Privacy & Data Protection Commitments

 

Effective Date: July 1, 2026

Audiense, LLC (“Audiense”), including its affiliated entities and subsidiaries, is committed to responsible data practices and maintaining a privacy program designed to support compliance with applicable privacy and data protection laws, including:

  • EU General Data Protection Regulation (GDPR)
  • UK GDPR and Data Protection Act 2018
  • California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)
  • Other applicable U.S. state privacy laws where relevant

Our privacy and security practices are designed to align with applicable legal requirements and industry standards.

Privacy by Design

We incorporate data protection principles into our product development and operational processes. This includes consideration of:

  • Data minimization
  • Purpose limitation
  • Role-based access controls
  • Configurable retention settings, where applicable
  • Risk-based privacy and security assessments
  • Secure development practices

Privacy considerations are evaluated throughout the product and service lifecycle.

Information We Process

Depending on the services provided and our relationship with customers, users, and business contacts, we may process personal information including:

  • Contact and business information
  • Account and authentication information
  • Device, browser, and usage information
  • Customer-provided data processed through our services
  • Communications and support-related information
  • Transactional and service-related records

The categories of personal information processed depend on the services used and the nature of the relationship with Audiense.

Data Roles

Depending on the services provided and contractual arrangements:

  • Audiense may act as a Controller (or “Business” under CCPA/CPRA).
  • Audiense may act as a Processor (or “Service Provider” under CCPA/CPRA).

Where required, we enter into appropriate contractual arrangements, including Data Processing Agreements (DPAs), that address applicable statutory requirements.

Legal Bases for Processing

Where GDPR or UK GDPR applies, Audiense processes personal data based on one or more of the following legal bases:

  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate business interests
  • Consent, where required
  • Protection of vital interests or public interests, where applicable

Personal data may be processed for purposes including:

  • Providing and supporting products and services
  • Managing customer relationships
  • Maintaining security and preventing fraud
  • Improving products, services, and operations
  • Complying with legal and regulatory obligations

Individual Rights

Subject to applicable law and depending on an individual’s jurisdiction and our role (e.g., Controller/Business or Processor/Service Provider), individuals may have certain rights regarding their personal information. These rights may include:

  • Right of access to personal information we process
  • Right to request correction of inaccurate personal information
  • Right to request deletion of personal information, subject to applicable exceptions
  • Right to data portability, where applicable
  • Right to restrict processing, where applicable
  • Right to object to certain processing activities, where applicable
  • Right to withdraw consent where processing is based on consent
  • Right to opt out of the sale or sharing of personal information, as defined under applicable U.S. state privacy laws
  • Right to lodge a complaint with a competent supervisory authority or regulator

Where we act as a Processor or Service Provider on behalf of a customer, we will direct individuals to the relevant Controller or Business and assist our customers in responding to such requests in accordance with our contractual obligations and applicable law.

We may take reasonable steps to verify the identity of individuals submitting requests and may limit or deny requests as permitted by applicable law. Requests are handled in accordance with applicable legal requirements, including statutory response timeframes and permitted exceptions.

Security Measures

We maintain administrative, technical, and organizational safeguards designed to protect personal information, which may include:

  • Encryption in transit
  • Access controls and authentication mechanisms
  • Monitoring and logging controls
  • Secure development practices
  • Vendor due diligence procedures
  • Security awareness and training programs

Security measures are reviewed periodically and updated as appropriate based on risk.

International Transfers

Where personal data is transferred internationally, we implement transfer mechanisms recognized under applicable law, which may include:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement (IDTA) or UK Addendum
  • Transfers to jurisdictions subject to adequacy decisions
  • Transfers to importers operating under Binding Corporate Rules or approved transfer mechanisms
  • Other recognized data transfer frameworks or successor mechanisms approved by applicable regulatory authorities

Service Providers & Subprocessors

We may engage third-party service providers and subprocessors to support service delivery. We implement contractual, technical, and organizational measures designed to require appropriate data protection standards and safeguard personal information consistent with applicable legal requirements.

Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations.

Retention periods vary depending on the nature of the information, the services provided, contractual requirements, and applicable legal obligations.

Incident Response

We maintain an incident response program designed to identify, assess, investigate, and address security incidents. Where required by law, we support applicable notification obligations to customers, regulators, and affected individuals.

Ongoing Program

Our privacy program is periodically reviewed and updated to reflect evolving legal requirements, regulatory guidance, industry standards, and business operations.

Contact

For privacy, data protection, consumer rights, or compliance-related inquiries, please contact:

Audiense, LLC 

2651 S Polaris Dr.

Fort Worth, TX 76137

Attn: Legal

Email: Buxton_Legal@Audiense.com

Request a Free Trial