PRIVACY POLICY
Last updated: 3 September 2026
NIFTAD LIMITED (doing business as ISCANET, Aurex and Locivo)
This Privacy Policy (also referred to as this “Privacy Notice”) for NIFTAD LIMITED, doing business as ISCANET, Aurex and Locivo (“NIFTAD LIMITED”, “ISCANET”, “we”, “us”, or “our”), describes how and why we may access, collect, receive, use, store, disclose, transfer, analyse, secure, retain, delete and otherwise process (“process”) personal information when you use our websites, applications, platforms, products and related services (collectively, the “Services”).
This Privacy Policy applies when you:
visit our website at https://www.joiniscanet.com, or any other website of ours that links to this Privacy Policy;
download or use the ISCANET application, progressive web application, employee or business portal, or another application of ours that links to this Privacy Policy;
create or use an ISCANET personal, business, employer, employee, worker, candidate, customer, administrator, developer or other authorised account;
use ISCANET business operations, workforce, recruitment, customer relationship management, communications, scheduling, forms, documents, knowledge, events, collaboration, invoicing, workflow automation, artificial intelligence, integration, API, embedded or related functionality;
use ISCANET career, talent, professional development, community or opportunity-related services; or
engage with us in other related ways, including sales, marketing, support, research, events, partnerships or other communications.
ISCANET is an evolving technology platform. Depending on your organisation, subscription, role, location and configuration, the Services may include workforce and people management, recruitment and applicant tracking, CRM and sales, customer communications, projects and operational workspaces, forms and surveys, documents and knowledge management, electronic signatures, meetings, appointments and scheduling, calendars, events, tickets, notifications, workflow automation, AI-assisted tools, analytics, integrations with third-party services, APIs, embedded experiences, public business pages and other productivity capabilities. Not every feature described in this Privacy Policy is necessarily available to every user, customer, plan or jurisdiction.
Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use the relevant Services. If you have questions or concerns, contact us at contact@joiniscanet.co.uk.
IMPORTANT INFORMATION ABOUT OUR ROLE
Depending on the circumstances, NIFTAD LIMITED may act as a controller, joint controller, processor, service provider, contractor or similar regulated role under applicable privacy law.
We generally act as a controller where we determine the purposes and means of processing, for example for our own account registration, website operations, security, billing administration, customer relationship management, support, product analytics, direct marketing, legal compliance and other corporate activities.
Where a business or organisation uses ISCANET to process information about its employees, workers, candidates, customers, prospects, suppliers, contacts or other people, that organisation will often determine why and how the information is processed and will therefore generally be the controller, while NIFTAD LIMITED acts as its processor or service provider. In those situations, the organisation is responsible for providing its own appropriate privacy information and lawful basis, and requests about that data may need to be directed to the organisation first.
CONTENTS
1. What information do we collect?
2. How do we process your information?
3. What legal bases do we rely on to process your information?
4. When and with whom do we share your personal information?
5. What is our stance on third-party websites, applications and services?
6. Do we use cookies and other tracking technologies?
7. Do we offer artificial intelligence-based products?
8. How do we handle Google Workspace and Google user data?
9. How do we handle your social logins?
10. How do we process business customer data and organisational data?
11. How do we process workforce, employee and worker data?
12. How do we process recruitment, applicant and candidate data?
13. How do we process CRM, customer and prospect data?
14. How do we process communications, messaging and email data?
15. How do we process forms, bookings, appointments, events and embedded submissions?
16. How do we process documents, knowledge content and electronic signatures?
17. How do integrations, APIs, automations, developer tools and marketplace functionality affect your data?
18. How do we process location information?
19. How long do we keep your information?
20. How do we keep your information safe?
21. How do we respond to security incidents and personal data breaches?
22. Do we collect information from minors?
23. What are your privacy rights?
24. Controls for Do-Not-Track and Global Privacy Control features
25. Do United States residents have specific privacy rights?
26. Do other regions have specific privacy rights?
27. How do we handle international data transfers?
28. Marketing and promotional communications
29. Account information, account closure and deletion
30. Do we make updates to this Privacy Policy?
31. How can you contact us about this Privacy Policy?
32. How can you review, update, correct or delete the data we collect from you?
33. Google API Services Limited Use disclosure
1. WHAT INFORMATION DO WE COLLECT?
In Short: We collect personal information that you provide to us, information provided by organisations that use ISCANET, information from connected services and third parties where authorised, and certain technical, device, usage and location information collected automatically when you use the Services.
Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you register for the Services, express an interest in obtaining information about us or our products and Services, participate in activities on the Services, submit forms, create records, upload content, communicate with us, purchase a subscription, use an AI or integration feature, or otherwise interact with us.
The personal information we collect depends on the context of your interactions, the choices you make and the products and features you use. It may include:
names, aliases and display names;
phone numbers and other contact details;
email addresses;
postal, business and billing addresses;
job titles, departments, roles and organisational relationships;
usernames, account identifiers and authentication-related data;
passwords where password-based authentication is used, or other authentication information handled through secure authentication systems;
contact, communication and notification preferences;
profile information and profile photographs;
business, professional, education and employment information;
documents, files, form submissions, messages, notes, comments and other content you choose to provide;
billing, subscription and transaction information;
support requests, survey responses and feedback; and
any other information you choose to submit through a feature of the Services.
Business and organisational information
If you create, administer or participate in a business or organisational workspace, we may process information including:
organisation name, trading name, company details, website, address, industry and business profile;
organisation owners, administrators, authorised users, teams, departments, roles and permissions;
subscription, billing, plan and account configuration information;
organisation settings, workflow configuration, integrations and connected services;
organisational units, reporting lines, positions and role assignments;
business activity, audit information and administrative actions; and
records created or uploaded by the organisation through the Services.
Workforce, employee and worker information
Where an organisation uses workforce or people-management features, the organisation may provide or create information about employees, workers, contractors, volunteers, consultants or other personnel. Depending on the functionality used, this may include:
identity and contact details;
employee or worker identifiers;
job title, department, position, manager and reporting information;
employment or engagement status, start date, termination date and rehire information;
work location, schedules, attendance and clock-in/clock-out records;
leave, absence and availability information;
compensation, payroll-related, bank, tax or benefit administration information where relevant;
onboarding, offboarding, policy acknowledgement and training information;
documents, agreements and electronic signatures;
performance, recognition, feedback and development information;
emergency or employment-related contacts;
workforce-related communications and operational records; and
other information configured or entered by the organisation.
Recruitment, applicant and candidate information
Where recruitment, hiring, assessment or talent features are used, information may include:
name, contact details and account information;
CVs, résumés, cover letters, portfolios and professional profiles;
employment history, education, qualifications, professional experience and skills;
application responses, assessment results and interview information;
candidate communications, notes, ratings, workflow status and hiring-stage information;
availability, location and work preferences;
right-to-work, immigration or sponsorship-related information where lawfully required by the relevant organisation;
audio, video, transcripts or AI-assisted interview information where a feature is enabled and appropriate notice or consent is provided; and
other information supplied by the candidate, recruiter, referrer or hiring organisation.
CRM, customer, prospect and business-contact information
Where organisations use ISCANET CRM, sales, communications or customer-management features, they may process:
names, email addresses, telephone numbers, job titles and organisations;
customer, prospect, supplier or business-contact details;
notes, enquiries, activities, tasks and follow-up records;
sales opportunities, pipeline stages, deals and commercial relationship information;
meeting, appointment and booking information;
communication history, email and messaging information;
consent, suppression, unsubscribe and communication-preference records;
campaign and sequence activity; and
other information relevant to the organisation's relationship with the individual.
Sensitive information
When necessary, with your consent where required, on the instructions of a business customer, or as otherwise permitted by applicable law, we may process sensitive or special category information. Depending on the Services and customer configuration, this may include information revealing race or ethnic origin, health or absence information, disability-related information, immigration or right-to-work information, student or education data, protected-characteristic information, account authentication data, financial information or other sensitive information.
Organisations using ISCANET are responsible for ensuring that they have an appropriate lawful basis and, where required, an additional condition for processing special category or sensitive information.
Payment data
We may collect information necessary to administer subscriptions and payments. Full payment-card information may be collected and processed directly by a third-party payment processor rather than stored by ISCANET. We currently use or may use Stripe for payment processing. Stripe's privacy information is available at Stripe Privacy Policy.
We may receive limited information from the payment provider, such as customer identifiers, subscription status, amount, currency, invoice or transaction references and payment status.
Social media and third-party login data
We may provide the option to register or sign in using an existing third-party identity or social account, such as Google or, where offered, another provider. If you choose to register or sign in this way, we may receive profile and authentication information from that provider as described in Section 9.
Application and device-permission data
If you use our application or progressive web application, we may request access to device features where necessary for a particular function. For example, we may request permission to send push notifications about your account, reminders or product features. You can generally control these permissions in your browser, operating system or device settings.
Information automatically collected
In Short: Some information — such as your IP address and browser, device, application and usage characteristics — is collected automatically when you visit or use the Services.
We automatically collect certain technical and usage information when you visit, use or navigate the Services. This information may not directly reveal your name, but can include device and usage information such as IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, approximate location, information about how and when you use the Services and other technical information. This information is primarily used to maintain the security and operation of our Services, diagnose issues, prevent abuse and support analytics and reporting.
Log and usage data
Log and usage data may include IP address, device information, browser type, settings, dates and times of access, pages or files viewed, searches, clicks, feature usage, session activity, system activity, error reports, crash information, application performance, security events, request metadata and other diagnostic or operational information.
Device data
Device data may include information about the computer, phone, tablet or other device you use to access the Services, including IP address or proxy server, device or application identifiers, browser type, hardware model, internet service provider or mobile carrier, operating system, system configuration, language and related technical attributes.
Location data
We may collect or infer location data that is precise or imprecise depending on the feature and the permissions you grant. Approximate location may be inferred from IP address. Where a location-dependent feature is enabled, such as a location-aware workforce attendance or geofencing feature, we may request more precise device location such as GPS-derived information. You may generally refuse or disable location permission through your device or browser settings, but doing so may prevent certain location-dependent Services from functioning.
Information from other sources
We may also receive personal information from:
a business, employer, recruiter or organisation that uses ISCANET and has a relationship with you;
another authorised user who creates or manages a record relating to you;
third-party identity, communication, calendar, payment or productivity services you choose to connect;
service providers and partners acting on our behalf;
referral sources;
publicly available professional or business information where collection is lawful and appropriate; and
other sources where you have authorised disclosure or where applicable law permits it.
Google API information
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Additional details are provided in Sections 8 and 33.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve and administer our Services, communicate with you, operate business and workforce functionality, support integrations and AI-assisted features, protect our Services, prevent fraud, comply with law and carry out other purposes with an appropriate lawful basis. We may also process information for other purposes with your consent where consent is required.
We process personal information for a variety of reasons, depending on how you interact with our Services, including:
To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create, access and maintain your account, authenticate your identity, recover access, manage settings and keep the account in working order.
To provide and operate the Services. We process information necessary to deliver the features you or the organisation using ISCANET has requested, including business operations, workforce management, recruitment, CRM, communications, scheduling, forms, documents, events, collaboration, workflow automation, AI-assisted tools, integrations and related functionality.
To establish and administer business workspaces. We may process information to create and manage organisations, authorised users, roles, permissions, plans, subscriptions, settings, integrations, workflow configuration and other administrative functions.
To provide workforce and people-management functionality. Where enabled, we may process workforce information to support employee or worker administration, attendance, scheduling, leave, onboarding, offboarding, documents, policies, recognition, feedback, compensation administration and other people-related functions.
To provide recruitment, candidate and hiring functionality. We may process applicant information to support applications, candidate pipelines, assessments, interviews, communications, hiring workflows, recruitment administration and related activities.
To provide CRM, sales and customer-management functionality. We may process customer and prospect information so authorised organisations can manage relationships, communications, opportunities, activities, follow-ups, sales pipelines and business records.
To provide communications functionality. We may process emails, messages, contact information and communication metadata where necessary to provide user-facing communication features, associate relevant communications with business records and support authorised workflows.
To provide third-party integrations. Where you choose to connect a service, we may process information necessary to establish, authenticate, maintain and operate the integration in accordance with the permissions granted.
To provide Google Workspace functionality. Where authorised, we process permitted Google user data only for the purposes disclosed in this Privacy Policy and in accordance with the Google API Services User Data Policy, including Limited Use requirements.
To provide artificial intelligence-assisted functionality. We may process information submitted to AI-assisted features in order to generate requested summaries, content, insights, recommendations, classifications, workflow assistance or other user-facing outputs.
To provide forms, bookings, appointments, surveys and event functionality. We may process information submitted through forms, appointment pages, booking experiences, assessments, surveys, registrations and similar interfaces to process the relevant request and provide the functionality configured by the organisation.
To manage documents, knowledge content and electronic signatures. We may process documents, files, signatures, timestamps, signer information, version history and related records to provide document management, collaboration, knowledge-management and e-signature functionality.
To process payments and subscriptions. We may process account, billing, subscription, transaction and payment-related information to manage purchases, invoices, subscriptions, refunds and our commercial relationship with customers.
To provide customer service and support. We may process information to respond to enquiries, investigate problems, troubleshoot issues, provide technical assistance, resolve complaints and communicate about support matters.
To communicate with you about the Services. We may send administrative, operational, transactional or service-related communications such as security alerts, account notifications, reminders, product updates and messages necessary to operate your account or provide requested Services.
To request feedback. We may process information when necessary to request feedback, conduct surveys, understand your experience and contact you about your use of the Services.
To send marketing and promotional communications. We may process contact information and marketing preferences to send information about products, services, events, resources, offers and related opportunities where this is lawful and consistent with your preferences. You can opt out of marketing emails at any time.
To deliver targeted or personalised advertising, where permitted and enabled. We may process public-website marketing and interaction information to develop or display personalised content or advertising tailored to interests, location or prior interactions, subject to applicable consent and opt-out requirements. Google Workspace API data, customer confidential workspace content, employee records, applicant records and CRM message content are not used for targeted advertising.
To personalise your experience. We may use appropriate information to tailor account settings, content, workflow suggestions, feature recommendations or other aspects of the user experience where lawful and relevant.
To protect our Services. We may process information as part of our efforts to keep the Services safe and secure, including access control, monitoring, abuse prevention, vulnerability management, fraud monitoring and investigation.
To identify usage trends. We may process information about how the Services are used to understand feature adoption, engagement, performance and patterns of use so that we can improve them.
To determine the effectiveness of marketing and promotional campaigns. We may analyse appropriate information to understand how users engage with our campaigns, communications, content and events and to improve their relevance and effectiveness.
To improve and develop our Services. We may process appropriate information to troubleshoot, test, maintain, improve and develop existing products, features, reliability, usability and security.
To maintain audit, accountability and business records. We may retain records of significant account, administrative, security, contractual or business activity to support compliance, investigations, dispute resolution and accountability.
To prevent fraud, abuse and unlawful activity. We may process information to identify, investigate, prevent or respond to fraud, unauthorised access, misuse, policy violations or unlawful conduct.
To enforce our legal terms and agreements. We may process information where necessary to enforce contractual rights, acceptable-use requirements, policies, subscriptions and other agreements.
To comply with legal and regulatory obligations. We may process information to comply with applicable laws, court orders, regulatory requirements, tax and accounting obligations, lawful government requests and other legal responsibilities.
To establish, exercise or defend legal claims. We may process information where reasonably necessary to protect our rights, obtain professional advice, establish facts, resolve disputes or defend legal claims.
To manage corporate transactions. Information may be processed in connection with a potential or actual merger, acquisition, investment, financing, restructuring, sale of assets or similar transaction, subject to applicable law.
To save or protect an individual's vital interests. We may process information where necessary to protect an individual's life, safety or other vital interests, such as to prevent serious harm.
For other purposes with your consent. Where we wish to process personal information for another purpose that requires consent, we may ask for your consent before carrying out that processing.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law, such as consent, performance of a contract, compliance with legal obligations, protection of vital interests or pursuit of legitimate interests that are not overridden by your rights.
If you are located in the United Kingdom, European Economic Area or another jurisdiction applying comparable rules
The UK GDPR, EU GDPR and related data-protection laws require us to explain the lawful bases on which we rely when we act as controller. Depending on the processing activity, we may rely on:
Consent. We may process your information where you have given permission for a specific purpose. You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Contract. We may process information where necessary to enter into or perform a contract with you, including providing paid or requested Services.
Legitimate Interests. We may process information where reasonably necessary for our legitimate interests or those of another person and those interests are not overridden by your interests, rights or freedoms.
Legal Obligations. We may process information where necessary to comply with laws, regulatory requirements, lawful requests, tax or accounting requirements or legal proceedings.
Vital Interests. We may process information where necessary to protect your vital interests or the vital interests of another person.
Examples of legitimate interests may include:
providing, maintaining, securing and improving our Services;
supporting customers and responding to enquiries;
understanding how Services are used and improving user experience;
preventing fraud, misuse and security incidents;
managing our commercial relationships and corporate operations;
supporting appropriate business-to-business marketing and communications;
measuring the effectiveness of our communications and marketing;
developing and testing product improvements; and
establishing, exercising or defending legal rights.
Special category and sensitive information
Where we act as controller and process special category personal data under UK or EU law, we also rely on an applicable additional condition, which may include explicit consent, employment or social-protection law obligations, protection of vital interests, legal claims, substantial public interest or another condition permitted by law. Where a customer controls the relevant information, that customer is responsible for identifying its lawful basis and additional condition.
If you are located in Canada
Where Canadian privacy law applies, we may process information with express or implied consent as permitted by law. You may withdraw consent subject to legal or contractual restrictions and reasonable notice.
In limited circumstances, Canadian law may permit collection, use or disclosure without consent, including where:
collection is clearly in the interests of an individual and consent cannot be obtained in a timely way;
processing is necessary for investigations or fraud detection and prevention;
processing is connected with certain business transactions and statutory conditions are satisfied;
information is contained in a witness statement and collection is necessary to assess, process or settle an insurance claim;
processing is necessary to identify an injured, ill or deceased person and communicate with next of kin;
there are reasonable grounds to believe an individual is, has been or may be a victim of financial abuse;
collection or use with consent would reasonably be expected to compromise the availability or accuracy of information and the processing is reasonable for investigating a breach of an agreement or a contravention of Canadian or provincial law;
disclosure is required by subpoena, warrant, court order or rules relating to production of records;
information was produced by an individual in the course of employment, business or profession and the processing is consistent with the purpose for which it was produced;
processing is solely for journalistic, artistic or literary purposes where the law permits; or
the information is publicly available and the processing is permitted by applicable regulations.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
In Short: We may disclose personal information in specific situations described below and with categories of recipients that help us provide, secure, support, administer and improve the Services or comply with law.
Vendors, consultants, contractors and service providers
We may disclose information to third-party vendors, service providers, contractors or agents that perform services for us or on our behalf and require access to information to perform that work. Where they act as our processors, we seek to put appropriate contractual protections in place and restrict their processing to our instructions and permitted purposes.
Categories of service providers may include:
cloud infrastructure, hosting and data-storage providers;
authentication and identity providers;
payment processors;
communications, email and messaging providers;
customer support and service-management providers;
analytics and performance-monitoring providers;
security, fraud-prevention and incident-response providers;
AI service providers where an AI feature is used;
document, e-signature and productivity service providers;
integration and API providers;
professional advisers, auditors and consultants; and
other suppliers reasonably necessary to operate the Services.
Business customers, account owners and authorised users
Where you use ISCANET through a business or organisation, personal information and activity within that organisation's workspace may be visible to authorised owners, administrators, managers or other users according to the organisation's configuration, roles and permissions. The organisation is responsible for determining appropriate access within its workspace.
Connected third-party services
If you choose to connect a third-party service, we may exchange information with that service as necessary to establish and provide the requested integration and within the permissions you authorise.
Business transfers
We may share or transfer information in connection with, or during negotiations of, a merger, financing, acquisition, restructuring, sale of company assets or similar corporate transaction, subject to applicable legal requirements. Google user data remains subject to Google's applicable Limited Use requirements and additional restrictions described in Sections 8 and 33.
Affiliates
We may disclose information to affiliates under common ownership or control where appropriate for legitimate corporate, operational, support or compliance purposes, subject to this Privacy Policy and applicable law.
Business partners
We may work with business partners to provide certain products, services, events, integrations, referrals or promotions. Where disclosure of personal information is required, we will do so only where an appropriate legal basis exists and in accordance with applicable notices and choices.
Google Maps Platform APIs and mapping services
Where a mapping or location feature uses Google Maps Platform APIs, information such as location or map requests may be processed by Google in accordance with Google's terms and privacy practices. You can review Google's Privacy Policy. Location accuracy depends on device, GPS, Wi-Fi, network and other factors and is not guaranteed.
Legal, regulatory and safety disclosures
We may disclose information where we reasonably believe disclosure is necessary to comply with applicable law, a court order, subpoena, regulatory request or other lawful process; to protect rights, safety or property; to investigate or prevent fraud, abuse or security incidents; or to establish, exercise or defend legal claims.
Third-party promotions, referrals, marketplaces or offer interfaces
The Services may in future include partner referrals, marketplace listings, promotions, or third-party offer interfaces. If a feature materially changes how your personal information is shared, we will provide appropriate additional notice or obtain consent where required rather than relying on this Privacy Policy to authorise an undisclosed materially different use.
Important restriction relating to Google user data
We do not sell Google user data, transfer Google user data to data brokers or information resellers, or use Google user data for targeted, personalised, retargeted or interest-based advertising. Google user data is subject to the additional restrictions in Sections 8 and 33.
5. WHAT IS OUR STANCE ON THIRD-PARTY WEBSITES, APPLICATIONS AND SERVICES?
In Short: We are not responsible for the privacy or security practices of independent third parties that are not controlled by us, even where we link to or integrate with them.
The Services may link to third-party websites, online services, mobile applications, integrations or advertisements that are not affiliated with or controlled by us. The inclusion of a link or integration does not necessarily imply endorsement. Information you provide directly to an independent third party is governed by that third party's privacy notice and terms.
We encourage you to review the privacy and security practices of third-party services before providing information or granting access. Where ISCANET acts as a processor and engages subprocessors to provide the Services, our responsibilities to the relevant customer are governed by applicable agreements and law.
6. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
In Short: We may use cookies, pixels, local storage and similar technologies for authentication, security, preferences, functionality, analytics and, where enabled and lawfully permitted, marketing or advertising.
We may use cookies and similar tracking technologies, such as web beacons, pixels, local storage or software development kit technologies, when you interact with our public websites or Services. Some technologies are necessary to operate the Services, maintain sessions, authenticate users, prevent fraud, remember preferences, prevent crashes and support core functionality.
Where enabled and permitted by applicable law, we may also use analytics or marketing technologies to understand engagement, measure campaign effectiveness, remember marketing choices, provide more relevant content, support advertising or retargeting, and understand website conversions.
Where law requires consent for non-essential cookies or similar technologies, we will seek consent through an appropriate cookie or preference mechanism. You may also be able to manage cookies through your browser.
Where certain advertising or analytics disclosures are treated as a “sale” or “sharing” under applicable US state law, eligible users may exercise applicable opt-out rights as described in Section 25.
Google Workspace API data, customer confidential workspace content, workforce records, candidate records and CRM message content are not used for targeted advertising.
A separate Cookie Policy or cookie preference interface may provide more detailed information about the specific technologies in use.
7. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: We offer or may offer products, features and tools powered or assisted by artificial intelligence, machine learning or similar technologies. Information may be processed by ISCANET and, where necessary, third-party AI service providers to provide the requested feature.
Use of AI technologies
As part of our Services, we may provide AI-assisted products, features or tools (collectively, “AI Products”). These tools are designed to assist users with productivity, analysis, content creation, workflow assistance and related functions.
AI Products may be used for functions including:
AI applications and assistants;
document generation, rewriting and summarisation;
AI-generated business or workforce insights;
text analysis, extraction, classification and organisation;
customer and CRM summaries, next-action suggestions and workflow assistance;
recruitment and candidate-support functionality;
knowledge retrieval and question answering;
automation assistance;
content drafting and analysis; and
other user-facing AI-assisted functions.
AI service providers
We may provide AI Products through third-party AI service providers, including OpenAI where enabled. Information submitted to an AI Product, and the resulting output, may be processed by the relevant provider as necessary to provide the requested feature, subject to applicable agreements, safeguards and provider terms. Information about OpenAI's business-data practices is available at OpenAI Business Data Privacy and OpenAI's Terms and Policies.
How we process information using AI
Personal information processed through AI Products remains subject to this Privacy Policy. Users and organisations must have authority to submit information to an AI feature and should avoid submitting information that is unnecessary for the requested purpose.
AI-generated outputs can be incomplete, inaccurate or misleading and should be reviewed by an appropriately authorised person before being relied upon for important employment, recruitment, legal, financial, compliance or other significant decisions.
Automated decision-making
Some AI or automation features may assist users by prioritising, summarising, classifying, scoring, recommending or triggering workflow steps. Where applicable law regulates solely automated decisions that produce legal or similarly significant effects, we and organisations using ISCANET are expected to comply with applicable requirements, including providing human involvement or rights where required.
Google Workspace API data and AI
Google Workspace API user data is subject to additional restrictions. ISCANET does not use raw or derived Google Workspace API user data to develop, improve or train generalised or non-personalised AI or machine-learning models, and does not transfer such data to third parties for that purpose. See Sections 8 and 33.
How to opt out or control AI use
Where an AI feature is optional, you may be able to choose not to use it or adjust relevant account or organisation settings. You may also contact us using the information in Section 31. Where your information is controlled by an organisation, the organisation may determine whether particular AI features are enabled.
8. HOW DO WE HANDLE GOOGLE WORKSPACE AND GOOGLE USER DATA?
In Short: Connecting Google is optional. Where you authorise a Google integration, ISCANET accesses only the Google user data needed for the user-facing feature you enable, uses it only for disclosed purposes, applies appropriate security safeguards and complies with Google API Services User Data Policy and Limited Use requirements.
Connecting Google is optional
ISCANET may allow an authorised user to connect a Google Account or Google Workspace service. The connection is initiated by the user and authorised through Google's OAuth consent process. Google shows the permissions requested before access is granted. You are not required to connect Google in order to use unrelated ISCANET functionality.
Current Gmail integration and requested permissions
The current Gmail-to-CRM integration is designed to support customer relationship management and productivity by synchronising relevant email communications into an authorised business workspace.
The current Gmail integration requests the Gmail read-only permission, together with basic Google identity permissions used to identify the connected account. Google's description of the Gmail read-only scope is “View your email messages and settings.” The current integration does not request Gmail permissions to send, delete or modify messages.
Google data we may access
Depending on the authorised Google feature, ISCANET may access limited Google user data such as:
the connected Google account email address and basic identity information;
Gmail message identifiers;
sender, recipient and CC information;
message subject;
message dates and timestamps;
email body or content for messages that are relevant to the enabled functionality;
Gmail thread or conversation identifiers and related metadata; and
other limited metadata reasonably necessary to identify, synchronise and display relevant communications.
The current Gmail CRM sync is designed to focus on communications involving contacts relevant to the organisation's CRM. It does not currently sync email attachments as part of that feature. If we materially expand the categories of Google data accessed or introduce a materially different use, we will update relevant disclosures and permissions before using the additional data.
Why we access Gmail data
Authorised Gmail information may be used to:
identify relevant communications involving CRM contacts;
display or maintain communication history within the organisation's ISCANET CRM;
help authorised users understand customer or prospect interactions;
support follow-up tasks and authorised workflows;
reduce manual duplication of relevant business communications between Gmail and ISCANET;
detect replies or communication events needed for user-configured CRM workflows; and
provide or improve the specific user-facing Gmail/CRM functionality the user has enabled.
How Google data is stored and protected
Where necessary to provide the integration, relevant Google-derived information may be stored in ISCANET. Credentials or tokens needed to maintain an authorised connection are stored using security measures designed to protect them against unauthorised access. We apply technical and organisational safeguards appropriate to the sensitivity of the data, including access controls, encryption or cryptographic protection where appropriate, authentication, monitoring, logging and tenant isolation.
Human access to Google user data
We do not permit personnel or contractors to read Google user data except where permitted by Google's applicable policies and necessary for a permitted purpose, such as when the user has affirmatively requested support relating to specific data, for security or abuse investigation, to comply with applicable law, or in another situation expressly permitted by the Google API Services User Data Policy.
Sharing and transfer restrictions
ISCANET does not:
sell Google user data;
transfer Google user data to advertising platforms, data brokers or information resellers;
use Google user data for targeted, personalised, retargeted or interest-based advertising;
use Google user data to determine creditworthiness or for lending purposes; or
use raw or derived Google Workspace API user data to develop, improve or train generalised or non-personalised AI or machine-learning models.
Google user data may only be transferred where permitted under Google's policies, such as where necessary to provide or improve an appropriate user-facing feature with user consent, for security purposes, to comply with law, or in another permitted circumstance.
Google Workspace API data and AI
ISCANET does not use raw or derived Google Workspace API user data to develop, improve or train generalised or non-personalised AI or machine-learning models. We do not transfer Google Workspace API user data to third parties for such training. If a future user-facing feature proposes to use Google data in an AI-assisted workflow, we will ensure the use is permitted, appropriately disclosed and authorised before implementation.
Disconnecting Google and revoking access
You may disconnect the Google integration through available ISCANET controls. You may also revoke access through your Google Account. Google's third-party connections controls are available at Google Account third-party connections.
Disconnecting or revoking access stops future synchronisation once the disconnection takes effect. Records already imported into the organisation's CRM may remain where necessary to preserve legitimate business records, comply with customer instructions, satisfy legal or security obligations or meet applicable retention requirements. Such retained data remains subject to this Privacy Policy and applicable deletion rights.
Google policy commitments
ISCANET's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We also design Google Workspace integrations with reference to the Google Workspace API User Data and Developer Policy.
Future Google integrations
ISCANET may in future offer additional Google integrations, such as calendar, meeting, contact, file or productivity functionality. We will request only permissions necessary for implemented features and will not request access solely to “future-proof” speculative functionality. Where a new integration materially changes the Google user data accessed or how it is used, we will update our disclosures and request appropriate authorisation before the new processing occurs.
9. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: If you choose to register or sign in using a third-party account, we may receive limited profile and authentication information from that provider.
Where we offer third-party or social sign-in, the profile information we receive varies by provider and permissions. It may include your name, email address, profile picture, provider account identifier and other information you choose to make available.
We use this information for authentication, account administration, security and other purposes disclosed in this Privacy Policy or made clear at the point of connection. We do not control how the third-party identity provider independently processes your information, and you should review that provider's privacy notice.
10. HOW DO WE PROCESS BUSINESS CUSTOMER DATA AND ORGANISATIONAL DATA?
In Short: Business customers may use ISCANET to process personal information for their own purposes. In many of those situations, the business is the controller and ISCANET processes information on its behalf.
An organisation may configure ISCANET to manage its workforce, candidates, customers, prospects, operations, communications, documents, forms, schedules, workflows and other business records. The organisation determines which data is entered, who can access it, why it is used and how long it should be retained, subject to the platform's functionality and the parties' agreement.
Where ISCANET acts as processor or service provider:
we process customer-controlled personal information on documented instructions and as necessary to provide, secure and support the Services;
we do not independently repurpose customer-controlled personal information for unrelated purposes merely because it is hosted on ISCANET;
we may use subprocessors to provide infrastructure or support, subject to applicable contractual safeguards;
we assist customers with data-protection obligations where required by law and contract; and
individual rights requests may be referred to or coordinated with the relevant customer.
Business customers are responsible for ensuring that they provide legally required privacy notices, obtain necessary consents, select appropriate lawful bases, configure access and permissions appropriately, and use ISCANET in accordance with employment, marketing, communications, privacy and other applicable laws.
11. HOW DO WE PROCESS WORKFORCE, EMPLOYEE AND WORKER DATA?
In Short: Organisations may use ISCANET to manage workforce information. The organisation will generally control that information and is responsible for lawful workplace processing and transparency.
Workforce features may process information relating to employees, workers, contractors, volunteers or other personnel for purposes such as organisational administration, attendance, scheduling, leave, onboarding, offboarding, documents, policies, recognition, feedback, compensation administration, training and related operations.
Where location-aware attendance or clock-in functionality is enabled, an organisation may use device location or geofencing information to confirm that a clock-in or clock-out occurs within an authorised location. Organisations are responsible for ensuring that such monitoring is necessary, proportionate, transparent and lawful.
Where electronic signing is enabled, records may include signer identity, signature, document version, timestamp, device or network information and related audit information in order to evidence the signing event.
If you are an employee or worker using ISCANET through your organisation and you have questions about the organisation's use of your information, you should normally contact your employer or organisation first.
12. HOW DO WE PROCESS RECRUITMENT, APPLICANT AND CANDIDATE DATA?
In Short: Recruitment information may be processed to support applications, assessments, interviews, communications and hiring workflows configured by the recruiting organisation.
Recruitment features may allow an organisation to collect or create CVs, application responses, candidate notes, skills information, assessment results, interview records, communication history, stage progression and other hiring information.
Where AI-assisted recruitment features are used, the technology may summarise, classify, extract or organise information or provide recommendations to authorised users. Organisations are responsible for ensuring that their use of such features is lawful, fair, appropriately transparent and subject to human oversight where required.
Recruitment information should not be used to make unlawful discriminatory decisions. Sensitive or protected-characteristic information should be processed only where there is an appropriate legal basis and purpose.
13. HOW DO WE PROCESS CRM, CUSTOMER AND PROSPECT DATA?
In Short: Businesses may use ISCANET CRM to manage customer and prospect relationships, communications, deals, tasks, appointments and related activities.
The business using ISCANET generally determines the purposes for which its customer, prospect and business-contact information is processed. ISCANET provides tools to store and organise relevant records, associate communications with contacts, manage opportunities and follow-ups, and automate authorised workflows.
Businesses are responsible for ensuring that customer communications, campaigns, sequences and follow-up activities comply with applicable electronic marketing, privacy and consumer-protection laws, including obtaining consent where required and respecting opt-outs, suppression records and other communication preferences.
CRM information imported from connected services, including relevant Gmail communications where authorised, remains subject to the additional rules described in this Privacy Policy.
14. HOW DO WE PROCESS COMMUNICATIONS, MESSAGING AND EMAIL DATA?
In Short: Where communication features are used, we may process message content and metadata necessary to provide, route, store, secure and associate communications with relevant records.
Depending on the feature, communications information may include:
sender and recipient details;
email addresses and telephone numbers;
subject lines and message content;
dates and timestamps;
thread, conversation and provider identifiers;
delivery, bounce, complaint, open, click or response information where available and lawful;
attachments where supported;
communication preferences and suppression records; and
information needed to associate a communication with a CRM, ticket, booking or other business record.
We may process communications to provide the requested feature, maintain conversation history, support user-configured workflows, detect replies, provide notifications, troubleshoot delivery issues, prevent abuse and comply with law.
15. HOW DO WE PROCESS FORMS, BOOKINGS, APPOINTMENTS, EVENTS AND EMBEDDED SUBMISSIONS?
In Short: ISCANET may allow organisations to create public or embedded forms, booking pages, appointment pages, event registrations, surveys and other data-collection experiences.
Information submitted through these experiences may include names, contact information, appointment preferences, form answers, event registrations, consent choices, business enquiries and other information requested by the organisation.
Where a customer determines the questions asked and the purpose of collection, the customer will generally act as controller and ISCANET as processor or service provider.
ISCANET may provide embeddable code or hosted interfaces that allow an organisation to collect information through its own website or digital property. The organisation is responsible for ensuring that its own privacy notice explains the collection and that it has a lawful basis for the information it requests.
16. HOW DO WE PROCESS DOCUMENTS, KNOWLEDGE CONTENT AND ELECTRONIC SIGNATURES?
In Short: Users may create, upload, edit, share, sign or store documents and knowledge content. Those materials may contain personal information selected by the relevant user or organisation.
Document and knowledge functionality may include pages, documents, notes, policies, attachments, version history, collaboration activity, permissions, comments, signatures and other user-generated content.
Electronic signature functionality may process signer identity, email address, signature, document version, signing timestamp, IP address, user-agent or device information and related evidence where necessary to establish the integrity and auditability of a signature event.
Customers are responsible for deciding what information they place in documents and for ensuring that documents containing sensitive or confidential information are shared only with appropriately authorised users.
17. HOW DO INTEGRATIONS, APIs, AUTOMATIONS, DEVELOPER TOOLS AND MARKETPLACE FUNCTIONALITY AFFECT YOUR DATA?
In Short: ISCANET may allow authorised users and developers to connect external services, configure automated workflows or use APIs and developer capabilities. Data flows depend on the integration, permissions and workflow selected.
Integrations
When you connect a third-party service, ISCANET may send or receive information necessary to provide the requested integration. The exact information depends on the integration and the permissions granted.
APIs and developer capabilities
ISCANET may provide APIs, webhooks, developer capabilities, MCP-compatible functionality, application integrations or other mechanisms that allow authorised systems to interact with ISCANET. Access may be governed by authentication, permissions, customer configuration, usage limits and contractual requirements.
Automations and workflows
Organisations may configure workflow automations that respond to business events and perform actions, such as creating follow-up tasks, sending notifications, updating records or triggering other authorised steps. Personal information may be processed as part of these workflows where necessary to perform the configured action.
Marketplace and third-party applications
If ISCANET introduces a marketplace or third-party application ecosystem, third-party applications may have their own privacy policies and data-processing practices. We will provide appropriate permission and disclosure mechanisms for third-party access and may restrict or revoke integrations that create privacy, security or policy risks.
This Privacy Policy does not authorise developers or customers to use APIs, automations or integrations in ways that violate applicable law, contractual restrictions, consent requirements or platform policies.
18. HOW DO WE PROCESS LOCATION INFORMATION?
In Short: Some Services may use approximate or precise location information where necessary for a user-facing feature, such as location-aware attendance, scheduling or mapping.
Approximate location may be inferred from IP address or network information. More precise location may be obtained from your device where a feature requests it and you grant permission.
You can generally disable precise location permission in your device or browser settings. If you refuse or withdraw permission, some location-dependent features may not work.
Where an organisation uses workforce location features, that organisation is responsible for ensuring the use is lawful, necessary, proportionate and transparently explained to affected personnel.
19. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep personal information only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, security needs or legitimate record-keeping requirements.
Retention periods vary depending on the nature of the information, the feature through which it was collected, the relevant customer's instructions, contractual obligations, legal and regulatory requirements, security considerations, dispute needs and the sensitivity of the information.
Examples include:
account and profile information may be retained while an account or customer relationship remains active and for an appropriate period afterwards;
customer-controlled workforce, recruitment, CRM, form, document and operational information may be retained according to the customer's instructions, contract and configured retention practices;
billing, subscription, tax and transaction information may be retained for periods required by law or legitimate accounting obligations;
security, audit and access records may be retained for periods necessary to investigate incidents, enforce rights and maintain platform integrity;
support and complaint records may be retained for an appropriate period after resolution;
Google-derived CRM records already imported before a Google connection is revoked may remain where needed to preserve authorised business records or meet lawful retention requirements; and
backup or archival copies may remain securely isolated until normal deletion or overwriting processes occur.
When we no longer have an ongoing legitimate need or legal basis to retain personal information, we will delete, anonymise or otherwise securely dispose of it, or securely isolate it until deletion is reasonably possible.
20. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect personal information through reasonable technical and organisational measures designed to reduce the risk of unauthorised access, disclosure, alteration, loss or destruction.
Depending on the relevant system and risk, safeguards may include:
encryption in transit and cryptographic protection or encryption at rest where appropriate;
authentication and access controls;
role-based and organisation-based permissions;
secure credential and token handling;
tenant isolation and access scoping;
logging, monitoring and audit capabilities;
secure development and change-management practices;
backup, resilience and recovery measures;
vulnerability, dependency and security testing processes;
security incident investigation and response procedures;
contractual confidentiality and data-protection obligations; and
organisational policies and access restrictions.
No electronic transmission over the internet or information-storage technology can be guaranteed to be completely secure. Although we work to protect information, we cannot promise that unauthorised third parties will never defeat security measures.
You are responsible for maintaining the confidentiality of your account credentials and for notifying us promptly if you suspect unauthorised access.
21. HOW DO WE RESPOND TO SECURITY INCIDENTS AND PERSONAL DATA BREACHES?
In Short: We maintain processes designed to identify, investigate, contain, remediate and document suspected security incidents and personal data breaches.
Where a personal data breach occurs and applicable law requires notification, we will notify the appropriate regulator and/or affected individuals in accordance with applicable legal requirements.
Where we act as processor for a customer, we will provide appropriate information and assistance to the customer in accordance with applicable law and contractual obligations.
22. DO WE COLLECT INFORMATION FROM MINORS?
In Short: Our Services are primarily intended for businesses, professionals and persons legally capable of using the relevant Services. We do not knowingly market our general Services to children under 18.
We do not knowingly collect, solicit or sell personal information from children under 18 for general consumer marketing purposes. If we learn that information has been collected from a child in circumstances where it should not have been, we will take reasonable steps to address the issue.
Some organisations may lawfully use business functionality that involves information relating to younger individuals, for example in education, recruitment, dependent, family or workforce-related contexts. In such cases, the organisation is responsible for ensuring it has an appropriate lawful basis, provides required notices and obtains parental or guardian consent where required.
If you become aware of information concerning a child that you believe has been processed improperly, contact us at contact@joiniscanet.co.uk.
23. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your country, province or state of residence, including the United Kingdom, European Economic Area, Switzerland, Canada and certain US states, you may have rights that allow greater access to and control over your personal information. You may also be able to review, change or terminate your account.
In some regions, applicable data-protection laws may give you rights including: (i) the right to request access to and obtain a copy of your personal information; (ii) the right to request rectification of inaccurate or incomplete information; (iii) the right to request erasure in certain circumstances; (iv) the right to restrict processing in certain circumstances; (v) where applicable, the right to data portability; (vi) the right to object to certain processing; (vii) rights relating to direct marketing; and (viii) rights relating to automated decision-making or profiling where applicable.
These rights are not absolute and may be subject to legal conditions, exemptions and limitations. We will consider and act upon valid requests in accordance with applicable data-protection law.
United Kingdom and EEA complaints
If you are located in the United Kingdom and believe we are unlawfully processing your personal information, you have the right to complain to the UK Information Commissioner's Office (ICO). You can find information about making a complaint at ICO – Make a complaint.
If you are located in the EEA, you may complain to the data-protection supervisory authority in your Member State. A list of European supervisory authorities is available through the European Data Protection Board – Our Members.
Switzerland
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC).
Withdrawing your consent
If we rely on your consent to process personal information, whether express or implied as permitted by applicable law, you may withdraw your consent at any time by updating available preferences or contacting us using the details in Section 31.
Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn and, where applicable law permits, will not affect processing conducted on another lawful basis.
Opting out of marketing and promotional communications
You may unsubscribe from marketing and promotional communications at any time by using the unsubscribe mechanism in the communication or by contacting us. You may still receive service-related, transactional, administrative, security or support communications that are necessary for the administration or use of your account.
Account information
If you would like to review or change account information or terminate an account, you may:
log in to available account settings and update your user information; or
contact us using the contact information in Section 31.
When you request account termination, we may deactivate or delete information from active systems subject to applicable retention requirements. We may retain some information where necessary to prevent fraud, troubleshoot problems, assist investigations, enforce legal terms, maintain audit or security records, resolve disputes or comply with legal requirements.
Cookies and similar technologies
Most web browsers accept cookies by default. You can usually configure your browser to remove or reject cookies. Removing or rejecting certain cookies may affect features or Services. Where we provide a cookie preference mechanism, you can use it to manage non-essential categories.
Contacting us about your rights
If you have questions or comments about your privacy rights, email contact@joiniscanet.co.uk.
24. CONTROLS FOR DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL FEATURES
In Short: Browser privacy signals are evolving. We respond to legally required opt-out signals where applicable and otherwise describe our current handling below.
Do-Not-Track
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature or setting. There is not a single universally adopted technical standard for interpreting every DNT signal across all jurisdictions and use cases. Unless applicable law requires otherwise, we do not treat a generic DNT browser signal as an instruction that overrides all cookie, analytics or service functionality.
Global Privacy Control
Where applicable law requires recognition of the Global Privacy Control (“GPC”) or a comparable legally recognised opt-out preference signal, we will seek to honour that signal for the relevant browser or device and processing activity to the extent required by law.
25. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: Residents of certain US states may have additional rights regarding access, correction, deletion, portability, targeted advertising, sale or sharing, sensitive data and qualifying profiling. Rights vary by state and are subject to legal exceptions.
Depending on where you live and whether the relevant law applies to NIFTAD LIMITED's processing, you may have rights under state privacy laws in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states as their laws apply or take effect.
Categories of personal information we may collect
Category | Examples | May we collect? | Typical context |
|---|---|---|---|
A. Identifiers | Name, alias, address, telephone number, email address, account name, online identifier, IP address | Yes | Accounts, CRM, workforce, recruitment, forms, communications |
B. Customer Records information | Contact, education, employment, financial or account information | Yes | Accounts, workforce, recruitment, billing |
C. Protected classifications | Age, date of birth, race/ethnicity, national origin, marital status or other protected data | Yes, where provided and lawful | Workforce, recruitment, customer configuration |
D. Commercial information | Transactions, subscriptions, purchases, invoices and payment history | Yes | Subscriptions, billing and commerce |
E. Biometric information | Biometric identifiers used for identification | Not ordinarily collected unless a specific future feature expressly requires and discloses it | Not a standard ISCANET data category |
F. Internet or network activity | Browser, device, usage, interaction, security and diagnostic information | Yes | Security, operations, analytics |
G. Geolocation data | Approximate IP-based or precise device location | Yes, where relevant and permitted | Attendance, geofencing, mapping |
H. Audio, electronic, visual or sensory information | Images, audio, video, call or interview recordings where enabled | Yes, where a feature is used | Profiles, interviews, meetings or support |
I. Professional or employment information | Job title, work history, qualifications, employment records | Yes | Workforce, recruitment, CRM |
J. Education information | Student, course, qualification or education records | Yes, where relevant | Career, recruitment or customer configuration |
K. Inferences | Summaries, recommendations, classifications, scores or insights derived from other data | Yes, where relevant | AI-assisted or analytics features |
L. Sensitive personal information | Account credentials, financial information, precise geolocation, racial/ethnic data and other sensitive categories | Yes, where necessary and lawful | Authentication, workforce, recruitment, location or billing |
Sources of personal information
The sources of personal information are described in Section 1 and may include you, business customers, authorised users, connected services, service providers and lawful third-party or public sources.
How we use personal information
Our processing purposes are described in Section 2.
Disclosures for business purposes
We may disclose the categories above to service providers, business customers, connected services, professional advisers and other recipients described in Section 4 where necessary for a legitimate business purpose and permitted by law.
Sale, sharing and targeted advertising
ISCANET does not sell Google user data under any circumstances. Google Workspace API data is not used or shared for targeted advertising.
For other personal information, if we use advertising or analytics technologies on public marketing pages and applicable US law treats disclosures associated with cross-context behavioural advertising as a “sale” or “sharing,” eligible residents may have the right to opt out. We do not use customer confidential workspace content, workforce records, candidate records, CRM message content or Google Workspace API data for cross-context behavioural advertising.
Your US state rights
Depending on applicable state law, rights may include:
the right to know whether we process your personal data;
the right to access personal data;
the right to correct inaccuracies;
the right to request deletion;
the right to obtain a portable copy of certain data;
the right to non-discrimination for exercising protected privacy rights;
the right to opt out of qualifying targeted advertising, sale or sharing;
the right to opt out of certain profiling in furtherance of decisions producing legal or similarly significant effects;
the right to limit certain uses or disclosures of sensitive personal information where applicable;
the right to obtain information about categories or specific third parties to whom data has been disclosed where applicable; and
the right to appeal certain privacy-request decisions where state law provides such a right.
How to exercise US state rights
You may exercise applicable rights by emailing contact@joiniscanet.co.uk or using another privacy-request method we make available. Where a cookie preference interface is available, you may use it to manage eligible advertising or tracking choices.
Request verification
We may need to verify your identity or authority before completing a request. We will use information provided for verification only as reasonably necessary to authenticate the request, prevent fraud and comply with law.
Where permitted, an authorised agent may submit a request on your behalf. We may require evidence of authorisation and may separately verify your identity.
Appeals
Where state law provides an appeal right and we decline to take action on your request, you may appeal by emailing contact@joiniscanet.co.uk and identifying the original request. We will provide the outcome of the appeal as required by applicable law, including information about further complaint options where required.
California “Shine the Light”
California Civil Code Section 1798.83, commonly known as the “Shine the Light” law, may permit California residents to request certain information about disclosures of personal information to third parties for their own direct-marketing purposes. Where applicable, you may submit a request using the contact details in Section 31.
26. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights depending on the country or region where you live. We will honour applicable rights to the extent required by law.
Australia
Where Australia's Privacy Act 1988 applies to our processing, we seek to handle personal information consistently with applicable Australian Privacy Principles. You may have rights to request access to or correction of personal information, subject to applicable exceptions.
If you believe your personal information has been mishandled, we encourage you to contact us first. If you remain dissatisfied and Australian law applies, you may be able to complain to the Office of the Australian Information Commissioner (OAIC).
New Zealand
Where New Zealand's Privacy Act 2020 applies, you may have rights to request access to or correction of personal information and other rights provided by the Act.
Information about making a privacy complaint is available from the Office of the Privacy Commissioner of New Zealand.
Canada
Canadian residents may have access, correction, consent-withdrawal and complaint rights under federal or provincial privacy laws, depending on the circumstances. Information about federal privacy concerns is available from the Office of the Privacy Commissioner of Canada.
Switzerland
Swiss residents may have rights under applicable Swiss data-protection law and may contact the Federal Data Protection and Information Commissioner (FDPIC).
Republic of South Africa
Where South Africa's Protection of Personal Information Act (POPIA) applies, you may have rights relating to access, correction, objection and complaints, subject to applicable law.
Information about the South African regulator is available from the Information Regulator (South Africa).
Other jurisdictions
If another jurisdiction grants you privacy rights that apply to our processing, we will consider valid requests in accordance with that law. The existence of a regional section in this Privacy Policy does not mean that every law applies to every interaction with ISCANET.
27. HOW DO WE HANDLE INTERNATIONAL DATA TRANSFERS?
In Short: Some service providers or systems may process information outside the country where you are located. Where transfer restrictions apply, we use recognised safeguards or another lawful transfer mechanism.
NIFTAD LIMITED is established in the United Kingdom, but our service providers and customers may operate internationally. Personal information may therefore be processed in countries other than the country in which it was collected.
Where UK or EEA transfer restrictions apply, we use an appropriate legal mechanism where required, which may include UK adequacy regulations, EU adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses or another legally recognised safeguard.
We may also conduct transfer-risk assessments or implement supplementary safeguards where appropriate to the nature of the transfer and applicable law.
28. MARKETING AND PROMOTIONAL COMMUNICATIONS
In Short: Where permitted by law, we may send information about ISCANET products, services, resources, events and opportunities. You may opt out of marketing communications at any time.
We may use contact information and marketing preferences to send newsletters, product information, event invitations, educational content, offers, surveys or other promotional communications where permitted by law.
Depending on the jurisdiction and communication method, we may rely on consent, legitimate interests or another lawful basis and will comply with applicable electronic-marketing requirements.
You may unsubscribe from marketing emails using the unsubscribe mechanism in the message or by contacting us. Opting out of marketing does not prevent necessary account, transactional, security, support or service communications.
Business customers that use ISCANET to communicate with their own customers or prospects are responsible for ensuring that their communications comply with applicable marketing, privacy and consumer-protection laws.
29. ACCOUNT INFORMATION, ACCOUNT CLOSURE AND DELETION
In Short: You may be able to review or update account information through account settings and may request account closure. Some information may be retained where necessary for legal, security, contractual or legitimate record-keeping reasons.
Where account controls are available, you may update profile or account information directly. You may also contact us to request correction, account closure or deletion.
Upon a valid request to terminate an account, we may deactivate or delete the account and associated information from active systems, subject to applicable rights, customer instructions and retention requirements.
We may retain limited information where necessary to:
comply with legal, tax, accounting or regulatory obligations;
prevent fraud, abuse or unauthorised re-registration;
maintain security and audit records;
troubleshoot or investigate incidents;
resolve disputes or enforce legal terms;
establish, exercise or defend legal claims; or
honour the instructions or legitimate records of a business customer where that customer controls the data.
30. DO WE MAKE UPDATES TO THIS PRIVACY POLICY?
In Short: Yes. We may update this Privacy Policy as necessary to reflect changes in law, our Services, integrations, data practices, security requirements or our organisation.
The updated version will be identified by an updated “Last updated” date at the top of this Privacy Policy. If we make material changes, we may provide additional notice through the Services, by email, through an in-product notification or by another appropriate method where required.
Where a material change affects how Google user data is accessed, used, stored or shared, we will update relevant privacy disclosures and, where required by Google's policies or applicable law, obtain renewed or additional user authorisation before the materially different use occurs.
We encourage you to review this Privacy Policy periodically. We may retain prior versions for governance, audit and record-keeping purposes.
31. HOW CAN YOU CONTACT US ABOUT THIS PRIVACY POLICY?
If you have questions, comments, complaints or privacy requests, you may contact us at:
NIFTAD LIMITED
Doing business as ISCANET, Aurex and Locivo
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ
United Kingdom
Email: contact@joiniscanet.co.uk
Website: https://www.joiniscanet.com
If your request concerns information controlled by an employer, business, recruiter or another organisation using ISCANET, please identify that organisation where possible. We may need to refer the request to or coordinate with the relevant controller.
32. HOW CAN YOU REVIEW, UPDATE, CORRECT OR DELETE THE DATA WE COLLECT FROM YOU?
In Short: Depending on applicable law, you may have the right to request access to personal information, details about how it has been processed, correction of inaccuracies, deletion, restriction, portability, objection or withdrawal of consent.
To submit a request, email contact@joiniscanet.co.uk or use another privacy-request mechanism we make available. Please provide enough information for us to understand the request and identify the relevant account, organisation or record.
We may request additional information to verify your identity or authority before completing a request. We will use verification information only as reasonably necessary to process and secure the request.
Where ISCANET processes information solely on behalf of a business customer, we may direct you to the relevant customer or assist the customer in responding.
We will respond within the period required by applicable law. Rights may be limited where an exemption applies, where we cannot verify the requester, where the request affects the rights of another person, or where retention is required by law.
33. GOOGLE API SERVICES LIMITED USE DISCLOSURE
In Short: This section is a prominent summary of our commitments for information received through Google APIs.
ISCANET's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
ISCANET accesses Google user data only where a user authorises an integration and only to provide or improve appropriate user-facing functionality disclosed in this Privacy Policy.
ISCANET requests only Google permissions necessary for implemented functionality and does not request broader access merely to support speculative future features.
ISCANET does not sell Google user data.
ISCANET does not transfer Google user data to advertising platforms, data brokers or information resellers.
ISCANET does not use Google user data for targeted, personalised, retargeted or interest-based advertising.
ISCANET does not use Google user data to determine creditworthiness or for lending purposes.
ISCANET does not use raw or derived Google Workspace API user data to develop, improve or train generalised or non-personalised AI or machine-learning models.
ISCANET does not transfer Google Workspace API user data to third parties for the purpose of developing, improving or training generalised or non-personalised AI or machine-learning models.
Human access to Google user data is restricted to circumstances permitted under Google's applicable policies, such as user-authorised support, security investigation, legal compliance or another permitted purpose.
Users can disconnect the Google integration and may revoke ISCANET's Google access through their Google Account.
Google-derived information already imported into an organisation's ISCANET records may be retained only in accordance with this Privacy Policy, customer instructions, legal requirements and applicable user rights.
For more information, please review the Google API Services User Data Policy, the Google Workspace API User Data and Developer Policy, and Section 8 of this Privacy Policy.
This Privacy Policy is intended to describe ISCANET's data practices transparently. Where a feature, integration or customer configuration materially changes the categories of personal information processed or the purposes of processing, appropriate additional notice, consent or policy updates will be provided where required.
