Home / Legal / Privacy Policy

Privacy Policy

October 16, 2024

This Privacy Policy (this “Policy“) applies to the processing of (a) personally identifiable information (“Personal Data“) that NetRoadshow collects through our websites www.netroadshow.com; www.structuredfn.com; www.researchfn.com; www.retailroadshow.com; www.om.netroadshow.com; and www.apparity.com (each a “NRS Website“) from registered users of the Services offered by NetRoadshow (“Registered Users“) and (b) Personal Data transferred to NetRoadshow by its customers for specialized data processing services. We follow this privacy policy in accordance with applicable law in the places where we operate. In some cases, we may provide additional data privacy notices specific to certain products, practices, or regions. Those terms are to be read in conjunction with this policy.

NetRoadshow, Inc. and its group of affiliated companies, Financial Software and Services, Inc., Secure Share Network, LLC, and Apparity, LLC (collectively, “NetRoadshow“) value the trust and confidence of their customers, employees, and business partners and respect individual privacy. NetRoadshow strives to uphold the highest ethical standards in all of its business practices, and collects, uses, and discloses personal information in a manner consistent with the laws of the countries in which it does business. Capitalized terms not defined elsewhere in this Policy are defined in Section 15.

1. Who we are

NetRoadshow provides global business to business services to investment banks, issuers of debt and equity securities, and corporations (collectively, the “Services“). NetRoadshow is committed to supporting its customers’ compliance with all applicable EU data protection requirements, including those set out in the General Data Protection Regulation (“GDPR“). Among other requirements, GDPR requires NetRoadshow to use third-party data processors who guarantee their ability to implement the technical and organizational requirements of the GDPR. We are also prepared to provide our customers with contractual commitments regarding our commitment to implement additional contractual provisions required by the GDPR. Data Processing Addendum: These provisions include our commitment to (i) respond to requests from data subjects to correct, amend or delete personal data; and (ii) be made aware of and report personal data breaches to relevant supervisory authorities and data subjects in accordance with GDPR timeframes.

2. Information we collect

User Information

Registered Users are individuals that represent businesses with whom NetRoadshow or NetRoadshow’s customers and business partners have a business relationship. NetRoadshow collects identifying information from Registered Users including names, addresses, phone numbers, email addresses, IP address, browser type, etc. This information is used for providing the Services, validation of identity, managing transactions, reporting, diagnosing technical problems, other operations related to providing the Services to NetRoadshow’s customers and business partners. NetRoadshow only uses the Personal Data of Registered Users for purposes of providing the Services, responding to support questions, providing activity monitoring to customers, regulatory reporting as required by each country our customers operate in, occasional inquiries about product features, marketing of the NetRoadshow product family, and other matters related to quality of Services.

The legal bases on which we process Registered User, Customer and Usage data are: (1) our legitimate interest to deliver and manage our services, validate user identity, and manage transactions; (2) the legal requirement to comply with and assist our customers to comply with securities and regulatory requirements. Registered User data is retained indefinitely and is only deleted upon user or customer request. Customer and Usage data is retained for two, five, seven, or ten years depending on the regulatory standards required in the country of operation.

Documents and related information

In connection with certain Services (e.g., Document Delivery Services and Data Room Services), Registered Users have the ability to add comments and annotations to documents which are stored and processed by NetRoadshow, and up load files and due diligence information which could include Personal Data. NetRoadshow has no control over the Personal Data which NetRoadshow customers and business partners upload into the Services.

Usage data

NetRoadshow may also track and analyze non-identifying and aggregate usage and volume statistical information from Registered Users, and we may provide such information to third parties that assist us for these purposes. NetRoadshow may collect analytics data, or use third-party analytics tools and services, to measure traffic and usage of the Services. These tools collect information sent by the browser or mobile device or a Registered User, including the pages visited and other information that assists NetRoadshow in administering and improving the Services.

NetRoadshow has implemented Google Analytics to improve the quality of the user experience and administer and improve the Services. As implemented at NetRoadshow, the Google Analytics cookie collects technology data including browser, operating system, screen resolution, screen colors, browser feature/java support; session data, such as the number of new users and returning users, frequency data, and recency data, and engagement; and geographic data, including language and location. You may obtain more information about data collected by Google Analytics here. You can opt-out of Google Analytics by installing a plug-in for major browsers available from Google here. You can opt-out of Google Analytics by installing a plug-in for major browsers available from Google here.

NetRoadshow also implements FullStory to Provide assistance in navigation, provide assistance during the visit, analyze your use of our services in order to improve the quality of the user experience and help diagnose user issues. As implemented at NetRoadshow, and in addition to the data collected by Google Analytics noted above, the FullStory cookie also collects information on your use of the Services, such as pages visited, links clicked, non-sensitive text entered, and mouse movements, as well as information more commonly collected such as the referring URL, browser, operating system, and Internet Protocol (“IP”) address. You may obtain more information about data collected by FullStory here.

If you wish to prevent all websites using the FullStory Services to be able to record activity, you can opt-out of the FullStory Services. Opting out will create a cookie that tells FullStory to turn off recording on any site which uses the FullStory Services. The cookie is available here.

3. How we collect your information

We collect information you provide to us when you sign up for an account on one of our applications, and information provided to us by employers when they register you as an employee-user for our applications. We collect information through a variety of technologies and analytics tools, including when you visit our sites and applications or use our applications during the course of routine business. We acquire information from other trusted sources to update or supplement the information you provided. Applicable law may require that you authorize the third party to share your information with us before we can acquire it.

An individual is offered the opportunity to choose (opt out) whether personal information is (i) to be disclosed to a third party or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individuals. All users signing up for a MyNetRoadshow account must opt in to our privacy policy as well as our terms of use before completing the sign up process.

4. Processing of personal data

The Services may include the transfer of Personal Data to NetRoadshow. NetRoadshow uses the Personal Data solely to provide Services to its customers. When NetRoadshow receives Personal Data, NetRoadshow is acting as the “processor” and its customer or business partner is the “controller” of such data. NetRoadshow’s customers or business partners retain responsibility for obtaining the appropriate consents or other lawful basis for processing such Personal Data under applicable EU, US-California, and Singapore law.

With respect to data generated as part of the use of NetRoadshow Services, including user name and password, NetRoadshow acts as a controller. See Section 2 for additional information.

5. Rights of data subjects

Any visitor to an NRS Website may request access to, and the opportunity to update, correct, transfer, or delete, his or her Personal Data by contacting our Chief Privacy Officer (chiefprivacyofficer@netroadshow.com) for assistance. If you are a resident of the EEA about whom NetRoadshow holds Personal Data on behalf of one of our customers or business partners, you may request access to, and the opportunity to update, correct, or delete, such Personal Data from our customer. If we do not have authority to permit you to access, update, correct, or delete, your Personal Data, we will assist you in contacting our customer who can handle your request. You are entitled to request access to the personal information we hold about you and that we amend or delete it.

Please be aware that if you do not allow us to collect personal information from you, we may not be able to deliver certain products and services to you. If collection of personal information is mandatory, we will make that clear at the point of collection so that you can make an informed decision whether to participate. If you have questions about the specific personal information about you that we process or retain, and your rights regarding that personal information, please contact (chiefprivacyofficer@netroadshow.com).

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, NetRoadshow commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Matthew Latzman, CISO at NetRoadshow at: chiefprivacyofficer@netroadshow.com.

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, NetRoadshow commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.

Individuals have the possibility, under certain conditions, to invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other DPF mechanisms. Please see Annex I for additional information: ANNEX I Introduction.

6. Responsibilities and management

NetRoadshow has a Director of Privacy who is responsible for overseeing our information security program, including our compliance with GDPR. The Director of Privacy reviews and approve any material changes to this program as necessary. You may direct questions, concerns, or comments regarding this Policy to chiefprivacyofficer@netroadshow.com.

NetRoadshow will maintain, monitor, test, and upgrade information security policies, practices, and systems to assist in protecting the Personal Data that it collects while providing Services to its customers.

All of our employees and consultants are required to maintain the confidentiality of Personal Data. Any employee or consultant that NetRoadshow determines is in violation of these policies will be subject to discipline, up to and including termination of employment and/or criminal prosecution.

7. Data security, integrity, and retention

NetRoadshow uses commercially reasonable and appropriate security measures to protect against unauthorized access, alteration, disclosure, or destruction of Personal Data of Registered Users and Personal Data. We have implemented technical, administrative, and physical security measures that are designed to protect personal information from unauthorized access, disclosure, use, and modification. All Personal Data is stored and processed in encrypted computer databases and servers. NetRoadshow uses Secure Socket Layer (TLS 1.2) technology to protect Personal Data using both server authentication and data encryption during transmission. We regularly review our security procedures to consider appropriate new technology and methods.

While we strive to protect your data, no security measures are perfect or impenetrable, despite our best efforts. We cannot guarantee that unauthorized access, hacking, data loss or a data breach will never occur, and we cannot warrant the security of any information that you provide to us. You are responsible for securing and maintaining the privacy of any password(s) and account registration information used with NetRoadshow.

We will retain your personal information for the length of time needed to fulfill the purposes outlined in this privacy policy unless a longer retention period is required or permitted by law.

8. Disclosure of personal information

Except as otherwise stated in this Policy, NetRoadshow does not disclose or share Personal Data with third parties. NetRoadshow does not sell, rent, or otherwise provide Personal Data to any third parties for marketing or promotional purposes.

Disclosure of user information and activity may be made to NetRoadshow customers for purposes of providing audit logs with respect to the customer’s data hosted by NetRoadshow. NetRoadshow retains the right to disclose Personal Data as required by law, such as to comply with a subpoena or similar legal process to the extent provided in the agreements with NetRoadshow and its customers or to respond to a government request. NetRoadshow may also may be required to disclose Personal Data in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

9. Data transfers, storage, and processing globally

We are a global business. We may transfer your Personal Data to countries other than your own country, including to the United States. These countries may have data protection rules that are different from your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfers. In certain situations, we may be required to disclose Personal Data in response to lawful requests from officials (such as law enforcement or security authorities). Wherever your Personal Information is transferred, stored or processed by us, we will take reasonable steps to safeguard the privacy of your personal information.

In the context of an onward transfer, NetRoadshow has the responsibility for the processing of personal information it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on its behalf. NetRoadshow shall remain liable under the DPF Principles if the third party agent processes such personal information in a manner inconsistent with the DPF Principles, unless NetRoadshow can prove that it is not responsible for the event giving rise to the damage.

Where applicable law requires a data transfer mechanism, we use one or more of the following:

  • Transfers to certain countries or recipients that are recognized as having an adequate level of protection for Personal Data under applicable law.
  • EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner’s Office.
  • Or other legal methods available to us under applicable law.

10. California residents’ rights

Notice to California Residents: If you are a California resident, you may have certain additional privacy rights. This notice to California residents is provided under California law, including the California Consumer Privacy Act (“CCPA”), Cal. Civ. Code 1798.100, et seq. This notice supplements our privacy policy by explaining your privacy rights if you are a California resident, providing our “notice at collection,” and providing certain mandated disclosures about our treatment of California residents’ information, both online and offline.

11. UK & EU residents’ rights

Notice to UK & EU Residents: If you are an EU or UK resident, you may have certain additional privacy rights.

Your personal data is primarily used to provide you with NetRoadshow applications and services you request. It may also be used to comply with legal obligations we are subject to or to fulfill our legitimate interests, such as to personalize your experience, develop and improve our services or to detect illegal activities.

You have a number of rights including the right to request access to, change, or remove your personal data. Please read the remainder of our privacy policy to learn more about deleting your account.

Our Chief Privacy Officer can be contacted by emailing chiefprivacyofficer@netroadshow.com.

You have a right to lodge a complaint with your local Data Protection Supervisory Authority or with the UK Information Commissioner’s Office: https://ico.org.uk/your-data-matters/

12. Brazilian residents’ rights

Notice to Brazilian Residents: If you are a Brazilian resident, you may have certain additional privacy rights.

Your personal data is primarily used to provide you with NetRoadshow applications and services you request. It may also be used to comply with legal obligations we are subject to or to fulfill our legitimate interests, such as to personalize your experience, develop and improve our services or to detect illegal activities.

You have a number of rights set forth in Brazil’s data protection legislation including but not limited to the right to confirm the existence of the processing of your personal data, request access to, change, or remove your personal data, or to change your marketing preferences (including withdrawing your consent at any time) – please read the remainder of our privacy policy to learn more about deleting your account. Our Chief Privacy Officer can be contacted by emailing chiefprivacyofficer@netroadshow.com.

13. Third Party Processors

Third Party Service Provider Purpose Entity Country Website Applicable NRS Product
Amazon AWS Data hosting United States, Ireland, Germany https://aws.amazon.com/ All Products
Mailgun Email service provider United States https://www.mailgun.com/ NetRoadshow, NetRoadshow Live, ResearchFN, NetRoadshow Dataroom, NetRoadshow Conferencing, Wall Crossing
DataValidation Email verification United States https://www.datavalidation.com/ NetRoadshow, ResearchFN
Twilio Communications technology provider and email provider (SendGrid product) United States https://www.twilio.com/
https://www.sendgrid.com/
NetRoadshow, NetRoadshow Conferencing, NetRoadshow Dataroom, NetRoadshow Conferencing, DealSite
Google User analytics, Tag Manager United States https://marketingplatform.google.com/about/analytics/ All Products
Fullstory User analytics United States https://www.fullstory.com/ NetRoadshow, ResearchFN, Wall Crossing, DealSite, LoansFN
Lindenbaum GmbH Communications technology Germany https://www.lindenbaum.eu/ NetRoadshow, NetRoadshow Conferencing
Zoom Communications technology United States https://zoom.us/ NetRoadshow Live, NetRoadshow Conferencing
Domo User analytics United States https://www.domo.com All Products
Hubspot CRM United States https://www.hubspot.com/ NetRoadshow
Salesforce CRM United States http://www.salesforce.com/ All Products
Way With Words Audio Transcription United States http://www.waywithwords.net/ NetRoadshow Conferencing
Rev Audio Transcription United States https://www.rev.com/ NetRoadshow Conferencing
TTE Transcripts Worldwide Audio Transcription United States http://www.ttetranscripts.com/ NetRoadshow Conferencing
hCaptcha Bot detection United States https://www.hcaptcha.com/privacy NetRoadshow, ResearchFN

14. Commitment to comply with EY-U.S. DPF and the UK extension to the EU-U.S. DPF and the Swiss-U.S. DPF

NetRoadshow complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. NetRoadshow has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. NetRoadshow has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

The Federal Trade Commission has jurisdiction, investigatory and enforcement powers over NetRoadshow’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

15. Changes to this privacy policy

From time to time, we may change this privacy policy to accommodate new technologies, industry practices, regulatory requirements or for other purposes. We will provide notice to you if these changes are material and, where required by applicable law, we will obtain your consent. Notice may be emailed to you at the last email address you provided us, by posting notice of such changes on our applications, or by other means, consistent with applicable law. Neither this policy nor any update to it will affect or modify any contract between NetRoadshow and its customers.

16. Definitions

Data Room Services” means a secure on-line repository for offering and due-diligence materials for debt offerings, equity offerings, and private transactions made by or for the account of a NetRoadshow customer.

Document Delivery Services” means the electronic delivery of securities transaction related materials, such as preliminary, amended, and final, offering memoranda and prospectuses to Registered Users.

Personal Information” means information that identifies (whether directly or indirectly) a particular individual, such as the individual’s name, postal address, email address, and telephone number. When anonymous information is directly or indirectly associated with personal information, the resulting information also is treated as personal information.

Application” means a program or service operated by us that may be displayed on various online environments.

17. Contact Us

If you have any questions or complaints about this Policy, please contact us at chiefprivacyofficer@netroadshow.com.