This Privacy Notice was last updated: October 10, 2023
Data privacy is important to HID® Global Corporation, an ASSA ABLOY group company, and its subsidiaries and affiliates (“HID Global” or “we” or “us”). This Privacy Notice describes the Personal Data that we collect about you as a visitor to HID Global’s website, or other HID Global websites that link to this Privacy Notice, how we use it, with whom we share it, and describes your rights with regard to the Personal Data we have about you.
If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, visit the CCPA Privacy Notice Tab.
HID Global collects, processes, and retains information about you when you visit our websites, which may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exist pages, the files viewed on our site (e.g. HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends in the aggregate and administer the site.
You may choose to provide us with additional information, such as your name, email address, company information, street address, telephone number, or other information, to access protected information on our websites or so we can follow up with you after your visit. We may combine other publicly available information related to the organization from which you work for with the information that you provide to us. HID Global or HID Global service providers may observe your activities, interactions, preferences, transactional information, and other computer and connection information (such as IP address) relating to your use of our websites and our services.
If you are a licensed or other authorized user of any of our online platforms, we process your name, email address, username, password, IP address, job title, phone number, information about the company where you work, actions you have taken in the applications on the platform, such as record creation, changes, input, responses, analysis, and approvals, and tickets filed on your behalf related to our platform.
We may also use log files, cookies and similar technologies. For more information about our use of these technologies and how to control them, see our Cookies and Similar Technologies section below. We may collect and store this information and combine this information with other Personal Data you may have provided.
If you register online on one of HID Global’s websites, we may also collect and store certain information in the aggregate about your visit automatically including: 1) internet domain and IP address from which you accessed our website 2) the date and time you access our website; and 3) the pages the you visited. We may also collect general demographic and profile data from our website from time to time.
We may also obtain data from third parties, such as authorized distributors with which we offer services or engage in joint marketing activities. We protect data obtained from third parties according to the practices described in this Notice, plus any additional restrictions imposed by the source of the data.
When you download mobile applications, we automatically collect technical data and related information about the devices being used for the Services, including information on the type of device you use, operating system version, application software, peripherals and the device identifier; push ID (“UDID”).
You have choices about the data we collect. When you are asked to provide Personal Data, you may decline. But if you choose not to provide data that is necessary to provide a product or feature, you may not be able to use that product or feature.
How We Use Personal Data
HID Global uses the data we collect to operate our business and provide you the products and services we offer, which includes using data to improve our products and personalize your experiences. We also may use the data to communicate with you, for example, informing you about your account and product information, to send email communications or make phone calls for the purpose of sending you information about upcoming webinars and events, product announcements, newsletters and educational content. We will use the aggregate data that we collect internally in order to better understand and assist our customers and to help improve our website and services.
If you have a contract or other agreement in place with us, we process personal data about you in order to fulfill the following obligations to you under that contract or agreement to:
- Provision your account on our platform
- Authenticate you to enable you to access your account on our platform, including additional users of the solution
- Provide customer service and support, and investigate issues that you raise
- Communicate with you, including via email, about your use of our solutions
We process Personal Data for certain Legitimate Interests, which include some or all of the following:
- where the processing enables us to enhance, modify, personalize or otherwise improve our services / communications for the benefit of our customers
- to provide maintenance and support services
- to identify and prevent fraud
- to enhance the security of our network and information systems
- to better understand how people interact with our websites
- to provide postal communications which we think will be of interest to you
- to determine the effectiveness of promotional campaigns and advertising.
Whenever we process data for these purposes we will ensure that we always keep your Personal Data rights in high regard and take account of these rights. You may object to this processing if you wish. EU residents may visit our GDPR Personal Data Inquiries page for further information on your rights. All others may send inquiries to [email protected]. Please bear in mind that if you object this may affect our ability to carry out tasks above for your benefit or to provide our products or features.
“Legitimate Interests” means HID Global’s interests in conducting and managing our business to enable us to give you the best service/products and the best and most secure experience.
For example, we have an interest in making sure our marketing is relevant for you, so we may process your information to send you marketing that is tailored to you and your company’s interests. It can also apply to processing that is in your interests as well. For example, we may process your information to protect you against fraud when transacting on our website, and to ensure our websites and systems are secure.
When we process your Personal Data for our Legitimate Interests, we make sure to consider and balance any potential impact on you (both positive and negative), and your rights under data protection laws. Our legitimate business interests do not automatically override your interests - we will not use your Personal Data for activities where our interests are overridden by the impact on you (unless we have your consent).
Reasons We Share Personal Data
We share your Personal Data with your consent or as necessary to complete any transaction or provide any product you have requested or authorized. In addition, we share Personal Data among ASSA ABLOY controlled affiliates and subsidiaries. We also share Personal Data with vendors or agents working on our behalf for the purposes described in this Notice, such as IT service providers which host, develop or offer support. Companies we've hired to assist in protecting and securing our systems and services may need access to Personal Data to provide those functions and they are not allowed to use Personal Data they receive from us for any other purpose. In such cases, these companies must abide by our data privacy and security requirements and agree to any data protection agreements as we may require.
HID Global does not sell your Personal Data to third parties. However, we may share your business contact information with our authorized distributors in order to assist you in purchasing our products or to contact you via phone or email for the purpose of marketing our products and services.
We may also disclose Personal Data as part of a corporate transaction such as a merger or sale of assets.
Disclosure Required by Law
HID Global may cooperate with law enforcement agencies in identifying users who use the website or HID Global’s products or services for illegal activities. Therefore, HID Global will respond to subpoenas, warrants, or other court orders regarding information concerning any user. HID Global will, at HID Global’s discretion, disclose information, including Personal Data, if HID Global reasonably believes that HID Global is required to do so by law, that such disclosure is necessary to protect HID Global from legal liability, or that HID Global should do so to protect the integrity of the website or the products or services.
How to Access & Control Your Personal Data
Upon request, HID Global will provide you with information about whether we hold any of your Personal Data. We will retain your information for as long as your account is active or as needed to provide you our products and services. Additionally, we will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
EU residents may visit our GDPR Personal Data inquiries page for more information on how to exercise your rights or make an inquiry regarding the Personal Data we have about you. Others may send an inquiry to [email protected].
If you would like to opt-out of receiving sales and marketing communications from us, you may update your communication preferences here.
Links to Third Party Sites
Cookies and Similar Technologies
What are cookies
Cookies are small pieces of text sent by your web browser by a website you visit. A cookie file is stored in your web browser and allows the Service or a third-party to recognize you and make your next visit easier and the Service more useful to you.
Cookies can be "persistent" or "session" cookies. Persistent cookies save a file on your computer permanently. It can then be used to customize the web page as the choices and user interests. Session cookies are sent between your computer and the server to access information while you are browsing. Session cookies to not identify you personally and disappear when you turn off your browser. All of our websites use “session cookies”.
Notice to End Users
Many HID Global products are intended for use by organizations and are administered to you by your organization. Your use of HID Global products may be subject to your organization's policies, if any. If your organization is administering your use of HID Global’s products, please direct your privacy inquiries to your administrator. HID Global is not responsible for the privacy or security practices of our customers, which may differ from those set forth in this Privacy Notice.
Wherever Personal Data is within HID Global or on its behalf, HID Global will take reasonable steps to protect the Personal Data from loss, misuse and unauthorized access, disclosure, alteration and destruction. HID Global trains employees on its Information Security Policies and guidelines and makes them available to its business partners as necessary. In addition, HID Global and its business partners enter into confidentiality agreements that require that: (i) care and precautions be taken to prevent loss, misuse, or disclosure of Personal Data and (ii) any service providers only use Personal Data to perform services on behalf of HID Global.
Our computer systems are currently based in the United States, so we may transfer, access, or store personal data about you outside of the European Union (the “EU”), European Economic Area (the “EEA”), Switzerland, or another country that requires legal protections for international data transfer.
Whenever we do, we ensure an adequate level of protection is provided for the information using one or more of the following approaches:
- We may transfer personal information to countries that have privacy laws that have been recognized by the country from which the data are transferred as providing similar protections for the data (“adequacy”).
- We may enter into written agreements, such as standard contractual clauses and other data transfer agreements, with recipients that require them to provide the same level of protection for the data.
- We may seek your consent for transfers of your personal information for specific purposes.
- We may rely on other transfer mechanisms approved by authorities in the country from which the data are transferred. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Data Protection Framework
HID complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. HID has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. HID has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. View our full Data Protection Framework Statement here.
This Privacy Notice may be updated from time to time as HID Global's services change and expand. We suggest that you review the Privacy Notice periodically. In the event of a material change, we will post a change notice on our website and we may notify individuals of such changes through contact information that we have for such individuals prior to the change becoming effective. If we amend the Privacy Notice, the new Notice will apply to Personal Data previously collected by HID Global only insofar as the rights of the individual affected are not reduced.
Inquiries and complaints
If you believe HID Global maintains your personal data in one of the services discussed in this Privacy Notice, you may direct inquiries or complaints to [email protected]. HID Global will respond within 45 days. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. If neither HID Global nor our dispute resolution provider resolves your complaint, and you are located in the EEA, you have the right to lodge a complaint with the competent supervisory authority.
HID Global Corporation
611 Center Ridge Drive
Austin, TX 78753
If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, visit the CCPA Privacy Notice Tab.
Statement of Data Protection Framework Participation
This statement outlines HID’s Notice of Certification Under the EU-US Data Protection Framework and Swiss-US Data Protection Framework.
Effective July 10, 2023
HID has certified certain of our services under the EU-U.S. Data Protection Framework and the Swiss-U.S. Data Protection Framework (the certification can be found here).
HID adheres to the principles of the EU-U.S. Data Protection Framework and Swiss-U.S. Data Protection Framework with respect to personal data submitted by HID’s direct customers and its authorized distributors (collectively, “Customers”) where EU and Swiss customer personal data is stored or processed in our U.S. based computer systems, including our online services.
HID collects, processes, and retains information about you when you visit our websites, which may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exist pages, the files viewed on our site (e.g. HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends in the aggregate and administer the site.
You may choose to provide us with additional information, such as your name, email address, company information, street address, telephone number, or other information, to access protected information on our websites or so we can follow up with you after your visit. We may combine other publicly available information related to the organization from which you work for with the information that you provide to us. HID or HID service providers may observe your activities, interactions, preferences, transactional information, and other computer and connection information (such as IP address) relating to your use of our websites and our services.
HID’s computer systems are primarily based in the United States, as such, EU customer information may be transferred to these systems in order for HID to provide the contracted service, including card personalization services and information collected via our mobile applications.
HID provides online tools that our Customers use to operate aspects of their businesses. In providing these tools, HID processes data our Customers submit to our services or instruct us to process on their behalves. While HID’s Customers decide what data to submit, it typically includes information about their employees (e.g., business contact information), purchases, and billing information.
Purposes of data processing:
HID processes data submitted by website visitors and Customers for the following purposes:
- Providing HID’s products and services to our customers (to fulfill these purposes, HID may access the data to provide the services)
- Correcting and addressing technical or service problems, or following instructions of the HID Customer who submitted the data, in relation to contractual requirements
- Gaining a better understanding of how people interact with our websites
- Improving our products and personalizing your experiences
- Informing you about your account and product information
- Sending email communications for the purpose of providing information about upcoming webinars and events, product announcements, newsletters and educational content
- Enhancing, modifying, personalizing or otherwise improving our services and communications for the benefit of our Customers
- Identifying and preventing fraud
- Enhancing the security of our network, mobile applications and information systems
Inquiries and complaints:
In compliance with the EU-U.S. DPF and the Swiss-U.S. DPF, HID commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF should first contact HID at: [email protected].
In compliance with the EU-U.S. DPF and the Swiss-U.S. DPF, HID commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF to TRUSTe Privacy Dispute Resolution, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://feedback-form.truste.com/watchdog/request for more information or to file a complaint. The services of Truste are provided at no cost to you.
If neither HID nor our dispute resolution provider resolves your complaint, you may have the possibility to engage in binding arbitration through the EU-U.S. Data Privacy Framework Panel.
Third parties who may receive personal data: HID uses a limited number of third-party service providers to assist us in providing our services to customers. These third party providers perform database monitoring and other technical operations, assist with the transmission of data, and provide data storage services. These third parties may access, process, or store personal data in the course of providing their services. HID maintains contracts with these third parties restricting their access, use and disclosure of personal data in compliance with our Data Protection obligations, and HID may be liable if they fail to meet those obligations and we are responsible for the event giving rise to damage.
Your rights to access, to limit use, and to limit disclosure: EU individuals and Swiss individuals have rights to access personal data about them, and to limit use and disclosure of their personal data. With our Data Protection certification, HID has committed to respect those rights. If you wish to request access, to limit use, or to limit disclosure, please provide the name of the HID Customer who submitted your data to our services. We will refer your request to that Customer, and will support them as needed in responding to your request.
U.S. Federal Trade Commission enforcement: The Federal Trade Commission has jurisdiction over HID’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
Compelled disclosure: HID may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Liability for Onward Transfers to Third Parties: HID shall remain liable under the Principles if its agent processes such personal information in a manner inconsistent with the Principles, unless the organization proves that it is not responsible for the event giving rise to the damage.
This PRIVACY NOTICE FOR CALIFORNIA RESIDENTS supplements the information contained in the Privacy Notice of HID and its subsidiaries (collectively, “we,” “us,” or “our”) and applies solely to visitors, users, and others who reside in the State of California (“consumers” or “you”) when you visit the HID website or provide contact information to receive HID services (collectively, our “Services”). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and other California privacy laws. Any terms defined in the CCPA have the same meaning when used in this notice.
Information We Collect
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“personal information”). In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:
|A. Identifiers.||A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name||YES|
|B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).||A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.||YES|
|C. Protected classification characteristics under California or federal law.||Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).||NO|
|D. Commercial information.||Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.||NO|
|E. Biometric information.||Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.||NO|
|F. Internet or other similar network activity.||Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.||YES|
|G. Geolocation data.||Physical location or movements.||YES|
|H. Sensory data.||Audio, electronic, visual, thermal, olfactory, or similar information.||NO|
|I. Professional or employment-related information.||Current or past job history or performance evaluations.||NO|
|J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).||Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.||NO|
|K. Inferences drawn from other personal information.||Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.||NO|
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from our customers, channel partners or their agents. For example, from information our clients provide to us related to the Services for which they engage us.
- Directly from you. For example, through information collected from you when you fill out a contact us form to request information or services.
- Directly and indirectly from you when using our Services or visiting our website. For example, usage details collected automatically in the course of your interaction with our platform or website.
Use of Personal Information
We may use or disclose the personal information we collect for one or more of the following business purposes:
- To fulfill or meet the reason for which the information is provided. For example, to submit this information to our channel partners for the purpose of completing a sale.
- To provide support services for our products, as requested by you.
- To provide you with email alerts, event registrations and other notices concerning our products or Services, or events or news, that may be of interest to you.
- To improve our Services to you.
- To carry out our obligations and enforce our rights arising from contracts entered into between you and us, including for billing and collections.
- To better understand how users interact with our websites.
- To determine the effectiveness of promotional campaigns
- For testing, research, analysis and product development.
- As necessary or appropriate to protect the rights, property or safety of us, our clients or others.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:
Category A: Identifiers.
Category B: California Customer Records personal information categories.
Category D: Commercial information.
We disclose your personal information for a business purpose to the following categories of third parties:
- Our customers, channel partners or their agents for which you have engaged in a business contract.
- Service providers.
- Third parties to whom you or your agents authorize us to disclose your personal information in connection with our Services.
In the preceding twelve (12) months, we have not sold any personal information.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- Our business or commercial purpose for collecting that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
Deletion Request Rights
You have the right to request that we delete any of your personal information we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service providers to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by email at [email protected] with the subject line: CCPA.
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to the registered email associated with the account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you use of our Services.
- Provide you a different level or quality of Services.
Changes to Our Privacy Notice
We reserve the right to amend this Privacy Notice at our discretion and at any time. The date this Privacy Notice was last updated is identified at the bottom of this page. You are responsible for periodically visiting the HID website and this Privacy Notice to check for any changes.