ENG

Counterpoint Research Privacy Policy

Last Updated: 1 September 2026

1. Introduction and Scope

Counterpoint Research (“Counterpoint,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information. This Privacy Policy explains how Counterpoint collects, uses, shares, retains, transfers and protects personal information when you interact with our websites, research platforms, products, services, events and communications. Where a specific Counterpoint product or service has additional privacy terms, those terms supplement this Policy. Where a written customer agreement contains specific data-protection provisions, those provisions will apply to the extent of any conflict.

2. Who Is Responsible for Your Personal Information

Counterpoint operates internationally. The entity generally responsible for your personal information is Counterpoint Research Inc., which serves as Counterpoint’s global entity for legal and contractual purposes regardless of your country or region. Where a Counterpoint affiliate operates a specific regional service or otherwise manages the relevant business relationship, that affiliate may act as the responsible entity for the related personal information, subject to applicable law. Counterpoint affiliates may also process personal information as necessary to support global operations, subject to applicable law. For privacy questions or requests, you may contact the Counterpoint Privacy Team at [email protected].

3. Personal Information We Collect

Depending on how you interact with Counterpoint, we may collect the following categories of personal information: • contact and professional information, such as name, business email address, telephone number, company, job title, role and country or region; • account and access information, such as username, login information, subscription or platform-access information and account activity; • business relationship information, such as customer or prospective-customer status, service interests, communications and relationship-management records; • event and webinar information, such as registration details and participation information; • marketing information, such as communication preferences and interactions with newsletters or other marketing communications; • technical and usage information, such as IP address, browser type, device information, website usage, logs and cookie or similar identifiers; and • other information you choose to provide when communicating with Counterpoint.

4. Sources of Personal Information

We may obtain personal information: • directly from you; • from your employer or organization in connection with a business relationship or service; • from event or webinar organizers and business partners, where permitted by applicable law; • from referrals or professional contacts; • from publicly available business sources and professional networking sources, where lawful; and • automatically through websites and digital services, including through cookies and similar technologies.

5. How We Use Personal Information

We may use personal information for purposes including: • responding to inquiries, requests and communications; • managing customer, prospective-customer and business relationships; • providing and administering access to research platforms, subscriptions and licensed content; • providing customer support and service communications; • organizing events, webinars and conferences; • sending newsletters, research updates, event invitations and information about Counterpoint products and services where permitted by applicable law; • operating, securing, analyzing and improving our websites, platforms and services; • protecting against fraud, unauthorized access, misuse and cybersecurity threats; • maintaining business, compliance and operational records; • complying with legal, tax, accounting, regulatory and contractual obligations; and • establishing, exercising or defending legal claims.

6. Legal Bases for Processing

Depending on the individual’s location and the nature of the processing, applicable privacy and data-protection laws may include the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR) and UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), applicable Canadian privacy legislation, the Swiss Federal Act on Data Protection (FADP), India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules, and other applicable local privacy and data-protection laws. Where applicable law provides additional rights or imposes additional requirements, Counterpoint will comply with those requirements to the extent applicable. Where the EU GDPR, UK GDPR or similar legislation applies, Counterpoint may process personal information based on one or more applicable lawful bases, including performance of a contract, compliance with a legal obligation, consent, legitimate interests or another lawful basis permitted by applicable law. Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. Marketing Communications

Where permitted by applicable law, Counterpoint may use business contact information to send newsletters, research updates, event invitations and information about Counterpoint products and services. You may unsubscribe from marketing emails at any time by using the unsubscribe mechanism included in the communication or by contacting us. Counterpoint may retain limited suppression information where necessary to ensure that an opt-out preference is honored.

8. Sharing Personal Information

Counterpoint may share personal information where necessary to provide services, operate its business, comply with law or otherwise carry out legitimate business purposes. Recipients may include, where applicable: • Counterpoint affiliates and group companies; • cloud and hosting providers; • IT and cybersecurity providers; • customer relationship management providers; • email and communications providers; • analytics providers; • authentication providers; • customer-support providers; • event and webinar providers; • marketing service providers; • professional advisers, auditors and insurers; • regulators and government authorities where legally required; and • parties involved in a merger, acquisition, restructuring, financing or sale of business assets. Where a third party processes personal information on Counterpoint’s behalf, Counterpoint will take reasonable steps to require appropriate confidentiality, security and data-protection obligations. Some third parties may act as independent controllers and may apply their own privacy policies. Counterpoint does not sell personal information for monetary consideration in the ordinary course of its business. Where applicable privacy laws define “sale” or “sharing” more broadly, Counterpoint will provide any legally required disclosures and opt-out mechanisms.

9. International Data Transfers

Counterpoint operates internationally and personal information may be transferred to, stored in or accessed from countries outside the country where the information was collected. Where applicable law restricts international transfers, Counterpoint will use an appropriate lawful transfer mechanism, which may include an adequacy decision, EU Standard Contractual Clauses, the UK International Data Transfer Agreement or applicable Addendum, approved contractual safeguards, applicable certification mechanisms or another transfer mechanism permitted by law. Where required, Counterpoint will implement appropriate supplementary safeguards and conduct relevant transfer assessments.

10. Data Retention

Counterpoint retains personal information only for as long as reasonably necessary for the purposes for which it was collected. Retention periods may depend on the nature and sensitivity of the information, the purpose for which it is processed, the relationship with the individual or customer, contractual requirements, legal, tax and accounting obligations, regulatory requirements, security and fraud-prevention requirements, dispute-resolution requirements and the establishment, exercise or defence of legal claims. • Account information — While the account remains active and for a reasonable period thereafter • Customer and subscription information — For the duration of the relationship and as required for legal, accounting and contractual purposes • Billing and transaction records — For the period required by applicable tax, accounting and legal requirements • Marketing preferences — Until withdrawal or opt-out and for the period necessary to maintain suppression records • Customer communications — For as long as reasonably necessary to administer the relationship and address legal or operational requirements • Security and technical logs — For the period reasonably necessary for security, fraud prevention and operational purposes • Event and registration information — For the period reasonably necessary to administer the event, relationship and related legal obligations Where personal information is no longer required, Counterpoint will delete, anonymize or securely dispose of it in accordance with applicable procedures. Specific legal, regulatory or contractual obligations may require longer retention.

11. Data Security and Personal-Data Breaches

Counterpoint maintains reasonable administrative, technical and organizational safeguards designed to protect personal information against loss, misuse, unauthorized access, disclosure, alteration or destruction. If Counterpoint becomes aware of a personal-data breach, it will assess and address the incident and provide notifications to regulators, affected individuals, customers or other parties where required by applicable law or contractual obligations. Where the GDPR applies, a qualifying personal-data breach may need to be reported to the competent supervisory authority within 72 hours of becoming aware of the breach, unless an applicable exception applies.

12. Your Privacy Rights

Depending on applicable law, individuals may have the right to: • access personal information held by Counterpoint; • correct inaccurate or incomplete personal information; • request deletion or erasure of personal information; • receive eligible personal information in a structured, commonly used and machine-readable format; • restrict or object to certain processing; • withdraw consent where processing is based on consent; • opt out of certain marketing communications; • opt out of sale or sharing where such rights apply; • limit certain uses of sensitive personal information where applicable; • obtain information about categories of personal information collected, sources, purposes of processing and categories of recipients; and • lodge a complaint with a competent data-protection authority. These rights are subject to applicable legal requirements and exceptions. Privacy requests may be submitted to the Counterpoint Privacy Team at [email protected]. Counterpoint may request reasonable information to verify the identity or authority of a requester before processing a request and will respond within the timeframe required by applicable law. Where legally permitted, Counterpoint may refuse or limit a request where an applicable legal exception applies, including where information must be retained to comply with law, maintain security, prevent fraud, complete a transaction or establish, exercise or defend legal claims.

13. Automated Decision-Making

Counterpoint does not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless such processing is permitted by applicable law and appropriate information and safeguards are provided.

14. Children’s Privacy

Counterpoint’s websites, research products and services are primarily intended for business and professional users and are not directed to children. Counterpoint does not knowingly collect personal information from children in circumstances where such collection is prohibited by applicable law. If Counterpoint becomes aware that personal information has been collected from a child in circumstances where it should not have been collected, Counterpoint will take reasonable steps to delete the information.

15. Changes to this Privacy Policy

Counterpoint may periodically modify or update this Privacy Policy to reflect changes in business practices, products and services, technology, applicable law, regulatory requirements or privacy practices. Updated versions will be published on the Counterpoint Website and the “Last Updated” date will indicate when the Policy was most recently revised. Where required by applicable law, Counterpoint will provide additional notice or obtain consent to material changes.

16. Contact Us

For privacy questions, complaints, rights requests or other privacy matters, contact: Counterpoint Research Privacy Team Email: [email protected] Where Counterpoint is legally required to appoint a Data Protection Officer, EU representative, UK representative, Swiss representative or other local privacy representative, the applicable contact details will be provided in the relevant country-specific notice or supplement.