Category
Whose Data
Use
Lawful Basis, in addition to Consent

Brand Panel Referral Information.

Non-Members; Global Audiences

If you are referred to participate in an Action powered by us from another company you're a customer of (for example, StateFarm), we tag you in our systems to reflect that referral. That way, StateFarm can send Actions to you.

Performance of a contract; Necessary for our legitimate interests

Contact Information. (Your name, email, address, phone number)

Non-Members; Global Audiences

You might choose to provide us with your contact information, whether through use of our services, a form on our website, an interaction with our support team, or a response to one of Suzy’s own Actions. We only use contact information to respond to an inquiry which you, as an External Audience, submit to us. Example: Our support team uses your email address to communicate with you if you have contacted us about a survey, form, application, or questionnaire you received.

Performance of a contract

Cookies. For example, data we get from first and third party cookies, page tags, pixels and similar technology placed on your device.

Non-Members; Global Audiences

Read our Cookie Policy for full details. We, our service providers, and third-party partners, may collect information about the use of our Sites by automated means, including via cookies, web beacons, and other technologies. This information may include information about the devices you use to access our Sites (such as IP address and browser and operating system type), dates and times of visits to, and use of our Sites, information about how our Sites are used (such as pages viewed, date and time of access, information about how users navigate on or between our webpages, or the features of our mobile applications that are used and how users navigate between screens on our mobile applications), the URLs that refer visitors to our Sites, and the search terms used to reach our Sites.

Necessary for our legitimate interests

Data Quality Information. For example, IP addresses, email domains, phone numbers, survey responses, behavioral information, etc.

Non-Members; Global Audiences

We use this information to moderate for bots, to authenticate users, to prevent fraud and abuse, and to gauge whether you are a high quality respondent. This helps us preserve the security of our Sites and helps us provide quality assurance controls for our Clients. For example, we employ IP and email domain blocking to prevent fraud and abuse, as well as patented technology that identifies behavior patterns indicative of bots.

Necessary for our legitimate interests (to prevent fraud and abuse, ensure data quality, and help improve network security).

Device and Browser Data. For example, IP address, device type, MAC ID, browser type.

Non-Members; Global Audiences

We use this data for service optimization and troubleshooting for your specific device/browser of preference (in other words, we want you to see the best possible view of the Sites on your specific device). We also infer your location from your IP address.

Necessary for our legitimate interests

Inferred Data.

Non-Members; Global Audiences

We may infer information about you (including your location and your preferences) from the above categories of information which we collect about you.

Necessary for our legitimate interests

Information from Third Parties and integration Partners. This includes your name and email address or IP address where you have given permission to those third parties to share that information with us or where that information is publicly available either online or through your device/browser data.

Non-Members; Global Audiences

We collect your personal information from third parties where, for example, you give permission to those third parties to share your information with us, where such information is publicly available online or through your device/browser data. We will collect and use information from third parties and integration partners to facilitate Clients or Panel Providers sending Actions to you.

Necessary for our legitimate interests

Log Data or Log Files that record data each time a device accesses a server. This contains data about the nature of access, for example, originating IP addresses, Internet service providers, the files viewed on our site (like HTML pages, graphics, etc.), operating system versions, device type, and timestamps.

Non-Members; Global Audiences

Log data can be used for a lot of different things but predominantly we use it for: monitoring abuse and troubleshooting site and security issues, improving the product functionality and creating new features, tracking behavior for content and services at an aggregate level (for example, to monitor service requests or service denial on our site overtime to ensure our site remains stable) and fixing bugs or functionality issues. We will also use log data to help us make recommendations to you or track your visits to our sites. For example, your IP address is used for abuse monitoring purposes (so we can identify an External Audience who abused the survey taking experience in a manner contrary to our usage policies or to facilitate a Client in complying with their own legal obligations).

Necessary for our legitimate interests

Matched Data.

Non-Members; Global Audiences

We provide our Panel Provider with a profile of the type of panelist we wish to use for a particular survey. This may include requirements such as (on a non-exhaustive basis) panelists of a particular gender, age or age range, income bracket or location. If you respond to a particular survey, we will know that you have (or that it is likely you have) the characteristics or match the details listed in the panelist profile. We do not actively seek to re-identify you through use of this data.

We may also utilize matching services (i.e., third parties who are specialized in data management, such as consumer behavior insights) to acquire additional information about you from public and private data sources (such as social networks, retailers, and content subscription services with whom you have an account) or to use your Personal Data as an aid to develop additional or new types of de-identified data sets (i.e., we compile your Aggregate Data with data from other consumers to create a new lifestyle segment). The matching service provider holds the Personal Data we share for a short time, uses it to assemble the additional information, and then return the combined information to us. They are contractually bound to delete the data we share with them and are not authorized to use it in any way other than for this specific purpose.

Necessary for our legitimate interests

Metadata.

Non-Members; Global Audiences

We receive data from the device you use to access surveys, such as your operating system version, device manufacturer and model, carrier (i.e., mobile provider), system locale. We may also store any information collected by the core SDK, like device name (can be personalized by device owner) and user agent string.

Necessary for our legitimate interests

Referral Data. This is information about the place where you were before you came to a Site – for example, if you were on social media before clicking on a link to a Site, we record information about the source that referred you to us.

Non-Members; Global Audiences

If you arrive at a Suzy website from an external source (such as a link on another website or in an email), we record information about the source that referred you to us.

Necessary for our legitimate interests

Response Data. This is responses to Actions, which may include things like your occupation field, interests, opinions, or other information you voluntarily provide to us when you participate in an Action.

Non-Members; Global Audiences

We collect and receive the responses you provide to Actions, which may directly identify you or which, when used with other information which we hold about you, may indirectly identify you. We use the information for our brand research and insights.

We also share your responses to Actions with the Client(s) who purchased license(s) with us and who initiated the Action(s). The Client(s) use your responses to Actions for their brand research and insights, marketing, and promotions.

Necessary for our legitimate interests

Response Rate Information. For example, page view data, response rates, response types, and survey type

Non-Members; Global Audiences

We use and analyze this information:

To improve the user interface;

To maintain a consistent and reliable External Audience experience; and

To improve our Client services by looking at what questions Clients are asking and the quality of their responses and response rates so that we can enhance our existing features and build new ones to optimize question/answer rates for Clients.

Necessary for our legitimate interests (to improve our Sites, to develop them, to grow our business, and to inform our product development and marketing strategy)

Sensitive Personal Data. See the section in this Notice titled "What is Personal Data" for details on what is considered Sensitive Personal Data.

Non-Members; Global Audiences

You may be asked to provide Sensitive Personal Data in response to Actions. If we collect that information or intend to disclose such information to a third party or use it for a purpose other than as described in this Notice, we will obtain your specific permission to do so prior to any such use or disclosure.

Performance of a contract

Usage Information. (how you use the Sites, what pages you click on, etc.)

Non-Members; Global Audiences

We collect usage information about you whenever you interact with our websites and services. This includes which webpages you visit, what you click on, when you perform those actions, what language preference you have, what you buy and so on. We use information about how you use our services to improve our services for you and all users. Examples: We collect information about the types of questions you answer via Aggregate Data, so we can examine patterns across External Audiences. We collect and use all this data for our legitimate interests like helping us improve the experience for External Audiences (so that questions are easier to answer), for training purposes, and to understand industry trends in and to help improve the completion rates on surveys/forms.

Necessary for our legitimate interests

All of the above categories - Aggregate Data.

Non-Members; Global Audiences

We may aggregate information you provide in a manner which does not identify you (“Aggregate Data”). We may collect and use data about access to and use of our Sites that we automatically collect as a form of Aggregate Data to determine how much time visitors spend on each page of our Site, how visitors navigate throughout the Site, and how we may tailor our web pages to better meet the needs of visitors. We may use your Aggregate Data for our own legitimate business purposes, including operating and enhancing our Site, for performing statistical analysis business planning, and for market research purposes.

Necessary for our legitimate interests

All of the above categories - Artificial Intelligence / Machine Learning.

Non-Members; Global Audiences

We use techniques like machine learning or artificial intelligence on Personal Data for ensuring compliance with legal and regulatory requirements, detecting quality to maintain reliable External Audiences, and to provide automated market research services to Clients like heatmapping, dynamic segmentation, data explorer, AI summaries, and the like. Clients have some controls over how we use Response Data and may have turned off our ability to apply machine learning to responses where it is linked to a specific product feature.

We also use automated processes and machine learning to:

  • analyze Response Data, which in turn helps us to identify trends, build product features that optimize responses, make product recommendations, and provide guidance on which products and services work best in different scenarios
  • extract and analyze usage patterns, which in turn helps us to improve our services and ease of use (for example, we might identify when respondents prefer multiple choice versus open text questions and make predictive response suggestions when certain question types are selected)
  • undertake personalization for Clients and you (for example by customizing the page on our website which you see at the end of a survey)
  • improve user experience (for example, by collecting and using device and browser information to improve how our service operates on those devices and in those browsers)
  • identify insightful data trends (via Aggregate Data)
  • to build features, improve our services, for fraud detection, and to develop Aggregate Data products

Necessary for our legitimate interests

All of the above categories - Legal and Security.

Non-Members; Global Audiences

For legal and security purposes such as enforcing our agreements, preventing unlawful or abusive activity, responding to legal inquiries and lawful requests, and preventing fraud. For example, we sometimes inspect and use techniques like machine learning on responses to Actions to ensure compliance with our Terms of Service.

Necessary for our legitimate interests

All of the above categories - Other.

Non-Members; Global Audiences

To respond to legal requests or prevent fraud, we may need to disclose any information or data we hold about you. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.

Necessary to comply with a legal obligation

Right
Details

Right of Access

Find out what kind of Personal Data we process about you and request details of this information, including categories of recipients to whom the Personal Data have been or will be disclosed and purposes of processing.

Right to Know

Ask us for a notice identifying the categories of Personal Data that we collect (and from whom), disclose, or share (and to whom we disclose or share), as well as our business or commercial purposes for collecting, disclosing, or selling that Personal Data. In most respects, this Policy serves as such notice.

Right to Rectify, also known as Right to Correct

Ask for your Personal Data to be rectified, updated or, corrected. We may need to verify the accuracy of the new information you provide to us.

Right to Transfer, also known as Right to Data Portability

Ask us to package up your Personal Data in a structured, commonly used and machine-readable format, so you can move, copy, or transfer it to another organization in a secure manner and without interrupting the integrity and usability of the information.

Right to Restrict or Object to Processing

Object to certain types of processing of your Personal Data, including profiling, targeted advertising, direct marketing, and statistical, scientific, or historical research purposes.

Right to not be Subject to Fully Automated Decisions

Ask to not be subject to decisions with a legal or similarly significant effect (including profiling) that are based solely on the automated processing of your Personal Data, unless you have given us your explicit consent or where necessary for the performance of a contract with us.

Right to Limit Use of Sensitive Information

Tell us to limit or stop processing your Sensitive Personal Data.

Right to Withdraw Consent at Any Time

Withdraw any consent you may have previously given us.

Right to Delete, also known as the Right to be Forgotten

Request that your Personal Data be erased. Where required, we will delete your Personal Data. We will decline your request for deletion if processing of your Personal Data is necessary: (i) for us to comply with our legal obligations; (ii) for the establishment, exercise, or defense of legal claims; (iii) for the performance of a task in the public interest, or (iv) for us to perform certain actions in accordance with applicable laws, such as detecting security incidents and protecting against fraudulent activity.

Right to Opt-Out of the Sale or Sharing of your Personal Data

Direct us not to sell your Personal Data to third parties.

California residents: You have the right to tell us not to sell or share your Personal Data to third parties. This right is referred to as the "right to opt-out of sale or sharing."

Control
Details

Voluntary Action Participation

You can always refuse to answer an Action. Your participation in any survey is entirely voluntary, and you may opt out of responding at any time by skipping the question, declining the invitation, or selecting “prefer not to say”, where applicable.

Advertising Controls

Some of the business partners that may collect information about your activities on our Sites may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior for purposes of targeted advertising.

  • For example, you may opt out of receiving targeted advertising through members of the Network Advertising Initiative by clicking here or the Digital Advertising Alliance by clicking here.
  • European users may opt out of receiving targeted advertising through members of the European Interactive Digital Advertising Alliance by clicking here, selecting your country, and then clicking “Choices” (or similarly-titled link).
  • Mobile app users may opt out of receiving targeted advertising in mobile apps through members of the Digital Advertising Alliance by installing the AppChoices mobile app, available here, and selecting the user’s choices.

Please note that we may also work with companies that offer their own opt-out mechanisms and may not participate in the opt-out mechanisms that we linked to above.

Marketing Emails and Service Announcements Controls

Individuals may unsubscribe from receiving marketing or other commercial emails from us by following the instructions included in the email. However, even if an individual opts out of receiving such communications, we retain the right to send them non-marketing communications (such as announcements regarding changes to this Notice). Under certain circumstances, we may need to contact you in order to make an important announcement about the Site. We will also post information regarding changes directly on the Site. We may also contact your to correct errors or to supply important information we deem relevant.

Do Not Track signals

"Do Not Track" is a feature enabled on some browsers that sends a signal to request that a website disable its tracking or cross-website user tracking. We treat any user-enabled global privacy controls, such as a browser plug-in or privacy setting, device setting, or other mechanism, that communicate or signal your choice to opt-out of the sale of your Personal Data as a valid request submitted pursuant to applicable privacy laws for that browser or device, or, if known, for the individual.


Document Title
Privacy Notice for External Audiences

Document Classification

Public

Categories

Privacy

Assignee

Privacy Officer

Owner-Approver

General Counsel

Contributors

Ad Hoc

Scheduled Review

Annual

Version
Date
Revision Author
Summary of Changes

1.0

27 June 2023

Rachel Harris

Initial version

1.1

15 Feb 2024

Rachel Harris

Review

2.0

18 March 2025

Rachel Harris

Necessary for our legitimate interests