GENERAL WEBSITE PRIVACY POLICY

Last Updated: May 25, 2018

1) Introduction.
Critical Mix, Inc. (“Company,” “we,” “our,” or “us”), owns and operates the websites www.criticalmix.com, www.criticalmix.uk and www.criticalmix.eu (the “Site(s)”) as a data controller. We know that your privacy is important to you. Through the Site, we promote our products and services, allow our customers access to our CMIX platform and operate the “Store” located on the Site through which we provide certain merchandise bearing our logo free of charge. We’re committed to helping you understand how we manage and protect the information we collect. We take privacy seriously and have taken many steps to help safeguard the information we collect from you.

This Privacy Policy describes the types of information we collect, how we collect information, how we use the information, how we share or disclose the information, how we store the information, and your choices regarding the use and processing of the information. Your use of our website, your use of our services, and your disclosure of PII to us are completely voluntarily, therefore the collection, processing, transfer, and storage of your PII as set forth in this Privacy Policy is with your consent.

This privacy policy does not apply to the collection, processing, storage, transfer, and/or disposal of information collected in connection with the survey panels or communities operated by or on our behalf.

2) What type of information do we collect? We collect the following information:

  1. Personally identifiable information (“PII”) which includes, without limitation, first and last names, email address, telephone number(s) (e.g., home, mobile, and business numbers), and residential address.
  2. Business contact information, including, without limitation, company name, job title, and department.
  3. Information on your employer or the company you represent.
  4. Information collected through automated means, includes, without limitation, IP address, browser type, operating system, referring URLs, information on actions or activities taken or engaged in on a website, and dates and times of website visits.

3) How we collect information.

  1. Information submitted or provided by you:
    1. Through or in connection with our Sites;
    2. Through or in connection with business meetings with actual or potential customers or clients;
    3. Through or in connection with promotions, meetings, events, and/or trade or industry shows or conferences sponsored by, hosted by, or attended by us and/or our employees, representatives, and/or agents;
    4. Through telephone calls, email communications, and/or other forms of communication with you;
    5. Through inquiries, from requests for bids or quotes from us, and from orders for our services; and
    6. Through your orders for Critical Mix branded products on our Store.
  2. Information collected from third partiesWe may collect information, including, without limitation, PII and business contact information, from third parties, including, without limitation, information service bureaus, data brokers, social media platforms, and/or industry conference or event organizers or sponsors. We may use the information collected from such third parties for various purposes, including, without limitation, sending you emails or other communications as described herein. In the event you receive such communications you will have the opportunity to opt-out of receiving communications from us.
  3. Information collected through automated means:
    1. Cookies. Cookies are small files that store certain data on a device or computer. We may use session and persistent cookies for several purposes including, without limitation, to enable you to use and transverse a website and quality control. Session cookies expire when you close your browser. Persistent cookies remain on your device or computer indefinitely until deleted. A user may disable and/or delete cookies via the user’s browser or otherwise, however, this may limit your use of a website, and/or decrease the functionality available to the user in connection with a website.
    2. Third Party Cookies. We uses third parties to provide services and certain functionality to us. We use contracts with such third parties to control their use of cookies and to limit their use of cookies to the limited purposes set forth in the contracts.
    3. Log Files. Our Sites may automatically gather and store certain information in log files, including, without limitation, data available from your web browser, including, without limitation, IP Address, browser type, internet service provider,
    4. referring/exiting pages, operating system, date/time stamp and click stream data.
  4. Cookie Notice: We value your privacy. Below please find a list of the cookies set or deployed by us and/or our service providers, partners, and/or subcontractors. For certain cookies no opt-out mechanism is provided.

    i. Essential Cookies:

    Performance cookie(Session cookie) incap_ses_* These cookies improve performance and security on the Website.
    Performance cookie(Persistent cookie) visid_incap_* These cookies improve performance and security on the Website.

    ii. Analytics and Customization – Data Collection:

    advertising.com APID, IDSYNC This enables the partner to make better decisions about whether to display an advertisement to you.
    Youtube APISID,HSID Google set a number of cookies on any page that includes a Google Map. While we have no control over the cookies set by Google, they appear to include a mixture of pieces of information to measure the number and behaviour of Google Maps users.
    casalemedia.com CMDD, CMID, CMPRO, CMPS, CMRUM3, CMSC, CMST The Casale Media Online Advertising Exchange (Index) uses cookies for the purpose of tracking when an Internet user has seen an advertisement. These cookies do not and can not provide Casale Media with any personally identifiable information about an Internet user.
    pubmatic.com KRTBCOOKIE_10, KRTBCOOKIE_80, PUBMDCID, PugT We use this cookie to correlate our user IDs with those of our partners (such as demand side platform clients or other advertising technology companies). We pass the information stored by the partner in this cookie to the partner when it is considering whether to purchase advertisements. This enables the partner to make better decisions about whether to display an advertisement to you.
    Adroll __ar_v4, __adroll We use AdRoll to provide interest-based advertisements to show our ads on other websites. The technology to do this is made possible by cookies and as such we may place a so called “remarketing cookie” during your visit. Tthe whole process is entirely anonymised.
    Google Analytics _ga,_gid These cookies are used to collect information about how visitors use our site. We use the information to compile reports on general user traffic, conversion statistics and to help us improve the site. The cookies collect information anonymously.
    incapsula nlbi_[ID] Used by Incapsula application delivery platform. Help us improve our website by collecting information about how visitors use our Site.

Do Not Track Notice.
Do Not Track (“DNT”) is a preference in your browser that you can set to notify websites that you visit that you do not want the websites to collect certain information about you. We do not respond to DNT signals. If you object to our practice with regards to DNT signals, you are free not to visit our Sites.

4) How We Use the Information that We Collect. We may use information, including, without limitation, PII and business contact information, to:

  1. Provide, administer, and communicate with you about our products, promotions, services, events (e.g., webinars, etc.), newsletters, and industry expertise/knowledge (e.g., whitepapers, articles, etc.);
  2. Create, supplement, and update our directories and records for actual and/or potential suppliers, customers, and/or clients;
  3. Protect against and prevent fraud, claims, liabilities, and to manage risk exposure;
  4. Respond to inquiries and requests;
  5. Operate, evaluate, conduct, and improve our business (including, without limitation, to conduct and complete transactions for our products and/or services, to improve our current products and/or services, to develop new products and/or services, etc.);
  6. Process and manage opt-out or unsubscribe requests;
  7. Comply with applicable laws, regulations, codes, and industry standards and practices;
  8. Conduct marketing and market research activities including, without limitation,: (a) contacting you to participate in customer satisfaction surveys or questionnaires via telephone, email, or otherwise, and (b) soliciting your opinions or feedback on our business activities, including, without limitation, current and future products and services;
  9. Create and send targeted communications to you regarding you or your company’s transactions with us and/or the profile for your company;
  10. Respond to a subpoena or an order of a court or government agency;
  11. Establish, exercise, or defend legal claims, including, without limitation, in order to protect the safety of an individual or to protect our rights and/or property; and
  12. Evaluate your interest in employment and contact you regarding possible employment opportunities with us and/or any company within the our group of companies.
  13. Respond to your request for Critical Mix branded products from our store.

In addition to the above, we may use information collected or received by us as otherwise set forth in this Privacy Policy.

In the event that you provide us with any feedback, suggestions, and/or comments regarding our business activities, including, without limitation, regarding current and/or future products and/or services, we may use, apply, and implement such feedback, suggestions, and/or comments, at our discretion, and without notice to you, without any consent or approval from you, without any compensation to you, and/or without any attribution or credit to you, and you hereby irrevocably assign and transfer to us all right, title, and interest in and/or to any such feedback, suggestions, and/or comments.

5) Analytics and Customization – Data Collection How do we share your information?
We do not sell your information and does not disclose your information, except as described in this Privacy Policy or as otherwise consented to by you.

We may share information, including, without limitation, PII and business contact information, as follows:

  1. Within the our group of companies (with our parents, subsidiaries, and affiliates) and the directors, managers, officers, employees, consultants, and agents of these companies, subject to the terms of this Privacy Policy or as otherwise disclosed to you at the time of the collection of your information or as subsequently consented to by you.
  2. To service providers who are performing services on our behalf, whether engaged directly by us or engaged by a third party, including, without limitation, companies providing email delivery services, fraud detection and prevention services, event coordination and management, etc. The service providers are authorized to use and disclose the information only as necessary to perform and provide the services for which they were engaged and subject to the terms set forth in this Privacy Policy.
  3. We may disclose information about you:
    1. if we are required to do so pursuant to applicable laws or legal or court process; or
    2. When we believe disclosure is necessary to prevent harm or financial loss, or in connection with an investigation of actual or suspected fraud or illegal activity.
  4. We reserve the right to transfer information about you in the event of a merger, acquisition, sale or other transaction involving Critical Mix or any of its subsidiaries or affiliates. In addition, we may transfer your information in the event of a change of control event. Following a transfer covered by this Section 5 you may contact the entity to whom your information was transferred, with any inquiries concerning the processing of your information.

6) Where is Information Stored?
Information, including, without limitation, PII and business contact information, is primarily stored on servers and systems located in the United States, which servers are licensed, owned, and/or maintained by or on behalf of us. Your information may also be stored on or in local servers, networks, and files maintained by or on behalf of a company within our Group of companies. BY DISCLOSING YOUR PII TO US YOU ARE EXPRESSLY CONSENTING TO THE TRANSFER AND EXPORTING OF YOUR PERSONAL INFORMATION TO COUNTRIES OUTSIDE OF THE COUNTRY WHERE YOU MAY RESIDE, INCLUDING, WITHOUT LIMITATION, TO THE UNITED STATES.

Critical Mix is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

Critical Mix complies with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries. Critical Mix has certified that it adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability. If there is any conflict between the policies in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/.

In compliance with the EU-US Privacy Shield Principles, Critical Mix commits to resolve complaints about your privacy and our collection or use of your personal information. European Union individuals with inquiries or complaints regarding this privacy policy should first contact Critical Mix at:

Critical Mix, Inc.
Attn: Jonathan A. Flatow, Data Protection Officer
53 Riverside Avenue
Westport, CT 06880
Phone: 1-888-511-4259
Privacy@criticalmix.com

Critical Mix has further committed to refer unresolved privacy complaints under the EU-US Privacy Shield Principles BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint.

Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.

You also have the right to lodge a complaint with the relevant supervisory authority in your country.

7) What Security Measures Have We Implemented?
We maintain appropriate technical, administrative and physical safeguards to protect information, including, without limitation, PII, received or collected by us. We review, monitor and evaluate its privacy practices and protection systems on a regular basis. Notwithstanding the foregoing, transmissions over the Internet and/or a mobile network are not one hundred percent (100%) secure and we do not guarantee the security of such transmissions. We are not responsible for any errors by individuals in submitting PII to us.

8) How can I opt-out?
You can opt out by clicking the unsubscribe link in emails we send to you or by emailing privacy@criticalmix.com. You have the right to access, modify, restrict the processing of, object to the processing of, or have your personal information transmitted to another data controller, and to have your personal information deleted from our site. Please email privacy@criticalmix.com. You may also exercise these rights by contacting our Data Protection Officer at the address or email listed in this Notice. We will respond to your request within 30 days. Upon opting out, or if you revoke any previously given consent, we will deactivate your account and you will not receive any further communications from us. To the extent we have a legitimate interest in retaining your information, such as the need to comply with a contract with you or to make reports to governmental entities or comply with the law, we will retain your information. As long as we do, your information will be subject to the Privacy Policy. Please note we will not be able to delete data that has been technologically archived in our backup systems, but we can delete current live information in our database.

9) Children’s Privacy.
In the United States, and elsewhere where the law provides, we do not knowingly collect information from children under the age of 13 on the Site or through the Service without permission from a parent or legal guardian. If you are under the age of 13, please do not provide any information to us. If we become aware that we have collected information from a child under the age of 13 without the permission of a parent or legal guardian, we will make commercially reasonable efforts to delete such information from our database.

In countries that are subject to the General Data Protection Regulation 2016/679, as may be amended from time to time (“GDPR”) we do not knowingly collect information from children under the age of 16 on the Site or through the Service without permission from a parent or legal guardian or a person holding parental authority over the child. If you are under the age of 16 and a citizen of a country subject to GDPR, please do not provide any information to us. If we become aware that we have collected information from a child under the age of 16 without the permission of a parent or legal guardian or a person holding parental authority over the child, we will make commercially reasonable efforts to delete such information from our database.

10) How Long We Retain Your Information?
We will retain PII and other information about you for such period of time as may be required or permissible by law.

11) Who can I contact with questions or complaints about this Privacy Policy?
If you have any questions or complaints regarding our privacy practices and/or this Privacy Policy or want to communicate an opt-out request to us, or want to exercise your rights to access, review, correct, delete or object to the processing of PII, please contact us:
via email at: privacy@criticalmix.com
or by phone or mail to:

Critical Mix, Inc.
Attn: Jonathan A. Flatow, Data Protection Officer
53 Riverside Avenue
Westport, CT 06880
Phone: 1-888-511-4259

12) Are there any companies affiliated with Critical Mix that may collect, store and process PII?
Yes, please see the list of companies below:

Critical Mix Europe, Ltd
Critical Mix GmbH
Critical Mix Bulgaria EOOD

13) Links To Other Websites.
Our website(s) may contain or provide links to other websites for your convenience and information. These websites may operate independently. Linked sites may have their own privacy notices or policies, which we strongly suggest you review if you visit any linked websites. To the extent any linked websites you visit are not owned or controlled by us, we are not liable or responsible for the websites’ content, any use of the websites, or the privacy practices of the owners of the websites.

14) Updates to this Privacy Policy.
This Privacy Policy may be updated periodically and without prior notice to you to reflect changes to our practices and procedures set forth herein. In the event of any updates or changes to this Privacy Policy, we will post a prominent notice on our website(s) to notify you of any significant changes.