Effective Date: 6/16/2026
1. Our Commitment to Privacy
Scope of this Policy. This Privacy Policy governs two things: (1) Bolero’s public marketing websites at www.bolerois.com and www.oneramp.com, and (2) Bolero’s direct business interactions, such as demo requests, marketing communications, and hiring. It does not govern data processing within Bolero’s hosted client environments. Data processing for institutional clients is governed by the applicable Master Services Agreement (MSA) and Data Processing Agreement (DPA) negotiated directly with each institution. End users who access Bolero’s software through their institution should contact that institution regarding data rights, not Bolero directly.
Bolero Information Systems, LLC (“Bolero,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you:
- visit our marketing websites (www.bolerois.com and www.oneramp.com);
- request information, a demo, or technical support;
- attend a Bolero-hosted event, webinar, or training; or
- use Bolero’s hosted research administration and grants management software and related services (the “Services”).
This policy is organized in two parts:
- Our Websites: How we handle information collected from visitors to our public marketing websites.
- Our Services & Institutional Data: How we handle data when providing our Electronic Research Administration (ERA) suite of services to our clients, who are typically institutions of higher education and research centers.
Our services are designed for faculty, researchers, and administrators to manage research grants, compliance, conflict of interest disclosures, and other aspects of research administration. Our platform does not typically process or store student educational records, though our staff is trained to understand regulations such as the Family Educational Rights and Privacy Act (FERPA).
Bolero’s Two Roles
Data Controller / Business: Bolero acts as a data controller for information collected through the Websites and direct business interactions (demo requests, marketing communications, hiring). Bolero determines the purposes and means of processing this information.
Data Processor / Service Provider: For Customer environments, Bolero generally acts as a data processor, processing Personal Data and Customer Data on the Customer’s documented instructions. The Customer is the data controller. If you are an end user (researcher, administrator, reviewer) and wish to exercise privacy rights regarding data in a Customer environment, please contact the Customer directly. Bolero will assist the Customer as required by contract and applicable law.
2. Information We Collect
A. Information You Voluntarily Provide
When you visit our public websites, we may collect personal information you choose to submit – for example, through a “Contact Us” or “Request a Demo” form. This may include your name, professional email address, phone number, job title, and institutional affiliation.
We will never ask for or collect your credit card information through our websites. Bolero is not a “financial institution” under the Gramm-Leach-Bliley Act (GLBA) and does not offer financial products or services to consumers. Although the Services may process employment compensation data (e.g., salary and effort on grant budgets) and researcher-disclosed financial interests (e.g., outside equity holdings or consulting income reported for conflict-of-interest review), this information is processed on behalf of Institutional Customers for research administration purposes and does not constitute “nonpublic personal information” of a consumer obtained in connection with a financial product or service as defined under GLBA.
B. Information We Collect Automatically
When you visit our websites, our servers may automatically collect non-identifying aggregate information, including:
- your IP address, which helps us ascertain your approximate geographic location;
- statistics about site usage, such as pages viewed, session duration, and referral source.
You can visit our websites without telling us who you are or revealing personal information about yourself.
C. Customer Data Processed on Behalf of Institutional Customers
Within client applications, Bolero processes data entered or uploaded by authorized users (researchers, faculty, staff, administrators, and other individuals designated by the Institutional Customer) on behalf of the Institutional Customer. The Institutional Customer determines what information is entered, by whom, and for what purpose. Categories of Customer Data may include, but are not limited to:
Personnel and Affiliation Data: Names, credentials, contact information, departmental affiliation, and role information for individuals identified in institutional workflows (e.g., investigators, key personnel, signatories, reviewers, approvers, and event participants).
Project, Award, and Agreement Data: Project descriptions, narratives, budgets, award and sub-award records, agreements (including sponsored research agreements, material transfer agreements, non-disclosure agreements, and similar instruments), and related supporting documentation.
Compliance and Disclosure Data: Information submitted in support of institutional compliance obligations, including conflict-of-interest and outside-activity disclosures (such as financial interests, outside employment, and time-commitment information); human and animal subjects research protocols; biosafety and other safety registrations; and export-control administrative metadata.
Workflow and Administrative Data: Information processed in routing, review, and approval workflows, which may include compensation, effort, and financial-disclosure information submitted by institutional personnel; registration, attendance, and survey-response information; and other records generated in the course of institutional administrative processes. Underlying financial transactions, where applicable, are handled by separate institutional systems of record.
Bolero may add, modify, or rename modules and features over time. New functionality that processes Personal Data on behalf of an Institutional Customer is governed by this Privacy Policy and the applicable Master Services Agreement (MSA) and Data Processing Agreement (DPA), without requiring republication of this policy unless the change introduces a materially new category of processing.
Specific data categories, processing purposes, and controller-processor obligations applicable to a particular Institutional Customer are set out in that Customer’s MSA and DPA.
3. Our Role with Institutional Data
Bolero acts as a data processor for our institutional clients. We provide a secure platform for them to manage their research administration data. The institution is the data controller and owns and directs the use of its data.
- Type of Data Processed: The data we process on behalf of our Institutional Customers is processed solely for the purposes specified by the Customer in the applicable Master Services Agreement, Statement of Work, and Data Processing Agreement, and as further described in Section 2C above.
- Purpose Limitation: We only use institutional data to provide and support the contracted services. We do not use this data for our own purposes, for marketing or business development, for selling or licensing data to third parties, or for training machine learning or AI models without the prior written consent of the Institutional Customer.
- Confidentiality: We are committed to maintaining the confidentiality and security of all institutional data in our care.
- Further detail regarding Bolero’s specific data processing obligations – including FERPA, GDPR, and other regulatory addenda- is set out in the applicable Master Services Agreement, Statement of Work, and Data Processing Agreement governing each institutional relationship. Institutional Customers requiring a Data Processing Agreement should contact privacy@bolerois.com.
4. How We Share Information
Bolero does not sell, rent, or trade Personal Information. Disclosure occurs only in the following limited circumstances:
- To Institutional Customers: Within a client application, Customer Data is accessible to authorized administrators and reviewers at the Institutional Customer consistent with the Customer’s roles and permissions configuration. Bolero does not independently share Customer Data with third parties except as directed by the Customer or permitted under the applicable DPA.
- To Subprocessors: Bolero shares data with third-party subprocessors to operate and deliver the Services. These vendors are contractually required to protect the data, use it only to provide services to Bolero, and comply with applicable privacy and security requirements. See Section 10.
- Legal Requirements: To respond to subpoenas, court orders, or other legal processes. Where legally permitted, Bolero will attempt to provide prior notice to the affected Institutional Customer before disclosing Customer Data.
- To Protect Rights: To establish or exercise our legal rights or defend against legal claims, and to protect the safety, rights, or property of Bolero, its customers, or the public.
- To Prevent Harm: When we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, threats to the physical safety of any person, or violations of our Terms of Use.
- Business Transfers: In the event of a merger, acquisition, or sale of substantially all of Bolero’s assets, Personal Information and Customer Data may be transferred as part of that transaction, subject to applicable law and confidentiality obligations. Bolero will notify Institutional Customers and require any successor entity to honor existing DPA commitments.
5. Cookies and Tracking Technologies
Bolero uses cookies solely for the operational function of its websites and client applications. We do not use cookies for behavioral advertising, cross-site tracking, or user profiling.
- Session and Authentication Cookies: Maintain authenticated user sessions within client applications. Expire upon logout or browser close.
- Security Tokens: Prevent cross-site request forgery (CSRF) and validate authenticated actions.
- Preference Cookies: Store interface preferences such as language and display settings.
Bolero does NOT use third-party advertising or retargeting cookies, web beacons, pixel tags, device fingerprinting, or cross-site analytics platforms. No third party collects behavioral tracking data from Bolero’s websites or services.
Your Choices: Most web browsers allow you to be notified when a cookie is sent and give you the chance to refuse it. Because Bolero’s cookies are strictly necessary for system operation, disabling them will prevent login to client applications.
6. Data Security
Bolero maintains an information security program designed to protect Personal Data and Customer Data using administrative, technical, and physical safeguards appropriate to the risks. Safeguards include:
- Encryption in Transit: Data transmitted between users and the Bolero platform is encrypted using TLS 1.2 or higher.
- Encryption at Rest: Customer Data stored in production databases and backup systems is encrypted using AES-256 or equivalent industry-standard algorithms.
- Access Controls: Role-based access controls (RBAC) restrict access to Personal Data to authorized personnel. Administrative access to production systems is privileged, monitored, and logged.
- Audit Logging: Bolero maintains audit logs of access to and modifications of sensitive data within client applications to support institutional compliance and incident investigation.
- Vulnerability Management: Bolero conducts regular vulnerability assessments and applies security patches on a risk-prioritized basis.
- Incident Response: Bolero maintains a documented incident response plan. See Section 11 for breach notification commitments.
- Employee Training: Bolero personnel with access to Personal Data receive periodic privacy and security awareness training.
- Subprocessor Security: Bolero contractually requires all subprocessors to maintain security standards appropriate to the data they process.
NOTE: No security system is impenetrable. Bolero cannot guarantee that Personal Information will never be accessed, disclosed, altered, or destroyed due to a breach of security measures. Unauthorized access to our Site is prohibited and punishable under applicable law. To report a security concern, contact: security@bolerois.com.
7. Sector-Specific Obligations
7.1 FERPA — Family Educational Rights and Privacy Act
Many of Bolero’s Institutional Customers are colleges and universities subject to FERPA (20 U.S.C. § 1232g; 34 C.F.R. Part 99). Bolero’s Services are designed for institutional administrative workflows and are not intended to function as a system of record for student “education records” as defined under FERPA. In most engagements, Bolero does not process education records.
To the extent that Personal Data processed through the Services nevertheless constitutes an education record under FERPA – for example, where a student is identified as personnel on a research project, listed in a research compliance protocol, or referenced in other institutional workflows – Bolero acts as a “school official” with a “legitimate educational interest,” as those terms are used in FERPA, under the direction of the Institutional Customer. In that capacity, Bolero:
- uses such records only to perform contracted services on behalf of the Institutional Customer;
- does not disclose such records to unauthorized parties;
- maintains security controls consistent with institutional requirements; and
- returns or destroys such records upon contract termination as directed by the Customer.
Customers control the design of forms and workflows used in the Services (including event registration and similar collection forms) and determine what information is collected, by whom, and for what purpose. Whether any data entered into the Services constitutes an education record under FERPA is a determination the Institutional Customer makes as the controller of that data. Institutional Customers are responsible for FERPA compliance generally, including providing required notices to students and obtaining necessary consents.
7.2 Human Subjects and Research Compliance Data
Bolero’s platform supports administrative workflows for IRB, IACUC, biosafety, radiation safety, and other research compliance processes. Bolero processes administrative metadata about research protocols and review workflows — for example, researcher identities, protocol descriptions, participant categories, review status, and approval records.
The Services are not designed to store the underlying research data itself. Customers should not upload to the Services, and the Services are not intended to function as a system of record for: signed informed-consent forms, completed survey or questionnaire responses from research participants, identifiable participant health information, raw research data sets, or other primary research records. Customers are responsible for storing and protecting such records in systems appropriate to their classification.
To the extent Customers nevertheless route information about research participants through the Services, Bolero processes such information strictly as a data processor under the direction of the Institutional Customer. Institutional Customers are responsible for:
- compliance with the Common Rule (45 C.F.R. Part 46), FDA regulations (21 C.F.R. Parts 50 and 56), and applicable institutional policies;
- obtaining informed consent from research participants before entering identifiable participant data into the platform;
- ensuring appropriate data use agreements are in place; and
- compliance with any other applicable regulations governing research data.
7.3 Export Control Compliance Metadata
Bolero’s platform captures administrative metadata about projects that may involve export-controlled materials or technologies (e.g., items subject to the Export Administration Regulations (EAR) or the International Traffic in Arms Regulations (ITAR)). Examples of administrative metadata include project descriptions, classification determinations recorded by the Institutional Customer, personnel screening status, foreign-national participation records, and approval workflow history.
The Services are not designed to store or transmit controlled technical data or technology itself. Customers should not upload to the Services, and the Services are not intended to function as a system of record for: technical drawings, schematics, source code, software, manufacturing or production information, or other technical data that is itself subject to EAR or ITAR controls. Customers are responsible for ensuring that no controlled technical data or technology is entered into the Services and for storing such material in systems appropriate to its classification.
Where personnel citizenship or nationality information is processed within the Services, it is processed for the Institutional Customer’s export-control review and screening workflow only. Bolero does not make export-classification determinations, issue or apply for export licenses, or perform deemed-export analyses on behalf of the Institutional Customer. Compliance with EAR, ITAR, and other applicable export-control regulations remains the responsibility of the Institutional Customer.
8. Data Retention
Bolero retains Personal Information only as long as necessary for the purposes described in this policy, including providing the Services, complying with legal obligations, resolving disputes, and enforcing agreements.
- Marketing Website Data: Contact form submissions and related correspondence are retained for no longer than necessary for the purposes described above, and reviewed periodically based on engagement activity.
- Customer Data: Retained for the duration of the applicable contract. Upon termination, Bolero’s standard practice is to provide the Institutional Customer a period to export their data; the specific duration of this post-termination export window is governed by the applicable Master Services Agreement and Data Processing Agreement. Following that period, Bolero will delete or destroy Customer Data in accordance with the DPA.
- Data Return and Backup Persistence: Bolero will return all Customer Data upon request from our production systems. While Bolero does not “surgically” remove individual data sets from encrypted system backups, such data may persist in secure archives following deletion from production systems for the period specified in the applicable Master Services Agreement and Data Processing Agreement to ensure disaster recovery and system integrity. During this retention period, the data remains protected by administrative, physical, and technical safeguards designed to prevent any unauthorized use or disclosure. Access to these backups is strictly limited and monitored, and data stored within them is not processed for any purpose other than restoration or legal compliance.
- Legal Hold: Bolero may retain data beyond standard periods when required by law, regulation, litigation hold, or regulatory investigation.
Federal grant regulations (e.g., 2 C.F.R. Part 200) may require Institutional Customers to maintain certain grant records for a defined number of years. Customers are responsible for ensuring that Bolero’s retention configurations satisfy their federal record-keeping obligations; Bolero will cooperate with retention extension requests under applicable DPAs.
9. Your Rights and Information Requests
Depending on applicable law and the context in which Personal Information was collected, individuals may have rights including:
- Access: Confirmation of whether Bolero processes your Personal Information and a copy of that data.
- Correction: Correction of inaccurate or incomplete Personal Information.
- Deletion: Deletion of Personal Information, subject to legal retention obligations.
- Portability: A copy of your Personal Information in a structured, machine-readable format.
- Restriction: Restriction of processing in certain circumstances.
- Objection: Objection to certain types of processing, including direct marketing.
For End Users of Client Applications
As a data processor, Bolero handles data under the direction of our institutional clients (the data controllers). If you are an individual (e.g., a faculty member or researcher) who uses our services through your institution and you wish to access, correct, or delete your data, you must submit your request directly to your institution. Bolero will act upon the verified direction of our client to facilitate your request.
For Marketing Website Contacts
To exercise rights regarding information submitted directly to Bolero via www.bolerois.com or www.oneramp.com, contact:
Email: privacy@bolerois.com
Mail: Bolero Information Systems, LLC
Attn: Privacy Officer,
P.O. Box 1332
Berthoud, CO 80513
Bolero has a Data Protection Officer (DPO) to oversee our privacy program and help facilitate these processes in coordination with our clients. Bolero will respond to verified requests within thirty (30) days for requests that are under our purview as data controller, requests sent to Bolero that are under purview of the data controller will be forwarded to the data controller without undue delay, typically within (5) days of receipt and answered only after direction from the data controller, or within the timeframe required by applicable law.
10. Subprocessors
All subprocessors are contractually bound to: (i) process data only as instructed by Bolero; (ii) implement appropriate technical and organizational security measures; (iii) assist Bolero in meeting its data protection obligations; and (iv) not engage further subprocessors without Bolero’s authorization.
| Subprocessor | Purpose | Data Type | Location |
|---|---|---|---|
|
AWS GovCloud |
Cloud infrastructure hosting; document file storage (S3); outbound email delivery (SES); AI/ML model integration for AI features (Bedrock – Q3 2026); |
Research data, personal data, document files, email content |
United States |
|
Rollbar |
Real-time application error tracking and exception monitoring |
System logs, error traces, user session data |
United States |
|
DocuSign |
E-signature document management – envelope creation, signing workflows, and signature status updates |
Personal identification, document content, signature data |
United States |
|
Slack |
Operational system status notifications to developers |
System operational messages |
United States |
Subprocessor Change Notification
Bolero will notify Institutional Customers of any material change to the subprocessor list at least thirty (30) days in advance via email or in-platform notice. Customers who object to a new subprocessor on documented and reasonable data protection grounds may submit written objection to privacy@bolerois.com. Bolero will work in good faith to address the concern, offer an alternative arrangement.
The current subprocessor list is maintained at: www.bolerois.com/trustcenter/
11. Breach Notification
Bolero maintains documented incident response procedures. If Bolero becomes aware of a confirmed security incident involving unauthorized access to, disclosure of, or loss of Personal Data or Customer Data, Bolero will:
- notify the affected Institutional Customer without undue delay and in accordance with the timeframe required by the applicable DPA and applicable law;
- provide available information about the nature of the incident, categories and approximate volume of data affected, likely consequences, and measures taken or proposed;
- cooperate with the Customer’s investigation and regulatory notification obligations; and
- take reasonable steps to contain, remediate, and prevent recurrence.
To report a potential security incident involving Bolero systems, contact: security@bolerois.com.
12. International Data Transfers
Bolero is based in the United States. Because Bolero’s Institutional Customers – universities and research organizations – routinely involve EU-based collaborators, visiting researchers, and international students, Personal Data about EU data subjects may flow through the Bolero platform as part of normal operations.
Bolero Article 27 Data Subject Requests
For Article 27 inquiries (data subject information requests) Bolero’s Data Representative in the EU and UK is DataRep. Please address any inquiries to DataRep using the appropriate address on our Data Protection Contacts List found at https://www.bolerois.com/DataRep_contact_locations.pdf.
Bolero as a GDPR Article 28 Processor
To the extent Bolero processes Personal Data of EU data subjects on behalf of an Institutional Customer that is established in the EU, or that is processing EU Personal Data in connection with offering services to EU residents, Bolero acts as a data processor under GDPR Article 28. In this capacity, Bolero commits to:
- process EU Personal Data only on documented instructions from the Institutional Customer (the data controller);
- ensure that personnel authorized to process EU Personal Data are subject to confidentiality obligations;
- implement appropriate technical and organizational security measures under GDPR Article 32;
- assist the controller in fulfilling data subject rights requests under GDPR Articles 12–23;
- assist the controller with security, breach notification, data protection impact assessments (DPIAs), and prior consultation obligations under GDPR Articles 33–36;
- delete or return all EU Personal Data upon termination of services as directed by the controller; and
- make available information necessary to demonstrate compliance and cooperate with audits and inspections.
Standard Contractual Clauses
For transfers of Personal Data from the EU to the United States on behalf of an Institutional Customer, Bolero will execute the EU Standard Contractual Clauses (SCCs) as the data processor, incorporated into the applicable DPA. Customers requiring SCCs should contact: privacy@bolerois.com
UK Data Transfers
For transfers of Personal Data from the United Kingdom, Bolero will rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable.
13. Children’s Privacy
Bolero’s websites and Services are not directed to individuals under the age of 16, and Bolero does not knowingly collect Personal Information from children under 16. If Bolero becomes aware that it has inadvertently collected information from a child under 16, it will take steps to delete such information promptly.
If a child under 16 sends us an email, we will use it only to respond and will not create a profile for the child or otherwise retain the information, except as needed to respond to the inquiry. If you believe we might have any information from or about a child under 16, please contact us at support@bolerois.com.
Institutional Customers operating programs that may involve minors are responsible for compliance with the Children’s Online Privacy Protection Act (COPPA) and applicable state laws.
14. Third-Party Websites
Our websites may provide links to external websites. The inclusion of a link does not imply our endorsement. We are not responsible for the privacy policies of these third-party sites and encourage you to review their policies directly. When you leave our site to visit a linked site, the only information transferred to the third party is the fact that you came from our site.
15. Governing Law
Disputes arising out of or related to your use of Bolero’s public marketing websites (www.bolerois.com and www.oneramp.com) or Bolero’s direct business interactions (such as demo requests, marketing communications, and hiring) shall be governed by and construed in accordance with the laws of the State of Nebraska, without regard to its conflict of law provisions. Any legal action or proceeding within that scope shall be brought exclusively in the federal or state courts located in Douglas County, Nebraska.
Disputes arising out of Bolero’s software services or Bolero’s relationship with an Institutional Customer are governed by the applicable Master Services Agreement between Bolero and that Institutional Customer; the governing law and venue provisions of that agreement control for those relationships.
16. Changes to This Privacy Policy
When material changes are made, Bolero will:
- update the Effective Date at the top of this policy;
- post the updated policy at www.bolerois.com/privacy-policy;
- notify Institutional Customers by email or in-platform notice at least thirty (30) days before material changes take effect; and
- where required by law or contract, obtain affirmative consent or provide opt-out rights.
- Note definition of material changes requiring notification:
- Material Change: Changes to the categories of data collected, third parties you share data with, or the purposes of processing (e.g., moving from “service delivery” to “AI training”).
- Non-Material: Fixing a broken link, correcting a misspelling, or updating the office address.
Continued use of the Services after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree, you must discontinue use and contact Bolero to arrange for data return or deletion.
17. Contact Us
If you have general questions about this Privacy Policy, please contact us at:
Privacy Officer – Bolero Information Systems, LLC
P.O. Box 1332
Berthoud, CO 80513
General privacy inquiries: privacy@bolerois.com
Security incidents: security@bolerois.com
DPA / GDPR requests: privacy@bolerois.com
Subprocessor list: www.bolerois.com/trustcenter/
Terms of Service: www.bolerois.com/terms
Privacy Policy (public URL): www.bolerois.com/privacy-policy
For requests regarding your personal data within our services, please contact your affiliated institution directly as noted in Section 9.