Biophotas, Inc. Privacy Notice
Last Modified: January 1, 2019
Biophotas, Inc. (“Biophotas,” “we”, “us”, or “our”) is responsible for this website and is the controller of data provided to us through it. We respect your privacy and aim to protect it along with your personal data. We currently operate the website Biophotas.com (“Website”). This Privacy Notice is incorporated into, and part of, the Terms and Conditions (the “Terms and Conditions”), which governs your use of these Website in general.
- Who We Are
This Site is published and maintained by or on behalf of Biophotas, Inc., with offices located at 1000 E. Howell Ave., Anaheim, CA 92805. Any questions about your data privacy or this Privacy Notice, please contact us at info@Biophotas.com, or by mail care of Biophotas Data Privacy.
Third Party Links
This website may include links to third-party website, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party website and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
- The Data We Collect About You and How We Collect It
We collect several different types of personal data from you depending on how you interact with our Website. Most of the information we collect is given to us by you through filling out forms, registering for an account, or otherwise providing information when asked. Occasionally, we do collect information about you without you providing it. Because we may change our website and the services we offer from time to time, the means and methods to provide us with personal data may also change. Depending on how you interact with us and use the website, the personal data we collect may vary.
Please read below for the common ways in which we collect your personal data.
Making a Purchase.
When you make a purchase on our Website, we collect your first and last name, company name (“Contact Information”), and your shipping and/or billing address, email (for order confirmation), and phone number (“Billing Information”). We use this information to process payment, process shipments of goods, and for legitimate interests like preventing fraud, facilitating returns, and providing customer service.
Creating an Account on the Website.
You are not required to create an account with Biophotas, but if you choose to create an account we ask you to provide an account password so that you may securely log-in to your account. This password is combined with your email address for account identification purposes (“Account Information”). By default, we’ll only use your personal data to administer your account and to provide the products and services you requested from us.
Contacting Us Online
At your option, you may send us a message through our Website and providing your Contact Information. If you do this, we will receive and store your communication with us in order to address your request. Additionally, if you email us, we will receive your email address and any other personal information you provide in or as an attachment to the email. We may share that information with third parties depending on the content of the email.
Contacting Us Via Telephone
We provide telephone number for you to contact us via telephone. If you call us, we may receive your telephone number and may record the phone call for quality assurance and security purposes.
Information Collected Automatically From Using Our Site
As you interact with the Biophotas Website, we may automatically collect information about your equipment, browsing actions and patterns (“Technical Data”). We collect this Technical Data by using cookies and other similar technologies. Technical Data may include you IP Address; device identifier data, the type of device you use, your operating system and version, the URL’s of our web pages that you visit, the URL’s of referring and exiting pages, the pages you view, the time spent on a page, the number of clicks made, the platform type, and generalized, non-specific location data. When we collect data that does not identify you as a natural person, we are permitted to use and disclose this information for any purpose, notwithstanding anything contrary in this Notice, except where prohibited by law.
- How We Use Your Personal Data.
We will only use your personal data when allowed by law. Generally, we will use your personal data: (a) with your consent; (b) where we need to perform the contract we are about to enter into or have entered into with you; (c) where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests; and (d) where we need to comply with a legal or regulatory obligation.
Purposes for which we will use your personal data
Below is a chart of some of the common ways in which we process your personal data. We have identified what our legitimate interests are where appropriate. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
Type of data
(varies depending on circumstances)
Lawful basis for processing including basis of legitimate interest
To fulfill a purchase order.
In furtherance of performance of a contract with you.
Notifying you about changes to our Terms & Conditions or Privacy Notice.
Necessary to comply with a legal obligation
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).
Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)
To provide you with information and marketing communications about our products and services.
Legitimate Interests (in marketing goods or services in which you may have a personal interest based on our ongoing business relationship).
To respond to customer service requests including order status and chat communications.
Legitimate Interest (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)
- Disclosures Of Your Personal Data
We may disclose your personal information to third parties on occassion. This disclosure may be required for us to provide you access to our Website, to send you our products, to comply with our legal obligations, to enforce our Terms and Conditions, to facilitate our marketing and advertising activities, or to prevent, detect, mitigate, and investigate fraudulent or illegal activities related to our Services. We attempt to minimize the amount of personal information we disclose to what is directly relevant and necessary to accomplish the specified purpose. We do not sell, rent, or otherwise disclose your personal information to third parties for their marketing and advertising purposes without your consent.
Third Party Service Providers. We may share your information, including but not limited to Contact Data and Technical Data, with third party service providers who perform various functions to enable us to provide our services and help us operate our business, such as website design, sending email communications, fraud detection and prevention, customer care, payment processing, or performing analytics. Our contracts with these third parties require them to maintain the confidentiality of the personal data we provide to them, only act on our behalf and under our instructions, and not use personal data for purposes other than the product or service they're providing to us or on our behalf. Third party shipping providers (e.g., DHL, UPS, USPS, etc.) with whom we share delivery address, contact information and shipment tracking information for the purposes of facilitating the delivery of items purchased and other delivery related communications.
Protection of Biophotas and Others. We may share personal data when we believe it is appropriate to enforce or apply our Terms and Conditions and other agreements; or protect the rights, property, or safety of BIOPHOTAS, our products and services, our users, or others. This includes exchanging information with other companies and organizations for fraud protection and risk reduction. This does not include selling, renting, sharing, or otherwise disclosing personal data of our customers for commercial purposes in violation of the commitments set forth in this Policy.
Response to Subpoenas and Other Legal Requests. We may share your information with courts, law enforcement agencies, or other government bodies when we have a good faith belief we're required or permitted to do so by law, including to meet national security or law enforcement requirements, to protect our company, or to respond to a court order, subpoena, search warrant, or other law enforcement request.
Sale of Our Business. If we sell, merge, or transfer any part of our business, we may be required to share your information. If so, you will be asked if you'd like to stop receiving promotional information following any change of control.
With your Consent. Other than as set out above, we will provide you with notice and the opportunity to choose when your personal data may be shared with other third parties.
- SMS Messages
We may make available a service through which you can receive messages on your wireless device via short message service (“SMS Service”). If you subscribe to one of our SMS Services, you thereby agree to receive SMS Service messages at the address you provide for such purposes. Such messages may come from Biophotas or third parties with which we share your phone number. You understand that your wireless carrier’s standard rates apply to these messages, and that you may change your mind at any time by following the instructions in the Right to Opt In and Opt Out section above. You represent that you are the owner or authorized user of the wireless device you use to sign up for the SMS Service, and that you are authorized to approve the applicable charges. To use the SMS Service, you must be 18 years of age or older and reside in the United States. You must first register and provide all required Personal Information, which may include, for example, your name, SMS address, wireless carrier and, if fees are applicable to the SMS Service you subscribe to, billing information (either your credit card information or mobile service carrier information if applicable fees will be billed through your carrier). We may also obtain the date, time and content of your messages in the course of your use of the SMS Service. We will use the information we obtain in connection with our SMS Service in accordance with this Privacy Notice. If fees are charged to your wireless account invoice, we may provide your carrier with your applicable information in connection therewith. Your wireless carrier and other service providers may also collect data about your wireless device usage, and their practices are governed by their own policies.
You acknowledge and agree that the SMS Service is provided via wireless systems which use radios (and other means) to transmit communications over complex networks. We do not guarantee that your use of the SMS Service will be private or secure, and we are not liable to you for any lack of privacy or security you may experience. You are fully responsible for taking precautions and providing security measures best suited for your situation and intended use of the SMS Service. We may also access the content of your account and/or wireless account with your carrier for the purpose of identifying and resolving technical problems and/or service related complaints.
By signing up for the SMS Service, you consent to receiving, from time to time, further messages which may include news, promotions and offers from us, our subsidiaries, entities owned, related to or controlled by us and partners, and you consent to our sharing of your Personal Information with such parties for such purposes, unless and until you have opted out of these activities by following the instructions in the Right to Opt In and Opt Out section above. Please follow the instructions provided to you by third parties to unsubscribe from their messages.
- Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
- Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. In some circumstances you can ask us to delete your data (see “EU Data Subjects Legal Rights”). In some circumstances we may anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
- International Data Transfers
Biophotas has its headquarters in the United States. Information we collect from you will be processed in the United States. Where we transfer your personal data to third party service providers outside of the European Economic Area (EEA), we rely on appropriate suitable safeguards or specific derogations recognized under data protections law, including the GDPR.
The European Commission has adopted standard data protection clauses, which provide safeguards for Personal Data transferred outside of the EEA. We may use Standard Contractual Clauses when transferring Personal Data from a country in the EEA to a country outside the EEA.
- EU Data Subjects Privacy Rights
EU data subjects have certain rights with respect to your personal data that we collect and process. We respond to all requests we receive from individuals in the EEA wishing to exercise their data protection rights in accordance with applicable data protection laws.
- Access, Correction or Deletion. You may request access to, correction of, or deletion of your personal data. You can often go directly into the Service under Account Settings to take these actions. Please note that even if you request for your personal data to be deleted, certain aspects may be retained for us to: meet our legal or regulatory compliance (e.g. maintaining records of transactions you have made with us); exercise, establish or defend legal claims; and to protect against fraudulent or abusive activity on our Service. Data retained for these purposes will be handled as described in Section 7 “Data Retention”, above.
- Objection. You may object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- Restriction. You have the right to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
- Portability. You have the right to request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw Consent. If we have collected and processed your personal data with your consent, you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal data conducted in reliance on lawful processing grounds other than consent.
- File a complaint. You have the right to file a complaint with a supervisory authority about our collection and processing of your personal data.
To file a request or take action on one of your rights, please contact us at the contact details provided. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
- Children’s Privacy
We are committed to complying with the Children's Online Privacy Protection Act (COPPA). Biophotas Website and services are not directed to children under the age of 16. We do not knowingly collect personal information from children under the age of 16. If we receive personal information that we discover was provided by a child under the age of 16, we will promptly destroy such information. Additional information is available on the Direct Marketing Association's home page at http://www.the-dma.org. If you would like to learn more about COPPA, visit the Federal Trade Commission home page at http://www.ftc.gov.
- Updates to Our Privacy Notice
By using this website, you agree to the terms and conditions contained in this Privacy Notice and Terms & Conditions and/or any other agreement that we might have with you. If you do not agree to any of these terms and conditions, you should not use this website. You agree that any dispute over privacy or the terms contained in this Privacy Notice will be governed by the laws of the State of California.
This Notice is expected to change from time to time. We reserve the right to amend this Notice at any time and provide notice to you by posting of the amended Privacy Notice on the website. We may also email you to give you notice of material changes to this Notice. The provisions contained herein supersede all previous notices or statements regarding our privacy practices and the terms and conditions that govern the use of this website.
- How to Contact Us
If you have any questions or wish to register a complaint in relation to this Privacy Notice or the manner in which your personal data is used by us, please contact us by any of the following means:
By Email: Info@BioPhotas.com
By Post: 1000 E. Howell Ave., Unit A, Anaheim, CA 92805
A Cookie is a piece of code that allows the web server to identify and track activity of the web browser. They are widely used in order to make websites work more efficiently, as well as to provide information to the owners of the website. We may use both “Session Cookies” and “Persistent Cookies” on this Website. Session Cookies will be deleted from your computer when you close your browser. Persistent Cookies will remain stored on your computer until deleted, or until they reach a specified expiry date.
Types of Cookies
Different cookies are used for different purposes. Our site may use these types of cookies:
- Analytics cookies. These cookies allow us to improve how our Website works, by allowing us and our third-party service providers to recognize and count the number of visitors and to see how visitors move around our Website when they are using it. These cookies generate aggregate statistics that are not associated with an individualized profile.
- Functionality cookies. These cookies are helpful to improve your Website experience, but are not essential. For example, these cookies help us recognize you return to our Website and personalize content for you.
- Advertising, tracking or targeting cookies. Ad cookies may allow us to record information about your visit to our Website so we can make our Website and the advertising displayed on it more relevant to your interests. They record things like pages visited and links clicked. These cookies enable us to share data, such as what you like, with our advertisers, so the advertisement you see can be more relevant to your preferences. They help us to understand shopping behavior of our visitors, which helps us to keep improving our Website for your benefit. These may also be Third-Party Cookies.
- Third-party cookies. Certain third party services and ad networks may display advertising on our Service, or manage our advertising on other websites. Such parties may use certain tracking technologies to collect certain information about your activities on the Services and different third party Services to provide you with targeted advertising based on your interests and preferences. You may opt-out of receiving targeted ads from certain advertisers and ad networks by visiting http://preferences.truste.com/ (or if you are located in the European Union visiting YourChoicesOnline.eu). Please note this does not opt you out of receiving all advertising.
Choosing Your Cookie Settings
You have a choice about the placement of cookies on our Website. Please visit our consent manager tool https://cellumastore.myshopify.com/pages/request-personal-data to make or manage your cookie use preferences. You may withdraw your consent for our cookie uses that are not strictly necessary at any time by re-engaging the consent manager tool.
You can also use your web browser to directly block all cookies, or just third-party cookies, through your browser settings. Using your browser settings to block all cookies, including strictly necessary ones, may interfere with proper site operation. Guidance on how to control cookies in popular browsers is contained here:
You can also find additional information on cookie controls and advertisement here:
- Network Advertising Initiative
- Digital Advertising Alliance
- European Interactive Digital Advertising Alliance
- Digital Advertising Alliance of Canada
Google allows users to opt out of tracking by Google Analytics and Google Analytics Demographics and Interest Reporting services. You can adjust your setting here, or download the Google Analytics Opt-Out Browser Add-on.
Do Not Track Signals
We do not currently respond to 'do not track' signals and similar settings or mechanisms. When you use the Website, we try to provide a customized experience.
Changes to Our Cookie Uses
Cross-Border Data Transfers
The cookies we use may process, store, or transfer personal data in and to a country outside your own, with privacy laws that provide different, possibly lower, protections. You consent to this transfer, storing, or processing when you consent to our cookie use. We are based in the United States.
Third Party Cookie Providers
If you have any questions or suggestions regarding this Policy, please contact us at Info@BioPhotas.com