Snapshot 31551
Normalized text
Scripts and page chrome removed; this is what change detection compares.
General Website Privacy Notice by Cint AB Effective Date: July 7, 2017 Last Revised: September 22, 2026 Select your region US Privacy Notice EU, UK and AUS Privacy Notice US Privacy Notice Note: If you are a survey participant of any panel, please reach out directly to your panel provider. It is the company who is paying you for your survey participation. You can also find the name from the link of the survey. I. Introduction & Notice a. Introduction Cint USA, Inc. (“Cint”) is committed to ensuring the privacy of (i) those customers who use the Cint Sites and Services (specifically, individuals acting at the direction of Suppliers, Buyers or other business customers, all of whom may be collectively referred to as “Clients”), (ii) Respondents referred, brokered, qualified, accessed by, hosted on, or otherwise provided by or to Clients on or through the Sites and (iii) to individuals who visit or interact with Cint’s website, including prospective customers, existing clients, event attendees, and anyone who contacts us directly (the individuals in the foregoing (i) (ii) and (iii) may be collectively referred to as “you” or “your”). This Policy describes what data is collected from or provided to Respondents or Clients, respectively, and how that data is used and disclosed. By using the Sites and Services, you consent to the terms of this Policy. This Policy was created to demonstrate our commitment to fair information practices. Our policies and procedures address applicable U.S. and international privacy requirements concerning the collection, use, and cross-border transfer of Personal Data. As described more fully below, Cint complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Cint has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Cint has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data Privacy Framework IF YOU DO NOT AGREE WITH THE TERMS IN THIS PRIVACY POLICY, DO NOT USE THE SERVICES AND SITES. CONTINUED USE OF THE SERVICES AND SITES CONSTITUTES YOUR FREELY GIVEN SPECIFIC AND INFORMED CONSENT AND AGREEMENT TO YOUR PERSONAL DATA BEING PROCESSED PURSUANT TO THIS POLICY. b. Definitions “Buyer(s)”means the business entity accepting and entering into an agreement with Cint for the purpose of acquiring Sample for Buyer Opportunities. “Buyer Opportunity(ies)”an engagement, campaign, or other project defined by a Buyer, such as Sample for a survey, a recruiting effort, or some other cost-per-action effort, that is sourced by one or more specific Supplier(s) or the Marketplace. “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. “Data Subject” means an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. “Marketplace” means Cint’s public cloud platform and application used to facilitate completed transactions between Suppliers and Buyers. “Personal Data” and “Personal Information” means any information relating to an individual that can be used to identify that individual either on its own or in combination with other readily available data. “Pixels” means small, graphic images on web pages, web-based documents, or in email messages that allow us or third parties to monitor who is visiting our Sites (or other third-party sites) or if an email has been read. “Processor” means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the controller. “Respondent” means a natural individual who has been sent to the Marketplace by a Supplier and provided an opt-in consent to participate in a Buyer Opportunity. “Respondent Screening Data” means all data supplied, indexed, or otherwise transmitted by Suppliers or provided by their Respondents on or through the Marketplace for the purposes of asking and answering questions and attempting to qualify Respondents to complete Buyer Opportunities. This data includes, but is not limited to, IP Addresses, Cookie Identifiers, Device Identifiers transmitted by a Respondent’s device and qualifying demographic data received by the Supplier and/or submitted by the Respondent. “Sample” means access to Respondents who are made available by a Supplier on the Marketplace to answer questions and participate in Buyer Opportunities. “Separate and Independent Controller” means each party is a distinct Controller with regard to Personal Data and determines it independent legal basis for the processing of Personal Data received. “Services” means the services performed by Cint as part of the Marketplace, Marketplace Services, Monetization Services, or other services, software or technology related to Data Score and Impact Measurement. “Sites” means the websites owned, maintained or licensed by Cint, including but not limited. “Special Categories of Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. “Supplier(s)”means any company with a user base of individuals willing to be Respondents on the Marketplace. “User(s)” means a user of our Services on behalf Clients. “We”, “our”, and “us”in this Privacy Policy refer to Cint. c. Regulatory Oversight For this Privacy Policy and its content, Cint is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). If Cint becomes subject to an FTC or court order based on non-compliance with this policy or EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), Cint shall make public any relevant Data Privacy Framework related sections of any compliance or assessment report submitted to the FTC, to the extent consistent with confidentiality requirements. II. Collection of Personal Information The Sites are not intended for children under the age of 13. If you are under 13 years old, please do not provide information of any kind whatsoever on the Sites. If you are the parent of a child under 13 and believe your child has provided us with personal information, please contact us via Section IX below and we will remove that information. b. Usage and Browsing Information Your Devices Transmits You can visit most of our Sites without registering or actively submitting Personal Data to us. If you do not register, general technical user data, such as your device’s Internet Protocol (IP) address, operating system and browser type, and the date and time of your visit, may be automatically collected through the use of “cookies” (small files that are stored on your computer by a website to give you a unique identification) or other technologies. For Users, cookies also keep track of services you have used, record registration information regarding your login name and password, ensure you do not repeatedly see survey questions, record your preferences and keep you logged into the Cint Sites. c. Information You Actively Submit As a User of the Marketplace or Visitor to our Sites If you register on our Sites as a user or sign up for our newsletter on behalf of a corporate customer (e.g., a client or supplier of market research sample), you will provide contact information such as your name, email address, mailing address and company affiliation. As a Respondent If you use our Sites as a Respondent, you will be prompted to provide certain demographic information about yourself and answer survey questions. In each such case, you know what information you provide and we collect, because you will actively submit the information. d. Business Information We do collect employee contact names, addresses, phone numbers and email addresses of our business partners, including buyers, suppliers and vendors, for the administration of our business relationships. If you feel that your Personal Data or personally identifiable information is being collected inappropriately, please notify us at [email protected] e. Cookie Opt-Out If you do not wish to participate in any of Cint’s online measurement and research services, please see our Cookie Notice Cint Cookie Policy – Cint™ | The World’s Largest Research Marketplace. f. Information Tracking Technologies We may use, and allow third parties to use, Pixels (sometimes called web beacons) on our Sites (or other third-party sites) to monitor the effectiveness of survey qualifications. Pixels may be linked to your Personal Information, and they collect the IP address of the device to which the web beacon is sent (for geolocation lookup), the URL of the page the web beacon comes from, the user agent string (for device lookup), and the time it was viewed. We may also use third-party devices, links or electronic mail, to deliver surveys to you during which additional Personal Information may be collected. These third-party surveys or devices may use cookies, web beacons or other technology to collect information about your visits to our Sites (or other third-party sites) in order to present surveys that may be applicable to you. We may collect traffic information and data on and from the use of third-party sites on behalf of our customers. Cint may use a Pixel or cookie to examine what is happening on third-party websites, including programs and sites with marketing and advertising partners, to improve the understanding of site traffic at a granular level, market research effectiveness and brand lift reporting. Respondents that are hosted on, accessed by or routed through the third-party sites should consult the privacy policy and other policies of third parties through whom they are providing information. These third-parties may collect and use data that has been augmented by our services for their own services, which may include marketing and ad targeting, among other uses. You can opt-out of receiving interest-based ads and tracking from third parties who are members of the Network Advertising Initiative (NAI) or who follow the Digital Advertising Alliance’s Self- Regulatory Principles for Online Behavioral Advertising by visiting the opt-out pages on the NAI website and DAA website. (http://www.networkadvertising.org/choices/) and (http://www.aboutads.info/choices/). g. Do Not Track Some browsers have a “do not track” feature that lets you tell websites that you do not want to have your online activities tracked. III. Purpose & Use of Collected Personal Information a. Generally Users We use your Personal Information to operate, evaluate and improve our business (including developing new products and services; enhancing and improving our Services; managing our communications; and analyzing our products). If you provide us with your name and contact information, we will use this data to answer requests from you, communicate with you regarding any Services we are providing to you as well as inform you about new products and services (unless and until you opt-out of marketing information). Respondents If you come to our Sites as a Respondent to qualify for or take surveys, we use the demographic information you provide to make your survey answers more meaningful to us and our clients. We may also use information derived from cookies, pixels and other technologies to determine your interest in particular surveys, advertisements and other communications. b. Combination & Synchronization We may combine and synchronize information that your device transmits, information that you actively submit and information that we obtain from third party sources (including suppliers of market research sample and data marketing platforms that may direct you to our Sites to answer demographic questions about yourself in preparation for your completion of surveys, and web publishers, advertisers, data brokers and online service providers that may have obtained information from you or your devices via cookies, pixels, and other tracking technologies). c. General Data Protection Regulation (GDPR) i. Respondent Screening Data In order to deliver the Services, we require opt-in consent from European Union Respondents prior to the collection and processing of your Personal Data. Exchange You have been routed to Exchange by your referring company (Supplier), and prior to using our Site, you must consent to our collection of your Personal Data. The following scenarios apply: Personal Data You Provide to Cint Cint acts as a Controller of the Personal Data you actively submit within our Marketplace. Personal Data Sent to Cint By Your Supplier Cint acts as a Separate and Independent Controller of the Personal Data received by Cint from your Supplier. Personal Data Sent By Cint to its Buyers The Personal Data we collect on our Sites pursuant to your opt-in consent may be shared by Cint with our Buyers, and as such, our Buyers then become Separate and Independent Controllers of that Personal Data. Marketplace Services Cint offers managed services to our Clients (“Marketplace Services”). Cint uses your Personal Data we collect directly on our Sites and via other external third-party survey hosting platforms to perform Marketplace Services. Personal Data collected via other external third-party hosting platforms may be transferred to Cint’s Sites in the performance of Marketplace Services. With regard to the control and processing of your Personal Data in connection with Marketplace Services, Cint and our Clients become Separate and Independent Controllers of that Personal Data. The opt-in consent you provide to Cint allows us to collect Personal Data from Suppliers and share this Personal Data with our Clients. Cint will share your Personal Data with a Client only if the company warrants that it has a lawful basis as a Separate and Independent Controller for processing your Personal Data. Monetization Services Cint offers technology and Services to Suppliers. Certain Personal Data may be exchanged between Suppliers and Cint to facilitate the efficient matching of you to appropriate Buyer Opportunities. When you provide your opt-in consent to Cint, as also described under the Marketplace section, you consent to our sharing of that data with Buyers for the purpose of matching you to a Buyer Opportunity. Audience (Data Score & Impact Measurement) Cint provides measurement Services to Clients that are global advertisers, agencies, advertising technology partners who wish to improve the relevance and impact of digital advertising campaigns. When on our Sites, you may receive an anonymous survey based on your exposure to an ad campaign or a third party identifier that is linked to your online profile via our tracker or one of our data partners. Information you share about your demographics, lifestyles, interests and opinions is used by Cint to sell Services that help Clients make better advertising decisions and improve accuracy of their targeting in digital channels; such data may become Respondent Screening Data. While we provide this information on a Respondent level to our Clients, we contractually prohibit our Clients from reidentifying you for the purpose of retargeting an advertising message. Third-Party Data Management Platforms (DMP) Services & Integrations Cint provides your Personal Data to DMPs for the following purposes: Targeted Advertising Cint shares your Personal Data via data synchronizations with DMPs who may use this information to gain insights and improve the accuracy of their targeted advertising products sold by DMPs and Cint’s Clients. NOTE: While Cint prohibits DMPs and Clients from retargeting you, if you delete your cookies we may lose the ability to associate your profiles on our Sites; as a result, your profile may be indirectly associated within a particular segment at which time you could receive targeted advertising products. Improved Survey Targeting Cint exchanges your Personal Data with DMPs to better understand metadata associated with your profile, which may then be used by Cint to perform Services on behalf of its Clients. Advanced Analytics. Cint shares your Personal Data with DMP, which is used by them to perform advanced analytics and customer research on behalf of Cint’s Clients. ii. Marketing Using Personal Data of Non-Respondents Cint processes Personal Data of non-Respondents, including Users, business contacts, and other visitors to our Sites, given our legitimate interest in undertaking marketing activities to offer you products or services that may be of interest. We may process your Personal Data via mail, live phone calls not on a “do not call list”, emails, and text messages. iii. Personal Data Provided under Section V Personal Data provided to enforce subject access rights pursuant to Section V of this Policy will be used only to respond to and comply with such requests. IV. Information Retention & Accuracy We take reasonable steps to ensure that Personal Information we receive, process, or maintain is accurate, complete, and reliable for its intended use. We rely on the accuracy of the information provided directly to us but accept responsibility for the management and confidentiality of the Personal Information collected. In general, we keep Personal Information only as long as we need it to provide you the Services you requested. We may also process data on behalf of third parties who have engaged us. We keep Personal Information processed on behalf of third parties for as long as needed to provide Services to third party in question. However, we reserve the right to retain Personal Information for any period required by law or to comply with our legal obligations, resolve disputes, and enforce our agreements. V. Sharing of Personal Information and Accountability for Onward Transfer a. User Data from Our Sites (other than from the Marketplace). When we have collected your first and last name in combination with other identifying Personal Data while using our Sites, we will only externally share that data as follows: With your consent; With affiliated and unaffiliated service providers all over the world that help us deliver our Services and run our business and Sites; When and as required by law including to meet national security requirements or to protect you, other users, us or third parties from harm, including fraud, data security breaches or where someone’s physical safety seem at risk; or In connection with a reorganization or sale of our company or assets, subject to the acquirer accepting the commitments made in this Policy and ensuring that the transfer is in compliance with applicable law. b. Respondent Screening Data from the Marketplace We share your Respondent Screening Data, information collected via the Cint tracking pixel, as well as data identified from third party databases (data management platforms) with third party partners and Clients. They may use this data to help them understand consumer trends, measure effectiveness of advertising campaigns and make better media decisions. While some of this information may be used by our third party partners and Clients to inform targeting models, we contractually prohibit them from using any information we provide for the purpose of directly retargeting you via their advertising. c. EU‑U.S., UK and Swiss‑U.S. Data Privacy Framework Principles Additionally, Cint may share your Personal Information with third party service providers and/or subprocessors, without your prior consent, subject to Cint doing the following: transfer such data only for limited and specified purposes; ascertain that the subprocessor is obligated to provide at least the same level of privacy protection as is required by EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF); take reasonable and appropriate steps to ensure that the subprocessor effectively processes the Personal Information transferred in a manner consistent with the organization’s obligations under EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF); require the subprocessor to notify Cint if it makes a determination that it can no longer meet its obligation to provide the same level of protection as is required by EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF); upon notice, including under (iv), take reasonable and appropriate steps to stop and remediate unauthorized processing; and provide a summary or a representative copy of the relevant privacy provisions of its contract with that subprocessor to the U.S. Department of Commerce upon request. Cint shall remain liable under the EU-US Data Privacy Framework Principle of Accountability for Onward Transfer if its subprocessors process your Personal Information in a manner inconsistent with the Data Privacy Framework Principles unless Cint proves it is not responsible for the event giving rise to the damage. Please see our Cint + Subprocessors webpage to view a current list of subprocessors and to subscribe to be updated when there are changes to the list. If you are visiting this website from a country other than the country in which our servers are located, your communications with us will result in the transfer of information across international boundaries. By visiting this website and communicating electronically with us, you consent to such cross-border transfers. In the case of data transfers from the EEA and Switzerland, the EU‑U.S., UK extension and Swiss‑U.S. Data Privacy Frameworks apply. VI. Protection of Personal Information Cint uses reasonable security measures in an effort to prevent loss, misuse and alteration of data under our control. However, we cannot guarantee the security of information on or transmitted via the Internet. We rely on various security procedures and systems to ensure the secure storage and transmission of data, including encryption and authentication technology licensed from third parties, to effect secure transmission of confidential information. Additionally, we have absolutely no control over the security of other sites you might visit, interact with or do business with. If we learn of a security systems breach, then we may attempt to notify you electronically so that you can take appropriate protective steps. Cint may post a notice on the Cint Site if a security breach occurs. We may also send an email to you at the email address you have provided to us in these circumstances. Depending on where you live, you may have a legal right to receive notice of a security breach in writing. To receive a free written notice of a security breach (or to withdraw your consent from receiving electronic notice) you should notify us. VII. Limits to Your Privacy Our Sites may contain links to external websites, and areas where you can provide information to third-parties. These are provided for your convenience only, and we do not have control over the content or privacy and security practices and policies of such third parties or third-party sites. Any Personal Information you provide in such areas, and on such linked pages is provided directly to that third party and is subject to that third party’s privacy policy. Please learn about the privacy and security practices and policies of external websites and third-parties before providing them with Personal Information. VIII. Choice Regarding Collection, Use & Distribution of Personal Information You can choose to opt-out whether your Personal Information is (i) to be disclosed to a third party or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individuals. If you choose to opt-out, please contact us via email at [email protected]. In such an event, you will only be able to access public areas of the Sites and may be limited in the use of Cint’s Sites. In certain cases, limiting the use and disclosure of your Personal Data may impact functionality or prevent the use of Cint products or Services. IX. Access & Correction If you register as a Buyer or Supplier, you can update, correct, or delete your user information and email subscription preferences by going to the log-in section of our Sites. You have the right to access the Personal Information we hold about you. You may also access your information that Cint holds by contacting us at the address below. You have the right to correct, amend, or delete that information where it is inaccurate, or has been processed in violation of the Data Privacy Framework Principles, except where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy in the case in question, or where the rights of persons other than the individual would be violated. We maintain processes or mechanisms to allow you to review, update, correct or delete Personal Information held by us. You may make changes to your account information, access, correct, or delete Personal Information held by Cint by contacting us at: Cint USA, Inc. Attn: Sales Operations 1235 St Thomas St. Suite 201 New Orleans, LA 70130 United States of America Email: [email protected] To protect your privacy and security, Cint may also take reasonable steps to verify your identity before making corrections to or deleting your information. We will respond to your request for access to modify or delete your information within a reasonable timeframe. X. Contacting Cint, Dispute Resolution, Arbitration & Cost Cint will address all questions, complaints or requests concerning this Privacy Policy within 30 days of receipt. For EU Respondents, please use our Respondent Data Rights Portal to inquire about your rights For EU Business Partners, Employees & Contractors please use our Business Partner, Employee & Contractor Data Rights Portal to inquire about your rights. Please see the applicable details below: a. EU, UK & Swiss Citizens In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), Cint commits to resolve complaints about your privacy and our collection or use of your Personal Information. European Union, UK, and Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact Cint at: Cint USA, Inc. Attn:DPO 1235 St Thomas St. Suite 201 New Orleans, LA 70130 United States of America Email: [email protected] Cint has further committed to refer unresolved privacy complaints under the EU-US Data Privacy Framework Principles to the INSIGHTS ASSOCIATION DATA PRIVACY FRAMEWORK PROGRAM, a non-profit alternative dispute resolution provider located in the United States and operated by the Insights Association. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please Data Privacy Framework for more information and to file a complaint. These dispute resolution services are provided at no cost to you. More details are available at ICDR-AAA Services for the Data Privacy Framework Program | ICDR.ORG If your complaint is not resolved after following the recourse mechanisms described above, you may have the ability to invoke binding arbitration. Additional information is available here. In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Cint commits to cooperate and comply respectively with the advice of the panel established by the EU Data Protection Authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship. b. Non-EU or non UK/Non-Swiss Citizens Cint commits to resolve complaints about your privacy and our collection or use of your Personal Information. Non-EU/Non-Switzerland citizens with inquiries or complaints regarding this privacy policy should contact Cint at: Cint USA, Inc. Attn: DPO 1235 St Thomas St. Suite 201 New Orleans, LA 70130 United States of America Email: [email protected] c. Mandatory Arbitration Agreement, Class-Action Waiver, and Jury Waiver Any dispute with our business partners arising out of or in connection with this Privacy Policy and not satisfactory addressed by Cint or Insights Association will be governed as to all matters, including, but not limited to the validity, construction and performance of this Agreement, by and under the laws of the State of New York, United States of America, without giving effect to conflicts of law principles thereof and excluding the U.N. Convention on the International Sale of Goods. (i) The Parties agree to maintain the confidential nature of all disputes and disagreements between them, including, but not limited to, informal negotiations, mediation or arbitration, except as may be necessary to prepare for or conduct these dispute resolution procedures or unless otherwise required by law or judicial decision. Except as provided in Section X.c (ii), each Party agrees that before it seeks mediation, arbitration, or any other form of legal relief, it shall provide written notice to the other of the specific issues in dispute (and referencing the specific portion of any contract between the Parties and which are allegedly being breached). Within thirty (30) days after such notice, knowledgeable executives of the Parties shall hold at least one meeting (in person or by video- or tele- conference) for the purpose of attempting in good faith to resolve the dispute. Except as provided in Section X.c (ii), any and all disputes, claims or controversies arising out of or relating to this Agreement shall be submitted to JAMS for mediation before arbitration or any other form of legal relief may be instituted. Mediation may be commenced by a Party providing JAMS a written request for mediation setting forth the subject of the dispute and the relief requested. The Parties will cooperate with JAMS in selecting a single mediator and scheduling a mediation, which should take place within forty-five (45) days following a request for mediation. The mediator shall be a retired judge who has had experience with technology disputes, but the mediator shall not have the authority to award punitive or exemplary damages. The Parties agree that they will participate in good faith and share equally in its costs. The mediation shall take place in New Orleans, Louisiana. (ii) The dispute resolution procedures in this Agreement shall not apply prior to a Party seeking a provisional remedy related to claims of misappropriation or ownership of intellectual property, trade secrets, or Confidential Information. XI. Changes to Privacy Policy We reserve the right to modify this Privacy Policy at any time. If we decide to change our Privacy Policy, we will prominently post those changes here and any other place we deem appropriate, so you are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If we make any material changes, we will notify you by way of an email (sent to the email address associated with your account) or by means of a notice on this site prior to the change becoming effective. We will use information in accordance with the privacy policy under which the information was collected. We use a self-assessment approach to address compliance with this Privacy Policy, verifying periodically that the policy is accurate, comprehensive, and addresses the privacy requirements applicable to the markets we serve. Periodically, our operations and business practices are reviewed for compliance with corporate policies and procedures governing the confidentiality of information. These reviews are conducted by internal staff who report directly to our General Counsel. EU, UK and AUS Privacy Notice This privacy notice does Not apply to personal data processed in connection with Cint’s market research platform services, which are governed by separate agreements and notices. See below: If you are a survey participant of any panel, please reach out directly to your panel provider. It is the company who is paying you for your survey participation. You can also find the name from the link of the survey. If you are a survey participant of Entscheiderclub.de, Clubdecideurs.ch, Clubdecisionisti.ch, please go to your profile directly. You can access your personal data and request deletion in your profile. 1. Scope and Who This Notice Applies To This Privacy Notice applies to individuals who visit or interact with Cint’s website, including prospective customers, existing clients, event attendees, and anyone who contacts us directly. 2. Personal Data and Personal Information We Collect We collect the following categories of information: 2.1. Identity and contact data: name, job title, employer, business email address, postal address, and telephone number. 2.2. Usage and technical data: IP address, browser type, operating system, Internet service provider, referring and exit pages, date and time stamps, and clickstream data, collected automatically via log files and similar technologies. 2.3. Communications data: the content of enquiries, requests, records of products and other messages you send to us. 2.4. Marketing preferences: your preferences for receiving marketing communications and your responses to those communications. 2.5. Cookie and tracking data: information collected through cookies and similar tracking technologies as described in 4. Above and in our [Cookie Policy]. 2.6. Inferences drawn from the above to create a profile about preferences or interests. We do not intentionally collect Sensitive Personal Information (as defined under the California Privacy Rights Act (“CPRA”)) or special category data (as defined under the General Data Protection Regulation (“GDPR”)) through this website. Sources of personal data: We collect personal data directly from you (through the website, forms, email, telephone, and events), automatically (through cookies and log files), and occasionally from third parties such as conference organizers, event sponsors, industry registration or publicly available sources. 3. Categories of Third Parties to Whom We Disclose Personal Information We disclose personal information to the categories of third parties described in section 6, including Cint group companies, service providers, and legal or regulatory authorities. 4. Sale and Sharing of Personal Information Cint does not sell your personal information for monetary consideration. Cint may share personal information with third-party advertising or analytics partners in ways that may constitute “sharing” under the CCPA (i.e., sharing for cross-context behavioral advertising purposes). You have the right to opt out of such sharing at any time — see clause 11.5 below. 5. Minors Under 16 – Children We do not knowingly collect, process, sale or share personal information of consumers below 16 years old. If we become aware that we have inadvertently collected personal data from a child below the applicable age threshold, we will promptly delete it. If you believe we have collected data from a child, please contact us at [email protected]. 6. Legal Bases for Processing (EEA, UK, and Switzerland) 6.1. Legitimate interests (Article 6(1)(f) GDPR): to respond to your enquiries, manage our business relationship with you, improve our website, prevent fraud, and send direct marketing to existing and prospective business contacts where permitted by applicable law. We have carried out a legitimate interests assessment and concluded that our interests are not overridden by your interests or fundamental rights in these contexts. 6.2. Performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR): where processing is necessary to take steps at your request before entering into a contract, or to perform our obligations to you. 6.3. Compliance with a legal obligation (Article 6(1)(c) GDPR): where processing is required by law. 6.4. Consent (Article 6(1)(a) GDPR): where you have given us specific, informed, and freely given consent, including for non-essential cookies and for certain direct marketing activities. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. 7. How We Use Your Personal Data We use the personal data we collect for the following purposes: 7.1. to respond to and process enquiries, requests, and communications you initiate; 7.2. to manage and develop our business relationship with you; 7.3. to send marketing communications about Cint’s products, services, and events, where you have consented or where we have a legitimate interest and applicable law permits; 7.4. to send surveys about our products and services; 7.5. to improve, test, and maintain our website and associated services; 7.6. to comply with legal and regulatory obligations; 7.7. to prevent, detect, and investigate fraud, security incidents, and illegal activity; and 7.8. to transfer data within the Cint group of companies for internal administrative purposes, subject to appropriate safeguards. We will not use your personal data for purposes incompatible with those described above without your consent or as otherwise permitted by law. Automated decision-making: We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing of your personal data. 8. Cookies and Tracking Technologies Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device. We use: 8.1. Strictly necessary cookies: required for the website to function and cannot be switched off. 8.2. Analytics cookies: to measure traffic patterns and understand how visitors use the website (e.g., Google Analytics or similar tools). 8.3. Functional cookies: to remember your preferences and personalize content. 8.4. Marketing and advertising cookies: to deliver relevant content and, where applicable, support cross-context behavioral advertising. When you first visit our website, we will ask for your consent before placing any non-essential cookies on your device. You can manage or withdraw your cookie consent at any time through Cint Cookie Policy – Cint™ | The World’s Largest Research Marketplace or by configuring your browser settings. Global Privacy Control: We honor the Global Privacy Control (“GPC”) signal. If your browser or device transmits a GPC signal, we will treat it as an opt-out of the sale and sharing of your personal information for cross-context behavioral advertising purposes, to the extent required by the CPRA and other applicable law. For full details of the cookies we use, their purposes, and their retention periods, please see Cint Cookie Policy – Cint™ | The World’s Largest Research Marketplace. 9. How We Share Your Information Cint does not sell your personal data or personal information for monetary consideration. We may share your information: 9.1. Within the Cint group: with Cint’s parent, subsidiary, and affiliated companies for internal administrative and business purposes, subject to appropriate intra-group data transfer agreements. 9.2. With service providers: with third-party vendors and processors who perform services on our behalf (such as IT hosting, email delivery, analytics, and CRM platforms). Service providers are contractually permitted to use your data only as necessary to provide those services. 9.3. With legal and regulatory authorities: where required by applicable law, court order, or to comply with a lawful request from a public authority, or to protect the rights, property, or safety of Cint, our customers, or others. 9.4. In connection with a business transaction: in the event of a merger, acquisition, reorganization, or sale of all or part of our business or assets. Any acquirer will be required to maintain the confidentiality and integrity of your personal data in a manner consistent with this Privacy Notice. 9.5. With your consent: for any other purpose where you have given your prior consent. All service providers and other third parties that receive personal data from us are required to implement appropriate technical and organizational measures to protect that data. 10. International Transfers Cint stores all primary data on servers within the European Union. Where personal data is transferred outside the EEA, UK, or Switzerland — including within the Cint group or to third-party service providers located in non-adequate third countries — we ensure an appropriate transfer mechanism is in place, such as: 10.1. standard contractual clauses approved by the European Commissionn (SCC) or, for UK transfers, the International Data Transfer Agreement (“IDTA”) or addendum approved by the UK Information Commissioner; 10.2. adequacy decisions issued by the European Commission or the UK Secretary of State; or 10.3. other lawful transfer mechanisms under the GDPR or applicable law. 10.4. Cint US complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. Cint has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Cint has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/ 11. Retention We retain your personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting obligations. The criteria we use to determine retention periods include: 11.1. the duration of our business relationship with you or your employer; 11.2. the nature of the personal data; 11.3. applicable legal limitation periods; and 11.4. any contractual or regulatory requirements. Enquiry and contact data is generally retained for two years from the date of last contact. Marketing preference records are retained for the duration of our marketing relationship and for a reasonable period thereafter to evidence consent and opt-outs. Technical log data is typically retained for 12 months. 12. Security Cint implements and maintains appropriate technical, organizational, and physical safeguards to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These include access controls, encryption in transit, and regular reviews of our security practices. No transmission over the internet or mobile network is completely secure. While we take reasonable steps to protect your data, we cannot guarantee the security of any information you transmit to us. 13. Your Rights (EEA, UK, and Switzerland) If the GDPR or equivalent legislation applies to you, you have the following rights with respect to your personal data: 13.1. Right of access: to request a copy of the personal data we hold about you. 13.2. Right to rectification: to request correction of inaccurate or incomplete personal data. 13.3. Right to erasure: to request deletion of your personal data in certain circumstances (for example, where it is no longer necessary for the purpose for which it was collected). 13.4. Right to restriction of processing: to request that we restrict processing of your personal data in certain circumstances. 13.5. Right to data portability: to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where technically feasible and where processing is based on consent or contract. 13.6. Right to object: to object to processing based on legitimate interests (including direct marketing) at any time. We will stop processing your personal data for direct marketing purposes immediately upon request. 13.7. Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing. 13.8. Right to lodge a complaint: to lodge a complaint with the relevant supervisory authority. In Sweden, the supervisory authority is the Integritetsskyddsmyndigheten (IMY) (imy.se). You may also complain to the authority in the EU Member State where you habitually reside or work, or where the alleged infringement occurred. Rights Available to Residents of Most Residents of California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, New Hampshire, Nebraska, and New Jersey You generally have the right to: (a) Know and Access: Confirm whether we process your personal data and request a copy of that data. (b) Delete: Request that we delete personal data we hold about you, subject to certain exceptions. (c) Data Portability: Obtain a copy of your personal data in a portable, usable format. (d) Opt Out of Sale: Direct us not to sell your personal data to third parties. (e) Opt Out of Targeted Advertising: Direct us not to use your personal data for targeted or cross-context behavioral advertising. Additional rights and specific variations by state are set out in the state-specific sections below. Global Privacy Control (GPC): If you use a browser or extension that sends a Global Privacy Control signal, we will treat it as a valid opt-out request for the sale of personal data and targeted advertising in states that require us to honor such signals, including California, Colorado, Connecticut, Delaware, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. California Residents California residents are protected by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and enforced by the California Privacy Protection Agency and the California Attorney General. Your rights include: (a) Access: Request disclosure of the categories and specific pieces of personal information we have collected about you since January 1, 2022. (b) Delete: Request deletion of your personal information, subject to limited exceptions. (c) Correct: Request correction of inaccurate personal information we hold about you. (d) Data Portability: Receive your personal information in a portable format. (e) Opt Out of Sale or Sharing: Direct us not to sell or share your personal information, including for cross-context behavioral advertising. You may exercise this right using the “Do Not Sell or Share My Personal Information” link on our website or by enabling the Global Privacy Control on your browser. We will display a visible confirmation when your opt-out request has been processed. (f) Limit Use of Sensitive Personal Information: Request that we limit our use and disclosure of sensitive personal information (such as precise geolocation, biometric data, health information, and similar categories) to what is necessary to provide you with the services you requested. (g) Opt Out of Automated Decision-Making: Where we use automated decision-making technology for significant decisions affecting you (such as in employment, lending, or similar contexts), you have the right to opt out and to request information about how that technology works. California residents also have a limited private right of action for certain data breaches. We will not retaliate against you for exercising any of these rights. We may not ask you to create an account to submit an opt-out request. To learn more, visit the California Privacy Protection Agency or the California Attorney General’s CCPA page. Virginia Residents Virginia residents are protected by the Virginia Consumer Data Protection Act (VCDPA), enforced by the Virginia Attorney General. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. We will respond to your appeal within 60 days. If your appeal is denied, we will provide information on how to contact the Virginia Attorney General. To learn more, visit the Virginia Attorney General’s Office. Colorado Residents Colorado residents are protected by the Colorado Privacy Act (CPA), enforced by the Colorado Attorney General. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personaldata. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. We will respond to your appeal within 60 days. If your appeal is denied, we will provide information on how to submit a complaint to the Colorado Attorney General. We are required to obtain your opt-in consent before processing sensitive personal data (including precise geolocation, biometric data, racial or ethnic origin, health conditions, sexual orientation, and genetic data). As of July 1, 2026, if we use your personal data to train artificial intelligence systems or large language models, we will disclose this in our privacy notice. To learn more, visit the Colorado Attorney General – Colorado Privacy Act. Connecticut Residents Connecticut residents are protected by the Connecticut Data Privacy Act (CTDPA), enforced by the Connecticut Attorney General. Significant amendments to the CTDPA took effect on July 1, 2026. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. (f) Know Third-Party Recipients: Request a list of third parties to whom we have sold your personal data. (g) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. We will respond to your appeal within 60 days. If your appeal is denied, we will provide information on how to submit a complaint to the Connecticut Attorney General. We are required to obtain your opt-in consent before processing sensitive personal data. To learn more, visit the Connecticut Attorney General – CTDPA. Utah Residents Utah residents are protected by the Utah Consumer Privacy Act (UCPA), enforced by the Utah Attorney General. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data that you have provided to us. (d) Data Portability: Obtain a portable copy of your personal data (e) Opt Out of Sale and Targeted Advertising: Direct us not to process your personal data for the sale of personal data or for targeted advertising. Note: Utah law does not currently provide a right to opt out of profiling or a right to appeal a denial of your request, and does not require us to honor universal opt-out preference signals. To learn more, visit the Utah Division of Consumer Protection – UCPA. Oregon Residents Oregon residents are protected by the Oregon Consumer Privacy Act (OCPA), enforced by the Oregon Attorney General. Businesses must honor universal opt-out preference signals under the OCPA. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling. (f) Appeal: If we decline to act on your request, you may appeal our decision in writing by contacting us at [[email protected]]. We will respond within 45 days. If your appeal is denied, we will provide information on how to contact the Oregon Attorney General. We are required to obtain your opt-in consent before processing sensitive personal data. To learn more, visit the Oregon Department of Justice – OCPA. Texas Residents Texas residents are protected by the Texas Data Privacy and Security Act (TDPSA), enforced by the Texas Attorney General. Businesses must honor universal opt-out preference signals, including the Global Privacy Control. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. To learn more, visit the Texas Attorney General – TDPSA. Montana Residents Montana residents are protected by the Montana Consumer Data Privacy Act (MCDPA), enforced by the Montana Attorney General. Your rights include: (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. To learn more, visit the Montana Department of Justice – MCDPA. Iowa Residents Iowa residents are protected by the Iowa Consumer Data Protection Act (ICDPA), enforced by the Iowa Attorney General. Your rights include: (a) Access: Request a copy of the personal data we hold about you. (b) Delete: Request deletion of personal data you have provided to us. (c) Data Portability: Obtain a portable copy of your personal data. (d) Opt Out of Sale: Direct us not to sell your personal data. Note: Iowa law does not currently provide rights to correct inaccuracies, opt out of targeted advertising, opt out of profiling, or appeal a denial of your request. Delaware Residents Delaware residents are protected by the Delaware Personal Data Privacy Act (DPDPA), enforced by the Delaware Attorney General. We are required to honor universal opt-out mechanisms, including the Global Privacy Control. Your rights include: (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. To learn more, visit the Delaware Department of Justice. New Hampshire Residents New Hampshire residents are protected by the New Hampshire Privacy Act (NHPA), enforced by the New Hampshire Attorney General. Businesses must honor universal opt-out preference signals under the NHPA. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or certain profiling activities. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. To learn more, visit the New Hampshire Department of Justice. Nebraska Residents Nebraska residents are protected by the Nebraska Data Privacy Act (NDPA), enforced by the Nebraska Attorney General. Nebraska requires businesses to honor universal opt-out mechanisms where they are already obligated to do so under another state’s privacy law. Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data. (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. To learn more, visit the Nebraska Attorney General – Data Privacy. New Jersey Residents New Jersey residents are protected by the New Jersey Data Privacy Act (NJDPA), enforced by the New Jersey Division of Consumer Affairs (effective January 15, 2025). Your rights include: (a) Access: Confirm whether we are processing your personal data and request a copy. (b) Correct: Request correction of inaccuracies in your personal data. (c) Delete: Request deletion of your personal data. (d) Data Portability: Obtain a portable copy of your personal data (e) Opt Out of Sale, Targeted Advertising, and Profiling: Direct us not to process your personal data for the sale of personal data, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. (f) Appeal: If we decline to act on your request, you may appeal our decision by contacting us at [[email protected]]. 14. Links to Third-Party Websites This website may contain links to third-party websites. Cint is not responsible for the privacy practices or content of those websites and this Privacy Notice does not apply to them. We encourage you to review the privacy notices of any third-party websites you visit. 15. Changes to This Privacy Notice We may update this Privacy Notice from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. We will post the updated Privacy Notice on this page with a revised “Last revised” date. Your continued use of our website after the posting of changes constitutes your acknowledgement of the updated Privacy Notice. Where we are required by law to obtain your consent to material changes, we will do so before the changes take effect. 16. Contact Us – How to Submit a Privacy RequestIf you have any questions, concerns, or complaints about this Privacy Notice or our privacy practices, or if you wish to exercise any of your rights, please contact us: To exercise any of the rights described in this notice, you may: Email us at [[email protected]] with the subject line “Web site Privacy Request”; or Contact us by post at: Cint AB, United Spaces Business Center, Drottninggatan 32, 4 tr, 111 51 Stockholm, Sweden. Attn: Data Privacy Officer We will verify your identity before processing your request. We will respond within the timeframe required by applicable law (generally 30 or 45 days, with a possible extension where reasonably necessary). We will not discriminate against you for exercising your privacy rights. If you have authorized an agent to submit a request on your behalf, the agent must provide written proof of authorization and we may require you to verify your own identity directly with us. If you are located in the EEA and are not satisfied with our response, you have the right to lodge a complaint with the Integritetsskyddsmyndigheten (IMY) at imy.se, or with the supervisory authority in your country of residence or place of work.