Nu Skin Enterprises Inc. Privacy Notice

Nu Skin Enterprises Inc., having its principal executive offices at 75 West Center Street, Provo, Utah 84601 (“Nu Skin”; “we”), is the data controller of the data processing described in this privacy notice.

Nu Skin is committed to respecting and protecting your privacy. We act in accordance with the requirements of the various privacy and data protection laws applicable in the countries or markets where we operate.

This Privacy Notice explains how we collect, use and share your Personal Data and explains the rights you have regarding our use of your Personal Data. Please ensure you read this Privacy Notice carefully before using our Website and/or providing us with your Personal Data.

1. What Personal Data do we collect

Nu Skin collects and processes the Personal Data it receives in the context of your professional contacts with us. This concerns the following Personal Data:

  • Personal Data of (representatives of) our shareholders, (representatives of) future shareholders, analysts or third parties following our group.
  • Personal Data provided directly by you (for example, when registering or via a request sent by email or via our website).

When you register on our mailing list to receive certain documentation relating Nu Skin (such as press releases and financial reports), we ask you to provide certain personal details. We strive to limit these personal details to the necessary minimum.

Examples of categories of Personal Data that we collect and process in this way are: your name, your title, your contact details, details of the company or natural person you represent, your position;

  • Personal Data obtained through your use of our website.

In some cases, we may collect additional electronic identification data and information about browser and hardware from visitors to our website. We may collect statistics and general information, for example regarding the use of our website.

  • Personal Data obtained from other sources, such as public registers or publicly accessible sources.
2. How we use your Personal Data

We process Personal Data to enable us to conduct our business, and more specifically for the following purposes:

  • compliance with our legal and regulatory obligations;
  • maintaining contacts with our shareholders, future shareholders, analysts and other business contacts;
  • the management of our investments (e.g. for corporate governance purposes);
  • the dissemination of press releases, financial reports and invitations to roadshows and events;
  • reply to requests you have sent on our website or by email;
  • for the management and improvement of our website.

We process your Personal Data based on the following legal grounds, as permitted by applicable law: (i) to comply with a legal obligation, (ii) when it is in our legitimate business interest to use your Personal Data, or (iii) based on your consent.

Our legitimate interests include operating, evaluating and improving our organization; preventing and protecting us and others against fraud, unauthorized transactions, claims and other liabilities; and ensuring compliance with company policies and industry standards.

3. Sharing and transferring your Personal Data

We do not pass on your Personal Data to third parties for commercial purposes.

We may transfer or make your Personal Data available to our employees and managers, to other companies in our group, to authorities or to subcontractors or service providers for the purposes mentioned above.

Our employees and managers are bound by strict confidentiality obligations. If we transfer Personal Data to sub-contractors or service providers in accordance with the above, we will ensure that contractual obligations are imposed on these sub-contractors or service providers in order to protect the confidentiality of your Personal Data.

4. How we protect your Personal Data

We protect your Personal Data and implement physical (eg. secured filing cabinets), technical and organizational security measures to protect it against any unauthorized or unlawful processing and against any accidental loss, destruction, or damage.

In particular, we operate data networks protected by industry standard firewall and password protection systems. We also use transport layer security (TLS) to protect the transmission of your Personal Data. Access to this information will be provided only to authorized individuals for legitimate business purpose.

In addition, access to your Personal Data is restricted to staff and service providers on a need-to-know basis.

While we endeavor to always protect our systems, sites, operations and information against unauthorized access, use, modification and disclosure, due to the inherent nature of the Internet as an open global communications vehicle and other risk factors, we cannot guarantee that any information, during transmission or while stored on our systems, will be absolutely safe from intrusion by others.

5. How long do we keep your Personal Data

We hold on to your Personal Data for as long as necessary to develop and manage our professional relationship with you or the person you represent. Your Personal Data will be kept for as long as this is necessary for the purpose for which it was collected (also taking into account any legal or regulatory storage obligations).

6. What are your rights regarding your Personal Data

You have certain rights regarding how we use and keep your Personal Data. You have the right to access your Personal Data processed by us, to have them rectified, or to have them deleted. You may request that the processing of your Personal Data be restricted. You can also object to the processing. You can also ask for your Personal Data to be transferred. If you have consented to our processing of your Personal Data, you have the right to withdraw your consent at any time. This does not affect the lawfulness of the processing that was based on your consent prior to withdrawal. This includes cases where you wish to opt out from marketing messages that you receive from us;

You can exercise the above rights by contacting the Privacy Team. We will respond to any of your requests to exercise these above data subject rights within the period prescribed by applicable laws. At our discretion, we may require you to prove your identity before providing the requested information. This is to ensure that your Personal Data is disclosed only to you. We may not be able to appropriately handle your request if you decide not to provide us with the Personal Data that we need to handle your request. If you are not satisfied with the way we handled your request, or for violations of applicable data protection laws, you may lodge a complaint or file a claim with a competent Supervisory Authority (for example, with the Supervisory Authority in your country or market of residence).

7. Changes to the Privacy Notice

We may update this Privacy Notice from time to time. We will notify you of any significant changes by posting those changes here or by notifying you through other appropriate communication channels we generally use with you. Any changes to this Privacy Notice will be considered effective immediately after the changes are posted on this Website unless otherwise indicated.

The Privacy Notice was last revised on October 16, 2019.