Oversight End User Privacy Notice
This privacy notice (“Notice”) provides information on the collection, use, sharing and processing of Personal Data by Oversight Systems, Inc. (“Oversight”) in connection with your use of Oversight’s Service on behalf of one of Oversight’s clients.
We may have links on our website to other websites we do not operate. If you click on a third-party link, you will be taken directly to that site which is governed by its own privacy notice. We strongly encourage you to read that privacy notice. We do not control that site and assume no responsibility for the content, policies or its practices.
This Notice was last updated January 25, 2024. We may periodically change or update this Notice to comply with legal requirements or changing business needs, so we encourage you to come back and read it periodically.
What is Personal Data
“Personal Data” means data that can be used to identify an individual. Personal Data we may collect includes:
- Name
- Email address
- Email content
- Phone number
- Company, Job title/Role
- Information on your use of the Service
Like many websites, we collect certain information automatically and store it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information.
The following sensitive Personal Data is prohibited in the Service so it should not be sent or uploaded to Oversight or the Service: social security or national identification numbers, information related to racial or ethnic origin, political opinions, religious beliefs, health data, biometrics or genetic information, criminal background or trade union membership information.
Using your Personal Data
The information that we process relating to you is used for providing the Service to your employer and tracking support requests. Oversight relies on our contractual obligations and legitimate interest as the lawful grounds to collect and process Personal Data.
Selling, Sharing and Disclosure of your Personal Data
We may disclose your Personal Data to our service providers or other members of your employer as part of providing the Service. This disclosure may also be required to enable your access to and use of our Service, to comply with our legal and contractual obligations to your employer, to enforce our Agreement, or to prevent, detect, mitigate, and investigate fraudulent or illegal activities related to our Service. We may also disclose Personal Data to law enforcement and in legal proceedings (as governed and restricted by the contract between us and your employer), and as authorized by law. We do not sell or rent your personal information to third parties.
Choices and Individual Rights
As an employee or client-approved third party, your employer exercises choice in how Oversight uses your Personal Data and at their direction Oversight supports them in responding to individual rights requests. (See Data Controllers, Data Processors, and Data Subject Rights below).
Ways you can access and correct your Personal Data
You may be able access and change some of your Personal Data by signing into the Oversight Service Portal. Please update your Personal Data immediately if it changes or is inaccurate. If you are not able to update your information directly, please log a helpdesk ticket to receive prompt assistance.
Security
Oversight has implemented appropriate physical, technical, and organizational measures and safeguards with respect to Personal Data designed to protect against accidental or unlawful destruction or accidental loss, alteration, and unauthorized disclosures or access.
Location and Retention
Your Personal Data is stored by Oversight on its servers located either in the United States or the European Union. Oversight will retain your Personal Data in the Service (excluding our support systems) only for as long as is necessary for the purposes set out in this Notice.
Cookies
For you to access and use the Service (Portal / Workbench / Dashboard) we require the use of session cookies. Although some of these session cookies contain a unique identifier that may be linked to Personal Data on the Oversight server, the session cookies are removed after you exit the Service and close your browser tab. For users accessing Oversight’s Service Desk ticketing website, cookies are used for session tracking, remembering login information, navigation, etc. Disabling cookies related to the Service or Service Desk will impact its functionality.
Oversight Portal
Cookie Name |
Cookie Controller |
Cookie Purpose |
AUTH_SESSION_ID |
Oversight |
Authentication/Session Management |
AUTH_SESSION_ID_LEGACY |
Oversight |
Authentication/Session Management |
dtCookie |
Oversight |
Performance Monitoring |
dtPC |
Oversight |
Performance Monitoring |
dtSa |
Oversight |
Performance Monitoring |
ESCP_AUTH_SESSION_ID |
Oversight |
Security |
ESCP_AUTH_SESSION_ID_LEGACY |
Oversight |
Security |
ESCP_JSESSIONID |
Oversight |
Security |
ESCP_KC_RESTART |
Oversight |
Security |
ESCP_KEYCLOAK_IDENTITY |
Oversight |
Security |
ESCP_KEYCLOAK_IDENTITY_LEGACY |
Oversight |
Security |
ESCP_KEYCLOAK_LOCALE |
Oversight |
Security |
ESCP_KEYCLOAK_REMEMBER_ME |
Oversight |
Security |
ESCP_KEYCLOAK_SESSION |
Oversight |
Security |
ESCP_KEYCLOAK_SESSION_LEGACY |
Oversight |
Security |
ESCP_XSRF-TOKEN |
Oversight |
Security |
JSESSIONID |
Oversight |
Session Management |
KC_RESTART |
Oversight |
Authentication/Session Management |
KEYCLOAK_IDENTITY |
Oversight |
Authentication/Session Management |
KEYCLOAK_IDENTITY_LEGACY |
Oversight |
Authentication/Session Management |
KEYCLOAK_LOCALE |
Oversight |
Authentication/Session Management |
KEYCLOAK_REMEMBER_ME |
Oversight |
Authentication/Session Management |
KEYCLOAK_SESSION |
Oversight |
Authentication/Session Management |
KEYCLOAK_SESSION_LEGACY |
Oversight |
Authentication/Session Management |
rxVisitor |
Oversight |
Performance Monitoring |
rxvt |
Oversight |
Performance Monitoring |
XSRF-TOKEN |
Oversight |
Security |
Oversight Workbench Users
Cookie Name |
Cookie Controller |
Cookie Purpose |
dtCookie |
Oversight |
Performance Monitoring |
rxVisitor |
Oversight |
Performance Monitoring |
dtSa |
Oversight |
Performance Monitoring |
rxvt |
Oversight |
Performance Monitoring |
dtPC |
Oversight |
Performance Monitoring |
ESCP_XSRF-TOKEN |
Oversight |
Security |
XSRF-TOKEN |
Oversight |
Security |
Oversight Dashboard Users
Cookie Name |
Cookie Controller |
Cookie Purpose |
JSESSIONID |
Tableau |
Session Management |
workgroup_session_id |
Tableau |
Session Management |
XSRF-TOKEN |
Tableau |
Security |
hid |
Tableau |
Routing client requests on the server |
AWSELB |
Tableau |
Load Balancing |
Data Controllers, Data Processors, and Data Subject Rights
For the Oversight Service (excluding our support systems), your employer is the data controller and determines the purposes and means of the processing of your Personal Data. Oversight is a data processor and processes your Personal Data on behalf of and at the direction of the data controller. If you wish to exercise any of your rights with regards to your Personal Data within Oversight’s Service, you must contact your employer. Any requests made directly to Oversight will be forwarded to your employer for further action.
Your right to file complaints under applicable data protection laws remains unaffected by this Notice.