
APERIO CI, INC.
POLICY ON DATA PROTECTION AND PRIVACY
OF PERSONAL INFORMATION
Aperio CI, Inc. (“Aperio”) transacts
business with companies here in the United States and internationally,
including countries that are part of the European Union (“EU”). We currently do not have employees and agents
who reside outside of the United States.
Our policy concerning the privacy of individuals’ personal identifiable
information is treated consistently with the same high level of security
regardless of whether the information emanated from within or without the
United States.
It is Aperio
CI’s policy to comply with all applicable regulatory requirements for the
processing of personal and sensitive data, including the EU Data Protection
Directive, the U.S. Commerce Department Safe Harbor framework, the U.K. Data
Protection Act of 1998, as each may be amended and supplemented.
Aperio CI
currently is subject to and will enter into a written contract with a EU Member, prior to processing any such data. The contract will contain terms and
provisions regarding each respective party’s rights and obligations as it
relates to the processing of data. This
will ensure that the EU data controller will be in compliance with the Member
State Data Protection law. Any data
processed by Aperio CI will not be disclosed to third parties, except where
permitted or required by the contract between the EU Member and Aperio CI. Any information, which an Aperio CI customer
(acting as the EU controller) identifies as sensitive information will be
treated accordingly.
Aperio CI has
in place and will provide as such in a Master Agreement with an EU Member that
Aperio CI has adequate data security measures to protect personal information
from loss, misuse, unauthorized access, disclosure, alteration and destruction.
For purposes
of this Policy, the following definitions shall apply:
“Agent”
means any third party that may use Personal information provided by Aperio CI
to perform tasks on behalf of or at the instruction of Aperio CI.
“Personal
Information” means any information or set of information that identifies or
could be used by or on behalf of Aperio CI to identify an individual. Personal information does not include
information that is encoded or anonym zed, or publicly available information
that has been combined with nonpublic Personal information.
“Sensitive
Personal Information” means Personal information that reveals race, ethnic
origin, trade union membership, or that concerns health. In addition, Aperio CI will treat as
sensitive Personal Information any information received from a third party
where that third party treats and identifies the information as sensitive.
2. to be used for a purpose other than the
purpose for which it was originally collected or subsequently authorized by the
individual.
For
Sensitive Personal Information, Aperio CI will give individuals the opportunity
to affirmatively and explicitly (opt-in) consent to the disclosure of the
information to a non-agent third party or the use of the information for a
purpose other than the purpose for which it was originally collected or
subsequently authorized by the individual.
Aperio
CI will provide individuals with reasonable mechanisms to exercise their
choices should requisite circumstances arise.
E.
“Enforcement.” Aperio CI will conduct compliance audits of
its relevant privacy practices to verify adherence to this Policy. Any employee that Aperio CI determines is in
violation of this policy will be subject to disciplinary action up to and
including termination of employment.
VI.
Dispute
Resolution. Any questions or concerns regarding the use
or disclosure of personal information should be directed to the Aperio CI
Privacy Officer at the address given below.
Aperio CI will investigate and attempt to resolve complaints and
disputes regarding use and disclosure of personal information in accordance
with the principles contained in this Policy.
For complaints that cannot be resolved between Aperio CI and the
complainant, Aperio CI has agreed to participate in the dispute resolution
procedures of the panel established by the European data protection authorities
to resolve disputes pursuant to the Safe Harbor Principles.
VII.
Contact
Information. Questions or comments regarding this Policy
should be submitted to the Aperio CI Privacy Officer by mail or e-mail as
follows:
Aperio CI,
Inc.’s Privacy Officer
Aperio CI,
Inc.
25 Howard
Place
Ronkonkoma,
New York 11779
The preceding
paragraphs describe Aperio CI’s personal data protection policy as of Friday,
February 12, 2010.
Aperio CI retains the right to modify or amend this Policy at any time
consistent with the requirements of the Safe Harbor Principles.