PACTO - Privacy policy

Published 09. Nov 2020|Updated 27. Dec 2020

   

 

 

 

 

1  Introduction

Thank you for using the Norwegian Refugee Council’s (“NRC”) Pacto application (“Pacto”) to establish a lease agreement with your Tenant/Property Owner and to manage your relationship with the other party as it pertains to that agreement. Trust is imperative in the establishment of such an arrangement not only between you and your Tenant/Property owner but also trust in NRC and the Pacto application that is seeking to help you establish that contract and manage the relationship. NRC is committed to protecting the privacy and security of your personal data without which the Pacto application would not be able to provide the services and assistance it aims to deliver.

The Pacto application is a product of the Norwegian Refugee Council. NRC is an independent humanitarian organisation working to protect the rights of displaced and vulnerable people during crisis. One of the core values of NRC is Accountability; NRC is committed to being accountable to our staff and the people we serve.

1.1  Data Controller

When this policy mentions “NRC”, “Pacto”, “we”, “us” or “our” it refers to the

 

Norwegian Refugee Council («Data controller») 

VAT number 977 538 319Prinsens gate 2, 0152 Oslo 

 

which is responsible for processing your information in accordance with the applicable national and Norwegian laws and rules. 

This policy describes how we collect, use process, and disclose your personal information in conjunction with your access to and use of the Pacto application and services.

 

2  Information we collect

There are 4 general categories of information that we collect.

2.1  Information you give us that is necessary for the use of the PACTO application.

We ask for the following information about you when you use the Pacto application. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it we may not be able to provide you with the requested services.

  • Account information: When signing up for the Pacto application, we require certain information such as your full legal name, email address, date of birth and phone number.
  • Profile and listing information: To use certain features of the Pacto application such as creating a lease agreement or property profile, we may ask you to provide additional information such as address, and GPS location of property.
  • Identity verification information: To help create and maintain a trusted environment, we may collect identity verification information (such as images of your government issued ID, passport, national ID card, or driving license, as permitted by applicable laws) or other authentication information.
  • Your electronic e-Signature: To digitally sign a lease agreement, we will ask for your signature to be electronically entered into the agreement template once terms have been agreed.
  • Communication with NRC and other Pacto application users: When you communicate with NRC or use the PACTO application to communicate with other Users, we collect information about your communication and any information you choose to provide.

2.2  Information you choose to give us that allows us to improve the Pacto experience

You may choose to provide us with additional information to improve your experience and this information will be processed based upon the legitimate interest of NRC to improve the Pacto service or, when applicable, your consent.

  • Additional profile information: You may choose to provide us with additional information such as gender, preferred language, profile picture. or number of household members.
  • Other information: You may also choose to provide us with additional information when you respond to surveys, request referral services, communicate with NRC staff, or request other types of support from NRC.

2.3  Information we automatically collect from your use of the Pacto application.

When you use the Pacto application, we automatically collect personal information about the services you use and how you use them. This information is necessary for adequate performance of our contract with you, to comply with any legal obligations and based upon our legitimate interest in providing and improving the services and functionalities of the Pacto application.

  • Geolocation: we may collect geolocation data about your approximate location via GPS or IP address
  • Usage information: We collect information about your interactions with the PACTO app and actions within the PACTO application
  • Log data and device information: We automatically collect log data and device data which may include details about how you used the PACTO application, IP address, type of data connection, access dates, times and lengths, hardware and software, device event information, unique identifiers and crash data.

2.4  Information we collect about you from third parties.

NRC may collect information, including personal information, that others provide about you when they use the Pacto application. We do not control, supervise or respond to how others process your personal information and any information request regarding the disclosure should be directed to such third parties.

  • User Referrals or Invitations: If you are invited to Pacto, the person who invited you may submit personal information about you such as your name, email address and phone number.

2.5  Children’s Data

The Pacto application is not directed to children under the age of 16 and we do not knowingly collect any personal information from children. If you believe that we are processing personal information belonging to a child inappropriately, we ask that you contact us immediately using the information provided in the contact section.

3  How NRC uses the information we collect

NRC may collect, use, store and process your personal data to (1) provide, understand, improve and develop the services provided by and through Pacto application, (2) create and maintain a safe, secure and trusted environment for all users and (3) report on social impact to investors and/or institutional donors.

3.1  Provide, understand, improve, and develop the services provided by, and through, Pacto application such that we can:

  • Enable you to use and access the Pacto application
  • Enable you to communicate with other users of the application
  • Operate, protect, improve and optimize the Pacto application and experience such as by conducting analytics and research
  • Provide customers service
  • Send you service or support messages
  • Enable the listing of a property to be leased
  • Enable the establishment of a legally binding lease agreement to be signed with e-signatures between parties to the agreement
  • Enable usage of e-signed agreements outside of the application

We process this personal information for given these legitimate interests in providing and improving Pacto and our users experience and where it is necessary to ensure the adequate performance of our contract with you.

3.2  Create and maintain a safe, secure, and trusted environment for all Users.

  • To detect and prevent fraud, spam, abuse, security incidents and other harmful activity.
  • To conduct security investigations and risk assessment, verify or authenticate information or identifications provided by you (such as to verify your Accommodation address or compare your identification photo to another photo you provide),
  • Comply with our legal obligations,
  • Resolve any disputes with any of our Users and enforce our agreements with third parties,
  • Enforce our Terms of Service and other policies

In connection with the activities above, we may conduct profiling based on your interactions with the Pacto application, your profile information and other content you submit to the Pacto application, and information obtained from third parties. In limited cases, automated processes may restrict or suspend access to the Pacto application if such processes detect activity that we think poses a safety or other risk to the Pacto application, our Users, or third parties. If you challenge the decisioning based on the automated process, please contact us as provided in the Contact Us section below.

We process this personal information for these purposes given our legitimate interest in protecting the Pacto application, our Users, to measure the adequate performance of our contract with you, and to comply with applicable laws.

3.3  Measure and report on social impact outcomes such that

  • We can report aggregate data to our investors on the contributions of the service to improving security of tenure and relationships between tenants and landlords
  • We can report on the general profile of users and their interactions with the application and other users of the application

4  Sharing and Disclosure

4.1  Sharing between Users

In order for Pacto to fulfil its role as a facilitator of the leasing/letting of property between Users and other interaction between Users, we may need to share certain information, including personal information, with other Users as it is necessary for the performance of our contract with you.

  • When you as a Tenant seek to rent a property, certain information about you is shared with the Property Owner including your name, email, and phone number. When signing a lease agreement additional information which may be required under national law for entering a legal lease agreement may be shared with the property owner and attached as an appendix to the lease agreement.
  • When you as a Property owner seek to rent your property to a Tenant, certain information about you is shared with the prospective tenant including your name, email address, phone number, property location and description, and contract proposal information.
  • When you as a tenant invite a Co-signer to the lease agreement for the rental of a property, certain information about you is shared with the Co-signer including your name, email address and phone number.

4.2  Compliance with Law, Responding to Legal Requests, Preventing Harm and Protection of our Rights.

  • NRC may disclose your information, including personal information, to courts, law enforcement, governmental authorities, tax authorities, or authorized third parties, if and to the extent we are required or permitted to do so by law or if such disclosure is reasonably necessary: (i) to comply with our legal obligations, (ii) to comply with a valid legal request or to respond to claims asserted against NRC, (iii) to respond to a valid legal request relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our users to legal liability, (iv) to enforce and administer our Terms of Service, or other agreements with Users, or (v) to protect the rights, property or personal safety of NRC, its employees, its Users, or members of the public. For example, if permitted due to the forgoing circumstances, Host tax information may be shared with tax authorities or other governmental agencies.
  • These disclosures may be necessary to comply with our legal obligations, for the protection of your or another person's vital interests or for the purposes of our or a third party’s legitimate interest in keeping the NRC application secure, preventing harm or crime, enforcing or defending legal rights, facilitating the collection of taxes and prevention of tax fraud or preventing damage.
  • Where appropriate, we may notify Users about legal requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law, or (ii) we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon NRC’s property, its Users and the Pacto application. In instances where we comply with legal requests without notice for these reasons, we may attempt to notify that Member about the request after the fact where appropriate and where we determine in good faith that we are no longer prevented from doing so.

4.3  Service Providers

The Pacto application uses a variety of third-party services to enable us to provide the services related to the PACTO application. Service providers may be located inside or outside the EEA. Our service providers are based in the US and European Union.

For example, service providers help us to 1) verify your identity and enable user registration 2) create e-signature Tenancy Agreements 3) to secure the application and its services 4) enable User to User communication and provide customer support services. These providers have limited access to your personal data to the extent needed to perform the service and are contractually bound by data processor agreements or the legal equivalent to protect your data. These third parties only use personal data in accordance with our instruction. NRC only shares data to ensure that we are able to fulfil our contract with you.

4.4  Referrals to other Service providers

In cases where you ask for support in resolving an issue that goes beyond NRC internal expertise to resolve, you may request that NRC share limited personal information to another service provider in order to enable you to access additional or supplementary services. In such cases, NRC will ask for explicit consent to share your personal data and inform you of what aspects of your personal data will need to be shared to facilitate your request.

4.5  Business Transfers.

If NRC undertakes or is involved in any merger, acquisition, divestiture, reorganization, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your information in connection with such transaction or in contemplation of such transaction (e.g., due diligence). In this event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy.

4.6  Aggregated Data.

We may also share aggregated information (information about our users that we combine together so that it no longer identifies or references an individual user) and other anonymized information for regulatory compliance, industry and market analysis, research, demographic profiling, marketing and advertising, and other business purposes.

5  Other important information

5.1  Analyzing your Communications.

We may manually review, scan, or analyze your communications on the Pacto application for fraud prevention, abuse prevention and investigation, risk assessment, regulatory compliance, product development, research, analytics, customer support and dispute resolution purposes. We may need to manually review some communications, such as for investigations into potential fraud or reports of abusive behaviour and to provide customer support.

These activities are carried out based on NRC's legitimate interest in ensuring compliance with applicable laws and our Terms, preventing fraud, promoting safety, and improving and ensuring the adequate performance of our services

6  Your Rights

6.1  Managing your information

You have the right to manage and update some of your information through your profile settings. You are responsible for keeping your personal information up-to-date and ensuring that the information you have provided is accurate. The application will occasionally send you reminders to verify your information.

6.2  Right to request changes to personal information

You have the right to request that we make changes to inaccurate or incomplete personal information about you that you are unable to change yourself through the application.

6.3  Your rights to access

You have the right at anytime to request access to the personal data NRC process about you and to have that data provided to you in structured, commonly used, and machine-readable format.

6.4  Data Retention and Erasure.

We generally retain your personal information for as long as is necessary for the performance of the contract between you and us and to comply with our legal obligations. You can request to have all your personal information deleted entirely. Please note that if you request the erasure of your personal information:

  • We may retain some of your personal information as necessary for our legitimate business interests, such as fraud detection and prevention and enhancing safety. For example, if we suspend an Pacto account for fraud or safety reasons, we may retain certain information from that Pacto account to prevent that User from opening a new NRC Account in the future.
  • We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, Pacto may keep some of your information for tax, legal reporting and auditing obligations.
  • Information you have shared with others may continue to be publicly visible on the Pacto application, even after your Pacto Aacount is cancelled. However, attribution of such information to you will be removed. Additionally, some copies of your information (e.g., log records) may remain in our database, but are disassociated from personal identifiers.
  • Because we maintain the Pacto application to protect from accidental or malicious loss and destruction, residual copies of your personal information may not be removed from our backup systems for a limited period of time.
  • We will on a regular basis delete inactive User accounts - and all associated data personal - for which, we no longer have a legitimate interest in data retention.

6.5  Retention and erasure of data by third party service providers.

Along with any request to have your personal information deleted, NRC will request that any third-party service provider delete your data as well. Please note that if you request the erasure of your personal information:

  • E-Signed agreements. Your personal data will not be removed from any e-signed agreement between you and another party. These e-signatures will be retained for as long as necessary to comply with legal requirements on legal document retention.

6.6  Objection to processing

You have the right to object to the processing of your data for specific purposes. If you object to processing NRC will cease to process your data unless we can provide compelling legitimate grounds for continuing to process.

For any processing based on consent, you may withdraw consent at any time without affecting the lawfulness of the processing that took place before the withdrawal.

6.7  Lodging complaints

You have the right to lodge complaints about our data processing activities by filing out a complaint and raising it with our data protection staff. Information on how to contact can be found in the Contact Us section.

You have the right to lodge a complaint directly with the supervisory authority. The supervising authority strongly recommends that you contact our data protection staff before seeking to contact them. Information on how to contact the supervising authority can be found at:

https://www.datatilsynet.no/rettigheter-og-plikter/den-registrertes-rettigheter/

 

7  SECURITY

We are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unauthorized access, loss, destruction, or alteration. Some of the safeguards we use to protect your information are firewalls and data encryption, and information access controls. If you know or have reason to believe that your Pacto account credentials have been lost, stolen, misappropriated, or otherwise compromised or in case of any actual or suspected unauthorized use of your Pacto account, please contact us following the instructions in the Contact Us section below.

8  CHANGES TO THIS PRIVACY POLICY

NRC reserves the right to modify this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on the NRC Application and update the “Last Updated” date at the top of this Privacy Policy. We will also provide you with notice of the modification by email at least thirty (30) days before the date they become effective. If you disagree with the revised Privacy Policy, you may cancel your Account. If you do not cancel your Account before the date the revised Privacy Policy becomes effective, your continued access to or use of the NRC Application will be subject to the revised Privacy Policy.

9  Contact Us

If you have any inquires on how we process your personal data or want to exercise your rights, send an email to the NRC Data protection officer:

 

data.protection@nrc.no