ESG Data Convergence Initiative Privacy Policy

1. Who we are

This is the Privacy Policy for The Boston Consulting Group, Inc. and its affiliates (“BCG” or “we”). This privacy policy was last updated in January 2024. For more detail on BCG’s international operations please see https://www.bcg.com/about/offices/default.aspx.

 

2. Applicability of this Privacy Policy

This Privacy Policy applies only to:

  • Your use of the ESG Data Convergence Initiative Website (“Site”) where you are provided with information about and a link to our interactive tool to help you simplify data sharing process for Environmental Social Governance (“ESG”) metrics, translating ESG to material impact, allowing you to benchmark against peers and make these metrics meaningful, while shaping how private equity ownership is evolving private company ESG performance.
  • You registering your interest via the Site to join the initiative and receive and participate in an industry benchmark on consolidated ESG metrics across over 4300 companies.
  • You signing up to receive notifications and newsletters about the initiative.

Please note that we do not collect any personal information as part of the ESG benchmarking exercise conducted for the Initiative.

 

3. Important information about this Privacy Policy

BCG understands that your privacy is important. BCG is committed to protecting your privacy and personal data you provide in relation to your access and use of the Site. This Privacy Policy (together with the Terms of Use, which you will also have been asked to agree to, and any additional terms of use incorporated by reference into the Terms of Use) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. This Site is not intended for and does not intentionally target or solicit to children or anyone of 18 years of age and younger. Please read the following carefully to understand our practices regarding your personal data and how we will treat it.

 

4. Changes to this Privacy Policy

Please note that BCG may, in its discretion, amend this privacy policy from time to time. To ensure you are able to remain informed about the information we collect and how we use it, material changes to our statement will be reflected here and we will notify you whenever we make a material change to this Privacy Policy. The Site may contain links to external sites or services which are not governed by this Privacy Policy. We encourage you to review the privacy policies of any such sites before you submit information there.

 

5. The data we collect about you

When you register your interest for an account, we collect information from you, including the following personal data: name, company name, business email address, and commitment status. By your use of the Site, we may also collect, use, store, and transfer the following personal data about you: location data, IP address, geolocation, user activity (e.g. pages visited and how long stayed there.)

We also collect, use and share aggregated data such as statistical data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate the data relating to details of your use of the Site to calculate the percentage of users accessing a specific feature. However, if we do ever combine or connect aggregated data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.

We do not collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

 

6. Authentication through okta

In order to use the Site, you will need to authenticate with the third-party provider Okta Inc. (301 Brannan St Ste 300, San Francisco, CA 94107) with your personal username and a personal password. To do this, download the Okta Verify app and perform the authentication process. The regulations and data protection declaration of Okta, Inc. apply. We have no influence on and are not responsible for the data collection by Okta Inc. Your data will be processed exclusively for the purpose of authentication. After successful authentication you will receive personal access to our app. Here you register once with your e-mail address.

 

7. How your personal data is collected

We may collect your data in different ways: based on your consent you provide by filling in forms on the Site for login; or by corresponding with us (for example, by email or chat). It includes information you enter when you register or when you report a problem with the Site. If you contact us, we will keep a record of that correspondence.

 

Cookie/Device storage objects

Non-essential Cookies

Performance cookies: These cookies are used to enhance the performance and functionality of the Site and collected based on your consent. These cookies facilitate navigation through the Site and the saving of preferences and content. For example, we might use performance cookies to keep track of which pages are most popular, which method of linking between pages is most effective, and to determine why some pages are receiving error messages.

Session or Web analytic cookies: We make use of analytic cookies to analyse how our visitors use our Site and to monitor Site performance. This allows us to provide a high-quality experience by customising our offering and quickly identifying and fixing any issues that arise.

  • sbjs_migrations
  • sbjs_current_add
  • sbjs_first_add
  • sbjs_current
  • sbjs_first
  • sbjs_udata
  • sbjs_session
  • h3l4tf0osh9q2lb6g503f3ee7r-session
  • _engagebay_visitor_id

If you decline consent to these cookies, you may still use this site, but your ability to use some areas of our site, will be limited. For example, this site will not be able to personalize your experience.

 

8. Purpose for use of your personal data

We process your personal information for the following purposes:

  • Corresponding with you via email
  • Managing usage of the Site; providing you with support related to accessing and using the Site; monitoring logins and log-outs
  • Improving the Site content and navigation; informing you about updates to the Site
  • Understanding the user population; determining whether the Site is designed to work with the Device settings of a majority of users
  • Send marketing communications via emails, chat, social media from BCG based on your consent where required.

We will not sell, share, or rent or otherwise make available your personal information to other parties, except that we may disclose the information to third parties who perform services on our behalf and have a need to access the information in connection with those services. Any third parties will only process this information to the extent to which and within the limits that BCG itself is permitted to process that data.

 

9. How your personal data is used

Personal information is processed in the following ways and in accordance with applicable data privacy laws, the processing is based on the lawful bases as stated below.

In some situations, as listed above we may need to process your personal data for the legitimate interests pursued by us for following purposes, unless consent is required specifically under applicable data privacy laws.

Where you have consented on or before the collection, use and/or disclosure of your personal data;

Where we are otherwise permitted to do so under applicable data privacy laws.

We process your personal information for the purposes described above: when we have your consent to do so, where applicable; when necessary to enter into a contract with you; when necessary for us to comply with a legal obligation; or when necessary for the purposes of our legitimate interests as a company operating globally. You may withdraw your consent at any time by sending an email to datasubjectrights@bcg.com. For users in Germany please email us at datenschutz@bcg.com.

 

10. Disclosure of personal data

The information you provide will naturally only be used for the purposes explained under this Privacy Policy and will not be disclosed to third parties. However, given the global nature of BCG, Personal data may be processed at various locations where BCG conducts business, including in the United States and other countries as well as to external service providers appointed by BCG or another BCG company to perform IT services, IT infrastructure, business, administrative, and management functions for BCG and cloud storage capabilities e.g. BCG maintains and stores personal information in systems and applications located in Europe and the United States, and the personal information is only accessible by authorized persons or vendors who are bound by privacy requirements. BCG appreciates the confidential nature of personal data and discloses it only as necessary for BCG’s valid business purposes or as required by law as described herein, although whenever possible to do so, information will be anonymized prior to its production.

We may also disclose your Personal Data to law enforcement agencies, courts, other government authorities or other third parties where we believe necessary to comply with a legal or regulatory obligation. Further we may disclose your Personal Data to potential transaction partners, service providers, advisors, and other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company, or we sell or transfer all or a portion of our assets or business. Should such a sale or transfer occur, we will use reasonable efforts to obligate the entity to which we transfer your Personal Data to use it in a manner that is consistent with this Policy.

 

11. Choices regarding disclosures

BCG does not disclose your personal data for purposes not described herein or to unaffiliated third parties for commercial or marketing purposes. BCG allows individuals to “opt out” before commencing any such disclosure in the future.

 

12. Data retention

Personal data will only be kept as long as is reasonably necessary to fulfil the purpose for which it was collected. We may retain your personal information for longer if they may be the subject of a legal claim, or may otherwise be relevant for future litigation.

In some circumstances we will anonymise and/or aggregate your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

 

13. Disclosure of personal data

The information you provide will naturally only be used for the purposes explained under this Privacy Policy and will not be disclosed to third parties. However, given the global nature of BCG, Personal data may be processed at various locations where BCG conducts business, including in the United States and other countries as well as to external service providers appointed by BCG or another BCG company to perform IT services, IT infrastructure, business, administrative, and management functions for BCG and cloud storage capabilities e.g. BCG maintains and stores personal information in systems and applications located in Europe and the United States, and the personal information is only accessible by authorized persons or vendors who are bound by privacy requirements. BCG appreciates the confidential nature of personal data and discloses it only as necessary for BCG’s valid business purposes or as required by law as described herein, although whenever possible to do so, information will be anonymized prior to its production.

We may also disclose your Personal Data to law enforcement agencies, courts, other government authorities or other third parties where we believe necessary to comply with a legal or regulatory obligation. Further we may disclose your Personal Data to potential transaction partners, service providers, advisors, and other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell or transfer all or a portion of our assets or business. Should such a sale or transfer occur, we will use reasonable efforts to obligate the entity to which we transfer your Personal Data to use it in a manner that is consistent with this Policy.

 

14. Data security

BCG handles personal data in accordance with BCG procedures to protect the integrity and security of the personal data, including conducting periodic reviews of personal data quality, purging obsolete information, and imposing security measures such as industry-standard technical, physical and administrative safeguards. We have taken extensive technical and operational precautions to protect your data from accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological progress.

 

15. Your rights

In accordance with applicable data protection laws, including but not limited to the GDPR, have the right to access your personal data, you have a right to request a copy of the personal information we hold about you and details of how we use that information. If any of the information held about you is incorrect or out of date, you have the right to amend or rectify it. Please follow the process outlined below and we will amend our records where appropriate. You also have the right to require us to erase your personal data, stop processing your personal data, restricting the processing of your personal information, right of portability of your personal information, right of not be subject to automated decision making, including profiling and/or to withdraw your consent to processing. This may not apply if there are other legal justifications to continue processing.

If you think we may have incorrect personal information or would like a copy of the personal information we hold on you, or to exercise any other data protection right, please contact us on our point of contacts below. Please note that we need you to prove who you are before we can provide you with any information. You also have a right to lodge a complaint with your local supervisory authority.

 

15. Contact us

If you have further questions on the topic of data protection, please contact us. For questions regarding the processing of your personal data, regarding access, rectification, blocking/restriction of processing or erasure of data, data transferability, objection to data processing and revocation of given consents, please contact us via:

Data Protection Office
Boston Consulting Group Inc.
200 Pier Four Boulevard
Boston, MA 02210
Contact Us

California

As required by the California Privacy Laws, this Privacy Policy describes the categories of personal data collected, processed, and disclosed by BCG, the categories of sources for that data, and the business or commercial purposes for which that data is collected, processed, and disclosed.

If you are a California resident, please see the California Addendum.

Germany
Data Protection Officer (Der Datenschutzbeauftragte)
Boston Consulting Group GmbH
Ludwigstrasse 21
80539 Munich Germany
Contact Us

Contact Us

If you have further questions on the topic of data protection, please contact us. For questions regarding the processing of your personal data, regarding access, rectification, blocking/restriction of processing or erasure of data, data transferability, objection to data processing and revocation of given consents, please contact us via:

Data Protection Office

Boston Consulting Group Inc.
200 Pier Four Boulevard
Boston, MA 02210

California

As required by the California Consumer Privacy Act (CCPA), this Privacy Policy describes the categories of personal data collected, processed, and disclosed by BCG, the categories of sources for that data, and the business or commercial purposes for which that data is collected, processed, and disclosed.

California residents may exercise their privacy rights by calling us toll free at
1-866-I-OPT-OUT (1-866-467-8688) and entering service code 837# to leave us a message.

Germany

Data Protection Officer (Der Datenschutzbeauftragte)
Boston Consulting Group GmbH
Ludwigstrasse 21
80539 Munich Germany