DATA PRIVACY POLICY

Organization: Distinctive Systems Inc.

Effective Date: October 1, 2026

1. Introduction and Commitment

Distinctive Systems, Inc. (hereafter "the Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data across all jurisdictions in which we operate. This Privacy Policy details our compliance, practices, and obligations under:

  • The EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce.
  • The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian provincial privacy legislation (including Quebec's Law 25, BC PIPA, and Alberta PIPA).

The Company complies with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. The Company has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles regarding personal data received from the European Union and the United Kingdom (and Gibraltar). If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the DPF program, visit https://www.dataprivacyframework.gov/.

2. Scope of Operations and Data Processed

The Company operates primarily as an authorized reseller and support provider of application software developed and published by our partner, Distinctive Systems Ltd., located in the United Kingdom. In this capacity, we facilitate corporate software licensing, deployment, technical implementation, and customer support for commercial entities across North America (United States and Canada).

This policy applies to all personal data received, processed, or stored by the Company in connection with our software reselling operations, technical support desk, and commercial activities.

3. Categories of Personal Data Collected and Retention

We collect and process only the minimum personal data necessary to fulfill our contractual and professional obligations.

This data typically includes:

  • Business Contact Information: Name, corporate job title, business email address, physical corporate address, and corporate telephone numbers.
  • Account and Transactional Records: Software license key identifiers, organization purchase history, contract details, and system registration credentials.
  • Technical and Support Data: Information provided voluntarily during technical assistance requests, including diagnostic log files, error descriptions, screenshots, software configuration attributes, and communication history with our help desk.

We do not sell personal information or share it for cross-context behavioral advertising.

Note on Sensitive Information: The Company does not actively solicit or process sensitive personal data (e.g., social security numbers, health data, precise geolocation, financial account credentials, genetic/biometric data, or trade union membership).

4. Purposes of Data Processing

The Company processes personal data exclusively for the following business purposes:

  1. Executing, delivering, maintaining, and validating software licensing agreements purchased by corporate end-users.
  2. Providing technical help desk support, remote troubleshooting, system optimization, and product updates related to the application software.
  3. Managing corporate customer relationships, processing invoicing, managing accounts receivable, and performing standard sales operations.
  4. Coordinating directly with the UK software publisher, Distinctive Systems Ltd., regarding software bug remediation, patch delivery, and escalation of core engineering support.
  5. Fulfilling legal obligations, protecting against security incidents, and preventing fraudulent or unauthorized software activity.

5. Onward Transfers and Cross-Border Transfers

To support our software distribution ecosystem, the Company transfers personal data across international borders under strict contractual and legal safeguards:

  • Transfers to the UK Software Publisher: As an authorized reseller, customer account identifiers, technical support queries, and operational telemetry may be transferred to Distinctive Systems Ltd. in the United Kingdom to resolve complex software engineering faults, manage global license key verification, or validate legitimate software usage.
  • Transfers to Third-Party Service Providers: We engage vetted third-party service providers (cloud infrastructure hosts, CRM platforms, billing gateways, communication tools) to perform operational tasks on our behalf. These service providers are bound by strict contractual data processing agreements restricting their use of data solely to the provided service.
  • Cross-Border Notice for Canadian Residents: Personal data collected in Canada may be transferred to, stored, or processed in the United States and the United Kingdom. While in those foreign jurisdictions, personal data may be accessible to foreign courts, law enforcement, and national security authorities under local legal orders.
  • DPF Accountability & Liability: The Company remains liable under DPF Principles if a third-party agent processes personal data in a manner inconsistent with DPF Principles, unless the Company proves it is not responsible for the event giving rise to damage.
  • Lawful Disclosure Requests: We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

6. California Consumer Privacy Statement (CCPA / CPRA Notice)

This section applies solely to residents of the State of California ("California Consumers") in accordance with the CCPA and CPRA.

A. Your California Privacy Rights

If you are a California resident, you have specific rights regarding your personal information:

  • Right to Know / Access: You have the right to request that we disclose the categories and specific pieces of personal information collected, the sources of collection, the business purpose for collection, and the categories of third parties to whom data was disclosed.
  • Right to Delete: You have the right to request the deletion of your personal information collected or maintained by us, subject to legal exceptions (such as retaining records for legal compliance or ongoing contracts).
  • Right to Correct: You have the right to request the correction of inaccurate personal information maintained in our systems.
  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information for monetary or other valuable consideration, nor do we share your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: Because we do not collect or process sensitive personal information for inferring characteristics, this right is automatically satisfied.
  • Right to Non-Discrimination: We will not discriminate against you (e.g., deny services, charge different prices, or provide a lower quality of service) for exercising any of your CCPA/CPRA rights.

B. Submitting a California Request

To exercise your CCPA/CPRA rights, submit a verifiable consumer request to us by:

Verification Process: We will verify your identity by matching data points provided in your request against data already retained in our system (e.g., confirming corporate email and recent license identifiers). You may designate an authorized agent to make a request on your behalf by providing written power of attorney or signed authorization.

7. Canadian Privacy Statement (PIPEDA & Provincial Compliance)

This section applies to individuals residing in Canada whose personal information is collected, used, or disclosed in the course of commercial activities.

A. Compliance Principles & Consent

We adhere to PIPEDA's Fair Information Principles and relevant provincial requirements (including Quebec Law 25):

  • Meaningful Consent: By purchasing, installing, or requesting support for our distributed software, or communicating with our team, you provide implied consent for the collection and use of your commercial contact and technical information for the purposes specified herein. Where explicit consent is required, we will obtain it at or before the time of collection.
  • Withdrawal of Consent: You may withdraw your consent to our continued collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions and reasonable notice. Note that withdrawing consent may impair our ability to deliver technical support or manage active software licenses.
  • Accountability: We have designated a dedicated Privacy Officer responsible for ensuring compliance with Canadian privacy regulations (see Section 10).

B. Access, Rectification, and Complaints in Canada

Canadian residents have the right to request access to their personal information, challenge its accuracy and completeness, and request corrections.

If you are a Canadian resident and believe your privacy rights have been infringed, you may contact our Privacy Officer. If our internal review does not resolve your concern, you have the right to lodge a complaint with:

  • Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca
  • Relevant Provincial Commissioners: E.g., Commission d'accès à l'information du Québec (CAI), Office of the Information and Privacy Commissioner for British Columbia (OIPC BC), or Information and Privacy Commissioner of Alberta.

8. General Individual Rights and Opt-Out Controls

Regardless of your geographic location, all users maintain the following core controls:

  • Third-Party Disclosures Opt-Out: You may opt-out of having your personal data disclosed to non-agent third parties by submitting a request to our privacy team.
  • Purpose Limitation Opt-Out: You may opt-out of having your personal data used for a purpose materially different from the original collection purpose or subsequent authorization.
  • Communication Preferences: You can opt-out of receiving promotional or corporate news updates by following the unsubscribe link in any email communication.

9. Data Security and Safeguards

The Company maintains technical, physical, and organizational security measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. These controls include encrypted transmission protocols (TLS/SSL), role-based administrative access restrictions, endpoint security software, and regular backup routines.

10. Dispute Resolution, Recourse, and Regulatory Authorities

In compliance with the DPF Principles, CCPA, and Canadian privacy frameworks, we commit to resolving complaints about your privacy and our collection or use of your personal information.

A. Internal Escalation

Contact us first with any inquiry or complaint:

Response Time: We will investigate and respond to all complaints within 45 days of receipt.

B. Independent Recourse Mechanism (DPF Unresolved Complaints)

  • If your DPF complaint cannot be resolved through these internal channels, the Company has committed to refer unresolved complaints to Judicial Arbitration and Mediation Services (JAMS), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of this independent recourse mechanism are provided at no cost to you.
  • Cost: This independent recourse mechanism is provided at no cost to the individual.

C. Binding Arbitration (DPF)

Under certain conditions, EU and UK individuals may invoke binding arbitration for unresolved DPF claims after other dispute resolution procedures have been exhausted (see Annex I of the DPF Principles).

D. Regulatory Oversight Bodies

  • United States: Federal Trade Commission (FTC) & California Privacy Protection Agency (CPPA) / California Attorney General.
  • United Kingdom: Information Commissioner’s Office (ICO).
  • Canada: Office of the Privacy Commissioner of Canada (OPC) and applicable provincial authorities.

11. Designated Privacy Officer & Contact Information

To submit rights requests, request policy clarifications, or lodge a formal inquiry, please contact our designated Privacy Compliance Officer:

  • Attn: Robert Hopwood
  • Company Name: Distinctive Systems, Inc.
  • Address: 19531 Lost Creek Drive, Estero, FL  33967
  • Email: naprivacy@distinctivesystems.com
  • Telephone: 646-448-9981