Effective Date: December 16, 2020
Sage provides the provisioning portal and associated technology, such as landing pages, to enable Sage customers to access their Sage products and financial data in the cloud in Microsoft Azure (“Azure”) environments managed by Sage business partners (“Partners”).
This notice describes the relationship between The Sage Group plc or its affiliates (together “Sage,” “we,” “us,” and “our”), our Partners, and our end customers in the deployment of Sage products in Azure and the associated collection, use, disclosure, and retention of Partner and customer personal data.
Sage provides tools for Sage product deployment, user management, and accessing the Sage products deployed in Partner-managed Azure environments
We provide the Sage Provisioning Portal Services (the “SPP Services”), which include (1) the console for managing users and subscriptions, (2) the tools accessible through the console for setting up and managing users and resources (including, for example, virtual machines) in Partner-managed Azure environments and deploying the applicable Sage product(s) into these environments, and (3) the landing pages from which customers can access the Partners’ Azure environments. We do not provide or manage the actual Azure environment which contains the Sage product(s) and customer data.
To provide the SPP Services, we collect business contact information, such as name, business email, business phone number and business address. We use this personal information to enable user management in the SPP Services. Our enablement and support teams may have access to this personal information to set up users or provide customer support.
Users access the SPP Services using Sage ID. Sage ID enables users to log in to certain Sage products using a single set of credentials based on a user’s business email address. An SPP Services user will be prompted to create a Sage ID if her or she does not yet have one. Sage ID functions using a user’s business email address, a password, and a session cookie set on the user’s browser. We use a third-party service provider to help administer this functionality.
Some tools in the SPP Services involve email notifications sent to users to guide them through workflows. We use a third-party service provider to send the emails. This service provider may collect analytics information, such as whether an email was opened, as part of its service.
We retain the personal data collected through the SPP Services as described in the Sage privacy notice here:
https://www.sage.com/en-us/legal/privacy-and-cookies/. This privacy notice also tells you how you can contact us with privacy inquiries and describes rights of individuals regarding the personal data we collect and process.
We generally do not have access to “Customer Data,” which is the data that customers input, or have inputted on their behalf, into the Sage software products once deployed. This is because customers work with their Partners to configure and manage their Sage products and virtual machines in the Partner-managed Azure environments. However, a limited number of our operations personnel may have controlled access to Customer Data for troubleshooting and system maintenance.
Partners provide Azure environments, implement, configure, and manage customer sites on Azure, and are responsible for the privacy and security of their environments
Partners provide the Azure environments. This means that after a customer user signs into the landing page, selects his or her Sage product on the landing page and navigates into the Sage product, she or he is moving from a Sage-managed website (the landing page) to a Partner-managed environment (the Sage product hosted in a virtual machine on Partner’s Azure subscription). Sage provides tools for initial set up and configuration of virtual machines on a Partner’s Azure subscription (including tools for backing up Customer Data), as well as deploys the applicable Sage product in the Partner’s Azure environment. Once that initial process is completed for a customer, the Partner may further configure the customer’s environment, for example, by adding add-ons or third-party products that a customer has purchased.
Partners are responsible for the privacy, security, configuration, and maintenance of their Azure environments, as well as the resources (including, for example, virtual machines) deployed in them.
As part of the sales, implementation, and ongoing service relationship with the customer, Partners collect customer business contact data about personnel of their customers. Partners may use this information to add customer users in the SPP Services.
Partners generally have extensive access to Customer Data and may access, use, and disclose Customer Data in the course of setting up customer environments and providing ongoing support or services. Partners are responsible for their privacy practices. Customers should contact their Partners or refer to their Partners’ privacy policies for information about Partner processing of customer data.
Les parties conviennent et exigent expressément que cette Politique de confidentialité soit rédigée en anglais. The parties have expressly requested and required that this Privacy Notice be drawn up in the English language.