OneBridge
Home

Privacy Policy

Effective date (Version 2.2): September 9, 2026

Introduction

This Privacy Policy explains how Onebridge handles personal data in the authenticated environment available at https://app.onebridgestalwart.com and in other authenticated environments identified as part of the same service (the "Platform"). It covers registration, organizations, members, documents, forms, journeys, tasks, service requests, proposals, billing, payments, notifications, and support. It applies together with the Platform Terms of Service and, for organizations and partners, with the Data Processing Agreement (DPA). Mandatory rights provided under applicable law remain preserved.


1. Who Is Responsible and in What Capacity

The party responsible for the Platform is Onebridge Stalwart LLC, Employer Identification Number (EIN) 39-3814073, with a postal address at 30 N Gould St, Ste N, Sheridan, Wyoming 82801, United States ("Onebridge"). Privacy channel: hello@onebridgestalwart.com, subject line "Privacy".

Onebridge's role depends on the situation:

SituationOnebridge's RoleConsequence
Accounts, authentication, permissions, security logs, billing, support, fraud prevention, and compliance with legal obligationsControllerOnebridge defines the purposes and responds directly to data subjects
Consulting and coordination services contracted by you (an individual) or your organization — including the review of documents and forms to prepare structures, proposals, filings, and deliverablesController (independently or jointly with the organization, as set out in the DPA)Onebridge applies professional judgment to the data and answers for its own processing decisions
The organization's use of the Platform as its own repository (documents, tasks, and data the organization manages without Onebridge's intervention)Processor, under the instructions documented in the DPAThe organization is the controller and answers to its own data subjects; Onebridge provides support
Licensed professional partners (attorneys, accountants, registered agents, financial institutions) performing acts reserved to their professionPartner = independent controllerThe partner follows its own professional and privacy rules
Commercial partners who offer Onebridge's services to their own clients (white label)Partner = controller; Onebridge = processor or joint controller, as defined in the DPADefined case by case in the DPA

When it is unclear who should respond to a request, Onebridge will inform the data subject and forward the request to the responsible party, cooperating to ensure a response within the legal deadline.


2. Individuals Whose Data May Be Processed

Account holders; organization administrators and members; clients and their representatives; owners, officers, and ultimate beneficial owners of companies; spouses, dependents, and other family members; employees and contractors of organizations; partners; and other individuals whose information appears in documents or forms required for a service (for example, counterparties to a contract).


3. Account and Access Data

Name, email, phone number, language, profile picture, and other registration data; credentials protected by a managed authentication service, with passwords stored only as a cryptographic hash and multi-factor authentication for administrators; account, session, and authentication identifiers; the organizations you belong to, your role, permissions, invitations, and access history; IP address, device, browser, date and time, security events, and activity logs; preferences, notifications, and communications with support.


4. Organization and Service Data

Depending on the features used and the service contracted, the Platform may process:

  • name, industry, city, status, logo, corporate structure, and data on representatives, members, and ultimate beneficial owners;
  • service requests, proposals, amounts, currency, billing status, invoices, receipts, and payment references;
  • form responses about the person, family, company, transaction, assets, and tax, accounting, or immigration situation, filled in manually or with the help of automations;
  • documents submitted, produced, or shared: identity and travel documents, corporate, banking, tax, accounting, immigration, family (e.g., certificates), and supporting documents;
  • journeys, tasks, owners, deadlines, steps, approvals, deliverables, and execution history;
  • messages, notifications, support files, and issue records.

Sensitive data. Some services require information that the law of your country classifies as sensitive or as a special category — for example, immigration or citizenship status, official document numbers, financial and account data, health data, ethnic origin or religion when they appear in official documents, and criminal records when required by authorities. We process this data only when necessary for the requested service, with restricted access, no use for advertising, and on the legal basis provided by applicable law, including specific consent where required. You should submit sensitive data only through the fields and flows indicated for that purpose.


5. Payment Data

The Platform displays prices, status, invoices, and transaction references. Payments may be made by bank transfer, ACH, wire transfer, Zelle, or card, depending on the options presented at the time of contracting. Electronic payments are processed by specialized providers identified in the payment flow. Onebridge does not store full card numbers or security codes. Onebridge processes only what is necessary to reconcile payments, issue documents, prevent fraud, and comply with tax obligations.


6. Sources of Data

You; administrators and members of your organization; documents and forms submitted; partners involved in the service; authentication, payment, and signature providers; public sources and official records, where the inquiry is permitted and necessary; authorities, in the course of a service.


7. Purposes and Legal Bases

We process personal data for the following purposes, on a legal basis subject to applicable law:

PurposePrimary Legal Basis (Subject to Applicable Law)
Create accounts, authenticate users, administer permissions, and keep the Platform securePerformance of the contract; legitimate interest (security); legal obligation
Register organizations, receive documents and forms, support form completion through automations, organize journeys and tasks, and deliver the contracted servicesPre-contractual steps and performance of the contract
Process requests, proposals, billing, payments, invoices, refunds, and tax obligationsPerformance of the contract; legal obligation
Coordinate the partners and licensed professionals required for the contracted scopePerformance of the contract; legitimate exercise of rights; specific consent where the law requires it (sensitive data in certain territories)
Provide support, send operational notifications, and maintain an auditable historyPerformance of the contract; legitimate interest
Prevent fraud, investigate incidents, enforce the Terms, and protect rightsLegitimate interest; legal obligation; legitimate exercise of rights
Improve the Platform using aggregated or anonymized usage metricsLegitimate interest, with a right to object
Comply with laws, regulations, orders from authorities, and record-keeping dutiesLegal obligation
Communications about new services to clientsLegitimate interest with opt-out (or opt-in, where required)

Sensitive data is processed only under the grounds admitted by the law applicable to the case — generally, compliance with a legal or regulatory obligation, the legitimate exercise of rights in administrative or judicial proceedings (including filings with authorities), or your specific and prominently requested consent. We do not process sensitive data for fraud prevention, except for identity verification required by law.

Artificial intelligence and automations. The Platform may use rule-based automations, with and without artificial intelligence, mainly to support form completion. These features may organize submitted information, suggest entries, identify incomplete fields, and run consistency checks. Suggestions may contain errors and must be confirmed before submission. Onebridge will not use these automations to make, without human review, decisions that produce legal effects or similarly significant impact on a person. Only contracted providers identified on the Subprocessors page may receive the fields and documents strictly necessary for the task. Contracts must prohibit the use of client data, files, prompts, and outputs to train general or shared models. The provider must delete processed content within 30 days, except for a shorter retention period or a limited technical record required for security. The country of processing and the specific retention period for each provider will be listed on the Subprocessors page. Until these conditions are documented, AI features that process personal data will remain disabled.


8. Children and Teenagers

Accounts are intended for adults and authorized organization representatives. Data about children and teenagers may appear in documents and forms when necessary for a legitimate service (for example, dependents in an immigration or succession process). Whoever provides such data represents that they have the authority to do so. We process this data only for the purpose of the service, with restricted access, no profiling, no advertising, and in the best interest of the minor; in Brazil, we observe LGPD article 14 and ANPD guidance; in the United States, we do not knowingly collect data online directly from children under 13.


9. Who We Share Data With

We share personal data only to the extent necessary, with the following categories of recipients:

  • administrators and authorized members of the organization the data relates to, according to the permissions assigned;
  • providers (subprocessors) of cloud, database, storage, authentication, security, communication, e-signature, support, analytics, and payment services, under contract and instructions — the list, with name, purpose, and country of processing, will be available at https://onebridgestalwart.com/subprocessadores; material changes will be communicated 30 days in advance, except where urgently required for security, continuity, or legal compliance;
  • licensed professional partners involved in the service — before any data is sent, we will disclose the partner's name and the country where they operate; they process data as independent controllers;
  • registries, immigration, tax, regulatory, judicial, or administrative authorities, when necessary for the service and authorized by you or by law;
  • auditors, advisors, and potential successors in a corporate transaction, under confidentiality;
  • third parties you designate or expressly authorize (we keep a record of the authorization).

Sale and advertising. Onebridge does not sell Platform personal data, does not receive payment for it, and does not use or share it for third-party behavioral advertising.


10. International Transfers

Platform data is stored in the United States, preferably in a cloud region located on the U.S. East Coast, and is accessed from the United States and from Brazil. Providers may process data in other countries only when identified on the Subprocessors page and subject to applicable contractual safeguards. Documents may be forwarded to professional partners in the country where the service will be performed, always with notice of the recipient and in compliance with the applicable transfer mechanism.

The transfer occurs through cloud storage, remote access, and document delivery, for the period indicated in Section 11 and for the purposes in Section 7. Before a transfer requiring specific safeguards, we will adopt the mechanism required by applicable law and technical and organizational measures proportionate to the risk. You may request information about the mechanism used through the privacy channel.


11. Retention and Deletion

We retain data for the following periods, depending on the category:

CategoryPeriodCriterion
Account and profile dataFor as long as the account exists, plus 30 days after closure for exportAfter that period, deletion, unless legally required to retain
Access logs (IP, date, time)6 monthsMarco Civil da Internet, art. 15
Security and audit logs of actions on the Platform12 monthsIncident investigation
Service documents and formsFor the duration of the service and for 5 years after the case is closed, unless deletion is requested earlier or the controlling organization instructs otherwiseNeeded for updates, renewals, and defense of rights; you may request a full copy at any time
Contracts, accepted proposals, invoices, receipts, and tax records7 years after the contract ends, payment is made, or the applicable fiscal year closes, whichever is latest, or for a longer period required by lawLegal obligation and exercise of rights
Customer service records5 years after the service request is closed, unless a different statutory period applies to the caseLimitation periods in consumer relations
Records of acceptance of terms and consentsFor the duration of the relationship and for 5 years after it ends, or for the longer applicable limitation periodEvidence
Communications with support3 years after the ticket or account is closed, whichever is laterService history
Backup copiesUp to 90 days after the active data is deletedBackup cycle

When closing an account or organization, the organization's administrator or the holder of an individual account may request, through hello@onebridgestalwart.com, the export of data and documents for 30 days. The export will be provided in a common electronic format, such as PDF, CSV, or ZIP file, depending on the type of content. After that period, we will delete or anonymize what does not need to be retained by law, litigation, an authority's order, or a valid instruction from the controlling organization. Onebridge may retain copies of the deliverables it produced, for accountability purposes, for the periods above.


12. Security and Shared Responsibilities

We adopt technical and administrative measures proportionate to the risks, including encryption in transit, encryption at rest where offered by the infrastructure provider, multi-factor authentication for administrators, role- and need-based access controls, security logs, backups, vendor review, and an incident response plan. Onebridge reviews privileged access at least quarterly and revokes access when it is no longer needed. You must protect your credentials, use secure devices, keep data up to date, not share accounts, and immediately report any suspicion of unauthorized access. Administrators are responsible for invitations, roles, and offboarding, and must grant only the access that is necessary.

No system is completely secure. In the event of an incident that could cause significant risk, we will investigate, mitigate, and notify affected individuals, the controlling organization, and the competent authority within the deadlines required by applicable law and by contract.


13. Your Rights

You may exercise, in accordance with applicable law, the rights of confirmation, access, correction, anonymization, blocking, deletion, portability, information about sharing, objection, withdrawal of consent, and review of automated decisions. Basic profile data, language, preferences, and notifications can be corrected directly in your account where that function is available.

How to request. Send your request to hello@onebridgestalwart.com with the subject line "Privacy". We may ask for reasonable and proportionate information to confirm your identity, such as responding from your registered email or confirming information only you would know, without requiring more documentation than necessary. A representative may make a request on your behalf with written authorization.

Deadlines. We respond within 15 days (Brazil), 1 month (EEA and United Kingdom, extendable by a further 2 months in complex cases, with notice), or 45 days (U.S. states, extendable by a further 45 days with notice), counted from receipt of the complete request. Handling requests is free of charge, except for manifestly repetitive or unfounded requests. If we refuse a request in whole or in part, we will explain why and how to appeal.

Appeal and complaint. You may request a review of our response through the same channel, marking the subject line "Appeal". You may also file a complaint with the data protection authority competent for your country.

When data was entered by an organization acting as controller, and Onebridge is only a processor, we will inform you and forward the request to the organization, cooperating with the response.


14. Mandatory Local Rules

This Policy constitutes the common core of the Platform's privacy practices. Onebridge will respect the mandatory rights of the data subject's country and will publish supplementary notices before beginning activities subject to additional local requirements.


15. Updates and Contact

We may update this Policy; the current version and prior versions will remain available on the Platform. Changes that expand purposes or recipients will be communicated on the Platform and by email with reasonable advance notice, as required by applicable law. Contact: Onebridge Stalwart LLC — EIN 39-3814073 — 30 N Gould St, Ste N, Sheridan, Wyoming 82801, United States — hello@onebridgestalwart.com.


16. Automated Decisions

Automated decisions. The automations described in Section 7 are designed to support the completion and review of forms. They will not be used, without human review, to accept or decline clients, set prices, assess eligibility, or produce other legal effects or similarly significant impacts. When an automation flags an inconsistency, risk, or need for correction, the relevant review will be carried out by a person. You may request human review through hello@onebridgestalwart.com.