Category of Data
Whose Data
Use
Lawful Purpose, in addition to consent

Account Creation Information. When you register for an account, we collect your first and last name, username, password, email address, phone number, and last login IP address.

Clients

We use your name, username, password, and email address for user account creation on the Suzy platform. We use your phone number and last login IP address for security purposes.
We also use registration information to render services to you and to send you transactional emails and updates about usage and billing.

Performance of a contract

Account Settings. You can set various preferences and personal details on pages like your account settings page. These may include, for example, your default language, time zone, and communication preferences (e.g., opting in or out of receiving marketing communications from us).

Clients

We use this information to run your account and honor your service preferences. Depending on your company's underlying contract, we sometimes co-manage this information in conjunction with your organization.

Performance of a contract; Necessary for our legitimate interests

Basic Profile Information. This includes your name, occupation, title, email address, and phone number and other criteria you have voluntarily shared with us. It may also include a profile picture, if you so choose.

Clients

We use this information to provide you with a personalized service experience, to help others identify you (if you are in a team account), to personalize marketing information, as well as to make product, feature, and service recommendations to you and your organization so you can optimize the use of our services

Performance of a contract

Billing Information.

Clients

If you make a payment to Suzy, we require you to provide your billing details, a name, address, email address, and financial information corresponding to your selected method of payment (e.g., a credit card number and expiration date, a bank account number, etc). If you provide a billing address, we will regard that as the location of the account holder to determine the contracting entity and the sales tax, if applicable, to be applied to your purchase.

Performance of a contract

Brand Panel Referral Information.

Clients

We use information you provide us from your CRM to deliver Crowdtap invitations and Actions to your desired panels. We may work with a third-party service provider to deliver the invitations to your desired panels.

Performance of a contract

Contact Information. For example, your name, phone number, and email address.

Clients

We use it when we need to contact you about products and services (unless you unsubscribe) or to provide you with account and transactional information and updates (Although you cannot unsubscribe from the latter, we try to contact you only when necessary). We will also respond back to you if you contact our customer support or sales teams.

Performance of a contract; Necessary for our legitimate interests

Contact Information. For example, your name, phone number, and email address.

Visitors

We will respond to you if you contact our customer support or sales teams and for our own business development – for example, we may contact you in response to your inquiries or send you information about our services where you operate in a business which may be interested in our services.

Necessary for our legitimate interests (for running our marketing outreach services)

Cookies. For example, data we get from first and third party cookies, page tags, pixels and similar technology placed on your device.

Clients; Visitors

Read our Cookie Policy for details. Generally, we will infer common identities across different services and multiple devices such as tablets, browsers, and mobile phones to create a continuous product experience or for security reasons, for example. We will also tailor ads to you when you are browsing other sites online, to enable us to determine the success of our advertising campaigns, and to improve upon them. Emails sent by Suzy or Clients through our services also include page tags that allow the sender to collect information about who opened those emails and clicked on links in them.

Necessary for our legitimate interests (to define types of users for our Sites, to keep our Sites updated and relevant, to develop our business, and to inform our marketing strategy)

Data Quality Information. For example, IP addresses, email domains, phone numbers, survey responses, behavioral information, etc.

Clients; Visitors

We use this information to moderate for bots, to authenticate users, and to prevent fraud and abuse This helps us preserve the security of our Sites and helps us provide quality assurance controls. For example, we employ IP and email domain blocking to prevent fraud and abuse, as well as patented technology that identifies behavior patterns indicative of bots.

Necessary for our legitimate interests (to prevent fraud and abuse, ensure data quality, and help improve network security).

Device and Browser Data. For example, IP address, device type, MAC ID, browser type.

Clients; Visitors

We use this data for service optimization and troubleshooting for your specific device/browser of preference (in other words, we want you to see the best possible view of the Sites on your specific device). We also infer your location from your IP address.

Necessary for our legitimate interests (to study usage of our Sites, to develop them, to grow our business and to inform our marketing strategy)

Inferred Data.

Clients; Visitors

We may infer information about you (e.g., your preferences and habits) from all of the above categories of information which we collect about you.

Necessary for our legitimate interests (to study usage of our Sites, to develop them, to grow our business, and to inform our marketing strategy)

Information from third parties and integration partners. This includes your name and email address or IP address where you have given permission to those third parties to share that information with us or where that information is publicly available either online or through your device/browser data.

Clients, Visitors

We use this information to ensure you can sign-up to our service from a third party integration like Facebook, LinkedIn, Microsoft, Google/SSO; to personalize our services for you; and to ensure you can use our service in conjunction with other services.

Performance of a contract; Necessary for our legitimate interests (provision of, and to improve, our services)

Log Data or Log Files that record data each time a device accesses a server. This contains data about the nature of access, for example, originating IP addresses, Internet service providers, the files viewed on our site (like HTML pages, graphics, etc.), operating system versions, device type, and timestamps.

Clients, Visitors

Log data can be used for a lot of different things but predominantly we use it for: monitoring abuse and troubleshooting site and security issues, improving the product functionality and creating new features, tracking behavior for content and services at an aggregate level (for example, to monitor service requests or service denial on our site overtime to ensure our site remains stable) and fixing bugs or functionality issues. We will also use log data to help us make recommendations to you or track your visits to our sites.

Necessary for our legitimate interests (to prevent fraud and abuse and ensure network security)

Matched Data.

Clients, Visitors

We utilize matching services (i.e., third parties who are specialized in data management, such as customer relation insights) to acquire additional information about you from public and private data sources (such as social networks, industry groups, and content subscription services with whom you have an account) or to use your Personal Data as an aid to develop additional or new types of de-identified data sets. The matching service provider holds the Personal Data we share for a short time, uses it to assemble the additional information, and then return the combined information to us. Partners are contractually bound to delete the data we share with them and are not authorized to use it other than as authorized.

Performance of a contract; Necessary for our legitimate interests

Metadata.

Clients, Visitors

We receive data from the device you use to access surveys, such as your operating system version, device manufacturer and model, carrier (i.e., mobile provider), system locale. We may also store any information collected by the core SDK, like device name (can be personalized by device owner) and user agent string.

Necessary for our legitimate interests

Questions Data. For example, survey questions, focus group questions, etc.

Clients

The terms of the applicable Master Services Agreement between a Client and us governs the ownership of Questions Data.
Generally speaking, we store Clients' survey/form/application data (questions) and Respondents' responses to provide analysis tools for you to use with respect to this data. Clients' questions are private. We don't sell those materials but we may include them in Aggregate Data; we use them only for purposes related to providing, improving, supporting, or operating the Sites.

Performance of a contract; Necessary for our legitimate interests

Referral Data. This is information about the place where you were before you came to a Site – for example, if you were on social media before clicking on a link to a Site, we record information about the source that referred you to us.

Clients, Visitors

We use this data to track the success of our integrations and referral processes and to plan further referrals. For example, if you arrive at suzy.com from an external source (such as a link on another website or in an email), we record information about the source that referred you to us.

Necessary for our legitimate interests (to study how customers use our Sites, to develop them, to grow our business, and to inform our marketing strategy)

Response Data. This is responses to Actions, which may include things like Respondents' occupation field, interests, opinions, or other information they voluntarily provide to us when they participate in an Action.

Clients

The terms of the applicable Master Services Agreement between a Client and us governs the ownership of Response Data. Generally speaking, we own responses to Actions and "Member Data", as that term is defined in our Terms.We use Response Data to deliver our services to Clients, to return analyzed response data to Clients, and to improve our Sites.We internally use the data to improve the quality of our services. We also may use techniques like machine learning on Response Data for ensuring compliance with Respondent terms of use, detecting quality to maintain reliable panelists, and to provide automated market research services like heatmapping, dynamic segmentation, data explorer, AI summaries, and the like.We also use Response Data to give you and other Clients more ways to reach desired target demographics in future Actions and for benchmarking and Aggregate Data use. For example, if you ask "How much weight can you deadlift?", we may give other Clients the ability to target Respondents who can deadlift more than, say, 100lbs (based on the responses data). Other Clients would not be able to determine that the question originated from your Action.

Performance of a contract; Necessary for our legitimate interests

Response Rate Information. For example, page view data, response rates, response types, and survey type

Clients

We use and analyze this information:To improve the user interface;To maintain a consistent and reliable Respondent experience; andTo improve our Client services by looking at what questions Clients are asking and the quality of their responses and response rates so that we can enhance our existing features and build new ones to optimize question/answer rates for Clients.

Performance of a contract; Necessary for our legitimate interests (to improve our Sites, to develop them, to grow our business, and to inform our product development and marketing strategy)

Sales Automation & Analytics.

Clients

We use and share your contact information with third parties to automate our sales processes and generate actionable insights to help manage inbound and outbound sales processes.

Necessary for our legitimate interests

Sales Team Engagement. For example, audio and video recording of you.

Clients

We utilize third-party Gong.io , a digital communications solution, or a functionally equivalent third party, to enable our sales team to capture, record, and summarize Client communications to improve customer engagement. Specifically, we use service providers like Gong to record audio, video, and shared screens. Consent is obtained prior to collecting such information.

Necessary for our legitimate interests

Sensitive Personal Data. See the section in this Policy titled "What is Personal Data" for details on what is considered Sensitive Personal Data.

Clients

If you moderate or attend a Suzy Live IDIs or Focus Groups, your Sensitive Personal Data will be captured via the video and audio recording of the live interaction.

Performance of a contract

Usage Information. (how you use the Sites, what pages you click on, etc.)

Clients; Visitors

We collect usage information about you whenever you interact with our Sites. This includes which webpages you visit, what you click on, when you perform those actions, what language preference you have, what you buy and so on. We use this information to improve our services. We also will market to you (unless you unsubscribe or change cookie preferences).

Necessary for our legitimate interests (to help us improve user experience, to study how customers use our Sites, to develop them, to grow our business, to inform our marketing strategy, and for machine learning purposes (we use the data to keep training our models and to build new ones))

All of the above categories - Aggregate Data

Clients, Visitors

We may collect and use data about access to and use of our Sites that we automatically collect as a form of "Aggregate Data" to determine how much time visitors spend on each page of our Site, how visitors navigate throughout the Site and how we may tailor our web pages to better meet the needs of visitors. We may use your Aggregate Data for our own legitimate business purposes, including operating and enhancing our Sites, performing statistical analysis business planning, and for market research purposes.

Performance of a contract; Necessary for our legitimate interests

All of the above categories - Artificial Intelligence / Machine Learning

Clients; Visitors

We use techniques like machine learning or artificial intelligence for ensuring compliance with legal and regulatory requirements, detecting quality to maintain reliable Respondents, and to provide automated market research services like heatmapping, dynamic segmentation, data explorer, AI summaries, and the like.

We also use automated processes and machine learning to:

  • analyze Response Data, which in turn helps us to identify trends, build product features that optimize responses, make product recommendations, and provide guidance on which products and services work best in different scenarios
  • extract and analyze usage patterns, which in turn helps us to improve our services and ease of use (for example, we might identify when Respondents prefer multiple choice versus open text questions and make predictive response suggestions when certain question types are selected)
  • improve user experience and undertake personalization for Clients (for example, by collecting and using device and browser information to improve how our service operates on those devices and in those browsers)
  • improve, develop, analyze, and provide customer relations, sales engagement, and business development
  • identify insightful data trends (via Aggregate Data)
  • to build features, improve our services, for fraud detection, and to develop Aggregate Data products

Performance of a contract; Necessary for our legitimate interests

All of the above categories - Legal and Security.

Clients; Visitors

For legal and security purposes such as enforcing our agreements, responding to legal inquiries and lawful requests, and protecting against fraud, illegal activity (such as incidents of hacking or misuse of our Sites), and claims and other liabilities, including by enforcing the terms and conditions that govern the Sites

Necessary to comply with a legal obligation; Necessary for our legitimate interests

All of the above categories - Marketing

Clients; Visitors

To help improve our marketing by, for example, building user profiles to ensure our marketing materials are relevant to you and optimize our campaigns using machine learning.

Necessary for our legitimate interests

All of the above categories - Other

Clients, Visitors

We may also use your Personal Data to:-Communicate about the products and services we offer-Respond to requests, inquiries, comments, and suggestions-Provide our products and services-Analyze use of our products and services-Operate, evaluate and improve our business, our Sites, and other products and services we offer (including to research and develop new products and services)-Establish and maintain an individual's profile on our Sites-Analyze and enhance our communications and strategies (including by identifying when emails we sent have been received and read)-Tailor the content we display in our communications and on our Sites-Perform our agreements with Clients, if you are using the Sites on behalf of a company that has an agreement with us (e.g., your employer)

Performance of a contract; Necessary for our legitimate interests

Right
Details

Right of Access

Find out what kind of Personal Data we process about you and request details of this information, including categories of recipients to whom the Personal Data have been or will be disclosed and purposes of processing.

Right to Know

Ask us for a notice identifying the categories of Personal Data that we collect (and from whom), disclose, or share (and to whom we disclose or share), as well as our business or commercial purposes for collecting, disclosing, or selling that Personal Data. In most respects, this Policy serves as such notice.

Right to Rectify, also known as Right to Correct

Ask for your Personal Data to be rectified, updated or, corrected. We may need to verify the accuracy of the new information you provide to us.

Right to Transfer, also known as Right to Data Portability

Ask us to package up your Personal Data in a structured, commonly used and machine-readable format, so you can move, copy, or transfer it to another organization in a secure manner and without interrupting the integrity and usability of the information.

Right to Restrict or Object to Processing

Object to certain types of processing of your Personal Data, including profiling, targeted advertising, direct marketing, and statistical, scientific, or historical research purposes.

Right to not be Subject to Fully Automated Decisions

Ask to not be subject to decisions with a legal or similarly significant effect (including profiling) that are based solely on the automated processing of your Personal Data, unless you have given us your explicit consent or where necessary for the performance of a contract with us.

Right to Limit Use of Sensitive Information

Tell us to limit or stop processing your Sensitive Personal Data.

Right to Withdraw Consent at Any Time

Withdraw any consent you may have previously given us.

Right to Delete, also known as the Right to be Forgotten

Request that your Personal Data be erased. Where required, we will delete your Personal Data. We will decline your request for deletion if processing of your Personal Data is necessary: (i) for us to comply with our legal obligations; (ii) for the establishment, exercise, or defense of legal claims; (iii) for the performance of a task in the public interest, or (iv) for us to perform certain actions in accordance with applicable laws, such as detecting security incidents and protecting against fraudulent activity.

Right to Opt-Out of the Sale or Sharing of your Personal Data

Direct us not to sell your Personal Data to third parties.

California residents: You have the right to tell us not to sell or share your Personal Data to third parties. This right is referred to as the "right to opt-out of sale or sharing."

Control
Available to
Details

Account Settings

Clients

You can control some Personal Data directly within your account by editing the information entered on your profile pages.

Deleting Questions

Clients

You have control over your Actions and can delete them at any time through the Suzy platform.

Terminating Account

Clients

You may terminate your account by contacting your account manager. Within a reasonable time thereafter, we will remove the associated Personal Data.

Advertising Controls

Clients; Visitors

Some of the business partners that may collect information about your activities on our Sites may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior for purposes of targeted advertising.

  • For example, you may opt out of receiving targeted advertising through members of the Network Advertising Initiative by clicking here or the Digital Advertising Alliance by clicking here.
  • European users may opt out of receiving targeted advertising through members of the European Interactive Digital Advertising Alliance by clicking here, selecting your country, and then clicking "Choices" (or similarly-titled link).

Please note that we may also work with companies that offer their own opt-out mechanisms and may not participate in the opt-out mechanisms that we linked to above.

Marketing Emails and Service Announcements Controls

Clients; Visitors

Individuals may unsubscribe from receiving marketing or other commercial emails from us by following the instructions included in the email. However, even if an individual opts out of receiving such communications, we retain the right to send them non-marketing communications (such as notices regarding changes in our Terms and Conditions, this Privacy Policy, or the Sites). We may also send you service related email announcements on rare occasions when it is necessary to do so. For instance, if our service is temporarily suspended for maintenance, we might send you an email. You do not have an option to opt out of these emails, which are not promotional in nature.

Do Not Track signals

Clients; Visitors

"Do Not Track" is a feature enabled on some browsers that sends a signal to request that a website disable its tracking or cross-website user tracking. We treat any user-enabled global privacy controls, such as a browser plug-in or privacy setting, device setting, or other mechanism, that communicate or signal your choice to opt-out of the sale of your Personal Data as a valid request submitted pursuant to applicable privacy laws for that browser or device, or, if known, for the individual.