Legal

Privacy Statement

This Privacy Statement (together with our

) describes the policies and procedures of Kroll Bond Rating Agency, LLC, KBRA Analytics, LLC, and its/their affiliates (collectively, “KBRA”, “we”, “our” or “us”) on the collection, use and disclosure of your information in connection with your use of or access to the services, features, content or applications we offer, including but not limited to any credit rating, other permissible service, research or press release (the “Services”), through our websites at
www.krollbondratings.com
,
www.kbra.com
or
www.kbraanalytics.com
(collectively, the “Website”), or by any other means, or in respect of your registration for, attendance at or participation in events which we host, organize or sponsor (alone or with others) (“Events”). We receive information about you from various sources, including without limitation: (i) if you register for the Website and the Services, through your user account on the Services (your “Account”); (ii) your use of the Services generally; (iii) your purchase of any of the Services; (iv) your contact and/or communication with any of our employees; (v) from you (or from someone acting on your behalf, as applicable) if you are registered for, attend or are a speaker at any of our Events or via a third party with whom we co-sponsor or co-organize any Event and (vi) from third party websites and services.

When you use the Services, register for, attend or are a speaker at any Event, your information is subject to the collection, transfer, manipulation, storage, disclosure and other uses (i.e., processed) as described in this Privacy Statement. Our servers, which hold your Personal Data (defined below) are hosted and operated in the United States and our Services and Events are subject to United States law and applicable data privacy laws.

For the purpose of applicable data privacy laws, the data controller of your Personal Data is Kroll Bond Rating Agency, LLC of 805 Third Avenue, 29th Floor, New York, NY 10022, USA, Kroll Bond Rating Agency Europe Limited, with a registered address at 6-8 College Green, Dublin 2, Ireland, KBRA UK Limited, with a business and registered address at Second Floor, 1 Connaught Place, London W2 2ET, United Kingdom and/or KBRA Analytics, LLC of 805 Third Avenue, 29th Floor, New York, NY 10022, USA.

Please read the following carefully to understand our use of your Personal Data.

What Does This Privacy Statement Cover?

This Privacy Statement covers any data relating to a living individual who can be identified directly from that data or indirectly in conjunction with other information (“Personal Data”), that we process in relation to the Services or Events. The term Personal Data includes “personal information”, as such term is defined under the California Consumer Privacy Act of 2018 (“CCPA”) (Civil Code § 1798.100), “private information”, as such term is defined under the New York Stop Hacks and Improve Electronic Data Security Act (“SHIELD Act”) (N.Y. Gen. Bus. L. §899-bb), and “personal data”, as such term is defined under the European Union General Data Protection Regulation (EU) 2016/679 and the United Kingdom General Data Protection Regulation.

This Privacy Statement does not apply to the practices of third parties that we do not own or control, including but not limited to any third party websites, services and applications (each a “Third Party Service” and collectively, “Third Party Services”) that you elect to access through the Service or relating to an Event, for example by clicking on links to those Third Party Services from within the Website, or to individuals we do not manage or employ. While we attempt to facilitate access only to those Third Party Services that share our respect for your privacy, we cannot take responsibility for the content or privacy statements of those Third Party Services. We encourage you to carefully review the privacy statements of any Third Party Services you access.

What Information Do We Collect and Why Do We Process It?

The information we gather enables us to personalize, improve and continue to operate the Services. In connection with certain aspects of the Service, we may request, collect and/or display some of your Personal Data. We collect the following types of information from our users.

Account Information:

When you create an account for the Services (“Account”), you will provide information that could be Personal Data, such as your username, password and email address. We may use your contact information to: (i) send you information about our Services; (ii) send you marketing information; (iii) invite you to conferences or Events; (iv) request meetings with you; (v) 2 evaluate your use of the Services and (vi) add you to internal contact and distribution lists. We may contact you when we believe it is necessary, such as for account recovery purposes. You may unsubscribe from marketing messages at any time through your Account settings, via the “unsubscribe” link in an email we have sent you, or by emailing

.

Cookies, IP Address Information and Other Information Collected Automatically:

  • We automatically receive and record information from your web browser when you interact with the Services, including your IP address and cookie information. This information is used to: (i) fight spam/malware; (ii) facilitate the collection of data concerning your interaction with the Services (e.g., which links you have clicked on or how many articles you have downloaded); (iii) prevent unauthorized access to and use of the Services; and (iv) track overall website usage to improve our Services and promote our business.
  • The Services automatically collect usage information, such as the number and frequency of visitors to the Services. We may use this data in aggregate form, that is, as a statistical measure. This type of aggregate data collection enables us and third parties authorized by us to better understand and operate the Services, such as by helping us figure out how often individuals use parts of the Services so that we can analyze and improve them. We may also collect data regarding individuals' accessing of the Services for sales and marketing purposes. We will never sell this data to third parties.
  • We may collect some device-specific information if you access the Services using a mobile device. Device information includes unique device identifiers, network information, and hardware model, as well as information about how the device interacts with our Services. This information is used to (i) collect information relating to usage of the Services and (ii) maintain and improve the Services so that it supports the device types used to access the Services.
  • By ticking the box consenting to the use of cookies in your KBRA account, you consent to our use of cookies as set out herein. If you do not consent to the use of cookies, you may block or disable them using your browser settings or through the opt-out links set out in “Types of Cookies used on the Website” section below. However, blocking cookies may limit your ability to use our Website and access to the Services.

Electronic Communications:

We may track when you open an electronic communication from us. We use this tracking to improve our customer service. We may also monitor and store electronic communications sent to or from us, including emails and text messages. Where we send you marketing or promotional e-mails regarding our products or services from our different divisions and affiliates, we do so based on your consent, if required by applicable law.

User Generated Data

Data generated by you in your use of the Services and your Account settings will be visible to necessary KBRA employees and will remain visible to such employees until you disable your Account.

Information Collected Using Cookies:

For information on how we use cookies please see

.

Events:

In connection with Events, we may request, collect and/or display some of your Personal Data. We collect the following types of information from our invitees, attendees and speakers:

  • When we invite you to an Event, if you have an Account with us, we track when you open an electronic communication from us and if you click on any of the links included.
  • When you register (or when someone acting on your behalf registers you) for or you attend one of our Events, we process the following information about you: name, email address and company.
  • Any personal data contained in responses you provide to any follow up survey relating to an Event you registered for or attended.
  • If you attend an Event, we might capture your image in photographs and videos. If you object to this, please contact us at [email protected] or inform one of our staff at the Event (for instance, you can tell the photographer at the time they are taking the photo).
  • In you are a speaker at one of our Events, we process your name, a short profile about you (which you submit to us or approve), professional and contact details and images or other personal data relating to you such as your voice, or likeness or any combination thereof (e.g., by taking photographs or recording videos, etc.) captured in connection with the Event.

Information You Give Us About Other People

If you provide information to us about any person other than yourself, you should ensure that you have a legal basis for doing so and that you have complied with your transparency obligations under data protection law. You should also try to limit the Personal Data you give us to what you think is necessary for us to provide our Services or for someone else to speak at or attend an Event.

Where Is My Information Stored?

As a global business, the information that we collect from you may be transferred to, and stored at, any of our locations which may be inside or outside the European Economic Area or United Kingdom including, in particular, the United States for the purposes described above. Our primary servers are in the United States. Some countries may not provide an adequate level of protection in relation to processing your data.

We have in place requirements relating to such international data transfers, for transfers both: (i) among our legal entities; and (ii) to third parties. We use specific contractual clauses designed to cause those third parties to respect the confidentiality of your Personal Data and use it only in connection with providing their services to us and in compliance with applicable data privacy laws. Please contact us at

if you wish to obtain information concerning such safeguards.

We will not retain your Personal Data for longer than is necessary for the purposes for which it was collected, as required by law, and for the exercise or defense of any legal claims.

How and Why Is My Information Processed, and With Whom Is My Information Shared?

Some of the information collected through or in connection with the Services is shared with third parties.

Downloading CUSIP Data

When you register for an Account, you accept additional terms which constitute an agreement with CUSIP Global Services (“CGS”) on behalf of the American Bankers Association. You acknowledge therein that the following information will be provided to CGS in connection with your download of any CUSIP data: your username, firm name downloaded by you, email address and IP address. This information will be used for purposes of monitoring compliance with your agreement with CGS and will be stored securely in the United States. It may be reviewed and corrected by contacting

. For additional information about CUSIP customer privacy practices, please visit
www.CUSIP.com
.

Websites Hosted by Squarespace

Some of our Websites are hosted via Squarespace, and for such Websites your Personal Data is processed by Squarespace, including for protection and improvement of Squarespace's services, as further described in Squarespace's

.

IP Address Information:

While we collect and store IP address information, that information is not made public. We do at times, however, share this information with third parties that provide us with certain services (each a “Service Provider” and collectively, “Service Providers”), including Google Analytics, and as otherwise specified in this Privacy Statement.

Aggregate Information:

We collect statistical information about how both unregistered and registered users, collectively, use the Services (“Aggregate Information”). Some of this information is derived from Personal Data. We may use this Aggregate Information for any purpose in connection with our business and may share Aggregate Information with our partners, Service Providers and other persons with whom we conduct business. We share this type of statistical data for purposes such as helping our partners and Service Providers to understand how and how often people use our Services and their services or websites, which facilitates improving both their services and how our Services interface with them. In addition, these third parties may share with us non-private, anonymized, aggregated or otherwise non Personal Data about you that they have independently developed or acquired. We also use this information to improve our Websites and promote our to business and Events.

Information Shared with Our Service Providers and Third Parties:

We may need to share Personal Data with our Service Providers in order for them to perform their services for us. Unless we tell you differently, our Service Providers do not have any right to use Personal Data or other information we share with them beyond what is necessary to assist us.

In respect of any Event, we may also share your data with our affiliates or with any partner, co-sponsor or co-organizer. In these circumstances will notify you of the identify of any such third party and provide you with a copy of their privacy statement.

Information Disclosed Pursuant to Business Transfers:

In some cases, we may choose to buy or sell assets. In these types of transactions, user information is typically one of the transferred business assets. Moreover, if we, or substantially all of our assets, were acquired, or if we go out of business or enter bankruptcy, user information would be one of the assets that is transferred or acquired by a third party.

Information Disclosed for Our Protection and the Protection of Others:

We also reserve the right to access, read, preserve, and disclose any information as we reasonably believe is necessary to (i) satisfy any applicable law, regulation, legal process or governmental request, (ii) enforce this Privacy Statement and our

, including investigation of potential violations hereof, (iii) detect, prevent, or otherwise address fraud, security or technical issues, (iv) respond to user support requests, or (v) protect our rights, property or safety, our users and the public. This includes exchanging information with other companies and organizations for fraud protection and spam/malware prevention.

Events:

We store photographs, videos and voice recordings from our Events on our systems and may post these to our Websites, service provider sites and/or on our social media. If you speak at one of our Events, we may also tag you and your company in photos from the Event on our social media. We may contact you after an Event you attended or registered for in relation to that Event.

We process this personal data for the purposes of conducting and promoting our business, including organizing Events and using associated promotional materials.

Information We Share:

Except as set forth herein, you will be notified when your Personal Data may be shared with third parties and will be able to prevent the sharing of this information.

Is Information About Me Secure?

Your Account information will be protected by a password for your privacy and security. You need to prevent unauthorized access to your Account and Personal Data by selecting and protecting your password appropriately and limiting access to your computer and browser by signing off after you have finished accessing your Account.

We seek to protect your information, including your IP address information, to keep it private; however, as no data transmission over the internet can be guaranteed as 100% secure, we cannot guarantee or warrant the security of any information that you transmit to us. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.

Our Legal Basis for Processing Your Personal Data

We will only process your Personal Data for the purposes set out below, to the extent necessary:

  • in order for your contract with us to be performed;
  • in order to comply with any legal or regulatory obligations; and
  • for our legitimate business interest in managing our business including legal, information technology, sales, administrative and management purposes and for the prevention and detection of crime and/or unauthorized use of the Services, provided our interest are not overridden by your interest.

Marketing and Events:

In respect of marketing and Events, we rely on (a) consent which you may withdraw at any time or (b) our legitimate interests in organizing Events, managing our business and providing and improving our Services, provided such interests are not overridden by the rights and interests of the data subjects concerned.

In respect of speakers at our Events, our lawful basis for processing your personal data is that the processing is necessary for the purposes of (a) our legitimate interests in organizing the Event and conducting and promoting our business activities, and (b) the legitimate interests of the Event audience in receiving the any materials relating to that Event which include your personal data described above.

What Information of Mine Can I Access?

If you are a registered user, you can access profile information associated with your Account by logging into the Services. Registered and unregistered users can access and delete cookies through their web browser settings.

What Rights Do I Have Regarding My Information?

  • For our Services, you can use some of the informational and marketing features of the Services without registering, thereby limiting the type of information that we collect.
  • You can always opt not to disclose certain information to us, even though it may be needed to take advantage of some of our features or Services or to attend an Event.
  • You can disable your Account. If you decide to do this, email
    [email protected]
    . If you disable your Account, any association between your Account and information we store will no longer be accessible through your Account. However, any activity on your Account prior to disabling the Account and your contact information will remain stored on our servers. Any public comments you have made through the Services will remain accessible to the public. Please note that we will need to verify that you have the authority to disable the Account.

Additional Provisions in Respect of Individuals in the European Union and United Kingdom

  1. You can object to the processing of your Personal Data where our legal basis for processing your Personal Data is our legitimate interests (or those of a third party).
  2. You can request access to a copy of your Personal Data held by us and details of the processing of your Personal Data by us. In the European Union (“EU”) and United Kingdom (“UK”), an initial copy of your Personal Data is provided free of charge, but we may charge a reasonable fee, based on administrative costs, for any further copies that you request.
  3. You can ask to have Personal Data we hold corrected if it is inaccurate or incomplete.
  4. You can request us to delete your Personal Data in certain circumstances.
  5. You can request us to stop processing your Personal Data in certain circumstances, including where the processing is unlawful or no longer necessary.

    You can ask us not to process your Personal Data for marketing purposes. If you do not want to receive newsletters, announcements, or other communications and/or services from us, please do not opt-in for those communications or services at the time of registration. If you have opted-in and, at a later time, wish to opt-out, please click on the unsubscribe link inserted in our communications or amend your preferences at

    . Along with every marketing email communication sent to you, we provide you the opportunity to discontinue receiving future communications (i.e., unsubscribe). Simply follow the unsubscribe process or directions provided in the email. You can also exercise the right at any time by contacting us at
    [email protected]
    .

  6. You can object to any decision about you based solely on automated processing (including any profiling) that produces legal effects or otherwise significantly affects you.
  7. You can complain to the relevant data protection supervisory authority in particular in the Member State of your residence, place of work or place of an alleged infringement, if you think that we are not complying with our GDPR or UK GDPR, as applicable obligations in relation to our processing of your Personal Data.
  8. We may, from time to time, ask for your consent to our use of your Personal Data for a specific purpose. If you are an individual in the EU or UK, you have the right to withdraw your consent to that use at any time.

However, depending on applicable law, these rights may not be exercised in certain circumstances, such as when the processing of your Personal Data is necessary to comply with a legal obligation or for the exercise or defense of legal claims. If you wish to exercise any of your rights in this regard please email

. All requests will be dealt with promptly and any information to which you are entitled will be provided within a reasonable timeframe as required by applicable law, subject to the exemptions stipulated in applicable data privacy laws. We may request proof of identification to verify your request.

In limited circumstances (such as our use of social media), we may act as a joint controller with another party. In such circumstances, upon your request to exercise any of the above rights we will advise you if there is another controller who you should contact. Please note that any other joint controller will also have its own privacy policy.

Additional Provisions in Respect of California Residents

  1. If you are a resident of California, the CCPA provides you with specific rights regarding your Personal Data. These include:
    1. The right to request a copy of the Personal Data we collected from you.
    2. The right to request information about our collection and use of your Personal Data: (i) the categories of Personal Data we collected about you in the preceding twelve (12) months, (ii) the categories of sources from which your Personal Data was collected, (iii) the business or commercial purpose(s) for which your Personal Data was collected, (iv) the categories of third parties with whom we shared your Personal Data, and (v) the categories of Personal Data we disclosed for a business purpose in the preceding twelve (12) months and, for each category identified, the categories of third parties to whom we disclosed that particular category of Personal Data.
    3. The right to request that we delete your Personal Data, subject to certain exceptions.
  2. To exercise the rights described above, it may be necessary for us to verify your identity or authority to make the request and confirm the Personal Data relates to you. Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your Personal Data. If you are making the request yourself, we will verify your identity through our existing authentication practices for your password-protected account. We will not discriminate against you for exercising any of your privacy rights under the CCPA or applicable law.
  3. During the past twelve (12) months, we collected from California residents the categories of Personal Data described above under “What Information Do We Collect?” and disclosed such Personal Data to third parties for the purposes specified above under “How, and With Whom, Is My Information Shared?”.
  4. We do not sell your Personal Data.
  5. You may exercise any of the rights described in this section by (i) clicking here and completing the form at such link; (ii) submitting a written request to (a) Legal Department at Kroll Bond Rating Agency, 805 Third Avenue, 29th floor, NY, NY 10022 or (b)
    [email protected]
    , or (iii) calling (646) 731-1240.

What Happens When There Are Changes to this Privacy Statement?

We may amend this Privacy Statement from time to time. Use of information we collect now is subject to the Privacy Statement in effect at the time such information is collected. If we make any material changes in the way we collect or use Personal Data, we will notify you by posting an announcement on the Services or sending you an email.

What If I Have Questions or Concerns?

If you have any questions or concerns regarding privacy using the Services, please send us a detailed message to

. We will make every effort to resolve your concerns.

Effective Date: July 6, 2023

CONNECT WITH KBRA
805 Third Avenue
29th Floor
New York, NY 10022
+1 (212) 702-0707
Contact Us

© 2010-2024 Kroll Bond Rating Agency, LLC. All Rights Reserved. Kroll Bond Rating Agency, LLC is not affiliated with Kroll Inc., Kroll Associates Inc., KrollOnTrack Inc., or their affiliated businesses.