1. Contact Information
Please contact us with any questions, comments, or data rights requests regarding this Privacy Notice using the following details:
Legal and Compliance Department
Octus Intelligence, Inc.
295 5th Ave 6th Floor
New York, NY 10016
Email: [email protected]
To exercise any privacy right described in this Notice, including requests to access, correct, or delete your personal information, and requests to opt out of the sale or sharing of personal information, please contact us at [email protected]. We will verify your request as described in the regional sections below.
2. Scope and Architecture
This Notice distinguishes between data collected through our public websites and subscription services, and data processed within our enterprise product applications, because different practices and legal roles apply to each.
3. Information We Collect
The categories of personal information we collect depend on how you interact with our Platform and Services:
A. Website, Research, and Subscription Data (General Services)
For visitors to our public websites, subscribers to Octus newsletters, and users of our subscription intelligence platforms, we collect:
- Identifiers: Name, professional email address, telephone number, and IP address.
- Professional Information: Employer and job title.
- Account and Authentication Information: Usernames, account identifiers, password hashes, multi-factor authentication records, password-reset information, and other authentication or access-control data
- Internet or Electronic Network Activity: Details of your visits to, and actions you take on, the Platform or via the Services, including traffic data, approximate location inferred from IP address, browser and device information, interaction and usage logs, and the resources you access.
- Commercial Information: Subscription history, billing records, and research or content preferences.
B. Customer Content and Enterprise Product Data
Within enterprise product environments, Octus processes Customer Content on behalf of subscribing institutional customers and separately processes Service Administration Data for Octus’ own account, authentication, security, support, billing, compliance, and service-management purposes.
- Customer Content: Institutional inputs, investment tracking files, sourcing records, issuer details, financial metrics, deal parameters, internal system notes, approval records, collaboration logs, transactional queries, prompts, document uploads, and other content submitted to the Services by or on behalf of a customer. Octus processes Customer Content under the applicable customer agreement and the customer’s instructions.
- Service Administration Data: Business contact details, account-registration and administration records, authentication and security telemetry, device and browser information, service-usage records, support communications, billing and contract administration, fraud-prevention information, and similar data used to administer, secure, support, and manage the Services and customer relationships.
- Product Interaction Data: Records of how authorized users interact with enterprise products, including feature usage, access and authentication events, support records, error logs, and security telemetry. Octus may process this data as Service Administration Data where it determines the purposes and means of processing.
- AI and Automated Processing Data: Text prompts, document uploads, contextual information, and related interaction data submitted to automated processing, parsing, or analytic features.
C. Sources of Personal Information
Depending on the context, Octus collects personal information directly from you; from your employer or the subscribing institution that provides or administers your account; automatically from browsers, devices, cookies, similar technologies, system logs, and use of the Platform or Services; from customer-authorized integrations and connected services; from service providers supporting authentication, security, billing, support, analytics, marketing, and events; and from business partners, referral sources, professional networks, publicly available sources, and data providers, where permitted by law.
4. Why We Collect Your Information
We process personal information for specific, delineated business and commercial purposes:
- Providing and Administering the Services: To authenticate user access, maintain active customer accounts, and deliver core operational platform functionality.
- Managing the Customer Relationship: To facilitate billing, respond to customer inquiries, provide technical support, and communicate updates regarding the Platform or Services.
- Analyzing and Improving the Platform: To evaluate usage patterns, monitor frequencies of interaction, and enhance system functionality.
- Automated Data Processing: To parse documentation, automate manual entry, and generate data summaries or platform analytics. We do not use customer-submitted operational inputs or proprietary documents to train generalized, cross-tenant machine learning models.
- Security and Compliance: To monitor, investigate, prevent, and detect fraud, security incidents, or misuse of the Platform, and to satisfy legal, audit, tax, or regulatory requirements.
5. How We Share Information
Information sharing rules are strictly applied depending on the environment in which the data is collected:
A. Platform Websites and Marketing
We may share identifiers and usage data with technical vendors who assist in administrative operations and subscriber communications. Where permitted by law, we allow selected third-parties to collect data through cookies and tracking technologies on our public-facing websites to evaluate marketing campaigns and serve tailored professional advertisements.
The cookies and similar tracking technologies on our public-facing websites fall into the following categories: strictly necessary cookies, which are required for site security, network management, and accessibility; performance and analytics cookies, which help us understand how visitors use our websites so we can improve them; functional cookies, which enable enhanced features and remember your preferences; and advertising cookies, which may be set by us or our advertising partners to measure campaign effectiveness and serve tailored professional advertisements. Strictly necessary cookies operate without your consent.
Where required by law, including in the EEA and United Kingdom, we set performance, functional, and advertising cookies only with your prior consent, which you may withdraw at any time using the cookie management tool available on our public websites. Disabling non-essential cookies will not affect your access to our enterprise product environments, where, as described in Section 5.B, tracking technologies for marketing or behavioral advertising are not used.
B. Enterprise Product Environments
Customer Content is not used or disclosed for marketing or cross-context behavioral advertising. It is disclosed only as permitted by the applicable customer agreement, including to subprocessors that help host, secure, operate, and support the relevant product and to integrations authorized by the customer. Octus may separately disclose Service Administration Data to service providers supporting account administration, authentication, security, support, billing, service analytics, fraud prevention, and legal or compliance obligations. Octus does not use advertising cookies or tracking technologies for cross-context behavioral advertising within enterprise product environments, but may use authentication, security, operational, support, error-reporting, and service-analytics technologies.Enterprise product data is shared only with:
- Infrastructure Sub-Processors: Secure cloud hosting infrastructure providers and specialized technical API sub-processors bound by strict data protection, logical isolation, and confidentiality agreements.
- Authorized Integrations: Downstream administrators, custodians, or third-party service systems explicitly authorized and connected via API by our customers.
- Service Administration Providers: Vendors supporting identity and access management, security, customer support, billing, service communications, analytics, fraud prevention, and legal or compliance functions.
C. Corporate Transfers
In the event that Octus undergoes a merger, acquisition, corporate restructuring, or asset sale, client and user databases are generally considered business assets and may be transferred to the successor entity, subject to the privacy commitments made in this Notice.
6. Data Security and Isolation
Octus implements appropriate technical, administrative, and physical measures designed to safeguard personal and institutional data against unauthorized access, loss, alteration, or disclosure. For our enterprise application layers, we maintain logical multi-tenancy access controls designed to keep each subscribing institution’s data logically separated from that of other institutions. Internal engineering and operational access to live production databases is restricted to authorized personnel, monitored, and logged for auditing purposes.
7. Retention
Octus retains personal information for as long as reasonably necessary for the purposes described in this Notice, including to provide the Services, or for other legitimate purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements. For personal information and institutional data processed within our enterprise product environments, retention is governed by our agreement with the subscribing institution, and we delete or return such data in accordance with that agreement upon termination of the customer relationship, subject to any legal retention requirements.
8. International Transfers
Octus is headquartered in the United States, and personal information we process may be transferred to, stored in, or accessed from the United States and other countries that may provide a different level of data protection than your country of residence. Wherever personal information is transferred, we take steps to ensure it remains protected in accordance with this Notice and applicable law. Additional safeguards that apply to transfers of personal data subject to the GDPR and UK GDPR are described in the European Economic Area and United Kingdom section below.
9. Regional Disclosures and Individual Rights
Depending on your jurisdiction, you may possess specific statutory rights regarding your personal data:
A. European Economic Area (EEA) and United Kingdom
- Where We Act as a Data Controller: For personal data collected via our public websites, newsletters, and core marketing subscriptions, Octus acts as a “Data Controller” under the GDPR/UK GDPR. For these activities, Octus relies on the lawful basis applicable to the particular processing, including performance of a contract, compliance with legal obligations, legitimate interests, and consent where required.
- Where We Act as a Data Processor: For Customer Content that Octus processes on behalf of a subscribing institutional customer and under that customer’s instructions, the customer is the Data Controller and the applicable Octus entity acts as a Data Processor. This processing is governed by the applicable customer agreement, including the Data Processing Addendum or equivalent binding data-protection terms.
- International data transfers. Where we transfer personal data outside the EEA or United Kingdom, we use an appropriate transfer mechanism as required by the GDPR or UK GDPR. Where an applicable adequacy decision or adequacy regulation covers the transfer, we may rely on that decision or regulation. Otherwise, for personal data for which Octus acts as a Data Controller, including transfers between Octus group companies, Octus uses the European Commission’s Standard Contractual Clauses and, for restricted transfers from the United Kingdom, the UK International Data Transfer Addendum, together with any additional safeguards required by applicable law. For personal data and institutional inputs for which Octus acts as a Data Processor, cross-border transfers are governed by the applicable data-transfer provisions of the Data Processing Addendum and the instructions of the relevant subscribing customer. You may request additional information about, or a copy of, the applicable safeguards by emailing [email protected], subject to appropriate redactions to protect confidential information.
- Data Subject Rights: Depending on the circumstances, individuals in the EEA or United Kingdom may have rights to request access, rectification, erasure, restriction, and portability; object to processing based on legitimate interests; object at any time to direct marketing; withdraw consent where processing is based on consent; and lodge a complaint with the applicable supervisory authority. For Customer Content processed solely on behalf of a subscribing customer, the customer is responsible for responding to rights requests. You should generally submit such a request to your organization’s account administrator. If you submit it to Octus, we will route it to the appropriate customer or assist the customer as required by applicable law and contract.
Please email us at [email protected] if you wish to exercise any of these rights. You should provide sufficient information that allows us to reasonably verify you are the person about whom we collected the personal information or an authorized representative of that person, and describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
B. California (CCPA/CPRA)
This section summarizes Octus’ California privacy disclosures for the preceding 12 months. During that period, Octus collected the categories of personal information described in Section 3, from the sources described in Section 3.C, and for the purposes described in Section 4. Octus disclosed the categories of personal information described in Section 3 to the recipient categories described in Section 5 for business purposes, as applicable. Octus did not sell personal information. Octus may have shared identifiers and internet or electronic network activity with advertising partners for cross-context behavioral advertising on public marketing channels, as described below. Section 7 describes the criteria Octus uses to determine retention periods.
- Where We Act as a Business: Octus acts as a “Business” under the CCPA/CPRA for personal information for which Octus determines the purposes and means of processing, including website, marketing, subscription, account, security, support, billing, and other Service Administration Data. Octus does not sell personal information. On public marketing channels, Octus may “share” identifiers and internet or electronic network activity with advertising partners for cross-context behavioral advertising. You may opt out through the “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” link on our public websites. Octus also processes qualifying opt-out preference signals, including Global Privacy Control, as requests to opt out of sale or sharing for the browser or device sending the signal and, where we can associate the signal with an account, the associated account.
- Where We Act as a Service Provider or Contractor: For Customer Content processed on behalf of and under the instructions of a subscribing institutional customer, Octus acts as a “Service Provider” or “Contractor” under the CCPA/CPRA, as applicable. The customer is responsible for responding to requests concerning Customer Content. You should generally direct such requests to the customer that controls the enterprise account. If you submit a request to Octus, we will route it to the appropriate customer or assist the customer as required. Octus may separately act as a Business for Service Administration Data associated with the same enterprise account.
- Sensitive Personal Information. Among the categories of personal information we collect, account log-in credentials constitute “sensitive personal information” under the CCPA/CPRA. We collect and use these credentials solely to authenticate users and secure account access – purposes for which the CCPA/CPRA does not require us to offer a right to limit use. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for any purpose that would entitle you to limit its use under the CCPA/CPRA.
- Consumer Rights: California residents may request access to, correction or deletion of, and a portable copy of their personal information, subject to applicable exceptions. Requests to know may cover personal information collected on or after January 1, 2022, unless doing so would be impossible or involve disproportionate effort. Submit requests using the methods in Section 1. Authorized agents may submit requests with proof of authorization. Octus will not discriminate against you for exercising these rights.
- Minors: The Platform and Services are intended for business and professional users and are not directed to children under 16. Octus does not have actual knowledge that it sells or shares the personal information of consumers under 16.
- Browser Privacy Signals and Cross-Site Tracking: Octus processes qualifying opt-out preference signals, including Global Privacy Control, as described above. Because there is no common industry standard for interpreting legacy “Do Not Track” browser headers, our public websites respond to Global Privacy Control rather than to that header. Where advertising cookies or similar technologies are enabled, advertising and analytics partners may collect information about your activity over time and across different websites, as described in this Notice and the Cookie Notice.
10. Changes to This Notice
Octus may update this Notice from time to time. When we make material changes, we will post the revised Notice, update the “Effective Date,” and provide additional notice where required by law.