Privacy Policy
This Privacy Policy (the “Privacy Policy”) governs all aspects of NDB’s collection, use, maintenance, and disclosure of personal information and personal data as defined in the relevant data privacy laws (the “Personal Data”) from all users (each a “User” and collectively, “Users”) of its corporate website and its services.
​
Introduction
NDB is a leading cybersecurity and compliance professional services firm providing audit and attestation services. NDB is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (“PCAOB”), NDB Compliance and Security, Inc., and its affiliates and subsidiaries (“NDB”), which are collectively referred to as NDB throughout this policy. Also, when this Privacy Policy refers to NDB the wider NDB group of companies is meant. Depending on which entity is responsible for the processing of Personal Data and the underlying systems, the NDB affiliate and/or NDB are the data controllers of Personal Data as defined herein, which means they determine what Personal Data is needed and how it is used. Unless specifically stated otherwise herein, this Privacy Policy applies to NDB.
​
The purpose of this policy is to provide users with transparency with respect to NDB’s collection and use of Personal Data. NDB is committed to protecting the confidentiality of information entrusted to it by users and has prepared this Privacy Policy to inform Users of NDB’s practices and policies concerning the collection, use, processing, maintenance, and disclosure of Personal Data. Below you will find the contents of this policy by section.
​
CONTENTS OF THIS POLICY
-
Personal Data Collection
-
What Personal Data We Collect
-
Personal Data We Use
-
Legal Bases for Processing
-
Data Retention
-
Disclosure of Personal Data
-
Safeguards
-
Enforcement and Dispute Resolution
-
Rights of the Data Subject Residing in the European Union or to which GDPR applies.
-
Privacy Policy for California Residents
-
Opting Out and Unsubscribing from the Mailing List
-
International Personal Data Transfers
-
Children’s Data
-
Changes to Policy
-
Contact Information
-
Disclaimer
​
1. Personal Data Collection
​
HOW WE COLLECT PERSONAL DATA
​
You have supplied your Personal Data:
-
We collect Personal Data such as a first and last name, phone number, email address, and other contact information when you send us a message through our website.
-
When a user subscribes to a mailing list.
-
When a user registers for a webinar, event and/or whitepaper.
-
Through resume submissions, contracting and/or employment inquiries.
​
You have accessed our websites:
-
We may collect information using analytics tools, including when you visit our sites. The data we receive is dependent upon your privacy settings in your browser.
​
We provide you services:
-
We may collect your Personal Data if you are part of an entity that we provide or receive services from.
​
The information is public:
-
We may collect information about you through various social media platforms, for example, by liking us on Facebook, following us on Twitter, LinkedIn, or other social networks. The data we receive is dependent upon your privacy settings with the social network.
2. What Information and Data We Collect
When you submit information to our website, or send us an email, or enter into a contract with us we may collect the following Personal Data:
-
First and last name
-
Phone number
-
Email address
-
Security questions and other information to provide user account maintenance and
-
Other contact information in response to surveys about our service offerings
​
In addition, when a user browses our website, we may collect:
-
Cookies
-
Geolocation information
-
Mobile / device information
-
Browser information
-
Operating system
-
IP address
-
Technical information such as referral websites, browsing history, crash, and system error issues.
3. Personal Data We Use
NDB may use Personal Data it has collected through its website and service offerings for any of the following:
-
To provide services to users or clients of NDB or one of its subsidiaries, affiliates, and business partners.
-
To determine users’ interest in services or to inform users about services offered by NDB or one of its subsidiaries, affiliates, and business partners.
-
To customize a users’ preferences to enhance a user’s experience with NDB or one of its subsidiaries, affiliates, and business partners.
-
To customize ads to users according to user preferences and settings.
-
To provide technical, quality control and perform maintenance to our website and internal systems.
​
4. Legal Bases for Processing
LEGITIMATE INTEREST
The processing is based on our legitimate interests or the legitimate interests of our subsidiaries and affiliates to continuously operate, improve and/or personalize our services and develop new services, monitor the usage of our website, and ensure the security and detect any frauds and abuse, unless the requirement to protect the individual’s personal data overrides those legitimate interests.
​
CONSENT
You have provided express consent to the processing of your Personal Data for the specific purposes by explicitly ticking the relevant buttons, where applicable, and by voluntarily filling in and providing your Personal Data.
​
CONTRACT
Processing is required for the performance of a contract in which NDB has been engaged to perform services.
​
5. Data Retention
We retain Personal Data for as long as reasonably necessary to fulfill the purpose for which it was originally collected unless a longer retention period is required based on applicable law, regulation, and/or professional standards.
​
6. Disclosure of Personal Data
NDB uses all information collected from a user for internal purposes only. We may share your Personal Data with our subsidiaries and affiliates.
​
Furthermore, NDB may, from time to time, disclose Personal Data about a user to other persons or entities that perform services on behalf of NDB (“Service Providers”), but only when:
​
-
The Service Provider has agreed to use such information solely for the purposes of providing services to NDB;
-
The Service Provider agrees to protect such information in the same manner as the policies set forth in this policy statement;
-
NDB needs to share the user’s information to provide the service the user has requested;
-
NDB needs to send the information to a Service Provider who works on behalf of NDB to provide a service to you.
​
Unless NDB informs a user otherwise, a service provider does not have any right to use the Personal Data NDB provides to them beyond what is necessary to assist NDB, or in response to a legal obligation including without limitation a subpoena, court order or NDB believes that the law requires disclosure, or where the information is currently in the public domain.
​
Upon lawful requests by public authorities, governmental agencies, law enforcement agencies, or other third parties in order to comply with any law, court order, legal request, or other legal process, including to meet national security or law enforcement requirements, NDB may disclose Personal Data as required by law.
​
NDB does not and will not sell, share or rent your personal data to anyone in exchange for monetary compensation. We may disclose your Personal Data by allowing certain third parties (such as online advertising services, advertising networks and social networks) to collect Personal Data via automated technologies on our websites for cross-context behavioral advertising purposes.
​
We may sell or share for cross-context behavioral advertising purposes the following categories of personal information about you to online advertising services, advertising networks and social networks: identifiers, online activity and inferences as described in our California Consumer Privacy Statement representing an Attachment to this Privacy Policy, an integral part hereto.
​
7. Safeguards
NDB holds personal data in the United States currently. NDB keeps a user’s Personal Data for as long as NDB determines necessary to fulfill the objective for which it was collected. Personal Data is maintained on NDB systems that are protected using industry standard security measures to ensure the confidentiality, availability, and integrity of the Personal Data. Unfortunately, however, NDB cannot and does not guaranty that the information submitted to, maintained by, or transmitted from NDB is or will always be completely secure, as transmission of information over the internet is oftentimes susceptible to potential interception, misuse, willful and/or negligent acts or omissions, misrouting, or possible loss.
​
8. Enforcement and Dispute Resolution
NDB will investigate and attempt to resolve all disputes and complaints regarding our use and disclosure of Personal Data in accordance with this Privacy Policy.
​
If you are a resident of the European Union and your concern with NDB has not been addressed satisfactorily, or if you believe we are not processing your Personal Data in accordance with applicable law or in accordance with this Privacy Policy, you have the right to file a complaint with the Data Protection Authority in the member state in which you reside.
​
9. Rights of the Data Subject Residing in the European Union or to which GDPR applies
Residents of the European Union have certain rights under European data protection law with respect to Personal Data, including the right to request access to, correct, amend, delete, limit the use of, object to or withdraw your consent for the processing of your Personal Data at any time. They may also have the right to receive a copy of your personal information in a commonly used and machine-readable format and to transmit such information to another controller (data portability).
​
If you are a resident of the European Union and would like to submit a Data Subject Access Request, please send us an email at info@ndbcpa.com.
​
NDB will respond in accordance with applicable laws and professional standards applicable to NDB. We are open about the Personal Data we collect and have implemented mechanisms to enable you to exercise any rights you might have with respect to your Personal Data.
​
After receiving your request and sufficient information to verify your identity, we will provide you with a copy of the Personal Data we have about you which you are entitled to receive under applicable law. We will also confirm the purposes for which such Personal Data is being used, its recipients and the origin of the information.
​
You may write to us at any time requesting amendments to certain Personal Data that you consider to be incorrect or irrelevant, or to request that we block, erase, or otherwise remove your Personal Data. We will update, block, erase or remove your Personal Data upon request in line with applicable law.
​
You may at any time ask us to delete your Personal Data. We will consider and where necessary comply with your request in accordance with applicable law, as explained above.
​
10. Privacy Policy for California Residents
NDB adopted the California Consumer Privacy Statement which supplements the information contained herein and represents an Attachment to this Privacy Policy, an integral part hereto. The California Consumer Privacy Statement applies solely to personal information as defined in the relevant data privacy laws collected about California consumers, such as our website visitors, attendees of our webinars and events, representatives of our business customers and business partners, and job applicants.
​
To submit an access, correction, or deletion request, please contact us at info@ndbcpa.com to opt-out of the sale or sharing of your personal information, follow the instructions provided in this Do Not Sell or Share My Personal Information.
​
11. Opting Out and Unsubscribing from the Mailing List
All our marketing communications contain an easy way to opt out from receiving future messages, such as a link through which you can unsubscribe.
​
If you would like to opt out of receiving marketing messages, you may use the unsubscribe link contained in the messages you have received, or alternatively you may send NDB an email at info@ndbcpa.com.
​
12. International Personal Data Transfers
NDB remains dedicated to privacy principles including but not limited to the EU-U.S. Privacy Shield Framework (“Privacy Shield”). Although the European Union Court of Justice (CJEU) invalidated the EU-US Privacy Shield regarding the collection, use, and retention of Personal Data transferred from the European Union to the United States, NDB remains dedicated to privacy principles, including those underlying the EU-U.S. Privacy Shield Frameworks.
​
To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.
NDB continues to certify to the Department of Commerce that it will observe the Privacy Shield Principles but will not limit the Privacy Shield Framework as the only valid source with respect to Personal Data that is transferred from the European Union and its Member States, respectively UK, to the United States and will use other appropriate safeguards and mechanisms, for example by agreeing on the EU or UK Standard Contractual Clauses first.
​
NDB is committed to ensure that all international Personal Data transfers will be processed in accordance with EU Standard Contractual Clauses. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the EU Standard Contractual Clauses prevail. The EU Standard Contractual Clauses shall mean the Standard Contractual Clauses, effective June 27, 2021, adopted by the EU Commission with EU Commission Implementing Decision 2021/914 of June 4, 2021 on Standard Contractual Clauses for the Transfer Of Personal Data to Third Countries pursuant to GDPR, published at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en ; or (if applicable) any future clauses issued by the EU for the transfer of Personal Data to non-EU (sub) processors and replacing or modifying the clause in the wording as issued by the EU.
In regard to transfers of Personal Data where UK GDPR applies, the following UK Standard Contractual Clauses shall apply, namely (i) the Standard Data Protection Clauses issued by the Commissioner under S119A(1) Data Protection Act 2018 published at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf ; or (ii) any future clauses as may be published by the UK Information Commissioner or the UK Government under UK GDPR from time to time for use in relation to Restricted Transfers from a controller located in the UK (or from its own processor) to a processor (or sub-processor) located in a third country.
​
NDB commits to resolve complaints about our collection or use of your Personal Data.
​
If you have any questions, complaints and/or other concerns, please first contact our Data Protection Officer who can be reached at: info@ndbcpa.com
​
You may also lodge a complaint with your local data protection authority or with the Data Protection Authority in Bulgaria, namely the Commission for Personal Data Protection, at kzld@cpdp.bg.
​
NDB commits to cooperate with the panel established by the EU data protection authorities (“DPAs”) and comply with the advice given by the panel, including with regard to human resources data transferred from the EU in the context of the employment relationship.
​
NDB has further committed to refer unresolved complaints about Personal Data other than human resources data to International Centre for Dispute Resolution, International Division American Arbitration Association (“ICDR-AAA”), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not resolved your complaint, please contact, or visit http://go.adr.org/privacyshield.html for more information or to file a complaint. The services of the ICDR-AAA are provided at no cost to you.
​
The Federal Trade Commission has jurisdiction over compliance with the Privacy Shield for NDB.
​
If your complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction.
​
In the context of an onward transfer, NDB has responsibility for the processing of Personal Data it receives under privacy principles including the Privacy Shield, and subsequently transfers to a third party acting as an agent on its behalf. NDB shall remain liable under the principles if its agent processes such personal information in a manner inconsistent with the principles, unless the organization proves that it is not responsible for the event giving rise to the damage.
​
13. Children’s Data
We define a child as a natural person who is under the age of 16 years old. We do not collect children’s data, whether knowingly, actively, or otherwise, and we do not actively market to children. If we discover that we have collected a child’s data, the data is deleted immediately.
​
Where we know a child is above the age of 16, but considered a minor under applicable law, we will obtain parental/guardian consent prior to using that child’s personal information.
​
14.Changes to the Policy
NDB reserves the right to update this Privacy Policy periodically to keep up with regulatory and industry standards. If there is a substantial change in the way we use Personal Data, any such changes shall be effective from the date of posting of any revisions hereto as well as to any existing information then being retained by NDB. In certain circumstances, we may need to request your consent to continue to process your Personal Data, based on any changes in our processing basis, methods and/or interest.