
Privacy Policy
INTRODUCTION
-
This Privacy Notice (the “Privacy Notice”) explains how 90K and its group companies (“90K”) collect, use, and protect the personal data of visitors (“Visitors”) to www.90kcapital.com and its subdomains (the “Website”).
-
By using the Website, Visitors agree to this Privacy Notice. 90K encourages all Visitors to read it carefully to understand how their information is handled.
-
Unless stated otherwise herein, references shall be made to the 90K Terms of Use, and all the defined terms used in this Privacy Notice, shall have the same meaning as the one given to them in these terms, as the case may be.
DEFINITIONS
-
“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control”, for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
-
“CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 et. Seq, and its implementing regulations, as may be amended from time to time.
-
“Controller” means 90K EU Sp. z o.o., a company organized under the laws of Poland, with its registered address at Piotrkowska No. 116, suite no. 52, city Łódź, Poland, and registration number: 0001137765
-
The terms “Controller“, “Member State“, “Processor“, “Processing” and “Supervisory Authority” shall have the same meaning as in the GDPR. The terms “Business”, “Business Purpose”, “Consumer” and “Service Provider” shall have the same meaning as in the CCPA. For the purpose of clarity, within this Privacy Notice, “Controller” shall also mean “Business”, and “Processor” shall also mean “Service Provider”, to the extent that the CCPA applies. In the same manner, Processor’s Sub-processor shall also refer to the concept of service Provider.
-
“Data Protection Laws” means all applicable and binding privacy and data protection laws and regulations, including those of the European Union, the European Economic Area and Visitors' Member States, Switzerland, the United Kingdom, Canada, Israel and the United States of America, including the GDPR, the UK GDPR, and the CCPA, applicable to, and in effect at the time of, the Processing of Personal Data hereunder.
-
“Data Subject” means the identified or identifiable person to whom the Personal Data relates.
-
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
-
“Personal Data” or “Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable natural person or Visitor, which is processed by 90K solely on behalf of the Visitor.
-
“Standard Contractual Clauses” means (a) in respect of transfers of Personal Data Subject to the GDPR, the Standard Contractual Clauses between controllers and processors, and between processors and processors, as approved by the relevant jurisdiction’s authorities (the EU, the UK, Switzerland).
-
“Sub-processor” means any third party that carries out specific Processing activities of Personal Data under 90K's instructions.
-
“UK GDPR” means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).
PRINCIPLES
While Processing Personal Data, 90K will respect the following principles:
-
Fairness and Lawfulness - when Processing Personal Data, the individual rights of the Data Subjects must be protected. Personal Data must be collected and processed lawfully, in a fair manner, in good faith and must be proportionate to the objective.
-
Purpose Limitation - Personal Data handled by 90K should be adequate and relevant to the purpose for which they are collected and processed. This requires, in particular, ensuring that the types of Personal Data collected are not excessive for the purpose for which they are collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation.
-
Transparency - the Data Subjects must be informed of how Visitors' Personal Data is being handled. When the Personal Data is collected, the Data Subject must be informed of:
-
The existence of the present Privacy Notice
-
The identity of the Controller
-
The purpose of Personal Data Processing
-
Whether the Personal Data is disclosed to Third-parties
4. Accuracy - Personal Data kept on file must be correct and if necessary, kept up to date. Inaccurate or incomplete Personal Data should not be kept on file and deleted.
PRIVACY BY DESIGN
-
90K will, both at the time of the determination of the means for Processing and at the time of the Processing itself, implement appropriate technical and organizational measures in order to meet the requirements of the applicable Data Protection Laws, and protect Visitors' rights.
-
90K will implement appropriate technical and organizational measures for ensuring that, by default, only Personal Data which are necessary for each specific purpose of the Processing are processed. This obligation applies to the amount of Personal Data 90K collects, the extent of the Processing, the period of storage and accessibility.
COLLECTED DATA
90K may collect the following types of Personal Data when Visitors visit the Website, and interact and communicate with 90K through any media or channel.
-
Data 90K collects automatically
When Visitors browse the Website, even if Visitors do not sign up to a mailing list and do not contact 90K, 90K automatically collects:
-
Browser events
-
Browser version
-
Device ID
-
Current URL
-
Initial referrer
-
Initial referring domain
-
Operating system
-
Other details of visits to the Website, including traffic data and location data.
-
Information about computer and internet connection, including IP address, operating system, screen height, width
2. Data Visitors provide to 90K -
Email address for the purposes of the newsletter subscription
-
Name, email address, and the content of your message when you contact us by email
3. 90K does not collect sensitive Personal Data, nor are 90K’s services directed to persons under the age of eighteen (18), and 90K does not knowingly collect or process the Personal Data of such persons.
PURPOSES AND LEGAL BASIS
The following table describes the various purposes for which 90K collects and Processes Personal Data. Please note that not all of the uses below will be relevant to every Visitor.
Purpose
Description
Legal basis
Improving 90K's Website
Analyzing overall trends and helping us improve the user experience on 90K's Website
Legitimate interest in providing a relevant and well-functioning website for the benefit of 90K's website visitors
Promoting the security of 90K's Website
Tracking use of 90K's Website and verifying and investigating any suspicious activity
Legitimate interest in promoting the safety and security of 90K's websites and in protecting 90K's rights and the rights of others
Sending communications
Sending marketing information via the newsletter
Legitimate interest in conducting marketing via the newsletter subscription
Responding to email inquiries
Legitimate interest in responding to inquiries and providing information about our services
Aggregating data for statistical, research, Website improvement, and other purposes. Aggregated data cannot lead to Visitors' identification
Legitimate interest in minimizing the amount of Personal Data processed as part of the noted processing activity
Complying with legal obligations
Cooperating with public and government authorities, courts or regulators in accordance with 90K's legal obligations
Legal obligation or 90K's legitimate interest in protecting against misuse or abuse of 90K's websites, complying with judicial proceedings, court orders or legal processes, responding to lawful requests, or for auditing purposes
SECURITY AND RETENTION
-
Visitors’ Personal Data is securely hosted on an AWS cloud server based in the European Economic Area (the “EEA”). AWS maintains a comprehensive set of compliance certifications and attestations, including but not limited to ISO 27001, 27017, 27018, NIST 800, PCI DSS, and SOC 1, 2, and 3 reports. More information about 90K's providers’ security practices is available in AWS’ Privacy Policy.
-
In addition, 90K applies industry standards and adequate technical and organizational measures, in accordance with applicable laws, to ensure that Visitors' data is kept secure.
-
In the event of a Personal Data breach, 90K shall without undue delay, and where feasible, not later than 72 hours after having become aware of it, notify the breach to the competent Supervisory Authority, unless said breach is unlikely to result in a risk to Visitors’ rights and freedoms. If the breach is likely to result in a high risk to Visitors’ rights and freedoms, the Company shall communicate this breach to the affected Visitors, if it is feasible, without undue delay.
-
The Company will store Visitors' Personal Data for as long as necessary to satisfy the purposes for which Visitors' Personal Data was collected or to comply with applicable legal requirements. Visitors' information might be retained for a period based on the contract Visitors have with us, in accordance with relevant industry standards or guidelines, and in accordance with 90K's legitimate business interests, including prevention of promotion abuse and similar activities. 90K might further retain information for business practices based on 90K’s legitimate interest such as product and service improvement, fraud prevention, record-keeping, in the event of complaint or enforcing 90K's legal rights.
PROCESSORS
90K may disclose Personal Data that 90K collects, or Visitors provide, to: To 90K’s Affiliates.
1. To Processors and Sub-processors, including but not limited to service Providers and other third parties 90K uses to support its business and who are bound by contractual obligations to keep Personal Data confidential and use it only for the purposes for which 90K disclose it to them.
2. 90K may share Visitors' Personal Data to any other relevant third parties, in particular if 90K is requested to do so to comply with a court order or law enforcement authorities request, or if 90K find it necessary, as determined in 90K’s sole discretion, to investigate, prevent or take action regarding illegal activities, to defend its interest or as otherwise required or permitted by law.
3. Unless otherwise stated, the Processors who receive data from 90K are prohibited to use this Personal Data beyond what is necessary to provide the product or service to Visitors, directly or by participating in 90K’s activities.
TRANSFERS
-
When transferring Personal Data, 90K is committed to ensuring that the data importer maintains materially similar security measures for storage and Processing of Personal Data as 90K do. Visitors' Personal Data may be processed, stored and transferred to third parties in the manner and amount as provided in this Privacy Notice, the contract(s) concluded between Visitors and us, and consents Visitors give to us from time to time.
-
Transfers from the EEA, Switzerland, and the United Kingdom to countries that offer an adequate level of data protection. Personal Data may be transferred to countries that offer an adequate level of data protection under or pursuant to the adequacy decisions published by the relevant authorities (“Adequacy Decisions”), as applicable, without any further safeguard being necessary.
-
If the Processing of Personal Data by Processor includes a transfer (either directly or via onward transfer) to other countries that have not been subject to a relevant Adequacy Decision, and such transfers are not performed through an alternative compliance mechanism recognized by Data Protection Laws (as may be adopted by Processor in its own discretion), the terms set forth in the applicable Standard Contractual Clauses shall apply.
DIRECT MARKETING
-
Subject to the applicable Data Protection Laws, 90K may from time to time send direct marketing materials promoting its services and/or activities to its Visitors who have subscribed for the newsletter.
-
Visitors may, at any time, opt-out of such communications by utilizing the marketing preferences center provided with each direct marketing communication. Visitors may also opt-out of direct marketing by communicating Visitors' preferences to 90K at legal@90kcapital.com.
VISITORS’ RIGHTS
As Data Subjects, Visitors shall have one or more of the following data subject rights with respect to the Personal Data that 90K Processes.
-
Access – Visitors have a right to access Visitors' Personal Data, including receiving a copy and to obtain certain information about the 90K’s processing activities.
-
Rectification – the GDPR grants Visitors the right to correct inaccurate Personal Data and/or complete incomplete Personal Data.
-
Deletion/Erasure – Visitors have the right to request erasure of Personal Data (the right to be forgotten). 90K shall take reasonable steps to inform any other Processors also processing the data.
-
Restrict Processing – Visitors have the right to restrict processing of Personal Data, under certain circumstances.
-
Portability – Visitors have the right to data portability to:
-
receive a copy of the Personal Data in a structured, commonly used and machine-readable format;
-
transmit the Personal Data to another data controller (including directly by another data controller where possible).
Object to processing – Visitors have the right to object to processing for profiling, direct marketing, and statistical, scientific, or historical research purposes.
Object to automated decision making – Visitors have the right to not be subject to automated decision making, including profiling, which has legal or other significant effects on Visitors.
Withdraw consent – Visitors may, at any time, withdraw Visitors' consent to 90K’s processing when the processing is based solely on Visitors' consent.
-
These rights can be exercised by writing to 90K at legal@90kcapital.com. Upon receipt of Visitors' requests at the contact details provided below, 90K shall reply without undue delay and within the applicable statutory deadlines. If the request is submitted by a person other than the Visitor, without providing evidence that the request is legitimately made on Visitors' behalf, the request will be rejected.
-
Any request to exercise rights is free of charge unless Visitors' request is unfounded or excessive (e.g. if Visitors have already requested such Personal Data multiple times in the last twelve months or if the request generates an extremely high workload). In such a case, 90K may charge Visitors a reasonable request fee according to applicable Data Protection Laws.
-
90K may refuse, restrict or defer the provision of Personal Data where it has the right to do so, for example if fulfilling the request will adversely affect the rights and freedoms of others.
-
Please note that any request with regards to Personal Data which is publicly available should be submitted directly to the third-party supplier of such data.
CHANGES
90K reserves the right to make any changes to this Privacy Notice at any time, as 90K deems necessary or desirable. If 90K makes any material changes restricting or affecting in any way Visitors' rights, 90K may notify Visitors on the Website and, when possible, by email, prior to the change becoming effective.
Visitors’ continued use of the Website after any such changes or after explicitly accepting the new Privacy Notice upon using the Website shall constitute Visitors' consent to such changes. If Visitors do not agree to any given modifications to this Privacy Notice, Visitors should stop using the Website.
JURISDICTION AND GOVERNING LAW
-
This Privacy Notice and any questions relating thereto shall be governed by the laws of the Cayman Islands, to the exclusion of any rules of conflict resulting from private international law.
-
Any dispute relating to this Privacy Notice must exclusively be brought before the courts of the Cayman Islands
CONTACT
-
We value Visitors' opinion, and if Visitors have any comments or questions about this Privacy Notice, 90K’s handling of Visitors' Personal Data, a possible Personal Data Breach, or want to exercise Visitors' rights, please please contact us at the addresses below and 90K will treat Visitors' requests or complaints confidentially.
-
Email - legal@90kcapital.com
-
Address - 71 Fort Street, 3rd Floor, Grand Cayman, KY1-1111, Cayman Islands
In addition, Visitors can contact 90K’s GDPR Art. 27 EU Representative and Art. 37 Data Protection Officer:
-
Name: Stefan Belchev
-
Details: legal@90kcapital.com
If Visitors feel Visitors' Personal Data has been mishandled or if 90K has failed to meet Visitors' expectations, Visitors are encouraged to contact 90K but Visitors are entitled to complain directly to the relevant Supervisory Authority.