NEXTEP Privacy Notice
Last Updated: December 10, 2020
At NEXTEP Systems, Inc. (“NEXTEP”), we respect your concerns about privacy. NEXTEP provides self-ordering kiosk solutions, point of sale, digital signage, mobile and online ordering, and restaurant management software (our “Services”) for managed food service companies, quick service and fast casual restaurants, and other corporate customers (our “Customers”). This Privacy Notice (“Notice”) relates to the collection of personal information through our Services, on our websites, forums and blogs (“Sites”) and mobile applications (“Apps”) in the course of our business activities.
For the purpose of this Notice, NEXTEP, “we” and “us” refer to NEXTEP, Systems Inc. and its subsidiaries and affiliates, as the context requires. Our privacy practices vary depending on the Services we provide and the country-specific requirements for the countries in which we operate. For some products and Services, where required, we will provide additional privacy notices before collecting your personal information. Please read this Notice carefully. If you have any questions, you may contact us at email@example.com or by the methods provided in the “Contact Us” section below.
NEXTEP collects personal information from users of our Services, Sites, and Apps who might be our Customers, prospective Customers, or our Customer’s end users (“End Users”) who engage with our Sites or Services as part of the Services we provide to our Customers.
Because NEXTEP’s relationship with End Users is indirect, we process such End User personal information only for the purposes of providing the Services, in accordance with our Customer’s instructions. If you are an End User who has a relationship with one of our Customers and you have a question about how your personal information is collected, used, or shared, or would like to exercise any rights you may have with respect to your personal information, please contact the Customer directly. Please be aware that not all of the information in this Notice will be directly applicable to our handling of your personal information. This Notice provides an overview of the possible circumstances in which we may interact with your personal information. If you have any questions about our processing of your personal information, please contact us at firstname.lastname@example.org.
Personal Information We Collect
Through our Sites and Apps, subject to your consent if required by law, we may collect the following personal information:
- Identifiers (including name and contact information including telephone number, email address, or postal address)
- Information protected against security breaches (such as financial account information, information about your preferred payment method, and username and password)
- Commercial information (such as your access and purchase history, the products and Services we provide to you, your marketing preferences, or information you provide in any communication with us or when you participate in any blog, community or forum on our Sites)
- Internet/electronic activity (see “Cookies and other tracking technologies” for additional information)
- Professional or employment related information (such as your status with the organization with which you are affiliated or information you provide as a job applicant)
- Inferences from the foregoing such as your preferences, characteristics or predispositions
Data anonymization and aggregation. Subject to your consent if required by law, we may anonymize or aggregate your personal information in such a way as to ensure that you are not identified or identifiable from it, in order to use the anonymized or aggregated data. For example, we may use anonymized or aggregated data for statistical analysis including to analyze trends, for product development, and for risk assessments and cost analysis. We may share anonymized or aggregated data with our parent, subsidiaries, affiliates or with other third parties.
Use of Personal Information
We may use the information that we collect about you for the following purposes:
Providing our Services and related support: including to help fulfill your requests for products and Services; to communicate with you about your use of our Services; to respond to your inquiries; to provide troubleshooting and other technical support; and for other customer service and support purposes.
Protecting the integrity of the Services: including to verify your identity; to detect and prevent fraud and unauthorized activities; to facilitate software; to preserve the integrity of the Services and our systems, and prevent unauthorized access and activities; to enforce our applicable terms; and to protect the rights and safety of others
Analyzing and improving the Services and our business: including to better understand how users access and use our Services; to evaluate and improve the Services and our business operations; to develop new features, offerings and Services; to conduct surveys and other evaluations; and for other research and analytical purposes.
Market to our Customers: including to contact them about our Services, and those of our affiliates, as well as other information we think may be of interest. Where required by applicable law, we will obtain your consent to use your personal information for marketing and related purposes. We do not use End User data for marketing purposes.
Securing and protecting our business: including to protect and secure our business operations, assets, Services, network and information and technology resources; to investigate, prevent, detect and take action regarding fraud, unauthorized access, situations involving potential threats to the rights or safety of any person or third party, or other unauthorized activities or misconduct.
Defending our legal rights: including to manage and respond to actual and potential legal disputes and claims, and to otherwise establish, defend or protect our rights or interests, including in the context of anticipated or actual litigation with users or third parties.
Auditing, reporting, corporate governance, and internal operations: including relating to financial, tax and accounting audits; audits and assessments of our operations, privacy, security and financial controls, risk, and compliance with legal obligations; our general business, accounting, record keeping and legal functions; to maintain appropriate business records; to enforce company policies and procedures; and related to any actual or contemplated merger, acquisition, asset sale or transfer, financing, bankruptcy or restructuring of all or part of our business.
Complying with legal obligations: including to comply with the law, our legal obligations and legal process, such warrants, subpoenas, court orders, and regulatory or law enforcement requests.
Sources of Personal Information
We collect personal information from the following sources:
Information that you provide to us: We collect personal information that you provide to us when you set up an account with us, use our Services, or communicate with us. For example, if you register for an online account with us, we may request your name, contact information and payment information. Providing us with personal information about yourself is voluntary, and you can always choose not to provide certain information, but then you may not be able to take advantage of or participate in some of the Services' features.
Information collected from third parties: We may collect information about you from third parties in the course of providing our Services to you. For example, we may collect personal information like your name and contact information from our Customer if you are a Customer’s end user in order to provide the Services to you.
Information collected through technology: When you visit our Sites or Apps or interact with an email we send to you, we may collect certain information automatically such as your account or device identifier, and usage information such as pages that you visit, information about links you click, the types of content you interact with, the frequency and duration of your activities, and other information about how you use our services. You have the ability to express your preference regarding some of the ways we collect information through technology in some of our services (see “Cookies and Other Tracking Technologies” for more information). We may collect geolocation in the Sites or Apps for the purpose of enabling location-based Services.
Sharing of Personal Information
Except as otherwise specified, we may share any of the categories of your personal information in the manner and for the purposes described below:
- With NEXTEP affiliates where such disclosure is necessary to provide you with our Services or to manage our business.
- With third-party service providers whose systems, applications, products or Services help us to provide the Services. For example, we share personal information with IT service providers who help manage our back office systems or administer our Sites and Apps. These service providers have agreed to confidentiality restrictions and have agreed to use any personal information we share with them, or which they collect on our behalf, solely for the purpose of providing the contracted service to us.
- With our Customer with whom you are also engaging when you use the Services. For example, you may be using a NEXTEP Site to log into your account with our Customer. NEXTEP will share the personal information you provide in order to fulfill your request. You may also receive communications from the Customer. Each such Customer operates independently from NEXTEP and their collection and use of your personal information is not subject to this Notice but to their own privacy notices.
- Where directed by a Customer, the Service may allow you to connect with external third party applications or services such as MyFitnessPal or FitBit, through an application programming interface (API) or other software. By allowing the Site to connect with your accounts on such third party sites, you consent to our accessing the information in those accounts, which information may include personal information. When you access the Sites via a third party account, activity you engage in through the Site may be published on the third party site. It is your choice whether to use any such third party sites.
- We may share identifiers with logistics service providers to enable the delivery of packages to individuals.
- We may share internet/electronic activity information (see “Cookies and Other Tracking Technologies” below) with advertisers and analytics providers in order to help us measure our ad campaigns and better understand how individuals interact with our Sites and Apps.
- With other third parties with whom you direct us to share defined categories of your personal information.
In addition, subject to applicable legal requirements, we may share personal information in connection with or during negotiation of any merger, financing, acquisition, bankruptcy, dissolution, transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business assets to another company.
Unless otherwise disclosed in a specific notice, and subject to your consent where required by applicable law, we do not sell your personal information to third parties for monetary compensation.
Cookies and Other Tracking Technologies
A "cookie" is a text file that is stored to your browser when you visit a website. Unique device identifiers like IP address or UDID recognize a visitor's computer or other device used to access the internet. Unique device identifiers are used alone and in conjunction with cookies and other tracking technologies for the purpose of "remembering" computers or other devices used to access the Sites and Apps.
Cookies or similar tracking technologies are used to help us remember information about your visit to the site, like your country, language and other settings. Tracking technologies allow us to understand who has seen which websites, advertisements, or emails we have sent to determine how frequently particular pages are visited, as well as the relevance and effectiveness of our messages. They can also help us to operate our Sites more efficiently and make your next visit easier. Cookies and other tracking technologies can allow us to do various other things, as explained further below.
Cookies can be classified by duration and by source:
Duration. The Sites use both “session” and “persistent” cookies. Session cookies are temporary - they terminate when you close your browser or otherwise end your “active” browsing session. Persistent cookies remember you on subsequent visits. Persistent cookies are not deleted when you close your browser, and they will remain on your computer or other device unless you choose to delete them (see below for “How to Delete or Block Cookies”).
Source. Cookies can be “first-party” or “third-party” cookies, which means that they are either issued by or on behalf of Active or by a third-party operator of another website. For an example of a third-party cookie, our Sites may contain a Facebook “like” button, which would set a cookie that can be read by Facebook. Our Sites may use both first-party and third-party cookies.
The cookies that we may use on the Sites fall into the following categories:
Strictly Necessary Cookies. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions taken by you such as logging in or filling in forms. You can set your browser to block or alert you about these cookies, but blocking them may impede the functionality of the Sites.
Performance Cookies. These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
Functionality Cookies. These cookies enable the Sites to provide enhanced functionality and personalisation. They may be set by us or by third-party providers whose Services we have added to our pages. If you do not allow these cookies then some of these Services may not function properly.
How to Delete or Block Cookies and Other Tracking Technologies
On some Sites, when technically feasible, we will enable tools to help you make choices about cookies and other tracking technologies. You may also delete or block cookies at any time by changing your browser settings. You can click “Help” in the toolbar of your browser for instruction or review the cookie management guide produced by the Interactive Advertising Bureau available at www.allaboutcookies.org. If you delete or block cookies, some features of the Sites may not function properly.
NEXTEP may provide links on our Sites to other websites that are not under our control. We do not endorse or make any warranty of any type regarding the content contained on such websites or products and Services offered on those websites. We make no representation regarding your use of such websites. Please be aware that we are not responsible for the privacy practices of the operators of other websites. We encourage our users to be aware when they leave our Sites and to read the privacy statements of each and every website that collects personal information. This Notice applies solely to information collected by us. You should read any other applicable privacy and cookies notices carefully before accessing and using such other websites.
Consent to Processing
By using our Site, participating in any of our Services and/or providing us with your personal information, you consent and agree to the collection, transfer, storage and processing of your information to and in the United States.
Our Site does not recognize browser "Do Not Track" signals but several of our service providers who utilize these cookies or beacons on our web sites enable you to opt out of this behavioral advertising. To learn more about how to opt out of the behavioral advertising conducted by these providers you can visit http://www.networkadvertising.org/.
YOUR LEGAL RIGHTS
If you are an End User who uses NEXTEP for the purpose of registering or engaging with our Customers and have questions about legal rights you may have with respect to your personal information collected by our Customer, please consult the Customer with which you have engaged.
Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, some users, including European Union residents and residents of the state of California, may have certain rights in relation to their personal information. These rights may include:
|EU Resident Rights||What does this mean?|
|Right to be informed||You have the right to be provided with clear and easy-to-understand information about how we use your personal information. This is why we are providing you this Notice and we may provide other forms of notice, as appropriate or required by law, in the Services.|
|Right to access personal information||You have the right to access and receive a copy of personal information we hold about you.|
|Right to data portability||In some circumstances, you have the right to receive the personal information you request from us in a format that is user-friendly and enables you to transfer it to another provider.|
|Right to rectification||You have the right to correct or update your personal information if it is outdated, incorrect or incomplete.|
|Right of erasure ("right to be forgotten")||In some circumstances, you have the right to have your personal information erased or deleted.|
|Right to restrict/suspend processing of personal information||You may object to processing of personal information that is based on legitimate interest. You may withdraw consent for processing that is based on consent (this includes the right to opt out of direct marketing).|
|Right to information about information transfers||You have the right to obtain a copy of documents related to the safeguards under which your personal information is transferred outside the EU.|
|Right to complain to a supervisory authority||You have the right to contact the data protection authority in your country to complain about our data protection and privacy practices.|
|CA Resident Rights||What does this mean?|
|Right to know about personal information collected, disclosed, and sold||You have the right to request that we disclose to you what categories of personal information we have collected, used, disclosed, or sold over the past 12 months. We have provided information about the categories of personal information we have collected, the sources from which we collected it, the purposes for which it was collected, and the third parties with whom we may share it with above.|
|Right to opt-out of the sale of personal information||You may request that we do not sell your personal information to third parties.|
|Right to request deletion||In some circumstances, you have the right to have your personal information erased or deleted.|
|Right to equal service and prices ("non-discrimination")||Your choice to exercise your privacy rights will not be used as a basis to discriminate against you in Services offered or pricing.|
Managing Your Preferences
Where we engage in direct marketing to Customers, we will take steps to seek to ensure that any direct marketing from us and which is sent by electronic means will provide a simple means for you to stop further communications, in accordance with applicable law. For example, in emails, we may provide you with an “unsubscribe” link, or an email address to which you can send an opt-out request. In addition, if we need your consent for direct marketing communications under applicable law, and if you provide your consent, you will be able to change your mind at any time.
Data Anonymization and Aggregation
Subject to your consent if required by law, we may anonymize or aggregate your personal information in such a way as to ensure that you are not identified or identifiable from it, in order to use the anonymized or aggregated data, for example, for statistical analysis and administration including analysis of trends, to carry out actuarial work, to tailor products and services and to conduct risk assessments and analysis of costs and charges in relation to our products and services. We may share anonymized or aggregated data with our global affiliates and with other third parties. This Notice does not restrict Global Payments' use or sharing of any non-personal, summarized, derived, anonymized or aggregated information.
How we Protect and Dispose of Personal Information
We maintain administrative, technical and physical safeguards designed to protect the personal information you provide against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use.
Any suspected attempt to breach our policies and procedures, or to engage in any type of unauthorized action involving our information systems, is regarded as potential criminal activity. Suspected attempts to access or use our systems in a way that is inconsistent with our legal terms or security controls may be reported to the appropriate authorities.
Please remember that communications over the internet such as emails are not secure. We seek to keep secure all confidential information and personal information submitted to us in accordance with our obligations under applicable laws and regulations. However, like all website operators, we cannot guarantee the security of any data transmitted through the internet.
When we no longer need your personal information to provide the Services, it will be securely deleted or de-identified in a manner that ensures you cannot be re-identified. Where we are collecting or storing your personal information on behalf of our Customer, the retention of your personal information may be subject to our contractual obligations to our Customer.
Changes and Updates to this Notice
We reserve the right, in our sole discretion, to modify, update, add to, discontinue, remove or otherwise change any portion of this Notice, in whole or in part, at any time. When we amend this Notice, we will revise the “last updated” date located at the top of the document. We will also take reasonable steps to ensure you are made aware of any material updates including providing you direct communication about such changes or providing a notification through the Services, as appropriate. If you provide personal information to us or access or use our Sites and Apps after this Notice has been changed, you will be deemed to have unconditionally consented and agreed to such changes. The most current version of this Notice will be available on the Sites and Apps and will supersede all previous versions of this Notice.
Choice of Law
Except where prohibited by law, this Notice, including all revisions and amendments thereto, is governed by the internal laws of the United States, State of Georgia, without regard to its conflict or choice of law principles which would require application of the laws of another jurisdiction.
Except where prohibited by law, by using the Sites or Apps in any way, you unconditionally consent and agree that: (1) any claim, dispute, or controversy (whether in contract, tort, or otherwise) you may have against NEXTEP and/or its parent, subsidiaries, affiliates and each of their respective members, officers, directors and employees (all such individuals and entities collectively referred to herein as the "NEXTEP Entities") arising out of, relating to, or connected in any way with the Sites or Apps or the determination of the scope or applicability of this agreement to arbitrate, will be resolved exclusively by final and binding arbitration administered by JAMS and conducted before a sole arbitrator in accordance with the rules of JAMS; (2) this arbitration agreement is made pursuant to a transaction involving interstate commerce, and shall be governed by the Federal Arbitration Act ("FAA"), 9 U.S.C. §§ 1-16; (3) the arbitration shall be held in Atlanta, Georgia; (4) the arbitrator’s decision shall be controlled by the terms and conditions of this Notice and any of the other agreements referenced herein that the applicable user may have entered into in connection with the Site; (5) the arbitrator shall apply Georgia law consistent with the FAA and applicable statutes of limitations, and shall honor claims of privilege recognized at law; (6) there shall be no authority for any claims to be arbitrated on a class or representative basis, arbitration can decide only your and/or the applicable NEXTEP Entity’s individual claims; the arbitrator may not consolidate or join the claims of other persons or parties who may be similarly situated; (7) the arbitrator shall not have the power to award punitive damages against you or any NEXTEP Entity; (8) in the event that the administrative fees and deposits that must be paid to initiate arbitration against any NEXTEP Entity exceed $125 USD, and you are unable (or not required under the rules of JAMS) to pay any fees and deposits that exceed this amount, NEXTEP agrees to pay them and/or forward them on your behalf, subject to ultimate allocation by the arbitrator. In addition, if you are able to demonstrate that the costs of arbitration will be prohibitive as compared to the costs of litigation, NEXTEP will pay as much of your filing and hearing fees in connection with the arbitration as the arbitrator deems necessary to prevent the arbitration from being cost-prohibitive; and (9) with the exception of subpart (6) above, if any part of this arbitration provision is deemed to be invalid, unenforceable or illegal, or otherwise conflicts with the rules of JAMS, then the balance of this arbitration provision shall remain in effect and shall be construed in accordance with its terms as if the invalid, unenforceable, illegal or conflicting provision were not contained herein. If, however, subpart (6) is found to be invalid, unenforceable or illegal, then the entirety of this Arbitration Provision shall be null and void, and neither you nor NEXTEP shall be entitled to arbitrate their dispute. For more information on JAMS and/or the rules of JAMS, visit their website at https://www.jamsadr.com/.
If you are an End User who has a relationship with one of our Customers and have a question about how your personal information is collected, used, or shared, or would like to exercise any rights you may have with respect to your personal information, please contact the Customer directly.
For other questions about this Notice, or if you are a Customer and want to exercise your rights as described in this Notice, you can submit a request by completing this form or may contact us as follows:
NEXTEP Systems, Inc.
3310 W. Big Beaver Road, Suite 200
Troy, MI 48084
In order to honor any access or deletion request, we will require you to provide enough information for us to verify your identity. For example, we may ask you for information associated with your account, including your contact information or other identifying information. If you designate an authorized agent to make a rights request on your behalf, we may require proper proof of that authorization as well as direct verification of your identity from you.