Effective Date: September 1, 2024
1. INTRODUCTION
This Sawtooth Software Privacy Policy (also referred to as the ‘Privacy Policy’) provides information on the collection, use, and sharing (collectively referred to as ‘processing’ or ‘process’) of personal information or data by Sawtooth Software and its affiliates (“Sawtooth”, “we” or “us”) in connection with your use of Sawtooth websites, mobile applications, community forum, software, applications, and/or social media pages that link to this Privacy Policy; your interactions with Sawtooth during inperson meetings at Sawtooth facilities or at Sawtooth events; and your activities in the course of online or offline sales and marketing campaigns.
This Privacy Policy also explains the privacy rights you have in relation to these processing activities. This Privacy Policy was previously updated on October 31, 2023. However, the Privacy Policy can change over time, for example, to comply with legal requirements or to meet changing business needs. Sawtooth will send users, who have not deleted their Sawtooth account, notice of material changes by email to the primary email address in the user's account The most up-to-date version and previous versions can be found on www.sawtoothsoftware.com/privacy-policy.
As used in this Privacy Policy, ‘personal information’ or ‘personal data’ means information that relates to an identified individual or to an identifiable individual that you submit to us or to one of our affiliates and business partners. For example, this could include, among other things, your name, address, email address, business contact details, or information provided by you. Personal information is also referred to as ‘information about you.’ For more details about the types of information about you that we may process, please refer to Section 4 below.
Sawtooth will never sell your personal information to a third party.
2. SCOPE
a. This Privacy Policy applies to the processing of personal information by Sawtooth of:
- visitors and users of the various Sawtooth sites, including our websites on www.sawtoothsoftware.com, our community forum on https://community.sawtoothsoftware.com/, and our social media pages that link to this Privacy Policy (collectively referred to as the sites);
- users of computer or mobile software and/or application;
- attendees of Sawtooth events (please also note that there is a separate Event Privacy Notice);
- customers and prospective customers and their representatives;
- subscribers to Sawtooth publications and newsletters;
- visitors to Sawtooth facilities;
- suppliers, vendors, and business partners and their representatives.
- job applicants (please also note the Privacy Notice for California Job Applicants or Privacy Notice for EEA/UK Job Applicants, whichever is applicable);
- employees; and
- survey respondents to surveys relating to Sawtooth products and services.
b. The Privacy Policy does not apply to the following activities:
- Personal information collected about you by Sawtooth’s customers or authorized users. Sawtooth customers and authorized users are responsible for their own personal information collection and processing practices, including when customers and authorized users use Sawtooth products or services to process your personal information. To find out more about our customers’ use of personal information about you, you are encouraged to review the relevant privacy policy of the company or institution that collected your information from you. Please consult that company or institution directly if you have any further questions about its use of information about you.
- Personal information processed by Sawtooth to provide third-party service. “Services personal information” is personal information processed by Sawtooth on behalf of a customer or authorized user in order to provide and perform contracted services through third-party vendors/providers. Please refer to the Services Privacy Policy for information on how Sawtooth processes services personal information, available at https://sawtoothsoftware.com/privacy-survey-respondents.
- Personal information you provide on third-party sites not controlled by Sawtooth. When interacting with our websites, you also may or may not be provided links that connect with non-Sawtooth websites, services, social networks, applications, or other features. Enabling these features will lead to other parties, other than Sawtooth, processing information about you. Sawtooth does not have any control over these features of other parties. We encourage you to review the privacy policies of these parties before using these features.
- The use of cookies and similar technologies for storing information, and accessing information stored, on a user's equipment such as a computer or mobile device. To understand more about our use of cookies and similar technologies and your rights under ePrivacy Directive/PECR if you are a resident in EU/UK, CCPA as amended if you are a California resident, or other state laws and regulations if you are a resident in a state with consumer privacy law, please review our Cookie Policy (sawtoothsoftware.com).
3. WHO IS RESPONSIBLE FOR YOUR PERSONAL INFORMATION?
Sawtooth and its subsidiary are responsible for processing your personal information described in this Privacy Policy – upon request, you may see the executed Data Sharing Agreement between Sawtooth Software, Inc. and Sawtooth Software, UK Limited.
4. WHICH CATEGORIES AND SPECIFIC PIECES OF PERSONAL INFORMATION DO WE PROCESS?
Sawtooth can process information about you collected directly from you both offline and online, including when you create a Sawtooth account to access Sawtooth products and services or attend a Sawtooth-sponsored event. Information about you may also be provided to Sawtooth by selected third-party sources, such as data aggregators who may not have a direct relationship with you or by third parties who collect information about you on behalf of Sawtooth such as when you download a Sawtooth white paper.
Specific pieces of information about you that Sawtooth may collect and process, depending on your interaction with Sawtooth, includes:
- name and physical address, email addresses, and telephone numbers;
- demographic attributes, when tied to personal information that identifies you;
- photographs that identify you;
- testimonials;
- transactional data, including products and services ordered, financial details and payment methods;
- company data such as the name, size and location of the company you work for and your role within the company, as well as publicly available company information and activity associated with company data;
- data from surveys conducted by Sawtooth or by third parties on behalf of Sawtooth;
- publicly available information, such as social media posts;
- call recording and chat transcript data from Sales and customer support calls and live chat sessions or interviews;
- unique IDs such as your mobile device identifier or cookie ID on your browser;
- IP address and information that may be derived from IP address, such as geographic location;
- information about a device you use, such as browser, device type, operating system, the presence or use of “apps”, screen resolution, and the preferred language;
- certain location or geolocation information you provide directly or through automated means, if you choose to enable location-based services from your device or Sawtooth app; and
- behavioral data of the internet connected computer or device you use when interacting with the sites, such as advertisements clicked or viewed, sites and content areas, date and time of activities or the web search used to locate and navigate to a site.
Certain online information about you or device information may originate from the use of cookies and similar technologies (for example, pixel tags, and device identifiers) on our sites, within our emails, or sites of third parties. For more information on cookies and similar technologies, please see Section 11 below.
Please note that Sawtooth does not control the content that you may post to Sawtooth Communities forums or social networks; in some cases, such content may be publicly available on the Internet. You should carefully consider whether you wish to submit personal information to these forums or social networks and whether you wish to make your profile available to other users, and you should tailor any content you may submit accordingly.
5. WHY AND HOW DO WE USE YOUR PERSONAL INFORMATION?
We may use personal information for the following business purposes:
- to communicate and respond to your requests and inquiries to Sawtooth;
- to create and administer a Sawtooth account and to deliver functionality on our sites and for their technical and functional management;
- to engage in transactions with customers, suppliers, and business partners and to process orders for Sawtooth products and services;
- to analyze, develop, improve, and optimize the use, function, and performance of our sites, products, and services;
- to manage the security and operation of our sites, facilities, networks, and systems; and
- to comply with applicable laws and regulations and to operate our business.
We may use personal information for the following commercial purposes:
- to administer subscriptions of Sawtooth publications and newsletters;
- to market our products and services or related products and services, and to tailor our marketing and sales activities to your or your company’s interests; and
- to provide select business-to-business services to Sawtooth customers using publicly available information about companies which may include personal information such as the name of a company’s Senior Market Research Manager that is publicly available.
These purposes are described below in further detail.
a. To communicate and respond to your requests and inquiries to Sawtooth:
If you get in touch with us (such as by submitting contact forms on our sites, reaching out to us via Sawtooth Sales chat, attending Sawtooth events or other occasions, sending an email or by visiting social media platforms), we process information about you to communicate with you and to respond to your requests or other inquiries. We can also process personal information to interact with you on third-party social networks.
b. To create a Sawtooth account and deliver functionality on our sites and for their technical and functional management:
When you choose to register with us (such as to create an account for the access and use of our software/application), we need to process the personal information provided by you so that we can create a Sawtooth account for you. Please note, this only applies to personal information controlled by Sawtooth, not personal information Sawtooth processes on behalf of our customers.
c. To engage in transactions with customers, authorized users, suppliers, and business partners, to process purchases of our products and services, and to collect past due invoices:
If you request a quote or place an order for our products and services, or if you provide services to Sawtooth, our employees, customers or partners as a supplier or business partner, Sawtooth processes information about you to engage in and administer the relevant transactions (such as by sending invoices and making payments), administer your order, and help you get started and adopt our products and services (e.g., by contacting you to activate your hosting account).
d. To analyze, develop, improve, and optimize the use, function, and performance of our sites, products, and services:
We may process personal information in order to analyze, develop, improve and optimize the use, function and performance of our sites and products and services, including for quality assurance and training purposes, as well as for marketing and sales campaigns. This includes processing personal information to conduct surveys to improve Sawtooth products and services. In case the sites permit you to participate in interactive discussions, create a profile, post comments, opportunities, or other content, or communicate directly with another user or otherwise engage in networking activities on Sawtooth sites, Sawtooth may process personal information when moderating these activities.
e. To manage the security of our sites, facilities, networks, and systems:
We may collect site use data for security and operations management to help keep our sites, facilities, networks, and systems secure, or to investigate and prevent potential fraud, including ad fraud and cyber-attacks and to detect bots.
f. To comply with applicable laws and regulations and to operate our business:
In some cases, we have to process personal information to comply with applicable laws and regulations. For example, to respond to a request from a regulator or to defend a legal claim. We may also process personal information in the performance and operation of our business, such as conducting internal audits and investigations or for finance and accounting and archiving and insurance purposes.
g. To administer subscriptions of Sawtooth publications and newsletters:
If you subscribe to our blogs and newsletters, we process information about you to administer your subscription to our blogs and newsletters.
h. To market our products, services, events, or related products and services and to tailor marketing and sales activities:
Sawtooth may use information about you to notify you about new product releases and service developments, events, alerts, updates, prices, terms, special offers and associated campaigns and promotions (including via newsletters). Sawtooth may also use personal information to advertise Sawtooth’s products and services or related products and services, and also to have our distributors, resellers, or partners notify you about our products or services or their related products or services (such as via joint sales or product promotions). We do our best to tailor your website visit, marketing experience and our communications to your expressed interests. This happens, for example, if you sign up for a Sawtooth community or webinar.
If you attend an event, please refer to our Event Privacy Notice available at https://sawtoothsoftware.com/event-privacy-notice.
We may also process your personal information to post testimonials on our sites, but we will first obtain your consent to use your name and testimonial.
i. To provide select services to Sawtooth customers using publicly available information which may include personal information such as the name of a company’s Market Researcher or IT/Marketing Director:
For some business-to-business services, we may collect the publicly available names of company researchers and directors to better understand the status of these companies and help inform our services which relate to branding and product bundling with choice analytics and additional survey products and methodologies.
6. WHAT IS OUR LEGAL BASIS FOR PROCESSING INFORMATION ABOUT YOU?
For personal information collected about you in the EU/EEA, the UK and other relevant jurisdictions, our basis for processing is the following:
- We rely on our legitimate interest in processing contact and related information about you in order to communicate adequately with you and to respond to your requests.
- In order to engage in transactions with customers, suppliers and business partners, and to process purchases and downloads of our products and services, we need to process information about you as necessary to enter into or perform a contract with you.
- We process personal information for marketing and sales activities (including events) based on your consent where so indicated on our sites at the time your personal information was collected, or further to our legitimate interest to keep you updated on developments around our products and services which may be of interest to you.
- We rely on our legitimate interest to analyze, develop, improve, and optimize our sites, facilities, products, and services, and to maintain the security of our sites, networks, and systems.
- In order to comply with applicable laws and regulations, such as to comply with a subpoena or other legal process, or to process an opt-out request.
7. FOR WHAT PERIOD DO WE RETAIN PERSONAL INFORMATION
Sawtooth intends to enforce the maintenance of personal information for the following retention periods by the end of 2024:
- Information about you we collect to engage in transactions with our customers, suppliers, and business partners, and to process purchases of our products and services, will be retained for the duration of the transaction or services period, or longer as necessary for record retention and legal compliance purposes.
- If you are a user with either free or expired/terminated subscription, you have registered for a Sawtooth Account to access Sawtooth sites or hosting account, your account and account information will be deleted if you do not log in for 18 consecutive months. We will notify you prior to the deletion of your data. Sawtooth retains backup records for 90 days after the deletion of your personal information.
- If you sign up for Sawtooth marketing materials, your information will be retained for as long as you consent to the subscription. Sawtooth retains backup records for 90 days after the deletion of your personal information.
- Contact information such as your email address or phone number collected online on our sites or offline from our interactions with you at Sawtooth events and conferences, and used for direct marketing and sales activities will be retained for as long as we have an active (customer) relationship with you. Sawtooth retains backup records for 90 days after the deletion of your personal information.
- If you have reached out to us via Sawtooth Sales chat, we will delete all chat transcripts 90 days after the chat has concluded.
- If you have visited a Sawtooth facility, the personal information needed to allow you to enter the facility will be held for one year after your last visit for records retention purposes.
- Personal information needed to retain your opt-out preferences is retained for as long as necessary to comply with applicable law).
8. WHEN AND HOW CAN WE SHARE YOUR PERSONAL INFORMATION?
a. Sharing within Sawtooth:
As a global organization, information about you may be shared globally throughout Sawtooth’s worldwide organization – upon request, you may see the executed Data Sharing Agreement between Sawtooth Software, Inc. and Sawtooth Software, UK Limited. Sawtooth employees are authorized to access personal information only to the extent necessary to serve the applicable purpose(s) and to perform their job functions.
b. Sharing with third parties:
We may share personal information with the following third parties for a business purpose:
- Third-party service providers (for example, credit card processing services, order fulfilment, analytics, event/campaign management, website management, information technology and related infrastructure provision, customer service, e-mail delivery, auditing, and other similar service providers) in order for those service providers to perform business functions on behalf of Sawtooth;
- Relevant third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings);
- As required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside your country of residence, for national security and/or law enforcement purposes.
- Sub-processors that we use to store your personal information and/or content in their US data centers. Cross-border data transfer may occur if you reside or send data from outside of the United States. A list of authorized sub-processors and their data center locations is available at www.sawtoothsoftware.com/GDPR.
We may share personal information with the following third parties for a commercial purpose:
- Sawtooth distributors or resellers for further follow-up related to your interests, specific partners that offer complementary products and services or with third parties to facilitate interest-based advertising; and
- Event partners or conference sponsors for Sawtooth events such as when you scan your badge at a sponsored booth.
When third parties are given access to personal information, we will take appropriate contractual, technical, and organizational measures designed to ensure that personal information is processed only to the extent that such processing is necessary, consistent with this Privacy Policy, and in accordance with applicable law.
9. HOW IS PERSONAL INFORMATION HANDLED GLOBALLY?
Sawtooth is a global corporation with worldwide operations, and personal information is processed globally as necessary in accordance with this policy. If personal information is transferred to a Sawtooth recipient in a country that does not provide an adequate level of protection for personal information, Sawtooth will take adequate measures designed to protect the personal information, such as ensuring that such transfers are subject to the terms of the EU/UK Standard Contractual Clauses or other adequate transfer mechanism as required under relevant data protection laws. Additional country-specific information on data transfers may be provided if you sign up for a Sawtooth account or register for an event.
10. HOW IS YOUR PERSONAL INFORMATION SECURED?
Sawtooth has implemented appropriate technical, physical, and organizational measures designed to protect personal information against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorized disclosure or access, as well as all other forms of unlawful processing.
11. WHAT COOKIES AND SIMILAR TECHNOLOGIES DO WE USE ON OUR SITES?
Cookies and similar technologies (e.g., pixels tags and device identifiers) are used by Sawtooth and our advertising technology partners to recognize you and/or your device(s) on, off and across different services and devices for the purposes specified in Section 5 above.
- When do we use cookies and similar technologies?
Cookies are small text files that contain a string of characters and uniquely identify a browser on a device connected to the Internet. We place cookies in your browser when you visit Sawtooth sites and non-Sawtooth sites that host our plugins or tags. Depending on your jurisdiction, you may be presented with different consent options, including the option to reject all non-essential cookies, prior to Sawtooth placing cookies on your browser. Visitors from all jurisdictions are provided with functionality to opt out of non-required cookies using the cookie preferences tool. We use cookies and other technologies on all our sites to ensure the best possible and secure experience on our sites and to provide you with tailored information on products and services. Sawtooth also uses cookies or similar technologies on its sites to collect online information such as your mobile device ID, IP address, and other information about your device, as well as behavioral data of your device usage on our sites (e.g., pages viewed, links clicked, documents downloaded).
- How can I manage my cookie preferences?
If you are a visitor or our sites, you can use our cookie preferences tool at www.sawtoothsoftware.com/cookie-policy to opt out of cookies that are not required to enable core site functionality, such as advertising and functional cookies.
If you do not want to receive cookies, you can also change your browser settings on your computer or other device you are using to access our services. Most browsers also provide functionality that lets you review and delete cookies, including Sawtooth cookies.
12. WHAT ARE YOUR PRIVACY RIGHTS?
a. California Residents
The California Consumer Privacy Act of 2018 (CCPA) gives consumers more control over the personal information that businesses collect about them and the CCPA regulations provide guidance on how to implement the law. This landmark law secures new privacy rights for California consumers, including:
- The right to know about the personal information a business collects about them and how it is used and shared;
- The right to delete personal information collected from them (with some exceptions);
- The right to opt-out of the sale or sharing of their personal information; and
- The right to non-discrimination for exercising their CCPA rights.
In November of 2020, California voters approved Proposition 24, the CPRA, which amended the CCPA and added new additional privacy protections that began on January 1, 2023. As of January 1, 2023, consumers have new rights in addition to those above, such as:
- The right to correct inaccurate personal information that a business has about them; and
- The right to limit the use and disclosure of sensitive personal information collected about them.
Please note that we do not “sell” or “share” your personal information, as those terms are defined under the CCPA as amended or other applicable state law. Additionally, we do not use your “sensitive personal information” for any purposes that would permit you to limit our use of such information.
b. EEA/UK Residents
- Your Right of Access:
- The right to obtain confirmation that Sawtooth processes your personal information; and
- Access to the personal information Sawtooth has about you.
- Your Right to Rectification:
- You have the right to have factually inaccurate personal information rectified, to the extent Sawtooth has any such inaccurate personal information.
- Your Right to Erasure:
- You have the right to have your personal information erased if:
- Your personal information is no longer necessary for the purpose for which Sawtooth originally collected or processed it;
- You decide to withdraw your consent;
- You object to Sawtooth’s processing of your personal information, and Sawtooth has no overriding legitimate interest or other valid basis to continue the processing of your personal information;
- Sawtooth has processed your personal information unlawfully; or
- Sawtooth must erase your personal information to comply with a legal obligation.
- You have the right to have your personal information erased if:
- Your Right to Restrict Processing:
- You have the right to limit the way Sawtooth uses your personal information in certain circumstances:
- You contested, in good faith, the accuracy of your personal information in Sawtooth’s possession and Sawtooth is verifying the accuracy of such information;
- Sawtooth has unlawfully processed your personal information and you oppose erasure and request restriction instead;
- Your personal information is subject to destruction under Sawtooth’s data retention policy, but you need Sawtooth to keep it in order to establish, exercise, or defend a legal claim; or
- You have objected, in good faith, to Sawtooth processing your personal information, and Sawtooth is considering whether it has legitimate grounds to continue processing your personal information.
- You have the right to limit the way Sawtooth uses your personal information in certain circumstances:
- Your Right to Object to Processing:
- You have the right to object to certain types of processing of your personal information, which include:
- Processing for direct marketing purposes (including profiling); and
- Processing for purposes of scientific/historical research and statistics.
- You have the right to object to certain types of processing of your personal information, which include:
- Your Right to Data Portability:
- Under limited circumstances, you have the right to obtain from Sawtooth and reuse your personal information for your own purposes. This right allows you to move, copy, or transfer your personal information easily, without hindrance to usability. If you request it, Sawtooth may transmit your personal information directly to another organization if this is technically feasible.
c. Contact Us to Exercise Your Rights
Prior to executing your individual rights request, we will first verify your identity by asking you to provide information about yourself and comparing that information with what we have on file about you. The information we may ask you to provide to verify your identity may include your name, or some other personal identifier. You may also authorize an agent to submit a request on your behalf by submitting a written permission that authorizes the agent to act on your behalf and includes your signature. If you use an authorized agent, we will still take steps to verify your identity. Please contact legal@sawtoothsoftware.com, and we will respond to your request consistent with applicable law.
If your inquiry relates to your company’s service account or support of Sawtooth products or services, please note the Sawtooth Privacy team cannot delete, correct, or access service account data or terminate your contracted Sawtooth product or service account. Please email sales@sawtoothsoftware.com to administer service account data.
Our EU Representative can be contacted at:
Rickert Rechtsanwaltsgesellschaft mbH
Colmantstraße 15 53115 Bonn Germany
art-27-rep-SawtoothSoftware@rickert.law
Our UK Representative can be contacted at:
Sawtooth Software UK Limited
C/O Monetta LLP, 232 Stamford Street Central,
Ashton-Under-Lyne,
United Kingdom, OL6 7NQ,
dean@sawtoothsoftware.com
+44 161 768 5267
13. DO YOU COLLECT SENSITIVE INFORMATION AND INFORMATION FROM CHILDREN?
a. Sensitive personal information
We ask that you do not send us and do not share any sensitive personal information (for example, government-issued IDs, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, genetic, or biometric data, criminal background, or trade union membership).
b. Children’s privacy:
As a company focused on serving the needs of businesses, Sawtooth's sites are not directed to minors and Sawtooth does not promote or market its services to minors. If you believe that we have mistakenly or unintentionally collected personal information of a minor through our sites without appropriate consent, please notify us through our inquiry form so that we may immediately delete the information from our servers and make any other necessary corrections. Additionally, please use this same form to request removal of content or information that was posted to our sites when the registered user was under the age of 16. Please note that such requests may not ensure complete or comprehensive removal of the content or information, as, for example, some of the content may have been reposted by another user.
14. DATA PROTECTION OFFICER
Sawtooth has appointed a Global Data Protection Officer. If you believe your personal information has been used in a way that is not consistent with the Privacy Policy or your choices, or if you have further questions, comments or suggestions related to this Privacy Policy, please contact the Global Data Protection Officer by emailing dpo@sawtoothsoftware.com.
Written inquiries to the Global Data Protection Officer may be addressed to:
Sawtooth Software, Inc.
3210 N. Canyon Rd, Ste 202,
Provo UT 84604
U.S.A.
15. FILING A COMPLAINT
If you have any complaints regarding our compliance with this Privacy Policy, please contact us at legal@sawtoothsoftware.com. We will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with this Privacy Policy and in accordance with applicable law. You also have the right to file a complaint with your local competent data protection authority. In the UK, please contact the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, SK9 5AF (https://ico.org.uk/). In the European Economic Area, please contact your local Supervisory Authority. If you are a resident in the state of California, please use this form: Complaint Form - California Privacy Protection Agency (CPPA).
16. SAWTOOTH SOFTWARE AND ITS SUBSIDIARY
Sawtooth Software, Inc. (Holding Company)
3210 N. Canyon Rd, Ste 202,
Provo UT 84604
U.S.A.
Tel: +1 801 477 4700
Sawtooth Software, UK Ltd.
C/O Monetta LLP, 232 Stamford Street Central,
Ashton-Under-Lyne,
United Kingdom, OL6 7NQ,
Tel: +44 161 768 5267
Archived Policies
October 31, 2023
December 29, 2021