- Changes to address new regulatory requirements resulting from the CCPA (California Consumer Privacy Act);
- Specifying in our Cookie Notice examples of cookies and similar technologies we use.
Schneider Electric strongly supports the fundamental rights to privacy and data protection as well as compliance with national and international privacy laws.
The data controllers of the data processing activities are the Schneider Electric subsidiaries who have determined the data processing means and purposes. They may vary on a case-by-case basis. In many instances, Schneider Electric Industries SAS, 35 rue Joseph Monier 92500 Rueil-Malmaison - France, Schneider Electric’s Head Office, is the data controller of global data processing activities. For information you can contact us at Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @]
Any order made by you online is also subject to the terms and conditions provided on the relevant sites. You must read them.4. Why do we collect and use personal information?
We use personal information for various purposes, including to fulfil orders and requests, to manage customer and prospect relationships, conduct surveys, improve our products, services, digital content as well as user journeys, manage user accounts and programmes, analyse activities on our digital platforms, run marketing activities, provide user with contextual and relevant information, ensure the security of our activities, protect against fraud, and, more generally, run our business activities.
Our primary goal in collecting information is to provide you with superior service and a smooth, efficient and personalised experience while using our digital content.
Schneider Electric collects personal information for the following purposes: 5. What type of personal information do we process?
- To fulfil orders of product, services and digital content. We collect this information to deliver your order, to obtain payment, to provide the functionalities of our applications, to communicate with you about the status of your order and for contract management purposes;
- To better address future requests for information and support. We keep record of exchanges including personal information to provide an optimised service on contacting us for support;
- For relationship management purposes which includes communicating about the products, services and digital content including email communications and messaging;
- To conduct surveys and polls. We may collect personal information to complete surveys and contact you for follow-up. We use this information to measure satisfaction, get to know our customers better and improve products, services and digital content;
- To improve our products, services and digital content; for instance, we analyse the use of our applications and websites in order to identify areas and functionalities where users have difficulties, and we improve them;
- To manage user digital accounts. We collect personal information at registration on our digital platforms (e.g. partner portal, ordering platform, mobile apps) to authenticate you, manage credentials to enable you to navigate through several digital platforms without having to re-authenticate (cf. single sign-on) and to interact with you;
- To run promotional programmes and activities: we collect personal information when you join a promotional or reward programme or activity. We use this information to administer the programme or activity, to send relevant e-mails about the programme and activity, notify winners, and make the winners' list publicly available in accordance with applicable regulations and laws;
- To send you marketing information by mail, fax, phone, text messages, email and electronic communications about promotions, news and new products or services that we think may be of interest to you in compliance with applicable opt-in and opt-out requirements. This can be conducted by Schneider Electric, its subsidiaries or selected third-parties acting on our behalf;
- To enable or administer our business, such as for quality control and consolidated reporting;
- To support corporate transactions or reorganisations in which Schneider Electric is involved;
- For business continuity and disaster recovery;
- To comply with legal obligations to which we are subject. For example, accounting and tax obligations;
- Any other purpose otherwise conveyed to you.
Schneider Electric processes various types of personal information including identity and contact related information, professional related information, information about preferences, interactions with us, financial related information, online traffic data and the content you provide to us. In most instances this information is obtained from customers, partners and users. We also purchase lists from marketing agencies and obtain information from our partners, through Cookies and social networks.
Personal information (also called personal data) is any information relating to an identified or identifiable individual. An identifiable individual is one who can be identified, directly or indirectly, in particular by reference to an identifier or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.
The types of personal information we process about you may include:
- Identity and contact related information, such as name, company, email address, phone number, photo, age range, contact addresses;
- Professional information, such as customer type, purchasing authority, purchasing timeframe; acquisition and use of Schneider Electric products, services and digital content;
- Information (e.g. energy consumption) which is specific to the digital platform you use
- Your preferences such as product and service preferences, contact preferences, marketing preferences;
- Your interactions with us such as queries, orders, claims, survey answers;
- Financial-related information such as bank account details, credit card information;
- Online traffic data such as IP address, device and system identifiers, your Schneider Electric user ID and password, referring website, type of browser used, consulted content, and location, based either on your IP address or on information transmitted by your mobile device;
- Content that you have provided via online forums or otherwise (see section 6 “Your content” below).
In most instances we collect personal information directly from users who have a business relationship with us. We may also obtain information through a reseller or a business partner, by purchasing customer lists from marketing agencies, from your online browsing experience, from social networks when you connect with these network’s credentials and through Cookies. You may obtain more precise information on the third-party source (if any) of personal information by contacting us at the email address indicated in section 10.6. Your content
You may choose to contribute content, including photos or comments, to online forums, applications or other digital platforms operated by Schneider Electric. Your content must be harmless. It must respect the law, the rights and interests of others. Need to have obtained consent before sharing someone else's data. You should apply caution before sharing information in a forum.
The content provided to us must respect the rights and interests of others, including their rights to protection of personal information and privacy. It should not be offensive, disrespectful or be harmful in any way.
Any provision of personal information to Schneider Electric about another individual must be compliant with privacy laws, including with notice and consent requirements for the disclosure of that information.
While Schneider Electric strives to protect your personal information, providing it online on shared forums is not risk-free. If you post, comment, indicate interest, or share personal information, including photographs, to any forum, social network or blog, please be aware that any personal information you submit can be read, viewed, collected, or used by other users of these forums, and could be used to contact you, send you unsolicited messages, or for purposes that neither you nor Schneider Electric have control over. Schneider Electric is not responsible for the personal information you choose to submit in these forums. You should apply caution before deciding to share information about yourself or another person.7. Who do we share personal information with?
We share personal information with the Schneider Electric subsidiaries and the service providers involved in our activities, with advertising and marketing agencies, with social networks if you use their login credentials, with third-party websites if you register with Schneider Electric credentials, competent regulatory bodies and authorities and business successors.
Schneider Electric is a global group of companies which works as one. To provide the best service to customers, prospects and users, personal data may be shared amongst personnel working for different entities. It may be the case, for example, for customer relationship management, sales or product support, marketing, product development purposes, improvement of the products, services and digital content, data quality checks, or security, finance, regulatory and compliance purposes.
We resort to service providers to carry out data processing activities and to provide our products, services and online content to you. These service providers include, without limitation, providers of hosting facilities, information systems, advertising and marketing agencies, IT support, security services, financial services, carriers who deliver products, outside accounting firms, lawyers and auditors.
We ensure all service providers working under contract for Schneider Electric are compliant with data privacy laws and aligned with Schneider Electric guidelines.
We also share the information as follows:
- In connection with the provision of advertising, we may share some limited personal information (e.g. device identifiers, Cookie identifiers) with ad exchanges or agencies that manage advertising on third-party websites and apps on which you may see advertising.
- Schneider Electric may disclose your personal information as necessary to potential buyers and successors in title, to facilitate a merger, consolidation, transfer of control or other corporate reorganisation in which Schneider Electric participates.
- Where required by law or court orders or to protect our legal rights, we will disclose your personal information to government agencies, regulators and competent authorities.
- Aggregated with other information, in such a way that your identity cannot reasonably be determined (for example, statistical compilations).
We will not sell or rent your personal information to a third party without your permission.8. How do we protect personal information?
Schneider Electric complies with widely recognised key data protection principles (fairness, purpose limitation, data quality, data retention, compliance with individuals’ rights, security) and takes reasonable measures for the security of personal information.
Schneider Electric respects the privacy rights and interests of individuals. Schneider Electric and its subsidiaries observe the following principles when processing personal information:
1. Processing personal information fairly and lawfully;
2. Collecting personal information for specified, legitimate purposes and not processing it further in ways incompatible with those purposes;
3. Collecting personal information which is relevant to and not excessive for the purposes for which it is collected and used. We may render information anonymous when feasible and appropriate, depending on the nature of the data and the risks associated with the intended uses;
4. Maintaining accurate personal information, and where necessary, keeping it up-to-date. We will take reasonable steps to rectify or delete information that is inaccurate or incomplete;
5. Keeping personal information only as long as it is necessary for the purposes for which it was collected and processed;
6. Processing personal information in accordance with individuals’ legal rights;
7. Taking appropriate technical, physical, and organisational measures to prevent unauthorised access, unlawful processing, and unauthorised or accidental loss, destruction, or damage to personal information;
8. When processing sensitive personal information, ensuring appropriate notice and consent or that the processing otherwise complies with applicable law;
Schneider Electric and all its subsidiaries must ensure that the above principles are complied with.
Schneider Electric and its subsidiaries are committed to taking commercially reasonable technical, physical, and organisational measures to protect personal information against unauthorised access, unlawful processing, accidental loss or damage, and unauthorised destruction. We offer the use of secure servers to enable you to place orders or to access your account information. We implement access control measures for our internal systems that hold personal information. Authorised users are given access to such systems through the use of a unique identifier and password. Access to personal information is provided to our staff for the sole purpose of performing their job duties. We sensitise our employees on proper use and handling of personal information. We also require our service providers to maintain compliant security measures. We implement security measures to determine the identity of registered users, so that appropriate rights and restrictions can be enforced for these users. In case of a registered user, we use both log ins and passwords for authentication. You are responsible for maintaining the security of your log-in credentials.
By using our digital content or providing personal information to us, you agree that we may communicate with you electronically or otherwise about related security, privacy, use and administrative activities. In spite of our efforts to implement appropriate security measures, online browsing carries inherent risks and we cannot guarantee that it is risk-free.9. Third-party websites and social media
We also provide social media links that enable you to share information with your social networks and to interact with Schneider Electric on various social media sites. The use of these links may result in the collection or sharing of information about you. We encourage you to review the privacy policies and the privacy settings of the social media sites with which you interact to make sure you understand the information that may be collected, used and shared by those sites and to adjust these settings as you see fit.10. What are your rights?
Schneider Electric will comply with your data protection rights, including your rights to request access to your personal information and to request that it be deleted or amended. You can always opt out of any direct marketing activity performed by Schneider Electric.
Schneider Electric will comply with your data protection rights, including your rights to access and correct your personal information. You may enquire about the nature of the personal information stored or processed about you by any Schneider Electric entity. You will be provided access to your personal information, regardless of the location of the data processing and storage.
You can request access to your personal information and request that it be deleted or amended at any time. To exercise your rights please click here or send an email to Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @].
You always have the right to opt out of our marketing communications. Your prior consent is sought, when required by any applicable law. To opt out of marketing emails, simply use the functionality provided at the bottom of any email we send.
Country-specific sections may supplement this section.11. Important information for individuals in the European Economic Area
Schneider Electric also complies with GDPR- specific requirements, including those relating to legal grounds for processing, cross-border data transfers, automated decision making and profiling, data retention, additional rights, claims and DPO contact details.
11.1 On what legal ground is Schneider Electric relying to use personal information?
The use of personal information is necessary, with respect to the purposes mentioned in section 3 above, to, respectively:
- Perform the contract entered into between Schneider Electric and you in the context of the use of our products, services or digital content. The performance of the contract includes knowing who you are, and your speciality and interacting with you for its performance. It includes as well addressing your requests for information, support, your job applications, managing your accounts and your enrolment into our programmes and ensuring compliance with terms and conditions and with this Privacy Statement.
- Comply with legal obligations to which we are subject. For instance, mandatory tax and accounting obligations or addressing filing obligations and requests by competent regulatory bodies and authorities.
- When it comes to:
o Surveys, some are carried out in our legitimate interest because they are to measure your satisfaction with services you requested from us. For other surveys we will request your consent. You will always be free to respond.
o Providing you with marketing communications and interest-based advertising, these activities carried out by us and by our subsidiaries are in our legitimate interests. We will always provide you a possibility to opt out and where required by applicable law we will seek your prior consent.
o Using location data transmitted by your mobile device, we will seek your prior consent, where required by applicable law.
We may also process your personal information for the purposes of our legitimate interests provided that such processing shall not outweigh your rights and freedoms, in particular to: 11.2 Will personal information be transferred abroad?
- Protect you, us or others from threats (such as security threats or fraud),
- Comply with the laws that are applicable to us around the world,
- Improve our products, services and digital content,
- Perform profiling to provide targeted content and interest-based advertising
- Share information between Schneider Electric subsidiaries and service providers as described in section 7,
- Understand and improve our online activities, our business, our customer basis and relationships generally.
- Enable or administer our business, such as for quality control and consolidated reporting
- Manage corporate transactions, such as mergers or acquisitions.
At Schneider Electric, a global company, the teams working on fulfilling the data processing purposes may have global or multi-country roles. They can then be located anywhere in the world where Schneider Electric operates, including outside the European Union, in countries which do not have equivalent standards for the protection of personal information as the country where you are located. We may also transfer data to service providers located outside of the EU, including in the United States of America. In the event that these data transfers cannot claim an adequacy decision by the European Commission, Schneider Electric will ensure that they comply with applicable legal requirements, for example by executing standard contractual clauses or through its Binding Corporate Rules for intragroup transfers as a data controller. To obtain more details on these transfers and, where appropriate, copies of the applicable safeguards implemented, you may contact: Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @]11.3 Do we use profiling and make automated decisions about individuals?
We may use profiling to provide you with online content which we believe corresponds to your interests. We combine registration information, such as work speciality and information about online activity to know you better, and provide you with online content corresponding to your profile.
We will not make automated-decisions about you that may significantly affect you, unless: 11.4 How long will personal information be retained?
- the decision is necessary as part of a contract;
- we have your explicit consent;
- or we are required by law to use the technology.
In these cases, due notice will be provided.
- The duration of our relationship (e.g. contract performance duration, account de-activation, your legitimate need to be recognised when contacted by us)
- Legal requirements for keeping data
- Statute of limitations
For marketing purposes, we keep relevant customer data for three years after the end of our relationship or since the last interaction with us.11.5 What are your additional rights?
In addition to the rights provided in section 10 above, you may ask us to erase, restrict or port your personal information and object to the use of your personal information. When data processing is based on individual consent, you have the right to withdraw your consent at any time by sending a request to the following email address: Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @] For processing necessary to perform the contract, or based on legitimate interest, we may not be able to accommodate the request to stop the processing, or if we do so, it may mean that you can no longer access the services or the digital content.11.6 Where to ask questions and file a claim?
DPO, 35 rue Joseph Monier CS30323, 92506 Rueil-Malmaison - France
Schneider Electric in the USA is providing this supplemental privacy notice to give California residents the additional information required by the California Consumer Privacy Act (the “CCPA”).
Schneider Electric is primarily focused on serving business and professional customers. We do collect a limited amount of consumer data from individuals who provide it to us via our online forms or by otherwise interacting with our websites or apps. We also receive consumer data in connection with our smart home products. This supplemental privacy notice explains how we comply with the CCPA for this information.12.1 CCPA Rights
The CCPA provides California residents with specific privacy rights, including the right to receive a privacy notice, the right to know what information we have collected about you during the past 12 months, and the right to know what categories of personal information we have shared with third parties. CCPA gives California residents the right to opt-out of having their personal information sold1. CCPA also gives California residents the right to request deletion of their personal information.
For information that Schneider Electric collects subject to the CCPA, this notice describes the categories of information that we collect from California residents generally, the purposes for which we use the information, and the categories of third parties to whom we disclose the information for business purposes. We may collect and share other categories of information with your consent.
Schneider Electric does not sell personal information. As described below, we may share personal information with our Affiliates2 and service providers. We may also disclose personal information to third parties for business purposes as permitted by CCPA, such as to our auditors, for compliance or security, or in connection with mergers and acquisitions.
We may also share personal information with third parties based on your consent, such as if you request a referral to a distributor or installer, enrol in a co-branded marketing programme or if you accept our use of third-party advertising cookies, as described in our Cookie Notice.12.2 How to Exercise Your Rights
If you are a California resident, you may exercise your rights or authorise another person to act on your behalf by:
• Clicking here: Your Privacy Choices
• Calling Schneider Electric at 800-789-3508
• Emailing us: Global-Data-Privacy@schneider-electric.com
Please note that we will need to verify your identity before we can fulfil your request. Because the information that we maintain subject to CCPA generally consists of marketing information, we will generally verify your identity using your email address. We will respond to requests using the email address that is associated with the information we maintain.
If you would like to designate an agent, please send an email from your own email address to Global-Data-Privacy@schneider-electric.com indicating the name and email address of your agent. We will respond to that person’s requests using both your email address and the agent’s email address.
Please understand that your rights are subject to some limitations. If you request that we delete your personal information, we will do so except in those situations where our retention is required for our internal business purposes, to finalise the ongoing business operations we have we you, to log your request or otherwise permitted by CCPA (such as for fraud prevention or legal compliance). In these situations, we will retain your information in accordance with our records retention programme and securely delete it at the end of the retention period.
Additionally, please note that many companies sell and install Schneider Electric products. We do not operate these companies, and we do not have any access to their databases. If you have registered with or purchased Schneider Electric products from another company, please contact that company directly to exercise your CCPA rights.12.3 Financial Incentives
Schneider Electric collects personal information in order to deliver offers and promotions and to enable loyalty programmes. While we cannot calculate the precise value of your information to us, our offers and incentives generally reflect the value of the relationships that we have with the individuals who participate in the programme.
We will not discriminate against you if you exercise your rights under CCPA. However, if you ask us to delete your information, you will not be able to receive additional offers or promotions. Any offers or promotions sent to you previously will continue to be honoured according to their original terms.12.4 CCPA Right to Know Disclosures