Graco Inc.

Graco BlueLink™ App Data Protection Notice

Last Modified: June 1, 2019

  1. Introduction and Scope
  2. Data Controller
  3. Personal Data We Collect About You and How We Collect It
  4. How We Use Your Personal Data
  5. How We Share Your Personal Data
  6. International Transfers of Personal Data
  7. Data Retention
  8. Your Rights With Regard to Your Personal Data
  9. Data Security
  10. Third Party Content
  11. Children
  12. Revisions to our Data Protection Notice

I. INTRODUCTION AND SCOPE

Graco Inc. (“Graco”), its affiliates and subsidiaries (together “we”, “our”, or “us”) is committed to protecting your privacy. This notice (“Notice”) describes the data processing activities in connection with the use of our app (“BlueLink App” or “App”). Our App has been designed to assist Graco sprayer users with general job management, which includes sprayer performance and maintenance tracking. Our App can therefore be used by different user groups, namely company owners, their employees (both, owners and employees are referred to as “managers” in the App), distributors and repair centers. Consequently, this Notice addresses all groups in their capacity as App users. It describes the categories of personal data we process, the purposes for which personal data is collected, the parties with whom we share it and the security measures we take to protect the data. It also informs users about their rights and choices with respect to their personal data, and how they can contact us to inquire about our data protection practices. We encourage our App users to read this Notice carefully. This Notice may change from time to time, for more information about notice amendments see Section XII. below.

II. DATA CONTROLLER

For the purpose of this Notice

Graco Inc.
Attn: Legal-Privacy
88-11th Avenue Northeast
Minneapolis, MN 55413
USA

is responsible for the processing of your Personal Data as the data controller. You can contact us by emailing privacy@graco.com, calling either +1 612 379 3654 (US) or +32 (0) 89 770 960 (EU) or mailing:

Graco Inc.
Attn: Legal-Privacy
88-11th Avenue Northeast
Minneapolis, MN 55440-1441
USA

III. PERSONAL DATA WE COLLECT ABOUT YOU AND HOW WE COLLECT IT

Personal data means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (“Personal Data”). 

(1) Personal Data You Give to Us to Use the App. Our App offers you the possibility of creating a BlueLink Account (“BlueLink Account” or “Account”).  When using our App with a BlueLink Account, you provide us with basic Personal Data relating to you in order to identify your BlueLink. In this context, we collect information you provide to us which includes:

  • Account information consisting of first and last name, mobile phone number, and email address (“Account Information Personal Data”).

The use of certain features of our App, such as job-related information or past sprayer usage and performance, is subject to the creation of a BlueLink Account, which requires providing your Account Information Personal Data.  The obligatory Account Information Personal Data fields are visible if you fail to fill them out when creating your BlueLink Account.

Alternatively, you may use our App in a Guest mode without creating a BlueLink Account or providing Account Information Personal Data.  However, in Guest mode there is no associated BlueLink Account to store job-related information or Operational Data such as past sprayer usage and performance.

(2) Third Party Personal Data You Upload to Your BlueLink Account.  When using the App linked to a BlueLink Account, you have the ability to enter the Personal Data of third parties (“Third Party Personal Data”).   This Third Party Personal Data is not required by us, the App, or your BlueLink Account, and as such, you are responsible for providing the legal basis for storing such Third Party Personal Data.  In this context, such information includes:

  • Account information consisting of company-related information such as company name, address, managers and other users; information about managers and other users such as mobile phone number, first and last name, manager or user role; Graco distributor information such as mobile phone number, first and last name; job-related information such as the job location and users or managers on the job.

(3) Operational Data You Give to Us.  When using the BlueLink App with a BlueLink Account, we automatically collect certain information about you and your App usage, such as Operational Data related to the performance of your Graco Sprayer. More information about the categories of Operational Data and the ways in which we collect includes:

  • Account information consisting of sprayer-related information such as sprayer product name, nickname and serial number, operational data consisting of gallons sprayed, sprayer error codes, sprayer maintenance history; job-related information such as the job name as entered by the user, field report; and
  • User App preferences such as volume units, pressure units and language settings.

(4) Device Data We Automatically Collect. If you are a BlueLink Account holder, we automatically collect information about your use of the App, as well as information regarding the mobile device used. This information includes:

  • Device information: Data about your mobile device and internet connection, hardware and software, unique device identifier, operating system, language settings, wireless network and mobile network information including the network operator;
  • Usage Information: Your use of our App and your interactions with the App’s features, e.g. functionalities use, use frequency, etc.; and
  • Geolocation Information: Your precise location established using GPS, wireless networks, cell towers, Wi-Fi access points and other sensors when the App sends operational data. Please note that, in general, mobile devices allow you to switch off the disclosure of your geo-location through the privacy settings. You are responsible for determining if you wish to provide geolocation information to us from your mobile device through your BlueLink Account.  Please note that the App does not transmit any data to us when used in Guest mode without a BlueLink Account.

(5) Data from other sources. We may also obtain information from other sources. These include:

  • Other App users with a BlueLink Account who provide us with Personal Data about you when using our App, e.g., when a company owner enters data about his or her employees to add them as managers.

IV. HOW WE USE YOUR PERSONAL DATA

We will only process your Personal Data for specific, explicit and legitimate purposes. We will not process your Personal Data for any further purposes than the ones the data was originally intended for, unless the new purpose is compatible with the original one. In the absence of compatibility, the processing of data for further purposes is subject to your prior explicit consent.

We process the Personal Data you provide us with for the purposes listed below:

  • Provide you with the features, functionalities and services of our App, which include the remote management and tracking of jobs, tracking of sprayer performance and maintenance history, schedule maintenance reminders, receive alerts and notifications, enter notes and field reports, assign managers to jobs, assistance in maintaining jobsite material and equipment needs, etc.;
  • Verify your identity and attempt to prevent fraud or other unauthorized or illegal activity;
  • Communicate with you in connection with customer care; and
  • Enforce our Terms of Service and other usage policies.

The Personal Data we collect automatically includes statistical data that helps us improve our App’s features and functionalities in order to deliver a better service, including by enabling us to:

  • Observe and analyze the performance of our App to improve its features and functionalities according to our target groups preferences;
  • Determine user frequency and time between user visits; and
  • Prevent and detect misuse and malfunction of our App, including troubleshooting.

The processing of all the Personal Data we collect relating to you is either (i) based on your consent; (ii) necessary to provide you with our products and services at your request prior into entering into a contract with you or necessary for the performance of a contract to which you are party; or (iii) based on our legitimate interests in ensuring and improving the functionality of our App, unless these are overridden by your interests and rights.    

V. HOW WE SHARE YOUR PERSONAL DATA

Due to the international scope of our business, your Personal Data can be shared or accessed by Graco-affiliated entities within the company group. You can find more information on data transfers to affiliates based outside of the EU in Section VII. below.

Subject to applicable law and regulations, we share your Personal Data with:

  • Other BlueLink account holders with access to your BlueLink account (as is the case, for example, with owners having access to their employees’ manager accounts);
  • Public authorities, including law enforcement; and
  • Service providers acting on our behalf for the purposes listed above in Section IV. We require these service providers to only process Personal Data in accordance with our instructions and only as long as necessary to perform the requested services or in compliance with applicable law (e.g., app administration providers)

VI. INTERNATIONAL TRANSFERS OF PERSONAL DATA

International data transfers refer to transfers of Personal Data outside of the European Economic Area (“EEA”). Our App connects with servers located in the United States. Accordingly, depending on your country of residence, your Personal Data may be subject to international data transfers. These transfers are covered by an appropriate data protection safeguard consisting of the EU – U.S. Privacy Shield.

Graco is certified to adhere to the Privacy Shield Principles as laid down by the EU – U.S. Privacy Shield Framework as well as those pursuant to the Swiss – U.S. Privacy Shield Framework regarding the collection, use and retention of personal information transferred from the EU and Switzerland to the United States respectively. To learn more about the Privacy Shield program and to view our certification, please visit the Privacy Shield Framework website at https://www.privacyshield.gov/. A full list of covered entities can be found at https://www.privacyshield.gov/list.

To obtain more information about the implemented appropriate data protection safeguards please contact Graco’s Legal Department – Privacy Directory by emailing privacy@graco.com, calling either +1 612 379 3654 (US) or +32 (0) 89 770 860 (EU), or mailing

Graco Inc.
Attn: Legal-Privacy
88-11th Avenue Northeast
Minneapolis, MN 55413
USA

VII. DATA RETENTION

Retention periods vary depending on the categories of data concerned. As a general rule, we will not retain your Personal Data for longer than is allowed under the applicable data protection laws or for longer that is necessary in relation to the purposes for which it was originally collected or otherwise processed. Unless statutory retention periods apply, we will delete your Personal Data if you delete your BlueLink account. Sprayer-related operational data, however, will be anonymized and retained beyond that period for statistical purposes.

In the absence of statutory retention periods, alternatively after completion of those periods, we will erase your Personal Data. Further, we will erase your Personal Data where one of the following applies: (i) when you withdraw your consent (where lawfulness of processing was based on your consent) and there is no other legal ground for the processing; (ii) when you object to the processing and there are no overriding legitimate grounds for the processing; (iii) when your Personal Data has been unlawfully processed; and (iv) when it is necessary to comply with legal obligations.

VIII. YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA

You have certain rights regarding the Personal Data we maintain about you and certain choices about what Personal Data we collect from you, how we use it, and how we communicate with you.

  • The right to request access to and receive information about the Personal Data we maintain about you.
  • The right to rectification or erasure of your Personal Data.
  • The right to restriction of processing of your Personal Data.
  • The right to data portability in order to transfer your Personal Data easily to another company.
  • Where Personal Data processing is based on your consent, the right to withdraw your consent at any time. You can tell us not to send you any further marketing emails by clicking on the unsubscribe link within the marketing emails you receive from us or by contacting us as indicated below.
  • The right to lodge a complaint with a supervisory authority.
  • The right to object to processing concerning your Personal Data.

You can submit a request to exercise these rights at any time by contacting our DPC at privacy@graco.com, calling either +1 612 379 3654 (US) or +32 (0) 89 770 860 (EU), or mailing:

Graco Inc.
Attn: Legal-Privacy
88-11th Avenue Northeast
Minneapolis, MN 55413
USA

For the avoidance of doubt, you must collect and retain any Operational Data ­– including sprayer data (i.e., non-Personal Data) – from your Account that you want transferred to a third party or retained beyond the life of your BlueLink Account.  Graco will not (1.) transfer Operational Data to any third party, except those third parties that provide the services for your BlueLink Account or BlueLink App (e.g., the cloud data provider for your BlueLink Account); or (2.) retain non-anonymized Operational Data beyond the life of your BlueLink Account.  Further, as related to the right of data portability, we will only transfer your Personal Data and not the Third Party Personal Data that you have collected in your BlueLink Account. You must collect and retain any Third Party Personal Data from your Account that you want transferred to a third party or retained beyond the life of your BlueLink Account.

IX. DATA SECURITY

The security of your Personal Data is important to Graco and we are committed to protection the data we collect. We maintain administrative, technical and physical safeguards designed to protect the Personal Data you provide or we process against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. We use SSL encryption for our App from which we transfer certain Personal Data.

X. THIRD PARTY CONTENT

Our App may contain links to third party websites. The links are provided exclusively for your convenience. Please be aware that this Notice does not apply to those third party websites nor do we have control over the content of linked third party websites. We encourage you to read the data protection policies and terms and conditions of linked or referenced website you enter.

XI. CHILDREN

Our App is not intended for children and we have no intention of collecting Personal Data from individuals under eighteen years of age. If a child has provided us with Personal Data, a parent or a guardian of that child may contact us to request to have such information deleted emailing privacy@graco.com, calling either +1 612 379 3654 (US) or +32 (0) 89 770 860 (EU), or mailing

Graco Inc.
Attn: Legal-Privacy
88-11th Avenue Northeast
Minneapolis, MN 55413
USA

XII. REVISIONS TO OUR DATA PROTECTION NOTICE

We reserve the right to amend this Notice from time to time consistent with applicable data protection laws and regulations. Any changes to this Notice will be posted on this page. If we make material changes to how we treat your Personal Data, we will notify you through an alert or a message via the App. The date this notice was last revised is identified at the top of the page.