Appendix A
Privacy Information for California Residents
This Appendix applies solely to individuals who reside in the State of California (“consumers” or “you”). This Appendix complies with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this Appendix. This Appendix does not apply to personal information outside the scope of the CCPA, including, for example:
- Personal health information collected, processed, sold, or disclosed pursuant to the Health Insurance Portability and Accountability Act (“HIPAA”).
- Personal information bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living as set forth in the Fair Credit Reporting Act.
- Standard Process as a Service Provider
When Standard Process acts as a service provider for its business customers, it collects some personal information on behalf of its customers subject to its contractual obligations. When Standard Process acts as a service provider for its business customers, it follows the instructions of its customer on how to process personal information on its customer’s behalf. The provisions of this Appendix do not apply to the personal information that Standard Process processes on behalf of our business customers.
- Disclosures
The below chart lists the categories of personal information that Standard Process may collect or has collected in the past 12 months and how it uses such information.
Categories of Personal Information | Categories of Sources from which the Personal Information is Collected | How the Personal Information is Used (Business Purposes) | Categories of Third Parties with whom Personal Information is Shared |
---|---|---|---|
Identifiers. This may include a real name, alias, address, email address, phone number, Social Security Number, driver’s license number, online identifier, IP address, account username and password, or other similar identifiers. | You, your agents, through our third party service providers, social media networks, and your care provider. | To provide you with information, products, or services; to advertise or market to you; to conduct surveys; and for our own legal obligations and business needs. | Entities that we are legally required to share with pursuant to law; service providers; prospective purchasers of our business; our affiliates; outside auditors and lawyers; and social networks. |
Internet and network information. This may include information on your interaction with a website, application, or advertisement, such as browsing history and how you use your account. | You, your agents, through our third party service providers, and social media networks. | To provide you with information, products, or services; to advertise or market to you; to improve our services and products; to conduct surveys; for our own business needs; and to secure our websites. | Entities that we are legally required to share with pursuant to law; service providers; our affiliates; outside auditors and lawyers; and your care providers. |
Device information. This may include the operating system of your device, device identifier, the type of device you are using, or your geolocation information. | You and through our third party service providers. | To provide you with information, products, or services; to advertise or market to you; to improve our services and products; to secure our websites; and for our own business needs. | Entities that we are legally required to share with pursuant to law; our affiliates; and service providers. |
Order information. This may include information about what you order, shipping, returns, product complaints, or warranties. | You, your agents, through our third party service providers, and your care provider. | To provide you with information, products, or services; to advertise or market to you; for our own legal obligations and business needs; to conduct surveys; and to improve our services and products. | Entities that we are legally required to share with pursuant to law; service providers; prospective purchasers of our business; our affiliates; outside auditors, insurers, and lawyers; and your care provider. |
Payment and credit information. This may include your credit or debit card information, banking information, information about your payment transaction, or other financial information you provide us. | You, your agents, and through our third party service providers. | To provide you with information, products, or services and for our own legal obligations and business needs. | Entities that we are legally required to share with pursuant to law; service providers; prospective purchasers of our business; our affiliates; and outside auditors and lawyers. |
Other information you submit to Standard Process or its service providers. This may include requests or communications you submit to us, emails, ratings, social media communications, or customer service call recording. | You, your agent, through our third party service providers, or social media networks. | To provide you with information, products, or services; to advertise or market to you; to improve our products or services; to conduct give aways or contests; and for our own legal obligations and business needs. | Entities that we are legally required to share with pursuant to law; service providers; our affiliates; outside auditors and lawyers; and social networks. |
Research or survey information. This may include survey results and other information about your participation in our research trials, such as information regarding your health, activities, preferences, and characteristics. | You or through our third party service providers. | To provide you with information, products, or services; to advertise or market to you; to improve our products and services; to conduct surveys; and for our own legal obligations and business needs. | Entities that we are legally required to share with pursuant to law; service providers; our affiliates; and outside auditors and lawyers. |
Health information. This may include information about your weight, height, health goals, blood pressure, medical conditions, or physical characteristics. This does not include information processed pursuant to HIPAA. | You, your agent, or your care provider. | To provide you with information, products, or services; to advertise or market to you; to improve our products and services; and for our own legal obligations and business needs. | Entities that we are legally required to share with pursuant to law; service providers; our affiliates; and your care provider. |
Inferences about you. This may include information about your preferences, characteristics, predispositions, behavior, or other trends that help us identify which products you may be interested in. | You, through our third party service providers, and social media networks. | To provide you with information, products, or services; to advertise or market to you; to improve our products and services; and for our own business needs. | Service providers; our affiliates; and social networks. |
Applicant or employment information. This may include your name, address, resume, work history, education, cover letter, drug screening information, and background check information. | You or through our third party service provider. | To evaluate you for employment at Standard Process; to begin the employment process; and for our own legal and business needs. | Entities that we are legally required to share with pursuant to law; our affiliates; and service providers. |
- Sale of Personal Information
In the past 12 months, we have not sold personal information.
- California Residents’ Rights and Choices
The CCPA provides California residents with specific rights regarding their personal information, described below. Below are your CCPA rights and how to exercise those rights.
a. Access to Specific Information and Data Portability Rights (“Right to Know”)
You have the right to request that Standard Process disclose certain information to you about its collection and use of your personal information over the past 12 months. You may request:
- The categories of personal information Standard Process collected about you;
- The categories of sources of personal information Standard Process collected about you;
- Standard Process’ business or commercial purpose for collecting that personal information;
- The categories of third parties with whom Standard Process shares that personal information; or
- The specific pieces of personal information Standard Process collected about you.
b. Deletion Request Rights
You have the right to request that Standard Process delete some or all of the personal information that it has collected from you and retained, subject to a number of exceptions. Standard Process is not required to delete personal information that is: (i) necessary to complete a transaction with you or for warranty or product recalls; (ii) used for security purposes, to prevent fraud, to fix errors, or to comply with law; (iii) reasonable for Standard Process to use for internal purposes given its relationship with you; or (iv) compatible with the context in which you provided the information. The list of exceptions above is not exhaustive, and we may also deny a deletion request as otherwise permitted by law.
c. Exercising Your Rights
To exercise your rights described above, please submit a verifiable consumer request to Standard Process by either:
- Calling us at 800-558-8740.
- Visiting CCPA Request Form.
Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. If you are making a request on behalf of another person, you must provide written legal documentation that you are authorized to act on behalf of that individual.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows Standard Process to reasonably verify you are the person about whom it collected personal information or an authorized representative; and
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
Standard Process may not be able to fulfill your request or provide you with personal information if it cannot verify your identity or authority to make the request and confirm the personal information relates to you. To verify your identity, Standard Process may request up to three pieces of personal information about you, and Standard Process reserves the right to take additional steps as necessary to verify your identity if it has reason to believe a request is fraudulent.
d. Response Timing and Format
Standard Process endeavors to respond to a verifiable consumer request within 45 days of its receipt. If Standard Process requires more time (up to 90 days), it will inform you of the reason and extension period in writing. Standard Process will deliver the written response by mail or electronically, at your option.
Any disclosures Standard Process provides will only cover the 12-month period preceding the date it receives your verifiable consumer request. The response Standard Process provides will also explain the reasons it cannot comply with a request, if applicable. For data portability requests, Standard Process will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
Standard Process does not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If Standard Process determines that the request warrants a fee, it will tell you why it made that decision and provide you with a cost estimate before completing your request.
e. Non-Discrimination
You have the right to not be discriminated against for exercising any of your CCPA rights. Unless permitted by the CCPA, Standard Process will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
- Provide you a different level or quality of goods or services; or
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.