INFORMATION GOVERNANCE & PRIVACY POLICY

KIMBLE LEWIS & COMPANY LLC

Effective Date: August 2026

Kimble Lewis & Company LLC views data privacy not merely as a regulatory requirement, but as a fundamental fiduciary obligation. This Information Governance & Privacy Policy outlines our uncompromising commitment to enterprise-grade data stewardship regarding information collected through kimblelewis.com (the "Site") and our related secure communications. By interacting with this digital architecture, you acknowledge the structural controls and practices described herein.

1. DATA COLLECTION ARCHITECTURE

We strictly limit data collection to the minimum required to execute high-level corporate communications and secure our digital perimeter:

  • Executive Mandate & Inquiry Data: When you initiate a mandate or submit a secure communication, we collect your name, corporate email address, organizational affiliation, and the precise contents of your briefing.
  • Infrastructure & Telemetry Data: To defend against automated spam and malicious payloads, our security architecture (including invisible honeypots or bot-mitigation networks) automatically collects basic network telemetry, such as IP address routing, browser type, and interaction timestamps.

2. THE COOKIELESS FIDUCIARY STANDARD

To maintain a frictionless, enterprise-grade digital experience while adhering to uncompromising data minimization principles, this Site has been engineered to operate free of invasive tracking cookies. We utilize privacy-first, cookieless analytics to monitor aggregate digital velocity without capturing, storing, or monetizing your personal behavioral data.

3. CORPORATE UTILIZATION OF INFORMATION

Information submitted to Kimble Lewis & Company LLC is utilized exclusively for high-stakes professional execution:

  • To evaluate and respond to C-suite operating mandates, independent board directorship opportunities, and global speaking engagements.
  • To securely route your communications through our encrypted Google Workspace infrastructure via our serverless API dispatchers (e.g., Resend).
  • To distribute Insights to Win strategic briefings, strictly upon your verified opt-in.

4. THIRD-PARTY INFRASTRUCTURE PARTNERS

We do not, and will never, sell your personal information. Data is routed only through rigorously vetted, enterprise-grade infrastructure providers necessary to maintain our global digital footprint. This includes our serverless hosting environments (e.g., Netlify) and secure API email protocols. We mandate that these infrastructure partners uphold strict data processing agreements.

5. PLATFORM BOUNDARIES

This Site acts as a central hub pointing to external platforms, including our thought leadership on Substack (Once Undesirable. Now Undeniable.) and our professional footprint on LinkedIn. When you navigate to these external platforms, your data is governed by their independent corporate privacy frameworks. Kimble Lewis & Company LLC maintains no liability for their algorithmic data handling.

6. GLOBAL DATA RIGHTS & COSO COMPLIANCE

Operating with the foresight required for global governance, we honor the data rights established by leading jurisdictions (including the GDPR in the EEA/UK, and the CPRA, VCDPA, and CDPA across the United States). Regardless of your physical jurisdiction, you retain the absolute right to:

  • Request a full audit of the personal data we hold regarding your corporate profile.
  • Demand the immediate correction or complete cryptographic deletion of your data from our systems.
  • Revoke consent for any opt-in marketing or thought leadership communications instantly.

7. SECURITY & RETENTION PROTOCOLS

We apply strict administrative, technical, and physical safeguards—rooted in COSO risk management principles—to defend your data in transit and at rest. Data is retained only for the duration required to evaluate executive mandates or comply with strict legal obligations, after which it is systematically purged.

8. CONTACT THE DATA CONTROLLER

For immediate execution of data rights, compliance audits, or privacy inquiries, contact our secure infrastructure directly at privacy@kimblelewis.com.

9. POLICY MODIFICATIONS & COPPA COMPLIANCE

This digital architecture is strictly designed for corporate professionals and enterprise stakeholders. We do not direct our Site toward, nor do we intentionally collect personal telemetry or data from, minors under the age of 16. Furthermore, we reserve the right to amend this Information Governance & Privacy Policy at our corporate discretion to reflect shifts in global regulatory frameworks. Any material modifications will be effective immediately upon publication, as indicated by the Effective Date at the top of this document; your continued engagement with the Site constitutes formal acceptance of these revised terms.

[Updated August 2026]