Privacy Notice
How ICS collects, uses, protects, and discloses personal information in connection with our compliance consulting services and website — consistent with GLBA, SEC Regulation S-P, FINRA rules, NYDFS 23 NYCRR 500, and applicable state privacy laws.
Effective date: August 2026
1. Scope and Applicability
This Privacy Notice applies to personal information collected by International Compliance Solutions LLC ("ICS," "we," "us," or "our") through our website, through direct client engagements, and through any communications you have with us. It applies to current and prospective clients, website visitors, and other individuals who interact with ICS. ICS provides compliance consulting and outsourcing services to financial institutions — including banks, broker-dealers, registered investment advisers, and insurance companies — and may process information subject to the Gramm-Leach-Bliley Act (GLBA), SEC Regulation S-P, FINRA rules, NYDFS 23 NYCRR 500, applicable state privacy laws, and other federal and state requirements. This Notice is designed to be consistent with those obligations.
2. Information We Collect
- ·Information you provide: name, job title, organization, business address, telephone, email, and information necessary to deliver compliance consulting services — collected when you contact us, become a client, subscribe to newsletters, respond to surveys, or request documentation.
- ·Information collected automatically: IP address, browser type, operating system, referring URLs, and pages visited, used for server diagnostics, security, and aggregate usage analysis. This does not identify you personally.
- ·Client engagement information: business and operational information ICS receives in the course of an engagement — including regulatory status, business activities, policies, procedures, and personnel — treated as strictly confidential and used only to deliver contracted services.
- ·NPI handling: to the extent ICS receives nonpublic personal information (NPI) of a client's customers, ICS handles it in compliance with GLBA, SEC Regulation S-P, and the confidentiality terms of the consulting agreement.
3. How We Use Your Information
- ·Service delivery: to provide, manage, and improve the compliance consulting services you or your organization have contracted.
- ·Communications: to respond to inquiries, provide requested information, and communicate about your engagement.
- ·Regulatory compliance: to comply with legal, regulatory, and supervisory obligations applicable to ICS and its clients.
- ·Website administration: to maintain the security and proper functioning of our website.
- ·Marketing: with your prior consent, to send newsletters, alerts, and updates about our services. You may opt out at any time.
- ·Quality improvement: to improve our services based on client feedback and survey responses.
- ·Legal protection: to protect the rights, property, or safety of ICS, its clients, or others, including in connection with legal proceedings.
4. Information Sharing and Disclosure
- ·ICS does not sell, trade, rent, or transfer personal information to unaffiliated third parties for their own marketing purposes.
- ·Service providers: with trusted technology vendors (IT support, CRM, compliance management platforms) processing information on our behalf under confidentiality agreements.
- ·Legal requirements: when required by law, regulation, court order, subpoena, or lawful request by a regulatory or law enforcement authority.
- ·Regulatory reporting: to regulators or other authorities as required by ICS's legal and regulatory obligations.
- ·Professional advisers: to attorneys, accountants, or other advisers engaged to assist ICS in connection with a specific matter, subject to professional privilege and confidentiality.
- ·Business transactions: in connection with a merger, acquisition, or sale of substantially all of ICS's assets, provided the acquiring entity agrees to treat your information in accordance with this Notice.
- ·With your consent: for any other purpose with your express written consent.
- ·ICS does not engage in third-party behavioral tracking and does not allow third-party advertising on our website.
5. Artificial Intelligence and Technology Tools
- ·ICS uses approved AI tools — specifically Anthropic Claude — to assist with regulatory research, compliance analysis, and document drafting. Strict controls apply.
- ·Data minimization: ICS staff are trained and instructed never to input client NPI, PII, account numbers, Social Security numbers, MNPI, or other client-specific sensitive information into any AI platform. AI tools are used exclusively with publicly available regulatory information and de-identified reference materials.
- ·Zero data retention: ICS maintains a zero-data-retention (ZDR) API configuration with Anthropic. No conversation data is stored beyond the session.
- ·No model training: ICS does not opt in to any AI model training program. Anthropic does not use our API inputs or outputs to train its models.
- ·Human oversight: all AI-generated outputs are reviewed, validated, and approved by qualified ICS professionals before any client delivery.
- ·Data processing location: all AI data processing occurs within the United States.
- ·For full detail, see our AI Governance Notice.
6. How We Protect Your Information
- ·Encryption of sensitive data in transit (TLS/SSL) and at rest.
- ·Role-based access controls restricting information access to authorized personnel with a legitimate business need.
- ·Multi-factor authentication (MFA) for access to ICS systems and third-party platforms.
- ·Continuous monitoring of networks and systems for unauthorized access or intrusions, supervised by our IT vendor, Sinergy Systems.
- ·Regular vulnerability assessments and security testing against leading standards (ISO 27001, NIST 800-53, FFIEC, PCI).
- ·Employee training on information security and data privacy, conducted at least twice annually.
- ·Written vendor agreements requiring all technology providers to maintain appropriate data security safeguards.
- ·ICS does not store or process credit card information on its own servers. No electronic transmission or storage system is completely secure; take appropriate precautions when transmitting sensitive information electronically.
7. Data Retention
ICS retains personal and client information for as long as necessary to fulfill the purposes described in this Notice and to comply with applicable legal, regulatory, and contractual obligations. Client engagement records are typically retained for three to seven years or longer depending on the record and the applicable regulatory framework. When information is no longer required, ICS disposes of it securely in accordance with its information security program.
8. Your Rights and Choices
- ·Access: request access to the personal information we hold about you.
- ·Correction: request correction of inaccurate or incomplete personal information.
- ·Deletion: request deletion of your personal information, subject to legal retention obligations.
- ·Opt-out: opt out of marketing communications at any time.
- ·Portability: where required by applicable law, request a copy of your information in a portable format.
- ·To exercise any of these rights, contact us using the information below. We will respond within a reasonable timeframe and in accordance with applicable law. We may need to verify your identity before processing your request.
9. Third-Party Links and Services
Our website may contain links to third-party websites. Those sites have their own privacy policies, for which ICS is not responsible. ICS's key technology vendors — including SMART-RIA, Less Annoying CRM, Thomson Reuters, QuickBooks, Google, and Anthropic — maintain their own privacy and security programs. ICS evaluates vendor data practices as part of its due diligence and requires vendors to maintain appropriate safeguards by contract.
10. Children's Privacy
ICS's services are directed to business clients and professionals in the financial services industry. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us immediately so we may take appropriate action.
11. Changes to This Notice
ICS may update this Notice to reflect changes in our practices, applicable law, or regulatory requirements. Material changes will be reflected in the effective date at the top of this page and, where appropriate, communicated directly to clients. Continued use of our website or services following the posting of changes constitutes acknowledgment of the updated Notice.
12. Contact
Privacy questions, requests to exercise data rights, or concerns about our practices may be directed to International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134 · +1 (305) 448-0014 · info@ics-compliance.com.
Questions about this document may be directed to info@ics-compliance.com or in writing to International Compliance Solutions LLC, 2600 Douglas Rd. Suite 908, Coral Gables, FL 33134.