Institutional Privacy Mandate
Last Updated: March 14, 2024 • Version 2.1 (US-Compliance)
1. Executive Summary
Eldenhall Research LLC ("The Institution") operates under a strict mandate of confidentiality, aligned with the operational standards required by US banking and academic institutions. We acknowledge that the data entrusted to us—including unpublished manuscripts, proprietary datasets, and personal identification—constitutes sensitive intellectual property. This Privacy Policy details the rigorous protocols we employ to secure this data.
2. Data Encryption & Financial Security
GLBA & Financial Compliance
In compliance with the Gramm-Leach-Bliley Act (GLBA) regarding the protection of non-public personal information, all financial transactions are processed via Stripe's Level 1 PCI-DSS certified infrastructure. Eldenhall Research LLC does not store, process, or transmit credit card numbers on its own servers.
Encryption Standards
All data in transit is encrypted via TLS 1.3 (Transport Layer Security). Data at rest within our internal databases (Firebase/GCP) is protected by AES-256 encryption.
3. Information Collection & Usage
The Institution collects specific data points necessary to execute the service agreement:
- Academic IP: Manuscripts, thesis drafts, and grant proposals. These are used strictly for editorial purposes and are never shared with third parties or used to train generative AI models.
- Institutional Metadata: University affiliation, department codes, and research funding IDs (required for invoicing).
- Communication Logs: Enquiries submitted via our secure portal are logged for compliance and audit trails.
4. Data Retention & Destruction
To minimize liability and risk exposure:
- Active Project Data is retained only for the duration of the editorial process.
- A 30-day "Grace Period" follows project completion for revision requests.
- After the Grace Period, all research manuscripts are moved to cold storage or permanently purged from active servers, pursuant to our Data Minimization Policy.
5. Non-Disclosure Agreement (NDA)
This Privacy Policy serves as a binding Institutional Non-Disclosure Agreement. The Institution guarantees that no client identity, research topic, or data point will be disclosed to publishers, peer reviewers, or competing research groups without the express written consent of the Client.
6. Compliance Office Contact
For legal inquiries, data deletion requests, or formal compliance audits, please contact:
Data Controller
Eldenhall Research LLC
117 South Lexington Street Ste 100
Harrisonville, MO 64701, USA
Secure Email: legal@eldenhallresearch.com