PRIVACY NOTICE
Effective Date: April 1, 2026
Introduction
Your privacy is important to us. This Privacy Notice describes how Monticello Associates, LLC (“Monticello”) and its Covered Entities (as defined below) collect, use, share, and protect Personal Information when they provide services to clients or engage with prospects who share personal information with us. Except as provided herein, for purposes of this Notice, prospects shall be treated as “clients.”
“Covered Entities” means Cresset Capital Management LLC, and any controlled subsidiary of such entity, as well as any private investment fund managed by such subsidiaries.
Financial companies choose how they share consumer’s Personal Information (as defined below). Federal law gives consumers the right to limit some, but not all, sharing. Federal law also requires Monticello and its Covered Entities (which may be referred to collectively as “we” or “us”) to tell clients what we do with their Personal Information. Please read this Notice carefully.
If an individual client’s relationship with us ends, we will continue to treat their Personal Information as described in this Privacy Notice.
What Personal Information We Collect
We collect information from clients in the course of providing or recommending services or products. “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, to an individual. Please note that Personal Information does information about an individual that is public information (for example, information from federal, state, or local government records and information that was lawfully made available to the general public), aggregated information (information relating to multiple individuals that has been combined and grouped together, resulting in a data set that is not reasonably capable of identifying any individual), or de-identified information (information that is not attributable to an identified or identifiable individual).
We may collect or process Personal Information about individuals in a number of ways and from a number of sources depending on the services / products provided to clients and the relationship we have with clients. We collect Personal Information from the following categories of sources:
- Directly from clients or individuals / entities acting on their behalf;
- Indirectly from clients, such as when they visit or interact with our digital services including our websites or events;
- Third-party sources, such as when data is used to provide and support our services / products such as custodial services, reporting services, fraud prevention, and marketing.
The following is a list of the categories of Personal Information, or information about entities, that we may collect or process. Some types of information will fit into multiple categories.
- Personal identifiers such as name, address, unique personal identifier, email address, account names, signature, telephone number, social security number, driver’s license number, passport number and other similar identifiers;
- Financial information such as bank account numbers, transaction and financial account information, source of wealth information, insurance information, and other information regarding clients’ financial circumstances;
- Protected classification characteristics such as date of birth, citizenship, marital status, sex or gender;
- Commercial information such as records of property, products or services purchased, obtained or considered, purchasing or consuming history or tendencies;
- Internet, application, and network activity such as browsing history, search and clickstream history, Internet Protocol (IP) address, online identifier, device identifier, online website tracking information, and other data related to user activity;
- Sensory data such as audio or visual recordings (if the client attends meetings) and photographs or visual recordings (if the client attends our events);
- Professional, employment, and education-related information such as occupation, employer, employment history, income, industry affiliations, and education;
- Sensitive Personal Information some of the Personal Information that we collect and process and that is described above is considered “Sensitive Personal Information.” This includes Social Security, driver’s license, state identification card, and passport numbers; account log-in, financial account, debit card, and credit card numbers in combination with credentials allowing access to an account, racial origin, or citizenship status.
How We Use Personal Information
We collect and use Personal Information, or information about entities, for the following business purposes:
- Administering, operating, and managing client relationship with us;
- Understanding client profiles and needs, and providing and offering services/products to clients;
- Complying with contractual obligations, relevant industry standards, and our policies;
- Authenticating client identity;
- Mitigating fraud and enhancing the security of our services;
- Contacting and communicating with clients;
- Conducting marketing activity, such as delivering advertisements and marketing communications;
- Performing analytics;
- Operating, evaluating, and improving our business and our services/products (including assessing and managing risk, fulfilling our legal and regulatory requirements, developing new services, improving and personalizing existing services, and performing accounting, auditing and other internal functions); and
- Other purposes permitted or required by applicable law.
To Whom We Disclose Personal Information
Monticello may disclose the Personal Information, or information about entities, we collect from and about clients with our Covered Entities and other third parties as described below. In particular, Monticello may disclose Personal Information as follows:
- Covered Entities: Monticello (and each Covered Entity) may disclose Personal Information, or information about entities, to each other to service clients, improve services, provide products, market other products or services, or for other purposes permissible under applicable laws and regulations.
- Service Providers: We may disclose Personal Information, or information about entities, to non-affiliated companies that perform services for us and/or clients, such as fraud analysis, identity verification, risk management, security services, advertising and marketing, data analytics and lead generation, support for client services, and information technology.
- Other Third Parties: We may disclose Personal Information, or information about entities, to other third parties as permitted by, or to comply with, applicable laws or when clients specifically direct or expressly consent to us disclosing such information. Examples include responding to a subpoena or similar legal process; protecting against fraud; providing requested data to a third party at a client’s direction; cooperating with law enforcement or regulatory authorities; or otherwise to protect the rights, property or security of clients or third parties.
Please review our Website Terms of Use for additional information regarding any use of our Websites, information collected through such usage, and tracking technology we may use, including Cookies, Web Beacons, and the like.
Monticello may share clients’ information with Covered Entities so that they may market to the clients, and Covered Entities may share clients’ information to enhance our ability to determine what services/products may be the best fit for a client or to enhance our ability to generate relevant information about a client. If we do so, federal law gives clients the right to limit such sharing. (State laws may give clients additional rights to limit sharing.) Please contact [email protected] to request limitations on such sharing.
Please note that we do not jointly market with non-affiliates and do not share information with non-affiliates to market to clients, although we may refer clients to a non-affiliate who a client may contact at their discretion.
Security
We take the security of Personal Information, or information about entities, seriously. We take commercially reasonable steps to protect clients’ information from loss, misuse, unauthorized access, disclosure, or destruction. We also take commercially reasonable steps to ensure that Personal Information, and or information about entities, remains secure after disposal, including shredding paper documents and records prior to disposal, and destroying data contained on electronic media in such a manner that the Information can no longer be read or reconstructed.
Please note that we do not send emails to clients requesting billing, login, user ID, or password information. If a client receives an email requesting such information that purports to be from us, we strongly advise clients to verify such communication is from us. We ask that clients report any suspicious communications to us as well.
Retention
We retain Personal Information and other information for varying time periods depending on our relationship with the client and the status of that relationship. When determining how long to keep information, we take into account our legal and regulatory obligations and our legitimate business interests, such as managing the client relationship, preventing fraud, responding to regulatory or supervisory inquiries, and establishing, exercising, or defending legal claims, disputes or complaints.
Use of Artificial Intelligence
We may use technologies, such as machine learning, artificial intelligence, and generative artificial intelligence, which enable computer systems to automate or perform tasks that have traditionally required human intelligence (“AI Systems”) to process Personal Information, or information about entities, in connection with the purposes described in the “How We Use Personal Information” section. Please note that our use of AI Systems will not result in automated decisions with any material legal or similar effects. Further, our internal policies mandate that all output is reviewed and approved by a human. Where required under applicable law, we provide a specific notice and/or obtain consent.
AI Systems are used to assist and enhance activities as well as to automate repetitive tasks, generate outputs, and provide insights and analytics to support our work. For example:
- Search: To enhance our search capabilities where AI Systems are used to extract relevant information using specific questions, commands, and statements (“Prompts”) from our databases as well as other documents, data, and records.
- Summarize: To classify, summarize, and digest content where AI Systems are used to condense documents, information, and text into summaries.
- Generate Content: To assist with drafting and generating content based on inputs or Prompts.
- Transcribe: To create a written transcription of spoken communication, for example meeting or discussion notes.
We never use AI Systems for investment advice, portfolio management decisions, or client recommendations. We use AI Tools in a manner consistent with our confidentiality, cybersecurity, and data protection policies and in accordance with applicable law. The use of AI Systems does not diminish our fiduciary duty to clients.
Modifications
We may, in our sole discretion, modify the Privacy Notice from time to time. If we make material modifications, we will notify all actual clients as required by applicable law and post on our Websites. Continued use of our services following the posting of any changes will mean that the client accepts those changes.
California Residents
For California residents, California law may provide individual consumers with additional rights regarding use of their Personal Information. Please see Privacy Notice for California Residents below.