and otherwise as needed to manage our business.
The Right Five Communications & Direct Marketing:
Occasionally, we may send you service-related announcements periodically from time to time through the general operation of the service. Generally, you may opt out of such emails at the time of registration or through your account settings, though we reserve the right to send you notices about your account, such as service announcements and administrative messages, even if you opt out of all voluntary email notifications.
We may Process your Personal Data in respect of using your name, email address and other information to send you notifications regarding new services offered by the Platform that we think you may find valuable. This may include contacting you via email, telephone, direct mail or other communication formats. If we already provide services to you, we may send information to you regarding both our current and new services, upcoming promotions and other supplementary information that may be of interest to you, using the contact details that you have provided to us and always in compliance with applicable law.
You may unsubscribe from our email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but we may continue to contact you to the extent necessary for the purposes of any services you have requested.
Collection and use of Personal Data by third-parties:
Children’s Online Privacy Protection Act:
17. OTHER DEFINITIONS
“Controller” means the entity or persons within The Right Five that decides how and why Personal Data is Processed. The Controller has primary responsibility for complying with applicable data protection laws.
“Data Protection Authority” means an independent public authority that is legally empowered with overseeing compliance with applicable data protection laws.
“Personal Data” means information that is about any individual, or from which any individual is identifiable either directly (Personally Identifying) or indirectly (Non-Personally Identifying), in particular by reference to an identifier such as a name, contact information, an email address, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
“Process” means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction.
“Processor” means any persons or entity that Processes Personal Data on behalf of the Controller.
“Profiling” means any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a person’s attributes, in particular to: analyze, gain insight to, or predict characteristics of that person’s abilities, capabilities and suitability for specific roles in the workplace; motivations; preferences; interests; dependability; behavior; location; or experiences.
“Relevant Personal Data” means Personal Data in respect of which we are the Controller.
“Sensitive Personal Data” means any Personal Data that may legitimately be sent to us from you or another legitimate source including race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health, sexual life, any actual or alleged criminal offences or penalties, national identification number, or any other information that may be deemed to be sensitive under applicable law.
18. CONTACT DETAILS
The Right Five
Attn: Privacy Officer
485 South Logan Street Apt 6
Denver CO 80209