DATA PRIVACY NOTICE APPLICABLE TO THE EU, SWITZERLAND, AND THE UK
In this Data Privacy Notice (the “Privacy Notice”):
- OPEX Corporation, with offices located in New Jersey, United States of America (“OPEX Corporation”), describes how www.opex.com (the “Website”) operates and how OPEX Corporation collects, uses, and shares information, including personal data, gathered from visitors to the Website or in the course of business activities conducted by OPEX Corporation elsewhere, when OPEX Corporation acts as the controller of that data and when its processing is governed by the European Union’s (“EU’s”) General Data Protection Regulation (“GDPR”), Swiss data protection law, or the data protection laws applicable in the United Kingdom (the “UK”).
- The registered branch offices and subsidiaries of OPEX Corporation listed in Appendix A (an “OPEX Branch/Subsidiary”) describe how each of them independently collects, uses, and shares information, including personal data, gathered in the course of conducting its business when the OPEX Branch/Subsidiary acts as a controller of that data and when the OPEX Branch/Subsidiary's processing is governed by the EU’s GDPR, Swiss data protection law, or the data protection laws applicable in the UK.
This Privacy Notice may be updated periodically to reflect changes in OPEX Corporation’s or OPEX Branches/Subsidiaries’ information practices. The latest update will be indicted at the top of this Privacy Notice.
OPEX Corporation and the OPEX Branches/Subsidiaries collect information that you provide to us as well as from third parties. Furthermore, OPEX Corporation collects information from you automatically when you use the Website.
Information You Provide To Us: OPEX Corporation and the OPEX Branches/Subsidiaries collect information that you provide to us when you solicit business from us, purchase products and services offered by us, perform supply or similar contracts with us, request information from us, contact us, register with us, complete a survey, submit an email. Furthermore, OPEX Corporation collects information from you when you use the Website or services available through the Website. The information referenced above may include your personal data including, by way of example, your name, postal address, telephone number, fax number, e-mail address, subscriber/screen name, and password used to access our services.
Data Collected from Third Parties: OPEX Corporation may obtain data from third parties and, where permitted by law, append this data to other data that OPEX Corporation already maintains about you. For additional information, see COOKIES AND OTHER TRACKING TECHNOLOGIES as well as ANALYTICAL TOOLS below.
Automatically Collected Data: OPEX Corporation and its third-party service providers collect data about you automatically when you visit the Website, namely through ‘cookies,’ ‘web beacons,’ and other tracking technologies. When you access the Website, communications data (e.g., home service domain name and Internet protocol address) or utilization data (e.g., information on the beginning, end, and extent of each access, as well as information on the services that you accessed) may be generated. As permitted by applicable law, OPEX Corporation and its third-party service providers may combine this information with the personal data that OPEX Corporation collects about you. For additional information, see COOKIES AND OTHER TRACKING TECHNOLOGIES as well as ANALYTICAL TOOLS below.
INFORMATION THAT WE REQUIRE
Where the collection and processing of personal data are required by law or to perform a contract, OPEX Corporation or an OPEX Branch/Subsidiary, as applicable, will request it from you. Failure to provide such data may result in OPEX Corporation or the OPEX Branch/Subsidiary being unable to provide products or services you request or to perform a contract to which you are a party.
USING YOUR INFORMATION
The following is an overview of the purposes for which OPEX Corporation and the OPEX Branches/Subsidiaries, as applicable, use your information, including your personal data. Additional details on how OPEX Corporation and the OPEX Branches/Subsidiaries process your personal data may be provided to you in a separate notice(s) or contract(s).
All processing (i.e., use) of your personal data is justified by a "condition" (called a “legal basis”) for processing. In addition, processing of sensitive personal data (such as passwords) is always specifically justified. In the majority of cases, processing will be justified on the following legal bases:
- the processing is necessary for OPEX Corporation or the OPEX Branch/Subsidiary to perform a contract with you or take steps to enter into a contract at your request (such as when we fuffill orders or you request product information or provide your details to obtain after-sales service);
- the processing is necessary for OPEX Corporation or the OPEX Branch/Subsidiary to comply with an EU or Swiss legal obligation (such as contractor vetting, accounting and tax recordkeeping, and responding to EU. Swiss, or United Kingdom law enforcement or court orders);
- with respect to OPEX Corporation, the processing is in OPEX Corporation’s legitimate interests, and not overridden by your interests and fundamental rights, and notably OPEX Corporation's legitimate interests in using Website visitor, customer, and supplier data to conduct and develop OPEX Corporation’s business activities with such visitors, customers, suppliers, and others. For example, OPEX Corporation may rely on our legitimate interests when processing personal data to understand your business needs, to improve our products and services (such as by soliciting your comments or tracking preferences on the Website), for marketing and promotional purposes, to investigate, prevent, or take action regarding illegal activities, and/or to respond to US or other non-EU or Swiss law enforcement or court orders;
- with respect to an OPEX Branch/Subsidiary, the processing is in the legitimate interest of the OPEX Branch/Subsidiary and not overridden by your interests and fundamental rights, and notably the OPEX Branch/Subsidiary’s legitimate interests in using customer and supplier data to conduct and develop the OPEX Branch/Subsidiary’s business activities with such customers, suppliers, and others For example, the OPEX Branch/Subsidiary may rely on its legitimate interests when processing personal data to understand your business needs, to improve its products and services, for marketing and promotional purposes, to investigate, prevent, or take action regarding illegal activities, and to respond to US or other non-EU or Swiss law enforcement or court orders; or
- you have consented to the processing (such as to send you direct marketing information).
OPEX Corporation and the OPEX Branches/Subsidiaries (or a third party operating on our behalf) may use your information, including your personal data, for the following purposes, as permitted by law:
- To provide OPEX products and services to you, to communicate with you about your use of such OPEX products and services, provide you with OPEX product updates/releases and news, respond to your inquiries, fill your orders, and/or for other customer service-related purposes.
- To help OPEX Corporation and the OPEX Branches/Subsidiaries better understand your business needs; to support a potential or current customer relationship with you, and to better understand how OPEX Corporation and the OPEX Branches/Subsidiaries can improve OPEX products and services, such as by soliciting your comments or, in the case of OPEX Corporation, tracking your preferences when browsing the Website.
- To contact you about OPEX products and services and to conduct surveys to better understand your needs as a potential or current customer.
- For marketing and promotional purposes, including through email or equivalent electronic means. For example, OPEX Corporation and the OPEX Branches/Subsidiaries may use personal data such as an email address to send news and newsletters, special offers and promotions, and to otherwise contact customers about OPEX products, services, or information that we think may interest customers. OPEX Corporation and the OPEX Branches/Subsidiaries may also use personal data to assist them in advertising OPEX products and services on third-party websites where proper consent has been obtained.
- For research and development purposes, including to improve OPEX products and services.
- In the case of OPEX Corporation, to improve the Website by tracking your activities on the Website; to understand the demographics of visitors to the Website by tracking your activities on the Website, and for other research and analytical purposes.
- To comply with applicable legal obligations, including to respond to a subpoena or court order.
OPEX Corporation and the OPEX Branches/Subsidiaries may share your information, including your personal data, for any of the reasons described in USING YOUR INFORMATION above as follows:
- Affiliates and Subsidiaries. We may share the information that we collect from you with our other affiliates and subsidiaries, including affiliates and subsidiaries located outside of your home country.
- Service Providers. We may share the information that we collect from you with third-party vendors, service providers, contractors, and agents who perform functions on our behalf. For example, we may use third parties to conduct surveys on our behalf, to perform information technology and other technical support functions, and for other purposes consistent with the purposes for which you have provided information to us.
We may also share your information in the following circumstances:
- Business Transfers. If OPEX Corporation or an OPEX Branch/Subsidiary is acquired by or merged with another company, if all or substantially all of the assets of OPEX Corporation or an OPEX Branch/Subsidiary are transferred to another company, or as part of preparation for such a transaction or as part of a bankruptcy proceeding, OPEX Corporation or the OPEX Branch/Subsidiary, as applicable, may transfer in whole or in part the information we have collected from you to such other company.
- In Response to Legal Process. We may also share the information that we collect from you to comply with the law, a judicial proceeding, court order, or another legal process, such as in response to a court order or a subpoena.
- Aggregate and De-Identified Information. We may share aggregate or de-identified information with third parties for marketing, advertising, research, or similar purposes, including to assist us in determining relevant advertising platforms as well as to determine the success of our various campaigns.
COOKIES AND OTHER TRACKING TECHNOLOGIES
When you view the Website, OPEX Corporation and its service providers may store some data on your device in the form of a ‘cookie,’ ‘web beacon,’ or other tracking technologies (collectively, “cookies”) to automatically recognize your device when you visit the Website. Cookies help OPEX Corporation in many ways. For example, cookies can allow OPEX Corporation to tailor your Website visit to better match your interests, as indicated by your activities when browsing the Website or other sites. Furthermore, cookies, for example, also help OPEX Corporation and its service providers to understand what advertisements you have been shown or clicked on as well as to present you with advertisements that are more relevant to you.
PLEASE SEE MORE DETAILED INFORMATION ABOUT THESE COOKIES, INCLUDING INFORMATION ABOUT HOW TO BLOCK OR MANAGE THE COOKIES, IN OPEX CORPORATION’S COOKIES NOTICE APPLICABLE TO THE EU, SWITZERLAND, AND THE UK.
- Google Analytics: To help OPEX Corporation design and optimize the Website, the Website may use Google Analytics, an analytical service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, California 94043 USA ("Google"). In this context, pseudonymized user profiles are created and cookies are used. The information generated by the cookie about your use of the Website is transferred to Google. This information is used to evaluate your use of the Website, to compile reports on Website activities, and to provide further services associated with the use of the Website and the Internet, for the purpose of market research and the demand-oriented design of the Website. IP addresses are anonymized so that assignment is not possible (IP masking). Further information on data protection in connection with Google Analytics can be found in Google Analytics’ Help section at https://support.google.com/analytics/answer/6004245?hl=en. You can prevent the collection of data generated by the cookie and related to your use of the Website (including your IP address) and the processing of this data by Google, for example, by downloading and installing a browser add-on at https://tools.google.com/dlpage/gaoptout?hl=en.
- Google AdWords Conversion Tracking: The Website may use Google’s Adwords conversion tracking (“Google Adwords”) to generate statistics related to the use of the Website and for the purpose of optimizing our Website. Google Adwords is provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, California 94043 USA ("Google"). Google Adwords places a cookie on your device if you have accessed the Website via a Google ad. If you then visit certain pages of the Website and the cookie has not yet expired, OPEX Corporation and Google can recognize that you have clicked on the ad and have been redirected to those pages.
- Hotjar: The Website may use the Hotjar analytical services provided by Hotjar Ltd., 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta to help OPEX Corporation to better understand visitors’ experiences of the Website (e.g., how much time a visitor spends on a page, which links the visitor chooses to click, what the visitor does and does not like, etc.). This, in turn, helps OPEX Corporation to design and optimize the Website.
- Facebook Plug-ins: The Facebook Plug-ins are operated (by Facebook Inc., 1601 Willow Road, Menlo Park, California 94025 USA (“Facebook“). You can find information on data protection at Facebook by visiting https://www.facebook.com/policy.php. Facebook is certified under the EU-US Privacy Shield.
- LinkedIn Plug-ins: The LinkedIn Plug-ins are operated by LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, California 94085 USA (“LinkedIn”). You can find information on data protection at LinkedIn by visiting https://www.linkedin.com/legal/privacy-policy. LinkedIn is certified under the EU-US Privacy Shield.
- Twitter Plug-ins: The Twitter Plug-ins are operated by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, California 94103 USA (“Twitter“). You can find information on data protection at Twitter by visiting https://www.twitter.com/privacy. Twitter is certified under the EU-US Privacy Shield.
- XING Plug-ins: The XING Plug-ins are operated by XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany. You can find information on data protection by visiting https://privacy.xing.com/en/privacy-policy/printable-version.
To increase the protection of your data when visiting the Website, plug-ins are embedded using the so-called “Shariff Solution.“ This means that when a page of the Website is accessed, a connection to the servers of the respective Plug-in Provider is not yet established.
Your web browser establishes a direct connection to the respective Plug-in Provider’s servers only when you activate the Plug-ins. When you activate a Plug-in, the Plug-in Provider receives information that your web browser has accessed the respective site of our Website, even when you do not maintain a user account with the provider or are not logged in. Usage data (including the IP address) are transmitted directly from your web browser to a server of the respective Plug-in Provider and may be stored there. This server may be located outside the EU or EEA (e.g., in the U.S.).
If you do not wish the Plug-in Providers to receive, save, or use data gathered through the Website, you should not use the respective Plug-ins. You can also block the Plug-ins from being loaded with browser add-ons (so-called ‘script blockers’).
Find out more about the purpose and scope of the data collection as well as about the processing and use of your data by Plug-in Providers and about your rights and possibilities to change settings to protect your data in the privacy statements of the respective providers linked above.
The Website is not for use by children under the age of 16 years, and OPEX Corporation does not knowingly collect, store, share, or use the personal data of children under 16 years. If you are under the age of 16 years, please do not provide any personal data, even if prompted by the Website to do so. If you are under the age of 16 years and you have provided personal data, please ask your parent(s) or guardian(s) to notify OPEX Corporation at email@example.com, and OPEX Corporation will delete the personal data.
TRANSFERS OF YOUR INFORMATION
The Website is controlled, operated, and administered by OPEX Corporation from its offices within the United States of America.
Your information, including personal data, may be processed in the United States of America and any other country in which OPEX Corporation, the OPEX Branches/Subsidiaries, and/or their third-party suppliers have operations including without limitation France, Germany, India (for database administration and related IT support), the Republic of Ireland, Switzerland, and the UK. OPEX Corporation and the OPEX Branches/Subsidiaries will take steps to ensure that your personal data receives the same level of protection as if it remained within the European Union, Switzerland, or the UK, including by entering into data transfer agreements, using the European Commission-approved Standard Contractual Clauses, relevant national equivalents, or other permitted safeguards.
For transfers to OPEX Corporation in the United States and transfers within the OPEX Branches/Subsidiaries, we have put in place European Commission-approved Standard Contractual Clauses, relevant national equivalents, or other permitted safeguards. If applicable, you have a right to obtain details of the mechanism under which your personal data is transferred outside of the EU, Switzerland, or the UK by contacting us at firstname.lastname@example.org.
RETENTION OF YOUR INFORMATION
OPEX Corporation and the OPEX Branches/Subsidiaries apply a general rule of keeping personal data only for as long as required to fulfill the purposes for which it was collected, which in most cases corresponds to the applicable statute of limitations. Personal data used for marketing will be retained no longer than is permitted pursuant to applicable law. However, in some circumstances OPEX Corporation and the OPEX Branches/Subsidiaries may retain personal data for other periods of time, for instance where we are required to do so in accordance with legal, tax, or accounting requirements, or if required to do so by a legal process, legal authority, or other governmental entity having authority to make the request, for so long as required.
YOUR RIGHTS REGARDING YOUR INFORMATION
OPEX Corporation and the OPEX Branches/Subsidiaries will take steps in accordance with applicable law to keep your personal data accurately, complete, and up-to-date. You are entitled to have inadequate, incomplete, or incorrect personal data corrected (that is, rectified).
You also have the right to request access to your personal data as well as to obtain additional information about the processing.
In the event your personal data is processed on the basis of your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Further, you are entitled to object to the processing of your personal data and have your personal data erased, under certain circumstances.
As from 25 May 2018, your rights also include:
- Data portability - where we are relying (as the legal basis for processing) upon your consent, or the fact that the processing is necessary to perform a contract to which you are party or to take steps at your request prior to entering a contract, and the personal data is processed by automated means, you have the right to receive all such personal data which you have provided us in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
- Right to erasure - you are entitled to have your personal data erased under specific circumstances, such as where you have withdrawn your consent, where you object to processing based on legitimate interests, and we have no overriding legitimate grounds (see below) or where personal data is unlawfully processed.
- Right to the restriction of processing - you have the right to restrict our processing of your personal data (that is, allow only its storage) where:
- you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
- where the processing is unlawful but you do not want us to erase the personal data;
- where we no longer need your personal data for the processing, but you require such personal data for the establishment, exercise or defense of legal claims; or
- where you have objected to processing justified on legitimate interest grounds (see below), pending verification as to whether we have compelling legitimate grounds to continue processing.
Where your personal data is subject to restriction, we will only process it with your consent or for the establishment, exercise or defense of legal claims.
- Right to object to processing based on legitimate interest legal basis - where we are relying upon legitimate interests to process personal data, you have the right to object to that processing. If you object, we must stop that processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or we need to process the personal data for the establishment, exercise or defense of legal claims. Where we rely upon legitimate interest as a basis for processing, we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
- Right to object to direct marketing (including profiling) - you have the right to object to our use of your personal data (including profiling) for direct marketing purposes, such as when we use your personal data to invite you to our promotional events.
- You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of alleged infringement, if you consider that the processing of your personal data infringes applicable law.
Please contact us as indicated in EXERCISING YOUR RIGHTS; QUESTIONS AND COMMENTS below if you wish to exercise any of your rights, or if you have any inquiries or comments regarding the processing of your personal data.
To help protect your personal data against accidental or unlawful destruction, loss or alteration, and against unauthorized disclosure or access, OPEX uses reasonable technical and organizational security measures. However, please note that no data transmission over the Internet, especially the use of email, can be guaranteed to be absolutely secure. We are not responsible for any lost, stolen, or compromised passwords or for any activity on your account via unauthorized password activity.
LINKS TO OTHER WEBSITES
Please be aware that the Website may contain links to other, third-party websites that operate independently from OPEX Corporation in whole or in part and to which this Privacy Notice does not apply. Such third-party websites may also reference or link to an OPEX Corporation website.
OPEX Corporation shall not be responsible for the privacy practices or the content of such third-party websites and disclaims any responsibility for such privacy practices and content. Without limiting the foregoing, any transactions that you enter into with any vendor, merchant, or another party that you access through such third-party websites are solely between you and that vendor, merchant, or another party.
This Privacy Notice shall not apply to any such third-party sites. For applicable provisions governing privacy on third-party sites, please refer to the privacy disclosures (if any) of the third-party site.
NOTICE TO POTENTIAL JOB APPLICANTS
The positions posted on the Website are for United States and Canadian job applicants only. If you are located outside the United States or Canada and wish to apply for a position, please contact the OPEX office closest to your home country directly.
EXERCISING YOUR RIGHTS; QUESTIONS AND COMMENTS
To exercise any of your rights, please contact us at email@example.com or at the applicable postal address or telephone number below.
If you wish to update or remove your personal data, opt-out from receiving, or opt-in to receive, marketing communications from us, please do so by indicating your preference on the Website (where available) or by contacting us at the postal address or email address below.
If you have any questions or comments about this Privacy Notice (e.g., to review and update your personal data), please contact us at firstname.lastname@example.org.
Alternatively, you may contact OPEX Corporation in the United States using the address and telephone number below, or you may contact the applicable OPEX Branch/Subsidiary using the relevant address(es) in Appendix A.
305 Commerce Drive
Moorestown, New Jersey 08057-4234 USA
Attn.: Vice President, Corp. & Legal Affairs
Telephone number: 856.727.1100
Alternatively, if you are located in Germany, you may contact our external Data Protection Officer for Germany using the contact details below.
Bernd Fuhlert, @-yet GmbH
42799 Leichlingen, Germany
CHANGES TO THIS NOTICE
OPEX BRANCH OFFICES/SUBSIDIARIES
|Applicable Country||Name and Address of the Branch Office/Subsidiary|
|France||OPEX Corporation, France branch
Address: Director EMEA, OPEX, Les Fjords – Bâtiment Vega, 19, avenue de Norvège, ZA de Courtaboeuf, 91140 Villebon-sur-Yvette, FRANCE
|Germany||OPEX Corporation, Germany branch
Address: Director EMEA, OPEX, Auf der Lug 8, 71726 Benningen am Neckar, GERMANY
|Republic of Ireland||OPEX Business Machines GmbH, Republic of Ireland branch
Address: Director EMEA, OPEX, 104 Lower Baggot Street, Dublin 2, REPUBLIC OF IRELAND
|Switzerland||OPEX Business Machines GmbH
Address: Director EMEA, OPEX, Pilatussrasse 41, 6003 Luzern, SWITZERLAND
|United Kingdom||OPEX Corporation, United Kingdom branch, until such time as this branch registration is dissolved
OPEX Business Machines GmbH, United Kingdom branch
Address: Director EMEA, OPEX, 29/32 Queensbrook, Bolton Technology Exchange, Spa Road, Bolton BL1 4AY, UNITED KINGDOM