Skip to content

Privacy Policy

(Last Updated and Effective as of: Oct 06, 2025)

Underscore Marketing, LLC — Global Privacy Statement

1. Introduction

This Privacy Statement describes how Underscore Marketing, LLC (“Underscore Marketing,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with our websites, marketing activities, and professional services.

This Statement is intended to satisfy the requirements of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 (UK GDPR), and applicable United States privacy laws, including comprehensive state-level privacy statutes that govern consumer rights, transparency, and data protection obligations.

Unless otherwise stated, this Global Privacy Statement applies to all individuals whose personal data we process worldwide.

2. Our Privacy Principles

We commit to:

  • Processing personal data lawfully, fairly, and transparently;
  • Limiting collection to what is relevant and necessary;
  • Seeking explicit consent when required;
  • Maintaining appropriate technical and organisational safeguards;
  • Respecting individual rights to access, correct, delete, restrict, and object to processing; and
  • Maintaining internal records of processing, performing data-protection impact assessments, and training our staff.

3. Sharing and Disclosure

We may share or disclose personal data only when it is lawful, proportionate, and consistent with the purposes described in this Privacy Statement. We do not sell personal information for monetary consideration.

We may disclose personal data to the following categories of recipients:

  • Service Providers / Processors
    Third parties are engaged to support our operations, including website hosting, analytics, marketing automation, customer relationship management (CRM), payment processing, email delivery, cloud storage, and IT security.
    • These parties act solely on our instructions.
    • They are bound by written contracts containing data-protection obligations, confidentiality, and security standards equivalent to ours.
  • Professional and Business Advisers
    External consultants, auditors, legal counsel, and accountants who require access to personal data for legitimate business purposes and who are subject to professional secrecy and confidentiality obligations.
  • Corporate Transactions
    In the event of a merger, acquisition, divestiture, financing, restructuring, or sale of all or part of our business, personal data may be transferred to prospective or actual purchasers, their advisers, or other relevant third parties as part of the transaction process.
    Any such transfer will occur under confidentiality agreements and with appropriate safeguards to ensure the maintenance of privacy protections.
  • Regulators, Courts, and Law-Enforcement Authorities
    We may disclose personal data when required by law, court order, or lawful request from government or regulatory authorities, or when necessary to:
    • comply with legal obligations;
    • protect our rights or property;
    • investigate suspected illegal activity, fraud, or security incidents; or
    • ensure the safety of individuals or the public.
  • Affiliates and Subsidiaries
    Where permitted by law, we may share personal data within the Underscore Marketing group of companies for administrative, analytical, or service-delivery purposes, consistent with the purposes outlined in this Statement.
  • Advertising and Analytics Partners
    With your consent (where required), we may share limited, pseudonymized, or aggregated information with partners who assist in measuring campaign effectiveness, website performance, or audience reach.
    No data is shared that directly identifies an individual without a lawful basis or consent.
  • Data Transfers Outside Your Jurisdiction
    Where recipients are located outside the European Economic Area, the United Kingdom, or your home jurisdiction, we implement appropriate safeguards—such as EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or reliance on the EU-US / UK-US Data Privacy Frameworks—to ensure an adequate level of protection.

We maintain a Third-Party Processor Register, which identifies key service providers, the nature of processing, and transfer mechanisms. This register is available upon legitimate request from regulators or clients, subject to confidentiality.

4. International Data Transfers

For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to countries not recognised as providing adequate protection, we rely on:

  • EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum; or
  • Certification under the EU-US and UK-US Data Privacy Frameworks (where applicable).

Additional safeguards, such as encryption and access controls, ensure equivalent protection.

5. Security

We maintain a comprehensive information-security program designed to protect personal data from unauthorised access, disclosure, alteration, and destruction.

Key measures include:

  • Encryption: Data encrypted in transit and at rest using industry standards;
  • Access Controls: Role-based permissions for authorised personnel only;
  • Network Security: Firewalls, intrusion detection, and endpoint protection;
  • Monitoring & Testing: Regular vulnerability scans, penetration tests, and independent audits;
  • Incident Response & Breach Notification: Documented procedures aligned with GDPR Articles 33–34 and U.S. state requirements;
  • Business Continuity: Backups and disaster recovery plans for resilience;
  • Vendor Oversight: Third-party processors must implement equivalent controls and are audited periodically; and
  • Employee Training: Mandatory privacy and security awareness programs for all staff.

While no system is entirely risk-free, these measures reflect our commitment to continuous improvement and alignment with global security standards.

6. Third-Party Websites

Our website may contain links to external sites not operated by us. We are not responsible for their privacy practices and recommend that you review their privacy notices before providing any personal data.

7. Individual Rights

We respect and facilitate the exercise of privacy rights granted under the GDPR, UK GDPR, and comprehensive U.S. state privacy laws.

Depending on your jurisdiction, you may have rights to:

  1. Access / Confirmation of processing;
  2. Correction / Rectification of inaccurate data;
  3. Deletion / Erasure (“Right to be Forgotten”);
  4. Restriction or Objection to processing (including direct marketing);
  5. Data Portability;
  6. Withdraw Consent at any time;
  7. Limit Use of Sensitive Personal Information;
  8. Opt Out of sale, sharing, targeted advertising, or profiling with significant effects;
  9. Appeal if we decline to act on your request; and
  10. Non-Discrimination for exercising your rights.

How to exercise:
Submit a request via our Data Request Form, email privacy@underscoremarketing.com, or call +1 (212) 651-4175.

We verify identity before acting on requests. Authorised agents may submit requests on your behalf with valid authorisation.

We respond within 30 days (GDPR) or 45 days (U.S. laws), with the option to extend the response time once, provided prior notice is given. Appeals are resolved within 45 days. You may complain to your local data-protection authority or state regulator.

8. Children

Our website and services are not directed to children under 13 (U.S.) or 16 (EU/UK) years of age. We do not knowingly collect their personal data.

9. Profiling and Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects based solely on automated processing, including profiling.

Automated decision-making means decisions made without human involvement that affect an individual’s rights or interests (e.g., credit or employment eligibility).
Profiling refers to automated processing used to evaluate personal aspects such as preferences or behaviour.

Where we use analytics or advertising tools that may constitute limited profiling, we ensure:

  • no legal or significant effects arise;
  • consent is obtained where required;
  • opt-out and withdrawal options are available; and
  • Human review occurs before any decision that could materially affect an individual.

Suppose we introduce automated decision-making in the future. In that case, we will update this Statement to provide the required information and safeguards (including human intervention rights) consistent with Article 22 of the GDPR and applicable U.S. state laws.

10. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes described herein, to comply with legal requirements, resolve disputes, and enforce agreements.

Retention criteria include:

  • purpose completion;
  • data type and sensitivity;
  • legal or contractual obligations and limitation periods; and
  • continuing business needs (e.g., audit or security).

At the end of the retention period, we will delete or irreversibly anonymise the data. Where immediate deletion is not possible, we isolate and secure the data until it is erased.

We maintain a documented retention schedule that is reviewed annually. Individuals may request deletion, subject to lawful exceptions (e.g., compliance with law or legal claims).

11. U.S. Consumer Privacy Rights

Residents of states with comprehensive privacy laws —including but not limited to California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia— may exercise the following rights:

  1. Know / Access data we process about you;
  2. Correct inaccurate information;
  3. Delete personal information, subject to legal exceptions;
  4. Data Portability in a readily usable format;
  5. Opt Out of sale, sharing, targeted advertising, or profiling with significant effects;
  6. Limit use of Sensitive Personal Information;
  7. Appeal our decision if a request is denied; and
  8. Be free from discrimination for exercising your rights.

How to exercise your rights: Submit your request via our website form, email privacy@underscoremarketing.com, or call +1 (212) 651-4175. We verify identity and respond within 45 days (extendable by one additional 45-day period with prior notice). Appeals resolved within 45 days.

We have not sold or shared personal information for monetary consideration in the past 12 months. If we engage in activities constituting “sale,” “sharing,” or “targeted advertising,” we will provide a “Do Not Sell or Share My Personal Information” link and honour browser-based opt-out signals such as Global Privacy Control (GPC).

Where required, we limit the use of sensitive personal information to statutorily permitted purposes and provide opt-out mechanisms where applicable.

12. Accountability and Governance

We maintain a comprehensive Privacy Management Program, including:

  • annual privacy risk assessments;
  • vendor due diligence and sub-processor register;
  • incident response and breach notification procedures; and
  • periodic training and audits to verify compliance.

13. Representatives and Contact Details

Contact Us
Underscore Marketing, LLC
90 Broad Street, 2nd Floor
New York, NY 10004 USA
Email: privacy@underscoremarketing.com
Phone: +1 (212) 651-4175

14. Updates to This Privacy Statement

We may update this Statement periodically to reflect any changes in law, technology, or operations. Material updates will be communicated via our website and, where feasible, directly to affected individuals.