They said they only did this for US based IP addresses. (Not that it makes it OK...)
Even if they aren't, I still wonder that if they're checking everyones IP addresses against that database, essentially sharing our access of SO with a third-party, would it still be an inappropriate use of personally identifiable information?
Quoting their website, "The organization name is available for about 40% of corporate, government, and educational networks."