Privacy Policy

Effective Date: May 15, 2018

At Post Holdings, Inc. (“Post” or “we” or “our”), we want you to be familiar with how and why we collect, use and disclose information about you. This includes information we collect through our website, www.postholdings.com (the “Site”) and in connection with the operation of our business and the offering of our subsidiaries’ products and services. Some of this information may individually identify you. This Privacy Policy explains our information practices with respect to information collected and the choices you can make about the collection, access and use of your information.

This Privacy Policy also applies to our targeted content, including online offers and advertisements for our subsidiaries’ products and services, which we (or a service provider acting on our behalf) may send to you on our subsidiaries’ or third party websites, platforms and applications (collectively, “Third Party Sites”) based on your use of the Internet. These Third Party Sites may have their own privacy policies and terms and conditions. We encourage you to read each such privacy policy and terms and conditions before using those Third Party Sites. If you wish to opt out of interest-based advertising, please visit http://preferences-mgr.truste.com/ or http://optout.aboutads.info to manage your preferences. Alternatively, if you are located in the European Union, you may visit http://www.youronlinechoices.eu/. Please note that you may continue to receive generic ads.

This Privacy Policy does not apply to any personal data collected from or about any of our or our subsidiaries’ employees.

We are committed to safeguarding your privacy and ensuring that your personal data is protected. As part of our commitment, we train our employees about the importance of privacy and how to handle and manage personal data appropriately and securely.

WHAT PERSONAL DATA DO WE COLLECT AND HOW DO WE USE IT?

We collect information that identifies you or from which you are identifiable (“Personal Data”) from you if you provide it to us.

Post certifies that it collects and processes Personal Data solely to the extent (i) that it has a legitimate, lawful basis for processing and (ii) that such Personal Data is relevant to the purposes for which it was collected or disclosed. With respect to Personal Data covered by the Privacy Shield, as defined and discussed further below, Post certifies that it collects and processes Personal Data solely to the extent such Personal Data is relevant to the purposes for which it was collected or disclosed.

In particular, we process personal data for the specific purposes listed in Subsections A-H below; the following explains which Personal Data we collect for each purpose, the exact nature of the purpose, the length such data is stored, the basis for collection, and any further relevant information.

A. Surfing on our Website – with or without Cookies

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: information about the type of browser you use, the size of the browser window, the screen resolution, the URL of the page that you are viewing, the title and other details of the web pages you have viewed, your location from IP address (not the IP address itself), your device address, your Cookie ID, hyperlinks that you have clicked, whether or not your browser has Java enabled, what version of Flash software your browser uses, the language settings from your browser and any other information you choose to share when using Third Party Sites (such as when you use the “Like” functionality on Facebook or the +1 functionality on Google+), and the websites you visited before arriving at our relevant Site.
  • 2. What is the Purpose of Processing your Personal Data? We (and third party service providers acting on our behalf or on their own behalf) use cookies and similar technologies to process data about you when you visit our Site. Cookies are files that store information on your computer hard drive or browser that mean that we can recognize that you have visited us before. We use cookies and similar technologies to improve our products and your experience on our Sites by evaluating the use of our Site, products and services to personalize content and ads, to provide social media features and to analyze our traffic. You can view more information on the cookies used and adjust your cookie preferences via the Cookie Consent Tool on our Site.

    Do Not Track (“DNT”) is a privacy preference that users can set in their web browsers. When our site receives a DNT code, except in the case of certain scenarios where a user actively and knowingly provides Personal Data (e.g. contact forms), our Site will not track your use across multiple websites other than the affiliated websites listed at www.postholdings.com/certified, but other websites (including, without limitation, certain of our subsidiaries’, affiliates’ and third party providers’ websites) to which we link may continue to track you. When we receive web requests from a user who enables DNT by actively choosing an opt-out setting in the user’s browser, we will also take reasonable efforts to disable tracking cookies/scripts (e.g. Google Analytics, Google Adwords, Facebook, Twitter and/or other third party scripts).

    How long do we store your Personal Data? Please check our Cookie Policy (https://postholdings.com/cookie-policy/ ) to learn about the storage periods for each cookie.
  • 3. What is the Basis for Processing your Personal Data? Your consent through our Cookie Consent Banner.
  • 4. Additional Comments: It is always possible for you to visit our Site without disclosing your Personal Data. This requires that you have disabled cookies. You can opt out of the processing of such information via the Cookie Consent Banner displayed at the bottom of the relevant Site. Please note, however, that without cookies you may not be able to use all of the features of our Site or online services.

B. Contact to Deal with Requests, Provide Information about Products, Services or Promotions, and Provide News Releases

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names and your email address.
  • 2. What is the Purpose of Processing your Personal Data? We process your Personal Data whenever you contact us in order to respond to your inquiries and comments. We process your Personal Data that you enter when registering for our Site or products or that you subsequently update or amend in your user account. We process Personal Data to provide you with the information that you request from us, including responding to your queries or comments and sending you products or samples that you have requested. We look at the products you have viewed on our Site.
  • 3. How long do we store your Personal Data? We store your Personal Data for forty-five (45) days after you provide the Personal Data to us, unless we are required by law to store the Personal Data for a longer period in which case we store the Personal Data for the period required by applicable law.
  • 4. What is the Basis for Processing your Personal Data? Performance of the contract with, or request by, you; if you provide to us Personal Data that is considered sensitive (e.g. information on your health or ethnic origin), your consent. If you wish to discontinue receiving this information, you may update your preferences by using the “Unsubscribe” link found in the emails that we send to you or by contacting us at privacyinquiries@postholdings.com.

C. Consider Your Job Application and Communicate with You Regarding Your Job Application

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first, middle, and last names, your mailing address, including city, state, and zip code, your email address, your phone number, including primary and secondary phone numbers, your gender, your ethnic origin, your veteran status, your voluntary self-identification of disability, your work experience, including job titles, company names, and dates of employment, and your education, including the names of the schools you attended, your level of education, your degree, including majors and minors, and the dates of your school attendance.
  • 2. What is the Purpose of Processing your Personal Data? We process your Personal Data in order to make employment decisions.
  • 3. How long do we store your Personal Data? We store your Personal Data for three years after you provide the Personal Data to us, unless we are required by law to store the Personal Data for a longer period in which case we store the Personal Data for the period required by applicable law.
  • 4. What is the Basis for Processing your Personal Data? Your consent.

D. Manage and Inform our Shareholders and Coordinate Investor Relations

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names, your mailing address, and number of shares of Post stock owned. We or our processors may also have banking information for the purposes of depositing dividend checks and this information includes the shareholder’s bank account number, email address, employee identification number, social security number and/or other tax identification number.
  • 2. What is the Purpose of Processing your Personal Data? We process your Personal Data in order to record and manage our shareholders and to provide you with information about our stock, shareholder meetings, dividends, and operation and business of our company and its subsidiaries. We also use this information for the payment of dividends.
  • 3. How long do we store your Personal Data? We store your Personal Data for so long as we or our processors, including, without limitation, our transfer agents, are required by law to store the Personal Data or for such longer period of time that we may be required to keep the Personal Data in order to protect the public interest.
  • 4. What is the Basis for Processing your Personal Data? Purchase of our stock and our legal obligations to you as a result of being a shareholder of our company and/or performance of a request by you to receive information about our stock and operation of our company and its subsidiaries.

E. Performance of Relevant Administrative Services Requested or Necessary to Facilitate our Relationship

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names, your address, your email address and your criminal or credit history.
  • 2. What is the Purpose of Processing your Personal Data? We will process your Personal Data for the purposes of performing administrative services requested or necessary to facilitate our relationship (e.g., facilitating payments or deliveries of products, services, information or materials) or to fulfill requests you have made (e.g., registration).
  • 3. How long do we store your Personal Data? We store your Personal Data for three years after you provide the Personal Data to us, unless we are required by law to store the Personal Data for a longer period in which case we store the Personal Data for the period required by applicable law.
  • 4. What is the Basis for Processing your Personal Data? Performance of the contract with, or request by, you; if you provide to us Personal Data that is considered sensitive (e.g. information on your health or religious affiliation), your consent.

F. Respond to Consumer Complaints and Reports of Business Concerns

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names, your mailing address, your email address and relevant information about (i) the complaint or business concern, (ii) the situation or circumstances giving rise to the complaint or business concern and/or (iii) any other Personal Data that you volunteer in your report or follow up communications.
  • 2. What is the Purpose of Processing your Personal Data? We will process your Personal Data for the purposes of responding to any consumer complaints or responding to reports from consumers about business concerns related to our businesses and operations.
  • 3. How long do we store your Personal Data? We store your Personal Data for no more than three years after you provide the Personal Data to us, unless (i) we are required by law to store the Personal Data for a longer period in which case we store the Personal Data for the period required by applicable law or (ii) unless we reasonably anticipate litigation with regard to the matter in which case we would retain relevant Personal Data until such time as the litigation is concluded or is no longer reasonably anticipated.
  • 4. What is the Basis for Processing your Personal Data? Our basis for processing is (i) your consent with regard to Personal Data you volunteer with regard to your complaint or business concern or (ii) a legal obligation to which we are subject.

G. Prevention of Harm to Us, Our Products or Services or a Person or Property (e.g., Fraud Prevention) or Defend Ourselves against Claims or Potential Claims

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names, your address, your email address, your criminal or credit history and relevant information about (i) the harm or potential harm, (ii) the claim or potential claim or (iii) the situation or circumstances giving rise to harm, potential harm, claim or potential claim.
  • 2. What is the Purpose of Processing your Personal Data? We will process your Personal Data for the purposes of preventing harm to Post or any of its subsidiaries, their products or services or to any person or property (e.g., fraud prevention) and/or in the bringing or prosecution of a claim or potential claim against you. In addition, we may process your Personal Data for the purposes of defending Post and/or its subsidiaries against claims or potential claims made against one or more of them.
  • 3. How long do we store your Personal Data? We store your Personal Data for six years after you provide the Personal Data to us, unless (i) we are required by law to store the Personal Data for a longer period in which case we store the Personal Data for the period required by applicable law or (ii) unless we reasonably anticipate litigation with regard to the matter in which case we would retain relevant Personal Data until such time as the litigation is concluded or is no longer reasonably anticipated.
  • 4. What is the Basis for Processing your Personal Data? Our basis for processing is (i) a legal obligation to which we are subject or (ii) the processing is necessary for the purposes of our legitimate interests in protecting our business, products, services or a person or property or to defend ourselves against claims or potential claims.

H. Communicate with You regarding our Site and Privacy Policy

  • 1. Which Personal Data do we collect about you? For this purpose, we process the following Personal Data: your first and last names, your email address and your mailing address.
  • 2. What is the Purpose of Processing your Personal Data? We process your Personal Data whenever there are material changes to our Site and Privacy Policy for the purposes of informing you of those material changes and obtaining your consent, if necessary.
  • 3. How long do we store your Personal Data? We store your Personal Data for seven years after you provide the Personal Data to us, unless we are required by law to store the Personal Data for a longer period period in which case we store the Personal Data for the period required by applicable law.
  • 4. What is the Basis for Processing your Personal Data? Performance of the contract with, or request by, you. If your consent was initially required, then your consent is the basis for this processing.

HOW DO WE SHARE PERSONAL DATA?

We engage other companies, including, without limitation, certain of our affiliates and subsidiaries (“Agents”), to perform certain services on our behalf. Pursuant to written agreements with these Agents, which agreements afford appropriate, and all required, protections of your Personal Data, we use these Agents to provide the following services on our behalf:

  • provide email services;
  • consumer relations, including consumer complaint response services;
  • employee recruitment services;
  • legal representation, including with regard to prevention harm to our company, its subsidiaries, our products or services or a person or property (e.g., fraud prevention); and
  • shareholder record-keeping, notice, transfer agent and other investor relation services.

All of our Agents are bound by contract to refrain from using your Personal Data for any purpose other than providing the applicable service to us. We are liable to you for our Agents appropriate processing of your Personal Data in a manner consistent with this Privacy Policy and applicable data privacy laws and regulations.

As described above, we use Agents to manage our advertising on other websites. These Agents may use cookies or similar technologies in order to provide you with advertising based upon your browsing activities and interests. Any personally identifiable information gathered by these Agents is not provided by the Agents to Post. It is only used by the applicable Agent pursuant to its own privacy policies. If you wish to opt out of interest-based advertising, please visit http://preferences-mgr.truste.com/ or http://optout.aboutads.info to manage your preferences. Alternatively, if you are located in the European Union, you may visit http://www.youronlinechoices.eu/. Please note that you may continue to receive generic ads.

In addition to disclosures described above, we may disclose or transfer Personal Data in connection with, or during negotiations of, any merger, acquisition, spin-off, sale of company assets, product lines or divisions, any financing or any similar transaction. We may also disclose Personal Data to prevent damage or harm to us, our services or any person or property, if we believe that disclosure is required to meet national security or law enforcement requirements, or in response to a lawful request by public authorities. Except as described in this Privacy Policy, we will not otherwise disclose Personal Data to any third parties unless you have been provided with an opportunity to opt in to such disclosure.

Post does not sell or share the Personal Data it collects from you to any unrelated third parties (who are not Agents) so that they may send you commercial promotions or unsolicited offers for unrelated products or services. If you would like more information about our disclosure of your Personal Data to third parties, please contact us at privacyinquiries@postholdings.com.

When Post transfers Personal Data to countries other than the country where it was provided, we do so in compliance with applicable data privacy laws and/or regulations, including, as applicable, the European Union General Data Protection Regulation 2016/679 (the “GDPR”) and/or the E.U.-U.S. Privacy Shield Principles and the Swiss-U.S. Privacy Shield Principles, including the Supplemental Principles, as set forth by the U.S. Department of Commerce (collectively, the “Privacy Shield Principles”). We may transfer Personal Data from persons outside of the United States (“U.S.”) to affiliates located either in the U.S. or otherwise; provided that such transfers to the U.S. from the European Union (“E.U.”) or Switzerland will comply, as applicable, with the GDPR and/or the Privacy Shield Principles in all respects.

LINKS TO OTHER WEBSITES

Our Site may contain links to the websites of our subsidiaries and affiliates (some of which do not fall under the jurisdiction of the GDPR or have not certified to the Department of Commerce that such entity adheres to the Privacy Shield Principles) and to websites that are owned and operated by third parties. These other websites may have their own privacy policies and are not governed by this Privacy Policy. We are not responsible for the privacy practices or the content of websites owned and operated by any such third parties. Other websites may collect and treat information collected differently.

YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA

You have the following rights with regard to your Personal Data: (i) the right to access; (ii) the right to rectification; (iii) the right to erasure; (iv) the right to restrict processing; (v) the right to object to processing; (vi) the right to data portability; (vii) the right to withdraw consent and (viii) the right to lodge complaints. You may exercise any of these rights by contacting us at privacyinquiries@postholdings.com. You also have the right to lodge your complaints with the applicable legal authorities, including, without limitation, the U.S. Department of Commerce, U.S. Federal Trade Commission (“FTC”) or the applicable E.U. supervisory authority(ies).

Post will respond to your requests in accordance with, and within the appropriate timeframe determined by, the applicable law and/or regulation governing the use of the given Personal Data. In most cases, Post will respond to requests within one month; provided, however, if the request is complex, Post may extend its response time in accordance with applicable law and regulation.

Post will contact users whose Personal Data is within the scope of the GDPR or the Privacy Shield Principles to obtain prior affirmative express consent when the same is required. For example, Post will receive your affirmative express consent before any sensitive or special category Personal Data is processed, is disclosed to a third party, or is used for a purpose other than those for which it was originally collected or subsequently authorized by you.

CHILDREN’S PRIVACY

This website is not directed to children under age 16, and we have no intention of collecting information from children under age 16, via this website or otherwise.

CALIFORNIA PRIVACY RIGHTS

California Civil Code Section § 1798.83 permits users of this website that are California residents to request certain information regarding our disclosure of personal data to third parties for their direct marketing purposes. To make such a request, please send an email to privacyinquiries@postholdings.com or by mail to Post’s Chief Privacy and Data Protection Officer at 1699 S. Hanley Rd., St. Louis, MO 63144.

HOW WE PROTECT PERSONAL DATA

Post maintains reasonable and appropriate technical and organizational security measures designed to help protect against loss, misuse, and alteration of Personal Data collected and processed by Post. However, information transmitted on the Internet and/or stored on systems attached to the Internet is not 100% secure. As a result, we do not ensure, warrant or guarantee the security or integrity of such information.

PRIVACY SHIELD COMPLIANCE

Post complies with the E.U.-U.S. Privacy Shield Principles and the Swiss-U.S. Privacy Shield Principles, including the Supplemental Principles (collectively, the “Privacy Shield Principles”) as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal data transferred from the E.U. to the U.S. or from Switzerland to the U.S., respectively (the programs being described herein as the “Privacy Shield”). Post has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in the Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov. A list of companies that are currently certified under the Privacy Shield is available by visiting https://www.privacyshield.gov/list.

We may, but shall not be required to, also process personal data submitted relating to individuals in the E.U. and/or Switzerland via other compliance mechanisms, including data processing agreements based on the E.U. Standard Contractual Clauses. Our Privacy Shield compliance is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (“FTC”), and we are committed to responding promptly to inquiries and requests by the United States Department of Commerce for information relating to the Privacy Shield Principles.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

PRIVACY SHIELD DISPUTE RESOLUTION

In compliance with the Privacy Shield Principles, Post commits to resolve complaints about our collection or use of your Personal Data. E.U. and/or Swiss individuals with inquiries or complaints regarding this policy should first contact Post’s Chief Privacy and Data Protection Officer at privacyinquiries@postholdings.com.

Post has further committed to refer unresolved Privacy Shield complaints to an alternative dispute resolution provider located in the U.S. If you do not receive timely acknowledgment of your complaint from us, or if we have not resolved your complaint, please contact the dispute resolution provider free of charge at https://feedback-form.truste.com/watchdog/request. Under certain limited circumstances, E.U. or Swiss individuals may invoke binding Privacy Shield arbitration as a last resort if all other forms of dispute resolution have been unsuccessful. To learn more about this method of resolution and its availability to you, please visit https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint.

The FTC has committed to reviewing, on a priority basis, referrals alleging non-compliance with the Privacy Shield Principles received from independent dispute resolution bodies, among others. If the FTC concludes that it has reason to believe Section 5 of the Privacy Shield Principles has been violated, it may resolve the matter by seeking an administrative cease and desist order prohibiting the challenged practices or by filing a complaint in a federal district court, which if successful could result in a federal court order to same effect.

CHANGES IN OUR PRIVACY POLICY

We may amend this Privacy Policy at any time. To the extent required by the GDPR, the Privacy Shield Principles or as required by applicable law, Post will contact users whose Personal Data is within the scope of the GDPR or the Privacy Shield Principles and then currently being processed by Post to obtain prior affirmative express consent to any material changes to how we collect, use, process, and/or share such user’s Personal Data or to this Privacy Policy. In addition, if we make any material changes to this Privacy Policy, including, any material changes to how we collect, use, process, and/or share your Personal Data, we will prominently post a notice of such changes on the website(s) covered by this Privacy Policy. We encourage you to periodically review this page for the latest information on our Privacy Policy.

YOUR ACKNOWLEDGEMENT OF THIS PRIVACY POLICY AND WHEN WE ASK FOR YOUR CONSENT

By using our Site, you acknowledge that we are processing your Personal Data in accordance with this Privacy Policy. If you do not wish that we process your Personal Data in this way, please do not use our Site or otherwise provide us with your Personal Data.

We process your Personal Data as described above. In certain instances, we only process your Personal Data if you have consented (for example, in cases where we process your Personal Data for job applications or seeking employment). Where we process your Personal Data on the basis of your consent, we will ask for your consent explicitly but, in some cases and only where permitted by applicable law, we may infer in a transparent manner consent from your actions. We may also ask you to provide additional consent if we need to use your Personal Data for purposes not covered by this Privacy Policy.

CONTACT US

If you are a resident of a European country participating in the Privacy Shield and you believe we maintain your Personal Data within the scope of this Privacy Shield certification, you may direct any questions or complaints to Post’s Chief Privacy and Data Protection Officer, whose contact details are as follows:

We are committed and required to respond to any of your inquiries on this issue within one month of receiving the inquiry.

Post Holdings, Inc. (“we”) use cookies to improve our products and your experience on our Sites by evaluating the use of our Site, products and services, to personalize content and ads, to provide social media features and to analyze our traffic. We also share information about your use of our site with our social media, advertising and analytics service providers. For more information, please see our Cookie Policy