Legal

Privacy Policy

Effective Date: July 29, 2026 · Last Updated: August 27, 2026 · Version: 1.1

Advalis Inc. & OZfile.com

This Privacy Policy explains how Advalis Inc. handles personal information in connection with our qualified opportunity zone reporting platform. Key points:

Our Core Privacy Commitments: No Marketing Use of Compliance Data: We do not use QOF reporting data, Investor or QOZB submissions, Asset Test data, or any compliance information for marketing purposes. Client Data Ownership: All client data remains the property of our Licensee Firm clients. No Sale of Data: We do not sell or monetize compliance information. Purpose-Limited Processing: Compliance platform data is used solely for Asset Tests, Filing Package and Information Return generation, and related compliance services under the OZ Provisions. SOC 2 Type 2 Certified Security: Enterprise-grade security protects all data. Transparent Practices: We maintain a clear distinction between public website analytics and secure compliance platform data.

Your Rights: You have the right to access and download your personal information, correct inaccurate data, request deletion (subject to legal requirements), opt-out of marketing communications, and control cookie preferences.

For detailed information, please read the full policy below.

Table of Contents

  1. 1. Introduction
  2. 2. Scope of this Policy
  3. 3. Definitions
  4. 4. Personal Information We Collect
  5. 5. How We May Use Personal Information
  6. 6. Legal Basis for Processing
  7. 7. How We May Disclose Personal Information
  8. 8. Cookies and Other Tracking Mechanisms
  9. 9. Data Retention
  10. 10. Your Privacy Rights and Choices
  11. 11. California Privacy Rights
  12. 12. Nevada Privacy Rights
  13. 13. Children's Information
  14. 14. International Data Transfers
  15. 15. External Links and Features
  16. 16. Security
  17. 17. Data Breach Notification
  18. 18. Automated Decision-Making
  19. 19. Marketing and Communications
  20. 20. Changes to this Policy
  21. 21. Contact Us

1. Introduction

This Privacy Policy ("Policy") describes how Advalis Inc., a Delaware corporation with its principal place of business at 270 S. Central Blvd, Suite 205, Jupiter, FL 33458 ("Advalis," "Company," "we," "us," or "our"), collects, uses, discloses, protects, and otherwise processes personal information described in this Policy, as well as the rights and choices individuals have regarding such personal information.

We are committed to protecting your privacy and ensuring the security of your personal information. This Policy applies to our cloud-based software platform and managed compliance services specifically engineered for qualified opportunity fund sponsors, fund managers, fund administrators, and the professional advisors and investors they serve, enabling the efficient generation, management, maintenance, and tracking of filings, reports, and statements required under the OZ Provisions.

Key Privacy Principles

We operate under the following fundamental privacy principles:

First, we maintain strict separation of compliance data and marketing. Information collected through our qualified opportunity zone reporting platform is never used for marketing purposes. We maintain a complete separation between operational compliance data and any marketing activities. Second, all QOF and Investment data, Asset Test outputs, Investor and QOZB submissions, and compliance content remains the exclusive property of our Licensee Firm clients. We act solely as a data processor, not a data owner. Third, we process compliance information only for the specific purpose of enabling Asset Tests, Filing Package and Information Return generation, and related compliance services under the OZ Provisions as directed by our clients. Fourth, we do not sell, rent, license, or otherwise monetize any compliance information or client data. Fifth, we maintain transparency by clearly distinguishing between data collected on our public website (which may be used for analytics and marketing) and data within our secure compliance platform (which is never used for marketing).

By using our Services (as defined below), you agree that your personal information will be handled as described in this Policy. Your use of our Services and any dispute over privacy is subject to this Policy and our Terms of Service, available at https://ozfile.com/terms/, including their applicable terms governing limitations on damages and the resolution of disputes.

2. Scope of this Policy

2.1 Services Covered

This Policy applies to the personal information we collect and process related to visitors to our website located at www.ozfile.com and all associated domains, subdomains, and web properties (the "Site"). It also covers Licensee Firms (commercial entities that have entered into Platform Services Agreements with us), Authorized Users (employees, contractors, or agents authorized by Licensee Firms), Invited Users (Investors and QOZB Representatives invited by Licensee Firms to submit information or access documents in connection with a QOF), individuals who use our services on behalf of our customers, and prospective customers who inquire about our Services.

Collectively, our website, software platform, applications, tools, features, functionality, Asset Test, Filing Package, Information Return, and Investor Statement generation tools, managed compliance services, APIs, documentation, training resources, support services, and all related online and offline services are referred to as the "Services."

2.2 Additional Notices and Limitations

Supplemental Notices: Depending on how you interact with us, we may provide you with other privacy notices with additional details about our privacy practices specific to certain Services or features. For example, when you are invited to submit information as an Invited User, you may receive specific privacy information from the Licensee Firm that invited you.

Exclusions: This Policy does not apply to job applicants or our employees (covered by separate employment privacy policies), information we process on behalf of our business clients as a data processor (covered by our agreements with those clients and their privacy policies), or anonymized or aggregated information that cannot reasonably identify you.

Client Data Ownership: Our processing of personal information belonging to our business clients is subject to our agreement with the respective client and their data handling practices. All client data remains the property of our Licensee Firm clients. We act as a data processor for Client Data, processing it only according to the instructions of our Licensee Firms.

3. Definitions

For purposes of this Policy, the following definitions apply:

"Asset Test" means the calculation performed by the Services to measure a QOF's holdings of qualified opportunity zone property against the 90% investment standard under IRC Section 1400Z-2(d)(1), based on the average of the percentages held on the last day of the first six-month period of the QOF's taxable year and the last day of the QOF's taxable year, using asset data and values provided or confirmed by the Licensee Firm.

"Authorized Users" means employees, contractors, agents, or other individuals who are granted access to use the Services under a Licensee Firm's account with express authorization.

"Client Data" means all data, information, content, materials, and other information provided, submitted, uploaded, or transmitted by or on behalf of Licensee Firms or Invited Users through the Services, including but not limited to personal information, Investment and Deferral Election data, QOZB information, Filing Packages, Investor Statements, documents, and communications.

"Deferral Election" means an election by an Investor under IRC Section 1400Z-2(a) to defer eligible gain by making a qualifying investment in a QOF, together with the related amounts, dates, and supporting data submitted through the Services.

"Filing Package" means the compiled, filing-ready forms, schedules, statements, and supporting documents generated by the Services for a QOF or its Investors with respect to a Reporting Period, including but not limited to IRS Form 8996, Form 8997 support data, and Information Returns.

"Information Return" means any return, report, or statement required under IRC Sections 6039K or 6039L, including any form prescribed by the IRS for such purposes and any successor or newly prescribed forms, and any related statements required to be furnished to Investors or QOFs.

"Investment" means an Investor's equity investment in a QOF processed through the Services, including any associated Deferral Election.

"Investor" means a person or entity that holds, has held, or is acquiring an Investment in a QOF and that is invited by a Licensee Firm to submit information through the Services or to access Investor Statements and other documents through the Investor Portal.

"Investor Portal" means the secure portal made available through the Services through which Investors may view and download Investor Statements and other documents made available to them by a Licensee Firm.

"Investor Statement" means any statement or document generated through the Services for delivery to an Investor, including but not limited to annual statements supporting the Investor's IRS Form 8997 filing obligations and any statements required to be furnished to Investors under the OZ Provisions.

"Invited User" means any individual, entity, client, or representative invited or authorized by a Licensee Firm to submit information through the Services, or to access documents made available through the Services, in connection with a QOF, including Investors and QOZB Representatives.

"IRS" means the Internal Revenue Service of the United States Department of the Treasury, or any successor agency.

"Licensee Firm" means any QOF sponsor, fund manager, fund administrator, accounting or tax firm, law firm, or other business entity that has entered into a Platform Services Agreement with Advalis for use of the Services.

"OZ Provisions" means IRC Sections 1400Z-1 and 1400Z-2, together with IRC Sections 6039K and 6039L, and all applicable Treasury Regulations, IRS forms, IRS guidance, and amendments thereto, governing qualified opportunity zones, qualified opportunity funds, and related reporting obligations.

"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.

"Platform Services Agreement" means the separate commercial agreement between Advalis and a Licensee Firm governing the specific terms, pricing, and conditions of the Licensee Firm's subscription to the Services.

"QOF" or "Qualified Opportunity Fund" means an investment vehicle organized as a corporation or partnership for the purpose of investing in qualified opportunity zone property that is or seeks to be certified as a qualified opportunity fund under IRC Section 1400Z-2, including any qualified rural opportunity fund. For purposes of access to and billing for the Services, each QOF, together with its associated QOZBs, Authorized Users, and projects, is treated as a single metered unit.

"QOZB" or "Qualified Opportunity Zone Business" means a qualified opportunity zone business within the meaning of IRC Section 1400Z-2(d)(3), including any trade or business of a QOF and any business in which a QOF holds qualified opportunity zone stock or a qualified opportunity zone partnership interest.

"QOZB Representative" means an individual invited or authorized by a Licensee Firm to submit information through the Services on behalf of a QOZB, including statements and data required under IRC Section 6039L.

"Reporting Period" means a taxable year of a QOF, or such other period prescribed by applicable law or supported by the Services, for which calculations, filings, reports, or statements are prepared through the Services.

"Security Incident" means any unauthorized access to, acquisition of, use of, or disclosure of Client Data or any breach of the security measures protecting the Services or Client Data.

"Services" means collectively all of Advalis's cloud-based software platforms, applications, tools, features, functionality, Asset Test, Filing Package, Information Return, and Investor Statement generation tools, managed compliance services, APIs, documentation, training resources, support services, and all related online and offline services provided by Advalis.

"Transmission Services" means the optional services, available to Licensee Firms under the applicable Platform Services Agreement, pursuant to which Advalis electronically transmits designated Information Returns or other filings to the IRS on behalf of a Licensee Firm. Transmission Services are not included in the base Services and apply only to filings for which a Licensee Firm has expressly enrolled and Advalis has accepted transmission responsibility under that Platform Services Agreement.

4. Personal Information We Collect

We collect personal information directly from you, automatically through your use of the Services, and from other sources. To the extent permitted by applicable law, we may combine the information we collect from or about you. The categories and types of information we collect vary depending on your relationship with us and how you interact with our Services.

4.1 IMPORTANT: No Marketing Use of Compliance Information

Information collected in the qualified opportunity zone reporting platform is strictly limited to compliance purposes and is NEVER used for marketing.

Key restrictions on compliance platform data include no marketing use, meaning platform data is never used for marketing, advertising, or promotional purposes. The compliance platform does not collect any marketing-related information. We do not sell, rent, license, or otherwise monetize any compliance information. All compliance information belongs exclusively to the Licensee Firm who licensed the Services, not to Advalis. Compliance data is used solely for Asset Tests, Filing Packages, Information Returns, Investor Statements, managed filing services, and providing the contracted services. We maintain complete separation between compliance platform data and any website analytics or marketing systems.

This restriction applies to all information submitted through the secure compliance platform, including Investor and Investment information, QOF, QOZB, and project details, Deferral Election data, statements and information required under IRC Sections 6039K and 6039L, Asset Test inputs and outputs, taxpayer identification numbers, all documents uploaded for compliance under the OZ Provisions, and any data entered in connection with a QOF.

4.2 Information Collected Directly

The personal information we collect directly varies depending upon your user category and interactions with us:

For Licensee Firms and Their Authorized Users:

Account Registration Information: We collect legal business name and DBA names, federal tax identification number (EIN), state business registration numbers, principal business address and additional office locations, primary contact information including name, title, email, and phone, billing contact information, account administrator details, and username and password credentials.

Business and Professional Information: This includes professional licenses and certifications, industry affiliations and memberships, business type and structure, years in business, fund and investor volume estimates, and service area coverage.

Payment and Billing Information: We collect payment method details such as credit card or ACH information, billing address, tax exemption certificates if applicable, purchase orders and invoicing preferences, and transaction history and payment records.

Communications and Support: We maintain records of support tickets and inquiries, training attendance records, feedback and satisfaction surveys, feature requests and suggestions, and correspondence with our team.

For Invited Users:

Investor Information (as required for reporting under the OZ Provisions): We collect full legal name and any aliases, current residential or business address, Social Security Number or Tax Identification Number when required, entity type and formation details for entity Investors, and email address and phone number for compliance purposes.

Investment and Fund Information: This includes the applicable QOF name and details, Investment amounts and dates, Deferral Election information including deferred gain amounts and related dates, capital account or ownership interest information, asset data and valuations where applicable, and supporting documentation requested by the Licensee Firm.

QOZB Information: For QOZB Representatives, we collect the QOZB's legal name and employer identification number, statements and information required under IRC Section 6039L, and the representative's name, title, email address, and phone number.

4.3 Information Collected Automatically

We and our service providers automatically collect certain information when you use our Services:

Device and Browser Information: We collect IP address and approximate geographic location derived from IP, browser type and version, operating system and version, device type, manufacturer, and model, screen resolution and browser window size, language preferences, unique device identifiers, and mobile network information if applicable.

Usage and Activity Information: This includes pages visited and content viewed, features used and actions taken, search queries within the Services, click paths and navigation patterns, time spent on pages and features, referring and exit URLs, date and time stamps of activities, error logs and performance data, and session duration and frequency.

Location Information: We gather general location through IP address, time zone settings, and language and regional preferences.

Tracking Technologies Information: We collect cookie identifiers, pixel tag data, session replay information on our public website only, analytics identifiers, and marketing attribution data.

4.4 Information from Third Sources

We may collect and receive personal information from third-party sources:

Business Partners and Service Providers: These include background check providers for business verification, payment processors providing transaction confirmations, credit reporting agencies for business accounts, marketing and lead generation partners, and industry associations and networks.

Public Sources: We may access business registrations and licenses, SEC and state securities filings, court records and regulatory filings, professional licensing boards, social media profiles for business accounts, and news articles and press releases.

Data Analytics and Enhancement Providers: We work with ZoomInfo for business contact enrichment, HubSpot for marketing interaction data, Google Analytics for website behavior analysis, and various industry databases and directories.

Government Entities: We may receive information from the IRS for compliance confirmations, state regulatory bodies, law enforcement when required, and tax authorities for business verification.

4.5 Free Tools and Developer Interfaces

Our Site offers free public tools. This subsection describes what each one collects and where that information goes.

Opportunity Zone Address Lookup: When you enter an address or click a location on the map, the address or coordinates are sent to our geocoding providers, Geocodio and the United States Census Bureau geocoder, to identify the census tract, and the result is returned to you. We cache lookup results so repeat searches are fast. We do not use lookup addresses for marketing and we do not build profiles from them.

Address Watchlist: If you choose to join the watchlist, we store the address you searched, its census tract identifiers, and your email address so we can notify you when the status of that location changes. You can leave the watchlist at any time using the link in any watchlist email.

Safe Harbor Report Generator: The details you enter are stored so we can assemble your report and deliver it to the email address you provide.

Deadline and Penalty Calculator: The calculator runs entirely in your browser and sends us nothing.

Guides and Downloads: When you request a guide, handbook, or similar resource, we collect your email address to deliver it and, subject to the choices described in Section 19, to send related updates.

Developer Keys and Machine Interfaces: We may offer public programmatic interfaces, including APIs and agent endpoints, that answer the same lookup questions as our free tools. If you request a developer key, we collect your email address to issue the key and meter its use. Addresses submitted through these interfaces are handled the same way as addresses entered in the address lookup tool.

5. How We May Use Personal Information

We collect, use, disclose, and otherwise process the personal information we collect for the following business and commercial purposes:

5.1 Service Delivery and Operations

Providing and Operating Our Services: We use personal information for creating and maintaining user accounts, authenticating users and managing access controls, processing Asset Test requests, facilitating data collection from Investors and QOZB Representatives including Deferral Election data and statements required under IRC Section 6039L, generating Filing Packages, Information Returns, and Investor Statements, making Investor Statements and other documents available to Investors through the Investor Portal as directed by Licensee Firms, transmitting designated filings to the IRS where a Licensee Firm has enrolled in optional Transmission Services and Advalis has accepted transmission responsibility under the applicable Platform Services Agreement, maintaining audit trails and compliance records, and providing technical infrastructure and platform functionality.

QOZ Compliance Management: We enable Licensee Firms to perform Asset Tests on QOFs, generate and manage Filing Packages, Information Returns, and Investor Statements, collect and store Investor and QOZB submissions, automate compliance analysis using AI and machine learning, manage compliance deadlines and notifications, track filing and statement furnishing status, and maintain QOF archives and retrieval systems. All such data remains the property of our Licensee Firm clients.

5.2 Business Operations and Improvement

Analytics and Performance: We analyze platform usage patterns and trends, measure feature adoption and effectiveness, identify system performance issues, conduct A/B testing and optimization, evaluate service quality and reliability, create aggregated and anonymized analytics, and monitor system health and availability.

Research and Development: We use data to improve existing features and functionality, develop new products and services, enhance user experience and interface design, train and improve our AI and machine learning models, conduct market research and competitive analysis, and test beta features and gather feedback.

5.3 Communications and Support

Customer Communications: We respond to inquiries and support requests, send service-related announcements and updates, provide technical support and troubleshooting, notify about system maintenance and downtime, communicate about account and billing matters, deliver training materials and resources, and send administrative and transactional messages.

Marketing and Promotional Activities: For marketing purposes, we send newsletters and product updates with consent, promote new features and services, conduct customer satisfaction surveys, invite participation in webinars and events, share industry news and compliance updates, and personalize marketing content based on interests. Client Data and QOZ compliance information are never used for marketing purposes.

5.4 Security and Legal Compliance

Security and Fraud Prevention: We protect against unauthorized access and cyber threats, detect and prevent fraudulent activities, investigate security incidents and breaches, implement access controls and authentication, monitor for suspicious behavior patterns, maintain system integrity and data protection, and conduct security audits and assessments.

Legal and Regulatory Compliance: We comply with reporting and filing requirements under the OZ Provisions, meet anti-money laundering (AML) obligations, comply with applicable U.S. securities laws, comply with IRS reporting and recordkeeping requirements, respond to legal process and law enforcement requests, maintain records as required by law, cooperate with regulatory examinations, and enforce our Terms of Service and policies.

5.5 Business Management

General Business Operations: We manage vendor and partner relationships, conduct financial planning and analysis, process mergers, acquisitions, or restructuring, maintain corporate records and governance, manage insurance and risk assessment, perform accounting and tax functions, and conduct internal audits and compliance reviews.

6. Legal Basis for Processing

We process personal information only when we have a valid legal basis to do so. Our legal bases for processing include:

6.1 Contract Performance

We process personal information as necessary to perform our contracts with you, including providing access to our Services under the Terms of Service, delivering services under Platform Services Agreements for Licensee Firms, processing payments and billing, providing customer support, and managing user accounts and authentication.

6.2 Legitimate Interests

We process personal information for our legitimate business interests, including improving and developing our Services, ensuring network and information security, preventing fraud and illegal activities, direct marketing to business contacts where permitted, internal administrative purposes, and enforcing our legal rights and remedies.

When relying on legitimate interests, we balance our interests against your rights and freedoms to ensure they are not overridden.

6.3 Legal Obligations

We process personal information to comply with legal obligations, including reporting and filing requirements under the OZ Provisions, IRS reporting and recordkeeping obligations, anti-money laundering regulations, applicable U.S. securities laws, tax and accounting obligations, responding to legal process, maintaining required business records, and cooperating with law enforcement and regulators.

6.4 Consent

Where required by law, we obtain your consent to process personal information, particularly for marketing communications where consent is required, cookies and similar tracking technologies, processing sensitive personal information, and cross-border data transfers where required.

You may withdraw consent at any time, though this will not affect the lawfulness of processing based on consent before withdrawal.

6.5 Vital Interests

In rare circumstances, we may process personal information to protect vital interests, such as in emergencies where someone's life or safety is at risk.

6.6 Public Interest

We may process personal information for tasks carried out in the public interest, particularly related to preventing financial crimes and ensuring regulatory compliance.

7. How We May Disclose Personal Information

We disclose personal information in the following circumstances and for the purposes specified:

7.1 Service Providers and Vendors

We disclose personal information to carefully selected vendors and service providers who perform functions on our behalf that are essential to providing our services, including:

Infrastructure and Technology Providers: These include Amazon Web Services for cloud hosting and storage, Cloudways for website hosting, Cloudflare for content delivery, DNS, and security services, geocoding providers (Geocodio and the United States Census Bureau geocoder) for our address lookup tools, database management providers, backup and disaster recovery services, email delivery services, and telecommunications providers.

Business Operations Providers: We work with payment processors and merchant services, accounting and financial services, legal and compliance advisors, insurance providers, office productivity tool providers, and human resources service providers.

All service providers are contractually obligated to protect personal information and use it only for providing services to us. Data shared with service providers is encrypted in transit and at rest.

7.2 Our Customers (Licensee Firms)

We process and disclose personal information as necessary to provide our Services to Licensee Firm clients by providing Invited User submissions to the requesting Licensee Firm, performing Asset Tests and generating Filing Packages, Information Returns, and Investor Statements as directed by Licensee Firms, making Investor Statements and other documents available to Investors through the Investor Portal as directed by Licensee Firms, providing compliance and audit information, facilitating the collection and storage of Investor and QOZB submissions, and facilitating communications about QOFs and Investments.

7.3 Marketing and Analytics Partners

We may disclose website visitor information (not Client Data or compliance information) to Google Analytics for website analytics, ZoomInfo for B2B contact information, HubSpot for marketing automation and CRM, Calendly for meeting and demo scheduling, marketing attribution platforms, and advertising networks for B2B marketing only.

Important: Client Data and QOZ compliance information are never shared with marketing or analytics partners.

7.4 Business Transfers

In connection with business transitions, encrypted database information may be disclosed to acquirers, successors in a merger, acquisition, or sale of assets, bankruptcy trustees or receivers, and investors or lenders with aggregated data only.

7.5 Legal and Compliance Disclosures

We disclose personal information when required or permitted by law to comply with subpoenas, court orders, and other legal process, respond to requests from law enforcement and regulatory authorities, comply with IRS and other regulatory requirements including reporting obligations under the OZ Provisions, investigate and prevent illegal activities, enforce our Terms of Service and protect our rights, protect the safety and security of individuals, and prevent fraud and financial crimes.

7.6 Consent-Based Disclosures

We may disclose personal information when you direct us to share it with specific third parties, with your explicit consent for specific purposes, or to third parties you designate to receive compliance outputs or information.

7.7 Aggregated and De-identified Information

We may use de-identified information that cannot reasonably identify you for benchmarking and internal reports.

8. Cookies and Other Tracking Mechanisms

8.1 Overview of Tracking Technologies

We and third parties use various tracking technologies to automatically collect information about your browsing activity and use of our Services:

Cookies: Cookies are small text files stored on your device that help us recognize you, remember your preferences, and understand how you use our Services. We use Essential Cookies that are required for the Services to function properly including authentication, security, and load balancing. We also use Performance Cookies that help us understand how visitors interact with our Services through page views and performance metrics. Functionality Cookies remember your preferences and settings such as language, region, and login information. Analytics Cookies collect information about Service usage for improvement purposes. Marketing Cookies track effectiveness of our marketing campaigns on our public website only.

Pixel Tags/Web Beacons: These are tiny graphics with unique identifiers that track user activities, email opens, and help us manage content and compile usage statistics.

Local Storage: We use HTML5 local storage to store preferences and temporary data on your device for improved performance.

Session Replay: On our public website only, not in the secure compliance platform, we may use session replay tools to understand user interactions and improve user experience.

Device Fingerprinting: We may collect device attributes to create a unique identifier for security and fraud prevention purposes.

8.2 Third-Party Analytics and Advertising

Analytics Services: We use third-party analytics services on our public website to evaluate usage. We use Google Analytics to analyze website traffic and user behavior. You can learn more at https://www.google.com/policies/privacy/partners/ and opt-out at https://tools.google.com/dlpage/gaoptout. We also use ZoomInfo to identify business visitors and enrich B2B contact information, and HubSpot for marketing analytics and lead tracking.

Advertising Technologies: We work with third-party advertising companies to display ads on other websites. These companies use cookies to track your browsing across websites. We use retargeting and remarketing to show relevant ads based on your visit to our Site. We also participate in interest-based advertising networks.

Important: Tracking for analytics and advertising occurs only on our public website, not within the secure compliance platform used for compliance under the OZ Provisions.

8.3 Your Cookie Choices

Browser Controls: Most browsers allow you to block or delete cookies through settings. You can set your browser to notify you when cookies are placed. Note that disabling cookies may affect Service functionality.

Opt-Out Options: You can opt-out through Google Analytics at https://tools.google.com/dlpage/gaoptout, the Network Advertising Initiative at https://optout.networkadvertising.org/, the Digital Advertising Alliance at https://optout.aboutads.info/, and the European Digital Advertising Alliance at https://www.youronlinechoices.eu/.

Do Not Track Signals: Currently, our Site and Services do not recognize browser "Do Not Track" signals. However, you can use the opt-out mechanisms described above.

Cookie Consent: Where required by law, we obtain consent before placing non-essential cookies.

9. Data Retention

9.1 Retention Periods

We retain personal information for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law:

Account Information: Active Licensee Firms' information is retained for the duration of the subscription term. Authorized Users' information is retained while authorization is active. Invited Users' submission access credentials expire upon submission completion or after 30–90 days, while Investor Portal access continues for so long as the inviting Licensee Firm maintains document availability.

Fund Reporting and Compliance Data: Active Client Data is retained during the subscription term. Asset Tests, Filing Packages, Information Returns, and Investor Statements are retained for five (5) years or as required by IRS recordkeeping requirements under the OZ Provisions. Supporting documentation is retained for five (5) years or as required by applicable regulations.

Post-Termination Retention: Licensee Firms have a 60-day data retrieval period to retrieve their data. Backup copies may be retained for up to six (6) months on a rolling basis. Audit logs are retained for five (5) years for compliance purposes. Aggregated analytics are retained indefinitely in anonymized form.

Marketing and Communications: Marketing preferences are retained until you opt-out or request deletion. Email communications are retained for three (3) years from last interaction. Support tickets are retained for three (3) years from resolution. Website analytics are retained for 26 months, which is the Google Analytics default.

9.2 Retention Criteria

We determine appropriate retention periods based on the purpose for which information was collected, legal and regulatory requirements including IRS recordkeeping obligations under the OZ Provisions, statute of limitations for legal claims, industry standards and best practices, whether retention is necessary for our legitimate interests, and your requests for deletion where applicable.

9.3 Deletion Practices

When personal information reaches the end of its retention period, we delete it from production systems within 30 days, from backup systems on the next backup rotation cycle, and from archived systems annually. Paper records are securely shredded and electronic media is securely wiped or destroyed.

Exception: We may retain information longer if required for legal proceedings, regulatory investigations, IRS examinations, or compliance obligations.

10. Your Privacy Rights and Choices

Depending on your location and applicable laws, you may have certain rights regarding your personal information:

10.1 Access and Portability Rights

Right to Access: You may request information about whether we process your personal information, the categories of personal information we collect, purposes for processing, categories of recipients, retention periods, and your rights regarding the information.

Right to Data Portability: Where technically feasible, you may request your personal information in a structured, commonly used, machine-readable format.

How to Exercise: Licensee Firms can access their data through their account dashboard or contact support. Investors may view and download Investor Statements and other documents made available to them through the Investor Portal. For other requests, Invited Users should contact the Licensee Firm that invited them, or email us at [email protected].

10.2 Correction and Update Rights

Right to Rectification: You may request correction of inaccurate personal information or completion of incomplete information. Account holders can update information through account settings. Contact our support team for assistance. Invited Users should contact the inviting Licensee Firm.

10.3 Deletion Rights

Right to Erasure: You may request deletion of your personal information, subject to certain exceptions.

Exceptions: We may retain information when necessary to complete requested services, comply with legal obligations including IRS recordkeeping requirements under the OZ Provisions, detect security incidents or illegal activity, exercise legal rights or defend against claims, or conduct internal uses aligned with your expectations.

Deletion Requests: Email [email protected] with sufficient information to identify your account and specify what information you want deleted.

10.4 Restriction and Objection Rights

Right to Restrict Processing: You may request we limit processing while verifying accuracy of disputed information, determining lawfulness of processing, or preserving information for legal claims.

Right to Object: You may object to processing based on legitimate interests, direct marketing purposes, or automated decision-making.

10.5 Marketing and Communication Preferences

Opt-Out Options: You can opt-out of marketing emails using the unsubscribe link in any marketing email, manage account notifications through your account settings preferences, text messages by replying STOP, and phone calls by requesting addition to our do-not-call list.

Transactional Communications: You cannot opt-out of service-related communications necessary for account management, security, or legal compliance.

10.6 Cookie and Tracking Preferences

See Section 8.3 for detailed information about managing cookie preferences and opting out of tracking technologies.

10.7 Response Timeline and Verification

Response Timeline: We provide acknowledgment within 5 business days, substantive response within 30 days, and may extend up to 60 additional days for complex requests with notice.

Identity Verification: We may require verification of your identity before processing requests through account verification using login credentials, government-issued ID verification, additional information to confirm identity, or authorized agent documentation where applicable.

10.8 Non-Discrimination

We do not discriminate against individuals who exercise their privacy rights. We will not deny services, charge different prices, provide different service levels, or suggest you will receive different treatment.

11. California Privacy Rights

11.1 Rights Under the California Consumer Privacy Act (CCPA)

California residents have additional rights under the CCPA:

Right to Know: Twice per year, you may request the categories of personal information collected, categories of sources, business or commercial purposes for collection, categories of third parties with whom we share information, and specific pieces of personal information we hold.

Right to Delete: You may request deletion of personal information, subject to exceptions in Section 10.3.

Right to Opt-Out of Sale: We do not sell personal information as defined by the CCPA. We have not sold personal information in the preceding 12 months.

Right to Non-Discrimination: As described in Section 10.8.

11.2 Categories of Information Collected

In the preceding 12 months, we have collected these categories under the CCPA: identifiers such as names, email addresses, and IP addresses; personal information categories under Cal. Civ. Code § 1798.80(e); commercial information including transaction history; internet activity information; geolocation data from general location derived from IP; professional information; and inferences drawn from other information.

11.3 California Shine the Light Law

Under California Civil Code Section 1798.83, California residents may request information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

11.4 How to Exercise California Rights

Submit Requests: You can submit requests online at https://ozfile.com/contact/, by email at [email protected], or by mail to Advalis Inc., Attn: Privacy Rights, 270 S. Central Blvd, Suite 205, Jupiter, FL 33458.

Authorized Agents: You may designate an authorized agent to submit requests on your behalf. The agent must provide written authorization signed by you, power of attorney if applicable, verification of their identity, and direct confirmation from you of the authorization.

12. Nevada Privacy Rights

Nevada residents have the right to opt-out of the sale of certain personal information to third parties. We do not currently sell personal information as defined under Nevada law. If you are a Nevada resident and would like to submit a request regarding the sale of your personal information, please contact us at [email protected].

13. Children's Information

13.1 Age Restrictions

Our Services are designed exclusively for business use by qualified opportunity fund sponsors, fund managers, fund administrators, and the professional advisors and investors they serve. The Services are not intended for, marketed to, or designed for use by children under the age of 18.

13.2 No Knowing Collection

We do not knowingly collect, solicit, or maintain personal information from children under 18 years of age. We do not knowingly permit children under 18 to register for or use the Services.

13.3 Parental Rights

If a parent or guardian believes that their child under 18 has provided us with personal information without their consent, please contact us immediately at [email protected]. We will investigate the matter promptly, delete any such information from our systems, terminate any associated access, and take steps to prevent future collection.

14. International Data Transfers

14.1 Data Location

Your personal information will be transferred to, processed, stored, and maintained in the United States of America. Our primary data centers and servers are located in the United States, specifically in AWS data centers that maintain SOC 2 Type 2 certification.

14.2 Cross-Border Transfers

If you access our Services from outside the United States: your information will be transferred to the United States; U.S. laws may differ from your country's laws; U.S. government authorities may access data under certain circumstances; and by using our Services, you consent to this transfer.

14.3 International Users

For EU/EEA Residents: We rely on appropriate safeguards for data transfers. Standard Contractual Clauses may apply to certain transfers. You may request information about safeguards by contacting us.

For UK Residents: Similar protections apply as for EU/EEA residents. We comply with UK GDPR requirements where applicable.

For Canadian Residents: We comply with PIPEDA requirements. You may file complaints with the Privacy Commissioner of Canada.

14.4 Data Localization

We do not currently offer data localization options. All data is processed and stored in the United States, regardless of where you are located.

15. External Links and Features

15.1 Third-Party Websites

Our Site and Services may contain links to third-party websites, including payment processor portals, fund administration platforms, government agency websites (IRS), industry association sites, and educational resources.

15.2 No Liability for Third-Party Practices

We are not responsible for the privacy practices, content, or security of third-party websites. These sites have their own privacy policies and terms of use. We encourage you to review their policies before providing any personal information.

15.3 Integrated Services

Some third-party services are integrated into our platform. These integrations are governed by our agreements with third parties. We share only the minimum information necessary. You may need to agree to third-party terms to use certain features.

15.4 Social Media

We maintain presence on social media platforms. Our social media pages are governed by the platforms' policies. Information you provide on social media is public. We may respond to public posts or direct messages. Social media interactions are not covered by this Policy.

16. Security

16.1 Security Program Overview

We have implemented and maintain comprehensive administrative, technical, and physical security measures designed to protect personal information against unauthorized access, use, loss, alteration, disclosure, and destruction. Our security program is based on industry standards and best practices, including SOC 2 Type 2 certification requirements.

16.2 Technical Safeguards

Encryption: Data at rest is protected with AES-256 encryption. Data in transit uses TLS 1.2 or higher. We employ industry-standard key management practices and maintain encrypted backups and archives.

Access Controls: We implement role-based access control (RBAC), principle of least privilege, multi-factor authentication for administrative access, strong password requirements, session timeout controls, and IP whitelisting capabilities.

System Security: We maintain firewalls and intrusion detection systems, regular security patches and updates, malware and antivirus protection, security information and event management (SIEM), network segmentation, regular vulnerability assessments, and annual penetration testing.

16.3 Organizational Safeguards

Personnel Security: We conduct background checks for employees with data access, require confidentiality agreements for all personnel, provide regular security awareness training, and deliver role-specific security training.

Policies and Procedures: We maintain written information security policies, incident response procedures, change management processes, a vendor management program, risk assessment procedures, business continuity planning, and disaster recovery planning.

16.4 Physical Safeguards

Data Center Security (AWS): Client Data is hosted in SOC 2 Type 2 certified facilities with 24/7 security monitoring, biometric access controls, security cameras and recording, environmental controls for temperature and humidity, fire suppression systems, redundant power systems, and geographic redundancy.

16.5 Security Limitations

Despite our efforts, no security measures are perfect or impenetrable. We cannot guarantee the absolute security of personal information. You acknowledge and accept the inherent security risks of providing information online and will not hold us responsible for breaches of security unless they result from our gross negligence or willful misconduct.

16.6 Your Security Responsibilities

You play a crucial role in maintaining security: use strong, unique passwords; enable multi-factor authentication when available; keep login credentials confidential; log out after each session; report suspicious activity immediately; keep your devices and software updated; and use secure networks when accessing the Services.

17. Data Breach Notification

17.1 Incident Response

In the event of a Security Incident involving personal information, we will immediately initiate our incident response plan, investigate and contain the incident, assess the nature and scope of the breach, identify affected individuals and data types, implement remediation measures, and document all response actions.

17.2 Notification Procedures

For Licensee Firms: Notification within 48 hours of discovery, detailed incident report within 5 business days, regular updates throughout investigation, final report with remediation measures, and assistance with regulatory notifications.

For Invited Users: Notification through the Licensee Firm that invited them, direct notification if required by law, information about the incident and affected data, steps taken to address the breach, and recommendations for protective measures.

17.3 Regulatory Compliance

We will comply with all applicable breach notification laws, including state breach notification requirements, CCPA breach provisions, industry-specific regulations, and international requirements (GDPR, etc.).

17.4 Cooperation and Support

Following a breach, we will cooperate with regulatory investigations, provide necessary documentation, support affected individuals, offer credit monitoring services where appropriate, and implement additional security measures.

18. Automated Decision-Making

18.1 Use of Automated Systems

We use automated systems and artificial intelligence for certain processing, including Asset Test calculations and Filing Package, Information Return, and Investor Statement generation, fraud detection and prevention, system security monitoring, and performance optimization.

18.2 Human Oversight

Important decisions affecting individuals always involve human review, including final Filing Package approval by Licensee Firms, account suspension or termination, and compliance determinations.

18.3 Your Rights

You have the right to request information about automated processing, request human review of automated decisions, contest decisions based solely on automated processing, and opt-out of certain automated processing where applicable.

19. Marketing and Communications

19.1 Marketing Communications

Types of Marketing: Product announcements and updates, industry news and compliance alerts, webinar and event invitations, educational content and resources, customer success stories, and promotional offers for qualified businesses.

Legal Basis: Consent (where required), legitimate interests (B2B marketing), and existing customer relationship.

19.2 Communication Preferences

You can manage your preferences through the email preference center in account settings, unsubscribe links in all marketing emails, contact preferences for different message types, and frequency settings for various communications.

19.3 Transactional Communications

You cannot opt-out of certain essential communications, including security alerts and breach notifications, account verification and authentication, payment and billing notices, service availability and maintenance notices, legal and compliance updates, and terms and policy changes.

19.4 Do Not Contact

If you wish to be added to our do-not-contact list, email [email protected]. Include all email addresses and phone numbers, specify types of communications to block, and allow 10 business days for processing.

20. Changes to this Policy

20.1 Policy Updates

We may modify this Policy from time to time to reflect changes in our data practices, new features or services, legal or regulatory requirements, industry standards and best practices, and user feedback and concerns.

20.2 Notice of Changes

Material Changes: 30 days advance notice via email, prominent notice on our website, in-app notifications for active users, summary of key changes, and option to review changes before they take effect.

Non-Material Changes: Updated Policy posted on website, "Last Updated" date changed, and changes effective immediately upon posting.

20.3 Acceptance of Changes

Your continued use of the Services after changes become effective constitutes acceptance of the modified Policy. If you do not agree with changes: Licensee Firms may terminate according to their Platform Services Agreement; Invited Users should not submit information through the Services; and you may exercise applicable data rights including deletion and portability.

20.4 Version History

We maintain a version history of this Policy. Previous versions are available upon request. We maintain a changelog documenting significant updates and archived versions for compliance purposes.

21. Contact Us

21.1 Privacy Contact Information

If you have any questions, concerns, requests, or complaints regarding this Policy or our privacy practices, please contact us:

Privacy Team: Email: [email protected] Hours: Monday–Friday, 9:00 AM – 6:00 PM ET

Mailing Address: Advalis Inc. Attn: Privacy Department 270 S. Central Blvd, Suite 205 Jupiter, FL 33458

21.2 Response Commitment

We are committed to addressing your privacy concerns. We provide acknowledgment within 5 business days, substantive response within 30 days, escalation procedures for complex issues, and multiple language support available.

21.3 Regulatory Authorities

You may also contact relevant privacy authorities:

United States: Federal Trade Commission at www.ftc.gov, State Attorneys General offices, and the Consumer Financial Protection Bureau at www.consumerfinance.gov.

European Union: Your local Data Protection Authority or the European Data Protection Board at www.edpb.europa.eu.

Other Jurisdictions: Please contact us for information about authorities in your jurisdiction.

Thank you for trusting Advalis Inc. with your personal information. We are committed to protecting your privacy and maintaining the security of your data.

This Privacy Policy is effective as of July 29, 2026.