PRIVACY AND DATA SECURITY STATEMENT
Thank you for visiting the online and mobile resources operated by Healthy Trends Worldwide LLC, including www.bloodflowdaily.com, and for viewing this privacy and data security statement. Our privacy statement, contained in the pages that follow, serves to give notice about the types of personal information we collect, how we use it, who we share it with and why, and what we do to try to protect it. We delve into those matters in a fair amount of detail in the pages that follow. We encourage you to read them carefully. In the meantime, we provide a quick overview below.
Summary of how we handle Personal Information
|
|
We collect and retain certain personal information from a variety of different data subjects. Our privacy statement applies mostly to those who visit and use our online and mobile resources, from whom we collect very little information unless it is voluntarily submitted to us. You can read here to learn about the categories of personal information we collect. |
We use personal information received from visitors and users of our online and mobile resources to communicate directly with them, complete transactions, personalize offers. We provide further detail about our use of personal information here. |
We share personal information when needed to fulfill our legal obligations and when our vendors and business partners need it to perform under the contracts we have with them. We provide further detail about our sharing of personal information here. We do not sell or rent any personal information. |
We’ve invested in a Security Program that addresses both technical and operational matters. Our program includes incident response and management and vendor oversight components. You can read about those components here and here. |
While certain features of our online and mobile resources do require that you provide some personal information, you can choose not to use those specific features and still enjoy the remainder of online and mobile resources. Moreover, you can opt out of certain activities. You can learn more about that here. |
Contacting Our Privacy Office
If you have any questions about our privacy and data security policies, procedures and practices, including anything we say in this privacy statement, we encourage you to contact our Privacy Office.
This privacy statement was amended as of March 1st, 2023 and is effective as of that date. The English language version of this privacy statement is the controlling version regardless of any translation you may attempt.
NAVIGATING THROUGH THIS STATEMENT
You can use the links below to navigate to areas of this statement that apply specifically to you, or which may otherwise be of interest:
Although not itself a contract, this privacy statement is an important document that explains how we address some ofour legal obligations, and your related legal rights, involving personal information. Clarity is therefore important. We’ll use this section to let you know about some words that have special meanings whenever you see them in this statement. Let’s start with the word “statement” itself: when we reference “this statement”, “this privacy statement” and “ our statement”, we mean the Privacy and Data Security Statement you are reading now. Wherever we say “Company”, “we”, “us”, or “our”, we mean Healthy Trends Worldwide LLC. We use the words “you” and “your” to mean you, the reader, and other visitors to our online and mobile resources who are, in all cases, over the age of 16.This age requirement is discussed in more detail later in this statement here.
When we talk about our “ online and mobile resources” , we mean all websites, portals or otherfeatures we operate to allow you to interact with us and our systems, as well as the mobile apps we’ve created and distributed to let you interact with the content we provide and participate in our rewards or the similar programs we may offer. An “affinity action” is when you “follow” us, “like” us or take a similar or analogous action on our external social media presence.
Finally, and perhaps most importantly, when we refer to “ personal information ”, we mean any information, data or data element, whether in electronic or other form, that, alone or in combination with other elements, can be used to distinguish, trace, or discover your identity. Certain data privacy laws include specific elements or defined terms for what they consider to be personal information (sometimes also referred to as “personal data”). Where such data privacy laws apply, then the term “personal data” includes the specific elements and defined terms required by such laws.
WHEN AND TO WHOM DOES THIS PRIVACY STATEMENT APPLY?
Our online and mobile resources collect personal information from the following data subjects:
This statement applies to our processing and sharing of personal information collected from those specific data subjects listed above whenever they visit www.bloodflowdaily.com or any other mobile or online resources we may operate. If we have legal obligations to other categories of data subjects, such as our employees, supply chain partners or vendors, we provide them with separate legally required notices in confidential contracts, policies and other similar documents.
WHERE DO WE GET YOUR PERSONAL INFORMATION FROM, WHAT CATEGORIES DO WE COLLECT, AND HOW DO WE USE AND SHARE IT?
The table immediately below provides detailed listing, on a category-by-category basis, of the types of personal information we collect or obtain, how we do so, and the ways in which we use and share it. In the remainder of this section we proved a more detailed description of each respective category and type of sharing. By using our online and mobile resources, you are signifying to us that you agree with this section of our privacy statement and that we may use and share your information as described .
Categories of Personal Information |
Business Purpose |
Categories of Sources |
Categories of Third Parties |
General Identifiers |
|
|
|
Protected Characteristics |
|
|
|
Commercial Information |
|
|
|
Internet Activity Data |
|
|
|
Geolocation Data |
|
|
|
Financial Data |
|
|
|
Audio/Visual Data |
|
|
|
Categories of Sources - where do we get your personal information ?
We collect and otherwise obtain your personal information in the following ways:
Voluntary Submissions. Here are some of the ways you voluntarily give us your personal information:
If you prefer we not receive the above-described personal information, please don’t submit it. This means you shouldn’t participate in the applicable activities on, or use the applicable features available from our online and mobile resources. Such participation and use is strictly your choice. By not participating, you may limit your ability to take full advantage of the online and mobile resources, but most of the content in our online and mobile resources will still be available to you and we never discriminate on the basis of how much information your provide.
Automatic Collection
If you access our online and mobile resources from a phone or other mobile device, the mobile services provider may transmit to us certain information such as uniquely identifiable mobile device information. That, in turn, allows us to collect mobile phone numbers and associate them with the mobile device identification information. Some mobile phone service providers also operate systems that pinpoint the physical location of devices and we may receive this geolocation data as well.
In addition, when you use our online and mobile resources, we may allow third party service providers to place their own cookies or similar technologies in order to engage in the same types of collection we describe above. For example, we use third party “web analytics” services such as those offered by Google Analytics. For more information on how Google specifically uses this data, go to www.google.com/policies/privacy/partners/ . You can learn more about how to opt out of Google Analytics by going to https://tools.google.com/dlpage/gaoptout .
Do Not Track (DNT) is a privacy preference that users can set to have their Internet browser automatically send a signal to our online and mobile resources to request we not track browsing activity across different sites. There is, however, currently no universal standard for sending and receiving DNT signals.As such, we cannot promise that we respond to all DNT signals, but do recognize and respond when required by Comprehensive Privacy Laws, such as when HTTP header fields or Java objects are used.
External Sources. We may work with companies who make data, including personal information, available so that companies like us can tailor our services to audiences who have the most interest. We also may work with digital advertising and marketing companies to provide you with ads that meet your interests and that enhance your experience with us. These ads may be displayed on websites or device applications operated by third parties. These third parties collect information with their own cookies, pixels, and related tracking technology and then provide that information to us. We are not responsible for their data collection practices.
We further maintain a presence on one or more external social media platforms such as Twitter, Facebook, YouTube and LinkedIn. We may allow the community features of our online and mobile resources to connect with, or be viewable from, that external social media presence. Similarly, our online and mobile resources may contain links to other websites or apps controlled by third parties. We are not responsible for either the content on, or the privacy practices of, social media platforms, or any third party sites or apps to which we link. Those apps, sites and platforms are not controlled by us and therefore have their own privacy policies and terms of use. To be clear: neither this statement nor the terms of use appearing on or in any of our online and mobile resources apply to our social media presence or any third party sites or apps to which we may link. That means even if you take an affinity action on our specific social media presence, and identifiers about you are automatically collected and given to us as a result, that collection and transfer is governed by the privacy policies and other terms of the applicable social media platform and are not our responsibility.
If you have questions about how those apps, sites and platforms collect and use personal information, you should carefully read their privacy policies and contact them using the information they provide. In addition, certain coalitions of advertisers allow consumers to opt out of receiving interest-based advertising from members of those coalitions. You can follow the links below to opt out of receiving interest-based advertising from members of these coalitions. You will need to exercise these opt outs on each browser on each device for which you wish to opt out of interest-based advertising.
Categories of Data – what types of personal information do we collect ?
The categories of personal information we have collected from visitors and users of our online and mobile resources in the previous 12 months, and may collect from you, are as follows, some elements of which, such as social security numbers, may be considered “sensitive information” under applicable law:
How Do We Use The Personal Information We Collect ?
Use for Legitimate Business Purposes. We use the personal information we collect only in the manner and through the means allowed by applicable law. That means we determine whether we have a lawful basis/legitimate business purpose to use your personal information before doing so. As stated in applicable law, such lawful bases/legitimate business purposes include receiving express consent, operating our business, performing a contract, and complying with a legal obligation. More specifically, weuse personal information to do the following:
Retention of Your Personal Information. We store and retain your personal information in accordance with applicable law and as long as necessary to carry out the purposes described above and in accordance with our internal data retention procedures. The criteria used to determine the retention periods include:
When/With Whom Do We Share Personal Information ?
We do not sell, and within the last 12 months have not sold, personal information to third parties. We may, however,share your personal information as listed below and have so shared the personal information of other users within the last 12 months:
HOW DO WE PROTECT COLLECTED PERSONAL INFORMATION?
We have adopted, implemented and maintain an enterprise-wide corporate information security and privacy program that includes technical, organizational, administrative, and other security measures designed to protect, as required by applicable law, against reasonably anticipated or actual threats to the security of your personal information (the “ Security Program”). Our Security Program was created by reference to widely recognized industry standards such as those published by the International Standards Organization and the National Institute of Standards and Technology. It includes, among many other things, procedures for assessing the need for, and as appropriate, either employing encryption and multi-factor authentication or using equivalent compensating controls. We therefore have every reason to believe our Security Program is reasonable and appropriate for our business and the nature of foreseeable risks to the personal information we collect. We further periodically review and update our Security Program, including as required by applicable law.
Our Incident Response and Management Plan
Despite the significant investment we’ve made in, and our commitment to, the Security Program including enforcement of our vendor and service provider oversight procedures , we cannot guarantee that your personal information, whether during transmission or while stored on our systems, otherwise in our care, or the care of our vendors and business partners, will be free from either failed or successful attempts at unauthorized access or that loss or accidental destruction will never occur. Except for our duty under applicable law to maintain the Security Program, we necessarily disclaim, to the maximum extent the law allows, any other liability for any such theft or loss of, unauthorized access or damage to, or interception of any data or communications including personal information.
All that said, as part of our Security Program, we have specific incident response and management procedures that are activated whenever we become aware that your personal information was likely to have been compromised. Those procedures include mechanisms to provide, when circumstances and/or our legal obligations warrant, notice to all affected data subjects within the timeframes required by law, as well as to give them such other mitigation and protection services (such as the credit monitoring and ID theft insurance) as may be required by applicable law. We further require, as part of our vendor and business partner oversight procedures, that such parties notify us immediately if they have any reason to believe that an incident adversely affecting personal information we provided to them has occurred.
Federal law imposes special restrictions and obligations on commercial website operators who direct their operations toward, and collect and use information from children under the age of 13. We take those age-related requirements very seriously, and, consistent with them, do not intend for our online and mobile resources to be used by children under the age of 16, and certainly not by anyone under the age of 13. Moreover, we do not knowingly collect personal information from minors under the age of 16. If we become aware that anyone under the age of 16 has submitted personal information to us via our online and mobile resources, we will delete that information and not use it for any purpose whatsoever. We encourage parents and legal guardians to talk with their children about the potential risks of providing personal information over the Internet.
SUBMITTING INFORMATION FROM OUTSIDE THE UNITED STATES
We control and operate the online and mobile resources from within the United States of America (the “U.S.”). Information collected through the online and mobile resources may be stored and processed in the United States or any other country in which Company or its affiliates or service providers maintain facilities. Although we do not actively block or monitor visitors from other countries, the online and mobile resources are directed only at visitors from the U.S. As such, this privacy statement is consistent with U.S. law and practice and is not adapted to other laws (including European data security and privacy laws). Company will apply the applicable laws of the U.S. including as embodied in this privacy statement in place of data protections under your home country's law. That is, you freely and unambiguously acknowledge that this privacy statement, not your home country's laws, controls how Company will collect, store, process, and transfer your personal information.
YOUR PRIVACY CHOICES; UNSUBSCRIBING
If we are using your personal information to send you marketing materials, such as newsletters or product alerts via text or email, regardless of where you live or whether you are protected by a Comprehensive Data Privacy Law, you may elect to unsubscribe and no longer receive those specific messages by following the instructions in the email or other communication (e.g., by responding to a text with “STOP”). We also may elect to provide a centralized opt-out link allowing you to opt out of any programs in which you may have enrolled using that particular online and mobile resource. When we receive your request, we will take reasonable steps to remove your name from our distribution lists, but it may take time to do so. You may still receive materials for a period of time after you unsubscribe. Unsubscribing or changing affinity actions or other submissions or requests made on our external social media presence, will likely require that you do so directly on that applicable social media platform as we do not control their procedures.
COMPREHENSIVE PRIVACY LAWS; CALIFORNIA PRIVACY RIGHTS
Privacy and data protection laws vary around the world and among the individual United States. Our obligations arising under the majority of the world’s privacy laws, including U.S. federal and most state laws, are satisfied by individual risk assessments that we conduct to ensure we act reasonably and responsibly when processing your personal data. In some jurisdictions, however, privacy laws grant you, the data subject, certain specific rights regarding your personal data. We refer to these types of privacy laws as “Comprehensive Privacy Laws.” Examples of Comprehensive Privacy Laws include the European Union’s General Data Protection Regulation (“GDPR”), and the consumer privacy statutes of several U.S. states, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, “ CPRA”) and similar laws in Connecticut, Colorado, Utah and Virginia. In other jurisdictions, such as Nevada, privacy laws have some features of Comprehensive Privacy Laws such as the right to opt-out of the sale of your personal data.
Whether and how a particular Comprehensive Privacy Law applies to us involves a complex assessment of factors such as the degree to which we direct our business at the residents of a particular jurisdiction, the volumes of data we collect from that jurisdiction and other similar elements. At this time, we believe that the nature, scope and locations of our business activities make us subject only to the CPRA. As such, when we collect personal data from California residents, we become subject to, and those residents have rights under CPRA. This section of our statement is used explain your rights under those laws. For purposes of this section, the words “you” and “your” mean only California consumers (as defined by CPRA) and those data subjects protected by any other Comprehensive Data Privacy Laws we may later determine apply to us. Questions about how the Comprehensive Privacy Laws of jurisdictions other than California might apply to us can be directed to us through the contact information found here.
Your Rights under CPRA and other Applicable Comprehensive Privacy Laws.
You have the following rights under the CPRA. It’s important to us that you know that if you exercise these rights, we will not discriminate against you by treating you differently from other residents of jurisdictions having Comprehensive Privacy Laws who use our sites and mobile resources or purchase our goods and services but did not exercise their rights.
How to Exercise Your Rights.
You, or an authorized agent acting on your behalf, can exercise the above Right to Know up to two different times every 12 months. To exercise any these rights, contact us at support@goldenafter50.com or 1-800-351-6106. We may ask you to fill out a request form. The CPRA only allows us to act on your request if we can verify your identity and/or your agent’s authority to make the request, so you will also need to follow our instructions for identity verification. If you make a verifiable request per the above, we will confirm our receipt and respond in the time frames prescribed by the applicable Comprehensive Privacy Law.
CHANGES TO THIS PRIVACY STATEMENT
We reserve the right to change or update this statement from time to time. Please check our online and mobile resources periodically for such changes since all information collected is subject to the statement in place at the time of collection. Typically, we will indicate the effective/amendment date at the beginning of this statement. If we feel it is appropriate, or if the law requires, we’ll also provide a summary of changes we’ve made near the end of the new statement.
If you have any questions about our privacy and data security policies, procedures and practices, including anything we say in this privacy statement, we encourage you to contact our Privacy Office.