Privacy Policy
This Privacy Policy describes how your personal data is processed by the various companies that form part of the CHECKPOINT GROUP (hereinafter “CHECKPOINT” or “CKP”) via the Site: https://checkpointsystems.com/ (hereinafter the “Site”).
Your personal data will be processed in accordance with the provisions of current legislation on the protection of personal data. In particular, and without limitation, this includes, amongst others:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC -General Data Protection Regulation- (hereinafter, “GDPR”);
- any national legislation, from any country, governing the processing of personal data;
- or any legislation amending, implementing or replacing the foregoing.
The entity with which you have a relationship will act as the data controller for your personal data. Furthermore, depending on the specific circumstances, the data controller may be any of the companies forming part of the Checkpoint Group, which you can view via the following link: Checkpoint Group Companies; this will be indicated in each case through the relevant information clause.
Whenever we collect your personal data, we will inform you of the entity acting as the data controller, including its identification and contact details.
1. Personal data that you provide to us
Generally, the personal information you provide to us (via the form on the Site or when you contact our customer service team) is name and surname, country, email address, contact telephone number and company. In very specific cases and depending on the purpose and intended use of your data, we may collect data relating to your personal and professional characteristics, CVs, employment details, commercial, financial and insurance information, and transactions involving goods and services.
In this regard, the personal data indicated above is mandatory to process your requests; consequently, a refusal to provide such data will make it impossible to process your requests and, where applicable, to provide the requested services.
Should you provide data relating to third parties, you confirm that you have their consent and undertake to pass on the information contained in this clause to them, thereby exempting CHECKPOINT from any liability. In any event, CHECKPOINT may carry out periodic checks to verify this, adopting the appropriate due diligence measures in accordance with applicable regulations.
Furthermore, where necessary to protect the security of the Site, prevent misuse or verify that interaction with the forms constitutes legitimate activity and is not automated, we may process additional technical data derived from the use of security mechanisms, fraud prevention, spam filtering or CAPTCHA, including the IP address, device and browser information, activity logs and other data strictly necessary to detect and mitigate unauthorized access, malicious bots, spam or automated attacks.
2. Personal data we collect
The Site uses cookies (and/or similar technologies) so that, depending on your cookie settings, CHECKPOINT may collect and process personal data.
Generally, we collect and store limited personal information and anonymous aggregate statistics from all users who visit our Site, whether you actively provide us with this information or are simply browsing our Site. The information we collect includes the Internet Protocol (IP) address of the device you are using, the browser you are using, your operating system, the date and time of access, the web address of the site from which you accessed our Site, and information about how you use our Site.
For further information on the use and configuration of cookies (and/or similar technologies), please see our Cookie Policy.
CHECKPOINT will process your personal data for the following purposes:
- If you request information via the forms provided for this purpose or contact our customer service team, to process and respond to your request, as well as to provide you with the best possible service;
- To comply with legal obligations, including, but not limited to, Law 10/2010 on the Prevention of Money Laundering;
- Where applicable, to share your data with other companies within the business group to which CHECKPOINT belongs, specifically the company CCL Industries Inc., for internal administrative purposes, including the processing of customers’ personal data;
- Where applicable, to share your data with CHECKPOINT distributors in territories where we do not have an established business presence, for the purpose of managing and handling enquiries or requests relating to our products and services;
- Depending on your cookie settings, carrying out statistical analyses and creating profiles based on your browsing habits;
- To ensure the security, availability and integrity of the Site, the forms available on it and, where applicable, CHECKPOINT’s online platforms, including the prevention, detection and mitigation of unauthorized access, misuse, attempted fraud, spam, malicious bots, automated attacks or other activities that may compromise the security of our systems, users, customers or services, by processing strictly necessary technical and browsing data, as well as, where appropriate, through the use of verification mechanisms or CAPTCHAs.
- To identify the individuals representing the customer or acting as points of contact for the purposes of the contract. This processing only applies where the customer is a legal entity;
- To manage the commercial relationship with our customers, including the processing of orders, the provision of contracted services, and the installation, maintenance and technical support of our security solutions;
- To carry out the due diligence processes implemented by CHECKPOINT in its dealings with third parties to ensure business integrity;
- To the extent necessary, to assess the financial solvency of business clients (legal entities) before granting trade credit terms;
- To bring or defend legal claims in the event of non-payment;
- If you have applied for a job with us, we will process your information to assess your candidacy for the relevant vacancy;
- To send marketing communications relating to our products or services, should you have subscribed or requested them, without this involving profiling or the disclosure of your personal data to third parties.
- To manage access to our online platforms and enable their use in accordance with the intended purpose of each platform.
The legal bases for processing your personal data for the purposes described above are as follows:
- If you request information via the ‘Contact Us’ form or get in touch with our customer service team: the performance of the contractual relationship with you, or taking steps prior to entering a contract if you are not yet a customer;
- To comply with the various legal obligations applicable by virtue of the data controller’s activities;
- Where applicable, to disclose your data to other companies within the group to which CHECKPOINT belongs. These include, amongst others, the company “CCL INDUSTRIES INC.”, based on our legitimate interest consisting of the centralized and efficient administrative management of the business group, the optimization of resources and the improvement of our services;
- Where applicable, to disclose your data to CHECKPOINT distributors in territories where we do not have an established place of business, the legal basis being the taking of steps prior to entering a contract at your request;
- Where applicable, your consent to carry out statistical analyses and create profiles based on your browsing habits using cookies, which you may withdraw at any time;
- We rely on our legitimate interest in ensuring the security, availability and integrity of the Site, the forms available on it, our online platforms and CHECKPOINT’s information systems, as well as in preventing, detecting and mitigating unauthorized access, misuse, spam, malicious bots, attempts at fraud, automated attacks or other activities that may compromise the security of our systems or services
- We rely on our legitimate interest in the efficient management of our commercial relationships with business customers, to identify the individuals who represent the customer or act as points of contact for the purposes of contracting;
- The performance of the contractual relationship with you, to manage the business relationship, including the processing of orders, the provision of the contracted services, and the installation, maintenance and technical support of our security and RFID technology solutions;
- We act based on a legitimate interest in applying the necessary due diligence procedures in the management and assessment of third parties to ensure business integrity;
- We rely on our legitimate interest, consisting of the protection of trade credit and the defense of our rights and interests, to assess the creditworthiness of business customers;
- We rely on our legitimate interest to deal with potential claims and take legal action;
- If you have applied for a vacancy with us, in the context of the performance of the contract or pre-contractual measures, we will process your data for the selection of qualified personnel and the efficient management of our relationship, to fulfil these purposes.
- Your consent to receive marketing communications, should you have subscribed or requested them, which you may withdraw at any time, without this involving profiling or the disclosure of your personal data to third parties.
- The performance of a contract, to manage access to and use of our online platforms in accordance with their specific functionalities.
As part of the provision of our services and the use of the various applications and technological solutions developed and/or marketed by CHECKPOINT, various forms of personal data processing associated with the operation of these tools may take place.
Each of these applications may involve the processing of personal data for specific purposes, depending on the type of solution implemented, the user profile and the context in which it is used.
Set out below are the applications that may involve the processing of personal data, as well as the main characteristics of the processing associated with each one, including the purpose, the categories of data processed and, where applicable, the legal basis justifying such processing.
Review the checkpoint applications here.
- where applicable, to competent authorities and bodies, courts, tribunals or any other third parties authorized under the applicable regulations;
- where applicable, to other companies within the business group to which CHECKPOINT belongs, specifically the entire CCL Group, for internal administrative purposes, including the processing of customers’ personal data, as detailed in the following link: CCL GROUP COMPANIES, which lists these entities.
- where applicable, to CHECKPOINT distributors in territories where we do not have an established business presence, for the purpose of managing and responding to enquiries or requests relating to our products and services.
However, CHECKPOINT has contracted out the provision of certain services (e.g. virtual infrastructure services, cloud computing, customer relationship management, the organization of games and competitions, the management of loyalty programs, the sending of marketing emails, as well as blocking malicious bots and spam in forms and logins, amongst others) to suppliers, who may have access to and/or process personal data in their capacity as data processors. Some of these suppliers may process and store personal information on servers located outside your country of residence; you can view details of these suppliers at or by sending an email to direction: privacy@checkpt.com.
Therefore, depending on the user’s location, data transfers to other countries may occur, whether in relation to companies within the CCL Group, distributors or partners. In such cases, your personal data may be transferred internationally to third parties located outside the European Economic Area (“EEA”), if CHECKPOINT is authorized to do so and subject to compliance with the appropriate safeguards set out in Articles 44 to 50 of the GDPR. Such third parties will only access the data to carry out their services on behalf of CHECKPOINT and in accordance with its instructions, subject to a duty of confidentiality and always following its instructions and may not at any time use such data for their own purposes and/or unauthorized purposes.
In any event, the appropriate safeguards include, amongst others:
- European Commission adequacy decision: a declaration by the European Commission that a non-EU country offers an adequate level of data protection equivalent to that provided by European data protection legislation, thereby enabling the international transfer of data to a third party established in that non-EU country;
- Binding Corporate Rules (BCRs): these apply to corporate groups or associations of companies engaged in a joint economic activity, enabling the flow of personal data based on self-regulation accepted and undertaken by each of the signatory entities;
- Standard Contractual Clauses (SCCs): are contractual clauses adopted by the European Commission that may be used to provide appropriate safeguards for transfers of personal data to third countries.
- A code of conduct or a certification scheme, together with binding and enforceable commitments, undertaken by the recipient regarding the application of appropriate safeguards for the protection of the transferred data.
- In the absence of the above, your personal data may, in exceptional circumstances, be transferred to a third country or international organization, in accordance with the mechanisms recognized in this regard by data protection legislation.
CHECKPOINT will, in order of preference, carry out international transfers subject to the following safeguards:
| Safeguard | Criterion used by CHECKPOINT |
|---|---|
| European Commission adequacy decision | Measure considered a priority by CHECKPOINT. You can find the list of countries covered by an adequacy decision at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en |
| Binding Corporate Rules | In the absence of an Adequacy Decision, this will be the preferred safeguard that CHECKPOINT will require from the importer of personal data. The list of organizations with BCRs can be found here: https://edpb.europa.eu/our-work-tools/accountability-tools/bcr_en?page=1 |
| Standard Contractual Clauses | As a secondary safeguard in the absence of the above, we will sign and/or request a copy, as appropriate, from the importer of the personal data, of the signed version of the Standard Contractual Clauses in line with the European Commission’s templates, available here: https://eur-lex.europa.eu/legal-content/ES/ALL/?uri=CELEX%3A32021D0914 |
Similarly, CHECKPOINT makes its Data Processing Agreement (DPA) available to data subjects; this forms part of the contractual framework applicable to the processing of personal data by external suppliers and Group entities. This document sets out the conditions, responsibilities and safeguards required under the GDPR.
You can access the DPA via the following link: .
CHECKPOINT will retain your personal data to fulfil and/or carry out the services requested (if you do not request its erasure or object to its processing via using the methods set out in the section ‘YOUR RIGHTS’). Once this processing period has ended, CHECKPOINT will retain the personal data with restricted access, where necessary, for the duration of the limitation period for criminal, civil, commercial and/or administrative liabilities of any kind, as well as for the periods required to comply with legal obligations or to defend against claims. Once these periods have elapsed, the personal data will be securely deleted.
CHECKPOINT will process the personal data of users of the respective applications for as long as the commercial or contractual relationship remains in force and for as long as such users retain their status as authorized users of each application. However, for each instance of data processing carried out via the respective applications, the period for which personal data is processed will be determined based on the nature of the service, the purpose of the processing, the validity of the user account, the client organization’s instructions, internal criteria regarding inactivity and access management, as well as any applicable legal, contractual or regulatory obligations.
Nevertheless, for each instance of data processing, in the information we provide to you at the time your personal data is collected, we will inform you of the applicable retention period for your personal data in relation to that specific processing. Furthermore, we inform you that we will take all reasonable measures to ensure that your data is rectified or erased where it is inaccurate.
At any time, you may exercise several rights regarding the processing of your personal data. These rights are inherent to every data subject and, as such, are inalienable; they are as follows:
- Right of access: The right to access the personal data processed by the data controller in accordance with Article 15 of the GDPR.
- Right to rectification: The right to request that the data controller rectify certain personal data relating to the data subject in accordance with Article 16 of the GDPR.
- Right to object: The right to object to processing based on legitimate interests or carried out for direct marketing purposes in accordance with Article 21(2) of the GDPR. In cases where the processing is based on a legitimate interest, the data subject shall have the right to request the balancing test report carried out by the data controller. Furthermore, where the purpose of the processing is to send commercial information from the data controller or third parties, the data subject may, free of charge and on a voluntary basis, opt out of advertising (For users in Spain, further information about advertising opt-out mechanisms is available at https://www.listarobinson.es/).
- Right to erasure: The right to request that the data controller erase all or part of the Data Subject’s personal data in accordance with Article 17 of the GDPR. Please note that whilst the commercial and/or contractual relationship we have with you remains in force, there is a range of personal data that we need to process in order to fulfil the contract; therefore, for the duration of the contract, we may be unable to erase or restrict the processing of certain data where such data is necessary for the performance of the contract or compliance with legal obligations.
- Right to restriction of processing: The right to obtain from the data controller the restriction of the processing of your personal data, if any of the conditions set out in Article 18 of the GDPR apply.
- Right to data portability: The right to receive the data you have provided to the data controller in a structured, commonly used and machine-readable format, and to transmit it to another data controller (or to have it transmitted directly to the new data controller, where technically feasible), in accordance with Article 20 of the GDPR.
- Right to withdraw consent: consent given for the processing operations identified in the section on processing based on the data subject’s consent, without such withdrawal having retroactive effect, in accordance with Article 7(3) of the GDPR.
- Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects the data subject. The data controller hereby informs the data subject that, whilst it does carry out decisions based on automated systems, these decisions (i) either do not produce legal effects or significantly affect the data subject; or (ii) are not adopted exclusively by automated means.
We will respond to your request as soon as possible and, in any event, within the statutory time limit. You may also withdraw your consent at any time by emailing at privacy@checkpt.com. Withdrawal of consent will not affect the lawfulness of processing carried out before its withdrawal.
If you consider that we have not processed your personal data in accordance with the applicable data protection legislation, you have the right to lodge a complaint with the competent data protection supervisory authority in the European Union Member State in which you reside, work or where the alleged infringement took place. You can consult the list of supervisory authorities in the European Union via the Site of the European Data Protection Board (EDPB).
Furthermore, CHECKPOINT does not market its products or services to end consumers in the United States, nor does it process personal data of US residents in an individual or domestic context. For further information on this matter, we recommend that you consult the following link: , which forms an integral part of this Privacy Policy.
Finally, we would like to remind you that if you provide us with data relating to another individual, you must, prior to its inclusion, inform that person of the provisions contained in this Policy.
You are responsible for all the information and personal data you provide to us, always guaranteeing its truthfulness, accuracy, validity and authenticity, and, where applicable, that you have the necessary authority or consent to provide such data.
You are also responsible for any information relating to third parties that you provide to us. In such cases, you undertake to ensure that you have a valid legal basis or authorization to provide such data and that you have informed the relevant third parties of the content of this Privacy Policy.
You undertake to hold all companies within the CHECKPOINT GROUP harmless from any liability arising from the absence of information or the relevant consent from the third party.
You must be of legal age to use the services offered via this Site. If we discover that you are under 14 years of age, we may block or delete any personal data you may have provided to us. In any event, the parents or guardians of a minor, may contact at privacy@checkpt.com to block and/or delete the minor’s personal data, using the methods set out in the ‘YOUR RIGHTS’ section of this Privacy Policy.
Should a person under the age of 14 provide personal data via the forms available on the Site, CHECKPOINT will request verification of authorization from their parents or legal guardians before proceeding with the processing, or, where applicable, delete the data where such verification is not possible.
We would also like to remind you that our services are intended for adults, and we recommend that minors do not provide their data without the supervision and authorization of their parents or guardians. It is also your responsibility to review this Policy periodically and check for any updates.
This Site may include, display or provide links to other sites for your convenience and information. These sites may operate independently of us. Linked sites may have their own privacy policies; we strongly recommend that you read them when you visit them. As any linked site you visit is not owned or controlled by us, we are not responsible for the content of such site, their use or their privacy practices.
This Policy may be updated from time to time to reflect changes in our processing of personal data. We will post a prominent notice on the Site to notify you of any significant changes to our Policy and will indicate at the bottom of the Policy when it was last updated.
Last updated: July 2026
© 2026 – Reproduction in whole or in part is prohibited. All rights reserved.
