1. Introduction
1.1. About This Privacy Policy. Text, Inc. and its Affiliates (“Text”, “we”, “us”, or “our”) respect your privacy and are committed to protecting information we process about you. This Privacy Policy applies to the processing of information, including Personal Data, by Text in connection with the Engagements described in this Privacy Policy. It describes the categories of information we process, the purposes for which we process it, when we disclose it, the rights available to individuals under applicable law, and the safeguards we apply to protect it.
Please note: It is vital to read and understand our Privacy Policy. By engaging in any form of communication with Text, you acknowledge that you have read and understood this Privacy Policy. The summaries below are provided for convenience only and do not modify or replace the provisions of this Privacy Policy.
Legal stuff made easy
This Privacy Policy explains how Text handles information in connection with your interactions with us, including what information we process, why we process it, when we disclose it, what rights may be available to you, and how we protect it. Depending on the circumstances, Text may act as a Data Controller or a Data Processor.
1.2. Scope. Depending on the nature of the applicable Engagement and the purposes for which Personal Data is processed, Text may act either as a Data Controller or a Data Processor. Accordingly, certain provisions of this Privacy Policy apply only where Text acts as a Controller, while others apply where Text acts as a Data Processor. Where relevant, this Privacy Policy identifies the applicable role. This Privacy Policy does not govern the privacy practices of our Clients or other third parties, including in connection with products, services, websites, applications, or other offerings provided by Clients to their End-Users. Such processing remains subject to the applicable Client’s own privacy notices and policies. Where Text processes Personal Data on behalf of a Client, the Client remains responsible for determining the purposes and legal bases for processing of Personal Data, providing any notices required by applicable law, obtaining and maintaining any required consents, permissions, or other lawful basis and communication preferences, withdrawals of consent, or opt-out requests, where applicable, and otherwise ensuring that its its collection and use of Personal Data through the Services complies with applicable privacy laws and the Agreement. Requests relating to Client Personal Data should generally be directed to the relevant Client, although Text will assist the Client in responding to such requests where required by applicable law and the applicable Agreement, including the DPA. Nothing in this Privacy Policy limits or modifies the respective obligations of Text or the Client under the applicable Agreement, including the DPA.
1.3. Changes to this Privacy Policy. We may update this Privacy Policy from time to time to reflect changes in applicable law, regulatory guidance, our Engagements, business operations, technologies, or data processing practices. When we make changes, we will revise the “Last Updated” date at the beginning of this Privacy Policy. The updated version of this Privacy Policy becomes effective on the date specified at the beginning of this document.
1.4. Relationship with Other Documents. Where you use the Services as a Client, this Privacy Policy forms part of the Agreement together with the Terms of Use and the Data Processing Addendum (“DPA”), as provided in the Terms of Use. Any applicable Order Form and product-specific or service-specific terms may also form part of or apply under the Agreement in accordance with their terms. Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the applicable Terms of Use or DPA, as applicable. In the event of a conflict between documents forming or incorporated into the Agreement, the order of precedence set out in the Terms of Use applies. In particular, to the extent of any conflict relating to the Processing of Personal Data subject to the DPA, the DPA governs to the extent of that conflict.
2. Data We Handle
2.1 Engagements. Text processes information through various interactions with individuals and organizations, regardless of the communication channel, technology, device, or method used to collect or process it. For purposes of this Privacy Policy, all such interactions (including but not limited to social media channels, phone, email, SMS, the chat window on our Website, giving feedback, making inquiries, signing up for our marketing communication) are collectively referred to as “Engagements”, and may include, without limitation: (a) Clients, including individuals acting on their behalf using, administering, purchasing, evaluating, or otherwise interacting with the Services, APIs, Website, Marketplace, Developer Program, Partner Program, hosted communication tools, authentication mechanisms, integrations, applications, customer support channels, artificial intelligence features, and any other products or services offered by Text; (b) Visitors of our Websites or our other online properties; (c) Individuals communicating with Text through available communication channels; (d) Participants registering for, attending, or otherwise participating in activities, initiatives, programs, surveys, or feedback, or events organized or made available by Text; and (e) otherwise interacting with Text in connection with its business operations and activities.
2.2. Our Role in Data Handling. Depending on the nature of the applicable Engagement and the purposes for which Personal Data is processed, Text may act either as a Data Processor or as a Data Controller. Where Text processes Client Personal Data on behalf of a Client in connection with the Services, Text acts as a Data Processor and processes such Personal Data in accordance with the Client’s documented instructions and the applicable Agreement, including the Data Processing Addendum (“DPA”). This includes, where applicable, Personal Data processed when a Client uses communication features of the Services to communicate with its End-Users or other recipients. In doing so, we may process Personal Data relating to the Client’s Users, End Users, and other individuals who use, access, communicate through, or otherwise interact with the Services or with Text in connection with the Client’s use, administration, or operation of the Services. Depending on the applicable Engagement, such information may include identifiers, authentication credentials, contact information, communications and content, usage information, technical and security information, consent, preference, and compliance information, and other information necessary to provide, secure, maintain, support, and improve the Engagements, as permitted under the Agreement. Text may also act as a Data Controller with respect to certain Personal Data processed in connection with the Services, where Text independently determines the purposes and means of such processing. This may include certain technical or operational information about Services usage, as well as information generated or collected in connection with the operation, security, performance, analytics, improvement, or development of the Services. Text also acts as a Data Controller with respect to Personal Data processed for its own business operations, including operating our Websites, marketing activities, communications, educational initiatives, events, recruitment activities, business relationships, product development, analytics, ensuring the security of our business operations, and other Engagements described in this Privacy Policy.
2.3. Grounds for Processing. Where applicable law requires a legal basis for processing Personal Data, Text relies on one or more of the following legal bases, depending on the applicable Engagements and the specific purpose of processing: (i) Processing may be necessary to enter into or perform a contract with you, including taking steps at your request before entering into a contract, providing the applicable Engagement, administering your account or subscription, processing transactions, and responding to requests relating to the contractual relationship; (ii) Processing may be necessary for Text to comply with applicable laws, regulations, court orders, legal processes, tax and accounting obligations, governmental requests, and other binding legal or regulatory requirements; (iii) based on your consent for specific purposes; and (iv) for the legitimate interests pursued by Text or a third party, provided that those interests are not overridden by your interests, fundamental rights, or freedoms. Such legitimate interests may include operating, administering, securing, maintaining, supporting, and improving the Engagements; preventing fraud, misuse, and security threats; communicating with individuals and managing customer and business relationships; understanding how the Engagements are used; conducting analytics, statistical analysis, benchmarking, and business intelligence; developing and evaluating products, features, and technologies; protecting Text’s business, rights, property, and users; and conducting marketing or promotional activities as described in this Privacy Policy. Before relying on legitimate interests, Text considers the nature and necessity of the processing, the reasonable expectations of the individuals concerned, and the potential impact of the processing on their rights and freedoms. Where Text acts as a Data Processor, the relevant Client determines the applicable legal basis for processing Client Personal Data, and Text processes such data in accordance with the Client’s documented instructions and the applicable Agreement.
2.4 Types and Sources of Data. The information we collect depends on how you interact with our Engagements, the choices you make, the features you use, and the nature of your relationship with Text. We may collect information directly from you, from the organization you represent, automatically through the Engagements, from our Clients, from integrated services, from publicly available sources, from our service providers, and from other lawful third-party sources. The categories of information we may process include, but are not limited to:
-
Identifiers: Information that identifies, relates to, or may reasonably be associated with an individual, such as name, email address, phone number, postal address, authentication credentials, IP address, username, business contact information, subscription identifiers, device identifiers, and other similar identifiers;
-
Commercial information: Information relating to subscriptions, transactions, billing activities, payment-related information, support history, tickets, purchasing history, customer relationship information, and similar commercial records;
-
Internet and electronic activity: This includes records of your interactions with our Engagements, including interaction history; chat and messaging logs; pages visited; links clicked; referring URLs; session information; navigation history; feature usage; records of communications sent or received; delivery and interaction status; and timestamps; performance metrics; usage patterns, communication records; browsing and diagnostic information, and similar activity data;
-
Device, technical, and geolocation information: Information relating to the devices, networks, and technologies used to access or interact with the Engagements, including IP address, browser type and details, operating system, device type and characteristics, language settings, country or region preferences, mobile network information, device phone number, location and geolocation information (including approximate geolocation derived from IP address), geographic region, usage logs, technical identifiers, and similar device, network, technical, and location information;
-
Communications and Content: Information you provide when communicating with Text through the Engagements, including support requests, chat conversations, e-mails, surveys, forms, Feedback, event participation, social media interactions, comments, reviews, community contributions, and other similar communications;
-
Inferences: information derived from other information we process that may reflect interests, characteristics, preferences, engagement patterns, demographics, product usage trends, or other insights used to personalize Engagements, improve user experiences, conduct analytics, support product development, and enhance our business operations;
-
Public website information: Information collected from or otherwise associated with websites, domains, or similar identifiers provided to Text, connected with an Engagement, or on which Services are deployed, including publicly available business information, website content, analytics information, service interaction information, and other lawfully available information associated with such identifiers. Such information may be collected through automated means;
-
Educational and participation data: Information relating to registrations, attendance, participation in educational initiatives, events, webinars, academies, bootcamps, workshops, and other similar initiatives offered by Text, including progress, engagement, communications, engagement metrics, preferences, and interactions with related content and materials;
-
Consent, preference, and compliance information: Information and records relating to your communication and privacy preferences, consents, permissions, opt-ins and opt-outs, suppression requests, withdrawals of consent, the date, time, source, and method by which a preference or consent was provided or withdrawn, applicable notice or consent language, and other records or evidence maintained to demonstrate or manage compliance with applicable requirements.
2.5 Sensitive Personal Data. Where Text acts as a Data Processor, the Services are not intended for the Processing of Sensitive Personal Data, and Text and the Client do not intend to, and shall not knowingly, collect, process, or transmit Sensitive Personal Data through the Services, unless otherwise expressly agreed in writing by the parties under a valid product-specific Business Associate Agreement (“BAA”), where applicable. The Client remains responsible for determining whether its use of the Services involves Sensitive Personal Data, providing any required notices, obtaining any required consents or other lawful basis, implementing any additional safeguards required by applicable law, and complying with the Agreement and, where applicable, the BAA. In the absence of an applicable BAA, the Client shall not provide or cause to be provided Sensitive Personal Data to Text for Processing through the Services, and Text may delete, restrict, isolate, or otherwise refrain from further processing such information. Where Text acts as a Data Controller, Text does not ordinarily seek to collect Sensitive Personal Data unless such processing is necessary for a specified purpose, permitted by applicable law, and subject to any additional requirements applicable to such data. To the fullest extent permitted by applicable law and the Agreement, Text is not responsible for Sensitive Personal Data submitted or otherwise made available through the Services or the Engagements, in violation of this Section, the applicable Agreement, or the applicable BAA.
Legal stuff made easy
We process information through the different ways in which individuals and organizations interact with Text, which we call “Engagements.” Information may come directly from you, from the organization you represent, from our Clients, automatically through the Engagements, from integrated services, publicly available sources, service providers, or other lawful third-party sources.
Depending on the circumstances and purpose of the processing, Text may act as a Data Controller or a Data Processor. When we process Client Personal Data on behalf of a Client, we act as a Data Processor in accordance with the applicable Agreement, including the DPA. We may act as a Data Controller for certain Services-related technical or operational information and for our own business operations.
We may process your data to perform a contract, comply with legal obligations, or, where permitted by law, act on your consent or pursue legitimate interests. When Text acts as a Data Processor, the relevant Client determines the applicable legal basis.
Depending on the Engagement, we collect and process your information, including Personal and Non-Personal Data, based on your interactions and choices. Sources include what you share, our systems, and third-party sources. This may include identifiers, commercial information, internet and electronic activity, device, technical and geolocation information, communications and content, inferences, public website information, and educational or participation information.
The Services are not intended for Processing Sensitive Personal Data unless otherwise expressly agreed in writing under an applicable product-specific BAA. Clients are responsible for ensuring that any such processing complies with the applicable Agreement, BAA, and applicable law.
3. How We Use Information
3.1. Text processes information, including Personal Data, only to the extent necessary for the purposes described in this Privacy Policy and, where applicable, the Agreement. As long as we process your information, including your Personal Data, we will continue to do so only to the extent necessary for one or more of the purposes described below and, where applicable, the Agreement:
-
Delivering and Operating the Engagements: To establish, provide, maintain, operate, administer, secure, improve, and develop our Engagements and related technologies. This includes, where applicable: (a) creating, managing registrations, subscriptions, licenses, and user profiles and participation records, including verifying eligibility, identity, processing payments and administering commercial relationships; (b) providing access to the Engagements and related functionality; (c) providing customer support, technical assistance, operational services and responding to inquiries; (d) measuring participation, engagement, attendance, adoption, and effectiveness of the Engagements; (e) researching, developing, testing, validating, training, improving, and deploying services, products, features, technologies, programs, artificial intelligence capabilities, machine learning systems and related capabilities; (f) monitoring availability, performance, reliability, functionality and quality of the Engagements; (g) enabling Partners and Developers to access Client-related information, including Personal Data, during authorized processing; (h) administering events, educational initiatives, webinars and similar Engagements; (i) performing our obligations under the applicable agreements; and (j) enabling communications through supported communication channels, including provisioning and managing communication identifiers, transmitting, routing, receiving, and delivering communications, maintaining delivery and status information, and supporting related operational and compliance functionality.
-
Operating, Securing, and Protecting Our Business: To protect the confidentiality, integrity, availability, and security of the Engagements, our business operations, customers, personnel, and third parties. This includes: authentication and access management; fraud prevention; cybersecurity monitoring; abuse detection and prevention of unauthorized activities; incident response; backup and disaster recovery; business continuity; debugging and troubleshooting; vulnerability management; monitoring system performance, availability, and reliability; enforcing our agreements and policies; and protecting the rights, property, safety, and legitimate interests of Text, our Clients, and others.
-
Compliance with Legal Obligations: To comply with applicable laws, regulations, court orders, governmental requests, regulatory requirements, tax obligations, accounting requirements, industry standards, or other legal obligations. We may also process information to establish, exercise, defend, investigate, or enforce legal claims or contractual rights, investigate suspected unlawful activity, or respond to lawful requests from public authorities.
-
Communications, Marketing and Promotions: We may communicate with you in connection with the Engagements, including to respond to requests and inquiries; provide administrative, transactional, security, account, billing, and service-related notices and updates; provide information about changes to the Engagements; and manage our customer, partner, developer, and other business relationships. We may also send or otherwise provide marketing and promotional communications, including offers, tailored marketing campaigns, newsletters, product or service recommendations, event invitations, promotional information, and other communications that may be relevant or of interest to you. Such communications may be delivered through email, phone, SMS or other messaging services, push notifications, in-product or in-app messages, social media, or other available communication channels. We may personalize or tailor marketing and promotional communications based on information about your interactions with the Engagements, preferences, interests, commercial relationship with Text, and other information described in this Privacy Policy, including profiles or inferences derived from such information, where permitted by applicable law. If you provide contact information to Text in connection with a particular Engagement, request, registration, event, resource, or other interaction, we may use that information to communicate with you in connection with that interaction and, where we have an appropriate legal basis, which may include your consent or our legitimate interests, to provide other marketing or promotional communications that may be of interest to you. Service-related and transactional communications may be necessary for the administration, security, operation, or performance of the applicable Engagement, or to comply with the Agreement or applicable law, and you may not be able to opt out of certain such communications where they are necessary for those purposes. You may opt out of marketing and promotional communications at any time by using the unsubscribe mechanism provided in the communication or contacting us at support@text.com. Opting out of marketing or promotional communications will not prevent us from sending non-promotional communications relating to your account, transactions, security, use of the Engagements, or our contractual or legal obligations.
-
Improving the Engagements: To understand how the Engagements are used and to improve, secure, develop, test, and evaluate our products, services, features, technologies, analytics, automation, artificial intelligence, and machine learning capabilities. This may include identifying usage patterns, improving performance and user experience, developing new functionality, supporting research and innovation, conducting statistical analysis and benchmarking, generating operational insights, and enhancing security. The Client represents that it has the rights necessary to provide its content, identifiers, and data and to authorize the processing described in this Privacy Policy and the Agreement. Where reasonably possible and appropriate for the intended purpose, including for statistical analysis and benchmarking, Text uses aggregated, pseudonymized, anonymized, or de-identified information.
-
Contributions, Feedback and Community Participation: Where you voluntarily submit (directly or via integrated services or third-party services) Feedback, participate in surveys, community initiatives, educational activities, beta programs, events, or similar Engagements, we may process such information to administer and improve the existing Engagements; develop new products and features; understand customer needs; evaluate customer satisfaction; identify product improvements; prepare educational, support, and knowledge materials; support our business operations; create case studies, testimonials, or marketing materials, and publicly attribute Feedback-related materials. The use of Feedback is subject to the Agreement where relevant.
-
User Engagement, Analytics, Personalization, and Profiling: Text may use automated methods, including profiling, to analyze how individuals interact with the Engagements, understand preferences and usage patterns, recognize returning users, measure engagement, personalize content and functionality, recommend and tailor relevant products, services, features, offers, marketing communications, promotions, or advertising. For these purposes, Text may combine information you provide or that we collect through the Engagements with other information associated with you, including information contained in our existing records or lawfully obtained from other sources. Such processing may involve information about your interactions with the Engagements, communications, participation history, product usage, preferences, commercial relationship with Text, and other information described in this Privacy Policy. Where permitted by applicable law, profiling may also be used to create or enrich audience segments, improve the relevance of marketing and advertising, tailor offers and promotional content, evaluate the effectiveness of campaigns, and identify products, services, features, or information that may be of interest to you. We do not use profiling to make decisions that have legal or similarly significant effects on an individual, unless such processing is permitted by applicable law and appropriate safeguards are in place. Where required by applicable law, individuals may object to, restrict, or withdraw consent for profiling by contacting support@text.com. Exercising such rights may affect the availability of optional personalization or other features where the relevant processing is reasonably necessary to provide those features, potentially resulting in the termination of our Agreement.
3.2 Client name and logo. The Client grants Text and its Affiliates a worldwide, royalty-free, non-exclusive right to use the Client’s company name, logo, and other brand identifiers to identify the Client as a customer of Text and for related marketing and promotional purposes, including in customer lists, on Text’s Websites, in sales presentations, and in other marketing materials, subject to the Client’s applicable brand guidelines. The Client represents that it has all rights and authority necessary to grant this authorization and may request that Text discontinue future use of its company name or logo by contacting Text at support@text.com. Any such request will apply prospectively only and will not require Text to withdraw, recall, modify, or cease use of materials that were created, published, distributed, or committed to production or distribution before Text received the request.
3.3 Cookies and other Tracking Technologies. Depending on how you interact with our Engagements, we, and our authorized service providers, may use cookies, pixels, local storage technologies, beacons, and similar technologies on our Websites, within or in connection with the Services, and on other websites, applications, or online properties where the Services are installed, integrated, embedded, or otherwise made available. On our Websites and other Text-controlled online properties, these technologies may be used to operate, secure and improve the applicable Engagements, remember preferences and settings; conduct analytics and research, understand and measure usage and engagement, personalize content and functionality, measure the effectiveness of communications and campaigns; measure the effectiveness of communications and campaigns; and support marketing and advertising activities, including providing or tailoring advertising based on browsing activities, interactions, preferences, and interests. Information collected through these technologies may be combined with other information we process about you, including information obtained through the Engagements or from other lawful sources, for the purposes described in this Privacy Policy. Within the Services**,** cookies and similar technologies are used primarily to operate, provide, secure, support, analyze, maintain, and improve the Services; authenticate users; remember settings; measure performance and usage; troubleshoot issues; and support product development and related operational purposes. Text does not use cookies or similar technologies within the Services to provide third-party advertising, conduct cross-site or cross-context behavioral advertising, or target an End User based on activity across unrelated Clients. Where cookies or similar technologies are deployed through the Services or on websites, applications, or other properties operated by a Client, the respective roles and responsibilities of Text and the Client depend on the nature and purpose of the processing. Where Text processes Personal Data on behalf of a Client, Text acts as a Data Processor or Service Provider, as applicable, and may process such information on behalf of the Client in accordance with the applicable Agreement, including the DPA. The Client remains responsible for determining the applicable purposes and legal bases for such processing and for providing any notices, obtaining any consents, establishing any other lawful basis, or any other measures required by applicable law for cookies, integrations, advertising technologies, or other third-party technologies that the Client enables, configures, or deploys in connection with the Services. Our authorized service providers and partners may also use or set cookies and similar technologies in connection with the Engagements. Certain third parties may process information for their own purposes as independent controllers, in which case their processing is governed by their own terms and privacy notices. Additional information about our use of cookies and similar technologies, including available privacy choices, is provided in our Cookie Policy and, where applicable, through our consent management tools.
3.4 Feedback and attribution. Where a Client or an individual voluntarily provides feedback, comments, quotations, reviews, testimonials, case study materials, or other contributions (“Feedback”), Text may use such Feedback for product improvement, research, educational materials, case studies, testimonials, marketing materials, and other related business purposes. The Client authorizes Text and its Affiliates, subject to the Client’s applicable brand guidelines, to reproduce, publish, distribute, adapt, create derivative works from, and publicly attribute the Feedback in any media, including on websites, in sales materials, social media, case studies, press releases, events, and investor materials. Text may also share Feedback-related materials with publishers, platforms, and service providers solely to prepare, publish, or distribute those materials. Where included in the Feedback, such attribution may identify the Client using its name, logo, or other brand identifiers in accordance with Section 3.2 and may identify an individual contributor by name, job title or role, image, likeness, or voice. Once Feedback has been voluntarily provided by or on behalf of the Client, the Client authorizes Text to exercise the rights described in this Section without further approval, unless otherwise agreed in writing with the Client. The Client represents that it has obtained and will maintain all rights, authorizations, consents, and permissions necessary to provide the Feedback and grant the rights described in this Section, including on behalf of its Users, and that such use does not infringe any third-party rights. Where an individual’s consent is required by applicable law, the Client represents that it has obtained and will maintain the corresponding consent from the relevant individual. An individual may withdraw consent for future uses by contacting support@text.com. Withdrawal will not affect materials created, published, distributed, archived, or committed to production before the request was received.
3.5 Login and Authentication Services. Certain Engagements may permit authentication via third-party identity providers, including enterprise identity providers, social login providers (such as Facebook Connect and Google Sign-In), OpenID providers, SSO services, and similar authentication services. These providers may share information with Text in accordance with your settings and the applicable provider’s terms and privacy policy. Such information is processed solely to authenticate users, administer accounts, provide access to the Engagements, maintain security, and support the requested authentication functionality (including through Supporting Applications), and the operation of the applicable Engagements. Your use of such authentication services remains subject to the applicable terms and privacy policies of those providers. We do not control how these providers handle your information and encourage you to review their applicable policies before enabling such integrations. Specifically, where our Services access or use information obtained from Google APIs, such access and use will comply with the Google API Services User Data Policy, including the Limited Use requirements. You acknowledge and agree that the use of third-party authentication services is at your discretion and risk and remains subject to the applicable provider’s terms and privacy practices. Text is not responsible for the acts or omissions of such third-party providers, including their processing of Personal Data.
3.6 Third-Party Integrations and Connected Services. The Engagements may rely on, integrate with, connect to, or otherwise enable the use of third-party tools, applications, software, embedded content, widgets, open-source components, websites, platforms, plug-ins, APIs, marketplaces, communication platforms, artificial intelligence providers, social media functionality, and other similar third-party technologies, whether selected by you or made available by us as part of the Services’ experience, (collectively, “Third‑Party Integrations”). Third‑Party Integrations are provided for your convenience and operate independently from Text and remain subject to their own terms, privacy notices, and processing practices. Certain Engagements may include embedded media, social media functionality, interactive widgets, sharing tools, community features, or other third-party functionality that enables interactions with external platforms or services. Such functionality may collect technical information relating to your interactions with the Engagements, including browser information, IP address, pages visited, and other usage information, and may use cookies or similar technologies necessary for their operation. Text does not control and is not responsible for the availability, security, content, or privacy practices of Third-Party Integrations. Before enabling or interacting with Third-Party Integrations, users should review the applicable terms and privacy policies governing those services. When you enable or use Third-Party Integrations, information may be exchanged between the Engagements and the applicable third-party provider to facilitate the requested functionality. Any independent processing carried out by the applicable third-party provider is governed by that provider’s own terms and privacy practices.
Legal stuff made easy
We use information to provide, operate, secure, maintain, support, improve, and develop our Engagements; comply with legal obligations; communicate with you; conduct marketing where permitted by law; conduct analytics, statistical analysis, and benchmarking; support research, innovation, artificial intelligence, and machine learning; administer feedback, events, and other participation; and personalize your experience where permitted by law.
We may use automated methods, including profiling, for personalization, recommendations, marketing, and advertising where permitted by applicable law. We do not use profiling to make decisions that have legal or similarly significant effects unless such processing is permitted by law and appropriate safeguards are in place.
On Text-controlled Websites and online properties, cookies and similar technologies may support analytics, personalization, marketing, and advertising. Within the Services, Text does not use cookies or similar technologies to provide third-party advertising, conduct cross-site or cross-context behavioral advertising, or target an End-User based on activity across unrelated Clients.
Third-Party Integrations operate under their own terms and privacy practices. More information about individual privacy rights is provided in Section 4.
4. Your Privacy Rights
4.1 Requests Relating to Personal Data. Where Text processes Personal Data as a Data Controller, and subject to applicable law and verification of your identity, you may exercise the following rights you may contact us at support@text.com: (i) access and obtain information regarding the Personal Data we process about you; (ii) request correction of inaccurate or incomplete Personal Data; (iii) request deletion of Personal Data, subject to applicable legal, contractual, security, operational, or regulatory retention requirements; (iv) object to or restrict certain processing activities; (v) withdraw consent where processing is based on consent, without affecting the lawfulness of processing conducted before such withdrawal; (vi) and request portability of Personal Data where required by applicable law. These rights are not absolute and may be subject to exceptions and limitations permitted or required by applicable law. Before responding to a request, Text may take reasonable steps to verify the identity of the individual submitting the request and to confirm that the request relates to Personal Data processed by Text in its capacity as a Data Controller. We will respond to verified requests within 30 days, subject to any extensions permitted by applicable law due to the complexity or number of requests, using a standard method accepted by Text and in accordance with Text’s data retention policy. We may retain Personal Data where and to the extent that retention is necessary or permitted to comply with a legal obligation, establish, exercise, or defend legal claims, protect security and integrity, protect the rights, freedoms, or legitimate interests of Text, or others, or rely on another applicable legal exception. Where immediate deletion is not reasonably feasible due to the manner in which information is stored, including in secure backups, we will restrict further use of the information and delete or overwrite it in accordance with our standard retention and backup cycles, unless continued retention is required or permitted by applicable law.
4.2 Requests Relating to Client Personal Data. Where Text acts as a Data Processor, requests relating to Client Personal Data should generally be directed to the relevant Client. Text will assist the Client in responding to such requests as required by the applicable Agreement, including the DPA.
5. How We Disclose Information
5.1 Text does not sell Personal Data for monetary consideration. This does not restrict disclosures to service providers, telecommunications carriers, or other authorized parties where necessary to provide the Engagements in compliance with applicable requirements, to respond to a complaint or investigation, protect legitimate interests, or otherwise as described in this Privacy Policy.
5.2 Within the Text Group. We may share information with our Affiliates, subsidiaries, parent companies, and other entities under common control for purposes consistent with this Privacy Policy, including service delivery, internal administration, security, compliance, business operations, product development, customer support, analytics, and corporate governance. We may also disclose information in connection with an actual or proposed merger, acquisition, financing, investment, corporate reorganization, bankruptcy, sale of assets, or similar corporate transaction. Where appropriate, such disclosures will be subject to confidentiality obligations and applicable legal requirements.
5.3 Service Providers and Sub-Processors. We engage trusted service providers, contractors, professional advisors, subprocessors, and other authorized partners to support the operation of the Engagements. We may disclose Personal Data and other information to such providers where necessary for hosting, infrastructure, payment processing, communications and messaging delivery, telecommunications and network services, analytics, customer support, security, identity management, artificial intelligence capabilities, marketing, business operations, and other services necessary to operate our business. Where such providers process Personal Data on our behalf and where required by applicable law, they are contractually required to process information only on our instructions, implement appropriate safeguards, maintain confidentiality and security of the information entrusted to them.
5.4 External Links. The Engagements may contain links to websites, applications, or services operated by third parties. This Privacy Policy does not apply to those third parties, and Text is not responsible for their content, security, or privacy practices. We encourage you to review the privacy notices of any third-party services before providing information to them.
5.5 Disclosure to Public Authorities and Law Enforcement. We may disclose information where necessary to comply with applicable laws, regulations, court orders, governmental requests, or legal processes; establish, exercise, defend, or enforce legal rights; investigate suspected fraud, abuse, unlawful activity, or security incidents; protect the rights, property, safety, or security of Text, our Clients, users, employees, or third parties; or otherwise comply with applicable legal obligations. We will provide notice where required and permitted by applicable law.
Legal stuff made easy
We may disclose information within the Text group and to service providers, Sub-Processors, professional advisers, and other authorized parties where necessary for the purposes described in this Privacy Policy. Some third parties may process Personal Data independently under their own terms and privacy notices.
We may also disclose or transfer information in connection with a corporate transaction, or where necessary to comply with applicable law, legal process or governmental requests, protect rights or security, investigate suspected unlawful activity, or establish, exercise or defend legal claims.
We do not sell Personal Data for monetary consideration.
6. How We Protect Information and How Long We Keep It
6.1 Security. Text will take reasonable steps to ensure that Personal Data is reliable for its intended use, accurate, complete, and up to date. We use appropriate technical and organizational measures designed to protect information against loss, misuse, and unauthorized or unlawful access, disclosure, alteration, and destruction. These safeguards are designed to take into account the nature of the information processed, the risks associated with processing activities, applicable legal requirements, industry standards, and the evolving security landscape. While we implement appropriate safeguards, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure. Accordingly, we cannot guarantee the absolute security of information processed through the Engagements. To the fullest extent permitted by applicable law, Text does not warrant that unauthorized access can always be prevented and is not responsible for incidents caused by circumstances outside its reasonable control. Where required by applicable law, we will notify affected individuals or the relevant Client of a Personal Data breach in accordance with applicable legal and contractual requirements. Where Text acts as a Data Processor, our security commitments are further described in the Agreement, including the DPA.
6.2 Retention. We retain your data for as long as necessary to fulfill the purposes for which it was collected and limit the storage period to the minimum necessary, unless a longer retention period is required or permitted by applicable law or the Agreement. Retention periods depend on the nature of the information, the Engagements involved, applicable legal requirements, contractual obligations, operational needs, and our role as a Data Controller or Data Processor. Retention periods may also reflect the need to maintain records of consents, permissions, communication preferences, opt-outs, suppression requests, communications, and related compliance records for as long as reasonably necessary to provide the Engagements, demonstrate compliance with applicable law or contractual requirements, manage communication preferences, or to establish, exercise, or defend legal claims. Where Text acts as a Data Processor, retention and deletion of Client Personal Data are governed by the Agreement and the Client’s documented instructions. Where information is no longer required, we will delete, anonymize, or otherwise securely dispose of it, unless continued retention is required or permitted by applicable law. When we retain information is processed for the improvement orand development of our Engagements, or new products, or and features, we take steps to eliminate information that directly identifies you, and we Text uses aggregated, pseudonymized, anonymized, or de-identified information where reasonably possible and appropriate for the intended purpose, as described in Section 3.1(5), the information only to uncover collective insights about the use of our Engagements, not to specifically analyze personal characteristics about you.
Legal stuff made easy
We use appropriate technical and organizational measures designed to protect information against loss, misuse, and unauthorized or unlawful access, disclosure, alteration, or destruction. No system or method of transmission can be guaranteed to be completely secure.
Where required by applicable law or the Agreement, we will provide notification of a Personal Data breach to affected individuals or the relevant Client.
We retain information only for as long as necessary for the purposes for which it is processed, or as otherwise required or permitted by applicable law or the Agreement. When information is no longer required, we delete, anonymize, or otherwise securely dispose of it, subject to applicable retention requirements and backup cycles.
7. International Transfer
7.1 Text operates globally and may process information in countries other than the country where the information was originally collected. Where Personal Data is transferred internationally, Text implements appropriate safeguards designed to protect such information in accordance with applicable data protection laws. Depending on the circumstances, these safeguards may include: the European Commission’s Standard Contractual Clauses; the UK International Data Transfer Addendum; the EU-U.S. Data Privacy Framework; the UK Extension to the EU-U.S. Data Privacy Framework; the Swiss-U.S. Data Privacy Framework; or other lawful transfer mechanisms recognized under applicable law.
Legal stuff made easy
Text operates globally, so information may be processed in countries other than the country in which it was originally collected. Where Personal Data is transferred internationally, we use safeguards required or recognized by applicable law, including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the applicable Data Privacy Framework, or other lawful transfer mechanisms.
8. Jurisdiction - specific rights
8.1 European Economic Area, United Kingdom, and Switzerland. Individuals located in the European Economic Area (“EEA”), the United Kingdom, and Switzerland may have additional rights under applicable data protection laws, including the General Data Protection Regulation (“GDPR”), the Data Protection Act 2018, which encompasses the UK General Data Protection Regulation (UK GDPR), the Swiss Federal Act on Data Protection (“FADP”), and other applicable legislation. Subject to applicable law, such individuals may have the right to: request access to Personal Data; request correction of inaccurate Personal Data; request deletion of Personal Data; request restriction of processing; object to certain processing activities; withdraw consent where applicable; request data portability; and lodge a complaint with the competent supervisory authority. All collection, use, and disclosure of Personal Data described in this Privacy Policy apply equally to individuals in these regions. Where Text acts solely as a Data Processor on behalf of a Client, requests relating to Client Personal Data should generally be directed to the relevant Client.
8.2 California. Residents of California may have additional rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), subject to applicable exceptions and limitations. Depending on applicable law, California residents may have the right to know what categories of Personal Data we collect and process; access Personal Data; request deletion; request correction; request portability; opt out of certain processing where required by law; limit the use of certain sensitive Personal Data where applicable; and exercise their rights without unlawful discrimination. Text does not sell Personal Data for monetary consideration and does not use Personal Data within the Services for cross-context behavioral advertising involving End-Users. However, we do share certain information with advertising or analytics partners in connection with our Websites and our own marketing activities to provide you with tailored ads. California residents may opt out of such sharing at any time as described in our Cookie Policy. We disclose the categories of Personal Information listed in Sections 2 (“Data We Handle”) and 5 (“How We Disclose Information”) of this Privacy Policy. To exercise any of the rights above, or if you are a business Client that requires a CCPA/CPRA addendum to our Agreement, please email support@text.com. We may need to verify your request before we can act on it.
8.3 Data Controller. Where Text acts as a Data Controller, the entity responsible for the processing of Personal Data is Text, Inc., 101 Arch Street, 8th Floor, Boston, MA 02110, United States of America, unless otherwise stated in connection with a specific Engagement.
Legal stuff made easy
Depending on where you are located and which privacy laws apply, you may have additional rights regarding your Personal Data.
Individuals in the EEA, United Kingdom, and Switzerland may have rights under applicable European, UK, or Swiss data protection laws, including rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to lodge a complaint with a competent supervisory authority.
California residents may have additional rights under the CCPA/CPRA. Text does not sell Personal Data for monetary consideration and does not use Personal Data within the Services for cross-context behavioral advertising involving End-Users. We may share certain information with advertising or analytics partners in connection with our Websites and our own marketing activities, subject to applicable privacy choices.
Text, Inc. also participates in the applicable EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework programs as described above.
9. Additional Privacy Notices
9.1 Age Restrictions and Children’s Privacy. The Engagements are not directed to individuals under the age of sixteen (16), or such higher minimum age as may be required under applicable law. Text does not knowingly collect Personal Data directly from children through the Engagements. If you believe that Personal Data relating to a child has been provided to Text without appropriate authorization, please contact us at support@text.com (or via support e-mail of the Services you use), so that appropriate action may be taken.
9.2 Corporate transactions. Text may disclose or transfer Personal Data and other information in connection with an actual or proposed merger, acquisition, financing, investment, reorganization, bankruptcy, sale of assets, or similar corporate transaction. Any successor or acquiring entity may process such information in accordance with this Privacy Policy, applicable law, and any additional notice provided in connection with the transaction.
9.3 DPO and EU Representative. Text, Inc. has designated Text SA as its European Union representative to serve as a contact point between our Company and individuals or data protection authorities in the EU and in regard to our obligations under the GDPR. You can contact Text SA via email: support@text.com. Text’s Data Protection Officer is Maciej Malesa. Correspondence may be sent to Text, Inc., 101 Arch Street, 8th Floor, Boston, MA 02110, United States of America, or by email to support@text.com.
9.4 Data Privacy Framework Notice. Text, Inc. complies with the EU-U.S. Data Privacy Framework program (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework program (Swiss-U.S. DPF) collectively, the “Data Privacy Framework”, as administered by the U.S. Department of Commerce, to the extent applicable. Text, Inc. has been certified by the U.S. Department of Commerce as adhering to the Data Privacy Framework Principles with respect to the processing of Personal Data received from the European Union, the United Kingdom (and Gibraltar), and Switzerland in reliance on the applicable Data Privacy Framework. If there is any conflict between the terms in this Privacy Policy and the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, please click here. To view our certification page, please visit this website.
Text, Inc. has further committed to refer unresolved privacy complaints under the DPF Principles to an independent dispute resolution mechanism, Data Privacy Framework Services, operated by BBB National Programs. If you do not receive a timely acknowledgment of your complaint or if your complaint is not satisfactorily addressed, please visit the following website for more information and to file a complaint. This service is provided free of charge to you.
Questions or complaints regarding our participation in the Data Privacy Framework should be directed to us at support@text.com. If your DPF complaint cannot be resolved through the above channels, you may, under certain conditions, invoke binding arbitration for certain residual claims not resolved by other redress mechanisms. To learn more, click the Data Privacy Framework website
The Federal Trade Commission has jurisdiction with enforcement authority over Text, Inc.’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
The contact details for supervisory authorities in the European Union and the United Kingdom can be found on the following websites.
Legal stuff made easy
Remember, depending on where you are, different rules might apply to how we handle your data, but we always aim to keep it safe and respect your rights:
- We follow a set of rules called GDPR, which is all about protecting your Personal Data if you live in Europe or are a European citizen.
- For UK residents, we respect the UK's own data protection laws, called the UK GDPR, which is part of the Data Protection Act 2018, to protect your privacy.
- If you're from California, we process your Personal Information under the CCPA and CPRA.
We don't sell Personal Data for monetary consideration, but we may share certain information with trusted partners to show you ads. We do not use Client Personal Data or End User Personal Data within the Services for cross-context behavioral advertising. If you want out, check our Cookie Policy.
We're part of a program called Data Privacy Framework, which ensures that we properly handle personal data from the European Union, the United Kingdom, and Switzerland.
If you want to learn more about this program, click here https://www.dataprivacyframework.gov/s/
You can also check out our certification page for more details. https://www.dataprivacyframework.gov/s/
The Federal Trade Commission keeps an eye on us to ensure we follow the program's rules.