OutSystems Privacy Statement
Updated: Friday, April 6, 2018 - 10:12 GMT
OutSystems (collectively, “OutSystems,” “We,” and “Us”) takes your privacy extremely seriously. This statement (“Statement”) explains what data and information we collect, how and why we collect it, and how we store, use, disclose, and keep information about you and your interactions with us secure. These interactions include when you use our websites, when you register or attend any OutSystems event, webinar, trade show, sales, or marketing activities, download an e-book, report or other digital assets, register and participate in our online community like using our forums or online training, you reply to an OutSystems survey, and/or if you use the OutSystems platform, any of our products and/or services, including any trial version (collectively the “Services”) in any manner.
1. Who are we?
2. What information about you do we collect and how do we do it?
3. Why do We collect Your data?
4. What are your rights regarding the information collected and processed?
5. How is your information used?
6. Who has access to Your information?
7. Your choices
8. Public forums and customer testimonials
9. Security precautions in place to protect the loss, misuse or alteration of your information
10. Use of 'cookies'
11. List of cookies
12. Links to other website
13. 16 or Under
14. Transferring your information
15. Website Recording
16. Data Retention
17. How you can access and update your information
18. OPTING OUT AND UNSUBSCRIBING FROM MARKETING MESSAGES
19. May this Privacy Statement be amended?
Who are we?
OutSystems is a software and services company that provides technology to help companies build mobile and web applications. The OutSystems company group is comprised of OutSystems Portugal and its subsidiaries worldwide. You can find our office locations and the full list of OutSystems companies at https://www.outsystems.com/company/contact-us/.
What information about you do we collect and how do we do it?
OutSystems collects data to operate effectively and provide our Services to you.
- Data provided by You manually: You provide some of this data directly, like when you create an OutSystems account in our community to participate in the forums, subscribe to blog updates, administer your organization’s licensing account, register for an OutSystems event, or download digital assets like eBooks and reports from our website, sign up for an OutSystems subscription on Microsoft Azure marketplace (https://azuremarketplace.microsoft.com/en-us/marketplace/apps/outsystems.outsystems), sign up for the OutSystems platform personal edition, or fill out a Contact Request form.
- Usage data collected automatically: We also get some information by recording how You interact with Our products by, for example, using technologies like cookies and receiving usage data from the OutSystems platform used by You.
- Additional data from third parties: We also obtain data from third parties to whom You’ve provided your information and you’ve given Your consent to be transferred to Us. We protect data obtained from third parties according to the practices described in this statement, plus any additional restrictions imposed by the source of the data. These third-party sources may include: data brokers from which we purchase data to supplement the data we collect; service providers that help us determine a location based on your IP address in order to customize certain products to your location; and OutSystems Partners with which we engage in joint marketing and sales activities.
When you are asked to provide personal data, you may decline. However, if you choose not to provide data that is necessary for us to provide Services, you may not be able to use those Services.
The data We collect depends on the consent You’ve provided and on the context of your interactions with OutSystems, the choices you make, including your privacy settings, and the Services you use. The data we collect can include the following:
- Name and contact data. We collect your first and last name, email address, postal address, phone number, company and position, and other similar contact data.
- Credentials. We collect passwords, password hints, and similar security information used for authentication and account access to our Services.
- Usage data. We collect data about your device and how you and your device interact with OutSystems and our Services.
- Location data. For products with location-enhanced features, we collect data about your location, such as a location derived from your IP address or data that indicates where you are located with less precision, such as at a city or postal code level.
- Content. We collect content of your files and communications when necessary to provide you with the Services You use. For example, if You post a comment or a file using Our community, forums or blog, We need to collect the content of that comment or file to display it to You and the other users of the same Services.
We also collect information You provide to Us when You contact Us about the Services and the content of messages You send to Us, such as requested feedback and product reviews You write, or questions and information You provide for customer support. When you contact Us, such as for customer support, phone conversations, or chat sessions with Our representatives may be monitored and recorded.
OutSystems may also receive information about You from other sources, including third parties from whom We have purchased data, and combine this information with information We already have about You. This helps us to update, expand, and analyze our records, identify new customers, and create more tailored content to provide Services that may be of interest to You.
Why do We collect Your data?
- Processing Your order: We use relevant personal information described above to process and deliver Your order, and to notify You of the status of your order.
- To provide customer support: If You contact our customer service (or vice versa), We will use personal information such as Your order information and contact history to process Your request and provide You with the best service possible. We will process Your personal information in this way if it is necessary for the performance of a contract with Us or if it is required for Us to comply with any legal obligations. If it is not necessary to process Your personal data for either of these reasons, We will process it as it is necessary for the purposes of our legitimate interests in ensuring We can provide the best service possible.
- To engage with you in relation to the programs or communities you decide to join: We will use Your personal information to provide You with the Services You have requested from Us. This will, if applicable, include the use of Your personal information for submission and publication (on our website or a third-party's) in relation to Our Services, using Your contact details for events and using information like your location for our mobile apps. We will process your personal information in this way if it is necessary for the performance of a contract with Us. If it is not necessary for the performance of such a contract, we will process it as it is necessary for the purposes of our legitimate interests in providing these Services appropriately and ensuring they function correctly. To the extent that we process location data, we do this on the basis of Your consent to receiving these Services, and we will not process location data before You have provided your consent to us doing so.
- Social sign-on (this means the use of your social network credentials such as your Facebook user login information to create and sign into your OutSystems account): When you use the social sign-on option, OutSystems will limit the use of public profile information to that which is necessary for the creation of your OutSystems account, as it is necessary for the performance of your contract with Us in relation to account creation. OutSystems will, upon receipt of any irrelevant information from the social network, discard such information. After having created your account, you will have the opportunity to supplement it with any information you would like to share with Us, such as personal information you provide through a completed survey. We will process this personal information as it is necessary for the purposes of our legitimate interests in completing your profile and ensuring we have accurate records about you. To the extent we cannot process it to meet these legitimate interests, we will only process this personal information if you consent to providing it. Any supplemental information you provide to us will be used for the purposes and on the lawful grounds explained in this statement, including to enrich your OutSystems profile and to personalise your OutSystems experience.
- Marketing: When you sign up to receive OutSystems emails, create an OutSystems single sign on, become a member of Our community, order or provide feedback on a Service, or use our website, we will use your personal information to create a profile based on the information we hold about you. This is necessary for the purposes of our legitimate interests in ensuring we have accurate information about you in one place. We create your profile in accordance with your preferences in order to provide you with the best personalized experience, to send you personalized marketing messages and newsletters and for opinion research purposes, such as:
- What kind of information: The way you interact with our brand across all the different channels described above (e.g. the website, apps, social media and marketing messages we send you) and the information we collect in that regard from each of these channels provides us valuable information about your interests and preferences. This insight gives us the opportunity to offer you the best OutSystems experience possible. To learn about you and your interests, we analyse your interactions with Us using various kinds of information, as set out above. In particular, we may combine the information we collect with information we lawfully obtain from third parties. This is necessary for the purposes of our legitimate interests in ensuring that we provide you the most appropriate offers for products and to personalise your experience. You can opt-out of us combining your personal information with the information lawfully collected from third parties through your account settings page or by contacting us using the contact details set out below. If you have given us your consent to send you marketing communications or if we are permitted by law to send such communications without obtaining your consent, we use the information that you have provided to us when interacting with us for sending you personalized marketing messages about OutSystems Services. In some instances we will also aggregate your personal information with that of other individuals, to create comprehensive reports about how customers use our Services, and experience our brand. This is necessary for the purposes of our legitimate interests in analysing our brand and determining how to improve our Services.
- What kind of channels: We will send direct marketing communications to you via the channel you choose, such as email, phone, or social media. We ask for your consent, where required by applicable law, in order to use the contact details you have provided to us to send our personalized marketing communications.
- What kind of messages: The messages we will send you will be personalized and tailored to your individual preferences and interests. We use analytics in order to generate such personalized messages. These analytics will process your personal information and place you in marketing segments, which determine the content of the messages and the offers you will receive from us. These direct marketing messages may contain information about our Services, promotions, and news. We personalise these messages because it is necessary for the purposes of our legitimate interests in ensuring that we provide the most appropriate information. We will, in certain circumstances, also use the channels for opinion research (such as to ask if you would like to participate in a survey) and to learn about your experience and improve your experience with OutSystems, including by sending you personalized messages.
- Re-targeting: Our website and apps use re-targeting technologies, which we will only use after you have provided your consent. This enables us to show our visitors, who were already interested in our Services, advertisements from us on partner websites. We believe that the display of personalized, interest-based advertising is more interesting and relevant to our customers than advertising that does not have a personal connection. Re-targeting technologies analyse the information we collect about your interactions with each Us as described in relation to marketing above and information obtained from other parties, including your cookies, and display advertisements based on your past web-surfing behavior. We will process your data for re-targeting purposes with your explicit consent. Please click here for further information on cookies and instructions on how to disable re-targeting. Note that our sites generally are not configured to respond to web browser do-not-track signals.
- Ads: We also work with non OutSystems companies who use tracking technologies to serve ads on our behalf across the Internet. These companies may collect personal information about your visits to our websites or apps and your interaction with our communications, including advertising. They will only collect this information to the extent you have consented to the placement of cookies for marketing purposes. Please click here for further information on cookies and instructions on how to change your cookie preferences.
- Conducting analytics: We will use the personal information we hold about you (as well as pseudonymised or anonymised information generated from your personal information) to carry out analysis and research. We carry out all such analysis and research on the basis that it is necessary for the purposes of our legitimate interests in understanding our customers and ensuring that our products meet the needs of our customers.
- Analysing our business: We will use your personal information (including by anonymizing and aggregating it with other customers' personal information) for sales, supply chain, and financial analysis purposes, to determine how We are performing, and where improvements can be made and where necessary to report back to our parent or affiliate group companies. This is necessary for the purposes of our legitimate interests in understanding how our business is performing, and considering how to improve our performance.
What are your rights regarding the information collected and processed?
With regard to your information that is collected and/or processed by OutSystems, you may exercise the following rights:
Right of access: You may request OutSystems to confirm if information about you is processed. If such is the case, you will receive access to your information.
Right of rectification: If our information about you is incorrect, you may request OutSystems to rectify your information. This includes the right to have incomplete information completed, taking into account the purpose of the processing.
Right to erasure: You may request OutSystems to erase your information, for instance if the information is unlawfully processed, or if you have withdrawn your consent.
Right to restrict processing: You may request OutSystems to restrict the processing of your information, if (i) the information is inaccurate, (ii) the processing is unlawful, (iii) you need us to retain the information after the retention period for a legal claim, or (iv) you have objected to the processing and a verification of our legitimate interests is pending.
Right to data portability: You may request OutSystems to provide you with an electronic file of your information, or to transfer your personal data to a third party if such is technically feasible.
How is your information used?
Where you have provided consent, we may use your information to:
- process orders that You have submitted;
- carry out our obligations arising from any contracts entered into by You and Us;
- perform the Services You’ve requested. For example, if You fill out a “Contact Request” web form, We will use the information provided to contact You about Your interest in the Services;
- seek Your views or comments on the Services we provide, through surveys We may send You;
- notify You of changes to our Services;
- send You communications which You have requested and that may be of interest to You;
- plan and host corporate events, host online forums and social networks in which You choose to attend and/or participate;
- plan activities, events, promotions related to our Services;
- process a grant or job application;
- contact You to further discuss Your interest in the Services and to send You information regarding OutSystems and its partners, such as information about OutSystems products and information on low-code development and digital transformation.
Who has access to Your information?
We may share Your information with other companies in order to work with them, including subsidiaries and affiliates of OutSystems corporate group. For example, OutSystems may need to share your information with other companies within the OutSystems corporate family for customer support, marketing, technical operations, and account management purposes.
We may pass your information to our third-party service providers such as OutSystems Partners, for the purposes of completing tasks and providing Services to You on Our behalf (for example to provide you with a demo of OutSystems, to provide You training on OutSystems, to develop software applications on OutSystems). However, when we use third-party service providers, we disclose only the personal information that is necessary to deliver the Service and we have a contract in place that requires them to keep your information secure and not to use it for their own direct marketing purposes unless you have provided Your consent or requested Us to do so, or We are required to do so by law, for example, by a court order or for the purposes of prevention of fraud or other crime.
OutSystems does not share Your collected information with business partners, unless: (1) You specifically opt-in to such sharing via an event registration form; or (2) You attend an OutSystems event and allow OutSystems or any of its business partners to scan your attendee badge. If You do not wish for Your information to be shared in this manner, You may choose not to opt-in via event registration forms and elect not to have Your badge scanned at OutSystems events. If You choose to share Your information with business partners in the manners described above, Your information will be subject to the business partners’ respective privacy statements.
Our website and apps will, in certain circumstances, provide you with social plug-ins from various social networks. If you choose to interact with a social network such as Facebook or Twitter (for example by registering an account), your activity on our website or via our apps will also be made available to that social network. This is necessary for the performance of your contract with Us which allows you to interact with a social network. If you are logged in on one of these social networks during your visit to one of our websites or apps or are interacting with one of the social plug-ins, the social network might add this information to your respective profile on this network based on your privacy settings. If you would like to prevent this type of data transfer, please log out of your social network account before you enter one of our websites or apps, or change the app's privacy settings, where possible. Please read the privacy policies of those social networks for detailed information about the collection and transfer of personal information, what rights you have and how you can maintain suitable privacy settings for your needs.
OutSystems will disclose personal information where required by law or legal process, for the administration of justice, to protect your vital interest, for investigations by law enforcement or regulatory bodies, to protect and defend OutSystems property and legal rights, to protect the personal safety of OutSystems website or (mobile) app users, or by order of a valid injunction from a court or law enforcement agency.
Unless described in this Statement, OutSystems does not share, sell, rent, or trade any information with third parties for their promotional purposes.
You have a choice about if You wish to receive information from Us. If You want to receive direct marketing communications from us about the Services and any of our exciting products and services, then you can select your choices by ticking the relevant boxes situated on the form on which we collect your information.
We will not contact you for marketing purposes by email or text message unless you have given your prior consent. You can change your preferences at any time at OutSystems Preference Center.
Public forums and customer testimonials
OutSystems provides blogs or chat rooms on the OutSystems website. Any personal information You choose to submit in such a forum may be read, collected, or used by others who visit those forums, and may be used to send you unsolicited messages. OutSystems is not responsible for the personal information you choose to submit in those forums
OutSystems posts a list of customers and testimonials on OutSystems website that shows information such as customer names and titles. OutSystems obtains the consent of each customer prior to posting any information on such a list or posting testimonials.
Security precautions in place to protect the loss, misuse or alteration of your information
At OutSystems, We believe You have a right to understand how we protect your applications and data.
We use appropriate technical, organizational and administrative security measures to protect the data supplied by You and managed by Us against loss, misuse, unauthorized access, disclosure, alteration, and destruction. Our security measures are continually improved in line with technological developments. For instance, OutSystems has been certified and attested to confirm compliance with ISO 27001, ISO 22301 and SOC 2 Type II standards, by independent auditors, which provides reasonable assurance of Our security and business continuity practices. Unfortunately, and despite all our efforts, no company or service can be guaranteed to be 100% secure.
Even considering OutSystems security endeavours, Our users also play an important role regarding the security of their personal data. The security measures applied on Your assets or the assets of Your company, as well as Your behaviors when using these assets are crucial for maintaining personal data secure. Actions such as defining a weak password to access Our services, not locking Your laptop or mobile device when You left it unattended, or using public assets to login on Our website, all pose a risk. This way, we ask You to take all the necessary precautions in order to avoid security breaches.
For more information about how We secure Your information, you can visit our Trust webpage.
Use of 'cookies'
It is possible to switch off cookies by setting your browser preferences. Turning cookies of may result in a loss of functionality when using our website.
List of cookies
The following table describes the cookies used by the OutSystems website.
|These cookies are provided by Google and are used to collect anonymous website usage data that is then aggregated into statistics that allow us to analyze the aggregate experiences on our websites. We use that information to analyze how how websites are being used and to improve the user experience and the content we provide.
Aprox Size (bytes)
|__utma||60||2 years||This cookie stores each user's amount of visits, and the time of the first visit, the previous visit, and the current visit.|
|__utmb||30||30 min||This Cookie is used in conjunction with __utmc to check approximately how long a visitor stayed on a site, by looking at when a visit starts, and when it approximately ends.|
|__utmc||15||Session||This Cookie is used in conjuntion with __umtb to check approximately how long a visitor stayed on a site, by looking at when a visit starts, and when it approximately ends.|
|__utmz||75||6 months||This cookie is used to store information on how a visitor found our website (search engine, search keyword, website link).|
|These cookies are set by the technology that is used to implement this website, OutSystems. These cookies are used to collect anonymous information for performance statistics, and to improve the user experience.
Aprox Size (bytes)
|osVisit||45||Session||This cookie is used to count the number of visits by this visitor to this website. It is set to expire after 30 minutes, so that if the visitor leaves the website and then returns after 30 minutes, a new visit session is counted.|
|osVisitor||45||never||This cookie indicates that this is a visitor that has visited this website before, and stores the total number of visits this visitor has started on this website.|
|pageLoadedFromBrowserCache||30||Session||This cookie is used to improve usability of our website. It ensures that, in pages where a feedback message is displayed, if the users clicks the back button they will not be shown the same feedback messages again.|
|ASP.NET_SessionId||40||Session||This cookie is set by the underlying technology (Microsoft ASP.NET) used to run this website.|
|These cookies are managed by 3rd party companies that provide targeting and advertising services, and are used to measure conversions of website visitors coming form advertising campaigns.
Aprox Size (bytes)
|__ar_v4||125||5 years||This cookie is associated with the DoubleClick advertising service from Google and helps with anonymous tracking conversion rates from ads.|
|__adroll||55||5 years||This cookie is associated with the AdRoll advertising service from AdRoll and helps with anonymous tracking conversion rates from ads.|
|sess||5||Session||This cookie is associated with the AdRoll advertising service from AdRoll and helps with serving ads and tracking conversion rates from ads.|
|uuid2||25||3 Months||This cookie is associated with the AdRoll advertising service from AdRoll and helps with serving ads and tracking conversion rates from ads.|
|These cookies are used to collect usage statistics that allows us to improve the user experience and improve the functionality and the quality of the information we provide.
Aprox Size (bytes)
|contact||15||6 months||OutSystems Analytics system|
|os_pi_visitor||20||6 months||Link between OutSystems Analytics system and marketing automation system used by OutSystems.|
|visitor_id0000||25||10 years||Marketing automation system used by OutSystems. These cookies are simply a numeric identifier that allow us to recognize repeat visitors, and has no meaning outside the marketing automation system. The number will vary depending on the visitor.|
|pi_opt_in||never||Opt In Cookie: The persistent cookie named “pi_opt_in” is used to stay in compliance with the “Do Not Track” initiative.|
|_mkto_trk||70||2 years||Marketing automation system used by OutSystems.|
|km_ai||40||5 years||These cookies are created by KISSmetrics, a third party analytics service. You can out-out of KISSmetrics though their user privacy page.|
|km_lv||15||5 years||These cookies are created by KISSmetrics, a third party analytics service. You can out-out of KISSmetrics though their user privacy page.|
|km_uk||5||5 years||These cookies are created by KISSmetrics, a third party analytics service. You can out-out of KISSmetrics though their user privacy page.|
Links to other websites
Our website may contain links to other websites run by other organizations. This Statement applies only to our website‚ so We encourage You to read the privacy statements on the other websites You visit. We cannot be responsible for the privacy policies and practices of other sites even if You access them using links from our website.
In addition, if You linked to Our website from a third-party site, We cannot be responsible for the privacy policies and practices of the owners and operators of that third-party site and recommend that You check the Statement of that third-party site.
16 or Under
We are protect the privacy of children aged 16 or under. If You are aged 16 or under‚ please get Your parent/guardian's permission beforehand whenever you provide Us with personal information.
Transferring your information
We are a global group of companies and We have databases in different countries, some of which are operated by the local OutSystems company, and some of which are operated by third parties on behalf of the local OutSystems company. We may transfer Your data to one of the OutSystems databases outside Your country of domicile, potentially including countries which may not require an adequate level of protection for your personal data compared with that provided in your country. For instance, if You use our Services while you are outside the European Union (EU) region, your information may be transferred outside the EU in order to provide you with those Services.
We ensure there are adequate safeguards in place when transferring Your data outside Your country and the EU, including by relying on Privacy Shield, Model Clauses, or other lawful mechanisms or otherwise that the transfer only occurs where permitted by applicable law, with the aim of ensuring that your privacy rights continue to be protected as outlined in this Statement
We use Segment services which may be used to improve our website experience and usability. It collects information such as mouse clicks, mouse movements, page scrolling, and any text keyed into website forms, for aggregated and statistical reporting. This service is only in the OutSystems website and for internal use only.
We will keep your personal information for two years from your last interaction with us, such as the date your account was deleted, your last order, the last time you used one of our apps, or in some other way contacted or interacted, unless a longer or shorter retention period is required by law, is necessary in the course of legal proceedings, or is otherwise needed for a particular purpose under applicable law.
The following are examples of how OutSystems might keep your personal information for as long as necessary for a particular purpose:
- We may keep your personal information collected during a purchase of a Service for as long as required by tax laws (longer than two years in some European countries);
- We may keep your personal information for a shorter period if you ask us to delete your personal information. In such a case, OutSystems will aim to delete your personal information within a maximum period of one month from the date of the request.
In general, We will hold Your personal information on Our systems for as long as is necessary for the relevant Service, or as long as is set out in any relevant contract You hold with Us and for a reasonable period of time afterward, for instance to pursue Our legitimate business interests, conduct audits, comply with Our legal obligations, resolve disputes, and enforce our agreements.
We review our retention periods for personal information on a regular basis.
How you can access and update your information
If you have registered for an account with OutSystems, you may generally update your user settings, profile and, organization’s settings by logging into the OutSystems website or into the applicable Service with your username and password and editing your settings or profile. To update your information, discontinue your account, and/or request return or deletion of Your data associated with your account, please contact firstname.lastname@example.org. For other requests to access, correct, modify or delete Your personal information, please contact email@example.com.
We will respond to your requests without undue delay, but within one month. If permitted under applicable legislation, OutSystems may extend the response period with two further months if such is necessary due to the complexity and number of requests. OutSystems will notify you of any extension and the reason thereof. If OutSystems denies Your request, We shall inform You on the reasons for such a denial.
If information about You is processed by OutSystems on behalf of one of our customers, We will forward Your request to the relevant customer. We will inform You that We have forwarded your request and provide You with the contact details of the relevant client.
OPTING OUT AND UNSUBSCRIBING FROM MARKETING MESSAGES
All of our marketing communications contain an easy way to opt out from receiving future messages, such as a link through which you can unsubscribe. If you would like to opt out of receiving OutSystems marketing messages you may use the unsubscribe link contained in the messages you have received, or alternatively you can contact our:
Data Protection Officer by E-mail at : firstname.lastname@example.org
Note that if you choose to opt out of receiving marketing messages in the manner explained above, we will continue to process your personal information, in particular to allow us to understand your interests and preferences, but we will stop using your personal information to send you personalized or non-personalized marketing messages. If you would like us to stop such processing in part or in full, we have explained how to do this in the above paragraph.
May this Privacy Statement be amended?
We keep this Statement under regular review. OutSystems may amend this Statement. We will notify you of any changes through our Website and/or through a message to you. This Statement was last updated in April, 2018
If you have any questions, comments or requests regarding this Statement or Our processing of your information, please contact:
OutSystems Data Protection Officer
Rua Central Park 2, 2A,
+351 21 4153730
+351 21 4153731