Privacy Policy

Effective Date: February 2026 | Annual Review: February 2027

Lotus Oak Capital Institute (“L0CI,” “we,” “us”) is a registered investment adviser with the California Department of Financial Protection and Innovation (CRD #339053). This privacy policy describes how we collect, use, and protect personal information from both advisory clients and website visitors.

Scope: Client Data vs. Website Visitor Data

This policy addresses two distinct categories of personal information:

  • Client financial data is governed by the Gramm-Leach-Bliley Act (GLBA) and Regulation S-P (17 CFR Part 248). As a state-registered investment adviser, L0CI is subject to California’s implementation of these federal privacy requirements.
  • Website visitor data is governed by the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA, Cal. Civ. Code §1798.100 et seq.) and the California Financial Information Privacy Act (FIPA, Cal. Fin. Code §4050-4060).

Information We Collect

We may collect: identity information (name, address, email, phone, date of birth), financial information (income, net worth, investment objectives, risk tolerance, account numbers), website usage data (pages visited, browser type, IP address), and communication records related to advisory services.

How We Collect Information

  • Directly from you: When you engage us for advisory services, submit inquiries, or communicate with us
  • From third parties: Custodians, broker-dealers, or other financial institutions involved in your accounts
  • Automatically: Through standard web server logs when you visit our website
  • Through authorized third-party data aggregators: With your explicit consent, we use Plaid to obtain read-only access to your financial accounts (see “Third-Party Data Aggregation” below)

Third-Party Data Aggregation

Authorized Aggregator

L0CI engages Plaid Inc. (“Plaid”) as our authorized third-party data aggregator. With your explicit consent through Plaid’s connection flow, Plaid provides L0CI with read-only access to your bank, credit card, brokerage, and lending account data so that we can deliver investment-advisory services. Plaid is the only aggregator authorized at the time of this notice.

L0CI does not engage in screen-scraping. All data aggregation is performed via Plaid’s API integrations, including OAuth-based connections to participating financial institutions.

Scope of Data Accessed

With your explicit consent through the Plaid Link flow, L0CI may access:

  • Transactions — historical and ongoing account transaction history
  • Account verification (Auth) — account and routing numbers, only when needed for funding workflows you specifically request
  • Balance — current account balances
  • Investments — investment-account holdings, transactions, and securities metadata
  • Liabilities — student-loan, mortgage, and credit-card liability detail

You control which financial institutions and accounts are connected through the Plaid Link consent screen. You may decline any institution and may revoke any specific connection at any time.

Purpose Limitation

Plaid-aggregated data is used solely to provide investment-advisory services to you, including financial planning, cash-flow analysis, portfolio reconciliation, fee billing, and performance reporting.

L0CI commits in writing that we:

  • Do not sell, lease, license, or otherwise monetize Plaid-aggregated data to any third party
  • Do not use Plaid-aggregated data for credit decisioning, employment decisioning, insurance underwriting, or any “Furnisher” activity governed by the Fair Credit Reporting Act (FCRA)
  • Do not use Plaid-aggregated data for marketing or for cross-promotion of non-advisory services
  • Do not disclose Plaid-aggregated data to affiliates for non-advisory marketing purposes

These commitments are enforced contractually through our Plaid Master Services Agreement.

Data Retention for Plaid-Aggregated Data

  • Operational data (transaction records, balances, holdings) — retained while your advisory relationship with L0CI is active and, thereafter, for 7 years as a matter of firm policy. This exceeds the 5-year regulatory minimum for state-registered investment advisers under 10 CCR 260.241.3(e)(1) and SEC Rule 204-2.
  • Audit and access-log data — retained 7 years under the same firm-policy standard (the regulatory minimum is 5 years)
  • Plaid access credentials — encrypted at rest using AES-256-GCM with a domain-separated encryption key; revoked and zeroed when you disconnect an institution or terminate the advisory relationship

When you terminate the advisory relationship, your Plaid access tokens are revoked and zeroed. Operational and audit data are retained for the 7-year firm-policy period — the regulatory minimum is 5 years — unless your deletion request applies (see “Your Privacy Rights” in our Privacy Rights page).

Data Flow Summary

When you connect a financial account via Plaid Link:

  1. Your bank or financial institution authenticates you (typically via OAuth at the bank’s own login page)
  2. Plaid receives your authorization to share account data with L0CI
  3. Plaid relays the authorized data to L0CI over an encrypted (TLS 1.3) connection, with cryptographically signed webhooks for ongoing updates
  4. L0CI stores the data in our advisory platform and uses it solely for the purposes listed above

Your Plaid Connection Rights

You may at any time:

  • Revoke a Plaid connection — via the Plaid Portal at https://my.plaid.com/ OR by written request to the CCO
  • View what we have — request a copy of the Plaid-aggregated data L0CI holds about you (we respond within 45 days per CCPA §1798.110)
  • Request deletion — subject to records-retention obligations under 10 CCR 260.241.3(e)(1) and SEC Rule 204-2, which require L0CI to retain certain advisory and audit records for a regulatory minimum of 5 years (L0CI retains them for 7 years as firm policy); while a record is within an applicable retention period it is restricted from any further use
  • Correct your data — corrections of bank-side data must be raised with the originating institution; L0CI will correct any L0CI-generated derivative data upon written request

Requests should be sent to the Chief Compliance Officer at the contact channel published in our Form ADV Part 2A.

Compliance Framework

L0CI’s Plaid integration complies with:

  • 17 CFR Part 248 (Regulation S-P) — Safeguards Rule; initial and annual privacy notice
  • California Consumer Privacy Act (CCPA / CPRA) — Cal. Civ. Code §1798.100 et seq.
  • California Financial Information Privacy Act (FIPA) — Cal. Fin. Code §4050-4060
  • Dodd-Frank §1033 (CFPB Open Banking Rule) — consumer financial data access
  • California IA records retention rule — 10 CCR 260.241.3(e)(1) (5-year regulatory minimum; L0CI retains 7 years as firm policy)
  • Plaid Master Services Agreement — including its breach-notification, FCRA-non-applicability, and screen-scraping-prohibition obligations

How We Communicate With You

L0CI communicates with clients through secure, supervised channels that we can retain in compliance with our recordkeeping obligations: firm email (@lotusoak.capital), our encrypted document portal, telephone, scheduled video conference, and postal mail where required.

We do not communicate with clients via SMS or text message. L0CI does not initiate, solicit, or conduct advisory communications over SMS or consumer text-messaging applications. Please use the channels above — or contact the Chief Compliance Officer — for any advisory communication. This protects the security and confidentiality of your information and ensures your communications with us are properly retained.

Your Privacy Rights

Financial Information Privacy Act (FIPA)

Under the California Financial Information Privacy Act (Cal. Fin. Code §4050-4060), we will not share your nonpublic personal financial information with nonaffiliated third parties unless:

  1. We provide you with a clear and conspicuous notice describing the proposed sharing
  2. You provide opt-in consent through an affirmative action authorizing the sharing
  3. You are given a reasonable opportunity to withdraw consent before sharing occurs

Your FIPA rights: You have the right to control whether and how your financial information is shared with nonaffiliated third parties. We will never share your financial information without your prior affirmative consent.

CCPA/CPRA Consumer Rights

If you are a California resident, you have the following rights under the CCPA/CPRA:

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected, its sources, business purposes, and third-party recipients.
  • Right to delete: Request deletion of personal information, subject to certain exceptions including regulatory retention requirements.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt-out: Opt out of the sale or sharing of your personal information. L0CI does not sell personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise these rights, contact us at the address below. We will respond to verifiable consumer requests within 45 days.

Note: Certain personal information is exempt from CCPA/CPRA deletion requests when subject to regulatory retention requirements. For example, advisory agreement records are subject to a regulatory minimum retention of 5 years under California Code of Regulations Title 10, Section 260.241.3(e)(1) (and SEC Rule 204-2); L0CI retains such records for 7 years as a matter of firm policy.

Data Protection & Contact

Information Sharing Practices

We do not sell your personal information. We may share information only with service providers contractually required to protect it, regulatory authorities when required by law, and with your affirmative consent.

We require all service providers to maintain confidentiality and implement appropriate security measures.

Security of Your Information

We implement administrative, technical, and physical safeguards to protect your personal information, including encryption at rest (AES-256) and in transit (TLS 1.3), multi-factor authentication, least-privilege access controls with quarterly reviews, and continuous monitoring.

Data Retention

We retain personal information per applicable regulatory requirements. The regulatory minimum for most client records is 5 years under 10 CCR §260.241.3(e)(1) (and SEC Rule 204-2); L0CI retains such records for 7 years as a matter of firm policy. Website usage data is retained for 1 year minimum.

Contact Us

To exercise your privacy rights, ask questions about this policy, or file a complaint:

Lotus Oak Capital Institute Attention: Chief Compliance Officer Email: [email protected]

We will acknowledge your request within 10 business days and provide a substantive response within 45 days.


This policy is reviewed annually and updated as regulatory requirements change.

Version: 1.0 | Last Reviewed: 2026-03-03

Version Date Changes
1.0 2026-02-01 Initial version