1. Scope and responsible entity
This Privacy Policy describes how MSM Research and Insights Inc. ("MSM," "we," "us" or "our"), which operates WDL Research as a website brand, handles personal information in connection with wdlresearch.com, business enquiries, supplier relationships and related business communications.
This Policy is primarily a notice for website visitors and business contacts. A separate project notice, panel notice, client instruction or supplier notice may apply when personal information is processed for a research study. If a project-specific notice conflicts with this Policy for that processing, the project-specific notice governs.
2. People and processing roles covered
Our role depends on the relationship and project. MSM generally acts as a business or controller for information collected directly through this website and for its own business administration. For research operations, MSM may act as a processor or service provider under a client’s instructions, as an independent controller for limited operational purposes, or alongside approved sample and recruitment partners that control their own participant relationships.
- Website visitors who browse the corporate website.
- Client, prospective-client and procurement contacts who request information, feasibility or proposals.
- Supplier and business-partner contacts involved in onboarding or project delivery.
- Research participants or respondents, only where MSM receives or otherwise processes participant-related information for a project.
3. Information we collect
The information we collect depends on how you interact with us. We seek to limit collection to information reasonably relevant to the interaction or project.
- Business contact information, including name, work email, telephone or WhatsApp number, company, role and country.
- Enquiry and RFQ information, including markets, target audiences, timing, feasibility requirements, message content and subsequent correspondence.
- Supplier information, including company identity, business contacts, capabilities, contracting details and performance-related communications.
- Technical information generated when the website is accessed, such as IP address, request time, browser or device information, requested URL, referral information and security logs maintained by hosting or infrastructure providers.
- Project information, which may include specifications, quotas, survey links, project identifiers, respondent identifiers, disposition data and quality signals.
- Participant-related information where required for a project. We prefer project IDs, respondent IDs and pseudonymous identifiers over unnecessary direct identifiers. The precise categories depend on client instructions and the supply source.
4. Sources of information
We may receive information directly from you; from your employer or colleagues; from clients and prospective clients; from approved sample, panel and recruitment partners; from research technology platforms; from publicly available business sources; and automatically through website and infrastructure logs. Participant information may originate from a client, an approved supply partner or the participant, depending on the research workflow.
5. How we use information
We use personal information only for legitimate and identified business, research, security and legal purposes.
- Responding to enquiries, assessing feasibility, preparing proposals and managing business relationships.
- Planning, operating, monitoring, reconciling and closing research projects.
- Routing participants, applying quotas, detecting duplicates or quality concerns, and supporting research integrity where relevant to a project.
- Evaluating and managing suppliers and approved sample partners.
- Operating, securing, troubleshooting and improving the website and internal systems.
- Maintaining contracts, business records, audit trails and financial documentation.
- Establishing, exercising or defending legal claims and complying with applicable laws, lawful requests and contractual duties.
- Sending business communications where permitted by law and consistent with the recipient’s relationship with us.
6. Legal bases where applicable
Where laws such as the GDPR or UK GDPR require a legal basis, processing may rely on steps requested before entering a contract or performance of a contract; legitimate interests in operating and protecting our business, responding to business enquiries and delivering responsible research operations; compliance with legal obligations; or consent where consent is required. When we process information solely for a client, the client determines the applicable legal basis and we act under documented instructions, subject to law and contract.
7. How information is disclosed
We may disclose information on a need-to-know basis to personnel and affiliated operations supporting the relevant purpose; clients and research technology platforms involved in a project; approved sample, panel, recruitment and fieldwork partners; hosting, database, communications and professional-service providers; transaction counterparties in a legitimate corporate transaction; and regulators, courts or authorities where legally required.
We do not disclose direct participant identifiers to a client or supplier unless the project requires it, the disclosure is authorized, and appropriate legal and contractual conditions are in place. We do not publish our supplier list, commercial rates or internal quality scoring methods.
8. Sale, sharing and targeted advertising
MSM does not sell website enquiry information for monetary consideration. The current website code does not activate cross-context behavioral advertising trackers. Online sample and research operations can involve transfers of participant-related information among clients, platforms and approved suppliers; the legal characterization of a particular transfer depends on the project facts and applicable law. Project-specific notices, contracts and opt-out mechanisms apply where legally required.
If our website advertising or data-transfer practices materially change, we will update this Policy and implement any legally required notice, consent or opt-out mechanism, including recognition of applicable preference signals where required.
9. International transfers
Our offices, clients, suppliers and service providers may be located in different countries. Information may therefore be processed outside the jurisdiction where it was collected. Where applicable law requires transfer safeguards, we use appropriate contractual and organizational measures, which may include data processing terms and approved contractual clauses. No transfer mechanism eliminates all risk, and the safeguards used depend on the relationship and destination.
10. Security
We apply proportionate technical and organizational measures intended to protect information against unauthorized access, alteration, loss or disclosure. Measures are selected according to the information, processing context and available systems and may include restricted access, authentication, secure transmission, logging, supplier controls and data minimization. No website, transmission method or storage system can be guaranteed to be completely secure.
Please do not submit special-category, highly sensitive or unnecessary personal information through the general Contact form.
11. Retention and disposal
We retain information only for as long as reasonably necessary for the stated purpose, contractual requirements, applicable legal or accounting obligations, security, dispute resolution and legitimate business records. Retention varies by data category and project. Participant-related project data is retained according to the relevant client instruction, project requirement, contract and applicable law, then deleted, anonymized or returned as appropriate.
The website enquiry database is not intended as permanent archival storage. Records are reviewed and removed when they are no longer reasonably required for follow-up, business records, security or legal purposes.
12. Privacy rights and requests
Depending on your location and the law that applies, you may have rights to request access, correction, deletion, restriction, objection or portability; withdraw consent; opt out of certain sale, sharing or targeted advertising; limit certain uses of sensitive information; and appeal a decision or complain to a regulator. These rights may be subject to exceptions.
Submit a request through the Contact page and identify it as a privacy request. We may ask for information reasonably necessary to verify identity, authority and jurisdiction. Authorized agents may submit requests where permitted, but we may require evidence of authorization and direct verification. If we process information only for a client, we may refer the request to that client.
13. California privacy notice
If the California Consumer Privacy Act, as amended, applies to MSM and to your information, California residents may request information about categories and specific pieces collected, sources, purposes and disclosures; request deletion or correction; opt out of sale or sharing; limit qualifying uses of sensitive personal information; and receive non-discriminatory treatment for exercising rights. MSM will evaluate applicability and respond in accordance with the law.
During the preceding 12 months, the categories described in Sections 3 and 4 may have been collected and disclosed for the business purposes described in Sections 5 and 7. We do not knowingly sell or share personal information of consumers under 16. Because applicability and project data flows depend on facts not established by this website alone, project-specific California disclosures or mechanisms may also apply.
15. Children and research participants
This corporate website is directed to business users and is not intended for children. We do not knowingly solicit personal information from children through the Contact form. Research involving minors, if undertaken for a specific project, must be governed by the client’s requirements, applicable law, appropriate consent procedures and the relevant participant-facing notice.
16. Third-party websites
The website links to third-party websites, including LinkedIn and audience-related sites. Those parties determine their own privacy practices. A link does not make MSM responsible for the third party’s content, security or handling of information.
17. Changes to this Policy
We may revise this Policy to reflect changes in law, technology, services or processing. The effective date identifies the current version. Material changes will be communicated through the website or another appropriate channel where required.
18. Contact
For privacy questions or rights requests, use the Contact page and state that the request concerns privacy, or write to: MSM Research and Insights Inc., 8 The Green, Dover, DE 19901, United States. WDL Research is a website brand of MSM Research and Insights Inc.