Open Connectivity Foundation
Last Updated: February 18, 2020
Open Connectivity Foundation, Inc., respects your privacy and is committed to protecting it in accordance with this policy.
This policy outlines the way in which we manage any personal data obtained through www.openconnectivity.org (the “Website”) or otherwise provided by or about individuals (“you”, “your”) in the course of you joining or receiving the services under our membership program, attending our events or subscribing to our mailing list (our “Services”).
This policy explains:
- What personal data we collect about you in the course of your engagement with our Services, why we collect it, who it goes to and how long we keep it for;
- How we use your personal data;
- How we protect your personal data; and
- Your legal rights in respect of your personal data, including how to access and update the information we hold about you.
Please note that some of the provisions here will only apply if you are based in the EU.
You can navigate to the relevant sections of the policy by clicking the links below:
- About us
- What information do we collect about you?
- Why do we collect your personal data and on what grounds?
- Marketing communications
- Who do we share your information with?
- Will my data be sent abroad?
- How long do you keep my personal data?
- Your rights in respect of your personal data
- Cookies and other technologies
- Third party links on the Website
- Changes to this policy
- Contact us
By continuing to use the Website and our Services, you agree to our use of your personal data on the terms outlined in this policy.
For the purposes of applicable data protection laws, Open Connectivity Foundation, Inc with its registered address at 3855 SW 153rd Drive, Beaverton, Oregon 97003 (“OCF”, “we”, “us” or “our”) is the controller of your data. This means that we are the primary entity who decides the purposes and means for dealing with your personal data.
Important: Working Groups and Task Groups
Although we are headquartered in the US, OCF is a global membership organization operated through various Working Groups, Task Groups and Steering Committees (as described in our Bylaws and website) which are run by our Members through their nominated representatives (“Members”). The Working Groups, Task Groups and Steering Committees collaborate by using collaboration tools and email and also engage in various online and offline group activities in furtherance of OCF’s mission. This means some of your personal data (primarily your member profile and the data you have provided) may be shared with the OCF community.
What information do we collect about you?
We collect several types of information from and about our Members, Website users, and email subscribers, including:
Personal data we collect directly from you:
- Information required to sign up for and administer an OCF membership application, e.g. company representative name, address, phone number, email address, web page URL
- Information required to sign up for and administer an OCF member account on our Website (including for publication on our online member directory, if you have opted-in to this), e.g. name, contact details, company name, job title, affiliated contact name
- Information required to sign up for and administer the OCF Certification Management System, e.g. name, email, job title, contact details, certified product details, and affiliated company.
- Information provided to us if you contact us or make an enquiry, including through emails, calls and the “Contact Us” form and “Report an Issue” form on our Website, e.g. names, e-mail addresses, contact details and any other information contained in records and copies of your correspondence.
- Information we receive from you when you sign up to OCF conferences and events including name, contact details, membership level, payment details, special attendee requirements (e.g. dietary restrictions and accessibility requirements).
- Information you provide us when you connect or engage with us via social media platforms, including LinkedIn, Twitter, YouTube and WeChat (“Social Media Platforms”).
Information received from other sources:
- Technical information regarding your visits to the Website including, but not limited to, traffic data, location data, weblogs and other communication data.
- Publically available details, such as contact details on your personal website or Social Media Platforms.
- Information that another representative has provided about you in connection with a membership application (e.g. as an alternate contact for your organization), membership agreement, or membership profile or status, such as your contact information.
- Any relevant personal data that you may have submitted to our service providers (including Vital Technical Marketing Group (“VTM”) and Higher Logic, LLC (“Higher Logic”)) in the course of them providing the Services on our behalf.
You may also provide information to be published or displayed (hereinafter, "posted") on areas of the Website, including the externally hosted OCF Workspace and Social Media Platforms that are visible to other Website users, Members, or other participants in Work Groups, Task Groups and Steering Committees that you participate in (collectively, "User Contributions"). Your User Contributions are posted on and transmitted to others at your own risk. Although we limit access to certain pages, please be aware that no security measures are perfect or impenetrable. Additionally, although our Members are bound by confidentiality provisions, we cannot control the actions of our Members, Website users or other recipients with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.
Why do we collect your personal data and on what grounds?
We will only use your personal data if we have a permitted lawful basis to do so. Generally we collect your personal data because it is necessary for:
- performing our contract for the Services with you;
- the pursuit of our legitimate interests (as set out below); or
- complying with our legal obligations.
We may also rely on your consent, where required by applicable law, to use your personal data for:
- keeping you informed of the latest OCF news and events (see “Marketing Communications” below)
- using your profile or images in promotional materials or creating content for membership Services
- Publishing your profile on our online member directory (which will contain details of your personal contact information from the company roster on the “My Account” page of the member portal)
- For sharing any sensitive personal information (e.g. health data regarding dietary restrictions with event organisers).
Depending on your jurisdiction, you may have the right to withdraw your consent to these activities at any time, which will mean (unless another lawful basis applies to your data) that we will cease to process the affected data after consent is withdrawn. However, please note this may result in us being unable to provide you with certain features of the Website and/or Services.
The primary purpose for which we collect information about you is to provide you with Services you have requested from us (i.e. to perform our contract with you). We also collect information about you for the following purposes:
To perform our contract with you
- To provide members with their membership benefits
- To process your communications, your membership of and subscription to the Website and to enable your use of the Website and the Services
- For supplying Services to you (including use of our OCF certification test tools)
- For continuity of service (e.g. to restore your membership if you are coming back after a long break). This will be in accordance with our data retention practices (see “How long do you keep my personal data?” below)
- To provide you with information or Services that you request from us
- For handling member contacts, queries, complaints or disputes.
For our legitimate interests
- For market research and analytical purposes, e.g. to improve our understanding of membership and event attendance trends and profiles
- For improving existing Services and developing new products and Services
- For promoting, marketing and advertising our Services
- Protecting OCF and our members by taking appropriate legal action against third parties who have committed criminal acts or are in breach of legal obligations to OCF
- To effectively handle any legal claims or regulatory enforcement actions taken against OCF
- To generally run the Website and for internal operations, in order to provide you with an up to date, efficient and reliable service
- Making important communications about your membership
- Maintaining our membership database.
To comply with our legal obligations
- To help prevent fraudulent activity, including on your account (for example, if our payment processors notify us that your card details are fraudulent, we may take action to block your access to the Website and/or our Services to you).
- To comply with our legal and regulatory obligations (including under applicable data protection laws)
- For preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies
- To fulfil our duties to our members.
If you have signed-up for our eNews emails or opted to subscribe to the Members email list when signing up for a member account on the Website, we will send you messages by email regarding information about the latest news and events from OCF. You can change your communication preferences at any time by adjusting your preferences in your Website account (as a Member representative) or emailing [email protected] Please note that you may still receive service messages related to your membership or the operation of the Website (e.g. server issues with the Website or important communications about your membership status).
Who do we share your information with?
- Our service providers who we use to provide the Services to you, including VTM and Higher Logic.
- Contractors and other third parties we use to support our business and who are bound by contractual obligations to keep personal data confidential and use it only for the purposes for which we disclose it to them.
- Third parties we may be required to disclose such personal data to in order to comply with our legal obligations or enforce our legal rights, e.g. any relevant authority or enforcement body and fraud protection and credit risk reduction agencies.
- Any potential or actual third party buyer of our business and/or assets in the event that we sell, trade or license ownership of any part of the OCF business or assets (including management of the Website).
OCF has not in the past, and does not now, sell personal data to third parties, nor does it disclose personal data to third parties for their marketing purposes.
Yes. As our contacts database is based and hosted in the US, any personal data you submit to us will be held there. Additionally, OCF members are based in multiple different countries and may be affiliated with multiple, cross-border Work Groups, Task Groups and Steering Committees.
If you are based in the EU, this means your personal data may be transferred outside of the European Economic Area to another jurisdiction. Where this is the case and we are responsible for making such a transfer, we will ensure that these are made subject to appropriate safeguards as required by applicable data protection laws, to ensure that a similar degree of protection is afforded to your personal data. These will include the use of recipients certified under the Privacy Shield regime, or the use of EU Commission approved standard contractual clauses, or transfers to countries deemed to provide an adequate level of protection for personal data by the European Commission. You can obtain further information about the safeguards in place for your international transfers of personal data by contacting us at https://openconnectivity.org/contact-us.
How long do you keep my personal data?
We keep your data for as long as it’s necessary to meet the relevant purposes for which we’ve collected your data, including for the purpose of satisfying any legal, accounting or reporting requirements.
To determine the appropriate length of time for holding your data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm, from unauthorised use or disclosure of your personal data, the purpose for which we process your data and whether we can achieve those purposes through other means, along with the applicable legal requirements.
Generally, we will retain your data for as long as we continue to have an active relationship with you. For example, while you have an active OCF membership, attend OCF events, subscribe to our eNews or other e-mail lists, or participate in or contribute to our forums/discussions or Workspace(s).
In the event your membership lapses, we will retain some membership data for a limited period of time to allow us to easily reinstate your membership if you elect to renew it in the near future. In such case, the membership data we retain for the purpose of reinstating your membership is limited to the company/member name, the date you originally became a member, your most recent membership level, your membership payment history, and the primary e-mail address associated with your membership.
Details of our retention practices for specific categories of data are available on request by Contacting Us.
In some circumstances you can ask us to delete your data: see “Your rights in respect of your personal data” below for further information.
In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
Your rights in respect of your personal data
The following section applies only if you are based in a jurisdiction with a data protection law that provides individuals with certain rights with respect to their personal data.
In certain circumstances you may have rights under data protection laws in relation to the personal data we hold about you. Depending on the jurisdiction in which you are based, you may have the right to request to:
- access information held about you.
- rectify any incorrect or incomplete data we hold about you. It is both in our interest and yours that any personal data we hold about you is accurate, complete and current. If the data we hold about you is inaccurate in any way, please contact us to have your personal data corrected. You can update any incorrect contact information yourself by updating your profile in the Member Portal of the Website at https://workspace.openconnectivity.org/kws/my_account.
- delete, restrict or remove the data we hold about you.
- transfer the data we hold about you to another party.
- object to any further processing of your data.
You can make all such requests via email to [email protected]
We will endeavour to respond to your requests within one month and free of charge. Please note that in respect of all these rights, we reserve the right to:
- refuse your request based on the exemptions set out in the applicable data protection laws
- request for proof of your ID to process the request or request further information
- charge you a reasonable administrative fee for any repetitive, manifestly unfounded or excessive requests.
If we refuse your request to exercise these rights, we will give reasons for our refusal and allow you to challenge our decision.
If you have any concerns about how we handle your data, please contact us. If you are not satisfied after we’ve tried to resolve your issue, you’ll be entitled to lodge a complaint with the data protection regulator for your country of residence.
Security of your data
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Cookies and other technologies
Most browsers allow you to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser. You can obtain information about how to manage cookies by clicking “help” on your browser’s menu or visiting www.aboutcookies.org. Please note that if you choose to erase or block your cookies, you will need to re-enter your original user ID and password to gain access to certain parts of the Website.
We also use other tracking technologies on the Website such as web server and application logs, which may record information such as internet domain and host names, Internet protocol (IP) addresses, browser software and operating system types, clickstream patterns and dates and times that our site is accessed.
Our Use of Google Analytics
When you visit the Website, Google Analytics automatically collects information from you through the use of Google’s analytics IDs, and Google provides some of this information to us. An analytics ID is a specific string of numbers and letters (often called a “character string”) that is assigned to your computer or device but does not name you. The analytics ID allows Google to track usage data of the Website, such as date and time of visit, duration of visit, Website traffic patterns, “clickstreams,” other similar information about your use of the Website, the type of web browser used, the operating system/platform you are using, your IP address, the websites that referred or linked you to our Website, and your CPU speed. Google Analytics does not share the analytics ID assigned to your computer or device that you use to access and use the Website. Google Analytics provides information about the use of our Website to us in aggregate form (i.e., data about many Website users combined and not just about you). Some of this data might include the geographic region of groups of Website users, but again, this data will be in aggregate form. We rely on this aggregate data to inform us how users are using the Website to help us improve the Website.
Types of Cookies
There are four general categories of cookies. A description of each category of cookie is below, followed by a table describing the categories of cookies used on the Website.
- Strictly necessary cookies. These cookies are essential to enable you to move around a website and use its features. Without these cookies, services you have asked for, like logging into a secure area of our Website, cannot be provided.
- Performance / analytical. These cookies collect information about how visitors use a website. The information collected by these cookies is performance and usage data such as that collected by Google Analytics as described throughout this Privacy Statement.
- Functionality cookies. These cookies allow a website to remember choices you make (such as your username or ID, language preference, or the area or region you are in) and provide enhanced, more personal features. They may also be used to provide services you have asked for. The information these cookies collect may be anonymized, and they cannot track your browsing activity on other websites.
- Targeting and advertising cookies. These cookies track browsing habits and are used to deliver targeted (interest-based) advertising. They are also used to limit the number of times you see an ad and to measure the effectiveness of advertising campaigns. They are usually placed by advertising networks with the website operator’s permission. They remember that you have visited a website and this information is shared with other organizations, such as advertisers.
We use the following categories of cookies for the reasons described below:
|Category||Do we use?||Purpose and Description|
|Strictly Necessary||Yes||We use these cookies to enable you to navigate the Website and use certain features, including logging in to and using the member portal.|
|Performance||Yes||We use these cookies to improve the performance of our Website and enhance your experience. Google Analytics automatically collects certain usage and performance data from our Website users. The information these cookies collect is aggregated and anonymous information, and we are never provided with your personal information from these cookies.|
|Functionality||Yes||Functionality cookies enable the Website to temporarily remember choices you make on the Website, and to provide a more personalized experience. You can customize or disable these cookies through your browser settings. A link to cookie management resources for commonly used browsers is above.|
|Advertising||No||We do not use any advertising, targeting, or marketing cookies on our Website.|
Except for essential cookies, all cookies will expire after 12 months.
Third party links on the Website
The Website may contain links to other websites not owned and operated by OCF, for example, Social Media Platforms and websites hosted by our third party suppliers to provide certain Services (e.g. Higher Logic and VTM). We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
We do not knowingly collect personal data from children under the age of 13. If we learn that we are in possession personal data on a child under the age of 13, we will immediately delete that information from our systems.
If you have any queries relating to this privacy notice (including any requests to exercise your legal rights in respect of your data, you can contact us at [email protected] or through the Contact Us page of our Website.