At Harness, we care about your privacy. This privacy notice explains what personal data (information about you) we collect when you visit a Harness office, why and how we use it, and what rights you have. We aim to be open with you and to use your data fairly, lawfully, and securely.
If you have any questions about how we use your data, please contact us using the details below.
The Harness company that runs the office you visit is the “data controller” for your visitor data.
This notice applies to you if you visit a Harness office as an external visitor, for example:
How your visit is managed depends on the type of office:
Your Harness host registers you in advance with building reception, using your name and expected arrival time. Building reception then gives you a QR code that works for the length of your visit. Building reception and QR codes are run by building management, not by Harness.
When you arrive on the Harness floor, you check in on our Envoy iPad system, which collects:
You will get a paper badge. It does not open any restricted areas, and someone from Harness will stay with you throughout your visit. You need to provide the information listed above and sign the visitor NDA to enter our office. If you do not, we may not be able to let you in.
If you are a regular vendor, you will get a badge through our Brivo access system. The system records the date and time each time you use the badge.
Some of our offices use CCTV. To find out how we use CCTV footage and what your rights are, please see our CCTV Notice: https://www.harness.io/legal/cctv-privacy-notice.
We do not intentionally collect “special categories of personal data” (sensitive information, such as health data). If you tell us about an accessibility need (for example, wheelchair access), we use that information only to help with your visit and do not keep a record of it.
We only use your personal data as data protection laws allow. The table below shows why we use it and the “legal basis” (the legal reason under the GDPR) for each use:
When we rely on “legitimate interests”, we have checked that our interests do not override your rights and freedoms. In particular: visitors expect to identify themselves and be recorded when entering business premises; we collect only a small amount of business-related information; we tell you about it when you check in; we keep it for a limited time; and we do not use it to make decisions that negatively affect you. You can object to this use of your data at any time (see Section 9).
To protect your privacy, we only share your data when it is necessary and when appropriate security safeguards are in place. The following people and organizations may see or receive your data.
Internal access to your personal data is provided to our personnel strictly on a need-to-know and case-by-case basis.
External service providers and other recipients:
Legal authorities:
For any international data transfers, we implement appropriate safeguards and mechanisms, including EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework that any recipient may hold, or relevant adequacy decisions.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, protecting personal data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or disclosure. For more information on our security practices, please visit our Trust Center at trust.harness.io.
We keep your personal data only as long as we need it for the purposes described in this notice, in line with our internal retention rules:
We may keep data for longer if the law requires it or if we need it to deal with legal claims.
We do not use automated decision-making, including profiling (decisions made only by computer, without a person involved), that has legal or similarly significant effects on you in connection with your visit.
Under the GDPR, you have the following rights in relation to your personal data:
The right to data portability (getting your data in a format you can move elsewhere) does not apply, because we do not rely on your consent or on a contract to use visitor data. These rights have limits, and in some situations a right may not apply. You can use your rights through our privacy portal at harness-privacy.relyance.ai.
If you are in the EEA or the UK, you can contact our EU Representative using the details in Section 1. You also have the right to complain to your local data protection authority (called a “supervisory authority”).
If you live in a US state with a consumer privacy law (such as California, Colorado, Connecticut, Oregon, Utah, Virginia, Texas, or other applicable states), you may have the right to access, correct, and delete your personal data. We do not sell or share visitor personal information, and we do not collect sensitive personal information (as defined under applicable US state privacy laws) about visitors. We will not treat you unfairly for using your privacy rights. To make a request, use our privacy portal at harness-privacy.relyance.ai. If your state law lets you appeal our decision, you can do so through the same portal.
If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to get a summary of your personal data and how we use it, to ask us to correct or delete it, and to name another person to use your rights for you. You can also complain to the Data Protection Board of India. You can use these rights through our privacy portal at harness-privacy.relyance.ai.
If you think we have not respected your data protection rights, you can complain to your local data protection authority, for example:
We may update this privacy notice from time to time. When we do, we will change the “Last updated” date at the top of this page. If we make important changes to how we use your personal data, we will tell you clearly [at our office reception points and on our website] before the change takes effect.