Welcome to Hyphen -- The new way for employees to communicate freely, and for companies to keep their finger on the pulse of their workforce, from Hyphenmark Inc., under the name “Hyphen” (“Hyphen,” “we,” “us” or “our”).
Through the Service, you can create questions anonymously, vote on questions anonymously, comment on questions anonymously and see other anonymous questions and comments from other users of the Service. When you share a Question through the app, you are anonymously sharing your Question with the users also using our Service and who have connected with the same Company Group as you. We may also choose to feature certain Questions, in which case such Questions may be anonymously shared with all users of the Service.
We take your privacy seriously. If you have any questions about this Policy or about privacy at Hyphen, please contact us at [email protected]
What Data Do We Collect?
Personal Data We Collect from Customer Companies
When a Customer Company indicates interest in our Service, we collect the following information via our sign-up form: full name, email address, company name, phone number, and size of company. We collect this information through a landing page which an interested Customer Company might access through forms on various directory services detailed in our Third Party Provider.
Personal Data We Collect from Employee Users
We collect certain human resource (“HR”) information, and other information about Employee Users, from the Customer Company, and at the Customer Company’s option, such as: region of origin, name, email address, phone number, education, demographic data, and gender. This Data is provided by the Customer Company’s HR department, and is loaded and maintained in our system to allow for segmentation analytics.
As noted above, we collect certain HR information about Employee Users directly from the Customer Company.
When Employee Users answer surveys or engage in conversations with peers on the App, Site, or System by voting on surveys or engaging in text conversations between peers, we collect employee opinions from Employee Users. Employee User votes or comments are connected to their authors.
When a User visits our Site, we use certain tracking data (“Tracking Information”). We use Intercom, Perspective API by Google Jigsaw, Mixpanel, Google Analytics, and Freshdesk for Tracking Information.
The following Tracking Information is collected: email address, device ID, IP address. We collect your email address, and our analytics provider, Mixpanel, collects other Tracking Information, such as IP addresses and device information, directly through inclusion of their sdk/pixel. Tracking Information is collected via the Site and our web-applications, as well as via our ios and android implementations.
Cookies and Use of Other Tracking Technology
We may also collect information using web beacons, also known as “tracking pixels.” Web beacons are electronic images that may be used in our Service or emails and help deliver cookies, count visits, understand usage, and campaign effectiveness, and determine whether an email has been opened and acted upon.
How Do We Use Your Data?
We may use information about you for various purposes, including to:
- Provide, maintain and improve our Service;
- Provide and deliver the Service Customer Company requests and configures, process transactions and send you related information, including confirmations;
- Investigate system issues that impact our ability to provide the Service to Users;
- Send you technical notices, updates, confirmations, security alerts and support and administrative messages;
- Respond to your comments, questions and requests and provide customer service;
- Communicate to Customer Companies with you about products, services, offers, promotions, rewards and events offered by Hyphen and others, and provide news and information we think will be of interest to you;
- Monitor and analyze trends, usage and activities in connection with our Service and improve and personalize the Service;
- Personalize and improve the Service, content or features that match user profiles or interests;
- Link or combine with information we get from others to help understand your needs and provide you with better service; and
- Connect you with other users in your Contacts.
We will not sell, rent, or share Personal Data with third parties outside of our company without your consent, except in the following ways:
Law Enforcement and Internal Operations
We sometimes contract with other companies and individuals to perform functions or services on our behalf, such as software maintenance, data hosting, sending email messages, etc. We necessarily have to share your Personal Data with such third-parties as may be required to perform their functions. We take steps to ensure that these parties take protecting your privacy as seriously as we do, including entering into Data Processing Addendum(s), EU Model Clauses and/or ensuring these third-parties have EU-U.S. and Swiss-US Privacy Shield certification.
Third Party Service Providers
The following third-party processors collect personal data on our behalf and transmit it to us.
We use the following third-party providers:
Type of Provider
Third-Party Provider Details
|CRM and Support|
How is My Data Protected?
We have implemented reasonable administrative, technical and physical security measures to protect your personal information against unauthorized access, destruction or alteration. For example:
- SSL encryption (https) where we deal with personal data. Personal Data is encrypted in transit using https/ssl/tls and encrypted at rest. Our database is encrypted and data transferred via sftp is encrypted using PGP.
- Password protection on your account.
- Rotating verification codes to access by some parties
- Data is kept on secure, encrypted servers, located in the US.
- Restricting staff access to Personal Data, protected by password logs and two factor authentication.
- Non-Disclosure Agreements with vendors
- Regular staff privacy and security training
However, because no security system can be 100% effective, we cannot completely guarantee the security of any information we store, process or transmit.
Payments Encryption: Hyphen utilizes only PCI-DSS compliant payment processing to ensure the security of your personal information.
Special Note Regarding Processing Employee User Data for Company Customers
Our Services involves the processing of Personal Data on behalf of our Customer Companies. When we do so, we are acting as processors for the controllers of such data. As such, we take steps to ensure that Personal Data subject to GDPR is processed in accordance with controller instructions and GDPR; such as entering into a Data Processing Addendum incorporating EU Standard Contractual Clauses governing the processing, transmission and use of such Employee User Personal Data. Customer Companies determine what data on Employee Users are collected and how it is used. If you wish to exercise your data subject rights to review, rectify, delete or port your Employee User Personal Data, please contact the controller to make such request. If you make the request to us, we will work with the controller to process and evaluate such request to confirm whether deletion is required by GDPR.
The foregoing rights apply to persons located in the European Economic Area and Switzerland
Right to Review and Rectify Your Personal Data
Customer Companies or Potential Customers can opt in or out of sharing certain Data either with us or with third parties via email, or via a “reply: to unsubscribe” response.
If you require assistance to change or delete inaccuracies within your Personal Data or would like to know what information about you was collected, please contact us at [email protected] to initiate this process. We reserve the right to charge for copies of data requested. We will inform you by email of changes in the use of Personal Data.
Right to Remove or Withdraw Consent
Customer Companies and their authorized representatives have the right to withdraw consent where such consent is required to share or use data and you may request that we delete your Personal Data. If you receive communications from us and no longer wish to receive them, please follow the removal instructions in the email or change your account settings. Customer Companies can delete Personal Data by emailing us at [email protected] to let us know they wish to terminate their Hyphen engagement. Employee Users wishing to delete data should contact the applicable Company Customer. Deleting your Personal Data does not mean that all of it will be removed. We take steps to delete Personal Data that is no longer necessary in relation to provide the Services by deleting it within 90 days of you terminating your account.. We may be required by law to retain it, or to exercise or defend legal claims, or contractual obligations with our Company Customers to retain some information in connection with our obligation to provide the Services. We also may de-identify and anonymize some data for purposes of retaining it.
If you would like us to transmit your Personal Data to another company providing similar services, we will work with them to do so upon request and verification of such request with both the requestor and the company receiving the Personal Data.
Right to Redress
If you are located in the European Economic Area (EEA) and you believe we have violated any data protection laws you may file a complaint with the Information Commissioner’s Office in the United Kingdom.
Transnational Transfer of Data
If you are providing your Personal Data to us directly to use our Services, we will transmit your data, including your Personal Data, to the United States in order to fulfill our contractual obligations to you.
Your California Privacy Rights
California residents who have an established business relationship with Hyphen may make a written request to Hyphen about whether Hyphen has disclosed any Personal Information to any third-parties for the third-parties' direct marketing purposes during the prior calendar year. To make such a request, please send an email or write us:
Name: Hyphen Data Protection Officer
Address: 612 Howard St., Suite 300, San Francisco, CA 94105
Phone: (650) 400 - 3411
Email: [email protected]
Third Party Websites
We may link to other websites. When you click on one of these links, you are ‘clicking’ to another website. Hyphen does not control the data collection or privacy practices of such third-party sites. We encourage you to read the privacy policies of any third-party sites, as their collection, use and storage practices, and policies may differ from ours.
Minors Under 16 Years of Age
Hyphen does not knowingly collect or store any personal information from or about children under the age of 16.
If you believe a child under the age of 16 has under any circumstances provided us with personal information and data, a parent or legal guardian can email us at [email protected] to request that their children’s information be deleted from our records.
Do Not Track
Do Not Track” or DNT is a feature enabled on some browsers that sends a signal to request that a web application disable its tracking or cross-site user tracking. At present, our Site does not respond to or alter its practices when a DNT signal is received.