Salesforce Privacy Statement, effective as of May 24, 2019
At Salesforce, trust is our #1 value. This Salesforce Privacy Statement ("Privacy Statement") describes our privacy practices for the activities set out in this Privacy Statement. Please read this Privacy Statement carefully to learn how we collect, use, share and otherwise process information relating to individuals ("Personal Data"), and to learn about your rights and choices regarding our processing of your Personal Data.
A reference to “Salesforce,” “we,” “us” or the “Company” is a reference to salesforce.com, inc. and the relevant affiliate involved in the processing activity. The addresses of our offices where salesforce.com, inc. and its affiliates are located can be found here.
1. Responsible Salesforce entity
Salesforce is the controller of your Personal Data as described in this Privacy Statement, unless expressly specified otherwise.
For the avoidance of doubt, this Privacy Statement does not apply to the extent we process Personal Data in the role of a processor on behalf of our customers, including where we offer to our customers various cloud products and services through which our customers (and/or their affiliates): (i) create their own websites and applications running on our platforms; (ii) sell or offer their own products and services; (iii) send electronic communications to other individuals; or (iv) otherwise collect, use, share or process Personal Data via our cloud products and services.
For detailed privacy information related to where a Salesforce customer and/or a customer affiliate who uses the Salesforce cloud products and services is the controller, please reach out to the respective customer directly. We are not responsible for the privacy or data security practices of our customers, which may differ from those set forth in this Privacy Statement. For more information, please also see Section 10.3 below.
2. Processing activities covered
This Privacy Statement applies to the processing of Personal Data collected by us when you:
- Visit our websites that display or link to this Privacy Statement;
- Visit our branded social media pages;
- Visit our offices;
- Receive communications from us, including emails, phone calls, texts or fax;
- Use our cloud products and services as an authorized user (for example, as an employee of one of our customers who provided you with access to our services) where we act as a controller of your Personal Data;
- Register for, attend and/or otherwise take part in our events, webinars or contests; or
- Participate in community and open source development.
We also host AppExchange, which is an online marketplace for on-demand web applications that run on the Salesforce platform and that may be provided by us or by third parties (see https://appexchange.salesforce.com/). When applications are provided by us and the application links to this Privacy Statement, this Privacy Statement applies. When applications are provided by third parties, the privacy statement of the third party applies and this Privacy Statement does not apply.
Our websites and services may contain links to other websites, applications and services maintained by third parties. The information practices of such other services, or of social media networks that host our branded social media pages, are governed by third parties’ privacy statements, which you should review to better understand those third parties’ privacy practices.
3. What Personal Data do we collect?
3.1 Personal Data we collect directly from you
The Personal Data that we collect directly from you includes the following:
- If you express an interest in obtaining additional information about our services, request customer support (including accessing the Help & Training Portal), use our "Contact Us" or similar features, register to use our websites, sign up for an event, webinar or contest, or download certain content, we may require that you provide to us your contact information, such as your name, job title, company name, address, phone number, email address or username and password;
- If you make purchases via our websites or register for an event or webinar, we may require that you provide to us your financial and billing information, such as billing name and address, credit card number or bank account information;
- If you attend an event, we may, with your further consent, scan your attendee badge, which will provide to us your information, such as name, title, company name, address, country, phone number and email address;
- If you register for an online community that we host, we may ask you to provide a username, photo and/or biographical information, such as your occupation, social media profiles, company name and areas of expertise;
- If you use and interact with our websites or emails, we automatically collect information about your device and your usage of our websites or emails through cookies, web beacons or similar technologies, such as Internet Protocol (IP) addresses or other identifiers, which may qualify as Personal Data (please see the "What device and usage data we process" section, below);
- If you use and interact with our services, we automatically collect information about your device and your usage of our services, through log files and other technologies, some of which may qualify as Personal Data (please see the "What device and usage data we process" section, below);
- If you voluntarily submit certain information to our services, such as filling out a survey about your user experience, we collect the information you have provided as part of that request; and
- If you visit our offices, you may be required to register as a visitor and to provide your name, email address, phone number, company name and time and date of arrival.
If you provide us or our service providers with any Personal Data relating to other individuals, you represent that you have the authority to do so and acknowledge that it will be used in accordance with this Privacy Statement. If you believe that your Personal Data has been provided to us improperly, or to otherwise exercise your rights relating to your Personal Data, please contact us by using the information set out in the “Contacting us” section below.
3.2 Personal Data we collect from other sources
We also collect information about you from other sources, including third parties from whom we have purchased Personal Data, and combine this information with Personal Data provided by you. This helps us to update, expand and analyze our records, identify new customers and create more tailored advertising to provide services that may be of interest to you. In particular, we collect Personal Data from the following sources:
- Third party providers of business contact information, including mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), IP addresses, social media profiles, LinkedIn URLs and custom profiles, for purposes of targeted advertising, delivering relevant email content, event promotion and profiling; and
- Platforms such as GitHub, to manage code check-ins and pull requests. If you participate in an open source or community development project, we may associate your code repository username with your community account so we can inform you of program changes that are important to your participation or relating to additional security requirements.
4. What device and usage data we process
|Type of Cookies||Description||Managing Settings|
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
If you have chosen to identify yourself to us, we may place on your browser a cookie that allows us to uniquely identify you when you are logged into the websites and to process your online transactions and requests.
Because required cookies are essential to operate the websites, there is no option to opt out of these cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Functional cookies may also be used to improve how our websites function and to help us provide you with more relevant communications, including marketing communications. These cookies collect information about how our websites are used, including which pages are viewed most often.
We may use our own technology or third-party technology to track and analyze usage information to provide enhanced interactions and more relevant communications, and to track the performance of our advertisements.
For example, we use Google Analytics ("Google Analytics"), a web analytics service provided by Google, Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You can learn about Google’s privacy practices by going to www.google.com/policies/privacy/partners/.
Salesforce may also utilize HTML5 local storage or Flash cookies for the above-mentioned purposes. These technologies differ from browser cookies in the amount and type of data they store, and how they store it.
You can choose to opt out of functional cookies. To change your cookie settings and preferences, click the Cookie Preferences link in the footer of the page.
To opt out from data collection by Google Analytics, you can download and install a browser add-on, which is available here.
To learn how to control functional cookies via your individual browser settings, click here.
To learn how to manage privacy and storage settings for Flash cookies, click here.
|Targeting or Advertising cookies||
Targeting or advertising cookies track activity across websites in order to understand a viewer’s interests, and to direct specific marketing to them. Some examples include: cookies used for remarketing, or interest-based advertising.
You can choose to opt out of targeting and advertising cookies. To change your cookie settings and preferences, click the Cookie Preferences link in the footer of the page.
See Section 4.3, below, to learn more about these and other advertising networks and your ability to opt out of collection by certain third parties.
4.3 Notices on behavioral advertising and opt-out for website visitors
As described above, we or third parties may place or recognize a unique cookie on your browser when you visit our websites for the purpose of serving you targeted advertising (also referred to as “online behavioral advertising” or “interest-based advertising”). To learn more about targeted advertising and advertising networks please visit the opt-out pages of the Network Advertising Initiative, here, and the Digital Advertising Alliance, here. To opt-out of targeted advertising that is provided to us and to third parties by Salesforce DMP, click here.
To manage the use of targeting and advertising cookies on this website, click the Cookie Preferences link in the footer of the page or consult your individual browser settings for cookies. To learn how to manage privacy and storage settings for Flash cookies, click here. Various browsers may also offer their own management tools for removing HTML5 local storage.
4.4 Opt-Out from the setting of cookies on your individual browser
In addition to utilizing the user preference center, where available, you may opt-out from the collection of non-essential device and usage data on your web browser (see the "What device and usage data we process" section, above) by managing your cookies at the individual browser level. In addition, if you wish to opt-out of interest-based advertising click here (or, if located in the European Union, click here). To opt-out of targeted advertising that is provided to us and to third parties by Salesforce DMP, click here. Please note, however, that by blocking or deleting cookies and similar technologies used on our websites, you may not be able to take full advantage of the websites.
While some internet browsers offer a “do not track” or “DNT” option that lets you tell websites that you do not want to have your online activities tracked, these features are not yet uniform and there is no common standard that has been adopted by industry groups, technology companies or regulators. Therefore, we do not currently commit to responding to browsers' DNT signals with respect to our websites. Salesforce takes privacy and meaningful choice seriously and will make efforts to continue to monitor developments around DNT browser technology and the implementation of a standard.
4.5 Social Media Features
Our websites may use social media features, such as the Facebook “like” button, the “Tweet” button and other sharing widgets (“Social Media Features”). You may be given the option by such Social Media Features to post information about your activities on a website to a profile page of yours that is provided by a third party social media network in order to share with others within your network. Social Media Features are either hosted by the respective social media network or hosted directly on our website. To the extent the Social Media Features are hosted by the respective social media networks and you click through to these from our website, the latter may receive information showing that you have visited our website. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our websites with your social media profile.
Salesforce also allows you to log in to certain of our websites using sign-in services such as Facebook Connect. These services will authenticate your identity and provide you the option to share certain Personal Data from these services with us such as your name and email address to pre-populate our sign-up form.
Your interactions with Social Media Features are governed by the privacy policies of the companies providing the relevant Social Media Features.
4.6 Telephony log information
If you use certain features of our services on a mobile device, we may also collect telephony log information (like phone numbers, time and date of calls, duration of calls, SMS routing information and types of calls), device event information (such as crashes, system activity, hardware settings, browser language), and location information (through IP address, GPS, and other sensors that may, for example, provide us with information on nearby devices, Wi-Fi access points and cell towers).
5. Purposes for which we process Personal Data and the legal bases on which we rely
We collect and process your Personal Data for the purposes and on the legal bases identified in the following:
- Promoting the security of our websites and services: We process your Personal Data by tracking use of our websites and services, creating aggregated, non-personal data, verifying accounts and activity, investigating suspicious activity and enforcing our terms and policies, to the extent this is necessary for our legitimate interest in promoting the safety and security of the services, systems and applications and in protecting our rights and the rights of others;
- Providing necessary functionality: We process your Personal Data to perform our contract with you for the use of our websites and services; where we have not entered into a contract with you, we base the processing of your Personal Data on our legitimate interest to provide you with the necessary functionality required during your use of our websites and services;
- Managing user registrations: If you have registered for an account with us, we process your Personal Data by managing your user account for the purpose of performing our contract with you according to applicable terms of service;
- Handling contact and user support requests: If you fill out a “Contact Me” web form or request user support, or if you contact us by other means including via a phone call, we process your Personal Data to perform our contract with you and to the extent it is necessary for our legitimate interest in fulfilling your requests and communicating with you;
- Managing event registrations and attendance: We process your Personal Data to plan and host events or webinars for which you have registered or that you attend, including sending related communications to you, to perform of our contract with you;
- Managing contests or promotions: If you register for a contest or promotion, we process your Personal Data to perform our contract with you. Some contests or promotions have additional rules containing information about how we will process your Personal Data;
- Managing payments: If you have provided financial information to us, we process your Personal Data to verify that information and to collect payments to the extent that doing so is necessary to complete a transaction and perform our contract with you;
- Developing and improving our websites and services: We process your Personal Data to analyze trends and to track your usage of and interactions with our websites and services to the extent it is necessary for our legitimate interest in developing and improving our websites and services and providing our users with more relevant content and service offerings, or where we seek your valid consent;
- Assessing and improving user experience: We process device and usage data as described in Section 4.1 above, which in some cases may be associated with your Personal Data, in order to analyze trends in order to assess and improve the overall user experience to the extent it is necessary for our legitimate interest in developing and improving the service offering, or where we seek your valid consent;
- Reviewing compliance with applicable usage terms: We process your Personal Data to review compliance with the applicable usage terms in our customer’s contract to the extent that it is in our legitimate interest to ensure adherence to the relevant terms;
- Assessing capacity requirements: We process your Personal Data to assess the capacity requirements of our services the extent that it is in our legitimate interest to ensure that we are meeting the necessary capacity requirements of our service offering;
- Identifying customer opportunities: We process your Personal Data to assess new potential customer opportunities to the extent that it is in our legitimate interest to ensure that we are meeting the demands of our customers and their users’ experiences;
- Registering office visitors: We process your Personal Data for security reasons, to register visitors to our offices and to manage non-disclosure agreements that visitors may be required to sign, to the extent such processing is necessary for our legitimate interest in protecting our offices and our confidential information against unauthorized access;
- Displaying personalized advertisements and content: We process your Personal Data to conduct marketing research, advertise to you, provide personalized information about us on and off our websites and to provide other personalized content based upon your activities and interests to the extent it is necessary for our legitimate interest in advertising our websites or, where necessary, to the extent you have provided your prior consent (please see the "Your rights relating to your Personal Data" section, below, to learn how you can control how the processing of your Personal Data by Salesforce for personalized advertising purposes);
- Sending marketing communications: We will process your Personal Data to send you marketing information, product recommendations and other non-transactional communications (e.g., marketing newsletters, telemarketing calls, SMS, or push notifications) about us and our affiliates and partners, including information about our products, promotions or events as necessary for our legitimate interest in conducting direct marketing or to the extent you have provided your prior consent (please see the "Your rights relating to your Personal Data" section, below, to learn how you can control the processing of your Personal Data by Salesforce for marketing purposes); and
- Complying with legal obligations: We process your Personal Data when cooperating with public and government authorities, courts or regulators in accordance with our legal obligations under applicable laws to the extent this requires the processing or disclosure of Personal Data to protect our rights or is necessary for our legitimate interest in protecting against misuse or abuse of our websites, protecting personal property or safety, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes or to respond to lawful requests.
Where we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to perform our contract with you.
6. Who do we share Personal Data with?
We may share your Personal Data as follows:
- With our contracted service providers, who provide services such as IT and system administration and hosting, credit card processing, research and analytics, marketing, customer support and data enrichment for the purposes and pursuant to the legal bases described above; such service providers comprise companies located in the countries in which we operate (see list of relevant countries here: https://www.salesforce.com/uk/company/locations/);
- If you use our websites to register for an event or webinar organized by one of our affiliates, with the affiliate to the extent this is required on the basis of the affiliate’s contract with you to process your registration and ensure your participation in the event; in such instances, our affiliate will process the relevant Personal Data as a separate controller and will provide you with further information on the processing of your Personal Data, where required. A list of companies currently within the Salesforce corporate group is provided as an exhibit to our Annual Report, available here;
- If you attend an event or webinar organized by us, or download or access an asset on our website, with sponsors of the event. If required by applicable law, you may consent to such sharing via the registration form or by allowing your attendee badge to be scanned at a sponsor booth. In these circumstances, your information will be subject to the sponsors’ privacy statements. If you do not wish for your information to be shared, you may choose to not opt-in via event/webinar registration or elect to not have your badge scanned, or you can opt-out in accordance with Section 10 below;
- If you use our services as an authorized user, with your affiliated customer responsible for your access to the services to the extent this is necessary for verifying accounts and activity, investigating suspicious activity, or enforcing our terms and policies;
- With sponsors of contests or promotions for which you register;
- With third-party social media networks, advertising networks and websites, which usually act as separate controllers, so that Salesforce can market and advertise on third party platforms and websites;
- Specifically in relation to the AppExchange website, with our third party partners who may contact you regarding their products or services;
- In individual instances, with professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in countries in which we operate (see list of relevant countries here https://www.salesforce.com/uk/company/locations/) who provide consultancy, banking, legal, insurance and accounting services, and to the extent we are legally obliged to share or have a legitimate interest in sharing your Personal Data;
- With affiliates within the Salesforce corporate group and companies that we acquire in the future when they are made part of the Salesforce corporate group, to the extent such sharing of data is necessary to fulfill a request you have submitted via our websites or for customer support, marketing, technical operations and account management purposes. A list of companies currently within the Salesforce corporate group is provided as an exhibit to our Annual Report, available here. Further, due to the nature of our relationship with our social enterprise organization, Salesforce.org, we may share Personal Data between Salesforce and Salesforce.org for the business and/or organizational purposes of both or either; and
- If we are involved in a merger, reorganization, dissolution or other fundamental corporate change, or sell a website or business unit, or if all or a portion of our business, assets or stock are acquired by third party, with such third party. In accordance with applicable laws, we will use reasonable efforts to notify you of any transfer of Personal Data to an unaffiliated third party.
We may also share anonymous usage data with Salesforce’s service providers for the purpose of helping Salesforce in such analysis and improvements. Additionally, Salesforce may share such anonymous usage data on an aggregate basis in the normal course of operating our business; for example, we may share information publicly to show trends about the general use of our services.
Any Personal Data or other information you choose to submit in communities, forums, blogs or chat rooms on our websites may be read, collected and used by others who visit these forums, depending on your account settings.
For further information on the recipients of your Personal Data, please contact us by using the information in the “Contacting us” section, below.
7. International transfer of Personal Data
Your Personal Data may be collected, transferred to and stored by us in the United States and by our affiliates and third-parties disclosed in Section 6, above, that are based in other countries. The addresses of our offices where salesforce.com, inc. and its affiliates are located can be found here.
Therefore, your Personal Data may be processed outside your jurisdiction, and in countries that are not subject to an adequacy decision by the European Commission or your local legislature and/or regulator, and that may not provide for the same level of data protection as your jurisdiction, such as the EEA. We ensure that the recipient of your Personal Data offers an adequate level of protection, for instance by entering into the appropriate back-to-back agreements and, if required, standard contractual clauses for the transfer of data as approved by the European Commission (Art. 46 GDPR), or we will ask you for your prior consent to such international data transfers.
9. How long do we keep your Personal Data?
We may retain your Personal Data for a period of time consistent with the original purpose of collection (see the "Purposes for which we process Personal Data and the legal bases on which we rely" section, above). We determine the appropriate retention period for Personal Data on the basis of the amount, nature and sensitivity of your Personal Data processed, the potential risk of harm from unauthorized use or disclosure of your Personal Data and whether we can achieve the purposes of the processing through other means, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).
After expiry of the applicable retention periods, your Personal Data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further use of such data.
For further information on applicable data retention periods, please contact us by using the information in the “Contacting us” section, below.
10. Your rights relating to your Personal Data
10.1 Your rights
You have certain rights relating to your Personal Data, subject to local data protection laws. Depending on the applicable laws and, in particular, if you are located in the EEA, these rights may include:
- To access your Personal Data held by us (right to access);
- To rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete (right to rectification);
- To erase/delete your Personal Data, to the extent permitted by applicable data protection laws (right to erasure; right to be forgotten);
- To restrict our processing of your Personal Data, to the extent permitted by law (right to restriction of processing);
- To transfer your Personal Data to another controller, to the extent possible (right to data portability);
- To object to any processing of your Personal Data carried out on the basis of our legitimate interests (right to object). Where we process your Personal Data for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection;
- Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects ("Automated Decision-Making"). Automated Decision-Making currently does not take place on our websites or in our services; and
- To the extent we base the collection, processing and sharing of your Personal Data on your consent, to withdraw your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.
If you are a resident of California, under the age of 18 and have registered for an account with us, you may ask us to remove content or information that you have posted to our websites. Please note that your request does not ensure complete or comprehensive removal of the content or information, because, for example, some of your content may have been reposted by another visitor to our websites.
10.2 How to exercise your rights
To exercise your rights, please contact us by using the information in the “Contacting us” section, below. We try to respond to all legitimate requests within one month and will contact you if we need additional information from you in order to honor your request. Occasionally it may take us longer than a month, taking into account the complexity and number of requests we receive. If you are an employee of a Salesforce customer, we recommend you contact your company’s system administrator for assistance in correcting or updating your information.
Some registered users may update their user settings, profiles, organization settings and event registrations by logging into their accounts and editing their settings or profiles.
To update your billing information, discontinue your account and/or request return or deletion of your Personal Data and other information associated with your account, please contact us by using the information in the “Contacting us” section, below
10.3 Your rights relating to customer data
As described above, we may also process Personal Data submitted by or for a customer to our cloud products and services. To this end, if not stated otherwise in this Privacy Statement or in a separate disclosure, we process such Personal Data in the role of a mere processor on behalf of a customer (and/or its affiliates) who is the responsible controller of the Personal Data concerned (see the "Responsible Salesforce entity" section above). We are not responsible for and have no control over the privacy and data security practices of our customers, which may differ from those set forth in this Privacy Statement. If your data has been submitted to us by or on behalf a Salesforce customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with the applicable customer directly. Because we may only access a customer’s data upon instruction from that customer, if you wish to make your request directly to us, please provide to us the name of the Salesforce customer who submitted your data to us. We will refer your request to that customer, and will support them as needed in responding to your request within a reasonable timeframe.
10.4 Your preferences for email and SMS marketing communications
If we process your Personal Data for the purpose of sending you marketing communications, you may manage your receipt of marketing and non-transactional communications from Salesforce by clicking on the “unsubscribe” link located on the bottom of Salesforce marketing emails, by replying or texting ‘STOP’ if you receive Salesforce SMS communications, or by unsubscribing here. Please note that, notwithstanding the above, you will continue to receive marketing and non-transactional communications from MuleSoft unless you manage your receipt of such communications by clicking on the “unsubscribe” link located on the bottom of MuleSoft marketing emails, replying or texting ‘STOP’ to MuleSoft SMS communications, or unsubscribing here.
You may also turn off push notifications on Salesforce and MuleSoft apps on your device, or unsubscribe by contacting us using the information in the “Contacting us” section, below.
Please note that opting out of marketing communications does not opt you out of receiving important business communications related to your current relationship with us, such as communications about your subscriptions or event registrations, service announcements or security information.
10.5 Your preferences for telemarketing communications
If you want your phone number to be added to our internal Do-Not-Call telemarketing register, please contact us by using the information in the “Contacting us” section, below. Please include your first name, last name, company and the phone number you wish to add to our Do-Not-Call register.
Alternatively, you can always let us know during a telemarketing call that you do not want to be called again for marketing purposes.
11. How we secure your Personal Data
We take precautions including organizational, technical and physical measures to help safeguard against the accidental or unlawful destruction, loss, alteration and unauthorized disclosure of, or access to, the Personal Data we process or use.
While we follow generally accepted standards to protect Personal Data, no method of storage or transmission is 100% secure. You are solely responsible for protecting your password, limiting access to your devices and signing out of websites after your sessions. If you have any questions about the security of our websites, please contact us by using the information in the “Contacting us” section, below.
12. Changes to this Privacy Statement
We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements and other factors. If we do, we will update the “effective date” at the top of this Privacy Statement. If we make a material update, we may provide you with notice prior to the update taking effect, such as by posting a conspicuous notice on our website or by contacting you using the email address you provided.
We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.
13. Contacting us
To exercise your rights regarding your Personal Data, or if you have questions regarding this Privacy Statement or our privacy practices please fill out this form or mail us at:
Salesforce Data Protection Officer (Salesforce Privacy Team)
415 Mission St, 3rd Floor
San Francisco, CA 94105, USA
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in the EEA, you have the right to lodge a complaint with the competent supervisory authority.