Privacy Policy
This Privacy Policy ("Policy") describes how OnePillar Holdings LLC and its controlled portfolio companies operating under assumed names (collectively, "the Company," "we," "us," or "our") collect, use, and disclose personal information. This Policy applies to information we process related to our employees, independent contractors, investors, vendors, and customers of our portfolio companies.
We are committed to protecting the privacy and security of personal information. This Policy is effective as of [2-15-2026]. Questions regarding this Policy may be directed to [hello@onepillarholdings.com].
For the purposes of this Policy, the following terms have the meanings set forth below:
We may collect and process various categories of Personal Information depending on your relationship with us. This includes, but is not limited to, the following:
We collect this information directly from you, from third parties (such as background check providers or business partners), and through automated means when you interact with our digital properties.
We process Personal Information for various business purposes, relying on one or more legal bases for processing. The purposes for which we collect and use Personal Information include:
Our legal bases for processing include the performance of a contract, compliance with a legal obligation, our legitimate business interests, and, where applicable, your consent. We limit the collection and processing of Personal Information to what is adequate, relevant, and reasonably necessary for the disclosed purposes.
We do not sell Personal Information. We may share or disclose your Personal Information with the following categories of third parties for the purposes described in this Policy:
OnePillar Holdings LLC is based in the United States, and information we collect is primarily processed and stored in the United States. If you are interacting with us from outside the United States, your Personal Information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.For transfers of Personal Information from other jurisdictions, such as the European Economic Area or the United Kingdom, we implement appropriate safeguards to ensure that your data is protected. These safeguards may include executing Standard Contractual Clauses approved for transfers of personal data, relying on adequacy decisions, or other data transfer mechanisms recognized under applicable law. We also employ technical and organizational measures, such as encryption, to protect information during transit and at rest.
We retain Personal Information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The criteria used to determine our retention periods include the duration of our relationship with you, the existence of a legal obligation, or whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations or litigation).
Upon expiration of the applicable retention period, we will securely destroy or dispose of Personal Information in a manner designed to ensure it cannot be reconstructed or read, such as by shredding physical documents or permanently erasing electronic data. We may also de-identify or aggregate Personal Information for statistical or analytical purposes, in which case we may use this information indefinitely without further notice to you, as it is no longer considered Personal Information.
Depending on your jurisdiction, you may have certain rights regarding your Personal Information. These rights may include:
To exercise any of these rights, please submit a request to [hello@onepillarholdings.com]. We must verify your identity before processing your request and may require you to use an existing account or provide additional information for authentication purposes. We will respond to your request within the time frames required by applicable law. These rights are not absolute, and we may deny a request in accordance with applicable legal provisions. A provision of a contract cannot waive or limit these consumer rights.
We have implemented and maintain reasonable administrative, technical, and physical data security practices designed to protect the confidentiality, integrity, and accessibility of Personal Information. These measures include access controls, encryption, employee training, and vendor security assessments to guard against unauthorized access, use, disclosure, alteration, or destruction of your information.
In the event of a data breach or cybersecurity event, we will take prompt action to investigate the incident, mitigate harm, and restore the security of our systems. If we determine that a "breach of system security" has occurred that requires notification, we will notify affected individuals and relevant regulatory authorities without unreasonable delay and in accordance with applicable laws.
This notification will generally be made no later than forty-five (45) days from the discovery of the breach, unless a delay is requested by law enforcement. If the breach affects more than one thousand (1,000) individuals, we will also notify consumer reporting agencies.
Our websites and digital platforms may use cookies, web beacons, and other similar automated technologies to collect information about your device and browsing activity. This information helps us operate our websites, analyze performance and usage, improve user experience, and for other disclosed purposes.Where we use these technologies for purposes such as targeted advertising, we will provide clear and conspicuous disclosure and a mechanism for you to opt out of such processing. You may manage your cookie preferences through your browser settings or through a cookie consent tool provided on our websites. Please note that disabling certain cookies may affect the functionality of our websites.
We restrict the processing of Sensitive Personal Data to limited and necessary purposes. We will not process Sensitive Data, such as information related to health, biometrics, or racial or ethnic origin, without first obtaining your explicit consent, or as otherwise required or permitted by applicable law. For example, we may process such data to administer health and disability benefits for our employees. When we process Sensitive Data, we apply heightened security measures and access controls to ensure its protection.
Our services and business operations are not directed toward individuals under the age of 16, and we do not knowingly collect Personal Information from minors. In the case of processing sensitive data concerning a known child, we will do so only in accordance with the federal Children's Online Privacy Protection Act (COPPA). If we become aware that we have inadvertently collected Personal Information from a minor without parental consent, we will take steps to delete the information as soon as possible.
Our websites and communications may contain links to third-party websites, applications, and services that are not operated by us. We provide these links for your convenience, but we do not review, control, or monitor the privacy practices of third parties. We are not responsible for their content or privacy policies. We encourage you to review the privacy policy of any third-party site you visit.
We conduct due diligence when selecting third-party vendors and service providers who may process Personal Information on our behalf. We require our vendors to enter into written agreements that impose data protection obligations, including requirements to maintain the confidentiality and security of the information they process for us. These agreements restrict vendors from using Personal Information for any purpose other than providing the contracted services. We also take steps to ensure that our vendors notify us in the event of a cybersecurity incident affecting our data.
We are committed to complying with all applicable laws and regulations regarding the processing of Personal Information. We may be required to disclose your Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Such disclosures may be made pursuant to a court order, subpoena, or other legal process. While we seek to protect individual privacy, our policy is to cooperate with valid legal requests. Any disclosure will be limited to what is legally required.
Residents of certain jurisdictions may be afforded additional rights regarding their Personal Information under applicable laws. For example, laws in states like California, Virginia, Colorado, and Tennessee provide specific consumer rights. We are committed to honoring these rights as required by law. If you are a resident of one of these jurisdictions, you may have additional rights to access, delete, or opt-out of the sale or sharing of your Personal Information. For more details on the rights available in your jurisdiction and how to exercise them, please contact us at [hello@onepillarholdings.com].
We reserve the right to amend this Policy at any time. When we make changes, we will post the updated Policy on our website and revise the "Effective Date." We encourage you to review this Policy periodically to stay informed about our information practices. For material changes, we may provide more direct notification as appropriate under the circumstances.
If you have any questions, concerns, or complaints regarding this Policy or our privacy practices, please contact us at [hello@onepillarholdings.com]. We will investigate and attempt to resolve any complaints and disputes. You may also have the right to lodge a complaint with the competent data protection authority in your jurisdiction.
This Policy and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of the State of [TN], without regard to its conflict of law principles. We encourage you to first contact us to resolve any dispute internally. Any legal action or proceeding arising under this Policy will be brought exclusively in the federal or state courts located in [TN], and the parties hereby irrevocably consent to the personal jurisdiction and venue therein.
This Policy establishes the foundational privacy principles for OnePillar Holdings LLC and its controlled Portfolio Companies. Each Portfolio Company operating under an assumed name must adopt or adhere to this Policy, particularly where OnePillar acts as the data controller or as otherwise contractually mandated. However, a Portfolio Company may issue its own separate, customer-facing privacy notice to govern the processing of Personal Information for which it is the independent controller. This Policy shall continue to govern data processed at the holding company level.
Version: [1.0] Effective Date: [2-15-26] Approved By: [Joseph R Brown]
Copyright 2025 Onepillar Holdings LLC