In this document, “we”, “us” and “our” refer to Shabas.
This policy applies to personal information which is collected and/or used by Shabas in its capacity as a controller as that term (or another term with equivalent meaning) is defined in the EU General Data Protection Regulation (GDPR) and other similar laws (e.g., Brazil’s Lei Geral de Proteção de Dados, the DIFC Data Protection Law 2020, etc.).
Collection of your Personal Information
In order to better provide you with products and services offered, Shabas may collect personally identifiable information, such as your:
- First and Last Name
- Mailing Address
- E-mail Address
- Phone Number
- Employer
- Job Title
We do not collect any personal information about you unless you voluntarily provide it to us. However, you may be required to provide certain personal information to us when you elect to use certain products or services. These may include: (a) registering for an account; (b) signing up to attend any Shabas-sponsored online or on-demand event such as webinar or podcast or videocast; (c) signing up to download any document (d) signing up for special offers from selected third parties; (e) sending us an email message; (f) submitting your contact information; (g) submitting a job application with us; (h) you contact us with any other enquiry, complaint or notice. To wit, we will use your information for, but not limited to, communicating with you in relation to services and/or products you have requested from us. We also may gather additional personal or non-personal information in the future.
Please do not provide any other person’s personal data to us unless we specifically request you to do so.
In this document, we have summarized the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.
Use of your Personal Information
Shabas collects and uses your personal information to operate and deliver the services you have requested.
Any information that you provide to us for the purpose of subscribing to our email notifications and/or download documents (e.g. articles) or information (e.g. podcasts) may be processed for the purposes of sending you the relevant notifications and/or documents or information.
Any enquiry you submit to us regarding the provision of services or requesting a proposal will be used for the purposes of offering, marketing, and selling relevant services to you.
Any communication that you send to us, and any metadata generated by our website contact form may be processed for the purposes of communicating with you and record-keeping.
Shabas may process your personal information where it is deemed necessary, for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
Shabas may use personal data supplied to us for the purposes of assessing and if necessary obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice.
Shabas may process any of your personal data supplied where necessary for the establishment, exercise, or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
Shabas may also use your personally identifiable information to inform you of other products or services available from Shabas and its affiliates.
If we are acquired by, merge with, or enter a joint venture with another company, or if all or substantially all of our assets are transferred to another company, or as part of a bankruptcy, we may transfer the information we have collected from you to the new or acquiring company.
If you apply for a position with Shabas, we will need to collect personal information in order to consider your application, and during any interview and assessment phase
If we hire you as a vendor, supplier or contractor, we will need to collect personal information in order to complete transactions and, where applicable, complete appropriate screening activities.
Finally, if you contact us for any other reason, we will collect basic contact details, as well as any other personal information relevant to the reason for your enquiry, in order to resolve that enquiry.
Sharing Information with Third Parties
Shabas does not sell, rent or lease its customer lists to third parties.
Shabas may share data with trusted partners to help perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. All such third parties are prohibited from using your personal information except to provide these services to Shabas, and they are required to maintain the confidentiality of your information.
Shabas may disclose your personal information, without notice, if required to do so by law or in the good faith belief that such action is necessary to: (a) conform to the edicts of the law or comply with legal process served on Shabas or the site; (b) protect and defend the rights or property of Shabas; and/or (c) act under exigent circumstances to protect the personal safety of users of Shabas, or the public.
Automatically Collected Information
Information about your computer hardware and software may be automatically collected by Shabas or our service provider. This information can include: your IP address, browser type, domain names, access times and referring website addresses.
When accessing Shabas website from your mobile phone, in addition to contact information, we or our service providers (such as mobile operating system and platform providers) may also collect information relating to your device, including your device model, operating system, browser type, unique device identifier, IP address, mobile phone number, mobile network carrier, location, and the way you are using the mobile application.
This information is used for the operation of the service, to maintain quality of the service, and to provide general statistics regarding use of the Shabas website.
Links
This website contains links to other sites. Please be aware that we have no control over, and we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.
Security of your Personal Information
Shabas has reasonable technical safeguards, security policies and procedures in place to protect personal information from unauthorized loss, misuse, alteration, or destruction. Measures we take include placing confidentiality requirements on our staff members and service providers, limiting access to your personal information on a “need to know” basis, and providing training to appropriate Shabas personnel.
Shabas uses the following methods for this purpose:
– SSL Protocol
When personal information (such as a credit card number) is transmitted to other websites, it is protected through the use of encryption, such as the Secure Sockets Layer (SSL) protocol.
We strive to take appropriate security measures to protect against unauthorized access to or alteration of your personal information. Unfortunately, no data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, you acknowledge that: (a) there are security and privacy limitations inherent to the Internet which are beyond our control; and (b) security, integrity, and privacy of any and all information and data exchanged between you and us through this Site cannot be guaranteed.
Retention of your personal information
Shabas retains your personal information for the period of time required for the purposes for which it was collected, any compatible purposes which we subsequently establish, or any new purposes to which you subsequently consent, or to comply with legal, regulatory and Shabas policy requirements. This period of time will usually be the period of your, or the relevant client’s, relationship, or contract with Shabas plus a period reflecting the length of time for which legal claims may be made following the termination of such relationship or contract. Some information (such as call recordings, and certain information required to demonstrate regulatory compliance) may need to be kept for longer. Personal information will be kept for a shorter or longer period of time if so required by law or a Shabas policy, if the information becomes subject to a legal hold (for example, following a communication from our regulator) or if we have identified through a data protection impact assessment that a different retention period is appropriate.
Right to Deletion
Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will:
- Delete your personal information from our records; and
- Direct any service providers to delete your personal information from their records.
Please note that we may not be able to comply with requests to delete your personal information if it is necessary to:
- Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;
- Debug to identify and repair errors that impair existing intended functionality;
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
- Comply with the California Electronic Communications Privacy Act;
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the achievement of such research, provided we have obtained your informed consent;
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us;
- Comply with an existing legal obligation; or
- Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided the information.
Children Under Thirteen
Our website and services are targeted at people over the age of 18. Shabas does not knowingly collect personally identifiable information from children under the age of thirteen. If you are under the age of thirteen, you must ask your parents or guardian for permission to use this website. If we have reason to believe that we hold personal data of a person under that age in our databases, we will delete that personal data.
E-mail Communications
From time to time, Shabas may contact you via email for the purpose of providing announcements, promotional offers, alerts, confirmations, surveys, and/or other general communication. In order to improve our Services, we may receive a notification when you open an email from Shabas or click on a link therein.
If you would like to stop receiving marketing or promotional communications via email from Shabas, you may opt out of such communications by “replying STOP” or “clicking on the UNSUBSCRIBE button.”.
External Data Storage Sites
We may store your data on servers provided by third party hosting vendors with whom we have contracted.
International Transfers of Your Personal Data
In certain circumstances your personal data may be transferred to countries outside the European Economic Area (EEA).
Shabas has employees, office and facility located in the United States of America. The European Commission has made an “adequacy decision” with respect to the data protection laws of this country. Transfers to this country will be protected by appropriate safeguards.
Facilities of service providers who host our data are situated in The United States of America. The European Commission has made an “adequacy decision” with respect to the data protection laws of this country.
You acknowledge that personal data that you submit to or through our website may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
If we transfer your personal information outside Shabas to third parties who help provide us with any of the activities described in this policy, we obtain contractual commitments (such as the Standard Contractual Clauses) from them in order to protect your personal information.
If we receive requests for information from law enforcement, courts or regulators (who may be based overseas), we carefully validate these requests before any personal information is disclosed.
What Is Our Legal Basis For Collecting Personal Information?
Certain laws, including the GDPR, require us to establish a ‘lawful basis’ for our processing of your personal information. In the majority of cases, processing will be justified on the basis that:
- the processing is necessary for the performance of a contract to which you are a party, or to take steps (at your request) to enter into a contract (e.g. where you request certain services as an individual client, or where we help advise your employer or service provider on fulfilling an obligation to you under a contract);
- the processing is necessary for us to comply with a relevant legal obligation (e.g. where we are required to collect certain information about our clients to make disclosures to courts or regulators); or
- the processing is in our legitimate interests, subject to due consideration for your interests and fundamental rights (this is the basis we rely upon for the majority of the processing of personal information in connection with the provision of our Services, and also for the purposes of most client on-boarding, administration and relationship management activities) or that of another natural person.
In limited circumstances, we will use your consent as the basis for processing your personal information, for example, where we are required by applicable law to obtain your prior consent in order to send you marketing communications.
Before collecting and/or using any special categories of data (as that term is defined in the GDPR, or as an equivalent term is defined by other privacy laws), or criminal record data, we will establish a lawful exemption which will allow us to use that information. This exemption will typically be:
- your explicit consent;
- the establishment, exercise, or defense by us or third parties of legal claims; or
- other uses allowed by applicable law including context specific exemptions provided for under local laws of EU Member States and other countries implementing the GDPR and similar privacy laws, such as in relation to the processing of special category data for the purposes of preventing or detecting fraud in relation to instructions from potential clients.
Your Rights in Jurisdictions Covered by the GDPR and Similar Laws
The rights described below may vary depending on the specific laws that apply to you.
To the extent the legal validity of processing your personal data is consent, you can withdraw it anytime by providing us with a written notice.
We may ask you for additional information to confirm your identity before disclosing any personal information to you. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
You can exercise your rights by contacting us. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly or inform you if we require further information in order to fulfil your request, so long as it is consistent with applicable law and professional standards.
We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way, or if it would impact the performance of a task carried out for reasons of public interest, or if it would impact legitimate interests pursued by us or by a third party.
In addition, under applicable local law you may have the legal right to lodge a complaint with the relevant supervisory authority or local data protection authority.
Right to Access
You have the right to access personal information which Shabas holds about you, together with certain information about how and why your personal information is processed. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.
Right to Rectification
You have a right to request us to correct your personal information where it is inaccurate or out of date.
Right to be Forgotten (Right to Erasure)
You have the right under certain circumstances to have your personal information erased. Your information can only be erased if it is no longer necessary for the purpose for which it was collected, and we have no other legal ground for processing the information.
Right to Restrict Processing
You have the right to restrict the processing of your personal information, but only where:
- its accuracy is contested, to allow us to verify its accuracy; or
- the processing is unlawful, but you do not want it erased; or
- it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise or defend legal claims; or
- you have exercised the right to object, and verification of overriding grounds is pending.
Right to Data Portability
You have the right to data portability, which requires us to provide personal information to you or another controller in a commonly used, machine readable format, but only where the processing of that information is based on (i) consent; or (ii) the performance of a contract to which you are a party. Please note that Shabas rarely relies upon consent as a legal basis, and the performance of a contract basis will only be relevant to the extent that you, as an individual, are party to a contract with Shabas or a client, and our use of your personal information is necessary for the performance of that contract.
Right to Object to Processing
You have the right to object to the processing of your personal information at any time, but only where that processing is based on our legitimate interests. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms. If you object to processing your information on specific grounds such as for marketing, we will cease to process your personal data for this purpose to the extent we are able.
Changes to this Statement
Shabas reserves the right to change this Privacy Policy from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account, by placing a prominent notice on our website, and/or by updating any privacy information. Your continued use of the website and/or Services available after such modifications will constitute your: (a) acknowledgment of the modified Privacy Policy; and (b) agreement to abide and be bound by that Policy.
Contact Information
Shabas welcomes your questions or comments regarding this Statement of Privacy. If you believe that Shabas has not adhered to this Statement, please contact Shabas at:
Shabas Solutions LLC
11166 Fairfax Blvd, Suite#310
Fairfax, Virginia 22030
Email Address:
Telephone number:
Effective as of March 01, 2023