What we collect, and what we do with it.
Written in plain sentences because the people reading it are family office controllers and their counsel. Where a legal term is needed, it is explained.
Who we are
ParetoAlpha, Inc. (“ParetoAlpha”, “we”) operates paretoalphasystems.com and the client portal at the same domain. We are the controller of the personal information described here. Questions go to info@paretoalphasystems.com.
Two different things: the website and the book
The public website collects a small amount of information about visitors and about people who ask to be contacted. The client portal, available only to families we have onboarded, holds financial information about that family (“the book”). The book is governed by the pilot order form and NDA signed before onboarding, which take precedence over this policy where they differ. This policy describes both, and says which is which.
What the website collects
When you fill in a form. Name, work email, firm, your role, the assets-under-advisement band you choose (or “prefer not to say”), and the question or message you write. If you arrive from a link with campaign parameters, we record the source, medium and campaign, the page you landed on, and the site that referred you. If you are part of a page test, we record which version you saw. We use this to reply to you, to run the question you asked, and to understand which pages and channels bring the families we can help. We process this data based on our legitimate business interest in responding to inquiries and serving relevant family offices.
When you use the sample book. Questions typed into the public demo run against fictional data. We keep the text of the question, how it was answered, and any rating you give, without any account data, so we can see which questions families ask that no framework answers well yet. If you choose “send me this run” we keep your email alongside it.
When you seal a 990-PF. What you type in the filer field is matched against a directory of foundations held on our own server; no third party is asked anything, and the text is not written to our logs. The nine-digit EIN of the foundation you choose is used to read that foundation’s e-filed return from the IRS’s public files; the EIN is sent in the request body, not in a URL, and is not written to our logs. The return is re-done and the result is written to our ledger under its fingerprint. The proof holds figures from the public return and nothing about you. To limit bursts, the address a request comes from is kept as a counter, apart from any EIN, and counters older than two days are swept. Analytics records that a proof was sealed, refused or failed, never which foundation.
A sealed proof page. The page is not listed on this site and asks search engines not to index it; it is reached by its link, which whoever asked for it holds. It is indexed only if an officer or trustee named in the return asks us in writing. When a proof is opened through its short link or checked, we count the open by the kind of visitor (a browser, a script, a link scanner, a preview bot) and the proof’s public code; no address, cookie or identifier is kept. The share button uses your device’s share sheet or copies the link; we record that a link was shared and how, not to whom.
Analytics. We use Vercel Web Analytics, which counts page views and events without cookies and without storing IP addresses or building profiles across sites. We do not use Google Analytics, advertising pixels or session recording.
Cookies. Three first-party cookies: pa_attr (which link brought you here; 90 days), pa_exp (which version of a page you saw, so it stays consistent; 90 days), and, if you sign in to the portal, a session cookie. No third-party cookies. You can block cookies in your browser; the site works without them.
What the portal collects
Once a family is onboarded: the entity list, account positions and balances delivered read-only through Plaid, a custodian, or an adviser’s reporting platform, the documents that carry deadlines, the few figures from the investment policy statement, and the questions asked of the book. Portal users are identified through a managed identity provider (Amazon Cognito). Every query is scoped to one family by row-level security in the database; a query without that family’s claim returns nothing. We process portal data under the contractual necessity of performing our agreement with your family office.
Who processes it for us
Vercel (website hosting, analytics), Neon (the website and portal database), Amazon Web Services (platform database, identity, compute, model hosting; hosted strictly in U.S. data centers), Stripe (billing; card details never touch our systems), Plaid (read-only account connections, only if you choose that path), HubSpot (our record of who asked to be contacted and what we said), Anthropic (the language model that turns a typed question into a computation and drafts the concierge’s replies; it receives the question and the computed rows it needs to answer it, and nothing it receives is used to train models), and our email and calendar providers. Each acts on our instructions under a written agreement. We do not “sell” or “share” personal information under California law (CPRA) or other privacy statutes, and we do not share data with advertisers.
How long
Website enquiries: until you ask us to delete them, or three years after the last contact. Demo questions: three years, without identifiers unless you gave an email. A sealed proof: written once and kept; it holds no information about the visitor who asked for it. An export you send before signing (for a first question): used only to answer that question, and deleted when you ask or within thirty days if you do not continue, by a person who confirms the deletion to you by email. Portal data: for the term of the agreement and ninety days after, then deleted, with automated encrypted backups expiring on their own schedule within a further thirty to ninety days. Where law requires a longer retention, we keep only what it requires.
Your rights
Wherever you are, you can ask what we hold about you, ask for it to be corrected or deleted, ask us to stop contacting you, and receive a copy in a usable format. Residents of the European Economic Area, the United Kingdom, California and other jurisdictions with privacy statutes have these rights by law; we extend them to everyone. Email info@paretoalphasystems.com; we answer within thirty days. We do not discriminate against anyone for exercising them.
Security
Described in detail on the security page. In short: encryption in transit (TLS 1.2 or higher, TLS 1.3 where supported) and at rest (AES-256), secrets held in a secrets manager, databases not reachable from the internet, per-user roles, row-level security, and an approval queue for any action the system prepares.
Children
The website and portal are for professionals and adults. We do not knowingly collect information from anyone under eighteen.
Changes
When this policy changes, the effective date at the top changes with it, and onboarded families are told by email before the change applies to them.