This Privacy Policy describes how Semasio ( “we,” “our,” or “us”), collects, uses, and discloses data from and about you when you use a Semasio website or interact with us in a business-to-business commercial capacity, including as a self-service customer of the Semasio advertising technology platform. We refer to these services as “Business Services.”
This Privacy Policy only applies to our Business Services and does not apply to Semasio’s advertising technology platform. (Please see the Semasio Platform Privacy Policy for further details.)
This Privacy Policy explains the types of personal data we may collect or receive about individuals in connection with our Business Services, how we use, process and share that personal data, and your rights and choices regarding your personal data. When we say “you,” we are referring to individuals whose personal data we process in connection with our Business Services only. The term “personal data” as used in this privacy policy has the meaning ascribed to that phrase and equivalent terms under applicable laws.
We collect the categories of personal data identified below. We “sell” or “share” (as those terms are defined under California law) some of these categories of data for marketing purposes to third parties, such as data analytics providers and advertising technology vendors. We do not knowingly sell or share personal data about persons under the age of 16. Please visit our Privacy Choices page to opt out of the sale or sharing of your personal data, as well as targeted advertising based on your use of the Business Services. You may also choose to enable a universal tool that automatically communicates your opt-out preferences, such as the Global Privacy Control (“GPC”). We will process the GPC signal as a request to opt out.
A. Category of Personal Data Collected
Do we “sell” or “share” this category of data?
Identifiers/biographical information, including first and last name, postal and email address, phone number, and online identifiers.
Yes (online identifiers)
Personal data categories listed in the California Customer Records statute, such as your credit or debit card number.
No
Commercial information, such as the services you purchase from us
No
Internet or other electronic network activity information
Yes
Geolocation data
No
Professional or employment-related information
No
Education information
No
Inferences, meaning inferences drawn from other categories of personal data.
No
B. The Business and Commercial Purposes for Which We Collect and Use Your Personal Data
C. Retention
We will retain your personal data for as long as reasonably necessary to provide you with the Business Services and for marketing purposes, unless you opt out as described in our Privacy Policy. We may, however, retain information following your opt-out or withdrawal of consent where legally permitted or required (e.g., for a legal compliance, auditing, or accounting reason).
A. Information You Provide
We collect personal data from you:
B. Information We Automatically Collect
We and our advertising and analytics partners and vendors use a variety of technologies, such as cookies, tags, SDKs and scripts, to collect certain information about your activity on the Business Services.
The specific types of personal data that we and our vendors automatically collect include:
Cookies and Other Similar Technologies. Semasio and its vendors collect and store online identifiers (“Cookie IDs”) through the Business Services. Cookies are small files that enable Semasio and its vendors to store information related to an internet user on a personal computer or another device from visits to websites, and to “remember” a particular individual, on a particular web browser and your preferences and improve the use and functionality of our sites. They can also enable the delivery of relevant and personalized advertisements to you across the internet.
Third parties may place cookies (and similar technologies) on our sites, and the providers of these technologies may combine information collected from your interactions with the Business Services. These third parties may combine this data with information they collect from other sources and use the combined information for analytics and/or advertising purposes.
To learn more about your choices regarding the automatic collection and use of your personal data, please see the Your Privacy Choices and Rights section below.
C. Information We Receive from Third Parties
We may receive personal data from other sources, including online advertising networks and analytics providers, social media platforms, and companies such as data aggregators who may provide us with business-to-business marketing lists that supplement the data that we collect directly from you as a visitor to our website or a user of our Business Services.
D. Combination of Information
We may combine the personal data that we receive from various sources. We use, disclose, and protect combined personal data as described in this Privacy Policy.
We may disclose each category of personal data that we collect to the following categories of recipients:
We may disclose your personal data for other reasons that we will describe at the time of information collection or prior to disclosing your information.
We may aggregate and/or de-identify any information collected so that such information can no longer be linked to you or your device and thus has become anonymous information as that term or its equivalents are defined under the GDPR or other applicable laws. We may use such anonymous information that is not personal data for any purpose, including without limitation for research and marketing purposes, and may also share such data with any third parties, including advertisers, promotional partners, and sponsors, in our discretion.
If you are in the European Economic Area (EEA) or the United Kingdom, we collect personal data from or about you in connection with the Business Services on the basis of user consent or legitimate interest. Therefore, the legal bases for the purposes set out in Section 1.B below are your consent, Art. 6(1)(a) GDPR, and our legitimate interests as a controller, Art. 6(1)(a) GDPR.
The table below provides further details about the legal basis for the processing purposes described in Section 1 of this Policy.
Processing Purpose
Legal Basis
Categories of Personal Data
Provide the Business Services
Section 1.B.i
Legitimate interests (Art. 6(1)(f) GDPR).
We have a legitimate interest in operating our Business Services.
Communicate with You
Section 1.B.ii
Consent (Art. 6(1)(a) GDPR)
To Develop and Improve our Services
Section 1.B.iii
Legitimate interests (Art. 6(1)(f) GDPR).
We have a legitimate interest in operating our Business Services in a secure manner, and in auditing our processes for legal and other compliance purposes, in ensuring security and integrity, in debugging our Business Services to identify and repair errors that impair existing intended functionality and for short-term and transient use.
Comply with applicable laws and regulations and respond to lawful requests
Section 1.B.v
Legitimate interests (Art. 6(1)(f) GDPR).
We have a legitimate interest in complying with applicable legal obligations.
Establish, exercise or defend legal claims; protect rights or property
Section 1.B.vi
Legitimate interests (Art. 6(1)(f) GDPR).
We have a legitimate interest in the establishment, exercise and defence of legal claims, as well as the protection of our rights and property.
Sell or transfer business assets
Section I.B.vii
Legitimate interests (Art. 6(1)(f) GDPR).
We have a legitimate interest in disclosing and otherwise processing personal data as part of a corporate transaction.
A. Third-Party Opt Outs
You may opt out of online targeted ads in general by using the industry opt-outs described below. These opt-outs will not remove you from Semasio’s databases. Please see Section 9 of the Semasio Platform Privacy Policy to learn how to do so.
Some of these choices apply only to the specific browser or device from which you opt out, and you will need to opt out separately on each browsers or device you use. If you delete or reset your cookies or mobile identifiers, change browsers, or use a different device, any opt-out cookie or tool may no longer work and you will have to opt out again.
Even if you choose to opt out of receiving interest-based advertising, you may still receive advertising, but the advertisements may be less relevant.
B. Unsubscribing from our Marketing and Promotional Communications
From time to time, we may send you marketing and promotional communications, including special offers from us or our partners. If you no longer wish to receive promotional and marketing emails from us, you may opt out of such communications at any time by following the opt-out instructions included in any promotional or marketing email you receive from us.
C. Privacy Rights and Requests
Under the General Data Protection Regulation (“GDPR”) and other privacy laws depending on where you reside, you may have certain additional rights regarding your personal data as summarized below, subject to certain restrictions and variations under applicable local laws. This section describes how to exercise those rights and our process for handling your requests. We may withhold these rights to the extent that the law in your country or state of residence does not recognize or no longer recognizes these rights. To the extent permitted by applicable law, we may charge a reasonable fee to comply with your request.
Please note that, where permitted under applicable law, we may decline a request if we are unable to verify your identity (or an agent’s authority to make the request) and confirm the personal data we maintain relates to you.
If you are interested in exercising one or more of the rights (other than the right to opt out – use the instructions in Section 5.E) outlined above, please visit our Privacy Choices page, or you can contact us at privacy@semasio.com. You must put the statement “Your Privacy Rights” in the subject field of your email. We may take steps to verify your identity before responding to your request by asking you a series of questions about your previous interactions with us. Submitting a privacy rights request does not require you to create an account with us.
If you are a business-to-business client or potential business-to-business client who wishes to opt-out of our marketing lists or otherwise exercise your privacy rights with respect to your use of our Business Services, please contact us at privacy@semasio.com. You must put the statement “Privacy Request Business Services” in the subject field of your email.
We will not discriminate against you if you decide to exercise your privacy rights.
D. Agent Requests
Depending on the laws in your country or U.S. state of residence, you may authorize someone to make a privacy rights request on your behalf (an authorized agent). Only you, or someone legally authorized to act on your behalf, may submit a request related to your personal data. You may also submit a request on behalf of your minor child. Authorized agents will need to demonstrate that you’ve authorized them to act on your behalf. Semasio retains the right to request confirmation directly from you confirming that the agent is authorized to make such a request, or to request additional information to confirm the agent’s identity.
E. Opt-Out Requests
You may request to opt out of the sale or share of your personal data, or of targeted advertising, at any time by using our Privacy Choices page.
For opt-outs specific to your use of our website (online identifiers and internet or other electronic network activity information) in connection with our Business Services, our online opt-outs are cookie-based. Thus, if you browse the web from multiple browsers or devices, you may need to opt out from each browser and/or device, and for the same reason, if you change browsers or clear your browser cookie cache, you may need to perform this opt-out function again. Alternatively, you can use the browser-based Global Privacy Control (“GPC”) signal to exercise your sale and sharing opt-out right of our Business Services. We will treat a GPC opt-out signal as a valid request to opt out of the sale or sharing of personal data linked to that browser and any consumer profile we have associated with that browser. If you use different browsers or browser profiles, you will have to enable the signal on each browser or profile.
F. Right to Withdraw Consent
In situations where we rely on consent to process your personal data, you likewise may withdraw your consent at any time by visiting our Privacy Choices page to submit an opt-out request. You may also contact us toll-free at 833 367-8688. Please be aware that withdrawing your consent does not affect the lawfulness of the processing of your personal data based on consent before its withdrawal.
G. Right to Appeal
Depending on where you reside, you may have the right to appeal a decision we have made in connection with your privacy rights request. To appeal a decision, please contact us at privacy@semasio.com.
H. Additional Notice to EEA and UK Residents
For residents of the European Economic Area and United Kingdom, Semasio is the controller responsible for processing your personal data.
At any time, you may request or assert any of the rights above by emailing us at privacy@semasio.com. If you believe there has been a violation of your privacy rights, please contact us or the supervisory authority.
Our Services may have links to third-party services, which may have privacy policies that differ from our own. We are not responsible for the practices of such sites.
Our Services are intended for a general audience. We do not direct our Business Services to minors under the age of eighteen (18), nor do we knowingly solicit or collect any personal data from minors. If you are a parent or legal guardian and think that your child has given us data, you can contact us in writing or by email as provided below under Section 13, “How to Contact Us.” Please mark your inquiries “Minors’ Privacy Information Request.” If we learn that a minor has provided personal data through our Business Services, we will use reasonable efforts to remove such information from our files.
We have implemented physical, administrative, and technical safeguards to maintain the security, confidentiality, and integrity of your information. However, as no transmission of information over the internet is absolutely secure, we cannot guarantee the safety of your information.
We retain personal data in accordance with requirements of applicable laws as long as it is necessary for the purposes we pursue (set out in Section 1) or we have a legal or compliance reason to do so.
Semasio maintains data centers in the United States and Denmark. Please visit this page for a list of our service providers.
In some cases, we may transfer personal data of individuals residing in the European Union (EU) or the European Economic Area (EEA) to recipients located outside of the EEA, namely the United States.
Where a transfer of personal data to such third countries is taking place, this happens only to countries in which the EU Commission has confirmed an adequate level of protection (a list of these countries and the respective adequacy decisions is available here) or where Semasio can reasonably ensure the secure handling of personal data by means of contractual agreements (e.g., standard contractual clauses) or other suitable guarantees, including certifications or proven compliance with sufficient security standards. We apply these same standards to other jurisdictions that require similar protections.
You have the right to ask us for more information about the safeguards we have put in place as mentioned above. Please contact us using the contact information provided in Section 13 if you would like further information or to request a copy where the safeguard is documented (which may be redacted to ensure confidentiality).
Semasio may change or update this Privacy Policy at any time. Any changes or updates we may make will be posted on this website. If you have an account with us for our Business Services and we change the Privacy Policy in a material way, we will provide appropriate notice to you.
If you have questions related to this privacy policy, or regarding our products or services, please contact us at privacy@semasio.com or info@semasio.com.
Postal addresses:
Semasio GmbH
Mönkedamm 11
20457 Hamburg
Germany
Semasio Inc.
c/o Casters Holdings, Inc.
433 West Van Buren Street, Suite 200,
Chicago, IL 60607
Controller
Controller: If you are based in the European Union (EU) or the United Kingdom, the controller of your personal data is Semasio GmbH.
European data protection officer (DPO): If you are a based in the European Union (EU) or the United Kingdom, you may contact our data protection officer and state in your request that your concern relates to Semasio GmbH. However, we respectfully ask that you only contact our Data Protection Officer regarding urgent matters relating to data protection.
Prof. Dr. Christoph Bauer
ePrivacy GmbH
Große Bleichen 21
20354 Hamburg
Germany
Email: dpo@eprivacy.eu
Representative of controllers or processors not established in UK (Article 27 UK GDPR):
UK Representative Service for GDPR Ltd.
7 Savoy Court
London WC2R0EX
United Kingdom
Email: dpo.uk@eprivacy.eu