MyAssets: Platform Privacy Policy
1. Introduction
1.1 This Policy (together with our Platform Terms and Conditions and any other documents referred to in them) sets out the basis on which we, MyAssets Limited (“MyAssets”), a UK registered company, with company number 14109037 and registered address of 73 Cornhill, London, United Kingdom, EC3V 3QQ, will process any personal data we collect from you, or which you provide to us, in the course of using the MyAssets’ platform (“Platform”).
1.2 We respect the privacy rights of all our users and recognise the importance of protecting the information we collect about you. Our Privacy Policy is designed to help you understand how we collect, hold, use and disclose personally identifiable information about you.
1.3 For the purpose of the UK Data Protection Act 2018 (“DPA’18”) MyAssets is the data controller.
2. Your Information
2.1 All personal data, including, but not limited to, data that is collected directly by us, data that is uploaded to the Platform by you, or data that is collected when you contact us, , is collected and processed under the UK General Data Protection Regulation (“UK GDPR”) and DPA’18 under the lawful basis of contract to facilitate to provision of our product and services.
3. Information that may be collected about you
3.1 In order to create an account on the Platform, unless you choose to create an account using an existing Google or Apple account, the following data must be provided. Please note that this applies to both direct users of the Platform, as well as those who are granted delegate access via a direct user’s account.
- Your name;
- Your email address; and
- A password.
3.2 In order to establish an active subscription, you must provide your payment information. This information is collected by our sub-processor Stripe. For more information please see section 6 below.
3.3 Once you have an active account, you can choose to provide the following data, however, the collection of such data is not required in order to open your account:
- A profile picture;
- Your phone number; and
- Your date of birth.
3.4 As part of the Platform’s functionality, you can upload a wide variety of content to the Platform. This information is likely to include personal data relating to both you and your family members, friends or other associated persons. This could include, but is not limited to, information relating to (including photographs and copies of):
- Bank accounts and associated information (e.g. loans, mortgages and savings);
- Investments (e.g. stocks and shares);
- Cryptocurrency;
- Wills;
- Property portfolios;
- Title deeds;
- Insurance policies;
- Trusts;
- Collectables (for example, unique and/or high-value items such as classic cars, antiques, art, wine and spirits, trading cards, comic books and unique memorabilia the ownership of which would identify the individual due to the rarity);
- Belongings (for example, jewellery, clothing and cars); and
- Guardianship documents.
3.5 During the course of using the Platform other personal data may be collected from you, including:
- Your internet Protocol (“IP”) address;
- Device type, for example IOS or Android;
- Time zone and location;
- Your activity on the Platform;
- Date and time stamps; and
- Operating system.
4. How your personal data may be used
4.1 We may use your data in the following ways:
- To provide you with our products and services.
- To ensure that content from the Platform is presented in the most optimised and effective manner for you and for your computer.
- To diagnose or fix technology problems.
- To control unauthorised use or abuse of the Platform and our products and services, or otherwise detect, investigate or prevent activities that may violate the Platform policies or be illegal.
- To carry out obligations arising from any interaction entered into between you and MyAssets.
- To allow you to participate in interactive features of this service, when you choose to do so.
- To send you rewards and enable you to participate in a prize draw, competition or complete a survey.
- To notify you about changes to any service.
- To administer the Platform including data analysis, testing, traffic monitoring, research, statistical and survey purposes.
- To provide you with information, products or services that you request or that we feel may interest you, where you have consented to be contacted for such purposes.
- To gather general statistical information which may then be provided to third parties. In such case any information provided to third parties will not allow you as a data subject to be personally identified.
4.2 We will only contact you for marketing purposes if you opted in to receiving such communications, either at the time of signing up to the Platform or at a later date. If you later decide that you do not wish to be contacted for marketing purposes, you can unsubscribe using the unsubscribe function in the footer of the email, or by sending an email to [email protected].
5. Special category personal data:
5.1 While we do not intend to collect special category personal data (such as information related to racial or ethnic origin, religion or other beliefs, health, criminal record or trade union membership) relating to you, we may inadvertently collect this information when you upload documents or information to the Platform. For example, you may upload a document that relates to your health insurance policy which may include information that reveals specific details about your health.
5.2 Any information uploaded by you that is not directly related to the creation and running of your account is encrypted and is not accessible by us. This means that it is not possible for us to access any information, which may include special category personal data, that is uploaded by you to the Platform.
5.3 Where any such special category personal data is uploaded to the Platform, you acknowledge that we will be collecting and handling this information in accordance with this Privacy Policy.
6. How your data may be disclosed
6.1 In order to provide services to you, we may transfer your personally identifiable information to third parties, parents, affiliates, subsidiaries and service providers, some of which may process and/or store your personally identifiable information outside of the European Economic Area (“EEA”). However, in such an instance all reasonable steps will be taken to ensure that your personal data is treated securely and in accordance with this Privacy Policy (where possible). Any data transfers that take place outside of the EEA will be covered by appropriate safeguards, for example Standard Contractual Clauses (“SCCs”), Binding Corporate Rules (“BCRs”) or Data Transfer Agreements (“DTAs”).
6.2 Third parties to whom your personally identifiable information may be disclosed include, but are not limited to:
6.2.1 Processors:
- TMO Platforms Limited (business registration number 77353303)
- MyAssets Limited (business registration number 72967412)
- Plaid: https://plaid.com/legal/#consumers
- Hubspot: https://legal.hubspot.com/privacy-policy
- Genesys: https://www.genesys.com/en-gb/company/legal/privacy-policy
6.2.2 Sub-processors:
- Stripe: https://stripe.com/gb/privacy;
- Google: https://policies.google.com/privacy?hl=en-US
- Apple: https://www.apple.com/legal/privacy/en-ww/
- Sendgrid: https://www.twilio.com/en-us/legal/privacy
- Google Firebase and Firestore: https://firebase.google.com/support/privacy/
- Cloudflare: https://www.cloudflare.com/en-gb/privacypolicy/
6.3 Please note that if you click on, or follow, any links from the Platform to external websites, our Privacy Policy will no longer apply. Please check the privacy policies of any such external site before submitting any personal data, as we cannot accept any responsibility or liability in relation to them.
7. Servers
7.1 All information you provide to us will be stored on our secure servers based in Germany, encrypted using SSL TLS v1.2 encryption.
7.2 We take your privacy seriously and will take all reasonable steps to protect your personal data, but please beware that any data that you submit to the Platform is sent at your own risk.
7.3 The data that we collect from you may be processed, transferred to, stored in or accessed by MyAssets’ employees in countries that are outside of the EEA. These countries include, but is not limited to, Hong Kong, the Philippines, Manila and New Zealand. By submitting your personal data, you agree to this. We will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
8. Data Storage
8.1 We hold personally identifiable information in a combination of hard copy and electronic files for the period necessary to support the Platform, comply with our legal obligations, resolve disputes, or otherwise fulfill the purposes outlined in this Privacy Policy. We use third-party information system providers who may store or have access to your personal information. We may also retain backup information on our servers for some time to comply with applicable law or our internal security policies. We do not always remove or delete all of your information for a number of reasons including technical and system constraints and contractual or legal requirements.
8.2 We operate a data retention period of 7 years from the date of our last interaction with you. 7 years after the date of our last interaction with you all of the data provided by you during all of your interactions with us will be reviewed and securely deleted/destroyed, subject to our legal and regulatory obligations.
8.3 No method of transmission over the internet, method of electronic storage or other security methods is one hundred percent secure. Therefore, while we strive to use commercially acceptable means such as firewalls, secure encrypted databases with limited physical and electronic access, and encryption to protect your personally identifiable information against unauthorised use, disclosure or modification, we cannot guarantee its absolute security.
9. Processing of personal data of those below the age of 13
9.1 The Platform is not intended for use by anyone under the age of 13 nor do we knowingly collect or solicit personally identifiable information from anyone under the age of 13. If you are under the age of 13, do not send any of your personal data to us, including your name, address, telephone number, or email address.
9.2 In the event that we confirm that we have collected personally identifiable information from someone under the age of 13 without verification of parental or guardian consent, we will delete/destroy that information promptly. If you are a parent or legal guardian of a child under the age of 13 and believe that we might have any information from or about such child, please contact us at the email or mailing address provided at the end of this Privacy Policy.
9.3 Due to the functionality of the Platform, you may choose to upload personally identifiable information about an individual under the age of 13. Should such data be uploaded to the Platform, this is done so at your discretion. In doing so, you acknowledge that we will process that personal data in line with this privacy policy and you understand that we will not have access to your data.
10. Data subject rights
10.1 You have the following rights under DPA’18 in relation to your personal data. You may exercise any of these rights at any time by contacting us at [email protected] or, if you are a direct user of the Platform, by completing the relevant form within your MyAssets’ account.
- Right to access (subject access request) - You have the right under DPA’18 to obtain confirmation as to whether or not we process your personal data, as well as access to any information we hold about you.
- Right to rectification – You have the right under DPA’18 to request the amendment or updating of all the personal information that we hold about you.
- Right to erasure – You have the right under DPA’18 to request that all of the information that we hold about you is deleted in line with our statutory and legal responsibilities.
- Right to restriction of processing – Subject to Article 18 (1) (a) to (d) of GDPR, you have the right under DPA’18 to obtain from the controller restriction of processing.
- Right to data portability – You may have the right under DPA’18 to request a copy of all of the information that we hold about you in a structured, commonly used and machine readable format. This right applies where the processing is based on consent or contract and the processing is carried out by automated means.
11. Enforcement
11.1 We cooperate with the appropriate regulatory authorities, including local data protection authorities (the UK Information Commissioner’s Office (“ICO”)), to resolve any complaints regarding the collection, processing and disclosure of personally identifiable information that cannot be resolved between MyAssets and the individual.
11.2 If you have a concern about your privacy or would like to know more about how your personally identifiable information is collected or used, please contact us via the Platform (if you are a direct user) or using the email address outlined below. We ask that when you contact us with a complaint, please include contact information and clearly describe your complaint. For any complaint regarding privacy please use [email protected].
11.3 We will respond to your request or complaint within a reasonable time and will let you know the next steps in resolving your complaint. If you are not satisfied with our response, you may also contact your local and federal data protection authorities to lodge a complaint.
11.4 Should you not be satisfied with the process, conduct or response to a request you may have made you have the right to complain to the ICO (https://ico.org.uk/make-a-complaint/).
12. Notices and provisions
12.1 We reserve the right to change our Privacy Policy at any time. These changes will take immediate effect unless you are notified otherwise. We recommend that you refer to this Privacy Policy on an ongoing basis so that you understand our current practice at the time of using our service. Unless stated otherwise in a separate agreement, this Privacy Policy applies to all information we hold about you.
13. Contact us
13.1 MyAssets regularly reviews its compliance with relevant data protection laws and this Privacy Policy. If you have any questions or want to get in contact with us regarding this Privacy Policy, please feel free to email us at [email protected].