1.
Introduction
Status
Pros (“Company,” “we,” “us,” or “our”)
is committed to protecting the privacy and security of information entrusted to
us by our clients, prospective clients, and visitors to our website. As a
provider of managed IT services (MSP) and managed security services (MSSP), we
handle sensitive technical, operational, and personal data as part of our
service delivery obligations.
This
Privacy Statement describes the types of information we collect, how we use and
protect that information, your rights with respect to your data, and how to
contact us with questions or requests.
By
using our website or engaging our services, you acknowledge that you have read
and understood this Privacy Statement.
2.
Information We Collect
2.1
Information You Provide Directly
We
collect information you voluntarily provide when you:
•
Complete a contact or inquiry form on our website
•
Request a proposal, assessment, or demonstration of services
•
Enter into a service agreement or statement of work with us
•
Communicate with our team via email, phone, or secure
messaging platforms
•
Participate in surveys, webinars, or other events we host
This
information may include your name, title, organization, email address, phone
number, mailing address, and the nature of your inquiry or engagement.
2.2
Information Collected Automatically
When
you visit our website, we may automatically collect certain technical data,
including:
•
IP address and approximate geographic location
•
Browser type and version
•
Operating system
•
Referring URL and pages viewed on our site
•
Date, time, and duration of your visit
This
information is collected via cookies, web beacons, and similar technologies as
described in Section 8 below.
2.3
Information Collected in Connection with Service Delivery
In
the course of providing managed services, we may process data on behalf of our
clients pursuant to a separate data processing agreement (DPA) or contractual
arrangement. This may include:
•
System logs, event data, and telemetry from client
environments
•
Security alerts, vulnerability findings, and incident data
•
Network configuration and asset inventory information
•
Employee directory data used to provision or administer
identity services
Such
data is processed strictly for the purpose of delivering the contracted
services and is subject to the confidentiality and security obligations set
forth in our client agreements.
3. How
We Use Your Information
We
use the information we collect for the following purposes:
•
Responding to inquiries and providing requested information
about our services
•
Delivering, managing, and improving our managed services and
security operations
•
Communicating with you about your account, contracts, or
service status
•
Sending relevant security advisories, threat intelligence
updates, or service notifications
•
Marketing our services to prospective clients where we have a
legitimate interest or your consent
•
Complying with legal, regulatory, and contractual obligations
•
Detecting, preventing, and responding to fraud, security
incidents, or unauthorized activity
•
Analyzing website usage to improve user experience and
content relevance
We
do not sell, rent, or trade your personal information to third parties for
their own marketing purposes.
4. Legal
Bases for Processing
Where
applicable law requires a legal basis for processing personal data (including
under the EU General Data Protection Regulation (GDPR) or applicable U.S. state
privacy laws), we rely on one or more of the following:
•
Contract performance: Processing necessary to fulfill a
service agreement or pre-contractual obligations
•
Legitimate interests: Processing for purposes such as fraud
prevention, network security, and service improvement, where those interests
are not overridden by your rights
•
Legal obligation: Processing required to comply with
applicable laws or regulations
•
Consent: Where you have provided clear, informed consent,
which may be withdrawn at any time
5. How
We Share Your Information
5.1
Service Providers and Subprocessors
We
may share information with trusted third-party vendors who assist us in
operating our business and delivering services. These include cloud
infrastructure providers, security tooling vendors, ticketing and PSA
platforms, and communication service providers. All such parties are bound by
confidentiality agreements and are prohibited from using your information for
any purpose other than providing services to us.
5.2
Legal and Regulatory Disclosures
We
may disclose information when required to do so by law, court order, or
regulatory authority, or when we believe in good faith that disclosure is
necessary to protect our rights, respond to claims, or ensure the safety of our
personnel or others.
5.3
Business Transfers
In
the event of a merger, acquisition, divestiture, or sale of all or a portion of
our assets, information we hold may be transferred as part of that transaction.
We will provide notice prior to such a transfer if your personal information
will become subject to a materially different privacy policy.
5.4
Client Environments
Data
processed within client environments is treated as client-owned and
confidential. We act as a data processor for such information and do not use it
for any purpose beyond performing contracted services, unless required by law.
6. Data
Security
We
implement and maintain a comprehensive information security program
commensurate with the sensitivity of the data we process. Our security controls
include, but are not limited to:
•
Encryption of data in transit and at rest using
industry-standard protocols
•
Role-based access control (RBAC) and least-privilege access
principles
•
Multi-factor authentication (MFA) for all administrative and
remote access
•
Continuous monitoring, intrusion detection, and security
event logging
•
Regular vulnerability assessments and penetration testing
•
Endpoint detection and response (EDR) deployed across our
operational systems
•
Security awareness training for all personnel
•
Documented incident response procedures aligned with NIST SP
800-61
While
we take reasonable and appropriate steps to protect your information, no
security measure is entirely infallible. In the event of a data breach
affecting your personal information, we will notify you in accordance with
applicable law.
7. Data
Retention
We
retain personal information only as long as necessary to fulfill the purposes
described in this Privacy Statement, or as required by applicable legal,
regulatory, contractual, or audit obligations. Our standard retention schedule
is as follows:
•
Client contact and agreement data: Retained for the duration
of the client relationship plus 7 years
•
Service delivery and operational logs: Retained for a minimum
of 1 year, or longer as required by client agreements or applicable regulations
•
Marketing and inquiry data: Retained until a request to
unsubscribe or withdraw consent is received, or after 3 years of inactivity
•
Website analytics data: Retained for up to 24 months
Upon
expiration of the applicable retention period, data is securely deleted or
anonymized in accordance with our data disposal procedures.
8.
Cookies and Tracking Technologies
Our
website uses cookies and similar technologies to enhance your browsing
experience, analyze usage patterns, and support marketing functions. The types
of cookies we use include:
•
Strictly necessary cookies: Required for core website
functionality such as security and session management
•
Analytical and performance cookies: Used to understand how
visitors interact with our site, enabling us to improve content and navigation
•
Functional cookies: Used to remember your preferences and
settings
•
Marketing cookies: Used to deliver relevant advertising
content, where applicable
You
may configure your browser to refuse all or some cookies, or to alert you when
cookies are being sent. Disabling certain cookies may affect the functionality
of our website. Where required by law, we will obtain your consent before
placing non-essential cookies.
9. Your
Privacy Rights
Depending
on your jurisdiction, you may have the following rights with respect to your
personal information:
•
Right of access: Request a copy of the personal information
we hold about you
•
Right to rectification: Request correction of inaccurate or
incomplete information
•
Right to erasure: Request deletion of your personal
information, subject to applicable legal or contractual obligations
•
Right to restrict processing: Request that we limit how we
use your information
•
Right to data portability: Receive your data in a structured,
machine-readable format
•
Right to object: Object to processing based on legitimate
interests or for direct marketing purposes
•
Right to withdraw consent: Withdraw consent at any time where
processing is based on consent
•
Right not to be subject to automated decision-making: Request
human review of significant automated decisions
To
exercise any of the above rights, please submit a written request to the
contact information provided in Section 12. We will respond within the
timeframe required by applicable law (typically 30 days for GDPR; 45 days for
U.S. state privacy laws). We may request verification of your identity before
fulfilling a request.
10.
Third-Party Links and Integrations
Our
website may contain links to third-party websites, partner portals, or
integrated tools. We are not responsible for the privacy practices or content
of those third-party sites and encourage you to review their privacy statements
independently. Our integration of third-party security tools and platforms
within client environments is governed by our client agreements and applicable
vendor DPAs.
11.
International Data Transfers
If
you access our services from outside the United States, please be aware that
your information may be transferred to, stored, and processed in the United
States or other jurisdictions where our service providers operate. Where
personal data is transferred from the European Economic Area (EEA) or the
United Kingdom, we rely on appropriate transfer mechanisms, including Standard
Contractual Clauses (SCCs) as adopted by the European Commission or equivalent
frameworks.
12.
Contact Information
If
you have questions, concerns, or requests related to this Privacy Statement or
our data practices, please contact us at:
Status Pros
Attn:
Privacy Officer
Address:
3001 Bishop Drive, Suite 300, San Ramon, CA 94583
Email:
privacy@statuspros.com
Phone:
(415) 767-5557
If
you are located in the EEA and believe we have not addressed your concern
adequately, you have the right to lodge a complaint with your local supervisory
authority.
13.
Updates to This Privacy Statement
We
may update this Privacy Statement periodically to reflect changes in our
practices, technology, legal requirements, or other factors. When we make
material changes, we will update the effective date at the top of this document
and, where appropriate, notify you by email or through a notice on our website.
We encourage you to review this Privacy Statement regularly.