1. Introduction

Status Pros (“Company,” “we,” “us,” or “our”) is committed to protecting the privacy and security of information entrusted to us by our clients, prospective clients, and visitors to our website. As a provider of managed IT services (MSP) and managed security services (MSSP), we handle sensitive technical, operational, and personal data as part of our service delivery obligations.

This Privacy Statement describes the types of information we collect, how we use and protect that information, your rights with respect to your data, and how to contact us with questions or requests.

By using our website or engaging our services, you acknowledge that you have read and understood this Privacy Statement.

2. Information We Collect

2.1 Information You Provide Directly

We collect information you voluntarily provide when you:

          Complete a contact or inquiry form on our website

          Request a proposal, assessment, or demonstration of services

          Enter into a service agreement or statement of work with us

          Communicate with our team via email, phone, or secure messaging platforms

          Participate in surveys, webinars, or other events we host

This information may include your name, title, organization, email address, phone number, mailing address, and the nature of your inquiry or engagement.

2.2 Information Collected Automatically

When you visit our website, we may automatically collect certain technical data, including:

          IP address and approximate geographic location

          Browser type and version

          Operating system

          Referring URL and pages viewed on our site

          Date, time, and duration of your visit

This information is collected via cookies, web beacons, and similar technologies as described in Section 8 below.

2.3 Information Collected in Connection with Service Delivery

In the course of providing managed services, we may process data on behalf of our clients pursuant to a separate data processing agreement (DPA) or contractual arrangement. This may include:

          System logs, event data, and telemetry from client environments

          Security alerts, vulnerability findings, and incident data

          Network configuration and asset inventory information

          Employee directory data used to provision or administer identity services

Such data is processed strictly for the purpose of delivering the contracted services and is subject to the confidentiality and security obligations set forth in our client agreements.

3. How We Use Your Information

We use the information we collect for the following purposes:

          Responding to inquiries and providing requested information about our services

          Delivering, managing, and improving our managed services and security operations

          Communicating with you about your account, contracts, or service status

          Sending relevant security advisories, threat intelligence updates, or service notifications

          Marketing our services to prospective clients where we have a legitimate interest or your consent

          Complying with legal, regulatory, and contractual obligations

          Detecting, preventing, and responding to fraud, security incidents, or unauthorized activity

          Analyzing website usage to improve user experience and content relevance

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

4. Legal Bases for Processing

Where applicable law requires a legal basis for processing personal data (including under the EU General Data Protection Regulation (GDPR) or applicable U.S. state privacy laws), we rely on one or more of the following:

          Contract performance: Processing necessary to fulfill a service agreement or pre-contractual obligations

          Legitimate interests: Processing for purposes such as fraud prevention, network security, and service improvement, where those interests are not overridden by your rights

          Legal obligation: Processing required to comply with applicable laws or regulations

          Consent: Where you have provided clear, informed consent, which may be withdrawn at any time

5. How We Share Your Information

5.1 Service Providers and Subprocessors

We may share information with trusted third-party vendors who assist us in operating our business and delivering services. These include cloud infrastructure providers, security tooling vendors, ticketing and PSA platforms, and communication service providers. All such parties are bound by confidentiality agreements and are prohibited from using your information for any purpose other than providing services to us.

5.2 Legal and Regulatory Disclosures

We may disclose information when required to do so by law, court order, or regulatory authority, or when we believe in good faith that disclosure is necessary to protect our rights, respond to claims, or ensure the safety of our personnel or others.

5.3 Business Transfers

In the event of a merger, acquisition, divestiture, or sale of all or a portion of our assets, information we hold may be transferred as part of that transaction. We will provide notice prior to such a transfer if your personal information will become subject to a materially different privacy policy.

5.4 Client Environments

Data processed within client environments is treated as client-owned and confidential. We act as a data processor for such information and do not use it for any purpose beyond performing contracted services, unless required by law.

6. Data Security

We implement and maintain a comprehensive information security program commensurate with the sensitivity of the data we process. Our security controls include, but are not limited to:

          Encryption of data in transit and at rest using industry-standard protocols

          Role-based access control (RBAC) and least-privilege access principles

          Multi-factor authentication (MFA) for all administrative and remote access

          Continuous monitoring, intrusion detection, and security event logging

          Regular vulnerability assessments and penetration testing

          Endpoint detection and response (EDR) deployed across our operational systems

          Security awareness training for all personnel

          Documented incident response procedures aligned with NIST SP 800-61

While we take reasonable and appropriate steps to protect your information, no security measure is entirely infallible. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.

7. Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this Privacy Statement, or as required by applicable legal, regulatory, contractual, or audit obligations. Our standard retention schedule is as follows:

          Client contact and agreement data: Retained for the duration of the client relationship plus 7 years

          Service delivery and operational logs: Retained for a minimum of 1 year, or longer as required by client agreements or applicable regulations

          Marketing and inquiry data: Retained until a request to unsubscribe or withdraw consent is received, or after 3 years of inactivity

          Website analytics data: Retained for up to 24 months

Upon expiration of the applicable retention period, data is securely deleted or anonymized in accordance with our data disposal procedures.

8. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience, analyze usage patterns, and support marketing functions. The types of cookies we use include:

          Strictly necessary cookies: Required for core website functionality such as security and session management

          Analytical and performance cookies: Used to understand how visitors interact with our site, enabling us to improve content and navigation

          Functional cookies: Used to remember your preferences and settings

          Marketing cookies: Used to deliver relevant advertising content, where applicable

You may configure your browser to refuse all or some cookies, or to alert you when cookies are being sent. Disabling certain cookies may affect the functionality of our website. Where required by law, we will obtain your consent before placing non-essential cookies.

9. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

          Right of access: Request a copy of the personal information we hold about you

          Right to rectification: Request correction of inaccurate or incomplete information

          Right to erasure: Request deletion of your personal information, subject to applicable legal or contractual obligations

          Right to restrict processing: Request that we limit how we use your information

          Right to data portability: Receive your data in a structured, machine-readable format

          Right to object: Object to processing based on legitimate interests or for direct marketing purposes

          Right to withdraw consent: Withdraw consent at any time where processing is based on consent

          Right not to be subject to automated decision-making: Request human review of significant automated decisions

To exercise any of the above rights, please submit a written request to the contact information provided in Section 12. We will respond within the timeframe required by applicable law (typically 30 days for GDPR; 45 days for U.S. state privacy laws). We may request verification of your identity before fulfilling a request.

10. Third-Party Links and Integrations

Our website may contain links to third-party websites, partner portals, or integrated tools. We are not responsible for the privacy practices or content of those third-party sites and encourage you to review their privacy statements independently. Our integration of third-party security tools and platforms within client environments is governed by our client agreements and applicable vendor DPAs.

11. International Data Transfers

If you access our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. Where personal data is transferred from the European Economic Area (EEA) or the United Kingdom, we rely on appropriate transfer mechanisms, including Standard Contractual Clauses (SCCs) as adopted by the European Commission or equivalent frameworks.

12. Contact Information

If you have questions, concerns, or requests related to this Privacy Statement or our data practices, please contact us at:

Status Pros

Attn: Privacy Officer

Address: 3001 Bishop Drive, Suite 300, San Ramon, CA 94583

Email: privacy@statuspros.com

Phone: (415) 767-5557

If you are located in the EEA and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local supervisory authority.

13. Updates to This Privacy Statement

We may update this Privacy Statement periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the effective date at the top of this document and, where appropriate, notify you by email or through a notice on our website. We encourage you to review this Privacy Statement regularly.