NPSx℠ Privacy Policy

Last updated on 7 February 2024

 

This Privacy Policy applies to the NPSx platform hosted on www.npsx.com, including, but not limited to, MyCX, CX Training, CX Roadmap & Accreditation, CX Community and NPS Loyalty Forum and KineticsSM AI (the "Platform") provided by Bain & Company Inc., a company headquartered in Boston, Massachusetts, USA, and/or the other companies of the Bain group ("Bain", “we”, “us”) who act as data controllers1 with respect to the personal data2 you share with Bain under this Policy.

 

This policy only covers the personal data handled by Bain as a data controller. If your employer subscribed to NPSx and gave you access to the Platform (i.e. you did not directly subscribe), your employer is the data controller of the data relating to the training or courses you are taking on the Platform and they can provide more information about how they use such data. This policy will not apply to such data and will only apply to personal data that Bain is a data controller of, such as your account registration data (name, contact details and login details), data about your interactions with experts and peers, data processed for support purposes or the data collected via cookies and other similar technologies.

 

Please note that this Privacy Policy does not apply to any Bain platform or website other than the Platform unless they explicitly link to this Privacy Policy.

 

Bain knows that your privacy is important to you and takes user privacy very seriously. We are committed to protecting your personal data in accordance with this Privacy Policy.

 

Bain reserves the right, at its sole discretion, to alter and update this Privacy Policy from time to time. We therefore invite you to review the current version of the Privacy Policy each time you return to our Platform.

 

Information we collect and how we use it

 

Bain might collect personal data from you such as your name, contact details, occupation, industry, region/country, IP address, which videos you view, which exercises and tasks you complete, which live sessions you attend, which courses you take on the Platform, your interaction with experts and peers on the Platform, and any other information you choose to share through the Platform including on the NPS Loyalty Forum and CX Community.

 

Bain will use your personal data to administer your access to the Platform, track your user activity, and to analyse and improve the user experience of the Platform.

 

Some of your personal data is collected and used to enable Bain to provide you with the services you requested. Other information might be optional (e.g. adding a profile picture or posting messages on the forum) and by using our Platform and submitting such information to us, you confirm that you understand and, to the extent we rely on your consent to process some of your personal data, you explicitly agree to Bain using your personal data for the purposes and in the manner described in this Privacy Policy. You do not have to provide us with any personal data. However, if you do not, we may be unable to provide you with access to the Platform.

 

Please do not send us any information you do not wish Bain to use.

 

 

Bain will keep your personal data for as long as needed to administer your access to the Platform or for as long as we have a relationship with you.

 

Please note that Bain is not responsible for any information you may disclose publicly in any chat rooms, message boards, or similar user forums or web pages, including those hosted on or linked to our Platform (“Forums”). You should keep in mind that, whenever you publicly disclose information about yourself online (for example, via such Forums), such information could be collected and used by people whom you do not know. In addition, certain Forums may display IP addresses along with the message poster's name and message. Bain bears no responsibility for any action or policies of any third parties who collect any information users may disclose on any Forums.

 

Use of cookies on the Platform

 

Our Platform may use cookies or other technology (“Cookies”) to obtain certain types of information about you when you browse our Platform. You can find information about what data is collected and how it is used in our Cookie Policy.

 

Who we share your personal data with

 

We may share your personal data with others, such as:

 

  • other offices in the Bain group – for a complete list of our offices, please refer to the Offices page of the bain.com website;
  • if your subscription is purchased for you by your employer then we may share your personal data with your employer in order to give them details on your use of the Platform including the courses you have taken;
  • carefully selected third party service providers, or IT systems providers so they can provide services to Bain, such as hosting services, support services, analytics services, email notification services, customer relationship and community management services;
  • external contractors carrying out services for and on behalf of Bain;
  • our advisors; and
  • law enforcement authorities or other government bodies when we are required to do so.

 

Third parties, other than law enforcement authorities or government bodies, will only handle your personal data on behalf of Bain for the purposes described in this Policy. Bain will not sell or otherwise share your personal data with such third parties for their own use unless you have consented to it separately and explicitly.

 

The companies of the Bain group and other third parties we share your information with may be located in other countries, including countries that do not offer the same protection to your personal data as the country in which you reside. Where that is the case, Bain ensures that your personal data is protected by using appropriate legal mechanisms. If you reside in the European Union, such mechanisms include using contracts or wording approved by the European Commission (called “Standard Contractual Clauses”3).

 

Links to other websites

 

Our Platform may contain links to third party websites that are governed by their own terms and privacy policies, including social network sites. Bain is not responsible for the privacy practices of such websites, which you should review before browsing or submitting information to them. Bain does not bear any liability and responsibility for the content or your use of these websites.

 

A link to a third party website does not mean that Bain endorses or accepts any responsibility for the content or the use of such website.

 

Security of your personal data

 

Bain has implemented appropriate technical and organizational security measures in order to protect your personal data from loss, misuse, alteration, or destruction. Such measures might include anonymizing4 or pseudonymizing5 data where possible. Authorized Bain personnel and third parties mentioned above will only have access to your personal data to the extent they need it to do their job or provide their services. Despite these precautions, however, Bain cannot guarantee that unauthorized persons will not obtain access to your information.

 

Your Rights

 

Depending on where you reside you might have the right to request access to, rectification or erasure of your personal data and to object to or ask for the restriction of the processing of your personal data. You might also have the right to request that we correct incorrect, inaccurate or out-of-date information about you or to withdraw your consent and request that we stop processing or delete your personal data.

 

If you receive marketing communications from Bain, you can opt out of receiving future emails from Bain or unsubscribe from participating in our programs through the "preferences" page, which is accessible in every marketing email you receive from Bain.

 

If you wish to make a request about your personal data, please contact us at [email protected]. Please note that we will take reasonable steps to check your identity before handling your request.

 

If you think we are handling your information unlawfully, we encourage you to get in touch with us at [email protected]. You may also have the right to lodge a complaint with your national supervisory authority.

 

Please note that we will take reasonable steps to check your identity before handling your request.

 

Children

 

Our Platform is not directed at children 16 years of age or younger. Bain will not intentionally collect information about anyone under the age of 16, and requests that no such information be submitted to us.

 

USA – California

 

As required under the California Consumer Privacy Act (“CCPA”), the categories of personal data (referred to as “personal information” in the CCPA) collected and processed by Bain, the purposes for which they are processed and the third parties such data is shared with are described in this Privacy Policy.

 

We have not sold and do not sell your personal data within the meaning of the CCPA.

 

If you are a resident of the State of California, you may have the right to request Bain to disclose to you:

  • the categories of personal data we have collected about you;
  • the categories of sources from which such personal data was collected;
  • the business or commercial purpose for which we have collected your personal data;
  • the categories of third parties with whom we share your personal data; and
  • the specific pieces of personal data we have collected about you.

You may also have the right to request that we delete your personal data subject to the limitations of the CCPA.

 

If you wish to exercise your rights, please submit your request by sending an email to [email protected]. We may have to request additional information to verify your identity.

 

Bain will not discriminate against you because you have exercised your rights under the CCPA.

 

Contact

 

If you have any questions about this Privacy Policy or how Bain handles your personal data, please contact [email protected] or Bain’s Global Data Protection Officer:

 

Email: [email protected]

 

Post: Bain & Company, Inc. United Kingdom, 40 Strand, London WC2N 5RW, United Kingdom.

 

[1] The data controller is the person or company that, together or jointly with others, determines the purposes (why) and means (how) of the processing of personal data.

[2] Personal data is any information that relates to an individual who is identified or identifiable, for instance by reference to a name, an identification number or an online identifier.

[3] Standard Contractual Clauses are an agreement that can be entered into by companies for transfers of personal data outside of the European Union. They are a mechanism approved by the European

Commission to ensure adequate safeguards to personal data when it is transferred outside of the European Union.

[4] Anonymizing means transforming data in such a way that it is no longer identifiable, i.e. the data can no longer be linked to an individual, even if combined with other information. Anonymous data is not considered "personal data".

[5] Pseudonymizing means transforming data in such a way that it is no longer identifiable without the use of additional information. Pseudonymous data is still considered "personal data".