Privacy Policy 

Last published: 30 December 2022

Effective  Date: 6  January 2023

Dear users, please note that we have updated our privacy policy. The main updates are that: 1) we have adjusted the scope of this privacy policy according to the actual situation; 2) we have added new scenarios for collecting and using personal information in Part II, Chapter 1, "How do we collect and use your personal information", including providing training registration and other related services to some users, collecting personal information from distributors, providing information about our products, services, news and events to users, providing information about the Invisalign Doctors or the Invisalign Providers to patients or consumers and allowing them to contact doctors, and inviting users to participate in our surveys.

This Privacy Policy (hereinafter referred as “the Policy”) only applies to the clear aligner products and services provided by Align Technology (Shanghai) Trading Co., Ltd. (Registered Address: Room 2203, Ascendas Plaza No. 333, Tian Yao Qiao Road, Xuhui District, Shanghai) and its affiliates (hereinafter referred as “Align” or “We”), including Invisalign System, iTero intra-oral scanners, OrthoCAD services, and Invisalign applications and websites(including but not limited to Invisalign official website(“Invisalign Website”), APP(“Invisalign APP”), social media account, Invisalign EMT, Align Online Lecture mini-program, H5 pages and mini-program(“Invisalign Mini-program”), collectively referred to as "Align Websites").

For the avoidance of doubt, our processing of personal information based on our specific purpose when we provide specific products or services under scenarios (e.g., Invisalign IDS website, iTero intra-oral scanners, Invisalign CRM WeChat mini program, My Invisalign APP, Invisalign Practice APP, etc.) will be subject to the privacy policy or similar legal documentation that applies exclusively to the scenario for that product or service. Please be careful to read the policy otherwise provided to you in such scenarios when you use the specific product or service.

We will strictly abide by applicable Chinese laws, regulations and standards in accordance with the principles of lawfulness, fairness and necessity. We will clearly inform you of the rules, purposes, methods and scope of our collection and use of your personal information and obtain your consent. Therefore, before you access or use the products and / or services provided by Align Websites, please read and fully understand the terms of this Privacy Policy, especially the terms that will alert you highlighted in black and bold. By clicking the "Confirm" button or by checking "Agree", you have fully understood and agreed to this Privacy Policy. If you have any questions, comments or suggestions about the terms or content of this Privacy Policy, please feel free to contact us through the contact information provided at the bottom of this Privacy Policy. We are happy to provide you with feasible assistance.

Part I Definition

Personal information: refers to all kinds of information related to identified or identifiable natural persons recorded by electronic or other means, excluding the information processed anonymously.

Sensitive personal information: refers to the personal information that is likely to result in damage to the personal dignity of any natural person or damage to his or her personal or property safety once disclosed or illegally used, including such information as biometric identification, religious belief, specific identity, medical health, financial account and whereabouts and tracks, as well as the personal information of minors under the age of 14.  And sensitive personal information will be bolded and italicized in this Policy.

Affiliates: refer to Align Technology, Inc. and any other entity directly or indirectly controlled by Align Technology, Inc., including but not limited to Align Technology (Chengdu) Co., Ltd., Align Technology (Chengdu) Healthcare Management Co., Ltd, Align Technology (Sichuan) Medical Equipment Co., Ltd., etc. These affiliates are independent legal entities.

Part II Privacy Policy

The Policy will help you understand the following

I. How do we collect and use your personal information?

II. How do we use cookies?

III. How do we share, transfer, publicly disclose and store your personal information?

IV. How do we protect your personal information?

V. How do you manage your personal information?

VI. How do we process children’s personal information?

VII. How will your personal information be transferred globally?

VIII. How is this Policy updated?

IX. How to contact us?

Align is firmly aware of the importance of personal information to you, and will do our best to protect your personal information. We are committed to maintaining your trust and complying with the relevant principles of data protection to protect your personal information. In the meantime, Align undertakes that we will take security protection measures in accordance with sound security standards in the industry to protect your personal information. Please read and understand this Privacy Policy prior to using our products (or services).

  1. How do we collect and use your personal information?
    • Align only collects and uses your personal information for the following purposes set out in this Policy:
      1. Providing you with online self-services and setting up and managing your member account
        1. If you are doctor:
          1. Business function 1:  We will collect your  name, DID, phone number, e-mail address, work unit, practice certificate,  ID number,  and  bank account number to create and match your qualification as Invisalign doctor, acquire the related information and progress for conference sign-in, training, business and fulfilling contractual obligations.
          2. Business function 2:  We may collect your name, phone number, work unit, province and city , to help you enroll in online or offline training, and personal location (Precise location data)  to complete training compliance check-ins, obtain training certifications, and provide you with marketing, operational, promotional and/or publicity activities related to Invisalign products or iTero products as authorized by you.
        2. If you are consultant:
          1. Business function 1:  We will collect your name, DID, phone number, email address,  work unit, practice certificate, ID number,  and  bank account number to create and match your qualification as Invisalign consultant/speaker, acquire the related information and progress for conference sign-in, training, business and fulfilling contractual obligations.
        3. If you are iTero user:
          1. Business function 1:  We will collect your  name, DID, phone number, email address, work unit (i.e. clinic name or lab name), zip code, phone number, and  address  to create and match your qualification as doctor and open account on Align Websites.
          2. Business function 2:  We may collect your name, phone number, work unit, province and city ,  to help you enroll in online or offline training, and   personal location (Precise location data)  to complete training compliance check-ins, obtain training certifications, and provide you with marketing, operational, promotional and/or publicity activities related to iTero products as authorized by you.
        4. If you are website visitor:
          1. Business Function 1:  Start Smile Assessment
            • To complete the smile assessment, you need to provide the following information:  your identity (teenagers, adults or parents looking for solutions for their children), your name, email address, mobile phone number, treatment status and other required information for survey.
            •  
            •  The above information you provide will be authorized for our use during your use of the services.
          2. Business Function 2: To provide details of physicians and their practices so that you can identify your preferred Invisalign Provider(s) and make appointments with them
            • When you visit or use our websites, we and our third-party service provider may automatically collect your location information and log information. The log information may include:
              1. The information in server log, such as Internet Protocol (IP) address, information about Internet Service Provider, clickstream data, browser type and language, the webpages browsed and logged out, date or time stamp, your login information, browser type and version, time zone settings, browser plug-in type and version, operating system and platform.
              2. The information related to your visits: including a complete Uniform Resource Locator (URL) clickstream (including date and time) directing to, passing through, and coming from our websites, information you browse or search for; page response time, download errors, length of time of visiting certain pages, page interaction information (such as scrolling, clicking, and mouse-over), and methods for browsing the page.
              3. Information about the computer you use to download any content from our websites to your computer or device, including unique device identifiers, usage information (such as page requests and the average time of browsing our site), operating system, browser type, and mobile network information, etc. Such information is used for system management and reporting the aggregated information to our advertisers.
          3. Business Function 3: We may collect the information (such as  user name/personal name, phone number, profession, clinic name and address, email address, gender, age, city etc.) from the opt-in page on Align Websites to help you make appointment with clinic, send you our products and services promotion regarding Invisalign, iTero, exocad and other affiliated products and services. These information may include special offers, and requests for feedback.
          4. Business Function 4:  We may collect the information (such as name, email, phone number, address, work experience etc.) from your resume collected via Align Websites for the purpose to manage your recruiting and inform you of the potential job opportunities and fulfill necessary steps before setting up employment.
        5. If you are distributor:
          1. Business Function  1:  We will collect distributor’s name, address, contact’s name, phone number, email address to create and match your qualification as distributor, provide related business information and fulfilling contractual obligations.  
      2. To allow you to use, purchase, book and/or download products and services, such as  the purchase of cleaning supplies.
      3. To provide you with information about our products, services, news, and events (e.g., when you attend our various marketing, operational, promotional and/or publicity events, we may collect photo or video information containing your  facial features   to distribute live photos and/or videos of the event to attendees).
      4. To provide information about the Invisalign Doctors or the Invisalign Providers to the patient or consumer and allow them to contact the doctors.
      5. To invite you to take part in our surveys.
      6. To gather demographic information about user trends, such as age, gender, and general income levels.
      7. To analyze use of our services and products, develop new services and products, and customize our products, services and other information we make available.
      8. Other purposes in accordance with Chinese laws and regulations and/or per your consent.
  1. How do we use cookies?
    •  
    • Cookies are small-sized text files. By reading the information included in them, we can distinguish you from other users, facilitate your visit, collect statistical data, and support personalized online experience.
    •  
    • When you visit Align Websites, we may assign your company one Cookie or some cookies. By visiting Align Websites, you agree that we place cookies on your computer or device.
    •  
    • Align Websites currently are using cookies for the following purposes including without limitation testing the multimedia features of your web browser, tracking the promotional advertising we display to you, storing current login and purchasing information in the secure part of the websites, providing a unique identifier for your computer or device so that we can generate statistical data regarding use of websites.
    •  
    • Most browsers automatically accept cookies, but you can refuse cookies by modifying your browser settings. For more information about cookies and changing browser settings to refuse cookies, please visit the “Help” menu in your browser. If you refuse cookies from Align Websites, you may not able to use all the functions of the sites which may result in restrictions or improper functioning of certain features provided by our sites.
    •  
    • Align Websites may allow third parties to download cookies into your device. When you visit Align Websites, third parties such as analytic companies and business partners may use cookies and other techniques to collect non-personal information about your online activities. The above information may be used to assess use of Align Websites, and personalize the content of Align Websites’ advertising. We can’t access or control cookies or other features that may be used by such third parties. And this Privacy Policy does not cover the use of cookies or information protection measures by such third parties.
    •  
      • Web beacon and pixel tag

        In addition to cookies, we will also use some other similar techniques such as web beacon and pixel tag on Align Websites. For example, the email we send to you may include a click URL that links to the content of our websites. If you click on this link, we’ll track this click to help us to understand your products or services preferences and improve customer service. Web beacons are clear images that are embedded in the websites or emails. By virtue of pixel tag in emails, we can tell whether the email has been opened or not. If you don’t want your activities to be tracked in this way, you can unsubscribe from our mailing list at any time.

      • Do Not Track

        Most web browsers have a Do Not Track feature that can issue Do Not Track requests to websites. Currently, major Internet standard organizations have not yet set up policies to specify how websites should respond to such requests. However, if your browser has Do Not Track features enabled, all of our websites will respect your choice.

  1. How do we process, share, transfer, publicly disclose and store your personal information?
    1. Processing
      • For the purpose of improving service efficiency, we may entrust a third party (including Align’s related parties) to process the personal information you provide on our behalf. For the third party entrusted by us to process the personal information, we will sign a data processing agreement with a such third party, requiring the third party to process your information in accordance with the terms of its agreement, this Policy and the requirements of the applicable Chinese data privacy laws and regulations.
    2. Sharing
      • We will not provide the personal information you provided with any personal information handler, except that we could obtain separate consent from you, or there is a legal basis from laws and regulations. When providing such personal information, we will inform you of the recipient ‘s name, contact information, purpose of processing, manner of processing and type of personal information.
    3. Transfer
      • We will not transfer your personal information to any companies other than Align, any organizations or any individuals with the following exceptions:
        1. Transfer after express consent is obtained: after your express consent is obtained, we will transfer your personal information to other parties.
        2. When personal information transfer is involved in the process of merger, division, dissolution, or being declared bankruptcy, we will inform you of the name and contact information of the new company or organization that holds your personal information. Where such companies or organizations change the original purpose and method of the transaction, such companies or organizations shall ask for your informed consent again, unless otherwise specified by laws and regulations.
    4. Public Disclosure
      • We will publicly disclose your personal information only under the following circumstances:
        1. After your separate consent is obtained
        2. Disclosure based on laws: we may publicly disclose your personal information when required by laws, legal procedures, proceedings or mandatory requirements of government authorities.
    5. Storage
      1. Location of storage:
        • Personal information collected and generated by us during our operations in the People's Republic of China is stored in China, with the following exceptions:
        •  
          1. Laws and regulations have clear provisions;
          2. Obtain your explicit authorization.
        • In the light of the above, we will ensure that your personal information is adequately protected in accordance with this Privacy Policy.
      2. Period of storage:
        • We will only retain your personal information for the minimum period of time required to achieve the purposes stated in this Policy, unless applicable legislation has a mandatory retention requirement. And we judge the criteria for the aforementioned deadlines include:
        •  
          1. Complete the service purpose related to data subject, maintain the corresponding service and business records, and respond to your possible inquiries or complaints;
          2. Guarantee the safety and quality of the services we provide to you;
          3. Do you agree to retain a longer retention period?
          4. Whether there are other special agreements for the retention period.
          5. After your personal information exceeds the retention period, we will delete your personal information or anonymize it as required by applicable law.
      3. Stop operation:
        • If the Align Websites decide to terminate operations, we will stop collecting your personal information after the related services stop operating. We will deliver the notice of suspension of operation to you in the form of an announcement. Your personal information will be deleted or anonymized.
  1. How do we protect your personal information?
    1. We have taken security protection measures which comply with the industry standards to protect your personal information, and to prevent data from unauthorized access, public disclosure, use, modification, damage or loss. We will take all reasonable and feasible measures to protect your personal information. For example, when you exchange data (such as credit card information) between your browser and “services”, it will be protected by SSL encryption; we’ll also provide https secure browsing for Align Websites; we’ll use encryption techniques to ensure confidentiality of data(especially children’s personal data); we will use trusted protection mechanisms to prevent data from malicious attacks; we’ll deploy access control mechanisms to ensure only authorized staff have access to personal information; and we will organize training courses on security and privacy to strengthen employees’ awareness about importance of personal information protection.
    2. We’ll take all reasonable and feasible measures to ensure that no irrelevant personal information is collected. We will only retain your personal information for the period required to fulfill the purposes described in this Policy unless the retention period needs to be extended or it is permitted by laws.
    3. Internet is not an absolutely secured environment and email, instant messaging, and other ways of communication with other Align users are not encrypted. We strongly recommend that you don’t send personal information by these methods. Please use a complex password to help us secure your account.
    4. After personal information security incidents happen unfortunately, we’ll inform you the following in a timely fashion in accordance with requirements of laws and regulations: the basic situation and the potential influence of the incident, the measures we’ve taken or will take, the suggestion for your self-protection and risk reduction, remedies, etc. We will promptly notify you of the incident by email, letter, telephone, push notification, etc. When it is difficult to notify owners of personal information one by one, we’ll issue a notice in a reasonable and effective manner. In the meantime, we’ll report on the handling of personal information security incidents according to the requirements of laws and regulations.
  2. How do you manage your personal data?
    • In accordance with China’s relevant laws, regulations and standards, and common practice in other countries, regions, we guarantee that you exercise the following rights in your personal information:
      1. Access to your personal information:
        • You have the right to access your personal information, with those exceptions in laws and regulations. If you want to exercise data access rights, you can request access by sending a written request to the following Align’s email address: privacy@aligntech.com.
        • In general, we will respond to your request for access within 15 days.
      2. Correction of your personal information
        • When you find your personal information we process is incorrect, you have the right to require us to correct it. You can request a correction by sending a written request to the following Align’s email address: privacy@aligntech.com
        • In general, we will respond to your request for access within 15 days.
      3. Deletion of your personal information
        • You can request deletion of personal information under the following circumstances:
          1. If our processing of your personal information violates laws and regulations
          2. If we collect, use your personal information.
          3. If our processing of your personal information violates any agreement with you
          4. If you withdraw consent or no longer use our products or services or close your account
          5. If we no longer provide products or services for you
        • Please be noted that when you delete information from our services or we receive and consent to your request to delete your personal data, we may not immediately delete it accordingly from the back-up system, but will delete such information when updating the back-up.
      4. Changing the scope of your consent
        • Each business function requires some basic personal information to be completed (see part one of this Policy). For collecting and using personal information on the legal basis of informed consent, you may give or withdraw your consent at any time.
        • When you withdraw your consent, we’ll no longer process the corresponding personal information. However, your decision to withdraw your consent will not affect the processing of personal information which is conducted based on your previous consent. If you don’t want to accept the commercial advertisements we send to you, you can cancel at any time by sending an email to privacy@aligntech.com
        • In general, we will respond to your request for access within 15 days.
      5. De-register your system account
        • When you wish to de-register your system account, you can send an email to privacy@aligntech.com.
        • In general, we will respond to your request within 15 days.
      6. Transfer or Get a copy of your personal information
        • When you wish to obtain a copy of personal information or request us to transfer your personal information to another personal information processor provided that statutory conditions are met, you can request a copy by sending an email to privacy@aligntech.com.
        • In general, we will respond to your request within 15 days.
      7. Responding to your request above
        • To ensure security, you may need to provide a written request or otherwise to prove your identity. We may require you to verify your identity before processing your request.
        • In general, we will respond to your request for access within 15 days.
        • For your reasonable request, we don’t charge fees in principle. However, we will charge a certain amount of costs for requests that are repeated many times and exceed reasonable limits. For those requests that are duplicative, require excessive technical means (for example, which need to develop new systems or fundamentally change current practices), pose risks to the legitimate rights of others, or are very impractical (for example, involving backup of information stored on tapes), we may reject them.
        • We may not be able to respond to your request, under the circumstances.
          1. Directly related to national security and national defense security;
          2. Directly related to public safety, public health and major public interests
          3. Directly related to a criminal investigation, prosecution, trial and execution of judgments, etc.
          4. There is sufficient evidence that you have a malicious will or abuse your rights.
          5. Responding to your request will result in significant damages to legitimate rights and interests of you, other individuals, and organizations.
          6. Trade secrets involved.
  1. How do we process children’s personal information?
    • Our products, websites and services are aimed at adults and teenagers. We will not collect children’s information without parents or guardians’ explicit consent.
    • We’ll only use or publicly disclose children’s personal information collected under parents or guardians’ consent if permitted by law, explicit consent of parents or guardians is obtained and it is necessary for protecting children.
    • Although the definition of children varies according to local laws and customs, we’ll not treat anyone under 14 years old as children.
    • If we find that we collect children’s personal information without prior consent of verifiable parents or guardians, we’ll try to delete such data as soon as possible.
  2. How will your personal information be transferred globally?
    • In principle, personal information collected and generated within People’s Republic of China will be stored within the territory of People’s Republic of China, with the exception of cross-border transfer is permitted by applicable China laws and regulations.
    • Since we operate globally, upon meeting requirements of Chinese laws and regulations, your personal information may also be stored on our servers which may be located outside the jurisdiction of your place of residence, with the purpose to entrust our related companies (See Part I Definition) to process the personal information in accordance with the purpose and methods listed in this Policy. However, we will continue to protect your information in accordance with this Policy. You may contact the email address under Article 9 to exercise your rights under the applicable China laws and regulations.
    • This Privacy Policy and the collecting and processing of information based on this Privacy Policy are governed and interpreted by the laws of the People’s Republic of China. No matter where we transfer, store or process your personal information, we’ll take reasonable steps to protect privacy of your personal information.
  3. How is this Policy updated?
    • Our privacy policy may change.
    • Without your explicit consent, we’ll not reduce your rights based on this Privacy Policy. We will post any changes to this Policy on this webpage.
    • For significant changes, we’ll also provide an explicit notice explaining the specific changes to this Privacy Policy.
    • The significant changes in this Policy include without limitation:
      1. There have been major changes in our service mode. For example, the purpose of processing personal information, the type of personal information to be processed, the use of personal information, etc.
      2. We have undergone major changes in ownership structure, organizational structure, changes in owners caused by business adjustments, bankruptcy, M&A, etc.
      3. The main objects of personal information sharing, transfer or disclosure happen
      4. Your rights about personal information processing and the exercising way change significantly
      5. There are changes in the department responsible for personal information security, contact, and compliant channels;
      6. Personal information security effect assessment report indicates high risks.
    • We’ll file the old version of this Policy for your reference
  4. How to contact us?
    • If you have any questions, opinions or suggestions, you can contact us by following methods.
    • Name: Align Technology (Shanghai) Trading Co., Ltd.
    • Address: 22F, Ascendas Plaza No. 333, Tian Yao Qiao Road, Xuhui District, Shanghai
    • Email address: privacy@aligntech.com
    • We have set up a department specialized in personal information protection or (a personal information protection specialist), you can contact them at the above email address.
    • In general, we’ll give responses within 15 days.