Our policy is designed to ensure the safety and accuracy of our clients and their customers’ personal information. Any information revealed to us will never be sold, rented, traded, or leased. CST adheres to all HIPAA Administrative Simplification Regulations found at 45 CFR 160, 162, and 164. All CST employees and independent contractors are required to complete the requisite training courses upon hire and annually thereafter.
CST holds a certification that it is in full compliance with the EU–U.S. Privacy Shield Framework and the Swiss–U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information from European Union member countries and Switzerland to the United States, respectively. CST adheres to the Privacy Shield privacy principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Privacy Shield program, please visit the Privacy Shield website, which includes the Privacy Shield privacy principles of notice, choice, onward transfer, security, data integrity, access, and enforcement.
CST’s EU–U.S. Privacy Shield and Swiss–U.S. Privacy Shield certifications
For complaints and disputes that cannot be resolved between CST and the complainant, CST has agreed to participate in the dispute resolution procedures of the panel established by the EU data protection authorities (DPAs), and the Swiss Federal Data Protection and Information (Swiss FDPIC) to resolve disputes pursuant to the Privacy Shield privacy principles. Individual DPAs may be contacted directly via the information provided on the Privacy Shield website. If your complaint is not resolved, you may have the ability to invoke binding arbitration. Please see the Privacy Shield website if you have questions on this topic.
Each and every person who works with CST, either as a direct employee in the central offices or as a contract interpreter, receives training in compliance with confidentiality and nondisclosure laws. This training takes place prior to the employee or contractor ever working with the customer in any form. Further, questions pertaining to their understanding of this information are incorporated into our testing program. Periodic review of this information takes place via quarterly training updates. As part of our employee initiation program, every employee is required to read, understand, and sign our proprietary employee manual, which includes all documentation that supports confidentiality, HIPAA, and Privacy Shield requirements.
CST is constantly aware of the necessity to keep all documentation and recordings regarding our customers and their clients in strict confidentiality. We have implemented the following procedures to ensure that our practice of protecting private information is followed. These practices are consistently reviewed and updated and include:
- Strict guidelines require that Customer confidential information never leave our secure office.
- We have contacts within the Centers for Medicare and Medicaid Services (CMS) and the U.S. Office for Civil Rights (OCR), both of which specialize in HIPAA compliance. These contacts evaluate our practices and advise us, ensuring our practices are HIPAA compliant.
- No confidential information is available on the web. All data is stored securely in-house.
- Our premises are not open to the public; the doors are locked and solely accessible via regulated key cards.
- Every employee has a strict confidentiality agreement with emphasis on HIPAA and Privacy Shield compliance.
- Interpreters are bound by signed confidentiality and HIPAA compliance agreements.
In order to provide our services, we may collect the following types of information:
- Information you provide – When you sign up for services with CST, we ask you for personal information (such as your name, email address, phone number, other account information, and an account password). For certain accounts, we accept credit card or other payment account information that we maintain in encrypted form on secure servers.
- User communications – When you send an email or other communications to CST, we may retain those communications in order to process your inquiries, respond to your requests, and improve our services.
When you sign up for our interpreter services, the only confidential information that is necessarily exchanged is the information that the interpreter is relaying between the two parties.
CST does record some telephone interpreting calls with permission from our customers. These recordings are made strictly for internal quality assurance purposes and are securely retained for 90 days, at which point they are destroyed.
- Call recordings are encrypted with an encryption level of at least 256AES.
- Access to call recordings is limited to authorized staff.
- Recordings are kept securely on the premise only.
Upon request, CST will provide you with information on whether we hold, or process on behalf of a third party, your personal information. To request this information, please contact us via email at email@example.com.
When notified by email or mail, CST will make a reasonable effort to correct, amend, or delete such Personal Data if such data is demonstrated to be inaccurate or incomplete.
CST only shares personal information with other companies or individuals outside of CST in the following limited circumstances:
- We have your consent. We require opt-in consent for the sharing of any sensitive personal information.
- We have a good faith belief that access, use, preservation, or disclosure of such information is reasonably necessary to (a) satisfy any applicable law, regulation, legal process, or enforceable governmental request; (b) enforce applicable Terms of Service, including investigation of potential violations thereof; © detect, prevent, or otherwise address fraud, security, or technical issues; or (d) protect against imminent harm to the rights, property, or safety of CST, its users, or the public as required or permitted by law.
We take appropriate security measures to protect against unauthorized access to or unauthorized alteration, disclosure, or destruction of data. These include internal reviews of our data collection, storage, and processing practices and security measures, as well as physical security measures to guard against unauthorized access to systems where we store personal data.
We restrict access to personal information to CST employees, contractors, and agents who need to know that information in order to operate, develop, or improve our services. These individuals are bound by confidentiality obligations and may be subject to discipline, including termination and criminal prosecution if they fail to meet these obligations. Additionally, CST maintains current certification for compliance with PCI data security standards.
CST is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. CST complies with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions. With respect to personal data received or transferred pursuant to the Privacy Shield Framework, CST is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, CST may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
c/o ClearSource Translation
604 Sycamore St., Suite 202
Hamilton, OH 45011 USA
CST PII POLICY
We are committed to protecting your personal information and rights to privacy. If you have any questions about our policy or how we handle your personal information, please contact firstname.lastname@example.org.
TABLE OF CONTENTS
INFORMATION COLLECTED THAT YOU DISCLOSE TO US
INFORMATION WE COLLECT ABOUT YOU
HOW DO WE PROTECT YOUR INFORMATION?
DO WE SHARE YOUR INFORMATION WITH THIRD PARTIES?
WHAT ARE MY PRIVACY RIGHTS?
DO WE COLLECT INFORMATION FROM MINORS?
CALIFORNIA ONLINE PRIVACY PROTECTION ACT
CALIFORNIA CONSUMER PRIVACY ACT
DO WE MAKE UPDATES TO THIS POLICY?
1. INFORMATION COLLECTED THAT YOU DISCLOSE TO US
What personal information do we collect from the users that visit our website?
While on our website, as appropriate, you may be asked to enter your name, email address, mailing address, phone number, or other details to help you with your experience.
When do we collect information?
We collect information from you when you subscribe to a newsletter, fill out a contact form, or any other instance where you manually enter information on our site.
How do we use your information?
In addition to the stated purpose of information gathering, such as newsletters, email signups, contact requests, etc., we may use the information we collect from you to:
- Personalize your experience and allow us to deliver the type of content and service offerings in which you are most interested.
- Improve our website in order to better serve you.
- Ask for ratings and reviews of services.
- Respond to your queries and requests for a quote.
- Provide you with support for our services.
- Remind you of CST and our services when you visit another site.
- Contact you via email about company information, new services that may interest you, and other marketing-related communications.
- Display advertisements about CST on other websites you visit.
2. INFORMATION WE COLLECT ABOUT YOU
We collect information from you directly and automatically when you visit, use, or navigate through our website.
We collect information directly from you through the following:
Contact forms: If you submit a contact form through our website, we collect your first and last name, email address, telephone number (optional), company name (optional), and information pertaining to your request or query.
Quote forms: If you submit a quote form through our website, we collect your email address, industry, location (state), language needs, estimated minutes per month, and how you arrived at our site.
Newsletters, webinars, and other marketing materials: If you sign up to receive our marketing materials, we collect your first and last name, email address, industry, company name, and other data as required.
We collect information automatically from you through the following:
Analytics information: Our website automatically collects data via Google Analytics and other similar services, including your IP addresses, browser and device characteristics, operating systems, language preferences, referring URLs, device names, countries, location information, how and when you use our site, and/or other general browsing or usage data.
Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your web browser (if you allow it) that enable our website’s or service provider’s systems to recognize your browser and capture and remember certain information.
- Keep track of, show, and send targeted advertisements.
- Help us understand your preferences based on previous or current site activity, which enables us to provide you with improved services and advertising.
- Compile aggregate data about site traffic and site interactions in order to offer better site experiences and tools in the future. We may also use trusted third-party services that track this information on our behalf.
If you clicked “Accept” on the banner that appeared when you first visited our website, you have consented to our cookies for the purposes stated above. You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You can do this through your browser settings. Since each browser is different, look at your browser’s Help menu to learn the correct way to modify your cookies.
If you turn cookies off, it may affect the user experience.
Google Analytics disclaimer
In case of activation of the IP anonymization, Google will truncate/anonymize the last octet of the IP address for member states of the European Union as well as for other parties to the Agreement on the European Economic Area. Only in exceptional cases, the full IP address is sent to and shortened by Google servers in the U.S.
On behalf of the website provider, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators, and providing other services relating to website activity and internet usage to the website provider.
You can prevent Google’s collection and use of data (cookies and IP address) by downloading and installing the browser plug-in available.
3. HOW DO WE PROTECT YOUR INFORMATION?
Our website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our site as safe as possible.
Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive you supply is encrypted via Secure Socket Layer (SSL) technology.
We implement a variety of security measures when a user enters and submit their information to maintain the safety of their personal information.
4. DO WE SHARE YOUR INFORMATION WITH THIRD PARTIES?
We will only share and disclose your personal information in these situations:
- Legal Compliance: Your information may be disclosed if we are legally obliged to do so to comply with applicable law, government requests, judicial proceedings, court orders, or legal processes.
- Vital Interests and Legal Rights: If we believe it is necessary to investigate or take action due to a violation of our policies, suspected fraud, threats of illegal activity, or as evidence in litigation in which we are involved.
- Business Transfers: We may share or transfer information in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- With Your Consent: We may disclose your personal information for any reason with your consent.
We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information unless we provide users with advance notice. This does not include website hosting partners and other parties who assist us in operating our website, conducting our business, or serving our users, so long as those parties agree to keep this information confidential.
Occasionally, at our discretion, we may link to third-party products, services, or content on our website. These third-party sites have separate and independent privacy policies. We, therefore, have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
5. WHAT ARE MY PRIVACY RIGHTS?
You have the right to request changes, review, or terminate your data from our records at any time.
Fair Information Practices
In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur: We will notify you via email within 7 business days.
We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.
6. DO WE COLLECT INFORMATION FROM MINORS?
When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.
We do not specifically market to children under the age of 18 years old.
7. CALIFORNIA ONLINE PRIVACY PROTECTION ACT
Visit the Consumer Federation of California for more information about CalOPPA.
According to CalOPPA, we agree to the following:
- Users can visit our site anonymously.
You can change your personal information at any time by emailing us at email@example.com.
8. CALIFORNIA CONSUMER PRIVACY ACT (CCPA)
Your personal information
Following is the personal information that we collect about you and how we use it.
Information we collect about you: CST collects the information you willingly submit to us as well as some basic information when you visit our website. For a list of the information we collect, please see the section titled “Information we collect about you” in this policy.
How we use the information we collect: We use the information we collect from you to serve you better and/or to respond to queries received directly from you. Please see the section titled “How do we use your information?” in this policy for more details.
Do we sell personal information: No; CST never sells your personal information.
CCPA rights and choices
If you are a California resident, you have certain rights pertaining to the personal information CST has collected about you.
- You have the right to request (twice in a 12-month period) that we disclose what personal information we have collected about you.
- You have the right to request that we delete the personal information we have collected about you, subject to certain exemptions under the law.
- You have the right to not receive discriminatory treatment for exercising your privacy rights under this law.
Exercising your rights under CCPA
If you’d like to exercise your rights, please use the contact information below:
Phone: (530) 388-5152
9. CAN-SPAM ACT
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped being sent to them, and spells out tough penalties for violations.
We collect your email address in order to:
- Send information, respond to inquiries, and/or other requests or questions.
- Send you additional information related to your product and/or service.
- Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.
To be in accordance with CAN-SPAM, we agree to the following:
- Not use false or misleading subjects or email addresses.
- Identify the message as an advertisement in some reasonable way.
- Include the physical address of our business or site headquarters.
- Monitor third-party email marketing services for compliance, if one is used.
- Honor opt-out/unsubscribe requests quickly.
- Allow users to unsubscribe by using the link at the bottom of each email.
If at any time you would like to unsubscribe from receiving future emails, you can follow the instructions at the bottom of each email or email us at firstname.lastname@example.org and we will promptly remove you from ALL correspondence.
10. DO WE MAKE UPDATES TO THIS POLICY?
11. CONTACTING US
604 Sycamore St., Suite 202
Hamilton, OH 45011 USA
Last Edited on 1/19/2022