Please use the following links to select the Privacy Notice applicable to you:
- Privacy Notice General
- Privacy Notice for California Residents
- Privacy Notice for Virginia Residents
- Privacy Notice for EEA, UK and Swiss residents
- Data Privacy Framework program for Residents of the European Union, UK and Switzerland
Translations:
- Datenschutzerklärung (Deutsch)
- Declaración de privacidad (español)
- Politique de confidentialité (français)
- Informativa sulla privacy (italiano)
Privacy Notice General
1. CONTROLLER OF THE PERSONAL DATA
Apollo Intelligence Operating, LLC
480 Pleasant Street, Suite B100
Watertown, MA 02472
Data Protection Contact & DPO: privacy@apollointelligence.net
2. SCOPE
This Notice applies to the processing of Personal Data that AIO transfers to and stores in the United States.
We’re committed helping you understand how we manage and protect the information we collect. We take privacy seriously and have taken many steps to help safeguard the information we collect from you.
3. PERSONAL DATA THAT WE COLLECT
AIO provides research solutions to its Clients, which are predominantly business customers, and individuals that may purchase products or participate to market research activities.
- General Data: AIO collects Personal Data from individuals when they register with our website or community, request information from us and participate in market research activities.
- Communication Data: AIO may process information contained in or relating to any communication that you send to us or that we send to you. The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
- Usage data: AIO may process data about your use of our website and services. The usage data may include your IP address, geographical location, browser type, version and language, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. We may also collect and process data on the websites you visited before our sites may be logged automatically if you are redirected to our site from our advertising campaigns. The source of the usage data is our analytics tracking system, marketing automation platform or other marketing technologies.
- Market Research data: AIO might also collect personal data and anonymized and/or pseudonymized data produced by individuals’ participation to market research activities.
- Information collected: The Personal Data that we collect may vary based on your interaction with AIO. As a general matter, AIO collects the following types of Personal Data:
Data collected from our Community of Healthcare Professionals:
Category |
Examples |
Collected |
A. Personal data | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, Social Security number, or other similar identifiers, telephone number, employment |
Yes |
B. Special categories of personal data | Age (40 years or older), race, color, national origin, citizenship, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, biometric data. |
Yes |
C. Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website. |
Yes |
D. Geolocation data. | Physical location or movements. |
Yes |
E. Sensory data. | Audio, visual, or similar information. |
Yes |
F. Professional or employment-related information. | Occupation, Employer Information. |
Yes |
4. PURPOSES OF DATA PROCESSING
AIO processes Personal Data that it collects directly from individuals registered with the Healthcare Community and indirectly in its role as a service provider for the following business purposes:
- Operations: maintaining and supporting our products as well as delivering and providing the requested products/services;
- Contractual; complying with contractual obligations related thereto (including managing transactions, reporting, invoices and other operations related to providing/receiving services to/from clients and individuals). This may include data included in Category A
- Market Research: Allowing individuals to participate in market research surveys and interviews and related activities. Report back to clients results in an anonymized and aggregated form.
- Publications: In certain occasions and strictly in accordance with your express instructions, we may process your personal data for the purposes of publishing such data on our website and elsewhere through our services.
- Relationships and communications: Processing contact data for the purposes of managing our relationships and communicating with you by email and/or telephone.
- Direct marketing: Processing contact data for the purposes of creating, targeting, and sending direct marketing communications by email and making contact by telephone for marketing-related purposes. We do this for improving and facilitating your participation in market research activities.
- Research and analysis: Processing usage data for the purposes of researching and analyzing the use of our website, for example monitoring, supporting, improving, and securing our website, services and business generally. AIO has a legitimate interest in maintaining security conditions on our websites to prevent malware, or other types of attacks. Security is essential to protect the personal data of customers and visitors.
- Record keeping: Processing your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records in servers located in the United State. We do this to ensure that we have access to all the information we need to run our business properly and efficiently in accordance with this Notice.
- Legal compliance and vital interests: Processing your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or to protect your vital interests or the vital interests of another natural person.
- Required by Law: for other business-related purposes permitted or required under applicable local law and regulation for example satisfying governmental reporting, tax, crime investigation and national security; and (7) as otherwise required by law). This may include data included in Category A
- Identity Verification: We may process your personal information, including name, postal address, email address and telephone number for verifying your identity when you join our Community and prevent fraud. We use trusted Partners to assist us in conducting identity verification and fraud prevention. We might also use other information you provide us for verifying your medical credentials.
- In general: as requested by you;
5. LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA
AIO uses the following legal bases for processing your data in relation with the above identified purposes:
Legal Basis | Purposes |
Your Consent | Market research Publications Record keeping In general |
Execution of a contract to which you or your company is party or in order to take preliminary steps at your request prior to entering into a contract | Operations Contractual Relationships and communications Direct marketing |
Comply with a legal obligation to which the AIO is subject | Legal compliance and vital interests Required by Law |
Legitimate interest |
Operations |
6. SPECIAL CATEGORY OF PERSONAL DATA OR SENSITIVE DATA
AIO might process certain categories of data that can be considered very sensitive. This data may be collected when individuals participate in market research activities carried out by AIO directly or on behalf of their clients. We are committed to handle this data with extreme care and only few authorized people have access to it. Such data might include: information about your health, your ethnic origin, biometric data, trade union membership, etc. Where we process special categories of personal data, “Sensitive Personal Data,” we will always obtain your explicit consent to those activities unless:
- Consent is not required by law;
- To protect your vital interests where you are incapable of giving your consent;
- For the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity;
- Processing is necessary for reasons of public interest regarding public health as required by the local law.
Where this is allowed by law, you have the right to withdraw that consent at any time.
7. AUTOMATED DECISIONS
We reserve the right to make automated decisions, including using machine learning algorithms about website visitors to optimize and provide better experience when navigating our websites. Only digital data as specified in section VIII are included in this processing.
We may analyze your participation in our surveys with the purpose to enrich the profiling data we hold about you. The profiling data that we have collected might be used for making manual or automated decisions that involve your participation in market research activities. As results of this processing, we will be able to send you market research activities within your sphere of expertise and interest.
You may contact us if you would like any clarifications about the automated decisions.
8. DIGITAL DATA
- Cookies: AIO may set and use cookies to enhance your user experience on the sites, such as retaining your personal settings and preferences. You may set your browser to prevent or reject cookies, or you may manually delete any cookies set. If you reject the cookies on the sites, you may still be able to use the sites, but they shall be limited to certain minimal functionality. From time-to-time AIO may use third-party tracking utilities that use session ID cookies that track site usability and assist AIO in improving user experience. This Privacy Notice does not cover the use of cookies by our third-party providers as we do not have access or control over these cookies.
- We may collect information on our sites or in our emails using web beacons and or tracking pixels (electronic images). We may use beacons to count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.
- You can review the cookies used by AIO’s website here.
- Trend Analyses: AIO may use IP addresses to analyze trends, administer the Sites, to track your movement within the Sites, and to gather broad demographic information for aggregate use.
- Links to other sites: our sites include links to other websites whose privacy practices may differ from AIO’s. If you submit personal data to any of those sites, your information is governed by the privacy statements of those third-party sites.
- Managing cookies: Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
- https://support.google.com/chrome/answer/95647 (Chrome);
- https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
- https://help.opera.com/en/latest/security-and-privacy/ (Opera);
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
- https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari);
- https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
9. CHOICE WITH RESPECT TO USES AND DISCLOSURES OF PERSONAL DATA
AIO recognizes that individuals have the right to limit the use and disclosure of their Personal Data, and we are committed to respect those rights. We offer individuals the opportunity to opt out of disclosures of Personal Data to a third party or the use of Personal Data for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individual. We apply a strict policy with respect to disclosures of Sensitive Data including, when applicable, obtaining the explicit consent (i.e., opt in consent) of an individual prior to disclosing Sensitive Data to a third party or using Sensitive Data for purposes other than those for which it was originally collected or subsequently authorized by the individual.
10. DISCLOSURE/TRANSFER OF INFORMATION FOR A BUSINESS PURPOSE
- AIO may disclose your Personal Information to a third party for a business purpose. We do this by entering into a contract that describes the purpose and requires the recipient to both keep that Personal Data confidential and not use it for any purpose except performing the contract. Furthermore, third parties must comply with data protection laws and agree to provide adequate protections that are no less protective than those set out in this Notice.
- Disclosure: We may disclose your Personal Information for a business purpose to the following categories of third parties:
- Our affiliates and subsidiaries
- Service Providers and consultants
- Professional services organizations, such as auditors and law firms
- Our business partners
- Internet service providers
- Government entities
- Operating systems and platforms
- Survey hosting providers
- Identity verification and fraud prevention providers
- Rewards fulfillment providers
- SMS and video conference service providers
- Customer and panel support services
- Credit card processor
- Tax authorities
- Purposes of disclosure: AIO may disclose your personal information for the below purposes:
- Survey reporting
- Email services
- Authentication of medical licenses
- Identity verification and fraud prevention
- Offering and providing customer support
- Internal marketing campaigns for communicating new offers to our clients
- Internal marketing campaigns for improving and facilitating participation of Panel Members in market research activities
- Internal marketing engagement (e.g. newsletters )
- Honorarium processing and fulfillment
- Auditing purposes and governmental reporting
- Tax reporting
- Allowing participation in market research activities
- For complying with your requests or contract obligation we have with you
- Disclosures due to acquisition or merge: We may share your information in connection with a merger, sale of company assets, financing or acquisition of all or a portion of our business to another company, if any. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy policy.
- Anonymous information: We may also share aggregated or anonymous information that does not directly identify you. AIO may share anonymized aggregated demographic information with AIO partners.
- Other forms of disclosures: AIO also may disclose your personal data for other purposes or to other third parties when you have consented to or requested such disclosure or under the following circumstances:
- We respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims;
- We believe it is necessary to share information to investigate or prevent fraud, or to take action regarding illegal activities, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
- We transfer information about you if AIO is acquired by or merged with another company. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy notice.
- In response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Third party compliance: Such third parties must agree to use such Personal Data only for the purposes for which they have been engaged by AIO and they must either:
- Comply with the data protection laws, Data Privacy Framework principles, or another safe and secure mechanism that provides high level of protection.; or
- Agree to provide adequate protections for the Personal Data that are no less protective than those set out in this Notice.
- Liability: AIO is potentially liable in cases of onward transfers of Personal Data to third parties, such as when third parties that act as agents on our behalf process Personal Data in a manner inconsistent with applicable data protection regulations.
11. TRANSFER PERSONAL DATA OUTSIDE YOUR COUNTRY OF RESIDENCE
The third parties as described in paragraph X might be based in US or in other countries. In these instances, AIO imposes strict contractual obligations to third parties to maintain a level of protection that is equal to the protection offered by this notice.
In other instances, we may ask your consent to allow us to transfer your personal data into another country. In doing so we will provide you with full information about the transfer.
You may contact our DPO if you would like to know more about our international transfer assessment and/or copy of the transfer mechanism that we use for sharing your Personal Data outside your country of residence.
12. ANTI-SPAM
AIO maintains a strict “No-Spam” policy, which means that AIO does not intend to sell, rent or otherwise give your email address to a third-party without your consent.
13. DATA INTEGRITY, PURPOSE LIMITATION AND RETENTION
AIO will not process Personal Data in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by you. To that end, AIO will take reasonable steps to ensure that your Personal Data is reliable for its intended use, accurate, complete, and current. AIO uses reasonable efforts to maintain the accuracy and integrity of your Personal Data and to update it as appropriate.
We retain your personal data as follow:
- Contact data will be retained for a minimum period of 2 years following the date of the most recent contact between you and us, or until an updating information request or removal request is made by you;
- Communication data will be retained for a minimum period of 2 years following the date of the communication in question or until a removal request is made by you;
- Usage data will be retained for a minimum period of 2 years or until a removal request is made by you following the date of collection;
- Market research data obtained during your participation in market research activities will be kept for up to 5 years;
- In general, we do not retain your personal data for more than 2 years since your last engagement/interaction with the Company;
We may retain your information as necessary (including a longer period) to comply with our legal obligations, resolve disputes and enforce our agreements.
14. PERSONNEL ACCESS OF PERSONAL DATA
Personnel from AIO may access and use your personal data only if they are authorized to do so and only for the purpose for which they are authorized.
15. DATA SECURITY
AIO have implemented physical and technical safeguards to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alternation, or destruction. For example, electronically stored Personal Data is stored on a secure network with firewall protection, and access to AIO ‘s electronic information systems requires user authentication via password or similar means. AIO also employs access restrictions, limiting the scope of employees who have access to Customer Personal Data. Further, AIO uses secure encryption technology to protect certain categories of personal data.
Despite these precautions, no data security safeguards guarantee 100% security all of the time.
16. YOUR RIGHTS
- Right of Access: You have the right to obtain confirmation about whether your personal data is included in our databases. Upon request, AIO will provide an individual access to your personal data within the time frame dictated by the applicable data protection regulations. AIO will allow you to know what Personal Data is included in our databases and to ensure that such Personal Data is accurate and relevant for the purposes for which AIO collected the Personal Data. You may also request a copy of your data in a commonly used and machine-readable form.
- Right of Rectification: You may review your own Personal Data stored in the databases and correct, update, modify, or delete any data that is incorrect or incomplete.
- Right of Erasure: You may request to have the personal information that we have about you to be deleted from our servers. AIO will take reasonable steps, including technical measures, to comply with your request.
- Data Portability: You may request the Personal Data you provided to us in a commonly used and machine-readable form.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time, without affecting the lawfulness of our processing based on such consent before it was withdrawn, including processing related to existing contracts for our Services.
- Limitations: these rights are subject to certain limitations and exceptions including, but not limited to, when the burden or expense of providing this access would be disproportionate to the risks to your privacy in the case in question, or where the rights of persons other than you would be violated by the provision of such access. If we determine that your access should be restricted in a particular instance, we will provide you with an explanation of our determination and respond to any inquiries you may have.
17. HOW TO EXERCISE YOUR RIGHTS
You can exercise your rights by filling out the form found at https://privacyportal-fr.onetrust.com/webform/f4acdbc3-5bc6-408b-bf08-97567a2323b4/06948036-81f9-484b-b350-46e4ad8da265. You may also submit a request at privacyrequest@apollointelligence.net, reach us on toll free number 877-390-2735 or via postal mail at AIO, Attn: Compliance Department, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA
18. RESPONSE TIMING AND FORMAT
We endeavor to respond to a verifiable request within 30 days of its receipt. If we require more time (up to two extra months), we will inform you of the reason and extension period in writing.
We will deliver our written response by mail or electronically, at your option.
The response we provide will also explain the reasons we cannot comply with a verifiable request, if applicable.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Request that we can’t process: We cannot respond to your request or provide you with Personal Data if we cannot verify your identity or authority to make the request and confirm the Personal Data relates to you. Making a verifiable request does not require you to create an account with us. We will only use Personal Information provided in a verifiable request to verify your identity or authority to make the request.
Request for Personal Data: AIO will track each of the following and will provide notice to the appropriate parties under law and contract when either of the following circumstances arise:
- legally binding request for disclosure of the Personal Data by a law enforcement authority unless prohibited by law or regulation; or
- requests received from the Data Subject.
19. PROCESS TO APPEAL THE CONTROLLER’S DECISIONS
Where this is required by your State or Country law, you have the right to appeal our refusal to take action on your request as described below.
Within 15 days of the notification of our decision, you have the right to appeal an AIO’s refusal to take action on a request by contacting our Data Protection Officer via email at privacy@apollointelligence.net or via postal mail at AIO, Attn: DPO, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA. Within 60 days of the receipt of your appeal, AIO will inform you about any action taken or not taken and provide written explanation of the reasons for the decision.
If we reject your appeal, you have the right to contact your State Attorney General or the Data Protection Authority of your country of residence.
20. RESPONSIBILITIES AND MANAGEMENT
AIO has designated the Privacy & Compliance Department to oversee its information security program, including its compliance with the Data Privacy Framework program and the GDPR and any other applicable Privacy Law. The Privacy & Compliance Department shall review and approve any material changes to this program as necessary. Any questions, concerns, or comments regarding this Notice also may be directed to: privacy@apollointelligence.net
California Residents
1. Controller of the Personal Data:
Apollo Intelligence Operating, LLC, Inc
480 Pleasant Street, Suite B100
Watertown, MA 02472
AIO Data Protection Contact & DPO: privacy@incrowdnow.com
2. SCOPE
This Notice applies to the processing of Personal Information that AIO transfers to and stores in the United States.
We’re committed to helping you understand how we manage and protect the information we collect. We take privacy seriously and have taken many steps to help safeguard the information we collect from you.
3. CATEGORY OF PERSONAL DATA AND PURPOSES OF PROCESSING
AIO collects personal data of the members of its community of respondents and non-members who participate in market research activities sponsored by Apollo’s clients. We disclose below the categories of personal data we process and the purposes:
- Registration with our Community: AIO collects Personal Data of individuals when they register with our website or community. This may include:
-
- Personal Information: name, surname, age, telephone number, email address, postal address.
- Professional information: medical specialty, your practice/institution name and address your NPIs or medical association number, and years in practice.
- Transaction history: the amount of incentives you have earned and redeemed
- Other information: specific information that we derived from your participation in market research activities. We only use the data provided to allow your participation in market research activities
We may use some of the data of our Community in aggregate for statistical reasons.
- Identity verification: As part of the registration process to our Community, you will be required to pass an identity check verification. The process may involve the scan of your national identification document and a picture of yourself. This process may also include Biometric data (e.g. facial images) is processed during the identity check. Identity validation will also include review of publicly available data associated with your name, address, email address and may also include the prompt of security questions. The identity verification provider will process your personal information in accordance with their privacy policy and you will have the opportunity to review their privacy policy before providing your consent. We have the legitimate interest to use the information provided by the identity verification provider for identity and fraud prevention.
- Professional background checks: In order to verify that you are a qualified and in practice healthcare professional, we might contact your working institution, checking your name, NPI, state license number or your medical association number against public registries or third parties’ databases. We have the legitimate interest to verify your professional background for the identity verification provider for identity and fraud prevention.
- Tax Report: As a US based company, Apollo reports the incentives received by the market research participants to the US federal tax authority. Apollo is required by US law to collect your personal information via the W9 form for US citizens and via
- Market research activities: During market research activities, Apollo may collect personal information related to member and not-member participation. This can include your answers to a survey or audio or/and video recordings of a market research interview. If you are not a member of the Apollo Community, we may also need to collect certain personal information for incentive fulfillment purposes as explained below. Before your participation in each market research activity, you will be informed about study requirements and you will be asked to provide your consent.
- Incentives fulfillment: Apollo processes your personal data for compensating you for the market research activities you complete. Depending on the type of compensation you select we may process different types of personal information. This could just be your full name and email address or your bank account number or IBAN.
- Relationship Communication Data: Processing contact data for the purposes of managing our relationships and communicating with you (excluding communicating for the purposes of direct marketing) by email and/or telephone. We may process personal information contained in or relating to any communication that you send to us or that we send to you. The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
- Usage data: AIO may process data about your use of our website and services. The usage data may include your IP address, geographical location, browser type, version and language, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. We may also collect and process data on the websites you visited before our sites that may be logged automatically if you are redirected to our site from our advertising campaigns. The source of the usage data is our analytics tracking system, marketing automation platform or other marketing technologies. You might find more information in our Cookie Policy below.
- Publications: In certain occasions and strictly in accordance with your express instructions, we may process your personal data for the purposes of publishing such data on our website and elsewhere through our services.
- Direct marketing: Processing contact data for the purposes of creating, targeting, and sending direct marketing communications by email and making contact by telephone for marketing-related purposes. We do this to improve and facilitate your participation in market research activities.
- Record keeping: Processing your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records in servers located in the United States. We do this to ensure that we have access to all the information we need to run our business properly and efficiently in accordance with this Notice.
- Vital interests: Processing your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or in order to protect your vital interests or the vital interests of another natural person.
- Legal: Required by Law: for other business-related purposes permitted or required under applicable local law and regulation for example satisfying governmental transparency reporting, tax, crime investigation and national security; and as otherwise required by law.
- Information collected: The Personal Data that we collect may vary based on your interaction with AIO. As a general matter, AIO collects the following types of Personal Data:
Data collected from individuals in accordance with CPRA:
Category | Examples | Collected |
A. Identifiers. | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, Social Security number, or other similar identifiers. | Yes |
B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)). | A name, signature, Social Security number, address, telephone number, employment, or medical information., Some personal information included in this category may overlap with other categories. | Yes |
C. Protected classification characteristics under California or federal law. | Age (40 years or older), race, color, national origin, citizenship, , marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation. | Yes |
D. Commercial information | Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies | No |
E. Biometric information | individual’s physiological, biological, or behavioral characteristics, including an individual’s deoxyribonucleic acid (DNA), that can be used, singly or in combination with each other or with other identifying data, to establish individual identity. Biometric information includes, but is not limited to, imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information. | No |
F. Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website. | Yes |
G. Geolocation data. | Physical location or movements. | Yes |
H. Sensory data. | Audio, visual, or similar information. | Yes |
I. Professional or employment-related information. | Occupation, Employer Information. | Yes |
J. Education information | Education information, defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g; 34 C.F.R. Part 99) | No |
K. Profiling | Inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | No |
L. Sensitive Personal Information | Personal information that reveals: A consumer’s social security, driver’s license, state identification card, or passport number.
A consumer’s account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account. A consumer’s precise geolocation. A consumer’s racial or ethnic origin, religious or philosophical beliefs, or union membership. The contents of a consumer’s mail, email, and text messages unless the business is the intended recipient of the communication. A consumer’s genetic data. (A) The processing of biometric information for the purpose of uniquely identifying a consumer. (B) Personal information collected and analyzed concerning a consumer’s health. (C) Personal information collected and analyzed concerning a consumer’s sex life or sexual orientation. |
Yes |
4. SENSITIVE PERSONAL INFORMATION
AIO might process certain categories of data that under the CPRA is considered very sensitive. This data may be collected when individuals participate to market research activities carried out by AIO directly or on behalf of their clients. We are committed to handling this data with extreme care and only a few authorized people have access to it. Such data might include: information about your health, your ethnic origin, biometric data, etc. Where we process Sensitive Personal Information data, we will always obtain your explicit consent to those activities unless:
- Consent is not required by law;
- To protect your vital interests where you are incapable of giving your consent;
- For the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity;
- Processing is necessary for reasons of public interest in the area of public health as required by the local law.
5. AUTOMATED DECISIONS
- We reserve the right to make automated decisions, including using machine learning algorithms about and website visitors in order to optimize the products and services offered and/or delivered. You may contact us if you would like any clarifications about the automated decisions.
- We might analyze your participation to our surveys with the purpose to enrich the profiling data we hold about yourself. The profiling data that we have collected might be used for making manual or automated decisions that involve your participation to market research activities. As results of this processing, we will be able to send you market research activities within your sphere of expertise and interest.
- You have the right to opt-out from automated decisions at any time. However, be advised that if you exercise this right, it may affect our ability to offer you survey opportunities and to maintain your membership in our network.
- You may contact us if you would like any clarifications about the automated decisions.
6. DIGITAL FINGERPRINT
- Cookies: AIO may set and use cookies to enhance your user experience on the sites, such as retaining your personal settings and preferences. You may set your browser to prevent or reject cookies, or you may manually delete any cookies set. If you reject the cookies on the sites, you may still be able to use the sites, but they shall be limited to certain minimal functionality. From time to time AIO may use third-party tracking utilities that use session ID cookies that track site usability and assist AIO in improving user experience. This Privacy Notice does not cover the use of cookies by our third party providers as we do not have access or control over these cookies.
- We may collect information on our sites or in our emails using web beacons and or tracking pixels (electronic images). We may use beacons to count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.
- You can review the cookies used by AIO’s website here.
- Trend Analyses: AIO may use IP addresses to analyze trends, administer the Sites, track Your movement within the Sites, and gather broad demographic information for aggregate use.
- Links to other sites: our sites include links to other websites whose privacy practices may differ from AIO’s. If you submit personal data to any of those sites, your information is governed by the privacy statements of those third-party sites.
- Managing cookies: Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
- https://support.google.com/chrome/answer/95647 (Chrome);
- https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
- https://help.opera.com/en/latest/security-and-privacy/ (Opera);
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
- https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari);
- https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
7. CHOICE WITH RESPECT TO USES AND DISCLOSURES OF PERSONAL INFORMATION
AIO recognizes that individuals have the right to limit the use and disclosure of their Personal Information, and we are committed to respecting those rights. We apply a strict policy with respect to disclosures of Sensitive Personal Information including, when applicable, obtaining the explicit consent (i.e., opt in consent) of an individual prior to disclosing Sensitive Personal Information to a third party or using Sensitive Personal Information for purposes other than those for which it was originally collected or subsequently authorized by the individual.
8. SALE OR SHARE OF INFORMATION FOR A BUSINESS PURPOSE
AIO has not shared or disclosed any categories of Personal Information for a business purpose in the last 12 months.
9. DISCLOSURE/TRANSFER OF INFORMATION FOR A BUSINESS PURPOSE
- AIO may disclose your Personal Information to a third party for a business purpose. We do this by entering into a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract or as required by the law. Furthermore, service providers must comply with any privacy state of federal law and agree to provide adequate protections that are no less protective than those set out in this Notice.
- AIO may have disclosed the following categories of Personal Information for a business purpose in the last 12 months. Please see the table included in section III for more information about the categories of personal information:
- Category A: Identifiers
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)).
- Category C: Protected classification characteristics under California or federal law.
- Category F: Internet or other similar network activity.
- Category G: Geolocation data.
- Category H: Sensory data.
- Category I: Professional or employment-related information.
- Disclosure: We may have disclosed your Personal Information for a business purpose to the following categories of third parties:
- Our affiliates and subsidiaries
- Service Providers and consultants
- Professional services organizations, such as auditors and law firms
- Our business partners
- Internet service providers
- Government entities
- Operating systems and platforms
- Survey hosting providers
- Identity verification and fraud prevention providers
- Rewards fulfillment providers
- SMS and video conference service providers
- Customer and panel support services
- Credit card processor
- Tax authorities
- Purposes of disclosure: We may have disclosed your Personal Information for the below purposes:
- Survey reporting
- Email services
- Authentication of medical licenses
- Identity verification and fraud prevention
- Offering and providing customer support
- Internal marketing campaigns for improving and facilitating participation of Panel Members in market research activities
- Internal marketing engagement e.g. newsletters
- Honorarium processing and fulfillment
- Auditing purposes and governmental reporting
- Tax reporting
- Allowing participation in market research activities
- For complying with your requests or contract obligation we have with you
- Other forms of disclosures: AIO also may disclose your Personal Information for other purposes or to other third parties when you have consented to or requested such disclosure or under the following circumstances:
- We respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims;
- We believe it is necessary to share information in order to investigate or prevent fraud, or to take action regarding illegal activities, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
- We transfer information about you if AIO is acquired by or merged with another company. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy notice.
- In response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Deidentified information: We may also share aggregated or anonymous information that does not directly identify you. AIO may share anonymized aggregated demographic information with AIO partners.
- Liability: AIO is potentially liable in cases of onward transfers of Personal Information to service providers, that, acting as agents on our behalf, process Personal Information in a manner inconsistent with applicable data protection regulations.
10. DISCLOSURE/TRANSFER OF PERSONAL INFORMATION OUTSIDE US
The Service providers as described in section 9 might be based in US or in other countries. In these instances, AIO imposes strict contractual obligations with third parties to maintain a level of protection that is equal to the state or federal law and in line with the terms of this Notice.
In other instances, we may ask your consent to allow us to transfer your Personal Information into another country. In doing so we will provide you with full information about the transfer.
You may contact our DPO if you would like to know more about our international transfer assessment and/or copy of the transfer mechanism that we use for sharing your Personal Information outside your country of residence.
11. ANTI-SPAM
AIO maintains a strict “No-Spam” policy, which means that AIO does not intend to sell, rent or otherwise give your email address to a third-party without your consent.
12. DATA INTEGRITY, PURPOSE LIMITATION AND RETENTION
- AIO will not process Personal Information in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by you. To that end, AIO will take reasonable steps to ensure that your Personal Information is reliable for its intended use, accurate, complete, and current. AIO uses reasonable efforts to maintain the accuracy and integrity of your Personal Information and to update it as appropriate.
- Data deletion and retention: We delete your account and the personal data you provided as part of the registration process when:
-
- You submit a deletion request and we are not subjected to a legal obligation to maintain your personal data
- We may delete an account and the data included on it after a long period of member’s inactivity and when the data is no longer necessary respect to the purposes for which it was collected.
We retain your personal data as follow:
-
- Market research data obtained during your participation in market research activities will be kept for up to 5 years;
- Incentive fulfillment data including your W8 and W9 will be kept for 7 years in accordance with the US federal law.
We may retain your information as necessary (including a longer period) to comply with our legal obligations, resolve disputes and enforce our agreements
13. PERSONNEL ACCESS TO PERSONAL INFORMATION
Personnel from AIO may access and use your Personal Information only if they are authorized to do so and only for the purpose for which they are authorized.
14. DATA SECURITY
AIO has implemented physical and technical safeguards to protect Personal Information from loss, misuse, and unauthorized access, disclosure, alternation, or destruction. For example, electronically stored Personal Information is stored on a secure network with firewall protection, and access to AIO ‘s electronic information systems requires user authentication via password or similar means. AIO also employs access restrictions, such as limiting the scope of employees who have access to Customer Personal Information. Further, AIO uses secure encryption technology to protect certain categories of personal data.
Despite these precautions, no data security safeguards guarantee 100% security all of the time.
15. YOUR RIGHTS AND CHOICES
Pursuant to the CCPA/CPRA and subject to certain exceptions and limitations, California residents may contact us to exercise their rights with respect to certain Personal Information that we hold about them. To the extent these rights may apply to you, they are described below.
- Right to Know and Access your Personal Information Collected or Disclosed. You have the right to request that we provide you with details about the Personal Information we collect, use and disclose. You can submit your request as described in section 16, and we reserve the right to conduct the verification described. In connection with this request, you are entitled to receive the following:
- The categories of your Personal Information that we have collected
- The categories of sources from which that Personal Information was collected
- The business/commercial purpose for the collection or selling or sharing personal information
- The categories of third parties to whom we disclose Personal Information
- The specific pieces of Personal Information we have collected about you (subject to some exceptions)
- If we have disclosed, sold or shared (as those words are defined in the CCPA and CPRA) Personal Information to third parties, you are also entitled to receive:
- The categories of Personal Information that we have collected about you.
- The categories of Personal Information that we have sold or shared about you and the categories of third parties to whom the personal information was sold or shared, by category or categories of Personal Information for each category of third parties to whom the Personal Information was sold or shared.
- The categories of Personal Information that we have disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
- Right to Delete Personal Information. You have the right to request deletion of the Personal Information we have collected about you (subject to some exceptions). You can submit your request as described in section 16, and we reserve the right to conduct the verification described.
- We may deny your deletion request if retaining the information is necessary for us or our service providers to:
- Complete the transaction for which we collected the Personal Information, provide a service that you requested, or take actions reasonably anticipated within the context of our ongoing business relationship with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code 1546 seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research that conforms or adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Right to Correct Inaccurate Personal Information . You may request the correction of inaccurate Personal Information processed by AIO, and update or modify any Personal Data that is incorrect or incomplete. You may also notify us by using the contacts in section 16 to correct any inaccurate personal information we have about you.
- Right to No Retaliation following the Exercise of a Consumer’s Privacy Rights. We will not discriminate against you for exercising any of your CCPA/CPRA rights. Unless permitted by the law, we will not:
- Deny you use of our services.
- Provide you a different level or quality of services.
- Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services
- Retaliate against an employee, applicant for employment, or independent contractor for exercising their rights under this title.
- Right to Limit Use and Disclosure of Sensitive Personal Information. You have the right to limit the use and disclosure of your Sensitive Personal Information to that use which is necessary to perform our services.
16. HOW TO EXERCISE YOUR RIGHTS AND IDENTITY VERIFICATION
- You can exercise your rights by filling out the form found at https://privacyportal-fr.onetrust.com/webform/f4acdbc3-5bc6-408b-bf08-97567a2323b4/06948036-81f9-484b-b350-46e4ad8da265. You may also submit a request at privacyrequest@apollointelligence.net, reach us on toll free number 877-390-2735 or via postal mail at AIO, Attn: Compliance Department, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA
- Only you or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable request related to your Personal Information.
- As part of this process, we may ask to verify your identity. Your request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative;
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
- We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable request does not require you to create an account with us. We will only use Personal Information provided in a verifiable request to verify your identity or authority to make the request.
17. RESPONSE TIMING AND FORMAT
We endeavor to respond to a verifiable request within 45 days of its receipt. If we require more time up to 45 more days, for a total of 90 days from the receipt, we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding receipt of a verifiable request if your data has been collected before January 1, 2022. The response we provide will also explain the reasons we cannot comply with a verifiable request, if applicable.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
18. RESPONSIBILITIES AND MANAGEMENT
AIO has designated the Privacy and Compliance Department to oversee its information security program, including its compliance with the Data Privacy Framework program. The Privacy and Compliance Department shall review and approve any material changes to this program as necessary. Any questions, concerns, or comments regarding this Notice also may be directed to privacy@apollointelligence.net.
19. CHANGE TO THIS NOTICE
This Notice may be amended from time to time, consistent with applicable data protection and privacy laws and principles. We will notify Members if we make changes that materially affect the way we handle Personal Information previously collected, and we will allow them to choose whether their Personal Information may be used in any materially different manner.
Virginia Residents
1. Controller of the Personal Data:
Apollo Intelligence Operating, LLC
480 Pleasant Street, Suite B100, Watertown, MA 02472
AIO Data Protection Contact & DPO: privacy@apollointelligence.net
2. SCOPE
Pursuant to the Virginia Consumer Data Protection Act (CDPA) AIO as adopted this Privacy Notice.
We’re committed to helping you understand how we manage and protect the information we collect. We take privacy seriously and have taken many steps to help safeguard the information we collect from you.
This Privacy Notice was established in January 2023.
3. CATEGORY OF PERSONAL DATA AND PURPOSES OF PROCESSING
AIO collects personal data of the members of its community of respondents and non-members who participate in market research activities sponsored by Apollo’s clients. We disclose below the categories of personal data we process and the purposes:
- Registration with our Community: AIO collects Personal Data of individuals when they register with our website or community. This may include:
-
- Personal Information: name, surname, age, telephone number, email address, postal address.
- Professional information: medical specialty, your practice/institution name and address your NPIs or medical association number, and years in practice.
- Transaction history: the amount of incentives you have earned and redeemed
- Other information: specific information that we derived from your participation in market research activities. We only use the data provided to allow your participation in market research activities
We may use some of the data of our Community in aggregate for statistical reasons.
- Identity verification: As part of the registration process to our Community, you will be required to pass an identity check verification. The process may involve the scan of your national identification document and a picture of yourself. This process may also include Biometric data (e.g. facial images) is processed during the identity check. Identity validation will also include review of publicly available data associated with your name, address, email address and may also include the prompt of security questions. The identity verification provider will process your personal information in accordance with their privacy policy and you will have the opportunity to review their privacy policy before providing your consent. We have the legitimate interest to use the information provided by the identity verification provider for identity and fraud prevention.
- Professional background checks: In order to verify that you are a qualified and in practice healthcare professional, we might contact your working institution, checking your name, NPI, state license number or your medical association number against public registries or third parties’ databases. We have the legitimate interest to verify your professional background for the identity verification provider for identity and fraud prevention.
- Tax Report: As a US based company, Apollo reports the incentives received by the market research participants to the US federal tax authority. Apollo is required by US law to collect your personal information via the W9 form for US citizens and via
- Market research activities: During market research activities, Apollo may collect personal information related to member and not-member participation. This can include your answers to a survey or audio or/and video recordings of a market research interview. If you are not a member of the Apollo Community, we may also need to collect certain personal information for incentive fulfillment purposes as explained below. Before your participation in each market research activity, you will be informed about study requirements and you will be asked to provide your consent.
- Incentives fulfillment: Apollo processes your personal data for compensating you for the market research activities you complete. Depending on the type of compensation you select we may process different types of personal information. This could just be your full name and email address or your bank account number or IBAN.
- Relationship Communication Data: Processing contact data for the purposes of managing our relationships and communicating with you (excluding communicating for the purposes of direct marketing) by email and/or telephone. We may process personal information contained in or relating to any communication that you send to us or that we send to you. The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
- Usage data: AIO may process data about your use of our website and services. The usage data may include your IP address, geographical location, browser type, version and language, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. We may also collect and process data on the websites you visited before our sites that may be logged automatically if you are redirected to our site from our advertising campaigns. The source of the usage data is our analytics tracking system, marketing automation platform or other marketing technologies. You might find more information in our Cookie Policy below.
- Publications: In certain occasions and strictly in accordance with your express instructions, we may process your personal data for the purposes of publishing such data on our website and elsewhere through our services.
- Direct marketing: Processing contact data for the purposes of creating, targeting, and sending direct marketing communications by email and making contact by telephone for marketing-related purposes. We do this to improve and facilitate your participation in market research activities.
- Record keeping: Processing your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records in servers located in the United States. We do this to ensure that we have access to all the information we need to run our business properly and efficiently in accordance with this Notice.
- Vital interests: Processing your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or in order to protect your vital interests or the vital interests of another natural person.
- Legal: Required by Law: for other business-related purposes permitted or required under applicable local law and regulation for example satisfying governmental transparency reporting, tax, crime investigation and national security; and as otherwise required by law.
- Information collected: The Personal Data that we collect may vary based on your interaction with AIO. As a general matter, AIO collects the following types of Personal Data:
Data collected from individuals:
Category |
Examples |
Collected |
A. Personal Data. | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, Social Security number, or any information that is linked or reasonably linkable to an identified or identifiable natural person. | Yes |
B. Sensitive data | Data that includes race, color, national origin, citizenship, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, biometric data.
Geolocation data |
Yes |
C. Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website. | Yes |
D. Professional or employment-related information. | Occupation, Employer Information. | Yes |
E. Profiling | Means any form of automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. | Yes |
4. SENSITIVE PERSONAL INFORMATION
AIO might process certain categories of data that under the CDPA is considered very sensitive. This data may be collected when individuals participate to market research activities carried out by AIO directly or on behalf of their clients. We are committed to handling this data with extreme care and only few authorized people have access to it. Such data might include: information about your health, your ethnic origin, biometric data, etc. Where we process sensitive personal information data, we will always obtain your explicit consent to those activities unless:
- Consent is not required by law;
- To protect your vital interests where you are incapable of giving your consent;
- For the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity;
5. AUTOMATED DECISIONS
We reserve the right to make automated decisions, including using machine learning algorithms about and website visitors in order to optimize the products and services offered and/or delivered. You may contact us if you would like any clarifications about the automated decisions.
We might analyze your participation to our surveys with the purpose to enrich the profiling data we hold about yourself. The profiling data that we have collected might be used for making manual or automated decisions that involve your participation to market research activities. As results of this processing, we will be able to send you market research activities within your sphere of expertise and interest.
You have the right to opt-out from automated decisions at any time. However, be advised that if you exercise this right, it may affect our ability to offer you survey opportunities and to maintain your membership in our network.
You may contact us if you would like any clarifications about the automated decisions.
6. DIGITAL FINGERPRINT
- Cookies: AIO may set and use cookies to enhance your user experience on the sites, such as retaining your personal settings and preferences. You may set your browser to prevent or reject cookies, or you may manually delete any cookies set. If you reject the cookies on the sites, you may still be able to use the sites, but they shall be limited to certain minimal functionality. From time to time AIO may use third-party tracking utilities that use session ID cookies that track site usability and assist AIO in improving user experience. This Privacy Notice does not cover the use of cookies by our third party providers as we do not have access or control over these cookies.
- We may collect information on our sites or in our emails using web beacons and or tracking pixels (electronic images). We may use beacons to count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.
- AIO uses cookies for the following purposes: see our Cookie Policy for details
- Trend Analyses: AIO may use IP addresses to analyze trends, administer the Sites, track Your movement within the Sites, and gather broad demographic information for aggregate use.
- Links to other sites: our sites include links to other websites whose privacy practices may differ from AIO’s. If you submit personal data to any of those sites, your information is governed by the privacy statements of those third-party sites.
- Managing cookies: Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
- https://support.google.com/chrome/answer/95647 (Chrome);
- https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
- https://help.opera.com/en/latest/security-and-privacy/ (Opera);
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
- https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari);
- https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
7. SALE OF INFORMATION FOR A BUSINESS PURPOSE
AIO does not sell any categories of Personal Information for a business purpose in accordance with CDPA.
8. TRANSFER OF INFORMATION FOR A BUSINESS PURPOSES
AIO might transfer personal information for business purposes by entering into a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract or as required by the law. Furthermore, service providers must comply with any privacy state of federal law and agree to provide adequate protections that are no less protective than those set out in this Notice.
- AIO may transfer the following categories of Personal Information for a business purpose. Please see the table included in section 3 for more information about the categories of personal information:
- Category A
- Category B
- Category C
- Category D
- Category E
- Transfer: We may have transfer your Personal Information for a business purpose to the following categories of third parties:
- Our affiliates and subsidiaries
- Service Providers and consultants
- Professional services organizations, such as auditors and law firms
- Our business partners
- Internet service providers
- Government entities
- Operating systems and platforms
- Survey hosting providers
- Identity verification and fraud prevention providers
- Rewards fulfillment providers
- SMS and video conference service providers
- Customer and panel support services
- Credit card processor
- Tax authorities
- Purposes of disclosure: We may have disclosed your personal information for the below purposes:
- Survey reporting
- Email services
- Authentication of medical licenses
- Identity verification and fraud prevention
- Offering and providing customer support
- Internal marketing campaigns for improving and facilitating participation of Panel Members in market research activities
- Internal marketing engagement e.g. newsletters
- Honorarium processing and fulfillment
- Auditing purposes and governmental reporting
- Tax reporting
- Allowing participation in market research activities
- For complying with your requests or contract obligation we have with you
- Other forms of disclosures: AIO also may disclose your personal data for other purposes or to other third parties when you have consented to or requested such disclosure or under the following circumstances:
- We respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims;
- We believe it is necessary to share information in order to investigate or prevent fraud, or to take action regarding illegal activities, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
- We transfer information about you if AIO is acquired by or merged with another company. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy notice.
- In response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Deidentified information: We may also share aggregated or anonymous information that does not directly identify you. AIO may share anonymized aggregated demographic information with AIO partners.
- Liability: AIO is potentially liable in cases of onward transfers of Personal Data to service providers that, acting as agents on our behalf, process Personal Data in a manner inconsistent with applicable data protection regulations.
9. DISCLOSURE/TRANSFER OF PERSONAL DATA OUTSIDE US
The Service providers as described in section 8 might be based in US or in other countries. In these instances, AIO imposes strict contractual obligations with third parties to maintain a level of protection that is equal to the state or federal law and in line with the terms of this Notice.
In other instances, we may ask your consent to allow us to transfer your personal data into another country. In doing so we will provide you with full information about the transfer.
10. ANTI-SPAM
AIO maintains a strict “No-Spam” policy, which means that AIO does not intend to sell, rent or otherwise give your email address to a third-party without your consent.
11. DATA INTEGRITY, PURPOSE LIMITATION AND RETENTION
- AIO will not process Personal Data in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by you. To that end, AIO will take reasonable steps to ensure that your Personal Data is reliable for its intended use, accurate, complete, and current. AIO uses reasonable efforts to maintain the accuracy and integrity of your Personal Data and to update it as appropriate.
- Data deletion and retention: We delete your account and the personal data you provided as part of the registration process when:
-
- You submit a deletion request and we are not subjected to a legal obligation to maintain your personal data
- We may delete an account and the data included on it after a long period of member’s inactivity and when the data is no longer necessary respect to the purposes for which it was collected.
We retain your personal data as follow:
-
- Market research data obtained during your participation in market research activities will be kept for up to 5 years;
- Incentive fulfillment data including your W8 and W9 will be kept for 7 years in accordance with the US federal law.
We may retain your information as necessary (including a longer period) to comply with our legal obligations, resolve disputes and enforce our agreements.
12. PERSONNEL ACCESS OF PERSONAL DATA
Personnel from AIO may access and use your personal data only if they are authorized to do so and only for the purpose for which they are authorized.
13. DATA SECURITY
AIO has implemented physical and technical safeguards to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alternation, or destruction. For example, electronically stored Personal Data is stored on a secure network with firewall protection, and access to AIO ‘s electronic information systems requires user authentication via password or similar means. AIO also employs access restrictions, such as limiting the scope of employees who have access to Customer Personal Data. Further, AIO uses secure encryption technology to protect certain categories of personal data.
Despite these precautions, no data security safeguards guarantee 100% security all of the time.
14. YOUR RIGHTS AND CHOICES
Pursuant to the Virginia Consumer Data Protection Act (CDPA) and subject to certain exceptions and limitations, Virginia residents may contact us to exercise their rights with respect to certain Personal Information that we hold about them. To the extent these rights may apply to you, they are described below.
- Right to Know and Access: You have the right to obtain confirmation about whether your Personal Data is being processed by AIO and to access it.
- Right to Correct Inaccuracies: You may correct inaccuracies of your Personal Data, taking into account the nature of the personal data and the purposes of the processing. You may ask us to review your own Personal Data processed by us and correct, update, modify, or delete any data that is incorrect or incomplete.
- Right to Deletion: You may request to have your Personal Data and the Personal Data obtained about you deleted.
- Right to Obtain a Copy: You may request a copy of your Personal Data previously provided to AIO in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the Personal Data to another controller without hindrance, as the processing is carried out by automated means.
- Right to Opt-out: You have the right to request to opt-out the processing of your Personal Data from:
- Targeted advertisement
- Sale of personal data
- Profiling in furtherance of decisions that produce legal or similar effects concerning you
- Right to Avoid Discrimination: AIO will not discriminate against you for exercising any of your consumer rights, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to you. Even if AIO does not process your personal information for the above purposes, you still have the opportunity to submit a request to opt-out.
15. IDENTIFICATION OF THE DATA SUBJECT
We cannot respond to your request or provide you with Personal Information if we cannot authenticate your request using commercially reasonable efforts; we will take the necessary steps to verify your identity and the request. Making a verifiable request does not require you to create an account with us. We will only use Personal Information provided in a verifiable request to verify your identity or authority to make the request.
16. HOW TO EXERCISE YOUR RIGHTS
You can exercise your rights by filling out the form found at https://privacyportal-fr.onetrust.com/webform/f4acdbc3-5bc6-408b-bf08-97567a2323b4/06948036-81f9-484b-b350-46e4ad8da265. You may also submit a request at privacyrequest@apollointelligence.net, reach us on toll free number 877-390-2735 or via postal mail at AIO, Attn: Compliance Department, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA
17. RESPONSE TIMING AND FORMAT
We endeavor to respond to a verifiable rights request within 45 days of its receipt. If we require more time, up to 45 more days, for a total of 90 days from the receipt of your initial request, due to the complexity/number of your requests, we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option.
If we determine that we can’t comply with your request, we will explain the reasons for declining to take actions and instruction for how to appeal our decision.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
18. PROCESS TO APPEAL THE CONTROLLER’S DECISIONS
Within 15 days of the notification of our decision, you have the right to appeal an AIO’s refusal to take action on a request by contacting our Data Protection Officer via email at privacy@apollointelligence.net or via postal mail at AIO, Attn: DPO, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA. Within 60 days of the receipt of your appeal, AIO will inform you about any action taken or not taken and provide written explanation of the reasons for the decision.
If we reject your appeal, you have the right to contact the Virginia Attorney General: https://www.oag.state.va.us/.
19. RESPONSIBILITIES AND MANAGEMENT
AIO has designated the Privacy and Compliance Department to oversee its information security program, including its compliance with the Data Privacy Framework program. The Privacy and Compliance Department shall review and approve any material changes to this program as necessary. Any questions, concerns, or comments regarding this Notice also may be directed to privacy@apollointelligence.net.
20. CHANGE TO THIS NOTICE
This Notice may be amended from time to time, consistent with applicable data protection and privacy laws and principles. We will notify Members if we make changes that materially affect the way we handle Personal Information previously collected, and we will allow them to choose whether their Personal Information may be used in any materially different manner.
Privacy Notice for EEA, UK and Swiss Residents
1. CONTROLLER OF THE PERSONAL DATA
Apollo Intelligence Operating, LLC
480 Pleasant Street, Suite B100
Watertown, MA 02472
UK Data Protection Representative: Matt Higgins, VP Business Development United Kingdom UKDataProtectionRepresentative@apollointelligence.net.
EU Data Protection Representative: Fabio Musumeci, Privacy and Compliance Director, Apollo Intelligence Operating, LLC: EUDataProtectionRepresentative@apollointelligence.net.
DPO Contact: privacy@apollointelligence.net
2. SCOPE
This Notice applies to the processing of Personal Data that AIO transfers to and stores in the United States.
We’re committed to helping you understand how we manage and protect the information we collect. We take privacy seriously and have taken many steps to help safeguard the information we collect from you.
This Privacy Notice was established in October 2022.
3. CATEGORY OF PERSONAL DATA AND PURPOSES OF PROCESSING
AIO collects personal data of the members of its community of respondents and non-members who participate in market research activities sponsored by Apollo’s clients. We disclose below the categories of personal data we process and the purposes:
- Registration with our Community: AIO collects Personal Data of individuals when they register with our website or community. This may include:
-
- Personal Information: name, surname, age, telephone number, email address, postal address.
- Professional information: medical specialty, your practice/institution name and address your NPIs or medical association number, and years in practice.
- Transaction history: the amount of incentives you have earned and redeemed
- Other information: specific information that we derived from your participation in market research activities. We only use the data provided to allow your participation in market research activities
We may use some of the data of our Community in aggregate for statistical reasons.
- Identity verification: As part of the registration process to our Community, you will be required to pass an identity check verification. The process may involve the scan of your national identification document and a picture of yourself. This process may also include Biometric data (e.g. facial images) is processed during the identity check. Identity validation will also include review of publicly available data associated with your name, address, email address and may also include the prompt of security questions. The identity verification provider will process your personal information in accordance with their privacy policy and you will have the opportunity to review their privacy policy before providing your consent. We have the legitimate interest to use the information provided by the identity verification provider for identity and fraud prevention.
- Professional background checks: In order to verify that you are a qualified and in practice healthcare professional, we might contact your working institution, checking your name, NPI, state license number or your medical association number against public registries or third parties’ databases. We have the legitimate interest to verify your professional background for the identity verification provider for identity and fraud prevention.
- Tax Report: As a US based company, Apollo reports the incentives received by the market research participants to the US federal tax authority. Apollo is required by US law to collect your personal information via the W9 form for US citizens and via
- Market research activities: During market research activities, Apollo may collect personal information related to member and not-member participation. This can include your answers to a survey or audio or/and video recordings of a market research interview. If you are not a member of the Apollo Community, we may also need to collect certain personal information for incentive fulfillment purposes as explained below. Before your participation in each market research activity, you will be informed about study requirements and you will be asked to provide your consent.
- Incentives fulfillment: Apollo processes your personal data for compensating you for the market research activities you complete. Depending on the type of compensation you select we may process different types of personal information. This could just be your full name and email address or your bank account number or IBAN.
- Relationship Communication Data: Processing contact data for the purposes of managing our relationships and communicating with you (excluding communicating for the purposes of direct marketing) by email and/or telephone. We may process personal information contained in or relating to any communication that you send to us or that we send to you. The communication data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms.
- Usage data: AIO may process data about your use of our website and services. The usage data may include your IP address, geographical location, browser type, version and language, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. We may also collect and process data on the websites you visited before our sites that may be logged automatically if you are redirected to our site from our advertising campaigns. The source of the usage data is our analytics tracking system, marketing automation platform or other marketing technologies. You might find more information in our Cookie Policy below.
- Publications: In certain occasions and strictly in accordance with your express instructions, we may process your personal data for the purposes of publishing such data on our website and elsewhere through our services.
- Direct marketing: Processing contact data for the purposes of creating, targeting, and sending direct marketing communications by email and making contact by telephone for marketing-related purposes. We do this to improve and facilitate your participation in market research activities.
- Record keeping: Processing your personal data for the purposes of creating and maintaining our databases, back-up copies of our databases and our business records in servers located in the United States. We do this to ensure that we have access to all the information we need to run our business properly and efficiently in accordance with this Notice.
- Vital interests: Processing your personal data where such processing is necessary for compliance with a legal obligation to which we are subject or in order to protect your vital interests or the vital interests of another natural person.
- Legal: Required by Law: for other business-related purposes permitted or required under applicable local law and regulation for example satisfying governmental transparency reporting, tax, crime investigation and national security; and as otherwise required by law.
- Information collected: The Personal Data that we collect may vary based on your interaction with AIO. As a general matter, AIO collects the following types of Personal Data:
Data collected from individuals
Category |
Examples |
Collected |
A. Personal data | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, Social Security number, or other similar identifiers, telephone number, employment |
Yes |
B. Special categories of personal data ART. 9 GDPR | Age (40 years or older), race, color, national origin, citizenship, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, biometric data. |
Yes |
C. Internet or other similar network activity. | Browsing history, search history, information on a consumer’s interaction with a website. |
Yes |
D. Geolocation data. | Physical location or movements. |
Yes |
E. Sensory data. | Audio, visual, or similar information. |
Yes |
F. Professional or employment-related information. | Occupation, Employer Information. |
Yes |
4. LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA
AIO uses the following legal bases for processing your data in relation with the above identified purposes:
Legal Basis | Purposes |
Your Consent | Market research Publications Usage data In general |
Execution of a contract to which you or your company is party or in order to take preliminary steps at your request prior to entering into a contract | Registration with our community Relationships and communications Direct marketing |
Comply with a legal obligation to which the AIO is subject | Vital interests Required by Law Tax Reporting |
Legitimate interest | Professional background checks Direct marketing Research and analysis Identity Verification Record Keeping |
5. SPECIAL CATEGORY OF PERSONAL DATA OR SENSITIVE DATA
AIO might process certain categories of data that can be considered very sensitive. This data may be collected when individuals participate in market research activities carried out by AIO directly or on behalf of their clients. We are committed to handling this data with extreme care and only a few authorized people have access to it. Such data might include: information about your health, your ethnic origin, biometric data, trade union membership, etc. Where we process special categories of personal data, “Sensitive Personal Data,” we will always obtain your explicit consent to those activities unless:
- Consent is not required by law;
- To protect your vital interests where you are incapable of giving your consent;
- For the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity;
- Processing is necessary for reasons of public interest in the area of public health as required by the local law.
Where this is allowed by law, you may have the right to withdraw that consent at any time.
6. AUTOMATED DECISIONS
We reserve the right to make automated decisions, including using machine learning algorithms about website visitors to optimize and provide better experience when navigating our websites. Only digital data as specified in section 8 are included in this processing.
We may analyze your participation in our surveys with the purpose to enrich the profiling data we hold about you. The profiling data that we have collected might be used for making manual or automated decisions that involve your participation in market research activities. As results of this processing, we will be able to send you market research activities within your sphere of expertise and interest.
You may contact us if you would like any clarifications about the automated decisions.
7. DIGITAL DATA
- Cookies: AIO may set and use cookies to enhance your user experience on the sites, such as retaining your personal settings and preferences. You may set your browser to prevent or reject cookies, or you may manually delete any cookies set. If you reject the cookies on the sites, you may still be able to use the sites, but they shall be limited to certain minimal functionality. From time-to-time AIO may use third-party tracking utilities that use session ID cookies that track site usability and assist AIO in improving user experience. This Privacy Notice does not cover the use of cookies by our third-party providers as we do not have access or control over these cookies.
- We may collect information on our sites or in our emails using web beacons and or tracking pixels (electronic images). We may use beacons to count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.
- You can review the cookies used by AIO’s website here
- Cookie Configuration Panel: You can configure the Cookie by using the configuration panel that pops up when you visit our website.
- Trend Analyses: AIO may use IP addresses to analyze trends, administer the Sites, to track your movement within the Sites, and to gather broad demographic information for aggregate use.
- Links to other sites: our sites include links to other websites whose privacy practices may differ from AIO’s. If you submit personal data to any of those sites, your information is governed by the privacy statements of those third-party sites.
- Managing cookies: Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
- https://support.google.com/chrome/answer/95647 (Chrome);
- https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop (Firefox);
- https://help.opera.com/en/latest/security-and-privacy/ (Opera);
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
- https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari);
- https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy (Edge).
8. CHOICE WITH RESPECT TO USES AND DISCLOSURES OF PERSONAL DATA
AIO recognizes that individuals have the right to limit the use and disclosure of their Personal Data, and we are committed to respecting those rights. We offer individuals the opportunity to opt out of disclosures of Personal Data to a third party or the use of Personal Data for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individual. We will comply with the GDPR with respect to disclosures of Sensitive Data including, when applicable, obtaining the explicit consent (i.e., opt in consent) of an individual prior to disclosing Sensitive Data to a third party or using Sensitive Data for purposes other than those for which it was originally collected or subsequently authorized by the individual.
9. DISCLOSURE/TRANSFER OF INFORMATION FOR A BUSINESS PURPOSE
- AIO may disclose your Personal Information to a third party for a business purpose. We do this by entering into a contract that describes the purpose and requires the recipient to both keep that Personal Data confidential and not use it for any purpose except performing the contract. Furthermore, third parties must comply with the GDPR and agree to provide adequate protections that are no less protective than those set out in this Notice.
- Disclosure: We may disclose your Personal Information for a business purpose to the following categories of third parties:
- Our affiliates and subsidiaries
- Service Providers and consultants
- Professional services organizations, such as auditors and law firms
- Our business partners
- Internet service providers
- Government entities
- Operating systems and platforms
- Survey hosting providers
- Identity verification and fraud prevention providers
- Rewards fulfillment providers
- SMS and video conference service providers
- Customer and panel support services
- Credit card processor
- Tax authorities
- Purposes of disclosure: AIO may disclose your personal information for the below purposes:
- Survey reporting
- Email services
- Authentication of medical licenses
- Identity verification and fraud prevention
- Offering and providing customer support
- Internal marketing campaigns for improving and facilitating participation of Panel Members in market research activities
- Internal marketing engagement e.g. newsletters
- Honorarium processing and fulfillment
- Auditing purposes and governmental reporting
- Tax reporting
- Allowing participation in market research activities
- For complying with your requests or contract obligation we have with you
- Disclosures due to acquisition or merge: We may share your information in connection with a merger, sale of company assets, financing or acquisition of all or a portion of our business to another company, if any. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy policy.
- Anonymous information: We may also share aggregated or anonymous information that does not directly identify you. AIO may share anonymized aggregated demographic information with AIO partners.
- Other forms of disclosures: AIO also may discloses your personal data for other purposes or to other third parties when you have consented to or requested such disclosure or under the following circumstances:
- We respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims;
- We believe it is necessary to share information in order to investigate or prevent fraud, or to take action regarding illegal activities, situations involving potential threats to the physical safety of any person, or as otherwise required by law.
- We transfer information about you if AIO is acquired by or merged with another company. In this event, AIO will notify you before information about you is transferred and becomes subject to a different privacy notice.
- In response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
- Third party compliance: Such third parties must agree to use such Personal Data only for the purposes for which they have been engaged by AIO and they must either:
- comply with the GDPR, the Data Privacy Framework principles, or another mechanism permitted by the applicable European data protection law(s) for transfers and processing of Personal Data; or
- agree to provide adequate protections for the Personal Data that are no less protective than those set out in this Notice.
- Liability: AIO is potentially liable in cases of onward transfers of Personal Data to third parties, such as when third parties that act as agents on our behalf process Personal Data in a manner inconsistent with applicable data protection regulations.
10. TRANSFER PERSONAL DATA OUTSIDE THE EEA, UK AND SWITZERLAND
The third parties as described in section 9.7 might be based in US or in countries other than EEA, UK and Switzerland. In these instances, AIO imposes strict contractual obligations and executes Standard Contractual Clauses with third parties to maintain a level of protection that is equal to the GDPR requirements.
In other instances, we may ask your consent to allow us to transfer your personal data into another country. In doing so we will provide you with full information about the transfer.
You might contact our DPO if you would like to know more about our international transfer assessment and/or copy of the transfer mechanism that we use for sharing your Personal Data outside your country of residence.
11. ANTI-SPAM
AIO maintains a strict “No-Spam” policy, which means that AIO does not intend to sell, rent or otherwise give your email address to a third-party without your consent.
12. DATA INTEGRITY, PURPOSE LIMITATION AND RETENTION
AIO will not process Personal Data in a way that is incompatible with the purposes for which it has been collected or subsequently authorized by you. To that end, AIO will take reasonable steps to ensure that your Personal Data is reliable for its intended use, accurate, complete, and current. AIO uses reasonable efforts to maintain the accuracy and integrity of your Personal Data and to update it as appropriate.
Data deletion and retention:
We delete your account and the personal data you provided as part of the registration process when:
- You submit a deletion request and we are not subjected to a legal obligation to maintain your personal data
- We may delete an account and the data included on it after a long period of member’s inactivity and when the data is no longer necessary respect to the purposes for which it was collected.
We retain your personal data as follow:
- Market research data obtained during your participation in market research activities will be kept for up to 5 years;
- Incentive fulfillment data including your W8 and W9 will be kept for 7 years in accordance with the US federal law.
We may retain your information as necessary (including a longer period) to comply with our legal obligations, resolve disputes and enforce our agreements.
13. PERSONNEL ACCESS TO PERSONAL DATA
Personnel from AIO may access and use your personal data only if they are authorized to do so and only for the purpose for which they are authorized.
14. DATA SECURITY
AIO has implemented physical and technical safeguards to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alternation, or destruction. For example, electronically stored Personal Data is stored on a secure network with firewall protection, and access to AIO ‘s electronic information systems requires user authentication via password or similar means. AIO also employs access restrictions, limiting the scope of employees who have access to Customer Personal Data. Further, AIO uses secure encryption technology to protect certain categories of personal data.
Despite these precautions, no data security safeguards guarantee 100% security all of the time.
15. YOUR RIGHTS
- Right of Access You have the right to obtain confirmation about whether your personal data is included in our databases. Upon request, AIO will provide an individual access to your personal data within the time frame dictated by the applicable data protection regulations. AIO will allow you to know what Personal Data is included in our databases and to ensure that such Personal Data is accurate and relevant for the purposes for which AIO collected the Personal Data. You may also request a copy of your data in a commonly used and machine-readable form.
- Right of Rectification: You may review your own Personal Data stored in the databases and correct, update, modify, or delete any data that is incorrect or incomplete.
- Right of Erasure: You may request to have the personal information that we have about you to be deleted from our servers. AIO will take reasonable steps, including technical measures, to comply with your request. In some circumstances your request might be rejected if it falls under one of the categories included in ART. 17.3:
- exercising the right of freedom of expression and information
- for compliance with a legal obligation
- for reasons of public interest in the area of public health
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
- establishment, exercise or defense of legal claims
- Objection: You may object, at any time, to your Personal Data being processed for a specific purpose.
- Restriction of Processing: You may restrict processing of your Personal Data for certain reasons, such as, for example if you consider your Personal Data collected by us to be inaccurate or you have objected to the processing and the existence of legitimate grounds for processing is still under consideration.
- Data Portability: You may request the Personal Data you provided to us in a commonly used and machine-readable form.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time, without affecting the lawfulness of our processing based on such consent before it was withdrawn, including processing related to existing contracts for our Services.
- Right to complain to a supervisory authority: you might lodge a complaint about our processing of your personal data with your local Data Protection Authority; AIO will collaborate with the authority to resolve it.
- Limitations: these rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practices_en and https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
16. HOW TO EXERCISE YOUR RIGHTS
You can exercise your rights by filling out the form found at https://privacyportal-fr.onetrust.com/webform/f4acdbc3-5bc6-408b-bf08-97567a2323b4/d6d3beac-9355-4ae1-b166-b97976381162. You may also submit a request at privacyrequest@apollointelligence.net, reach us on toll free number 877-390-2735 or via postal mail at AIO, Attn: Compliance Department, 480 Pleasant Street, Suite B100, Watertown, MA 02472 USA
17. RESPONSE TIMING AND FORMAT
We endeavor to respond to a verifiable request within 30 days of its receipt. If we require more time (up to two extra months), we will inform you of the reason and extension period in writing.
We will deliver our written response by mail or electronically, at your option.
The response we provide will also explain the reasons we cannot comply with a verifiable request, if applicable.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Request that we can’t process: We cannot respond to your request or provide you with Personal Data if we cannot verify your identity or authority to make the request and confirm the Personal Data relates to you. Making a verifiable request does not require you to create an account with us. We will only use Personal Information provided in a verifiable request to verify your identity or authority to make the request.
Requests for Personal Data
AIO will track each of the following and will provide notice to the appropriate parties under law and contract when either of the following circumstances arise:
- legally binding request for disclosure of the Personal Data by a law enforcement authority unless prohibited by law or regulation; or
- requests received from the Data Subject.
18. NOTIFICATION
AIO notifies Clients and individuals about its adherence to GDPR and other applicable data protection regulations, as well as the Data Privacy Framework principles, through its publicly posted website privacy notice available at: Coming Soon
19. RESPONSIBILITIES AND MANAGEMENT
AIO has designated the Privacy Department to oversee its information security program, including its compliance with the Data Privacy Framework program. The Privacy Department shall review and approve any material changes to this program as necessary. Any questions, concerns, or comments regarding this Notice also may be directed to privacy@apollointelligence.net.
20. ENFORCEMENT AND DISPUTE RESOLUTION
We commit to resolving individuals’ complaints related to our privacy practices or our collection, or use, or disclosure of Personal Data. An individual may file a privacy complaint by contacting our DPO at privacy@apollointelligence.net. Further, individuals with questions or concerns about the use or disclosure of their Personal Data should contact us as outlined in Section 16.
If an individual’s complaint cannot be satisfied through our internal complaint process, the individual may bring a complaint before the ICDR/AAA Data Privacy Framework (DPF) Program, a non-profit alternative dispute resolution provider located in the United States and operated by the international division of the American Arbitration Association. The ICDR/AAA Data Privacy Framework (DPF) Program is designed to handle eligible complaints brought by Swiss, UK and EU citizens about Data Privacy Framework Principles. If you have any complaints regarding our compliance with the Data Privacy Framework (DPF) you should first contact us (as provided above). If contacting us does not resolve your complaint or you do not receive timely acknowledgement of your complaint, please visit the ICDR/AAA Data Privacy Framework (DPF) Program website at https://go.adr.org/dpf_irm.html for more information and to file a complaint. We will cooperate with the independent dispute resolution mechanism to resolve any complaint that is not resolved through our internal processes.
If a complaint regarding Data Privacy Framework (DPF) compliance is not resolved by any of the above dispute resolution mechanisms, an individual has the possibility, under certain conditions, to invoke binding arbitration. Additional information about binding arbitration can be found at: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2.
The above does not preclude your right to contact your local Data Protection Authority. We will collaborate with the DPA to find a solution to resolve the complaint.
21. CHANGES TO THIS NOTICE
AIO will maintain, monitor, test, and upgrade information security policies, practices, and systems to assist in protecting the Personal Data that it collects. AIO personnel will receive training, as applicable, to effectively implement this Notice. Please refer to Section VIII for a discussion of the steps that AIO has undertaken to protect Personal Data.
This Notice may be amended from time to time, consistent with the Data Privacy Framework and applicable data protection and privacy laws and principles. We will notify Customers if we make changes that materially affect the way we handle Personal Data previously collected, and we will allow them to choose whether their Personal Data may be used in any materially different manner.
22. DEFINITIONS
Capitalized terms in this Privacy Notice have the following meanings:
- “Customer” means a prospective, current, or former partner, vendor, supplier, customer, or client of AIO. The term also shall include any individual agent, employee, representative, customer, or client of an AIO Customer where AIO has obtained his or her Personal Data from such Customer as part of its business relationship with the Customer.
- “Data Subject” means an identified or identifiable natural living person in the European Union. An identifiable person is one who can be identified, directly or indirectly, by reference to a name, or to one or more factors unique to his or her personal physical, psychological, mental, economic, cultural or social characteristics.
- “Employee” means an employee (whether temporary, permanent, part-time, or contract), former employee, independent contractor, or job applicant of AIO.
- “Europe” or “European” refers to a country in the European Economic Area.
- “Personal Data” as defined under Regulation (EU) 2016/679, the General Data Protection Regulation means any and all data (regardless of format) that (i) identifies or can be used to identify, contact or locate a natural person, or (ii) pertains in any way to an identified natural person. Personal Data includes obvious identifiers (such as names, addresses, email addresses, phone numbers and identification numbers) as well as biometric data, “personal data” (as defined in the GDPR), and any and all information about an individual’s computer or mobile device or technology usage, including (for example and without limitation) IP address, MAC address, unique device identifiers, unique identifiers set in cookies, and any information passively captured about a person’s online activities, browsing, application or hotspot usage or device location.
- “Sensitive Data” is a subset of Personal Data which due to its nature has been classified by law as deserving additional privacy and security protections. Sensitive Personal Data consists of: (i) all government-issued identification numbers, (ii) all financial account numbers (including payment card information and health insurance numbers), (iii) individual medical records, genetic and biometric information, (iv) user account credentials, such as usernames, passwords, security questions/answers and other password recovery data, (v) data elements that constitute Special Categories of Data under the GDPR, namely EEA Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, and (vi) any other Personal Data designated by AIO as Sensitive Personal Data.
Data Privacy Framework program for Residents of the European Union, UK and Switzerland
1. DATA PRIVACY FRAMEWORK
AIO complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. AIO has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. AIO has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.
AIO acknowledges that as a participant in the Data Privacy Framework (DPF ) we are under the investigatory and enforcement powers of the Federal Trade Commission (FTC).
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/
2. RENEWAL
- AIO will renew its Data Privacy Framework certification annually, unless it subsequently determines that it no longer needs such certification or if it employs a different adequacy mechanism.
- Prior to the re-certification, AIO will conduct an in-house verification to ensure that its attestations and assertions with regard to its treatment of Personal Data are accurate and that the company has appropriately implemented these practices. Specifically, as part of the verification process, AIO will undertake the following:
- Review this Notice to ensure that it accurately describe the practices regarding the collection of Customer Personal Data.
- Ensure that this Notice informs about AIO’s participation in the Data Privacy Framework program and where to obtain a copy of additional information (e.g., a copy of this Notice).
- Ensure that this Notice continues to comply with the Data Privacy Framework principles and GDPR.
- Confirm that data subjects are made aware of the process for addressing complaints and any independent dispute resolution process (AIO may do so through its publicly posted website, its Privacy Notice and/or its Terms of Use).
- Review its processes and procedures for training Employees about AIO’s participation in the Data Privacy Framework program and the appropriate handling of Customer Personal Data.
- AIO will prepare an internal verification statement on an annual basis.