Your privacy is important to Signify. We have drafted this Privacy Notice (also referred to as “Notice”) in an easy and comprehensible way to help you understand who we are, what personal data we collect about you, why we collect it, and what we do with it. Keep in mind that personal data (in this Notice also referred to as “data” or “your data”) means any information or set of information from which we are able, directly or indirectly, to personally identify you, in particular by reference to an identifier, e.g. name and surname, email address, phone number, etc. Please keep in mind that since Signify is an international company, this Notice may be replaced or supplemented in order to fulfill local requirements, as well as to provide you with additional information on how we process your data through specific Signify products, services, systems or applications. For products or services (including web or app-based functionality) that may involve specific processing of your data, this Notice might be supplemented by our product specific notices which provide additional information on the processing of your data related to the product or service. For these specific privacy notices, please visit our Signify privacy center (see “Legal information” section). We strongly encourage you to take some time to read this Notice in full. If you do not agree to this privacy notice, please do not provide us with your data.
WHEN DOES THIS PRIVACY NOTICE APPLY?
This Notice covers how we collect and use your data, e.g. when you visit or use our consumer and customer-directed websites, applications or social media channels; purchase and use our products, services, systems or applications; subscribe to our newsletters or other marketing communications ; provide to us your goods or services; contact our customer support; join our business events; or otherwise interact with us (directly or indirectly) in your capacity as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us. This Privacy Notice only applies to you in case we are considered to be the Data Controller for the processing of personal data. In case we are acting as a Data Processor, the Privacy Notice shared by the Data Controller will govern your personal data.
WHO IS SIGNIFY?
As Signify, we are a global organization leader in the general lighting market with a unique competitive position and recognized expertise in the development, manufacturing and application of innovative lighting products, systems and services. When this Notice mentions “we,” “us,” or the “Company,” it refers to the controller of your data under this Notice, namely the Signify affiliate with which you had, have or will have a business relationship or that otherwise decides which of your data are collected and how they are used, as well as Signify Netherlands B.V. (Registration number 17061150 – High Tech Campus 48, 5656 AE, Eindhoven, The Netherlands). Please note that the Signify affiliates include the subsidiary companies in which Signify N.V. has control, either through direct or indirect ownership. You may obtain a list of Signify affiliates by contacting the Signify Privacy Office (you will find the contact details in the below section “what are your choices?”).
WHAT TYPES OF DATA WE COLLECT ABOUT YOU?
Depending on who you are (e.g. customer, consumer, supplier, business partner, etc.) and how you interact with us (e.g. online, offline, over the phone, etc.) we may process different data about you. We may collect your data, for example, when you visit or use our consumer and customer-directed websites, applications or social media channels, purchase and use our products, services, web-based tools, mobile applications, systems, subscribe to our newsletters, install a software update, provide to us your goods or services, contact our customer support, join our business events, participate to our contests, promotions and surveys or otherwise interact with us. The data collected through your interaction with and use of our services and websites, may not, standing alone, reveal your specific identity or directly relate to an individual, but could, when combined with other data, link back to you. Below you will find an overview of the categories of data that we may collect: Information you provide to us directly
|Categories of data||Examples of types of data|
|Personal identification data||Name, surname, title, date of birth|
|Contact information data||Email, phone number, address, country|
|Account log in information||Pictures uploaded to Signify accounts or otherwise provided to us for example in the context of a webinar or interview.|
|Images, quotes and/or videos from which you may be identified||Pictures uploaded to Signify accounts or otherwise provided to us for example in the context of a webinar or interview.|
|Financial data||Credit card data, bank account data
|Any other information that you decide to voluntarily share with Signify or its affiliates||Feedback, opinions, reviews, comments, uploaded files, interests, information provided for our due diligence process
|Categories of data||Examples of types of data|
|Device information||Hardware model, IMEI number and other unique device identifiers, MAC address, IP address, operating system version, device settings used to access the services, and device configuration|
|Log information||Time, duration and manner of use of our products and services or products and services connected to ours|
|Location information||Your location (derived from your IP address, Bluetooth beacons or identifiers, or other location-based technologies), that may be collected when you enable location-based products or features such as through our apps|
|Luminaire information||Luminaire unique identifiers, luminaire information stored in the device
|Other information about your use of our digital channels or products||Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data|
HOW DO WE USE YOUR DATA?
We may use your data for different legitimate reasons and business purposes. Below you will find an overview of the purposes for which we may process your data:
|Purposes||Conducting due diligence|
|Assessment and (re)screening of (potential) Customers, Suppliers and/or Business Partners||Conducting due diligence|
|Conclusion and execution of agreements||Sales, billing, shipment of products or services, registration to mobile applications or websites, participation in training, warranty, service communications, account management|
|Providing support (upon your request)||Providing support via communication channels, such as customer or contact center support
|Direct marketing||Promoting contact with consumers and/or business customers (only in certain countries), including prospective customers, email and/or electronic marketing, market surveys, personalizing your experience by presenting products and offers tailored to your preference, interests or profile (such as on our sites, applications or in other communication channels)|
|Security and protection of our interests/assets||Deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests|
|Compliance with legal obligations||Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as tax and national insurance deductions, record-keeping and reporting obligations, conducting compliance audits, compliance with government inspections and other requests from government or other public authorities, responding to legal process such as subpoenas, pursuing legal rights and remedies, and managing any internal complaints or claims|
|Defense of legal claims||Establishment, exercise or defense of legal claims to which we are or may be subject to|
|Product development||To improve the services, products, online services, mobile applications and communications we provide towards you or others|
HOW DO WE USE YOUR DATA FOR MARKETING?
Signify Netherlands B.V. and other relevant Signify affiliates may send you regular promotional communications about their products, services, events and promotions. Such promotional communications may use, amongst others, the “PHILIPS”, “HUE”, “SIGNIFY” and/or “INTERACT” brand and may be sent to you via different channels such as: email, phone, SMS text messages, postal mailings, third party social networks. Please find our current list of brands here. We may also contact you regarding information, products, services, events and promotions from Signify as well as from other third-parties providers of products and services complementing our products and services that we believe can be relevant to you because of your usage of our products or to expand your functionality; mainly when we find this third-party has specific services or solutions to meet your needs, or to optimize your use of our products and services. We will not share your registration data with our trusted partner unless we have sufficient grounds to do so. When permitted and/or required by applicable law or where we have your consent, to be able to tailor the communications to your preferences and behavior and provide you with the best, personalized experience, we may analyze and combine all information associated with your data and data about your interactions with us. We may also use this information to create segments of our audience showing which of our products and/or services users are interested in and track success of our marketing efforts. We may keep records of whether you open our electronic communication, as well as the links you click on our electronic communication.
WHAT ARE YOUR CHOICES ON SOCIAL MEDIA?
When you interact or communicate on social media channels/pages/promotions and blogs (e.g. when you click on ‘like’ or ‘share’, when you post and share comments and when you submit ratings and reviews) your data is processed by a third party that provides social listening services to us. This means that the third party that provides social listening services will retain a copy of your online publicly available interactions to which the third party has provided us access. Your data we collect includes publicly available data provided in the social media context by you from the relevant social media provider via a third party that provides social listening services. We use your data to gain a general view of the opinion of people about us and our brands, to resolve issues and/or improve our products and services and/or start a promotional conversation with you. If you do not want to share this information with us as described above, do not interact with us on social media channels. From our social media pages and campaigns, we receive visitor statistics. Although Signify and our social media service provider are responsible for those visitor statistics, the respective social media service provider is your primary point of contact and handles requests to exercise your rights and any complaints you may have. Where necessary, we assist, the respective social media service provider in responding to your requests or complaints. For more information on the personal data that we receive from social media network providers and how to change your settings, please check the websites and privacy policies of the social media network providers.
HOW DO WE USE YOUR DATA IN OTHER COMMUNICATIONS?
Customer Survey communications: We are constantly working to improve our services and to make them more in line with what customers want. That is why we can use your data (customer ID and e-mail address) to invite you for a customer or market research campaign. We can also have these investigations carried out by third parties. In this way you help us to become even better. We only send you these types of communications with your prior consent, unless this is not necessary according to the applicable law. Solicited communications: In some instances, you might want Signify to inform you about a specific matter via electronic communications – but do not want to consent to our marketing communications. In these cases, we will communicate with you in regards to the solicitude you have made. Administrative, service and transactional communications: You will always receive administrative, service and transaction communications from us, such as technical and/or security updates of our products, order confirmations, notifications about your account activities, and other important notices. You cannot opt-out from this type of communication.
ON WHAT LEGAL BASIS DO WE USE YOUR DATA?
- To be able to process your data, we may rely on different legal bases, including:
- Your consent (only when legally required or permitted). If we rely on your consent as a legal basis for processing your data, you may withdraw your consent at any time;
- The necessity to establish a contractual relationship with you and to perform our obligations under a contract;
- The necessity for us to comply with legal obligations and to establish, exercise, or defend against legal claims;
- The necessity to pursue our legitimate interests, including:
- To ensure that our networks and information are secure
- To administer and generally conduct business within the Company
- To prevent or investigate suspected or actual violations of law, breaches of a business customer contract, or non-compliance with the Signify Integrity code or other Signify policies;
- To optimize or extend our marketing reach and communication relevance;
- The necessity to respond to your requests;
- The necessity to protect the vital interests of any person;
- Any other legal basis anyhow permitted by local laws.
WHEN DO WE SHARE YOUR DATA?
We do not sell your personal data. We also do not share any of your personal data except in the limited cases described here. If it is necessary for the fulfillment of the purposes described in this Notice, we may disclose your data to the following entities: Signify affiliates: due to our global nature, your data may be shared with certain Signify affiliates. Access to your data within Signify will be granted on a need-to-know basis; Service providers: like many businesses, we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as ICT service providers, consulting providers, shipping providers, payment providers, electronic communication service platforms, Competition service providers; Business partners: we may share your data with trusted business partners so they can provide you with the services you request, including chat service providers; Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Signify. Professional advisors and others: we may share your data with other parties including professional advisors, such as banks, insurance companies, auditors, lawyers, accountants, other professional advisors. Other parties in connection with corporate transactions: we may also, from time to time, share your data in the course of corporate transactions, such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding); Upon your request in case of a personal data portability request. We may share anonymized information, reports and analyses based on anonymized information. We may disclose aggregated, anonymized information, and analyses and reports derived from such information with our service providers, suppliers, advertisers, merchants, consumer and market research companies and other organizations. This anonymized, non-personal information, may also be shared with other users to help them better understand their lighting usage compared to others in our community, raise awareness about safety issues, help us generally improve our system, or other informational purposes. We take steps to keep this non-personal information from being associated with you, and we require our partners to do the same.
WHEN DO WE TRANSFER YOUR DATA ABROAD?
Due to our global nature, data you provide to us may be transferred to or accessed by Signify affiliates and trusted third parties from many countries around the world. As a result, your data may be processed outside the country where you live, if this is necessary for the fulfillment of the purposes described in this Notice. If you are located in a country member of the European Economic Area, we may transfer your data to countries located outside of the European Economic Area. Some of these countries are recognized by the European Commission as providing an adequate level of protection. With regard to transfers from the European Economic Area to other countries that are not are recognized by the European Commission as providing an adequate level of protection, we have put in place adequate measures to protect your data, such as organizational and legal measures (e.g. binding corporate rules and approved European Commission standard contractual clauses). You may obtain a copy of these measures by contacting the Signify Privacy Office (you will find the contact details in the below section “What are your choices?”).
HOW LONG DO WE KEEP YOUR DATA?
We keep your data for the period necessary to fulfill the purposes for which it has been collected (for details on these purposes, see above section “How do we use your data?”). Please keep in mind that in certain cases a longer retention period may be required or permitted by law. The criteria used to determine our retention periods include:
- How long is the data needed to provide you with our products or services or to operate our business?
- Do you have an account with us? In this case, we will keep your data while your account is active or for as long as needed to provide the services to you.
- Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws in the applicable jurisdiction, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation, or protection against a possible claim.
HOW DO WE SECURE YOUR DATA?
To protect your data, we will take appropriate measures that are consistent with applicable data protection and data security laws and regulations, including requiring our service providers to use appropriate measures to protect the confidentiality and security of your data. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. Depending on the state of the art, the costs of the implementation and the nature of the data to be protected, we put in place technical and organizational measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data. If you have reason to think that your interaction with us or your Data is no longer processed in a secure manner, please reach out to the Signify Privacy Office immediately in accordance with “What are your choices?” as described below.
WHAT ARE YOUR RESPONSIBILITIES?
We would like to remind you that it is your responsibility to ensure, to the best of your knowledge, that the data you provide us, are accurate, complete and up-to-date. Furthermore, if you share with us data of other people, it is your responsibility to collect such data in compliance with local legal requirements. For instance, you should inform such other people whose data you provide to us, about the content of this Notice and obtain their prior consent.
WHAT ARE YOUR CHOICES?
We aim to provide you with access to your data. Usually, you can autonomously control your data (e.g. by logging in to your account) and update, modify or, if legally possible, delete it. In this case, we strongly encourage you to take control of your data. There may be situations where we are entitled to deny or restrict your rights, for example, when necessary to protect the rights and freedoms of other individuals, or refuse to delete your personal data in case the processing of such data is necessary to comply with legal obligations and/or to establish, exercise, or defend our self from legal claims. You can always contact our Privacy Office if you would like to:
- review, change or delete the data you have supplied to us (to the extent Signify is not otherwise permitted or required to keep such data);
- object to certain data processing operations (e.g., opt-out from marketing communications);
- receive a copy of your data (in a common machine-readable format, to the extent it is required by applicable law);
- ask us any other questions related to the protection of your data in Signify
For any questions or reasonable inquiry related to the protection of your data in Signify or regarding this Notice in general, you can contact the Signify Privacy Office:
- Mail: Signify – Attn: Privacy Office – Basisweg 10, 1043 AP Amsterdam, the Netherlands; or
- Online: Signify Privacy Center, “Privacy request” section.
Please keep in mind that email communications are not always secure. Therefore, please do not include sensitive information in your emails to us. We will do our best to address your request in time and free of charge, except where it would require a disproportionate effort. In certain cases, we may ask you to verify your identity before we can act on your request. If you are unsatisfied with the reply received, you may then refer your complaint to the relevant regulator in your jurisdiction.
DO WE COLLECT DATA FROM CHILDREN?
We do not intentionally collect information from children under the age of 16.
- Special note to Children under the age of 16: if you are under the age of 16, we advise that you speak with and get your parent or guardian’s consent before sharing your data with us;
- Special note to Parents of Children under the age of 16: we recommend you to check and monitor your children’s use of our products, systems, services, applications (including websites and other digital channels) in order to make sure that your child does not share personal data with us without asking your permission.
BRAZIL PRIVACY DISCLOSURES
The Brazilian General Law on Data Protection (the “LGPD”) provides any person located in Brazil and/or any personal data that has been collected or is processed within Brazil with specific rights over their personal data. In addition to the above, this section describes your LGPD rights and explains how to exercise those rights. The following does not apply to information or data that cannot identify you or another person, taking into account the use of reasonable and available technical means at the time of its processing.
Whenever necessary, Signify will obtain your consent in advance through a prior, free, informed, unequivocal expression of will, provided by you, and consent may never be obtained in a tacit or implicit manner. Consent for the treatment of sensitive personal data must always spell out the purpose of their treatment in a prominent way. If there is a change in the purpose of the treatment for which consent obtained, Signify will contact you to obtain new consent regarding the processing of your personal data related to the new purposes. You can revoke the consent if you disagree with the changes made.
INTERNATIONAL TRANSFER OF PERSONAL DATA
As described above in this Notice, it may be necessary for Signify to transfer your Personal Data internationally. We may transfer your Personal Data to countries located outside of Brazil. Some of these countries do not have an adequate level of protection for personal data, as determined by the General Data Protection Law. If the international transfer of Personal Data occurs to countries that do not have personal data protection laws at the same level as the LGPD, we will adopt appropriate measures to protect your Personal Data, such as organizational and legal measures (e.g. binding rules and standard contractual clauses for such transfer).
You have the right to request: (i) confirmation whether we process (or not) your Personal Data; (ii) access to your Personal Data processed by us; (iii) rectification of your Personal Data; (iv) portability of your Personal Data; (v) anonymisation, blocking or deletion (erasure) of unnecessary or excessive data or data processed in breach of the provisions of the LGPD; (vi) deletion of personal data processed based on your consent, with the exceptions provided for in the LGPD; (vii) the information of the public and private entities with which Signify has carried out shared use of personal data; (viii) information on the possibility of not providing consent and the consequences of refusal; (ix) revocation of consent, under the terms of the LGPD. In certain circumstances, you have the right to object and restrict the processing of your personal data and/or request a review of automated decisions affecting your interest. Our Privacy Notices set out full information on how you can exercise these rights, how we share personal data with third parties, how we protect your personal data and how we ensure that your data is adequately protected if it is processed outside of Brazil. To contact Signify, please check the “What are your choices” section in the Notice above. You also have the right to contact the National Data Protection Authority (“ANPD”) directly.
CALIFORNIA PRIVACY DISCLOSURES
The California Consumer Privacy Act (‘CCPA’) provides California consumer residents with specific rights regarding their personal information. In additional to the above this section describes your CCPA rights and explains how to exercise those rights. The following is not applicable to de-identified or aggregated personal information or data publicly available.
INFORMATION WE COLLECT
In the execution of our services and/or when visiting our websites we collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (defined as “data”). In particular, we might collect and/or have collected and disclosed for the aforementioned business purpose the following categories of data from you in the last twelve (12) months prior to the effective date of this Notice:
|Category||Examples||We Collected||We Disclosed|
|A. Identifiers.||A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
|B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).||A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice|
|C. Protected classification characteristics under California or federal law.||Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice|
|D.Commercial information.||Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
|E.Biometric information.||Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.||NO||NO|
|F. Internet or other similar network activity.||Browsing history, search history, information on a consumer’s interaction with a website, application, advertisement or other content.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
|G. Geolocation data.||Physical location or movements, or the location of your device or computer.||YES|
|Product development||To improve the services, products, online services, mobile applications and communications we provide towards you or others||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
|H. Sensory data.||Audio, electronic, visual, thermal, olfactory, or similar information.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
|I. Professional or employment-related information.||Current or past job history or performance evaluations.||NO||NO|
|J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).||Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.||NO||NO|
|K. Inferences drawn from other personal information.||Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.||YES||YES, to affiliates, service providers, and other vendors mentioned in this Notice
- Signify Affiliates.
- Service providers.
- Third parties to whom we disclose your personal information in connection with products or services we provide to you, and to accomplish our business purposes and objectives as set forth in this Notice.
DATA FROM CHILDREN
We do not intentionally collect information from children under the age of sixteen (16) years as we do not offer services to them. Parent who set up a profile holding information about children under the age of sixteen (16) years can only do so by granting parental consent which consent choices can be changed by the adults in the family. We do not direct services to children under the age of thirteen (13) years old. As a result, we do not knowingly process data or information from children under thirteen 13 years old.
DO NOT SELL?
“Right to Know”: You may have the right to request that we disclose to you what personal information of yours that we collect, use, and/or disclose. “Right to Delete:” You may have the right to request the deletion of your personal information collected or maintained by us. Depending on your choices, certain offerings may be limited or unavailable. If you have questions about the foregoing or how to execute your Right to Know and/or Right to Delete in our Privacy Notice or specifically with regard to categories and specific data processed, categories of sources from which your data is collected by us, categories of third parties with whom we share your data in the preceding 12 months of its collection, and/or the business or commercial purpose for collecting, please contact our Privacy Office (see section “What are your choices?”). You may also make a verifiable request to exercise your rights by contacting us via the toll-free telephone 1-800-555-0050. If we cannot verify if you (or your authority to act on behalf of another person) we have the right to deny requests. While verifying your identity we shall generally avoid requesting additional information from you for purposes of verification. If, however, we cannot verify your identity from the information already maintained by us, we may request additional information from you, which shall only be used for the purposes of verifying your identity while you are seeking to exercise your rights under the CCPA, and for security or fraud-prevention purposes. We shall delete any new personal information collected for the purposes of verification as soon as practical after processing your request, except as required to comply with applicable legislation. An “authorized agent” means a natural person or a business entity registered with the Secretary of State that you have authorized to act on your behalf, provided you have:
- Provided the authorized agent written permission to do so and we could verify this; and
- Verified your own identity directly with the business.
Subsection 1 does not apply when you have provided the authorized agent with a valid power of attorney. We endeavor to timely respond to a verifiable individual, free of charge and in a portable format unless it is excessive, repetitive or materially unfounded. If we require more time, we will inform you of the reason thereof and extension period in writing.
We will not discriminate against you for exercising your rights under the CCPA. Unless permitted by applicable regulations, we will not charge different prices or rates, deny products or services, provide different products or services or level of quality and/or suggest you may receive the foregoing mentioned. However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your data’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
WHEN WILL THERE BE UPDATES TO THIS PRIVACY NOTICE?
This privacy notice might change from to time. The most current version of this Notice will govern our use of your data and can be found in the website of the Signify Privacy Center, see “Legal information” section. – Signify –