CONTROP Privacy and Data Protection Policy and Notice
Controp Precision Technologies Ltd. and its affiliates (“Controp”, “we”, “our” or the “Company”, and their cognates) respects the privacy of its customers, employees, sites and website visitors, and is committed to protecting the personal information you may share with us (these and any others with respect to whom we collect personal data, shall collectively be referred to as “Visitor” or “you” or “Data Subjects”).
Controp specializes in the development and production of electro-optical and precision motion control systems for defense, para-military and homeland security applications (the “Services”).
For the purposes of EU General Data Protection Regulation (the “GDPR”), other applicable privacy laws: Controp is a data controller (the “Controller”) in relation to the personal data of our customers and prospective customers, employees and sites visitors.
1. WHICH INFORMATION MAY WE COLLECT?
Summary: we collect various categories of personal data in order to meet our contractual obligations, and also to meet various legitimate interests, such as fraud prevention and marketing.
We may collect data about you in connection with your transactions with us, or in processing data for our customers. We also collect data about our employees and site visitors. One type of data collected is non-identifiable and anonymous information (“non-personal data”). We also collect several categories of personal data (“Personal Data”), as described below.
Personal Data which is being gathered consists of any details which are personally identifiable and which are provided consciously and voluntarily by you, or by an organization you represent or are associated with or through your use of our websites (as described below), by email, or other ways in which you communicate and interact with us. This generally includes your name (first and last), email address, phone number, postal address, position and organization name and other information you may choose to provide to Controp. Additionally, we may obtain location data related to the geographic location of your laptop, mobile device or other digital device on which the Controp websites are used.
You do not have any legal obligation to provide any information to Controp, however, we require certain information in order to perform contracts, or to provide any services. If you choose not to provide us with certain information, then we may not be able to provide you or your organization with some or all of the services.
By contacting us or submitting requests for support or information via the websites, email etc, Controp will collect details, including also your name, facility name, phone number and personal or company email you provided, country and other such information. Controp may use this information to offer Controp’s services and support.
Controp also collects Personal Data through the use of CCTV cameras and office entrance systems. This may consist of video images of you in the public spaces at Controp sites, as well as records of your entrances and exits of the Controp sites, buildings and office floors. Controp may not be aware of the nature of the information collected through our services (for example, through our CCTV systems), and such information may include sensitive or special categories of Personal Data, but we do not knowingly collect such data about our customers, employees, site visitors etc.
2. HOW DO WE COLLECT PERSONAL DATA OF YOURS ON CONTROP FACILITIES AND SERVICES?
Summary: we collect Personal Data when you or your organization send it to us, or when a vendor, distributor or other business partner, sends it to us so; we collect Personal Data through our websites and services, and through our interactions with you.
We collect Personal Data required to provide Services when you register interest, or when you provide us such information by entering it manually or automatically, or through your use of our facilities and Services, or in connection with site visits, in the course of preparing a contract, or otherwise in engaging with us. We also may collect Personal Data when you call us for support, in which case we collect the information you provide us. We also collect Personal Data through our CCTV recordings which automatically collect information about your presence in the Controp facilities.
We also collect Personal Data through your use of our websites. In other words, when you are using the websites, we are aware of it and may gather, collect and record the information relating to such usage, either independently or through the help of third-party services as detailed below. This includes technical information and behavioral information such as the user’s Internet protocol (IP) address used to connect your device to the Internet, your uniform resource locators (URL), operating system, type of browser, browser plug-in types and versions, screen resolution, Flash version, time zone setting, the user’s ‘clickstream’ on the websites, the period of time the user visited the websites, methods used to browse away from a page. We likewise may place cookies on your browsing devices (see ‘Cookies’ section below).
3. WHAT ARE THE PURPOSES OF PERSONAL DATA WE COLLECT?
Summary: we process Personal Data to meet our obligations, protect our rights, and manage our business.
We will use Personal Data to provide and improve our services to our customers and others and meet our contractual, ethical and legal obligations. All Personal Data will remain accurate complete and relevant for the stated purposes for which it was processed, including for example:
Processing which is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract:
Processing which is necessary for the purposes of the legitimate interests pursued by Controp or by a third party of providing an efficient and wide-ranging service to customers:
Processing which is necessary for compliance with a legal obligation to which Controp is subject:
4. SHARING DATA WITH THIRD PARTIES
Summary: we share Personal Data with our service providers, partners, and group companies, and authorities where required.
We transfer Personal Data to:
Members of our Group: This includes individual or corporate representatives of Controp, and any members of our group, which means our controlling parent companies and subsidiaries – whether wholly or partially owned by Controp, and co-owned companies.
Third Parties. We transfer Personal Data to third parties in a variety of circumstances. We endeavor to ensure that these third parties use your information only to the extent necessary to perform their functions, and to have a contract in place with them to govern their processing on our behalf. These third parties include business partners, suppliers, affiliates, agents and/or sub-contractors for the performance of any contract we enter into with you. They assist us in providing the services we offer, processing transactions, fulfilling requests for information, receiving and sending communications, analyzing data, providing IT and other support services or in other tasks, from time to time. These third parties also include analytics and search engine providers that assist us in the improvement and optimization of our websites, and our marketing.
We periodically add and remove third party providers. At present services provided by third-party providers to whom we may transfer Personal Data include also the following:
- Website analytics;
- Document management and sharing services;
- Customer ticketing and support;
- On-site and cloud-based database services;
- CRM software;
- ERP software;
- Data security, data backup, and data access control systems;
- Project Management systems;
- Call center systems;
- Our lawyers, accountants, and other standard business software and partners.
In addition, we will disclose your Personal Data to third parties if some or all of our companies or assets are acquired by a third party including by way of a merger, share acquisition, asset purchase or any similar transaction, in which case Personal Data will be one of the transferred assets. Likewise, we transfer Personal Data to third parties if we are under a duty to disclose or share your Personal Data in order to comply with any legal or audit or compliance obligation, in the course of any legal or regulatory proceeding or investigation, or in order to enforce or apply our terms and other agreements with you or with a third party; or to assert or protect the rights, property, or safety of Controp, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction and to prevent cybercrime.
For avoidance of doubt, Controp may transfer and disclose non-Personal Data to third parties at its own discretion.
5. WHERE DO WE STORE YOUR DATA?
Summary: we store your Personal Data across multiple locations globally
We store your Personal Data on servers owned or controlled by Controp, or processed by third parties on behalf of Controp, by reputable cloud-service providers (see the following section regarding international transfers).
6. INTERNATIONAL DATA TRANSFERS
Summary: we transfer Personal Data within and to the EEA, UK, USA, Israel and elsewhere, with appropriate safeguards in place.
We may transfer your Personal Data outside of the EEA, in order to:
- store or backup the information;
- enable us to provide you with the services and products and fulfil our contract with you;
- fulfill any legal, audit, ethical or compliance obligations which require us to make that transfer;
- facilitate the operation of our group businesses, where it is in our legitimate interests and we have concluded these are not overridden by your rights;
- to serve our customers across multiple jurisdictions; and
- to operate our parent company, subsidiaries and affiliates in an efficient and optimal manner.
7. DATA RETENTION
Summary: we retain Personal Data according to our data retention policy, as required to meet our obligations, protect our rights, and manage our business.
Controp will retain Personal Data it processes only for as long as required in our view, to provide the services and as necessary to comply with our legal and other obligations, to resolve disputes and to enforce agreements. We will also retain Personal Data to meet any audit, compliance and business best-practices.
8. SERVICES AND WEBSITES DATA COLLECTION AND COOKIES
In many cases, these tags/files lead to the use of your device’s processing or storage capabilities. Some of these tags/files are set by Controp itself, others by third parties; some only last as long as your browser session, while others can stay active on your device for a longer period of time.
These tags/files can fall into several categories: (i) those that are necessary for functionality or services that you request or for the transmission of communications (functionality tags/files); (ii) those that we use to carry out website performance and audience metrics (analytics tags/files) and (iii) the rest (tracking across a network of other websites, advertising, etc.) (other tags/files).
Internet browsers allow you to change your cookie settings, for example to block certain kinds of cookies or files. You can therefore block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies, you may not be able to access all or parts of the website, due to the fact that some may be functionality cookies. For further information about deleting or blocking cookies, please visit: https://www.aboutcookies.org/how-to-delete-cookies/
Functionality and analytical tags/files do not require your consent. For other tags/files, however, we request your consent before placing them on your device. You can give your consent by allowing cookies in your browser settings or by continuing to use our website.
To consult the list of cookies which we use on our website, please check your browser’s settings. Instructions: https://www.wikihow.com/View-Cookies
9. SECURITY AND STORAGE OF INFORMATION
Summary: we take data security very seriously, invest in security systems, and train our staff. In the event of a breach, we will notify the right people as required by law.
We take great care in implementing, enforcing and maintaining the security of the Personal Data we process. Controp implements, enforces and maintains security measures, technologies and policies to prevent the unauthorized or accidental access to or destruction, loss, modification, use or disclosure of Personal Data. We likewise take steps to monitor compliance of such policies on an ongoing basis. Where we deem it necessary in light of the nature of the data in question and the risks to data subjects, we may encrypt data. Likewise, we take industry standard steps to ensure our websites and services are safe.
Note however, that no data security measures are perfect or impenetrable, and we cannot guarantee that unauthorized access, leaks, viruses and other data security breaches will never occur.
Controp shall act in accordance with its policies and with applicable law to promptly notify the relevant authorities and data subjects in the event that any Personal Data processed by Controp is lost, stolen, or where there has been any unauthorized access to it, all in accordance with applicable law and on the instructions of qualified authority. Controp shall promptly take reasonable remedial measures.
10. EU DATA SUBJECT RIGHTS
Summary: depending on the law that applies to your Personal Data, you may have various data subject rights, such as rights to access, erase, and correct Personal Data, and information rights. We will respect any lawful request to exercise those rights.
Data subjects with respect to whose data GDPR applies, have rights under GDPR and local laws, including, in different circumstances, rights to data portability, rights to access data, rectify data, object to processing, and erase data. It is clarified for the removal of doubt, that where Personal Data is provided by a customer being the data subject’s employer, such data subject rights will have to be effected through that customer. In addition, data subject rights cannot be exercised in a manner inconsistent with the rights of Controp employees and staff, with Controp proprietary rights, and third-party rights. As such, job references, reviews, internal notes and assessments, documents and notes including proprietary information or forms of intellectual property, cannot be accessed or erased or rectified by data subjects. In addition, these rights may not be exercisable where they relate to data that is not in a structured form, for example emails, or where other exemptions apply. If processing occurs based on consent, data subjects generally have a right to withdraw their consent.
A data subject who wishes to modify, delete or retrieve their Personal Data, may do so by contacting CONTROP (firstname.lastname@example.org). Note that Controp may have to undertake a process to identify a data subject exercising their rights. Controp may keep details of such rights exercised for its own compliance and audit requirements. Please note that Personal Data may be either deleted or retained in an aggregated manner without being linked to any identifiers or Personal Data, depending on technical commercial capability. Such information may continue to be used by Controp.
Data subjects in the EU have the right to lodge a complaint, with a data protection supervisory authority in the place of their habitual residence. If the supervisory authority fails to deal with a complaint, you may have the right to an effective judicial remedy.
Minors. We do not knowingly collect or solicit information or data from or about children under the age of 16 or knowingly allow children under the age of 16 to register for Controp services. If you are under 16, do not register or attempt to register for any of the Controp Service or send any information about yourself to us. If we learn that we have collected or have been sent Personal Data from a child under the age of 16, we will delete that Personal Data as soon as reasonably practicable without any liability to Controp. If you believe that we might have collected or been sent information from a minor under the age of 16, please contact us at: email@example.com, as soon as possible.
Controp contact details:
Last Revised: Oct 10, 2021