TFG UPPER HOLDINGS INC.

Privacy Policy

Effective Date: January 1, 2026

1. Introduction

TFG UPPER HOLDINGS INC. (hereinafter referred to as we, our, or the Company), a Computer Systems Design and Related Services firm headquartered at 234 W Florida St, Milwaukee, WI 53204-1659, United States, takes the privacy of individuals who interact with our digital properties and services seriously. This Privacy Policy explains how we collect, use, disclose, retain, and secure personal information gathered through our website at tfgrise.mom (the Site), our client engagement platforms, and any service delivered under the developer identity TFG Rise.

By accessing the Site or engaging with our services, you acknowledge that you have read, understood, and agreed to the practices described in this document. If you reside in a jurisdiction with enhanced data protection requirements, additional provisions set forth in Sections 6 and 7 apply to you.

Our operations span global technology infrastructure, cybersecurity, data engineering, cloud architecture, and intelligent automation — all fields where data integrity is a foundational commitment, not merely a compliance checkbox. This policy reflects the operational standards we maintain across every engagement.

We are headquartered in Milwaukee, Wisconsin, and our data processing activities are governed by applicable United States federal and state privacy statutes, as well as the standards we voluntarily adopt to meet the expectations of international clients and partners.

2. Information We Collect

We gather information through direct input, automated collection technologies, and third-party sources. Each category serves a defined operational purpose and is handled in accordance with the protections described in Section 5.

2.1 Information You Provide Directly

  • Contact and identity data — Full name, work email address, company name, job title, and phone number when you submit an inquiry through our contact form, request a consultation, or engage via direct correspondence.
  • Project requirement data — Technical specifications, infrastructure descriptions, security posture details, and business objectives you share during scoping discussions, RFPs, or service onboarding.
  • Account credentials — If we provision you with access to any client portal or collaboration platform, we collect and store the minimum authentication data required to maintain secure access.
  • Communication records — Email threads, support tickets, meeting notes, and the content of any correspondence you initiate with our team.

2.2 Information Collected Automatically

  • Device and browser metadata — IP address, browser type and version, operating system, screen resolution, language preferences, and device identifiers.
  • Usage data — Pages visited, time spent on each page, referral sources, click patterns, scroll behavior, and interaction events that help us understand how our Site is navigated.
  • Server logs — Timestamps, request paths, response codes, and transfer sizes logged by our web infrastructure for security monitoring and performance analysis.
  • Cookies and similar technologies — Small data files stored on your device that facilitate session management, preference retention, and aggregated analytics. You may manage cookie preferences through your browser settings, though disabling essential cookies may affect Site functionality.

2.3 Information from Third Parties

  • Business partners and referral networks — When a trusted partner refers you to our services, we may receive basic contact information and a summary of relevant requirements.
  • Publicly available sources — Professional profiles, company registries, and industry databases used to contextualize prospective engagements.
  • Service providers — Hosting, analytics, and security vendors that supply de-identified or aggregated insights derived from their own platform data.

3. How We Use Your Information

Every data processing activity we undertake is tied to a specific, documented purpose. We do not repurpose personal information for unrelated secondary uses without additional notice.

3.1 Core Service Delivery

  • Responding to inquiries, providing proposals, and delivering the consulting, architecture, infrastructure, and automation services we are engaged to perform.
  • Managing client accounts, invoicing, and contractual obligations.
  • Facilitating secure communication between our engineering teams and client stakeholders.

3.2 Site Operations and Improvement

  • Monitoring Site performance, diagnosing technical issues, and maintaining system integrity.
  • Analyzing aggregated usage patterns to improve content structure, navigation, and accessibility.
  • Testing and deploying security patches, infrastructure upgrades, and performance optimizations.

3.3 Security and Compliance

  • Detecting, preventing, and investigating fraudulent activity, unauthorized access, or infrastructure abuse.
  • Complying with legal obligations, court orders, regulatory requests, and industry standards.
  • Enforcing our Terms of Service and other contractual agreements.

3.4 Business Communications

  • Sending service-related announcements, policy updates, and account notifications.
  • Sharing relevant thought leadership, case studies, or capability updates — only with your prior consent and always with an opt-out mechanism.

We rely on the following legal bases for processing: contractual necessity for service delivery, legitimate interest for Site operations and security, consent for marketing communications, and legal obligation for compliance activities.

4. How We Share Your Information

We are not in the business of selling personal information. Data sharing is limited to the operational and legal contexts described below.

4.1 Service Providers and Subprocessors

  • Infrastructure providers — Cloud hosting, content delivery, and DNS service vendors that store and serve our digital assets. These providers are bound by data processing agreements that mandate confidentiality, security, and restricted use.
  • Analytics platforms — Aggregated usage insights are generated through tools that process anonymized interaction data. No personally identifiable information is shared with analytics vendors for their independent use.
  • Communication tools — Email delivery services, scheduling platforms, and collaboration software that facilitate our operational workflows.

4.2 Legal and Regulatory Disclosure

  • In response to a valid subpoena, court order, or government request that compels disclosure by applicable law.
  • To protect the rights, property, or safety of TFG UPPER HOLDINGS INC., our clients, employees, or the public, as permitted by law.
  • During merger, acquisition, or asset sale negotiations, subject to confidentiality agreements and data protection obligations.

4.3 With Your Consent

In any scenario not covered above, we will seek your explicit consent before sharing personal information with external parties.

5. Data Retention and Security

The integrity and resilience of the data under our stewardship is a non-negotiable engineering priority. We apply the same discipline to our own data environment that we architect for clients.

5.1 Retention Schedules

Personal information is retained only as long as necessary to fulfill the purposes outlined in Section 3, or as required by applicable law. Contact form submissions and correspondence are retained for the duration of the relevant engagement plus twenty-four months thereafter. Automatically collected Site data is retained for a rolling thirteen-month window before permanent de-identification or deletion. Client account data is deleted within ninety days of a verified account closure request, except where extended retention is mandated by law.

5.2 Technical Security Controls

  • Encryption — All data transmitted between your browser and our servers is protected by TLS 1.3 with strong cipher suites. Data at rest is encrypted using AES-256. Database volumes, backup snapshots, and log archives are all encrypted with distinct key management policies.
  • Network architecture — Our infrastructure operates within a segmented network topology. Public-facing endpoints, application logic, and data storage each reside in isolated network tiers with strict ingress and egress filtering rules enforced at the firewall and security group level.
  • Access control — Access to production systems and personal data stores is governed by role-based access control, enforced through multi-factor authentication, and reviewed quarterly. The principle of least privilege is applied uniformly — no individual or service account has permissions beyond what their function explicitly requires.
  • Vulnerability management — Continuous vulnerability scanning operates across our entire infrastructure surface. Critical patches are applied within forty-eight hours of release, and non-critical patches follow a bi-weekly deployment cadence validated through staging environments.
  • Logging and monitoring — All access events, configuration changes, and anomalous activity patterns are captured in a centralized, tamper-proof audit log. Automated alerting triggers investigation workflows for any deviation from established security baselines.
  • Backup and disaster recovery — Data is replicated across geographically distributed storage clusters with point-in-time recovery capability. Backup integrity is validated through automated restoration testing on a weekly cycle.
  • Endpoint protection — All systems with access to personal data are protected by endpoint detection and response tooling, host-based intrusion detection, and enforced disk encryption.

5.3 Organizational Controls

  • Security training — Every team member at TFG UPPER HOLDINGS INC. completes mandatory data protection and security awareness training during onboarding and on an annual refresher cycle. Training covers phishing recognition, secure coding practices, incident reporting procedures, and data handling protocols.
  • Third-party risk assessment — All service providers and subprocessors undergo a security review before onboarding. We evaluate each vendor against criteria including their security certifications, data handling practices, incident response capability, and breach notification procedures.
  • Incident response — A documented incident response plan is maintained, tested through tabletop exercises semi-annually, and executed by a designated response team. In the event of a confirmed data breach presenting risk of harm, affected individuals and relevant regulatory authorities will be notified within the timeframes prescribed by applicable law.

5.4 Certifications and Audits

Our security posture is validated through independent third-party assessments. We maintain SOC 2 Type II certification and ISO 27001 compliance. Annual penetration tests are conducted by external security firms, and remediation findings are tracked through closure. Our infrastructure platform undergoes continuous compliance monitoring against CIS benchmarks and industry-specific frameworks relevant to our client verticals.

No method of transmission or storage is absolutely secure. While we deploy extensive technical and organizational measures to protect your data, we cannot guarantee security against a determined adversary exploiting an unknown vulnerability. We encourage you to take appropriate precautions on your side — use strong passwords, enable multi-factor authentication on your accounts, and remain vigilant against phishing attempts.

6. International Data Transfers

As a company headquartered in the United States with a global client base spanning twelve regions, personal information may be transferred to, stored in, or processed in countries other than your own. We apply consistent safeguards regardless of where data resides.

For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other jurisdictions, we rely on approved transfer mechanisms including Standard Contractual Clauses and supplementary technical, organizational, and contractual measures as required. For clients and Site visitors in other regions, we assess applicable local law and implement equivalent protections.

Before any cross-border data flow is established, we conduct a transfer impact assessment to identify the legal basis, evaluate the recipient jurisdiction's data protection regime, and document the supplementary safeguards applied. These assessments are reviewed annually and updated when regulatory developments or service architecture changes introduce new transfer scenarios.

7. Your Data Rights

Depending on your jurisdiction, you may exercise the following rights regarding the personal information we hold about you. We respond to all verifiable requests within the timelines prescribed by applicable law — typically thirty days, extendable once for complex requests.

01
Right to Access
Request confirmation of whether we process your personal data and obtain a copy of the data we hold.
02
Right to Rectification
Request correction of inaccurate or incomplete personal information in our systems.
03
Right to Erasure
Request deletion of your personal data where there is no overriding legitimate ground for continued processing.
04
Right to Restrict Processing
Request limitation on how your data is processed while a dispute or verification is in progress.
05
Right to Data Portability
Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
06
Right to Object
Object to processing based on legitimate interests, direct marketing, or profiling activities.
07
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts.
08
Right to Non-Discrimination
Exercising any of your privacy rights will not result in denial of service, different pricing, or degraded quality of service.

To exercise any of these rights, please contact us using the details in Section 10. We will verify your identity before processing any request — typically by confirming information you have previously provided to us. If you are acting as an authorized agent, we will require signed authorization and direct confirmation from the data subject.

If you believe we have not adequately addressed your request, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction.

8. Children's Privacy

Our Site and services are not directed to individuals under the age of sixteen. We do not knowingly collect, solicit, or process personal information from children. Our client engagements, which span enterprise infrastructure, cloud architecture, cybersecurity, and automation, are inherently oriented toward organizations and business professionals — not minors.

If we become aware that a child under sixteen has provided us with personal information without verifiable parental consent, we will promptly delete that data from our active systems, backup archives, and any subprocessor environments. If you are a parent or guardian and believe your child has submitted personal information to us, please contact us immediately using the details provided in Section 10 so that we may take corrective action.

We have implemented age-verification prompts in areas of the Site where data submission occurs, and our automated collection mechanisms are configured to minimize the likelihood of inadvertently capturing data associated with minors.

9. Changes to This Privacy Policy

We periodically review and update this Privacy Policy to reflect changes in our data processing practices, regulatory requirements, and the evolving threat landscape. When material changes are made, we will update the Effective Date at the top of this document and post a prominent notice on the Site at least thirty days before the change takes effect.

For substantive updates — such as new categories of data collection, new processing purposes, or changes to the parties with whom data is shared — we will also notify active clients and registered users via the email address we have on file. Continued use of the Site or our services after the effective date of a revised policy constitutes acknowledgment of the updated terms.

We maintain an archived version of each prior iteration of this Privacy Policy. Upon request, we will provide a copy of the version that was in effect at the time of a specific data collection event. This ensures transparency and enables you to understand how your data has been governed throughout the relationship.

If a regulatory change or enforcement action requires us to update this policy on an accelerated timeline, we will post the revised version as soon as practicable and indicate the reason for the expedited update.

10. Contact Information

Questions, concerns, or requests related to this Privacy Policy or our data handling practices should be directed to the following contacts. Our Data Protection team is available during business hours, US Central Time, and aims to acknowledge all inquiries within one business day.

TFG UPPER HOLDINGS INC.

Attn: Data Protection Officer

234 W Florida St, Milwaukee, WI 53204-1659

United States

Email: team@tfgrise.mom

Phone: +1 (326) 266-2209

Website: www.tfgrise.mom

For data subjects in the European Economic Area, you may also contact our EU Representative or lodge a complaint with the supervisory authority in your Member State of residence. For California residents, inquiries related to the California Consumer Privacy Act may be directed to the email and postal addresses above with the subject line CCPA Request. For clients subject to sectoral regulations — such as HIPAA, GLBA, or PCI DSS — supplementary data handling addenda are available upon request as part of the engagement contracting process.

Developer identity: This Site and its supporting infrastructure were developed and are maintained by TFG Rise, a service identity of TFG UPPER HOLDINGS INC. All data processing activities conducted under the TFG Rise identity are governed by this same Privacy Policy.