Tietosuoja
Tietosuojaseloste
PRIVACY POLICY FOR PARTICIPANTS OF EVOLV SERVICES
Effective on June 1, 2023
Your privacy is important for us.
This Privacy Policy sets out the terms of personal data processing for participants of Evolv services according to EU’s General Data Protection Regulation as well as Finnish Data Protection Act and Act on the Protection of Privacy in Working Life.
Content
- Controller of the register
- Definitions
- To what purposes Evolv processes your data and based on which grounds?
- General principles for data protection in Evolv services
- What types of information Evolv may collect about you?
- Which sources Evolv gathers your personal data from?
- To whom Evolv may transfer and assign your personal data?
- Is your data transferred to countries outside the European Union?
- How long does Evolv process your data?
- How can you exercise the different types of rights you have?
- How can you exercise your right to lodge a complaint to the supervisory authority?
- Which law do we apply for processing personal data?
- How can we update this Privacy Policy?
- Controller of the register
Controller of the register is the Finnish company Evolv Ltd (business registration number: 2995199-3), hereinafter referred to as ”Evolv”.
Evolv’s contact details related privacy matters are:
Evolv Ltd / Privacy
Metallimiehenkuja 10, 02150 Espoo, Finland
E-mail address: contact@evolv.fi
Please do not hesitate to contact us if you have any questions, concerns or ideas related to Evolv’s personal data procedures.
- Definitions
In the following the most essential terms used in this privacy policy are explained:
- ’Participant’ or ‘End User’ or ‘You’ means any person who participates to Evolv Leadership Diamond® program and services.
- ’Personal data’ means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly.
- ’Consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
- To what purposes Evolv processes your data and based on which grounds?
Evolv may process your personal data directly necessary for your Evolv Leadership Diamond® coaching program and participation to services and which is connected with managing the rights and obligations of the parties to the relationship or with the benefits possibly provided by Evolv or its corporate customer for you, or which arises from the special nature of the work concerned.
Evolv services include but are not limited to Leadership Diamond® coaching programs for individuals and teams. When taking any of our services into use, you have actively given consent to our Terms of Service and this Privacy Policy.
Evolv may also process your personal data for communication and marketing purposes, for example to invite you to Evolv’s and/or its corporate customers’ events.
Processing of your personal data is based on the following grounds of the EU’s General Data Protection Regulation (one or more grounds may apply simultaneously):
- Processing is necessary in order to take steps at your request prior to entering into a contract
- Processing is necessary for the purposes of the legitimate interests pursued by Evolv and/or its corporate customers
- You have given consent to the processing of your personal data
The legitimate interests of Evolv or third party referred to in point 2) above may include amongst others the following matters: business development.
In addition to the above, Evolv uses your data if we think it’s necessary for security purposes or to investigate possible fraud or other violations of our agreements or this Privacy Policy.
- The general principles for data protection in Evolv services
No security system is impenetrable and security risks exist in any system. However, we make consistent efforts to keep your information secure. Evolv has established electronic and administrative safeguards designed to make the information processed secure and to protect it from abuses. Such mechanisms include, for example, the control of data network traffic and filtering, use of relevant encryption technologies and secure data centers, managed processes of granting of user rights and monitoring of their usage, instructing the personnel involved in the processing of personal data.
- What types of information Evolv may collect about you?
Evolv collects only such personal data which is necessary in providing our services. The data which we collect in Evolv Leadership Diamond® coaching programs and services may include the following types of data:
General information
- Personal information
-
- Last name, first name
- Email address
- Phone number(s)
- Language
- Job position
- Company i.e. participant’s employer
- Company address
- IP address
- Device information such as device type and version, browser and operating system related information
- Session ID and other similar information
- Most recent login date stamp to the Evolv Leadership Diamond® mobile application
- Password to the Evolv Leadership Diamond® mobile application
- Mobile application device token via which push messages can be sent to the participant, which can be also restricted by a participant
- Calendar bookings in mobile application, which forwards invitations to participant’s own calendar. This can be restricted by a participant.
Coaching specific information
- Participant’s wellbeing and leadership targets, added voluntarily by a participant
- Information about participant’s progress in the coaching program, added voluntarily by a participant
- Evolv Index mood-barometer results, added voluntarily by a participant
- Surveys and wellbeing data from wearable devices which contain information on you regarding a) wellbeing habits: physical activity, stress and recovery level, nutrition habits, sleep, muscle and mobility fit, aerobic fit b) work personality and mental wellbeing c) personal values c) leadership styles
- Chat communication, discussions and guidance related to coaching targets, challenges, actions and results between a participant and dedicated coaches
- Participant’s coaches in the program
- Participant’s team mates in the program
- Which sources Evolv gathers your personal data from?
Evolv gathers personal data directly from:
- Evolv Leadership Diamond® mobile application
- In and between coaching discussions
- The coaching program relevant 3rd party surveys and Evolv surveys
- E-mail correspondence, teams-meetings, phone calls and face-to-face meetings
- 3rd party applications such as FirstBeat
- To whom Evolv may transfer and assign your personal data?
We do not sell, rent or loan your name, e-mail address, or other personal data to anyone.
Evolv may share your personal data with authorized third parties that perform services for Evolv for the purposes described in this Privacy Policy within the limits of the applicable legislation. This may include for example providing services such as software services, managing and analyzing personal data and surveys, or providing coaching to a participant.
Evolv does not allow those companies to use the personal data for any purpose other than to perform those services, and Evolv requires them to protect your personal data in a way consistent with this Privacy Policy and legislation.
When collecting your personal data through third parties’ surveys in Evolv coaching program / services, the third parties use own service providers for data collection and data hosting. A third party in question requests your additional consent for using their survey service.
All personnel of Evolv and its subcontractors and service providers are obliged to keep the information of the personal data which they obtain in their work confidential.
The external service providers include:
- Network of coaching specialists (several third party service providers who work as dedicated Evolv coaches. Their access to personal data is limited to their dedicated Evolv Leadership Diamond® coaching programmes)
- Administrative support (coordination of Evolv services and coaching programmes)
- Firstbeat Technologies Oy (equipment for physical wellbeing measurement)
- Wellbeing Factory Oy (wellbeing survey)
- Workplace Nordic Oy using service provider Paradigm Personality Labs LLC (work personality survey)
- Nastaset Oy (maintenance of the Evolv Leadership Diamond® mobile application)
- Microsoft Office 365 (data and communication).
- Amazon Web Services, Inc (AWS) (data in Evolv Leadership Diamond® mobile application)
- Other possible third party service providers which are agreed during the service with a participant and/or his/her employer
Your results may be included in aggregate level reports to our corporate customers. The aggregate level reports will only be shown when sample sizes are large enough to not enable identifying individuals. While maintaining anonymity, we may collect and use data for research, service development, statistical evaluations and other comparable purposes. The anonymized and aggregated data shall not anymore be considered as personal data.
Evolv may share your personal data as part of any merger, acquisition, sale of company assets or transition of service to another provider. This also applies in the unlikely event of an insolvency, bankruptcy or receivership in which your personal data would be transferred to another entity as a result of such a proceeding.
Evolv may share your personal data based on a valid order from a court or other official body with sufficient authority.
- Is your data transferred to countries outside the European Union?
Evolv’s primary aim is to use resources located within the EU. Evolv may sometimes transfer your personal data outside the country where you use our services, including to countries outside the EU and EEA that do not have laws providing specific protection for personal data or that have different legal rules on data protection. In such cases Evolv ensures that a legal basis for such a transfer exists and that adequate protection for your personal data is provided as required by applicable law, for example, by using standard agreements approved by relevant authorities (where necessary) and by requiring the use of other appropriate technical and organizational information security measures.
Currently your data may be transferred to outside EU and EEA by using Workplace Big Five Personality Survey.
- How long does Evolv process your data?
Evolv may process your data at maximum two years from the end of your last coaching program / use of Evolv services. Based on your consent Evolv may process your personal data for as long as the consent describes.
Evolv may process your personal data based on legal requirements for as long as the applicable legislation allows.
- How can you exercise the different types of rights you have?
You have the right to obtain from Evolv confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, receive information about your personal data.
You have the right to obtain from Evolv the erasure of personal data concerning you without undue delay where one of the following grounds applies and when there are no overriding legal obligations or legitimate grounds for processing:
- your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- you withdraw consent on which the processing is based and where there is no other legal ground for the processing
You have the right to obtain from Evolv restriction of processing where one of the following applies:
- the accuracy of the personal data is contested by you, for a period enabling Evolv to verify the accuracy of the personal data;
- Evolv no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
- you have objected to processing pending the verification whether the legitimate grounds of Evolv override those of you.
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests pursued by Evolv. Evolv shall no longer process the personal data unless Evolv demonstrates compelling legitimate grounds for the processing.
Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
Please be aware that you cannot opt out of receiving service messages from Evolv, including but not limited to security and legal notices.
You have the right to receive the personal data concerning you, which you have provided to Evolv, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller where: the processing is based on consent or on a contract; and (b) the processing is carried out by automated means.
All rights can be exercised by contacting Evolv’s privacy team by using the contact details issued at section 1 above. The team will then give further instructions on how to exercise a specific right. Where Evolv has reasonable doubts concerning the identity of the person making the request, Evolv may request the provision of additional information necessary to confirm your identity.
Evolv will provide information on action taken on a request to you within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests.
- How can you exercise your right to lodge a complaint to the supervisory authority?
In case you suspect a breach of data protection legislation, please contact Evolv’s privacy team first (contact information in section 1). In case the matter is not solved amicably between you and Evolv, you may contact the Finnish Data Protection Authority. Contact information of the competent authority can be found www.tietosuoja.fi.
12.Which law do we apply for processing personal data?
The processing of personal data is governed by the European Union’s applicable data protection legislation as well as national laws of Finland.
- How can we update this Privacy Policy?
Evolv may modify this Privacy Policy, and if we make material changes to it, we will provide notice on our website or by other means, to provide you the opportunity to review the changes as they become effective and binding.