Effective Date: Decmeber 11, 2018
doTERRA GH Ireland Limited, and its affiliates and subsidiaries (collectively, “doTERRA” or “us”) respect your concerns about privacy. This Online Privacy Notice describes the types of personal information we obtain through doTERRA’s websites and mobile applications listed in Appendix A (collectively, the “Sites”), how we may use the information, with whom we may share it and the choices available regarding our use of the information. The Notice also describes the measures we take to safeguard the personal information we obtain and how individuals can contact us about our privacy practices.
The data controllers for the processing of your personal data described in this Notice will be doTERRA GH Ireland Limited, with its address at 32 Molesworth Street, Dublin 2, Ireland (hereinafter: “doTERRA GH”); doTERRA Enterprises, sarl, with its address at 39, Avenue John F. Kennedy L 1855 Luxembourg (hereinafter: "doTERRA Enterprises"), and the local entity of the doTERRA group responsible for the country where you purchase doTERRA products or services (hereinafter: doTERRA Local).
Click on one of the links below to jump to the listed section:
Information We Obtain
The types of personal information we obtain include:
- contact and identification information, such as name, phone and fax number, email, postal and shipping address, time zone, signature, electronic signature, and tax ID number/national ID number;
- information used to create your account to access the Sites, such as birth date, partner/spouse’s name, photo, preferred language, and online password;
- payment information, such as billing address and payment card details, including card number, expiration date and security code, which is transmitted, collected, and stored by our third-party payment processor on our behalf;
- acknowledgment/acceptance of terms and conditions and company policies;
- connection or traffic data, such as login details, IP addresses, time stamps, browser type and URL activity (for detection of malicious URL strings);
- location data, such as IP address information relating to geolocation; and
- other personal information contained in content you submit to us, such as through the “Feedback” feature, public forums or customer support tools on the Sites.
If you are a doTERRA account holder, we also process information on upline and downline accounts, location of scheduled meetings and, with your consent, information in testimonials about doTERRA’s products, which may include sensitive personal data.
Information We Obtain by Automated Means
How We Use The Information We Obtain
We use the information we obtain about you to perform our contract with you or in order to take steps at your request prior to entering into a contract, in particular to:
- provide our products and services to you;
- establish and manage your account with doTERRA;
- process and fulfill orders in connection with our products and services and keep you informed about the status of your order;
- identify and authenticate you so you may order our products and access and use the Sites;
- establish invoices and calculate commissions; and
- provide technical support.
In addition, we use the information we collect to the extent necessary for our legitimate interests, in particular to:
- perform data analytics (including market research, trend analysis, financial analysis, and anonymization and aggregation of personal information);
- operate, evaluate, develop, manage and improve our business and the Sites (including operating, administering, analyzing and improving our products, services and Sites; developing new products and services; managing and evaluating the effectiveness of our communications; performing accounting, auditing, billing reconciliation and collection activities and other internal functions);
- protect against, identify and prevent fraud and other criminal activity, claims and other liabilities; and
- send promotional materials, newsletters, and other communications about our products and services
- to communicate about, and administer participation in, special events, programs, promotions, offers surveys, focus groups and market research; and
- if you are a Wellness Advocate, to report to upline and downline distributors.
In addition, we may process your personal information to comply with and enforce applicable legal requirements to which we are subject and for the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
We also may use the information we collect about you in other ways for which we provide specific notice at the time of collection and obtain your consent if required by applicable law.
We do not sell or otherwise share personal information about you except as described in this Online Privacy Notice. We may share your personal information with (1) our affiliates and subsidiaries and (2) our service providers who perform services on our behalf, such as order fulfillment, customer support, payment processing, processing of commissions and bonuses, shipping of goods, sales management, security analytics, and data analytics. We do not authorize our service providers to use or disclose the information except as necessary to perform services on our behalf or comply with legal requirements. Please contact us using the contact details below if you would like to obtain more information about the affiliates and third party service providers with whom we may share your personal data.
If you are a doTERRA account holder, we also share your personal information with the account’s sales organization (including upline and downline accounts) for the purposes of administering sales, commissionable volume, distribution of products, and providing activity reports.
Some of these data recipients are located outside the European Union, including in jurisdictions that have not been recognized by the European Commission as providing an adequate level of data protection. In this event, doTERRA ensures that appropriate safeguards aimed at ensuring such a level of data protection are in place, including by selecting service providers that are either certified to the EU-U.S. and Swiss-U.S. Privacy Shield frameworks pursuant to article 45 of the GDPR, or executing data transfer agreements with our service providers based on the European Commission’s Standard Contractual Clauses pursuant to article 46 of the GDPR. You may obtain more information about the location of the recipients with whom we share your personal information and request a copy of the safeguards we have put in place by contacting us as indicated in the How to Contact Us section below.
We also may disclose information about you (1) if we are required to do so by law or legal process (such as a court order or subpoena); (2) in response to requests by government agencies, such as law enforcement authorities; (3) to establish, exercise or defend our legal rights; (4) when we believe disclosure is necessary or appropriate to prevent physical or other harm or financial loss; (5) in connection with an investigation of suspected or actual illegal activity; or (6) otherwise with your consent. We reserve the right to transfer any information we have about you in the event we sell or transfer all or a portion of our business or assets (including in the event of a merger, acquisition, joint venture, reorganization, divestiture, dissolution or liquidation).
Your Choices and Rights
We offer you certain choices in connection with the personal information we obtain about you. Subject to applicable by law, you may (1) have the right to access personal information we maintain about you; (2) request that we correct or erase your personal information; (3) have the right to obtain the restriction of our processing of your personal information; and (4) object at any time to the processing of your personal information on grounds relating to your particular situation and, in any event, to the processing of your personal information for direct marketing purposes; and (5) where you have consented to the processing of your personal information, you have the right to withdraw your prior consent at any time. Subject to applicable law, you also have the right to receive, in a structured, commonly used and machine-readable format, the personal information that you have provided to us about you, with your consent or based on a contract to which you are party. You also have the right to have this information transmitted to another data controller, where it is technically feasible. You also may lodge a complaint with a data protection authority if you are not satisfied with our responses.
To exercise these rights, please contact us as indicated in the How to Contact Us section of this Privacy Notice. To help protect your privacy and maintain security, we may take steps to verify your identity before granting you access to the information or complying with your request. To the extent permitted by applicable law, we may charge a reasonable fee to comply with your request if we find it to be manifestly unfounded or excessive, or in case of an access request, in order to provide you with additional copies of the personal information we maintain about you.
Other Online Services and Third-Party Features
The Sites may provide links to other online services for your convenience and information, and may include third-party features such as apps, tools, payment services, widgets and plug-ins (e.g., Facebook, Twitter, Instagram, YouTube and Pinterest buttons). These online services and third-party features may operate independently from us. The privacy practices of the relevant third parties, including details on the information they may collect about you, is subject to the privacy statements of these parties, which we strongly suggest you review.
How We Protect Personal Information
Retention of Personal Information
To the extent permitted by applicable law, we retain personal information we obtain about you for the duration of our contractual relationship, plus a reasonable period in order to be able to run regular deletion routines, or to take into account the applicable statute of limitation period or to comply with mandatory applicable law.
Children's Personal Information
The Sites are designed for a general audience service and are not directed to children. doTERRA does not knowingly collect or solicit personally information from children under the age of 16. If we learn that we have collected personal information from an individual under the age of 16, we will promptly delete that information. If you believe that an individual under the age of 16 may have provided us with personal information, please contact us at firstname.lastname@example.org.
Updates To This Privacy Notice
How To Contact Us
If you have any questions about this Online Privacy Notice, or if you would like to exercise your data protection rights, please contact doTERRA or write to us at:
Attn: Legal Department
389 South 1300 West
Pleasant Grove, Utah 84062
This Online Privacy Notice applies to doTERRA’s online processing of personal information in connect with the following websites and mobile apps: