TestGate Privacy Policy
Principles
- Privacy is very important to us.
- We won't share your personal information or project data with anyone except to comply with the law, develop and monitor our products, or protect our rights.
- You retain all rights to, and we respect the confidentiality of, all the project data you store on the TestGate service.
- TestGate is compliant with the EU General Data Protection Regulation (GDPR) that is in effect from 25 May 2018.
What we collect and store
- TestGate collects and stores your name and email address when you sign up for the TestGate service.
- TestGate collects limited web session data and statistics as identified by HTTP cookies and browser requests. This data is stored in log files that are only retained for a limited period as required for the analysis and improvement of the TestGate service.
- TestGate stores project data submitted to TestGate as part of the service, mainly consisting of test cases and test results.
What we use it for
- The running of the service, including identification, authentication and monitoring.
- Deriving aggregated, anonymized, statistics and performance metrics.
- Maintenance, analysis and improvement of the TestGate service.
If you are a registered user of TestGate, we will use your email address to send you emails essential to your use of TestGate, for example when assigning Test Runs, or to invite new users to join your account. These emails cannot be opted out of, except by unsubscribing from TestGate and deleting your account.
Additionally, registered users of TestGate will be sent emails during the free trial period to help them get started with the TestGate application. Non-essential emails in this category can be opted out of using links in the footer. Essential emails (such as notification of expiry dates) cannot be opted out of except by deleting the TestGate account.
We may also occasionally send you an email to help you with your use of the TestGate service, to tell you about new features, solicit your feedback, or just keep you up to date with what's going on with TestGate Limited and our products. These emails include an unsubscribe link which you can use to stop receiving all non-essential communication.
What we will and won't disclose
We will never disclose personally identifying (or potentially personally identifying) information about you, or your project data, unless:
- it is to our employees, contractors or affiliated organisations that (i) need to know that information in order to process it on TestGate Limited's behalf or to provide services available at TestGate Limited's websites, (ii) that have agreed not to disclose it to others, and (iii) that are themselves GDPR compliant. Some of these employees, contractors and affiliated organizations may be located outside of your home country; by using TestGate Limited's websites, you consent to the transfer of such information to them.
- we have your permission
- we are required to do so by law
- we believe in good faith that disclosure is reasonably necessary to protect the rights of TestGate Limited, third parties or the public at large.
TestGate Limited will not rent or sell potentially personally-identifying and personally-identifying information to anyone.
We may share with other organisations, or make public, aggregated anonymous data derived from our stored data or statistics.
If you send us a message or request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users. Such publication will not disclose personally-identifying information, unless such information is intrinsic to the medium (for example, including a twitter handle when re-tweeting on twitter).
Where data is stored
TestGate is hosted on Amazon's cloud platform (AWS) and all TestGate-stored data is stored on AWS server instances, EBS volumes and S3.
TestGate uses Google Analytics to monitor and track the performance of the service. As for all sites using Google Analytics, this means that as users browse the TestGate website and make use of the TestGate service, their browsers will generate usage statistics that will be transmitted to and stored by Google Analytics. Google Analytics is itself GDPR compliant. Users and visitors of TestGate are therefore encouraged to read Google's Data Protection Compliance documentation.
TestGate uses the email-delivery service Postmark by Wildbit LLC to send emails to registered users of the TestGate service. As for all clients of Postmark, this means email addresses will be shared with and stored by Postmark for the sending of emails. TestGate users are therefore encouraged to read Wildbit's Privacy Policy and Wildbit's Postmark EU Data Protection information.
TestGate also uses the email-automation services provided by Userlist.io to send emails to registered users of the TestGate service. Email addresses will be shared with and stored by Userlist.io for the sending of emails on TestGate's behalf. TestGate users are therefore encouraged to read Userlist's Privacy Policy.
TestGate uses FastSpring to handle payments. All the data required for payments, including name, address and credit card information or other payment method details, are supplied to FastSpring on web pages served by FastSpring servers on behalf of TestGate. TestGate does not therefore process or store any personal data relating to payment details.
Users of TestGate are encouraged to read FastSpring's Privacy Policy and FastSpring's GDPR Compliance.
Access
Registered users of TestGate can view and edit the data that TestGate stores about them using the TestGate service itself.
Registered users of TestGate, who are the account owner of a team account, can download all the data that TestGate stores for their account as a ZIP of CSV data using the Account Export feature.
Subscribers of TestGate can contact FastSpring, Postmark (Wildbit LLC), or Userlist.io directly to request a copy of their personal data that these services are storing. Alternatively, subscribers of TestGate can make such requests to TestGate and TestGate will ask for this data on their behalf.
Deletion
Users of TestGate can unsubscribe and delete their accounts if they wish TestGate to delete their personal data. Alternatively, users can make a request to TestGate that this data be deleted, in which case TestGate will delete their TestGate Account (and all associated test plan/result data) for them.
When an account is deleted, email addresses may be retained by TestGate for possible future communications, such as notification of new features or services. If a user wishes to not receive such communication, they can use the unsubscribe link contained in all such communications. Email recipients who have unsubscribed will be stored by TestGate (and/or the relevant email processing third party, e.g. Postmark) so they can be identified as an email address that does not wish to receive further communications. If a user would prefer to be completely forgotten, then they can make a direct request of TestGate who will ensure that both TestGate and any third parties delete their data. Such users might then receive future communication if they later (re)provide their email address.
HTTP Cookies
A cookie is a string of information that a website stores on a visitor's computer, and that the visitor's browser provides to the website each time the visitor returns. The operation of the TestGate service relies on cookies for user login (the sessionid cookie) and form data security (the csrftoken cookie). If these cookies are deleted, or disabled, continued use of TestGate is not possible.
TestGate also uses third party cookies from Google Analytics (the cookies with names that begin __utm...). These are used for usage statistics and analysis for the monitoring and improvement of the TestGate service. TestGate does not use Google Analytics "User ID" feature.
TestGate's usage of Google Analytics is basic enough that the GDPR legislation does not require an explicit opt-in from users of TestGate. Nevertheless, users can block Google's cookies using browser settings or plugins.
Business Transfers
If TestGate Limited, or substantially all of its assets were acquired, or in the unlikely event that TestGate Limited goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of TestGate Limited may continue to use your personal information as set forth in this policy.
Privacy Policy Changes
TestGate Limited may change its Privacy Policy from time to time, and at TestGate Limited's sole discretion. TestGate Limited encourages visitors to frequently check this page for any changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change.
Updated 10 March 2019.