TOWER SOFTWARE LABS INC.
PRIVACY POLICY
Effective March 28, 2025. This Privacy Policy may be modified to be kept up to date
This website (“Website”) is operated by Tower Software Labs Inc. (“Tower”). The terms “Tower,” “we,” “us,” “our” and “ours” when used in this privacy policy (“Privacy Policy”) includes subsidiaries, divisions, branches, affiliates, or companies under common control of Tower, unless such entity maintains its own privacy policy. The terms “you,” “your” and “yours” when used in this Privacy Policy means any user of this Website or Online Services (defined below).
IMPORTANT: BY SUBMITTING PERSONAL DATA TO US AND/OR BY USING OUR WEBSITE OR ONLINE SERVICES, YOU AGREE THAT ALL PERSONAL DATA THAT YOU SUBMIT MAY BE PROCESSED BY US IN THE MANNER AND FOR THE PURPOSES DESCRIBED BELOW.
Scope of Privacy Policy
This Privacy Policy describes our current policies and practices with regard to personal data collected by us from you directly and/or through the Website or Online Services (as defined below). The term “personal data” refers to information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your device. This Privacy Policy applies only to operation of Websites and Online Services that directly link to this policy when you click on the Privacy Policy link. We adopt this Privacy Policy to comply with applicable law. Nothing in the Privacy Policy shall be interpreted or construed to limit, undermine, curtail other rights granted to you by applicable law. We may provide separate privacy notices that apply to specific products or services that we offer; in which case this Privacy Policy does not apply.
Online Services
We provide online services and service facilitation tools such as: Tower Data Room and such other online tools introduced by us from time to time (“Online Services”). These Online Services are part of a business relationship. If you have been invited to an Online Service, you have been so by a Tower client or client advisor. By accepting the invitation to the Online Service, you are agreeing to the use of your contact details in accordance with this Privacy Policy. If you request access to an Online Service, you are agreeing to the use of your personal data in accordance with this Privacy Policy.
Collection, Use and Disclosure of your Personal Data
1. Tower as a Service Provider or Processor
Some of Tower’s services require Tower to process data that has been uploaded, stored, and shared via Tower’s clients. Tower does not review or analyze the content of the data. However, it may contain personal data which Tower processes pursuant to its clients’ instructions. Tower does not control such data; rather it handles this type of data as a data processor only. Tower processes such data as governed by written agreements in place with its clients and to the extent necessary to comply with applicable laws. As a result, Tower’s clients are responsible for obtaining and providing all appropriate notifications and consents when they collect personal data. Personal data that is transferred to Tower by its clients to be processed shall be deemed to have been collected with appropriate notifications and consents. Tower assumes no responsibility for obtaining or validating that appropriate consent has been obtained or notifications provided with respect to data provided by its client(s).
2. Tower as a Business or Controller
When you provide information through the Website or Online Services, are a supplier or service provider, provide contact information with one of our sales representative, communicate with us by phone, or partner constituents, apply for employment, or have included your personal data in an event registration form, certification, survey or questionnaire, we may request and obtain personal data about you such as your name, employer’s address, work e-mail, job title, voice, work telephone number, other other information you choose to share.
Further, with regard to Online Services, the client who is using the Online Services may add you as a user and provide certain personal data, such as your work email. We will use the work email to provide you a user ID and account activation email to access the Online Services and create a user profile for the uses as described below. When you first sign onto the Online Service, you will be presented with a requirement to set up a “profile,” which will require you to provide you name, job role, company name, and work phone number. You will be able to update or correct any of the personal data in your profile.
If you provide us with any personal data relating to other individuals, you represent that you have the authority to do so, and where required, have obtained the necessary consent, and acknowledge that it may be used in accordance with this Privacy Policy.
Information collected by automated means
We may also use technology to collect information indirectly about the use of our Website or Online Services that may reveal your identity. For example, if you are already identified as a user in our database, our Web server automatically logs interactions with our HTML-enabled emails, Website, Online Services, or advertisements, including IP addresses, device type, regional location, and which Web browsers our visitors use. Our HTML-enabled emails and Website contains hyperlinks to other pages on our Website. We may use technology to track how often these emails are accessed, links are used and which pages on our Website our visitors choose to view. In addition with regard to our Online Services, we will also will maintain a history of your access, and certain actions taken by you while accessing the Online Services (e.g. access to projects and documents, including time, date and length of access) will include maintaining a log of users’ IP addresses, the websites from which users access the Online Service, the type of web browsers used to access the Online Service and the browser’s settings that may affect Online Service performance. This type of information may also be collected when you read our HTML-enabled emails.
Data we receive from third parties
From time to time, we may obtain information about you from third-party sources, such as public databases and websites, resellers and distributors, joint marketing or business partners, security and fraud detection firms and social media platforms. Examples of the information we may receive from other sources include contact information from business partners with whom we operate co-branded events, services, and marketing campaigns.
Sensitive Personal Data
We do not collect sensitive personal data. Unless we specifically make a request and it is relevant to the services that we provide, we ask that you do not provide us with any sensitive personal data (meaning information revealing racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, genetic, health, or biometric information, information about sex life or sexual orientation, or criminal convictions or offenses) through our websites or mobile applications, or otherwise to us.
Links to other Websites
This Website may contain hyperlinks to websites that are not operated by us. These hyperlinks are provided for your reference and convenience only and do not imply any endorsement of the activities of these third-party Websites or any association with their operators. We do not control these websites and are not responsible for their operation, data, or privacy practices. We urge you to review any privacy notice posted on any site you visit before using the site or providing any personal data about yourself.
Use of Personal Data
We may share your personal data with other companies within our group of companies in order to use your personal data under these limited circumstances:
Use of Personal Data | Legal Basis |
To provide you with requested information on products or services | For the performance of our contract with you or to take steps at your request before entering into a contract |
To provide and to facilitate the delivery of products and services you request | For the performance of our contract with you or to take steps at your request before entering into a contract |
To provide customer service and support | For the performance of our contract with you |
To send you related information, including confirmations, invoices, technical notices, updates, security alerts, training and support and administrative messages | For the performance of our contract with you |
To create, maintain, transition, customize, and secure your account with us | For the performance of our contract with you or to take steps at your request before entering into a contract |
For direct marketing purposes | For our legitimate interests, i.e., to promote our business, products, and services to existing and former customers; and consent where applicable |
To operate, audit and improve the Website or Online Services | For the performance of our contract with you; and For our legitimate interests, i.e. · to understand how Online Service or Website is accessed, and how it is used, · to determine if there are any potential security issues arising from such use, · to make sure we are following our own internal procedures so we can deliver the best service to you, · to understand customer/potential customer feedback and in responding to your communications in a consistent way, · for other quality control and training purposes, · to understand impact of any marketing offers that we make, and · to maintain our accreditations so we can demonstrate we operate at the highest standards |
To conduct research and development | For our legitimate interests, i.e. · to be as efficient as we can so we can deliver the best service for you at the best price, · to develop, improve, support, service and maintain our products and services, · to develop new services and to improve or personalise existing services, and · to understand market and usage trend |
To perform customer surveys; Create anonymous data
| For our legitimate interests, i.e. · collecting and assessing feedback, · identifying usage and market trends, · determining the effectiveness of our marketing campaigns, and · to evaluate and improve our products, services; · marketing and customer relationships; We may create anonymous data from your personal data and other individuals whose data we collect and make sure that we exclude data that personally identifies you and only use the data for our legitimate interests For our legitimate interests, i.e., to develop new services and to improve or personalise existing services |
To understand you and your preferences when using our Website or Online Services | For our legitimate interests, i.e., to develop new services and to improve or personalise existing services; |
To disclose the information in our databases and server logs to comply with a legal requirement | For the administration of justice, for the purposes of national security only to the extent that is strictly necessary and proportionate, to interact with anti-fraud databases, to protect your vital interests, to protect the security or integrity of our databases or this Website and Online Services, to take precautions against legal liability |
Link or combine it with other personal information we get from third parties | For our legitimate interests, i.e. · to minimize fraud that could be damaging for us and for you, · to promote our business, products, and services to existing and former customers, · to be as efficient as we can so we can deliver the best service for you at the best price, and · to help understand your needs, provide you with better service |
If you submit your resume or CV, we will use the information to process your inquiry and to monitor recruitment statistics | For our legitimate interests, i.e. · Job candidate processing, · to provide more information about employment opportunities, or · to take steps at your request before entering into employment with us |
In the event of a corporate sale, merger, reorganization, dissolution or similar event, your personal data may be part of an asset transfer or sale | For our legitimate interests, i.e., corporate development |
Preparing internal and financial reports, and business modeling | Our legitimate interest, i.e., in the management of our business operations and reporting obligations |
Where we rely on our legitimate interest, we will balance that against our applicable legal obligations to you. Tower will not collect additional categories of personal data or use the personal data we collected for materially different, unrelated, or incompatible purposes without providing you notice.
If we request your consent to use your personal data, you have the right to withdraw your consent any time in the manner indicated when we requested the consent or by contacting us. If you have consented to receive marketing communications from our third-party partners, you may withdraw your consent by contacting those partners directly.
Sharing of Personal Data
Tower may disclose your personal data to various third-party service providers for the following business purposes:
· To support our information technology;
· For customer service and account management;
· To supplement, update, or correct the data or provide additional publicly available data;
· To manage mailings on our behalf;
· To aggregate data collected through our Online Services and Website;
· To perform back-end services related to our Online Services;
· To perform customer surveys and call recording;
· To assist with direct marketing efforts;
· To personalize your Website or Online Service experience;
· To facilitate marketing events and customer surveys;
· Where necessary in the course of the professional services that professional advisors such as lawyers, bankers, auditors, and insurers provide to us;
· To prevent fraud, money laundering, undertake credit checks, comply with laws and check with identity verification agencies;
· To process an order, issue invoices, take payment from, make payment to your organization, or manage account or payment history; and
· In the event of a corporate sale, merger, reorganization, dissolution or similar event, your personal data may be part of an asset transfer or sale.
We may transfer your personal data to any third party who is not otherwise covered by the categories listed above where you have given us permission to do so, or with whom you have entered into a contract when we need to transfer your personal data to that party in order to fulfil that contract.
When we disclose your personal data for a business purpose, we enter a contract that requires that all third-party processors process your personal data with the same level of protection and in a manner consistent with the uses agreed upon in this Privacy Policy.
Tower does not sell your personal data.
Retention
Tower retains personal data we collect from you where we have an ongoing legitimate interest to do so. When personal data is no longer necessary or relevant for the stated purpose or to fulfill a legal or business requirement, it shall be securely destroyed. Tower will either physically or electronically erase the personal data. When processing in our role as a processor, we will retain personal data for as long as our customer instructs us to and/or as required by applicable law.
Data Security
We will maintain, monitor, and enforce reasonable organizational, administrative, technical, and physical safeguards to protect the security and confidentiality of your personal data from loss, misuse, unauthorized access or disclosure. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instruction, and they are subject to a duty of confidentiality.
Your Rights
Tower will make reasonable efforts to keep personal data accurate, complete, and up to date as is necessary to fulfill the purposes for which the information is to be used.
Depending on the territorial jurisdiction in which you are a resident of, in certain circumstances you may have certain rights regarding your personal data including:
· right to withdraw consent in cases where consent is relied upon;
· right to obtain access to or a copy of, correct and erase of your personal data;
· right to lodge a complaint;
· right to object to any automated processing of personal data;
· right to restrict, or object to, how we use your personal data;
· right to move or provide some of your personal data to other companies;
· right to ask us to stop using your personal data;
· right to ask why we are using your personal data, what personal data we are using, with whom we are sharing, the period for which it is retained, the source of the personal data where it was not provided by you, and the transfers of the personal data to countries outside the EAA, Switzerland and the United Kingdom.
In certain circumstances we may not be able to do this or may not be required to do this. If you would like to exercise, or discuss, any of these rights, please see below (“Exercising Rights”)
Automated decision making
You have the right not to be subject to automated decision making (e.g., profiling) that significantly affects you. The exercise of this right is not available to you in the following cases:
· The automated decision is required to enter into, or perform, a contract with you;
· We have your explicit consent to make such a decision;
· The automated decision is authorised by local law of an EU member state.
Unless the automated decision is authorized by local or EU law, you still have the right to obtain human intervention in respect of the decision, to express your point of view and to contest the decision.
Please note that Automated Decision-Making currently does not take place on our Website or in our Online Services.
Exercising Rights
To exercise your data quality, access, choice, and corrections rights described above, please submit a verifiable request to our Office of the General Counsel by submitting a request to support@withtower.com Only you may make a request related to your personal data. We endeavor to respond to a verifiable request within any legally required time limit or otherwise within thirty (30) days of its receipt, which thirty (30) day period may be extended with written notification, and deliver our response (or reasons we cannot comply with a request) via electronic mail. We will not discriminate against you for exercising any of your rights. We may make a charge, if excessive, repetitive, or manifestly unfounded.
If you no longer wish to receive electronic mail, you can email us at support@withtower.com with the word “unsubscribe” in the subject line or simply respond to the pertinent E-mail with the word “unsubscribe” in the subject line. (Please note: “Unsubscribe” is an automatic process. We will not respond to these messages.) Additionally, you can call us at (855) 608 9027, or by mail at Tower Software Labs Inc., First Canadian Place, 100 King St W #6200, Toronto, ON M5X 1B8. Please allow up to one (1) week for your opt-out request to be processed.