Privacy Policy
This Privacy Policy explains how Tomattos Technologies Limited, its brands, subsidiaries, and Affiliates (“Tomattos”, “we” or “us”) collects, uses, shares and protects personal information.
Scope of the Policy
Tomattos respects the privacy of every individual who visits www.tomattos.com (“Website”) and/or purchases its Services. This Privacy Policy is our commitment to transparency in communicating how we collects, uses, and discloses the information that is collected from you, the visitor of its website and/or customer as well as the choices you have with respect to the information.
BY USING OUR SERVICES OR VISITING OUR SITE, YOU AGREE TO BE BOUND BY THIS PRIVACY POLICY. IF YOU DO NOT AGREE WITH ANY OF THE TERMS OF THIS POLICY, PLEASE DO NOT USE OUR WEBSITE OR SERVICES OR OTHERWISE PROVIDE US WITH YOUR INFORMATION.
This Privacy Policy applies to how we collect, use, and disclose information from the following individuals:
- Customers – individuals who register, on their own or on behalf of an entity, to use Tomattos Services with the creation or administration of a Tomattos account.
- Event/Marketing Participants – individuals who provide their information to Tomattos when they register for Tomattos webinars, subscribe to marketing material, participate in surveys or contests, or attend other Tomattos events.
- Website Visitors – individuals who visit Tomattos’s Website and opt to provide contact information including an email address to receive communications from Tomattos. For purposes of this Privacy Policy, a Website Visitor does not include an individual who visits a website hosted by Tomattos but owned and operated by a Tomattos customer.
This Privacy Policy does not apply to our Customers’ website hosted by Tomattos. Our Customers are responsible for the information they or their end users store in our hosting environment as well as compliance with applicable laws, regulations, and Tomattos’s terms related to the collection and storage or personal information.
Information we Collect
Customers
Tomattos asks for your account information which includes your name, email address, physical address, phone number, credit card information, and website domain. By voluntarily providing Tomattos with your account information, you represent that you own and consent to our use of such personal data.
Event/Marketing Participants
Tomattos may ask for your name, email address, physical address, and phone number. Participation in events, surveys, contents, or subscribing to marketing material is voluntary and you may choose whether or not to participate and therefore disclose this personal data.
Website Visitors
At your option, Tomattos asks and may collect your name, email address, physical address, and phone number. In addition, we also collect information such as web server logs, internet protocol (IP) addresses, browser type, or other statistical information as part of aggregated data. We use Google Analytics to help us gather statistical information about the visitors to our Website and how they use the Website on an anonymous, aggregate basis. However, we will not associate this data with your personally identifiable data unless required to do so to cooperate with law enforcement activity or other governmental request or to comply with law. We may use this information to gain a better understanding of the users of our Website, to improve our Website, and to improve our Services. Depending on the type of browser and device that you use, you may have the ability to control the type of information that Google Analytics use. To understand how Google Analytics collects and processes data, please visit www.google.com/policies/privacy/partners/.
Tomattos uses cookies, beacons, tags, and other tracking technologies to gather demographic information about you, identify your visits to our Website, other interactions with our Website, and personalize your search experience on our Website. We gather information such as internet protocol (IP) addresses, internet service provider (ISP), operating system, browser type, date/time stamp, and store it in log files. See our Cookie Policy, below, for more information.
How we Use Your Information
Tomattos uses the information it collects about you in the following ways:
- To respond to any requests from you regarding sales and support.
- To contact you regarding any agreements or accepted terms that you may have with Tomattos for the Services.
- To provide you with marketing emails, special offers, advertising campaigns, or newsletters.
- To provide you with information logs associated with the use of Tomattos’s Services.
- To contact you regarding functionality changes to our Services or Website.
- To develop new features and functionality to our Services and Website.
- To collect payment and bill for our Services.
- To help personalize searches.
- To diagnose problems.
- To find and prevent fraud.
- To register your domain and
- IP address through APNIC & ARIN.
- To carry out other purposes as disclosed to you through the Website, or found in terms or an agreement between you and Tomattos.
- Process for other purposes for which we obtain your consent.
How we Share Your Information
Tomattos shares the information it collects about you in the following ways:
- Third Party Providers – Tomattos may share your information with third party providers that provide services on our behalf. These companies may assist with marketing support, processing credit card payments, providing sales leads, and customer support. Third party providers may only process personal information pursuant to Tomattos’s instructions, and in compliance with Privacy Policy and other applicable regulations (e.g. EU-US Privacy Shield framework).
- Advertising – Based on cookies and other tracking devices, we may work with advertising companies to display ads that may be of interest to you.
- Business Transactions – To provide information to a third party in the event of any disposition of all or any portion of our business (e.g. reorganization, sale, assignment, bankruptcy).
- Aggregated or De-identified Data – We may aggregated or otherwise de-identified your personal information. We own such aggregate or de-identified information and may use and share this information with third parties.
- As Required by Law or Similar Investigations – To comply with legal obligations (e.g. subpoena) or investigate potential legal violations. Tomattos may be required to share personal data in response to lawful requests from public authorities including to meet national security and/or law enforcement requirements.
- Safety – We may disclose your information to protect and defend the safety of Tomattos in connection with investigating and preventing fraud or security issues.
- Consent – Tomattos may share your information with your consent.
Cookie Policy
What are Cookies? Cookies are small data files that are placed on your computer or mobile device when you visit a website. Cookies set by the website are called “first party cookies.” Cookies set by parties other than the website are called “third party cookies.” Third party cookies enable third party features or functionality, such as advertising or website analytics, to be provided on or through the website. The parties that set these third party cookies can recognize your computer or device both when it visits the website in question and also when it visits certain other websites and/or mobile apps.
What Cookies and Other Tracking Technologies does Tomattos Use? We may use several different kinds of cookies on this Website, including strictly necessary cookies, which are cookies that are necessary for the Website to function and cannot be switched off in our systems; and performance cookies, which allow us to count visits and traffic sources so we can measure and improve the performance of our Website.
Cookies are not the only way to track visitors to a website. We may use similar technologies from time to time, like web beacons (sometimes called “tracking pixels” or “clear gifs”). These are tiny graphics files that contain a unique identifier that enable us to recognize when someone has visited our Websites. These technologies often depend on cookies to function properly, and so disabling cookies may impair their functioning.
Third-Party Cookies. In addition to our own cookies, we collaborate with various third-party service providers who also use cookies to help us optimize our website and understand more about the visitors to our website. For example, we use Google Analytics to provide us with demographic information about our visitors and to help us analyze how people use our website. Our third-party service providers include: AffiliateWP, Bing, CloudFlare, Facebook, Google Analytics, Google TagManager, HotJar, Hubspot, LinkedIn, Perfect Audience, and Salesforce. To learn more about how these providers use cookies, please click the links above or visit their respective websites to view their privacy policies.
How Can You Disable Cookies and Other Tracking Technology? Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org and www.youronlinechoices.com. Some Internet browsers also may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
Your Choice
You may unsubscribe from receiving promotional or marketing emails from Tomattos at any time by using the “unsubscribe” link in the email received, or by emailing us at help@tomattos.com. As outlined in the Section, Information We Collect, you can also control your cookie settings.
With respect to your account information, you may update, correct or delete information that you provided to us by logging into your Tomattos account or contacting us at help@tomattos.com.
You are not required to provide all personal information identified in this Policy to use our Website or receive or Services, but certain functionality will not be available if you do not provide personal information. For example, if you do not provide personal information, we may not be able to respond to your request, perform a transaction with you, or provide you with marketing that we believe you would find valuable.
Data Retention & Security
When Tomattos no longer has a legitimate business need (e.g. termination of a Customer agreement) to process your personal information, we will either delete or anonymize it.
Tomattos takes all reasonable steps to protect information received from you from loss, misuse or unauthorized access, disclosure, alteration, and/or destruction. We maintain technical, physical, and administrative safeguards to secure your information, and we use industry standard encryption for your data that is transferred over the internet. Despite its use of encryption, Tomattos cannot guarantee any method of transmission of information over the internet is 100% secure. If you have any questions about the security of your personal information, please contact us at help@tomattos.com.
International Transfers
Tomattos is a Bangladesh & United Kingdom company and stores your information in its data centers in the Bangladesh or, in limited cases, in the United Kingdom. Tomattos may transfer your personal information to countries other than the country in which you live. Privacy laws in the locations where we handle your personal information may not be as protective as the privacy laws in your home country.
About Children
Third Party Sites & Services
The Website may contain links to other websites and services operated by third parties. These links are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third party websites, applications or services, and we are not responsible for their actions. Other websites and services follow different rules regarding their collection, use and sharing of your personal information. We encourage you to read their privacy policies to learn more.
Notice to European Users
The following applies to individuals in the European Economic Area (EEA) and United Kingdom (UK):
Controller
Tomattos Technologies Limited is the controller of your personal information covered by this Privacy Policy for purposes of EEA and UK data protection legislation.
Legal bases for processing
We are required to inform you of the legal bases of our processing of your personal information, which are described in the table below. If you have questions about the legal basis of how we process your personal information, contact us using one of the methods detailed at the end of this Privacy Policy.
- To provide the Website and our Services and communicate with you. You are subject to a contract with us and we need to use your personal information to provide services you have requested or take steps that you request prior to providing services.
- To send you marketing communications. For compliance, fraud prevention, and safety. These processing activities constitute our legitimate interests. We consider and balance the potential impact on your rights before we process your personal information for our legitimate interests. We do not use your personal information for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
- For compliance with law. Processing is necessary to comply with our legal obligations.
- With your consent. If we expressly ask for your consent prior to processing your information, our processing is based on your consent. Where we rely on your consent you have the right to withdraw it anytime in the manner indicated on the Website.
- To share your personal information as described in this Policy. This sharing constitutes our legitimate interests, and in some cases may be necessary to comply with our legal obligations.
Retention
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your Rights
EEA and UK data protection laws give you certain rights regarding your personal information. You may ask us to take the following actions in relation to your personal information that we hold:
- Access. Provide you with information about our processing of your personal information and give you access to your personal information.
- Correct. Update or correct inaccuracies in your personal information.
- Delete. Delete your personal information.
- Transfer. Transfer a machine-readable copy of your personal information to you or a third party of your choice .
- Restrict. Restrict the processing of your personal information.
- Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.
You may submit these requests by contacting us as detailed at the end of this Privacy Policy. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal information or response to your requests regarding your personal information, you may contact us or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.
Cross-Border Data Transfers
Any information you provide to us through the use of the Website may be stored, processed, transferred among, and accessed from the Bangladesh and other countries which may not guarantee the same level of protection of personal information as the one in which you reside. However, we will handle your personal information in accordance with this Policy regardless of where your personal information is kept. Regarding transfers from the EEA and UK to the Bangladesh, we rely on the derogations for transfers which are necessary to perform the transaction with you. Where required by law, you may request a copy of the suitable mechanisms we have in place by contacting us as detailed below. If you reside in other non-BD jurisdictions outside the EEA and UK, your use of the Website or provision of any personal information constitutes your consent for the transfer of such data to the Bangladesh for the purposes identified above. If you have questions about cross-border transfers, please contact us as detailed below.
Privacy Shield Certification and Complaint Resolution
Tomattos complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, please visit https://www.privacyshield.gov/. Tomattos’s participation in Privacy Shield is subject to investigation and enforcement by the law. Tomattos has responsibility for the processing of personal information it receives under the Privacy Shield and subsequently transfers to a third party acting as an agent on its behalf. Tomattos will only engage in such transfers as further detailed in this Privacy Policy. Tomattos remains liable under the Privacy Shield if a third party agent processes personal information covered by this Privacy Policy in a manner inconsistent with the Privacy Shield Principles, except where Tomattos is not responsible for the event giving rise to the damage.
In compliance with the Privacy Shield Principles, Tomattos commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Tomattos at: help@tomattos.com. Tomattos has further committed to refer unresolved Privacy Shield complaints to JAMS, an alternative dispute resolution provider (the “ADR Provider”) located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/ for more information or to file a complaint. The services of the ADR Provider are provided at no cost to you. Under certain circumstances, you may be able to invoke binding arbitration to resolve disputes regarding our compliance with Privacy Shield. See https://www.privacyshield.gov/article?id=ANNEX-I-introduction for further information.
Notice to California Residents
The following section applies to California residents.
Shine the Light
Under California’s “Shine the Light” law, you have the right to ask us once a year if we have shared your personal information with third parties for direct marketing purposes. To make a request please contact us as instructed below and specify you are making a Shine the Light request.
California Consumer Privacy Act (“CCPA”)
The CCPA creates consumer privacy rights and requires businesses to make disclosures about their privacy policies and practices. Pursuant to the CCPA, both our privacy practices and your privacy rights are discussed in detail in the following information.
Personal Information We Collect
We collect your personal information when you interact with our Website or otherwise communicate with us. For the purposes of this Privacy Notice, “personal information” means information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device. We have collected the following categories of personal information covered by the CCPA from consumers within the past 12 months, and have used it for the following business purposes:
- Identifiers, including real name, alias, mailing address, email address, account name, telephone numbers, and unique personal identifiers such as online identifiers and IP address- To provide our Site and Services and to market our Services to you- Directly from you when you contact us, order Services, set up an account, or respond to promotions as well as through our authorized resellers if you purchase Services through them.
- Geolocation data- To provide our Services and assist in marketing and identify Website traffic patterns- Passively when you visit our Website.
- Financial information, including credit card number or debit card number- To fulfill your orders for our Services- Directly from you or from our authorized resellers when you pay for Services.
- Commercial information, including Services purchased- To fulfill your orders for our Services- Directly from you or from our authorized resellers when you order our Services.
- Internet or other electronic network activity information, including browsing history, search history, and information regarding an individual’s interaction with an internet site, application, or advertisement- To provide you more relevant content, track original Website visits, and optimize your Website experience as well as to ensure our systems are properly functioning- Passively when you visit our Website.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible business purposes without providing you notice.
Sharing Your Information
We do not sell your personal information, but may disclose it to third parties for a business purpose. Specifically, in the past 12 months we have disclosed unique personal identifiers such as online identifiers and IP address and Internet or other electronic network activity information to our internet service providers, operating systems and platforms, and marketing intelligence service providers.
Your Rights
The CCPA gives you certain rights regarding your personal information:
- Right to Know. You may request no more than twice in a 12-month period that we provide you with copies of specific personal information we have collected, sold, or disclosed about you. However, under California law, we cannot provide you with certain sensitive information, despite your request (for example, we will not send you copies of your social security number even if it is something we collected).
- Right to Delete. You may request that we delete certain personal information we have collected about you, with certain exceptions.
Exercising Your Rights
To exercise your rights above, please submit a request to us here, by emailing us at help@tomattos.com. Please describe your request with sufficient detail so we can properly respond to your request. As part of your request, please specify which right you are exercising and be prepared to provide the following information: name, email address, and the type of request you wish to make. We may ask for additional information to verify your identity. The information you provide in your request and any follow up information we ask for from you will be used solely to verify your request. After receiving your request, we may need to contact you for further information and will notify you if your request has been granted or declined, or if an exception applies to your request. Only you or an individual designated as your authorized agent to act on your behalf may make a request related to your personal information. We may not discriminate against you if you choose to exercise your rights.
Responding to Your Rights Request
We will try to respond to your request within 45 days. If we need more time, we will contact you with the reason we need more time and the extension period. We will deliver our written response by mail or electronically, at your option. In response to your request to know, we will only disclose the information we have collected in the 12 months prior to our receipt of your request. Our response will also explain the reasons we cannot comply with any request, if applicable. We will not charge a fee to process or respond to your request unless your request is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate prior to completing your request.
Changes to Privacy Policy
Tomattos reserves the right to modify this Privacy Policy at any time, however, should we change the Privacy Policy in a material way, a notice will be posted on our website along with the updated Privacy Policy. If you disagree with the changes, you may terminate your Services.
Effective date of current Privacy Policy: 01 January, 2022
Last change date: 01 January, 2022
Contact Tomattos
If you have any questions or concerns over this Privacy Policy, or wish to exercise any of your statutory rights, please contact us at-
H-12, 11th Floor, Razzak Plaza
Moghbazar, Ramna
Dhaka-1217, Bangladesh
help@tomattos.com
8809606444111, 8801621222111