Last updated November 8, 2024
Picarro Inc. (“Picarro”) operates the Picarro website, Picarro Community online forum (collectively with all content, services and products available on or through the website, the “Website”) and P-Cubed Platform (collectively a suite of data collection, processing and data analytics, referred to as “P-Cubed”). It is Picarro’s policy to respect your privacy regarding any information we may collect while operating the Website or when you otherwise engage with Picarro. This Privacy Policy is governed by our Terms of Service.
This Privacy Policy is intended to help you understand:
Picarro complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Picarro has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Picarro has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Picarro is responsible for the processing of personal data it receives, under the Data Privacy Framework, and subsequent transfers to a third party acting as an agent on its behalf. Picarro complies with the DPF Principles for all onward transfers of personal data from the EU, the United Kingdom and Switzerland, including the onward transfer liability provisions.
Like most website operators, Picarro collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. Picarro’s purpose in collecting non-personally-identifying information is to better understand how Picarro’s visitors use the Website. We may choose to aggregate this non-personally-identifying information with your personal data for analytics and other purposes.
P-Cubed collects non-personally-identifying environmental data. These data are used with Picarro proprietary algorithms to generate actionable data to ensure regulatory compliance and create safer workplaces and communities. The P-Cubed platform is accessible from the EU hosted environment (https://pcubed.eu.picarro.com) or NA hosted environment (https://pcubed.picarro.com).
The Website is not intended for or directed to persons under the age of 16, and we will not knowingly collect information from such persons. Any person who provides information to us through registration or in any other manner on the Website represents to Picarro that they are 16 years of age or older. If we learn that a child under 16 has submitted personal data to us, we will attempt to delete the information as soon as possible.
Persons who visit the Website or otherwise engage with Picarro choose to interact with Picarro in ways that require Picarro to gather personal data that allows them to be individually identified. We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
The amount and type of information that Picarro gathers depends on the nature of the interaction. For example, we ask visitors who sign up for the Picarro Community to provide a username, email address, geographic location, and other information including main area of specialty and name of employer. Picarro may ask for payment information, including credit card information, in connection with purchases made on the Website. All credit card information submitted through the site is processed by a third-party provider on Picarro’s behalf and cannot be accessed by Picarro. In each case, Picarro collects such information only as far as is necessary or appropriate to fulfill the purpose of the visitor’s interaction with Picarro. Picarro does not disclose personal data other than as described below. Visitors can always refuse to supply personal data (except to the extent a user’s IP address or other Technical Data supplied by their device may constitute personal data), with the caveat that it may prevent them from engaging in certain Website-related activities. Picarro will only use your personal data, including your contact details, for marketing purposes if doing so is within the scope of our legitimate interests or you have given your explicit consent for us to do so. Picarro will never sell, rent, or provide user information to other vendors or other companies that seek to market or sell products by using such user information.
We do not collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership or information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses.
Picarro may collect statistics about the behavior of visitors to our Website. For instance, Picarro may monitor the most popular content on the Website or report the most popular discussion groups in the Picarro Community. However, Picarro does not disclose personal data other than as described in this Privacy Policy.
We use different methods to collect data from and about you. These include:
Picarro is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC) regarding personal data received or transferred pursuant to the Data Protection Framework. In compliance with the Data Protection Framework Principles, Picarro commits to resolve complaints about our collection or use of your personal information.
Picarro discloses personal data to those of its employees, service providers, contractors and affiliated organizations that (i) need to know that information in order to process it on Picarro’s behalf or to provide services available on or through the Website, and (ii) that have agreed not to disclose it to others. Some of those employees, service providers, contractors and affiliated organizations may be located outside of your home country. Please see the information concerning international transfers set forth below regarding such employees, service providers, contractors and affiliated organizations.
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Picarro commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.
We will only use your personal data as permissible by law. Most commonly, we will use your personal data in the following circumstances:
Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to sending direct marketing communications to you via direct mail, email, or text message where we do not have an existing business relationship or other legitimate interest in doing so. If we do rely on consent, you have the right to withdraw consent to marketing at any time by contacting us in the manner set forth in this Privacy Policy. If we do not rely on consent, you have the right to object to our processing of your personal data in any case, again, by contacting us.
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data on more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal grounds, we are relying on to process your personal data where more than one ground has been set out in the table below.
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
---|---|---|
To register you, your employer or principal as a new or potential customer | (a) Identity (b) Contact | (a) Performance of a contract with you (b) Necessary for our legitimate interests (operating our business) |
To process and deliver your order including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us | (a) Identity (b) Contact (c) Financial (d) Transaction | (a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Asking you to leave a review or take a survey (c) For after sales service, including marketing and managing any maintenance contracts, repairs to or questions about our products purchased | (a) Identity (b) Contact (c) Profile (d) Marketing and Communications | (a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
To administer and protect our business and the Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity (b) Contact (c) Technical | (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise) (b) Necessary to comply with a legal obligation |
To deliver relevant Website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical | Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
To use data analytics to improve our Website, products/services, marketing, customer relationships and experiences | (a) Technical (b) Usage | Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Website updated and relevant, to develop our business and to inform our marketing strategy) |
To make suggestions and recommendations to you about goods or services that may be of interest to you | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and Communications | Necessary for our legitimate interests (to develop our products/services and grow our business) |
If you are (i) a vendor or service provider, or (ii) a representative of a vendor or service provider, to manage our relationship with you (in the case of (i)) or to manage our relationship with the vendor or service provider you represent (in the case of (ii)) | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Financial (g) Marketing and Communications | To enter into or perform a contract with the vendor or service provider. Necessary for our legitimate interests in operating our business. |
With your consent | All types of data | We may use information about you where you have given us consent to do so for a specific purpose not listed above. For example, we may publish testimonials or featured customer stories to promote our products/services, with your permission. |
You can ask us to stop sending you marketing messages at any time by clicking the link at the bottom of all marketing emails or by emailing a request to privacy@picarro.com.
Picarro discloses personal data when required to do so by law, or when Picarro believes in good faith that disclosure is reasonably necessary to protect the property or rights of Picarro, third parties or the public at large. Additionally, Picarro may disclose personal data in connection with a sale or merger with another entity or if Picarro should ever file for bankruptcy or have its assets sold to another entity.
We may disclose your personal data to our employees, contractors, or third party service partners. These third party service partners are listed at the end of this document on Exhibit A. Some of these service partners use “cookies” or other tracking devices on the Website, which are software programs or other systems that collect information about your use of our services. As described below, we will only transfer your information internationally (for example, to information technology vendors in other countries) where we believe appropriate safeguards are in place to protect your information.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Our business operates principally in the United States of America and to the extent we process your data directly we will do so in the United States or within the European Union or Switzerland. If you reside in the European Union, we will only transfer your data to third parties outside of the European Economic Area ("EEA") (a) if we have first obtained your prior consent; or (b) after taking such measures as are necessary to ensure the transfer is in compliance with the requirements of the GDPR. Such measures may include (without limitation) transferring your data to a recipient in a country that the European Commission has decided provides adequate protection for personal data, to a recipient that has achieved binding corporate rules authorization in accordance with the GDPR, or to a recipient that has executed standard contractual clauses adopted or approved by the European Commission.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. While we implement safeguards designed to protect your information, no security system is impenetrable and due to the inherent nature of the Internet, we cannot guarantee that data, during transmission through the Internet or while stored on our systems or otherwise in our care, is absolutely safe from intrusion by others.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Without limiting the previous sentence, if we have a business relationship with you or an entity you represent, we will retain your personal data for at least the duration of that relationship. Otherwise, the length of time for which we retain information will depend on the nature of the information. Specifically:
Profile Data and Identity Data: We retain your profile data and identity data for as long as your account is active and a reasonable period thereafter in case you decide to re-activate your account. Where we retain information for service improvement and development, we only use the information to uncover collective insights about the use of our services, not to specifically analyze personal characteristics about you.
Information you share on the Picarro Community: If your account is deactivated or disabled, some of your information and the content you have provided will remain in order to allow other users to make full use of the Picarro Community. For example, we may continue to display content you provided such as posts or responses.
Marketing information: If you have elected to receive marketing communications from us or if we have determined that we have a legitimate interest in marketing to you, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our services, such as when you last opened an email from us. We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.
The Website may include links that direct you to other websites or services whose privacy practices may differ from ours. If you submit information to any of those third party sites, your information is governed by their privacy policies, not this one. We encourage you to carefully read the privacy policy of any website you visit.
You have certain choices available to you when it comes to your information. Below is a summary of those choices, how to exercise them and some limitations.
You have the right to request a copy of your information, to object to our use of your information (including for marketing purposes), to request the deletion or restriction of your information, to request your information in a structured, electronic format, the right to have your personal data rectified if it is incorrect, the right to withdraw your consent to processing of your personal data (where the consent is the lawful basis for such processing) and, if the GDPR applies, the right to lodge a complaint with a supervisory authority, which may be the Data Protection Authority in the country where you reside.
You can exercise some of the choices by accessing the Picarro Community or the Website and using settings available within your account. Otherwise, you can contact us to exercise your rights using the contact information below.
You may opt out of receiving marketing communications and automated messages from us by using the unsubscribe link within each email or by contacting us to have your contact information removed from all promotional and transactional emails. However, even after you opt out from receiving promotional messages from us, you will continue to receive certain transactional messages from us regarding our products and services such as payment failure notices or account suspension notices sent via email.
To contact Picarro with any comments, inquiries, or complaints:
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Picarro commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Picarro at:
Email: privacy@picarro.com
Phone: +1 408 962 3900
Postal Correspondence:
Picarro, Inc.
Attn: Privacy
3105 Patrick Henry Drive
Santa Clara, CA 95054
USA
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Picarro commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to Judicial Arbitration and Mediation Services(JAMS), an alternative dispute resolution provider operating in 30 locations worldwide. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit the JAMS website (https://www.jamsadr.com/DPF-Dispute-Resolution) for more information or to file a complaint. The services of JAMS are provided at no cost to you.
If neither Picarro nor our dispute resolution provider resolves your complaint satisfactorily, you may explore invoking binding arbitration through the Data Privacy Framework Panel, which is more fully described in Annex I of the Data Privacy Framework Principles: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2.
By using our Website or otherwise interacting with Picarro, you agree to this Privacy Policy. Although most changes are likely to be minor, Picarro may change its Privacy Policy from time to time. The date of the most recent update of this document will always be displayed at the beginning of this page. Picarro encourages visitors to frequently check this page for any changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change provided, however, where we feel it is necessary and appropriate, we may also email you regarding changes to this Privacy Policy.
To support the Website and the Picarro Community, we use different service providers that may store and process personal data about you. This section provides important information about the identity, location, and role of these Data Processors/Subprocessors. We use different types of Processors/Subprocessors to perform various functions as explained in the table below.
Processor/Subprocessor | Role | Link to Partner’s Privacy Policy |
---|---|---|
Amazon Web Services | Hosting of our SaaS based managed service product, P-Cubed | Link |
Box | File Storage | Link |
Cloudflare | To anonymously track network security policies applied to visitors of the Picarro Website. | Link |
ESRI | Application platform performing spatial analysis of collected data and customer provided GIS assets. | Link |
Google Analytics | To identify returning users to Picarro Website and to analyze Website user behavior, for example, the number of pages viewed, and the duration of time spent by a user on the Website. | Link |
Google Maps API | Location based APIs for processing P-Cubed data | Link |
Lacework | Unified security platform integrated into AWS to monitor, alert and manage cloud assets. | Link |
Microsoft | Office 365 – email servers and file storage, Bing Maps - location based services for P-Cubed | Link |
NetSuite | ERP/CRM | Link |