Privacy notice
Your information has a narrow job.
Effective and last revised: August 4, 2026
- We use inquiry details to review and respond to your request.
- We do not add advertising tracking or sell inquiry information.
- Do not send passwords, patient information, client files, payment data, or other sensitive records through the contact form.
- Inquiries that do not become engagements are generally retained for no more than 12 months after the last meaningful interaction.
1. Scope
This notice applies to the public AlomSec website, contact form, and information exchanged while evaluating a potential engagement. A signed customer agreement may contain additional terms for assessment evidence, customer systems, personnel, and reports. If those terms conflict with this notice for engagement data, the signed agreement controls.
2. Who handles the information
AlomSec is the product name used for this service. The United States business operating the site determines how website inquiry information is used. Its legal contracting identity and business details are provided in proposals, agreements, invoices, and responses to verified privacy requests. Privacy questions and rights requests can be submitted through the contact form by selecting Privacy request.
3. Information we collect
Information you provide
- Name and organization.
- Work email address.
- Industry and approximate employee range.
- The inquiry topic and message.
- Your consent to have the inquiry reviewed and answered.
- Any follow-up information you choose to provide during a business conversation.
Security and delivery information
When you visit the site or submit the form, our edge and hosting providers may process IP address, request time, requested path, browser and device characteristics, transport-security information, bot-detection signals, and response status. AlomSec does not add analytics tags, advertising pixels, or behavioral profiling scripts.
Information we do not request through public inputs
Do not send passwords, API keys, access tokens, private keys, regulated records, vulnerability evidence containing secrets, payment-card data, health information, or confidential files through the contact form. File uploads are disabled.
4. Why we use information
| Purpose | Information | Reason for processing |
|---|---|---|
| Review and answer an inquiry | Name, organization, work email, topic, message | To take requested steps and communicate about a possible service. |
| Define and manage a business relationship | Inquiry and follow-up business records | Contract administration, legitimate business operations, and recordkeeping. |
| Protect the form and site | Network, request, browser, Turnstile, and abuse signals | Prevent spam, fraud, denial of service, and unauthorized activity. |
| Meet legal obligations and protect rights | Relevant inquiry or security records | Compliance, dispute handling, incident response, and establishment or defense of legal claims. |
Where applicable law requires a specific legal basis, processing may rely on your request or consent, steps before entering a contract, performance of a contract, compliance with law, or our legitimate interests in secure and accountable business operations. Consent can be withdrawn for future consent-based processing, but withdrawal does not undo processing that was lawful when performed.
5. When information is disclosed
Information may be disclosed only as reasonably necessary to:
- Cloudflare, which provides website delivery, network protection, abuse prevention, and protected form processing.
- The restricted mailbox provider used to deliver and respond to an inquiry.
- Professional advisers or service providers bound to use the information for a defined business purpose.
- Authorities or other parties when required by valid legal process, necessary to protect rights and safety, or involved in a business reorganization subject to appropriate safeguards.
We do not sell personal information, share it for cross-context behavioral advertising, or provide inquiry lists to data brokers.
6. Retention
Retention depends on why the information exists:
- Inquiries that do not become an engagement are generally retained for up to 12 months after the last meaningful interaction, then deleted or de-identified unless a legal or security reason requires longer retention.
- Proposal, contract, invoicing, and engagement-administration records may be retained for the engagement term and up to seven years afterward where needed for tax, accounting, insurance, dispute, or legal obligations.
- Security reports and abuse records are retained for the time reasonably necessary to investigate, remediate, prevent recurrence, and defend the service.
- A minimal suppression record may be kept when needed to honor a do-not-contact request.
- Infrastructure providers retain their own operational records under their configurations and published terms.
These periods are ceilings for ordinary operations, not a promise to retain every record for the full period. Information may be removed earlier when it is no longer needed.
7. Security safeguards
The public site uses encrypted HTTPS, restricted content and browser policies, anti-abuse controls, bounded form inputs, and fixed inquiry delivery. The marketing site does not expose assessment systems or customer portal data.
Access to inquiry information is limited to people and providers who need it for the purposes above. We use account access controls, encrypted transport, restricted service configuration, and operational review. No transmission or storage method is completely secure, so this notice does not promise absolute security.
8. Cookies and similar technologies
AlomSec does not use advertising or audience-measurement cookies. The contact page loads Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. Turnstile processes technical signals needed to provide that security function. Browser or edge security mechanisms may also be used when necessary to deliver and protect the service.
9. Your privacy choices
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an explanation of processing; object to certain processing; withdraw consent; or appeal a denied request. Submit the request through the contact form and select Privacy request.
We may ask for information reasonably necessary to verify identity and authority before acting. An authorized agent may submit a request, but we may require proof of authorization and direct identity verification. We will not discriminate against a person for exercising an applicable privacy right.
10. United States state privacy disclosure
In the preceding 12 months, the site may have collected identifiers, professional or employment-related information, internet or network activity, and correspondence content, all as described above. Sources are the individual, their organization, and security or delivery providers. Business purposes are inquiry handling, service administration, site security, legal compliance, and protection of rights. These categories may be disclosed to the provider categories in Section 5. They are not sold or shared for cross-context behavioral advertising.
AlomSec does not knowingly use or disclose sensitive personal information from the public form for purposes that require a right to limit under applicable state law. The form is not intended to collect sensitive personal information.
11. International processing
AlomSec and its providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, transfers are handled under an available legal mechanism or contractual safeguard.
12. Children
This business security site and its services are not directed to children under 13, and we do not knowingly collect their personal information. If such information is identified, it will be deleted unless law requires otherwise.
13. Security engagement boundary
Submitting a form, identifying a public asset, or discussing a possible service does not authorize any security test. Testing requires a separate written agreement that identifies ownership, scope, allowed techniques, rules of engagement, contacts, stop conditions, and a valid time window. Assessment evidence is then handled under that agreement.
14. Changes to this notice
We may revise this notice as the site, providers, or legal requirements change. The effective date at the top will be updated when a revision is published. Material changes affecting an active customer relationship may also be communicated through the normal engagement channel.
15. Contact
Use the AlomSec contact form and select Privacy request. The form is the published privacy contact channel for this site.