Privacy Policy
Last revised: February 6, 2023
We value your trust and respect your privacy. We exist to support the
construction industry by simplifying and automating certain tasks for qualifying contractors for projects.
We have kept our policy simple, clear and concise in plain English. It
explains what we do, what information we collect, and why, so you can feel confident about using PledgX. Where
we have used legal speak, we’ve also provided some useful HINTS to help you decipher that legal speak.
However, please bear in mind that the Policy language itself is what is legally binding. We are committed to
meeting our obligations under Canadian data privacy laws, including the Personal Information Protection and
Electronic Documents Act, S.C. 2000, c. 5, and applicable provincial laws. If anything here is unclear,
please reach out to us. We sincerely hope this helps you better understand our privacy practices, and how we
operate. Thank you for joining the PledgX platform!
1. Scope
1.1 PledgX Companies
Our products and our Saas services, our Support, and any Additional Services we
offer through PledgX from time to time (“Service(s)”) are offered by PledgX Inc. or by companies related by
common ownership or control (collectively, “PledgX,” “we,” “us,” or “our”).
This privacy policy applies to:
- pledgx.com and its subdomains including sit.qualify.pledgx.com (the “Site”);
- Our application that incorporates this privacy policy; and
- Products and services branded with the PledgX name.
1.2 Business Partners
This privacy policy does not apply to products or services offered on or through
our Site or services by our Business Partners, third-party websites, or Service Providers including, among
others, Stripe, (“Business Partners”), which have their own policies. You should carefully read the privacy
policies and any terms and conditions applicable to such Business Partners. When you request products or
services from such Business Partners, you consent to us providing such Business Partners with information about
you necessary to fulfill or process your request.
HINT!
Sometimes, we work with other companies and organizations to bring our customers an
unbeatable experience. When this happens, their privacy policies apply and they’ll have access to some of your
Personal Information, but only as much as is absolutely necessary to provide the service you want.
1.3 Access to Minors
Because of the nature of the services we provide, we do not market our services to
people under the age of 18, nor do we knowingly collect information from people under the age of 18.
1.4 Personal Information
“Personal Information”, as used in this policy, means any information about an identifiable individual, which includes information that can be used on its own or with other information to identify, contact, or locate a single person. That’s what this policy is about – our collection, protection, use, retention, disclosure and other processing of Personal Information and your rights relating to these activities. This policy does not apply to information that is not considered Personal Information.
Specifically, we collect the following categories of personal information when you
interact with us:
- Contact Information (e.g., name, phone number, address, and email address);
- Geo-Location Information;
- Website, Mobile Application, and Email Usage Data (e.g., interactions with a website, application or advertisement);
- Device Information (e.g., internet protocol (IP) address, device type, unique identifier, app version, operating system, and network data);
- Login Information;
- Demographic Information;
- Professional or employment-related information (in Resumes); and
- Education information (in Resumes).
HINT!
We treat your personal information with the same respect we want our own to be
treated with. Given above is a list of categories of Personal Information that we collect.
1.5 Aggregate Data
We also compile, collect and create certain aggregate or anonymized data about our users. This is data or information that is not associated with or linked to your Personal Information, including information that has been aggregate or otherwise anonymized so that it no longer related to an identifiable individual. We may use and disclose aggregated or anonymized information in our public statements and to identify individuals that may be interested in our Services.
HINT!
What is aggregate data? “John Snow has 3 years of experience as a Project
Superintendent” is the Personal Information of John Snow, but “20% of PledgX users have 3 or more years of
experience as Project Superintendents” is aggregate data.
Understanding our customers is a huge part of building better experiences. To do this, we may look at and share customer data in summarized and anonymous forms, but rest assured, when we do, we cannot identify you or any customer personally.
2. Fair Information Principles
We use Personal Information to provide you and your business with the services.
Our Privacy Policy is based on the following ten fair information principles outlined by the Government of Canada:
- Accountability (s. 2.1)
- Identifying purposes (s. 2.2)
- Consent (s. 2.3)
- Limiting collection (s. 2.4)
- Limiting use, disclosure, and retention (s. 2.5)
- Accuracy (s. 2.6)
- Safeguards (s. 2.7)
- Openness (s. 2.8)
- Individual access (s. 2.9)
- Challenging compliance (s. 2.10)
HINT!
The government provides these 10 principles on collecting, storing, and using
personal information. By following this list, we cover all our bases so you can rest easy knowing your personal
information is safe.
2.1 Accountability
PledgX has named a Privacy Officer who is responsible for all things privacy at
PledgX. This includes our policies and procedures that are designed to keep your Personal Information safe.
Though the overall responsibility for ensuring our compliance with data privacy laws and this privacy policy
rests with our Privacy Officer, other individuals within PledgX have responsibility for the day-to-day
collection and processing of personal information and may be delegated to act on behalf of the Privacy
Officer.
2.2 Identifying Purposes
PledgX collects, uses, discloses, and otherwise manages Personal Information in a
variety of ways related to our Site and the services we provide. We’ve outlined these below in Section 2.2.1.
Your use of the services determines which information we collect and use. For example, Resumes are optional,
unless you’d like to attach a resume to a Contractor’s Qualification Statement, at which point we will need to
collect your resume to provide you with this service. Similarly, when you add a Project, the project owner’s
email is optional, but if you’d like us to get their Reference, this information becomes necessary.
HINT!
Many PledgX services and features simply wouldn’t work without some personal
information. Here’s why and how that information is collected, stored, and used.
2.2.1 Collection and Use
Either before or at the time of collection, we will identify the purposes for
which we plan to use your Personal Information. PledgX may collect, use, disclose or store Personal Information
to operate, provide, develop and improve our Services, including, among other things, in connection with:
- In order to provide you with the services you request, which may include the following:
- We collect information directly from you when you use or interact with our Site or our services. This Personal Information may relate to you, your employees, or individuals you interact with.
- We may also collect information from third parties when you connect your PledgX account to them. These integrations may pull data into or share data out of PledgX. In some cases, we use a service provider to connect you to a third-party service (e.g., when you pay for subscription to a Plan). When you connect your PledgX account with a third-party service, their terms and policies apply.
- We may also collect your name and email address from third parties when you sign up and login to our Site using single sign-on (SSO).
- To promote or offer you services, and to determine your eligibility for new products services we may offer from time to time.
- To offer you products and services from our Business Partners.
- To provide you with educational materials and guides relevant to the services you use.
- To contact you for the purposes of Service updates and system and account notifications.
- To provide you with support in connection with the services.
- We collect information and usage data whenever you interact with us, whether online, through a mobile application, or through an email. This data may include which of our websites you visit, what you click on, and when you performed those actions. These activities may be performed by us or a service provider acting on our behalf.
- We may use your Personal Information to prevent fraud or criminal activity, to protect or enforce the rights of PledgX, to safeguard the security of our users, PledgX and others and as required or permitted by applicable law.
We do not sell your Personal Information to other companies.
HINT!
We sometimes connect with other service providers to deliver the best products and
services. When this happens, your Personal Information also falls under their terms and policies. We will not
sell your details, ever.
2.2.2 Disclosure and Retention
We may disclose your Personal Information to other PledgX companies, our
affiliates, or to third parties with whom we have a written contract limiting the use and disclosure of your
Personal Information. We may share your Persoanl Information to support the products and services you request or
provide you information on products and services that may benefit you.
For example:
- PledgX Companies and Our Other Affiliates. We may provide information to companies related by common ownership or control. These companies may use this information to support the products and services you request or market additional products and services to you.
- Business Partners. We work closely with a variety of business partners that are not PledgX companies. We may offer products jointly with our Business Partners. We may share information that is related to such transactions with that Business Partners. We require all Business Partners to have written agreements with us that require them to safeguard your information and prohibit them from selling, retaining, using or disclosing your Personal Information for any purpose other than for the specific purpose of performing the contract.
- Service Providers. We may transfer (or otherwise make available) your personal information to third parties who provide services on our behalf. We have agreements with our service providers that require them to utilize appropriate physical, technical, and administrative controls to protect personal information and prevent them from using personal information for any purpose other than performing the service they provide. For example, we may use service providers to host our website and to process payments. Your Personal Information may be maintained and processed by these third parties in other jurisdictions. We use service providers in Canada and the United States. When your Personal Information is in another jurisdiction, it will be subject to their laws. We only share the information these service providers need to perform the service and we don’t authorize them for any other use or disclosure of personal information.
- Persons Who Acquire Our Assets or Business. If we sell or transfer any of our business or assets (including insolvency or bankruptcy proceedings), certain information about our clients may be a part of that sale or transfer. In the event such sale or transfer results in a material change to this privacy policy, we will notify you. The notification procedure will be the same as the procedure we use to notify you of a change to this privacy policy as described below.
- Responses to Legal Requests. We may disclose your Personal Information when we have a good faith belief that such disclosure is required or permitted by law pursuant to a legal request. This may occur in connection with a court order, legal process, or other judicial, administrative or investigative proceeding that produces a request for information from us. In certain situations, we may be required to disclose your Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Protection of PledgX and Others. We may disclose your Personal Information when we believe that disclosure is necessary to protect either your or our rights and safety. We may disclose your Personal Information to federal, state, provincial, or local officials in order to, and only to the extent necessary, inform the official of activities that may constitute, or may have constituted, a violation of any criminal law or to assist the official in investigating or prosecuting a violation of criminal law.
- Aggregate Data. We may disclose aggregate information compiled using information that does not identify you individually or personally. This may include, for example, the total number of visitors from a particular geographic area.
HINT!
There are times when personal information does need to be disclosed. You have the
right to know about these situations, so we’ve listed them here. Online services like PledgX need to interact
with other business partners or service providers in order to work properly. When this involves sharing personal
information, we’re vigilant about ensuring the information is managed securely and responsibly. If the ownership
of PledgX changes, customer information may be included in the transfer of ownership. Rest assured, we’ll let
you know if that change causes material updates to these policies. When laws require us to share customer
information with the proper authorities, we’re obligated to do so. Some summarized, anonymous information may be
shared publicly, but could never be connected to individual customers.
2.3 Consent
2.3.1 Submitting Your Personal Information
By submitting your Personal Information, you are consenting to our collection,
use, and disclosure of this information.
We will seek consent for the use or disclosure of Personal Information at the time
of collection. However, additional consent will be sought after the Personal Information has been collected if
the Personal Information is required for a new purpose.
In certain circumstances, obtaining consent may be inappropriate. The federal
Personal Information Protection and Electronic Documents Act and provincial privacy laws provide for exceptions
where it is impossible or impractical to obtain consent. We will comply with the applicable legal requirements
in all cases.
2.2.2 Submitting the Personal Information of Others
When you submit the Personal Information of your customers or employees to us, you
are responsible for informing such customers and employees about PledgX, and for obtaining any necessary consent
or authority from them, including informing them that PledgX operates within Canada and utilizes service
providers within the United States.
You may also choose to seek reference from someone using our Get a Reference
feature. We may ask for that person’s name and contact information, including email address. We will send them a
single invitation email to provide their reference on you or your company. Please ensure that you only submit
email addresses of individuals or businesses with whom you have a relationship and who would want to receive the
message.
2.3.3 Closing your PledgX Account
At any time and without penalty, you can close your PledgX account and stop using
our services. Please ensure you complete the account closure process which includes sending an account closure
request email to support@pledgx.com.
Otherwise, your account may not be closed.
HINT!
We’d be sad to see you go, but if you do, we won’t make closing your account a
hassle. Just don’t forget the confirmation email to make it official.
2.3.4 Email and Communications Consent
At any time, you can opt-out of commercial email communications from us by
clicking on the unsubscribe link in such emails, or via the Email Preferences settings in your account. Certain
non-commercial communications may still be sent to you that are required to provide you with our services. For
example, system notifications, major product changes, changes to our Terms of Use, or other news that we believe
will materially affect how you interact with PledgX.
The only way to completely stop all emails from PledgX is to close your account as
outlined above.
HINT!
We like to keep in touch, and promise we won’t overdo it. Still, if you’d ever like
to opt-out, we’ve made it easy.
Heads up: If you do opt out of our marketing emails, we may still send you important,
non-marketing messages.
2.4 Limiting Collection
PledgX limits the amount and type of Personal Information we collect to that which
is necessary for our purposes as described in s. 2.1.1. The services you use will determine most of the
information PledgX collects. We’ll also provide you the option of sharing additional information to enhance your
PledgX experience.
PledgX may also use third-party services to supplement or enrich our understanding
of our customers. This includes cross-referencing information like a name, business name, email address or IP
address in third-party databases and using the information there to improve our understanding of you and your
business.
Some of the services allow you to provide access to your PledgX account to other
authorized users, which we call “collaborators”. Collaborators have access to information in your PledgX
account, including Personal Information, and may perform various tasks on your behalf. You take full
responsibility for any collection, use or disclosure of your Personal Information by your collaborator(s).
To provide access to your account to a collaborator, you must provide the
collaborator’s name and email address. We will send them a single email inviting them to the Site. PledgX only
uses this information to invite your collaborator. Please ensure that you only submit email addresses of
individuals or businesses that you have a relationship with and who would want to receive the message. The
collaborator may contact us at privacy@pledgx.com to request that we remove their name and email address from our
database. This will remove the collaborator’s ability to access to or perform tasks on your behalf in your
PledgX account.
HINT!
We only collect the personal information we need to deliver the services you want.
What we collect depends on which services you use. You can allow someone else to access and use your PledgX
account. Be vigilant, as you are responsible for how that person uses the information they can access.
2.5 Limiting Use, Disclosure and Retention
We will use and disclose your Personal Information as described in this policy.
Some PledgX employees may have access to your Personal Information outside of Canada and the US. Regardless of
where a PledgX employee is physically located, your Personal Information is protected by the safeguards
described in this Privacy Policy.
We will retain your Personal Information for the period reasonably necessary to
fulfill the purposes outlined in this policy, unless a longer retention period is required by law. To be clear,
that means we’ll retain your Personal Information while you have an active account, and afterward if we need to
do so to meet our legal obligations. If you choose to close your PledgX account, we will destroy your Personal
Information within 60 days unless we are otherwise legally obliged to keep it longer consistent with our
retention policies or if we determine it is necessary to defend against legal claims.
HINT!
We take our responsibilities about using, disclosing, and storing your personal
information seriously. With rare legal exceptions, your Personal Information will be destroyed within 60 days of
closing your account.
2.6 Accuracy
PledgX relies on you to provide us with information that is accurate, complete,
and up to date. You can request updates or corrections of any inaccuracies in your Personal Information at any
time by contacting us at the contact information listed in Section 2.10 of the policy. We will respond to your
request within a reasonable timeframe.
HINT!
It’s up to you to ensure the information you provide PledgX is accurate. If you need
to make changes, just let us know.
2.7 Safeguards
PledgX uses a combination of reasonable and appropriate safeguards designed to
protect your Personal Information. These safeguards include administrative controls (things like policies,
procedures, and training), technical controls (things like encryption, firewalls, and secure coding frameworks),
and physical controls (secured hosting environments). If you have questions about security on our Site, you can
contact us at info@pledgx.com.
Nevertheless, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we
cannot guarantee absolute security.
We ensure that any third party acting on our behalf maintains reasonable and
appropriate safeguards in respect of your Personal Information. Additional information about our third parties’
privacy practices is available upon request.
You are also responsible for helping to protect the security of your Personal
Information. For instance, never give out your email account information or your password for the Services to
third parties. Our team will never request your password or PIN, and we ask that you never post account or
credit card numbers in any of the documents you upload to our platform.
HINT!
From policies to software to physical measures, we do everything we can to protect
your Personal Information. If you’d like more details, feel free to reach out. When we work with another
partner, we make sure they’re vigilant about protecting your Personal Information too.
2.8 Openness
This policy outlines our privacy practices. If you have questions about it, please
contact our Privacy Officer at privacy@pledgx.com.
HINT!
We have someone to help if you have any questions about this document, so reach
out.
2.9 Individual Access
You may access, update and correct inaccuracies in the Personal Information in our
custody or control at any time, subject to limited exceptions prescribed by law. You can download or export data
you input into the Site at any time, or correct inaccuracies by simply logging in to your account and making the
necessary changes.
You can also request access, corrections or updates to all your Personal
Information, including information not available through your account, by contacting us as set out in Section
2.10 in this privacy policy. We may request certain Personal Information for the purposes of verifying the
identity of the individual seeking access to their personal information records.
2.10 Compliance
If you have any questions, concerns, or complaints about our privacy practices or
this policy, you can contact us at:
PledgX Inc.
Privacy Officer
295 Hagey Blvd, 1st Floor, Waterloo, ON N2L 6R5, Canada
Email:
privacy@pledgx.com
We will investigate all written complaints we receive. If we find a complaint to
be justified, we will take appropriate measures to try to resolve it.
If you're not satisfied with our response, you have the option of contacting the Office of the Privacy Commissioner of Canada.
HINT!
If you have any questions or concerns about our privacy, we have someone to listen
and help. Here's how you can get in touch with that person.
3. Additional Details
3.1 Public Content and Social Media
PledgX may introduce public forums and blogs that you can interact with. Any
information submitted there may be read and collected by anyone. You may request removal of Personal Information
from forum or blog posts and comments by contacting us at privacy@pledgx.com.
If you provide us with a testimonial, with your consent we may post it on our Site
or in other materials and media, along with your name. If you want your testimonial removed, please contact us
at privacy@pledgx.com.
You may engage with us through social media sites. When you engage with us on
these sites, we may have access to certain information about your account (e.g., name, username). These sites
may collect your IP address, how you’re engaging with us, and may use cookies to enable the site to function
properly. We may use this information to personalize your experience and to provide you with other products or
services you may request.
HINT!
When you post or provide information to somewhere like a comments section or forum,
other people may see it. If you’d like this information removed, get in touch and we’ll get it done. Same thing
goes for testimonials you may have provided. If you’d like it removed, just ask.
3.2 Additional Information on Service Providers
We may use services provided by third-party platforms (such as social networking
sites) to serve targeted ads on such platforms to you or others, and we may provide a hashed version of your
email address or other information to the platform provider for such purposes. To opt-out of the sharing of your
Personal Information with such platforms, please send an email to privacy@pledgx.com.
HINT!
When third-parties are involved, we keep your details anonymous
3.3 California Consumer Privacy Act
If you live in California, you may have the following rights over your Personal
Information:
- For the period covering the 12 months preceding your request, you may request that we disclose to you the categories and specific pieces of information collected about you, the categories of sources from which we collected that information, and the purposes for which your Personal Information was collected.
- You may also request that we delete information we collected from you.
- You have the right not to be discriminated against for exercising your rights over your Personal Information.
As stated above, we do not sell your personal information.
You may submit a request to exercise your rights by emailing privacy@pledgx.com. When receiving a
request, we will collect personal information to verify the identity of the individual making the request.
Government identification may be required.
HINT!
Some states have different laws. Here’s some of the ways things work in
California.
3.4 General Data Protection Regulation
Our services are hosted on servers located in Canada and the United States. We
also use service providers located in Canada and the United States to provide you with our services. The
transfer of your Personal Information, and the information you input into our services, to Canada and the United
States is necessary to deliver our services. Please be aware that the laws in Canada or the United States may
not provide the same level of protection to your personal information as your home country.
We have updated documentation, internal policies and procedures, and agreements to
align with GDPR requirements applicable to us.
You should consult with your legal professional to understand your GDPR compliance
obligations. If you are deemed a data controller, you are responsible for ensuring that you have a legitimate
basis for the collection, processing, and transfer of the personal data you input into our services. By using
our services, you represent to us that you have met your GDPR compliance obligations.
If you are accessing our services from the European Union, you may have certain
rights regarding the processing of your personal information. For instance, if the information you provide
contains special categories of personal data, we will only process it with your explicit consent, which can be
withdrawn at any time. You may have the following additional rights:
- You have the right to access and correct your Personal Information.
- You have the right to obtain erasure of your Personal Information, object to or restrict processing activities related to your Personal Information, or withdraw your consent to the processing of your Personal Information after you have provided it.
- You have the right to obtain a copy of your Personal Information in a structured, commonly used, machine readable format.
- You have the right to lodge a complaint with your local supervisory authority regarding our processing of your Personal Information.
To exercise your rights, or if you otherwise have questions about the processing
of your personal data, you may contact us at privacy@pledgx.com.
HINT!
Most of what we do happens in Canada and the United States. So, information you
provide will likely pass through these two countries. Like California, the European Union provides residents
with unique rights and responsibilities.
3.5 Visiting the Site and Using the Mobile Apps
In general, you can visit the Site without telling us who you are or submitting
any Personal Information. However, we and/or our service providers (such as Google Analytics) collect IP
(Internet protocol) addresses from all visitors to the Site and other related information such as page requests,
browser type, operating system, and average time spent on our Site. When you use any of our mobile apps, we also
collect device type, operating system, unique device identifier, and date and time stamp. This information is
used to help us understand the activity on, and to monitor and improve, our Site and mobile apps.
HINT!
To help make our apps and website the best they can be, we look at information on how
they’re used.
3.6 Cookies, Tags, and Web Beacons
We treat the personal information of everyone who comes to our Site in accordance
with this Privacy Policy, whatever their “do not track” setting. While we do not respond to web browser “do not
track” signals, we give you choices about receiving promotional offers. You can exercise your choices as
described in this privacy policy.
Technologies such as cookies, web beacons, tags and scripts are used by PledgX,
our advertising and analytics service providers (such as Google analytics), and affiliates to analyze usage
trends, administer the Site, and to gather demographic information about our user base as a whole.
A cookie is small piece of data that our Site can send to your browser, which may
then be stored on your device so we can recognize you when you return. We use cookies for session tracking to
make it possible to navigate the secure environment inside our Site. These cookies (1) may let us know who you
are, (2) are necessary to access your account, and (3) will give us information that we can use to personalize
our Site according to your preferences. You can control the use of cookies in your browser. If you disable
cookies, you will not be able to access your account or take advantage of all of the features of the Site and
mobile apps.
HINT!
Although we track web activity, you can choose to receive or not receive promotional
offers from us. As always, we only collect information as required and to improve what we offer. Cookies (not
the kind you eat) are a helpful way of providing you with a smooth experience. You can turn cookies off in your
browser but the site may not work properly if you do.
3.7 Notification of Privacy Policy Changes
We may update this privacy policy to reflect changes to our information practices.
If we make any material changes we will notify you by email (sent to the e-mail address specified in your
account) or by means of a notice on our website prior to the change becoming effective. We encourage you to
periodically review our privacy policy for the latest information on our privacy practices.
HINT!
It’s a good idea to check in on this policy here and there for updates. If the
updates are significant, we’ll let you know.
3.8 Updating or Deleting your Personal Information
You may update or delete your Personal Information through your PledgX account. We
may maintain a copy of the information in our records. Additionally, if you request that we permanently delete
your account or information, we may still retain and use your Personal Information as reasonably necessary to
comply with our legal obligations.
HINT!
You’re free to update or delete your Personal Information. We will only hang on to
anything we legally need to keep.