Privacy Policy
Last updated: September 2026 · version 2.0 · iussec.com
1. Who we are
| Item | Detail |
|---|---|
| Entity | IUSSEC, LLC |
| Florida document number | L26000460832 |
| Registered & principal business address | 7901 4th St N Ste 300, St. Petersburg, FL 33702, USA |
| Trading name | IusSec |
| Website | iussec.com |
| contacto@iussec.com |
IUSSEC, LLC is a Florida limited liability company governed by the laws of the State of Florida and applicable United States federal law. This policy applies to everyone who contacts us, including clients outside the United States.
To the extent IUSSEC, LLC processes personal data of individuals residing in the European Union or European Economic Area (EEA) under GDPR Article 3(2), such processing follows the applicable substantive requirements of Regulation (EU) 2016/679. EU representative exemption: under Article 27(2)(a) GDPR, IUSSEC, LLC is not required to designate an EU representative because its processing of EU data subject data is limited, occasional, does not include large-scale processing of special categories of personal data, and is unlikely to result in a risk to the rights and freedoms of natural persons, given the nature, context, scope and purposes of the processing.
2. Our role — controller or processor
IUSSEC, LLC acts as an independent data controller for personal data collected directly through this website, marketing interactions, billing, and Executive Assessment questionnaire submissions. For advisory engagements where a client provides its own confidential system data or internal records under a Master Services Agreement or Statement of Work, IUSSEC, LLC acts as a data processor under the terms of the Data Processing Addendum executed with that client, not under this general policy alone.
3. What we collect
| Category | Data elements | Collection point |
|---|---|---|
| Contact & identification data | Full name, business email address, phone number, job title, company name. | Intake forms (Tally), contact forms, scheduling (Calendly). |
| Technical & telemetry data | IP address, browser type, operating system, device identifiers, referral URLs, session logs. | Automated website logging and essential technical cookies. |
| Transactional & payment data | Billing name, billing address, transaction timestamps, masked card identifiers (last 4 digits). Full card details are collected directly by our payment processor, never by us. | Stripe payment gateway. |
| Organizational & compliance input | Operational workflows, compliance posture data, technical architecture details, and your Executive Assessment responses. | Secure questionnaire intake (Tally). |
We do not ask for special category data. Please don't include confidential or sensitive information in a first message.
4. Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Reviewing your intake and delivering the Executive Assessment, Scorecard and roadmap | Performance of a contract |
| Website security, fraud prevention, protecting our infrastructure | Legitimate interests |
| Bookkeeping, tax filing, regulatory record-keeping | Legal obligation |
| Sending a resource you requested (e.g. the AI Act guide) or corporate briefings | Consent |
We do not sell personal data. We do not subject client Assessment data to automated decision-making or profiling that produces legal or similarly significant effects. Business contact data submitted through our own intake and lead-generation forms may be scored internally to prioritize outreach (see Section 5, Anthropic PBC); this scoring does not make or materially affect any decision about you and never determines eligibility for, or the outcome of, any service.
5. Service providers & sub-processors
IUSSEC, LLC does not sell, rent, or trade personal data. We disclose it only to vetted service providers under confidentiality and security obligations:
| Provider | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (PCI-DSS Level 1). We never store unencrypted card data. | US / EU |
| Tally B.V. | Hosting the Assessment questionnaire | EU |
| Calendly, LLC | Meeting scheduling | US |
| Namecheap Hosting | Website, DNS & infrastructure | US |
| Close, Inc. | CRM — IUSSEC's own business development records, not client Assessment data | US |
| n8n GmbH (n8n Cloud) | Internal workflow automation between our own systems | EU (Germany, Sweden) |
| Anthropic PBC | AI model provider — internal lead research and scoring automation. Not used for client Assessment data as of this version | US |
| Mailgun (Sinch) | Transactional email delivery (guide delivery, lead notifications). If not configured, email is sent directly from our server | US / EU |
When we use these providers for our own business development (prospecting, CRM, scheduling), we act as the data controller. When we use a provider to process a client's own Assessment or engagement data on that client's behalf, we act as a data processor under the terms of the Data Processing Addendum executed with that client.
6. International data transfers (EU/EEA to United States)
Personal data collected from users in the EU/EEA may be transferred to and stored on servers in the United States. To satisfy GDPR Chapter V, IUSSEC, LLC relies on the EU-U.S. Data Privacy Framework where a vendor is certified, or the European Commission's Standard Contractual Clauses integrated into our sub-processor agreements, supplemented by technical safeguards including TLS encryption in transit and AES encryption at rest.
7. Record of consent
When you submit a form we record, alongside your details, the date and time of submission, the version of the notice you accepted, and which form it came from. That record is our evidence of consent and is kept as long as consent remains the basis for processing.
8. Data retention
- Assessment data & workpapers: retained for three (3) years following delivery, then securely purged or anonymized.
- Financial & billing records: retained for seven (7) years per US federal and Florida tax obligations.
- Technical server logs: a rolling window of ninety (90) days, unless extended for active incident response.
9. Data security & Florida Information Protection Act (FIPA)
IUSSEC, LLC maintains reasonable administrative, technical and physical safeguards designed to protect personal information from unauthorized access, acquisition, destruction, modification or disclosure, per Fla. Stat. § 501.171(2). Our controls include encryption in transit (TLS 1.3), role-based access control, multi-factor authentication on administrative systems, and regular vulnerability review.
Breach notification: affected individuals are notified as expeditiously as practicable, no later than thirty (30) days after we determine a breach occurred (Fla. Stat. § 501.171(4)). The Florida Attorney General's office is notified within the same 30-day window only if the breach affects 500 or more Florida residents (Fla. Stat. § 501.171(3)(a)). Where a breach affects individuals in the EU/EEA and poses a risk to their rights, the competent supervisory authority is notified without undue delay, within 72 hours where feasible (GDPR Art. 33).
10. Your rights
EU, EEA and UK residents (GDPR / UK GDPR)
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21)
- The right to lodge a complaint with your local supervisory authority
United States residents
IUSSEC, LLC does not meet the statutory revenue thresholds of the Florida Digital Bill of Rights or the CCPA, but we extend the same transparency to all clients: you may request verification, correction, or deletion of your contact and assessment records at any time.
To exercise any of these rights, write to contacto@iussec.com with subject line "Privacy Rights Request – [Your Name]", attaching proof of identity. We acknowledge within ten (10) business days and respond within thirty (30) days (extendable by two months for complex requests under GDPR).
11. Cookies
This site uses only strictly necessary technical cookies. We do not use analytics, tracking or advertising cookies, so no consent banner is required. Embedded third-party services (Stripe, Tally, Calendly) may set their own cookies when you interact with them, governed by their own policies.
12. Changes and contact
We may update this policy to reflect regulatory change or changes to our services. The current version is always on this page, with its date and version number. Material changes affecting existing clients will be communicated directly or via a prominent website notice before taking effect.
- Email: contacto@iussec.com
- Spanish-language versions: Política de Privacidad · Aviso Legal