Hello — I’m the Harborfield Assistant. I can explain Harborfield, compare reports, or help you find a relevant starting point. Final product access is determined separately through eligibility.
Loading
Preparing the requested page…
Loading
Preparing the requested page…
Hello — I’m the Harborfield Assistant. I can explain Harborfield, compare reports, or help you find a relevant starting point. Final product access is determined separately through eligibility.
Privacy notice
Information handling, retention, and written privacy requests.
Research architecture
Version-awareDocument framework
Published operational boundaries remain versioned and reviewable.
Review state
ExplicitHarborfield Business Consulting LLC handles information to provide online, written research and decision-support services. This notice applies to the website, public assistant, eligibility process, accounts, orders, intake, reports, corrections, and written support across all six products identified in our Terms.
Current service status: Harborfield remains pre-launch. Live checkout and payments are disabled. Test/mock checkout takes no card information and moves no money. Customer file uploads are not currently enabled, and the Contact page directs questions to email rather than an operational message-submission form.
| Information | Purpose |
|---|---|
| Account and authentication identifiers, sign-in/session records, and assigned access role | Provide account access and restrict protected materials to authorized users. |
| Eligibility answers and decision metadata | Apply customer, activity, scope, communication, and product-access rules. |
| Order identifier, product, price, currency, payment/refund status, timestamps, provider references where applicable, and policy-acceptance records | Administer the order and preserve accurate transaction and acceptance records. |
| Written intake, public URLs supplied by the customer, and necessary non-sensitive service, market, and operating context | Define and perform the purchased research or documentation scope. |
| Reports, sources and provenance, calculation/validation records, QA decisions, and delivery records | Prepare, validate, review, and deliver the purchased work and explain its evidence. |
| Correction requests and report-version history | Apply the purchased correction allowance and maintain the relationship between original and corrected work. |
| Support, cancellation, refund, privacy, and accessibility correspondence | Respond to written requests and administer the related matter. |
| Necessary technical, security, and audit records | Protect the service, investigate incidents, and explain access or operational decisions. |
Only information needed for these purposes should be submitted. A product's higher price does not authorize collection of prohibited sensitive data.
When you use the public assistant, your question, recent conversation context, and selected navigation context are processed to answer questions about Harborfield's public information. When AI-assisted mode is configured and used, that context is sent to OpenAI together with the approved public website content, product information, and policy excerpts used to draft an answer.
The current application keeps its displayed conversation in temporary browser memory rather than creating a persistent customer chat transcript. The application asks the AI provider not to store the generated response for later retrieval. These implementation choices do not establish a promise of zero provider retention or immediate deletion from all infrastructure logs.
Do not submit private customer records, credentials, financial account details, or sensitive documents to the assistant. The assistant is not the route for submitting paid-product intake, private support records, or final eligibility decisions.
Do not send Social Security numbers, driver's-license images, full bank statements, full payment-card numbers or CVV, bank usernames or login credentials, tax returns, credit reports, medical information, immigration status information or documents, passwords, API keys, recovery codes, or other unnecessary sensitive information.
If prohibited information is submitted incidentally, ordinary processing of the affected material stops, access is restricted, and the information is not used as report evidence. Harborfield's target is removal as soon as operationally practicable and within seven days, unless a documented active incident investigation requires temporary restricted preservation. Where practical, only minimal incident metadata is retained.
No live payment provider is currently active. A future separately approved hosted payment provider would handle payment credentials. Harborfield's own transaction records are limited to necessary order, amount, currency, transaction/reference, payment/refund status, timestamp, acceptance, and fulfillment/dispute information. Harborfield does not request or store full payment-card numbers, CVV, or bank login credentials.
Service-provider categories supported by the current service include website hosting, account authentication, database and private-file storage, email, and public research data. The public assistant also supports the AI processing described above. Research-provider use depends on the purchased product and relevance of the research question; a provider integration is not a promise that every report will contact that provider.
Access to protected order and report material is subject to customer ownership, authentication, authorized staff roles, and delivery controls. Human reviewers may handle the material needed for QA and corrections. Provider access and retention depend on the service performed and the verified environment.
These are Harborfield's selected business-policy periods. They are not presented as legally or tax-required periods.
| Data category | Normal retention or availability |
|---|---|
| Eligibility without a completed purchase | Normal maximum of 90 days; a documented temporary security/fraud hold may extend this where necessary. |
| Order-linked eligibility and intake | Normally 24 months after final order closure, subject to applicable approved deletion requests and transaction, dispute, or security exceptions. |
| Customer uploads and working files | Normal maximum of 24 months after final order closure; earlier deletion when no longer needed and safely supported. Uploads are not currently enabled. |
| Authenticated report portal/download access | Normally 12 months after final delivery or final approved correction, whichever is later. A completed full refund revokes future access. |
| Underlying report artifact | Up to 24 months after final order closure for correction, dispute, or operational purposes. Retaining an artifact does not extend normal portal access. |
| Minimal order, payment, refund, policy-acceptance, and necessary fulfillment/dispute records | Seven years under Harborfield's selected business-record retention policy. This does not mean keeping the complete intake and report for seven years. |
| Support, correction, refund, and privacy correspondence | Normally 24 months after final closure of the relevant matter. |
| Security and audit logs | Normally 12 months. A documented active incident, fraud investigation, payment dispute, or other approved hold may extend this only as needed. |
| Customer-linked research/source/provenance records | The applicable order-linked retention period. Public-source metadata fully separated from customer personal information may be retained longer when lawful and useful. |
An incomplete or abandoned order follows the applicable order-linked rules. It does not create a separate indefinite-retention rule or mean that the service has been completed. The pre-work cancellation rule remains applicable.
The periods above do not override a documented permitted hold or a verified provider/legal obligation. Information is not described as anonymous unless the customer linkage has actually been removed.
Send privacy or deletion requests in writing to support@harborfield.us. Harborfield's operational target is to complete eligible deletion or anonymization action within 30 days. Records legitimately retained for minimal transaction/business records, an active dispute, security or fraud investigation, or a verified provider/legal obligation may not be eligible for deletion at that time.
Deleting information from the primary system does not establish that all backup copies have already expired. Database backups follow a seven-day retention window. Information removed from the primary database may remain in an existing backup until that backup expires. After a restoration, previously recorded deletions are reapplied and access restrictions are checked before customer access is reopened. This database-backup window is separate from the retention periods for email, logs, and other provider records. A downloaded report on your own device cannot be recalled or remotely deleted by Harborfield.
Privacy and data requests: support@harborfield.us. Do not attach sensitive documents or credentials.
Lifecycle framework
Retention periods, deletion requests, and backup handling are explained in the Privacy notice.