Last Updated: March 7, 2023 This privacy policy (“Privacy Policy”) governs how we, Vesttoo Ltd. (together, “Vesttoo” “we”, “our” or “us”) use, collect and store Personal Data we collect or receive from or about you (“you”) such as in the following use cases: (i) When you browse or visit our website, https://vesttoo.com/ (“Website”) (ii) When you make use of, or interact with, our Website a. When you subscribe to our distribution list / newsletters / blog b. When you contact us (e.g., need help, submit a request) c. When we process your job application d. When you sign up and login to our platform ("Platform") (iii) When you attend a marketing event or exchange business cards with us for marketing purposes (iv) When we acquire your personal data from third-party sources (such as lead-generation companies)\ (v) When we use the personal data of our customers (e.g., contact details) (vi) When we use the personal data of our resellers, distributors, agents and/or finders (e.g., contact details) (vii) When we use the personal data of our service providers and suppliers (e.g., contact details)\ (viii) When you interact with us on our social media profiles (e.g., Facebook, Instagram, Twitter, LinkedIn) (ix) When you participate in webinars and/or other events we organize.
We greatly respect your privacy, which is why we make every effort to provide a platform that would live up to the highest of user privacy standards. Please read this Privacy Policy carefully, so you can fully understand our practices in relation to personal data. “Personal Data” or “Personal Information” means any information that can be used, alone or together with other data, to uniquely identify any living human being. Please note that this is a master privacy policy and some of its provisions only apply to individuals in certain jurisdictions. For example, the legal basis in the table below is only relevant for GDPR-protected individuals. Important note: Nothing in this Privacy Policy is intended to limit in any way your statutory right, including your rights to a remedy or means of enforcement. Table of contents:
This Privacy Policy can be updated from time to time and, therefore, we ask you to check back periodically for the latest version of this Privacy Policy. If we implement significant changes to the use of your Personal Data in a manner different from that stated at the time of collection, we will notify you by posting a notice on our Website or by other means.
Specific Personal Data we collect Why is the Personal Data collected and for what purposes? Legal basis (GDPR only, if applicable) Third parties with whom we share your Personal Data Consequences of not providing the Personal Data When you browse or visit our Website Cookies, analytic tools and log files
For more information, please read our cookies policy here.
● To personalize the Website
● For marketing and retargeting purposes
Legitimate interest (e.g. essential cookies) 3rd party platforms such as for the following purposes: ● Mailchimp ● HubSpot ● Salesforce
Read more about the purposes of each cookie here Cannot analyze, support and improve our Website
Cannot personalize the Website Read more about the purposes of each cookie here
When you make use of, or interact with, our Website When you subscribe to our distribution list / newsletters ● Full name ● Email address ● To send you marketing communications
● To send you more information about Vesttoo
● To send you Vesttoo's updates, case studies, and other materials Consent 3rd party platforms such as for the following purposes: ● MailChimp ● HubSpot ● Salesforce Cannot send you marketing communications Cannot send you more information about Vesttoo Cannot send you Vesttoo's updates, case studies, and other materials When you contact us (e.g. need help, submit a request) ● Full name ● Email address ● Company name ● Position ● Country/Region ● Your business ● Any other information that you decide to provide/supply us\ ● To answer your question(s)/request(s)
● To provide support
To customize your experience Performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
Legitimate interest (e.g. provide support and answer your questions) 3rd party platforms such as for the following purposes: ● MailChimp ● HubSpot ● Salesforce Cannot answer your question(s)/request(s) Cannot provide support Cannot customize your experience
● Full name ● Email address ● To send you marketing communications
● MailChimp ● HubSpot ● Salesforce Cannot send you marketing communications
When we process your job application ● Full name ● E-mail address ● Phone number ● CV and cover letter ● Your LinkedIn public profile ● Any other information that you decide to provide/supply us with ● To process your job application ● To assess the candidate ● To communicate with you (candidate/interview-related communications) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract Legitimate interest (e.g. to assess a candidate) 3rd party platforms such as for the following purposes: ● Gmail Cannot process your job application Cannot assess the candidate Cannot communicate with you
When you sign up and login to our Platform ● Full name ● Company name ● Position ● Email address ● User name and Password ● Geolocation. ● Usage pattern. ● IP Address ● To create your account
● To allow you to login/sign up to the Platform
● To fulfill your requests for our services and related activities (e.g., account management)
● To perform/execute the relevant agreement
● To grant you access to the Platform Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
Legitimate interest (e.g. to allow you to sign up to the Platform) 3rd party platforms such as for the following purposes:
● MailChimp ● HubSpot ● Salesforce Cannot create your account Cannot allow you to login/sign up to the Platform Cannot fulfill your requests for our services and related activities (e.g., account management) Cannot perform/execute the relevant agreement
● Full name ● Email address ● To send you marketing communications
● MailChimp ● HubSpot ● Salesforce Cannot send you marketing communications
When you attend a marketing event, exchange business cards with us or otherwise provide us with your Personal Data for marketing purposes ● Full name ● Job title ● Email address ● Company name ● Phone number ● Any other information that you decide to provide/supply us ● To establish a business connection
● To send you marketing communications
● To send you more information about Vesttoo
● To send you Vesttoo's updates, case studies, and other materials Depending on the context, legitimate interest (B2B marketing), pre-contractual discussions or consent 3rd party platforms such as for the following purposes: ● MailChimp ● Gmail – Marketing communication ● HubSpot ● Salesforce Cannot establish a business connection Cannot send you marketing communications
Cannot send you more information about Vesttoo
Cannot send you Vesttoo's updates, case studies, and other materials When we use the personal data of our customers (e.g. contact details) ● Full name ● Email address ● Phone number ● Company name and details ● Payment information ● Any other information that you decide to provide/supply us ● To provide our products and services
● To perform the applicable agreement
● To communicate with our customers
● To send you marketing communications
Compliance with a legal obligation (e.g. tax laws, bookkeeping laws, etc.).
Legitimate interest (e.g. send you contract-related communications). 3rd party platforms such as for the following purposes: ● Gmail ● HubSpot ● Salesforce Cannot provide our products and services Cannot perform the applicable agreement Cannot communicate with our customers Cannot send you marketing communications
● Full name ● Email address ● To send you marketing communications
Legitimate interest (e.g. to send you more information about Vesttoo) 3rd party platforms such as for the following purposes: ● MailChimp ● HubSpot ● Salesforce Cannot send you marketing communications When we use the personal data of our service providers (e.g. contact details)\ ● Full name ● Email address ● Phone number ● Company name ● Any other information that you decide to provide/supply us ● To contact our service providers ● To perform the applicable agreement
Compliance with a legal obligation (e.g., tax laws, bookkeeping laws, etc.). Legitimate interest (e.g. perform the contract, send contract-related communications) 3rd party platforms such as for the following purposes: ● Gmail ● HubSpot ● Salesforce Cannot contact our service providers Cannot perform the applicable agreement When you interact with us on our social media profiles (e.g., Facebook, Twitter, LinkedIn) ● Full name ● Email address ● Phone number ● Company name ● Job title ● Social media profiles ● Any other information you choose to share with us ● Field of interest. ● Describing your business ● Country of origin. ● To reply and/or respond to your request or question ● To establish a business connection Depending on the context, legitimate interest (B2B marketing), pre-contractual discussions or consent 3rd party platforms such as for the following purposes: ● LinkedIn - Social media channels ● Facebook – Social media channels ● Twitter - Social media channels ● YouTube - Social media channels ● HubSpot ● Salesforce Cannot reply and/or respond to your request or question Cannot establish a business connection
When you participate in webinars and/or other events we organize ● Full name ● Email address ● Phone number ● Company name ● Job title ● Event that you decided to register ● Any other information you choose to share with us ● To allow you to register in our webinars and other similar events that we organize ● To send you reminders and event-related communications Depending on the context, legitimate interest (B2B marketing or to allow you to register to the event), pre-contractual discussions or consent 3rd party platforms such as for the following purposes: ● LinkedIn - Social media channels ● Facebook – Social media channels ● Twitter - Social media channels ● YouTube - Social media channels ● Partners with whom we organize the websinars and/or events (if any) ● HubSpot ● Salesforce Cannot allow you to register in our webinars and other similar events that we organize
Cannot send you reminders and event-related communications
Finally, please note that some of the abovementioned personal data will be used for detecting, taking steps to prevent, and prosecution of fraud or other illegal activity, to identify and repair errors, to conduct audits, and for security purposes. Personal Data may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims. In certain cases, we may or will anonymize or de-identify your personal data and further use it for internal and external purposes, including, without limitation, to improve the services and for research purposes. “Anonymous Information” means information which does not enable identification of an individual user, such as aggregated information about the use of our services. We may use Anonymous Information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them).
2.1. Security. We have implemented appropriate technical, organizational and security measures designed to protect your Personal Data. However, please note that we cannot guarantee that the information will not be compromised as a result of unauthorized penetration to our servers. As the security of information depends in part on the security of the computer, device or network you use to communicate with us and the security you use to protect your user IDs and passwords, please make sure to take appropriate measures to protect this information. 2.2. Retention of your Personal Data. In some circumstances we may store your Personal Data for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, or (iii) if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings. Regarding retention of cookies, you can read more in our cookie policy here.
In addition to the recipients described above, we may share your Personal Data as follows: 3.1. With our business partners with whom we jointly offer products or services. 3.2. With our affiliated companies. 3.3. To the extent necessary, with regulators, courts or competent authorities, to comply with applicable laws, regulations and rules (including, without limitation, federal, state or local laws), and requests of law enforcement, regulatory and other governmental agencies or if required to do so by court order; 3.4. If, in the future, we sell or transfer, or we consider selling or transferring, some or all of our business, shares or assets to a third party, we will disclose your Personal Data to such third party (whether actual or potential) in connection with the foregoing events; 3.5. In the event that we are acquired by, or merged with, a third party entity, or in the event of bankruptcy or a comparable event, we reserve the right to transfer, disclose or assign your Personal Data in connection with the foregoing events, including, in connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or to another company; and/or 3.6. Where you have provided your consent to us sharing or transferring your Personal Data (e.g., where you provide us with marketing consents or opt-in to optional additional services or functionality). 3.7. If you want to receive the list of the current recipients of your Personal Data, please make your request by contacting us to privacy@vesttoo.com.
4.1. Storage: We store Personal Data in an internal database that Vesttoo has created. Such database is stored on AWS with servers located in Ohio. 4.2. Access from Israel: Access from Israel is covered by the European Commission’s Adequacy Decision regarding Israel. You can read more here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en.
4.3. External transfers: In order to run our business and provide our Website and Services to you, we transfer Personal Data to certain countries around the world, including to our affiliates and service providers, many of whom are located outside of your jurisdiction. Therefore, your Personal Data may be processed in countries with privacy laws that are different from privacy laws in your country. Where we transfer your Personal Data outside of EU/EEA (for example to third parties who provide us with services), we will use commercially reasonable efforts to obtain contractual commitments from them to protect your Personal Data and to implement an appropriate level of protection to your Personal Data by implementing at least one of the following safeguards: a) making sure the destination country has been deemed to provide an adequate level of protection for Personal Data; and/or b) by executing implement data onward transfer instruments such as data processing and protection agreements. 4.4. Internal transfers: Transfers within the Vesttoo group will be covered by an internal processing agreement entered into by members of the Vesttoo group (an intra-group data processing agreement) which contractually obliges each member to ensure that Personal Data receives an adequate and consistent level of protection wherever it is transferred to.
5.1. The following rights (which may be subject to certain exemptions or derogations) shall apply to certain individuals (some of which only apply to individuals protected by the GDPR): You have certain choices about your Personal Data. The following rights (which may be subject to certain exemptions or derogations) shall apply to certain individuals (some of which only apply to individuals protected by the GDPR): o You have a right to access personal data held about you. Your right of access may normally be exercised free of charge, however we reserve the right to charge an appropriate administrative fee where permitted by applicable law; o You have the right to request that we rectify any personal data we hold that is inaccurate or misleading; o You have the right to request the erasure/deletion of your personal data (e.g. from our records). Please note that there may be circumstances in which we are required to retain your personal data, for example for the establishment, exercise or defense of legal claims; o You have the right to object, to or to request restriction, of the processing; o You have the right to data portability. This means that you may have the right to receive your personal data in a structured, commonly used and machine-readable format, and that you have the right to transmit that data to another controller; o You have the right to object to profiling; o You have the right to withdraw your consent at any time by contacting us. Please note that there may be circumstances in which we are entitled to continue processing your data, in particular if the processing is required to meet our legal and regulatory obligations. Also, please note that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. If you withdraw consent / opt-out (as applicable), we will still collect and use non-Personal Data regarding your activities on our Website and/or Platform and for other legal purposes as described in this Privacy Policy. o You also have a right to request certain details of the basis on which your personal data is transferred outside the European Economic Area, but data transfer agreements and/or other details may need to be partially redacted for reasons of commercial confidentiality; o You have a right to lodge a complaint with your local data protection supervisory authority (i.e., your place of habitual residence, place or work or place of alleged infringement) at any time or before the relevant institutions in your place of residence. We ask that you please attempt to resolve any issues with us before you contact your local supervisory authority and/or relevant institution.
5.2. Rights under CCPA and other applicable US laws: The following rights (which may be subject to certain exemptions or derogations) shall apply to certain individuals (some of which only apply to individuals protected by the CCPA: (a) You have the right to know what Personal Information is being collected about you, including the categories of Personal Information, the categories of sources from which the Personal Information is collected, the business or commercial purpose for collecting, selling, or sharing Personal Information, the categories of third parties to whom the business discloses Personal Information, and the specific pieces of Personal Information the business has collected; (b) You have a right to correct inaccurate Personal Information we have about you; (c) You have the right to request the deletion of your Personal Information (e.g. from our records and the records of our service providers), subject to certain exceptions. Please note that there may be circumstances in which we are required to retain your Personal Information, for example for the establishment, exercise or defense of legal claims; (d) You have the right to know whether your Personal Information is sold or disclosed and to whom; (e) You have the right to opt-in to financial incentives. You also have the right to opt-out at any time. Please see below for more information about the financial incentive(s) we offer. (f) Right to limit the use or disclosure of sensitive Personal Information (g) Right to Opt Out of sale or sharing of your Personal Information to third parties; and (h) You have the right to equal service and price, even if you exercise your privacy rights.
5.3. You can exercise your rights by contacting us at privacy@vesttoo.com. You have a right to lodge a complaint with your local data protection supervisory authority (i.e., your place of habitual residence, place or work or place of alleged infringement) at any time or before the relevant institutions in your place of residence (e.g. the Attorney General in your State). In addition, you may use an authorized agent to submit a request on your behalf if you provide the authorized agent written permission signed by you. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfil your request. When processing your request, we will do it in accordance with the requirements of applicable privacy laws and we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. In the event that your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initial requested, we will address your request to the maximum extent possible, all in accordance with applicable law. 5.4. Marketing emails – opt-out: You may choose not to receive marketing email of this type by sending a single email with the subject "unsubscribe" to info@vesttoo.com. Please note that the email must come from the email account you wish to block OR if you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails, and we will process your request within a reasonable time after receipt.
● Google Signals. The Website uses a tool called “Google Signals” to collect information about use of the Website. When we activate Google Signals, some existing Google Analytics features are updated to also include aggregated data from Google users who have turned on “Ads Personalization” (Ads Personalization available at https://support.google.com/ads/answer/2662856/). Audiences that we create in Google Analytics and publish to Google Ads and other Google Marketing Platform advertising products can serve ads in cross device-eligible remarketing campaigns to Google users who have turned on Ads Personalization. Google Analytics collects additional information about users who have turned on Ads Personalization, base across device types and on aggregated data from users who have turned on Ads Personalization. The data is user based rather than session based. The Cross Device reports include only aggregated data. No data for individual users is ever exposed. You can modify your interests, choose whether your Personal Data is used to make ads more relevant to you, and turn on or off certain advertising services in the Ads Personalization link above. ● Facebook Pixels and SDKs. We use Facebook pixels or SDKs, which are tools that provide help to website owners and publishers, developers, advertisers, business partners (and their customers) and others integrate, use and exchange information with Facebook, as such the collection and use of information for ad targeting. Please note that third parties, including Facebook, use cookies, web beacons, and other storage technologies to collect or receive information from your websites and elsewhere on the internet and use that information to provide measurement services and target ads. Facebook’s ability to use and share information is governed by the Facebook Tools Terms, available at: https://www.facebook.com/legal/technology_terms/. You can prevent your data from being used by Facebook Pixels and SDKs by exercising your choice through these mechanisms: http://www.aboutads.info/ choices or http://www.youronlinechoices.eu/.
● Advertising Partners. Through our services, we allow third party advertising partners to set technologies and other tracking tools to collect information regarding your activities and your device. We also may combine and share such information and other information (such as demographic information and past purchase history) with third party advertising partners. These advertising partners will use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit third party websites within their networks. This practice is commonly referred to as “interest-based advertising” or “online behavioral advertising. We allow access to other data collected by the services to share information that may be useful, relevant, valuable or otherwise of interest to you. If you prefer not to share your Personal Information with third party advertising partners, you may let us know.
● We reserve the right to remove or add new analytic tools.
If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at privacy@vesttoo.com. ● Data controller: Vesttoo Ltd.\ Address:"Levenstein Tower, 23 Menachem Begin Street Tel-Aviv 6618356 Israel