|
Revised: June 1, 2007
The Mirachem
Corporation (“Mirachem”) has adopted the following
Online Privacy & Security Policy (“Policy”) to govern
the use of information and data (“Online Information”)
processed through its web sites, email systems, online
applications, user communities and/or other online
venues (“Online Properties”). This policy governs how
employees and agents of Mirachem store and use Online
Information, as well as the rights and responsibilities
of users submitting Online Information (“Users”).
1.
General Data Privacy and
Security Standards
In addition to the specific requirements on this policy
relating to Online Information, Mirachem has
long-standing and well-
documented policies concerning the use,
storage and distribution of private or secure
information. In general, these policies
require all employees and agents of
Mirachem to:
- Always
value the trust of our business contacts and
respect the importance of keeping personal,
financial and other confidential information
secure.
- Provide
information to interested parties on Mirachem’s
policies and standards regarding the use,
storage and distribution of confidential
information
-
Consider all private information, such as names,
address, billing information, credit card or
banking account details, to be confidential
information, and handle it according to our
strict policies governing such information
- Adhere
to the highest standards of conduct in ensuring
the security and proper use of confidential
information.
- Follow
procedures designed to maintain accurate
information and respond in a timely manner to
requests to change or correct information.
- Use a
combination of safeguards, including physical,
electronic and procedural security, to protect
our business contacts from the criminal use of
their private information and to prevent
unauthorized access to this data.
- Require
other companies with which we do business to
abide by our privacy and security policies and
to maintain the security of confidential
information.
Back
To Top
2.
User
Responsibilities and Best Practices
It is considered a best practice to review the
privacy and user policies of any website visited. We
encourage Users to review Mirachem’s Online Privacy &
Security Policy before using our Online Properties or
submitting any information to us. By using our Online
Properties and/or submitting information, Users are
accepting the provisions and practices of this Policy.
Users should also review Mirachem’s Online Acceptable
Use Policy for additional information on Mirachem’s
Online Properties.
Users should also be aware that this
Policy applies only to Mirachem Online Properties and
not to other websites. This may include websites that
are linked to or from one of our Online Properties. All
Mirachem properties will be identified, at a minimum, by
information contained in the footer of each web page. We
endeavor to author all online content in such a fashion
that external links (web links that do not lead to
Mirachem Online Properties) open in a separate browser
window to assist Users in knowing that they have left a
Mirachem property, however, we cannot guarantee that
this will be true in all cases.
Another best practice
when conducting online activity is to adopt safe
browsing habits. These include an awareness of the
possibility of encountering various risks and
vulnerabilities including viruses, malicious scripts,
“phishing” schemes or online “forgeries”. Users who are
unfamiliar with these terms and their associated risks
are encouraged to learn more about these threats and the
steps necessary to minimize them.
Back
To Top
3. Changes
to this Policy
This Policy may be changed at any
time. Any changes will be posted online and be available
by other means as described in this Policy. However,
changes will only apply to activities and information on
a go-forward basis and will not be applicable
retroactively or to previously-submitted Online
Information. Users are encouraged to review the privacy
policy whenever they visit the site to make sure that it
understood how any personal information provided will be
used.
Back
To Top
4. Information
that we Collect and How We Use It
There are five types of Online
Information that we collect and use. These types of data
progress in the level of confidentiality from that which
is accessible to most Mirachem personnel, to that which
is restricted to a need-to-know basis. These types of
data are:
i.
Automatically Gathered
Background Data (“AGBD”)
ii.
User-Submitted Information
(“USI”)
iii.
Personal and/or
Organizational Information (“POI”)
iv.
Transaction Data (“TD”)
v.
Financial Information (“FI”)
Please note that not all of these types
of information will be collected from each user and/or
with each visit to an Online Property.
i.
Automatically Gathered
Background Data (“AGBD”)
We routinely collect
information about each use of our Online Properties.
However, this information is not personally identifiable
and is not attached to specific Users, nor is it used to
track individual-specific traffic. Such information may
include the internet protocol (IP) address, browser
software, operating system, site referral information,
time, date and viewing history of each User. This
information is used to understand the usage of our
Online Properties, evaluate the effectiveness of content
delivered to Users, monitor the results of marketing
efforts and improve the overall online experience for
our Users.
ii.
User-Submitted Information
(“USI”)
Users may choose to submit
information to us. This is often done via an online form
or email. The information collected varies widely
dependant on the nature of the communication. Common
examples of this type of information include product
inquiries, requests for service, comments and opinions
or responses to surveys. This information is used to
respond to User requests, facilitate the sales and
customer support processes, continue Mirachem’s quality
improvement efforts and other business functions as may
be appropriate. USI may also include data that is of
another type listed above and which we will handle
accordingly.
iii.
Personal and/or
Organizational Information (“POI”)
This type of information
includes details necessary to communicate effectively.
This includes names, mailing, physical and email
addresses, telephone and fax numbers, website addresses
and other personally and/or
organizationally-identifiable information. This
information is only collected via a voluntary
submission, which may occur in a variety of formats
including phone conversation, fax transmission, email,
written communication or online communication. POI is
used to facilitate reliable and effective communication
between Mirachem and its business contacts.
iv.
Transaction Data (“TD”)
Transaction Data includes the
specifics of product and service transactions that occur
between Users and Mirachem. This may include product
information, details of customer use of our products,
payment methods, shipping and logistics data, order
history and payment history.TD may be used to provide
customer service and technical support, monitor and
evaluate Mirachem’s marketing programs, identify
potential areas of interest and opportunity for
customers, facilitate Mirachem’s sales efforts and
support Mirachem’s account administration activities.
vi.
Financial Information (“FI”)
Financial
Information includes all data relating to the processing
of payments and handling of financial transactions. This
may include banking information, Mirachem credit account
information, credit card / debit card data, letters of
credit or financial statements. FI is used to process
payments and to facilitate Mirachem’s collection of open
accounts.
Back
To Top
5.
How We
Protect Information that We Collect
Mirachem uses multiple security
measures to protect data against unauthorized access and
illicit use. These include a
variety of physical, electronic and procedural
safeguards.
i.
Physical Security
Mirachem’s physical facilities
are organized and secured in such a fashion that data is
physically segregated under lock-and-key to prohibit
unauthorized access. Increasing levels of physical
security exist as the level of confidentiality of the
data increases.
ii.
Electronic Security
Mirachem’s data networks
utilize user-specific access control. Security is
enforced on a user-by-user basis, ensuring that
individuals have access to only that data which is
required for their job function. Mirachem also utilizes
a series of hardware and software security measures to
minimize risk from viruses and other online threats, and
conducts frequent systems audits to screen for
vulnerabilities. Mirachem complies with the Payment Card
Industry (PCI) standards of security and employs a
third-party vendor to perform external electronic threat
assessments.
iii.
Procedural Security
Users with
access to Mirachem’s internal operations are trained in
the importance information security and are routinely
audited to ensure compliance with Mirachem’s standards.
These audits cover a variety of topics including data
handling and filing, best practices for working online,
privacy and security policies, legal obligations and
customer service standards.
Back
To Top
6.
How We
Share Information that We Collect
Mirachem is opposed to the
practice of selling, renting or otherwise distributing
confidential or private information to
third parties for marketing or other
for-profit purposes. We do share certain types of data
under certain circumstances as
outlined below.
i.
Automatically Gathered
Background Data (“AGBD”)
This information is routinely
used by Mirachem personnel and its third-party
contractors in development of our Online Properties and
other sales/marketing efforts. This data may also be
used in the aggregate to develop general Internet usage
statistics.
ii.
User-Submitted Information
(“USI”)
User-Submitted Information may
be shared on an anonymous basis with Mirachem’s
third-party contractors as relevant to a specific
project or assignment. Any USI that contains Personal
and/or Organizational Information will be handled
according to our policies regarding that type of
information.
iii.
Personal and/or
Organizational Information (“POI”)
Access to POI by Mirachem
employees is restricted to those with a need to know.
We provide POI to our third party
contractors, agents or partners who work on our behalf
to provide certain products or services. These third
parties do not have the right to use POI beyond what is
necessary to fulfill their obligations to Mirachem, and
are contractually obligated to maintain the
confidentiality and security of this information.
Mirachem may use POI, and share it with
applicable contractors, when trying to protect against
or prevent actual or potential fraud or unauthorized
transactions, or when investigating fraud or
unauthorized access which has taken place.
We may release POI when we believe, in
our good judgment, that such release is reasonably
necessary to comply with applicable law, enforce or
apply the terms of any of our policies or agreements, or
to protect the rights, property or safety of The
Mirachem Corporation, our Users, or others relevant
parties.
We may also share POI under other
circumstances with the prior consent of the applicable
business contact.
iv.
Transaction Data (“TD”)
Access to TD by Mirachem
employees is restricted to those with a need to know.
We provide TD to our third party
contractors, agents or partners who work on our behalf
to provide certain products or services. These third
parties do not have the right to use TD beyond what is
necessary to fulfill their obligations to Mirachem, and
are contractually obligated to maintain the
confidentiality and security of this information
Mirachem may use TD, and share it with
applicable contractors, when trying to protect against
or prevent actual or potential fraud or unauthorized
transactions, or when investigating fraud or
unauthorized access which has taken place.
We may release TD when we believe, in our
good judgment, that such release is reasonably necessary
to comply with applicable law, enforce or apply the
terms of any of our policies or agreements, or to
protect the rights, property or safety of The Mirachem
Corporation, our Users, or others relevant parties.
We use TD, without the inclusion of
Personal and/or Organizational Information, for
developing customer and technical support, as well as
for our sales and marketing programs.
We may also share TD under other
circumstances with the prior consent of the applicable
business contact.
v.
Financial Information (“FI”)
Access to FI by Mirachem
employees is restricted to those with a need to know.
We must share certain FI with third party
service providers such as credit card processors and
merchant banks to process applicable financial
transactions.
Mirachem may use FI, and share it with
applicable contractors, when trying to protect against
or prevent actual or potential fraud or unauthorized
transactions, or when investigating fraud or
unauthorized access which has taken place.
We may release FI when we believe, in our
good judgment, that such release is reasonably necessary
to comply with applicable law or to enforce or apply the
terms of any of our policies or agreements.
Mirachem reports payment history and
performance on Mirachem credit accounts to one or more
credit reporting agencies. Mirachem may also use FI as
permitted by law in its efforts to collect on balances
owed to it, or in pursuit of any legal and/or
collections efforts as permitted by law.
We may also share
FI under other circumstances with the prior consent of
the applicable business contact.
Back
To Top
7.
How
Contacts Can Control the Information that We Collect
Users have control over the
information that we collect as follows.
i.
Automatically Gathered
Background Data (“AGBD”)
Some of this information is
collected as soon as a visit is made to one of
Mirachem’s Online Properties. The only way to avoid this
collection is to not visit one of our Online Properties.
We also utilize cookie and tracking
technology in some areas, depending on the features
offered and/or selected by the User. If personally
identifiable information is provided, such as when using
our E-commerce or user community functions, this
information may be associated with a cookie. We use
these cookies for security and/or user-customization
purposes. Users can control our Online Properties’
ability to use these technologies based on the privacy
and/or security settings in their software. Some of our
Online Properties may be unavailable and/or inoperative
if the User restricts the ability to use these
technologies.
Once we have collected this AGBD, it
becomes the property of The Mirachem Corporation and
will remain accessible to us, and be used by us, as we
deem appropriate without further input from the User.
ii.
User-Submitted Information
(“USI”)
User-Submitted Information can
only be collected when Users provide it to us. If the
User does not wish us to have access to this
information, it should not be provided.
Once we have collected this USI, it
becomes the property of The Mirachem Corporation and
will remain accessible to us, and be used by us, as we
deem appropriate without further input from the User.
iii.
Personal and/or
Organizational Information (“POI”)
Mirachem’s access to POI is
possible only when it is provided by a User in some
fashion. If Users do not wish us to have this data, it
should not be submitted.
Once we have collected POI, Users can
exercise a certain degree of control over Mirachem’s use
of this data.
At any time, Users may request in writing
that we purge their POI from our records. We must retain
POI that relates to actual transactions, or in other
circumstances that may require us to keep legal or
bookkeeping records.
Users may also provide us with
instructions on how we and may not communicate with them
using POI. This is done by indicating Communications
Preferences. This can be done via our online tool, in
writing via a fax transmission or postal mail, or by
contacting our Customer Service Department as indicated
in this Policy. We cannot be restricted from reasonably
contacting a User regarding a transaction between us. We
must also maintain a valid mailing address and at least
one of either a valid telephone number or email address
in our records.
iv.
Transaction Data (“TD”)
Access to TD by Mirachem
employees is restricted to those with a need to know.
We provide TD to our third party
contractors, agents or partners who work on our behalf
to provide certain products or services. These third
parties do not have the right to use TD beyond what is
necessary to fulfill their obligations to Mirachem, and
are contractually obligated to maintain the
confidentiality and security of this information
Mirachem may use TD, and share it with
applicable contractors, when trying to protect against
or prevent actual or potential fraud or unauthorized
transactions, or when investigating fraud or
unauthorized access which has taken place.
We may release TD when we believe, in our
good judgment, that such release is reasonably necessary
to comply with applicable law, enforce or apply the
terms of any of our policies or agreements, or to
protect the rights, property or safety of The Mirachem
Corporation, our Users, or others relevant parties.
We use TD, without the inclusion of
Personal and/or Organizational Information, for
developing customer and technical support, as well as
for our sales and marketing programs.
We may also share TD under other
circumstances with the prior consent of the applicable
business contact.
Transaction Data is the property of The
Mirachem Corporation.
v.
Financial Information (“FI”)
Access to FI by Mirachem
employees is restricted to those with a need to know.
We must share certain pieces FI with
third party service providers such as credit card
processors and merchant banks to process applicable
financial transactions.
Mirachem may use FI, and share it with
applicable contractors, when trying to protect against
or prevent actual or potential fraud or unauthorized
transactions, or when investigating fraud or
unauthorized access which has taken place.
We may release FI when we believe, in our
good judgment, that such release is reasonably necessary
to comply with applicable law or to enforce or apply the
terms of any of our policies or agreements.
Mirachem reports payment history and
performance on Mirachem credit accounts to one or more
credit reporting agencies. Mirachem may also use FI as
permitted by law in its efforts to collect on balances
owed to it or in pursuit of any legal and/or collections
efforts as permitted by law.
We may also share FI under other
circumstances with the prior consent of the applicable
business contact.
Once we have collected FI, Users can
exercise a certain degree of control over Mirachem’s use
of this data.
At any time,
Users may request in writing that we purge their FI from
our records. We must retain FI that relates to actual
transactions, or in other circumstances that may require
us to keep legal or bookkeeping records. Mirachem also
reserves the right to retain and use any FI necessary to
enforce or apply any policy or agreement, or to
facilitate the collection of any open account.
Back
To Top
8.
How to
Contact Us About this Policy or to Exercise Your Rights
Written questions or concerns about this Policy can be
directed to Mirachem as follows:
Via Postal Mail:
The Mirachem Corporation
Attention: Security Administrator
PO Box 14059
Phoenix, AZ 85063
Via Email:
The Mirachem Corporation
Attention: Security Administrator
security@mirachem.com
Via Fax:
The Mirachem Corporation
Attention: Security Administrator
602-353-1161
You may also contact us by phone on our
toll-free Customer Service number at 800-847-3527 or at
our administrative
offices, 602-272-6066.
To establish or change your Communication
Preferences with us, you can use the
online tool found here, complete our designated
form,
found here,
and return it to us by mail or fax, or contact our
Customer Service Department at 800-847-3527.
All requests for removal of information from our
records must be made in writing and must include the
following:
- The full name, title (if
applicable) and contact telephone number of the
individual making the request.
- The contact name, organization name
(if applicable), and complete address associated with
the records to be deleted.
- A description of the information to
be removed from our records.
- The original signature of the
requestor.
Requests for removal should be directed to:
Via Postal Mail:
The Mirachem Corporation
Attention: Security Administrator
PO Box 14059
Phoenix, AZ 85063
Via Courier:
The Mirachem Corporation
Attention: Security Administrator
4645 W. McDowell Road, Unit 103
Phoenix, AZ
85035
Back
To Top
|