CCPA Privacy Policy

CALIFORNIA PRIVACY NOTICE

This California Privacy Notice (“Notice”) supplements the information contained in Navien, Inc.’s Privacy Policy (https://www.navieninc.com/privacy) and applies solely to all consumers and households who reside in the State of California (“consumers” or “you”). Navien, Inc. (“Navien” or “we”) adopts this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”). Any terms defined in the CCPA have the same meaning when used in this Notice.

I. PERSONAL INFORMATION WE COLLECT

Our Website collects information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device (“personal information”). In particular, Navien’s websites, including, without limitation, navien.com, navieninc.com, boilermadesmart.com, boilersmadesmart.com, gonavien.com, holehousecombi.com, tanklessmadesimple.com, wholehomeboiler.com, wholehomecombi.com, wholehouseboiler.com, wholehousecombi.com, wholehousecombis.com, and any other website that Navien owns or may own from time to time (collectively, “Website”), has collected the following categories of personal information from its consumers within the last twelve (12) months:

• Category A: Identifiers – A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers. Collected - YES

• Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). – A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. Collected - YES

• Category C: Protected classification characteristics under California or federal law. – Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). Collected - NO

• Category D: Commercial information. – Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Collected - YES

• Category E: Biometric information. – Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. Collected - NO

• Category F: Internet or other network activity – Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement. Collected - YES

• Category G: Geolocation data – Physical location or movements. Collected - YES

• Category H: Sensory data – Audio, electronic, visual, thermal, olfactory, or similar information. Collected - NO

• Category I: Professional or employment-related information – Current or past job history or performance evaluations. Collected - NO

• Category J: Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99) – Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. Collected - NO

• Category K: Inferences drawn from other personal information – Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. Collected – NO

Personal information does not include:

• Publicly available information from government records.

• Deidentified or aggregated consumer information.

• Information excluded from the CCPA’s scope, like:

o health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;

o personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.

Navien obtains the foregoing categories of personal information from the following categories of sources:

• Directly from you. (i.e., from forms you complete or products and services you purchase)

• Indirectly from you. (i.e., from observing or logging your actions on our Website)

II. BUSINESS OR COMMERCIAL PURPOSES FOR USING PERSONAL INFORMATION

We may use or disclose the personal information we collect for one or more of the following business or commercial purposes:

We may need to collect and use some of the information listed below because we are either legally required to do so or because we need it to provide the requested services to you. If you do not provide the information that we ask for, we may not be able to provide you with the requested services.

• To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to request service or ask a question about our products or services, we will use that personal information to respond to your inquiry. If you provide your personal information to purchase a product or service, we will use that information to process your payment and facilitate delivery. We may also save your information to facilitate new product orders or process returns.

• To provide, administer and communicate with you about products, services, events, surveys and promotions (including by sending you marketing communications);

• To provide our services to you (including access to website and/or platforms), to communicate with you (including send you administrative and contractual information, such as information regarding the terms and conditions, warranty policies or service contracts) and to provide you other customer-related services, such as handle your queries and complaints;

• To contact you in the event of a service notification for your registered appliance or to provide other notices concerning the safety of your appliance regardless of your stated privacy preferences;

• To process, evaluate and respond to your requests, inquiries and applications;

• To confirm and process your order, provide you with updates regarding your order, process returns and contact you concerning your order;

• To create, administer and communicate with you about your account (including any purchases and payments);

• To personalize your experience on the services by presenting products and offers tailored to you, and to facilitate social sharing functionality;

• To verify your identity to ensure security for the other purposes listed here;

• To operate, evaluate and improve our business (including improving or developing new products and services; managing our communications; performing market research; determining and managing the effectiveness of our advertising and marketing; analyzing our products, services and websites; administering our websites; and performing accounting, auditing, billing, reconciliation and collection activities);

• To protect against and prevent fraud, unauthorized transactions, claims and other liabilities, and manage risk exposure and quality;

• To conduct investigations and comply with and enforce applicable legal requirements, industry standards and our policies and terms, such as this and other sites’ terms of use;

• To ensure the security of our network services, information resources and the safety of our products, services, and employees.

• For other uses, as agreed by you and us.

• To create, maintain, customize, and secure your account, if any, with us.

• To personalize your Website experience and to deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Website, third-party sites, and via email or text message (with your consent, where required by law).

• For testing, research, analysis, and product development, including to develop and improve our products, and services.

• As described to you when collecting your personal information or as otherwise set forth in the CCPA.

• To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Navien’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by Navien about our Website’s or services’ users is among the assets transferred.

III. PERSONAL INFORMATION SALES OPT-OUT AND OPT-IN RIGHTS AND OTHER CONSUMER REQUESTS

Navien does not sell, rent or trade any personal information to third parties. Nonetheless, if you are 16 years of age or older, you have the right to direct us not to sell your personal information at any time (the “right to opt-out”). We do not sell the personal information of consumers we actually know are less than 16 years of age, unless we receive affirmative authorization (the “right to opt-in”) from either the consumer who is between 13 and 16 years of age, or the parent or guardian of a consumer less than 13 years of age. Consumers who opt-in to personal information sales may opt-out of future sales at any time.

To exercise the right to opt-out or to submit any other verifiable consumer request, you (or your authorized representative) may submit a request to us by calling 800-519-8794 or by completing the online form located at https://www.navieninc.com/contact.

Once you make an opt-out request, we will wait at least twelve (12) months before asking you to reauthorize personal information sales. However, you may change your mind and opt back in to personal information sales at any time by submitting a request to us at the web address above.

You do not need to create an account with us to exercise your opt-out rights. We will only use personal information provided in an opt-out request to review and comply with the request.

For all verifiable consumer requests, please allow 30-45 days for us to respond, depending on the nature of your request.

About Navien | Contact Us | Terms & Conditions | FAQs | Privacy Policy | CCPA | CPRA | CPA | VCDPA | Notices
All Navien branded merchandise on this site is sold by a third party vendor.