<em>Last updated: July 22, 2020</em>
("IMI", "we" or "us") regarding our collection, use, and disclosure of information (including Personal Information, defined below) through our website at www.hcaptcha.com and www.botstop.com (the "Sites") and the hCaptcha application program interface and related software and materials (collectively, the "Service").</p>
<p>Not Applicable to Third Party Websites.
<p>A Note to Customers Outside the United States.
IMI is based in the United States.
The Sites and Service are controlled and operated by us from the United States.
Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Sites and Service you consent to the transfer of information to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country.
In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.<br>
<br>A Note to California Residents.
Please see our "Notice to California Residents" section related to your rights under the California Consumer Privacy Act ("CCPA").<br>
<br>A Note to European Economic Area Residents.
Please see our "Notice to EU Data Subjects" section related to your rights under the General Data Protection Regulation ("GDPR") and our "EU-US Privacy Shield and Swiss-U.S.
Privacy Shield" section related to IMI's Privacy Shield certification.
Note that IMI is the controller of your personal information, except where we process personal information on behalf of our Integrators in connection with the provision of our Service, in which case we are the processor of personal information, and those Integrators are the controllers of the personal information.
<br>If you have any questions or concerns about how such data is handled or would like to exercise your rights, you should contact the person or entity (i.e., the data controller) who has contracted with us to use the Service to process this data.
We will, however, provide assistance to our Integrators to address any concerns you may have, in accordance with the terms of our contract with them.<br>
<br>A Note to Residents of Switzerland.
Please see our "EU-US Privacy Shield and Swiss-U.S.
Privacy Shield" section related to IMI's Privacy Shield certification.<br>
</p>Information We Collect<br>
<p>We collect information from individuals who interact with our Sites and Services, including those who incorporate our Service into their website ("Integrators"), those who utilize our services for data labeling ("Customers"), and the end users who interact with the our Service through the websites of our Integrators ("End-Users").<br>
<p>We collect the following categories of information:<br>
<li>Information that can be used to identify or contact an individual ("Personal Information"), such as name, email address, and country.
We collect Personal Information from our current and prospective Integrators and Customers when they give it directly to us (for example, by filling in a form when signing up for an account, or applying to receive email notifications from us).
We may also verify the identity of our Integrators and Customers by comparing personal information against third party databases or official legal documents.<br>
<li>Information collected automatically as a result of an Integrator’s or Customer’s use of the our Sites or the Services ("Analytics Information"), such as IP addresses, browser type, Internet service provider, platform type, device type, operating system, date and time stamp of access, and other similar information.
Some Analytics Information is collected on our behalf by third parties we engage for that purpose, and some Analytics Information is collected through a variety of tracking technologies, including cookies (see "Third Party Analytics and Tracking Technologies" below).<br>
<li>Information collected as a result of End-Users answering prompts through the Service ("Labeled Data"), such as image labeling data, text converted from audio files played to those End-Users, answers to questions, and other prompts generated by the Service for purposes of labeling data for use in machine learning applications.
Note that Labeled Data is not tied to any identified individual.</li>
<li>Other information collected from End-Users as part of the Service to that is required to determine whether they<br>are human, such as mouse movements, scroll position, keypress events, touch events, and gyroscope / accelerometer information as applicable.</li>
<li>We may collect additional information from End-Users who wish to work with us as Individual Data Labelers.</li>
</ul>How We Use Information<br>
<p>We use the information we collect for the following purposes:<br>
<li>To administer Integrator and Customer accounts and provide the Service.
We use Personal Information in order to associate specific accounts with Integrators and Customers and to provide them the Service, to respond to requests or inquiries, to provide support or technical assistance, and to facilitate payments.<br>
<li>To improve to Site and the Service.
We use Analytics Information to improve our existing and develop new services and offerings and to customize existing and future product offerings.</li>
<li>To derive market insights.
We use Analytics Information to analyze the market and conduct business analyses related to the Site and our Services, and for other research purposes.</li>
<li>To provide a market for Labeled Data.
Our Service enables high volume data labeling and human review for machine learning systems as a service to website owners and companies who need help getting their data labeled.
To that end, we disclose Labeled Data to our Customers interested in acquiring Labeled Data.<br>
<li>To secure our services and systems.
We use Analytics Information to secure our systems by identifying potential threats and vulnerabilities, and to otherwise protect the information we collect.</li>
<li>For any legitimate business purpose, provided that the information is de-identified or aggregated such that it cannot be reasonably tied to an individual..<br>
</ul>How We Share Information<br>
<p>We share or disclose personal information in the following cases:<br>
<li>Upon direct request from an Integrator to identify the fraud risk of a specific CAPTCHA challenge request or IP address, or otherwise where specific consent was given.<br>
<li>With vendors we engage to provide essential aspects of the Sites and the Service, such as data storage, hosting, and Analytics, and only for those purposes.</li>
<li>As necessary to comply with applicable law, including governmental requests, law enforcement requests, and otherwise to public and private entities in order to protect the rights, privacy, safety, or property of you, us, or others.</li>
<li>With others for any legitimate business purpose, provided the information is de-identified<br>or aggregated such that it cannot be reasonably tied to an individual.<br>
</ul>Third Party Analytics and Tracking Technologies<br>
In some instance, we work with third party vendors to employ cookies for the purposes of collecting Analytics Information.<br>
<p>We use Sentry to collect debugging data when a user experiences an error.
For information on how Sentry collects and processes data, please click here.<br>
<p>We use Cloudflare to optimize our web traffic.
For information on how Cloudflare collects and processes data, please click here.<br>
Please note that doing so may negatively impact your experience using the Sites or Service, as some features may not work properly.<br>
</p>How We Secure Information<br>
<p>We implement appropriate technical and organizational measures to protect the information we collect and store, and require all agents who carry out our processing on our behalf to do the same.
Unfortunately, no security measures are 100% foolproof, and as such no network or system (including ours) can be guaranteed to be 100% secure against destruction, loss, alteration, unauthorized disclosure of, or access to information we collect and store.
If you believe your information may not be secure for any reason, please contact us immediately at email@example.com.<br>
<p>To the fullest extent permitted by law, the Site and the Service (and any other associated services, information, data, features, and other content or materials) are provided on an “as-is” and “as-available” basis.
To the fullest extent permitted by law, IMI excludes all warranties, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, and non-infringement.<br>
</p>Managing Your Information (Your Rights)<br>
<p>You may access, correct, amend, or delete certain Personal Information you may have provided us through your Integrator, Customer, or Accessibility User account (if you are an Integrator, Customer, or Accessibility User).
If you are unable to do so, or have any questions about Personal Information we have collected and/or shared about you, or would like to withdraw your consent for our processing (i.e.
entirely delete your account) please contact us at firstname.lastname@example.org.<br>
<p>If you would prefer to block cookies or other tracking technologies, most browsers and mobile devices all you to change your settings so as to notify you when you receive cookies or other tracking technologies are being used, and to choose whether or not to accept/allow it.
Most browsers also allow you to disable or delete existing cookies or to automatically reject future cookies.
You may also use third party tools, including browser plug-ins, to control your cookie preferences.
Note, however, that if you disable all cookies, some portions of our Sites may not function properly.<br>
</p>Information from Children<br>
<p>Our Sites and Service are not directed to children under the age of 13 and we do not knowingly collect Personal Information from children under the age of 13.
If we learn that we have collected Personal Information of a child under the age 13, we will take reasonable steps to delete such information from our files as soon as is practicable, unless we have a legal obligation to retain it.
Please contact us at email@example.com if you believe we have any information from or about a child under the age of 13.<br>
</p>Notice to California Residents<br>
<p>Under California Civil Code Section 1789.3, California users are entitled to the following consumer rights notice: California residents may reach the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs by mail at 1625 North Market Blvd., Sacramento, CA 95834, or by telephone at (916) 445-1254 or (800) 952-5210.<br>
<br>This section provides additional details about the personal information we collect about California consumers and the rights afforded to them under the California Consumer Privacy Act or "CCPA."<br>
<br>For the categories of personal information we have collected from you in the preceding 12 months, please see the "Information We Collect" section above.
We collect this information for the business and commercial purposes described in the "How We Use Personal Information" section above.
In the preceding 12 months, we have shared the following categories of information with third parties for a business purpose: <br>
</p>Category of Personal InformationExamples of Personal Information SharedCategories of Third-Party RecipientsIdentifiers.A real name, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.Service ProvidersPersonal information categories listed in the California Customer Records statute (Cal.
Code § 1798.80(e)).A name, credit card number, debit card number, or any other financial information.Service ProvidersCommercial information.Records of products or services purchased, obtained, or considered.Service ProvidersInternet or other electronic network activity.Browsing history, information on a consumer's interaction with an internet website, application, or advertisement.Service Providers<br>
<br>Note: Fraud risk associated with an individual IP address may be shared with an Integrator upon request.<p>The Company does not "sell" (as this term is defined in the CCPA) the personal information we collect.
Please refer to the "Third Party Analytics and Tracking Technologies" section above for more information regarding the types of third-party cookies, if any, that we use.<br>
<br>Subject to certain limitations, the CCPA provides California consumers the right to request to know more details about the categories or specific pieces of personal information we collect (including how we use and disclose this information), to delete their personal information, to opt out of any "sales" that may be occurring, as well as the right to not be discriminated against for exercising these rights.<br>
<br>California consumers may make a request pursuant to their rights under the CCPA by contacting us at firstname.lastname@example.org.
Please note that you must verify your identity and request before further action is taken, such as by providing your government identification.
Consistent with California law, you may designate an authorized agent to make a request on your behalf.
In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, the requester’s valid government issued identification, and the authorized agent’s valid government issued identification.<br>
</p>EU-US Privacy Shield and Swiss-U.S.
<p>Personal Data collected from individuals in the European Economic Area ("EEA") or Switzerland may be transferred, stored and processed by us and our services providers, partners and affiliates in the United States and potentially other countries whose data protection laws may be different to the laws of your country.<br><br>IMI's commitment to comply with the Privacy Shield Principles<br>IMI has self-certified to the Privacy Shield framework.
IMI confirms its commitment to comply with the EU-US Privacy Shield and Swiss-U.S.
Privacy Shield as set forth by the U.S.
Department of Commerce regarding the collection, use, and retention of Personal Data from European Union member countries and Switzerland.
IMI has certified that it adheres to each of the Privacy Shield Principles: Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability.
To learn more about the Privacy Shield program, and to view our certification, please visit www.privacyshield.gov.<br><br>Accountability for onward transfers<br>IMI's accountability for Personal Data that it receives under the Privacy Shield and subsequently transfers to a third party is described in the Privacy Shield Principles.
In particular, IMI remains responsible and liable under the Privacy Shield Principles if third-party agents that it engages to process the Personal Data on its behalf do so in a manner inconsistent with the Principles, unless IMI proves that it is not responsible for the event giving rise to the damage.<br><br>Right of access<br>You have a legal right to request the Personal Data about you held by us.
On request, we will provide you with a copy of this information.
You also have a right to correct, amend or delete such Personal Data where it is inaccurate or has been processed in violation of the Privacy Shield Principles.<br><br>Resolution of disputes and complaint mechanism<br>In compliance with the Privacy Shield Principles, IMI commits to resolve complaints about your privacy and our collection or use of your Personal Data.
If European Union or Swiss citizens have any queries related to the processing of your Personal Data under the Privacy Shield framework, we encourage you to contact us directly in the first instance at: email@example.com.<br><br>Independent recourse mechanism<br>For any complaints that cannot be resolved with IMI directly, we have agreed to cooperate with JAMS.
If you are unsatisfied with the resolution of your complaint, you may contact JAMS at https://www.jamsadr.com/eu-us-privacy-shield for further information and assistance.
These recourse mechanisms are available at no cost to you.<br><br>Binding arbitration<br>A binding arbitration option will also be made available to you in order to address residual complaints not resolved by any other means.<br><br>Enforcement<br>IMI is subject to the investigatory and enforcement powers of the U.S.
Federal Trade Commission (FTC).<br><br>Disclosure of EU or Swiss Personal Data to public authorities and law enforcement agencies<br>IMI may be required to share your Personal Data in response to lawful by public authorities, including to meet national security and law enforcement requirements.<br>
</p>Notice to EU Data Subjects<br>
<br>Some of the information you provide us may constitute sensitive data as defined in the GDPR (also referred to as special categories of personal data), including identification of your race or ethnicity on government-issued identification documents.<br>
<br>Legal Bases for Processing<br>
<br>We only use your personal information as permitted by law.
We are required to inform you of the legal bases of our processing of your personal information, which are described below.
If you have questions about the legal bases under which we process your personal information, contact us at firstname.lastname@example.org.<br>
<br>Processing Purposes<br><br>To communicate with you<br>To optimize our platform<br>For compliance, fraud prevention, and safety<br>To provide our service<br><br>Legal Basis<br>
<br>These processing activities constitute our legitimate interests.
We attempt to consider and balance any potential impacts on you (both positive and negative) and your rights before we process your personal information for our legitimate interests.
We do not use your personal information for activities where our interests are overridden by any adverse impact on you (unless we have your consent or are otherwise required or permitted to by law).<br>
<br>With your consent<br>
<br>Where our use of your personal information is based upon your consent, you have the right to withdraw it at any time in the manner indicated in the Service or by contacting us at email@example.com.<br>
<br>Under the GDPR, you have certain rights regarding your personal information.
You may ask us to take the following actions in relation to your personal information that we hold:<br>
<br>Stop sending you direct marketing communications which you have previously consented to receive.
We may continue to send you Service-related and other non-marketing communications.<br>
<br>Provide you with information about our processing of your personal information and give you access to your personal information.<br>
<br>Update or correct inaccuracies in your personal information.<br>
<br>Delete your personal information.<br>
<br>Transfer a machine-readable copy of your personal information to you or a third party of your choice.<br>
<br>Restrict the processing of your personal information.<br>
<br>Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.<br>
<br>Data Subject Access Rights Requests<br>
<br>We may request specific information from you to help us confirm your identity and process your request.
Applicable law may require or permit us to decline your request.
If we decline your request, we will tell you why, subject to legal restrictions.
If you would like to submit a complaint about our use of your personal information or response to your requests regarding your personal information, you may contact us at firstname.lastname@example.org or submit a complaint to the data protection regulator in your jurisdiction.
You can find your data protection regulator at this location.<br>
<br>Cross-Border Data Transfer<br>
<br>As described in our "A Note to Customers Outside the United States" section, please be aware that your personal data will be transferred to, processed, and stored in the United States.
Data protection laws in the U.S.
may be different from those in your country of residence.
You consent to the transfer of your information, including personal information, to the U.S.
<br>Use for New Purposes<br>
If we need to use your personal information for an unrelated purpose, we may notify you and explain the applicable legal basis for that use.
If we have relied upon your consent for a particular use of your personal information, we may seek your consent for any unrelated purpose and allow you to terminate your use of the service at that time if you object.<br>
<p>We store your Personal Data securely throughout the life of your account with us.
We will only retain your Personal Data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting obligations or to resolve disputes.
The criteria we use to determine storage periods include the applicable contractual provisions that are in force, legal statutory limitation periods, applicable regulatory requirements, and industry standards.<br>
<br>While retention requirements vary by jurisdiction, information about our typical retention periods for different aspects of your personal data are described below.<br>
<br>Contact information for marketing purposes is retained on an ongoing basis until you un-subscribe.
Thereafter we will add your details to our suppression list indefinitely.
Email information collected from Accessibility Users will never be used for marketing purposes.<br><br>Records of communications with you (e.g.
support tickets opened via email or Twitter) may be kept indefinitely.<br><br>Information collected via technical means such as cookies, webpage counters and other analytics tools is discarded as soon as practical, but may be kept for a limited period of up to one year from expiry of the cookie, typically in a de-identified and aggregated form unless we detect potential abuse of our service, in which case we will retain that information to aid us in preventing future abuse.
We are unable to link this anonymized and aggregated information to you, your household, an IP address, or any personal information based on the information stored.<br>
If a revision is material, as determined solely by us, we will notify you, for example via email.
<em>Last updated: July 18, 2020</em>
<p>We understand your privacy is important to you and are committed to being transparent about the technologies we use.
<br>GDPR Note: we believe the hCaptcha anti-bot service (i.e.
the Service embedded by websites, games, or mobile apps) includes only so-called "consent-exempt" cookies pursuant to GDPR regulations.
Examples of such exempt cookies include:<br>
<br>* Technical cookies strictly necessary for the provision of the service.
These include preference cookies, session cookies, load balancing cookies, etc.<br>
<br>* Statistical cookies managed directly by us (i.e.
first party, not third-party cookies), where the data is not used for profiling.<br>
<br>This is not legal advice, and no warranties are provided regarding this analysis.
If you have additional questions or concerns, please contact us at email@example.com.
The hCaptcha.com and BotStop.com websites (the Sites) may include additional cookies, as described in this Policy.<br>
<br>What is a Cookie?<br>A cookie ("Cookie") is a small text file that is placed on your hard drive by a web page server.
Cookies contain information that can later be read by a web server in the domain that issued the cookie to you.
Some of the cookies will only be used if you use certain features or select certain preferences, and some cookies will always be used.
You can find out more about each cookie by viewing our current cookie list below.
We update this list periodically, so there may be additional cookies that are not yet listed.
Web beacons, tags and scripts may be used in the Sites or in emails to help us to deliver cookies, count visits, understand usage and campaign effectiveness and determine whether an email has been opened and acted upon.
We may receive reports based on the use of these technologies by our service/analytics providers on an individual and aggregated basis.<br>
<br>To recognize new or past users.<br>To store your login session information if you are registered on our Sites.<br>To improve our Site and to better understand your visits on our platforms and Site.<br>To integrate with third party social media websites.<br>To serve you with interest-based or targeted advertising.<br>To observe your behaviors and browsing activities over time across multiple websites or other platforms.<br>To better understand the interests of our Customers and Integrators.<br><br>Some Cookies are necessary for certain uses of the Sites, and without such Cookies, we would not be able to provide many services that you need to properly use the Sites.
These Cookies, for example, allow us to operate our Sites so you may access it as you have requested and let us recognize that you have created an account and have logged into that account to access Site content.
They also include Cookies that enable us to remember your previous actions within the same browsing session and secure our Sites.<br>
<br>We also use functional Cookies and Cookies from third parties for analysis and marketing purposes.
Functional Cookies enable certain parts of the Sites to work properly and your user preferences to remain known.
Analysis Cookies, among other things, collect information on how Customers, Integrators, and End-users use our Sites, the content and products that users view most frequently, and the effectiveness of our third party advertising.
Advertising Cookies assist in delivering ads to relevant audiences and having our ads appear at the top of search results.
Cookies are either "session" Cookies which are deleted when you end your browser session, or "persistent," which remain until their deletion by you (discussed below) or the party who served the cookie.
Full details on all of the Cookies used on the Sites are available at our Cookie Disclosure table below.<br>
If you want to learn more about cookies, or how to control, disable or delete them, please visit http://www.aboutcookies.org for detailed guidance.<br>
Similarly, the third parties who serve cookies on our Sites may link your name or email address to other information they collect, which may include past purchases made offline or online, or your online usage information.<br>
<br>If you are located in the European Economic Area, you have certain rights that are described above under the header "Notice to EU Data Subjects", including the right to inspect and correct or delete the data that we have about you.<br>
Used for strictly necessary anonymous service-related statistics, and for other technical purposes like assisting in accessibility support.<br>
Used for strictly necessary technical purposes: load balancing, routing.
See more details.<br>
up to 30 days.<br>
Used for strictly necessary technical purposes: enables Accessibility User use.
See more details.<br>
up to 30 days.<br>