Privacy Shield Policy
This Policy applies to all personal information received by Exton Soft LLC, including its wholly owned (directly and indirectly) subsidiaries (hereinafter “XtonTech”) from residents of the EU or Switzerland. In most cases, the data we receive will be in electronic form and relates to our customers. It may include personal information about our customers’ employees, business contacts, clients, and any other individuals with whom our customers have dealings. When we receive and process personal information provided to us by our customers, we do so as “data processors” acting on the instructions of our customers and/or the court system.
1. Collectively, “Information” means “Personal Information” that (1) is transferred from the EU or Switzerland to the United States; (2) is recorded in any form; (3) is about, or pertains to a specific individual; and (4) can be linked to that individual; and/or Sensitive Personal Information.
2. With regard to information received by XtonTech from residents of the EU, “Sensitive Personal Information” shall mean Personal Information that reveals race, ethnic origin, sexual orientation, political opinions, religious or philosophical beliefs, trade union membership, or that concerns an individual’s health.
3. With regard to information received by XtonTech from residents of Switzerland, “Sensitive Personal Information” shall mean Personal Information specifying medical or health conditions, personal sexuality, racial or ethnic origin, political opinions, religious, ideological or trade union-related views or activities, or information on social security measures or administrative or criminal proceedings and sanctions, which are treated outside pending proceedings.
4. “Agent” is any third party that collects, uses, or stores Information in support of XtonTech engagements.
3. Privacy Shield Principles
The practices to which XtonTech is committed are based on the EU-U.S. Privacy Shield Principles and the Swiss-U.S. Privacy Shield Principles negotiated between the European Commission and the responsible Swiss government agency, respectively and the United States Department of Commerce (collectively, the “Privacy Shield Principles”). Adherence by XtonTech to these Privacy Shield Principles provides the necessary level of protection required by the EU/Swiss Directives for the transfer of personal information outside the EU/Switzerland. XtonTech’s execution of these principles may be limited in certain circumstances, in particular:
(a) where there is a conflicting or overriding legal obligation;
(b) to the extent expressly permitted by any applicable law, rule or regulation; or
(c) where XtonTech receives personal information as a “data processor” acting on the instructions of a customer. As XtonTech will be receiving personal information from the EU/Switzerland in this case merely for processing, its principle obligations are limited to onward transfer, security, access, and enforcement. XtonTech’s customer remains responsible for notice, choice, and data integrity.
Notice: XtonTech receives data to be processed and/or stored, the contents of which may, or may not be Information. Notice will be provided in clear language when individuals are first asked to provide Information to XtonTech, or as soon as practicable thereafter, and in any event before XtonTech uses such Information for a purpose other than that for which it was originally collected or processed by the transferring organization, or discloses it for the first time to a third party.
Choice: Where XtonTech is the collector of Information and Choice is permissible, it will offer individuals the opportunity to choose (opt-out) whether their Information is:
(a) to be disclosed to a third party (unless that disclosure is allowed or required by contract), or
(b) to be used for a purpose that is not consistent with the purpose for which that Information was originally collected, or subsequently authorized by the individual.
XtonTech will provide individuals with reasonable mechanisms to exercise their choices.
Onward Transfers: In the event XtonTech transfers Information, it will obtain assurances from its Agents, prior to such transfer, that they will safeguard the Information in a manner consistent with this Policy. Every Agent utilized enters into a contractual relationship with XtonTech, which includes confidentiality and non-disclosure clauses, and provides the same level of commitment to and protections, as required by the Privacy Shield Principles. XtonTech remains responsible and liable under the Privacy Shield Principles if Agents that it engages to process the personal data on its behalf do so in a manner inconsistent with the Privacy Shield Principles, unless XtonTech can prove that it is not responsible for the event giving rise to the damage.
Security: XtonTech takes adequate and reasonable administrative, technical, and physical precautions to protect Information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction. XtonTech utilizes commercially accepted security equipment, techniques, and procedures to control, monitor and record access to any facility containing Information.
Data Integrity: XtonTech will use Information only in ways that are relevant and compatible with the purpose for which that information was collected or provided to XtonTech. XtonTech will take reasonable steps to ensure that all data collected, processed and/or stored is protected from destruction, corruption, or use in a manner inconsistent with the purpose for which it received the information.
Access: Upon request, and where permissible by law and purpose for which it possesses the Information, XtonTech will grant individuals reasonable access to Information that it holds about them. In addition and where permissible, XtonTech will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete, except where the burden or expense of providing access would be disproportionate to the risks of the individual’s privacy, or where the rights of another individual may be violated. A reasonable fee may be charged as compensation for our expenses incurred in accessing, changing, or deleting the personal information.
Enforcement: XtonTech will conduct compliance audits at least annually of its relevant privacy practices to verify adherence to this Policy and will self-certify with the US Department of Commerce. Further, XtonTech will conduct follow up investigations to verify that attestations and assertions regarding practices are true. Violations and/or complaints may be made to XtonTech via email to Legal@XtonTech.com and XtonTech engages in training to support implementation and compliance. Any employee that XtonTech determines is in violation of this Policy will be subject to disciplinary action.
4. Contact Information
Please refer all questions or comments regarding this Policy to:
Exton Soft LLC (DBA Xton Technologies, LLC)
Peter Senescu, Managing Member
256 Eagleview Blvd, STE 259, Exton, PA 19341
This Privacy Shield Policy is available at https://www.XtonTech.com/company/privacy-shield-policy
5. Changes To This Privacy Shield Policy
This Policy may be amended from time to time to remain consistent with the requirements of the Privacy Shield Principles and other applicable laws.
The effective date of this Privacy Shield Policy is: January 10, 2020