Last updated: December 2023
Please read this privacy notice (“Privacy Notice”) carefully as it describes our collection, use, disclosure, retention and protection of your personal information. This Privacy Notice applies to any website, application or service which references this Privacy Notice. When you provide us with your personal information or when we collect it in any of the ways described in section 2 below, you agree that we may collect, store and use it: (a) in order to perform our contractual obligations to you; (b) based on our legitimate interests for processing, i.e. for internal administrative purposes, data analytics and benchmarking (see section 3 below for more information), direct marketing, maintaining automated back-up systems or for the detection or prevention of crime); or (c) based on your consent, which you may withdraw at any time, as described in this Privacy Notice.
This Privacy Notice may be relevant to you even if you are not a customer or direct contact of ours - even if you have never used a website, application or service of ours. We may have your personal information because we have received it from a user of a website, application or service of ours.
1. Who we are
This Privacy Notice applies to all products, applications and services offered by The Sage Group plc, company incorporated in England with company registration number 02231246 and whose registered office address is C23 5 & 6 Cobalt Park Way, Cobalt Business Park, Newcastle-Upon-Tyne, Tyne & Wear, NE28 9EJ, and its affiliates, but excludes any products, applications or services that have separate privacy notices which do not incorporate this Privacy Notice.
2. How we collect information
To the extent permissible under applicable law, we collect information about you and any other party whose details you provide to us when you:
- register to use our websites, applications or services (including free trials); this may include your name (including business name), address, email address and telephone number. We may also ask you to provide additional information about your business and your preferences;
- place an order using our websites, applications or services; this may include your name (including business name), address, contact (including telephone number and email address) and payment details;
- use our applications, which may include the collection of metadata;
- complete online forms (including call back requests), take part in surveys, post on our message boards, post any blogs, enter any competitions or prize draws, download information such as white papers or other publications or participate in any other interactive areas that appear on our website or within our application or service;
- interact with us using social media;
- interact with us through our chatbots;
- provide your contact details to us when registering to use or accessing any websites, applications or services we make available or when you update those details; and
- contact us offline, for example by telephone, fax, SMS, text message, email or mail.
We will also collect your information where you only partially complete and/or abandon any information inputted into our website and/or other online forms and may use this information to contact you to remind you to complete any outstanding information and/or for marketing purposes.
We also collect information from your devices (including mobile devices) and applications you or your users use to access and use any of our websites, applications or services. For example, we may collect the device identification number and type, location information and connection information such as statistics on your page views, traffic to and from the sites, referral URL, ad data, your IP address, your browsing history and your web log information. We may do this using cookies or similar technologies (as described in section 11 below).
We may enhance personal information we collect from you with information we obtain from third parties that are entitled to share that information; for example, information from credit agencies, search information providers or public sources, e.g. for customer due diligence purposes, but in each case as permitted by applicable laws.
Providing us with information about others
If you provide us with personal information about someone else, you are responsible for ensuring that you comply with any obligation and consent obligations under applicable data protection laws in relation to such disclosure. Insofar as required by applicable data protection laws, you must ensure that you have provided the required notices and have obtained the individual’s explicit consent or otherwise have a legal basis to provide us with the information and that you explain to them how we collect, use, disclose and retain their personal information or direct them to read our Privacy Notice.
3. How we use your information
To the extent permissible under applicable law, we use your information to:
- provide any information and services that you have requested or any applications or services that you have ordered;
- compare information for accuracy and to verify it with third parties;
- provide, maintain, protect and improve any applications, products, services and information that you have requested from us;
- manage and administer your use of applications, products and services you have asked us to provide;
- manage our relationship with you, e.g. customer services and support activities;
- monitor, measure, improve and protect our content, website, applications and services and provide an enhanced, personal user experience to you;
- undertake internal testing of our website, applications, systems and services to test and improve their security, provision and performance, in which case, we would pseudonymize any information used for such purposes, as well as ensure is it only displayed at aggregated levels which will not be linked back to you or any other living individual;
- provide you with any information that we are required to send you to comply with our regulatory or legal obligations;
- comply with any other of our regulatory or legal obligations;
- detect, prevent, investigate or remediate, crime, illegal or prohibited activities or to otherwise protect our legal rights, including cooperation with regulators and law enforcement agencies for these purposes;
- contact you to see if you would like to take part in our customer research, e.g. provide feedback on your use of our applications, products and services;
- to monitor and/or carry out statistical analysis and benchmarking as permitted by law and in accordance with the “Data analytics and benchmarking” section below;
- deliver targeted advertising, marketing, including in-product messaging, or information to you which may be useful to you based on your use of our applications and services;
- deliver joint content and services with third parties with whom you have a separate relationship, such as social media providers; and
- provide you with location-based services, e.g. advertising and other personalized content where we collect geolocation data.
To the extent permitted by applicable law, we retain information about you after the closure of your Sage account or if your application for a Sage account is declined or if you decide not to proceed. This information will be held and used for as long as permitted for legal, regulatory, fraud prevention and legitimate business purposes.
Our website, applications (including mobile applications) and services may contain technology that enables us to:
- compare specific information from your device or systems directly relevant to your use of the websites, applications or services with our records to ensure the websites, applications or services are being used in accordance with our end-user agreements and to troubleshoot any problems;
- obtain information relating to any technical errors or other issues with our website, applications and services;
- comply with our legal or regulatory obligations;
- collect information about how you and users use the functions of the features of our website, applications and services; and
- gather statistical information about the operating system and environment from which you access our applications or services.
You can manage your privacy settings within your browser or our applications and services where applicable.
In addition to the purposes described in this section 3, we may also use information we gather to deliver targeted advertising, marketing (including in-product messaging) or information to you which may be useful based on your use of the website, applications or services or any other information we have about you. Depending on the websites, applications or services, you may able to configure these features to suit your preferences. Sections 5 and 6 of this Privacy Notice provide further details on how we will do this.
We may monitor and/or record our communications with you, including emails and phone conversations. Information we collect may then be used for training purposes, quality assurance, to record details about our website, applications and services you order from us or ask us about, and in order to meet our general legal and regulatory obligations.
We may obtain information through mobile applications that you or your users install on yours or their own mobile devices to access and use our website, applications or services or which you or your users use to provide other services related to that mobile application (for example, to sync information from our application or service with such mobile application). These mobile applications may be our own mobile applications or those belonging to third parties. Where the mobile application belongs to a third party, you must read that third party’s own privacy notice as it will apply to your use of that third party mobile application. We are not responsible for such third party mobile applications and their use of your personal information.
Mobile applications may provide us with information related to a user’s use of that mobile application and use of our applications and services accessed using that mobile application. We may use such information to provide and improve the mobile application or for our own application or services. For example, activity undertaken within a mobile application may be logged.
You can configure our mobile application’s privacy settings on your device, though this may affect the performance of that mobile application and the way it interacts with our applications and services.
Data analytics and benchmarking
We may use information generated and stored during your use of our services for our legitimate business interests to enable us to give you the best service and/or solutions and the best user experience. Because we are committed to innovation, this use of information might involve the use of statistical analysis, benchmarking and forecasting services, predictive analysis and artificial intelligence/machine learning.
These purposes include:
- Conduct profiling activities, to evaluate customer segmentation areas/products/services of interest, to adapt our services, support you and personalize the communications we send to you in relation to those services, where permitted by law. To do this, we use data generated by your use of our products and websites (your consent is collected where required by applicable laws). You have the right to object to such use of your personal data in accordance with Section 6 below.
- deliver advertising, marketing (including in-product messaging) or information to you which may be useful to you based on your use of services;
- carry out research and development to improve our services, products and applications;
- develop and provide new and existing functionality and services (including statistical analysis, benchmarking, insights, receipt recognition and cashflow forecasting services); and
- provide you with location-based services, such as location relevant content, where we collect geo-location data to provide a relevant experience.
Please be aware that our use may include personal information of your individual clients, suppliers, employees and other individuals whose information you input into any of our websites, applications or services.
Any individual whose personal information we process has the right to object to processing based on our legitimate interests. If you wish to do so, please contact us at email@example.com
4. Sharing your information
We may share your information with:
- any company within the Sage Group for the purposes set out in this Privacy Notice, which includes: global information and customer relationship management; software and service compatibility and improvements; and to provide you with any information, applications, products or services that you have requested;
- our service providers and agents (including their sub-contractors) or third parties which process information on our behalf, including internet service and platform providers, payment processing providers and those organizations we engage to help us send communications to you so that they may help us to provide you with the applications, products, services and information you have requested or which we believe is of interest to you. We have contracts in place with them. This means that they cannot do anything with your personal data unless we instruct them to do so. They will hold it securely and only retain it for the period we instruct them to;
- other entities may also be controllers of the data we share with them. For example, we may collaborate with academic or research organizations to perform public interest research or as necessary for our own or another organization’s legitimate interests, e.g. to deliver valuable insights to our customers or to enable us to improve the service we offer you. In such a case, we will take additional steps to protect your personal data, including pseudonymization, anonymization or aggregation, before sharing these data. We do this in order to protect the privacy and confidentiality of your data;
- partners, including system implementers, resellers, value-added resellers, independent software vendors and developers that may help us to provide you with the applications, products, services and information you have requested or which we believe is of interest to you;
- third parties used to facilitate payment transactions, such as clearing houses, clearing systems, financial institutions and transaction beneficiaries;
- third parties where you have a relationship with that third party, such as social media providers for example, for targeted advertising purposes;
- third parties for marketing purposes, e.g. our partners and other third parties with whom we work and whose products or services we think will interest you in the operation of your business activities. For example, financial services organizations, such as banks, insurers, finance providers, payment solutions providers, software and services providers that provide business solutions;
- credit bureaus and fraud prevention agencies;
- Any government body, regulator or other third party necessary in order to meet Sage Group’s legal and regulatory obligations;
- law enforcement agencies so that they may detect or prevent crime or prosecute offenders;
- any third party in the context of actual or threatened legal proceedings, provided we can do so lawfully (for example in response to a court order);
- any third party in order to meet our legal and regulatory obligations, including statutory or regulatory reporting or the detection or prevention of unlawful acts;
- our own and Sage Group professional advisors and auditors for the purpose of seeking professional advice or to meet our audit responsibilities;
- another organization if we buy or sell (or negotiate to buy or sell) any business or assets;
- another organization to whom we may transfer our agreement with you; and
- Government entities where reporting is mandatory under applicable law(s).
We may publicly share non-personally identifiable information (non-PII) about the use of our website, applications, products or services or with third parties; this will not include any personally identifiable information (PII).
We are required by law to provide metadata to HM Revenue & Customs (HMRC) when you use a software package or application compatible with Making Tax Digital used to help you complete and submit tax returns or provide updates. To find out more about the data sent to HMRC and to view HMRC’s transaction monitoring privacy notice, please click here
From time to time, we may use your information to contact you with details about our applications, products and services that we think may be of interest to you. We may also share your information with our group companies and carefully selected third parties so that they (or we) may contact you with information about their products or services that we think may be of interest to you. We or they may wish to contact you for this purpose by telephone, mail, SMS or email. You have the right at any time to stop us from contacting you for marketing purposes. You may also request at any time that we do not share your information with third parties referred to in this paragraph. If you wish to exercise these rights, you can do so by selecting your contact preferences at the time you provide us with your information on our websites, applications or services and by using any of our accessible preference centers. You may also do so by sending us an email at [email protected]. You may also opt-out from all marketing emails by using the links provided in these emails.
Third party platform advertising
When you respond to communications we post on third-party platforms such as LinkedIn, Instagram, Facebook, Google and Twitter, we may also share your information with third parties in order to serve targeted advertising and/or content to you via the relevant third party platform based on your profile and/or interests. Your information is used by the third party platform provider to identify your account and target advertisements to you. You can control which advertisements you see via the privacy settings on the relevant provider’s platform and we recommend that you consult the third party’s help or support center for further information.
We use Conversion APIs provided by Meta, Google and LinkedIn to ensure our ads match your potential interest, to track their efficiency and to optimise the effectiveness of our campaigns. An API is a software intermediary allowing two applications to talk to each other, when using a conversion API, we allow our server to communicate with these third-party servers. Where you consent to “Targeting technologies” on our website, we collect information about your usage of our website from our server logs and share this information with these third parties for the abovementioned purposes. We also share what we call “offline” data, which is information we collected from our interactions with you that took place outside of our website and can help us understanding your entire experience with Sage. This data includes your hashed contact details, as well as information about your organisation and information about your interactions with Sage (e.g. whether you are interested in a product, which product it is, how interested you are). You can deactivate this tool by withdrawing your consent to “Targeting technologies”.
6. Your information and your rights
If you are based within the EEA or within another jurisdiction with similar data protection laws, in certain circumstances you have the following rights:
- the right to be told how we use your information and obtain access to your information;
- the right to have your information rectified or erased or place restrictions on processing your information;
- the right to object to the processing of your information, e.g. for direct marketing purposes or where the processing is based on our legitimate interests;
- the right to have any information you provided to us on an automated basis returned to you in a structured, commonly used and machine-readable format, or sent directly to another company, when technically feasible (“data portability”);
- where the processing of your information is based on your consent and the right to withdraw that consent is subject to legal or contractual restrictions;
- the right to object to any decisions based on the automated processing of your personal data, including profiling; and
- the right to lodge a complaint with the appropriate authority responsible for data protection matters. In the UK, thiis would be through the Information Commissioner’s Office.
If we hold any information about you that is incorrect or if there have been changes to your information, please let us know so that we are able to keep our records accurate and up to date.
If you withdraw your consent to the use of your personal information for purposes set out in our Privacy Notice, we may not be able to provide you with access to all or parts of our website, applications and services.
We will retain your personal information for the duration of our business relationship and afterwards for as long as is necessary and relevant for our legitimate business purposes in accordance with the Sage Group Data Retention, Marking and Destruction Policy or otherwise as permitted by applicable laws and regulations. When we no longer need your personal information, we will dispose of it in a secure manner without further notice to you.
7. Changes to our Privacy Notice
We may change this Privacy Notice from time to time. However we will not diminish your rights under this Privacy Notice. We will always update this Privacy Notice on our website, so please review this when you visit our website. The "last updated" mention lets you know when we last updated this Privacy Notice.
8. Security and storage of information
We will keep your information secure by taking appropriate technical and organizational measures against its unauthorized or unlawful processing and against its accidental loss, destruction or damage. We will do our utmost to protect your personal information, though we cannot guarantee the security of your information transmitted to our website, applications or services, as well as to other websites, applications and services via the internet or similar connection. If we have given you (or you have chosen) a password to access certain areas of our websites, applications or services, please keep this password safe – we will not share this password with anyone.
If you believe your account has been compromised, please contact us immediately at [email protected].
9. Transfers outside of the European Economic Area and the UK
Personal information in the European Union and the UK is protected by data protection laws but other countries do not necessarily protect your personal information in the same way.
Our website and some of our applications, services or parts of them may also be hosted in the United States or otherwise outside of the UK or the EEA (which means all the EU countries plus Norway, Iceland and Liechtenstein, together comprising thhe “EEA”). This means that we may transfer any information which is submitted by you through the website or the application or service outside the EEA to the United States or to other territories outside of the EEA. When you send an email to us, this will also be stored on our email servers hosted in the United States.
We may use service providers based outside of the EEA to help us provide our website, applications and services to you (for example, platform and payment providers who help us deliver our applications and services, or advertising or execute your payments) and this means that we may transfer your information to service providers outside the EEA for the purpose of providing our applications, advertising and services to you.
We take steps to ensure that where your information is transferred outside of the EEA by our service providers and hosting providers, appropriate measures and controls in place to protect that information in accordance with applicable data protection laws and regulations. For example, we may share information with our group companies or affiliates based outside the EEA for the purposes envisaged by this Privacy Notice. All Sage group companies are subject to Sage group data protection policies designed to protect data in accordance with EU data protection laws. In each case, such transfers are made in accordance with the requirements of Regulations (EU) 2016/679 (the General Data Protection Regulations or “GDPR”) and may be based on the use of the European Commission’s Standard Model Clauses for transfers of personal data outside the EEA.
By using our website, products, services or by interacting with us in the ways described in this Privacy Notice, you consent to the transfer of your information outside the EEA in the circumstances set out in this Privacy Notice. If you do not want your information to be transferred outside the EEA, you should not use our website, applications or services.
10. Other sites and social media
When clicking on and following an external link via our website, application or service to another site or service, this Privacy Notice will no longer apply. We are not responsible for the information handling practices of third party sites or services and we encourage you to read the privacy notices appearing on those websites or services.
Our websites, applications or services may enable you to share information on social media sites, use social media sites to create your account or to connect with your social media account. These social media sites may automatically provide us with access to certain personal information that they have already collected. For example, this may apply to content you may have already viewed on their platforms. You should be able to manage your privacy settings from within your own third party social media account(s) to manage what personal information you enable us to access from that account.
11. Cookies, analytics and traffic data
If you follow a link which takes you away from our website, our privacy notice does not apply when you arrive at your new online destination, and we are not responsible for the handling of your personal data after you have left our website. Please read the privacy information of the third party responsible for the new online location which you have linked to.
12. Further information
If you have any questions about how we handle your information, the contents of this Privacy Notice, your rights under local laws, how to update your records or how to obtain a copy of any personally identifiable information that we possess, please write to our Chief Data Protection Officer, at The Sage Group plc, C23 5 & 6 Cobalt Park Way, Cobalt Business Park, Newcastle-Upon-Tyne, Tyne & Wear, NE28 9EJ or send an email to [email protected]