Virginia Privacy Notice Addendum
Table of contents
This section supplements the Privacy Notice and applies only to Virginia residents. If you are a Virginia resident, the Virginia Consumer Data Protection Act – Va. Code Ann. §§ 59.1-575 to 59.1-584 (“VCDPA”) provides you with specific rights regarding your personal data, subject to certain exceptions. We collect the type of data described in this Virginia Privacy Notice Addendum and in the Privacy Notice, which includes personal data and sensitive data, as defined by the VCDPA, in the manner described herein and in the Privacy Notice. VCDPA defines “Personal Data” as any information that is linked or reasonably linkable to an identified or identifiable natural person. Personal Data does not include de-identified data or publicly available information. Personal Data that is excluded from the scope of the VCDPA includes:
- covered entities or business associates covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and related federal laws and regulations, clinical trial data, or other qualifying research data;
- personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or the Farm Credit Act, and the Driver’s Privacy Protection Act of 1994;
- information collected from governmental organizations, non-profit organizations and higher education institutions; and
- data processed or maintained for employment purposes including emergency contact information or benefits administration.
If you do not provide the information that we ask for, we may not be able to provide you with the requested services. Sensitive data is a category of Personal Data that requires greater security protections and standards of care in handling. “Sensitive Data” is defined by the VCDPA as (1) Personal Data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; (2) the processing of genetic or biometric data for the purpose of uniquely identifying a natural person; (3) the personal data collected from a known child; or (4) precise geolocation data. Subject to limited exceptions, we will only process your Sensitive Data with your consent.
If you are a Virginia resident the VCDPA provides you with specific rights regarding your Personal Data, subject to certain exceptions. These rights are explained below:
- Right against Retaliation or Discrimination. You have the right not to be retaliated or discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your rights.
- Right to Access. Subject to certain exceptions, you have the right to confirm whether we are processing your data and you have the right to access such Personal Data.
- Right to Delete. You have the right to request that we delete any of the Personal Data we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete and will direct our service providers to delete your Personal Data from our records, unless an exception applies. Please click here to learn more about the limitations that may apply to your request.
- Right to Correct. In certain circumstances and upon the receipt of a verifiable consumer request, you have the right to request that PandaDoc correct any inaccurate Personal Data PandaDoc maintains about you. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your Personal Data as directed, taking into account the nature of the Personal Data and the purposes of maintaining your Personal Data.
- Right to Opt-Out of Sale or Use of Your Personal Data for Targeted Advertisement. You have the right to opt-out of having your Personal Data, including Sensitive Data, sold and/ or used for targeted advertising. For clarity, PandaDoc does not sell Personal Data or Sensitive Data for monetary consideration. If you wish to opt-out of selling of your Personal Data, please click here to be redirected to our “Do Not Sell My Personal Data” page.
- Right to Data Portability.You have the right to obtain a copy of your Personal Data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller without hindrance, where the processing is carried out by automated means.
- To assert your rights, please contact us as set forth below.
- To confirm your identity, it is imperative that we verify the consumer request and so you must provide information that allows us to reasonably verify that you are the person about whom we collected the Personal Data or are an authorized representative. If you make a request on behalf of another person, we will need to verify that you have the authority to do so. You must also describe the request with sufficient detail that allows us to properly understand, evaluate and respond to such request. We cannot respond to your request or provide you with Personal Data if we cannot verify your identity or authority to make the request and confirm the Personal Data relates to you. We will not honor your request if an exception to the law applies.
- We will respond to requests within forty-five (45) days after our receipt of such verifiable request (or within such other time as required by applicable law). If we need additional time, we will notify you in writing prior to the expiration of the forty-five (45) day period and inform you of the reason for an additional forty-five (45) day extension of time. For the avoidance of doubt, any such requests for Personal Data will cover the twelve (12) month period immediately preceding the date of such verifiable request and such requests can be made up to twice annually per consumer. Disclosure of Personal Data in response to such a request will be provided free of charge and in a commonly used format. For more information about requests, please see the “Your rights and controlling your personal information” section of the Privacy Notice.
To exercise any of your rights, please click here or you can also send a request in writing to PandaDoc, Inc., Attention: Privacy Department, 3739 Balboa St. #1083, San Francisco, CA 94121.
To exercise your personal privacy rights, please click below for the applicable location:
Within sixty (60) days of receipt of your appeal, we will inform you in writing of any action taken or not taken in response to your appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you may also contact the Attorney General here to submit a complaint.