*PLEASE READ THIS POLICY CAREFULLY BEFORE REGISTERING FOR AN ACCOUNT WITH US*
Date last revised: 18th March 2024
Ethex Investment Club Ltd (Ethex) (we / us / our) are committed to protecting and respecting your personal data and your privacy. We recognise that your personal data is your property and that you have provided it to us for specific purposes.
Unless otherwise required by law, the Information Commissioner’s Office ( ICO) guidance or best practice, or in order to perform our contract with you, we will only process your personal data in the way we tell you or in the way you ask us to, and we will give it back to you at any time.
1. This policy
1.1 This policy, together with the Investor Terms & Conditions, explains how any personal data we collect from you, or that you provide to us, will be processed by us or any processor on our behalf.
1.2 This policy applies to our contract with you. You are therefore advised to read it carefully. Terms used within it shall have the meaning(s) given in the Data Protection Act 2018 as amended by The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (the Act).
1.3 By visiting our website located at https://www.ethex.org.uk (the / our Website), or by registering for an Account with us, you accept and consent to the practices described in this policy.
1.4 Any changes we make to this policy will be posted on this page. You are advised to check back frequently as any changes will be binding on you when you continue to use the Website after the date of the relevant change.
1.5 For more information relating to your rights under this policy, please see section 10.
1.6 If you have any queries relating to this policy, please contact us at help@ethex.org.uk
2. Who we are
2.1 We are Ethex Investment Club Ltd, a company registered in England (company number 07432030) with registered office is at The Old Music Hall, 106-108 Cowley Road, Oxford, OX4 1JE. We operate the Website and we are the data controller for the purposes of the Act. The relevant investee company in connection with your investment will also be a joint controller in respect of your data.
2.2 We are registered with the ICO to process your personal data and our registration number is Z3560212.
2.3 Your data will be processed on our behalf by Share In Ltd, a company registered in Scotland (company number SC408803) with registered office; Suite 2, Ground Floor Orchard Brae House, 30 Queensferry Road, Edinburgh, United Kingdom, EH4 2HS ( ShareIn). ShareIn host our Website and will be the data processor for the purposes of the Act and the Regulation.
2.4 Your data will be held by ShareIn on their secure servers located in the Republic of Ireland, but will be processed by staff who work in the UK.
2.5 We operate on the terms of a written agreement with ShareIn relating to your personal data.
2.6 Any payment transactions you make through our Website will be made through ShareIn, encrypted through SSL technology. ShareIn are a joint controller in respect of any of your personal data provided to them and any of your personal data they hold will be subject to their privacy policy.
3. Your consent
3.1 By registering for an Account and/or otherwise using the Website, you expressly consent to:
3.1.1 provide us and ShareIn with the personal data necessary to allow you to use the Website and make investments through it;
3.1.2 the processing of your personal data by us and/or ShareIn, or those specifically listed third parties, in accordance with this policy; and
3.1.3 the transfer of your personal data to those third parties listed in this policy, for the reasons specified.
3.2 You may withdraw your consent under 3.1 at any time. However, where the withdrawal of your consent prevents us or ShareIn from verifying your identity or otherwise monitoring who you are, you will be unable to use your Account and make investments through our Website OR You may exercise your rights under 3.1 at any time, which includes withdrawing your consent to our processing of your personal data. However, where this withdrawal prevents us from performing our contract with you, we may not be able to provide our goods and services to you.
4. What we collect
4.1 We may collect all or some of the following categories of data from you:
Title Full name Address (including postcode) Date of birth
Email address Nationality Bank account or debit card details IP addresses
Passport (including passport number) Driving licence (including driving licence number) Investor categorisation
4.2 Before you are able to invest, and as part of our Account opening process, you may be required to provide a photo ID document in the form of an in date passport or UK driving licence, and any associated personal data contained on that document will be retained by us or ShareIn (from time to time).
4.3 In addition to the above, we will also provide you with your Account Details, which includes your username which is either created by, or assigned to, you. The Account Details should be remembered by you, but will be stored by us in case you forget them.
5. How we collect your data
The data listed in section 4 is collected in the following ways:
5.1 By you registering for an Account – this is any information you give to us that we request from you when signing-up for an Account to use our Website.
5.2 Information collected – each time you visit our Website, whether through your home, work or a public network, your own computer or mobile device, ShareIn will automatically collect:
5.2.1 technical information – your IP address (used by your computer or device to connect to the internet), and any internet browser type and version details; and
5.2.2 visit-specific information – your URLs, Projects and Properties you viewed or searched for, your clickstream through the Website.
5.3 Received from third parties – we and ShareIn verify your eligibility to make an investment and any payment you wish to make.
6. Cookies
6.1 Our Website will use the cookies listed in section 6.2 (alpha-numeric text files placed on your computer) to:
6.1.1 distinguish you from other users;
6.1.2 optimise your browsing experience;
6.1.3 make necessary improvements to our Website;
6.1.4 recognise and count the number of visitors to our Website and see how they move around the Website during use;
6.1.5 recognise you when you return to our Website; and
6.1.6 record your visit to our website, including any links you may follow.
6.2 The following cookies are set to our Website for the listed purposes:
Cookie | Purpose |
---|---|
ASP.Net_SessionId | Enhances user experience by remembering session history. |
ASPXAUTH | Records users authentication session |
_culture | Assists recognising user’s nationality and language preferences, login, token, username recognition and encoding. |
RequestVerificationToken | Part of a mechanism to protect against cross site scripting attacks |
ARRAffinity | Enhances user browsing experience – part of load balancing setup |
cookie-policy | Tracks presentation of the cookie information advice |
6.3 Our Website additionally uses Google Analytics, a web analytics service provided by Google, LLC (Google), Google Ads, an online advertising service also provided by Google LLC (Google) and Microsoft Clarity (a web analytics service provided by Microsoft). Google Analytics and Microsoft Clarity use analytical, performance or targeting cookies to help analyse how you use the Website and compile reports on your activity for us. Google Ads cookies are used to display custom display adverts to users who have previously visited the Ethex website.
6.4 Any information generated by the cookie about your use of the Website (including your IP address) will be transmitted to, and stored by, Google on servers in the United States and Microsoft on MS Azure cloud servers. Google and Microsoft will use this information for the purpose of evaluating your use of the Website, compiling reports on your activity for us, serving custom display adverts and providing other services relating to website activity and internet usage. Google, and Microsoft may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's or Microsoft's or behalf. Google and Microsoft will not associate your IP address with any other data held by Google or Microsoft.
You can find out more about how Google uses your personal data through this link - https://policies.google.com/technologies/partner-sites.
You can find out more about Microsoft Clarity’s data retention through this link - https://learn.microsoft.com/en-us/clarity/setup-and-installation/data-retention
6.5 You may refuse the use of cookies through our Cookies setting page - https://www.ethex.org.uk/cookies or by selecting the appropriate settings on your browser, however please note that if you do this your ability to use the Website may be restricted. By using the Website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
6.6 Except for essential cookies, all cookies will expire after your session.
7. What we do with your data
7.1 Your data is primarily necessary to verify who you are when accessing your Account and to ensure you meet our eligibility requirements in order to submit an Application and make an investment.
7.2 Additionally, we or ShareIn will use all of your data you provide us to notify you about:
7.2.1 other investment opportunities listed on our Website that are similar to those in which you have invested, or otherwise viewed or enquired about; or
7.2.2 changes to our Website or our services.
7.3 We or ShareIn use any data we collect about you (as a result of your visit to our Website) to:
7.3.1 personalise and improve our services (including the Website and its security);
7.3.2 deal with your inquiries and requests;
7.3.3 administer and monitor traffic and behaviours on our Website for analysis, testing, research, statistical and survey purposes;
7.3.4 ensure that any part of our Website (including any content) is presented in the most effective manner for you and your computer or device, and to make improvements (where necessary); and
7.3.5 keep our Website safe and secure.
7.4 Where we change our services, or any applicable terms and conditions, we will contact you.
7.5 Any data we obtain about you from third parties are used for the purposes of verifying your eligibility to submit an application and to make an investment through our Website, and are acquired only to the extent we are unable to do so as a result of the information you provide to us.
7.6 Once collected, we and/or ShareIn may retain your data for up to six years following the date of your last investment or the date you close your Account (whichever is the later). This is to enable us to refer back to any transactions or records you are involved in (should we be required to do so).
8. How and why we disclose your data
8.1 Subject to the rest of part 8 of this policy, we or ShareIn will only disclose your personal data to the following third parties for the following purposes:
8.1.1 the relevant investee company – in connection with your investment, details of which will be stated on your application;
8.1.2 our approved payment gateway – in order for you to make the payment(s) required as part of your Investment;
8.1.3 one of our approved transaction email providers, SendGrid Inc. - in order for us to be able to send emails to you (NB only your email address is passed to SendGrid);
8.1.4 one of our approved transaction email providers, Intuit (trading as Mailchimp) – in order for us to send emails to you. The information sent to Mailchimp includes your name, email address and information about your use of the Ethex platform. Information about use of the platform is only sent from users who have registered an account with us. If you would prefer this information not to be shared with Mailchimp you can select to not receive marketing information in your Ethex account preferences. If you have not registered an account with us, you can unsubscribe from our marketing emails by clicking the “unsubscribe” link on any email.
8.1.5 one of our approved contact management software providers, Bigin by Zoho – in order to send relevant communications to you. The information stored in Zoho includes your name, email address and information about your use of the Ethex platform. Information about use of the platform is only sent from users who have registered an account with us
Bigin are located in Europe. SendGrid and Mailchimp are located in the United States of America, and as such Personal Data is being sent to (and stored in) the USA. As privacy and data protection laws may be different than those set out in the Act we use standard contractual clauses (SCCs) with those companies to ensure that the transfer of personal data outside of the UK is done so with regard to the same standards as set out in the Act.
8.2 In addition to the transfers contemplated by part 8.1, we or ShareIn may transfer or disclose your personal data to:
8.2.1 comply with any legal obligation (such as where stated at clause 6.5 of the Investor Terms and Conditions);
8.2.2 enforce or apply any part of our Investor Terms and Conditions generally; or
8.2.3 protect our rights or our property, or those of our other Account Holders.
8.3 Any websites which are linked from the Website are outside of our control and not covered by this policy. If you access those websites using the links provided, the website operators may collect information from you which will be used by them in accordance with their own privacy policies (if any). These policies may differ from ours, and we cannot accept any responsibility or liability in respect of these.
9. Security
9.1 We have put in place appropriate technical and organisational measures to help protect your personal information from unauthorised access, use, disclosure, alteration or destruction consistent with applicable Data Protection Laws.
9.2 Each member of staff has unique log-in details and authentication software requires these to access the systems. Staff have access to personal data only for the purposes of performing their roles.
9.3 We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
10. Your rights
10.1 In relation to all of your personal data, you have the following rights to ask us or us or ShareIn (in addition to any rights you may have under the Act):
10.1.1 not to process your personal data for marketing purposes;
10.1.2 to clarify what data we or ShareIn hold about you, how it was obtained, to whom it has been disclosed and for how long it will be stored;
10.1.3 to amend any inaccurate data we or ShareIn hold about you;
10.1.4 to delete any of your data (where you no longer think we or ShareIn need to hold it or you think we or ShareIn have obtained it or processed it without your consent at any time); and
10.1.5 to only process your personal data in limited circumstances or for limited purposes.
10.2 If you wish to exercise any of your rights at any time, please contact us on the details contained at the beginning of this policy in the first instance. We will require you to verify your identity to us before we provide any personal data, and reserve the right to ask you to specify the types of personal data to which your request relates.
10.3 Where you wish to exercise any of your rights, they may be subject to payment of a nominal administration fee (to cover our costs incurred in processing your request) and any clarification we may reasonably require in relation to your request. Such fees may be charged where we consider (acting reasonably) that your request is excessive, unfounded or repetitive.
10.4 Any data provided to you in accordance with your rights will be in a structured and machine-readable form.