Totalis Consulting Group, Inc.
Effective date: 15 August 2026 · Version 2.0
In short
We collect very little. If you contact us, we use your details to reply to you and to carry on that conversation. We do not sell your information, we do not rent or trade it, and we do not hand it to advertisers, data brokers or list vendors. Documents that a credit union puts into our TISEA platform belong to that credit union, are never used to train artificial intelligence models, and are governed by our contract with them rather than by this page.
The sections below set all of that out in full. This summary is for convenience; where it differs from the detail, the detail governs.
1. Who we are and what this policy covers
Totalis Consulting Group, Inc. (“Totalis,” “we,” “us,” “our”) is a company incorporated in the United States and based in Alpharetta, Georgia. We build and operate TISEA, an examination-readiness service for credit unions.
This policy covers the personal information Totalis collects and decides how to use — information you give us when you visit our website, submit a form, request a demonstration, email our support or security addresses, or apply for a role with us.
This policy does not cover the material a credit union uploads into the TISEA platform. That material belongs to the credit union. Totalis handles it strictly on that credit union’s instructions and under our written agreement with them, and that agreement governs it. Section 8 explains this in more detail. If you are an employee or a member of a credit union and you have a question about information held about you in TISEA, please ask your credit union.
Questions about this policy go to tiseasupport@totalis.com.
2. Information we collect
2.1 When you contact us
If you complete a form on our website, request a demonstration, or write to one of our email addresses, we receive:
- your name;
- your email address;
- the name of your organization or credit union;
- your telephone number, if you choose to give it;
- your job title, if you choose to give it; and
- whatever else you write to us, together with our correspondence back and forth.
2.2 When you apply for a role with us
If you apply for a position or send us a résumé, we receive the information you choose to provide — your name, contact details, work history, and anything else in your application or in our correspondence about it.
2.3 When you visit our website
Our website host and our website software record standard technical information automatically. This includes your IP address, the type of browser and device you are using, the pages you view, the page that referred you, and the date and time of your visit. We use this to keep the site running and secure and to understand which pages are useful.
2.4 Information we ask you not to send
We do not need, and we ask you not to send us, Social Security numbers, member or customer account numbers, payment card numbers, or account credentials. If you need to send us something sensitive, write to us first and we will arrange a secure method.
If you send us such information anyway, we will delete it once we have dealt with your request, unless we are required to keep it.
3. Cookies, analytics and Do Not Track
Cookies. Our website sets cookies that are necessary for the site to function. Where analytics or measurement tools are in use, those tools may also set cookies and may receive technical information such as your IP address. We use them to understand how our own website is performing.
Your control. You can block or delete cookies through your browser settings, or use a browser privacy extension. The site will still work, although some features may behave differently.
Do Not Track. Some browsers can send a “Do Not Track” signal. No common industry standard exists for how such signals should be interpreted, and our website does not currently respond to them.
Behavioral advertising. We do not run behavioral or cross-site advertising on this site, and we do not sell or share personal information for cross-context behavioral advertising.
4. How we use information
We use personal information to:
- reply to your enquiry and provide the support you have asked for;
- arrange a demonstration and follow up on it;
- continue a business conversation you have started with us, including telling you about our services;
- provide, operate and support TISEA for our customers;
- improve TISEA and our website using aggregated information that does not identify anyone;
- evaluate a job application and communicate with you about it;
- protect our systems and information, and investigate suspected misuse; and
- comply with our legal, regulatory and contractual obligations.
Marketing. If you would prefer not to hear from us, tell us and we will stop. Every marketing email we send includes a way to opt out, and simply replying to ask us to stop is always sufficient.
Telephone numbers. Where you give us a telephone number, we use it to reach you about the matter you raised. We do not use it for automated marketing calls or automated marketing text messages, we do not place it in an autodialer campaign, and we do not give it to anyone else for marketing. If we ever wish to send you a text message, we will ask you first.
Automated decisions. We do not use personal information to make automated decisions that produce legal or similarly significant effects about you.
5. When we disclose information
There are four circumstances, and only four, in which personal information covered by this policy leaves Totalis:
5.1 Service providers. We use a small number of established providers to run the business — cloud infrastructure, business email and collaboration, website hosting, and similar operational services. They act on our instructions, are bound by written terms that require them to protect the information, and may not use it for their own purposes. A current list of the providers we use is available on request.
5.2 Legal compulsion and legal protection. We may disclose information where the law requires it — for example in response to a subpoena, a court order, or a lawful request from a regulator — or where disclosure is necessary to establish or defend legal claims, or to protect the safety of any person.
5.3 Business transfer. If Totalis is involved in a merger, an acquisition, or a sale of all or part of its business, information may transfer as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
5.4 At your direction. Where you ask us to share something, or where sharing is an evident part of what you have asked us to do.
6. What we do not do
These commitments apply to all personal information covered by this policy.
- We do not sell personal information, and we have not sold personal information in the twelve months preceding the effective date of this policy.
- We do not rent, trade or barter personal information.
- We do not disclose personal information to advertisers, data brokers, list vendors or marketing partners.
- We do not share personal information for cross-context behavioral advertising.
- We do not use personal information to train or fine-tune artificial intelligence models, whether our own or a third party’s.
7. How long we keep information
Enquiries and support correspondence. We keep it while we deal with your request, and afterwards as a business record for as long as it remains useful to the relationship — ordinarily no more than twenty-four months after our last exchange with you. We then delete it, unless we are required to keep it for longer. You can ask us to delete it sooner.
Job applications. We keep applications for a reasonable period in case a suitable role arises. Ask us to delete yours and we will.
Technical and security logs. We keep them for a limited period for security monitoring and troubleshooting.
Customer information. We keep it for as long as the account is active, and afterwards for the period set out in our agreement with that customer. Section 8 explains what happens to material inside TISEA when an agreement ends.
Where we are required by law to keep something for longer, we keep it for that period and no longer.
8. Customer content in TISEA
When a credit union uses TISEA, it uploads its own examination documents, evidence and records. Totalis acts as that credit union’s service provider in respect of that material. Specifically:
- the material remains the credit union’s property;
- we process it only on the credit union’s instructions and only as our agreement with them permits;
- we do not use it for our own purposes;
- we do not sell it or share it; and
- we do not use it to train or fine-tune artificial intelligence models, whether our own or a third party’s.
Where TISEA uses an artificial intelligence service to analyse a document, the analysis is performed inside our own cloud environment and region. The service operates under contractual terms under which the content is not retained by the model provider, is not used to train foundation models, and is not accessible to the model provider.
When a customer agreement ends, material held in TISEA on that customer’s behalf is returned or deleted in accordance with that agreement. Where a current or former customer asks us to dispose of their data, we do so within thirty days, or on the timetable set out in their agreement, except where we are required by law to keep something for longer.
9. Financial institution customers
Our customers and prospective customers are credit unions, which are themselves subject to the Gramm-Leach-Bliley Act and to National Credit Union Administration requirements. Where Totalis handles information on behalf of a credit union, we do so as that credit union’s service provider, subject to the confidentiality and safeguarding obligations in our agreement with them. That agreement, rather than this policy, governs how such information is handled.
10. How we protect information
Totalis maintains a documented information security program, reviewed at least annually. Among other measures:
- information is encrypted in transit and at rest;
- access is granted only to personnel with a documented business need, and is reviewed on a scheduled basis;
- multi-factor authentication is required for company email, our code repositories and our cloud infrastructure;
- devices used to reach company systems run managed endpoint protection; and
- security events are handled under a written incident response plan.
If something goes wrong. Where we determine that personal information has been compromised, we investigate under our incident response plan and notify affected individuals, our customers, and any regulator, as and when applicable law and our agreements require.
No method of transmission or storage is entirely secure and we cannot guarantee absolute security. If you believe you have found a vulnerability, or that information has been exposed, tell us at security@totalis.com.
11. Your choices and rights
You may ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is inaccurate;
- delete what we hold, where we are not required to keep it;
- explain how we use it, including what we collect and to whom we disclose it; and
- stop marketing to you, at any time.
Making a request. Email tiseasupport@totalis.com. We will take reasonable steps to verify who you are before we act, and we will respond within the period applicable law allows. You may use an authorized agent to make a request on your behalf; we may ask for proof of that authority.
If you are not satisfied. Write to us again and ask that the matter be escalated to the President & Chief Executive Officer, who will review it personally. You also retain the right to raise it with your state Attorney General or another supervisory authority.
California residents. The California Consumer Privacy Act gives California residents the rights to know, to delete, to correct, and to opt out of the sale or sharing of personal information. As set out in Section 6, we do not sell or share personal information, so there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We will not discriminate against anyone for exercising a privacy right.
12. Children
Our website and our services are intended for businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under sixteen. If you believe a child has given us personal information, tell us and we will delete it.
13. Links to other websites
Our website may link to websites we do not operate. We are not responsible for their content or their privacy practices, and we encourage you to read the privacy policy of any website you visit.
14. Where information is held
Totalis operates from the United States, and the information we collect is processed and stored in the United States — except that a service provider may route or cache technical information through infrastructure located elsewhere in the course of delivering our website.
If you contact us from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from the law of your own country.
We do not currently offer our services in the European Economic Area or the United Kingdom, and we do not direct our website to individuals located there.
15. Accessibility of this policy
If you use assistive technology and have difficulty accessing this policy, write to tiseasupport@totalis.com and we will provide it in an alternative format.
16. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date shown at the top of this page, and where a change is significant we will give more prominent notice. We encourage you to review this page periodically.
17. How to contact us
Totalis Consulting Group, Inc.
Alpharetta, Georgia, United States
Privacy questions and requests: tiseasupport@totalis.com
Security reports and vulnerability disclosures: security@totalis.com
Privacy Policy v2.0 · Effective 15 August 2026 · Supersedes all prior versions.