UPSCRIPT
PRIVACY ADDENDUM FOR CALIFORNIA RESIDENTS

Effective Date: June, 2023

This Privacy Addendum was updated June, 2023

1. Introduction

This Privacy Addendum for California Residents (the “California Privacy Addendum”) supplements the information contained in UpScript’s Privacy Policy and further describes our collection and use of Personal Information (as defined below) . This California Privacy Addendum applies solely to all visitors, users, and others who reside in the State of California (“Consumers” or “you”). We adopt this notice to comply with the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, the “CPRA”), and any terms defined in the CPRA have the same meaning when used in this notice.

2. Scope of this California Privacy Addendum

This California Privacy Addendum applies to information that we collect on or through our Website that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your device (“Personal Information”). However, publicly available information that we collect from government records and deidentified or aggregated information (when de-identified or aggregated as described in the CPRA) are not considered Personal Information and this California Privacy Addendum does not apply.

This California Privacy Addendum does not apply to employment-related Personal Information collected from our California-based employees, job applicants, contractors, or similar individuals (“Personnel”). Please contact your local human resources department if you are part of our California Personnel and would like additional information about how we process your Personal Information.

This California Privacy Addendum also does not apply to certain Personal Information that is excluded from the scope of the CPRA, like: health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.

3. Information We Collect About You and How We Collect It

We have collected some or all of the following categories of personal information over the twelve (12) month period prior to the last revision date of this Policy:

Category
Applicable Pieces of Personal Information Collected
A. Identifiers.
A real name; postal address; unique personal identifier; online identifier; Internet Protocol address; and email address.
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).

A name; physical characteristics or description; address; telephone number; credit card number, debit card number, or any other financial information; physician and medical information.
Some Personal Information included in this category may overlap with other categories.
C. Protected classification characteristics under California or federal law.
Age (40 years or older); medical condition; and sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions).
D. Biometric information.
Genetic, physiological, behavioral, and biological characteristics; and sleep, or health data.
E. Internet or other similar network activity.
Information on a Consumer’s interaction with a website, application, or advertisement, including traffic data, log file information, operating system, browser type, mobile network information, and device ID.
F. Sensory data.
Audio; visual; or similar information.
G. Sensitive Personal Information (“Sensitive Personal Information”)
  • Complete account access credentials (user names; account numbers; or card numbers combined with required access/security code or password)
  • Precise geolocation (within an area of less than 1850 feet)
  • Health or medical information
  • Racial or ethnic origin
  • Genetic data
  • Mail; email; or text messages contents not directed to us
  • Unique identifying biometric information
  • Sex life or sexual orientation information

UpScript will not collect additional categories of Personal Information without providing you notice.

4. Sources of Personal Information

We collect Personal Information about you from the sources described in our Privacy Policy.

5. Purposes for Our Collection of Your Personal Information

We only use your Personal Information for the purposes described in our Privacy Policy.

We may use, “share” for the purposes of cross-context behavioral advertising, or disclose the Personal Information we collect. Over the prior twelve (12) months, we have used shared for the purpose of cross-context behavioral advertising, or disclosed the Personal Information we have collected, for the purposes described in our Privacy Policy as well as the following additional purposes:

  • Performing services on behalf of UpScript, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business or service provider.

UpScript will not use the Personal Information we collect for materially different, unrelated, or incompatible purposes without providing you notice.

6. Third Parties to Whom We Disclose Your Personal Information for Business Purposes

UpScript may disclose your Personal Information to third parties for one or more business purposes. When we disclose Personal Information to non-affiliated third parties for a business purpose, we enter a contract that describes the purpose, requires the recipient to both keep that Personal Information confidential and not use it for any purpose except for the purposes for which the Personal Information was disclosed, and requires the recipient to otherwise comply with the requirements of the CPRA.

In the preceding twelve (12) months, UpScript has disclosed the following categories of Personal Information for one or more of the business purposes described below to the following categories of third parties:

Personal Information Category
Categories of Service Providers, Non-Service Providers and Non-Contractor Third Party Recipients
A. Identifiers.
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))

Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
C. Protected classification characteristics under California or federal law.
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
D. Biometric information.
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
E. Internet or other similar network activity.
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.
F. Sensory data.
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.

 

Sensitive Personal Information Category
Categories of Third-Party Recipients
Genetic data
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
Unique identifying biometric information

Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
Health, sex life, or sexual orientation information
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.

 

We disclose your Personal Information to the categories of third parties listed above for the following business purposes:

  • Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with this specification and other standards.
  • Helping to enhance and manage the security and integrity of our products, services, and IT infrastructure to the extent the use of the Personal Information is reasonably necessary and proportionate for these purposes.
  • Debugging to identify and repair errors that impair existing intended functionality of our Platform, products, or services.
  • Performing services on behalf of us, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of us.
  • Providing advertising and marketing services, including interest-based, cross-context behavioral advertising, to Consumers.
  • Undertaking internal research for technological development and demonstration.

In addition to the above, we may disclose any or all categories of Personal Information to any third party (including government entities and/or law enforcement entities) as necessary to:

  • comply with federal, state, or local laws or to comply with a court order or subpoena to provide information;
  • comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities;
  • cooperate with law enforcement agencies concerning conduct or activities that we (or one of our service providers) believe may violate federal, state, or local law;
  • comply with certain government agency requests for emergency access to your Personal Information if you are at risk or danger of death or serious physical injury; or
  • exercise or defend legal claims.

7. To Whom Do We Sell or Share Your Personal Information

“Sale” of Your Personal Information for Monetary or Other Valuable Consideration

In the preceding twelve (12) months, UpScript has not “sold” your Personal Information as the term “sell” is commonly understood to require an exchange for money.

However, the use of advertising and analytics cookies on our website(s) is considered a “sale” of Personal Information as the term “sale” is broadly defined in the CPRA to include both monetary and other valuable consideration. Our “sale” would be limited to our use of third-party advertising and analytics cookies and their use in providing you behavioral advertising and their use in understanding how people use and interact with our website(s). Our “sales” of your Personal Information in this matter is subject to your right to opt-out of those sales (see Your Choices Regarding our “Sale” or “Sharing” of your Personal Information).

“Sharing” of Your Personal Information for Cross-Context Behavioral Advertising

UpScript may “share” your Personal Information for the purpose of cross-context behavioral advertising, subject to your right to opt-out of that sharing (see Your Choices Regarding our “Sale” or “Sharing” of your Personal Information). Our “sharing” for the purpose of cross-context behavioral advertising would be limited to our use of third-party advertising cookies and their use in providing you cross-context behavioral advertising (i.e., advertising on other websites or in other mediums). When the recipients of your Personal Information disclosed for the purpose of cross-context behavioral advertising are also permitted to use your Personal Information to provide advertising to others, we also consider this disclosure as a “sale” for monetary or other valuable consideration under the CPRA.

In the preceding twelve (12) months, UpScript has “sold” for monetary or other valuable consideration, or “shared” for the purpose of cross-context behavioral advertising, the following categories of Personal Information to the following categories of third parties:

Personal Information Category
May be Sold or Shared
Categories of Third Parties To Whom Your Personal Information may be Sold or Shared
A. Identifiers.
Sold and Shared
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Shared
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
C. Protected classification characteristics under California or federal law.
Shared
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
D. Biometric information.
Shared
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
E. Internet or other similar network activity.
Sold and Shared
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.
F. Sensory data.
Shared
Service providers, advertisers and advertising networks, business partners, affiliates, parents, and subsidiary organizations of UpScript, social media companies, and Internet cookie information recipients, such as analytics and behavioral advertising services, government entities, operating systems and platforms, data brokers and aggregators, and other third parties.

 

Sensitive Personal Information Category
May be Sold or Shared
Categories of Third Parties To Whom Your Personal Information may be Sold or Shared
Genetic data
Shared

Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
Unique identifying biometric information
Shared
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.
Health, sex life, or sexual orientation information
Shared
Business partners, affiliates, parents, and subsidiary organizations of UpScript, government entities, and operating systems and platforms.

 

Sale of Personal Information of Minors Under the Age of 16

We do not “sell” Personal Information of minors under the age of 16 for monetary or other valuable consideration, and we do not “share” such Personal Information for cross-context behavioral advertising without affirmative consent as required by the CPRA. More information on how minors under the age of 16 may change their choice regarding the “sale” or “sharing” of their Personal Information can be found in Your Choices Regarding our “Sale” or “Sharing” of your Personal Information).

8. Consumer Data Requests

The CPRA provides California residents with specific rights regarding their Personal Information. This section describes your CPRA rights and explains how to exercise those rights. You may exercise these rights yourself or through your Authorized Agent. For more information on how you or your Authorized Agent can exercise your rights, please see Exercising Your CPRA Privacy Rights.

  • Right to Know. You have the right to request that UpScript disclose certain information to you about our collection and use of your Personal Information over the past 12 months (a “Right to Know” Consumer Request). This includes: (a) the categories of Personal Information we have collected about you; (b) the categories of sources from which that Personal Information came from; (c) our purposes for collecting this Personal Information; (d) the categories of third parties with whom we have shared your Personal Information; and (e) if we have “sold” or “shared” or disclosed your Personal Information, a list of categories of third parties to whom we “sold” or “shared” your Personal Information, and a separate list of the categories of third parties to whom we disclosed your Personal Information to. You must specifically describe if you are making a Right to Know request or a Data Portability Request. If you would like to make both a Right to Know Consumer Request and a Data Portability Consumer Request you must make both requests clear in your request. If it is not reasonably clear from your request, we will only process your request as a Right to Know request. You may make a Right to Know or a Data Portability Consumer Request a total of two (2) times within a 12-month period at no charge.
  • Access to Specific Pieces of Information (Data Portability). You also have the right to request that UpScript provide you with a copy of the specific pieces of Personal Information that we have collected about you, including any Personal Information that we have created or otherwise received from a third-party about you (a “Data Portability” Consumer Request). If you make a Data Portability Consumer Request electronically, we will provide you with a copy of your Personal Information in a portable and, to the extent technically feasible, readily reusable format that allows you to transmit the Personal Information to another third-party. You must specifically describe if you are making a Right to Know request or a Data Portability request. If you would like to make both a Right to Know Consumer Request and a Data Portability Consumer Request you must make both requests clear in your request. If it is not reasonably clear from your request, we will only process your request as a Right to Know request. In response to a Data Portability Consumer Request, we are not permitted to disclose and will not disclose certain Sensitive Personal Information, health insurance or medical identification number, or your account password or security question or answers. We will also not provide this information if the disclosure would create a substantial, articulable, and unreasonable risk to your Personal Information, your account with UpScript, or the security of our systems or networks. We also will not disclose any Personal Information that may be subject to another exception under the CPRA. If we are unable to disclose certain pieces of your Personal Information, we will describe generally the types of personal information that we were unable to disclose and provide you a description of the reason we are unable to disclose it. You may make a Right to Know or a Data Portability Consumer Request a total of two (2) times within a 12-month period at no charge.
  • Correction. You have the right to request that we correct any incorrect Personal Information about you to ensure that it is complete, accurate, and as current as possible. You may also request that we correct the Personal Information we have about you as described below under Exercising Your CPRA Privacy Rights. In some cases, we may require you to provide reasonable documentation to show that the Personal Information we have about you is incorrect and what the correct Personal Information may be. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect or if the Personal Information is subject to another exception under the CPRA.
  • Deletion. You have the right to request that UpScript delete any of your Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your Consumer Request (see Exercising Your CPRA Privacy Rights), we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies pursuant to the CPRA. Some exceptions to your right to delete include, but are not limited to, if we are required to retain your Personal Information to complete the transaction or provide you the goods and services for which we collected the Personal Information or otherwise perform under our contract with you, to detect security incidents or protect against other malicious activities, and to comply with legal obligations. We may also retain your Personal Information for other internal and lawful uses that are compatible with the context in which we collected it.
  • Non-Discrimination. We will not discriminate against you for exercising any of your CPRA rights. Unless permitted by the CPRA, we will not do any of the following as a result of you exercising your CPRA rights: (a) deny you goods or services; (b) charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; (c) provide you a different level or quality of goods or services; or (d) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

 

Exercising Your CPRA Privacy Rights

To exercise the rights described above, please submit a request (a “Consumer Request”) to us by either:

If you fail to make your Consumer Request in accordance with the ways described above, we may either treat your request as if it had been submitted with our methods described above or provide you with information on how to submit the request or remedy any deficiencies with your request.

Only you, or your Authorized Agent whom you authorize to act on your behalf, may make a Consumer Request related to your Personal Information. If applicable, you may also make a Consumer Request on behalf of your minor child. To designate an Authorized Agent, see Authorized Agents below.

All Consumer Requests must:

  • Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an Authorized Agent of such a person. This may include:
  • Full name, phone number, and email address associated with your account.
  • Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm which Personal Information relates to you or the individual for whom you are making the request as their Authorized Agent.

Making a Consumer Request does not require you to create an account with us.

We will only use Personal Information provided in a Consumer Request to verify the requestor’s identity or authority to make the request.

Authorized Agents

You may authorize your agent to exercise your rights under the CPRA on your behalf by registering your agent with the California Secretary of State or by providing them with power of attorney to exercise your rights in accordance with applicable laws (an “Authorized Agent”). We may request that your Authorized Agent submit proof of identity and that they have been authorized to exercise your rights on your behalf. We may deny a request from your Authorized Agent to exercise your rights on your behalf if they fail to submit adequate proof of identity or adequate proof that they have the authority to exercise your rights.

9. Your Choices Regarding our “Sale” or “Sharing” of Your Personal Information

“Sale” of Your Personal Information

If you are 16 years of age or older, you have the right to direct us to not sell your Personal Information for monetary or other valuable consideration at any time (the “right to opt-out”). We do not sell the Personal Information of Consumers we know are less than 16 years of age, unless we receive affirmative authorization (the “right to opt-in”) from either the Consumer who is between 13 and 16 years of age, or the parent or guardian of a Consumer less than 13 years of age. Consumers who opt-in to Personal Information sales may opt-out of future sales at any time.

“Sharing” of Your Personal Information

If you are 16 years of age or older, you have the right to direct us to not share your Personal Information for the purposes of cross-context behavioral advertising, which is showing advertising on other websites or other media based on your browsing history with our Website (the “right to opt-out”). We do not share the Personal Information of Consumers we actually know are less than 16 years of age for this purpose, unless we receive affirmative authorization from either the Consumer who is between 13 and 16 years of age, or the parent or guardian of a Consumer less than 13 years of age. Consumers who opt-in to our sharing of Personal Information for these purposes may opt-out of future such sharing at any time.

How You May Opt-Out of Our Sale or Sharing of Your Personal Information

To exercise the right to opt-out of the “sale” of your Personal Information for monetary or other valuable consideration and of “sharing” your Personal Information for the purposes of cross-context behavioral advertising, you (or your authorized representative) may:

  • Adjust your cookie preferences by setting your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. However, if you do not consent to our use of cookies or select this setting, you may be unable to access certain parts of our Website or other websites. You can find more information about cookies at http://www.allaboutcookies.org and http://youronlinechoices.eu.
  • Using our Opt-Out button
Checkbox ImageDo Not Sell or Share My Personal Information

When we receive one of these privacy control signals, we will opt you out of any further “sales” or “sharing” of your Personal Information when you interact with our Website through that browser and on that device. We will only be able to add your choice to opt-out to your account if you are currently logged in when we receive the privacy control signal from your browser. When we are able to add your choice to your account, you will be opted out of “sale” or “sharing” of your Personal Information on all browsers and devices on which you are logged in, and for both online and offline “sales” and “sharing.”

Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize Personal Information sales. However, you may change your mind and opt back into the sale of Personal Information at any time by exercising your opt-out rights as described in this notice.

You do not need to create an account with us to exercise your opt-out rights. You may be required to provide us with additional contact information so that we may verify your request to opt-in to the sale of your Personal Information. We will only use Personal Information provided in an opt-out request to review and comply with the request.

If you (or your Authorized Agent) submit a request to opt-in to our “sale” or “sharing” of your Personal Information, we will use a two-step process in order to confirm that you want to opt-in for such “sale” or “sharing” of your Personal Information. This process may include verifying your request through your email address on record, calling you on your phone number on record (which may be through the use of an automated dialer), sending you a text message and requesting that you text us a confirmation (which may be through the use of an automated dialer) or sending you a confirmation through US mail. By making a Consumer Request, you consent to us contacting you in one or more of these ways.

10. Your Choices Regarding Our Use and Disclosure of Your Sensitive Personal Information

We may use or disclose your Sensitive Personal Information for the following purposes:

  • To perform the services or provide the goods or services reasonably expected by an average Consumer who requests such goods or services;
  • To detect security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted Personal Information, provided that our use of your Personal Information is reasonably necessary and proportionate for such purposes;
  • To resist malicious, deceptive, fraudulent, or illegal actions directed at UpScript and to prosecute those responsible for those actions, provided that our use of your Personal Information is reasonably necessary and proportionate for this purpose;
  • To ensure the safety of natural persons, provided that our use of your Personal Information is reasonably necessary and proportionate for this purpose; and
  • To perform services on behalf of us, such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of us.

How You May Limit the Use of your Sensitive Personal Information

You may limit our use and disclosure of your Sensitive Personal Information to only the above uses, you (or your authorized representative) may submit a request to us by via the contact information below. When you ask us to limit our use and disclosure of your Sensitive Personal Information, we will still use your Sensitive Personal Information for the above purposes, but no other purposes.

Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize our use or disclosure of your Sensitive Personal Information for purposes other than those listed above. However, you may change your mind and opt back into our use and disclosure of your Sensitive Personal Information at any time by making the request via the contact information below

You do not need to create an account with us to exercise your rights to limit our use and disclosure of your Sensitive Personal Information. You may be required to provide us with additional contact information so that we may verify your request to limit the use and disclosure of your Sensitive Personal Information to the above purposes. We will only use Personal Information provided in a request to limit the use and disclosure of your Sensitive Personal Information to review and comply with the request.

11. Retention of Personal Data

We will keep your Personal Information for no longer than is necessary for the purpose(s) it was provided for. Further details of the periods for which we retain Personal Data are available on request. However, we may retain any or all categories of Personal Data when your information is subject to one of the following exceptions:

  • When stored in our backup and disaster recovery systems. Your Personal Data will be deleted when the backup media your Personal Data is stored on expires or when our disaster recovery systems are updated.
  • When necessary for us to exercise or defend legal claims.
  • When necessary to comply with a legal obligation.
  • When necessary to help ensure the security and integrity of our Websites and IT systems.

12. Other California Privacy Rights

Shine the Light

California Civil Code Section 1798.83 (California’s “Shine the Light” law) permits users of our Website that are California residents and who provide Personal Information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of Personal Information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared your Personal Information with for the immediately prior calendar year (e.g., requests made in 2023 will receive information regarding such activities in 2022). You may request this information once per calendar year. To make such a request, please send an email to service@GetContrave.com or write us at our postal address at the bottom of this Addendum.

13. Changes to This CPRA Privacy Addendum

UpScript reserves the right to amend this California Privacy Addendum at our discretion and at any time. It is our policy to post any changes we make on this page with a notice that the California Privacy Addendum has been updated on the Website’s home page. If we make material changes to how we treat our users’ Personal Information, we will notify you by email to the email address specified in your account and/or through a notice on the Website’s home page. The date this California Privacy Addendum was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and reviewing this California Privacy Addendum to check for any changes. Your continued use of our Website following the posting of changes constitutes your acceptance of such changes.

14. Contact Information

If you have any questions or comments about this California Privacy Addendum, the ways in which UpScript collects and uses your information described above and in the Privacy Policy, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us at: