Privacy Policy

PRIVACY POLICY

Mingletoe LLC

Version 2.0 | Effective Date: June 19, 2026 | Last Updated: June 19, 2026

PLEASE READ THIS POLICY CAREFULLY. YOUR USE OF THIS WEBSITE AND OUR SERVICES IS SUBJECT TO THIS PRIVACY POLICY AND THE WEBSITE TERMS AND CONDITIONS.

Contents

I. Notice

II. Personal Information That We Collect; Customer Data

III. E-mail Newsletter Subscriptions

IV. User Accounts

V. Special Promotions and Purchases; Submission of Content to Be Published

VI. Information Collected by Other Means or Media

VII. Information About Other People

VIII. Customer Service

IX. Non-Personally Identifiable Information That We Collect

X. Cookies, Tracking Technologies, and Your Choices

XI. Not Intended for Persons Under 13

XII. Use, Disclosure, and Sharing of Information; Control Over Your Information

XIII. Our Commitment to Data Security

XIV. Data Retention

XV. Hyperlinks To and From Other Sites

XVI. Consent to Processing in the United States; EU Processing

XVII. Contact Us Regarding Privacy

XVIII. Notification of Changes

XIX. Your California Privacy Rights

Data Processing Addendum

Annex 1 — Standard Contractual Clauses

Annex 2 — Details of the Processing of Customer Personal Data

Annex 3 — Technical and Organisational Security Measures

 

 

I. Notice

The “Website” refers to the website(s) at mingletoe.com, messageengineer.com, and any of their subdomains, or a successor website as indicated by the Company, together with any of the products or services offered through the Website (or otherwise by the Company), such as digital courses, newsletters, podcasts, and other materials hosted on the Website or associated platforms, as well as the landing pages and email marketing materials of the Company. This Website is owned or operated by Mingletoe LLC and/or its affiliates and subsidiary companies, or any successor to ownership of the Website (collectively, the “COMPANY”). This Privacy Policy (“Privacy Policy”) applies to information that you provide to the COMPANY, or that is collected about you, via this Website and/or through your use of the products or services (collectively, the “Services”) that may be provided by this Website or by the COMPANY through other means, as set forth below and as defined in the applicable Terms and Conditions (which may also be found under the link labeled “Terms” on the Website).

This Privacy Policy is intended to provide you notice of the COMPANY’s information-management practices, including the categories of information gathered, how that information is used and safeguarded, the third parties with whom it may be shared, and the degree to which you may control the maintenance and sharing of your information. Your use of any COMPANY Service or Website constitutes acceptance of, and agreement to, this Privacy Policy and any other applicable terms. This Privacy Policy is part of, and is incorporated by reference into, the Terms and Conditions for this Website. Certain terms used herein are defined in the Terms and Conditions.

Annual review. The COMPANY reviews this Privacy Policy at least once every twelve (12) months, and updates it whenever its information practices materially change, in order to keep the disclosures accurate and current. The “Last Updated” date at the top of this Policy reflects the date of the most recent revision.

II. Personal Information That We Collect; Customer Data

“Users” refers to users of the Websites and Services. Because the Websites and Services are intended to facilitate marketing, professional services, and transactions among Users, personal information that you provide, or that is provided about you — such as, but not limited to, your name, company name, mailing address, billing address, telephone numbers, e-mail address, and billing terms — may be shared with other Users where you direct or initiate such a transaction. Sensitive information, such as full payment-card numbers, is shared only with the parties necessary to facilitate a transaction you have agreed to.

When you register for, or purchase, any Service or product on the Website, you will be asked to provide personal information about yourself, such as your name, e-mail address, mailing address, and telephone number. In order for our third-party vendors to process your payments, you will also be asked to provide certain billing information, such as your payment-card number, expiration date, bank-account information, billing address, and similar information (collectively, “Billing Information”). You authorize our third-party service providers and payment vendors, including, without limitation, Stripe and HubSpot, to collect, process, and store your Billing Information in accordance with their respective privacy policies. We reserve the right to change our payment vendors at any time, or to use additional payment vendors, at our discretion, and we will update this Privacy Policy accordingly. The COMPANY also uses Stripe and HubSpot, among others, as platforms through which certain products and services are provided to you, and your information may be shared with them for those purposes.

Categories of personal information collected. Consistent with applicable law, the categories of personal information the COMPANY may collect are: identifiers (such as name, e-mail address, postal address, telephone number, and online identifiers); commercial information (such as products or services purchased or considered); Billing Information and financial-account details; internet or network activity (such as browsing activity on the Website and interactions with our e-mails); geolocation data derived from IP address; professional or employment-related information; and any other information you choose to provide. The categories of third parties with whom these may be shared are described in Section XII and in the subprocessor list in Annex 2.

Sensitive personal information. The COMPANY does not intentionally collect “sensitive personal information” as that term is defined under the California Consumer Privacy Act, as amended (the “CCPA”) — for example, government-identifier numbers, precise geolocation, account log-in credentials in combination with access codes, contents of private communications, or data concerning health, racial or ethnic origin, religious beliefs, sexual orientation, or genetic or biometric characteristics — for the purpose of inferring characteristics about you. We do not use or disclose any sensitive personal information for purposes other than those permitted under the CCPA. Should our practices change, this Privacy Policy will be updated and any required choices will be offered to you.

Customer Data. For the purposes of EU data-protection laws (“EU Data Protection Law”), the COMPANY is a data controller with respect to the personal data it collects about Users (that is, the COMPANY is responsible for, and controls the processing of, that personal data). In providing our Services and the Website, our customers may upload data to us, which may include personal information about our customers’ own end users (all of which we call “Customer Data”). Customer Data is owned and controlled by our customers, and any Customer Data that we maintain or process is treated as strictly confidential. We collect and process Customer Data solely on behalf of our customers and in accordance with our agreements with them. We do not use or disclose Customer Data except as authorized and required by our customers and as provided for in our agreements with them, including the Terms and Conditions, this Privacy Policy, and the Data Processing Addendum below.

III. E-mail Newsletter Subscriptions

When you create or accept a User Account, or when you subscribe through a sign-up form, you are agreeing to be subscribed to our e-mail newsletters, if any. You may also be asked for other information at the same or a later time. You may unsubscribe from marketing e-mails at any time by following the directions in Section IV and in each marketing message.

IV. User Accounts

In order to use certain of the COMPANY’s Services, you may need to register and create, or otherwise accept, a user account (“User Account”). When you log into a User Account, you are agreeing to be bound by this Privacy Policy and the Terms and Conditions and are also “accepting” your User Account. There may or may not be a cost to create a User Account. You may be asked to choose a username, screen name, or member name (each, a “User Name”) and a password. You may also be asked to provide certain personal information about yourself, such as your first and last name, company name, billing and shipping address, telephone number, and e-mail address. The Website allows you to update certain information when you are logged in.

This Privacy Policy does not apply to any information you may disclose publicly through the Services. In some instances, you may choose to create a “Public Profile” that will be available to others on the Internet. Public Profiles are managed entirely by you, and you are solely responsible for your Public Profile’s content and its “public” or “private” status. The COMPANY bears no responsibility for the actions or policies of any third parties who collect information that Users may disclose in user forums or other public areas of this Website. You are also responsible for maintaining and updating the registration information in your User Account with current and complete information.

You can unsubscribe from marketing e-mails from the Website by clicking the unsubscribe link contained within such e-mails. You cannot unsubscribe from non-marketing correspondence, including correspondence with parties involved in a transaction with you, or e-mails from the COMPANY regarding your User Account and your activities on or through the Website.

Please be aware that it is not always possible to completely remove or modify information in our databases. In addition, we may institute a policy under which User information is deleted after a defined period, after which your User information may no longer exist in the COMPANY’s active database(s). Even if you choose to unsubscribe or otherwise modify your User Account settings, the COMPANY reserves the right to contact you regarding your account and your use of this Website and/or the Services.

V. Special Promotions and Purchases; Submission of Content to Be Published

To participate in some Services, such as sweepstakes, contests, and surveys (“Special Promotions”), or to make online purchases or subscriptions (“Purchases”), you may need to provide personal information, such as name, address, e-mail address, telephone number, and date of birth. Your information may be collected by the COMPANY or by a third party, such as a co-sponsor or a vendor involved in, or providing services in connection with, a Special Promotion, or an e-commerce partner in the case of a Purchase.

If you make a Purchase or enter a sweepstakes or other Special Promotion on one of our sites or through our Services, the COMPANY will collect your personal information, and you consent to the COMPANY providing that information to third parties who provide services such as payment processing, customer service, promotion or sweepstakes administration, order fulfillment, and/or prize delivery, as applicable. As more fully described in Section XII, these third parties are prohibited from using this information for their own marketing purposes, and from sharing, selling, or otherwise distributing the personal information of our customers, unless you choose to opt in to such additional uses under their respective privacy policies. By entering a sweepstakes or other Special Promotion, you are also agreeing to the official rules that govern it, which may contain specific provisions applicable to you, including, except where prohibited by law, allowing the sponsor(s) to use your name, voice, or likeness in advertising or marketing associated with the promotion.

If you make a Purchase or enter a promotion in which the COMPANY is participating on a third party’s website (or through some other means or medium), we will collect your information from the third party only if you opt in to receive additional communications from us, or where we are required to fulfill some function in relation to your activity (for example, to send your order or deliver a prize).

If you submit to the Website a comment, photograph, or other content to be published, online or offline, we may publish your name or other personal information in connection with publishing that content, and you grant us permission to do so.

VI. Information Collected by Other Means or Media

In some situations, we may also collect personal information and other information about you through other means, directly or indirectly. For example, if you access any COMPANY content, or purchase such content, via your wireless carrier or through another third party, the COMPANY may collect information directly from you or through the third party. Likewise, if you use our software, or provide information to other companies who share information about their customers, we may collect additional information about you. In each of these cases, the COMPANY will apply this Privacy Policy to any personal information so collected.

VII. Information About Other People

Some COMPANY Websites and Services may ask you to submit personal information, as well as other information, about other people and/or their affiliated companies. Such information may be used to facilitate transactions among those people and third parties, and may be shared and used by such parties to the extent the COMPANY allows. You represent that you have the authority to provide such information, and you agree to such use and sharing.

VIII. Customer Service

Some Services may offer support and technical assistance through customer-service channels via telephone, online chat, SMS, or e-mail. Whenever you communicate with customer service, you do so with the understanding that an operator may view, and make changes to, the information in your User Account in order to provide the assistance that you need.

IX. Non-Personally Identifiable Information That We Collect

As part of the registration process for some Services, you may be asked to provide information that does not personally identify you, such as your personal preferences or purchasing habits. This information is generally optional but may be included in your User Account profile. The COMPANY requests this information to understand you better and to bring to your attention new services, programs, or offers that may be of interest to you.

In many cases, the COMPANY will automatically collect certain non-personally identifiable information about your use of the Websites and Services. The COMPANY may collect, among other things, the type of Internet browser or operating system you use, the domain name of your Internet service provider, your “click path” through the COMPANY sites or “click-through” from an e-mail, the website or advertisement that linked to or from the COMPANY site, and your IP address. To do this, the COMPANY may use cookies and similar technologies (see Section X). If you use any of our wireless Services, we may also automatically collect information such as the type of wireless device you are using, your mobile identification number, and your telecommunications carrier. Your use of our Websites and Services through these technologies will be anonymous unless you provide us with personal information, have provided such information in the past, or have a User Account.

Information that is anonymized, aggregated, or otherwise not capable of being associated with you, and that cannot identify you, is not considered personal data, and the COMPANY reserves the right to use and share such data in its discretion without the limitations set forth in this Privacy Policy. You may choose not to provide the COMPANY with personal data, but you may then be unable to take full advantage of certain features of our Services, and we may be unable to provide you with certain requested information, products, and/or services.

X. Cookies, Tracking Technologies, and Your Choices

This Website’s pages and e-mail messages may contain cookies, web beacons (also known as clear GIFs), and similar technologies. Cookies are information files that this Website may place on your device to provide extended functionality. The COMPANY may use cookies for a number of purposes, including tracking usage patterns on the Website, measuring the effectiveness of communications, limiting multiple responses and registrations, facilitating navigation, providing information to you about our products and services, and as part of a verification or screening process. Among the types of cookies we may use are session cookies and persistent cookies. A session cookie expires when you close your browser. A persistent cookie remains on your device for an extended period or until you delete it; persistent cookies enable us to recognize returning visitors and to personalize the experience on our Website.

Most browsers are initially set to accept cookies. Most browsers allow you to erase cookies, block the acceptance of cookies, or receive a warning before a cookie is stored. You should refer to your browser’s instructions or “Help” resource to learn how to manage cookies. Please note that some parts of this Website may not operate correctly if you disable cookies, and you may be unable to take advantage of certain features.

Do Not Track and Global Privacy Control signals. Certain browsers offer a “Do Not Track” (“DNT”) setting. Because no common industry or legal standard for recognizing or honoring legacy DNT signals has been adopted, the COMPANY does not currently respond to browser DNT signals. The COMPANY does, however, recognize and honor the Global Privacy Control (“GPC”) signal where required by applicable law. Where a GPC signal is detected, the COMPANY treats it as a valid request to opt out of the “sale” or “sharing” of personal information for the browser or device from which the signal is received, to the extent applicable.

Third-party collection across sites. The COMPANY’s web pages may include content or analytics services provided by third parties, and those services may set their own cookies or web beacons. The COMPANY does not control cookies set by third parties, and the COMPANY’s Privacy Policy does not cover the use of information collected by third-party servers. To the extent a third party collects personal information about your online activities over time and across different websites when you use our Website, that collection is governed by the third party’s own privacy policy, and you are encouraged to review it.

A web beacon is a small graphic image that allows the party that set the beacon to collect certain information about the viewer of a web page, web-based document, or e-mail message, such as the type of browser, the IP address of the device to which the beacon is sent, and the time the beacon was viewed. The COMPANY may use web beacons to count visitors to web pages on the Website, to understand how Users navigate the Website, and to count how many e-mail messages were opened, acted upon, or forwarded.

XI. Not Intended for Persons Under 13

The COMPANY recognizes the sensitivity of personal information concerning children and minors, and is committed to complying with all applicable laws and regulations regarding children, including the Children’s Online Privacy Protection Act (“COPPA”). This site is intended only for persons 13 years of age and older. If you are under 13 years of age, please discontinue use of this site immediately and leave this Website. The COMPANY will not knowingly collect, maintain, or disclose any personal information from a person under 13.

If you are a parent or guardian and you discover that your child under the age of 13 has submitted personal information without your permission or consent, the COMPANY will make reasonable efforts to remove the information from its active list at your request. To request removal, please send an e-mail to admin@mingletoe.com that includes the same User Name and/or e-mail address that your child submitted, with the word “PRIVACY” in the subject heading.

XII. Use, Disclosure, and Sharing of Information; Control Over Your Information

a. Non-Personally Identifiable Information

From time to time, the COMPANY may use, and share with third parties, aggregate, non-personally identifiable User information to show general demographic and preference information among Users of the COMPANY Websites. For example, the COMPANY may produce and share “trend reports” using such aggregate information, generated from order information (for example, products purchased, amounts spent, and general shipping regions) and related data. When you visit or download information from this Website, our web servers may automatically collect website-usage information, which is non-personally identifying and describes how visitors use the Website, including the number and frequency of visitors to each page, browser type, referrer data, and IP addresses. The COMPANY may use IP addresses for purposes such as system administration, approximate server-location determination, aggregate reporting to business partners, and auditing use of the Website.

b. Personally Identifiable Information

The COMPANY uses information about you to deliver the Services you request, to keep you informed about changes affecting our Services or your account, to inform you of other Services or offers in which you might be interested, and to improve and enhance our sites and Services. If you provide the COMPANY with personal information, we will take all reasonable and appropriate steps to protect it from unauthorized disclosure.

No sale or sharing of personal information. The COMPANY does not, and will not, sell your personal information, and does not “share” your personal information for cross-context behavioral advertising, as the terms “sell” and “share” are defined under the CCPA. The COMPANY has not sold or shared personal information in the preceding twelve (12) months. Should this practice ever change, the COMPANY will update this Privacy Policy and provide the opt-out mechanisms required by applicable law before any such activity occurs.

Use of artificial-intelligence tools. The COMPANY may use artificial-intelligence and large-language-model tools as back-end aids for tasks such as drafting content, summarizing materials, and supporting internal operations. The COMPANY does not use these tools to make automated decisions that produce legal or similarly significant effects concerning individuals, and no such automated decision-making is performed about you in connection with the Services. The COMPANY does not permit your personal information to be used to train third-party artificial-intelligence models, except as necessary to provide the Services to you and consistent with the applicable vendor’s contractual commitments. The artificial-intelligence subprocessor the COMPANY engages is identified in Annex 2.

When you create or accept a User Account, you are opting in to receive e-mail from us. You can opt out of future marketing messages at any time by following the directions in each message to “unsubscribe.” If you opt out of marketing messages, we reserve the right to contact you regarding your account status, technical support, product information, changes to account terms, and any other matter that may affect our Service to you or the products you purchased from us or registered with us.

As stated in the Terms and Conditions, you consent to the disclosure to, and use by, a subsequent owner or operator of a COMPANY Website or Service of any information about you contained in the applicable COMPANY database, in the event the COMPANY assigns its rights and obligations regarding your information in connection with a merger, acquisition, or sale of all or substantially all of the assets related to the applicable site or Service. In any such event, your continued use of the Website or related Service signifies your agreement to be bound by the Terms and Conditions and Privacy Policy of the subsequent owner or operator.

The COMPANY and other entities may work together to provide portions of the COMPANY Websites and certain Services. These companies will handle your personal information in accordance with this Privacy Policy. As described in Section V, the COMPANY may also work with third parties to provide some Services, and you consent to the COMPANY sharing your information with third parties who provide services such as payment processing, customer service, promotion administration, order fulfillment, and/or prize delivery, as applicable. Third parties who provide, or participate in, Services on COMPANY Websites are prohibited from using our customers’ personal information for their own marketing purposes, and from sharing, selling, or otherwise using such information, unless you choose to opt in to such use by the third party.

The COMPANY will not share, sell, rent, or disclose any personal information that we have collected, except as stated herein or in the following instances: (1) where you have given consent to disclose; (2) where we have previously informed you of the disclosure, including by means of this Privacy Policy, the Website, or the Service through which you provided your information; (3) where we are required by law, legal process, or court order to disclose; (4) where disclosure is necessary to identify, contact, or bring legal action against someone who may cause, or be causing, harm to, or interference with, the COMPANY’s rights or property, other Users, or anyone else; or (5) to respond to an inquiry, request, or complaint that you have made. The COMPANY may also use IP addresses, in cooperation with Internet service providers, to identify Users where it deems necessary to comply with law, to enforce this Privacy Policy or the Terms and Conditions, or to protect our sites, customers, or others.

c. Information Disclosed to Other Users of This Website

The Services may include functionality that allows you to (i) market or advertise services or items you wish to sell; (ii) view information about, or contact others regarding, the services or items they wish to sell; and/or (iii) transact with others. When you market or advertise services or items, you consent to the sharing, publicly with other Users, of information related to those services or items, together with your identity and contact information. When you contact others about services or items, you consent to the sharing, with those you seek to contact, of information about you, such as your interests, preferences, identity, and contact information. When you transact with others, your communications, identity, and contact information will be shared with those with whom you seek to transact.

d. Control Over Your Information; Special Notes Regarding the EU and Switzerland

(i) Modifying account information. If you have a User Account with us, you can modify certain information in your account (for example, your contact information) through the “profile,” “account,” “settings,” or “preferences” options on the Website. If you have any questions about modifying or updating information in your account, please contact us using the details in Section XVI. Please note that the COMPANY does not own or control Customer Data uploaded to our Service by our customers and cannot modify or delete Customer Data except at the request of our customer, or as permitted by our Terms and Conditions.

(ii) E-mail communications. See Section IV.

(iii) For residents of the EU and Switzerland. If you are located in the EU or Switzerland, you have the following rights in respect of the personal data that we hold about you:

  • Right of access — the right to obtain access to your personal data;
  • Right to rectification — the right to obtain the correction of your personal data without undue delay where that data is inaccurate or incomplete;
  • Right to erasure — the right to obtain the erasure of your personal data without undue delay in certain circumstances, such as where the data is no longer necessary for the purposes for which it was collected or processed;
  • Right to restriction — the right to obtain the restriction of our processing of your personal data in certain circumstances, such as where the accuracy of the data is contested by you;
  • Right to portability — the right to move, copy, or transfer your personal data from one organization to another; and
  • Right to object — the right to object to processing based on legitimate interests and to processing for direct-marketing purposes.

If you wish to exercise one of these rights, please contact us using the details in Section XVI. You also have the right to lodge a complaint with your local data-protection authority. Further information about how to contact your local data-protection authority is available through the European Data Protection Board.

XIII. Our Commitment to Data Security

While the COMPANY takes reasonable and appropriate precautions to protect your personal information from unauthorized disclosure and to prevent security breaches in our Websites, Services, and databases, no website, Internet transmission, computer system, or wireless connection is completely secure. Consequently, the COMPANY cannot guarantee that unauthorized access, hacking, data loss, or other breaches will never occur. Your use of the COMPANY Websites and Services is at your own risk. The COMPANY urges you to take steps to protect your information, including selecting a strong password, keeping it in a safe place separate from your account information, logging out of your User Account, and closing your web browser when finished.

Whenever you provide the COMPANY with sensitive or confidential information (for example, payment-card numbers for Purchases), the COMPANY will take commercially reasonable steps to protect the transmission of that information by establishing an encrypted connection using Transport Layer Security (“TLS”). Unless otherwise specified herein or on the Website where you make a Purchase, payment-card numbers are used only for payment processing and are not retained for marketing purposes.

XIV. Data Retention

The COMPANY retains personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to provide the Services, to maintain your User Account, to comply with our legal, tax, accounting, and regulatory obligations, to resolve disputes, and to enforce our agreements. The criteria used to determine our retention periods include the nature and sensitivity of the information, the purposes for which it is processed, whether a User Account remains active, and applicable legal-retention requirements. When personal information is no longer required, the COMPANY will delete, anonymize, or de-identify it, or securely store it and isolate it from further use, in accordance with applicable law. Customer Data is retained and deleted in accordance with Section 8 of the Data Processing Addendum below.

XV. Hyperlinks To and From Other Sites

COMPANY sites may frame, or contain links to, or advertisements regarding, non-COMPANY websites. Other sites may also reference, advertise, or link to COMPANY Websites. The COMPANY does not endorse or sponsor other websites, is not responsible for the privacy practices or the content of non-COMPANY sites, expressly disclaims any statements or assertions made on such websites, and disclaims all liability associated with your use of, and the content on, such other sites and advertisements.

XVI. Consent to Processing in the United States; EU Processing

By providing any personal information to the COMPANY, all Users, including, without limitation, Users in the member states of the European Union (“EU”), understand and consent to this Privacy Policy and to the collection, storage, and processing of such information in the United States of America.

Regarding the processing of your personal data in the EU, the purposes for which we may do so are:

  • the provision of personal data by you may be necessary for the performance of any contractual relationship we have with you;
  • where it is necessary for compliance with our legal obligations under EU law;
  • where it is in our legitimate interests (provided these are not overridden by your interests and fundamental rights and freedoms), such as: to contact you and respond to your requests and enquiries; for business administration, including statistical analysis; to provide the Services and the Website to you; for fraud prevention and detection; and to comply with applicable laws, regulations, or codes of practice; and
  • on the basis of your freely given, specific, informed, and unambiguous consent.

You are entitled under EU Data Protection Law to withdraw your consent where it has been given, at any time. If you do so and we have no alternative lawful basis to process your personal data, this may affect our ability to provide you with the Services and the Website.

XVII. Contact Us Regarding Privacy

The COMPANY is dedicated to protecting your personal information and welcomes comments and questions on this Privacy Policy. You may e-mail your questions or comments to admin@mingletoe.com, with the word “PRIVACY” in the subject heading. The COMPANY’s mailing address is: Mingletoe LLC, 29 New York Avenue, Ocean Grove, New Jersey 07756. The contact phone number is +1-415-341-6863.

Please note that information submitted to the Website via a “contact us,” “help,” or similar e-mail address or form will not necessarily receive a response. We will not use the information provided to these e-mail addresses or forms for marketing purposes unrelated to your request.

XVIII. Notification of Changes

The COMPANY reserves the right to change this Privacy Policy and its Terms and Conditions at any time. In the case of any material change to this Privacy Policy, we will post the revised Policy with an updated “Last Updated” date and, for no fewer than 30 days, will identify it on the home page of our sites as an “Updated Privacy Policy.” All changes to this Privacy Policy will be effective when posted, and your continued use of any COMPANY Website or Service after posting will constitute acceptance of, and agreement to be bound by, those changes. As noted in Section I, the COMPANY also reviews this Privacy Policy at least once every twelve (12) months.

XIX. Your California Privacy Rights

This section applies to California residents and supplements the disclosures elsewhere in this Privacy Policy. It is provided pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), and the California “Shine the Light” law.

Your CCPA rights. Subject to certain exceptions, California residents have the following rights:

  1. Right to know / access. You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it.
  2. Right to delete. You may request that we delete personal information we have collected from you, subject to certain exceptions.
  3. Right to correct. You may request that we correct inaccurate personal information we maintain about you, and we will use commercially reasonable efforts to do so.
  4. Right to opt out of sale or sharing. You have the right to opt out of the “sale” or “sharing” of your personal information. As stated in Section XII, the COMPANY does not sell or share personal information; accordingly, no opt-out is necessary, although we honor the Global Privacy Control signal as described in Section X.
  5. Right to limit the use of sensitive personal information. You may direct a business that uses or discloses sensitive personal information beyond certain permitted purposes to limit such use. As stated in Section II, the COMPANY does not collect or use sensitive personal information beyond the purposes permitted under the CCPA, so no action is required of you.
  6. Right to non-discrimination and non-retaliation. We will not discriminate or retaliate against you for exercising any of your CCPA rights.

Exercising your rights. To exercise any of these rights, please contact us at admin@mingletoe.com with the word “PRIVACY” in the subject heading. We will verify your request by reasonable means before responding, which may require you to confirm information we already maintain about you. You may use an authorized agent to submit a request on your behalf, subject to verification of the agent’s authority. We will respond to verifiable consumer requests consistent with the timelines required by the CCPA.

California “Shine the Light.” California Civil Code Section 1798.83 permits California residents who have an established business relationship with us to request information about our disclosure of personal information to third parties for those third parties’ direct-marketing purposes. As stated throughout this Privacy Policy, we do not disclose personal information to third parties for their own direct-marketing purposes unless you affirmatively agree to such disclosure. To make a request under this section, please e-mail admin@mingletoe.com with the word “PRIVACY” in the subject heading. We are required to respond to no more than one request per customer per calendar year, and we are not required to respond to requests made by means other than through this e-mail address.

 

 

Data Processing Addendum

1. Background

  1. “Customer” refers to “You,” a user of the Website, as referenced in the Terms and Conditions.
  2. In the event that we Process any Customer Personal Data (each as defined below) and (i) the Customer Personal Data relates to Data Subjects located in the EEA, or (ii) you are established in the EEA, this Data Processing Addendum (the “DPA”) shall apply to the Processing of such Customer Personal Data.
  3. In the event of a conflict between any provision of this DPA and the remaining provisions of the Terms and Conditions (including as incorporated into the Privacy Policy), the provisions of this DPA shall prevail.
  4. Each party will comply with all applicable requirements of the Data Protection Laws (as defined below). This DPA is in addition to, and does not relieve, remove, or replace, either party’s obligations under the Data Protection Laws.
  5. The Customer and the COMPANY acknowledge that, for the purposes of the Data Protection Laws, the Customer is the Controller and the COMPANY is the Processor.

2. Definitions

Unless otherwise set out below, each capitalized term in this DPA has the meaning set out in the Terms and Conditions, and the following terms have the meanings set out below:

  • “Customer Personal Data” means the personal data described in Annex 2 and any other personal data that the COMPANY Processes on behalf of the Customer in connection with the COMPANY’s provision of the Services or Website;
  • “Data Protection Laws” means the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, and all applicable legislation protecting the fundamental rights and freedoms of persons and their right to privacy with regard to the Processing of Customer Personal Data;
  • “European Economic Area” or “EEA” means the Member States of the European Union together with Iceland, Norway, and Liechtenstein;
  • “Party” means each of the Customer and the COMPANY;
  • “Security Incident” means any accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, any Customer Personal Data;
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as set out or incorporated by reference in Annex 1 to this DPA, and, where the transfer is subject to UK data-protection law, the UK International Data Transfer Addendum to those clauses issued by the UK Information Commissioner; the applicable modules and Annexes (including Annex 2 — Details of the Processing and Annex 3 — Technical and Organisational Measures) shall apply as appropriate to the relationship between the Parties;
  • “Subprocessor” means any Processor engaged by the COMPANY that agrees to receive from the COMPANY any Customer Personal Data;
  • “Terms” refers to the Terms and Conditions of the Website, into which the Privacy Policy and this DPA are incorporated; and
  • the terms “personal data,” “Controller,” “Processor,” “Data Subject,” “Process,” and “Supervisory Authority” shall have the same meaning as set out in the GDPR.

3. Data Processing

3.1 Instructions for Data Processing. The COMPANY will Process Customer Personal Data only in accordance with (a) the Terms (including this DPA), to the extent necessary to provide the Service to the Customer, and (b) the Customer’s written instructions, unless Processing is required by European Union or Member State law to which the COMPANY is subject, in which case the COMPANY shall, to the extent permitted by applicable law, inform the Customer of that legal requirement before Processing. The Terms (including this DPA) constitute the Customer’s complete and final instructions to the COMPANY in relation to the Processing of Customer Personal Data.

3.2 Processing outside the scope of the Terms (including this DPA) will require prior written agreement between the Customer and the COMPANY on additional instructions for Processing.

3.3 Required consents. Where required by applicable Data Protection Laws, the Customer will be responsible for ensuring that all Data Subjects have given all necessary consents for the lawful Processing of Customer Personal Data by the COMPANY in accordance with the Terms.

3.4 Privacy notices. The Customer warrants and represents that (a) it has provided all applicable notices to Data Subjects required for the lawful Processing of Customer Personal Data by the COMPANY in accordance with the Terms; or (b) in respect of any Customer Personal Data collected by the COMPANY on behalf of the Customer, it has reviewed and confirmed the notices provided by the COMPANY to Data Subjects as accurate and sufficient for the lawful Processing of Customer Personal Data by the COMPANY in accordance with the Terms.

4. Transfer of Personal Data

4.1 Authorized Subprocessors. The Customer agrees that the COMPANY may engage the Subprocessors listed in Annex 2 to Process Customer Personal Data.

4.2 The Customer agrees that the COMPANY may use Subprocessors to fulfill its contractual obligations under the Terms. The COMPANY shall notify the Customer from time to time of the identity of any Subprocessor it engages. If the Customer (acting reasonably) does not approve of a new Subprocessor, then, without prejudice to any right to terminate the Terms, the Customer may request that the COMPANY move the Customer Personal Data to another Subprocessor, and the COMPANY shall, within a reasonable time following receipt of such request, use all reasonable endeavors to ensure that the Subprocessor does not Process any of the Customer Personal Data.

4.3 Except as set out in this DPA, the COMPANY shall not permit, allow, or otherwise facilitate Subprocessors to Process Customer Personal Data without first entering into a written agreement with the Subprocessor that imposes obligations equivalent to those imposed on the COMPANY under this DPA.

4.4 Liability of Subprocessors. The COMPANY shall at all times remain responsible for compliance with its obligations under this DPA and will be liable to the Customer for the acts and omissions of any Subprocessor as if they were the acts and omissions of the COMPANY.

4.5 International Transfers of Personal Data. To the extent that the Processing of Customer Personal Data by the COMPANY involves the transfer of such data to a country or territory outside the EEA (or, as applicable, the United Kingdom), other than to a country or territory recognized as ensuring an adequate level of protection, such transfer shall be governed by the Standard Contractual Clauses. In the event of any conflict between the Standard Contractual Clauses, this DPA, and the Terms, the Standard Contractual Clauses shall prevail.

5. Data Security, Audits, and Security Notifications

5.1 COMPANY Security Obligations. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of natural persons, the COMPANY shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures set out in Annex 3 of this DPA.

5.2 Upon request by the Customer, the COMPANY shall make available all information reasonably necessary to demonstrate compliance with this DPA.

5.3 Security Incident Notification. If the COMPANY or any Subprocessor becomes aware of a Security Incident, the COMPANY will (a) notify the Customer without undue delay after becoming aware of the Security Incident; (b) investigate the Security Incident and provide reasonable assistance to the Customer (and any law-enforcement or regulatory official) as required to investigate it; and (c) take steps to remedy any non-compliance with this DPA.

5.4 COMPANY Employees and Personnel. The COMPANY shall treat the Customer Personal Data as the confidential information of the Customer and shall ensure that any employees or other personnel of the COMPANY have agreed in writing to protect the confidentiality and security of Customer Personal Data.

6. Access Requests and Data Subject Rights

6.1 Data Subject Requests. Except as required (or where prohibited) under applicable law, the COMPANY shall notify the Customer of any request received by the COMPANY or any Subprocessor from a Data Subject in respect of their personal data included in the Customer Personal Data, and shall not respond to the Data Subject directly.

6.2 The COMPANY shall provide the Customer with the ability to correct, delete, block, access, or copy the Customer Personal Data in accordance with the functionality of the Service.

6.3 Government Disclosure. The COMPANY shall notify the Customer of any request for the disclosure of Customer Personal Data by a governmental or regulatory body or law-enforcement authority (including any data-protection supervisory authority), unless otherwise prohibited by law or a legally binding order of such body or agency.

7. Assistance

7.1 Where applicable, taking into account the nature of the Processing, and to the extent required under applicable Data Protection Laws, the COMPANY shall provide the Customer with any information or assistance reasonably requested by the Customer for the purpose of complying with the Customer’s obligations under applicable Data Protection Laws, including: (a) using all reasonable endeavors to assist the Customer, by implementing appropriate technical and organizational measures insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise Data Subject rights under the GDPR; and (b) providing reasonable assistance to the Customer with data-protection impact assessments and prior consultations with any Supervisory Authority, in each case solely in relation to the Processing of Customer Personal Data and taking into account the information available to the COMPANY.

8. Duration and Termination

8.1 Deletion of data. Subject to Section 8.2, the COMPANY shall, at the Customer’s election and within 90 (ninety) days of the date of termination of the Terms: (a) delete, and use all reasonable efforts to procure the deletion of, Customer Personal Data Processed by it or any Subprocessors; or (b) return a complete copy of all Customer Personal Data by secure file transfer in a format notified by the COMPANY to the Customer (and delete, and use all reasonable efforts to procure the deletion of, all other copies of Customer Personal Data Processed by the COMPANY or any Subprocessors).

8.2 The COMPANY and its Subprocessors may retain Customer Personal Data to the extent, and for such period as, required by applicable laws, provided that the COMPANY shall ensure the confidentiality of all such Customer Personal Data and shall ensure that it is Processed only as necessary for the purpose(s) specified in the applicable laws requiring its storage, and for no other purpose.

 

 

Annex 1 — Standard Contractual Clauses

The Parties incorporate by reference the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “EU SCCs”), and, where applicable to transfers subject to UK data-protection law, the International Data Transfer Addendum to the EU SCCs issued by the United Kingdom Information Commissioner under section 119A of the UK Data Protection Act 2018 (the “UK Addendum”).

For the purposes of this Annex 1, references to the “data exporter” and the “data importer” shall be to the Customer and to the COMPANY, respectively (each a “party”; together, “the parties”). The EU SCCs are completed as follows:

  1. Module. Module Two (Controller to Processor) applies to transfers of Customer Personal Data from the Customer (as Controller) to the COMPANY (as Processor). Module Three (Processor to Processor) applies as between the COMPANY and any Subprocessor.
  2. Clause 7 (Docking clause). The optional docking clause applies.
  3. Clause 9 (Use of sub-processors). Option 2 (general written authorisation) applies. The COMPANY shall inform the Customer of any intended changes to the list of Subprocessors at least fourteen (14) days in advance, thereby giving the Customer the opportunity to object.
  4. Clause 11 (Redress). The optional language regarding independent dispute resolution does not apply.
  5. Clause 17 (Governing law). The EU SCCs are governed by the law of the Republic of Ireland.
  6. Clause 18 (Choice of forum and jurisdiction). Disputes shall be resolved before the courts of the Republic of Ireland.
  7. Annexes. Annex I (List of Parties; Description of Transfer; Competent Supervisory Authority) and Annex II (Technical and Organisational Measures) to the EU SCCs are completed by reference to Annex 2 and Annex 3 of this DPA, respectively. The competent supervisory authority shall be determined in accordance with Clause 13 of the EU SCCs.

To the extent the legacy standard contractual clauses approved by Commission Decision 2010/87/EU previously applied to any transfer, the Parties agree that those clauses are superseded by the EU SCCs set out in this Annex 1 with effect from the effective date of this Privacy Policy.

 

 

Annex 2 — Details of the Processing of Customer Personal Data

This Annex 2 includes certain details of the Processing of Customer Personal Data as required by Article 28(3) of the GDPR and for the purposes of the Standard Contractual Clauses.

Subject matter and duration of the Processing. The subject matter of the Processing is the use of, and access to, the Services and/or Website by the Customer in accordance with the Terms. The duration of the Processing is the term of the Terms, subject to Section 8.2 of the DPA.

Nature and purpose of the Processing. The Processing of Customer Personal Data provided by the Customer to the COMPANY, or collected by the COMPANY on behalf of the Customer, for the purposes of providing the Services and/or Website to the Customer.

Types of Customer Personal Data Processed. First and last name; contact information (including e-mail address); usage information; online identifiers; and any other personal data the Customer or its users submit to the COMPANY in the course of using the Services and/or Website.

Categories of Data Subject. Employees and other personnel of the Customer authorized by the Customer to use the Services on its behalf, and employees and other personnel of the Customer’s customers.

Obligations and rights of the Customer. As set out in the Terms (including this DPA).

Authorized Subprocessors. The Customer authorizes the COMPANY to engage the following Subprocessors to Process Customer Personal Data:

  1. Stripe, Inc. — payment processing.
  2. HubSpot, Inc. — customer relationship management, marketing, and platform services.
  1. Google LLC — analytics and cloud/productivity services.
  2. Anthropic, PBC — artificial-intelligence and large-language-model tools used as back-end aids for content drafting and operational support; not used for automated decision-making about individuals.
  1. Dropbox, Inc. — file storage.

The COMPANY shall notify the Customer of any intended addition to, or replacement of, the Subprocessors listed above, as provided in Section 4.2 of the DPA and Clause 9 of the EU SCCs.

 

 

Annex 3 — Technical and Organisational Security Measures

  1. The COMPANY maintains internal policies and procedures, or procures that its Subprocessors do so, which are designed to: (a) secure any personal data Processed by the COMPANY against accidental or unlawful loss, access, or disclosure; (b) identify reasonably foreseeable internal and external risks to the security of, and unauthorized access to, the personal data Processed; and (c) minimize security risks, including through risk assessment and regular testing.
  2. The COMPANY uses reasonable efforts to procure that its Subprocessors conduct periodic reviews of the security of their networks and the adequacy of their information-security programs, as measured against industry security standards and their policies and procedures.
  3. The COMPANY uses reasonable efforts to procure that its Subprocessors periodically evaluate the security of their networks and associated services to determine whether additional or different security measures are required to respond to new security risks or to findings generated by periodic reviews.
  4. The technical and organisational measures include, as appropriate: encryption of personal data in transit using TLS; access controls and authentication; the principle of least privilege for personnel access; secure storage of credentials separate from account data; logging and monitoring; and confidentiality obligations binding on personnel.