PRIVACY POLICY

Last updated: January 2020

TOPICS:
1) What is “Personal Information”? (Hint: It’s Your Data)
2) What Data Do We Collect?
3) How Do We Collect Your Data?
4) Why Do We Collect Your Data and How Do We Use It?
5) Who Will Have Access to My Data?
6) How Do We Store Your Data and For How Long?
7) Do I Have a Say? (Exercise Your Data Protection Rights)
8) How Do We Protect the Privacy of Children?
9) What Are Cookies and How Do We Use Them?
10) Other Technologies
11) Privacy Policies of Other Websites
12) Changes to Our Privacy Policy
13) How to Contact Us
14) Contact the Appropriate Authority

This Privacy Policy explains how Iovate Health Sciences International Inc. (together with its affiliates, referred to as “Iovate”, “we”, “us”, “our”) handles any Personal Information that visitors (“you”, “your”) provide to us on one of our websites, applications and other online properties (each or together, the “Site”). We respect and understand your concerns about the privacy of your Personal Information and we commit to treating it in a responsible manner. Unless otherwise specifically noted, this Privacy Policy does not apply to Personal Information collected from you by third-party web sites or applications to which the Site(s) may link.


Please read this Privacy Policy and our Terms of Use before using the Site and submitting Personal Information to us.
 
1) What is “Personal Information”? (Hint: It’s Your Data)

“Personal Information” is “Data” that identifies you (or your household) or could be used for such identification, directly or indirectly, alone or in combination, and which is submitted to and/or collected by the Iovate Site. Examples of Personal Information include but are not limited to: name; postal, e-mail or IP address; location data; device identifiers; telephone numbers; biometric data; purchase history; search and browsing history; account information; and cookies collected by this Site in accordance with the Iovate Cookie Settings.
 
2) What Data Do We Collect?

Iovate may collect Data including, but not limited to, the following (if you provide these):
- basic personal details such as your name, age range, birth date, gender;
- contact data such as your telephone number(s); mailing and e-mail addresses;
- Site username and password;
- payment information such as credit card number and expiration date;
- photographs;
- occupation, income range, religion, ethnicity and other unique identifiers;
- social security or social insurance number(s);
- height, weight, bodyfat percentage and measurements;
- areas of interest;
- fitness goals, exercise patterns, weight-training regimen;
- eating patterns, food preferences, experience with diet programs;
- level of water intake;
- supplement and other product usage;
- recruitment related information (e.g., job application); and
- any other Data that you may provide.
You also provide Data via cookies collected when you use the Site, unless you have disabled cookies by changing your browser settings or have turned off the collection of cookies using our Cookie Settings.
We may combine your Data with information that we collect from other online and offline sources. This information may include, for example: (1) information we receive from visitors when they call us, redeem coupons or complete our surveys or other forms; (2) information visitors submit to us at our retail locations or special events; and (3) updated contact and other information about our visitors that we may receive from third parties.
 
3) How Do We Collect Your Data?
You directly provide most of the Data we collect. We collect and process Data in the following ways:

(i) When You Submit Data: For example, when you: register online to purchase goods or receive certain services (e.g., an app) or information (e.g., newsletters or promotions); submit a survey or an application; provide feedback on a Site message board (such as giving a product review); send an email; contact Iovate customer service; or use or view the Site via your browser’s cookies.

By providing your Data, you are consenting to the use indicated by Iovate at the time the Data is collected and pursuant to this Privacy Policy, though you may withdraw your consent at any time by contacting us (see Section 13 or click here).

(ii) Passive Collection of Data: The Iovate Site may collect information about your visits to the Site without you actively submitting such information, though it is usually unidentifiable to you. Data may be collected using various technologies, such as cookies and web beacons. See the Iovate Cookie Settings for further detail. Generally, information collected through such means cannot be used to identify you without additional identifiable information and Iovate will not connect additional identifiable information with passive information collection technologies in order to identify any individual.
 
4) Why Do We Collect Your Data and How Do We Use It?

We also collect your Data so you can:
• Sign up to receive newsletters and other communications from Iovate;
• Contact us (including our Webmaster, customer service representatives, or other employees);
• Complete a registration form, survey or poll;
• Participate in a sweepstakes or contest;
• Make product or service inquiries;
• Purchase products and leave reviews; and
• Participate in interactive portions of the Site.

We collect your Data for business purpose only and, in general, so we can:
• process orders and post reviews;
• manage your account;
• provide better customer service;
• provide a user-friendly Site experience;
• customize the user experience based on preferences;
• respond to your inquiries;
• provide notices regarding Iovate’s products or services (including requested materials, like newsletters and promotions);
• invite you to participate in surveys or programs, contests or sweepstakes;
• Email you with special offers on products and services we think you might like (i.e., if you provided us with your prior opt-in consent for such purposes);
• Conduct market research;
• To ensure and improve Site functionality (e.g., by compiling statistics, analyzing trends), including managing interactive features of the Site and ensuring security).

Iovate may consolidate the Data of Site users in a non-identifiable form (aggregated and anonymized) to help us better design the Iovate Site and Iovate products, to enhance our research activities, and to facilitate other business functions. Iovate may share aggregated anonymous information about Site users with its affiliates, partners and other third parties for this and the reasons provided above. We will keep a record of all the ways we use Data.

We will only use your Data if we have a lawful basis: (i) with your consent, freely given, specific, informed and unambiguous; (ii) where necessary for the performance of a contract; (iii) to comply with a legal obligation; (iv) where necessary to protect vital interests – e.g., ‘life or death’ scenarios; (v) to carry out a task in the public interest; and/or (vi) if we have a legitimate interest that outweighs your fundamental rights and interests.

When we process an order you make, your Data will be shared with a third-party payment processing company for the purpose of completing the transaction. We may also send your Data to, and use the resulting information from, credit reference agencies to prevent fraudulent purchases.
 
5) Who Will Have Access to My Data?
Iovate does not sell or rent your Data to third parties. We do not share your Data, except as provided in this Privacy Policy.
Your Data will only be accessed for the purpose(s) you have agreed to, by: (i) a restricted number of Iovate or affiliate company employees, (ii) certain companies with which Iovate may conduct joint programs, and/or (iii) by third parties with whom Iovate contracts to carry out business activities for Iovate for services including, but not limited to (e)mailing of information, maintenance of databases, processing of payments. Any Data accessed will be on a need-to-know basis and in accordance with the instructions of Iovate pursuant to this Privacy Policy and also, in the case of any partners or third parties, according to a written agreement which contains provisions for the protection of Data.

Iovate trains our employees about the importance of privacy and how to handle and manage customer Data appropriately and securely, and we only work with other parties who provide the same level of protection for your Data.
Our Site may also include social media features (e.g., share or like buttons). Such features are provided by third-party social media platforms such as LinkedIn, Twitter, Facebook, Instagram, SnapChat, and Pinterest. Where Data is collected this way, its processing is governed by the privacy policy of the respective social media platforms.Iovate operates on a global basis and may transfer your Data to a country other than your own. Data stored in another jurisdiction is subject to the laws of that country. For example, Data that is transferred to and stored in the U.S. may be available to the U.S. government or its agencies under a lawful order made in that country. Iovate reserves the right to disclose your Data to respond to authorized information requests from government authorities, when otherwise required by law, or where necessary to protect the rights, property or personal safety of another individual if such disclosure does not override your rights to the privacy of your Data. In the event Iovate sells one of its product lines or divisions, Iovate will only transfer your Data to the buyer subject to your consent where required by applicable law so that the buyer can continue to provide you with information and services.
Except as otherwise stated in this section and in Section 6, Iovate will not transfer your Data to third parties.

 6) How Do We Store Your Data and For How Long?

We use reasonable measures including technical, physical, and organizational / administrative safeguards (e.g., encryption, anonymization) to securely store your Data and help protect it from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free, so your use of the Site and the Data you provide is at your own risk.

In general, Iovate will only store your Data for as long as it is needed to fulfill the purposes for which it was collected, subject to applicable data retention periods imposed upon Iovate by applicable law and any other legitimate legal bases. Once the purpose for which the Data was collected is fulfilled, we will ensure we securely destroy or overwrite your Data.
To see how long we keep the cookies we collect, refer to the Cookie Settings.

Iovate may send you marketing, promotional or other information. In certain cases, when interacting with Iovate, you may be provided with a choice to opt-in or opt-out of receiving such information. In other cases, you will not be presented this choice. If you, at any time, choose to opt-out of receiving such information, we will abide by that marketing preference. Moreover, at any time (no matter what you have chosen or informed us of in the past), you may send us an email at privacy@iovate.com to express a marketing preference or to update or request the deletion of your Data. Of course, you may also follow the “unsubscribe” instructions contained in the marketing communications you receive from Iovate. We will abide by your preference and update your Data accordingly. We will generally respond to such requests within thirty (30) days.

In certain cases, we may give you the option to opt-in to receive marketing, promotional or other information from one of our partners or another third party. If you chose to opt-in for that, we will provide your Data to that third party. BY CHOOSING TO OPT-IN TO A THIRD PARTY DISCLOSURE OF YOUR DATA, YOU ACKNOWLEDGE THAT ONCE YOUR DATA HAS BEEN SHARED WITH THAT THIRD PARTY, THE SUBSEQUENT SAFEGUARDING OF YOUR DATA WILL BE GOVERNED BY THAT THIRD PARTY’S PRIVACY POLICY, AND ANY REQUEST FOR FURTHER INFORMATION WITH RESPECT TO THEIR INTENDED USE AND/OR TO CHANGE YOUR MARKETING PREFERENCES WITH THAT THIRD PARTY SHALL BE DIRECTED TO THAT THIRD PARTY (AND NOT TO IOVATE).

If you have previously opted-in to receive such information from us or a specific third party, declining to opt-in at any future time for us or that third party will not be treated as an opt-out for your marketing preference.

Kindly note that no matter what your marketing preferences are, we may contact you to acknowledge, confirm or fulfill any order that you place, to respond to you, or for other legitimate business reasons. Please remember that if you post any Data in public areas of the Site, such as an online forum or chat room, this Data may be collected and used by others over whom Iovate has no control. Use caution when posting Data in public forums. Iovate is not responsible for the use made by third parties of Data you post or otherwise make available in public areas of the Iovate Site.

 7) Do I Have a Say?(Exercise Your Data Protection Rights)

You may always limit the amount and type of Data that Iovate receives about you by choosing not to enter any Data into forms or data fields on the Iovate Site. Some online services can only be provided to you if you provide us with appropriate Data. Other parts of the Iovate Site may ask whether you wish to opt into our contact lists for offers, promotions and additional services that may be of interest to you.

You may also be provided with preference questions or preference boxes, allowing you to indicate that you do not want the Iovate Site to use tracking technologies, such as cookies, to “remember” your Data, such as user IDs or mailing addresses, on return visits. However, the Iovate Site does not generally provide you with the ability to opt out of the tracking technologies. Some Internet browsers allow you to limit or disable the use of tracking technologies that collect unidentifiable information.

Every user is entitled to the following:

The Right to Access - You have the right to make reasonable requests for further details on what Data we collect about you, and how we use, share and retain the Data (as applicable). You may make one (1) request per year for your Data free of charge; we may charge a small fee to cover administrative costs of responding to any additional requests in the same twelve (12) months.

The Right to Rectification - You have the right to request that we correct any Data you believe is inaccurate. You also have the right to request us to complete the Data you believe is incomplete. We will also take reasonable steps to ensure that your Data remains accurate and complete.

The Right to Erasure - You have the right to request that we delete your Data, under certain conditions.

The Right to Object to, or Restrict / Limit Processing – You have the right, under certain conditions, to ask us to stop using all or some of your Data (e.g., if you do not believe we have a lawful basis) or to limit our use (e.g., you may wish to permit us to use some but not all of the Data we request).

The Right to Data Portability – You have the right to request that we transfer the Data that we have collected to another organization, or directly to you, under certain conditions. You may make one (1) request per year for your Data free of charge; we may charge a small fee to cover administrative costs of responding to any additional requests in the same twelve (12) months.

To exercise one of your rights listed above, please click here to submit your request. All requests will be verified before any Data is disclosed. We will respond to requests as soon as possible and generally within thirty (30) days. We will respond in a manner accessible to you, which is typically a format recognizable by most software applications (e.g., email, .xsl). We will retain a record of all requests for a minimum of twenty-four (24) months.

If you previously consented to receiving communications from Iovate and you wish to withdraw your consent, you can do so any time. Please click here to complete your request.

Note that, even if you have chosen not to receive e-mail messages or to limit the Data we collect with cookies, your use of the Site still remains subject to this Privacy Policy and our Terms of Use. It will remain your sole responsibility to review the Site for any important changes to these.

If you would like to exercise any of these rights, you may also use the information provided in Section 13 to contact us. You will not be discriminated against because you object to or limit our use of your Data and, to the extent possible, we will continue to make our Site and other services available to you. If you are not satisfied with our use of your Data or our response to any exercise of these rights, please let us know so that we have the opportunity to address your concerns.

 8) How Do We Protect the Privacy of Children?

Iovate does not knowingly collect or use any Data from children (we define “children” as persons under the age of 18) on the Iovate Site. We do not knowingly allow children to order our products, communicate with us, or use any of our online services. If you are a parent or guardian and become aware that your child has provided us with information, please contact us by clicking here or using one of the methods specified below, and we will work with you to address this issue.

 9) What Are Cookies and How Do We Use Them?

Cookies are small text files that are transferred to your computer’s hard disk by a Site. Web beacons (also referred to as GIF files, pixels or Internet tags) help Iovate recognize a unique cookie on your browser. When you visit a Site, we will automatically collect cookies once you consent. If you do not wish for us to collect your cookies, you can disable the cookies (including Performance, Functional and Targeting Cookies), with the exception of Strictly Necessary cookies, which are necessary to ensure functionality of a Site. See our Cookie Settings for further information.

Keep in mind that cookies allow you to take advantage of some of the features available on a website. For this reason, we recommend that you leave them turned on. For instance, if you block or otherwise reject our cookies, you will not be able to add items to your Shopping Cart, proceed to Checkout, or use products or services that will require you to Login. If, at any time, you would like to turn a cookies setting on or off, you may do so by clicking here.

 10) Other Technologies

DNT is a concept that has been promoted by regulatory agencies such as the U.S. Federal Trade Commission (FTC) to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across sites by using browser settings. The World Wide Web Consortium (W3C) has been working with industry groups, Internet browsers, technology companies, and regulators to develop a DNT technology standard. While some progress has been made, it has been slow. No standard has been adopted to this date and, as a result, we are not equipped to respond to “do not track” signals.

For more information on how to block and opt out from tracking technologies used on our Site, please see our Cookie Settings.

Automated Decision-Making
We do no use automated decision-making without human intervention, including profiling, in a way that produces legal effects concerning or otherwise significantly affecting you.

 11) Privacy Policies of Other Websites

The Site may contain links to other websites. Our Privacy Policy applies to our Site only, so if you click on a link to an external website, you should read their privacy policy. We are not responsible for the information that a third-party website or application may collect about you, even if you accessed the website or application via our Site.

 12) Changes to Our Privacy Policy
Iovate conducts regular reviews of this Privacy Policy and, without prejudice to your rights under applicable law, reserves the right to amend this policy from time to time to reflect technological advancements, legal and regulatory changes and good business practices. We will notify you of such changes by updating the effective date at the top of this Privacy Policy. Please ensure you check the Privacy Policy each time you visit the Site to review any changes. Nevertheless, any time our cookies collection practices change, you will be separately notified and asked to accept or reject the cookies. We will also seek separate consent for any uses of Data you willingly submit if we seek to use that Data for any purpose not previously identified at the time you submitted the Data.

If you have opted-out of receiving communications from Iovate that you previously signed up for, the information submitted / collected will still be subject to this Privacy Policy and the Terms of Use, unless and until such time you request the exercise of certain rights (e.g., right to deletion).

 13) How to Contact Us

If you have any questions about the Data we collect, this Privacy Policy, or if you would like to make a suggestion, please click here; however, if you wish to exercise one of your specific Data protection rights, you can use any of the following ways to communicate with us. You may complete an on-line request (click here) or reach out to us:

By Email to: privacy@iovate.com

By Mail to: Iovate Health Sciences International Inc.
Legal Department
Attention: Data Privacy & Security Officer
381 North Service Road West
Oakville, ON L6M 0H4 Canada

By Telephone to: 905-678-3119
1-888-334-4448 (North America only)

 14) Contacting the Appropriate Authority

Should you wish to report a complaint or if you feel that we have not addressed your concern in a satisfactory manner, you may contact the relevant data protection / supervisory authority in your area. We would, however, appreciate the chance to deal with your concerns before you exercise that option. We will respond to any communications from you in an expedient manner and, in any event, within thirty (30) days – though, often this time will be much sooner.