Skip to main content

Privacy Policy

Last updated: May 25, 2021

TruSight Solutions, LLC (“TruSight”) respects your right to privacy. This Privacy Notice explains who we are, how we collect, share, and use personal information about you, and how you can exercise your privacy rights. This Privacy Notice only applies to personal information that we collect through our websites at www.trusightsolutions.com and my.trusightsolutions.com (“Websites”).

If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided at the bottom of this Privacy Notice.

What does TruSight do?

TruSight is a financial technology company, headquartered in New York, NY, with employees in the United States and Germany. Our products are third-party risk assessment solutions that leverage industry best practices.

For more information about TruSight, please see the “What We Do” section of our trusightsolutions.com website.

What personal information does TruSight collect and why?

The personal information that we may collect about you broadly falls into the following categories:

  • Information that you provide voluntarily: Certain parts of our Websites may ask you to provide personal information voluntarily. For example, we may ask you to provide your contact details in order to register an account with us or to submit inquiries to us. The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.

You may be asked to provide sensitive personal information, such as information about your race or ethnicity, in our “Career” section as part of voluntary disclosures in applications for open positions.

  • Information that we collect automatically: When you visit our Websites, we may collect certain information automatically from your device. In some countries, including countries in the European Economic Area, this information may be considered personal information under applicable data protection laws.

Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Websites, including the pages accessed and links clicked.

Collecting this information enables us to better understand the visitors who come to our Websites, where they come from, and what content on our Websites is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Websites to our visitors.

Some of this information may be collected using cookies and similar tracking technology, as explained further under the heading “Cookies and similar tracking technology” below.

  • Information that we obtain from third party sources: From time to time, we may receive personal information about you from companies that are being assessed or that are our customers, but only where we have checked that these companies either have your consent or are otherwise legally permitted or required to disclose your personal information to us.

The only type of personal information we collect from these companies is contact information to enable your use of our platform. This enables you to participate in an assessment or to access assessment reports.

With whom does TruSight share my personal information?

We may disclose your personal information to the following categories of recipients:

  • our customers who are consuming our products, but only if authorized by the relevant assessed company
  • our service providers, but only for purposes that are described in this Privacy Notice or notified to you when we collect your personal information
  • any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person
  • an actual or potential buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger, or acquisition of any part of our business, provided that we inform the buyer it must use your personal information only for the purposes disclosed in this Privacy Notice
  • any other person with your consent to the disclosure.

Legal basis for processing personal information

If you are a visitor from the European Economic Area or the United Kingdom, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.

However, we will normally collect personal information from you only (i) where we need the personal information to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so. In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.

If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).

If we collect and use your personal information in reliance on our legitimate interests (or those of any third party), this will normally be to enable use of our platform or to communicate with you. We may have other legitimate interests, and we will make clear to you at the relevant time what those legitimate interests are.

If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “How to contact us” heading below.

Cookies and similar tracking technology

We use cookies and similar tracking technology (collectively, “Cookies”) to collect and use personal information about you (including to serve interest-based advertising). We use Cookies to provide a personalized experience on our Websites and to allow access without re-entering your user ID, to make improvements, and to better tailor our site to your needs. If you do not want Cookies stored on your computer, you may adjust your browser settings to refuse Cookies, although this may prevent you from using certain features of the Websites and other services.

How does TruSight keep my personal information secure?

We use appropriate technical and organizational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information.

We protect personal information in several ways:

  • Encryption is employed for data at rest and in transit.
  • Access is provided only on a “need to know” basis.
  • We perform penetration testing and vulnerability scanning.
  • Personal data is anonymized in non-production environments.
  • Information security policies are communicated to and acknowledged by employees and subcontractors with access to personal data, and they are trained accordingly.

International data transfers

Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country (and, in some cases, may not be as protective).

Specifically, our Websites’ servers are located in the United States, and our third party service providers and partners operate around the world. This means that when we collect your personal information, we may process it in any of these countries.

However, we have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Notice. These include implementing the European Commission’s Standard Contractual Clauses for transfers of personal information, which require customers to protect personal information they process from the EEA and the United Kingdom in accordance with European Union and United Kingdom data protection law.

Our Standard Contractual Clauses can be provided on request.

Data retention

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements).

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

Your data protection rights

If you are a resident of the European Economic Area or the United Kingdom, you have the following data protection rights:

  • If you wish to access, correct, update or request deletion of your personal information, you can do so at any time by contacting us using the contact details provided under the “How to contact us” heading below.
  • In addition, you can object to processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us using the contact details provided under the “How to contact us” heading below.
  • Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Updates to this Privacy Notice

We may update this Privacy Notice from time to time in response to changing legal, technical, or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws.

You can see when this Privacy Notice was last updated by checking the “last updated” date displayed at the top of this Privacy Notice.

How to contact us

If you have any questions or concerns about our use of your personal information, please contact us at legal@trusightsolutions.com.

svgImg Coronavirus Statement

Coronavirus Statement

Our highest priority at TruSight Solutions is to maintain health and safety, and we are closely monitoring the global situation regarding the spread of coronavirus (COVID-19.) At the same time, we remain steadfast in our commitment to deliver assessment products of the highest quality for our customers and assessed parties. In light of these dual goals, this statement addresses precautions and strategies that TruSight is implementing with respect to on-site assessments and the assessors who conduct these facility visits.

Assessors who have been assigned to conduct on-site assessments have attested that they have not traveled in the past 30 days to a country with a Level 2 or Level 3 designation from the U.S. Centers for Disease Control and Prevention. (A Level 2 alert is for enhanced precautions, and a Level 3 warning is to avoid non-essential travel.)

Upon request, each individual assigned assessor will confirm this assurance in writing via email.

Any assessor currently conducting an assessment in an affected country is bound by the country’s domestic regulations and will remain in that country as long as required.

Assessors have been instructed to escalate any personal travel concerns to their manager. Individual concerns will be respected and assignments adjusted accordingly.

For reasons of health and safety, there could be a delay in conducting an assessment and/or delivering a product where a country is prohibiting travel or otherwise inhibiting movement that is necessary for such assessment. In this event, we will inform impacted vendors and customers as soon as we become aware of the situation. We may also propose performing a remote assessment in lieu of an on-site assessment and making adjustments accordingly.

As the coronavirus situation quickly evolves, TruSight is closely following developments from the World Health Organization, U.S. Centers for Disease Control and Prevention, and other domestic and international bodies. If you have questions or concerns, please reach out directly to your TruSight contacts.

scroll to top icon