1. Scope, Entities, & Data Controllers
This Global Privacy Policy governs all data processing activities conducted by Harbour One, Inc.(hereinafter referred to as “Harbour One,” “we,” “our,” or “us”), a Delaware corporation, acting as the primary Data Controller. This policy applies to all registered partners, applicants, and client accounts accessing the Harbour One invite-only transactional ecosystem, available via our desktop and mobile web applications (collectively, the “Platform”).
By accessing our secure storefront editor, executing deposits into the Harbour One Escrow Engine, or utilizing our virtual advisory features, you consent to the collection, cryptographic storage, processing, and purging of your information in strict alignment with this policy.
2. Detailed Categories of Information We Collect
To maintain the integrity of our high-ticket consulting and advisory network, Harbour One collects specific categories of personal, professional, and operational data:
2.1 Information Provided Directly by You
- Enterprise Profile Data: Legal name, authenticated corporate email, secure passwords, profile photography, geographical location coordinates, and billing addresses.
- Verified Professional Credentials: Social media handles and OAuth tokens (LinkedIn, Twitter/X, Instagram), employment history, past consultancy records, corporate entity listings, and verification proofs.
- Advisory Intake Briefs: Details regarding your technical systems, codebases, architectural designs, financial structures, and target deliverables uploaded during booking checkout.
2.2 System & Telemetry Data
- Cryptographic Session Data: IP addresses, browser agents, system hardware configurations, unique device IDs, and secure session tokens.
- Interaction & Audit Logs: Timestamped logs detailing navigation sequences, chat engagement frequencies, storefront view counts, profile edits, and API request records.
3. Escrow Ledger, Payments, & Anti-Money Laundering (AML) Data
Every transaction routed through the Harbour One Escrow Engine requires strict compliance with international banking regulations, Know Your Customer (KYC) mandates, and Anti-Money Laundering (AML) directives:
- Identity & Regulatory Vetting: For Creators and high-net-worth Clients, we collect official government identification, tax documentation (W-9 or W-8BEN certifications), and legal corporate filings. This data is handled by our third-party identity partners using military-grade security.
- Ledger & Payment Tracking: We log transaction amounts, deposit timestamps, bank routing strings, and credit card validation hashes. We do not store raw primary account numbers (PANs) on our servers; card details are tokenized and processed by our PCI-DSS Level 1 compliant gateway partners (including Stripe).
- Dispute & Moderation Files: If a party flags a transaction in the Resolution Center, we collect evidence files, task logs, brief specifications, and chat transcripts for review by our arbitration panel.
4. Zero-Trust Storage & The 30-Day Automated Asset Purge
We recognize that advisory briefs often contain sensitive intellectual property, including proprietary source code, systems design diagrams, and corporate pitch decks:
Cryptographic Asset Shredding Protocol
Any project briefs, system diagrams, financial projection spreadsheets, or code assets uploaded by Clients to the Harbour One Escrow Engine are encrypted at rest using AES-256.
Hard 30-Day Retention Limit: Exactly thirty (30) calendar days after the session has been marked as Completed and escrow funds have cleared, our Platform automated data shredder permanently and irrevocably deletes all uploaded briefing attachments from our active databases and backup files. It is the sole responsibility of both Clients and Creators to download copies prior to this window.
5. Legal Basis & Specific Processing Purposes
We process your data based on contract execution, compliance with regulatory obligations, and our legitimate business interests:
| Data Category | Specific Purpose | Legal Basis |
|---|---|---|
| Account & KYC Profiles | Verify user identity, validate credentials, calculate trust metrics, and prevent fraud. | Contract, Legal Obligation |
| Escrow Ledger Logs | Record transactions, hold deposits, clear payouts, and verify regulatory audits. | Contract, Legal Obligation |
| Secure Chat Logs | Provide real-time messaging, review fulfillment criteria, and resolve platform disputes. | Contract, Legitimate Interest |
| Platform Telemetry | Monitor database loads, diagnose latency, prevent security attacks, and optimize storefront speeds. | Legitimate Interest |
6. Information Sharing & Third-Party Disclosures
Harbour One does not sell or rent data. Information is shared strictly under these conditions:
- Transaction Partner Transmissions: When a Client submits a request, their legal profile name, verified trust metrics, and advisory brief details are shared with the Creator. Upon escrow confirmation, mutual scheduling and contact details are exchanged.
- Subcontractors & Service Providers: We share limited parameters with banking networks, ID validation APIs, analytics providers, email communication channels, and secure hosting facilities (Amazon Web Services).
- Platform Arbitration Panels: In the event of a dispute, relevant evidence, brief descriptions, and chat logs are disclosed to our internal resolution moderation panel to settle escrow funds distribution.
- Legal Requirements: We disclose data to government authorities if required by law or a valid subpoena.
7. International Data Transfers & EU-US Frameworks
Harbour One operates globally. Your data is stored on secure servers located in the United States. If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, your data is transferred using Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent data protection.
8. Cybersecurity Measures & Server Specifications
We employ advanced cybersecurity frameworks to protect the Platform's operations:
- Data Transit Protection: All API requests, admin connections, and user traffic are encrypted in transit using Transport Layer Security (TLS 1.3).
- Server Architecture Security: Web servers operate inside isolated Virtual Private Clouds (VPCs) with strict firewall rules and DDoS protection.
- Access Controls: System access is restricted to verified personnel using multi-factor authentication (MFA) and audited security keys.
9. GDPR, CCPA & Data Subject Rights
Regardless of your residency, Harbour One offers comprehensive controls over your information:
- Right to Access & Portability: You can download a structured copy of your active profile records and transaction histories.
- Right to Correction & Deletion: You can update your profile details or request deletion of your account. Please note that regulatory financial logs, tax certificates, and escrow transaction histories are legally exempt from deletion requests.
- Right to Opt-Out: You can manage notification settings and opt-out of marketing communications.
10. Contact Our Data Protection Officer (DPO) & Legal Counsel
If you have questions about this Privacy Policy, wish to file a data access request, or have concerns about data security, please contact our Data Protection Officer:
Harbour One Legal & Compliance Dept.
Email: legal@harbourone.club
Address: Harbour One Inc., Attn: Privacy Officer, 1209 North Orange Street, Wilmington, DE 19801