Attn: Legal Department
99 Hudson, 17th Floor, New York, NY 10013
2. A Note About Minors. We do not intentionally gather personal data from visitors who are under the age of 18. If a minor under 18 submits personal data to Ethic and we learn that the personal data is the information of a minor under 18, we will attempt to delete the information as soon as possible. If you believe that we might have any personal data from a minor under 18, please contact us at firstname.lastname@example.org.
4. Types of Data We Collect. We collect personal data from you in various ways.
(a) Information You Provide to Us. We collect the personal data you voluntarily provide to us. For example:
We may collect personal data from you, such as your first and last name, phone number, e mail and mailing addresses, professional title, company name, and password when you create an account to log in to our Services (“Account”);
We may collect holdings information provided by you or your advisor;
If you take a survey on one of our Sites, we will collect the answers you provide and may provide them to registered investment advisors so they may market their products and/or services to you;
- Certain services, such as two-factor authentication, may require our collection of your phone number. We may associate that phone number to your mobile device identification information;
- We retain information on your behalf, such as files and messages that you store using your Account;
- If you provide us feedback or contact us via e-mail, we will collect your name and e-mail address, as well as any other content included in the e-mail, in order to send you a reply;
- When you publicly post or share content (such as text, images, photographs, messages, comments or other kind of content) on a publicly accessible area of the Service or with other users of the Services, the information contained in your posting will be stored in our servers and other users will be able to see it. The information that you provide in your profile page (“Profile”) will be visible to others;
- When you post messages on the message boards of our Sites, the information contained in your posting will be stored on our servers and other users will be able to see it;
- We also collect other types of personal data that you provide to us voluntarily, including when you answer questions on one of our surveys to determine what kind of portfolio we might recommend to Clients, your financial and sustainability goals and objectives, other financial information and other information your provide during the onboarding process, and other requested information if you contact us via e-mail regarding support for the Services. We may also share this information with registered investment advisors that we partner with so that they can market their products and services to you; and
- We may also collect personal data at other points in our Services that state that personal data is being collected.
(b) Acting as your Authorized Agent. Ethic offers services where Ethic acts as an agent to retrieve your financial account information, such as your account balances and holdings and transactions, and household information, from financial institutions designated by you. By accessing and using the Services you expressly authorize and direct Ethic, on your behalf, to electronically retrieve your account information maintained by third party financial institutions with which you have a legally binding customer relationship (“Account Information”). Ethic may work with one or more third-party financial service technology providers to access and retrieve your Account Information.
(c) Information Collected via Technology.
- Cookies and Other Information Collected by Automated Means. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and activity occurring on or through the Service. The information that may be collected automatically includes your computer or mobile device operating system type and version number, manufacturer and model, browser type, screen resolution, IP address, the website you visited before browsing to our website, general location information such as city, state or geographic area; and information about your use of and actions on the Service, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and length of access. Our service providers and business partners may collect this type of information over time and across third-party websites and mobile applications. On our webpages, this information is collected using cookies, browser web storage (also known as locally stored objects, or “LSOs”), web beacons, and similar technologies, and our emails may also contain web beacons.
(d) Information Collected from You About Others. If you decide to invite a third party to create an Account, we will collect your and the third party’s names and e-mail addresses in order to send an e-mail and follow up with the third party. We rely upon you to obtain whatever consents from the third party that may be required by law to allow us to access and upload the third party’s names and e-mail addresses as required above. You or the third party may contact us at email@example.com to request the removal of this information from our database.
(e) Information Collected from Third Party Companies. We may receive personal and/or anonymous data about you from our third-party partners, including from registered investment advisor databases. These third-party companies may supply us with personal data. We may add this information to the information we have already collected from you via our Services in order to improve the Services we provide.
5. Use of Your Personal Data
(a) To operate the Service. We use your personal information to:
- provide, operate and improve the Service
- provide information about our products and services
- establish and maintain your user profile on the Service
- communicate with you about the Service, including by sending you announcements, updates, security alerts, and support and administrative messages
- communicate with you about events or contests in which you participate
- understand your needs and interests, and personalize your experience with the Service and our communications
- provide support and maintenance for the Service
- respond to your requests, questions and feedback
(b) For research and development. We analyze use of the Service to analyze and improve the Service and to develop new products and services, including by studying user demographics and use of the Service.
(c) To send you marketing and promotional communications. We may send you Ethic-related marketing communications as permitted by law. You will have the ability to opt-out of our marketing and promotional communications as described in section 8(a) below.
(d) To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
(e) For compliance, fraud prevention, and safety. We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
(f) With your consent. In some cases we may specifically ask for your consent to collect, use or share your personal information, such as when required by law.
(g) To create anonymous, aggregated or de-identified data. We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you. We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including, but not limited to analyze and improve the Service and promote our business.
(a) Third Parties Designated by You. When you use the Services, the personal data you provide will be shared with the third party that you designate to receive such information, including other websites and your business associates. For example, registered investment advisors, advisory firms, wealth management and technology providers.
(b) Users. We will share your personal data with other users solely for the purpose of providing the Services. For example, advisor firms on the Services may have access to information regarding their End-Client accounts.
(c) Third Party Service Providers. We may share your personal data with our third-party service providers to: provide you with our Services; to invoice or process payments; to retrieve your Account Information; database management; to conduct quality assurance testing; to facilitate creation of accounts; to provide technical support; to provide mailing services; and/or to provide other services to Ethic.
(d) Brokerage Partners. We may share the information required to become a Client with select brokerage partners solely for the purpose of allowing our brokerage partner to provide services to you.
(g) Information You Share; Public Profile. When you use our Services, you may choose to post or share certain information with other users. We may display this content on the Services, and once displayed on web pages viewable by other users, that information can be collected and used by others. We cannot control who reads the information you choose to share or what other users may do with the information that you voluntarily post and/or share. In addition, certain information may be displayed in your Profile and on the Services, such as your name, professional title, company name, and photo. You may edit such information by going to your Profile settings. Once you have posted information publicly, while you will still be able to edit and delete it on the Services, you will not be able to edit or delete such information cached, collected, and stored elsewhere by others.
8. Your Choices Regarding Information. You have several choices regarding the use of information on our Service:
(b) Cookies. If you decide at any time that you no longer wish to accept Cookies from our Service for any of the purposes described above, then you can instruct your browser, by changing its settings, to stop accepting Cookies or to prompt you before accepting a Cookie from the websites you visit. Consult your browser’s technical information. If you do not accept Cookies, however, you may not be able to use all portions of the Service or all functionality of the Service.
(c) Changing or Deleting Your personal data. All users may review, update, correct or delete the personal data in their user account by contacting us or editing their profile via the Services. If you completely delete all of your personal data, then your user account may become deactivated. We will use commercially reasonable efforts to honor your request. We may retain an archived copy of your records and residual information related to your Account, as well as any data related to your trades, as required by law or for legitimate business purposes.
(d) Declining to Provide personal data. You may decline to provide certain personal data to Ethic. Declining to provide personal data may disqualify you for features of the Services that require certain Personal Data.
(e) Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
9. Security. Ethic takes reasonable steps to protect your personal data from loss, misuse, and unauthorized access, alteration, disclosure, or destruction. No Internet, email, or electronic operating system that enables the transmission of data is ever fully secure or error free so, please take special care in deciding what information you send to us in this manner. In the event of a data breach involving personal data you will be notified as soon as reasonably practicable, along with any supervisory authority as required.
11. Your California Privacy Rights
Under California Civil Code section 1798.83, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to us via email at firstname.lastname@example.org. You must put the statement "Your California Privacy Rights" in your request and include your name, street address, city, state, and ZIP code. We are not responsible for notices that are not labeled or sent properly, or do not have complete information.
12. Notice to European Users
The information provided in this “Notice to European Users” section applies only to individuals in Europe.
- To operate the service. Legal basis: Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service. If we have not entered into a contract with you, we process your personal data based on our legitimate interest in providing the Service you access and request.
- To administer events and contests, for research and development, to send you marketing communications, to manage our recruiting and process employment applications, for compliance, fraud prevention and safety, to create anonymous data. Legal basis: These activities constitute our legitimate interests. We do not use your personal data for these activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
- To comply with law. Legal basis: Processing is necessary to comply with our legal obligations.
- With your consent. Legal basis: Processing is based on your consent. Where we rely on your consent you have the right to withdraw it any time in the manner indicated when you consent or in the Service.
Automated Decision-Making and Profiling. We may use automated decision-making and/or profiling in regard to your personal data for some services and products, for example, fraud prevention technology that automatically blocks video uploads. You can request a manual review of the accuracy of an automated decision that you are unhappy with or limit or object to such automated decision-making and/or profiling by contacting us at email@example.com.
We retain personal data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal data we have collected about you, we will either delete or anonymize it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible. If we anonymize your personal data (so that it can no longer be associated with you), we may use this information indefinitely without further notice to you.
European data protection laws give you certain rights regarding your personal data. If you are located within the European Union, you may ask us to take the following actions in relation to your personal data that we hold:
- Access. Provide you with information about our processing of your personal data and give you access to your personal data.
- Correct. Update or correct inaccuracies in your personal data.
- Delete. Delete your personal data.
- Transfer. Transfer a machine-readable copy of your personal data to you or a third party of your choice.
- Restrict. Restrict the processing of your personal data.
- Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal data that impacts your rights.
You may submit these requests by email to firstname.lastname@example.org or our postal address provided above. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal data or our response to your requests regarding your personal data, you may contact us at email@example.com or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.
Cross-Border Data Transfer
If we transfer your personal data out of Europe to a country not deemed by the European Commission to provide an adequate level of personal data protection, the transfer will be performed:
- Pursuant to the recipient’s compliance with standard contractual clauses, EU-US Privacy Shield (or Swiss-US Privacy Shield, as applicable), or Binding Corporate Rules
- Pursuant to the consent of the individual to whom the personal data pertains
- As otherwise permitted by applicable European requirements.
You may contact us if you want further information on the specific mechanism used by us when transferring your personal data out of Europe.