WEBSITE PRIVACY POLICY September, 2024
This website is operated by Xsight Labs Ltd.
This Privacy Policy explains our privacy practices for processing Personal Data on our Website.
We are committed to protecting your privacy and processing your Personal Data fairly and lawfully in compliance with applicable data protections laws. You can review our full Privacy Policy below to understand how we collect and use your Personal Data. In it, we explain in the types of Personal Data we collect, how we collect it, what is legal basis of collection, what we may use it for, who we may share it with, what our retention periods are and what are your rights in relation to the Personal Data we collect.
Within the Privacy Policy you will find some specific examples of why and how we use your Personal Data.
Read this policy and make sure you fully understand our practices in relation to your Personal Data, before you access or use the Website. If you have read this Privacy Policy, and remain opposed to our practices, you must immediately leave this Website, and avoid or discontinue all use of the Website. If you have further questions or concerns regarding this policy please contact us at: information@xsightlabs.com.
(All capitalized terms shall have the meanings as defined in the full Privacy Policy below).
Xsight Labs Ltd. (“Xsight”, “we”, “our” or “us”) provides this Privacy Policy, as will be updated from time to time (our “Policy” or “Privacy Policy”) to inform the Visitors of our Website (or “you”) of our policies and procedures regarding the collection, use and disclosure of information we receive when you use the Website, and how you control the data processing.
(All capitalized terms shall have the meanings as defined in the Definitions section below).
“GDPR” shall mean the General Data Protection Regulation (EU) 2016/679 as amended, replaced or superseded from time to time.
“Applicable Laws” shall mean the GDPR; European Union Member State laws, rules and guidelines implementing or supplementing the GDPR, as amended from time to time and to the extent applicable to Xsight; and any other applicable privacy or other law to the extent applicable to Xsight.
“Personal Data” shall also have the meaning ascribed to it in the GDPR or the meaning of similar terms in other applicable laws. To put it simply, Personal Data means individually identifiable information, namely, information that identifies an individual or may with reasonable efforts cause the identification of an individual, including unique identifiers like IP addresses or cookie IDs.
The term “Processing” shall have the meanings ascribed to it in the GDPR.
“Subprocessor” shall mean any entity appointed by us or by one of our subprocessors, to Process Personal Data on our behalf or on behalf of that subprocessor; excluding any employee of Xsight or of Xsight’ subprocessor or of any such appointed person but including any contractor or affiliate of the foregoing.
“Visitor” or “you” means visitors of our Website.
“Website” means our public website available at https://xsightlabs.com/ providing information regarding our products.
This Policy was originally written in English. If you are reading a translation and it conflicts with the English language version, please note that the English language version prevails.
This Privacy Policy is meant to be read together with our Terms and Conditions of Sale, which you can find at https://xsightlabs.com/terms-conditions/. In general, we recommend that you routinely review this privacy policy and your preferences on our Website.
A Note on Legal Bases. Certain jurisdictions only allow the processing of personal data where a legal basis has been established. Under the EU’s General Data Protection Regulation (“GDPR”), the possible legal bases include (but are not limited): your consent, the processing is necessary to perform a contract with you, the processing is necessary to fulfill our legal obligations, or a company has a legitimate business interest to process your personal data. Where we are a controller, we only collect and process data where we have established a legal basis. Below you can find more details about specific legal bases.
We share your personal data as follows:
1. Affiliates. We share your personal data with our affiliated companies, where this is necessary to provide you with our products and services and so that we can manage our business, such as to keep updated records of our users.
2. Service Providers. Below is a list of the types of service providers we use, the service each provides, and the types of data shared with each. All service providers have agreed to confidentiality restrictions and have undertaken to use your personal data solely as we direct.
| Type of Service | Description | Personal Data Shared |
|---|---|---|
| Cloud Computing | We use service providers that offer cloud computing services. They offer us space on their servers for us to store our files and programs, including your personal data. | All personal data that we collect from you is stored on third-party servers. |
| Customer Relationship Management (CRM) | We use an external CRM tool to help us keep track of our customers and information related to them, including their personal data. | Your name, company, position, email address, and phone number. |
| Bookkeeping Services | We use the services of a third-party bookkeeping service to manage our financial transactions and records. | Your name, age, marital status, position in the company, address, and bank account information. |
| Analytics Providers | We use a service provider to assist us with analytics services. | Data collected automatically through our site, including IP addresses and cookie information. |
3. Change of Ownership. If we are looking to sell our company, liquidate assets, or merge with another, we may share your personal data with other interested parties as part of negotiations toward that transaction or in connection with the transaction. In such a case, or where we do sell our company, your personal data shall continue to be subject to the provisions of this Privacy Policy.
4. Law Enforcement Related Disclosure. We may share your personal data with government agencies or other relevant parties, such as a law office or independent auditor: (i) if we believe that such disclosure is appropriate to protect our rights, property, or safety (including the enforcement of the Terms and this Privacy Policy) or those of a third party; (ii) if required by law or court order; or (iii) as is necessary to comply with any legal and/or regulatory obligations, such as audit requirements.
In all of the above cases in which we collect, use or store your Personal Data, you may have the following rights and, in most cases, you can exercise them free of charge. At any time, you may contact us at: information@xsightlabs.com and request to know what Personal Data we keep about you. We will make good-faith efforts to locate the data that you request to access.
When you ask us to exercise any of your rights under this Policy and the applicable law, we may need to ask you to provide us certain credentials to make sure that you are who you claim you are, to avoid phishing and/or disclosure to you of Personal Data related to others.
We may redact from the data which we will make available to you, any Personal Data related to others, if applicable.
Depending on which laws apply, you have certain legal rights over your data. Below is some general information about rights that may apply to you but we recommend checking the law or consulting with a lawyer to understand what applies in your specific case. To exercise your rights, please contact us at information@xsightlabs.com. We may ask for reasonable evidence to verify your identity before we can comply with any request.
To exercise these rights, where applicable, please contact us as detailed in Section 13 “Contact Us” of this Policy.
We take the safeguarding of your data very seriously, and use a variety of industry standard systems, applications and procedures to protect the Data from loss, theft, damage or unauthorized use or access. However, although we make efforts to protect your privacy, we cannot guarantee that the Website will be immune from any wrongdoings, malfunctions, unlawful interceptions or access, or other kinds of abuse and misuse.
We also regularly monitor our systems for possible vulnerabilities and attacks, and regularly seek new ways and for further enhancing the security of our Website and protection of our Visitors’ privacy.
The security of your data also depends on the security of the devices you use and the way in which you protect your user IDs and passwords. The measures we take include:
Database Backup. Our databases are backed up and verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality and integrity.
You should take steps to protect against unauthorized access to your device by, among other things, signing off after using a shared computer, choosing a robust password that nobody else knows or can easily guess, and keeping your log-in and password private.
If you receive an e-mail asking you to update your information with respect to the Website, do not reply and please contact us at information@xsightlabs.com.
We retain different types of information for different periods, depending on the purposes for processing the data. We retain your personal data as long as necessary to fulfill each of the purposes we described above.
When deciding how long to store personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized access, the purposes for which the personal data was collected, as well as applicable legal requirements. Please note that we may delete information from our systems without notifying you first. Retention by any of our service providers or subcontractors may vary in accordance with each business’s retention policy. Generally, we retain information about persons who contacted us for up to 12 months.
In some circumstances, we may store your personal data even after we’re finished using it if required to do so by law (e.g. to fulfill tax or audit requirements), or to keep accurate records of our interactions in case there is a prospect of litigation relating to your personal data. In such cases, we will maintain the same security measures as described above.
Please contact us at information@xsightlabs.com if you would like details about the retention periods for each type of personal data we process.
Our Website is not meant to be used by or for persons under 18, as such, we do not knowingly collect Personal Data from minors younger than 18. Insofar as Personal Data may be collected based on your consent, the data subject must be above the age of 18. If these age requirements are not met, you are required not to use the Website.
We do not support Do Not Track (DNT). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
The California Consumer Privacy Act or “CCPA” (California Civil Code Section 1798.100 et seq.) requires us to disclose to California residents who use our Website (“California users”) how we collect, share, and store personal information about California users, as well as the rights they have with respect to that information.
For the purposes of this clause 16, “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, or as otherwise may be defined by applicable law.
Depending on your usage, we collect different types of information and we and any of our third-party sub-contractors and service providers use the information we collect for different purposes, as specified below. It is your voluntary decision whether to provide us with certain Personal Information, but if you refuse to provide such Personal Information, we may not be able to register you and/or provide you with the Website or part thereof.
Categories of Personal Information We Collect. In the past twelve months, we have collected the following Personal Information from users of our Website who are using the Website. This Personal Information is used for the purposes described herein.
The CCPA also requires us to communicate information about rights California users have to request access to their Personal Information, to request deletion of their Personal Information, to request additional details about our information practices, to request to opt out of the “sale” of their Personal Information, if applicable, and to not be discriminated against for exercising such rights.
Your options in regard to the Personal Information we collect about you are described below.
Contact Information. To exercise any of the rights detailed above, please submit a verifiable request to us by contacting us at information@xsightlabs.com. You may only request to exercise your right of access twice within a 12-month period.
Submitting a Verifiable Request: In order to exercise your right to know or right to delete, you must submit a request containing sufficient information that allows us to reasonably verify you are the person about whom we collected the applicable Personal Information or an authorized agent of such person, which may include details relating to your account. Any requests made through your password-protected account will be verified through our existing authentication procedures for such account.
Submitting Requests through an Authorized Agent: An authorized agent may exercise requests on your behalf. In order to exercise your right to know or right to delete through an agent, we may ask for reasonable evidence to verify your identity and the agent’s identity, and written authorization permitting the agent to act on your behalf before complying with your request. In order to submit a request to opt-out of the sale of your Personal Information through an agent, we may ask for written authorization permitting the authorized agent to act on your behalf before complying with your request. We reserve the right to deny the request of any agent that does not provide proof that they have been authorized to act on behalf of the applicable consumer in accordance with applicable law.
Retention: We retain your Personal Information as long as necessary to fulfill each of the purposes we described above. When deciding how long to store Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized access, the purposes for which the Personal Information was collected, as well as applicable legal requirements. Please note that we may delete information from our systems without notifying you first. Retention by any of our service providers or subcontractors may vary in accordance with each business’s retention policy.
Do Not Sell My Info: As described above, we may provide Personal Information for the purpose of connecting you with providers to discuss services that you may be interested in for yourself or for a Resident and to our partners and other third parties. We give you the option to opt out of such sharing at any time by following the “Do Not Sell My Personal Information” link. The link is also available on our Website.
California’s Shine the Light law also permits residents of California to request certain details about how their information is shared with third parties for direct marketing purposes. Under the law, a business must either provide this information or permit California residents to opt in to, or opt out of, this type of sharing. To opt out of having information about you shared with third parties for direct marketing purposes, please email us at information@xsightlabs.com.
We may update this Privacy Notice from time to time to keep it up to date with legal requirements and the way we operate our business. We will place any updates on this webpage. Please come back to this page every now and then to make sure you are familiar with the latest version. However, substantial changes will be effective thirty (30) days after the notice was initially posted. We will make an effort to inform you of substantial changes through the channels of communication generally used in such circumstances.
If we need to adapt the Policy to legal requirements, the amended Policy will become effective immediately or as required.
Your continued use of the Website following such notice shall constitute your consent to any changes made and a waiver of any claim or demand in relation to such changes. If you do not agree to the new or different terms, you should not use and are free to discontinue using the Website.
For further information about this Policy, please contact us at information@xsightlabs.com.
If you have any concerns relating to this Policy, please contact us and we will make good-faith efforts to address your concerns. We are usually able to resolve privacy questions or concerns promptly and effectively. If you are not satisfied with the response you receive from us, you may escalate concerns to the applicable privacy regulator in your jurisdiction. Upon request, we will provide you with the contact information for that regulator.
Copyright © 2017-2026, Xsight Labs Ltd. All rights reserved.
Last Updated: September, 2024