Effective Date | August 11th 2022
Please be aware that THE WEBSITE VelocityEHS.COM (EHS.COM) IS HOSTED ON SERVERS IN THE UNITED STATES If you are located outside of the United States, information we collect AT THE WEBSITE (including cookies) are processed and stored in the United States, which may not offer the same level of privacy protection as the country where you reside or are a citizen. By using the Services and providing information to us, you consent to the transfer to and processing of the information in the United States.
If you provide personal information to our platform solutions (suite of products), VelocityEHS shall process this information as a data processor on behalf of its Customers. Unless VelocityEHS uses some of this information for marketing or business purposes (e.g. metrics), in such case, VelocityEHS shall be considered the data controller. Additionally, VelocityEHS is the controller of the personal information we collect through the ehs.com website. Any questions or concerns regarding VelocityEHS’s privacy and data protection practices can be directed to our Data Protection Lead at [email protected]
2. INFORMATION WE COLLECT
Personal information is information that directly or indirectly identifies you. Below are some examples of the personal information we may collect through the Services:
- Such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.
- Customer Records. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)), such as name, , address, telephone number, Some personal information included in this category may overlap with other categories.
- Protected Classification Characteristics. Such as age (40 years or older), sex
- Commercial information. Such as products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
- Internet or other similar network activity. Such as information on a consumer’s interaction with a website, application, or advertisement.
- Geolocation data. Such as physical location or movements.
- Professional or employment-related information. Such as current job history
- Inferences drawn from other personal information. Such as profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
3. HOW WE COLLECT INFORMATION
We collect information as follows.
- When you register for the Services: When you register for the Services, we may collect basic contact information (such as name, address, telephone number, e-mail address and company name), as well as billing information.
- When you contact us: We may ask for contact information such as your name, address, telephone number, email address, contact preferences, and information related to our products and Services. We collect this information so that we may: keep you informed about VelocityEHS, respond to your inquiries, and provide you with information about our products and Services.
VelocityEHS may also retain the content of and metadata regarding any correspondence you may have with the company or its sales and customer service representatives, regardless of the mode of communication by which such correspondence was made. This information helps VelocityEHS to improve its Services and the materials, products and services that we offer on the Services, and to more effectively and efficiently respond to both current and future inquiries.
- When you use the Services: VelocityEHS processes data imported by our customers and end users when they access and use our Services. This data can often include personal information of our customers, end users or other data subjects (e.g. non-registered 3rds parties that work together with our customers). The personal information may include contact information, such as name, home address, office address, telephone number, and email address. This information is necessary for VelocityEHS to provide its comprehensive environmental, health, safety and sustainability software solutions. These solutions may include one of our software tools, implementation services, secure cloud hosting, on-demand training, etc.
Customers can also use our tools to schedule, manage and track workplace incidents, formal safety meetings and ensure compliance with state and federal safety regulations and this may provide VelocityEHS with human resource-related data such as date of birth, age, gender, job title and work history. Also, customers using our tracking and streamline tools to submit regulatory reports may provide VelocityEHS with more sensitive information such as medical records, medical bills and doctors’ notes (please note this sensitive data is collected only by our business unit located in Oakville, Canada).
If you provide personal information to our Chemical Management (U.S) product, VelocityEHS shall process this information as a data processor on behalf of its customers, who use our Services to assist with their chemical management processes. The personal information includes name, email address and location. Unless VelocityEHS uses some of this information for marketing or business purposes (e.g. metrics), in such case, VelocityEHS shall be considered the data controller.
The Company may also collect, from you, the following personal information about your contacts: (a) name and email address, in order to forward a job posting, refer our products or services, share an article, blog post or other content or (b) through our “import contacts” feature we may collect the name, email address, phone number of your contacts in order to provide description of use/purpose of collection e.g. to connect you with people you know who also use our Service. When you provide us with personal information about your contacts we will only use this information for the specific reason for which it is provided.
- When you make a payment to VelocityEHS: If you make a payment to VelocityEHS, we will ask for payment information and other information requested for processing your payment.
- Through Server Logs: A server log is a list of the activities that a server performs. VelocityEHS’s servers automatically collect and store in server logs your search queries, Internet Protocol (IP) address, browser type, browser language, the date and time of your request and referral URL and certain cookies that identify your browser or VelocityEHS account.
- From Your Computer, Tablet or Mobile Telephone: We collect information about your computer, tablet or mobile telephone (“Device”), such as model, operating system version, mobile network information, telephone number, internet service provider and similar identifiers. VelocityEHS may associate your Device information with your VelocityEHS account. We may collect and store information (including personal information) on your Device through browser web and web application data caches. We may collect information from sensors that provide VelocityEHS with information on nearby devices, Bluetooth address, Wi-Fi access points and information made available by you or others that indicates the current or prior location of the user. We also may collect IP address and MAC address. How we collect this data depends on how you access the Services. Certain Services may collect this data even when you are not actively using the Services.
- Purchased from Business Partners: We may collect or obtain information about you from marketing partners, social media platforms, data aggregators, location intelligence platforms, third party providers of business contact information, publicly available databases, and similar sources, for advertising and analytics purposes, so that we may offer you personalized features and offers tailored to your interests, and in order to offer you an overall better service. We will use this information where you have provided your consent to the third party or to VelocityEHS, or where VelocityEHS has a legitimate interest in using your information in order to provide you with the content or service requested. We will combine this information with personal information provided by you, in order to identify prospective customers or products you’ll be interested in, to create more tailored advertising, and to improve the accuracy of our records.
- Mobile Applications: When you download and use our Services, we automatically collect information on the type of device you use and the operating system version. VelocityEHS sends you push notifications from time-to-time in order to update you about any events or promotions that we may be running. If you no longer wish to receive these types of communications, you may turn them off at the device level. To ensure you receive proper notifications, we will need to collect certain information about your device such as operating system and user identification information. We do not ask for, access or track any location- based information from your mobile device at any time while downloading or using our Mobile Apps or Services. VelocityEHS uses mobile analytics software to allow us to better understand the functionality of our Mobile Software on your phone. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. We do not link the information we store within the analytics software to any personally identifiable information you submit within the mobile application.
4. Cookies & Similar Technologies
While this information on its own may not constitute “personal data”, we may combine the information we collect via Cookies with personal data that we have collected from you to learn more about how you use the Services to improve them.
Types of Cookies
We use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your device until you delete them). To make it easier for you to understand why we need them, the Cookies we use on the Services can be grouped into the following categories:
- Strictly Necessary: These Cookies are necessary for the Services to work properly. They include any essential authentication and authorization cookies for the Services.
- Functionality: These Cookies enable technical performance and allow us to “remember” the choices you make while browsing the Services, including any preferences you set. They also include sign-in and authentication cookies and IDs that enable you to return without additional sign-in.
- Performance/Analytics: These Cookies allow us to collect certain information about how you navigate the Services running on your device. They help us understand which areas you use and what we can do to improve them.
- Marketing and Customer Support: These Cookies are used to deliver relevant information related to the Services to an identified machine or other device (not a named or otherwise identifiable person) which has previously been used to visit the Services. Some of these types of Cookies on the Services are operated by third parties with our permission and are used to identify advertising sources that are effectively driving customers to the Services.
Here is a representative list of the cookies we use.
Cookies Set by Third Party Sites
To enhance our content and to deliver a better online experience for our users, we sometimes embed images and videos from other websites on the Services. We currently use, and may in future use content from websites such as Facebook, LinkedIn and Twitter. You may be presented with Cookies from these third-party websites. Please note that we do not control these Cookies. The privacy practices of these third parties will be governed by the third parties’ own privacy statements or policies. We are not responsible for the security or privacy of any information collected by these third parties, using cookies or other means. You should consult and review the relevant third-party privacy statement or policy for information on how these cookies are used and how you can control them.
Other Similar Technologies
VelocityEHS web pages may use other technologies such as web beacons to help deliver cookies on the Services and count users who have visited those websites. We also may include web beacons in our promotional email messages or newsletters to determine whether you open and act on them as well as for statistical purposes.
In addition to standard cookies and web beacons, the Services can also use other similar technologies to store and read data files on your computer. This is typically done to maintain your preferences or to improve speed and performance by storing certain files locally.
How to Control and Delete Cookies
Cookies can be controlled, blocked or restricted through your web browser settings. Information on how to do this can be found within the Help section of your browser. All Cookies are browser specific. Therefore, if you use multiple browsers or devices to access websites, you will need to manage your cookie preferences across these environments.
If you are using a mobile device to access the Services, you will need to refer to your instruction manual or other help/settings resource to find out how you can control cookies on your device.
Please note: If you restrict, disable or block any or all Cookies from your web browser or mobile or other device, the Services may not operate properly, and you may not have access to the Services available through the Services. VelocityEHS shall not be liable for any impossibility to use the Services or degraded functioning thereof, where such are caused by your settings and choices regarding cookies.
To learn more about cookies and web beacons, visit www.allaboutcookies.org.
Do Not Track: Some web browsers (including Safari, Internet Explorer, Firefox and Chrome) incorporate a “Do Not Track” (“DNT”) or similar feature that signals to websites that a user does not want to have his or her online activity and behavior tracked. If a website that responds to a particular DNT signal receives the DNT signal, the browser can block that website from collecting certain information about the browser’s user. Not all browsers offer a DNT option and DNT signals are not yet uniform. For this reason, many website operators do not respond to DNT signals. VelocityEHS does respond to DNT signals.
5. HOW WE PROCESS PERSONAL DATA
We will only use your personal information when the law allows us to. Most commonly, we will use your personal information in the following circumstances.
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
VelocityEHS uses information collected for the following purposes based on our legitimate interests:
- To communicate with you;
- To administer and protect our business and the Services including troubleshooting, data analysis, security, testing, system maintenance, support, reporting, technical functionality, hosting of data, and in the context of a business reorganization or group restructuring exercise;
- To prevent and investigate fraud and other misuses of the Services;
- To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you;
- To notify you of changes made to the Services or new products made available;
- To send you promotional material from VelocityEHS and some of our affiliates;
- To use data analytics to improve our website, Services, marketing, client relationships and experiences; or
- To make suggestions and recommendations to you about products or Services that may be of interest to you.
We also use your personal information when necessary for the performance of a contract in the following contexts:
- To process your payments, orders, and transactions including:
- Manage payments, fees and charges
- Collect and recover money owed to us;
- To set up and maintain your account with us;
- To manage our relationship with you which will include:
- Asking you to leave a review or take a survey
- Responding to your questions and inquiries
We may also use your personal information when necessary to comply with legal obligations.
6. HOW WE SHARE INFORMATION
We may share personal information collected via the Services with service providers. VelocityEHS shares information with VelocityEHS’s other third-party service providers that perform Services on our behalf, such as:
- Fulfilling orders and delivering packages
- Payment processing
- Providing customer service
- Sending marketing communications
- Fulfilling subscription services
- Conducting research and analysis
- Providing cloud computing infrastructure
VelocityEHS may aggregate information collected though the Services and remove identifiers so that the information no longer identifies or can be used to identify an individual (“Anonymized Information”). VelocityEHS shares Anonymized Information with third parties and does not limit third parties’ use of the Anonymized Information because it is no longer personal information.
Applicable law may require VelocityEHS to disclose your personal information if: (i) reasonably necessary to comply with legal process (such as a court order, subpoena or search warrant) or other legal requirements; (ii) disclosure would mitigate VelocityEHS’s liability in an actual or threatened lawsuit; (iii) necessary to protect legal rights of VelocityEHS, users, customers, business partners or other interested parties; or (iv) necessary for the prevention or detection of crime (subject in each case to applicable law). For residents of the European Economic Area (“EEA”), VelocityEHS will disclose personal information only when permitted to do so under applicable European and EU Member States’ national data protection laws and regulations.
California Shine the Light Law: California Civil Code Section 1798.83 permits users who are California residents to obtain from us once a year, free of charge, a list of third parties to whom we have disclosed personal information (if any) for direct marketing purposes in the preceding calendar year. If you are a California resident and you wish to make such a request, please send an e-mail with “California Privacy Rights” in the subject line to [email protected] or write us at: VelocityEHS, 222 Merchandise Mart Plaza, Suite 1750, Chicago, IL 60654.
7. MINOR’S PRIVACY
The Services are not directed to or intended for use by individuals under the legal age of majority in the individuals country of residence (“minors”). Consistent with the requirements of applicable law, if we learn that we have received any information directly from a minor without his or her parent’s verified consent, we will use that information only to respond directly to that child (or his or her parent or legal guardian) to inform the minor that he or she cannot use the Services and subsequently will delete that information.
California Minors: If you are a California resident who is under the age of 18 and you are unable to remove publicly-available content that you have submitted to us, you may request removal by contacting us at: [email protected] When requesting removal, you must be specific about the information you want removed and provide us with specific information, such as the URL for each page where the information was entered, so that we can find it. We are not required to remove any content or information that: (1) federal or state law requires us or a third party to maintain; (2) was not posted by you; (3) is anonymized so that you cannot be identified; (4) you don’t follow our instructions for removing or requesting removal; or (5) you received compensation or other consideration for providing the content or information. Removal of your content or information from the Service does not ensure complete or comprehensive removal of that content or information from our systems or the systems of our service providers. We are not required to delete the content or information posted by you; our obligations under California law are satisfied so long as we anonymize the content or information or render it invisible to other users and the public.
8. SECURITY OF PERSONAL DATA
VelocityEHS takes precautions intended to help protect information that we process but no system or electronic data transmission is completely secure. Any transmission of your personal information is at your own risk and we expect that you will use appropriate security measures to protect your personal information.
You are responsible for maintaining the security of your account credentials for the Services. VelocityEHS will treat access to the Services through your account credentials as authorized by you. Unauthorized access to password-protected or secure areas is prohibited and may lead to criminal prosecution. We may suspend your use of all or part of the Services without notice if we suspect or detect any breach of security. If you believe that information you provided to us is no longer secure, please notify us immediately using the contact information provided below.
If we become aware of a breach that affects the security of your personal information, we will provide you with notice as required by applicable law. To the extent permitted by applicable law, VelocityEHS will provide any such notice that VelocityEHS must provide to you under applicable law at your account’s email address. By using the Services, you agree to accept notice electronically.
9. DATA RETENTION
We retain personal information in identifiable form only for as long as necessary to fulfill the purposes for which the personal information was provided to VelocityEHS or, if longer, to comply with legal obligations, to resolve disputes, to enforce agreements and similar essential purposes. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
10. ACCESSING AND UPDATING YOUR PERSONAL INFORMATION
VelocityEHS processes data in their platform solutions on behalf of its customers. End users of our products may request access to their personal information or correct an error or omission in their personal information by contacting the data controller or their employer. Unless VelocityEHS uses some of this information for marketing or business purposes (e.g. metrics), in such case, VelocityEHS shall be considered the data controller and you may request access to your personal information or correct an error or omission in your personal information by contacting us at [email protected] or write us at: VelocityEHS Holdings Inc., Attn: Privacy Inquiries, 222 Merchandise Mart Plaza, Suite 1750, Chicago, IL 60654. We will make good faith efforts to resolve requests to correct inaccurate information except where the request is unreasonable, requires disproportionate technical effort or expense, jeopardizes the privacy of others, or would be impractical. Some individuals, including residents of the European Union (“EU”), United Kingdom (“UK”), and certain US States, may have additional rights concerning the access and updating of their personal information (see Sections 11 and 12 below).
Email and Newsletter Preferences: You may sign-up to receive email or newsletter or other communications from us. If you would like to discontinue receiving this information, you may update your email preferences by using the “Unsubscribe” link found in emails we send to you or at your member profile on our website or by contacting us through one of the methods listed below:
11. THE EU AND UK GENERAL DATA PROTECTION REGULATION (“GDPR”)
Residents of the EU and UK may be entitled to other rights under the GDPR. These rights are summarized below. Customers (data controller) making a request on behalf of a user must be recognized as an authorized VelocityEHS Contact, Primary Contact or Primary Admin. These contacts with authority may make access requests on behalf of application users.
In cases where VelocityEHS is the data controller, we may require you to verify your identity before we respond to your requests to exercise your rights. If you are entitled to these rights, you may exercise these rights with respect to your personal information that we collect and store:
- the right to withdraw your consent to data processing at any time (please note that this might prevent you from using certain aspects of the Services);
- the right of access your personal information;
- the right to request a copy of your personal information;
- the right to correct any inaccuracies in your personal information;
- the right to erase your personal information;
- the right to data portability, meaning to request a transfer of your personal information from us to any other person or entity as chosen by you;
- the right to request restriction of the processing of your personal information; and
- the right to object to processing of your personal information.
You may exercise these rights free of charge. These rights will be exercisable subject to limitations as provided for by the GDPR. Any requests to exercise the above listed rights may be made to: [email protected] If you are an EU resident, you have the right to lodge a complaint with a Data Protection Authority about how we process your personal information at the following website: https://edpb.europa.eu/about-edpb/board/members_en. If you are a resident of the UK you have the right to lodge a complaint with the UK Information Commissioner’s Office about how we process your personal information at the following website: https://ico.org.uk/make-a-complaint/.
International Transfers of personal information
Whenever we transfer your personal information out of the EU or UK, we ensure a similar degree of protection is afforded to it by using a solution that enables lawful transfer of personal data to a third country in accordance with Article 45 or 46 of the GDPR (including the EU Commission Standard Contractual Clauses and UK International Data Transfer Addendum).
VelocityEHS participates in the EU-U.S. and the Swiss-U.S. Privacy Shield Frameworks (the “Privacy Shield”); however, we no longer rely on the Privacy Shield as a lawful data transfer mechanism for transfers of EU data. To learn more about the Privacy Shield program generally, and to view VelocityEHS’s certification, please visit https://www.privacyshield.gov/. With respect to data collected and transferred pursuant to the Privacy Shield, we continue to comply with its requirements under the Privacy Shield, and otherwise take steps to comply with the General Data Protection Regulation.
For additional information on the mechanisms used to protect your personal information, please contact us at [email protected].
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request
12. THE California Consumer Privacy Act AND STATE PRIVACY RIGHTS
This Section applies if you are subject to the California Consumer Privacy Act (“CCPA”) or other US state statutes relating to the rights of individuals regarding the processing of personal information (collectively “State Privacy Laws”).
Information We Collect
Our Services collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“personal information”). In particular, the Services collect or may have collected in the last twelve (12) months the categories of personal information as described in Section 2 above.
Use of Personal Information
We may use or disclose the personal information we collect for one or more of the business purposes indicated in Section 5 above.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract. We share your personal information with the categories of third parties listed in Section 6 above.
In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:
- Customer Records.
- Protected Classification Characteristics (sex and age).
- Commercial information.
- Internet or other similar network activity.
- Geolocation data.
- Professional or employment-related information.
- Inferences drawn from other personal information.
Your Rights and Choices
Some State Privacy Laws provide consumers with specific rights regarding their personal information. This section describes your rights and explains how to exercise those rights.
Right to Access Specific Information and Data Portability Right
You may have the right to request that we disclose certain information to you about our collection and use of your personal information over the past twelve (12) months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we disclosed your personal information for a business purpose, the business purpose for which personal information was disclosed, and the personal information categories that each category of recipient obtained.
Right to Delete
You may have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
Exercising Your Rights
To exercise the access, data portability and deletion rights described above, please complete this Verifiable Consumer Request Form .
Only you, or a person registered with jurisdiction’s Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make such a request for access or data portability twice within a 12-month period. The verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, and describe your request with sufficient detail that allows us to properly understand, evaluate and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response electronically. Any disclosures we provide will only cover the 12-month period preceding the receipt of the verifiable consumer request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your rights as described above.
14. HOW TO CONTACT US
If you have any questions, comments, or concerns about how we handle your personal information, you may contact us at: 1-888-362-2007, [email protected], or write to us at: VelocityEHS Holdings Inc., Attn: Privacy Inquiries, 222 Merchandise Mart Plaza, Suite 1750, Chicago, IL 60654.