Legal Document

Privacy Policy

Effective Date: May 2, 2026  |  Last Reviewed: May 2, 2026  |  Version 2.0
Massachusetts 201 CMR 17.00 GDPR Compliant GLBA Notary Services M.G.L. c. 93H CCPA / CPRA
Plain-Language Summary We collect only the information needed to complete your notary service. We do not sell your data. We protect notary journal records under Massachusetts law. European residents have full GDPR rights. Contact us at any time to access, correct or delete your information.
Section 01

About This Policy

This Privacy Policy applies to Tewksbury Notary, operating as Neighborhood Parcel, located at 1215 Main St, Unit 115, Tewksbury, MA 01876 (“we,” “us,” “our”). It covers all services provided through this website and in person, including loan signing, apostille processing, I-9 verification, CORI form notarization, mobile notary service and all other notary public services we perform.

We operate as a Massachusetts commissioned notary public service. Hanson Webb holds his commission under the Commonwealth of Massachusetts and has operated continuously since 2007. This policy governs how we handle personal data in connection with notary acts, document handling, website use and client communications.

Laws Covered by This Policy This policy is written to comply with: Massachusetts M.G.L. c. 93H (data breach notification), Massachusetts 201 CMR 17.00 (protection of personal information), Massachusetts M.G.L. c. 66A (Fair Information Practices), the General Data Protection Regulation (GDPR, EU/UK), the Gramm-Leach-Bliley Act (GLBA, applicable to loan signing), the California Consumer Privacy Act (CCPA) as amended by the CPRA, and Massachusetts M.G.L. c. 222 (Notary Public Act).

By using this website or engaging our notary services, you acknowledge that you have read and understood this policy. If you do not agree, do not use this website or request our services. View our related Terms of Agreement for full service terms.

Section 02

Information We Collect

We collect information in three ways: directly from you during service requests, automatically through website technology and through third-party tools we use to operate our business.

Personal Identification Information

When you request a notary service, book an appointment or contact us, you may provide:

  • Full legal name as it appears on government-issued ID
  • Email address and phone number
  • Mailing address and service location address
  • Government-issued photo ID details (type, number, expiration date) for identity verification, as required under Massachusetts notary law
  • Signature (recorded in our notary journal as required by M.G.L. c. 222)

Document Information

The nature of notary work requires us to view and record details about the documents we notarize. This includes:

  • Document type (deed, affidavit, power of attorney, healthcare proxy, apostille request, CORI form, I-9, loan package, etc.)
  • Document date and parties named in the document
  • Notary journal entry as required by law and NNA best practice
  • Copies of documents only where you explicitly request copy certification

We do not retain the full content of documents we notarize unless you request copy certification or unless we are legally required to do so. Read the specific section on notary journal records for retention rules.

Financial and Mortgage Document Data

For loan signing and mortgage closing services, we may briefly handle documents that contain nonpublic personal financial information including loan amounts, property values, interest rates and lender information. We handle this data subject to the Gramm-Leach-Bliley Act safeguards described in Section 6.

Automatically Collected Technical Data

When you visit this website, we automatically collect:

  • IP address and general geographic location
  • Browser type, version and operating system
  • Device type (desktop, mobile, tablet)
  • Pages visited, time on page and referring URL
  • Cookie data (see Section 10)

This data is used to improve the website and is not linked to your service records without your consent.

Section 03

How We Use Your Information

We use your information only for the purposes listed below. We do not use your data for advertising, profiling or sale to third parties.

Purpose Data Used
Complete your notary service appointment Name, ID details, document type, address
Maintain the notary journal as required by Massachusetts law Name, ID type, signature, document type, date
Confirm appointments and send service receipts Name, email, phone
Process payment through our payment processor Payment details (held by processor, not us)
Respond to inquiries and customer support requests Name, email, message content
Comply with legal obligations (court orders, subpoenas) Whatever is legally required
Analyze website usage to improve our services Anonymous technical data, cookies
Defend against legal claims or complaints Service records, journal entries
We do not sell, rent or trade your personal information. This applies to all categories of data we hold, including notary journal entries, loan document details and contact information. We never have and never will sell client data.
Section 04

Legal Basis for Processing (GDPR)

For clients located in the European Union, the United Kingdom or the European Economic Area, we identify a specific lawful basis for each category of data processing under Articles 6 and 9 of the General Data Protection Regulation.

Processing Activity Lawful Basis (GDPR Article 6)
Performing the notary service you requested Article 6(1)(b): Contract performance
Maintaining the notary journal as legally required Article 6(1)(c): Legal obligation
Processing payment Article 6(1)(b): Contract performance
Responding to legal requests and defending claims Article 6(1)(c): Legal obligation / Article 6(1)(f): Legitimate interests
Website analytics and improvement Article 6(1)(a): Consent (cookie consent) / Article 6(1)(f): Legitimate interests
Marketing and follow-up communications Article 6(1)(a): Consent (opt-in only)
GDPR Data Controller Identification Tewksbury Notary, operating as Neighborhood Parcel, is the Data Controller for all personal data processed through this website and in connection with our notary services. We do not currently appoint a separate Data Protection Officer (DPO), as our processing volume and type do not trigger the mandatory DPO requirement under GDPR Article 37. European residents may address data inquiries to info@tewksburynotary.com.

Where we rely on legitimate interests (Article 6(1)(f)), those interests are: operating a lawful notary business, defending against legal claims and maintaining records that protect both clients and the notary. We have balanced these interests against your rights and concluded they do not override your fundamental rights to privacy.

Section 05

Notary Journal and Records

Massachusetts notary law (M.G.L. c. 222) and NNA best practice require us to maintain a notary journal of every notarial act we perform. This is a legal record, not optional. The journal is the primary evidence that a notarization occurred correctly.

What the Journal Contains

  • Date, time and location of the notarial act
  • Type of notarial act performed (acknowledgment, jurat, oath, copy certification, etc.)
  • Description of the document (type and date only, not full content)
  • Full name of each signer as it appears on their ID
  • Type and identifying details of the ID presented
  • Signer’s signature as recorded in the journal
  • Fee charged, if any

Your Rights Over Journal Entries

Because the notary journal is a legal record, your right to deletion does not apply to journal entries. We are required to maintain these records as evidence of proper notarial procedure. However, you may request access to your own journal entry by contacting us at info@tewksburynotary.com.

Massachusetts law does not specify a mandatory retention period for the notary journal. We follow NNA best practice and retain journal records for a minimum of 10 years following the date of the last entry in that journal.

Legal Authority for Journal Retention Journal records are maintained under M.G.L. c. 222, the NNA Notary Best Practices Guidelines and MISMO standards for loan signing agents. They are not subject to deletion requests but remain confidential. We do not share journal entries except when required by court order, subpoena or legal investigation.

For specific services, we also retain records under the following authorities: I-9 records under 8 U.S.C. 1324a (federal employment eligibility law), CORI form records under Massachusetts M.G.L. c. 6, Section 172, and apostille records under Hague Convention documentation standards. See the full retention schedule in Section 9.

Section 06

Loan and Mortgage Document Data (GLBA)

When we perform loan signing services for mortgage closings, refinances and HELOCs, we act as a notary signing agent in conjunction with a Massachusetts-licensed attorney or lender. During this process, we may handle closing packages that contain nonpublic personal financial information (NPI) as defined under the Gramm-Leach-Bliley Act (GLBA), 15 U.S.C. 6801 et seq.

Important: Scope of Our Role Massachusetts law (M.G.L. c. 222, Section 17 and Executive Order 455) requires that real estate closings be conducted by a licensed Massachusetts attorney. We provide notary signing agent support only. We do not conduct closings, draft legal documents or provide legal advice. See our full Terms of Agreement.

How We Handle NPI Under GLBA

  • We access loan documents only to the extent necessary to locate and notarize the correct signature pages
  • We do not copy, photograph, retain or transmit the contents of loan packages beyond what is required for the notarial act
  • Closing packages received electronically are handled through secure, encrypted channels provided by the title company or lender
  • Physical closing packages are stored securely and returned or destroyed immediately following the signing appointment
  • We do not disclose borrower financial information to any third party outside the transaction parties (lender, title company, attorney)
  • Our access to borrower NPI is governed by the data security requirements of our contracting title companies and lenders

Safeguards Program

In compliance with the GLBA Safeguards Rule (16 CFR Part 314, as updated in 2023), we maintain a Written Information Security Program (WISP) that applies to all loan signing work. The WISP covers access controls, encryption standards, employee practices and incident response procedures. This WISP is also required under Massachusetts 201 CMR 17.00.

Opt-Out Rights Under GLBA

The GLBA requires financial institutions to provide clients the right to opt out of sharing NPI with unaffiliated third parties. Because we do not share your NPI with any unaffiliated third party for marketing or commercial purposes, no opt-out mechanism is required beyond what this policy already provides. If your situation changes, contact us at info@tewksburynotary.com.

Section 07

Sharing and Third Parties

We share your information only in the limited circumstances below. In every case, we require that third parties protect your data to at least the standard required by this policy.

Circumstances Where We Share Data

  • Service providers: We use third-party tools for appointment booking, payment processing and website hosting. Each provider is bound by a data processing agreement. Current providers include our booking platform at hiremobilenotary.com, WordPress.com for website hosting and our payment processor. We do not grant these providers access to your data beyond what is necessary for their service.
  • Legal and regulatory requirements: We will disclose your information if required by a valid subpoena, court order, law enforcement request or regulatory demand. We will notify you before disclosure where legally permitted.
  • Transaction parties in loan signings: For loan signing work, the title company, lender and closing attorney are parties to the same transaction and already hold your NPI. We may confirm signing completion to these parties.
  • Defense of legal claims: We may disclose relevant records if we are required to defend against a legal claim, complaint or regulatory investigation related to a notarial act we performed.
  • Business transfer: If this business is ever sold or transferred, client records may transfer to the new owner, who will be required to honor this policy or provide you with advance notice of any change.

What We Never Do

  • We do not sell your information to data brokers, advertisers or any third party
  • We do not share your information for marketing by third parties
  • We do not share notary journal entries except when legally compelled
  • We do not share financial document content (NPI) outside the transaction parties

For questions about specific third parties we use, contact us at our contact page.

Section 08

Data Security

We maintain a Written Information Security Program (WISP) as required by Massachusetts 201 CMR 17.00. The WISP is a comprehensive, documented set of policies and procedures designed to protect the personal information of Massachusetts residents. All employees, contractors and service providers with access to personal data are bound by its terms.

Technical Safeguards

  • HTTPS encryption on all pages of this website
  • Encrypted transmission for all electronic data containing personal information
  • Secure, password-protected access to client records with unique user credentials
  • Firewall protection on all systems that store personal information
  • Secure, third-party payment gateways that hold payment card data (we do not store card numbers)
  • Regular review of access logs for unauthorized activity

Physical Safeguards

  • Physical notary journal stored in a locked location accessible only to authorized personnel
  • Physical closing packages handled and returned or securely destroyed immediately after each signing
  • Secure shredding for any paper documents containing personal information that reach end of retention

Organizational Safeguards

  • Access to personal data restricted to personnel who need it to perform their role
  • Annual review of the WISP and this Privacy Policy
  • Vendor agreements require equivalent data protection standards
Limitation of Liability Despite our technical and organizational measures, no system of data transmission or storage is 100% secure. We cannot guarantee that a breach will never occur. In the event of a breach affecting your personal information, we will notify you as required under M.G.L. c. 93H and GDPR Article 33/34. See Section 13 for breach notification procedures.
Section 09

Data Retention Schedule

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by applicable law. The schedule below applies to all categories of data we hold.

Data Category
Retention Period
Legal Authority
Notary journal entries
10 Years
NNA Best Practice / M.G.L. c. 222
I-9 verification records
3 Years Min
8 U.S.C. 1324a (federal law)
CORI form records
5 Years
M.G.L. c. 6, Section 172 / Best Practice
Loan signing records (completion confirmation)
10 Years
MISMO Standards / GLBA Safeguards Rule
Apostille and authentication records
7 Years
Hague Convention best practice
Client contact information (non-journal)
3 Years
MA limitations period / Business need
Website analytics data (anonymized)
26 Months
GDPR guidance / Google Analytics default
Payment records (transaction confirmation only)
7 Years
IRS / Massachusetts tax law
Correspondence and email records
3 Years
MA statute of limitations for contract claims

When data reaches the end of its retention period, we securely delete or destroy it. Paper records are shredded. Electronic records are permanently deleted from all active systems and backups on a scheduled basis.

If you submit a deletion request and the data is subject to a legal hold (for example, an active notary journal under mandatory retention), we will inform you which records we are legally required to keep and which we will delete.

Section 10

Cookies and Tracking Technologies

This website uses cookies and similar tracking technologies. A cookie is a small text file placed on your device that helps us recognize your browser on return visits and understand how you use our site.

Types of Cookies We Use

Cookie Type Purpose Can You Opt Out?
Strictly Necessary Required for the website to function. Session management and security. No (required for site operation)
Analytics Track page views, session duration and traffic sources to improve the site (Google Analytics). Yes
Functional Remember your preferences (language, region) between visits. Yes
Third-Party Set by embedded tools (booking widget, maps). Subject to third-party privacy policies. Yes

Managing Cookies

You can control cookies through your browser settings. Disabling analytics or functional cookies will not prevent you from using this site or booking our services. Disabling strictly necessary cookies may affect core site functions.

For European visitors, we obtain consent before placing non-essential cookies, in compliance with GDPR Article 6(1)(a) and the EU ePrivacy Directive. You may withdraw consent at any time by adjusting your browser settings or contacting us.

We do not use cookies to build advertising profiles, track you across unaffiliated websites or sell your browsing data to third parties.

Section 11

Your Privacy Rights

Your rights depend on where you live. We honor all rights listed below. To exercise any right, use the contact details in Section 16. We will respond within 30 days for Massachusetts and U.S. requests and within 30 days for GDPR requests (one extension of 60 days is permitted with notice).

Massachusetts Residents (M.G.L. c. 66A and 93H)

Massachusetts law gives you the following rights over personal information we hold:

  • Right to know: You may request a description of the categories of personal information we hold about you and the purposes for which we use it.
  • Right to access: You may request a copy of the personal information we hold about you, subject to the retention and legal hold exceptions noted in Section 9.
  • Right to correct: If we hold inaccurate information about you, you may request a correction.
  • Right to breach notification: Under M.G.L. c. 93H, we must notify you promptly if a breach of your personal information occurs. See Section 13.

European Union, United Kingdom and EEA Residents (GDPR)

If you are located in the EU, UK or EEA, you have the following rights under the General Data Protection Regulation:

GDPR Right What It Means Applies Here?
Right of Access (Art. 15) Request a copy of all personal data we hold about you Yes
Right to Rectification (Art. 16) Correct inaccurate or incomplete data Yes
Right to Erasure (Art. 17) Request deletion of your data where we have no legal obligation to retain it Yes (with exceptions)
Right to Restriction (Art. 18) Limit how we use your data while a dispute is resolved Yes
Right to Portability (Art. 20) Receive your data in a structured, machine-readable format Yes (for consent-based processing)
Right to Object (Art. 21) Object to processing based on legitimate interests Yes
Right to Withdraw Consent (Art. 7) Withdraw consent for any processing based on consent Yes (at any time)
Right to Lodge a Complaint File a complaint with your national data protection authority Yes

Note: The right to erasure does not apply to notary journal records we are legally required to maintain. We will tell you which records fall under a legal hold when you submit a deletion request.

California Residents (CCPA / CPRA)

  • Right to know: Request disclosure of the categories and specific pieces of personal information we collect, use, disclose and sell.
  • Right to delete: Request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to correct: Request correction of inaccurate personal information.
  • Right to opt out of sale or sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out form is required.
  • Right to limit use of sensitive personal information: We use sensitive information only to perform the services you requested. No limiting mechanism is needed beyond what this policy already provides.
  • Right to non-discrimination: We will not discriminate against you for exercising any CCPA right.

Residents of Colorado, Virginia and Connecticut

Residents of these states have rights comparable to those listed above under their respective state privacy laws (CPA, VCDPA, CTDPA). We honor access, correction, deletion, portability and opt-out rights for all U.S. residents, regardless of state. Contact us using the details in Section 16.

Section 12

International Data Transfers

Our primary operations are in Tewksbury, Massachusetts, USA. If you are located outside the United States, your personal data will be processed in the United States.

For clients in the European Union, United Kingdom or EEA, transferring data to the United States requires an appropriate legal safeguard under GDPR Chapter V. We rely on the following mechanisms:

  • Standard Contractual Clauses (SCCs): Where required, we enter into the European Commission’s approved SCCs with our service providers who receive EU personal data in the United States.
  • Adequacy Decisions: Where available, we rely on adequacy decisions issued by the European Commission.
  • Consent: For individual service requests from EU/EEA residents, we obtain explicit consent to transfer personal data to the United States for the purpose of performing the notary service requested (for example, apostille processing for documents going to EU member states).

You may request information about our data transfer mechanisms by contacting us at info@tewksburynotary.com.

For apostille services involving documents used in Hague Convention member countries, all document processing occurs in the United States and is submitted to the Massachusetts Secretary of State. No EU personal data is transferred to non-EU countries as part of the apostille process itself.

Section 13

Breach Notification

In the event of a breach involving your personal information, we will notify you and the appropriate authorities as required by applicable law.

Massachusetts Residents (M.G.L. c. 93H)

Under Massachusetts law, we must notify you of a breach of security involving your personal information as soon as reasonably possible. A “breach” under M.G.L. c. 93H means unauthorized access to or use of your personal information that creates a substantial risk of identity theft or fraud. We must also notify the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation.

GDPR Breach Notification (EU/UK/EEA Residents)

Under GDPR Articles 33 and 34:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms.
  • If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
  • Breach notifications to you will include: the nature of the breach, our contact information, likely consequences and the measures we are taking to address the breach.

How We Will Notify You

We will notify you by email using the address you provided, or by written notice to your mailing address if no email is available. If we cannot notify individuals directly at reasonable cost (for large-scale breaches), we will use a prominent notice on this website as permitted by law.

Reporting a Suspected Breach If you believe your personal information held by us has been compromised, contact us immediately at info@tewksburynotary.com or call 978-424-4629. We will investigate and respond within 2 business days.
Section 14

Children’s Privacy

Our notary services are intended for adults aged 18 and older. We do not knowingly collect or solicit personal information from anyone under the age of 13, and we do not knowingly allow children under 13 to use this website.

Exceptions apply for documents that involve a minor as the subject (not the signatory). For example, a minor travel consent form or a DS-3053 child passport application will name a minor, but the signing party is always an adult parent or guardian. In these cases, the minor’s information is recorded only to the extent necessary for the document’s legal purpose.

If you believe we have inadvertently collected personal information from a child under 13, contact us at info@tewksburynotary.com and we will delete that information promptly.

Section 15

Changes to This Policy

We review this Privacy Policy at least once per year and whenever we make material changes to how we collect or use personal data. If we make material changes, we will:

  • Update the “Effective Date” at the top of this page
  • Post the updated policy at tewksburynotary.com/privacy-policy/
  • Notify clients who have provided an email address when changes are material
  • For GDPR-covered clients, obtain fresh consent where the change affects consent-based processing

Continued use of this website or our services after the effective date of a revised policy constitutes acceptance of the revised policy for non-GDPR users. GDPR users will be asked to affirmatively confirm acceptance of material changes where consent is the lawful basis.

You can always view the current version of this policy on our website. For version history, contact us directly.

Section 16

Contact and Data Requests

To exercise any privacy right, submit a data request, ask a question about this policy or report a concern, use the contact details below. We verify your identity before processing requests that involve access to or deletion of personal data.

All requests are acknowledged within 2 business days. Final response is provided within 30 days. For GDPR requests, we respond within 30 days with an optional 60-day extension for complex requests, with notice.

Privacy Contact Information

We are here to help. Reach us by phone, email or in person at our Tewksbury office.

Business Name
Tewksbury Notary (Neighborhood Parcel)
Office Address
1215 Main St, Unit 115
Tewksbury, MA 01876
Phone
Submit a Privacy Request

Additional Resources

These pages provide related information that may answer your questions:

Regulatory Authorities

If you are not satisfied with our response to a privacy request, you have the right to contact the relevant authority:

  • Massachusetts: Office of Consumer Affairs and Business Regulation, mass.gov/ocabr, or the Massachusetts Attorney General’s Office at mass.gov/ag
  • European Union: Your national data protection authority. A full list is available at edpb.europa.eu
  • United Kingdom: Information Commissioner’s Office (ICO) at ico.org.uk
  • California: California Privacy Protection Agency at cppa.ca.gov
Legal Notice This Privacy Policy was last reviewed and updated on May 2, 2026. It is effective as of that date. This policy is published at tewksburynotary.com/privacy-policy/ and supersedes all prior versions. For questions about notary law compliance, consult a Massachusetts-licensed attorney. Tewksbury Notary operates as a notary public signing agent only and does not provide legal advice. See our Terms of Agreement for full service terms and limitations.