Effective Date: February 1, 2019
Privacy Shield Principles:
- Accountability for Onward Transfer
- Data Integrity and Purpose Limitation
- Recourse, Enforcement, Liability
Information Collected By The Looker Site
When you use the Site, create an account to use the Site (or someone, such as your organization’s administrator, creates an account on your behalf), use our Platform or otherwise communicate with us (e.g. via email), Personal Information will be collected by the Site or Platform. The Personal Information collected is as follows:
- Business address
- Business telephone number
- Email address
- IP-address and other online identifiers
- Location Data
- Any customer testimonial you have given us consent to share on the Site (please see below “ACCESSING, CORRECTING AND DELETING YOUR INFORMATION” for information about how to update or delete your testimonial).
- Information you provide to the Site’s Interactive Areas. Note that any information that you post in an Interactive Area might be read, collected, and used by others who access it. You may take down any information you have added to the Interactive Areas at any time. (Please also see below “ACCESSING, CORRECTING AND DELETING YOUR INFORMATION” for information about how to delete information we hold about you).
- To request removal of your personal information from an Interactive Area, please contact us at email@example.com.
- Information you provide via fillable forms or text boxes, such as training, webinars or event registration.
- Information regarding the device you are using, comprising the hardware model, operating system and version, unique device identifiers, network information, IP address, and/or Platform information when interacting with the Site or Platform.
- Information about all of your interactions with the Site or Platform (“Usage Data”) and how the Site or Platform is performing (“Analytics Data”).
- Usage Data includes information regarding any interaction you have with the Site or Platform, such as which functionalities are used and the frequency of use (e.g., pages visited, actions taken, queries run, fields added, user accounts, account roles, and connected database types).
- License checks including the number of users, roles, and database connections.
- Analytics Data includes information gathered via our licensing management service, which sends data to Looker concerning the performance of the Site or Platform.
- If a Looker customer uses the software to analyze personal data in their databases, Looker will process the categories of personal data analyzed, which may include special categories of data as determined by the customer, including without limitation factors specific to the individual’s physical, physiological, genetic, mental, economic, cultural or social identity.
- Information gathered through cookies, pixel tags, logs, or other similar technologies. See “COOKIES AND RELATED TECHNOLOGIES” section below.
Additional Information Collected By The Looker Platform
When you use the Platform, create an account to use the Platform (or someone, such as your organization’s administrator, creates an account on your behalf), additional information about your use of the Platform is collected:
- Unique identifier(s) we assign to users as part of monitoring user experience.
- Information contained in your organization’s Looker database used with the Platform, to which we have access when we automatically back it up and encrypt it for you.
As well as the processes described above, you may also choose: not to provide certain Personal Information when requested (e.g. via forms available on the Site); and/or to opt-out of the collection of certain Personal Information by us, by emailing us at firstname.lastname@example.org.
See also “COOKIES AND RELATED TECHNOLOGIES” section below for information about how information generated using these technologies is used.
Looker also may collect information that does not identify or locate you personally, meaning business information such as SIC code, industry, number of employees, or sales funnel status. Looker reserves the right to maintain, disclose, or otherwise use such information without limitation including aggregated with other information to improve the Site, Platform and services offered by Looker.
Data Integrity and Purpose Limitation
This section describes the ways we use and store Personal Information.
Information Stored in Looker
Looker uses a read-only connection to access the minimum amount of data needed to answer your questions and only returns the relevant result set. Alternatively, customers can choose to give Looker write-access to their database to take advantage of PDTs (persistent derived tables). This feature lets you define summary tables that Looker will write on your behalf into your database, at a cadence of your choosing.
Accordingly, Looker holds two types of Personal Information, in two ways: information about Looker users, and the customer data necessary to answer Looker users’ queries.
Information about Looker users. This information about Looker users includes end-user login/registration information for Looker users as well as metadata about their usage. Metadata is used to facilitate product improvements, customer support and license auditing. Login information is controlled by customers directly as it is entered on their Looker instance and they can delete their users’ (i.e. their employees’) information at any time. We retain basic user contact information to send product updates, relevant marketing, training and events based on the users’ communication preferences.
Customer data necessary to answer users’ queries. Once Looker is connected to a customer database, the Looker cache retains data from the customer’s database that is fetched in response to its users’ queries. This data is encrypted and stored by Looker for a maximum of 30 days or 2GB of data—whichever occurs first. If you prefer, you can also take additional steps to reduce the amount of time that query results are held in cache.
How Information May Be Used By The Looker Site
Looker may use the Personal Information collected by the Site or Platform as follows:
- To respond to your requests for information about our products, services, training and events.
- To provide product enablement and licensing, customer service and support.
- To administer your account if you have registered on the Site or Platform, including billing and payment.
- To enable your access and use of the Site or Platform, and to enable you to communicate, collaborate, and share information with those you designate.
- To send you technical notices, updates, security alerts, and support and administrative messages.
- To inform you about our products and services.
- To apply information security policies and controls on the Site, including overall Site integrity, identity management and account authentication.
- For legal compliance, such as to enforce our legal rights, to comply in good faith with applicable laws, and to protect users of the Site or Platform.
- For other general business management and operations purposes, such as to provide, operate, maintain, make modifications to protect and improve the Site or Platform.
- To send marketing, advertising, training or event materials to which you’ve agreed, requested or subscribed.
- For research and development to improve the Looker product, Platform and services.
- For other purposes about which we notify you and, where relevant or required, give you choice about the new purpose.
Additional Information Used By The Looker Platform
Looker may use your Personal Information collected by the Platform as follows, depending upon the nature of your Looker deployment:
- To administer your Platform user account.
- To enable your access and use of the Platform, and to enable you to communicate, collaborate, and share information with those you designate.
- To enable your access and use of Platform Integration and Application services.
- To monitor your user experience on the Platform.
- To enable Looker to proactively help customers maintain the performance and functionality of deployments of the Platform.
- To enable Looker to verify your license to use the Platform.
Choice, Control and Access
This section describes the ways you can exercise your rights to access and control your Personal Information.
Email Communications Preferences
Looker respects your email communications and marketing preferences. If you prefer not to receive product release notes communications or promotional email messages (such as marketing, events, training) from Looker, you can unsubscribe from Looker’s email marketing list by following the unsubscribe link located at the bottom of each promotional email, going to our subscription center, or contacting us at email@example.com with “UNSUBSCRIBE” in the subject line. Note: Please allow five (5) business days to be removed from all email communications.
Accessing, Correcting And Deleting Your Personal Information
Ensuring that Personal Information we hold about you is accurate and complete is important to us. If you would like to request access to, correct or delete the Personal Information, please send us an email at firstname.lastname@example.org. We will verify these requests and respond to you in accordance with our legal obligations, which typically means forwarding your request to the licensed administrator (customer) of your Looker account for review.
To request removal of your personal information from an Interactive Area, please contact us at email@example.com.
Looker customers create and remain in control of your data and data about your users and user activities and reports. When you remove users from your Looker-connected database instance, their data will be removed from Looker’s databases within 30 days and within 30 days they will no longer remain in Looker's cache. If you wish to delete a Looker user’s account data, we have a process to permanently anonymize the data by data engineering, either self-serve or on request. If you would like Looker to delete your customer data or Looker user account detail, please send an email to firstname.lastname@example.org.
Accountability and Onward Transfer
This section describes our accountability with regard to the onward transfer of your Personal Information to third party service providers (suppliers), partners and across country borders.
Except as listed below, Looker will not share Personal Information with third parties unless you have consented to the disclosure.
Depending on how Looker is deployed by the customer, Looker may share Personal Information with third-party service providers that need your information to provide the following operational or other support services to Looker, the Site or Platform:
- Data management.
- Database hosting.
- Integration services.
- Professional services.
- Information security, integrity, and identity and authentication services.
- Email communications (e.g. operational, marketing, events, training).
- Financial operations (e.g. licensing, billing).
- Payments and payment card processing.
- Shipping services.
- Communication services (e.g enabling collaboration, conferencing or messaging).
- Support services (e.g. providing customer service and support).
- Cloud services (e.g. functioning of the Site or Platform).
To ensure the confidentiality and security of your Personal Information, we ask service providers that handle Personal Information to sign a Data Protection Addendum. These service providers are restricted by contract from using your Personal Information in any way other than to provide services for Looker. Looker is accountable and has liability in cases of onward transfers to third party service providers.
Looker does not share the information contained in your organization’s Looker database and used with the Looker Platform with the above third-parties.
If you integrate a 3rd party service through the Looker Action, Integration or Application Hub, or through Professional Services, you are choosing to share the information contained in your organization’s Looker database with that 3rd party service.
Looker may also provide your Personal Information to a third party if:
- We believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process, or lawful government request, including in connection with national security or law enforcement requirements. This may include disclosures: to respond to subpoenas or court orders; to establish or exercise our legal rights or defend against legal claims; or to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Service Agreement, or as otherwise required by law. In each case, we will make reasonable efforts to verify the validity of the request before disclosing your personal information.
- To enforce our agreements, policies and Terms of Service.
- To protect the security and integrity of the Site.
- To respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing serious bodily injury or death of any person.
Looker may also share your Personal Information with our subsidiaries, affiliates, and partners, to facilitate our global operations and in accordance with applicable laws, our Service Agreement, Terms of Service or Contracts. We may also provide your Personal Information to a third party in connection with a merger or acquisition of Looker, either in part or in whole, or the assignment or other transfer of the Site. In such event, such third party will either:
- involving your Personal Information collected before such merger, acquisition, assignment or other transfer, inform you and get your express affirmative consent to opt in to the new practices; and/or
- involving your Personal Information to be collected after such merger, acquisition, assignment or other transfer, inform you in some prominent manner enabling you to make a choice about whether to agree to the new practices.
- You may choose to opt-out of allowing your Personal Information to be shared with certain third-parties. To do so, please contact email@example.com with your request. We will do our best to respond in a timely manner and grant your request to the extent permitted by law.
International Transfer And Storage Of Information Collected
We primarily store information collected from you within the European Economic Area, the United States and in other countries and territories. By default, Looker hosts in the U.S. region, but at the customer’s request, we can host in various other regions, including within the EU, Asia and Latin America, which varies based on each unique customer circumstances. To facilitate our global operations, we may transfer and access such personal information from around the world, including from other countries in which Looker has operations. For customers who need to be hosted inside the EU, we host in the Dublin, Ireland region. Customers can also host their own Looker instance on their own servers. We use applicable, approved information transfer mechanisms where required, such as EU Standard Contractual Clauses (SCCs), or the EU - U.S. Privacy Shield.
Looker has a dedicated information security function responsible for security and data compliance across the organization.
Looker protects the Personal Information it collects via the Site or Platform with reasonable and appropriate physical, electronic, and procedural safeguards and has a SOC 2 report. Any sections of the Site or Platform that collect sensitive Personal Information use industry-standard secure socket layer (TLS/SSL) encryption. To take advantage of TLS, your browser must support up-to-date encryption protection, as found in the latest versions of most common browsers, such as Internet Explorer, Mozilla Firefox, Google Chrome, and Safari.
Cookies And Related Technologies
- are essential for us to provide our Site or Platform to you;
- help us optimize, personalize and/or otherwise improve your experience and/or the performance of the Site and our service and marketing-related communications with you; and
- enable advertising delivered to you to be more relevant.
Most web browsers allow you to erase cookies on your computer, block cookies from your computer, or notify you when a cookie is stored on your computer. If you choose to disable or otherwise block certain cookies, you may be unable to use, or experience decreased functionality with, parts of the Site. Your browser may also support functions to block or restrict pixel tags.
How We Respond To Do Not Track Signals
We track visitors to the Site over time (see “COOKIES AND RELATED TECHNOLOGIES” section above), We do not track visitors to the Site across third-party websites and therefore we do not respond to Do Not Track signals in these circumstances.
Looker’s third-party service providers serve ads on our behalf across the Internet. Some of these ads may be personalized for you based on information collected from your use of the Site. We do not share any of your Personal Information with the third-party service providers that serve ads on behalf of Looker. Please visit the Network Advertising Initiative Opt-Out page at: http://www.networkadvertising.org/managing/opt_out.asp if you do not wish to receive personalized ads from Looker on third-party websites.
The Network Advertising Initiative (“NAI”) offers useful information about Internet advertising companies, including information about how to opt out of interest-based advertising by their members. See http://www.networkadvertising.org/participating-networks for the list of NAI members. See http://www.networkadvertising.org/managing/opt_out.asp for the opt-out page. You may also visit http://www.aboutads.info/consumers/ to learn about online behavioral advertising and how to opt out from online behavioral ads served by some or all participating companies.
Links To Third-Party Sites
Looker is a business service, not a consumer product. The Site or Platform is not directed to, nor intended to be used by, individuals under the age of 13, or the equivalent minimum age in the relevant jurisdiction. Looker does not knowingly collect personal information from individuals under the age of 13, or the equivalent minimum age in the relevant jurisdiction. If you become aware that an individual under the age of 13, or the equivalent minimum age in the relevant jurisdiction, has provided us with personal information, please contact us immediately at firstname.lastname@example.org. If we become aware that an individual under the age of 13, or the equivalent minimum age in the relevant jurisdiction, has provided us with personal information, we will take steps to delete such information.
If you apply for a job at Looker, we collect and use your personal data for legitimate human resources and business management reasons including:
- identifying and evaluating candidates for potential employment, as well as for future roles that may become available;
- recordkeeping in relation to recruiting and hiring;
- ensuring compliance with legal requirements, including diversity and inclusion requirements and practices;
- conducting criminal history checks as permitted by applicable law;
- protecting our legal rights to the extent authorized or permitted by law; or
- emergency situations where the health or safety of one or more individuals may be endangered.
Your personal data may be accessed by recruiters and interviewers working in the country where the position for which you are applying is based, as well as by recruiters and interviewers working in different countries.
We use third party service providers to provide a recruiting software system. We also share your personal data with other third party service providers that may assist us in recruiting talent, administering and evaluating pre-employment screening and testing, and improving our recruiting practices.
Recourse and Enforcement
This section describes how to contact us about our practices or to make a complaint, the complaint and recourse methods available to you, and the enforcement powers to which we are subject.
In compliance with the Privacy Shield Principles, Looker commits to resolve complaints about our collection or use of your personal information. European Union, UK and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Looker at:
101 Church Street, 4th Floor, Santa Cruz, CA 95060
Data Protection Officer
Lillian Pang, Taceo Limited
If you have an unresolved complaint, Looker has committed and signed on to the JAMS EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield ADR (JAMSADR), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not resolved your complaint, please contact or visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint.
The services of JAMS EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield ADR are provided at no cost to you. Mediations will be conducted pursuant to JAMS International Mediation Rules unless the parties have specified a different set of Rules or Procedures.
Looker is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). European Union and Swiss individuals have the possibility, under certain conditions, to invoke binding arbitration.
- "Analytics Data" means information about how the Site and/or the Platform are performing.
- "Do Not Track" is a technology and policy proposal that enables users to opt out of tracking by websites they do not visit, including analytics services, advertising networks, and social platforms.
- "Interactive Areas" means the Site’s publicly accessible blogs, community forums, comments sections, discussion forums, training material, event registration or other interactive features.
- "Looker", "we" and "us" mean Looker Data Sciences, Inc.
- "Looker Users" means individuals designated by the Looker customer as a user of the Looker software products or Platform.
- "Looker Customers" means companies that license Looker software products or Platform, including “Powered by Looker” and white label versions.
- "JAMS" stands for Judicial Arbitration and Mediation Services. JAMS is the largest private alternative dispute resolution (ADR) provider in the world.
- "NAI" means the Network Advertising Initiative.
- "Platform" means Looker’s software products, including the Looker Data Platform, Looker Data Apps, Powered by Looker and white-label deployments.
- "Site" means the website at https://looker.com.
- "Usage Data" means information about all of your interactions with the Site and/or the Platform. It may include information regarding any interaction you have with the Site or Platform, such as which functionalities are used and the frequency of use (e.g., pages visited, actions taken, queries run, fields added, user accounts, account roles, and connected database types).