Data Protection Policy
Effective
How Evolutions protects the personal data it controls and the data customers entrust to us as a processor — the roles, safeguards, transfers, and rights that apply to each.
1. Overview
Evolutions International Inc., a Delaware corporation (“Evolutions,” “we,” “us,” or “our”), builds operating-system software for global asset management — including our platform for registered investment advisers and our fund-administration tools for private-fund managers. This Data Protection Policy (the “Policy”) sets out how we protect personal data across our business: the data we control ourselves, and — once our platform is active — the data our business customers entrust to us to process on their behalf.
This Policy is written for customers, their end clients, and regulators who want a single view of our data-protection commitments. It is distinct from our Privacy Policy, which is the notice we give to the people whose data we control directly — visitors to our website and the business contacts who deal with us. Where this Policy and a written agreement we have signed with a customer disagree about that customer’s data, the agreement prevails.
2. Scope & roles
Data-protection law assigns a role to everyone who touches personal data, and our obligations follow from that role. We act in two capacities:
- As a controller, for the personal data we decide to collect and use for our own purposes — our website, our contact and marketing channels, and our relationships with business contacts at customers, prospects, and partners. Our Privacy Policy is the notice that goes with that role.
- As a processor (service provider), for the data a business customer places in our platform for us to handle on its behalf — for example, information about that customer’s own funds, investors, and counterparties. The customer is the controller; we process only under its documented instructions, through our customer agreement and any data processing addendum.
Most of this Policy applies whichever role we are in — the safeguards, the transfers, and the breach discipline do not change with the role. Where a commitment is specific to one role, we say so.
3. Categories of personal data
As a controller we handle a deliberately small set of categories, because our site is a pre-launch page and we collect no more than our correspondence and our relationships require:
- Identifiers and contact details — name, email address, phone number, employer, and job title, when provided.
- Professional information — role, organization, and other professional context shared with us.
- Communications — the content of messages, inquiries, and correspondence.
- Technical and usage data — IP address, browser and device type, pages requested, and the user-agent string recorded when the contact form is submitted, as described in our Privacy Policy.
As a processor for our business customers, the categories depend on what the customer places in the platform and what the services need. For fund-administration and adviser workflows this will typically include investor and counterparty identifiers, contact and ownership details, and the records needed to run a fund or an advisory book. We do not seek special-category data, and we ask customers not to place it in the platform unless a service requires it and we have agreed the safeguards for it.
4. Legal bases
Where the GDPR or UK GDPR applies, every processing purpose needs a legal basis. Our bases as acontroller are set out in full in the Privacy Policy, and are in summary: legitimate interests for correspondence, business-contact records, security, and our opt-out analytics; legal obligation for the records the law requires us to keep; and consent only where we ask for it and you give it.
As a processor, we do not pick our own basis for customer data: we process it under the customer’s instructions, and it is the customer — as controller — that identifies and records the legal basis. If a customer asks us to do something with its data that we believe lacks a lawful basis, we raise that with the customer rather than proceed.
5. How we use information
As a controller we use personal data to:
- respond to inquiries and communicate with you;
- evaluate, establish, and manage business relationships;
- operate, secure, and improve our services;
- comply with legal obligations and enforce our agreements; and
- protect the rights, property, and safety of Evolutions, our users, and others.
As a processor we use customer data only to deliver the services that customer has engaged us for, and to meet the duties the law places on us directly. We do not use data one customer entrusts to us for the benefit of another customer, and we do not use it to build profiles or to train models for our own purposes.
7. International transfers
Evolutions is based in the United States, and we process and store information there. When personal data moves across borders — including when a provider in another country receives it — we put an appropriate safeguard in place before the transfer. Our full account of how we think about transfers, including when a direct message to us is not itself a restricted transfer and which safeguard we rely on for each provider, is in the Privacy Policy.
In short: where a provider’s agreement already incorporates the European Commission’s Standard Contractual Clauses we rely on them; where a provider is self-certified under the EU-US Data Privacy Framework we treat that as one factor, not the whole answer; and where no safeguard is in place yet we are working to put one in place and we keep the exposed data minimal in the meantime. We will not claim a safeguard we do not have.
8. Retention
We keep personal data only as long as necessary for the purposes we hold it for and to meet legal, tax, and accounting requirements, after which we delete or de-identify it. The criteria we apply are set out in the Privacy Policy.
For customer data we process as a processor, the retention clock belongs to the customer: we keep it while the service is live, then delete or return it at the customer’s election, unless a law, regulation, or our own record-keeping duty requires us to hold it longer. Financial record-keeping rules often set the longest periods, and we will tell a customer which records we must retain and for how long where that affects their data.
9. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data and the risks of processing it, in line with GDPR Article 32 and equivalent obligations. In practice that includes, at a minimum:
- encryption of personal data in transit using current, reputable protocols;
- access controls and authentication, so people reach only the data their role requires;
- reputable, security-assessed infrastructure and hosting providers;
- logging and monitoring to detect and respond to anomalies;
- secure development practices, including input validation and dependency management; and
- confidentiality obligations on our personnel and, by contract, on our subprocessors.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. What we commit to is treating security as a continuing discipline, not a one-time checkbox — and to telling you straight when something goes wrong, as set out next.
10. Breach response
We take every suspected personal-data breach seriously. Our response follows the same discipline whatever our role: detect and contain, assess the impact, notify the people the law says must be told, and remediate.
Where the GDPR or UK GDPR applies, we report a personal-data breach to the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk. Where a breach is likely to result in a high risk to individuals, we also tell those individuals without undue delay, except where the law permits otherwise.
Where the affected data belongs to a business customer and we are the processor, we notify that customer without undue delay and help it meet its own notification duties. A subprocessor must tell us of any breach affecting our or our customers’ data without undue delay, so the chain of notification stays intact.
11. Privacy by design
We build data protection into our products and processes from the outset rather than bolting it on afterwards. That means data minimization by default — collecting no more than a feature needs — privacy-conscious defaults, and a review of the data-protection impact of new features and significant changes before they ship. Where a processing activity is likely to carry a high risk, we carry out a data protection impact assessment and act on what it finds before we proceed.
12. Data subject rights
Where we act as a controller, the rights you have over your personal data — access, correction, deletion, restriction, portability, objection, and the withdrawal of consent — and how to exercise them are set out in Your privacy rights in the Privacy Policy.
Where we act as a processor for a business customer, those rights belong to the customer to field: it is the controller, and the individual should direct a request to it. We support our customers in answering such requests within the time the law allows, providing the information we hold and acting on the customer’s documented instructions.
13. Governance & accountability
Data protection at Evolutions is owned at the top and reviewed regularly. We maintain records of our processing activities, keep this Policy and the Privacy Policy current, and hold our people to confidentiality and secure-handling expectations. We have not appointed an Article 27 representative or a data protection officer because our processing does not currently meet the thresholds that require one; the contact point for any data-protection question is the one set out below.
14. Changes to this policy
We may update this Policy from time to time. When we do, we will revise the “Effective” and “Last updated” dates above and, for material changes that affect customer data, we will also notify affected customers directly as their agreement provides.
15. Contact us
Questions about this Policy, or requests relating to personal data we control, may be sent to privacy@evolutionsmail.example.hq.com or by mail to Evolutions International Inc., 2817 Merrimac St, Fort Worth, TX 76107.