PRIVACY POLICY


CUSTOM JAVASCRIPT / HTML
We respect your privacy and are committed to protecting it through compliance with this policy. This Privacy Policy explains how we collect, process, and use different types of information from users of our website (“you” or “User”), including personal data.

Please read this policy carefully to understand our practices. If you do not agree with our policies and practices, you may choose not to use our website. By accessing or using this website, you acknowledge that you have read and understand this Privacy Policy. We may update this policy from time to time. Please review this policy periodically. Your continued use of the website after changes have been posted constitutes acknowledgment of the updated Privacy Policy.

This website is intended primarily for business-to-business transactions and is not intended for children under 16 years of age. We do not knowingly collect personal information from minors. If you are under 16, do not use this website or provide any information on or through it. If we learn that we have collected personal information from a minor, we will delete that information. If you believe we may have collected information from or about a minor, please contact us.

The Company is considered a Controller, as defined below, and is located at:

C&A Tool Engineering, Inc.
4100 US-33
Churubusco, IN 46723

For the purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act, we are a Business

1. DEFINITIONS


As used in this Privacy Policy, the following terms are defined as:

a. Business-to-Business
“Business-to-Business,” or “B2B,” references communications, transactions, sales, and services between two companies and does not involve consumers. 

b. Controller 
“Controller” is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

c. Data Subject or “User”
“Data Subject” or “User” is any identified or identifiable natural person, whose Personal Data is processed by the Controller or a Processor acting on the Controller’s behalf.  

d. Personal Data
“Personal Data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Because we operate on a business-to-business basis, the Personal Data we collect primarily relates to individuals acting in a professional or business capacity. Such data is treated as Personal Data under applicable data protection laws, and all rights described in this Policy apply.

e. Processing
“Processing” refers to any operation performed on Personal Data, whether or not by automated means, such as collection, organization, storage, retrieval, use, disclosure, or deletion. 

f. Processor 
“Processor” is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

g. Sell
“Sell,” as used herein, means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Data Subject’s Personal Data to a third party for monetary or other valuable consideration. “Sell” does not include using or sharing Personal Data with a Service Provider for business purposes. 

h. Sensitive Personal Information
“Sensitive Personal Information” is a subset of Personal Data that reveals more specific information about a User, including SSN, driver’s license or passport numbers, credit or debit card information, passwords and security access codes, precise location, race or ethnic origin, religious and/or political affiliation, genetic or biometric data, contents of email, texts, or other communications for which we are not the intended recipient. 

i. Service Provider
“Service Provider” means a person or organization that processes Personal Data on behalf of a business and that receives from or on behalf of the business a Data Subject’s Personal Data for a business purpose. 

j. Share
“Share,” as used herein, means renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Data Subject’s Personal Data to a third party for cross-contextual behavioral advertising, whether or not for monetary or other valuable consideration. “Share” does not include using or sharing Personal Data with a Service Provider for business purposes. 

2. HOW WE COLLECT INFORMATION

We obtain Personal Data from the following sources:  

a. Information you voluntarily provide via contact form, email, or similar direct communication
b. Website Cookies and/or browser Cookies. 
c. Information collected when you place an order with COMPANY
d. Information obtained indirectly through third-party partners

Because we sell business-to-business and not to consumers, the Personal Data we collect is generally limited to Business-to-Business information. For more information about how this website uses Cookies, please refer to our Cookies Notice. To accept, reject, adjust, or withdraw your consent to Cookies tracking, click here

3. HOW WE USE INFORMATION

We may use or disclose the Personal Data we collect for the following purposes: 

a. Business Operations - Processing orders, managing customer accounts, invoicing, and other business processes

b. Customer Communication - Contact you regarding product offerings (excluding direct marketing), handling complaints, providing support, and other aspects of customer management

c. Legal Compliance - Comply with legal and regulatory requirements, enforce our rights arising from contracts between you (or your company) and us, billing and collections, or as required by law, regulation, or court order

d. Information Security - Ensure network functionality and security 

e. Record Keeping Compliance – To create and maintain customer databases or similar records, back-up copies of business records, to comply with legal and regulatory requirements regarding document retention.

f. With Consent - For any other purpose to which you consent.

g. As-Needed Basis with Third Parties - We may share information we collect on an as-needed basis with third parties, such as trusted service providers, consultants and contractors who are granted access to our systems for services pertaining to outsourced digital technology providers and service providers offering software as a service. These service providers are contractually restricted from using or disclosing the information except as required by their contract or to comply with legal requirements. 
We do not use Personal Data for automated decision-making or profiling. 

4. HOW LONG WE RETAIN INFORMATION

We retain User Personal Data for as long as reasonably necessary to fulfill the business purpose for which it was collected and to comply with legal obligations. See Section 6 for approximate retention periods by category of Personal Data. 

5. LEGAL BASIS FOR COLLECTING INFORMATION

We rely on the following legal grounds for collecting and processing your Personal Data:

a. Your consent for specific purposes, such as placing an order
b. Processing necessary for performance of a contract or to take steps to execute a contract
c. When necessary to comply with legal obligations
d. When necessary to protect your interests or the interests of another person
e. When necessary for tasks supporting the public interest
f. When necessary 

6. INFORMATION WE COLLECT

We collect a variety of Personal Data from Users, specifically: 
Category of Personal Data

Consumer Identifiers

  • Examples: Name, Email, Phone
  • Purpose for Collection/Use: Customer Service, communicating with customers or potential customers, processing and fulfilling orders
  • Estimated Retention Period: No more than 7 years from last business interaction
Category of Personal Data

Customer Records

  • Examples: Organization/Employer, Business Address, Business Financials  
  • Purpose for Collection/Use: Customer Service, communicating with customers or potential customers, processing and fulfilling orders, maintenance of business records, cybersecurity and fraud prevention, legal and contract compliance, invoicing or collections
  • Estimated Retention Period: No more than 7 years from last business interaction
Category of Personal Data

Employee Identifiers Records

  • Examples: Name, Contact Information, Employment History, Information Provided in Application for Employment
  • Purpose for Collection/Use: Verifying identity and employment eligibility, maintaining employment records, payroll, taxes, and administration of employee benefits, cybersecurity and system access permissions
  • Estimated Retention Period: No more than 1 year from last business interaction
Category of Personal Data

Internet/Network Data

  • Examples: IP address, browser type, referring URL, pages viewed, metadata
  • Purpose for Collection/Use: Website functionality, improving website performance, cybersecurity and fraud detection, website analytics, managing User preferences including Cookies preferences
  • Estimated Retention Period: No more than 7 years from last business interaction
Category of Personal Data

Voluntarily Shared Data

  • Examples: Information User provides in a consent form or via email or phone
  • Purpose for Collection/Use: Responding to inquiries, customer relationship management, customer service
  • Estimated Retention Period: No more than 7 years from last business interaction or as requested by User
Category of Personal Data

Third Party Data

  • Examples: Information shared with us by vendors like CRM
  • Purpose for Collection/Use: Improving customer relationship management, vendor services, website analytics and performance
  • Estimated Retention Period: No more than 7 years from last business interaction

7. THIRD PARTIES WITH WHOM WE SHARE INFORMATION

We specifically work with the following third-party partners to assist with customer relations management and marketing: 

a. Pipedrive CRM Database
We use Pipedrive, a customer relationship management (CRM) platform, to manage customer interactions, contact information, sales processes, leads, and related business operations. Pipedrive acts as our Data Processor. In the last twelve (12) months we have disclosed the following categories of Personal Data, generally limited to B2B information, solely for legitimate business purposes:
• Identifiers (e.g. Name, Email, Phone Number)
• Professional and Business Information (e.g. Company Name, Job Title)
• Commercial Information (e.g. Records of communications, note relevant to business relationships, customer history)
• Information you voluntarily provide (e.g. via a contact form)

Pipedrive processes Personal Data solely for the following B2B purposes:
(i) verifying the accuracy of customer business information;
(ii) auditing customer contacts;
(iii) maintaining security and integrity of customer information;
(iv) debugging and system maintenance; and 
(v) providing advertising and marketing services only when you have provided consent 

Per our Data Processing Agreement with Pipedrive, Pipedrive only processes Personal Data solely in accordance with our instructions for the purpose of providing CRM services and does not sell or share Personal Data for cross-context behavioral advertising. Our legal basis for using Pipedrive includes:
• our legitimate interest in maintaining accurate and relevant B2B contact information;
• performing contractual obligations with existing customers;
• consent, where required by applicable law. 

Personal data stored in Pipedrive may be transferred to countries outside the EU/EEA or UK. Where such transfers occur, we rely on appropriate safeguards, such as the Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms, to ensure an adequate level of protection. For more information on how Pipedrive handles data, please refer to Pipedrive’s own privacy notice

b. Typeform
We use Typeform, an online form and survey platform, to collect information using forms, surveys, questionnaires, and other similar feedback tools. When a User submits information into a Typeform form on our website, the Personal Data the User voluntarily provides is stored and processed within the Typeform platform, and is transferred to Pipedrive CRM to assist with managing communications, follow-ups, and customer contact information. Typeform acts as our Data Processors, and in the last twelve (12) months we have disclosed the follow categories of Personal Data solely for business purposes:
• Identifiers (e.g. Name, Email, Phone Number)
• Professional and Business Information (e.g. Company Name, Job Title)
• Commercial Information (e.g. Content of User submissions on online forms, details of the products or services inquired about in a contact form) 
• Information you voluntarily provide 
• Technical Information (e.g. IP address, device type)

We share Personal Data with Typeform solely for the following business purposes:
(i) organizing and managing customer communications;
(ii) providing customer service, including organizing inquiries and responding to such inquiries;
(iii) tracking communications with actual or potential customers; 
(iv) performing our contractual obligations; 
(v) analyzing form performance;
(vi) as otherwise consented to by the User. 

Per our Data Processing Agreement with Typeform, Personal Data is only processed in accordance with our instructions and for the purpose of providing contact form services and Typeform is prohibited from selling or sharing Personal Data.

Personal data stored in Typeform may be transferred to countries outside the EU/EEA or UK. Where such transfers occur, we rely on appropriate safeguards, such as the Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms, to ensure an adequate level of protection. For more information on how Typeform handles data, please refer to Typeform’s own privacy notice

8. RIGHTS IN PERSONAL DATA 

We do not Sell or Share the Personal Data of Users/Data Subjects, nor do we collect, Sell, or Share the Sensitive Personal Information of Users/Data Subjects. Because we do not sell or share Personal Data, we do not offer an opt-out of sale or sharing at this time. You have the following rights regarding your Personal Data:

a. Right to Know and Right of Access
You have the right to know whether your Personal Data is being processed and may request that we disclose certain information to you about our collection and processing of your Personal Data. Once we receive your request and confirm your identity (see Exercising Your Rights), we will disclose to you:
• The categories of personal information we collected about you.
• The categories of sources for the personal information we collected about you.
• Our business or commercial purpose for collecting or sharing that personal information.
• The categories of third parties with whom we share that personal information.
• The specific pieces of personal information we collected about you (also called a data portability request).

b. Right to Delete
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions depending on your residency. Once we receive your request and confirm your identity (see Exercising Your Rights), we will review your request to see if an exception allowing us to retain the information applies. 

c. Right to Correction
You have the right to request correction of inaccurate Personal Data. Upon receipt of a verifiable request from you, , we will use commercially reasonable efforts to correct the inaccurate personal information. 

9. RIGHTS SPECIFIC TO THE EUROPEAN UNION

If you are a resident of the European Union (EU), or are physically located in the EU, you have the following rights in addition to those stated in the preceding Section:

a. Right to Restriction of Processing
You have the right to obtain from us a restriction on Processing your Personal Data, provided that certain conditions are met. In such case, the corresponding Personal Data will be marked and may only be processed by us for certain purposes.

b. Right to Data Portability
You have the right to obtain your Personal Data in a structured, commonly used, and machine-readable format. 

c. Right to Object
You have the right to object to the Processing of your Personal Data in accordance with Article 6(1)(e) or (f) of the GDPR and to withdraw your consent to Processing. 

d. Right to File a Complaint
 You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

10. EXERCISING YOUR RIGHTS

We do not discriminate against consumers for exercising any of their rights pertaining to Personal Data. To exercise your rights regarding your Personal Data, please submit a request by either:

• Calling us at 260-693-2167.
• Emailing us at privacy@catool.com.

Only you, or someone legally authorized to act on your behalf, may make a request to exercise your rights as they relate to your personal information. To designate an authorized agent to submit requests on your behalf you must provide the agent with written permission to act, and we may require you to verify your identity directly with us. We may deny a request from an agent who does not provide proof of authorization. 

The request must:

• Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative; and
• Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

You must provide sufficient information for us to verify your identity or your authority to act on another’s behalf. We will only use information in your request to verify your identity or authority. We aim to respond within 45 days. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing.

11. CHANGES TO THIS POLICY

We reserve the right to amend this policy at our discretion and at any time. When we make changes to this policy, we will post the updated policy on the website and update the policy’s effective date. Your continued use of our website following the posting of changes constitutes your acceptance of such changes.

12. CONTACT US

To ask questions or comment about this privacy policy and our privacy practices, contact us at: 260-693-2167.

Last Updated: 09/01/2026

    C&A Tool Engineering, Inc.
    4100 North U.S. 33 | PO Box 94
    Churubusco, IN 46723

    Tel: (260) 693-2167 | Fax: (260) 693-3633
    © 2025 C&A Tool Engineering, Inc. All rights reserved.  | Privacy Policy | Sitemap

    CONNECT WITH US.

    C&A Tool Engineering, Inc.
    4100 North U.S. 33 | PO Box 94
    Churubusco, IN 46723

    © 2021 C&A Tool Engineering, Inc. 

    All rights reserved.