This Privacy Policy describes how Trevor collects, uses and discloses information, and what choices you have with respect to the information.
When we refer to “Trevor”, we mean Trevor Tech GmbH, a company incorporated in Germany whose registered office address is at Lohmühlenstraße 65, 12435 Berlin, which is the entity that acts as the controller or processor of your information.
Applicability of this Privacy Policy
This Privacy Policy applies to the services offered via the website Trevor.io (collectively, the "Services") and other interactions (e.g. customer service inquiries, user conferences, etc.) you may have with Trevor. If you do not agree with the terms, do not access or use the Services, Website or any other aspect of Trevor’s business. This Privacy Policy does not apply to any third party applications or software that integrate with the Services through the Trevor platform ("Third Party Services"), or any other third party products, services or businesses. In addition, a separate agreement governs delivery, access and use of the Services (the "Terms of Use"), including the processing of personal data (collectively, "Customer Data"). The organization (e.g., the business or location) that entered into the Customer Agreement ("Customer") controls their instance of the Services and any associated Customer Data.
Information We Collect And Receive
Trevor may collect and receive Customer Data and other information and data (“Other Information”) in a variety of ways:
Customer Data. Customers or individuals granted access to a Datasource by a Customer (“Authorized Users”) may submit Customer Data to Trevor while using the Services. For example, if you run a query against your database using Trevor, Customer Data will be submitted to Trevor in the form of the results of your query.
Other Information. Trevor also collects, generates and/or receives Other Information:
How We Use Information
A quick distinction
Data protection law in certain jurisdictions, such as the EU, differentiates between the “controller” and “processor” of information. In general, Customer is the controller of Customer Data. In general, Trevor is the processor of Customer Data and the controller of Other Information.
Usage
Customer Data will be used by Trevor in accordance with Customer’s instructions, including any applicable terms in the Customer Agreement and Customer’s use of Services functionality, and as required by applicable law. Customer may, for example, use the Services to grant and remove access to a Datasource, assign roles and configure settings, access, modify, export, share and remove Customer Data and otherwise apply its own policies to the Services.
Trevor uses Other Information in furtherance of our legitimate interests in operating our Services, Website and business. More specifically, Trevor uses Other Information:
To provide, update, maintain and protect our Services, Website and business. This includes use of Other Information to support delivery of the Services under a Customer Agreement, prevent or address service errors, security or technical issues, analyze and monitor usage, trends and other activities or at an Authorized User’s request.
As required by applicable law, legal process or regulation.
To communicate with you by responding to your requests, comments and questions. If you contact us, we may use your Other Information to respond.
To send emails and other communications. We may send you service, technical and other administrative emails, messages and other types of communications. We may also contact you to inform you about changes in our Services, our Services offerings, and important Services-related notices, such as security and fraud notices. These communications are considered part of the Services and you may not opt out of them. In addition, we sometimes send emails about new product features, promotional communications or other news about Trevor. These are marketing messages so you can control whether you receive them.
For billing, account management and other administrative matters. Trevor may need to contact you for invoicing, account management and similar reasons and we use account data to administer accounts and keep track of billing and payments.
To investigate and help prevent security issues and abuse.
If Information is aggregated or de-identified so it is no longer reasonably associated with an identified or identifiable natural person, Trevor may use it for any business purpose. To the extent Information is associated with an identified or identifiable natural person and is protected as personal data under applicable data protection law, it is referred to in this Privacy Policy as “Personal Data.”
Data Storage and Retention
Trevor stores Customer Data for between 24 and 48 hours for performance reasons, and to protect your database from too much load. It is then permanently deleted.
Trevor may retain Other Information pertaining to you for as long as necessary for the purposes described in this Privacy Policy. This may include keeping your Other Information after you have deactivated your account for the period of time needed for Trevor to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
Customer Data and Other Information are stored on Heroku Postgres or Amazon S3.
How We Share And Disclose Information
This section describes how Trevor may share and disclose Information. Customers determine their own policies and practices for the sharing and disclosure of Information, and Trevor does not control how they or any other third parties choose to share or disclose Information.
Customer’s Instructions: Trevor will solely share and disclose Customer Data in accordance with a Customer’s instructions, including any applicable terms in the Customer Agreement and Customer’s use of Services functionality, and in compliance with applicable law and legal process.
Displaying the Services. Example (1): an Authorized User’s email address is displayed next to a query they saved to show who is the creator of the query.
Customer Access. Owners, administrators, Authorized Users and other Customer representatives and personnel may be able to access, modify or restrict access to Other Information. For example, your employer may revoke your access to a Datasource you were previously invited to, at which point you will not be able to see any saved queries you previously created.
Third Party Service Providers and Partners. We may engage third party companies or individuals as service providers or business partners to process Other Information and support our business. These third parties may, for example, provide virtual computing and storage services. Additional information about the subprocessors we use to support delivery of our Services is set forth at Trevor Subprocessors.
During a Change to Trevor’s Business. If Trevor engages in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of Trevor’s assets or stock, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g. due diligence), some or all Other Information may be shared or transferred, subject to standard confidentiality arrangements.
Aggregated or De-identified Data. We may disclose or use aggregated or de-identified Other Information for any purpose. For example, we may share aggregated or de-identified Other Information with prospects or partners for business or research purposes, such as telling a prospective Trevor customer the average numbers of queries run within a typical Datasource.
To Comply with Laws. If we receive a request for information, we may disclose Other Information if we reasonably believe disclosure is in accordance with or required by any applicable law, regulation or legal process.
To enforce our rights, prevent fraud, and for safety. To protect and defend the rights, property or safety of Trevor or third parties, including enforcing contracts or policies, or in connection with investigating and preventing fraud or security issues.
With Consent. Trevor may share Other Information with third parties when we have consent to do so.
Security
Trevor takes security of data very seriously. Trevor works hard to protect Information you provide from loss, misuse, and unauthorized access or disclosure. These steps take into account the sensitivity of the Information we collect, process and store, and the current state of technology.
To learn more about current practices and policies regarding security and confidentiality of the Services, please see our Security Practices. Given the nature of communications and information processing technology, Trevor cannot guarantee that Information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others.
Changes To This Privacy Policy
Trevor may change this Privacy Policy from time to time. Laws, regulations and industry standards evolve, which may make those changes necessary, or we may make changes to our business. We will post the changes to this page and encourage you to review our Privacy Policy to stay informed. If we make changes that materially alter your privacy rights, Trevor will provide additional notice, such as via email or through the Services. If you disagree with the changes to this Privacy Policy, you should deactivate your Services account. Contact the Customer if you wish to request the removal of Personal Data under their control.
International Data Transfers
Trevor may transfer Personal Data between the European Union or Switzerland and the US. Transfers originating from the European Union or Switzerland to the US will only be to individuals or organisations that specifically comply with the E.U.-U.S. Privacy Shield and Swiss-U.S. Privacy Shield. These frameworks were developed to enable companies to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States.
Data Protection Officer
To communicate with our Data Protection Officer, please email [email protected]
Your Rights
Your principal rights under data protection law are (a) the right to access; (b) the right to rectification; (c) the right to erasure; (d) the right to restrict processing; (e) the right to object to processing; (f) the right to data portability; (g) the right to complain to a supervisory authority; and (h) the right to withdraw consent.
You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.
To the extent that the legal basis for our processing of your personal data is (a) consent or (b) that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.
If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.
In addition, individuals located in certain countries, including the European Economic Area, have certain statutory rights in relation to their personal data. Subject to any exemptions provided by law, you may have the right to request access to Information, as well as to seek to update, delete or correct this Information. You can usually do this using the settings and tools provided in your Services account. If you cannot use the settings and tools, contact Customer for additional access and assistance.
To the extent that Trevor’s processing of your Personal Data is subject to the General Data Protection Regulation, the legal basis for processing your information will be in order to fulfil the terms of the services you have requested or our legitimate interests, which are the proper administration of our website and business. Trevor may also process Other Information that constitutes your Personal Data for direct marketing purposes and you have a right to object to Trevor’s use of your Personal Data for this purpose at any time.
Data Protection Authority
Subject to applicable law, you also have the right to restrict Trevor’s use of Other Information that constitutes your Personal Data and lodge a complaint with your local data protection authority if you believe that we are misusing your information in any way.
Contact
If you have any questions, please contact Trevor on [email protected]