First Foundation Inc. California Consumer Privacy Act (“CCPA”) Disclosure
Privacy
Your privacy is important to us. At First Foundation Inc., we value and protect your privacy. Below you will find First Foundation’s California Consumer Privacy Act (CCPA) Privacy Policy and CCPA Notice at Collection, as well as the printable PDF links to our CCPA Privacy Policy and Notice at Collection.
CCPA Privacy Policy (PDF)
CCPA Notice At Collection (PDF)
If you have any questions, please contact us today at CCPA@ff-inc.com.
CALIFORNIA CONSUMER PRIVACY ACT
PRIVACY POLICY
The purpose of this Privacy Policy (“Policy”) is to provide consumers covered under the California Consumer Privacy Act a comprehensive description of the practices of First Foundation Inc. regarding the collection, use, disclosure, and sale of personal information and of the rights of consumers regarding their personal information.
Background
The California Consumer Privacy Act (CCPA) became effective as of January 1, 2020, and was amended by the California Privacy Rights Act on January 1, 2023, collectively known as the CCPA. The CCPA grants individual California consumer residents the rights outlined below and is subject to some restrictions.
Definitions
The following terms you will see in this First Foundation Inc. CCPA PRIVACY POLICY are defined below:
“We” “our” “us” “First Foundation” means First Foundation Inc., First Foundation Advisors, First Foundation Bank, and its family of companies.
“You” “your” or “consumer” refer to a natural person who is a California Resident
“Personal Information” “PI” or “Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household. “Personal Information” does not include information that is publicly available (which means information that is lawfully made available from federal, state, or local government records).
Collection of Personal Information
Below is a list of categories of personal information we have collected about consumers in the preceding 12 months. For each category identified we have also provided the categories of sources from which we collected the personal information, the business or commercial purpose for collecting the information, and the categories of third parties to whom we disclose the personal information.
Purposes
The business and commercial purposes for which we collect personal information as disclosed below are defined as follows:
- Employment Processing: Means to use personal information in order to perform services in connection with a consumer’s role, responsibility, and/or status as a job applicant or an employee, owner, director, officer, or contractor of First Foundation Inc. This includes but is not limited to administering payroll or benefits, maintaining compliance with internal policies and procedures, and to comply with applicable federal and state employment laws.
- Operational Processing: Means to use personal information in order to perform services and enforce our rights in connection with the financial products or services we provide, including but not limited to, opening, maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying information, processing payments, providing financing, or other similar activities.
- Security Purposes. Means to use personal information to detect and investigate security incidents, and protect against malicious, deceptive, fraudulent, or illegal activity.
- Internal Research & Development Purposes. Means to use personal information to undertake internal research activities to verify or maintain the quality or safety of a service that is owned or controlled by us and to develop, verify, improve, upgrade, or enhance our services.
- Auditing Purposes. Means to use personal information in connection with activities to audit and/or achieve compliance with our policies and procedures or applicable legal and regulatory standards.
- Debugging Purposes. Means the use of personal information for debugging to identify and repair errors that impair existing intended functionality of our services.
Collection of Personal Information
Over the last 12 months, we have obtained the categories of personal information listed below. The table below summarizes the categories of personal information, the categories of sources from which that personal information First Foundation Inc. may have collected, the business or commercial purpose(s) for which the information was collected, and categories of third parties to whom we have disclosed personal information.
Disclosure or Sale of Personal Information
First Foundation collects and may disclose your personal information to a third party for a business purpose related to servicing your account, offering of of our products and services to you, or to perform a request made by you. Additionally, we may disclose your information to detect and mitigate potential fraud, respond to law enforcement requests for information, and as required by applicable law, comply with a court order, or government regulation.
The personal information disclosed for business purposes may include, your name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. We do not knowingly share or sell the personal information of consumers under 16 years of age.
When we disclose personal information to third parties, we enter into a binding contract that describes the purpose for disclosing the information and requires the recipient to keep the personal information confidential and not use it for any purpose except performing the contract.
We will not collect additional categories of personal information or use the personal information we collected for different or unrelated purposes without providing you notice.
Selling of Your Personal Information
First Foundation does not engage in the selling or sharing of consumers’ personal information as defined under the CCPA.
Right to Know About Personal Information Collected, Disclosed or Sold
Under the CCPA, you have the right to request First Foundation disclose what personal information it collects, uses, and sells about you.
Right to Request Deletion of Personal Information
The CCPA grants certain consumers the right to request First Foundation delete personal information collected and maintained in its records. Once we have received your request and verified your identity, we will review your request and act upon your request.
Right to Correct Inaccurate Personal Information
You have the right under CCPA to request First Foundation correct any inaccurate personal information we may have.
Right to Limit the Use of Sensitive Personal Information
First Foundation does not use or sell Sensitive Personal Information beyond what is allowed under Title 11 Section 7027(m), such as providing you with the services you requested and therefore, we do not offer the Right to Limit use.
Right to Non-Discrimination for the Excercise of a Consumer's Privacy Rights
You have the right to exercise any rights given by the CCPA. Consumers will not be discriminated against for exercising any of their rights under the CCPA. This means First Foundation will not deny services, charge differential pricing, or provide different service levels to consumers to who exercise their privacy rights.
Information Required for Submitting a Verifiable Request to the Bank
Using any of the methods described below under the “Contact Us” section, please provide the following pieces of information (if applicable):
- Your first and last name, including your middle initial if applicable
- A telephone number where you can be reached during business hours
- Your account number (if you have one)
- Email address
- Your physical address
Once we receive your request, we will contact you within five business days to follow up on your request.
Before disclosing any information, we will verify your identity. Once we have verified your identity, we will respond within 45 days of receiving your request. We will deliver our written response by mail or electronically, at our option. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity, specifically by electronic mail communication.
If your identity cannot be verified, we will attempt to contact you to gather additional information. If we are not successful in our attempts, we will notify you that your request has been denied due to the inability to verify your identity.
Right to Opt-Out of the Sale of Personal Information
You have the right, under the CCPA to opt-out of the sale or sharing of your personal information. First Foundation does not sell or share consumer personal information.
Designating an Authorized Agent
Consumers can assign an authorized agent to act on his/her behalf and exercise rights under the CCPA. Please contact us for more information.
Contact Us
To submit a request or if you have questions or concerns regarding this notice or you wish to exercise your rights under the CCPA, please contact us:
You may begin your request here: [SUBMIT A REQUEST] Call: (888) 830-4199 Ask to be directed to the Privacy Officer Email us: CCPA@ff-inc.com
Last Updated 09/11/2024
CALIFORNIA CONSUMER PRIVACY ACT
NOTICE AT COLLECTION
The California Consumer Privacy Act (CCPA) requires First Foundation Inc. (First Foundation Advisors, First Foundation Bank, and its family of companies) to notify you of the personal information we collect for consumers who reside in California. For additional information about how we collect, use, and share your personal information please see our CCPA Privacy Policy.
We want you to understand what information we collect and how we use it.
Retention Period
Personal information is maintained securely until such time we no longer have a need for it to carry out the purpose for which it was originally collected and for other lawful business purposes, to include meeting our legal and regulatory compliance requirements.