GDPR / Data Protection
This page describes our approach to data protection. Applicable legal obligations depend on the services, jurisdictions, and data processing activities involved.
Data protection principles
We aim to process personal data lawfully, fairly, and transparently; for specified purposes; with data minimization; with accuracy efforts; with storage limitation; and with integrity and confidentiality appropriate to risk.
Lawful bases
Depending on the activity, processing may rely on:
- Website inquiries — legitimate interests in responding to business requests, or steps toward a contract
- Client work — performance of a contract and related legitimate interests in delivering and supporting services
- Cookie preferences / optional analytics — consent, when those tools are enabled
- Legal compliance — legal obligation where applicable (for example tax or regulatory recordkeeping)
Data subject rights
Where GDPR or similar laws apply, individuals may have rights including access, rectification, erasure, restriction, portability, objection, and consent withdrawal.
- Access - request a copy of personal data we hold
- Rectification - correct inaccurate data
- Erasure - request deletion in certain circumstances
- Restriction - limit processing in certain cases
- Data portability - receive data in a structured format where applicable
- Objection - object to certain processing
- Consent withdrawal - where processing is consent-based
Access requests & exercising rights
Submit requests to [email protected]. We may need to verify identity before fulfilling a request.
Data processing
Processing activities are described at a high level in our Privacy Policy. For client projects where we act as a processor, a Data Processing Agreement (DPA) is available on request and may be included in the statement of work.
Data retention
We retain personal data only as long as needed for the stated purposes or as required by law. Website inquiries are generally kept up to 24 months after last contact unless a project or legal need requires longer retention.
International transfers
We operate from the United States. Personal data from visitors or clients outside the U.S. may be transferred to and processed in the United States. Where required, we use provider contractual safeguards and other lawful transfer mechanisms.
Security measures
We implement technical and organizational measures appropriate to the risk of processing. Exact controls vary by system.
Contact process
Privacy / data protection contact: [email protected]
Postal address: 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States
You may also have the right to lodge a complaint with a supervisory authority in your country or region (for example an EU/EEA data protection authority if GDPR applies to you).