Introduction
This Privacy notice is to help you understand what information we, as a Data Controller, collect, why we collect it, and how you can manage your information when you:
- Interact or use our website, including when you download materials, or ask us to contact you.
- Register and attend or speak at our one of our events e.g. Awards, Honours, or webinars (“Event” or collectively “Events”).
- Provide your Personal Information for the purposes of administering our services and managing our relationship with you in any manner (collectively “Supporter Benefits”) e.g. setting up an account or collecting your Personal Information to process an invoice for accounting purposes.
You can easily navigate to specific parts that explain how we use your data by using the panel on the left-hand side of this notice.
We will tell you:
- Why we can process your information
- The purposes of processing
- Whether you must provide your data to us
- How long we store it
- Who we may share it with
- Instances of transferring it to another country
- Instances of automated decision making or profiling
- Instances of using Artificial Intelligence to process your data
Who we are
We are Catalyst, a global non-profit, charitable organization, supported by many of the world’s most powerful CEOs and leading companies, (“Supporters”), advance diversity, equity and inclusion in the workplace, building better workplaces for all. One way we do this is by using our research findings to create reports, presentations, and products that help organizations build inclusive workplaces. You can read more about us here.
Data Protection Officer
Catalyst Inc. is headquartered in New York, in the United States of America. Catalyst has appointed an internal data protection officer for you to contact if you have any questions or concerns about Catalyst’s personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Catalyst’s data protection officer. Catalyst’s data protection officer’s name and contact information are as follows:
The Data Protection Officer
Catalyst Inc.
120 Wall Street, 15th Floor,
New York, NY10005
How we collect and use (process) your personal data
Catalyst collects personal data about its Supporter organizations, Supporter employees and individuals who visit our website. We use this information to provide Supporter benefits, including access to Supporter only content and resources on our website, events and our fee for service products. We do not sell personal data to anyone and only share it with third parties who are facilitating the delivery of Catalyst benefits and fee for service products.
We do not knowingly collect information from children.
Most individuals provide their personal data directly to Catalyst. However, in some cases, Catalyst may receive personal data about individuals from third parties. This may happen, for example, if your employer is a Supporter of Catalyst and signs you up to access our website, or when companies provide us with company contact information or contact and employment information for individuals who may be interested in our mission and fee for service products.
We may also collect your information from third parties or third-party websites (e.g., LinkedIn) if you fill out a form on that site requesting content from or register for an event with Catalyst.
You may access and update your data with Catalyst and contact us at [email protected] at any time.
Personal information Catalyst collects:
A. Supporters
When your organization becomes a Catalyst Supporter, we collect information about you and your organization including but not limited to your name, your employer’s name, your work email address (including your country location), your email address and payment details when making a donation. We may also collect a contact phone number.
We process your personal information for administrative purposes, to deliver benefits to your organization, and to inform you of Catalyst-related events, content, and other opportunities associated with your Supporter organization. Catalyst may also use this information to help Catalyst understand our Supporters’ needs and interests to better tailor our products and services to meet these needs.
Personal data categories | Purpose | GDPR Lawful Basis |
First name, last name, company name, work email address, contact telephone number, company name, job title and payment information | Provide Supporter benefits including access to the website and other content; to receive donations or fee for service payments | Article 6 (1)(f) - Catalyst’s legitimate interests |
Employment and other professional biographical information; professional activities; location; level of experience, topics of interest | Provide support; inform Supporter of benefits and professional opportunities; understanding Supporter’s needs and interests to better tailor products and services to meet Supporter needs; verifying registration and ensuring only registered guests are allowed attendance at events; business intelligence | Article 6 (1) (a) - consent |
B. Live events
Catalyst hosts live, in-person and virtual events throughout the year. These include conferences and events such as the Catalyst Awards Dinner & Conference, and Catalyst Honours. If you register for one of our events and you are a Supporter employee, we will access the information in your account to provide you with information and services associated with the event. You may be asked to provide more information when signing up for an event than is found in your profile (e.g., whether it’s your first Catalyst event and your meal preferences).
If you are not a Supporter employee and you sign up for one of our events, we will collect the following information: name, email, company, title, industry, address, phone number, whether it’s your first Catalyst event, your meal preferences, and any special accommodations (e.g. mobility assistance, allergies).
Catalyst uses the information provided by event attendees to provide them with event services, including badge printing, tailoring sessions to meet the audience profile and to determine the sessions likely to require the biggest rooms, and related purposes connected with the event. We also use the information for billing purposes, as some attendees do not pay at the time of registration.
If you are a presenter or speaker at one of our events, we will collect information about you including your name, employer and contact information, biography and photograph. We may also collect information provided by event attendees who evaluated your performance as a presenter. We may also make and store a recording of your voice and likeness in certain instances.
We keep a record of your participation in Catalyst events as an attendee or presenter. This information may be used to provide you with information relating to the event or to tell you about other events and publications. It may also be used to help Catalyst understand our Supporters’ needs and interests to better tailor and future events.
In association with attending one or more of our events, you will have the option to download the Catalyst Events App to help you navigate the conference and plan your schedule. The Catalyst Events App’s sole purpose is to act as a mobile interface for Catalyst events, not to collect your data. Catalyst does not collect any personal information from your device. We do not access any other applications on your device. We do not monitor app data or analytics, nor do we use any tracking or analytics tools on this app. Although we may send “push notifications” to your app, Catalyst does not otherwise use it to communicate with you.
When you register for a live event, you will have an opportunity to opt-in to be listed in an attendee list. This list is shared with event sponsors/exhibitors as well as other attendees who request it.
Personal data categories | Purpose | GDPR Lawful Basis |
Name, contact information, including mobile telephone number, and payment information | Event registration; Attendee Hub validation | Article 6 (1)(f) - Catalyst’s legitimate interests |
Professional biographical information; professional activities information; meal preference | Ensure event subject matter and content is relevant to attendee needs; ensure adequate food and dietary provisions; badge printing; determining which sessions require larger rooms; providing attendees with information and services associated with the event | Article 6 (1)(f) - Catalyst’s legitimate interests |
C. Web conferences
Catalyst offers several webinar and virtual conferences throughout the year. Many of them are free to Supporters and their employees, while non-Supporters may be charged a fee.
Personal data categories | Purpose | GDPR Lawful Basis |
Name and contact information | Access to web conference | Article 6(1)(f) - Catalyst’s legitimate interest |
Payment information | Process payments | Article 6(1)(f) - Catalyst’s legitimate interest |
D. Publications & newsletters
In addition to producing original content, Catalyst also subscribes to news feeds and blogs produced by others, which we often link to from our website and within our newsletters. This means you may find yourself on Catalyst website or reading an email from Catalyst and we will offer you a link to another organization’s website where you will find content on diversity, equity and inclusion that we find relevant and useful to you. At these times, you will be leaving Catalyst’s website. Catalyst is not responsible or liable for content provided by these third-party websites or personal information they may happen to gather from you.
To receive Catalyst newsletters by email, you need to provide Catalyst with at least your first name and last name, an email address, and the country in which you live. The purpose of processing this data is to have the necessary information to deliver Catalyst’s newsletters by email. You may at your own option choose to subscribe to Catalyst News and Updates which may be considered direct marketing. You may unsubscribe at any time to newsletter subscriptions as well as marketing messages.
Catalyst uses a third-party email service provider to manage our subscriptions. Services like this are necessary because email hosts like this are able to send bulk emails, manage subscribe/unsubscribe features, and keep track of open rates and invalid email addresses. When you click on a hyperlink in the email, the URL will include a tracking code. If (and only if) you have accepted [Pardot?] cookie (name of cookie?) through the Catalyst cookie tool, then that information will be recorded in Catalyst’s account with [Pardot] and associated with you. Catalyst uses this information to better understand what information is of interest to its subscribers so it can produce more of that information for them. [Pardot?] does not use or sell this information.
As noted above, you may manage your Catalyst subscriptions by subscribing or unsubscribing at any time. Please note that if you have set your browser to block cookies, this may have an impact on your ability to unsubscribe. If you have any difficulties managing your email or other communication preferences with Catalyst, please contact us at [email protected].
Personal data categories | Purpose | GDPR Lawful Basis |
Name and work email address | Access to email newsletters; direct marketing | Article 6 (1)(f) - Catalyst’s legitimate interest |
E. Web and digital analytics
Catalyst uses Google Analytics to track how often people gain access to or read our content. Provided you have opted-in to analytics cookies, we use this information in the aggregate to understand what content our Supporter’s and visitors to website find useful or interesting, so we can produce the most valuable content to meet your needs.
Personal data categories | Purpose | GDPR Lawful Basis |
Anonymous website usage intelligence | Improve products and services | Article 6(1)(f) - Catalyst’s legitimate interest |
Cookies data | Business intelligence | Article 6(1)(a) - consent |
F. Your correspondence with Catalyst
If you correspond with us by email, the postal service, or other form of communication, we may retain such correspondence, and the information contained in it and use it to respond to your enquiry or to keep a record of your complaint, accommodation request, or similar concern. If you wish to have Catalyst delete your personal information or otherwise refrain from communicating with you, please contact us at [email protected].
Note: if you ask Catalyst not to contact you by email at a certain email address, Catalyst will retain a copy of that email address on its “master do not send” list in order to comply with your no-contact request.
Personal data categories | Purpose | GDPR Lawful Basis |
Name, contact information, communication content | Supporter service and support | Article 6(1)(f) - Catalyst’s legitimate interest |
G. Payment and purchase information
You may choose to purchase fee for service products from, or make an individual donation to, Catalyst using a payment card. Typically, payment card information is provided directly to Catalyst. Catalyst does not store the card information. Occasionally, individuals ask Catalyst employees to, on their behalf, enter payment card information into the PCI/DSS-compliant payment processing service to which the Catalyst subscribes. We strongly encourage you not to submit this information by email. When Catalyst employees receive payment card information from customers or members by email, phone, or mail, it is entered as instructed and then deleted or destroyed. Catalyst relies on the legitimate interest basis for processing this personal data.
Personal data categories | Purpose | GDPR Lawful Basis |
Name; payment information; billing address | Fulfilling fee for service orders and/or donation payments | Article 6(1)(f) - Catalyst’s legitimate interest |
What happens if you don’t give us your data
You can enjoy many of Catalyst’s content and services without giving us your personal data because a great deal of information on our website is available even to those who are not from a Supporter organization. You can also enjoy subscriptions to our newsletters without becoming a Supporter, but you will need to create a profile with us which involves providing your name, email, country and postal code. Some personal information is necessary so that Catalyst can supply you with the services you have purchased or requested, and to authenticate you so that we know it is you and not someone else.
Use of Catalyst website
As is true of most other websites, Catalyst’s website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of the Catalyst’s website, including a history of the pages you view. We use this information to help us design our site to better suit our users’ needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyse trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences.
Catalyst has a legitimate interest in understanding how users, Supporters and potential Supporters use its website. This assists Catalyst with providing more relevant content and products and services, with communicating value to our Supporters and users, and with providing appropriate staffing to meet user and Supporter needs.
Cookies and web beacons
Catalyst makes available a comprehensive Cookie Notice that describes the cookies used on Catalyst’s website and provides information on how users can accept or reject them. Click here to view the notice.
When and how we share your personal data
Information about your Supporter donations or purchases is maintained in association with your Supporter account. The personal information Catalyst collects from you is stored in one or more databases hosted by third-party processors located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. You can view a list of our main third-party processors here.
We do not otherwise reveal your personal data to non-Catalyst persons or businesses for their independent use unless: (1) you request or authorize it; (2) it’s in connection with Catalyst-hosted events and conferences as described above; (3) it is to assist your employer with confirming receipt or consumption of a purchase they made on your behalf or in relation to their donation; (4) the information is provided to comply with the law (for example, to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (5) the information is provided to our agents, vendors or service providers who perform functions on our behalf; (6) to address emergencies or acts of God; or (7) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our users and Site visitors and disclose the results of such aggregated (but not personally identifiable) information to our, service providers, and/or other third parties for marketing or promotional purposes.
The Catalyst website uses interfaces with social media sites such as Facebook, LinkedIn and others. If you choose to "like" or share information from the Catalyst website through these services, you should review the privacy policy of that service. If you are a member of a social media site, the interfaces may allow the social media site to connect your site visit to your personal data.
Transfers of your personal data
Catalyst has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Catalyst website and services, you acknowledge that your personal information will be processed in the United States and, depending on the circumstances, that may involve a transfer of your information to the United States. Catalyst provides safeguards by entering binding, standard data protection clauses where appropriate for the data subjects’ location. Catalyst also enters into data processing agreements and model clauses with its suppliers whenever feasible and appropriate. Since it was founded, Catalyst has received zero government requests for personal information.
For more information or if you have any questions, please contact us at [email protected].
Your rights
The European Union’s General Data Protection Regulation and other countries’ privacy laws provide certain rights for data subjects. A good explanation of them (in English) is available on the website of the Irish Data Protection Commission.
This Privacy Notice is intended to provide you with information about what personal data Catalyst collects about you and how it is used. If you have any questions, please contact us at [email protected]. If you wish to confirm that Catalyst is processing your personal data, or to have access to the personal data Catalyst may have about you, please contact us at [email protected].
You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Catalyst might have received the data from Catalyst; what the source of the information was (if you didn’t provide it directly to Catalyst); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Catalyst if it is inaccurate. You may request that Catalyst erase that data or cease processing it, subject to certain exceptions. You may also request that Catalyst cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Catalyst processes your personal data. When technically feasible, Catalyst will—at your request—provide your personal data to you or transmit it directly to another controller.
You may, at no cost to you, receive a report of most of the personal data Catalyst has regarding you by emailing [email protected]. If access cannot be provided within a reasonable time frame, Catalyst will provide you with a date when the information will be provided. If for some reason access is denied, Catalyst will provide an explanation as to why access has been denied.
For questions or complaints concerning the processing of your personal data, you can email Catalyst’s data protection officer at [email protected].
In many jurisdictions, including but not limited to in the European Union, you have recourse with your nation’s data protection authority. To find your DPA, visit Authorities Listings | Global Privacy Enforcement Network.
Security
To help protect the privacy of data and personally identifiable information you transmit through use of this site, we maintain physical, technical and administrative safeguards. We update and test our security technology on an ongoing basis. We restrict access to your personal data to those employees who need to know that information to provide benefits or services to you. In addition, we train our employees about the importance of confidentiality and maintaining the privacy and security of your information. We commit to taking appropriate disciplinary measures to enforce our employees' privacy responsibilities. You can read more about our security practices in our Trust Center.
Data storage and retention
Your personal data is stored by Catalyst on its servers, and on the servers of third-party cloud-based database management services Catalyst engages, located in the United States. Catalyst retains data for the duration of the Supporter’s relationship with Catalyst and for a period of time thereafter to allow individuals to recover accounts if they decide to renew, to analyse the data for Catalyst’s own operations, and for historical and archiving purposes associated with Catalyst's history as a non-profit organization. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact Catalyst’s Data Protection Officer at [email protected].
Questions, concerns or complaints
If you have questions, concerns, complaints, or would like to exercise your rights, please contact Catalyst’s Data Protection Officer at [email protected].