INIT Innovations in Transportation, Inc. Privacy Policy – Entra ID Integration

About INIT Innovations In Transportation, Inc.

At INIT Innovations In Transportation, Inc. (“our” or “we” or “us”), we respect your privacy and are committed to protecting it and maintaining the integrity of any personally identifiable data, as it is defined by applicable law (“Personal Information”) we collect about you.  Personal Information is defined by applicable law but can be generally thought of as information about an identified or identifiable person, i.e., information which can be traced back to an individual. This can include, depending on applicable law, names, addresses, employer, e-mail addresses, telephone numbers, and certain information about your IP address and browser.  It may also include information about INIT application access including data automatically logged when accessing INIT applications.  The purpose of this Privacy Statement (“Privacy Statement”) is to disclose how we collect, use, and disclose Personal Information, our purpose for collecting Personal Information, and to inform you of the steps we take to keep your Personal information confidential.

Scope of this Privacy Statement

This Privacy Statement governs the types of Personal Information we may collect about you or that is automatically provided to us when registering for, or accessing, INIT applications through Microsoft Azure. The addition of your user account to an INIT system or INIT application is done only by request under the requirements of the contract between your transit agency and INIT. The removal of your user account in the INIT system is also further restricted and coordinated through your employer. 

Information Collected Through Automatic Data Collection

As you access, authenticate, and perform activities within INIT applications, automatic data collection methods collect certain information about your equipment, actions, and patterns including:

  • Details of your authentication attempts including general geographic location, public IP address, browser meta-data, and other metadata logged by Microsoft during the authentication process.
  • Information about the success or failure of multi-factor authentication attempts including metadata surrounding the device type used in the multi-factor authentication process.
  • Usage information surrounding the date, time and duration of applications accessed through Azure.
  • Details of your corporate email address, phone numbers, company name, position, and full name.
  • Technical details of your source internet protocol address, browser type and configuration.

 

Purpose and Legal Basis for Collecting and Using Your Information

The information gathered automatically is required for the purposes described in this statement and not having this information would likely make it difficult for us to fulfill our contractual obligations to your relevant transit agency, limit our ability to provide support and limit our ability to detect and respond to information security events. Purposes include:

  • To establish identity
  • To perform necessary identity and security verifications
  • To authorize you to access sensitive applications
  • To deliver the applications and services required under our contractual obligations to your employer
  • To provide customer support and services
  • To respond to inquiries from your employer
  • To provide data in security investigations
  • To understand and collect data about faults and failures for the purposes of improving our services and service delivery
  • To respond to issues, questions and queries
  • To co-operate with law enforcement and legal authorities
  • To comply with any legal obligations or defend any legal claims
  • To comply with civil, criminal, or regulatory inquiries, investigations, subpoenas, summonses or legal processes.
  • To detect security incidents, protect against malicious, deceptive, fraudulent, abusive, or illegal activity.

 

How we may Disclose and Share Your Personal Information

We may disclose both aggregated, de-identified information, as well as specific individual personal information, without restriction for the purposes described in this privacy statement. This information may be disclosed to the following:

  • Your employer. Depending on the contractual relationship between INIT and the relevant transit agency, the relevant data may already be owned by the transit agency.
  • Third party providers that provide services to us or to whom we outsource certain services which may include information security operations centers, log aggregation tools and other information security relevant providers.  To the extent that those third-party providers have separate privacy policies, those policies may apply.
  • Third parties to whom we are obliged to send information, including public authorities, law enforcement officials, judges and courts if we are required to do so by a court of competent jurisdiction, or other legal or regulatory authority, and in order to comply with the requirements of these authorities and the applicable international, federal, state, or local laws, where appropriate, and, if there is a good faith belief, and reliance on said belief, that disclosure is necessary to comply with any legal process served on us.
  • To companies that form part of the INIT group, of which we are part, in the course of providing your agency with our business services, support, or the fulfilment or delivery of our products or services and to manage our contractual relationship with your agency.

 

Data Retention and Right of Removal

The collected data described in this privacy policy is stored by Microsoft and may be copied to third parties also described in this policy and is potentially stored into perpetuity because it is for the purposes of statistical analysis, to detect security incidents, to help to ensure security and integrity of our systems, and for other internal uses that are reasonably aligned with an objective user’s expectations given your relationship with us and compatible with the context in which you provided the information. 

If your jurisdiction provides certain rights regarding the removal or correction of personal data that we collect, you may send a request, that complies with applicable law, for removal or correction to the address below and we will comply with the applicable state law.   We will never discriminate based upon your exercise of such a right. 

Requests, questions or inquiries regarding this policy can be sent to privacy@initusa.com and should identify “Entra ID Integration” in the subject line.