Effective Date: January 22, 2020
If you are a California resident, Nevada resident, or data subject located in Europe, please see the "Additional Disclosures for California Residents," "Additional Disclosures for Nevada Residents," and "Additional Disclosures for Data Subjects in Europe" sections below. If you have any questions or wish to exercise your rights and choices, please contact us as set out in Section 11.
2. INFORMATION MAXMIND COLLECTS
Information You Provide
We collect information that you voluntarily provide to us while using the Services, such as when you register an account, make a purchase of one of our products or services, respond to our customer surveys, submit a data correction request, communicate with our customer service team, or apply for a job.
The information we collect includes information relating to identified or identifiable natural persons. The categories of information we collect, including in the last 12 months, include the following: contact data, including your first and last name, telephone number, email address, and postal address; billing information; credentials, including your passwords; content data, including the content of the messages you send to us; IP addresses or IP ranges you submit; and resume data, including data necessary to consider you for a job opening (such as your employment history, writing samples, and references). We also use payment processes to collect and process payment data, including your payment instrument and security code associated with your payment instrument, on our behalf.
You may choose to voluntarily submit other information to us through the Services that we do not request, and, in such instances, you are solely responsible for such information.
Information Collected Automatically
We automatically collect information about your device and how your device interacts with our Services and other services. The categories of information we automatically collect, including in the last 12 months, and the methods by which we may collect such information include the following:
Cookies, Web Beacons, and Embedded Scripts
MaxMind may also use web beacons, small graphic images or other web programming code (also known as "1x1 GIFs" or "clear GIFs"), which may be included in our web pages and e-mail messages. Web beacons may be invisible to you, but any electronic image or other web programming code inserted into a web page or e-mail can act as a web beacon. Web beacons or similar technologies may be used for a number of purposes, including, without limitation, to count visitors to the Services, to monitor how users navigate the Services, to count how many e-mails that were sent were actually opened or to count how many particular articles or links were actually viewed.
MaxMind may also use embedded scripts in connection with the provision of its Services. "Embedded scripts" are programming code designed to collect information about your interactions with a website, such as the links you click on, and may assist our customers in providing us with information used to provide the Services. The code is temporarily downloaded onto your device from our web server, our customer's web server, or a service provider or other party, is active only while you are connected to the website containing the embedded script, and is deactivated or deleted thereafter.
Log File Information
Your web browser automatically sends information to every website you visit, including ours. For example, our server logs may receive and record information such as the pages you access on the Services, referring URLs, your browser type, your operating system, the date and time of your visit, and the duration of your visit to each page.
User Agent Strings
Log file information may also include a user agent string, a series of characters automatically sent with your Internet requests that provide information necessary for smooth Internet communications, such as the operating system and browser you used. A user agent string might be used to identify the device originating a message.
MaxMind may also request access to or otherwise receive information about your device location when you access the Services. Your location data may be based on your IP address and other location-aware technologies. We use location data in connection with providing the Services and to help improve the Services.
Unique Identification Number
Information MaxMind Receives from Other Sources
3. HOW MAXMIND USES INFORMATION
Providing Our Services
As stated above, MaxMind uses information such as your first and last name, telephone number, email address, postal address, billing information, or other contact information we obtain from you, our customers, or our business partners, for the purposes of providing, enhancing, or improving our IP geolocation, fraud detection, demographic targeting, databases, and other services and products.
Communications with You
MaxMind maintains one or more contact lists (with email addresses and other information) to allow MaxMind to communicate with individuals who do business with MaxMind or who have expressed an interest in the Services. We may contact you to confirm your purchases or respond to requests that you make, notify you of changes to your account or the Services, for marketing purposes, or to otherwise inform you of information related to our business or your account with us.
Website Administration and Customization
MaxMind uses the information we collect about you for a variety of website administration and customization purposes. For example, we use your information to process your registration request, provide you with services and communications that you have requested, send you email updates and other communications, customize features and advertising that appear on and off the Services, deliver the Services content to you, measure Services traffic, measure user interests and traffic patterns, and improve the Services.
Usage of IP Addresses
The MaxMind services, including the minFraud service, use IP addresses to help organizations detect and prevent fraudulent activity. Among other things, MaxMind obtains IP addresses and order information (including customer name and billing address) through its minFraud service. MaxMind uses the billing location from this data along with other data to create databases that pair IP addresses with the locations in which they are likely being used, down to a postal code level of resolution.
We also use information with your consent, including for the following purposes: to allow you to participate in our surveys; to serve advertising tailored to your interests on our Services and other services; and to fulfill any other purpose disclosed to you and with your consent.
Some of our lawful bases for processing your information stem from our customers on whose behalf we provide services.
MaxMind uses information that does not identify you for any purpose except as prohibited by applicable law. For information on your rights and choices regarding how we use your information, please see Section 6 below.
4. HOW MAXMIND SHARES INFORMATION
Sharing with Our Service Providers
We provide your information to our service providers, contractors, business partners, and advertisers, for the purpose of delivering services to you as well as for purposes related to Services administration and operation, including conducting analytics and helping us with sales tax compliance. When sharing information for the purpose of providing you with the services you request, we will share your information only as necessary for the service provider working on MaxMind's behalf to complete its work for us. For example, if you use a credit or debit card to complete a transaction on the Services, we will share your credit or debit card number with a payment processing and/or a fulfillment company in order to complete your transaction.
Sharing of Databases
One aspect of MaxMind's products and services is the provision of databases to our customers and other third parties, including our business partners and resellers. These databases include information such as IP addresses and corresponding data pertaining to such IP addresses, such as geolocation data, fraud analysis data, and related information. Such databases are compiled using numerous data sources, including information we receive from our customers when individuals make purchases or conduct other transactions with our customers. In addition, we respond to API queries from our customers, and such responses may include information about the level of risk we associate with information about your device or email address, or your Unique ID.
We share your information with our customers in connection with us processing your information on their behalf. For example, we share your information with our customers to provide them with our products and services, respond to your questions and comments, fulfill your requests, and otherwise comply with applicable law.
Vendors and Other Parties
We may share your information with vendors and other parties for purposes of providing you with tailored advertisements, measuring and improving our Service and advertising effectiveness, and enabling other enhancements. Vendors may act as our service providers, or in certain contexts, independently decide how to process your information.
MaxMind integrates with the service Have I Been Pwned to verify whether your account password has previously appeared in a third party data breach, which may allow MaxMind to evaluate the strength of the password, provide a warning, and/or block the password outright. We are not responsible for the effectiveness or accuracy of their information. For more information on Have I Been Pwned, please visit the website at https://haveibeenpwned.com.
Security and Compliance with the Law
We reserve the right to disclose your information to appropriate third parties if we are required to do so by law or we believe that such action is necessary in order (a) to comply with a legal process such as a search warrant, subpoena, or court order; (b) to protect the company's rights and property; (c) to investigate reports of users sending material using a false email address or users sending harassing, threatening, or abusive messages; (d) to protect against misuse or unauthorized use of the Website or Services; or (e) to respond to emergencies, such as when we believe someone's physical safety is at risk. MaxMind may be required to disclose information in a life-threatening emergency or in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
Transfer of Business
Over time, MaxMind may buy or sell various assets. In the event that we sell some or all of our assets, or our company is acquired by another company, or during the negotiation of such sale or acquisition, our databases and any information we collect may be among the transferred or negotiated assets.
We may share your information for any other purpose disclosed to you and with your consent.
Without limiting the foregoing, in our sole discretion, MaxMind shares information that does not identify you with third parties, including our customers, for any purpose except as prohibited by applicable law. For information on your rights and choices regarding how we share your information, please see Section 6 below.
5. ANALYTICS AND ONLINE TRACKING
6. YOUR RIGHTS AND CHOICES
Opt-Out of Email Communications
If you are a registered member of the Services, you can make changes to your account information by logging into the Website and modifying your preferences. If you do not wish to receive email notifications from us, you may opt-out by contacting us at firstname.lastname@example.org with your request. In addition, certain email communications we send to you, such as newsletters and promotional announcements, contain a clearly worded "Opt-Out" or "Unsubscribe" link allowing you to withdraw your permission for future mailings. Please note that we reserve the right to send you certain communications relating to your account or use of the Services (for example, administrative and service announcements) and these transactional account messages may be unaffected even if you opt-out from marketing communications.
Opt-Out from Database Sharing
Blocking or Deleting Cookies
You can manually delete cookies, which are normally located in your temporary Internet folder or cookie folder. You can also reset the preferences in your web browser to notify you when you have received a cookie or, alternatively, to refuse to accept cookies. Deleting or blocking cookies will prohibit your ability to make online purchases on the Services and to use and access portions of the Services that require logging in with a username and password, and may affect other functionality.
Analytics and Advertising
Some of the advertisers and service providers that perform advertising-related services for us and our partners may participate in the Digital Advertising Alliance ("DAA") Self-Regulatory Program for Online Behavioral Advertising. To learn more about the DAA and how you can exercise certain choices regarding interest-based advertising, visit https://www.aboutads.info/choices. Some of these companies may also be members of the Network Advertising Initiative ("NAI"). To learn more about the NAI and your opt-out options for their members, see https://www.networkadvertising.org/choices/. Please be aware that, even if you are able to opt out of certain kinds of interest-based advertising, you may continue to receive other types of ads. Opting out only means that those selected members should no longer deliver certain interest-based advertising to you, but does not mean you will no longer receive any targeted content and/or ads (e.g., from other ad networks). MaxMind is not responsible for effectiveness of, or compliance with, any third-parties' opt-out options or programs or the accuracy of their statements regarding their programs.
Your browser settings may allow you to automatically transmit a "Do Not Track" signal to websites and online services you visit; however, there is no consensus among industry participants as to what "Do Not Track" means in this context. Like many websites and online services, unless and until the law is interpreted to require us to do so, the Website does not alter its practices when it receives a "Do Not Track" signal from a visitor's browser. To find out more about "Do Not Track," you may wish to visit https://www.allaboutdnt.com.
7. INTERNATIONAL TRANSFER
MaxMind implements reasonable administrative, physical, and technical security measures to help protect your data from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. However, no physical or electronic security system is impenetrable. MaxMind cannot guarantee the security of the Service's servers or databases, nor can we guarantee that information you supply will not be intercepted while being transmitted to us over the Internet.
9. POLICY REGARDING CHILDREN
The Services are not intended for use by children under the age of thirteen years old. MaxMind does not knowingly collect information from children under the age of thirteen. If you are a parent or guardian, and believe we have collected information about your child in violation of this policy, please contact us at the address set forth in Section 11 below. We do not knowingly "sell" as defined by the CCPA the personal information of minors under 16 years old who are California residents without their affirmative authorization.
11. CONTACT FOR ADDITIONAL INFORMATION, OPTING OUT, DATA ACCESS AND CORRECTION, AND DISPUTES
By email: email@example.com
Tawa Gonzalez (Privacy Agent)
14 Spring Street, Suite 3
Waltham, MA 02451
For EU-specific requests, including our compliance with Privacy Shield, please contact our Data Protection Officer at:
By email: firstname.lastname@example.org
Data Protection Officer
14 Spring Street, Suite 3
Waltham, MA 02451
12. ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS
These additional disclosures apply only to California residents. The California Consumer Privacy Act of 2018 ("CCPA") provides additional rights to know, delete and opt out, and requires businesses collecting or disclosing personal information to provide notices and means to exercise rights.
California Notice of Collection
In the past 12 months, we have collected the following categories of personal information enumerated in the CCPA:
- Identifiers, including name, address, email address, account name, IP address – and an ID number assigned to your account.
- Customer records, phone number, billing address, and credit or debit card information.
- Commercial information, including purchases and engagement with the Services.
- Internet activity, including history of visiting and interacting with our Services, browser type, browser language and other information collected automatically.
- Geolocation data.
- Employment and education data, including information you provide when you apply for a job with us.
- Inferences drawn.
For more information on information we collect, including the sources we receive information from, review the "Information MaxMind Collects" section above. We collect and use these categories of personal information for the business purposes described in the "How MaxMind Uses Information" section above, including to provide and manage our Services.
MaxMind discloses the following categories of personal information for commercial purposes: identifiers, demographic information, commercial information, internet activity, geolocation data and inferences. We use and partner with different types of entities to assist with our daily operations and manage our Services. Please review the "How MaxMind Shares Information" section above for more detail about the parties we have shared information with.
To the extent "sale" under the CCPA is interpreted to include the disclosure of MaxMind’s databases as set out in the "How MaxMind Shares Information" section or use of advertising technology activities as set out in the "Analytics and Advertising" section, MaxMind will comply with applicable law as to such activity. Please note that where we use and disclose personal information for purposes related to security, fraud detection, and other similar purposes, some of your rights may be limited to the extent that they adversely affect the rights and freedoms of other consumers.
Right to Know and Delete
If you are a California resident, you have the rights to delete the personal information we have collected from you and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:
- The categories of personal information we have collected about you;
- The categories of sources from which the personal information was collected;
- The categories of personal information about you we disclosed for a business purpose or sold;
- The categories of third parties to whom the personal information was disclosed for a business purpose or sold;
- The business or commercial purpose for collecting or selling the personal information; and
- The specific pieces of personal information we have collected about you.
To exercise any of these rights, please submit a request through our online form available at Right to Know: https://support.maxmind.com/privacy-center/ccpa-right-to-know/ and Right to Delete: https://support.maxmind.com/privacy-center/ccpa-right-to-delete/, call our toll free number at 1-844-802-0220, or email us at email@example.com. In the request, please specify which right you are seeking to exercise and the scope of the request. We will confirm receipt of your request within 10 days. We may require specific information from you to help us verify your identity and process your request. If we are unable to verify your identity, we may deny your requests to know or delete.
If personal information about you has been processed by us as a service provider on behalf of a customer and you wish to exercise any rights you have with such personal information, please inquire with our customer directly. If you wish to make your request directly to us, please provide the name of our customer on whose behalf we processed your personal information. We will refer your request to that customer, and will support them to the extent required by applicable law in responding to your request.
Right to Opt-Out of Sale
To the extent MaxMind sells your personal information as the term "sell" is defined under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information by us to third parties at any time. You may submit a request to opt-out by clicking Do Not Sell My Personal Information: https://support.maxmind.com/privacy-center/ccpa-do-not-sell/ccpa-do-not-sell-opt-out/. You may also submit a request to opt-out by emailing us at firstname.lastname@example.org.
You can designate an authorized agent to submit requests on your behalf. However, we will require written proof of the agent’s permission to do so and verify your identity directly.
Right to Non-Discrimination
You have the right not to receive discriminatory treatment by us for the exercise of any of your rights.
Shine the Light
California's "Shine the Light" law permits customers who are California residents to request certain details about how a business shares their personal information as defined by "Shine the Light" with third parties (and in some cases affiliates) for those third parties' or affiliates' own direct marketing purposes. California customers may request information about our compliance with this law by contacting us by e-mail at email@example.com or by mail at the address set forth in Section 11 above. Any such inquiry must include "California Privacy Rights Request" in the first line of the description and include your name, street address, city, state, and ZIP code. Please note that we are only required to respond to one request per customer each year, and we are not required to respond to requests made by means other than through this email or mail address.
13. ADDITIONAL DISCLOSURES FOR NEVADA RESIDENTS
Nevada law requires certain businesses to establish a designated request address where Nevada consumers may submit requests directing the business not to sell certain kinds of personal information that the business has collected or will collect about the consumer. A sale under Nevada law is the exchange of personal information for monetary consideration by the business to a third party for the third party to license or sell the personal information to other third parties. If you are a Nevada consumer from whom MaxMind has collected personal information and you wish to submit a request relating to our compliance with Nevada law, please contact us as at firstname.lastname@example.org.
14. ADDITIONAL DISCLOSURES FOR DATA SUBJECTS IN EUROPE
EU data protection law makes a distinction between organizations that process personal data for their own purposes (known as "controllers") and organizations that process personal data on behalf of other organizations (known as "processors").
MaxMind also operates as a controller with respect to certain of its services and/or databases. For example, MaxMind operates as a controller in connection with personal data collected from visitors through its website, including through data correction requests. Also, when MaxMind combines personal data from different customers, like many kinds of analytics services, it may do this both as a processor at its customers' instruction and as a controller itself for the purpose of providing services to all of its customers. For example, MaxMind may process and aggregate or otherwise de-identify some of the personal data that a customer shares with MaxMind in order to make that personal data part of another database for one or more other services provided to MaxMind customers.
Data Subject Rights
If you are a data subject in Europe, you have the right to access, rectify, or erase any personal data we have collected about you through the Services. You also have the right to data portability and the right to restrict or object to our processing of personal data we have collected about you through the Services. In addition, you have the right to ask us not to process your personal data (or provide it to third parties to process) for marketing purposes or purposes materially different than for which it was originally collected or subsequently authorized by you. You may withdraw your consent at any time for any data processing we do based on consent you have provided to us.
To exercise any of these rights, contact us using the information at Section 11 above and specify which right you intend to exercise. We will respond to your request within 30 days. We may require additional information from you to allow us to confirm your identity. Please note that we store information as necessary to fulfill the purposes for which it was collected, and may continue to retain and use the information even after a data subject request for purposes of our legitimate interests, including as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
If your information has been processed by us on behalf of one of our customers and you wish to exercise any rights you have with such information, please inquire with our customer directly. If you wish to make your request directly to MaxMind, please provide the name of the MaxMind customer on whose behalf MaxMind processes your information. We will refer your request to that customer, and will support them to the extent required by applicable law in responding to your request.
If you have any issues with our compliance, you have the right to lodge a complaint with a European supervisory authority.
MaxMind complies with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal data from the European Union, the United Kingdom and Switzerland to the United States, respectively. MaxMind has certified that it adheres to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability.
MaxMind is subject to the investigatory and enforcement jurisdiction of the United States Federal Trade Commission in complying with its commitments under the Privacy Shield Principles. We hereby affirm our commitment to subject to the Privacy Shield Principles all personal data transferred from the European Union, the United Kingdom and Switzerland in reliance on Privacy Shield. This means that MaxMind shall be liable to you for any third party agent to which we transfer your personal data and that processes such personal data in a manner that violates the Privacy Shield Principles, unless we can demonstrate that we are not responsible for the resulting damages. MaxMind takes reasonable steps to ensure that personal data is relevant to its intended use and is accurate, complete, and current and retained only as long as needed for an intended or compatible purpose.