EXPENSEONDEMAND GLOBAL PRIVACY POLICY

Last update: December 13th, 2023

At Expense On Demand Limited (“ExpenseOnDemand”, “we”, “us”, or “our” which include our group and affiliated companies), our most important asset is our relationship with our user community. We are committed to maintaining the confidentiality, integrity and security of information about our users and their organisations as per GDPR. This privacy policy (“Privacy Policy” or “Policy”) describes how we collect, use, disclose, share and secure the personal and company information you provide when you use our expense management, invoicing or bill processing software, through our mobile application (the “Application”) or visit the ExpenseOnDemand websites www.expenseondemand.com (the “Site” and, together with any related software, tools and services provided in connection with the Application or the Site, the “ExpenseOnDemand Service”).

It also describes your choices regarding the use, access and correction of your Personal Data (as defined in Section 3 of this Privacy Policy) and how to contact us if you have any further queries or complaints about our management of your personal information.

In this Privacy Policy, “you” and “your” refers to individual users of the ExpenseOnDemand Service, as well as to Members and Corporate Members. “Members,” “Corporate Members,” and other capitalized terms not defined in this privacy policy are defined in the ExpenseOnDemand Terms of Service.

We process your Personal Data as set out in the Privacy Policy which you should read.

You can contact EXPENSE ON DEMAND’s data protection officer by emailing or by post to DPO, EXPENSE ON DEMAND, FirstFloor, 3 Cumbrian House, 217 Marsh Wall, London, E14 9FJ, United Kingdom.

1. MEMBER ACKNOWLEDGMENT

By submitting or making available Personal Data (as defined below) through our Site, the ExpenseOnDemand Software or the ExpenseOnDemand Service, you confirm that you have read and acknowledged the terms of this Privacy Policy and you understand our practices around the collection, storage, use and disclosure of your Personal Data in accordance with this Privacy Policy.

2. A NOTE ABOUT CHILDREN

We do not intentionally gather Personal Data about individuals who are under the age of 18. If you become aware that we inadvertently hold or have access to Personal Data about anyone under 18, please let us know so we can delete it.

3. TYPES OF PERSONAL DATA WE COLLECT AND HOW IT IS COLLECTED

Personal information or“Personal Data”, means any information about an individual from which that person can be identified, or which when combined with other information which is in the possession of, or is likely to come into the possession of, ExpenseOnDemand could be used to identify that person. “Personal Data” also includes any information or opinion, whether true or not and whether recorded in material form or not, by which you may be reasonably identifiable. ExpenseOnDemand will not use your Personal Data except as set forth in this Privacy Policy and in the Terms of Service. We may collect (both directly and indirectly), use, store and transfer different kinds of personal data aboutyou. For specific details about how ExpenseOnDemand does this with cookies,identifiers and other tracking technologies please review the ExpenseOnDemand Cookie Policy below. The categories of Personal Data we collect, use, store and transfer have been grouped together as follows:

Registration Data
When you purchase or register for our Services or create an ExpenseOnDemand account, we collect directly from you (or for certain corporate accounts, from your employers) Personal Data, including your name, , billing and mailing address, email, professional title, company name, credit card, other payment information, and password and/or other sign-on mechanism. In addition, we (or our third-party credit card or payment processor on our behalf) will collect Personal Data including your credit card number or account information when you upgrade to a paid account.

Transaction Data that Allows Us to Provide our Services to You.
This includes current and historical financial information, such as bank account, payment card and other payment account, contact information (billing and mailing address, email address, and phone numbers), expense data, receipts, transaction data imported from third party financial service companies, and other details about reimbursements and payments to and from you and other details of products and services you have purchased from us. We collect your location-based information for the purpose of mileage tracking, providing location specific features, and to confirm your location status for specific events associated with the services. We may share your geo-location data with third parties for the sole purpose of providing these services. If you do not wish to allow us to collect and/or share your information in this manner please opt out by contacting us at support@expenseondemand.com.

Technical Data.
The ExpenseOnDemand Service (which may be hosted by a third-party service provider) collects Personal Data from you, such as browser type, your approximate geographic location of your mobile device or computer (from your Internet Protocol (IP) address), operating system and version, Internet Protocol (IP) address, domain name, information about your application, operating environment and hardware profiles and/or a date/time stamp for your visit. We may also use Identifiers (as defined below) and navigational data like Uniform Resource Locators (URL) to gather information regarding the date and time of your visit and/or access to the ExpenseOnDemand Service and your activity on the Site and the Application. Like most internet services, we automatically gather this Personal Data and store it in log files each time you visit the Site, use the Application or access your account on our network. We use mobile analytics software to allow us to better understand the functionality of our Mobile Software on your phone. This software may record information such as how often you use the Application, the events that occur within the Application, aggregated usage, performance data, and where the Application was downloaded from. We do not link the information we store within the analytics software to any Personal Data you submit within the mobile Application.

Information about your Interactions with ExpenseOnDemand.
We collect information about your interactions with ExpenseOnDemand, which may include your use of our products, services, websites or apps, including information collected using Cookies and other technologies (for further information on how we use Cookies and the information we collect using Cookies, see our cookies policy in Section 5 below). It may also include communications with us, such as if you contact our customer service centers, including recording calls and the contents of your device screen (by ExpenseOnDemand itself or using a third-party service) for quality and training purposes. This may also include data about your participation in promotions or programs. This may also include data about how you exercise rights or preferences regarding your data. We also retain information on your behalf, such as the Personal Data described above and any correspondence. If you provide us feedback or contact us via email, we will collect your name and email address, IP address, as well as any other content included in the email, in order to send you a reply, and any information that you submit to us, such as a resume. If we conduct a survey in which you participate, we may collect additional profile information. We may also collect Personal Data at other instances in the Site or Application user experience where we state that Personal Data is being collected.

Other Self-Reported Information.
You have the option to provide us with additional information about yourself and others through surveys, forms, features and applications. Where such information is not required by ExpenseOnDemand for the purposes of providing the services to you, you acknowledge that ExpenseOnDemand may store, use and disclose such Personal Data in accordance with this Privacy Policy.

Member-Generated Content.
Some of our Services allow you to create and post or upload content, such as data, text, software, audio, photographs, graphics, video, messages, or other materials that you create or provide to us or to other Members through either a public or private transmission. For example, Member-Generated Content includes any discussions, posts, or messages you send on our Forums, as well as messages you send using ExpenseOnDemand Chat. Our Site offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them, as well as by our third party service providers such as OpenAI, L.L.C., to ensure compliance with our Acceptable Use Policy and Content Standards through our Enforcement Policy.

Social Media Features and Widgets.
Our Site includes Social Media Features, such as the Facebook “Like” button and Widgets, (“Features”). These Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. They may also allow third party social media services to provide us information about you, including your name, email address, and other contact information. The information we receive is dependent upon your privacy settings with the third party social media service. Features are either hosted by a third party or hosted directly on our site. Your interactions with these Features are governed by the privacy statements of the third party companies providing them. You should always review and, if necessary, adjust your privacy settings on third party websites and services before linking or connecting them to our website or Service.

Contact List Data:
For users of the ExpenseOnDemand mobile app only, we will access the list of contacts stored within your mobile device when you engage with relevant features of the app. The access enables you to readily incorporate existing contact information in your use of the app. ExpenseOnDemand does not access your list of contacts for any other purposes.

Third Party Data:
We will collect your Personal Data from you unless it is unreasonable or impracticable to do so. However, we may collect, receive, and retain Personal Data about you from the following non-publicly accessible sources: (i) companies that distribute the ExpenseOnDemand Service by way of a co-branded or private-labeled website, (ii) companies that offer their products and/or services via the ExpenseOnDemand Service, (iii) companies that provide services (such as payment processing services) in connection with the ExpenseOnDemand Service,. Our Partner Companies may supply us with Personal Data, such as your name and email and mailing address, bank account, credit, or financial information or your login credentials for such Partner Company’s website or service, in order to help us establish the account or fulfil our obligations to you. We may also collect your Personal Data if necessary from public sources (such as LinkedIn, Corporate Subscribers Websites, Clearbit, Lexis Nexus). We may add this information to the information we have already collected from you via our Site or Application in order to perform and improve the ExpenseOnDemand Service. If you provide us Personal Data about others, or if others give us your information, we will only use that information for the specific reason for which it was provided to us.

We also collect, use, and share aggregated or de-identified data, such as statistical or demographic data. This information has either been de-identified or otherwise combined with that of other users and analysed or evaluated as a whole, such that no specific individual may be identified. We may use aggregated or de-identified data for purposes such as research and marketing purposes and may also share such data with any third parties, including advertisers, promotional partners, sponsors,event promoters, and/or others.

We do not collect any “Special Categories of Personal Data” about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation,political opinions, trade union membership, information about your health, and genetic and biometric data) nor do we collect any information about criminal convictions and offences.

4. THIRD PARTY LINKS

This Privacy Policy applies only to the use and disclosure of Personal Data that we collect while you use the ExpenseOnDemand Service. Our provision of a link to any other website or location is for your convenience and does not signify our endorsement of such other website orlocation or its contents. When you click on such a link, you will leave the ExpenseOnDemand Service and go to another site. During this process, a third party may collect Personal Data from you. We have no control over, do not review, do not endorse,and cannot be responsible for, these outside websites or their content. Please be aware that the terms of this Privacy Policy do not apply to these outside websites or content, or to any collection of data after you click on a link to a third party. If you submit Personal Data to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.

5. EXPENSEONDEMAND COOKIE POLICY AND USE OF TRACKING TECHNOLOGIES

When you interact with the Site or the Application, we try to make that experience simple and useful. We and our partners use industry standard identifiers, such as cookies or other similar technologies. We will generally refer to cookies, web beacons, flash cookies, and pixels collectively as “cookies”, “tracking technology” or “identifiers” in this policy. By using our Services, you are agreeing that we can use cookies and other tracking technologies described in this Cookie Policy.

A. What are cookies and how long are they stored? 

Cookies are small pieces of information which are issued to your computer or mobile device (as the case maybe) when you visit a website or access or use a mobile application and which store and sometimes track information about your use of the Site or Application(as the case may be). A number of cookies we use last only for the duration of your web or Application session and expire when you close your browser or exit the Application (known as “session cookies). Other cookies are used to remember you when you return to the Site or Application and will last for longer (known as persistent cookies). A persistent cookie lasts until you or your browser deletes the cookies or they expire. 

Cookies set by us are called“first party cookies”, while cookies set by parties other than ExpenseOnDemand are called “third party cookies”. The parties that set third party cookies can recognize your device, both when you use the Services and when you use other websites or mobile apps. You should check the third party’s website for more information about how they use cookies and other tracking technologies. Both first party and third party cookies can serve a number of different functions,such as analytics, marketing and advertising. 



B. What other similar tracking technologies does ExpenseOnDemand use?  

Web Beacons: In addition to cookies, web beacons may be set by us or third parties in respect of your use of the Site or Application. Web beacons are small image files within the content of the Site or Application for analytics purposes sowe or third parties can understand which parts of the Site or Application are visited and which functions of the Site or Application are used and whether particular content is of interest. 

Flash cookies: We may also use so-called “flash cookies”(also known as “Local Shared Objects” or “LSOs”) to collect and store information about your use of our Services.

Mobile Device Identifiers: We also use mobile device identifiers which perform a similar role, like the IDFA used by Apple devices and the UDID used by Android devices. 


C. How do we use cookies? 

We use cookies to provide ourSite, gather information about your usage patterns when you navigate the Sites in order to enhance your personalized experience, and to understand usage patterns to improve our Sites, products, and services. We also allow certain third parties to place cookies on our Site in order to collect information about your online activities on our Sites over time and across different websites you visit. This information is used to provide advertising tailored to your interests on websites you visit, also known as interest based advertising,and to analyze the effectiveness of such advertising. 

Usage information may be linked to your account in order to assist ExpenseOnDemand to provide services to your account, for example analysing data for the purposes of trouble shooting. ExpenseOnDemand will not sell or disclose usage data to any third party unless such usage data has been aggregated or de-identified. 

Cookies on our Sites are generally divided into the following categories:

Strictly necessary cookies. These are cookies that are required for the operation of our website or provide necessary functions relating to the services you request. They include, for example, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services. 

Analytical or performance cookies. These allow us to recognize and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example,by ensuring that users are finding what they are looking for easily. These cookies also allow us to collect statistical information about how you use the Site or App (including how long you spend on the Site or Application) and where you have come to the Site or Application from, so that we can improve the Site and learn which parts of the Site and which functions of the Application are most popular with users. 

Functionality cookies. These cookies enable helpful but non-essential website functions that improve your website experience. By recognising you when you return to our website, they may, for example, allow us to personalize our content for you, greet you by name, or remember your preferences (for example, your choice of language or region). This also enables us to customize elements of the promotional layout and/or content of the pages of the Site or Application We also use functional social media plugins, such as the Facebook “Like” button and Widgets, such as the “Share this” button or interactive mini-programs that run on our site. These Features may collect your IP address, which page you are visiting on our Site, and may set an Identifier to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Site. Your interactions with these Features are governed by the Privacy Policy of the company providing it.

Targeting cookies. These cookies enable different advertising related functions. They may allow us to record information about your visit to our website, such as pages visited, links followed, and videos viewed so we can make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.


D. Your Choices

Cookies

Most web and mobile device browsers automatically accept cookies but, if you prefer, you can change your browser to prevent thator to notify you each time a cookie is set. Here are links to information from some of the larger browsers about how you can control your browser cookies: Chrome, Firefox, Safari, Internet Explorer. Visit All AboutCookies.org to learn more cookies and how to block cookies using different types of browser or mobile device. Please note, however, that by blocking or deleting cookies used on the Site or Application, you may not be able to take full advantage of the ExpenseOnDemand Service. Please Read Google’s overview of privacy and safeguarding data

Behavioural Advertising

We may partner with a third party to either display advertising on our Site or Application or to manage our advertising on other sites. Our third-party partner may use technologies such as cookies to gather information about your activities on this website and other sites in order to provide you advertising based upon your browsing activities and interests. If you wish to opt -out of interest-based advertising click https://optout.networkadvertising.org/?c=1 or https://youradchoices.com/control (or if located in the European Union click Union click here). Please note you will continue to receive generic ads.

If you would like more information about cookies and targeted advertisements or to opt out of having this information used by companies that are part of the Network Advertising Initiative, please click here or the Digital Advertising Alliance, please click here.

Analytics

We and our vendors (including but not limited to Google Analytics) may use Identifiers and similar tracking technologies to monitor performance and usage on the site for internal analytics and performance monitoring. These Identifiers and similar tracking technologies are used to help the Site collect and store information regarding your visit, such as session state and authentication tokens. Users can control the use of cookies at the individual browser level but if you choose to disable cookies, it may limit your use of certain features or functions provided through the ExpenseOnDemand Service. To manage Flash cookies, please click here. 

To opt out of Google Analytics you can download a Browser Add-On.

The use of Identifiers by our vendors is not covered by our Privacy Policy. We do not have access or control over these cookies.

We use mobile analytics software to allow us to better understand the functionality of our Mobile Software ony our phone. This software may record information such as how often you use the Application, the events that occur within the Application, aggregated usage,performance data, and where the Application was downloaded from. We do not link the information we store within the analytics software to any personally identifiable information you submit within the mobile Application.

Do Not Track Statement 

Some browsers have a “do not track” feature that allows you to tell websites that you do not want to have your online activities tracked. At this time, due to a lack of industry standards, we do not respond to browser “do not track” signals. 



6. USE OF YOUR PERSONAL DATA

ExpenseOnDemand and our Partner Companies may use your Personal Data in the following ways:

a) to facilitate the creation of and secure your account on our network;

b) identify you as a Member in our system;

c) to administer and provide improved administration of the ExpenseOnDemand Service;

d) to improve the quality of experience when you interact with the ExpenseOnDemand Service, including staff training;

e) to send you a welcome email to verify ownership of the email address provided when your account was created;

f) to send you administrative email and/or chat notifications, such as security or support and maintenance advisories;

g) to collect fees and payments owing to us;

h) to respond to your inquiries related to employment opportunities or other requests and to resolve disputes;

i) to provide you with access to and information about customized features, new functionality, and partner integrations;

j) to determine your eligibility to use the various programs part of the ExpenseOnDemand Service;

k) to provide you with hardcopy or electronic newsletters, or surveys;

l) to operate our business, including to process payment transactions, manage and enforce contracts with you or with third parties, manage our corporate governance, compliance and auditing practices,and generate anonymized or aggregated data;

m) to send with your consent (or where a friend has referred you to us) upgrades and special offers related to the ExpenseOnDemand Service and for other marketing purposes of ExpenseOnDemand or our Partner Companies;

n) to prevent and identify fraud and other illegal activity including but not limited to making telephone calls to you,from time to time, as a part of secondary fraud protection or to solicit your feedback;

0) to verify your identity as part of compliance with requirements of Partner Companies or applicable regulations;

p) to resolve disputes and protect the rights of Members and third parties;

q) to respond to claims and legal process (such as subpoenas and court orders);

r) to monitor and enforce compliance with the applicable Terms of Service;

s) to prevent or stop any activity that may be illegal, unethical, or legally actionable;

t) to compare information provided by you for accuracy and verification with third parties;

u) to provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses and responding to consumer rights requests;

v) as otherwise described to you when collecting your personal information; directed by you; needed to comply with laws; and

w) to evaluate or conduct a merger, divestiture,restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy,liquidation, or similar proceeding, in which personal information held by us about our consumers is among the assets transferred.

From time to time, we may also use your Personal Data to send important notices to you, such as communications about purchases you have made, or changes to our terms and conditions or other policies. This information is important to your interactions with us, and you acknowledge that if you opt out of receiving these communications, where permitted by applicable law, ExpenseOnDemand reserves its right to discontinue its services to you.

If you provide feedback on the ExpenseOnDemand Service, we may use such feedback for any purpose. ExpenseOnDemand will collect and store any information contained in such communication and will treat the Personal Data in such communication in accordance with this Privacy Policy.

Any information, including Personal Data, which you elect to make publicly available on the ExpenseOnDemand Service will be available to other Members or the public. If you remove information that you have made public on the ExpenseOnDemand Service, copies may remain viewable in cached and archived pages of the ExpenseOnDemand Service, or if other Members have copied or saved that information. 

In some cases we collect information provided by our Corporate Members, and in such cases, we have no direct relationship with the individuals whose Personal Data we process. If you believe your Personal Data has been collected by us in such circumstances, and would no longer like to be contacted as an employee or customer of one of ourCorporate Members, please contact that Corporate Member directly in order to request your removal.  

We may send you push notifications from time-to-time in order to update you about any events or promotions that we may be running. If you no longer wish to receive these types of communications, you turn them off at the device level. To ensure you receive proper notifications, we will need to collect certain information about your device such as operating system and user identification information.


7. DISCLOSURE OF YOUR PERSONAL DATA

We may share your Personal Data with Partner Companies to provide technical support or to provide specific services, such as hosting of your applications, maintenance services, database management or payment processing for purchases, reimbursements, payroll, orother payments (including but not limited to Stripe or PayPal), and with your consent, to register you for participation in various programs. Partner Companies will have access to your Personal Data only to perform these services on our behalf and are obligated not to disclose or use it for any other purpose.

Any subsidiaries, joint ventures, or other companies under common control with us (collectively,“Related Entities”), may share some or all of your Personal Data, in which case we will require our Related Entities to honour this Privacy Policy and your Personal Data will only be used for the purposes set out in this Privacy Policy. 

ExpenseOnDemand may sell/divest/transfer the company (including any shares in the company), or any combination of its products, services, assets and/or businesses. Personal Data may be among the items sold or otherwise transferred in these types of transactions, you will be notified via email and/or a prominent notice on ourSite of any change in ownership of your Personal Data.

We may also sell, assignor otherwise transfer such information in the course of corporate divestitures,mergers, acquisitions, bankruptcies, dissolutions, reorganizations,liquidations, similar transactions or proceedings involving all or a portion of the company.

In certain situations, ExpenseOnDemand and its Partner Companies may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. ExpenseOnDemand may disclose Personal Data if it is necessary to (a) comply with relevant laws or to respond to subpoenas or warrants or lawful requests from government authorities served on ExpenseOnDemand;or (b) protect or defend the rights, reputation or property of ExpenseOnDemand or users of the ExpenseOnDemand Service.  We look for opportunities to be an advocate for you when law enforcement or other third parties subject to a legal process seek to encroach on your privacy.  If we receive requests from law enforcement or private parties seeking information, we are prepared to take a stand when appropriate. We have various tools at our disposal that we may elect to rely on to do so depending on the circumstances, for example: our legal team reviewing these requests to ensure that parties are following applicable laws and statutes; rejecting or challenging requests that have no legal basis or are unclear, overbroad, or otherwise inappropriate; construing legal process as narrowly as possible; encouraging parties to look else where for the information. We are prepared to ensure that requests have a legal basis. 

Except as otherwise stated in this policy and our Terms of Service, we do not sell, trade, share, or rent the Personal Data collected from the ExpenseOnDemand Service to third parties.

We may aggregate or de-identify information collected through the ExpenseOnDemand Service so that such information is no longer directly identifiable to an individual. We may use and share such aggregated or de-identified information solely for marketing purposes or distribution to third party research firms. 

Service Provider,Sub-Processors/Onward Transfer

ExpenseOnDemand may transfer Personal Data to companies that help us provide the ExpenseOnDemand Service and related programs. Transfers to subsequent third parties are covered by the provisions in this Policy regarding notice and choice and the service agreements with our Clients. 



8. CHOICE/OPT-OUT

ExpenseOnDemand offers you thec hoice of receiving different types of communication and information related to our company, products and services. You may subscribe to e-newsletters or other publications; you may also elect to receive marketing communications and other special offers from us via email. If at any time you would like to change your communication preferences, we provide unsubscribe links and an opt-out mechanism for your convenience where available. You may also access and manage your preferences from your account.


9. PERSONAL DATA CHANGES

If you believe that the Personal Data we hold about you may not be complete, accurate and up-to-date, you may change aspects of any of your Personal Data in your account by editing your profile within the registration portion of the Site. You may request deletion of your account information by us, but please note that we may be permitted or required (by law or otherwise) to keep this information and not delete or change it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). If you request deletion, subject to our rights to retain the Personal Data as set out in this Privacy Policy and the rights of any Corporate Member to retain the Personal Data as set forth below, we will respond to your request within 1 month. We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Access to Data Controlled by ourCorporate Members

You have the right to access your Personal Data subject to any exceptions which may apply in the jurisdiction in which you reside. If you have connected to a Corporate Policy and shared your Personal Data with the Corporate Member administering such Corporate Policy, you acknowledge that some Personal Data shared with a Corporate Member may not be able to be deleted as it pertains to their records. Upon request, we will provide you with information about whether any of your Personal Data is shared with a Corporate Member administering a connected Corporate Policy. 

Blog / Forum

Our Site offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them, as well as by our third party service providers such as OpenAI,L.L.C., to ensure compliance with our Acceptable Use Policy and Content Standards through our Enforcement Policy. To request removal of your Personal Data from our blog or community forum, contact us at support@expenseondemand.com. In some cases, we may not be able to remove your Personal Data, in which case we will let you know if we are unable to do so and why.


10. SECURITY OF YOUR APPLICATION AND PERSONAL DATA

ExpenseOnDemand is committed toprotecting the security of your Personal Data. We use a variety ofindustry-standard security technologies and procedures to help protect yourPersonal Data from unauthorized access, use, or disclosure. When you entersensitive information (such as a credit card number) on our order forms, weencrypt the transmission of that information using secure socket layertechnology (SSL). We also require you to enter a password and/or other sign-onmechanism to access your account information. Please do not disclose youraccount password and/or other sign-on mechanism to unauthorized people. Despitethese measures, you should know that ExpenseOnDemand cannot fully eliminatesecurity risks associated with Personal Data. If you have any questions aboutthe security of your Personal Data, you can contact us at support@ExpenseOnDemand.com.



11. CONTACT INFORMATION

If you have any comments,questions or complaints about this Privacy Policy or if you feel that we have breached our obligations in the handling, use or disclosure of your Personal Data, feel free to email comments or questions to us at support@expenseondemand.com 

If you have general enquiry type questions, you can choose to use a pseudonym. However, if you require information which is specific to your circumstances then it may not be possible for you to deal with us by pseudonym. You acknowledge and agree that when contacting ExpenseOnDemand, whether by email, chat, or otherwise, you will not include any personally identifiable information in your communications, andthat if such information is included in your communications with ExpenseOnDemand,ExpenseOnDemand will have no legal obligation or liability with regard to such information.



12. CHANGES TO THIS PRIVACY POLICY

If ExpenseOnDemand makes changes to this Privacy Policy, these changes will be posted on the Site and Application in a timely manner. ExpenseOnDemand reserves the right to modify this Privacy Policy at any time, so please review it frequently. You acknowledge that the updated policy will apply to the collection, storage, use or disclosure of Personal Data from the date of publication and it is your responsibility to check the Site and Application regularly for updates. You can determine when this Privacy Policy was last revised by referring to the “Last Updated” legendat the top of this page. Any changes to this Privacy Policy will become effective upon our posting of the revised Privacy Policy on the Site and Application. If we make any material changes, we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on this Site prior to the change becoming effective. Use of the ExpenseOnDemand Service following such changes constitutes your acceptance of the revised Privacy Policy then in effect. We encourage you to periodically review this page for the latest information on our privacy practices.

13. OVERSEAS DISCLOSURE

ExpenseOnDemand is based in the United Kingdom, and, unless we expressly agree otherwise, we may host,transfer, and process data, including Personal Data, in the United Kingdom and in other countries through ExpenseOnDemand and third parties that we use to operate and manage the Service. These countries may have data protection laws that are different from those of your country of residence. When you access or use the Service, or otherwise provide information to us, you understand and acknowledge that the processing and transfer of information in and to the United Kingdom and other countries which may have different privacy laws from your or their country of residence. ExpenseOnDemand takes appropriate measures to ensure such transfers are in compliance with applicable laws and our Terms of Service.



14. DATA RETENTION

Other than in aggregated orde-identified form as permitted under the ExpenseOnDemand Terms of Service, andexcept as required by applicable law, we will delete or otherwise destroy yourPersonal Data as soon as practicably possible following your termination or cancellation of your use of the ExpenseOnDemand Service.

ExpenseOnDemand will retain data licensed to our Corporate Members as set forth in the ExpenseOnDemand Terms of Service for as long as needed to provide services to our Corporate Member. ExpenseOnDemand will retain and use this information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. We ensure thatPersonal Data we dispose of is de-identified or destroyed in a secure fashion. 

The Corporate Member with which you are affiliated with may have specific policies concerning the retention of data including Member Generated Content. Please consult the entity ororganisation with which you are affiliated with for additional detail about its specific data retention policies. 

III. Legal Basis for Processing

We have listed the use of your Personal Data by us in Section 6 above. The legal grounds on which we process the Personal Data for those uses includes; if you consent to the processing, to satisfy our legal obligations, if it is necessary to carry out our obligations arising from any contracts we entered with you or to take steps at your request prior to entering into a contract with you, or for our legitimate interests to providing our services to our customers and the effective management of ExpenseOnDemand and to protect our property, rights or safety of ExpenseOnDemand, our customers or others. If data processing is based on consent, note that you have the right to withdraw your consent at any time, but that the withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal.

V. Your Privacy Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data, such as:

a) Access: The right to request access to the Personal Data that ExpenseOnDemand has about you;

b) Rectification: The right to rectify or correct any Personal Data that is inaccurate or incomplete;

c) Portability: The right to request a copy of your Personal Data in electronic format so that you can transmit the data to third parties, or to request that ExpenseOnDemand directly transfer your Personal Data to one more third parties;

d) Objection: The right to object to the processing of your Personal Data for certain purposes;

e) Erasure: The right to erasure of your Personal Data when it is no longer needed for the purposes for which you provided it, as well as the right to restriction of processing of your Personal Data to certain limited purposes where erasure is not possible.

f) Restriction: You have the right to request that we restrict our processing of your Personal Data where you believe such data to be inaccurate; our processing is unlawful; or we no longer need to process such data for a particular purpose, but where we are not able to delete the data due to a legal or other obligation or because you do not want us to delete it. 

g) Consent: the right to withdraw your consent to the processing of your Personal Data at any time. Please note, however, that we may still be entitled to process your Personal Data if we have another legitimate reason for doing so. For example, we may need to retain Personal Data to comply with a legal obligation

The rights described above maynot be absolute and are limited by applicable laws.

You can exercise your privacy rights by contacting us via email at: support@ExpenseOnDemand.com. We will handle your request under applicable law. When you make a request, we may verify your identity to protect your privacy and security.

Right to Request Deletion

You have the right to request that we delete your personal information. Under certain circumstances ExpenseOnDemand may be unable or otherwise not required to delete your personal information,for example, to comply with legal obligations, or to complete a business transaction that you have requested. 

Exercising Access, Data Portability, and Deletion Rights

To exercise the access, data portability, and deletion rights described above, please submit a consumer request to us via email at: support@ExpenseOnDemand.com with the relevant subject line or via webform. We will handle your request under applicable law. When you make a request, we may verify your identity to protect your privacy and security. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:

a) Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative.

b) Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

Making a verifiable consumer request does not require you to create an account with us. However, we do consider requests made through your password protected or otherwise authenticated account sufficiently verified when the request relates toPersonal Information associated with that specific account. If you request access to or deletion of your personal information and do not sign in to an account with us, we require you to provide the following information: name,email address, phone number, and postal address. In addition, if you do not have an account and you ask us to provide you with specific pieces of personal information, we reserve the option to require you to sign a declaration under penalty of perjury that you are the consumer whose personal information is the subject of the request.

Response Information

Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable.



16. QUERIES, CONCERNS, AND COMPLAINTS

If you have any queries, concerns or complaints about the manner in which we have collected, stored, used or disclosed your personal information, please contact the Data Protection Officer at support@ExpenseOnDemand.com. We will treat your complaint confidentially and, after investigating your complaint, discuss the ways in which we can remedy the situation. We will ensure that we respond to your complaint within a reasonable time (and in any event within the time required by applicable law).

If your inquiries or complaints regarding our Privacy Policy or use of data that have not been resolved to your satisfaction within 30 days via the means set forth herein, please contact:

  • The Information Commissioner’s Office in the United Kingdom

We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy or our privacy practices, please contact our DPO at support@ExpenseOnDemand.com.