Porch Group Media’s US- EU Privacy Shield Principles

Porch Group Media complies with the EU-U.S. Privacy Shield Framework (Privacy Shield) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and the United Kingdom to the United States in reliance on Privacy Shield. Porch Group Media has certified to the Department of Commerce that it adheres to the Privacy Shield Principles with respect to such information. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.

To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.

The Privacy Principles are:

  • Notice
  • Choice
  • Accountability for Onward Transfer
  • Security
  • Data Integrity and Purpose Limitation
  • Access
  • Recourse, Enforcement and Liability

Processor on Behalf of Clients

Porch Group Media provides customized computer services designed to help companies manage their customer information more effectively, increase profitability of their marketing and reduce the operational costs of processing customer information. In this capacity, Porch Group Media does not own or control any of the information it processes on behalf of Porch Group Media’s clients. All such information is owned and controlled by Porch Group Media’s clients. In this capacity Porch Group Media receives information transferred from the EU and the UK to the United States merely as a processor on behalf of our clients. Porch Group Media does not make any of its clients’ data available to any third parties unless it is at the express request of our clients.

When Porch Group Media acts as a processor on behalf of its clients, the policies outlined below apply to all data processing operations concerning personal information that has been transferred from the EU and the UK to the United States.

Processing Contracts
Before starting any processing on behalf of Porch Group Media’s clients, Porch Group Media will enter into a processing contract with the EU and the UK data controller responsible for the personal information pursuant to the applicable EU Member State Data Protection law and the UK Data Protection Law. The processing contract ensures that the EU data controller and the UK data controller will be in compliance with the Member State and UK Data Protection law.

Any data processed by Porch Group Media will not be further disclosed to third parties except where permitted or required by the processing contract, EU Privacy Shield or the applicable Member State or UK Data Protection law.

Any information Porch Group Media’s client (acting as the EU or UK controller) identifies as sensitive will be treated accordingly.

The processing contract will also specify that the processing will be carried out with appropriate data security measures. Porch Group Media has in place measures to protect personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction.

Notice
Porch Group Media adheres to the Principles of the Privacy Shield, and is committed to subject all personal data received from the EU and the UK to the Privacy Shield Principles.

To find out more about participating companies, here is a link to the list maintained by the USDOC: https://www.privacyshield.gov/list.

Prior to the transfer of any non-public personal information from the EU and the UK to the United States, Porch Group Media requires contractual confirmation from the EU controller and the UK controller from whom Porch Group Media acquired the information that the personal data has been provided to Porch Group Media in accordance with the applicable EU Member State and UK Data Protection law, thereby ensuring the data subjects have been provided with proper notice regarding how their personal data will be used. In addition, when personal data is collected directly from data subjects, Porch Group Media provides the data subject with notice regarding the manner and circumstances in which the personal data will be used and transferred to third parties.

Choice
Prior to the transfer of any non-public personal information from the EU and the UK to the United States, Porch Group Media requires contractual confirmation from the EU and UK controller from whom Porch Group Media acquired the information that the personal data has been collected in accordance with applicable EU Member State Data Protection and UK law, thereby ensuring the data subjects have been provided with the proper choice regarding how their personal data may be used.

Accountability for Onward Transfer
Porch Group Media complies with the notice and choice principles as described above for all data disclosed or transferred to a third party. Data transfer would only occur at the express request and direction of the client. Examples of a third party would be a printer to prepare catalogs or mailings on the client’s behalf or a market research firm to conduct client managed research.

Porch Group Media requires that any third party:

  • Enter into a written agreement with Porch Group Media requiring them to provide the same level of protection as Porch Group Media provides including that the data is being transferred for limited and specified purposes; and that the third party adhere to the Privacy Shield Principles. In cases of onward transfer to third parties, Porch Group Media is generally liable for the acts of the third party that are in violation of the Privacy Shield Principles.

Security
Porch Group Media has in place an information security policy to protect personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction. Porch Group Media’s security officer is responsible for conducting investigations into any alleged computer or network breaches, incidents or problems and ensuring the proper disciplinary action is taken against those who violate Porch Group Media’s information security policy. Any security compromises or potential security compromises and any inquiries concerning security should be reported to the Porch Group Media consumer advocate. Contact information is provided below under Access.

Data Integrity and Purpose Limitation
Porch Group Media takes reasonable steps to ensure the information transferred from the EU and the UK to the United States is reliable, accurate, complete and current. The steps Porch Group Media takes to assure data integrity are based on the purposes for which the personal information is used.

Access
An individual may request access to the information Porch Group Media maintains in its information products. The individual has the right to learn whether or not data about him or her is found in Porch Group Media’s information products and to correct, amend or delete that information when it is inaccurate. This right applies only to personal information about the individual making the request and is subject to other limitations as defined by law.

Individuals can request access by emailing or writing:

Privacy Advocate
Porch Group Media
2319 Oak Myrtle Lane
Wesley Chapel, FL 33544
Email: privacyshield@porchgroupmedia.com

Porch Group Media’s consumer advocate will explain the process for making an access request. In order to confirm the identity of the individual and have the necessary information to retrieve the individual’s information, Porch Group Media provides a request form which the individual fills out, signs and postal mails to Porch Group Media. Porch Group Media agrees to process all reasonable requests for access within a reasonable time period, but reserves the right to deny access or limit access in cases where the burden or cost of providing access would be disproportionate to the risks to the individual’s privacy or in the case of an unwarranted or fraudulent request.

Recourse, Enforcement and Liability
Individuals who wish to file a complaint or who take issue with Porch Group Media’s EU U.S. Privacy Shield Principles should contact Porch Group Media’s consumer advocate. Porch Group Media’s consumer advocate will explain the process to be followed when filing a complaint. Filing a complaint in English will speed-up the request process.
Porch Group Media has registered under the DMA division of the ANA Privacy Shield complaint resolution process.

If consumers can’t resolve a complaint after contacting Porch Group Media’s consumer advocate, they may file a written complaint with the DMA division of the ANA Privacy Shield:

ANA Privacy Shield
225 Reinekers Lane, Suite 325
Alexandria, VA 22314

To file a complaint/inquiry:

Porch Group Media is also subject to the jurisdiction of the U.S. Federal Trade Commission. Consumers unable to resolve a complaint through the DMA Privacy Shield Complaint process may contact the Federal Trade Commission:

Federal Trade Commission
Attn: Consumer Response Center
600 Pennsylvania Avenue NW
Washington, DC 20580

consumerline@ftc.gov
www.ftc.gov

In the event a dispute cannot be resolved, Porch Group Media is open to the possibility of Binding Arbitration.

Porch Group Media is required to disclose personal information in response to lawful requests by public authorities, including meeting national security or law enforcement requirements.