Page for Posts: 47549
is_page(): true
is_home(): false
is_singular(): true
Current template: template-canvas.php
Current post ID: 11977
get_queried_object_id(): 11977
The post type is: page
Current query: Array ( [page] => 0 [pagename] => privacy-policy [error] => [m] => [p] => 0 [post_parent] => [subpost] => [subpost_id] => [attachment] => [attachment_id] => 0 [name] => privacy-policy [page_id] => 0 [second] => [minute] => [hour] => [day] => 0 [monthnum] => 0 [year] => 0 [w] => 0 [category_name] => [tag] => [cat] => [tag_id] => [author] => [author_name] => [feed] => [tb] => [paged] => 0 [meta_key] => [meta_value] => [preview] => [s] => [sentence] => [title] => [fields] => all [menu_order] => [embed] => [category__in] => Array ( ) [category__not_in] => Array ( ) [category__and] => Array ( ) [post__in] => Array ( ) [post__not_in] => Array ( ) [post_name__in] => Array ( ) [tag__in] => Array ( ) [tag__not_in] => Array ( ) [tag__and] => Array ( ) [tag_slug__in] => Array ( ) [tag_slug__and] => Array ( ) [post_parent__in] => Array ( ) [post_parent__not_in] => Array ( ) [author__in] => Array ( ) [author__not_in] => Array ( ) [search_columns] => Array ( ) [ignore_sticky_posts] => [suppress_filters] => [cache_results] => 1 [update_post_term_cache] => 1 [update_menu_item_cache] => [lazy_load_term_meta] => 1 [update_post_meta_cache] => 1 [post_type] => [posts_per_page] => 8 [nopaging] => [comments_per_page] => 50 [no_found_rows] => [order] => DESC )

Privacy Policy


APPLIED TECHNICAL SERVICES, LLC DATA PRIVACY AND CCPA NOTICE

Effective Date: September 10, 2026

Applied Technical Services, LLC and all of its subsidiaries and business lines (collectively, “ATS,” the “Company,” “we,” “us” and “our”) are committed to having a strong program in place for protecting consumer personal data and complying with state and federal privacy laws that impose requirements on ATS to protect consumer personal data and grant rights to consumers with respect to their own data. This privacy notice is not applicable to Economic Union (EU) citizens. If you are an EU citizen and would like to learn more about your consumer data protections and rights, visit: https://www.sgs.com/en-us/privacy-at-sgs. ATS is a subsidiary of SGS SA.

There are three aspects to ATS’s Data Privacy Policy: (i) data management; (ii) data security and protection; and (iii) incorporation of consumer data privacy rights and protections. In addition to the Company’s data privacy policy, each business line may also have contractual obligations of data confidentiality and security with each of its clients. To have an effective and comprehensive privacy policy, the Company must understand the consumer data that the Company collects, stores, uses or discloses. ATS maintains an inventory that documents the data location (where the data is stored), data flow (how, when and with whom the Company receives or shares the data) and the method and manner under which data is transferred.

ATS implements and maintains reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of consumer data. The safeguards we employ are designed to protect against any reasonably foreseeable threats or hazards to the security or integrity of data, and protect against unauthorized access or use of that information that could result in substantial harm or inconvenience to our clients and consumers. The specific safeguards are designed to control the risks identified. The safeguards may include physical controls, policies and procedures, service provider and vendor agreements, restrictions to access, such as locks and/ or passwords, training, monitoring and other reasonable safeguards. The Company conducts periodic risk assessments to evaluate the adequacy of its administrative, technical and physical safeguards.

The Company and/or its clients may be subject to state or federal laws which establish privacy and consumer data protection principles. The Company is mindful of whether consumers’ have the right to know what data is collected and stored, how it is used and to whom it is disclosed and, potentially, the right to restrict those activities. If a business line collects personal data on a particular jurisdiction’s residents, the business line will be subject to and comply with the applicable privacy laws and regulations of that jurisdiction.

Finally, all Company employees, including managers, are required to comply with ATS’s Data Privacy Policy, and receive periodic training regarding its requirements.

1. Contact Details

The Company is responsible, as a business, for collecting and processing the personal data in the context of our business relationships and, in particular, in order to provide services as part of the execution of our contractual obligations with our Customers or to carry out pre-contractual steps as part of an offer for services or for entering into a contract with Customer.

If you have any questions or comments about this Notice or to exercise any right under Section 8 please contact us:

You may opt out of receiving marketing communications from ATS at any time by clicking the “Unsubscribe” link in any marketing email or by contacting us directly using the methods above.

2. Categories and Types of Personal Data Collected and Processed

The personal data processed by the Company may include:

  • contact information (name, home and/ or business address, telephone, email addresses) (identifiers);
  • sensitive personal data (social security information, nationality, date of birth, drivers’ license information, login information, credit card number, precise geolocation, racial or ethnic origin, the contents of email and text, as well as genetic data);
  • financial details (tax identification and bank account details) (“personal data” defined in the California Customer Records law); and
  • Any information that you voluntarily share with us such as feedback, opinions or information provided via any of our helplines.

For some of our services, we may also collect additionally:

  • personal data (pictures, electronic identification data such as cookies, IP addresses and passwords) (for further information please see the Cookie Policy (https://atslab.com/about-ats/cookie-policy/)) (collectively, internet and electronic network activity information);
  • professional and employment information (education and training) and other data set forth above gathered as part of an employee application;
  • any data gathered as part of a 3rd party conformity assessment/ audit;
  • device information such as IP address, referring website, ATS pages your device visited and the time that your device visited our website;
  • Internet log information and details, collected through our third parties such as Google Analytics, that does not specifically identify you; and
  • any other data which we process in the context of our business relationship as per the specific applicable contract terms or General Conditions.

Sources of Personal Data

  • You, personal data is collected directly from you when you interact with the Company.
  • Contractual parties that assist in providing our services or in execution of our contractual obligations with you or that manage, maintain, and protect our services and facilities.

The Company will always process the personal data for a specific purpose and will only process the personal data which is relevant to achieve that purpose. In particular, the Company will process personal data on the following legal basis and for the following purposes:

  1. For fulfillment of contractual obligations. Personal data is processed to provide our services in the context of carrying out our contracts with our Customers and for managing our business relationship with them and ensure the proper execution of services, for instance by handling Customer service related queries and issuing invoices or making payments. The purposes of data processing are primarily in compliance with the specific service. You can find other details about the purposes of data processing in the relevant contract documents and terms and conditions.
  2. In the context of legitimate interests. Where required and without unduly affecting Customers’ privacy interests or fundamental rights and freedoms, the Company may process the personal data beyond the actual fulfillment of the contract for the purposes of Company’s legitimate interests pursued directly by the Company or by a third party. These legitimate interests may include:
    • Performing our services;
    • Contacting Customers for direct marketing purposes about services Company think will be of interest to Customers, including those offered by ATS Group affiliates;
    • Helping the Company to learn more about its Customers, the products and services they receive, and other products and services they may be interested in receiving by conducting opinion research;
    • Assessing legal claims and defending in legal disputes;
    • Guaranteeing the Company‘s IT security infrastructure and environment; and
    • Risk management and compliance.
  3. As a result of your consent.
    As long as you have granted us consent to process the personal data for certain purposes (e.g., marketing purposes), this processing is legal on the basis of your consent. Your consent is always optional and can be withdrawn at any time.
  4. Due to legal obligations or in the public interest. Furthermore, we are subject to various legal obligations, i.e., regulatory and statutory requirements. Purposes of processing include fulfilling control and reporting obligations under fiscal laws or, in certain cases, due to accreditation and/ or certification mandatory requirements. Where the personal data we collect is needed to meet Company legal or regulatory obligations or enter into an agreement with you or is needed for legitimate purposes, if the Company cannot collect this personal data Company will be unable to engage you as a customer or provide its services and fulfill its contractual obligations (in which case Company will inform you accordingly).
  5. As part of job applicant and employee onboarding and retention. Sensitive personal data is collected for HR purposes.

4. Who Has Access to Personal Data and to Whom It Is Disclosed

Personal data may be disclosed:

  1. within the ATS Group to other ATS affiliates and parent companies in order to provide services to Customers, ensure a consistent standard of service across our group, and for any of the purposes set forth in Section 3. In the preceding 12 months, the following categories of personal data have been disclosed to the above parties and for the disclosed purposes:
    • contact information, sensitive personal data, financial details, voluntarily provided information, internet and electronic network activity information, professional and employment information, data gathered as part of a 3rd party conforming assessment/audit, device information, internet log information, and other data which we process in the context of our business relationship as per the specific applicable contract terms or general conditions;
  2. to contractual parties who need to carry out specific activities in relation to the personal data, according to the purposes of the processing, or to service providers who provide services to Company such as IT and hosting providers, marketing providers, debt collection providers, or sub-contractors. When we do so we take steps to ensure they meet our confidentiality and data security standards, so that your personal data remains secure. In the preceding 12 months, the following categories of personal data have been disclosed to the above parties and for the disclosed purposes:
    • contact information, sensitive personal data, financial details, voluntarily provided information, internet and electronic network activity information, professional and employment information, data gathered as part of a 3rd party conforming assessment/audit, device information, internet log information, and other data which we process in the context of our business relationship as per the specific applicable contract terms or general conditions;
  3. in other circumstances such as acquisitions and sale to third party companies when we envisage selling or transferring part or all of our business provided that all contract measures are taken to ensure they meet our security standards so that your personal data remains secure. In the preceding 12 months, the following categories of personal data have been disclosed to the above parties and for the disclosed purposes:
    • contact information, sensitive personal data, financial details, voluntarily provided information, internet and electronic network activity information, professional and employment information, data gathered as part of a 3rd party conforming assessment/audit, device information, internet log information, and other data which we process in the context of our business relationship as per the specific applicable contract terms or general conditions; and
  4. to government agencies, law enforcement authorities, or judicial bodies to comply with and enforce our legal rights and obligations, including regulatory reporting, to respond to requests from law enforcement or governmental authorities, or as part of a valid legal process. In the preceding 12 months, the following categories of personal data have been disclosed to the above parties and for the disclosed purposes:
    • contact information, sensitive personal data, financial details, voluntarily provided information, internet and electronic network activity information, professional and employment information, data gathered as part of a 3rd party conforming assessment/audit, device information, internet log information, and other data which we process in the context of our business relationship as per the specific applicable contract terms or general conditions.

We do not use or disclose your sensitive personal data for purposes other than those allowed under the CCPA.

5. International Transfer of Personal Data

ATS only transfers personal data outside of North America, including to Switzerland, and across other national boundaries within the ATS Group or outside the ATS Group when:

  1. it is justified for business purposes; and
  2. safeguards have been implemented to ensure that personal data will continue to be protected at a minimum with the same level of protection required in the jurisdiction of origin. To ensure this level of protection for your personal data, ATS may use a data transfer agreement with the third-party recipient based on standard contractual clauses approved by the European Commission or ensure that the transfer is to a jurisdiction that is the subject of an adequacy decision by the European Commission or to the US under the EU-US Data Privacy framework.

Any transfer of the personal data to international organizations and/or non-EEA countries will take place according to one of the methods permitted by current legislation.

6. How Personal Data Is Protected

The Company implements appropriate technical and organizational measures to protect personal data against unauthorized, accidental or unlawful destruction, loss, alteration, misuse, disclosure or access and against all other unlawful forms of processing.

These security measures have been implemented taking into account the state of the art of technology, their cost of implementation, the risks presented by the processing and the nature of the personal data, with particular care for sensitive personal data. In particular, adequate awareness, confidentiality undertakings and training are in place to ensure that personal data is not shared or disclosed to unauthorized persons.

7. How Long Personal Data Is Stored

Personal data will be stored on paper and/ or electronically for (i) only the time necessary for the purposes for which it was collected, respecting the principles of limitation of conservation and minimization; (ii) to comply with regulatory obligations, in compliance with the principles of necessity, minimization and adequacy; and (iii) after termination of the contractual relationship to fulfill regulatory and/or contractual and tax obligations or in case of legal claims. Subsequently, when the aforementioned reasons for the processing will cease, the personal data will be anonymized, deleted or destroyed.

8. Consumers’ Rights

Each consumer can exercise the following rights by sending a request in writing to the Company at the contact details in Section 1, to the extent permitted by law in the country where the consumer resides or is a national citizen of, as the case may be:

  • To access: you can obtain information relating to the processing of your personal data and a copy of such personal data.
  • To erase or delete: you can require the deletion of your personal data to the extent permitted by law. We may deny your deletion request to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
  • To object or to restrict: you can object to or request the restriction of the processing of your personal data on grounds relating to your particular situation. In cases of opposition to the processing of personal data the Company reserves the right to assess the application, which will not be accepted if there are legitimate reasons to proceed with the processing that prevail over your freedoms, interests and rights.
  • To rectify, update, or correct: where you consider that your personal data is inaccurate or incomplete, you can require that such personal data be modified accordingly and the Company will use commercially reasonable efforts to fulfill your correction request.
  • To withdraw your consent: where you have given your consent for the processing of your personal data, you have the right to withdraw your consent at any time.
  • To data portability or request an export: you have the right to have the personal data you have provided to us returned to you or, where technically feasible, transferred to a third party.
  • To know: you have the right to be informed if in the last 12 months the Company has disclosed, sold or shared your personal data to a third party.
  • To opt out: you may opt out of allowing the Company to sell your personal data by using ATS’s online privacy request form here and selecting the “Do not sell or share my personal information (California Residents)” option from the “type of query” drop down menu.
  • To opt in: you may change your mind and opt-in to personal data sales and cross-context behavioral advertising at any time by using ATS’s online privacy request form here.
  • To exercise: only you, or someone legally authorized to act on your behalf, may exercise your rights or make a request related to your personal data. You may only submit a request to know twice within a 12-month period. Your request to must provide sufficient information that allows us to reasonably verify you are the person about whom the Company collected personal data or an authorized representative and describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it. The Company will pass your deletion requests on to service providers, contractors with instructions to delete your personal data, and, unless impossible or involves disproportionate effort, to all third parties to whom we sold or shared the information. We cannot respond to your request or provide you with personal data if we cannot verify your identity or authority to make the request and confirm the personal data relates to you. The Company will only use personal data provided in the request to verify the requestor’s identity or authority to make it. You may make a request as described above in Section 1.

The Company is committed to keeping your personal data accurate and up to date. Therefore, if your personal data changes, please inform us of the change as soon as possible.

9. Response Timing and Format

We strive to maintain good customer relations and address requests to your satisfaction. If you are not satisfied with the Company’s answer or processing of your personal data, please contact us via the methods listed in Section 1 above. Should you not be satisfied with us or you believe that the processing of your personal data is contrary to the then-current legislation, you may have the right to lodge a complaint to a relevant authority.

We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please contact us as provided in Section 1.

The Company endeavors to substantively respond to a verifiable request within forty-five (45) days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing.

We will deliver our written response by mail or electronically, at your option.

Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal data that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

10. Anti-Discrimination

ATS will not discriminate against you for exercising any of your rights stated above. Specifically, in the event you exercise such rights, unless permitted by law, ATS will not:

  • Deny you goods or services.
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  • Provide you a different level or quality of goods or services.
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Privacy Notice Status and Update

This Privacy Notice was updated in July 2026. The Company reserves the right to amend it from time to time by publishing an updated version on Privacy Policy – Applied Technical Services. The new modified or amended privacy notice will apply from that revision date. Therefore, we encourage you to review this privacy notice periodically to be informed about how we are protecting your personal data.