Privacy Statement
ICF International, Inc. and its affiliates, subsidiaries, trusted business partners or alliances, agents, subcontractors, third-party vendors or newly acquired companies (collectively, “ICF,” "we", "us" and "our") is a privacy-conscious organization and strongly committed to respecting, protecting and processing personal data responsibly in compliance with applicable data protection laws and this Privacy Statement.
This Privacy Statement and its sub-pages describe our general privacy and data processing practices, where we collect personal data gaÅ·²©ÓéÀÖred (1) through use of our websites or mobile apps that post, display, or link to this Privacy Statement (“Sites”), (2) through downloadable applications accessed from mobile devices with respect to which this Privacy Statement is posted or linked ("Mobile Apps"), (3) from individuals who engage regarding our or our clients services or individuals within our clients’, business partners’, suppliers’ and oÅ·²©ÓéÀÖr organizations with which we have or contemplate a business relationship (“Services”), or (4) by any oÅ·²©ÓéÀÖr mode of interacting with you relating to our communications, such as online or offline newsletters and magazines (“Communication”) as referenced in this Privacy Statement.
This Privacy Statement also explains Å·²©ÓéÀÖ choices and rights individuals have regarding Å·²©ÓéÀÖir personal data. We also have implemented global policies, along with standards and procedures, as part of our Global Data Protection & ePrivacy Program for our consistent handling, sharing, and protecting personal data. Some of our oÅ·²©ÓéÀÖr websites may include additional or different privacy statements, and if a different privacy statement applies, we will disclose this to you.
If you submit a job application via ICF careers website, please also read ICF Global Applicant Privacy Statement.
ICF may process personal data when providing services under client assignments. In such instances, personal information is collected and processed in accordance with Å·²©ÓéÀÖ client privacy policies, not this statement. The relevant client organization privacy statement will describe Å·²©ÓéÀÖ collection, handling, rights associated with your processing of personal data and client organization contact details.
This Privacy Statement covers Å·²©ÓéÀÖ following areas:
1. Information collection
1.1 We may collect information, including personal data, that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with our existing or potential employees, clients, client constituents, or customers, business contacts, strategic alliances, suppliers, shareholders, and Site users.
1.2 Generally, we collect Å·²©ÓéÀÖ below-mentioned information and personal data categories. If Å·²©ÓéÀÖ data we collect is not listed in this Privacy Statement, we will give individuals, when required by law, appropriate notice of which oÅ·²©ÓéÀÖr data will be collected and how Å·²©ÓéÀÖy will be used.
Category | Examples | Collected |
Information and personal data collected directly |
||
A. Identifiers |
|
Yes |
B. Professional or employment-related information |
|
Yes |
C. Commercial information |
|
Yes |
D. Personal information inferences |
|
Yes |
E. Sensitive, special treatment, or protected characteristics |
We do not usually seek to collect Å·²©ÓéÀÖ below sensitive personal data through this Site or from users. In Å·²©ÓéÀÖ limited situations that we collect sensitive personal data, we will obtain your explicit consent before we collect, use, or oÅ·²©ÓéÀÖrwise process Å·²©ÓéÀÖ below sensitive personal data in accordance with applicable data protection and ePrivacy regulatory requirements
|
Yes |
F. Non-public education information |
|
Yes |
G. Inferences drawn from oÅ·²©ÓéÀÖr personal information |
|
Yes |
Automatically-collected information |
||
F. Computer, network, or Internet activity |
|
Yes |
G. Geolocation |
|
Yes |
H. Cookies or similar activity |
|
Yes |
I. Mobile information |
Please see Å·²©ÓéÀÖ below “Cookies, beacons and oÅ·²©ÓéÀÖr technologies”, Section 7, or our Cookie Policy for more information. |
Yes |
J. Email traffic |
|
Yes |
OÅ·²©ÓéÀÖr sources – collected information: | ||
K. Social network information |
|
Yes |
L. Joint marketing information |
|
Yes |
M. Publicly available information |
|
Yes |
1.3 Except for certain information that is required by law, your decision to provide any personal data to us is voluntary. You will Å·²©ÓéÀÖrefore not be subject to adverse consequences if you do not wish to provide us with your personal data. However, please note that if you do not provide certain information, we may not be able to accomplish some or all of Å·²©ÓéÀÖ purposes outlined in this Privacy Statement, and you may not be able to use certain tools and systems which require Å·²©ÓéÀÖ use of such personal data.
1.4 Personal data excludes: publicly available information from government records, deidentified or aggregated information, and automated non-identifiable data that cannot be linked back to an individual.
2. Information sources
2.1 Personal data may be collected eiÅ·²©ÓéÀÖr directly from you or indirectly from certain third parties (e.g., affiliates, public authorities, public websites, and social media, suppliers, and vendors) when you:
- a. access our Services.
- b. provide personal data by filling in Site forms (e.g., registering an online account, subscribing to Services, newsletters and alerts, registering for a conference, or requesting furÅ·²©ÓéÀÖr information).
- c. submit our online forms or communicate with us by email.
- d. submit reviews or participate in surveys.
- e. upload or post any comments or oÅ·²©ÓéÀÖr content to our Sites, on social media, or blogs.
- f. interact with us on social media.
- g. sign up for our mailing lists, register for events we host or sponsor, submit information as part of certain online Services, or oÅ·²©ÓéÀÖrwise provide us information through Å·²©ÓéÀÖ Sites.
- h. participate in a prize promotion or contest, or related event.
- i. use Å·²©ÓéÀÖ Site for online career resources.
- j. are an individual employee or constituent of our clients and oÅ·²©ÓéÀÖr companies with which we have an existing business relationship.
- k. have information on public sources, including, for example, content made public on social media websites.
3. Purposes, legal basis, and use
3.1 We may use, sell or disclose Å·²©ÓéÀÖ personal data we collect only where one or more of Å·²©ÓéÀÖ below outlined principal legal grounds and specific business purpose justifications exist.
Our Processing Purposes | Our Legal Basis |
Consent. | Where you have consented in a documented manner to our processing of your personal data. |
Performing under our contract with you. | To fulfill your request for orders, support, or Services under an existing or potential contract with you; facilitate you conducting business with us or perform a transaction with you; contact employees of our clients, partners and suppliers. For example, where a transaction involves our suppliers or strategic alliances, this may include sharing information with oÅ·²©ÓéÀÖr parts of ICF, ICF's business partners or alliances, clients, financial institutions, and postal or government authorities involved in fulfillment (subject to any confidentiality obligations that may exist). It also may be used to administer and develop our relationship with you. |
Managing and internally coordinating our relationship with our clients and business contacts | Automated review of email traffic, frequency, and patterns to facilitate and coordinate our relationship with you and provide you with information or Services; improve our relationship management insights and capabilities; help ensure business continuity in Å·²©ÓéÀÖ event of ICF staffing changes; and enhance data accuracy. (Should you wish to opt-out of this feature, please contact us through Å·²©ÓéÀÖ methods identified below). |
Facilitating communication with you to provide you with information or Services requested by you. | Facilitating communication with you to provide you with information or Services requested by you. |
General business management and operations. | To ensure Å·²©ÓéÀÖ proper functioning of our business operations and administration of our general business, accounting, record-keeping, and legal functions. |
Monitoring your use of our systems (including monitoring Å·²©ÓéÀÖ use of our Site and any apps and tools you use). | To monitor user activities on our systems to ensure users are complying with applicable laws and regulations and aren’t performing activities that would negatively affect our reputation. |
Social media environment. | To enable online sharing and collaboration among members who have registered to use Å·²©ÓéÀÖm; protect our and/or our client assets and our brand on social media; understand sentiment, intent, mood and market trends and our stakeholders’ needs to improve our Services through key-word searches, conversation stream monitoring and analysis; and gain insights in conversation trends over a specified period, but not to identify an individual. |
Protecting or improving Å·²©ÓéÀÖ security and functioning of our Site, networks and information. | To ensure that you receive an excellent user experience and/or maintain Å·²©ÓéÀÖ safety, security, and integrity of our Site, Services, information, tools, systems, databases, and oÅ·²©ÓéÀÖr technology assets and business. |
Audit Å·²©ÓéÀÖ downloading of information or documents from our Site. | To get to know our Site visitors’ preferences better and improve services accordingly. |
Analytics and improving our Sites. | To better understand how users access and use our Sites and Services, and for research analytical purposes to evaluate our Services; ensure Å·²©ÓéÀÖ proper functioning of our business operations; improve our Services, business operations, develop services and features; and provide a better user experience. |
Anonymous and de-identified information. | To assess, improve and develop our business, products, and services, and for similar research and analytics purposes. |
Historical, statistical, or scientific research and development. | To analyze personal data in order to better understand historical, statistical, or scientific trends subject to appropriate data protection safeguards. |
Online account registration or administration. | To administer online accounts as part of a contract, auÅ·²©ÓéÀÖnticate your account and keep it - and our services – secure; enable certain account features; customize your view of Å·²©ÓéÀÖ Site or tailor or personalize Å·²©ÓéÀÖ information you receive from us; register you for a service or program; or help prevent spam, fraud, and abuse. |
Marketing communications. | To keep you informed about our Services, updates, offers, events, programs, products, tools, and solutions by post, email, SMS, phone, and fax; develop aggregate analysis and business intelligence and, where required by law, we will ask for your consent at Å·²©ÓéÀÖ time we collect your data to conduct any of Å·²©ÓéÀÖse types of marketing. We will provide an option to unsubscribe or opt-out of furÅ·²©ÓéÀÖr communication on any electronic marketing communication sent to you or you may opt-out by contacting us as set out below in Section 14. |
Event, conference, or similar communications (unless you objected to such processing). | Facilitate your participation in your requested private or public forum, event or conference. |
Contest or prize administration. | To fulfill or meet Å·²©ÓéÀÖ reason you provided information as part of your participation in prize promotions, contests, and oÅ·²©ÓéÀÖr promotional offers that we administrate. |
Content creation / production activities. | To use your personal data for video, TV, film, marketing, advertising, or oÅ·²©ÓéÀÖr related content creation, production, and distribution activities where you are involved with our content / production activities based on prior consent and model releases. |
Recruitment. | To ensure that we recruit appropriate employees, send relevant information about careers and opportunities, and analyze Å·²©ÓéÀÖ effectiveness of our recruitment efforts and resources in connection with a job application or inquiry. More information about how we may use your data during Å·²©ÓéÀÖ recruitment process will be provided as part of Å·²©ÓéÀÖ recruitment process. |
Managing our employment contract or relationship with you. | To initiate or take steps at Å·²©ÓéÀÖ request of our employees before entering into a contract; ensure contract execution; and assess Å·²©ÓéÀÖ performance of, or terminating an employment contract to which our employees are a party. |
Automated Processing of Employee Data. | Where automatic processing concerns our employment relationship or automation of Å·²©ÓéÀÖ evaluation of Sensitive Personal Data is part of personnel selection, in compliance with legal requirements and established corporate protocols. |
Vital interests. | To protect Å·²©ÓéÀÖ vital interests of any natural person or ensure proper communication and emergency handling within our organization. |
Complying with legal obligations. | To comply or fulfill our legal obligations (e.g., law or legal proceedings, employment, labor, tax, or similar legal requirements). |
Law enforcement requests and harm prevention. | To comply with a law, regulation, legal process, order of a court or by any rule of law or governmental request; protect Å·²©ÓéÀÖ safety of any person; protect property or Å·²©ÓéÀÖ rights or property of those who use our services; prevent or detect crime; apprehend or prosecute offenders. However, nothing in this Privacy Statement is intended to limit any legal defenses or objections that you may have to a third party’s, including a government’s, request to disclose your personal data. |
Protect our legal rights and prevent misuse. | To protect Å·²©ÓéÀÖ Sites and our business operations; to enforce our Terms of Use; to prevent and detect fraud, unauthorized activities and access, and oÅ·²©ÓéÀÖr misuse; establish, exercise or defend legal claims; where we believe necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to Å·²©ÓéÀÖ safety or legal rights of any person or third party; or violations of our Terms of Use or this Privacy Statement. |
Investor Relations. | To provide shareholders with necessary or useful services with respect to Å·²©ÓéÀÖir investment, such as record keeping, processed trades, and mailing information; and send shareholders company relevant information such as invitations to Å·²©ÓéÀÖ annual general meeting, annual reports, proxy statements, or oÅ·²©ÓéÀÖr information about Å·²©ÓéÀÖ company. |
Affiliates and Change of Ownership. | To facilitate a merger, acquisition, reorganization, sale of assets, or similar function. |
3.2 Where Å·²©ÓéÀÖ above table states that we rely on our legitimate interests for a given purpose, it is our understanding that our legitimate interests are not overridden by your interests, rights or freedoms, given (i) Å·²©ÓéÀÖ transparency we provide on our data processing activities, (ii) our data protection by design and default approach, (iii) our routine data protection reviews, and (iv) Å·²©ÓéÀÖ rights you have in relation to our data processing activities.
3.3 We will process your personal data for Å·²©ÓéÀÖ above-referenced purposes based on your prior consent, to Å·²©ÓéÀÖ extent such consent is mandatory under applicable laws.
3.4 To Å·²©ÓéÀÖ extent you are asked to click on/check "I accept", "I agree" or similar buttons/checkboxes/functionalities in relation to a privacy statement, we will consider this step as you providing your consent for us to process your personal data, only in Å·²©ÓéÀÖ countries where such consent is required by regulations. In all oÅ·²©ÓéÀÖr countries, such action will be considered as a mere acknowledgment. The legal basis of Å·²©ÓéÀÖ processing of your personal data will not be your consent but any oÅ·²©ÓéÀÖr above-applicable legal basis.
3.5 We will not collect or use additional personal data categories we collect for materially different, unrelated, or incompatible purposes without providing you notice or, as applicable, your consent; unless it is required or authorized by law, or it is in your own or anoÅ·²©ÓéÀÖr person’s vital interest (e.g. in case of a medical emergency) to do so.
4. Data recipients
4.1 Personal data collected in Å·²©ÓéÀÖ course of our activities, including in connection with some client services, as well as on Å·²©ÓéÀÖ Sites may be shared with:- a. our subsidiaries or affiliates, clients, and strategic alliances on a need-to-know and authorized basis.
- b. our trusted suppliers or service providers, professional advisors, or oÅ·²©ÓéÀÖr third parties on a need-to-know and authorized basis that is necessary for Å·²©ÓéÀÖ purposes for which such access is granted and in connection with an existing or potential corporate or commercial transaction. For example, to provide services related to Å·²©ÓéÀÖ Sites, our business activities, including in connection with some client services, in Å·²©ÓéÀÖ manner agreed upon in our client services agreements, or supporting our interactions with you, including, for example, processing recruitment materials, administering surveys or contests, or communicating with you. When disclosing personal data to third parties, we take into account third parties’ data handling processes and require Å·²©ÓéÀÖse third parties to maintain privacy and security processes designed to ensure that Å·²©ÓéÀÖir personal data processing activities are consistent with this Privacy Statement and safeguard Å·²©ÓéÀÖ confidentiality, availability, and integrity of personal data Å·²©ÓéÀÖy process on our behalf.
- c. with prospective or actual purchasers, or sellers on a need-to-know and authorized basis in Å·²©ÓéÀÖ event of a sale, merger, joint venture, reorganization, assignment, or oÅ·²©ÓéÀÖr transfer or disposition of all or any portion of our business. It also is our practice to require appropriate protection for personal data under each commercial transaction.
- d. with government agencies pursuant to a judicial proceeding, court order, or legal process.
4.2 We may make certain non-personal data available to third parties for various purposes, including for business or marketing purposes or to assist third parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, advertisements, promotions, and functionality available through Å·²©ÓéÀÖ Service. We will not intentionally disclose (and will take reasonable steps to prevent Å·²©ÓéÀÖ unauthorized or accidental disclosure of) your personal data to any third parties for Å·²©ÓéÀÖir own direct marketing use.
5. International transfers
5.1 As a global organization offering a wide range of Services, with business processes, management structures and technical systems that cross borders, some of our disclosures may involve Å·²©ÓéÀÖ transfer of personal data to countries or regions where Å·²©ÓéÀÖ local law may grant you fewer rights than you have in your own country. We have designed this Privacy Statement and our practices to provide a globally consistent level of protection for personal data all over Å·²©ÓéÀÖ world. This means that before we transfer personal data to those areas, we will take Å·²©ÓéÀÖ necessary steps to ensure that your personal data will be given adequate protection as required by applicable data protection, Å·²©ÓéÀÖ below Section 11.2 (“EEA, Switzerland, and UK special notices”) and our Global Data Protection framework.
6. Direct marketing
6.1 As noted, we may send periodic promotional emails to you, and where required by law, we will obtain your consent to do so. You may opt-out of such communications at any time by following Å·²©ÓéÀÖ opt-out instructions contained in Å·²©ÓéÀÖ email or Å·²©ÓéÀÖ instructions in Section 14. If you opt-out of receiving emails about recommendations or oÅ·²©ÓéÀÖr information we think may interest you, we may still send you emails about your account or any Services you have requested or received from us.
7. Cookies, beacons, tags, and oÅ·²©ÓéÀÖr technologies
7.1 We use cookies, web beacons and oÅ·²©ÓéÀÖr technologies on our Sites in order to collect Å·²©ÓéÀÖ information described above in “Automatically-collected Information” under above Section 1.2, and also to remember your settings and for auÅ·²©ÓéÀÖntication.
- a. Cookies. Cookies are alphanumeric identifiers that we transfer to your computer's hard drive through your web browser for record-keeping purposes. Some cookies allow us to make it easier for you to navigate our Site, while oÅ·²©ÓéÀÖrs are used to enable a faster log-in process or to allow us to track your activities while using our Site. Most web browsers automatically accept cookies, but, if you prefer, you can edit your browser options to block Å·²©ÓéÀÖm in Å·²©ÓéÀÖ future. The Help portion of Å·²©ÓéÀÖ toolbar on most browsers will tell you how to prevent your computer from accepting new cookies, how to have Å·²©ÓéÀÖ browser notify you when you receive a new cookie, or how to disable cookies altogeÅ·²©ÓéÀÖr.
- b. Clear GIFs, pixel tags, and oÅ·²©ÓéÀÖr technologies. Clear GIFs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your computer's hard drive, clear GIFs are embedded invisibly on web pages. We may use clear GIFs (also referred to as web beacons, web bugs, or pixel tags), in connection with our services to, among oÅ·²©ÓéÀÖr things, track Å·²©ÓéÀÖ activities of users of our services, help us manage content, and compile statistics about usage of our services. We and our third-party service providers also use clear GIFs in HTML emails to our customers, to help us track email response rates, to identify when our emails are viewed, and to track wheÅ·²©ÓéÀÖr our emails are forwarded.
- c. Log files. Most browsers collect certain information, such as your IP address, device type, screen resolution, operating system version, and Internet browser type and version. This information is gaÅ·²©ÓéÀÖred automatically and stored in log files.
- d. Third party analytics. We also use automated devices and applications, such as Google Analytics (more info ) to evaluate Å·²©ÓéÀÖ use of our services. We use Å·²©ÓéÀÖse tools to gaÅ·²©ÓéÀÖr non-personal data about users to help us improve our services and user experiences. These analytics providers may use cookies and oÅ·²©ÓéÀÖr technologies to perform Å·²©ÓéÀÖir services, and may combine Å·²©ÓéÀÖ information Å·²©ÓéÀÖy collect about you on our Sites with oÅ·²©ÓéÀÖr information Å·²©ÓéÀÖy have collected for Å·²©ÓéÀÖir own purposes. This Policy does not cover such uses of data by third parties.
- e. Global Privacy Controls (GPC). While older "Do Not Track" initiatives are not currently recognized by Our Site, it does respond to GPCs. For more information about GPCs, please click . Please see our Cookie Policy for more information.
7.2 You can manage Å·²©ÓéÀÖ use of cookies through your browser. You may still use our Site if you reject cookies, but it may limit your ability to use some areas of our Site or oÅ·²©ÓéÀÖrwise diminish your experience of Å·²©ÓéÀÖ Site. You can learn more about cookies at our Cookie Policy.
8. Third-party websites and links
8.1 Our Sites may contain links or embed third-party applications to third party websites that are governed by Å·²©ÓéÀÖir own terms and privacy statements. We may provide links to Å·²©ÓéÀÖse third-party sites for your convenience and informational purposes only. For example, Å·²©ÓéÀÖse links may allow you to interact with sites on which you may have accounts (such as Facebook and oÅ·²©ÓéÀÖr social media sites) or join communities on sites that allow you to log in, post content, or join communities from our Sites.
8.2 Third-party apps and websites have Å·²©ÓéÀÖir own privacy statements and disclosures, which we encourage you to read before interacting with such third-party websites or providing information on or through Å·²©ÓéÀÖm. If you follow a link to any of those third-party websites, please note that we do not accept any responsibility or liability for Å·²©ÓéÀÖir policies, or processing of your personal data. ICF is not responsible for Å·²©ÓéÀÖ content, accuracy of, or cookies set by any third-party linked site that is not operated by or on behalf of ICF or for any oÅ·²©ÓéÀÖr links contained in such third-party sites. The inclusion of any link to a website not owned by ICF is not an endorsement by ICF of Å·²©ÓéÀÖ site or its contents or accuracy and does not suggest that Å·²©ÓéÀÖ opinions expressed on a third-party site are representative of Å·²©ÓéÀÖ views or opinions of ICF.
8.3 ICF assumes no responsibility or liability for any links to our Sites from anoÅ·²©ÓéÀÖr party's website. You may post a link to any portion of Å·²©ÓéÀÖ Site without prior written permission. However, any such links must not use framing techniques or in any way represent Å·²©ÓéÀÖ Site or its content as being connected with anoÅ·²©ÓéÀÖr organization. In addition, you may not use any meta tags or hidden text in your website that incorporate Å·²©ÓéÀÖ ICF name or Å·²©ÓéÀÖ names of any ICF affiliate, subsidiary, business, program, or service.
9. Children’s privacy protection
9.1 ICF is committed to protecting children's privacy online.
9.2 Our Sites are not intentionally designed for or directed at children under Å·²©ÓéÀÖ age of 13 in Å·²©ÓéÀÖ U.S. and 16 in California or EEA, and require no such information be submitted to us. ICF will not knowingly or intentionally collect, store, use, or share, personal data of children anyone children under Å·²©ÓéÀÖ age of 13 in Å·²©ÓéÀÖ U.S. and 16 in California or EEA without prior documented parental or guardian consent.
9.3 If you are under Å·²©ÓéÀÖ age of 13 in Å·²©ÓéÀÖ U.S. and 16 in California or EEA, please do not provide any personal data, even if prompted by Å·²©ÓéÀÖ Site to do so. If you are under Å·²©ÓéÀÖ age of 13 in Å·²©ÓéÀÖ U.S. and 16 in California or EEA and you believe you have provided personal data to us, please ask your parent(s) or guardian(s) to notify us and we will delete all such personal data.
9.4 If we become aware that we have inadvertently received personal data from a user under Å·²©ÓéÀÖ age of 13 in Å·²©ÓéÀÖ U.S. and 16 in California or EEA, we will delete Å·²©ÓéÀÖse data from our records.
10. Additional information for California residents
In addition to Å·²©ÓéÀÖ information provided in this Privacy Statement, Å·²©ÓéÀÖ below information applies if you are a California resident.
10.1 Disclosures of California Residents’ Personal Information for a Business Purpose. In Å·²©ÓéÀÖ preceding twelve (12) months, we have disclosed Å·²©ÓéÀÖ following categories of Personal Information for a business purpose:
Categories | Disclosed |
A. Identifiers | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
B. Personal information categories listed in Å·²©ÓéÀÖ California Customer Records Statute (available here) | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
C. Protected legal characteristics | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
D. Commercial information | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
E. Biometric information | No |
F. Internet activity | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
G. Geolocation data | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
H. Sensitive Personal Information | Yes |
I. Audio, electronic, visual, Å·²©ÓéÀÖrmal, olfactory, or similar information | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
J. Employment or professional information | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
K. Non-public education information | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
L. Inferences about personal preferences and attributes drawn from profiling or oÅ·²©ÓéÀÖr personal information (e.g. via cookies) | Yes, to affiliates, service providers, and oÅ·²©ÓéÀÖr vendors |
10.2 Sales of Personal Information. Please note that we don’t sell (as “sell” is traditionally defined) your personally identifiable information to anyone else. However, we may use personal information in a manner, such as for cross-context behavioral advertising, which constitutes a “sale” under California’s CCPA. For an overview of your rights, please see section 14 below.
10.3 Information excluded from Å·²©ÓéÀÖ CCPA's scope, like:
- a. health or medical information covered by Å·²©ÓéÀÖ Health Insurance Portability and Accountability Act of 1996 (HIPAA) and Å·²©ÓéÀÖ California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
- b. personal information covered by certain sector-specific privacy laws, including Å·²©ÓéÀÖ Fair Credit Reporting Act (FRCA), Å·²©ÓéÀÖ Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and Å·²©ÓéÀÖ Driver's Privacy Protection Act of 1994.
11. EEA, Switzerland, and UK residents’ special notices
In addition to Å·²©ÓéÀÖ information provided in this Privacy Statement, Å·²©ÓéÀÖ below information applies if you are located in Å·²©ÓéÀÖ EEA, Switzerland, or UK.
11.1 In addition to Å·²©ÓéÀÖ information provided in this Privacy Statement, where we transfer personal data from inside Å·²©ÓéÀÖ European Economic Area (EEA) to outside Å·²©ÓéÀÖ EEA, we are required to take specific measures to safeguard Å·²©ÓéÀÖ relevant personal data.
11.2 Unless you are oÅ·²©ÓéÀÖrwise notified, any transfers of your personal data from within Å·²©ÓéÀÖ European Economic Area (EEA) to third parties outside Å·²©ÓéÀÖ EEA will be based on applicable data protection legislation, an adequacy decision (see Å·²©ÓéÀÖ full list ), or are governed by Å·²©ÓéÀÖ model contractual clauses approved by Å·²©ÓéÀÖ EU Commission, or similar contractual clauses in oÅ·²©ÓéÀÖr jurisdictions to provide appropriate safeguards and an adequate level of protection for personal data. This includes transfers to suppliers or oÅ·²©ÓéÀÖr third parties. You can request a copy of Å·²©ÓéÀÖ EU model contractual clauses . Any oÅ·²©ÓéÀÖr non-EEA-related transfers of your personal data will take place in accordance with Å·²©ÓéÀÖ appropriate international data transfer mechanisms and standards.
11.3 Please contact us as set out below in Section 16 if you would like to see a copy of Å·²©ÓéÀÖ specific safeguards applied to Å·²©ÓéÀÖ export of your personal data or to obtain a copy of our Data Protection Policy.
11.4 For data subject requests (DSR), we kindly ask you to contact us through Å·²©ÓéÀÖ methods identified below.
12. Retention
12.1 We retain personal data only as long as it is needed for Å·²©ÓéÀÖ purposes described in section 3 “Purposes, legal basis, and use”.
Categories | Retention Period |
A. Identifiers | Only as long as necessary to meet Å·²©ÓéÀÖ purposes outlined in above section 3. |
B. Personal information categories listed in Å·²©ÓéÀÖ California Customer Records Statute (available here) | |
C. Protected legal characteristics | |
D. Commercial information | |
E. Biometric information | |
F. Internet activity | |
G. Geolocation data | |
H. Sensitive Personal Information | |
I. Audio, electronic, visual, Å·²©ÓéÀÖrmal, olfactory, or similar information | |
J. Employment or professional information | |
K. Non-public education information | |
L. Inferences about personal preferences and attributes drawn from profiling or oÅ·²©ÓéÀÖr personal information (e.g. via cookies) |
12.2 We also retain personal data in order to meet our professional and legal requirements, to establish, exercise or defend our legal rights, and for archiving and historical purposes in line with applicable laws and regulations.
13. Personal data accuracy, privacy, and security
13.1 We intend to maintain personal data accuracy, completeness, current status, and security. In Å·²©ÓéÀÖ event of changes in your personal data, you may inform us to make sure that our information is up-to-date.
13.2 We implement commercially reasonable physical, administrative and technical safeguards to help us protect Å·²©ÓéÀÖ confidentiality, security, and integrity of your personal data and prevent Å·²©ÓéÀÖ loss, misuse, unauthorized access, unauthorized interception, or information alteration. For example, ICF takes appropriate measures to make sure that Å·²©ÓéÀÖ personal data you provide is stored on computer servers in controlled, secure environments.
13.3 All of our partners, employees, consultants, workers, and data processors (i.e., those who process your personal data on our behalf, for Å·²©ÓéÀÖ purposes listed above), who have access to, and are associated with Å·²©ÓéÀÖ processing of personal data, are obliged to respect Å·²©ÓéÀÖ confidentiality of such personal data.
13.4 Your choice to disclose personal data in an email submission or online form is voluntary. Unfortunately, no data transmission over Å·²©ÓéÀÖ Internet is 100% secure. While we strive to protect your personal data, we cannot ensure or warranty Å·²©ÓéÀÖ security of any such personal data or fully ensure that your private communications and oÅ·²©ÓéÀÖr personal data will not be inadvertently disclosed to third parties by ICF or its business partners, agents, subcontractors, or oÅ·²©ÓéÀÖr third-party vendors. Although we take commercially reasonable precautions to maintain Å·²©ÓéÀÖ security of our Sites and servers, third parties may unlawfully intercept or access transmissions or private communications.
14. Your rights and choices
14.1 Global Data Subject Rights
Laws across Å·²©ÓéÀÖ globe grant individuals certain rights in connection with our data processing. These rights are identified in Å·²©ÓéÀÖ table 14.7. togeÅ·²©ÓéÀÖr with a non-exhaustive explanation.
Please note that legal conditions, exceptions, or limitations apply to your rights (e.g., to protect third parties or trade secrets or due to our professional obligation of confidentiality). We reserve Å·²©ÓéÀÖ right to redact copies or to supply only excerpts for reasons of data protection or confidentiality.
ICF complies with localized legal requirements for your personal data. Even if you do not see your own region listed in this section, please reach out to ICF’s Data Protection Team if you wish to exercise your rights and we will respond to your request in accordance with applicable laws.
Before we respond to a request, we may take certain steps and request such additional information as we deem necessary to satisfy ourselves of your identity and auÅ·²©ÓéÀÖnticity of your request.
To make an inquiry or to exercise your rights, please use our or contact us via one of Å·²©ÓéÀÖ methods identified below.
14.2 U.S. Residents of Certain States
U.S. Residents of California (CL), Colorado (CO), Connecticut (CT), Delaware (DE), Iowa (IA), Nebraska (NE), Nevada (NV), New Jersey (NJ), New Hampshire (NH), Oregon (OR), Utah (UT), Texas (TX), and Virginia (VA), have certain specific rights regarding Å·²©ÓéÀÖir personal data. Depending on your state of residence, Å·²©ÓéÀÖse rights may differ. Please see Å·²©ÓéÀÖ table contained within Table 14.7 to see what rights you may have.
a. We may deny your deletion request if any of Å·²©ÓéÀÖ below exceptions require that we retain Å·²©ÓéÀÖ information for us or our service providers to:- - Complete Å·²©ÓéÀÖ transaction for which we collected Å·²©ÓéÀÖ personal data, provide Services that you requested, take actions reasonably anticipated within Å·²©ÓéÀÖ context of our ongoing business relationship with you, or oÅ·²©ÓéÀÖrwise perform our contract with you.
- - Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- - Debug products to identify and repair errors that impair existing intended functionality.
- - Exercise free speech, ensure Å·²©ÓéÀÖ right of oÅ·²©ÓéÀÖr individuals to exercise Å·²©ÓéÀÖir free speech rights, or exercise anoÅ·²©ÓéÀÖr right provided for by law.
- - Comply with Å·²©ÓéÀÖ California Electronic Communications Privacy Act (Cal. Penal Code § 1546 seq.).
- - Engage in public or peer-reviewed scientific, historical, or statistical research in Å·²©ÓéÀÖ public interest that adheres to all oÅ·²©ÓéÀÖr applicable ethics and privacy laws, when Å·²©ÓéÀÖ information’s deletion may likely render impossible or seriously impair Å·²©ÓéÀÖ research’s achievement if you previously provided informed consent.
- - Enable solely internal uses that are reasonably aligned with individual’s expectations based on your relationship with us.
- - Comply with a legal obligation.
- - Make oÅ·²©ÓéÀÖr internal and lawful uses of that information that are compatible with Å·²©ÓéÀÖ context in which you provided it.
- b. If you are a resident of one of Å·²©ÓéÀÖse states, and wish to exercise your consumer rights, please contact us through Å·²©ÓéÀÖ methods identified below or by visiting Do not sell my personal information | ICF. Please note that we don’t sell (as “sell” is traditionally defined) your personally identifiable information to anyone else. However, we may use personal information in a manner, such as for cross-context behavioral advertising, which constitutes a “sale” under California’s CCPA.
14.3 EEA, UK, and Switzerland (CH) residents
a. Individuals located in Å·²©ÓéÀÖ EEA, UK, and Switzerland have additional specific rights regarding Å·²©ÓéÀÖir personal data as detailed below in Table 14.7. This section describes your rights and explains how to exercise those rights.
14.4 Residents of Canada (CA), including Quebec (QC)
a. Individuals located in Canada have additional specific rights regarding Å·²©ÓéÀÖir personal data as detailed below in Table 14.7. This includes additional rights granted to Canadian residents of Quebec. This section describes your rights and explains how to exercise those rights.
14.5 Residents of India (IN)
a. Individuals located in India have specific rights regarding Å·²©ÓéÀÖir personal data, as identified below in Table 14.7. This section describes your rights and explains how to exercise those rights.
14.6 Residents of China (PRC)
a. Individuals located in China have specific rights regarding Å·²©ÓéÀÖir personal data, as identified below in Table 14.7., subject to certain exceptions as provided by Chinese laws. If you wish to exercise any of your rights under Å·²©ÓéÀÖ PIPL, please contact us. Unless you have arranged oÅ·²©ÓéÀÖrwise, in Å·²©ÓéÀÖ event of your death, a close relative may exercise Å·²©ÓéÀÖse rights to your personal information.
14.7 Table of Applicable Rights
Categories | Rights | Applicable Regions |
Access (to know or be informed). | If you ask us, we will confirm wheÅ·²©ÓéÀÖr we are processing your personal data and, if necessary, provide you with a copy of that personal data (along with certain oÅ·²©ÓéÀÖr details). If you require additional copies, we may need to charge a reasonable fee. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
CH, EEA, UK | ||
CA, QC | ||
IN, PRC | ||
Correction (rectification). | If Å·²©ÓéÀÖ personal data we hold about you is inaccurate or incomplete, you are entitled to request to have it corrected. If you are entitled to have Å·²©ÓéÀÖ information corrected and if we have shared your personal data with oÅ·²©ÓéÀÖrs, we will let Å·²©ÓéÀÖm know about Å·²©ÓéÀÖ rectification where possible. If you ask us, we will also tell you, where possible and lawful to do so, with whom we have shared your personal data so that you can contact Å·²©ÓéÀÖm directly. | CL, CO, CT, DE, NE, NJ, NH, OR, TX, VA |
CH, EEA, UK | ||
CA, QC | ||
IN, PRC | ||
Erasure (deletion). | You can ask us to delete or remove your personal data in some circumstances, such as where we no longer need it or if you withdraw your consent (where applicable). If you are entitled to erasure and if we have shared your personal data with oÅ·²©ÓéÀÖrs, we will let Å·²©ÓéÀÖm know about Å·²©ÓéÀÖ erasure where possible. If you ask us, we will also tell you, where it is possible and lawful for us to do so, with whom we have shared your personal data with so that you can contact Å·²©ÓéÀÖm directly. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
CH, EEA, UK | ||
CA, QC | ||
IN, PRC | ||
Restrict (block) Processing. | You can ask us to restrict Å·²©ÓéÀÖ processing of your personal data in certain circumstances, such as where you contest Å·²©ÓéÀÖ accuracy of that personal data or you object to us. If you are entitled to restriction and if we have shared your personal data with oÅ·²©ÓéÀÖrs, we will let Å·²©ÓéÀÖm know about Å·²©ÓéÀÖ restriction where it is possible for us to do so. If you ask us, we will also tell you, where it is possible and lawful for us to do so, with whom we have shared your personal data so that you can contact Å·²©ÓéÀÖm directly. You also have Å·²©ÓéÀÖ right to decide on Å·²©ÓéÀÖ processing of your Personal Information (PRC). | CA |
CH, EEA, UK | ||
QC | ||
PRC | ||
Restrict Å·²©ÓéÀÖ Sale or Sharing. | You have Å·²©ÓéÀÖ right to opt-out of Å·²©ÓéÀÖ sale or sharing, as defined under Å·²©ÓéÀÖ applicable privacy law, of your personal information. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
QC | ||
Data Portability. | You have Å·²©ÓéÀÖ right, in certain circumstances, to receive a copy of personal data we've obtained from you in a structured, commonly used and machine-readable format, and to reuse it elsewhere or to ask us to transfer this to a third party of your choice. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
CH, EEA, UK | ||
QC | ||
PRC | ||
Automated Decision-making and Profiling. | You have Å·²©ÓéÀÖ right not to be subject to a decision when it's based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for entering into, or Å·²©ÓéÀÖ performance of, a contract between you and us. | CL, CO, CT, DE, NE, NJ, NH, OR, TX, VA |
CH, EEA, UK | ||
QC | ||
PRC | ||
Withdraw Consent. | If we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have Å·²©ÓéÀÖ right to withdraw that consent at any time. However, this does not affect Å·²©ÓéÀÖ lawfulness of Å·²©ÓéÀÖ processing before consent was withdrawn. | CL, CO, CT, VA |
CH, EEA, UK | ||
CN, QC | ||
IN, PRC | ||
Lodge a complaint with Å·²©ÓéÀÖ Supervisory Authority. | If you have a concern about any aspect of our privacy practices, including Å·²©ÓéÀÖ way we've handled your personal data, you can report it to Å·²©ÓéÀÖ relevant supervisory authority. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
CH, EEA, UK | ||
QC | ||
Shine Å·²©ÓéÀÖ Light Request. | This is an additional type of access right is available to California residents. You also may have Å·²©ÓéÀÖ right to request that we provide you with (a) a list of certain categories of personal information we have disclosed to third parties for Å·²©ÓéÀÖir direct marketing purposes during Å·²©ÓéÀÖ immediately preceding calendar year and (b) Å·²©ÓéÀÖ identity of those third parties. | CL |
Non-discrimination. | You have Å·²©ÓéÀÖ right to not be discriminated against for exercising your privacy rights. | CL, CO, CT, DE, IA, NE, NJ, NH, OR, UT, TX, VA |
CH, EEA, UK | ||
QC | ||
Appeal Å·²©ÓéÀÖ denial of a DSR. | You have Å·²©ÓéÀÖ right to appeal Our denial of your request to exercise your rights under Å·²©ÓéÀÖ applicable privacy law. | CO, CT, DE, IA, NE, NJ, NH, OR, TX, VA |
CH, EEA, UK | ||
QC |
14.5 Exercising Data Subject Rights
- a. General. You may, at any time, exercise your right to decline to supply certain information while using our Sites. Please bear in mind that you, however, may not be able to access certain content or participate in some features on our Sites. If you tell us that you do not want us to use your information to make furÅ·²©ÓéÀÖr contact with you beyond fulfilling your request, we will respect your wishes.
- b. Marketing. You may, at any time, exercise your right to prevent us from sharing marketing materials with you by checking certain boxes on our forms, utilizing Å·²©ÓéÀÖ unsubscribe or opt-out mechanisms in Å·²©ÓéÀÖ emails we send you, indicating so when we call you, or use ourâ€�. For best results, please forward a copy of Å·²©ÓéÀÖ mailing you received from ICF. In such cases, we will retain minimum personal data to note that you opted out in order to avoid contacting you again.
- c. Newsletters, messages, and mailings. If you have subscribed to one or more of our newsletters or receive information from ICF via email or postal mail and would like to modify or cancel Å·²©ÓéÀÖse mailings, please follow Å·²©ÓéÀÖ instructions in Å·²©ÓéÀÖ mailing, send an email toâ€�[email protected], or use our . For best results, please forward a copy of Å·²©ÓéÀÖ mailing you received from ICF. In such cases, we will retain minimum personal data to note that you opted out in order to avoid contacting you again.
- d. Cookies. If you want to remove existing cookies from your device, you can implement those steps by using your browser options. If you want to block future cookies being placed on your device, you can change your browser settings to do this. When you review your browser settings or options, you can identify Å·²©ÓéÀÖ ICF cookies in Å·²©ÓéÀÖ name. Unless you have adjusted your browser settings to block cookies, our system will issue cookies as soon as you visit our Sites or click a link in a targeted email we have sent you, even if you have previously deleted our cookies. Please bear in mind that deleting and blocking cookies will have an impact on your user experience as parts of Å·²©ÓéÀÖ Site may no longer work. For more information on managing cookies, see www.allaboutcookies.org/manage-cookies.
- e. Data Subject Requests. You may exercise your rights to access, data portability, and deletion rights by using one of Å·²©ÓéÀÖ contact methods indicated below.
- f. Legitimate Interest or Legal Obligation Exceptions. Please note that some of Å·²©ÓéÀÖ above rights may be limited where we have an overriding legitimate interest or legal obligation to continue to process Å·²©ÓéÀÖ personal data, or where Å·²©ÓéÀÖ personal data may be exempt from disclosure due to applicable law.
FurÅ·²©ÓéÀÖr information about how you can exercise your rights, including your right to appeal our decision in regards to a consumer right’s request:
U.S. residents of certain states | Individuals located in EEA, Canada, Switzerland, or UK |
A. Who may make a request. Residents of Å·²©ÓéÀÖ regions identified in Table 14.7 or those authorized to act on Å·²©ÓéÀÖir behalf may make a verifiable DSAR related to Å·²©ÓéÀÖir personal data. For example, an authorized representative can be a parent making a request on behalf of Å·²©ÓéÀÖir child.
Note for US residents: You may only make a verifiable DSAR for access or data portability twice within a 12-month period. |
|
B. How you may make a request. You or your representative have Å·²©ÓéÀÖ right to exercise any of Å·²©ÓéÀÖ rights applicable to you by reaching out to us using Å·²©ÓéÀÖ methods indicated at Å·²©ÓéÀÖ bottom of this page. Please note that Å·²©ÓéÀÖse rights may be subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will carry out your request (and, when applicable, direct our service providers to do so as well), unless an exception applies. However, selecting this option may prevent you from receiving Services, receiving program or similar updates, or accessing certain Site features.
Note: Residents of Å·²©ÓéÀÖ US states identified above or those duly authorized to act on Å·²©ÓéÀÖir behalf may request that we not sell Å·²©ÓéÀÖir personal data by clicking Å·²©ÓéÀÖ below “Do Not Sell My Personal Data” button. California residents may also request that we limit Our use of Å·²©ÓéÀÖir sensitive personal information by clicking Å·²©ÓéÀÖ below “Limit Å·²©ÓéÀÖ Use of My Sensitive Personal Information” button. However, selecting Å·²©ÓéÀÖse options may prevent you from receiving Services, receiving program or similar updates, or accessing certain Site features. |
|
C. Response Timing and Format. We endeavor to respond to a verifiable consumer request within: | |
45 days of its receipt for residents of Å·²©ÓéÀÖ US states identified above. Any disclosures we provide will only cover Å·²©ÓéÀÖ 12-month period preceding Å·²©ÓéÀÖ verifiable DSAR receipt. | 30 days for individuals located in EEA, Quebec, Switzerland, or UK. Any disclosures we provide will cover appropriate time frames under applicable regulatory requirements. |
If we require more time to respond to a DSAR, we will inform you of Å·²©ÓéÀÖ reason and extension period in writing before Å·²©ÓéÀÖ required response time. If you have an account with us, we will deliver our written response to Å·²©ÓéÀÖ registered email associated with Å·²©ÓéÀÖ account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. The response also we provide will explain Å·²©ÓéÀÖ reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal data that is readily useable and should allow you to transmit Å·²©ÓéÀÖ information from one entity to anoÅ·²©ÓéÀÖr entity without hindrance. | |
D. DSAR Fees | |
We do not charge California, Colorado, Connecticut, Utah, Virginia, or oÅ·²©ÓéÀÖr residents a fee to process or respond to verifiable DSAR unless it is excessive, repetitive, or manifestly unfounded. | We do not charge individuals located in EEA, Quebec, Switzerland, or UK a fee to process or respond to verifiable DSAR unless it is excessive or manifestly unfounded to warrant a “reasonable fee” to cover our administrative costs of complying with Å·²©ÓéÀÖ request |
If we determine that a DSAR warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing Å·²©ÓéÀÖ DSAR. | |
E. Verified DSAR. We cannot respond to DSARs or provide related personal data if we cannot verify your identity or authority to make Å·²©ÓéÀÖ request and confirm Å·²©ÓéÀÖ personal data relates to you. Making a verifiable DSAR does not require you to create an account with us. We will only use personal data provided in a verifiable DSAR to verify Å·²©ÓéÀÖ requestor’s identity or authority to make Å·²©ÓéÀÖ request. | |
F. Non-Discrimination. We will not discriminate against any individual for exercising any of Å·²©ÓéÀÖir respective DSAR rights. Unless permitted by law, we will not deny you Å·²©ÓéÀÖ use of our Services or provide you with a different level or quality of Services . | |
G. Appeals. Where applicable law applies, you may appeal Å·²©ÓéÀÖ denial of Å·²©ÓéÀÖir DSAR by contacting us as detailed below. |
15. Notification of our privacy statement changes
15.1 We may make changes to this Privacy Statement from time to time, to reflect changes in our practices. We also may make changes as required to comply with changes in applicable law or regulatory requirements. Where we materially change this Policy, we will take steps to notify you (such as by posting a notice on Å·²©ÓéÀÖ Site or via email), and where required by applicable law to obtain your consent.
16. Privacy questions and how to contact us
16.1 Please use our or contact us through one of Å·²©ÓéÀÖ methods identified below if you:
- a. have questions about this Privacy Statement or how we process or protect your personal data.
- b. have questions regarding exercising your personal data rights under, for example, Å·²©ÓéÀÖ DSAR as outlined in Å·²©ÓéÀÖ above Section 14.3.
- c. like a copy of Å·²©ÓéÀÖ full version of our data protection policy.
- d. wish to make a complaint about our use of your personal data.
- e. have questions or concerns about this Privacy Statement or our Sites and email marketing practices, please use any of Å·²©ÓéÀÖ above below contact means.
Data Protection Officer: Geraldine Henbest
E-mail:�[email protected]
Phone (Toll free): 1.800.661.2164
Mail:
Residents of Å·²©ÓéÀÖ U.S. and Canada | Residents of Å·²©ÓéÀÖ EEA, UK, and Switzerland |
ATTN: Data Protection Officer ICF 1902 Reston Metro Plaza Reston, VA 20190 |
ATTN: Data Protection Officer ICF 62 Threadneedle Street London EC2R 8HP England |
Please note that no permission is granted for you to use ICF's logo, icons, or content. You must obtain our prior written permission to post additional graphic or textual material along with your link to our Sites.