Ethic Inc. (“Ethic”, “Company”, “we”, “us” and/or “our”) is committed to protecting your privacy. We have prepared this Privacy Policy to describe to you our practices regarding the personal data (as defined below) we collect from users of our websites, located at http://www.ethic.tech and http://www.ethic.com (the “Sites”), as well as all related websites, applications, networks and other services provided by us an on which a link to this Privacy Policy is displayed (collectively, together with the Sites, our “Services”). This Privacy Policy is incorporated into and is subject to the Ethic Terms of Use found at https://www.ethic.com/legal/terms-of-service and applies whether you are using the Sites to evaluate the Services or for educational purposes or as a Client with an investment portfolio managed or advised by Ethic.
1. Questions; Contacting Ethic; Reporting Violations. If you have any questions or concerns or complaints about our Privacy Policy or our data collection or processing practices, or if you want to report any security violations to us, please contact us at the following address or phone number:
Ethic Inc.
Attn: Legal Department
99 Hudson, 17th Floor, New York, NY 10013
legal@ethic.com
2. A Note About Minors. We do not intentionally gather personal data from visitors who are under the age of 18. If a minor under 18 submits personal data to Ethic and we learn that the personal data is the information of a minor under 18, we will attempt to delete the information as soon as possible. If you believe that we might have any personal data from a minor under 18, please contact us at legal@ethic.com.
3. A Note to Users Outside of the United States. If you are a non-U.S. user of the Services, by visiting the Services and providing us with data, you acknowledge and agree that your personal data may be processed for the purposes identified in the Privacy Policy. In addition, your personal data may be processed in the country in which it was collected and in other countries, including the United States, where laws regarding processing of personal data may be less stringent than the laws in your country. By providing your data, you consent to such transfer.
4. Types of Data We Collect. We collect personal data from you in various ways.
(a) Information You Provide to Us. We collect the personal data you voluntarily provide to us. For example:
We may collect personal data from you, such as your first and last name, phone number, e mail and mailing addresses, professional title, company name, and password when you create an account to log in to our Services (“Account”);
We may collect holdings information provided by you or your advisor;
If you take a survey on one of our Sites, we will collect the answers you provide and may provide them to registered investment advisors so they may market their products and/or services to you;
- Certain services, such as two-factor authentication, may require our collection of your phone number. We may associate that phone number to your mobile device identification information;
- We retain information on your behalf, such as files and messages that you store using your Account;
- If you provide us feedback or contact us via e-mail, we will collect your name and e-mail address, as well as any other content included in the e-mail, in order to send you a reply;
- When you publicly post or share content (such as text, images, photographs, messages, comments or other kind of content) on a publicly accessible area of the Service or with other users of the Services, the information contained in your posting will be stored in our servers and other users will be able to see it. The information that you provide in your profile page (“Profile”) will be visible to others;
- When you post messages on the message boards of our Sites, the information contained in your posting will be stored on our servers and other users will be able to see it;
- We also collect other types of personal data that you provide to us voluntarily, including when you answer questions on one of our surveys to determine what kind of portfolio we might recommend to Clients, your financial and sustainability goals and objectives, other financial information and other information your provide during the onboarding process, and other requested information if you contact us via e-mail regarding support for the Services. We may also share this information with registered investment advisors that we partner with so that they can market their products and services to you; and
- We may also collect personal data at other points in our Services that state that personal data is being collected.
(b) Acting as your Authorized Agent. Ethic offers services where Ethic acts as an agent to retrieve your financial account information, such as your account balances and holdings and transactions, and household information, from financial institutions designated by you. By accessing and using the Services you expressly authorize and direct Ethic, on your behalf, to electronically retrieve your account information maintained by third party financial institutions with which you have a legally binding customer relationship (“Account Information”). Ethic may work with one or more third-party financial service technology providers to access and retrieve your Account Information.
(c) Information Collected via Technology.
- Cookies and Other Information Collected by Automated Means. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and activity occurring on or through the Service. The information that may be collected automatically includes your computer or mobile device operating system type and version number, manufacturer and model, browser type, screen resolution, IP address, the website you visited before browsing to our website, general location information such as city, state or geographic area; and information about your use of and actions on the Service, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and length of access. Our service providers and business partners may collect this type of information over time and across third-party websites and mobile applications. On our webpages, this information is collected using cookies, browser web storage (also known as locally stored objects, or “LSOs”), web beacons, and similar technologies, and our emails may also contain web beacons.
- Analytics Services. In addition to the tracking technologies we place, other companies may set their own cookies or similar tools when you visit our Services. This includes third party analytics services (“Analytics Services”), including but not limited to FullStory, Mixpanel and Google Analytics that we engage to help analyze how users use the Services, as well as third parties that deliver content or offers. We may receive reports based on these parties’ use of these tools on an individual or aggregate basis. We use the information we get from Analytics Services only to improve our Services. The information generated by the Cookies or other technologies about your use of our Services (the “Analytics Information”) is transmitted to the Analytics Services. The Analytics Services use Analytics Information to compile reports on user activity. The Analytics Services may also transfer information to third parties where required to do so by law, or where such third parties process Analytics Information on their behalf. Each Analytics Services’ ability to use and share Analytics Information is restricted by such Analytics Services’ Terms of Use and Privacy Policy. For a full list of Analytics Services we use, please contact us at legal@ethic.com. Please visit the following URLs to learn more about how the Analytics Services we use collect and process data: FullStory https://www.fullstory.com/legal/privacy/; Mixpanel https://mixpanel.com/legal/privacy-overview, and Google Analytics https://policies.google.com/privacy.
(d) Information Collected from You About Others. If you decide to invite a third party to create an Account, we will collect your and the third party’s names and e-mail addresses in order to send an e-mail and follow up with the third party. We rely upon you to obtain whatever consents from the third party that may be required by law to allow us to access and upload the third party’s names and e-mail addresses as required above. You or the third party may contact us at legal@ethic.com to request the removal of this information from our database.
(e) Information Collected from Third Party Companies. We may receive personal and/or anonymous data about you from our third-party partners, including from registered investment advisor databases. These third-party companies may supply us with personal data. We may add this information to the information we have already collected from you via our Services in order to improve the Services we provide.
5. Use of Your Personal Data
We use your personal information for the following purposes and as otherwise described in this Privacy Policy or at the time of collection:
(a) To operate the Service. We use your personal information to:
- provide, operate and improve the Service
- provide information about our products and services
- establish and maintain your user profile on the Service
- communicate with you about the Service, including by sending you announcements, updates, security alerts, and support and administrative messages
- communicate with you about events or contests in which you participate
- understand your needs and interests, and personalize your experience with the Service and our communications
- provide support and maintenance for the Service
- respond to your requests, questions and feedback
(b) For research and development. We analyze use of the Service to analyze and improve the Service and to develop new products and services, including by studying user demographics and use of the Service.
(c) To send you marketing and promotional communications. We may send you Ethic-related marketing communications as permitted by law. You will have the ability to opt-out of our marketing and promotional communications as described in section 8(a) below.
(d) To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
(e) For compliance, fraud prevention, and safety. We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
(f) With your consent. In some cases we may specifically ask for your consent to collect, use or share your personal information, such as when required by law.
(g) To create anonymous, aggregated or de-identified data. We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect. We make personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you. We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including, but not limited to analyze and improve the Service and promote our business.
6. Disclosure of Your personal data. We disclose your personal data as described below and as described elsewhere in this Privacy Policy.
(a) Third Parties Designated by You. When you use the Services, the personal data you provide will be shared with the third party that you designate to receive such information, including other websites and your business associates. For example, registered investment advisors, advisory firms, wealth management and technology providers.
(b) Users. We will share your personal data with other users solely for the purpose of providing the Services. For example, advisor firms on the Services may have access to information regarding their End-Client accounts.
(c) Third Party Service Providers. We may share your personal data with our third-party service providers to: provide you with our Services; to invoice or process payments; to retrieve your Account Information; database management; to conduct quality assurance testing; to facilitate creation of accounts; to provide technical support; to provide mailing services; and/or to provide other services to Ethic.
(d) Brokerage Partners. We may share the information required to become a Client with select brokerage partners solely for the purpose of allowing our brokerage partner to provide services to you.
(e) Affiliates. We may share some or all of your personal data with our parent company, subsidiaries, joint ventures, or other companies under a common control (“Affiliates”), in which case we will require our Affiliates to honor this Privacy Policy.
(f) Corporate Restructuring. We may share some or all of your personal data in connection with or during negotiation of any merger, financing, acquisition or dissolution transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets. In the event of an insolvency, bankruptcy, or receivership, personal data may also be transferred as a business asset. If another company acquires our company, business, or assets, that company will possess the personal data collected by us and will assume the rights and obligations regarding your personal data as described in this Privacy Policy.
(g) Information You Share; Public Profile. When you use our Services, you may choose to post or share certain information with other users. We may display this content on the Services, and once displayed on web pages viewable by other users, that information can be collected and used by others. We cannot control who reads the information you choose to share or what other users may do with the information that you voluntarily post and/or share. In addition, certain information may be displayed in your Profile and on the Services, such as your name, professional title, company name, and photo. You may edit such information by going to your Profile settings. Once you have posted information publicly, while you will still be able to edit and delete it on the Services, you will not be able to edit or delete such information cached, collected, and stored elsewhere by others.
(h) Other Disclosures. Regardless of any choices you make regarding your personal data (as described below), Ethic may disclose personal data if it believes in good faith that such disclosure is necessary (a) in connection with any legal investigation; (b) to comply with relevant laws or to respond to subpoenas or warrants served on Ethic; (c) to protect or defend the rights or property of Ethic or users of the Services; and/or (d) to investigate or assist in preventing any violation or potential violation of the law, this Privacy Policy, or our Terms of Use.
7. Third Party Websites. Our Services may contain links to third party websites. When you click on a link to any other website or location, you will leave our Services and go to another site, and another entity may collect personal data or Anonymous Data from you. We have no control over, do not review, and cannot be responsible for, these outside websites or their content. Please be aware that the terms of this Privacy Policy do not apply to these outside websites or content, or to any collection of your personal data after you click on links to such outside websites. We encourage you to read the privacy policies of every website you visit. The links to third party websites or locations are for your convenience and do not signify our endorsement of such third parties or their products, content or websites.
8. Your Choices Regarding Information. You have several choices regarding the use of information on our Service:
(a) Email Communications. We will periodically send you free newsletters and e-mails that directly promote the use of our Services. When you receive newsletters or promotional communications from us, you may indicate a preference to stop receiving further communications from us and you will have the opportunity to “opt out” by following the unsubscribe instructions provided in the e-mail you receive or by contacting us directly (please see contact information below). Despite your indicated e-mail preferences, we may send you service-related communications, including notices of any updates to our Terms of Use or Privacy Policy.
(b) Cookies. If you decide at any time that you no longer wish to accept Cookies from our Service for any of the purposes described above, then you can instruct your browser, by changing its settings, to stop accepting Cookies or to prompt you before accepting a Cookie from the websites you visit. Consult your browser’s technical information. If you do not accept Cookies, however, you may not be able to use all portions of the Service or all functionality of the Service.
(c) Changing or Deleting Your personal data. All users may review, update, correct or delete the personal data in their user account by contacting us or editing their profile via the Services. If you completely delete all of your personal data, then your user account may become deactivated. We will use commercially reasonable efforts to honor your request. We may retain an archived copy of your records and residual information related to your Account, as well as any data related to your trades, as required by law or for legitimate business purposes.
(d) Declining to Provide personal data. You may decline to provide certain personal data to Ethic. Declining to provide personal data may disqualify you for features of the Services that require certain Personal Data.
(e) Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
9. Security. Ethic takes reasonable steps to protect your personal data from loss, misuse, and unauthorized access, alteration, disclosure, or destruction. No Internet, email, or electronic operating system that enables the transmission of data is ever fully secure or error free so, please take special care in deciding what information you send to us in this manner. In the event of a data breach involving personal data you will be notified as soon as reasonably practicable, along with any supervisory authority as required.
10. Changes to This Privacy Policy. This Privacy Policy is subject to occasional revision, and if we make any material changes in the way we use your personal data, we will notify you by sending you an e-mail to the last e mail address you provided to us and/or by prominently posting notice of the changes on our Services.
11. Your California Privacy Rights
Under California Civil Code section 1798.83, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to us via email at legal@ethic.com. You must put the statement "Your California Privacy Rights" in your request and include your name, street address, city, state, and ZIP code. We are not responsible for notices that are not labeled or sent properly, or do not have complete information.
12. Notice to European Users
The information provided in this “Notice to European Users” section applies only to individuals in Europe.
Personal information. References to “personal data” in this Section 12 of this Privacy Policy are equivalent to “personal data” governed by European data protection legislation.
Controller. Ethic, Inc. is the controller of your personal data covered by this Privacy Policy for purposes of European data protection legislation.
Legal bases for processing. We use your personal data only as permitted by law. Our legal bases for processing the personal data described in this Privacy Policy are described in the bullet points below.
- To operate the service. Legal basis: Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service. If we have not entered into a contract with you, we process your personal data based on our legitimate interest in providing the Service you access and request.
- To administer events and contests, for research and development, to send you marketing communications, to manage our recruiting and process employment applications, for compliance, fraud prevention and safety, to create anonymous data. Legal basis: These activities constitute our legitimate interests. We do not use your personal data for these activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
- To comply with law. Legal basis: Processing is necessary to comply with our legal obligations.
- With your consent. Legal basis: Processing is based on your consent. Where we rely on your consent you have the right to withdraw it any time in the manner indicated when you consent or in the Service.
Use for new purposes. We may use your personal data for reasons not described in this Privacy Policy where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal data for an unrelated purpose, we will notify you and explain the applicable legal basis.
Sensitive personal data. We ask that you not provide us with any sensitive personal data (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Service, or otherwise to us. If you provide us with any sensitive personal data to us when you use the Service, you must consent to our processing and use of such sensitive personal data in accordance with this Privacy Policy. If you do not consent to our processing and use of such sensitive personal data, you must not submit such sensitive personal data through our Service.
Automated Decision-Making and Profiling. We may use automated decision-making and/or profiling in regard to your personal data for some services and products, for example, fraud prevention technology that automatically blocks video uploads. You can request a manual review of the accuracy of an automated decision that you are unhappy with or limit or object to such automated decision-making and/or profiling by contacting us at legal@ethic.com.
Retention
We retain personal data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal data we have collected about you, we will either delete or anonymize it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible. If we anonymize your personal data (so that it can no longer be associated with you), we may use this information indefinitely without further notice to you.
Your rights
European data protection laws give you certain rights regarding your personal data. If you are located within the European Union, you may ask us to take the following actions in relation to your personal data that we hold:
- Access. Provide you with information about our processing of your personal data and give you access to your personal data.
- Correct. Update or correct inaccuracies in your personal data.
- Delete. Delete your personal data.
- Transfer. Transfer a machine-readable copy of your personal data to you or a third party of your choice.
- Restrict. Restrict the processing of your personal data.
- Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal data that impacts your rights.
You may submit these requests by email to legal@ethic.com or our postal address provided above. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal data or our response to your requests regarding your personal data, you may contact us at legal@ethic.com or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.
Cross-Border Data Transfer
If we transfer your personal data out of Europe to a country not deemed by the European Commission to provide an adequate level of personal data protection, the transfer will be performed:
- Pursuant to the recipient’s compliance with standard contractual clauses, EU-US Privacy Shield (or Swiss-US Privacy Shield, as applicable), or Binding Corporate Rules
- Pursuant to the consent of the individual to whom the personal data pertains
- As otherwise permitted by applicable European requirements.
You may contact us if you want further information on the specific mechanism used by us when transferring your personal data out of Europe.