Last updated and approved by the Vestd Board: May 2018
Vestd Limited (“we”, “our”, “us”) is committed to protecting and respecting your privacy. We aim at all times to ensure that we only capture data from you that is required for us to carry out your requirements as expressed by you to us through the Vestd websites, which comprise our platforms, app.vestd.com (the “Platform”) and our marketing sites, vestd.com, (the “Marketing Site”) .
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the Data Protection Act 1998 (the “Act”), Vestd Limited is the data controller and processor. We are registered with the Information Commissioner’s Office with Registration Number: A8068490.
Vestd Ltd has a Data Protection Officer (DPO) who can be contacted at email@example.com.
We collect information about you, your Officers, and your Shareholders:
- that you provide when filling in forms on this Website. This includes information which you provide when creating a profile in order to become a registered member of the Vestd platform;
- that you provide in your interactions with us or with other Vestd members through the Vestd Platform or Vestd Marketing Site;
- information you post or upload to the Platform or Marketing Site or information you transmit when communicating with other registered users through the interactive features of the Platform;
- if you contact us by phone, email or otherwise, we may keep a record of that correspondence;
- when you visit this Platform or Marketing Site (see also under Cookies below);
- that you provide for the purpose of our carrying out identity and anti-money laundering checks on you, your Officers or your Members. These checks will only be carried out if you choose to register as a Vestd member and are described in more detail in the Company or Participant Terms which you will enter into with us in order to become a Vestd member.
We are also working closely with third parties (including, for example, sub-contractors in technical services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them.
We may also automatically collect other identifiable information each time you visit this Platform or Marketing Site, including:
- technical information, including the Internet protocol address used to connect your computer to the Internet, browser type and version, device type and screen size.
- information about your visit, including the full Uniform Resource Locators (URL), page response times, errors, and length of visits to certain pages.
USE OF YOUR INFORMATION
We use your information to provide our service to you and to support your relationship with us and, if you agree, to send you information we think may be of interest to you. For example, we may send you information regarding the technical functionality of the Platform, or respond to a request for a demonstration from the Marketing Site.
For users of the Platform:
- We will not send any information to your Officers or Shareholders unless it has been explicitly instructed by you as part of the Platform operation.
- We use your information for the purpose of our carrying out identity and anti-money laundering checks on you and to verify your eligibility to use the Platform and the services offered by the Platform.
- We use your collected information to personalise your repeat visits and to ensure that content from this Platform is presented in the most effective manner for you and your device.
- We use information collected from you to administer this Website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.
- We may combine information we receive from other sources with information you give to us and information we collect about you. We may use this information and the combined information for the purposes set out above (depending on the types of information we receive).
- We may use your information to send you information about products, services, promotions and events which we think may be of interest to you.
- We will keep your information confidential and will not disclose it to any 3rd parties except for the specific circumstances laid out below or unless with your prior written consent.
For users of the Marketing Site:
- We will use your information only to respond to your direct queries.
- Any subsequent provision of information or notifications about Vestd will be done on a strictly managed “sign up only” basis.
- At any time every user of the Marketing site will be able to Unsubscribe from this.
DISCLOSURE OF YOUR INFORMATION
We may disclose your personal information to any member of our corporate group.
In certain limited situations, we may also disclose your personal information to third parties:
- if we sell or buy any business or assets, in which case we may disclose your personal information to the prospective seller or buyer of such business or assets;
- if Vestd Limited or substantially all of its assets are acquired by a third party, in which case personal information held by it about its users and customers will be one of the transferred assets;
We have assessed that the following are the most material risks to the platform’s data security, and also have identified the associated mitigation measures.
Vestd will implement and maintain processes and technical solutions appropriate to protect and keep your data secure. These include organisational controls to restrict access to data to only those who need it as well as technical restrictions to prevent unauthorised access to your data.
If we become aware of a data breach we will endeavor to notify affected customers as soon as possible but not longer than 72 hours of becoming aware of the breach or data loss. We will provide details and updates as appropriate.
Where you have a password for the Platform which enables you to access your account you are responsible for keeping that password confidential and the password should not be shared with anyone.
The Platform contains a dynamically generated personal pin number for each user, such that we can verify the identity of any individual who is seeking to act on behalf of a company or user.
All personal information you provide to us is stored on secure servers. Some of these servers may be located outside of the European Economic Area (EEA). In respect of any transfer of your personal information outside the EEA, we are responsible for ensuring that an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data is ensured in that country.
We will store your data for as long as is necessary to serve you as a customer and fulfill our requirements under law.
If you leave Vestd some data may need to be retained for compliance and reporting reasons but we endeavor to remove sensitive and unnecessary details after 48 hours.
Some actions that are carried out on the Platform that impact your Company will be communicated to Companies House, this data will be entered into a permanent record. We will notify you before these actions are carried out.
Company and personal data will also be retained in backups that are taken. If data is ever recovered from these, deletion requests will be applied to this recovered data.
If you are not a customer your details will be held for as long as we are fulfilling your initial contact request. You can withdraw your consent and unsubscribe from communications at any point. Your details will be retained for 6 months after our last contact. This is so that we have continuity of information, should you contact us again in that period.
We do not directly store Vestd members’ credit card details.
A cookie records information relating to your internet activity (such as whether you have visited the sites before). This information is used to track visitor use of our sites and to compile statistical reports on site activity. The cookies we use and those of our chosen 3rd parties also allow us to identify you as you move around the site and when you return.
LINKS TO OTHER WEBSITES
You have the right to revoke your consent to use your details for marketing purposes at any point. You can exercise the right at any time by contacting us at firstname.lastname@example.org.
ACCESS TO INFORMATION
The Act gives you rights to access information held about you. Your right of access can be exercised in accordance with the Act.
RIGHT TO BE FORGOTTEN
If you wish to remove your personal and your company data from the Platform you should contact us at email@example.com, this process will result in your no longer being a Vestd customer.
Any changes we may make to our Privacy and Cookies Policy in the future will be posted on this page and, where appropriate, notified to you by email.