gro Privacy Notice
Effective Date: June 1, 2024
Last Updated: June 1, 2024
gro (“we,” “us,” or “gro”) is committed to protecting your privacy and has implemented the measures below to protect the personal data we process about you (“Personal Data”).
If you are a California resident, please read our Notice to California Residents Section, which contains additional information that we are required to provide to you by the California Consumer Privacy Act of 2018 (CCPA).
Our Business
Gro is an app that validates and encourages changes in behavior and takes a proactive approach to mental health. We help university students identify tools that can help them form new ways of thinking and learn how to cope with life’s challenges and prepare for their future.
Scope
Except as set forth in the Exclusions section below, this notice applies to all Personal Data gathered for and on behalf of gro through the various gro sites that link or refer to it (such as websites or applications operated by or on behalf of gro and HTML-formatted e-mail messages) together with any and all offline sources including sales and marketing activities and surveys (collectively, the “Sources”). By using the Sources, you consent to the data collection and use practices described in this notice.
Exclusions
- Customer Contracts. This notice does not apply to the information that we process in connection with providing services to our customers or partners under our contracts with them. Our processing of such information is governed by our customer contracts and other relevant privacy notices.
1. Information We Collect
When you visit our websites or otherwise interact with gro (such as when you email with us, download content from us, answer surveys), we may collect the following information about you. We may also collect information about you in the ordinary course of business in the context of an existing business relationship, from our customers or from third parties:
- Contact details, such as name, social media handle, job title and employer, email address, mailing address, phone number, and emergency contact information.
- Professional credentials, such as your specialty, educational and professional history, and institutional affiliations.
- Financial information, such as payment card information, bank account number, or other details used to purchase our products/services.
- Usage information, such as information about how you use the services and interact with us.
- Survey data, such as your responses to our online and offline surveys.
- Communications that we exchange when you contact us.
- Biometric Data such as voice or likeness during audio/video recordings.
- Publicly available information, including information that you or others publish on social media and in publications, such as tweets, comment, news articles, or video or audio content.
- Device identifiers, including information about the device you are using to visit connect to our websites or applications, such as your device operating system type and version number, manufacturer and model, device identifier (such as the Google Advertising ID or Apple ID for Advertising), browser type, screen resolution, IP address, and other device identifiers.
- Online activity data, including browsing history, search history, clickstream data, and other information about your interactions with our services, websites, applications, social media pages, and email communications. We, our service providers and business partners also collect this type of information over time and across third-party websites.
2. Sensitive Personal Data
We do not generally seek to collect Sensitive Personal Data (which is also known in certain jurisdictions as special categories of Personal Data) through the Sources. The term “Sensitive Personal Data” refers to categories of personal data identified by data privacy laws as requiring special treatment, including in some circumstances the need to obtain explicit consent from you. These categories generally include racial or ethnic origin, political opinions, financial background, religious or similar beliefs, sexual life, trade union membership or affiliations, individual medical records and history, physical, mental or physiological health condition or genetic or biometric information, ideological views or activities, information on social security measures, or administrative or criminal proceedings and sanctions which are treated outside pending proceedings.
If we seek to collect Sensitive Personal Data, we will do so in accordance with applicable law. Unless we have specifically requested such data, however, we ask that you not send to us, nor share with us, any Sensitive Personal Data.
3. How We Use Personal Data
We may use Personal Data for the following purposes:
A. Service delivery. We use Personal Data to:
- provide, operate and improve our business and the services we provide;
- provide information about our products and services;
- communicate with you about the services, including by sending you announcements, updates, security alerts, and support and administrative messages;
- communicate with you about events, surveys, questionnaires or webinars in which you participate;
- understand your needs and interests, and personalize your experience with our services and communications;
- provide support and maintenance for our sites; and
- respond to your requests, questions and feedback.
B. Research and development. We may use Personal Data for research and development purposes, including to collect information about your experiences with or opinions about gro or topics of importance in the industry via surveys, focus groups and other online or offline research activities. We may also use Personal Data to analyze and improve our sites, services, marketing, and business. As part of these activities, we will explain to you how we collect and use your data, and may in all cases create aggregated, de-identified or other anonymous data from Personal Data we collect.
C. Marketing and advertising. We may send you gro-related marketing communications, including in person or electronically, as permitted by law.We advertise online and offline, and our advertisements may be targeted based on your use of the sites or your activity elsewhere online and offline.
D. Appending our databases. We may assign a unique identifier to the Personal Data we collect about you or combine this data with other information about you and use this information to supplement our existing databases of Personal Data, analytics, and insights for purposes consistent with this notice. We may also combine information about you that we collect with your Personal Data.
E. Compliance. We may use Personal Data to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements and internal policies;
- enforce the terms and conditions that govern our services; and
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.
4. Disclosure to Third Parties
We may share Personal Data with third parties, as described below.
- Customers: We may share Personal Data, analytics and insights from our databases with our customers in connection with providing our services to those customers.
- Companies and people who work for us: We contract with other companies and individuals to help us provide services including the Sources. For example, we may host some of our Sources on another company’s computers, hire technical consultants to maintain our sites, or work with companies to remove repetitive information from customer lists, analyze data, provide marketing assistance, and provide customer service. In addition, we may validate your identity and other information against available databases. In order to perform their services, these other companies may have limited access to some of the Personal Data we maintain about our users. Other companies may collect information on our behalf through their websites or applications. We require that such companies not use your information for any purpose other than fulfilling their responsibilities to us. We also require that such companies keep your Personal Data confidential and comply with applicable laws. gro’s practice is to (i) conduct reasonable and appropriate due diligence on our service providers; and (ii) obtain written commitments regarding the processing of Personal Data, including that the service provider will only handle Personal Data in accordance with our instructions; adopt adequate technical and organizational measures to protect your personal data; and not retain Personal Data when it is no longer required for completion of its services. Details of service providers and the countries in which they are based are available from the gro by contacting its Global Privacy and Data Protection Officer.
- Promotional and informational offers: Sometimes we send offers to selected groups of users. To accomplish this we may use third parties working on behalf of gro. We provide a variety of mechanisms for you to tell us you do not want to receive such promotional or informational offers. For example, where required by law, we may provide an opt-in box for customers to receive information that is sent by a third-party fulfilment house, and we make clear that, by opting in, you are submitting your data to a third party. You can elect not to receive promotional or informational material from us by following the instructions to opt-out as mentioned or included in each of our programs we send to you.
- Business partners. We may share the information we collect with our prospective or current customers, and other business partners who work with us.
- Universities or academic institutions. We may share the information with academic institutions that we partner with.
- Professional advisors: We may disclose Personal Data to professional advisors, such as lawyers, bankers, auditors, and insurers, where necessary in the course of the professional services that they render to us.
- Business transfers: If we transfer a business unit or an asset (such a gro website) to another company, we may transfer the Personal Data we have collected to the relevant third party.
- Legal requirements: We may be obligated to cooperate with various law enforcement inquiries. gro reserves the right to share or transfer your information to comply with a legal requirement, disclose any activities or information about you to law enforcement or other government officials as we, at our sole discretion, determine necessary or appropriate, in connection with an investigation of fraud, for the administration of justice, intellectual property infringements, or other activity that is illegal or may expose us or you to legal liability. We may release information if, in our judgment the release may be necessary to prevent the death or serious injury of an individual.
5. Legal Basis for Processing Personal Data
In certain jurisdictions, such as the Member States of the European Union, we are required to identify the legal bases for processing Personal Data. We process Personal Data:
- To perform contracts with you or to take steps at your request prior to entering into such contract;
- To comply with a legal obligation;
- For our legitimate business interests, which will be assessed in connection with the specific use of Personal Data;
- With your consent (or, where required to process Sensitive Personal Data, with your explicit consent), which will be requested and given via the Sources or otherwise.
6. Withdrawal of Consent
In certain jurisdictions, when we process Personal Data based on your consent or your explicit consent, you have the right to withdraw your consent in whole or in part at any time. Where applicable, once we have received notification that you have withdrawn your consent, we will no longer Process the Personal Data for the purpose(s) to which you originally consented unless there are compelling legitimate grounds that override your interests, rights and freedoms (for example, to comply with a legal obligation), or for the establishment, exercise, or defense of legal claims. If we processed Personal Data for direct marketing purposes, you have the right to object at any time, in which case we will no longer process your Personal Data for such purposes. The withdrawal of your consent does not affect the lawfulness of such processing that occurred before its withdrawal. Should you withdraw consent to future processing of your Personal Data, we may not be able to contact or interact with you as originally planned when you first provided your consent.
7. Cross-Border Transfers
gro operates on exclusively within the United States of America and your data will not be transferred out of this jurisdiction.
8. Retention and Deletion
gro will retain your Personal Data for as long as your account is active; as needed to provide you products or services; as needed for the purposes outlined in this Privacy Notice or at the time of collection; as necessary to comply with our legal obligations (e.g., to honor opt-outs), resolve disputes, and enforce our agreements; or to the extent permitted by law. gro does not retain Personal Data after it no longer serves the purposes for which it was collected or subsequently authorized. At the end of the retention period, gro will delete your Personal Data in a manner designed to ensure that it cannot be reconstructed or read.
9. Protection of Information
The security of your Personal Data is important to gro. We use reasonable physical, electronic, and administrative safeguards that are designed to protect your Personal Data from loss, misuse and unauthorized access, disclosure, alteration, and destruction. However, regardless of our efforts and the device you use to access the Sources, it is possible that third parties may unlawfully intercept or access transmissions or private communications over an unsecured transmission.
10. Cookies and Other Tracking Technologies
The Sources and/or third parties may use “cookies,” “web beacons,” scripts, tags, Local Shared Objects (Flash cookies), Local Storage (HTML5) beacons, and other similar tracking technologies (collectively, “Tracking Technologies”) to collect information from you automatically as you use the Sources, browse gro websites, and the web. These Tracking Technologies help us tailor our content, gather statistics about and understand website and internet usage, improve or customize the content, offerings, or advertisements through the Sources, personalize your experience with respect to the Sources (for example, to recognize you by name when you return to a gro website), save your password in password-protected areas, save your online video player settings, help us offer you programs or services that may be of interest to you, deliver relevant advertising, maintain and administer the Sources, and for other purposes described in Section 3, “How We Use Personal Data” of this Privacy Notice.
These Tracking Technologies collect “click stream” data and other information regarding your use of the Sources, such as your visits, use of our features and preferences, and may also collect your IP address or some other identifier unique to the device you use to access the Sources (“Identifier”). Your Identifier may be automatically assigned to the device you use to access the Sources. The Sources and/or third parties may also use cookies and similar technologies to recognize you on, off, and across the Sources and across your devices. By using the Sources, whether as a registered user or otherwise, you acknowledge, understand, and hereby agree that you are giving us your consent to track your activities and your use of the Sources through these technologies.
A. Cookies
“Cookies” are text files that a website can send to your device through your browser, which is then used to identify your device by the website. Cookies can be both “session level” (stored only for until you close your web browser), which help you efficiently navigate our Sources during a visit, and “persistent” (stored for a longer period, even after you close your browser), which remember relevant information such as your language preference. gro Sources may use both session level and persistent cookies.
Cookies may also be “first-party cookies,” which are cookies that are placed by the website owner on a website, or “third-party cookies,” which are cookies belonging to one party that are placed on another party’s website. We may use both first- and third- party cookies on the Sources. Some of the third-party cookies we use relate to Tracking Technologies we have licensed from third parties, including Adobe Experience Cloud and Google Analytics. These companies use programming code to collect information about your interaction with our sites, such as the pages you visit, the links you click on, and how long you are on our sites.
If you would like more information about cookies, including how to manage them, please see All About Cookies.
gro Sources do not recognize automated “do not track” instructions. You can, however, adjust your web browser’s privacy preferences regarding the use of most cookies, through your browser’s privacy settings. Unless you choose to block cookies, some Sources may issue cookies when you visit them or click on an e-mail link that we send to you, even if you have previously deleted our cookies. If you choose to delete or block cookies, you may impact your user experience on the Sources, as some features may no longer work. In addition to deleting or blocking cookies, you may be able to manage cookie preferences with the cookie manufacturer. For example, you can opt out of Google Analytics by downloading and installing a browser plugin available here. You can opt out of Adobe Experience Cloud by clicking here.
11. Children’s Privacy
We are committed to protecting the privacy of children. For that reason, we do not knowingly collect or maintain personally identifiable information from any person we actually know is under the age of 13. No part of the Sources are structured to attract anyone under age 13. If we determine that we have collected information about individuals under the age of 13 (or, in certain jurisdictions, 16) through our Sources, we will delete that information.
13. Your Rights as a Data Subject
In some jurisdictions (for example, the Member States of the European Union) you may be entitled to certain rights in and to your Personal Data, subject to certain conditions and exceptions contained in applicable law. These rights may include the following:
- Request us to confirm whether your Personal Data is processed by us, and if we do, to obtain access to your personal data and certain information about it.
- Require the correction of your Personal Data if it is inaccurate or incomplete.
- Direct us to stop processing your Personal Data under certain circumstances.
- Erase or delete your Personal Data, for example, where the data is no longer needed to achieve the purpose for which it was collected.
- Restrict the further Processing of Personal Data
- Request us not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (we currently do not engage in such processing and will notify you prior to doing so).
- Request to receive your Personal Data for transmission to, or to directly transmit to, another data controller in a structured, commonly used and machine-readable format.
To protect your privacy and the security of your Personal Data, we will take reasonable steps to verify your identity before complying with such rights requests.
14. Exercising Your Rights or Raising Concerns
Should you have questions about the Personal Data that we process, or if you have a question, concern, or would like to exercise your legal rights in and to your Personal Data, please contact the gro as follows:
E-mail at beau@gromentalhealth.com.
15. How Your Dispute or Complaint May Be Resolved
Any questions, concerns, or complaints regarding the use of your Personal Data should be directed to gro Privacy Team using the contact information presented above.
16. Changes to This Privacy Notice
We may periodically update this notice. When we post changes to this notice, we will also revise the “Last Updated” date appearing at the top of the notice. If there are material changes to this notice, we will notify you by e-mail or by means of a notice on our home page. We encourage you to review this notice periodically to be informed of how we are using your information and to be aware of any changes to it. Your continued use of the Sources after the posting of any amended notice shall constitute your agreement to be bound by any such changes. Any changes to this notice are effective immediately after we post it.