Last updated: October 2019
We refer to the above website and all related websites as “sites” and to each of them as a “site.” The terms “we,” “us,” and “our” refer to HepQuant and all associated companies and subsidiaries. When we refer to “you” or “your,” we mean the person accessing the site. If the person accessing the site does so on behalf of, or for the purpose of, another person, including a business or other organization, “you” or “your” also means the other person, including a business organization.
- GENERAL DISCLOSURE
- COLLECTION AND USE OF INFORMATION ON THE SITES
- WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION
- GROUNDS TO PROCESS YOUR INFORMATION
- COOKIES POLICY
- WHAT ARE COOKIES AND WHY WE USE THEM?
- OPT-OUT OPTIONS
- SUPPLEMENTAL MARKETING DATA
- THIRD PARTY LINKS
- SOCIAL MEDIA
- LEGAL DISCLOSURE OF INFORMATION
- RESPONSE TO “DO NOT TRACK” SIGNALS
- CHILD ONLINE PRIVACY PROTECTION ACT (COPPA) COMPLIANCE AND RELATED INFORMATION
- RETENTION OF PERSONAL INFORMATION
- ACCESS TO YOUR PERSONAL INFORMATION
- OPT-OUT AND UNSUBSCRIBE
- RESPONSE TIMES
- IDENTIFYING YOU IN CONNECTION WITH REQUESTS
- CONTACT US
- TABLE OF COOKIES
We take your privacy and the protection of your personal data seriously. We will only store, process and disclose your personal data where we have practical business interest and in accordance with the law. We will make it clear when we collect personal information and will explain what we intend to do with it. We do our best to protect your privacy through the appropriate use of information security measures.
COLLECTION AND USE OF INFORMATION ON THE SITE
We collect different personal information from or about you depending on the manner in which you use our site, including but not limited to collecting personal information from correspondence, faxes, e-mails, telephone inquiries, web forms, and other means of communication. We (and our affiliates and authorized service providers) may collect, store, transfer and use:
- information about your visits to, and use of, this site;
- information about any transactions carried out on-site or in-person between you and us on or in relation to the sites, including information relating to any purchases you make of our Services;
- any information you provide to us if you correspond with us;
- if you create or attempt to create a business relationship with us, we may ask you for your name, geo-location and other demographic information, e-mail address, street address, zip code or other personal information. You may, however, visit the sites without providing that information.
In addition to the digital collection of information through this site, HepQuant collects certain other personal and medical information through telephone conversations and in-person meetings with our prospective customers. This information may include full name, contact information, and medical issues, motivations for seeking out HepQuant, and marketing campaign sources. This information is captured and housed in the following systems:
- our Customer Relationship Management software;
- our email distribution database
- our in-office computers and mobile devices;
- intra-company information-sharing systems such as texting, email and smart wearable devices
- certain secure cloud-based applications
We use this information to provide, improve and develop our Services, as well as to communicate with you about our Services and to market our services to you. If we send you marketing emails, each email will contain instructions permitting you to “opt out” of receiving future marketing or other communications.
We may also use your information for other purposes disclosed to you in connection with our Services from time to time.
When and With Whom Do We Share Your Information
We may share your information with trusted third parties who assist us in operating our sites and in conducting our business and business relationship with you. Third parties include, as examples, organizations that perform outsourcing and other services for us such as marketing and advertising, live chat messaging, payment processors, social media websites, order fulfillment organizations, shipping companies, warranty and other service organizations, data storage organizations and systems development and maintenance organizations.
These third-party service providers may access your personal information and may only use it as directed by us for the purpose of our requested service. We require all third parties to respect the security of your personal data. We do not allow our third party service providers to use your personal information for their own purposes, and they are only permitted to process your personal information in accordance with our instructions.
We do not allow third parties to collect personally identifiable data about your online or mobile activities over time and across different websites or mobile devices when you use the sites. We also will not sell your personal information.
We use servers and data storage from providers such as NexusTek (Denver, CO & Phoenix, AZ), our website server host WP Engine (The Dalles, Oregon), GoDaddy (U.S. and global servers), Salesforce (9 managed data centers through U.S. and international), Facebook and Google Drive.
As stated above, we use Google Analytics to help understand your usage of our sites and to improve our Services. We may disclose or use aggregated or de-identified information for any purpose. Aggregated Data may be derived from your personal information but does not directly or indirectly reveal your identity.
Grounds to Process Your Information
We rely on the following legal grounds to process your personal information, namely:
- Performance of a contract – We may need to collect and use your personal information to enter into a contract or to perform a contract that you or your company has with us.
- Consent – Where required by applicable law, we will rely on your consent for collecting your personal information.
Our sites use first and third-party cookies for technical, analytical and advertising purposes. “First-party cookies” refer to cookies that are set by our sites, and we are the only ones with access to this information. On the other hand, “third-party cookies” or requests allow certain other third parties to have access to the information collected. Not all cookies are necessary to navigate the sites. Cookies used for analytical and advertising purposes, such as site analytics and advertising cookies (non-essential cookies) are not necessary to navigate our sites. You have the choice not to accept or to delete them anytime, and carry on browsing normally.
What are cookies and why we use them?
Cookies are files that are downloaded on your computer or mobile device when you visit certain websites. Cookies allow us to track your browsing behavior, links clicked, items downloaded, your device type, and to collect various data, including analytics, about how you use and interact with our sites. This allows us to provide you with a better experience on our sites and more relevant product information. Cookies allow us to collect, analyze and improve the performance of our communications. We may also collect your location (IP address) so that we can personalize our interest-based online advertising. We believe that these interest-based ads provide you with more relevant and more interesting ads. However, you may choose to opt out of such targeted advertising from HepQuant at any time through the methods provided below. We comply with the Self-Regulatory Principles for Online Behavioral Advertising set forth by the Digital Advertising Alliance.
- Network Advertising Initiative (NAI) – http://www.networkadvertising.org/
- Digital Advertising Alliance (DAA) – http://www.aboutads.info/choices/
- Digital Advertising Alliance Canada (DAAC) – http://youradchoices.ca/choices
- Digital Advertising Alliance EU (EDAA) – http://www.youronlinechoices.com/
- DAA AppChoices page – http://www.aboutads.info/appchoices
You can also restrict or block cookies that are set by the Services (or any other site on the Internet) by adjusting the settings in your browser. Please be aware that restricting cookies may impact the functionality of the Services. Most browsers allow you to refuse to accept cookies. Additional general information about cookies, including how to be notified about the placement of new cookies and how to disable cookies, can be found at www.allaboutcookies.org.
Supplemental Marketing Data
Supplemental data may be received about you from other sources, including publicly available databases or third parties from whom we have purchased data, in which case we may combine this data with information we already have about you so that we can update, expand and analyze the accuracy of our records, identify new customers, and provide information and products that may be of interest to you. If you provide us personal information about others, or if others give us your information, we will only use that information for the specific reason for which it was provided to us. To opt out of any database information about you that we may possess, please send notification to [email protected].
Third Party Links
For instance, information collected through Google Analytics is shared with Google and its partners who may combine it with other information you’ve provided to them or they’ve collected from your use of their services. This information may be stored in Google’s servers in the United States of America according to its privacy practices.
We may collect information from other sources, such as social media platforms that may share information about how you interact with our social media content. We do not control how your personal information is collected, stored or used by such third-party websites or to whom it is disclosed. You should review the privacy policies and settings on any social networking website that you subscribe to so that you understand the information they may be collecting and sharing. If you do not want your networking websites to share information about you, you must contact those websites and determine whether they give you the opportunity to opt-out of sharing such information. We are not responsible for how these third party websites may use information collected from or about you.
HepQuant employs security measures utilizing industry-standard technology to protect the loss, misuse or alteration of personal information that you disclose through the sites. Personal information is stored in a secured database and sent via an encrypted Internet channel. Nevertheless, no online or computer environment is 100% secure, and we cannot guarantee absolute security of the transmission or storage of your information. We hold information about you both at our own premises and with the assistance of third party service providers. Further public disclosure here of our security measures could aid those who might attempt to circumvent those security measures. If you have additional questions regarding security, please feel free to contact us directly at [email protected].
Legal Disclosure of Information
HepQuant may disclose personal information when we have reason to believe that disclosing this information is necessary to identify, contact or bring legal action against someone who may be violating any agreement with HepQuant, or may be causing injury to or interference with (either intentionally or unintentionally) our rights or property, other users of the sites, or anyone else that could be harmed by such activities. We may disclose information in response to a subpoena, search warrant, in connection with judicial proceedings, or pursuant to court orders, legal process or other law enforcement measures. HepQuant may disclose or access personal information when we believe in good faith that the law requires it, to establish our legal rights or to defend against legal claims, and for administrative and other purposes that we deem necessary to maintain, service and improve our products and services.
Response to “Do Not Track” Signals
Some Internet browsers include the ability to transmit “Do Not Track” signals. Since uniform standards for “Do Not Track” signals have not yet been adopted, HepQuant does not process or respond to “Do Not Track” signals.
Child Online Privacy Protection Act (COPPA) Compliance and Related Information
The Child Online Privacy and Protection Act (COPPA) regulates online collection of information from persons under the age of 13. It is our policy to refrain from knowingly collecting or maintaining personally identifiable information relating to any person under the age of 18. If you are under the age of 18, please do not supply any personally identifiable information through the sites. If you are under the age of 18 and have already provided personally identifiable information through the sites, please have your parent or guardian contact us immediately at [email protected] so that we can remove such information from our files.
We only collect the personal information necessary to fulfill the purposes identified to you prior to or at the time of collection, or any other reasonable and legitimate purposes or as required by law. We do not use or disclose your personal information, except for the purposes for which it was collected, or new purposes to which you have consented, or as required or otherwise permitted by applicable law. We do not, as a condition of providing services to you or on your behalf, or as an administrative or management requirement, require consent to the collection, use or disclosure of personal information beyond that reasonably required for such purposes, or to comply with its obligations under applicable law.
Retention of Personal Information
We may keep a record of your personal information, including correspondence or comments, in the applicable file specific to you. We will utilize, disclose, or retain your personal information for as long as necessary to fulfill the purposes for which it was collected and for legal or business requirements. We will establish minimum and maximum retention periods and procedures for maintaining and destroying your personal information. When personal information is retained to make a decision about you, we will retain such information for the period required in order to comply with our internal compliance and data retention policies.
In some circumstances we may anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you. This allows the specific information collected (name, email, address, phone number, etc.) to become anonymous, but allows HepQuant to keep the transaction or engagement data. For example, HepQuant will not be able to tell if “John Smith” registered for an event, but we will be able to tell that a person registered for an event and maintain headcount and transactional history. This will allow HepQuant to maintain a level of information that helps us develop and improve our sites and Services.
CALIFORNIA PRIVACY RIGHTS
California law permits residents of California to request certain details about our disclosure of your personal information by us to third parties for direct marketing purposes during the immediate preceding calendar year. If you are a California resident and would like to request this information, please contact us using the information provided under Contact Us.
Access to Your Personal Information
Subject to the exceptions provided by the applicable law, we will make available to you any specific personal information about you that we have collected, utilized or disclosed, upon your written request. We will make such information available to you in a form that is generally understandable, including explaining any abbreviations or codes and using an alternative format, if required. Simply send your request for access to the HepQuant Privacy Director by sending an e-mail to [email protected] or call us at +1 303.923.2242. Please be as specific as possible in your request so that we can meet the applicable timelines.
Opt-Out and Unsubscribe / Email & Telephone Communications
Email Delivery Policy: In compliance with the United States CAN-SPAM Act of 2003, we send only to email lists composed of recipients who have opted in to such communication and/or considered transactional relationship based on an existing business relationship. All emails that are sent whether the format be Text or HTML include an Unsubscribe/Opt-Out link. Any email recipient may elect at any time to Unsubscribe/Opt-Out via this link. Users may also opt-out of receiving any or all communications from HepQuant, including telephone and text messaging outreach by contacting us at [email protected].
We will make every reasonable effort to respond to each of your written requests not later than 30 days after receipt of such requests. When applicable, we will advise you in writing if we cannot meet your requests within this time limit. When applicable, you have the right to make a complaint to the appropriate privacy commission with respect to this time limit.
We expect to provide access without charge as a general matter. However, we reserve the right to collect a reasonable charge when you request the transcription, reproduction, or transmission of such information. We will notify you, following your request for transcription, reproduction, or transmission, of the appropriate amount that will be charged. You will then have the opportunity to withdraw your request.
Identifying You in Connection with Requests
We may require that you provide to us sufficient information to identify yourself before we provide information about the existence, use, or disclosure of your personal information in our possession. Any such information shall be used only for this purpose.
The Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) and the European Union General Data Protection Regulation (“GDPR”) impose requirements regarding the collection, use, and disclosure of personal data in relation to our commercial activities, as does private-sector privacy legislation in their local jurisdictions, provinces and territories.
THIS INTERNATIONAL POLICY APPLIES TO ALL PERSONAL DATA ABOUT YOU THAT WE COLLECT, HOLD, USE AND DISCLOSE, REGARDLESS OF THE WAY IN WHICH WE COLLECT IT (I.E. WHETHER THROUGH A SITE OR OTHERWISE).
In this International Policy, personal data is as defined by applicable European Union and Canadian law. It generally means any information about an identifiable individual. It may include your name, age, mailing address, residential phone number, or e-mail address, personal history (including financial and credit information, donations, personal health information, billing history, personal family and relationship matters, and penal or criminal information), personal information related to corporate involvements, work experience (past and present), discipline, income and benefits, medical records, tax records and security clearances.
Collection of Personal Data
We collect personal data from the web site, as well as through correspondence, faxes, live chats, e-mails, telephone inquiries, web forms, and other means of communication. We collect such information when we provide publication services, digital services and other lawful services.
We (and our affiliates and authorized service providers) may collect, store and use the information discussed above in COLLECTION AND USE OF INFORMATION ON THE SITES.
We also may collect information about your computer and your visits to the sites such as your IP address, geographical location, browser type, domain names, referring website addresses, access times, length of visit and number of page views. We may use this information in the administration of the sites, to improve the usability of the sites, to provide better service, to send you newsletters, updates, marketing communications, and other information or that may be of interest to you. We also use outside services such Google Analytics to gather data about visitors to our sites. We may sometimes permit our authorized service providers to have access to aggregate statistics about our customers, sales, traffic patterns, usage and related information.
We often collect personal data from you or from third parties and as agents on behalf of third parties, where we have obtained the requisite consent to do so or as otherwise permitted by law. Third parties include, as examples, organizations for whom we provide services to you or on your behalf, and organizations that perform outsourcing and other services for us (such as payment processors, order fulfillment organizations, shipping companies, warranty and other service organizations, and systems development and maintenance organizations).
Where we are the Data Controller with regard to that data you may exercise your rights as data subject, including the right to object to the processing of your personal data when it is processed based on legitimate interests as provided in this International Policy below.
How We Use Personal Data
As a general matter, we collect your personal data primarily to provide Services to our customers, for administrative or management requirements and to enhance our relationships with our customers.
HepQuant collects and uses your personal data to operate its sites and deliver the Services you have requested.
HepQuant may also use your personal data to inform you of other products or services available from HepQuant and its affiliates. HepQuant may also contact you via surveys to conduct research about your opinion of current services or of potential new services that may be offered.
HepQuant does not sell, rent or lease its customer lists to third-parties.
HepQuant may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest to you. In those cases, your personal data (e-mail, name, address, telephone number) is not transferred to the third-party. HepQuant may share data with trusted partners to help perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. All such third parties are prohibited from using your personal data except to provide services to you, and they are required to maintain the confidentiality of your data.
HepQuant may keep track of the websites and pages our users visit within HepQuant in order to determine what Services are the most popular. This data is used to deliver customized content and advertising within HepQuant to customers whose behavior indicates that they are interested in a particular subject area.
HepQuant will disclose your personal data only if required to do so by law or in the good faith belief that such action is necessary to: (a) conform to the edicts of the law or comply with legal process served on HepQuant or the site; (b) protect and defend the rights or property of HepQuant; and/or (c) act under exigent circumstances to protect the personal safety of users of HepQuant, or the public.
The Basis On Which We Process Your Personal Data
We rely on the following legal grounds to process your personal data, namely:
- Performance of a contract – We may need to collect and use your personal data to enter a contract or to perform a contract that you or your company has with us.
- Consent – Where required by applicable laws, we will rely on your consent for collecting your personal data.
We will only process personal data for a specific purpose or for any other purposes specifically permitted by applicable data protection legislation.
Except when otherwise permitted by law, we obtain the requisite consent prior to collecting and, in any case, prior to using or disclosing your personal data for any purpose. You may provide your consent to us orally, in writing, by electronic communication or any other means reasonably capable of conveying your consent. We will obtain your express consent if we collect, use or disclose sensitive personal data in our capacity as a data controller. We may also share data with third-party partners for whom you have given us consent. Your consent may also be intrinsic to the circumstances such as in the case where you have already provided personal data to us and you maintain your relationship with us or where you provide our representatives with your phone number so that we can contact you. Except when otherwise permitted by law, we will only use the data for the purpose for which it was given. From time to time, we may collect, utilize or disclose your personal data based on your consent and as otherwise permitted by law.
When your consent is required, you may withdraw your consent at any time (unless withdrawing the consent would frustrate the performance of legal obligations) upon providing to us a 30-day notice. However, the withdrawal of your consent may adversely affect our ability to provide Services to you and to maintain our relationship.
We remain responsible for all personal data communicated to third parties for processing. As such, we ensure that third parties that are engaged to provide products or services on our behalf and are provided with personal data are required to observe the intent of this International Policy by having comparable levels of security protection or, when required, by assuring us (such as, through a confidentiality agreement) that they will not use or disclosure the personal data for any purpose other than the purpose for which the personal data was communicated.
We only collect the personal data necessary to fulfill the purposes identified to you prior to or at the time of collection, or any other reasonable and legitimate purposes, or as required by law.
We do not use or disclose your personal data, except for the purposes for which it was collected, or new purposes to which you have consented, or as required or otherwise permitted by applicable law.
We do not, as a condition of providing services to you or on your behalf, or as an administrative or management requirement, require consent to the collection, use or disclosure of personal data beyond what is reasonably required for such purposes, or to comply with our obligations under applicable law.
Retention Of Personal Data
We may keep a record of your personal data, including correspondence or comments, in a file specific to you. We will utilize, disclose, or retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and for legal or business requirements. We have established minimum and maximum retention periods and procedures for maintaining and destroying your personal data. When personal data is retained to make a decision about you, we will retain such information for the period required in order to comply with our internal data retention policies.
Access And Rights To Your Personal Data
Subject to the exceptions provided by the applicable law, we will make available to you any of your personal data that we have collected, utilized or disclosed, upon your written request. We will make such information available to you in a form that is generally understandable, including explaining any abbreviations or codes and using an alternative format, if required. If you are a located in the European Economic Area (“EEA”), the GDPR provides you rights of access, rectification, erasure, restriction, objection or portability in line with the type of services being provided. Simply send your request, using the Request Form provided, to the Privacy Officer listed below. Please be as specific as possible in your request so that we can meet the applicable time lines. REQUEST FORM
If you are a located in the EEA you also have the right to lodge a complaint to your Supervisory Authority.
We will make every reasonable effort to respond to each of your written requests not later than 30 days after receipt of such requests. When applicable, we will advise you in writing if we cannot meet your requests within this time limit. When applicable, you have the right to make a complaint to the appropriate supervisory authority with respect to this time limit.
We expect to be able to respond to your request without charge as a general matter. However, we reserve the right to collect a reasonable charge when you request the transcription, reproduction or transmission of such information. We will notify you, following your request for transcription, reproduction or transmission of the appropriate amount that will be charged. You will then have the opportunity to withdraw your request.
Identifying You In Connection With Requests
We may require that you provide to us sufficient information to identify yourself before we provide information about the existence, use or disclosure of your personal data in our possession. Any such information shall be used only for this purpose.
Opt-Out And Unsubscribe
We respect your privacy and give you an opportunity to opt-out of receiving certain information. Users may opt-out of using the instructions located in e-mails sent by HepQuant or by contacting us at EMAIL.
We will use reasonable efforts to ensure that your personal data is kept as accurate, complete and up-to-date as possible. We will not routinely update your personal data, unless necessary. In order to help us maintain and ensure that your personal data is accurate and up to date, you must inform us, without delay, of any change in the data you provided to us.
You can at any time, challenge the accuracy or completeness of the personal data we have about you, subject to the exceptions provided by applicable law. If you demonstrate that the personal data we have on you is inaccurate or incomplete, we will amend the personal data as required. Where appropriate, we will transmit the amended data to third parties to whom we have communicated your personal data.
We use security safeguards appropriate to the sensitivity of personal data to protect it from loss or theft, as well as unauthorized access, disclosure, copying, use or modification. These safeguards include physical measures, such as restricted access to offices and equipment, organizational measures, such as security clearances and publishing this policy to appropriate personnel with instructions to act in accordance with its principles (for example, limiting access on a “need to know” basis), and technological measures, such as the use of passwords and/or encryption.
Please direct all complaints or other inquiries regarding personal information, the General Policy, or the International Policy to our Privacy Manager pursuant to the above CONTACT US section.