STATE PRIVACY RIGHTS CONSUMER REQUESTS PROCESSING POLICY
Updated: July 21, 2026
OVERVIEW
This policy applies to HB Global, LLC and its associated brands, divisions, and business units (collectively, “HB Global,” “Company,” “we,” or “us”) and governs the procedure for handling lawful consumer privacy requests submitted by consumers to HB Global pursuant to those applicable privacy laws currently in effect. This policy shall be updated from time to time to accommodate changes in state, federal, and international laws with which HB Global must comply.
The Company shall designate and appoint an employee, service provider, or other responsible agent (the “Request Response Coordinator”) to receive, process, and respond to all consumer privacy rights requests. The Company shall establish, and the Request Response Coordinator shall maintain, a consumer privacy request database (the “Database”) for tracking the status of requests submitted by individuals to the Company.
This policy addresses (1) the tasks and actions to be taken by the Request Response Coordinator, and (2) the responsibilities and obligations applicable to the Company when properly responding to consumer privacy rights requests pursuant to applicable law.
TIMING OF RESPONSES TO REQUESTS
The Company must process consumer requests in a timely manner and according to the requirements of applicable privacy laws.
- Confirmation of Receipt
- Within 10 business days of receiving a request to know, delete, or correct personal information, the Company shall confirm receipt of the request and provide information to the consumer describing how the request will be processed, including:
- The general verification process, and
- When the consumer should expect a response, except in instances where the Company has already granted or denied the request.
- Confirmation may be made in the same way the request was received.
- Within 10 business days of receiving a request to know, delete, or correct personal information, the Company shall confirm receipt of the request and provide information to the consumer describing how the request will be processed, including:
- Response
- Requests to Know, Delete, and Correct
- Within 45 calendar days of receiving a request to know, delete, or correct personal information, the Company shall substantively respond to the request and provide the consumer with the information requested and/or confirmation of deletion.
- If the Company cannot verify the request within 45 calendar days, the Company may deny the request and shall inform the consumer of the denial and the reason for the denial.
- Requests to Know, Delete, and Correct
- If the Company cannot respond within 45 days, the Company may take up to an addition 45 calendars days (for a total of 90 calendar days from receipt of the request) to respond to the request, so long as:
- The Company provides the consumer with notice and an explanation of the reason that the Company will take more than 45 days to respond.
- Requests to Opt-Out of and Restrict the Processing, Sharing, and Sale of Personal Information and Requests to Opt-Out of Profiling
- Within 15 business days, the Company shall fully comply with a request to opt out of any of the following:
- The sale of personal information.
- The processing of sensitive personal information.
- Targeted advertising.
- The sharing of personal information for cross-contextual behavioral advertising.
- Profiling in furtherance of decisions that produce legal or similarly significant effects.
- Within 15 business days, the Company shall fully comply with a request to opt out of any of the following:
PROCEDURE FOR RESPONDING TO REQUESTS
- Accepting and Receiving Consumer Privacy Rights Requests
- A consumer may submit, and the Company shall accept, consumer privacy rights requests submitted via the following methods:
- Email sent to: [email protected]
- Phone calls made to: 717-214-3183
- In writing and sent to: HB Global, Attn: Privacy Officer, 4660 Trindle Road, Suite 301, Camp Hill, PA 17011
- All requests shall be routed and assigned to the Request Response Coordinator for processing.
- Upon receipt of a request, the Request Response Coordinator shall check whether the consumer currently exists in the Database.
- If the consumer has a pre-existing record or identity in the Database, the Request Response Coordinator shall associate the request with that pre-existing record or identity.
- If the consumer does not have a pre-existing record or identity in the Database, the Request Response Coordinator shall create a new record or identity for the consumer in the Database and associate the request with that new record or identity.
- Verification of Requests
- Requests to Know, Delete, and Correct
- The Request Response Coordinator shall verify the identity of the consumer before disclosing, deleting, or modifying any personal information of the consumer held by the Company.
- For requests to know categories of personal information held by HB Global, the Request Response Coordinator shall match at least two pieces of personal information provided by the consumer to the information stored about the consumer by the Company.
- For requests to know specific pieces of personal information, to delete personal information, and to correct personal information, the Request Response Coordinator shall match at least three pieces of personal information and shall require the consumer to sign a declaration under penalty of perjury that he/she is the consumer in question.
- If the consumer provided insufficient information, the Request Response Coordinator may ask and require the consumer to provide the following pieces of personal information in order to verify the consumer’s identity, to the extent necessary and maintained by the Company:
- name
- record of purchases
- job title
- home address or office address
- email address
- telephone number
- If the request is made by a designated agent, not including an agent with power of attorney, the Request Response Coordinator may:
- Require the consumer to do the following:
- Provide the authorized agent with written and signed permission to make a request on the consumer’s behalf.
- Verify authorized agent’s own identity directly with the Company.
- Directly confirm with the Company that the consumer provided the authorized agent with permission to submit the request on his/her behalf.
- Deny the request if the authorized agent does not submit proof of authorization
- Require the consumer to do the following:
- If the Request Response Coordinator cannot verify the consumer’s identity, the Company may deny the request and shall inform the requestor of the same.
- If there is no reasonable method by which the consumer’s identity may be verified, the Company shall inform the consumer of this inability and explain why verification is not possible.
- For requests to know specific pieces of personal information:
- The Company shall not disclose any specific pieces of personal information and shall inform the requestor that it cannot verify the consumer’s identity.
- If the request is denied, in whole or in part, the Company shall evaluate the request as if it were a request for categories of personal information.
- The Request Response Coordinator shall verify the identity of the consumer before disclosing, deleting, or modifying any personal information of the consumer held by the Company.
- For requests to know categories of personal information:
- If the request is denied, in whole or in part, the Company shall provide or direct the consumer to its general business practices regarding the collection, maintenance, and sale of personal information set forth in its applicable privacy policy.
- Requests to Opt Out or Restrict Processing
- The Company shall not require the consumer to verify his/her identity as a prerequisite to fulfilling the following types of requests:
- Requests to opt out of the sale of personal information.
- Requests to restrict the processing of sensitive personal information.
- The Company shall not require the consumer to verify his/her identity as a prerequisite to fulfilling the following types of requests:
- Requests to opt out of targeted advertising.
- Requests to opt out of the sharing of personal information for cross-contextual behavioral advertising.
- Requests to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects.
- If the Request Response Coordinator has a good-faith, reasonable, and documented belief that the request is fraudulent, the Company may deny the request.
- If the request is denied, the Request Response Coordinator must inform the consumer that it will not comply with the request and must provide an explanation of why it believes the request is fraudulent.
- Response to Verified Requests
- Requests to Know
- The Company shall not be required to search for and provide personal information if any of the following conditions are met:
- Providing the personal information would violate an evidentiary privilege.
- The personal information is maintained solely for legal or compliance purposes.
- The Company shall not be required to search for and provide personal information if any of the following conditions are met:
- The personal information is medical information governed by the Confidentiality of Medical Information Act or is protected health information protected by the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act.
- The personal information is governed by the Gramm-Leach-Bliley Act or the Farm Credit Act of 1971.
- The personal information is collected, processed, sold, or disclosed pursuant to the Driver’s Privacy Protection Act of 1994.
- The personal information has been deidentified or anonymized and is not maintained in a searchable or reasonably accessible format.
- If one of the exemptions listed above applies, the Request Response Coordinator shall notify the consumer of the categories of records that may contain personal information but were not searched because an exemption applies.
- The Company shall use reasonable security measures when transmitting personal information to the consumer.
- Specific Pieces of Personal Information (also known as a data portability request)
- If the request is denied, in whole or in part, the Request Response Coordinator shall evaluate the request as if it were a request for categories of personal information.
- If the request is denied, in whole or in part, because of a conflict with state or federal law, or an exception to applicable state privacy law, the Request Response Coordinator shall inform the consumer and explain the basis for the denial, unless prohibited by law.
- if the request is only denied in part, the Request Response Coordinator shall disclose the other information sought in the request.
- Unless prohibited by (iv) below, the Request Response Coordinator shall disclose the specific pieces of personal information collected within the preceding 12 months, beginning on the day the request was received.
- The Request Response Coordinator shall not disclose:
- Unredacted Social Security numbers.
- Unredacted driver’s license numbers.
- Unredacted government-issued identification numbers.
- Unredacted financial account numbers.
- Unredacted health insurance or medical identification numbers.
- Account passwords.
- Security questions and answers.
- Unique biometric data generated from measurements or technical analysis of human characteristics.
- The response shall be provided to the consumer in a commonly used, and where technically and reasonably feasible, structured, and machine-readable format that allows the personal information to be transferred to another entity without hindrance.
- Categories of Personal Information
- If the request is denied, in whole or in part, the Request Response Coordinator shall:
- Provide or direct the consumer to its general business practices regarding the collection, maintenance, and sale of personal information set forth in its applicable privacy policy; and
- Inform the consumer as to how they may appeal the request denial.
- The Request Response Coordinator shall not refer to the Company’s general practices outlined in the Company’s applicable privacy policy unless the response would be the same for all consumers and the privacy policy discloses all information that is otherwise required to be in a response to a request to know such categories.
- If the request is denied, in whole or in part, the Request Response Coordinator shall:
- The Request Response Coordinator shall provide an individualized response to the consumer for requests to know, including:
- The categories of personal information collected about the consumer in the 12 months preceding receipt of the request.
- The categories of sources of the personal information.
- The business or commercial purpose for the collection or sale of the personal information.
- The categories of third parties with whom the Company shares personal information.
- The categories of personal information sold in the 12 months preceding receipt of the request and categories of third parties to whom it sold each particular category of personal information.
- The categories of personal information disclosed for a business purpose in the 12 months preceding receipt of the request and categories of third parties to whom it disclosed each particular category of personal information.
- Requests to Delete
- If the Company sells personal information, and the consumer has not already made a request to opt-out, the Request Response Coordinator shall:
- Ask the consumer if he/she would like to opt out of the sale of personal information, and
- Include either the contents of, or a link to, the notice of right to opt out.
- The Request Response Coordinator shall determine whether an exception applies that allows the Company to deny the request. The Company may deny the request where it is necessary for the Company or its service providers to:
- Complete the transaction for which the Company collected the personal information, provide a service that the consumer requested, take actions reasonably anticipated within the context of the Company’s ongoing relationship with the consumer, or otherwise perform a contract with the consumer.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- If the Company sells personal information, and the consumer has not already made a request to opt-out, the Request Response Coordinator shall:
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another individual or consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with specific state or federal laws.
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if the consumer previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with the consumer’s expectations based on their relationship with the Company.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which the consumer provided it.
- Where the Request Response Coordinator determines that the Company may deny the request, the Request Response Coordinator shall do all of the following:
- Inform the consumer that the Company will not comply;
- Describe the basis for the denial, including any conflict with federal or state law, unless prohibited from doing so by law;
- Delete the consumer’s personal information that is not subject to the exception;
- Ensure that the Company does not use the personal information retained for any purpose other than provided for by the exception; and
- Inform the consumer as to how they may appeal the request denial.
- Where the Request Response Coordinator determines that the Company will or must comply with the request, the Request Response Coordinator shall do the following:
- Permanently and completely erase the personal information on the Company’s existing systems (excluding archived or back-up systems on which the relevant personal information is not readily available, as described in additional detail below), deidentify the personal information, or aggregate the consumer information;
- Notify the Company’s service providers or contractors of the need to delete from their records the consumer’s personal information that they collected pursuant to their written contract(s) with the Company; and
- Notify all third parties to whom the Company has sold or shared the personal information of the need to delete the consumer’s personal information unless this proves impossible or involves disproportionate effort.
- If the Company claims that notifying some or all third parties would be impossible or would involve disproportionate effort, the Request Response Coordinator shall provide the consumer a detailed explanation that includes enough facts to give a consumer a meaningful understanding as to why the Company cannot notify all third parties. The Company shall not simply state that notifying all third parties is impossible or would require disproportionate effort.
- If the Company stores any personal information on archived or backup systems, the Company may delay compliance with the consumer’s request to delete, with respect to data stored on the archived or backup system, until the archived or backup system relating to that data is restored to an active system or is next accessed or used for a sale, disclosure, or commercial purpose.
- The Request Response Coordinator shall inform the consumer of whether the Company has complied with the request, and shall also inform the consumer that the Company will maintain a record of the request as required by applicable law.
- The Request Response Coordinator shall retain a record of the deletion request which contains the minimum personal information necessary to demonstrate the fulfillment of the request. The personal information contained in the record of the deletion request shall not be used or shared for any other purpose.
- Requests to Correct
- Accuracy
- The Request Response Coordinator shall determine the accuracy of the “corrected” personal information provided by the consumer.
- In determining the accuracy of the personal information provided to the Company by the consumer, the Request Response Coordinator shall consider the totality of the circumstances, including, but not limited to:
- The nature of the personal information (e.g., whether it is objective, subjective, unstructured, sensitive, etc.).
- How the Company obtained the contested personal information.
- Documentation relating to the accuracy of the personal information, whether provided by the consumer, the Company, or another source.
- If the Company is not the source of the personal information and the Company has no documentation in support of the accuracy of the personal information, the consumer’s assertion of inaccuracy may be sufficient to establish that the personal information in the Company’s possession is inaccurate.
- In determining the accuracy of the personal information provided to the Company by the consumer, the Request Response Coordinator shall consider the totality of the circumstances, including, but not limited to:
- Documentation
- The Request Response Coordinator shall accept, review, and consider any documentation that the consumer provides in connection with their right to correct, whether provided voluntarily or as required by the Company.
- The Company may require the consumer to provide documentation if necessary to rebut the Company’s own documentation that the personal information is accurate. In determining the necessity of the documentation requested, the Request Response Coordinator shall consider the following:
- The nature of the personal information at issue (e.g., whether it is objective, subjective, unstructured, sensitive, etc.).
- The nature of the documentation upon which the Company considers the personal information to be accurate (e.g., whether the documentation is from a trusted source, whether the documentation is verifiable, etc.).
- The Request Response Coordinator shall inform the consumer of whether the Company has complied with the request.
- When the Company has complied with the consumer’s request, the Request Response Coordinator shall also inform the consumer of the categories of personal information which have been updated.
- Where the Company has denied the consumer’s request, the Request Response Coordinator shall inform the consumer as to how they may appeal the request denial.
- The Request Response Coordinator shall determine the accuracy of the “corrected” personal information provided by the consumer.
- Accuracy
- Response to Requests Not Requiring Verification
- Requests to Opt Out of the Sale of Personal Information
- The Request Response Coordinator may ask the consumer whether he/she wishes to opt out of the sale of personal information for certain uses of that information, so long as an option to opt out of the sale of all personal information, for all uses, is more prominently presented.
- Within 15 business days of receiving the request, the Request Response Coordinator shall comply with the request to opt out.
- If the Company sold the consumer’s personal information after the request was received, but before compliance, the Company shall notify those third parties that the consumer opted out and instruct the third parties not to sell the consumer’s personal information.
- The Request Response Coordinator shall inform the consumer of whether the Company has complied with the request.
- The Company shall wait at least 12 months from the date of the request before asking the consumer to consent to the sharing or sale of their personal information.
- Requests to Restrict the Processing (Limit the Use and Disclosure) of Sensitive Personal Information
- Within 15 business days of receiving the request, the Request Response Coordinator shall comply with the request to restrict the processing (limit the use and disclosure) of sensitive personal information.
- The Company may continue to use and disclose sensitive personal information, consistent with the Company’s privacy policy, for the following purposes:
- To perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
- To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information.
- To resist malicious, deceptive, fraudulent, or illegal actions directed at the Company and to prosecute those responsible for those actions.
- To ensure the physical safety of natural persons.
- To perform services on behalf of the Company.
- To verify or maintain the quality or safety of a product, service, or device that is owned, manufactured, manufactured for, or controlled by the Company, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by the Company.
- To collect or process sensitive personal information where the collection or processing is not for the purpose of inferring characteristics about a consumer.
- Within 15 business days of receiving the request, the Request Response Coordinator shall notify all of the Company’s service providers or contractors that use or disclose the consumer’s sensitive personal information for purposes other than those set forth above that the consumer has made a request to limit and instructing them to comply with the consumer’s request to limit within the same time frame.
- If the Company disclosed or made available the consumer’s sensitive personal information to a third party for purposes other than those set forth above, after the consumer submitted their request and before the Company complies with that request, the Request Response Coordinator shall notify the third party that the consumer has made a request to limit and direct the third party 1) to comply with the consumer’s request and 2) to forward the request to any other person with whom the third party has disclosed or shared the sensitive personal information during that time period.
- The Request Response Coordinator shall inform the consumer of whether the Company has complied with the request.
- The Company may continue to use and disclose sensitive personal information, consistent with the Company’s privacy policy, for the following purposes:
- Within 15 business days of receiving the request, the Request Response Coordinator shall comply with the request to restrict the processing (limit the use and disclosure) of sensitive personal information.
- Requests to Opt Out of Targeted Advertising or the Sharing of Personal Information for Cross-Contextual Behavioral Advertising
- Within 15 days of receiving the request, the Request Response Coordinator shall comply with the request to opt out of targeted advertising or the sharing of personal information for cross-contextual behavioral advertising.
- The Request Response Coordinator shall inform the consumer whether the Company has complied with the request.
- Requests to Opt Out of Profiling
- Within 15 days of receiving the request, the Request Response Coordinator shall comply with the request to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects to the consumer.
- The Request Response Coordinator shall inform the consumer whether the Company has complied with the request.
- Accepting, Receiving, and Processing Consumer Privacy Rights Request Appeals
- A consumer may appeal the denial of a request to know, delete, or correct personal information.
- A consumer may submit, and the Company shall accept appeals to consumer privacy rights requests submitted via the following methods:
- Emails sent to: [email protected]
- Phone calls made to: 717-214-3183
- In writing and sent to HB Global, LLC, Attn: Privacy Compliance Officer, 4660 Trindle Road, Suite 301, Camp Hill, PA 17011
- All appeals shall be routed and assigned to the Request Response Coordinator for processing.
- Upon receipt of a request, the Request Response Coordinator shall check whether the consumer currently exists in the Database.
- If the consumer has a pre-existing record or identity in the Database, the Request Response Coordinator shall associate the request with that pre-existing record or identity.
- If the consumer does not have a pre-existing record or identity in the Database, the Request Response Coordinator shall respond to the consumer and state that no such previous request exists.
- The Request Response Coordinator shall compile all relevant information in the Company’s possession regarding the initial request and denial decision and forward it to the Legal Department.
- The Legal Department shall review the relevant information and justification for the denial considering all applicable consumer privacy laws and regulations and shall affirm or overturn the denial decision as appropriate.
- If the Legal Department overturns the denial decision, it shall:
- Document the decision and rationale;
- Instruct the Request Response Coordinator to complete the request consistent with that decision and this policy; and
- Provide a written response to the consumer describing any action taken or not taken in response to the appeal, including an explanation of the reasons for the decisions.
- If the Legal Department affirms the denial decision, it shall:
- Document the decision and rationale;
- Instruct the Request Response Coordinator to update the appeal as denied and closed, consistent with that decision and this policy; and
- Provide a written response to the consumer describing any action taken or not taken in response to the appeal, including an explanation of the reasons for the decisions, and provide the consumer with an online mechanism, if available, or other method through which the consumer may contact their respective Attorney General to submit a complaint.