Privacy Policy & Privacy Notice
Privacy Policy
(Regulation P / Gramm-Leach-Bliley Act Privacy Provisions)
Privacy Policy Purpose
It is the policy of Grand Bank for Savings, FSB aka Grand.bank® (the “Bank”) to fully comply with any applicable federal, state, and local laws and agency guidance that govern the protection of consumer nonpublic personal information (“NPI”), including Regulation P that implements the privacy provisions of the Gramm-Leach-Bliley Act (“GLBA”) (together, “Privacy Laws”), and includes providing privacy notices and the right for consumers to opt out of certain disclosures, as stated in this Policy and the Procedures developed to comply with this Policy. NPI does not include information reasonably believed to be publicly available. This Policy applies to the Bank across all business endeavors, including all activities and financial products primarily for personal, family or household purposes related to bank accounts, lending, including loans and lines of credit, and credit card issuance.
Definitions
Words and terms in this Policy are defined either in this Policy, in the law relevant to this Policy, or by their plain meaning. For clarity, first look to see if the definition is in this Policy. If not, look at the specific law(s) governing this Policy, and if not in the law, then the plain meaning (which can include the meaning of the word in the dictionary). If necessary, Procedures under this Policy will include the definitions of words and terms used within the Procedures.
Privacy Compliance Program
The Bank will establish a system of internal controls, programs, and self-correction to ensure compliance with the Privacy Laws, including evaluating Procedures, reviewing notices and disclosures, and utilizing random sampling and transaction testing, as applicable.
Enforcement by the Chief Compliance Officer
The Chief Compliance Officer (“CCO”) is responsible for the Bank’s overall compliance program and has the authority to enforce the Privacy Policies and Procedures. The CCO will report quarterly to the Bank Audit and Compliance Committee about any material or significant changes to the Procedures and give an annual report of the Privacy compliance program to the entire Board of Directors (the “Board”).
Personnel Training
The CCO will ensure that all personnel involved in loan origination, bank accounts, credit card issuance, and the hiring of employees, including executive officers, periodically receive Privacy training. The Compliance Department will maintain records of all Privacy training.
Independent Testing
The CCO will perform annual independent testing of the Bank’s Privacy compliance program to evaluate the overall integrity and effectiveness of the Privacy compliance program. The audit will utilize transaction testing where applicable and cover Policies, Procedures, risk assessments, training, and required reporting, and result in a final report containing management responses. The CCO will present the final report directly to the Board. The Bank may engage an independent third party to perform the audit/an additional audit.
Disclosure Templates
For compliance purposes under this Policy, the Bank will use disclosure templates, model forms, and model reports published by the federal regulatory agencies where applicable, when available, and when deemed a safe harbor. For any third-party or Bank developed disclosures and forms, the CCO will periodically perform a compliance analysis against federal requirements, and the Legal Department will confirm if these disclosures and forms meet the requirements of applicable federal law.
Procedures
The CCO and the business will draft Procedures and controls as necessary in accordance with federal law and this Policy for review and approval by the Management Compliance Committee. The Procedures will implement and support the requirements and prohibitions of the Privacy Laws and this Policy and provide consistent and uniform administration and operational control in matters related to or governed by the Privacy Laws and this Policy.
Recordkeeping
The Bank will maintain physical or electronic records relevant to Privacy compliance for the period of years listed in the Record Retention Policy and Procedures of the Bank.
Updated 09.2026