Last updated: October 12th, 2020
This Privacy and Data Protection Policy describes the policies and procedures of ExSilico Ltd trading as Sharehold ("Sharehold", “we”, “our” or “us”) regarding our collection, use and disclosure of your information in connection with your access and use of https://sharehold.com (the “Site”), our mobile application for iOS and Android (the “App”), and the other services, features, products, content or applications offered by Sharehold (together with the Site and the App, the “Services”). As used in this Privacy and Data Protection Policy, “Personal Data” means any information that can be used to individually identify a person. All defined terms not defined herein shall have the meaning ascribed to them in the Sharehold Terms of Service, of which this Privacy and Data Protection Policy is a part.
We urge you to read this Privacy and Data Protection Policy in full, but wanted to mention a few things upfront:
This Privacy and Data Protection Policy covers our treatment of Personal Data that we collect about you (a) from you directly, when you register for and use your Account on the Services; (b) from your web browser and/or device, as you interact with the Services generally; and (c) from third party websites and services, including our business partners and service providers.In this Privacy and Data Protection Policy, we describe the various purposes for which we use your Personal Data, as well as the legal bases supporting those purposes. As you’ll read below, the legal basis on which we rely for a given use of your Personal Data may be contractual necessity (i.e., where we need to use your Personal Data to complete a contract with you), consent (which you must freely give us, and which you can withdraw at any time), and/or certain legitimate business interests of ours or of others, but only where we have determined that those interests are not overridden by your own interests, rights, and freedoms.The Services are hosted and operated in Ireland, Europe ("EU"), the United States ("US"), and elsewhere throughout the world through us and certain of our service providers. By using the Services, you acknowledge that any Personal Data you provide to us will be hosted on servers in the EU, the US, and other countries.If you are using the Services in the European Economic Area, you may have certain rights regarding the Personal Data we collect from you, under the European Union General Data Protection Regulation (“GDPR”), as outlined below, and for purposes of the GDPR, Sharehold would be a controller of Personal Data collected from you through the Services. If you have any questions about this Privacy and Data Protection Policy or whether any of the following applies to you, please contact us directly at firstname.lastname@example.org, or at 7 Burdett Ave, Sandycove, Co. Dublin, A96 A339, Ireland, or at +353 (1) 4433 593 if you have any questions or concerns about our collection and use of your Personal Data.As noted in our Terms of Service, we do not knowingly collect or solicit Personal Data from anyone under the age of 18. If you are under the age of 18, you are not allowed to use the Services, so please do not access or use the Site or the App, or attempt to send us any Personal Data. If we confirm that we have collected Personal Data from an individual under the age of 16, we will delete that information as quickly as possible.This Privacy and Data Protection Policy does not apply to the practices of third parties that we do not own or control, including, but not limited to, any third party websites, services, products or applications (each a “Third Party Service”) that you elect to access and may interact with during your use of the Services, or to individuals that we do not manage or employ. We take steps to ensure that we only work with Third Party Services that share our respect for your privacy, although we cannot take responsibility for the content, products, services or privacy policies of those Third Party Services. We encourage you to carefully review the privacy policies of any Third Party Services you access.Sharehold takes the protection of your personal data very seriously. To find out more, go to “How Do We Protect Your Personal Data?”
What Does This Privacy and Data Protection Policy Cover? This Privacy and Data Protection Policy covers Sharehold’s processing of Personal Data that Sharehold gathers when you are accessing and using the Services. As used in this Privacy and Data Protection Policy, “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure.This Privacy and Data Protection Policy also covers Sharehold’s treatment of any Personal Data that Sharehold’s business partners and service providers share with Sharehold, or that Sharehold shares with its business partners and service providers.This Privacy and Data Protection Policy does not apply to the practices of third parties, and their sites, services or applications that Sharehold does not own or control, or to individuals that Sharehold does not employ or manage (“Third Parties”). While we attempt to provide access only to those Third Parties that share our respect for your privacy, we cannot take responsibility for the content, actions or data protection policies or practices of those Third Parties. We encourage you to carefully review the data protection policies and practices of any Third Parties you access, and to carefully consider what kind of Personal Data you choose to post or otherwise make available through the Services.
What Personal Data does Sharehold Collect From You?
We collect Personal Data about you when you provide such information directly to us, when third parties such as our business partners or service providers provide us with Personal Data about you, or when Personal Data about you is automatically collected in connection with your use of our Services.By providing Personal Data of others to Sharehold, you represent that you have authority to do so. We disclaim responsibility for the information of others that you provide to us in the course of your use of the Services.
Information we collect directly from you: We receive Personal Data directly from you when you provide us with such Personal Data, including without limitation the following:Account information, including your:full name, andphone number, andemail address.Any Personal Data that you make available on or through the Services.Any Personal Data you provide when you communicate with us or our customer service representatives (so please only provide what is necessary).Any Personal Data you provide us when purchasing Products, including your:full name, andphone number, andemail address, andshipping address.If applicable, in order to collect payments on your behalf, and provide payments to you, we, using Stripe as a third-party payment processor, collect payment information from you, your attendees and customers, your vendors, and other parties to whom we provide payments on your behalf and from whom we collect payments on your behalf. This information is used solely to collect and provide payments related to the Services, and is only stored by Stripe, not by us. You should review the terms of service and privacy policies of Stripe, available at https://stripe.com/us/privacy.
Information we automatically collect when you use our Services: Some Personal Data is automatically collected when you use our Services, such as the following:IP address,Web browser information,Operating system information,Pages you visit and links you click on for the Services only (not for marketing purposes), andCertain Cookies (see below for more information) (collectively, “Usage Data”).
How Do We Use Your Personal Data? We process Personal Data to operate, maintain and understand our Services. For example, we use Personal Data to:Verify and establish your AccountProcess and fulfill your purchases of ProductsProtect against or deter fraudulent, illegal or harmful actionsCommunicate with you about the Services, including sending you updates, offers, emails, newsletters and other information that we believe may be of interest to you.Provide support and assistance for the ServicesIdentify trends and other statistical information that may be useful to our businessComply with our legal or contractual obligationsRespond to user inquiriesFulfill user requestsResolve disputesEnforce our Terms of Service (including, for clarity, this Privacy and Data Protection Policy)We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.
Contractual Necessity: We process the following categories of Personal Data as a matter of “contractual necessity,” meaning that we need to process the data to perform under our Terms of Service with you, which enables us to provide you with the Services. When we process data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such data.Account Information that you provide us.Information that you provide us when purchasing Products through the Services.Information that you provide us when making a request or inquiry with our customer service representatives.
Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of our business.Account Information that you provide us.Usage Data we collect in connection with your use of the Services.Examples of these legitimate interests include:Protection from fraud or security threatsOperation, maintenance and improvement of our business, products and servicesProvision of customer supportCompliance with legal obligationsCompletion of corporate transactions.
Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
How and With Whom Do We Share Your Data?We share limited Personal Data with vendors, third party service providers, and agents who work on our behalf and provide us with services related to the purposes described in this Privacy and Data Protection Policy or our Terms of Service. We limit this based on the minimum information required for such vendors, third party service providers, and agents to perform the required services. These parties include:Hosting service providers;Email providers;Payment processors;Cloud communication service providers;Shipping providers; andContractors.We also share Personal Data when we believe it is necessary to:Comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies.Protect us, our business or our users, for example to enforce our Terms of Service, prevent spam or other unwanted communications and investigate or protect against fraud.As part of the Services, you will receive from Sharehold email and other communications. You acknowledge and agree that by availing yourself of the Services, you allow Sharehold to send you email and other communication that it determines in its sole discretion relate to your use of the Services.Last, we also share information with third parties when you give us your express consent to do so.Furthermore, Sharehold will NOT buy or sell Personal Data to or from a third party under any circumstances, except solely in the event that we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, in which case Personal Data would be one of the assets that is transferred to or acquired by the third party that is acquiring our assets. HOWEVER, you should know that:Sharehold would only choose to sell its business or assets to, or to be acquired by, an entity that we believe will take a customer-first approach to Personal Data, like Sharehold does; andAny entity acquiring our business or assets would have an obligation to use the Personal Data that comes with it strictly in accordance with this Privacy and Data Protection Policy, as we’ve outlined above in “How Do We Use Your Personal Data?”.You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Data only as set forth in this policy.
How Long Do We Retain Your Personal Data?We retain Personal Data about you for as long as you have an open Account with us or as otherwise necessary to provide you Services, or until you contact us to request deletion (see below). In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. Afterwards, we retain some information in a depersonalized or aggregated form but not in a way that would identify you personally.
Do We Store the Personal Data of Children?As noted in the Terms of Service, we do not knowingly collect or solicit Personal Data from anyone under the age of 18. If you are under 18, please do not attempt to register for the Services or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under age 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at email@example.com.
What Do Users Need to Know?Rights Regarding Your Personal Data:By law, users in the European Union, United Kingdom, Lichtenstein, Norway, or Iceland have certain rights with respect to their Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email us at firstname.lastname@example.org. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
If you are a user of the Services, you have the following rights:Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data. You can also access certain of your Personal Data by logging into your online account.
Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data by emailing email@example.com.
Erasure: You can request that we erase your Account from our systems. To request us to delete your Account, please send an email to firstname.lastname@example.org from the email address we have on file for your Account. We reserve the right to permanently erase your Account information from our systems immediately or promptly after we receive the request, subject only to legal requirements or appropriate exceptions under applicable law. (We also reserve the right to delete Accounts on our own initiative.) Please note that Account deletion may not ensure complete or comprehensive removal of the content or information you have posted on or submitted to the Services, and will not remove content or information that has been stored, shared or re-posted by other users and other third parties.
Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services. You may withdraw your consent by sending an email to email@example.com.
Portability: You can ask for a copy of certain of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
Objection: You can contact us at firstname.lastname@example.org to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
Restriction of Processing: You can ask us to restrict further processing of your Personal Data by contacting us at email@example.com.
Right to File Complaint: You have the right to lodge a complaint about our practices with respect to your Personal Data with the supervisory authority of your country or EU Member State.
Transfers of Personal DataThe Services are hosted in the EU and the US, and operated in Ireland and the US and elsewhere throughout the world through Sharehold and its service providers, where the laws may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Sharehold and will be hosted on EU and US servers and elsewhere throughout the world, and you authorize Sharehold to transfer, store and process your information to and in the EU, the US, and elsewhere throughout the world as necessary to perform our duties in providing you with the Services. Additionally, you understand that your Personal Data may be processed in countries where laws regarding processing Personal Information may be less stringent than in your country. Please contact us at firstname.lastname@example.org with any questions or concerns.
What If You Have Questions Regarding Your Personal Data?If you have any questions about this Privacy and Data Protection Policy or our data practices generally, please contact us using the following information:Shareholddpo@sharehold.com +353 (1) 4433 593 7 Burdett Ave, Sandycove, Co. Dublin, A96 A339, Ireland
Changes to this Privacy and Data Protection Policy:ExSilico Ltd may amend this Privacy and Data Protection Policy from time to time. Use of information we collect now is subject to the Privacy and Data Protection Policy in effect at the time such information is used. If we make changes in the way we use Personal Data, we will notify you by posting an announcement on our Site or Services or sending you an email. Users are bound by any changes to the Privacy and Data Protection Policy when he or she uses the Services after such changes have been first posted.
Effective Date of Privacy and Data Protection Policy: March 12th, 2020