Privacy Policy
This Privacy Policy (“Policy”) explains how Morpheus Wealth Pty Ltd (“Company”) collects, uses, discloses, and protects personal information obtained through the HeirWealth website, app and related services (“Services”). By using the Services, you consent to the collection and processing of your personal information as described in this policy.
1. Collection of Personal Information
Personal information We Collect
The types of personal information we may collect from users of the Services include:
• Name, email address, and contact information
• Financial information, including bank and investment account details, insurance policy details, details of other assets and liabilities, valuations and transaction history
• Documents relating to you, your related entities or information recorded on the Services
• Details of family contacts and third party advisors (e.g. wealth managers, financial advisors, accountants and legal advisors)
• User preferences and settings
• Device information, such as IP address and mobile device identifier
• Usage data, including log files and analytics information
Collection Methods
We may collect personal information from you through the following methods:
• Information you provide when creating an account or using the Services
• Information obtained through your use of the Services, such as valuation and transaction data and portfolio information
• Communication and correspondence with us, including support requests and feedback
• Information added by linked third-party service providers or advisors (e.g., wealth managers, financial advisors, accountants) upon your consent
2. Use of Personal Information
Purpose of Use
We may use your personal information for the following purposes:
- Providing and improving the functionality and features of the Services
- Personalizing and customising your user experience
- Managing and analysing portfolios, transactions, and investment data
- Facilitating access to advisors and wealth management services based on user preferences
- Communicating with you, including responding to inquiries and providing support
- Sending important notices and updates regarding the Services or your account
- Conducting research, analytics, and market analysis to improve our services
- Complying with legal obligations and enforcing our rights and agreements
Direct Marketing
We may use your personal information to send you direct marketing communications about our products, services, and promotions. You can opt-out of receiving such communications by following the instructions provided in the communication or contacting us directly.
Lawful Bases for Processing Personal Data (EEA/UK GDPR Compliance)
For users located in the European Economic Area (EEA) and the UK, we process your personal data based on the following lawful grounds:
- Contractual necessity: To provide the App’s services as agreed in our Terms and Conditions
- Legitimate interests: For improving and securing the App, responding to inquiries, and facilitating advisor access
- Legal obligations: To comply with regulatory requirements
- Consent: Where required, such as for sending marketing communications or sharing data with advisors
3. Disclosure of Personal Information
Third-Party Service Providers
We may share your personal information with:
- Trusted third-party service providers that assist us in delivering and improving the Services.
- Wealth managers, financial advisors, and accountants with whom users explicitly connect their accounts.
All third-party recipients are contractually bound to protect the confidentiality and security of your personal information.
Legal Requirements and Protection
We may disclose your personal information if required by law, regulation, or legal process. We may also disclose your information to protect and defend our rights, property, or safety, or the rights, property, or safety of our users or others.
4. Data Security
Security Measures
We implement reasonable technical and organizational measures to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. However, no method of transmission or storage is 100% secure, and we cannot guarantee the absolute security of your information.
Retention of Personal Information
We retain personal information for as long as necessary to fulfil the purposes outlined in this Policy or as required by law. We will securely delete or anonymize personal information that is no longer needed.
5. International Data Transfers (EEA/UK GDPR Compliance)
Cross-Border Transfer
Your personal information may be stored and processed in jurisdictions outside of your country, including Australia and the United States. If we transfer your information to a jurisdiction that does not have the same data protection laws as Australia, we will take reasonable steps to ensure an adequate level of protection for your information. When transferring personal data outside the EEA and UK, we unsure that appropriate safeguards are in place, such as:
- Adequacy decision by the European Commission (if applicable)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding corporate rules (BCRs) (where applicable)
6. User Rights and Choices
Access and Correction
You may request access to, correction, or deletion of your personal information held by us. We will respond to such requests in accordance with applicable laws.
For users in the EEA and UK, you have the following rights under GDPR:
- Right to Access: Request access to the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): Request deletion of your personal data, subject to legal obligations.
- Right to Restrict Processing: Request limitation of processing under certain conditions.
- Right to Data Portability: Receive a copy of your personal data in a structured format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with a data protection authority in your country if you believe your rights have been violated.
To exercise any of these rights, please contact us at privacy@morpheuswealth.com.
Opt-Out
You can optout of receiving direct marketing communications by following the instructions provided in the communication or by contacting us directly. However, please note that even if you opt out of marketing communications, we may still send you important notices regarding the Services or your account.
Cookies and Tracking Technologies
We may use cookies and similar tracking technologies to collect information about your use of the Services. You can manage your preferences for cookies and similar technologies through your device or browser settings.
7. Children’s Privacy
The Services is not intended for use by individuals under the age of 16 or the minimum age permitted under applicable law. We do not knowingly collect personal information from individuals under 16 years of age. If we become aware that we have inadvertently collected personal information from a child under 16, we will take steps to delete the information as soon as possible.
8. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify you of any material changes by posting the updated Policy within the Services or by other means.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at privacy@morpheuswealth.com. If required under GDPR, we may appoint a Data Protection Officer.
Supervisory Authority Contact (For EEA/UK Users) If you believe we have not addressed your concerns satisfactorily, you may contact your local data protection authority:
UK: Information Commissioner’s Office (ICO) – www.ico.org.uk
EEA: Contact your national data protection authority via the European Data Protection Board (EDPB) – www.edpb.europa.eu