CATO SMS (“we,” “us,” or “CATO SMS”), operating through its affiliates/subsidiaries located throughout the world (collectively, the “Company”) is committed to protecting your privacy and has implemented the measures below to protect the personal data we process about you (“Personal Data”).
CATO SMS is a business-to-business service provider primarily to the biopharmaceutical industry.
Our website, mobile applications, and other services are intended for businesses. In connection with marketing our services, or providing services for or on behalf of our customers, we interact with individuals who represent businesses, such as doctors. When doctors and other business representatives share their information with us in the context of these interactions, it is with the understanding that we will share their details with our actual and potential customers. This is because our customers are looking to provide services to the businesses those individuals represent or obtain services from them.
Except where otherwise identified by us, our website, mobile applications and other services are not intended for individuals to use for personal or household purposes.
Except as set forth in the Exclusions to Policy Scope section of this notice, this notice applies to all Personal Data gathered for and on behalf of CATO SMS through the various CATO SMS sites that link or refer to it (such as websites or applications operated by or on behalf of CATO SMS and HTML-formatted e-mail messages) together with any and all offline sources including sales and marketing activities (collectively, the “Sources”). By using the Sources, you consent to the data collection and use practices described in this notice.
Exclusions to Policy Scope
- Customer Contracts. This notice does not apply to the information that we process in connection with providing services to our customers under our contracts with them. Our processing of such information is governed by our customer contracts and other relevant privacy notices.
CATO SMS has additional privacy notices or terms that are tailored for the different ways your Personal Data is collected by different CATO SMS lines of business or functions. For example, CATO SMS provides employment applicants with a notice that describes the Personal Data we may collect in connection with CATO SMS’s employment and recruiting efforts. If you receive a privacy notice provided to you for a specific purpose, the terms of the more specific notice or contract will control your interaction with CATO SMS to the extent that notice conflicts with this notice.
Identification of Data Controller
The CATO SMS legal entity that is the data controller of your Personal Data is the company entity located in your jurisdiction and with which you interacted to provide your Personal Data and/or another CATO SMS legal entity with which you interacted to provide your Personal Data (if you did not interact with a local legal entity). You can contact the CATO SMS entity acting as a data controller through our Privacy Office, using the contact information provided in this notice.
Information We Collect
When you visit our websites or otherwise interact with CATO SMS, we may collect the following information about you. We may also collect information about you from our customers or from third parties:
- Contact details, such as name, social media handle, job title and employer, email address, mailing address, phone number, and emergency contact information.
- Transaction history, such as details about the programs and activities in which you have participated, including conferences, ad boards, speakers programs, dinner series and other events.
- Professional credentials, such as your specialty, educational and professional history, and institutional affiliations.
- Financial information, such as payment card information, bank account number, or tax identification number.
- Usage information, such as information about how you use the services and interact with us.
- Survey data, such as your responses to our online and offline surveys.
- Communications that we exchange when you contact us.
- Publicly available information, including information that you or others publish on social media and in publications, such as tweets, comment, news articles, or video or audio content.
- Device identifiers, including information about the device you are using to visit connect to our websites or applications, such as your device operating system type and version number, manufacturer and model, device identifier (such as the Google Advertising ID or Apple ID for Advertising), browser type, screen resolution, IP address, and other device identifiers.
- Online activity data, including browsing history, search history, clickstream data, and other information about your interactions with our services, websites, applications, social media pages, and email communications. We, our service providers and business partners, also collect this type of information over time and across third-party websites.
Sensitive Personal Data
We do not generally seek to collect Sensitive Personal Data through the Sources. The term “Sensitive Personal Data” refers to categories of personal data identified by data privacy laws as requiring special treatment, including in some circumstances the need to obtain explicit consent from you. These categories generally include racial or ethnic origin, political opinions, financial background, religious or similar beliefs, sexual life, trade union membership or affiliations, individual medical records and history, physical, mental or physiological health condition or genetic or biometric information, ideological views or activities, information on social security measures, or administrative or criminal proceedings and sanctions which are treated outside pending proceedings.
If we seek to collect Sensitive Personal Data, we will do so in accordance with applicable law. Unless we have specifically requested such data, however, we ask that you not send to us, nor share with us, any Sensitive Personal Data.
Personal Data Usage
CATO SMS may use Personal Data for the following purposes:
Service Delivery. We use Personal Data to:
- provide, operate and improve our business and the services we provide;
- provide information about our products and services;
- communicate with you about the services, including by sending you announcements, updates, security alerts, and support and administrative messages;
- communicate with you about events, surveys, questionnaires or webinars in which you participate;
- understand your needs and interests, and personalize your experience with our services and communications;
- provide support and maintenance for our sites; and
- respond to your requests, questions and feedback.
Research and Development. We may use Personal Data for research and development purposes, including to analyze and improve our sites, services, marketing, and business. As part of these activities, we may create aggregated, de-identified or other anonymous data from Personal Data we collect.
Marketing and Advertising. We may send you CATO SMS-related marketing communications, including in person or electronically, as permitted by law. You will have the ability to opt out of our marketing and promotional communications as described in the Your Privacy Choices section below.We advertise online and offline, and our advertisements may be targeted based on your use of the sites or your activity elsewhere online and offline.
Appending our Databases. We may assign a unique identifier to the Personal Data we collect about you, or combine this data with other information about you, and use this information to supplement our existing databases of Personal Data, analytics, and insights for purposes consistent with this notice. We may also combine information about you that we collect with your Personal Data.
Compliance. We use Personal Data to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements and internal policies;
- enforce the terms and conditions that govern our services; and
- prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.
Disclosure to Third Parties
We share Personal Data with certain other parties, as described below.
- Affiliates. We may share Personal Data with our subsidiaries and affiliates for purposes consistent with this notice.
- Customers. We may share Personal Data, analytics and insights from our databases with our customers in connection with providing our services to those customers.
- Those who Work for Us. We contract with other companies and individuals to help us provide services including the Sources. For example, we may host some of our Sources on another company’s computers, hire technical consultants to maintain our sites, or work with companies to remove repetitive information from customer lists, analyze data, provide marketing assistance, and provide customer service. In addition, we may validate your identity and other information against available databases. In order to perform their services, these other companies may have limited access to some of the Personal Data we maintain about our users. Other companies may collect information on our behalf through their websites or applications. We require that such companies not use your information for any purpose other than fulfilling their responsibilities to us. We also require that such companies keep your Personal Data confidential and comply with applicable laws. CATO SMS’s practice is to (i) conduct reasonable and appropriate due diligence on our service providers; and (ii) obtain written commitments regarding the processing of Personal Data, including that the service provider will only handle Personal Data in accordance with our instructions; adopt adequate technical and organizational measures to protect your personal data; and not retain Personal Data when it is no longer required for completion of its services. Details of service providers and the countries in which they are based are available from the CATO SMS by contacting its Global Privacy and Data Protection Officer.
- Informational offers. We may send offers to selected groups of users. To accomplish this we may use third parties working on behalf of CATO SMS. We provide a variety of mechanisms for you to tell us you do not want to receive such promotional or informational offers. For example, where required by law, we may provide an opt-in box for customers to receive information that is sent by a third-party fulfillment house, and we make clear that, by opting in, you are submitting your data to a third party. You can elect not to receive promotional or informational material from us by following the instructions to opt-out as included in each of our programs we send to you.
- Business partners. We may share the information we collect with our prospective or current customers, and other business partners who work with us.
- Professional advisors. We may disclose Personal Data to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
- Business transfers. If we transfer a business unit or an asset (such a CATO SMS website) to another company, we may transfer the Personal Data we have collected to that party.
- Legal requirements. We may be obligated to cooperate with various law enforcement inquiries. CATO SMS reserves the right to share or transfer your information to comply with a legal requirement, disclose any activities or information about you to law enforcement or other government officials as we, at our sole discretion, determine necessary or appropriate, in connection with an investigation of fraud, for the administration of justice, intellectual property infringements, or other activity that is illegal or may expose us or you to legal liability. We may release information if, in our judgment the release may be necessary to prevent the death or serious injury of an individual.
Legal Basis for Processing Personal Data
In certain jurisdictions we are required to identify the legal bases for processing Personal Data. To this end, note that we process Personal Data:
- to perform contracts with you or to take steps at your request prior to entering into such contract;
- to comply with a legal obligation;
- for our legitimate business interests, which will be assessed in connection with the specific use of Personal Data; and/or
- with your consent (or, where required to process Sensitive Personal Data, with your explicit consent), which will be requested and given via the Sources or otherwise.
Withdrawal of Consent
In certain jurisdictions, when we process Personal Data based on your consent or your explicit consent, you have the right to withdraw your consent in whole or in part at any time. Where applicable, once we have received notification that you have withdrawn your consent, we will no longer Process the Personal Data for the purpose(s) to which you originally consented unless there are compelling legitimate grounds that override your interests, rights and freedoms (for example, to comply with a legal obligation), or for the establishment, exercise, or defense of legal claims. If we processed Personal Data for direct marketing purposes, you have the right to object at any time, in which case we will no longer process your Personal Data for such purposes. The withdrawal of your consent does not affect the lawfulness of such processing that occurred before its withdrawal. Should you withdraw consent to future processing of your Personal Data, we may not be able to contact or interact with you as originally planned when you first provided your consent.
CATO SMS operates on a global basis, and your Personal Data may be transferred, accessed and stored globally as necessary for the uses stated in this notice, or in another notice or agreement provided to you. We have taken measures to protect the confidentiality, integrity, availability, and security of Personal Data when it is transferred. By using the Sources (and if required by law), you consent to the transfer of information to countries outside of your country of residence.
To the extent that your Personal Data is shared with service providers or other third parties processing Personal Data on our behalf, which are located outside your country of residence, it is our practice to enter into appropriate contracts that require such third parties to comply with applicable data protection laws.
Retention and Deletion
CATO SMS will retain your Personal Data for as long as your account is active; as needed to provide you products or services; as needed for the purposes outlined in this Privacy Notice or at the time of collection; as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements; or to the extent permitted by law. CATO SMS does not retain Personal Data after it no longer serves the purposes for which it was collected or subsequently authorized. At the end of the retention period, CATO SMS will delete your Personal Data in a manner designed to ensure that it cannot be reconstructed or read.
Protection of Information
We use commercially reasonable physical, electronic, and administrative safeguards that are designed to protect your Personal Data from loss, misuse and unauthorized access, disclosure, alteration, and destruction. However, regardless of our efforts and the device you use to access the Sources, third parties may unlawfully intercept or access transmissions or private communications over an unsecured transmission.
Cookies and Related Technologies
The Sources and/or third parties may use “cookies,” “web beacons,” scripts, tags, Local Shared Objects (Flash cookies), Local Storage (HTML5) beacons, and other similar Cookies (collectively, “Cookies”) to collect information from you automatically as you use the Sources, browse CATO SMS websites, and the web. These Cookies help us tailor our content, gather statistics about and understand website and internet usage, improve or customize the content, offerings, or advertisements through the Sources, personalize your experience with respect to the Sources (for example, to recognize you by name when you return to a CATO SMS website), save your password in password-protected areas, save your online video player settings, help us offer you programs or services that may be of interest to you, deliver relevant advertising, maintain and administer the Sources, and for other purposes described in this Privacy Notice.
These Cookies collect “click stream” data and other information regarding your use of the Sources, such as your visits, use of our features and preferences, and may collect your IP address or some other identifier unique to the device you use to access the Sources (“Identifier”). Your Identifier may be automatically assigned to the device you use to access the Sources. By using the Sources, whether as a registered user or otherwise, you acknowledge, understand, and hereby agree that you are giving us your consent to track your activities and your use of the Sources through these technologies.
For the purposes of clarity, “Cookies” are text files that a website can send to your device through your browser, which is then used to identify your device by the website. Cookies can be both “session level” (stored only for until you close your web browser), which help you efficiently navigate our Sources during a visit, and “persistent” (stored for a longer period, even after you close your browser), which remember relevant information such as your language preference. CATO SMS Sources may use both session level and persistent cookies.
Cookies may also be “first-party cookies,” which are cookies that are placed by the website owner on a website, or “third-party cookies,” which are cookies belonging to one party that are placed on another party’s website. We may use both first- and third- party cookies on the Sources. Some of the third-party cookies we use relate to Cookies we have licensed from third parties. These companies use programming code to collect information about your interaction with our sites, such as the pages you visit, the links you click on, and how long you are on our sites.
Privacy of Persons Under 13 Years of Age
We are committed to protecting the privacy of children. For that reason, we do not knowingly collect or maintain personally identifiable information from any person we actually know is under the age of 13. No part of the Sources are structured to attract anyone under age 13.
You may have an opportunity to elect to receive recurring informational/promotional e-mail from us. Our e-mail correspondence will include instructions on how to update certain Personal Data and how to unsubscribe from our e-mails. Please follow the instructions in the e-mails to opt-out of an e-mail. We will unsubscribe you from that newsletter or other programs within 30 business days. You can contact us at email@example.com in order to change your preferences with respect to marketing contacts.
In addition, some of our business partners that collect information about your activity on or through the Sources may be members of organizations or programs that provide you with choices regarding the use of your browsing behavior or mobile application usage for purposes of targeted advertising.
Your Rights as a Data Subject
In certain jurisdictions you may be entitled to certain rights in and to your Personal Data, subject to certain conditions and exceptions contained in applicable law. These rights may include the following:
- Request us to confirm whether your Personal Data is processed by us, and if we do, to obtain access to your personal data and certain information about it.
- Require the correction of your Personal Data if it is inaccurate or incomplete.
- Direct us to stop processing your Personal Data under certain circumstances.
- Erase or delete your Personal Data, for example, where the data is no longer needed to achieve the purpose for which it was collected.
- Restrict the further Processing of Personal Data
- Request us not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (we currently do not engage in such processing and will notify you prior to doing so).
- Request to receive your Personal Data for transmission to, or to directly transmit to, another data controller in a structured, commonly-used and machine-readable format.
To protect your privacy and the security of your Personal Data, we will take reasonable steps to verify your identity before complying with such rights requests.
Exercising Your Rights or Raising Concerns
Should you have questions about the Personal Data that we process, or if you have a question, concern, or would like to exercise your legal rights in and to your Personal Data, please contact the CATO SMS Global Privacy and Data Protection Officer at firstname.lastname@example.org.
How Your Dispute or Complaint May Be Resolved
Any questions, concerns, or complaints regarding the use of your Personal Data should be directed to CATO SMS Global Privacy and Data Protection Officer. If you are located in certain jurisdictions, you also have the right to raise a complaint about the collection or use of your Personal Data to your local regulator.
Changes to This Privacy Notice
We may periodically update this notice. When we post changes to this notice, we will also revise the “Last Updated” date appearing at the top of the notice. If there are material changes to this notice, we will notify you by e-mail or by means of a notice on our home page. We encourage you to review this notice periodically to be informed of how we are using your information and to be aware of any changes to it. Your continued use of the Sources after the posting of any amended notice shall constitute your agreement to be bound by any such changes. Any changes to this notice are effective immediately after we post it.
FOR CALIFORNIA RESIDENTS
On a discretionary basis, CATO SMS aims to respond to California residents regarding their data. In general, California residents have:
- The right to know the categories of data we’ve collected and the categories of sources
- The right to know the business purposes for sharing the data
- The right to know the categories of third parties with whom we’ve shared data
- The right to access the specific pieces of data we process and the right to delete your data.
FOR NEVADA RESIDENTS
Nevada residents have the right to access and/or correct their personal information, or opt out of the sale of personal information.
If you are a Nevada resident and would like to review, correct, or update your personal information, you or your authorized representative may submit your request to email@example.com. We will respond to your verified request as soon as reasonably practicable, but no later than sixty (60) days after receipt. If circumstances cause any delay in our response, you will be promptly notified and provided a date for our response.
Under Nevada law, residents have the right to direct us to not sell or license your personal information to third parties. To exercise this right, if applicable, you or your authorized representative may submit a request to firstname.lastname@example.org. We will respond to your verified request as soon as reasonably practicable, but no later than sixty (60) days after receipt. If circumstances cause any delay in our response, you will be promptly notified and provided a date for our response.