WestRock Privacy Notice
WestRock Company, its subsidiaries and affiliates (collectively “WestRock”), is committed to protecting your privacy. This Privacy Notice describes WestRock’s practices regarding how we collect, use, share, and safeguard your personal information.
THE TYPES OF PERSONAL INFORMATION WE MAY COLLECT
WestRock collects data from you through our interactions with you. The types of data we collect depends on the context of your interactions with WestRock. We strive to collect only data that is necessary and appropriate.
To learn more about the categories of data we collect and the reasons we collect it, along with information that may also be legally relevant to you based on your location, please click on the links below.
- Information You Share With Us Via Email, Phone, Post, Through Online Forms, Chats, Or Via Social Media
When you contact us to learn more information about WestRock products or about WestRock as a company (i.e., investor relations) we collect certain data about you in order to respond to your request and provide you information about our products or our company.
Type of Information or Data |
Purpose for Collection |
Name and contact information (This may include email address, telephone number, postal address, social media handle, or other information we may use to respond to you). |
Enable communication |
Contents of communications |
Exchange information, respond to requests |
- Information You Share With Us as a Business Customer or Supplier
If you are a business customer of WestRock or a supplier or vendor to WestRock, we collect the following information in order to better serve our business relationship:
Type of Information or Data |
Purpose for Collection |
Contact Information (This may include email address, telephone number, postal address, social media handle, or other information we may use to respond to you). |
Enable communication |
Details of Communication (contents of emails, faxes, invoices, purchase orders, etc.) |
Make and respond to requests, exchange information, etc. |
User Account Information (user name, password, etc.) |
Use WestRock website, IT systems |
Company / Employer Information (name of employer, job title, names of managers and associates, transactional information, etc.) |
Associate business contact with correct business, conduct business |
Health-related information |
Protect the data subject or another person, such as during an epidemic |
Payment information |
Enable purchases |
We may maintain this information if you are a prospective, current, or former customer, supplier, or vendor of WestRock.
- WestRock Online Account Holder Information
With a WestRock account, you may sign in to certain portals or applications provided to certain WestRock customers.
Type of Information or Data |
Purpose for Collection |
Credentials / User Name |
Enable communication |
Name and contact information |
Enable communication |
Device and Usage data |
Improvement of our systems |
Information about your activities on the WestRock Links website |
Improvement of our systems |
- Information You Share With Us By Visiting Our Website or Mobile Applications
We automatically collect certain information about your use of WestRock’s online services and mobile applications, including your interaction with content and services available online. This information includes:
Type of Information or Data |
Purpose for Collection |
Data about your interaction with our platforms, including your IP address, location, operating system, browser, URLs of any pages you visit on our sites or apps, device identifiers, and other similar usage information. |
Ensure network and information security, continuity of service, improvement of our platforms |
Please click here for WestRock's Cookie Policy.
- Information You Share With Us as a Visitor On-site at a WestRock Facility
If you are visiting a WestRock facility in person, you may be asked to share certain information about yourself prior to entering our premises:
Type of Information or Data |
Purpose for Collection |
Contact Information (email address, telephone number, postal address, etc.) |
Enable communication |
Employer Information (name of employer, job title, names of managers and associates, transactional information, etc.) |
Associate business contact with correct business, conduct business |
Copy of Government Issued Identification |
Confirm identity |
In the United States you may be asked to share your vaccine status, recent health systems, and other information to prevent in the spread of COVID19 |
Protect our employees and partners from illness |
Closed circuit video images as permitted by applicable law |
Protect our facility |
- Information You Share With Us As a Job Applicant
Type of Information or Data |
Purpose for Collection |
Name and Related Information |
Identification |
Contact Information (email address, telephone number, postal address, etc.) |
Enable communication |
Application Information (resume/CV, application form, letter of application, supporting documents, etc.) |
Evaluate job candidate |
Details of Communication (Offer and Acceptance letters, contents of emails, faxes, etc.) |
Make and respond to requests, exchange information, etc. |
Special Data (Age, Disability, National Origin, Religion, Race/Ethnic Background, Sexual Orientation, etc.) |
Complete legally-required reporting; collected only where required |
Please note that WestRock employees may find information regarding WestRock’s privacy practices for employees in the WestRock Employee Data Privacy Notice, WestRock Acceptable Use Policy, and employee handbook. This information is available to WestRock employees on the Company website.
HOW WE USE THE PERSONAL INFORMATION WE RECEIVE
We use the information you share with us for different purposes depending on the context in which you interact with WestRock. For example, we use your information to:
- Provide you with services or products you request or might find beneficial;
- Communicate with you regarding WestRock, including information that may be relevant to investors;
- Provide customer support or to answer your questions;
- Enhance the security of our systems;
- Enhance our visitor experience on our website or applications;
- Protect the safety or our employees and contractors;
- Comply with applicable legal and regulatory requirements.
In summary, we use the information provided to us to operate our business globally, which includes the provision of services and products, analyzing our performance, meeting our legal and regulatory obligations, developing and securing our workforce, among other legitimate business functions.
You may find out more information about our legitimate interest or other relevant legal basis for processing by clicking on the jurisdiction specific links within this Notice.
How We Share and Safeguard Personal Information
We share certain information with third parties as listed herein, such as with vendors working on our behalf and our affiliates.
Storing and Retaining Personal Data
We retain your personal data for as long as is necessary for the purposes provided in this Notice or to meet other legal, regulatory, tax or accounting requirements.
We may keep an anonymized form of personal data, which will no longer refer to an individual person or have personally identifying information, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.
If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the data.
Selling and Sharing Personal Information
WestRock has not engaged in any activity that would constitute a sale of data within the last twelve months.
Special Notices
Australia Privacy Notice
With regard to processing of personal information regarding residents of Australia, WestRock provides the following additional information.
APP Entity
WestRock Company, located at the below address, is the “APP entity” for the processing activities identified in this Notice:
Attention: Global Privacy Office
WestRock
1000 Abernathy Road NE
Atlanta, Georgia 20228, United States of America
Disclosure of Personal Information
Disclosure Within WestRock
The WestRock group operates in many countries and may share your personal information among its affiliate companies (referred to in the Privacy Act as “related bodies corporate”) including those that operate in countries outside Australia. As WestRock is based in the US, the most likely recipients within WestRock are located in the US. WestRock has taken such steps as are reasonable in the circumstances to ensure that the overseas recipients do not breach the Australian Privacy Principles in relation to the information.
Disclosure Outside WestRock
Personal information may be disclosed to our outsourced service providers, including those located in Australia and those in other countries. WestRock has taken such steps as are reasonable in the circumstances to ensure that the overseas recipients do not breach the Australian Privacy Principles in relation to the information.
WestRock may transfer personal information to public authorities when we are required by law to do so.
Complaints about a breach of Australian Privacy Principles
WestRock takes seriously its responsibility to comply with Australian Privacy Principles. Individuals who notice a breach of these Principles may contact the WestRock Privacy Office (link to Contacting Our Privacy Office) to register a complaint.
We may request that you provide proof of your identity.
Exercising Your Rights Under the Privacy Act 1988 (as amended)
The Privacy Act provides certain specific rights to residents of Australia. This section of the Notice describes the rights that may be available to you and how you may exercise those rights with WestRock. In particular, you may:
- request access to your personal information;
- request that we correct any inaccurate and/or incomplete personal information that we store about you; and
- request not to receive direct marketing communications from WestRock.
To exercise one or more of these rights, please contact the WestRock Global Privacy Office (link to Contacting Our Privacy Office).
We may request that you provide proof of your identity.
Brazil Privacy Notice
Legal basis for processing. Under the Brazilian General Data Protection Law (the “LGPD”), a company must have a legitimate and specific purpose to process your personal information. The legal basis may be different for different types of processing of personal data, and may fall into one of the following categories:
Data Subjects/Categories of Data | Legal Basis |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Name and contact information, Content of communications
| Legitimate Interest |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Data about your interaction with our platforms, including your IP address, location, operating system, browser, URLs of any pages you visit on our sites or apps, device identifiers, and other similar usage information. | Legitimate Interest |
Business customers, suppliers or vendors, or employees or representatives of such an entity/ All Data | Legitimate Interest |
On-site Visitors/ All Data | Legitimate Interest |
Job Applicants/ All Data | Contract with the Data Subject |
Individual Rights. If you reside in Brazil the LGPD may provide you with certain privacy rights. This section of the Notice describes the rights that may be available to you and how you may exercise those rights with WestRock.
In particular, you may:
- Confirm that we are processing your personal data, and provide information about the processing;
- Provide access to your personal data;
- Update and correct incomplete, inaccurate or outdated data;
- Anonymize, block or delete unnecessary or excessive data, or data processed in non-compliance with the provisions in the LGPD;
- Provide a portable copy of your personal data;
- Delete personal data processed on the basis of consent, except for the situations where maintaining the data is necessary or allowed by legislation;
- Provide information on public and private entities with which we shared your personal data;
- Provide information on the possibility of not giving consent and the consequences of the refusal;
- Recognize that you have revoked consent to process your personal data, and take appropriate actions; and
- Review decisions made exclusively based on automated processing of your Personal Data.
To exercise one or more of these rights, please contact the WestRock Global Privacy Office. We may request that you provide proof of your identity.
WestRock will not discriminate against you based on your decision to exercise your rights.
California Privacy Notice
California Privacy Notice
Personal Information We Collect. The type of information we collect varies based on our interaction with you. For example, we collect more and different information from WestRock employees than we collect from WestRock online account holders. We strive to collect only data that is necessary and appropriate for the nature of our interaction with you. In most cases, we collect your personal information directly from you.
WestRock collects the following categories of personal information:
Category of Data |
Source of Data |
Business or Commercial Purpose of Processing |
Name, contact information, and other identifiers |
We usually collect this information directly from you.For example, you might give us your contact information so that we can provide you a quote on custom packaging solutions.In some cases, a third party may provide the information to us as part of a promotion.We make no representations as to how a third party may collect and use your information. |
To provide the products or services that you have requested or purchased; to refine our services and to communicate with you about WestRock and WestRock products; to communicate with you about services you provide to WestRock. |
Commercial information, including products or services purchased, obtained, or considered |
We collect this information when you shop at our on-line merchandise store, and as part of the warranty, rebate, and promotions processes. |
To provide the products or services that you have requested or purchased. |
Financial data such as bank account numbers, credit or debit card numbers, and similar information |
We use third party processors to facilitate any payments you may make to us online, so we do not store or have future access to your payment card information. We collect bank account information from employees and related persons for payroll and benefits purposes. |
To provide the products or services that you have requested or purchased and to manage our human resources and meet legal requirements. |
Internet and other electronic network activity |
When you visit our site, we collect information such as browsing activity on our site, ads viewed or clicked, and search terms used. Our systems automatically collect information such as IP address, browser type and language, operating system, device type, and hardware attributes from all website visitors. Use of WestRock’s internal electronic systems by persons performing services for WestRock is monitored in accordance with WestRock policy. |
To help diagnose technical issues and to ensure the security of our systems and data. To communicate with you about WestRock and WestRock products. |
Geolocation |
When you visit our website, you provide WestRock with a general location associated with your IP address. WestRock will sometimes request that website visitors directly provide more detailed location information in order to further assist you in locating our facilities. |
To provide location‑specific notices and services. To help you identify WestRock locations near you. To provide the products or services that you have requested or purchased. |
Audio, electronic, visual, or similar information |
Surveillance devices located on the premises of our facilities. Also, you may choose to access our social media platforms, where you may choose to provide photos and other user‑generated content. |
To ensure the physical security of our facilities and personnel and to refine our services and to communicate with you about WestRock and WestRock products. |
Professional or employment‑related information |
We collect this information from job applicants, employees, former employees, non-employees performing services for WestRock, and related persons, as a normal part of our human resources processes.This includes, as appropriate, union membership information.We may also collect this information from third-party networking sites, such as LinkedIn or service providers. Additionally, we collect data about the employers of WestRock online account holders from website visitors to facilitate business to business transactions. |
To manage our human resources and meet legal requirements. To transact business with other companies through their employees. |
Education Identifiers |
We collect this information from job applicants, employees, former employees, non-employees performing services for WestRock, and related persons, as a normal part of our human resources processes. We may also collect information from third party verification service providers. |
To manage our human resources and meet legal requirements. |
Sensitive Identifiers |
Under some circumstances, we may collect Social Security, driver’s license, state identification card, or passport numbers, union membership data, racial or ethnic origin identifiers, and information about religious or philosophical beliefs from job applicants, employees, former employees, non-employees performing services for WestRock, and related persons, as part of our human resources processes.
|
To manage our human resources and meet legal requirements.
|
Protected classifications under California or federal law |
We collect this information only as required by law, typically as part of the employment process. (For a list, see: https://www.senate.ca.gov/content/protected-classes) |
To manage our human resources and meet legal requirements. |
Inferences |
At WestRock, like many other companies, we use contextual customization of advertisements to enhance your visit to our website.We do not build a profile of your user experience but instead use this information to share advertisements with you after you have exited our website. |
To refine our services and to communicate with you about WestRock and WestRock products. |
Selling and Sharing of personal information for cross‑context behavioral advertising. WestRock does not sell your personal information for monetary consideration. However, our use of cookies and other tracking technologies, as well as the collection of personal information on our sites and applications by third parties, may be considered a “sale” or “sharing” under California law.
The following table represents the categories of personal information we have “sold” or “shared” in the last twelve months, the categories of recipients, and the business purpose for the “sale” or “sharing.”
Category of Data |
Category of Recipients |
Business Purpose for Selling/Sharing |
Name, contact information and other identifiers |
Advertisers and marketing partners, providers of data analytics, and social media networks |
To make the online advertisements you see more relevant to your interests, including advertisements for WestRock products and services. We may also share this information with data analytics service providers to improve our understanding of our relevant markets. |
Commercial information including products or services purchased, obtained, or considered |
Advertisers and marketing partners, providers of data analytics, and social media networks |
To make the online advertisements you see more relevant to your interests, including advertisements for WestRock products and services.We may also share this information with data analytics service providers to improve our understanding of our relevant markets. |
Internet and other electronic network activity |
Advertisers and marketing partners, providers of data analytics, and social media networks |
To make the online advertisements you see more relevant to your interests, including advertisements for WestRock products and services.We may also share this information with data analytics service providers to improve our understanding of our relevant markets. |
Other disclosures of personal information. As noted in the list below, we may disclose your personal information to vendors performing operational services on our behalf, including maintaining service accounts, providing customer service, processing or fulfilling orders and transactions, processing payments, providing marketing or advertising services, providing analytic services, providing data storage, processing employment-related information, administering employee benefits, or providing similar services.
As required under California's privacy laws, the table below lists the categories of personal information that WestRock has disclosed to third parties for a business purpose in the preceding 12 months:
Category of Data |
Category of Recipients |
Business or Commercial Purpose of Disclosure |
Name, contact information, and other identifiers |
Our service providers - like many businesses, WestRock uses vendors who provide customer services, advertisements/promotions, marketing services, process or fulfill orders and transactions, process payments, provide marketing or advertising services, and provide analytic, legal or insurance services. Government entities. Unions and Trade organizations. |
Respond to your questions and requests; Conduct business with you; Conduct business with your employer or a similar relevant entity; Ensure the security and integrity of our network, systems, and data; Track website usage; Collect employment-related information to manage our human resources and administer employee benefits; Comply with union labor agreements; Short-term, transient use. |
Commercial information, including products or services purchased, obtained, or considered |
Service providers performing operation services on our behalf. |
Respond to your questions and requests; Conduct business with you; Conduct business with your employer or a similar relevant entity; Short‑term transient use. |
Financial data such as bank account numbers, credit or debit card numbers, and similar information |
Service providers assisting us with processing payments or similar services |
Operational services on our behalf, including processing payments, processing employment-related information, administering employee benefits, or providing similar services. |
Internet and other electronic network activity |
Service providers performing operational services on our behalf, including assisting us in maintaining our website or providing similar services. |
Operational services on our behalf, including providing marketing or advertising services, assisting us in maintaining our website, or providing similar services. |
Geolocation |
Service providers |
Operational services on our behalf, including providing customer service, processing or fulfilling orders and transactions, or providing similar services. |
Professional or employment‑related information |
Service providers Unions and Trade Organizations |
Operational services on our behalf, including processing employment-related information, administering employee benefits, or providing similar services; complying with union and trade organization labor agreements. |
Education Identifiers |
Service providers |
Process employment‑related information to manage our human resources and administer employee benefits |
Sensitive personal information, including the protected classifications listed above, your Social Security, driver’s license, state identification card, or passport number; your account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; your precise geolocation; your racial or ethnic origin, religious or philosophical beliefs, or your union membership; the contents of your mail, email, and text messages (unless WestRock is the intended recipient of the communication); your genetic data; processing of biometric information for the purpose of uniquely identifying you; and personal information collected and analyzed concerning your health, sex life, or sexual orientation |
Our service providers; Government entities |
Process employment-related information to manage our human resources and administer employee benefits; Comply with legal requirements; (Note that this information is not disclosed for other purposes and these purposes do not infer characteristics about the individual.) |
Protected classifications under California or federal law. (for a list, see: https://www.senate.ca.gov/content/protected-classes) |
Our Service providers; Government entities |
Process employment‑related information to manage our human resources and administer employee benefits |
California Consumer Rights
California residents are entitled to certain rights under California privacy laws as follows:
Right to know and access personal information: The right to request that a business disclose: (1) the categories of personal information it has collected about you; (2) the sources from which the personal information is collected; (3) the business or commercial purpose for the collection, selling or sharing of personal information; (4) the categories of third parties to whom the business discloses personal information; (5) the categories of personal information that the business sold or disclosed for a business purpose about the consumer; and (6) the specific pieces of personal information it has collected about you.
Right to opt-out: The right to opt‑out of the sale or sharing of your personal information. If you opt‑out of the sharing of your personal information, that signal will apply to information associated with and activities under your WestRock Account. If you do not have a WestRock Account, the signal will apply to the device you are using instead.
Right to correct: The right to request that a business which maintains inaccurate personal information about you correct that inaccurate personal information, taking into account the nature of the personal information and the purposes of the processing of the personal information.
Right to delete: The right to request the deletion of your personal information. There are some exceptions to this right.
Non-discrimination and financial incentives: You may not be discriminated against or retaliated against for exercising your rights under California law.
Exercising your rights: If you wish to exercise your California privacy rights or have any questions or concerns about WestRock’s privacy policies and information practices, please submit a request here or call us at 1-888-914-9661, pin # 159311. To verify your request, you may need to provide proof of identity, such as a copy of your driver’s license. You may also designate an authorized agent to make a request under the California Consumer Privacy Act. If you utilize an authorized agent, we may require proof that the agent acts on your behalf.
Children’s Privacy. We do not knowingly collect, sell, or share any information from children under the age of 16 outside of providing benefits to our employee’s dependents, and we have no knowledge that we have done so.
This California Privacy Notice was last updated on January 5, 2023.
Canada Privacy Notice
Under the Canada’s data privacy law, the Personal Information Protection and Electronic Documents Act (“PIPEDA”) a company must have a legitimate and specific purpose to process your personal information. WestRock has described those purposes here. (link above).
If you reside in Canada, the PIPEDA may provide you with certain privacy rights. This section of the Notice describes the rights that may be available to you and how you may exercise those rights with WestRock.
In particular, you may:
- Access the personal information WestRock holds about you;
- Correct any inaccurate or outdated personal information WestRock holds about you (or, if that is not possible, ask that WestRock delete such data);
- Withdraw consent for any activities you have previously consented to.
Under PIPEDA requires that WestRock share with you what personal information is made available to related organizations and third parties.
Categories of Information | Purpose of Processing | Third Parties to Whom This Information Was Disclosed |
Your contact information, such as your mailing address, telephone number, or email address for purposes of contacting you or mailing information or products to you. | Provide our products, respond to questions, marketing, investor relations | Service Providers Performing Services on Behalf of WestRock Like many businesses, WestRock uses vendors who provide customer services, advertisements/promotions and contextual customization of advertisements, marketing services, process or fulfill orders and transactions, process payments, provide marketing or advertising services, and provide analytic, legal or insurance services. As a part of providing services on behalf of WestRock, our vendors may need to process your personal information (such as your email address or your payment information) in order to fulfill an order you may have requested from WestRock. We sometimes allow service providers to also utilize aggregated or de-identified information for other purposes. Service providers offering services to you. In addition, we may share your contact information with certain third parties who offer or market services to you. WestRock affiliates: We may share your personal information with WestRock affiliates for the purpose of providing you with information about our products, for marketing, investor relations, or other similar business purposes.
|
Demographic data, website usage, IP addresses, account login information, and additional traffic information. | Product development or marketing | Service providers providing marketing services to WestRock. |
China Privacy Notice
Personal data related to individuals in China may be processed by WestRock outside of China mainland. Where this occurs, it will be done in compliance with local laws including the Personal Information Protection Law.
Lawful basis for processing. Under China’s data protection law named the Personal Information Protection Law (the “PIPL”), a company must have a lawful basis to process your personal information. The legal basis may be different for different types of processing of personal data, and may fall into one of the following categories:
Data Subjects/Categories of Data | Legal Basis |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Name and contact information, Content of communications
| Consent |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Data about your interaction with our platforms, including your IP address, location, operating system, browser, URLs of any pages you visit on our sites or apps, device identifiers, and other similar usage information. | Consent |
Business customers, suppliers or vendors, or employees or representatives of such an entity/ All Data | Consent |
On-site Visitors/ All Data | Consent |
Job Applicants/ All Data | Contract with the Data Subject |
Individual Rights. If you reside in China, then PIPL may provide you with certain privacy rights, including the following:
- You have the right to request confirmation as to whether or not WestRock processes your personal information, and, where that is the case, request:
- the personal information or categories of personal information we hold;
- the source of the personal information, as well as the purpose for which it is used;
- the identity or category of third parties with whom we share personal information.
- You have the right to access your personal information, unless laws and regulations specify otherwise;
- You have the right to request that we correct any inaccurate and/or incomplete personal information that we store about you;
- You have the right to request that we erase your personal information under the following circumstances
- If our processing of personal information violates laws or regulations;
- If we collected and used your personal information without your consent;
- If our processing of personal information breaches our agreement with you;
- If you no longer use our products or services or you have cancelled your account;
- If we no longer provide you with products or services.
When we decide to respond to your deletion request, we will also inform any third parties that acquire your personal information from us that they must delete your personal information without delay, unless otherwise specified in laws and regulations, or the third party has acquired specific authorization from you;
- You have the right to withdraw consent to the processing of personal information by WestRock. Such withdrawal will not affect processing already completed based on your prior given consent;
- You have the right to request a portable copy of your personal information;
- You have the right to request that we stop or restrict processing of your personal information, including automated processing and automated decision-making.
To exercise one or more of these rights, please contact the WestRock Global Privacy Office. We may request that you provide proof of your identity.
WestRock will not discriminate against you based on your decision to exercise your rights.
EU-UK Privacy Notice
With regard to processing of personal information by one of our affiliates in the European Economic Area or the United Kingdom, WestRock provides the following additional information.
Controller Contact Details
WestRock Company, located at the below address, is the Controller for the processing activities identified in this Notice:
Attention: Global Privacy Office
WestRock
Suite 5, Second Floor
Aspect House
Aspect Business Park
Bennerly Road
Nottingham, NG6 8WR
United Kingdom
The purposes of the processing and legal basis for the processing
We will only collect and process personal information where we have a lawful basis to do so. The legal basis under GDPR may be different for different types of processing of personal data, and may fall into one of the following categories:
Data Subjects/Categories of Data | Legal Basis |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Name and contact information, Content of communications
| Legitimate Interest in Business Communication |
Website visitors, users of our mobile app, and individuals who contact us via phone, post, or other means/ Data about your interaction with our platforms, including your IP address, location, operating system, browser, URLs of any pages you visit on our sites or apps, device identifiers, and other similar usage information. | Legitimate Interest in Network and Information Security |
Business customers, suppliers or vendors, or employees or representatives of such an entity/ All Data | Performance of a contract |
On-site Visitors/ All Data | Legitimate Interest in Protecting our assets, employees, and partners |
Job Applicants/ All Data | Performance of a contract |
On a case-by-case basis, we may perform processing on the basis of:
- “Compliance with WestRock’s Legal Obligations” – For example, we are usually required by law to report employee payroll information to the relevant tax authority.
- “Consent of the Data Subject” – We may process some personal data based on the specific, freely given and clearly documented consent of the data subject.
- “Legitimate Interests” – Those pursued by WestRock as a business, except where such interests are overridden by the interests and fundamental rights of the data subject. For example, we may rely on this legal basis when processing personal information to ensure IT security, or to communicate with business contacts.
- “Performance of a Contract” – We may rely on this legal basis in dealing with the personal information of employees with an employment contract, for example. It also applies to pre-contractual data exchanges such as job application information.
International Data Transfers
Transfer of Personal Data Within WestRock
The WestRock group operates in many countries and may share your information among its affiliate companies including those that operate in countries outside your own. WestRock has put in place standard contractual clauses between these companies to ensure your personal information is protected, as described in this Notice.
Transfer of Personal Data Outside WestRock
Personal data may be transferred to our outsourced service providers, including those located in another country. In these circumstances WestRock will, as required by applicable law, put in place appropriate technical, organizational, contractual and/or other lawful measures to protect your personal data.
WestRock may transfer personal data to public authorities when we are required by law to do so.
Complaints with Relevant Data Protection Authority
As a resident of the European Union or the United Kingdom, you have the right to lodge a complaint with the relevant data protection authority. We suggest contacting us directly about any questions or complaints in relation to how we process personal information so that we may work to solve your issues. However, you also have the right to contact the relevant data protection authority in your country directly.
Data Subject Rights. If you reside in the European Economic Area, then the General Data Protection Regulation may provide you with certain privacy rights. Similarly, if you reside in the United Kingdom, the UK’s General Data Protection Regulation may provide you with certain privacy rights. This section of the Notice describes the rights that may be available to you and how you may exercise those rights with WestRock.
In particular, you may:
- request confirmation as to whether or not WestRock processes your personal data, and, where that is the case, request specific information about our processing of the data, as required by Article 15 GDPR/UK GDPR;
- request access to your personal data and/or a portable copy of the personal data which you have actively provided;
- request that we correct any inaccurate and/or incomplete personal data that we store about you;
- withdraw consent to the processing of personal data by WestRock. Such withdrawal will not affect the lawfulness of processing based on your prior given consent, nor will it affect the lawfulness of processing not based on consent;
- request that we stop or restrict processing, including automated processing and profiling, of your personal information. In the case of automated decision-making, you may request human intervention;
- request that we erase your personal data;
- lodge a complaint with the relevant data protection authority. We suggest contacting us about any questions or complaints in relation to how we process personal information. However, based on applicable law you may also have the right to contact the relevant data protection authority in your country, state or other jurisdiction directly.
To exercise one or more of these rights, please contact the WestRock Global Privacy Office. We may request that you provide proof of your identity.
WestRock will not discriminate against you based on your decision to exercise your rights.
Mexico Privacy Notice
Aviso de Privacidad - México
WestRock Company y sus subsidiaries Victory Packaging de México, S. de R.L. de C.V.,Gondi, S. de R.L. de C.V. and its subsidiaries Empaques Modernos San Pablo, S. de R.L. de C.V.; Celulosas Mairo, S. de R.L. de C.V., Empaques Plegadizos Modernos, S. de R.L. de C.V., Empaques Modernos de Guadalajara, S. de R.L. de C.V., Papel, Cartón y Derivados, S. de R.L. de C.V., Cuautipack, S. de R.L. de C.V., Papelera Industrial Potosina, S. de R.L. de C.V., Empaques Modernos Peosa, S. de R.L. de C.V., Empaques Modernos Sonora, S. de R.L. de C.V., Empaques Modernos de Yucatán, S. de R.L. de C.V., Rock-Tenn México, S. de R.L. de C.V., Aluprint Plegadizos, S. de R.L. de C.V., Empaques Modernos Nava, S. de R.L. de C.V., Empaques de Cartón Jamesa S. de R.L. de C.V., Cajas y Empaques de Jalisco, S. de R.L. de C.V., Grupo Gondi, S. de R.L. de C.V., Gestión y Administración Corporativa, S. de R.L. de C.V., Seguridad Privada Gondi, S. de R.L. de C.V., Empaques Modernos Querétaro, S. de R.L. de C.V. and Papel y Empaques Gondi Monterrey, S. de R.L. de C.V. (en lo sucesivo “WestRock”, o el “Responsable”), con dirección en 1000 Abernathy Rd NE Atlanta, Georgia 30328, Estados Unidos, en atención a Ley Federal de Protección de Datos Personales en Posesión de los Particulares, su Reglamento y diversa normativa vigente y relacionada (en lo sucesivo, la “Legislación de DP”) y en cumplimiento con la Legislación de DP, por medio del presente Aviso de Privacidad le informamos sobre el tratamiento de sus Datos Personales.
WestRock le informa que los Datos Personales (según dicho término se define más adelante) obtenidos del Titular (según dicho término se define más adelante), en su carácter presente o futuro de cliente, proveedor y/o empleado de WestRock, así como aquellos obtenidos por la contratación de WestRock para brindar cualesquiera de sus servicios o por cualquier tipo de relación contractual o de negocios que celebre con WestRock, serán tratados bajo los principios de legalidad, consentimiento, información, calidad, propósito, lealtad, proporcionalidad y responsabilidad de conformidad con lo siguiente:
Si usted considera que su derecho de protección de Datos Personales ha sido lesionado por alguna conducta de nuestros empleados, o de nuestras actuaciones o respuestas presume que en el tratamiento de sus Datos Personales existe alguna violación a las disposiciones previstas en la Legislación de DP, podrá interponer la queja o denuncia correspondiente ante el Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI). Para mayor información visite www.inai.org.mx
Ultima fecha de actualización del Aviso de Privacidad 1 de diciembre 2022.
|
Privacy Notice - Mexico
WestRock Company, together with its subsidiaries Victory Packaging de Mexico, S. de R.L. de C.V., Gondi, S. de R.L. de C.V. and its subsidiaries Empaques Modernos San Pablo, S. de R.L. de C.V.; Celulosas Mairo, S. de R.L. de C.V., Empaques Plegadizos Modernos, S. de R.L. de C.V., Empaques Modernos de Guadalajara, S. de R.L. de C.V., Papel, Cartón y Derivados, S. de R.L. de C.V., Cuautipack, S. de R.L. de C.V., Papelera Industrial Potosina, S. de R.L. de C.V., Empaques Modernos Peosa, S. de R.L. de C.V., Empaques Modernos Sonora, S. de R.L. de C.V., Empaques Modernos de Yucatán, S. de R.L. de C.V., Rock-Tenn México, S. de R.L. de C.V., Aluprint Plegadizos, S. de R.L. de C.V., Empaques Modernos Nava, S. de R.L. de C.V., Empaques de Cartón Jamesa S. de R.L. de C.V., Cajas y Empaques de Jalisco, S. de R.L. de C.V., Grupo Gondi, S. de R.L. de C.V., Gestión y Administración Corporativa, S. de R.L. de C.V., Seguridad Privada Gondi, S. de R.L. de C.V., Empaques Modernos Querétaro, S. de R.L. de C.V. and Papel y Empaques Gondi Monterrey, S. de R.L. de C.V. (hereinafter “WestRock”, which for purposes of this privacy notice will be referred to as the “responsible person”), located at 1000 Abernathy Rd NE Atlanta, Georgia 30328, United States, provides the following in accordance with the Federal Law for the Protection of Personal Data in Possession of Individuals, its Regulations and other current and related regulations (hereinafter, the "DP Legislation") and in compliance with the DP Legislation, we hereby inform you about the treatment of your Personal Data.
WestRock informs you that the Personal Data (as such term is defined below) obtained from the Data Subject (as such term is defined below), as a present or future customer, supplier and/or employee of WestRock, as well as those obtained by contracting from WestRock to provide any of its services or by any type of contractual or business relationship with WestRock, will be processed under the principles of legality, consent, information, quality, purpose, loyalty, proportionality and responsibility in accordance with the following:
If you believe that your right to protection of Personal Data has been violated by any conduct of our employees, or from our actions or responses you presume that in the processing of your Personal Data there is any violation of the provisions of the DP Legislation, you may file a complaint or complaint with the National Institute of Transparency, Access to Information and Protection of Personal Data (INAI). For more information visit www.inai.org.mx
Privacy Notice last updated on December 1, 2022. |
Nevada Privacy Notice
The State of Nevada provides certain rights for residents of that state, which includes the right to request that a business disclose what personal information it collects, uses, discloses, and sells.
Sale of personal information. Under Nevada law we are not engaged in any activity that would constitute a sale within the last twelve months.
Sharing of Personal Information, Including Categories of Personal Data, Business Purpose, and Recipients. We share certain information with third parties as is listed herein, such as with vendors working on our behalf and our affiliates.
The following represents the categories of information, the purpose for processing, and the type of third party to whom this information was disclosed within the last twelve months:
Categories of Information | Purpose of Processing | Third Parties to Whom This Information Was Disclosed |
Contact information, such as your mailing address, telephone number, or email address for purposes of contacting you or mailing information or products to you. | Provide our products, respond to questions, marketing, investor relations | Service Providers Performing Services on Behalf of WestRock Like many businesses, WestRock uses vendors who provide customer services, advertisements/promotions and contextual customization of advertisements, marketing services, process or fulfill orders and transactions, process payments, provide marketing or advertising services, and provide analytic, legal or insurance services. As a part of providing services on behalf of WestRock, our vendors may need to process your personal information (such as your email address or your payment information) in order to fulfill an order you may have requested from WestRock. We sometimes allow service providers to also utilize aggregated or de-identified information for other purposes. Service providers offering services to you. In addition, we may share your contact information with certain third parties who offer or market services to you. |
Demographic data, website usage, IP addresses, account login information, and additional traffic information. | Product development or marketing | Service providers providing marketing services to WestRock. |
Consumer Rights. You have the right to make verified requests regarding the information WestRock may have collected about you through your interactions with WestRock and for information regarding material changes to this privacy notice.
If you wish to exercise your Nevada privacy rights, please contact us. To verify your request, you may need to provide proof of identity, such as a copy of your driver’s license. You may also designate an authorized agent to make a request. If you utilize an authorized agent, we may require proof that the agent acts on your behalf.
We will not discriminate against you because you exercise your rights under Nevada law.
Children's Privacy
We do not knowingly collect any information from children under the age of 18 outside of providing benefits to our employee’s dependents. If we learn that a child under the age of 18 has improperly provided us with personal information, we will delete it in accordance with applicable law. If you are a parent or guardian and believe we have inadvertently collected information from your child in a manner not permitted by law, please contact us at WestRock_Global_Privacy_Office@westrock.com.
Contacting Our Privacy Office
If you have questions about this Notice or about WestRock’s data privacy practices, you may contact us through our Global Privacy Office. We may be reached via email at WestRock_Global_Privacy_Office@westrock.com.
You may also reach us via post by writing to:
WestRock Company
Attention: Global Privacy Office
1000 Abernathy Road NE
Atlanta, Georgia 20228, United States of America
Alexa Limeres serves as the Data Protection Officer in Canada and Brazil and the Grievance Officer in India. You may contact her via email at WestRock_Global_Privacy_Office@westrock.com.
You may also call the WestRock Compliance Line (+1 800-457-6435) and ask to speak to the Global Privacy Office. Callers outside the United States may reach the WestRock Compliance Line by calling country-specific toll-free phone numbers available here.
When this Privacy Notice Was Last Updated
This Privacy Notice was last updated on May 16, 2022