At Xactly we C.A.R.E. about you, our customer:
To succeed and earn your trust, we need to meet your expectations every single day, with every interaction. We also know that trust starts with security and visibility. Using Xactly Incent Trust, you can find real-time updates on system performance, including privacy and security information, for the Incent Suite, presented in the following areas:
Xactly recognizes the importance of visibility into the system availability, scheduled maintenance, and overall reliability of the Xactly Incent Suite. This page displays the system maintenance announcements, including the current system status of the Xactly Incent Suite, as well as the Historic System Up Time of the Xactly Incent production environment.
Current System Status
To determine the refresh status section that applies to your business, please refer to the URL in the browser window address bar when you log into Incent (example: “secure1.xactlycorp.com”).
Xactly understands that the confidentiality, integrity, and availability of our customers’ information are vital to their business operations and therefore to our success.
We use a multi-layered approach to protect that key information, constantly monitoring and improving our applications, systems, and processes to meet the changing demands and challenges of security.
Secure Data Centers
Our service is collocated in dedicated secure cages in top-tier data centers. These facilities provide carrier-level support, including:
- 24×7 monitoring by closed-circuit cameras and onsite guards
- Data center space is physically isolated and accessible only by specified administrators
- Access is restricted to authorized personnel through biometric two-factor authentication
- Fully-managed, hardened, stateful inspection firewall technology
- Fully-managed Intrusion Detection System (IDS)
- Edge-to-edge security, visibility and carrier-class threat management and remediation utilizing Arbor Networks Peakflow to compare real-time network traffic, immediately flagging anomalies such as:
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, worms or botnets
- Network issues such as traffic and routing instability, equipment failures, or misconfigurations
- 24x7x365 Firewall, VPN, and IDS support and maintenance
- Security Incident Response Team (SIRT) to handle reports of security incidents
Power and Environment
Redundant UPS and generator backups for all systems
HVAC (Heating Ventilation Air Conditioning) systems arranged in an N+1 redundancy configuration
Automated controls that provide the appropriate levels of airflow, temperature, and humidity
Fire Detection and Suppression
Multi-zoned, dry pipe, water-based fire suppression systems
Monitors to sample the air and provide alarms prior to pressurization
Dual-alarm activation necessary for water pressurization
Water discharge specific to fire alarm location
Flood Control and Earthquake
All facilities built above sea level with no basement areas
Moisture barriers on exterior walls
Dedicated pump rooms for drainage/evacuations systems
Moisture detection systems
Location-specific seismic compliance
All facilities meet or exceed requirements for local seismic building codes
Secure Transmission and Sessions
Connection to the Xactly Incent environment is via SSL 3.0/TLS 1.0, using global step-up certificates, ensuring that our users have a secure connection from their browsers to our service
Individual user sessions are identified and re-verified with each transaction, using a unique token created at login
Perimeter firewalls and edge routers block unused protocols
Internal firewalls segregate traffic between the application and database tiers
A third-party service provider continuously scans the network externally and alerts changes in baseline configuration
The Xactly Incent service performs real-time replication to disk within the data center for business continuity purposes, and offsite data storage at a secure facility for disaster recovery purposes. Note also the following:
Data is transmitted across encrypted links
Disaster recovery functionality is exercised regularly to verify projected recovery times and the integrity of customer data
All data is backed up at each data center, on a rotating schedule of incremental and full backups. The backups are then replicated over secure links to a secure archive.
Internal and Third-party Testing and Assessments
Xactly tests all code for security vulnerabilities before release, and regularly scans our network and systems for vulnerabilities. Third-party assessments are also conducted regularly, including:
- Web application vulnerability assessments
- Network vulnerability assessments
- Selected penetration testing and code reviews
- Security control framework review and testing
Xactly Operations monitors notifications from various sources and alerts from internal systems to identify and manage threats. Potential threats are logged and investigated as part of the Xactly Incident Management Process.
Effective Date: August 12, 2014
Xactly Corporation (“Xactly” or “we”) has created this privacy statement (“Statement”) in order to demonstrate our commitment to data privacy. Privacy on the www.xactlycorp.com Web Site (the “Site) and the Xactly platforms; Xactly Incent Pro, Incent Enterprise, Insights and Objectives (the “Platform”) is of great importance to us. Since we gather sensitive information from our visitors and customers, we have established this Statement to communicate our information gathering and management practices as well the choices we have made regarding how we use the information we collect. In an effort to ensure the highest levels of data privacy, our standards meet or exceed the U.S. Department of Commerce’s “Safe Harbor” standards. If you have any questions regarding this policy please contact us via email at email@example.com.
Xactly has received TRUSTe’s Privacy Seal certifying that this privacy statement and our practices have been reviewed for compliance with the TRUSTe program viewable on the validation page available by clicking the TRUSTe seal. The TRUSTe certification does not cover information collected behind the login or through mobile applications.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact TRUSTe at https://feedback-form.truste.com/watchdog/request.
Xactly complies with the U.S.–E.U. and U.S.–Swiss Safe Harbor Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal data from European Union member countries and Switzerland. Xactly has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Safe Harbor program, and to view Xactly’s certification, please visit http://www.export.gov/safeharbor.
In order to access certain portions of the Site, you will be required to register by providing certain limited information regarding you and the company you represent such as name, email address, address and phone number. Xactly collects this information and engages third parties to collect personal information to assist us for a variety of reasons, including personalizing your experience, contacting visitors to further discuss their interest in our company, when you register for a webinar or other informational offering, and sending information regarding our company, such as newsletters and events. Xactly and the third parties we engage may combine the information we collect with information obtained from other sources to help us improve its overall accuracy and completeness, and to help us better tailor our interactions with you. Visitor and any personal customer information will not be distributed or shared with any third parties under any circumstance other than as outlined in this Statement. Customers can opt out of being contacted by us, or receiving such information from us, at any time by following the unsubscribe instructions contained in the email communications you receive or by sending an email to firstname.lastname@example.org.
Cookies and other Web Technologies
When you interact with the xactlycorp.com Site and Platform, we strive to make that experience easy and meaningful. Like many websites, Xactly uses automatic data collection tools, such as cookies, embedded web links, web beacons, and clear gifs. When you come to our Site and Platform, our Web server may send a cookie to your computer. Cookies are files that Web browsers place on a computer’s hard drive and are used to tell us whether customers and visitors have visited the Site previously. Standing alone, cookies do not identify you personally. They merely recognize your browser. Unless you choose to identify yourself to Xactly either by requesting a download or registering for a demo or webinar, you remain anonymous to Xactly. If you do not accept cookies from the domain “xactlycorp.com”, you cannot access certain portions of the Site or Platform without registering again each time you would like to access restricted information.
We use IP addresses to analyze trends, administer the Site, track user’s movement, and gather broad demographic information for aggregate use. IP addresses that we collect are not linked to personally identifiable information.
Our third party partners employ a software technology called clear gifs (a.k.a. Web Beacons/Web Bugs), that help us better manage content on our Site by informing us what content is effective. Clear gifs are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of Web users. In contrast to cookies, which are stored on a user’s computer hard drive, clear gifs are embedded invisibly on Web pages and are about the size of the period at the end of this sentence. The information gathered does not personally identify you, but could potentially be linked with the personal information that you or third parties engage by Xactly provide to Xactly. We do not tie the information gathered by clear gifs to our customers’ personally identifiable information.
Social Media Features
Users Outside of the United States
While we make every effort to honor the laws and wishes of all users, this Site is available for users located primarily in the United States of America and therefore may or may not address privacy requirements contained in non-domestic legislation.
Xactly takes substantial precautions to protect data and information under its control from misuse, loss or alteration. We utilize some of the most advanced technology available today for Internet security and are constantly taking measures to adjust to the changing security landscape. As such, Xactly maintains layered, defense in-depth security measures, including hosting our solution in a Tier IV (the highest recognized level) datacenter, to allow only authorized personnel access to your information. When you provide us with sensitive information (such as your login credentials) we transmit your personal information via SSL encryption. Unfortunately, no system can ensure complete security, and Xactly disclaims any liability resulting from use of the Site. If you have any questions regarding security on our web site, you can contact us email@example.com.
Links to Third-Party Sites
The Site contains links to other Web Sites. Xactly is not responsible for the privacy practices or the content of these other Web Sites. Visitors are advised to check the policy statements of other Web Sites to understand their policies. Accessing a linked site may expose your private information.
Xactly complies with the US-EU Safe Harbor Framework and US-Swiss Safe Harbor Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland.
Xactly has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Safe Harbor program, and to view our certification page, please visit http://www.export.gov/safeharbor/.
Xactly provides you with a choice to opt out of disclosure of your personal information to a third party or the use of personal information for something other than it was originally collected.
Xactly collects information under the direction of its customers, and has no direct relationship with the individuals whose personal data it processes.
Xactly may transfer personal information to companies that help us provide our services to our customers and users such as an email service provider to send emails on our behalf and a career management partner to collect potential employee information. Transfers to these third parties are covered by the provisions in this Policy regarding notice and choice and the service agreements with our Clients.
We reserve the right to disclose personal information as required by law and when we believe that disclosure is necessary to protect our rights and/or to comply with a judicial proceeding, court order, or legal process served on our Web site.
In the event Xactly goes through a business transition, such as a merger, acquisition by another company, or sale of all or a portion of its assets, your personally identifiable information will likely be among the assets transferred. You will be notified via either email or prominent notice on our Web site for 30 days of any such change in ownership or control of your personal information.
Xactly shall use information collected for its relevant and intended purpose only. If there is any change of use of the personal information collected, Xactly shall inform you and gain your approval before making such changes of the use of the personal information collected. Further, Xactly shall take reasonable steps to ensure that the personal information collected is accurate and reliable for its intended use.
Access to Personal Information Received
Xactly shall provide you with reasonable access, as required by law, to your personal information in order to confirm that it is correct or to amend or delete inaccurate information. If you need to correct, update, or remove personal information provided to Xactly, please contact Xactly at: firstname.lastname@example.org.
Xactly has no direct relationship with the individuals whose personal data it processes. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to the Xactly’s customer (the data controller). If the customer requests Xactly to remove the data they can contact us at:email@example.com. We will endeavor to respond to all requests for access within 30 days.
Xactly will retain your personal information and the personal information we process on behalf of our customers for as long as needed provide services to our customers. Xactly will retain and use this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
225 W. Santa Clara Street, Suite 1200
San Jose, CA 95113
This Policy may be amended from time to time, consistent with the requirements of the Safe Harbor Privacy Principles. Appropriate notice of any material amendments we will notify you by email (sent to the e-mail address specified in your account) or by means of a prominent notice on this Site prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
For additional questions, or to be taken off our marketing lists, please send an e-mail firstname.lastname@example.org or to the contact information above.