Privacy policy
Privacy Policy
This privacy policy (“Privacy Statement”) sets out the basis on which any Personal Data (as defined below) Polysciences, Inc. (“Polysciences”, “us”, “we”, “our”) collects from you (“you”, “your”) or that you provide to us, and how such Personal Data will be processed by us.
By “Personal Data”, we mean any information which, either alone or in combination with other data, identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to any individual or a household, for example, your name, email address, username, contact details or any unique identifier such as an IP address, device ID or other online identifier.
Capitalized terms that are not defined in this Privacy Statement shall have the meaning ascribed in our General Terms and Conditions (the “Terms”).
Please read the following carefully to understand what Personal Data we collect, how that Personal Data is used and the ways it can be shared by us.
We may amend this Privacy Statement from time to time to keep it up to date with legal requirements and the way we operate our business. Please regularly check these pages for the latest version.
1. About us (as the data controller)
Polysciences, Inc. is for the purposes of this Privacy Statement the data controller. We are based in the United States and so we may process, store, and transfer the Personal Data we collect in and to a country outside your own, including the United States.
If you have any questions about this privacy policy, including any requests to exercise your legal rights (Paragraph 9 and 10), please contact us using the information set out in the contact details section (Paragraph 13).
2. Personal Data We Collect
Information that we collect may depend on how you interact with Polysciences. A description of the types of information we may collect is described in detail below.
· Identifiers such as first name, last name, username or similar unique personal identifier, online identifier, email address, telephone number and postal address.
· Profile Data such as username, password, country, language preference, preferred distributor, customer status, event attendance history.
· Internet and Other Electronic Network Activity such as internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices used to access our website or other online platforms.
· Financial Information such as credit or debit card information, payment details, or other payment information.
· Commercial Data such as products you have purchased, payments you have made, and/or other details of products and services you have purchased from us in the past, purchase or product preferences, personal interests, feedback, reviews, and survey responses.
· Usage Data includes information about how users use interact with us and our website, such as statistics regarding the opening and clicking on emails sent by company, and activity on the website (including, for example, user’s activity, time spent, user stats, referring/exit pages, and clickstream data).
· Marketing and Communications Information such as marketing campaign data, click-throughs, user preferences and consent in receiving marketing e-mails, phone, text, email and webchat communications, and email and text communications.
· Inference Data including inferences drawn from the Personal Data identified above.
3. Retention of your Personal Data
We have data retention and deletion policies designed to retain Personal Data for no longer than is necessary for the purposes set out herein or as otherwise required to meet legal or business needs. Because of those requirements, we might not be able to honor erasure requests.
To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
|
TYPE OF DATA |
RETENTION PERIOD |
|
Customer purchase data (SAP/Batchmaster) |
Retain for 7 years |
|
Customer account (Shopify) |
Review after 24 months of inactivity |
|
Customer account (Salesforce) |
Review after 24 months of inactivity |
|
Email platform (Klaviyo) |
Review after 24 months of inactivity |
|
Web form submissions/leads |
Review after 12 months of inactivity |
|
Cookies and analytics |
Delete after 13 months of collection |
4. Legal Basis for Collection
Certain laws outside the U.S. require us to identify a legal basis for collecting and using your Personal Data. Where these applicable laws apply, we rely on one or more of the following legal bases:
· Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
· Legitimate interests: When we consider we have a legitimate interest (for ourselves or of a third party) to process your Personal Data it refers to being in the interest of our organization to conduct and manage our business; this includes conducting analytics to improve and optimize the site and the services, protecting our interests and enforcing agreements with others, as well as complying with industry self-regulatory requirements. We might have legitimate interest to process Personal Data in other contexts. We ensure that we balance any potential impact on you and your rights before we process your Personal Data on that basis. You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us. Please also consult the section “Your rights” below.
· Legal obligation: We may use your Personal Data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
· Consent: We do not rely on consent as a legal basis for processing your Personal Data other than in relation to our use of cookies (please see our Cookies Notice for more details which can be found here; when we send third party direct marketing communications to you via email; and, when providing you with personalized content, ads, and promotions tailored to your interests and preferences. From time to time, we may share your Personal Data with third parties with your consent.
If you do not wish for your Personal Data to be used in the ways described within this Privacy Statement, then you should not use our services. Where we need information from you to offer our services or meet any of our legal or regulatory requirements, failure to provide such information will mean that you will not get access to the services.
It is important that the Personal Data we collect from you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us. You can do so by contacting us. We will endeavor to effect those changes within a reasonable timeframe.
5. How We Collect Your Personal Data
Information You Provide To Us:
Polysciences may collect Personal Data from you that you voluntarily provide to us in various ways, including, but not limited to:
· Create an account with us
· Place an order or purchase products from us or otherwise use our website
· Call, email, text, or otherwise communicate with us
· Register and attend an event or webinar
· Sign up to receive newsletters
· Respond to surveys or marketing emails
· Write a review
· Otherwise interact us or with our website
Information We Collect When You Use Our Services
Automated technologies or interactions. As you navigate around our website or other online platforms (whether or not you have created or have logged into a user account), we may collect certain information using various technologies to help us personalize your experience. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, time zone setting and location, language preferences, device type and ID, and other technical information from the devices you use to access our website or other online platforms.
Cookies and Tracking Technologies. We and our service providers use cookies, pixels, and other tracking technology to recognize your browser or device and to capture and remember certain information about your activities on our website. For example, cookies gather information about how long you spend on a web page so that we can understand what web pages are of interest to users. If you prefer, you can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off cookies by adjusting your browser settings. If you turn off your cookies, some of the features of the website may not function properly. Pixel tags generally work in conjunction with cookies, registering when a particular device visits a particular page. You cannot decline pixel tags; however, if you turn off cookies the pixel tag will simply detect an anonymous visit. We also use pixel tags in our HTML-based emails to let us know which emails have been opened by the recipients and whether any links have been clicked. This allows us to gauge the effectiveness of certain communications and the effectiveness of our marketing campaigns. If you prefer not to be tracked through our emails, most email services will allow you to turn off pixels by disabling external images in settings.
Information We Collect From Third Parties
We collect Personal Data from various third parties, including those listed below. The collection, use, and disclosure of Personal Data received from third parties is governed by the privacy policies listed on the website where the information was submitted by the user. Third parties may send their own cookies and pixel tags to you and may collect information and use it in a way inconsistent with this Policy. Please carefully review these third-party privacy policies to understand how your information may be collected, used and disclosed by these third parties. For full information on the cookies used on our website, please refer to our Cookie Policy which can be found here.
Third Party Service Providers. We collect Personal Data from service providers including payment processors, email service providers, and website hosting platforms.
Third Party Advertising Partners. We collect Personal Data received from third party advertising partners, including partners who host and manage various online advertisements and ad platforms. This may be combined with the website analytics data described below.
Event Organisers. We collect Personal Data from third party event organisers who share attendee details with exhibitors at their events. Whenever we contact you as a result of receiving your Personal Data this way, we will also provide you with information as to who we received this information from and your options to opt-out of receiving further information.
Analytics. We use third party cookies provided by Google Analytics to assist us in better understanding our website visitors. These cookies collect IP address and usage data, such as the length of time a user spends on a page, the pages a user visits, and the websites a user visits before and after visiting our website. Based on this information, Google Analytics compiles data about website traffic and interactions, which we use to offer better user experiences and tools in the future. For more information on Google Analytics, visit Google’s Privacy and Terms. You can access the Google Analytics Opt Out Browser Add-on, currently located here.
6. Our Use and Processing of Your Personal Data
In the table below we have provided a description of the different purposes for which we use and process Personal Data.
We process your Personal Data for the following purposes.
|
Purpose |
Personal Data |
Basis on which we process (where applicable)
|
|
|
From You |
From Others and Your Devices |
||
|
Establish and maintain a relationship with you |
All Personal Data we have associated with you or about you. |
All Personal Data we have associated with you or about you. |
Performance of a contract |
|
Deliver our goods and services to you |
All Personal Data we have associated with you or about you. |
All Personal Data we have associated with you or about you. |
Performance of a contract |
|
Administer the website, system administration and detecting usage patterns (including fraud activities), provide information about developments and new products, including development and enhancement to the website |
Identifiers, Profile Data, Commercial Data, Marketing and Communications Information, Audio and Visual Information, Inference Data |
N/A |
When it is in our legitimate interest |
|
Detection for troubleshooting purposes |
N/A |
Internet and Other Electronic Network Activity, Usage Data |
When it is in our legitimate interest |
|
Provide you with news and other matters of general interest to you as a user of our services |
Identifiers, Profile Data |
Internet and Other Electronic Network Activity, Usage Data |
When it is in our legitimate interest |
|
Increase your visibility on the platform to allow a better experience as a user and create a community |
Identifiers, Profile Data |
N/A |
When it is in our legitimate interest |
|
Enhance your browsing experience by delivering personalized content, ads, and promotions tailored to your interests and preferences. |
Identifiers, Profile Data, Financial Information, Commercial Data, Marketing and Communications Information, Audio and Visual Information, Inference Data |
Internet and Other Electronic Network Activity, Usage Data |
Consent or when it is in our legitimate interest |
|
Send you targeted marketing communications |
Identifiers, Profile Data, Financial Information, Commercial Data, Marketing and Communications Information, Inference Data |
Internet and Other Electronic Network Activity, Usage Data |
Consent or when it is in our legitimate interest |
|
Send you transactional and service related emails such as reminders relating to abandoned shopping cart reminders, browse abandonment reminders, and/or checkout abandonment reminders. |
Identifiers, Profile Data, Commercial Data, Marketing and Communications Information, Inference Data |
Internet and Other Electronic Network Activity, Usage Data |
When it is in our legitimate interest |
|
Request feedback from you |
Identifiers, Profile Data, Commercial Data, Marketing and Communications Information |
N/A |
When it is in our legitimate interest |
|
Respond to queries or complaints |
Identifiers, Profile Data, Commercial Data, Marketing and Communications Information |
N/A |
Compliance with a legal obligation (e.g., under consumer rights law) |
|
Facilitate payment |
Identifiers, Profile Data, Financial Information, Commercial Data |
Internet and Other Electronic Network Activity, Usage Data |
Performance of a contract |
|
Facilitate shipping |
Identifiers, Profile Data, Commercial Data |
N/A |
Performance of a contract |
|
Meet our legal and regulatory requirements, including checking your identity and verifying you are in legal capacity to contract |
All Personal Data we have associated with you or about you. |
All Personal Data we have associated with you or about you. |
Compliance with a legal obligation |
|
To provide safety, integrity and security across out site, in particular to: (a) investigate suspicious activity including fraudulent, abusive or unlawful acts; and (b) detect, prevent and combat harmful or unlawful behavior such as to review and, and in some cases, remove content reported to us. |
All Personal Data we have associated with you or about you. |
All Personal Data we have associated with you or about you. |
When it is in our legitimate interest |
7. Sharing Personal Data with Third Parties
As necessary, we share your Personal Data with:
a) Internal third parties including, our parent company, subsidiaries, successors, assigns, affiliates or any of their representatives.
b) Service providers, to the extent necessary to supply our services to you, such as payment service providers to whom we fully outsource the handling and other processing of your payment card information, hosting services, communications services, website development services, fulfillment and shipping services and advertising/marketing services.
c) Selected third parties, including analytics and search engine providers that assist us in the improvement and optimization of our services.
We also disclose your Personal Data to third parties:
a) In the event that we sell or buy any business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets.
b) If substantially all of the assets in Polysciences, or any member of the Group, are acquired by a third party, in which case your Personal Data will be one of the transferred assets.
c) If we are under a duty to disclose or share your Personal Data to comply with any legal obligation, court or police request, or to enforce or apply our Terms of use and other agreements, or to protect the rights, property, or safety of Polysciences, our users, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Categories of Personal Data that have been shared with service providers, selected third parties, and internal third parties for a business purpose in the past twelve months include Identifiers, Profile Data, Internet and Other Electronic Network Activity, Financial Information, Commercial Data, Usage Data, Marketing and Communications Information, Audio and Visual Information, Inference Data.
You can find more information on the actual parties we are sharing your data in Appendix 1 below. The list is updated regularly.
Personal Data Sold or Shared for Targeted Advertising.
Polysciences does not sell any Personal Data and has no actual knowledge of any sales or sharing of Personal Data of minors under 16 years of age. We have shared Personal Data with our third party advertising partners to serve ads to you about our goods and services as you browse the Internet (aka targeted advertising). This means that these third-party service providers may use their own cookies or tags to track your online activities and purchases in order to deliver targeted advertising based on your interests. You can opt of this sharing by clicking on the this link. Additionally, if your browser supports it, you can turn on the Global Privacy Control (GPC) to opt-out of the sharing of your Personal Data for targeted advertising. Learn more at the Global Privacy Control website.
8. International Transfers
If you are a European Economic Area (EEA) or UK resident please note that when you provide information to us (or a third party on our behalf) it may accordingly be accessed and used in countries outside of the EEA or the UK respectively. In relation to such transfers, you acknowledge that you have been made aware that: (i) some countries outside the EEA and the UK provide levels of protection of personal data which are substantially poorer than those of countries within the EEA and the UK and (ii) in respect of such countries it is possible that this personal data might be intercepted and accessed by governmental and other authorities/agencies in those countries.
By submitting your personal data to us, you consent to this transfer, storing or processing.
Where your personal data is processed outside the EEA and UK without your express consent (for example to provide services to you or where we are mandated to do so at law), we are required to ensure a level of data protection at least as protective as those mandated by the EEA or the UK (as applicable). If you would like to know more about the safeguards used by us to protect the transfer of your personal data, please contact us at marketing@polysciences.com.
9. Security
We take reasonable endeavors to protect and safeguard Personal Data. Unfortunately, the transmission of information via the Internet or over email is not completely secure.
10. Your EU / UK Privacy Rights
Depending on where you reside, you may have some rights in relation to how we process your Personal Data under data protection laws. You may exercise these rights by contacting us (see details below). Please note that these rights do not apply to the United States because we are not covered business under applicable U.S. state privacy laws that offer such rights.
Request access to your Personal Data (commonly known as a "subject access request"). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your Personal Data in certain circumstances. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:
· If you want us to establish the data's accuracy;
· Where our use of the data is unlawful but you do not want us to erase it;
· Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
· You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
When we rely on your consent to process Personal Data (cookies, marketing communication, as well as personalized content, ads, and promotions), you have the right to withdraw your consent at any time. For cookies, this is done by setting up the cookie’s preferences (please check our Cookies Notice for more details which can be found here) or by updating your preferences. We will do your best to honor your request promptly.
No fee usually required
You will not have to pay a fee to access your Personal Data or to exercise any of your other rights. We may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
11. Your California Privacy Rights
California Consumer Privacy Act. The California Consumer Privacy Act as amended (“CCPA”) provides consumers who are California residents with specific rights regarding their Personal Data. This section describes your CCPA rights and explains how to exercise those rights.
Right to Know. Once we receive and confirm your verifiable consumer request as described below, you have the right to request, no more than twice in any 12-month period, that we disclose what Personal Data we have collected about you in the immediately preceding 12-month period, including, the categories of Personal Data we collected about you; the categories of the sources from which the Personal Data is collected; our business or commercial purpose(s) for collecting, selling or sharing that Personal Data; the categories of third parties to whom we disclosed that Personal Data; and the specific pieces of Personal Data we collected about you.
In addition, if we sold or disclosed your Personal Data for a business or commercial purpose, we will provide you with two separate lists disclosing:
- Disclosures for a business purpose, identifying the Personal Data categories disclosed that each category of recipient obtained; and
- Sales and/or disclosures for a commercial purpose, identifying the Personal Data categories that each category of each category of recipient obtained.
Right to Delete. You have the right to request that we delete any or all of your Personal Data that we collected from you and retained, subject to certain exceptions.
Right to Correct. You have the right to correct inaccurate Personal Data that we maintain about you.
Right to Opt-Out of the Sale/ Sharing. You have the right to opt-out of the sale or sharing of your Personal Data. We do not sell your Personal Data.
Right to Limit the Use or Disclosure of Sensitive Personal Data. You have the right to request that we limit the use and disclosure of Sensitive Personal Data to specific business purposes approved by the CCPA. We do not process Sensitive Personal Data.
Right to Non-Discrimination. You have the right not to be discriminated against for exercising any of your CCPA rights. Unless permitted by the CCPA, if you exercise any of your California rights, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
Exercising Your Rights
Requests to know, correct, or delete can be submitted by calling our toll-free number (800) 523-2575 or by contacting us at marketing@polysciences.com. You can opt out of having your Personal Data shared to third parties for targeted marketing by clicking on this link. Additionally, if your browser supports it, you can turn on the Global Privacy Control (GPC) to opt-out of the sharing of your Personal Data for targeted online advertising. You can learn more about the GPC and how to enable it in your browser from the Global Privacy Control website.
Please note that these rights currently apply only to California consumers. Only you or a person that you authorize to act on your behalf, may make a verifiable consumer request related to your Personal Data.
Authorizing an Agent to Act on Your Behalf
Where applicable and except where you have provided an agent with a Power of Attorney pursuant to Sections 4000 – 4465 of the California Probate Code, when using an authorized agent you must provide that person with written permission clearly describing their authority to make a request on your behalf. That agent must also be able to verify their identity with us and provide us with their authority to act on your behalf. An individual to whom you have provided Power of Attorney pursuant to applicable state rules may also make a request on your behalf. We may deny a request from an authorized agent if the agent does not provide us with the signed written permission demonstrating that they have been authorized to act on your behalf.
Verifying your request
The verifiable consumer request initiated by your or your authorized agent must:
· Include your full legal name, email and phone number, which we will need to contact you in order to verify that you are the person about whom we collected Personal Data or an authorized representative
· Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
· If you are making the request as an authorized agent you must also provide; the full legal name of the party for which you are making the request and documentation for which your authorization is based.
We cannot respond to your request or provide you with your Personal Data if we cannot verify your identity or authority to make the request and confirm the Personal Data relates to you. Making a verifiable consumer request does not require you to create an account with us. One of our representatives will contact you in order to verify your identity. You may need to provide additional information in order to verify your request. We will only use Personal Data provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. The response we provide will also explain the reasons we cannot comply with a request, if applicable.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Other California Privacy Rights. California Civil Code Section 1798.83 permits California residents who have provided personally identifiable information to us or our third-party advertisers and marketing partners, if any, to request certain information regarding our disclosure of personally identifiable information to third parties for their own direct marketing purposes. Requests should be submitted via email to info@Polysciences.com and should include CALIFORNIA PRIVACY RIGHTS in the subject line. Please be aware that not all information sharing is covered by the requirements of Section 1798.83 and only information on covered sharing will be included in our response. This request may be made no more than once per calendar year.
Do Not Track Signal
Some web browsers may transmit “do not track” signals to websites with which the web browser communicates. This website does not respond to “do not track” signals. We may allow certain third-party advertising partners to place tracking technology, such as cookies on our website. This technology allows us and/or third-parties to collect personally identifiable information about your online activities over time and across different websites. Please see our Cookies Notice for more details which can be found here.
12. Changes to this Privacy Statement
We may from time to time, make changes to this Privacy Statement. We suggest you check back regularly to check to see if there have been any changes to this Privacy Statement.
13. Questions or Complaints
If you have any questions or concerns about this Privacy Statement or our privacy practices, or wish to exercise your rights, please contact us using the details provided below.
Polysciences can be contacted in writing at Polysciences, Inc. at 400 Valley Road Warrington, PA 18976 or contact us via email at marketing@Polysciences.com.
Depending on where you reside, you also have the right to make a complaint at any time to a data protection regulator in the country in which you reside. We would, however, appreciate the chance to deal with your concerns before you approach a data protection regulator so please contact us in the first instance.