PRIVACY NOTICE FOR DATA SUBJECTS IN EMEA

Effective Date: August 2026

Your privacy is important to us. This privacy notice (“Privacy Notice“) applies to every person from the European Economic Area (“EEA“), Switzerland, the United Kingdom (“UK“) and the Dubai International Financial Centre (“DIFC“), collectively “EMEA”:

  • who visits or registers with www.citadel.com, www.citadelsecurities.com or any other of our websites where this policy is posted (each a “Site“);
  • who uses the products and services that we make available from the Site or who engages with us to use the services that Citadel provides, as described on the Site (our “Services“);
  • whose personal data we may process as a result of providing the Services to others;
  • who contacts Citadel either in relation to the Site or the Services; or
  • who we have identified as a potential candidate, has expressed an interest in, or has applied to work at Citadel.

Please read this Privacy Notice as it explains how we handle your personal data and your rights in relation to it.

1. PURPOSES OF THIS NOTICE

This Privacy Notice explains to data subjects in EMEA the type of personal data that Citadel Enterprise Europe Limited, Citadel Enterprise Europe Services Limited, Citadel Securities Ireland Services Limited, Citadel Securities Europe Services Limited, Citadel Securities France Services SAS, Citadel HF Management (Europe) LLP, Citadel Management (Europe) Limited, Citadel Management (Europe) II Limited, Citadel Management (Europe) III Limited, Citadel Enterprise France SAS, Citadel France SAS, Citadel Securities (Europe) Limited, the Dublin Branch of Citadel Securities (Europe) Limited, Citadel Securities GCS (Ireland) Limited, the Paris Branch of Citadel Securities GCS (Ireland) Limited, the Amsterdam Branch of Citadel Securities GCS (Ireland) Limited, Citadel Securities Switzerland GmbH, the Amsterdam Branch of MRI Analytics Services LLC, Citadel Enterprise Switzerland GmbH, Citadel Securities Netherlands Services B.V., Citadel Enterprise (DIFC) Services Limited, Citadel Flex Power GmbH, Citadel Flex Power Services GmbH, Citadel Enterprise Americas LLC, Citadel Securities Americas LLC, Citadel Americas LLC and their affiliates (“Citadel” “we“, “us” or “our“) might collect from you, or which we have obtained about you from a third party, the purposes for which we process your personal data and your rights in respect of our processing of your personal data.

When using the Site, this Privacy Notice should be read in conjunction with our Website’s Terms of Use.

This Privacy Notice only applies to the use of your personal data obtained by us, whether from you directly or from a third party. It does not apply to your personal data collected by third parties during your communications with those third parties or the use of their products or services.

This Privacy Notice is intended to meet the requirements of privacy laws of the UK, the EEA, Switzerland, and DIFC, in particular the EU’s General Data Protection Regulation (the “EU GDPR“), the UK GDPR, the Swiss Data Protection Act (the “Swiss DPA“), other similar European privacy laws, and the DIFC Law No. 5 of 2020 on Data Protection Law (the “DPL 2020“). Any references in this Notice to concepts under the EU GDPR should be read to mean the same as the equivalent concept under the UK GDPR, Swiss DPA, and the DPL 2020.

Additionally, as an international business we may be subject to other privacy laws and process personal data relating to individuals located in other territories – if this applies to you, please visit our global privacy notice at https://www.citadel.com/privacy/.

2. WHO ARE WE AND WHAT DO WE DO?

We are the data controllers responsible for your personal data processed via the Site and/or use of our Services.

Depending on which Citadel entity you contract with for the Services, or to which Citadel entity you apply for a job, other Citadel group companies or companies managed by Citadel (the “Citadel Group“) may also be data controllers responsible for your personal data processed in relation to the Services. For details of our group companies and office locations, see our Global Privacy Notice.

3. PERSONAL DATA COLLECTION

In providing our Site and Services, we may collect and process different types of personal data about you for different processing purposes. These purposes include:

  1. to verify your identity;
  2. to help us deliver the Services;
  3. to develop new products or Services and conduct analysis to enhance current products and Services;
  4. to review the usage and operations of the Site (and related Citadel digital channels, including Citadel social media channels) and to improve its content;
  5. to provide you with customised Site content and Site experience (including on related Citadel digital channels, including Citadel social media channels);
  6. to carry out requests made by you on the Site or in relation to Services;
  7. to respond to user enquiries/offer support on the Site or in relation to Services;
  8. to investigate or settle inquiries or disputes;
  9. to comply with any applicable law, court order, other judicial process, or the requirements of any relevant regulator;
  10. to enforce our agreements with you;
  11. to protect our rights, property or safety or third parties, including our other clients and users of the Site or Services;
  12. for recruitment, talent management, brand building, company communications, employment and academic trading program administration purposes;
  13. to record telephone calls with you in order to comply with our financial regulatory obligations (or for other proportionate purposes); and
  14. to use artificial intelligence technologies provided by third-party vendors to support and improve the efficiency of our business operations; and
  15. to use as otherwise required or permitted by law.

The personal data we collect from you may include:

  • Visitors to the Site.
    • Contact information, including your name, job title, address, email address, telephone, or mobile number.
    • Your interaction with the Site.
    • IP address.
    • Your geolocation to ensure the correct notices (for instance cookie notices) are shown to you and to personalise the services we provide to you.
    • Demographic information such as postcode, preferences and interests (including demographic information provided by third parties which may include amongst other things: location, hardware details for trouble shooting, search engine, social media interactions, interests and/or preferences).
    • Other information relevant to provision of Services.
    • Any other personal data you provide to us (including, for Alpha League platform visitors, any information you provide about investment ideas submitted through the Alpha League platform).
  • Individual clients or investors to whom we provide or propose to provide Services.
    • Contact information, including your name, job title, address, email address, telephone, or mobile number wire transfer instructions.
    • Citadel account number.
    • Other information relevant to provision of Services.
    • Information that you provide to us as part of our providing the Services to you which depends on the nature of your agreement with Citadel.
    • Relevant information as required by applicable Know Your Client and Anti-Money Laundering regulations (or similar). This may include evidence of source of funds, at the outset of and periodically during our relationship with clients, investors, shareholders and intermediaries, which we may request or obtain from third-party sources, including documentation from the prospective client or online sources.
    • Voice recordings where we are required to record telephone calls with you for financial regulatory purposes or other proportionate purposes (such as establishing facts relevant to our business, verifying compliance with regulatory practices, detecting or preventing crime, or ensuring effective operation of our communications systems). We may also summarise, transcribe and/or record certain internal and external meetings using AI-powered tools. Where such tools are used, meeting participants will be informed where necessary. In the event a meeting participant asks that such tools not be used or be turned off, we will comply. Personal data processed may include your voice, name, statements made during meetings, and resulting transcripts or summaries.
    • Marketing and service communications preferences.
    • Any other personal data you provide to us.

Individuals whose personal information may be processed by us as a result of providing the Services to others (including corporate clients, investors or intermediaries).

Citadel primarily engages with corporate clients, investors or intermediaries, who are not themselves data subjects. However, we may receive personal data about their personnel (e.g. workers, employees, directors, representatives).

For instance, if we are providing Services to a corporate client, investor or intermediary we may be provided with, and then process, personal data about their representatives such as the representative’s name, contact details, and information necessary to fulfil the Services (e.g. Know Your Client and Anti-Money Laundering information).

In using the Alpha League platform, we may process personal data provided by such representatives in relation to the User Investment Profile section of the platform.

We might also need to process personal data in relation to a corporate client’s, investor’s or shareholder’s workers who use a Service in the course of their work for such corporate entity.

We may process voice recordings where required for financial regulatory purposes or to establish facts, ascertain compliance, prevent or detect crime, or ensure effective operation of our communications systems.

We may also summarise, transcribe and/or record certain external meetings using AI-powered tools. Where such tools are used, meeting participants will be informed where necessary. In the event a meeting participant asks that such tools not be used or be turned off, we will comply. Personal data processed may include your voice, name, statements made during meetings, and resulting transcripts or summaries.

In this Privacy Notice, when we reference the processing of personal data related to corporate clients, investors, or intermediaries, we also mean any of their personnel whose personal data we may process in connection with our engagement and provision of the Services.

  • Event attendees
    • Name and job title.
    • Information collected relating to your attendance at an event, including via a registration or feedback form.
    • Photos or video recordings that feature you or your likeness (including any images which we take or obtain when you attend events that we host).
  • Industry information
    • We maintain databases containing publicly available industry information for research and investment purposes (collected by us or our trusted third party service providers). This may include names, business contact details, professional interests, and affiliations. Any processing of personal data is incidental to Citadel’s investment decisions.
  • Potential recruits to any Citadel office in EMEA.
    • Name and job title.
    • Contact information including email address.
    • Curriculum vitae, education, employment history and similar information.
    • Other information relevant to potential recruitment to Citadel (including background checks, reference checks, sanctions checks and similar, immigration status, relevant test scores in relation to any application).
    • Information relating to criminal convictions and offences (as relevant and permissible).
    • Information about your communications and interactions with Citadel and our Site such as your visits to our Site (please also see the information we collect under Visitors to the Site which we also collect in relation to recruitment), email activity, and attendance at Citadel events.
    • Information relevant to diversity and inclusion monitoring and related initiatives, processed to comply with applicable anti-discrimination laws.
    • Any other information you give to us as part of the application process or that you give to us generally.
    • Citadel may also receive information from third party recruiters, agents and from your references as part of any recruitment process. Such information may also include special categories of personal data (such as information about your health, any medical conditions, your racial or ethnic origin, etc.).
    • We also collect information relating to potential candidates, including indirectly from third party recruitment agencies or third party professional networking sites (such as LinkedIn) and from individual potential recruits directly during recruiting events or where you sign up to receive information on open roles.

Suppliers (including trading counterparties, subcontractors and individuals associated with our suppliers and subcontractors).

We collect and process personal data about our suppliers (including trading counterparties) and their representatives to manage the relationship and contract, to receive services from our suppliers and, where relevant, to provide the Services to our clients.

We may process voice recordings where required for financial regulatory purposes or to establish facts, ascertain compliance, prevent or detect crime, or ensure effective operation of our communications systems.

We may also summarise, transcribe and/or record certain internal and external meetings using AI-powered tools. Where such tools are used, meeting participants will be informed where necessary. In the event a meeting participant asks that such tools not be used or be turned off, we will comply. Personal data processed may include your voice, name, statements made during meetings, and resulting transcripts or summaries.

Visitors to any Citadel office in EMEA.

If you attend one of our physical offices or other locations, we may process personal data that you volunteer in connection with your visit and any enquiries you make. For example, you may provide personal data when signing in as a guest. CCTV footage may also be collected for security purposes.

For entrance kiosks using facial recognition technology, we may process your government-issued ID, an RFID access card (for regular visitors), and biometric facial scans to verify your identity and grant access.

  • Applicants and participants in one of our academic trading programs
    • Contact information, including your name, address, email address, telephone, or mobile number.
    • Employment status and history, directorship status and history, elected official history, current confidentiality and non-disclosure contractual obligations owed to third parties, current or historic membership of scientific advisory boards or possession of non-public material relevant to investment decision making.
    • Details of your history of any criminal convictions, direct or indirect violations of law relating to securities, future contracts or regulated entities, or orders of any regulatory authority barring or suspending your right to be associated with a regulated entity (as permissible).
    • Any other personal data you provide to us, which may include special categories of personal data (e.g. any medical conditions).

4. PERSONAL INFORMATION USE

Below we explain how we use the personal data described in section 3 and our legal bases for processing.

Please note that where we rely on ‘legitimate interest’ as your lawful basis for processing your personal data for any of the purposes listed below, if it is not the appropriate lawful basis for processing personal data for such purpose in your jurisdiction, we will rely on an alternative lawful basis such as consent, performance of a contract, or compliance with legal obligations.

Fulfilment of Services.

We collect personal data you submit during use of the Site and Services to perform the Services we provide. The relevant contract terms also apply.

These purposes include:

  • to ensure any investor is aware of the performance of their investment;
  • to make necessary regulatory communications with clients, investors or intermediaries;
  • general client, investor, or intermediary management to ensure Services are provided correctly; and
  • relationship management between Citadel and any client, investor, shareholder or intermediary.

What is our legal basis? We use your personal data to perform our obligations under any contract with you, or where it is in our legitimate interest or a third party’s legitimate interest to use personal data to provide the Services effectively.

  • Business management, administration and legal and regulatory compliance.
    We use your personal data for the following business management, administration and legal and regulatory compliance purposes:

    • to manage and administer Citadel’s business;
    • to manage and administer any investment funds that we manage and in which you may be an investor (please note further information will be provided in the relevant Confidential Offering Memorandum);
    • to comply with applicable legal and regulatory obligations, including Know Your Client, Anti-Money Laundering and Anti-Bribery requirements;
    • to enforce our legal rights;
    • to maintain regulatory records of our business activities including telephone voice recordings (where required by financial regulations);
    • telephone call recording for proportionate purposes such as establishing facts relevant to Citadel’s business, verifying compliance with regulatory practices, detecting or preventing crime, or ensuring effective operation of our communications systems;
    • to make any necessary corporate filings;
    • protect rights of third parties;
    • to administer any academic trading program; and
    • in connection with a business transition such as a merger, acquisition by another company, or sale of all or a portion of our assets.

What is our legal basis?

Where we use your personal data in connection with a business transition, to enforce our legal rights, or to protect the rights of third parties it is in our or a third party’s legitimate interest to do so. For all other purposes described in this section, it is our legal obligation to use your personal data to comply with any legal obligations imposed upon us.

  • Recruitment, Talent Management and Brand Awareness.
    We use your personal data for the following recruitment, talent management and brand awareness purposes:

    • to build the Citadel brand and to raise awareness of Citadel’s service offerings in the recruitment market;
    • to assess your suitability for any position at Citadel, including employment, freelancer, member, internship, summer placement, academic trading programme, or business support roles;
    • to identify candidates and assess suitability for future positions for which we think you may be suitable; to take any steps necessary to enter into any contract of employment (or otherwise) with you;
    • to comply with any regulatory or legal obligations in relation to any such application;
    • to review Citadel’s equal opportunity profile where such processing is necessary to comply with applicable anti-discrimination laws. Citadel does not discriminate on the grounds of gender, race, ethnic origin, age, religion, sexual orientation, disability or any other basis covered by local legislation;
    • to maintain relationships and communicate with potential future recruits such as students, new graduates, survey respondents, attendees at our recruitment events, and any other person where you have signed up to receive information on such opportunities at Citadel; and
    • to maintain relationships with our alumni.

What is our legal basis?

Where we use your personal data for recruitment, talent management and brand awareness, it will be to take steps at your request to enter a contract with you, or it is in our legitimate interest to use personal data to make the best recruitment, brand awareness and talent management decisions for Citadel, or it is our legal obligation to comply with applicable law. We will not process any special category data except where we are able to do so under applicable legislation or with your explicit consent, or, in the case of diversity and inclusion personal data, where such processing is necessary to comply with applicable anti-discrimination laws. Any personal data we process relating to criminal convictions and offences will be to comply with our legal obligations as part of financial regulatory compliance and for crime prevention.

If we have engaged you or the organisation you represent to provide us with products or services

If we have engaged you or the organisation you represent to provide us with products or services (for example, if you or the organisation you represent provide us with services such as IT support or financial advice), we will collect and process your personal data in order to manage our relationship with you or the organisation you represent, to receive products and services from you or the organisation you represent and, where relevant, to provide our Services to others.

What is our legal basis?

We use your personal data to perform our obligations under any contract with you or the organisation you represent, or it is in our legitimate interest to maintain an effective working relationship with you or the organisation you represent and to receive the products and services that you or your organisation provides, and, where relevant, to provide our Services to others effectively.

Physical and health security

We have security measures in place at our offices, including CCTV and building access controls. Signs in our office indicate that CCTV is in operation. The images captured are securely stored and accessed on a need-to-know basis (e.g. to investigate an incident). CCTV recordings are typically automatically overwritten after a short period unless an issue requires investigation (such as a theft). Visitors to our offices sign in at reception and we keep a record of visitors for a short period. Our visitor records are securely stored and accessible on a need-to-know basis (e.g. to investigate an incident).

Facial recognition technology may also be used to ensure that only those with the right to access our premises do so.

In relation to pandemic prevention measures, limited health data (e.g. temperature testing or questions about travel) may be processed.

What is our legal basis?

It is in our legitimate interests to process your personal data so that we can keep our premises secure and provide a safe environment for our personnel and visitors to our premises.

Facial recognition is used at Citadel’s entrance kiosks to authenticate you. If you prefer not to use a kiosk, staff can provide an alternative. Kiosk use requires your explicit consent where required by applicable law.

Any processing in relation to pandemic prevention measures will be undertaken in line with relevant government guidance and where there is a lawful basis to process such data (e.g. legitimate interests, legal obligations and public interest).

  • Insight and Analysis.
    • Use of Site and Services

We analyse your contact details along with other personal data that we observe about you from your interactions with our Site and/or with our Services.

Where you have given your consent (where required by applicable laws) we and our third parties use cookies, log files and other technologies to collect personal data from the computer hardware and software you use to access the Site, or from your mobile and any emails that you receive from us. This includes the following:

  • a session ID to track usage statistics on our Site;
  • an IP address to monitor your usage of the Site; and
  • information regarding your personal or professional interests, demographics, buying habits, experiences with our products and contact preferences.

Our web pages use cookies, web beacons and pixel tags (all referred to as “cookies”) to track visitors, count users, and collect aggregate information. We may also use third-party cookies to collect information about your online activity over time. See the “Our use of cookies and similar technologies” section for details.

This information helps us measure the effectiveness of our content, digital channels, and branding, and understand how visitors use and interact with our Site.

We use this information to improve our Site content and service offerings; to manage user preferences; and for marketing and recruitment purposes. We may share this information with third parties for these purposes (see “Personal Information Sharing”).

In some of our email messages, we use a “click-through URL” linked to certain websites administered by us or on our behalf. We may track click-through data to assist in determining interest in particular topics and measure the effectiveness of these communications.

What is our legal basis?

Where your data is collected through the use of non-essential cookies, we rely on consent to collect your data. Please see the Manage My Preferences section in our cookie consent banner for further details about the cookies that we use, and to update your preferences.

However, we may rely on other legal bases when we use your personal data that has been collected via the use of cookies. Where we use this data to analyse Site and Service usage, it is in our legitimate interest to improve our Site and Services.

Where we use this personal data for the purposes described in the “Marketing communications” section of this Privacy Notice, please see this section for details of the legal basis that we rely on.

Where your personal data is anonymised, we do not require a legal basis to use it as the personal data will no longer constitute personal data that is regulated under data protection laws. However, our collection and use of such anonymised information may be subject to other laws where your consent is required. Please see the “Our use of cookies and similar technologies” section for further details.

Industry Information

We collect and maintain such databases to be primarily used for research and statistical analysis for business investment purposes, and to gain further global insights.

What is our legal basis?

It is in our legitimate interest (or a third party’s) to use this data to provide Services in an effective way. We also rely on the fact that this personal data has been made public by the individuals.

Marketing communications

We carry out the following marketing activities using your personal data:

  • Email marketing

We use information that we observe about you from your interactions with our Site, emails, social media and Services, to provide information that we think will be of interest to you. This may include information about our Services, recruitment, industry updates, newsletters, event invitations and promotional materials.

What is our legal basis?

We will send you marketing communications via email where you have consented to receive such communications, or where it is otherwise within our legitimate interests to do so. You have the right to opt-out of email marketing communications at any time.

  • Social media remarketing

We share your email address (usually encrypted or ‘hashed’) with social media platforms, such as LinkedIn, (“Social Platforms”) to match your data with their users and display targeted advertising to you.

Please note that such activity is also subject to the privacy choices you have elected to make on such Social Platforms.

What is our legal basis?

Where we use your personal data to provide you with personalised advertising on Social Platforms, we rely on the consent that you have provided in respect of the collection of such data, or it is otherwise in our legitimate interests to promote our Site and our Services to you when you use those Social Platforms (including in relation to recruitment).

Your feedback about our Services.

We may contact you for feedback about our Services, which we use to improve service quality.

What is our legal basis?

It is in our legitimate business interests to use the information you provide to us in your feedback for the purposes described above.

Hosting and managing events

We may organise events for business promotion, charitable causes, or other reasons. We process your personal data to communicate with you about events where you have requested information or where we have another lawful basis.

If you attend one of our events, we may process your personal data to record your attendance at the event and for related record-keeping purposes and, if relevant, we may collect and process any dietary requirements you may have. You may also feature in photographs taken at our events and such photographs may appear in publications that we make available.

What is our legal basis?

We use your personal data to perform any contract with you for event attendance, or where it is in our legitimate interest to operate the event effectively.

We may specifically ask your permission to use your photographs, quotes, testimonials, or other content that you make available or publish at the event. Where this is the case, our processing of your such personal data will be based on consent.

Utilisation of artificial intelligence algorithms, models, and systems (“AI”)

We use AI technologies provided by third-party vendors to support and improve the efficiency of our business operations, including screening and organizational tools that may use AI to assist in evaluating qualifications, skills, or suitability for roles and AI-powered transcription, summarization, and recording of certain internal and external meetings.

Where such tools are used in meetings, if any meeting participant asks that they be not used or turned off, we will comply. Personal Data processed in this context may include your voice, name, and any statements made during meetings, and any resulting transcripts or summaries.

AI is not used to make automated decisions that have legal or similarly significant effects on individuals. Where AI outputs are used, they are reviewed by decision-makers who consider additional relevant information before making any decisions related to individuals.

Biometric data

In limited circumstances, technologies we use in our business operations may collect, obtain, store, retain, create and/or use certain personally identifiable information that applicable law may define as, or consider to be, a biometric identifier or biometric information (together, biometric data).

These technologies include:

  • AI-powered technologies provided by third-party vendors for summarisation, transcription and/or recording of in-person meetings that collect biometric data for speaker identification where compatible with applicable local laws. Such biometric data will only be used on an opt-in basis.
  • Certain platforms provided by third-party vendors that assist in evaluating qualifications, skills or suitability for roles. If such platforms process biometric data, users of the platform will be notified and may opt out from such processing.
  • Physical access control technology in certain of our office locations, where compatible with applicable local laws.

We may retain an individual’s biometric data until the first of the following occurs: the initial purpose for the collection has been satisfied; or six months have passed since the individual’s last interaction with Citadel. Unless otherwise required by law or legal process, when this retention schedule no longer authorises Citadel to retain any biometric data, it is securely and permanently destroyed.

Except as otherwise described in this Privacy Notice, Citadel does not disclose, re-disclose or disseminate biometric data unless the disclosure is consented to by the individual or the individual’s legally authorised representative, is required by applicable law, or is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.

What is our legal basis?

It is in our legitimate interests to use your personal information in this way to improve the efficiency of our business.

5. IF YOU FAIL TO PROVIDE YOUR PERSONAL DATA

If we are required by law or contract to collect your personal data and you do not provide it, we may be unable to perform our contract with you and may need to cancel your application or Services.

6. HOW DO WE OBTAIN YOUR CONSENT?

Where our use of your personal data requires your consent, you can provide such consent:

  • at the time we collect your personal data following any instructions provided; or
  • by informing us by e-mail, post or phone using the contact details set out in this Privacy Notice – please see the “Contact Us” section below.

7. OUR USE OF COOKIES AND SIMILAR TECHNOLOGIES

The Site uses cookies to function and for certain purposes described in this Privacy Notice.

You can manage your cookie preferences, but some parts of our Site require essential or functional cookies to work properly. If you block or subsequently delete those cookies, some aspects of our Site may not work properly, and you may not be able to access all or part of our Site.

For more information about our use of cookies, please see the “Insight and Analysis” and “Marketing communications” sections of this Privacy Notice.

In some cases, the cookies that we use may be provided by a third party. Information about you may be shared with the relevant third party and used in accordance with their privacy notice.

In addition, where we use cookies relating to services provided by Google, Google has published information about how it uses personal data in connection with its services here.

For further information about types of cookies used and to customise your cookie preferences, please select Manage My Preferences in our cookie consent banner.

For more information on cookie management and blocking or deleting cookies for a wide variety of browsers, visit www.allaboutcookies.org.

8. PERSONAL INFORMATION SHARING

We share personal data with third parties or other entities within our group of companies only when legally permitted to do so. When we share personal data, we use reasonable efforts to put contractual arrangements and security mechanisms in place to protect the personal data and to comply with our data protection, confidentiality and security standards.

When processing your personal data, we may need to share it with other third parties as follows:

  • Our affiliated companies and licensees using the Citadel or other Citadel affiliate name, including subsidiaries of such companies. For details of our office locations, please click here. We may share personal data with other Citadel Group entities where necessary for administrative purposes and to provide Services to our clients, investors and intermediaries.
  • Third-party service providers for applications, data processing or IT services, including technology, cloud-based software services, identity management, website hosting, data analysis, security, recruitment portals, marketing, and storage. Personal data may be stored in secure data centres worldwide.
  • Third party service providers that otherwise assist us in providing Services or information (including but without limitation any Administrator of an investment fund managed by Citadel).
  • Third party organisations that assist us with our marketing activities listed above, such as survey providers and similar.
  • Event partners and suppliers. When we run events, we will share personal data with third-party service providers that are assisting us with the operation and administration of that event. If we are running an event in partnership with other organisations, we will share personal data with such organisations for use in relation to the event.
  • Third party organisations, such as Google Analytics, Lucky Orange and LinkedIn who assist us with our insight and analytics activities listed above.
  • Third party organisations that assist with our recruitment activities listed above, such as SalesForce and third-party providers that undertake background checks on our behalf and other entities within the Citadel Group.
  • Third-party service providers that are assisting us with the operation and administration of our events. If we are running an event in partnership with other organisations, we will share your personal data with such organisations for use in relation to the event.
  • Auditors, lawyers, accountants and other professional advisers. We share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in.
  • Law enforcement or other government and regulatory agencies or to other third parties as required by, and in accordance with, applicable law or regulation.

Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, to establish, exercise or defend legal rights. We fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.

9. EXTRA-EEA, EXTRA-SWITZERLAND, EXTRA-UK AND EXTRA-DIFC TRANSFERS

Due to Citadel’s international operations, where necessary to deliver the Services (as set out in this Privacy Notice) we will transfer personal data to countries outside the EMEA region (including to Citadel’s US affiliates) and such personal data may be stored on servers located outside the EMEA region; in principle, in any country in the world. Citadel – and many third-party service providers that Citadel works with – are based in the US, but Citadel also has material operations in the UK and the EEA. As such, your personal data will be transferred (both to other companies within the Citadel Group as well as to third party service providers) to the US, the UK, and the EEA as required to deliver the Services. However, your personal data may also be shared with other companies within the Citadel Group or third-party service providers outside of the EMEA region (i.e., outside the EEA, Switzerland, UK and/or DIFC), on a less frequent basis, where necessary to deliver the Services.

When transferring your personal data outside the EMEA region, we will use reasonable efforts to comply with applicable legal and regulatory obligations, including (but not limited to) having a lawful basis for transferring personal data where required and putting appropriate safeguards in place to ensure an adequate level of protection for the personal data.

Unless we can rely on a derogation under Art. 49 GDPR (or analogous provision under the UK GDPR, Swiss FADP the DPL 2020), or equivalent provision under applicable law (e.g., if the transfer is necessary for the performance of a contract, in the case of legal proceedings abroad, or if you have consented to the transfer in question), we will, where required by applicable law, implement at least one of the safeguards set out below:

Adequacy decisions We may transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data, or have a system of certification pursuant to which transfers of personal data to participating organisations are deemed adequate, by the European Commission, the Swiss Federal Council, the UK Government, and/or the DIFC Commissioner of Data Protection (the “Commissioner“) (as applicable). Such systems of certification may include the EU-US Data Privacy Framework adopted pursuant to European Commission Implementing Decision of 10 July 2023, the UK Extension to the EU-US Data Privacy Framework adopted pursuant to The Data Protection (Adequacy) (United States of America) Regulations 2023, and any analogous frameworks or certification schemes adopted by the applicable governmental or regulatory body under applicable law, including the Swiss FADP and the DPL 2020.
Model clauses Where we transfer your personal data to certain service providers or entities within the Citadel Group, we may use specific Standard Contractual Clauses approved by the European Commission (as adapted to also satisfy Swiss law requirements), the UK Information Commissioner, and/or the Commissioner, which give personal data the same protection it has in Europe, Switzerland, the UK, and/or DIFC (as applicable). To find out more about the SCCs we use, please see here (EU), here (UK) and here (DIFC).

Please contact us if you would like further information on the specific mechanisms used by us when transferring your personal data outside the EMEA region.

10. HOW LONG DO WE KEEP YOUR PERSONAL DATA FOR?

For Site visitors, we retain personal data for at least six years from our last interaction, in compliance with applicable data protection legislation (or longer if required by regulatory or professional indemnity obligations).

For Services-related personal data, we retain it for at least six years from our last interaction, in compliance with applicable data protection legislation (or longer if required by regulatory or professional indemnity obligations). We may then destroy such files without further notice. If you request copies, we may charge for duplication costs.

For recruitment data, if your application is unsuccessful, we retain your data for a period after notification. If successful, standard Citadel staff retention protocols apply. In considering how long to retain your personal data, we take into account its relevance to our business and potential legal claims.

If personal data is only useful for a short period, e.g. for specific marketing campaigns or CCTV footage, we may delete it after such retention period.

11. PERSONAL DATA SECURITY

We take the security of personal data we hold seriously. We adhere to internationally recognised security standards. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the personal data we hold secure.

12. YOUR RIGHTS AND ACCESS TO PERSONAL DATA

You have the following rights in relation to the personal data we hold about you:

Right of access.

If you ask us, we will confirm whether we are processing your personal data and, if necessary, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may need to charge a reasonable fee.

Right to rectification.

If the personal data we hold about you is inaccurate or incomplete, you are entitled to have it rectified. If you are entitled to rectification and if we have shared your personal data with others, we will let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.

Right to erasure.

You can ask us to delete or remove your personal data in some circumstances such as where we no longer need it or if you withdraw your consent (where applicable). If you are entitled to erasure and if we have shared your personal data with others, we will let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.

Right to restrict processing.

You can ask us to ‘block’ or suppress the processing of your personal data in certain circumstances such as where you contest the accuracy of that personal data or you object to us. If you are entitled to restriction and if we have shared your personal data with others, we will let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.

Right to data portability.

You have the right, in certain circumstances, to obtain personal data you have provided us with (in a structured, commonly used and machine readable format) and to reuse it elsewhere or to ask us to transfer this to a third party of your choice.

Right to object.

You can ask us to stop processing your personal data, and we will do so, if we are:

  • relying on our own or someone else’s legitimate interests to process your personal data, except if we can demonstrate compelling legal grounds for the processing; or
  • processing your personal data for direct marketing.

 Rights in relation to automated decision-making and profiling.

You have the right not to be subject to a decision when it is based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for entering into, or the performance of, a contract between you and us.

Although we may use AI in various ways (see the “Personal Information Use” section for more information), this does not include automated decision making. Where relevant and useful, we may use the outputs generated by AI to assist in improving the efficiency of our business. Additionally, we do not rely solely on AI output, instead considering it alongside other relevant information to make any decision.

Right to withdraw consent.

If we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have the right to withdraw that consent at any time.

Right to provide instructions on the handling of your personal data after your death (France only).

You have the right to define guidelines as regards the retention, erasure and communication of your personal data after your death. Such guidelines may be general or specific, as set out in the French Data Protection Act.

Right to complain to us.

If you believe that our processing of your personal data does not comply with applicable privacy laws, or you otherwise have a concern about the way we have handled your personal data, you have the right to complain to us. If you wish to submit a complaint, please contact us using the contact details provided in the “Contact Us” section.

Once we receive your complaint, we will acknowledge receipt and will take appropriate steps to investigate the matters you have raised and will keep you informed of our progress. We will notify you of the outcome of your complaint without undue delay.

Right to lodge a complaint with the supervisory authority.

In addition to your right to complain to us, you can also complain to your local data protection regulators – for instance, those regulators in the EU, Switzerland, DIFC, and the UK in which Citadel has offices are as follows:

In the UK the data protection regulator is the Information Commissioner’s Office (ICO). You can contact the ICO using the following website https://www.ico.org.uk.

In Ireland the data protection regulator is the Data Protection Commissioner- Ireland (DPC). You can contact the DPC using the following website: https://www.dataprotection.ie/en.

In France the data protection regulator is the Commission nationale de l’informatique et des libertés (CNIL). You can contact the CNIL using the following website https://www.cnil.fr/.

In Switzerland the data protection regulator is the Federal Data Protection and Information Commissioner (FDPIC). You can contact the FDPIC using the following website https://www.edoeb.admin.ch/en/contact-2.

In the Netherlands, the data protection regulator is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can contact the Autoriteit Persoonsgegevens using the following website https://www.autoriteitpersoonsgegevens.nl/.

In Germany, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) can be contacted using the following website: BfDI – Homepage, and the data protection authorities of the federal states can be contacted through the following website: https://www.datenschutzkonferenz-online.de/datenschutzaufsichtsbehoerden.html

In DIFC, the Commissioner of Data Protection can be contacted using the following website: https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection

The rights that you have in relation to your personal data may differ depending on the jurisdiction that you are in. For example, in DIFC, you also have an anti-discrimination right, meaning you have the right not to be treated differently in our provision of services purely because you have exercised another right in respect of your personal data that we process.

13. COLLECTION OF INFORMATION BY THIRD-PARTY SITES AND SPONSORS

The Site contains links to other sites with different privacy practices. Citadel is not responsible for information submitted to or collected by these third parties. You may also share information with Social Platforms like LinkedIn, over which Citadel has no control. Review the relevant social media privacy notices for details.

LinkedIn

LinkedIn Ireland Unlimited Company (LinkedIn) is a controller of your personal data when our online advertising activities involve advertising to you on LinkedIn. LinkedIn has published information about how it uses your personal data in connection with its advertising services, including how you can opt-out of LinkedIn’s interest-based advertising, here and here.

Where we receive insights from LinkedIn for the purposes described in the Social media remarketing section above, we are joint controllers with LinkedIn in relation to LinkedIn’s processing of their social media data to provide those insights to us.

For further information about how LinkedIn uses your personal data in connection with these activities, including the legal basis LinkedIn relies on and the ways to exercise your data subject rights against LinkedIn, please see LinkedIn’s Privacy Policy at https://www.linkedin.com/legal/privacy-policy.

14. REVISIONS TO THIS PRIVACY NOTICE

We may update this Privacy Notice to reflect changes in how we use your personal information or to comply with legal or regulatory changes.

15. CONTACT US

If you have any questions about this Privacy Notice or want to exercise your rights set out in this Privacy Notice, please contact us by:

Citadel Enterprise Americas LLC

ATTN: Corporate Communications

Southeast Financial Center

200 S. Biscayne Blvd.

Miami, FL 33131.

If you are based in Germany, you can contact our Data Protection Officer using the following details: [email protected]

If you are a data subject located in DIFC and your query relates to the processing of your personal data by our DIFC operations, you may also contact us by: email: [email protected]; or post: Citadel Enterprise (DIFC) Services Limited, Gate Village Building 01, GV01/L01/104, Level 1, Dubai International Financial Centre, Dubai, U.A.E.