This Privacy Policy sets out why and how Trinity Consultants and its affiliated companies[1] (collectively “Trinity Consultants,” “we,” “our,” and/or “us”) collect, use, store, disclose and otherwise process your personal information in various circumstances, and the rights you may have relating to your personal information under applicable laws. This Policy does not apply to our employees or job applicants. This Policy may apply to website visitors, client and vendor contacts, business contacts, event registrants, publication subscribers, office visitors, and other individuals who interact with us in a business or professional capacity. Individuals with disabilities may access this Policy in an alternative format by contacting [email protected].

The specific practices outlined in this privacy statement apply to websites, solutions and services maintained by or on behalf of Trinity Consultants and that display this policy. Additional information regarding our processing of the personal information of residents of Australia, California, Canada, and India is available under the addenda below. This Policy does not apply to personal information collected or processed in mainland China, which should be addressed through a separate China-specific privacy notice where applicable.

Some of our web pages contain links to websites operated and maintained by others outside Trinity Consultants. When you follow a link to another site, you are subject to the privacy policies of that site. We have no control over the privacy practices of websites or applications that we do not own, and we encourage you to review their privacy practices. Except where otherwise indicated, the terms used in this Privacy Policy are based on the terms used in the GDPR. To the extent you reside in a jurisdiction with a data privacy law similar to the GDPR, the terms in this Privacy Policy shall have the meaning of the analogous term under applicable data privacy law.

Our websites and services are not intended for or designed to attract children under the age of 18, and we will not knowingly solicit or collect personal information from children we actually know are under 18.

Who is the Controller for the Personal Information Processed?

For the purposes of this Policy, unless you are otherwise advised, the controller of your personal information will be Trinity Consultants, Inc., 12700 Park Central Dr., Suite 600, Dallas, Texas 75251 USA. Nothing in this Policy creates any contractual right. All questions, concerns, or complaints should be directed to Trinity Consultants’ Data Privacy Officer by e-mail at [email protected].

What Personal Information We Collect

We do not engage in sales directly to consumers acting in an individual or household capacity (“consumers”). As such, the information we collect about consumers is limited. Generally, we collect the following information relating to you and/or your use of our sites or services:

  • Contact details and account information (e.g., name, title of business contact, address, e-mail, phone number, fax number, account password).
  • Financial information (e.g., payment method and history, billing information, accounts payable) from our business customers and vendors.
  • Commercial and purchase information (e.g., purchase or browsing history).
  • Automatically collected information (e.g., information that is automatically logged and combined about you, your device, and your interaction over time with the websites, services, and online resources, including browser and device information, date and time of access, operating system, IP addresses, information collected through cookies, pixel tags and other technologies, such as the address of the page you are visiting, your browsing environment, and your display settings).
  • Marketing information (e.g., your preferences for receiving marketing communications and details about how you engage with them).
  • Other information you may choose to provide (e.g., instructions, comments and opinions you provide when you contact us directly by email, online forms, telephone or mail, survey responses when you choose to participate in a survey, and any other information that you choose to provide to us when you interact with us such as when you register for events or subscribe to publications).

We do not intentionally collect sensitive personal information, including special categories of personal information, in ordinary business interactions unless such information is specifically requested, voluntarily provided with appropriate consent, or required or permitted by applicable law. Sensitive personal information may include Social Security numbers, information related to racial or ethnic origin, political views, religious beliefs, health information, biometric information, or similar information protected by applicable law. If sensitive personal information is provided to us without a valid business, legal, or consent-based basis, and to the extent we become aware of its existence, we will delete or otherwise handle it in accordance with applicable law.

In addition to personal information, we collect and store anonymized data or other data that is not considered personal data under applicable privacy law (“non-personal information,” such as search engine queries and anonymous survey responses), to help us better understand and meet the needs of our visitors. We may share non-personal information with others, including the public, in aggregated form (for instance, in a list of our most popular search engine queries), in partial or edited form (such as in a report summarizing responses to a questionnaire), or verbatim (for example, in a complete listing of survey responses).

Sources of Personal Information

During the 12-month period prior to the effective date of this Privacy Notice, we may have collected or received personal information:

  • Directly from you, for example when you communicate with us.
  • From third party sources, such as our service providers and business partners.
  • Automatically and indirectly from you, such as through logging and analytics tools, cookies, pixel tags, and other technologies on our website, surveillance cameras, or through technical information generated when you are present at one of our locations.

Why We Process Personal Information

Trinity Consultants and its service providers and business partners process personal information for the following purposes and pursuant to the following legal grounds:

  • Providing our products and services and communicating with our business customers about them (contractual requirement, legal obligation, or legitimate business interests). We collect and process the personal information of individuals working for our customers so that we can enter into and perform contracts with our customers, provide our products and services, improve our products and services, and communicate with customers.
  • Working with our vendors (contractual requirement or legitimate business interests). We collect and process the personal information of individuals working for our vendors so we can enter into and perform contracts with our vendors to support our provision of products and services.
  • Enhancing the customer experience (consent or legitimate business interests). The Company collects and processes personal and business information about individuals who purchase products and services from our business customers, as well as their impressions of their purchase experience and experience with the products and service. This information is used to identify products and services that may be of interest to our customers, to provide them with information regarding the same, and to troubleshoot and respond to requests for assistance.
  • For marketing and advertising purposes (consent or legitimate business interests). We use your personal information to do things like send you information relating to our products, services, and events that may be of interest to you, and to otherwise provide you with our marketing and advertising materials or to engage in customer generation and acquisition activities. We may engage third-party advertising providers to display our ads on their online services. For more information, please see the “Cookies” and “Marketing and Exercising your Right to Opt-Out of Marketing” sections below.
  • Maintaining and improving the functionality of our websites and services (consent, contractual requirement, or legitimate business interests). We use your personal information to do things like provide our websites and services’ functionality to you, such as arranging access to your account and providing you with related client services. We use the personal information that we collect to do things like measure the number of visitors to the different areas of our sites, and to help us improve our sites and services and make them more useful to users. This includes analyzing these logs periodically to determine the traffic through our servers, the number of pages served, and the level of demand for pages and topics of interest. For more information, please see the ‘Cookies” section below.
  • Meeting our legal, regulatory, and contractual obligations (legal obligation, contractual requirement, and legitimate business interests). We use your personal information to do things like comply with applicable laws and regulations, exercise and protect our legal rights, identify and investigate harmful or fraudulent activities, prevent or deter security incidents or violations of our policies or applicable laws, and comply with our contractual obligations with our affiliates, service providers, business partners, and other third parties.
  • For other purposes, where you give us consent to do so, we may process your personal information for other specific purposes that are not listed in this Privacy Policy. For example, we may use your personal information to process or respond to a specific request, such as a request to subscribe to our publications or join our mailing list.

Recipients of Personal Information

We disclose personal information as follows:

  • To Affiliates and Subsidiaries. Personal information may be disclosed to Company affiliates and subsidiaries as necessary to fulfill the purposes described in this Policy.
  • To Service Providers, Business Partners, and Other Third Parties. Personal information may be disclosed to our third-party service providers and business partners to perform services for us. These can include website hosting, account hosting, targeted advertising services, products and services-related consulting and monitoring, usage and data analysis, information technology and related infrastructure provision, customer service, email delivery, auditing, fulfilling orders, payment/billing, finance, fraud prevention, logistics, sales, event management, training, surveys, printing, archiving, or to fulfill the purpose for which you have provided it and other related services. We may also disclose your personal information to other third parties as necessary or appropriate in the ordinary course of business, such as:
    • To comply with applicable law and regulations, including laws outside your country of residence;
    • To private and public entities and institutions, including debt collectors, courts, or other companies insofar as there is a relevant legal basis for such disclosure;
    • To professional advisors, such as lawyers, accountants, insurers, or auditors, where necessary in the course of the professional services they render to us; and
    • For other legal reasons such as to enforce our terms and conditions or to protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
  • Disclosures to public and government authorities. We may be required to disclose personal information in response to lawful requests by public and government authorities to comply with national security or law enforcement requirements.
  • For business transfers. For example, we may be required to disclose your personal information with potential buyers, investors, or other counterparties (and their advisors) in connection with a proposed merger, acquisition, reorganization, or sale of some or all of our business or assets.
  • To other third parties. With your consent, we may share personal information with other third parties not specified herein.

Cookies

We may use cookies, pixels, and similar technologies (“Cookies”) when you use our websites, platforms, applications or other products and services. Cookies are small text files that web servers place on a user’s hard drive that may track your behavior on our website (including its subpages), and we use the information for optimization of our website and marketing activities. Our consent management system shows you a list of the cookies we use, including their provider, purpose, description, and other relevant information. In the default setting, only essential cookies are enabled for residents of the EEA and UK. Through the consent management system, you can determine whether you consent to the setting up of additional cookies. You can modify your cookie settings or turn off all or certain types of cookies by adjusting your browser settings. You can also manage your cookie preferences via our consent management system. These cookies are on by default for U.S. residents, who may be able to opt out where that right is provided by law.

Our third-party providers may use the cookies and information collected through them to recognize your device on other websites. We can instruct the respective third-party providers to display advertising that is based on the visit or use of our websites, platforms, applications or other products and services. If you register with the third-party provider using your own user data, the respective recognition characteristics of different browsers and end devices can be aligned with each other. If the third-party provider generated a separate characteristic for the laptop, desktop, smartphone or tablet you use, these individual characteristics can be associated with each other as soon as you use a service of a third-party provider with your login information. This way, the third-party provider can effectively manage our advertising campaigns across different end devices.

We disclose information collected about the use of our site with our social media, advertising, and analytics partners such as Google. We utilize Google Analytics to collect analytical information to help us understand which users visit our Website and how visitors use our Website. This information also helps Google make their services more useful to you by helping you rediscover things you’ve searched for, read, and watched. You can manage the settings about the information on activities Google collects from various devices and Google services when you are logged in with your Google account, via the link https://myactivity.google.com/myactivity. To learn more, please visit https://policies.google.com/technologies/partner-sites.

Marketing and Exercising Your Right to Opt-Out of Marketing

In jurisdictions where express consent is legally required, we will not use your personal information to send you marketing materials if you have not expressly consented. If you request that we stop processing your personal information for marketing purposes, we will stop processing your personal information for those purposes where required by law.  In all jurisdictions, you can opt out of direct e-mail marketing by clicking the “unsubscribe” link in the email.

Our marketing-related communications may contain tracking technology so that we can tailor the content of our marketing-related communications more closely to the personalized needs of recipients. Those tracking technologies include, for instance, miniature graphics embedded in an e-mail sent in HTML format that enable analysis of whether and when the relevant e-mail was opened, and which links contained in the e-mail were followed.

The personal data collected using tracking pixels are stored by us and statistically analyzed to optimize the marketing-related communications service as described above. The user may withdraw his/her consent to marketing-related communications tracking at any time.

Data Subject Rights of EEA and UK Residents

Residents of the European Economic Area, including Ireland, and residents of the United Kingdom may have the following rights regarding their personal information under the GDPR, UK GDPR, and other applicable data protection laws:

  • Right of Access / Right to Know: You have the right to obtain confirmation from us as to whether or not personal information concerning you is being processed and to obtain information, including about how, what when, why and for how long your personal information is processed and to whom it is disclosed. You have the right to access your personal information and to receive a copy of the data.
  • Lawful Bases for Processing: Where applicable, we process personal information based on one or more lawful bases, including consent, performance of a contract, compliance with legal obligations, protection of vital interests, performance of a task carried out in the public interest, or our legitimate interests, provided those interests are not overridden by your rights and freedoms.
  • Right to Rectification: You have the right to request that we correct inaccurate personal information and to complete incomplete personal information.
  • Right to Erasure (Right to be Forgotten): You have the right to request that we erase personal information concerning you where it is no longer needed for the purposes for which it was collected or processed or has otherwise been improperly processed.
  • Right to Object: You have the right to object to the processing of your personal information if the processing is based upon our legitimate interest or for the performance of a task carried out in the public interest, including any profiling based on such processing, or if the processing is for direct marketing.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information while your requests are pending.
  • Right to Portability: You have the right to receive personal information that you have provided to us and transmit such personal information to another entity where the processing of such personal information is based on consent and is processed by automated means. Additionally, you have the right to require that we transmit such personal information directly to another entity, where technically feasible.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority as described herein if you believe that the processing of your personal information infringed on applicable data protection regulations.
  • Right to Withdraw Consent: Where the processing of your personal information is based on your consent, you have the right to withdraw your consent at any time, with effect for the future.

To make a subject access request, you should send the request to our Data Protection Officer by sending an email to [email protected]. In some cases, we may need to ask for proof of identification before the request can be processed. We will inform you if it needs to verify your identity and the documents it requires. We normally will respond to a request within a period of one month from the date it is received. In some cases, such as where we process large amounts of an individual’s personal information, we may respond within three months of the date the request is received. We will write to you within one month of receiving the original request to tell you if this is the case.

International Transfers

The Company is headquartered in the United States and may transfer your personal information to other countries for processing purposes, including countries where Trinity Consultants, its affiliates, service providers, or business partners operate, such as the United States, Canada, Australia, India, the EEA, Ireland, and the UK. Where required by applicable law, we implement appropriate safeguards for such transfers, which may include one or more of the following safeguards requiring the recipient to treat the personal information in accordance with applicable law:

  • we transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information by the European Commission (in the case of transfers out of the EEA) or the UK Government (in the case of transfers out of the UK); and/or
  • where we use certain service providers, we may use specific contracts approved by the European Commission (in the case of transfers out of the EEA) and/or the UK Government (in the case of transfers out of the UK), in both cases which give personal information the same protection it has within the EEA and/or UK as applicable.
  • where required by applicable law, we may conduct transfer assessments and implement supplementary contractual, technical, or organizational measures designed to protect personal information transferred internationally.

Onward Transfers to Third Party Agents

After personal information is transferred from the EEA and/or UK to Company entities in the United States, the Company may thereafter transfer the personal information to third parties acting as controllers. When the Company makes such onward transfers to third party controllers, the Company will enter into a contract with the third party controller that provides that (1) such personal information may be processed only for limited and specified purposes consistent with the consent provided by the individual; (2) the third party controller will provide the same level of protections as the Company; (3) the third party controller will notify the Company if the third party can no longer meet its obligation to provide the same level of protection for the personal information as required; and (4) upon such notice by the third party controller, the third party controller will cease processing the personal information and/or take reasonable and appropriate steps to remediate any unauthorized processing.

Onward Transfers to Public Authorities

The Company may be required to disclose personal information in response to lawful requests by public authorities to comply with national security or law enforcement requirements.

Recourse Mechanisms For Personal Information Transferred Internationally

Inquiries or complaints regarding transfers of personal information from the EEA or UK to the U.S. should be directed to our Data Privacy Office by e-mail at [email protected].

If a complaint remains unresolved, EEA residents should contact the state or national data protection authority in the jurisdiction where they reside for resolution. A listing of the EU Data Protection Authorities (DPAs) is located at: http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.

Individuals in the UK should contact the UK’s Information Commissioner’s Office (the ICO). Information about the ICO is located at www.ico.org.uk.

Data Security and Storage Limitation

We have implemented policies and technical security measures designed to secure your personal information against accidental loss and unauthorized access, use, alteration, or disclosure. Such internal policies and technical measures include:

  • The use of pseudonymization and encryption of personal information where appropriate;
  • Procedures and controls designed to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • Procedures and controls designed to restore the availability and access to personal information in a timely manner in the event of a physical or technical incident;
  • Procedures for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing; and
  • Procedures designed to ensure that data is not accessed, except by employees in the proper performance of their duties.

Nevertheless, although we endeavor to safeguard your personal information, no method of electronic transmission or storage can be guaranteed completely secure, and we cannot guarantee that your personal information will remain secure in all circumstances. You also play a role in the security of your personal information. Accordingly, it is important for you to protect against unauthorized access to your information and device.

We retain personal information only for as long as necessary to meet the purposes for which it was collected, to fulfill our legitimate business interests, to comply with any data retention laws or legal requirements, and to assert our rights or defend against claims. Generally, we retain personal information for the duration of our relationship with you plus any legally required record or data retention period and/or any period of time necessary to exercise our legal rights, or to protect our, our employees’, and our business partners’ and clients’ rights, property, or safety and the rights, property and safety of others. The criteria used to determine our retention periods include: (1) the length of time we have an ongoing relationship with you and provide products or services to you, (2) whether there is a legal obligation to which we are subject, and (3) whether retention is advisable in light of our legal rights (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations). Thereafter, we will securely destroy, de-identify, or anonymize the information so that it can no longer be associated with you when it is no longer needed in identifiable form, in which case we may use such information without further notice to you.

When the Company engages third parties to process personal information on its behalf, such third parties are required by contract to process the personal information based on the Company’s written instructions, are under a duty of confidentiality, and are required to implement appropriate technical and organizational measures to ensure the security of the personal information.

When the Company shares personal information of EEA or UK residents with affiliated companies, vendors, and business customers located outside of the EEA or UK, such as the U.S., the Company uses appropriate safeguards such as standard contractual clauses to protect the personal information.

Changes to Our Privacy Policy

We reserve the right to make changes to this policy. It is our policy to post any changes we make to our privacy policy on this page. If we make material changes to how we handle personal information, we will provide notice of the changes on the website home page.

Questions and Concerns

Any questions or concerns regarding how the Company processes personal information should be directed to our Data Privacy Office by e-mail at [email protected].

Dispute resolution: If for some reason you believe this site has not adhered to these principles, please notify our Data Protection Officer at [email protected]. If our web pages are not fully in compliance with our stated policies, they will be corrected. For your convenience, you may contact our European Local Representative as required under GDPR Article 27 at: https://verasafe.com/public-resources/contact-data-protection-representative or at the following address: VeraSafe Netherlands BV, Keizersgracht 391 A, 1016 EJ Amsterdam, The Netherlands.

Our Local Representative in the United Kingdom can be reached at: [email protected] or at the following address: Ten Hogs House, Manor Farm Offices, Flexford Road, North Baddesley, Hampshire SO52 9DF.

EEA and UK residents also have the right to lodge a complaint with the local or national data protection authority in the jurisdiction where they reside. A listing of the EU Data Protection Authorities (“DPAs”) is located at: http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.

Individuals in the UK should contact the UK’s Information Commissioner’s Office (the ICO). Information about the ICO is located at www.ico.org.uk.

Addendum A: Privacy Rights of Residents of Australia

The Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs), and binding codes issued under the Privacy Act, govern the way we manage your personal information. In Australia, “personal information” is any information or opinion about a person, who is identified or reasonably identifiable, whether or not that information or opinion is true.

Types of information collected

The personal information that we collect and hold about you depends on your interaction with us.

The kinds of information we typically collect is included under the ‘What information we collect’ section of this document and may include other information relevant to providing you with the goods and services you are, or someone else you know is, seeking.

Sensitive information is any information or an opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices or criminal record that is also personal information. Sensitive information also includes health information about an individual, genetic information about an individual that is not otherwise health information, biometric information that is to be used for the purpose of automated biometric verification or biometric identification or biometric templates.

We will only collect such sensitive information when you have voluntarily submitted this information to us (which we will take to constitute your consent to its collection) or we otherwise have your consent for us to do so. We will only collect this sensitive personal information if it is reasonably necessary for us to pursue one or more of our functions or activities, or where the information is required or authorised by law or necessary for the establishment, exercise or defence of a legal claim.

We may disclose your sensitive information to third parties for the same reason for which that information was collected by us, or as otherwise permitted by law.

Method of collection

We generally collect personal information directly from you through the use of any of our standard forms, through our website, social media accounts, in person, via email or over the phone.

There may, however, be some instances where personal information about you will be collected indirectly because it is unreasonable or impractical to collect personal information directly from you. Where possible, we will notify you about these instances in advance, or where that is not possible, as soon as reasonably practicable after the information has been collected.

If we receive unsolicited information about you that we do not ask for or which is not directly related to our functions or activities, we may be required to destroy or de-identify that information, provided it is lawful and reasonable to do so.

When we collect personal information from third parties, we rely on that third party to tell you that they have disclosed it to us.

Failure to provide information

If the personal information you provide to us is incomplete or inaccurate, we may be unable to provide you, or someone else you know, with the services you, or they, are seeking.

Legal requirements

We collect personal information to assist us to fulfil our legal and regulatory obligations, including under the Corporations Act 2001 (Cth), the Competition and Consumer Act 2010 (Cth) and the A New Tax System (Goods and Services Tax) Act 1999 (Cth).

Overseas disclosure

We may disclose your personal information to third parties outside Australia, including our related bodies corporate, vendors, business partners or other third parties solely for our business purposes, including to the USA.

Direct Marketing

We (or third parties on our behalf) may send you direct marketing communications and information about our products and services. This may take the form of emails, SMS, mail or other forms of communication, in accordance with the Spam Act and the Privacy Act. You may opt-out of receiving marketing materials from us by contacting us using the details set out below or by using the opt-out facilities provided (for example, an unsubscribe link).

Security of information

We may hold your personal information in either electronic or hard copy form. We take the security of your personal information very seriously and will take such steps as are reasonable in the circumstances (including through physical, technical and administrative means) to protect your personal information from loss, interference, misuse, unauthorised access, modification or disclosure as required by law in Australia. These steps may include access controls, encryption and secure premises. However, no data transmission over the internet can be guaranteed to be totally secure and we cannot guarantee that such transmission will be secure.

Access to information

You may access the personal information we hold about you, upon making a written request.  We will respond to your request within a reasonable period. We may charge you a reasonable fee for processing your request (but not for making the request for access).

We may decline a request for access to personal information in circumstances prescribed by the Privacy Act, and if we do, we will give you a written notice that sets out the reasons for the refusal (unless it would be unreasonable to provide those reasons), including details of the mechanisms available to you to make a complaint.

If, upon receiving access to your personal information or at any other time, you believe the personal information we hold about you is inaccurate, incomplete or out of date, please notify us immediately. We will take reasonable steps to correct the information so that it is accurate, complete and up to date.

If we refuse to correct your personal information, we will give you a written notice that sets out our reasons for our refusal (unless it would be unreasonable to provide those reasons), including details of the mechanisms available to you to make a complaint.

Complaints and Feedback

If you wish to make a complaint about a breach of the Privacy Act, the APPs or a privacy code that applies to us, please contact us using the details below and we will take reasonable steps to investigate the complaint and respond to you.

If after this process you are not satisfied with our response, you can submit a complaint to the Office of the Information Commissioner. To lodge a complaint, visit the ‘Complaints’ section of the Information Commissioner’s website, located at http://www.oaic.gov.au/privacy/privacy-complaints, to obtain the relevant complaint forms, or contact the Information Commissioner’s office.

If you have any queries or concerns about our privacy policy or the way we handle your personal information, please contact us at:

Street address:          12700 Park Central Dr., Suite 600, Dallas, Texas 75251 USA

Email address:          [email protected]

Telephone:                 800.229.6655

Website:                     https://trinityconsultants.com/

For more information about privacy issues in Australia and protecting your privacy, visit the Australian Federal Privacy Commissioner’s web site http://www.privacy.gov.au/.

Addendum B: Privacy Rights of California Residents

This part of this Policy is intended to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (collectively, the “CCPA”), as applicable to residents of the State of California.

Collection

In the preceding 12 months, depending on your interactions with us, we may have collected the following categories of personal information:

  1. Identifiers, such as name, alias, postal address, unique personal identifier (e.g., device identifier, unique pseudonym, or user alias/ID), online identifiers, IP addresses, email address, and other similar identifiers.
  2. Categories of personal information described in California Civil Code § 1798.80, such as name, signature, telephone number, or financial information such as bank account number, credit card number or debit card number, or other financial information.
  3. Internet or other electronic network activity information, such as information about your device(s) when accessing our websites and services and your usage details relating to our websites and services, information you provide when filling in forms on our websites and services, or information you provide when requesting further information, products, or services from us.
  4. Professional and employment-related information, such as information relating to your position, (e.g., job title, job description, or department), employment status, employment history, or business email address.
  5. Commercial Information, such as records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  6. Geolocation data, such as time and physical location related to use of an internet website, application, device, or physical access to an office location.
  7. Sensory or surveillance information, such as call monitoring.
  8. Inferences and profiles based on other personal information, such as information about your behavior, preferences, characteristics, psychological trends, or predispositions.
  9. Other information you choose to provide.

We do not collect or process sensitive personal information (as that term is defined by the CCPA) for the purpose of inferring characteristics about individuals.

“Sales,” “Sharing,” and Disclosures of Personal Information for a Business Purpose

Our business model does not include selling your personal information, such as your name, email address, phone number, postal address, or online activity, to third parties in exchange for money. However, we do share online activity, such as cookies and the advertising identifier associated with your computer or mobile device, with our advertising partners to show ads that are targeted to your interests. Under California law, sharing personal information with partners in exchange for some benefit, such as providing more relevant ads based on your information across websites, can be considered a “sale” or “sharing” in some circumstances. As such, we may be considered to “sell” or “share” or otherwise disclose your personal information for targeted or cross-context behavioral advertising.  The information that we collect and may “sell” or “share” for cross-context behavioral advertising, and may have disclosed for those purposes in the preceding 12 months, include automatically collected information through our website, and the recipients of that information are social media platforms and other targeted advertising companies. California residents may opt out of the “sale” or “sharing” of personal information as described in the “Consumer Rights,” section discussed below. Please note that the right to opt out only applies to “sales” or “sharing” of personal information and does not restrict our ability to disclose information to third parties for valid business purposes.
We do not use, disclose, or otherwise process sensitive personal information for purposes other than those allowed by the CCPA as set out in Cal. Code Regs. tit. 11 § 7027(m).
We generally collect and disclose for a business purpose, and in the preceding 12 months we may have collected and disclosed for a business purpose, the categories of personal information listed above in “Collection,” for business or commercial purposes as described in ‘Why We Process Personal Information” to the categories of entities identified in “Recipients of Personal Information.”

California Consumer Rights

California residents have the following privacy rights regarding your personal information:

  • The right to know and right to access: The right to request, twice in a 12-month period, that we disclose the personal information we have collected about you, including the categories of personal information; the categories of sources from which the personal information is collected; the business or commercial purpose for collecting, selling, or sharing personal information; the categories of third parties to whom the business discloses personal information; and the specific pieces of personal information we have collected about you;
  • The right to delete: The right to request that we delete certain personal information that we have collected from you, subject to certain exceptions;
  • The right to correct: The right to request that we correct inaccurate personal information that we maintain about you;
  • The right of portability: You have the right of portability, or right to have us transfer your personal information to other persons or entities upon your request;
  • The right to opt out of sale or sharing: You have the right to opt out of the sale or disclosure of your personal information for cross-context behavioral advertising; and

You can exercise your privacy rights by submitting a request to us by emailing us at: [email protected]; calling us at: 800.229.6655; or asking our Data Privacy Office for a written request form.  To help protect the security of your personal information, we will take steps to verify your identity before granting access to your personal information or complying with your request. We may require you to provide us with identifying information for you such as personal email address, personal telephone number, employee identification number, and/or other information that we can match with the personal information we have collected about you to verify your identity.  If you ask us to provide you with specific pieces of personal information, we may require you to sign a declaration under penalty of perjury that you are the individual whose personal information is the subject of the request and provide appropriate proof of identity.

You may use an authorized agent to exercise your privacy rights. We will require your authorized agent to provide us proof of your authorization, which may take the form of either: (1) a power of attorney authorizing the authorized agent to act on your behalf, or (2) your written authorization permitting the authorized agent to exercise your privacy rights on your behalf.  Further, we may require you or your authorized agent to provide us with identifying information to verify your identity.  We may also require you to either verify your own identity directly with us or directly confirm with us that you provided the authorized agent permission to submit the request.

Within 10 days of receiving your request to delete, correct, or know, we will confirm receipt of your request and provide information about how we will process your request.  Generally, we will respond to your request within 45 days.  If we need more time to respond, we will provide you with notice and an explanation of the reason we need more time to respond.  We may deny your request if we cannot verify your identity or are legally permitted to deny your request.  If we deny your request, we will explain the basis for the denial, provide or delete any personal information that is not subject to the denial, and refrain from using the personal information retained for any purpose other than permitted by the denial. We will maintain a record of your request and our response for 24 months. To the extent permitted by law, we may charge a reasonable fee to comply with your request if the request is manifestly unfounded, excessive, or repetitive.

As discussed above, we do not sell your personal information for monetary consideration. However, to the extent we “sell” or “share” your personal information (as those terms are defined under CCPA), California residents have the right to opt out of that “sale” or “sharing” on a going-forward basis at any time.

We will not discriminate against or retaliate against you for exercising any rights available to you under the CCPA, including by denying goods or services, charging different prices or rates, providing a different level or quality of goods or services, or suggesting that you may receive a different price, rate, level, or quality of goods or services, except as permitted by applicable law.

You may also be able to restrict the collection of personal information through your device’s operating system or by disabling cookies, but doing so may prevent you from using the functionality of the websites. If your browser supports it, you can turn on the Global Privacy Control (GPC) to opt out of the “sale” or “sharing” of your personal information. We honor the GPC and other universal opt out signals where we are required to do so by applicable law, and we process these signals in a frictionless manner. These are signals you can send from your browser to a website to convey your choice to exercise certain opt-out rights granted by individual states. To download and use a browser supporting the GPC browser signal, click here: https://globalprivacycontrol.org/orgs. If you choose to use the GPC signal, you will need to turn it on for each supported browser or browser extension you use. However, please note that if you have the GPC signal enabled, you will not receive advertisements tailored to your interests.

Some internet browsers have a “Do Not Track” feature that lets you tell websites that you do not want to have your online activities tracked. Given that there is not a uniform way that browsers communicate the “Do Not Track” signal, our website does not currently interpret, respond to or alter its practices when it receives “Do Not Track” signals.

Even if you opt out of the sharing or processing of your California Personal Information for cross-context behavioral advertising, you may still see our ads online at other sites and apps, and we may still base aspects of ads on your interactions with us and the websites.

Addendum C: Privacy Rights of Residents of Canada

This part of this Policy is intended to comply with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar applicable provincial legislation in Canada. If you have any questions, comments, or complaints regarding our privacy practices and policy, please contact our Data Protection Officer:

  • By email at [email protected]
  • By phone at 800.229.6655
  • By mail at 12700 Park Central Dr., Suite 600, Dallas, Texas 75251 USA

Transfers of your personal information.

The Company is headquartered in the United States and has service providers located in Canada, the EEA, the UK, and other countries. Your personal information may be transferred, processed and stored in Canada, the United States, or other locations outside of your country or region as we deem appropriate from time to time.

Your personal information may become subject to the laws of such other jurisdictions, which may not be as protective as the privacy laws in your home country or region. Where required by applicable laws, measures have been put in place to protect your personal information that we transfer across borders. All inquiries regarding transfer of your personal information may be submitted to [email protected].

Residents of Canada have the following privacy rights regarding personal information:

  • Right to know and access. The right to request that we disclose the personal information we have collected about you, including the existence, use, and disclosure of your personal information.
  • The right to correct: The right to request that we correct or supplement inaccurate or incorrect personal information that we maintain about you;
  • The right to withdraw consent. Where consent serves the lawful basis of processing, the right to withdraw consent for the processing of your personal information at any time, subject to legal or contractual restrictions. Withdrawal of consent may affect our ability to provide you with certain products or services.

You have the right to make a complaint regarding our handling of your personal information using the contact information set out above. If you are not satisfied with our response to your complaint, you may file a complaint with the Office of the Privacy Commissioner of Canada:

  • 30 Rue Victoria, Gatineau, QC J8X 2A1
  • 1-800-282-1376
  • priv.gc.ca

We will respond to your request within thirty (30) days of receiving it at minimal or no cost to you and in a form that is generally understandable. We may extend this period by up to an additional thirty (30) days where meeting the original deadline would unreasonably interfere with our activities, where additional time is needed for necessary consultations, or where time is needed to convert information into an alternative format.  If we extend the time limit, we will notify you in writing of the extension, the reasons for it, and your right to complain to the Office of the Privacy Commissioner of Canada. Individuals with a disability may request access in an alternative format where a version in that format already exists or where conversion is reasonable and necessary.

You can exercise your privacy rights by submitting a request to us by using the contact information above.  To help protect the security of your personal information, we may require you to provide sufficient information to permit us to provide an account of the existence, use, and disclosure of personal information. We may refuse your request in certain circumstances, such as where the information is privileged or where disclosure would reveal confidential commercial information. If we refuse your access request, we will inform you in writing of the refusal, the reasons for it, and any recourse available to you.

Addendum D: Privacy Rights of Residents of India

This part of this Policy is intended to comply with the Digital Personal Data Protection Act, 2023 (“DPDPA”) and other applicable Indian data protection laws. This Notice is provided to you (the “Data Principal”) by Trinity Consultants, Inc. (the “Data Fiduciary”).

We will only process your personal data for purposes for which you have given consent or for certain legitimate uses as permitted under the DPDPA. When we request your consent, the request will be accompanied or preceded by the foregoing notice. Where you have given consent prior to the commencement of the DPDPA, we will provide the foregoing notice as soon as reasonably practicable.

Residents of India have the following privacy rights regarding personal information:

  • Right to access. The right to obtain (a) a summary of personal data being processed by us and the processing activities undertaken by us with respect to such data; (b) the identities of all other Data Fiduciaries and Data Processors with whom your personal data has been shared by us, along with a description of the personal data; and (c) any other information related to your personal data.
  • Right to withdraw consent. Where consent serves the lawful basis of processing, the right to withdraw consent for the processing of your personal information at any time, subject to legal or contractual restrictions. Withdrawal of consent may affect our ability to provide you with certain products or services.
  • Right to correction and erasure. The right to request the correction of inaccurate or misleading personal data, the completion of incomplete personal data, the updating of personal data, and the erasure of personal data no longer necessary for the purpose for which it was collected.
  • Right to redress. The right to have a grievance, and have such grievance addressed in accordance with the DPDPA.
  • Right to nominate. The right to nominate any other individual to exercise your rights in accordance with the DPDPA in the event of death or incapacity.

You may also make a complaint to the Data Protection Board of India. You may access our website at https://trinityconsultants.com/.

To exercise any of your rights or if you have any grievance regarding the processing of your personal data, you may contact us:

  • Through our website at https://trinityconsultants.com/
  • By email at [email protected]
  • By phone at 800.229.6655
  • By mail at 12700 Park Central Dr., Suite 600, Dallas, Texas 75251 USA

Questions

Questions, including requests for an alternate format or for an accommodation to access this privacy policy, should be directed to our Data Privacy Office by e-mail at [email protected].

Effective date:  07/29/26

[1] Any legal entity, including, but not limited to, any juridical person, corporation, partnership, limited liability company, or group that directly or indirectly controls, is controlled by, or is under common control with Trinity Consultants through one or more intermediaries.