Privacy Policy GDPR Addendum

Privacy Policy Addendum for EU Residents (GDPR)

Effective Date: July 22, 2022
Last Updated on: July 22, 2022

Introduction

This GDPR Privacy Addendum supplements the information in the Rand Privacy Policy and applies to Personal Data about individuals located in the European Economic Area. For purposes of this GDPR Privacy Addendum, Personal Data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

This GDPR Privacy Addendum (the “GDPR Privacy Addendum”) supplements the information contained in the Rand Privacy Policy and applies solely to all users of our Site who are located in the European Economic Area. We adopt this GDPR Privacy Addendum to comply with the General Data Protection Regulation (2016/679) and any
implementing acts of the foregoing by any of the member states of the European Economic Area, the United Kingdom, or Switzerland (“GDPR”) and any terms defined in the GDPR or our Privacy Policy have the same meaning when used in this GDPR Privacy Addendum. This GDPR Privacy Addendum takes precedence over anything contradictory in our Privacy Policy.

Data Controller, Data Protection Officer, and Representative

Rand Technology, LLC is the data controller of the Personal Data you provide on or through our Site.

We may be contacted in any manner set forth below in the “Contact Information” section of this GDPR Privacy Addendum.

Lawful Basis for Processing Your Personal Data

We have a lawful basis for our processing of your Personal Data, including processing for our legitimate interests (when balanced against your rights and freedoms), as required by law, and with your consent.

If you are in the European Union, the processing of your Personal Data is lawful only if it is permitted under the applicable data protection laws. We have a lawful basis for each of our processing activities as set forth more fully below:

Purpose/Activity Type of data Lawful basis for processing
To register you as a new User Identity
Contact
Performance of a contract with you
To process your materials Identity
Contact
Financial
Transaction
Marketing and Communications
Performance of a contract with you
Necessary for our legitimate interests
To manage our relationship with you which will include: Notifying you about changes to our terms or privacy policy; Communicating with you regarding your submission Identity
Contact
Profile
Marketing and Communications
Performance of a contract with you
Necessary to comply with a legal obligation
Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
To deliver direct marketing to you Identity
Contact
Profile
Usage
Marketing and Communications
Tracking
Technical
For most direct marketing communications, we rely on consent based on our privacy policy, however there are situations in which it is in our legitimate interests to use your personal data in this way
To enable you to take part in a prize draw, competition or complete a survey Identity
Contact
Profile
Usage
Marketing and Communications
Performance of a contract with you
Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) Identity
Contact
Technical
Tracking
Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)
Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you Identity
Contact
Profile
Usage
Marketing and Communications
Technical
Tracking
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences Technical
Tracking
Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you Identity
Contact
Technical
Usage
Profile
Necessary for our legitimate interests (to develop our products/services and grow our business)
To prevent and detect unlawful acts Identity Contact
Financial Transaction
Technical Tracking
Necessary for our legitimate interests (to protect our business and our customers by way of undertaking fraud monitoring and suspicious transaction monitoring)
Necessary to comply with a legal or contractual obligation to share personal data for the purposes of law enforcement
In order to resolve legal claims or disputes involving you or us All relevant data categories, depending on the nature of the allegation or claim Necessary to bring or defend a claim

Special Categories of Information

We do not collect or use Personal Data considered as Special Categories of Information such as the following:

  • Personal Data Revealing Racial Or Ethnic Origin.
  • Political Opinions.
  • Religious Or Philosophical Beliefs.
  • Trade Union Membership.
  • Genetic Data And Biometric Data Processed For The Purpose Of Uniquely Identifying A Natural Person.
  • Data Concerning Health.
  • Data Concerning A Natural Person’s Sex Life Or Sexual Orientation.

Automated Decisions Making

We do not use your Personal Data with any automated decision making process, including profiling, which may produce a legal effect concerning you or similarly significantly affect you.

Your Rights Regarding Your Information and Accessing and Correcting Your Information

You may have certain rights under applicable data protection laws, including the right to access and update your Personal Data, restrict how it is used, transfer certain Personal Data to another controller, withdraw your consent at any time, and the right to have us erase certain Personal Data about you. You may also have the right to complain to a supervisory authority about our processing of your Personal Data.

Applicable data protection laws may provide you with certain rights with regards to our processing of your Personal Data.

  • Access and Update. You may notify us through the Contact Information below of any changes or errors in any Personal Data we have about you to ensure that it is complete, accurate, and as current as possible. We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.
  • Restrictions. You may have the right to restrict our processing of your Personal Data under certain circumstances. In particular, you can request we restrict our use of it if you contest its accuracy, if the processing of your Personal Data is determined to be unlawful, or if we no longer need your Personal Data for processing but we have retained it as permitted by law.
  • Portability. To the extent the Personal Data you provide us is processed based on your consent and that we process it through automated means, you may have the right to request that we provide you a copy of, or access to, all or part of such Personal Data in structured, commonly used and machine-readable format. You also have the right to request that we transmit this Personal Data to another controller, when technically feasible.
  • Withdrawal of Consent. To the extent that our processing of your Personal Data is based on your consent, you may withdraw your consent at any time by contacting us through email at [email protected]. You may also withdraw your consent to send you legal updates by clicking the unsubscribe link at the bottom of a legal update that you receive from us. Note that unsubscribing from one of our newsletters in this way only unsubscribes you from that newsletter; you may need to unsubscribe from additional newsletters separately. Withdrawing your consent will not, however, affect the lawfulness of the processing based on your consent before its withdrawal, and will not affect the lawfulness of our continued processing that is based on any other lawful basis for processing your Personal Data.
  • Right to be Forgotten. You may have the right to request that we delete all of your Personal Data. We will only delete your Personal Data when we no longer have a lawful basis for processing your Personal Data or after a final determination that your Personal Data was unlawfully processed. We may not accommodate a request to erase information if we believe the deletion would violate any law or legal requirement or cause the information to be incorrect. In all other cases, we will retain your Personal Data as set forth in this policy. In addition, we cannot completely delete your Personal Data as some data may rest in previous backups. These will be retained for the periods set forth in our disaster recovery policies.
  • Complaints. You may have the right to lodge a complaint with the applicable supervisory authority in the country you live in, the country you work in, or the country where you believe your rights under applicable data protection laws have been violated. However, before doing so, we request that you contact us directly in order to give us an opportunity to work directly with you to resolve any concerns about your privacy.

How You May Exercise Your Rights. You may exercise any of the above rights (when applicable) by contacting us through any of the methods listed under Contact Information below. If you contact us to exercise any of the foregoing rights, we may ask you for additional information to verify your identity. We reserve the right to limit or deny your request if you have failed to provide sufficient information to verify your identity or to satisfy our legal and business requirements. Please note that if you make unfounded, repetitive, or excessive requests (as determined in our reasonable discretion) to access your Personal Data, you may be charged a fee subject to a maximum set by applicable law.

Consent to Processing of Personal Data in the United States

We may process your Personal Data outside of your home country, including to the United States. We only do this when we are legally permitted to do so and when we have appropriate safeguards in place to protect your Personal Data.

If you are a resident of the European Economic Area (“EEA”), in order to provide our Site and legal updates to you, we may send and store your Personal Data outside of the EEA, including to the United States. Accordingly, your Personal Data may be transferred outside the country where you reside or are located, including to countries that may not or do not provide an equivalent level of protection for your Personal Data. Your information may be processed and stored in the United States and United States federal, state, and local governments, courts, or law enforcement or regulatory agencies may be able to obtain disclosure of your information through the laws of the United States. By using our Site, you represent that you have read and understood the above and hereby consent to the storage and processing of your Personal Data outside the country where you reside or are located, including in the United States.

Your Personal Data is transferred by us to another country only if it is required or permitted under applicable data protection law and provided that there are appropriate safeguards in place to protect your Personal Data. The European Commission has determined that the transfer of Personal Data pursuant to the Standard Contractual Clauses may provide for an adequate level of protection of your Personal Data. Under these Standard Contractual Clauses, you have the same rights as if your data was not transferred to such third party.

Children

We do not use or disclose the personal information of consumers we actually know are less than 16 years old, unless we receive affirmative authorization (the “right to opt-in”) from either the consumer who is between 13 and 15 years old, or the parent or guardian of a consumer less than 13 years old.

Data Retention Periods

We may retain your Personal Data. We will retain your Personal Data for as long as you have an account or profile with us. In some instances, we may keep it after you no longer have an account or profile with us, for example we may keep it:

  • on our backup and disaster recovery systems;
  • for as long as necessary to protect our legal interests; and
  • and to comply with other legal requirements.
  • for data that has been aggregated or otherwise rendered anonymous in such a manner that you are no longer identifiable, indefinitely.

Changes to this GDPR Privacy Addendum

We reserve the right to amend this GDPR Privacy Addendum at our discretion and at any time and at any time and as described in our Privacy Policy. When we make changes to this GDPR Privacy Addendum, we will post the updated notice on the Site and update the notice’s effective date. Your continued use of our Site following the posting of changes constitutes your acceptance of such changes.