In order to provide our due diligence services via our Products, we gather publicly available information about the companies and related individuals that our clients ask us to due diligence, and then present such information in a due diligence report (the “Report”) to clients who register with us to use such Products.
This Policy describes the ways in which Ethixbase collects and uses information about you when you visit our website at https://ethixbase.com (the ‘Website’) or register for an account (‘Account’) permitting you to use our Products. This Policy also describes how Ethixbase prepares the Report(s) for each client.
If we have collected information about you in order to create a Report, unless you object to the information we have collected about you (which you can do as set out in, and subject to the terms of, this Policy), you agree to us collecting and using such information as set out in this Policy. In addition, by visiting our Website and using our Products you agree to be bound by this Policy in respect of the information collected about you. Ethixbase may change this Policy at any time in which case we shall notify you of any changes to this Policy by noting this on the Website and updating the “last changed” date below. The changes will apply to your use of the Website and/or our Products (as applicable) after we have given notice. If you do not wish to accept the new Policy you should not continue to use the Website and/or our Products (as applicable). If you continue to use the Website and/or our Products (as applicable), or do not object to us continuing to collect your data after the date on which the change comes into effect, your use of the Website and/or our Products (as applicable), or your lack of objection, indicates your agreement to be bound by the new Policy.
This Policy was last changed on 16 March 2018.
Information that we collect about you and how we use it and protect it
1. ICO registration: For the purposes of data protection legislation, Ethixbase is the controller for the processing of your personal data. If you are a UK customer, Ethixbase UK Limited has notified the Information Commissioner’s Office (“ICO”) of its processing of personal data. The notification indicates what data is processed by Ethixbase UK Limited and for what purpose, and to which persons or entities the data will be provided. Click here to consult the notification in the public register of the ICO. Ethixbase’s registration number is ZA261305.
2. The information which is collected by us: Ethixbase collects the following information:
- if you register for e-mail alerts on the Website we will collect your e-mail address and, if you wish to submit such information: (i) your name; (ii) your job title; (iii) your employer name; (iv) your phone number; (v) the country in which your employer is based; and (vi) the industry in which you operate;
- if you use our Products then we collect the information that you provide to us (whether provided directly by you or by you based on information that you have received from a third party and transferred to us) in order for us to be able to carry out our due diligence services. This will include: (i) the full entity name of the company/ies for due diligence purposes; (ii) the country of registration of such company/ies ((i) and (ii) being the “Organisation Data”); (iii) the full name of the associated individuals of the company/ies that you want us to check for due diligence purposes; (iv) the country of residence of the associated individuals of the company/ies that you want us to check for due diligence purposes; and (v) any other information that we request from you in relation to such individuals such as nationality, date of birth and passport number ((iii), (iv) and (v) being the “Individuals Data” and together with the Organisation Data the “Client Provided Data”);
- if you use our Products then we collect any information which you provide to us when creating an Account to use our Products, including (i) your name; (ii) your employer name; (iii) your job title; (iv) your e-mail address and the e-mail addresses of any other contact persons; and (v) your employer’s country of incorporation (“Client Data”);
- if you are an individual listed in any of our Reports, then, in addition to the Individuals Data which is provided by our clients (as detailed in paragraph 2(b) above), we will collect certain information about you in the course of our due diligence searches. This information is obtained from a variety of publicly available sources, including news reports, as well as via our third-party service providers whom we use to assist us in relation to such searches (“Report Data”); and
3. How the information collected about you when you create and use our Products is used: The information about you described in paragraph 2 may be used by Ethixbase as follows:
- if you provide your e-mail address to us under paragraph 2(a), we use your e-mail address to provide our e-mail alerts to you. If you provide the other information listed under paragraph 2(a)(i) to (vi), we use such information to build up a fuller marketing profile for you in order to be able to decide which products and services we consider that you might be interested in. You have the right to opt-out of our use of such data for this marketing purpose at any time by contacting email@example.com. If you want to stop receiving the e-mails at any time you may click “Unsubscribe” in the e-mail itself or contact firstname.lastname@example.org;
- the Client Provided Data listed in paragraph 2(b) is used for us to provide our services to you, namely in order for us to be able to carry out our due diligence research. We will use this information to prepare the Report for you. You can select which type of Report you want us to prepare when asking us to perform such services for the first time;
- the Client Data listed in paragraph 2(c) is used to provide a Report to you. Ethixbase requires your name, job title and e-mail address to provide the Report to you and requires your employer’s name and country of incorporation to undertake certain fraud and security checks in relation to its provision of services to you;
- the Report Data listed in paragraph 2(d) is used to provide the Report to Ethixbase’s clients. It comprises the core content of each Report;
- the Analytical Data listed in paragraph 2(e) enables Ethixbase to undertake administrative tasks in relation to the management of the Website and its Products including to evaluate how our visitors use and navigate our Website and Products, including the number and frequency of visitors to each web page, and the length of their visits as well as to provide technical support and troubleshooting, and to tweak, tune and facilitate the improvement of the customer experience. It’s also used to allow us to personalise the content that you and others see based on personal characteristics or preferences and to target ads to you on another website. You may opt out from receiving targeted advertisements from us by visiting the NAI website opt-out page or the DAA opt-out page or, for EU users, the EDAA opt-out page;
- the Client Provided Data and Client Data may also be used to communicate with you (and the third parties that you have provided us with such data in relation to) in order to deliver compliance related materials that we consider you might be interested in. Where any such communication is received, you have the right to opt-out of us using such data for this marketing purpose at any time by clicking “Unsubscribe” in the e-mail itself or by contacting email@example.com;
- the information in paragraph 2 may also be used by us to allow us to personalise the content that you and others see based on personal characteristics or preferences and to target ads to you on another website. You may optout from receiving targeted advertisements from us by visiting the NAI website opt-out page or the DAA opt-out page or, for EU users, the EDAA opt-out page; and
- the information set out in paragraph 2 is shared with third parties as described in paragraph 5 below.
4. Ground for processing:
- In relation to the information collected as listed in paragraph 2(a): In collecting your e-mail address we rely on the fact that such e-mail address is required to fulfil our contract with you (namely providing you the e-mail alerts requested by you entering your e-mail address). In collecting the other items listed in paragraph 2(a) above, we rely on consent as you have the choice as to whether to provide such items to us or not. You can still receive the marketing e-mails if you only provide your e-mail address but if you choose to provide the additional items of information it allows us to build up a fuller profile in order to be able to decide which product and service e-mails are likely to be of most interest to you.
- In relation to the information collected as listed in paragraphs 2(b) to (e): Ethixbase relies on the legitimate interests processing ground to collect all of the information listed in paragraphs 2(b) to (e). It is in Ethixbase’s legitimate interests to collect such items of personal data listed above because this is necessary in order to provide and improve the due diligence services via its Products and Website. Such due diligence is a legal requirement for many companies and Ethixbase assists in streamlining this process for such clients. In addition, where Ethixbase uses the Client Data and Client Provided Data for marketing purposes, this is also a legitimate interest of Ethixbase which is necessary in order to permit Ethixbase to be able to grow and market its business offering of streamlining due diligence services to interested customers. The items of personal data collected in each instance are not of nature whereby your rights and freedoms as a data subject are outweighed by such data collection because:
- with respect to the Client Provided Data and the Report Data the personal data is already data that is publicly available (being sourced from publicly available sources) and could be found by any individual conducting their own manual search for such data and all Ethixbase does is assimilate this personal data in a more easy-to-read and acceptable format for its clients or use it to market to such entities (subject to compliance with applicable data protection and direct marketing legislation); and
- with respect to the Client Data and Analytical Data, such data is not particularly sensitive data and is used to provide and improve the service of the Report creation as provided by Ethixbase to such client or to market to such clients subject to compliance with applicable data protection and direct marketing legislation.
5. Sharing information with third parties: Ethixbase shall not pass your information to any third party (other than as described in this paragraph). Your information may, subject to Ethixbase’s obligations to comply with applicable data protection legislation, be shared with the following third parties:
- the Client Provided Data, Report Data, Client Data and Analytical Data with its hosting provider for web hosting;
- the Client Data and Analytical Data with its CRM provider for CRM management;
- the Client Data and Analytical Data with its marketing automation provider for marketing automation and tracking;
- the Client Data and (subject to compliance with applicable data protection and direct marketing legislation) the Client Provided Data with its marketing provider for sending out a daily newsletter to subscribers;
- the Client Data with its accounting provider for accounting purposes;
- the Analytical Data with GoogleAnalytics for tracking website activities;
- the Client Provided Data with FormStack for creating forms that third parties complete and submit;
- having taken precautions to maintain the security of such information, Ethixbase may share all information collected under paragraph 2 with its regulator (the ICO);
- in anonymised form, Ethixbase may share all information collected under paragraph 2 with:
- Its online advertising partners to serve adverts that you may see on the Website and to ensure that such ads are relevant to you;
- any third party, in relation to the sale of some or all Ethixbase’s business, or its assets, or as part of any business restructuring or reorganisation. Ethixbase will take steps with the aim of ensuring that your rights continue to be protected if your personal data is transferred in accordance with this paragraph;
- data aggregators and platform providers as part of an analysis of user metrics or sales performance; or
- law enforcement agencies in compliance with law enforcement.
6. Security: Ethixbase has implemented technology and policies to safeguard your privacy from unauthorised access and improper use, including limited access servers and associated security measures.
7. Storage and Data Retention: We store your personal data in the EEA and other countries outside the EEA, including the USA. Where we transfer your personal data outside the EEA we take steps to ensure the adequacy of such transfer, such as the EU/US Privacy Shield and the use of model clauses. We retain your personal data for as long as you use our Products or are identified by us within a Report, and for one year thereafter.
8. Links to third-party websites and third-party adverts: Ethixbase is not responsible for the privacy policies and practices of other sites even if you access them using links from the Website. You should check the policy of each site you visit and contact its owner or operator if you have any concerns or questions. In addition, if you link to the Website from a third party site, Ethixbase is not responsible for the privacy policies and practices of the owners or operators of that third party site and recommends that you check the policy of that third party site and contact its owner or operator if you have any concerns or questions.
Contact with Ethixbase
9. Information Ethixbase collects and uses if you contact us or make complaints: When Ethixbase receives complaints by email it files any relevant document and may retain details of the complainant and other individuals identified in the complaint. Ethixbase will only use this information to process the complaint and to check on Ethixbase’s Website and staff. Ethixbase shall retain information in relation to a complaint for a maximum of 6 years after its closure, in a secure environment and access to it will be restricted on a ‘need to know’ basis.
Cookies and Similar Technologies
- Disabling Cookies: The use of the cookies described above improves the functionality of the Website and your experience of using them. If you do not want these cookies to be served on your device, you are able to disable them by changing the settings on your browser, or on your device. Please note that if you do decide to disable cookies you may not be able to access some services on the Website, and some of the features of the Website or our Products may not function properly. By continuing to use the Website or our Products, you consent to the relevant cookies being set on your device.
- More information: To find out more about how cookies work, how to manage and delete them and to see which ones have been set please visit aboutcookies.org or www.allaboutcookies.org.
|Cookie Type||Purpose||Further Information|
|Session Cookie||Ethixbase uses session cookies to help with the navigation of a user on a website and provide the ability for a user to traverse and navigate the website without losing data or a selection made from a previous page.||This cookie expires when a browser is closed or after 15 mins of inactivity|
|Permanent Cookie||Ethixbase uses permanent cookies to remember the user’s login and password information if they opt to from the login page. This allows the users not to re-enter their login information each time they visit the website.||Although the cookie is persistent, it expires after a period of 3 months|
|Google Analytics Third Party Cookie||Ethixbase uses Google Analytics cookies to track and report on website traffic. This cookie collects information in an anonymous form on website usage such as number of visitors on the website, frequency and volume of users at any given time which Ethixbase use in turn to help improve its services.|
|AutoPilot Third Party Cookie||Ethixbase uses AutoPilot session cookies to collect information on users’ behaviour while navigating our website. It tracks when users access the site, pages visited and succeeding transactions of users to identify possible ways to improve the user experience of its products.||This is a session cookie and does not store any personally identifiable information.|
Your rights and our contact details
11. Exercising your rights: You can contact us using the details set out in paragraph 12 below if you wish to: (i) access a copy of the personal data that we hold about you; (ii) correct any items of personal data that we hold about you; and/or (iii) have any items of personal data that we hold about you erased or object to our processing of such items of personal data. Please note that we may not be able to erase the personal data that we hold about you if we are required to retain it for other legal reasons – for example if you are subject to a particular sanction requirement we will be obliged to report this to our clients.
12. Ethixbase Details and complaints: If at any time you would like to contact Ethixbase about your views on this Policy or any inquiry relating to your personal information, you can do so by sending an e-mail to us at firstname.lastname@example.org. You have the right to make a complaint to the ICO by contacting them at any time or write to us at email@example.com.