Updated August 27, 2020
We may change the provisions of this Policy at any time and will indicate when changes have been made by revising the date at the top of this Policy. We encourage you to review the Policy whenever you access the Services to make sure that you understand our information collection, use and disclosure practices. If we make material changes to this policy, we will provide you with additional notice of such changes.
On August 27, 2020, Lucid updated this Policy: (1) to clarify where we may host, process, and transfer data we collect when you use the Services; (2) to inform you of your ability to disable certain types of cookies, other similar tracking technologies, and analytics services; and (3) in accordance with the final regulations issued pursuant to the California Consumer Privacy Act of 2018.
Information We Collect
Information That You Provide to Us
Lucid may collect information that you provide when you use the Services, such as when you: (1) create an account; (2) make a purchase; (3) participate in events or promotions; (4) send questions or comments via e-mail or live chat to Lucid customer support; (5) apply for a job with us online; (6) fill out surveys; or (7) otherwise communicate with us through or about the Services. The types of personal information that you provide may include your name, e-mail address, telephone number, postal address, credit card information, and other contact or identifying information that you choose to provide.
Lucid stores, processes and maintains files that you create and/or upload using the Services (as well as previous versions of your files), including Lucid documents that you create, sharing lists, and other data related to your account in order to provide the service to you.
Information About Use of Our Services
Lucid’s servers automatically record certain information about your use of the Services. Lucid uses a variety of technologies to collect this information, including persistent and session cookies, web beacons, and pixel tracking technology. The information we collect includes storage usage, number of log-ins, actions taken, data displayed or clicked on (e.g., UI elements, links), and other login information (e.g., browser type, IP address, date and time of access, cookie ID, referrer URL, etc.). Lucid may collect automated error reports in the case of software malfunction; such error reports may contain some or all of the information in your documents and may be reviewed to help resolve problems with the Lucid applications or service.
When you participate in a videoconference with us, we may record the session and retain recordings of the session if we notify you that the session is being recorded so that you can opt out.
If you participate in a training or product course, we collect course completion data.
Information We Collect from Third Parties
We may obtain information from other sources and combine that with information we collect through our Services. For example:
- If you create or log into your account through a third-party social networking site or one of our integration partners, we will have access to certain information from that service, such as your name and account information.
- If you elect to purchase a license to use our products, we may receive information about your purchase from our third-party payment processor.
- We may collect information from unaffiliated third parties so we can better understand you and provide you with information and offers that may be of interest to you. For example, we may receive information about your company, company size, job title, and job level as well as contact information, such as email address or phone number.
Please note that all of the information we collect about you may be combined and used for the purposes described in the “How We Use Your Information” section below.
How We Use the Information We Collect
We use personal information collected through our Services for purposes described in this Policy or otherwise disclosed to you on or in connection with our Services. For example, we may use your information to:
- Operate and improve our Services;
- Send you advertising or promotional materials, including information about new products, contests, features and enhancements, special offers and other events of interest from Lucid and our select partners;
- Provide and deliver the products and Services you request, process transactions, and to send you related information, including confirmations and invoices;
- Send you technical notices, updates, security alerts and support and administrative messages;
- Respond to your comments, questions and requests and provide customer service;
- Monitor and evaluate trends, usage and activities in connection with our Services;
- Personalize and improve the Services and provide content, communications or features that match user profiles or interests; and
- Link or combine with other information we get from third parties to help understand your needs and provide you with better service.
Lucid reserves the right to review documents to help resolve problems with our software or Services, or to ensure compliance with our Terms of Service.
Lucid may share your personal information with third parties in the following circumstances:
- Files you create, upload, or copy into our products may, if you choose, be read, copied, used and redistributed by people you know or, again if you choose, by people you do not know. Information you disclose using the chat function of the Services may be read, copied, used and redistributed by people participating in the chat. Use care when including sensitive personal information, such as home addresses or phone numbers, in files you share or in chat sessions.
- With your employer if you are a registered user, and the domain of the primary email address associated with your account is owned by your employer and that email address was assigned to you as an employee of that organization, and an authorized representative of that organization wishes to establish an enterprise account and add you to it, then certain information concerning your individual account may become accessible to that organization’s administrator, including your name and email address, and your account may be added to the corporate account.
- With third party vendors, consultants and other service providers who are working on our behalf and need access to your information to carry out their work for us. These entities have agreed to maintain the confidentiality, security, and integrity of the personal information they obtain from us, and, unless we notify you otherwise and provide you with an opportunity to opt-out, will not use your personal information for any purpose other than as described in this Policy.
- With data analytics and advertising services in order to understand your preferences and to show you advertising about our Services.
- With law enforcement, courts of competent jurisdiction, or others when we have a good faith belief that access, use, preservation or disclosure of such information is reasonably necessary to (a) satisfy any applicable law, regulation, legal process or enforceable governmental request, (b) enforce applicable Terms of Service, including investigation of potential violations thereof, (c) detect, prevent, or otherwise address fraud, security or technical issues, or (d) protect against harm to the rights, property or safety of Lucid, its users or the public as required or permitted by law.
- When we have your consent.
- In connection with, or during negotiations of, any merger, sale of some or all of Lucid’s assets, bankruptcy or reorganization, financing or acquisition of all or a portion of Lucid’s business to another company.
We may share with third parties certain pieces of aggregated, non-personal information, such as the number of users who used a type of document or how many users clicked on a particular advertisement. Such information does not identify you individually.
Advertising and Analytics Services Provided by Others
Lucid takes reasonable measures to protect your personal information and your documents from loss, misuse and unauthorized access, disclosure, alteration and destruction and to ensure that your documents remain available to you.
We store the information we collect about you for as long as is necessary for the purpose(s) for which we originally collected it. We store our backups for six (6) months. We may retain certain information for legitimate business purposes or as required by law.
Hosting and Data Transfer
We are based in the United States and, unless we expressly agree otherwise, we may host, transfer, and process data, including personal information, in the United States and in other countries through Lucid affiliates and third parties that we use to operate and manage the Services. These countries may have data protection laws that are different from those of your country of residence. Lucid uses a variety of safeguards, including contractual and technical measures, to protect the data we transfer.
In connection with Lucid’s processing of personal data it receives from the European Union, United Kingdom, or Switzerland (“European Data”), Lucid adheres to the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework Principles issued by the U.S. Department of Commerce (the “Principles”). For more information about the Principles, please visit the Department of Commerce’s Privacy Shield website.
Please direct any inquiries or complaints regarding our compliance with the Principles to the point of contact listed in the “Contact Us” section below. If Lucid does not resolve your complaint, you may submit your complaint to JAMS, Lucid’s designated alternative dispute resolution provider for Privacy Shield issues at https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim. JAMS is located in the United States and their services are provided at no cost to you. Under certain conditions specified by the Principles, you may also be able to invoke binding arbitration to resolve your complaint.
Lucid is subject to the investigatory and enforcement powers of the FTC. If Lucid shares European Data with a third-party service provider that processes the data solely on our behalf, then Lucid will be liable for that third party’s processing of European Data in violation of the Principles, unless Lucid can prove that it is not responsible for the event giving rise to the damage.
Under the Principles, you have the right to access your information that Lucid has collected from you. You may do so by contacting Lucid using the “Contact Us” information below or through our designated Privacy Shield dispute resolution provider. You have the right to limit the use and disclosure of your personal data by not providing said information to Lucid or by not using our Services. You may request that Lucid correct, amend, or delete your information where it is inaccurate, or has been processed in violation of the Principles, except where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question, or where the rights of other persons would be violated.
Your Choices and Rights
You have several choices with respect to your personal information, as follows:
- You may terminate your use of the Services at any time.
- Accessing, Editing, or Deleting your Personal Information. If you have created an account, you may at any time review and/or update the contact information we have for you. Please note that even if you delete information from your account, or deactivate it, we may retain certain information as required by law or for legitimate business purposes. We may also retain cached or archived copies of your information for a certain period of time.
- Promotional Communications. You may opt out of receiving promotional emails, text messages, or mail from Lucid by visiting your user settings page and updating your communications preferences, by following the instructions in emails or text messages, by visiting this website, or by sending an e-mail to email@example.com. If you opt out, we may still send you transactional or relationship messages, such as emails about your account or updates to our Services.
California Privacy Disclosure
Under the California Consumer Privacy Protection Act (CCPA), we are required to provide you with information about the information Lucid may collect, the purpose for which we collect such information, the sources of that information, and the categories of third parties with whom we share that information.
In the preceding 12 months, we have collected the following categories of personal information: identifiers, financial information, internet or electronic network activity information, professional and employment-related information, education information, and inferences. For details about the precise data points we collect and the categories of sources of such collection, please see the Information We Collect section above. We collect personal information for the business and commercial purposes described in the How We Use the Information We Collect section above. In the preceding 12 months, we have disclosed the following categories of personal information for business purposes to the following categories of recipients:
Category of Personal Information
Categories of Recipients
Advertising networks, data analytics providers, payment processing and other financial services partners, fulfillment partners, security and fraud prevention partners, customer service partners, general business productivity partners and recruiting partners
Payment processing and other financial services partners, fulfillment partners, security and fraud prevention partners, customer service partners
Internet or electronic network activity information
Advertising networks, data analytics providers, payment processing and other financial services partners, fulfillment partners, security and fraud prevention partners, customer service partners
Professional and employment-related information
Data analytics providers, fraud prevention partners, recruiting partners
Data analytics providers, recruiting partners, general business productivity partners
Advertising networks, data analytics providers, payment processing partners, fulfillment partners, customer service partners
Other information you choose to provide
Advertising networks, data analytics providers, payment processing and other financial services partners, fulfillment partners, security and fraud prevention partners, customer service partners, recruiting partners
Your California Rights
California residents have the right to request access to or deletion of their personal data. You may exercise these rights as described in the “Your Choices and Rights” section above, or by emailing us at firstname.lastname@example.org. California residents also have the right to request additional details about our information practices and to not be discriminated against for exercising their rights. After submitting a request to access or delete your personal data, please monitor your email address associated with your Lucid account for correspondence from Lucid aimed at verifying your identity before we process your request. If we receive your request from an authorized agent, we may ask for evidence that you have provided such agent with written authority to submit requests on your behalf. We may also require that you confirm your request and your identity directly with Lucid.
Residents of the European Economic Area
If you are a resident of the European Economic Area (EEA), please review this additional information.
Legal Basis for Processing
When we process your personal data, we will only do so in the following situations:
- We have your consent to do so. For example, we may ask your consent to send you marketing communications.
- We need to use your personal data to perform our responsibilities under our contract with you (e.g., processing payments for and providing the Services you have requested).
- We have a legitimate interest in processing your personal data. For example, we may process your personal data to communicate with you about changes to our Services, and to provide, secure, and improve our Services.
You have certain rights and protections under the law regarding the processing of your personal data. You may access, review, modify, and delete your personal data by following the instructions under “Your Choices” above.
Questions or Complaints
If you are a resident of the EEA and have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint with the data privacy authority where you reside. For contact details of your local Data Protection Authority, please see: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.
If you have questions or concerns regarding this Policy, please contact Lucid at: email@example.com or at 10355 S Jordan Gateway, Suite 150, South Jordan, UT 84095, Attn: Privacy Notices.
What is Lucid for Education?
Lucid Software Inc. (“Lucid,” “we,” or “us”) offers web- and app-based visual communication tools that students and teachers can use to create flowcharts, diagrams, and design materials that bring 21st century learning to the classroom. Our services include Lucidchart, a visual diagramming tool and Lucidpress, a design creation tool (collectively, “the Services”).
Teachers and students use these Services to learn core content in creative and collaborative ways that foster critical thinking while mastering the key literacies. More than 5 million students, teachers, and administrators around the world are using Lucid for Education to learn and work together. We are committed to protecting the privacy and security of all our users, including students. We care deeply about empowering today’s students for the future of work and are humbled that millions already trust us to do that. We are committed to keeping the trust of schools and parents by protecting the personal information we collect and using that information only to provide our Services.
Schools that use our Services may integrate with other technology services such as Canvas or Google Classroom and allow students to access or share content through our Services. This Policy does not apply to features or other services Students may access through our Services.
What Information Do We Collect about Students?
Lucid will not collect, maintain, use or share Student personal information beyond that needed for authorized educational/school purposes, as authorized by the parent or Student or as otherwise allowed by this Policy.
When a Student registers for the Services, Lucid collects (1) name, (2) email address, and (3) password. Registration information may be provided by the Student directly or by their school.
Information That We Collect Automatically from Students
When Students use the Services, we collect and maintain the files that Students create and/or upload using the Services (as well as previous versions of those files), including documents that Students create, sharing lists, and other data related to the Student’s account.
Similar to other web services, Lucid uses both persistent and session cookies, web beacons, and pixel tracking technology to record information such as:
- account activity (e.g., storage usage, number of log-ins, actions taken);
- data displayed or clicked on (e.g., UI elements, links, web pages viewed);
- other log information (e.g., browser type, operating system, device name and model, IP address, date and time of access, length of time spent on our websites or in our Services, device identifier or a similar unique identifier, referrer URL, webpage that led a user to our website); and
- user preferences while using the Services (e.g. language).
“Cookies” are alphanumeric identifiers that we transfer to a computer’s hard drive through a web browser for record-keeping purposes. We may use both session Cookies (which expire once a user closes a web browser) and persistent Cookies (which stay on a computer until a user deletes them). Some Cookies allow us to make it easier for a Student to navigate our website and Services, while others are used to enable a faster log-in process or to allow us to track a Student’s activities, but only as those activities relate to the Student’s use of our websites and Services.
How Do We Use Student Information?
We use the information we collect from Students to provide, administer, operate, and improve our Services, to support the internal operations of our websites and Services, monitor and evaluate trends, usage and activities in connection with our Services and better tailor our Services to our users’ needs. We also use the information we collect to respond to comments, questions and requests and provide customer service and for security reasons and to comply with legal obligations.
When information is provided by schools, we use that information to create an account and to track the number of users on the account for billing purposes. We may use aggregate or de-identified information about the use of the Services for research, analysis, and similar purposes, for example, to better understand how users access and use the Services; to improve the Services; or for other research and analytical purposes.
How Do We Share Student Information?
We are committed to not advertising or marketing to Students or others based on Students’ use of the Services. We will not disclose any personal information about Students to third parties, except as described below. We never sell, rent, or trade any Student information.
Lucid may share Student personal information with third parties in the following circumstances:
- We will disclose Students’ personal information: (1) to each Student’s individual teacher(s) and parent(s) or guardian(s); and (2) as directed by the Student’s school. In addition, if the Student has an account through a school, the Student’s teacher(s) and school administrators can see the Student’s profile and work. Teachers may share assignments with other students and with other teachers or administrators.
- When we have a parent’s or guardian’s consent directly or through the school.
- With third-party vendors, consultants and other service providers who are working on our behalf, who are hosting our data, and need access to information to carry out their work for us. These entities have agreed to maintain the confidentiality, security, and integrity of the personal information they obtain from us, and, will not use personal information for any purpose other than as described in this Policy.
- With law enforcement, courts of competent jurisdiction, or others when we have a good faith belief that access, use, preservation or disclosure of such information is reasonably necessary to (1) satisfy any applicable law, regulation, legal process or enforceable governmental request, (2) enforce the applicable Terms of Service, including investigation of potential violations thereof, (3) detect, prevent, or otherwise address fraud, security or technical issues, or (4) protect against harm to the rights, property or safety of Lucid, its users or the public as required or permitted by law.
- In connection with, or during negotiations of, any merger, sale of some or all of Lucid’s assets, bankruptcy or reorganization, financing or acquisition of all or a portion of Lucid’s business to another company; provided that a successor entity may only maintain Student personal information subject to these same commitments for the previously collected Student personal information.
- When schools use integrations, like Google Classroom or Canvas, these integrations may receive information needed to provide their services. For example, an assignment created in Lucidchart or Lucidpress may be submitted through Canvas. In this case, Canvas would receive the assignment and submission data.
- Schools may enable Students to share, publish, or collaborate with other services using our Services. When Schools enable these features, other users will receive access to information Students share or collaborate on and third parties may receive information that Students publish, all of which may be redistributed by those users or third parties.
What Controls Do We Make Available?
Schools control the personal information shared with us, and are responsible for ensuring that they have any parental consent necessary to share personal information with us and to allow us to collect personal information from Students.
Parents or legal guardians of a Student who is using the Services through their schools can contact the appropriate official at the Student’s school to access, review, correct, or delete their Student’s personal information or accounts. If the school determines that the request should be implemented, the school may either make the change themselves or submit the request to us.
If your child has registered for a Lucid account independent of a school (or if you set up an account for your child independent of a school), you may update, correct, or delete your child’s profile information or preferences at any time by logging into your child’s account and accessing the account setting page or by emailing firstname.lastname@example.org. You may ask us to delete the account by emailing us at email@example.com. When you exercise these rights, we may ask you to provide proof of legal guardianship.
If you are not sure what type of account your child has, please contact us at firstname.lastname@example.org and we will assist you.
Please note that even if you delete information from your account or deactivate it, we may retain certain information as required by law. We may also retain cached or archived copies of your Student’s information or content for a certain period of time.
Most web browsers automatically accept cookies, but if you prefer, you can edit your browser options to block them in the future. The Help portion of the toolbar on most browsers will tell you how to prevent your computer from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. Visitors to our websites who disable cookies will still be able to browse certain areas of the website, but some features may not be available to you.
If you have questions or concerns regarding this Policy, please contact Lucid at:
- Email us at: email@example.com;
- Call us at: 855-917-2480 and ask for the Lucid for Education team; or
- Write us at: 10355 S Jordan Gateway, Suite 300, South Jordan, UT 84095, Attn: Legal Notice.