This Privacy Policy explains how AC BLUFFDALE LLC collects, uses, stores, shares and protects personal information when you visit our website, contact our front desk or engage us for professional services. It is published by AC BLUFFDALE LLC, whose registered office is at 8817 S Shady Meadow Dr, Sandy - 84093-7005, United States (US). The practice is operated by the developer and systems engineering team trading as AC Bluffdale, and this document describes the standards that team applies to every engagement.

We have written this policy in plain language on purpose. If any part of it is unclear, or if you would like more detail about a specific processing activity, please write to frontdesk@acbluffdale.buzz or telephone +12722926951 and we will explain it.

Privacy is not a formality for an engineering practice. The same discipline we apply to system design we apply to information handling: define the boundary, name the owner, record the decision and test that the control still works. This document is the public record of that discipline for the personal information we hold.

We encourage you to read this policy together with our terms of service, which describe the wider contractual framework for using this website and commissioning work. Where a signed data processing agreement exists with a client, that agreement takes priority for the data it covers.

1. Scope of This Policy

This policy applies to personal information that AC BLUFFDALE LLC processes through the website published at acbluffdale.buzz, through email and telephone contact with our front desk, through proposals and statements of work, and through the delivery of the services we provide to clients. It also applies to information collected during recruitment and supplier relationships.

This policy does not apply to information that we process on behalf of a client while acting as a processor. When we host, integrate or maintain a client system, the client remains responsible for the data inside that system, and the client privacy notice governs that data. In those situations we act only on the documented instructions of the client and under the terms of the applicable services agreement.

2. Who Is the Data Controller

For the purposes described in this policy, the data controller is AC BLUFFDALE LLC, with its registered office at 8817 S Shady Meadow Dr, Sandy - 84093-7005, United States (US). The company operates in the field of computer systems design and related professional services.

Questions about this policy, requests to exercise privacy rights and complaints may be sent to frontdesk@acbluffdale.buzz or by telephone to +12722926951. We aim to acknowledge every privacy enquiry within five business days and to resolve it within thirty days.

3. Information We Collect

The categories of personal information we collect depend on how you interact with us. In general the categories are as follows.

Identity and contact details

Names, job titles, employer names, business email addresses, business telephone numbers and postal addresses. These are collected when you make an enquiry, request a proposal or become a client contact.

Enquiry content

The subject and body of messages you send through our contact form or by email, together with any attachments you choose to include. This may include technical details about your systems where you provide them voluntarily.

Contractual and financial records

Purchase order references, billing contact details, invoicing records and payment status. We do not store full payment card numbers on our own systems.

Website technical data

Standard server information such as internet protocol address, browser type, operating system, referring page, pages requested and request timestamps. This data is used to operate and secure the website.

Engagement records

Meeting notes, requirements documents, architecture records and correspondence created while delivering professional services. These may incidentally contain personal information about the individuals involved in a programme.

4. How We Obtain Information

We obtain personal information directly from you when you complete our contact form, send us email, telephone the front desk, sign a proposal, or engage us for services. We also obtain information from the organisations that employ you when those organisations introduce you as a project contact or a point of escalation.

A limited amount of technical information is generated automatically by our web server when your browser requests a page. We do not purchase personal information from data brokers and we do not build advertising profiles.

5. Why We Use Personal Information

We use personal information for the following purposes: to respond to enquiries and provide requested information; to prepare proposals and statements of work; to deliver, support and manage contracted services; to issue invoices and maintain financial records; to manage supplier and partner relationships; to maintain the security and availability of our systems; to comply with legal, tax and regulatory obligations; and to improve the quality and clarity of our services.

We do not use personal information for purposes that are incompatible with those listed above. Where we wish to use information for a new purpose we will tell you first and, where required, obtain your consent.

6. Our Lawful Bases for Processing

Where applicable law requires a lawful basis, we rely on the following. Performance of a contract covers processing needed to deliver services you or your employer have engaged. Legitimate interests covers responding to business enquiries, securing our systems, preventing fraud and improving our services, in each case balanced against your rights. Legal obligation covers tax, accounting and record keeping duties. Consent covers any optional activity, such as subscribing to occasional updates, and you may withdraw consent at any time.

7. Cookies and Similar Technologies

Our website is designed to work with the smallest possible footprint. We use only the cookies and local storage that are strictly necessary to serve pages, remember interface preferences such as a mobile navigation state and support basic security. We do not use advertising cookies and we do not sell cookie data.

You can block or delete cookies through your browser settings. Doing so may affect certain interface conveniences but will not prevent you from reading any page on this website.

8. How We Share Information

We do not sell personal information. We share it only where necessary and only with parties who are bound to protect it. Those parties include hosting and email providers that operate our infrastructure, professional advisers such as accountants and legal counsel, subcontractors who assist with delivery under confidentiality obligations, and public authorities where the law requires disclosure.

Where we share information with a client as part of a joint programme, we limit the share to what is necessary for the programme and inform the individuals concerned where practicable. All sharing is documented in the relevant contract or processing agreement.

We may also disclose information where we believe in good faith that disclosure is necessary to protect the rights, property or safety of the Company, our clients or the public, to investigate suspected fraud, or to respond to a lawful request from a public authority. Where a request is overbroad or legally questionable we will seek to narrow it before responding and will notify the affected party where the law allows.

In the event of a corporate reorganisation, merger or sale of assets, personal information may be transferred as part of the transaction. Any recipient would remain bound by this policy or by terms no less protective, and we would notify affected individuals of the change in ownership where required.

9. Service Providers and Subprocessors

We select service providers carefully and require them to implement appropriate technical and organisational measures. Agreements with processors require them to act only on our documented instructions, to apply confidentiality to their staff, to assist with data subject requests, to notify us of any incident without undue delay and to delete or return data at the end of the relationship.

We maintain a current list of subprocessors used for the website and for client delivery and we make that list available to clients on request. Clients with specific restrictions on subcontracting are invited to raise them at the proposal stage so that arrangements can be adjusted before work begins.

Subprocessors are reviewed before onboarding and periodically afterwards. The review covers security posture, data handling practices, incident history and the location of processing. Where a subprocessor makes a material change to how it handles data, we assess the impact and either accept the change, negotiate protections or replace the provider.

We remain accountable for the performance of our subprocessors. If a provider fails to meet the standards we require, we treat that failure as our own and act to protect the individuals whose information is affected.

10. International Data Transfers

AC BLUFFDALE LLC is established in the United States. Where personal information originating outside the United States is transferred to us, we handle it consistently with this policy and with applicable transfer requirements. Where required, we put in place appropriate safeguards such as standard contractual clauses, and we assess the legal environment of the destination before any transfer is made.

Because we work with clients in several regions, some processing may occur in a region other than the one in which the information was first collected. In every case the same security standards and contractual protections apply to the information wherever it is handled.

11. How Long We Keep Information

We keep personal information only as long as it is needed for the purpose for which it was collected, and then for the additional period required by law or by legitimate business need. Enquiry correspondence that does not lead to an engagement is normally deleted within twenty four months. Contract and invoicing records are kept for the period required by tax and accounting law, which is commonly seven years in the United States.

Engagement records are retained for a period that reflects the operational life of the systems involved, because clients often need historical design decisions long after a programme closes. When a retention period ends, records are securely deleted or irreversibly anonymised.

Backup copies may persist for a short additional period after deletion because of the way routine backup cycles work. Backups are isolated from general access, encrypted, and purged on the normal rotation schedule. We do not use backups as a hidden long term archive for data that has been deleted from live systems.

Where a legal hold applies, for example because litigation is reasonably anticipated, we preserve relevant records for the duration of the hold and then resume the normal retention schedule. A hold is documented, time limited and reviewed so that it is not left in place indefinitely.

12. How We Protect Information

Security engineering is our profession, and we apply it to our own systems. Access to personal information is limited to personnel who need it for a defined role, protected by multi factor authentication and reviewed periodically. Data is encrypted in transit and at rest using current industry standards. Systems are patched on a schedule, monitored for unusual activity and backed up with restoration tests.

Our offices are secured and physical records that contain personal information are kept in locked storage with restricted access. Staff receive regular training on confidentiality, phishing awareness and incident reporting. We test our own controls and we remediate findings with owners and deadlines, because an unclosed finding is treated as an open risk.

No method of transmission or storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at frontdesk@acbluffdale.buzz or by telephone at +12722926951.

13. Your Privacy Rights

Depending on where you live, you may have the right to be informed about how your personal information is used, to access a copy of the information we hold, to correct inaccurate information, to request deletion, to restrict or object to certain processing, to receive information in a portable format and to withdraw consent where consent is the basis for processing.

To exercise a right, write to frontdesk@acbluffdale.buzz and describe the request. We will verify your identity before acting, using information we already hold, and we will respond within the period required by applicable law. If we cannot meet a request we will explain why. If you are not satisfied with our response you may complain to the supervisory authority in your jurisdiction.

We do not discriminate against individuals who exercise privacy rights. You will receive the same quality of service whether or not you make a request.

14. Privacy for Children

Our website and services are intended for organisations and professional audiences. We do not knowingly collect personal information from children under the age of thirteen. If we learn that such information has been collected, we will delete it promptly. A parent or guardian who believes that a child has provided information to us should contact frontdesk@acbluffdale.buzz so that we can remove it.

15. Marketing Communications

We send occasional service updates and notices to existing clients and to individuals who have asked to hear from us. Every such message includes a clear way to opt out, and opt out requests are honoured promptly. We do not send marketing messages to individuals who have never had a relationship with us unless a lawful basis permits it and the message is relevant to their professional role.

16. Automated Decision Making

We do not use personal information to make decisions that produce legal or similarly significant effects through automated processing alone. Where we use analysis tools to help prioritise work, a human reviewer remains responsible for the outcome and for any decision that affects an individual.

17. Third Party Websites

Our website may link to external sites that we do not control. This policy does not apply to those sites, and we are not responsible for their content or their privacy practices. We encourage you to read the privacy notice of any external site before providing personal information to it.

18. Data Breach Response

We maintain an incident response procedure that covers detection, containment, assessment, notification and remediation. If a breach affecting personal information occurs, we act to stop it, assess the risk to individuals and notify affected parties and regulators where the law requires it. We keep a record of incidents and the actions taken, and we update our controls afterwards so that the same cause cannot recur.

Clients with contractual notification requirements should include them in the relevant agreement so that our response timelines match their obligations. We will always tell affected parties promptly and factually, without minimising the scope of an incident.

19. Changes to This Policy

We review this policy at least annually and whenever our processing activities change in a material way. When we make a significant change we update the effective date at the top of the page and, where the change affects individuals who have an ongoing relationship with us, we provide direct notice. Continued use of the website after a change takes effect indicates acceptance of the revised policy.

20. How to Contact Us

For any question about this policy or about your personal information, please use the details below. We welcome questions and we would rather explain our practices than leave anyone uncertain about them.

Company Details

AC BLUFFDALE LLC

8817 S Shady Meadow Dr
Sandy - 84093-7005
United States (US)

Email: frontdesk@acbluffdale.buzz

Telephone: +12722926951