- Why Abacus?
As set forth in Abacus’ Global Code of Conduct: "We respect the confidentiality and privacy of our clients, our people and others with whom we do business."
Abacus Information Technology, LLC d/b/a Abacus Group, LLC and GoVanguard NJ LLC (doing business as Gotham Security). (together "Abacus") complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Abacus has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Abacus has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Data Privacy Framework Policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. Abacus U.S. is subject to investigatory and enforcement powers of the U.S. Federal Trade Commission.
To learn more about the Data Privacy Framework (DPF) program, and to view our certification page, please visit https://www.dataprivacyframework.gov/.
We previously certified with the requirements of the EU-US Privacy Shield Framework in relation to our processing of personal data.
We collect and process personal information from certain individuals and for the purposes described in this Data Privacy Framework Policy. Personal information covered by this Data Privacy Framework Policy is collected and processed only as permitted by the Principles.
Notice to individuals regarding the personal information collected from them and how that information is used may be provided through this Data Privacy Framework Policy, other Abacus website notices, or other direct forms of communication with appropriate parties, such as contracts or agreements.
Consistent with the Principles, Abacus may transfer personal information to third parties, including transfers from one country to another. We will only disclose an individual’s non-public personal information to third parties under one or more of the following conditions:
Individuals whose personal information is covered by this Data Privacy Framework Policy have the right to access the personal information that Abacus maintains about them as specified in the Principles.
Individuals may contact us to limit the use and disclosure of their personal data. Individuals may also contact us to correct, amend or delete such personal information if it is inaccurate or has been processed in violation of the Principles. Requests for access, correction, amendment or deletion should be sent to: email@example.com.
Abacus will consider all such requests and provide our response within a reasonable period (and in any event within one month of your request unless we tell you we are entitled to a longer period under applicable law). Please note, however, that certain personal data may be exempt from such requests in certain circumstances, for example if we need to keep using the information to comply with our own legal obligations or to establish, exercise or defend legal claims.
Individuals have a right to ask us to restrict the way that we process their personal information in certain specific circumstances. As such they can choose to opt out of whether their personal information is (i) to be disclosed to a third party or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individual. Any such opt-out requests should be sent to firstname.lastname@example.org
Abacus takes appropriate measures to protect personal information in its possession to ensure a level of security appropriate to the risk of loss, misuse, unauthorized access, disclosure, alteration, and destruction. These measures take into account the nature of the personal information and the risks involved in its processing, as well as best practices in the industry for security and data protection.
Abacus collects and processes personal information only to the extent that it is compatible with the purposes for which it was collected or subsequently authorized by the data subject. Abacus does not retain personal information after it no longer serves the purposes for which it was collected or subsequently authorized. Abacus takes reasonable steps to ensure that personal information is accurate, complete, current, and reliable for its intended use.
In compliance with the Principles, Abacus commits to resolve Principles-related complaints about our collection and use of your personal information. EU, UK and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF should first contact Abacus at: email@example.com. Abacus has a policy of responding to individuals within forty-five (45) days of an inquiry or complaint.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Abacus commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and Swiss-U.S. DPF to the International Centre for Dispute Resolution/American Arbitration Association (ICDR/AAA) https://www.icdr.org/dpf, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://go.adr.org/dpf_irm.html for more information or to file a complaint. The services of the ICDR/AAA are provided at no cost to you.
If your complaint is not resolved by us or by the ICDR/AAA, you may, under certain conditions, have the option to invoke binding arbitration under the Principles. For further information, please see the Data Privacy Framework website (https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf)
Abacus will renew its EU-U.S. DPF and Swiss-U.S. DPF certifications annually, unless it subsequently determines that it no longer needs such certification or if it employs a different adequacy mechanism.
Prior to the re-certification, Abacus will conduct an in-house verification to ensure that its attestations and assertions about its treatment of Individual Customer and Personnel Personal Data are accurate and that the company has appropriately implemented these practices. Specifically, as part of the verification process, Abacus will undertake the following:
Abacus will prepare an internal verification statement on an annual basis.
Abacus may update this Policy at any time by publishing an updated version here. We will not update this Data Privacy Framework Policy in contravention to the Principles so long as we remain certified to the Data Privacy Framework.
View a PDF of our Data Privacy Framework Statement HERE.