Privacy Policy

Effective Date: August 30, 2023

1. ABOUT

VeryGoodGraphics LTD and its affiliates ("VGG," "we," "us," and "our") are committed to making design accessible to all. This Privacy Policy explains how we collect, use, and share your personal information, as well as how you can exercise your privacy rights. Any capitalized terms not defined in this Privacy Policy can be found in our Terms and conditions.

2. SCOPE

This Privacy Policy applies to the personal information processed by us, including on our websites (e.g., verygoodgraphics.com and any other websites that we own or operate), our mobile applications, our application program interfaces, our design tool services, and our related online and offline offerings (collectively referred to as the "Services").

Please note that this Privacy Policy does not apply to any third-party websites, services, or applications, even if they are accessible through our Services. Additionally, separate privacy notices, available upon request if applicable to you, govern the processing of personal information related to our current employees and contractors.

3. PERSONAL INFORMATION WE COLLECT

The personal information we collect varies depending on how you interact with our Services. Here are the categories of personal information we may collect:

  1. Account Information: When you create a VGG account, we collect the personal information you provide, such as your name, email address, personal website, and profile picture. If you enable phone-based two-factor authentication, we will also collect your phone number.
  2. Communication Information: We collect personal information such as your email address, phone number, mailing address, and marketing preferences when you request information about the Services, sign up for our newsletter, or communicate with us in any other way.
  3. Candidate Information: If we post job openings or opportunities on the Services and you respond to them or provide us with your candidacy information, we collect and process the information you provide.
  4. Service Use Information: We collect information you provide about the Services to fulfill the purpose of providing the Services to you. This may include personal information related to your interactions with other users.
  5. Customer Service Information (including Training and Quality Assurance): When you contact VGG's sales, customer service, or support personnel, we collect the information you provide during the interaction. We may also record telephone calls or video conferences between you and our representatives for training or quality assurance purposes.
  6. Student Account Information: If you qualify for Educational Use, we may collect information about your school and curriculum, such as your school name, school mailing address, school website, and proof of registration. Please note that the Services are only intended for users aged 13 and above, as specified in our Terms and conditions.
  7. Sweepstakes, Contests, Surveys, and Events Information: If you participate in sweepstakes, contests, surveys, conferences, or other events hosted, run, or sponsored by us, we may collect information you provide or receive information about you. This may include your name, email address, mailing address, demographic data, and any event-specific information.

Please review our Privacy Policy for more details on how we handle and safeguard your personal information.

3.1 Information Collected Automatically (Technical information)

In addition to the personal information you provide, we also collect certain information automatically when you use the Services. This technical information includes:

With your permission, we may also collect information about the fonts installed on your operating system. This information helps us provide services to you.

3.2 Cookies, Pixel Tags/Web Beacons, and Analytics Information

In addition to the automatic data collection mentioned earlier, we and our partners may use various technologies, including cookies, pixel tags/web beacons, and other similar technologies, to collect information when you interact with our Services. These technologies allow us to record certain information and enhance your experience. Here's more information about each of these technologies:

  1. Cookies: Cookies are small text files that are placed in your device's browser to store preferences and other information. They help us remember your settings and provide a personalized experience. You have control over the collection of data through cookies, and you can manage your preferences as described in the "Your Choices" section below.
  2. Pixel Tags/Web Beacons: Pixel tags or web beacons are small pieces of code embedded in the Services. They help us track user engagement and gather information about how you interact with the Services. For example, they can tell us if you visited a specific web page or clicked on an advertisement. We may also use web beacons in emails to track open rates and user actions.

These technologies enable us to understand user behavior, improve our Services, and deliver targeted advertisements. However, we handle this information in accordance with our Privacy Policy and applicable laws.

3.3 Information from Other Sources

In certain cases, we may receive information about you from other sources. This includes:

  1. VGG Customers: If you use our Services on behalf of or in collaboration with an organization (such as your employer), that organization may provide us with information about you to set up and manage your account.
  2. Third-Party Services and Organizations: If you access our Services through a third-party service, we may collect information about you from that service, provided that you have made such information available through your privacy settings.

We handle this information in accordance with our Privacy Policy and applicable data protection laws.

Please note that you have control over the information shared with us from other sources, and you can manage your privacy settings accordingly.

We use your personal information for various business purposes, and we rely on different legal bases for processing your data. Here are the ways we use your information:

4.1 Providing and managing the Services or information requested

Legal Basis:

Please note that for Candidate Information, the legal basis may vary and specific provisions may apply.

If you have provided your consent for a specific processing activity, you have the right to withdraw your consent at any time. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. To exercise your rights or for more information, please refer to the "Contact Us" section of our Privacy Policy.

4.2 Communicating with you about your account, activities on our Services, and changes to our Privacy Policy or terms and conditions

Processing your Account Information, Communication Information, Service Use Information, Student Account Information, Sweepstakes, Contests, Surveys and Events Information, and and customer service information.

Legal Basis:

4.3 Administering and protecting our business and Services

Troubleshooting, data analysis, testing, system maintenance, support, reporting, internal quality control, safety, and hosting of data.

Processing your Account Information, Communication Information, Technical Information, Service Use Information, Student Account Information, and Customer Service Information.

Legal Basis:

4.4 Using data analytics to improve our website, products/Services, marketing, customer relationships, and experiences

Processing your Technical Information, Service Use Information, and Customer Service Information.

Legal Basis:

4.5 Enabling you to participate in a prize draw, competition, or complete a survey

Processing your Sweepstakes, Contests, Surveys, and Events Information and Communication Information.

Legal Basis:

4.6 Carrying out surveys for user research and analyzing your feedback

Processing your Surveys and Events Information, Account Information, Student Account Information, Communication Information, and Use of Services Information.

Legal Basis:

4.7 Contacting customers and prospective customers about products, services, developments, and events we think may be of interest to you

Processing your Account Information, Student Account Information, and Communication Information.

Legal Basis:

4.8 Delivering relevant content and advertisements to you and measuring or understanding the effectiveness of the advertising we serve to you

Processing your Account Information, Student Account Information, Communication Information, Service Use Information, and Technical Information.

Legal Basis:

4.9 Collecting information through the device-based settings which you have enabled, and cross-device tracking

Processing User Content, including media that you choose to share.

Legal Basis:

This may include any personal data we process about you.

Legal Basis:

4.11 Recruiting and hiring, including considering your candidacy for employment

This includes the processing of Candidate Information and Communication Information.

Legal Basis:

4.12 De-identifying data and creating aggregated information

This could include any personal data we process about you.

Legal Basis:

5. DISCLOSING YOUR INFORMATION TO THIRD PARTIES

We may share the personal information we collect with the following categories of third parties:

Other Users of VGG's Services: When using VGG's Services to collaborate or interact with others, certain information about you may be shared with your collaborators. This includes content that you create, which may contain information about you, and can be seen, shared, edited, copied, and downloaded by others based on the settings you or your administrator (if applicable) have selected.

The collaboration features of the Services may also display some or all of your profile information to other users when you share or interact with specific content. For example, when you comment on content, your profile picture and name may be displayed next to your comment so that other users know who made it. Similarly, when you join a team, your name, profile picture, and contact information may be displayed in a list for other team members to find and interact with you.

It's important to note that while VGG requires all users to comply with its acceptable use policy, VGG is not responsible for the privacy practices of users who receive information about you through the Services.

The Public: When you or others collaborate on content using VGG's Services, it is possible to make that content publicly available. In such cases, any information about you that is included in the content will also become publicly available and may be indexed by search engines. You have the ability to check the privacy settings of each piece of content to determine whether it is public or private.

Additionally, when you post content on VGG's Community, certain information about you will be publicly shared. This includes your picture, name, user handle, and X(Twitter) (or other social networking site) handle, if you have provided us with this information.

Service Providers: VGG may share the personal information it collects about you with its service providers. These service providers are entrusted with your personal information for various purposes, including:

  1. Provision of the Services: Service providers that assist in delivering the Services you use.
  2. Provision of Information, Products, and Other Services: Service providers that help provide the information, products, or other services you have requested.
  3. Marketing and Advertising: Service providers involved in marketing and advertising activities.
  4. Payment and Transaction Processing: Service providers that assist in processing payments and transactions.
  5. Customer Service Activities: Service providers that support customer service activities.
  6. IT and Related Services: Service providers that provide IT and related services.

Please note that specific third-party service providers mentioned, such as algolia have their own Privacy Policies that govern their use of your personal information.

Your Organization and Administrator: If you access the Services on behalf of an organization or have your account paid for by another party, VGG may share your information with that organization or paying party upon their request. This sharing of information may grant the organization certain rights over your information. For example, the organization may request enhanced security controls for your account or link your VGG account with your organization's account to facilitate collaboration.

If you are an administrator of a team, organization, or other account within the Services, VGG may share your contact information with current or past users related to you. This sharing is done to facilitate Service-related requests.

It's important to note that your information may also be subject to your organization's privacy policy, and VGG is not responsible for the privacy or security practices of its customers.

Third-Party Platforms and Services: We may share your personal information with third-party platforms and services if you have expressly consented or requested us to do so. We are not responsible for the practices or conduct of these third-party services.

Advertising Partners: We work with third-party advertising partners who may use tracking tools to collect information about your activities and device when you use our Services. This information includes your IP address, cookie identifiers, the pages you visit, your location, and the time of day. These advertising partners use this information, along with similar data collected from other websites, to deliver targeted advertisements to you when you visit third-party services within their advertising networks. This is known as "interest-based advertising" or "personalized advertising."

If you do not wish to share your personal information with these third-party advertising partners, you can follow the instructions provided under the "Your Choices" section to opt out.

Disclosures to Protect Us or Others: We may access, preserve, and disclose information associated with you to law enforcement bodies, government agencies, courts, or other third parties when we believe it is required or appropriate to do so. This includes situations where we need to comply with law enforcement or national security requests, respond to legal process such as court orders or subpoenas, protect your, our, or others' rights, property, or safety, enforce our policies and contracts, collect amounts owed, prevent financial loss, or in connection with an investigation or prosecution of suspected or actual illegal activity. We may also disclose information if we believe, in good faith, that it is necessary or advisable to do so.

Disclosure in the Event of Merger, Sale, or Other Asset Transfer: In the event of a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, we may sell or transfer your information as part of the transaction. This will be done in accordance with our legitimate interests in administering our business and as permitted by law and/or contract.

Please note that the privacy practices of third parties and organizations receiving your information are beyond our control, and you should review their privacy policies for more information.

6. INTERNATIONAL DATA TRANSFERS

We may transfer, process, and store your information anywhere in the world, including countries with data protection laws that differ from those in your own country. We take steps to protect your information in accordance with applicable laws.

If we transfer your personal information to countries or territories outside the European Economic Area (EEA) and the UK that have been recognized as providing an adequate level of protection, we rely on the relevant adequacy decisions from the European Commission and adequacy regulations from the UK Secretary of State.

In cases where the transfer is not covered by an adequacy decision or regulations, we have implemented appropriate safeguards to ensure that your personal information is protected in accordance with this Privacy Policy. This includes using the European Commission's Standard Contractual Clauses or the UK GDPR's Standard Contractual Clauses adopted pursuant to or permitted under Article 46.

If you would like to request a copy of our Standard Contractual Clauses or obtain further details about the safeguards we have in place with our third-party service providers and partners, please contact us.

7. E.U. – U.S. PRIVACY SHIELD AND SWISS – U.S. PRIVACY SHIELD

VGG relies on Standard Contractual Clauses for the transfer of personal data. Additionally, VGG complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as outlined by the U.S. Department of Commerce for the transfer of personal information from the European Union and Switzerland to the United States.

VGG has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. In case of any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles take precedence. To learn more about the Privacy Shield Framework and view our certification, please visit the U.S. Department of Commerce's Privacy Shield List.

VGG is responsible for the onward transfer of personal information to our agents under the Privacy Shield Framework. As for personal information received or transferred under the Privacy Shield Framework, VGG is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission.

If you have any questions, concerns, or complaints regarding our Privacy Shield certification or our collection and use of your personal information, please contact us using the information provided below.

VGG has also committed to referring unresolved complaints related to personal information to the JAMS Privacy Shield Dispute Resolution Program, an independent dispute resolution provider located in the United States. This service is available free of charge. For more information or to submit a complaint, you can visit the following website: https://www.jamsadr.com/eu-us-privacy-shield.

Under certain conditions described on the Privacy Shield website, you may have the right to invoke binding arbitration if other dispute resolution options do not adequately address your concerns.

8. YOUR CHOICES

You have the right to opt out of certain uses of your personal information. Here are the options available to you:

Email: If you receive unwanted marketing emails from us, you can use the unsubscribe link at the bottom of the email to opt out of future marketing emails. However, transaction-related emails regarding products or services you have requested will still be sent to you. Certain non-promotional communications regarding us and our services cannot be opted out of (e.g., communications about the services or updates to our Terms and conditions or Privacy Policy).

Mobile Devices: If you receive push notifications through our mobile application, you can opt out of receiving them by changing the settings on your mobile device.

Cookies and Interest-Based Advertising: You can decide whether to accept or reject cookies. If you're in the European Union, you can change your cookie preferences through our cookie consent tool, accessible by clicking "cookie settings" in the footer of our website. You can also adjust your browser or device settings to stop or restrict the placement of technologies (cookies) or remove them. Please note that cookie-based opt-outs may not be effective on mobile applications, but you can opt out of personalized advertisements on some mobile applications by following specific instructions for Android and iOS.

Opting out of targeted ads: The online advertising industry provides websites where you can opt out of receiving targeted ads from participating data partners and advertising partners. You can visit websites such as www.networkadvertising.org/managing/opt_out.asp, http://www.youronlinechoices.eu/, https://youradchoices.ca/choices/, and www.aboutads.info/choices/ to access these options and learn more about targeted advertising, consumer choice, and privacy. Please note that you need to separately opt out on each browser and device.

"Do Not Track": We do not respond to Do Not Track signals or similar mechanisms transmitted by web browsers.

9. YOUR PRIVACY RIGHTS

In accordance with applicable law, you may have the following rights:

  1. Access: You can request access to your personal information, including confirmation of whether we are processing it, obtaining a copy of your personal information, and receiving an electronic copy of the personal information you provided or requesting its transfer to another company (data portability).
  2. Correction: If your personal information is inaccurate or incomplete, you can request its correction. We may provide self-service tools for you to update your personal information.
  3. Deletion: You can request the deletion of your personal information.
  4. Restriction or Objection: You can request the restriction of our processing of your personal information or object to the processing of your personal information.
  5. Withdrawal of Consent: You can withdraw your consent to our processing of your personal information.
  6. Opt-out of Marketing Communications: You have the right to opt out of receiving marketing communications. Please refer to the previous section for more information on how to do this.

If you would like to exercise any of these rights, please contact us using the information provided below. We will process your requests in accordance with applicable laws and may need to verify your identity to protect your privacy.

Please note that if you use our services on behalf of an organization (such as your employer), the organization may be responsible for handling individual rights requests.

10. DATA RETENTION

We retain the personal information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purposes for which it was collected. This includes providing our Services, resolving disputes, establishing legal defenses, conducting audits, pursuing legitimate business purposes, enforcing our agreements, and complying with applicable laws.

The specific retention periods depend on the nature of the information, the purpose for which it is collected and processed, and any legal requirements. Once we no longer have a legitimate business need or legal basis to process your personal information, we will either delete or anonymize it. In cases where deletion is not immediately possible (such as when personal information is stored in backup archives), we will securely store your personal information and isolate it from further processing until deletion becomes feasible.

You have the right to request the deletion of your personal information at any time, as explained in the "Your Privacy Rights" section above. However, please note that deleting your personal information will require you to delete your account with us, as we need your personal data to maintain your account.

11. SECURITY OF YOUR INFORMATION

We prioritize the security of your information and take steps to ensure that it is treated securely and in accordance with this Privacy Policy. We implement appropriate technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction.

In the event of a security breach involving our systems, where we have become aware of unauthorized access to your personal information, we will make reasonable efforts to notify you electronically. This may include posting a notice on our Services, sending a notification by mail, or sending an email to you. We will promptly take appropriate measures to mitigate any potential harm and comply with applicable laws and regulations regarding data breach notifications.

We may also communicate with you electronically regarding security, privacy, and administrative issues related to your use of our Services. It is important that you maintain the security of your account and promptly inform us if you become aware of any unauthorized access or use of your account.

Please note that while we strive to protect your personal information, no method of transmission over the internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for any actions taken under your account.

12. THIRD-PARTY WEBSITES/APPLICATIONS

Our Services may include links to third-party websites/applications, and third-party websites/applications may also refer or link to our Services. Please note that these third-party services are not under our control, and we do not have responsibility for their privacy practices or the content they provide.

We encourage our users to carefully review the privacy policies of each website or application they interact with. This will help you understand how your information may be collected, used, and shared by these third parties. Visiting and interacting with these third-party websites/applications is at your own risk.

It's important to note that our inclusion of links to third-party websites/applications does not imply endorsement, approval, or responsibility for their privacy practices or the content they provide.

13. CHILDREN’S INFORMATION

Our Services are not intended for children under the age of 13 (or other age as required by local law), and we do not knowingly collect personal information from children unless under limited circumstances. If you become aware that your child has provided us with personal information without your consent, please contact us using the information provided below. If we learn that we have collected personal information from a child in violation of applicable law, we will promptly delete the information and terminate the child's account. In some cases, students in the United States under the age of thirteen may use our Services under an agreement with their educational institution. For more details on how we handle children's personal information, please refer to our Supplemental Privacy Policy for Children (attached as Exhibit A).

14. SUPERVISORY AUTHORITY

If you are located in the European Economic Area or the UK and believe that our processing of your personal information violates applicable law, you have the right to lodge a complaint with a supervisory authority.

15. CHANGES TO OUR PRIVACY POLICY

We reserve the right to revise this Privacy Policy at our discretion. If there are any significant changes to the policy, we will notify you in accordance with the applicable law.

Exhibit A:Supplemental Privacy Policy for Children

This Supplemental Privacy Policy for Children specifically addresses VGG's collection, use, and disclosure of personal information from children under the age of thirteen who are students of VGG's educational institution customers in the United States. It provides information to parents, guardians, schools, and school districts regarding the types of personal information collected, how it is used, disclosure practices, and how Responsible Parents can request access, modification, and deletion of their children's personal information. When VGG provides services to students at a school or school district, the consent of the school and/or school district is relied upon to collect, use, and disclose children's personal information in accordance with this Supplemental Privacy Policy for Children. In the event of any conflict between this Supplemental Privacy Policy for Children and the Privacy Policy, this Supplemental Privacy Policy for Children takes precedence.

Personal Information VGG Collects from Children

VGG collects personal information from children in connection with the creation or management of their accounts and when they use the Services. The personal information collected during account creation or administration may include the child's first and last name, email address, IP address, photograph (if uploaded for their profile), phone number (if 2FA is enabled), job title, and educational records or details provided by the school or school district. If a child communicates with VGG for support or other purposes, additional personal information may be collected.

When children use the Services, VGG may automatically collect certain personal information, such as their IP address, user settings, cookie identifiers, mobile advertising identifiers, browser or device information, and internet service provider. VGG may also collect personal information about the child's use of the Services, including analytics, content generated using the Services, details about files created, pages visited, links clicked, types of content interacted with, frequency and duration of activities, and other usage information.

How VGG Uses Children’s Personal Information

VGG uses the personal information collected from children solely for the purpose of providing Services. This may include facilitating account creation and administration, delivering the requested services, providing customer support, and ensuring the proper functioning and optimization of the Services. VGG does not use children's personal information for any other purposes unrelated to the provision of the Services.

VGG’s Practices for Disclosing Children’s Personal Information

VGG may disclose a Child's personal information in the following circumstances:

  1. Public Availability: If a Child or others collaborating on content make it publicly available, the information, including any personal information about the Child, can be accessed by the general public and indexed by search engines. The Child can check the privacy settings of their content to determine its public or private status.
  2. Sharing with Other Users: VGG may disclose a Child's personal information to other users of the Services with whom the Child chooses to share or interact.
  3. Disclosure to Teacher, School, and/or School District: VGG may share a Child's personal information with the teacher, school, and/or school district on whose behalf the Child is using the Services.
  4. Service Providers: VGG may disclose a Child's personal information to third-party service providers that assist in providing the Services.
  5. Legal Obligations: VGG may disclose a Child's personal information if required to do so by law, legal process, a court order, a subpoena, or government or regulatory request.
  6. Protection of Rights and Safety: VGG may disclose a Child's personal information if it believes that such disclosure is necessary or appropriate to protect the rights, property, or safety of VGG, its customers, or others. This includes protecting the safety of a Child, ensuring the security of the Services, and taking precautions against liability.
  7. Law Enforcement and Public Safety: VGG may disclose a Child's personal information to law enforcement agencies or in connection with an investigation related to public safety.
  8. Business Transfers: In the event of a merger, divestiture, restructuring, reorganization, dissolution, or sale of VGG's assets, including in bankruptcy or similar proceedings, VGG may transfer the personal information collected from Children to the buyer or successor.

It's important to note that VGG takes measures to safeguard Children's personal information and only discloses it when necessary and permitted by law.

Parental Choices and Controls

A Responsible Parent has the following choices and controls over their Child's personal information:

  1. Review: A Responsible Parent can use the Services to review the personal information collected from their Child.
  2. Correction or Deletion: A Responsible Parent can request VGG to correct or delete their Child's personal information if it is inaccurate or no longer necessary. It's important to note that requesting deletion of records may result in the termination of the Child's account and/or access to the Services.
  3. Refusal to Permit Further Collection or Use: A Responsible Parent has the right to refuse further collection or use of their Child's personal information by VGG.

To request changes or deletion of Children's personal information, a Responsible Parent can contact VGG by sending an email to bd@verygoodgraphics.com . VGG may require the Responsible Parent to take certain steps or provide additional information to verify their identity before fulfilling the request.

It's essential for Responsible Parents to communicate directly with VGG regarding their Child's personal information and exercise control over its collection and use.