1. Introduction

We are committed to safeguarding the privacy of our website visitors. This policy applies where we are acting as a data controller with respect to the personal data of our website visitors; in other words, where we determine the purposes and means of the processing of that personal data.

We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website we will ask you to consent to our use of cookies when you first visit our website.

Our website incorporates privacy controls which affect how we will process your personal data. By using the privacy controls, you can specify whether you would like to receive direct marketing communications. You can access the privacy controls via [https://www.cmcgi.org/content/gi-personal-data-processing-policy].

In this policy, "we", "us" and "our" refer to International Council of Management Consulting Institutes.

2. Legal framework

In accordance with the requirements of Directive (EU) 2002/58/EC ("E-Privacy Directive") and Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC ("GDPR") applicable from May 25th 2018, we have the obligation to manage safely and only for specified purposes the personal data that you provide us with, by using our website in accordance with the provisions of the GDPR.

For more details on the content of these legal requirements, please visit the following links:

https://eur-lex.europa.eu/legal-content/RO/TXT/?uri=CELEX%3A32016R0679

3. How we collect and use (process) your personal information

  1. 1 Personal Information You Offer:

We can collect, store and use the following personal data:

  • Information about your computer and about visiting and using this website (including your IP address, geographic location, browser type and version, operating system, referral source, visit duration, page views);
  • The information you provide when using the Contact Form (including your contact information);
  • The information you provide when subscribing to email and / or newsletters notifications (including your name and email address);
  • The information you provide when you use the services or information that is generated during the use of these services (including timing, frequency and service usage pattern);
  • The information contained in or related to any communication you send or send to us through this site (including correspondence with us, the content of the communication and the data associated with the communication);
  • Any other personal data you have chosen to send us.

We may process data about your use of our website ("usage data"). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is our analytics tracking system. The legal basis for this processing is our legitimate interests, namely monitoring and improving our website and services.

We may process your account data ("account data"). The account data may include your name and email address. The account data may be processed for the purposes of operating our website, providing our services, ensuring the security of our website and services, maintaining back-ups of our databases and communicating with you. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business.

We may process information contained in any enquiry you submit to us regarding our services ("enquiry data"). The enquiry data may be processed for the purposes of offering, marketing services to you. The legal basis for this processing is consent.

  1. What happens if you do not give us your data

You can enjoy this site without providing us your personal data or your consent. Some personal information is required for our site to be able to provide you with the services you have requested and to log in to your account, so that we know you are you and not someone else. You can manage your data and you can withdraw marketing communications/newsletters at any time.

Please note that if you do not give us your data, we will most likely not be able to communicate with you and provide you with the services described below.

  1. The Purposes of Using Your Personal Data

Personal data transmitted through this site and personal data that we have collected from you or from third parties or from public sources will be used for the purposes specified in this Privacy Policy. Depending on the relationships that we have or want to have with you, we may use your personal data for the following purposes based on the legal bases outlined below:

  1. Communications based on legitimate interest according to art. 6 par. (1) lit. f) from GDPR: if you contacted us through this site or otherwise, we can process your name, contact details, phone number, location, and other information you have provided us with in order to answer your questions, to organize the meeting, a telephone conversation or other communications;
  2. Marketing and public relations, based on your consent according to art. 6 par. (1) lit. a) from GDPR: if you are a visitor of our site, we can process through cookies and other web beacons your IP address, geographic location, browser type and version, operating system, reference source, visit duration, log files, interactions with our web site. The data automatically collected about you or your device in accordance with this Privacy Policy will be used in order to conduct marketing research and analyze the characteristics of visitors of the site, to assess the impact of our marketing communications and to adapt it to the detected trends, to plan our future marketing activities, prepare our business analysis, personalize services and communications for you to guide your advertising or to offer direct marketing of the same or similar services. Also, if you are our subscriber to the newsletter, you can receive our marketing materials, we can process the personal data you have provided to us to distribute promotional materials, we can make announcements about our services, we can personalize this site and our marketing communication for you, we can send you notifications by e-mail, we can send newsletters and our e-mail magazines (you can inform us at any time if you are not interested in these materials) or we may send marketing communications about our activity that we think might be of interest to you.
  3. Security, based on legitimate interest under Art. 6 par. (1) lit. f) from GDPR: If you are a visitor to this site, we may process the personal data that you have uploaded, data collected automatically about you or your device in accordance with this privacy notice (for example, cookies, web alerts) to keep this website secure against fraud, to protect our rights and interests . We mention that this information can be disclosed for purposes of investigation or prosecution.

4. Disclosure and transfer of personal data

The information we collect from you will be processed in the European Economic Area and if the case may be, in exceptional situations, outside of the European Economic Area, depending on the purpose of the processing. We strives to apply appropriate safeguards to protect the confidentiality and security of your personal data during the transfer and to use it only in accordance with our relationship and the practices described in this Privacy Policy. We minimize the risk to your rights and freedoms by not collecting or storing sensitive information about you.

To the extent permitted by applicable data protection laws, we may disclose your personal data to customers (to engage in business or to confirm the high quality of our services), auditors, agencies, supervisors or other external service providers to fulfill our contractual obligations.

We will clearly indicate to you each recipient if it is well known at the time of processing initiation.

5. Your rights

GDPR offers certain rights to the data subjects.  Your principal rights under data protection law are:

(a)       the right to access;

(b)       the right to rectification;

(c)       the right to erasure;

(d)       the right to restrict processing;

(e)       the right to object to processing;

(f)        the right to data portability;

(g)       the right to complain to a supervisory authority; and

(h)       the right to withdraw consent.

You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.

You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.

In some circumstances you have the right to the erasure of your personal data without undue delay. Those circumstances include: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defense of legal claims.

In some circumstances you have the right to restrict the processing of your personal data. Those circumstances are: you contest the accuracy of the personal data; processing is unlawful but you oppose erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise or defense of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise or defense of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.

You have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.

To the extent that the legal basis for our processing of your personal data is:

(a)       consent; or

(b)       that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.

If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.

To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.

You may exercise any of your rights in relation to your personal data by written notice to us to [C/O Maurer & Stager AG, Fraumünsterstrasse 17/Postfach 318, CH – 8024 Zurich] OR [SENDING A WRITTEN NOTICE AT THE FOLLOWING membership@cmcgi.org].

6. Personal Data Security

In order to protect the confidentiality of the data and personal information you submit through the use of our website, we will maintain physical, technical and administrative safeguards. We update and test our security technology continuously. We restrict access to your personal data to those employees who need to know that information to provide you with the requested benefits or services. In addition, we train our employees on the importance of confidentiality and maintain the confidentiality and security of your information.

7. Site Security

We cannot guarantee that data transmissions on the Internet can be 100% secure. As a consequence, we cannot guarantee the security of the information you submit and in consequence you understand that any information you transfer to us is at your own risk. However, we use site security measures in line with the best practices to protect the website, emails and mailing lists. These measures include technical, procedural, monitoring and tracking measures designed to protect data from improper use, unauthorized access or disclosure, loss, alteration or destruction of data.

We are aware that there may be mistakes or unauthorized program inaccuracies that almost every web site, service, or user intersects. In these situations, our goals are to move quickly to isolate the problem, to ensure or restore the proper functionality, and to minimize our users' misgivings. If necessary, we will notify the competent authorities of any such incidents of misuse or unauthorized incursion into our site.

8. Questions, concerns, complaints

If you have any questions about your personal information or if you wish to exercise your rights or have any concerns or complaints, please contact us by sending an email to [membership@cmcgi.org].

If you do not want to use the information you have provided us, please send us an email [membership@cmcgi.org] with the title "Do not use my data" and your name.

To update or correct your personal information, please contact us at [membership@cmcgi.org].

Last Updated: [September 2018].