Privacy Policy
This Privacy Policy explains how CSD DIGITAL ENTERPRISES, LLC collects, uses, stores and protects information when you visit our website, contact our studio or engage our services. The policy is written by the developer and operator known as CSD Digital, the trading identity of CSD DIGITAL ENTERPRISES, LLC, a computer systems design firm based in South Jordan, Utah.
Table of Contents
- 1. Scope of This Policy
- 2. Who Is Responsible for Your Data
- 3. Information We Collect
- 4. How We Obtain Information
- 5. Why We Use Information
- 6. Legal Bases for Processing
- 7. Cookies and Similar Technologies
- 8. Website Analytics
- 9. How We Share Information
- 10. Service Providers and Subprocessors
- 11. International Data Transfers
- 12. Data Retention
- 13. Security Measures
- 14. Your Privacy Rights
- 15. How to Exercise Your Rights
- 16. Privacy for Children
- 17. Marketing Communications
- 18. Links to Other Websites
- 19. Automated Decision Making
- 20. Data Breach Response
- 21. Changes to This Policy
- 22. How to Contact Us
1. Scope of This Policy
This Privacy Policy applies to the website published at www.csddigital.buzz and to any communication you have with CSD DIGITAL ENTERPRISES, LLC through that website, by email, by telephone or in the course of a professional engagement. It describes the categories of information we handle, the reasons we handle them, the choices available to you and the protections we apply.
This policy does not apply to information that we process on behalf of a client while delivering an engagement, where the client remains the owner of the data and the client directs how it is used. In those circumstances the client is the responsible party and our obligations are set out in the written agreement between the client and CSD DIGITAL ENTERPRISES, LLC. If you are an employee or customer of one of our clients and you wish to exercise a privacy right, please contact that client first.
This policy also does not cover websites operated by other organisations that you may reach through a link on our site. Those organisations publish their own privacy notices and we encourage you to read them.
2. Who Is Responsible for Your Data
The entity responsible for the information described in this policy is CSD DIGITAL ENTERPRISES, LLC, a limited liability company registered in the United States and operating as a computer systems design firm. Our studio address is 881 W Baxter Dr Ste 100, South Jordan - 84095-8506, Utah, United States (US).
You can reach the person accountable for privacy matters by writing to eamonn.doyle@csddigital.buzz or by calling +19286224453 during normal business hours. We ask that privacy requests be sent by email so that there is a clear written record of the request and of our response.
Where this policy refers to we, us or our, it means CSD DIGITAL ENTERPRISES, LLC. Where it refers to you, it means the individual visiting the website, sending an enquiry or otherwise interacting with our studio.
3. Information We Collect
We aim to collect as little as possible while still running a professional studio effectively. The categories of information we may collect are described below.
Information you provide directly
When you complete the contact form on this website, send us an email or speak with us by telephone, you may provide your name, your email address, your telephone number, the name of your organisation, the subject of your enquiry and the content of your message. If we enter into an engagement, you may also provide business contact details, billing information and documents relevant to the work.
Information collected automatically
When you load a page on this website, our hosting infrastructure may record technical information such as the internet protocol address assigned to your connection, the type and version of your browser, the operating system of your device, the date and time of the request, the pages requested and the address of the page that referred you. This information is used to deliver the site securely and to understand aggregate usage.
Information from professional correspondence
If you correspond with us over time, we retain the thread of that correspondence so that we can continue the conversation accurately and avoid asking you to repeat information. This includes meeting notes, agreed actions and technical details that you choose to share.
4. How We Obtain Information
Most of the information we hold comes directly from you. You provide it when you submit the contact form, when you reply to an email, when you join a call or when you send us a document. We do not purchase contact lists and we do not acquire personal information from data brokers.
A smaller amount of information is generated automatically by the systems that serve this website, as described in the section on information collected automatically. Some information may also be created by us in the ordinary course of work, for example a record of the date on which you asked us to contact you, or a note that you asked us not to send marketing material.
If a colleague or a partner introduces you to us, we may receive your name, your role and your contact details from that person. In such a case we treat the information in the same way as information you provide yourself, and we confirm the introduction with you before adding you to any list.
5. Why We Use Information
We use the information we hold for a limited set of purposes, each of which is connected to running a computer systems design practice.
- To respond to your enquiry and to hold the conversation that follows.
- To prepare proposals, scopes of work and engagement plans.
- To deliver, support and improve the services we have agreed to provide.
- To maintain accounting, tax and other business records required by law.
- To keep the website secure, available and free from abuse.
- To understand, in aggregate, which parts of the website are useful to visitors.
- To send professional updates where you have asked to receive them.
- To establish, exercise or defend legal claims where this becomes necessary.
We do not sell personal information. We do not rent it, trade it or make it available to advertising networks. We do not use the content of your enquiries to train machine learning models for public release.
6. Legal Bases for Processing
Where data protection law requires a legal basis for processing, we rely on the following grounds.
Performance of a contract
We process information because it is necessary to enter into or perform an agreement with you or with the organisation you represent. This covers responding to a request for a proposal, delivering an engagement and administering payment.
Legitimate interests
We process certain information because we have a legitimate interest in operating a secure and effective professional practice. This includes keeping the website available, preventing abuse, understanding aggregate usage and maintaining business records. We balance those interests against your rights and we limit the processing to what is reasonably required.
Consent
Where we rely on consent, for example when you ask to receive occasional professional updates, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Legal obligation
We process and retain certain records because the law requires it, including accounting and tax records and records needed to respond to lawful requests from public authorities.
8. Website Analytics
We may measure aggregate traffic to understand which pages are read and which are ignored. Where analytics are used, they are configured to minimise the collection of personal information. We prefer aggregate reporting over individual profiling, and we do not attempt to identify individual visitors from analytics records.
If we ever adopt a tool that would materially change the information collected, we will update this policy and, where required, ask for your consent before the tool becomes active. The current configuration does not combine analytics data with information you provide through the contact form in order to build a profile of you.
Server logs are retained for a short period for security and troubleshooting. They are not used to build advertising audiences and they are not shared with marketing platforms.
10. Service Providers and Subprocessors
Like most professional practices, we depend on a small number of external platforms. These may include providers of email, cloud hosting, file storage, document collaboration, electronic signature and accounting services. Each provider is selected with care and is expected to meet a standard of security and confidentiality that is appropriate to the information it handles.
Before a provider is engaged, we consider the sensitivity of the information it will process, the location in which that processing occurs and the contractual commitments the provider offers. Where a provider processes information on our behalf, we require written terms that limit the provider to processing on our instructions and that impose confidentiality, security and deletion obligations.
We review our provider list periodically. If a provider can no longer meet our requirements, we replace it or we change the way the relevant function is delivered.
11. International Data Transfers
CSD DIGITAL ENTERPRISES, LLC operates from the United States and our primary systems are located there. If you contact us from another country, your information will be transferred to and processed in the United States. Data protection law in the United States may differ from the law of the country in which you live.
Where a transfer requires additional protection, we rely on appropriate safeguards such as standard contractual clauses, a recognised adequacy mechanism or your explicit consent where that is the appropriate route. We also limit transfers to the information that is genuinely needed for the purpose at hand.
If you would like further detail about the safeguards that apply to a particular transfer, you may write to eamonn.doyle@csddigital.buzz and we will explain the mechanism we rely on.
12. Data Retention
We keep information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. Retention periods are set with reference to the nature of the information and the risk that would arise if it were lost or misused.
Enquiries that do not develop into an engagement are normally deleted within twenty-four months. Correspondence relating to an active engagement is retained for the duration of the engagement and for a reasonable period afterwards so that we can support the work we delivered. Accounting and tax records are retained for the period required by applicable law.
Where information is held in backups, it will be removed in accordance with the rotation schedule of the relevant backup system. Backup copies are not used for any purpose other than restoration in the event of loss.
13. Security Measures
We apply technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure and destruction. These measures include encryption of data in transit, access controls that limit information to those who need it, the use of strong authentication for the systems we operate and a practice of keeping software up to date.
Internally, we limit access to personal information to those who require it for a defined purpose. Everyone who handles information on behalf of the studio is expected to follow our confidentiality commitments and to report a suspected incident promptly.
No method of transmission or storage is completely secure, and we cannot promise absolute security. What we can promise is that we take the protection of information seriously, that we review our measures as the studio grows, and that we will notify affected individuals and the relevant authorities where a breach occurs and notification is required by law.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights in relation to your personal information.
- The right to be informed about how your information is used.
- The right to request a copy of the information we hold about you.
- The right to ask us to correct information that is inaccurate or incomplete.
- The right to ask us to delete information in defined circumstances.
- The right to ask us to restrict the way we use information.
- The right to object to processing based on legitimate interests.
- The right to withdraw consent where consent is the basis for processing.
- The right to receive certain information in a portable format.
- The right to complain to a supervisory authority.
- The right not to be discriminated against for exercising a privacy right.
These rights are not absolute. Some are subject to conditions, and some may be limited by our legal obligations or by the need to protect the rights of others. Where we cannot act on a request, we explain the reason in writing.
15. How to Exercise Your Rights
To exercise a right, write to eamonn.doyle@csddigital.buzz with enough detail for us to understand the request and to verify your identity. Please include the email address you used when contacting us and a short description of what you would like us to do.
We will acknowledge your request promptly and will normally respond within thirty days. If a request is complex or if we receive several requests from the same person, we may extend that period and will tell you if we do. There is normally no charge for exercising a right, but we may charge a reasonable fee for repetitive or manifestly unfounded requests.
We may ask for additional information to confirm that the request genuinely comes from you. This verification step protects your information from being released to someone impersonating you. You may also appoint an authorised agent to act on your behalf, and we will require evidence of that authority.
16. Privacy for Children
Our services are directed at businesses and professional audiences. We do not knowingly collect personal information from children under the age of sixteen, and we do not design any part of this website to attract children. If you believe that a child has provided personal information to us, please contact eamonn.doyle@csddigital.buzz and we will delete the information promptly.
Where we learn that information has been collected from a child without the consent of a parent or guardian as required by law, we will remove it. If you are a parent or guardian and you wish to review or request deletion of information relating to a child in your care, you may use the same contact address.
17. Marketing Communications
We send occasional professional updates only where there is a lawful basis to do so. If you receive a marketing message from us, it will include a clear way to stop receiving further messages, and we will honour an opt-out request promptly.
Transactional messages are different from marketing messages. If you are an active client, we may need to contact you about a live engagement, a security matter or an administrative issue. Those messages are part of delivering the service and are not affected by a marketing opt-out.
We do not pass your details to third parties so that they can market their own products to you. If we ever co-host an event or a briefing with another organisation, we will explain how the information will be used before you register, and you can choose whether to take part.
18. Links to Other Websites
This website may include links to resources operated by other organisations. Those links are provided because they may be useful, but we do not control the destinations and we are not responsible for the way they handle personal information.
We encourage you to read the privacy notice of any website you visit after leaving ours. This policy applies only to information processed by CSD DIGITAL ENTERPRISES, LLC through the channels described in the section on scope.
19. Automated Decision Making
We do not make decisions about individuals using solely automated processes that would produce a legal effect or a similarly significant effect. Decisions about enquiries, proposals and engagements are made by people.
Where we use software to help organise information, the software assists a human decision rather than replacing it. If we ever introduce a process that would materially change this position, we will describe it in this policy and, where required, provide a route to request human review.
20. Data Breach Response
We maintain a simple and rehearsed response to a suspected personal data breach. When an incident is reported, we contain it, assess the risk to individuals, and take steps to reduce harm. We keep a written record of the incident, the assessment and the actions taken.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, we notify the relevant supervisory authority without undue delay and within the timeframe required by applicable law. Where a breach is likely to result in a high risk to individuals, we also notify the affected individuals directly, describing the nature of the incident and the steps we recommend they take.
We review every incident afterwards to understand what failed and to strengthen the controls that should have prevented it. A report can be made at any time to eamonn.doyle@csddigital.buzz.
21. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, in the services we offer or in the law that applies to us. When we make an update, we revise the effective date shown at the top of the page.
If a change materially affects the way we use personal information, we will provide a clear notice on the website and, where we have an ongoing relationship with you, we will contact you directly where the law allows. Continuing to use the website after a change takes effect indicates that you have had the opportunity to review the updated policy.
We recommend reviewing this page occasionally so that you remain aware of the commitments we have made. Previous versions can be requested by writing to the contact address below.
22. How to Contact Us
Questions, requests and complaints about privacy are welcome and will be handled by the studio directly. Please write to eamonn.doyle@csddigital.buzz or call +19286224453 during business hours.
CSD DIGITAL ENTERPRISES, LLC
881 W Baxter Dr Ste 100
South Jordan - 84095-8506
Utah, United States (US)
Email: eamonn.doyle@csddigital.buzz
Telephone: +19286224453
Website: www.csddigital.buzz
If you are not satisfied with our response and you live in a jurisdiction that provides for one, you may lodge a complaint with the supervisory authority responsible for data protection in your country or region. We would appreciate the chance to resolve the matter with you first.