Privacy Notice

CMap Software Limited (CMap, we, us, our) is a SaaS business providing professional services companies with cloud software which helps them to win more work and deliver it more profitably. Processing customer information is a fundamental part of the service we provide, and we take the privacy of the personal data you entrust us with very seriously.

This Privacy Notice explains how we collect, use, and protect your personal data, whether you are a customer, website visitor, or other user of our services. It also outlines your rights under relevant data protection law, including your right to make a complaint to us.

CMap Software Limited is a company registered in England and Wales (No. 09732010) with its registered office at Arkwright House, Parsonage Gardens, Manchester, M3 2LF, United Kingdom

We are registered with the Information Commissioner’s Office under registration number ZB185577. If you have any questions about this Privacy Notice, please get in touch using the contact details below.

Application of this Privacy Notice

CMap is the controller of the personal data described in this Privacy Notice. It applies to our practices in relation to the collection, storage, usage and disclosure of data that relates to identified or identifiable individuals, who:

•      are visitors of our website www.cmap.io, which is owned and controlled by CMap; or

•      interact with us in relation to our services via oursales and marketing channels (e.g. events, webinars).

We are not the controller of personal data held in the CMap application, or in any third party applicationsor software that integrate with the services through it, or in any other thirdparty products, services or businesses. Where a customer uses our software toprocess information about their own staff, contractors or clients, that customer is the controller and CMap acts as their processor, on their instructions and under our Data Processing Agreement. This Privacy Notice does not cover that data.

If you are a CMap customer and have any questions about the way in which we collect, use, and protect the personal data of users of the CMap application and the personal data which theymay process on it, please see our Data Processing Agreement.

If you do not have a relationship with CMap, but believe that a CMap subscriber has entered your personal data into our websites or services, you will need to contact that organisation with questions about your personal data (including where you want to access, correct, amend, or ask them to delete it). In those circumstances the subscriber, not CMap, is the controller of that data, and we do not have access to that data.

Data collection

When you visit our website or interact with us in other ways we collect personal data about you in a number of different ways. Where we do this, we will be acting as controller of that personal data. These ways of collecting personal data can be broadly categorised as follows.

Data you provide to us directly: When you visit or interact with our website, or engage with oursales and marketing teams in calls, email exchanges or similar during thecourse of our direct marketing activities we might ask you for (or you may provide us with) your personal data. For example, if you sign up on our website for a demo or request other information we would need your contact information andother incidental information to allow us to understand your use case, respond to any questions you may have, offer you support and to set you up with a demo account.

We may also record phone calls or online meetings with our sales and marketing team or support and customer success team for the purpose of tracking and analysing them in order to make improvements to our services. We will tell you at the start of the call or meeting if it is being recorded.

Data we collect automatically: When you visit or interact with our website and certain other marketing materials we send to you, we may collect or record certain technical data aboutyou automatically, such as:

•      IP address and device type;

•      address of the web page visited before using thewebsite or services;

•      browser type, settings and plugins; and

•      language preferences.

We also collect information when you navigate through our websites, including which pages you’ve looked at and which links you’ve clicked. Some of this is done through the use of our own cookies and similar technologies and some through the use of third-partyservices. If you want to find out more about the types of technology we use, why we use them, and how to control them, you can find this in our CookiePolicy.

We use third-party analytics and marketing intelligence providers to identify the organisation associated with your IP address, and, where permitted by law, we may also receive businesscontact information associated with visitors to our website. We do this on the basis of our legitimate interests in business-to-business marketing. You can object to it at any time – see Opting Out below.

Data we receive from third parties: We may receive personal data from third parties, if, for example, you have attended webinars or other events organised by other organisations. We also make use of information which is available publicly, or which a third party otherwisehas the right to share with us, for example, social media sites such as LinkedIn and business data providers.

We use this information to supplement the personal data we already hold about you, in order to better inform, personalise and improve our services, to validate the personal data youprovide, and to offer you services which we believe will be of interest to you. Where we obtain your personal data from a third party rather than from you, we will tell you within one month of obtaining it, or when we first contact you if that is sooner.

The personal data we may collect will include your full name, company name, job title, telephone number, email address, business address, social media profile links (LinkedIn etc), the marketing and website interaction data described above, and any other information you choose to provide to us.

If we don’t collect your personal data, we may be unable to provide you with all our services, and some functions and features on our websites may not be available to you.

How we use personal data and our lawful bases

We use the personal data covered by this Privacy Notice in connection with managing our relationship with customers, potential customers and other interested stakeholders through marketing campaign updates, direct marketing activities, servicing newsletter sign-ups and demo requests, responding to enquiries for information or support, and requesting and receiving feedback.

The information is either needed to fulfil your request, to carry out business development activities and direct marketing campaigns, or to enable us to provide you with a more personalised service. You don’t have to disclose any of this information to browse our sites.

We will only process your personal data where we have a lawful basis for doing so. The table below sets out what we use your personal data for and the lawful basis we rely on in each case:

What we use personal data for Our lawful basis
Operating and providing our website and services, and responding to enquiries, demo requests and support requests Performance of a contract, or taking steps at your request before entering into a contract; our legitimate interests in responding to enquiries
Publicising and marketing our services to prospective and existing customers Our legitimate interests in promoting our business to other businesses; consent where required by law
Recording calls and online meetings for quality, training and service improvement Our legitimate interests in improving the quality of our services; consent where required
Improving our content and services to ensure they remain relevant and current Our legitimate interests in developing and improving our business
Enhancing our security measures and detecting and preventing illegal activity Compliance with a legal obligation; our legitimate interests in protecting our business, staff and customers
Handling requests to exercise your data protection rights, and investigating and responding to data protection complaints Compliance with a legal obligation
Complying with our other legal, regulatory, tax and accounting obligations Compliance with a legal obligation

Where we rely on our legitimate interests, we have assessed that those interests are not overridden by your interests, rights and freedoms. You can ask us for a summary of that assessment using the contact details below.

Automated decision-making and profiling

We use profiling in a limitedway for marketing purposes, for example to understand which of our services are likely to be of interest to the organisation you work for. You can object to this at any time.

We do not currently make decisions about you by solely automated means (i.e., without any humaninvolvement) where those decisions have legal effects for you or similarly significant effects. If we introduce any such decision-making, we will update this notice and put in place the safeguards that data protection law requires for decisions of that kind (Articles 22A to 22D of the UK GDPR). Those safeguards include telling you that a significant decision has been taken about you by automated means, giving you the opportunity to make representations about it, obtaining human intervention, and contesting the decision.

Who we share personal data with

We will never sell or rent personal data to other organisations.

We may share personal data withthe following categories of recipient:

•      our group companies, subsidiaries and affiliatedcompanies;

•      service providers who process personal data on our behalf, including cloud hosting and infrastructure providers, IT support and security providers, customer relationship management and marketing automation platforms, analytics and marketing intelligence providers, email and mailing providers, customer support providers, and payment processors;

•      our professional advisers, including auditors, lawyers, accountants and insurers;

•      event partners, where we run an event in partnership with other named organisations — we will be very clear about what will happen to your data when you register, and will only share the data required insupport of the event;

•      an actual or potential buyer (and its agents and advisers), where we merge with or are acquired by another organisation, or where our business or assets are transferred; and

•      regulators, law enforcement agencies, courts and other public authorities, where we are obliged to share personal data by law or for the purposes of national security, taxation or criminal investigations.

We may also share personal dataif we receive a complaint about any content you have posted or transmitted toor from one of our sites, to enforce or apply our Terms and Conditions, or where we believe we need to do so to protect and defend our rights, property or the personal safety or rights of our staff, customers or visitors, and forother lawful purposes.

We may disclose aggregate statistics about our site visitors, supporters, customers and sales to describeour services and operations to prospective partners, advertisers and otherreputable third parties and for other lawful purposes, but these statistics will not include any information that identifies you.

International data transfers

When we share data, it may be transferred to, and processed in, countries other than the country you live in – such as the United States, where we have a subsidiary company. These countries may have different data protection laws.

Where your personal data is transferred out of the United Kingdom or the European Economic Area, it is protected in one of the following ways:

  • the country has been formally recognised as providing an adequate level of protection — by the UK Government for     transfers from the UK, or by the European Commission for transfers from the EEA;
  • the recipient is in the United States and is certified under the EU–US Data Privacy Framework and, for transfers from     the UK, its UK Extension (the "UK–US data bridge"); or
  • we have put in place approved contractual protections, the UK International Data Transfer Agreement or the UK     Addendum for transfers from the UK, or the European Commission's Standard Contractual Clauses for transfers from the EEA, together with any additional measures needed.

Data retention

We keep your personal data only for as long as we reasonably need it for the purposes we collected it for. In deciding how long that is, we consider how much data there is and how sensitive it is, the potential harm if it were lost or misused, whether we can achieve the same purpose another way, and any legal, accounting or reporting requirements that apply. On that basis, how long we keep each type of information is determined as follows:

Type of personal data How we decide how long to keep it
Prospect and marketing contact data By reference to your engagement with us. We review these records at set intervals and delete or anonymise them where there has been no interaction for a sustained period. If you unsubscribe or object, we act on that straight away.
Enquiry, demo and support records For as long as we need them to deal with your enquiry and any follow-up, and then for a further period reflecting the time within which a related claim could be brought.
Call and meeting recordings For as long as we need them for the quality, training or service improvement purpose the recording was made for. They are deleted once that purpose has been met, unless they are needed for an ongoing matter.
Data protection complaints and rights requests For as long as we need them to show how we handled the matter, taking into account the period within which it could be escalated to the Information Commissioner's Office or otherwise challenged.
Website and cookie data As set out in our Cookie Policy, which gives the lifespan of each cookie we use.
Suppression records For as long as we need them to make sure we do not contact you again.

 

If you ask us to have no further contact with you, we will keep some basic information on a suppression list to avoid sending you unwanted materials in future in order to comply with your request.

How we secure your personal data

We take the security of all the data that we collect, hold and process very seriously. We implement appropriate technical and organisational measures to safeguard your personal data against unauthorised access, loss, or misuse. These include encryption, access controls, and regular security audits. To help demonstrate this commitment, our information security management system is certified to the internationally recognised standard ISO/IEC 27001 and under the UK’s National Cyber SecurityCentre’s Cyber Essentials Plus scheme.

To find out more about ourapproach to data security, visit our Data & Security page.

Communications

Marketing. We may contact you with direct marketing communications to demonstrate how our services can support you. We may send you information when you have not directly requested it; this only happens where we have identified you as being of potential interest to the services we offer. In any circumstance, our interests do not override your rights, and you are free to unsubscribe from our marketing and tohave your data deleted.

As our software is only sold and used business to business, our direct marketing activities are governed byspecific legislation, including the Privacy and Electronic Communications (ECDirective) Regulations 2003 in the UK, CAN-SPAM in the United States, andDirective 2002/58/EC in the EU, commonly known as the e-Privacy Directive.

Service Changes. We may contact you in relation to any changes to our services or terms.

Opting Out. If you would like to change the way you hear from us, or you no longer wish to receivedirect marketing communications from us, you can click “unsubscribe” in any ofour emails, use the form on our Contact Us page, tell us during any telephone conversation, or contact us using the details below. We will always act on an objection to direct marketing.

What are your rights?

You can exercise your rights under applicable data protection law by contacting us using the contact details below. We may require additional details to confirm your identity before we are able to act on any instructions. We will let you know if this is the case.

Your rights include the right to:

•      be told how we use your personal data (right to be informed);

•      request a copy of the information we hold about you (right of access);

•      have information we hold about you corrected if it is wrong (right of rectification);

•      ask us to stop using your information (right to restrict processing);

•      ask us to remove your personal data from our records (right to erasure, sometimes called the ‘right to be forgotten');

•      object to our processing of your information, including for direct marketing purposes (right to object);

•      obtain and reuse your personal data for your own purposes (right to data portability);

•      not be subject to a significant decision based solely on automated processing, and to the safeguards described above;

•      withdraw your consent at any time, where we rely on consent to process your personal data;

•      make a complaint to us about how we have handled your personal data (see “Complaints Procedure” below); and

•      make a complaint to the Information Commissioner’s Office.

We will respond to a request to exercise your rights without undue delay, and in any event within one month of receiving it. If your request is complex, or you have made a number of requests, we may extend that period by up to two further months; we will let you know if that happens and explain why. When we respond, we will also remind you of your right to complain to us and to the Information Commissioner’s Office.

Complaints Procedure

If you have concerns about how we have collected, used, stored, shared or otherwise processed your personal data, you have the right to raise a data protection complaint.

Complaints should be submitted via privacy@cmap.io, but you can also raise a complaint by telephone, in writing to our registered address, or by using the form on our Contact Us page. We will treat a complaint as a data protection complaint however it reaches us, and whether or not you call it one. Please provide as much detail as possible, including what happened and when, so that we can look into it properly.

We will then:

•      acknowledge receipt of your complaint within 30 calendar days;

•      investigate your concerns fairly, objectively and inaccordance with applicable UK legislation;

•      maintain the confidentiality of your information, sharing it only where necessary to investigate and resolve your complaint; and

•      communicate the outcome of our investigation without undue delay, and advise you of any action we intend to take.

Where we need additional information to assist the investigation, we may contact you.

If your complaint relates to personal data held about you in the CMap application by one of our customers, we will tell you and, where we are able to, point you to the right organisation, because that customer rather than CMap is the controller of that data.

If you are not satisfied with the outcome of our investigation, or believe we have not handled your personal data in accordance with the law, you have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection. If you are in the EEA, you can also complain to the data protection authority in your country.

Contact details for the UK’s ICO are:

•      Address: Information Commissioner's Office, WycliffeHouse, Water Lane, Wilmslow, Cheshire. SK9 5AF.

•      Telephone: +44 (0) 303 123 1113

•      Website: ico.org.uk

Updates and amendments

We may make updates to thisnotice over time. The current version will be published on our website and is effective from the date shown at the top of this notice. Where changes are significant, we will take reasonable steps to bring them to your attention.

Previous Privacy Notice October 2024

How to contact us

If you wish to talk through anything in our Privacy Notice, find out more about your rights or obtain acopy of the information we hold about you, please contact us via the followingmethods:

•      By telephone: (UK) +44(0)1625 521 000

•      By email: privacy@cmap.io

•      By post: CMap Software - EMEA Enquiries. CMap Software, 6th Floor, Arkwright House, Parsonage Gardens, Manchester, M3 2LF, United Kingdom

Please note that calls may be monitored or recorded.