IDEOPrivacy Policy

This Privacy Policy applies to ideo.com, ideo.cn, jp.ideo.com, ideocolab.com, openideo.com, ideou.com, creativeconfidence.com, ideodesignthinking.cn, and creativetensions.com, including their subdomains, all of which are owned and operated by IDEO (the “Site(s)”). This Privacy Policy describes how IDEO (“we”, IDEO or “us”) collects, uses, shares and secures the personal information you provide in relation to the Sites only and does not represent all privacy practices conducted by us in our other businesses. It describes your choices regarding use, access and correction of your personal information. The use of information collected through the Sites shall be limited to the purposes of: (i) providing the service for which a client of IDEO (“Client”) has engaged IDEO; (ii) providing a service to you and other Users of the Sites (“Users”); and/or (iii) the purpose for which you signed up to receive communications from us. You acknowledge and consent that information you send to IDEO may be sent outside your country of origin according to the terms of this Privacy Policy.

IDEO (including the Sites as listed above) complies with all applicable privacy laws, including the following:

  • California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively “CCPA”) and other U.S. state-level privacy laws currently in force,
  • and the Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法) (“PIPL”) as to data collected from residents of China (if any).
  • General Data Protection Regulation of the E.U. (“GDPR”) as applicable to data collected from E.U. residents, 
  • UK Data Protection Act of 2018 (“UK GDPR”) as applicable to data collected from UK residents, 
  • Act on the Protection of Personal Information (個人情報保護法) (“APPI”) as to data collected from residents of Japan,
  • Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法) (“PIPL”) as to data collected from residents of China.

Should you have any questions about our data protection measures, the processing of your data or the protection of your rights as a data subject, you can contact IDEO and our external data protection officer as follows:

US/UK/EU Data Protection Officer & EU/UK Representative of controllers or processors not established in the European Union (Article 27 GDPR)

ePrivacy Holding GmbH
represented by Prof. Dr. Christoph Bauer
Burchardstraße 14, 20095
Hamburg, Germany
www.eprivacy.eu/en/legal

Name and Contact Details of the responsible Parties
IDEO LP

2525 16th Street
San Francisco, California
94103, USA

IDEO Creative Design (Shanghai) Co. Ltd.

Building 11, Columbia Circle, No. 1262 Yan’an W(est) Rd.
Changning District, Shanghai, 200050
People’s Republic of China

If you have any questions or concerns regarding your personal information, please contact privacynotice@ideo.com. If you wish to communicate directly with our data protection officer (because you have a particularly sensitive matter for example), please contact them by post, as communication by e-mail could always have security gaps. Please state in your request the company your concern relates to.

1. INFORMATION WE COLLECT AND HOW WE USE IT

PERSONAL INFORMATION: The type of information we collect from you depends on how you use our Sites and whether or not you are a former employee. Generally, when using our Sites, we may collect personal information in two ways: (i) you provide it to us, or (ii) it is collected automatically.

(i) Information provided by you

You may provide personal information to us, such as your first and last name, contact information, email address, image, Username, physical address, and contents of your communication. You may also provide payment information to our third-party payment processors. Information that could be used to identify or contact you is considered “Personal Information” under this Privacy Policy.

We may use your information, including your Personal Information, for the following purposes, and we only collect the minimum amount of Personal Information about you that we consider necessary for achieving these purposes:

  • To better understand how Users access and use our Sites, both on an aggregated and individual User basis, on individual Sites and across them in order to improve our Sites and respond to User desires and preferences, and for other research and analytical purposes;
  • To provide our services to you, which may include communicating with you about your use of our Sites and services, responding to your inquiries, troubleshooting problems, working with our third-party providers to process your orders and for other customer service purposes;
  • To tailor the content and information that we may send or display to you, provide personalized help and instructions, and to otherwise personalize your experiences while using the Sites;
  • With your consent, for marketing, and promotional purposes, including, for example, to send you news and newsletters, promotions;
  • To contact you about projects, opportunities or information we think may interest you provided you have opted into receiving such communications from us;
  • To administer surveys and questionnaires;
  • To protect our own rights and interests, such as to resolve any disputes, enforce our Terms of Use, and to respond to legal requests;
  • In the interests of educational research around IDEO values and teachings such as human-centered approaches and design thinking. IDEO has affiliations with many educational establishments including but not limited to Harvard and Stanford University for this purpose; and,
  • To allow you to access and register for our services more easily (e.g., in the setting up of personal profile accounts through third-party accounts and social media applications to which you may be already subscribed.
  • To collect personal correspondence, such as email, from you or other Users or third-parties corresponding about your activities or postings on the Site
  • To collect, process, and share Personal Information sent in response to a job posting (e.g., your resume) solely for the purpose of evaluating of your job application.

Categories of personal information collected from UK and EU residents processed on basis of EU and UK GDPR

Please refer to the charts in Section 5 for the categories and uses of personal data.

Health related market research in the UK/EU/EEA

When IDEO performs market research in the UK/EU/EEA for a client in the medical or healthcare sector, the research may include participants like:

  1. people with specific health conditions,
  2. people who use certain healthcare services, medicines or medical devices,
  3. people who act as carers for people referred to in (a) or (b) above, and
  4. healthcare professionals.

If you join such research and you tell IDEO about:

  1. an adverse event,
  2. a product complaint; or
  3. a serious reporting situation,

in respect of medicines and medical devices, IDEO may need to report the details that you have told us about to the company that asked us to perform the research.

This reporting enables the company to comply with its legal pharmacovigilance obligations, which aim to ensure the safety of such products.

When making a report, IDEO may include your contact information - such as your name and contact details, the country in which you are located, if you are a healthcare professional, your professional details. However, such information will only be shared by IDEO in accordance with the law or with your consent.

Sharing this information helps the company that asked us to perform research learn more about the adverse event or other issue that you shared with IDEO. This also enables the company to comply with its legal pharmacovigilance obligations, which aim to ensure the safety of such products.

NON-IDENTIFYING INFORMATION:

Certain information that does not identify you (“Non-Identifying Information”) could be considered a part of your Personal Information if it were combined with other identifiers (for example, combining your first name with your last name) in a way that enables you to be identified. But the same pieces of information are considered Non-Identifying Information when they are taken alone or combined only with other Non-Identifying Information (for example, your country and gender). We may combine your Personal Information with Non-Identifying Information and aggregate it with information collected from other Users of the Sites to attempt to provide you with a better experience, to improve the quality and value of the Sites, and to analyze and understand how the Sites are used. We may also use the combined information without aggregating it to serve you specifically, for instance to deliver a product or service to you according to your preferences or restrictions, or to send you User surveys or requests for feedback. We may collect any Personal Information you provide through such surveys or calls for feedback.

(ii) Information collected automatically

In general, IDEO will gather some technical information automatically, such as to improve our Sites’ performance on your browser. This information includes your Internet Protocol (“IP”) address (often associated with the portal through which you enter the Internet, like your Internet service provider (“ISP”), your company or your university), browser type, referring/exit pages, the files viewed on our Site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data. IDEO gathers this information using third-party services such as Google Analytics and HubSpot for the purpose of monitoring website performance and determining customer service and Site needs. Please visit the privacy policies of these third parties to learn about their privacy practices and your opt-out choices.

SOCIAL MEDIA INFORMATION:

When you have interacted with IDEO Sites content or even employees, through channels such as social media channels we may collect this information using an automated marketing tool, Hubspot. This means that where you have provided certain information (e.g., your email address) to us before and/or have opted in to receiving communications from IDEO, we may use your interactions with us on social media, combined with information we already have about you to establish your preferences and provide more targeted content. Hubspot may retain details of your publicly available social media handle such as your @address pursuant to its Privacy Policy(https://legal.hubspot.com/privacy-policy). Please see our IDEO Newsletters and Events section for further detail around Hubspot and our marketing practices.

COOKIES AND SIMILAR TRACKING TECHNOLOGIES:

When you visit the Sites, we and our partners may use cookies or similar technologies to analyze trends, administer the Sites, gather demographic information about our User base as a whole, and track Users’ movements around the Sites, including, in the case of cookies such as Hotjar, activity on individual pages in real-time (you may opt out of Hotjar here). A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you browse our Sites; cookies contain information that is transferred to your computer's hard drive. Our Sites use cookies to distinguish you from other Users of our Sites. This helps us to provide you with a positive experience when you browse our Sites and also allows us to improve our Sites and services.

We use the following categories of cookies:

  • Strictly necessary cookies: These are cookies that are required for the operation of our Sites. They include, for example, cookies that enable you to log into secure areas of our Sites.
  • Analytical/performance cookies: They allow us to recognize and count the number of visitors and to see how visitors move around our Sites when they are using them. This helps us to improve the way our Sites work, for example, by ensuring that Users are finding what they are looking for easily.
  • Functionality cookies: These are used to recognize you when you return to our Sites. This enables us to personalize our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
  • Targeting cookies: If you opt in, these cookies record your visit to our Sites, the pages you have visited and the links you have followed. We will use this information to make our Site more relevant to your interests, but also to ensure that we are aligning our Site in the best way with our target visitors. Our third-party partner may use cookies or similar technologies in order to provide you advertising based upon your browsing activities and interests. Please note you will continue to receive generic ads.

Most browsers are initially set up to accept cookies, but you can set your cookie preferences in the banner that appears on all IDEO websites listed above or reset your browser to refuse all cookies or to indicate when a cookie is being sent. If you choose to disable cookies, it may limit your use of certain features or functions on our Sites or services. If you wish to restrict or block the cookies that are set by any website you should do this through each individual browser setting and on each device you use to access the Internet (for these Sites, you can set those preferences in the cookie banner that appears on all IDEO Sites listed above). You can allow cookies from specific websites by making them “trusted websites” in your Internet browser. For more information on how to do this, and how to change your browser settings, you may visit: www.allaboutcookies.org.

LOG DATA:

When you visit the Sites, whether through an account or as a non-registered User browsing, we automatically track certain information that your browser sends whenever you visit our Sites. We use this information to do internal research on our Users’ demographics, interests, and behavior to better understand and protect you and our community. This information may include the URL that you just came from, which URL you go to next, access times and dates, your computer browser information, your IP address, and other statistics (“Log Data”). We use Log Data to monitor and analyze the use of the services on the Sites and for the Sites’ technical administration, to increase our Sites’ functionality and User-friendliness, and to better tailor the Sites to our Users’ needs. For example, some of the information is collected so that when you visit the Sites again, we will recognize you and provide you with information appropriate to your interests. We also use the information to verify that the visitors to our Sites met the criteria to process their requests.

OPT-OUT MECHANISMS:

Currently, our systems recognize browser “do-not-track” requests. You may also disable certain tracking as discussed in this section (e.g., by disabling cookies) and you may opt-out of Internet-based advertising by following the instructions above in this Cookies section.

REGARDING CHILDREN AND MINORS:

We do not knowingly collect Personal Information from Users under the age of 13 or the applicable age established by the laws in your jurisdiction (“Child” or “Children”). If IDEO learns that a Child’s Personal Information has been collected, we will delete the account. If parents or guardians believe that we have unintentionally collected their Child’s Personal Information, they should contact us to request the deletion of the information at privacynotice@ideo.com.

2. DISCLOSURE OF YOUR INFORMATION

OTHER CORPORATE ENTITIES:

We may share your information, including your Personal Information, Non-Identifying Information and Log Data, with our affiliates, subsidiaries, and branch offices in the United States and internationally, and with third parties who provide services on our behalf to help with our business activities such as providing email distribution services, customer service, or technical support. These companies are authorized to use your Personal Information only as necessary to provide these services to us pursuant to our written agreements with them. To the extent that these entities have access to your information, they will treat it at least as protectively as they treat information they obtain from their other Users. These entities follow privacy practices no less protective of our Users than our practices described in this Privacy Policy, to the extent allowed by applicable law. We do not share or sell your email address or contact information or any third parties’ email addresses with any third parties outside of the terms stated in this section of our Privacy Policy (“Disclosure of Your Information”).

We may share some or all of your Personal Information with another business entity should we plan to reorganize, spin out, merge with, acquire, or be acquired by that business entity. Should such an event occur, we will require that the new or combined entity follow this Privacy Policy with respect to your Personal Information. If your Personal Information will be used contrary to this Privacy Policy, you will receive prior notice as provided herein.

IDEO ADVERTISING ON AND USE OF DATA WITH THIRD PARTY PLATFORMS:

We may share data collected on the Sites, including email addresses, to show you and others personalized advertisements on third party websites and online services such as Facebook(Meta), Google, Adobe and LinkedIn, including their advertising and analytics services. The categories of third-party websites are as follows:

  • Providers of web analysis tools
  • Web hosting and web development providers
  • Service providers for IT development services
  • Ticket and customer support software providers
  • Marketing and Advertising agencies
  • Sales service providers
  • Payment service providers
  • Logistics service providers
  • Receivables management and collection service providers
  • Cloud services
  • Conference and Webinar Software
  • Service providers for online surveys
  • Service provider for chat software
  • Service providers for bookkeeping and invoicing
  • Providers for external document management
  • Provides for application management software
  • Social Media advertising platforms
  • Online software design collaboration software platforms

In order to facilitate this, we may share data collected on the Sites with third parties who will help us identify user profiles to target in our advertising campaigns, and analyze and maximize the effectiveness of the Site and our advertising and marketing outreach initiatives. This works because third party providers have aggregated information based on trends and behaviors of its users linked to information they hold about users like yourself, such as an email address. Some of these advertisements may be for IDEO services such as IDEO U and other ads may be to recruit survey participants and feedback providers.

You may be able to opt out of receiving personalized advertisements from online services such as Facebook. However, when you opt out of personalized advertising, you may continue to see online advertising from IDEO. For more information on Facebook ads, please visit https://www.facebook.com/about/ads. This does not affect your rights to Personal Data deletion, removal or amendment under applicable law.

You have the option to register for and access some of our services using third party social media sites such as Google or Facebook, when we ask you to “Sign up through Facebook” or “Continue with Facebook.” These are sites which you have chosen to share your information with independently of IDEO in accordance with their terms and conditions. When you choose to register with our Sites using services such as Facebook, IDEO will obtain information such as your email address and in some cases, profile picture information, automatically through your social media provider which provides this information to us.

LinkedIn Page

We operate a LinkedIn Page (“Business Services”) on LinkedIn, a service of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter “LinkedIn”).

We use our company page to contact and communicate with LinkedIn members and visitors(“Member”), to provide information about our company and its products and services. If you contact us, we may view the information you have posted on LinkedIn as a LinkedIn member. If you share, like or comment on our content or if you mention our company profile on LinkedIn, we can also access to this information.

When a Member visits, follows or engages with the Page, LinkedIn processes personal data to provide Page Insights to us. It enables us to improve our marketing activities.  LinkedIn will process data that was provided by the Member to LinkedIn, such as job function, country, industry, seniority, company size, and employment status data from a member’s profile. Additionally, LinkedIn will process information on how a member has interacted with our company page.

We have concluded an agreement with LinkedIn, the Page Insights Joint Controller Addendum (the “Addendum”). This user agreement is incorporated into the LinkedIn Pages Terms and sets out the responsibilities of LinkedIn and us with respect to the processing of Page Insights. The Page Insights Joint Controller Addendum is available here: https://legal.linkedin.com/pages-joint-controlleraddendum.

For more information about Page Insights and how to exercise your data subject rights, please see the "Page Insights Information". For more detailed information about how LinkedIn processes what personal data, including how you can exercise your data subject rights against LinkedIn, please see LinkedIn’s privacy policy is published here: https://www.linkedin.com/legal/privacy-policy.

Facebook Fanpage

We operate a Facebook page (so-called "Fanpage") on Facebook, a service of Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta").

During your visit to the Fanpage, personal data is processed not only by us but also by Meta, even if you do not have a profile on Facebook or are not logged in. While using our Fanpage, user data (such as contact data), content data (such as entries in forms), usage data (such as websites visited, interests in content, access times), communication data (such as device information, IP addresses), are processed. On the one hand, this is done for the purpose of informing you and for communication, for example via contact requests and feedback forms, as well as for marketing.

If you are logged in when you open our Fanpage, we can view the information contained in your public Facebook profile. Meta also provides us with anonymous usage statistics ("page insights"). We use these to improve the user experience. However, we do not have access to the usage data that Meta uses to create the statistics.

We are jointly responsible with Meta for collecting data from visitors to our fan page and forwarding it to Meta (this includes information on the types of content viewed, interactions with content, actions taken, technical information such as IP address, operating system, browser type, language settings, cookie data). Interests can be derived from this, and user profiles can be formed, but we cannot draw any conclusions about individual users from this. Meta also uses the data to provide "page insights", which can be used to gain knowledge about interaction with the pages and the associated content. We have therefore entered into a joint responsibility agreement with Meta regarding the processing of your data in accordance with art. 26 GDPR. The agreement with Meta also regulates which security measures Meta must observe. The data subject rights, such as information or other requests, are also to be fulfilled by Meta. You can view the terms of this agreement with Meta here: https://www.facebook.com/legal/terms/page_controller_addendum. The further processing by Meta is not our joint responsibility.

Meta also stores so-called cookies on your end device when you visit our fan page, even if you do not have a Facebook profile or are not logged in there. This enables Meta to create user profiles based on your preferences and interests and to display advertising tailored to these preferences within and outside of Facebook. Cookies remain on your end device until you delete them. The details of this can be found in Meta's privacy policy (see below).

The data processing is carried out with your consent based on art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future via our consent management platform, which you can access here, without affecting the lawfulness of the processing carried out based on the consent until revocation. Furthermore, you can revoke your consent by setting your browser accordingly or as a logged-in user of the social network Facebook at https://www.facebook.com/settings/?tab=ads#_. You can also deactivate user-based advertising via the deactivation page of the network advertising initiative (http://optout.networkadvertising.org/), via http://www.youronlinechoices.com/de/praferenzmanagement/ or the US website (http://www.aboutads.info/choices).

As a logged-in Facebook user, you can make an objection and further settings in the Advertising Settings section.

It cannot be guaranteed that Meta does not transfer data to the USA for the purpose of storage and further processing. If such data transfer to the USA takes place, it is based on the standard contractual clauses of the EU Commission: https://facebook.com/help/566994660333381. Read more in the Meta EU data transfer addendum: https://www.facebook.com/legal/EU_data_transfer_addendum

For more information about Page Insights and how to exercise your data protection rights, please see the "Page Insights Information". For more detailed information on how Meta processes what personal data, including how to exercise your data subject rights against Meta, please refer to Meta's Data Policy at https://www.facebook.com/about/privacy.

Instagram Business Account

We operate an Instagram Business Account on Instagram (hereinafter “Instagram”), a service of Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta") with whom we jointly use technologies, systems, insights, and information.

During your visit, personal data is processed not only by us but also by Meta, even if you do not have a profile on Instagram or are not logged in. While visiting our Instagram profile, user data (such as contact data), content data, usage data (such as websites visited, interests in content, access times), communication data (such as device information, IP addresses) are processed. On the one hand, this is done for the purpose of informing you and for communication, for example via contact requests and feedback forms, as well as for marketing.

If you are logged in when you open our Instagram profile, we can view the information contained in your public Instagram profile. Meta also provides us with anonymous usage statistics ("Insights"). We use these to improve the user experience. However, we do not have access to the usage data that Meta uses to create the statistics.

We are jointly responsible with Meta for collecting data from visitors to our Instagram page and forwarding it to Meta (this includes information on the types of content viewed, interactions with content, actions taken, technical information such as IP address, operating system, browser type, language settings, cookie data). Interests can be derived from this, and user profiles can be formed, but we cannot draw any conclusions about individual users from this. Meta also uses the data to provide "page insights", which can be used to gain knowledge about interaction with the pages and the associated content. We have therefore entered into a joint responsibility agreement with Meta regarding the processing of your data in accordance with art. 26 GDPR. The agreement with Meta also regulates which security measures Meta must observe. The data subject rights, such as information or other requests, are also to be fulfilled by Meta. You can view the terms of this agreement with Meta here. The further processing by Meta is not our joint responsibility.

Meta also stores so-called cookies on your end device when you visit our Instagram business profile, even if you do not have an Instagram profile or are not logged into it. This enables Meta to create user profiles based on your preferences and interests and to display advertising tailored to these preferences within and outside of Instagram. Cookies remain on your end device until you delete them. The details of this can be found in Meta's privacy policy (see below).

The data processing is carried out with your consent based on art. 6(1)(a) GDPR. You can revoke your consent at any time with effect for the future via our consent management platform, which you can access here, without affecting the lawfulness of the processing carried out based on the consent until revocation. Furthermore, you can revoke your consent by setting your browser accordingly or as a logged-in user of the social network Instagram at the privacy and security settings. You can also deactivate user-based advertising via the deactivation page of the network advertising initiative (http://optout.networkadvertising.org/), via

http://www.youronlinechoices.com/uk/your-ad-choices or the US website (http://www.aboutads.info/choices). As a logged-in Instagram user, you can make an objection and further settings in the privacy and security settings.

It cannot be guaranteed that Meta does not transfer data to the USA for the purpose of storage and further processing. If such data transfer to the USA takes place, it is based on the standard contractual clauses of the EU Commission:

https://www.facebook.com/legal/EU_data_transfer_addendum and https://facebook.com/help/566994660333381.

For more information about Page Insights, please see the "Page Insights Information". For more detailed information on how Meta processes what personal data, including how to exercise your data subject rights against Meta, please refer to Meta's Data Policy at https://www.facebook.com/about/privacy and https://help.instagram.com, as well as the cookie policy at: https://help.instagram.com/1896641480634370/?helpref=uf_share .

LEGAL REQUESTS:

IDEO cooperates with law enforcement inquiries, as well as other third parties to enforce laws and intellectual property rights. Therefore, in response to a verified request by law enforcement, an applicable regulator, or other government officials relating to a criminal investigation or alleged illegal activity, we can disclose your name, city, state, telephone number, and email address. Without limiting the above, in an effort to respect your privacy, we will not otherwise disclose your Personal Information to law enforcement or other government officials without a subpoena, court order or substantially similar legal procedure, except when we believe in good faith that the disclosure of information is necessary to prevent imminent physical harm or financial loss; report suspected illegal activity; or in response to a regulator’s request for information regarding compliance with applicable law.

Requirements processing personal data on basis of EU GDPR, UK GDPR

Legal Basis

We base the processing of your data on the following legal bases:

  • Your consent, if you have given us such consent (Art. 6 para. 1 lit. a) GDPR)
  • The initiation or execution of a contract with you (Art. 6 para. 1 lit. b) GDPR)
  • The fulfillment of legal obligations (Art. 6 para. 1 lit. c) GDPR)
  • The implementation of our legitimate interests (Art. 6 para. 1 lit. f) GDPR)

Legitimate Interests

When processing your data, we may pursue the following legitimate interests:

  • To provide our services to you or our clients and to appropriately manage projects and relationships with you or our clients
  • The development and improvement of our services and websites
  • Protection of our business interestsMeasuring and improving the effectiveness of our marketing efforts across different channels and platforms
  • Protection of our systems against misuse
  • On the production of statistics
  • For the storage of our correspondence with you

Requirement or Obligation to Provide Data

Unless this is expressly stated, the provision of your data is not required or obligatory.

3. STORAGE AND TRANSFER OF YOUR INFORMATION

Depending on the IDEO Site you are using, or where you contact us, your information is stored on the servers of our service providers, including Workday, Rackspace, Google, Amazon Web Services, Hype and Heroku. Please note that information we collect from you may be stored and processed in the United States or any other country in which we or our service providers maintain facilities. We or our service providers may transfer information that we collect about you, including Personal Information across borders and from your country or jurisdiction to other countries or jurisdictions around the world. We encourage you to review Heroku, Amazon Web Services, Hype, Workday, and Rackspace’s terms of service agreements and privacy policies before providing information to them.

Requirements for processing personal data on basis of EU GDPR, UK GDPR: Data is being transferred to countries outside the European Economic Area and the United Kingdom. We only transfer personal data to so called “third countries” where the EU Commission and the UK Information Commissioner’s Office have confirmed an adequate level of protection or where we can ensure the careful handling of personal data by means of contractual agreements or other suitable guarantees, such as certifications or proven compliance with international security standards, which you can review on request.

Retention periods:

We store your data,

  • if you have consented to the processing, until you revoke your consent;
  • if we need the data for the execution of a contract, for as long as the contractual relationship with you exists;
  • if we use the data on the basis of a legitimate interest, for as long as your interest in deletion or anonymisation does not outweigh the need for the data;
  • insofar as statutory storage obligations exist, until the end of the statutory retention period.
4. SECURITY OF YOUR INFORMATION

We use reasonable physical, procedural, technical and administrative security measures to protect your Personal Information against loss or theft as well as unauthorized access and disclosure to protect your privacy. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

5. YOUR CALIFORNIA PRIVACY RIGHTS

Since 2005, California Civil Code Section 1798.83 permits our Users who are California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. For inquiries regarding our disclosure policy, please contact us at: IDEO LP, Attn: Legal Group, 2525 16th Street, San Francisco, CA 94103 or privacynotice@ideo.com.

California Consumer Privacy Act of 2018

Categories of Personal Information Collected

In the first chart below, we identify each category of personal information that we have collected about our users in the last 12 months, using the categories enumerated in the CCPA. In the second chart below, we identify the category of personal information we collect about our job applicants. If we have collected that category of personal information in the last 12 months, an “X” appears in the corresponding row in the second column of the chart. For each category of personal information we have collected, we also identify (i) the source(s) from which the information was collected; (ii) the purpose(s) for which it was collected; (iii) the categories of third parties, if any, with which it has been shared and (iv) the categories of third parties, if any, with which it has been sold (as defined under the CCPA). Please note that in the chart below, when we list the categories of third parties with whom we share Personal Information, this does not include Service Providers, as defined under the California Consumer Privacy Act of 2018.

Certain IDEO Sites provide blank text fields or other similar mechanisms by which users can enter whatever text they would like. As a result, while IDEO does not require users to provide any information beyond what is disclosed below in order to use our services, users may voluntarily share additional personal information. For challenges on OpenIDEO, the specific topic of the challenge may lead to users choosing to enter more sensitive information into these blank text fields but IDEO does not require any users to provide such information.

We may provide certain user information to law enforcement or school officials if we are required to under law or to prevent harm to users or others.

CATEGORIES OF PERSONAL INFORMATION
COLLECTED (IN THE LAST 12 MONTHS)
CATEGORIES OF SOURCE(S)
PURPOSE(S) FOR COLLECTION
CATEGORIES OF THIRD PARTIES WITH WHICH IT HAS BEEN SHARED*
DISCLOSED OR SOLD TO THIRD PARTIES FOR A COMMERCIAL OR BUSINESS PURPOSE*
NAME
X
From users directly
From third party sign-in providers
From third party e-commerce providers
From third party survey providers
To allow secure login to the IDEO platforms and sites
To communicate for technical support and service update purposes
To assist IDEO in completing transactions with users
To analyze activity on our sites and platforms to evaluate and improve IDEO  services
To facilitate the matching of candidates to jobs posted on IDEO.com
Data analytics providers
Operating systems and platforms
Web application integration services
Email and communication services
CRM providers
OpenIDEO challenge sponsors
ALIAS
X
From users directly
From third party sign-in providers
To allow secure login to the IDEO platforms and sites
To communicate for technical support and service update purposes
Data analytics providers
Operating systems and platforms
Internet Service Providers
From users directly
From third party sign-in providers
From third party e-commerce providers
From third party survey providers
SIGNATURE
POSTAL ADDRESS
X
From users directly
From third party sign-in providers
From third party e-commerce providers
To enable IDEO to tailor services to users in certain geographical areas
To assist IDEO in completing transactions with users
To facilitate the matching of candidates to jobs posted on IDEO.com
Internet Service Providers
EMAIL ADDRESS
X
From users directly
From third party sign-in providers
From third party survey providers
From third party marketing analytics companies
From third party e-commerce providers
To allow secure login to the IDEO platforms and sites To communicate for technical support and service update purposes To communicate for educational support and feedback purposes To communicate newsletter information To maintain IDEO Client and it's users' accounts To send surveys To send invitations for IDEO events To Maintain mailing lists To assist IDEO in completing transactions with users To facilitate the matching of candidates to jobs posted on IDEO.com
Social Networks  for targeted look-alike audience advertising
Email and communication services
Event management services
Operating systems and platforms
Web application integration services
Internet Service Providers
OpenIDEO challenge sponsors
Social networks for targeted look-alike audience advertising
TELEPHONE NUMBER
X
From users directly
From third party e-commerce providers
To communicate for technical support and service update purposes
To assist IDEO in completing transactions with users
To facilitate the matching of candidates to jobs posted on IDEO.com
Internet Service Providers
Phone communication providers
UNIQUE PERSONAL IDENTIFIER (E.G., DEVICE ID, AD ID, IP ADDRESS, ETC.)
X
Data analytics providers
From third party survey providers Advertising trackers
Directly from users
To maintain security of IDEO platforms and IDEO user accounts
To analyze traffic and usage of our services to improve and maintain those services
Internet Service Providers such as AWS or Heroku
Data analytics providers
ACCOUNT OR POLICY NUMBER (E.G., BANKING, INSURANCE, CREDIT, ETC.)
GOVERNMENT ID NUMBER (E.G., SSN, DRIVER’S LICENSE, PASSPORT, ETC.)
PHYSICAL CHARACTERISTICS OR DESCRIPTION
X
Directly from users
In order to provide targeted surveys
BIOMETRIC INFORMATION
PROFESSIONAL OR EMPLOYMENT-RELATED INFORMATION
X
Directly from users
In order to better tailor services to users.
In order to provide targeted surveys
To facilitate the matching of candidates to jobs posted on IDEO.com
Web and hosting platforms
Internet Service Providers
Platform operating and integration services
EDUCATION INFORMATION
X
Directly from usersFrom a user’s school or school district
In order to better tailor services to users.
In order to provide targeted surveys
To facilitate the matching of candidates to jobs posted on IDEO.com
Platform operating and integration services
Internet Service Providers
MEDICAL INFORMATION
FINANCIAL INFORMATION
INSURANCE INFORMATION
COMMERCIAL INFORMATION (E.G., PURCHASE HISTORY)
X
From third party e-commerce providers such as Shopify
From payment providers such as Stripe
Data analytics providers
To assist IDEO in completing transactions with users
To analyze activity on our sites and platforms to evaluate and improve IDEO  services
Data analytics providers
Third party developers
Social Media Marketing Services
IDEO provides conversion information to Social Media marketing services providers
GEOLOCATION DATA
X
From users directly.
In order to better tailor services to users.
Development partners sInternet Service Providers
INTERNET OR OTHER ELECTRONIC NETWORK ACTIVITY INFORMATION (E.G., BROWSING OR SEARCH HISTORY, INTERACTION WITH AN ONLINE SERVICE, ETC.)
X
Content hosting services
Data analytics providers
To analyze traffic and usage of our services to improve and maintain those services
Data analytics providers
Social Media Marketing Services
IDEO provides certain network activity to Social Media marketing services providers
AUDIO INFORMATION
X
From users directly. From online conference call providers
To allow IDEO to share educational content with users who are unable to attend webinars
To allow IDEO to evaluate homework assignments and challenge submissions that users have submitted.
VISUAL INFORMATION
X
From users directly. From online conference call providers
From third party sign in providers
To allow users to personalize their IDEO platform experiences.
To allow IDEO to share educational content with users who are unable to attend webinars
To allow IDEO to evaluate homework assignments and challenge submissions that users have submitted.
Internet Service Providers
ELECTRONIC, OLFACTORY, THERMAL, OR SIMILAR INFORMATION

IDEO may also draw inferences based on personal information above which it may use to understand the usage of our services to improve and maintain those services. We may provide those inferences to third parties in an anonymous and aggregate form to improve and maintain our services, and to market or advertise our services.

Applicant Personal Information Chart

CATEGORIES OF PERSONAL INFORMATION
COLLECTED (IN THE LAST 12 MONTHS)
CATEGORIES OF SOURCE(S)
PURPOSE(S) FOR COLLECTION
CATEGORIES OF THIRD PARTIES WITH WHICH IT HAS BEEN SHARED*
DISCLOSED OR SOLD TO THIRD PARTIES FOR A COMMERCIAL OR BUSINESS PURPOSE*
NAME
X
From users directly
From third party sign-in providers
From third party e-commerce providers
From third party survey providers
To allow secure login to the IDEO platforms and sites
To communicate for technical support and service update purposes
To assist IDEO in completing transactions with users
To analyze activity on our sites and platforms to evaluate and improve IDEO  services
To facilitate the matching of candidates to jobs posted on IDEO.com
Data analytics providers
Operating systems and platforms
Web application integration services
Email and communication services
CRM providers
OpenIDEO challenge sponsors
ALIAS
X
From users directly
From third party sign-in providers
To allow secure login to the IDEO platforms and sites
To communicate for technical support and service update purposes
Data analytics providers
Operating systems and platforms
Internet Service Providers
From users directly
From third party sign-in providers
From third party e-commerce providers
From third party survey providers
SIGNATURE
POSTAL ADDRESS
X
From users directly
From third party sign-in providers
From third party e-commerce providers
To enable IDEO to tailor services to users in certain geographical areas
To assist IDEO in completing transactions with users
To facilitate the matching of candidates to jobs posted on IDEO.com
Internet Service Providers
EMAIL ADDRESS
X
From users directly
From third party sign-in providers
From third party survey providers
From third party marketing analytics companies
From third party e-commerce providers
To allow secure login to the IDEO platforms and sites To communicate for technical support and service update purposes To communicate for educational support and feedback purposes To communicate newsletter information To maintain IDEO Client and it's users' accounts To send surveys To send invitations for IDEO events To Maintain mailing lists To assist IDEO in completing transactions with users To facilitate the matching of candidates to jobs posted on IDEO.com
Social Networks  for targeted look-alike audience advertising
Email and communication services
Event management services
Operating systems and platforms
Web application integration services
Internet Service Providers
OpenIDEO challenge sponsors
Social networks for targeted look-alike audience advertising
TELEPHONE NUMBER
X
From users directly
From third party e-commerce providers
To communicate for technical support and service update purposes
To assist IDEO in completing transactions with users
To facilitate the matching of candidates to jobs posted on IDEO.com
Internet Service Providers
Phone communication providers
UNIQUE PERSONAL IDENTIFIER (E.G., DEVICE ID, AD ID, IP ADDRESS, ETC.)
X
Data analytics providers
From third party survey providers Advertising trackers
Directly from users
To maintain security of IDEO platforms and IDEO user accounts
To analyze traffic and usage of our services to improve and maintain those services
Internet Service Providers such as AWS or Heroku
Data analytics providers
ACCOUNT OR POLICY NUMBER (E.G., BANKING, INSURANCE, CREDIT, ETC.)
GOVERNMENT ID NUMBER (E.G., SSN, DRIVER’S LICENSE, PASSPORT, ETC.)
PHYSICAL CHARACTERISTICS OR DESCRIPTION
X
Directly from users
In order to provide targeted surveys
BIOMETRIC INFORMATION
PROFESSIONAL OR EMPLOYMENT-RELATED INFORMATION
X
Directly from users
In order to better tailor services to users.
In order to provide targeted surveys
To facilitate the matching of candidates to jobs posted on IDEO.com
Web and hosting platforms
Internet Service Providers
Platform operating and integration services
EDUCATION INFORMATION
X
Directly from usersFrom a user’s school or school district
In order to better tailor services to users.
In order to provide targeted surveys
To facilitate the matching of candidates to jobs posted on IDEO.com
Platform operating and integration services
Internet Service Providers
MEDICAL INFORMATION
FINANCIAL INFORMATION
INSURANCE INFORMATION
COMMERCIAL INFORMATION (E.G., PURCHASE HISTORY)
X
From third party e-commerce providers such as Shopify
From payment providers such as Stripe
Data analytics providers
To assist IDEO in completing transactions with users
To analyze activity on our sites and platforms to evaluate and improve IDEO  services
Data analytics providers
Third party developers
Social Media Marketing Services
IDEO provides conversion information to Social Media marketing services providers
GEOLOCATION DATA
X
From users directly.
In order to better tailor services to users.
Development partners sInternet Service Providers
INTERNET OR OTHER ELECTRONIC NETWORK ACTIVITY INFORMATION (E.G., BROWSING OR SEARCH HISTORY, INTERACTION WITH AN ONLINE SERVICE, ETC.)
X
Content hosting services
Data analytics providers
To analyze traffic and usage of our services to improve and maintain those services
Data analytics providers
Social Media Marketing Services
IDEO provides certain network activity to Social Media marketing services providers
AUDIO INFORMATION
X
From users directly. From online conference call providers
To allow IDEO to share educational content with users who are unable to attend webinars
To allow IDEO to evaluate homework assignments and challenge submissions that users have submitted.
VISUAL INFORMATION
X
From users directly. From online conference call providers
From third party sign in providers
To allow users to personalize their IDEO platform experiences.
To allow IDEO to share educational content with users who are unable to attend webinars
To allow IDEO to evaluate homework assignments and challenge submissions that users have submitted.
Internet Service Providers
ELECTRONIC, OLFACTORY, THERMAL, OR SIMILAR INFORMATION

*This does not include when:

  • You direct us to disclose your Personal Information or use us to interact with a third party and the third party does not sell the Personal Information;
  • We use or share an identifier solely to alert a third party that you have opted out of the sale of your Personal Information;
  • Your Personal Information is transferred as an asset as part of a transaction in which the third party assumes control of all or part of our business, in which case the third party would have to tell you in writing if it materially changes the way in which the information is used or shared; and
  • We use or share your Personal Information pursuant to a written contract with a service provider that is necessary to perform a business purpose. In this case, the service provider performs on our behalf, and our written contract prohibits it from keeping, using or disclosing your Personal Information for any purpose other than for the specific purpose identified in the contract.

If you are a California resident and we know you are under 16 years of age, we will not sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate to any other business or third party for monetary or other valuable consideration your personal information.

Rights of California Residents

Right to Know: If you are a California resident, you may submit, free of charge, but no more than twice in a 12-month period, a verifiable request for the following information:

  • The specific pieces of Personal Information we have about you;
  • The categories of Personal Information we collected, sold or disclosed for a business purpose about you within the last 12 months;
  • The categories of sources from which the Personal Information was collected;
  • The purposes for which the Personal Information was collected or sold; and
  • The categories of third parties to whom the Personal Information was sold, disclosed for a business purpose, or otherwise shared.

If possible, we will provide this information to you in a readily usable format that allows transmission to another entity.

To submit a request, please visit the IDEO privacy center and click on Download Your Data; you will be prompted to enter the name and email address connected to IDEO. You may submit questions to us by email at privacynotice@ideo.com. Within 10 days of receipt, we will let you know we received your request. We will provide a substantive response within 45 days, unless we need more time, in which case we will notify you. If we need additional information to verify your identity, we will contact you to request that information. If we are not able to verify your identity, we will deny your request, but if applicable, we will refer you to the applicable sections of this Privacy Policy that address our data collection and use practices. If we deny your request, even if only in part, we will explain the reason in our response.

Right to Delete: If you are a California resident, you may submit a verifiable request for us to delete any Personal Information we have collected about you. To submit a request, please visit the IDEO privacy center and click on Delete Your Data; you will be prompted to enter the name and email address connected to IDEO. Alternatively, you may submit a request or questions to us by email at privacynotice@ideo.com. Within 10 days of receipt, we will confirm receipt of your request. We will provide a substantive response within 45 days, unless we need more time, in which case we will notify you. If we need additional information to verify your identity, we will contact you to request that information. If we are not able to verify your identity, we will deny your request to delete, but we will treat it like a request to opt-out (discussed below). If we deny your request, even if only in part, we will explain the reason in our response.

Right to Opt-Out: While IDEO does not exchange your data for monetary compensation, IDEO may share your data with third parties providing services to IDEO or to enable certain tracking functions on our Sites according to the terms of our Privacy Policy. At any time, you may tell us not to sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate to another business or third party for monetary or other valuable consideration of your personal information. You may make this request by clicking Do Not Sell My Info which will take you to the IDEO privacy center, and click on Manage Consent Settings; you will be prompted to enter the name and email address connected to IDEO. Alternatively, you may submit a request or questions to us by email at privacynotice@ideo.com.

Right to be Free from Discrimination: We may not discriminate against you because you have chosen to exercise your rights, including, for example, by denying you access to our online services or charging you different rates or prices for the same online services, unless that difference is reasonably related to the value provided by your data.

Right to Correct: Effective January 1, 2023, you have the right to request correction of your data by submitting a request at privacynotice@ideo.com.

Right to Limit Use and Disclosure of Sensitive Data: Effective January 1, 2023, you have the right to limit our use and disclosure of your Sensitive Data. Sensitive Data includes (1) government ID data, (2) financial account numbers and log-in data, (3) geolocation, (4) race, religion, and union membership data, (5) your private communications (unless directed toward IDEO), (6) your genetic data, (7) biometric data used to identify you, (8) your medical information, and (9) your sexual orientation. IDEO collects the Sensitive Data indicated on the CCPA data charts above for internal, non-public use only.

Exercising Your Rights: To submit a verifiable request or to otherwise contact us for more information about how to exercise your rights, please visit the IDEO privacy center or send questions to us by email at privacynotice@ideo.com.

If you would like to designate an authorized agent to make a request on your behalf, please be sure the agent is able to (i) demonstrate you have provided written permission for the agent to submit the request on your behalf, and (ii) provide proof of his, her or their own identity. If the agent does not satisfy these requirements, we will deny the request.

Contact Us

If you have any questions or concerns about our privacy policies or practices, please contact us at privacynotice@ideo.com.

Rights applicable to Residents of the European Union and the United Kingdom

When the EU GDPR or the UK GDPR are applicable, data subjects have the following rights:

  • To request information about the processing of your data, as well as to receive a copy of your personal data. Among other things you may request information on the purposes of the processing, the categories of personal data processed, the recipients of the data (if a transfer is made), the duration of the storage or the criteria for determining the duration;
  • To receive personal data relating to you in a structured, common and machine-readable format or to transfer it to another person in charge;
  • To correct your data. If your personal data is incomplete, you have the right to complete the data, taking into account the purposes of the processing;
  • To have your data deleted or blocked;
  • To have the processing restricted;
  • To object to the processing of your data;
  • To revoke your consent to the processing of your data for the future; and
  • To complain to the responsible supervisory authority about unauthorised data processing.

Requests pursuant to EU GDPR or UK GDPR may be submitted to privacynotice@ideo.com or at the IDEO privacy center: https://ideo.ethyca.com/

6. YOUR PERSONAL INFORMATION RIGHTS

IDEO acknowledges that you have the right to access, to delete, and to limit the sharing of your Personal Information under various laws. You may delete and amend your account preferences for all of our Sites stated above, which will limit the Personal Information you provide to us. You may contact us at any time at privacynotice@ideo.com. If you instead contact the support site of the product you are using with one of these requests, they will let IDEO’s privacy team know. You may also write to us at the address stated in this policy. Our granular cookies notice should also help you to limit any tracking and give you options around your data - if you are not satisfied about this you may contact us privacynotice@ideo.com. If you are based in Europe, you may also contact your local Data Protection Authority who can manage disputes.

We may retain your information for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes and enforce our agreements or for five (5) years, whichever is longer. In certain circumstances we may be required by law to retain your Personal Information, or may need to retain your Personal Information in order to continue providing a service.

Pursuant to California’s Digital Online Eraser Law (California Senate Bill 568), Users under the age of 18 (“Minors”), and pursuant to GDPR, all EU Users, have the right to remove, or request the removal of, content or information they have posted publicly on the Site. Please be advised that any information you post to a bulletin board, message board, chat room, community, or other forum is publicly viewable. We strongly recommend that all Users avoid posting personal or sensitive information at any time.

Please note that removal of this content or information from public view does not guarantee complete or comprehensive removal. After your removal request has been honored, we may retain copies of the content or information you have previously posted on our servers if it has been rendered anonymous or if we are required by law to retain it. Additionally, we do not have control over third parties (e.g., other Users) who may have copied or reposted this information.

Upon request IDEO will provide you with information about whether we hold any of your Personal Information. You may access, correct, or request deletion of your Personal Information by contacting us at privacynotice@ideo.com. We will respond to your request within a reasonable timeframe in accordance with applicable law.

IDEO collects some information under the direction of its Clients, and may not have a direct relationship with the individuals whose Personal Information it processes. If you were invited to one of our IDEO platforms directly by an IDEO Client and would no longer like to be contacted by our Client that uses our service, please contact the Client that you interact with directly. Likewise, if you were invited to one of our IDEO platforms by an IDEO Client and you would like to access, or seek to correct, amend, or delete inaccurate data, you should direct your query to the Client (the data controller) in the first instance, unless the data relates to information IDEO holds in its capacity as a Site owner (and therefore a data processor). This will not affect your legal rights. If requested to remove data we will respond within a reasonable timeframe and in accordance with applicable law. IDEO will retain this Personal Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

In addition to your right to opt out, delete, amend your information at any time as stated in this policy, in the event IDEO desires to use your Personal Information for a purpose materially different than the purposes set forth in this Privacy Policy, it will contact you via the email address listed on your account and you shall have the opportunity to opt out of such use of your information. IDEO may not use your information for such materially different purpose without the opportunity to opt out and without adequate notice of changes to its privacy practices.

Please note that if IDEO has provided your email address to third party services such as Facebook at your direction (or you have registered for our services using such third parties) and if you wish to have your personal data removed from such third-party service, you may have to contact them directly as they may seek your authority to do so.

7. CHANGES TO THIS PRIVACY POLICY

Please note that this Privacy Policy may change from time to time. We will not retroactively reduce your rights under this Privacy Policy without your explicit consent, and we expect most such changes will be minor. For future changes, we will post the new Privacy Policy to the Sites, or provide other appropriate notices if required under applicable law. Each version of this Privacy Policy will be identified at the bottom of the page by its effective date.

8. CONTACT US

If you have any additional questions or concerns about this Privacy Policy, please feel free to contact us any time through this Site; by mail to IDEO LP, 2525 16th Street, San Francisco, California, 94103, USA,; or by email to privacynotice@ideo.com.

9. IDEO NEWSLETTERS AND EVENTS

NEWSLETTERS

We invite people who are interested in hearing more about IDEO’s activities on the Sites or any other IDEO affiliated sites to sign up to our newsletters in various ways. By signing up to one of our IDEO newsletters you are giving consent to receive relevant marketing emails and communications from IDEO (“Subscription”). Your Subscription will allow IDEO to contact you regarding the Sites and any other IDEO affiliated sites and services. For example, if you sign up for the IDEO.com newsletter, you may receive information about new courses from IDEO U.

We are also cognizant that as of 2020, much of our engagement and work with Clients is remote. This means that where you are a business contact of IDEO and have been identified specifically by an employee of IDEO with whom you have had contact before, as part of IDEO’s legitimate business interests, IDEO may contact you about relevant events, webinars and content.

IDEO may integrate business operational systems including its Customer Relationship Management System (“CRM”) with marketing systems in order to understand our services, business offerings, clients and content better.

Our Subscription lists are managed by Hubspot, Mailchimp (including its affiliates Mandrill and Tiny Letter) and your Subscription may be subject also to Hubspot and Mailchimp’s terms of use and privacy policy respectively. If you have previously signed up for an IDEO newsletter and would like to unsubscribe, you may opt-out of these communications at any time by using the unsubscribe link at the bottom of the email or by emailing us at privacynotice@ideo.com.

OTHER COMMUNICATION

When you create an account on IDEO U or OpenIDEO, IDEO may contact you using personal details you provide regarding the Sites, with information we believe may be of interest or relevant to you; however, you may opt out at any time. In being a part of the IDEO network, we are interested in your creative inputs, outputs and views, and may also contact you:

  • To ask if you would be interested in participating in voluntary or paid research opportunities on behalf of IDEO;
  • To ask if you would be interested in creative and relevant job opportunities; and
  • To ask if you would be interested in connecting with other like-minded individuals on creative initiatives within the IDEO network.

IDEO also uses vendors such as Docusign to manage certain external communications. Docusign uses tracking technology and analytics to give almost real time marketing intelligence including if recipients have opened attachments or read emails that are sent to them. Please see their privacy policy for more information.

10. ADDITIONAL PRIVACY PRACTICES FOR IDEO SERVICES

OpenIDEO

Users of OpenIDEO will have an OpenIDEO profile which can be viewed in the “My Profile” section of the Site. Once you register, create My Profile, or submit a Contribution you are not anonymous to us (and may be visible to other Users depending on the activity). As only Users can submit a Contribution on the Site, if you choose to submit a Contribution prior to registering to the Site, we will require you to first (i) register with your Login Information thus creating My Profile and, if applicable, (ii) agree to any Challenge Rules or if applicable, any Alliance guidelines.

Please note that if you register for OpenIDEO using Facebook or Google, the following information, if it has been made publicly available by you, will be stored on our servers as your login information: Facebook or Google ID, first and last name, email address, country, profile photo, locale, gender and date of birth. Additionally, your Facebook or Google Profile Picture becomes part of your login Information but is not stored by us. Your use of information by Facebook or Google in this context will be set out more fully in their privacy policies and in accordance with the settings you choose using their sites.

All Contributions will be viewable by other Users of the Site. You always have the option to not provide information by choosing not to register or submit a Contribution or Applause. If you choose to submit Contributions or Applause, or post messages on the Site, we will collect and store the information you provide to us. If you delete your account on the Site, your User data will be removed from the Site and your My Profile will be deleted, however your posts and comments may still be visible under the alias “Inactive User.”

It is each User’s decision as to whether they add Personal Information to their My Profile section or upload a photograph/image of themselves and opt to make these visible to other Users as part of My Profile. The image/photo/picture, first and last name, gender and date of birth from Facebook or Google (if used) can be deleted at each User’s discretion. Your Facebook or Google ID is not visible in My Profile but can appear in your My Profile URL.

Chapters” are groups of individuals who choose to arrange themselves geographically to solve challenges, work more deeply on areas within a challenge, or just meet for community purposes. Chapter organizers are volunteers selected by IDEO to run certain Chapters. If you RSVP for an event organized by a Chapter through the Site, your name and photo will be added to the event registrants list unless you choose to show as an anonymous attendee in My Profile. (Event creators and Organizers will still have access to your name and email unless you choose not to attend an Event. Event creators and Organizers are prohibited from use of Personal Information for anything other than their Chapter head duties related to the event.)

Challenge and Alliance Sponsor and their agents: IDEO challenges or alliances are promoted, sponsored, and championed by sponsors (“Challenge or Alliance Sponsor”). A Challenge or Alliance Sponsor (other than IDEO) cannot store or disclose your Personal Information; this can only be done by IDEO in compliance with this Privacy Policy. IDEO may share information that you have entered in My Profile with a Challenge or Alliance Sponsor to analyze Users’ Contributions, comments and Applause for the Challenge or Alliance Sponsor’s own Challenge(s) or Alliance(s). Some Sponsors may choose to use an organization to help them comply with their obligations e.g., to make payments for grants or prizes, in a secure way which helps maintain their charitable status; contributes to their objectivity or some other legal or regulatory commitment. In such case, certain information you have entered into My Profile may be shared with those organizations.

Chapter Organizers: IDEO does not give a Chapter Organizer any authority to store or disclose your Personal Information; this can only be done by IDEO in compliance with this Privacy Policy. In addition, and as stated above, Chapter Organizers may have access to your Personal Information, but they are under strict obligations to use that information only for purposes related to their Chapter head duties.

IDEO U

When you decide to join an IDEO U learning course, you will be asked to register for an account. Our IDEO U Site is administered and managed by our service provider, NovoEd.

Where you are purchasing access to courses for other people:

On registration and as part of sign up, you will have the opportunity to review this privacy policy. If you are purchasing for other people and therefore reviewing the contents of this policy on their behalf you warrant that you have the right to do so and they have also had the opportunity to accept and review the privacy policy.

As part of the Course Registration process, you will be asked to provide us with your email address, payment information (including your billing address) and, optionally, your phone number. Course payments are processed via a third-party payment processor of your choice: PayPal or Shopify. We encourage you to review PayPal and Shopify’s privacy policies.

Personal information that NovoEd collects for us during Account creation for IDEO U may include your name and email address. We strongly encourage you to review NovoEd’s terms of service agreement and privacy policy.

You may also choose to sign up through NovoEd with your social media profile (e.g., Facebook or LinkedIn). When you engage with our or NovoEd’s content on or through third-party social networking sites, plug-ins and applications, you may allow us to have access to certain information from your social media profile (e.g., name, email address, photo, current position) to deliver the content or as part of the operation of the application. Through some social networking sites’ privacy settings, you can control what data you share. For more information about how social networking sites such as LinkedIn or Facebook handle your Personal Information, please refer to their privacy policies and terms of use.

Course Providers: We may share Personal Information, Non-Identifying Information and Log Data with instructors who provide the courses on the IDEO U Site ("Course Providers"). They use this information mainly to provide, administer and improve courses and the services, to respond to your inquiries, and to analyze and conduct research on the services.

Your Employer: If you are participating in IDEO U as part of an employer-sponsored program, at the request of your employer and as part of our agreement with them, we may provide your employer information about your activities and performance in connection with IDEO U, including Contributions and performance information with respect to particular IDEO U courses or services. IDEO shall not be responsible or liable for the use of such information by your employer, and such use shall be subject to your employer's policies (including privacy policies) applicable to you.

If you are an employer and have registered employees on their behalf to participate in IDEO U courses, you are liable for their actions and omissions and agree to indemnify IDEO for all losses and damages suffered as a result, including but not limited to breaches of this Privacy Policy.

Analytics and Development partners: From time to time, IDEO U may give access to development partners helping optimize our services and assessing what our users want and need; and performing business critical updates. This means they may need access to our Shopify or other provider infrastructure to look at new ways of ‘shopping’ or interacting with our services, giving them access to an account which holds personal data such as user shopper IDs (although we will never allow our providers to download, export or use such data unless it is strictly necessary and appropriate security controls are in place).

Creative Tensions Application and Site

Creative Tensions is a methodology and design principle which IDEO has incorporated from a physical in-person experience into a digital application (“DCT”) designed to leverage the creative nature of conflict, differing perspectives, and tension in an interactive session (of generally less than two hours). Users are invited to the tool using a unique meeting link sent by the moderator and will be assigned a unique session ID (no account registration required) which will be deleted when the group session ends. Alternatively, a temporary account can be created.

DCT uses Google Analytics and as stated above in this privacy policy, we recommend you review their privacy terms. The digital technology developed by IDEO in partnership with the Sundance Institute, is used alongside remote conferencing software. IDEO uses Zoom as its chosen provider. Zoom’s privacy policy can be found here. It is possible if you are part of an organization that your organization has requested a different software provider to facilitate the session remotely. If this is the case, we suggest you review the privacy terms before accepting any invite or downloading related software.

During use of the DCT, Users will have an option to identify themselves by uploading a personal image, which represents them during the session, and by inputting the name by which they would like to be referred. The User determines which personal image and whether to choose an avatar or other image to represent their participation. Other Users will do the same, and we ask you to respect the privacy of other Users and do not capture their image, participation in the DCT app, or any other personal data you may be privy to during the session, unless you have permission to do so.

effective Date: January 1, 2024