Last Updated: May 11, 2018
This SAP Concur Privacy Statement (“Privacy Statement”) describes the various ways that Concur Technologies, Inc., Concur Holdings (Netherlands) B.V., their subsidiaries, other affiliated and/or related companies, as applicable (“SAP Concur” or “we” or “us” or “our”) process information about you that is collected by SAP Concur in the context of sales and marketing activities through Channels (as defined below) and explains how SAP Concur uses such information for its own business purposes. As used in this Privacy Statement, “Personal Data” means any data collected through our Channels that can be used to identify an individual. The “Channels” are the various SAP Concur online, digital, electronic sites and technologies, such as public-facing sales and marketing websites, software applications, social media pages, chat features and online conversations, tele-prospecting or HTML-formatted e-mail messages we use to pursue our sales and marketing activities. Channels may also include sales and marketing activities carried out offline. In this Privacy Statement, “goods and services” includes access to SAP Concur’s web services, offerings, contests, sweepstakes, other content, non-marketing related newsletters, whitepapers, tutorials, trainings, events, conferences, webinars and seminars.
If you use SAP Concur business applications like SAP Concur Travel, Expense, or Invoice for which your company, institution or other providing entity (“Providing Entity”) has subscribed either directly with SAP Concur or indirectly via an authorized reseller, please see the SAP Concur Processor Privacy Statement for information on how we access, use, store, collect or disclose your data on behalf of your Providing Entity.
Data Controller. The data controller is the SAP Concur legal entity which initially collects your information and decides how and why to use the data for its business purposes. Where a registration form is presented on an SAP Concur website, the named data controller may vary depending on the actual offering or the purpose of the data collection. For other SAP Concur websites, the data controller is the SAP Concur entity named in the legal disclosure page on the website, or if the local laws that govern the website do not require any specific legal disclosure, the data controller shall be the SAP Concur legal entity named in the copyright notice displayed on such website.
Links to other websites. This Privacy Statement applies solely to information collected by us through the Channels and does not apply to any third-party activities, including third party websites linked from our Channels, third party social networking platforms or features we make available through our Channels, or third-party ads displayed on our Channels. We are not responsible for the privacy practices or content of such third parties. We encourage you to read the privacy statements of those third parties.
Use of SAP Concur websites by children. SAP Concur’s Channels are not directed to users under the age of 13. If you are younger than 13, you may not use our Channels. If you are a parent or guardian and believe we may have collected information about a child, please contact us at: Privacy-Request@Concur.com
SAP’s Data Protection Officer (DPO) is Mathias Cellarius, SAP SE, Dietmar-Hopp-Allee 16, 69190 Walldorf, Germany, who may be contacted at Privacy@Concur.com; or you may contact our group Privacy Team at any time at Privacy-Request@Concur.com.
We collect your Personal Data. We collect such Personal Data about you directly, indirectly and/or automatically as described below. To the extent permitted by applicable law, we may combine the information collected, as described below, including information about the organization for which you work, with other information in our possession or information that you provide to us, and we treat all this information about you as Personal Data.
When you access, use and/or interact with us through a Channel, we directly collect information you voluntarily provide us. This includes but is not limited to the following:
Examples of direct interactions with you through the Channels where you provide us business information and Personal Data about you include the following:
We also obtain business information and Personal Data about you from third party sources, as permitted by applicable law, such as the following:
When you access, use and/or interact with us through a digital Channel, you do so using a “Device”, which is either a personal computer, desktop or laptop, or a mobile device such as a phone or a tablet. A “Device Identifier” is the number that is automatically assigned to the Device you use to access the digital Channel, and we may identify your Device through its Device Identifier. The “Tracking Technologies” are the various technologies we use to automatically collect Device Identifiers and other information about you, such as the following:
The information collected through Tracking Technologies may be considered Personal Data under applicable data protection laws. For additional information about our use of Tracking Technologies, please see below in How We Follow Visits and Usage, Why and How You Keep Control (Cookies, Analytics and Advertising).
Legal Basis for Processing. We collect and process your Personal Data with your consent and/or as necessary to provide the goods and services you use on the Channels, fulfill your inquiry, operate our business, meet our contractual and legal obligations, ensure compliance, protect the security of our systems and our customers, or fulfil other legitimate interests.
Freely Given Consent. As a general principle, granting your consent and providing business information and Personal Data about you is entirely voluntarily and there are no adverse consequences to you if you do not grant a consent when required under applicable law or do not provide the required information. However, there are circumstances where SAP Concur cannot take action without certain Personal Data because such information is required, such as to process your orders or provide you with access to a web offering or newsletter. In these cases, without the relevant Personal Data, SAP Concur will not be able to provide you with what you requested.
Purposes of Processing. We use and process Personal Data about you for purposes described below:
To Provide the goods or services requested on the Channels. If you order goods or services from SAP Concur, we will use the Personal Data which you enter into our online or other forms to process your order or provide the requested goods or services, such as to process your registration to a SAP Concur hosted event. This also includes taking the steps that are necessary prior to entering this contractual business relationship, such as responding to your related inquiries, comments and questions, providing you with shipping and billing information, and providing customer feedback and support. This may also include conversation data that you may trigger on the Channels (e.g., chat-functionalities or other web appearances, contact forms, e-mails or telephone). When you order such goods or services from us, we communicate with you via email and phone to resolve customer complaints, investigate suspicious transactions, confirm your preferences, send you notice of payments or information about changes to our goods and services, and to send notices, updates, technical notices, security alerts, support and other administrative messages and other disclosures as required by law. For example, when you have registered to attend an SAP Concur hosted event, even if you have unsubscribed from our email marketing and promotional messages, we will still send you emails about related items for this specific event, such as additional activities you can sign up for, the launch of the event app, event schedule changes or the like. Generally, you cannot opt out of these communications, which are not marketing related but merely required to fulfil your request in the context of the relevant business relationship you initiated.
To Ensure compliance. We use your Personal Data to prevent, detect, mitigate, and investigate fraudulent or illegal activity. The information required to track your choices regarding the processing or use of your Personal Data or receiving marketing materials is based on the country law in which the relevant SAP Concur company operates and is stored and exchanged between members of the SAP group as necessary to ensure compliance.
To Operate and Improve our Channels, goods and services, to keep you up to date, to follow-up on a referral, communicate through social media channels, to append data or request your feedback. SAP Concur processes and uses your Personal Data based on its legitimate interest for the use cases below:
To provide updates about SAP Concur’s goods and services. We use business information about you and your Personal Data collected through the Channels as well as an interaction profile based on prior interactions with SAP Concur on the Channels (e.g., prior purchases, product usage data, information gathered during customer support contacts, participation in webinars, seminars or events or the use of web services or interaction with emails) and adding to profiles through data appending with third party sources in order to (i) keep you up to date on the latest product announcements, product updates, unique offers, and other information regarding SAP Concur’s goods and services (including marketing-related information or newsletters) as well as events of SAP Concur and our partners and (ii) to display relevant content on our Channels and provide a personalized experience and implement the preferences you request. In connection with these marketing-related activities, SAP Concur may provide a hashed user ID to third party operated social networks or other web offerings (such as Twitter, LinkedIn, Facebook, Instagram or Google) where this information is then matched against the social networks’ data or the web offerings’ own databases in order to display to you more relevant information. With regard to marketing related types of communication including providing personalized updates about SAP Concur’s goods and services as described above, we will (a) where legally required only provide you with such information after you have granted your consent to such electronic communications (also commonly called “opt-in”) and (b) provide you the opportunity to exercise an opt-out choice if you do not want to receive further marketing related types of communication from us. We also maintain the SAP Concur Preference Center for you to manage your information, your marketing preferences and exercise your opt-out choices.
To create and maintain a digital community user profile. SAP Concur offers you the option to use web offerings such as forums, blogs, and networks (e.g., the SAP Concur Digital Community) linked to this website that require you to register and create a user profile. User profiles provide the option to display personal information about you to other users, including but not limited to your name, photo, social media accounts, postal or email address, or both, telephone number, personal interests, skills, and basic information about your company. These profiles may relate to a single web offering of SAP Concur or, if created in the SAP Cloud Platform Identity Authentication Service, may also allow you to access other web offerings of SAP or of other entities of the SAP Group, or both (irrespective of any consent granted under the section “Forwarding your Personal Data to other SAP companies,” below). It is, however, always your choice which of these additional web offerings you use and your Personal Data is only forwarded to them once you initially access them. Kindly note that without your consent for SAP Concur to create such user profiles, SAP Concur will not be in a position to offer such services to you where your consent required under applicable law. Within any web offering, in addition to access your profile is used to personalize interaction with other users, such as with messaging or “follow” functionality, and by SAP Concur to enhance the quality of communication and collaboration through such offerings and for SAP Concur to provide gamification elements (gamification is the process of taking something that already exists, such as a website, an enterprise application, or an online community, and integrating game mechanics into it to motivate participation, engagement, and loyalty). To the greatest extent supported by the relevant web offering, you can use the functionality of the relevant web offering to determine which information you want to share.
To accommodate your special requirements. In connection with the registration for and providing access to an event, conference or seminar we may ask for information about your health for the purpose of identifying and being considerate of individuals with disabilities or special dietary requirements throughout the event. Any such use of information is based on your consent which shall be collected upon your registration to the event, conference or seminar. If you do not provide any such information about disabilities or special dietary requirements, SAP Concur will not be able to take any respective precautions.
To share information about you as part of an Event, Conference, Seminar or Webinar. If you register for an event, seminar, webinar or conference of SAP Concur, based on your consent we may share basic participant information such as your name, company and email address with other participants of the same event, seminar, webinar or conference to foster the communication and exchange of ideas.
We may use Tracking Technologies to collect information. The following are some examples of Tracking Technologies we may use:
First and third-party cookies. We use first and third-party cookies on our Channels. Whether a cookie is ‘first’ or ‘third’ party refers to the domain placing the cookie. First-party cookies are those set by a website that you are visiting at the time (e.g., cookies placed by the SAP Concur French website while visiting that website). Certain cookies are set by a domain other than that of the website you are currently visiting. If you visit a website and another entity sets its cookie or reads its cookie through that website, this would be a third-party cookie (e.g., cookies placed by Google while visiting the SAP Concur UK website).
Persistent and session cookies. We use persistent cookies and session cookies on our Channels. Persistent cookies remain on your Device for the period of time specified in the cookie. They can remain on your Device after you visit the website that set them and can be read the next time that you visit the website that created that specific cookie or visit another website with a beacon from the website that dropped the cookie. Persistent cookies can remain after you end a browser session. A browser session starts when you open a browser window and finishes when you close the browser window. Session cookies allow us to link your actions during a browser session. Session cookies are created temporarily. Once you close the browser, session cookies are typically deleted. For more information on cookies, visit www.allaboutcookies.org.
Web Beacons. We may collect information using web beacons. Web beacons are electronic images that may be used on our websites or in our emails. We use web beacons to deliver cookies, count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.
ETag, or entity tag. A feature of the cache in browsers. It is an opaque identifier assigned by a web server to a specific version of a resource found at a URL. If the resource content at that URL ever changes, a new and different ETag is assigned. Used in this manner, ETags are a form of Device Identifier. ETag tracking may generate unique tracking values even where the consumer blocks HTTP, Flash, and HTML5 cookies.
Flash LSOs. When we post videos or other media on our websites, third parties may use local shared objects, also known as Flash cookies, to store your preferences for volume control, or to personalize certain features. Flash cookies are different from browser cookies because of the amount of, type of, and how data is stored. Cookie management tools provided by your browser will not remove Flash cookies. To learn how to manage privacy and storage settings for Flash cookies visit www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html#117118
Publisher provided identifiers (PPIDs). These are identifiers we use with cookies and other Tracking Technologies in connection with personalized ads and content on our Channels, on third party websites, in applications, in our emails and elsewhere. The PPID allows us to have a consistent identifier for you across devices from which you use our apps and access our sites. This helps us better tailor your ads and content to your interests and helps keep us from showing you the same ads too many times even as you use different devices.
Targeting or Advertising. We and our third-party partners may use information collected using Tracking Technologies on our Channels to learn more about you and your preferences and deliver content, including ads that seem relevant to your interests on our Channels and can be displayed to you on third-party websites and applications. We also may use Tracking Technologies to know when you return to our Channels after visiting these third-party websites and applications. We use information about you collected through Tracking Technologies to try to understand your interests and show you relevant advertising about products and services that may interest you. Our third-party partners may also use this information for third party advertising. Third parties may automatically collect information about your visits to our Channels and other websites, your IP address, your ISP, the browser you use to visit our Channels. They do this by using Tracking Technologies. Information collected may be used, among other things, to deliver advertising targeted to your interests and to better understand the usage and visitation of our Channels and other websites tracked by these third parties. Please note we are not responsible for Tracking Technologies in third party ads, and we encourage you to check the privacy policies of advertisers and/or ad services to learn about their use of Tracking Technologies. If you would like more information about this practice and to know your choices about not having this information used by these companies, visit www.networkadvertising.org/consumer/opt_out.asp.
Analytics. We use analytics, including analytics conducted by third party partners, to help improve our Channels and your user experience, such as remembering you when you return, understanding your preferences and interests, and knowing which of our Web pages are visited and which Channels are most often used.
Managing Preferences. You have the right to accept or reject cookies and can access and/or change your cookie preference or opt-out of third party analytics or opt-out of receiving interest-based advertising from SAP Concur at any time by accessing our cookie preferences page via the link on the site. If you have any problems using this mechanism, please email us at Privacy-Request@Concur.com
We work with third party vendors, consultants and other service providers that help us run our sales and marketing activities. These companies provide work and services such as email delivery, postal delivery, collecting business information and Personal Data about you on our behalf, event/campaign registration and management, information technology and related infrastructure services, data analysis and insight, auditing and other similar services. In some cases, these companies need access to some of your Personal Data to carry out their work for us. They are not permitted to use your Personal Data for their own promotional or business purposes.
As permitted under applicable law, we may transfer your Personal Data to the other entities of the SAP group. The current list of SAP group entities can be found here. Record of any required consent to our sharing your information with the other entities of the SAP group is stored in the SAP Concur Preference Center.
As permitted under applicable law, we may share your contact information with sponsors, co-sponsors and/or exhibitors of events and/or conferences organized and hosted by SAP Concur (such as SAP Concur Fusion). Please note that our sponsors, co-sponsors and/or exhibitors may directly request your information at their conference booths or presentations. You should review their privacy policies to learn how they use personal information.
Occasionally, we may engage in joint sales or product promotions with selected business partners to provide content or to host events, conferences and seminars. If you purchase or specifically express interest in a jointly-offered product, promotion or service, we may share relevant Personal Data with those partners as permitted under applicable law. However, please be aware that we do not control our business partners’ use of such Personal Data. Our partners are responsible for managing their own use of the Personal Data collected in these circumstances. We recommend you review the privacy policies of the relevant partner to find out more about their handling of your Personal Data.
We may also share your information in the following circumstances:
SAP Concur maintains data handling and storage practices and procedures that are designed to promote the integrity and confidentiality of Personal Data. We update and test our security technology on an ongoing basis. We use commercially acceptable means to protect your personal information in an effort to prevent loss, misuse and unauthorized access, disclosure, alteration and destruction, but we cannot guarantee its absolute security.
As part of a global group of companies, SAP Concur has affiliates and third-party service providers within, as well as outside of, the European Economic Area (EEA). Therefore, your Personal Data may be transferred, used, processed or stored in the United States or any other country where SAP Concur operates or maintains facilities or call centers, including jurisdictions that may not have data privacy laws that provide protections equivalent to those provided in your home country. We take steps designed to ensure that the Personal Data we collect under this Privacy Statement is processed according to the provisions of this Privacy Statement and applicable law wherever the data is located. By providing your information to us on our Channels, you agree to that transfer, storage, and processing in the United States. Also, we may transfer your data from the United States to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Channels.
When we transfer Personal Data from the European Economic Area and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level of data protection, such transfer is based on the Standard Contractual Clauses (according to EU Commission Decision 87/2010/EC or any future replacement) in order to contractually ensure that your Personal Data is subject to a level of data protection which applies within the EEA. You may obtain a redacted copy (from which commercial information and information that is not relevant has been removed) of such Standard Contractual Clauses by sending a request to Privacy-Request@Concur.com.
We store and retain your Personal Data for as long as necessary to fulfill the purposes described in this Privacy Statement, such as to provide goods and services requested by you, respond to your inquiries or for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements, or until you object to SAP Concur’s use of your Personal Data (if SAP Concur’s use of your Personal Data is based on a legitimate interest) or you withdraw your consent (if SAP Concur’s use of your Personal Data is based on your consent).
For clarity, in circumstances where we are required by law to retain your Personal Data longer, such as for tax, legal, accounting or other purposes, or where we need your Personal Data to assert or defend against legal claims, we will retain such information until the end of the relevant retention period or the resolution of such claims.
Preference Center and Choices. You can customize and control your marketing communication preferences by updating the Personal Data you provide us and your subscription settings in the SAP Concur Preference Center where you can return at any time to change your elections. You can also unsubscribe from promotional emails by: (1) following the unsubscribe instructions in our emails; or (2) emailing us at Privacy-Request@Concur.com. You can find details on how to automatically unsubscribe from e-mail communications in the SAP Concur Preference Center. If you have any problems using any of these opt-out mechanisms, please contact us at Privacy-Request@Concur.com. Please note that even if you unsubscribe from promotional email messages, we may still need to contact you with transactional information related to the goods and services you have ordered or requested on the Channels.
Cookies and Do Not Track. You can opt out of cookies that are not required to enable core site functionality and can manage your cookie preferences via the link on the website. We may not recognize or respond to every type of “do not track” signal or other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information about an individual consumer’s online activities over time and across third-party websites or online services, but we give you certain choices about how we collect Personal Data as described in this Privacy Statement. Please remember that if you delete your cookies, or use a different browser or computer, you will need to set your cookies preferences again. If you have any problems using this cookie preference mechanism, please contact us at Privacy-Request@Concur.com.
Analytics and Advertising. We encourage you to review the privacy policies of our third-party advertisers and analytics service providers to learn about your choices about information they collect from you. Many are available at Preferences-Mgr.Truste.com or through the cookie preferences link on our website. In addition, the Network Advertising Initiative offers information about some of the Internet advertising companies we may use, including how to opt-out of interest based advertising they deliver. To opt-out of Google Analytics web tracking you can download Google Analytics Opt-out Browser Add-on.
We adhere to applicable data protection laws in the EEA, which, if applicable to you, include the rights described below. If you wish to exercise any privacy right that is available to you, we will process your request in accordance with applicable data protection laws. We may need to retain certain information for record-keeping purposes and/or to complete transactions that you began prior to requesting any deletion.
If you would like to exercise any of the above rights, please contact Privacy-Request@Concur.com so that we may consider your request under applicable law, verify any relevant legal requirements and exemptions, including steps to verify your identity before complying with the request.
We may update this Privacy Statement from time to time without notice to you other than posting the revised Privacy Statement on the Channels or by providing such notice about or obtaining consent to changes as may be required by applicable law. If we change our Privacy Statement, we will post those changes to this Privacy Statement and change the “last updated” date above. We encourage you to periodically review this Privacy Statement for the latest information on our privacy practices.
If you have any questions about this Privacy Statement or to file any complaint regarding this Privacy Statement, please contact us at the following address:
Concur Technologies, Inc.
601 – 108th Avenue NE, Suite 1000
Bellevue, WA 98004
Attention: Privacy Manager
Telephone: (888) 883-8411
SAP Concur will investigate and attempt to resolve complaints and disputes regarding the collection, use, and disclosure of Personal Data by referencing the privacy principles stated in this Privacy Statement. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at feedback-form.truste.com/watchdog/request.