This Privacy Notice is effective as of August 1, 2018.
At Polyform Products Company, Inc. (“PPC”), we recognize the importance of protecting your Personal Data and are committed to processing it responsibly and in compliance with applicable data protection laws in all countries in which we operate.
In the normal course of its business activities, PPC collects, uses, and sometimes shares personal data of various individuals and organizations in order to run its day-to-day operations. This Privacy Notice describes PPC’s general privacy practices that apply to such Personal Data collection and use.
TYPES OF PERSONAL DATA WE COLLECT
In describing our collection, use, and sharing of data in this Notice, we refer to our collection and use of "Personal Data." "Personal Data," as used in this Notice, is any Data related to an identified or identifiable natural person. Examples of Personal Data include first and last name, mailing address, email address, billing data, IP address, other online contact data, or telephone number, gender, age category, profession, and level of clay experience and main interests.
HOW WE COLLECT YOUR PERSONAL DATA
We collect Personal Data in three ways:
Passive Data Collection
We may collect, use, and share (with PPC consultants, partners, service providers, distributors and licensees) precise location data, including the real-time location of your mobile or fixed location device.
We use analytics tools and other third-party technologies, such as Google Analytics, Facebook Analytics, and DoubleClick Cookiesto collect non-personal data in the form of various usage and user metrics when you use the PPC Sculpey.com website or use our services (the PPC Sculpey.com website and our services are referred to as “Sites and/or Services” in this Notice). These tools and technologies collect and analyze certain types of data, including cookies, IP addresses, device and software identifiers, referring and exit URLs, onsite behavior and usage data, feature use metrics and statistics, usage and purchase history, MAC Address, mobile unique device ID, and other similar data.
The third-party analytics companies who collect data on our Sites and/or Services and other online products and/or services may combine the data collected with other data they have independently collected from other websites and/or other online or mobile products and services relating to your activities across their network of websites as well as online and/or mobile products and services. Many of these companies collect and use data under their own privacy notices.
In addition to our use of technologies as described herein, we may permit certain third-party companies to help us tailor advertising that we think may be of interest to you based on your use of our Sites and/or Services and to otherwise collect and use data about your use of our Sites and/or Services. For more information about this practice, please see the "Third Party Advertising Technologies" section below.
You may opt out of the DoubleClick cookie by visiting the Google advertising opt-out page or you may opt out of Google Analytics by visiting the Google Analytics opt-out page.
Google has additional Data available about their Remarketing Privacy Guidelines, and Restrictions.
You may view a list of other third party service providers who collect Data, and/or opt-out of such collection of Data about you, by visiting http://www.networkadvertising.org/choices/ or http://www.aboutads.info/choices/.
We may use a variety of methods, including "cookies" to collect data.
What is a cookie?
Cookies are text files containing small amounts of Data which are downloaded to your device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. Cookies are useful because they allow a website to recognize a user’s device. You can find more information about cookies at: http://www.allaboutcookies.org .
Cookies do lots of different jobs, like letting you navigate between pages efficiently, remembering your preferences, and generally improve the user experience. They can also help to ensure that advertisements you see online are more relevant to you and your interests.
The cookies used on our Sites and/or Services have been categorized based on the categories found in the ICC UK Cookie guide. The cookies used on our Sites and/or Services by category are described below.
PPC collects cookies on our Sites and/or Services to capture data about page visits (e.g. “performance cookies.”) This data is anonymous and PPC uses this data only internally to deliver the most effective content to our visitors. Data from the cookie is used to gauge page popularity, analyze traffic patterns on our Sites and/or Services and guide development of other improvements to our Sites and/or Services.
Targeting, Performance, and Functionality Cookies
In our email programs, PPC employs some tracking methods (e.g. “targeting, performance, and functionality cookies”). We track “opens” via a tracking pixel in the email- meaning we track who opens our e-mail messages and when you open our e-mail messages; and we track “clicks” via encoded URLs-meaning we track whether you click on the links contained in our e-mail messages via MailChimp. This data is used internally only to help us deliver relevant messaging and is not shared with any third parties other than as indicated in this Notice.
Functionality and Necessary Cookies
Opting Out of Cookies
You can set your browser to notify you when you receive a cookie, giving you the chance to decide whether or not to accept it. You may also change your cookie settings through preference options in our Sites and/or Services, where applicable. We will indicate that upon selecting your preferences, that we will use a cookie to remember your preferences.
Third Party Advertising Technologies
In addition to using cookies and related technologies as described above, we also may permit certain third-party companies such Hootsuite and MailChimp to help us tailor advertising that we think may be of interest to users and to collect and use other data about user activities on our Sites and/or Services (e.g., to allow them to tailor ads on third party services). These companies may deliver ads that might also place cookies and otherwise track user behavior. These companies may use information about user behavior in order to provide customized advertisements across various services and products. In the course of providing these services, products or placing advertisements, these third-party companies may place or recognize a unique cookie on your computer and may record data to these cookies based upon your activities on any of our Sites and/or Services and on third party websites. Each of these companies uses this cookie data according to their own privacy and security notices. If you wish to not have this data used for the purpose of serving you targeted ads, you may opt-out as indicated in this Notice. Please note this does not opt you out of being delivered advertising. You will continue to receive generic ads.
Personal Data relating to Children
We do not knowingly seek or collect Personal Data from users under the age of 16 (a “Child”). In the event that we learn that we have inadvertently collected Personal Data from a Child, we will delete that information as quickly as possible. If you believe that a Child may have provided us Personal Data, please contact us at [email protected].
HOW WE USE YOUR PERSONAL DATA
We only use your data as expressly set forth in this Notice. If a need arises to use your data for a secondary purpose, we will provide you prior notice of such use.
Communication and Responding to Requests
We use your information, including Personal Data to provide you with customer support, process transactions, respond to users' requests, send newsletters and updates, send special offers and advertisements, seek your opinions and feedback, community announcements, and connect users to PPC Sites and/or Services, and to products and services of our partners and licensees.
We use your information, including Personal Data, behavioral metrics, and other non-personally identifiable information to operate, provide, improve, and maintain our Sites and Services, to develop new products and services, to prevent abuse and fraud, to personalize and display advertisements and other content for you, and for other administrative and internal business purposes.
We use your information, including Personal Data, behavioral metrics, geo-location data, demographic data and marketing preferences to personalize and display advertisements and other content for you.
We may allow you to share user generated clay images, videos, text, and drawings, through our Sculpey.com community using #sculpeyprojects, for example, through the use of various third-party services (e.g., social networking, search and sharing services). When sharing content using one of these third-party services, if you are not already logged in to the third-party service, you will need to supply login credentials for it. If you are not a registered user of the third-party service, you will need to sign up for it. You are supplying the registration information or login credentials for the third-party service directly to that third party, and not to us. By using any of these third-party services to share content, you permit us to access, use and disclose any information relating to your account on each such third- party service (such as your user name and profile information) that is available to us through the third-party service, including through its application programming interface (API) pursuant to this Notice.
More specifically, our Sites and/or Services may use interfaces with social media sites such as Instagram, Pinterest, Facebook, Twitter, YouTube and others. If you choose to "like" or share information from our Sites and/or Services through these services, you should review the privacy notice of that service. If you are a member of a social media site, the interfaces may allow the social media site to connect your site visit to your personally identifiable information resulting in the public display of the same.
Legal basis for processing personal Data (EEA visitors only)
If you are a visitor from the European Economic Area, our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which we collect it.
However, we, generally, will normally collect Personal Data from you only where we have your consent to do so, where we need the Personal Data to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Data from you or may otherwise need the Personal Data to protect your vital interests or those of another person.
If we ask you to provide Personal Data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Data is mandatory or not (as well as of the possible consequences if you do not provide your Personal Data).
Similarly, if we collect and use your Personal Data in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
If you have questions about or need further Data concerning the legal basis on which we collect and use your Personal Data, please contact us using the contact details provided under the How To Contact Us heading below.
REASONS WE SHARE YOUR PERSONAL DATA
We do not share your Personal Data with third parties except as noted herein. We may share your Personal Data as necessary to maintain business operations which includes sharing Personal Data with retailers that subscribe to Services, and with vendors working on our behalf (for example, delivery of services and digital advertising); as required by law or to respond to legal process; to maintain the security of our products; to protect PPC’s customers, employees, rights, or property; as part of a merger or acquisition; or with your express consent.
The PPC has its headquarters in the United States. Information we collect from you will be processed in the United States. The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the General Data Protection Regulation (“GDPR). The PPC relies on derogations for specific situations as set forth in Article 49 of the GDPR. In particular, the PPC collects and transfers to the U.S. personal data only: with your consent; to perform a contract with you; or to fulfill a compelling legitimate interest of the PPC in a manner that does not outweigh your rights and freedoms. The PPC endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with the PPC and the practices described in this Privacy Notice. The PPC also enters into data processing agreements and model clauses with its vendors, such as Hootsuite and MailChimp, whenever feasible and appropriate.
PPC commits to resolve complaints about your privacy and our collection or use of your Personal Data. EU and Swiss individuals with questions or concerns about the use of their Personal Data should contact us using the information provided in the “How to Contact Use” below.
If a Customer's question or concern cannot be satisfied through this process, PPC commits to cooperate under an independent dispute resolution mechanism operated by the European Union Data Protection Authorities (EU DPA) or the Swiss Federal Data Protection and Data Commissioner (FDPIC) and comply with the advice given by the EU DPA or FDPIC, as applicable.
If you do not receive timely acknowledgement of your complaint, or if your complaint is not satisfactorily addressed by PPC, EU individuals may bring a complaint before the EU DPA (http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm) or Swiss individuals may bring a complaint before the FDPIC (http://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/task.html) .
HOW WE SECURE YOUR PERSONAL DATA
PPC uses a variety of security technologies and procedures to help protect your Personal Data from unauthorized access, use or disclosure. While we implement safeguards designed to protect your Personal Data, no security system is impenetrable and due to the inherent nature of the internet, we cannot guarantee that data, during transmission through the internet or while stored on our systems or otherwise in our care, is absolutely safe from intrusion by others.
Data storage and retention
Your Personal Data is stored by the PPC on its servers, and on the servers of the cloud-based database management services the PPC engages, located in the United States. The PPC retains data for the duration of the customer’s or your business or subscriber relationship with the PPC and for a period of time thereafter to allow you to recover accounts if they decide to renew, to analyze the data for PPC’s own operations, and for historical and archiving purposes associated with PPC’s. For more information on where and how long your Personal Data is stored, contact us by using the contact details provided under the How To Contact Us heading below.
HOW TO ACCESS AND CONTROL YOUR PERSONAL DATA
You may access and review the Personal Data PPC stores about you and correct any factual errors. Most of your Personal Data may be accessed and corrected by simply logging into your account and accessing your profile.
If you are an EU resident, you have the following data protection rights:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.
To exercise your data subject rights, navigate to https://www.sculpey.com/create/general-inquiry/.
If you have a privacy-related concern complaint, or question, please contact us at: [email protected]
Or, you may reach us using the following information:
Polyform Products Company, Inc.
1901 Estes Avenue
Elk Grove Village, IL 60007-5415 USA
If you are a resident of the EU, you also have the right to file a complaint with the applicable data protection or other supervisory authority (“DPA”). You can find a list of DPAs at: https://www.dataprotection.ie/docs/Home/4.htm
CHANGES TO NOTICE
Please note that this Privacy Notice may change from time to time. If there are material changes to this Privacy Notice or in how we use your Personal Data, we will post a notice on our home page that this Privacy Notice has changed. You are also encouraged to periodically review this Privacy Notice to stay informed on how we are protecting your personal Data.