Ovation-Worldwide Holdings
Privacy Policy
We care about your privacy
YOUR PRIVACY MATTERS
Ovation-Worldwide Holdings, LLC Privacy Policy
Ovation-Worldwide Holdings, LLC, operating OvationMR (ovationmr.com), EthOS (ethosapp.com and associated mobile apps), and the SurveyWink Participant Panel (surveywink.com), is a global market research firm headquartered in the United States and may act as a data controller for certain activities such as operating our websites, research panels, and platform administration services, while in many research projects we act as a processor on behalf of research sponsors. We conduct research around the world through our survey platforms, research panels, participant portals, and mobile applications. We are committed to protecting the privacy and confidentiality of individuals who participate in our research or interact with our services. We design our data practices to comply with applicable global data protection and privacy regulations. Our research practices also follow recognized industry standards, including the Insights Association Code of Conduct, which promotes transparency, participant privacy, and responsible research practices.
03/12/2026
03/12/2026
Introduction
Who This Policy Applies To
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data, and describes your privacy rights under applicable laws.
The specific data we collect depends on how you interact with our services and the type of research activities you participate in.
Research Participants
Individuals who participate in surveys, interviews, diary studies, product testing, or other research activities conducted through our platforms.
Research Panel Members
Individuals who register for and maintain membership in our research panels, such as SurveyWink, and may be invited to participate in research studies
Platform Users (Clients)
Authorized users of our research platforms, including EthOS, who create, manage, or analyze research projects on behalf of their organizations.
Website Visitors
Individuals who browse or interact with our public websites.
Research Participants
Individuals who participate in surveys, interviews, diary studies, product testing, or other research activities conducted through our platforms.
Research Panel Members
Individuals who register for and maintain membership in our research panels, such as SurveyWink, and may be invited to participate in research studies
Platform Users (Clients)
Authorized users of our research platforms, including EthOS, who create, manage, or analyze research projects on behalf of their organizations.
Website Visitors
Individuals who browse or interact with our public websites.
Clients, prospective clients, vendors, and other professional contacts who interact with OvationMR through business communications or service relationships.
Privacy and Security Go Hand in Hand
PROTECTING YOUR PRIVACY
Participant Privacy and Confidentiality
We design our research platforms, websites, and processes to protect your personal information. Personal data is handled with confidentiality and used only for legitimate research and service purposes, with safeguards in place to prevent misuse, unauthorized access, or disclosure.
SECURITY & TRUST
ISO/IEC 27001 Certified
OvationMR maintains an ISO/IEC 27001-certified Information Security Management System (ISMS), demonstrating our commitment to strong security controls and the protection of personal data.
PROTECTING YOUR PRIVACY
Participant Privacy and Confidentiality
We design our research platforms, websites, and processes to protect your personal information. Personal data is handled with confidentiality and used only for legitimate research and service purposes, with safeguards in place to prevent misuse, unauthorized access, or disclosure.
SECURITY & TRUST
ISO/IEC 27001 Certified
OvationMR maintains an ISO/IEC 27001-certified Information Security Management System (ISMS), demonstrating our commitment to strong security controls and the protection of personal data.
1. Scope and Role
Different data protection laws use different terms to describe the roles organizations have when handling personal data. For example, U.S. privacy laws such as the CCPA/CPRA use terms like business, service provider, and contractor, while laws such as the GDPR use the terms controller and processor. In simple terms, a controller decides why and how personal data is used, while a processor handles data on behalf of someone else who makes those decisions. Throughout this Privacy Policy, we use the terms controller and processor for consistency.
In most research projects, OvationMR acts as a processor processing personal data on behalf of research sponsors that design and control the study. In other contexts, such as managing our research panels, websites, and platform accounts, OvationMR acts as the data controller.
When OvationMR acts as controller)
Managing SurveyWink panel member accounts, managing our websites, operating our research platforms, platform administration, participant management, and related services.
When OvationMR acts as processor
Processing personal data on behalf of research sponsors using our survey and research platforms, including EthOS.
When OvationMR acts as controller)
Managing SurveyWink panel member accounts, managing our websites, operating our research platforms, platform administration, participant management, and related services.
When OvationMR acts as processor
Processing personal data on behalf of research sponsors using our survey and research platforms, including EthOS.
2. Categories of Personal Data We Collect
Not all categories listed below apply to every Service. These categories may be collected directly from you, provided by research partners or panel providers, or generated through your participation in research activities. The specific data collected depends on your interaction with our platforms, the type of research activity, and whether OvationMR acts as controller or processor.
Account and Contact Information
- Name
- Email Address
- Phone Number
- Postal Address
- Username and Password
- Account Preferences
- Communications Settings
- Account Preferences
Demographic and Profile Information
- Age / date of birth
- Gender
- Household Information
- Education and employment data
- Lifestyle and interest data
Research Participation Data
- Survey Responses
- Ethnographic diary entries
- In-moment research submissions
- Photos, videos, audio recordings
- Open-ended responses and behavioral insights
Technical and Usage Data
- IP Address
- Device identifiers
- Browser type and operating system
- Website and App usage metrics
- Log data and timestamps
- Cookie identifiers
Incentive and Payment Information
- Points balance
- Reward redemptions
- Payment method details processed via secure third-party providers
Sensitive Personal Data
- Race or ethnicity
- Precise geolocation data
- Other sensitive data voluntarily provided in surveys or research activities when relevant to a specific research study
Sensitive Personal Data
Some research studies may involve the collection of sensitive personal data where relevant to the research topic or the objectives of the research study, such as demographic attributes, race or ethnicity, health-related information, political opinions, or other sensitive topics when relevant to the research. Participation in our research studies is always voluntary. Providing sensitive information is voluntary; however, some studies may require certain information to participate, and explicit consent is obtained where required by law.
If you are located in the EU or UK, we rely on explicit consent for the collection of sensitive data, subject to appropriate safeguards including pseudonymization (meaning information is separated from direct identifiers such as your name or email so it cannot easily be linked back to you) and confidentiality protections.
2. Categories of Personal Data We Collect
Not all categories listed below apply to every Service. These categories may be collected directly from you, provided by research partners or panel providers, or generated through your participation in research activities. The specific data collected depends on your interaction with our platforms, the type of research activity, and whether OvationMR acts as controller or processor.
Account and Contact Information
- Name
- Email Address
- Phone Number
- Postal Address
- Username and Password
- Account Preferences
- Communications Settings
- Account Preferences
Demographic and Profile Information
- Age / date of birth
- Gender
- Household Information
- Education and employment data
- Lifestyle and interest data
Research Participation Data
- Survey Responses
- Ethnographic diary entries
- In-moment research submissions
- Photos, videos, audio recordings
- Open-ended responses and behavioral insights
Technical and Usage Data
- IP Address
- Device identifiers
- Browser type and operating system
- Website and App usage metrics
- Log data and timestamps
- Cookie identifiers
Incentive and Payment Information
- Points balance
- Reward redemptions
- Payment method details processed via secure third-party providers
Sensitive Personal Data
- Race or ethnicity
- Precise geolocation data
- Other sensitive data voluntarily provided in surveys or research activities when relevant to a specific research study
Sensitive Personal Data
Some research studies may involve the collection of sensitive personal data where relevant to the research topic or the objectives of the research study, such as demographic attributes, race or ethnicity, health-related information, political opinions, or other sensitive topics when relevant to the research. Participation in our research studies is always voluntary. Providing sensitive information is voluntary; however, some studies may require certain information to participate, and explicit consent is obtained where required by law.
If you are located in the EU or UK, we rely on explicit consent for the collection of sensitive data, subject to appropriate safeguards including pseudonymization (meaning information is separated from direct identifiers such as your name or email so it cannot easily be linked back to you) and confidentiality protections.
3. How We Collect and Use Personal Data
We collect personal data when you interact with our services in the following ways, and in some cases we may also receive limited profile or qualification information from research partners or panel providers. In most cases, research data shared with research sponsors is provided in aggregated, pseudonymized, or otherwise de‑identified form so that individual participants are not directly identifiable. The table below summarizes the categories of personal data we collect, why we use it, and who we may share it with. We do not sell personal information or share personal information for cross‑context behavioral advertising.
address, account
credentials
participation, rewards,
sales, marketing, and
newsletters
service providers
supporting platform
operations
education, employment,
interests
sampling, research insights
approved research
processors
entries, multimedia
submissions
responses, reporting
service providers
identifiers, browser, logs,
cookies
analytics, performance
chatbot, security, and IT
infrastructure providers
payment details
compliance
and reward fulfillment
providers
3. How We Collect and Use Personal Data
We collect personal data when you interact with our services in the following ways, and in some cases we may also receive limited profile or qualification information from research partners or panel providers. In most cases, research data shared with research sponsors is provided in aggregated, pseudonymized, or otherwise de‑identified form so that individual participants are not directly identifiable. The table below summarizes the categories of personal data we collect, why we use it, and who we may share it with. We do not sell personal information or share personal information for cross‑context behavioral advertising.
address, account
credentials
education, employment,
interests
entries, multimedia
submissions
identifiers, browser, logs,
cookies
payment details
participation, rewards,
sales, marketing, and
newsletters
sampling, research insights
responses, reporting
analytics, performance
compliance
service providers
supporting platform
operations
approved research
processors
service providers
chatbot, security, and IT
infrastructure providers
and reward fulfillment
providers
4. Cookies and Mobile Technologies
Cookies and Tracking,
We use cookies and similar technologies on our websites to support functionality, security, performance, analytics, and user experience. A cookie is a small text file that is stored on your device when you visit a website and helps the site recognize your browser, remember preferences, and maintain secure sessions. Our websites also use a consent management platform to help manage cookie preferences and support compliance with applicable privacy laws such as the EU GDPR, UK GDPR, and the ePrivacy Directive.
When you visit our websites, you may be presented with a cookie consent banner—depending on the specific site and your region—that allows you to accept, reject, or customize your cookie preferences. Non-essential cookies will only be activated after you provide consent where required by applicable law.
Cookies on our websites may help us to:
– Maintain secure sessions
– Enable core website functionality
– Remember user preferences
– Measure website traffic and usage patterns
– Improve performance and user experience
– Detect fraud, prevent duplicate survey participation, or misuse of research systems
– Support session management for research participation and reward processing
Mobile Applications (iOS and Android)
If you use the EthOS mobile application, we may collect additional information necessary for app functionality and research participation.
Device permissions may include:
– Camera
– Microphone
– Photo library
– Location services, including precise GPS-level location when enabled
– Push notifications for new studies, research tasks, or reminders
We may collect mobile device information such as device model, operating system, identifiers, app diagnostics, and network information to ensure proper app functionality, maintain security, troubleshoot technical issues, analyze performance, and prevent fraud or misuse. We also use analytics and performance monitoring tools to identify application errors, improve functionality, and maintain service reliability.
We do not use advertising identifiers for cross-context behavioral advertising.
Cookies and Tracking,
We use cookies and similar technologies on our websites to support functionality, security, performance, analytics, and user experience. A cookie is a small text file that is stored on your device when you visit a website and helps the site recognize your browser, remember preferences, and maintain secure sessions. Our websites also use a consent management platform to help manage cookie preferences and support compliance with applicable privacy laws such as the EU GDPR, UK GDPR, and the ePrivacy Directive.
When you visit our websites, you may be presented with a cookie consent banner—depending on the specific site and your region—that allows you to accept, reject, or customize your cookie preferences. Non-essential cookies will only be activated after you provide consent where required by applicable law.
Cookies on our websites may help us to:
– Maintain secure sessions
– Enable core website functionality
– Remember user preferences
– Measure website traffic and usage patterns
– Improve performance and user experience
– Detect fraud, prevent duplicate survey participation, or misuse of research systems
– Support session management for research participation and reward processing
Mobile Applications (iOS and Android)
If you use the EthOS mobile application, we may collect additional information necessary for app functionality and research participation.
Device permissions may include:
– Camera
– Microphone
– Photo library
– Location services, including precise GPS-level location when enabled
– Push notifications for new studies, research tasks, or reminders
We may collect mobile device information such as device model, operating system, identifiers, app diagnostics, and network information to ensure proper app functionality, maintain security, troubleshoot technical issues, analyze performance, and prevent fraud or misuse. We also use analytics and performance monitoring tools to identify application errors, improve functionality, and maintain service reliability.
We do not use advertising identifiers for cross-context behavioral advertising.
5. International Data Transfers
As a U.S.-based company, personal data may be processed in the United States or other countries where data protection laws may differ from those in your country.
Where required, we implement safeguards such as:
Standard Contractual Clauses (SCCs) – Legal agreements approved by regulators that require organizations transferring data internationally to protect it according to EU/UK privacy standards.
Contractual Data Protection Provisions – Privacy and security commitments written into our contracts with partners and service providers to ensure personal data is handled appropriately.
Security and Technical Safeguards – Technical and organizational protections such as encryption, access controls, and confidentiality requirements designed to keep personal data secure when transferred or processed. Additional safeguards may be implemented where required under applicable law.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including conducting research studies, administering research panels, providing our services, complying with legal obligations, resolving disputes, and enforcing agreements.
Retention periods may vary depending on the nature of the research project, contractual obligations with research sponsors, regulatory requirements, and legitimate business needs. When personal data is no longer required, we securely delete, anonymize, or de-identify the information in accordance with our data retention policies. In some circumstances, research results may be retained in pseudonymized or aggregated form for statistical analysis or research validation purposes.
7. Privacy Rights
Depending on your location and applicable data protection laws, you may have certain rights regarding your personal data. We do not use automated decision‑making or profiling that produces legal or similarly significant effects on individuals. These rights may arise under laws such as the EU General Data Protection Regulation (GDPR), UK GDPR, and U.S. state privacy laws including the California Consumer Privacy Act (CCPA/CPRA). While the specific rights available may vary by jurisdiction, we make reasonable efforts to honor these rights for individuals wherever possible, even when local laws may not strictly require it.
- Access
- Correction
- Deletion
- Restriction
- Objection
- Data portability
- Withdraw consent
- Non-discrimination
To exercise your rights, please contact us at privacy@ovationmr.com. For privacy and security reasons, we may take reasonable steps to verify your identity before fulfilling a request. In some cases, if the personal data was collected as part of a research study conducted on behalf of a research sponsor, we may direct your request to the appropriate organization responsible for that study. We will respond to privacy requests within the timeframes required by applicable law. We may also retain limited information related to a request (such as the email correspondence or records of the request) where necessary to document our compliance with applicable privacy laws and regulatory requirements.
8. Children’s Privacy
Our Services are not directed to children under the age of 13, consistent with the U.S. Children’s Online Privacy Protection Act (COPPA), or to minors under the age permitted by applicable law in their jurisdiction. In limited circumstances, research studies involving minors may be conducted only where appropriate parental or guardian consent has been obtained in accordance with applicable laws and research ethics standards. We do not knowingly collect personal data from children without such consent. If we become aware that personal data from a child has been collected without the required consent, we will take reasonable steps to promptly delete that information from our systems. If you believe a child has provided personal data without appropriate consent, please contact us so that we can investigate and address the situation.
9. Security Measures
We use a combination of administrative, technical, and organizational safeguards to protect personal data from unauthorized access, loss, misuse, or disclosure. OvationMR maintains an ISO/IEC 27001‑certified Information Security Management System (ISMS), which means our security program follows internationally recognized standards for protecting information.
Examples of security controls we use include:
Access Controls – Only authorized personnel can access systems containing personal data, and access is limited based on job responsibilities.
Encryption – Sensitive information is protected using encryption when transmitted over networks and when stored in secure systems.
Security Monitoring – Our systems are monitored for suspicious activity, unauthorized access attempts, and potential security threats.
Vendor Security Reviews – Third‑party service providers are evaluated to ensure they meet appropriate security and privacy standards.
Employee Training – Employees receive training on information security, data protection, and confidentiality obligations.
Incident Response Procedures – We maintain processes for identifying, investigating, and responding to potential security incidents.
While no system can guarantee absolute security, we continually review and improve our safeguards to protect personal data.
ISO/IEC 27001 Certified
10. Changes to This Policy
We may update this Privacy Policy periodically. Where required by applicable law, we will provide notice of material changes. Updates will be posted with a revised effective date.
11. Contact Info
COMPANY
OvationMR-Worldwide Holdings, LLC
ADDRESS
101 Avenue of the Americas
9th Floor, Suite 908
New York, NY 10013
EMAIL / PHONE
privacy@ovationmr.com
+1.212.653.8750
COMPANY
OvationMR-Worldwide Holdings, LLC
ADDRESS
101 Avenue of the Americas
9th Floor, Suite 908
New York, NY 10013
EMAIL / PHONE
privacy@ovationmr.com
+1.212.653.8750
12. Complaints
If you have concerns about how your personal data has been handled, you may have the right to lodge a complaint with a supervisory authority in your jurisdiction.
However, we would appreciate the opportunity to address and resolve your concern first. If you have a privacy-related question or complaint, please contact us at privacy@ovationmr.com so that we can work with you to resolve the matter.
For individuals located in the European Economic Area (EEA) or the United Kingdom, we have appointed representatives for data protection matters in those regions. These representatives are designated specifically for regulatory purposes within those jurisdictions.
EEA Representative
VeraSafe Netherlands BV, Keizersgracht 555, 1017 DR
Amsterdam, Netherlands.
UK Representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL, United Kingdom
EEA Representative
VeraSafe Netherlands BV, Keizersgracht 555, 1017 DR
Amsterdam, Netherlands.
UK Representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL, United Kingdom


