For purposes of this Policy, “Company,” “we,” “us,” and “our” refer to the Golden Eagle Golf Club development team and the applicable project entity or entities identified in definitive project documents. This Policy is intended for prospective investors, strategic participants, advisors, and other individuals who interact with the Platform.
Information We Collect
We may collect information you provide directly, including:
- Name, email address, phone number, mailing address, and preferred contact method.
- Professional background, business affiliation, title, investor type, and investment experience.
- Preliminary investor qualification information, including accreditation status, financial sophistication, eligibility category, net worth or income range, entity status, and related representations.
- Areas of interest, desired investment range, timing, project preferences, questions, and communications with the development team.
- Consent records, policy acknowledgments, confidentiality acknowledgments, electronic-communications consent, and form-submission metadata.
- Identity, compliance, tax, anti-money-laundering, know-your-customer, or investor-verification information if requested later through a secure workflow.
We may also collect limited information automatically, including:
- IP address, device type, browser type, operating system, approximate location derived from IP address, referral source, pages viewed, session timing, click activity, and interaction logs.
- Cookie identifiers, analytics identifiers, security logs, and similar technical information used to operate, secure, and improve the Platform.
We do not intentionally collect information from individuals under 18 years old, and the Platform is not directed to minors.
How We Use Information
We use information for the following purposes:
- Inquiry management: to receive, evaluate, route, and respond to investor inquiries.
- Investor qualification: to assess eligibility, accreditation representations, suitability indicators, and verification needs.
- Project communications: to schedule calls, provide requested information, send administrative notices, and share project updates when you request or consent to them.
- Compliance: to support securities-law compliance, investor records, anti-fraud review, anti-money-laundering or know-your-customer procedures where applicable, tax and accounting needs, audit support, and legal obligations.
- Security and fraud prevention: to protect the Platform, detect unauthorized access, maintain logs, prevent misuse, and investigate suspicious activity.
- Operations and analytics: to understand Platform performance, improve inquiry workflows, troubleshoot issues, and measure engagement with project materials.
- Legal rights: to enforce terms, protect confidential information, respond to lawful requests, and establish, exercise, or defend legal claims.
We do not sell personal information to data brokers. We do not use personal information for behavioral advertising unless the Platform is later updated and you are given any notices and choices required by applicable law.
Legal Bases for Processing, Where Applicable
Where a legal basis is required, we process personal information based on one or more of the following: your consent, performance of a requested pre-contractual or contractual process, compliance with legal obligations, legitimate interests in managing investor inquiries and protecting the Platform, and establishment or defense of legal claims.
If you consent to receive project updates, you may withdraw that consent at any time. Withdrawal does not affect prior processing or processing needed for legal, security, compliance, or transactional purposes.
How We Share Information
We may share information with the following categories of recipients:
| Recipient Category | Purpose |
|---|---|
| Project entities and authorized personnel | Inquiry review, project communications, investor qualification, and project administration. |
| Legal counsel | Securities-law review, confidentiality obligations, investor qualification, document preparation, dispute resolution, and compliance. |
| Accountants, auditors, and tax advisors | Financial reporting, audit support, tax compliance, and project administration. |
| Securities administrators, transfer agents, fund administrators, or verification providers | Offering administration, accreditation verification, subscription processing, and investor records if an offering proceeds. |
| Hosting, form, CRM, data-room, email, scheduling, analytics, security, and IT providers | Platform operation, communications, hosting, analytics, cybersecurity, and workflow administration. |
| Government, regulatory, law-enforcement, or court authorities | Compliance with subpoenas, court orders, lawful requests, securities rules, tax requirements, or other legal obligations. |
| Professional advisors you authorize | Coordination with your legal, tax, financial, accounting, or investment advisors at your request. |
| Transaction counterparties | Corporate transactions, restructuring, financing, merger, acquisition, sale, or transfer of all or part of the project or related assets, subject to appropriate protections. |
Service providers are expected to use personal information only for authorized purposes and to maintain appropriate confidentiality and security protections. We will not permit service providers to use inquiry data for their own independent marketing unless separately disclosed and authorized.
Data Processing Agreements and Vendor Assurance
Where required or appropriate, we use written service-provider terms, data-processing agreements, confidentiality obligations, or equivalent contractual protections with vendors that process personal information for the Platform.
We confirm the applicable hosting, form, CRM, analytics, email, scheduling, and data-room providers and retain the supporting vendor security documentation for any public-facing statements about those providers.
Cookies and Analytics
The Platform may use cookies, pixels, local storage, and similar technologies for essential site functionality, security, analytics, and performance measurement. Essential cookies support basic operation and security. Analytics cookies help us understand traffic, pages viewed, referral sources, and interaction patterns.
If an analytics tool such as Google Analytics 4 is enabled, it is configured consistently with this Policy, including appropriate retention settings, restricted data sharing where appropriate, and avoidance of unnecessary personal information in URLs, form fields, or event names. You can manage cookies through your browser settings and may use the Google Analytics opt-out browser add-on if Google Analytics is used.
We do not currently use cookies for third-party behavioral advertising unless separately disclosed. If targeted advertising, sale of personal data, or profiling for legally significant decisions is introduced later, we will update this Policy and provide required opt-out mechanisms.
Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, subject to legal, regulatory, tax, accounting, securities, audit, security, and dispute-resolution requirements. Current retention targets are:
| Record Type | Retention Target |
|---|---|
| Active inquiries | Duration of active discussions plus up to 3 years, unless a longer period is required or justified. |
| Declined or inactive inquiries | Up to 1 year after final action or inactivity, unless needed for compliance, audit, legal, security, or dispute purposes. |
| Investor qualification and offering records | As required by applicable securities, tax, corporate, accounting, AML/KYC, and audit obligations, which may be longer than ordinary inquiry records. |
| Consent and policy acknowledgment records | As long as needed to document consent, notice, confidentiality, and terms acceptance. |
| Security logs | As long as reasonably necessary for security, fraud prevention, investigation, and system integrity. |
| Cookies and analytics identifiers | According to the settings of the applicable tool, generally no longer than needed for analytics, security, and operational purposes. |
Deletion requests may be limited where retention is required or permitted for legal compliance, regulatory records, securities-law obligations, audit trails, security, fraud prevention, dispute resolution, or legal claims.
Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards may include encrypted transmission, access controls, role-based permissions, logging, secure credential practices, vendor due diligence, and restricted access to inquiry data based on business need.
No website, email system, or data transmission method is completely secure. We cannot guarantee absolute security, and you should not submit sensitive information through unsecured channels. If a secure upload, data room, or verification process is provided, you should use that process rather than ordinary email for sensitive documents.
Privacy Rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of certain processing such as targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
Virginia residents covered by the Virginia Consumer Data Protection Act (VCDPA) may submit authenticated requests to exercise applicable rights and may appeal a decision if a request is denied. EU/EEA or UK individuals may have GDPR or UK GDPR rights, including access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.
To exercise privacy rights, contact privacy@goldeneaglegolf.club with “Privacy Request” in the subject line. We may need to verify your identity before responding. We will respond within the time required by applicable law. For Virginia VCDPA requests, this is generally 45 days, with one 45-day extension where reasonably necessary. For GDPR requests, this is generally one month, with up to two additional months where necessary due to complexity or number of requests.
If we deny a Virginia privacy request, we will explain the decision and provide instructions for appeal. If the appeal is denied, we will provide a method for contacting the Virginia Attorney General where required.
Communications Preferences
You may opt out of non-essential project-update emails by using the unsubscribe method provided in the email or by contacting privacy@goldeneaglegolf.club. Even if you opt out of project updates, we may still send transactional, legal, security, administrative, or inquiry-related messages.
Children and Minors
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we learn that a minor has submitted information, we will delete it unless retention is required by law or necessary for security, fraud prevention, or legal purposes.
International Visitors and Data Transfers
The Platform is operated from the United States. If you access the Platform from outside the United States, your information may be transferred to, stored in, or processed in the United States or other countries where our service providers operate.
If EU/EEA, UK, or Swiss personal data is intentionally collected or targeted, we confirm the applicable transfer mechanism before processing. Depending on the vendor and processing context, this may include use of the EU-U.S. Data Privacy Framework for certified U.S. recipients, Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or another lawful transfer mechanism. We do not rely on the former Privacy Shield framework.
GLBA and Financial Information
The Platform collects preliminary investor-qualification information and may later collect financial or verification information. We determine with counsel whether the Platform, the project entity, or any service provider is subject to the Gramm-Leach-Bliley Act (GLBA), including whether any activity could be treated as a covered financial activity, finder activity, investment-advisory activity, or service-provider activity.
If GLBA applies, we will maintain safeguards appropriate to the sensitivity of customer information and will update this Policy or provide additional privacy notices as required.
Third-Party Links
The Platform may link to third-party websites, data rooms, scheduling tools, document tools, payment processors, or verification providers. We are not responsible for privacy practices of third parties we do not control. You should review third-party privacy policies before submitting information through those services.
Changes to This Policy
We may update this Policy to reflect changes in law, Platform functionality, vendors, security practices, investor-intake workflows, or project operations. Material changes will be posted on the Platform or communicated by email where appropriate. The “Last Revised” date indicates when the Policy was last updated.
Contact
Privacy questions and rights requests may be directed to:
Golden Eagle Golf Club · Privacy Team
privacy@goldeneaglegolf.club
Legal questions regarding investor documents, confidentiality obligations, or offering materials may be directed to:
Golden Eagle Golf Club · Development Team
contact@goldeneaglegolf.club