Privacy policy
Last updated: March 1, 2024
When does this Privacy Policy apply?
What is “personal data”? What about “cookies”?
When we use the term “personal data,” we mean any information relating to an identified or identifiable natural person. This includes obvious information such as name, home address, email address and telephone number, date of birth, but also IP addresses and data specific to the physical, physiological, genetic, economic, cultural or social identity of natural persons. We also include cookies and other tracking technologies in our definition of personal data.
A “cookie” is a file that a website places on a computer's hard drive so that the website can remember something about individuals at a later time. In this Privacy Policy, when we refer to “cookies,” we also include other technologies with similar purposes, such as pixels, beacons and tags.
We may place cookies, in which case they are referred to as “first-party cookies.” They may also be placed by third parties, such as Google Analytics, in which case they are referred to as “third-party cookies” and result in the sharing of your personal data, such as IP addresses, with those third parties.
For more information about cookies, you can visit websites such as http://www.cookiecentral.com/ and https://www.allaboutcookies.org/.
What personal data do we process and why?
We collect personal data to (a) provide our Services to our Clients, Users and other individuals (where applicable), (b) allow you to create an account on our software Services, if you choose to do so, (c) respond to your requests, (d) conduct our marketing activities, including through retargeting cookies, and (e) obtain analytics and performance data regarding the performance of our Services, including our advertisements.
Under the European Union General Data Protection Regulation (“GDPR”) (where applicable), we rely on different legal bases to justify our processing of personal data, such as consent, performance of a contract and legitimate interests. However, these legal bases may not be valid in all jurisdictions and are provided for informational purposes in the event that the GDPR becomes applicable. For example, in Canada, where such legal bases do not apply except for consent, we collect, use and disclose this personal data with your consent, which may be express or implied. You may withdraw your consent at any time. We process personal data on behalf of our clients.
Under the GDPR, where applicable, we are considered data processors, and our clients are responsible for ensuring that they have an appropriate legal basis for processing your personal data. We have no control over how our clients process personal data, and if you have questions about how they process your personal data, we encourage you to contact them directly.
However, in limited cases, such as for marketing activities, we may be a data controller, which means that under the GDPR (where applicable), we are responsible for determining the legal basis for processing your personal data under the GDPR. Where this is the case, we have identified the applicable legal basis in this Privacy Policy.
What cookies and similar tracking technologies do we use?
We collect essential, functional, performance and targeting cookies. To view the section of this Policy explaining how to manage your cookie preferences, go to Section 6. We collect functional, performance and targeting cookies only with your consent. IC uses both first-party and third-party cookies:
- First-party cookies — First-party cookies are cookies that we issue and that can only be set or retrieved by us. They are used for our own purposes, for example to personalize websites.
- Third-party cookies — Third-party cookies are placed on our websites by other entities, for example to create new features or provide advertising.
Do we conduct interest-based advertising?
We conduct interest-based advertising (“IBA”), also known as targeted advertising or behavioural advertising.
Interest-based advertising is also known as targeted advertising (retargeting) or behavioural advertising. Retargeting means that the advertisements shown to you are personalized based on your behaviour while browsing online. Retargeting means that the advertisements shown to you are personalized based on your behaviour while browsing online. This is enabled through cookies and requires the processing of electronic data that is considered personal data under certain laws.
For example, we may show you advertisements based on your interests when you use Facebook through a tool offered by Facebook called the Custom Audience Tool. This tool allows us to personalize our advertisements based on your behaviour. We do not share any of your personal information, including your behaviour, with Facebook. The tool allows us to convert your email address into a unique number that Facebook uses to match against unique numbers it generates from the email addresses of its users as part of real-time bidding.
We use Facebook Ads, Google Ads and LinkedIn Ads cookies to conduct IBA. This means that Facebook and Google use this information to show you relevant advertisements and improve the advertising you see.
You can opt out of interest-based advertising by managing your cookies. Go to the next section of this Privacy Policy to learn how.
How can you change your cookie preferences?
You can manage your cookie preferences through your browser by following the instructions provided below by clicking on the browser you use. However, by blocking certain cookies that enable features of the Services, some parts of the Services may not be available.
You can also use WebChoices, which is a browser-based tool for opting out of interest-based advertising. AdChoices provides additional solutions and explanations for managing, blocking and controlling cookies, as well as plug-ins for retaining your cookie opt-out preferences even if you delete your cookies.
You can install the Google Analytics Opt-out Browser Add-on, which prevents Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visit activity. For more information about Google's privacy practices, please visit Google's Privacy & Terms webpage: https://policies.google.com/privacy.
Where do we store your personal data?
Our servers are hosted in Canada. However, our service providers may store your personal data in other countries (go to the next section of this Policy to learn how we may share your personal data). Some countries may not provide the same level of protection for personal data as your country.
If you are located in the European Union, where applicable, we are required to ensure that appropriate safeguards are in place before transferring your personal data outside the European Union.
With whom may we share your personal data?
We do not sell personal data, and we do not share personal data collected in connection with the Services for reasons other than providing the Services and conducting our marketing activities, unless required by law or as set out below.
We share your personal data with the following categories of recipients: Clients, service providers, integration partners, law enforcement authorities (where required by applicable law), and parties to our business transactions.
It is important for us to inform you that clients are not our service providers; they are separate controllers of your personal data and may process and otherwise handle your personal data as they deem appropriate. The third parties with whom we may share your personal data are listed in the table below:
How long do we retain your personal data?
We retain your personal data for as long as necessary to fulfill the purpose for which it was collected or as required by applicable laws, whichever period is longer.
How do we protect your personal data?
We strive to implement physical, organizational, contractual and technological safeguards proportionate to the risks, taking into account factors such as the sensitivity of the personal data we collect.
However, it is important to understand that we cannot guarantee the security of personal data over the Internet and that you must also take precautions, such as not sharing your login credentials with anyone. No method of transmitting or storing information is 100% secure or error-free, so unfortunately we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately using the contact information provided at the beginning of this Policy.
Within our organization, only staff members who need access to your personal data because of their role or duties are granted such access.
What rights do you have regarding your personal data?
Your rights differ depending on where you are located in the world.
In most locations, you may access and correct your personal data, as well as withdraw your consent to the processing of your personal data.
In other jurisdictions, such as the European Union (where applicable), you have additional rights, such as the right to object to the processing of your personal data, the right to data portability, the right to erasure and the right to restrict the processing of your personal data.
All of these rights are subject to limitations provided by law, so if we are unable to comply, we will respond to you and explain why. We will respond to all requests within 30 days. In some cases, we may need additional information to validate your identity, in which case we will use it only for that purpose and delete it afterward. We do not charge any fees for you to exercise your rights.
Under the GDPR (where applicable), you are entitled to these additional rights:
- The right of access: under the right of access, you have the right to access your data free of charge in a commonly used format, such as an electronic format if the request is made electronically.
- The right to rectification: you have the right to have your personal data corrected if it is inaccurate or incomplete, and we will respond to this request within one month if it is not considered complex.
- The right to erasure: the “right to be forgotten,” or right to erasure, means that you have the right to request that your data be deleted easily and securely where there is no compelling reason for retaining and continuing to process it.
- The right to restrict processing: you have the right to “block” or restrict the processing of personal data in certain circumstances.
- The right to data portability: you also have the right to data portability, which allows you to obtain and reuse your personal data across different services for your own purposes.
- Right to object: the right to object means that you have the right to object to direct marketing (including profiling), processing based on legitimate interests, and processing for scientific and historical research and statistical purposes, in which case we must stop processing the personal data immediately and at any time, without exception or grounds for refusal, free of charge.
If you would like to learn more about these rights, please click here for a more detailed explanation.
You always have the right to file a complaint with local authorities if you disagree with how we process your personal data. Please see below for information on how to do so.
How can you exercise your rights regarding your personal data?
You can exercise your rights at any time by contacting us using the contact information provided at the beginning of this Privacy Policy.
Once we receive your request, we will contact you within 30 days. We may not be able to fulfill your request, for example, if it is not applicable under the law. If we cannot process your request, we will provide you with an explanation.
When you exercise your rights, we may need to request personal data in order to validate your identity.
If your request is lengthy and difficult, and if we are permitted to do so by law, we may charge you a reasonable fee to assist you. If you are not satisfied with how we handle your request, you may contact your local data protection authorities or privacy commissioners and file a complaint. We will provide you with information on how to do so in our response to your request, based on your location.
If you are in the European Union, you can contact your local data protection authority. A list of data protection authorities can be found here.
If you are located in Canada, please note that the Office of the Privacy Commissioner of Canada has prepared this FAQ to help you access your personal data when it is held by a business. You can also contact the Information Centre of the Office of the Privacy Commissioner of Canada:
Phone
9:00 a.m. to 4:00 p.m. EST
Toll-free: 1-800-282-1376
Mailing address
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec
K1A 1H3
You can also use this online form.
If you have concerns about how we collect, use or disclose your personal data, or how we responded to your request, please let us know. We will do our best to improve our processes to ensure that this does not happen again. We will also provide you with additional information about our practices if you would like us to do so.
Can I unsubscribe from marketing communications?
Yes, you can do so directly in the emails you receive by clicking the “Unsubscribe” link at the bottom of the page. You can also contact us directly or manage your preferences within our Services, where applicable.
Do you respond to “Do Not Track” signals?
If you reside in California, you have the right to ask businesses to stop tracking you across the Internet. Please note that we do not respond to Do Not Track signals. However, if you have a legitimate request regarding your personal data, rest assured that we will do our best to assist you!
Can we change this Privacy Policy?
Yes, we may change this Privacy Policy from time to time, for example to reflect new processing activities, adapt to new laws and regulations, or reflect technological or business changes, such as mergers and acquisitions. You can refer to the last updated date above to determine when this version was published.