This Privacy Policy describes how BrightRock Investment Group LLC collects, uses, stores and protects information when you visit our website, contact our team, or use the reporting, document assembly, data room, archive, statement and investor portal systems that we design and operate. BrightRock Invest is the developer brand under which our engineers build and maintain these systems, and the same privacy commitments apply to every service we provide.
1. Introduction and Scope
BrightRock Investment Group LLC respects the privacy of every visitor, client, investor and business partner who interacts with us. This Policy explains what information we gather, the reasons we gather it, the choices available to you, and the safeguards we apply. It covers our public website, our client reporting platforms, our document assembly tools, our data room integrations, our compliance archive workflows, our statement generation services and our investor portal deployments.
This Policy does not apply to third party websites or services that we do not control, even when we link to them or connect them to a client system. When we integrate a third party service into an engagement, the privacy terms of that provider govern the data it processes on its own behalf, and we will identify the provider during onboarding so your team can review those terms.
By using our website or engaging our services, you acknowledge that you have read this Policy. If you do not agree with the practices described here, please do not use the website or submit information to us.
2. Who Is Responsible
The entity responsible for the information described in this Policy is BrightRock Investment Group LLC, a company located at 1835 S Highway 89, Brigham City - 84302-4117, United States (US). BrightRock Investment Group LLC determines the purposes and means of the processing carried out through this website and through the systems we operate directly for our clients.
Where we process information on behalf of a client, for example when running a reporting pipeline that contains investor records, the client is the controller and BrightRock Investment Group LLC acts as a processor. In that situation, the client decides what data enters the system and which individuals may access it, while we follow the client instructions and apply the safeguards described in this Policy and in the relevant engagement agreement.
Questions about this Policy, or about the role BrightRock Investment Group LLC plays in a particular engagement, may be directed to the contact details in the final section below.
3. Information We Collect
We collect several categories of information, and the category depends on how you interact with us. When you browse the website we collect limited technical information. When you contact us we collect the details you choose to provide. When we operate a client system we process the business records that the engagement requires.
Technical information
This includes your internet protocol address, browser type and version, operating system, device type, referring page, pages visited, the date and time of each request, and general geographic region derived from the address. We use this information to keep the website available, to diagnose faults and to understand which pages are useful.
Contact information
When you send a message through our contact form or by email, we receive your name, your email address, any telephone number you include, the subject of your message and the content of your message. We use these details only to respond to your enquiry and to maintain a record of our correspondence.
Business and client information
In the course of an engagement we may process business records such as portfolio data, account statements, fund documents, diligence materials and compliance records. These records may include personal information about investors, officers or representatives, and we handle them strictly according to client instructions and the applicable agreement.
Portal account information
When we deploy an investor portal, the portal may store account identifiers, access credentials in hashed form, session metadata and an audit record of sign-ins and document views. This information allows the portal to authenticate users and to give administrators a reliable activity trail.
4. How We Obtain Information
Most information reaches us in one of three ways. First, you provide it directly, for example when you complete the contact form, send an email, or speak with our team. Second, it arrives automatically as your browser interacts with the website. Third, it is supplied by a client as part of an engagement, when a reporting pipeline reads a custodian file or a document assembly system retrieves a template library.
We do not purchase personal information from data brokers and we do not build advertising profiles. Where a client provides information about individuals, the client is responsible for ensuring that it has a lawful basis to share that information with us and that the individuals concerned have received the required notices.
If you provide information about another person, please ensure you have their permission to do so, because we will treat that information in the same way as information you provide about yourself.
5. Why We Use Information
We use information for specific and limited purposes. We respond to enquiries and provide the services a client has engaged us to deliver. We operate, maintain and secure the website and the systems we host. We diagnose technical problems and improve the reliability of our platforms. We meet our legal, accounting and reporting obligations. We detect and prevent fraud, misuse and unauthorized access. We communicate about changes to our services, our policies or our terms.
We also use aggregated and de-identified information to understand how our services perform in general, such as measuring the time a typical pipeline takes to complete. Aggregated information cannot reasonably be used to identify any individual, and we do not attempt to re-identify it.
We will not use your information for a new purpose that is incompatible with the purposes listed here without first informing you and, where required, obtaining your consent.
6. Legal Bases for Processing
Where the law requires us to identify a legal basis for processing, we rely on one or more of the following. We process information to perform a contract with you or to take steps at your request before entering a contract, such as responding to a service enquiry. We process information to pursue our legitimate interests in operating a secure and effective business, provided those interests are not outweighed by your rights. We process information to comply with legal obligations, including tax, accounting and record keeping duties. We process information with your consent where we have asked for it, and you may withdraw that consent at any time.
When we process information as a processor on behalf of a client, the client is responsible for the legal basis, and we process the information only on the client documented instructions unless a legal obligation requires otherwise.
9. Service Providers and Subprocessors
We rely on a small number of carefully selected service providers to deliver our services. These include cloud hosting providers that run our infrastructure, email providers that deliver notifications and correspondence, and security providers that help us detect and respond to threats. Each provider is assessed before we engage it and is bound by a written agreement that requires confidentiality, reasonable security and compliance with applicable data protection law.
When we add or replace a subprocessor that will process client personal data, we provide advance notice where our engagement agreement requires it, so the client has an opportunity to object. A current list of subprocessors is available to clients on request, and we keep that list under review as our infrastructure evolves.
We remain responsible for the performance of our subprocessors and for ensuring that the protections we promise in this Policy continue to apply to information they handle.
10. International Data Transfers
BrightRock Investment Group LLC is based in the United States, and the systems we operate are primarily hosted there. Where information is transferred from another country into the United States, or between other jurisdictions, we take steps to ensure the transfer is lawful and that the information continues to receive an appropriate level of protection.
Those steps may include standard contractual clauses, an adequacy determination, or another lawful transfer mechanism recognized by the relevant authorities. Where a client requires a specific transfer mechanism, we will work with the client to put the necessary terms in place before any data moves.
You may contact us for more information about the safeguards that apply to a particular transfer, and we will provide the relevant details to the extent we are permitted to do so.
11. Data Retention
We keep information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. Contact enquiries are retained for a reasonable period so we can follow up and maintain a record of the conversation. Website technical logs are retained for a shorter period and then deleted or aggregated. Client engagement records are retained according to the applicable agreement and any statutory retention obligation.
Where a client defines a retention schedule for the records in a reporting or archiving system, we follow that schedule and do not keep copies beyond it. When information is no longer required, we delete it or render it permanently unreadable, and we require our service providers to do the same.
If a legal hold applies, we suspend deletion for the affected records until the hold is released by an authorized person, and we keep a record of the hold and its release.
12. Security Measures
We apply technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure and destruction. These measures include encryption of data in transit, access controls that follow the principle of least privilege, authentication requirements for administrative functions, logging of sensitive actions, regular review of our infrastructure, and staff training on privacy and security responsibilities.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We maintain an incident response process so that, if a breach affecting personal information occurs, we can investigate promptly, take corrective action and notify affected parties and authorities as required by law.
If you believe your interaction with us is no longer secure, please contact us immediately using the details in the final section so we can investigate without delay.
13. Your Privacy Rights
Depending on where you live, you may have specific rights regarding your personal information. These rights commonly include the right to know what information we hold about you, the right to request a copy of that information, the right to request correction of inaccurate information, the right to request deletion subject to legal limits, the right to restrict or object to certain processing, and the right to receive information in a portable format.
You also have the right not to be discriminated against for exercising these rights. To make a request, contact us using the details in the final section and describe what you would like us to do. We may need to verify your identity before acting, and we will respond within the period required by applicable law.
If we process your information as a processor on behalf of a client, we will forward your request to that client, because the client controls the information and is best placed to respond. We will assist the client as required by the applicable agreement.
14. Privacy for Children
Our website and services are intended for businesses and for adults acting in a professional or investment capacity. They are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, please contact us and we will take reasonable steps to delete it.
Where a client system contains information about a minor, for example as a beneficiary of an account, the client is responsible for ensuring that the collection and use comply with the rules that protect children in the relevant jurisdiction, and we will support the client in applying appropriate protections.
15. Investor Portal Data
Investor portals that we deploy are configured so that each investor can see only the records associated with that investor. Access is granted through authenticated accounts, sessions expire, and administrative actions are logged. Portal content such as statements and documents is generated from the same controlled source that feeds the reporting pipeline, so the portal does not become a separate, unmanaged copy of sensitive records.
When an investor account is closed, the account is disabled and its access credentials are invalidated. Records that must be retained for legal or contractual reasons remain in the compliance archive under the applicable schedule. Portal administrators can review activity and revoke access at any time, and every such action is recorded.
16. Marketing Communications
We send marketing communications only where we have a lawful basis to do so. If you receive a message from us and would prefer not to receive further marketing messages, you can opt out using the link in the message or by contacting us directly. We will honor your choice promptly.
Opting out of marketing does not affect service messages that are necessary to deliver a service you have engaged, such as security notices or administrative updates. We keep a record of your communication preferences so that we can respect them consistently.
We do not share your contact details with third parties for their own marketing purposes.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, our services or the law. When we make a material change, we will update the effective date at the top of this page and, where appropriate, provide additional notice. We encourage you to review this Policy periodically so that you remain aware of how we protect information.
If a change significantly alters how we use information we already hold, we will provide a clear notice and, where the law requires, seek your consent before the change applies to you. Continued use of the website or our services after an update takes effect indicates that you accept the revised Policy.
18. How to Contact Us
If you have a question about this Policy, wish to exercise a privacy right, or want to raise a concern about how we handle information, please contact us using the details below. We take privacy questions seriously and will respond as quickly as we reasonably can.
BrightRock Investment Group LLC
1835 S Highway 89
Brigham City - 84302-4117
United States (US)
Email: contact@brightrockinvest.autos
Telephone: +17246454311