| Support

Phorest Platform Privacy Notice for US & Canada Salons & Staff

Pattern Pattern

Effective Date: 1 August 2025

Last Updated: 1 August 2025

nDevor Systems Ltd d/b/a Phorest, (“Phorest” “we,” “our,” or “us”) values your privacy. This US and Canada Privacy Notice (“Privacy Notice”) describes how Phorest collects, uses, discloses, and otherwise processes personal information from or about individuals located in the US and Canada, as well as the rights and choices individuals may have regarding such personal information. 

For additional information about the privacy choices you may have regarding your personal information, please review the Your Privacy Choices section below. 

California Residents: If you are a resident of California, please refer to the Additional Information for California Residents section below for information about the categories of personal information we may collect, and your rights under California privacy laws.

Canada (Including Quebec) Residents: If you are a resident of Canada, please refer to the Additional Information for Canadian Residents section below for information about the categories of personal information we may collect, and your rights under Canadian Privacy Laws.

EU/UK Privacy Notice: If you are located in the European Union or United Kingdom, please refer to our applicable notice here.

By using our Phorest Services (as defined below), you agree that your personal information will be handled as described in this Privacy Notice. 

Table of Contents

  1. Scope
  2. Personal Information Collected
  3. How We May Use Personal Information
  4. Disclosures of Personal Information
  5. Cookies and Other Tracking Mechanisms
  6. Your Privacy Choices
  7. External Links and Features
  8. Children’s Privacy
  9. Security
  10. Changes to this Privacy Notice
  11. Contact Us
  12. APPENDIX 1 – Additional Information for California Residents
  13. APPENDIX 2 – Additional Information for Canadian Residents

1. Scope

Phorest provides business management software to salons and their employees and contractors to take payments, manage online bookings, SMS notification delivery and other services (the “Phorest Services”). Phorest also operates the website www.phorest.com (the “Site”) and mobile application PhorestGo (“PhorestGo” or the “App,” and together with the Website, the Platform) which are accessed by users to avail of the Phorest Services. 

Phorest acts as controller of your personal information (meaning that it is the entity responsible for the collection, use, or disclosure of your personal information and does so for its own purposes) from which you can be directly or indirectly personally identified (personal information) when you use the Phorest Services. 

This Privacy Notice applies to the personal information of the following categories of users of Phorest Services:

  1. customer businesses such as salons who are natural persons or sole proprietors (“Salons”); 
  1. employees or contractors of customer businesses who use the Phorest Platform and Services (“Staff”) as indicated specifically throughout this Privacy Notice. 

Please note that this Privacy Notice does not apply to personal information collected by third parties through use of their products or services (for example, where you follow links to third party websites over which we have no control, or you purchase goods or services from those third parties independently of Phorest).

Phorest also provides functionality which allows clients of Salons or Staff to book appointments. If you are a client of a Salon or Staff that uses the Phorest Services in this manner, the Privacy Notice at Phorest Privacy Notice | Phorest applies to you. 

The Phorest Services also are governed by the following terms, including their applicable terms governing limitations on damages and the resolution of disputes:

  1. for Salons – Phorest Salon Software Terms and Conditions (including any service-specific terms that apply to additional Phorest Services offered from time to time) (the Phorest Platform T&Cs)) and the PhorestPay Terms and Conditions.
  1. for Employees who avail of PhorestTips and for Salons who enable the PhorestTips service for their employees PhorestTips Employee Terms & Conditions.

This Privacy Notice applies to the extent we process personal information on our own behalf, as a controller or business.

Additional Notices. Depending on how you interact or engage with us, we may provide you with additional or supplemental privacy notices. These additional notices will control to the extent there is a conflict with this Privacy Notice. For example, this Privacy Notice does not apply to the personal information we collect and process about job applicants and candidates for employment with us, or to employees or contractors with whom we work.

2. Personal Information Collected

We collect personal information directly from you, from third-party sources, and, to the extent permitted by applicable law, automatically through your use of the Phorest Services. To the extent permitted by applicable law, we may combine the personal information we collect from publicly available or third-party sources. The personal information we collect varies depending upon your use of our Phorest Services and our interactions with you.

Personal Information Collected Directly. We may collect the following personal information directly from you:

Category of Personal Information Personal Information We Collect
Salons
Demographic and Contact DataFirst and last name, email address, phone number, postal address
Account data Customer ID, transaction data, login details
Financial information and purchase history data such as account number, sort code and tax and banking details (to facilitate the creation of direct debits and payment of your Phorest invoice).
Technical dataIP address; browser type and operating system; geolocation (subject to applicable law); any other unique numbers assigned to a device.
Other Identifying Information that You Voluntarily Choose to ProvideWhile using Phorest Services, you may submit or upload certain content, communications, data, attachments or files to our Services for hosting and processing by us at your discretion (subject to applicable law). 
Online presenceURL of salon’s website and/or social media account
Staff
Demographic and Contact DataFirst and last name, email address, phone number (as provided by salon owner)
PhorestTips account data Account ID, transaction data, email address
Financial information and purchase history data Tax ID number (where applicable) for self-employed staff
Technical dataIP address; app and/or browser type and operating system; geolocation; any other unique numbers assigned to a device.
Other Identifying Information that You Voluntarily Choose to ProvideWhile using Phorest Services, you may submit or upload certain content, communications, data, attachments or files to our Services for hosting and processing by us at your discretion (subject to applicable law). 

Personal Information Collected from Third Parties. We may collect and receive personal information from third party sources, such as business partners, data analytics and marketing providers, operating systems, social media platforms, customers and other users, and service providers or other third parties who provide services or perform functions on our behalf. We may collect the following information regarding both Salons and Staff from third-party sources:

  • Lead and Prospect Information. We may receive lead information from third parties about prospective customers that may be interested in our Phorest Services. We may also engage with third parties to enhance or update our customer information. For example, we may receive certain personal information from data analytics and marketing providers for marketing and advertising purposes, and for purposes of reaching new customers.
  • Referral Information. We may offer users the ability to invite friends or refer other users to access or use our Phorest Services. In doing so, we may collect and receive certain personal information about individuals referred to our Phorest Services.

Personal Information Collected Automatically. We may, to the extent permitted by applicable law, automatically collect or derive personal information related to your use of our Phorest Services, including through the use of cookies, pixel tags, and other similar technologies. This may include:

  • Device and Browsing Information. When you use our Phorest Services, we may collect browser type, domain name, page views, access times, date/time stamps, operating system, language, device type, unique ID, Internet service provider, referring and exiting URLs, clickstream data, and other similar device and browsing information. 
  • Activities and Usage. We also may collect activity information related to your use of the Phorest Services, such as information about the links clicked, searches, features used, items viewed, time spent within the Phorest Services, your interactions with us within the Phorest Services, and other similar activity and usage information.
  • Location Information. We also may collect or derive general location information, such as through your IP address. Additionally, with your permission, we may collect geolocation information from your device. You may turn off location data sharing through your device settings. 

For more information about our use of cookies and other similar technologies, please see the Cookies and Other Tracking Mechanisms section below.

3. How We May Use Personal Information

We may collect, use, disclose and otherwise process personal information for the following purposes:

  • Phorest Services and Support. To enable the Phorest Services, communicate with you about your use of the Phorest Services, provide troubleshooting, technical support, and for similar support purposes, respond to your inquiries, fulfill your requests, and to otherwise run our day-to-day operations.
  • Account Creation and Management. To enable account creation and management, including allowing you to create a profile and set preferences.
  • Analytics and Improvement. To better understand how users access and use the Phorest Services, and for other research and analytical purposes, such as to evaluate, develop, and improve our Phorest Services and business operations, and for internal quality control and training purposes.
  • Communication. To respond to your questions, send you requested materials and newsletters, as well as information and materials regarding our Phorest Services and our offerings. We may also use this information to send administrative information to you, for example, information regarding the Phorest Services and changes to our terms and policies.
  • Customization and Personalization. To tailor content we may send or display on the Phorest Services, including to offer location customization and to otherwise personalize your experiences and offerings.
  • Marketing and Advertising. For marketing, advertising, and promotional purposes. For example, to send you promotional information about our Phorest Services, including information about sales, discounts, and new offerings, as well any other information that you sign up to receive.
  • Insight Development and Data Enhancement. We may combine personal information collected through the Phorest Services with other information that we or third parties collect in other contexts to obtain insights into how our Phorest Services are used.
  • Security and Protection of Rights. To protect the Phorest Services and our business operations, and to protect our rights or those of our stakeholders; to prevent and detect fraud, unauthorized activities and access, and other misuse; where we believe necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety or legal rights of any person or third party, or violations of our Terms of Use. 
  • Compliance and Legal Process. To comply with applicable legal or regulatory obligations, including as part of a judicial proceeding, to respond to a subpoena, warrant, court order, or other legal process, or as part of an investigation or request, whether formal or informal, from law enforcement or a governmental authority.
  • Auditing, Reporting, and Other Internal Operations. To conduct financial, tax and accounting audits, audits and assessments of our operations, including our privacy, security and financial controls, as well as for risk and compliance purposes. We may also use personal information to maintain appropriate business records and enforce our policies and procedures.
  • General Business and Operational Support. To assess and implement mergers, acquisitions, reorganizations, bankruptcies, and other business transactions such as financings, and to administer our business, accounting, auditing, compliance, recordkeeping, and legal functions.

4. Disclosures of Personal Information

We may disclose the personal information we collect for the purposes described above and as follows:

  • Vendors and Phorest Services Providers. We may disclose personal information we collect to our service providers, processors, and others who perform functions on our behalf. These may include, for example, IT service providers, help desk, payment processors, analytics providers, consultants, auditors, and legal counsel.
  • Affiliates and Subsidiaries. We may disclose personal information we collect to our affiliates or subsidiaries who will use and disclose this personal information in accordance with this Privacy Notice.
  • Business Partners. Any information that we collect and process on behalf of a business client will be disclosed to the business client and otherwise shared as directed by that business client. 
  • Salons. Where an employee of a Salon avails of PhorestTips, certain PhorestTips account data will be shared with the employing Salon as part of Phorest’s reporting procedures in which case the Salon is a separate controller.
  • Third Party Marketing and Analytics Providers. We may disclose or make available personal information to third party platforms and providers that we use to provide or make available certain features or portions of the Phorest Services, or as necessary to respond to your requests. We may also make personal information available to third parties to support our marketing, analytics, advertising, and campaign management.
  • Compliance and Legal Obligations. We may disclose personal information to third parties to comply with our legal and compliance obligations and to respond to legal process. For example, we may disclose information in response to subpoenas, court orders, and other lawful requests by regulators and law enforcement, including responding to national security or law enforcement disclosure requirements. This may include regulators, government entities, and law enforcement as required by law or legal process. Additionally, it may include certain disclosures that we are required to make under applicable laws, such as the names of sweepstakes and contest winners.
  • Security and Protection of Rights. We may disclose personal information where we believe it is necessary to protect the Phorest Services, our rights and property, or the rights, property and safety of others. For example, we may disclose personal information in order to (i) prevent, detect, investigate and respond to fraud, unauthorized activities and access, illegal activities, and misuse of the Phorest Services, (ii) situations involving potential threats to the health, safety, or legal rights of any person or third party, or (iii) enforce, and detect, investigate and take action in response to violations of, our PhorestPay Terms and Conditions. We may also disclose information, including personal information, related to litigation and other legal claims or proceedings in which we are involved, as well as for our internal accounting, auditing, compliance, recordkeeping, and legal functions.
  • In Support of Business Transfers. If we, or our affiliates are, or may be acquired by, merged with, or invested in by another company, or if any of our assets are, or may be, transferred to another company, whether as part of a bankruptcy or insolvency proceeding or otherwise, we may transfer the information we have collected from you to the other company.  We may also share certain personal information as necessary prior to the completion of such a transaction or corporate transactions such as financings or restructurings, to lenders, auditors, and third-party advisors, including attorneys and consultants, as part of due diligence or as necessary to plan for a transaction.
  • Aggregate and Deidentified Information. Notwithstanding anything else in this Privacy Notice, we may, to the extent permitted by applicable law, use, disclose, and otherwise process aggregate and deidentified information related to our business and the Phorest Services with third parties for quality control, analytics, research, development, and other purposes. 
  • Other Disclosures. We may disclose personal information in other ways not described above, but will notify you and, if necessary, obtain your consent.

5. Cookies and Other Tracking Mechanisms

We use cookies, pixels, local storage objects, log files, APIs, and other mechanisms to automatically collect browsing, activity, device, and similar information within our Phorest Services and to target advertising and content. We may also engage third-parties or service providers to do the same. We use this information to, for example, analyze and understand how visitors interact with our Phorest Services; identify and resolve bugs and errors in our Phorest Services; assess, secure, protect, optimize and improve the performance of our Phorest Services; conduct marketing and analytics activities; and personalize content in our Phorest Services. To manage your preferences regarding cookies, targeted advertising, and other tracking mechanisms within our Phorest Services, please see Your Privacy Choices below. Unless otherwise permitted by applicable law, we will only use these technologies with your consent.

Cookies. Cookies are alphanumeric identifiers that we transfer to your device’s hard drive through your web browser for record-keeping purposes. Some cookies allow us to make it easier for you to navigate our Phorest Services, while others are used to enable a faster log-in process, support the security and performance of the Phorest Services, or allow us to track activity and usage data within Service. 

Pixel Tags. Pixel tags (sometime called web beacons or clear GIFs) are tiny graphics with a unique identifier, similar in function to cookies. While cookies are stored locally on your device, pixel tags are embedded invisibly within web pages and online content. We may use these, in connection with our Phorest Services to, among other things, track the activities of users, help us manage content and compile usage statistics. We may also use these in HTML e-mails we send, to help us track e-mail response rates, identify when our e-mails are viewed, and track whether our e-mails are forwarded.

Local Storage Objects. Local storage is a web storage mechanism that allows us to store data on a browser that persists even after the browser window is closed. Local storage may be used by our web servers to cache certain information in order enable faster loading of pages and content when you return to our websites. You can clear data stored in local storage through your browser. Please consult your browser help menu for more information.

Third-Party Analytics and Tools. We use third party tools, such as Google Analytics, which are operated by third party companies. These third-party analytics companies may use cookies, pixels, and other similar tools to collect usage data about our Phorest Services in order to provide us with reports and metrics that help us evaluate usage of our Phorest Services and improve performance and user experiences. To learn more about Google’s privacy practices, please review the Google Privacy Privacy Notice at https://www.google.com/policies/privacy/partners/. You can also download the Google Analytics Opt-out Browser Add-on to prevent their data from being used by Google Analytics at https://tools.google.com/dlpage/gaoptout.

 Targeted Advertising. We work with third parties, such as ad networks, channel partners, mobile ad networks, analytics and measurement services and others (“third-party ad companies”) to personalize content and display advertising within our Phorest Services, as well as to manage our advertising on third-party sites, mobile apps, and online services. We may share certain information with these third-party ad companies, and we and them may use cookies, pixels tags, and other tools to collect usage and browsing information within our Phorest Services, as well as on third-party sites, apps and services, such as IP address, location information, device ID, cookie and advertising IDs, and other identifiers, as well as browsing information.  We and these third-party ad companies use this information to provide you more relevant ads and content within our Phorest Services and on third-party sites and apps, and to evaluate the success of such ads and content.

Cross-Device Tracking. We and our third-party providers may use the information we collect within our Phorest Services and on other third-party sites and services to help us and these third parties to identify other devices that you use (e.g., a mobile phone, tablet, other computer, etc.).

Third-Party Advertising. We work with third parties, such as ad networks, channel partners, mobile ad networks, analytics and measurement services and others (“third-party ad companies”) to personalize content and display advertising within our Phorest Services, as well as to manage our advertising on third-party sites, mobile apps and online services. We may share certain information with these third-party ad companies, and we and them may use cookies, pixels tags, and other tools to collect usage and browsing information within our Phorest Services, as well as on third-party sites, apps, and services, such as IP address, location information, device ID, cookie and advertising IDs, and other identifiers, as well as browsing information. We and these third-party ad companies use this information to provide you more relevant ads and content within our Phorest Services and on third-party sites and apps, and to evaluate the success of such ads and content.

6. Your Privacy Choices

We make available several ways that you can manage your privacy choices and submit privacy requests related to your personal information. Some of these choices are browser and device specific, which means that you need to set the preference for each browser and device you use to access our Phorest Services. In addition, if you delete or block cookies, you may need to reapply these preferences to each browser and/or device used to access our Phorest Services. 

These options include:

  • Account and Profile Information. You can review and update some of the personal information we maintain about you by logging into your account and updating your profile information directly within our Phorest Services.
  • Marketing Communications. We may send periodic promotional emails or other similar communications to you, in accordance with applicable law. You may opt-out of these communications by following the instructions provided to you in the communication. If you opt-out of receiving promotional content from us, we may still send you communications about your account or any services you have requested or received from us. Additionally, you can manage your communication preferences in your account settings.
  • Push Notifications. You can manage the type of push notifications you receive from us in the App or in PhorestGo by adjusting your device settings or by modifying the settings.
  • Cookie Settings. To prevent cookies from tracking your activity on our Site or visits across multiple websites, you can set your browser to block certain cookies or notify you when a cookie is set; you can also delete cookies. The “Help” portion of the toolbar on most browsers will tell you how to prevent your device from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to delete cookies. Visitors to our Site who disable cookies will be able to browse the Site, but some features may not function.
  • Browser Signals/Do Not Track. Our Site currently does not respond to “Do Not Track” signals. You may, however, disable certain tracking as discussed in this section (e.g., by disabling cookies); you also may opt-out of targeted advertising by following the instructions in the Industry Ad Choice Programs section below.
  • Industry Ad Choice Programs. You can also control how participating third-party ad companies use the information that they collect about your visits to our Site and those of third parties, in order to display more relevant targeted advertising to you. If you are in the U.S., you can obtain more information and opt out of receiving targeted ads from participating third-party ad networks at aboutads.info/choices (Digital Advertising Alliance). Opting out of participating third party ad networks does not opt you out of being served advertising. You may continue to receive generic or “contextual” ads on our Site. You may also continue to receive targeted ads on other websites, from companies that do not participate in the above programs.   

7. External Links and Features

Our Service may contain links to third-party websites or features or provide certain third-party connections or integrated services. Any access to and use of such linked websites, features, or third-party services is not governed by this Privacy Notice. We are not responsible for the information practices of such third parties, including their collection, use, and disclosure of your personal information. You should review the privacy policies and terms for any third parties before proceeding to those websites or using those third-party features or services.

8. Children’s Privacy    

Our Phorest Services are not designed for children, and we do not knowingly collect personal information from children under 13. If you are a parent or legal guardian and you believe we have collected your child’s information in violation of applicable law, please contact us using the contact information in the Contact Us section below.

9. Security

We have implemented safeguards intended to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. Please be aware that despite our efforts, no data security measures can guarantee security.

10. Changes to this Privacy Notice

This Privacy Notice is current as of the effective date set forth above. We may change this Privacy Notice from time to time, so please be sure to check back periodically. We will post any updates to this Privacy Notice on this page. If we make material changes to how we collect, use, or disclose the personal information we have previously collected, we will endeavor to provide you prior notice as required by applicable law, such as by emailing you or posting prominent notice on our website or within the Phorest Services.

11. Contact Us

If you have any questions or concerns regarding this Privacy Notice or our privacy practices, you may contact us at gdprdpo@phorest.com.

APPENDIX 1 – Additional Information for California Residents

This section of the Privacy Notice provides additional information for California residents and describes our information practices pursuant to the California Consumer Privacy Act 2018, as amended by the California Privacy Rights Act 2020, and its implementing regulations (the “CCPA”). Depending on how you interact or engage with us, we may provide you with other privacy notices with additional details about our privacy practices. 

This section applies to “personal information” as defined in the CCPA, whether collected online or offline. This section does not address or apply to our handling of personal information that is exempt under the CCPA. 

Categories of Personal Information Collected and Disclosed. Depending on how you use the Phorest Services, we may collect (and have collected in the prior 12 months) the following categories of personal information:

Categories of Personal Information CollectedCategories of Third Party Disclosures
Identifiers. Such as name, alias, email, phone number, address, user ID username, unique personal identifier, online identifier, IP address, or other similar identifiers.Advertising networks;Data analytics providers;Salons;Other users in accordance with your privacy settings; andOthers as required by law.
Customer Records. Such as account information and customer records that contain personal information, such as name, account name, other characteristics or descriptions, email, address, phone number, and other contact information, communications preferences, billing and payment information, customer service and support tickets and records, and other information you provide in order to use our Phorest Services.Salons; andOthers as required by law.
Commercial Information. Such as records of products or services purchased, obtained, or considered, or other purchasing or use histories or tendencies.Salons; andOthers as required by law.
Internet and electronic network activity information. Such as browsing history, clickstream data, search history, and information regarding interactions with our Site, mobile application, advertisements, or emails, including other usage data related to your use of our Phorest Services or other online services.Advertising networks;Data analytics providers;Internet service providers, operating systems, and platforms; andOthers as required by law.
Geolocation Data. Such as general location information about a particular individual or device.Data analytics providers; andOthers as required by law.
Audio, Visual, and Other Electronic Data. Such as information collected via call recordings if you are interacting with us in a customer service capacity or if you call us on a recorded line, recorded meetings and webinars, videos, photographs, user profile images, and security camera footage to secure our offices and premises.Others as required by law.
Professional information. Such as job title, company name, business email, business phone number, and other similar professional-related information.Salons; andOthers as required by law.
Inferences. Such as inferences drawn from any of the information described in this section to create a profile about a consumer reflecting the consumer’s preferences, characteristics, behaviors, attitudes, intelligence, abilities, and aptitudes.Advertising networks;Data analytics providers; andOthers as required by law.
Protected Classifications. Such as race/ethnicity, gender, age, sex, veteran status, disability, and other characteristics of protected classifications under California or federal law.Salons; andOthers as required by law.
Sensitive Personal Information. In limited circumstances, we may collect: Social security numbers, driver’s license, state identification card, or passport number; Account log-in in combination with any required security or access code, password, or credentials allowing access to an account; and the contents of a consumer’s mail, email, and text messages (where we are not the intended recipient).Salons; andOthers as required by law.

We have also disclosed the above categories of personal information to our service providers for business purposes in the past 12 months.

Source of Personal Information. We generally collect personal information from the following categories of sources:

  • Directly or indirectly from you;
  • Our business partners;
  • Salons; and
  • Our vendors and service providers.

Purposes of Collection, Use, and Disclosure. As described in the How We May Use Personal Information section above, in general, we collect and otherwise process personal information for the following business or commercial purposes, or as otherwise directed or consented to by you:

  • Phorest Services and support;
  • Account creation and management;
  • Analytics and improvement;
  • Communication;
  • Customization and personalization;
  • Marketing and advertising;
  • Insight development and data enhancement;
  • Security and protection of rights; 
  • Compliance and legal process;
  • Auditing, reporting, and other internal operations; and
  • General business and operational support.

Sensitive Personal Information. Other than the purposes described above, we do not collect, use, or disclose “sensitive personal information” beyond the purposes authorized by the CCPA.

Retention of Personal Information. Phorest only retains the personal information it receives as described in this Privacy Notice for (a) as long as necessary to provide you with the Service and the App as Phorest’s client; or (b) as long as necessary to fulfil the purpose(s) for which it was collected, including for the purposes of providing Phorest products and services, to resolve disputes, to establish legal defenses, to conduct audits, to pursue our business purposes, to enforce Phorest’s agreements and to comply with applicable laws. In some circumstances, Phorest may store your personal information for longer periods, for instance where Phorest is required to do so in accordance with legal, regulatory, tax and accounting requirements. 

Phorest is required under tax laws to retain your personal information for a minimum period of seven (7) years. Any personal information related to health and safety records will be retained for ten (10) years. 

Phorest will continue to process your personal information where processing is necessary for the establishment, exercise or defense of legal claims; or (b) justified under applicable law.

Rather than delete your data, we may also deidentify it by removing identifying details. Where we have committed to maintaining and using personal information in a deidentified form, we agree not to reidentify deidentified data except as permitted by applicable law.

Sales and Sharing of Personal Information. The CCPA defines “sale” as disclosing or making available personal information to a third-party in exchange for monetary or other valuable consideration, and “sharing” includes disclosing or making available personal information to a third-party for purposes of cross-contextual behavioral advertising.

While we do not disclose personal information to third parties in exchange for monetary compensation, we may be considered as “selling” or “sharing” personal information under the CCPA because of our use of third-party ad or analytics cookies and other tools. We “sell” or “share” the following categories of personal information: identifiers, and Internet or other electronic network activity information. We disclose these categories to third-party advertising networks, analytics providers, and social networks for purposes of marketing and advertising. We do not sell or share personal information about individuals we know are under the age of 16.

California Privacy Rights. The CCPA provides California residents with specific rights regarding personal information. Subject to certain conditions and exceptions, California residents have the following rights with respect to their personal information:

  1. Right to Know (Access & Portability). You have the right to request: 
    1. the categories or personal information we collected about you; 
    2. the categories of sources from which the personal information is collected; 
    3. our business or commercial purposes for collecting, selling, or sharing personal information; the categories of third parties to whom we have disclosed personal information; and 
    4. a copy of the specific pieces of personal information we have collected about you.
  1. Right to Correct. You have the right to request we correct inaccurate personal information.
  1. Right to Delete. You have the right to request we delete your personal information.
  1. Right to Opt-Out of Sales and Sharing. You have the right to opt-out of “sales” and “sharing” of your personal information as those terms are defined under the CCPA. To exercise these rights, please use the (Do Not Sell or Share My Personal Information/Your Privacy Choices) link at the bottom of our website.

You also have the right to opt-out of “sales” and “sharing” of your personal information using an opt-out preference signal. If our site detects that your browser or device is transmitting an opt-out preference signal, such as the “global privacy control”—or GPC— signal, we will opt that browser or device out of the use of cookies or other tools on our site that result in a “sale” or “sharing” of your personal information. If you come to our site from a different device or from a different browser on the same device, or if you clear your cookies, you will need to opt-out again, or use an opt-out preference signal, for that browser and/or device as well.

  1. Right to Limit Use and Disclosure. We do not engage in uses or disclosures of “sensitive personal information” that would trigger the right to limit use of sensitive personal information under the CCPA. 
  1. Right to Non-Discrimination. We will not discriminate against you for exercising any of the rights described in this section.

Exercising Your Privacy Rights. If you are a California resident and would like to exercise your CCPA rights, you may do so via any of the methods described below:

  • Email us at gdprdpo@phorest.com. 

Verification. Before responding to your request, we must first verify your identity using the personal information you recently provided to us. You must provide us with your full name and email address. We will take steps to verify your request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for the denial.

Authorized Agents. You may designate someone as an authorized agent to submit requests and act on your behalf. Authorized agents will be required to provide proof of their authorization in their first communication with us, and we may also require that the relevant consumer directly verify their identity and the authority of the authorized agent.

APPENDIX 2 – Additional Information for Canadian Residents

This section of the Privacy Notice provides additional information for residents of Canada and describes our information practices pursuant to applicable Canadian privacy laws, including, without limitation, the Personal Information Protection and Electronic Documents Act (Canada), the Act respecting the protection of personal information in the private sector (Québec), the Personal ‎Information Protection Act (Alberta), the Personal Information Protection Act (British ‎Columbia) ‎‎(collectively the “Canadian Privacy Laws”)‎, each as may be applicable to your situation. 

Unless otherwise specified in this Appendix, all capitalized terms shall have the same meaning as that set out in the main body of the Privacy Notice. To the extent that there is a conflict between this Canada Appendix and the main body of the Privacy Notice, the provisions of this Appendix will prevail for residents of Canada only. You may have different rights depending on your province or territory of ‎residence within ‎Canada: please consult the sections below relevant to your ‎province or territory of residence.‎

How we collect your personal information. The means through which we collect your personal information are described in Section 2 “Personal Information Collected” of the main body of the Privacy Notice.

Consent. Notwithstanding any information provided in the main body of the Privacy Notice, unless otherwise allowed by Canadian Privacy Laws applicable in your province or territory of ‎residence, we will only ‎‎collect, use, or communicate your personal information ‎with your consent.‎ You are generally not obliged ‎to provide your personal ‎information, however please note that we may be unable to process an ‎‎application on your behalf or provide certain services to you if you refuse to ‎provide certain personal ‎‎information.‎ 

You have the right to withdraw your consent to further use, communication or processing of your ‎personal ‎information, as further explained below in the “Your Rights” ‎section of this Appendix.‎

To the extent required by applicable Canadian Privacy Laws, we will not collect personal information about you from third party unless you either give us or the relevant third party your consent to same.

Types of personal information we collect. The categories and elements of personal information we collect are described in Section 2 “Personal Information Collected” of the main body of the Privacy Notice.

Purposes for which we collect personal information. The purposes for which we collect your personal information are described in Section 3 “How We May Use Personal Information” of the main body of the Privacy Notice.

Persons to whom we communicate personal information. The categories of third parties to whom we may communicate your personal information are those described in Section 4 “Disclosures of Personal Information” of the main body of the Privacy Notice.

Cross-border transfers of personal information. To achieve the purposes identified in the main body of the Privacy Notice, your personal information may be transferred outside of your province or territory of residence, including to other countries. This may include jurisdictions with privacy laws which do not provide the same level of protection as Canadian Privacy Laws. These laws might permit foreign governments, courts, law enforcement or ‎‎‎‎regulatory agencies to ‎access, use or disclose personal information in those jurisdictions. We will only conduct such transfers in full compliance with applicable Canadian Privacy Laws, including, without limitation, i) by conducting any any necessary data privacy impact assessments and ii) ensuring that written agreements with appropriate safeguards are in place to govern such transfer and protect your personal information in compliance with applicable data protection laws. 

Security measures. The security measures we have in place to protect your personal information are described in Section 9 “Security” of the main body of the Privacy Notice. 

Retention and deletion of personal information. Phorest only retains the personal information it receives as described in the main body of the Privacy Notice for (a) as long as necessary to provide you with the Service and the App as Phorest’s client; or (b) as long as necessary to fulfil the purpose(s) for which it was collected, including for the purposes of providing Phorest products and services, to resolve disputes, to establish legal defenses, to conduct audits, to pursue our business purposes, to enforce Phorest’s agreements and to comply with applicable laws. In some circumstances, Phorest may store your personal information for longer periods, for instance where Phorest is required to do so in accordance with legal, regulatory, tax and accounting requirements. As a general rule, we will delete your personal information no later than seven years after your last interaction with us, unless otherwise required by applicable Canadian Privacy Laws.

Notwithstanding the above, we will retain any personal information used to render a decision concerning you for a period of at least one year after such decision was rendered.

Rather than delete your data, we may also anonymize it, to the extent permitted by and in accordance with the requirements of locally applicable Canadian Privacy Laws.

Rights relating to Personal Information. Applicable Canadian Privacy Laws provide residents of Canada with specific rights regarding personal information. Subject to certain conditions and exceptions, Canadian residents have the following rights with respect to their personal information:

  • Access. You have the right to access and receive a copy of your personal ‎information that we hold.
  • Rectification. You have the right to request that we update or correct inaccuracies in your ‎Personal Information that we hold, if you demonstrate the inaccuracy or incompleteness of ‎your Personal Information that we hold.
  • Withdraw consent. You have the right to withdraw your consent to our use, communication, or further processing of your ‎personal information at any time after you have consented. Please note that this may impact our ability to continue to ‎provide certain services or functionalities to you. Withdrawing your consent does not affect the lawfulness of any use ‎or communication of your personal information by us up to that point, and does not oblige us to delete your ‎personal information if we are otherwise allowed to retain it under applicable privacy laws.

If you are a resident of the province of Québec, you have the following rights, ‎in addition to those identified above:‎

  • Portability. You have the right to obtain a copy of your ‎personal information that we hold in an accessible technological format or to have us transfer it to another third party of your ‎choice.‎
  • De-indexation. You have the right to request, in certain ‎circumstances, that we cease ‎disseminating your Personal Information or to ‎de-‎‎index any hyperlink that allows access ‎to that personal information by ‎technological means, if ‎‎such dissemination contravenes ‎applicable law.‎

You may exercise any of the rights listed above by contacting us at gdprdpo@phorest.com. 

We will respond to your request within 30 days of receipt. To the extent permitted by applicable Privacy Laws, if further time is required, we will inform you of ‎this and the reason for the delay, and the timeframe for response. 
Changes to this Appendix. We may make changes to the Privacy Notice and this Appendix from time to time, so please be sure to check back periodically. We will post any updates to this Privacy Notice or this Appendix on this page. If we make material changes to how we collect, use, or disclose the personal information we have previously collected, we will endeavor to provide you prior notice as required by applicable law, such as by emailing you or posting prominent notice on our website or within the Phorest Services. Where required by applicable law, we will obtain your consent to such amended practices.