Trust & Compliance Centre > Privacy Policy
Privacy Policy
Effective date: September 1st, 2021
At Vested Impact, we know you care about how your personal information is used and shared, and we take your privacy seriously. Please read the following to learn more about our Privacy Policy.
By using or accessing the Service in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy, and you hereby consent that we will collect, use, and share your information in the following ways.
Remember that your use of Vested Impact's Service is at all times subject to our Terms of Service, which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Service. Our Privacy Policy applies to all users of the Vested Impact website: www.vestedimpact.co.uk (and any subdomains).
What does this Privacy Policy Cover?
This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Service. "Personal Data" means any information that identifies or relates to a particular individual and also includes information referred to as "personally identifiable information" or "personal information" under applicable data privacy laws, rules, or regulations. This Privacy Policy does not cover the practices of companies we don't own or control or people we don't manage.
Changes to this Privacy Policy
Vested Impact may change this Privacy Policy from time to time. Laws, regulations, and industry standards evolve, which may make those changes necessary, or we may make changes to our Service or business. We will post the changes to this page and encourage you to review our Privacy Policy to stay informed. If we make changes that materially alter your privacy rights, we will do our best to alert you to changes by placing a notice on the Vested Impact website, by sending you an email, and/or by some other means. Please note that if you've opted not to receive legal notice emails from us (or you haven't provided us with your email address), those legal notices will still govern your use of the Service, and you are still responsible for reading and understanding them.
If you use the Service after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.
What Personal Data does Vested Impact Collect?
We collect Personal Data about you from:
- You;
- when you provide such information directly to us, and
- when Personal Data about you is automatically collected in connection with your use of our Service.
Vested Impact also creates profiles of companies, which we call "Profiles," from different sources. Once we have collected information (primarily business-related information) about a person or company, we combine multiple mentions of the same person or company into a Profile. Profiles are then made available to users of the Service, and our customers and strategic partners.
When we create or enhance Profiles about company's, we may collect this information from multiple sources, including:
- Publicly-available web sources that we scan using technology or manual methods.
- User contributions about companies.
- Research conducted internally by Vested Impact.
- Other companies and data partners that license information to us.
What Categories of Personal Data We Collect
| Category of Data | Source of Data | Purpose of Processing | Grounds for Processing (e.g. contractual necessity, legitimate interest, consent) | Specific Legitimate Interest (if applicable) |
|---|---|---|---|---|
| Customer Account Data (e.g. first last name, email, IP address, company) | Data Subject | Analytics | Legitimate Interest | Monitoring and conducting analytics on website & app use, pages/links clicked, traffic demographics, patterns of navigation, on potential security/spam breach, on performance issues, etc. |
| Customer Account Data (e.g. first last name, email, company) | Data Subject | Customer Success Communication | Legitimate Interest | Personalised service and communications related to the customer's use of the product |
| Customer Account Data | Data Subject | Marketing Campaign (email, list creation, ads) | Legitimate Interest | Personalization, market research, targeted advertisement, or direct marketing |
| Customer Account Data (e.g. first last name, device type, browser) | Data Subject | Product Development | Legitimate Interest | Improving performance, troubleshooting bugs, other internal development needs |
| Customer Account Data (e.g. first last name, email, company) | Data Subject | Sales Communication | Legitimate Interest | Targeted advertisement or direct marketing |
| Customer Account Data (e.g. first last name, email) | Data Subject | Using Vested Impact Products | Contractual Necessity | Contractual Necessity |
| Billing Data (e.g. first last name, card type, card country) | Data Subject | Analytics | Legitimate Interest | Monitoring and conducting analytics on website & app use, pages/links clicked, traffic demographics, patterns of navigation, on potential security/spam breach, on performance issues, etc. |
| Billing Data (e.g. first last name, card type, card country) | Data Subject | Customer Success Communication | Legitimate Interest | Personalised service and communications related to the customer's use of the product |
| Billing Data (e.g. first last name, card type, card country) | Data Subject | Product Development | Legitimate Interest | Improving performance, troubleshooting bugs, other internal development needs |
| Customer Support Data (e.g. first last name, email, address) | Data Subject | Analytics | Legitimate Interest | Monitoring and conducting analytics on website & app use, pages/links clicked, traffic demographics, patterns of navigation, on potential security/spam breach, on performance issues, etc. |
| Customer Support Data (e.g. first last name, email, address, last 4 digits of credit card) | Data Subject | Customer Success Communication | Legitimate Interest | Personalised service and communications related to the customer's use of the product |
| Customer Support Data (e.g. first last name, email) | Data Subject | Marketing Campaign (email, list creation, ads) | Legitimate Interest | Personalization, market research, targeted advertisement, or direct marketing |
| Customer Support Data (e.g. first last name, email) | Data Subject | Product Development | Legitimate Interest | Improving performance, troubleshooting bugs, other internal development needs |
| Customer Support Data (e.g. first last name, email) | Data Subject | Sales Communication | Legitimate Interest | Targeted advertisement or direct marketing |
| Customer Support Data (e.g. first last name, email) | Data Subject | Using Vested Impact Products | Contractual Necessity | Contractual Necessity |
| User Session Data (e.g. page url, utms) | Data Subject | Advertising | Legitimate Interest | Personalization, market research, targeted advertisement, or direct marketing |
| User Session Data (e.g. page url) | Data Subject | Mobile App Marketing | Legitimate Interest | Personalization, market research, targeted advertisement, or direct marketing |
| User Session Data (e.g. utms, logged in, xsrf token) | Data Subject | Using Vested Impact Products | Legitimate Interest | Maintain logged-in state during a single browsing session. Maintain their logged in state across browsing sessions. Enable users to log back in when a new session is started. Prevent cross-site request forgery attacks. Product feature rollout, conducting analysis. Ad performance and conversion tracking. Personalization of Web Content |
The following sections provide additional information about how we collect your Personal Data.
Information You Provide to Us
We receive and store any information you knowingly provide to us. For example, through the registration process and/or through your account settings, we may collect Personal Data such as your name, email address, phone number, and third-party account credentials (for example, your log-in credentials for LinkedIn, e-mail, or other third-party sites). If you provide your third-party account credentials to us or otherwise sign in to the Service through a third party site or service (such as Salesforce, Twitter, Facebook, or Google), you understand some content and/or information in those accounts ("Third Party Account Information") may be transmitted into your account with us, and that Third Party Account Information transmitted to our Service is covered by this Privacy Policy. Certain information may be required to register with us or to take advantage of some of our features.
We may communicate with you if you've provided us the means to do so. Also, we may receive a confirmation when you open an email from us, which helps us improve our Service. If you do not want to receive communications from us, please contact us at info@vestedimpact.co.uk.
Information Collected Automatically
Like many other commercial websites, we may also gather information in connection with your use of the Site or Service through the use of cookies and other similar technologies such as server logs, pixel tags, web beacons, user website activity and JavaScript (collectively, "Cookies") to enable us to recognize your web browser or device and tell us how and when you visit and use our Service, to analyze trends, to learn about our user base, and to operate and improve our Service. Cookies are small pieces of data-usually text files-placed on your computer, tablet, phone, or similar device when you use that device to visit our Service. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). Please note that because of our use of Cookies, the Service does not support "Do Not Track" requests sent from a browser at this time.
We use the following types of Cookies:
- Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of our Service. Disabling these Cookies may make certain features and services unavailable.
- Functional Cookies. Functional Cookies are used to record your choices and settings regarding our Service, maintain your preferences over time and recognize you when you return to our Service. These Cookies help us to personalize our content for you, greet you by name, and remember your preferences (for example, your choice of language or region).
- Performance/Analytical Cookies. Performance/Analytical Cookies allow us to understand how visitors use our Service such as by collecting information about the number of visitors to the Service, what pages visitors view on our Service and how long visitors are viewing pages on the Service. Performance/Analytical Cookies also help us measure the performance of our advertising campaigns in order to help us improve our campaigns and the Service's content for those who engage with our advertising. For example, Google, Inc. ("Google") uses cookies in connection with its Google Analytics services. Google's ability to use and share information collected by Google Analytics about your visits to the Service is subject to the Google Analytics Terms of Service and the Google Privacy Policy. You have the option to opt-out of Google's use of cookies by visiting the Google advertising opt-out page or obtaining the Google Analytics Opt-out Browser Add-on .
- Retargeting/Advertising Cookies. Retargeting/Advertising Cookies collect data about your online activity and identify your interests so that we can provide advertising that we believe is relevant to you. For more information about this, please see the section below titled "Information about Interest-Based Advertisements."
You can decide whether or not to accept Cookies through your internet browser's settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your computer. If you do this, however, you may have to manually adjust some preferences every time you visit a site, and this may cause some services and functionalities to not work.
To explore what Cookie settings are available to you, look in the "preferences" or "options" section of your browser's menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit www.allaboutcookies.org/ .
How We Use Your Personal Data
We process Personal Data to operate, improve, understand and personalize our Service. We use Personal Data for the following purposes:
- To meet or fulfill the reason you provided the information to us.
- To communicate with you about the Service, including Service announcements, updates or offers.
- To provide support and assistance for the Service.
- To create and manage your Account or other user profiles.
- To personalize your experience, website content and communications based on your preferences, including targeted offers and ads served through the Service.
- To process orders or other transactions.
- To respond to user inquiries and fulfill user requests.
- To market, improve, and develop the Service, including testing, research, analysis, and product development (including creation, enhancement, and distribution of Profiles).
- To protect against or deter fraudulent, illegal or harmful actions and maintain the safety, security and integrity of our Service.
- To comply with our legal or contractual obligations, resolve disputes, and enforce our Terms of Service.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- For any other business purpose stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws.
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.
How and With Whom Do We Share Your Data?
We share Personal Data with vendors, third party service providers and agents who work on our behalf and provide us or you with services related to the purposes described in this Privacy Policy or our Terms of Service. These parties include:
- Payment processors
- Fraud prevention service providers
- Staff augmentation and contract personnel
- Hosting service providers
- Marketing service providers
- Product development service providers
- Customer success providers
We also share Personal Data when necessary to complete a transaction initiated or authorized by you or provide you with a product or service you have requested. In addition to those set forth above, these parties also include:
- Other users (where you post information publicly, direct us to share the information (such as with other members of your team), or as otherwise necessary to effect a transaction initiated or authorized by you through the Services).
We also share Personal Data when we believe it is necessary to:
- Comply with applicable law or respond to valid legal process, including requests from law enforcement or other government agencies
- Protect us, our business or our users, for example to enforce our terms of service, prevent spam or other unwanted communications and investigate or protect against fraud
- Maintain the security of our products and services
We also share information with third parties when you give us consent to do so.
If we choose to buy or sell assets, user information is typically one of the transferred business assets. Moreover, if we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party, and we would share Personal Data with the party that is acquiring our assets. You acknowledge that such transfers may occur, and that any acquirer of us or our assets may continue to use your Personal Information as set forth in this policy.
What Security Measures Do We Use?
We seek to protect Personal Data using appropriate technical and organizational measures based on the type of Personal Data and applicable processing activity.
- All Vested Impact staff undertake Data Protection Training
- The Vested Impact website uses SSL (https)
- User accounts and sign on is provided by Auth0 to protect your login information and passwords
- The authenticity of request methods are verified to prevent CSRF (cross-site request forgery) attacks
- Vested Impact employees use Single Sign-On (SSO) and passwords and enable screen locking
- Access to Azure and Payment Processors is limited and requires Two-Factor Authentication (2FA)
- Azure assets are scanned using the Microsoft defender and Azure analysis tools
- Vested Impact performs third-party penetration testing
How Long Do We Retain Your Personal Data?
We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide you Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. Afterwards, we retain some information in a depersonalized or aggregated form but not in a way that would identify you personally.
Personal Data of Children: As noted in the Terms of Service, we do not knowingly collect or solicit Personal Data from anyone under the age of 16. If you are under 16, please do not attempt to register for the Services or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under age 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at info@vestedimpact.co.uk
What Rights Do You Have Regarding Your Personal Data?
You have certain rights with respect to your Personal Data, including those set forth below. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
Your Personal Data rights include:
- Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data by emailing info@vestedimpact.co.uk.
- Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can also correct some of this information directly by emailing info@vestedimpact.co.uk.
- Erasure: You can request that we erase some or all of your Personal Data from our systems.
- Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
- Portability: You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
- Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
- Restriction of Processing: You can ask us to restrict further processing of your Personal Data.
- Right to File Complaint: You have the right to lodge a complaint about Vested Impact's practices with respect to your Personal Data with the supervisory authority of your country or EU Member State.
Transfers of Personal Data: The Services are hosted and operated in the United Kingdom ("U.K")By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Vested Impact in the U.K. and will be hosted on U.K. servers, and you authorize Vested Impact to transfer, store and process your information to and in the U.K., and possibly other countries. You hereby consent to the transfer of your data to the U.K.
Contact Information:
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data, your choices and rights regarding such use, please do not hesitate to contact your Vested Impact representative or email us at info@vestedimpact.co.uk.
Let's measure what matters
Complete the form and tell us a bit about your needs.
One of our team will be in
contact to see how we can help.