Effective Date: January 1, 2026
TFG UPPER HOLDINGS INC. (hereinafter referred to as we, our, or the Company), a Computer Systems Design and Related Services firm headquartered at 234 W Florida St, Milwaukee, WI 53204-1659, United States, takes the privacy of individuals who interact with our digital properties and services seriously. This Privacy Policy explains how we collect, use, disclose, retain, and secure personal information gathered through our website at tfgrise.mom (the Site), our client engagement platforms, and any service delivered under the developer identity TFG Rise.
By accessing the Site or engaging with our services, you acknowledge that you have read, understood, and agreed to the practices described in this document. If you reside in a jurisdiction with enhanced data protection requirements, additional provisions set forth in Sections 6 and 7 apply to you.
Our operations span global technology infrastructure, cybersecurity, data engineering, cloud architecture, and intelligent automation — all fields where data integrity is a foundational commitment, not merely a compliance checkbox. This policy reflects the operational standards we maintain across every engagement.
We are headquartered in Milwaukee, Wisconsin, and our data processing activities are governed by applicable United States federal and state privacy statutes, as well as the standards we voluntarily adopt to meet the expectations of international clients and partners.
We gather information through direct input, automated collection technologies, and third-party sources. Each category serves a defined operational purpose and is handled in accordance with the protections described in Section 5.
Every data processing activity we undertake is tied to a specific, documented purpose. We do not repurpose personal information for unrelated secondary uses without additional notice.
We rely on the following legal bases for processing: contractual necessity for service delivery, legitimate interest for Site operations and security, consent for marketing communications, and legal obligation for compliance activities.
We are not in the business of selling personal information. Data sharing is limited to the operational and legal contexts described below.
In any scenario not covered above, we will seek your explicit consent before sharing personal information with external parties.
The integrity and resilience of the data under our stewardship is a non-negotiable engineering priority. We apply the same discipline to our own data environment that we architect for clients.
Personal information is retained only as long as necessary to fulfill the purposes outlined in Section 3, or as required by applicable law. Contact form submissions and correspondence are retained for the duration of the relevant engagement plus twenty-four months thereafter. Automatically collected Site data is retained for a rolling thirteen-month window before permanent de-identification or deletion. Client account data is deleted within ninety days of a verified account closure request, except where extended retention is mandated by law.
Our security posture is validated through independent third-party assessments. We maintain SOC 2 Type II certification and ISO 27001 compliance. Annual penetration tests are conducted by external security firms, and remediation findings are tracked through closure. Our infrastructure platform undergoes continuous compliance monitoring against CIS benchmarks and industry-specific frameworks relevant to our client verticals.
No method of transmission or storage is absolutely secure. While we deploy extensive technical and organizational measures to protect your data, we cannot guarantee security against a determined adversary exploiting an unknown vulnerability. We encourage you to take appropriate precautions on your side — use strong passwords, enable multi-factor authentication on your accounts, and remain vigilant against phishing attempts.
As a company headquartered in the United States with a global client base spanning twelve regions, personal information may be transferred to, stored in, or processed in countries other than your own. We apply consistent safeguards regardless of where data resides.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other jurisdictions, we rely on approved transfer mechanisms including Standard Contractual Clauses and supplementary technical, organizational, and contractual measures as required. For clients and Site visitors in other regions, we assess applicable local law and implement equivalent protections.
Before any cross-border data flow is established, we conduct a transfer impact assessment to identify the legal basis, evaluate the recipient jurisdiction's data protection regime, and document the supplementary safeguards applied. These assessments are reviewed annually and updated when regulatory developments or service architecture changes introduce new transfer scenarios.
Depending on your jurisdiction, you may exercise the following rights regarding the personal information we hold about you. We respond to all verifiable requests within the timelines prescribed by applicable law — typically thirty days, extendable once for complex requests.
To exercise any of these rights, please contact us using the details in Section 10. We will verify your identity before processing any request — typically by confirming information you have previously provided to us. If you are acting as an authorized agent, we will require signed authorization and direct confirmation from the data subject.
If you believe we have not adequately addressed your request, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction.
Our Site and services are not directed to individuals under the age of sixteen. We do not knowingly collect, solicit, or process personal information from children. Our client engagements, which span enterprise infrastructure, cloud architecture, cybersecurity, and automation, are inherently oriented toward organizations and business professionals — not minors.
If we become aware that a child under sixteen has provided us with personal information without verifiable parental consent, we will promptly delete that data from our active systems, backup archives, and any subprocessor environments. If you are a parent or guardian and believe your child has submitted personal information to us, please contact us immediately using the details provided in Section 10 so that we may take corrective action.
We have implemented age-verification prompts in areas of the Site where data submission occurs, and our automated collection mechanisms are configured to minimize the likelihood of inadvertently capturing data associated with minors.
We periodically review and update this Privacy Policy to reflect changes in our data processing practices, regulatory requirements, and the evolving threat landscape. When material changes are made, we will update the Effective Date at the top of this document and post a prominent notice on the Site at least thirty days before the change takes effect.
For substantive updates — such as new categories of data collection, new processing purposes, or changes to the parties with whom data is shared — we will also notify active clients and registered users via the email address we have on file. Continued use of the Site or our services after the effective date of a revised policy constitutes acknowledgment of the updated terms.
We maintain an archived version of each prior iteration of this Privacy Policy. Upon request, we will provide a copy of the version that was in effect at the time of a specific data collection event. This ensures transparency and enables you to understand how your data has been governed throughout the relationship.
If a regulatory change or enforcement action requires us to update this policy on an accelerated timeline, we will post the revised version as soon as practicable and indicate the reason for the expedited update.
Questions, concerns, or requests related to this Privacy Policy or our data handling practices should be directed to the following contacts. Our Data Protection team is available during business hours, US Central Time, and aims to acknowledge all inquiries within one business day.
TFG UPPER HOLDINGS INC.
Attn: Data Protection Officer
234 W Florida St, Milwaukee, WI 53204-1659
United States
Email: team@tfgrise.mom
Phone: +1 (326) 266-2209
Website: www.tfgrise.mom
For data subjects in the European Economic Area, you may also contact our EU Representative or lodge a complaint with the supervisory authority in your Member State of residence. For California residents, inquiries related to the California Consumer Privacy Act may be directed to the email and postal addresses above with the subject line CCPA Request. For clients subject to sectoral regulations — such as HIPAA, GLBA, or PCI DSS — supplementary data handling addenda are available upon request as part of the engagement contracting process.
Developer identity: This Site and its supporting infrastructure were developed and are maintained by TFG Rise, a service identity of TFG UPPER HOLDINGS INC. All data processing activities conducted under the TFG Rise identity are governed by this same Privacy Policy.