Dentsu International (referred to as “our”, “us” and “we” in this notice) is an advertising agency that is part of a global media group. Merkle is part of Dentsu International. We help our clients to improve how they advertise and market, whether by print, post, email or on websites. We believe that the responsible use of data supports business growth and builds strong relationships between brand and consumer. As a business, we are committed to respecting and protecting the privacy of all individuals with whom we interact. We are committed to being transparent in our handling and processing of personal data at all times in accordance with applicable privacy and data protection laws.
This Privacy Notice covers Merkle’s data products, including DataSource, Identity, M1, and Merkury.
DataSource: This product covers most of the adult U.S. population and is built by combining data supplied to us by other companies that collect data from you.
Identity: Our Identity product is a set of processes that manage and associate information across a number of sources to create an identity map across those identifiers and tie them to an individual.
M1: M1 is a platform we offer our clients to allow them to understand their consumers, plan their marketing campaigns, activate those campaigns and understand the effectiveness of those advertising campaigns. When these campaigns are activated, we work with publishing networks (including social media and online display advertising) to display our client’s advertising to you.
Merkury: Merkury is an identifier designed to allow marketers to engage audiences online without using third-party cookies. Publishers place the Merkury tag onto their sites, which places a first-party cookie into the publisher’s first-party domain. This allows publishers to combine their first-party data with our proprietary data, which includes identifiers, such as hashed e-mail address and IP address, to build and find audiences across the Merkury publisher networks.
For activities related to our website, please see here for our Website Privacy Notice.
This Privacy Notice explains in detail the types of personal data we may collect or receive about you in connection with our data products, and how we use, process, and share that personal data.
The California Consumer Privacy Act of 2018 (“CCPA”), as amended by the California Privacy Rights Act, The Virginia Consumer Data Protection Act (“VCDPA”), , the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), and the Utah Consumer Privacy Act (“UCPA”) provides residents of their respective states with additional rights with respect to their personal data. Those rights are explained below in Section 7 (Your Privacy Rights).
This Privacy Notice includes certain disclosures required under applicable U.S. privacy laws. Please note that the rules implementing some of these laws have not yet been finalized. We are committed to continual compliance with these laws and will update our processes and this notice as the rules are finalized and the law requires.
In this Privacy Notice, the term “personal data” has the meaning ascribed to it under applicable U.S. privacy laws, and includes the term “personal information” as defined by the California Consumer Privacy Act of 2018, as amended.
We are a global marketing agency and operate separate data products in the U.K. and the U.S. This Privacy Notice is intended for U.S. consumers.
We receive personal data from third party sources like advertisers, brands, data brokers, non-profit organizations, public records, government entities, our clients (who may already do business with you), our partner publishers and partner service providers. We may also receive personal data from other sources such as public registers. We put information together so that we can check your personal data is correct and up to date, and then we keep the collection of information about you in our products (see How We Use Your Personal Data).
We also receive information from websites provided by our clients and business partners that use our cookies, pixels, and/or small pieces of code known as “web beacons” or “clear gifs”, such as the Merkury tag (collectively, “Tracking Technology”).
We use Tracking Technology to help us better source information about email activities and activities of visitors to our client websites and determine which marketing material is effective and preferred by our respective Publishers/Clients and their consumers.
From our sources (see Sources of Information), we get and store various types of information about people and households. These may include the following:
We also process other types of information, not classified as personal data, which we may link to your personal data. This may include business information for the purposes of identifying segments of individuals who live near certain businesses, or aggregated credit card spend data for the purpose of modelling likely behavior.
Except where prohibited by law or court order, we use your personal data for the following purposes:
As noted above, in this Privacy Notice, the term “personal data” has the meaning ascribed to it under applicable U.S. laws, and includes the term “personal information” as defined by the California Consumer Privacy Act of 2018, as amended.
If you are a California resident, the California Consumer Privacy Act (“CCPA”) requires us to provide you with the following additional information about: (1) the purpose for which we use each category of “personal information” (as defined in the CCPA) we collect; and (2) the categories of third parties to which we (a) disclose such personal information for a business purpose, (b) “share” personal information for “cross-context behavioral advertising,” and/or (c) “sell” such personal information.
We may share your personal information by allowing certain third parties (such as online advertising partners) to collect personal information via automated technologies for targeted advertising or “cross-context behavioral advertising.” We “sell” (as defined by statute) and “share,” as defined by applicable privacy laws, so that our clients can provide relevant and tailored advertising to you.
In the table below we set out further information about the purposes for which we use your personal data and the categories of third parties to which we disclose this personal data. In the second column, we also specify how such personal data is categorized under applicable U.S. privacy laws. For more information about the categories of personal data under applicable U.S. privacy laws, see Your Privacy Rights.
Purpose/Activity
To provide services to our clients. For example, we collect, process, keep and use the personal data in the products to help our clients deliver relevant advertising or marketing and find new customers.
We also use personal data to help our clients create advertising “segments,” for instance: “men living in a particular zip code who are aged between 20 and 30.”
To combine or match personal data in our products to select the most appropriate group of people for our clients’ advertising or marketing campaigns.
We also use matched or combined information to check that your information is up-to-date and accurate, confirm which devices are used by which people and conduct data analytics to assist targeting – this includes predictive data concerning people's purchasing behavior, likelihood of response to marketing or purchase of a product, brand loyalty, product and brand affinities and preferences. This may include models predicting your likely spend on various products and services (e.g. monthly spend on vehicle fuel).
To assess the effectiveness of client advertising and marketing campaigns.
To administer our services and products, and for internal operations.
For example, we use personal data for troubleshooting, data analysis, and testing.
To respond to any inquiries or feedback that you send us
To update you with any changes to our terms and conditions/other policies
To share information with our service providers.
To share information within the dentsu international group for business purposes.
To share information with other third parties, such as regulator and law enforcement agencies
Types of personal data that may be processed
Categories of third parties to which we disclose this personal data for a business purpose
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities; Online advertising partners
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities; Online advertising partners
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities; Online advertising partners
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities; Online advertising partners
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities
Third-party service providers; Entities due to corporate mergers or restructuring; Other parties as required by law or to prevent or investigate illegal activities
Categories of third parties to which this information is ”shared” or “sold” for advertising/analytical purposes
Clients, Third-party service providers; Online advertising partners
Clients, Third-party service providers; Online advertising partners
We do not sell/share.
Clients
We do not sell/share
Third-Party Service Providers
We do not sell/share
We do not sell/share
We use information as otherwise disclosed or permitted by law, or as we may notify you. We may use personal data to create deidentified or aggregated data which does not identify you or any other individual. We may use and disclose this anonymous or aggregated data as we choose.
When a client uses our services to run an advertising or marketing campaign, we are what's known as a “service provider" or “third party” for the client provided data used for that campaign. We use that personal data for the client's advertising or marketing campaign and act on the client's instructions.
Information shared within our group of companies
We are a globally operating media group consisting of multiple companies. Therefore, we may from time to time disclose your personal data within our group of companies.
Information shared with our third-party service providers
We use a number of third parties to perform business functions on our behalf, such as sending our newsletters and hosting our online services and customer relationship management. We will disclose personal data to these vendors and service providers to enable them to provide their services.
Information shared with clients and entities authorized by our clients.
We may share personal data from our products with clients and their agencies and other entities authorized by them for their analytics, profiling, and/or marketing purposes including email and postal mail fulfillment providers. We will provide our clients with information so that they can send marketing or show ads to consumers. We may share hashed or anonymized user data from email communications or website activities with third parties so they may set cookies and/or collect your data directly from you (e.g. through a cookie or other technology) for their own use and subject to their own privacy policies. This data may be combined and linked with data from other sources.
Information shared with social media platforms and publishers.
We may share your personal data with social media platforms and publishers who allow us to buy advertising space for our clients. This may mean that you receive our clients’ marketing messaging when you use those social media platforms and other digital properties.
Information shared with other parties as required by law or to prevent or investigate illegal activities
Where required or permitted by law, personal data may be provided to others, such as regulator and law enforcement agencies, for example in response to a court order or a subpoena, or in response to a law enforcement agency’s request, or where we believe it is necessary to investigate, prevent or take action regarding illegal activities or to protect dentsu international, our websites, customers, employees, and business partners from fraud or other malicious activity, and as otherwise required by law.
Information shared due to corporate mergers or restructuring
We may disclose personal data with any successor to all or part of our business. For example, if part of our business is sold, we may give our customer list as part of that transaction.
We may share personal data for other reasons we may describe to you from time to time or as permitted by law.
Our products containing your personal data is kept in the U.S. and backed up in the U.S. We are a globally operating media group consisting of multiple companies. Therefore, we may from time to time disclose your personal data within our group of companies. Some of our group companies are located in the European Union (“EU”) or European Economic Area (“EEA”), and we implement and maintain policies designed to ensure the security of such disclosures and transfers in accordance with the applicable privacy and data protection laws.
We update data in our systems at least every thirty days. As indicated in Your Choices section below, you can request that we delete personal data we have associated with you, however we may continue to receive personal data about you after we have processed your deletion request.
This section explains the choices you may exercise over the use of your personal data.
We enable users to opt-out from certain uses of information in a digital environment. If you want to opt-out from our solutions from the browser you are currently using, click here and our systems will attempt to place an opt-out cookie on your computer.
We and other third party companies collect and receive information from across a variety of websites and mobile applications you visit or use over time in order to infer your interests and deliver relevant advertising to the browsers and devices you may use, including across associated devices. This type of advertising is known as interest-based advertising. You may visit http://www.aboutads.info/choices/ to learn more about this activity and opt out of our and many of our partners collection and use of data for that purpose. Some mobile operating systems have their own opt-out mechanisms that apply to IBA in mobile app environments. To exercise this opt-out, please visit the privacy settings of your Android or iOS device. We adhere to the Digital Advertising Alliance’s Self-Regulatory Principles.
Please note that if you clear cookies from your browser or reset your device identifier, you may need to renew your opt-out choice. You will also continue to receive advertising after an opt-out, but those advertisements may be less relevant to your interests. If you use multiple browsers or devices you will need to exercise your choices on those browsers or devices as well.
While we do not currently respond to Do Not Track signals, when our systems detect the presence of our opt-out cookie or a mobile o/s opt-out indicator, our solutions will stop engaging in IBA for the opted out browser or device. And if we have linked two or more browsers or devices as described above, our systems will attempt to sever the link for the opted out browser or device. device.
The California Consumer Privacy Act (“CCPA”), as amended, the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), and the Utah Consumer Privacy Act (“UCPA”) provides residents of their respective states with additional rights with respect to their personal data.
Depending on where you live and what you are asking us to do, we may or may not be obligated to comply with your request, and/or the time required to complete a request may vary. Based on how we collect and utilize your personal data, you may have the following rights:
You can make these requests online by clicking here, or by calling us at (+1) (833) 570-5939 (toll-free in the US). For any business-to-business requests, you can make these requests online by clicking here, or by calling us at (+1) (833) 570-5939 (toll-free in the US). For any employment related requests, you can make these requests online by clicking here. We may deny certain requests, or fulfill a request only in part, based on our legal rights and obligations. For example, we may retain personal data as permitted by law, such as for tax or other record keeping purposes, to maintain an active account, and to process transactions and facilitate customer requests. Note that for purposes of these requests under this Privacy Notice, personal data does not include information about job applicants, employees and other of our personnel; information about employees and other representatives of third-party entities we may interact with; or information we have collected as a service provider to our clients. Finally, please note that we are required by California Civil Code section 1798.105(d) to keep a record of your request.
Only you, or a person or business entity that you authorize to act on your behalf (an "Authorized Agent"), may make the requests set forth above. You may also make a request on behalf of your minor child. For California residents, Authorized Agents must be a person or entity registered with the California Secretary of State.
The request should include your contact information and describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it. In addition, you should provide sufficient information (including information that reasonably enables us verify the identifying information we currently maintain about you) that allows us to reasonably verify that you are the person about whom we collected the personal data or an authorized representative.
We will respond to consumer requests in a reasonably timely manner. If we require extra time to respond, we will inform you of the reason and extension period in writing. In order to protect the security of your personal data, we will not honor a request if we cannot verify your identity or authority to make the request and confirm the personal data relates to you. The method used to verify your identity will depend on the type, sensitivity and value of the information, including the risk of harm to you posed by any authorized access or deletion. Generally speaking, verification will be performed by matching the identifying information provided by you to the personal data that we already have.
Any disclosures we provide for California residents will only cover the 12-month period preceding our receipt of your request (and will not be made more than twice in a 12-month period). If we cannot comply with a request, or cannot fully comply with a request, the response we provide will also explain the reasons we cannot comply. If we deny your request in whole or in part, you may have the right to appeal the decision. In such circumstances, we will provide you with information regarding the appeals process.
Data Subject Rights Requests Metrics - California Consumer Privacy Act
If you reside in California, you have the right to ask us one time each year if we have shared personal data with third parties for their direct marketing purposes. To make a request, please send us an email, or write to us at the address listed below. Indicate in your letter that you are a California resident making a “Shine the Light” inquiry.
We have reasonable security measures in place to help protect personal data from loss, misuse, unauthorized access, disclosure, alteration, and destruction.
We have implemented reasonable, industry-standard security policies, standards and practices designed to protect information from internal and external threats. The degree of protection for each piece of information is based on the risk and consequences associated with having that information compromised. While no security measures will provide for absolute security, all of our employees responsible for the management of information have the responsibility to adhere to our documented security controls, which are developed commensurate with the understood risk.
This Privacy Notice is limited to the personal data received and used by us in connection with our products and does not apply to personal data collected through one of our websites. We may obtain information through various sources (see Sources of Information) and are not responsible for the privacy practices of such sources. We also may share information with our clients and other third parties and are not responsible for the privacy practices of such clients and third parties.
We do not actively seek to collect personal data about children aged 16 or under. If you have any concerns about your child’s privacy in relation to our services, or if you believe that your child under the age of 16 may have entered personal data onto our website, please contact us at dpous@merkleinc.com. We will delete such personal data from our records or seek verifiable parental or legal guardian consent to retain such information within a reasonable time.
This Privacy Notice may be updated from time to time to reflect changes in law, best practice or a change in our practices regarding the treatment of personal data. The date of the most recent revision will appear below. You should review this page from time to time to ensure that you are happy with any changes that have been made. If you do not agree to the changes, please do not continue to use our services and please refrain from sharing your personal data with us.
This policy is effective as of Jan 12, 2024.
If you have any questions about this Privacy Notice or would like to exercise any of the rights mentioned above, you can contact our Data Protection Officer in any of the following ways:
Address: Data Protection Officer
Merkle Inc.
7001 Columbia Gateway Drive
Columbia, MD 21046
Telephone:
(+1) (833) 570-5939 (US, toll-free)
Or by email at: dpous@merkleinc.com