1. Introduction

This privacy policy (“Privacy Policy”) explains when and why Canva UK Operations Limited (a Canva company), company number 08825531, registered address 33-35 Hoxton Square, London, N1 6NN (“Flourish” “we” “our” “us”) collect personal data, how we use it, the conditions under which we may disclose it to others, and how we keep it secure. Capitalized terms that are not defined in this Privacy Policy have the meaning given to them in our Terms and Conditions.

We may change this Privacy Policy from time to time, so please check this page occasionally to ensure that you’re happy with any changes. If there’s a material change we’ll contact you to let you know.

Any questions regarding our privacy practices and this Privacy Policy should be sent by email to [email protected], or in writing to Flourish Privacy, 33-35 Hoxton Square, London, N1 6NN.

2. Who are we?

Canva UK Operations Limited (‘Flourish’), company number 08825531, registered address 33-35 Hoxton Square, London, N1 6NN.

Flourish is the controller of, and responsible for, personal data of individuals who:

  • Use the Flourish service/s (the “Services”)

  • Attend Flourish-sponsored or hosted events, forums, workshops or websites;

  • Show interest in Flourish, (e.g. sign-up to newsletters, mailing lists or offers or request papers, content or articles we have published)

Flourish acts as a processor when it processes your personal data on behalf of:

I. your employer or organization (if they have a Business account for the Services);

II. a Canva Contracting Entity (as defined and identified in the Canva Terms of Use) if you’ve accessed the Services through Canva, or

III. another user, if your personal data has been uploaded to or used in the Service by that User in their professional capacity.

In those cases, the company we’re acting on behalf of, is the controller.

3. How do we collect information from you?

We obtain information about you when you give it to us (e.g. when you register your account, when you use Flourish, when you contact us, and when you sign up for our email newsletter or join us at an event); when you use our Services, including visits or uploads to our website. We may also collect certain technical information automatically through cookies and other tracking technologies, as described below. We may also receive some information about you from third-parties, (like your employer if they’ve asked us to set up an account for you, for example) or if you’ve used your Google or Canva account credentials to register with Flourish.

4. Why do we need your information?

Your information helps us to provide you with access to Flourish (like checking your credentials) and to use our Services (so we can make sure you can use all the features applicable to your plan). We use your information to administer your account, take payments from you (if applicable), provide you with news and updates on Flourish, information about Flourish products or Services which may interest you, and improve Flourish and its Services for you and other Users.

Sometimes we need to use your personal data to help us investigate or resolve problems and to make sure we can keep your account and all Services and events safe and secure.

If you’re not a Flourish User yet, but you’ve shown interest in us or events we’re running, sponsoring or hosting, we need information to be able to administer those events or send you information you’ve asked for.

5. What information do we collect from you?

a. Information about who you are

This includes things like your name, email address, company details and phone number (if applicable).

If you’re a Service User this might also include things like your username, display name, plus optional additional information about your company, job role and your intended use of the Services.

b. Payment information

If you purchase a subscription to the Service, we will collect and store your billing information (such as address and VAT number).

c. Customer Support, Feedback and Communications Information

If you contact us, for example to report a problem or send us a question, or respond to a survey or research, we store details of the communication. We may also store any phone number used to call our customer service number or social media handle used to connect with our customer service team.

d. Service & Usage Information

When you use the Service, we collect or derive certain information automatically such as the actions you take, and the time you take those actions. Where permitted, by using cookies, we also collect information such as the type of internet browser you use.

We also store any data and code you upload to the Service as part of your use of the Service, which may include personal data or sensitive information about you or others.

With regard to each of your visits to our website we will automatically collect the following information:

  • technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform; and

  • information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page. You cannot be identified from this aggregate information retained or used for these purposes.

For more information about our use of cookies and similar technologies and how you can control them, please read our Cookies Policy.

Where permitted, we may also record users’ screen sessions using the Fullstory tool or similar tools. These recordings may capture code, data and text that you have uploaded to the Service but will not capture other personally identifiable information.

6. How and why do we use your personal data?

We may collect, store, analyze, copy, share, test, aggregate, delete and generally process personal data to help us run our Service and business, including, for example, (non-exhaustive list) to:

  • carry out our obligations arising from any contracts entered into between you and us, including to process your payments, and validating your Plan to make sure you can access all the features applicable to your plan and provide you with the information, products and Services that you request from us;

  • to check authorisation and credentials for accessing the Service;

  • to administer your account and notify you of changes to our Services or important notices;

  • to help us investigate or resolve problems and to make sure we can keep your account and all Services and events safe and secure;

  • to provide you with information about Flourish, and other of our Services that may interest you;

  • to seek your views or comments on the Services we provide;

  • to administer our website and Services under our terms and for internal operations, including troubleshooting;

  • and, in our legitimate interests, data analysis, testing, research, statistical and survey purposes;

  • to improve Flourish and related affiliate businesses, products and websites to ensure that content is presented in the most effective manner for you and your computer;

  • to prevent, detect, investigate and address safety, security, fraud and abuse risks and to develop our algorithms and models to identify violations of this Privacy Policy or our Terms and Conditions (e.g. detecting content such as spam or offensive material);

  • to allow you to participate in interactive features of our Service, when you choose to do so;

  • to better understand our Users and how they like to use our Service, and whether they use other affiliate company products or services;

  • to measure and understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you; and

  • to make suggestions and recommendations to you and other Users about goods or Services that may interest you or them, subject to your stated preferences, where relevant.

  • If you’re not a Flourish Service User yet, but you’ve shown interest in us or events we’re running, sponsoring or hosting, we need information to be able to send you administer those events or send you information you’ve asked for.

We need a legal basis to collect, use and disclose your personal data. Our legal basis for collecting, using and disclosing your data will depend on the information concerned and the context in which it is processed. However, we will normally process your data:

  1. only where we need the data to perform a contract with you, for example, when you sign up to Services, we process your information to create and maintain your account in order to fulfill our contact with you, or if your information is processed to deal with business transactions, your information is processed to carry out pre-contractual measures, to deliver the Services or information we’ve agreed to.

  2. when we have your consent, for example you sign up for our newsletter or register for an event, or you’ve agreed to receive marketing emails from us.

  3. when we have legal obligations, for example such as for tax, accounting and audit purposes or to implement and maintain appropriate security measures;

  4. when we have a legitimate interest, for example when we make suggestions and recommendations to you, manage and improve our Service and understand the effectiveness of advertising we serve to you and others where it is in our legitimate interests to do. To carry out data analysis, testing, research, statistical and surveys to plan and develop our products and business. We do not rely on this lawful basis where our legitimate interests are overridden by your interests.

8. Who do we share your information with?

a. Our affiliates, employees and authorized contractors:

We may share your information, including personal data with any member or authorized contractor of Canva UK Operations Limited and our affiliates.

b. Our third-party service providers and partners:

We may share your information, including personal data, with third-party service providers and agents who work on our behalf and provide us with services related to the Service, including for:

  1. billing and credit card payment processing. All payment information is handled only by PCI-compliant organizations. When paying with a credit card, payment information is stored and processed by our payment providers on our behalf.

  2. maintenance,

  3. sales,

  4. marketing,

  5. administration,

  6. support,

  7. data enrichment,

  8. hosting, and

  9. database management services, or

  10. outside professional advisors,

  11. co-sponsors and presenters of webinars and events that you attend, or

  12. co-branded partners when you download or request certain marketing of such content.

Flourish may contain links to other websites run by other organizations. This Privacy Policy applies only to our website and Service, so we encourage you to read the privacy statements on the other websites you visit. We are not responsible for how they process your personal data.

ii. Profile, Project and Template visibility

Anyone with view access to your Projects (e.g. you and any colleagues in the same Company account) will see your Projects or Templates listed on your Profile page, along with your name, username and any additional information that you decided to add to your Profile. You can also optionally enable your Profile page to be publicly visible. If you do this, anyone on the internet will be able to view your published Projects and Profile information (but not any unpublished Projects).

iii. Business transactions

We may transfer your personal data to a third party as part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganization, or if we’re under a duty to disclose or share your personal data in order to comply with any legal obligation (such as a court order, subpoena or other legal obligation) or to enforce or apply our terms of use or to protect the rights, property or safety of our supporters and Users. However, we will take steps to ensure that your privacy rights continue to be protected in accordance with the terms of this Privacy Policy.

We will not sell or rent your information to third parties. We will also not share your information with third parties for their own marketing purposes.

We may disclose aggregate statistics about visitors to business partners, suppliers, sub-contractors for performance of the contract with you, and prospective purchasers of Flourish, but these statistics will not include any personally identifiable information about you.

iv. Law enforcement

For matters that we are required to use your information by law: Flourish will use or disclose your information where we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to enforce our Terms and Conditions or to protect the security or integrity of our Service; and/or (c) to exercise or protect the rights, property, or personal safety of Flourish, our Users or others.

9. Security

When you give us personal data, we take steps to ensure that it’s treated securely.

While we strive to protect your personal data, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk.

Where we have given (or where you have chosen) a password which enables you to access certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

10. How do we store your information?

Except where otherwise expressly agreed, your personal data is sent to and primarily stored on secure servers within the European Economic Area (EEA). This storage is necessary in order to process the information.

We may transfer your personal data to our other offices, affiliates and/or to the third parties mentioned in the circumstances described above (see “Who do we share your information with”), which may be situated outside the UK and EEA. These countries concerned may not offer an equivalent level of protection for personal data as laws in the UK and EEA.

Where personal data is transferred outside the UK and EEA in relation to providing our Service, we will take all steps reasonably necessary to ensure that your information is subject to appropriate safeguards, such as relying on a recognized legal adequacy mechanism or entering into approved standard contractual clauses relevant to transfers of personal data – as well as ensuring that your personal data is treated securely and in accordance with this Privacy Policy.

By using Flourish, you understand that your personal data may be transferred and processed outside the UK and EEA.

11. How long do we keep your information?

If you decide to close your account, your User Content, Projects and Profile information, and any Templates created by you that are not being used by other Users, will be deleted. Please note, Templates created by you that are already being used by other Users may continue to be available to those Users after deletion of your account.

For Frozen accounts, we will continue to store all Projects, Profile information and Templates for a minimum period of 2 years after closure of an account, in order to allow the account to be reactivated without any data loss. We reserve the right to delete all Templates, Profile information and Projects at the end of this period, or sooner on request from the company administrator who controls the account.

If we delete your account for other reasons – for example, for breach of our Terms and Conditions, we reserve the right to delete all Projects, Profile information and Templates without notice.

In any case, we may also be required to retain your information to comply with our legal, financial and audit obligations, and for backup and archival purposes.

12. Your rights and choices

You have a choice about whether or not you wish to receive information from us, and we will not contact you unless you have given prior consent. If you do not want to receive news, updates or marketing from us, please click the “Unsubscribe” link in any email, or contact us: support@flourish.studio (You will continue to receive any essential emails regarding your Flourish account.)

The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, you can correct this in the Flourish app on your Settings page, or by contacting us at support@flourish.studio.

You also have certain rights under applicable data protection laws.

You have the right to ask for a copy of the information we hold about you. To request this information, contact us at support@flourish.studio.

Under certain circumstances, you also have a right:

  • to request the rectification or erasure of your personal information held by us;

  • to withdraw your consent to the processing of your personal information, where we rely on your consent as our lawful basis to do so;

  • to object and request that we cease processing your information, where we rely on legitimate interests as our lawful basis to do so;

  • to request that we restrict the processing of your personal information (while we verify or investigate your concerns with this information, for example); and

  • to request that your information be provided in structured, commonly used and machine-readable format or transferred to a third party controller; and

  • in the UK, you also have the right to complain if you have concerns about how we use your personal data.

If you are unhappy with the way we have handled your information, you also have a right to complain to a supervisory authority. In the UK supervisory authority is the Information Commissioner. If you’re in an EU member state, you can find details of the relevant authority here.

If you are an individual and have questions or concerns about how your personal data is handled by one of our Flourish Users in one of their Projects or their User Content, you should contact the relevant User that is using our Service and refer to their separate privacy policies.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect our current practice and ensure compliance with applicable laws. When we post changes to this Privacy Policy, we will revise the “Last Updated” date at the top of this page. We encourage you to check this page occasionally to ensure that you’re happy with any changes. By using our Service, you confirm that you have read and understand this Privacy Policy.

14. Contacting us

Please submit any questions or comments you have about our privacy practices or this Privacy Policy, or any requests concerning your personal data information, by email to support@flourish.studio or write to us at: Flourish Team, Canva UK Operations Limited, 33-35 Hoxton Square, London, N1 6NN.

Our local representative in the EEA is European Data Protection Office (EDPO) with registered address at Ground Floor, 71 Lower Baggot Street, Dublin, D02 P593 Ireland. The EDPO can be contacted at info@edpo.com. If you are in the EEA, data subject request forms can be accessed at http://edpo.com/gdpr-data-request/.