Terms of Service, Privacy Policy and Compliance
Privacy Policy
1 Purpose
In its everyday business operations Vomela Holdings, LLC makes use of a variety of data about identifiable individuals, including data about:
· Current, past, and prospective employees
· Customers
· Users of its websites
· Subscribers
· Other stakeholders
In collecting and using this data, the organization is subject to a variety of legislation controlling how such activities may be carried out and the safeguards that must be put in place to protect it.
The purpose of this policy is to detail how Vomela handles personal data entrusted to us by our customers in the course of providing services, and the safeguards we implement to responsibly process such data. This policy also identifies the relevant legislation applicable to our operations and to describe the steps Vomela Holdings, LLC. is taking to ensure that it comply with them.
2 Scope
This Privacy and Personal Data Protection Policy (“Policy”) applies to Vomela Holdings, LLC and all direct and indirect subsidiaries and operating divisions (collectively, “Vomela”).
This includes, but is not limited to:
· SaaS operations
· Commercial print and fulfilment operations
· Marketing services and customer engagement platforms
This Policy applies to all employees, contractors, temporary personnel, and third parties acting on behalf of Vomela who access, process, or manage personal data.
Vomela operates across multiple jurisdictions, including the United States, European Economic Area (including Poland and Germany), the United Kingdom, and Canada. This Policy is designed to meet applicable data protection requirements in all such jurisdictions.
3 Privacy and Personal Data Protection Policy
3.1 The General Data Protection Regulation and Global Privacy Laws
The GDPR and related national laws govern how Vomela collects, uses, retains, and transfers personal data of individuals in the EEA (including Poland and Germany). Vomela also complies with the UK GDPR and Data Protection Act 2018, Canadian privacy laws (PIPEDA/CPPA and applicable provincial laws), and applicable United States federal and state privacy laws (including HIPAA where relevant). Vomela will ensure compliance is demonstrable, documented, and consistently applied across all operations.
Key obligations and commitments:
a) Records of Processing (RoPA): Vomela will maintain and regularly review Records of Processing Activities for all relevant processing.
b) Lawful bases: Vomela will document the lawful basis for GDPR/UK GDPR processing and complete Legitimate Interest Assessments where applicable.
c) Data subject rights: Vomela will honor data subject rights and meet statutory timelines (e.g., one month under GDPR/UK GDPR, with permitted extensions and local variations).
d) DPIAs & privacy by design: Vomela will perform Data Protection Impact Assessments for highrisk processing and apply privacy by design principles.
e) Cross border transfers: Vomela will use appropriate safeguards for international transfers (adequacy decisions, SCCs + Transfer Impact Assessments, UK IDTA, or BCRs) and document transfer mechanisms.
f) DPO / representatives: Vomela will evaluate and appoint a Data Protection Officer or local representatives where required by law.
g) Breach notification: Vomela will follow applicable breach reporting rules (e.g., 72 hour supervisory notification under GDPR) and local breach/notification obligations.
h) HIPAA / PHI: Where subsidiaries act as Business Associates or process PHI, Vomela will execute BAAs and apply HIPAA compliant safeguards.
3.2 Definitions
There are a total of 26 definitions listed within Article 4 – Definitions of the GDPR and it is not appropriate to reproduce them all here. However, the most fundamental definitions with respect to this policy are as follows:
a) Consent: Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of their personal data.
b) Controller: The natural or legal person, public authority, agency, or other body that determines the purposes and means of the processing of personal data.
c) Cross-Border Transfer: The transfer of personal data from one jurisdiction to another, including transfers outside the European Economic Area (EEA), United Kingdom, or Canada.
d) Data Controller vs. Data Processor (Vomela Context): For purposes of this Policy, Vomela and its subsidiaries may act as either a Data Controller or Data Processor depending on the nature of the services provided.
i. Vomela acts as a Controller when determining the purposes and means of processing (e.g., employee data, marketing, internal operations).
ii. Vomela acts as a Processor when processing personal data on behalf of customers, including SaaS, print, mailing, and fulfilment services.
e) Data Subject: An identified or identifiable natural person whose personal data is processed by Vomela.
f) Personal Data: Any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified, directly or indirectly, by reference to identifiers such as a name, identification number, location data, online identifier, or factors specific to the individual’s physical, physiological, genetic, mental, economic, cultural, or social identity.
g) Personal Data Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
h) Personal Information (Canada): Information about an identifiable individual as defined under the Personal Information Protection and Electronic Documents Act (PIPEDA), which broadly aligns with the definition of personal data under GDPR.
i) Processing: Any operation or set of operations performed on personal data, whether by automated means or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure, or destruction.
j) Processor: A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
k) Protected Health Information (PHI): Individually identifiable health information that is protected under the Health Insurance Portability and Accountability Act (HIPAA), including demographic data, medical histories, test results, and other health-related information.
l) Standard Contractual Clauses (SCCs): Contractual clauses approved by the European Commission that provide appropriate safeguards for the transfer of personal data outside the EEA.
m) UK International Data Transfer Addendum: A legally recognized mechanism that supplements SCCs for transfers of personal data from the United Kingdom.
3.3 Roles in Data Processing
3.3.1 Vomela Roles
a) Data Controller: Vomela acts as a Controller when it determines the purposes and means of processing personal data (for example: employee/HR data, internal corporate systems, marketing for Vomela’s own products and services).
b) Data Processor: Vomela acts as a Processor when it processes personal data on behalf of a customer or other Controller (for example: SaaS platform services, print production, mailing, fulfilment operations).
3.3.2 Vomela – Data Processor
a) process personal data only on the documented instructions of the Controller;
b) implement appropriate technical and organizational security measures to protect personal data;
c) ensure that any subprocessors engaged are subject to written contractual terms at least as protective as this Agreement and shall remain liable for their compliance;
d) assist the Controller to respond to data subject requests, data protection impact assessments (DPIAs), and regulatory enquiries as reasonably required;
e) assist the Controller with breach notification obligations and will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data;
f) comply with contractual obligations relating to international transfers of personal data, including using appropriate safeguards (e.g., adequacy decisions, Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum) and conducting Transfer Impact Assessments when required; and
g) make available, on request and subject to confidentiality, information and reasonable cooperation to enable the Controller to demonstrate compliance with applicable data protection law, including allowing audits or inspection rights where contractually agreed.
3.3.3 Vomela – Controller
When Vomela acts as a Controller, it will comply with the obligations in this Policy and applicable law(s) for Controllers.
3.4 Principles Relating to Processing of Personal Data
3.4.1 Data Protection Principles
Vomela commits to the following data protection principles and will apply them to all personal data processing activities across its operations:
a) Lawfulness, fairness and transparency: Personal data will be processed only where there is a valid legal basis (e.g., contract performance, legal obligation, legitimate interests, consent, or other lawful basis required by local law). Processing will be fair to the data subject and conducted in a transparent manner: Vomela will provide clear, concise privacy notices explaining what personal data is collected, why it is processed, how it is used, and the rights available to the individual.
b) Purpose limitation: Personal data will be collected for specified, explicit and legitimate purposes and will not be further processed in a manner incompatible with those purposes. Any new purpose will be assessed for compatibility and, where required, communicated to data subjects.
c) Data minimization: Vomela will limit collection and retention to the minimum personal data necessary to achieve the stated purpose. Data collection forms, processes, and systems will be designed to avoid excessive or unnecessary personal data capture.
d) Accuracy: Reasonable steps will be taken to ensure that personal data is accurate and up to date. Where inaccuracies are identified, Vomela will correct or securely dispose of the data without undue delay.
e) Storage limitation: Personal data will be retained only for as long as necessary for the original purpose or to satisfy legal, tax or audit obligations. Retention periods will be defined, documented and applied consistently; data that is no longer required will be securely deleted or anonymized.
f) Integrity and confidentiality: Appropriate technical and organizational measures will be implemented to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Controls will be proportionate to the sensitivity of the data and the risk to individuals (e.g., encryption, access controls, logging, physical security and secure disposal).
3.4.2 Demonstrating Compliance
Vomela is responsible for demonstrating compliance with these principles. To that end Vomela will:
a) Maintain and review Records of Processing Activities (RoPA) and a central data inventory.
b) Perform Data Protection Impact Assessments (DPIAs) where processing is likely to result in high risk to individuals.
c) Implement and monitor internal policies, procedures and technical controls to operationalize the principles above (including privacy by design and by default).
d) Provide rolebased training and awareness for staff and business partners who handle personal data.
e) Conduct regular compliance reviews, audits and risk assessments and retain evidence demonstrating compliance decisions and remedial actions.
f) This policy applies equally to all Vomela entities and to any third parties processing personal data on Vomela’s behalf. Where local law imposes additional or stricter requirements (for example under GDPR, UK GDPR, PIPEDA/CPPA, HIPAA or applicable U.S. state breach/consumer privacy rules), Vomela will apply the more protective requirement.
3.5 Rights of the Individual
3.5.1 Data Subject Rights
Vomela recognizes and respects the rights of data subjects and will provide mechanisms to enable individuals to exercise their rights under applicable data protection laws. Data subjects have the following rights (subject to any applicable legal exemptions and limitations):
a) Right to be informed: to receive clear, transparent information about the processing of their personal data (e.g., via privacy notices or at the time of collection).
b) Right of access: to obtain confirmation whether their personal data is being processed and, where it is, to receive a copy of the personal data and certain supplementary information.
c) Right to rectification: to have inaccurate or incomplete personal data corrected without undue delay.
d) Right to erasure (right to be forgotten): to request deletion of personal data where a lawful ground for retention no longer exists, subject to any applicable legal or contractual retention obligations.
e) Right to restrict processing: to request a temporary restriction on processing where accuracy is contested, processing is unlawful and erasure is opposed, Vomela no longer needs the data for the purpose but the individual requires it for legal claims, or the individual has objected to processing pending verification of legitimate interests.
f) Right to data portability: to receive personal data they have provided to Vomela in a structured, commonly used and machine‑readable format, and to transmit that data to another controller where technically feasible.
g) Right to object: to object to processing based on legitimate interests or for direct marketing; Vomela will stop processing unless it can demonstrate compelling legitimate grounds or needs the data for legal claims.
h) Rights related to automated decision‑making and profiling: to request human intervention, express views and contest decisions where automated decision‑making produces legal or similarly significant effects, subject to limited lawful exceptions.
3.5.2 Handling Requests
a) Submission: Data subject requests should be submitted using Vomela’s designated privacy request channels IT.Compliance@Vomela.com will verify the requester’s identity before responding if necessary.
b) Fees: Vomela will not charge a fee for handling legitimate requests except in limited circumstances permitted by law (e.g., where requests are manifestly unfounded or excessive). If a fee is to be charged or the request is refused, Vomela will provide a clear explanation.
c) Refusal and partial compliance: If Vomela refuses a request in whole or in part, it will inform the individual of the reasons for refusal and any available review or complaint mechanisms (including supervisory authorities).
d) Recordkeeping: Vomela will log and retain records of data subject requests and responses to demonstrate compliance.
3.5.3 Timelines
Timelines and extensions Vomela will respond to data subject requests in accordance with applicable law:
a) For GDPR/UK GDPR: Vomela will respond without undue delay and in any event within one month of receipt of the request. That period may be extended by a further two months where necessary, taking into account the complexity and number of the requests; Vomela will inform the requester of any extension within one month of receipt and provide reasons for the delay.
b) For Canadian federal/provincial law (PIPEDA/CPPA and applicable provincial rules): Vomela will follow applicable timelines under that law and will communicate any specific timelines or extensions in the response.
c) For U.S. state privacy laws and HIPAA: Vomela will comply with relevant state timelines or HIPAA requirements where applicable and will advise requesters of any jurisdictional differences.
To make such requests, please refer to the below.
When we are processing data on behalf of another party that is the “data controller,” you should direct your request to that party.
We provide certain choices regarding the information Visitors provide to us. We have created some mechanisms to provide you with control over your information when using our Website. First, if you do not wish to have your e-mail address used for promotional purposes by PFL, you may withdraw consent at a later time by contacting PFLTrust@PFL.com.
Second, you may contact PFLTrust@PFL.com
to request changes to any personal information that you have provided to us in connection with the Website or Services. We will use reasonable efforts within the scope of our business and technology practices to respond to such requests for correction or updates to personal information.
1Contact Information
To inquire or comment about this Privacy Statement and our privacy practices or if you need to update, change or remove your information, contact us at:
PFL Tech, Inc
Attn: Privacy Officer
100 PFL Way
Livingston, MT 59047
www.pfl.com
1-800-930-5088
Updates as of July 2021
PFLTrust Compliance Information
GDPR Statement of Compliance
Introduction
The General Data Protection Regulation (“GDPR”), which will become enforceable on May 25th, 2018, aims to strengthen the security and protection of personal data in the European Union (“EU”). This rule clarifies how the EU personal data laws apply even beyond the borders of the EU and will replace the European Privacy Directive and national legislations accordingly. Any organization that works with EU residents’ personal data in any manner has obligations to protect the data. PFL Tech, Inc. (“PFL”) is well aware of its role in providing the right tools and processes to support its users and customers in order to meet their GDPR mandates.
PFL’s Commitment
At PFL, we have demonstrated our commitment to data privacy and protection by meeting the industry standards for PCI, HIPAA, SOC 1 and SOC 2. We recognize that the GDPR will help us move towards the highest standards of operations in protecting customer data and PFL attests that we will comply with applicable GDPR regulations as a data processor by the May 25th, 2018 enforcement date.
PFL GDPR Roles and Employees
PFL has designated Casey Bartz, Chief Technology Officer, as our Data Protection Officer (DPO) and has a dedicated internal team of cross-functional stakeholders to develop and implement our roadmap for GDPR compliance. The team is responsible for promoting awareness of the GDPR across the organization, assessing our GDPR readiness, identifying any gap areas and implementing the new policies, procedures and measures. PFL understands that continuous employee awareness and understanding is vital to the continued compliance of the GDPR. We have incorporated GDPR specific content to PFL’s onboarding and annual employee training programs.
PFL GDPR Readiness
Our readiness initiatives include:
- Designating data privacy roles;
- Building on existing security policies, processes and controls;
- Providing visibility and transparency;
- Enhancing data integrity and security;
- Portability and transferability of data;
- Identifying personal data;
- Encrypting, anonymizing or deleting user data; and
- Creating provisions for data subject’s rights.
PFL Users and Customers
Compliance with the GDPR requires a partnership between PFL and our users and customers in their use of applicable PFL services. In this context, PFL will act as a data processor and our users and customers will act as data controllers. Working together, we hope to explore opportunities within our relevant service offerings to support our users and customers in meeting their GDPR obligations. PFL encourages partners and customers to independently familiarize themselves with the GDPR. Please direct questions or comments regarding PFL’s data privacy program to
GDPR or CCPA Data Request Form
Request a copy of the data that we have stored about you or request that your data be removed from our system.
