Privacy Statement for SAP Ariba
This Privacy Statement was updated on 30.06.2020
Last Updated on 01.05.2018 - Access archived version
Protecting the individual”s privacy on the Internet is crucial to the future of Internet-based business and the move toward a true Internet economy. We have created this Privacy Statement to demonstrate our firm commitment to the individual”s right to data protection and privacy. This Privacy Statement outlines how we handle information that can be used to directly or indirectly identify an individual ("Personal Data").
Note: The SAP Ariba Privacy Statement for Cloud Services available at http://www.ariba.com/legal/privacy-policy describes SAP Ariba practices for processing personal data submitted to the SAP Ariba Cloud Services by customers.
- General Information
- Processing based on a statutory permission
- Processing based on consent
- Cookies and similar tools
- Country-Specific Provisions
A. General Information
Who is the Data Controller? The data controller of www.ariba.com is Ariba Inc., 3420 Hillview Ave, Palo Alto, CA 94304, USA (“SAP Ariba”). The SAP Group’s data protection officer can be reached at firstname.lastname@example.org.
What Personal Data does SAP Ariba collect? When you visit SAP Ariba’s websites, SAP Ariba stores certain information about your browser, the operating system, and your IP address. If you use a registration form, SAP Ariba will collect the information you provide to SAP Ariba, which consists of your first and last name, email addresses, telephone numbers, location (country, state/province, city), company name, job title/role, department and function, current relationship to SAP, and your company’s industry. If you provide a credit card number or bank details to order goods or services from SAP Ariba, then SAP Ariba will collect this information to process your payment for the requested goods or services.
Why does SAP Ariba need your Personal Data? SAP Ariba requires your Personal Data to provide you with access to this site; to deliver any ordered goods or services; and to comply with statutory obligations, including checks required by applicable export laws. Further information on why SAP Ariba needs your Personal Data can be found in Section B, below, if SAP Ariba’s use of your Personal Data is based on a statutory permission. Further information on why SAP Ariba needs your Personal Data can be found in Section C, below, if SAP Ariba’s use of your Personal Data is based on your consent. If SAP Ariba’s use of your Personal Data is based on consent, note that the information in this Privacy Statement on respective consent statements for certain types of Personal Data uses can also be found in the Consent Resource Center. As a general matter and although providing Personal Data is voluntary, SAP Ariba may not be able to perform or satisfy your request without it; for example, SAP Ariba might require your Personal Data to process an order you place, or to provide you with access to a web offering that you requested. In these cases, it is not possible for SAP Ariba to satisfy your request without certain Personal Data.
Kindly note that you can order goods or services without providing a consent into SAP Ariba’s further marketing operations.
From What Types of Third Parties does SAP Ariba obtain Personal Data? In most cases, SAP Ariba collects Personal Data from you. SAP Ariba might also obtain Personal Data from third parties, if the applicable national law allows SAP Ariba to do so. SAP Ariba will treat this Personal Data according to this Privacy Statement, plus any additional restrictions imposed by the third party that provided SAP Ariba with it or the applicable national law. These third-party sources include:
- SAP and/or SAP Group’s business dealings with your employer
- Third parties you directed to share your Personal Data with SAP Ariba
How long will SAP Ariba store my Personal Data? SAP Ariba will only store your Personal Data for as long as it is required:
- to make goods and services requested available to you, including using ariba.com;
- for SAP Ariba to comply with its statutory obligations resulting from applicable export laws;
- until you object against such use by SAP Ariba, if SAP Ariba’s use of your Personal Data is based on SAP Ariba’s legitimate business interest as further stated in this Privacy Statement;
- until you revoke your consent granted in this Privacy Statement, if SAP Ariba is processing your Personal Data based on your consent;
- to fulfill the purposes outlined in this Privacy Statement.
SAP Ariba will also retain your Personal Data for additional periods if it is required by mandatory law to retain your Personal Data longer or where your Personal Data is required for SAP Ariba to assert or defend against legal claims, SAP Ariba will retain your Personal Data until the end of the relevant retention period or until the claims in question have been settled.
Who are the recipients of your Personal Data and where will it be processed? Your Personal Data will be passed on to the following categories of third parties to process your Personal Data:
- companies within the SAP Group
- third party service providers; for e.g., for consulting services and other additional related services, for the provision of the website or newsletter dispatch
As part of a global group of companies operating internationally, SAP Ariba has affiliates (the “SAP Group”) and third-party service providers outside of the European Economic Area (the “EEA”) and will transfer your Personal Data to countries outside of the EEA. If these transfers are to a country for which the EU Commission has not issued an adequacy decision, SAP Ariba uses the EU standard contractual clauses to contractually require that your Personal Data receives a level of data protection consistent with the EEA. You can obtain a copy (redacted to remove commercial or irrelevant) of such standard contractual clauses by sending a request to email@example.com. You can also obtain more information from the European Commission on the international dimension of data protection here: European Commission.
What are your data protection rights? You can request from SAP Ariba: access at any time to information about which Personal Data SAP Ariba processes about you and the correction or deletion of such Personal Data. Please note, however, that SAP Ariba can or will delete your Personal Data only if there is no statutory obligation or prevailing right of SAP Ariba to retain it. Kindly note further that if you request that SAP Ariba deletes your Personal Data, you will not be able to continue to use any SAP Ariba service that requires SAP Ariba’s use of your Personal Data.
If SAP Ariba uses your Personal Data based on your consent or to perform a contract with you, you can further request from SAP Ariba a copy of the Personal Data that you have provided to SAP Ariba. In this case, please contact the email address below and specify the information or processing activities to which your request relates, the format in which you would like to receive this information, and whether the Personal Data should be sent to you or another recipient. SAP Ariba will carefully consider your request and discuss with you how it can best fulfill it.
Furthermore, you can request from SAP Ariba that SAP Ariba restricts your Personal Data from any further processing in any of the following events: (i) you state that the Personal Data SAP Ariba has about you is incorrect, subject to the time SAP Ariba requires to check the accuracy of the relevant Personal Data, (ii) there is no legal basis for SAP Ariba processing your Personal Data and you demand that SAP Ariba restricts your Personal Data from further processing, (iii) SAP Ariba no longer requires your Personal Data but you state that you require SAP Ariba to retain such data in order to claim or exercise legal rights or to defend against third party claims, or (iv) in case you object to the processing of your Personal Data by SAP Ariba based on SAP Ariba’s legitimate interest (as further set out below), subject to the time required for SAP Ariba to determine whether it has a prevailing interest or legal obligation in processing your Personal Data.
For individuals within the State of California, you instead have the right:
- to request from SAP Ariba access to your Personal Data that SAP Ariba collects, uses, discloses, or sells (if applicable) about you;
- to request that SAP Ariba delete Personal Data about you;
- to non-discriminatory treatment for exercise of any of your data protection rights;
- in case of request from SAP Ariba for access to your Personal Data, for such information to be portable, if possible, in a readily usable format that allows you to transmit this information to another recipient without hindrance; and
- to opt-out of the sale of Personal Data. In accordance with the disclosure requirements under the CCPA, SAP Ariba is exempt from providing a notice to opt-out because it does not and will not sell your Personal Data.
Please note, however, that SAP Ariba can or will delete your Personal Data only if there is no statutory obligation or prevailing right of SAP Ariba to retain it. Kindly note further that if you request that SAP Ariba deletes your Personal Data, you will not be able to continue to use any SAP Ariba service that requires SAP Ariba’s use of your Personal Data.
How can you exercise your data protection rights? Please post any requests to exercise your rights at https://support.ariba.com/privacy-request.
For individuals within the State of California, you may also exercise your rights as follows: You can call toll-free to submit a request using the numbers provided here. You can also designate an authorized agent to submit requests to exercise your data protection rights to SAP Ariba. Such authorized agent must be registered with the California Secretary of State and submit proof that you have given authorization for the agent to act on your behalf. If you are an Individual with a disability, contact SAP Ariba at the above address or toll-free phone number to access the Privacy Statement in an alternative format.
How will SAP Ariba verify requests to exercise data protection rights? SAP Ariba will take steps to ensure that it verifies your identity to a reasonable degree of certainty before it will process the data protection right you want to exercise. When feasible, SAP Ariba will match Personal Data provided by you in submitting a request to exercise your rights with information already maintained by SAP Ariba. This could include matching two or more data points you provide when you submit a request with two or more data points that are already maintained by SAP Ariba.
In accordance with the verification process set forth in the California Consumer Privacy Act (“CCPA”), SAP Ariba will require a more stringent verification process for deletion requests, or for Personal Data that is considered sensitive or valuable, to minimize the harm that might be posed to you by unauthorized access or deletion of your Personal Data. If SAP Ariba must request additional information from you outside of information that is already maintained by SAP Ariba, SAP Ariba will only use it to verify your identity so you can exercise your data protection rights, or for security and fraud-prevention purposes.
SAP Ariba will decline to process requests that are manifestly unfounded, excessive, fraudulent, or are not otherwise required by local law.
Right to lodge a complaint. If you take the view that SAP Ariba is not processing your Personal Data in accordance with the requirements in this Privacy Statement or under applicable data protection laws, you can at any time lodge a complaint with the data protection authority of the EEA country where you live or with the data protection authority of the country or state where SAP Ariba has its registered seat.
Can I use SAP Ariba’s services if I am a minor?
Children. In general, SAP Ariba websites and online services are not directed to users below the age of 16 years, or equivalent minimum age in the relevant jurisdiction. If you are younger than 16 or the equivalent minimum age in the relevant jurisdiction, you cannot register with and use this website or online services.
U.S. Children’s Privacy. SAP Ariba does not knowingly collect the Personal Data of children under the age of 13. If you are a parent or guardian and believe SAP Ariba collected information about a child, please contact SAP Ariba as described in this Privacy Statement. SAP Ariba will take steps to delete the information as soon as possible. Given that SAP Ariba websites and online services are not directed to users under 16 years of age and in accordance with the disclosure requirements of the CCPA, SAP Ariba does not sell the Personal Data of any minors under 16 years of age.
B. Processing based on a statutory permission
Why does SAP Ariba need to use my Personal Data and on what legal basis is SAP Ariba using it?
Processing to fulfill contractual obligation. SAP Ariba requires your Personal Data to deliver goods or services you order under a contract SAP Ariba has with you, to establish a contract for goods or services between you and SAP Ariba, and to send you invoices for ordered goods or services. SAP Ariba processes Personal Data to fulfill contractual obligations pursuant to Article 6(1) lit. b GDPR or the equivalent article under other national laws, when applicable.
Furthermore, SAP Ariba communicates on a regular basis by email with users who subscribe to its services and will also communicate by phone to resolve your or other customer complaints or to investigate suspicious transactions. SAP Ariba will use your email address to confirm your opening of an account, to send you notice of payments, to send you information about changes to its products and services, and to send notices and other disclosures as required by law. Generally, users cannot opt out of these communications because these communications are required for relevant business relationships and not marketing-related in nature.
For marketing-related communications such as emails and phone calls, SAP Ariba will (i) only provide you with such information after you have opted in, if legally required, and (ii) provide you the opportunity to opt out if you do not want to receive further marketing-related communications. You can also opt out of marketing-related communications at any time by updating your preferences at https://my.ariba.com/UnsubscribePage.html.
Processing to ensure compliance. SAP Ariba and its products, technologies, and services are subject to the export laws of various countries including, without limitation, those of the European Union and its member states, and of the United States of America. You acknowledge that, pursuant to the applicable export laws, trade sanctions, and embargoes issued by these countries, SAP Ariba is required to take measures to prevent entities, organizations, and parties listed on government-issued sanctioned-party lists from accessing certain products, technologies, and services through SAP Ariba’s websites or other delivery channels controlled by SAP Ariba. This could include (i) automated checks of any user registration data as set out herein and other information a user provides about his or her identity against applicable sanctioned-party lists; (ii) regular repetition of such checks whenever a sanctioned-party list is updated or when a user updates his or her information; (iii) blocking of access to SAP Ariba’s services and systems in case of a potential match; and (iv) contacting a user to confirm his or her identity in case of a potential match. Any such use of your Personal Data is based on the permission to process Personal Data in order to comply with statutory obligations (Article 6 para. 1 lit. c GDPR) and SAP Ariba‘s legitimate interest (Article 6 para. 1 lit. f GDPR) or the equivalent articles under other national laws, when applicable.
Furthermore, you acknowledge that any information required to track your data protection and privacy choices for processing of your Personal Data, or receipt of marketing materials (that is to say, depending on the country in which the relevant SAP Group company operates, whether you have expressly consented to or opted out of receiving marketing materials) may be stored and exchanged between members of the SAP Group as required to ensure compliance.
Processing based on SAP Ariba’s legitimate interest. SAP Ariba can use your Personal Data based on its legitimate interest (Article 6 para. 1 lit. f GDPR) or the equivalent article under other national laws, when applicable as follows:
- Fraud and Legal Claims. If required, SAP Ariba will use your Personal Data for the purposes of preventing or prosecuting criminal activities such as fraud and to assert or defend against legal claims.
- Questionnaires and survey. SAP Ariba could invite you to participate in questionnaires and surveys. These questionnaires and surveys will be generally designed in a way that they can be answered without any data that can be used to identify you. If you nonetheless enter such data in a questionnaire or survey, SAP Ariba will use this personal data to improve its products and services.
- Contract Performance. If you purchase or intend to purchase goods or services from SAP Ariba on behalf of a corporate customer or otherwise be the nominated contact person for the business relationship between a corporate customer (a “Customer Contact”) and SAP Ariba, SAP Ariba will use your Personal Data for this purpose. This includes, for the avoidance of doubt, such steps which are required for establishing the relevant business relationship. In case that an existing Customer Contact informs SAP Ariba that you are his replacement, SAP Ariba will, from the point in time of such notification, consider you to be the relevant Customer Contact for the respective customer until you object as further set out below.
- Creation of anonymized data sets. SAP Ariba will anonymize Personal Data provided under this Privacy Statement to create anonymized data sets, which will then be used to improve its and its affiliates’ products and services.
- Personalized Newsletter. If you opt-in to receive marketing communications such as newsletters from SAP Ariba, SAP Ariba will collect and store details of how you interact with the newsletters to help create, develop, operate, deliver and improve our newsletter communications with you. This information is aggregated and used to help SAP Ariba provide more useful information and to understand what is of most interest.
- Recordings for quality improvement purposes. In case of telephone calls or chat sessions, SAP Ariba will record such calls (after informing you accordingly during that call and before the recording starts) or chat sessions in order to improve the quality of SAP Ariba’s services.
- To keep you up-to-date or request feedback. Within an existing business relationship between you and SAP Ariba, SAP Ariba might inform you, where permitted in accordance with local laws, about its products or services (including webinars, seminars or events) which are similar or relate to such products and services you have already purchased or used from SAP Ariba. Furthermore, where you have attended a webinar, seminar or event of SAP Ariba or purchased products or services from SAP Ariba, SAP Ariba might contact you for feedback regarding the improvement of the relevant webinar, seminar, event, product or service.
Right to Object. You can at any time object to SAP Ariba’s use of your Personal Data as set forth in this section by updating your preferences at https://my.ariba.com/UnsubscribePage.html. In this case, SAP Ariba will carefully review your objection and cease further use of the relevant information, subject to SAP Ariba’s compelling legitimate grounds for continued use of the information, which override your interest in objecting, or if SAP Ariba requires the information for the establishment, exercise or defense of legal claims.
Processing under applicable national laws. If the applicable national law allows SAP Ariba to do so, SAP Ariba will use information about you for a business purpose, some of which is Personal Data
- to plan and host events
- to host online forums or webinars
- for marketing purposes such as to keep you updated on SAP Ariba’s latest products and services and upcoming events
- to contact you to discuss further your interest in SAP Ariba services and offerings
- to help SAP Ariba create, develop, operate, deliver and improve SAP Ariba services, products, content and advertising and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by SAP Ariba
- to provide more personalized information to you
- for loss prevention
- for account and network security purposes
- for internal purposes such as auditing, analysis, and research to improve SAP Ariba’s products or services
- to verify your identity and determine appropriate services
- to assert or defend against legal claims
- detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity
- debugging to identify and repair errors that impair existing intended functionality
- Short-term, transient use, provided the personal information is not disclosed to a third party and is not used to build a profile about you or otherwise alter your individual experience outside the current interaction, including, but not limited to, the contextual customization of ads shown as part of the same interaction
- Undertaking internal research for technological development and demonstration
- Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by SAP Ariba
C. Processing based on consent
In the following cases, SAP Ariba will process your Personal Data if you granted prior consent to the specific proposed processing of your Personal Data (Article 6(1) lit. a GDPR). Each below section about a processing operation of Personal Data is linked to one consent statement in the Consent Resource Center. If you re- open this Privacy Statement after you initially grant one or more consents, you will see the full Privacy Statement and not just information on the consents you granted.
News about SAP Ariba’s Products and Services. Subject to a respective provision and your consent, SAP Ariba may use your name, email and postal address, telephone number, job title and basic information about your employer (name, address, and industry) as well as an interaction profile based on prior interactions with SAP Ariba (prior purchases, participation in webinars, seminars, or events or the use of (web) services - further details on this topic can be found in the Cookie Statement displayed on the relevant SAP Ariba website) in order to keep you up to date on the latest product announcements, software updates, software upgrades, special offers, and other information about SAP Ariba’s software and services (including marketing-related newsletters) as well as events of SAP Ariba and in order to display relevant content on SAP Ariba’s websites. In connection with these marketing-related activities, SAP Ariba may provide a hashed user ID to third party operated social networks or other web offerings (such as Twitter, LinkedIn, Facebook, Instagram or Google) where this information is then matched against the social networks’ data or the web offerings’ own data bases in order to display to you more relevant information.
Creating user profiles. SAP Ariba offers you the option to use its web offerings including forums, blogs, and networks (such as the SAP Ariba Community) linked to this website that require you to register and create a user profile. User profiles provide the option to display personal information about you to other users, including but not limited to your name, photo, social media accounts, postal or email address, or both, telephone number, personal interests, skills, and basic information about your company.
These profiles may relate to a single web offering of SAP Ariba or, if created in the SAP Cloud Platform Identity Authentication Service, may also allow you to access other web offerings of SAP Ariba or of other entities of the SAP Group, or both (irrespective of any consent granted under the section “Forwarding your Personal Data to other SAP companies.” below). It is, however, always your choice which of these additional web offerings you use, and your Personal Data is only forwarded to them once you initially access them. Kindly note that without your consent for SAP Ariba to create such user profiles SAP Ariba will not be in a position to offer such services to you where your consent is a statutory requirement that SAP Ariba can provide these services to you.
Within any web offering, beyond the mere provision of access your profile is used to personalize interaction with other users (for example, by way of messaging or follow functionality) and by SAP Ariba to foster the quality of communication and collaboration through such offerings and for SAP Ariba to provide gamification elements (gamification is the process of taking something that already exists, such as a website, an enterprise application, or an online community, and integrating game mechanics into it to motivate participation, engagement, and loyalty). To the greatest extent supported by the relevant web offering, you can use the functionality of the relevant web offering to determine which information you want to share.
Special categories of Personal Data. In connection with the registration for and provision of access to an event or seminar, SAP Ariba may ask for information about your health for the purpose of identifying and being considerate of individuals who have disabilities or special dietary requirements throughout the event. Any such use of information is based on the consent you grant hereunder.
Kindly note that if you do not provide any such information about disabilities or special dietary requirements, SAP Ariba will not be able to take any respective precautions.
Event profiling. If you register for an event, seminar, or webinar of SAP Ariba, SAP Ariba may share basic participant information (your name, company, and email address) with other participants of the same event, seminar, or webinar for the purpose of communication and the exchange of ideas.
Forwarding your Personal Data to other SAP companies. SAP Ariba may transfer your Personal Data to other entities in the SAP Group. The current list of SAP Group entities can be found here. In such cases, these entities will then use the Personal Data for the same purposes and under the same conditions as outlined in this Section C. above.
Forwarding your Personal Data to other third Parties. At your request, as indicated by your consent, SAP Ariba will transfer your registration data to the companies listed on the registration page. The companies will use your registration data for the purposes of their participation in the event and are obliged to delete the data thereafter. If a company intends to use your data for any other purposes, they will contact you to explain how and for which other purposes they will use your registration data.
Revocation of a consent granted hereunder. You may at any time withdraw a consent granted hereunder by unsubscribing at https://my.ariba.com/UnsubscribePage.html. In case of withdrawal, SAP Ariba will not process Personal Data subject to this consent any longer unless legally required to do so. In case SAP Ariba is required to retain your Personal Data for legal reasons your Personal Data will be restricted from further processing and only retained for the term required by law. However, any withdrawal has no effect on past processing of personal data by SAP Ariba up to the point in time of your withdrawal. Furthermore, if your use of an SAP Ariba offering requires your prior consent, SAP Ariba will not be (any longer) able to provide the relevant service (or services, if you revoke the consent for SAP Ariba to use your profile under the SAP Cloud Platform Identity Authentication Service for multiple SAP Ariba offerings), offer or event to you after your revocation.
D. Cookies and Similar Tools
Information gathered by cookies or similar technologies, and any use of such information, is further described in SAP Ariba’s Cookie Statement. You can exercise your cookie preferences as outlined in SAP Ariba’s Cookie Statement.
E. Additional Country Specific Provisions
Where SAP Ariba is subject to U.S. privacy requirements, the following also applies: Do Not Track. Your browser may allow you to set a “Do not track” preference. Unless otherwise stated, our sites do not honor “Do not track” requests. However, you may elect not to accept cookies by changing the designated settings on your web browser or, where available, by referring to our Cookie Statement. Cookies are small text files placed on your computer while visiting certain sites on the Internet used to identify your computer. Please note that if you do not accept cookies, you may not be able to use certain functions and features of our site. This site does not allow third parties to gather information about you over time and across sites.