Privacy Statement

This Privacy Statement is effective May 22, 2018.

Unisys is driven by our mission to build high-performance security-centric solutions for the most demanding businesses and governments on Earth. Unisys Corporation and its subsidiaries around the world (Unisys or we) understand that when our clients, partners and other individuals provide personal data to Unisys, they place their trust in us. We take this trust seriously and are committed to respecting each individual’s privacy and protecting the personal data we handle.

This Privacy Statement describes our privacy practices to help you understand what personal data we collect, use, share and transfer and to inform you about the choices you can make regarding your personal data.

This Privacy Statement applies to Unisys websites, domains, or applications that link to this Statement, including those of our subsidiaries. You can find a list of our subsidiaries at https://www.unisys.com/about-us/locations. We may supplement this Privacy Statement with a privacy statement for a specific product, service or website. When we do, the more specific statement is applicable. For example, for information describing how we treat personal data you provide for recruiting and hiring purposes, please review our Recruiting Privacy/Data Protection Notice.

Summary

How We Collect and Use Personal Data

We collect and use personal data that you provide in order to operate our business, provide our products and services, send marketing and other communications, and comply with applicable laws and regulations. In addition to the data you provide to us directly, we may also process personal data about you that we receive from our clients or third parties.

The types of personal data we process will depend on the purpose, including:

  • Provide products and services - contact details (such as name, email, address, company name, phone number and other information necessary) to provide services to our clients and our client’s customers, including providing warranty and repair services and product support updates;
  • Improve our products and services - contact details to conduct quality controls and evaluate the performance of our products and services, including conducting customer satisfaction surveys;
  • Conduct due diligence – contact details and publicly available information about financial or reputational status of a client or third party supplier/partner;
  • Generate sales and marketing leads – contact details, marketing preferences, publically available social media information to maintain a client relationship management database and send relevant newsletters, solution updates, event notifications and other marketing communications;
  • Customize your website experience – contact details and information obtained through the use of digital collection tools such as cookies (for more information about the way we use cookies, click here);
  • Manage relationships with our clients, suppliers and partners – contact details and payment information in order to execute contracts, generate invoices and make payments;
  • Respond to inquiries or requests for information – contact details for electronic communication; and
  • Secure our premises and networks – contact details for authentication to use guest networks, collaboration tools and visit our offices; images captured through our CCTV systems set up for security purposes in our offices.

When we receive personal data about you from our clients in order to provide our services, Unisys processes the personal data as instructed by our clients and in accordance with our contractual obligations. Our clients are responsible for complying with regulations or laws regarding notice, disclosure, and/or obtaining consent prior to transferring the personal data to Unisys for processing.

How We Protect Your Personal Data

We use reasonable security procedures and technical and organizational measures to protect against accidental or unlawful destruction, loss, disclosure or use of personal data we handle. Our network and systems used to provide services are governed by Unisys corporate Information Security policies, which are based upon standards, including International Organization for Standardization (ISO) 27001 and National Institute of Standards and Technology (NIST).

We limit access to and use of your personal data to authorized persons and trusted third parties who have a reasonable need to know the information in order to perform our services and business operations and who are bound by confidentiality obligations.

How Long We Retain Personal Data

We retain your personal data only for as long as is necessary to fulfill the purpose for which the data was collected from you and in consideration of and compliance with applicable legal or regulatory requirements to maintain the data for legitimate purposes. For example, where required by law for audits or accounting requirements, to enforce our agreements or handle disputes.

When personal data is no longer needed for the purpose it was collected or processed or to comply with a legal obligation, we securely destroy it.

How We Share Your Personal Data

We do not sell or otherwise disclose personal data about our website visitors or others that interact with Unisys or our products or services, except as described herein.

We may share your personal data with authorized Unisys personnel in our subsidiaries with a need to know the information in order to process the personal data for the purpose we collected it. We also share personal data with third parties who are acting on our behalf in order to provide the products or services you request or to support our relationship with you. These third parties are not authorized by us to use or disclose the information except as necessary to perform services on our behalf pursuant to a contractual obligation or to comply with legal requirements. Unisys requires such third parties to comply with applicable data protection and privacy laws and agree to implement and maintain appropriate technical and organizational security measures to safeguard the personal data.

Our sharing may include:

  • With any of our Unisys subsidiaries and trusted third party suppliers/partners in order to perform our services or business operations;
  • With our professional advisors and insurers to run our business;
  • With competent legal authorities when required by applicable laws or regulations;
  • With law enforcement authorities or other government officials when we are required to do so by law or pursuant to legal process (including for national security purposes);when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual fraud or illegal activity; or when we believe that disclosure is necessary to protect our rights, protect your safety or the safety of others;
  • With appropriate third parties in connection with the sale, transfer or financing of all or part of a Unisys business or its assets, including any such activities associated with a bankruptcy proceeding.

How We Transfer Personal Data Across International Borders

Unisys is a global enterprise based in the United States with operations in countries around the world. Authorized Unisys personnel and third parties acting on our behalf may access, use and process personal data collected from you in a country that is different from the country where you entered the personal data, which may have less stringent data protection laws.

As an IT and security services company, Unisys has implemented global privacy practices for processing personal data protected under various data protection laws. Unisys transfers personal data between the countries in which we operate in accordance with the standards and conditions of applicable data privacy laws, including standards and conditions related to security and processing and acceptable transfer mechanisms.

With respect to personal data coming from the EU or Switzerland, Unisys complies with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks set forth by the US Department of Commerce regarding the collection, use, and retention of personal data from individuals in the European Union member countries and Switzerland.

Unisys has certified that it adheres to the Privacy Shield Privacy Principles and agrees that if there is any conflict between the principles in this Privacy Statement and the Privacy Shield Privacy Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our self-certification, please visit https://www.privacyshield.gov.

Unisys commits to resolve complaints about our collection or use of your personal data. EU or Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us at unisysglobalprivacy@unisys.com. For any Privacy Shield complaints that cannot be resolved with us directly, EU or Swiss individuals may bring a complaint through the JAMS alternative dispute resolution process. Information about how to file a complaint with JAMS can be found at: https://www.jamsadr.com/eu-us-privacy-shield. The services of JAMS are provided at no cost to you. Finally, as a last resort and in limited situations, EU or Swiss individuals may seek redress from the Privacy Shield Arbitration Panel, a binding arbitration mechanism. Find more information here: https://www.privacyshield.gov/article?id=G-Arbitration-Procedures.

When we share your personal data under the Privacy Shield framework with a third party, Unisys is responsible for the processing of your personal data. Unisys remains liable under the Privacy Shield Principles if our third party service provider processes your personal data in a manner inconsistent with the Privacy Shield Principles.

The U.S. Federal Trade Commission has jurisdiction over Unisys’ compliance with the Privacy Shield.

How We Respect Your Privacy in Marketing

Unisys uses various means of communication and tools to market its products and services. We provide commercial marketing email to persons who consent or where we have a legitimate interest and it is otherwise permissible under applicable law. You may opt-out of our commercial marketing emails by using the “Unsubscribe” or “Opt-out” link in the commercial email or by contacting us at unisysglobalprivacy@unisys.com.

We strive to make your Unisys experience the best it can be by using various tools that provide us with information about how you and other visitors interact with our website so that we can tailor your Unisys experience and improve our web properties. These tools include Cookies and other automatic data collection tools. For information on these tools, please click here.

How To Request Access To Your Personal Data

We rely on you to provide accurate, complete and current personal data to us.

If you need to correct or update the personal data you provided to us, in many cases, you can edit your data from the location where you provided the personal data to us. If you are not able to access it yourself, we will respond in a timely manner to all reasonable requests to access, correct or delete your personal data. Requests and questions can be submitted to unisysglobalprivacy@unisys.com.

  • Additional Rights if You Reside in the EU, EEA or Switzerland

Unisys and its subsidiaries are Data Processors for our clients where we process personal data in order to provide our solutions to our client. When we are a Data Processor, we process the personal data in accordance with the instructions of the Data Controller.

For individuals whose personal data we collect directly or instruct our trusted third party to collect on our behalf, Unisys Corporation or one of our subsidiaries located in the EU, EEA or Switzerland is a Data Controller under the General Data Protection Regulation. The type of data we process as a Data Controller includes contact details such as name, company, email, phone, website preferences and other information collected for marketing or business operation purposes.

We process personal data as a Data Controller using the following legal basis:

  • Legitimate interest – we process personal data to meet our legitimate business interest such as to develop and improve our solutions, support our sales and business operations, secure our systems, facilities and personnel.
  • Legal obligation – we process personal data to comply with applicable laws and regulations.
  • Performance of Agreement – we process personal data in order to perform or fulfill our obligations under an agreement with you or the entity with which you are affiliated.
  • Consent – we may process personal data based upon the provision of your consent. You may withdraw your consent at any time by contacting us at unisysglobalprivacy@unisys.com.

For your personal data, you may exercise the following rights:

Access - You have the right to obtain confirmation from us if we are processing your personal data.

Rectification - You have the right to request that we correct inaccurate personal data and to have incomplete data completed.

Objection - You have the right to object to the processing of your personal data for compelling and legitimate reasons relating to your particular situation and we will comply except in cases where legal provisions expressly provide for that processing.

Portability - In limited circumstances, you may receive your personal data that you have provided to us, in a structured, commonly used and machine-readable format. This only applies if the processing is based on your consent or a contract and the processing is carried out by automated means.

Restriction - You may request to restrict processing of your personal data if (i) you contest the accuracy of the data – for a period we need to verify your request; (ii) the processing is unlawful and you oppose the erasure of the data and request restriction instead; (iii) we no longer need the data, but you tell us you need the data to establish, exercise or defend a legal claim; or (iv) you object to processing based on public or legitimate interest – for a period we need to verify your request.

Erasure - You may request to erase your personal data where there is no compelling reason for its continued processing.

Right to lodge a complaint - You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of employment, or the location where the issue that is the subject of the complaint occurred.

Right to refuse or withdraw consent - Please note that in case we ask for your consent to processing, you are free to refuse to give consent and you can withdraw your consent at any time without any adverse negative consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected.

You can exercise these rights by contacting us at unisysglobalprivacy@unisys.com. If you consider that the way we process your personal data infringes your rights under the GDPR or is not compliant, you can lodge a complaint with Unisys directly or with a supervisory authority in the EU Member state in which you reside or where the data was processed.

How To Contact Us

If you have any questions or comments regarding this statement or our privacy practices, or any concerns regarding a possible violation of this statement, our practices or any applicable privacy law, or a concern or complaint about our practices related to the Privacy Shield, please contact the Unisys Corporate Compliance Office or our Unisys Compliance Helpline, www.unisyscompliance.com and we will promptly respond.

Our mailing addresses are:

Unisys Corporate Compliance Office
Law Department
801 Lakeview Drive, Ste. 100
Blue Bell, PA 19422
United States

Unisys EU Privacy Manager
Westend City Centre – Tower “A”
Vaci ut 1/3
Budapest 1062
Hungary

unisysglobalprivacy@unisys.com

www.unisyscompliance.com

Links To Other Websites

As a convenience to our website visitors, we sometimes provide links to other websites. These linked sites are not under the control of Unisys and we are not responsible for their content. You should review the privacy statements of any linked website to understand their privacy practices before using the site.

Children

It is not our intent to collect personal data from children under the age of consent in their country of residence. Our websites are not designed to attract children and we request that children under the age of consent not submit personal data to us through our websites.

Updates To Our Privacy Statement

We may update this Privacy Statement from time to time. When we update this statement, we will also update the date at the top. Only the current statement is effective, so please review it periodically. If we make any material changes, we may also notify you by contacting you directly or posting a notice on our website. You may request a copy of our prior Privacy Statement by contacting us at unisysglobalprivacy@unisys.com.