Evergreen Private Capital
Privacy Policy
Effective September 28, 2024
This Privacy Policy is published for use on the Evergreen Private Capital website and describes our information practices in connection with the Site. It does not constitute legal advice to any reader, and neither its publication nor your review of it creates an attorney-client relationship between you and Evergreen Private Capital, its affiliates, or any legal counsel involved in its preparation.
1. Who We Are
Evergreen Private Capital, together with its affiliates ("Evergreen," "we," "us," or "our"), is a private-client and private-office financial firm serving families and institutions. Evergreen operates the website located at evergreen.io, including its public pages, its Contact page, its Private Client sign-in page, and any password-protected client area made available through it (collectively, the "Site").
For purposes of the data protection laws of the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland, Evergreen Private Capital is the "controller" of personal information collected through the Site. Evergreen may be reached through the Contact page at evergreen.io or, if you are an existing client, through your Relationship Manager.
2. Scope of This Policy
This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and protect personal information when you visit or use the Site, submit an inquiry through the Contact page, or sign in to the private client area with credentials issued by your Relationship Manager. "Personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include information that has been de-identified or aggregated so that it can no longer reasonably be linked to an individual.
This Policy applies to the Site only. It does not apply to:
- personal information we collect offline or through channels other than the Site, such as in-person meetings, telephone calls, or correspondence with your Relationship Manager, except where that information is subsequently used in connection with the Site (for example, to issue credentials);
- personal information collected in connection with the establishment or servicing of a client relationship, including identity verification, anti-money-laundering, know-your-customer, suitability, and subscription information, which is governed by the privacy notices and agreements delivered to you as part of that relationship, including any notice provided under the Gramm-Leach-Bliley Act ("GLBA") and its implementing regulations; or
- third-party websites or services that may be linked from the Site.
Where this Policy and a privacy notice delivered to you as a client both address the same personal information, the client privacy notice will control with respect to that information to the extent of any inconsistency.
3. Information We Collect
We collect only the personal information that is reasonably necessary to operate the Site, respond to inquiries, and provide secure access to our private clients. The categories of personal information we collect through the Site are described below.
Information you provide through the Contact form. When you submit an inquiry through our Contact page, we collect:
- your full name;
- your email address;
- your telephone number;
- the name of your family office or institution, if you choose to provide it; and
- the content of your message, together with any personal information you choose to include in it.
Information you provide when signing in. When you sign in to the private client area, we collect:
- the Client ID or email address that was assigned to or registered for you by your Relationship Manager;
- your password, which is transmitted over an encrypted connection, is protected using industry-standard techniques, and is not stored in plain text; and
- any additional authentication information we may require, such as a one-time verification code or security response.
We do not offer public account creation. Credentials are issued only by Relationship Managers following our client-acceptance procedures, and the personal information used to establish your credentials (such as your name, email address, and client identifier) is supplied to the Site from our client records.
Information collected automatically. When you visit the Site, our web servers and our hosting and security providers automatically record certain technical information, which may include:
- your Internet Protocol (IP) address and the approximate geographic location (such as country or region) inferred from it;
- browser type and version, operating system, device type, screen resolution, and language settings;
- the date and time of your visit, the pages you view, the links you click, the address of the website from which you arrived (referring URL), and the pages you visit immediately before and after leaving the Site;
- for signed-in users, the date, time, and approximate location of each sign-in attempt, whether it was successful, and the actions taken within the private client area, which we record for security and audit purposes; and
- error reports, diagnostic information, and security-event data generated by our hosting, content-delivery, and security providers.
Cookies and similar technologies. The Site uses a limited number of cookies and similar technologies, as described in Section 7.
Information from other sources. We may combine information collected through the Site with information we already hold about you in our client records, or with information provided to us by your Relationship Manager, your authorized representatives, or publicly available sources, where necessary to verify your identity, respond to your inquiry, or maintain the security of the Site.
Sensitive personal information. We do not knowingly collect sensitive personal information (such as government identification numbers, financial account numbers, precise geolocation, biometric data, health information, or information about racial or ethnic origin, religious beliefs, or sexual orientation) through the public pages of the Site, and we ask that you not include such information in a Contact form message. Sign-in credentials are treated as sensitive personal information under certain U.S. state privacy laws; we use them only to authenticate you and secure your access, as described in this Policy.
4. How We Use Personal Information
We use the personal information described above for the following purposes:
- Responding to inquiries. To review and respond to messages submitted through the Contact form, to contact you by email or telephone about your inquiry, and to determine whether and how Evergreen may be able to assist you.
- Providing private client access. To authenticate Authorized Users, to administer credentials issued by Relationship Managers, to display account information and documents to the appropriate client, and to deliver notices and reports through the private client area.
- Relationship management. If you are a client or prospective client, to communicate with you about your relationship with Evergreen and, subject to applicable law and your preferences, to share information that we believe may be of interest to you.
- Security and fraud prevention. To monitor, detect, investigate, and prevent unauthorized access, credential misuse, account takeover, fraud, and other malicious or unlawful activity; to maintain audit logs; and to protect the rights, property, and safety of Evergreen, our clients, and others.
- Operating and improving the Site. To operate, maintain, troubleshoot, and secure the Site; to understand how the Site is used in aggregate; and to improve its performance, design, and content.
- Legal and regulatory compliance. To comply with applicable laws and regulations, including securities, anti-money-laundering, sanctions, tax, and record-keeping requirements; to respond to lawful requests from courts, regulators, and government authorities; and to establish, exercise, or defend legal claims.
- Business operations. To manage our business, including for internal audit, risk management, insurance, and corporate transactions.
We do not use personal information collected through the Site for automated decision-making that produces legal or similarly significant effects on you. We do not use personal information collected through the Site to serve targeted advertising, and we do not sell it.
5. Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the EEA, the UK, or Switzerland, we are required to have a legal basis for processing your personal information. We rely on the following legal bases:
- Performance of a contract or steps prior to entering into a contract: to provide private client access to Authorized Users under the Terms of Service and the applicable client agreements, and to respond to inquiries from prospective clients.
- Legitimate interests: to operate, secure, and improve the Site; to prevent fraud and unauthorized access; to communicate with clients and prospective clients; to manage our business; and to establish, exercise, or defend legal claims. Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms, and you have the right to object as described in Section 13.
- Compliance with legal obligations: to meet our obligations under applicable financial-services, anti-money-laundering, sanctions, tax, and record-keeping laws.
- Consent: where required by law, for example for the placement of any non-essential cookies (should we introduce them) or for certain electronic marketing communications. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
6. How We Share Personal Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We disclose personal information collected through the Site only in the following circumstances:
- Affiliates. We may share personal information with our affiliated entities under common ownership or control, for the purposes described in this Policy and consistent with this Policy.
- Relationship Managers and personnel. Personal information submitted through the Contact form or generated through the private client area is made available to the Evergreen personnel who need it to respond to you or to service your relationship, including Relationship Managers and client-service, compliance, technology, and security personnel.
- Service providers. We engage third-party service providers to perform functions on our behalf, including website hosting, content delivery, and infrastructure; security monitoring, threat detection, and authentication; email and communications delivery; document storage; and professional services such as legal, accounting, and audit. These providers are permitted to process personal information only as necessary to perform services for us, in accordance with our instructions and appropriate confidentiality and data protection obligations.
- Fund administrators, custodians, and other counterparties. Where the private client area displays information supplied by or shared with fund administrators, custodians, transfer agents, auditors, or similar parties in connection with your investments, personal information may be exchanged with those parties as described in the applicable client agreements and client privacy notices.
- Professional advisers. We may disclose personal information to our legal, tax, accounting, and other professional advisers, and to insurers and insurance brokers, where reasonably necessary for the purposes described in this Policy.
- Legal, regulatory, and protective disclosures. We may disclose personal information if we believe in good faith that disclosure is required or permitted by law, regulation, legal process, or governmental or regulatory request (including from securities regulators, tax authorities, law-enforcement agencies, and self-regulatory organizations); to enforce our Terms of Service or other agreements; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Evergreen, our clients, or others.
- Business transfers. If Evergreen is involved in a merger, acquisition, reorganization, financing, sale of assets, or similar transaction, or in the event of insolvency, personal information may be transferred to the successor or acquiring entity as part of that transaction, subject to customary confidentiality arrangements.
- With your direction or consent. We may share personal information with third parties when you direct us to do so or otherwise consent to the disclosure, including with your designated representatives, advisers, or authorized agents.
We may also share aggregated or de-identified information that cannot reasonably be used to identify you, for any lawful purpose.
7. Cookies and Similar Technologies
The Site uses a limited set of cookies and similar technologies. A cookie is a small text file placed on your device by a website. The Site uses:
- Strictly necessary cookies. These are required for the Site to function and cannot be switched off in our systems. They include cookies and similar tokens that maintain your signed-in session in the private client area, protect against cross-site request forgery and other security threats, balance load across our servers, and remember basic preferences necessary to display the Site. Our hosting and security providers may also set cookies or use similar technologies to distinguish legitimate visitors from automated traffic and to mitigate denial-of-service and other attacks.
- Session and local storage. The Site may use browser session storage or local storage to support the functioning of forms and the private client area during your visit.
We do not currently use analytics cookies, advertising cookies, social-media plug-ins, or third-party tracking technologies on the Site, and we do not permit third parties to collect personal information across other websites through the Site. If we introduce analytics or other non-essential cookies in the future, we will update this Policy and, where required by applicable law, request your consent before placing them.
You can control cookies through your browser settings, including by blocking or deleting cookies. Please note that disabling strictly necessary cookies will prevent you from signing in to the private client area and may affect other functions of the Site.
8. Data Retention
We retain personal information for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, tax, and reporting requirements, to resolve disputes, and to enforce our agreements. The criteria we use to determine retention periods include the nature and sensitivity of the information; the purposes for which we collected it; whether you are or become a client of Evergreen; the applicable statutory limitation periods; and the record-keeping obligations imposed on financial-services firms, which may require retention for a number of years after the end of a client relationship.
By way of illustration: Contact form submissions that do not lead to a client relationship are generally retained for a limited period sufficient to respond to the inquiry and maintain a record of our correspondence, after which they are deleted or anonymized in accordance with our retention schedule; sign-in and security logs are retained for a period consistent with our security and audit requirements; and information relating to Authorized Users is retained for the duration of the client relationship and thereafter for the period required by applicable law and our records retention policy. When personal information is no longer required, we securely delete, destroy, or de-identify it.
9. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental, unlawful, or unauthorized access, disclosure, alteration, loss, or destruction. These measures include encryption of data in transit using industry-standard transport-layer security; protected storage of passwords; access controls that limit access to personal information to personnel who require it; authentication and session controls for the private client area; logging and monitoring of access to the private client area; the use of hosting and security providers that maintain recognized security controls; and periodic review of our security practices.
No method of transmission over the internet or method of electronic storage is completely secure. Although we work to protect your personal information, we cannot guarantee its absolute security. You play an important role in protecting your information by keeping your credentials confidential, using strong and unique passwords, signing out after each session, and notifying your Relationship Manager immediately of any suspected unauthorized access. Evergreen will never ask you for your full password by email or telephone.
In the event of a breach of security affecting your personal information, we will notify you and the relevant authorities as and when required by applicable law.
10. International Transfers
Evergreen is based in the United States, and the Site is administered primarily in the United States. If you access the Site from outside the United States, your personal information will be transferred to, stored, and processed in the United States and in any other country where we or our service providers operate. These countries may have data protection laws that differ from, and may be less protective than, the laws of your jurisdiction.
Where we transfer personal information originating in the EEA, the UK, or Switzerland to a country that has not been recognized as providing an adequate level of data protection, we implement appropriate safeguards as required by applicable law, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or other lawful transfer mechanisms, together with supplementary measures where appropriate. You may request further information about the safeguards we use by contacting us as described in Section 18.
11. Your Rights and Choices
Depending on where you reside and subject to applicable law, you may have some or all of the following rights with respect to your personal information:
- to request access to, or a copy of, the personal information we hold about you;
- to request correction of inaccurate or incomplete personal information;
- to request deletion of your personal information;
- to request that we restrict, or to object to, certain processing of your personal information;
- to receive your personal information in a portable format;
- to withdraw consent where our processing is based on consent;
- to opt out of the sale or sharing of personal information or its use for targeted advertising (although we do not engage in those activities); and
- not to be discriminated against for exercising your rights.
Additional details regarding the rights available to residents of particular U.S. states are set out in Section 12, and details regarding the rights of individuals in the EEA, the UK, and Switzerland are set out in Section 13. Details on how to exercise your rights, including how we verify requests, are set out in Section 18.
Communications preferences. You may ask us to stop contacting you in response to a Contact form inquiry at any time by replying to our communication or by contacting us through the Contact page. Please note that we may continue to send Authorized Users service-related and legally required communications regarding the private client area and their relationship with Evergreen.
Certain rights may be limited where the personal information is subject to GLBA or other financial-privacy laws, where we are required to retain the information by law, or where the information is necessary to provide the private client area or to detect security incidents or fraud. If we decline a request in whole or in part, we will explain the reasons, subject to legal restrictions.
12. Privacy Rights of U.S. State Residents
This Section supplements the rest of this Policy and applies to residents of California (under the California Consumer Privacy Act as amended by the California Privacy Rights Act, the "CCPA") and of other U.S. states that have enacted comprehensive consumer privacy laws (including, by way of example, Colorado, Connecticut, Oregon, Texas, and Virginia), to the extent those laws apply to Evergreen and to the personal information concerned.
Financial privacy laws. Many of these state laws do not apply to personal information collected, processed, or disclosed pursuant to GLBA, or to financial institutions subject to GLBA. Personal information that we collect in connection with providing financial products or services to you as a client (including information displayed in or relating to the private client area) is generally governed by GLBA and the privacy notice delivered to you as a client, rather than by the state laws described in this Section. This Section applies principally to personal information collected through the public pages of the Site, such as Contact form submissions and technical data from website visitors.
Categories of personal information collected. In the twelve (12) months preceding the Effective date of this Policy, we have collected the following categories of personal information through the Site, from the sources and for the business purposes described in Sections 3 and 4:
- Identifiers, such as name, email address, telephone number, Client ID, and IP address.
- Personal information categories described in California Civil Code Section 1798.80(e), such as name and telephone number.
- Professional or employment-related information, such as the name of the family office or institution with which you are associated and any title or role you include in your message.
- Internet or other electronic network activity information, such as browser and device information, pages viewed, referring URLs, and sign-in and interaction logs.
- Geolocation data, limited to the approximate location inferred from an IP address (we do not collect precise geolocation).
- Sensitive personal information, limited to account log-in credentials (Client ID or email address in combination with a password or other access code), which we use solely to authenticate Authorized Users and secure the private client area.
- Any other personal information you voluntarily include in a Contact form message.
We do not collect biometric information, precise geolocation, audio or visual recordings, education information, or inferences used to create a profile through the Site.
Sources. We collect these categories directly from you (through the Contact form and the sign-in page), automatically from your device and browser (through our servers and our hosting and security providers), and from our internal client records and Relationship Managers (in connection with the issuance of credentials).
Disclosures for a business purpose. In the preceding twelve (12) months, we have disclosed each of the categories of personal information listed above, for business purposes, to the following categories of recipients: our affiliates; service providers (including hosting, infrastructure, security, authentication, and communications providers); professional advisers; and government, regulatory, and law-enforcement authorities where required by law.
No sale or sharing. We have not sold personal information, and we have not shared personal information for cross-context behavioral advertising, in the preceding twelve (12) months, and we do not do so. We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age. We use and disclose sensitive personal information only for purposes permitted under applicable regulations, such as providing the private client area, ensuring security and integrity, and preventing fraud; we do not use sensitive personal information to infer characteristics about you.
Your rights. Subject to applicable law and certain exceptions, you may have the right to:
- Know and access: request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties to whom we have disclosed it.
- Delete: request that we delete personal information we have collected from you.
- Correct: request that we correct inaccurate personal information we maintain about you.
- Portability: request a copy of your personal information in a portable and, to the extent technically feasible, readily usable format.
- Opt out of sale, sharing, or targeted advertising: we do not sell or share personal information or use it for targeted advertising, so there is no such activity from which to opt out.
- Limit use of sensitive personal information: we use sensitive personal information only for the limited purposes permitted without a right to limit; if that changes, we will provide a means to limit such use.
- Opt out of profiling: we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.
- Non-discrimination: we will not discriminate against you for exercising any of these rights, including by denying services, charging different prices, or providing a different level or quality of service.
- Appeal: residents of certain states may appeal our decision regarding a request by contacting us as described in Section 18 and indicating that you wish to appeal. If your appeal is denied, you may contact your state Attorney General.
Exercising your rights. You may submit a request by using the Contact page at evergreen.io and indicating that you are making a privacy rights request, or, if you are a client, by contacting your Relationship Manager. We will need to verify your identity before responding to a request to know, delete, or correct. We typically verify requests by matching the information you provide with information we already hold, such as your name, email address, telephone number, or, for Authorized Users, your Client ID and confirmation through your Relationship Manager. We may request additional information where necessary to verify your identity or to protect the security of your information. We will not use information provided for verification for any other purpose.
Authorized agents. You may designate an authorized agent to make a request on your behalf. We may require the agent to provide proof of written authorization signed by you, and we may require you to verify your identity directly with us or confirm that you provided the agent with permission to submit the request.
Timing. We will confirm receipt of a verifiable request within ten (10) business days where required and will respond within forty-five (45) days of receipt, which we may extend once by an additional forty-five (45) days where reasonably necessary, in which case we will inform you of the extension and the reason for it.
Shine the Light. California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
Notice of financial incentive. We do not offer financial incentives or price or service differences in exchange for the retention or sale of personal information.
13. Individuals in the EEA, the UK, and Switzerland
This Section applies if you are located in the EEA, the UK, or Switzerland, and supplements the rest of this Policy. Evergreen Private Capital acts as controller of the personal information collected through the Site. The legal bases on which we rely are described in Section 5, and information about international transfers is set out in Section 10.
Your rights. Subject to applicable law and certain exceptions and limitations, you have the following rights under the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection:
- Right of access: to obtain confirmation as to whether we process your personal information and, if so, to receive a copy of it together with certain information about the processing.
- Right to rectification: to have inaccurate personal information corrected and incomplete personal information completed.
- Right to erasure: to have your personal information erased in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected.
- Right to restriction: to require us to restrict processing of your personal information in certain circumstances, for example while a dispute about accuracy is resolved.
- Right to data portability: to receive personal information that you provided to us in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller, where processing is based on consent or contract and is carried out by automated means.
- Right to object: to object to processing based on our legitimate interests, on grounds relating to your particular situation, in which case we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for the establishment, exercise, or defense of legal claims. You have an absolute right to object to processing for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
- Rights relating to automated decision-making: not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. We do not engage in such decision-making through the Site.
To exercise these rights, please contact us as described in Section 18. We will respond within one month of receipt of your request, which may be extended by up to two further months where necessary, taking into account the complexity and number of requests; we will inform you of any such extension within the first month.
Right to lodge a complaint. If you believe that our processing of your personal information infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement; with the Information Commissioner's Office in the UK; or with the Federal Data Protection and Information Commissioner in Switzerland. We would appreciate the opportunity to address your concerns before you approach a supervisory authority, and we invite you to contact us in the first instance.
Provision of personal information. Providing personal information through the Contact form is voluntary; however, if you do not provide your name and contact details we will be unable to respond to your inquiry. For Authorized Users, provision of sign-in credentials and related technical information is necessary to provide secure access to the private client area, and access cannot be provided without it.
14. Children's Privacy
The Site is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under the age of eighteen (18), and in particular we do not knowingly collect personal information from children under the age of thirteen (13) within the meaning of the U.S. Children's Online Privacy Protection Act. If you are under eighteen, do not use the Site or submit any information through it. If we learn that we have collected personal information from a child in violation of this Section, we will take steps to delete that information promptly. If you believe that a child has provided us with personal information, please contact us as described in Section 18.
15. Third-Party Websites and Services
The Site may contain links to websites or services operated by third parties, such as custodians, fund administrators, or other service providers. This Policy does not apply to those third-party websites or services, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party website or service before providing personal information to it. The inclusion of a link on the Site does not imply our endorsement of the linked website or service.
16. Do Not Track and Global Privacy Control
Some browsers transmit "Do Not Track" ("DNT") signals or Global Privacy Control ("GPC") signals to websites. Because we do not track visitors across third-party websites and do not sell or share personal information, the Site does not respond differently when it receives a DNT or GPC signal; there is no tracking, sale, or sharing from which to opt out. Should our practices change, we will update this Policy and, where required by law, honor GPC signals as a valid request to opt out of sale or sharing.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, in the Site, or in applicable law. When we do, we will post the revised Policy on the Site and update the "Effective" date above. If we make material changes, we will provide additional notice as appropriate, which may include a notice on the Site, a notice within the private client area, or an email to Authorized Users. We encourage you to review this Policy periodically. Your continued use of the Site after a revised Policy becomes effective indicates that you have read and understood the revised Policy.
18. How to Contact Us and Exercise Your Rights
If you have questions, concerns, or complaints about this Policy or our privacy practices, or if you wish to exercise any of the rights described in this Policy, you may contact us:
- through the Contact page at evergreen.io, indicating in your message that your inquiry concerns privacy or a data rights request;
- if you are a client or Authorized User, through your Relationship Manager; or
- for legal requests, including formal legal notices and other legal correspondence, by email to legal@evergreen.io.
When submitting a rights request, please include your full name, the email address or Client ID associated with your information, your state or country of residence, and a description of the request you are making. We will use this information to verify your identity and respond to your request in accordance with applicable law. We will not charge a fee for responding to requests unless permitted by law, for example where requests are manifestly unfounded, excessive, or repetitive.
19. Governing Law and Venue
This Policy, and any dispute, claim, or controversy arising out of or relating to this Policy or our privacy practices in connection with the Site (including non-contractual disputes or claims), shall be governed by and construed in accordance with the laws of the State of Florida, United States, without giving effect to any choice-of-law or conflict-of-laws rules that would result in the application of the laws of any other jurisdiction, and, where applicable, the federal laws of the United States, except to the extent that a privacy or data-protection law of another jurisdiction applies of its own force to the matters described in this Policy (including the laws identified in Sections 12 and 13).
You and Evergreen agree that any legal action or proceeding arising out of or relating to this Policy or our privacy practices in connection with the Site shall be brought exclusively in the state courts of the State of Florida or the United States District Courts located in the State of Florida, and you irrevocably submit to the personal jurisdiction of those courts and waive any objection based on inconvenient forum. If a Client Agreement between you and Evergreen designates a different governing law or forum, that designation will control with respect to any dispute arising under that Client Agreement. If you are a consumer resident in a jurisdiction whose laws grant you mandatory protections that cannot be derogated from by contract, nothing in this Section deprives you of the protection of those laws or of any mandatory right to bring proceedings in the courts of your place of residence.