
![]() |
|
Information |
govService Admin Privacy Policy | |
govService-Admin-Privacy-Policy |
Article Details |
|
Data Category | Examples | Purpose of Processing |
Agent String | Location, IP address, user agent, sign in information | To inform you of any technical issues with your account, the application in general, or in the event your issue cannot be immediately resolved. Your agent string is collected for internal auditing and support purposes. |
Identifiers | Work email, name, phone # | |
Query Data | Questions and responses | To assist with your query. |
Session Recordings | Screen capture video and audio | To replicate issues and to best assist with potential fixes, this may include helpdesk support queries that include citizens/customer information. |
We will use your personal data only when the law allows us to. Most commonly:
Generally, we do not rely on your consent other than for sending marketing communications. Please see our US marketing privacy statement and our UK marketing privacy statement. In that case we will offer unsubscribe links on each communication, and you have the right to withdraw consent at any time.
When applicable, our legitimate interests may include the following:
We will only use your personal data for the uses and purposes set out above, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original uses and purposes. If we need to use your personal data for an unrelated purpose, we will notify you and will explain the legal basis which allows us to do so.
Back to Top
We are not generally relying on your consent, as stated above. Where we need to collect personal data by law or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform our obligations under the contract we have or are trying to enter into with you (for example, to provide you with services). In this case, we would not be able to provide you the access to use the service and may have to cancel a product or service you have with us. We will notify you if this is the case at the time.
Back to Top
We do not use your personal data for decisions based solely on automated processing.
Back to Top
Yes. We share your personal data with the following categories of recipient:
No. We do not buy and sell personal data.
Back to Top
Yes. Granicus complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
We are responsible for the processing of personal data we receive or subsequently transfer to a third party acting as an agent on our behalf. We will comply with the Data Privacy Framework Principles for all 6 onward transfers of personal data from the EU, and the UK, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to Data Privacy Framework, we are subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
In addition, Granicus commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs), and the UK Information Commissioner’s Office (ICO),the Gibraltar Regulatory Authority (GRA) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, and the UK Extension to the EU-U.S. DPF. You may engage such authorities if you have concerns regarding our adherence to the Data Privacy Framework Principles or any applicable privacy law or regulations. We will respond directly to such authorities regarding investigations and resolution of complaints. Under certain conditions, more fully described on the Data Privacy Framework website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Back to Top
Granicus govService is hosted within our database service provider with both live and backup replication within EU and UK datacenters.
The only instance when data is stored outside of the EU or UK is when you contact our customer support team and provide them your information. We will try and limit this to the minimum necessary for a given purpose, and ensure we have appropriate protections in place for your privacy that correspond with the highest global standards, such as the EU GDPR equivalent level protections wherever you or your data may be on the globe.
Granicus’ compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF deems the organization to provide adequate privacy protection, which is a requirement for the transfer of personal data outside of the European Union under the EU General Data Protection Regulation (GDPR), and outside of the United Kingdom under the UK Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR).
Back to Top
We are committed to ensuring that your personal data is secure. In order to prevent unauthorized access, loss or disclosure, we have put in place security controls that reduce the risk of a security breach of your personal data.
If a data breach does occur, we will do everything in our power to limit the damage. In case of a high- risk data breach, and depending on the circumstances, we will inform you about remedial actions to prevent any further damage.
We also use other technical controls, including user confidentiality agreements and Data Loss Prevention (DLP) solutions locally, to secure data and keep it in appropriate systems. Access to customer data occurs on a case-by-case basis and is strictly controlled and limited to a small number of individuals based on their roles.
Employees and temporary workers are required to follow policies, procedures, and complete confidentiality training to understand the requirement of maintaining the confidentiality of customer information. If they fail to do so, they are subject to disciplinary action. All employees are required to complete privacy and security training. We also offer a wide variety of other training to all employees and temporary workers to help us achieve our goal of protecting your personal data.
Back to Top
Your data will not be retained for a period longer than necessary for the purposes above. Where there is a risk of a legal claim, we may also keep data for the relevant statutory period. In many cases, this means that your data will be retained for the duration of our contract with our client, plus any legal statutory period. Information retained during any legal statutory period will be minimized to only the data strictly necessary to resolve any legal claims that may arise.
When we no longer need to use your personal data, we will remove it from our systems and records or take appropriate steps to properly anonymize it so that individuals can no longer be identified from it (unless we need to keep your personal data to comply with any legal or regulatory obligations).
Back to Top
To exercise any of the following rights, please contact support@granicus.com. Under certain circumstances, by law you have the right to:
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Back to Top
The CCPA (California Consumer Privacy Act) will apply to your data. This legally gives you slightly less rights than the UK GDPR does (it only covers the last 12 months of data and gives some rights such as access, deletion, opt out of sale, etc.). But don't worry, we treat all our customers the same, so you can still use all the other GDPR rights that we mention in this policy.
Some timescales are different, and we'll notify you of them if you want to use the rights. In addition, you can bring your complaints to a regulator, in this case the California Attorney General.
Importantly, the CCPA requires us to notify if we buy or sell your data for any benefit, which we do not do.
We collect the same category of data irrespective of your location (whether you reside in the EU, UK or California) and for the same purpose. The collected data is shared only with the third parties mentioned in section #8 of this policy.
Back to Top
We will not discriminate against you for exercising any of your rights under applicable law (such as GDPR, CCPA etc.). Unless permitted by the applicable laws, we will not:
Yes. We do use online tracking technologies, such as cookies, but we only place cookies on your device that are essential to allow us to operate our services, and do not use these for tracking your other internet use. These allow us to know that you are logged in and the same unique user when you go to each web page. Critically, we do not use these tracking technologies for online targeted behavioral advertising. You can control the use of cookies at the individual browser level, but if you choose to disable cookies, it may limit your use of certain features or functions on our website or service.
Currently, various browsers offer a “do not track” or “DNT” option and the global privacy control which sends a signal to websites visited by the user about the user's browser DNT preference setting. We will do our best to respect such signals we receive, and as required where placing tracking technologies on your device, notify you what and why.
Back to Top