Privacy Policy

This global privacy policy explains how Tracy-Locke and/or its affiliates ("Tracy-Locke," referred to as "we", "us" or "our") handle your personal data, including the types of personal data we collect about you, how your personal data may be used and when it may be disclosed, how we protect your personal data and the rights you have in relation to the processing of your personal data. Tracy-Locke respects your privacy and we are committed to protecting your personal data in accordance with applicable data privacy laws and our internal policies.

In the event of conflict between a translated version of this global privacy policy and the English version, the English version shall prevail.

1. Who is the controller of my personal data?

Unless we notify you otherwise, Tracy-Locke is the controller of your personal data as it is the entity who alone or jointly determines how or why your personal data is being processed. Our affiliates may be the controller of your personal data in certain circumstances depending on our relationship, and the services we are providing to you.

2. How do we collect your personal data?

We use different methods to collect personal data from and about you, including:

Collection directly from you
Most of the personal data we process about you comes directly from you. You may give us your name and contact details when filling in forms or corresponding with us by email, phone, mail, in person or otherwise including when you:

Depending on the products and/or services we provide to you, you may also have the option to upload a photograph of yourself as part of your registration for such products and/or services. This is optional and your photograph can be updated at any time.

Automatic collection
We automatically collect technical information when you use our websites, for example: IP address, log-in data, browser type, time zone setting and location and plug-in types when you interact with our websites. We also collect data through cookies. Please see our cookies policy for further details.

Collection from other sources
We may collect information about you from third parties and public sources (such as public databases and social media websites). This is to ensure we have accurate, up-to-date or necessary information for us to communicate with you or to provide the best possible service. The types of information we may collect include personal details (including name, age, gender and other demographic data) and contact information (including postal address and telephone numbers).

3. For which purposes and on which legal basis do we process your personal data?

We have set out below a description of all the ways we plan to use your personal data and which legal basis we rely on to do so. We have also identified what our legitimate interests are, where appropriate.

Necessary for compliance with a legal obligation: Complying with legal requirements.

Necessary for performance of a contract: Managing our contractual relationship with you.

Legitimate interest in proper business functioning: Operating and managing our business operations and/or improving our products, service and event experience.

Legitimate interest in business development: Marketing or communicating information to you related to our products and services, unless you have objected. Sharing personal data with our affiliates and selected partners (including sponsors).

Legitimate interest in network and information security: Monitoring your use of our systems (including automated tools). Improving the security and functioning of our website, networks and information.

Legitimate interest in business analytics: Undertaking analytics to describe, predict and improve business performance and user experience.

Legitimate interest in managing directories: Enabling individuals within a product or service directory to identify and contact appropriate users.

4. How do we use personal data for direct marketing purposes?

We may send you marketing communications about our products and services, including those we believe may interest you.

Do we send targeted e-mails?
Yes. We send targeted direct marketing to relevant business contacts. These emails may include web beacons, cookies, tracking of links clicked, and logging website activity after clicking those links. Please see our cookies policy for further details.

Do we maintain CRM databases?
Yes. Tracy-Locke uses CRM technology to manage marketing activity. This includes business contact information, publicly available data, engagement data (email opens, clicks, downloads), website activity, and notes from interactions with Tracy-Locke professionals.

Do we combine and analyse data?
Yes. We may combine data from public sources, data across our websites, information collected during sign-up or log-in, and interaction history. We do this to better understand your interactions with Tracy-Locke.

Your rights regarding marketing
You may opt out at any time.

Post: Omnicom Group Inc., Attn: General Counsel, 280 Park Avenue, New York, NY 10017
Telephone: 1-833-520-0506

5. What about sensitive data?

We do not seek to collect sensitive personal data and request that you do not submit it. If we must collect it, we will do so in accordance with law and request consent where required.

6. What about persons 18 or under?

We do not knowingly collect information from persons under 18. If you believe a minor has provided information, please contact us at [email protected] and we will delete it.

7. Will we share your personal data with third parties?

We may share your data with:

We take necessary steps to ensure adequate protection whenever data is shared.

8. How long will your personal data be retained?

We retain your information only as long as necessary, considering current and future use, legal and contractual obligations, relationship management needs, and product/service requirements.

9. Do we transfer your data internationally?

Yes. As a global organization, we may transfer your data internationally, including outside the EEA. Transfers are protected by approved contractual safeguards and internal agreements ensuring appropriate protections.

10. Data security

We maintain organizational, physical, and technical measures including pseudonymisation and encryption, resilience and continuity protocols, incident recovery procedures, and regular testing and evaluation of security controls.

11. Which rights do you have?

Depending on jurisdiction, you may request access, rectification, deletion, restriction, objection, portability, and avoidance of automated decision-making. California residents may request additional information regarding data shared for direct marketing.

To submit a data subject access request, follow the link provided by Tracy-Locke or contact us directly.

12. Use of ChatGPT-Powered Assistant on This Website

Our website includes an AI-powered assistant using the OpenAI Assistants API ("AI Assistant"). When you interact with the AI Assistant, the text you submit is processed to generate responses.

How your AI Assistant data is handled:

This section supplements the rest of the privacy policy.

13. What if you have questions or want further information?

Contact us at:

Post: Omnicom Group Inc., Attn: General Counsel, 280 Park Avenue, New York, NY 10017
Telephone: 1-833-520-0506

If located in the EEA, you may lodge a complaint with your local supervisory authority, though we ask that you contact us first.