Privacy Shield Policy
Effective Date: April 30, 2019
EU-U.S. and Swiss-U.S. Privacy Shield
For purposes of this Policy, the following definitions shall apply:
“Agent” means any third party that collects or uses personal information under the instructions of, and solely for, Quartz Media or to which Quartz Media discloses personal information for use on Quartz Media’s behalf.
“Quartz Media, Inc.” or “Quartz Media” means Quartz Media, Inc., its subsidiary Newspicks USA, LLC, any of their subsidiaries, predecessors and successors in the United States.
“Personal information” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Personal information does not include information that is anonymized or aggregated.
“Sensitive information” means any personal information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, information that concerns health or sex life, and information about criminal or administrative proceedings and sanctions.
EU-U.S. AND SWISS-U.S. PRIVACY SHIELD FRAMEWORKS
Quartz Media participates in and complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from the EEA and Switzerland, respectively, transferred to the United States pursuant to Privacy Shield. Quartz Media has certified that it adheres to the Privacy Shield Principles. If there is any conflict between the terms of this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view Quartz Media’s certification, visit https://www.privacyshield.gov/.
Quartz Media undertakes lead generation activities on behalf of customers; in this context, Quartz Media may act as a processor of personal information on behalf of its customers, including of personal information about individuals in the EEA and Switzerland such as contact information and sales lead information. Quartz Media shares this information with its customers and uses this information for the provision of services to its customers.
Quartz Media receives information about employees of Quartz Media who are located in the EEA, and which is transferred in the context of the employment relationship, such as name, address, birthday, gender, nationality, work location, compensation, and other such information that is required to process payroll, provide benefits, and comply with domestic and international regulatory requirements. Quartz Media uses this information for internal employment and human resources purposes.
Quartz Media may receive information from third parties about users of websites and applications in connection with advertising, including information from social media websites (such as account IDs or user names, email address, friend lists) and information from publicly or commercially available sources (such as demographic information, contact information, group affiliation, occupational information, and educational background).
Quartz Media will subject all personal information received via the Privacy Shield to the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks. Quartz Media is subject to the investigative and enforcement authority of the Federal Trade Commission (FTC). Quartz Media may be required to disclose personal information in response to lawful requests by public authorities including to meet national security and law enforcement requirements.
Quartz Media will offer EEA and Swiss individuals whose personal information has been transferred to us the opportunity to choose whether the personal information it has received is to be used for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual. An individual may opt-out of such uses of their personal information by contacting us at the address given below.
Quartz Media will not use sensitive personal information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual unless Quartz Media has received the individual’s affirmative and explicit consent (opt-in).
Data Integrity and Purpose Limitation
Quartz Media will use personal information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual. Quartz Media will take reasonable steps to ensure that personal information is relevant to its intended use, accurate, complete and current.
Transfers to Agents
Quartz Media may disclose personal information to Agents, including but not limited to, providers of analytical, hosting, payment processing and other support services. Agents may have access to personal information if needed to perform their functions for Quartz Media. Quartz Media does not transfer personal information to non-Agent third parties. In the event that Quartz Media transfers personal information to non-Agent third-parties, it will first provide EEA and Swiss individuals with opt-out choice (or opt-in for sensitive data).
Quartz Media will require its Agents to safeguard personal information consistent with this Policy by contract obligating the Agent to provide at least the same level of protection as is required by the EU-U.S. and Swiss-U.S. Privacy Shield Principles. Quartz Media is liable for onward transfers of personal information from the EEA where its Agent processes personal information inconsistent with the EU-U.S. and Swiss-U.S. Privacy Shield Principles, unless Quartz Media proves that it is not a party to the event giving rise to the damages.
Access and Correction
Pursuant to the Privacy Shield principles, Quartz Media acknowledges the right of EEA and Swiss individuals to access their personal data. In addition, Quartz Media will take reasonable steps to permit individuals to correct, amend, or delete such information that is demonstrated to be inaccurate, incomplete, or processed in violation of the Privacy Shield Principles. An individual may request to access his or her information, or otherwise correct, amend, or delete his or her information pursuant to the EU-U.S. and Swiss-U.S. Privacy Shield Principles by contacting us at the address given below.
Quartz Media will take reasonable and appropriate precautions to protect personal information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction.
Quartz Media will conduct compliance audits of its relevant privacy practices to verify adherence to this Policy. Any employee that Quartz Media determines is in violation of this policy will be subject to disciplinary action.
Dispute Resolution – Privacy Shield
In compliance with the EU-U.S. and Swiss-U.S. Privacy Shield Principles, Quartz Media commits to resolve complaints about your privacy and our collection or use of your personal information. EEA or Swiss individuals with inquiries or complaints regarding this Policy should first contact Quartz Media at the address given below. Quartz Media will investigate and attempt to resolve complaints regarding use and disclosure of personal information by reference to the principles contained in this Policy.
Non-Human Resources Data
Quartz Media has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint. This service is provided free of charge to you.
Human Resources Data
If your complaint involves human resources data transferred to the United States from the EU and Switzerland in the context of the employment relationship, and Quartz Media does not address it satisfactorily, Quartz Media commits to cooperate with the panel established by the EU data protection authorities (DPA Panel) or the Swiss Federal Data Protection and Information Commissioner, as applicable and to comply with the advice given by the DPA panel or Commissioner, as applicable, with regard to such human resources data. To pursue an unresolved human resources complaint, you should contact the state or national data protection or labor authority in the appropriate jurisdiction. Complaints related to human resources data should not be addressed to the BBB EU PRIVACY SHIELD.
Contact details for the EU data protection authorities can be found at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm
Contact details for the Swiss Federal Data Protection and Information Commissioner can be found at: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/links/data-protection—switzerland.html
If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction
Questions regarding this Policy should be submitted to Quartz Media:
Office of General Counsel
ATTN: Privacy Team
Quartz Media, Inc.
675 Avenue of the Americas, Suite 410
New York, New York 10010
LIMITATIONS & CHANGES
Adherence by Quartz Media to the EU-U.S. and Swiss-U.S. Privacy Shield Principles may be limited (a) by the exception for personal information that is gathered for publication, broadcast, or other forms of public communication of journalistic material as well as information found in previously published material disseminated from media archives; (b) to the extent required to respond to a legal obligation; (c) to the extent necessary to respond to requests by authorities; and (d) to the extent expressly permitted by an applicable law, rule or regulation.
This Policy may be amended from time to time, consistent with the requirements of the EU-U.S. and Swiss-U.S. Privacy Shield Principles. The amended Policy will be made publicly available via Quartz Media’s website.