- Changes to address new regulatory requirements resulting from the CCPA (California Consumer Privacy Act);
- Specifying in our Cookie Notice examples of cookies and similar technologies we use.
Schneider Electric strongly supports the fundamental rights to privacy and data protection as well as compliance with national and international privacy laws.
The data controllers of the data processing activities are the Schneider Electric subsidiaries who have determined the data processing means and purposes. They may vary on a case-by-case basis. In many instances, Schneider Electric Industries SAS, 35 rue Joseph Monier 92500 Rueil-Malmaison - France, Schneider Electric’s Head Office, is the data controller of global data processing activities. For information you can contact us at Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @]
Any order made by you online is also subject to the terms and conditions provided on the relevant sites. You must read them.4. Why do we collect and use personal information?
We use personal information for various purposes, including to fulfill orders and requests, to manage customer and prospect relationships, conduct surveys, improve our products, services, digital content as well as user journeys, manage user accounts and programs, analyze activities on our digital platforms, run marketing activities, provide user with contextual and relevant information, ensure the security of our activities, protect against fraud, and, more generally, run our business activities.
Our primary goal in collecting information is to provide you with superior service and a smooth, efficient and personalized experience while using our digital content.
Schneider Electric collects personal information for the following purposes:
- To fulfill orders of product, services and digital content. We collect this information to deliver your order, to obtain payment, to provide the functionalities of our applications, to communicate with you about the status of your order and for contract management purposes;
- To better address future requests for information and support. We keep record of exchanges including personal information to provide an optimized service on contacting us for support;
- For relationship management purposes which includes communicating about the products, services and digital content including email communications and messaging;
- To conduct surveys and polls. We may collect personal information to complete surveys and contact you for follow-up. We use this information to measure satisfaction, get to know our customers better and improve products, services and digital content;
- To improve our products, services and digital content; for instance, we analyze the use of our applications and websites in order to identify areas and functionalities where users have difficulties, and we improve them;
- To manage user digital accounts. We collect personal information at registration on our digital platforms (e.g. partner portal, ordering platform, mobile apps) to authenticate you, manage credentials to enable you to navigate through several digital platforms without having to re-authenticate (cf. single sign-on) and to interact with you;
- To run promotional programs and activities: we collect personal information when you join a promotional or reward program or activity. We use this information to administer the program or activity, to send relevant e-mails about the program and activity, notify winners, and make the winners' list publicly available in accordance with applicable regulations and laws;
- To send you marketing information by mail, fax, phone, text messages, email and electronic communications about promotions, news and new products or services that we think may be of interest to you in compliance with applicable opt-in and opt-out requirements. This can be conducted by Schneider Electric, its subsidiaries or selected third-parties acting on our behalf;
- To enable or administer our business, such as for quality control and consolidated reporting;
- To support corporate transactions or reorganizations in which Schneider Electric is involved;
- For business continuity and disaster recovery;
- To comply with legal obligations to which we are subject. For example, accounting and tax obligations;
- Any other purpose otherwise conveyed to you.
Schneider Electric processes various types of personal information including identity and contact related information, professional related information, information about preferences, interactions with us, financial related information, online traffic data and the content you provide to us. In most instances this information is obtained from customers, partners and users. We also purchase lists from marketing agencies and obtain information from our partners, through Cookies and social networks.
Personal information (also called personal data) is any information relating to an identified or identifiable individual. An identifiable individual is one who can be identified, directly or indirectly, in particular by reference to an identifier or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.
The types of personal information we process about you may include:
- Identity and contact related information, such as name, company, email address, phone number, photo, age range, contact addresses;
- Professional information, such as customer type, purchasing authority, purchasing timeframe; acquisition and use of Schneider Electric products, services and digital content;
- Information (e.g. energy consumption) which is specific to the digital platform you use
- Your preferences such as product and service preferences, contact preferences, marketing preferences;
- Your interactions with us such as queries, orders, claims, survey answers;
- Financial-related information such as bank account details, credit card information;
- Online traffic data such as IP address, device and system identifiers, your Schneider Electric user ID and password, referring website, type of browser used, consulted content, and location, based either on your IP address or on information transmitted by your mobile device;
- Content that you have provided via online forums or otherwise (see section 6 “Your content” below).
In most instances we collect personal information directly from users who have a business relationship with us. We may also obtain information through a reseller or a business partner, by purchasing customer lists from marketing agencies, from your online browsing experience, from social networks when you connect with these network’s credentials and through Cookies. You may obtain more precise information on the third-party source (if any) of personal information by contacting us at the email address indicated in section 10.6. Your content
You may choose to contribute content, including photos or comments, to online forums, applications or other digital platforms operated by Schneider Electric. Your content must be harmless. It must respect the law, the rights and interests of others. You need to have obtained consent before sharing someone else’s data. You should apply caution before sharing information in a forum.
The content provided to us must respect the rights and interests of others, including their rights to protection of personal information and privacy. It should not be offensive, disrespectful or be harmful in any way.
Any provision of personal information to Schneider Electric about another individual must be compliant with privacy laws, including with notice and consent requirements for the disclosure of that information.
While Schneider Electric strives to protect your personal information, providing it online on shared forums is not risk-free. If you post, comment, indicate interest, or share personal information, including photographs, to any forum, social network or blog, please be aware that any personal information you submit can be read, viewed, collected, or used by other users of these forums, and could be used to contact you, send you unsolicited messages, or for purposes that neither you nor Schneider Electric have control over. Schneider Electric is not responsible for the personal information you choose to submit in these forums. You should apply caution before deciding to share information about yourself or another person.7. Who do we share personal information with?
We share personal information with the Schneider Electric subsidiaries and the service providers involved in our activities, with advertising and marketing agencies, with social networks if you use their login credentials, with third-party websites if you register with Schneider Electric credentials, competent regulatory bodies and authorities and business successors.
Schneider Electric is a global group of companies which works as one. To provide the best service to customers, prospects and users, personal data may be shared amongst personnel working for different entities. It may be the case, for example, for customer relationship management, sales or product support, marketing, product development purposes, improvement of the products, services and digital content, data quality checks, or security, finance, regulatory and compliance purposes.
We resort to service providers to carry out data processing activities and to provide our products, services and online content to you. These service providers include, without limitation, providers of hosting facilities, information systems, advertising and marketing agencies, IT support, security services, financial services, carriers who deliver products, outside accounting firms, lawyers and auditors.
We ensure all service providers working under contract for Schneider Electric are compliant with data privacy laws and aligned with Schneider Electric guidelines.
We also share the information as follows:
- In connection with the provision of advertising, we may share some limited personal information (e.g. device identifiers, Cookie identifiers) with ad exchanges or agencies that manage advertising on third-party websites and apps on which you may see advertising.
- Schneider Electric may disclose your personal information as necessary to potential buyers and successors in title, to facilitate a merger, consolidation, transfer of control or other corporate reorganization in which Schneider Electric participates.
- Where required by law or court orders or to protect our legal rights, we will disclose your personal information to government agencies, regulators and competent authorities.
- Aggregated with other information, in such a way that your identity cannot reasonably be determined (for example, statistical compilations).
We will not sell or rent your personal information to a third party without your permission.8. How do we protect personal information?
Schneider Electric complies with widely recognized key data protection principles (fairness, purpose limitation, data quality, data retention, compliance with individuals’ rights, security) and takes reasonable measures for the security of personal information.
Schneider Electric respects the privacy rights and interests of individuals. Schneider Electric and its subsidiaries observe the following principles when processing personal information:
1. Processing personal information fairly and lawfully;
2. Collecting personal information for specified, legitimate purposes and not processing it further in ways incompatible with those purposes;
3. Collecting personal information which is relevant to and not excessive for the purposes for which it is collected and used. We may render information anonymous when feasible and appropriate, depending on the nature of the data and the risks associated with the intended uses;
4. Maintaining accurate personal information, and where necessary, kept up-to-date. We will take reasonable steps to rectify or delete information that is inaccurate or incomplete;
5. Keeping personal information only as long as it is necessary for the purposes for which it was collected and processed;
6. Processing personal information in accordance with individuals’ legal rights;
7. Taking appropriate technical, physical, and organizational measures to prevent unauthorized access, unlawful processing, and unauthorized or accidental loss, destruction, or damage to personal information;
8. When processing sensitive personal information, ensuring appropriate notice and consent or that the processing otherwise complies with applicable law;
Schneider Electric and all its subsidiaries must ensure that the above principles are complied with.
Schneider Electric and its subsidiaries are committed to taking commercially reasonable technical, physical, and organizational measures to protect personal information against unauthorized access, unlawful processing, accidental loss or damage, and unauthorized destruction. We offer the use of secure servers to enable you to place orders or to access your account information. We implement access control measures for our internal systems that hold personal information. Authorized users are given access to such systems through the use of a unique identifier and password. Access to personal information is provided to our staff for the sole purpose of performing their job duties. We sensitize our employees on proper use and handling of personal information. We also require our service providers to maintain compliant security measures. We implement security measures to determine the identity of registered users, so that appropriate rights and restrictions can be enforced for these users. In case of a registered user, we use both log ins and passwords for authentication. You are responsible for maintaining the security of your log-in credentials.
By using our digital content or providing personal information to us, you agree that we may communicate with you electronically or otherwise about related security, privacy, use and administrative activities. In spite of our efforts to implement appropriate security measures, online browsing carries inherent risks and we cannot guarantee that it is risk-free.9. Third-party websites and social media
We also provide social media links that enable you to share information with your social networks and to interact with Schneider Electric on various social media sites. The use of these links may result in the collection or sharing of information about you. We encourage you to review the privacy policies and the privacy settings of the social media sites with which you interact to make sure you understand the information that may be collected, used, and shared by those sites and to adjust these settings as you see fit.10. What are your rights?
Schneider Electric will comply with your data protection rights, including your rights to request access to your personal information and to request that it be deleted or amended. You can always opt out of any direct marketing activity performed by Schneider Electric.
Schneider Electric will comply with your data protection rights, including your rights to access and correct your personal information. You may inquire about the nature of the personal information stored or processed about you by any Schneider Electric entity. You will be provided access to your personal information, regardless of the location of the data processing and storage.
You can request access to your personal information and request that it be deleted or amended at any time. Individual Rights Requests can be sent to: Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @].
You always have the right to opt out of our marketing communications. Your prior consent is sought, when required by any applicable law. To opt out of marketing emails, simply use the functionality provided at the bottom of any email we send.
Country-specific sections may supplement this section.11. Important information for individuals in the European Economic Area
Schneider Electric also complies with GDPR- specific requirements, including those relating to legal grounds for processing, cross-border data transfers, automated decision making and profiling, data retention, additional rights, claims and DPO contact details.11.1 On what legal ground is Schneider Electric relying to use personal information?
The use of personal information is necessary, with respect to the purposes mentioned in section 3 above, to, respectively:- Perform the contract entered into between Schneider Electric and you in the context of the use of our products, services or digital content. The performance of the contract includes knowing who you are, and your specialty and interacting with you for its performance. It includes as well addressing your requests for information, support, your job applications, managing your accounts and your enrollment into our programs and ensuring compliance with terms and conditions and with this Privacy Statement.
- Comply with legal obligations to which we are subject. For instance, mandatory tax and accounting obligations or addressing filing obligations and requests by competent regulatory bodies and authorities.
- When it comes to:
o Surveys, some are carried out in our legitimate interest because they are to measure your satisfaction with services you requested from us. For other surveys we will request your consent. You will always be free not to respond.
o Providing you with marketing communications and interest-based advertising, these activities carried out by us and by our subsidiaries are in our legitimate interests. We will always provide you a possibility to opt out and where required by applicable law we will seek your prior consent.
o Using location data transmitted by your mobile device, we will seek your prior consent, where required by applicable law.
We may also process your personal information for the purposes of our legitimate interests provided that such processing shall not outweigh your rights and freedoms, in particular to:
- Protect you, us or others from threats (such as security threats or fraud),
- Comply with the laws that are applicable to us around the world,
- Improve our products, services and digital content,
- Perform profiling to provide targeted content and interest-based advertising
- Share information between Schneider Electric subsidiaries and service providers as described in section 7,
- Understand and improve our online activities, our business, our customer basis and relationships generally.
- Enable or administer our business, such as for quality control and consolidated reporting
- Manage corporate transactions, such as mergers or acquisitions.
At Schneider Electric, a global company, the teams working on fulfilling the data processing purposes may have global or multi-country roles. They can then be located anywhere in the world where Schneider Electric operates, including outside the European Union, in countries which do not have equivalent standards for the protection of personal information as the country where you are located. We may also transfer data to service providers located outside of the EU, including in the United States of America. In the event that these data transfers cannot claim an adequacy decision by the European Commission, Schneider Electric will ensure that they comply with applicable legal requirements, for example by executing standard contractual clauses or through its Binding Corporate Rules for intragroup transfers as a data controller. To obtain more details on these transfers and, where appropriate, copies of the applicable safeguards implemented, you may contact: Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @]11.3 Do we use profiling and make automated decisions about individuals?
We may use profiling to provide you with online content which we believe corresponds to your interests. We combine registration information, such as work specialty and information about online activity to know you better, and provide you with online content corresponding to your profile.
We will not make automated-decisions about you that may significantly affect you, unless:
- the decision is necessary as part of a contract;
- we have your explicit consent;
- or we are required by law to use the technology.
In these cases, due notice will be provided.
- The duration of our relationship (e.g. contract performance duration, account de-activation, your legitimate need to be recognized when contacted by us)
- Legal requirements for keeping data
- Statute of limitations
For marketing purposes, we keep relevant customer data for three years after the end of our relationship or since the last interaction with us.11.5 What are your additional rights?
In addition to the rights provided in section 10 above, you may ask us to erase, restrict or port your personal information and object to the use of your personal information. When data processing is based on individual consent, you have the right to withdraw your consent at any time by sending a request to the following email address: Global-Data-PrivacyATschneider-electric.com [Replace in the address AT by @] For processing necessary to perform the contract, or based on legitimate interest, we may not be able to accommodate the request to stop the processing, or if we do so, it may mean that you can no longer access the services or the digital content.11.6 Where to ask questions and file a claim?
DPO, 35 rue Joseph Monier CS30323, 92506 Rueil-Malmaison - France
Schneider Electric in the USA is providing this supplemental privacy notice to give California residents the additional information required by the California Consumer Privacy Act (the “CCPA”).
Schneider Electric is primarily focused on serving business and professional customers. We do collect a limited amount of consumer data from individuals who provide it to us via our online forms or by otherwise interacting with our websites or apps. We also receive consumer data in connection with our smart home products. This supplemental privacy notice explains how we comply with the CCPA for this information.12.1 CCPA Rights
The CCPA provides California residents with specific privacy rights, including the right to receive a privacy notice, the right to know what information we have collected about you during the past 12 months, and the right to know what categories of personal information we have shared with third parties. CCPA gives California residents the right to opt-out of having their personal information sold1. CCPA also gives California residents the right to request deletion of their personal information.
For information that Schneider Electric collects subject to the CCPA, this notice describes the categories of information that we collect from California residents generally, the purposes for which we use the information, and the categories of third parties to whom we disclose the information for business purposes. We may collect and share other categories of information with your consent.
Schneider Electric does not sell personal information. As described below, we may share personal information with our Affiliates2 and service providers. We may also disclose personal information to third parties for business purposes as permitted by CCPA, such as to our auditors, for compliance or security, or in connection with mergers and acquisitions.
We may also share personal information with third parties based on your consent, such as if you request a referral to a distributor or installer, enroll in a co-branded marketing program or if you accept our use of third-party advertising cookies, as described in our Cookie Notice.12.2 How to Exercise Your Rights
If you are a California resident, you may exercise your rights or authorize another person to act on your behalf by:
• Calling Schneider Electric at 800-789-3508
• Emailing us: Global-Data-Privacy@schneider-electric.com
Please note that we will need to verify your identity before we can fulfill your request. Because the information that we maintain subject to CCPA generally consists of marketing information, we will generally verify your identity using your email address. We will respond to requests using the email address that is associated with the information we maintain.
If you would like to designate an agent, please send an email from your own email address to Global-Data-Privacy@schneider-electric.com indicating the name and email address of your agent. We will respond to that person’s requests using both your email address and the agent’s email address.
Please understand that your rights are subject to some limitations. If you request that we delete your personal information, we will do so except in those situations where our retention is required for our internal business purposes, to finalize the ongoing business operations we have we you, to log your request or otherwise permitted by CCPA (such as for fraud prevention or legal compliance). In these situations, we will retain your information in accordance with our records retention program and securely delete it at the end of the retention period.
Additionally, please note that many companies sell and install Schneider Electric products. We do not operate these companies, and we do not have any access to their databases. If you have registered with or purchased Schneider Electric products from another company, please contact that company directly to exercise your CCPA rights.12.3 Financial Incentives
Schneider Electric collects personal information in order to deliver offers and promotions and to enable loyalty programs. While we cannot calculate the precise value of your information to us, our offers and incentives generally reflect the value of the relationships that we have with the individuals who participate in the program.
We will not discriminate against you if you exercise your rights under CCPA. However, if you ask us to delete your information, you will not be able to receive additional offers or promotions. Any offers or promotions sent to you previously will continue to be honored according to their original terms.12.4 CCPA Right to Know Disclosures
Category of Personal Information and Representative Data Elements>
Purpose for Collecting and Sharing the PI>
Categories of Third Parties to whom this type of Personal Information is Disclosed for a Business Purpose>
|Contact Information: Name; Username; Mailing address; Email address; Telephone number; Mobile number||We use this type of information to identify you and communicate with you, including: To send transactional messages (such as confirmations); To send marketing communications, surveys, and invitation; To personalize our communications and provide customer service, For our Everyday Business Purposes³||We may disclose this type of information to our Affiliates and to Service Providers, including to social media companies that use the data only to identify which of our customers use their platforms so that we can deliver ads to you on the platform. Third parties who deliver our communications, such as the postal service and couriers; Third parties who assist us with address hygiene and fulfillment; Other third parties as required by law|
|Relationship Information: Personal characteristics and preferences, such as your age range, marital and family status; Loyalty and rewards program data; Household demographic data, including census data; Data from social media profiles; Hobbies and interests||We use this type of information: To better understand you and to understand our customers generally; For product and service development and improvement; To identify prospective customers; For internal business purposes, such as quality control, training and analytics; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Third parties with whom we have joint marketing and similar arrangements; Our lawyers, auditors and consultants; Other third parties as required by law|
|Transaction and Interaction Information: Account information and related records; Records related to use of our websites and apps; Authentication data (passwords, account security questions); Customer service records; Visitor logs||We use this type of information: To fulfill our business relationship with you, including customer service; For recordkeeping and compliance, including dispute resolution; For internal business purposes, such as finance, quality control, training, reporting and analytics; For risk management, fraud prevention and similar purposes; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Third parties with whom we have joint marketing and similar arrangements; Third parties as needed to complete the transaction, including delivery companies, agents and manufacturers; Our lawyers, auditors and consultants Customers, in connection with their audits of Schneider Electric Other third parties as required by law|
|Inferred and Derived Information: Propensities, attributes and/or scores generated by internal analytics programs||We combine inferred data with other relationship information and use this type of information: To better understand you and to understand our customers generally; For product and service development and improvement; For internal business purposes, such as quality control, training and analytics; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Third parties with whom we have joint marketing arrangements; Our lawyers, auditors and consultants; Other third parties as required by law|
|Online & Technical Information: IP Address; Device identifiers and characteristics; Advertising ID; Web Server Logs; First Party Cookies; Third Party Cookies; Web beacons, clear gifs, pixel tags; Server log records; Activity log records||We use this type of information: For system administration, technology management, including optimizing our websites and applications; For information security and cybersecurity purposes, including detecting threats; For recordkeeping, including logs and records that maintained as part of Transaction Information; To better understand our customers and prospective customers and to enhance our Relationship Information, including by associating you with different devices and browsers that they may use; For online targeting and advertising purposes; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers including to companies such as Google that use the data collected by cookies and similar means to help us with our online advertising programs, and to: Third parties who assist with our information technology and security programs, including companies such as network security services who retain information on malware threats detected; Third parties who assist with fraud prevention, detection and mitigation; Third party network advertising partners; Our lawyers, auditors and consultants; Other third parties as required by law. We also disclose this information with your consent, if you explicitly allow us to place third party advertising cookies. To learn more and review your cookie settings, please read our Cookie Notice.|
|IoT and Sensor data: Commands, usage and other data collected, computed or produced by smart home products (such as home automation, energy management, safety and security, and electrical products) and their associated apps; Diagnostics data (such as context and description of detected errors); Geolocation data||We use this type of information: To enable product functionality; For internal business purposes, such product development, security, and quality control; For relationship purposes, including analytics regarding product usage; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Third parties who assist with our information technology and security programs, including network security services and cybersecurity consortia • Third parties who assist with fraud prevention, detection and mitigation; Third parties as needed to complete the transactions including third parties who provide products and services that you connect with ours; Third party network advertising partners; Our lawyers, auditors and consultants; Other third parties as required by law|
|Audio Visual Information: We collect this type of information from: Photographs; Video images; CCTV recordings; Call center recordings and call monitoring records Voicemails||We use this type of information: For internal business purposes, such as call recordings used for training, coaching or quality control; For relationship purposes, such as use of photos and videos for social media purposes; For premises security purposes and loss prevention; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Third parties who assist with our information technology and security programs, and our loss prevention programs; Our lawyers, auditors and consultants; Other third parties as required by law|
|Compliance data: We collect this type of information from: Compliance program data, such as records maintained to demonstrate compliance with applicable laws; Product safety data and other regulatory information; Records related to consumer preferences, such as your opt-ins and opt-outs of marketing programs; Records related to CCPA rights requests||We use this type of information: To comply with and demonstrate compliance with applicable laws; For legal matters, including litigation and regulatory matters, including for use in connection with civil, criminal, administrative, or arbitral proceedings, or before regulatory or self-regulatory bodies, including service of process, investigations in anticipation of litigation, execution or enforcement of judgments and orders; For internal business purposes, such as risk management, audit, internal investigations, reporting, and analytics; For our Everyday Business Purposes||We may disclose this type of information to our Affiliates and Service Providers and to: Our lawyers, auditors and consultants; Regulators, customers and other third parties, in connection with their audits of Schneider Electric; Other third parties (including government agencies, courts and opposing law firms, consultants, process servers and parties to litigation) in connection with legal matters|
2. Schneider Electric’s Affiliates are companies that are directly or indirectly controlled by Schneider Electric SE.
3. Everyday Business Purposes encompasses the Business Purposes (as defined in the CCPA) and following related purposes for which personal information may used:
• To provide the information, product or service requested by the individual or as reasonably expected given the context in which with the personal information was collected (such as customer credentialing, providing customer service, personalization and preference management, providing product updates, bug fixes or recalls, and dispute resolution);
• For identity and credential management, including identity verification and authentication, and system and technology administration;
• To protect the security and integrity of systems, networks, applications and data, including detecting, analyzing and resolving security threats, and collaborating with cybersecurity centers, consortia and law enforcement about imminent threats;
• For fraud detection and prevention;
• For legal and regulatory compliance, including all uses and disclosures of personal information that are required by law or reasonably needed for compliance with company policies and procedures, such as: anti-money laundering programs, security and incident response programs, intellectual property protection programs, and corporate ethics and compliance hotlines;
• For corporate audit, analysis and reporting;
• To enforce our contracts and to protect against injury, theft, legal liability, fraud or abuse, and to protect people or property, including physical security programs;
• To de-identify the data or create aggregated datasets, such as for consolidating reporting, research or analytics;
• To make back-up copies for business continuity and disaster recovery purposes; and
• For corporate governance, including mergers, acquisitions and divestitures.
Last update : 23/12/2019