Privacy Policy
1. Who we are
Pennant One is a brand governance and content execution platform operated by Statement Branding and Advertising LLC (“Statement Branding,” “we,” “us”), a limited liability company registered in New Jersey. Pennant One is a product name; Statement Branding and Advertising LLC is the legal entity responsible for this service.
Contact: hello@pennantone.com · 4 Riverview Terrace, Hillsborough, New Jersey 08844
2. Scope
This policy covers the Pennant One platform, including its web application, its ingestion of institutional material, and its integrations with third-party publishing channels.
Pennant One is a business-to-business service used by educational institutions and their communications staff. It is not directed to children and is not used to collect information from students.
3. Our role: controller and processor
We act in two capacities:
- As a controller, for account and platform data belonging to the individuals who use Pennant One — school staff, agency personnel, and administrators.
- As a processor, for institutional material and brand content that a client organization provides to or authorizes us to ingest. The client organization remains the controller of that material. We process it only on their documented instructions and for the purpose of operating the service on their behalf.
4. What we collect
- Account data. Names, work email addresses, organizational affiliation, role, and authentication credentials for platform users.
- Institutional and brand material. Documents, publications, website content, and other materials a client provides for brand ingestion, or that we scan from client-owned public web properties at the client's direction.
- Generated content and review history. Content produced by the platform, together with approval, decline, and edit records created by human reviewers.
- Integration credentials. OAuth tokens and connection metadata for third-party channels a client authorizes (for example, LinkedIn Pages, Meta Business accounts, email service providers, and content management systems).
- Usage and technical data. Log data, IP address, browser and device information, and platform activity records.
- Performance and analytics data. Aggregate engagement and delivery metrics from connected channels — such as impressions, reach, opens, clicks, and page views — used to measure how published content performs. We collect this in aggregate or de-identified form. We do not track or store the behavior of individual recipients; per-recipient personalization and tracking, where a client uses it, occur in the client's own systems, outside Pennant One.
5. What we do not collect
Pennant One is designed to operate without student data.
We do not require, request, or process student records, grades, attendance, health information, disciplinary records, or family contact information. Content generated by Pennant One is produced in template form using merge fields; personalization with individual recipient data occurs downstream in the client's own systems of record, outside Pennant One. Where we collect performance analytics from connected channels, we do so at the aggregate level and do not build or store individual-level engagement profiles.
Where institutional material provided for ingestion incidentally contains personal information, we process it solely under the client's instructions and do not use it to build profiles of individuals.
6. Data isolation between clients
Each client organization's data is maintained in a separate, dedicated data set.
Brand specifications, ingested material, generated content, and review and edit history belonging to one client are not shared with, combined with, made available to, or used to improve services for any other client. There is no cross-client pooling of data, and no client's material contributes to outputs produced for another client.
7. How we use information
We use information to operate and provide the platform; to ingest and structure a client's brand identity; to generate content governed by that client's brand specification; to route content through human approval; to publish approved content to channels the client has authorized; to maintain audit and provenance records; to secure the service and prevent abuse; and to comply with legal obligations.
Human review is a required step. Pennant One does not publish content to any connected channel without approval by an authorized user.
8. Artificial intelligence processing
Pennant One uses Anthropic's commercial API to generate and evaluate content. Client material submitted for processing is transmitted to Anthropic as a subprocessor.
Under Anthropic's Commercial Terms, Anthropic may not train its models on customer content submitted through its commercial services, and inputs and outputs are deleted from Anthropic's backend systems within 30 days by default. Statement Branding does not use client material to train any model, and does not use one client's material to improve outputs for another.
9. Third-party channel integrations
Where a client authorizes a connection to a publishing channel, we request only the permissions necessary to publish approved content and, where applicable, retrieve performance data.
We store access tokens encrypted. Clients may revoke a connection at any time through the platform or directly through the third-party provider. Content published to a third-party platform becomes subject to that platform's own terms and privacy practices.
10. Subprocessors
We use third-party service providers to operate the platform, including cloud hosting and infrastructure, AI model processing, and the channel integrations a client authorizes. We require subprocessors to maintain appropriate confidentiality and security protections. A current list of subprocessors is available on request.
11. Data location
Data is stored and processed in the United States. We do not currently offer regional data residency options.
12. Retention
We retain client material and generated content for the duration of the client relationship and for a defined period thereafter as set out in the applicable service agreement. On termination, we delete or return client data in accordance with that agreement. Account and log data is retained as needed for security, audit, and legal purposes.
13. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle, including encryption in transit and at rest, access controls, credential isolation, and audit logging of approval and publishing actions.
No system is perfectly secure. In the event of a breach affecting client data, we will notify the affected client without undue delay and cooperate with their notification obligations.
14. Your rights
Individuals whose personal information we hold as a controller may request access, correction, or deletion of that information by contacting us at hello@pennantone.com.
For material we process on behalf of a client organization, requests should be directed to that organization as the controller. We will assist our clients in responding to such requests.
15. Children's privacy
Pennant One is a professional tool used by institutional staff. It is not directed to children, and we do not knowingly collect personal information from children. Client organizations are responsible for ensuring that material submitted for ingestion does not include student personal information.
16. Changes
We may update this policy. Material changes will be communicated to clients, and the “last updated” date above will be revised.
17. Contact
Statement Branding and Advertising LLC
4 Riverview Terrace, Hillsborough, New Jersey, 08844
hello@pennantone.com
Related: Terms of Use · Security Statement