CBRE Host Building Platform Global Privacy Notice
Last Updated: 21 July 2023
Last Reviewed: 21 July 2023
This CBRE Host Core Platform Global Privacy Notice (“Notice”) is issued by CBRE, Inc. and its group entities (collectively, “CBRE”) to assist you in understanding collection and handling practices with respect to information that relates to you or any other identifiable individual (“Personal Information”) when you use CBRE’s Host Building mobile application or Host Building (Desktop) application, whether such applications are branded as CBRE offerings, or have been re-branded as an offering of a CBRE Client (collectively, the “Host Building Platform”).
This Notice is also intended to assist you in making informed decisions and exercising your data privacy rights under applicable law.
Table of Contents
- Information About the Responsible Entity
- Personal Information Collected and Sources
- Use of Personal Information
- Sharing of Personal Information
- Retention of Personal Information
- How We Secure Personal Information
- Use of Performance Tracking Technologies
- International Data Transfers
- Your Data Privacy Rights
- Contact CBRE
- Changes to this Notice
|SCOPE||This Notice applies to the Personal Information processed when you use the CBRE Host Building Platform.|
|PERSONAL INFORMATION COLLECTED / SOURCES||
The Host Building Platform may collect and process the following Personal Information, depending on (i) the nature of the building where Host Building services are being provided and (ii) the functions made available in the version of the Host Building Platform licensed for your use:
The Host Building Platform may collect the above-described information from: (i) directly from you, (ii) as generated through your use of the Host Building Platform, or (iii) from any party inviting you as a visitor to a property where Host Building services are provided.
See details below in Personal Information Collected and Sources.
|SPECIAL CATEGORY / SENSITIVE PERSONAL INFORMATION WE COLLECT||
Where permitted under applicable law, when you register for events or classes, we may also (indirectly) process information (also known as “Special Category” or “Sensitive” Personal Information in some jurisdictions) including Personal Information that may indicate, or allow one to make inferences about, your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or Personal Information concerning your physical or mental health, sexual life, or sexual orientation.
This information is not directly collected, requested or recorded, but rather may be inferred based on the nature of classes and/or events for which you register, food you may order, vendors you may patronize or other activities in which you may engage using the Host Building Platform.
The Host Building Platform does not request, create or retain records of Special Categories of Personal Information associated with any user.
See details below in Personal Information We Collect and Sources.
|USE OF YOUR PERSONAL INFORMATION||
The Host Building Platform uses your Personal Information in order to facilitate your access to the Host Building Platform, communicate and manage our relationship with you, provide you with Host Building services (such as space reservation, class or event registration, administering attendance at classes or events, fulfilling service requests, and facilitating visitors’ access to the relevant property), and analyzing use and performance of the Host Building Platform.
We process the above-described Personal Information, where necessary, in each case in order to perform our obligations under our contracts with our clients (i.e. providing you with Host Building services via the Host Building Platform) or based on your consent (if required by law).
See details below in Use of Personal Information.
CBRE, acting on behalf of your building owner, manager, or landlord (the “CBRE Client”), may share your information with our service providers, with vendors and event organizers, or with flexible space providers engaged at the property where CBRE is providing Host Building services or by CBRE’s client to provide you with flexible working space that may be reserved using the Host Building Platform.
See details below in Sharing of Personal Information.
Personal Information collected by the Host Building Platform will be retained in accordance with applicable regulatory and contractual requirements, and in consideration of legitimate business objectives and for the duration necessary to fulfill the purposes described in this notice.
See details below in Retention of Personal Information.
CBRE implements appropriate technical and organizational security measures to safeguard the Personal Information collected and processed by the Host Building Platform against loss and unauthorized alteration or disclosure.
See details below in How We Secure Your Personal Information.
|PERFORMANCE TRACKING TECHNOLOGIES||
Please see details in Use of Performance Tracking Technologies below.
|INTERNATIONAL DATA TRANSFERS||
CBRE may share your Personal Information with other CBRE Group, Inc. entities and service providers located outside of your home country as is necessary to administer the functioning of the Host Building Platform or to provide you with Host Building ervices. When doing so, CBRE implements appropriate safeguards for international data transfers as required by applicable law.
See details below in International Data Transfers.
Depending on the laws in your country, you may have certain rights to request access, rectification, deletion, objection, or other actions regarding your Personal Information.
See details below, including how to exercise any privacy rights you may have under applicable law, in Your Data Privacy Rights.
You are always free to contact us if you have questions or concerns about this Notice or our Personal Information collection and processing activities.
See details below in Contact CBRE.
|DATA PROTECTION OFFICER||
Where required by law, we have appointed a data protection officer whose contact details are disclosed in this Notice.
See details below in Data Protection Officers.
We have appointed a representative for any responsible CBRE entity located outside of the EEA and the UK that process Personal Information subject to the EU General Data Protection Regulation and UK data protection law.
See details below in EU and UK Representative.
|CHANGES TO THIS NOTICE||
If we make any material changes to this Notice, we will publish changes to the link where you are viewing this Notice and, if the changes are significant, we will provide a more prominent notification that changes have been made.
See details below in Changes to this Notice.
Depending on the legal regulations in your country and the applicable laws to which you are subject (such as in the EU/EEA and UK), you may have the right to information about the entity (or entities) responsible for collecting and processing your Personal Information (also known as the “Data Controller” in some jurisdictions). The Responsible Entity/Data Controller can be identified by viewing the Privacy Notice that is published in the “Settings” menu of the version of the Host Building Platform that has been licensed to you.
a. Categories of Personal Information We Collect
Where we may lawfully do so under applicable law, the Host Building Platform collects the following categories of Personal Information directly from you or from other sources, such as your contact when you visit a building where the Host Building Platform is in use and/or Host Building services are being provided by CBRE (for more information on data sources, see Personal Information Collected and Sources, below).
- For Commercial Properties, Employment Information: such as the name of your employer, your business email address, business telephone number, and your office location.
- For Residential Properties, Tenancy Information: such as your residential address at the relevant property.
- Personal Identifiers and Contact Information: such as your name, personal (non-business) email address, personal telephone number, and, if you choose to provide it, your photograph.
- Credential Information: such as the username and/or password you create or are assigned when you create your user profile upon registration to use the Host Building Platform.
- Administrator Role Information: such as the teams and roles to which an administrator is assigned and the related Host Building Platform permissions, functions and access associated with such teams and/or roles.
- Device Information: such as unique IDs associated with your device and device geolocation.
- Special Category/Sensitive Information: such as Personal Information revealing or relating to your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or Personal Information concerning your physical or mental health, sexual life, or sexual orientation.
- Event Registration Information: such as information related the events and/or classes you register to attend using the Host Building Platform, including the name, time, location, and nature of the class/event and the fact that you wish to attend the class/event.
- Service Request Information: such as any information you voluntarily provide in relation to a service request, including the nature of your request, the location where service is needed, the contact information of the person who will be present for, or whose office/until the service is needed, and any additional information you provide in relation to the request.
- Visitor Contact Information: such as the name, business or personal (non-business) email addresses of visitors invited to the relevant property by a Host Building Platform user.
b. Special Categories of Personal Information
To the extent permitted under applicable law, The Host Building Platform may indirectly collect and process categories of Personal Information relating to you which (depending on the laws and regulations to which you are subject, such as the GDPR in the EU/EEA) enjoy special protection by qualifying as Special Categories of Personal Information, Sensitive Personal Information or similar.
Examples of such Special Categories or Sensitive Personal Information include the Special Category/Sensitive Data described in Section 2. (a) above. The Host Building Platform will collect and process those categories of Personal Information only where allowed by law and where there is a lawful basis for doing so, including your consent, subject to any restrictions and additional safeguards as required by law.
This information is not directly collected, requested, or recorded, but rather may be inferred based on the nature of classes and/or events for which you register, food you may order, vendors you may patronize or other activities in which you may engage using the Host Building Platform.
The Host Building Platform does not request, create or retain records of Special Categories of Personal Information associated with any user.
c. Sources From Whom Personal Information is Collected
The Host Building Platform collects Personal Information directly from you when you provide such information directly via the Host Building Platform, or through your activities within, and use of, the Host Building Platform.
If you visit a workplace or residential property where CBRE is providing Host Building services to the owner, landlord or property manager, the individual who has invited you, or your other contact at that property may provide us with your name and business or personal email address to facilitate your being granted access to the property.
d. Consequences of Not Providing Personal Information
CBRE may require certain Personal Information in order to:
- provide you with access to the Host Building Platform,
- perform the Host Building services our Client has contracted with us to provide to you,
- facilitate your receipt of services from engaged third-parties (such as third-parties administering classes or events you wish to attend), or
- comply with our legal obligations.
If you fail to provide such Personal Information when requested, you may not be able to access the Host Building Platform or utilize all the functions of the Host Building Platform.
The purposes for which the Host Building Platform uses your Personal Information are as follows:
- To enable your access to the Host Building Platform, where necessary the Host Building Platform may process your Credential Information and: (i) Employment Information and verify it with Employment Information provided by your employer or their landlord or property manager; or (ii) Tenancy Information, and verify it with Tenancy Information provided by your landlord or property manager.
- To facilitate administration of the Host Building Platform and Host Building Services at a given property, where necessary we may process Employment Information, Tenancy Information, Contact Information, Credential Information, and Administrator Information.
- To communicate and manage our relationship with you, where necessary the Host Building Platform may process your Employment Information or Personal Identifiers and Contact Information to contact you with information about the Host Building Platform or the relevant property, or any requests you make through the Host Building Platform.
- To administer and address service requests, including dispatching personnel to provide necessary services and to communicate with you regarding resolution of the same, where necessary the Host Building Platform may process your Employment, Tenancy Information and/or Personal Identifiers and Contact Information (as is appropriate/relevant) and Service Request Information, where appropriate.
- To process requests to reserve space at the relevant property, including reservation of desk and conference room space, and notifications of intent to work on location at commercial properties, or common areas or other reservable space at residential properties, where necessary the Host Building Platform may process your Employment, Tenancy, and/or Personal Identifiers and Contact Information (as is appropriate/relevant) and Device Information.
- To manage access of visitors to the property and maintain security and safety, where necessary the Host Building Platform may process Visitor Contact Information, as well as the Employment, Tenancy and/or Personal Identifiers and Contact information of the individual submitting notice of a visitor to the property.
- To allow you to register for, and administer your attendance at, some events or classes, where necessary the Host Building Platform may process your Employment Information, Personal Identifiers and Contact Information, Event Registration Information and Special Category/Sensitive Information.
- To allow you to register for some events or classes, where such classes/events are administered by a third party, the Host Building Platform facilitates the collection of Event Registration Information by the relevant third parties by linking directly to their web pages. You will be notified when you are being redirected to such third parties. In such cases these third parties act as controllers of this information, and we encourage you to read their privacy notices to understand how they will use and store your information.
- To assign an anonymized identifier for use and analysis of usage of the Host Building Platform, the Host Building Platform may process your Device Information.
Where permitted under applicable law, the Personal Information collected by the Host Building Platform may be shared and processed with the following categories of recipients, some of whom may be located in a country that does not provide an adequate level of data privacy and protection rights as your home country, as necessary for the purposes identified in Section 3 – Use of Personal Information, above. CBRE has in place appropriate safeguards regarding internal Personal Information sharing. See Section 8 - International Data Transfers below for more information. To the extent possible, Personal Information is shared in an aggregated, pseudonymized or anonymized format.
a. Internally with Other CBRE Entities
Personal Information collected by, or that you provide to the Host Building Platform may be shared with and processed by other CBRE entities as necessary for the purposes identified in Section 3 – Use of Personal Information, above and in accordance with applicable law and regulation.
b. With Third Parties
The potentially relevant third parties include:
- Service Providers who assist CBRE with infrastructure and IT services, including cloud service providers.
- Consultants and advisors who assist us with legal, regulatory, and business operations activities, such as legal counsel, compliance consultants and business auditors.
- Third-Party partners who provide CBRE with licensed technology used in the Host Building Platform.
- The CBRE Client that has engaged us to provide you with access to the Host Building Platform and to provide Host Building Services (i.e., the owner, Landlord, or manager of the relevant property).
- Flexible working space providers who have been engaged by your employer to provide you with flexible working space that may be reserved using the Host Building Platform.
- Third Party Service Providers and/or CBRE Group Entities responsible for responding to Service Requests submitted through the Host Building Platform.
- Third Party Vendors/Service Providers who administer classes/events for which you register.
- Host Building Platform users who you may be visiting at the property who provide us with information necessary to grant you access.
- Business partners in case of a merger or sale, such as if CBRE is merged with another organization, or in the event of a transfer of our assets or operations.
CBRE may be required to disclose your Personal Information to governmental and regulatory authorities, law enforcement agencies, courts and/or litigants when legally compelled to do so, for example, in response to a court order, subpoena or other lawful, legally binding request, including to meet national security or law enforcement agencies requirements, or in connection with legal proceedings or similar processes as necessary to exercise or defend our legal rights.
CBRE is committed to not disclose your Personal Information in response to an international court order or a subpoena or other legal obligation, unless we are legally compelled to do so under applicable law. In particular, CBRE, Inc. has assessed and is of the view that neither it nor its US subsidiaries qualify as a provider of electronic communication service, as defined in 18 U.S.C. § 2510, nor a provider of a remote computing service, as defined in 18 U.S.C. § 2711, and thus US public authorities cannot issue a legally binding demand for disclosure of data under Section 702 of the US Foreign Intelligence Surveillance Act ("FISA 702") upon CBRE, Inc. or its US subsidiaries. In case CBRE nevertheless receives at some point a disclosure demand for Personal Information under FISA 702, we will publish a Transparency Report on cbre.com and our EEA websites (see our Schrems II statement). All Personal Information transferred by CBRE to the US is encrypted in transit.
CBRE will retain your Personal Information in accordance with all applicable regulatory and contractual requirements. In addition, the duration of retention will be determined by the following factors:
- The purpose for which the data was collected, including the purposes described in Section 3 of this Notice, and whether continued retention of the data is necessary to fulfill those purposes; and
- Whether the record in question is relevant to contractual or financial requirements (e.g., records of transactions between individuals and CBRE).
Data may also be deleted sooner, including by user request or due to a period of extended user inactivity.
CBRE implements appropriate technical and organizational security measures to safeguard the Personal Information we collect and process about you against loss and unauthorized alteration or disclosure. The information you provide is encrypted in transit and at rest. We utilize role-based access controls to limit access to your Personal Information on a strict need-to-know basis consistent with the purposes for which we have collected such information. We utilize anti-malware and intrusion detection systems to guard against unauthorized access to our network, and we have an incident response plan in place to quickly respond to any suspected leak or breach of Personal Information.
Where we share your Personal Information with our service providers, we have assessed that their technical and organizational measures provide an appropriate level of security.
Cookies: The Host Building (Desktop) Application utilizes cookies for the limited purpose of user authentication. Cookies are not utilized for performance tracking, targeting or other non-essential purposes.
Performance Tracking: Analytics data collected using performance tracking technology is not individually associated with you, nor can CBRE or its clients identify you using this data. This data includes information on application usage trends and engagement. Depending on the version of the Host Building Platform licensed by the relevant CBRE Client for your use, the “Analytics Permission” menu of the “My Profile” section of the Host Building Platform allows you to opt in or out of this technology being activated.
Please note that a limited subset of anonymous engagement metrics cannot be disabled through your profile settings, which are utilized to track aggregated content metrics, but cannot be used to identify you individually.
Depending on the location of the CBRE Client who has engaged CBRE to license the Host Building Platform for your use, and the recipients (see Section 4 - Sharing of Personal Information above), your Personal Information may be processed and hosted in countries other than your home country, such as the United States, Mexico, Singapore, India, the Philippines and Australia. Those other countries may have less stringent data protection laws than the country in which you reside, in which you initially provided the information and/or in which your information was originally collected. No such transfers will be initiated unless permitted under both applicable law and the Host Building Platform Services Agreement between CBRE and the Client who has engaged CBRE to license the Host Building Platform for your use.
In case of international data transfers, CBRE will protect your Personal Information as required by all applicable data protection laws.
a. EEA and UK to Non-EEA Data Transfers
With respect to international data transfers initiated by CBRE from the European Economic Area ("EEA") or UK to recipients in any non-EEA jurisdictions,
- some recipients are located in countries which are considered as providing for an adequate level of data protection under EU law (or UK law, as applicable). These transfers do not, therefore, require any additional safeguards under EU (or UK, as applicable) data protection law.
- other recipients are located in countries not providing an adequate level of data protection under EU or UK law, such as such as the United States, Mexico, Singapore, India, the Philippines and Australia, and, where required by law, we have implemented appropriate safeguards, such as EU Standard Contractual Clauses, and/or are relying on binding corporate rules of the recipient or an appropriate derogation. Where applicable, we implement supplementary technical and contractual safeguards. Under applicable law you may have the right to ask for further information on such appropriate safeguards (see Section 10 - Contact CBRE below).
As stated above (see Section 4.c - Legally Compelled Disclosures), CBRE, Inc. has assessed and is of the view that US public authorities cannot issue a lawful disclosure demand for Personal Information under FISA 702 upon CBRE, Inc. or its US subsidiaries. All Personal Information transferred by CBRE to the US is encrypted in transit.
Depending on the legal regulations in your country and the applicable laws to which you are subject, you may have all or some of the following rights set out below and may submit a request(s) to exercise any such rights through our Data Subject Rights Portal or by contacting us at [email protected]. Irrespective of the =entity that is responsible for the processing of your Personal Information as Data Controller or the equivalent under applicable law, you may use such centralized contact details and CBRE will ensure that the responsible entity receives your request and addresses it promptly as required by applicable law.
- Right of access: You may have the right to obtain confirmation as to whether your Personal Information is being processed, and, where that is the case, to request access to your Personal Information. You may have the right to obtain a copy of your Personal Information undergoing processing. For additional copies requested by you, a reasonable fee based on administrative costs may be charged.
- Right to rectification: You may have the right to obtain the rectification of inaccurate Personal Information concerning you.
- Right to erasure (right to be forgotten) or anonymization: You may have the right to ask us to erase (or in some jurisdictions, anonymize) your Personal Information. In some jurisdictions, this right may be limited to deletion or anonymization of data that is unnecessary, excessive, or unlawfully processed, or deletion of data that is processed based on your consent.
- Right to restriction of processing: You may have the right to request the restriction of processing your Personal Information.
- Right to data portability: You may have the right to receive your Personal Information which you have provided to the Host Building Platform in a structured, commonly used and machine-readable format and you may have the right to transmit such Personal Information to another entity without hindrance.
- Right to withdraw consent: If we rely on your consent for any Personal Information processing activities, you have the right to withdraw or revoke this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal. This right to withdraw consent applies in particular to consents given for marketing and profiling purposes, if any.
- Right to object: Under certain circumstances, you may have the right to object, on grounds relating to your particular situation, at any time to the processing of your Personal Information by the Host Building Platform, and CBRE can be required to no longer process your Personal Information unless the relevant responsible entity or Data Controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. The right to object may, in particular, not exist if the processing of your Personal Information is necessary to take steps prior to entering into a contract or to perform a contract already concluded.
- Right to request an explanation of our processing activity of your Personal Information
- Right to information on the possibility to withhold consent and information on the consequences of doing so.
- Right to information on third parties with whom we have shared your data.
- Right to lodge a complaint with the competent data protection authority in your home country or in the country in which the responsible entity is located, in particular with respect to the result of automated decision-making. A list of European Union Data Protection Authorities is available from the European Data Protection Board. In Brazil, the competent data protection authority is the Autoridade Nacional de Proteção de Dados (ANPD).
In addition to other rights provided under applicable law, with respect to Personal Information collected and processed within Brazil, you may have the right to request review of decisions taken solely based on the automated processing of Personal Information which affects your interests, including decisions aimed at defining their personal, professional, consumption and credit profiles or aspects of their personality.
In addition to other rights provided under applicable law, with respect to Personal Information collected and processed within China, you may have a right to deregister as a user of an application and cancel online accounts.
You are always free to contact us if you have questions or concerns regarding this Notice or our data handling practices. We may contact you by email in relation to any Observations, Incidents, and Self-Certifications you report or make. If you prefer us to contact you in an alternative manner, please let us know and we will accommodate your request if possible and appropriate.
a. General Enquiries
You may contact CBRE’s Global Data Privacy Office (“GDPO”) at [email protected] or by writing to us at 321 North Clark Street, Suite 3400, Chicago, Illinois 60654, Attention: Global Director, Data Privacy. You may also raise questions or concerns about the GDPO to CBRE’s Ethics & Compliance department via the CBRE Ethics Helpline.
Individuals in Europe, the Middle East or Africa:
If you are located in Europe, the Middle East or Africa, you may also e-mail us via the GDPO at [email protected] or write to us at Henrietta House, Henrietta Place, London, W1G 0NB, United Kingdom, Attention: EMEA Director, Data Privacy.
Individuals in Asia or the Pacific:
If you are located in Asia or the Pacific, you may also e-mail us via the GDPO at [email protected] or write to us at 15/F M1 Tower, 141 H.V. Dela Costa Street, Salcedo Village, Makati City, Philippines 1227, Attention: APAC Senior Manager, Data Privacy.
In some countries, CBRE has appointed a Data Protection Officer (“DPO”), whom you may contact with questions or concerns about how CBRE processes your personal information. Contact information for our DPOs in the European Union, the UK and Brazil is available in our Global Privacy and Cookie Notice.
We have appointed a representative for the responsible CBRE entities located outside of the EEA and UK that process your personal information subject to the EU General Data Protection Regulation and UK data protection law. The representatives contact details are available in our Global Privacy and Cookie Notice.
We are a rapidly evolving, global business. We will continue to assess and make changes to this Notice from time to time as required. If we make any material changes to this Notice, we will make changes here and, if the changes are significant, we will provide a more prominent notice (including, for certain services, email notification of Notice changes).