1. This Privacy Notice (the “Notice”) sets out how we, Katun Corporation with offices at 10951 Bush Lake Road, Minneapolis, Minnesota U.S.A. 55438-2391, and our affiliates, parent companies and associated offices from time to time (collectively “Katun”, “we”, “us”, “our”) process the personal data of individuals (each a “User”, “you”, “your”) who contact us or who use our websites, services, applications, content and related features, including Katun.com, the Katun Online Catalog, and the Katun Marketplace (collectively, the “Website”) or whose details we process on behalf of our clients in connection with our client services (“Client Services”).
2. If you have any questions about this Notice, please contact us by email to the Data Protection Officer, Laurie Young, at Laurie.firstname.lastname@example.org.
3. This notice, together with our Website Terms and any other documents referred to in these documents, set out our views and practices regarding your personal data and how we will treat it. Please read these documents carefully. By visiting our Website, you acknowledge the processing described in this Notice, our Website Terms and related documents.
4. We will let you know, by posting on our Website or otherwise, if we make any changes to this Notice from time to time. Your continued use of the Website, our services or your continued dealing with us after notifying such changes will amount to your acknowledgement of the amended Notice.
5. This version of our privacy notice was published in March 2018.
What are personal data?
6. “Personal data” means any information relating to an identified or identifiable natural person, known as ‘data subject’, who can be identified directly or indirectly; it may include name, address, email address, phone number, IP address, location data, cookies, a recording of your call with us and similar information. It may also include “special categories of personal data” such as racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a data subject, data concerning health or data concerning a natural person’s sex life or sexual orientation.
What personal data do we process?
7. We may process the following personal data:
(a) Information provided by you. You may give us information about you by, for example, filling in forms such as the contact form on the Katun Online Catalog, or any other website associated with Katun, subscribing to services, such as email updates, making applications in respect of job postings, corresponding with us by e-mail, phone or otherwise. This information may include your name, email address, phone number, information about your query and similar information.
(b) Information about others. You may also provide to us personal data relating to third parties, such as people who you work with, or your referees. Information about third parties should only be provided if you have demonstrable permission to do so or if the information is available in the public domain.
(c) Information about your device. With regard to each visit to our website we may collect technical information about your device such as IP address, operating system, browser, time zone setting, language setting, the Internet address of the website from which you linked directly to our website, URL clickstream data, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
(d) Information from third party sources. This may include information about you received from credit reference agencies, our service providers and other third parties.
8. Generally, you are under no obligation to provide this information, but without it, we may be unable to provide you with some of our Website content and services as well as services that we provide on behalf of our clients.
9. We will rely on the information provided by you as accurate, complete and up to date and you agree to ensure that this will be the case.
How do we use your personal data?
10. We will only process personal data, in accordance with applicable law, for the following purposes:
(a) responding to your queries, requests and other communications, for example, if you apply for a job or you send us a query about our Website;
(b) providing the Website and related services including our Website, content and features;
(c) enabling suppliers and service providers to carry out certain functions on our behalf in order to provide the Website and related services, including freight carriers, banking services, webhosting, data storage, identity verification, technical, logistical and other functions, as applicable;
(d) allowing you to use features on our Website and related services, when you choose to do so;
(e) carrying out profiling for business administration, recruitment, advertising and other business purposes, such as for example analyzing User trends to deliver relevant ads to Users’ devices; using recruitment tools that allow us to score those applicants who complete a test, and to consider their suitability for specific roles;
(f) sending you personalized marketing communications as permitted by law or as requested by you. If you would like to unsubscribe please click here or notify your local sales representative which can be found at http://www.katun.com/eu/about-us/contact-katun/locations/europe/
(g) serving personalized advertising to your devices, based on your interests in accordance with our Cookie Statement below. You have the right to disable cookies as set out below;
(h) ensuring the security of our business and preventing and detecting fraud;
(i) administering our business, including complaints resolution, troubleshooting of our website, data analysis, quality control, staff training, testing of new features, research, statistical and survey purposes;
(j) developing and improving our Website and related services;
(k) providing Client Services, where we process personal data as a data processor in accordance with the instructions of our clients in their capacity as data controllers; and
(l) complying with applicable law, including in response to a lawful request from a court or regulatory body.
11. The legal basis for our processing of personal data for the purposes described above will typically include:
• processing necessary to fulfil a contract that we have in place with you or other data subjects, such as processing for the purposes set out in paragraphs 10(a), (b), (c), (d) and (e);
• your consent, such as processing for the purposes set out in paragraphs 10(e), (f) and (g);
• processing necessary for our or a third party’s legitimate interests, such as processing for the purposes set out in paragraphs 10(a), (b), (c), (h), (i) and (j), which is carried out on the basis of our legitimate interests to ensure that our Website and related services are properly provided, ensure the security of our business and our Users and the proper administration of our business;
• processing necessary for compliance with a legal obligation to which we are subject, such as processing for the purposes set out in paragraph 10(l);
• our agreements with, and instructions provided by, our clients for whom we act as a data processor, as set out in paragraph 10(k); and
• any other applicable legal ground from time to time.
13. The cookies placed on our website. We use the following cookies on our website:
• Strictly necessary cookies. These cookies are essential in order to enable you to move around our website and use its features. Without these cookies, the Website and related services you have asked for cannot be provided. They are deleted when you close the browser. These are first party cookies.
• Performance cookies. These cookies collect information in an anonymous form about how visitors use our website. They allow us to recognize and count the number of visitors and to see how visitors move around the website when they are using it and the approximate regions that they are visiting from. These are first party cookies.
• Functionality cookies. These cookies allow our website to remember choices you make (such as your user name, language or the region you are in, if applicable) and provide enhanced, more personal features. The information these cookies collect may be anonymized and they cannot track your browsing activity on other websites. These are first party cookies.
14. We may combine information from these types of cookies and technologies with information about you from other sources.
15. Cookie consent and opting out. By using our Website, we assume that you are happy for us to place cookies on your device. Most Internet browsers automatically accept cookies. However, if you, or another user of your device, wish to withdraw your consent at any time, you have the ability to accept or decline cookies by modifying your browser setting. If you choose to decline cookies, you may not be able to fully experience the interactive features of our Website and related services.
16. Marketing. If you would like us to stop sending you marketing emails you may use the opt-out link at the bottom of any marketing email we send. Although we encourage you to use the opt-out link because it is automated, you may also send us a request by contacting either your customer service representative or notify your local sales representative which can be found at http://www.katun.com/eu/about-us/contact-katun/locations/europe/.
17. Cookies. By using our Website, we assume that you are happy for us to place cookies on your device. Most Internet browsers automatically accept cookies. However, if you, or another user of your device, wish to withdraw your consent at any time, you have the ability to accept or decline cookies by modifying your browser setting. If you choose to decline cookies, you may not be able to fully experience the interactive features of our Website and related services. The website www.allaboutcookies.org contains comprehensive information about the process of opting out on different browsers. Note that if you disable cookies, the Website may not function properly.
Disclosure of personal data
19. There are circumstances where we may wish to disclose or are compelled to disclose your personal data to third parties. These scenarios include disclosure to:
• our affiliates, parent companies or associated offices;
• our suppliers and service providers to facilitate the provision of the Website, related services and our Client Services, including IT consultants, webhosting providers, recruitment services providers, identity verification partners (in order to verify your identity against public databases), call centers, consultants and similar third parties;
• our suppliers and service providers to facilitate necessary and legitimate business activities, for example freight carriers and banking services.
• subject to appropriate legal basis such as consent, our advertising and marketing partners who enable us, for example, to deliver personalized ads to your devices or who may contact you by post, email, telephone, SMS or by other means;
• successor or partner legal entities, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganization, change of legal form, dissolution or similar event relating to our business. In the case of a merger or sale, your personal data will be permanently transferred to a successor company;
• our clients and third parties as directed by our clients, where we process personal data as a data processor on behalf of our clients;
• public authorities, such as law enforcement agencies, courts and other public bodies where we are required by law to do so; and
• other third parties where you have provided your consent.
International transfer of your personal data
20. We may transfer your personal data to a third party in countries outside the country in which it was originally collected for further processing in accordance with the purposes set out above. In particular, your personal data may be transferred across our group of companies to the US, throughout Europe, Taiwan and other countries. Where this is the case, we will ensure that appropriate transfer mechanisms, such as the EU Commission approved Standard Contractual Clauses, are in place to ensure an adequate level of data protection.
21. If we transfer personal data to private organizations abroad, such as our suppliers and service providers, we will, as required by applicable law, ensure that your privacy rights are adequately protected by appropriate technical, organization, contractual or other lawful means. You may contact us for a copy of such safeguards in these circumstances.
Retention of personal data
22. We retain personal data for as long as is necessary for the purposes listed above or longer as may be required by the law. Please contact us for further details of applicable retention periods.
23. We may keep an anonymized form of your personal data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.
24. We will retain personal data in accordance with our clients’ instructions where we act on their behalf as a data processor.
Security of personal data
25. We will use appropriate technical and organizational information security measures to try to prevent unauthorized access to your personal data. However, please be aware that the transmission of information via the internet is never completely secure. Whilst we can do our best to keep our own systems secure, we cannot control the whole of the internet and we cannot therefore guarantee the security of your information as it is transmitted to and from our website.
26. Where you have created or received a password or authentication code which enables you to access certain parts of our website, you are responsible for keeping this password or authentication code confidential. We ask you not to share your password or authentication code with anyone.
Data subject rights
27. Depending on your country’s laws, you may have numerous rights in relation to your personal data except where we processed such data on behalf of another party, e.g. our client as part of Client Services, in which case you should contact the client directly in relation to your rights. For further information about your data privacy rights please visit the website of your local data privacy authority.
• Right to make a subject access request (SAR). Data subjects may request in writing copies of their personal data. However, compliance with such requests is subject to certain limitations and exemptions and the rights of other individuals. Each request should make clear that a SAR is being made. You may also be required to submit a proof of your identity and payment, where applicable. You may access the request form via the Privacy Link on our Website.
• Right to rectification. Data subjects may request that we rectify any inaccurate or incomplete personal data.
• Right to withdraw consent. Data subjects may at any time withdraw their consent to the processing of their personal data carried out by us on the basis of their previous consent. Such withdrawal will not affect the lawfulness of processing based on such previous consent.
• Right to object to processing including profiling. We will comply with valid objection requests unless we have a compelling overriding legitimate ground for the continuation of our processing or we have another lawful reason to refuse such request. We will comply with each valid opt-out request in relation to marketing communications.
• Rights in relation to automated decisions about you. Where we make a decision about you based solely on automated processing which significantly affects you, you will have you the right to contest the decision, express your point of view and obtain human intervention.
• Right to erasure. Data subjects may request that we erase their personal data. We will comply, unless there is a lawful reason for not doing so. For example, there may be an overriding legitimate ground for keeping the personal data, such as, our business record retention obligations that we have to comply with.
• Restriction. Data subjects may request that we restrict our processing of their personal data in various circumstances. We will comply, unless there is a lawful reason for not doing so, such as, a legal obligation to continue processing your personal data in a certain way.
• Right to data portability. In certain circumstances, data subjects may request the controller to provide a copy of their personal data in a structured, commonly used and machine-readable format and have it transferred to another provider of the same or similar services. We do not consider that this right applies to our Website. However, to the extent it does, we will comply with such transfer request. Please note that a transfer to another provider does not imply erasure of the data subject’s personal data which may still be retained for legitimate and lawful purposes.
• Right to lodge a complaint with the supervisory authority. We suggest that data subjects contact us about any questions or complaints in relation to how we process their personal data. However, each data subject has the right to contact the relevant supervisory authority directly. A list of supervisory authorities is available here.
28. Where we act on behalf of our clients as a data processor, we will pass on any rights requests to our respective clients who will then be in touch with the requestor.