O.C. Tanner Company Privacy Policy
Effective date: August 15, 2008
Privacy policy
Thank you for visiting an O.C. Tanner web site. This statement applies to all personal information we handle (except as noted below), including on-line, off-line, and manually processed data.
Information Collection and Use
O. C. Tanner collects personal identifiable information in four contexts. The first pertains to the administration of our employee recognition and appreciation business. Here we collect certain employee data so that we may effectively administer the recognition and incentive programs and determine an employee's eligibility for awards in accordance with the criteria established by the employer. We will ask the employer to provide us, on behalf of its employees, all necessary information required by us to fulfill our contractual obligations to the employer. In most cases this includes the employee's name, work e-mail address, work address, home address, and date of hire. We will ask for no more information than is needed to fulfill our contractual obligation with the employer. However, we may also use the information that has been given to us for other business purposes, such as to measure the employee's interest in various services or special offers, and to inform the employee about new products and services. These offers may be based on information provided by the employer or by the employee.
The second context pertains to orders for products, whether in redemption of an award given by an employer or as an unsolicited order. In this case it is necessary for us to collect certain personal identifiable information to process the orders. This information may include contact information (such as first and last name, e-mail address, shipping address and telephone number), employer's name, and financial information (such as credit information, expiration date, etc.). We use this information for billing purposes and to fill your orders. If we have questions or problems processing your order, we will use this information to contact you. In addition, we may use the information that has been given to us for other business purposes, such as to measure your interest in various services or special offers, and to inform you about new products and services.
The third context pertains to surveys. The vast bulk of the surveys we conduct are in connection with the administration of our employee recognition and appreciation business and are for the benefit of the employer. We may also conduct marketing surveys for data research purposes only. The information provided is used for research analysis and we analyze the answers in the aggregate. A person's cooperation is absolutely voluntary; he or she may withdraw from a marketing research study at any time. No personal information will be sought without prior consent. We may ask for contact information in the event we need to verify or validate answers. We also may ask for demographical information.
Information provided in response to or in connection with a survey, whether collected through a web site or through traditional market research tools, and whether provided at the request of an employer or for market research, is and may be provided to our client(s) and/or other entities and/or the public as part of cumulative market research information or statistical data in the ordinary course but without identifying the participants individually directly or indirectly.
Finally, with respect to non-customers, such as a visitor to a website, if you provide an address, we may send you offers. We may use the information you give us, for example, to measure your interest in various services or products, and to inform you about new services or products.
If the visitor chooses to provide information to us by completing registration forms or otherwise (such as the company name, address, e-mail address, telephone number, etc.) we will assume that the visitor is requesting information about our company and its services and products. The personal identifiable information provided in this context may be used to fulfill requests and may also be used by us to further our business interests.
We do not intentionally collect personal identifiable information about children under the age of 13. If you are under the age of 18 but at least 13 years of age you may use this Site only under the supervision of a parent or legal guardian who agrees to be bound by the Terms of Use posted on this website ("Terms of Use"). Children under the age of 13 may not use this Site and parents or legal guardians may not agree to the Terms of Use on their behalf. If you do not agree to (or cannot comply with) any of the Terms of Use, do not use this Site.
Consent
O. C. Tanner expects that its customers have received all required consents, according to applicable privacy laws, from their employees before transferring, in printed, electronic, facsimile or any other format, personal identifiable data to O. C. Tanner.
Information Sharing and Disclosure
Except as may be required by law, O. C. Tanner does not divulge, distribute, sell, or permit any of its employees, agents or representatives to divulge, distribute, or sell customer employee data received in connection with the customer's award program unless specifically approved. O. C. Tanner does not divulge, share or sell any personal identifiable information that may be provided to it, including e-mail addresses, with any third party for their marketing or promotional purposes. O. C. Tanner may share personal identifiable information that is provided to it with entities wholly owned by it for the purpose of making a product or service offer or to send a newsletter, "e-zine" or other notice pertaining to effective employee recognition. At any time, a person may request to be removed from the list by following the "UNSUBSCRIBE" proceedures in the email, or if there are no such proceedures, by sending an e-mail notice to info@octanner.com that explains the desire to stop receiving communications and gives us the address (e-mail and/or mail) that you want removed.
We may share customer information, including personal identifiable information, with a business that carries out services for us. We use outside shipping companies to fulfill orders, and a credit card processing company to bill you for goods and services. These companies do not retain, share, store, or use personally identifiable information for any other purpose.
We may share your information as permitted or required by law.
If accessing a website from a company-dedicated site, a person from the company to whom the site is dedicated will have access to the following information:
- Your first name, last name, and email address
- The intended recipient's name, address, and telephone number
- The product you purchased and the amount you paid
- e-cards that you sent, including the name and e-mail address of the recipient and the message placed on the e-card.
- Gift certificates that you purchased, including the amount of the certificate and the intended recipient of the gift certificate
We cannot assure the confidentiality of the information from a company-dedicated site once it is accessed by the company to whom the site is dedicated, nor can we limit how that company will use your information. If you do not want anyone other than O.C. Tanner agents and representatives looking at or using your information (see above for how we will use it), you should leave the company-dedicated site. If you accessed an O. C. Tanner site from a company's intranet, or if the URL contains the name of a company other than O. C. Tanner, you are likely accessing the O. C. Tanner site from a company-dedicated site.
Links to other Sites
As you follow links on our website to visit other websites, we encourage you to review their privacy policies. When you follow a link to another site, you are subject to the privacy policies of the new site.
Log files/Cookies
Our sites do not use "persistent cookies" or any persistent tracking technologies that can identify a specific site visitor, or information about that visitor, over multiple visits. However, some O.C. Tanner web sites utilize "session cookies" that identify the visitor for the duration of a browsing session. Session cookies are expired from your Web browser when your session ends.
Security
The security of your personal information is important to us. When you enter sensitive information (such as a credit card number) on our web site, we use industry-standard encryption technologies to protect all your information from unauthorized access.
Although we take reasonable steps to safeguard and to prevent unauthorized access to your private information, we cannot be responsible for the acts of those who gain unauthorized access and we make no warranty we will prevent unauthorized access to your private information. IN NO EVENT SHALL O.C. TANNER COMPANY, O.C. TANNER RECOGNITION COMPANY, OR THEIR AFFILIATES BE LIABLE FOR ANY DAMAGES (WHETHER CONSEQUENTIAL, DIRECT, INDIRECT, PUNITIVE, SPECIAL OR OTHERWISE) ARISING OUT OF, OR IN ANY WAY CONNECTED WITH, A THIRD PARTY'S UNAUTHORIZED ACCESS TO YOUR INFORMATION, REGARDLESS OF WHETHER SUCH DAMAGES ARE BASED ON CONTRACT, STRICT LIABILITY, TORT, OR OTHER THEORIES OF LIABILITY, AND ALSO REGARDLESS OF WHETHER WE WERE GIVEN ACTUAL OR CONSTRUCTIVE NOTICE THAT DAMAGES WERE POSSIBLE.
Safe Harbor
The U.S. Department of Commerce and the European Commission have agreed on a set of data protection principles and frequently asked questions (the "Safe Harbor Principles") to enable U.S. companies to satisfy European Union ("EU") law requirements for adequate protection of personal information transferred from the companies located in the EU to companies located in the U.S. The European Economic Area ("EEA") has also recognized the U.S. Safe Harbor as providing adequate data protection. Consistent with our commitment to protect personal privacy, O.C. Tanner adheres to the "Safe Harbor Principles" and is Safe Harbor Certified.
Safe Harbor Privacy Principles
The following privacy principles are based on the Safe Harbor Principles.
Definitions
"Personal data" means data that is (a) transferred to the United States from the EU, (b) is about, or relates to, an identified or identifiable individual, (c) can be linked to that individual, and (d) is recorded. Personal data may include, among other things, an individual's name, address, phone number, e-mail address, or social security or national health insurance or an equivalent number. For further clarity, the term "personal data" does not include data that pertains to a specific individual, but from which that individual cannot reasonably be identified. Unless otherwise indicated, references herein to personal data include sensitive personal data (as defined below).
"Sensitive personal data" is a subset of personal data that indicates an individual's medical or health condition, racial or ethnic origin, political opinions, religion, union membership, sexual orientation, or actual or alleged criminal activity.
"Company" or "O. C. Tanner" refers to O. C. Tanner Company, its U.S. subsidiaries and divisions, including but not limited to the following: O. C. Tanner Recognition Company and O. C. Tanner Manufacturing Company.
Notice and Choice
To the extent permitted by the Safe Harbor Agreement, O.C. Tanner reserves the right to process personal information in the course of providing professional services to its clients without the knowledge of individuals involved. Where we collect personal information directly from individuals, we inform them about the types of personal information we collect from them, the purposes for which we collect and use it, and the types of non-agent third parties to which we disclose that information by making this policy available prior to the entry of any personal data. We also inform those individuals about the choices and means, if any, we offer individuals for limiting the use or disclosure of their information again by making this policy available prior to the entry of any personal data.
Except as provided above O. C. Tanner gives individuals from whom it collects personal data the opportunity to opt out from allowing O. C. Tanner to disclose his or her personal data to a third party or to use it for a purpose incompatible with the purpose for which it was originally collected. For sensitive personal data, O. C. Tanner requires such individual to affirmatively opt in and give consent if the data is to be disclosed to a third party or used for a purpose other than its original purpose.
Individuals desiring to exercise their opt out rights should contact O. C. Tanner's General Counsel, whose contact information is as follows: 1930 South State Street, Salt Lake City, Utah 84115 USA; brian.katz@octanner.com; telephone (801) 493-3503. Individuals from whom sensitive personal data is sought will be advised of how to opt in and give the required consent at the time the data is collected, if the data is to be disclosed to a third party or used for a purpose other than its original purpose.
Disclosures and Transfers
O.C. Tanner will not disclose an individual's personal information to third parties, except when one or more of the following conditions is true:
- We have the individual's permission to make the disclosure;
- The disclosure is required by law;
- The disclosure is reasonably related to the sale or disposition of all or part of O. C. Tanner's business;
- The information in question is publicly available;
- The disclosure is reasonably necessary for the establishment or defense of legal claims; or
- The disclosure is to another O.C. Tanner entity or to persons or entities providing services on our or the individual's behalf (each a "transferee"), consistent with the purpose for which the information was obtained, if the transferee, with respect to the information in question:
- is subject to law providing an adequate level of privacy protection;
- has agreed in writing to provide an adequate level of privacy protection; or
- subscribes to the Principles.
Permitted transfers of information, either to third parties or within O.C. Tanner, include the transfer of data from one jurisdiction to another, including transfers to and from the United States of America. Because privacy laws vary from one jurisdiction to another, personal information may be transferred to a jurisdiction where the laws provide less or different protection than the jurisdiction in which the information originated.
Data Security
To prevent unauthorized access or disclosure, maintain data accuracy, and ensure the appropriate use and confidentiality of information, either for its own purposes or on behalf of its clients, O.C. Tanner has put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we process. However, O. C. Tanner cannot guarantee the security of information on or transmitted via the Internet.
Data Integrity
O.C. Tanner processes personal information only in ways compatible with the purpose for which it was collected or authorized by the individual. To the extent necessary for such purposes, we take reasonable steps to make sure that personal information is accurate, complete, current, and otherwise reliable with regard to its intended use.
Access and Correction
If an individual becomes aware that information O. C. Tanner maintains about that individual is inaccurate, or if an individual would like to update or review his or her information, the individual may contact O. C. Tanner at info@octanner.com. O. C. Tanner will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate. The individual will need to provide sufficient identifying information, such as name, address, hire date, and employee number. We may request additional identifying information as a security precaution. In addition, we may limit or deny access to personal information where providing such access would be unreasonably burdensome or expensive in the circumstances, or as otherwise permitted by the Safe Harbor Agreement. In some circumstances, O. C. Tanner may charge a reasonable fee, where warranted, for access to personal information.
Enforcement and Dispute Resolution
O.C. Tanner utilizes the self-assessment approach to assure its compliance with its privacy statement. O.C. Tanner periodically verifies that the policy is accurate, comprehensive for the information intended to be covered, prominently displayed, completely implemented, and in conformity with the Safe Harbor Principles. O. C. Tanner encourages interested persons to raise any concerns with it using the contact information below. O. C. Tanner will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with the principles contained in this policy.
With respect to any complaints relating to this policy that cannot be resolved through O. C. Tanner's internal processes, O. C. Tanner agrees to comply with the dispute resolution procedures of the EU data protection authorities to resolve disputes pursuant to the Safe Harbor Principles. In the event that O. C. Tanner or such authorities determine that O. C. Tanner did not comply with this policy, we will take appropriate steps to address any adverse effects and to promote future compliance.
Any person who we determine is in violation of our privacy policies will be subject to disciplinary process.
CONTACT INFORMATION
Written questions or comments regarding our Safe Harbor certification should be submitted to O.C. Tanner by mail as follows:
O.C. Tanner Company
General Counsel
1930 South State Street
Salt Lake City, UT 84115 USA
Your agreement
All information submitted by site visitors is voluntary. Submitting information constitutes your consent for O.C. Tanner to use the information for the purpose stated and indicates to us that you are aware of our privacy policy provisions. The practices outlined in this privacy statement apply to web sites maintained by or on behalf of O.C. Tanner.
We reserve the right to change or modify this privacy policy at any time. Any changes to the policy will be posted to this website. Your use of the site after the modification implies that you consent to the changes.
Notes:
COMPANY-DEDICATED SITE
If you are accessing this site from a "company-dedicated site," the information you provide us can be used more broadly. You can determine whether you are using a company-dedicated web site by going to the home page and looking in the upper-left corner. You are accessing a company-dedicated web site if you see a vertical line followed by the name of a company after the "thanks" logo.
You can return to the O.C. Tanner site by re-typing the O.C. Tanner web site into the address line of your web browser.