This Privacy Notice was last updated on July 29th, 2022.
FOR CALIFORNIA CONSUMER PRIVACY ACT PLEASE VISIT HERE.
Welcome to Beanworks Solutions Inc. (“Beanworks”). Beanworks provides accounts payable management solutions for businesses (“Clients”) including enabling payment remittance communications between Clients and their vendors (“Services”).
This Privacy Notice explains what data we collect when you use the Beanworks website www.Beanworks.com (including all subdomains, the “Site”) and/or the Services and in connection with our sales and marketing activities, why we collect the data, how it is used and your rights and choices.
While providing our Services, we may collect information related to our Clients’ customers on behalf of our Clients. Our use of information collected through the Services under the direction of our Clients (acting as a data controller according to GDPR) is limited to the purpose of providing the Services and is governed by our contract with the applicable Client and the Client’s own privacy policies. We are not responsible for the privacy policies or privacy practices of Clients or other third parties.
Each time you access, use, place an order on, or browse this Website, you signify that you understand the then-current Privacy Notice. Beanworks is committed to meeting applicable data privacy regulations and more specifically; European Union (EU) General Data Protection Regulation (GDPR) requirements, and the California Consumer Protection Act (CCPA or CaCPA).
1. Information we collect
When you interact with the Site or the Services, we may collect information that alone or in combination with other information could be used to identify you (“Personal Data”), as described below:
Personal Data That You Provide To Us. While the type of data that we collect depends on the processing we intend to conduct, typically we collect your name, email address, phone number, and the name of your employer. We collect this information:
- When you enter it directly on our Site or send to us electronically, for example when you complete a web form to give your Personal Data to us directly (such as on our “Contact Us” page), when you request information, including a product demo, register for a webinar or other event, or subscribe to our blog. when you attend one of our events, during phone calls with sales representatives;
- When you interact with us on social media;
- When you contact us via alternative channels, for example by telephone, fax, SMS, email or mail.
We also collect your personal data when you:
- Contact customer support;
- Place an order to purchase our Services;
- Use our Services, including actions and the times they were performed;
- Apply for employment through the Site.
- When you apply for employment through the Site, our provider of recruiting services will collect your resume and any additional information that you elect to provide to us, including but not limited to employment history, resumes, career path, job applications, contact data and education certificates, letters of recommendation, criminal record extracts.
Service Data. In providing our services, our Clients may upload personal data which they have collected from their vendors, for example names (including business names), addresses, email addresses and telephone numbers of employees which is provided on invoices they receive from their vendors. We refer to this data as “Service Data”.
Enhanced Data: We may enhance the information that we collect from you using information from third parties that are permitted to share that information, such as the industry that the company you work for operates in. We do this to provide more personalised marketing to you and operate within the scope of relevant laws.
Data that you provide to us about others: If you disclose to us any personal data of other parties, it is your responsibility to ensure that you comply with any notification and consent obligations required under applicable law related to such disclosure. Depending on your local laws and regulations, you may be required to ensure that you have explained to them how we will process their personal data, for example by providing them with this Privacy Notice, and that you have received the individuals consent, or otherwise have the legal basis to provide their personal data to us for processing.
Children: Neither the Site nor the Services are directed to or intended to be used by children who are under the age of 16 and Beanworks does not knowingly collect Personal Data from children under 16. If you have reason to believe that a child under the age of 16 has provided Personal Data to Beanworks through the Site, please contact us using one of the options provided in the “Contact Us” section at the bottom of this Notice we will endeavor to delete that information from our databases.
2. How we use personal data and other information
- To provide the Services to you and respond to your requests. When you ask for information about the Services (for example, when you request a demo or ask us to send you offers or price information), or register to a webinar or an event, we will use your contact information to respond to your request. For EU data subjects, such use is necessary to respond to or implement your request.
- We use account-related data provided by Clients in connection with the purchase, sign-up, use or support of the Client account (such as usernames, email address and billing information) to provide you with access to the Services and/or the Site, contact you regarding your use of the Services and/or the Site or to notify you of important changes to the Services and/or the Site. For EU data subjects, such use is necessary for the performance of the contract between you and us.
- We process Service Data on behalf of our Clients for the purpose of providing the Services to Clients in accordance with the applicable Client’s contract. Beanworks’ purpose in collecting this information is simply to enable our Clients to manage and pay amounts owed to them by their vendors.
- For marketing purposes. We will use your email or mail address to send you information (as applicable) by email and post about new products and services, upcoming events or other promotions. You may opt-out of receiving such emails by following the instructions contained in each promotional email we send you. Our sales representatives may also use your phone number to contact you directly by phone, in connection with such new products and services, upcoming events or other promotions.
- Where required by applicable law (for example, if you are an EU data subject), we will only send you marketing information by email or mail, or contact you by phone, if you consent to us doing so at the time you provide us with your Personal Data. When you provide us with your consent to be contacted for marketing purposes, you have the right to withdraw your consent at any time by following the instructions to “opt-out” of receiving marketing communication in each marketing email we send you. In addition, if at any time you do not wish to receive future marketing communications or wish to have your name deleted from our mailing or calling lists, please contact us using of the contact options provided in the ”Contact Us” section at the end of this Notice. Please note that if you opt out from marketing communications, we may still contact you regarding issues related to our Services and to respond to your requests.
- To process job applications. When you apply for employment through our Site we will use your contact details and data about your employment history and education to (i) conduct job interviews, evaluate your application, and as is otherwise needed for recruitment (for EU data subjects, this use is necessary to respond to your request to process your application for employment); (ii) communicate with you and inform you of current and future career opportunities (unless you tell us that you do not want us to keep your details for that purpose) and manage and improve our recruiting and hiring processes pursuant to our legitimate interest in doing so; (iii) conduct reference and background checks were required or permitted by applicable local law, pursuant to our legitimate interest in doing so or as required by the law; and (iv) for compliance with corporate governance, legal and regulatory requirements. If you are hired, your personal data will be used as part of your employee record under our employee privacy policies.
3. Sharing information
Sharing of your Personal Information within Beanworks
Beanworks employees and those from different entities in Quadient are authorized to access Personal Information only to the extent necessary to perform their job functions. This includes activities like servicing a customer agreement or activities related to providing customer support.
Sharing of your Personal Information outside Beanworks
We share information with certain third parties, as follows:
- Third Party Service Providers. Third parties who provide services to us have access to your Personal Data: companies who perform automated and manual data extraction and verification of data extracted from invoices that you provide to us, website analytics companies, hosting and cloud computing service providers, providers of CRM, marketing and sales software solutions. Pursuant to our instructions, these parties may access, process or store Personal Data in the course of performing their duties to us and solely in order to perform the services we have hired them to provide.
- Administrative and Legal Reasons. We may disclose Personal Data when required to do so by law, such as to comply with a subpoena, bankruptcy proceedings, or similar legal process, or in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, or when we believe in good faith that disclosure is reasonably necessary to protect the property or rights of Beanworks, third parties, or the public at large.
- Business Transfers. We may disclose and transfer your information and data: (a) if we assign our rights regarding any of the information to a third party or (b) in connection with a corporate merger, consolidation, restructuring, sale of certain of our ownership interests, assets, or both, or other corporate change, including without limitation, during the course of any due diligence process.
- Beanworks will never sell or rent your data to other organizations for marketing purposes.
4. What is our basis for processing your personal data?
For personal information collected about you in the EU, our basis for processing is most commonly as follows:
Beanworks collects, uses, stores and otherwise processes personal data where necessary to provide a service which you request, where necessary to comply with a legal obligation, and where necessary pursuant to Beanworks’ legitimate interests and where these interests are not overridden by your data protection rights.
For example, we have a legitimate interest in processing your Personal Data to analyze how the Site and our products and services are being used by you, and to ensure network and information security, as described in this Privacy Notice. When we process your Personal Data for our legitimate interests, we make sure to consider and balance any potential impact on you and your rights under data protection laws. Our legitimate interests do not automatically override your interests. We will not use your Personal Data for activities where our interests are overridden by the impact on you unless we have your consent or those activities are otherwise required or permitted to by law. You have the right to object to processing that is based on our legitimate interests.
Beanworks may also process your personal data where you have given consent or provided your “opt-in”. For example, when you fill in an online form or request more information about Beanworks products or services, you consent to Beanworks using your personal data as requested. Where Beanworks asks for consent, you are free to withhold or revoke it.
Beanworks’ products and services mainly address companies and businesses. Non-commercial prospects may also have an interest in Beanworks’ products and services. In many instances where personal information is collected, Beanworks can rely on a legitimate interest to send marketing communications. However, Beanworks will ensure that your contact data will be used for marketing purposes if you have provided your consent. Therefore, Beanworks will always ask for approval and consent, when collecting personal information. Your personal information is utilized in the Quadient group of .
5. Your rights:
EU and UK DATA SUBJECTS
Scope: This section applies solely to EU and UK data subjects (for these purposes, reference to the EU also includes the European Economic Area countries of Iceland, Liechtenstein and Norway).
Subject to applicable law, you have the following rights in relation to your Personal Data:
Right of access
If you ask us, we will confirm whether we are processing your Personal Data and, if so, provide you with a copy of that Personal Data along with certain other details. If you require additional copies, we may need to charge a reasonable fee.
Right to rectification
If your Personal Data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your Personal Data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
Right to erasure
You may ask us to delete or remove your Personal Data, such as where you withdraw your consent. If we shared your data with others, we will tell them about the erasure where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
Right to restrict processing
You may ask us to restrict or ‘block’ the processing of your Personal Data in certain circumstances, such as where you contest the accuracy of the data or object to us processing it. We will tell you before we lift any restriction on processing. If we shared your Personal Data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
Right to data portability
Effective 25 May 2018, you have the right to obtain your Personal Data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you. We will give you your Personal Data in a structured, commonly used and machine-readable format. You may reuse it elsewhere.
Right to object
You may ask us at any time to stop processing your Personal Data, and we will do so:
- If we are relying on a legitimate interest to process your Personal Data — unless we demonstrate compelling legitimate grounds for the processing or
- If we are processing your Personal Data for direct marketing.
Rights in relation to automated decision-making and profiling
You have the right to be free from decisions based solely on automated processing of your Personal Data, including profiling, that affect you, unless such profiling is necessary for entering into, or the performance of, a contract between you and us or you provide your explicit consent.
Right to withdraw consent
If we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing of your data before we received notice that you wished to unsubscribe.
Right to Lodge a Complaint
In the event you consider Our processing of your personal information not to be compliant with the applicable data protection laws, you can lodge a complaint:
- Directly with Beanworks by using this form
- With the competent data protection authority. The name and contact details of the Data Protection Authorities in the European Union can be found here.
You may exercise your rights by contacting us as indicated under the “Contact Us” section below.
CALIFORNIA DATA SUBJECTS
Scope: This section applies solely to data subjects residing in the State of California.
Subject to applicable law, you have the following rights in relation to your Personal Data:
Right to Access
If you are a California resident, You have the right to request the disclosure of certain information about Our collection and/or use of Your personal information over the past 12 months. You may submit a CCPA access request using one of the methods provided in the “Contact Us” section below.
Right to Opt-Out
You have the right to opt-out of the sale of Your personal information by companies you do business with. We do not sell your personal information, and as such, We have not included a “Do Not Sell My Personal Information” link on Our website.
Right to Request Deletion
You have the right to request that We delete any of Your personal information that We collected from You and retained, subject to certain exceptions. You may submit a CCPA deletion request using one of the methods provided in the “Contact Us” section below. Once We receive and confirm Your verifiable consumer request, We will delete (and direct Our service providers to delete) Your personal information from Our records, unless an exception applies.
6. Transfer of data abroad
Our North American data centers are located in Canada, and our European data centers are located in Ireland. Data for North American customers and European customers are stored in their respective continent.
Beanworks is a company part of Quadient with operations in 29 countries and personal information is processed globally. In order to provide our services and fulfil our contractual obligations, it is necessary that we transfer your data to countries where there may be less stringent laws and regulations to protect personal data. This typically occurs when we use Third Party Service Providers based outside of Canada or the European Economic Area (EEA). The processing of this data is subject to special rules under data protection regulations.
In these cases, we will ensure that the data processing is compliant with data protection regulations and personal data is handled in a securely. We verify the security of these transfers with additional scrutiny. Beanworks will ensure that such transfers are subject to the terms of the EU Model Clauses, such as using “Standard Contractual Clauses”, which have been provided and approved by the European Commission as well as relevant UK bodies, as well as Data Processing Addendums which are additional protections on our contracts with our Third Party Service Providers.
7. Data security
We take reasonable administrative and technical steps to protect the Personal Data provided via the Site from loss, misuse and unauthorized access, disclosure, alteration, or destruction. These include contractual restrictions and physical, electronic and administrative safeguards such as firewalls, data encryption, SSL and other up-to-date technologies. However, the Internet cannot be guaranteed to be fully secure and we cannot ensure or warrant the security of any information you provide to us. Please keep this in mind when providing us with your Personal Data.
8. Retention of your data
We will keep your Personal Data only for as long as is reasonably necessary for the purposes outlined in this Privacy Notice, or for the duration required by law, whichever is the longer.
If you wish to request that We no longer use your registration information to provide you services, contact us using one of the options provided in the “Contact Us” section of this Notice.
9. Do not track disclosures
Beanworks does currently respond to “Do Not Track” signals sent by your browser or mobile application and operate as described in this Privacy Notice whether or not a “Do Not Track” signal is received. If we change our practices in the future and begin to respond to “Do Not Track” signals, we will update this Privacy Notice accordingly.
10. Publicly posted information
This Privacy Notice shall not apply to any information you post to the public areas of the Site. This includes, but is not limited to comments to the Beanworks blog or public forums. Comments posted to public areas may be viewed, accessed, and used by third parties subject to those parties’ privacy practices and policies.
11. Links to other websites
The Site may contain links to other websites not operated or controlled by us (“Third Party Sites”), including social media websites and services. The information that you share with Third Party Sites will be governed by the specific privacy policies and terms of service of the Third Party Sites and not by this Privacy Notice. By providing these links we do not imply that we endorse or have reviewed these sites. Please contact those sites directly for information on their privacy practices and policies.
12. Communications preferences and opt-out
As a result of providing your contact information, Beanworks may market to you, including sending promotional communications and relevant offers. To opt-out of receiving marketing-related communications from Beanworks, please click on the “unsubscribe” link in the communication. Please note that if you do unsubscribe from receiving marketing-related emails from us, we may still use your email address to send you important administrative messages. If you wish for us to completely delete your personal record from our database, please contact us using one of the options provided in the “Contact Us” section of this Notice and we will delete your contact information.
13. Changes to this privacy notice
We may change this Privacy Notice from time to time, and we will post the revised Notice and provide notice on the Site.
14. Contact us
If you have a question related to this Privacy Statement, please contact Us by using this access request form. Your message will be forwarded to the appropriate member of Quadient’s Data Privacy Team, such as Data Protection Officers or members of their teams.
If you would like to access Personal Data we hold about you or exercise your other rights under the applicable law, please submit a verifiable access request to Us by either:
- using the access request form
- emailing us at firstname.lastname@example.org, or
- calling us at +1-800-636-7678
In Your request, You need to provide enough information that allows Us to reasonably verify that You are the consumer that We collected information about.