Privacy Policy
Updated: June 15, 2024
Effective: May 21, 2018
Web Sites Covered
Whiteboard Ventures Inc. D/B/A as Xpand is committed to protecting the privacy of your personal information. This Privacy Statement describes Xpand’s information practices.
This Privacy Statement covers the information practices of web sites (and other protocols) that link to this Privacy Statement: www.xpand.io and all subdomains of www.xpand.io; (collectively referred to as “Xpand’s web sites” or “the Company’s web sites”). Xpand is the controller for the personal data discussed in this Privacy Statement, except as noted in the “Xpand as a Service Provider” section below.
Xpand.io, http://www.xpand.io, is a marketing and sales information source for the Company. Related Xpand web sites are created for corporate customers to use the Xpand Service.
Xpand’s web sites may contain links to the web sites of other companies. Xpand is not responsible for the information practices or the content of such other web sites. The Company encourages you to review the privacy statements of such web sites to understand their information practices.
Xpand as a Service Provider
Xpand customers are organizations that use our services to help them onboard employees. Xpand processes personal data in these services only according to our customers’ instructions. If you have questions about personal data you have entered into an Xpand service used by one of our customers, or want to exercise any of your rights regarding your personal data, our customer contract requires that we redirect your inquiry back to that Xpand customer.
EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) and to the rights of EU and UK individuals and Swiss individuals
Xpand complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Xpand has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Xpand has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Xpand commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Xpand by emailing support@xpand.io.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Xpand commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Xpand commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to the BBB National Programs DPF Services, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://bbbprograms.org/programs/all-programs/dpf-consumers for more information or to file a complaint. The services of the BBB National Programs DPF Services are provided at no cost to you.
The Federal Trade Commission has jurisdiction over Xpand’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
Xpand is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to your organization and following the procedures and subject to conditions set forth in Annex I of Principles.
General Data Protection Regulation (GDPR) - European Representative
Pursuant to Article 27 of the General Data Protection Regulation (GDPR), Whiteboard Ventures, Inc. has appointed European Data Protection Office (EDPO) as its GDPR representative in the EU. You can contact EDPO regarding matters pertaining to the GDPR by:
- Sending an email to privacy@edpo.brussels
- Using EDPO’s online request form at https://www.edpo.brussels/contact
- Writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium
Our Guiding Principles
- We minimize the information we collect and maintain about you
- We do not share personally identifiable information except for obvious reasons
- We will not spam you
Personal Information Collected
Xpand offers a variety of services that are collectively referred to as the “Service.” Xpand collects information from individuals who visit the Company’s web sites (“Visitors”) and individuals and companies who contract to use the Service (“Customers”).
When expressing an interest in obtaining additional information about the Service or registering to use the Service, Xpand requires you to provide the Company with contact information, such as name, company name, address, phone number, and email address (“Required Contact Information”). When registering to use the Service, Xpand requires Customers to provide the Company with "Required User Information" about their users, such as name and email address. Required Contact Information and Required User Information are referred to collectively as “Data About Xpand Customers.” If you correspond with us by email, we may retain the content of your email messages and our responses so that we can provide you with better customer service. We also store information that you have indirectly provided to us via your Content and Application(s).
Xpand will only collect and use sensitive personal data if a Customer’s proven legal purpose requires it.
Xpand only collects and uses the personal data of children and minors from their parents or legal guardians for limited and legitimate purposes.
As you navigate the Company’s web sites, Xpand may also collect information through the use of commonly-used information-gathering tools, such as cookies (“Web Site Navigational Information”). Web Site Navigational Information includes standard information that is automatically reported by your browser each time you access a web page. When you use the Service, our servers automatically record certain information that your web browser sends. These server logs may include information such as your web request, Internet Protocol (IP) address, browser type, referring / exit pages and URLs, number of clicks, domain names, landing pages, pages viewed, and other such information. We use this information, which does not identify individual users, to analyze trends, to administer the site, to track averaged users' movements around the site and to gather demographic information about our user base as a whole.
Use of Information Collected
We use your personal information only to provide you with the expected features and functionality of the Service and respond to customer service requests. By providing Xpand your email address you consent to our using the email address to send you critical Service notices, including any notices required by law, in lieu of communication by postal mail.
We may also use your email address to send you other messages, including company news, updates, related product or service information, etc. Out of respect for your privacy, you may choose to stop receiving these messages by following unsubscribe instructions included in these emails or you can email us at support@xpand.io.
Xpand uses Web Site Navigational Information to operate and improve the Company’s web sites. The Company may also use Web Site Navigational Information in combination with Data About Xpand Customers to provide personalized information about the Company.
Sharing of Information Collected
Xpand does not sell, trade, rent or otherwise transfer to outside parties Data About Xpand Customers. If this practice changes in the future Xpand will update this policy and provide individuals with opt-in choice prior to their information being shared. This does not include trusted third-party agents who assist us in operating our website, namely Amazon Web Services, which provides our servers. These companies are authorized to use Data About Xpand Customers only as necessary to provide these services to us. If we do this, such third-parties' use of your information will be bound by this privacy policy and all transfers of data to third-parties may only occur to other organizations that follow adequate data protection principles.
Pursuant to the Data Privacy Framework, Xpand remains liable for the transfer of personal data to third parties acting as our agents unless we can prove we were not a party to the events giving rise to the damages.
We may store Data About Xpand Customers in locations outside the direct control of Xpand (e.g., on servers at hosting providers).
We may also disclose Data About Xpand Customers:
- in response to a lawful request by public authorities, such as to comply with a subpoena, or similar legal process, including to meet national security or law enforcement requirements,
- if necessary for the performance of a contract to which the Customer is party or in order to take steps at the request of the Customer prior to entering into a contract,
- if necessary for compliance with a legal obligation to which the Customer is subject;
- when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request,
- if Xpand is involved in a merger, acquisition, or sale of all or a portion of its assets (you would be notified via email and/or a prominent notice on our web site of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information), and
- to any other third-party with your prior consent to do so.
Xpand shares Data About Xpand Customers and their usage with the Customer's designated administrative users, for example, information about recent logins and usage of the Xpand's applications. If Customers publish data and Content to multiple users within the Xpand application (e.g., by adding accounts), we will share the associated Content with those users.
When employers require it, Xpand uses the US Department of Homeland Security's Citizenship and Immigration Services E-Verify service. Xpand does not store, retain, or use E-Verify Information except for the minimum necessary to process and maintain status information on the E-Verify process.
Access to Personal Information
Xpand acknowledges the individual’s right to access their personal data. If your personally identifiable information changes, or if you no longer desire our Service, you may correct, update, amend or remove it by making the change on our member information page or by contacting us by email, telephone or postal mail at the contact information listed below. We will respond to your request to access within 30 days.
Correcting and accessing your Information
We encourage you to update the information you provide to us, such as providing us with a new mailing or email address, a name change, etc. This will help us continue to provide information to you that best meets your needs. Xpand complies with laws and regulations applicable to the right to amend your data in our files. These rights are limited in some ways. In addition, to protect your data from unauthorized access or alteration by third-parties, all requests to update or access your information will be subject to verification of your identity. Please submit requests to support@xpand.io.
We will retain your information for as long as your account is active or as needed to provide you services. We will also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Web Site Navigational Information
Xpand uses commonly-used information-gathering tools, such as cookies and web beacons, to collect information as you navigate the Company’s web sites (“Web Site Navigational Information.”) This section describes the types of Web Site Navigational Information the Company may collect and how the Company may use this information.
Cookies
Xpand uses cookies to make interactions with the Company’s web sites easy and meaningful. A cookie is a small text file that is stored on a user's computer for record-keeping purposes. When you visit one of the Company’s web sites, the Company’s servers send a cookie to your computer. Standing alone, cookies do not personally identify you. They merely recognize your web browser.
Unless you choose to identify yourself to Xpand, either by responding to a promotional offer, opening or using an account, or filling out a web form, you remain anonymous to the Company.
If you have chosen to identify yourself to Xpand, the Company uses session cookies containing encrypted information to allow the Company to uniquely identify you. Each time you log into the Service, a session cookie containing an encrypted, unique identifier that is tied to your account is placed your browser. These session cookies allow the Company to uniquely identify you when you are logged into the Service and to process your online requests. Session cookies are required to use the Service.
We use both session ID cookies and persistent cookies. Session cookies are required for most of the functionality of our web site and for web tools such as our administrative application. These cookies are used to implement application authentication, allowing us to implement secure access to your data. A session ID cookie expires when you close your browser.
A persistent cookie remains on your hard drive for an extended period of time. You can remove persistent cookies by following directions provided in your Internet browser's "help" file.
Persistent cookies enable us to track and target the interests of our users and to improve our site. For security reasons, we do not use persistent cookies for application authentication.
If you reject cookies, you may still use our site, but your ability to use some key areas of our site, such as our administrative application tools, will be disabled or significantly affected.
Xpand uses persistent cookies that only the Company can read and use to identify browsers that have previously visited the Company’s web sites. When you log into the Service or provide the Company with personal information, a unique identifier is assigned to you. This unique identifier is associated with a persistent cookie that the Company places in your web browser. The Company is especially careful about the security and confidentiality of the information stored in persistent cookies. For example, the Company does not store account numbers or passwords in persistent cookies. If you disable your web browser’s ability to accept cookies, you will be able to navigate the Company’s web sites, but you will not be able to successfully use the Service.
Xpand may use information from session and persistent cookies in combination with Data About Xpand Customers to provide you with information about the Company and the Service.
IP Addresses
When you visit Xpand’s web sites, the Company collects your Internet Protocol (“IP”) addresses to track and aggregate non-personally identifiable information. For example, Xpand uses IP addresses to monitor the regions from which Customers and Visitors navigate the Company’s web sites.
Xpand may also collect IP addresses from Customers whey they log into the Service as part of the Company’s “Identity Confirmation” and “IP Range Restrictions” security features.
Customer Data
Xpand Customers use the Service to host data and information (“Customer Data”). Xpand will not review, share, distribute, or reference any such Customer Data except as provided in the Xpand Master Subscription Agreement, Statements Of Work, or as may be required by law. Individual records of Customer Data may be viewed or accessed only for the purpose of resolving a problem, support issues, suspected violation of the Xpand Master Subscription Agreement, or as may be required by law. Customers are responsible for maintaining the security and confidentiality of their Xpand usernames, passwords and multifactor authentication devices (if any).
Security
Xpand uses robust security measures to protect Customer Data from unauthorized access, maintain data accuracy, and help ensure the appropriate use of Customer Data. On those pages where our users can register for our service and/or log-in, we encrypt the transmission of that information using Transport Layer Security (“TLS”), previously Secure Socket Layer (“SSL”), technology, which protects Customer Data using both server authentication and data encryption. These technologies help ensure that Customer Data is safe, secure, and only available to the Customer to whom the information belongs and those to whom the Customer has granted access. Xpand also implements an advanced security method based on dynamic data and encoded session identifications, and the Company hosts its web sites in a secure server environment that uses firewalls and other advanced technology to prevent interference or access from outside intruders. Xpand also offers enhanced security features within the Service that permit Xpand to configure security settings to the levels Customers deem necessary.
If you have any questions about security on our web site, you can email us at support@xpand.io.
Because the Company uses the Service to maintain Data About Xpand Customers, this information is secured in the same manner as described above for Customer Data.
What else should you know about?
Links to 3rd Party Sites
Our web site includes links to other web sites whose privacy practices may differ from those of Xpand. If you submit personal information to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any web site you visit.
Blog / Support Forum
Our web site offers public and Customer-wide accessible blogs, community forums, directories and social communications tools. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information from these tools, contact us at support@xpand.io. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.
Testimonials
We may display personal testimonials of satisfied customers on our site in addition to other endorsements. With your consent we may post your testimonial. If you wish to update or delete your testimonial, you can contact us at support@xpand.io.
Single Sign-On
Users affiliated with some Customers may be able to log in using sign-in services provided by the Customer. These services will authenticate your identity and may automatically share or provide you the option to share certain personal information with us such as your name and email address to pre-populate information in our Service. Services of this nature may give you the option to sync and share information with others within your network.
Social Media Widgets
Certain portions of our web site, such as the public blog, include Social Media Features, such as the Facebook Like button or Twitter button. These Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third-party or hosted directly on our site. Your interactions with these Features are governed by the privacy policy of the company providing it.
Changes to this Privacy Statement
We may update this privacy policy to reflect changes to our information practices. If we make any material changes, we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on this web site prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
Contacting Us
Questions regarding this Privacy Statement or the information practices of the Company’s web sites should be directed to Xpand by sending an email to support@xpand.io or by mailing Xpand Privacy, 500 7th Ave, 8th Floor, New York, NY 10018.