California Consumer Privacy Act Disclosures
These disclosures are provided by KLA Corporation and their corporate affiliates (“Company,” “KLA,” or “us”) and apply solely to residents of the State of California (“consumers” or “you”) with respect to personal information the Company processes as a business. Any terms defined in the California Consumer Privacy Act of 2018, as amended from time to time, including by the California Privacy Rights Act of 2020 and its implementing regulations (“CCPA”) have the same meaning when used in these disclosures. These disclosures do not reflect our collection, use, or disclosure of California residents’ personal information, or data subject rights, where an exception or exemption under the CCPA applies. You can download a pdf version of these disclosures here.
These disclosures comprise of the following Sections:
- Our Notice of the categories, purposes, and the “sale” or “sharing” of personal information about California residents we collect online from individual representatives of our customers, vendors, investors, and partners. Candidates, please see the Global Career Site Privacy Policy for the notice relevant to candidates; and
- Our California Consumer Privacy Act Privacy Policy, which applies to information we collect both through the website and other avenues, including offline, from individual representative of prospective, current, and past suppliers and customers and prospective, current, and past employees and other personnel.
I. Notice at Collection Online
Categories of Non-Sensitive Personal Information | Retention Time |
---|---|
Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers. Specifically, name, user identification, title, company, email address, physical address, telephone number, and fax number. | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Commercial information, including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Specifically, information provided in a request for technical support such as product key, serial number, and order number. | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an internet website, application, or advertisement. Specifically, IP address, URI (Uniform Resource Identifier) address, domain name, computer and network traffic information, browser type, operating system, time of visit, duration of visit, size of the response files received and the corresponding status of the responses, and date and time stamps of actions. | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Online identifiers (cookies and similar technologies) | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Geolocation data. Specifically, location based on IP address. | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Audio, electronic, visual, or similar information. For example, voice and images shared during a video conferencing meeting | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
Categories of Sensitive Personal Information | Retention Time |
---|---|
The contents of a consumer’s mail, email, and text messages unless the business is the intended recipient of the communication. Specifically, to conduct internal audits and investigations or if needed for other legitimate business reasons. | In general, we retain each of the categories of personal information and sensitive personal information described in this notice for the longer of (i) your relationship with us as a current or prospective customer, vendor, investor, or partner; (ii) any duration necessary for compliance with laws; or (iii) for as long as necessary for the exercise or defense of legal rights and archiving, back-up, and deletion processes. |
We use non-sensitive personal information about website visitors to:
- Establish and verify your identity and the accuracy of your information.
- Provide you with the information, products, and services you request from us and carry out our obligations arising from any contracts entered into between you and us, including to process, maintain, and service your accounts, enable service providers to perform the services on our behalf or assist us with our provision of services to you, and otherwise serve you in ways associated with the circumstances under which you provided the information.
- Allow you to enroll in or register for our promotions or events.
- Manage user relationship and communicate with you, including to respond to your inquiries and fulfill your requests.
- Recruit individuals for employment via our Careers website. Please see the Global Career Site Privacy Policy for details relevant to candidates.
- Administer, facilitate, and improve operations of our websites.
- Provide firmware or software updates.
- Measure and understand the effectiveness of our marketing campaigns and market and advertise our products and services to you.
- Engage in research and development efforts to assess the performance of our products and services, analyze usage, interests, and trends in connection with our products and services, improve and personalize our products and services, and develop new products and services.
- Monitor and enhance the safety and security of our websites, including to prevent fraud or other unauthorized or illegal activity.
- Conduct internal audits and investigations.
- Handle and record consumer rights requests, including opt-ins and opt-outs.
- Comply with laws, regulatory requirements, and KLA’s Standards of Business Conduct, as well as respond to lawful requests, court orders, and legal processes.
- Send you administrative information, including information about our websites and changes to our services, terms, conditions, or policies.
We use sensitive personal information about our website visitors if it is reasonably necessary and proportionate:
- To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information, including in or via our premises, computers, software, networks, communications devices, and other similar systems.
- To resist malicious, deceptive, fraudulent or illegal actions directed at us and to prosecute those responsible for those actions.
- To ensure the physical safety of natural persons.
- For short-term, transient use.
- To collect or process it where such collection or processing is not for the purpose of inferring characteristics about a consumer.
- To perform functions that are required under laws that apply to us.
Requests to opt-out of certain uses of your personal information:
We may share personal information with third parties to provide analytics services and serve ads on our behalf targeted to your interests and based on your online activities. Information may be linked to your browser or device (like cookies and similar tracking technologies).
Your information is not “sold” or “shared” for monetary consideration, but certain uses may be considered “sale” or “sharing of personal information under the CCPA.
Click the “Do Not Sell/Share My Personal Information” link located at the bottom of our website and follow the directions to opt-out of these uses of your personal information. You can also opt-out by enabling the Global Privacy Control signal available in certain browsers and extensions, and we will treat that signal as a valid opt-out request. Because some technologies operate differently by website and device, you may need to take this step to opt-out on additional websites and devices you use.
Please note that KLA does not engage in the offline “sale” of your personal information as defined by CCPA.
Read more about other privacy rights that may be available to you below in Section II, our California Consumer Privacy Act Privacy Policy, below.
II. California Consumer Privacy Act Privacy Policy
Last Updated: May 17, 2024
1. OUR PERSONAL INFORMATION HANDLING PRACTICES IN THE PRECEDING 12 MONTHS
We have set out below categories of personal information about California residents we have collected, and as applicable disclosed, for a business purpose in the preceding 12 months. The table is followed by a description of the purposes for which we collected personal information.
Categories of Non-Sensitive Personal Information | Did we collect? If so, from what source? | Did we disclose? If so, to whom and for what purpose? |
---|---|---|
Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites or when you apply for a position at KLA, or during the course of your engagement or employment with KLA. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. Using cookies and automatic collection methods. KLA and its service providers may collect information from the computer, tablet, phone, or other device that you install our mobile application on, that you use to access our websites, or that you use to open an email from KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, locally and overseas, such as KLA human resources personnel, relevant business managers, authorized members of internal control functions, and individuals from information technology, finance, payroll and stock departments. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites and help us with advertising or marketing. KLA also uses third parties or service providers who provide administrative or other services to the Company, who have a duty of confidentiality to us. Examples of such parties include: external auditors, trustees, in-house and outside counsel, insurance companies, travel service providers, IT service providers, payroll administrators, and employee benefit providers. |
Online identifiers | Using cookies and automatic collection methods. KLA and its service providers may collect information from the computer, tablet, phone, or other device that you install our mobile application on, that you use to access our websites, or that you use to open an email from KLA. | Third parties and service providers that provide products or services to us. For example, companies that help us support our websites and help us with advertising or marketing. |
Any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, social security number, address, telephone number, passport number, driver’s license or state identification card number, education, employment, employment history, bank account number, medical information, or health insurance information, but excluding publicly available information that is lawfully made available to the general public from federal, state, or local government records. (The categories of personal information described in the California Customer Records Act (Cal. Civ. Code § 1798.80€) | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites or when you apply for a position at KLA or during the course of your engagement or employment with KLA. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, locally and overseas, such as KLA human resources personnel, relevant business managers, authorized members of internal control functions, and individuals from information technology, finance, payroll and stock departments. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites and help us with advertising or marketing. KLA also uses third parties or service providers to provide administrative or other services to the Company, who have a duty of confidentiality to us. Examples of such parties include: external auditors, trustees, in-house and outside counsel, insurance companies, travel service providers, IT service providers, payroll administrators, and employee benefit providers. |
Characteristics of protected classifications under California or federal law. | • Directly from you. For example, when you applied for a position at KLA and disclosed this optional information to us, or during the course of your engagement or employment with KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, locally and overseas, such as KLA human resources personnel, relevant business managers, and authorized members of internal control functions. • Third parties and service providers that provide products or services to us. For example, KLA may use third parties or service providers to help with our internal research or to provide certain employee benefits. |
Commercial information, including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | • Directly from you. For example, when you contact us or we contact you to request including via the KLA websites or when you create a user account. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. For example, KLA affiliates may share business processes and common data systems such as our enterprise resource planning (ERP) system. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites, or that provide services to you. KLA may use third parties or service providers to help with auditing interactions and transactions with you, addressing security, fixing errors, helping us with advertising or marketing, maintaining accounts and providing customer service, helping with our internal research, and verifying service quality or safety. |
Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an internet website, application, or advertisement. Specifically, KLA uses various analytics tools to track basic website pageviews and website visit data, including device type, operating system, and browser type KLA also collects information relating to the use of KLA’s assets, facilities, properties, and systems, notably computer and telecommunications systems. | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites or when you log in to our network as an employee or other authorized individual. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. • Using cookies and automatic collection methods. KLA and its service providers may collect information from the computer, tablet, phone, or other device that you install our mobile application on, that you use to access our websites, or that you use to open an email from KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, locally and overseas, such as relevant business managers, authorized members of internal control functions, and individuals from information technology. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites. KLA may use third parties or service providers to help with, addressing security, fixing errors, helping us with advertising or marketing, maintaining accounts and providing customer service, helping with our internal research, and verifying service quality or safety. |
Geolocation data. Specifically, location based on IP address. KLA uses various analytics tools that provide a number of geographic dimensions such as city, country, and continent. | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. • Using cookies and automatic collection methods. KLA and its service providers may collect information from the computer, tablet, phone, or other device that you install our mobile application on, that you use to access our websites, or that you use to open an email from KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/ or required by law in the Company, locally and overseas, such as relevant business managers, authorized members of internal control functions, and individuals from information technology. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites. KLA may use third parties or service providers to help with addressing security, fixing errors, helping us with advertising or marketing, helping with our internal research, and verifying service quality or safety. |
Audio, electronic, visual, or similar information. For example, voice and images shared during a video conferencing meeting, or other recordings such as in the context of providing videos for training and communications | • Directly from you. For example, when you participate in a video conferencing meeting, training or communication with KLA. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. Made available only to those who need access for authorized purposes and /or required by law in the Company, locally and overseas, such as relevant business managers, authorized members of internal control functions, and individuals from information technology. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites, or that provide services to KLA such as video conferencing services. |
Professional or Employment related information. | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites or when you create a user account such as when you complete an application for employment. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. Made available only to those who need access for authorized purposes and / or required by law in the Company, locally and overseas, such as KLA human resources personnel, and relevant business managers. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites, or that provide services to KLA. KLA may use third parties or service providers to help with the recruiting process and to help with attracting and engaging candidates. |
Education information, defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g; 34 C.F.R. Part 99). | • Directly from you. For example, when you apply for our position with us. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. Made available only to those who need access for authorized purposes and / or required by law in the Company, locally and overseas, such as KLA human resources personnel, and relevant business managers. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites, or that provide services to KLA. KLA may use third parties or service providers to help with the recruiting process and to help with attracting and engaging candidates. |
Categories of Sensitive Personal Information | Did we collect? If so, from what source? | Did we disclose? If so, to whom and for what purpose? |
---|---|---|
A consumer’s social security, driver’s license, state identification card, or passport number, including information revealing an employee’s citizenship or immigration status | • Directly from you. For example, when you contact us or we contact you to request information including via the KLA websites or when you apply for a position at KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and /or required by law in the Company, locally and overseas, such as KLA human resources personnel, relevant business managers, authorized members of internal control functions, and individuals from information technology, finance, payroll and stock departments. • Third parties and service providers that provide products or services to KLA. KLA uses third parties or service providers to provide administrative or other services to the Company, who have a duty of confidentiality to us. Examples of such parties include: travel service providers, payroll administrator, and employee benefit providers. |
A consumer’s precise geolocation. Specifically, time and location at a point-in-time if a badge is used to enter the premises through our electronic card reader system and location based on IP address. | • Directly from you. For example, when you enter our premises through our badge access system. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. • Using cookies and automatic collection methods. KLA and its service providers may collect information from the computer, tablet, phone, or other device that you install our mobile application on, that you use to access our websites, or that you use to open an email from KLA. | • KLA Affiliates. Made available only to those who need access for authorized purposes and /or required by law in the Company, such as relevant business managers, authorized members of internal control functions, and individuals from information technology. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites or third parties or service providers that provide our security systems or services. |
A consumer’s racial or ethnic origin. | • Directly from you. For example, when you complete an application for employment and you choose to voluntarily disclose this information. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, such as relevant business managers, and authorized members of internal control functions. • Third parties and service providers that provide products or services to us. For example, KLA may use third parties or service providers to help with internal research or to provide certain benefits to you. |
The contents of a consumer’s mail, email, and text messages unless the business is the intended recipient of the communication. Specifically, to conduct internal audits and investigations or if needed for other legitimate business reasons. | • Directly from you. For example, when you send communications through our network. • Third Parties, including Service Providers. For example, service providers that KLA uses and other third parties that KLA chooses to collaborate or work with. | • KLA Affiliates. Made available only to those who need access for authorized purposes and/or required by law in the Company, locally and overseas, such as relevant business managers, and authorized members of internal control functions and Information Technology. • Third parties and service providers that provide products or services to us. For example, companies that help us support our websites, or that provide services to KLA. KLA may use third parties or service providers to help with, addressing security, fixing errors, helping with our internal research, and verifying service quality or safety. |
2. BUSINESS OR COMMERCIAL PURPOSE FOR COLLECTING PERSONAL INFORMATION
For information collected online:
- Establish and verify your identity and the accuracy of your information.
- Provide you with the information, products, and services you request from us and carry out our obligations arising from any contracts entered into between you and us, including to process, maintain, and service your accounts, enable service providers to perform the services on our behalf or assist us with our provision of services to you, and otherwise serve you in ways associated with the circumstances under which you provided the information.
- Allow you to enroll in or register for our promotions or events.
- Manage user relationship and communicate with you, including to respond to your inquiries and fulfill your requests.
- Recruit individuals for employment via our Careers website. Please see the Global Career Site Privacy Policy for details relevant to candidates.
- Administer, facilitate, and improve operations of our websites.
- Provide firmware or software updates.
- Measure and understand the effectiveness of our marketing campaigns and market our products and services to you.
- Engage in research and development efforts to assess the performance of our products and services, analyze usage, interests, and trends in connection with our products and services, improve and personalize our products and services, and develop new products and services.
- Monitor and enhance the safety and security of our websites, including to prevent fraud or other unauthorized or illegal activity.
- Conduct internal audits and investigations.
- Handle and record consumer rights requests, including opt-ins and opt-outs.
- Comply with laws, regulatory requirements, and KLA’s Standards of Business Conduct, as well as respond to lawful requests, court orders, and legal processes.
- Send you administrative information, including information about our websites and changes to our services, terms, conditions, or policies.
For information collected from our employees, the purposes are related to their employment, which are:
- To perform the services or provide the goods reasonably expected by our employees in their role as our employees, including those services and goods that are reasonably necessary for us to administer the employment relationship and for our employees to perform their duties;
- To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information, including in or via our premises, computers, software, networks, communications devices, and other similar systems;
- To resist malicious, deceptive, fraudulent or illegal actions directed at us and to prosecute those responsible for those actions;
- To ensure the physical safety of natural persons;
- For short-term, transient use;
- To collect or process it where such collection or processing is not for the purpose of inferring characteristics about a consumer; and
- To perform functions that are required under laws that apply to us.
We do not knowingly sell or share for cross context behavioral advertising the personal information of California residents under 16 years of age.
3. CCPA RIGHTS
As a California resident, you have the following rights under the CCPA:
- The right to know what personal information we have collected about you, including the categories of personal information; the categories of sources from which the personal information is collected; the business or commercial purpose for collecting, selling, or sharing personal information; the categories of third parties to whom we disclose personal information; and the specific pieces of personal information we have collected about you. You may only exercise your right to know twice within a 12-month period.
- The right to delete personal information that we have collected from you, subject to certain exceptions.
- The right to correct inaccurate personal information that we maintain about you.
- The right to opt-out of the sale or sharing of your personal information by us.
- The right to limit our use and disclosure of sensitive personal information to purposes specified in subsection 7027(m) of the California Consumer Privacy Act Regulations. We do not use or disclose sensitive personal information for purposes other than those specified in subsection 7027(m) of the California Consumer Privacy Act Regulations.
- The right not to receive discriminatory treatment by the business for the exercise of privacy rights conferred by the CCPA, in violation of California Civil Code § 1798.125, including an employee’s, applicant’s, or independent contractor’s right not to be retaliated against for the exercise of their CCPA rights.
4. HOW TO EXERCISE CCPA RIGHTS
Methods of Submission and Instructions. To submit a request to exercise your rights to know, delete, or correct your personal information, please email privacy@kla.com, call +1 888-278-3169 (toll free), or populate our web form here.
Verification. Only you, or someone legally authorized to act on your behalf, may make a request related to your personal information. You may designate an authorized agent by taking the steps outlined under “Authorized Agent” below. In your request or in response to us seeking additional information, you, or your authorized agent, must provide sufficient information to allow us to reasonably verify that you are, in fact, the person whose personal information was collected, which will depend on your prior interactions with us and the sensitivity of the personal information being requested. We may ask you for information to verify your identity and, if you do not provide enough information for us to reasonably verify your identity, we will not be able to fulfil your request. We will only use the personal information you provide to us in a request for the purposes of verifying your identity and to fulfill your request.
Authorized Agents. You can designate an authorized agent to make a request under the CCPA on your behalf if:
- The authorized agent is a natural person or a business entity, and the agent provides proof that you gave the agent signed permission to submit the request; and
- You directly confirm with the Company that you provided the authorized agent with permission to submit the request. If you provide an authorized agent with the power of attorney pursuant to Probate Code sections 4121 to 4130, it may not be necessary to perform these steps and we will respond to any request from such authorized agent in accordance with the CCPA.
5. CONTACT US
If you have any questions or comments about these disclosures or our practices, please contact us at:
Email address: privacy@kla.com
Postal address: Three Technology Drive, Milpitas, CA 95035, United States
Last Modified and Effective Date: May 17, 2024