CAN-SPAM Policy

1. OVERVIEW AND PURPOSE

Rho Technologies and all subsidiaries and affiliates (collectively, “Rho” or the “Company”) is not a bank, money transmitter, or money service business. The Company can only pass customer instructions to partner banks as a program manager and technology provider.

It is the policy of the Company to adhere to the CAN-SPAM Act. The Company’s overall goals for complying with the act are to:

  • Proactively reduce spam and unsolicited commercial email messages and prohibit disguising the source and content of our messages.

  • Give consumers the choice to cease receiving our unsolicited commercial email messages.

The CAN-SPAM Act, a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have you stop emailing them, and spells out tough penalties for violations. The CAN-SPAM Act applies not only to bulk email. It covers all commercial messages, which the law defines as “any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service,” including email that promotes content on commercial websites. The law makes no exception for business-to-business email. That means all email – for example, a message to former customers announcing a new product line – must comply with the law. Each separate email in violation of the CAN-SPAM Act is subject to penalties, so non-compliance can be costly. The Company adheres to all CAN-SPAM requirements.

2. KEY DEFINITIONS

2.1. Affirmative Consent: The term "affirmative consent", when used with respect to a commercial electronic mail message, means: (A) the recipient expressly consented to receive the message, either in response to a clear and conspicuous request for such consent or at the recipient’s own initiative; and (B) if the message is from a party other than the party to which the recipient communicated such consent, the recipient was given clear and conspicuous notice at the time the consent was communicated that the recipient’s electronic mail address could be transferred to such other party for the purpose of initiating commercial electronic mail messages.

2.2. Commercial Electronic Mail Message:

2.2.1. In General: The term "commercial electronic mail message" means any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service (including content on an Internet website operated for a commercial purpose).

2.2.2. Transactional or Relationship Messages: The term "commercial electronic mail message" does not include a transactional or relationship message.

2.2.3. Reference to Company or Website: The inclusion of a reference to a commercial entity or a link to the website of a commercial entity in an electronic mail message does not, by itself, cause such message to be treated as a commercial electronic mail message for purposes of this Act if the contents or circumstances of the message indicate a primary propose other than commercial advertisement or promotion of a commercial product or service.

2.3. Transactional or Relationship Message: The term "transactional or relationship message" means an electronic mail message the primary purpose of which is:

  • to facilitate, complete, or confirm a commercial transaction that the recipient has previously agreed to enter into with the sender;

  • to provide warranty information, product recall information, or safety or security information with respect to a commercial product or service used or purchased by the recipient;

  • to provide (I) notification concerning a change in the terms or features of, (II) notification of a change in the recipient’s standing or status with respect to, or (III) at regular periodic intervals provide, account balance information or other type of account statement with respect to, a subscription, membership, account, loan, or comparable ongoing commercial relationship involving the ongoing purchase or use by the recipient of products or services offered by the sender;

  • to provide information directly related to an employment relationship or related benefit plan in which the recipient is currently involved, participating, or enrolled;

  • or to deliver goods or services, including product updates or upgrades, that the recipient is entitled to receive under the terms of a transaction that the recipient has previously agreed to enter into with the sender.

3. ROLES & RESPONSIBILITIES

3.1. Risk Committee

In view of the nature, diversity, number, and complexity of applicable laws and to achieve optimum compliance with the laws and regulations affecting the Company, management has established a risk committee (“RC”). The RC is comprised of key members of the Company’s executive management team and must include at least one of the Company's managing members. With the support, direction, and technical assistance from the Chief Compliance Officer (“CCO”), the RC is the governing body responsible for the broad oversight of this policy. The RC will also perform and/or oversee other duties that are outlined in this policy.

3.2. Chief Compliance Officer

The CCO, in coordination with the Marketing and Sales Departments, is responsible for administering and enforcing this policy.

4. POLICY

4.1. General Requirements

The following general requirements will be followed by the Company:

  • Don’t use false or misleading header information. “From,” “To,” “Reply-To,” and routing information – including the originating domain name and email address – must be accurate and identify the person or business who initiated the message.

  • Don’t use deceptive subject lines. The subject line must accurately reflect the content of the message.

  • Disclose clearly and conspicuously that the message is an advertisement.

  • Tell recipients where you’re located. Messages must include a valid physical postal address. This can be a current street address, a post office box registered with the U.S. Postal Service, or a private mailbox registered with a commercial mail receiving agency established under Postal Service regulations.

  • Tell recipients how to opt out of receiving future emails from the Company. The Company’s messages must include a clear and conspicuous explanation of how the recipient can opt out of receiving future email from the Company. The notice must be easily understood by an ordinary person so that it can be recognized, read, and comprehended. The Company will provide a return email address or another easy, Internet-based way for people to communicate their choice to the Company. The Company’s spam filter will be set to ensure opt-out requests are not blocked.

  • Honor opt-out requests promptly. Opt-out mechanisms will be able to process opt-out requests for at least 30 days after the message is sent. The Company will honor a recipient’s opt-out request within 10 business days. The Company cannot charge a fee, require the recipient to provide any personally identifying information beyond an email address, or require the recipient to take any step beyond sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request. Once a person has told the Company they do not want to receive more messages from the Company, the Company cannot sell or transfer their email addresses, even in the form of a mailing list. The only exception is that the Company may transfer the addresses to a third-party hired to assist with compliance with the CAN-SPAM Act.

  • Monitor what others are doing on your behalf. The law makes clear that even if the Company hires another company to handle its email marketing, the Company cannot contract away its legal responsibility to comply with the law. Both the company whose product is promoted in the message and the company that actually sends the message may be held legally responsible.

4.2. Verification Procedures

The following verification procedures will be performed by the Company:

  • Create a complete list of the products and/or services that the Company has promoted via email.

  • Identify Company personnel who are responsible for the Company’s compliance with CAN-SPAM. (See Company’s Marketing Policy).

  • Provide all Company personnel who engage in commercial email messages with this policy and any other training to aid them in email activities.

  • Ensure that the Company’s marketing plans reflect electronic communication strategies that comply with CAN-SPAM.

  • Have available all sent email messages so that an examiner may select samples to determine whether these messages had “commercial” promotion as their primary purpose.

  • Review sent email messages, whose primary purpose was “commercial,” and verify that the messages comply with the CAN-SPAM provisions:

  • Do not use false or misleading transmission information, such as:

    • False or misleading header information;

    • A “from” line that does not accurately identify any person who initiated the message; and

    • Inaccurate or misleading identification of a protected computer used to initiate the message.

  • Do not use deceptive subject headings.

  • Provide a functioning email return address or other Internet-based response mechanism.

  • Provide a clear and conspicuous identification that the message is an advertisement or solicitation; clear and conspicuous notice of the opportunity to decline to receive further commercial email messages from the sender; and a valid physical postal address of the sender. Note: this provision does not apply to a commercial email message if the recipient has given prior affirmative consent to receipt of the message.

  • Do not reflect address harvesting, hijacking, or dictionary attacks.

  • Retain any customer requests to opt out of receiving any additional email messages from the Company. Review these requests to confirm that controls are in place to discontinue commercial email messages within 10 business days of receipt of an opt-out notification.

  • Summarize and/or track all findings, concerns, and actions taken for customer requests to opt out of receiving any additional email messages from the Company.

5. TRAINING

It is the responsibility of the CCO to ensure that all Employees receive appropriate training on CAN-SPAM and the directives of this policy annually.

6. RECORD RETENTION

Documentation will be retained in accordance with the Data Management Policy.

7. EXCEPTIONS, QUESTIONS, AND INTERPRETATIONS OF THIS POLICY

Requests for exceptions to this policy must be very specific and may only be granted on specific items, rather than to entire sections. Company personnel, with the exception of those who are to communicate their requests by submitting them to the CCO for consideration by senior management.

Any questions regarding the interpretation of this policy should be directed to the CCO.

8. ENFORCEMENT

All Company employees are responsible for complying with this policy. Management is responsible for ensuring adherence to this policy within their departments and third parties for which they have oversight. The CCO, internal and/or external auditors, and potentially other control groups (as applicable), will monitor compliance with this policy.

9. APPROVAL, REVIEW, AND REVISION HISTORY

This policy shall be reviewed and approved by the RC at least annually. Any substantive revisions must be approved by the RC and the partner bank. The CCO is responsible for approving non-substantive revisions. The CCO shall share the updated policy with the partner bank after any non-substantive changes are made.