EEA Privacy Disclosures

These privacy disclosures (the “Disclosures”) provide information about the collection, use, processing and sharing of data about individuals located in the European Union, Iceland, Liechtenstein or Norway (the “European Economic Area” or “EEA”).

These Disclosures also provide information about the collection, use, processing and sharing of data about individuals located in the United Kingdom, which has left the European Union but has adopted legislation substantially similar to the GDPR.  With respect to individuals in the UK, references to the GDPR in these Disclosures are to be read as referring to the UK’s similar legislation, the Data Protection Act 2018.

In these Disclosures:

    • GDPR means the European Union’s General Data Protection Regulation;
    • Personal Data means information relating to an identified or identifiable individual; an identifiable individual is one who can be identified, directly or indirectly, by use of any identifier or factor specific to that individual; and
    • GDPR Processing Activities means the collection, use, processing or sharing of Personal Data when those activities are within the scope of the GDPR.

These Disclosures apply only to the use of Personal Data in GDPR Processing Activities. In these Disclosures the words “we,” “us” or “our” refer to Financial Health Network Entities. These Disclosures apply to GDPR Processing Activities by any means, including hardcopy (such as paper applications or forms) and electronic means (such as websites and mobile applications).

How We Collect and Use Personal Data

We collect several categories of Personal Data in circumstances that may involve GDPR Processing Activities, including data you provide, data collected automatically (potentially including location data), and data we obtain from third party sources.

We use the Personal Data that we collect to:

    • Create and maintain your account;
    • Process, fulfill, and follow-up on your attendance at events or conferences, including any EMERGE events;
    • Process your account registration, for EMERGE and Member events;
    • Answer your questions;
    • Send you newsletters, updates, and other communications that you have requested; and
    • Send you information about our services and resources.

As described in more detail below, we rely on a number of legal bases to lawfully process your Personal Data.

The ways in which we collect and use your data vary depending on the relationship between you and us. The following sections of these Disclosures describe in more detail how we collect and use Personal Data in various circumstances that may involve GDPR Processing Activities.

Please note that, depending on the situation, some of the processing of Personal Data we do in the various circumstances described below may not fall within the scope of the GDPR.

1. Personal Data We Collect

Websites and Mobile Applications
As is true of most digital platforms, we obtain certain data automatically when you use one of our websites or mobile applications, such as your IP address, browser type and device type. Certain web-forms also collect Personal Data you provide, for example when you enter data into form fields, such as for the purpose of registration. If we also process data through our websites or mobile applications for one of the activities described further below, those descriptions will provide additional information about how those data are collected and used. We and our third-party vendors use this Personal Data for the primary purposes of conducting analytics, improving our websites, responding to your requests and providing you with relevant information.

2. Personal Data We Obtain from Third Party Sources

As part of our GDPR Processing Activities, we may obtain certain Personal Data about you from third party sources, which we may use for the purposes and in the ways described in “How We Collect and Use Personal Data” above and in “Additional Uses of Personal Data” below. In some cases, we may obtain your consent for additional uses.

Partners and Service Providers
We use partners and service providers to provide services for us. Some of these partners have access to Personal Data about you that we may not otherwise have (for example, when you sign up directly with that provider) and may share some or all these data with us.

3. Additional Uses of Personal Data

In addition to the uses described above, including under “How We Collect and Use Information” and “Personal Data We Obtain from Third Party Sources,” we may use your Personal Data for the following purposes. These additional uses may under certain circumstances be based on your consent, or may be necessary to fulfill our contractual commitments to you, for legal compliance, or to serve our legitimate interest in the following activities:

    •  Conducting our operations and administering educational offerings;
    • Responding to your requests for research assistance;
    • Processing and responding to your requests or inquiries of any other kind;
    • Providing you with newsletters, articles, service alerts or announcements, event invitations, and other information that we believe may be of interest to you;
    • Conducting research, surveys and similar inquiries to help us understand trends and needs of our Members and customers;
    • Performing marketing, promotions and advertising, either directly or through third-parties. These activities may include interest-based advertising, targeted advertising and online behavioral advertising in order to increase the likelihood that the content will be of interest to you;
    • Preventing, investigating, taking action regarding or providing notice of fraud, unlawful or criminal activity, other misconduct, security or technical issues, or unauthorized access to or use of Personal Data, our website or data systems; or
    • Responding to subpoenas, court orders, or other legal process; enforcing our agreements; protecting the health, safety, rights or property of you, us or others; and meeting legal obligations.
4. Legitimate Interests

In addition to interests otherwise described in these Disclosures, we rely on other legitimate interests in using and sharing your Personal Data. These interests include:

    • Providing, improving and customizing our educational offerings;
    • Administering our operations;
    • Furthering research and understanding in fields of academic study;
    • Offering attendance to events and opportunities to participate;
    • Understanding how our online platforms are being used;
    • Exploring ways to develop and grow our operations;
    • Cybersecurity;
    • Enhancing protection against fraud, spam, harassment, intellectual property infringement, crime and security risks; and
    • Meeting our obligations and enforcing our legal rights.
5. Data Retention

We will retain your Personal Data for as long as is necessary for the purposes set out in these Disclosures and for as long as is required under applicable law or is needed to resolve disputes or protect our legal rights or otherwise to comply with legal obligations.  Consistent with the foregoing guidance, some data may be retained indefinitely.

Where we are processing Personal Data based on your consent, we generally will retain the information for the period of time necessary to carry out the processing activities to which you consented, subject to your right, under certain circumstances, to have certain of your Personal Data erased (see “Your Rights” below).

Where we are processing Personal Data based on contract, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship.

Where we are processing Personal Data based on the public interest, we generally retain the information for the period of time that continues to serve that underlying interest.

 Where we are processing Personal Data based on our legitimate interests, we generally will retain the data for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of the data subjects.  In some cases, where Personal Data was primarily processed and retained on the basis of consent, contract, the public interest, or other bases described in these Disclosures, we may continue thereafter to retain the data based on a legitimate interest.

How We Share and Disclose Personal Data

We share your Personal Data with third parties in the ways described in these Disclosures, including the “How We Collect and Use Personal Data” section above, as well as between Financial Health Network Entities. Additionally, we may share information as described below:

Service Providers
We share your Personal Data with third-party service providers that complete transactions or perform services on our behalf or for your benefit, such as:

    • Marketing and analytics;
    • Event registration and coordination;
    • Providing course platforms or tools that enable or enhance our offerings;
    • Research insights and analytics;
    • Research collaboration;
    • System maintenance and security;
    • Facilitating other transactions with you; and
    • Assisting with our legal compliance.

Partners
We may share your Personal Data with other entities for the purposes of delivering programs and services, such as:

    • Cross-registration for courses and events with other entities;
    • Online education offerings through online platforms; and
    • Research arrangements with other entities or partners.

Third-Party Mobile App Providers
With your knowledge and consent, our services on your mobile device may gather and transfer your Personal Data, including location information, from and to other applications, functions and tools within your mobile device if you use our mobile applications.

Social Media Platforms
We may also use services provided by third parties (such as social media platforms) to serve targeted ads or sponsored content on third-party platforms. For more information regarding our use of cookies and similar technologies, see the “Cookies and Similar Technologies” section below.

Legal Process, Safety and Terms Enforcement
We may disclose your Personal Data to legal or government regulatory authorities as required by applicable law. We may also disclose your Personal Data to third parties in connection with claims, disputes or litigation, when otherwise required by applicable law, or if we determine its disclosure is necessary to protect the health, safety, rights or property of you, us or others, or to enforce our legal rights or contractual commitments that you have made.

International Data Transfers

Much of our Personal Data processing takes place in the United States, though sometimes we or third parties with whom we share data, as discussed above, may process data in other countries.  The data privacy laws in the United States and other countries outside the EEA and the UK may provide less protection than such laws in the EEA or the UK.  In the event we transfer your Personal Data outside the EEA or outside the UK as part of our GDPR Processing Activities, we rely where required on appropriate or suitable safeguards or specific derogations recognized under the GDPR or under UK law.

The European Commission has adopted standard data protection clauses, also applicable in the UK, which provide safeguards for Personal Data transferred outside of the EEA or the UK. We may use Standard Contractual Clauses when transferring Personal Data from a country in the EEA or from the UK to a country outside the EEA or the UK. If so and your Personal Data are affected, you can request a copy of the Standard Contractual Clauses relevant to your Personal Data by contacting us as set forth in the “Contact Us” section below.

Cookies and Similar Technologies

We may collect Personal Data about you, or information that becomes Personal Data if combined with other information, when you visit or use our websites and online services. This information may be collected through the use of cookies, which are small data files placed on your computer or mobile device that allow us to collect certain information whenever you visit or interact with our websites or online services. Some of these cookies are managed by us (first-party cookies), while others are managed by third parties that we do not control (third-party cookies). This information may also be collected through the use of other data collection technologies (such as web beacons, pixels or tags) that embed graphic files in our websites and online services. These graphic files contain a unique identifier that enables us to recognize when someone has visited our website or online services, or in the case of web beacons, opened an email that we have sent them.

These small data files or graphic files serve various functions:

    • Strictly Necessary: Necessary to deliver our services;
    • Performance and Functionality: Enhance the performance and functionality of our services but are non-essential to their use;
    • Analytics and Customization: Allow us to understand the effectiveness of our services and marketing campaigns, as well as to customize our services based on this information; or
    • Advertising: Make advertising messages more relevant to you and your interests.

You can control the use of certain cookies and similar technologies by:

    • Setting or amending your web browser controls to accept or refuse cookies (please visit your browser’s help menu for more information).

If you choose to reject certain cookies and similar technologies, you may still use our websites and online services although your access to some functionality and features may be restricted. If you have any questions regarding our use of cookies and other similar technologies, please contact us as set forth in the “Contact Us” section below.

Your Rights

Upon your reasonable, good faith request we will provide you with information about whether we hold any of your Personal Data as part of our GDPR Processing Activities, to the extent required by and in accordance with applicable law. In certain cases, you may also have a right, with respect to your Personal Data collected and used in the GDPR Processing Activities, to:

    • correct or update any of your Personal Data that is inaccurate;
    • restrict or limit the ways in which we use your Personal Data;
    • object to the processing of your Personal Data;
    • request the deletion of your Personal Data; and
    • obtain a copy of your Personal Data in an easily accessible format.

To submit a request, please send an email message to privacy@finhealthnetwork.org. Because we want to avoid taking action regarding your Personal Data at the direction of someone other than you, we will ask you for information verifying your identity. We will respond to your request within a reasonable timeframe.

Subject to certain legal limits, you also have the right to withdraw your consent to our processing of your Personal Data as part of our GDPR Processing Activities, where our processing is solely based on your consent. In some cases, you can do this by discontinuing use of the services involved in the GDPR Processing Activities. This would include by closing all of your online accounts with us and contacting us at privacy@finhealthnetwork.org to request that your Personal Data be deleted. If you withdraw your consent to the use or sharing of your Personal Data for the purposes set out in these Disclosures or the other Financial Health Network privacy statements that link to or expressly adopt these Disclosures, you may not have access to some or all of the related services, and we might not be able to provide you some or all of the services. Please note that, in certain cases, we may continue to process your Personal Data after you have withdrawn consent and requested that we delete your Personal Data, if we have a legal basis to do so. For example, we may retain certain data if we need to do so to comply with an independent legal obligation, if we still need the data for the lawful purposes for which we obtained the data, or if it is necessary to do so to pursue our legitimate interest in keeping our services and operations safe and secure or to safeguard our rights or the rights or safety of others.

If you have any complaints regarding our privacy practices, you have the right to make a complaint with your national data protection authority (i.e., supervisory authority).

User Generated Content

Some of our online activities, such as listservs, chat rooms and bulletin boards, enable users to submit their own content. Please remember that any Personal Data you submit or post as user-generated content in these circumstances could in some cases be seen by others or become public. You should exercise caution when deciding to disclose your personal, financial or other information in such submissions or posts. We cannot prevent others from using that information in a manner that may violate these Disclosures, the law or your personal privacy and safety. We are not responsible for the results of such postings.

Updates to the Disclosures

We may update these Disclosures from time to time without prior notice by posting revised Disclosures to this site. You can determine when these Disclosures were last revised by checking the Last Updated date at the beginning of these Disclosures.

Contact Us

If you have any questions, comments, requests or concerns about these Disclosures or other privacy-related matters, you may contact us in the following ways:

Email: privacy@finhealthnetwork.org

Financial Health Network
135 S. LaSalle Street
Suite 2125
Chicago, IL 60603
Telephone: 312.881.5856