Birch Hill Birch Hill
How It Works Security Pricing Docs Blog About
Sign In Request Access
How It Works Security Pricing Docs Blog About
Sign In Request Access

Legal

Privacy Policy

Effective July 1, 2026  ·  Last updated July 1, 2026

1. Introduction

Birch Hill, Inc. ("the Company," "we," "us," or "our") operates birchhiil.com and the Birch Hill cross-border settlement platform (collectively, the "Service"). The Service provides AI-assisted settlement infrastructure to corporate treasury teams: it routes and settles cross-currency institutional payments on stable rails, auto-reconciles each settlement leg, and generates structured compliance trail documentation for every wire processed.

The Service is a business-to-business platform. The individuals whose information we process are primarily our customers' authorized treasury personnel and the employees or agents acting as counterparties to payments processed on customers' behalf. This Privacy Policy describes what information the Company collects in connection with the Service, how we use and share it, and the rights available to individuals whose information we process.

This Policy addresses US federal privacy requirements and Florida general privacy requirements, including the Florida Digital Bill of Rights (FDBR), which are described in Section 9. We also extend California Consumer Privacy Act rights to California residents as described in Section 9.5.

We are based at 701 Brickell Avenue, Suite 1550, Miami, FL 33131, and can be reached at [email protected].

2. Information We Collect

2.1 Business Account and Onboarding Information

When a company onboards to the platform, the Company collects business identification details including the customer company's legal name, registered address, and tax identification numbers provided for regulatory screening. We also collect information about the authorized treasury personnel who access the platform on the customer's behalf: names, business email addresses, job titles, and assigned access roles (such as initiator, approver, or auditor).

2.2 Payment Instruction and Transaction Data

To route and settle cross-border payments, we receive and process payment instruction data submitted by customers: beneficiary account identifiers (IBAN, SWIFT/BIC, account number and routing code), originator information, currency pairs, payment amounts, value dates, and transaction reference identifiers. After each payment settles, the Service automatically generates a structured compliance trail record that includes the routing path selected, leg-by-leg timestamps, the FX rate applied, originator and beneficiary details as submitted, and the settlement confirmation reference. These compliance trail records are integral to the Service and are retained to support treasury audit obligations and applicable financial regulatory requirements.

2.3 Reconciliation and Exception Metadata

The automated reconciliation layer produces metadata about each settlement leg, including break flags and exception records. This data is surfaced to authorized treasury personnel within the platform portal to support period-close accuracy. It is not used for any purpose unrelated to settlement operations and reconciliation.

2.4 Platform Access and Security Logs

The Service records technical access information to support security monitoring and the immutable audit log: IP address, browser type, device identifiers, session timestamps, and the specific actions taken by each authorized user within the platform. These logs are maintained as an append-only record and cannot be modified after recording.

2.5 Website Visitor Information

When you visit birchhiil.com outside the authenticated platform, we automatically collect limited technical information: IP address and approximate city-level location, browser type and operating system, pages visited, referring URL, and time on page. See Section 5 for details on cookies used on the website.

2.6 Contact Inquiries

If you contact us via a web form, email, or phone, we collect the information you provide, including your name, business email address, company name, and the content of your message.

2.7 We Do Not Knowingly Collect Children's Data

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact [email protected] and we will delete it.

3. How We Use Information

We use the information collected through the Service to:

  • Route, execute, and settle cross-border payments on behalf of customer treasury teams across supported corridors;
  • Generate the compliance trail documentation attached to each settled wire, including routing path, leg-by-leg timestamps, FX rate applied, and settlement confirmation reference;
  • Perform automated reconciliation and surface payment exceptions to authorized treasury personnel before period close;
  • Maintain the immutable audit log required for treasury operations and regulatory review;
  • Apply anti-money laundering screening and sanctions controls integrated into the payment routing layer;
  • Monitor platform security, investigate unauthorized access, and maintain access controls per assigned treasury roles;
  • Respond to support and sales inquiries and provide requested information about the Service;
  • Send service-related communications and, where required by applicable law and with your consent, marketing updates;
  • Comply with applicable financial regulations, anti-money laundering laws, and other legal obligations.

The Company does not use payment instruction data, compliance trail records, or transaction data to train machine learning or AI models. We do not engage in behavioral advertising. We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see the relevant state section below.

4. Sharing of Information

We share personal information only with:

  • Regulated financial infrastructure partners and correspondent institutions, to the limited extent necessary to route and settle individual payments submitted by customers on their own behalf;
  • Service providers acting on our behalf (including cloud infrastructure, security monitoring, and anonymized web analytics) under contractual confidentiality and data-processing agreements that restrict use to providing the contracted service;
  • Regulatory authorities, financial regulators, and law enforcement when required by applicable law, court order, or to protect the rights, safety, or property of the Company, its customers, or others;
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and reasonable notice to affected parties.

We do not sell personal information to third parties.

5. Cookies and Tracking

We use cookies and similar technologies on birchhiil.com to operate the site, support authenticated sessions within the platform portal, and measure anonymous usage. We do not use cookies for behavioral advertising or cross-site tracking. For full details and how to manage your preferences, see our Cookie Policy.

6. Data Retention

Transaction records and compliance trail documentation are retained for a minimum of seven years to satisfy treasury audit requirements and applicable financial regulatory retention obligations. Platform access and security logs are retained for 90 days and then aggregated into non-identifiable statistical records. Business account information for accounts that have been inactive for 36 months is reviewed and, where no legal hold applies, scheduled for deletion. Website inquiry and contact form data is purged after 24 months of inactivity. Public website server access logs are retained for 90 days and then aggregated.

7. Security

The Company applies administrative, technical, and physical safeguards designed to protect personal information and payment data: TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, least-privilege access controls for platform systems, role-based access segregation for authorized treasury users, and an append-only audit log that cannot be modified after recording. No security system is perfectly secure; the Company cannot guarantee absolute security. If you believe your platform credentials have been compromised, contact [email protected] immediately.

8. Your General Rights

Depending on your jurisdiction, you may have rights including the right to access personal information we hold about you, to correct inaccuracies, to request deletion, and to limit certain processing. To make a request, email [email protected]. The Company will respond within the timeframe required by applicable law. State-specific rights and procedures are described in the sections below.

9. Florida Residents (FDBR)

The Florida Digital Bill of Rights ("FDBR") gives Florida consumers the rights described below. The FDBR's main controller-obligation chapters apply primarily to large operators; the Company extends these consumer-rights provisions to all Florida visitors as a matter of policy.

9.1 Your FDBR Rights

  • Right to Confirm and Access personal data we process about you.
  • Right to Correct inaccuracies.
  • Right to Delete personal data we have collected from or about you.
  • Right to Data Portability where technically feasible.
  • Right to Opt Out of sale of personal data, targeted advertising, and significant-effect profiling. The Company does not engage in any of these activities.

9.2 Sensitive Data Consent

The Company does not knowingly process sensitive data within the meaning of the FDBR. If we ever begin to process such data, we will obtain consent first.

9.3 How to Exercise

Email [email protected]. We respond within 45 days; one 45-day extension is available with notice.

9.4 Appeal

You may appeal a denial by replying to our response. The Florida Department of Legal Affairs receives unresolved complaints.

9.5 California Visitors

If you are a California resident visiting from another state, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. The Company does not sell personal information and does not "share" personal information for cross-context behavioral advertising.

To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.

11. Contact

Questions, requests, or complaints can be sent to:

Birch Hill, Inc.
701 Brickell Avenue, Suite 1550
Miami, FL 33131
Email: [email protected]
Phone: +1 (305) 554-0163
Birch Hill

AI-assisted cross-border settlement infrastructure for corporate treasuries. Settle in minutes, comply by default. Angel-backed and built in Miami.

701 Brickell Avenue, Suite 1550 Miami, FL 33131 +1 (305) 554-0163 [email protected]
Platform
How It Works Security Pricing Docs API Reference
Company
About Blog Contact Privacy Policy Terms of Service Cookie Policy
© 2026 Birch Hill, Inc. All rights reserved. Built in Miami.
Privacy Terms Cookies Cookie preferences