While the legal value of Privacy Shield participation has been invalidated from a GDPR perspective, Kreller continues its participation and maintains our obligations with respect to transfers made under the Privacy Shield Framework. We feel it is an important framework which demonstrates our commitment to protect personal information in accordance with a set of privacy principles that offer meaningful privacy protections and recourse for EU individuals. Kreller also utilizes Standard Contractual Clauses with Data Controllers by request.
Definitions of Terms Used
“Personal Information” means information that is transferred from the EU, UK or Switzerland to the U.S.; is recorded in any form; and pertains to a specific individual or can be used to identify an individual, either directly or indirectly.
“Sensitive Personal Information” means Personal Information specifying medical or health conditions, racial or ethnic origin, political opinions or philosophical beliefs, trade union memberships or information concerning the sex life of the individual.
“Agent” means any third party that uses Personal Information provided by Kreller to perform tasks on behalf of or at the instruction of Kreller and who is bound by a Confidentiality Agreement.
“Processing” of Personal Information means any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
Notice, Choice & Accountability for Onward Transfer
Kreller does not collect Personal Information about individuals through its websites except when such individuals specifically provide such information on a voluntary basis such as through our subscription registration for news or blog updates, a request for samples or Whitepapers, employment submissions via the website or via an email sent to us through our website.
Kreller enters into agreements with client organizations that provide us with individuals’ Personal Information in order for us to provide investigative or business credit services in a manner consistent with and limited to the purpose for which the data subject provided their Personal Information. Kreller is committed to safeguarding our client confidences, including any Personal Information received from or about our clients or from or about their third party business associates, including information which is hosted on KOL (Kreller’s risk management system) and Kreller’s Case Management System. Kreller will not share Personal Information with third parties for purposes other than those in support of Kreller’s business operations and as necessary to facilitate the purpose for which it was provided. Kreller personnel, third party agents and third party administrators are required to treat this information confidentially and to use and disclose it only to provide the services for which Kreller was retained. Accordingly, Kreller has in place written agreements with client organizations using our services, as well as our third party agents and administrators which require, amongst other things, that parties safeguard Personal Information, and abide by all applicable laws. For our clients who are subject to the GDPR, the agreements will set forth a permissible basis for the onward transfer of Personal Information from the EU, EEA, UK or Switzerland to the United States. Except as set forth in this privacy statement, Kreller does not disclose Personal Information received from its clients to third parties without its clients’ consent. To the extent permitted by Privacy Shield, the FCRA and other applicable laws, Kreller reserves the right to process Personal Information in the course of our internal business operation without the knowledge of the individuals involved. Kreller does not provide Personal Information to third parties for their marketing purposes. In cases of onward transfer of EU Personal Data, Kreller has the responsibility for the processing of personal data it receives under Privacy Shield and subsequently transfer to a third party acting as an agent on its behalf. Kreller shall remain liable if the agents we engage to process such personal information do so in a manner inconsistent with the Privacy Shield Principles, unless Kreller proves that it is not responsible for the event giving rise to the damage.
Kreller will offer individuals the opportunity to choose (opt out) whether their Personal Information is (a) to be disclosed to a non-Agent or non-third party administrator or (c) to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual. For Sensitive Personal Information, we will give individuals the opportunity to affirmatively and explicitly (opt in) consent to the disclosure of the information to a non-Agent third party or non-third party administrator or the use of the information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual.
In the event you decide that you want to opt out from Kreller’s use of your Personal Information that you previously provided to Kreller, notify us by email at: firstname.lastname@example.org.
We may also be required to disclose your Personal Information in response to lawful requests by public authorities having jurisdiction over Kreller, including to meet national security or law enforcement requirements. We may also use or disclose your Personal Information, if necessary, to protect and defend the rights or interest of Kreller or others.
Kreller may, as a result of a sale, merger, consolidation, change in control, transfer of assets, reorganization or liquidation of our company, transfer, sell or assign your Personal Information to third parties involved in the aforementioned events.
Security, Data Integrity and Purpose Limitation
Kreller combines technical and physical safeguards with employee policies and procedures to protect your Personal Information from loss, misuse, unauthorized access, disclosure, alteration and destruction. Kreller employs Secure Socket Layer (SSL) data encryption when data is transmitted over the Internet to our Website. We have installed layered firewalls and other security technologies to help prevent unauthorized access to our systems. The servers used to store Personal Information are maintained in a secure environment with appropriate security measures. Password protection protocols are utilized on all computers.
Kreller will use your Personal Information only in a manner that is compatible with the purpose for which it was collected or authorized by the individual or our client. Kreller will take commercially reasonable measures to ensure that Personal Information is accurate, complete, current, and otherwise reliable with regard to its intended use. Data will be retained only for as long as it serves its relevant purpose and in consideration of correlated compliance and legal considerations.
Kreller acknowledges that EU individuals have the right to access the personal information that we maintain about them. Upon request, and with proof of identity, we will grant individuals reasonable access to their Personal Information that Kreller holds about them in response to a lawful request by public authorities having jurisdiction over Kreller. Under such circumstances, Kreller will allow individuals to correct, amend, or delete that information that is demonstrated to be inaccurate or incomplete except where providing such access would be unreasonably burdensome or expensive in the circumstances or where the rights of persons other than the individual would be violated as a result. Additionally, access to Personal Information will be granted under the terms of the Fair Credit Reporting Act when information is processed or obtained related to a request which qualifies under the Fair Credit Reporting Act. Although we make every effort to ensure that the data we collect and store about you is as accurate as possible, we cannot guarantee that third parties are accurate in information that they transmit and therefore we are not responsible for the accuracy of the data that may be supplied by any third-party sources of information or our clients.
Recourse, Enforcement and Liability
Kreller is subject to the investigatory and enforcement powers of the Federal Trade Commission in connection with the processing of your Personal Information under the Privacy Shield Framework.
Dispute Resolution for EU and Swiss Individuals
Kreller has committed to refer unresolved privacy complaints under the EU-US and Swiss-US Privacy Shield Principles to BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus.
If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint.
Please note that if your complaint is not resolved through the above channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.