Privacy Policy

ROCKBRIDGE ASSOCIATES, INC.

Effective Date: October 2013
Last Updated: July 24, 2019

COMMITMENT TO PRIVACY AND SURVEY RESEARCH ETHICAL STANDARDS

Rockbridge Associates is a full-service custom market research firm that conducts qualitative and quantitative studies with consumers and businesses. We are committed to respecting and protecting your privacy whether you are a research respondent who is participating in a study or an individual visiting our website to obtain information about our services. This Privacy Policy explains how we collect, store, use and transfer data that we obtain via our own website or through surveys and other primary research methods used on behalf of our clients.

We respect your right to refuse to participate in a study, to respond to specific questions, or to withdraw your permission to be contacted in the future.

We are a member of the Insights Association, the professional association for survey research organizations. As a member, we adhere to the Insights Association Code of Standards and Ethics for Marketing Research and Data Analytics in the conduct of our research.

If you have any concerns about the information we collect and store or how it is used, please contact our Data Protection Officer (DPO) at privacy@rockresearch.com, or write to us at:

Privacy Office
Rockbridge Associates, Inc.
10130-G Colvin Run Road
Great Falls, VA  22066

If you are visiting our website or are participating in one of our research studies from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. While the data protection and other laws of the U.S. might not be as restrictive as those in your country, please be assured that we take steps to ensure that your privacy is protected. As further described below, we participate in the EU-U.S. Privacy Shield and the US-Swiss Privacy Shield programs that help U.S. companies comply with European and Swiss privacy laws and rules concerning the transfer of Personal Data from the European Union (“EU”) and from Switzerland to the United States.

TYPES OF INFORMATION WE COLLECT

  1. Personal Data is any type of information, including information transferred from the EU or Switzerland to the United States, recorded in any form, that may be used to identify a specific individual. We may collect a variety of Personal Data from you, including but not limited to your full name, non-governmental identification numbers, date of birth, gender, mailing address, phone numbers, email address and other similar information. We may also collect information about your personal opinions and preferences.
  2. We may collect Personal Data from you directly when you voluntarily provide it to us (for example, through a contact form or on Opinion Pond) or we may obtain Personal Data from clients who ask us to conduct research on their behalf. We may also obtain Personal Data from list providers who have assured us that their lists are made up only of individuals who have given their permission to be included in the list.
  3. We may collect and use Personal Data obtained from publicly available sources, where this is permitted by law.
  4. We may occasionally collect Personal Data that reveals race, ethnic origin, sexual orientation, political opinions, religious or philosophical beliefs, genetic data, biometric data, trade union membership or that concerns an individual’s health (“Sensitive Data”). We will not collect such Sensitive Data without your consent, and will fully comply with all legal restrictions related to the collection, storage, use and transfer of such Sensitive Data.
  5. We will never ask you for certain information which, if stolen or misused, could give rise to economic crimes against you, such as bank account or credit card numbers, social security or other similar government-issued ID numbers.
  6. We may also automatically collect a variety of publicly available information, such as IP address and device ID, for system administration, service improvement and data integrity purposes.
  7. You may provide personal information to us when you contact us through our website seeking information about our services. We will treat this information as confidential Personal Data.

HOW WE SHARE YOUR INFORMATION

  1. If you provide information to us in order to inquire about our services, we will only use that information to contact you about our services. We will not sell or provide your information to any third party for any other use. By submitting this Personal Data through our website contact form, you are consenting to us sharing your personal information within Rockbridge Associates. For more information about Rockbridge Associates, please see our website: http://rockresearch.com/
  2. We may share your Personal Data with employees of our company for the purpose of analyzing survey responses.
  3. In some circumstances, in order to gain your participation in Internet-based, telephone or in-person survey research, we may transfer your name and email address or your name and telephone number to a marketing research field service facility, to a professional interviewer located in your home country, or to a company that operates Internet based research platforms such as ConfirmIt, Qualtrics, Medallia. Before doing so we will ensure that the third party provides and agrees in writing to provide an adequate level of protection and will not use it for any other purpose.
  4. In some circumstances, with your permission and where it is legal to do so, we may transfer your name and email address to a fulfillment company in order to send you an e-gift card as a “thank you” incentive for participating in survey research. Before doing so we will ensure that the fulfillment company provides and agrees in writing to provide an adequate level of protection for your personal information and will not use it for any other purpose. If you provide personal information in a survey or other research instrument to which you are responding, we will anonymize your response and will not supply any information that could personally identify you to any other entity, including our clients, without your permission.
  5. Rockbridge Associates may be required to disclose an individual’s Personal Data in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

HOW WE USE INFORMATION YOU PROVIDE

  1. The information collected in a research context may be used to plan new products or services, gauge customer/member satisfaction, measure awareness of products or services, or to test reaction to products, services or communications.
  2. Even if certain information is not considered Personal Data, we will protect the anonymity of your responses to questionnaires, in focus groups, on research websites or from any means of collecting feedback from you in a research context. If we obtain your contact information from a research panel or other third party, we will comply with the contact limitations and data protections that you agreed to when you signed up to participate in survey research or when you became a customer of a third party.
  3. We may occasionally re-contact you to validate your participation in a research study; we will identify ourselves and our purpose when we conduct such validation contacts.
  4. Most research surveys include demographic questions collecting Sensitive Data such as racial or ethnic origin, age, gender or income. We use these questions to help us make sure that the research reflects a representative sample of the population we are studying.
  5. If we receive your contact information from a list or panel company, we will use it only in order to ask you to participate in marketing research, to conduct survey research with you, to validate answers you give, and to respond to your requests to us or our client. We select panel companies that adhere to an opt-in process in obtaining panelists and have an adequate policy for protecting the privacy of panelists. We will also not use your information in any other way that is inconsistent with the research or other purpose for which you agreed to be contacted.
  6. If we receive your contact information from our client and you are a customer of that client, we will only use your contact information to ask you to participate in marketing research. We will not use this information to sell you any goods or services. We will protect your anonymity when communicating your research responses to clients unless you have explicitly given permission for your identity and contact information to be shared with our client or you have specifically asked us to give that information to our client so that they may resolve questions or complaints you may have.
  7. Whether we obtain your Personal Data from a list company or from clients, we will not use this information to sell you any goods or services and we will not provide your contact information to any other party so that they may use that contact information for the purpose of directly selling you goods or services. We will share your Personal Data with our clients only with your specific permission or at your request, or with restrictions as permitted by the Insights Association Code of Standards and Ethics for Marketing Research and Data Analytics.

LEGAL BASES FOR PROCESSING

We may process your Personal Data where you have given your consent to such processing for one or more specific purposes, where processing is necessary for complying with our legal obligations, where necessary to protect your vital interests or those of another natural person, or where necessary for the purposes of the legitimate interests pursued by Rockbridge Associates or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Where processing is based on your consent, you have the right to withdraw consent at any time; however, this will not affect the lawfulness of processing based on consent before its withdrawal.

COOKIES

Cookies are small files which a site or its service provider transfers to your computer’s hard drive through your web browser (if you allow) and which enable the site’s or service provider’s systems to recognize your browser and capture and remember certain information.

For example, we use cookies to help us compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future.

Through your browser’s settings, you can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. Since each browser is a little different, look at your browser’s help menu to learn the correct way to modify your cookies.

PERSONAL DATA RETENTION

We will only retain your information, including Personal Data, for as long as necessary to fulfill the purposes for which we collected it and as permissible by applicable law. To determine the appropriate retention period for information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of your information, the purposes for which we process your information and whether we can achieve those purposes through other means, and the applicable legal requirements.

ADHERENCE TO EU-U.S. AND SWISS-U.S. PRIVACY SHIELD PRINCIPLES

Rockbridge Associates complies with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, respectively. Rockbridge Associates has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program and to view our certification please visit http://www.privacyshield.gov/. Rockbridge subjects itself to the investigatory and enforcement powers of the Federal Trade Commission (FTC).

PRIVACY SHIELD PRINCIPLES

Notice

This Privacy Policy is to notify you of the purpose for which we are collecting and using your Personal Data and the type of non-agent third parties to which we may disclose that information. See the section above titled “How We Use Information You Provide.”

Choice

You have the opportunity to choose whether your Personal Data is to be disclosed to a third party or used for a purpose other than the purpose for which it was originally collected or subsequently authorized by you. When we invite you to participate in a web-based survey we give you a link to allow you to opt out of further communications regarding the survey. If we contact you by telephone or mail requesting your response to a survey, you are free to decline to participate. Otherwise, you can contact us and exercise your right to choose by contacting us at the information provided in this Privacy Policy.

Accountability for Onward Transfers

We will ensure that any third party to which Personal Data may be disclosed subscribes to the Principles and agrees in writing to provide an adequate level of privacy protection. Pursuant to the Privacy Shield Principles, Rockbridge Associates may face potential liability in cases of improper transfers of Privacy Shield data to third parties.

Data Security

We take reasonable steps to protect your Personal Data from loss, misuse and unauthorized access, disclosure, alteration and destruction. We have put in place appropriate physical, electronic and managerial procedures to safeguard and secure your Personal Data from loss, misuse, unauthorized access or disclosure, alteration or destruction, but we cannot guarantee the security of information on or transmitted via the internet.

Data Integrity and Purpose Limitation

We will only process Personal Data in a way that is compatible with and relevant to the purpose for which it was collected or authorized by you. To the extent necessary for those purposes, we will take reasonable steps to ensure that your Personal Data is accurate, complete, current and reliable for its intended use. We will limit use of your Personal Data to the use we disclosed to you when we collected it. Prior to using any Personal Data for another purpose we will notify you and obtain your permission.

Access

We acknowledge your right to access your Personal Data and to correct, amend or delete Personal Data, except where the burden or expense of providing access would be disproportionate to the risks to your privacy in the case in question or where the rights of persons other than you would be violated. To access your Personal Data, contact us at the information provided in this Privacy Policy.

Recourse, Enforcement and Liability

In compliance with the EU-U.S. and Swiss-U.S. Privacy Shield Principles, Rockbridge Associates commits to respond to complaints about your privacy and our collection or use of your personal information within 45 days. European Union or Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact Rockbridge Associates at: privacy@rockresearch.com

Or you can write to us at:

Privacy Office
Rockbridge Associates, Inc.
10130-G Colvin Run Road
Great Falls, VA  22066

Further Recourse for European and Swiss Individuals:

Rockbridge Associates has further committed to refer unresolved privacy complaints under the EU-U.S. and Swiss-U.S. Privacy Shield Principles to BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint. This dispute resolution process will be free of charge to you.

Under certain limited conditions, an individual may invoke “last resort” binding arbitration.

CHILDREN’S PRIVACY

Our general website does not direct any services to children, and we require parental consent for participation from all individuals under 18 years of age. If we gain actual knowledge that a child under the age of 18 has provided any personal information to us without the parent’s or guardian’s consent, we will use that information only to respond directly to that child to inform him or her that we must have parental consent before receiving his or her personal information.

EXTERNAL LINKS

If our general website or any survey we conduct links you to other sites, those sites do not operate under this Privacy Policy. We recommend you examine the privacy statements posted on those other websites to understand their procedures for collecting, using, and disclosing personal information.

DO NOT TRACK

Please note we do not respond to “do not track” (DNT) signals in browsers because no DNT standard has been adopted. If a DNT browser mechanism is in place, we will still track, plant cookies, or use advertising as described in this Privacy Policy.

CHANGES TO THIS PRIVACY NOTICE

This Privacy Policy may be amended from time to time. We will notify you about material changes to this Privacy Policy by sending a notice to the email address you provided to us or by placing a prominent notice on our website or on our surveys.