1. Purpose, Scope and Users
Policy: PR-V1092718 Effective Date: 31 May 2018
Inmark, LLC and each affiliate and subsidiary thereof (collectively referred to as Inmark) conducts every business transaction (including without limitation, operations, negotiations and marketing) with integrity and complies with the laws and regulations of the United States, as well as the laws and regulations of each foreign country in which Inmark operates or is looking to operate. All Inmark personnel are expected to conduct Inmark business legally and ethically and with respect to maintaining privacy in communication.
Inmark values the confidence of its customers and vendors and respects individual privacy, including personal data of employees, clients, affiliates, customers, business partners, consultants, contractors, subcontractors and investors. Not only does Inmark strive to collect use and disclose personal data in a manner consistent with the laws of the countries in which it does business, but it also has a tradition of upholding the highest ethical standards in its business practices.
Inmark intends to apply this policy to all transfers of personal data, whether in electronic, paper or verbal format, received or made by Inmark. The provisions and the uses of this policy apply to all employees, contractors, subcontractors, agents and consultants working with, or on behalf of, Inmark.
This Policy sets forth the basic principles by which the Company processes the personal data of customers, clients, vendors, business partners, employees, contractors, and other individuals and indicates the responsibilities of its business departments and employees while processing personal data.
Questions about this policy, or requests for further information, should be directed to Inmark at firstname.lastname@example.org
For purposes of this policy, the following definitions shall apply:
Agent: Any third party that uses personal information provided to it by or on behalf of Inmark to perform tasks on behalf of and under the instructions of Inmark.
Personal Data: Any information relating to an identified or identifiable natural person (“Data Subject“) who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special Categories of Personal Data: Personal information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, criminal records or trade union membership, or that concerns health or sexual orientation.
Data Controller: The natural or legal person, public authority, agency or any other body, which alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Processor: A natural or legal person, public authority, agency or any other body which processes personal data on behalf of a Data Controller.
Processing: An operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of the data.
3. Basic Principles Regarding Personal Data Processing
Inmark intends to process personal data in accordance with the data protection privacy principles of any and all applicable international laws and regulations, including but not limited to the GDPR Principles. Inmark also commits to subject to the Privacy Shield Principles all personal data received from the EU and Personal Data Protection Act2012 (PDPA)The GDPR Principles are set forth below:
Lawfulness, Fairness and Transparency
Inmark processes personal data lawfully, fairly and in a transparent manner in relation to the data subject.
Inmark collects personal data for specified, explicit and legitimate purposes and does not further process the data in a manner that is incompatible with those purposes.
Inmark collects personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. Inmark strives to collect the least amount of personal data possible. With the increasing number of countries restricting or disallowing the use of subjects’ initials as an identifier, Inmark will no longer collect subjects’ initials, except where the sponsor requires such and the Sponsor is compliant with the applicable national laws.
Inmark keeps personal data accurate and, where necessary, up to date and takes reasonable steps to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified in a timely manner.
Storage Period Limitation
Inmark keeps personal data for no longer than is necessary for the purposes for which the personal data are processed.
Integrity and confidentiality
Inmark uses appropriate technical or organizational measures to process personal data in a manner that ensures appropriate security of personal data, including protection against accidental or unlawful destruction, loss, alteration, unauthorized access to, or disclosure.
4. Building Data Protection in Business Activities
In order to demonstrate compliance with the principles of data protection, Inmark has built data protection into its business activities.
4.1. Privacy Notices to Data Subjects
When individuals are first asked to provide personal data to Inmark, or as soon as practicable thereafter and in any event before Inmark uses or discloses the information for a purpose other than for which it was originally collected, Inmark properly informs data subjects of the following: the types of personal data collected, the purposes of the processing, processing methods, the data subjects’ rights with respect to their personal data, the retention period, potential international data transfers, if data will be shared with third parties and the Company’s security measures to protect personal data. This information is provided through a Privacy Notice in clear and understandable language.
Since Inmark has multiple data processing activities, it has developed different privacy notices depending on the processing activity, the data subject and the categories of personal data collected. Inmark´s Data Protection Officer is responsible for creating and maintaining the Register of Privacy Notices. Where special categories of personal data are being collected, the Privacy Notice explicitly states the purpose for which this data is being collected.
Where Inmark, as a data processor, receives personal data from its subsidiaries, affiliates or other entities in the EU, and any other country, it shall use such data in accordance with all applicable laws and regulations, including the GDPR. Where Inmark, as a data controller, receives personal data from third parties, it shall provide the subjects with an appropriate Privacy Notice within a reasonable period after obtaining the personal data, at the time of the first communication or first disclosure to another recipient.
4.2. Data Subject’s Choice and Consent
Whenever personal data processing is based on the data subject’s consent, Inmark retains a record of such consent. Inmark provides data subjects with options to provide the consent and informs and ensures that their consent (whenever consent is used as the lawful ground for processing) can be withdrawn at any time. When requests to correct, amend or destroy personal data records, Inmark ensure that these requests are handled without undue delay and in any event within one month of receipt of the request. Inmark´s Data Protection Officer also records the requests and keeps a log of these.
Personal data is only processed for the purpose for which it was originally collected. If Inmark wants to process collected personal data for another purpose, it seeks the consent of its data subjects in clear and concise writing.
Inmark will obtain consent from all customers, employees, customers, business partners,
Contractors, subcontractors, consultants and investors, where required, for processing, use and/or distribution of any personal and/or special categories of personal data prior to the processing, use or distribution of such data.
4.3. Use, Retention and Disposal
The purposes, methods, storage limitation and retention period of personal data are consistent with the information contained in the Privacy Notice. Inmark maintains the accuracy, integrity, confidentiality and relevance of personal data based on the processing purpose. Adequate security mechanisms designed to protect personal data are used to prevent personal data from being stolen, misused, or abused and prevent personal data breaches.
4.4. Disclosure to Third Parties
Inmark may share an individual’s personal data with agents, contractors, partners or vendors of Inmark in connection with services that these individuals or entities perform for, or with, Inmark. Whenever Inmark uses a third-party vendor to process personal data on its behalf, Inmark ensures that this vendor can provide security measures to safeguard personal data that are appropriate to the associated risks. For this purpose, the Processor GDPR Compliance Questionnaire is used.
Inmark requests the vendor to provide the same level of data protection. The vendor must only process personal data to carry out its contractual obligations towards Inmark or upon the instructions of Inmark and not for any other purposes. Inmark explicitly specifies the respective responsibilities of the third party in the relevant contract or any other legal binding document, such as the Data Processing Agreement.
4.5. Cross-border Transfer of Personal Data
Inmark intends that all transfers of personal data comply with all applicable international laws and regulations, including the GDPR.
When transferring personal data out of the European Economic Area (EEA), adequate safeguards will be used, such as including standard contractual clauses issued by the European Commission in contracts with third parties. Specifically, for example, for transfers of personal data from Switzerland and the EU to the US, Inmark follows and complies with the EU-US Privacy Shield and the Swiss-U.S. Privacy Shield Principles published by the U.S. Department of Commerce. Inmark certifies that it adheres to the Privacy Principles of notice, choice, onward transfer, security, data integrity, access and enforcement. To learn more about the Privacy Shield please visit https://www.privacyshield.gov/list (link is external). Transfers of personal data outside of the European Union, other than to the U.S. shall be made in accordance with the data protection principals prescribed by the international law and regulations applicable in the relevant countries.
Privacy Shield Enforcement
The Federal Trade Commission has jurisdiction over Inmark’s compliance with the
In compliance with the Privacy Shield Principles, Inmark commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Inmark at: email@example.com
Inmark commits to cooperate with EU Data Protection Authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities with regard to human resources data transferred from the EU and Switzerland in the context of the employment relationship.
4.6. Subject Rights
Rights of Access by Data Subjects
When acting as a data controller, Inmark provides data subjects with a mechanism to enable them to access their personal data and allows them to update, rectify, erase, or transmit their personal data, if appropriate or required by law. The access mechanism is further detailed in Inmark´s Data Subject Access Request Procedure, as well as in the Privacy Notices.
Data Subjects have the right to receive, upon request, a copy of the data they provided to Inmark in a structured format and to transmit those data to another controller, for free. Inmark´s Data Protection Officer is responsible to ensure that such requests are processed within one month, are not excessive and do not affect the rights to personal data of other individuals.
Right to be forgotten
Upon request, Data Subjects have the right to obtain from the Company the erasure of its personal data, if applicable. When the Company is acting as a controller, Inmark will take necessary actions to inform the third-parties who use or process that data to comply with the request.
4.8 Data Protection Impact Assessments
Where a type of processing in particular using new technologies and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, Inmark shall, when acting as the controller, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (Data Protection Impact Assessment), according to Inmark´s Data Protection Impact Assessment Guidelines. Inmark shall consult the supervisory authority prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by Inmark to mitigate the risk.
Inmark employs cookies on our websites, these are a small piece of data sent from the website and stored in the web browser of the visitor. Each time the visitor loads the website, the browser sends the cookie back to the server to notify the website of the visitor’s previous activity. This website’s performance cookie is not connected to personal information; it is used in aggregate with other website visitors’ data to generate statistical reports on how people are navigating and using the website. Inmark uses the reports to help us improve the website usage and performance. Visitors to inmarkpackaging.com or any of Inmark’s subsidiary websites may additionally receive cookies from third party sources, these sources can provide more about their privacy and cookie policies.
5. Response to Personal Data Breach Incidents
When Inmark learns of a suspected or actual personal data breach, the Data Protection Officer must perform an internal investigation and take appropriate remedial measures in a timely manner, according to the Data Breach Response and Notification Procedure. Where there is any risk to the rights and freedoms of data subjects, Inmark shall notify the relevant data protection authorities without undue delay and, when possible, within 72 hours.
6. Organization, Accountability and Audit
The responsibility for ensuring appropriate personal data processing lies with everyone who works for or with Inmark and has access to personal data processed by Inmark.
The key areas of responsibilities for processing personal data lie with the following organizational roles:
|Chief Executive Officer (CEO)||Makes decisions about and approves, Inmark´s general strategies on personal data protection and ensures enforcement of this Policy.|
|Chief Financial Officer (CFO)||Manages the personal data protection program and is responsible for the development and promotion of end-to-end personal data protection policies.
Monitors and analyses personal data laws and changes to regulations, develops compliance requirements and assists business departments in achieving their personal data goals.
|Director of Information Technology (DIO)||Ensures all systems, services and equipment used for storing data meet required security standards.
Performs regular checks and scans to ensure security hardware and software is functioning properly.
|Marketing Director||Approves any data protection statements attached to communications, such as emails and letters.
Addresses any data protection queries from journalists or media outlets like newspapers.
Where necessary, works with the DPO to ensure marketing initiatives abide by data protection principles.
|Controller||Improves all employees’ awareness of user personal data protection.
Ensures end-to-end employee personal data protection. Ensures that employees’ personal data is processed based on the employer’s legitimate business purposes and necessity.
|Communicates the policy to employees and contractors as part of the induction process, and at regular intervals thereafter.
Organizes additional training to individuals whose roles require regular access to personal data, or who are responsible for implementing this policy or responding to subject access requests under this policy, to help them understand their duties and how to comply with them.
|Director of Purchasing||Passes on personal data protection responsibilities to vendors by ensuring Data Processing Agreements are signed.
Improves vendors’ awareness levels of personal data protection, as well as the flow down of personal data requirements to any third party a vendor is using.
The Vendor Manager must ensure that Inmark reserves a right to audit vendors.
|Manager, Quality Assurance||Ensures Audits are conducted on how well business departments implement this Policy.|
Any employee that Inmark determines to be in violation of this policy will be subject to disciplinary action and this may result in termination of their employment with Inmark. The employee may also be subject to civil or criminal liabilities if his or her conduct violates laws or regulations.
Inmark reserves the right to amend this policy from time to time to ensure it remains consistent with the Principles.
8. Reservation of Rights
Inmark reserves the right to share individuals’ personal data as required by law or duly authorized data request of governmental authorities.
9. Conflicts of Law
This Policy is intended to comply with the laws and regulations in the place of establishment and of the countries in which Inmark operates. In the event of any conflict between this Policy and applicable laws and regulations, the latter shall prevail.