PRIVACY POLICY
Thank you for accessing www.carton.com (hereinafter, CARTON.COM) owned by CARTON COMPANY INCORPORATED S.A. de C.V., a company responsible for the processing of your personal data, with its address at Av. Paseo Monte Miranda No.17 ORVIT BUSINESS CENTER Floor 5 Fracc. Monte Miranda 76240 El Marqués, Querétaro, Mexico.
At CARTON.COM, we work every day to serve you better when you bid, make an offer, or use our services. Protecting the Personal Data you share with us is a fundamental part of this. Therefore, we want to assure you that your information is safeguarded and protected with us, and explain how we use it to offer you a better and more personalized customer experience when you use our services.
This Privacy Notice explains the processing we do of your Personal Data, to whom, under certain conditions, we transfer and/or transmit your Personal Data, as well as the security measures we have taken to protect them. It also explains the rights you have as the owner of your Personal Data and how you can exercise them.
We invite you to read this Privacy Notice carefully, and if you have any questions, please contact us via email at [email protected], by phone at (442) 5000-445, or by sending a communication to Av. Paseo Monte Miranda No.17 ORVIT BUSINESS CENTER Floor 5 Fracc. Monte Miranda 76240 El Marqués, Querétaro, Mexico.
I. DEFINITIONS
SELLER: A natural or legal person who "offers" a specific product, based on a "bid" published by the buyer.
BUYER: A natural or legal person who, by publishing a "bid," seeks to acquire a product with certain characteristics (images, logos, brands, color combinations, structures, designs, and other distinguishing elements) through an offer from the sellers.
ATTENTION CHANNELS: Means through which you can exercise your rights, which are: (i) via email at [email protected], (ii) directly at Av. Paseo Monte Miranda No.17 ORVIT BUSINESS CENTER Floor 5 Fracc. Monte Miranda 76240 El Marqués, Querétaro, Mexico, or by phone at (442) 5000-445.
CARTON.COM OR CONTROLLER: CARTON COMPANY INCORPORATED S.A. de C.V.
PERSONAL DATA: Any information concerning an identified or identifiable natural person. For example, CARTON.COM may collect the following Personal Data: name, identification number, address, phone number, email, geolocation data, use and visit of the website, browsing history, and purchase habits.
SENSITIVE PERSONAL DATA: Sensitive data is understood to be those that affect the most intimate sphere of the USER, or whose improper use could lead to discrimination or involve a serious risk for the user. Sensitive data are considered to be those that may reveal aspects such as racial or ethnic origin, current health status and morals, union affiliation, political opinions, sexual preferences, etc.
CONSENT: Expression of the USER’s will to allow the processing of their data.
DATA PROCESSOR: A natural or legal person, public or private, who individually or jointly processes Personal Data on behalf of the Data Controller.
DATA CONTROLLER: A natural or legal person, private entity, who decides on the database and/or the processing of data.
USER: A natural person whose Personal Data is processed.
PROCESSING OF PERSONAL DATA: The obtaining, use, disclosure, or storage of personal data by any means. Use encompasses any action of access, management, utilization, transfer, or disposition of personal data.
II. AUTHORIZATION
By accepting this Privacy Policy, you authorize CARTON.COM to process your Personal Data.
CARTON.COM will only process your Personal Data with your authorization and solely for the purposes indicated in section V of this document. You may revoke your authorization at any time by requesting it through any of the means indicated in section VIII.
III. TRANSFER OF PERSONAL DATA TO THIRD PARTIES
Additionally, by accepting this Privacy Notice, you authorize CARTON.COM to share your Personal Data with Related Companies and with the SELLER or BUYER of CARTON.COM, as applicable, for the purposes indicated in section V. However, as a USER, you may revoke the authorization granted or object to receiving commercial communications at any time by requesting it through any of the means indicated in section VIII.
Likewise, in the event of choosing the winner of the BID, you authorize CARTON.COM to transfer the databases containing your Personal Data to the SELLER.
Notwithstanding the provisions of this Privacy Notice, CARTON.COM may not disclose your Personal Data to third parties unless it has obtained your prior consent or is legally required to do so.
CARTON.COM will be responsible for the effective compliance with the obligations regarding the processing of Personal Data by its Related Companies and its SELLERS or BUYERS, without prejudice to the responsibility that may apply to them for any breach of such obligations. Similarly, if the processing of Personal Data is to be carried out by service providers for CARTON.COM, such service providers must assume confidentiality commitments and adopt measures that ensure due compliance with Personal Data protection regulations, especially those established in the Federal Law on the Protection of Personal Data Held by Private Parties and its Regulations.
IV. GENERAL PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
Our commitment is to ensure that all Processing of Personal Data we perform is always done respecting the rights that the Constitution and laws grant you. Therefore, we want to inform you about the principles that guide us in this matter:
PRINCIPLE OF LEGALITY: Personal data must be collected and processed lawfully. The collection of personal data must not be done through deceptive or fraudulent means.
PRINCIPLE OF CONSENT: All Processing of Personal Data will be subject to the USER's consent. Consent will be explicit when the will is expressed verbally, in writing, by electronic, optical, or any other technology, or by unequivocal signs. The USER tacitly consents to the processing of their data when the privacy notice is made available, and they do not express their opposition.
PRINCIPLE OF INFORMATION: The Data Controller must inform the USER about the Personal Data being collected and the purposes through the privacy notice.
PRINCIPLE OF QUALITY: The Data Controller will ensure that the personal data contained in the databases are relevant, correct, and updated for the purposes for which they were received.
PRINCIPLE OF PURPOSE: The Processing of Personal Data must be limited to fulfilling the purposes outlined in the privacy notice. If the Data Controller intends to process the data for a purpose that is not compatible or analogous to the purposes established in the Privacy Notice, the Data Controller must obtain the USER's consent again.
PRINCIPLE OF LOYALTY: Processing Personal Data must be done fairly and lawfully, meaning with full compliance with legality and respect for good faith and the rights of the USER, whose information is subject to Processing.
PRINCIPLE OF PROPORTIONALITY: The Data Controller may only use the USER's Personal Data in accordance with the express purposes of its collection.
PRINCIPLE OF ACCOUNTABILITY: The Data Controller will ensure compliance with the principles of Personal Data protection established in the Federal Law on the Protection of Personal Data Held by Private Parties, and will adopt the necessary measures for their application, even when processed by a third party at the request of the Data Controller. The Data Controller must take the necessary and sufficient steps to ensure that the privacy notice made available to the USER is respected at all times, by the Data Controller or by third parties with whom a legal relationship exists.
CARTON.COM will be responsible for the effective compliance with the obligations regarding the processing of data by its Related Companies, without prejudice to the responsibility of these entities for any breach of such obligations. Likewise, if the processing of data is to be carried out by service providers for CARTON.COM or its Related Companies, such service providers must assume confidentiality commitments and adopt measures to ensure compliance with the obligations of the Data Protection Law.
V. PURPOSES FOR WHICH YOUR PERSONAL DATA MAY BE PROCESSED
Your Personal Data may be processed by CARTON.COM, its Related Companies, or through its suppliers, exclusively for the following purposes:
- Perform the necessary management to develop the corporate purpose of CARTON.COM regarding the fulfillment of the contract entered into with the USER.
- Comply with obligations contracted with the USER.
- Provide Personal Data to third parties with whom CARTON.COM has a contractual relationship and to whom it is necessary to provide such data for the fulfillment of the contracted purpose. For example, CARTON.COM may use third parties to help collect your payments, send products, or operate our customer service systems.
- Prepare, implement, promote, and offer you new products and/or services, or new features, modes, or characteristics of the products and/or services that are already available to you.
- Automatically complete documents associated with transactions you make based on the products and/or services purchased, or that you may purchase in the future, from CARTON.COM and/or its Related Companies.
- Develop commercial actions or after-sales services, whether general or personally directed at you, aimed at improving your customer experience.
- Send information via physical mail, email, text messages (SMS and/or MMS), digital means such as Facebook, "WhatsApp," or similar platforms, to the cell number or communication medium you provide us, for the purpose of verifying your Personal Data, and to send information about the chosen SELLER through the BID.
- Share Personal Data with third parties who are Business Partners and Related Companies, so they can offer products and/or services that improve the value proposition for CARTON.COM customers, all in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties.
- Transfer personal data outside or within the country to Related Companies, so that they can process your Personal Data according to the purposes set forth in this Policy, in accordance with the provisions of section V.
- Transmit Personal Data within or outside the country to third parties, in accordance with section III of this policy.
VI. RIGHTS OF THE USER OF PERSONAL DATA ACCORDING TO THE FEDERAL LAW ON THE PROTECTION OF PERSONAL DATA HELD BY PRIVATE PARTIES
The USER of Personal Data will have the following rights:
- ARCO rights (Access, Rectification, Cancellation, and Opposition) of their Personal Data.
- Request proof of the authorization granted to CARTON.COM for the Processing of their Personal Data.
- Be informed by CARTON.COM, upon request, in accordance with section VII of this Policy, about the use that has been made of their Personal Data.
- Submit inquiries to the Data Controller or Data Processor, in accordance with section 3 of this policy, and file complaints with the National Institute for Transparency, Access to Information, and Protection of Personal Data.
- Access Personal Data that is subject to Processing free of charge, in accordance with Article 22 of the Federal Law on the Protection of Personal Data Held by Private Parties.
- Revoke the authorization granted for the processing of Personal Data.
The USER of Personal Data is responsible for keeping their information updated and ensuring its accuracy at all times. CARTON.COM will not be responsible for any liability arising from inaccurate information.
VII. PROCEDURE FOR EXERCISING ARCO RIGHTS UNDER THE FEDERAL LAW ON THE PROTECTION OF PERSONAL DATA HELD BY PRIVATE PARTIES
You may exercise the rights mentioned in the previous section and all other rights granted by the Federal Law on the Protection of Personal Data Held by Private Parties by contacting CARTON.COM via email at [email protected], by phone at (442) 5000-445, or by sending a communication to Av. Paseo Monte Miranda No.17 ORVIT BUSINESS CENTER Floor 5 Fracc. Monte Miranda 76240 El Marqués, Querétaro, Mexico. The Legal and Governance Affairs Management will be responsible for issuing the guidelines for addressing requests, inquiries, and complaints, through which the USER can exercise their rights to know, update, rectify, and delete Personal Data, and revoke authorization for the Processing of Personal Data.
ARCO Rights
If you wish to exercise your ARCO rights (access, cancellation, rectification, and opposition to the processing of your personal data), or revoke the consent you have given to CARTON.COM for the Processing of your Personal Data stored in our databases, you must contact CARTON.COM through the Attention Channels and submit a request for Personal Data consultation. To do this, it is necessary that, at the time of submitting the request, you (a) send the documents that prove the identity of the USER or the representative's authority, (b) the name and address of the USER, (c) a clear and precise description of the Personal Data for which the USER seeks to exercise any of the rights, (d) the express statement to revoke your consent for the processing of your personal data and, therefore, not to be used, and (e) any other element or document that facilitates the location of the Personal Data. If the USER's request for Personal Data is unclear, erroneous, or incomplete, CARTON.COM may ask the USER to provide additional information to process the request within five (5) business days following receipt of the request. If the USER does not respond within ten (10) business days of the request for additional information, the request will be considered not submitted.
CARTON.COM will communicate to the USER via email or any means it deems appropriate, within a maximum period of twenty (20) business days from the date of receipt, the determination adopted, so that, if applicable, it can be effectively implemented within fifteen (15) business days from the date the response is communicated. When it is not possible to address the inquiry within the established terms, the aforementioned deadlines may be extended once for equal periods, and the USER will be informed of this situation, indicating the reasons for the delay and the date the inquiry will be addressed.
Complaint for Rectification, Cancellation, or Opposition of Personal Data
If you wish to file a complaint for rectification, cancellation, or opposition of Personal Data, you must contact CARTON.COM through the Attention Channels, and CARTON.COM will address your request under the same terms as the previous section of this document.
If you express, through any of the Attention Channels, that you do not wish to receive advertising, CARTON.COM will process your request within twenty (20) business days from receipt of the request. In this way, you will receive an email confirming the removal of your Personal Data from CARTON.COM's advertising databases. Additionally, you will be asked to confirm if you want your CARTON.COM account to be deleted. The USER will have a period of five (5) business days from the date of the email to make this confirmation. If the USER confirms that they want their CARTON.COM account to be deleted, or if they do not respond within five (5) business days, CARTON.COM, in compliance with current data protection regulations, will proceed to delete the account within five (5) business days.
The deletion of the CARTON.COM account will result in the loss of all your BID history, as well as any other personal information that CARTON.COM holds about the USER.
The request for opposition of information and the revocation of Consent will not proceed when there is a legal, contractual, or commercial obligation for you to remain in our database.
VIII. COOKIES AND THEIR USE BY CARTON.COM
At CARTON.COM, we use cookies and similar technologies to personalize and improve your customer experience and to show you relevant online advertising.
Cookies are small text files that contain a unique identifier stored on the computer or mobile device through which you access the Site so that they can be recognized each time you use the Site.
You may choose to disable some or all of the cookies we use at any time. However, this may restrict your use of the Site and limit your experience on it. The use of cookies does not contain or affect Personal Data and does not pose a risk of viruses. If you want more information about cookies, go to http://www.allaboutcookies.org. If you want information on how to delete cookies, visit the website http://www.allaboutcookies.org/manage-cookies/index.html.
IX. CARTON.COM IS NOT RESPONSIBLE FOR THIRD-PARTY SITES ADVERTISED ON THE SITE
To enhance your customer experience, the Site may contain third-party advertising and links to other sites or frames of other sites. Please note that CARTON.COM is not responsible for the privacy practices or content of such third parties or sites, so you should review their privacy policies.
X. SAFEGUARDS TAKEN BY CARTON.COM TO PROTECT YOUR PERSONAL DATA
CARTON.COM maintains the physical, electronic, and procedural safeguards required by law in relation to the collection, storage, and transfer of your Personal Data, and periodically evaluates their effectiveness. The purpose of these safeguards is to prevent unauthorized or illegal access, accidental loss, destruction, or damage to your Personal Data.
Therefore, when CARTON.COM collects data from the Site, it does so through a secure server that features protection programs. Additionally, CARTON.COM's security procedures require that at times you provide proof of identity before delivering information about your Personal Data. For electronic payment card information, CARTON.COM also uses Secure Socket Layer (SSL) encryption systems that encode the information to prevent fraudulent uses. Although this cannot be guaranteed, these systems have proven effective in handling sensitive information, preventing access by external threats (e.g., hackers). Notwithstanding the above, we recommend not sending credit or debit card data unencrypted or from public or unsecured sites or devices. Please note that you are solely responsible for protecting against unauthorized access to your password and computer.
XI. VALIDITY AND MODIFICATION OF THIS PRIVACY POLICY
This policy will apply from January 28, 2021, and your Personal Data will remain stored only for the time required by law or to fulfill the purposes authorized by you. This policy may be modified by CARTON.COM at any time. Notwithstanding the above, CARTON.COM will inform you, by any means deemed appropriate, of any significant changes prior to such modification taking effect.