Privacy Notice for Covered Residents
This Privacy Notice for Covered Residents (the “Notice”) supplements the information contained in our Privacy Policy and applies only if you reside in the Commonwealth of Virginia, or the States of Colorado, Utah, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, or New Jersey (collectively, the “Covered States”) (a resident of any Covered States, a “Covered Consumer”). The Notice applies equally to Covered Consumers unless noted otherwise.
For purposes of this Notice “Sell,” “Selling,” “Sale,” or “Sold,” means the exchange of Personal Information for monetary or other valuable consideration by Zep to a third party. “Sell,” “Selling,” “Sale,” or “Sold,” does not include the following:
· Disclosure of Personal Information to a third party that processes data on behalf of Zep;
· Disclosure of Personal Information to a third party for purposes of providing a product or service requested by you;
· Disclosure or transfer of Personal Information to an affiliate of Zep;
· Disclosure or transfer of Personal Information to a third party as an asset that is part of a proposed or actual merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of Zep’s assets; and
· Disclosure of Personal Information that is intentionally made available by you to the general public via a channel of mass media without restricting the Personal Information to a specific audience.
“Sensitive Data Inferences” means inferences made based on Personal Data, alone or in combination with other data, which are used to indicate an individual’s racial or ethnic origin; religious beliefs; mental or physical health condition or diagnosis; sex life or sexual orientation; or citizenship or citizenship status.
“Sensitive Personal Information” means any of the following: (1) Personal Information revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship or citizenship status; (2) genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; (3) Personal Information from a person known to be under 13 years of age; (4) if you are a Virginia, Utah, Connecticut, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, or New Jersey Consumer, precise geolocation data; (5) if you are a Delaware, Oregon, or New Jersey Consumer, the definition also includes Personal Information revealing status as transgender or nonbinary; (6) if you are a Delaware, New Jersey or Oregon Consumer, the definition also includes Personal Information revealing status as transgender or nonbinary; (8) if you are an Oregon Consumer, the definition also includes Personal Information revealing status as a victim of crime; (9) if you are a Colorado Consumer, the definition also includes Sensitive Data Inferences; and (10) if you are a New Jersey Consumer, Sensitive Personal Information also includes financial information, which includes your account numbers, account log-in, financial accounts, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to those accounts.
“Verifiable Request” means the identifying information provided by a consumer in connection with a request matches the Personal Information of the consumer already maintained by us or a third party identity verification service. Identifying information you can submit in order to permit Zep to verify your request may include your first and last name, the email address and phone number that is associated with your account, and a secure confirmation code that we provide to you via email.
“Targeted Advertising” means displaying to a consumer an advertisement that is selected based on Personal Information obtained or inferred over time from the consumer’s activities across nonaffiliated websites, applications, or online services to predict consumer preferences or interests. “Targeted Advertising” does not include the following:
· Advertising to a consumer in response to a consumer request;
· Advertisements based on activities within our own websites or online applications;
· Advertisements based on the context of a consumer’s current search query, visit to a website, or online application; or
· Processing Personal Information solely for measuring or reporting advertising performance, reach, or frequency.
“Profiling” means any form of automated processing of Personal Information to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Relevant Data Privacy Law” means the specific data privacy law of the state of which a consumer is a resident: the Virginia Consumer Data Protection Act (“VCDPA”) for a Virginia Consumer, the Colorado Privacy Act (“CPA”) and Colorado Privacy Act Rules for a Colorado Consumer, and the Connecticut Data Privacy Act (“CTDPA”) for a Connecticut Consumer, the Utah Consumer Privacy Act (“UCPA”) for a Utah Consumer, the Oregon Consumer Privacy Act (“OCPA”) for an Oregon Consumer, the Texas Data Privacy and Security Act (“TDPSA”) for a Texas Consumer, the Montana Consumer Data Privacy Act (“MCDPA”) for a Montana Consumer, the Delaware Personal Data Privacy Act (“DPDPA”) for a Delaware Consumer, the Iowa Consumer Data Protection Act (“ICDPA”) for an Iowa Consumer, the Nebraska Data Privacy Act (“NDPA”) for a Nebraska Consumer, the New Hampshire Senate Bill 255 (“NHSB”) for a New Hampshire Consumer, and the New Jersey Senate Bill 332 (“NJSB”) for a New Jersey Consumer.
1. Information We Collect or Process
Zep has collected or processed the following categories of Personal Information from Covered Consumers:
· Identifiers (names, personal or business addresses, email addresses, and IP addresses).
· Other information which is not required to use our Services but that you choose to provide to us through an online form.
Zep obtains this Personal Information from the following types of sources:
· Directly from you. For example, from forms you complete or products and services that you purchase.
· Indirectly from you. For example, from information automatically sent by your web browser or from analyzing data about your actions on our website.
2. Use of Personal Information
Zep may use or disclose the Personal Information we collect for one or more of the following “Business Purpose(s):”
· To fulfill or meet the reason you provided the information
· To provide our website or online services
· To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations
· To respond to your requests under the Relevant Data Privacy Law;
· For any other purpose described to you when we collect your Personal Information; and
· For any other acceptable purposes as set forth in the Relevant Data Privacy Law.
Unless we notify you otherwise, we will not collect additional categories of Personal Information, nor use the Personal Information we collect for any other materially different, unrelated, or incompatible purposes.
3. Disclosures of Personal Information
Zep has disclosed your Personal Information as described in this Notice, including the following categories of Personal Information:
Zep discloses Personal Information to third parties for a Business Purpose. When we disclose Personal Information for a Business Purpose, we enter into an agreement with the receiving party that describes the purpose for sharing the Personal Information, and that requires the receiving party to keep that Personal Information confidential.
We may disclose your Personal Information with the following categories of third parties: our Service Providers and Affiliates.
We process Personal Information for the purpose of Targeted Advertising, subject to your right to opt-out of such processing.
4. Your Rights and Choices
If you are a Covered Consumer, you may request information about our collection and processing of your Personal Information, whether or not it was collected electronically. If you submit a Verifiable Request, we will disclose whether we have collected or processed your Personal Information and allow you to access the Personal Information we have collected, to the extent we continue to retain the Personal Information. To the extent technically feasible, we will disclose this information to you in a readily usable format that allows you to transmit the data to another entity without hindrance. In the case of individuals located in Colorado, Connecticut, Utah, Oregon, Montana, Delaware, New Hampshire, or New Jersey in the event that you make more than (1) request in any twelve (12) month period, we reserve the right to charge a fee prior to processing any such request(s). In the case of individuals located in Texas, Iowa, or Nebraska in the event that you make more than (2) requests in any twelve (12) month period, we reserve the right to charge a fee prior to processing any such request(s).
You also have the right to request that we delete any of your Personal Information that we collect or maintain by submitting a Verifiable Request. We may deny your deletion request if retaining your Personal Information is necessary for us or our Service Providers to:
· Complete the transaction for which we collected your Personal Information, provide goods or services that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you;
· Prevent or detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or investigate, report, or prosecute those responsible for such activity;
· Debug products to identify and repair errors that impair existing intended functionality;
· Engage in public or peer-reviewed scientific or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the achievement of such research, if you previously provided informed consent;
· Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us;
· Cooperate with law enforcement agencies concerning conduct or activities that we reasonably and in good faith believe may violate the law;
· Comply with a legal obligation; or
· Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
If you are a Virginia, Colorado, Connecticut, Oregon, Texas, Montana, Delaware, Nebraska, New Hampshire, or New Jersey Consumer, you may request that we correct any of your Personal Information that is inaccurate by submitting a Verifiable Request. We will correct any inaccurate Personal Information pursuant to your request, taking into account the nature of the Personal Information and the purposes of the processing of your Personal Information. We may deny your correction request if the Personal Information is accurate.
If you choose to exercise a privacy right under the Relevant Data Privacy Law, you have the right not to receive unlawful discriminatory treatment.
You may submit a Verifiable Request for the information listed above, or exercise any of your rights enumerated under this Notice, by calling us at 1-800-232-9267 or by completing a form on our website here. You may also submit a Verifiable Request on behalf of your minor child. Additionally, you can submit a request on someone else’s behalf here. In order to submit a request on someone else’s behalf, you must provide a copy of the written authorization signed by the consumer on whose behalf you are submitting the request, or other applicable documentation evidencing your authority to file such a request, such as a power of attorney.
After we receive your Verifiable Request, we will provide to you, in writing, the requested information. You can choose to have this information delivered to you by postal mail or electronically. We will try to respond to your verified request within forty-five (45) days of receipt, but if we require more time (up to another forty-five (45) days) we will inform you of the reason and extension period in writing. If we decline to act on your request for any reason permitted under the Relevant Data Privacy Law, we will notify you of our decision within forty-five (45) day of receiving your request. If applicable, our response will explain the reasons why we cannot comply with your request.
If you are a Virginia, Colorado, Connecticut, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, or New Jersey resident and we deny your request or fail to act on it within the required time period, you may have the right to appeal this decision by submitting a new Verifiable Request in which you conspicuously note that you are appealing a previous decision. If you are a Virginia, Connecticut, Texas, Montana, Delaware, Iowa, Nebraska, or New Hampshire resident, we will respond to your Verifiable Request to appeal within sixty (60) days of receipt. If you are an Oregon or New Jersey resident, we will respond to your Verifiable Request to appeal within forty-five (45) days. If you are a Colorado Consumer, we will try to respond to your Verifiable Request to appeal within forty-five (45) days of receipt, but if we require more time (up to another sixty (60) days) we will inform you of the reason and extension period in writing. If applicable, our response will explain the reasons why we are denying your appeal, and any further steps that may be available to you.
You have the right, at any time, to direct us to stop processing your Personal Information for Targeted Advertising. You may opt-out by submitting a Verifiable Request. Consumers who opt-in to processing of their Personal Information for Targeted Advertising to third parties may opt-out at any time.
Zep does not and will not, without first obtaining your consent, process your Personal Information for Profiling and/or Sale to third parties.
Should you choose to exercise any of the rights enumerated under this Notice we will not:
· Deny you goods or services;
· Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
· Provide you a different level or quality of goods or services; or
· Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
However, please be aware that it may be a functional necessity for our Services to have Personal Information about you in order to operate, and we may not be able to provide some or all of our Services to you if you direct us to delete your Personal Information.
5. Retention of Your Information
We retain each category of your Personal Information for no longer than is reasonably necessary for one or more of the above lawful bases for processing, subject to your right to request we delete your Personal Information. Due to the nature of the services, it is not possible to predict the length of time that we intend to retain your Personal Information. Instead, we use the following criteria to determine whether it remains reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing:
· Whether not there is a retention period required by statute or regulations;
· Pendency of any actual or threatened litigation for which we are required to preserve the information;
· Generally accepted best practices in our industry; and/or
· Pendency of applicable statutes of limitations for potential legal claims.
When we determine that it is no longer reasonably necessary to retain your Personal Information for one or more disclosed lawful bases for processing based on the above criteria, we will delete your Personal Information.