Effective Date: January 2020
Microbiologics is committed to protecting the privacy and security of your personal information by complying with the Privacy Shield Principles, and to being transparent about what information we hold. This policy explains how Microbiologics handles and uses personal data we collect about you. Microbiologics understands its obligations to you to help you understand how and why we process your personal data.
Microbiologics is a “data controller.” This means that we are responsible for deciding how we hold and use personal information about you. We are required under data protection legislation to notify you of the information contained in this privacy notice.
Why we hold your personal data
We are required to hold your personal data for various legal and practical purposes, without which we would be unable to provide products and services to you. Holding your personal data enables us to meet various administrative and legal/regulatory obligations (e.g. for shipping products, complaint handling, technical support).
Personal data collected by Microbiologics
Microbiologics collects data to provide the products and services you request, ease your navigation on our website, communicate with you, and improve your experience interacting with us. This information may be provided by you directly, such as when you create an account on our website, order a product, etc. We collect such data using technologies like cookies and other tracking technologies, error reports, and usage data collected when you interact with Microbiologics’ services running on your device.
We also obtain data from third parties or use third parties to assist us with data collection. For example, we may supplement the data we collect as described in this section by purchasing demographic data from other companies. We also may use services from other companies to help us determine a location based on your IP address notably to customize certain services to your location. In addition, we utilize third-party services to collect usage data.
The data we collect depends on the services and features you use and the nature of your relationship with us, and may include the following:
- Contact information, such as name, address, phone number, fax number, email address or other similar contact data.
- Financial information, such as tax ID numbers, account numbers, banking information, etc.
- Sales information, such as data required for sales quoting, order entry, fulfillment, billing, and paying royalties.
- Credentials to access electronic systems, such as on-line accounts on our website and ERP system.
- Usage information, such as personalized information about your use of our services, to better understand uses thereof and identify potential improvements, as well as to send you promotional communications or offers tailored to your use of our services.
- Website usage and requests, we may collect information regarding every web request sent to the relevant servers. This information is used to provide support, as well as to assess usage and performance of our services. The data collected for each request can include such things as timestamps, any exception messages, user agent, IP address, e-mail address, request time and duration, as well as files names.
- Information you provide to us, such as the content of messages you send to us, including feedback or questions you ask our technical support representatives, when necessary to provide you with the products and services you use. We may collect and utilize any data files you send to us for troubleshooting and improving our services so long as you have anonymized, scrubbed, or deleted any personally identifiable information contained therein which you do not want us to collect or utilize. When you contact us, phone conversations or chat sessions with our representatives may be monitored and recorded in order to improve our services, facilitate the processing and resolution of your request or complaint.
- Feedback information, such as responses from participation in a survey. Participation is voluntary, and you have the choice of whether to disclose any requested information.
- Distributor information, such as contracts, agreements, etc. required in the normal course of business
Please note the above list are examples of information we may have concerning you and it does not mean that we do hold this information on you.
How your personal data is collected by Microbiologics
We typically collect personal information about our customers through the sales process and other customer interactions with us. Data will be stored in a range of formats, including paper hardcopies in filing cabinets electronic systems, and on other IT systems (including email). Microbiologics takes the security of your data seriously. We have internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the proper performance of their duties.
How your personal data is used by Microbiologics
Microbiologics uses information that we collect from our interested parties for the purposes of:
- Providing our products and/or services.
- Providing ongoing technical support, including complaint handling.
- Providing important product change notifications, recall or field safety corrective action information required by international regulations.
- Communicating with you, including promotional communications and customer relationship management (“CRM”).
- Providing marketing information about other products and services.
- Helping us run our company, for example to improve our products and services, train staff or perform marketing activities.
- Complying with our legal and regulatory obligations.
- Accounting and other administrative purposes.
If we send you a marketing e-mail, it will include instructions on how to opt out of receiving these e-mails in the future. We also maintain e-mail preference centers for you to manage your information and marketing preferences. For information about managing e-mail subscriptions and promotional communications, please visit the Your rights regarding personal data section of this privacy statement. Please remember that even if you opt out of receiving marketing e-mails, we may still send you important service information related to your accounts and subscriptions.
Sharing your data with others
We may provide your personal data to:
- Microbiologics-controlled affiliates and subsidiaries, located in and outside your country, including outside the European Union (in such case, we will use appropriate legal framework to operate data transfers).
- Outsourced service providers who perform functions on our behalf, located inside or outside of the European Union (in such case, we will use appropriate legal framework to operate data transfers). For example, when you provide payment data to make a purchase, we will share payment data with banks and other entities that process payment transactions or provide other financial services, and for fraud prevention and credit risk reduction.
- Our authorized agents and representatives located inside or outside of the European Union (in such case, we will use appropriate legal framework to operate data transfers), who sell products or provide services on our behalf, such as training service providers or product resellers.
- Anyone expressly authorized by you to receive your personal data.
- Anyone to whom we are required by law to disclose personal data, upon valid and enforceable request thereof.
Finally, we will access, disclose and preserve personal data, including your content, when we have a good faith belief that doing so is necessary to:
1. Comply with applicable law or respond to valid legal processes, including from law enforcement or other government agencies, upon valid and enforceable request thereof.
2. Operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks.
Please note that some of our services may direct you to services of third parties whose privacy practices differ from Microbiologics’. If you provide personal data to any of those services, your data is governed by their privacy statements or policies. Microbiologics is not responsible for the privacy practices of these other sites. Please review the privacy policies for these web sites to understand how they process your information.
We require third parties to only use your personal data for the specific purpose for which it was given to us and to protect the privacy of your personal data. We will only disclose your personal data to third parties who agree to keep your information confidential.
Transfer of personal data to other countries
Where data is shared within the European Union (EU), the third party will be required to comply with and safeguard the data under the terms of the Data Protection Authorities and appropriate EU regulations.
Your personal information will only be transferred to countries, outside of the EU, whose data protection laws have been assessed as adequate by the European Commission, or where adequate safeguards, such as the EU-US Privacy Shield, are in place.
Handling of personal data
Security of personal data
Microbiologics is committed to protecting the security of your personal data. Depending on the circumstances, we may hold your personal data in hard copy and/or electronic form. For each medium, we use technologies and procedures to protect personal data. We review our strategies and update as necessary to meet our business needs, changes in technology, and regulatory requirements.
These measures include, but are not limited to, technical and organizational security policies and procedures, security controls and employee training.
Storage and transfer of personal data
Microbiologics also collaborates with third parties such as cloud hosting services and suppliers located around the world to serve the needs of our business, workforce, and customers. In some cases, we may need to disclose or transfer your personal data within Microbiologics or to third parties in areas outside of your home country. When we do so, we take steps to ensure that personal data is processed, secured, and transferred according to applicable law.
Retention of personal data
Microbiologics retains personal data for as long as necessary to provide the products and services and fulfill the transactions you have requested, or for other business purposes such as complying with our legal/regulatory obligations, resolving disputes, and enforcing our agreements. We are required by law to keep some types of information for certain periods of time (e.g. statute of limitations). If your personal data is no longer necessary for the legal or business purposes for which it is processed, we will generally destroy or anonymize that information.
Your rights regarding personal data
Microbiologics respects your right to access and control your personal data. You have choices about the data we collect. When you are asked to provide personal data that is not necessary for the purposes of providing you with our products or services, you may decline. However, if you choose not to provide data that is necessary to provide a product or service, you may not have access to certain features or services.
Under certain circumstances, by law you have the right to:
|Request access||In some jurisdictions, you have the right to request access to your personal data. Please contact us if you would like a copy of your personal information we hold to verify that we are lawfully processing it. Please reference request data transfer section for more details on fees.|
|Request correction (rectification)||In some jurisdictions, you may have the right to correct or amend your personal data if it is inaccurate or requires updating. Please inform us of any data which you would like corrected and we will usually respond within a month of the request. Please note that such a request could be refused if it interferes with legal or regulatory obligations. We will pass on the changes to any third parties who need to change their records and let you know this has been done.|
|Request erasure||In some jurisdictions, you have the right to ask for the deletion of your personal data. Where possible, we will comply with all such requests, though some details are part of the Microbiologics’ permanent records which cannot reasonably be deleted. Please note that such a request could be refused because your personal data is required to provide you with the products or services you requested, or data retention is required by our legal obligations.|
|Object to processing||In some jurisdictions, you have the right to ask us to stop processing your personal data. If we can, we will stop processing your data if you object to processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling). We will stop processing your data for direct marketing if you tell us to. We will stop processing your data if you object to processing for purposes of research and statistics.|
|Restrict to processing||In some jurisdictions, you have the right to ask us to restrict the processing of your personal data. You can tell us that we can keep your data but must stop processing it, including preventing future mailings and communications. If possible, we will inform any third parties to whom your data has been disclosed of your requirement.|
|Request data transfer (data portability)||
If you reside within the European Union, you have the right to ask for a copy of your personal data and/or ask for it to be ported to another provider of your choice. Please contact us if you want to review, verify, correct or request erasure of your personal information. Your data is spread across manual paper records and several electronic database systems.
Usually you will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
|Not to be subject to automated decision-making including profiling||We do not use any automated decision-making.|
Marketing preferences: If you have provided us with your contact information, we may, subject to any applicable Spam Act or similar regulation, contact you via e-mail, postal mail or telephone about Microbiologics products, services and events that may be of interest to you, including our newsletter.
E-mail communications you receive from Microbiologics will generally provide an unsubscribe link allowing you to opt-out of receiving future e-mail or to change your contact preferences. E-mail communications may also include a link to directly update and manage your marketing preferences. Please remember that even if you opt out of receiving marketing e-mails, we may still send you important product or service information related to your accounts and subscriptions.
Cookies and similar technologies
While this information on its own may not constitute your personal data, we may combine the information we collect via cookies with personal data that we have collected from you to learn more about how you use our services to improve them.
Cookies set by third party sites
To enhance our content and to deliver a better online experience for our users, we sometimes embed images and videos from other websites on the Sites. We currently use, and may in future use content from sites such as Facebook, LinkedIn and Twitter. You may be presented with cookies from these third-party websites. Please note that we do not control these cookies. The privacy practices of these third parties will be governed by the parties’ own privacy statements or policies. We are not responsible for the security or privacy of any information collected by these third parties, using cookies or other means. You should consult and review the relevant third-party privacy statement or policy for information on how these cookies are used and how you can control them.
We also embed social sharing icons throughout our website. These sharing options are designed to enable users to easily share content from our website with their friends using a variety of different social networks. If you choose to connect using a social networking or similar service, we may receive and store authentication information from that service to enable you to log in and other information that you may choose to share when you connect with these services. These services may collect information such as the web pages you visited and IP addresses, and may set cookies to enable features to function properly. We are not responsible for the security or privacy of any information collected by these third parties. You should review the privacy statements or policies applicable to the third-party services you connect to, use, or access. If you do not want your personal data shared with your social media account provider or other users of the social media service, please do not connect your social media account with your account for the services and do not participate in social sharing on the services.
Other similar technologies
Microbiologics web pages may use other technologies such as web beacons to help deliver cookies on our sites and count users who have visited those sites. We also may include web beacons in our promotional e-mail messages or newsletters to determine whether you open and act on them as well as for statistical purposes.
In addition to standard cookies and web beacons, our services can also use other similar technologies to store and read data files on your computer. This is typically done to maintain your preferences or to improve speed and performance by storing certain files locally.
How to control and delete cookies
Cookies can be controlled, blocked or restricted through your web browser settings. Information on how to do this can be found within the help section of your browser. All cookies are browser specific. Therefore, if you use multiple browsers or devices to access websites, you will need to manage your cookie preferences across these environments.
If you are using a mobile device to access the sites, you will need to refer to your instruction manual or other help/settings resource to find out how you can control cookies on your device.
Please note: If you restrict, disable or block any or all cookies from your web browser or mobile or other device, the sites may not operate properly, and you may not have access to our products or services available through the sites. Microbiologics shall not be liable for any impossibility to use the sites and services or degraded functioning thereof, where such are caused by your settings and choices regarding cookies.
We do not support “Do Not Track” browser settings and do not currently participate in any Do Not Track frameworks that would allow us to respond to signals or other mechanisms from you regarding the collection of your personal information.
EU-U.S. and Swiss-U.S. Privacy Shield frameworks
Privacy Shield principles
Before Microbiologics uses EU personal data for a purpose that is materially different than the original purpose for which it was collected or authorized, we will provide the opportunity to opt out. When we collect sensitive personal data, we will obtain opt-in consent if Privacy Shield requires. This includes disclosure of sensitive personal data to third parties, or third-party use of sensitive personal data for a different purpose than it was originally collected or authorized.
Accountability for Onward Transfer
Microbiologics requires a written contract with any third party receiving EU personal data to ensure that the third party (i) processes the EU personal data for limited and specified purposes; (ii) provides at least the same level of protection as is required by the Privacy Shield principles; (iii) takes reasonable and appropriate steps to ensure they effectively process the EU personal data in a manner consistent with our obligations under the Privacy Shield principles; (iv) notifies us, if at any time, they cannot comply with this policy or the Privacy Shield principles; and (v) takes reasonable and appropriate steps to cease processing EU personal data and remediate unauthorized processing.
Be it known, that under certain circumstances, we may be required to disclose EU personal data in response to valid requests by public authorities, including for national security or law enforcement requirements.
We take reasonable and appropriate measures to protect EU personal data from loss, misuse and unauthorized access, disclosure, alteration, and destruction, considering the risks involved and the nature of the EU personal data.
Data Integrity and Purpose Limitation
We take reasonable measures to ensure that EU personal data is reliable for its intended use, accurate, complete, and current. We adhere to the Privacy Shield principles for as long as it retains EU personal data in identifiable form. Microbiologics takes reasonable and appropriate measures to retain EU personal data in identifiable form only for as long as it serves a relevant purpose. We do not process EU personal data in a way that is inconsistent with the purpose for which it was originally collected or subsequently authorized by you.
You have the right to access your EU personal data and to correct, amend or delete the data if it is inaccurate or processed in violation of the Privacy Shield principles. We are not required to grant these rights if the burden or expense is not consistent with the risks to privacy, or if the rights of others could be violated.
Recourse, Enforcement, and Liability
Microbiologics is subject to the regulatory enforcement powers of the United States Federal Trade Commission in regard to personal data received, processed, or transferred pursuant to the Privacy Shield frameworks.
We encourage escalating unresolved privacy complaints to an independent dispute resolution mechanism. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm for more information and to file a complaint with an EU Data Protection Authority. This service is provided free of charge to you. We commit to cooperate with the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC), as applicable, and comply with the advice given by such authorities.
If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction.
If you reside in Australia, you may obtain information about privacy and lodging a complaint with the Federal Privacy Commissioner (FPC) at http://www.oaic.gov.au.
Microbiologics commits to periodic self-review activities to verify its compliance with the Privacy Shield principles and to take corrective action resulting from any exposed issues. We acknowledge that annual self-certification to the United States Department of Commerce is required to remain on the department’s list of Privacy Shield participants.
Notice to users outside the United States
Microbiologics is headquartered in the United States. Your use of our products or services is governed by United States law. If you are using the website from outside of the United States, your information may be transferred to, stored, and processed in the United States where Microbiologics’ servers are located. In accordance with and as permitted by applicable law and regulations, we reserve the right to transfer your information, process, and store it outside your country of residence to wherever we or our third-party service providers operate.
Name: Kali Sorum
Attention: Kali Sorum
200 Cooper Avenue North
Saint Cloud, MN 56303-4440 USA
Where you have specific requests relating to how we manage your data, we will endeavor to resolve these, but please note that there may be circumstances where we cannot comply with specific requests.