Last Updated Date: 7 June 2021
Last Reviewed Date: 6 June 2021
This document aims to provide you with information on Civicom® policy regarding the use of data received through the course of business and interaction with Civicom, as well as the steps we take to protect your privacy.
In the normal course of business, Civicom may collect both Personal Information about you and non-Personal Information associated with you.
We may update this notice from time to time. We ask you to check this notice regularly to ensure you are aware of the most updated version.
The Ways Civicom Collects Personal Information
Civicom collects any information that you voluntarily submit to us and that identifies you personally, including contact information, such as your name, e-mail address, company name, address, phone number, and other information about yourself or your business.
Personal Information can also include information about any transactions, both free and paid, that you enter on our websites. We may also collect information about you that is available on the internet, such as from Facebook, LinkedIn, Twitter and Google, or information that we acquire from service providers.
1. Civicom Websites
When you visit our website, we collect your IP address and type of browser. Our websites also collect information by using cookies.
1.1 Website Cookies
A cookie is a small text file placed on the hard drive of your computer that allows our website to recognize you. Our cookies assign a randomly generated number to your computer. The cookies do not extract from your computer any information regarding other Internet sites or your surfing activities.
- To retain your preferences for pop ups and advertisements;
- To obtain details about your device and browser so the display can adapt to your screen size and layout content to fit your browser;
- To improve our services with usage information about our website, such as the number and frequency of visitors and the pages you visit, your geographical location, referral source, and length of visit; and
- To collect company IP addresses to follow up potential leads, we are not able to identify any individual visitors with this information. We use KickFire for this, you can read more about their service here: www.id.kickfire.com
You may disable browser cookies at any time. To do so, please refer to your browser’s Help page.
1.2 Website Beacons
Web beacons are used to collect non-personally identifiable data to assist us in delivering cookies on our sites and to allow us to count users who have visited those web pages and in turn to deliver Services.
We may use web beacons, customized links or similar technologies to determine whether your email has been opened and which links you click on in order to provide you more focused email communications or other information.
1.3 Navigational Information
Please note this does not opt you out of being served advertising. You will continue to receive generic ads.
1.4 Registrations and Forms
We collect Personal Information that is provided during webinar registration, through our sign up and landing pages, through your subscribing to one or more of our blogs, through our online chat, and our contact us forms; any of these may be managed by us using a third-party platform. This information is used to either assure your registration and/or to provide you with the information or answers you requested.
Our forms require you to identify your country of location. If you are located in an EU country, they require you to check a box indicating your knowledge and permission that we have collected your data, offer you the option to opt out, and provide you with information on how to do so. If you are located in the United States, we ask for you to provide your state of residence. We include information on various state privacy laws here.
Our registrations and forms may ask you only once to authorize the use of your Personal Information in order to eliminate your need to repeatedly enter the same information. If you are an EU/Swiss natural person, you may contact us at GDPR[at]civi[dot]com to change or request removal of your Personal Information at any time. Requests made under rights available under non-EU legislation may be directed to privacy[at]civi[dot]com.
1.5 Buttons and Tools From Other Companies
Civicom websites and mobile apps may include buttons and tools that link to our social media accounts, such as our Company Facebook, LinkedIn, or Twitter accounts. Your interaction with our social networking pages may result in us receiving information about you.
2. Mobile Apps
When you register to use our mobile apps, we receive information sent by your device to our servers to identify you, such as your Device ID and email address . We will also receive any other Personal Information and content you may upload including your name, company, email address, phone number, and text messages, photos, videos and voice recordings.
We use mobile analytics software to allow us to better understand the functionality of our Mobile Apps on your mobile device. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. When you use our Mobile Apps we also collect your device model and version, and device identifier (or “UDID”).
If you have enabled your GPS, this will send us your latitude/longitude coordinates, cell tower and WiFi-based location information.
We send push notifications from time to time in order to update you. Mobile research study notifications may include new comments or available exercises within the scope of the research. The PleaseDo application may send notifications and promotions. Hey DAN will push announcements related to your use of the service.
We may link information we store within the analytics software to Personal Information you submit within the Mobile App. We do this to improve the services we offer you and improve our analytics and site functionality.
If you sign up for one of our services using Facebook or Google, we do not use your Facebook or Google credentials for any reason other than to enable you to use the service you signed up for, unless you provide your permission for us to use them for other reasons.
3. Operator-Assisted Conference Calls
When you participate in an operator-assisted call our facilitators may request your Personal Information in order to grant you access and to facilitate your call experience. We may provide it to the call sponsor at their request.
4. Phone Inquiries
If you contact us by phone for information or assistance with our Services, we may ask you to provide your contact information in order to facilitate your call experience and provide our Services to you.
5. Trade Events
If you provide your business card to us at a trade event, we consider this your opt-in to receive information about our Services and will use your contact details to send you information and resources that we think may be valuable to you. You can opt out at any time by clicking on the unsubscribe link in an email sent by us, or email us with your request to unsubscribe. If you are an EU/Swiss natural person, you have the additional option to opt out at any time by emailing us your request to unsubscribe at GDPR[at]civi[dot]com. Requests made under rights available under non-EU legislation may be directed to privacy[at]civi[dot]com.
6. Data on Marketing Research Respondents
Through our CiviSelect Website (civiselect.com), social media accounts, and by telephone and email, we collect information for individuals who desire to be included in our CiviSelect respondent database or in an active research study. Individuals who wish to participate must provide their first and last name, phone number, email address, country, and whether or not they have high speed internet in order to be considered for a marketing research study.
Additional information, such as address, ethnicity, birthdate, gender, health information, income, and other demographics may be required for a specific study based on client requirements to participate. These requirements also apply to any individual who replies to any of our respondent recruiting solicitations or by way of a third-party respondent recruiter or panel (“Respondent Information” is incorporated under the definition of “Personal Information”).
Respondent Information shared with us by our clients as a part of a specific study may include similar information as the above. As part of our facilitation role we will contact you based on the information provided to us and in order to include you in the study.
In order to participate in a research study, you may need to provide additional information about yourself that is required by the research study in order to confirm that you are eligible to participate under the project specifications required. This information is collected to determine if you qualify for the study. Anonymized data is in most cases entered into a spreadsheet for disposition reporting.
When you are a respondent in a marketing research study, we or our clients may ask your opinions and views on products and services external to our company or theirs. Any information you provide is treated with the strictest confidence and is solely used to facilitate your participation in a study.
Researchers who engage with us in our facilitation of a research study may have their own privacy policies which apply to studies involving you. Those privacy policies may detail how they handle your personally identifiable information. We encourage you to become familiar with any such policies.
1. EU–U.S. Privacy Shield and Swiss–U.S. Privacy Shield
Civicom participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss–U.S. Privacy Shield Framework. Civicom is committed to subjecting all personal data received from European Union (EU) member countries and Switzerland, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List at https://www.privacyshield.gov.
Civicom is responsible for the processing of personal data it receives under the Privacy Shield Framework and subsequent transfers to a third party acting as an agent on its behalf. Civicom complies with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Civicom is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Civicom may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
You may direct any inquiries or complaints related to our Privacy Shield compliance to GDPR[at]civi[dot]com. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, you may contact our U.S.-based third party dispute resolution provider (free of charge) at:
Attn: Privacy Shield
2020 K Street NW, Suite 660 | Washington, DC 20006
Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
As part of the Privacy Shield Frameworks, the U.S. State Department Senior Coordinator serves as the Ombudsperson to facilitate the processing of requests relating to national security access to data transmitted from the EU and Switzerland to the U.S.
In light of the United Kingdom’s exit from the European Union, Civicom commits to extend adherence to Privacy Shield principles to Personal Information sent to and from the United Kingdom.
To view Civicom’s certification, please visit https://www.privacyshield.gov/list
2. HIPAA Compliance
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended, including by the Health Information Technology for Economic and Clinical Health Act (HITECH), is a United States federal law regulating the US healthcare system, with its primary purpose to protect the privacy and security of health and medical information, known as Protected Health Information (PHI). For more information about HIPAA, see here: https://www.hhs.gov/hipaa/
Certain Civicom clients are in the health care sector and as such, Civicom is acting as a Business Associate of Covered Entities as defined under HIPAA. Accordingly, Civicom will readily review and accept Business Associate Agreements with clients and partners to govern and ensure that PHI shared with us will not be compromised.
Civicom is committed to confidentiality and the protection of health information for individuals, clients, customers and partners. We ensure that privacy and security of their health information is protected in all forms, with particular care in controlling the confidentiality, storage and access to electronic Protected Health Information. We have achieved this by implementing security standards, administrative, technical, and physical safeguards, organizational requirements, and requirements for documentation, policies and procedures.
Our standards are maintained and improved by continuous review and audit of internal processes and business agreements, with the aid of external consultants and specialized staff dedicated to data privacy. Any complaints concerning Civicom’s privacy policies and procedures or Civicom’s compliance with such policies and procedures should be made to our Data Protection Officer, Jennifer Morehead at jennifer.morehead[at]civi[dot]com.
Civicom provides training to all members of its workforce on policies and procedures with respect to data privacy and security, as necessary and appropriate for them to carry out their job responsibilities. Processing of data is kept to a minimum and will not be excessive in relation to a declared and specified purpose.
We offer individuals the opportunity to opt out (choose) whether their Personal Information is to be disclosed to a third party acting as a controller or processor, as well as to opt out (choose) whether their Personal Information will be used for a purpose that is materially different from the purpose for which it was originally collected or which they subsequently sanctioned for use. We require, or when acting on behalf of a client, or as a facilitator we require, written confirmation (opt in) from individuals that we are able to disclose their Personal Information to a third party acting as either a controller or processor.
We will provide individuals reasonable and clear mechanisms for individuals to exercise their choices. For the purposes of this understanding, Personal Information includes first and last name, phone number, email and/or physical address and phone number. Sensitive Personal Information includes health care, genetic or biometric data, information regarding religious beliefs, race, ethnicity, union memberships, and sexual behavior or orientation.
4. Security of Personal Information
We are committed to protecting your privacy and have implemented reasonable administrative, technical, and physical security controls to secure your Personal Information.
If a password is provided to help protect your projects and Personal Information, it is your responsibility to keep your password confidential.
5. Where Civicom Stores My Personal Information
We use a variety of security technologies and procedures to help protect your Personal Information from unauthorized access, use or disclosure. Your Personal Information and files are stored in our servers and those hosted by our authorized third-party storage providers. We secure the Personal Information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use or disclosure.
If you have any questions about the security of your Personal Information, you can contact us at privacy[at]civi[dot]com.
6. Access to My Personal Information
Civicom recognizes the right of individuals to access their Personal Information. If you have an online account with Civicom, you can view or edit your Personal Information online or cancel your account at any time.
If you have an online account with Civicom, you can view or edit your Personal Information online or cancel your account at any time.
If you do not have an online account but are our client or customer, you may contact us by way of your Account Manager or by contacting us at privacy[at]civi[dot]com in order to edit your information or cancel your account with us.
If you are not a customer or client, but would like to change your mind about receiving information from Civicom you also can contact us at privacy[at]civi[dot]com to have your information changed or removed.
As an EU/Swiss natural person, you have the additional option to reach us to modify your information, review the information we have on file about you, or request that your information be removed from our system by emailing us at GDPR[at]civi[dot]com.
In the case where we are your data processor and not your data controller, you may need to contact your data controller to request to see or change your Personal Information with us.
The above paragraphs on access to your Personal Information are subject to our need to comply with our legal obligations or contractual agreements.
For requests for changes or deletions of personally identifiable information, we reserve the right to validate your identity and/or to charge you an adequate handling fee before providing access to data, except as required by the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks.
7. Third Party Service Providers and Clients
Civicom uses third party service providers to deliver some of our services. We may share your Personal Information with our third-party service providers to fulfill their obligations to us on your behalf. These service providers include:
- Market research partners such as recruiters, transcribers, translators, moderators and end clients;
- Market research technology and/or platform providers; and
- Webinar platform and audio conferencing storage providers.
We may disclose the Personal Information you provide to our clients who use our tools and software platforms, and/or to contractors, service providers and other third-parties we use to support our business (and who are bound by contractual obligations to keep Personal Information confidential and use it only for the purposes for which we disclose it to them).
8. Personal Information Across National Borders
As a global company working with a continuous flow of global projects, we operate a highly secure web-enabled infrastructure that assures all of our clients that we have taken the appropriate steps to ensure security, as well as to meet the EU-US data protection requirements. Where global projects require data transfer to countries outside the EEA not deemed as having adequate data protection rules, significant controls are in place to meet the required levels of data protection under the GDPR and other legislation. Where acting as controller or processor transferring personal data, we carry out such transfers using appropriate safeguards as specified under Article 46 of the GDPR. These safeguards are provided by means of strict information security policies, data flow procedures, mapping and security measures, GDPR and HIPAA training, , an approved code of conduct, and standard data protection clauses where required. We employ a full-time Compliance team dedicated to privacy, ensuring our practices are proactive at all levels of the organization.
Our servers are maintained in the following locations and can be directed to any other country as an additional safeguard:
- Google (Gmail/GSuite): Berkeley County, South Carolina; Council Bluffs, Iowa; Douglas County, Georgia; Jackson County, Alabama; Lenoir, North Carolina; Mayes County, Oklahoma; Montgomery County, Tennessee; Quilicura, Chile; The Dalles, Oregon; Changhua County; Taiwan; Singapore; Dublin, Ireland; Eemshaven, Netherlands; Fredericia, Denmark; Hamina, Finland; St Ghislain, Belgium.
- Amazon (AWS): Northern Virginia, USA; Ohio, USA; Oregon, USA.
- CoSo Cloud (Adobe Connect): New Jersey, USA.
9. We Do Not Sell Your Personal Information
In line with our obligations for transparency under the GDPR and other data privacy regulations such as the California Consumer Privacy Act (CCPA), Civicom does not sell your personal information for any reason. Civicom is fully prepared to agree to CCPA compliance in our capacity as vendors.
How Civicom Uses the Information It Collects
If you contact us by phone for information or assistance with our Services, we may ask you to provide your contact information in order to serve you.
We may use information that was collected from you for a number of reasons:
- To respond to demo requests, pricing inquiries, and questions about our Services
- To address reports of technical issues
- To provide you with Services requested
- For billing purposes
- To conform to legal requirements or comply with legal process
- To protect or defend the rights and property of Civicom
- To enforce the Terms of Service Agreement
- To protect the rights of our account holders or others
- For normal business operations
- To improve our Services
- For any other purpose disclosed by us when you provide the information
- For shipping and handling required to deliver our Services to you
- When we have any reason, in good faith, to believe that disclosure is necessary to prevent or respond to fraud, defend our websites and mobile apps against attacks, or protect the property and safety of Civicom, our employees, customers, or the public
- If we merge with another company, if all or a portion of our assets are acquired by another company, or if we sell a Civicom website, mobile app, or business unit, you may receive emails directly from a person who is assigned to you as an Account Manager in the course of our relationship with you. You may elect to not respond to these emails or to inform the Account Manager that you no longer wish to be contacted by replying via email to the person who corresponded with you.
Retention of Personal Information
We retain Personal Information that you provide to us as long as we consider it potentially useful in contacting you about your account or our other Services, or as needed to comply with our legal obligations, resolve disputes and enforce our agreements.
We will delete your Personal Information at an earlier date if you so request, as described under our “Unsubscribe” links or through contacting us to change or delete your information. You can contact us via your Account Manager, or by email to any party you have received emails from at our company. If you do not have a contact person to reach out to, email us at inquire[at]civi[dot]com. In the case of EU/Swiss natural persons, contact us at GDPR[at]civi[dot]com.
If you are an agent or other party who provides information to our customers as part of their use of our Services, the customers decide how long to retain the Personal Information that is collected on their behalf. If a customer terminates its use of our Services, then we will provide the customer with access to all information stored for the customer upon their request, including any Personal Information. After an account ends, we may, unless legally prohibited, delete customer information, including Personal Information.
For marketing research studies, our standard retention policy is 6 months. However, this period may be shorter or longer, depending on the directions of the client associated with the Respondent Information.
If you participate in a conference, records of your phone number are stored in the relevant customer account for billing purposes for an indefinite period of time. We will never use these records for marketing purposes, and do not accept liability for any other possible use of your information by the customers who receive this information in their account. This extends to any information disclosed by you during a conference call and any customer requests to produce transcripts of calls.
If you participate in a conference or webinar facilitated by our company, including under any of our other brand names, by default we receive records of your phone number, and any other information you potentially provide during the course of a call or webinar.
If you are a credit card customer, note that we use a third-party PCI-DSS compliant service provider for credit card payments in order to process your transaction. Your credit card number is processed in encrypted form by our credit card processor. We do not have the capability to store and read it.
Who To Contact With Questions Or Concerns