Effective Date: July, 2021
Welcome, and thank you for your interest in Comfy, a product of Building Robotics, Inc. (“Building Robotics”, “we,” or “us”). We provide a service through our website at www.comfyapp.com (the “Site”), and through related websites, networks, embeddable widgets, downloadable software, mobile applications, tablet applications, web applications, and other online and offline services provided by us (collectively, together with the Site, our “Service”). The Service is enabled when we have entered into an agreement with the owner, operator, tenant, or your employer (our “Customer”) to provide the Service in your workspace (the “Building(s)”).
Personal data collected by our Service
The personal data that we collect can be broken down into different categories: (a) Comfy Data, (b) Customer Data, and (c) Marketing Recipient Data as described below.
(a) Comfy Data.
Comfy Data that is collected and processed by us as the responsible data controller when a user participates in our Service consists of the information described below:
- User-provided Information. To sign up for the Service or to request support from us, we ask you to provide your personal data like name, email address and phone number in the event we need to communicate with you.
- Information related to User’s devices and connection to our systems, e.g.:
- Device-related data (mobile or laptop/desktop browser version, OS version; if user is using demo mode of app, screen width and height)
- Data relating to a user’s visit: Referring URL and domain at first arrival
- Coarse-grained user location (derived from IP address).
- User Agent
- Time/Date and IP addresses of user sessions
- “Automatically Collected" Information. We may also use various types of technology to automatically collect information about your web browser and/or device type, the web pages or sites that you visit just before or just after you use the Service, the pages or other content you view or otherwise interact with on the Service, and the dates and times that you visit, access, or use the Service. We also may use these technologies to collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message.
- Integrated Services. You may be given the option to access or register for the Service through the use of your user name and passwords for certain services provided by third parties (each, an “Integrated Service”), such as through the use of your Google credentials, or otherwise have the option to authorize an Integrated Service to provide personal data or other information to us. By authorizing us to connect with an Integrated Service, you authorize us to access and store your personal data that the Integrated Service makes available to us, including your name and email address, and to use and disclose such information in accordance with this Policy. You should check your privacy settings on each Integrated Service to understand and change the information sent to us through each Integrated Service. Please review each Integrated Service’s terms and privacy policies carefully before using their services and connecting to our Service.
(b) Customer Data
Customer Data that is processed on behalf of, and under an agreement with, the relevant Customer and according to its instructions when a user participates in our Service. Depending on the scope and configuration of the Services deployed to a Customer, Customer Data may include e.g.:
- Information concerning the requests submitted by a user (e.g. to control the temperature and lighting of their workspace; to find and book meeting rooms; to request repairs; to view desk availability or book a desk; to view available amenities; to view maps of buildings and campuses, etc.)
- Information about the location of a user
- Information about the location from which or with respect to which a user submitted the request (building, floor, zone, space type)
- Date and time of a user request
- User preferences for the office settings that are controlled by the Comfy app
- App Engagement Data (information on a user’s actions within the Comfy app)
(c) Marketing Recipient Data
In addition to the Comfy Data and Customer data that we collect from users of the Service, we collect personal data from Marketing Recipients who are interested in learning more about our products and services. This personal data consists of basic contact information such as the Marketing Recipient’s name and email address. This personal data is collected by us when Marketing Recipients sign up for commercial emails from us via online or offline sign-up forms, and through other means such as in-person events and meetings and from the internet.
How we use the personal data that we collect
- To Provide the Service:
We use Comfy Data to
- provide the core functionality of the Service to users and our Customers, i.e. to operate, maintain, enhance and provide all features of the Service to you and our Customer, to provide services and information that you request, to respond to comments and questions and otherwise to provide customer support to users and our Customer.
- to protect the security and integrity of our systems
- to process and deliver entries and rewards in connection with promotions that may be offered from time to time on the Service.
We use Customer Data to provide the Service to the Customer, and as per our Customers’ instructions. As a result, the Customer is responsible for how the Customer Data will be processed.
- To Market our Business:
If you are a Marketing Recipient, we may use your personal data to send communications, including updates on promotions and events, relating to products and services offered by us and by third parties we work with that are related to the Service. Generally, you have the ability to opt-out of receiving any promotional communications as described below under “Your Choices.” For Marketing Recipients who are not otherwise users of the Service, we only use your personal data for the purposes described in this paragraph.
When we disclose personal data
- Comfy Data and Marketing Recipient Data: We work with third party service providers to provide website, application development, hosting, maintenance, data processing, marketing, and other services for us. These third parties may have access to or process your personal data as part of providing those services for us. However, we limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions. In addition, they agree to maintain the confidentiality of such information and are contractually bound to use personal data only according to our instructions.
- We may make certain automatically-collected, aggregated, or anonymized information (i.e. non-personal data) available to third parties for various purposes, including (i) compliance with various reporting obligations; (ii) for business or marketing purposes; or (iii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and/or functionality available through the Service.
- We may disclose your personal data if required to do so by law or in the good-faith belief that such action is necessary to comply with state and federal laws (such as U.S. copyright law or applicable data protection laws), in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
- We also reserve the right to disclose your personal data to the extent permitted by applicable data protection laws that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability, (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity, (iii) investigate and defend ourselves against any third-party claims or allegations, (iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others.
- To the extent permitted by applicable data protection laws, information about our users, including personal data, may be disclosed and otherwise transferred to an acquirer, or successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
Customer Data: will be disclosed to the Customer or others as set forth in the agreements concluded between us and the Customer, to the Customer or others as may be instructed by the Customer, and to comply with applicable laws and/or governmental orders.
The Service may contain features or links to websites and services provided by third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Service. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.
Protecting the privacy of young children is especially important. Our Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children under the age of 16 without obtaining parental consent. If you are under 16 years of age, then please do not use or access the Service at any time or in any manner. If we learn that personal data has been collected on the Service from persons under 16 years of age and without verifiable parental consent, then we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 16 years of age has obtained an account on the Service, then you may alert us at email@example.com and request that we delete that child’s personal data from our systems.
We use reasonable and appropriate measures to help protect the integrity and security of Comfy Data and Marketing Recipient Data that we collect and maintain.
If we learn of a security systems breach, then we or the Customer may attempt to notify you so that you can take appropriate protective steps. We may post a notice through the Service if a security breach occurs. Depending on where you live, you may have a legal right to receive notice of a security breach in writing.
We take appropriate technical and organizational security measures to protect Customer Data (in particular against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access) and shall inform our Customer in case of a breach.
For Comfy Data and Marketing Recipient Data only: If you wish to access, receive a copy of, change or delete the Comfy Data or Marketing Recipient Data that we hold about you, you may contact us at firstname.lastname@example.org.
If you receive commercial email from us, you may unsubscribe at any time by following the instructions contained within the email. You may also opt-out from receiving commercial email from us, and any other promotional communications that we may send to you from time to time, by sending your request to us by email at email@example.com or by writing to us at the address given at the end of this Policy. Please be aware that if you opt-out of receiving commercial email from us or otherwise modify the nature or frequency of promotional communications you receive from us, it may take up to ten business days for us to process your request, and you may receive promotional communications from us that you have opted-out from during that period. Additionally, even after you opt-out from receiving commercial messages from us, you will continue to receive administrative messages from us regarding the Service.
Upon receipt of any of the above request(s), we will use reasonable efforts to reflect any changes you request in our databases to the full extent required by applicable law.
If you are not satisfied with how we have attempted to resolve your complaint, you may contact the relevant data protection authority.
For Customer Data only. Because we have collected Customer Data about you on behalf of and under the instructions of a specific Customer, we must receive any instructions with respect to the handling of Customer Data from the Customer. We encourage you to contact the Customer to access, receive a copy of, change, or delete any Customer Data, and we agree to work with our Customer in good faith to assist it with your request.
Subject to our obligations contained in the section above titled “Your Choices”, and unless a different retention period is required by law or by agreement with our Customer, we will retain the personal data of users of the Service until the first to occur of the following: five (5) years from the date of collection of such personal data, the date on which our contractual relationship with our Customer terminates, or ninety (90) days following the date on which we become aware that you are no longer an active user of the Service. At such time, we will delete your personal data.
For Marketing Recipients, we will retain your personal data until you request that we delete such personal data as described in the section above titled “Your Choices”.
We may retain other information that is not personal data (such as anonymized and/or aggregated data) for backups, archiving, prevention of fraud and abuse, analytics, to improve our service, or where we otherwise reasonably believe that we have a legitimate reason to do so.
This section applies to Comfy Data only. Customer is responsible for determining the data retention schedules applicable to his Customer Data.
Our Compliance with Data Laws for International Users
If you are located in the European Economic Area or Switzerland, our processing of your personal data is subject to the EU General Data Protection Regulation (the "GDPR"). The GDPR requires that we provide users with more information about the processing of your personal data. Here is what you need to know:
Legal Ground for Processing your personal data
The GDPR requires us to tell you about the legal grounds we're relying on to process any personal data about you. The legal grounds for our processing of Comfy Data for the purposes above are:
- it is necessary for our contractual relationship;
- the processing is necessary for us to comply with our legal or regulatory obligations; and/or
- the processing is in our legitimate interest as a provider of the Services (for example, to protect the security and integrity of our systems and to provide you with customer service, etc.).
The Customer is responsible for determining the legal grounds for the processing of Customer Data carried out by Comfy on behalf of Customer.
The Service is hosted in the United States and is intended for users located within the United States as well as users located outside of the United States. If you submit personal data to us directly (e.g. via a request submitted on the Site) and you are located within the European Economic Area, Switzerland, or the United Kingdom or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your personal data outside of those regions to the United States for processing.
Previously, Building Robotics had participated in the EU-US Privacy Shield Principles and the Swiss-US Privacy Shield Principles (collectively “Privacy Shield” or “Privacy Shield Principles”) regarding the collection, use, sharing, and retention of personal data from the European Economic Area, Switzerland, or the United Kingdom. However, after the judgment of the Court of Justice of the EU Case c311/18, Comfy no longer relies upon the EU-U.S. Privacy Shield Framework as a legal basis for transfers of personal data. The European Commission has approved the use of model contract clauses and other legal mechanisms as a means of ensuring adequate protection when transferring data outside of the EEA and we will enter into model contract clauses with our Customers in the EEA, Switzerland and the United Kingdom. Please note that we continue to apply the Privacy Shield Principles to the personal data that was collected thereunder during the term of our Privacy Shield certification.
As described in this Policy, we may share personal data with third parties and may be required to disclose information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Your Right to File a Complaint
If you are not satisfied with how we handle your Comfy Data or Marketing Recipient Data, we encourage you to contact us at firstname.lastname@example.org. But you also have the right to lodge a complaint with the relevant data protection authority. For complaints concerning Customer Data, please contact the Customer on whose behalf we provide the Service in your Building.
Changes and Updates to this Policy
Please revisit this page periodically to stay aware of any changes to this Policy, which we may update from time to time. If we modify this Policy, we will make it available through the Service, and indicate the date of the latest revision. In the event that the modifications materially alter your rights or obligations hereunder, we will use reasonable efforts to notify you of the change and will obtain new consent from you to the extent required by GDPR or other applicable laws. For example, we may send a message to your email address, if we have one on file, or generate a pop-up or similar notification when you access the Service for the first time after such material changes are made. Your continued use of the Service after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of this Policy.
Our Contact Information
Please contact us with any questions or comments about this Policy, your personal data, our use and disclosure practices, or your consent choices by email at email@example.com.
Building Robotics, Inc.
1504 Franklin St., Suite 200
Oakland, CA 94612
Data Protection Officer
In addition, we have appointed a Data Protection Officer (“DPO”). Our DPO can be contacted directly by email at DPO@comfyapp.com or by mail at:
Building Robotics, Inc.
ATTN: Data Protection Officer
1504 Franklin St., Suite 200
Oakland, CA 94612
Our representative in the EU
Our designated representative established in the European Union who represents us with regard to our obligations under the GDPR is Siemens AG, Otto-Hahn-Ring 6, 81739 Munich, Germany and may be contacted by mail at firstname.lastname@example.org.
Further information for US residents
If you are a U.S. resident, then please take note of the following:
Do Not Track
At this time our Online Offerings do not recognize or respond to “Do Not Track” browser signals. For more information on “Do Not Track”, please visit your browser’s support page.
Additional US State Rights
Depending on the US state in which you reside, you may have special rights with respect to your personal data. For information regarding any of those rights, please click here.