Effective Date: March 1, 2019
1. Categories of Personal Data and Processing purposes - What personal data do we process about you and why?
You may use the Rexnord Website without providing any personal data about you. In this case, we will collect only the following metadata that result from your usage of the Rexnord Website: browser type and version, operating system and interface, website from which you are visiting
us (referrer URL), webpage(s) you are visiting on our Rexnord Website, date and time of accessing our Rexnord Website, and internet protocol (IP) address. Your IP address will be stored once you access our Rexnord Website. Metadata will be used in anonymized form and to prevent fraud and misuse of our IT systems, as well as to ensure physical, IT and network security.
2. Processing Basis and Consequences - What is the legal justification for processing your personal data and what happens if you choose not to provide it?
We rely on the following legal grounds for the collection, processing, and use of your personal data:
- the processing is necessary to enable you the use of the Rexnord Website;
- the processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of you which require protection of personal data; such legitimate interests are the fulfilment of the processing purposes set out above in Section 1, in particular improvement of the quality and services of our Rexnord-Website and services, prevention of fraud, misuse of our IT systems, physical, IT and network security, as well as marketing relating to our products and services;
- the processing is necessary for compliance with a legal obligation to which we are subject;
3. Categories of Recipients and International Transfers - Who do we transfer your personal data to and where are they located?
We may transfer your personal data to third parties for the processing purposes described above as follows:
- Within the Rexnord Group: Each of our affiliates and subsidiaries (each affiliate or subsidiary including us referred to as "Rexnord Affiliate") within the global Rexnord Group may receive your personal data as necessary for the processing purposes described above. Depending on the categories of personal data and the purposes for which the personal data has been collected, different internal departments within the Rexnord Company may receive your personal data. For example, our IT department may have access to your metadata. Moreover, other departments within the Rexnord Company have access to certain personal data about you on a need to know basis, such as the legal department, the finance department or internal auditing.
- With data processors: Certain third parties, whether affiliated or unaffiliated, may receive your personal data to process such data under appropriate instructions ("Processors") as necessary for the processing purposes described above, such as website service providers, IT support service providers, and other service providers who support us to run our website. The Processors will be subject to contractual obligations to implement appropriate technical and organizational security measures to safeguard the personal data, and to process the personal data only as instructed.
You can ask for further details of the currently engaged Processors by contacting us as
set out in Section 7 below.
- Other Recipients: We may transfer - in compliance with applicable data protection law - personal data to law enforcement agencies, governmental authorities, judicial authorities, legal counsel, external consultants, or business partners. In case of a corporate merger or acquisition, personal data may be transferred to the third parties involved in the merger or acquisition. We will not disclose your personal data to third parties for advertising or marketing purposes or for any other purposes without permission.
Any access to your personal data is restricted to those individuals that have a need-to-know in order to fulfill their job responsibilities.
International transfers. You should expect that the recipients identified above which will receive or have access to your personal data, are located inside or outside the European Economic Area ("EEA").
- For recipients located outside of the EEA, some are certified under the EU-U.S. Privacy Shield and others are located in countries with adequacy decisions pursuant to Art. 45 GDPR (in particular, Canada, Switzerland, Israel), and, in each case, the transfer is thereby recognized as providing an adequate level of data protection from a European data protection law perspective. Other recipients might be located in countries, such as the USA, which do not adduce an adequate level of protection from a European data protection law perspective.
- We will take all necessary measures to ensure that transfers out of the EEA are adequately protected as required by applicable data protection law. With respect to transfers to countries not providing an adequate level of data protection, we will base the transfer on appropriate safeguards, such as standard data protection clauses adopted by the European Commission or by a supervisory authority (Art. 46(2)(c) or (d) GDPR), approved codes of conduct together with binding and enforceable commitments of the recipient(Art. 46 (2)(e) GDPR), or approved certification mechanisms together with binding and enforceable commitments of the recipient (Art. 46 (2)(f) GDPR). You can ask for a copy of such appropriate safeguards by contacting us as set out in Section 7 below.
4. Retention Period - How long do we keep your personal data?
Your personal data will be retained as long as indicated below.
If we are required by applicable law to retain certain of your personal data, we will not delete them. We may also retain your personal data if we need your personal data to establish, exercise or defend a legal claim, on a need to know basis only. To the extent possible, we will restrict the processing of your personal data for such limited purposes after the termination of the contractual relationship.
5. Your Rights - What rights do you have and how can you assert your rights?
Right to withdraw your consent: If you have declared your consent regarding certain collecting, processing and use of your personal data (in particular, regarding the receipt of direct marketing communication via email, and telephone), you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal. You can withdraw your consent as follows email: Dataprivacy@rexnord.com. Further, you can object to the use of your personal data for the purposes of marketing without incurring any costs other than the transmission costs in accordance with the basic tariffs.
Additional data privacy rights: Pursuant to applicable data protection law, you may have the right to: (i) request access to your personal data; (ii) request rectification of your personal data; (iii) request erasure of your personal data; (iv) request restriction of processing of your personal data; (v) request data portability; and/or (vi) object to the processing of your personal data (including objection to profiling).
Please note that these aforementioned rights might be limited under the applicable local data protection law. Below please find further information on your rights to the extent that the GDPR applies:
To exercise your rights, please contact us as stated under Section 7 below. You also have the right to lodge a complaint with the competent data protection supervisory authority in the relevant Member State (e.g., the place where you reside, work, or of an alleged infringement of the GDPR).
6. Cookies and other tracking technologies
Description and storage time
Tracks if a session is valid for the user (Necessary Cookie) 1-year storage
Stores the culture of the user (Necessary Cookie) 1-year storage
Performance Cookie 2-years storage
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources, so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site and will not be able to monitor its performance.
7. Questions and Contact Information