CCI
Castleton Commodities International LLC

Website Privacy Policy

Introduction to this Website Privacy Policy

This website (the "Site") is owned and operated by Castleton Commodities International LLC ("CCI"). At CCI, we recognize the importance of privacy to you and are firmly committed to protecting your privacy when you visit the Site and provide information to us. As a result, we have instituted this website privacy policy ("Privacy Policy"). CCI is providing this Privacy Policy to explain how we collect, use, disclose and protect the Personal Data you submit to us when accessing and using the Site. CCI is the controller within the meaning of applicable data protection laws.

In general, you may visit the Site and view its content while remaining anonymous by not providing any Personal Data. If you do not agree with this Privacy Policy, please do not provide us any information and do not use the Site.

As used in this Privacy Policy, "we," "our" and "us" means CCI and its affiliates.

Scroll

The meaning of Personal Data

“Personal Data” is defined in data protection laws applicable in your country. It includes any information relating to an identified or identifiable natural person. This means any individual who can be identified directly or indirectly by reference to an identifier such as name, identification number, location data, online identifiers (for example, IP addresses – if they can be used to identify you) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. 

Put simply, this includes data which either by itself or with other data held by us or available to us, can be used to identify you. 

Important notice about international transfers

Due to the global nature of our business, your Personal Data will be stored and transferred to parties located in other countries, including outside the European Economic Area. These other countries will either have different data protection laws than your country of residence or they will not have data protection laws. They may not be deemed by the European Commission as providing adequate protection for Personal Data. 

In particular, we store your Personal Data on servers in the United States of America. The US are not deemed by the European Commission to have adequate protections for Personal Data.  Steps will be taken to put in place safeguards (including around security) to protect your Personal Data when it is in these other countries.  This may include the use of European Model Clause contracts, where required under applicable law.  You can find out what these are online at the following address:  https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en. If you have any questions or wish to be provided with a copy, please contact us. Please note commercially sensitive information may be removed/blanked out from copies supplied to you.

The categories of Personal Data we may collect, the purpose and the lawful basis

Personal Data collected from you include the following:

Category

Personal Data

Purpose

Lawful basis

Professional and Employment-Related Information

Name, email, DOB, account names, bank account information, signatures, contact numbers and other similar contact information and identifiers.

Collecting and processing employment applications, including confirming eligibility, background and related checks, onboarding including payroll and benefits and related recruiting efforts.

Processing is necessary for us to enter into a contract with you.

Contact Information

Full name, postal address, e-mail address, employer/business and professional information, job titles, telephone, and fax numbers.

 

Managing and responding to your queries, and where applicable, maintaining our employment relationship with you.

Performance of contract and legitimate interests - it’s important that we can respond to your enquiries.

Internet or Other Electronic Network Activity Information (IP address, browser information)

IP address, browser information, interactions with a website, application or advertisement.

Monitoring and producing statistical information regarding the use of our platforms and analysing and improving their functionality.

Legitimate interests - we need to perform this limited routine monitoring to make sure our website work properly, to diagnose any problems with our server and administer our Site.

Sensitive Information

Social security, driver’s license, identification card, passport details, racial or ethnic origin, religious or philosophical beliefs, or union membership, genetic or biometric data, health information and information regarding sex life or sexual orientation.

 

Sensitive information will not be collected unless necessary and in compliance with applicable laws and regulations which will include appropriate safeguards.

Only in circumstances where explicit consent was given or where processing is carried out for legitimate business activities and appropriate safeguards are in place.

 Any other relevant and required information

Information listed above

Establishing and enforcing our legal rights and obligations and monitoring to identify and record fraudulent activity.

Complying with instructions from law enforcement agencies, any court or otherwise as required by law.

For our general record-keeping and customer/employee relationship management.

Maintaining our employment relationship with you.

Managing the proposed sale, restructuring or merging of any or all part(s) of our business, including to respond to queries from the prospective buyer or merging organisation.

Resolving any complaints from or disputes with you.

Maintaining Personnel Records

Facilitating the secure use of the Company’s information systems

Managing

Complying with applicable state and federal health, labor, employment, benefits, workers compensation, disability, equal employment opportunity, workplace safety, and related laws, guidance, or recommendations.

 

Legitimate interest (see column on left)

In summary, we need certain categories of Personal Data because that is necessary in order to administer any contract with you (where relevant). Certain other Personal Data is processed for our legitimate interests in cases where this does not result in prejudice to you.

Data anonymisation and use of aggregated information

We may convert your Personal Data into statistical or aggregated data in such a way as to ensure that you are not identified or identifiable from that data.  We may use this aggregated data to conduct market research and analysis, including to produce statistical research and reports.  For example, we may produce reports on which of our product offerings attract the fewest or the highest number of enquiries from brokers and intermediaries and other persons visiting our Site. 

In particular, we may use technology to collect anonymous information about the use of this Site. For example:

1. We use technology to track the pages of our Site that visitors view. We also use technology to determine which web browsers our visitors use. This technology does not identify you personally, it simply enables us to compile statistics about our visitors and their use of our Site.

2. Certain pages of this Site may contain hyperlinks to other pages of it. We may use technology to track how often these links are used and which pages on our Site our visitors choose to view. Again, this technology does not identify you personally — it simply enables us to compile statistics about the use of these hyperlinks.

We use this anonymous data to improve the content and functionality of this Site and consider areas and subjects which are attracting interest so that we can focus our e-mail updates (for those that wish to receive such communications). This allows us to better understand our Site visitors’ interest areas generally and therefore to improve our Site and products and services we offer.

Disclosure of your Personal Data to third parties

We may disclose your Personal Data to third parties, including but not limited to as follows:

  1. within our group of companies for the purposes of use described in this Privacy Policy;
  2. to third parties who supply services to us and who help us and our group of companies to operate our business. For example, sometimes a third party may have access to your Personal Data in order to support our information technology or to handle mailings on our behalf. The same applies to our recruiting platform Workday;
  3. to our legal and other professional advisers;
  4. as necessary in order to comply with a legal requirement (including, where appropriate, any imposed on our group companies in the United States), for the administration of justice, to protect vital interests, to protect the security or integrity of our databases or this Site, to take precautions against legal liability;
  5. to regulatory authorities, courts and governmental agencies to comply with legal orders, legal or regulatory requirements and government requests; and
  6. CCI may engage third parties to manage the Site and provide other services in connection with the Site, such as the collection and analysis of data. Such third parties may have access to certain personal information you provide as necessary for the provision of such services on behalf of CCI; provided, however, all such third parties shall be required to protect such personal information in accordance with this Privacy Policy.

Security of Personal Data

We endeavour to use appropriate technical and physical security measures to protect Personal Data which is transmitted, stored or otherwise processed by us, from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access, in connection with our Site. These measures include computer safeguards and secured files and facilities. Our service providers are also selected carefully and required to use appropriate protective measures. In certain areas, CCI uses industry-standard SSL-encryption to protect data transmissions. Most current browsers support the level of security needed to use these areas.

In particular, we endeavour to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate: (a) pseudonymisation (such as where data is separated from direct identifiers so that linkage to an identity is not possible without additional information that is held separately) and encryption, (b) ensuring the ongoing confidentiality, integrity, availability and resilience of systems and services used to process your Personal Data, (c) ensuring the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (d) ensuring a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational security measures.

Retention period or criteria used to determine the retention period

We keep your Personal Data for as long as it is necessary to do so to fulfil the purposes for which it was collected as described above and in accordance with our data retention schedule. We may retain your Personal Information for longer if it is necessary to comply with our legal or reporting obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, enforce our legal agreements and policies, address other legitimate business needs, or as permitted or required by applicable law. 

The criteria we use to determine data retention periods for Personal Data includes the following: (i) Retention in case of queries.  We will retain it for a reasonable period after the relationship between us has ceased (up to 6 months) in case of queries from you; (ii) Retention in case of claims.  We will retain it for the period in which you might legally bring claims against us (in Germany this means we will retain it for 10 years) if and to the extent we have entered into any contract with you; (iii) Retention in accordance with legal and regulatory requirements.  We will consider whether we need to retain it after the period described in (ii) because of a legal or regulatory requirement. 

If your application for employment is successful and you commence employment with CCI, your Personal Data will be transferred to your personnel file and will be processed for employment purposes.

If your application for employment is not successful, for non-EU applicants, excluding the United Kingdom, we will retain your Personal Data and the documents that were submitted as part of your application in our talent pool. This data will only be used to match your profile to future job vacancies and to contact you in the event that you are considered as a possible candidate in the future. Your data will be deleted after 24 months at the latest. For unsuccessful applicants from the EU and the United Kingdom, we will retain your Personal Data and the documents that were submitted as part of your application for no more than six months, but if you consent (by separately acknowledging your agreement to have your data processed pursuant to this policy), we will further retain such Personal Data and documents in our talent pool. This data will only be used to match your profile to future job vacancies and to contact you in the event that you are considered a possible candidate in the future. Your data will be deleted after 24 months at the latest. Further, you may withdraw your consent to our retention of this data at any time without giving any reason by contacting us. In the event you contact us to withdraw your consent, we will delete all your personal data.

California Residents

This section applies only to California residents. It supplements and amends the information contained in the Privacy Policy with respect to California residents. The other provisions of the Privacy Policy continue to apply, except as modified in this California section.

Shine the Light.  California Civil Code Section 1798.83 permits you to request information regarding the disclosure of your personal information by us to third parties for the third parties’ direct marketing purposes. Such requests must be submitted to us in accordance with the instructions in the Contact Us section of this Policy.  Please mention when contacting us that you are making a “California Shine the Light” inquiry. Within 30 days of receiving such a request, we will provide a list of the categories of personal information disclosed to third parties for third-party direct marketing purposes during the immediately preceding calendar year, along with the names and addresses of these third parties.  This request may be made no more than once per calendar year.  We reserve our right not to respond to requests submitted other than in accordance with the instructions specified in this paragraph. 

Eraser Law.  If you are a California resident under the age of 18, and a registered user of any site where this policy is posted, California law permits you to request and obtain removal of content or information you have publicly posted. You may submit your request using the contact information at the end of this Policy. Please be aware that such request does not ensure complete or comprehensive removal of the content or information you have posted and that there may be circumstances in which the law does not require or allow removal even if requested.

California Consumer Privacy Act. The following provisions describe our policies and practices regarding the collection, use, and disclosure of Personal Information, including information we obtain when you access or use the Site or through other channels (e.g., phone and email conversations, when you visit our locations or attend our events, or through our authorized services providers), in accordance with the California Consumer Privacy Act, as amended (“CCPA”).

Any terms defined in the CCPA have the same meaning when utilized in this section. The other provisions of the Privacy Policy continue to apply except as modified herein.

Please read this section, in addition to the Categories of Personal Data already listed, carefully before using the Site, or submitting information to us. By accessing or visiting the Site, or submitting Personal Information to us, you indicate your understanding that the collection, use, and sharing of your information is subject to the terms of this policy. Except as otherwise noted, any capitalized terms not defined in this section have the meaning set forth in the Privacy Policy.

Personal Information We Collect

During the past 12 months, we may have collected the following categories of your Personal Information:

Identifiers and Contact Information. This category includes names, addresses, telephone numbers, mobile numbers, email addresses, signatures, account names, dates of birth, bank account information, and other similar contact information and identifiers.

Protected Classification Information. This category includes characteristics of protected classifications under California or federal law.

Commercial Information.  This category includes, without limitation, products and services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Education Information. This category includes, without limitation, information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, Sec. 1232g; 34 C.F.R. Part 99).

Internet or Other Electronic Network Activity Information. This category includes, without limitation, browsing history, search history, or a consumer’s interactions with a website, application, or advertisement.

Geolocation Data. This category includes, without limitation, location information collected when using one of our apps, devices, or vehicles.

Audio, Electronic, Visual, Thermal, Olfactory, or Similar Information. This category includes, without limitation, information collected from voicemail messages, while speaking with one of our service representatives, and/or by video camera.

Biometric Information. This category includes, without limitation, an individual’s physiological, biological, or behavioral characteristics used or intended for use – singly or in combination with each other or with other identifying data – to establish individual identity. 

Professional and Employment-Related Information. This category includes, without limitation, information regarding job applications, information related to onboarding for payroll and benefits, and information needed for evaluating performance.

Sensitive Personal Information. This category includes:

  • social security, driver’s license, state identification card, or passport number;
  • log-in, financial account, debit card, or credit card number, in combination with any required security or access code, password, or credentials allowing access to an account;
  • precise geolocation;
  • racial or ethnic origin, religious or philosophical beliefs, or union membership;
  • content of mail, email, and text messages (unless we are the intended recipient of the communication);
  • genetic data;
  • biometric information;
  • health information; and
  • information regarding sex life or sexual orientation.

Sources of Personal Information

We may collect your Personal Information from the following sources: 

You.  We collect information you provide us – e.g., in connection with your use of our products or services or application for or employment with us. For instance, when you contact us regarding our products or services, you may provide your name, email address, and information related to the product or service you request.  When you apply for a job with us, you may provide information regarding your educational and professional history.  In connection with your employment with us, you may provide financial account information needed for payroll processing and government identification numbers needed to verify your identity and work authorization status.    

Related Entities and Affiliates.  We may collect Personal Information about you from our affiliates and other related parties.

Service Providers and Contractors.  We may collect your Personal Information from service providers or contractors who collected information about you that is needed to provide you products or services or in connection with your application for or employment with us.

News Outlets, Social Media, Surveys, and Third Parties.  In the course of performing our services or marketing activities, or in connection with your application for or employment with us, we or third parties on our behalf may conduct research and other activities that result in the collection of your Personal Information.

Information Collected Automatically. As you navigate through and interact with our Site, we may compile statistical information concerning your usage of the Site through analytics services, such as those provided by Google Analytics. To do so, we may collect certain information about your equipment, browsing actions and patterns, including:

  • Details of your visits to our Site, such as traffic data, location data, logs and other communication data and the resources that you access and use on the Site.
  • Information about your computer and internet connection, including your IP address, operating system, and browser type.
  • Information about the type of device you are using, mobile ad identifiers, the time and length of your visit, and the website that referred you to our Site.
  • Information about your preferences to make your use of the Site more productive, via the use of Cookies. For more information on Cookies, please see the Cookies and Other Tracking Technologies section. While all of this information can be associated with the IP address your computer had while you visited the Site, it will not be associated with you as an individual or with any other information you may submit through the Site or that we may store about you for any other purposes. We may use this information to generate aggregate statistics about visitors to our Site. Please check your web browser if you want to learn what information your browser sends or how to change your settings.

Purposes for Collecting and Using Personal Information

We may collect and use your Personal Information for the same purposes for which we collect and use your Personal Data.  Please see “Personal Data we may collect, the purpose and the lawful basis” section above for additional information. 

Disclosure of Personal Information

We may disclose your Personal Information to the same third parties and for the same purposes for which we may disclose your Personal Data.  Please see “Disclosure of your Personal Data to third parties” section above for additional information. 

We do not “sell” or “share” your Personal Information, as those terms are defined in the CCPA.  Nor do we have actual knowledge of selling Personal Information of minors under the age of 16. 

Retention of Personal Information

Our retention practices related to Personal Information are the same as those related to Personal Data.  Please see the “Retention period or criteria used to determine the retention period” section above for additional information.

Consumer Rights

If you are a California resident, you may have certain rights related to your personal information, subject to certain exceptions. Specifically:

Right to Know. You have the right to request that we disclose the following to you upon receipt of your verifiable consumer request: 

  • The categories of Personal Information we have collected about you
  • The categories of sources from which we collected that information
  • The business or commercial purposes for collecting, selling, or sharing that information
  • The categories of Personal Information we sold or disclosed for a business purpose
  • The categories of third parties to whom we sold or disclosed that information
  • The specific pieces of Personal Information we collected about you

Right to Delete. You have the right to request that we delete your Personal Information from our records, subject to certain exceptions. Upon receipt of a verifiable consumer request, and as required by the CCPA, we will delete and direct any service providers to delete your Personal Information.

We are not required to comply with deletion requests if we, or our service providers or contractors, need the subject information in order to:

  • Complete the transaction for which the personal information was collected, provide a good or service requested by you or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between us and you.
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity.
  • Debug to identify and repair errors that impair existing intended functionality.
  • Exercise free speech, ensure the right of another consumer to exercise their right of free speech, or exercise another right provided for by law.
  • Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
  • Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us and compatible with the context in which you provided the information to us.
  • Comply with a legal obligation.
  • Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided the information.

Right to Correct.  You have the right, subject to certain limitations, to request that we correct any inaccurate Personal Information we maintain about you.  Upon receipt of a verifiable consumer request, and as required by the CCPA, we will take appropriate steps to respond to your request.

Right to Opt-Out of Selling or Sharing. You have the right, subject to certain limitations, to opt-out of having your Personal Information sold or shared. However, we do not sell or share your Personal Information, as those terms are defined in the CCPA, and do not have actual knowledge that we have sold Personal Information of minors under age 16.

Right Against Discrimination. You have the right not to be discriminated against for exercising any of the rights described in this section. For example, we generally will not provide you a different level or quality of goods or services if you exercise these rights.

Submitting Consumer Rights Requests

To submit a consumer rights request, please contact us toll free at 1-855-955-5354 or by sending an email to our Compliance Department at Compliance@CCI.com.

Verification. We reserve the right to only respond to verifiable consumer requests. A verifiable consumer request is one made by:

  • the consumer who is the subject of the request,
  • a consumer on behalf of the consumer’s minor child, or
  • a natural person or business entity authorized to act on behalf of a consumer.

To verify your identity, we may ask you to verify Personal Information we already have on file for you. If we cannot verify your identity from the information we have on file, we may request additional information from you, which we will only use to verify your identity, and for security or fraud-prevention purposes.  Making a verifiable consumer request does not require you to create an account with us. Additionally, you will need to describe your request with sufficient detail to allow us to review, understand, assess, and respond. 

Authorized Agents.  You may authorize a natural person or business entity to act on your behalf with respect to your rights under this section. Unless you have provided the authorized agent with a qualifying power of attorney, you must provide your authorized agent written permission, signed by you, to act on your behalf and verify the authorized agent’s identity with us.  We reserve the right to deny requests from persons or businesses claiming to be authorized agents that do not submit sufficient proof of their authorization.

We may not be able to respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.

Our Response.  We reserve the right to charge a fee to process or respond to your request if it is excessive, repetitive, or manifestly unfounded. If we determine that a request warrants a fee, we will attempt to notify you as to why we made that decision and provide a cost estimate before completing your request. We will endeavour to respond to a verifiable consumer request within forty-five (45) calendar days of receipt, but we may require an extension of up to forty-five (45) additional calendar days to respond and we will notify you of the need for the extension.

If you have an account with us, we will deliver our written response to that account.  If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.  Any disclosures we provide will only cover the 12-month period preceding the receipt of your verifiable consumer request. With respect to Personal Information collected on and after January 1, 2022, and to the extent expressly permitted by applicable regulation, you may request that such disclosures cover a period beyond the 12 months referenced above, provided doing so would not be impossible or require a disproportionate effort by us. The response we provide will also explain the reasons we cannot comply with a request, if applicable. To the extent permitted by the CCPA, we will respond to no more than two requests during any 12-month period.

Please note that when we function as a service provider or contractor to our business clients and have received your Personal Information in connection with those functions, we are not obligated to respond to your requests concerning personal information.  In those cases, we may direct you to the applicable business client(s) with whom you have a direct relationship. 

Your rights under other data privacy laws

You may have additional rights under data privacy laws in your country, including the CCPA.  These may include (as relevant):  

- The right to request access to the Personal Data we hold about you (right to know);

- the right to rectification including to require us to correct inaccurate Personal Data;

- the right to request restriction of processing concerning you or to object to processing of your Personal Data,

- The right to request the erasure/deletion of your Personal Data where it is no longer necessary for us to retain it;

- The right to data portability including to obtain Personal Data in a commonly used machine-readable format in certain circumstances such as where our processing of it is based on a consent; the right object to automated decision-making including profiling (if any) that has a legal or significant effect on you as an individual; and

- The right to withdraw your consent to any processing for which you have previously given that consent.  

You can also lodge a complaint with the appropriate supervisory authority.

Please see “Contact Us” if you wish to exercise any of these rights (as relevant).

Links to Other Websites

This Site may contain hyperlinks to websites that are not operated by us. These hyperlinks are provided for your reference and convenience only and do not imply any endorsement of the activities of these third-party websites or any association with their operators. We do not control these websites and are not responsible for their data or privacy practices. We urge you to review any privacy policy posted on any site you visit before using the site or providing any Personal Data.

Updates and changes to this Privacy Policy

We may decide to change this Privacy Policy. If the change is fundamental or may significantly affect you, we will provide you with the updated Privacy Policy in advance of the change taking effect. We encourage you to review the content of this Privacy Policy regularly.

Contact Details

If you wish to exercise your data protection rights against us, please e-mail Compliance@CCI.com.

Be sure to include your email address and telephone number with your correspondence.

Alternatively, write to

Attn: Compliance

2200 Atlantic Street, Suite # 800

Stamford, CT 06902-6834

Phone: 203-564-8100

 

Our legal representative for Europe and the UK  is Castleton Commodities UK Limited, 20 Fenchurch Street, 34th floor, London EC3M 3BY, +44 (0)20 3321 1300.

 

Last updated: 21 June 2023