Privacy Policy
KWM Gutterman, Inc. (“Company,” “we,” “us,” or “our”)
Last Updated: 7/24/2026
1. Introduction and Scope
This Privacy Policy describes how KWM Gutterman, Inc., an Illinois, USA, corporation with its principal place of business at 795 S Larkin Ave, Rockdale, IL 60436, collects, uses, discloses, retains, and safeguards personal data in connection with:
- Our website at www.kwmgutterman.com and related digital properties (the “Site”);
- Our client account portals, e-commerce, and quotation systems (the “Portals”);
- Requests for quotation (“RFQs”), lead generation forms, trade show and marketing interactions;
- Telemetry, diagnostic, and performance data generated by connected industrial machinery we manufacture, sell, lease, or service (“Connected Equipment”); and
- Our sales, service, warranty, and support relationships with business customers, distributors, and suppliers.
We operate primarily in a business-to-business (B2B) context. The personal data we process generally relates to individuals acting in their professional capacity (e.g., procurement officers, plant engineers, maintenance technicians, authorized signatories). This Policy applies to those individuals as well as to any consumer-capacity visitors to the Site.
2. Categories of Personal Data We Collect
2.1 Data You May Provide Directly
| Category | Examples | Typical Source |
| Business contact identifiers | Name, job title, employer, business email, business phone, business address | RFQ forms, lead forms, Portal registration, trade shows |
| Account credentials | Username, password (hashed), security questions, multi-factor tokens | Portal registration |
| Commercial and transactional data | RFQ contents, purchase orders, quotations, contract terms, order history, shipping details, tax IDs (e.g., EIN, VAT number) | Sales and fulfillment processes |
| Payment data | Bank account details, wire instructions, credit references, letter-of-credit details (card data is processed by PCI-DSS compliant processors; we do not store full card numbers) | Invoicing and payment |
| Communications | Emails, support tickets, call recordings (where permitted and disclosed), meeting notes | Sales, service, and support interactions |
| Compliance and screening data | Government-issued ID of authorized signatories where required, end-use/end-user statements, denied-party screening results | Export control and sanctions compliance (Section 8) |
2.2 Data Collected Automatically
| Category | Examples |
| Device and usage data | IP address, browser type and version, operating system, referring URLs, pages viewed, session duration, clickstream data |
| Cookies and similar technologies | Session cookies, persistent cookies, pixels, tags, and SDKs (see Section 6) |
| Portal activity logs | Login timestamps, documents downloaded (e.g., spec sheets, CAD files, manuals), quote configurations |
2.3 Connected Equipment / IoT Telemetry
Connected Equipment may transmit machine-generated data to us, including:
- Operating parameters (temperature, pressure, vibration, cycle counts, throughput, energy consumption);
- Fault codes, error logs, and predictive maintenance indicators;
- Firmware/software version and configuration data;
- Equipment geolocation (where GPS/network-based location modules are installed and enabled); and
- Operator identifiers only where the customer configures the equipment to associate telemetry with individual operator logins.
Telemetry is primarily machine data, not personal data. Where telemetry can be linked to an identifiable individual (e.g., operator IDs, badge scans), we treat that data as personal data under this Policy. Our collection of telemetry is governed by the applicable equipment sales, lease, or service agreement, which controls in the event of conflict. Customers are responsible for providing any legally required notices to their own personnel regarding workplace telemetry.
2.4 Data From Third-Parties
We may receive personal data from: business information providers (e.g., Dun & Bradstreet), sanctioned-party screening databases, credit bureaus, our authorized distributors and sales agents, trade show organizers, and publicly available professional sources (e.g., corporate websites, LinkedIn).
3. Purposes and Legal Bases for Processing (GDPR/UK GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
| Purpose | Legal Basis |
| Responding to RFQs; preparing quotations; negotiating and performing contracts | Contract performance (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) where the contracting party is a legal entity and the data subject is its representative |
| Portal account creation and administration | Contract performance; legitimate interests |
| Order fulfillment, shipping, installation, commissioning, warranty, and service | Contract performance; legitimate interests |
| IoT telemetry: remote diagnostics, predictive maintenance, safety monitoring, warranty verification | Contract performance; legitimate interests (equipment reliability, safety, product improvement) |
| Product research and development using aggregated/de-identified telemetry | Legitimate interests |
| B2B direct marketing (newsletters, product announcements, trade show invitations) | Legitimate interests, with opt-out at all times; consent where required by local ePrivacy/marketing laws |
| Cookies and non-essential tracking | Consent (Art. 6(1)(a)) via our consent management platform |
| Export control, sanctions screening, denied-party screening, customs compliance | Legal obligation (Art. 6(1)(c)); legitimate interests |
| Fraud prevention, network and information security | Legitimate interests; legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interests |
| Corporate transactions (merger, acquisition, financing, asset sale) | Legitimate interests |
We do not use personal data for automated decision-making producing legal or similarly significant effects on individuals without human involvement.
4. Data Retention
We may retain personal data only as long as necessary for the purposes described above, and thereafter as required for legal, tax, warranty, and product-liability purposes typical of industrial equipment with multi-decade service lives. When retention periods expire, data is securely deleted or irreversibly anonymized.
5. Disclosure of Personal Data
We may disclose personal data to:
- Service providers / processors — hosting, cloud infrastructure, CRM, ERP, payment processors, freight forwarders and customs brokers, IoT platform providers, analytics vendors, and professional advisors — under contracts requiring confidentiality and data protection terms (including Art. 28 GDPR processor terms where applicable).
- Affiliates and subsidiaries — for the purposes described in this Policy, subject to intra-group data transfer agreements.
- Authorized distributors, sales agents, and installation/service partners — to fulfill quotes, orders, installation, and service in your region.
- Government authorities and regulators — including customs, export control, and sanctions authorities, where required by law or valid legal process.
- Parties to corporate transactions — in connection with any merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality protections and, where required, notice to you.
We do not sell personal data for monetary consideration. See Section 10 for our CCPA/CPRA “sale”/“sharing” disclosures regarding advertising cookies.
6. Cookies and Tracking Technologies
We may use the following categories of cookies and similar technologies:
- Strictly necessary — authentication, security, load balancing, consent-state storage (no consent required).
- Functional — language, region, and portal preferences.
- Analytics/performance — aggregate usage measurement and/or third-party analytics provider.
- Advertising/targeting — B2B remarketing and campaign measurement, and/or third-party advertising platform.
Non-essential cookies are deployed only with your consent where required (EU/UK/other consent jurisdictions), collected via our consent management platform, which you may revisit at any time. U.S. visitors may opt out of targeting cookies via the same mechanism, or via the Global Privacy Control (GPC) browser signal, which we honor as an opt-out of sale/sharing where legally required.
Our Site does not otherwise respond to legacy “Do Not Track” browser signals, for which no standard has been adopted.
7. International Data Transfers
We are a global business. Personal data may be transferred to and processed in the United States and other countries where we, our affiliates, or our processors operate, which may not provide the same level of data protection as your home jurisdiction.
Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on:
- The European Commission’s Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, supplemented by transfer impact assessments and technical/organizational safeguards;and/or
- Derogations under Art. 49 GDPR where applicable (e.g., transfer necessary for contract performance).
Transfers from other jurisdictions with data localization or cross-border transfer rules (e.g., China PIPL, if applicable to your operations) are handled under jurisdiction-specific mechanisms; contact us for details.
8. Export Control and Sanctions Screening
As a manufacturer of industrial machinery, we are subject to U.S. export control laws (EAR and, where applicable, ITAR), EU dual-use regulations, and economic sanctions administered by OFAC, the EU, the UK OFSI, and the UN. We screen customers, contacts, consignees, and end users against restricted- and denied-party lists and may collect nationality, end-use, and end-user information required for licensing determinations. This processing is a legal requirement; we cannot transact where screening cannot be completed.
9. Your Rights – EEA, UK, and Similar Jurisdictions
Subject to applicable law, you may have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing (including objecting to direct marketing at any time); data portability; and withdraw consent (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority (in the EEA) or the ICO (UK).
To exercise rights, contact us per Section 13. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity and, in the B2B context, may coordinate with your employer where the data relates to a corporate account.
10. California Privacy Rights (CCPA/CPRA)
This section applies to California residents. Note that certain B2B and employment-related data is fully covered by the CCPA as amended by the CPRA.
Categories collected (last 12 months): identifiers; customer records (Cal. Civ. Code § 1798.80(e)); commercial information; internet/network activity; geolocation (equipment-level, and coarse IP-based); professional/employment-related information; and inferences. Sources, purposes, and disclosures are as described in Sections 2, 3, and 5.
Sale/Sharing: We do not sell personal information for money. Our use of third-party advertising/analytics cookies may constitute a “sale” or “sharing” (for cross-context behavioral advertising) under the CPRA. You may opt out as specified in Section 6. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not knowingly sell or share the personal information of consumers under 16.
Your rights: to know/access, delete, correct, opt out of sale/sharing, limit use of sensitive personal information (not applicable to our practices), and non-discrimination for exercising your rights. Submit requests via [email protected]. We will verify your request and respond within 45 days (extendable once by 45 days). You may designate an authorized agent with written permission.
Retention: as set forth in Section 4.
11. Other U.S. State Privacy Laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. Submit requests per Section 13; if we decline a request, you may appeal by replying to our decision, and we will respond per applicable state law.
12. Security; Children; Third-Party Links
We maintain administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit, access controls, network segmentation for IoT infrastructure, logging, and vendor due diligence. No system is perfectly secure; we cannot guarantee absolute security. We will notify affected parties and regulators of breaches as required by law.
Our Site and services are intended for business users and are not directed to children under 16 (or under 13 in the U.S.). We do not knowingly collect children’s data.
The Site may link to third-party websites; their privacy practices are their own, and we are not responsible for them.
13. Contact Us; Changes to This Policy
KWM Gutterman, Inc.
795 S Larkin Ave, Rockdale, IL 60436
United States
Phone: 888-729-4290
We may update this Policy from time to time. Material changes will be announced via the Site (and, for Portal account holders, by email) before taking effect, and the “Last Updated” date will be revised. Continued use of the Site or services after the effective date constitutes acceptance to the extent permitted by law; where consent is legally required for a change, we will obtain it.