Last Modified: August 15, 2022
We may modify this Policy at any time, without prior notice, and changes may apply to any personal information we already hold about you, as well as any new personal information collected after the Policy is modified. If we make changes, we will notify you by revising the date at the top of this Policy. We will provide you with notice if we make any material changes to how we collect, use or disclose your personal information or that impact your rights under this Policy by posting a new notice on our Services page. If you continue to access or use our Services after being provided with the notice of changes, you acknowledge your acceptance of the updated Policy. If the applicable laws require notice and permission before making such material changes, we will do so.
In addition, we may provide you with real time or “just-in-time” disclosures or additional information about the data handling practices of specific parts of our Services when required by applicable laws. Such notices may supplement this Policy or provide you with additional choices about how we process your personal information.
2. Personal Information We Collect
Website and Account Information
Personal information is any information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device as defined by applicable law (“personal information”).
In particular, we collect the following categories of personal information:
Demographic Information (Blueprint)
In addition to Website and Account Information, in connection with certain Services, such as the Blueprint platform, you may provide general demographic information regarding your company’s employee population (“Demographic Information”). Demographic Information is not intended to identify individuals. You shall not provide employee names, employee identification numbers, or any other similar unique identifiers within Demographic Information and we reserve the right to delete such information immediately upon receipt.
Demographic Information may include:
If you wish to apply for a job at Paradigm on our Website, you may provide the following information:
3. Sources of Personal Information
a) Information You Provide Us
In connection with the Services, we may ask you to provide these categories of personal information:
b) Information We Collect Automatically
4. How We Use Your Information
Your personal information can be used for various purposes, including:
We will disclose to you any other use of your personal information in connection with our Services prior to processing your personal information for such purposes. You may choose not to allow us to process your personal information for any purposes that are not compatible with the purposes for which we originally collected your personal information or subsequently obtained your consent. However, you should be aware that if you choose to limit how we use your personal information, some or all of our Services may not be available to you.
5. How We Share Your Information
We may share your personal information as follows:
We will, at our discretion, provide you with advance notice if we are compelled to disclose your personal information to law enforcement, unless we are prohibited from doing so by public authorities or the law.
6. Cookies and Similar Tracking Technologies
Types of Cookies on Our Services. We use the following types of cookies on our Services:
How to Manage Cookies. Depending on whether you would like to manage a first-party or third-party cookie, you will need to take the following steps:
7. Your Choices
You have certain choices about the way we use or handle your personal information, including:
8. How We Secure Your Information
Paradigm employs commercially reasonable physical, administrative, and technical safeguards to help protect and secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.
You should be aware that, unfortunately, no system can be 100% secure. Although the security of your personal information is our highest priority, there will always be a risk that your personal information gets compromised. We also depend on you to keep your information secure by ensuring you access our Services via secure connections and taking other precautionary measures. Please notify us immediately at email@example.com if you become aware of any unauthorized access to or use of your personal information.
9. Transfers of Your Information
When you access or use our Services, your personal information may be processed in the United States or any other country in which Paradigm, its affiliates, or service providers maintain facilities. Such countries or jurisdictions may have data protection laws that are less protective than the laws of the jurisdiction in which you reside. If you do not want your information transferred to, processed, or maintained outside of the country or jurisdiction where you are located, you should immediately stop accessing or using the Services.
If you are located in the European Economic Area or Switzerland, please refer to the section below entitled, “Notice to Individuals in the European Economic Area, Switzerland and UK”.
10. How We Retain Personal Information
We generally retain your personal information for as long as necessary to fulfill the purposes of collection or to comply with applicable law. Otherwise, we will try to delete your personal information upon your request or when we no longer need it for the purposes it was originally collected, if your state or country of residence provides requires such. We will not delete any personal information that also relates to other individuals, unless such other individuals also wish to delete their personal information at the same time.
We recognize that retention requirements can vary between jurisdictions, but we generally apply the retention periods described below.
11. Privacy Rights
If you are a U.S. resident, your state of residence may provide you certain rights regarding your personal information, including:
To exercise any privacy rights provided by your state of residence, please contact us at firstname.lastname@example.org. Please note that certain employment information (e.g. job title, job level, department, functional group, etc.) may require administrator approval. If you wish to change employment information, please contact the administrator for your account.
Your state of residence may also permit you to ask us for a notice that identifies the categories of personal information that we share with our affiliates and/or third parties for marketing purposes, and that provides contact information for such affiliates and/or third parties. If your state provides you these rights and you would like a copy of this notice, please submit a written request to us at the address provided under the “Contact Us” section.If you are an EEA, Switzerland or UK resident please see “Notice to Individuals in the European Economic Area, Switzerland and UK” section.
12. Third Party Links On Our Services
You may find links to other websites, third party applications, and widgets on our Services that we do not own or control (“Third Party Links”). Paradigm is not responsible for the content on Third Party Links, nor do we endorse or review the privacy practices of such websites. Please read the privacy policies of such Third Party Links to understand how your personal information will be handled before using their websites or services.
13. Do-Not-Track Signals
Currently, we do not monitor or take any action with respect to Do Not Track signals or other mechanisms, which means that we collect information about your online activity both while you are using the Services and after you leave our Services.
14. Children’s Personal Information
Our Services are not for or directed towards children. We do not knowingly or intentionally collect personal information from minors, which we consider to be under the age of 13 or the equivalent age as specified by applicable law in your jurisdiction.
If we learn that we have collected personal information from a child, we will remove that information immediately and delete it (subject to applicable law). Please contact us if you believe we have collected personal information about a child without consent from their parent or guardian so we can take action to prevent such access and to delete their information from our Services.
15. Nevada Privacy Rights.
Nevada residents who wish to exercise their sale opt-out rights under Nevada Revised Statutes Chapter 603A may submit a request to this designated address: email@example.com. However, please know we do not currently sell data triggering that statute’s opt-out requirements.
16. Notice to Individuals in the European Economic Area, Switzerland and the UK
This section only applies to individuals using or accessing our Service while located in the European Economic Area, Switzerland or the United Kingdom (“UK”) (collectively, the “Designated Countries”) at the time of data collection.
We may ask you to identify which country you are located in when you use or access some of the Services, or we may rely on your IP address to identify which country you are located in. When we rely on your IP address, we cannot apply the terms of this section to any individual that masks or otherwise hides their location information from us so as not to appear located in the Designated Countries. If any terms in this section conflict with other terms contained in this Policy, the terms in this section shall apply to individuals in the Designated Countries.
Our Relationship to You. Paradigm is a controller with regard to any personal information collected from individuals directly. A “controller” is an entity that determines the purposes for which and the manner in which any personal information is processed. Paradigm is a data processor with regarding to any personal information it processes at the request of a data controller.
Legal Bases for Processing Your Personal Information. For personal information collected about you in the EEA, Switzerland and the UK, we set out below, in a table format, a description of the ways in which we use your personal information and the legal bases we rely on to do so. Where appropriate, we have also identified our legitimate interests in processing your personal information.
We may process your personal information for more than one legal basis depending on the specific purpose for which we are using your personal information. Please contact us at firstname.lastname@example.org. If you need details about the specific legal basis we are relying on to process your personal information where more than one ground has been set out in the table below.
Individual Rights. If the processing of your personal information is subject to the EU, Swiss or UK GDPR, the rights available to you depend on our reason for processing your personal information. Your rights may include:
For residents of France and Germany, you can send us specific instructions regarding the use of your data after your death.
You are not required to pay any charge for exercising your rights. These rights will be exercisable subject to limitations as provided for by GDPR.
Any requests to exercise the above-listed rights may be made to email@example.com.
You can also withdraw your consent at any time where we are relying on your consent to process your personal information. Please note that your withdrawal will not affect the lawfulness of any processing carried out before you withdrew your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Transfer of Your Personal Information. We transfer your personal information subject to appropriate safeguards as permitted under the relevant data protection laws. We rely primarily on the Standard Contractual Clauses as approved by the European Commission to facilitate the international transfer of your personal information collected in the EEA, the United Kingdom and Switzerland (“European Personal Information”), and any onward transfer of such information to the extent the recipients of the European Personal Information are located in a country that the EU, Switzerland or the UK considers to not provide an adequate level of data protection. Please contact us if you would like to learn about the specific transfer security mechanisms we use.
Data retention. We will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purpose of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, our obligations to the Plan Sponsor, and the applicable legal requirements.
17. Further Assurances
You agree to perform, execute, acknowledge, and deliver or cause to be performed, executed, acknowledged, and delivered all such further acts, agreements, and assurances as may reasonably requested by Paradigm or required by applicable privacy laws or regulations.
18. Contact Us