Privacy Policy
Effective Date: September 30, 2025 Company: 1012 Capri, LLC
This Policy is written specifically for a remote cybersecurity consulting business that receives website enquiries and may process confidential business and technical information during authorized engagements.
Scope of this Privacy Policy
This Privacy Policy describes how 1012 Capri, LLC (“1012 Capri,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information obtained through this website, service enquiry forms, email, telephone communications, proposals, contracts, and authorized cybersecurity consulting engagements.
This Policy applies to website visitors, prospective clients, current clients, client representatives, vendors, service providers, and other individuals who communicate with us. It does not replace a confidentiality agreement, data processing agreement, statement of work, or other written engagement document. Where a signed agreement contains more specific privacy or data-handling terms, that agreement controls for the relevant engagement.
Information we collect
Information provided directly
We may collect a person’s name, business email address, telephone number, company name, job title, requested service, desired timing, budget information, and the contents of messages submitted through the website or sent to us directly.
Engagement and technical information
When a client authorizes cybersecurity work, we may receive information reasonably necessary to perform the agreed scope, including system inventories, network diagrams, cloud architecture information, policies, access-control records, configuration details, security logs, incident summaries, screenshots, vulnerability information, backup documentation, training records, vendor information, and business continuity materials.
Clients must not provide unrelated personal information or live credentials unless we have agreed on a secure transfer method and the information is necessary for the authorized scope.
Website and device information
Our website platform and supporting providers may automatically collect IP address, browser type, device type, operating system, referring page, pages viewed, date and time of access, approximate location derived from IP address, cookie identifiers, and security or diagnostic events.
How we use information
We may use information for the following business purposes:
- Responding to enquiries and determining whether a requested engagement is appropriate.
- Preparing proposals, statements of work, authorization documents, schedules, and invoices.
- Delivering authorized cybersecurity assessments, consulting, policy development, training, planning, and advisory services.
- Communicating findings, recommendations, project updates, security notices, and administrative information.
- Verifying authority, protecting systems, preventing fraud, and investigating suspected misuse.
- Maintaining business, accounting, tax, legal, insurance, and contractual records.
- Improving our website, documentation, workflows, security controls, and service quality.
- Complying with applicable law, legal process, professional duties, and enforceable requests from public authorities.
We do not use client technical information to access systems outside the written authorization or for offensive activity unrelated to the engagement.
Legal bases and business grounds
Depending on the interaction and applicable law, we process personal information because it is necessary to take requested steps before entering a contract, perform a contract, comply with legal obligations, protect legitimate business and security interests, establish or defend legal claims, or act with the individual’s consent.
Where consent is the legal basis, consent may be withdrawn for future processing. Withdrawal does not affect processing already performed lawfully and may not require deletion where another lawful retention basis applies.
How information is disclosed
We may disclose information to service providers that support website hosting, cloud infrastructure, secure communications, document storage, project management, accounting, payment processing, insurance, legal advice, and other legitimate business operations. Service providers receive only the information reasonably necessary to perform their function and are expected to use appropriate confidentiality and security measures.
Our website is operated using Shopify infrastructure. Shopify and other platform or application providers may process limited website and device data in accordance with their own terms and privacy practices.
We may also disclose information:
- At the client’s direction or with the individual’s consent.
- To authorized client representatives and vendors involved in remediation or project delivery.
- To comply with a subpoena, court order, regulatory demand, or other lawful process.
- When reasonably necessary to protect rights, safety, systems, property, clients, or the public.
- In connection with a merger, financing, reorganization, sale of assets, or similar business transaction, subject to appropriate safeguards.
We do not sell personal information for monetary consideration. We do not knowingly share personal information for cross-context behavioral advertising. If these practices change, we will update this Policy and provide any legally required notice and opt-out mechanism.
Data minimization and retention
We seek to collect only information reasonably necessary for the relevant purpose. Retention depends on the type of record, the sensitivity of the information, contractual requirements, legal obligations, limitation periods, insurance needs, and the status of the engagement.
| Record category | General retention approach |
|---|---|
| General enquiries | Generally retained for up to 24 months after the last substantive communication unless the enquiry becomes an engagement or a longer period is reasonably required. |
| Contracts, invoices, and accounting records | Generally retained for at least seven years or for the period required by applicable tax, accounting, or legal rules. |
| Engagement documentation and final deliverables | Generally retained for up to three years after completion unless the agreement, legal obligations, insurance requirements, or an active dispute require a different period. |
| Temporary credentials or access artifacts | Deleted, returned, disabled, or rendered unusable when no longer required for the authorized work, subject to secure backup cycles and incident-preservation requirements. |
| Security and diagnostic logs | Retained for a reasonable period necessary to detect misuse, investigate incidents, and maintain website or service security. |
Information that is no longer required may be deleted, anonymized, aggregated, returned, or securely archived. Backup copies may remain until overwritten through ordinary backup rotation.
Security measures
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, acquisition, alteration, disclosure, loss, misuse, or destruction. Measures may include access restrictions, multi-factor authentication, encryption, secure transfer methods, logging, backups, vendor review, confidentiality obligations, and incident-response procedures.
No method of transmission, storage, or security control is completely risk-free. We cannot guarantee absolute security. Clients should not send passwords, private keys, recovery codes, or sensitive technical records through a public contact form or ordinary unsecured email.
Cookies and similar technologies
The website may use cookies, local storage, pixels, and similar technologies for platform operation, security, navigation, preferences, performance measurement, and analytics. Essential technologies may be required for the website to function. Optional technologies will be handled according to applicable consent and opt-out requirements.
Additional details are provided in the separate Cookie Policy. Browser settings may allow cookies to be blocked or deleted, but disabling essential technologies may impair website operation.
Privacy rights
Depending on residence and applicable law, an individual may have the right to request confirmation of processing, access, correction, deletion, restriction, portability, or objection, and may have the right to withdraw consent or opt out of certain sales, targeted advertising, or profiling.
Colorado residents acting in an individual or household context may have rights under the Colorado Privacy Act, where that law applies. California residents may have rights under California privacy law, where applicable. Individuals in the European Economic Area or United Kingdom may have additional rights where those laws govern the processing.
To submit a request, contact us using the details at the end of this page. We may request information reasonably necessary to verify identity, authority, residence, and the scope of the request. We may deny or limit a request where permitted by law, including where disclosure would adversely affect another person, reveal protected security information, compromise trade secrets, or conflict with legal retention obligations.
Where applicable law provides an appeal right, a request to appeal should identify the original request and explain why the response should be reconsidered.
Universal opt-out signals
Where required by applicable law and technically supported by the website and its providers, we will process recognized universal opt-out mechanism signals as required. A signal may apply only to the browser or device from which it is sent unless the individual is authenticated and the law requires broader application.
Children’s information
Our website and services are intended for businesses and adult business representatives. We do not knowingly solicit personal information from children under thirteen. We do not knowingly offer services directly to minors. If we learn that information was collected from a child in a manner prohibited by law, we will take reasonable steps to delete it.
International processing
Information may be processed in the United States and in other locations where service providers operate. Where legally required, we use appropriate contractual or legal mechanisms for cross-border transfers. Individuals should understand that privacy laws may differ between jurisdictions.
Changes to this Policy
We may revise this Privacy Policy to reflect changes in law, technology, service providers, or business practices. The Effective Date displayed at the top identifies the operative version. Material changes may be communicated through the website or another reasonable method.
Contact 1012 Capri
Use these details for policy questions, privacy requests, billing concerns, formal notices, or questions about an authorized cybersecurity engagement. Do not send passwords, private keys, authentication codes, or other live credentials through ordinary email.