WATERS CORPORATION EEA PRIVACY DISCLOSURES
Effective Date: May 25, 2018
Last Updated: May 25, 2018
How We Collect and Use Personal Data
Data You Provide
Data Collected Automatically
Data We Obtain from Third Party Sources
Legitimate Interests
Data Retention
How We Share and Disclose Personal Data
International Data Transfers
Your Rights
Updates to the Disclosures
Contact Us
We are Waters Corporation and its affiliated companies (collectively, “Waters”). The following additional European Economic Area (“EEA”) privacy disclosures (the “Disclosures”) supplement the www.Waters.com Privacy Notice and any other Waters privacy notices that link to, or expressly adopt or refer to, these Disclosures. These Disclosures apply only to our processing of Personal Data within the scope of the European Union’s General Data Protection Regulation (“GDPR”) (collectively, the “EEA Processing Activities”) as follows: (i) processing of personal data by a Waters company located in the EEA and (ii) processing of Personal Data of individuals located in the EEA by a Waters company located outside of the EEA in relation to offering goods or services into the EEA or monitoring the behavior of individuals in the EEA. Unless otherwise expressly stated, the terms of the Privacy Notice apply to the EEA Processing Activities identified in these Disclosures. We may gather Personal Data for these EEA Processing Activities by any means, including hardcopy (such as, paper application or forms) and electronic means (such as, websites, mobile applications, and other digital properties).
The Waters affiliated company who controls the EEA Processing Activity involving Personal Data about you will be the data controller responsible for the collection and use of such Personal Data.
If you have any questions about these Disclosures or our information practices, or if you would like to contact a specific data controller, please contact us as set forth in the Contact Us section below.
Please read these Disclosures carefully.
How We Collect and Use Personal Data
When we use the term “Personal Data,” we mean information that can be used to identify you, directly or indirectly, as an individual person. For more information about the types of Personal Data we collect as well as the purposes and legal bases for our processing of Personal Data, click below:
How We Share and Disclose Personal Data
International Data Transfers
Your Rights
Updates to the Disclosures
Contact Us
We collect Personal Data you provide, such as when you enter the data into form fields on our digital properties, fill out job applications or complete forms at our tradeshows and seminars. We collect:
Category of Personal Data | Purposes of Processing | Legal Bases for Processing |
Contact Information including your name, home address, business address, email address and phone number |
|
To process transactions requested by you and meet our contractual obligations (for example, fulfilling orders that you place online) Legitimate interests (for example, maintaining an ongoing relationship with customers) Vital interests (for example, protecting natural persons in the event of a safety announcement or recall relating to our products) Your consent, where applicable and unambiguously requested |
Professional Details Including employer, department and job title |
|
To process transactions requested by you and meet our contractual obligations (for example, fulfilling orders that you place online on behalf of your employer) Legitimate interests (for example, understanding market trends and customer needs) Vital interests (for example, protecting natural persons in the event of a safety announcement or recall relating to our products) Your consent, where applicable and unambiguously requested |
Account Information Including account name, password, security question responses, unique identification number and discount eligibility |
|
To process transactions requested by you and meet our contractual obligations (for example, fulfilling orders that you place online through your account on behalf of your employer) Legitimate interests (for example, maintaining the security of member accounts) Vital interests (for example, protecting natural persons in the event of a safety announcement or recall relating to our products) Your consent, where applicable and unambiguously requested |
Product Interest Information Including products and areas of interest, and “favorited” purchases |
|
Legitimate interests (for example, obtaining insights into interest and usage patterns of our services and products) Your consent, where applicable and unambiguously requested |
Online Purchase Information including payment card information, purchase details, government identification number, automated order entries and other transaction information |
|
To process transactions requested by you and meet our contractual obligations (for example, fulfilling automatic online orders that you create through your account) Legitimate interests (for example, operating our business, administering our services and managing your accounts) Compliance with legal obligations (for example, required reporting to tax authorities) Your consent, where applicable and unambiguously requested |
Employment Application Information including contact information, employment and education history, and other information you include in your CV/resume or application materials, as well as certain health data |
|
To process transactions requested by you and meet our contractual obligations (for example, taking steps at your request prior to entering into a contract) Legitimate interests (for example, operation of our business and facilitation of employment decisions) Your consent, where applicable and unambiguously requested |
Survey Responses including satisfaction with Waters, a Waters product or a Waters service; opinions on the design and usability of Waters services, products and software; and information about the market, products you use today and your thoughts about the future |
|
Legitimate interests (for example, obtaining insights into interest and usage patterns of our services and products) Your consent, where applicable and unambiguously requested |
User Generated Content including information you provide on our forums or other services, including reviews and feedback on Waters products |
|
Legitimate interests (for example, receiving feedback from customers on purchased products) Your consent, where applicable and unambiguously requested |
Inquiry and Report Information including the content of your email, text, or chat and, where applicable, your voice |
|
To process transactions requested by you and meet our contractual obligations (for example, providing support for warranty claims) Legitimate interests (for example, ensuring the quality of our customer support or products and services) Your consent, where applicable and unambiguously requested |
Mobile Application Information including, for example, information relating to your product needs |
|
Legitimate interests (for example, providing product selection assistance) Your consent, where applicable and unambiguously requested |
2. Data Collected Automatically
As is true of most digital platforms, we gather certain data automatically when you use our online services. This information includes browser, device, cookie and similar data that we collect as follows:
Category of Personal Data | Purposes of Processing | Legal Bases for Processing |
Log Files |
|
Legitimate interests (for example, fraud prevention) |
Cookies, Analytics and Related Technologies For more information, including on how to control your privacy settings and your ad choices, read our Cookie Policy. |
|
Your consent, where applicable and unambiguously requested Legitimate interests (for example, administering our services) |
3. Data We Obtain from Third Party Sources
We also obtain from third-parties the same categories of Personal Data described in the Data You Provide and the Data Collected Automatically sections, which we use for the purposes and under the legal bases described in those sections and as otherwise described below in this section. In some cases, we obtain your consent for additional uses, where we unambiguously request such consent.
Business Partners and Service Providers: We use business partners and service providers to perform services on our behalf, and some of these parties provide us Personal Data about you that we do not otherwise have (for example, where you sign up directly with that provider) and share some or all this information with us. In addition to the purposes described above, we generally use this information to administer and tailor our services, analyze the use of our services, and conduct marketing and advertising campaigns. We receive Personal Data from the following categories of third-party business partners and service providers:
Publicly Available Sources: We collect Personal Data about you that we do not otherwise have (including contact information, professional details and product interest information) from social media platforms (for example, Facebook, Twitter, Instagram, LinkedIn and YouTube), blogs (for example, WordPress), and other publicly available databases.
We rely on several legitimate interests in using and sharing Personal Data about you. These interests include:
We will retain Personal Data about you for as long as is necessary for the purposes set out in these Disclosures unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights, all in accordance with the principles set forth in Article 5(1) of the GDPR. The criteria used to determine the period for which Personal Data about you will be stored varies depending on the legal basis under which we process such Personal Data:
Legitimate Interests | For a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of the data subjects. |
Consent | For the period of time necessary to fulfill the underlying agreement with you, subject to your right, under certain circumstances, to have certain Personal Data about you erased (see Your Rights below). |
Contractual Necessity | For the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship. |
Vital Interests | For the period of time necessary to protect the vital interests of an individual. |
We may face threat of legal claim and in that case, we may need to apply a “legal hold” that retains information beyond our typical retention period. In that case, we will retain the information until the hold is removed, which typically means the claim or threat of claim has been resolved.
How We Share and Disclose Personal Data
We share Personal Data with certain categories of third parties as described in the Privacy Notice.
We may transfer Personal Data about you within Waters and/or to the third parties discussed in the Privacy Notice. Your Personal Data may be transferred to, stored, and processed in a country other than the one in which it was collected, including, but not limited to, Australia, Austria, Belgium, Brazil, Canada, the Cayman Islands, China, Denmark, Finland, France, Germany, Hong Kong, Hungary, India, Ireland, Israel, Italy, Japan, Luxembourg, Malaysia, Mexico, the Netherlands, Norway, Poland, Portugal, Puerto Rico, Romania, Singapore, South Korea, Spain, Sweden, Switzerland, Taiwan, the United Kingdom and the United States. The country to which Personal Data is transferred may not provide the same level of protection for Personal Data as the country from which it was transferred. We may transfer Personal Data about you outside the EEA and when we do so, we rely on appropriate or suitable safeguards recognized under data protection laws.
Adequacy Decision: We may transfer Personal Data about you to Canada, Israel and Switzerland, which the European Commission has approved as providing adequate protection to personal data.
Standard Contractual Clauses: The European Commission has adopted Standard Contractual Clauses, which provide safeguards for Personal Data transferred outside of the EEA. We use these Standard Contractual Clauses when transferring Personal Data from a country in the EEA to a country outside the EEA where Standard Contractual Clauses have been executed. You can request a copy of our Standard Contractual Clauses by contacting us as set forth in the Contact Us section below.
EU-U.S. Privacy Shield: We are not certified under the EU-U.S. Privacy Shield. However, if we transfer any Personal Data about you from the EEA to a third party outside the EEA who is certified under the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce, we may rely on such certification to ensure adequate protection for Personal Data so transferred. You can learn more about Privacy Shield by visiting https://www.privacyshield.gov/.
We process all Personal Data in line with the rights granted to you under the law, including the right of access, rectification, restriction of processing, objection to processing, erasure and data portability, as applicable. In addition, we recognize your right to withdraw your consent to the processing of Personal Data about you where we are relying on consent for the purposes of such processing. If you have any complaints regarding our privacy practices, you have the right to lodge a complaint with your national data protection authority (i.e., supervisory authority).
We will provide you upon your reasonable, good faith request with information about whether we hold any Personal Data about you along with any details required to be provided to you under applicable law. In certain cases, subject to certain limitations at law, you may also have a right to:
To submit a request, please contact us as set forth in the Contact Us section below. We will respond to your request within a reasonable timeframe.
Right to Withdraw Consent
Where the purpose of our processing of Personal Data about you is based on consent, you also have the right to withdraw your consent to such processing, subject to certain limitation at law. You may withdraw your consent in the following ways:
If you withdraw your consent to the processing of Personal Data about you for the purposes set out in these Disclosures, you may not have access to all (or any) of our services, and we might not be able to provide you all (or any) of our services. In some cases, withdrawing your consent may require you to close your online account and discontinue the use of certain services.
Please note that, in certain cases, we may continue to process Personal Data about you after you have withdrawn consent or requested that we delete Personal Data about you, if we have a legal basis for the purpose of such processing. For example, we may retain certain information if we need to do so to comply with an independent legal obligation, or if it is necessary to do so to pursue our legitimate interest in keeping our services safe and secure.
Right to Lodge a Complaint
If you have any complaints regarding our privacy practices, you have the right to lodge a complaint with your national data protection authority (i.e., supervisory authority).
These Disclosures will be revised as required. If we decide to change these Disclosures, we will post notice of the changes on our Services. The updated Disclosures will be effective as of the Effective Date listed at the start of these Disclosures. You can determine when these Disclosures were last revised by checking the Last Updated date at the start of these Disclosures.
If you have any questions, comments, requests or concerns about these Disclosures or other privacy-related matters, you may contact us at:
Waters Corporation
Attention: Data Privacy
34 Maple Street
Milford, Massachusetts 01757
Data_Privacy@waters.com