Privacy Policy
Effective Date: September 1, 2025
**********
Lucas Financial Consulting, LLC (“Lucas Financial,” “we,” “us,” or “our”) operates the DST Atlas technology and the website located at DSTAtlas.com (together, the “Services”). This Privacy Policy explains how we collect, use, disclose, and secure personal information, and describes your rights and choices. If you do not agree with this Policy, please do not use the Services.
If you are using the Services on behalf of an Organization (e.g., a broker-dealer, RIA, or sponsor), our processing of personal information for that Organization may be governed by our Data Processing Addendum (“DPA”) with the Organization. In those cases we act as a processor/service provider and the Organization’s privacy notice controls.
Table of contents
- Information we collect
- How we use information
- How we disclose information
- Your privacy choices
- State-specific rights (CA, CO, others)
- Global Privacy Control & universal opt-out
- Cookies & analytics
- Data retention
- Security
- Children’s privacy
- International users
- Processor vs. controller roles
- Changes to this Policy
- How to contact us
Information we collect
We collect information in three main ways: (1) directly from you, (2) automatically through the Services, and (3) from third parties (e.g., your Organization).
- Information you provide
- Account & profile data: name, email, role (e.g., registered rep, sponsor, RIA), firm name, broker-dealer or sponsor affiliation, CRD or similar identifiers, and any other registration details.
- Portfolio Builder inputs & outputs: data you enter to generate client-facing reports (including whitelabeled versions).
- Communications: messages, support requests, and feedback.
- Payment/transactional: if applicable, limited billing details processed via our payment processor (we do not store full card numbers).
- Information collected automatically
- Device & usage: IP address, device identifiers, browser type, operating system, pages viewed, links clicked, approximate location (derived from IP), timestamps, and referrer URLs.
- Cookies and similar technologies: pixels, tags, SDKs used for functionality, analytics, security, and (if enabled) advertising delivery and measurement.
- Information from third parties
- Organizations: where your access is provisioned by an Organization, we may receive identifiers (e.g., user ID, firm ID), role/permissions, or business contact info.
- Service providers & partners: analytics providers, fraud-prevention tools, ad delivery systems, and identity verification services.
- Public sources: professional directories, regulator-hosted databases, or public websites (e.g., to confirm firm affiliation).
How we use information
We use personal information to:
- Provide and secure the Services, including account creation, authentication, permissions, access controls, and fraud/abuse prevention.
- Operate the Portfolio Builder (formatting, caching, and storing your inputs/outputs to deliver requested functionality).
- Customer support and to respond to inquiries.
- Improve and develop the Services, including analytics and research.
- Comply with legal and regulatory requirements, including audits, supervisory requests, and enforcing our agreements.
- Marketing & communications about features, updates, and events (you can opt out at any time).
- Advertising delivery and measurement (if enabled), which may constitute “sharing” for cross-context behavioral advertising under certain state laws.
When required, we rely on your consent; otherwise, we rely on contractual necessity, legitimate interests (such as service improvement and security), or legal obligations.
How we disclose information
We disclose personal information to:
- Service providers/processors: cloud hosting, security, analytics, communications, payment, and (if used) ad delivery/measurement. These parties may access personal information only to perform services for us and must protect it.
- Organizations: if your account is managed by an Organization, we may disclose usage or account information to that Organization under our agreement with them.
- Sponsors/broker-dealers/RIA firms: where you instruct us to share (e.g., when generating or distributing a Portfolio Builder output) or where the Organization’s settings permit.
- Legal and compliance: regulators, law enforcement, or other third parties when required by law or to protect rights, safety, or the integrity of the Services.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations.
- With your direction: when you ask or consent to disclosures.
We do not sell personal information for money. We may “share” limited identifiers and internet/electronic activity with ad/measurement partners to deliver and measure advertising on our site; you can opt out.
Your privacy choices
- Access / Delete / Correct: You may request access to, deletion of, or correction of your personal information.
- How: Email info@dstatlas.com
- Do Not Sell or Share / Targeted Advertising Opt-Out: You may opt out of “selling”/“sharing” personal information or targeted advertising as defined by state laws.
- How: Email info@dstatlas.com
- Marketing Emails: Click “unsubscribe” in any marketing email.
If your access is provided by an Organization, some requests may need to be directed to that Organization (where we act as its processor).
State-specific rights
California (CCPA/CPRA)
California residents have the right to know/access, delete, correct, opt out of sale/share, and limit use/disclosure of sensitive personal information (SPI). We do not use SPI (e.g., precise geolocation, login credentials, financial account numbers, etc.) to infer characteristics or for purposes beyond permitted uses. You may use an authorized agent; we will verify requests.
Colorado (CPA)
Colorado residents may access, delete, correct, port, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We also provide an appeals process if we deny your request: email How: Email info@dstatlas.com with the subject “Privacy Request Appeal.” We respond within the timelines required by law.
Other U.S. states
Residents of Virginia, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights.
Global Privacy Control
We recognize browser-based Global Privacy Control (GPC) and other qualified universal opt-out signals where required. When detected, we treat the signal as a request to opt out of sale/share or targeted advertising for that browser.
Cookies & analytics
We use cookies and similar technologies to:
- Operate the site (authentication, security, preferences).
- Measure usage (first-party analytics; we may use third-party analytics).
- Deliver and measure advertising (if enabled, e.g., ad server tags).
You can set your browser to block/clear cookies, or use GPC. Blocking cookies may impact functionality.
Data retention
We retain personal information for as long as needed to provide the Services, comply with legal/financial recordkeeping, resolve disputes, enforce agreements, and for legitimate business purposes. Typical examples:
- Account and audit logs: up to 7 years after account closure.
- Portfolio Builder outputs you store with us: until you delete them or as required by your Organization’s retention policy.
- Cookie/analytics data: per cookie duration or shorter when you opt out.
When no longer needed, we will delete or de-identify information consistent with applicable law.
Security
We employ administrative, technical, and physical safeguards appropriate to the nature of the data we process (access controls, encryption in transit, segmented environments, logging/monitoring). No system is 100% secure; you are responsible for maintaining the confidentiality of your credentials and promptly notifying us of any suspected compromise.
Children’s privacy
The Services are not directed to children under 13 (or under 16 in certain jurisdictions for specific data uses). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will delete it.
International users
If you access the Services from outside the United States, you understand that your information may be processed in the U.S. and other countries with privacy laws that may differ from those where you live. Where required, we will implement appropriate safeguards for cross-border transfers.
Processor vs. controller roles
- Controller: For most direct-to-user activity on DSTAtlas.com, Lucas Financial is the controller of your personal information.
- Processor/Service Provider: When we process personal information on behalf of an Organization under contract (e.g., provisioning users, restricting access, generating reports for its clients), we do so as a processor/service provider and follow the Organization’s instructions under our DPA. If your request concerns data controlled by your Organization, we may direct you to it.
Changes
We may update this Policy from time to time. If changes are material, we will notify you (e.g., by email or a notice on the site) before they take effect. The “Last updated” date reflects the most recent changes.
Contact
DST Atlas
Attn: Privacy
Email: info@dstatlas.com