1. Data controller and contact details
For the purposes of the EU General Data Protection Regulation (GDPR) and other applicable privacy laws, the data controller is:
- Legal entity name: Northbridge Investment Education LLC
- Registered address: 350 Fifth Avenue, New York, NY 10118, United States
- General contact email: [email protected]
- Privacy contact email: [email protected]
- Phone: +1 (212) 555-1284
If you have questions about this policy, want to exercise your rights, or want us to delete data you previously sent, contact us using the privacy email above. We may need to verify your identity before fulfilling certain requests.
2. Personal data we collect
We collect information that you choose to provide, information generated as part of how websites work, and information collected through cookies where permitted. The categories below describe what we may process.
2.1 Data you provide directly
- Full name (for example, when you submit a contact form)
- Email address (to respond to your message or send educational updates if you opt in)
- Message content (what you write in the form or email)
- Marketing preference (whether you request occasional educational emails)
We do not ask for account numbers, government IDs, or sensitive information. Please do not send sensitive financial or health information in any form fields on this site.
2.2 Data collected automatically
- IP address and approximate location derived from IP (city or region level)
- Device and browser information (browser type, version, operating system, device type, language)
- Usage and behavioral data (pages viewed, time on page, referrer, clicks, scroll depth where supported)
- Server log data (timestamp, requested URL, HTTP status, user agent, and related diagnostic data)
- Cookie identifiers or similar local storage identifiers (where enabled)
2.3 Cookies and similar technologies
We use cookies and local storage to remember essential preferences and, if you accept them, to collect analytics. Marketing cookies are not required to use the site. You can reject non-essential cookies using the cookie banner at any time.
3. How we collect personal data
We collect data in the following ways:
- Web forms: when you submit the contact form on the site, we receive your name, email, and message. If you tick the checkbox to receive occasional educational emails, that preference is recorded with your request.
- Email communications: if you email us directly, we process the information you send and any follow-up correspondence needed to respond.
- Cookies and local storage: our cookie banner stores your choice (accept or reject) in your browser using local storage, so we do not ask you on every page load.
- Analytics tools: if you accept analytics cookies, we may use Google Analytics 4 (GA4) to understand website performance and Meta Pixel to measure the effectiveness of ads and improve relevance. These tools typically collect device identifiers, cookie identifiers, and usage events.
- Server logs: our hosting provider records logs for security and reliability, which may include IP address and user agent details.
If you reject non-essential cookies, we will not knowingly set analytics or marketing cookies through our banner-controlled scripts. Some strictly necessary technologies may still be used to deliver the site and remember your cookie preference.
4. Legal bases for processing (GDPR Article 6)
Where GDPR applies, we rely on the following legal bases:
4.1 Consent (Article 6(1)(a))
We use consent as the legal basis for optional processing, including:
- Analytics cookies and analytics processing (such as GA4) when you choose “Accept” on the cookie banner.
- Marketing cookies and ad measurement (such as Meta Pixel) when you choose “Accept” and where we deploy such tools.
- Educational email updates if you opt in via the checkbox near the contact form submit button.
You can withdraw consent at any time. For cookies, use your browser settings and clear cookies, then select “Reject” when the banner appears again, or adjust settings in your browser to block cookies. For email updates, use the unsubscribe instructions provided in any email or contact us at [email protected].
4.2 Contract or pre-contract steps (Article 6(1)(b))
When you contact us with a request, we process your name, email, and message to take steps at your request and to respond. This includes handling inquiries about our educational materials, permissions, or support questions about how to use our calculators.
4.3 Legitimate interests (Article 6(1)(f))
We process certain data based on our legitimate interests, balanced against your rights and expectations. This includes:
- Security and fraud prevention (monitoring logs, detecting abuse, and defending against attacks).
- Website reliability (diagnostics, error monitoring, and performance maintenance).
- Record keeping to document communications and comply with legal obligations.
You can object to processing based on legitimate interests. If you do, we will evaluate your objection and stop processing unless we have compelling legitimate grounds or a legal obligation to continue.
5. Purposes of processing
We use personal data for the following purposes:
- Service delivery: to provide access to educational content and calculators, and to keep the site functional across devices.
- Customer support: to respond to messages and provide clarifications about our content or site features.
- Site improvement: to understand which pages are useful, where visitors get stuck, and how to improve navigation and readability (analytics only when consent is given).
- Marketing communications: to send occasional educational updates only when you opt in. These updates may include links to new guides, calculators, or policy changes.
- Advertising measurement: to understand ad performance and reduce wasted impressions (only when you accept relevant cookies and where such tools are active).
- Security and legal compliance: to maintain the security of our systems, enforce our Terms, and comply with applicable legal obligations.
We do not sell personal data. We do not use your contact details to send promotional messages unless you explicitly request educational updates.
6. Data retention periods
We keep personal data only for as long as necessary for the purposes described above. Retention can vary depending on the type of data and legal requirements. Our standard retention periods are:
- Contact form submissions and support emails: up to 2 years after the last interaction, unless a longer period is needed for legal compliance or to resolve disputes.
- Email update list (if you opt in): until you unsubscribe, then up to 30 days to complete removal from active systems, plus limited suppression records to respect your choice.
- Server logs: typically 30 to 90 days, unless security investigation requires longer retention.
- Analytics data: 14 months (where configured in our analytics tools), then aggregated or deleted according to the tool settings.
- Cookie consent record stored in local storage: remains until you clear your browser storage or reset site data.
If you request deletion, we will remove data where we can, unless we must retain some information for legal obligations or to establish, exercise, or defend legal claims.
8. International data transfers
Northbridge Investment Education LLC is based in the United States. If you access our website from the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be processed in the United States or other countries where our service providers operate.
When personal data is transferred outside the EEA to a country that may not provide the same level of data protection, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms. Where applicable, we also assess whether supplementary measures are needed based on the data type and the service provider’s technical controls.
You can request information about relevant safeguards by contacting [email protected].
9. Your rights under GDPR and how to exercise them
Where GDPR applies, you have rights regarding your personal data. We respect these rights and provide practical ways to exercise them. To submit a request, email [email protected] with the subject line “Privacy Request” and describe what you need. We may ask for reasonable verification to protect you from unauthorized access.
- Right of access: you can ask for a copy of the personal data we hold about you and information on how we use it.
- Right to rectification: you can ask us to correct inaccurate or incomplete information.
- Right to erasure: you can request deletion of personal data where there is no overriding reason for us to keep it.
- Right to restrict processing: you can ask us to limit processing in certain situations, for example while a dispute about accuracy is resolved.
- Right to data portability: where processing is based on consent or contract and carried out by automated means, you can request a portable copy of the data you provided to us.
- Right to object: you can object to processing based on legitimate interests. If you object, we will stop unless we have compelling grounds.
- Right to withdraw consent: if processing is based on consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out.
If you are in the EEA and believe we have not addressed your concerns, you have the right to lodge a complaint with a supervisory authority. For example, you may contact the Irish Data Protection Commission (DPC) at 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland, or your local authority in your country of residence or work.
11. Children’s privacy
Our website is not directed to children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] and we will take steps to delete the data from our systems where reasonably possible.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service providers. When we update the policy, we will revise the “Last Updated” date at the top of this page. For significant changes, we may provide a notice on the website or by email if we have your email address and permission to contact you.
13. Contact, DPO, and data deletion requests
We do not currently designate a Data Protection Officer as a formal role. However, we maintain a dedicated privacy contact channel to ensure requests are handled promptly.
- Privacy email: [email protected]
- Mailing address: Northbridge Investment Education LLC, 350 Fifth Avenue, New York, NY 10118, United States
If you want to unsubscribe from educational emails, use the unsubscribe link in the email or contact us. If you want us to delete your form submission data, email us from the same address you used to contact us so we can verify the request, or provide enough context for us to locate the message.