Controlled Thermal Resources Privacy Policy

Effective Date: October 13, 2023

Controlled Thermal Resources Holdings, Inc. (together with its relevant subsidiaries, associates, and affiliated companies, “we,” “our,” or “us”) respect your privacy and are committed to protecting your Personal Information. This Controlled Thermal Resources Privacy Policy (this “Policy”) applies to information collected through the websites that we operate and offline in our provision of products and services to business customers and does not cover any information collected by third parties (unless specifically stated).

In this Policy, we use the term “Personal Information” to refer to information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual, household or device. We are committed to protecting the privacy of those with whom we interact. This Policy contains details about how we collect, use, and share Personal Information that we obtain from and about you.  Please read this Policy carefully.

California residents may have certain rights under the California Consumer Privacy Act, including as amended by the California Privacy Rights Act (together, the “CCPA”), and other applicable US privacy laws, including regulations promulgated thereunder (collectively, “U.S. Privacy Laws”). If you are a resident of California, please see “Your Privacy Rights and How to Exercise Them” below for more specific information about your privacy rights.

Non-Applicability, Human Resources: This Policy does not apply to our job applicants, current employees, former employees, or independent contractors (“Personnel”), however, our California-based Personnel may obtain a separate privacy notice that applies to them by contacting our human resources department

  1. NOTICE OF DATA PRACTICES

The description of our data practices in this Policy covers the twelve (12) months prior to the above-referenced effective date and will be updated at least annually.

(a) What Personal Information Do We Collect and Disclose and How Long Do We Retain It?

We collect and disclose your Personal Information for a business purpose as described in the table below . We did not “sell” or “share” your Personal Information in the last 12 months.

 

The length of time for which we retain each category of Personal Information described above depends on the purposes for which we collected and use it and as required to comply with applicable laws. We keep your Personal Information for no longer than reasonably necessary to achieve the purposes for which it was collected or processed.  The criteria used to determine the period of time such Personal Information is retained includes the nature and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of the Personal Information, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).

(b) From What Sources Do We Collect Personal Information?

We use different sources and methods to collect Personal Information from and about you, including through:

· Direct interactions. You may give us Personal Information filling in forms or by corresponding with us by mail, phone, email or otherwise. This includes Personal Information you provide when you:

o inquire about, purchase or request support for our products or services;

o request marketing to be sent to you;

o connect with us via social media;

o participate in a promotion or survey; or

o give us feedback or contact us.

· Automated technologies or interactions. As you interact with our websites, we will automatically collect Personal Information about your equipment, browsing actions and patterns. We collect this Personal Information by using cookies and other similar technologies. We may use third party analytics services to provide us with a clearer picture of how you use our websites, including when you view specific pages or take specific actions on our websites.

· Affiliates, third parties or publicly available sources. We may receive Personal Information about you from our affiliates and various third parties, as set out below:

o from affiliated companies controlled by, controlling or under common control with us;

o from analytics providers;

o from data brokers, event sponsors (e.g., tradeshows) or aggregators; and

o from publicly available sources, such as government and administrative bodies.

(c) How Do We Use Personal Information?

We may use Personal Information for the following purposes:

· For our own internal business purposes, such as to evaluate or audit the usage, performance and safety of the Services; evaluate and improve the quality of the Services and design new products and services; operate our websites; internal research and analytics purposes; display or evaluate the effectiveness of our advertising or marketing efforts; evaluate and improve the quality of your interactions with us; catalog your responses to surveys or questionnaires; or maintain internal business records.

· For general marketingsuch as for contextual ad customization or to market our products and services. We may use Personal Information we collect to send you newsletters, surveys, questionnaires, promotions, or information about events. You can unsubscribe to our email marketing via the link in the email or by contacting us using one of the methods described in “Contact Information,” below.

· For direct marketing, such as sending you communications and information about our projects and investment opportunities that we consider may be of interest to you.  These communications may be sent in various forms, including mail, SMS, fax and email, in accordance with applicable marketing laws. 

· To communicate with you, such as to send communications you request, to answer inquiries, to update our records and keep your contact details up to date, and to process and respond to any complaint you may make.

(d) To Whom Do We Disclose Personal Information?

We may share your personal data with the parties set out below for the purposes described above.

· Affiliates. Corporate parents, subsidiaries, business units, and other companies that share common ownership with us.

· Service providers. Third parties acting as processors.

· who provide services to us, including providers of: (a) IT and system administration services (e.g., hosting); (b) marketing and advertising services; and (c) customer relationship management services.

· Professional advisers. Third parties acting as processors or joint controllers, including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.

· Parties to a corporate transaction. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Information with third parties in connection with such transaction. Any other entity which buys us or part of our business will have the right to continue to use your Personal Information, but only in the manner set out in this Policy unless you agree otherwise.

· Law enforcement and other government agencies. We may share information with third parties such as law enforcement or other government agencies to comply with law or legal requirements; to enforce or apply our website terms of use and other agreements; and to protect our, our users’, or third parties’ rights, data, property or safety.

(e) Children’s Privacy

We recognize the importance of children’s safety and privacy on the Internet. For this reason, we do not knowingly sell or share (as “share” is defined by the CCPA) any information, including Personal Information, from children under 16 years of age. If you think we may have unknowingly collected Personal Information of an individual under 16 years old, please contact us (See “Contact Information,” below).

    2. YOUR PRIVACY RIGHTS AND HOW TO EXERCISE THEM

As described more below, subject to meeting the requirements for a verifiable request and applicable limitations, California residents are entitled to the privacy rights described in this section.  If you are not a California resident, the rights describe below do not apply to you.

(a) Right to Access

You are entitled to access the Personal Information that we have collected about you up to twice in a 12-month period. Following our receipt of a verifiable request through one of the methods provided in the “Contact Information” section below, we will disclose to you the following:

· The categories of Personal Information we have collected about you;

· The categories of sources from which the Personal Information was collected;

· The business purpose behind collecting the Personal Information;

· The categories of third parties with whom we have shared the Personal Information; and

· The specific Personal Information we have collected about you.

(b) Right to Delete

Upon a verifiable request, made through one of the methods provided in the “Contact Information” section below, we will delete Personal Information we have collected from you and direct our service providers to delete your Personal Information from their records.  Note that you only have the right to request that we delete Personal Information that we have collected directly from you.

(c) Correct Your Personal Information

Upon a verifiable request, made through one of the methods provided in the “Contact Information” section below, we will correct inaccurate Personal Information that we maintain about you.  

(d) How to Exercise Your Privacy Rights

To submit a request to exercise your privacy rights, or to submit a request as an authorized agent, use our Privacy Rights Request Portal, or email us at info@cthermal.com and respond to any follow-up inquiries we make. Please be aware that we do not accept or process requests through other means (e.g., via fax, chats, social media etc.).  We will not discriminate against you for your exercise of your privacy rights.

(1) Your Request Must be a Verifiable Request

In order for you to exercise your privacy rights, we will need to obtain certain information from you to verify your identity.  For a report of the specific Personal Information we have collected about you, you must provide us with two of the following pieces of information in order for us to verify your identity:  

• full name;

• email address

You also must provide us with a signed declaration, under penalty of perjury, that you are who you say you are. 

For a report of the categories of Personal Information we have processed collected about you, for a request to delete your Personal Information, or for a request to correct your Personal Information, you must provide us with two of the above-referenced pieces of information in order for us to verify your identity. 

Where necessary, we may request additional information about you so that we can verify your identity. Where we did not already hold that information, we will use it only for the purpose of verifying your identity and to process your request.   

If we are unable to verify you sufficiently, we will be unable to honor your request. We will use Personal Information provided in a request to exercise your rights only to verify your identity or authority to make the request and to track and document request responses, unless you also gave it to us for another purpose.

(2) Agent Requests

You may use an authorized agent to exercise your privacy rights on your behalf.  Authorized agents may demonstrate that the agent has authority to exercise rights on the requesting consumer’s behalf by submitting supporting documentation to info@cthermal.com.  At a minimum, we will require evidence of the agent’s identity (via passport or driver’s license submission), and at least one of the following evidencing proof of your legal authority to act on the behalf of the individual who is the subject of this request:

  • Written authorization signed by the consumer; or

  • Certified copy of a Power of Attorney.

Whenever you interact with us on behalf of another individual or entity, such as by providing or accessing Personal Information about another individual, you represent that your interactions and exchanges comply with applicable laws. You shall have sole responsibility for any violation of applicable laws as a result of a failure to obtain any necessary consent from such individual.

(e) Our Responses

We will respond to requests to exercise your privacy rights described above within 45 calendar days, unless we need more time, in which case we will notify you and may take up to 90 calendar days total to respond to your request. 

We will make commercially reasonable efforts to identify Personal Information that we process to respond to your request(s).  We will typically not charge a fee to fully respond to your requests; provided, however, that we may charge a reasonable fee, or refuse to act upon a request, if your request is excessive, repetitive, unfounded, or overly burdensome.  If we determine that the request warrants a fee, or that we may refuse it, we will give you notice explaining why we made that decision. 

Consistent with applicable U.S. Privacy Laws and our interest in the security of your Personal Information, we will not deliver to you your Social Security number, driver’s license number, or other government-issued ID number, financial account number, any health or medical identification number, an account password, or security questions or answers in response to a privacy rights request.

3. ADDITIONAL INFORMATION FOR NEVADA RESIDENTS

Nevada residents have the right to instruct us not to “sell” “covered information” as those terms are defined by Chapter 603A of the Nevada Revised Statutes. Although we do not currently “sell” “covered information” of Nevada residents, as those terms are defined under that law, you may contact us at info@cthermal.com and provide your name, Nevada address, and email address to be verified and exercise your opt-out rights in the event we do sell covered information under that law in the future. If you change your email address or other contact information, contact us in the same manner to update your contact information to help facilitate your opt-out. Changing your contact information elsewhere (e.g., informational requests, etc.) will not update your Nevada opt-out information and we will only use the information provided to our opt-out program for managing opt-outs.  It is your responsibility to keep your opt-out information current. If after opting-out you direct us to share your covered information with others, we will do so regardless of your prior opt-out.

4. LINKS TO THIRD PARTY WEBSITES

Our website may contain links to other websites operated by third parties.  We make no representations or warranties in relation to the privacy practices of any third-party website and we are not responsible for the privacy policies or the content of any third-party website.  Third party websites are responsible for informing you about their own privacy practices.

5. CHANGES TO THIS POLICY

We regularly review this Policy. We reserve the right to alter, modify, update, add to, subtract from or otherwise change this Policy at any time. We will use your Personal Information in a manner consistent with the Policy in effect at the time we collected your Personal Information. You are responsible for periodically visiting our websites and this Policy to check for any changes.

6. CONTACT US

If you have any questions, comments, or concerns about our privacy practices, please contact us by e-mail at info@cthermal.com, or visit the Contact Us section of our website. Please note that e-mail communications will not necessarily be secure; accordingly, you should not include sensitive information in your e-mail correspondence with us.