DATA PROTECTION NOTICE

Similar documents
Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

UK SCHOOL TRIPS PRIVACY POLICY

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

Personal data: By Personal data we understand all information about identified or identifiable natural ( data subject ) according to GDPR

What you need to know. about GDPR. as a Financial Broker. Sponsored by

Broad Run Investment Management, LLC

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

GDPR factsheet Key provisions and steps for compliance

Data Privacy Policy for Employees and Employee Candidates in the European Union

INFORMATION WITH REGARD TO THE PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH REGULATION (EU) 2016/679 AND THE RELEVANT GREEK LEGISLATION

ACCENTURE BINDING CORPORATE RULES ( BCR )

GDPR Factsheet - Key Provisions and steps for Compliance

General Data Protection Regulation. What should community energy organisations be doing to prepare?

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

Depending on the circumstances, we may collect, store, and use the following categories of personal information about you:

EU GENERAL DATA PROTECTION REGULATION

Tourettes Action Data Protection Policy

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

PRIVACY NOTICE (applicable from May 25th 2018)

ECOLAB INC. PRIVACY POLICY STATEMENT PERSONAL DATA

GDPR DATA PROCESSING NOTICE FOR FS1 RECRUITMENT UK LTD FOR APPLICANTS AND WORKERS

General Personal Data Protection Policy

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

GDPR transparency notice for candidates (contractors and permanents)

Celgene General Privacy Policy

Supplemental guide to the GDPR for HR professionals

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

GDPR Privacy Notice for Staff

Opus2 or an Opus2 Affiliate within the Group (as applicable), shall be the Data Controller in respect of the Personal Data covered in this Notice.

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe,

The General Data Protection Regulation An Overview

Data Protection Policy

Foundation trust membership and GDPR

Syntel Human Resources Privacy Statement

Privacy Policy MONAT GLOBAL

How employers should comply with GDPR

This division includes the UK's largest single mortgage brokerage and also offers expert advice on life and general insurance.

General Data Protection Regulation (GDPR) Frequently Asked Questions

Data Protection Policy

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Getting ready for the new UK data protection law Eight practical steps for micro business owners and sole traders

Guidance on the General Data Protection Regulation: (1) Getting started

Impact. Data Privacy Statement. Outcomes-Based Learning. Introduction

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

General Data Protection Regulation

Data Protection Policy

DATA PROTECTION POLICY

The Sage quick start guide for businesses

Preparing for the General Data Protection Regulation (GDPR)

EU General Data Protection Regulation

Associate Privacy Notice

This privacy policy (the 'conditions') was last amended in May 2016.

DATA PROTECTION NOTICE FROM THE DENYS GROUP. This Data Protection Notice applies to all companies cited below, which are part of the Denys group:

General Optical Council. Data Protection Policy

Vendor Agreements and the New EU GDPR Steps to Take Now

Personal Data Policy

HKT Financial Services (IA) Limited Privacy Statement

The New EU General Data Protection Regulation 1

DATED: 25/05/2018 GDPR PRIVACY NOTICE FOR HOPES & DREAMS LTD FOR EMPLOYEES, CHILDREN ATTENDING A GROUP NURSERY AND THEIR PARENTS

Preparing Your Vendor Agreements for the General Data Protection Regulation

Recruitment Privacy Notice

Data Protection. Policy

EU General Data Protection Regulation (GDPR)

Employee Privacy Notice

Accelerate Your Response to the EU General Data Protection Regulation (GDPR) with Oracle Cloud Applications

DATA PROTECTION POLICY 2016

Data Protection Policy

ARTICLE 29 DATA PROTECTION WORKING PARTY

European Union General Data Protection Regulation 2016 (Effective 25 May 2018)

The General Data Protection Regulation (GDPR) and Data Protection Act (DPA) 2017

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

Data Protection Policy & Procedures

Privacy Policy PURPOSE SCOPE POLICY. Data Collection

The General Data Protection Regulation and associated legislation. Part 1: Guidance for Community Pharmacy. Version 1: 25th March 2018

ARTICLE 29 Data Protection Working Party

Recruitment Privacy Notice

CANDIDATE DATA PROTECTION STANDARDS

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

Job Applicant Privacy Notice

ARTICLE 29 Data Protection Working Party

St Mark s Church of England Academy Data Protection Policy

Privacy Policy for Employees

DATA PROTECTION POLICY

OUR CUSTOMER TERMS CLOUD SERVICES TELSTRA APPS MARKETPLACE

Processing of personal data in a trust network for electronic identification

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Talisman Canadian Privacy Policy

A GDPR Primer For U.S.-Based Cos. Handling EU Data: Part 1

VODACOM M-PESA CONSUMER TERMS & CONDITIONS OF USE

10366/15 VH/np DGD 2C LIMITE EN

THE E-VERIFY PROGRAM FOR EMPLOYMENT VERIFICATION MEMORANDUM OF UNDERSTANDING ARTICLE I PURPOSE AND AUTHORITY

Getting Ready for the GDPR

EDPS - European Data Protection Supervisor CEPD - Contrôleur européen de la protection des données

Humber Information Sharing Charter

Salesforce s Processor Binding Corporate Rules. for the. Processing of Personal Data

Data Protection Policy

Prepaid Cards. Coles Gift Mastercard Conditions of Use. Issued by: Indue Ltd Issue Date: July 2017 ABN

KRONOS WORLDWIDE, INC. SAFE HARBOR PRIVACY POLICY Effective December 1, 2009 Amended and Restated as of July 20, 2012

closer look at Definitions The General Data Protection Regulation

Transcription:

DATA PROTECTION NOTICE 1. YOUR PERSONAL DATA COLLECTED & OBTAINED This Data Protection Notice ("Notice") sets out the basis on which It Works! Marketing International UC ( It Works!", we or us ) of 45-46 James Place East, Dublin 2, Ireland uses the personal data detailed below ("Personal Data") we collect from you or that you provide to us through our website or an It Works! Independent Distributor. The information provided by you will be held by us as a data controller. Personal Data Your name, date of birth, email address, billing and shipping addresses, phone number, tax identification number, gender, photo, payment information, details of your purchases, social networking sites, Internet protocol (IP) address, and browser data from the It Works! Website. 2. HOW & WHY WE PROCESS YOUR PERSONAL DATA The following tables detail how ("") and why ("") we process your Personal Data. We also set out who we may transfer your Personal Data to ("") and the period that your Personal Data will be stored for (""). NECESSARY FOR ENTERING INTO OR PERFORMANCE OF A CONTRACT It is necessary to process your Personal Data to enter into and perform our contract with you. We obtain, collect, and process your Personal Data for the following purposes: To process your application to become an It Works! Independent Distributor; To process your application to become an It Works! Customer; To create and manage your account; To fulfil orders for products which you have submitted either as a Distributor or Customer; To process payment for purchases or other services for or on your behalf; To enforce our Distributor or Customer Agreement and otherwise manage our relationship with you, as applicable; To conduct searches to verify your identity; To deliver and organise your orders; To notify you about changes to the It Works! Site and/or services. Your Personal Data will be disclosed to other members of the It Works! Sales organization, including but not limited to any of its affiliates and/or subsidiaries, and service providers engaged by It Works! to fulfil your contract with It Works!. We only share your Personal Data with third party service providers, including warehousing providers, distribution/delivery service providers, payment service providers, and cloud service providers, with whom we have entered into a Data Processing Agreement or have established that their data protection policies and procedures comply with all laws and regulations. We will retain information collected under this legal basis for the length of contract plus seven (7) years. However, we may be required by applicable laws and/or regulations to hold your Personal Data longer than this period. 1

IMPORTANT You are obliged to provide us with your Personal Data as it is necessary to enter into a contract with us. The consequences for not doing so are that your application to become an It Works! Independent Distributor or an It Works! Customer will be refused and/or any purchase of It Works! products or services made by you will not be fulfilled. COMPLIANCE WITH A LEGAL OBLIGATION It is necessary to process your Personal Data in order to comply with the legal obligations which apply to us. We obtain, collect, and process your Personal Data in order to comply with the following legal obligations: To comply with the It Works! Distributor and Customer Agreements, as applicable; To calculate, process, and send commission payments, bonuses, and awards; To send general correspondence relating to your contract or relationship with It Works!; To comply with our contractual relationship with you; To meet any applicable government or regulatory requirements. Your Personal Data will be disclosed to governmental, regulatory, and tax authorities as required. We will retain information collected under this legal basis for the length of our business relationship plus seven (7) years. However, we may be required by applicable laws and/or regulations to hold your Personal Data longer than this period. CONSENT IMPORTANT When you freely and voluntarily give us your Personal Data for the Purpose below, you consent to our processing of your Personal Data. We obtain, collect, and process your Personal Data to register and provide you with information, products, or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes; to notify you about changes to the It Works! Site and/or services; and to send you marketing communications about our products, offers, and promotions. We do share your Personal Data with other members of the It Works! Sales organization, including but not limited to any of its affiliates and/or subsidiaries. We do not share your Personal Data with marketers outside of It Works!. We will retain your marketing communications consent for as long as you remain a Distributor or Customer of It Works! and thereafter as permitted in accordance with local data protection rules, unless you withdraw your consent for us to provide you with marketing information. You may withdraw consent for us to process your Personal Data at any time. However, please note that any processing carried out before you withdraw your consent will remain valid. 2

LEGITIMATE INTEREST We have a legitimate interest to process your Personal Data. We obtain, collect, and process your Personal Data for the following purposes: To manage our sites and services so that we can continue to provide you with opportunities as you engage in your It Works! business; To provide services to help you better serve your Customers; To protect against or identify possible fraudulent transactions; To develop and provide product information, advertising, and business tools; To analyze the use of our products, services, and sites; To understand how you are utilizing business tools offered by us, including personal websites and other e-commerce tools; To determine the effectiveness of our advertising and promotions. We only share your Personal Data with third party service providers, including warehousing providers, distribution/delivery service providers, payment service providers, and cloud service providers, with whom we have entered into a Data Processing Agreement or have established that their data protection policies and procedures comply with all laws and regulations. We will retain information collected no longer than is necessary to fulfil the purposes for which it was collected. However, we may be required by applicable laws and/or regulations to hold your Personal Data longer than this period. 3. TRANSFERS OF YOUR PERSONAL DATA Your Personal Data may be stored and transferred inside or outside the European Economic Area ("EEA"). We only transfer your Personal Data where the EU Commission has decided that the third country in question ensures an adequate level of protection in line with EU data protection standards OR there are appropriate safeguards in place to protect your Personal Data. If you would like to find out more about the appropriate safeguards that we have in place to govern the transfer of your Personal Data you can contact us at privacy@itworks.com. 4. HOW LONG WE KEEP YOUR PERSONAL DATA FOR We may keep your Personal Data for the periods specified in Section 2, above. 5. YOUR RIGHTS The table below sets out your rights to address any concerns or queries about our processing of your Personal Data: Right Right of Access Right to Rectification Right to Erasure Further Information You have the right to request a copy of your Personal Data. We will only charge you for making such an access request where we feel your request is unjustified or excessive. You have the right to request that we amend any inaccurate Personal Data that we have about you. You have the right to ask us to erase your Personal Data where: 1. Your Personal Data is no longer necessary in relation to the purposes for which it was collected or otherwise processed by 3

us; 2. You withdraw your consent and no other legal ground permits us to process your Personal Data; 3. You object to the processing and there are no overriding legitimate grounds for the processing; 4. Your Personal Data has been unlawfully processed; or 5. Your Personal Data must be erased in order to comply with a legal obligation. Right to Restriction of Processing We may not be able to comply with a request where we require your Personal Data for compliance with a legal obligation or in connection with legal proceedings or for exercising the right of freedom of expression and information. You have the right to ask us to restrict processing your Personal Data in the following situations: 1. Where you contest the accuracy of your Personal Data; 2. Where the processing is unlawful and you do not want us to delete your Personal Data; 3. Where we no longer need your Personal Data for the purposes of processing but you require the data in relation to a legal claim; or 4. Where you have objected to our processing of your Personal Data pending the verification of whether our legitimate business interests override your interests, rights, and freedoms or in connection with legal proceedings. Right to Data Portability Right to Object Right to Object to Automated Decision- Making, including Profiling When you exercise this right, we may only store your Personal Data. We may not further process the data unless you consent or the processing is necessary in relation to a legal claim or to protect the rights of another person or legal person or for reasons of important public interest. We will inform you before the processing restriction is lifted. You may request us to provide you with your Personal Data which you have given us in a structured, commonly used and machine-readable format, and you may request us to transmit your Personal Data directly to another data controller where this is technically feasible. This right only arises where: 1. We process your Personal Data on your consent or where it is necessary to perform our contract with you; and 2. The processing is carried out by automated means. You have a right to object at any time to the processing of your Personal Data where we process your Personal Data on the legal basis of pursuing our legitimate interests. You have a right to object at any time to the processing of your Personal Data for direct marketing purposes. You have a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We may not be able to comply with this request where the processing 4

is necessary to enter or perform our contract with you or where you explicitly consent to this. However, you are entitled to have a person from our team review the decision so that you can query it and set out your point of view to us. You can exercise any of these rights by submitting a request to privacy@itworks.com. We will provide you with information on any action taken upon your request in relation to any of these rights without undue delay and at the latest within one month of receiving your request. We may extend this up to two (2) months if necessary due to the specific circumstances of the request. However, we will inform you if this situation arises. You have the right to lodge a complaint with the Office of the Data Protection Commissioner with regards to us processing your Personal Data by contacting the Office of the Data Protection Commissioner. 6. CHANGES TO THIS NOTICE We may amend this Notice on occasion, in whole or part, at our sole discretion. Any changes will be effective immediately upon notice to you. If at any time we decide to use your Personal Data in a manner significantly different from that stated in this Notice, or otherwise disclosed to you at the time it was collected, we will notify you, and you will have a choice as to whether we use your Personal Data in the new manner. Questions, comments and requests regarding this Data Protection Notice are welcomed and should be addressed to privacy@itworks.com. MAY 2018 5