Last Revised: September 25, 2019
This Policy is intended to comply with the requirements set forth under REGULATION (EU) 2016/679 of The European Parliament and The Council of the European Union.
The collection, use and disclosure of information we collect from you through our service, Elanders Americas Customer Portal and Online Ordering Site, shall be limited to the purpose of providing the service for which you have engaged Elanders Americas.
This Policy also applies to our website, elandersamericas.com, which is a promotional and recruitment site. By using the website, you consent to the data practices described in this statement.
DATA CONTROLLER & PROCESSORS
Elanders Americas is the data controller for the processing of your personal information. In some cases, we may be a joint data controller with our Clients. The information that you voluntarily provide on a site will be used to process your order. Order and shipping data may be shared with service providers, that Elanders Americas has established relationships with, to provide services on our behalf. This includes other Elanders AB companies or partner companies. Each of these service providers is committed to protecting your personal data to the same degree as Elanders Americas. Payment information is only provided to those service providers as required to process the transaction. This may include a gateway transaction service for payment processing, credit card companies or banking institutions. Specific agreements with these service providers addressing protection of your personal information are in place.
COLLECTION AND USE
Personal data or information means any information about an individual from which that person can be identified. Our legal basis for the collection of personal data is to fulfill our commitment of a contract with you, or your employer on your behalf, for services requested. Failure on your part to provide the requested data may impede the performance of the contract.
Elanders Americas will use personal information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by you. We will take reasonable steps to ensure that personal information is relevant to its intended use, accurate, complete and current.
COLLECTION: We collect the following kinds of personal information from you:
- Contact Information such as name, email address, mailing address, phone number
- Shipping Information such as name, address, phone number, contact name
- Billing Information such as credit card number and billing address
We may also collect the following information from some of our Clients:
- Information about your business such as company name, company size, business type
- Product information
DATA SUPPLEMENTATION: We obtain address information about you from third party sources, such as the US Postal Service, to verify your address is valid and complies with addressing standards.
USE: We use this information to:
- Fulfill your order
- Send you an order confirmation
- Respond to customer service requests
- Administer your account
Information supplied by you on our elandersamericas.com website may also be used for recruitment purposes or to send you information that we think may be of interest to you. If you do not wish to receive marketing materials, brochures or emails from Elanders Americas, you may inform us of your preference by sending a letter or emailing Elanders Americas at the contact information above.
EMAIL COMMUNICATIONS: If you provide your personal data on our website, elandersamericas.com,
Elanders Americas may, from time to time, contact you via email for the purpose of providing announcements, promotional offers, alerts, confirmations, surveys, and/or other general communication. If you would like to stop receiving marketing or promotional communications via email from Elanders Americas, you may opt out of such communications by clicking the Unsubscribe button.
SHARING: We will share your personal information with third parties only in the ways that are described in this Policy. Elanders Americas does not sell, rent or lease customer information to third parties.
SERVICE PROVIDERS: We may provide your personal information to companies that provide services to help us with our business activities such as processing your credit card information. These companies are authorized to use your personal information only as necessary to provide these services to us and are required to maintain the confidentiality of your information. We obtain assurances from our service providers that they will safeguard personal information consistent with the Policy and the applicable laws such as the requirements set forth under REGULATION (EU) 2016/679 of The European Parliament and The Council of the European Union.
LOCAL STORAGE: Third parties with whom we partner use Local Storage, such as HTML5, to provide certain features on our website based upon your web browsing activity. HTML5 is also used to collect and store information. Various browsers may offer their own management tools for removing HTML5.
LOG FILES: As is true of most websites, we gather certain information automatically and store it in log files. This information may include Internet protocol (IP) addresses, browser type, Internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We do not link this automatically collected data to other information we collect about you.
LINKS: Our website, elandersamericas.com, contains links to other sites. Please be aware that we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.
DATA SECURITY AND DISCLOSURE
Appropriate security measures are in place to prevent personal data from accidental loss, misuse, alteration or unauthorized access and disclosure. Depending on the data provided, we use the following methods for this purpose: SSL protocol, encryption, restricted access, and authentication processes.
Additionally, access to personal data is limited to those Elanders Americas employees or service provider employees who are authorized to process the data, under specific instructions, and subject to a duty of confidentiality. Elanders Americas will conduct compliance audits of its relevant privacy practices to verify adherence to this Policy.
We will only disclose personal data as required above or as required by law or regulation, such as to comply with a subpoena, bankruptcy proceedings, or similar legal process when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
We collect, store and process the information from our sites in the United States of America. If you are outside the U.S., then your personal and non-personal data will be transferred to the U.S. and potentially to other countries where our service providers are located in order to allow the processing of the product or service you have requested.
CHILDREN UNDER THIRTEEN
Elanders Americas does not knowingly collect personally identifiable information from children under the age of thirteen. If you are under the age of thirteen, you must ask your parent or guardian for permission to use this site.
Your personal data will be retained as long as necessary to fulfill the purpose(s) for which it was collected, including legal, accounting or reporting requirements as governed by law. To determine the appropriate retention period for personal data, we consider the nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, and the purposes for which we process your personal data. For example, name, address and order information may be kept for a longer period of time to address future questions, resolve disputes or for legal requirements, whereas credit card information is processed and deleted immediately upon the completion of the transaction. For specific information regarding the retention of your data, please contact our DPO using the contact methods provided above.
Subject to applicable law, you have rights in relation to your personal information. You may exercise your rights by contacting us as indicated under the CONTACT INFORMATION section above. Specifically, the following rights are available to individuals located in the European Union under the requirements of REGULATION (EU) 2016/679 of The European Parliament and The Council of the European Union:
- Right of access, correction and erasure:If you wish to request access, please contact us at the mailing address or email address provided above. We will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data. Please note that we can only release information that we are certain belongs to you. Elanders Americas will respond to your request within a reasonable timeframe and take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete. Please note that any requests for erasure will be weighed against any requirements to retain the data for legal or accounting purposes and, under those circumstances, we may not delete your data. If your requests are repetitive or excessive, we may charge a reasonable fee.
Access to Data Controlled by our Clients: In some instances, Elanders Americas has no direct relationship with the individuals whose personal data we process. An individual who seeks access, correction and/or erasure should direct his query to Elanders Americas’ Client (the data controller). If the Client requests Elanders Americas to remove the data, we will respond to their request within a reasonable timeframe.
- Right to restrict processing: You may ask us to restrict or ‘block’ the processing of your personal information in certain circumstances, such as where you contest the accuracy of the personal information or object to us processing it. We will tell you before we lift any restriction on processing that you have requested.
- Right to data portability: You have the right to obtain your personal information from us that you consented to give us or that is necessary to perform a contract with you. We will provide your personal information in a common format so that you may reuse it elsewhere.
- Right to object to processing:You may ask us at any time to stop processing your personal information, and we will do so. Please be aware that if the information is necessary and used to perform services under a contract which is in progress, we will complete the contracted services first.
- Rights in relation to automated decision-making and profiling: You have the right to be free from decisions based solely on automated processing of your personal information, including profiling, that affect you, unless such processing is necessary for entering into, or the performance of, a contract between you and us or you provide your explicit consent to such processing.
- Right to withdraw consent: If we rely on your consent to process your personal information, you have the right to withdraw that consent at any time. This will not affect the the lawfulness of processing based on your prior consent.
- Right to lodge a complaint with the data protection authority:If you have a concern about our privacy practices, including the way we have handled your personal information, you can report it to the data protection authority that is authorized to hear those concerns.
- EU General Data Protection Regulation Complaint handling form – click here to obtain copy of the form.
You may assert your rights and raise your concerns or complaints about the handling of your personal data by filling in the form provided and sending it by email to firstname.lastname@example.org and email@example.com or by postal mail to the following addresses.
Att: Responsible GDPR
Flöjelbergsgatan 1 C
SE-431 35 Mölndal, Sweden
Midland Information Resources
5440 Corporate Park Drive
Davenport, IA 52807
You have the right to file a complaint at any time with the Information Commissioner’s Office (ICO) or any other relevant supervisory authority for data protection issues (see YOUR RIGHTS section below) However, we would appreciate the opportunity to resolve your concerns before you reach out to any authorities, so please consider contacting us first.
For purposes of this Policy, the following definitions shall apply:
“Client” means a company that Elanders Americas has a direct business relationship with. If you are a customer of one of our clients and would no longer like to be contacted by a Client that uses our services, please contact that Client directly.
“Contract” and “Performance of Contract” means processing your data where it is necessary for the performance of a contract to which you are a party, such as processing your order for products or services.
“Elanders Americas” means Midland Information Resources, DBA Elanders Americas, its divisions and groups in the United States.
“Personal data” or “personal information” means any information or set of information that identifies or could be used by or on behalf of Elanders Americas to identify an individual. Personal information does not include information that is encoded or anonymized, or publicly available information that has not been combined with non-public personal information.
“Sensitive personal information” means personal information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, views or activities, that concerns health or sex life, information about social security benefits, or information on criminal or administrative proceedings and sanctions other than in the context of pending proceedings. In addition, Elanders Americas will treat as sensitive personal information any information received from a third party where that third party treats and identifies the information as sensitive.
“Service Provider” means any third party that collects or uses personal information under the instructions of, and solely for, Elanders Americas or to which Elanders Americas discloses personal information for use on our behalf.