Sample Solutions BV (“Sample Solutions”, or “us” or “we” or “our” shall include Sample Solutions affiliates and subsidiaries) within its scope of work and in order to realize its core activity collects, stores and processes personal data. The platform Sales.Rocks is also part of Sample Solutions BV.
Sample Solutions provides samples and services to support the market research industry by providing clients with access to consumer and business respondents via telephone (both fixed/landline and wireless/mobile). We also provide B2B data to sales and marketing purposes.
Our company Data Protection Policy refers to our commitment to treat the information of employees, customers, stakeholders and other interested parties with the utmost care and confidentiality.
With this policy, we ensure that we gather, store and handle data fairly, transparently and with respect towards individual rights.
While Sample Solutions is committed to assisting its Customers in its role as a data processor, Customers are still ultimately responsible for adhering to their obligations as a “data controller.” Broadly speaking, this means that Customers are responsible for obligations such as:
- Properly collecting, processing, and transmitting personal data from EU subjects
- Properly marketing and communicating to current/potential customers
- Properly handling requests from EU data subjects, such as erasure and access.
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
This policy does not apply to the practices and processing of our customers, companies that we do not own or control, to individuals that we do not employ or manage or to services provided by other companies but accessible through our Website.
- · What personal data we may collect about you or your company;
- · Why our processing is lawful;
- · Who we may share your information with;
- · How we will use the information;
- · Who we may provide that information with;
- · Your rights regarding the information.
Sample Solutions is a member of the following industry organizations and complies with all the privacy policies and codes of ethics of these associations:
- • WAPOR (The World Association for Public Opinion Research)
- • AAPOR (The American Association for Public Opinion Research)
- • ISO (The International Organization for Standardization)
1. What type of information do we collect?
We gather personal information if and to the extent it is necessary to provide our services to you, and if we are entitled or obliged to process personal information under applicable law.
Sample Solutions’s or Sales.Rocks Website: If you contact us about our products and services or request a demo on our website, or request marketing content through third party websites, the forms you complete or the emails you send may include information about you, such as your full name, your email address, the organisation on behalf of whom you are contacting us, a general or personal phone number and your enquiry.
Sample Solutions’ or Sales.Rocks’ Online Client Platform: In order to provide a Sample Solutions Client with access to our platform and enable them to access our services, we collect the full name, email address, phone number and password of each individual authorised by such client to access the platform.
- ·Information you provide to us:
We process personal information that you actively and knowingly provide to us (e.g. your first name, last name, email address, telephone number) if you submit an RFQ, sign up to our newsletter or through our chat).
We will inform you each time which information is required so you can choose to use our services or not. If you choose not to provide us with certain information you may not be able to register with us or take advantage of some of the features we provide.
- · Log data
Whenever you visit our site, we may collect information that your browser sends to us which is called log data. This data may include information such as your IP address, browser version, access times and dates and other related statistics. Additionally, we use log data including your IP address for security purposes such as whitelisting, prevention and recognition of attacks and malware.
- · number of visits to our website;
- · pages visited while at the website and time spent per page;
- · page interaction information, such as scrolling, clicks and browsing methods (using heatmaps);
- · referring websites where visitors have come from and where they go afterwards;
- · page response times and any download errors; and
- · other technical information relating to end user device, ip address or browser or browser plug-in.
Sample Solutions does not seek to collect any non-business-related data such as date of birth, home address, personal email or telephone number and Sample Solutions does not collect sensitive personal data.
2. How do we collect information?
- Information submitted or provided by you.
- We collect publicly available information to the extent legally permitted under applicable law. We may append this information to our existing information.
Our data will be:
- Accurate and kept up-to-date.
- Collected fairly and for lawful purposes only.
- Processed by the company within its legal and moral boundaries.
- Protected against any unauthorized or illegal access by internal or external parties.
Our data will not be:
- Communicated informally.
- Stored for more than necessary to fulfill the purposes for which it was collected.
- Transferred to organizations, states or countries that do not have adequate data protection policies.
- Distributed to any party other than the ones agreed upon by the data’s owner (exempting
legitimate requests from law enforcement authorities).
Sales.Rocks B2B Database: Sample Solutions gathers current and historic business contact data. The data collected about individuals on the Sales.Rocks platform consists of:
- · Name;
- · Employer Company & Company Details;
- · Previous employment history;
- · Office Location (Country, City & Postcode);
- · Business Telephone Number;
- · Skills Set;
- · Company Business Email Address;
- · Contact Business Email Pattern with Probability scores;
- · Job Title.
We also hold data in respect of your employer company such as its name, alias, size, industry, website, web technologies used, and industry. Where you have moved jobs, we may hold your previous employers and previous titles.
In order to be able to link back info to specific email addresses we make use of hashes of email addresses. Once emails are generated temporarily (e.g. via the most likely email format of a company in combination with first name and/or surname), we generate hashes and store these with the suggested format. Hashing is generating a value or values from a string of text using a mathematical function. In our case we use the hashes for storing instead of the actual email address. There are instances where users want to look up additional information based on provided email addresses. We would then hash these emails in the same way to allow a search with our database.
In order to provide certain aspects of its services, Sample Solutions requires a full name and company domain to be recorded against profiles in its database. We do not store the contact email address but only the suggested pattern. Where Sample Solutions does not have the business email address of a profile from public sources, it may generate a business email address based on the email address structure understood to be implemented by the employer company.
The majority of the personal data we collect about you comes from publicly available sources such as from business and employment-oriented social networks, recruitment websites and company websites.
3. How we use personal data
- · We collect personal data for market research purposes to help our clients improve their products, services or the way they conduct their business.
- · You may choose to obtain access to, or to correct your personal information at any time. Similarly, you may withdraw your consent to processing your personal data at any time (in which case we will delete your personal data). In order to effect any of these, please contact us using the details below.
4. Processing Grounds
We process personal data based on four different legal grounds.
4.1 Consent as a legal ground for lawful processing
In some instances, Sample Solutions processes a data subject’s data with given consent. Your consent may be obtained by third parties on Sample Solutions behalf. You have the right to withdraw such consent at any time and we will cease to process data after consent is withdrawn. Examples for consent is when you have opted-in for being contacted by our team, subscribed to a newsletter, engaged with us via chat or have signed up to one of our platforms.
4.2 Contractual necessity as a lawful basis for processing
Sample Solutions may process your data to comply with our legal and regulatory obligations e.g. preventing, investigating and detecting crime, fraud or anti-social behaviour and prosecuting offenders, including working with law enforcement agencies.
4.3 Contractual necessity as a lawful basis for processing
GDPR Recital 40 mentions ‘the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract’ as a legitimate basis of lawful processing and GDPR Recital 44 simply states that processing should be lawful where it is necessary in the context of a contract or the intention to enter into a contract. Therefore we may process your data where we have a contract with the individual and we need to process their personal data to comply with our obligations under the contract.
4.4 Legitimate Interest
Sample Solutions processes personal data when it is in our or our clients’ legitimate interest to do so and when these interests are not overridden by the interests or fundamental rights and freedoms of the data subject. Our and our clients’ legitimate interests include: having information about potential business customers or finding suitable survey respondents organised in one searchable database, being able to retrieve to accurate, updated and complete information, being able to identify a contact that holds a certain role within a B2B company;, enabling clients to only reach out to relevant contacts, being able to generate and contact potential B2B leads in order to undertake forms of B2B research or B2B marketing, having access to aggregated statistical insights for the purpose of understanding patterns and trends, being able to receive statistical data on country, industry or employee size level.
Our Services are designed to help Users and vendors (e.g. HR professionals, B2B partners, sales platforms) validate and verify contact information and to find business profiles they seek in order to interact with relevant Contacts , through access to business profiles retained in the Sales.Rocks database (“Sales.Rocks Database”).
The information provided by Sample Solutions BV is not directly created by sample Solutions BV but rather is retrieved from the web, public sources or from the contribution of relevant data from other users and business partners.
GDPR Recital 47 also states that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.
The Business Profiles we collect from publicly available sources and from our trusted business partners are stored in the Sales.Rocks Database. Our algorithms process this information in order to identify the most up-to-date information related to each profile. In addition, The Sales.Rocks Database includes Business Profiles relating to individuals, which were lawfully obtained by Sales.Rocks from business partners who own established and legitimate directories or from publicly available sources. We may use and share Business Profiles with our Users when they use our Plugin online for the purpose of validating and authenticating online identities by finding relevant data related to a specific individual. We may also disclose to our vendors and business partners (or permit their access to) Business Profiles retained in the Sales.Rocks Database for the purpose of ensuring that their current data is up to date, enriching it and allowing our partners to obtain relevant Business Profiles for employment, commercial and business opportunities. If you prefer that we will not share your Business Profile with our Users, vendors or business partners, you may opt-out by filling in your relevant details here. In this case, we shall not continue to use or disclose your Business Profile. To learn more about our commitment to respect your rights in accordance with applicable privacy and data protection regulations, please see “Your Rights Regarding Your Personal Information” below. The following information is not collected to the Sales.Rocks Database: any information which is shared with us by our Users when downloading or using our Plugins, or accessing and registering on our Site. Specifically – If a User chooses to connect its with the CRM or Email account to the Sales.Rocks App, Sales.Rocks will not collect information associated with such use In order to provide our service and match the relevant information from our database with applicable profiles Users view on supported sites, we need to read certain words (such as full name and company name of the Contacts) We store the data in our servers temporarily and delete it after providing the Users with the service. This data is not added to our database. Sales.Rocks does not store browsing history or data.
5. With whom do we share the data?
We will share your information with the following:
5.1 Our companies
Access to personal data within Sample Solutions and our group of companies is restricted to those individuals who have a need to access the information for our business purposes.
5.2 Our clients
We may share personal data with our clients as part of the offering of our services. Sample Solutions provides limited access to its database. Our clients may use the data to contact individuals on their business telephone, at their business email address, through other electronic mail or through targeted display ads on social networks in order to market products and/or services. For the the purpose of market research they can also contact individuals using randomly generated phone numbers (RDD)
5.3 Suppliers, subcontractors, service providers
This includes external third-party service providers, such as accountants, auditors, experts, lawyers and other outside professional advisors; IT systems, support and hosting service providers; technical engineers; data storage and cloud providers and similar third-party vendors and outsourced service providers that assist us in carrying out business activities.
Sample Solutions works with resellers in various countries. They can potentially receive access to part of the database.
5.5 Government authorities
In addition, we may disclose your information to the extent that we are required to do so by law (which may include to government bodies and law enforcement agencies); in connection with any legal proceedings or prospective legal proceedings; and in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention).
5.6 Potential acquirers or investors
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, you will be notified via email, account message and/or a prominent notice on our website of any change in ownership or uses of this information, as well as any choices you may have regarding this information.
6. Data Storage, Security and transfer of data
6.1 Where is the data stored?
Information including without limitation, personal information is primarily stored on servers and systems located in the EU, which servers are licensed, owned, and/or maintained by or on behalf of Sample Solutions. We are using the Amazon AWS cloud with our website and platforms being hosted in either Frankfurt or Dublin.
Your personal information is treated as strictly confidential and we have taken appropriate technical and organizational security measures against loss and unlawful processing of such information.
As a company that works in this field, Sample Solutions highly values system security and data safeguard. Our systems require identity assurance, visible trust, and strong protection and therefore Sample Solutions security policies include data encryption, pseudonymization, firewalls, malware protection, intrusion detection, safe data storing, SSL security certificates and reliable web hosting.
Sample Solutions is ISO 27001 certified and receives a yearly audit on data security and data protection as well.
Please be aware that, although we endeavour to provide reasonable security for information we process and maintain, no security system can prevent all potential security breaches.
6.3 Transferring data
Market research is a tool used by all sorts of organizations to obtain feedback from customers, members, potential customers and other stakeholders and our main goal is to provide sample and services to support the market research industry and give an extensive range of services from sample delivery to data collection, analysis, and research delivery to bring our customers fresh marketing insights.
The information collected in a research context may be used to plan new products or services, gauge customer/member satisfaction, measure awareness of products or services, or to test reaction to products, services or communications.
We may occasionally collect information that is legally considered more sensitive i.e. “Sensitive Personal Information”. In such instances, we will fully comply with legal restrictions on the collection, storage, use and transfer of such information.
In some circumstances, in order to gain your participation in Internet-based, telephone or in person survey research, we may transfer your name and email address or your name and telephone number to a marketing research field service facility, or to a company that operates an
Internet-based research platform. Before doing so we will ensure that the third party provides and agrees in writing to provide an adequate level of protection and will not use it for any other purpose.
All of our data is delivered via our own platform where we host the data on a dedicated server.
You may withdraw your consent to processing your personal data at any time by contacting us using the details below.
Links to Other Sites
7. Client information
We treat all information we receive from clients as confidential and do not use the information for any purpose other than to fulfill our obligations to them. We keep client information secure at all times and prevent the misuse and unauthorized disclosure of it by our employees or any third parties.
8. Children and minors
Our site and services are directed to the general public. We do not knowingly collect Personal Information from children under sixteen years of age.
9. How long do we retain Personal Information?
We will retain your Personal Information for the period necessary to fulfill the purposes for which it was collected and as required for business or legal purposes unless a longer retention period is required or permitted by law.
If you withdraw your consent to our processing your personal data, we will delete the personal data concerned at that point and will not keep a copy of it. Your right to withdraw your consent is dealt with in more detail below.
10. Conditions for consent
Where processing is based on consent, the data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. You may withdraw your consent for us to collect, use or disclose your personal data by giving us written notice via the web form on the Claim GDPR out-out Page.
11. Which rights do I have as a data subject?
You always have the following rights set forth under the applicable law:
- · The right to get transparent information about the processing of your Personal Information;
- · The right to get access to your Personal Information.
- · The right to rectify inaccurate Personal Information concerning you and to get information about any rectification.
- · The right to erase Personal Information concerning you and to get information about any erasure.
- · The right to restrict the processing of Personal Information concerning you and to get information about any restriction.
- · The right to receive Personal Information you provided to us (and which concerns you) and transmit this received Personal information to another provider.
- · The right to object to any data processing that is based on our legitimate interest.
- · The right not to be subject to a decision solely based on automated processing including profiling.
We respond to all inquiries within thirty days.
12. Can I see and/or correct information about me?
Yes, you can. We allow individuals to see and correct the data we have about them. Please contact us via the web form on the Claim GDPR out-out page.
13. How can I access my information?
You may access the information we collect from or about you in order to review, edit or delete such information, or you may exercise your right to opt-out from communications from Sample Solutions, by sending a request through the Claim GDPR out-out Page.
14. How can I opt-out?
You may opt-out by:
- Clicking on the unsubscribe link contained in any e-mail communication received from Sample Solutions.
- Sending a request through the Claim GDPR out-out page.
- Using the SMS opt-out through our platform.
15. Legal proceedings
We may disclose your personal data if required to do so by law in order to (for example) respond to a subpoena or a request from law enforcement, a court or a government agency (including in response to public authorities to meet national security or law enforcement requirements) or in good faith in the belief that such action is necessary to:
- · Comply with a legal obligation.
- · Protect or defend our rights, interests or property or that of third parties.
- · Prevent or investigate possible wrongdoing in connection with the services.
- · Act in urgent circumstances to protect the personal safety of users of the services or the public.
- · Protect against legal liability.
16. Does using Sample Solutions mean that I have a “legitimate interest” to reach out to EU Data Subjects?
Unfortunately the answer is no. You are ultimately responsible for how you use data collected from its own customers or from a 3rd party vendor, such as Sample Solutions.
It remains the responsibility of a customer, as the data controller, to ensure that it has a legal basis to use that information and any required consent to send marketing, market or social research or other communications to the individual. We rely on our Customers to adhere to their own responsibilities as far as how they communicate with customers/prospective customers.
17. For residents of California
Your Rights Under the California Consumer Protection Act of 2018 (“CCPA”)
Pursuant to the California Consumer Protection Act of 2018 (“CCPA”), and subject to certain exceptions and limitations, Californians can contact Sample Solutions to exercise the rights described below with respect to certain personal information that Sample Solutions holds about them. To the extent those rights apply to you, they are described below. Sample Solutions also handles certain personal information on behalf of Sample Solutions customers. You should contact those customers to exercise any rights you may have with respect to that personal information.
Right to Know About Personal Information Collected, Disclosed, or Sold
You have the right to request that we provide you with details about the personal information we collect, use, disclose and sell. You can submit a verifiable consumer request by contacting us via the Claim GDPR out-out page. Sample Solutions reserves the right to verify your identity to our satisfaction, including by asking you to log into your account if you have one.
You are entitled to receive the following:
- ·The categories of your personal information that Sample Solutions has collected in the preceding twelve months.
- · The categories of sources from which that information was collected.
- · The business/commercial purpose for the collection or selling.
- · The categories of third parties with whom Sample Solutions shares personal information.
- · The specific pieces of personal information Sample Solutions has collected about you (subject to some exceptions).
- · Because Sample Solutions has disclosed or sold (as those words are defined in the CCPA) personal information to third parties in the last twelve months, you are also entitled to receive the categories of personal information that Sample Solutions has disclosed or sold in the past twelve months.
Right to Request Deletion of Personal Information
You have the right to request deletion of the personal information we have collected about you (subject to some exceptions). You can submit your request as described above, and we reserve the right to conduct the verification described above.
Right to Non-discrimination for the Exercise of a Consumer’s Privacy Rights
You have the right not to receive unlawful discriminatory treatment by Sample Solutions for the exercise of your privacy rights under the CCPA.
Right to Opt-Out of the Sale of Personal Information
You have the right to opt-out of the sale of your personal information by Sample Solutions. You can submit a verifiable consumer request by emailing firstname.lastname@example.org.
List of Categories of Personal Information to be Collected and May Have Been Sold or Disclosed and Categories of Personal Information Collected
Sample Solutions does not directly collect personal information but rather generated personal phone numbers via random digit dialing.
The categories of personal information we may collect include:
“Identifiers” such as
- · Telephone number(s) (including home, cell, and/or business telephone numbers).
- ·Demographic information.
- ·Undertaking internal research for technological development and demonstration.
- · Undertaking activities to verify or maintain the quality or safety of services and devices, and to improve, upgrade, or enhance services and devices; and
- · Facilitating the operational purposes of Sample Solutions or our service providers.
- · Categories of Personal Information that May Have Been Sold.
Sample Solutions sold all of the above categories of personal information in the last twelve months.
- · Categories of Personal Information that Were Disclosed.
Sample Solutions disclosed all of the above categories of personal information in the last twelve months.
Data Protection Officer:
Sample Solutions has appointed a DPO to provide an oversight of our data protection program.
For any data protection questions or concerns you can reach to us via the Claim GDPR opt-out page.
You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing at any time by contacting our DPO.
Address: Stationsplein 45, 3013 AK Rotterdam, The Netherlands
Phone: +31 10 310 4188