This section (European Economic Area and United Kingdom section – collectively, for ease of reference, “EEA”) of WithumSmith+Brown, PC’s general Privacy Policy supplements that Privacy Policy but applies solely to individuals located in the European Economic Area and United Kingdom. This EEA section describes our policies and practices regarding the collection, use, and disclosure of personal data we collect about you online through our Website and from offline channels such as telephone calls, visits to our facilities and other in person interactions in accordance with the EU General Data Protection Regulation or UK General Data Protection Regulation (collectively, for ease of reference “GDPR”).

Any terms defined within the GDPR have the same meaning when utilized within this EEA section. All other terms shall have the meaning set forth in the Privacy Policy or Terms of Use, as applicable. The other provisions of the Privacy Policy continue to apply except as modified in this EEA section.

Please read this EEA section carefully before using the Website or submitting personal data to us. This EEA section is incorporated into and subject to our Terms of Use.

The Company is the data controller of the personal data we collect from you for the processing activities set forth in the Privacy Policy.

Collection of Personal Data

We collect and process the following personal data about you, where permitted by applicable law:

Marketing and communications data (e.g., name, address, email, company, IP address, subscriptions, interests). You are not required to provide any of the personal data listed above; however, if you choose not to provide certain information, products or services when requested, we may be unable to send you email alerts, respond to your inquiry, provide certain Website features, or comply with certain legal obligations.

Sources

We obtain information about you from the following sources:

Cookies and Web Technologies

Please see our Cookie Policy here for information on the cookies and web technologies placed by us or third parties on this Site. You can also accept or reject all non-essential cookies or customize your preferences in the Cookie Consent Manager by clicking on the “Cookie Preferences” link in the privacy banner pop-up. If you accept a cookie, you can freely withdraw your consent at any time by following the instructions in the Cookie Policy or Cookie Consent Manager. For information how we use personal data collected through these technologies, please continue reading.

Purpose and Lawful Basis for Processing

We process your personal data for a variety of purposes, as outlined below, where we have a lawful basis to do so. These bases generally include but are not limited to entering into or performing a contract with you; complying with applicable legal and regulatory obligations; where our legitimate interests or those of a third party are not outweighed by your privacy rights; as necessary to protect your interests or those of others; as necessary for the public interest; or based on your affirmative consent. The following chart identifies our purposes for collecting and processing your personal data and the lawful bases we rely on to do so.

If we process your special category data, we generally do so based on your explicit consent; as necessary for carrying out our obligations or exercising our specific rights or yours in the field of employment and social security and social protection law in so far as it is authorized by Union or Member State law or a collective agreement pursuant to EU member state law;where you have manifestly made it public; or, as necessary for the establishment, exercise or defense of legal claims.

You may obtain information regarding how we assess our legitimate interests or object to our processing your personal data when we rely on our legitimate interests by contacting us at [email protected].

We will process your personal data for the purpose for which we collect it and for further purposes only if we deem them compatible with that original purpose. Please note, we may process your personal data without your knowledge or consent when required or permitted by law.

When we process your personaldata based on your consent, you have the right to withdraw your consent for that specific processing activity at any time. To do so, please contact [email protected].

Sharing Your Personal Data

We may disclose or share your personal data for the purposes that we use it, as described in this Policy. To carry out such purposes, we may disclose your personal data to the following categories of third parties.

Some of these third parties may transfer your personal data out of the EEA or UK to another jurisdiction for processing or storage.

Data Subject Rights

You have certain rights under applicable law with respect to your personal data, subject to limitations. These may include the right to:

  1. Obtain confirmation as to whether we are processing your personal data, receive access to the personal data and information about that processing, and obtain a copy of the personal data in a commonly used electronic form.
  2. Request correction of incomplete or inaccurate personal data we hold about you.
  3. Request a restriction on the processing of your personal data in certain limited circumstances.
  4. Object to the processing of your personal data carried out in the public interest, based on our legitimate interest or those of a third party, or for purposes of direct marketing. You may obtain information regarding how we assess our legitimate interests or object to our processing your personal data when we rely on our legitimate interests by contacting us at [email protected].
  5. Request the erasure or deletion of your personal data.
  6. Receive your personal data, which you provided to us, in a structured commonly used machine-readable format and to transmit that personal data to another data controller where processing is based on your consent, pursuant to performance of a contract, or where the processing is performed by automated means.
  7. Not to be subject to a decision based solely on automated processing, including profiling, which produces a legal effect concerning you or similarly significantly affects you.
  8. Withdraw your consent where processing is based on consent.
  9. Lodge a complaint with the appropriate authority in your jurisdiction.

To exercise any of these rights, please contact us at [email protected].

Retention

We retain your personal data for as long as necessary to achieve the purpose for which we collected it and compatible purposes (e.g., to provide you products and services, maintain our relationship with you, ensure we don’t send marketing communications to you if you have opted out) . We may retain your personal data for longer if it is necessary to comply with our legal obligations or reporting obligations such as resolving disputes or collecting fees, or as permitted or required by applicable law. We may also retain your personal data in a deidentified or aggregated form so that it can no longer be associated with you. To determine the appropriate retention period for your personal data, we consider various factors such as the amount, nature, and sensitivity of your information; the potential risk of unauthorized access, use or disclosure; the purposes for which we process your personal data; and applicable legal requirements.

Transfers

We may share your personal data with related entities, subsidiaries, or affiliates, with data processors, or with other third parties. When we do so, this may involve transferring your personal data out of the EEA or UK to other countries including the U.S for processing or storage. When we transfer your personal data out of the EEA or UK, we do so in accordance with the applicable regulations to ensure it receives a similar degree of protection as provided by the data protection laws of your jurisdiction. For more information on the mechanism we use to transfer your personal data, please contact us at [email protected].

When you visit the Site or interact with certain features on our Site such third parties (e.g., a third party link or social media widget) may collect or access your personal data to provide you with certain services, content or information or to provide us with information about Site usage and visitors for analytics or marketing purposes. These third parties may transfer this information to a third country for processing or storage, including the U.S. Please see the privacy policies of these third parties for additional information, as well as our Cookie Policy .