Aperio CI, INC.
POLICY ON DATA PROTECTION AND PRIVACY OF PERSONAL INFORMATION

I. INTRODUCTION

Aperio CI, Inc. (“Aperio CI”) transacts business with companies here in the United States and internationally, including countries that are part of the European Union (“EU”). We do not currently have employees who reside outside of the United States. We do have agents who reside outside of the United States. Our policy concerning the privacy of individuals’ personal identifiable information is treated consistently with the same high level of security regardless of whether the information emanated from within or without the United States.

II. Data Protection Compliance

It is Aperio CI’s policy to comply with all applicable regulatory requirements for the processing of personal and sensitive data, including the EU Data Protection Directive, the U.S. Commerce Department Privacy Shield framework, the U.K. Data Protection Act of 1998, as each may be amended and supplemented.

Aperio CI complies with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries. Aperio CI has certified that it adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability. If there is any conflict between the policies in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/

Aperio CI, Inc is participating in the EU-U.S.Privacy Shield program. This is a link to the Commerce Department’s list of participating companies. https://www.privacyshield.gov/list

III. Aperio CI as a Data Processor

Aperio CI’s role in data protection and privacy is generally limited by its position as a data processor. Aperio CI currently receives data from entities located in the EU (an “EU Member”) merely for processing.

As explained in Supplemental Principle 10 (Obligatory Contracts for Onward Transfers), when personal data is transferred from the EU to the United States only for processing purposes, a contract will be required, regardless of participation by the processor in the EU-U.S. Privacy Shield.

Data controllers in the EU are always required to enter into a contract when a transfer is made for processing purposes only, whether the processing operation is carried out inside or outside the EU, and whether or not the processor participates in the Privacy Shield. The purpose of the contract is to make sure that the processor:

  • acts only on instructions from the controller;
  • provides appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, and understands whether onward transfer is allowed; and
  • taking into account the nature of the processing, assists the controller in responding to individuals exercising their right to access their personal data.

Accordingly, for processing purposes, Aperio CI’s privacy policy with regard to the EU-U.S. Privacy Shield Principles is tailored to Aperio CI’s Role as a data processor. Many responsibilities imposed by regulatory authorities are necessarily outside the scope of Aperio CI’s limited role as a data processor and therefore fall to other parties, including Aperio CI’s clients and their constituents.

Aperio CI currently is subject to and will enter into a written contract with a EU Member, prior to processing any such data. The contract will contain terms and provisions regarding each respective party’s rights and obligations as it relates to the processing of data. This will ensure that the EU data controller will be in compliance with the Member State Data Protection law. Any data processed by Aperio CI will not be disclosed to third parties, except where permitted or required by the contract between the EU Member and Aperio CI. Any information, which an Aperio CI customer (acting as the EU controller) identifies as sensitive information will be treated accordingly.

Aperio CI has in place and will provide as such in a Master Agreement with an EU Member that Aperio CI has adequate data security measures to protect personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction.

If we ever were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we would provide you with an opt-out choice to limit the use and disclosure of your personal data.

We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

In cases of onward transfer to third parties of data of EU individuals received pursuant to the EU-US Privacy Shield, Aperio CI is potentially liable.

IV. Definitions

For purposes of this Policy, the following definitions shall apply:

"Agent" means any third party that may use Personal information provided by Aperio CI to perform tasks on behalf of or at the instruction of Aperio CI.

"Personal Information" means any information or set of information that identifies or could be used by or on behalf of Aperio CI to identify an individual. Personal information does not include information that is encoded or anonym zed, or publicly available information that has been combined with nonpublic Personal information.

"Sensitive Personal Information" means Personal information that reveals race, ethnic origin, trade union membership, or that concerns health. In addition, Aperio CI will treat as sensitive Personal Information any information received from a third party where that third party treats and identifies the information as sensitive.

V. Privacy Principles

  1. "Notice" Where Aperio CI collects Personal Information directly from individuals, it will inform them about the purposes for which it collects and uses Personal Information about them, the types of non-agent third parties to which Aperio CI discloses that information, and the choices and means, if any, Aperio CI offers individuals for limiting the use and disclosure of their Personal Information. Notice will be provided in clear and conspicuous language when individuals are first asked to provide Personal Information to Aperio CI, or as soon as practicable thereafter, and in any event before Aperio CI uses the information for a purpose other than that for which it was originally collected. Aperio CI may disclose Personal Information if required to do so by law or to protect and defend the rights or property of Aperio CI.
  2. "Choice" Aperio CI will offer individuals the opportunity to choose (opt-out) whether their Personal Information is
    1. to be disclosed to a non-agent third party, or
    2. to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.

      For Sensitive Personal Information, Aperio CI will give individuals the opportunity to affirmatively and explicitly (opt-in) consent to the disclosure of the information to a non-agent third party or the use of the information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.

      Aperio CI will provide individuals with reasonable mechanisms to exercise their choices should requisite circumstances arise.
  3. "Data Integrity." Aperio CI will use Personal information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual. Aperio CI will take reasonable steps to ensure that Personal Information is relevant to its intended use, accurate, complete and current.
  4. "Access." Upon request, Aperio CI will grant individuals reasonable access to personal information that it holds about them. In addition, Aperio CI will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete. Aperio CI acknowledges that EU individuals have the right to access the personal information that we maintain about them. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his query to privacy.officer@aperioci.com.
  5. "Enforcement." Aperio CI will conduct compliance audits of its relevant privacy practices to verify adherence to this Policy. Any employee that Aperio CI determines is in violation of this policy will be subject to disciplinary action up to and including termination of employment.

VI. Dispute Resolution.

Any questions or concerns regarding the use or disclosure of personal information should be directed to the Aperio CI Privacy Officer at the address given below. Aperio CI will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with the principles contained in this Policy. For complaints that cannot be resolved between Aperio CI and the complainant, Aperio CI has agreed to participate in the dispute resolution procedures of the panel established by the European data protection authorities to resolve disputes pursuant to the Privacy Shield Principles.

Aperio CI is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).

European Union individuals may file a complaint, free of charge, online or by mail In compliance with the EU-US Privacy Shield Principles, Aperio CI, Inc. commits to resolve complaints about your privacy and our collection or use of your personal information. European Union individuals with inquiries or complaints regarding this privacy policy should first contact Aperio CI, Inc at:

Privacy Officer
Aperio Ci, Inc.
25 Howard Place
Ronkonkoma, NY 117979
privacy.officer@aperioci.com

Aperio Ci, Inc. has further committed to refer unresolved privacy complaints under the EU-US Privacy Shield Principles to BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint.

Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.

Changes to Aperio CI’s Privacy Shield Privacy Policy

The preceding paragraphs describe Aperio CI’s personal data protection policy as of Friday, September 30, 2016. Aperio CI retains the right to modify or amend this Policy at any time consistent with the requirements of the Privacy Shield Principles.

+1 631.468.4000