Privacy Notice
Hyperion Materials & Technologies - Global Privacy Notice
Last Updated: August 2026
Hyperion Materials & Technologies ("Hyperion," "we," "us" or "our") respects your privacy and is committed to protecting personal information in accordance with applicable privacy and data protection laws.
This Privacy Notice explains how Hyperion collects, uses, discloses, stores, transfers and otherwise processes personal information when you interact with us. It applies, as relevant, when you visit a Hyperion website, contact us or request information, request a quotation, sample, demonstration or technical support, purchase or supply products or services, act as a distributor or other business partner, attend or interact with us at a conference or other business event, receive or request communications from Hyperion, visit a Hyperion facility, or otherwise interact with Hyperion in a business or professional capacity.
Hyperion operates globally through affiliated companies, sales organizations and facilities in multiple countries. Additional or supplemental privacy notices may apply to particular countries, facilities, websites or activities. Where applicable law requires additional information, we may provide that information separately or at the point where personal information is collected.
1. Who Is Responsible for Your Personal Information
The Hyperion company responsible for processing your personal information depends on the circumstances in which you interact with us. In many cases, this will be the Hyperion company with which you or your organization does business, to which you submit an inquiry, order or other request, whose facility you visit, whose personnel you interact with, or that is responsible for the relevant website, service or business activity.
Because Hyperion operates globally and uses shared business systems and functions, more than one Hyperion company may be involved in processing personal information. Hyperion companies may share information where appropriate for functions such as customer relationship management, sales administration, order fulfillment, product and technical support, information technology, cybersecurity, finance, legal and regulatory compliance, marketing administration and corporate management.
Hyperion's operating model is primarily business-to-business. Personal information is therefore commonly processed in the context of relationships with customers, prospective customers, suppliers, distributors, representatives, other business partners and professional contacts. The responsible Hyperion company and the Hyperion companies that need access may differ by transaction, geography, product line, facility, support function or shared system.
If you have a question about the Hyperion entity responsible for your personal information, contact the Data Protection Office at dpo@hyperionmt.com. We will direct your inquiry to the appropriate Hyperion company where necessary.
2. Personal Information We Collect
Business contact information, such as your name, employer or organization, job title or function, business postal address, business email address, business telephone or mobile number, country or region, preferred language and other professional contact information.
Customer, supplier and business relationship information, such as account information, requests for quotations, orders and transaction history, contracts and correspondence, product and service interests, sample and demonstration requests, technical support and service information, warranty and claims information, distributor and business-partner information, and information concerning our current or prospective business relationship with you or your organization.
Financial and transaction information, where relevant to our relationship, such as billing and invoicing information, payment information, bank information, credit information, purchasing records and information necessary for accounting, tax, fraud prevention and other financial purposes.
Website and device information, which may include IP address, browser and device information, operating system, cookie and similar technology identifiers, referring and exit pages, pages or content viewed, links clicked, dates and times of access, language settings, approximate location derived from technical information, and information concerning your interaction with our websites.
Marketing and preference information, such as products or services of interest, communication preferences, language preferences, marketing permissions and opt-outs, newsletter or event preferences, and information concerning your interaction with Hyperion communications.
Conference, trade show and event information, such as registration and attendance information, information contained on a business card, information obtained through a badge scan where permitted, products or services in which you express an interest, requests for follow-up, and information you voluntarily provide during discussions with Hyperion personnel.
Facility, safety and security information reasonably necessary for visitor administration, site security, health and safety or compliance purposes, which may include visitor registration information, arrival and departure information, access information and, where used and permitted by applicable law, CCTV images.
Compliance information reasonably necessary for sanctions, export-control, anti-bribery, anti-corruption, fraud prevention, regulatory compliance, investigations and the establishment, exercise or defense of legal claims.
3. Sensitive Personal Information
Hyperion's public websites and ordinary business-to-business interactions are generally not intended to collect sensitive or specially protected personal information. Please do not provide sensitive personal information through website inquiry forms unless it is reasonably necessary for your request.
Where Hyperion needs to process information classified as sensitive, special-category or similarly protected under applicable law, we will apply any additional notice, consent, security or other requirements required by that law.
4. How We Obtain Personal Information
We may obtain personal information directly from you; from your employer or organization; from other Hyperion companies; from distributors, representatives and business partners; from conference, trade-show and event organizers; from service providers; from professional or industry sources; from publicly available sources; and from other sources where permitted by applicable law.
5. How We Use Personal Information
We may use personal information to respond to inquiries and requests; provide product and service information; prepare quotations and proposals; provide samples or demonstrations; develop and manage prospective customer relationships; enter into and perform contracts; process and fulfill orders; provide products, services and technical or warranty support; manage customer, supplier, distributor and other business relationships; process payments; administer events; follow up on interactions with Hyperion representatives; send marketing and other commercial communications where permitted by law; operate, maintain, secure and improve our websites, systems, products and services; understand website and communication usage; protect Hyperion personnel, facilities, systems and information; detect and prevent fraud, security incidents and misuse; comply with legal and regulatory requirements; investigate complaints or incidents; establish, exercise or defend legal rights; conduct audits and internal reporting; and otherwise operate and administer Hyperion's business.
We will not use personal information for a materially incompatible new purpose without providing additional notice or obtaining consent where required by applicable law.
6. Legal Grounds for Processing
The legal grounds on which Hyperion processes personal information vary according to applicable law and the circumstances of the processing. Depending on the jurisdiction, these may include your consent; taking steps at your request before entering into a contract; entering into or performing a contract; compliance with legal or regulatory obligations; protection of life, health, safety or other vital interests; Hyperion's or another person's legitimate interests, where recognized by applicable law; processing permitted in connection with an existing business or commercial relationship; reasonable processing of information that has lawfully been made public, where permitted by applicable law; or another ground authorized by applicable law.
Hyperion does not rely on “legitimate interests” as a legal basis in jurisdictions whose laws do not recognize that basis. Where applicable law requires consent, separate consent, express consent or another specific authorization for a particular processing activity, we will obtain the required authorization.
7. Conferences, Business Contacts and Marketing
If you interact directly with a Hyperion representative at a conference, trade show or other business event, we may use the information you provide to respond to your request and follow up concerning the products, services or subjects discussed, where permitted by applicable law. Similarly, where you or your organization has an existing or prospective business relationship with Hyperion, we may use appropriate business contact information to administer and develop that relationship where permitted by applicable law.
A conference interaction, business-card exchange, badge scan, website inquiry or existing business relationship does not necessarily constitute consent to receive all future promotional communications. Whether Hyperion may send a particular marketing communication depends on applicable privacy, electronic communications and telecommunications laws and the communication channel involved.
Where prior consent is required, we will obtain the required consent unless an applicable legal exception permits the communication. You may opt out of marketing communications at any time by using the unsubscribe mechanism in the communication or contacting dpo@hyperionmt.com. Opting out of marketing does not prevent Hyperion from sending transactional, contractual, warranty, safety, service, legal or other non-marketing communications where appropriate.
8. Cookies and Similar Technologies
Our websites may use cookies and similar technologies to provide website functionality, maintain security, remember preferences, understand website usage and improve our websites and services. Some Hyperion websites may also use analytics or other technologies where permitted by applicable law. The particular cookies and technologies used may differ depending on the website, country and services being provided.
Where applicable law requires consent before non-essential cookies or similar technologies are used, Hyperion will request that consent. Where available, additional information and choices will be provided through the Cookie Notice or Cookie Settings mechanism on the relevant website.
9. How We Disclose Personal Information
We may disclose personal information as reasonably necessary for the purposes described in this Notice and as permitted by applicable law.
Hyperion companies. Because Hyperion operates globally, information may be shared with or accessed by Hyperion affiliated companies where reasonably necessary for purposes such as responding to inquiries, sales and customer relationship management, order fulfillment, technical and product support, information technology and cybersecurity, finance and accounting, legal and regulatory compliance, marketing administration and corporate management.
Service providers. We may engage third parties to provide services such as website and infrastructure services, cloud and information technology services, customer relationship management systems, communications, analytics, event management, logistics, cybersecurity, payment and financial services, and professional advisory services. We require service providers to handle personal information in accordance with applicable contractual and legal requirements.
Distributors and business partners. Where appropriate, we may provide information to authorized distributors, representatives or other business partners, including where a partner is responsible for responding to a request or servicing a particular location.
Authorities and legal recipients. We may disclose personal information where required by applicable law, regulation, court order or lawful governmental request, or where reasonably necessary to protect legal rights, property, safety or security.
Corporate transactions. Information may be disclosed in connection with an actual or proposed merger, acquisition, financing, restructuring, divestiture or other corporate transaction, subject to applicable law.
Hyperion does not sell personal information for monetary consideration. Where applicable law defines “sale,” “sharing,” targeted advertising or similar concepts more broadly, Hyperion will provide disclosures and choices required by that law.
10. International Processing and Transfers
Hyperion is a global organization with sales activities, facilities, affiliated companies, personnel, service providers and shared business systems in multiple countries. As a result, personal information may be accessed, transferred, stored or otherwise processed outside the country in which it was originally collected.
This may occur, for example, when information is processed through Hyperion's global customer relationship management systems, information technology infrastructure, sales and customer-support processes, finance and business administration systems, cybersecurity functions and other shared business functions.
Privacy laws governing international transfers differ among jurisdictions. Where applicable law restricts an international transfer, Hyperion will use an applicable transfer mechanism, safeguard, consent or legal exception as required by the law governing the relevant transfer. Depending on the jurisdiction, such measures may include approved contractual protections, adequacy determinations, certifications, regulatory procedures, intra-group safeguards, consent where permitted, statutory exemptions or other mechanisms recognized by applicable law.
11. Retention
Hyperion retains personal information for as long as reasonably necessary for the purposes for which it was collected and for any additional period required or permitted by applicable law. In determining appropriate retention periods, we consider the nature and duration of our relationship with you or your organization; the purpose for which information was collected; contractual and warranty periods; legal and regulatory recordkeeping obligations; applicable limitation periods; accounting and tax requirements; export-control and compliance obligations; security and fraud-prevention requirements; the nature and sensitivity of the information; and the need to establish, exercise or defend legal claims.
Where applicable law requires a more specific retention disclosure, we will provide that information as required. When personal information is no longer required, we will delete, anonymize or otherwise dispose of it in accordance with applicable law and Hyperion's applicable retention requirements.
12. Information Security
Hyperion maintains administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure or destruction. These safeguards may include, as appropriate, access controls, security policies, employee training, technical security measures, vendor requirements and incident-response procedures.
No information system can be guaranteed to be completely secure. If a personal information breach occurs, Hyperion will investigate the incident and provide notifications to individuals or authorities where required by applicable law.
13. Your Privacy Rights
Depending on where you reside and the law applicable to the processing, you may have rights to obtain information about our processing; access personal information; obtain a copy; correct or supplement inaccurate or incomplete information; request deletion; object to or refuse certain processing; restrict certain processing; withdraw consent where processing is based on consent; request portability or transfer where applicable; opt out of direct marketing; opt out of certain sales, sharing, targeted advertising or profiling where applicable; and lodge a complaint with an applicable privacy or data protection authority.
To exercise a privacy right, contact dpo@hyperionmt.com. We may request information reasonably necessary to verify your identity and determine the applicability of the requested right. We will respond in accordance with applicable law.
14. Children
Hyperion is a business-to-business organization. Our public websites, products and services are intended for businesses and professional users and are not directed to children. We do not knowingly solicit personal information from children through our business websites. If we become aware that we have collected a child's personal information in circumstances requiring parental or guardian authorization, we will take appropriate steps in accordance with applicable law.
15. Additional Information for Mainland China
This section applies to the processing of personal information of individuals in Mainland China where the Personal Information Protection Law of the People's Republic of China (“PIPL”) or other applicable Chinese privacy, cybersecurity or network-data laws apply. If this section conflicts with another portion of this Privacy Notice in relation to processing governed by Chinese law, this section applies to the extent necessary to comply with Chinese law.
Hyperion's China-facing website is intended for business and professional users. Depending on how you interact with the website, personal information processed may include name, employer or organization, job title or business function, business email address, business telephone number, country or region, product or service interests, inquiry and correspondence information, and website and technical information of the types described in Section 2.
Hyperion processes personal information only for purposes reasonably related to the activities described in this Notice and under a ground permitted by applicable Chinese law. Depending on the circumstances, such grounds may include consent, processing necessary to enter into or perform a contract to which the individual is a party, compliance with legal obligations, reasonable processing of lawfully disclosed information within legally permitted limits, or another circumstance permitted by Chinese law. Hyperion does not rely upon a general GDPR-style “legitimate interests” basis for processing governed by the PIPL.
Where Chinese law requires consent, separate consent or written consent for a particular activity, Hyperion will obtain the applicable authorization.
Sensitive personal information. The China-facing website is not intended to solicit sensitive personal information through ordinary business inquiry forms. Please do not provide sensitive personal information unless it is reasonably necessary for your interaction with Hyperion. If Hyperion needs to process sensitive personal information, we will comply with applicable Chinese requirements concerning necessity, notice, safeguards and consent.
Processing outside Mainland China. Hyperion operates globally and uses shared business systems and processes. Personal information submitted through Hyperion's China-facing website may be transferred to and processed outside Mainland China, including in the United States and/or countries in Europe, through Hyperion's global customer relationship management, information technology and other business processes. Such processing may be undertaken by Hyperion affiliated companies and service providers for purposes including responding to your inquiry; providing requested product or service information; preparing quotations or proposals; managing prospective and existing customer relationships; providing products, services or technical support; administering Hyperion's global systems; and other purposes described in this Privacy Notice.
Where Chinese law requires Hyperion to provide additional information concerning an overseas recipient, processing purpose, processing method, categories of personal information or methods for exercising rights, we will provide that information as required. Where separate consent is required for a transfer or provision of personal information outside Mainland China, we will obtain that consent. Hyperion will comply with any other applicable Chinese requirements governing cross-border transfers of personal information.
For China-facing website forms, where applicable Chinese law requires separate consent for an overseas transfer or provision of personal information, Hyperion will present a separate Overseas Processing notice and a separate consent control. That consent will not be bundled with a general acknowledgement of this Privacy Notice or with optional marketing consent. The applicable point-of-collection notice will identify the overseas recipient information and other transfer details required by Chinese law.
Disclosure to other recipients. Where Hyperion provides personal information to another personal information processor and Chinese law requires additional notice or authorization, we will provide the information and obtain any separate consent required by applicable law. Service providers processing information on Hyperion's behalf are subject to applicable contractual and legal requirements.
Marketing. Where you submit an inquiry, request information, request a quotation or otherwise ask Hyperion to contact you, Hyperion may use your business contact information to respond to and manage that request as permitted by applicable law. Submitting a business inquiry or interacting with a Hyperion representative does not automatically constitute consent to receive unrelated or indefinite promotional communications. Where consent is required for marketing communications, Hyperion will obtain the required consent. You may opt out using the unsubscribe method provided or by contacting dpo@hyperionmt.com.
Retention. Hyperion retains personal information processed in connection with the China-facing website only for as long as reasonably necessary for the applicable processing purpose or as otherwise required or permitted by law. Retention periods are determined based on factors including the nature and duration of the business relationship or inquiry, legal and regulatory obligations, contractual requirements, applicable limitation periods, security requirements and the need to establish, exercise or defend legal rights. Where applicable Chinese law requires a more specific retention period or method of determining the period to be provided for a particular processing activity, Hyperion will provide that information as required.
Your rights in Mainland China. Subject to applicable Chinese law, you may have rights to know about and make decisions concerning processing; restrict or refuse certain processing; access or obtain a copy of personal information; correct or supplement inaccurate or incomplete information; request deletion where applicable; withdraw consent where processing is based on consent; request transfer of personal information where applicable legal conditions are satisfied; and request an explanation of applicable personal information processing rules. Requests may be submitted to dpo@hyperionmt.com.
Children in Mainland China. Hyperion's China-facing website is intended for businesses and professional users and is not directed to children. We do not knowingly solicit personal information from children through the website. If Hyperion becomes aware that it has processed personal information of a child under 14 in circumstances subject to Chinese law, we will take appropriate steps in accordance with applicable legal requirements.
16. Changes to This Privacy Notice
We may update this Privacy Notice periodically to reflect changes in applicable law, our business, our websites and technologies, or our processing practices. We will publish the updated Notice on the relevant Hyperion website and revise the 'Last Updated' date. Where applicable law requires additional notice or consent for a material change in processing, we will provide that notice or obtain the required consent.
17. Contact Us
Questions, privacy requests or concerns regarding this Privacy Notice or Hyperion's processing of personal information may be directed to the Data Protection Office at dpo@hyperionmt.com, Hyperion Materials & Technologies, 6325 Huntley Road, Worthington, Ohio 43085, United States. Where applicable law gives you the right to complain to a privacy, data protection or other supervisory authority, you may exercise that right.