Elucidate GmbH, located in Berlin, Germany, registered in: Amtsgericht Charlottenburg HRB 196707B, is responsible for your Personal Data (later referred throughout this document as “Elucidate”, “we”, “us” or “our”).
Elucidate acts either as a Data Controller or as a Data Processor. Both roles – Controller and/or Processor – will be carried out in pursuant of GDPR and EU-Regulations, where different obligations will apply according to each role.
We collect and process Personal Data relating to: (i) visitors to efi.elucidate.co and elucidate.co in relation to the services we provide; (ii) our Clients that are global financial institutions and regulators. The data we process differs depending on the different interactions with us, as detailed below.
This privacy policy (“Policy”) sets out to give you information on:
Third-party links
This website includes links to third-party websites, plug-ins and applications, including Calendly, Zapier and Webflow. Upon clicking on those links, you will be redirected to a third-party website where our privacy policy no longer applies.
Our Data Protection Officer oversees how we collect, use, share and protect information gathered to ensure all required rights are fulfilled. Our external Data Protection Officer is:
Dr. Christoph Bauer, CEO of ePrivacy GmbH,
Große Bleichen 21
20354 Hamburg
Germany.
The information we have collected is stored in a GCP data centre, a GDPR compliant data processing facility in Frankfurt am Main, Germany (“Hosting Provider”). This Hosting Provider holds the following certifications ISO 27001, ISO 27017, ISO 27018, SOC1, SOC2, SOC 3, FIPS 140-2, PCi, CSA STAR. All data stored in our databases is encrypted using 256-bit Advanced Encryption Standard (AES-256).
The information we have collected is stored in a GCP data centre, a GDPR compliant data processing facility in Frankfurt am Main, Germany (“Hosting Provider”). This Hosting Provider holds the following certifications ISO 27001, ISO 27017, ISO 27018, SOC1, SOC2, SOC 3, FIPS 140-2, PCi, CSA STAR. All data stored in our databases is encrypted using 256-bit Advanced Encryption Standard (AES-256).
4.1 Website Data
When you are using the website you may provide us your Personal Data. If you contact us through our Contact page, we collect your name and email address so we can respond to you.
If you download our WhitePaper on our webpage, we collect your first and last name, email address, phone number, job title and organization name so we may send you the WhitePaper and information on our products and services.
You can revoke your consent and/or unsubscribe anytime by submitting a request to: privacy@elucidate.co.
Additionally, when using the website we might collect Personal Data on your internet browser, operating system, IP address, time of the page request, referrer URL, device information, session information, size of the requested file and any status or error codes through the usage of cookies. Cookies are text files placed on your computer that we use to ensure the functionality of our website, gather statistical information about the use and development of our website, and for general data security and error analysis purposes. For further information, visit all aboutcookies.org.
Elucidate Cookies are defined in Cookiebot, please refer to that section for it's type, name and purpose
You can set your browser not to accept cookies, and the above website tells you how to remove cookies from your browser. Additionally, if you wish to enable or disable the above cookies please use our Cookiebot Consent Management Platform available on our website.
However, in a few cases, some of our website features may not function as a result.
4.2 HR Data
If you apply for a job on the website, we collect your first and last name, email, phone number, citizenship, work permit information, education level, employment history, salary history, and any Personal Data you choose to submit on a cover letter, recommendation letter or CV (“Job Applications”). We use this information to assess your qualifications for open positions and to contact you for further information if we deem it necessary.
You can revoke your consent anytime by submitting a request to: privacy@elucidate.co.
4.3 Client Data
We receive different Personal Data sets from our Clients in a pseudonymised format, using secure hashing algorithms. We receive the following categories of Personal Data from our Clients:
We process the Client Data in combination with Public Data, to perform comprehensive data analysis for the measurement, assessment, standardisation and reporting of financial crime risk.
The consent collected by our Clients complies with the GDPR’s requirements and enables Elucidate´s processing activities. Any processing of your Personal Data by Elucidate is subject to your rights of choice and control as explained below in the “Data protection rights” Section. You can contact our Clients at any time to revoke your consent and/or if you contact us at privacy@elucidate.co and we will promptly share such request to our Clients directly.
4.4 Public Data
Together with the Client Data or on a standalone basis, we process the following Public Data, including among others: (i) Financial Action Task Force (“FATF”) information; (ii) Transparency International Corruption Perceptions Index (“CPI”); (iii) Global Legal Entity Identifier Foundation (“GLEIF”) information, as necessary to provide our services to our Clients and produce the Elucidate FinCrime Index (“EFI”).
4.5 CRM Data
We receive the following categories of Personal Data from our business contacts and/or via public search, in order to maintain business communication, manage our business relationship, set up and manage your account for our services:
You can revoke your consent anytime by submitting a request to: privacy@elucidate.co. Additionally, whenever you receive an email from us, you can click on the Unsubscribe link at the bottom of the email communication.
Our data processing centre and our backup data centre are located in Frankfurt am Main in Germany. We have configured the data centres to store data within the EU only.
In all cases, we strive to ensure that data remains within the EU/EEA and select our processors and/or sub-processors with that in mind. In such exceptional cases where a processor and/or sub-processor stores data outside the EU/EEA, the selected processor and/or sub-processor is required to provide the suite of GDPR protections to such data. By law we are required to ensure that the level of protection guaranteed to your Personal Data by the EU laws is not undermined by such transfer, therefore we enter into EU Standard Contractual Clauses with such processor and/or sub-processor.
We do not knowingly process Personal Data of children under the age of sixteen (16).
We rely on contractual and legal obligations in order to collect and process all data lawfully. We ensure to protect the legitimate interest of all parties and to act according to the principle of transparency.
Elucidate is a regulated benchmark and therefore subjected not only to GDPR but to other EU-Regulations (eg. REGULATION (EU) 2016/1011). According to EU-Law we are obliged to retain all data exclusively related to the process of generating and providing the Elucidate FinCrime Index (“EFI”) platform for 5 years before deleting it.
Data from website visitors, job candidates and business contacts do not fall into this category and are handled separately according to GDPR regulations.
This Policy may change from time to time, so please check back periodically to ensure that you are aware of any changes in our processing of your Personal Data, particularly when we change how we use your information or the processor and/or sub-processors we engage. If at any time in the future we plan to use Personal Data in a way that differs from this Policy, we will post Policy edits here and place notices on other pages of the Site as applicable, or by other means if required by law. You are responsible for ensuring that you are aware of the most recent version of this Policy. This Policy was last modified on: January 21st, 2021.
Download Elucidate Data Privacy Policy (PDF)