EFFECTIVE DATE: November 1, 2019
Please note that our Site and Services are intended for use by our business customers only, and is not for consumer or household use.
California residents may have additional rights with respect to their personal information as set forth in Appendix A – California Privacy Rights and European Residents may have additional rights with respect to the personal information as set forth in Appendix B – Additional Provisions Applicable to Processing of Personal Information of European Union Data Subjects.
The Information We Collect About You
We collect information about you directly from you and from third parties, as well as automatically through your use of our Site or Services.
Information We Collect Directly From You. You may browse certain areas of the Site without registering with us or providing us personal information. If you complete our Contact Us form, we will collect your first and last name, Company name, phone number, country, email address, and any information you might provide in your message to us. In addition, you can sign up to access our online catalog by registering at the Site and providing the following information: user name, password, first and last name, email address, city, state, zip code, country, and your company (“Catalog Account”).
The purpose for collecting this information is to be able to communicate with you regarding our products and services, and to enable you to access our online catalog on behalf of your company.
In addition, if you are providing personal information for third parties in connection with using our Services or registering a Catalog Account, you are responsible for ensuring that you have all required permissions and consents to provide such personal information to us for use in connection with the Services, and that our use of such personal information to provide the Services does not violate any applicable law, rule, regulation, or order.
How We Use Your Information
We use your information, including personal information, for the following purposes:
Provide our services
We use your information to provide you with our Site and Services (e.g. access to our online catalog), communicate with you about your use of our Site and Services, respond to your inquiries, and fulfill your orders, and for other customer service purposes.
Provide personalized services
We use your information to tailor the content and information that we may send or display to you, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the Site and Services.
Improve and develop our services
We use your information to ensure our Site and Services are working as intended, to better understand how users access and use our Site and Services, both on an aggregated and individualized basis, to make improvements to our services, to develop new Services, and for other research and analytical purposes.
We use your information for marketing and promotional purposes. For example, we may use your information, such as your email address, to send you news and newsletters, special offers, and promotions, to conduct contests and sweepstakes, or to otherwise contact you about products or information we think may interest you or your company. We also may use the information that we learn about you to assist us in advertising our Services on third party websites.
How We Share Your Information
We may share your information, including personal information, as follows:
- Consent. We may ask for your permission to share your personal information to persons or entities not described below. In such case, we will only share your personal information in accordance with the terms of the permission you have given to us.
- Affiliates. We may disclose the information we collect from you to our affiliates or subsidiaries solely for the purpose of providing Services to you; however, if we do so, their use and disclosure of your personal information will be maintained by such affiliates and subsidiaries in accordance with this Policy.
- Service Providers. We may disclose the information we collect from you to third party vendors, service providers, contractors or agents who perform functions on our behalf.
- Business Transfers. If we are acquired by or merged with another company or legal entity, if substantially all of our assets are transferred to another company, or as part of a bankruptcy proceeding, or are in negotiations for any of these types of transactions, we may transfer the information we have collected from you to the other company.
- In Response to Legal Process. We also may disclose the information we collect from you in order to comply with the law, a judicial proceeding, court order, or other legal process, such as in response to a subpoena.
- To Protect Us and Others. We also may disclose the information we collect from you where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Service or this Policy, or as evidence in litigation in which we are involved.
- Aggregate and De-Identified Information. We may share aggregate or de-identified information about users and their use of the Services with third parties and publicly for marketing, advertising, research, or similar purposes.
Please note that except as noted above, we will not sell or share your personal information with any third party for their direct marketing purposes without your consent.
Currently, our systems do not recognize browser “do-not-track” requests. You may, however, disable certain tracking as discussed in this section (e.g., by disabling cookies), but such disabling will impair use of the Site and Services.
Cookies. Cookies are alphanumeric identifiers that we transfer to your computer’s hard drive through your web browser for record-keeping purposes. Some cookies allow us to make it easier for you to navigate our Site and Services, while others are used to enable a faster log-in process, or to allow us to track your activities at our Site and Services. There are two types of cookies: session and persistent cookies.
- Session Cookies. Session cookies exist only during an online session. They disappear from your computer when you close your browser or turn off your computer. We use session cookies to allow our systems to uniquely identify you during a session, or while you are logged into the Site. This allows us to process your online transactions and requests and verify your identity after you have logged in and as you move through our Site.
- Persistent Cookies. Persistent cookies remain on your computer after you have closed your browser or turned off your computer. We may use persistent cookies to track aggregate and statistical information about user activity.
Disabling Cookies. Most web browsers automatically accept cookies, but if you prefer, you can edit your browser options to block them in the future. The Help portion of the toolbar on most browsers will tell you how to prevent your computer from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. Visitors to our Site who disable cookies will not be able to browse certain areas of the Site or use the Services.
Our Site and Services may contain links to third-party websites. Any access to and use of such linked websites is not governed by this Policy, but instead is governed by the privacy policies of those third party websites. We are not responsible for the information practices of such third party websites.
Security of My Personal Information
We have implemented commercially reasonable precautions to protect the information we collect from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Please be aware that despite our efforts, no data security measures can guarantee 100% security.
You should take steps to protect against unauthorized access to your password, phone, and computer by, among other things, signing off after using a shared computer, choosing a robust password that nobody else knows or can easily guess, and keeping your log-in and password private. We are not responsible for any lost, stolen, or compromised passwords, or for any activity on your account via unauthorized password activity.
What Rights Do I Have Regarding My Personal Information?
You may request access, a copy, modification, or deletion of personal information that you have submitted to us by contacting us at email@example.com. We will use reasonable efforts to accommodate such requests to the extent required by law, provided that we may be required to retain personal information to comply with legal obligations, accounting requirements, or for other business purposes. We may request additional information to verify the identity of the requesting party before responding to a request. Please note that copies of information that you have updated, modified, or deleted may remain viewable in cached and archived pages of the Site for a period of time.
What Choices Do I Have Regarding Use of My Personal Information for Marketing?
You can choose to sign up for the HCT mailing list to receive the latest news and releases about HCT products. You may opt-out of such communications by following the opt-out instructions contained in the e-mail. Please note that it may take up to 10 business days for us to process opt-out requests. If you opt-out of receiving emails about recommendations or other information we think may interest you, we may still send you e-mails about your account or any Services you have requested or received from us.
Location of Information
Our Site and Services are offered from the United States. We store any information we collect in the United States. If you access the Services or Site from outside the United States, you agree to the transfer of your information to the United States, which may have less protections for your personal information than your jurisdiction of residence.
Children Under 13
Our Site and Services are not designed for children under 13. If we discover that a child under 13 has provided us with personal information, we will delete such information from our systems.
If you have questions about the privacy aspects of our Site or Services or would like to make a complaint, please contact us at firstname.lastname@example.org.
Changes to this Policy
This Policy is current as of the Effective Date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any changes to this Policy on the Site. If we make any changes to this Policy that materially affect our practices with regard to the personal information we have previously collected from you, we will endeavor to provide you with notice in advance of such change by highlighting the change on our Site or if you have an account with us, providing notice to the email address in your account (for this reason you should make sure to update your account information promptly if it changes).
CALIFORNIA PRIVACY RIGHTS
HCT complies with the California Consumer Privacy Act (CCPA) to the extent it applies to personal information collected from California consumers; however, as noted above, the Site and Services are intended for use by our current and prospective business customers. Under California Civil Code Section 1798.145(n)(1), personal information collected from you in your capacity as an employee, employee, owner, director, officer, or contractor of your business or company is not subject to the requirements of the CCPA. However, you will still be entitled to make certain requests as to that information as set forth in the section entitled “What Rights Do I Have Regarding My Personal Information?” in the Policy above.
If you believe that you are also entitled to exercise rights under the CCPA, you can contact us at email@example.com or 310-260-7680 to request that:
- Right to Know: We disclose what personal information we collect, use, and disclose. Note: we do not sell your personal information as the term “sell” is defined in the CCPA.
- Right to Delete: We delete the personal information we collected or maintain about you.
We will review and respond to that request within the time period required by the CCPA, including advising you whether the personal information collected is exempt from these requirements.
If you are a California consumer and not exempt from the CCPA, you have a right not to receive discriminatory treatment by the business for the exercise of the privacy rights conferred by the CCPA.
If you are entitled to and exercise your rights under the CCPA, we may request additional information from you to verify the consumer request, which may include your name, email address, phone number, zip code or other identifying information that you may have provided to us.
You may also be entitled to make a request under the CCPA though an authorized agent. In such a case, we may require that the consumer: (1) provide us documentation that the authorized agent has written permission from you to make the request; and (2) verify consumer’s own identity directly with the business.
ADDITIONAL PROVISIONS APPLICABLE TO PROCESSING OF PERSONAL INFORMATION OF EUROPEAN UNION DATA SUBJECTS
This Appendix outlines certain additional information that we are obligated to provide to Data Subjects of the European Union, as well as certain rights such residents have with respect to the processing of your personal information, pursuant to applicable local laws. Capitalized terms not otherwise defined in this Appendix B, shall have the meaning ascribed to them by the European Union General Data Protection Regulation 2016/679 and its amendments (“GDPR”).
The controller of personal information collected through the Site is HCT Packaging, Inc. 2800 28th Street Suite 240 Santa Monica, CA 90405.
LEGAL BASIS FOR PROCESSING OF PERSONAL INFORMATION
We process the personal information collected for the purposes described in the section entitled “How We Use Your Information in our Policy.” The legal basis for our processing activities include processing personal information as necessary to comply with our contractual obligations, compliance with our legal obligations, protecting the safety of our employees, guests and others, for our legitimate business interests, and pursuant to your consent. The particular legal basis for the processing of your personal information is based on the purpose for which such information was provided or collected.
For example, we use personal information as necessary for the performance of contracts with you, or in order for us to take steps, at your request, prior to entering into a contract, such as the purchase of our Services. For example, we are not able to provide our services and products according to contracts unless you provide us with necessary personal information. This collection and processing of the Personal Data is based on Art. 6 para. 1(b) GDPR (necessary for the performance of a contract with you).
We may also process your personal information if we have received your consent, to respond to requests from you or to take actions in our legitimate interest (except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal information) such as marketing purposes, or to otherwise inform you of our business operations and to improve our products and services. Please note that if we rely on consent, you may withdraw your consent at any time, but such withdrawal will not affect the lawfulness of the processing prior to the withdrawal. The collection and processing of personal information based on your consent is in accordance with Art. 6 para. 1(a) GDPR; the collection and processing of personal information based on legitimate interest is in accordance with Art. 6 para 1(f) GDPR.
We retain personal information about you for the time necessary to accomplish the purpose for which such information was collected, usually for the duration of any contractual relationship and for any period thereafter as legally required or permitted by applicable law. Our retention policies reflect applicable statute of limitation periods and legal requirements.
DATA SUBJECT RIGHTS
Data Subject of the European Union have the following rights:
- Access, Correction, and Erasure Requests: You have the right to:
- contact us to confirm whether we are processing your personal information.
- receive information on how your personal information is processed.
- obtain a copy of your personal information.
- request that we update or correct your personal information.
- request that we delete personal information in certain circumstances.
- Right to Object to Processing: You have the right to request that we cease processing of your personal information: for marketing activities, including profiling for statistical purposes where such processing is based on our legitimate business interests, unless we are able to demonstrate a compelling legitimate basis for such processing or we need to process your personal information for the establishment, exercise or defense of a legal claim.
- Right to Restrict Processing: You have the right to request that we limit the processing of your personal information:
- while we are evaluating or in the process of responding to a request by you to update or correct your personal information where such processing is unlawful and you do not want us to delete your data.
- where we no longer require such data, but you want us to retain the data for the establishment, exercise or defense of a legal claim.
- where you have submitted an objection to processing based on our legitimate business interests, pending our response to such request.
- Data Portability Requests: You have the right to request that we provide you, or a third party that you designate, with certain personal information in a commonly used, machine readable format. Please note, however, that data portability rights apply only to personal information that we have obtained directly from you and only where our processing is based on consent or the performance of a contract.
If you believe our processing of your personal information violates data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work, or the place of the alleged violation.
Submitting Requests: You can submit requests by contacting us at firstname.lastname@example.org. We will respond to all such requests within 30 days of our receipt of the request, unless there are extenuating circumstances, in which event we may take up to 60 days to respond. We will inform you if we expect our response to take longer than 30 days. Please note, however, that certain personal information may be exempt from such rights pursuant to applicable data protection laws. In addition, we will not respond to any request unless we are able to appropriately verify the requester’s identity. We may charge you a reasonable fee for subsequent copies of personal information that you request. In addition, if we consider that a request is manifestly unfounded or excessive, we may either request a reasonable fee to deal with the request or refuse to deal with the request.