EU-US and Swiss-US Privacy Shield Policy

This Privacy Shield Policy (“Policy”) describes G. H. Smart & Company, Inc.’s (“ghSMART,” “we,” or “us”), collection, use, and disclosures of certain personally identifiable information that we receive in the US from the European Union (“EU Personal Data”) and Switzerland (“Swiss Personal Data”). This Policy applies to the following US affiliated entities: G. H. Smart & Company, Inc. and ghSMART UK Limited.

GhSMART recognizes that the EU and Switzerland have established certain protections regarding the handling of EU Personal Data and Swiss Personal Data, including requirements to provide adequate protection for EU Personal Data transferred outside of the EU, and Swiss Personal Data transferred outside of Switzerland. To provide adequate protection for all EU Personal Data and Swiss Personal Data about corporate clients, suppliers, employees, and business partners received in the US, ghSMART has elected to self-certify to the EU-US Privacy Shield Framework and Swiss-US Privacy Shield Framework, collectively administered by the US Department of Commerce (collectively, “Privacy Shield”). GhSMART has an affirmative commitment to comply with the Privacy Shield Framework, and it adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement, and Liability.

For purposes of enforcing compliance with the Privacy Shield, GhSMART is subject to the investigatory and enforcement authority of the US Federal Trade Commission. For more information about the Privacy Shield, see the US Department of Commerce’s Privacy Shield website located at: https://www.privacyshield.gov. To review GhSMART’s representation on the Privacy Shield list, see the US Department of Commerce’s Privacy Shield self-certification list located at: https://www.privacyshield.gov/list.

Personal Data Collection and Use, Including Data Transfers Received From Third Parties

GhSMART will only access and use EU Personal Data and Swiss Personal Data in ways that are compatible with the purposes for which GhSMART, or its contractual third parties, collected it, or for purposes the individual later authorizes.

GhSMART collects EU and/or Swiss personal data from contractors, vendors, clients, business partners, employment candidates and individuals associated with fulfilling the contractual obligations of our client agreements. The information we collect varies based on the underlying purpose of the data collected. The specific types of information we collect may include: Name, personal contact details [telephone, email, address], prior employment history, employment dates, name of employer, location of employment, tenure, job title, performance appraisals/assessment, salary & benefits, education and training history [institutions, qualifications, grades and courses attended], standardized test scores, other details of qualifications, professional memberships/organizations, emails, meeting notes, expressions of opinion or future intentions, assessment of strengths and weaknesses, and other professional or personal information voluntarily provided during an assessment process.

Purposes of EU and/or Swiss Personal Data Collection and Use

    • Fulfilling the deliverables of our client agreements as part of our consulting services which may include assessments, leadership development, coaching, training and any related services or products.
    • Assessing the suitability of candidates for a role.
    • Providing products, services and support to our clients.
    • Providing information about our products, services and events to prospective clients or candidates for employment.
    • Administrative purposes relating to processing transactions with our clients.
    • Facilitating ghSMART’s internal administrative purposes including accounting, audit, tax, legal, regulatory, compliance, vendor management and complying with policies and procedures.
    • Analysis and research of data in order to provide training to our consultants and to improve our consulting business practices and products core activities.
    • Analysis and research where aggregated and deidentified data may be used in publications.
    • Evaluating the quality of our products and services.
    • Other purposes disclosed at the time of collection.
    • Compliance with legal requirements.

ghSMART will only process EU and/or Swiss Personal Data in ways that are compatible with the purpose for which ghSMART collected the EU and/or Swiss Personal Data, or for purposes that the individual or entity providing the EU and/or Swiss Personal Data later authorizes. Before we use your EU and/or Swiss Personal Data for a purpose that is materially different than the purpose for which it was collected or that you later authorized, we will provide you with the opportunity to opt out. ghSMART maintains reasonable procedures to help ensure that EU and/or Swiss Personal Data is reliable for its intended use, accurate, complete, and current.

Data Transfers to Third Parties

Third-Party Agents or Service Providers. We do transfer EU Personal Data or Swiss Personal Data to certain third-party agents or service providers that perform services on our behalf with whom we have entered written agreements and which agreements addresses data privacy and security policies and procedures that requires all contractual parties to ensure that your EU Personal Data or Swiss Personal Data is protected with the same level of protection the Privacy Shield requires. We also may transfer your EU Personal Data or Swiss Personal Data to other ghSMART entities within our organization such as a subsidiary or branch, when we have taken steps to ensure that your EU Personal Data or Swiss Personal Data is protected with the same level of protection the Privacy Shield requires. Under certain circumstances, we may remain liable for the acts of our third party agents or service providers that perform services on our behalf for their handling of EU and/or Swiss Personal Data that we transfer to them.

Disclosures for National Security or Law Enforcement. Under certain circumstances, we may be required to disclose your EU Personal Data or Swiss Personal Data in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

Security
GhSMART maintains reasonable and appropriate security measures to protect EU Personal Data and Swiss Personal Data from loss, misuse, unauthorized access, disclosure, alteration, or destruction in accordance with the Privacy Shield principles.

Access Rights
You may have the right to access the EU Personal Data or Swiss Personal Data that we hold about you and to request that we correct, amend, or delete it if it is inaccurate or processed in violation of the Privacy Shield. These access rights may not apply in some cases, including where providing access is unreasonably burdensome or expensive under the circumstances or where it would violate the rights of someone other than the individual requesting access. If you would like to request access to, correction, amendment, or deletion of your EU Personal Data or Swiss Personal Data, you can submit a written request to the contact information provided below. We may request specific information from you to confirm your identity.

E.U. and Swiss individuals whose personal data we process on behalf of a ghSMART customer (as a data processor) should first contact the customer, who is the controller of your personal data, to access, amend, or delete their personal data. We will work with our customers to provide individuals the necessary access about what personal data is processed.

Dispute Resolution

In compliance with the Privacy Shield Principles, ghSMART commits to resolve complaints about your privacy and our collection or use of your Personal Data.

You can direct any questions or complaints about the use or disclosure of your EU Personal Data or Swiss Personal Data to us at: privacy@ghSMART.com

We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of your EU Personal Data or Swiss Personal Data within 45 days of receiving your complaint. ghSMART has further committed to refer unresolved privacy complaints under the EU-US Privacy Shield Principles and the Swiss-US Privacy Shield Principles to JAMS EU PRIVACY SHIELD, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit JAMS here. The services of JAMS are provided at no cost to you.

Under certain limited conditions, individuals may invoke arbitration before the Privacy Shield Panel to be created by the U.S. Department of Commerce and the European Commission.

If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.

Changes To This Policy

It is our policy to post any changes we make to our Privacy Shield Policy on this website. Please visit our website and this Privacy Shield Policy to check for any changes.

For any questions regarding this policy, please contact privacy@ghSMART.com.