Date: October 11, 2021
This Privacy Notice (“Notice”) explains how Diebold Nixdorf, Inc. and its subsidiaries and affiliates listed here (collectively, “Diebold Nixdorf,” “we,” “our” or “us”) collect, use, and disclose your personal data. This Notice also explains the rights and the choices you have related to your personal data and how to contact us regarding our privacy practices.
This Notice applies to personal data that we collect: (i) through Diebold Nixdorf websites, apps, portals, and other digital assets (the “Services”), and (ii) when you interact with us through other means than the Services, such as by telephone or at a trade event.
This Notice does not apply if you receive a separate privacy notice from Diebold Nixdorf that modifies or supplements this Notice. This Notice also does not apply if you enter into a contract with Diebold Nixdorf and the terms of the contract conflict with this Notice.
This Notice is separated into two parts. The first part provides general information applicable to all personal data subject to this Notice. The second part provides additional information about the processing of personal data that originates from certain countries. You can go to either part of the Notice, and any section within either part, by clicking on the links directly below.
General Information Applicable to All Personal Data: What Personal Data We Collect and How We Collect It| How We Use Your Personal Data| Who We Share Your Personal Data With | International Transfers | Links to Third-Party Websites, Apps, and Services | Security | Analytics and Advertising| Your Choices | Retention of Your Personal Data | Processing Personal Data of Customers and Business Partners | Changes to this Notice | Contact Us
Additional Information for Individuals in Certain Countries: European Economic Area and United Kingdom| Colombia| Brazil| Mexico | Singapore | Malaysia | Philippines | Australia | Canada | California
GENERAL INFORMATION APPLICABLE TO ALL PERSONAL DATA
WHAT PERSONAL DATA WE COLLECT AND HOW WE COLLECT IT
“Personal data” is any information that identifies you as an individual. It is also information that can identify you when combined with other information. We collect personal data in various ways depending on how you interact with us. Sometimes you provide us with your personal data, sometimes others (like your employer) provide us with your personal data, and other times we automatically collect your personal data.
Personal Data We Collect Directly From You
We collect personal data directly from you in different ways. For example, we collect personal data when you register for an account, subscribe to a newsletter or notification, submit a request, or register to attend a Diebold Nixdorf business or trade event. We also collect personal data directly from you in other ways, such as in connection with our products and services or a transaction with you, or if you call or email us.
The types of personal data that we collect from you depend on how you interact with us, our relationship with you, and the particular transaction. Generally, we collect the following personal data:
When you are asked to provide personal data, you may decline. We will indicate if it is necessary to provide personal data. If you choose not to provide personal data that we request, we may not be able to provide you the relevant products or services or a particular feature on the Services.
Personal Data We Collect From Others
We collect personal data about you from others, including from social media platforms and other third parties. For example, we receive information about you when you interact with our pages, groups, accounts, or posts on social media platforms.
Your employer (or an entity that you have contracted with) may provide us your contact details (i.e., your name, job title, business email address, business physical address and/or your business or personal phone number) in order for us to provide the services we have contracted to provide.
If you provide any personal data to us, or permit us to collect any personal data, relating to another person, you are telling us that you have the authority to share that personal data and permit us to use the personal data in accordance with this Notice.
Personal Data We Automatically Collect
When you interact with the Services, we and our service providers may collect personal data about you through automated means such as cookies, web beacons, pixels, software development kits (SDKs), and other tracking technologies (collectively, “tracking technologies”).
The personal data that we and our service providers may automatically collect includes:
Please read our Cookie Notice for more information about our use of tracking technologies and the choices you have related to these tracking technologies. You can also customize your settings at any time by clicking on the “Cookie Preferences” link at the bottom of our website pages or in the app menu. Your browser may also allow you to adjust settings to accept or reject cookies. Please see “Your Choices” below for more information. In certain cases, if your browser does not accept our cookies, you may not be able to access certain parts of our Services. We currently do not respond to “Do Not Track” browser signals.
We and our service providers may also collect certain personal data about you through automated means such as social media tools, widgets, or plug-ins to connect you to your social media accounts. These features may allow you to sign-in through your social media account, share a link, or post directly to your social media account. When you visit a website that contains such tools or plugins, the social media platform may learn about your visit. Your interactions with these tools or plug-ins are governed by the privacy policies of the corresponding social media platforms. We recommend that you review privacy policies, terms of use, and license agreements of these third-party social media platforms. For further details, please see “Links To Third-Party Websites, Apps, and Services” below.
We use your personal data to conduct our business – this includes managing our business relationships, monitoring access to the Services, managing safety and security risks, and complying with our legal obligations.
The purposes for which we use your personal data will depend on the type of personal data collected and the context in which it was collected. However, the primary purposes for which we use your personal data include:
Developing and managing our business relationships. For example, we may use your personal data to: provide the Services; generate leads; deliver our products or services or carry out transactions, including processing payments and providing support; send you technical notes, updates, security alerts, and administrative messages; provide information that you or a business partner requests, including pricing information, technical data, invoices, or shipping or product information; communicate with you and respond to your questions, comments, or requests; manage complaints and undertake remediation activities; maintain and administer your account; tailor the Services’ experience and content based on your interests and preferences; provide newsletters and notifications you subscribe to; and negotiate, manage, and fulfill our contracts with our business partners.
Improving our products and services. For example, we may use your personal data to: analyze how the Services are being accessed and used in order to improve your experience on the Services and the functionalities offered through the Services; improve the products and services we offer and develop new products, services, and offerings; review recordings or screenshots of interactions with customers for training and quality assurance; conduct market research; and conduct surveys or obtain your feedback.
Advertising and marketing purposes. For example, we may use your personal data to: send promotional communications; inform you about our products, services, and offerings that we believe you or your business might want to hear about; analyze the characteristics of visitors to the Services; measure the effectiveness of our marketing campaigns and advertising; and invite you to events, product launches, and industry meetings that may interest you.
Administrative and internal business purposes. For example, we may use your personal data to: manage internal operations, such as troubleshooting, data analysis, testing, research, statistical, and survey purposes; and analyze, manage, and improve our businesses, including conducting audits and identifying usage trends.
Managing shareholder relationships. For example, we may use your personal data to communicate with shareholders and undertake shareholder transactions.
Protecting Diebold Nixdorf. For example, we may use your personal data to: maintain the security and integrity of the Services and our products and services; detect, prevent, and respond to fraud and other illegal activity on the Services; and detect and prevent security incidents.
Legal and compliance purposes. For example, we may use your personal data to: comply with our legal, regulatory, and risk management obligations; respond to requests from governmental and public authorities; enforce our terms of service and other contractual agreements; detect, prevent, and respond to intellectual property infringement, violations of law, or other misuse of our products or services; protect our rights or property, or your or others’ health, safety, welfare, rights, or property; and establish, exercise, and defend legal and contractual claims.
We may also use your personal data for other uses consistent with the context in which the information was collected or with your consent.
WHO WE SHARE YOUR PERSONAL DATA WITH
We share your personal data as follows:
We also share your personal data as we believe to be necessary or appropriate:
In addition, we may use, disclose, or transfer personal data to a third party in connection with any business transaction, reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
Diebold Nixdorf is a multinational company. For the purposes set out in this Notice, we may need to transfer your personal data within the Diebold Nixdorf group of companies and to third parties located outside the country where we collected your personal data. These countries may have different data protection laws and requirements than the country from which we collected your personal data. In those instances, your personal data may be subject to the laws of other countries regarding disclosure to the government, courts, law enforcement, and regulatory authorities. Please see “Additional Information” below for more information about the transfer of your personal data in certain countries.
LINKS TO THIRD-PARTY WEBSITES, APPS, AND SERVICES
The Services may contain links to other websites, apps, or services that are not covered by this Notice, including plugins from social media platforms and other third parties. An example of a social media plugin is the Facebook “Like” button. These links and plugins are provided for your convenience and information. We do not own or operate these third-party websites, apps, services, or social media platforms. We are not responsible for and do not control any third party’s data collection or privacy practices. The inclusion of links to third party websites, apps, or services does not imply endorsement of the linked site or service by us or by our affiliates or subsidiaries. We encourage you to review the privacy policies or notices on these third-party websites, apps, services, and social media platforms before submitting any personal data.
We maintain physical, technical and organizational safeguards to protect the confidentiality, security, and integrity of your personal data. Although we use security measures to help protect your personal data against unauthorized disclosure, misuse, or alteration, no data transmission or storage system can be guaranteed to be 100% secure.
We use third-party analytics, including Google Analytics, to better understand how users engage with the Services. The information collected by the tracking technologies about your interactions with the Services is used to assess how often you visit the Services, what pages you view when you visit the Services, and what other websites you visited before coming to the Services. For more information on Google Analytics’ privacy practices, please visit https://support.google.com/analytics/answer/6004245. You may prevent Google Analytics from recognizing you on the Services by opting out of the use of such cookies or deleting or disabling cookies from the Services. For more information, see “Your Choices” below.
We work with third parties to present advertisements and engage in data collection, reporting, and ad delivery and response measurement on the Services and on third-party websites across the Internet and apps over time. These third parties use tracking technologies to perform this activity. They also obtain information about apps you use, websites you visit, and other information from across your devices and browsers in order to help serve advertising that will be more relevant to your interests on and off the Services and across your devices and browsers. This type of advertising is known as interest-based advertising. They also use this information to associate various browsers and devices together for the purpose of interest-based advertising and other purposes like analytics. For more information on your options related to the use of your information, see “Your Choices” below.
You have certain choices about how your personal data is processed.
Marketing communications. To opt out of receiving email marketing communications, you can follow the "unsubscribe" instructions provided in any marketing email you receive from us. If you previously chose to receive push notifications on your mobile device from us, but no longer wish to receive them, you can manage your preferences through your device or app settings, depending on the type of device. You can also update your preferences in your account or submit a request to dataprivacy@dieboldnixdorf.com.
Cookie Preferences. You can customize your settings at any time by clicking on the “Cookie Preferences” link at the bottom of our website pages or in the app menu.
Opt-Out of Google Analytics. You may exercise choices regarding the use of cookies from Google Analytics by visiting https://tools.google.com/dlpage/gaoptout.
Opt-Out of Tracking Technologies. In addition to the ability to opt-out from the use of certain tracking technologies through the settings under “Cookie Preferences,” you have the following options:
RETENTION OF YOUR PERSONAL DATA
We will retain your personal data for as long as is necessary for the purposes described in this Notice, or as otherwise permitted or required under applicable law. To determine the appropriate retention period, we will consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure of the data; the purposes for which we process the data and whether we can achieve those purposes through other means; and the applicable legal requirements. This means that the retention periods will vary for different types of personal data.
PROCESSING PERSONAL DATA OF CUSTOMERS AND BUSINESS PARTNERS
There may be instances where this Notice does not apply to the processing of your personal data or where there are other policies that control the processing of your personal data.
We may collect your personal data pursuant to a contract we have with a commercial customer (“Customer”). In that case, we must process personal data in accordance with the instructions from our Customer, which is ultimately the business responsible for determining how your personal data will be processed. If you are contacting us in connection with personal data that we process for a Customer, we encourage you to review the Customer’s privacy notice to understand how personal data is processed.
Also, some of our products and services (“B2B Services”) are intended for use by our Customers, distributors, suppliers, vendors, and other business partners (“B2B Business Partners”), and your use of such products and services will be administered by our B2B Business Partners. In such cases, authorized personnel at your employer (or an entity with which you have contracted) may have access to your personal data collected by these B2B Services, and your employer (or an entity with which you have contracted) may have policies applicable to your use of the B2B Services. We are not responsible for such policies, which may be different from this Notice. If your employer (or an entity with which you have contracted) is administering your use of a B2B Service, please contact such entity with any privacy questions related to your use of that B2B Service. If there is a conflict between this Notice and an agreement between Diebold Nixdorf and a B2B Business Partner, then the agreement between Diebold Nixdorf and the B2B Business Partner will control.
We may make changes to this Notice at any time. When we make changes to this Notice, we will revise the “Effective Date” at the top of this Notice. If the changes are material, we will provide a more prominent notice on our corporate website.
If you have any questions about this Notice or about how we process your personal data, you may contact us at dataprivacy@dieboldnixdorf.com or by writing to us at:
Diebold Nixdorf, Inc.
Attn: General Counsel
50 Executive Pkwy
Hudson, Ohio 44236
Additional Information for Individuals in Certain Countries
European Economic Area and The United Kingdom
This section of the Notice applies to the personal data collected from individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”). It supplements the information above in the Notice.
Controller
The controller determines how and why your personal data is processed. In the EEA and the UK, the controller of your personal data is the Diebold Nixdorf entity with which you have a contract or direct relationship, and/or as applicable, Diebold Nixdorf, Inc., 50 Executive Pkwy, Hudson, Ohio 44236 USA. A list of Diebold Nixdorf entities in the EEA and the UK with their contact information is available here.
Lawful Basis for Processing Your Personal Data
We must have a lawful basis to process your personal data. The lawful basis depends on the purposes for the processing. In most cases, the lawful basis will be one of the following: your consent, processing is necessary for the performance of a contract to which you are a party or to enter into a contract with you, processing is necessary for compliance with a legal obligation, or processing is necessary for the purposes of our or a third party’s legitimate interests.
The table below sets out the purposes for which we use your personal data and our lawful basis for doing so. Please note that not all uses will be relevant to every individual.
What we use your personal data for |
The lawful basis for processing |
Developing and managing our business relationships. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Improving our products and services. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) continually developing and improving our organization and the products and services we offer; (ii) training our staff to provide a high level of service; and (iii) ensuring our business remains competitive. |
Advertising and marketing purposes. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Administrative and internal business purposes. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) planning and allocating resources and budget; (ii) managing risks and determining what products and services we can offer and the terms of such products and services; and (iii) ensuring our processes and systems operate effectively and that we can continue operating as a business. |
Managing shareholder relationships. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for the performance of a contract with you or to take steps to enter into a contract with you. We may process your personal data when it is necessary for our legitimate interests, including our interest to manage our relationship with shareholders. |
Protecting Diebold Nixdorf. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under European Union law or the laws of EEA Member States and the UK. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) protecting the security of Diebold Nixdorf and our products and services; and (ii) preventing, detecting, and responding to fraud and other illegal activity to protect our business and reputation. |
Legal and compliance purposes. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under European Union law or the laws of EEA Member States and the UK. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) complying with laws we are subject to outside of the EEA and the UK; and (ii) protecting Diebold Nixdorf and its interests. |
International Transfers
If we transfer your personal data outside the EEA or the UK to countries not deemed by the European Commission (or the UK Parliament, in the case of the UK) to provide an adequate level of personal data protection, the transfer will be based on standard contractual clauses approved by the European Commission (or the UK Parliament, in the case of the UK), which impose data protection obligations on the parties to the transfer. We could also implement other approved data transfer mechanisms, such as binding corporate rules, for such transfers. Please contact us at dataprivacy@dieboldnixdorf.com if you would like additional information on the specific mechanism we use to transfer your personal data.
Your Rights
Under data protection laws in the EEA and the UK, you have certain rights regarding your personal data. Subject to certain conditions, you have the following rights:
If you have provided us your consent to process your personal data, you can withdraw your consent at any time. If you withdraw your consent, this will not affect the lawfulness of the processing of your personal data before you withdrew consent.
You can exercise any of these rights by submitting a request to us using one of the methods listed under “Contact Us” below. We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason.
If you would like to submit a complaint about our use of your personal data or our response to your personal data request, you may contact us using one of the methods listed under “Contact Us” below. You also have the right to submit a complaint to a data protection supervisory authority.
Contact Us
If you have any questions about this Notice or about how we process your personal data, you may contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at the addresses for the Diebold Nixdorf entities in the EEA and the UK and Diebold Nixdorf, Inc. listed above under “Controller.”
In Germany, you may contact our German Data Protection Officer (Alef Völkner from fox-on Datenschutz) by email at DSB@fox-on.com or by phone at +49 0 22 66-90 15 920.
This section of the Notice applies to the personal data of individuals in Brazil. It supplements the information above in the Notice.
Controller
The controller determines how and why your personal data is processed. The controller of your personal data is the Diebold Nixdorf entity in Brazil with which you have a contract or direct relationship, and as applicable, Diebold Nixdorf, Inc., 50 Executive Pkwy, Hudson, Ohio 44236. The Diebold Nixdorf entities in Brazil include:
Lawful Bases
The table below sets out the purposes for which we use your personal data and our lawful basis for doing so. Please note that not all uses will be relevant to every individual.
What we use your personal data for |
The lawful basis for processing |
Developing and managing our business relationships. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Improving our products and services. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) continually developing and improving our organization and the products and services we offer; (ii) training our staff to provide a high level of service; and (iii) ensuring our business remains competitive. |
Advertising and marketing purposes. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Administrative and internal business purposes. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) planning and allocating resources and budget; (ii) managing risks and determining what products and services we can offer and the terms of such products and services; and (iii) ensuring our processes and systems operate effectively and that we can continue operating as a business. |
Managing shareholder relationships. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for the performance of a contract with you or to take steps to enter into a contract with you. We may process your personal data when it is necessary for our legitimate interests, including our interest to manage our relationship with shareholders. |
Protecting Diebold Nixdorf. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under Brazilian law. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) protecting the security of Diebold Nixdorf and our products and services; and (ii) preventing, detecting, and responding to fraud and other illegal activity to protect our business and reputation. |
Legal and compliance purposes. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under Brazilian law. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) complying with laws we are subject to outside of Brazil; and (ii) protecting Diebold Nixdorf and its interests. |
The collection of your personal data may be voluntary or mandatory depending upon the purposes for which it is collected. Where it is obligatory for you to provide us with your personal data and you fail to provide us with your personal data, we will not be able to provide you the Services and/or certain products or services.
Your Rights
Under the General Personal Data Protection Law (Brazil) 13.709/2018, you have certain rights regarding the processing of your personal data. Subject to certain conditions, you have the following rights:
You can exercise these rights by submitting a request using one of the methods listed under “Contact Us” below. We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You may also contact our Data Protection Officer in Brazil, at Diebold Brasil LTDA, attention: Data Protection Officer, Avenida Francisco Matarazzo, 1350 - 4th floor - 05001-100 - São Paulo, SP Brazil.
This section of the Notice applies to the personal data of individuals in Colombia. It supplements the information above in the Notice.
Controller
The controller determines how and why your personal data is processed. The controller of your personal data is Diebold Colombia S.A., Carrera 69 No. 25 B-44 Of. 1001 A, Edif. World Business Port, Bogota, Colombia, and/or as applicable, Diebold Nixdorf, Inc., 50 Executive Pkwy, Hudson, Ohio 44236 USA.
Authorization to Process Your Personal Data
Diebold Colombia S.A. will request authorization to process your personal data under the terms, and for the purposes, set forth in this Notice. Your authorization may be obtained by any means, such as written, verbal, or electronic consent. The authorization may also be obtained from your unequivocal conduct, which makes it possible to conclude in a reasonable way that you granted your consent for the processing of your personal data. Such conduct should clearly evidence your intent to authorize the processing of your personal data. Diebold Colombia S.A. will keep proof of such authorization in an appropriate manner.
Your Rights
Under Colombian data protection laws, you have certain rights regarding your personal data. Subject to certain conditions, you have the following rights:
You can exercise these rights by submitting a request to us using one of the methods listed under “Contact Us” below. We may request specific information from you to confirm your identity prior to processing your request. If you make such a request, we will respond to the request in accordance with the time periods set out in Ley 1581 de 2012. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason. Under certain conditions, we may charge a reasonable fee for the cost of copying your personal data. We will inform you of such costs before charging you.
If you would like to submit a complaint about our use of your personal data or our response to your personal data request, you may contact us using one of the methods listed under “Contact Us” below. You also have the right to submit a complaint to the Superintedencia de Industria y Comercio for violations of Ley 1581 de 2012 and other Colombian data protection laws that may apply to you.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at colombia.protecciondatos@dieboldnixdorf.com. You can also contact us by post at the addresses above under “Controller” or by telephone at +57 (1) 5185026.
This section of the Notice applies to the personal data of individuals in Mexico. It supplements the information above in the Notice.
Controller
The controller determines how and why your personal data is processed. The controller of your personal data is the Diebold Nixdorf entity in Mexico with which you have a contract or direct relationship, and as applicable, Diebold Nixdorf, Inc., 50 Executive Pkwy, Hudson, Ohio 44236 USA.. The Diebold Nixdorf entities in Mexico include:
Consent
By using the Services or voluntarily providing your personal data, you consent to the collection, use, and sharing of your personal data as described in this Notice. You also consent to the transfer of your personal data for processing outside of Mexico as described in this Notice.
Your Rights
In accordance with the Federal Law on the Protection of Personal Data Held by Private Individuals and its implementing regulations (collectively, the “Federal Law”), you have the rights of access, rectification, cancellation, and objection (“ARCO Rights”) with respect to your personal data that we process. You may also revoke your consent to our processing of your personal data at any time. To exercise your ARCO Rights or to revoke your consent to the processing of your personal data, please contact us using one of the methods listed under “Contact Us” below.
We will review any request you make to exercise your ARCO rights or to revoke your consent. When you submit a request to exercise your ARCO rights or revoke your consent, we will respond to the request and indicate: (i) the information that we will need to identify you, (ii) the timeframes in which we will respond to your request, (iii) additional information we will need to carry out your request, and (iv) the means with which we will deliver the information you request (if applicable). Our response to your request to exercise your ARCO rights will be free of charge; however, we may charge you the reasonable cost of shipping or reproduction of copies or other formats. We will inform you of these costs before charging you. If you exercise your ARCO rights less than 12 months from the date of your last request, we may charge you a fee for such response in accordance with the Federal Law.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at the addresses above under “Controller.”
This section of the Notice applies to the personal data of individuals in Australia. It supplements the information above in the Notice.
Consent
By communicating with us, providing your personal data to us and/or continuing to use the Services and/or Diebold Nixdorf products or services, you confirm that you have read this Notice and agree to us processing your personal data in accordance with this Notice. You agree to us transferring your personal data outside of Australia, including to countries with different laws and data protection regimes than Australia, such as the United States and India. If you do not consent to us processing your personal data or transferring your personal data outside of Australia, please notify us using one of the methods listed under “Contact Us” below.
The collection of your personal data may be voluntary or mandatory depending upon the purposes for which it is collected. Where it is obligatory for you to provide us with your personal data and you fail to provide us with your personal data or do not consent to the processing, we will not be able to provide you the Services and/or certain products or services.
Your Rights
Under the Privacy Act 1988 (Australian Privacy Principles 12 and 13) you have the right to ask for access to personal data that we hold about you, and to ask that we correct that personal data.
You can exercise these rights by submitting a request to us using one of the methods listed below under “Contact Us.” We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason. We may charge you a small fee to cover our costs when giving you access to your personal data, but we will always check with you first.
If we make a correction to your personal data and we have disclosed incorrect information to others, you can ask us to tell them about the correction. We must do so unless there is a valid reason not to. If we refuse to correct your personal data, you can ask us to associate with it (for example, attach or link) a statement that you believe the information is incorrect and why.
How to Make a Complaint
If you would like to submit a complaint about our use of your personal data or our response to your personal data request, you may contact us using one of the methods listed below under “Contact Us.” Following your initial contact, you will be asked to set out the details of your complaint in writing in a form provided. We will endeavor to reply to you within 30 days of receipt of the completed complaint form, and where appropriate, will advise you of the general reasons for the outcome of the complaint. While we hope that we will be able to resolve any complaints you may have without needing to involve third parties, if you are not satisfied with the outcome of your complaint, you can refer your complaint to the Office of the Australian Information Commissioner.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at Diebold Nixdorf Australia Pty Limited, G Building C' 1 Homebush Bay Drive, Rhodes NSW 2138.
This section of the Notice applies to the personal data of individuals in Malaysia. It supplements the information above in the Notice.
Consent
By communicating with us, providing your personal data to us and/or using the Services or Diebold Nixdorf products or services, you confirm that you have read this Notice and agree to the use, processing, disclosure, and transfer of your personal data as described in this Notice. If you do not agree to us processing your personal data or to the transfer of your personal data outside of Malaysia, please notify us at dataprivacy@dieboldnixdorf.com. You can withdraw your consent at any time as described below under “Your Rights.”
The collection of your personal data may be voluntary or mandatory depending upon the purposes for which it is collected. Where it is obligatory for you to provide us with your personal data and you fail to provide us with your personal data or do not consent to the processing, we will not be able to provide you the Services and/or certain products or services.
International Transfers
We may transfer your personal data outside Malaysia if (i) you have given consent to the transfer; (ii) the transfer is necessary for the performance of a contract between you and us; (iii) the transfer is necessary for the performance of a contract between us and a third party which is entered into at your request or is in your interest; (iv) the transfer is for the purpose of legal proceedings or for the purpose of obtaining legal advice or for establishing, exercising, or defending legal rights; (v) we have taken all reasonable precautions and exercised all due diligence to ensure that your personal information will be processed in accordance with Malaysian law; (vi) the transfer is necessary in order to protect your vital interests; or (vii) where the Malaysian government deemed that the transfer of your personal data is necessary for the public interest.
Your Rights
The Malaysia Personal Data Protection Act 2010 grants you certain rights regarding the processing of your personal data. Subject to certain conditions, you have the right to:
You can exercise these rights by submitting a request using one of the methods listed below under “Contact Us.” We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason.
Depending on the circumstances, we reserve the right to charge you a reasonable administrative fee in the amounts permitted under applicable law. Reasonable administrative costs might include reasonable staff costs in locating and collating the information, reasonable reproduction or photocopying costs, and reasonable costs in having someone explain the information to you.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at Diebold - Corp Systems Sdn. Bhd., Suites K-10-01 to 04, Level 10 Block K, Solaris Mont Kiara, No 2 Jalan Solaris, 50480 Kuala Lumpur.
This section of the Notice applies to the personal data of individuals in the Philippines. It supplements the information above in the Notice.
Controller
The controller determines how and why your personal data is processed. The controller of your personal data is Diebold Nixdorf Philippines, Inc., 33F Rufino Pacific Tower 6784 Ayala Ave., Corner V.A. Rufino St., Legaspi Village, 1226 Makati City, Philippines, and as applicable, Diebold Nixdorf, Inc., 50 Executive Pkwy, Hudson, Ohio 44236 USA.
Lawful Basis
The table below sets out the purposes for which we use your personal data and our lawful basis for doing so. Please note that not all uses will be relevant to every individual.
What we use your personal data for |
The lawful basis for processing |
Developing and managing our business relationships. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Improving our products and services. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) continually developing and improving our organization and the products and services we offer; (ii) training our staff to provide a high level of service; and (iii) ensuring our business remains competitive. |
Advertising and marketing purposes. For example, we may use your personal data to:
|
Depending on our relationship with you:
|
Administrative and internal business purposes. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) planning and allocating resources and budget; (ii) managing risks and determining what products and services we can offer and the terms of such products and services; and (iii) ensuring our processes and systems operate effectively and that we can continue operating as a business. |
Managing shareholder relationships. For example, we may use your personal data to:
|
We may process your personal data when it is necessary for the performance of a contract with you or to take steps to enter into a contract with you. We may process your personal data when it is necessary for our legitimate interests, including our interest to manage our relationship with shareholders. |
Protecting Diebold Nixdorf. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under Philippine law. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) protecting the security of Diebold Nixdorf and our products and services; and (ii) preventing, detecting, and responding to fraud and other illegal activity to protect our business and reputation. |
Legal and compliance purposes. For example, we may use your personal data to:
|
We may process your personal data to fulfill a legal obligation under Philippine law. We may process your personal data when it is necessary for our legitimate interests, including such interests as: (i) complying with laws we are subject to outside of the Philippines; and (ii) protecting Diebold Nixdorf and its interests. |
Your Rights
The Philippines Data Privacy Act of 2012 and its regulations grant you certain rights regarding the processing of your personal data. Subject to certain conditions, you have the following rights:
If you have provided your consent to the processing of your personal data, you can withdraw your consent at any time. If you withdraw your consent, this will not affect the lawfulness of the processing of your personal data before you withdrew consent.
You can exercise these rights by submitting a request using one of the methods listed below under “Contact Us.” We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason.
If you would like to submit a complaint about our use of your personal data or our response to your personal data request, you may contact us using one of the methods listed below under “Contact Us.” You also have the right to submit a complaint to the National Privacy Commission. Under certain conditions, you may also claim compensation if you suffered damages due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at the addresses listed above under “Controller.”
This section of the Notice applies to the personal data of individuals in Singapore. It supplements the information above in the Notice.
The Singapore Personal Data Protection Act and other applicable data protection laws in Singapore (collectively, the “PDPA”) exempt certain types of personal data (e.g., business contact information) from their scope. This means that you may not have certain rights and we may not have certain obligations described below with respect to your personal data.
Consent
We will seek your consent prior to collecting, using, or disclosing your personal data for any purpose unless such collection, use, or disclosure is permitted or authorized under applicable law. The consent may be express in writing, or implied, and in some cases it may be provided orally or electronically. Consent may be implied when you voluntarily provide personal data for a purpose and it is reasonable that you would voluntarily provide such personal data. You have the right to withdraw your consent at any time by contacting us using one of the methods listed below under “Contact Us.”
Your Rights
The PDPA grants you certain rights regarding the processing of your personal data. Subject to certain conditions, you have the right to:
You can exercise these rights by submitting a request using one of the methods listed below under “Contact Us.” We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at the addresses listed below for the Diebold Nixdorf entities in Singapore.
You can also contact our Data Protection Officer in Singapore, at Diebold Nixdorf Singapore Pte. Ltd., attention: Data Protection Officer, 30A Kallang Place #04-0-1, Singapore 339213.
This section of the Notice applies to the personal data of individuals in Canada. It supplements the information above in the Notice.
The Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) exempts certain types of personal data (e.g., business contact information) from its scope. This means that you may not have certain rights and we may not have certain obligations described below with respect to your personal data.
Consent
We will seek your consent prior to collecting, using, or disclosing your personal data for any purpose. The consent may be express in writing, or implied, and in some cases it may be provided orally or electronically. Whether the consent is express or implied will depend on the sensitivity of the personal data and the reasonable expectations you might have in the circumstances. You have the right to withdraw your consent at any time by contacting us using one of the methods listed below under “Contact Us.”
Your Rights
Upon written request and subject to exceptions permitted or required by law, we will provide you with access to your personal data that is in our possession. You may also contact us to correct and update your personal data. In each such case, you must clearly indicate the information that you wish to have changed.
You can exercise these rights by submitting a request to us using one of the methods listed below under “Contact Us.” We may request specific information from you to confirm your identity prior to processing your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you the reason why, unless we are not permitted by law to disclose the reason. We may charge you a nominal fee for access to your personal data and we will give you notice before charging you any costs.
How To Make a Complaint
If you would like to submit a complaint about our use of your personal data or our response to your personal data request, you may contact us using one of the methods listed under “Contact Us” below. If any concern you raise is not satisfactorily resolved, we can provide information on other complaint procedures that may be available to you.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com. You can also contact us by post at Diebold Nixdorf Canada, Limited, 6630 Campobello Road, Mississauga, Ontario Canada L5N 2L8.
This section of the Notice applies to the personal information of individuals that reside in the State of California. It supplements the information contained in the Notice above.
California Consumer Privacy Act (“CCPA”)
Personal Information We Collect
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer (“personal information”). We have collected the following categories of personal information in the past 12 months:
Category of Personal Information |
Examples of Data We Collect |
Identifiers |
IP address, email address (business and/or personal), username/password or other similar identifiers |
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). |
Name, address (business and/or personal), telephone number (business and/or personal), tax identification number, payment card information |
Commercial information |
Records of products or services purchased, records of communications, and records of events attended |
Internet or other similar network activity. |
Browsing history, information on interaction with a website, application, or advertisement |
Sensory data |
Audio information if you contact us via phone, and recordings |
Inferences drawn from other personal information |
Profile reflecting a person’s preferences |
We obtain the categories of personal information listed above from the following categories of sources:
How We Use Your Personal Information
The purposes for which we use your personal data will depend on the type of personal data collected and the context in which it was collected. We may use or disclose the personal information we collect for one or more of the following business purposes:
Developing and managing our business relationships. For example, we may use your personal data to: provide the Services; generate leads; deliver our products or services or carry out transactions, including process payments and provide support; send you technical notes, updates, security alerts, and administrative messages; provide information that you or a business partner requests, including pricing information, technical data, invoices, or shipping or product information; communicate with you and respond to your questions, comments, or requests; manage complaints and undertake remediation activities; maintain and administer your account; tailor the Services’ experience and content based on your interests and preferences; provide newsletters and notifications you subscribe to; and negotiate, manage, and fulfill our contracts with our business partners.
Improving our products and services. For example, we may use your personal data to: analyze how the Services are being accessed and used in order to improve your experience on the Services and the functionalities offered through the Services; improve the products and services we offer and develop new products, services, and offerings; review recordings or screenshots of interactions with customers for training and quality assurance; conduct market research; and conduct surveys or obtain your feedback.
Advertising and marketing purposes. For example, we may use your personal data to: send promotional communications; inform you about our products, services, and offerings that we believe you or your business might want to hear about; analyze the characteristics of visitors to the Services; measure the effectiveness of our marketing campaigns and advertising; and invite you to events, product launches, and industry meetings that may interest you.
Administrative and internal business purposes. For example, we may use your personal data to: manage internal operations, such as troubleshooting, data analysis, testing, research, statistical, and survey purposes; and analyze, manage, and improve our businesses, including conducting audits and identifying usage trends.
Managing shareholder relationships. For example, we may use your personal data to communicate with shareholders and undertake shareholder transactions.
Protecting Diebold Nixdorf. For example, we may use your personal data to: maintain the security and integrity of the Services and our products and services; detect, prevent, and respond to fraud and other illegal activity on the Services; and detect and prevent security incidents.
Legal and compliance purposes. For example, we may use your personal data to: comply with our legal, regulatory, and risk management obligations; respond to requests from governmental and public authorities; enforce our terms of service and other contractual agreements; detect, prevent, and respond to intellectual property infringement, violations of law, or other misuse of our products or services; protect our rights or property, or your or others’ health, safety, welfare, rights, or property; and establish, exercise, and defend legal and contractual claims.
We may also use your personal data for other uses consistent with the context in which the information was collected or with your consent.
How We Share Your Personal Information
We may disclose your personal information to a third party for a business purpose. In the last 12 months, we have disclosed the following categories of personal information for a business purpose: Identifiers, Personal Information Categories in California Records, Commercial Information, Internet or Similar Network Activity, Sensory Data, and Inferences.
We disclose your personal information for a business purpose to the following categories of recipients:
In the last 12 months, we did not sell any personal information. We do not sell the personal information of minors under 16 years of age and would not do so in the future without affirmative authorization of the individual if between 13 and 16 years of age, or the parent or guardian of an individual less than 13 years of age.
Your Rights
Please note that the CCPA applies in a limited context with respect to the personal information of California consumers that we collect in connection with providing products or services to, or receiving products or services from, other businesses (i.e., the business-to-business context). If your personal information was collected under these circumstances, you may not have any or all of the privacy rights listed below.
You may have the following privacy rights under the CCPA:
You may exercise your right to request to know twice a year, free of charge. If we are unable to fulfill your request to know, we will let you know the reason why. Please note, in response to a request to know, we are prohibited from disclosing certain personal information to you.
If you would like to make a request to know or request to delete or are an authorized agent of a California resident who would like to make such a request, contact us at 1-866-384-4277 or email us at dataprivacy@dieboldnixdorf.com.
We will take steps to verify your identity before processing your request. We will not fulfill your request unless you have provided sufficient information for us to reasonably verify that you are the individual about whom we collected personal information. When we confirm receipt of your request, we will inform you of the personal information that we will need to process your request. The information will depend on our relationship with you. We will only use the personal information you provide to verify your identity and to process your request, unless you initially provided the information for another purpose.
You may use an authorized agent to submit a request to know or a request to delete. When we verify your agent’s request, we may verify both your and your agent’s identity and request that you directly confirm with us that you provided the authorized agent permission to make the request on your behalf. To protect your personal information, we reserve the right to deny a request from an agent that does not submit proof that they have been authorized by you to act on your behalf.
Shine the Light
In addition to CCPA, California residents also have rights under Shine the Light. California residents may request information from us once per calendar year about any personal information shared with third parties for the third party’s own direct marketing purposes, including the categories of information and the names and addresses of those businesses with which we have shared such information. To request this information, please contact us at dataprivacy@dieboldnixdorf.com or by postal mail sent to Diebold Nixdorf, Inc., Attn: General Counsel, 50 Executive Pkwy, Hudson, Ohio 44236. Your inquiry must specify “Shine the Light Request” in the subject line of the email or the first line of the letter, and include your name, street address, city, state and ZIP code.
Contact Us
If you have any questions about this Notice or about our processing of your personal data, please contact us at dataprivacy@dieboldnixdorf.com.