Updated July 16, 2026
Surgical Specialty Hospital of Arizona, LLC dba The CORE Institute Specialty Hospital, a HOPCo managed hospital (“CISH”,” “we,” “us,” or “our”) recognizes the importance of protecting the privacy of your personal information, and we have prepared this Privacy Policy to provide you with important information about the privacy practices applicable to the CISH websites, including any website that links to or refers to this Privacy Policy (collectively, the “Sites”). This Policy does not address personal information collected through other means.
Our Key Privacy Commitments
We are committed to protecting your personal information and Protected Health Information (PHI). To support this, we make the following commitments:
We only collect personal information and PHI as necessary to provide and improve our services.
We use PHI only as permitted by HIPAA, HITECH, applicable state privacy laws, and our Business Associate Agreements (BAAs).
We do not use PHI for advertising, marketing, or sales-based analytics.
We do not sell your personal information or PHI, and we do not “share” PHI for cross-context behavioral advertising You can request access, correction, or deletion of your data at any time where permitted by law.
We apply industry-standard security measures, including encryption, access controls, continuous monitoring, and third-party security testing.
HIPAA Notice of Privacy Practices (NPP)
- If you use our Sites as part of a healthcare service provided by a HIPAA Covered Entity, you may also receive a separate Notice of Privacy Practices (NPP) from that provider. The NPP describes how your PHI may be used and disclosed and how you can access your PHI. This Privacy Policy supplements but does not replace any HIPAA NPP issued by your provider.
Information We Collect though the sites
We may collect the following kinds of information when you use the Sites:
Information you provide directly to us. For certain activities, such as when you use our Sites, subscribe to our alerts, or contact us directly such as through completing our “Contact Us” form, we may collect some or all of the following types of information:
Contact information, such as your full name, email address, mobile phone number, and address;
Other identifying information;
Username and password;
Your location;
Personal health information, including information about your health condition, previous treatments, general health, and health insurance; and
Any other information you provide to us.
If you are applying for employment through our website, please see our US Recruiting Privacy Policy
We may combine such information with information we already have about you.
Information we collect automatically. We may collect certain information automatically when you use our Sites, such as your Internet protocol (IP) address, device and advertising identifiers, browser type, operating system, Internet service provider, pages that you visit before and after using the Sites, the date and time of your visit, information about the links you click and pages you view within the Sites, and other standard server log information. We may also automatically collect technical information (such as time zone setting and location, and other technology on the devices) used to access the Sites. We may also use other automatic technologies such as web server logs, pixels and web beacons. We may also collect certain location information when you use our Sites, such as your mobile device’s GPS signal, or information about nearby Wi-Fi access points and cell towers.
We may also receive information about you from other sources, including through third-party services and organizations. We may combine our first-party data, such as your email address or name, with third-party data from other sources and use this to contact you (e.g. through direct mail). For example, if you access third-party services, such as Facebook, Google, or Twitter, through the Sites to log into the Sites or to share information about your experience on the Sites with others, we may collect information from these third-party services.
SMS / MMS PRIVACY NOTICE
We use SMS messaging to send important service-related communications, such as appointment or treatment reminders and other care-related messages. These messages are delivered through trusted third-party providers who act as data processors on our behalf.
No sale or rental of data — we never sell or rent your information, and we do not share it with third parties for advertising or marketing.
Security — messages travel over TLS 1.2 and are stored with AES-256 encryption; our providers apply strong safeguards and are ISO 27001 certified. Where required, service providers are bound by a HIPAA Business Associate Agreement.
Message frequency — up to 5 texts per appointment (typically: scheduling, confirmation, pre-visit forms (if needed), reminder and a post-visit follow-up message); msg & data rates may apply.
Opt-out / help — reply STOP at any time to end texts, HELP for help, or email privacy@hopco.com with questions.
All SMS communications are handled in accordance with applicable privacy and data protection laws, including the Telephone Consumer Protection Act (TCPA).
No mobile Opt-in Data will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
How We Use Your Information
We generally use the information we collect online to:
Provide and improve the Sites;
Contact you, including contact you in connection with our Services and appointments, events or offerings that you may have registered for; identify and authenticate your access to the parts of our Portal or other password-protected Services that you are authorized to access; to send you surveys; for recruiting and human resources administration purposes; to protect our rights or our property and to ensure the technical functionality and security of our Services; and as required to meet our legal and regulatory obligations;
Fulfill your requests for services and information;
Send you information about us or on behalf of our affiliates and trusted third-party partners, provided that we will not, without your express opt-in permission, use your personal information to send you general marketing emails from our Company and/or on behalf of third parties;
Analyze the use of the Sites and user data to understand and improve the Sites;
Customize the content you see when you use the Sites;
Prevent potentially prohibited or illegal activities;
To protect our rights and the rights of other users;
For any other purposes disclosed to you at the time we collect your information or pursuant to your consent.
HOW WE SHARE YOUR INFORMATION
We are committed to maintaining your trust, and we want you to understand when and with whom we may share the information we collect.
Authorized third-party vendors and service providers. We may share your information with third-party vendors and service-providers that help us with specialized services, including billing, payment processing, customer service, email deployment, business analytics, marketing (including but not limited to advertising, attribution, deep-linking, direct-mail, mobile marketing, optimization and retargeting), performance monitoring, hosting, and data processing. These third-party vendors and service providers may not use your information for purposes other than those related to the services they are providing to us.
Corporate affiliates. We may share your information with our corporate affiliates that are subject to this policy.
Business transfers. We may share your information in connection with a substantial corporate transaction, such as the sale of the Sites or CISH, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy.
Legal purposes. We may disclose information to respond to subpoenas, court orders, legal process, law enforcement requests, legal claims or government inquiries, and to protect and defend the rights, interests, health, safety, and security of CISH, our affiliates, users, or the public. If we are legally compelled to disclose information about you to a third party, we will attempt to notify you by sending an email to the email address in our records unless doing so would violate the law or unless you have not provided your email address to us.
With your consent or at your direction. We may share information for any other purposes disclosed to you at the time we collect the information or pursuant to your consent or direction.
De-identified Data. We create and use de-identified and/or aggregated data about our users (for example, statistical or demographic data) to help us and our partners evaluate and improve treatments, devices, digital health tools, and patient safety. Once data has been de-identified in accordance with applicable standards, it is no longer considered Personal Information or PHI.
We may license or share HIPAA-de-identified data (as defined under 45 CFR §164.514(b)), which is no longer Personal Information or PHI. Such data may be used for research, analytics, scientific study, or to support development of technologies that improve patient care.
If you access third-party services, such as Facebook, Google, or Twitter, through the Sites to login to the Sites or to share information about your experience on the Sites with others, these third-party services may be able to collect information about you, including information about your activity on the Site, and they may notify your connections on the third-party services about your use of the Site, in accordance with their own privacy policies. Information you submit may be received, maintained, or transmitted on our systems or those of contractors, third parties, or affiliates, including offshore or overseas locations.
NOTE: The Sites are intended for use in the United States only by users over the age of 18. If you access this Sites from outside the United States, if you choose to provide Personal Information, you do so on your own initiative and at your own risk and are responsible for compliance with all applicable laws and regulations.
USER COMMUNICATIONS
Email communications that you send to us via the email links on our Services may be shared with a customer service representative, employee, medical expert or agent that is most able to address your inquiry. We make reasonable efforts to respond in a timely fashion once communications are received. Once we have responded to your communication, it is discarded or archived, depending on the nature of the inquiry and all applicable laws, rules and regulations.
SECURITY
The security of your personal information is important to us. We implement administrative, technical, and physical safeguards consistent with HIPAA and industry standards. However, no security safeguards are 100% secure and we cannot guarantee the security of your information.
Additional Security Measures
In addition to the safeguards described above, we implement:
Strict data-minimization practices, accessing only the information necessary for the specific purpose;
Encryption of Personal Information and PHI in transit (TLS 1.2/1.3) and at rest;
Role-based access controls ensuring only authorized personnel may access PHI;
Audit logs and continuous monitoring of PHI access;
Regular penetration testing and vulnerability scanning by accredited security firms;
Segregated production, development, and analytics environments with technical safeguards preventing PHI exposure;
Contractual and technical controls ensuring that third-party processors may not use PHI for any purpose other than delivering the contracted service; and
A documented incident-response and breach-notification procedure compliant with HIPAA and HITECH.
How Long We Keep Your Information
We will keep your information for as long as reasonably necessary for the purposes described in this Privacy Policy, while we have a legitimate business need to do so, or as required by law (e.g. for regulatory reporting including to government entities who may oversee the safety and efficacy of research, legal, tax, accounting or other purposes), whichever is longer.
To determine the appropriate retention period for your information, we will consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of your information, the purposes for which we use your information, and whether we can achieve those purposes through other means, and the applicable legal requirements.
YOUR CHOICES
You may request that we update or delete your personal information by sending us an email at privacy@hopco.com. We will use commercially reasonable efforts to correct or delete your information. Please see “Your Rights” below for more about your data rights.
Deletion Requests
You may request deletion of your personal information by contacting privacy@hopco.com. Deletion will occur except where we are legally required to retain information, including:
PHI retained under HIPAA retention rules;
Medical record retention laws in the state where you reside;
Contractual obligations under a Business Associate Agreement; and
Legal, regulatory, or audit-related retention requirements.
If we hold PHI on behalf of a Covered Entity, we will notify the Covered Entity, which will determine how the request is fulfilled in accordance with HIPAA and the applicable BAA.
Opt-out of Communications:
You may opt out of communications or marketing-related emails by clicking the “Unsubscribe” link at the bottom of each such email. You may continue to receive service-related and other non-marketing communications by following the instructions in a particular communication (such as a text message) or by sending an email with your communication preferences to privacy@hopco.com.
Disabling Cookies:
You may be able to refuse or disable cookies by adjusting your web browser settings. Because each web browser is different, please consult the instructions provided by your web browser (typically in the “help” section). Please note that you may need to take additional steps to refuse or disable local shared objects and similar technologies. For example, local shared objects can be controlled through the instructions on Adobe’s Setting Manager page. If you choose to refuse, disable, or delete these technologies, some of the functionality of the Sites may no longer be available to you.
Do Not Track Signals
Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. Our Sites currently do not respond to “Do Not Track” (DNT) signals and operates as described in this Privacy Policy whether or not a DNT signal is received. If we do respond to DNT signals in the future, we will update this Privacy Policy to describe how we do so. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
YOUR RIGHTS
Your local laws may permit you to request that we:
Provide access to and/or a copy of certain information we hold about you;
Prevent the processing of your information for direct-marketing purposes (including any direct marketing processing based on profiling);
Update or rectify information which is out of date or incorrect;
Delete certain information which we are holding about you;
Oppose, cancel, or restrict the way that we process and disclose certain information;
Transfer your information to a third-party provider of services;
Revoke your consent for the processing of your information.
We will consider all requests and provide our response within the time period stated by applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests, to comply with a legal obligation. We may request you provide us with information necessary to confirm your identity before responding to your request as required or permitted by applicable law. If you would like further information in relation to your legal rights under applicable law, or would like to exercise those rights, please email us at privacy@hopco.com. Please be sure to include your name, address (including the state where you reside), and email address so we can respond to your request in the time frame required under your state’s laws.
We will not discriminate against you for exercising any of your rights described in this Privacy Policy.
THIRD-PARTY ADVERTISING, LINKS, AND CONTENT
The advertising technologies described in this section are used only as stated above: on non-clinical pages, only after opt-in consent, and never on PHI or PHI-adjacent pages.
Subject to those limits:
Some of the Sites may contain links to content maintained by third parties that we do not control. We allow third parties, including business partners, advertising networks, and other advertising service providers, to collect information about your online activities through cookies, pixels, local storage, and other technologies. These third parties may use this information to display advertisements on our Sites and elsewhere online tailored to your interests, preferences, and characteristics. We are not responsible for the privacy practices of these third parties, and the information practices of these third parties are not covered by this Privacy Policy.
Some third parties collect information about users of our Sites to provide interest-based advertising on our Sites and elsewhere, including across browsers and devices. These third parties may use the information they collect on our Sites to make predictions about your interests in order to provide you ads (from us and other companies) across the internet. Some of these third parties may participate in an industry organization that gives users the opportunity to opt out of receiving ads that are tailored based on your online activities. Due to differences between using apps and websites on mobile devices, you may need to take additional steps to disable targeted ad technologies in mobile apps.
Many mobile devices allow you to opt out of targeted advertising for mobile apps using the settings within the mobile app or your mobile device. For more information, please check your mobile settings. You also may uninstall our apps using the standard uninstall process available on your mobile device or app marketplace.
To opt out of interest-based advertising across browsers and devices from companies that participate in the Digital Advertising Alliance or Network Advertising Initiative opt-out programs, please visit their respective websites. You may also be able to opt out of interest-based advertising through the settings within the mobile app or your mobile device, but your opt-out choice may apply only to the browser or device you are using when you opt out, so you should opt out on each of your browsers and devices if you want to disable all cross-device linking for interest-based advertising. If you opt out, you will still receive ads, but they may not be as relevant to you and your interests, and your experience on our Sites may be degraded.
CHILDREN
We do not knowingly allow individuals under the age of 18 to create accounts on our Sites. Our Sites are not intended for use by, and we do not knowingly collect personal information from, children under 13. By using our Sites, you confirm that you are at least 13 years old. If you are between the ages of 13 and 17, you may only use our Sites with permission from a parent or legal guardian. If we become aware that we have collected personal information from a child under 13 without verified parental consent, we the age of 13 through our Sites, we will take reasonable steps to delete that information as soon as practicable If you believe that we may have collected information from a child under 13, please contact us at privacy@hopco.com.
CHANGES TO THE PRIVACY POLICY
We may update this Privacy Policy from time to time. When we update the Privacy Policy, we will revise the “Effective Date” date above and post the new Privacy Policy. We recommend that you review the Privacy Policy each time you visit the Sites to stay informed of our privacy practices. If we make material changes to this Privacy Policy, we will notify you by email or through the Sites as required.
QUESTIONS?
If you have any questions or concerns about our Privacy Policy, or if you wish to submit a data subject access, deletion, or opt-out request according to the state law where you reside, please contact our privacy officer at privacy@hopco.com. Please be sure to include your name, address (including the state where you reside), and email address so we can respond to your request in the time frame required under your state’s laws.
Cookie Notice
Our approach to tracking and consent: We do not load any non-essential cookies, tags, pixels, analytics, or advertising technologies until you provide opt-in consent through our cookie banner. Only strictly necessary technologies required to operate the Sites run before consent.
Separately, we never place advertising or analytics technologies on any page that collects, displays, or transmits health information, or that concerns a specific medical condition, symptom, treatment, procedure, or provider; for example, condition pages, appointment or intake forms, records or prescription requests, and the patient portal. Those pages are not tagged or tracked, whether or not you have consented.
When we do use cookies, it is to collect information about your browsing activities over time and across different websites following your use of our Sites. They allow us to recognize and count the number of users, to see how users move around the Sites when they are using it and assess our internal performance and functionality needs. This helps us to improve the services we provide to you and the way the Sites works. You can find more information about cookies and how to manage them at http://www.allaboutcookies.org/.
In addition to cookies that are “strictly necessary” which are required for the proper operation of our Sites, we may use the following cookies:
Functionality cookies: these cookies record information about choices you’ve made and allow us to tailor our Sites to you. These cookies mean that when you continue to use or come back to our Sites, we can provide you with our Sites as you have asked for them to be provided.
These cookies allow us to:
Save your location preference if you have set your location on your homepage;
Remember settings you have applied, such as layout, text size, preferences, and colors;
Show you when you are logged in; and
Store accessibility options.
Performance and Analytics cookies: these cookies help us analyze how our Sites are accessed, used, or are performing in order to provide you with a better user experience and to maintain, operate and continually improve our Sites. They allow us to count visitors and traffic to our Sites. All information collected from analytic cookies is aggregated so it is not identifiable.
These cookies allow us to:
Better understand our Sites visitors so that we can improve how we present our content;
Test different design ideas for pages, such as our homepage;
Collect information about visitors of our Sites such as where they are located and what browsers they are using;
Determine the number of unique users of our Sites;
Improve our Sites by measuring any errors that occur; and
Conduct research and diagnostics to improve product offerings.
Marketing: We may use Google pixels and Microsoft Bing marketing cookies to help in our marketing efforts.
We do not use third-party tracking pixels (such as Meta Pixel or similar tools) on pages where PHI is created, viewed, or transmitted.
You may opt-out of functionality cookies and performance cookies at any time by clicking the “Manage Cookies” link at the bottom of the page. You can then adjust the available sliders to “On” or “Off,” then clicking “close”.
Alternatively, you can change your preferences by changing the settings in your browser. Most browsers will allow you to choose the level of privacy settings you want. This lets you control your cookie settings so that you can:
See what cookies or other locally stored data you’ve got and delete them on an individual basis;
Block third party cookies or similar technology;
Block cookies or similar technology from websites;
Block all cookies or similar technologies from being set; or
Delete all cookies or similar technologies when you close your browser.
Most browsers are set to accept cookies by default. However, you can remove or reject cookies in your browser’s settings. Please be aware that such action could affect the availability and functionality of the Site. For more information on how to control cookies, check your browser or device’s settings for how you can control or reject cookies, or visit the following links:
WHAT IF I AM ACCESSING THIS PORTAL FROM OUTSIDE OF THE UNITED STATES?
If you are visiting our Site from outside the United States, your information may be transferred to, stored or processed in the United States, where our servers are located, and our central database is operated. Although the data protection and other laws of the United States and other countries might not be as comprehensive as those in your country, we take steps to protect your privacy, including, for transfers of personal information from the European Economic Area, the use of contractual clauses (known as “Model Clauses” or “Standard Contractual Clauses”) that have been approved by the European Commission. By using our Site, you understand and agree that your information may be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy.
VISITORS FROM THE EUROPEAN ECONOMIC AREA (EEA)
Our Sites and services are primarily directed to users in the United States. If you are located in the European Economic Area (EEA), you may access our Sites for informational purposes. Your personal data will be processed in the United States under U.S. law, which may not provide the same level of protection as EU law.
If you are an EEA resident, you are entitled to rights under the EU General Data Protection Regulation (GDPR), including the right to request access to, rectification of, or erasure of your personal data; to restrict or object to our processing (including where we rely on legitimate interests); to request data portability; and to withdraw consent where consent is the basis for processing. You also have the right to lodge a complaint with your local supervisory authority.
Legal bases for processing: We process personal data about EEA visitors only where we have a lawful basis under Article 6 GDPR, which may include:
Contract necessity – to provide services you request (such as responding to inquiries or scheduling appointments).
Legal obligation – where required by applicable law.
Legitimate interests – for purposes such as maintaining site security, improving our services, and conducting limited analytics, unless your rights and freedoms override these interests.
Consent – when you choose to provide us with special categories of personal data (such as health information) or for communications that are not otherwise legally required.
Special categories of data: If you provide health-related or other sensitive information, we will process such information only with your explicit consent or where another exception under Article 9 GDPR applies (for example, healthcare purposes or legal claims).
Cookies and online tracking: For EEA visitors, we use only cookies and similar technologies that are strictly necessary to operate our Sites or maintain security and functionality. Limited analytics may be used based on our legitimate interests, and you can disable these in your browser settings. We will not place non-essential cookies for EEA visitors without a lawful basis.
International transfers: Your information may be transferred to, stored, or processed in the United States or other countries outside the EEA. For such transfers, we rely on the European Commission’s Standard Contractual Clauses (2021/914/EU), together with supplementary safeguards.
Contact: You may contact us at privacy@hopco.com with any questions or to exercise your rights.
EU Representative under Article 27 GDPR: Although our services are primarily directed to the United States and we do not actively market to EEA residents, CISH has appointed Olthof Support, Rondeel 2, 2652 GZ Berkel En Roderijs, Netherlands, as its representative in the European Union to ensure GDPR-related inquiries are handled appropriately and in anticipation of potential future expansion into the EU. EU residents may contact our representative regarding GDPR matters at ear@myrecovery.com or by mail at the address above. This contact is for data-protection inquiries only and is not a patient-support channel.
YOUR NEVADA PRIVACY RIGHTS
We may collect the following categories of covered information about you through our Site, when you visit the Site such as:
First and Last Name;
Physical Address;
Email Address;
Telephone Number; and
User Name.
We may share such covered information with categories of third parties such as marketing. Third parties may collect covered information about your online activities over time and across different Internet websites or online services when you use the Site. If you use or visit the Site, you may review and request changes to any of your covered information that is collected through the Site by emailing privacy@hopco.com. You may submit a verified request that we not sell any covered information that we have collected or will collect about you by emailing privacy@hopco.com. After we receive your request and determine that it is a verified request, we will not sell any covered information that we have collected or will collect about you.
Recruiting Privacy Policy
1.) What Personal Information Do We Collect?
We collect and maintain personal information in respect of those individuals who seek to be employed by us, such as those applying for employment via the UKG Pro applicant tracking tool. This may, depending on the role and jurisdiction, include personal information contained in:
Resumes and/or applications;
References and interview notes;
Information required for travel to and from an interview;
Photographs and video;
Letters of offer and acceptance of employment; and
Background screening information.
In addition to the examples listed above, personal information also includes information such as name, home address, telephone, personal email address, date of birth, employee identification number and marital status, and any other information necessary for CISH’s business purposes, which is voluntarily disclosed in the course of an individual’s application for employment with CISH.
As a general rule, CISH collects personal information directly from you. In most circumstances where the personal information that we collect about you is held by a third party, such as in the case of a reference or background check, we will obtain your permission before we seek out this information from such sources. Any information processed or retained by those third parties is subject to our agreements with them, their privacy policies, and may be processed as permitted or required by law.
From time to time, we may utilize the services of third parties (including other CISH affiliated entities) in our business and may also receive personal information collected by those third parties in the course of the performance of their services for us or otherwise. Where this is the case, we will take reasonable steps to ensure that such third parties have represented to us that they have the right to disclose your personal information to us and that their practices align with this privacy policy.
Where permitted or required by applicable law or regulatory requirements, we may collect information about you without your knowledge or consent.
2.) How Do We Use Personal Information?
The personal information described above is used and disclosed for our business purpose of recruiting qualified candidates for employment. Such uses include:
Determining eligibility for initial employment, including the verification of references and qualifications;
Assessing qualifications for a particular job or task;
Arranging travel for an in-person interview;
Complying with applicable labor or employment statutes;
Ensuring the security of company-held information;
Such other purposes as are reasonably required by CISH in connection with your application for employment; and
For any additional purposes that we advise you of and for which we have a legal basis, which may for instance be your consent when such consent is required by law.
We may use your personal information without your knowledge or consent where we are permitted or required by applicable law or regulatory requirements to do so.
3.) Monitoring
In the course of conducting our business, we may monitor activities on our systems for security purposes. For example, some of our locations are equipped with surveillance cameras in public areas and our websites are monitored for suspicious activity. Where in use, surveillance cameras and website monitoring are there for the protection of employees and third parties and to protect against theft, vandalism and damage to CISH’s goods and property. Generally, recorded images are routinely destroyed and not shared with third parties unless there is suspicion of a crime, in which case they may be turned over to law enforcement or other authority.
This section is not meant to suggest that all applicants will in fact be monitored or their actions subject to constant surveillance. It is meant to bring to your attention the fact that such monitoring may occur and may result in the collection of personal information.
4.) When Do We Disclose Your Personal Information?
We may share your personal information with our employees, contractors, consultants, and other parties (including other CISH affiliated entities), technology providers for communication tools, such as Microsoft O365 and UltiPro, who require such information to assist us with evaluating your qualifications for employment, including parties that provide products or services to us or on our behalf. In some instances, such parties may also provide certain information technology and data processing services to us so that we may communicate with you, coordinate scheduling for interviews, arrange travel or similarly conduct recruiting activities. We may share personal information with such parties both in and outside of your home jurisdiction, and as result, your personal information may be collected, used, processed, stored, or disclosed in the United States of America and in some cases, other countries.
When we share personal information with such parties, we typically require that they only use or disclose such personal information in a manner consistent with the use and disclosure provisions of this Privacy Policy.
In addition, personal information may be disclosed or transferred to another party (including to another member of the CISH affiliated entities. outside of your home jurisdiction) in the event of a change in ownership of, or a grant of a security interest in, all or a part of CISH through, for example, an asset or share sale, or some other form of business combination, merger or joint venture.
Further, your personal information may be disclosed:
As permitted or required by applicable law or regulatory requirements. In such a case, we will endeavor to not disclose more personal information than is required under the circumstances;
To comply with valid legal processes such as search warrants, subpoenas or court orders;
as part of CISH’s regular reporting activities to other CISH affiliated entities (including outside of your home jurisdiction);
To protect the rights and interests of CISH;
during emergency situations or where necessary to protect the safety of a person or group of persons;
Where the personal information is publicly available; or
With your consent where such consent is required by law.
We do not sell personal information subject to this Privacy Policy to third parties. For the avoidance of doubt and clarification, we do not sell, trade, rent, or otherwise share Mobile Opt-in Data for marketing purposes with anyone.
5.) Consent
Applicants submitting personal information for the purposes of pursuing employment are doing so voluntarily and may withdraw their candidacy at any time. The personal information submitted may need to be retained for a short time (< 1 year) for official records but will not be retained beyond that time or for any other purpose.
All communications with respect to such withdrawal or variation of consent should be in writing and addressed to privacy@hopco.com.
How is Your Personal Information Protected?
CISH endeavors to maintain physical, technical and procedural safeguards that are appropriate to the sensitivity of the personal information in question and maintains an ISO 27001 certification. These safeguards are designed to protect your personal information from loss and unauthorized access, copying, use, modification or disclosure.
Despite these safeguards, no method of transmission over the Internet or data storage is fully secure. In the event that we are required by law to inform you of a breach to your personal information we may notify you electronically, in writing, or by telephone, if permitted to do so by law.
How Long is Your Personal Information Retained?
Except as otherwise permitted or required by applicable law or regulatory requirements, CISH endeavors to retain your personal information only for as long as it believes is necessary to fulfill the purposes for which the personal information was collected (including, for the purpose of meeting any legal, accounting or other reporting requirements or obligations).
Updating Your Personal Information
It is important that the information contained in our records is both accurate and current. If your personal information happens to change during the course of your application for employment, please keep us informed of such changes.
In some circumstances we may not agree with your request to change your personal information and will instead append an alternative text to the record in question.
Access to Your Personal Information and Deletion of Your Personal Information
You may request access to, and rectification, or deletion of personal information that we hold about you. This right and CISH’s obligations to comply, vary based on the applicable regulations in the jurisdiction where you live. Each request will be evaluated individually against the legal requirements.
To make such a request, please contact our Privacy Officer using the contact information set out below. Please note that any such communication must be in writing. In your request, please make clear what specific personal information you would like to have accessed, rectified, or deleted.
When requesting access to, or rectification or deletion of your personal information, please note that we may request specific information from you to enable us to confirm your identity and right to access, rectify, or delete, as well as to search for and provide you with the personal information that we hold about you. If you require assistance in preparing your request, please contact our Privacy Officer at privacy@hopco.com.
Your right to access, rectify, or delete the personal information that we hold about you is not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse your request. In addition, the personal information may have been destroyed, erased or made anonymous in accordance with our record retention obligations and practices.
In the event that we cannot provide you with access to, or rectification or deletion of your personal information, we will endeavor to inform you of the reasons why, subject to any legal or regulatory restrictions.
We will respond to all requests for access, rectification, or deleting of your personal information within the time required under the applicable laws where you live.
We will not discriminate against you for exercising any of your rights described in this Privacy Policy.
Inquiries or Concerns
If you have any questions about this Privacy Policy or concerns about how we manage your personal information, please contact our Privacy Officer at privacy@hopco.com. We will endeavor to answer your questions and advise you of any steps taken to address the issues raised by you.
Privacy Officer
CISH has appointed a privacy officer to oversee compliance with privacy policies. The Privacy Officer can be reached via email at privacy@hopco.com.
Revisions to the Privacy Policy
CISH may from time to time make changes to this Privacy Policy to reflect changes in its legal or regulatory obligations or in the manner in which we deal with your personal information. Any changes to this Privacy Policy will be effective from the date it is posted, which is reflected on the website displaying this policy. This Privacy Policy was last reviewed or updated as of the Effective Date set forth above.