PensionBee Inc. Privacy Policy
1. Introduction
This Privacy Policy (the "Policy") outlines how PensionBee (defined herein)
collects, uses, shares, processes, and protects its Customers, Consumers,
and Users (each individually defined herein, and collectively “you” or
“your”) Personal Data (defined herein), which is designed to comply with
applicable U.S. federal and state regulations (the "Regulations").
PensionBee is required to have policies and procedures addressing the
protection of customer information and records. This includes protecting
against any anticipated threats or hazards to the security or integrity of
your records and information, and against unauthorized access to, or use of
your records or information.
2. Who this Policy Applies To
This Policy applies to you in your capacity as a Customer, Consumer, and/or
User.
3. Terminology and Definitions
-
Affiliates and Successor Entities: companies related to
PensionBee by common ownership or control or any legal successor thereto,
including PensionBee Limited, PensionBee Group plc, PensionBee Trustees
Limited.
-
Consumer: means an individual who obtains or has obtained
a financial Products & Services from PensionBee that is to be used
primarily for personal, family, or household purposes, or that
individual's legal representative.
-
Customer: means a Consumer who has a Customer
Relationship with PensionBee.
-
Customer Relationship: means a continuing relationship
between a Consumer and PensionBee under which PensionBee provides one or
more Products & Services to the Consumer that are to be used primarily for
personal, family, or household purposes.
-
Data Breach: unauthorized access or authorized access for
a non-permitted purpose or other security incidents that expose Consumer
or Customer's Personal Data or NPI.
-
Joint marketing: any agreement with a company or
individual other than PensionBee that markets or promotes Products &
Services to you.
-
Non-affiliates: companies not related to PensionBee by
common ownership or control, and individuals employed by or jointly
employed by PensionBee or any Affiliate of PensionBee.
-
Non-Public Personal Information (NPI): Information
relating to your financial status, accounts, or transactions that is not
publicly available, and which PensionBee is required to protect under
applicable laws.
-
PensionBee: PensionBee Inc. and any Affiliates and
Successor Entities, and for each of them, any of its officers, directors,
employees, agents or advisors (each a “PensionBee Party”).
-
Personal Data: Information by which you can be identified
either directly or indirectly, such as name, address, contact information,
financial information, and identification details.
-
Processing: The collection, use, disclosure, storage, and
management of your Personal Data for lawful purposes.
-
Products & Services: Any products and services provided
by PensionBee at any time.
-
Promotions: Any activity or proposed activity in any
medium that is marketed at any time to any Customers, Consumers, and
Users.
-
Third-Party Service Providers: Any Non-Affiliates
providing products and services to PensionBee including custodians,
brokers, IT service providers, and auditors assisting in business
operations or service delivery.
-
Users: Any person who directly or indirectly provides
Personal Data to PensionBee or Third Party Service Provider in connection
with PensionBee's business or any Products & Services, including any
person who (i) visits and/or interacts with any PensionBee website,
PensionBee application, PensionBee sponsored third party website or
application, (ii) uses or accesses any PensionBee system, premises, or
Products & Services; (iii) is a PensionBee Party, (iv) is a Third Party
Service Providers, or any officers, directors, employees, agents or
advisors of any Third Party Service Providers; and (v) participates in any
PensionBee promotion, campaign, research or event.
4. Types of Information Collected
PensionBee Parties and Third Party Service Providers collect and process NPI
from you as necessary to provide Products & Services and for other purposes
outlined herein, which NPI can include the following:
|
Mandatory and/or Automatic Collection
|
Optional Collection (based on your specific relationship with
PensionBee or PensionBee's Products & Services)
|
|
Information from You or Third Party Sources
|
- Full Legal Name
- Postal Address
- Email Address
- Telephone Number
- Date of Birth
- Passport or Driver's License
- Social Security Number
- Biometric Data
- Banking Information
-
Financial Information including: account numbers, balances,
transactions, portfolio details, and investment history
- Tax Identification Numbers
- Sources of Income
- Net Worth
- Credit Card Numbers
- Beneficiary Details
-
Other Identifies for Legal Compliance Purposes
-
Other information that may be required pursuant to SEC Regulations
-
Transaction history and balances from Custodians
-
Credit Reports or other data related to your credit worthiness
-
Information from other professionals like attorneys and
accountants
|
- Employment Information
- Salary Information
- Benefit Data
-
Data Related to Financial Planning
- Investment Portfolio Details
- Risk Preferences
- Financial Goals
- Trusted Contact Information
|
|
Information from Website Visits
|
- IP addresses
- Browser types
- Anonymous usage data
- Cookies, caches, and analytics
|
|
If you fail to provide required NPI or Personal Data that is subject to
mandatory compliance, PensionBee may not be able to deliver certain Products
& Services or fulfill contractual obligations.
You acknowledge and agree that PensionBee may continue to share your NPI or
Personal Data only as described in this Policy including after you cease to
be a Customers, Consumers, and Users or cease to use any of Products &
Services.
5. How Information is Collected
PensionBee collects Personal Data and NPI in the following ways:
-
Direct Collection: Information that you provide through
communication with PensionBee, including account registration,
maintenance, termination, the ongoing provision of any Products & Services
offered by PensionBee, service forms, calls, correspondence and
Promotions;
-
Third-party Sources: Any third party involved in the
provision of any current or future Products & Services, for example:
- Your custodian or financial institution;
- Publicly accessible sources;
- Data brokers from which PensionBee purchases data;
- Third-Party Service Providers;
- AI services or products; and
- Social media sites with which you interact with; and
-
Automated Technologies: Certain data may also be
automatically collected when you use Products & Services, such as activity
logs, and interaction details with digital platforms.
6. Purposes of Processing Personal Data
PensionBee processes your data, including your Personal Data, for the
purposes of (i) offering, promoting, researching, developing, marketing,
distributing, managing, opening and closing, maintaining and servicing any
Products & Services for Customers, Consumers and Users, (ii) locating,
identifying and rolling over your 401ks, 403(b)s, Roth and Traditional IRAs,
SEP IRAs, and any other retirement investment accounts offered from time to
time into any Products & Services and (iii) any other specified purposes
outlined further below in Clause 6.1.
Without prejudice to the operation of Clause 6.2, PensionBee does not sell
your NPI to anyone and PensionBee only discloses your NPI to affiliated and
non-affiliated third parties as necessary to provide any Products & Services
or as required by law.
PensionBee will never process your data, including your Personal Data, for
purposes otherwise prohibited under the laws and regulations applicable to
investment advisors in the United States.
6.1. Key Purposes
PensionBee uses your Personal Data for the following key purposes:
- Conducting identity verification and background checks;
- Preventing fraud and safeguarding financial information;
- Portfolio management and investment advisory services;
-
Communication with financial service providers and financial regulators;
- Communication with Third Party Service Providers;
-
Utilizing products and services provided by Third Party Service Providers;
-
Use by Third Party Service Providers as necessary or advisable for them to
directly or indirectly provide or contribute to the provision of any
Products & Services;
-
Pursuant to any purpose permitted under any contract, arrangement, or
memorandum of understanding entered into by PensionBee with any Third
Party Service Provider;
-
Pursuant to any action PensionBee or a Third Party Service Provider
undertakes on your behalf in the provision of any Product & Service;
-
Determine eligibility and offering of additional Products & Services;
- Developing new Products & Services;
-
Ensuring systems security, including without limitation, against internal
and external cyber risks;
- Ensuring best execution practices;
- Risk Management;
- Improving service quality and operational efficiency;
-
Internal, external, and statutory auditing, risk assessment, staff
training programs and ensuring compliance with all applicable PensionBee
policies and procedures;
-
Use of AI tools (including PensionBee AI Generated Products & Services or
use of third party AI generated Products & Services) in creating data,
responses or other use purposes in offering or developing Products &
Services;
-
Statistical analysis for market trends; and maintaining account security
and business continuity;
-
Enforcement and defense of terms and conditions of any Products & Services
offered to a User in allegations of breach or other legal actions taken
involving PensionBee;
-
Where you are an officer, agent, employee, advisor or contractor of
PensionBee: for all purposes arising out of or in connection with the
establishment, compliance with / maintenance of, enforcement, amendment
and / or termination of your engagement by PensionBee.
- Compliance with any legal and regulatory obligations;
-
Research for law and regulatory reform in sectors relevant to Products &
Services;
-
Activities for the purpose of reforming laws and regulations applicable to
the Products & Services;
-
Monitoring for, communicating with, and responding to requests from
federal or state regulatory authorities (including financial, legal,
security and other applicable regulatory authorities) for compliance;
-
Responding to any state attorney or attorney general inquiry requests; and
- Responding to legal and regulatory inquiries.
6.2. Anonymized and Aggregated Data Use
Any one or more PensionBee Parties or Third Party Service Providers may
collect and use NPI and other data, including Personal Data collected about
you from various sources,including information that is either provided to us
by you or obtained by us during the course or provision of any Products &
Services, including data and information gathered during the Customer
Identification Program (“CIP”) process (collectively, "Personal Data"), when
such Personal Data is anonymized and aggregated for internal and third party
purposes of PensionBee or Third Party Service Provider, including, but not
limited to product development, service enhancement, data modeling studies,
Know Your Customer (“KYC”) services and systems, identity verification, and
fraud prevention purposes.
7. Personal Data Sharing and Third Party Disclosures
You agree to PensionBee sharing your Personal Data and NPI with PensionBee
Parties and Third Party Service Providers.
You further agree PensionBee and any Third Party Service Provider may share
Personal Data and NPI to fulfill legal obligations and for the purpose of
providing any Products & Services. PensionBee shall make good faith efforts
to ensure that all data shared with third parties is handled lawfully,
securely, and in accordance with applicable regulations.
Some of these sharing purposes include:
-
For everyday business purposes – such as to process your transactions,
maintain your account(s), respond to court orders and legal
investigations, or report to credit bureaus;
- For marketing – to offer any Products & Services to you;
- For joint marketing – with other individuals and companies;
-
For Third Party Service Providers – in connection with any Products &
Services;
-
For PensionBee affiliates' everyday business purposes – information about
your transactions and experiences and information about your
creditworthiness;
- For non-affiliates – to market to you; or
-
In circumstances involving mergers, acquisitions, or organizational
restructuring, or assessments for such mergers and acquisitions, or
assessments with antitrust or regulatory authorities, relevant data may be
shared with any third party for such purposes.
7.1. Categories of Third Parties
PensionBee shares Personal Data and NPI with the following categories of
non-affiliated third parties who assist PensionBee in providing Products &
Services to you or to whom PensionBee is legally required to provide. These
third parties are contractually bound to maintain the confidentiality of
your information. Examples of such third parties include:
-
Custodians, Broker-Dealers, and Banks: To execute
transactions and maintain your assets (e.g., APEX Clearing Corporation);
-
Third-Party Administrators: For processing fees,
generating performance reports, and client account aggregation (e.g., IT
vendors and processing platforms);
-
KYC Providers: For account set up, KYC checks, and fraud
prevention measures;
-
Third Party Service Providers: as engaged by PensionBee,
including without limitation Software as a Service ("SaaS"); data
providers, data centers, AI products and services, cloud ware services,
outsourcing services, client relationship managers, telecommunication
services, external research and design tools, marketing service providers,
and data backup services;
-
Cybersecurity System Providers: For the protection of
Personal Data, financial data, and security systems and frameworks;
-
Legal and Regulatory Authorities: In response to
subpoenas, court orders, or required regulatory filings (e.g., the SEC,
state regulators), investigations by tax authorities including the IRS and
for compliance with applicable laws; and
-
Internal, External or Regulatory Auditors: For legal and
compliance purposes.
7.2. Promotions
PensionBee promotions may be jointly sponsored or offered by other parties.
When you enter a promotion, you agree to the terms and conditions that
govern the promotion, including, rights for PensionBee to share Personal
Data and NPI as well as for administrative purposes and as required by law,
and allow PensionBee, the promotion sponsor and/or other entities to use
your name, voice and/or likeness in advertising or marketing materials.
7.3. Advertising Analytics
PensionBee uses third-party advertising and analytics services to better
understand your online activity and serve you targeted advertisements. For
example, PensionBee may use Google Analytics, and you can review the “How
Google uses information from sites or apps that use our services” linked
here:
http://www.google.com/policies/privacy/partners/
for information about how Google processes the information it collects.
These companies collect information about your use of Products & Services
and other websites and online services over time through cookies, device
identifiers, or other tracking technologies. The information collected
includes your IP address, web browser, mobile network information, pages
viewed, time spent, links clicked, and conversion information. PensionBee
and its Third Party Service Providers use this information to, among other
things, analyze and track data, determine the popularity of content, and
deliver advertisements targeted to your interests on Products & Services and
other platforms, as well as providing advertising-related services to
PensionBee such as reporting, attribution, analytics, and market research.
8. No Liability for Third Party Data Breaches
You acknowledge that PensionBee may engage Third Party Service Providers to
assist in providing Products & Services, which may involve access to,
processing, or storage of NPI or other Personal Data. PensionBee strongly
encourages you to review these Third Party Service Provider's privacy
policies along with any other privacy policies of third parties that you may
be exposed to using Products & Services.
You agree that PensionBee is not responsible for any third party's privacy
practices. You further agree that PensionBee is not liable for any Data
Breaches caused by the actions, omissions, or practices of any Third Party
Service Provider, regardless of whether such Third Party Service Provider
was acting within the scope of its engagement with PensionBee and including
when a Third Party Service Provider provides Personal Data or NPI to
PensionBee that it was not authorized to provide. This limitation of
liability applies to all claims, damages, or expenses arising from a Data
Breach caused by a Third Party, regardless of the form of action or legal
theory.
9. Safeguarding Personal Data and NPI
PensionBee is committed to maintaining security measures and data protection
practices to safeguard Personal Data and NPI, using industry-standard
security protocols, regular system monitoring, employee training to mitigate
risks and ensure compliance with applicable data protection laws, and
physical, electronic, and procedural safeguards to protect and secure your
Personal Data and NPI, including:
-
Restricting employee access to your Personal Data and NPI on a strict
need-to-know basis to service your account or for legitimate business
purposes;
-
Maintaining a secure office and utilizing technology safeguards, such as
firewalls, password protection, and encryption, to prevent unauthorized
access;
-
Training employees on the importance of maintaining the security and
confidentiality of client information;
- Data encryption protocols to protect sensitive transactions;
-
Firewalls to safeguard Personal Data and NPI against unauthorized
breaches;
-
Restricted access controls based on user roles and organizational security
rules;
-
Regular audits to ensure compliance, including adherence to Rule 206(4)-7
of the SEC Advisers Act;
-
Negotiating appropriate confidentiality obligations with service providers
who have access to your Personal Data or NPI; and
-
Conducting operations in compliance with ISO Certifications including
Information security, cybersecurity and privacy protection — Information
security management systems — Requirements ("ISO 27001").
10. Retention of Your Personal Data and NPI
PensionBee Parties retain your Personal Data and NPI for as long as
necessary to achieve the original purpose(s) for which it was collected.
PensionBee Parties will also keep your Personal Data and NPI for a longer
period if required by law, in connection with an ongoing or potential claim,
or for another legitimate legal, regulatory or operational reason.
After the applicable retention period, your Personal Data and NPI will
either be deleted or anonymized, subject to legal requirements.
This Policy continues to apply to your Personal Data and NPI.
11. Your Rights and Controls
11.1. Account Information
Customers and Consumers may access, update, or remove certain information
that they have provided to PensionBee through their account by visiting
their account settings or sending an email to the email address set out in
the "Contact Us" section below. PensionBee may require additional
information from Customers and Consumers to allow PensionBee to confirm
their identity.
Please note, Customers and Consumers will not be able to access update or
remove certain information about them that is required to be retained that
is necessary to comply with applicable law and regulations, PensionBee legal
obligations, resolve disputes, and enforce agreements.
11.2. Tracking Technology and Cookies
Many web browsers are set to accept cookies and similar tracking
technologies by default. If you prefer, you can set your browser to manage
these technologies. If you choose to delete or reject these technologies,
this could affect certain features of the Products & Services. If you use a
different device, change browsers, or delete the opt-out cookies that
contain your preferences, you may need to perform the opt-out task again.
PensionBee's website and app store data such as cookies to enable the
PensionBee website and app to function and for the purposes of analytics and
marketing. You can disable cookies in your browser by following these
instructions and you can disable cookies in the PensionBee app by opting out
of tracking when downloading the app.
You can stop receiving promotional emails from PensionBee by selecting the
"unsubscribe" link in those emails. PensionBee may still send you
service-related or other non-promotional communications, such as account
notifications, receipts, security notices and other transactional or
relationship messages. PensionBee will never send you promotional or
marketing text messages.
12. Privacy Laws
12.1. GLBA and the Right to Opt Out
The Gramm-Leach-Bliley Act (the "GLBA") applies to your Personal Data and
NPI provided to PensionBee or Third Party Service Providers. The GLBA allows
you the right to limit the sharing of your Personal Data and NPI provided to
any PensionBee or Third Party Service Provider by "opting-out" of the
following:
-
sharing any of your Personal Data and NPI with Affiliates and Successor
Entities for everyday business purposes not connected to Products &
Services, like information about your creditworthiness; or
-
sharing any of your Personal Data and NPI with Affiliates and Successor
Entities or Non-affiliates who use your information to market to you.
If you choose to opt out or reject the sharing of your Personal Data or NPI,
it could affect certain features of the Products & Services and may not
receive notice of certain offers, Products & Services or other marketing
opportunities that may be relevant or of interest to you.
State laws may give you additional rights to limit sharing. Please see
further below with respect to State laws.
Please notify PensionBee immediately at the following email address (info@pensionbee.com) if you choose to opt out of these types of sharing in relation to GLBA
rights.
12.2. Customer Rights and Regulation S-P
In accordance with Regulation S-P, Customer rights with respect to any of
their Personal Data and NPI provided to PensionBee Parties or Third Party
Service Providers include:
-
Right to Access: To receive an annual privacy notice
regarding PensionBee's practices and disclosures. PensionBee is also
required to provide initial and annual privacy notices to you describing
information sharing policies and informing customers of their rights;
-
Right to Opt-Out: Limit the disclosure of Personal Data
and NPI to unaffiliated third parties (except where exemptions apply, such
as fraud prevention); and
-
Right to Request Information: Ask us for details on the
Personal Data and NPI we collect and share.
To exercise any of these rights, Customers must request in writing to
info@pensionbee.com.
We may share, without payment, certain information with advertising and marketing
partners to support advertising, audience matching, retargeting, and marketing measurement activities.
California Residents: Under California privacy law (CPRA/CCPA), California residents have the right to opt out of the “sale” or “sharing” of
personal information used for cross-context behavioral advertising purposes.
Because PensionBee does not sell your personal information, you do not need to act further to ensure your information is not being sold.
We recognise browser-based opt-out preference signals, including Global Privacy Control (GPC), where required under applicable law. If your
browser or device sends a recognised GPC signal, advertising cookies and similar tracking technologies used for cross-context behavioural advertising purposes
will automatically be disabled for that browser/device where applicable.
If you are a visitor to the PensionBee app and not a PensionBee customer,
you can exercise your opt-out rights by clicking
Manage my consent
and disabling advertising cookies.
If you are a PensionBee customer, you can opt out of data sharing by selecting the option ‘Privacy and Cookie Preferences’ in the Beehive.
12.4. State Specific Privacy Laws
Some US States may have specific privacy laws that affect your Personal Data
and NPI such as rights to access, delete, or correct such information and to
opt out of certain processing activities. These state rights cannot replace
federal financial privacy laws such as the GLBA but may apply to the extent
they provide you with additional rights not inconsistent with the GLBA.
When a state right is available to a Customer in that state who wises to
exercise any of these state rights, such Customer must request in writing to
info@pensionbee.com.
12.5. International Transfer
Any Personal Data or NPI provided to any PensionBee or Third Party User may
be transferred to, processed, stored, and used in jurisdictions that are not
subject to U.S. Data protection laws and such other jurisdictions may be
different from those of your country of residence. By providing your
Personal Data or NPI to any PensionBee or Third Party User for the purposes
of, or in connection with, any of the permitted purposes contemplated by
this Policy or provision of any information to any PensionBee or Third Party
Service Provider from any jurisdiction other than the U.S. constitutes your
agreement to the transfer to and from, and the collecting, processing,
usage, sharing, and storage of information about you including Personal Data
and NPI in jurisdictions other than the U.S. and you agree to indemnify and
hold harmless PensionBee from any losses, damages, or claims that arise from
the collecting, processing, usage, sharing, and storage in those
jurisdictions.
13. Dispute Resolution Process
If you have any concerns or disputes regarding PensionBee's handling of your
Personal Data or NPI or this Policy, please raise these directly with us at
info@pensionbee.com. PensionBee
will investigate and provide a resolution promptly.
14. Changes to Privacy Policy
PensionBee reserves the right to update this Policy periodically including
to address changes in applicable law or regulation. Updates will be posted
on the PensionBee website at
https://www.pensionbee.com/us/privacy-policy
and any material changes will be notified via email or other appropriate
communication methods.
15. Contact Information
If you have any questions about the Policy, please contact us at
info@pensionbee.com.