Privacy policy (Trello power-up)

Last Updated: November 8, 2023

This Privacy Policy explains our approaches to the processing of Time Tracking Power-Up by Everhour (further “Powerup”) users Personal Data.

OUR CONTACT DETAILS

EVERHOUR LTD (the “Company” or “we”, “us”, “our”)
Address: 4 Pavlou Nirvana & Aipeias Str., Alpha Tower, Floor 1, Flat/Office, 11 3021, Limassol, Cyprus
E-mail: powerup@everhour.com

This Privacy Policy describes, among other issues:

  • Our role in the processing
  • Personal Data that we collect about you and the ways we process it
  • Situations in which we can share your Personal Data with third parties
  • Storage of your Personal Data
  • Your rights with regard to Personal Data and methods of their realization

We may update this Privacy Policy from time-to-time to keep it in conformity with the Regulation of the European Parliament and of the Council (EU) 2016/679 (the “GDPR”), California Consumer Privacy Act, California Civil Code sections 1798.100 et seq. (the “CCPA”) and other relevant legislation. We will notify you if we make any material changes to our Privacy Policy. If such changes make it necessary to obtain your explicit consent for further processing of your Personal Data, we will request your consent or your renewed consent (in case it was obtained previously).

OUR ROLE IN THE PROCESSING

We act as the data controller in a limited number of cases connected with:

  • meeting our legal obligations
  • improving Powerup
  • making sure that your data and Powerup’s systems are safe and secure
  • marketing Powerup and its features
  • communicating with you.

We may also act as a data controller when you visit Powerup as an unregistered user.

We act as a data processor when processing information that you and your invited users store in your Powerup account. Such data is subject to your management as the account holder. We will process such information only under your instruction and on your behalf.

You can read more on the distribution of roles in the processing on our page on GDPR.

COLLECTING AND USING YOUR PERSONAL DATA

We only collect and use your Personal Data as specified in the table:

Purpose of the processing Personal Data Legal basis for the processing
To bill you for services - Business Name
- Email
- Subscription plan
- Credit card details
- Extra billing information (e.g. VAT number, address of record)
Terms of Use
* Without providing this data you will not be able to use Powerup
Receiving and responding to your enquiries, requests for support and other communication - Name
- Email address
- Subject
- Information that you leave in the message / email
Our legitimate interest in helping you resolve any issues with Powerup and your interest in receiving our response and support

COOKIES

In addition to the above, we may use the “cookies”, “web beacons”, and similar technologies which help us to evaluate access trends and improve Powerup. Please visit this page to get more information about our use of these technologies.

DISCLOSURE OF YOUR PERSONAL DATA

Like most companies, we use tools from third parties (service providers) that help us to support Powerup and improve your experience with Powerup. To that end, we may share some of your Personal Data with the service providers listed in the table below. They operate independently from us and have their own Privacy Policies which we strongly recommend you to review:

Service Provider Type of Service Country Privacy Policy
Amazon Web Services Inc. Cloud Infrastructure United States Amazon Privacy Notice
Stripe Inc. Payments United States Stripe Privacy Policy
Help Scout PBC Customer Support United States Help Scout Privacy Policy
Google Inc. Analytics United States Google Privacy Policy
GitHub Inc. Internet hosting, provides bug reports United States GitHub Privacy Statement
Asana Inc. Work management platform United States Asana Privacy Statement
Slack Technologies LLC Business communication platform, provides notifications of subscriptions Ireland
United States
Slack Privacy Policy
DocuSign Inc. Electronic signature and document archive storage service United States DocuSign Privacy Notice

Please note that we may disclose your Personal Data when required to do so by law or in connection with any legal proceedings or prospective legal proceedings or in order to establish, exercise or defend our legal rights, protect your safety or the safety of others, investigate fraud, or respond to a valid governmental request.

We also reserve the right to share your Personal Data in case it is required under the terms of a reorganization, merger, or sale of our company.

We do not and will not sell your Personal Data to third parties.

RETENTION OF YOUR PERSONAL DATA

We retain your Personal Data for as long as needed to fulfill the purposes indicated in the section “Collecting and using your personal data”.

When you remove your account, we delete all data associated with your account from our production database. Meanwhile, we do keep backups, designed for catastrophic system recovery, for 30 days. The backups are purged on a rolling 30-day cycle. When an account is deleted, none of your Personal Data will remain on our servers past 30 days. Anything you delete from your account while it’s active will also be purged from the backups on day 30.

In certain cases, we may retain your Personal Data for a longer period when needed to comply with our legal obligations, to resolve disputes, establish and defend legal claims.

NO AUTOMATED DECISION-MAKING OR AUTOMATED PROFILING

We neither use automated decision-making nor refer to automated profiling.

RIGHTS THAT YOU HAVE AND THE WAY, YOU CAN EXERCISE THEM

When we act as data controller, you may file a request to us to exercise your rights in relation to your Personal Data as set out in the tables below. Please note that we have no direct relationship with third parties with whom our users may interact using Powerup. Any such party who would like to amend or delete data which may be stored in Powerup should direct his or her request to the relevant user acting as the “data controller” for such information.

If you would like to access, amend or delete information that you provided, you may also do so by signing in to Powerup and making any changes that you want.

EU Residents’ Rights Explanation
Right to access personal information You may ask what Personal Data concerning you is kept by us and receive a copy of it, as well as other supplementary information
Right to rectification You may request us to modify your Personal Data that you believe is inaccurate or outdated
Right of erasure You may request the deletion of Personal Data concerning you at any time
* Please note that we can retain your Personal Data if necessary to comply with our legal obligations or resolve disputes. If we have no basis to continue processing your Personal Data, we will delete or remove it and notify you about such deletion or removal
Right to restrict/suspend processing of Personal Data You may request the limitation of the processing of your Personal Data when one of the following applies: (a) the accuracy of the Personal Data is contested by you, (b) the processing is unlawful and you oppose the erasure of the Personal Data, (c) we no longer need the Personal Data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims, and (d) you have objected to processing pending the verification whether the legitimate basis overrides this
Right to data portability You may be entitled to obtain your Personal Data in a structured, commonly used and machine-readable form in order to transfer it to another data controller. Please note that this right only applies to Personal Data that we processed based on your consent or Terms of Service
Right to be informed You have the right to be provided with clear and easy-to-understand information about how we use your Personal Data
The right to object to the processing You may object to the processing of Personal Data concerning you, where we are relying on a legitimate interest and there is something about your particular situation that makes you want to object to the processing on this basis. We will no longer process the Personal Data unless we demonstrate compelling legitimate basis for the processing which overrides your interests, rights and freedoms or for the establishment, exercise or defense of legal claims
Right to withdraw consent You may withdraw your consent at any time where we are relying on the consent to process your Personal Data. If we have no other basis for processing your Personal Data, after you send us a request to withdraw consent, we will stop processing your Personal Data that we were processing under your consent
Right to complain to a supervisory authority You have the right to contact the data protection authority in your country to complain about our data protection and privacy practices

We aim to comply without undue delay, and within one month at the latest. To address more complex requests, we might need to extend the answering time by a further 2 months. In this case, we will notify you about the extension within 1 month of receipt of your request and will explain to you the reasons for such extension. We may decline to process unreasonable requests or requests that are not otherwise required by local law.

California residents also have the following rights under the CCPA:

California Residents’ Rights Explanation
Right to know about Personal Data collected, disclosed, and sold You have a right to be informed about what categories of Personal Data we are collecting: you can request us to disclose what Personal Data we have collected in the past 12 months and right to get a free copy of your Personal Data disclosed in a readily usable and readable format
Right to opt-out of the sale of personal information Each California resident can request business stops selling Personal Data to third parties
Please note that we do not, and will not, provide your Personal Data in direct exchange for money. Therefore, in the literal sense, we do not sell your Personal Data
Right to request deletion You can also request us to delete the Personal Data we have collected in the past 12 months
Right to equal service and prices (“non-discrimination”) Your choice to exercise any of your privacy rights will not be used as a basis to discriminate against you in services offered or pricing.

Mandatory Verification: As required by CCPA we will need to verify your identity before processing your request. In order to verify your identity, you will be asked to log in to your account or (if you do not have an account) we will try to match the information you provided with the information we handle about you. In certain circumstances, we may decline the request, mainly where we are unable to verify your identity, for example, if you have requested us to delete your Personal Data.

As required by CCPA we endeavor to respond to a verifiable request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by e-mail.

How to exercise any of your rights? You may exercise your rights by sending a relevant request to the e-mail indicated in the contact details.

CHILDREN’S PERSONAL DATA

We do not knowingly collect or solicit information from children under the age of 13 (or 16 – for European Economic Area residents) and do not knowingly allow such persons to use Powerup. If we discover that we hold Personal Data of a user under 13 (or 16, where applicable), we will promptly delete such data from our records.

If you are under the age of 13 (or 16, where applicable), please do not provide any Personal Data to us.

If you are aware of anyone younger than 13 (or 16, where applicable) using Powerup, please let us know and we will delete Personal Data about this person as soon as possible.

QUESTIONS

If you have any questions or would like to provide feedback, please reach out at powerup@everhour.com. We will do our best to resolve your query as soon as possible.