Peak Horizons Capital, LLC
Issue
The SEC’s Regulation S‑P (Privacy of Consumer Financial Information), adopted under Section 504 of the Gramm‑Leach‑Bliley Act and amended in 2024, requires investment advisers to disclose to clients who are natural persons their policies and procedures regarding the collection, use, safeguarding, disposal, and breach notification of customer records and non‑public personal information.
For purposes of this Policy:
“Customer Information” means any record containing nonpublic personal information about a client of Peak Horizons Capital, LLC (“PCHL”) or about a customer of another financial institution where such information has been provided to Peak Horizons Capital, LLC in connection with providing our services, where in paper, electronic, or any other form.
“Non-public Personal Information” (NPPI) includes personally identifiable financial information that is not publicly available and is obtained by Peak Horizons Capital, LLC in connection with providing advisory or related services. Examples include: name, address, phone number (if listed), Social Security or tax identification numbers, financial circumstances and income, account balances and holdings, and other information used to provide advisory and investment planning services.
“Sensitive Customer Information” is a subset of Customer Information that, if accessed or used without authorization, could reasonably result in substantial harm or inconvenience to an individual. It includes, for example, Social Security numbers and other government identification numbers, financial account numbers together with any required access code or credentials, and authentication data such as usernames and passwords or biometric identifiers. Sensitive Customer Information is subject to heightened incident‑response and notification procedures described below.
Consumer Information is collected from clients at the inception of their account and occasionally thereafter, primarily to determine accounts’ investment objectives and financial goals and to assist in providing requested services.
Peak Horizons Capital, LLC will not disclose a client’s Non‑public Personal Information to anyone unless it is permitted or required by law, at the direction or with the consent of a client, or is necessary to provide requested services.
PROCEDURES
a. The Chief Compliance Officer will promptly assess the nature and scope of the incident, identify the systems and data affected, and determine which clients are impacted.
b. Peak Horizons Capital, LLC will take immediate steps to contain the incident and prevent further unauthorized access.
c. If Sensitive Customer Information was, or is reasonably likely to have been, accessed or used without authorization, Peak Horizons Capital, LLC will notify each affected individual as soon as practicable, and no later than 30 days after becoming aware that such unauthorized access or use has occurred or is reasonably likely to have occurred, unless a law‑enforcement delay is authorized.
d. For Utah residents, notification will be made in the most expedient time possible, without unreasonable delay, as required by Utah law, and consistent with the timing standards described above.
e. Peak Horizons Capital, LLC will maintain written records of all incidents, investigations, determinations, and notifications for a minimum of five years.
11. Service Provider Oversight. Peak Horizons Capital, LLC requires that service providers with access to customer information maintain appropriate safeguards and notify Peak Horizons Capital, LLC within 72 hours of becoming aware of any breach or unauthorized access involving customer information. Peak Horizons Capital, LLC will conduct initial and ongoing due diligence of service providers and maintain written agreements that define data protection responsibilities and breach notification obligations.
Responsibilities
The Chief Compliance Officer will monitor for compliance with Peak Horizons Capital, LLC’s Privacy Policy and Procedures and will coordinate the dissemination of the Privacy Notice.
Recordkeeping
Peak Horizons Capital, LLC will maintain written records relating to this Privacy Policy and its safeguards and disposal procedures, including: (i) copies of this Privacy Policy and related written policies and procedures; (ii) records of service‑provider due diligence and written agreements that address Customer Information safeguards, breach notification, and disposal obligations; (iii) logs and documentation of incidents involving unauthorized access to or use of Customer Information, including investigations, determinations regarding whether customer notification was required, and copies of any notifications provided; and (iv) records of dates and methods of delivery of this Privacy Notice to clients. Such records will be maintained for at least five years, or such longer period as may be required by applicable law or regulation.
Attachment A
Procedures to Safeguard Client Records and Non-public Personal Information
Peak Horizons Capital, LLC shall strive to: (a) ensure the security and confidentiality of consumer, customer, and former customer records and information; (b) protect against any anticipated threats or hazards to the security or integrity of such records and information; and (c) protect against unauthorized access to or use of such records or information that could result in substantial harm or inconvenience to any customer. Accordingly, the following procedures will be followed:
A. CONFIDENTIALITY
Employees shall maintain the confidentiality of information acquired in connection with their employment, with particular care taken regarding Non-Public Personal Information. Employees shall not disclose Non‑Public Personal Information and other Customer Information except to persons who have a bona fide business need to know the information in order to serve the business purposes of Peak Horizons Capital, LLC and/or its clients. Peak Horizons Capital, LLC does not disclose, and no employee may disclose, any Non‑Public Personal Information and other Customer Information about a client or former client other than in accordance with these procedures.
B. INFORMATION SYSTEMS
Peak Horizons Capital, LLC has established and maintains its information systems, including hardware, software, and network components, in order to protect and preserve Non-Public Personal Information.
Access to specific databases and files shall be given only to employees who have a bona fide business need to access such information. Passwords shall be kept confidential and shall not be shared except as necessary to achieve a business purpose. User identifications and passwords shall not be stored on computers without access controls, written down, or stored in locations where unauthorized persons may discover them.
Passwords shall be changed promptly if there is reason to believe a password has been compromised. The Chief Compliance Officer may also require periodic password changes as determined appropriate. All access and permissions for terminated employees shall be removed from all systems promptly upon notification of the termination.
To avoid unauthorized access, employees shall close out programs and shut down their computers when they leave for an extended period of time and overnight. Laptops shall be secured when leaving the premises. Confidentiality shall be maintained when accessing the firm’s network remotely through the implementation of appropriate firewalls and encrypted transmissions.
C. DOCUMENTS
Employees shall avoid placing documents containing Non‑Public Personal Information and other Customer Information in office areas where they could be read by unauthorized persons, such as in photocopying areas or conference rooms. Documents that are being printed, copied, or faxed shall be attended to by the responsible employee. Documents containing Non‑Public Personal Information and other Customer Information sent by mail, courier, messenger, or fax shall be handled with appropriate care. Employees may only remove documents containing Non‑Public Personal Information and other Customer Information from the premises for bona fide work purposes, and any such information must be returned to the premises as soon as practicable.
D. DISCUSSIONS
Employees shall avoid discussing Non‑Public Personal Information and other Customer Information with, or in the presence of, persons who have no need to know the information. Employees shall avoid discussing Non‑Public Personal Information and other Customer Information in public locations, such as elevators, hallways, public transportation, or restaurants.
E. DISPOSAL OF OLD INFORMATION
Non‑Public Personal Information and other Customer Information that is no longer required to be maintained shall be destroyed and disposed of in an appropriate manner. Refer to the Document Destruction procedures contained in the Investment Adviser Compliance Manual & Written Supervisory Procedures for additional information.
F. IDENTITY THEFT PREVENTION
An identity thief can obtain a victim’s personal information through a variety of methods. Employees shall take the following actions to prevent identity theft:
Information We Share With Service Providers
We may share your Non‑Public Personal Information and other Customer Information with nonaffiliated third‑party service providers that perform services on our behalf. These services may include: technology and software platforms used to manage client accounts, portfolio management, financial planning, and communications; data integration and workflow automation providers; custodians and broker‑dealers that hold or execute transactions in your accounts; compliance, cybersecurity, and regulatory reporting services; cloud storage and document management providers; and other vendors that support our operations.
We require these service providers, through written agreements, to maintain the confidentiality and security of your information and to prohibit them from using it for any purpose other than performing services for our firm. We do not sell your personal information to third parties. We may also share information as permitted or required by law, such as to comply with a subpoena, respond to regulatory inquiries, or prevent fraud.
Use of Artificial Intelligence and Related Tools
We may use artificial intelligence and related technology tools to assist in research, analysis, communications, and business operations. Any such tools used in connection with client information are subject to appropriate data‑protection agreements and safeguards, and we require that they use client information only to perform services for our firm and not to train generalized models or for unrelated purposes, unless explicitly permitted and disclosed in accordance with applicable law.