1. | OUR APPROACH TO PRIVACY |
1.1 | Criteria Corp. ("Criteria", "we", "our", or "us") is committed to protecting and respecting your privacy. This privacy policy sets out how we collect, store, process, transfer, share and use data that identifies or is associated with you ("personal information") and information regarding our use of cookies and similar technologies. |
1.2 | Criteria operates an employee and applicant testing platform that allows potential or current employees to take aptitude, personality and skills tests through our website at www.ondemandassessment.com (the "Service"). |
1.3 | Before accessing or using our Service, please ensure that you have read and understood our collection, storage, use and disclosure of your personal information as described in this privacy policy. |
2. | IDENTITY OF THE DATA CONTROLLER |
2.1 | Criteria Corp is a data controller of the personal information we hold about you. The company on whose behalf you are taking tests (the âEmployerâ) and Insight Venture Management, L.L.C, a company described in Section 3.10(a) below, are also data controllers of some information we collect. |
3. |
PERSONAL INFORMATION WE COLLECT ABOUT YOU
The personal information we may collect from you directly |
3.1 | We collect personal information that you voluntarily submit directly to us when you use our Service. This can include information you provide to us when you fill in a form on our Service, respond to questions, take a test on our Service or upload any documents (such as CVs) through the Service. |
3.2 | We will indicate to you if the provision of certain personal information is mandatory or optional. If you choose not to provide any personal information marked as mandatory, we may not be able to perform our obligations to you, and the prospective or current employer that asked you to use our Service (the "Employer") may not be able to process your application or perform some of its obligations to you. |
3.3 |
The list below sets out the categories of personal information we collect about you:
|
3.4 |
We may use this information to:
|
3.5 |
The processing of the above personal information is necessary for:
Personal information we may collect automatically |
3.6 |
We also automatically collect the following personal information indirectly about how you access and use the Service and information about the device you use to access the Service:
|
3.7 | We may use the information we collect automatically to present our Service to you on your device and to determine products and services that may be of interest to you for marketing purposes. We may also use the personal information we collect from you to monitor and improve our Service and business, and to help us to develop new products and services. |
3.8 | The processing of the personal information we collect from you automatically is necessary for our legitimate interests, namely: to tailor our Service to the user and to improve our Service generally; to monitor and resolve issues; for marketing purposes; to communicate with users; to contact users; and for the detection and prevention of fraud. |
3.9 |
We may anonymise and aggregate any of the personal information we collect (so that it does not directly identify you). We may use anonymised information for purposes that include testing our IT systems, research, data analysis, improving our Service and developing new products and features. We may also share such anonymised information with others.
The categories of recipients to which we may transfer your personal information |
3.10 |
As required in accordance with how we use your personal information, we may share your personal information with the following:
|
4. | COOKIES AND SIMILAR TECHNOLOGIES |
4.1 | Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our website. |
4.2 | Cookies are pieces of code that allow for personalisation of our website experience by saving your information such as user ID and other preferences. A cookie is a small data file that we transfer to your computer's hard disk for record-keeping purposes. |
4.3 |
We use the following types of cookies:
|
4.4 | The cookies we use are designed to help you get the most from our Service but if you do not wish to receive cookies, most browsers allow you to change your cookie settings. Please note that if you choose to refuse cookies you may not be able to use the full functionality of our Service. These settings will typically be found in the "options" or "preferences" menu of your browser. In order to understand these settings, the following links may be helpful, otherwise you should use the "Help" option in your browser for more details. |
4.5 | We may also employ clear gifs (also known as web beacons) which are used to anonymously track the online usage patterns of our users. In addition, we may also use clear gifs in HTML-based emails sent to our users to track which emails are opened and which links are clicked by recipients. The information allows for more accurate reporting and improvement of our Service. |
4.6 | To learn more about cookies, clear gifs/web beacons and related technologies and how you may opt-out of some of this tracking, you may wish to visit http://www.allaboutcookies.org. |
4.7 |
If you only want to limit third party advertising cookies and similar technologies, you can opt out of receiving certain targeted advertising by visiting the following links (please bear in mind that there are many more companies listed on these sites than those that drop cookies via our website):
|
5. | OPTIONAL DEMOGRAPHIC INFORMATION AND CONSENT |
5.1 | Depending upon your location, we may ask to collect the Demographic Information described in Section 3.3(d) above, such as information about your ethnicity. We will need your consent to use this information as described in this privacy policy. You do not have to give us consent and, where you have given us consent to collect and use your personal data in this way, you may withdraw your consent at any time. If you wish to withdraw any consent that you have given us, please contact us using the details at the end of this privacy policy. |
6. | STORING AND TRANSFERRING YOUR PERSONAL INFORMATION |
6.1 | Security. We implement appropriate technical and organisational measures to protect your personal information against accidental or unlawful destruction, loss, change or damage. All personal information we collect will be stored on our secure servers and all transfers of personal information are protected by TLS encryption technology. We will never send you unsolicited emails or contact you by phone requesting your account ID, password, credit or debit card information or national identification numbers. |
6.2 | Retention Periods. We will store the personal information we collect for our own purposes for no longer than necessary for the purposes set out and in accordance with our legal obligations and legitimate business interests. Your Employer may have their own policies regarding how long they store the information we collect on their behalf â please refer to any privacy policies provided by your Employer or contact your Employer directly using the contact details below to find out more. |
6.3 | International Transfers of your Personal Information. As we are located in the USA, any information we collect from you for our own purposes or on behalf of an Employer will initially be collected and stored in the USA. If you are in the EU or EEA, this may mean that your personal information will be stored in a jurisdiction that offers a level of protection that may, in certain instances, be less protective of your personal information than the jurisdiction you are typically resident in. |
6.4 | We will take reasonable steps to ensure that your personal information is treated securely and in accordance with applicable law and this privacy policy. |
6.5 | Privacy Shield. We comply with the EU-U.S. Privacy Shield framework and Swiss-U.S. Privacy Shield framework as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal information received from European Union countries and Switzerland (the "Privacy Shield"). We have certified that we adhere to the Privacy Principles of notice, choice, accountability for onward transfer, security, data integrity, purpose limitation, access, and recourse, enforcement and liability ("Principles"). If there is any conflict between the policies in this policy and the Principles, the Principles shall govern. To learn more about Privacy Shield, please visit the U.S. Department of Commerce Privacy Shield website: https://www.privacyshield.gov/. For more information regarding our Privacy Shield certification, please see: https://www.privacyshield.gov/list. |
6.6 | If you wish to enquire further about the safeguards we use, please contact us using the details set out at the end of this privacy policy. |
7. | YOUR RIGHTS IN RESPECT OF YOUR PERSONAL INFORMATION |
7.1 |
If you are resident in the European Union, in accordance with European Union privacy law, you have the following rights in respect of your personal information that we or the Employer holds:
|
7.2 | If you wish to exercise one of these rights, please contact us using the contact details at the end of this privacy policy. We will notify the other data controllers of your communication. We will, in our capacity as a data controller, honour your requests according to applicable law. We will also contact the Employer and Insight, who may also have obligations to fulfil your requests with respect to their control of your data. |
7.3 | Residents in other jurisdictions may have similar rights to the above. If you would like to exercise one of these rights, please contact us and Insight using the contact details at the end of this privacy policy. We will comply with any request to the extent required under applicable law. |
8. | JURISDICTION AND ENFORCEMENT |
8.1 | As part of our participation in the Privacy Shield, we are subject to the investigatory and enforcement powers of the US Federal Trade Commission (FTC). |
8.2 | You also have the right to lodge a complaint to your local data protection authority. Further information about how to contact your local data protection authority is available at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm. |
8.3 | In compliance with the EU-US and Swiss-US Privacy Shield Principles, we commit to resolve complaints about your privacy and our collection or use of your personal information. European Union or Swiss individuals with inquiries or complaints regarding this privacy policy should first contact us using the contact information listed below. |
8.4 | We have further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the JAMS Privacy Shield Program. Under certain conditions specified by the Principles, you may also be able to invoke binding arbitration to resolve your complaint. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.jamsadr.com/eu-us-privacy-shield for more information and to file a complaint. |
9. |
LINKS TO THIRD PARTY SITES
Our Service may, from time to time, contain links to and from third party websites, including those of other users, our partner networks, advertisers, partner merchants, news publications, retailers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. Please check the individual policies before you submit any information to those websites. |
10. |
OUR POLICY TOWARDS CHILDREN
Our Service is not directed at persons under 16 and we do not knowingly collect personal information from children under 16. If you become aware that your child has provided us with personal information, without your consent, then please contact us using the details below so that we can take steps to remove such information and terminate any account your child has created with us. |
11. |
CHANGES TO THIS POLICY
We may update this privacy policy from time to time and so you should review this page periodically. When we change this privacy policy in a material way, we will update the "last modified" date at the end of this privacy policy. Changes to this privacy policy are effective when they are posted on this page. |
12. |
NOTICE TO YOU
If we need to provide you with information about something, whether for legal, marketing or other business related purposes, we will select what we believe is the best way to get in contact with you. We will usually do this through email or by placing a notice on our Service. |
13. | CONTACTING CRITERIA AND INSIGHT |
13.1 | If you are based in the EU, the Criteria Corp representative is [***]. Regardless of your location, please contact criteriaprivacy@criteriacorp.com. If you have any questions, comments and requests regarding your personal information. You may contact Insight directly at datainquiries@insightpartners.com. |
13.2 | This privacy policy was last modified on May 31, 2018. |