DESCRIPTION OF PURPOSE
This privacy notice (“Privacy Notice”) describes how NEPC, LLC (“NEPC,” “we,” “us,” “our”) collects and processes Personal Information (defined below) we collect in the course of conducting business, visiting our website, or when individuals apply for a job with us through our website, and describes rights residents of certain states may have with respect to their Personal Information. “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular client or household. It describes our privacy policies and practices with respect to client information and provides notices to residents in various states or jurisdictions. NEPC maintains additional privacy documents including a Privacy Policy for employees, and a Privacy Notice for visitors to our public website.
This Privacy Notice does not apply to information we collect about individuals when acting in their capacity as employees or independent contractors. Depending on who you are and the nature of your interaction with NEPC, some of the Personal Information we collect may be nonpublic personal information. For purposes of this Notice, “affiliated entities” are companies related by common ownership or control, which may include financial and nonfinancial companies.
STATEMENT OF POLICY
It is NEPC’s policy to protect the confidentiality, integrity, and security of any nonpublic personal information and other confidential information of our existing, former, and certain prospective clients (“Confidential Information”) and to prevent the unauthorized access to, and the use or disclosure of, such information. This notice is intended to help you understand how NEPC protects your Confidential Information.
We use the Personal Information we collect to provide financial products and services to our customers, maintaining investor accounts and communicating with you about your holdings and account related activities on an ongoing basis, to market existing and prospective customers, for information security and fraud detection, and to maintain our relationships and fulfill our obligations to our customers. We may use your Personal Information to process your job application and evaluate you as a potential hire. We may also use your Personal Information to enforce or defend our rights, or those of another client or other third party. NEPC will collect and use Personal Information in the course of business for tasks such as the execution of account documents, for the legitimate interests of NEPC, and to enable NEPC in complying with its legal and regulatory obligations.
NEPC seeks to safeguard Confidential Information against theft, fraudulent use, loss, unauthorized access, or misuse, and has implemented physical, electronic, and procedural safeguards to help protect Confidential Information. Within NEPC, we do not disclose Confidential Information to colleagues other than is necessary to ensure that we can effectively perform our assigned duties (i.e., on a “need to know” basis).
OUR INFORMATION SHARING PRACTICES
Generally, except as otherwise provided herein, we will not share your Personal Information or Usage Data, how the user interacts with a website application or service and often collected indirectly, (which we will refer to in this Privacy Notice collectively as “User Information”) with any third party without your permission.
Third-Party Service Providers. We employ other companies and individuals to perform functions on our behalf, such as for analyzing data and providing certain of the Internet Services. Some of these third-party service providers have access to Personal Information needed to perform their functions, but we require that they not use Personal Information for other purposes. Personal data is not shared with any unaffiliated third parties for their marketing purposes.
Other Disclosure Scenarios. Notwithstanding anything in this Privacy Notice to the contrary, we reserve the right, and you hereby expressly authorize us, to share any User Information: (1) in response to subpoenas, court orders, regulatory requests or legal process, or to establish, protect or exercise our legal rights and interests or defend against legal claims; (2) if we believe it is necessary in order to investigate, prevent or take action regarding inappropriate or illegal activities, fraud, or situations involving potential threats to the safety of any person or property; (3) if we believe it is necessary to investigate, prevent, or take action regarding abuse of our websites infrastructure or the internet in general (such as voluminous spamming, denial of service attacks, or attempts to compromise the security of information); (4) to our subsidiaries, joint ventures, or other companies under common control with us (in which case we will require such entities to honor this Privacy Notice); (5) as part of a corporate transaction with a successor or affiliate or in connected with any acquisition, merger or sale of assets; or (6) with third parties who provide services to us; provided, however, that in those circumstances we request that our service providers not share your User Information in a manner inconsistent with this Privacy Notice.
We do not sell User Information and have not sold any User Information over the last 12 months.
USE OF THIRD PARTY ARTIFICIAL INTELLIGENCE (“AI”) SERVICES
We may use third-party AI services to assist with internal workflows or client deliverables, such as summarizing recorded meetings or internal discussions, drafting internal notes or action items from NEPC generated content, analyzing operational data provided directly to or from us. or to support compliance, risk, or client service functions through categorization or synthesis of our information.
Personal Information and financial information will be treated confidentially and will be stored securely in accordance with our data protection policies and applicable privacy regulations. NEPC does not sell data, including Confidential Information, to any third parties.
NEPC does not provide any AI services with non-public information including but not limited to social security numbers, full financial statements, or other sensitive identifiers. All AI related processing is subject to ongoing monitoring consistent with the NEPC’s cybersecurity, operational risk, and third-party oversight frameworks.
Information processed via third-party AI services is used solely to support our internal operations and client service obligations. Information shared with an approved AI vendor is retained only as long as necessary for the business purpose for which it was provided. Where feasible, we configure AI services to automatically delete submitted content after processing.
Employees, contractors, and service providers who use or access AI services are required to follow NEPC’s Code of Conduct, Information Security Program, and data-handling standards, consistent with this Privacy Notice and regulations within.
SECURITY
We have implemented measures to help protect your User Information from loss, misuse or unauthorized access or disclosure. Unfortunately, however, no data transmission over the Internet can be guaranteed to be 100% secure. As a result, while we strive to protect your User Information, we cannot guarantee its security.
LINKS
Our website may contain links to other websites. We are not responsible for the privacy practices of any such other website (whether accessed through an advertisement, service or content link) and urge you to review such practices prior to submitting any information to such websites.
OTHER PRIVACY NOTICES YOU MAY RECEIVE FROM US
This Privacy Notice supplements the information set out in any other contract or investment agreement made available to you. However, for the avoidance of doubt, it is not intended to modify or override any representations made or commitments given by you (whether on your behalf or on behalf of others) in those documents.
CHANGES TO THIS NOTICE
We may review and update this Notice from time to time. If changes are made, we will update the Privacy Notice and reflect the date of such modification. If the changes are material, you will be notified via a notice on our website.
NOTICE TO CALIFORNIA RESIDENTS
This PRIVACY NOTICE TO CALIFORNIA RESIDENTS applies solely to clients, current and prospective employees, visitors, users and others who reside in the State of California (“Consumers”). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”). Any terms defined in the CCPA have the same meaning when used in this notice.
We collect the following categories of personal information from Consumers:
- Identifiers and personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)) (e.g., name, postal address, email address, driver’s license number, or other similar identifiers).
- Commercial information (e.g., records of personal property, products or services purchased).
- Inferences drawn from the foregoing.
NEPC obtains the categories of personal information listed above from the following categories of sources:
- Directly from our clients or their agents. For example, from documents that our clients provide to us related to the services for which they engage us.
- Indirectly from our clients and their agents. For example, through information we collect from our clients in the course of providing services to them.
NEPC uses such personal information in the following ways:
- To carry out our obligations arising from any contracts entered into between NEPC and Consumers.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
If a Consumer wishes to have their information deleted then they may request that NEPC do so, however, NEPC can refuse to delete personal information that it maintains in order to do any of things listed in 1798.105 (d)(1)‐(9) of the CCPA.
The Consumer has the right to request a report concerning their personal information that contains the information specified in 1798.110 (a) of the CCPA concerning the Consumer’s personal information. In no way will NEPC discriminate against a Consumer who makes a request under the CCPA.
NEPC does not sell any type of information to third parties and does not otherwise share personal information except in the ordinary course of business.
NOTICE TO RESIDENTS OF THE EUROPEAN UNION (“EU”)
This PRIVACY NOTICE TO RESIDENTS OF THE EU applies solely to clients, visitors, users and others who reside in the EU (“EU Consumers”). We adopt this notice to comply with the General Data Protection Regulation (“GDPR”). Any terms defined in the GDPR have the same meaning when used in this notice.
In addition to the information contained above, EU Consumers have the following rights under the GDPR:
- Have a copy of the personal information we hold about you provided to you or another “controller” where technically feasible.
- Request the erasure of your personal information.
If an EU Consumer wishes to exercise any of your rights above, please call NEPC at +1 617-374-1300 or contact us by e-mail. You have the right to lodge a complaint with the appropriate regulatory authority with respect to issues you may have with this Privacy Notice.
NOTICE TO RESIDENTS OF MASSACHUSETTS
The Commonwealth of Massachusetts has data security regulations that apply to our employees and certain Massachusetts-based clients. Regulation 201 CMR 17.00 establishes minimum standards to be met in connection with the safeguarding of personal information contained in both paper and electronic records. The objective of 201 CMR 17.00 is to ensure the security and confidentiality of customer information. Employees and Massachusetts-based clients may request to see our Written Information Security Program (“WISP”) for details on compliance with 201 CMR 17.00.
USE OF COOKIES ON NEPC’S WEBSITE
A cookie is a small text file that is sent to your device when you visit our website. Each time you return to the website, your browser retrieves and sends the relevant cookie(s) to our server. This enables the website to remember your preferences, so you don’t have to re-enter them when you come back to the site or move from one page to another. Some of these cookies are required for the operation of the website. Others allow NEPC to count the number of visitors and to understand how visitors navigate the website. This helps NEPC determine the effectiveness of the site and improve the visitor experience. Depending on the type, cookies may be stored for the duration of your visit to the site and are deleted from your device when you close your browser, or they may be saved on your device after the browser has closed and are activated each time you return to the site.
CONTACT US
If you have any further questions about our Privacy Notice or practices, please contact us at:
Address:
NEPC, LLC
225 Franklin Street
Boston, MA 02110
Phone: +1 (617) 374-1300
Last Updated December 4, 2025.