Your personal data is important to us

Vortx, Inc. is a US based organization which builds, sells, on-boards and hosts a number of payment (eCommerce) applications. We offer the ability for our hosted clients to capture, store and protect data under contract with their shoppers.

FOR EU AND SWISS INDIVIDUALS WHOSE DATA WE HANDLE

Vortx, Inc.  (“Vortx,” “we,” or “us”) complies with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland transferred to the United States pursuant to Privacy Shield.  Vortx, has certified that it adheres to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/

Vortx is subject to the investigatory and enforcement authority of the US Federal Trade Commission.

What we need to collect

We only collect basic personal data about you which does not include any special categories of information or location-based information. This does however include name, address, email etc. We collect only the data that is necessary for us to contract with you, when you purchase goods or services from us. Our company will be what’s known as the ‘Controller’ of the personal data you provide to us.

Why we need it

We need to collect data that is contractually required for us to process an online payment, to deliver your purchased product and to meet our statutory reporting obligations. In such cases, we don’t need to get your consent (since we can’t fulfill our contract without the data) but we still want you to know how carefully we manage the protection of that data. We will not collect any personal data from you that we do not need in order to provide and oversee this service to you.

What we do with it

All the personal data we process is processed by our staff, and, for the purposes of IT hosting and maintenance this information is located on servers that are located in the United States.   We will only share your data with third parties who are acting as our agents, and without exception these agents will be providers of products and services (or trials thereof) for which you have subscribed, as follows:

  • When you purchase a third-party plug-in or service, we need to pass your data to the author
  • When you sign up for a trial of a service offered by a third party, we need to pass along your data
  • If we are carrying out third-party PCI scanning, then we will share your email address to forward scan results

Our third party agents have already assured us of their preparedness for data protection compliance.   

We have a Data Protection regime in place to oversee the effective and secure processing of your personal data. Our online store allows our administrators to anonymize and delete your personal data in a timely and responsible manner and also allows you to request the immediate deletion of your data once the transaction is full and final and we have met our statutory reporting obligations. You will find an option to delete the data on your account page. (You will not be able to delete data where we have an overriding obligation to retain it.) Vortx may be liable for the onward transfer of EU and Swiss personal data to agent third parties unless we can prove that we were not a party to the damages.

How long we keep it

We have a formal retention policy which requires us to keep details of your transactions for a period of six years from the date of the transaction in order to meet our statutory reporting obligations in respect of our formal accounts as well as in terms of tax reporting. After that point, your data will be deleted.

What we would also like to do with it

We would however like to use your name and email address to inform you of our future offers and similar products. This is a legitimate purpose allowed for in law; this information is not shared with third parties and you can unsubscribe at any time via phone, email (privacyshield@vortx.com) or our website.

What are your rights?

We acknowledge the right of EU and Swiss individuals to access their personal data pursuant to the Privacy Shield.  Individuals wishing to exercise this right may do so by applying through email (privacyshield@vortx.com) or by calling our office (541.201.9965) If at any point you believe the information we process on you is incorrect you can request to see this information, you can object to its use and even have it corrected or deleted. In order to exercise these rights, or if you wish to raise a complaint on how we have handled your personal data, you can contact our Data Protection Officer (details in the footer) who will investigate the matter.

Note that we may be required to share EU and Swiss personal data in response to lawful requests by public authorities including to meet national security and law enforcement requirements.  In compliance with the Privacy Shield Principles, Vortx commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union and Swiss individuals with Privacy Shield inquiries or complaints should first contact Vortx (Data Protection Officer) at the address in the footer.

Vortx has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint. This service is provided free of charge to you.

If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms.  See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction

Vortx, Inc.
2245, Ashland Street, Ashland, OR 97520
+1.541.201.9965
Data Protection Officer: Ellen Smith :: privacyshield@vortx.com