Effective date: March 30, 2025
This Privacy Policy is designed to help as a website visitor or user of our services understand how Aravolta DCIM collects, uses, and shares your information in order to operate, improve, develop, and protect our services. We encourage you to read this policy thoroughly.
Aravolta DCIM is a company that helps businesses align with HIPAA, SOC 2, and other information security compliance frameworks. Our business-to-business SaaS platform guides our customers through the compliance processes and may also include audit management, virtual CISO consulting services, and more.
This policy aims to provide a clear explanation of information Aravolta DCIM collects from and about you as a website visitor and/or user of our services and how we use and share it. Please note that this policy only applies to information that we collect, use, and share. This policy does not apply to any websites, products, or services provided by others, including our customers. If you would like to know more about their practices, we suggest reviewing their privacy policies. This policy does not apply to personal data about current and former Aravolta DCIM employees, job candidates, contractors and agents acting in similar roles.
As part of customer on-boarding and in order to complete transactions we request the following identifiers during account set up: full name, business legal name, business address, email address, and business phone number.
Aravolta DCIM's services allow you to establish technical integrations with certain service providers, thereby allowing Aravolta DCIM to access data on your behalf from such service providers. To enable such access, you may be required to provide the authentication data for your accounts such as Github and AWS as required by the applicable service provider.
When you use a device, like your smartphone, tablet, or computer, to view our website or interact with our services (including through a service provider's app), we may collect the following data about that device:
We collect your user activity on the Aravolta DCIM platform, for example, we may collect data on time spent on particular pages and buttons clicked on each respective page.
When needed for Aravolta DCIM to provide its services, the service providers you use may provide us with identifiers and commercial information about you as part of providing us with information about your use of the service providers and configurations in providers and configurations in place. Such information may include your name, email address, phone number, or information about your accounts and transactions.
We may derive additional information about you from the other categories of data we collect. For example, we may infer your geolocation or your annual income.
We may collect and share cookie data from and with third parties when you visit our website, or we may allow third parties to collect this cookie data from our sites. Please see "Cookies and Similar Technologies" under "How We Share Your Data" below for more details.
We may collect data when you interact with Aravolta DCIM through other means such as our marketing activities, social media accounts, and joint marketing activities in partnership with other services. Additionally, we may collect information through other individuals at your organization, individuals that have referred Aravolta DCIM to you, or third party services and datasets. For example, we may collect your name, social media handle, or email address.
We do not sell or rent personal information that we collect. We use your information for the following business purposes:
Aravolta DCIM's security policies and practices are designed to protect the security, confidentiality, and integrity of your data. Aravolta DCIM implements security controls designed to limit access to this data to personnel who have a business reason to know it and prohibits its personnel from unlawfully accessing, using, or disclosing this data. Such practices include encryption of your data in transit and at rest, logging and monitoring access to your data, database backups, and segregated development and production environments. We also take reasonable steps, through contractual or other reasonable means, to ensure that a comparable level of personal information protection is implemented by the third parties who assist us in providing products and services to you.
For individuals in the European Economic Area ("EEA") or the United Kingdom ("UK"), Aravolta DCIM only processes your personal data when we have a valid legal basis to do so. Our legal basis for processing the data we collect will depend on what data we collected and the purpose for processing it. Generally, we will only collect and process your data where:
To the extent we rely on consent to collect and process your data, you have the right to withdraw your consent at any time per the instructions provided in this policy.
We retain your data only as long as it is needed. To determine whether the data is needed, we consider the reason your data was collected and used and any legal requirements to hold onto your data. We review your data periodically to ensure it is still needed to fulfill the purpose for which it was collected or any other legal requirements.
The exceptions to this may be if: (a) Aravolta DCIM needs your data to continue providing you with a Aravolta DCIM service you requested; (b) Aravolta DCIM is required by law to keep your data; (c) Aravolta DCIM needs your data to help prevent fraud or protect privacy, provide support, or investigate misuse and misconduct; (d) where Aravolta DCIM has anonymized your data such that it cannot be reidentified or (e) we request - and you specifically agree - to allow us to retain your data longer.
Your data will only be processed as required by law or in accordance with this policy.
Please refer to the "How to Exercise Rights in Your Data" section of this policy for options that may be available to you, including how to request deletion of your data. You can also contact us about our data retention practices using the contact information in the "Contacting Aravolta DCIM" section below.
Aravolta DCIM does not transfer data we collect about you across international borders.
You may exercise the following rights related to your personal data, subject to some limitations and exceptions provided by law, and you will not be discriminated against for exercising them:
Please note that for an official record of your activities and history conducted through a service provider that may or may not be technically integrated with Aravolta DCIM, you should make that request directly to your service provider.
You can contact us as described in the "Contacting Aravolta DCIM" section below to exercise any of your data protection rights. You may be required to provide additional information necessary to confirm your identity before we can respond to your request. We will consider requests and provide our response within a reasonable period of time (and within any time period required by applicable law). Please note, however, that certain data may be exempt from such requests, for example if we need to keep the data to comply with our own legal obligations or to establish, exercise, or defend legal claims.
Additionally, depending on where you live, you may have the right to make a complaint at any time to your (data protection) supervisory authority. For example, if you are in Canada, you may contact the Office of the Privacy Commissioner of Canada which you can find here. For end users in the EEA, you can find contact information for the European Data Protection Board (EDPB) on the EDPB's website here. For end users in the UK, you can find contact information for the Information Commissioner's Office (ICO) on the ICO's website here. For end users in Switzerland this is the Federal Data Protection and Information Commissioner which you can find here.
Our services are not targeted or directed at children under the age of 16, and we do not intend to or knowingly collect or solicit personal information from children under the age of 16. If you have reason to believe that a child under the age of 16 has provided personal information to us, we encourage the child's parent or guardian to contact us in accordance with the section Contacting Aravolta DCIM to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 16, we will promptly delete that personal information.
You may contact Aravolta DCIM to exercise rights in your data, to ask questions about our privacy policies and practices, and to file a complaint.
If you believe the privacy laws relating to the protection of your personal information or this policy have not been respected, you may file a complaint with us. We will acknowledge your complaint, investigate it and provide you with a response within a reasonable period of time (and within any time period required by applicable law). If, after an investigation, your complaint is deemed justified, we will take appropriate steps to correct the situation, including, if necessary, amending our policies and practices. You may be required to provide additional information necessary to confirm your identity before we can respond to your request. Please note, however, that certain data may be exempt from such requests, for example if we need to keep the data to comply with our own legal obligations or to establish, exercise, or defend legal claims.
We may update or change this policy from time to time. If we make any updates or changes, we will post the new policy on this URL and update the effective date at the top of this policy.