Privacy Policy

Effective as of February 16, 2022. Revised March 1, 2023.             

This “Privacy Policy” describes the privacy practices of Metric ESG, Inc. (“Metric”, “we”, “us”, or “our”) in connection with the www.metric-esg.com website, the Metric software, and any other website, application, or software that we own or control and which posts or links to this Privacy Policy (collectively, the “Service”).   Metric may provide additional or supplemental privacy policies or notices to individuals for specific products or services that we offer at the time we collect personal information. These supplemental privacy policies or notices will govern how we may process the information in the context of the specific product or service. Use of the Service are intended for our business customers and their employees.

Personal Information We Collect

Information you provide to us.  We collect the personal information you provide to us through or in connection with the Service or otherwise, as described below.

As a business customer, when you communicate with us about the Service or otherwise correspond with us, we may collect the following information from you:

  • Business contact information, such as your first and last name, email and mailing addresses, phone number, professional title and company name.

  • Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online.

  • Usage information, such as information about how you use the Service and interact with us.

  • Transaction information, such as information about payments to and from you and other details of products or services you have purchased from us.

  • Marketing information, such as your preferences for receiving communications about our activities, events, and publications, and details about how you engage with our communications.

As a business customer, when you create an account through the Service and use the Service, we may collect the following information from you and your users:

  • Profile information, such as your username and password that you may set to establish an account with us.

  • Content you choose to upload to the Service, such as text, raw data, along with the metadata associated with the files you upload.

  • Payment information, such as payment card information (billing name, credit card number, expiration data, CVV, and billing address) that is collected and processed by our payment processors Stripe and Intuit as further described below in the “How We Share Your Personal Information” section.

  • Usage information, such as information about how you use the Service and interact with us, including information associated with any content you upload to the Service or otherwise submit to us, and information you provide when you use any interactive features of the Service.

  • Registration information, such as information that may be related to a service, an account or an event you register for.

When you, as an employee of our business customers, participate in a survey (such as a Diversity, Equity, and Inclusion survey), we may collect the following information from you as a processor/service provider on behalf of such business customer:

  • Demographic and employment-related information, such as your employment status, length of employment, job function, and country of residence.

  • Sensitive categories of information, such as your race, ethnicity, gender, sexual orientation, veteran or military status, and disability.

  • Education information, such as the education you have completed.

Other information that we may collect which is not specifically listed here, but which we will use in accordance with this Privacy Policy or as otherwise disclosed at the time of collection.

Information we obtain from social media platforms. We may maintain pages for our Company on social media platforms, such as Facebook, LinkedIn, Twitter, Google, YouTube, Instagram, and other third party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use and processing of your personal information. You or the platforms may provide us with information through the platform, and we will treat such information in accordance with this Privacy Policy.

Information we obtain from third parties.  We may receive personal information about you from third-party sources. For example, a business partner may share your contact information with us if you have expressed interest in learning specifically about our products or services, or the types of products or services we offer. We may obtain your information from your employer as your employer may request that we conduct a survey on their behalf. We may obtain your personal information from other third parties, such as marketing partners, publicly-available sources and data providers.

Automatic data collection.  If you use our Service or communicate with us, we, our service providers, and our business partners may automatically log the following types of information about you, your computer or mobile device, and your interactions over time with us:

  • Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE, 3G), and general location information such as city, state or geographic area.

  • Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the website, navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, and whether you have opened our marketing emails or clicked links within them.

  • Location data when you authorize the Service to access your device’s location.

Cookies and similar technologies. Like many online services, we use the following technologies:

  • Cookies, which are text files that websites store on a visitor‘s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, helping us understand user activity and patterns, and facilitating analytics and online advertising.

  • Local storage technologies, like HTML5 and Flash, that provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications.

  • Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.

These technologies may be used for the following purposes:

  • Technical operation. To allow the technical operation of the Service, such as by remembering your selections and preferences as you navigate the site, and whether you are logged in when you visit password protected areas of the Service.

  • Analytics. To help us understand user activity on the Service, including which pages are most and least visited and how visitors move around the Service, as well as user interactions with our emails. For example, we use Google Analytics to learn more about the types of users that visit our website and to help improve our website. To provide this service, Google Analytics may collect certain information about you from your computer, including the pages you visit, the length of your visit, information about your device (such as your IP address), and other information about you. You can read more about Google Analytics and your privacy choices in the “Analytics” portion of the “Your Choices” section.  

How We Use Your Personal Information

We use your personal information for the purposes described below and as otherwise described in this Privacy Policy or at the time of collection.

Personal Information collected from our business customers:

To operate the Service.  We use your personal information to:

  • provide, operate and improve the Service

  • provide information about our products and services

  • establish and maintain your user profile on the Service

  • enable security features of the Service, such as by sending you security codes via email or SMS, and remembering devices from which you have previously logged in

  • communicate with you about the Service, including by sending you announcements, updates, security alerts, and support and administrative messages

  • communicate with you about surveys or events in which you participate

  • understand your needs and interests, and personalize your experience with the Service and our communications

  • provide support and maintenance for the Service

  • respond to your requests, questions and feedback

To send you marketing and promotional communications.  We may send you direct marketing communications. You will have the ability to opt-out of our marketing communications as described in the “Opt out of marketing communications” section below.

Personal Information collected from our business customers and/or their employees:

To operate the Service.  We use your personal information to:

  • provide, operate and improve the Service

  • enable security features of the Service, such as by sending you security codes via email or SMS, and remembering devices from which you have previously logged in

  • communicate with you about the Service

  • communicate with you about surveys or events in which you participate

  • provide support and maintenance for the Service

  • respond to your requests, questions and feedback

For research and development.  We analyze use of the Service to analyze and improve the Service and to develop new products and services, including by studying user demographics and use of the Service.

To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.

For compliance, fraud prevention, and safety.  We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

With your consent.  In some cases we may specifically ask for your consent to collect, use or share your personal information, such as when required by law. 

To create anonymous, aggregated or de-identified data.  We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect.  We make personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you.  We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business. 

How We Share Your Personal Information

We do not share your personal information with third parties without your consent, except in the following circumstances or as described in this Privacy Policy:

Affiliates.  We may share your personal information with our corporate parent, subsidiaries, and affiliates, for purposes consistent with this Privacy Policy.

Service providers.  We may share your personal information with third party companies and individuals that provide services on our behalf or help us operate the Service (such as customer support, hosting, analytics, email delivery, marketing, and database management services). These third parties may use your personal information only as directed or authorized by us and in a manner consistent with this Privacy Policy, and are prohibited from using or disclosing your information for any other purpose.

Payment processors. Any payment card information you use to make a purchase on the Service is collected and processed directly by our payment processors, Stripe and Intuit. Stripe and Intuit may use your information, including payment information, in accordance with their privacy policies, https://stripe.com/privacy and https://www.intuit.com/privacy/statement/.

Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.

For compliance, fraud prevention and safety. We may share your personal information for the compliance, fraud prevention and safety purposes described above.  

Business transfers.  We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.

Legal Bases for Information Processing

This section applies to users located in the EU or UK.

The General Data Protection Regulation (GDPR) and UK GDPR require explanation of the valid legal bases relied upon in order to process personal information. As such, Metric may rely on the following legal bases to process your personal information:

Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time by emailing privacy@metric-esg.com.

Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.

Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.

Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.

This section applies to users located in Canada.

Metric may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permissions can be inferred (i.e., implied consent). You can withdraw your consent at any time by emailing privacy@metric-esg.com.

In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:

  • If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way

  • For investigations and fraud detection and prevention

  • For business transactions provided certain conditions are met

  • If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim

  • If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province

  • If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records

  • If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced

  • If the information is publicly available and is specified by the regulations

Your Choices

In this section, we describe the rights and choices available to all users.

Access or Update Your Information. For our business customers, if you have registered for an account with us, you may review and update certain personal information in your account profile by logging into the account.

Opt out of marketing communications. Our business customers may receive marketing-related emails from us and may opt out of such emails by following the opt-out or unsubscribe instructions at the bottom of the email.  You may continue to receive service-related and other non-marketing emails. 

Cookies.  Most browser settings let you delete and reject cookies placed by websites. Many browsers accept cookies by default until you change your settings. If you do not accept cookies, you may not be able to use all functionality of the Service and it may not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit www.allaboutcookies.org.

Analytics. We may use Google Analytics to help us understand user activity on our Service. You can learn more about Google Analytics and how it collects and processes data by visiting https://policies.google.com/technologies/partner-sites. You can opt out of Google Analytics by using the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout/, or by disabling cookies on your browser.

Do Not Track.  Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit.  We currently do not respond to “Do Not Track” or similar signals.  To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

Choosing not to share your personal information. We need to collect personal information to provide certain services.  If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.

Other sites, mobile applications and services

The Service may contain links to other websites, mobile applications, and other online services operated by third parties.  In addition, our content may be included on web pages or in mobile applications or online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party.  We do not control third party websites, mobile applications or online services, and we are not responsible for their actions.  Other websites and services follow different rules regarding the collection, use and sharing of your personal information.  We encourage you to read the privacy policies of the other websites and mobile applications and online services you use.

Security practices

We employ organizational, technical and physical safeguards designed to protect the personal information we collect.  However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information.

International data transfers

We are headquartered in the United States and have service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, or country where privacy laws may not be as protective as those in your state, province, or country. 

Children  

The Service is not directed to, and we do not knowingly collect personal information from, anyone under the age of 16[A1] .  If a parent or guardian becomes aware that his or her child has provided us with information without their consent, he or she should contact us. We will delete such information from our files as soon as reasonably practicable.  We encourage parents with concerns to contact us[A1] .

Your California Privacy Rights

Under California Civil Code section 1798.83, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to us via email at privacy@metric-esg.com or via postal mail at 222 W. Merchandise Mart Plaza, Suite 1212, Chicago, IL 60654. You must put the statement "Your California Privacy Rights" in your request and include your name, street address, city, state, and ZIP code. We are not responsible for notices that are not labeled or sent properly, or do not have complete information.

Under the California Consumer Privacy Act (CCPA), you have the rights listed below.

The California Code of Regulations defines ‘residents’ as:

  • (1) every individual who is in the State of California for other than a temporary or transitory purpose and

  • (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose

Your rights with respect to your personal data:

Right to request deletion of the data. You can ask for the deletion of your personal information. If you ask Metric to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) our compliance requirements resulting from a legal obligation.

Right to be informed - request to know. Depending on the circumstances, you have a right to know:

  • whether we collect and use your personal information;

  • the categories of personal information that we collect;

  • the purposes for which the collected personal information is used;

  • whether we sell or share personal information to third parties;

  • the categories of personal information that we sold, shared, or disclosed for a business purpose;

  • the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose;

  • the business or commercial purpose for collecting, selling, or sharing personal information; and

  • the specific pieces of personal information we collected about you.

In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.

Right to non-discrimination for the Exercise of a Consumer’s Privacy Rights. We will not discriminate against you if you exercise your privacy rights.

Right to Limit Use and Disclosure of Sensitive Personal Information. We do not process consumer’s sensitive personal information.

Other privacy rights:

  • You may object to the processing of your personal information.

  • You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.

  • You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.

  • You may request to opt out from future selling or sharing of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.

To exercise these rights, you can contact us by email at privacy@metric-esg.com or referring to the contact details in the ‘How to Contact Us’ section.

Your EEA, UK, Switzerland, and Canada Privacy Rights

In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information; (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us using the contact details provided in the ‘How to Contact Us’ section below.

We will consider and act upon any request in accordance with applicable data protection laws.

If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.

If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section ‘How to Contact Us’ below or updating your preferences.

However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.

Account Information

If you would at any time like to review or change the information in your account or terminate your account, you can contact us using the information provided in the ‘How to Contact Us’ section.

Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.

Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service, such as our website or homepage of our software. We may, and if required by law will, also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through the Service.

Any modifications to this Privacy Policy will be effective upon our posting the new terms and/or upon implementation of the new changes on the Service (or as otherwise indicated at the time of posting). In all cases, your continued use of the Service after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.

How to Contact Us

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. to request to review, update, or delete your personal information, please email us at privacy@metric-esg.com

Please direct any further questions or comments about this Policy or privacy practices to privacy@metric-esg.com. You may also write to us via postal mail at:

            Metric ESG, Inc.

            Attn: Legal – Privacy

            222 W. Merchandise Mart Plaza, Suite 1212

Chicago, IL 60654