- Collection of Personal Data
We may collect nonpublic personal information and other personal information about you, including information that can help us directly or indirectly identify you (“personal data”).
We may collect certain categories of personal data from or about you, including:
- identifiers and similar information, such as name, address, email address, telephone number, date of birth and birth place, social security number, tax identification number, passport details, driver’s license details and other national identity documentation details, online identifiers or other similar identifiers;
- personal details, such as gender, national origin, or marital status;
- commercial information, including records of products or services purchased, obtained, or considered, or other transaction histories or tendencies, including funds in which you are invested, investments considered, risk tolerance and investment activity;
- financial information, such as bank account details, credit card details, account balances, wire instructions, tax status, income, assets, and source of wealth;
- professional or employment-related information, such as education information, investment experience, occupation, compensation, employer, title, employment history, investment experience;
- certain information that may qualify as “special category” data under the GDPR, such as data revealing race or ethnical origin, political opinions, religious or philosophical beliefs, trade union membership, health or sexual orientation;
- internet or other electronic network activity information, including interactions with the Site or use of certain online tools; and
- audio, electronic, visual, or similar information.
- Sources of Personal Data
We may collect personal data directly from you and/or your intermediaries through sources such as: (i) account applications, subscription agreements, and other forms or related documentation; (ii) written, electronic, or verbal correspondence with us or our service providers; (iii) investor transactions; (iv) an investor’s brokerage or financial advisory firm, financial advisor, or consultant; and/or (v) from information captured on applicable websites, fund data rooms and/or investor reporting portals (as applicable).
We may also collect personal data from different sources, such as: (i) our service providers; (ii) public websites or other publicly accessible directories and sources, including bankruptcy registers, tax authorities, governmental agencies and departments, and regulatory authorities; and/or (iii) from credit reporting agencies, sanctions screening databases, or from sources designed to detect and prevent fraud.
In certain circumstances, we may be provided with your personal data in the context of our operations, including investment due diligence.
- Purposes for Collection and Use of Personal Data
We may collect, use or process personal data for business or commercial purposes, such as:
- performing services on behalf of a fund, including fulfilling your requests, maintaining or servicing accounts, providing investor relations service, processing subscriptions, withdrawals and redemptions (as applicable), verifying information, processing payments, or providing similar services;
- communicating with you;
- performing our contractual and regulatory obligations to a subscriber to a fund, including providing updates on a fund’s performance, providing tax reporting and other operational matters;
- detecting security incidents and protecting against malicious, deceptive, fraudulent, or illegal activity, including preventing fraud and conducting “Know Your Client,” anti-money laundering, terrorist financing, and conflict checks;
- enabling or effecting commercial transactions;
- where permitted by applicable law, providing you with marketing or promotional materials;
- establishing, exercising or defending legal claims and in order to protect and enforce our (or another person’s) rights, property, or safety, or to assist others to do the same;
- complying with legal or regulatory requirements;
- administering and improving our Site; and
- internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.
We may from time to time control or process personal data for the purposes of operating our business, including in respect of marketing and advertising. Any person who does not wish their personal data to be processed for marketing purposes may opt out of such processing by contacting us as set out in Section 12 below.
We will only use personal data for the purposes that it has been collected for, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose of the control or processing. Any person requiring information with respect to any additional purpose for which personal data may be controlled or processed may obtain such information by contacting us as set out in Section 12 below. If we need to control or process personal data for an unrelated purpose, we will use its reasonable endeavors to notify affected persons and to explain the basis on which we are permitted to undertake the same.
We may be legally obliged to process certain personal data in order to be able to perform services and business operations or to comply with contractual requirements. If you choose not to provide us with the necessary personal data or to restrict us from processing personal data, we may not be able to meet our obligations or deliver the products or services requested. This may lead to cancellation of contracts; if this is the case, we will endeavor to contact you to discuss this.
- Disclosure of Personal Data
We may share personal data with certain third parties for the purposes set out above, including as follows:
- We share your personal data with our service providers to perform the functions for which we engage them. For example, we may share your personal data with professional service providers such as banks, auditors, law firms, tax advisors, consultants and other third parties. We may also use third parties to host the Site or assist us in providing functionality on the Site, provide data analysis and research as regards the Site, to send out email updates about the Site or remove repetitive information from our user lists.
- We may share your personal data with regulatory, legal and tax authorities, including for example to respond to a subpoena, regulation, binding order of a data protection agency, legal process, governmental request or other legal or regulatory process. We may also share personal information as required to pursue available remedies or limit damages we may sustain. We also may share your personal data with third parties (including, but not limited to, governmental organizations and self-regulatory organizations) to enforce our rights, protect our property or protect the rights, property or safety of others, to prevent fraud, unauthorized transactions or liability; or as needed to support external auditing, compliance and corporate governance functions.
- We may transfer information, including your personal data, in connection with a change of ownership or control by or of us or any affiliated entity (in each case whether in whole or in part) and where we sell or transfer all or a portion of our business or assets (including in the event of a reorganization, dissolution or liquidation)
Newmarket does not share your personal information with third parties for those third parties’ marketing purposes.
- Security and Retention of Personal Data
Newmarket uses reasonable security measures designed to prevent unauthorized intrusion to the Site and to protect your personal data from unauthorized access, alteration, acquisition or misuse. We will take reasonable steps to use technical, administrative, organizational and physical security measures appropriate to the nature of the personal data we are processing and that comply with applicable laws to protect personal data against unauthorized access and exfiltration, acquisition, theft, or disclosure. We generally restrict access to personal data to those employees and agents who have been advised as to the proper handling of such information and who need to know such data to provide services to clients. Given the nature of information security, there is no guarantee that such safeguards will always be successful.
How long we keep your personal data will vary depending on the type of personal data and our reasons for collecting it. The retention period will be determined by various criteria, including the purposes for which we are using it (as it will need to be kept for as long as is necessary for any of those purposes) and our legal obligations (as laws or regulations may set a minimum period for which we have to keep your personal data). In general, we will retain your personal data for as long as we require it to perform our contractual rights and obligations or for periods required by our legal and regulatory obligations.
- Additional Information for EEA and UK Data Subjects
- Legal Basis
As described above in Sections 2 and 4, we process personal data for various purposes. Our lawful bases for processing such personal data include:
- where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;
- to comply with certain legal and regulatory requirements;
- depending on the circumstances, we may need to process your personal data for the performance of a contract to which you are a party, or related pre-contractual steps; and
- with your consent, as required by the GDPR.
- Rights Applicable to Certain EEA or UK Data Subjects
Under the GDPR and any other applicable EU or UK data privacy laws, certain data subjects have a right to: (i) request access to and rectification of your personal data; (ii) correct personal data that we hold where it is incomplete or inaccurate; (iii) restrict the processing of your personal data in certain circumstances; (iv) object to the processing of your personal data in certain circumstances, including where we process personal data for direct marketing purposes or where we have processed such data on the basis of our legitimate interests; (v) request that we erase your personal data under certain circumstances; (vi) ask for a copy of your personal data to be provided to you, or to a third party, in a digital form; (vii) withdraw your consent to the processing of your personal data (where applicable); and (viii) lodge a complaint about the processing of your personal data with your local data protection authority. We particularly appreciate it when you make your question, problem or complaint known. Please contact us as set out in Section 12 below so we can try to find a suitable solution. If you wish to lodge a complaint, the UK data protection authority for example is the Information Commissioner. (You can contact the Information Commissioner at: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone: +44 (0)303 123 1113; email: firstname.lastname@example.org).
- How to Exercise Your Rights Under the GDPR
If you wish to exercise any of these rights as an EEA or UK data subject, you should contact us as set out in Section 12below.
- Transfers of Personal Data Outside the EEA or the UK
Our activities and the jurisdictions in which we are established are such that it may be necessary for personal data that we obtain from you to be transferred and/or processed outside of the EEA or the UK, chiefly but not limited to the United States. Personal data may be accessible by employees and other persons working on our behalf, located outside of the EEA or the UK, including to certain service providers (including but not limited to technical service providers and electronic data storage providers) who may process the information you give us. In circumstances where we transfer personal data outside the EEA or the UK, we will seek to ensure a similar degree of protection is afforded to it by ensuring that, where possible, personal data is generally transferred only to persons in countries outside the EEA or the UK in one of the following circumstances:
- to persons and undertakings in countries that have been deemed to provide an adequate level of protection for personal data by the European Commission or the relevant Secretary of State in the United Kingdom, as applicable (an “adequacy decision”);
- to persons and undertakings to whom the transfer of such personal data is made pursuant to a contract that is compliant with the model contracts for the transfer of personal data to third countries from time to time approved by the European Commission or in the form of the international data transfer agreement adopted by the Information Commissioner’s Office and the UK Parliament or an equivalent or replacement agreement (the IDTA), as applicable, and as supplemented where and if required;
- to persons and undertakings outside of the EU or the UK pursuant to other appropriate safeguards for the transfer of personal data; and
- only on one of the conditions allowed under the GDPR in the absence of an adequacy decision or appropriate safeguards.
You can contact us through the information provided in Section 12 below for further information on specific mechanisms we utilize for transferring personal data outside the EEA or the UK and the countries to which such transfer may be made (which may include, but are not limited to, the United States).
- Cookies and Similar Technologies
Our Site does not currently take any action when it receives a Do Not Track request. Do Not Track is a privacy preference that you can set in your web browser to indicate that you do not want certain information about your webpage visits collected across websites when you have not interacted with that service on the page. For details, including how to turn on Do Not Track, visit www.donottrack.us.
- Links to External Websites
- How to Contact Us