PRIVACY POLICY

NORTH AMERICA AND ASIA PRIVACY NOTICE

This Privacy Policy applies to the Johns Manville (“we,” “our” or “us”) websites hosted in the United States, including without limitation http://www.jm.com(each, a “Site” and collectively, the “Sites”), the applications we have placed on third-party websites, including without limitation, third-party social networking services, and our mobile application[s] (collectively, the “Applications,” and together with the Site, the “Service”), and describes the information that we collect through the Service and how we use it, how we protect it and the choices you can make about your information.

If you do not agree with the terms of this Privacy Policy or the Terms and Conditions of Use of the Service (“Terms”), you should immediately stop using or visiting the Service. Please note that other privacy policies and terms and conditions may apply regarding the Service.

CONSENT:

If you are located outside of the United States, please note that the Sites and Services referenced are hosted in the United States. Therefore, your information may be processed and stored in the United States. As a result, United States federal and state governments, courts or law enforcement or regulatory agencies may be able to obtain disclosure of your information through laws applicable in the United States. Your use of the Service or your submission of any information to us will constitute your consent to the transfer of your information outside of your home country, including the United States, which may provide for different data protection rules than in your country.

By using the Service or allowing someone to use the Service on your behalf, you expressly consent to the collection, use, disclosure and storage of your information and other information received by us as a result of such use in accordance with this Privacy Policy and to the Terms. If you do not agree with the terms of this Privacy Policy or the Terms, you should immediately stop using or visiting the Service. Please note that other privacy policies and terms and conditions may apply regarding the Applications.

Information We Collect

We collect the following types of information in the manner described below.

1. You may voluntarily provide us with information, including:

  • Your name, title, company name, postal address, email address, telephone number, password and other information to use the Service;
  • Information when you respond to surveys or otherwise contact or interact with us; and
  • Any other information you voluntarily provide us with, including your comments and other content in connection with using the Service.

2. Any information we may receive through a third-party social networking service may be used as described in this Privacy Policy.

3. We may automatically collect other information about you, including:

  • An identifier that is unique to the device on which you install our mobile application(s) and some device identifiers may be persistent device identifiers, as well as certain software and hardware information about your device;
  • Your Internet Protocol (IP) address;
  • Your geographic location;
  • The Site pages that you visit and the time of your visits; and
  • Aggregated information that cannot be used to specifically identify you when you use or visit the Service.

4. We may combine all of the information we collect from or about you and use it in the manner described in this Privacy Policy.

Third-Party Social Networking Services

We may interact with registered users of various third-party social networking services. Please note that any content you post to such third-party social networking services (e.g., pictures, information or opinions), as well as any information that you otherwise make available to users (e.g., your profile), is subject to the applicable third-party social networking service’s privacy policy and terms and conditions. We recommend that you review this information carefully to better understand your rights and obligations with regard to such content and information. Please see Your Choices Regarding Your Information below.

How We Use Your Information

We use the information that we collect for the following purposes, including:

  • The purposes for which you provided it;
  • To respond to your inquiries;
  • For fulfillment of requests;
  • To identify you as a user of the Service;
  • To send you information about your relationship with us;
  • To allow you to participate in surveys;
  • To contact you with information, including promotional information, that we believe will be of interest to you;
  • To process and respond to your inquiries;
  • To improve the Service or develop new services;
  • To provide the services you request, including the Service;
  • To create anonymous data, which we may use for any purpose;
  • To analyze the Service;
  • To allow us to personalize and enhance your experience using the Service;
  • To generate and review reports and data about our user base and service usage patterns;
  • To analyze the accuracy, effectiveness, usability or popularity of the Service;
  • To improve the content and features of the Service or develop new services;
  • To compile aggregate data for internal and external business purposes;
  • To prevent fraudulent transactions, monitor against theft and otherwise protect our users and our business;
  • To administer and troubleshoot the Service; and
  • As otherwise stated in this Privacy Policy, the Terms or the other privacy policies or terms and conditions regarding the Applications.

How Your Information is Disclosed

Information may be disclosed to third parties in accordance with our Privacy Policy. Please note that a user may choose not to share certain information as described in Your Choices Regarding Your Information below.

  1. Mobile applications. Regarding our mobile application(s), all requests are sent through your mobile network carrier’s network and your mobile carrier may have access to them. Please review your mobile carrier’s privacy policies for additional information.
  2. Third Parties. We may use third parties to perform functions in connection with the Site (for example, email, surveys, website hosting, video services, etc.). We may share information about you that they need to perform their functions and in accordance with our agreements with them.
  3. Business Changes. If we become involved in a merger, acquisition, sale of assets, securities offering, bankruptcy, reorganization, dissolution, or other transaction or if the ownership of all or substantially all of our business otherwise changes, we may share or transfer your information to a third party or parties in connection therewith.
  4. Subsidiaries and Affiliates. We may also share your information with our subsidiaries and affiliates for purposes consistent with this Privacy Policy. Our subsidiaries and affiliates will be required to maintain that information in accordance with this Privacy Policy.
  5. Investigations and Law. Regardless of the choices you make regarding your information (as described below), we may disclose information about you to third parties to:
  • Enforce or apply the Terms, any applicable end user license agreement or the other privacy policies and terms and conditions regarding the Applications;
  • Comply with law, in response to subpoenas, warrants, or court orders, or in connection with any legal process or cooperate with government or law enforcement officials or private parties;
  • Protect our rights, reputation, safety and property, or that of our users or others;
  • Protect against legal liability;
  • Establish or exercise our rights to defend against legal claims; or
  • To investigate, prevent or take action regarding suspected illegal activities, suspected fraud, the rights, reputation, safety or property of us, users or others, violation of the Terms, our policies or agreements, the other privacy policies and terms and conditions regarding the Applications or as otherwise required by law.

6. Aggregated Information. We may share aggregated information relating to visitors to and users of the Service with affiliated or unaffiliated third parties.

7. Cookies, Other Storage, Web Beacons, Persistent Device Identifiers and Other Technologies. Please see Cookies, Other Storage, web Beacons, Persistent Device Identifiers and Other Technologies below.

Cookies, Other Storage, Web Beacons, Persistent Device Identifiers and Other Technologies

We, along with third parties, use cookies, other storage, web beacons, persistent device identifiers and other technologies. These technologies are used for tracking, analytics and personalization and optimization of the Service.

1. Cookies. Cookies are small bits of information that are transferred to and stored in separate files within your computer’s browser. You can instruct your browser to stop accepting cookies. But if you do not accept cookies, you may not be able to use all portions or all functionality of the Service.

  • Persistent cookies remain on the visitor’s computer after the browser has been closed.
  • Session cookies exist only during a visitor’s online session and disappear from the visitor’s computer when they close the browser software.

2. Other Storage. Flash cookies (also known as local stored objects) are data files that can be created on your computer by the websites you visit and are a way for websites to store information for later use. Flash cookies are stored in different parts of your computer from ordinary browser cookies. You can disable the storage of flash cookies. For additional information about managing and disabling flash cookies, please visit http://helpx.adobe.com/flash-player/kb/disable-local-shared-objects-flash.html.

3. Web Beacons. Web beacons are small strings of code that provide a method for delivering a graphic image on a Web page or in an email message for the purpose of transferring data. You can disable the ability of web beacons to capture information by blocking cookies.

4. Persistent Device Identifiers. Persistent device identifiers are unique strings that are associated with the device that you use to connect to the Service. Persistent device identifiers may be modified or disabled by sophisticated users.

Please see http://www.networkadvertising.org/choices/ to opt-out of third party advertising, including the following vendors: Chango, DataXu, Google, MaxPoint Interactive, MediaMath, and Rocket Fuel.

Security

While we take reasonable measures to protect the information you submit via the Service against loss, theft and unauthorized use, disclosure, or modification, we cannot guarantee its absolute security. No Internet or email transmission is ever fully secure or error free. Email sent to or from the Service may not be secure. You should use caution whenever submitting information online and take special care in deciding what information you send to us via email.

Links to Other Websites

This Privacy Policy applies only to the Service. The Service may contain links to other websites and applications to which this Privacy Policy does not apply. The links from the Service do not imply that we endorse or have reviewed these websites [or applications]. The policies and procedures we describe here do not apply to these websites or applications. We neither can control nor are responsible for the privacy practices or content of these websites and applications. We suggest contacting these websites or applications directly for information on their privacy policies.

Your Choices Regarding Your Information

You have choices regarding the use of information on the Service.

  1. Changing Your Information. You may make changes to your information, including keeping your information accurate, by contacting us at privacy@jm.com.
  2. Email Communications. You can make changes regarding receiving email communications from us by contacting us at privacy@jm.com.

You may opt-out of all information collection by uninstalling our mobile application(s). You may use the standard uninstall, application and data management processes available as part of your mobile device or via the removal features provided in your chosen mobile application store or network. Once you have uninstalled our mobile application(s), all information stored is deleted.

  1. Cookies, Other Storage, Web Beacons, Persistent Device Identifiers and Other Technologies. Please see Cookies, Other Storage, Web Beacons, Persistent Device Identifiers and Other Technologies above.
  2. Social Networking. You should make sure you are comfortable with the information that a third-party social networking service may make available to us by carefully reviewing the service’s privacy policy and terms and conditions and by modifying your privacy settings directly on that service. Please see Third-Party Social Networking Services above.

Children

We do not knowingly collect personal information from children under age 13. If you are under the age of 13, please do not submit any personal information through the Service. If you have reason to believe that we may have accidentally received personal information from a child under age 13, please contact us immediately at privacy@jm.com.

Changes to Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time and from time to time without prior notice. Please review this Privacy Policy periodically, and especially before you provide any information. This Privacy Policy was made effective on the date indicated above.

How to Contact Us

Please also feel free to contact us at privacy@jm.com if you have any questions about this Privacy Policy.

EU PRIVACY NOTICE 

Effective date: November 25, 2019

Introduction

Johns Manville (“JM,” “we,” “us,” “our”) is committed to fulfilling our responsibilities under the European Union’s General Data Protection Regulation (“GDPR”) in relation to the collection, retention, use, and other processing of EU personal data.  This Privacy Notice sets forth how we process EU personal data obtained via our websites – including www.jm.comwww.jmroofing.newswww.jmroofing.eventswww.jmextramile.comwww.jmtcsafety.comhomeinsulation@jm.com, www.jminsulationinsider.com, and www.jmgoboard.com (collectively, the “Sites”) – in our role as a data controller (i.e., when we are responsible for determining the purpose and means of the processing).

Personal Data We Collect

Personal data collected via the Sites may include:

●       Contact data.  You may provide us with your contact details, such as your name, phone number, home address, company name, job title, and email address (for example, when you contact us, provide website feedback, or register for classes or trainings (e.g., through Johns Manville Roofing Institute)).

●       Authentication Data.  To verify the identity of registered users we may collect a user name, password, and other similar authentication information (for example, if you register an email press release account we will ask that you provide a username and password).

●       Account Information.  In addition to contact data, when creating an account on one of the Sites you may provide us with additional information about yourself (for example, if you register an email press release account, you may provide us with URLS to your website, blog, Twitter, Facebook, and LinkedIn, and, if you are an accredited member of the news media, a picture of your media badge).

 

●       Interests and Notification Preferences.  The Sites may provide mechanisms for you to sign up for notifications regarding products and promotions JM believes are of interest to you based on our interests and preferences (for example, through our Submittal Wizard).

●       Business Project Information.  You may submit information related to your business projects, including information on the project’s address (for example, through our Submittal Wizard or when you submit a Services Request).

●       Supplier Application Information.  You may provide information about yourself and your company such as your contact information and your company’s contact information (for example, if you apply to become one of our suppliers through the Supplier Partnership contact form).

●       Job Application Information.  If you apply for a job through our Careers Page we or our vendor may collect personal data such as your name, e-mail address, physical address, phone number, and CV.

●       Device Information.  We may obtain information about devices that access our Sites, including the type of device, its operating system, device settings, unique device identifiers, and error data.

●       Location Information.  The Sites may use GPS (global positioning systems) software, geo-filtering, and other location-aware technologies to locate you (sometimes precisely) (note: you may be able to toggle on or off location technologies using your internet browser (e.g., Google Chrome); if you disable location technologies, you may not be able to use certain features of this Sites).

●       Information About Others.  The Sites may also allow you submit personal data about third parties (for example, when registering for in-person or on-site classes or trainings, you may provide information related to your emergency contact including their name, phone number, and other contact information).  When you submit personal data about third parties, you represent that you have obtained the third party’s consent to disclose their personal data to us.

●       Other Information You Provide.  This includes emails and other communications that you send us or otherwise contribute such as feedback and user support inquiries regarding the Sites (note: please be aware that information you post on public parts of our Sites may be visible to anyone).

How and Why We Use Your Personal Data

We may process personal data to:

●        Transact with you, respond to your comments, questions and requests, provide customer service, send you informational notices, and contact you if we need to obtain or provide additional information.

●        Process your Sites registration and identify you as a user.

●        Verify your location and deliver or restrict content based on your location.

●        Facilitate, manage, personalize, and improve our user and partner relationships.

●        Prevent and address fraud, breach of policies or terms, and threats or harm.

●        Ensure the security and integrity of the personal data we process.

●        Comply with applicable legal requirements.

Our processing of such personal data is carried out pursuant to the following legal bases:

●        The processing is necessary for us to provide you with the products and services you request, or to respond to your inquiries.

●        We have a legal obligation to process your personal data, such as to comply with applicable tax and other government regulations or to comply with a court order or binding law enforcement request.

●        To protect your vital interests, or those of others.

●        We have a legitimate interest in carrying out the processing activity.  In particular, we have a legitimate interest in the following cases:

o   To analyze and improve the safety and security of the Sites.  This includes implementing and enhancing security measures and protections and protecting against fraud, spam, and abuse.

o   To maintain and improve the Sites.

o   To operate the Sites and provide you with certain tailored information and communications to develop and promote our network and opportunities.

●        You have consented to the use of your personal data.  When you consent, you can change your mind at any time.

If we make a material change to how we process your personal data, we will notify you as appropriate and may also modify this Privacy Notice.

How We May Share Your Personal Data

We may share your personal data:

●        With our affiliates, partner organizations, or suppliers when it is reasonably necessary or desirable, such as to help provide services to you or analyze and improve the Sites.

●        With our staff, agents, vendors, consultants, and other service providers who perform functions on our behalf.  For example, we may use third parties to help us provide customer support, manage our advertisements on other platforms, and send marketing and other communications on our behalf.

●        To abide by applicable law or protect rights and interests.  For example, we may disclose your personal data if we determine that such disclosure is reasonably necessary to comply with the law, protect our or others’ rights, property, or interests, or prevent fraud or abuse. 

●        If we are involved in a reorganization, merger, acquisition, or sale of some or all of our assets.

How We Use Tracking Technologies

We may utilize online identification tools—such as cookies, web beacons, pixels or similar tracking technologies—in accordance with applicable law and requirements.  “Cookies” are small text files placed on your device when you visit a website; they store information which is sent back to our servers or those of third parties.  As described in more detail below, we use such technologies to:

●       Recognize new or past users.

●       Store your profile or authentication credentials if you are registered on the Sites.

●       Improve the Sites and to better understand your use of the Sites.

●       Integrate with third-party social media websites.

●       Serve you with interest-based or targeted advertising.

●       Observe your behaviors and browsing activities over time across multiple websites or other platforms.

●       Better understand the interests of our Sites users.

Some cookies are required for certain uses of the Sites.  For example, if you choose to register an account through the Sites, we will use cookies to facilitate your registration and remember your preferences.

Different types of cookies may be used for specific purposes, for example:

●       Functional cookies and cookies from third parties may be used for analysis and marketing purposes.  Functional cookies enable certain parts of the website to work properly, retain user preferences, and allow users to log in using social network user credentials.

●       Analysis cookies may collect information on how visitors use a website, the content and products that website users view most frequently, and the effectiveness of third-party advertising.

●       Advertising cookies assist in delivering ads to relevant audiences.  This may include, for example, placing ads at the top of search results.

Cookies are either “session” cookies which are deleted when you end your browser session, or “persistent” cookies, which remain until you delete them or the party who served the cookie removes it.

Through your device or browser settings you may change your settings to disallow certain Sites’ features, disabling certain tracking technologies.  For example, turning off location tracking through your device’s or browser’s settings will disable the Sites’ location tracking technologies.  You can set your browser settings either to receive our cookies or use our Sites without cookie functionality.  To control flash cookies visit this link.  Please note that if you restrict the use of tracking technologies, some functions of the Sites may be unavailable, and we will not be able to present you with personally-tailored content.

We may link the information collected by tracking technologies with other information we collect from you pursuant to this Privacy Notice.  Similarly, the third parties who serve tracking technologies on our Sites may link personal data we collect from you to other information they collect.  Specifically, we may use Google Analytics.  To opt out of Google Analytics, visit their opt-out mechanism.

For more information on our use of tracking technologies and cookies, contact us at privacy@jm.com.

How We Protect Your Personal Data

We maintain appropriate technical and organizational safeguards designed to help protect personal data from unauthorized disclosure or access and accidental or unlawful destruction, loss, or alteration.  Although we use reasonable efforts to safeguard personal data, we cannot guarantee the security of your information obtained through the Sites.

How Long We Retain Your Personal Data

We will store your personal data for no longer than is necessary for the performance of our obligations or to achieve the purposes for which the information was collected, or as may be permitted under applicable law.  To determine the appropriate retention period, we will consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure of the data; the purposes for which we process the data and whether we can achieve those purposes through other means; and the applicable legal requirements.  Unless otherwise required by applicable law, at the end of the retention period we will remove personal data from our systems and records or take appropriate steps to properly anonymize it.

Links to Third-Party Websites

Some features of the Sites may open your preferred internet browser on your device and allow you to access certain third-party websites.  These websites are governed by their own privacy policies, terms, and cookie policies.  We encourage you to read the policies and terms of websites that the Sites may link to.

Personal Data Transfers

If we transfer your personal data out of the European Economic Area (“EEA”) to countries not deemed by the European Commission to provide an adequate level of personal data protection, the transfer will be based on one of the following safeguards recognized by the European Commission as providing adequate protection for personal data, where required by EU data protection legislation:

  • Contracts approved by the European Commission which impose data protection obligations on the parties to the transfer.
  • The EU – U.S. Privacy Shield Framework (for transfers to third parties in the United States that have self-certified to the Framework).

For further information on the mechanism(s) used to transfer your personal data, please contact us at privacy@jm.com.

Your Rights and Choices

The GDPR provides EU data subjects with certain rights regarding their personal data.  Subject to certain conditions, you may ask us to take the following actions in relation to your personal data that we hold:

●        Provide you with information about our processing of your personal data and give you access to your personal data.

●        Update or correct inaccuracies in your personal data.

●        Delete your personal data.

●        Transfer a machine-readable copy of your personal data to you or a third party of your choice.

●        Restrict the processing of your personal data.

●        Object to our processing of your personal data for direct marketing purposes.

●        Object to reliance on our legitimate interests as the basis for processing of your personal data.

You may exercise some of these rights and choices through Sites’ features such as editing your account settings when you are logged in.  Additionally, you can submit these requests by email to privacy@jm.com or our postal address provided below.  We may request specific information from you to help us confirm your identity prior to processing your request.  Applicable law may require or permit us to decline your request.  If we decline your request, we will tell you why, subject to legal restrictions.

If you would like to submit a complaint about our use of your personal data or our response to your requests regarding your personal data, you may contact us at privacy@jm.com or submit a complaint to the data protection regulator in your jurisdiction.  You can find information about your data protection regulator here.

How to Contact Us

To make a query, raise a concern, or exercise your data protection rights, please contact us at privacy@jm.com.

The data controller for your personal data is Johns Manville, which you may contact by via email at privacy@jm.com or at the following address:

Johns Manville

717 17th Street, 12th floor

Denver, CO 80202

Attn: Data Privacy