The types of Personal Information we may collect (directly from you or from Third Party-sources) and our privacy practices depend on the nature of the relationship you have with WSRC and the requirements of applicable law. We endeavor to collect information only relevant for the purposes of Processing. Below are the legal bases and some of the ways we collect information and how we use it.
WSRC collects Personal Information regarding its current, prospective and former clients, customers, visitors and guests (collectively “Individuals”). The data we collect from Individuals includes information such as title, name, address, phone number, email address, username, answer to a security question and password, government identification (driver’s license, passport), and credit card and other financial information related to payments for services or goods. We may also collect demographic information you choose to provide, such as your business or company information, professional experiences, educational background, nationality, ethnic origin, age, gender, interests, preferences and favorites.
We acquire, hold, use and Process Personal Information about Individuals for a variety of business purposes including to:
Depending on how you interact with WSRC, we and our Third Party-service providers may also collect and use information in a variety of ways, including:
WSRC collects Personal Information from current, prospective and former Employees, their contact points in case of a medical emergency, and beneficiaries under any insurance policy (“Human Resources Data”). The Human Resources Data we collect may include title, name, address, phone number, email address, date of birth, passport number, driver’s license number, Social Security number, financial information related to credit checks, bank details for payroll, information that may be recorded on a CV or application form, language abilities, contact information of third parties in case of an emergency and beneficiaries under any insurance policy. We may also collect Sensitive Human Resources Data such as details of health and disability, including mental health, medical leave, and maternity leave.
We acquire, hold, use and Process Human Resources-related Personal Information for a variety of business purposes including:
Through our Sites, WSRC may in the future allow Third-Party advertising partners to set tracking tools (e.g., cookies) to collect anonymous, non-Personal Information regarding your activities (e.g., your IP address, page(s) visited, time of day). We may also share such information we have collected with Third-Party advertising partners. These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering future targeted advertisements to you when you visit non-WSRC related websites within their networks. This practice is commonly referred to as “interest-based advertising” or “online behavioral advertising.”
WSRC may collect information about you from Third-Party sources to supplement information provided by you. This supplemental information allows us to verify information that you have provided to WSRC and to enhance our ability to provide you with information about our business, products and services. WSRC’s agreements with these Third Party-sources typically limit how the Company may use this supplemental information.
Individuals who provide us with Personal Information, or whose Personal Information we obtain from Third Parties, may receive periodic emails, newsletters, mailings or phone calls from us with information on WSRC or our business partners’ products and services or upcoming special offers/events we believe may be of interest. We offer our Individuals the option to decline these communications at no cost to the individual.
From time to time, WSRC may perform research (online and offline) via surveys. We may engage Third Party-service providers to conduct such surveys on our behalf. All survey responses are voluntary, and the information collected will be used for research and reporting purposes to help us to better serve Individuals by learning more about their needs and the quality of the products and services we provide. The survey responses may be utilized to determine the effectiveness of our Sites, various types of communications, advertising campaigns and/or promotional activities. If an Individual participates in a survey, the information given will be used along with that of other study participants. We may share anonymous individual and aggregate data for research and analysis purposes.
Like many other websites, WSRC or its business partners may employ a cookie, or small piece of computer code that enables Web servers to “identify” visitors, each time an Individual initiates a session on the Company’s Sites. A cookie is set in order to identify Data Subjects; tailor our Sites to you; measure and research the effectiveness of our Sites’ features, offerings and advertisements; and authenticate users for registered services. Cookies can only access Personal Information that you have provided on our Sites and cannot be accessed by other sites. We may also use Google Analytics and Google Analytics Demographics and Interest Reporting to collect information regarding visitor behavior and visitor demographics on some our Sites, and to develop website content. This analytics data is not tied to any Personal Information. At any time, visitors may choose to opt-out of Google Analytics tracking with the Google Analytics opt-out browser add-on.
Data Subjects also have the ability to delete cookie files from their own hard drive at any time. However, please also be advised that cookies may be necessary to provide
access to much of the content and many of the features of WSRC’s Sites.
WSRC may use “pixel tags,” also known as “web beacons,” which are small graphic files that allow us to monitor the use of our Sites. A pixel tag can collect information such as the Internet Protocol (“IP”) address of the computer that downloaded the page on which the tag appears; the URL of the page on which the pixel tag appears; the time the page containing the pixel tag was viewed; the browser type and language; the device type; geographic location; and the identification number of any cookie on the computer previously placed by that server. When corresponding with you via HTML capable email, we or our Third Party-service providers may use “format sensing” technology, which allows pixel tags to let us know whether you received and opened our email. Anonymous and Aggregated information
Anonymized and aggregated information is used for a variety of functions, including the measurement of visitors’ interest in and use of various portions or features of the Sites. Anonymized or aggregated information is not Personal Information, and WSRC may use such information in a number of ways, including research, internal analysis, analytics and any other legally permissible purposes. We may share this information within WSRC and with Third Parties for our or their purposes in an anonymized or aggregated form that is designed to prevent anyone from identifying you.
Where you have consented to WSRC’s Processing of your Personal Information or Sensitive Personal Information, you may withdraw that consent at any time and opt out. Additionally, before we use Personal Information for any new purpose not originally authorized by you, we will provide information regarding the new purpose and give you the opportunity to opt out.
Prior to disclosing Sensitive Data to a Third Party or Processing Sensitive Data for a purpose other than its original purpose or the purpose authorized subsequently by the Data Subject, WSRC will endeavor to obtain each Data Subject’s explicit consent (opt-in). Where consent of the Data Subject for the Processing of Personal Information is otherwise required by law or contract, WSRC will comply with the law or contract.
An “Unsubscribe” button will be provided at the top or bottom of each email communications sent by WSRC so that you can opt-out. However, we will continue to send transaction-related emails regarding products or services you have requested.
We maintain telephone “do not call” lists and “do not mail” lists as mandated by law. We process requests to be placed on do not mail, do not phone and do not contact lists within 60 days after receipt, or such shorter time as may be required by law.
With regard to Personal Information that WSRC receives in connection with the employment relationship, WSRC will use such Personal Information only for employment-related purposes as more fully described in the section above titled “Human Resources Data”. If WSRC intends to use this Personal Information for any other purpose, the Company will provide the Data Subject with an opportunity to opt-out of such uses.
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. WSRC does not recognize or respond to browser-initiated DNT signals.
Should WSRC engage in interest-based advertising, it will endeavor to comply with the cross-industry Self-Regulatory Program for Online Behavioral Advertising as managed by the Digital Advertising Alliance (DAA) (http://aboutads.info). As part of this service, WSRC’s online advertisements may sometimes be delivered with icons that help Individuals understand how their data are being used and provide choice options to Individuals that want more control. The list of our advertising partners may be updated from time to time. To opt-out of internet-based advertising by all DAA-participating companies, please visit http://www.aboutads.info/choices/.
We may disclose information about you: (i) if we are required to do so by law, court order or legal process; (ii) in response to lawful requests by public authorities, including to meet national security or law enforcement requirements; (iii) under the discovery process in litigation; (iv) to enforce WMG policies or contracts; (v) to collect amounts owed to WSRC; (vi) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation or prosecution of suspected or actual illegal activity; or (vii) in the good faith believe that disclosure is otherwise necessary or advisable. In addition, from time to time, server logs may be reviewed for security purposes – e.g., to detect unauthorized activity on the Sites. In such cases, server log data containing IP addresses may be shared with law enforcement bodies in order that they may identify users in connection with their investigation of the unauthorized activities.
All Personal Information sent or collected via by WSRC may be stored anywhere in the world, including but not limited to, in the United States, on the cloud, our servers, the servers of our affiliates or the servers of our service providers. By providing information to WSRC, you consent to the storage of your Personal Information in these locations.
The security of all Personal Information provided to WSRC is important to us, and WSRC takes reasonable steps designed to protect your Personal Information. Unfortunately, no data transmission over the Internet or storage of information can be guaranteed to be 100% secure. As a result, while WSRC strives to protect your Personal Information, we cannot ensure or warrant the security of any information you transmit to WSRC, and you do so at your own risk.
Due to the nature of WSRC’s business, services and benefits are not marketed to minors. WSRC does not knowingly solicit or collect Personal Information from children under the age of 13. If we learn that we have collected Personal Information from a child under the age of 13, we will promptly delete that information.
California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the Third Parties to whom we have disclosed their Personal Information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of Personal Information disclosed to those parties. WSRC does not share Personal Information with third parties for their own marketing purposes.
“Agent” means any third party that processes Personal Information pursuant to the instructions of, and solely for, WSRC or to which WSRC discloses Personal Information for use on its behalf.
“Data Subject” is an identified or identifiable natural person.
“Employee” refers to any current, temporary, permanent, prospective or former employee, director, contractor, worker or retiree of WSRC or its subsidiaries worldwide.
“Personal Information” is any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Privacy Shield Principles” collectively means the seven (7) privacy principles as described in the Privacy Shield: (1) notice, (2) choice, (3) accountability for onward transfer, (4) security, (5) data integrity and purpose limitation, (6) access, and (7) recourse, enforcement and liability. Additionally, it includes the sixteen (16) supplemental principles described in the Privacy Shield: (1) sensitive data, (2) journalistic exceptions, (3) secondary liability, (4) performing due diligence and conducting audits, (5) the role of the data protection authorities, (6) self-certification, (7) verification, (8) access, (9) human resources data, (10) obligatory contracts for onward transfers, (11) dispute resolution and enforcement, (12) choice – timing of opt-out, (13) travel information, (14) pharmaceutical and medical products, (15) public record and publicly available information and (16) access requests by public authorities.
“Process” or “Processing” means any operation which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Sensitive Data” or “Sensitive Personal Information” is a subset of Personal Information which, due to its nature, has been classified by law or by policy as deserving additional privacy and security protections. Sensitive Personal Information includes Personal Information regarding EU-residents that is classified as a “Special Category of Personal Data” under EU law, which consists of the following data elements: (1) race or ethnic origin; (2) political opinions; (3) religious or philosophical beliefs; (4) trade union membership; (5) genetic data; (6) biometric data where Processed to uniquely identify a person; (6) health information; (7) sexual orientation or information about the individual’s sex life or (8) information relating to the commission of a criminal offense.
“Third Party” is any natural or legal person, public authority, agency or body other than the Data Subject, WSRC or WSRC’s agents.
Wallace Skin Research Center
5120 Goldleaf Circle, Suite 20-B
Los Angeles, CA 90056
Phone: (323) 296-2036