Last Updated: January 2021
PART I. GENERAL INFORMATION
1.1 OUR COMMITMENT TO PRIVACY
1.2 INTRODUCTION TO BRAZE
Braze is a U.S. company, headquartered in New York, with global operations. A reference to “Braze,” “we,” “us” or the “Company” is a reference to Braze, Inc. and the relevant affiliate(s) involved in the processing activity.
Braze is a life-cycle engagement platform for companies around the world, supporting stronger relationships between brands and their clients, primarily by leveraging first party data to personalize and automate life-cycle marketing campaigns through first party channels, such as email, SMS, mobile and web push notifications, and in-app/in-browser messaging.
Braze processes a variety of personal data, including but not limited to name and job role, CV/resume and work history, education, interests, professional references, email addresses, device data, ID data, event attendance, location, marketing subscription status, audio and video recordings from our prospects, customers, business partners and vendors (if they are natural persons), their respective employees, advisors, and/or contractors, along with the data of whoever our customers have authorized to use the Braze services (the “Services”) on their behalf.
Braze collects personal data relating to or identifying individuals (“Personal Data”) from people (collectively, “Individuals”) who:
- Visit our website (found at www.braze.com) (the “Website”);
- Visit our offices;
- Receive communications from us, including emails, phone calls or texts;
- Use our Services as an authorized user (for example, an employee of one of our customers who has been granted access to our Services);
- Register for, attend and/or otherwise take part in our events, webinars or contests;
- Apply to work with us; or
- Work at partners or suppliers of Braze and interact with our company in the course of doing business or contemplating doing business with us.
Braze collects Personal Data from a variety of sources, such as the Individual who is the subject of such Personal Data, from publicly available sources (such as an Individual’s Social Media accounts), from our business partners, from data providers and from Braze affiliates.
Additionally, our Website or Services may contain links to other websites, applications and services maintained by third parties. The privacy and data security practices of such third-party sites are governed by the privacy statements of those third parties, and not by Braze.
More information about Braze can be found at www.braze.com.
PART II. INFORMATION WE COLLECT AS A DATA CONTROLLER AND THE PURPOSES FOR WHICH WE USE IT
Braze acts as a Data Controller with respect to the Personal Data it collects from Individuals, as described in Section 1.2 above.
2.1 DEVICE AND USAGE DATA
As is true of most websites, we gather certain information automatically in connection with the use of the Website by individual users. This information may include IP address (or proxy server), device and application identification numbers, location, browser type, Internet service provider and/or mobile carrier (“Device Data”). We may also automatically collect information about how you use the Website, such as the pages and files viewed, searches, operating system and system configuration information and date/time stamps associated with your usage (“Usage Data”).
2.2 USE OF PERSONAL DATA
Braze collects Personal Data for several purposes, including:
- Enabling us to understand who is interested in learning about our products, services, content, and company-related initiatives;
- Promoting the security of our Website and Services by tracking use of our Website and Services, enforcing our terms and policies, investigating and preventing fraudulent, suspicious or illegal activities, and preventing unauthorized access to the Services;
- Providing, operating, and maintaining the Services;
- Responding to your requests for support or information;
- Registering office visitors to maintain the security of our offices and to ensure the confidentiality of our business activities;
- Analyzing our customers' use of the Services for trend monitoring, marketing, and advertising purposes and to send marketing communications about us and our affiliates and partners, including information about our products, promotions or events;
- Analyzing overall trends on our Website to help us to provide and improve our Website and to ensure its security and continued proper functioning;
- For internal training and research;
- Sending messages to the users of our Services with respect to technical alerts, updates, security notifications, and educational and administrative communications;
- Recruiting, interviewing, evaluating and hiring job candidates; and
- Complying with legal obligations, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes or to respond to lawful requests.
Where we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to comply with our legal obligations or perform our contract with you.
If you provide us with Personal Data relating to another person, you confirm that you have informed them of our identity and the purposes (as set out above) for which their Personal Data will be used and that you have obtained their consent prior to sharing their information with us.
2.3 SHARING AND DISCLOSURE OF INFORMATION TO THIRD PARTIES
We may share and disclose Personal Data to the following types of third parties and for the following purposes:
- To customers – We may disclose information to our customers in the form of aggregated, anonymous data about the way the Services have been used to enable us to provide and improve our Services, to provide strategic advice to our customers, and to further and enhance our role as a thought leader in the industry;
- To vendors, consultants and other service providers – We may disclose information to third-party vendors, consultants and other service providers in connection with our marketing efforts, or in connection with our general business purposes;
- To comply with laws – We may disclose information to a third party where we are legally required to do so in order to comply with any applicable law, regulation, legal process or governmental request;
- To protect our legal rights – We may also disclose information where we believe it necessary in order to protect or exercise, establish or defend our legal rights;
- Business transfers – We may share or transfer information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company;
- To provide our Services – We use sub-processors in our provision of the Braze Services to our customers, such as third-party hosting providers and third-party database support services. Some of these third-party sub-processors may have logical access to data about you, but in all cases, any sub-processor to whom we disclose any information will be subject to a written agreement containing confidentiality protections designed to protect any Personal Data that is shared with them;
- To advisors – In individual instances, we may share Personal Data with professional advisers acting as processors or joint controllers, including lawyers, bankers, auditors and insurers based in countries in which we operate, who provide consultancy, banking, legal, insurance and accounting services, but only to the extent we are legally obliged to share or have a legitimate interest in sharing your Personal Data;
- To affiliates – We may share Personal Data with affiliates within the Braze corporate group and companies that we may acquire in the future when they are made part of the Braze corporate group, to the extent such sharing of data is necessary to fulfill a request you have submitted via our Website or for customer support, marketing, technical operations or account management purposes; and
- Publicly shared data – Any Personal Data or other information you choose to submit in communities, forums, blogs or chat rooms on our Website may be read, collected and used by others who visit these forums, depending on your account settings.
PART III. INTERNATIONAL TRANSFERS, SECURITY AND DATA RETENTION
3.1 PROCESSING OF PERSONAL INFORMATION IN THE U.S. AND ELSEWHERE
Our Website servers are located in the United States, and our group companies and third-party service providers and partners operate in the United States, Singapore and the United Kingdom. This means that when we collect your Personal Data, we may process it in any of these countries. These countries may have data protection laws that are different from the laws of your country (and, in some cases, may not be as protective), but we will put in place appropriate safeguards, including certification to the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce.
330 West 34th Street, 18th Floor
New York, NY 10001
Braze has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved Privacy Shield complaints regarding Personal Data transferred from the EU, the United Kingdom and Switzerland. Under certain circumstances, individuals may be able to invoke binding arbitration, in accordance with the Privacy Shield requirements. In addition, as a U.S.-based company, Braze may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
We use technical, organizational and administrative security measures designed to protect the security, confidentiality and integrity of information.
3.3 DATA RETENTION
We will retain Personal Data we collect from you for so long as we have an ongoing legitimate business need to do so (in connection with the purposes set out in Part II above). We determine the appropriate retention period for Personal Data on the basis of the amount, nature and sensitivity of your Personal Data processed, the potential risk of harm from unauthorized use or disclosure of your Personal Data and whether we can achieve the purposes of the processing through other means, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).When we have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymize it or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.
PART IV. TRACKING TECHNOLOGIES
4.1 TRACKING TECHNOLOGIES USED IN CONNECTION WITH OUR WEBSITE
When you visit our Website, we or an authorized third party may place a cookie on your browser and/or device, which collects information, including Personal Data, about your visits to our Website over time. Cookies allow us to track usage, determine your browsing preferences and improve and customize your browsing experience.
We also use web beacons on our Website and in email communications. For example, we may place web beacons in marketing emails that notify us when you click on a link in the email. Such technologies are used to operate and improve our Website and email communications. For instructions on how to unsubscribe from our marketing emails, please visit our Preference Center.
4.2 BLOCKING COOKIES FROM OUR WEBSITE
4.3 SOCIAL MEDIA SHARING
Our Website may allow you to share articles on social network sites such as LinkedIn and Twitter. You may be given the option on our Website to post information about your activities on a website to a profile page of yours that is provided by a third-party social media network in order to share with others within your network. These social media sites are hosted by the respective social media networks and if you click through to these social media sites from our Website, the latter may receive information showing that you have visited our Website. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our Website with your social media profile.
Your interactions with social media sites are governed by the privacy policies of the companies providing the relevant social media sites.
PART V. YOUR PRIVACY RIGHTS
5.1 PRIVACY RIGHTS
You may have the following privacy rights:
- If you wish to access, correct, update or request deletion of your Personal Data, you can do so at any time by contacting us through this FORM (which will ask from you information necessary for us to process your request) or by using the contact details provided under the “How to contact us” heading below.
- In addition, if you are a resident of the European Union or the United Kingdom, you can object to processing of your Personal Data, ask us to restrict processing of your Personal Data or request portability of your Personal Data. Again, you can exercise these rights by contacting us through this FORM (which will ask from you information necessary for us to process your request) or by using the contact details provided under the “How to contact us” heading below.
- You have the right to opt-out of marketing communications we send you at any time. You can exercise this right by clicking on the “opt-out” link in the marketing communications we send you or by going to our Preference Center, or by using the contact details provided under the “How to contact us” heading below.
- You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects ("Automated Decision-Making"). Automated Decision-Making currently does not take place on our Website or in our Services;
- Similarly, if we have collected and processed your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on lawful processing grounds other than consent.
- You have the right to complain to a data protection authority about our collection and use of your Personal Data. For more information, please contact your local supervisory authority.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
Where you wish to enforce any of these rights in respect of our Services, you should contact the Customer who provides you with the Customer Application. We will then help them to fulfil that request in accordance with their instructions and applicable legal requirements.
5.2 UNSUBSCRIBE FROM OUR MAILING LIST
Braze complies with all applicable anti-spam laws when it sends emails or other digital messages to you. You may at any time ask us to remove you from any mailing list on which you previously asked Braze to include you by going to our Preference Center, or by clicking "Unsubscribe" in any email communications we send you. Please note that opting-out of the receipt of marketing communications from us does not opt you out of receiving important business communications related to your current relationship with us, such as communications about your subscriptions or event registrations, service announcements or security information.
PART VI. LEGAL BASIS FOR PROCESSING PERSONAL INFORMATION (EEA AND UK VISITORS ONLY)
If you are a visitor to our Website from the EEA or the United Kingdom, our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it.
However, we will normally collect Personal Data from you only where we have your consent to do so, where we need the Personal Data to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Data from you or may otherwise need the Personal Data to protect your vital interests or those of another person.
If we ask you to provide Personal Data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Data is mandatory or not (as well as of the possible consequences if you do not provide your Personal Data).
Similarly, if we collect and use your Personal Data in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Data, please contact us through this FORM (which will ask from you information necessary for us to process your request) or by using the contact details provided under the “How to contact us” heading below.
PART VII. IMPORTANT INFORMATION FOR CALIFORNIA RESIDENTS
This section applies only to California residents. It describes how we collect, use and share Personal Information of California residents in operating our business, and their rights with respect to that Personal Information. For purposes of this Part VII, Personal Information has the meaning given in the California Consumer Privacy Act of 2018 (“CCPA”) but does not include information exempted from the scope of the CCPA.
7.1 YOUR CALIFORNIA PRIVACY RIGHTS.
As a California resident, you have the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law.
- Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months:
- The categories of Personal Information that we have collected.
- The categories of sources from which we collected Personal Information.
- The business or commercial purpose for collecting and/or selling Personal Information.
- The categories of third-parties with whom we share Personal Information.
- Whether we have disclosed your Personal Information for a business purpose, and if so, the categories of Personal Information received by each category of third-party recipient.
- Whether we’ve sold your Personal Information, and if so, the categories of Personal Information received by each category of third-party recipient.
- Access. You can request a copy of the Personal Information that we have collected about you during the past 12 months.
- Deletion. You can ask us to delete the Personal Information that we have collected from you.
- Non-discrimination. You are entitled to exercise the rights described above free from discrimination. This means that we will not penalize you for exercising your rights by taking actions such as denying you services, increasing the price/rate of services, decreasing service quality, or suggesting that we may penalize you as described above for exercising your rights.
7.2 HOW TO EXERCISE YOUR RIGHTS
You can request to exercise your information, access and deletion rights by visiting our Preference Center. We will need to confirm your identity and California residency to process your information, access or deletion requests, and we reserve the right to confirm your California residency. Government identification may be required. If you wish to designate an authorized agent to make a request on your behalf, we will need to verify both your and your agent’s identities and your agent must provide valid power of attorney or other proof of authority acceptable to us in our reasonable discretion. We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
7.3 PERSONAL INFORMATION THAT WE COLLECT, USE AND SHARE
STATUTORY CATEGORY (including statutory definition)
WHAT WE COLLECT
Commercial Information. Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
· Data about what an individual has purchased from Braze (including tickets to Braze-sponsored events)
· Data about what an individual has downloaded from the Braze Website
Identifiers. Real name, alias, postal address, unique personal identifier, customer number, email address, account name, social security number, driver’s license number, passport number or other similar identifiers.
· Real name
· Unique customer number (assigned randomly by Braze)
· Email address
· Account name
Inferences. The derivation of information, data, assumptions, or conclusions from any other category of Personal Information to create a profile about a person reflecting the person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
May be derived from your:
· Device Data (as described in Section 1.2)
· Usage Data (as described in Section 1.2)
· Job title
· Company size
Internet or Network Information. Browsing history, search history, and information regarding a person’s interaction with an Internet website, application, or advertisement.
Usage Data (as described in Section 1.2)
Online Identifiers. An online identifier or other persistent identifier that can be used to recognize a person, family or device, over time and across different services, including but not limited to, a device identifier; an Internet Protocol (IP) address; cookies, beacons, pixel tags, mobile ad identifiers, or similar technology; customer number, unique pseudonym, or user alias; telephone numbers, or other forms of persistent or probabilistic identifiers (i.e., the identification of a person or a device to a degree of certainty of more probable than not) that can be used to identify a particular person or device.
· Device data (as described in Section 1.2)
· Unique customer number (assigned randomly by Braze)
Professional or Employment Information. This term is not defined in the CCPA, but likely includes any information relating to a person's current, past or prospective employment or professional experience (e.g., job history, performance evaluations).
· Current company
· Current job title
Audio, electronic, visual, thermal, olfactory, or similar information.
Audio and video recordings.
Protected Classification Characteristics. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
We do not intentionally collect this data, but certain characteristics may be revealed in identity data or other information we collect.
The business/commercial purposes for which we use these categories of Personal Information are described above in Section 2.2 (Use of Personal Data). The categories of third parties to which we these categories of Personal Information are described above in Section 2.3 (Sharing of Personal Data). We do not sell your Personal Information.
PART VIII. OTHER IMPORTANT INFORMATION
Our Services are not directed to individuals under the age of 16. We do not knowingly collect Personal Data from such individuals without parental consent and require our customers to fully comply with applicable law in the data collected from children under the age of 16. If you are a parent or guardian and believe your child has provided us with Personal Data without your consent, please contact us by using the information in the “How to Contact Us” section, below, and we will take steps to delete such Personal Data from our systems.
8.3 HOW TO CONTACT US
- If you would like to update your preferences with regards to our marketing communications to you, you can do this in our Preference Center.
- If you have a request regarding Braze’s processing (e.g., access, update or deletion) of your Personal Data (other than setting up your preferences for our marketing communications, which you can do in our Preference Center), please complete this FORM.
330 West 34th Street, 18th Floor
New York, NY 10001