OPSWAT, INC. CALIFORNIA CONSUMER PRIVACY ACT NOTICE - Non-Workforce

Effective Date: May 27, 2020

Unless defined below, capitalized terms have the same meanings as in the Terms of Service.

This OPSWAT, Inc. (“OPSWAT”) California Consumer Privacy Act Notice - Non-Workforce (“CCPA Notice”) applies to You only if You are a natural person, a California resident (as defined under §17014 of Title 18 of the California Code of Regulations), and meet the “Consumer” definition under CCPA §1798.140(g).

This CCPA Notice is incorporated into, made part of, and governed by the OPSWAT Privacy Policy.

This CCPA Notice does not apply to job applicants, employees, owners, directors, officers, or contractors of OPSWAT or its Affiliates (“Workforce”). OPSWAT, Inc. CCPA Notice - Workforce applicable to Workforce is here: https://onlinehelp.opswat.com/policies/OPSWAT%2C_INC._CALIFORNIA_CONSUMER_PRIVACY_ACT_NOTICE_-_Workforce.html

Effective January 1, 2020, the California Consumer Privacy Act of 2018, Cal. Civil Code §1798.100 et seq. and related regulations, as amended (“CCPA”) requires OPSWAT to inform You of the: (a) Personal Information categories OPSWAT collects, (b) Categories of Sources (defined in AG Regulations, §999.301(d)) where OPSWAT gets the Personal Information, (c) OPSWAT Business or Commercial Purposes (defined under CCPA §1798.140(d) and §1798.140(f)) for collection, (d) Categories of Third Parties (defined in AG Regulations, §999.301(e)) OPSWAT shares Personal Information with, and (e) rights to Your Personal Information.

More information on the CCPA:

1. PERSONAL INFORMATION COLLECTED; SOURCES OF PERSONAL INFORMATION; BUSINESS OR COMMERCIAL PURPOSES; THIRD PARTIES OPSWAT SHARES WITH

During the past twelve (12) months, OPSWAT may have (a) collected the categories of Personal Information (b) from the Categories of Sources (c) for the Business or Commercial Purposes, and (d) shared the Personal Information with the Categories of Third Parties below.

Categories of Personal Information

Categories of Sources

Business or Commercial Purposes for Collection

Categories of Third Parties With Whom OPSWAT Shares

Identifiers

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From OPSWAT Third-Party Providers

From public sources

From Your entity

From Your Outsourced Providers

From Your suppliers, licensors, customers, or other third parties You choose to interact with

OPSWAT business and marketing partners

Communicate with You

Comply with Applicable Laws

Defend OPSWAT legal rights

Detect, protect against, and prosecute security incidents

Inform You about third party products or services

OPSWAT marketing activities

Prevent fraud or illegal activity

Process payments

Protect Your accounts (i.e. Portal, online store)

Provide OPSWAT Services to You

Verify Your identity

OPSWAT Affiliates

OPSWAT business (e.g. insurance, attorneys, accountants, financing) and marketing partners

Internet service providers

Data analytics providers

Government entities

Operating systems and platforms

OPSWAT Third-Party Providers

Third parties as required by Applicable Laws

Your Outsourced Providers, suppliers, licensors, customers, or other third parties You authorize

Financial information, including bank account

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From OPSWAT Third-Party Providers

From public sources

From Your entity

From Your Outsourced Providers

From Your suppliers, licensors, customers, or other third parties You choose to interact with

Comply with Applicable Laws

Defend OPSWAT legal rights

Detect, protect against, and prosecute security incidents

Prevent fraud or illegal activity

Process payments

Verify Your identity

Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From Your entity

From Your Outsourced Providers

From Your suppliers, licensors, customers, or other third parties You choose to interact with

Comply with Applicable Laws

Defend OPSWAT legal rights

Detect, protect against, and prosecute security incidents

OPSWAT marketing activities

Prevent fraud or illegal activity

Provide OPSWAT Services to You

Internet or other electronic network activity information, including browsing history, search history, and information regarding a Consumer’s interaction with an internet website, application, or advertisement

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From OPSWAT Third-Party Providers

OPSWAT business and marketing partners

Comply with Applicable Laws

Defend OPSWAT legal rights

Detect, protect against, and prosecute security incidents

Develop new Services

Improve existing Services

Inform You about third party products or services

Maintain reliability, quality or safety of Services

OPSWAT marketing activities

Prevent fraud or illegal activity

Protect Your accounts (i.e. Portal, online store)

Provide OPSWAT Services to You

Provide OPSWAT Support for OPSWAT Services

Geolocation data

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From Your mobile provider or ISP

Website browsers

Comply with Applicable Laws

Defend OPSWAT legal rights

Detect, protect against, and prosecute security incidents

Maintain reliability, quality or safety of Services

OPSWAT marketing activities

Prevent fraud or illegal activity

Protect Your accounts (i.e. Portal, online store)

Provide OPSWAT Services to You

Provide OPSWAT Support for OPSWAT Services

Audio, electronic, visual, thermal, olfactory, or similar information, including call recordings

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

Detect, protect against, and prosecute security incidents

Maintain reliability, quality or safety of Services

Prevent fraud or illegal activity

Provide OPSWAT Services to You

Professional or employment-related information

Directly from You or Your independent contractors, including through use of OPSWAT Services (i.e. completion of OPSWAT website and online forms)

From Your entity

From Your Outsourced Providers

From Your suppliers, licensors, customers, or other third parties You choose to interact with

Detect, protect against, and prosecute security incidents

Inform You about third party products or services

OPSWAT marketing activities

Prevent fraud or illegal activity

Provide OPSWAT Services to You

Inferences drawn from Personal Information to create a profile about a Consumer reflecting the Consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes

OPSWAT

Detect, protect against, and prosecute security incidents

Develop new Services

Improve existing Services

Inform You about third party products or services

Maintain reliability, quality or safety of Services

OPSWAT marketing activities

Prevent fraud or illegal activity

Provide OPSWAT Services to You

2. RIGHTS

Exercising Your Rights. Subject to the below exceptions and limitations, You have the following rights under the CCPA with respect to the Personal Information OPSWAT collects about You:

(a) Right to Know. You have the right to request up to two times in any 12-month period from the date OPSWAT received Your first request that OPSWAT give You information about OPSWAT’s collection, use, and sharing of Your Personal Information over the past twelve (12) months. If You want to exercise this Right to Know, submit a request to Request About My Personal Data: https://go.opswat.com/myuserright, or Tel: +1 855 OPSWAT1 (+1 855 6779281).

Once OPSWAT receives Your Right to Know request and verifies Your identity, OPSWAT will disclose to You, to the extent permitted by Applicable Laws, the following information for the 12 months prior to the date on which OPSWAT received Your request:

(1) Personal Information categories OPSWAT collected about You.
(2) Categories of Sources from which OPSWAT collected Your Personal Information.
(3) OPSWAT Business and Commercial Purposes for collecting Your Personal Information.
(4) Categories of Third Parties with whom OPSWAT shares Your Personal Information.
(5) Specific pieces of Personal Information OPSWAT collected about You.
(6) Personal Information categories that OPSWAT disclosed for a Business Purpose about You.

OPSWAT never shares, even with You, Your social security number, government-issued identification number, driver’s license number, health or medical information, financial account numbers, password, or security questions and answers.

(b) Right to Delete. Subject to the below exceptions, You have the Right to Delete the Personal Information OPSWAT collects from You. If You want to exercise this Right to Delete, submit a Right to Delete request to Request About My Personal Data: https://go.opswat.com/myuserright, or Tel: +1 855 OPSWAT1 (+1 855 6779281).

Under the CCPA, OPSWAT will not delete Personal Information that OPSWAT collects from You if OPSWAT needs to maintain the Personal Information to:

(1) Complete a transaction You requested, or provide OPSWAT Services to You;
(2) Reasonably maintain a relationship between OPSWAT and You;
(3) Perform a contract between OPSWAT and You;
(4) Detect, protect against, and prosecute security incidents;
(5) Prevent fraud or illegal activity, or prosecute parties responsible for such activity;
(6) Provide OPSWAT Support for OPSWAT Services;
(7) Perform internal uses or operations that are reasonably aligned with Your expectations based on Your relationship with OPSWAT (e.g. password resets);
(8) Comply with Applicable Laws; or
(9) Perform internal uses or operations in a lawful manner compatible with the context in which OPSWAT collected Your Personal Information, including as needed to defend OPSWAT legal rights.

Once OPSWAT receives Your Right to Delete request and verifies Your identity, OPSWAT will delete Your Personal Information from OPSWAT records, subject to the above exceptions. OPSWAT shall maintain records of Consumer requests made pursuant to the CCPA and how OPSWAT responded to said requests for at least twenty-four (24) months.

If OPSWAT denies Your Right to Delete request, OPSWAT will (a) inform You and provide the basis of the denial, including the applicable exceptions, (b) delete Your Personal Information that is not subject to an exception, (c) not use Your Personal Information retained for a purpose other than provided for by an exception.

OPSWAT may delete Your Personal Information by the following means:

(1) Permanently and completely erase the Personal Information from OPSWAT existing systems, except archived or backup systems;
(2) De-identify the Personal Information so that it cannot reasonably be linked or identified to You; or
(3) Aggregate the Personal Information such that Your identity has been removed.

OPSWAT will specify the means used to delete Your Personal information in OPSWAT’s response to You.

If Your Personal Information is stored on an archived or backup system, OPSWAT is not required to delete Your Personal Information from that system until the system is restored to an active system, or OPSWAT next uses or accesses the system for a disclosure or Commercial Purpose.

If Your Personal Information is de-identified, OPSWAT is not obligated to provide or delete the Personal Information in response to a request or to re-identify individual data to verify a request.

(c) Right to Opt out of Sale of Your Personal Information. If a business sells Consumer Personal Information, the CCPA grants Consumers a right to tell a business not to sell (i.e., opt out of the sale of) Personal Information. OPSWAT does not sell Your Personal Information. When OPSWAT collects Your Personal Information You are deemed to have opted out of sale under the CCPA at the time of collection.

(d) Right Against Discrimination. OPSWAT will not discriminate against You for exercising Your CCPA rights. OPSWAT will not:

(1) Deny You Services for exercising Your rights;
(2) Charge You a different price or rates for Services, including granting discounts or other benefits, or imposing penalties, because You exercised Your rights;
(3) Provide You a different level or quality of Services because You exercised Your rights; or
(4) Suggest that You may receive a different price or rate for Services, or a different level or quality of Services, as a result of exercising Your rights.

OPSWAT’s denial of Your Request to Know or Request to Delete for reasons permitted by the CCPA or AG Regulations shall not be considered discriminatory.

A price or Service difference that is the direct result of compliance with Applicable Laws shall not be considered discriminatory.

Request Receipt Confirmation; Identity Verification. When you submit a Right to Know or a Right to Delete request, OPSWAT will confirm receipt within ten (10) business days with (a) an email, (b) message via Your account (i.e. online store, Portal), (c) during the telephone call if the request is by telephone, or (d) postal mail if no email or account (1) asking You to verify Your identity to ensure the request came from You, (2) along with information about how OPSWAT will process the request, including the expected response time, except when OPSWAT has already granted or denied the request.

If You do not receive the request receipt confirmation within 10 business days, re-submit Your request.

If You do not use a designated submission method to submit a request, or the request is deficient in a manner unrelated to the identity verification process, OPSWAT will at its sole discretion (a) treat the request as if it had been submitted in accordance with an OPSWAT designated method, or (b) provide You information on how to properly submit a request or remedy request deficiencies.

To verify identity, OPSWAT may ask You to confirm Personal Information You provided to OPSWAT.

If You have an OPSWAT account (i.e. Portal, online store), OPSWAT may verify Your identity through OPSWAT’s existing authentication practices for the account, provided that OPSWAT shall require You to re-authenticate before disclosing or deleting Your Personal Information.

If You do not have an OPSWAT account, and Your request does not relate to the Right to Know specific pieces of Personal Information OPSWAT collected about You or the Right to Delete, two (2) pieces of Your Personal Information must match with information OPSWAT maintains.

If You do not have an OPSWAT account, and Your request relates to the Right to Know specific pieces of Personal Information OPSWAT collected about You or the Right to Delete, three (3) pieces of Your Personal Information must match with information OPSWAT maintains, and You must provide a signed declaration under penalty of perjury that You are the Personal Information data subject using the CCPA Consumer Declaration form.

If OPSWAT cannot verify Your identity from the information OPSWAT already maintains, OPSWAT may request additional information from You, which shall only be used to verify Your identity, and for security or fraud prevention purposes. OPSWAT shall delete new Personal Information collected for verification purposes as soon as practical after processing Your request, except as required to comply with Applicable Laws.

Response Time. OPSWAT will respond to Right to Know and Right to Delete requests within forty-five (45) calendar days. The 45 calendar days begins on the day OPSWAT receives the request, regardless of the time required to verify identity. If OPSWAT cannot verify Your identity within 45 calendar days, OPSWAT may deny Your request.

If necessary, OPSWAT may take up to an additional 45 calendar days to respond to Your request, for a maximum total of ninety (90) calendar days from the day OPSWAT receives the request, provided that OPSWAT provides You an explanation of the reason that OPSWAT will take more than 45 calendar days to respond to the request.

Requests from Authorized Agents. If You authorize a natural person or business entity registered with the Secretary of State, subject to California Civil Code §999.326 (“Authorized Agent”) to make a Right to Know or Right to Delete request or otherwise act on Your behalf, (a) You must verify Your identity with the CCPA Authorized Agent Affidavit – Consumer form

and (b) the Authorized Agent must provide OPSWAT Your signed written permission allowing the Authorized Agent to act, unless You provided the Authorized Agent with power of attorney pursuant to California Probate Code §§4000 to 4465 using the CCPA Authorized Agent Affidavit – Entity form

for an Authorized Agent that is a legal entity, or the CCPA Authorized Agent Affidavit – Individual form

for an Authorized Agent that is an individual. OPSWAT may deny a request from an Authorized Agent that does not submit proof that You authorized the Authorized Agent to act.

Request Denial. OPSWAT reserves the right to deny Your Right to Know or Right to Delete request if OPSWAT cannot reasonably verify Your identity or if responding to Your request would create a substantial security risk. If OPSWAT denies a request, OPSWAT will inform You and provide the basis of the denial, including the applicable exceptions. OPSWAT reserves the right to deny a Right to Know or Right to Delete by an Authorized Agent if OPSWAT is not reasonably able to confirm proper authorization and/or verify Your identity as the requestor.

3. DO NOT TRACK

OPSWAT does not respond to Do Not Track (“DNT”) signals or have a mechanism for responding to browser DNT signals. There currently is no industry or legal standard for recognizing DNT signals.

4. MINORS

OPSWAT directs Services at adults only. OPSWAT does not permit, or knowingly collect Personal Information from, persons under age eighteen (18), sixteen (16), thirteen (13), or other relevant age “minor” is defined, to use Services. If You are a minor, do not provide Your Personal Information to OPSWAT.

5. CONTACT

If You have questions or concerns about this CCPA Notice, contact OPSWAT at Request About My Personal Data: https://go.opswat.com/myuserright, Tel: +1 855 OPSWAT1 (+1 855 6779281), or Address: OPSWAT, Inc., P.O. Box 77878, San Francisco, CA, 94103, Attn: CCPA Notices.