01. Data Controller
The Contracting Entity that determines the purposes and means of processing shall be the primary controller of your personal data. Other HSO entities may act as processors, subprocessors or independent controllers depending on the actual data flow, service provided and applicable internal arrangements. For privacy requests, contact legal@huronsmithoil.com.
02. Personal Data we Collect
We may collect the following categories of personal data, depending on your interaction with us:
- Identification and contact data: first and last name, email address, phone number, postal address, company position and industry sector.
- Registration and account data: username, encrypted password, communication preferences and profile settings.
- Billing and payment data: information necessary to process payments (credit/debit card details, billing address). We do not store full payment card data on our servers; this is managed securely and exclusively by PCI-DSS Level 1 certified payment gateways.
- Usage and browsing data: IP address, device type, operating system, browser, pages visited, interactions on the Site, access and API usage logs, as well as activity on the trading platform.
- Communication data: content of inquiries, support tickets, emails and any other communication you send us.
03. Purposes of Processing and Legal Bases
We process your personal data for the following purposes, based on the legal bases indicated:
- Performance of a contract or pre-contractual measures: managing your registration, providing the products and services purchased, facilitating participation in trading processes, processing payments, making shipments and providing technical support and customer service.
- Compliance with legal obligations: keeping accounting and tax records, responding to requests from judicial or administrative authorities, complying with AML/CFT regulations and security breach notification.
- Legitimate interests of HSO: improving our products and services through aggregated usage analysis, protecting the security and integrity of our systems, preventing fraud and abuse, and sending you commercial communications about products or services similar to those you have already contracted (always with a clear and easy option to unsubscribe).
- Explicit consent: where required by law, we will request your prior, informed and explicit consent for purposes such as sending newsletters, installing non-essential cookies or participating in promotional activities. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out previously.
04. How we Share your Information
We do not sell your personal data for monetary consideration. Where we use cookies, pixels or advertising technologies that may constitute a “sale” or “sharing” under certain privacy laws, we will provide the required notice, consent or opt-out mechanisms, including, where applicable, a “Do Not Sell or Share My Personal Information” option. We may share your information exclusively with:
- Essential service providers: companies that assist us in the operation of the business (web hosting, payment gateways, analytics tools, email delivery services, identity verification platforms), always under strict contractual agreements that oblige them to process data only according to our instructions and to implement equivalent security measures.
- Authorities and regulatory bodies: when necessary to comply with the law, respond to legal processes, protect our rights or cooperate in official investigations.
- Business transfer: in the event of a merger, acquisition, restructuring or sale of all or part of our assets, personal data may be transferred to the acquiring entity, always respecting applicable legal guarantees.
05. International Data Transfers
Your personal data may be stored and processed on servers located in the United States and, in certain cases, in other countries where our service providers have facilities. Where the GDPR applies because data subjects are located in the European Union and an international transfer is subject to that regime, HSO will use appropriate mechanisms, such as Standard Contractual Clauses, transfer assessments and reasonable supplementary measures. If HSO targets services to individuals located in the European Union in a manner that triggers GDPR Article 27, it will appoint an EU representative as appropriate.
06. Data Subject Rights (Florida, Mississippi, and California)
If you are a resident of Florida, Mississippi or California, and to the extent granted by applicable law, you may exercise the following rights:
- Right of access and portability: request confirmation as to whether we are processing your personal data and obtain a copy thereof in a structured, commonly used and machine-readable format.
- Right of rectification: request the correction of any inaccurate or incomplete personal data.
- Right of deletion (“right to be forgotten”): request the deletion of your personal data, unless there is a legal obligation requiring us to keep them.
- Right to restriction of processing: obtain the restriction of the processing of your data in certain circumstances, including the restriction of the processing of sensitive data as provided in the Florida Digital Bill of Rights (SB 262).
- Right to non-discrimination: you will not be subject to retaliation or discrimination for exercising any of your privacy rights.
To exercise your rights, send a request by email to legal@huronsmithoil.com with the subject “Privacy Rights Request”. To protect your information, we may ask you to verify your identity before processing the request. We will respond within the timeframes established by applicable law.
07. Security Breach Notification
In the event of a security breach compromising unprotected personal data, HSO will notify affected individuals without undue delay and competent authorities where legally required. For Florida residents, notification will be made in accordance with FIPA, including the thirty (30) day timeframe where applicable. For Mississippi residents, HSO will follow the Mississippi Security Breach Notification Law and any other applicable legal requirement.
08. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes for which they were collected, including the retention periods required by tax, commercial and anti-money laundering laws. As a general rule, data related to financial transactions and contractual relationships will be retained for a period of five (5) to seven (7) years from the end of the relationship. After these periods, the data will be securely deleted or anonymized.
09. Data Security
We implement and maintain appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, disclosure or destruction. These measures include:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
- Network segmentation and access controls based on roles and minimum privileges.
- Security audits and penetration testing periodically conducted by independent external entities.
- Internal security policies and mandatory training for all staff.
10. Cookie Policy
For detailed information about the cookies and similar technologies we use, as well as to manage your preferences and grant or revoke your consent, please consult our Cookie Policy.
11. Modifications to the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices or applicable law. The updated version will be published on the Site with a new “last updated” date. If the changes are substantial, we will notify you through the contact means you have provided (email) or by a prominent notice on the Site.
12. Privacy Contact
For any questions, comments or requests regarding this Privacy Policy or the processing of your personal data, please contact our Privacy Officer:
- Email: legal@huronsmithoil.com
- Phone: +1 (866) 954-5938
- Postal Address: 204 Hays St, Batesville, Mississippi, 38606, USA