This policy has been updated and is effective as of September 11, 2026.
1. Overview
This Privacy Policy, which is reviewed on an annual basis, outlines how we collect, use, disclose, and protect personal information in compliance with CCPA, GDPR, HIPAA, Ohio, and other privacy regulation frameworks.
2. Purpose
The purpose of this Privacy Policy is to inform our data subjects about our practices regarding the collection, use, and disclosure of personal information.
3. Scope
This Privacy Policy applies to all personal information collected by our business, including information collected through our website, services, and products.
4. Definitions
- Personal Data: Any information that identifies, relates to, describes, or could reasonably be linked to an individual, such as name, contact details, or identification numbers.
- Processing: Any operation performed on personal data, whether automated or not, including collection, use, storage, disclosure, or deletion.
- Data subject: The individual whose personal data is being collected or processed.
- Breach: A security incident that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
5. Privacy Program Responsibilities
At MCPC, the Privacy Program is designed to ensure compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy frameworks, including those of Ohio. Responsibilities within the program are clearly delineated across key roles.
Leadership holds overarching oversight responsibility for the program, ensuring it is adequately staffed and funded. Leadership is accountable for setting the top-level direction and ensuring that all organizational practices align with MCPC’s commitment to data privacy. Additionally, leadership participates directly in data governance, sharing responsibilities as part of the Data Controller function and making final decisions regarding data collection.
The Chief Information Security Officer or Deputy CISO at MCPC, as defined by the Information Security Policy, also serves as the designated Data Protection Officer (DPO) required under GDPR, and acts as the Privacy Contact Point for CCPA-related matters. This individual oversees the organization’s data protection strategy and ensures compliance with applicable privacy laws. The DPO advises leadership on privacy risks, monitors internal practices, and serves as the point of contact for data subjects and regulatory authorities. The DPO operates with a degree of independence and reports directly to the Security Leadership Committee (SLC), in accordance with the SLC Charter (CORP-SLC-CHT), to maintain objectivity in oversight.
The role of the Data Controller is collectively fulfilled by Leadership and IT and Security Personnel. As Data Controllers, they determine the purposes and means of processing personal data and ensure that all processing activities are lawful, transparent, and respectful of individual rights. IT and Security Personnel are tasked with implementing and maintaining the technical and organizational measures necessary to protect personal data, supporting the DPO in operationalizing privacy controls, and responding to data subject requests in accordance with legal obligations.
6. Policy Statement
At MCPC, we are committed to protecting the privacy and security of your personal data. We want to assure you that we do not and will never sell your personal data to third parties.
We collect personal data solely for the purpose of delivering and improving the services we provide to you. This data collection is limited to what is necessary for legitimate business purposes and to fulfill our contractual obligations.
Your data may be shared with trusted partners and subcontractors only to the extent required to deliver our services effectively. These third parties are contractually obligated to handle your data in accordance with applicable privacy laws and our strict data protection standards.
6.1 Data Retention
Data retention is determined based on business needs, legal requirements, and the nature of the services provided, in accordance with the Records Retention Policy (SEC-Records Retention-POL). We retain personal data only for as long as necessary to fulfill these purposes.
6.2 Regulated Industries
MCPC recognizes the importance of data privacy and security in highly regulated industries. While MCPC does not directly process or store regulated data such as patient health information or cardholder data, our services may involve indirect access to systems or devices where such data resides. This section outlines our approach to safeguarding privacy in these contexts.
6.2.1 Patient Data
MCPC provides services that may involve access to networks or devices containing Protected Health Information (PHI) from Covered Entities as defined under the Health Insurance Portability and Accountability Act (HIPAA). Consequently, MCPC may be classified as a Business Associate under HIPAA regulations (45 CFR § 160.103). However, MCPC does not process, store, or manage PHI within its service offerings.
Our personnel are trained to handle PHI in accordance with our HIPAA training program, with instructions to avoid PHI whenever possible. Our procedures are designed to ensure that any incidental exposure is managed in compliance with HIPAA’s Privacy Rule. We employ administrative, physical, and technical safeguards to minimize the risk of unauthorized access or disclosure. Where a PHI breach or Security Incident occurs, MCPC will also notify the affected Covered Entity or customer without unreasonable delay and no later than five (5) business days after discovery, in the manner required by the applicable Business Associate Agreement, in addition to any individual or regulator notifications.
6.2.2 Card Holder Data
MCPC may operate in environments where Payment Card Industry Data Security Standard (PCI DSS) regulated data is present. Although we do not directly process or store cardholder data, our services may involve working on systems or infrastructure that support payment processing.
MCPC adheres to stringent internal controls and follows industry standards to ensure the security of cardholder data. Our role is confined to supporting our agreements for STL, ITAD, ITAM, or other MCPC offerings, and we maintain a clear boundary from any direct interaction with payment data.
However, MCPC may collect cardholder data to process credit card payments through a third party. The cardholder data is collected and transmitted securely to the third party; it is not retained by MCPC. Furthermore, MCPC personnel are thoroughly trained on cardholder data privacy and security through MCPC’s PCI DSS training program.
7. Privacy Notice
At MCPC, we are committed to protecting your privacy. This notice explains how we collect, use, and share your personal information in accordance with the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), and other privacy frameworks.
We collect limited personal information, including your full name, contact details, address, and other information only as necessary to provide and improve our services. This information may be collected directly from you, provided by your employer (our customer), automatically through your use of our services, or from trusted third parties. We do not sell your personal data.
Your information may be shared with service providers and partners solely to support service delivery. All third parties are contractually bound to protect your data. We retain your data only as long as necessary for business, legal, or regulatory reasons.
You have rights under applicable laws. Your rights include the right to access, correct, delete, or restrict the use of your data. You may also object to certain processing or request data portability. To exercise your rights, please contact us at [email protected].
We implement appropriate technical and organizational safeguards to protect your data. If we make significant changes to this notice, we will notify you through our website or other appropriate means.
8. Consent
MCPC primarily processes personal data on behalf of its customers and does not typically collect data directly from individuals. As such, MCPC does not obtain consent directly from data subjects. Instead, MCPC relies on the lawful basis and consent obtained by its customers for the collection and processing of personal data.
By engaging MCPC’s services, our customers confirm that they have obtained all necessary consent or have established another lawful basis for processing personal data in accordance with applicable privacy laws, including the GDPR and CCPA.
9. Breach Notification
A “Breach” as defined in this policy is a type of security incident and shall additionally be handled in accordance with the Incident Response Policy (SEC-IR-POL).
9.1 California Residents
In the event of a breach of unencrypted personal data collected from California residents, MCPC will notify the individuals reasonably believed to be affected or to have been affected by the data breach. Such individuals will receive a notice that complies with California Civil Code § 1798.82 for California residents. MCPC will contact the California Attorney General if the data breach involves over 500 residents.
9.2 European Residents
In the event of a breach of unencrypted personal data collected from European residents that is reasonably believed to be a risk to the rights and freedoms of natural persons, then the data controller will notify the appropriate authorities within seventy-two (72) hours of becoming aware of the breach as described in Article 33 of the GDPR. Furthermore, the Data Controller will also notify the affected European residents without undue delay if required as described in Article 34 of the GDPR.
9.3 Others
If unencrypted personal data is breached, MCPC will adhere to the breach notification laws of the state in which the affected individual resides. Where MCPC’s home state of Ohio’s requirements apply, MCPC will notify residents within forty-five (45) days of discovery and notify consumer reporting agencies for breaches involving information of over one thousand (1,000) individuals, if applicable.
10. Contact Us
According to the privacy notice, data subjects may have the right to review, amend, or delete their data based on their residency and applicable rights. Data subjects wishing to review their data can contact us at [email protected]. MCPC personnel will verify your identity before responding to any inquiries.