Data Privacy Framework Policy
Ik Multimedia US, LLC., (“Ik Multimedia US” or “Company”) complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. Ik Multimedia US has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Ik Multimedia US has certified to the U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles (collectively, the “DPF Principles”), the DPF Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit www.dataprivacyframework.gov.
For purposes of this Policy:
"Consumer" means any natural person who is located in the EEA, UK, but excludes any individual acting in his or her capacity as an Employee.
"Controller" means a person or organization which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
"Customer" means any entity for which Ik Multimedia provides products and/or services, such as without limitation, ICANN approved registry services.
"Employee" means any current, former or prospective employee, contractor, intern or temporary worker of Ik Multimedia or any of its EEA, UK , or any related individual whose Personal Data Ik Multimedia processes in connection with an employment relationship, who is located in the EEA, UK.
"EEA" means the European Union and Iceland, Liechtenstein and Norway.
"Personal Data" means any information, including Sensitive Data, that is (i) about an identified or identifiable individual, (ii) received by Ik Multimedia in the U.S. from the EEA, UK and (iii) recorded in any form.
"Data Privacy Framework Principles" means the Principles and Supplemental Principles of the DPF.
"Processor" means any natural or legal person, public authority, agency or other body that processes Personal Data on behalf of a Controller.
"Sensitive Data" means Personal Data specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership (including trade union-related views or activities), sex life (including personal sexuality), information on social security measures, the commission or alleged commission of any offense, any proceedings for any offense committed or alleged to have been committed by the individual or the disposition of such proceedings, or the sentence of any court in such proceedings (including administrative proceedings and criminal sanctions).
"UK" means the United Kingdom and Gibraltar.
Scope
This Data Privacy Framework Policy (the “Policy”) sets forth the privacy principles that Ik Multimedia LLC follows when processing Personal Data received from Ik Multimedia Italy’s customers or prospective customers located in the European Economic Area (“EEA”), Switzerland, and the United Kingdom while providing services from the United States (“U.S.”). This Policy does not apply to information collected through other Ik Multimedia US websites or to information collected during Ik Multimedia US sponsored sales and marketing activities. This Policy also does not apply to Personal Data collected through Ik Multimedia US’s recruiting process. For purposes of this Policy, Personal Data means data about an identified or identifiable individual that is received by Ik Multimedia US in the United States from the EEA, and the United Kingdom, and recorded in any form, and is within the scope of Regulation (EU) 2016/679 (“General Data Protection Regulation” or “GDPR”), the Swiss Federal Data Protection Act, or the UK Data Protection Act 2018, respectively.
Ik Multimedia US’s Role as a Data Processor of Ik Multimedia Italy and its Customers and Prospective Customers.
Ik Multimedia Italy, produces software and hardware for music production and in connection with these software products.
Ik Multimedia LLC provides for Ik Multimedia Italia: marketing and promotional activities, product demonstrations, cloud services and product technical support services (collectively “Services”) for the benefit of its customers and prospective customers in the EEA, and the United Kingdom through employees who may be located in the U.S. These U.S.-based employees may process Personal Data to provide Services to customers and prospective customers located in the EEA and the United Kingdom.
Ik Multimedia LLC receives the following data from Ik Multimedia Italy of its customers:
- identification data
- e-mail
- username
- Data relating to the software and hardware used: e.g. Serial number, Model.
Consequently, Ik Multimedia LLC does not generally know the categories of Personal Data to be processed or the purpose(s) of the processing unless and until Ik Multimedia LLC receives this information from Ik Multimedia Italy and its customers or prospective customers.
When Ik Multimedia LLC processes Personal Data, Ik Multimedia LLC does so only for the purpose of providing Services.
Ik Multimedia LLC Compliance with the Data Privacy Framework Principles
Ik Multimedia US employees located in the United States may provide Services for customers and prospective customers located in the EEA and the United Kingdom. To provide such Services, Ik Multimedia LLC may process Personal Data. Ik Multimedia LLC will apply the following DPF Principles to Personal Data physically or remotely transferred from the EEA, and the United Kingdom to the United States.
ACCESS
Data Subjects have the right to access the Personal Data an organization holds about them. If such Personal Data is inaccurate or processed in violation of the DPF Principles, a Data Subject may also request that Personal Data be corrected, amended, or deleted.
When Ik Multimedia LLC receives Personal Data, it does so on behalf of Ik Multimedia Italy's customer or potential customer. To request access, correction, modification or deletion of Personal Data, data subjects should contact Ik Multimedia Italy who collected their Personal Data. Ik Multimedia LLC will work with reasonable requests from Ik Multimedia Italy's customers and potential customers to assist data subjects in exercising their rights under the DPF.
CHOICE
Data subjects have the right to opt out of (a) disclosures of their Personal Data to third parties not identified at the time of collection or subsequently authorized, and (b) uses of Personal Data for purposes materially different from those disclosed at the time of collection or subsequently authorized. Ik Multimedia Italy is responsible for informing Data Subjects when they have the right to opt out of such uses or disclosures.
Data Subjects who wish to limit the use or disclosure of their Personal Data should submit that request to Ik Multimedia Italy. Ik Multimedia LLC will cooperate with Ik Multimedia Italy and its customers’ and prospective customers’ instructions regarding Data Subjects’ choices.
SECURITY
Ik Multimedia LLC is committed to safeguarding the Personal Data that it receives. Ik Multimedia LLC takes reasonable and appropriate measures to protect Personal Data in Ik Multimedia LLC possession from loss, misuse, unauthorized access, disclosure, alteration and destruction.
Ik Multimedia LLC utilizes a combination of online and offline security technologies, procedures and organizational measures to help safeguard Personal Data. For example, facility security is designed to prevent unauthorized access to Ik Multimedia LLC computers. Electronic security measures — including, for example, network access controls, passwords and access logging — provide protection from hacking and other unauthorized access. Ik Multimedia LLC also protects Personal Data through the use of firewalls, role-based restrictions and, where appropriate, encryption technology. Ik Multimedia LLC limits access to Personal Data to employees, subcontractors, and third-party agents that have a specific business reason for accessing such Personal Data. Individuals granted access to Personal Data are aware of their responsibilities to protect such information and are provided appropriate training and instruction.
DATA INTEGRITY AND PURPOSE LIMITATION
Ik Multimedia Italy are responsible for limiting their collection of Personal Data to that which is necessary to accomplish the purposes disclosed to Data Subjects and compatible purposes. They also are responsible for providing Ik Multimedia LLC with instructions or authorization for the processing of Personal Data consistent with such purposes.
Ik Multimedia Italy also has a responsibility to ensure that (a) Personal Data they collect is accurate, complete, current and reliable for its intended uses; and (b) Personal Data is retained only for as long as is necessary to accomplish the customer's or prospective customer's legitimate business purposes disclosed to the Data Subject and for compatible purposes. Ik Multimedia LLC will cooperate with Ik Multimedia Italy customers' and prospective customers' reasonable requests for assistance in meeting these obligations.
In the performance of Services, Ik Multimedia LLC will request only the minimum amount of information required to perform the applicable Services and will retain such information only for as long as necessary to provide the Services or for compatible purposes, such as to provide additional Services, to comply with legal requirements, or to preserve or defend Ik Multimedia LLC legal rights.
ONWARD TRANSFER
Ik Multimedia LLC may disclose Personal Data to subcontractors and third-party agents who assist Ik Multimedia LLC in providing Services to its customers and prospective customers. Before disclosing Personal Data to a subcontractor or third-party agent, Ik Multimedia LLC will obtain assurances from the recipient that it will: (a) use the Personal Data only to assist Ik Multimedia LLC in providing the Services; (b) provide at least the same level of protection for Personal Data as required by the DPF Principles; and (c) notify Ik Multimedia LLC if the recipient is no longer able to provide the required protections. Upon notice, Ik Multimedia LLC will act promptly to stop and remediate unauthorized processing of Personal Date by a recipient. Ik Multimedia LLC will remain liable for onward transfers to its subcontractors and third-party agents.
Ik Multimedia LLC may also be required to disclose, and may disclose, Personal Data in response to lawful requests by public authorities, including for the purpose of meeting national security or law enforcement requirements. To the extent permitted, Ik Multimedia LLC will inform IK Multimedia Italy and its relevant customer or prospective customer before making such disclosure and provide it with a reasonable opportunity to object to such disclosure.
Ik Multimedia LLC will not otherwise disclose Personal Data to third parties.
RECOURSE, ENFORCEMENT & LIABILITY
In compliance with the EU-U.S. DPF Principles, including the UK Extension of the EU-U.S. DPF Principles. DPF Principles, Ik Multimedia US commits to resolve complaints about your privacy and Ik Multimedia LLC collection or use of Personal Data transferred to the United States pursuant to this Policy.
European Union and United Kingdom individuals with DPF inquiries or complaints should first contact Ik Multimedia Data Protection Officer by emailing privacy@ikMultimedia.com or dpo@ikmultimedia.com.
DISPUTE RECOURSE MECHANISM
If a Consumer’s complaint cannot be resolved through Ik Multimedia US internal processes Ik Multimedia LLC commits to cooperate with the panel established by the E.U. data protection authorities (DPAs) and to comply with the advice given by the panel with regard to data transferred from the E.U.
Ik Multimedia have chosen to cooperate with DPAs and respond directly to such authorities with regard to the investigation and resolution of complaints.
For the contact information for the appropriate authority, please contact us at the address given below. Alternatively, EU individuals may go to this link to ascertain a comprehensive list of EU DPA’s.
UK individuals can go to ico.org.uk/about-the-ico/who-we-are/ to ascertain a list of ICO offices and commissioners.
Arbitration
If your DFP compliant cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not otherwise resolved by other redress mechanisms. For more information about binding arbitration, visit this link.
The Federal Trade Commission has jurisdiction over Ik Multimedia LLC’s compliance with the DPF.
For More Information
Data Subjects with questions about how Ik Multimedia US processes Personal Data should first contact the Ik Multimedia US customer or prospective customer that collected the Personal Data. Ik Multimedia US's Data Protection & Privacy Department can be contacted by emailing privacy@ikMultimedia.com or dpo@ikmultimedia.com..
This policy is executed in English and may be translated into other languages. In the event of any conflict or discrepancy between the English language version and a translated version, the English language version of this policy shall control.
Changes to this Privacy Policy
Ik Multimedia LLC may revise this Policy at any time. If Ik Multimedia LLC decides to materially change this Policy, Ik Multimedia LLC will post the revised Policy at this location.