For those who have been asked to respond to a questionnaire
IInsightful Edge provides products and services which enable our Clients to collect and collate feedback, in the form of 360 feedback, Team Climate, Employee Engagement and Customer Feedback products. We run surveys for our Clients’ on our server environment and collect the responses to those surveys on their behalf. Our Clients will provide us with contact information of potential survey participants to invite them to participate in a survey. We refer to this contact information as Participant Data and responses as Questionnaire Data. Our Clients remain data controllers of the Data and we will process that in order supply the pre agreed format usually in the form of anonymised reports. This does not effect individuals rights to anonymity where it is described as part of the product or service.
We have a number of standard products with predefined questions that retain a minimum amount of personal information.
Bespoke - Our Clients can design and supply their own questionnaires and in that scenario have used their own discretion to determine what information they collect, who they invite to participate in a survey, what the Questionnaire Data will be used for, whether it will be combined / used with other information and data, who it will be shared with and how long it will be stored once it is returned to them (usually in the form of an anonymised report). We strongly recommend you understand the parameters of the how the data is being processed. We offer our Clients a range of options as to how they use our products and services.
- The information we collect about you
- How we use your information
- Who we share your information with
- Your rights as a data subject
- How long we keep your information
- Security of your information
- International transfers of information
1. The information we collect about you
We collect the following information about you:
Questionnaire Data: we collect your survey responses. Our Clients may have provided your contact information to enable us to invite you to participate in the survey usually in the form of a name and email address, but sometimes additional information for certain products, for example:
- 360 Feedback – Your role and or work relationship to another colleague (for example manager, direct report or peer)
- Team climate – Your department and or team name
- Employee Engagement – Your department, region or other identifiers that help the organisation to understand their results in an actionable way.
- Customer Feedback – In order to prove we are genuine we are sometimes provided with high level information, such a genre of product you were purchasing, or the name of a customer advisor who supported you.
As explained above, we process this Questionnaire Data on our Clients’s behalf and make no use of it ourselves.
Additional collection note: If you are a reviewer on a 360 feedback product, your details may have been provided by a colleague who is legitamately seeking feedback from you.
Technical information: we may collect information relating to your interaction with our software and services, including the type of browser and/or device used, operating system, date/time stamp, referrer page and IP address. We do not link this information to your Questionnaire Data.
Cookies: our online questionnaire service, uses a minimal about of cookies. Predominantly we will use them to offer up your language preference if it is available.
Web beacons: when we send you emails, we may include a web beacon to allow us to determine the number of people who open our emails and information such as when and how many times the email was viewed, whether any links were clicked on, whether the email was forwarded. This helps us to measure the effectiveness of our email campaigns. When you click on a link in an email, we may record this individual response to customise our offerings to you. Web beacons can be refused when delivered via email. If you do not wish to receive web beacons via email, you will need to disable HTML images or refuse HTML emails via your email software, but please note that this is likely to reduce the functionality of such emails.
Your contact information: we will use information from you if you contact us directly for support, for example in relation to a survey invitation that you have received. Your information will be in our customer service system emails for reference, but will not be used for any other purpose,
2. How we use your information
We use the information that we hold about you in the following ways:
Questionnaire Data – to provide our products and services: we hold, store and process your Questionnaire Data solely to provide our products and services to our Clients, in accordance with our agreement with them. We only use your Questionnaire Data for our own purposes if required to do so by law.
Technical information – to protect our services, and for analysis: we will use your information in accordance with our legitimate interests of administering and maintaining our systems and ensuring network and information security, for example to prevent unauthorised access to our networks, to investigate faults, to control the abuse of our products or services, to prevent denial of service attacks and to monitor system usage and server load. We may also use this information in aggregate form for our legitimate interests of improving our products and services.
Your contact information – to respond to your enquiry: we will only use your contact information to support your use of our products and services for example where you contact us directly, in order to respond to your enquiry. This is in accordance with our legitimate interests of providing customer service. In many cases (for example where you wish to exercise your rights as a data subject) this may involve referring you to our Clients for them to respond to you directly.
We will not use any information that we hold about you for marketing purposes.
3. Who we share your information with
Questionnaire Data: The projects we support using your data may vary in the way that questionnaire data is used:
For 360 feedback, team climate, and employee engagement the data is generally treated anonymously unless stated in your welcome email, i.e in 360 feedback self scores and managers scores are generally not anonymous. In most cases we will only provide an aggregated report back to our Clients, but sometimes will be asked to send the report directly to you, to your manager, and or to a coach (this should be made clear to you at the beginning of the project, if you are unsure please ask and we will advise or direct you to our Clients for clarity).
For the purposes of customer feedback products, this data is generally supplied back to our Clients in 2 forms:
- In an aggregated report for the purpose of reviewing trends
- In its raw form so that further analysis can be done by the client and specific issues for specific clients can be addressed
Unless we are required to do so by law, we will not disclose your Questionnaire Data to any other third parties other than our Clients, people working on their behalf, and our sub-processors (such as our affiliates, developers and our hosting providers) that we have agreements in place with.
Your contact information: where you contact us directly we may, if appropriate, refer your enquiry to our Clients/data controller.
4. Your rights as a data subject
Where we are the Data Control we will offer these rights directly, acting as the Data Processor we will support your Data Controller to deliver on their obigations. To request this information please contact us at firstname.lastname@example.org or your Data Controller directly.
If you wish to access, correct, or delete your Questionnaire Data, or exercise any of the other rights described below in relation to your Questionnaire Data, let us know. You may have the right to exercise the following additional rights:
Right to Access: At any point, you can request copies of Questionnaire Data you entered into the system. Our response will be given free of charge, unless the request is considered excessive or manifestly unfounded in which case administration fees may be charged. Contact us at email@example.com and we will, having verified your identity, send you a CSV file of available data, providing it does not impact on other participants rights to anonymity.
Right to Rectification: If at any time we have Participant Data incorrectly entered you have the absolute right to request that we amend it. With regards to Questionnaire Data your opportunity to rectify is limited on those products that are anonymous as once they have been closed and distruibuted to the name reciepients, any changes may comprimise anonymity of yourself or others..
Right of Erasure (Right to be forgotten): in certain circumstances you have the right to erasure of personal information held about you, although this may be qualified where e.g. it is necessary for that information to be retained for record keeping purposes or compliance with our obligations.
Right to Object: you have the right to object to our processing of your personal data for purposes based on our legitimate interests. In some cases, we may be able to demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.
Right of Restriction: you have to right to request that we restrict the processing of your personal data (e.g. where you believe that the personal data we hold about you is inaccurate or unlawfully held).
Right to Data Portability: You may have the right to be provided with your personal information in a structured, machine readable and commonly used format and to request that we transfer the personal information provided by you to another data controller. Providing this does not comprimise:
- Our specific business IP
- Comprimise someone right to anonymity (offered by our service)
If you would like to exercise such rights, please contact us at firstname.lastname@example.org. Or please look on the landing page of your questionnaire for more options. To protect your privacy and security, we may take steps to verify your identity before complying with the request.
You also have the right to withdraw consent at any time where we are relying on consent to process your personal information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.
You also have the right to complain to a data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority. In the UK, this is the Information Commissioner’s Office https://ico.org.uk/.
5. How long we keep your information
Questionnaire Data: As standard we hold data for 5 years, our Clients may determine a different period of time when we contract with them, so if you have any questions about this please ask them directly.
Aside from Questionnaire Data we are likely to hold only very limited information about you. We typically retain technical information for no longer than a year from the date we collect it and will retain your contact information for no longer than 2 years after we have resolved your enquiry (unless we have a specific reason to retain it for longer, for example to comply with a legal requirement)
6. Security of your information
We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your PIIstored on our Sites or controlled by us.
Sensitive (special category) and private data exchange between you and our Sites happens over a SSL secured communication channel and is encrypted and protected with digital signatures.
While we use appropriate technical and operational measures to keep your PII secure, the transmission of information via the internet is not within our control and is not completely secure. Although we will do our best to protect your PII, we cannot guarantee the security of your PII sent to us by email. Any such transmission is at your own risk. Once we have received your PII, we will use strict procedures and security features to try to prevent unauthorised access.
Our data centre providers are ISO27001 certified, and your Questionnaire Data is encrypted on the servers at rest and in transit across the internet.
7. International transfers of information
Insightful Edge partner with clients around the globe.
As a result, we may transfer your personal information to countries outside the EEA (the EU member states plus Norway, Liechtenstein and Iceland) for the purposes set out in this privacy notice.
Where this is applicable, we take steps to make sure that when we transfer your personal information appropriate protection is in place. Often, this protection is set out under a contract with the Client or Individual who receives that information.
Last updated 23 May 2018
Reviewed Annually (unless prompted earlier by changes in legislation and / or business requirement)