Togetherise Privacy Policy
Togetherise (“we,” “us,” or “our”) is committed to protecting your privacy and ensuring that your personal information is handled securely and responsibly. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal information when you use our platform (the “Service”). By using the Service, you agree to the practices described in this Privacy Policy.
This Privacy Policy is informed by the Personal Information Protection and Electronic Documents Act (PIPEDA), Ontario’s Personal Health Information Protection Act (PHIPA), and the General Data Protection Regulation (GDPR).
If you have any questions about this Privacy Policy, please contact us at [email protected].
1. Accountability
We are responsible for all personal information under our control, including information transferred to third-party service providers. Togetherise has appointed a Chief Compliance Officer (CCO) who is accountable for ensuring compliance with this Privacy Policy. Any inquiries or concerns regarding the use of personal information, including information shared with third parties, should be directed to the CCO at [email protected].
2. Information We Collect
User-Provided Data :
We collect personal information that you provide to us when you register for the Service, such as your name, email address, mailing address, phone number, date of birth, financial information, and any other details necessary for providing our services. This information may be collected through various means, including account registration, investment activities, and communications with us.
Automatic Data Collection :
We collect information automatically when you use our Service. This includes your IP address, browser type, device information, browsing activity, and other technical data that help us improve the functionality and security of our platform.
Cookies and Similar Technologies :
We use cookies, clear gifs (web beacons), and log files to enhance your experience on our platform. Cookies help us remember your preferences, track usage patterns, and improve our services. You can manage your cookie preferences through your browser settings, but disabling cookies may affect your ability to use certain features of the Service.
Cookies :
When you visit the Service, we may send one or more cookies – a small text file containing a string of alphanumeric characters – to your computer that uniquely identifies your browser and enhances your navigation through the Site. We may use both session cookies (temporary and disappear after you close your browser) and persistent cookies (remain on your hard drive after you close your browser). Persistent cookies can be removed by following your web browser’s directions.
Clear Gifs :
We may employ clear gifs (web beacons) to track usage patterns and monitor the effectiveness of our services and marketing efforts. Clear gifs in HTML-based emails help us track which emails are opened by recipients.
Biometric Data :
We may use biometric data, such as facial recognition or fingerprint scanning, to verify your identity. This data is collected and processed in accordance with applicable laws and is not disclosed to unauthorized third parties.
3. Purpose of Collection and Use of Information
Togetherise collects and uses your personal information for the following purposes:
Provision of Services :
To create and manage your account, process transactions, and provide you with access to the features and functionalities of the Service.
Compliance with Legal Obligations :
To comply with applicable laws and regulations, including securities laws, anti-money laundering (AML) regulations, and know-your-client (KYC) requirements.
Marketing and Communications :
To send you newsletters, promotional offers, and other marketing materials that may be of interest to you. You may opt out of marketing communications at any time.
Improvement of Services :
To analyze usage patterns, diagnose technical issues, and improve the performance and security of our platform.
Fraud Prevention and Risk Management :
To protect against fraud, unauthorized access, and other risks to our users and platform.
4. Consents
Your knowledge and consent are required for the collection, use, or disclosure of your personal information. By using the Service, you consent to the collection and processing of your personal information as described in this Privacy Policy. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. However, withdrawing consent may limit your ability to use certain features of the Service.
5. Limiting Collection
We collect only the personal information necessary to fulfill the purposes identified in this Privacy Policy. Personal information is collected by fair and lawful means, and we do not collect information indiscriminately.
6. Limiting Use, Disclosure, and Retention
Togetherise will not use or disclose your personal information for purposes other than those for which it was collected, except with your consent or as required by law. We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations.
Personal information related to investment activities will be retained for a minimum of seven years, as required by Canadian securities laws. After this period, you may request the deletion of your data, provided it is not required for ongoing legal or regulatory purposes.
7. Accuracy of Information
We make every effort to ensure that your personal information is accurate, complete, and up-to-date. You are responsible for notifying us of any changes to your personal information. If you believe that the information we hold about you is inaccurate or incomplete, you may request a correction by contacting us at [email protected].
8. Safeguards
We implement appropriate physical, organizational, and technological safeguards to protect your personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification. These safeguards include, but are not limited to:
Physical Security :
Secured office environments, restricted access to sensitive areas, and secure storage of physical records.
Organizational Measures :
Access controls based on a “need-to-know” basis and regular training for employees on privacy and security practices.
Technological Measures :
Password protection, encryption, firewalls, and intrusion detection systems to protect electronic data.
9. Cybersecurity and Data Protection
As a fully digital platform, Togetherise relies on advanced cybersecurity measures to protect your personal information. We ensure that our systems and third-party providers comply with industry standards, including:
Encryption :
Use of Transport Layer Security (TLS) and Secure Socket Layer (SSL) protocols to secure data transmission.
Data Backups :
Regular, redundant backups of data stored in secure locations separate from the main server.
Monitoring and Intrusion Detection :
Continuous monitoring of network activity for unauthorized access or anomalies.
Disaster Recovery :
High availability and disaster recovery plans to ensure minimal downtime in case of a system failure.
Togetherise requires all its partners providing e-services to comply with the following standards:
Advanced Encryption Systems (AES) with data block transfer standards of 128, 192, or 256-bit size.
General Data Protection Rules (GDPR) compliance.
Payment Card Industry Data Security Standard (PCI DSS) compliance, if applicable.
EU-US Privacy Shield or Swiss-US Privacy Shield compliance.
ISO/IEC 27001 and/or 27018 compliance.
SOC 1, 2, or 3 compliance.
10. Disclosure of Information
We may disclose your personal information to third parties for the following purposes:
Service Providers :
To third-party providers who assist us in delivering our services, such as payment processors, identification verification services, and marketing platforms.
Legal Obligations :
To comply with legal or regulatory requirements, such as responding to a subpoena or court order.
Business Transactions :
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of the transaction.
We ensure that all third-party service providers adhere to strict privacy and security standards consistent with our own.
11. Access to Information
You have the right to request access to your personal information under our control. Upon request, we will inform you of the existence, use, and disclosure of your personal information and provide access to that information. You may also request corrections to your personal information if it is inaccurate or incomplete.
Requests for access or corrections should be made in writing to [email protected]. We will respond to your request within 30 business days.
12. Breach of Privacy
In the event of a breach of your personal information, Togetherise will promptly notify you and take all necessary steps to mitigate the impact of the breach. We will investigate the cause of the breach and implement measures to prevent future occurrences. Notifications will be provided in accordance with legal requirements.
13. International Data Transfers
Your personal information may be stored and processed in countries outside of Canada where Togetherise or its service providers operate. We take appropriate measures to ensure that your personal information is protected in accordance with this Privacy Policy and applicable laws, regardless of where it is processed.
14. Your Rights
You have the right to:
Access :
Request access to your personal information.
Correction :
Request corrections to any inaccuracies in your personal information.
Deletion :
Request the deletion of your personal information, subject to legal or contractual obligations.
Restriction :
Request restrictions on the processing of your personal information.
Portability :
Request the transfer of your personal information to another service provider.
To exercise any of these rights, please contact us at [email protected].
15. Links to Other Websites
The Togetherise platform may contain links to third-party websites or resources. These third-party sites are not under Togetherise’s control, and this Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party websites you visit. Togetherise is not responsible for the content, privacy practices, or security of any linked third-party websites.
16. Notification Procedures
It is our policy to provide notifications, whether required by law or for other business-related purposes, via email, SMS, written notice, or through a conspicuous posting on our website, as determined by Togetherise at our discretion. You may opt out of certain means of notification as described in this Privacy Policy.
17. Changes to This Privacy Policy
Togetherise may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the updated policy on our website and, where required, by sending you an email. Your continued use of the Service after any changes are made indicates your acceptance of the updated Privacy Policy.
18. Governing Law
This Privacy Policy is governed by the laws of Ontario, Canada. Any disputes arising under this Privacy Policy shall be resolved exclusively by the provincial or federal courts located in Toronto, Ontario.
19. Contact Information
If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact our Chief Compliance Officer at [email protected].
Last updated: 2024-08-15