Last updated: November 2nd, 2023.
This notice tells you how we look after your personal data when you visit our websites at https://www.extern.com/, or any of our sub-domains (collectively referred to as the “Website”), when you are involved in our externship program (“Program”), where you are considering being involved in a Program, or where you are another type of business contact, such as a supplier or service provider to our business.
This notice sets out what information we collect about you, what we use it for and who we share it with. It also explains your rights and what to do if you have any concerns about your personal data.
We may sometimes need to update this notice, to reflect any changes to the way the Program is provided or to comply with new business practices or legal requirements. You should check this Privacy Notice to see whether any changes have occurred.
We trade under the name “Extern”. The legal entities that may hold and be responsible for the management of your personal data is Extern, Inc. (referred to as “Extern”, “we”, “us” or” our”).
Depending on where you are located, you may be subject to jurisdiction specific laws and regulations. This privacy notice is intended to provide you with the information that we are required to provide you with, wherever you are located. We will look after your personal data carefully wherever you are located, but you may not be able to exercise all of the rights set out below if you are resident in a jurisdiction where such rights do not exist.
Personal data means any information which does (or could be used to) identify a living person.
We have set out the types of personal data that we collect and where we receive it from below.
Type of Personal Data:
Please note that we do not collect any payment card data or similar data relating to your method of payment. You provide this data directly to [our payment process] who processes payments on our behalf. We only receive and process information about the timing and amount of your payment.
Sensitive information (also known as “special category” data) includes information about your health, racial or ethnic origin, political opinions, religious or philosophical beliefs, sex life or sexual orientation.
We collect and process information about you and your interactions with us, for example:
We are required to identify a legal justification (also known as a lawful basis) for collecting and using your personal data. There are six legal justifications which organizations can rely on.
The most relevant of the lawful bases to us are where we use your personal data to:
The table below sets out the lawful basis we rely on when we use your personal data. If we intend to use your personal data for a new reason that is not listed in the table, we will update our privacy notice.
We may anonymize the personal data we collect (so it can no longer identify you) and then combine it with other anonymous information so it becomes aggregated data. Aggregated data helps us identify trends (e.g. what percentage of users responded to a specific survey). Data protection law does not govern the use of aggregated data and the various rights described below do not apply to it.
Where we need to collect your personal data (for example, in order to fulfill a contract we have with you), failure to provide us with your personal data may mean that we are not able to provide you with the services. Where we do not have the information required about you to fulfill an order, we may have to cancel the service ordered.
We may send you marketing messages where you have consented, or where we are otherwise not legally prohibited from doing so.
You can opt out of receiving marketing messages from us at any time. Just let us know at support@extern.com. Opting out of marketing will not affect our processing of your personal data in relation to any contract you have with us and where we required to use your personal data to fulfil that contract or provide you with certain information.
We share (or may share) your personal data with:
If we were asked to provide personal data in response to a court order or legal request (e.g. from the police), we would seek legal advice before disclosing any information and carefully consider the impact on your rights when providing a response.
We are based in the USA and therefore, by providing your personal data to us, you acknowledge that it will be transferred to and processed in the USA.
We may also disclose personal information across borders to employers who take part in our Programs, and to third parties so that they may perform services for us, on our behalf, or in the context of the provision of our services to you.
We may also disclose your personal information across borders to others outside our group of companies where:
We have implemented security measures to prevent your personal data from being accidentally or illegally lost, used or accessed by those who do not have permission. These measures include:
If there is an incident which has affected your personal data and we are the controller, we will notify the regulator and keep you informed (where required under data protection law). Where we act as the processor for the affected personal data, we notify the controller and support them with investigating and responding to the incident.
If you notice any unusual activity on the Website, please contact us at support@extern.com
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for.
To decide how long to keep personal data (also known as its retention period), we consider the volume, nature, and sensitivity of the personal data, the potential risk of harm to you if an incident were to happen, whether we require the personal data to achieve the purposes we have identified or whether we can achieve those purposes through other means (e.g. by using aggregated data instead), and any applicable legal requirements (e.g. minimum accounting records for HM Revenue & Customs).
We may keep Identity Data, Contact Data, information about payments received from you and certain other data (specifically, any exchanges between us by email or any other means) for up to seven years after the end of our contractual relationship with you.
If you browse our website, we keep personal data collected through our analytics tools for only as long as necessary to fulfill the purposes we collected it for.
If you have registered an interest in our Program or services, or you have subscribed to our mailing list, we keep your details until you ask us to stop contacting you.
You have specific legal rights in relation to your personal data, which may vary by jurisdiction. The following list sets out your legal rights if you are resident in the European Economic Area or in the UK. We will do our best to comply with the below, even where we are not legally required to do so. If you wish to exercise any of the rights listed below, please contact support@extern.com
If you are resident in the United Kingdom you can complain to the UK Information Commissioner’s Office: https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/
If you are resident in Canada you can complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/
If you are resident in the European Economic Area you can complain to the Data Protection Commission in Ireland: https://forms.dataprotection.ie/contact.
We can decide not to take any action in relation to a request where we have been unable to confirm your identity (this is one of our security processes to make sure we keep information safe) or if we feel the request is manifestly unfounded or excessive. We may charge a fee where we decide to proceed with a request that we believe is unfounded or excessive. If this happens, we will always inform you in writing.
COOKIE POLICY
Cookies will typically be placed on your computer or internet-enabled device whenever you visit us online. This allows the site to remember your computer or device and serve a number of purposes.
On our Website, a notification banner will appear allowing you to manage your consent to collect cookies (cookie banner).
Session vs. persistent cookies: cookies have a limited lifespan. Cookies which only last a short time or end when you close your browser are called session cookies. Cookies which remain on your device for longer are called persistent cookies (these are the type of cookies allow websites to remember your details when you log back onto them).
First party vs third party cookies: cookies placed on your device by the website owner are called first party cookies. When the website owner uses other businesses’ technology to help them manage and monitor their website, the cookies added by the other business are called third party cookies.
Below is a summary of the categories of cookies collected on our websites:
We use cookies to:
We can only use cookies with your permission (you will be prompted by a message when you first visit our Website, also known as a cookie banner, where you can choose to accept or decline our cookies).
You can update your settings on our Website.
You can choose to decline cookies but if you turn off necessary cookies, some pages and functions on our Website may not work properly. You can also manage cookies through your browser settings or device settings (your user manual should contain additional information).
You can also delete cookies directly with the relevant third parties (for example, you can disable Google Analytics on their website).
If you have any questions about our cookies, or how we otherwise use your personal data, please visit our Privacy Policy for further details.