Effective date: May 25, 2018
Welcome to the Webflow, Inc., (hereinafter, “Webflow,” “Company,” “us,” “our,” or “we”) EU & Swiss Privacy Policy (the “Policy”).
This Policy governs our information-handling practices as applicable to residents in the European Union (“EU”), European Economic Area (“EEA”), and Switzerland (collectively, the “Data Subjects”) that are visiting our website, www.webflow.com, and the other websites under the webflow.com domain (collectively, the “Sites”), or are customers who use our SaaS product, web design software, tools, and related services (together with the Sites, the “Service”).
This Policy explains how we collect, use, disclose, and protect Data Subjects’ information as part of the Service in accordance with data-protection laws in the EU, EEA, and Switzerland (collectively the “Data Protection Laws”). Any discussion of your use of the Service in this Policy is meant to include your visits and other interactions with the Sites and Services, whether or not you are a user of Webflow’s SaaS product.
Capitalized terms that are not defined in this Policy have the meaning given them in our Terms of Service or Global Privacy Policy.
By accessing and using the Service, you signify your acceptance to the terms of this Policy. If you do not agree with or you are not comfortable with any aspect of this Policy, our Global Policy or the Terms of Service, you should immediately discontinue access or use of our Services. In the event of a conflict between the Global Privacy Policy and this Policy, this Policy supersedes the Global Privacy Policy.
In order for you to understand Webflow’s data protection obligations and your rights to your Personal Information under this Policy, it is important that you identify which relationship(s) you have with Webflow.
Hereinafter we may refer to Customers and Users collectively as “you.”
Webflow provides notice to you through posted privacy policies and may provide additional "just-in-time" disclosures about the data collection, use, and sharing practices of specific Services. The Global Privacy Policy generally describes our privacy practices, while this Policy is specific to Users and Customers located in the EU, EEA, and Switzerland while using our Services. This Policy describes how we process Personal Information from the EU, EEA, and Switzerland in accordance with Privacy Shield and applicable data protection law.
As a data processor, Webflow is not able to provide notice to or obtain consent from Customer End Users. To the extent required by law, Webflow supports Customers’ data-protection compliance efforts, but it is up to the Customer to ensure the appropriate data protection safeguards are in place before processing Personal Information from Customer End Users.
As described in the Global Privacy Policy, Webflow collects various types of Personal Information about you while you are using the Services. Information that is anonymized or aggregated is not “Personal Information.”
In general, we collect the following types of Personal Information:
Any information that is disclosed in the forums or our blog becomes public information. This means that your posts are available to the public and may appear in search engines or other publicly available platforms, and may be “crawled” or searched by third parties. Your public posts can also be read, collected, or used by others to send you unsolicited messages. Be careful when posting on public parts of our Services and do not post any information that you are not comfortable sharing publicly.
Under the Data Protection Laws, we are required to notify you about our purposes of processing your Personal Information, as well as the legal basis for such processing.
Unless otherwise permitted by law, we may process your Personal Information:
To ensure network and information security.
We process your Personal Information to:
Without processing your Personal Information, we may not be able to ensure the security of our Services.
Processing is necessary for compliance with a legal obligation.
To enforce Webflow’s terms and agreements.
We have Terms of Service and other policies that define how you can use our Services. To ensure that you and others are using our Services in accordance with such terms and policies, we may process your Personal Information to:
We collect information about your account usage and monitor your interactions with our Services. We may use any of your Personal Information collected on our Services for these purposes. The consequences of not processing your Personal Information for such purposes is the termination of your account, as we cannot perform our Services in accordance with our terms.
Processing is necessary for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract.
To provide our Services.
We process your Personal Information to provide the Services. For example, when you want to bill a client for your work, we collect registration, financial, transaction, and interaction data to send the bill to the client and obtain payment. We cannot provide you with Services without such information.
Processing is necessary for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract.
To provide Service communications.
We may reach out to you to send you administrative or account-related information to keep you in the loop about our Services, alert you of relevant security issues or updates, or provide other transaction-related information to you. While we generally use your registration data for this purpose, we may send personalized Service communications to you based on other Personal Information, such as interaction, payment, or transaction data. Without such communication, you may miss out on important developments relating to your account that may affect how you can use our Services.
Processing is necessary for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract.
To ensure quality control.
We process your Personal Information for quality control and staff training to make sure we continue to provide you with accurate information. Without our quality-control measures, you may experience issues while using the Services. For example, you may not be able to bill clients accurately or in a timely fashion, or you may encounter interruptions on our Services.
Processing is necessary for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract.
To provide customer service.
When you contact our customer service channel, we process your Personal Information to respond to your questions, disputes, feedback, or issues with our Services. We may process your Personal Information in response to another customer’s request, as relevant. Without processing your Personal Information for such purposes, we cannot respond to your requests.
Processing is necessary for the performance of a contract to which the Data Subject is party or to take steps at the request of the Data Subject prior to entering into a contract.
To enhance your experience on our Services.
We process your Personal Information to provide a personalized experience on our Services and to implement your feedback or the preferences you request. For example, you may share parts of your social media account information with us for authentication. Without such processing of your Personal Information, we may not be able to ensure your continued enjoyment of part or all our Services.
Processing is necessary for the purposes of the legitimate interests pursued by Webflow.
For research and development purposes.
We process your Personal Information to better understand you and the way you use and interact with our Services. For example, interaction data can provide helpful insights that assist us with measuring, customizing, or improving current Services. In addition, such information can help us develop new Services for your enjoyment. Without such processing, we cannot ensure your continued enjoyment of our Services.
Processing is necessary for the purposes of the legitimate interests pursued by Webflow.
To facilitate acquisitions, mergers, or other business transactions.
We may process any of your Personal Information as is necessary in the context of acquisitions, mergers, or other business transactions. We will try to notify you in advance if we intend to process your Personal Information for this purpose. You will have the option of terminating your account if you do not wish to have your Personal Information processed for such purposes.
Processing is necessary for the purposes of the legitimate interests pursued by Webflow.
To engage in marketing activities.
We may send you marketing communications from time to time. Such marketing communications may contain information about our events, partner events, or promotional offers. We may use your interaction and/or transaction data to provide you with targeted marketing communications. You can opt out of our marketing communications at any time and free of charge.
Processing is based Processing is necessary for the purposes of the legitimate interests pursued by Webflow.
We will only use your Personal Information for the purposes above or for compatible purposes.
If we wish to share your Personal Information with third parties that are not described in this Policy or the Global Privacy Policy, we may request your permission as required by Data Protection Law. You may opt out of having your Personal Information shared with third parties, or from allowing us to use your Personal Information for any purpose that is incompatible with the purposes for which we originally collected it or subsequently obtained your authorization. However, if you limit the way we use your Personal Information, certain features or Services may not be available to you.
We only collect Personal Information about you from third parties that you voluntarily choose to connect with our Services. For example, you can share Personal Information with us when you access our Site or Service through a third-party connection, or when you log in or connect an application to Webflow. We process this information for the purposes of performance of our contracts with you. For more information, please see Section 2(c) of the Global Privacy Policy.
Webflow conducts the majority of data processing activities required to provide you with the Services. However, we do engage third-party service providers to assist with supporting our Services, including vendors in the following areas:
Each service provider is vetted and bound by contractual obligations that are equivalent to the provision of this Policy or more stringent. See the “Accountability for Onward Transfers” section below for more information about our agreements with third parties.
We are committed to keeping your Personal Information secure on our Services. We limit our storage of your Personal Information to the amount of time necessary to fulfil the purposes for which we collected the Personal Information, including for the purposes of satisfying any legal, accounting, or reporting obligations, or to resolve disputes. Although retention laws and requirements vary by jurisdiction, we have some standard retention periods for parts of your Personal Information which are described below:
If you have questions about retention periods that apply to any other data, please contact us at privacy@webflow.com.
Webflow uses approved data transfer mechanisms to transfer your Personal Information in and out of the United States and other jurisdictions. We rely on European Commission–approved Standard Contractual Clauses as a legal mechanism for any data transfers from the U.S. to a country outside the EU, EEA, or Switzerland to the extent that any such transfers occur.
In relation to transfers of Personal Information to the U.S., Webflow participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (hereinafter, the “Framework” or “Privacy Shield”) as set forth by the U.S. Department of Commerce regarding the collection, use, disclosure, and retention of Personal Information transferred from the EU, EEA, and Switzerland to the United States. Webflow has certified to the Department of Commerce that it adheres to the Privacy Shield Principles.
This EU & Swiss Privacy Policy and the Webflow Global Privacy Policy describe Webflow’s privacy practices. In the event there is a conflict between the terms in the Global Privacy Policy and this Policy, this Policy shall govern for any conflicts related to EU, EEA, or Swiss data subjects. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.
Webflow complies with the Privacy Shield Principles and the Data Protection Laws for all onward transfers of Personal Information from the EU, EEA, and Switzerland, including the onward transfer liability provisions. Webflow contractually obligates third-party agents or service providers to provide the same level of protection as required by the Privacy Shield Framework and under the Data Protection Laws. In addition, we limit and specify the purpose(s) for processing your Personal Information consistent with any notice provided to you and your consent.
Upon request by the United States Department of Commerce, Webflow will provide a summary or representative copy of the relevant privacy provisions of its agreement with a third-party agent.
In certain situations, Webflow may be required to disclose your Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, to comply with a judicial proceeding or court order, or as otherwise required by law.
We are committed to ensuring the security of your Personal Information by using reasonable and appropriate physical, electronic, and administrative safeguards. Please refer to Section 6 of the Global Privacy Policy for more detailed information about our security safeguards.
Direct marketing includes any communications to you that are only based on advertising or promoting products and services. Transactional communications about your account or our Services are not considered “direct marketing” communications.
We will only contact Customers by electronic means (including email) based on our legitimate interests or the Customer’s consent. When we rely on legitimate interest, we will only send you information about our Services that are similar to those which were the subject of a previous sale or negotiations of a sale to you.
If you do not want us to use your Personal Information in this way, or to pass your Personal Information on to third parties for marketing purposes, please go to the email settings for your account to opt out, click an unsubscribe link in your emails, or contact us at privacy@webflow.com. You can object to direct marketing at any time and free of charge.
You have the rights to your Personal Information that are described below. You can exercise your rights by contacting us at privacy@webflow.com so that we may consider your request under applicable law. When we receive an individual rights request via email, we may take steps to verify your identity before complying with the request to protect your privacy and security.
Your rights to your Personal Information are not without limits. Access may be denied when:
We will investigate and work expeditiously to resolve any complaints or disputes in accordance with this Policy and the Privacy Shield Framework. If you have an inquiry or complaint regarding our privacy policies or practices, please contact us first at privacy@webflow.com.
If you have an unresolved complaint or dispute arising under the requirements of the Privacy Shield Framework, we agree to refer your complaint under the Framework to an independent dispute resolution mechanism free of charge. Our independent dispute resolution mechanism is JAMS. For more information and to file a complaint, visit the JAMS website. We are also subject to the investigatory and enforcement powers of the Federal Trade Commission with respect to the Framework.
Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.
You have also a right to lodge a complaint with a competent supervisory authority situated in a Member State of your habitual residence, place of work, or place of alleged infringement.
We recognize that some Data Protection Laws vary based on the age of consent. Depending on the jurisdiction, the age of consent can be between 13 to 16 years old. We do not knowingly request to collect Personal Information from any Data Subject under the age of consent as defined by the jurisdiction in which the Data Subject resides. If we are aware of or suspect that a Data Subject is under the age of consent, we will require the Data Subject to terminate their account. We will also take steps to delete the information as soon as possible. Please notify us if you know of any individuals under the age of consent using our Services.
We may change this Policy at any time and the changes will apply to any Personal Information we already hold and to any new Personal Information collected after the change occurs. If we make any material changes to this Policy, we will endeavor to notify you by email or by posting a prominent notice on the Services prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of our Services after the effective date of this Policy constitutes an acceptance of the amended terms. You may refer to the “Last Updated” date of this Policy to determine if the Policy has changed since the date of your last visit.
If you have any questions regarding this Policy or about the privacy practices of Webflow, please contact us by email at privacy@webflow.com, or at:
Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103