VIRGINIA, COLORADO, AND CONNECTICUT PRIVACY NOTICE

This Virginia, Colorado, and Connecticut Privacy Notice is incorporated into our Privacy Policy by reference. To view these terms, please see our Privacy Policy.

The Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and similar laws in other U.S. states ("State Privacy Laws") provide their consumers with specific rights regarding their personal information. To the extent that you are a resident of one of these states, this section describes your rights under the State Privacy Laws and explains how you may exercise these rights.

The categories of personal information we process, our purposes for processing your personal information, the categories of personal information that we share with third parties, and the categories of third parties with whom we share it are set forth in the terms of our Privacy Policy and in the Personal Information Processing Chart. To the extent that our personal information processing activities are addressed by a separate privacy notice (e.g., for our Love ISDIN Program), please consult the terms of that privacy notice for detailed information about our data practices, including the categories of personal information that we collect and disclose.

Rights to Your Information

In addition to the rights set forth in our Privacy Policy, the State Privacy Laws provide you with the following rights:

Right to know. You have the right to know whether we process your personal information and to access such personal information.

Right to data portability. You have the right to obtain a copy of your personal information that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another business without hindrance, where the processing is carried out by automated means. You may request such personal information up to twice annually, subject to certain exceptions.

Right to delete. You have the right to delete personal information that you have provided by or that we have obtained about you. Please note that we may deny such request if the requested deletion falls under an exception as set forth in State Privacy Laws. Additionally, if you request deletion of your personal information and we have obtained such information from a third-party source, we may retain such data by keeping a record of the deletion request and the minimum data necessary to ensure that your personal information remains deleted from our records and that such retained data is not used for any other purpose, or we may opt you out of the processing of such personal information for any purpose except for those allowed under State Privacy Laws.

Right to opt out. You have the right to opt out of the processing of the personal information for purposes of: (i) targeted advertising; (ii) the sale of personal information; or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. As of the latest date of the Privacy Policy:

We DO process personal information for the purposes of targeted advertising;

We DO sell your personal information in exchange for monetary or other valuable consideration; and

We DO NOT engage in profiling decision based on your personal information that produce legal or similarly significant effects concerning you.

If you wish to opt out of the processing of your personal information for any of the above purposes, please email us at privacy.us@isdin.com. For residents of Colorado and Connecticut, we will also treat opt-out preference signals as valid opt-out requests.

Right to correct. You have the right to correct inaccuracies in your personal information, taking into account the nature of the personal information and the purposes for which we process it.

Right to nondiscrimination. You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights. Unless permitted by State Privacy Laws, we will not:

Deny you goods or services;

Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;

Provide you a different level or quality of goods or services; or

Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

How to Exercise Your Rights; Verifying Your Identity

To exercise any of your privacy rights, or if you have any questions about your privacy rights, you may contact us by emailing us at privacy.us@isdin.com.

After submitting a request, we will take steps to verify your identity in order for us to properly respond and/or confirm that your request is not fraudulent. We may contact you for additional information as reasonably necessary to authenticate your request, but if we are ultimately unable to authenticate your request using reasonably commercial efforts, then we may not be able to comply with it.

Only you may make a verifiable request related to your personal information. If you are making a request as the parent or legal guardian of a known child regarding the processing of that child’s personal information, we may ask you to submit reliable proof of your identity.

Response Time; Your Right to Appeal

We will make every effort to respond to your request within 45 days from when you contacted us. If you have a complex request, State Privacy Laws allow us up to 90 days to respond. We will contact you within 45 days from when you contacted us to inform you of the need for additional time and the reason for such extension. We may charge you a reasonable fee to cover administrative costs if your requests are manifestly unfounded, excessive, or repetitive.

If we decline to take action on a request that you have submitted, we will inform you of our reasons for doing so, and provide instructions for how to appeal the decision. You will have the right to appeal within a reasonable period of time after you have received our decision. Within 60 days (45 days for residents of Colorado) of our receipt of your appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If we deny your appeal, we will provide you with a method for contacting your state attorney general’s office to submit a complaint.

PERSONAL INFORMATION PROCESSING CHART

In the past 12 months, we have collected the following categories of personal information from the sources described in the section of the Privacy Policy titled How We Collect Your Personal Information. The chart below describes our business or commercial purposes for collecting and disclosing these categories personal information, the parties we have disclosed such information to, and whether we have sold or shared (or otherwise disclosed for targeted advertising) each category of personal information. Depending on your level of interaction with us, we may not have collected your personal information from all of the categories listed below. The categories of personal information described below are retained and stored for as long as is necessary to effectuate the business and commercial purposes for which they have been collected, and otherwise as described in the section of the Privacy Policy titled Data Retention.

Category of data: Personal Identifiers

Examples

A real name, postal address, online identifier, Internet Protocol address, email address, account name.

Business or Commercial Purposes for Collecting Personal Information

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors.

Providing personalized advertising and marketing services.

For analytics and personalisation

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

For security and fraud prevention. This may include: helping maintain the safety, security, and integrity of our Service, databases and other technology assets, and business; internal research; technological development and demonstration; and improving, upgrading, or enhancing our Service; detecting security incidents; protecting against malicious, deceptive, fraudulent, or illegal activity; and prosecuting those responsible for that activity; and investigating suspected fraud, harassment, or other violations of any law, rule, or regulation, or the policies for our Service.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors.

Providing personalized advertising and marketing services.

For analytics and personalisation

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Marketing and advertising.

For analytics and personalisation

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Service providers who perform business services for us.

Marketing and advertising partners.

Category of data: Personal information covered by the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

Examples

A name, physical characteristics or description, address, telephone number, credit card number, debit card number, or any other financial information.

Business or Commercial Purposes for Collecting Personal Information

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors.

Providing personalized advertising and marketing services.

For analytics and personalization

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

For security and fraud prevention. This may include: helping maintain the safety, security, and integrity of our Service, databases and other technology assets, and business; internal research; technological development and demonstration; and improving, upgrading, or enhancing our Service; detecting security incidents; protecting against malicious, deceptive, fraudulent, or illegal activity; and prosecuting those responsible for that activity; and investigating suspected fraud, harassment, or other violations of any law, rule, or regulation, or the policies for our Service.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors.

Providing personalized advertising and marketing services.

For analytics and personalisation.

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

To comply with legal obligations.This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Marketing and advertising.

For analytics and personalisation

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Service providers who perform business services for us.

Marketing and advertising partners.

Category of data: Commercial information

Examples

Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Business or Commercial Purposes for Collecting Personal Information

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors

Providing personalized advertising and marketing services.

For analytics and personalisation.

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

For security and fraud prevention. This may include: helping maintain the safety, security, and integrity of our Service, databases and other technology assets, and business; internal research; technological development and demonstration; and improving, upgrading, or enhancing our Service; detecting security incidents; protecting against malicious, deceptive, fraudulent, or illegal activity; and prosecuting those responsible for that activity; and investigating suspected fraud, harassment, or other violations of any law, rule, or regulation, or the policies for our Service.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

To communicate with you. This may include: contacting you about and providing you and our clients with our Service; enabling our website chat function; responding to your direct inquiries, requests, issues or feedback, and providing customer service; and adding you to our mailing lists and sending you emails from time to time.

To provide our products and services. This may include: operating the Service, and providing you with any specific services that you have requested; creating, maintaining, and otherwise managing your account, profile, or subscription; delivering content and product and service offerings relevant to your interests; fulfilling your orders and/or completing the transactions you have requested, processing your payments, and providing you receipts and order updates; to remind you of items you have left in your cart; and providing a forum for discussion, asking questions, posting photos and reviews, and sharing experiences.

Helping to ensure the security and integrity of our services, to verify or maintain the quality or safety of our services, and to identify and repair errors.

Providing personalized advertising and marketing services.

For analytics and personalisation

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Marketing and advertising partners

For analytics and personalisation

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Marketing and advertising partners.

Service providers who perform business for us.

Category of data: Internet or other similar network activity.

Examples

Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.

Business or Commercial Purposes for Collecting Personal Information

Providing personalized advertising and marketing services.

For analytics and personalisation

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

Providing personalized advertising and marketing services.

For analytics and personalisation

For other business services performed on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services.

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Marketing and advertising partners.

For analytics and personalisation

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Marketing and advertising partners.

Service providers who perform business for us.

Category of data- geolocation data.

Examples

Information sufficient to identify the name of a city or town.

Business or Commercial Purposes for Collecting Personal Information

Providing personalized advertising and marketing services.

For analytics and personalisation

For security and fraud prevention. This may include: helping maintain the safety, security, and integrity of our Service, databases and other technology assets, and business; internal research; technological development and demonstration; and improving, upgrading, or enhancing our Service; detecting security incidents; protecting against malicious, deceptive, fraudulent, or illegal activity; and prosecuting those responsible for that activity; and investigating suspected fraud, harassment, or other violations of any law, rule, or regulation, or the policies for our Service.

To comply with legal obligations. This may include: compliance with legal or regulatory obligations, establishing or exercising our rights, and to defending against a legal claim; responding to law enforcement requests and as required by applicable law, court order, legal process, or governmental regulation.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

Providing personalized advertising and marketing services.

For analytics and personalisation

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Service providers who perform business for us.

For analytics and personalisation

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Marketing and advertising partners.

Service providers who perform business for us.

Category of data- Inferences drawn from other personal information for profiling purposes.

Examples

Used to create a profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

Business or Commercial Purposes for Collecting Personal Information

Providing personalized advertising and marketing services.

Disclosed  in the Prior Twelve (12) Months for the Following Business Purposes

Providing personalized advertising and marketing services.

For analytics and personalisation

“Sold” or “Shared” in the Prior Twelve (12) Months for the Following Purposes

Service providers who perform business for us.

Categories of Third Parties With Whom We Disclose, Sell, or Share Personal Information

Marketing and advertising partners.

Service providers who perform business for us.