Privacy and Cookies Policies

SPECTRA MEDICAL DEVICES PRIVACY POLICY

Last modified: December 10, 2023

Spectra Medical Devices, LLC (“Spectra Medical Devices” or “we” or “us”) respects your privacy and is committed to protecting it through our compliance with this policy. This Privacy Policy (our “Privacy Policy”) describes the information we collect, how we collect information, and the reasons we collect information. This Privacy Policy also describes the choices you have regarding the information Spectra Medical Devices collects, including how you can manage, update, or request to delete information.

Please take a moment to review this Privacy Policy. You may scroll through this Privacy Policy or use the headings below. It is important that you understand this Privacy Policy. By using our Platform, you are agreeing to the terms of this Privacy Policy. If you have any questions or concerns about this Privacy Policy, you may contact us at any time using the Contact Information at the end of this Policy, or use the https://www.spectramedical.com/contact/ page of our Platform.

If you do not agree with our policies and practices, your choice is not to use our Platform. By accessing or using our Platform you agree to this Privacy Policy. This Privacy Policy may change from time to time (see Changes to Our Privacy Policy). Your continued use of our Platform after we make changes is deemed to be acceptance of those changes, so please check this Privacy Policy periodically for updates.

CONTENTS

  1. Key Terms & Definitions and Scope of Our Privacy Policy
  2. Personal Information
  3. Why and How We Use Your Personal Information
  4. Why and How We Share Your Personal Information
  5. Your Choices for How We Collect, Use and Share Your Personal Information
  6. Accessing, Correcting and Deleting Personal Information
  7. Children’s Privacy
  8. Jurisdiction-Specific Privacy Rights
  9. Data Security
  10. Changes to Our Privacy Policy
  11. Contact Information
  12. Glossary
  13. Spectra Medical Devices GDPR Privacy Addendum
  14. Spectra Medical Devices CALIFORNIA Privacy Addendum

1. Key Terms & Definitions and Scope of our Privacy Policy

It is helpful to start by explaining some of our key terms and definitions used in this Privacy Policy.

Personal Information” or “Personal Data”: Information identifying, relating to or about an identified or identifiable individual, as described more fully in this Policy.

Platform”: Our Websites and related functionality and online services, as applicable.

Privacy Policy” or “Policy”: This privacy policy.

Products”: Any products available for purchase on or through our Platform, or that we otherwise provide or sell to you.

Website”: Our websites located at www.spectramedical.com and https://store.spectramedical.com/.

Spectra Medical Devices,” “we,” “us”: Spectra Medical Devices, LLC.

Please refer to our Glossary for additional explanations of terms and phrases used in this Policy.

When does our Privacy Policy apply?

This Privacy Policy describes the types of information we may collect from you when you visit or use our Platform or any components of our Platform, and when we communicate with you electronically, such as through our Platform, email, and other electronic messages between Spectra Medical Devices and you.

When does our Privacy Policy not apply?

This Privacy Policy does not apply to information (a) we collect from you through any offline or in-person or face-to-face interactions we have with you, or through an audio-only telephone conversations; (b) by any other websites or platforms operated by us, unless the website or platform is listed above or links to this Privacy Policy; (c) collected by any third-party website that we may provide a link to or that is accessible from our Platform; or (d) covered in part or in whole by a separate privacy policy provided by us (e.g., relating specifically to health information, financial information, other special information, etc.).

Terms of Use.

This Privacy Policy is incorporated into and governed by our Terms of Use, which is found at found at https://www.spectramedical.com/terms-of-use/, incorporated herein by reference.

2. Personal Information

What is Personal Information?

Personal Information is information that you provide to us which personally identifies you, such as your name, address, email address, telephone number, medical license number, or billing information, or other data that can be reasonably linked to such information by Spectra Medical Devices, such as information we associate with your Spectra Medical Devices account.

What types of Personal Information do we collect?

We collect and use Personal Information in order to operate and provide our Platform to you, including our Products. You may provide Personal Information to us, and we may collect Personal Information from you automatically as you use and navigate through our Platform.

How do we collect your Personal Information?

Information you provide to us. You may provide Personal Information to us through our Platform. For example, you may be able to register to use our Platform or create an account with us, which allows or requires you to provide certain information to us (e.g., contact information such as your name, email address, telephone number, etc.). You provide Personal Information and other information to us when you contact us through our Platform.

When you purchase Products. You can purchase Products, or make payments to us, through our Platform. In these situations, we collect your credit card, debit card or other payment card information or bank or other financial account information. We use third-party payment processors to collect and process your payment information.

Online Activity. We collect information about your activity on our Platform, Internet, network, and other online activity information, such as browsing history, search history, and information regarding your interaction with our Platform and other websites. We use various technologies to collect and store location information, including cookies, pixels or pixel tags, local storage, such as browser web storage or application data caches, databases, session replay, and server logs.

Information we collect automatically as you use our Platform. We collect Personal Information and information automatically about the computers, devices, browsers and your Internet activity as you use and interact with our Platform. The information we collect typically includes Unique Identifiers, browser type and settings, device types and settings, operating system, mobile network information including carrier name and phone number, and application version number. We also collect information about the interaction of your browsers and devices with our Platform, such as IP address, device type, system activity, wireless carrier name (when you use a wireless or mobile device), and the date, time, and referrer URL of your request. Note that we obtain your consent before using or sharing your Personal Information for purposes of non-essential cookies or tracking technologies. We use the following technologies to automatically collect data:

  • Cookies. We and our service providers may use cookies, web beacons, and other technologies to receive and store certain types of information whenever you interact with our Platform through your computer or mobile device. Some of the cookies we use are "session" cookies, meaning that they are automatically deleted from your hard drive after you close your browser at the end of your session. Session cookies are used to optimize performance of the Website and to limit the amount of redundant data that is downloaded during a single session. We also may use "persistent" cookies, which remain on your computer or device unless deleted by you (or by your browser settings). We may use persistent cookies for various purposes, such as statistical analysis of performance to ensure the ongoing quality of our Platform. We and third parties may use session and persistent cookies for analytics and advertising purposes, as described herein.
  • Facebook Pixel and Instagram. We use Facebook Pixel and Instagram, a web analytics and advertising service provided by Facebook Inc. (“Facebook”) on our Platform. With its help, we and our customers can keep track of what users do after they see or click on a Facebook or Instagram advertisement, keep track of users who access our Platform or advertisements from different devices, and better provide advertisements to our target audiences. The data from Facebook Pixel and Instagram is also saved and processed by Facebook. Facebook can connect this data with your Facebook or Instagram account and use it for its own and others advertising purposes, in accordance with Facebook’s Data Policy which can be found at https://www.facebook.com/about/privacy/. Please click here if you would like to withdraw your consent for use of your data with Facebook Pixel https://www.facebook.com/settings/?tab=ads#_=_.
  • Google Ads (AdWords). Google Ads (AdWords) remarketing service is provided by Google Inc. You can opt-out of Google Analytics for Display Advertising and customize the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads. Google also recommends installing the Google Analytics Opt-out Browser Add-on – https://chromewebstore.google.com/detail/google-analytics-opt-out/fllaojicojecljbmefodhfapmkghcbnh?hl=en&pli=1 for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics. For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en.
  • Google Analytics. We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of our Platform. Google Analytics uses cookies, to help our Platform analyze how users use our Website. You can find out more about how Google uses data when you visit our Platform by visiting “How Google uses data when you use our partners' sites or apps”, (located at www.google.com/policies/privacy/partners/). For more information, please visit Google and pages that describe Google Analytics, such as www.google.com/analytics/learn/privacy.html.
  • LinkedIn. We use LinkedIn cookies to, among other activities, store and track visits across websites. You can find more information on the data collected by LinkedIn by visiting their Privacy Policy: https://www.linkedin.com/legal/privacy-policy.
  • X/Twitter. We use X/Twitter Pixel, a remarketing service, provided by X/Twitter, Inc. for marketing and advertising purposes. To learn more about how Twitter uses your Personal Information, we encourage you to visit Twitter’s privacy policy at https://twitter.com/en/privacy.
  • Yahoo. We use Yahoo cookies, pixels, and tags to uniquely identify browsers and devices to assist in personalizing your experience while on our Platform and to understand how you interact with our Platform. For more information on the services Yahoo provides, please visit here.

Third-Party Sources. In some circumstances, Spectra Medical Devices also collects information about you from publicly-accessible sources. We may collect information about you from trusted partners, such as marketing partners who provide us with information about our potential customers, and security partners who provide us with information to protect against fraud and abuse of our Platform.

3. Why and How We Use Your Personal Information

As described more fully below, we use information that we collect about you or that you provide to us, including any Personal Information for the following purposes:

  • Provide our Platform and related services to you.
  • Provide you with information or Products that you request or purchase from us.
  • Process your requests, purchases, transactions, and payments and prevent transactional fraud.
  • Support, develop, troubleshoot, and debug our Platform and Products.
  • Create, maintain, customize, and secure your account with us.
  • Provide you with notices about your account.
  • Provide you with support for the Platform and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
  • Personalize your Platform experience and to deliver content and product and service offerings relevant to your interests.
  • Provide personalized and interest-based advertising. (More information below.)
  • Administer surveys and questionnaires.
  • Provide you information about products and services, and other information that may be of interest to you.
  • Authenticate use, detect fraudulent use, and otherwise maintain the security of our Platform.
  • Help maintain the safety, security, and integrity of our Platform and Products.
  • Auditing relating to a current interaction with you and concurrent transactions, including, but not limited to, counting advertising impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with any applicable specification and other standards.
  • Detecting security incidents, responding to, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
  • Debugging to identify and repair errors that impair existing intended functionality.
  • Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
  • To respond to law enforcement requests, court orders, and subpoenas and to carry out our legal and contractual obligations.
  • Notify you about changes to our Platform or any products or services we offer or provide though them.
  • Allow you to participate in interactive features on our Platform.
  • In any other way we may describe when you provide the information.
  • Fulfill any other purpose for which you provide it.
  • For any other purpose with your consent.

Provide our Platform and Related Services. We use your Personal Information to operate, maintain, supervise, administer, improve and enhance our Platform and related Services, features and functionality. We use your contact information to communicate and interact with you, such as to send you emails about our Platform. We use the IP address assigned to your device to send you the data you request to display on your device. We use unique identifiers stored in cookies on your device to help us authenticate you as the person who should have access to certain areas and features of our Platform. We also use your information to ensure our Platform is working as intended, such as tracking outages or troubleshooting issues that you report to us. And we use your information for research and development for our business, and to make improvements to our Platform.

Analyze Use of the Platform. We use data collected from you and your devices for analytics and measurement to understand how our Platform is used. For example, we analyze data about your use of our Platform to accomplish tasks such as optimizing our Product designs. We use a variety of tools to do this, such as Google Analytics and similar third-party online data analytics services.

Personal Information Provided by Third Parties. We may use Personal Information collected automatically and associate it with Personal Information we collect in other ways or receive from third parties. It helps us to improve our Platform and to deliver a better and more personalized service by enabling us to:

  • estimate our audience size and usage patterns;
  • store information about your preferences;
  • customize our Platform according to your individual interests;
  • speed up your searches; and
  • recognize you when you return to our Platform.

Purchase Products from Us. When you purchase Products from us, you may provide us information such as your payment card or bank account information, shipping address or delivery instructions. We use this information for things such as processing, fulfilling, and delivering your order, and to provide support in connection with the Products you purchase.

Security and Legal Purposes. We use your information to help improve the safety and reliability of our Platform. This includes detecting, preventing, and responding to fraud, abuse, security risks, and technical issues that could harm Spectra Medical Devices, our users, or the public. Information may also be used in connection for legal reasons and purposes, such as to comply with applicable law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Use, including investigation of potential violations; and to detect, prevent, or otherwise address fraud, security, or technical issues; and to protect against harm to the rights, property or safety of Spectra Medical Devices, our users, or the public as required or permitted by law.

Personalized and Interest-Based Advertising. We may use your Personal Information to provide interest-based advertisements from us and that are customized to your particular preferences, including for companies that are not affiliated with us. See additional information under Why and How We Share Your Personal Information below for additional information about our sharing your Personal Information for personalized and interest-based advertising.

Advertising and Marketing. We may also use your information to contact you about our Products that may be of interest to you. Please contact us using the Contact Information at the end of this Policy, or use the Contact Us page of our Platform if you would like to opt out or change your preferences with respect to receiving advertising and marketing communications from us.

4. Why and How We Share Your Personal Information

We share Personal Information with third parties under certain circumstances and for certain purposes described throughout this Policy, including:

  • Service providers and others to operate our Platform. We share your Personal Information with our affiliates, vendors, service providers, and business partners, including providers and vendors we use for operating and maintaining our Platform, and its features, functionality and services. These third parties include data hosting and data storage partners, analytics, ad network, advertising (including interest-based advertising), technology services and support, and data security.
  • Our business purposes. We may share your Personal Information with our affiliates, vendors, service providers, and business partners, including providers and vendors we use for our business activities and operations generally, such as data hosting and data storage partners, analytics, ad network, advertising, technology services and support, and data security. We may also share your Personal Information with professional advisors, such as auditors, law firms, and accounting firms.
  • Personalized and interest-based advertising. We partner with third-party advertising networks that collect IP addresses, unique device identifiers, browser type, operating system, time zone, country, referring pages, and other information through the use of cookies, pixel tags, and server logs on our Platform. They use this information to provide you with interest-based advertisements that are customized to your particular preferences, including for companies that are not affiliated with us. You may see these interest-based advertisements on our Platform, as well as on third-party websites and apps, and across different devices you use. We may use this process to help us manage and improve the effectiveness of our marketing efforts. It also allows to display ads to our users about Spectra Medical Devices after they leave our Platform, and to track users after they see or click on an advertisement, keep track of users who access our Platform or advertisements from different devices, and better provide advertisements to our target audiences. The data collected through these tracking technologies is also saved and processed by our advertising and marketing service provider partners.

Advertisers and other third parties may assume or infer that users who interact with or click on an interest-based ad or content are part of the group that the ad or content is directed towards (for example, users in a particular geographical area or users who purchased or browsed for classical music). Third-party advertisers or advertising companies working on their behalf sometimes use cookies in the process of delivering content, including ads, directly to your browser or device, and they may automatically receive an IP address when this happens. They may also use cookies to measure the effectiveness of their ads, show you more relevant advertising content, and perform services on behalf of Spectra Medical Devices.

We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can learn more about interest-based advertisements and your opt-out rights and options from members of the Network Advertising Initiative (“NAI”) on its website (www.networkadvertising.org) and from members of the Digital Advertising Alliance on its website (www.aboutads.info).

  • Affiliates. We may share your Personal Information with our subsidiaries and affiliates.
  • Compliance with law. We may share your Personal Information to comply with applicable law or any obligations thereunder, including cooperation with law enforcement, judicial orders, subpoenas, and regulatory inquiries.
  • To Enforce our rights. We may share your Personal Information to enforce our Terms of Use and any other agreement, terms and conditions relating to your use of the Platform. We also may share information as needed to ensure the safety and security of our Platform and our users, and to detect, prevent, or otherwise address fraud, security, or technical issues.
  • Protect rights, property and safety. If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Spectra Medical Devices, our customers, or others. This may include exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
  • Business transfers. We may share your Personal Information to a buyer, potential buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of a bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our users are among the assets transferred.
  • De-identified information. We may also de-identified information, so that it cannot be reasonably used to identify any individual, with third parties for marketing, advertising, research, or any other purposes permitted by law.
  • Knowledge. We may share your Personal Information in any other way we may describe when you provide the information or to fulfill any other purpose for which you provide it.
  • Consent. We may share your Personal Information for any other purpose with your consent.

5. Your Choices for How We Collect, Use and Share Your Personal Information

We provide you with various choices on how you can opt out of our certain uses and sharing of your Personal Information. As a general rule, you cannot opt out of our collection, use and sharing of Personal Information to the extent it is necessary to provide the Platform or related basic services, features and functionality available on or through the Platform to you.

Cookies. We obtain your consent before using or sharing your Personal Information for purposes of non-essential cookies or tracking technologies. You can change the cookie settings you selected when using our Platform by using the cookie tool available in the bottom left hand corner of the website or by emailing [email protected]. You can also change the settings on your Internet browser or block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. These settings are usually found in the 'options' or 'preferences' menu of your internet browser. However, if you use your browser settings to block all cookies (including strictly necessary cookies), you may not be able to access or use all or areas and aspects of our Platform.

Personalized and interest-based advertising. You can generally opt out of receiving personalized and interest-based advertisements from third-party advertisers and ad networks who are members of the Network Advertising Initiative (NAI) or who follow the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising by visiting the opt out pages on the NAI website and DAA website. We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can also opt out of receiving targeted ads from members of the NAI on its website. You can learn more about interest-based advertisements and your opt out rights and options on the NAI website and DAA website.

Messages. If you do not wish to have your email address used by Spectra Medical Devices to send you advertising messages and content, you can opt out at any time by clicking the unsubscribe link at the bottom of any marketing emails you receive from us. You may have other options with respect to marketing and communication preferences through our Platform.

Do Not Track Signals. We also may use automated data collection technologies to collect information about your online activities over time and across third-party websites or other online services (behavioral tracking). Some web browsers permit you to broadcast a signal to websites and online services indicating a preference that they “do not track” your online activities.

6. Accessing, Correcting and Deleting Personal Information

Access, Corrections and Deletion. Please contact us using the Contact Information at the end of this Policy, or use the Contact Us page of our Platform if you have any questions regarding reviewing, accessing, correcting or deleting your Personal Information. Please promptly inform us of any changes or errors in any Personal Information we have about you to ensure that it is complete, accurate, and as current as possible. If you need to export or a copy of your data, please let us know and we will assist you with your request. You may also have certain deletion rights in accordance with applicable law. We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.

Retention of Personal Information. We retain the data we collect for different periods of time depending on what it is, how we use it and applicable legal requirements. We may retain some data for longer periods of time than other data when necessary for legitimate business or legal purposes, such as security, fraud and abuse prevention, or financial record-keeping. Please contact us using the Contact Information at the end of this Policy, or use the Contact Us page of our Platform if you have any questions about obtaining copies or the retention of your Personal Information.

7. Children’s Privacy

Our Platform is not intended for children under 18 years of age. No one under age 18 may provide us with any Personal Information on or through the Platform. We do not knowingly collect Personal Information from children under 18. If you are under 18, do not use or provide any information on our Platform or on or through any of its features, register on the Platform, make any purchases through the Platform, including your name, address, telephone number, email address, or any screen name or user name you may use. If we learn we have collected or received Personal Information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information directly from a child under 18, please contact us using the Contact Information at the end of this Policy.

8. JURISDICTION-SPECIFIC PRIVACY RIGHTS

The law in some jurisdictions may provide you with additional rights regarding our use of Personal Information. To learn more about any additional rights that may be applicable to you as a resident of one of these jurisdictions, please see the privacy addendum for your jurisdiction that is attached to this Privacy Policy.

Your California Privacy Rights

If you are a resident of California, you have the additional rights described in the California Privacy Addendum.

In addition, California Civil Code Section 1798.83 (California’s “Shine the Light” law) permits users of our Platform that are California residents and who provide Personal Information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of Personal Information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared your Personal Information with for the immediately prior calendar year (e.g., requests made in 2023 will receive information regarding such activities in 2022). You may request this information once per calendar year. To make such a request, please send an email to [email protected] or write us at our postal address provided at the end of this Policy.

Your GDPR Privacy Rights

If you are a resident of the European Economic Area, Switzerland, or the United Kingdom, you have the additional rights described in our GDPR Privacy Addendum.

9. Data Security

Security Measures. We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Platform, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to our Platform. Any transmission of Personal Information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures deployed on the Platform.

Consent to Processing of Personal Information in the United States. In order to provide our Platform, products, and services to you, we may send and store your Personal Information outside of the country where you reside or are located, including to countries that may not or do not provide an equivalent level of protection for your Personal Information. Your Personal Information may be processed and stored in the United States and federal, state, and local governments, courts, or law enforcement or regulatory agencies in the United States may be able to obtain disclosure of your information through the laws of the United States. By using our Platform, you represent that you have read and understood the above and hereby consent to the storage and processing of Personal Information outside the country where you reside or are located, including in the United States.

10. Changes to Our Privacy Policy

We may alter this Privacy Policy at any time. It is our policy to post any changes we make to our Privacy Policy on the home page or other prominent location on the Platform. If we make material changes to how we treat our users’ Personal Information, we will notify you as required or permitted by applicable law. The date this Privacy Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Platform and this Privacy Policy to check for any changes.

YOUR CONTINUED USE OF OUR PLATFORM FOLLOWING THE POSTING OF CHANGES CONSTITUTES YOUR ACCEPTANCE TO SUCH CHANGES.

11. Contact Information

If you have any questions, concerns, complaints, or suggestions regarding our Privacy Policy or the ways in which we collect and use your Personal Information described in this Privacy Policy, have any requests related to your Personal Information pursuant to applicable laws, or otherwise need to contact us, please contact us using this Contact Information, or use the Contact Us page of our Platform.

Spectra Medical Devices, LLC
299 Ballardvale Street, Suite 1
Wilmington, MA 01887

(978) 657-0889

[email protected]

12. Glossary

An Application Data Cache is a data repository on a device. It can, for example, enable a web application to run without an internet connection and improve the performance of the application by enabling faster loading of content.

Browser Web Storage enables websites to store data in a browser on a device. When used in "local storage" mode, it enables data to be stored across sessions. This makes data retrievable even after a browser has been closed and reopened. One technology that facilitates web storage is HTML 5.

A Cookie is a small file containing a string of characters that is sent to your computer when you visit a website. When you visit the site again, the cookie allows that site to recognize your browser. Cookies may store user preferences and other information.

Interest-based Advertising is sometimes referred to as personalized or targeted ads. Interest-based ads are used to display features, products, and services that might be of interest to the user.

A Pixel or Pixel Tag is a type of technology placed on a website or within the body of an email for the purpose of tracking certain activity, such as views of a website or when an email is opened. Pixel tags are often used in combination with cookies.

Server Logs. Like most websites, our servers automatically record the page requests made when you visit our sites. These “server logs” typically include your web request, Internet Protocol address, browser type, browser language, the date and time of your request, and one or more cookies that may uniquely identify your browser.

Session Replay provides the ability to replay a visitor's journey on a web site or within a mobile application or web application. Replay can include the user's view (browser or screen output), user input (keyboard and mouse inputs), and logs of network events or console logs. Session replay is used to help improve customer experience, analyze usability and help identify obstacles in conversion processes on websites. It can also be used to study a website's usability, customer behavior, interests, and the handling of customer service questions as the customer journey, with all interactions, can be replayed. It can also be used to analyze fraudulent behavior on websites.

A Unique Identifier is a string of letters, numbers and characters that can be used to uniquely identify a computer, device, personal device, browser or app. Different identifiers vary in how permanent they are, whether they can be reset by users, and how they can be accessed. On other platforms besides browsers (e.g., personal devices), Unique Identifiers are used to recognize a specific device or app on that device. Unique identifiers may also be incorporated into a device by its manufacturer (sometimes called a universally unique ID or UUID).

Spectra Medical Devices GDPR Privacy Addendum

Last modified: November 30, 2023

1. Introduction

This GDPR Privacy Addendum (the “GDPR Privacy Addendum”) supplements the information contained in our Privacy Policy (our “Privacy Policy”) and applies solely to the users of our Website who are located in the European Economic Area, the United Kingdom, or Switzerland. We adopt this GDPR Privacy Addendum to comply with the European Union’s General Data Protection Regulation, and any laws implementing the foregoing by any member states of the European Economic Area, the United Kingdom (including the UK Data Protection Act and the UK-GDPR), and or Switzerland (collectively, the “GDPR”). Unless otherwise defined in this GDPR Privacy Addendum, any terms defined in the GDPR or our Privacy Policy have the same meaning when used in this GDPR Privacy Addendum. When this GDPR Privacy Addendum is applicable to you, it takes precedence over anything contradictory in our Privacy Policy.

2. Data Controller, Data Protection Officer, and Representative

Spectra Medical Devices is the data controller of your Personal Information. At this time, Spectra Medical Devices is not required to appoint a Data Protection Officer or a representative in either the European Union or the United Kingdom, and has elected not to do so. Spectra Medical Devices or its representative may be contacted in any manner set forth below in the “Contact Information” Section of this GDPR Privacy Addendum.

3. Information We Collect About You and How We Collect It

The Personal Information we collect and the ways in which we collect it is described in our Privacy Policy. The Personal Information we collect from you is required to enter into a contract with Spectra Medical Devices, for Spectra Medical Devices to perform under the contract, and to provide you with our Products and services. If you refuse to provide such Personal Information or withdraw your consent to our processing of Personal Information (when appropriate), then in some cases we may not be able to enter into the contract or fulfill our obligations to you under it.

4. Lawful Basis for Processing Your Personal Information

The processing of your Personal Information is lawful only if it is permitted under the GDPR. We have a lawful basis for each of our processing activities (except when an exception applies as described below):

  • By using our Website, you consent to our collection, use, and sharing of your Personal Information as described in our Privacy Policy and this GDPR Privacy Addendum. If you do not consent to the terms of our Privacy Policy and this GDPR Privacy Addendum, please do not use the Website;
  • Legitimate Interests. We will process your Personal Information as necessary for our legitimate interests. Our legitimate interests are balanced against your interests and rights and freedoms and we do not process your Personal Information if your interests or rights and freedoms outweigh our legitimate interests. Our legitimate interests are to: facilitate communication between Spectra Medical Devices and you; detect and correct bugs and to improve our Websites; safeguard our IT infrastructure and intellectual property; detect and prevent fraud and other crime; promote and market our business; and check your credit and perform risk assessments;
  • To Fulfill Our Obligations to You under our Contract. We process your Personal Information in order to fulfill our obligations to you pursuant to our contract with you to deliver our goods and services to you; and
  • As Required by Law. We may also process your Personal Information when we are required or permitted to by law; to comply with government inspections, audits, and other valid requests from government or other public authorities; to respond to legal process such as subpoenas; or as necessary for us to protect our interests or otherwise pursue our legal rights and remedies (for instance, when necessary to prevent or detect fraud, attacks against our network, or other criminal and tortious activities), defend litigation, and manage complaints or claims.

5. Special Categories of Information

Some Personal Information processed by Spectra Medical Devices may be considered sensitive, including Personal Information that reveals information concerning your health. Spectra Medical Devices processes this information only with your consent or as otherwise permitted by the GDPR, including when our processing of such sensitive Personal Information is necessary for the purposes of preventative medicine, for the provision of health or social care or treatment or the management of health or social care systems and services.

6. Automated Decision Making

Spectra Medical Devices does not use your Personal Information with any automated decision making process, including profiling, which may produce a legal effect concerning you or similarly significantly affect you.

7. How We Use Your Information

We use your Personal Information as described in our Privacy Policy.

8. Disclosure of Your Information

We do not share or otherwise disclose your Personal Information for purposes other than to the entities and for the purposes described in our Privacy Policy.

9. Your Rights Regarding Your Information and Accessing and Correcting Your Information

The GDPR provides you with certain rights with regards to our processing of your Personal Information. These rights replace the similar rights provided in our Privacy Policy or are supplemental to such rights.

  • Access and Update. You can review and change your Personal Information by contacting us through the Contact Information below or by using the Contact Us page of our Website. You can also notify us of any changes or errors in any Personal Information we have about you to ensure that it is complete, accurate, and as current as possible. We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.
  • You have the right to restrict our processing of your Personal Information under certain circumstances. In particular, you can request we restrict our use of it if you contest its accuracy, if the processing of your Personal Information is determined to be unlawful, or if we no longer need your Personal Information for processing but we have retained it as permitted by law.
  • To the extent the Personal Information you provide Spectra Medical Devices is processed based on your consent and that we process it through automated means, you have the right to request that we provide you a copy of, or access to, all or part of such Personal Information in structured, commonly used and machine-readable format. You also have the right to request that we transmit this Personal Information to another controller, when technically feasible.
  • Withdrawal of Consent. To the extent that our processing of your Personal Information is based on your consent, you may withdraw your consent at any time by closing your account. Withdrawing your consent will not, however, affect the lawfulness of the processing based on your consent before its withdrawal, and will not affect the lawfulness of our continued processing that is based on any other lawful basis for processing your Personal Information.
  • Right to be Forgotten. You have the right to request that we delete all of your Personal Information. We cannot delete your Personal Information except by also deleting your user account, and we will only delete your account when we no longer have a lawful basis for processing your Personal Information or after a final determination that your Personal Information was unlawfully processed. We may not accommodate a request to erase information if we believe the deletion would violate any law or legal requirement or cause the information to be incorrect. In all other cases, we will retain your Personal Information as set forth in this policy. In addition, we cannot completely delete your Personal Information as some data may rest in previous backups. These will be retained for the periods set forth in our disaster recovery policies.
  • You have the right to lodge a complaint with the applicable supervisory authority in the country you live in, the country you work in, or the country where you believe your rights under applicable data protection laws have been violated. However, before doing so, we request that you contact us directly in order to give us an opportunity to work directly with you to resolve any concerns about your privacy.
  • How You May Exercise Your Rights. You may exercise any of the above rights by contacting us through any of the methods listed under Contact Information below or by using the Contact Us page of our Website. If you contact us to exercise any of the foregoing rights, we may ask you for additional information to verify your identity. We reserve the right to limit or deny your request if you have failed to provide sufficient information to verify your identity or to satisfy our legal and business requirements. Please note that if you make unfounded, repetitive, or excessive requests (as determined in our reasonable discretion) to access your Personal Information, you may be charged a fee subject to a maximum set by applicable law.

10. Consent to Processing of Personal Information In Other Countries Outside the European Economic Area or the United Kingdom

In order to provide our Website, Products, and services to you, we may send and store your Personal Information outside of the EEA or the United Kingdom, including to the United States. Accordingly, your Personal Information may be transferred outside the country where you reside or are located, including to countries that may not or do not provide an equivalent level of protection for your Personal Information. Your information may be processed and stored in the United States and United States federal, state, and local governments, courts, or law enforcement or regulatory agencies may be able to obtain disclosure of your information through the laws of the United States. By using our Website, you represent that you have read and understood the above and hereby consent to the storage and processing of Personal Information outside the country where you reside or are located, including in the United States.

Your Personal Information is transferred by Spectra Medical Devices to another country only if it is required or permitted under the GDPR and provided that there are appropriate safeguards in place to protect your Personal Information. To ensure your Personal Information is treated in accordance with our Privacy Policy and this GDPR Privacy Addendum when we transfer it to a third party, Spectra Medical Devices uses Data Protection Agreements between Spectra Medical Devices and all other recipients of your data that include, where applicable, the standard contractual clauses adopted by the European Commission and/or the Information Commissioner’s Office in the United Kingdom (collectively, the “Standard Contractual Clauses”). The European Commission and the Information Commissioner’s Office in the United Kingdom have determined that the transfer of Personal Information pursuant to the Standard Contractual Clauses provides for an adequate level of protection of your Personal Information, however, the Standard Contractual Clauses may need to be supplemented in some cases with additional measures on a case-by-case basis after an analysis that such supplemental measures can provide you with an essentially equivalent level of protection as afforded in the EEA and/or the UK. When, as a result of this analysis, we believe this to be appropriate and necessary, the Standard Contractual Clauses have been supplemented in this way. Under these Standard Contractual Clauses, you have the same rights as if your Personal Information was not transferred to such third country.

11. Data Retention Periods

Spectra Medical Devices will retain your Personal Information for as long as Spectra Medical Devices has a business reason to retain the Personal Information, including for as long as necessary to comply with any legal requirement and to protect our legal interests or otherwise pursue our legal rights and remedies. Spectra Medical Devices will retain data that has been aggregated or otherwise rendered anonymous in such a manner that you are no longer identifiable, indefinitely.

12. Changes to This GDPR Privacy Addendum

We may change this GDPR Privacy Addendum at any time. It is our policy to post any changes we make to our GDPR Privacy Addendum on the home page or other prominent location on the Website. If we make material changes to how we treat our users’ Personal Information, we will notify you as required or permitted by applicable law. The date this GDPR Privacy Addendum was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and this GDPR Privacy Addendum to check for any changes.

13. Contact Information

If you have any questions, concerns, complaints, or suggestions regarding our Privacy Policy or this GDPR Privacy Addendum, have any requests related to your Personal Information described in the Privacy Policy or this GDPR Privacy Addendum, or otherwise need to contact us, you can do so at the contact information below or through the Contact Us page on our Website.

To Contact Spectra Medical Devices (Controller)

Spectra Medical Devices, LLC
299 Ballardvale Street, Suite 1
Wilmington, MA 01887

(978) 657-0889

[email protected]

Spectra Medical Devices CALIFORNIA Privacy Addendum

Last modified: November 30, 2023

1. Introduction

This Privacy Policy Addendum for California Residents (the “California Privacy Addendum”) supplements the information contained in Spectra Medical Devices (“Spectra Medical Devices,” or “we,” “our,” or “us”) Privacy Policy and describes our collection and use of Personal Information (as defined below). This California Privacy Addendum applies solely to all visitors, users, and others who reside in the State of California (“Consumers” or “you”). We adopt this Addendum to comply with the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 and its implementing regulations (collectively, the “CCPA”) and any terms defined in the CCPA have the same meaning when used in this California Privacy Addendum.

2. Scope of this California Privacy Addendum

This California Privacy Addendum applies to information that we collect on our Website and when you use our services (both online and offline) that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your device (“Personal Information”). However, publicly available information that we collect from government records and deidentified or aggregated information (when deidentified or aggregated as described in the CCPA) are not considered Personal Information and this California Privacy Addendum does not apply to such information.

This California Privacy Addendum does not apply to employment-related Personal Information collected from our California-based employees, job applicants, contractors, or similar individuals, if any (“Personnel”).

This California Privacy Addendum also does not apply to certain Personal Information that is excluded from the scope of the CCPA, including health or medical information covered by the Health Insurance Portability and Accountability Act and its implementing regulations or the California Confidentiality of Medical Information Act or Personal information collected as part of a clinical trial or other biomedical research study.

3. Information We Collect About You and How We Collect It

We collect, and over the prior 12 months have collected, the following categories of Personal Information about Consumers:

Category Applicable Pieces of Personal Information Collected
Identifiers. A real name, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, or other similar identifiers.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, signature, address, telephone number, driver’s license or state identification card number, credit card number, debit card number, medical information, or health insurance information.

Some personal information included in this category may overlap with other categories.

Commercial information. Records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Internet or other similar network activity. Browsing history, search history, information on a Consumer’s interaction with a website, application, or advertisement.
Inferences drawn from other personal information. Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Sensitive Personal Information · Government identifiers (driver’s license or state identification card)

· Health information

Spectra Medical Devices will not collect additional categories of Personal Information without providing you notice. As further described in To Whom Do We Sell or Share Your Personal Information, we may “sell” any categories of Personal Information for valuable (non-monetary) consideration and we may “share” any categories of Personal Information for cross-context behavioral advertising. Under CCPA, “sell” broadly means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information by Spectra Medical Devices to a Third Party for monetary or other valuable consideration. “Share” means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Information by Spectra Medical Devices to a Third Party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration. “Third Party” means a person or entity which is not a Consumer or a Service Provider; “Service Provider” means a person or entity that processes Personal Information on behalf of Spectra Medical Devices and that receives Consumer’s Personal Information from or on behalf of Spectra Medical Devices for a business purpose, pursuant to a written contract meeting CCPA’s requirements.

4. Sources of Personal Information

We collect the categories of Personal Information listed above from the sources described in the How We Collect Personal Information About You section of our Privacy Policy.

5. Purposes for Our Collection of Your Personal Information

We limit the collection, use, retention, and sharing of Personal Information (including Sensitive Personal Information) to that which is reasonably necessary and proportionate to achieve the business purpose for which the Personal Information was collected or processed (for example, please refer to the “How We Use Your Personal Information” and “Disclosure of your Personal Information” sections of our Website Privacy Policy).

Additionally, pursuant to the CCPA, we may use, “sell” for monetary or other valuable consideration, “share” for the purposes of cross-context behavioral advertising or disclose the Personal Information we collect. Over the prior 12 months, we have used, “sold” for monetary or other valuable consideration, shared for the purpose of cross-context behavioral advertising, or disclosed the Personal Information we have collected, for the purposes described in our Privacy Policy as well as the following additional purposes:

  • Short-term, transient use, provided the Personal Information that is not disclosed to another third-party and is not used to build a profile about you or otherwise alter your experience outside the current interaction, including, but not limited to, the contextual customization of ads shown as part of the same interaction.
  • Performing services on behalf of Spectra Medical Devices, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business or service provider.

Spectra Medical Devices will not use the Personal Information we collected for materially different, unrelated, or incompatible purposes without providing you notice. Note that we obtain your consent before using or sharing your Personal Information for purposes of non-essential cookies or tracking technologies.

6. Third Parties to Whom We Disclose Your Personal Information for Business Purposes

We may disclose your Personal Information to Third Parties for one or more business purposes. In the preceding 12 months, Spectra Medical Devices may have disclosed the following categories of Personal Information for a business purpose:

Personal Information Category Categories of Third-Party Recipients
Identifiers. Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Commercial information. Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Internet or other similar network activity. Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Inferences drawn from other personal information. Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.

 

Sensitive Personal Information Category Categories of Third-Party Recipients
Government identifiers (driver’s license, state identification card) Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Health information Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.

We disclose your Personal Information to the categories of Third Parties listed above for the following business purposes:

  • Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
  • Helping to ensure security and integrity of our services and IT infrastructure to the extent the use of the Personal Information is reasonably necessary and proportionate for these purposes.
  • Performing services on behalf of us, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of us.
  • Providing advertising and marketing services, except for cross-context behavioral advertising, to Consumers.

In addition to the above, we may disclose any or all categories of Personal Information to any Third Party (including government entities and/or law enforcement entities) as necessary to:

  • Comply with federal, state, or local laws, or to comply with a court order or subpoena to provide information;
  • Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
  • Cooperate with law enforcement agencies concerning conduct or activities that we (or one of our service providers’) believe may violate federal, state, or local law;
  • Comply with certain government agency requests for emergency access to your Personal Information if you are at risk or danger of death or serious physical injury; or
  • Exercise or defend legal claims.

7. To Whom Do We Sell or Share Your Personal Information

“Sale” of Your Personal Information for Monetary or Other Valuable Consideration
We do not sell Personal Information as the term “sell” is commonly understood to require an exchange for money. However, the use of advertising and analytics cookies on our Website is considered a “sale” of Personal Information as the term “sale” is broadly defined in the CCPA to include both monetary and other valuable consideration. Using this broad definition, our “sale” is limited to our use of third-party advertising and analytics cookies and their use in providing behavioral advertising and their use in understanding how people use and interact with our Website. We obtain your consent on our Website before “selling” your Personal Information. The CCPA prohibits third parties who purchase the Personal Information we hold from reselling it unless you have received explicit notice and an opportunity to opt-out of further sales.
“Sharing” of Your Personal Information for Cross-Context Behavioral Advertising
Spectra Medical Devices may “share” your Personal Information for the purpose of cross-context behavioral advertising; however, we obtain your consent on our Website before “sharing” your Personal Information. Our “sharing” for the purpose of cross-context behavioral advertising would be limited to our use of third-party advertising cookies and their use in providing you cross-context behavioral advertising (i.e., advertising on other websites or in other mediums). When the recipients of your Personal Information disclosed for the purpose of cross-context behavioral advertising are also permitted to use your Personal Information to provide advertising to others, we also consider this disclosure as a “sale” for monetary or other valuable consideration under the CCPA.

In the preceding 12 months, Spectra Medical Devices has “sold” for monetary or other valuable consideration, or “shared” for the purpose of cross-context behavioral advertising, the following categories of Personal Information to the following categories of third parties:

Personal Information Category Sold and/or Shared Categories of Third-Party Recipients
Identifiers. Sold and Shared Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Sold and Shared Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Commercial information. Sold and Shared Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Internet or other similar network activity. Sold and Shared Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.
Inferences drawn from other personal information. Sold and Shared Advertisers and advertising networks; social media companies; business partners; and affiliates of Spectra Medical Devices.

 

Sensitive Personal Information Category Sold and/or Shared Categories of Third-Party Recipients
Government identifiers (driver’s license or state identification card) No N/A
Health information No N/A

Sale of Personal Information of Minors Under the Age of 16
We do not have any actual knowledge that we “sell” the Personal Information of minors under the age of 16 for monetary or other valuable consideration and we do not have any actual knowledge that we “share” such Personal Information for cross-context behavioral advertising without affirmative consent as required by the CCPA. More information on how minors under the age of 16 may change their choice regarding the “sale” or “sharing” of their Personal Information can be found in Your Choices Regarding our “Sale” or “Sharing” of Your Personal Information.

8. Consumer Data Requests

The CCPA provides California residents with specific rights regarding their Personal Information. This section describes your CCPA rights and explains how to exercise those rights. You may exercise these rights yourself or through your Authorized Agent. For more information on how you or your Authorized Agent can exercise your rights, please see Exercising Your CCPA Privacy Rights.

  • Right to Know. You have the right to request that Spectra Medical Devices disclose certain information to you about our collection and use of your Personal Information over the past 12 months (a “Right to Know” Consumer Request). This includes: (a) the categories of Personal Information we have collected about you; (b) the categories of sources from which that Personal Information came from; (c) our purposes for collecting this Personal Information; (d) the categories of third parties with whom we have shared your Personal Information; and (e) if we have “sold” or “shared” or disclosed your Personal Information, a list of categories of third parties to whom we “sold” or “shared” your Personal Information, and a separate list of the categories of third parties to whom we disclosed your Personal Information to. You must specifically describe if you are making a Right to Know request or a Data Portability Request. If you would like to make both a Right to Know Consumer Request and a Data Portability Consumer Request, you must make both requests clear in your request. If it is not reasonably clear from your request, we will only process your request as a Right to Know request. You may make a Right to Know or a Data Portability Consumer Request a total of two (2) times within a 12-month period at no charge.
  • Access to Specific Pieces of Information (Data Portability). You also have the right to request that Spectra Medical Devices provide you with a copy of the specific pieces of Personal Information that we have collected about you, including any Personal Information that we have created or otherwise received from a third-party about you (a “Data Portability” Consumer Request). If you make a Data Portability Consumer Request electronically, we will provide you with a copy of your Personal Information in a portable and, to the extent technically feasible, readily reusable format that allows you to transmit the Personal Information to another third-party. You must specifically describe if you are making a Right to Know request or a Data Portability request. If you would like to make both a Right to Know Consumer Request and a Data Portability Consumer Request you must make both requests clear in your request. We will not disclose any Personal Information that may be subject to an exception under the CCPA. If we are unable to disclose certain pieces of your Personal Information, we will describe generally the types of Personal Information that we were unable to disclose and provide you a description of the reason we are unable to disclose it. You may make a Right to Know or a Data Portability Consumer Request a total of two (2) times within a 12-month period at no charge.
  • You have the right to request that we correct any incorrect Personal Information about you to ensure that it is complete, accurate, and as current as possible. You may request that we correct the Personal Information we have about you as described below under Exercising Your CCPA Privacy Rights. In some cases, we may require you to provide reasonable documentation to show that the Personal Information we have about you is incorrect and what the correct Personal Information may be. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect or if the Personal Information is subject to another exception under the CCPA.
  • You have the right to request that Spectra Medical Devices delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your Consumer Request (see Exercising Your CCPA Privacy Rights), we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies pursuant to the CCPA. Some exceptions to your right to delete include, but are not limited to, if we are required to retain your Personal Information to complete the transaction or provide you the goods and services for which we collected the Personal Information or otherwise perform under our contract with you, to detect security incidents or protect against other malicious activities, and to comply with legal obligations. We may also retain your Personal Information for other internal and lawful uses that are compatible with the context in which we collected it.
  • Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not do any of the following as a result of you exercising your CCPA rights: (a) deny you goods or services; (b) charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; (c) provide you a different level or quality of goods or services; or (d) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Exercising Your CCPA Privacy Rights
To exercise the rights described above, please submit a request (a “Consumer Request”) to us by either:

If you fail to make your Consumer Request in accordance with the ways described above, we may either treat your request as if it had been submitted with our methods described above or provide you with information on how to submit the request or remedy any deficiencies with your request.

Only you, or your Authorized Agent that you authorize to act on your behalf, may make a Consumer Request related to your Personal Information. To designate an Authorized Agent, see Authorized Agents below.

All Consumer Requests must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an Authorized Agent of such a person. This may include verifying information that we may already have about you, such as your name and email address.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm which Personal Information relates to you or the individual for whom you are making the request as their Authorized Agent.

Making a Consumer Request does not require you to create an account with us. However, we do consider requests made through your password-protected account sufficiently verified when the request relates to Personal Information associated with that specific account.

We will only use Personal Information provided in a Consumer Request to verify the requestor’s identity or authority to make the request.

For instructions on exercising sale opt-out rights, see Your Choices Regarding our “Sale” or “Sharing” of Your Personal Information.
Authorized Agents
You may authorize your agent to exercise your rights under the CCPA on your behalf by registering your agent with the California Secretary of State or by providing them with power of attorney to exercise your rights in accordance with applicable laws (an “Authorized Agent”). We may request that your Authorized Agent submit proof of identity and that they have been authorized to exercise your rights on your behalf. We may deny a request from your Authorized Agent to exercise your rights on your behalf if they fail to submit adequate proof of identity or adequate proof that they have the authority to exercise your rights.

9. Your Choices Regarding Our “Sale” or “Sharing” of Your Personal Information

As noted above, Spectra Medical Devices obtains your consent on our Website before “selling” or “sharing” your Personal Information. If you provide your consent to the “sale” or “sharing” of your Personal Information and later wish to revoke your consent, please email us at [email protected] and we will promptly opt you out of future “sales” or “sharing.” We do not sell or share the Personal Information of Consumers we actually know are less than 16 years of age.
You can also set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. However, if you do not consent to our use of cookies or select this setting you may be unable to access certain features or parts of our services or other websites. You can find more information about cookies at http://www.allaboutcookies.org and http://youronlinechoices.eu.

Once you make an opt-out request, we will wait at least 12 months before asking you to reauthorize Personal Information sales. However, you may change your mind and opt back into the sale of Personal Information at any time by:

  • If you have opted out of the sale or sharing of your Personal Information through cookies by adjusting your cookie preferences or by following the above link, you may simply re-adjust your cookie preferences.
  • If you have opted out of the sale or sharing of your Personal Information through the use of a browser privacy control signal, you may turn off the signal and re-adjust your cookie preferences.

Browser Privacy Control Signals
You may also exercise your right to opt-out of the “sale” of your Personal Information for monetary or other valuable consideration and “sharing” your Personal Information for the purposes of cross-context behavioral advertising by setting the privacy control signal on your browser, if your browser supports it. We currently recognize and support the following privacy signals sent by browsers:

When we receive one of these privacy control signals, we will opt you out of any further “sale” or “sharing” of your Personal Information when you interact with our Website through that browser and on that device. We will only be able to propagate your choice to opt-out to your account if you are currently logged in when we receive the privacy control signal from your browser. When we are able to propagate your choice to your account, you will be opted out of “sale” or “sharing” of your Personal Information on all browsers and devices on which you are logged in, and for both online and offline “sales” and “sharing.”

10. Your Choices Regarding Our Use and Disclosure of Your Sensitive Personal Information

As further described below, we do not use or disclose your Sensitive Personal Information for any purpose other than the following:

  • To perform the services reasonably expected by an average Consumer who requests such services;
  • To perform services on behalf of us, such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of us; and
  • To verify or maintain the quality or safety of a service controlled by us, and to improve, upgrade, or enhance the service controlled by us.

Because we only use your Sensitive Personal Information for the purposes described above, we do currently allow you to limit our use of your Sensitive Personal Information for these purposes and no other purposes.

11. Personal Information Retention Periods

We will keep your Personal Information for no longer than is necessary for the purpose(s) it was provided for. Further details of the periods for which we retain Personal Information are available on request. However, we may retain any or all categories of Personal Information when your information is subject to one of the following exceptions:

  • When stored in our backup and disaster recovery systems. Your Personal Information will be deleted when the backup media your Personal Information is stored on expires or when our disaster recovery systems are updated.
  • When necessary for us to exercise or defend legal claims.
  • When necessary to comply with a legal obligation.
  • When necessary to help ensure the security and integrity of our Website.

12. Changes to This California Privacy Addendum

Spectra Medical Devices reserves the right to amend this California Privacy Addendum at our discretion and at any time. When we make changes to this California Privacy Addendum, we will post the updated addendum on the Website and update the addendum’s last updated date. If we make material changes to our practices with regard to the Personal Information we collect from you, we will notify you as required or permitted by applicable law, such as through email to the email address specified in your account and/or through a notice on the Website’s home page. You are responsible for ensuring we have an up-to-date, active, and deliverable email address for you, and for periodically accessing the Website and reviewing this Addendum to check for any changes.

Your continued use of our Website following the posting of changes constitutes your acceptance of such changes.

13. Contact Information

If you have any questions or comments about this California Privacy Addendum, the ways in which Spectra Medical Devices collects and uses your information described above and in the Privacy Policy, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at:

Phone: (855) 623-5900

Website: www.spectramedical.com

Email: [email protected]

Postal Address:

Spectra Medical Devices, LLC
299 Ballardvale Street, Suite 1
Wilmington, MA 01887