These privacy disclosures (the “Disclosures”) provide information about the collection, use, processing and sharing of data about individuals located in the European Union, Iceland, Liechtenstein or Norway (the “European Economic Area” or “EEA”).
These Disclosures also provide information about the collection, use, processing and sharing of data about individuals located in the United Kingdom, which has left the European Union but has adopted legislation substantially similar to the GDPR. With respect to individuals in the UK, references to the GDPR in these Disclosures are to be read as referring to the UK’s similar legislation, the Data Protection Act 2018.
In these Disclosures:
These Disclosures apply only to the use of Personal Data in GDPR Processing Activities. In these Disclosures the words “we,” “us” or “our” refer to Financial Health Network Entities. These Disclosures apply to GDPR Processing Activities by any means, including hardcopy (such as paper applications or forms) and electronic means (such as websites and mobile applications).
We collect several categories of Personal Data in circumstances that may involve GDPR Processing Activities, including data you provide, data collected automatically (potentially including location data), and data we obtain from third party sources.
We use the Personal Data that we collect to:
As described in more detail below, we rely on a number of legal bases to lawfully process your Personal Data.
The ways in which we collect and use your data vary depending on the relationship between you and us. The following sections of these Disclosures describe in more detail how we collect and use Personal Data in various circumstances that may involve GDPR Processing Activities.
Please note that, depending on the situation, some of the processing of Personal Data we do in the various circumstances described below may not fall within the scope of the GDPR.
Websites and Mobile Applications
As is true of most digital platforms, we obtain certain data automatically when you use one of our websites or mobile applications, such as your IP address, browser type and device type. Certain web-forms also collect Personal Data you provide, for example when you enter data into form fields, such as for the purpose of registration. If we also process data through our websites or mobile applications for one of the activities described further below, those descriptions will provide additional information about how those data are collected and used. We and our third-party vendors use this Personal Data for the primary purposes of conducting analytics, improving our websites, responding to your requests and providing you with relevant information.
As part of our GDPR Processing Activities, we may obtain certain Personal Data about you from third party sources, which we may use for the purposes and in the ways described in “How We Collect and Use Personal Data” above and in “Additional Uses of Personal Data” below. In some cases, we may obtain your consent for additional uses.
Partners and Service Providers
We use partners and service providers to provide services for us. Some of these partners have access to Personal Data about you that we may not otherwise have (for example, when you sign up directly with that provider) and may share some or all these data with us.
In addition to the uses described above, including under “How We Collect and Use Information” and “Personal Data We Obtain from Third Party Sources,” we may use your Personal Data for the following purposes. These additional uses may under certain circumstances be based on your consent, or may be necessary to fulfill our contractual commitments to you, for legal compliance, or to serve our legitimate interest in the following activities:
In addition to interests otherwise described in these Disclosures, we rely on other legitimate interests in using and sharing your Personal Data. These interests include:
We will retain your Personal Data for as long as is necessary for the purposes set out in these Disclosures and for as long as is required under applicable law or is needed to resolve disputes or protect our legal rights or otherwise to comply with legal obligations. Consistent with the foregoing guidance, some data may be retained indefinitely.
Where we are processing Personal Data based on your consent, we generally will retain the information for the period of time necessary to carry out the processing activities to which you consented, subject to your right, under certain circumstances, to have certain of your Personal Data erased (see “Your Rights” below).
Where we are processing Personal Data based on contract, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship.
Where we are processing Personal Data based on the public interest, we generally retain the information for the period of time that continues to serve that underlying interest.
Where we are processing Personal Data based on our legitimate interests, we generally will retain the data for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of the data subjects. In some cases, where Personal Data was primarily processed and retained on the basis of consent, contract, the public interest, or other bases described in these Disclosures, we may continue thereafter to retain the data based on a legitimate interest.
We share your Personal Data with third parties in the ways described in these Disclosures, including the “How We Collect and Use Personal Data” section above, as well as between Financial Health Network Entities. Additionally, we may share information as described below:
We share your Personal Data with third-party service providers that complete transactions or perform services on our behalf or for your benefit, such as:
We may share your Personal Data with other entities for the purposes of delivering programs and services, such as:
Third-Party Mobile App Providers
With your knowledge and consent, our services on your mobile device may gather and transfer your Personal Data, including location information, from and to other applications, functions and tools within your mobile device if you use our mobile applications.
Social Media Platforms
Legal Process, Safety and Terms Enforcement
We may disclose your Personal Data to legal or government regulatory authorities as required by applicable law. We may also disclose your Personal Data to third parties in connection with claims, disputes or litigation, when otherwise required by applicable law, or if we determine its disclosure is necessary to protect the health, safety, rights or property of you, us or others, or to enforce our legal rights or contractual commitments that you have made.
Much of our Personal Data processing takes place in the United States, though sometimes we or third parties with whom we share data, as discussed above, may process data in other countries. The data privacy laws in the United States and other countries outside the EEA and the UK may provide less protection than such laws in the EEA or the UK. In the event we transfer your Personal Data outside the EEA or outside the UK as part of our GDPR Processing Activities, we rely where required on appropriate or suitable safeguards or specific derogations recognized under the GDPR or under UK law.
The European Commission has adopted standard data protection clauses, also applicable in the UK, which provide safeguards for Personal Data transferred outside of the EEA or the UK. We may use Standard Contractual Clauses when transferring Personal Data from a country in the EEA or from the UK to a country outside the EEA or the UK. If so and your Personal Data are affected, you can request a copy of the Standard Contractual Clauses relevant to your Personal Data by contacting us as set forth in the “Contact Us” section below.
These small data files or graphic files serve various functions:
You can control the use of certain cookies and similar technologies by:
Upon your reasonable, good faith request we will provide you with information about whether we hold any of your Personal Data as part of our GDPR Processing Activities, to the extent required by and in accordance with applicable law. In certain cases, you may also have a right, with respect to your Personal Data collected and used in the GDPR Processing Activities, to:
To submit a request, please send an email message to firstname.lastname@example.org. Because we want to avoid taking action regarding your Personal Data at the direction of someone other than you, we will ask you for information verifying your identity. We will respond to your request within a reasonable timeframe.
Subject to certain legal limits, you also have the right to withdraw your consent to our processing of your Personal Data as part of our GDPR Processing Activities, where our processing is solely based on your consent. In some cases, you can do this by discontinuing use of the services involved in the GDPR Processing Activities. This would include by closing all of your online accounts with us and contacting us at email@example.com to request that your Personal Data be deleted. If you withdraw your consent to the use or sharing of your Personal Data for the purposes set out in these Disclosures or the other Financial Health Network privacy statements that link to or expressly adopt these Disclosures, you may not have access to some or all of the related services, and we might not be able to provide you some or all of the services. Please note that, in certain cases, we may continue to process your Personal Data after you have withdrawn consent and requested that we delete your Personal Data, if we have a legal basis to do so. For example, we may retain certain data if we need to do so to comply with an independent legal obligation, if we still need the data for the lawful purposes for which we obtained the data, or if it is necessary to do so to pursue our legitimate interest in keeping our services and operations safe and secure or to safeguard our rights or the rights or safety of others.
If you have any complaints regarding our privacy practices, you have the right to make a complaint with your national data protection authority (i.e., supervisory authority).
Some of our online activities, such as listservs, chat rooms and bulletin boards, enable users to submit their own content. Please remember that any Personal Data you submit or post as user-generated content in these circumstances could in some cases be seen by others or become public. You should exercise caution when deciding to disclose your personal, financial or other information in such submissions or posts. We cannot prevent others from using that information in a manner that may violate these Disclosures, the law or your personal privacy and safety. We are not responsible for the results of such postings.
We may update these Disclosures from time to time without prior notice by posting revised Disclosures to this site. You can determine when these Disclosures were last revised by checking the Last Updated date at the beginning of these Disclosures.
If you have any questions, comments, requests or concerns about these Disclosures or other privacy-related matters, you may contact us in the following ways:
Financial Health Network
135 S. LaSalle Street
Chicago, IL 60603