Legal
Privacy policy
How Northfield Digital Alpha handles information — the data our clients entrust to the platform, and the data we collect ourselves.
Version 1.0 · Effective July 15, 2026 · Applies to ALPHA, Northfield, OpenFinance, and Market76
01Scope of this policy
1.1 Who we are
This policy is issued by Northfield Digital Alpha, Inc. (“ALPHA,” “we,” “us,” or “our”), a Delaware corporation headquartered in New Haven, Connecticut. ALPHA operates a single decision platform under three heritage identities: Northfield (risk models and optimization), OpenFinance (semantic data and books of record, operated through Digital Financial Group), and Market76 (preference modeling and personalization). References to ALPHA in this policy include these identities unless the context indicates otherwise.
1.2 What this policy covers
This policy explains how we handle personal information in connection with our websites (including ndalpha.com, northinfo.com, openfinance.com, and market76.com), our products and platform, our events and communications, and our dealings with clients, prospects, partners, and job applicants. It does not cover the practices of third parties we do not control, or of clients who use our platform to process their own data.
1.3 Client data vs. data we collect
ALPHA acts in two distinct capacities, and it matters which one applies to a given set of data.
Client Data — we are a processor
When clients use the ALPHA platform to model risk, integrate books of record, or personalize decisions, they route their own data — including positions, transactions, and records that may contain personal information — through our systems. We process that data only on our clients’ instructions and on their behalf. Our clients are the controllers of that data; their own privacy notices, not this one, govern it. If you are an individual whose information appears in a client’s data and you wish to exercise rights over it, please contact that client directly.
ALPHA-Collected Data — we are a controller
Separately, we collect and determine the purposes for a limited set of information about the people we deal with directly: website visitors, business contacts at client and prospect firms, event attendees, subscribers, and job applicants. This policy governs that data. The rest of this document is about ALPHA-Collected Data.
02Information we collect
2.1 Information you provide to us
We collect information you give us directly — for example, when you fill in a contact or demo request, subscribe to research or data feeds, register for an event, apply for a role, or correspond with us. This typically includes:
- Identity and contact details — name, business email, telephone number, employer, and job title.
- Professional context — the firm you represent, your areas of interest, and the products you ask about.
- Correspondence — the content of messages, enquiries, and support requests you send us.
- Recruitment information — where you apply for a role, your CV, work history, and any information you choose to share in support of your application.
2.2 Information we collect automatically
When you visit our websites or use the authenticated portal, we and our service providers collect certain technical information automatically, including your device and browser type, IP address, approximate location derived from it, pages viewed, referring pages, and the dates and times of access. We collect this information through cookies and similar technologies (see Cookies and similar technologies).
2.3 Information we receive from third parties
We may receive information about you from third parties, such as our clients’ and partners’ teams who introduce you to us, event co-hosts, marketing and analytics providers, recruitment agencies, and publicly available professional sources. We use this information to understand who we are dealing with and to keep our records current.
03How we use information
We use ALPHA-Collected Data to:
- respond to your enquiries and provide the information, demonstrations, and support you request;
- operate, secure, and improve our websites, the authenticated portal, and our products;
- manage our relationships with clients, prospects, and partners, and administer contracts;
- send research, product updates, and marketing communications where permitted, and let you opt out at any time;
- organize and run events, briefings, and webinars;
- evaluate and process job applications;
- understand how our sites and communications are used, so we can make them better; and
- comply with legal obligations, enforce our terms, and protect our rights, our clients, and the public.
04Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, we rely on one or more of the following legal bases: your consent (for example, for certain marketing or cookies); the performance of a contract with you or your firm; our legitimate interests in operating and growing a business-to-business platform, provided those interests are not overridden by your rights; and compliance with a legal obligation. Where we rely on legitimate interests, you may object as described under Your rights and choices.
06Cookies and similar technologies
We use cookies and similar technologies to run our sites, remember your preferences, understand usage, and measure the performance of our content. Strictly necessary cookies are always active; analytics and preference cookies are used where permitted. You can manage non-essential cookies through your browser settings and, where offered, our on-site controls.
A detailed cookie schedule will be published here once our cookie-management tool is in place.
07Data retention
We keep personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, or reporting requirements, and to resolve disputes and enforce our agreements. When information is no longer needed, we delete it or anonymize it. Retention periods vary by the type of data and the context in which we hold it.
08Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, and alteration, appropriate to the sensitivity of the data and the risks involved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, please contact us using the details below.
09International data transfers
ALPHA operates from the United States, with offices in New Haven, Cambridge, New York, London, and Chicago, and uses service providers in several countries. As a result, personal information may be transferred to, stored in, and processed in countries other than your own, whose data-protection laws may differ. Where we transfer personal information out of the EEA or the UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, together with additional measures where required.
10Your rights and choices
Depending on where you live, you may have rights over your personal information. We honor these rights in accordance with applicable law.
10.1 EEA & UK (GDPR)
If you are in the European Economic Area or the United Kingdom, you may have the right to:
- Access
- obtain confirmation of, and a copy of, the personal information we hold about you.
- Rectification
- have inaccurate or incomplete information corrected.
- Erasure
- ask us to delete your information in certain circumstances.
- Restriction
- ask us to limit how we use your information.
- Portability
- receive certain information in a portable, machine-readable format.
- Objection
- object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent
- withdraw consent where we rely on it, without affecting prior processing.
You also have the right to lodge a complaint with your local supervisory authority.
10.2 California (CCPA/CPRA)
If you are a California resident, you may have the right to know what personal information we collect, use, and disclose; to request deletion or correction of that information; and to opt out of any “sale” or “sharing” of personal information as those terms are defined under California law. We do not sell personal information. We will not discriminate against you for exercising your rights.
10.3 How to exercise your rights
To make a request, email privacy@ndalpha.com. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where the law permits, subject to verification.
11Children's privacy
ALPHA’s websites and products are intended for institutional and professional audiences and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
12Third-party links and services
Our sites may link to third-party websites and services that we do not operate or control. This policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy notices of any third-party site you visit.
13Changes to this policy
We may update this policy from time to time. When we do, we will revise the version and effective date at the top of the page, and, where changes are material, we will provide a more prominent notice. Your continued use of our sites and services after an update takes effect constitutes acceptance of the revised policy.
14How to contact us
If you have questions about this policy or how we handle your information, or if you wish to exercise your rights, contact us at:
- Privacy team
- privacy@ndalpha.com
- Entity
- Northfield Digital Alpha, Inc.
- Headquarters
- New Haven, Connecticut, United States
If you are an individual whose personal information was processed by ALPHA on behalf of a client, please direct your request to that client, who acts as the controller of that data.