Privacy Statement (original) (raw)

Table of contents

Scope of this Privacy Statement

Red Hat, Inc. and its affiliated companies and subsidiaries (collectively, “Red Hat”) respect your privacy. This Privacy Statement applies to personal data collected by Red Hat through the redhat.com website, and other websites which we operate and on which we post a direct link to this Privacy Statement. For some websites managed by Red Hat affiliates, the affiliate may act as a controller for data collected from the website. This Privacy Statement may not apply to open source project websites sponsored by Red Hat. Such project websites may have their own privacy statements, which we encourage you to review. In certain cases, this Privacy Statement applies to personal data collected by Red Hat when Red Hat makes this Privacy Statement or a link to the Privacy Statement available in a digital communication, paper form or in person (for example when attending an event).

Please also note that co-branded websites (websites where Red Hat presents content together with one or more of our business partners) may be governed by additional or different privacy statements. Please refer to the privacy statement on those websites for more information about applicable privacy practices.

Red Hat’s obligations with respect to personal data that may be held on behalf of customers in connection with cloud services Red Hat provides, such as personal data stored by customers using our OpenShift Online offering, are defined in our agreements with our customers and are not governed by this Privacy Statement.

As used in this Privacy Statement, “personal data” means any information that relates to, is capable of being associated with, describes, or could be linked to, an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Back to top

The Categories of Personal Data We Collect

To the extent permitted by applicable law, the categories and types of personal data collected directly from you may include, without limitation:

Red Hat generally does not collect sensitive personal data, which is data such as your religious or philosophical beliefs, racial or ethnic origin, health or medical information (other than for the purpose of responding to an accommodation request for an event), genetic or biometric data, bank account information (other than for the purpose of processing your order) or other similar sensitive personal data as such term is defined under applicable law. If Red Hat reasonably needs to collect any sensitive personal data from you, Red Hat will obtain your consent for the collection of such personal data as may be required under applicable law. For California consumers, please see the California Supplemental Privacy Statement to review the California required disclosures on sensitive personal information.

How we collect personal data (sources of data)

Red Hat collects personal data directly from you and from other categories of sources as described in more detail below. The categories of personal data collected directly from you by Red Hat include all of the categories identified above in “The categories of personal data we collect” section. Red Hat collects personal data directly from you when you interact with us through our websites, including, without limitation, when you:

Personal data we collect online may also be combined with personal data you provide to us through offline channels such as through a call center, during an interview or in conjunction with a Red Hat event you attend.

We may also collect information indirectly from you relating to your use of our websites and response to our emails through the use of various technology. The categories of personal data collected in this manner are what we refer to above as Internet or other similar network activity and inferences. Collecting information in this manner allows us to analyze the effectiveness of our websites and our marketing efforts, personalize your experience and improve our interactions with you. For more information about the technology we employ for these purposes, see the “cookies and other technology” section below.

We may also supplement the personal data we collect from you with additional personal data we receive from third parties, such as your employer, our customers, and our business partners where you purchase any of our products or services through such business partners. The categories of personal data we receive from this type of third party includes account and commercial information and professional or employment-related information. We do this to help us improve the overall accuracy of the information and its completeness and to help us better tailor our interactions with you.

From time to time, we may collect contact information through other sources, such as list vendors. When we do so, we ask the vendors to confirm that the information was legally acquired by the third party and that we have the right to obtain it from them and use it.

Back to top

How we use (process) your personal data

Red Hat may use personal data we collect about you to:

If you are in the People’s Republic of China (PRC, for the purpose of this Privacy Statement only, excluding Hong Kong, Macau and Taiwan), the information necessary for entering into or performing a contract with Red Hat may be collected and processed by Red Hat without your express consent or the act of providing the information to Red Hat by you is deemed as consent.

We will not use your personal data in a manner that is inconsistent with the purpose of its original collection, unless we have provided you additional notice and you have consented.

Red Hat will retain your personal data for only as long as is required to fulfill the purposes for which the information is processed or for other valid reasons to retain your personal information (for example to comply with our legal and regulatory obligations, resolve disputes, enforce our agreements and for the establishment, exercise or defense of legal claims).

Back to top

How we disclose your personal data

Red Hat discloses personal data for the following business purposes:

We do not sell personal data as the term sell is commonly understood. Under certain Data Protection Laws, a “sale” is defined to include disclosures of personal data to a third party for monetary or valuable consideration. When you use Red Hat websites, Red Hat’s authorized partners, such as advertising networks, data analytics providers, social networks and advertising partners, may collect cookies and similar technology and use this data (such as your Internet or other similar network activity) for their own purposes, such as improving their own services. This activity may qualify as a “sale” under applicable Data Protection Laws. You can make choices to allow or prevent such uses (see the Cookies and Other Technology section below on how to manage your cookie preferences). For California consumers, please see the California Supplemental Privacy Statement for more information.

Back to top

Cookies and other technology

When you visit our websites we may automatically collect information such as your IP address, browsing history, information on your interaction with the website, browser type and language, operating system, location, date and time (i.e., the category above referred to as Internet or other similar network activity). We may also use cookies to collect information as you navigate our websites. A cookie is a small amount of data that is sent to your browser from a web server and stored on your device. The cookie may be placed by Red Hat or by an authorized third party. We use both session-based and persistent cookies on our websites. Session-based cookies exist during a single session and disappear when you close your browser or turn off your device. Persistent cookies remain on your device even after you close your browser or turn off your device.

Red Hat categorizes the cookies on our websites into three categories: Required, Functional and Advertising cookies.

If you do not want your information to be stored by cookies, you can manage your cookie preferences by using the options and tools made available to you by either your web browser or Red Hat. You can configure your browser so that it always rejects these cookies or asks you each time whether you want to accept them or not. Your browser documentation includes instructions explaining how to enable, disable or delete cookies at the browser level (usually located within the “Help”, “Tools” or “Edit” facility). If you have set your browser’s global privacy settings (such as selecting “Do Not Track”), then we recognize the global privacy settings from your browser to signal your choice to opt-out of “sales” and targeted advertising as appropriate under applicable Data Protection Laws. If a cookie manager has been implemented by Red Hat on the website you are visiting, the cookie tool will be displayed on the website during your visit (e.g., click the “Cookie Preferences” or similar link at the bottom of the website). You can use the cookie manager to set your cookie preference and to see a list of the cookies used on the Red Hat website. The cookie manager also provides information on the specific cookies used and the classification of the cookie (i.e., Required, Functional or Advertising). Whether you utilize the cookie manager or manage cookies at the individual browser level, please remember that Required cookies will remain and cannot be turned off. Please also understand that choosing to reject cookies may reduce the performance and functionality of our websites.

Red Hat also uses web beacons alone or in conjunction with cookies to compile information about usage of our websites and interaction with emails from Red Hat (e.g., open rates, click through rates). Web beacons are clear electronic images that can recognize certain types of information on your device, such as cookies, when you viewed a particular website tied to the web beacon, and a description of a website tied to the web beacon. For example, Red Hat may place web beacons in marketing emails that notify Red Hat when you click on a link in the email that directs you to one of our websites. Red Hat uses web beacons to operate and improve our websites and email communications.

Back to top

Your rights and choices

In accordance with the laws of certain countries, you may have certain rights and choices regarding the personal data we collect and maintain about you, and how we communicate with you.

Where the EU General Data Protection Regulation 2016/679 (“GDPR”), the Brazilian General Data Protection Law (“LGPD”), the California Consumer Privacy Act of 2018 (“CCPA”) (as amended by the California Privacy Rights Act of 2020 (“CPRA”)), the Colorado Privacy Act (“CPA”), the Connecticut Public Act No. 22-25 (the Connecticut Data Privacy Act or “CTDPA”), the Personal Information Protection Law (“PIPL”) of the PRC, the Virginia Consumer Data Protection Act (“VCDPA”) or similar legal requirements apply to the processing of your personal data (collectively, “Data Protection Laws”), especially when you access the website from a country in the European Economic Area (“EEA”), Brazil, the PRC or as a consumer in a U.S. state or in a jurisdiction with similar legal protections, you have the following rights, subject to some limitations, against the respective Red Hat Company responsible for the website you are using:

If you would like to exercise any of these rights, you may do so via our Personal Data Request Form. For U.S. consumers, you may also submit requests by calling Red Hat’s U.S. toll free number at 1-800-546-7274. Where the applicable Data Protection Laws provide a right to appeal, and we inform you that we are unable to take action in response to your request to exercise your rights, you may appeal our decision within a reasonable period of time following our decision. To submit your appeal, please do so by selecting "Other" via our Personal Data Request Form or by emailing privacy@redhat.com.

Where the applicable Data Protection Laws apply, you also have the right to withdraw any consent you have given to uses of your personal data. If you wish to withdraw consent that you have previously provided to us, you may do so via our Personal Data Request Form. However, the withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

Where the applicable Data Protection Laws do not apply, Red Hat grants you the ability to access, modify, or update some of your personal data online at any time. You may log in and make changes to your information, such as your password, your contact information, your general preferences, and your personalization settings. If necessary, you may also contact us via our Personal Data Request Form and describe the changes you want made to the information you have previously provided. However, note that changing or deleting information necessary for Red Hat to assist with support, services, and purchases may result in a delay or interruption in processing your requests.

You will be given an opportunity to tell us whether you would like to receive information, special offers, and promotional materials by email from Red Hat or our business partners when you create a redhat.com account, when you register for a service, when you provide us with your personal data, or when we send you a marketing email. Where required by applicable law, we will obtain adequate consent to provide you with these marketing materials. You also have the ability to opt out of receiving marketing emails from Red Hat at any time without cost by clicking on the relevant link contained in our marketing emails or by contacting us via our Personal Data Request Form. You can also exercise your rights and choices by contacting us as described below under “How to contact us.”

When you exercise your privacy rights, such as those conferred by the applicable Data Protection Laws, you have a right not to receive discriminatory treatment by Red Hat for the exercise of such privacy rights.

Back to top

Verification

Before responding to a request for information about your personal data, we must verify the request. Verification is important to protect your information and to help confirm that we are responding to a valid request and providing the response to the correct individual. To verify the request we initially ask for at least two (2) or three (3) identifiers, such as name, email address and location. If we have a need to request additional identifiers to reasonably verify your identity, we will contact you and request additional verification. The information we ask to verify your identity may depend on your relationship with us.

When you exercise your privacy rights under the applicable Data Protection Laws, you can designate an authorized agent or representative to make a request on your behalf by providing the authorized agent with written permission to do so and verifying your identity with us as part of the request, or by providing the authorized agent with Power of Attorney pursuant to applicable law (e.g., the California Probate code). We will ask the individual submitting the request to denote that they are an authorized agent or representative. When submitted by an authorized agent or representative, we ask the authorized agent or representative to provide name, email address and a description of the relationship with the individual who is the subject of the request and to certify that the representative has permission to submit the request, and may request proof of the consumer’s written permission.

Back to top

Security

Red Hat intends to protect your personal data. We have implemented appropriate physical, administrative and technical safeguards to help us protect your personal data from unauthorized access, use and disclosure. For example, we encrypt certain personal data such as payment information when we transmit such information over the Internet. We also require that our business partners and service providers protect such information from unauthorized access, use and disclosure.

Back to top

Red Hat may provide social media features that enable you to share information with your social networks and interact with Red Hat on various social media websites. Your use of these features may result in the collection or sharing of information about you, depending on the feature. We encourage you to review the privacy policies and settings on the social media websites with which you interact to make sure you understand the information that may be collected, used, and shared by those websites.

Our websites may make chat rooms, forums, blogs, message boards, and/or news groups available to its users. Remember that your comments and posts become publicly available, and we urge you to exercise discretion when submitting such content.

Our websites may contain links to other websites. Red Hat does not control and is not responsible for the information collected by websites that can be reached through links from our websites. If you have questions about the data collection procedures of linked websites, please contact the organizations that operate those websites directly.

Back to top

Children's online privacy

Red Hat’s products and services are not directed to children and Red Hat does not knowingly collect online personal data from children under the age of 16. If you are a parent or guardian of a minor under the age of 16 and believe that he or she has disclosed personal data to us, please contact us via our Personal Data Request Form or as described below under “How to contact us.” Red Hat will ensure their personal data is properly processed and disposed of with the consent of their parent or guardian.

Back to top

Data transfers and Data Privacy Frameworks

Red Hat is a global organization, with legal entities, business processes, and technical systems that operate across borders. Red Hat may transfer your personal data to other Red Hat entities in the United States and elsewhere. The United States and other countries may not have the same data protection laws as the country from which you initially provided the information.

Where required by applicable law, we have put in place appropriate safeguards (such as standard contractual clauses approved by the European Commission) in accordance with applicable legal requirements to ensure that your data is adequately protected. When transferring your personal data internationally, Red Hat will protect your personal data as provided in this Privacy Statement and comply with applicable legal requirements as may be in effect from time to time. If you wish to obtain a copy of the relevant safeguards that are in place to protect the international transfer of your personal data, please contact us as described below under “How to contact us.”

If you are located in the European Economic Area (“EEA”), the United Kingdom or Switzerland, Red Hat, Inc., and Red Hat Professional Consulting, Inc. have certified to the EU-U.S. and Swiss-U.S. Data Privacy Frameworks for the transfer of personal data from the EEA and Switzerland, as well as the UK Extension for the transfer of personal data from the United Kingdom, to the United States, as described further in our Data Privacy Framework Notice. To learn more about the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension please visit www.dataprivacyframework.gov/s/. To view our certification, please visit www.dataprivacyframework.gov/s/participant-search.

Back to top

Changes to this privacy statement

Red Hat reserves the right to make corrections, changes or amendments to this Privacy Statement at any time. The revised Privacy Statement will be posted on this website. A notice will be posted on our homepage for 30 days whenever this Privacy Statement is changed in a material way, and the date of last update will be indicated at the top of the Privacy Statement. If you do not refuse the changes in writing within that notice period and you continue to use our websites, we consider that you have read and understand the Privacy Statement as changed, including with respect to personal data provided to us prior to the changes in the Privacy Statement. We encourage you to periodically review this Privacy Statement for any changes or updates. If you would like information related to the previous version of this Privacy Statement and/or a copy of the previous version, please click here.

Back to top

EEA Data Protection Authority

If you are a resident of the European Economic Area and wish to raise a concern about our use of your personal data, you may direct questions or complaints to the Irish Data Protection Commissioner, which is Red Hat’s lead supervisory authority, at:

Irish Data Protection Commissioner
Office of the Data Protection Commissioner
Canal House, Station Road, Portarlington, Co. Laois, R32 AP23, Ireland
Phone: +353 57 8684800
+353 (0)761 104 800
Fax: +353 57 868 4757
Email: info@dataprotection.ie

Alternatively, you may contact your local supervisory authority.

Back to top

We provided this information above in the “Your rights and choices” section, but remember that if you would like to exercise any of your privacy rights, you may do so via our Personal Data Request Form. For California consumers, you may also submit requests, or access the information provided in this Privacy Statement in an alternative format, by calling Red Hat’s U.S. toll free number at 1-800-546-7274.

If you have any questions about Red Hat’s privacy practices or use of your personal data, please feel free to contact us at privacy@redhat.com, via our Personal Data Request Form or by mail at:

Red Hat, Inc.
Corporate Legal Group
100 East Davie Street
Raleigh, North Carolina 27601
United States

Red Hat Representative Contact Information in the European Economic Area:

Red Hat Limited
6700 Cork Airport Business Park
Phase II 1st Floor
Cork
Ireland

For a PDF version of the Privacy Statement, please click here.