Privacy Notice for Stack Overflow for Teams, Enterprise

Updated 24 September 2021

ABOUT STACK OVERFLOW

The Stack Overflow Network (also referred to herein as “Stack Overflow” or “Network”) is a set of related Internet sites and other applications for asynchronous collaboration and sharing knowledge, owned and operated by Stack Exchange, Inc. (“Stack Overflow”, “we” or “us”), a Delaware corporation.

Stack Overflow welcomes you to the Network, the largest community of developers and technologists in the world, and invites you to participate in the community by sharing knowledge with your peers and colleagues.

ABOUT STACK OVERFLOW ENTERPRISE

Stack Overflow’s Enterprise platform (“Enterprise”) is a private, secure Question and Answer platform for corporate customers (“Customer” or “Organization”). We offer two hosting options for Enterprise: we can host it on a private infrastructure on our customer’s behalf or it can be self-hosted within the customer’s own infrastructure. In providing services through our platform, we will process the personal data of users. The data which we collect from you varies depending on which option you choose.

Stack Overflow as Processor

When we provide Enterprise services to our Customers, the Customer acts as the controller and Stack overflow acts as the processor in respect of any personal data that is held or processed as a result. Any personal data that we process as part of the services will be on behalf of the Controller. Your organization retains the responsibility to comply with any applicable regulatory requirements including issuing any privacy notices and obtaining consent, where required, for processing personal data. You should read your organization’s privacy notice to find out more about how your data is processed and how you can exercise your rights. We are also required by data protection laws to sign a Data Processing Addendum (DPA) with your organization before we can process your personal data.

Stack Overflow as Controller

When you interact with us as an Enterprise customer, we will also collect and process certain information for our own purposes as controller. This includes personal data such as billing information, names, telephone number, email address and other contact details of key contacts and authorized users.

This Privacy Notice describes the personal data that we collect about you as controller when you interact with us as an Enterprise customer; how and why we collect it, how we use it, and how we keep it secure and your data privacy rights.

HOW WE COLLECT YOUR PERSONAL DATA

Stack Exchange Hosted Enterprise Instance

When you purchase an Enterprise instance which we host, we will collect the following information:

Information that you give to us

Account registration information Account registration information such as name, email address, IP address, that we will need from Customers or individuals granted access to your organization’s Private Network (“Authorized Users”).
Sales and other contact information Names and contact details of key contacts and representatives
Billing and account information Billing and accounting information

Information we generate or collect automatically through your use of Enterprise

Services metadata When an Authorized User interacts with the Services, metadata is generated that provides additional context about the way Authorized Users work.
Log data Our servers automatically collect information when you access or use our websites or Services and record it in log files. This log data may include the Internet Protocol (IP) address, the address of the web page visited before using the Website or Services, browser type and settings, the date and time the Services were used, information about browser configuration and plugins, language preferences and cookie data.
Device information Stack Overflow collects information about devices accessing the Services, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and crash data.
Location information We receive information from you and other third-parties that helps us approximate your location. For example, with your consent, we may collect information about the location of your mobile device (for example, by using GPS or Bluetooth).
Contact Information In accordance with the consent process provided by your device, any contact information that an Authorized User chooses to import (such as an address book from a device) is collected when using the Services.
Information collected from cookies and similar technologies We use cookies, which are small text files that collect and track certain technical information, and similar technologies to help us operate and provide our Services to you. We use this information for various reasons including to improve the quality of our services, improve your experience, understand user activity, and personalize content and advertisements. More information on how Stack uses cookies and how you can disable them can be found in our cookie policy.

Self-hosted Enterprise instance (On Premises)

When you purchase an Enterprise instance which you host, we will collect the following:

Information that you give to us

Account registration information Account registration information such as name, email address, IP address, that we will need from Authorized Users.
Sales and other contact information Names and contact details of key contacts and representatives
Billing and account information Billing and accounting information

Information we generate or collect automatically through your use of Teams Enterprise

Usage and diagnostic data In response to your support request(s), we may also manually collect data about your Enterprise instance in order to diagnose, troubleshoot, or resolve a bug or issue. We will never collect any of this data without your express consent and permission to do so. Such data could include active user counts, total questions asked and answered, error counts, and other aggregated data which at no time reveals any private or protected information contained within your Enterprise instance. In such a scenario, we will only collect the minimum data required to troubleshoot and resolve your expressed issue(s).

WHAT WE USE YOUR PERSONAL DATA FOR (PURPOSES)

When we host your Stack Overflow Enterprise instance, services metadata (as described above) is automatically and regularly transmitted to our diagnostic tools. We use this data for maintaining and enhancing the Stack Overflow Enterprise product and related services we provide.

When you host your Stack Overflow Enterprise instance in your own infrastructure, we receive no data.

Any content you provide in the course of your use of the Stack Overflow Enterprise product is shared privately with authorized users of your team, and may include private questions and answers, votes, source code, and other sensitive data. Our collection of such content is solely to provide the Products and Services and is provided as processor, pursuant to our DPA, terms and conditions, other Agreements with you and this Privacy Policy.

OUR LEGAL GROUNDS FOR USING YOUR PERSONAL DATA

We will only use your personal data when the law allows us to. We will use your personal data in the following circumstances:

  • Where we need to perform the contract we are about to enter into or have entered into with you. For example, when Customers purchase an Enterprise product, where you request a service from us, or where we need to set up your account or for billing purposes.
  • Where we have your consent. For example, where you have provided your consent to receive marketing emails from us or where you have given your consent to be contacted by a third party sponsor for an event you have participated in. You can withdraw your consent at any time. In the case of marketing emails, you can withdraw your consent by clicking on the “unsubscribe” link in the email you received.
  • Where we need to comply with a legal or regulatory obligation.
  • Where it is in our legitimate interests, including our commercial interests or a third party’s legitimate interest in using the personal information. Examples include when we carry out analysis to understand how our products are used and how we can improve them; carrying out marketing analyses to better understand your interests and preferences so that we can make our marketing more relevant to your interests and preferences. This includes when we promote our own products and services.

Whenever we rely on legitimate interests for processing, we ensure that we consider and balance our interests against the individual’s interests before processing. We do not use your personal data on the basis of legitimate interest for activities where individuals’ interests override our interests.

WHO DO WE SHARE YOUR PERSONAL INFORMATION WITH?

Any content you provide in the course of your use of the Stack Overflow Enterprise product is shared privately with authorized users of your Team, and may include private questions and answers, votes, source code, and other sensitive data. In addition, we will share your personal data as described in our General Privacy Notice.

INTERNATIONAL DATA TRANSFERS

We may share your personal data with entities within Stack Overflow and transfer it to internal and third party systems and service providers including data centers and cloud services providers based outside the UK and the EEA. More details about international transfers can be found in our General Privacy Notice.

WHERE WE PROCESS YOUR INFORMATION (LOCATIONS)

We will process your personal data as described in our General Privacy Notice.

OUR ONGOING COMMITMENT TO DATA SECURITY

Our commitment to data security is described in our General Privacy Notice.

YOUR RIGHTS

You have a number of rights in relation to your personal data and you can contact us if you want to exercise any of these.

Your rights include:

Access The right to be provided with a copy of your personal data also known as a "data subject access request"
Rectification The right to require us to correct any mistakes in your personal data
Erasure The right to require us to delete your personal data—in certain situations
Restriction of processing The right to require us to restrict processing of your personal data in certain circumstances (e.g., if you contest the accuracy of the data)
Data portability The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations
To object

The right to object:

  • at any time to your personal data being processed for direct marketing (including profiling);
  • in certain other situations to our continued processing of your personal data, (e.g. processing carried out for the purpose of our legitimate interests).

If you would like to exercise any of these rights, please email [email protected].

We may need to request specific information from you to help us confirm your identity before we can deal with your request. We will respond to your request within one month. If your request is complicated, it may take us longer. We will let you know if we need longer than one month to respond.

You also have the right to take your concerns at any time to the UK or EU Supervisory Authority, depending on your location.

HOW LONG WILL WE RETAIN YOUR PERSONAL INFORMATION FOR?

We will keep your personal data only for as long as is necessary for the purposes set out in this privacy notice and to fulfil our legal obligations. We will not keep more data than we need. While you remain an Enterprise customer or user, we will retain your data in order to keep providing services to you. We are required to keep some basic information about our customers for a longer period in accordance with applicable tax and other laws. In some circumstances you can ask us to delete your data. If you also interact with us through the Public website or on other Products, we may hold your personal data in relation to those other Products or Services.

YOUR CHOICES - HOW TO ACCESS AND CONTROL YOUR PERSONAL DATA

You can make choices about the collection and use of your data by Stack Overflow in the various ways set out below.

You may change or correct your account settings or you can inform your usual contact person.

You can also control your personal data that Stack Overflow has collected and exercise your data protection rights as set out in Your Rights, or by using the tools described below.

Promotional emails, notifications, SMS messages, telephone calls and postal mail from Stack Overflow

When we send promotional emails and texts, we will give you an ‘unsubscribe’ option to opt out of receiving such messages. You can opt out of receiving telephone calls. Occasionally, we may send promotional mail. You can let us know if you do not wish to receive mail by contacting us. You can also opt out in your Profile Settings.

Interest based advertising

We may carry out interest-based advertising through third party services such as Microsoft or Google, as described under Advertising, above. You can opt out of such advertising in the following ways:

  • You can control the use of your data for interest-based advertising from Microsoft by visiting their opt-out page.
  • You can opt out of advertising from Google or find out more by visiting Google's help center.

More information and resources on how you can control your ad choices and how to opt out of interest based advertising can be found on NAI Consumer Opt Out and YourAdChoices.com.

If you want to access or control personal data processed by Stack Overflow that is not available via the tools, please refer to Your Rights or contact us at [email protected].

HOW WE MAY CONTACT YOU

Service communications

From time to time, we may send you service emails, for example, how to use certain features of products you have bought or renewal reminders (if applicable).

Marketing and product communications, notifications and newsletters

From time to time, Stack Overflow may communicate with you about commercial and other Product and Services offerings and to let you know how you can continue to share, learn, and build your knowledge within the Stack Overflow community. You can opt-out of such messages at any time by changing your permissions in your Profile Settings or by telling your usual Stack Overflow contact. In some cases, e.g. third party offers, we will only send these if you have given us permission.

Direct marketing opt out

You may opt-out of receiving Stack Overflow email marketing materials by using the unsubscribe link in these communications or by changing your Email Settings.

ADDITIONAL INFORMATION FOR CALIFORNIA CONSUMERS

For details on California consumers, see our General Privacy Notice.

CHILDREN

The Stack Overflow platform is not intended for children. We do not knowingly offer this or any other Product or Service to anyone under the age of 16.

PRIVACY POLICY AMENDMENTS

We may amend or update this policy from time to time and will notify you of any material changes to this policy. Previous versions of this privacy policy are available upon request.

CONTACT US

Privacy Officer

  • Privacy Officer, 110 William Street, Floor 28, New York, NY 10038, [email protected], phone: 212-232-8280

UK Representative

  • Privacy Officer, Bentima House, 168-172 Old Street, London EC1V 9BP, [email protected], phone: +44 (0) 20 3349 1000

EU Representative

  • The MD Stack Overflow GMBH HRB 234500
    3 Frieslandstraat, Amsterdam,
    [email protected], phone: +44 (0) 20 3349 1000