Client Security and Privacy Policy
Effective date: January 2025
Introduction
At Golden Tree Wealth Partners, dba Golden Tree Tax & Accounting and Golden Tree Capital Architecture™, we are committed to safeguarding the privacy and confidentiality of our clients' personal and financial information. This Client Security and Privacy Policy outlines the measures we take to protect your data, as well as your rights in relation to the information we collect, store, and process. Our policies and procedures are designed to follow recognized best practices in information security, including principles found in the Cybersecurity Maturity Model Certification (CMMC).
Information we collect
We collect various types of information necessary to provide you with high-quality financial consulting, tax preparation, bookkeeping, payroll services, and other advisory services, including:
- Personal identification details (e.g., name, address, email, phone number)
- Financial and tax-related information (e.g., tax returns, accounting records, financial statements)
- Payment information for billing and subscriptions
- Other business and personal data necessary to provide our services
How we use your information
We use the information we collect to:
- Provide the services you have requested, including financial consulting, tax advisory, bookkeeping, and payroll services
- Communicate with you about your account or services
- Process payments and subscriptions
- Ensure compliance with applicable legal, regulatory, and professional requirements
- Improve the services we provide to you
How we protect your information
Golden Tree Wealth Partners takes reasonable administrative, technical, and physical measures to protect your data from unauthorized access, disclosure, alteration, and destruction. Our practices draw on recognized information security frameworks, including the Cybersecurity Maturity Model Certification (CMMC), and include the following:
- Multi-factor authentication. We require multi-factor authentication on the systems and accounts we use to store and exchange client information, wherever the provider supports it.
- Encryption. We use reputable software and cloud providers that encrypt data in transit and at rest.
- Secure systems. We rely on business-grade software and cloud services with built-in security protections, and we review our setup periodically for risks.
- Access control. Access to your information is limited to the people working on your engagement, on a least-privilege basis, and is removed when it is no longer needed.
- Ongoing review. We review our security practices periodically and update them as threats and requirements change.
- Team responsibility. Everyone who works on client matters, including independent contractors, is expected to follow our security practices and to report anything suspicious right away.
- Backups. Client files are kept with cloud providers that maintain backups, so information can be recovered after a system failure.
- Devices. Devices used for client work are expected to stay current on software updates and to run security protection.
- Secure exchange. We use secure portals or encrypted methods to exchange sensitive documents, and we avoid sending sensitive information by regular email.
- Incident response. If a security incident affects your information, we will investigate it, contain it, and notify you as required by law.
Confidentiality and data sharing
We do not share your personal or financial information with third parties except in the following circumstances:
- With your consent or at your request
- As necessary to perform our services (e.g., third-party processors for payment processing or software providers)
- To comply with legal obligations, such as tax reporting or regulatory requirements
- To protect our rights, property, or the safety of our clients, employees, or others
Data retention
We retain your personal and financial information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. When data is no longer needed, we securely dispose of it in accordance with our data retention policy.
Client rights
As a client, you have the right to:
- Access the personal and financial information we hold about you
- Request corrections to any inaccurate or incomplete information
- Request the deletion of your data, subject to legal and contractual limitations
- Withdraw consent for certain uses of your data (where applicable)
- Object to or request restriction of the processing of your data
To exercise these rights, please contact us using the details provided below.
This website
This website does not use forms, accounts, or advertising trackers. If you email or call us, we receive only what you choose to share. If you book a call, scheduling is handled by Calendly under its own privacy policy. Fonts are served by Google Fonts and the site is hosted by our web host; like any website, these providers may receive standard technical information such as your IP address and browser type when pages load.
Changes to this policy
We may update this Client Security and Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. We will notify you of any material changes through appropriate channels, such as email or our website.
Contact us
If you have any questions or concerns regarding this policy or your privacy rights, please contact us at:
Golden Tree Wealth Partners
dba Golden Tree Tax & Accounting and Golden Tree Capital Architecture™
info@goldentreewealth.com
(847) 409-0326