Legal

Privacy Policy

How Basilio Inc, operating the brand Got Suspended?, collects, uses, shares, retains, and otherwise processes information.

Effective date: 8 September 2026 | Last updated: 8 September 2026

This Privacy Policy (this “Policy”) describes how Basilio Inc, a corporation operating under the brand “Got Suspended?” (the “Company”, “we”, “us”, or “our”), collects, uses, shares, retains, discloses, sells, and otherwise processes information in connection with the websites at gotsuspendedclients.com and gotsuspended.com and any related or successor domain, application, or online service (together, the “Site”), and our consulting, reinstatement, dispute, funds-release, brand-protection, reputation, and related services (the “Services”). It applies to information about visitors to the Site, prospective clients, clients and their personnel, and other individuals whose information we receive. This Policy forms part of, and is incorporated into, our Terms and Conditions (the “Terms”). Capitalized terms not defined in this Policy have the meanings given in the Terms.

By accessing the Site, submitting a case or intake form, booking a consultation, communicating with us, making a payment, or otherwise using the Services, you acknowledge that you have read and understood this Policy and consent, on your own behalf and on behalf of the individuals whose information you provide, to the collection, use, sharing, retention, sale, and processing of information as described in it, to the fullest extent permitted by applicable law. If you do not agree, you must not access the Site or use the Services.

BROAD-USE NOTICE. The Services are provided to businesses and to sophisticated commercial parties. You grant us broad, irrevocable (except as law requires), worldwide, and perpetual rights to collect, use, combine, analyze, retain, disclose, sell, share, and commercialize the information we obtain, for any purpose not prohibited by applicable law, including operating, securing, and improving our business, developing and training analytical and artificial-intelligence systems, marketing and advertising, and creating and exploiting de-identified, aggregated, and derived data. Where a right, consent, or latitude described in this Policy is broader than a particular law allows, it applies to the maximum extent that law permits and is limited only to the extent that law requires.

1. Summary of Key Points

This summary highlights key points from this Policy. It is provided for convenience only, does not replace the full Policy, and is qualified in its entirety by the detailed sections that follow. Capitalized terms are defined in Section 2.

What we collect. We collect identifiers and contact data, account, platform, and case data, financial and transaction data, communications, commercial data, device and usage data, cookies and tracking data, information from third parties and public sources, sensitive information you provide to work a matter, and inferences and derived data. See Sections 5 and 6.

How we use it. We use information to provide and improve the Services, operate and secure our business, conduct analytics and research, develop and train software and artificial-intelligence systems, market and advertise, process payments, prevent fraud, comply with law, and for any other lawful purpose. See Sections 9 through 12.

How we share it. We share information with Subcontractors and service providers (including personnel in the Philippines, Armenia, and elsewhere), affiliates, advertising and analytics partners, professional advisers, acquirers in a corporate transaction, and authorities, and we may sell or share it for advertising. See Sections 13 through 15.

Your choices and rights. Depending on where you live, you may have rights to access, correct, delete, and port information, to opt out of sale, sharing, and targeted advertising, and to limit sensitive-information use. See Sections 25 through 30.

How to contact us. Contact our Data Protection Officer at DPO@gotsuspendedclients.com. See Section 34.

2. Definitions and Interpretation

In this Policy, the following terms have the meanings set out below, and other capitalized terms have the meanings given in the Terms. The singular includes the plural and the reverse, and the words “including”, “includes”, and “such as” are illustrative and not words of limitation.

“Personal Information” any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, and includes “personal data” as defined under the General Data Protection Regulation and comparable laws.

“Sensitive Information” the subset of Personal Information that applicable law treats as sensitive or special-category, including government identifiers, financial-account information, precise geolocation, account credentials, and similar categories.

“Processing” any operation performed on information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, and destruction.

“Controller” the party that determines the purposes and means of Processing; under United States state law, the “business”.

“Processor” the party that Processes Personal Information on behalf of and on the documented instructions of a Controller; under United States state law, the “service provider” or “contractor”.

“Subcontractor” any independent contractor, agency, specialist, vendor, subprocessor, or domestic or offshore personnel we engage, in our sole discretion, to perform any portion of the Services or to Process information on our behalf.

“Platform” any third-party platform, marketplace, network, advertising system, application store, bank, payment processor, publisher, search engine, review site, or other service upon or through which the Services are rendered, owned and controlled by an independent third party.

“Sale” the disclosure of Personal Information to a third party for monetary or other valuable consideration, as that concept is defined under applicable United States state privacy law.

“Sharing” the disclosure of Personal Information to a third party for cross-context behavioral advertising, as that concept is defined under applicable United States state privacy law.

“De-Identified Data” information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual or household.

“You” the individual or entity accessing the Site or using the Services, and where you provide information about other individuals, those individuals as the context requires.

“Targeted Advertising” displaying advertisements to you selected based on Personal Information obtained from your activity across nonaffiliated websites, applications, or services over time, as that concept is defined under applicable law.

“Profiling” any form of automated Processing of Personal Information to evaluate, analyze, or predict aspects concerning you, such as your preferences, behavior, reliability, or circumstances.

“Consumer or Data Subject” an identified or identifiable individual to whom Personal Information relates, including a “consumer” under United States state law and a “data subject” under the General Data Protection Regulation.

“Supervisory Authority” a data-protection or privacy regulator with authority over the Processing, including a state attorney general and a European or United Kingdom supervisory authority.

“Standard Contractual Clauses” the contractual clauses approved for the transfer of Personal Information to jurisdictions that restrict such transfers, including the European Commission Standard Contractual Clauses and the United Kingdom International Data Transfer Addendum.

“Cookies” small files and similar technologies placed on a device to store and read information, as further described in Section 7.

“Data-Processing Addendum” a separate agreement between you as Controller and us as Processor governing our Processing of Personal Information on your documented instructions, which controls over this Policy as to that Processing.

3. Scope, Acceptance, and Relationship to the Terms

Scope. This Policy applies to information we obtain through the Site, the Services, our intake and case-management channels, our marketing and communications, our payment and billing operations, and our dealings with the accounts, funds, content, and matters that are the subject of an engagement. It does not apply to information handled by Platforms or other third parties that we do not control.

Business context; consent and authority. You engage us for business or commercial purposes. Your acceptance of the Terms and your use of the Services constitute your informed consent, and where applicable the consent of the individuals whose information you provide, to the Processing described here. You represent and warrant that you are authorized to provide any third-party Personal Information you submit, that you have given any notices and obtained any consents that your own privacy obligations require, and that our Processing of that information on your instructions will not cause you or us to violate any law.

Precedence. This Policy is incorporated into the Terms and is read together with them. In a conflict concerning the Processing of information, this Policy governs; a data-processing addendum executed with you governs over both as to Processing carried out on your documented instructions; in all other respects the Terms govern.

Changes over time. The version of this Policy in effect when you use the Site or the Services governs that use, except as a change is required by law or as Section 32 provides.

What this Policy does not cover. This Policy does not cover the practices of Platforms, payment processors, banks, advertisers, or other third parties we do not control, information you disclose in public forums or to third parties directly, or information handled under a separate agreement that expressly governs it. It also does not limit any right or remedy available to us under the Terms or applicable law.

4. Our Roles: Controller, Processor, and Service Provider

When we act for ourselves. In respect of the Site, our own marketing, analytics, security, billing, recruitment, and business operations, we act as a Controller and, under United States state law, as a business, and we determine the purposes and means of Processing.

When we act on your instructions. In respect of the Personal Information contained in the case materials, accounts, and documents you provide so that we can assess and work a matter, we act as a Processor and, under United States state law, as a service provider or contractor, Processing that information on your documented instructions and for the purpose of providing the Services and the purposes permitted by law. Where required, we will enter into a data-processing addendum with you, which upon execution controls as to that Processing.

Your responsibility as Controller. Where we act as your Processor or service provider, you are the Controller or business and are solely responsible for the lawfulness of the information you provide, for the notices and consents required to collect it and to share it with us, for the accuracy of your instructions, and for your own compliance obligations to the individuals concerned and to authorities.

Joint arrangements. Nothing in this Policy makes us a joint Controller with you unless we expressly agree in writing, and any allocation of responsibility in a data-processing addendum governs as between us.

Mixed roles. In many engagements we act in both capacities at once, as a Controller for our own operational, security, analytics, marketing, and improvement purposes, and as a Processor for the case data we handle on your instructions. Where the same information is Processed for both, each Processing activity is governed by the role that applies to it, and our broad rights under this Policy apply to our Controller activities to the fullest extent the law allows.

5. Information We Collect

We collect a broad range of information about you, in the categories set out below. The specific information collected depends on how you interact with us, the Services you request, and the choices you make.

5.1 Information you provide to us

  • Identifiers and contact data: name, business name, job title, postal and billing addresses, email addresses, telephone and WhatsApp numbers, and account usernames and handles.

  • Account, platform, and case data: the credentials, enforcement and suspension notices, prior appeals, plans of action, order and account-health records, listing and catalog data, supplier and sourcing information, contracts, identity and verification documents, and other materials you provide or authorize us to access to assess and work a matter.

  • Financial and transaction data: billing details, payment-method information, invoices, transaction history, reserve, hold, and payout information, and records of amounts held, released, reconciled, or disputed.

  • Communications and content: the content of your messages, calls, voicemails, intake submissions, uploads, and correspondence with us and our personnel, and any recordings or transcripts made in accordance with law.

  • Commercial and preference data: the Services you purchase or consider, your marketing and contact preferences, and your feedback, reviews, and survey responses.

5.2 Information we collect automatically

When you use the Site we automatically collect device and usage data, including IP address, device and browser type and characteristics, operating system and language settings, unique device and online identifiers, referring and exit pages and URLs, the pages and content you view, links and features you interact with, search terms, clickstream and session-replay-style interaction data where enabled, approximate location derived from IP address, and access dates and times.

5.3 Inferences and derived data

We generate inferences, profiles, assessments, scores, tags, and conclusions about you, a matter, an account, or a course of dealing, drawn from the information above and from our analysis and models. Derived data of this kind is Personal Information where it is reasonably linkable to you and is otherwise our data.

5.4 Business, matter, and counterparty information

Because we work platform-enforcement, dispute, funds, and reputation matters, the materials you provide often contain information about your business and about third parties, including your customers, suppliers, employees, agents, and counterparties, and about the accounts, transactions, communications, and disputes at issue. You are responsible for ensuring you may lawfully share that information with us and for making any disclosures those third parties are owed.

5.5 Feedback, reviews, events, and surveys

We collect information you provide when you give feedback, leave a review or testimonial, respond to a survey, or register for or attend a consultation, webinar, or event, including your responses and any content you submit, which we may use to operate and improve the Services and, where permitted, for marketing.

6. Sensitive and Special-Category Information

To render the Services you may provide, and you authorize us to collect and Process, information that applicable law treats as sensitive or special-category, including government-issued identifiers such as tax and social-security numbers and passport and license details, financial-account and payment information, account credentials and security information, precise geolocation where you provide it, and identity and verification documents.

You provide such information voluntarily and, where the law requires it, on the basis of your explicit consent, which you give by submitting the information for the stated purpose of assessing or working a matter. We use Sensitive Information only for the purposes permitted by applicable law, including providing the Services you request, verifying identity, preventing fraud, and complying with law, and we do not use or disclose it to infer characteristics about you for advertising. We do not seek information concerning health or, except as strictly necessary to a matter, other categories a matter does not require, and you should not provide categories of information a matter does not require.

Because our work involves platform accounts and funds, you may need to provide, and you authorize us to receive and Process, government identifiers, banking and payment-account details, and identity and verification documents so that we can prepare submissions, verify ownership, and pursue reinstatement or release. We handle such information subject to the safeguards in Section 18 and Annex B, share it only with the recipients described in Sections 13 and 14 and, at your direction, with the relevant Platform, bank, or processor, and retain it only as long as Section 18 permits. If you object to our Processing of a category of Sensitive Information necessary to a matter, we may be unable to provide the affected Services.

7. Cookies, Pixels, and Tracking Technologies

We and our partners use cookies, pixels, tags, web beacons, SDKs, local and session storage, and similar technologies to operate the Site, remember your preferences, authenticate sessions, measure and analyze performance and traffic, and support marketing and advertising, including, where permitted, targeted and cross-context behavioral advertising. The categories we use are summarized below.

CategoryPurposeExamplesConsent
Strictly necessarySecurity, load balancing, session integrity, and core Site functionsSession and authentication cookies, consent-state storageNot required
FunctionalRemembering preferences and settings and improving usabilityPreference and language cookiesWhere required
Analytics and performanceMeasuring traffic, usage, and Site performanceGoogle Analytics and similarWhere required
Advertising and targetingDelivering, measuring, and personalizing advertising, including cross-context behavioral advertisingMeta Pixel, Google Ads, and similarWhere required

Where required by law, we present a consent tool and honor the choices you record through it, and where required we treat recognized opt-out preference signals as a valid opt-out of Sale and Sharing. Where consent is not required, your continued use of the Site constitutes acceptance of these technologies. You can also control cookies through your browser settings, though disabling some cookies may impair the Site. This Policy governs our use of these technologies; where we maintain a separate cookie notice, it supplements this Policy.

The third-party technologies we commonly use include the following, each governed by the relevant provider policies as well as this Policy:

ProviderTypePurpose
Google AnalyticsAnalyticsMeasuring traffic, usage, and Site performance
Google AdsAdvertisingDelivering and measuring advertising and conversions
Meta PixelAdvertisingDelivering and measuring advertising on Meta platforms
Microsoft AdvertisingAdvertisingDelivering and measuring advertising
LinkedIn and TikTok tagsAdvertisingDelivering and measuring advertising and audiences
WordPress and site toolingFunctional and necessaryOperating and securing the Site
CalendlyFunctionalScheduling consultations
Consent management toolStrictly necessaryRecording and enforcing your consent choices

8. Sources of Information

We collect information from the following categories of source: directly from you and your representatives; automatically from your devices and interactions with the Site; from Platforms, banks, and payment processors in connection with a matter; from our Subcontractors and service providers; from analytics, advertising, marketing, and lead-generation partners; from social-media and single-sign-on providers where you use them; from referral sources and business partners; and from public records and commercial and third-party data sources.

We may combine and cross-reference information from these sources with information we already hold in order to verify identity, enrich records, improve accuracy, assess and work matters, prevent fraud, and support analytics, marketing, and the development of our systems. Combined information is treated under this Policy according to the categories it contains.

9. How We Use Information

We use information for the purposes described below and for any other purpose not prohibited by applicable law. Where a legal basis is required, the bases on which we rely are described in Section 10.

9.1 To provide and manage the Services

We use information to receive and assess intake, diagnose enforcement and hold categories, prepare strategy, narratives, plans of action, and submissions, manage and escalate a matter, communicate with you, schedule and conduct consultations, deliver reporting, and otherwise perform, administer, and enforce the Terms and any engagement.

9.2 To operate, secure, and improve our business

We use information to operate, maintain, evaluate, secure, and improve the Site, the Services, and our business; to develop new products, services, and features; to perform research, analytics, benchmarking, quality assurance, and statistical and performance analysis; to build, train, test, tune, and improve our and our providers software, automation, analytical models, and artificial-intelligence and machine-learning systems; and to create models, insights, and know-how that we may use and retain.

9.3 To market and advertise

We use information to market and advertise our Services and those of our affiliates, to personalize content, offers, and the Site, to measure and improve the effectiveness of our marketing, and to deliver, measure, and personalize advertising, including targeted and cross-context behavioral advertising, across our own and third-party properties.

9.4 To transact, protect, and comply

We use information to process payments and manage billing, collections, reserves, and disputes; to detect, investigate, and prevent fraud, abuse, security incidents, and prohibited conduct, and to protect our rights, property, personnel, and interests and those of others; to comply with law, respond to legal process and requests from authorities, and establish, exercise, or defend legal claims; to carry out corporate transactions; and for any other purpose disclosed to you, reasonably related or compatible with the foregoing, or to which you consent.

9.5 Recording and monitoring of communications

We may record, transcribe, and monitor calls, messages, and other communications with you, and retain the resulting records, for training, quality assurance, verification, dispute resolution, security, and compliance purposes, to the extent permitted by applicable law and, where required, with notice or consent. By communicating with us you consent to such recording and monitoring where your consent is required and you are authorized to give it.

9.6 Single sign-on and social features

If you access the Site or Services using a social login or single-sign-on provider, or interact with social-media features, we may receive information from that provider, such as your identifier and profile details, in accordance with its terms and your settings, and we may use it to authenticate you and to provide and personalize the Services. Your relationship with that provider is governed by its own policies.

9.7 Payment processing

Payments are processed by third-party payment processors. We may receive limited transaction and payment-status information and tokens from them, but full payment-card numbers are handled by the processor under its own terms and its Payment Card Industry compliance, and are not stored by us in plaintext. Your provision and use of a payment method is also subject to the processor terms.

Where the General Data Protection Regulation, the United Kingdom GDPR, or a comparable law applies, we rely on one or more of the following legal bases, depending on the purpose:

  • Performance of a contract with you and taking steps at your request before entering into one, for providing, administering, and supporting the Services.

  • Our legitimate interests, for operating, securing, evaluating, improving, and marketing our business, developing our systems and models, preventing fraud and abuse, and pursuing corporate transactions, where those interests are not overridden by your interests and fundamental rights.

  • Compliance with a legal obligation, for record-keeping, tax, anti-fraud, sanctions, and responding to lawful requests.

  • The establishment, exercise, or defense of legal claims.

  • Your consent, where required, including your explicit consent for any special-category data and for certain marketing and cookies; you may withdraw consent prospectively as described in this Policy, without affecting Processing already carried out or Processing on another basis.

Where we rely on legitimate interests, you may obtain further information about the balancing we have carried out by contacting us. The table below maps our principal purposes to the legal bases on which we typically rely; more than one basis may apply to a given activity.

PurposeTypical legal basis
Providing, administering, and supporting the ServicesPerformance of a contract; legitimate interests
Operating, securing, and improving our business and systemsLegitimate interests; legal obligation for security and record-keeping
Developing and training analytical and artificial-intelligence systemsLegitimate interests; consent where required
Marketing and advertising, including targeted advertisingLegitimate interests; consent where required for cookies and certain marketing
Payments, billing, collections, and fraud preventionPerformance of a contract; legal obligation; legitimate interests
Compliance, legal requests, and defense of claimsLegal obligation; establishment, exercise, or defense of legal claims
Processing of special-category or sensitive dataExplicit consent, or another condition permitted by law

11. Artificial Intelligence, Analytics, Profiling, and Automated Processing

We use software, automation, analytics, and artificial-intelligence and machine-learning systems as internal instruments of workflow, analysis, and improvement. You agree that we may Process information you provide, and information we generate, to build, train, evaluate, fine-tune, and improve such systems and our Services, and to create models, insights, benchmarks, and know-how that we may use, retain, and commercialize.

We may carry out profiling and automated analysis to assess matters, prioritize and route work, detect fraud and risk, and personalize marketing. Where a decision producing legal or similarly significant effects concerning you would be based solely on automated Processing and is restricted by applicable law, we will not make it on that basis without a lawful ground, and you may exercise the rights that law provides, including to obtain human review, express your view, and contest the decision. No output of any such system constitutes a warranty, guarantee, or assurance of any result, and human operators retain oversight of the Services.

Examples of the analytical and artificial-intelligence uses contemplated by this Policy include classifying and summarizing case materials, drafting and refining narratives and submissions for human review, estimating the difficulty and posture of a matter, identifying patterns across matters to improve our methods, scoring risk and detecting anomalies for fraud and security, and improving search, routing, and quality assurance. We may use both our own systems and third-party systems for these purposes, subject to our contractual and security controls. Where we use a third-party system, we do not authorize the provider to use your information to train its own models for unrelated purposes except as our agreement with it permits and applicable law allows.

12. De-Identified, Aggregated, and Derived Data

We may de-identify, anonymize, pseudonymize, and aggregate information so that it no longer reasonably identifies you or any individual or household, and we may create derived data, models, statistics, insights, benchmarks, and know-how from information we Process.

All such De-Identified Data, aggregated data, and derived data, and all models and know-how, are and remain our exclusive property, and we may use, retain, disclose, license, sell, and commercialize them for any purpose, indefinitely, without restriction and without further notice or compensation to you. Where required by law, we maintain such data in de-identified form, publicly commit to maintaining and using it only in de-identified form, do not attempt to re-identify it except as permitted, and contractually oblige recipients to the same.

By way of example, we may publish or share aggregate statistics, benchmarks, trend reports, and case studies about enforcement patterns, outcomes, and the Services, and we may use derived models to improve our diagnosis and handling of matters, provided that such outputs do not identify you or any individual. Nothing in this Section requires your consent to our use of De-Identified Data or derived data, and your rights over identifiable Personal Information do not extend to data that no longer identifies you.

13. How and With Whom We Share Information

We may disclose the categories of information described in this Policy to the following categories of recipient:

  • Subcontractors, vendors, and service providers, whether domestic or international, including personnel and subprocessors located in the Philippines, Armenia, and other jurisdictions, engaged to help us provide, operate, host, secure, support, market, or improve the Services;

  • our affiliates, subsidiaries, and related entities and the other businesses operated by our principals;

  • analytics, advertising, marketing, communications, hosting, payment, identity, and technology providers;

  • Platforms, banks, and payment processors, to the extent necessary to work a matter and at your direction;

  • professional advisers, including lawyers, accountants, auditors, bankers, and insurers;

  • a successor, acquirer, investor, or lender, and their advisers, in connection with any merger, acquisition, financing, reorganization, sale of assets, insolvency, or similar transaction, and in diligence for any such transaction, and we may transfer information as a business asset;

  • courts, regulators, and law-enforcement or governmental authorities, where we consider disclosure necessary or appropriate to comply with law or legal process, to respond to a request, or to protect our rights, property, safety, or interests or those of others; and

  • any other person with your consent or at your direction, and otherwise as permitted by applicable law.

The service providers we use include, without limitation, cloud hosting and infrastructure providers such as Amazon Web Services and Google Cloud Platform, analytics providers such as Google Analytics, advertising providers such as Google and Meta, communications and messaging providers such as Twilio and WhatsApp, email and marketing providers such as Mailchimp and ActiveCampaign, scheduling providers such as Calendly, identity and authentication providers, and payment processors such as Stripe. This list may change from time to time.

13.1 Corporate transactions

If we are involved in a merger, acquisition, financing, reorganization, joint venture, sale or transfer of assets, insolvency, bankruptcy, or receivership, or negotiations or diligence for any of these, we may disclose and transfer information, including Personal Information, to the counterparties, their advisers, and successors as part of that transaction, and the acquirer or successor may continue to Process the information under this Policy or a successor policy. Personal Information is one of the business assets that may be transferred in such a transaction.

13.2 Legal, government, and safety disclosures

We may access, preserve, and disclose information where we believe in good faith that doing so is necessary or appropriate to comply with applicable law, regulation, legal process, or a governmental or law-enforcement request; to enforce the Terms and our policies; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, safety, or interests of the Company, our clients, our personnel, or others. Where permitted, we may seek to limit or challenge a request, but we are not obligated to do so.

13.3 Fraud prevention and security

We share information with fraud-prevention, identity-verification, and security providers, and with Platforms and processors, to detect, investigate, and prevent fraud, abuse, and security incidents, and we may retain and use records of suspected or confirmed misconduct to protect ourselves and others.

14. Subprocessors and Onward Transfers

Where we act as your Processor or service provider, you authorize us to engage Subcontractors as subprocessors, including our affiliates and domestic and international personnel and vendors, to carry out Processing on your behalf. We maintain a record of the subprocessors we engage for such Processing and impose on them, by contract, data-protection obligations no less protective than those to which we are subject, and we remain responsible for their performance to the extent required by law. The categories of subprocessor we use include cloud hosting and storage, communications and messaging, analytics, advertising, payment processing, customer support and case handling, identity and verification, and staffing and business-process personnel. Where required by law and requested in writing, we will make available the current list of subprocessors and a mechanism to receive notice of changes.

15. Sale and Sharing of Personal Information; Targeted Advertising

Depending on the technologies in use and the categories involved, our disclosure of information to advertising, analytics, and marketing partners, and our use of cookies and similar technologies for targeted and cross-context behavioral advertising, may constitute a Sale or Sharing of Personal Information as those terms are defined under certain United States state privacy laws. To the maximum extent permitted by law we may engage in such Sale and Sharing, and we may receive consideration for it.

We do not Sell or Share Sensitive Information for cross-context behavioral advertising, and we do not knowingly Sell or Share the Personal Information of individuals we know to be under sixteen (16) years of age. Where the law grants you a right to opt out of the Sale or Sharing of your Personal Information, to opt out of targeted advertising and certain profiling, or to limit the use of Sensitive Information, you may exercise it as described in Sections 25 through 30 and through any consent or preference tool we make available, including recognized opt-out preference signals where the law requires us to honor them.

16. Our Rights and Latitude

Broadest permissible use. To the fullest extent permitted by applicable law, we may collect, access, use, combine, analyze, retain, store, transfer, disclose, monetize, Sell, Share, and otherwise Process the information described in this Policy for any lawful purpose we determine, whether or not that purpose is expressly listed here, and we reserve all rights in the information, data, models, insights, and know-how we generate.

Construction in our favor. This Policy is to be construed so as to permit the broadest use of information that applicable law allows. A limitation applies only where, and only to the extent that, applicable law or a right that cannot be waived requires it, and the remainder of this Policy continues in full force. No example, list, or illustration in this Policy limits the general and discretionary rights stated in this Section.

Consent and waiver. To the extent permitted by law, you consent to the Processing described here and waive any right or claim inconsistent with it. Where consent is required and later withdrawn, the withdrawal operates prospectively only and does not affect Processing already carried out or Processing we may continue on another lawful basis. Your consent under this Policy extends to the individuals whose information you provide, and you are responsible for having obtained it.

Reservation. We reserve every right in information not expressly granted to you by non-waivable law, and nothing in this Policy transfers to you any right in our data, systems, models, or know-how.

We may send you administrative, transactional, service, relationship, and marketing communications by email, telephone, SMS and text, WhatsApp, push notification, postal mail, and other channels. Administrative, transactional, and service communications are part of the Services and are not subject to opt-out.

By providing a telephone or messaging number and engaging the Services, you consent, to the extent permitted by applicable law including the Telephone Consumer Protection Act and comparable laws, to receive calls and messages, including by automated dialing systems, prerecorded or artificial voice, and text and messaging services, at that number for service and marketing purposes, and you represent that you are the subscriber or customary user of the number and are authorized to give that consent. Consent is not a condition of purchase where the law so requires. Message and data rates may apply, and message frequency varies. You may opt out of marketing calls and messages by using the opt-out mechanism provided, by replying STOP to a text where offered, or by contacting us, and we will honor applicable choices, although we may continue to send you non-marketing communications. You may opt out of marketing emails using the unsubscribe link, and we maintain internal suppression lists as the law requires.

We keep records of the consents you give and the opt-outs you make, together with the date and manner in which they were given or made, to demonstrate our compliance and to honor your choices across our systems. Honoring an opt-out may take a short period to take effect across all systems and Subcontractors, and an opt-out from marketing does not stop administrative, transactional, security, or legal communications, which are part of the Services. Where you have engaged us or requested information, we may rely on an applicable exception, such as an existing business relationship, to the extent the law allows.

18. Data Retention

We retain information for as long as we determine necessary or useful for the purposes described in this Policy, for our legitimate business purposes, and to comply with law, resolve disputes, and enforce our agreements, and we may retain information for the full period any applicable limitation or record-keeping law allows. We may retain information in archival and backup systems, and we may retain De-Identified Data, aggregated data, and derived data indefinitely. When we no longer have a business or legal reason to retain identifiable information, we delete, isolate, or de-identify it, subject to backup cycles.

The criteria we use to determine retention periods include the duration of our relationship with you and the matter, the nature and sensitivity of the information, our legal and contractual obligations, the existence of any dispute or investigation, and our legitimate business needs. Indicative retention periods are summarized below and may be extended where law or a dispute requires.

InformationIndicative retention
Account, case, and matter recordsDuration of the engagement plus the applicable limitation period
Financial, billing, and tax recordsAs required by applicable tax and record-keeping law
Marketing and contact dataUntil you opt out or the relationship lapses, then a reasonable suppression period
Communications, call recordings, and correspondenceFor the duration of the matter and a reasonable period thereafter for quality, dispute, and compliance purposes
Site, device, and analytics dataA rolling period consistent with our analytics and security needs
Fraud, security, and compliance recordsAs long as necessary to protect our interests and comply with law
Backups and archivesUntil overwritten in the ordinary backup cycle
De-identified, aggregated, and derived dataIndefinitely

Where we Process Personal Information as your Processor, we return or delete it at the end of the engagement as described in any applicable data-processing addendum, except for copies we are required or permitted by law to retain or that are held in routine backups and subject to continued confidentiality.

19. International Data Transfers

We are based in the United States and operate from, and use personnel, affiliates, and providers located in, the United States, the Philippines, Armenia, and other jurisdictions, whose data-protection laws may differ from, and may not provide the same level of protection as, the laws of the jurisdiction where you are located. By using the Services and providing information, you consent to the transfer, storage, and Processing of information in those jurisdictions.

Where a transfer of Personal Information out of the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction that restricts cross-border transfers requires a lawful transfer mechanism, we rely on an appropriate mechanism, which may include the European Commission Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or Agreement, the Swiss addendum, adequacy decisions where applicable, and any supplementary measures required, or your explicit consent or another derogation where available. You may contact us for information about the safeguards we apply. You remain responsible for determining the lawfulness of any transfer of information you provide to us and for any onward transfer you direct.

Our use of personnel and providers in the Philippines and Armenia means that Personal Information necessary to work a matter or to support the Services may be accessed and Processed from those countries. Where you are in a jurisdiction that restricts such access, your acceptance of this Policy and your provision of information for the purpose of receiving the Services constitute your instruction and, where required, your consent to that access and Processing, subject to the safeguards described above. If you need a copy of the transfer safeguards or wish to discuss them, contact our Data Protection Officer using the details in Section 34.

20. Security Measures

We maintain administrative, technical, and organizational safeguards reasonably designed to protect information in our possession, commensurate with the nature of the information and the Services. These may include access controls and least-privilege access, authentication and credential-management controls, encryption of data in transit, network, endpoint, and application protections, logging and monitoring, secure development and change-management practices, personnel confidentiality obligations and training, vendor due diligence and contractual safeguards, and prompt rotation or revocation of credentials shared with us at the conclusion of an engagement.

No system, transmission, or storage is ever perfectly secure, however, and we cannot and do not guarantee the absolute security of information. Because the Services depend on Platforms and third parties, and because information travels over networks we do not control, we do not warrant that information will always be secure and, to the fullest extent permitted by law, we bear no liability for any loss, access, disclosure, or compromise originating with a Platform, with you, or with any third party, or otherwise beyond our reasonable control.

20.1 Your security responsibilities

You are responsible for the security of your own accounts, devices, networks, and credentials, for using strong and unique passwords and available security features, for transmitting information to us only through appropriate channels, and for promptly notifying us of any suspected compromise of a credential or account used in connection with the Services. You should not send us information a matter does not require, and you should rotate any credential shared with us at the conclusion of an engagement.

20.2 Incident response

We maintain procedures to identify, assess, contain, and remediate security incidents and, where an incident affects information in our possession, to notify as described in Section 21. Our detailed security measures are summarized in Annex B.

21. Personal-Data Breach Notification

We maintain procedures to detect, investigate, and respond to security incidents. Where we determine that a confirmed security incident affecting Personal Information in our possession requires notification under applicable law, we will notify the affected individuals or the relevant authority as, and within the time, that law requires. Where we act as your Processor, we will notify you without undue delay after becoming aware of a confirmed personal-data breach affecting your data and will provide reasonable information and cooperation to assist you in meeting your own obligations. As between us and you, you are responsible for your own breach-notification obligations to individuals and authorities, and for determining whether and how to notify, except where a data-processing addendum provides otherwise. Any liability arising from a security incident is subject to the disclaimers and the limitation of liability in the Terms.

22. Regulated Data

The Services are not designed to collect or Process data subject to special regulatory regimes unless we separately agree in writing. We do not solicit protected health information, and we do not act as a business associate under the Health Insurance Portability and Accountability Act absent a signed business-associate agreement. Cardholder data is handled by payment processors that maintain Payment Card Industry Data Security Standard compliance and is not stored by us in plaintext. Where a matter unavoidably involves financial-account information subject to laws such as the Gramm-Leach-Bliley Act, or education records subject to comparable laws, we Process it only as necessary to provide the Services and subject to any addendum the law requires. Where regulated data would be Processed, the applicable addendum must be agreed before we Process it, and you must not provide regulated data outside that arrangement.

You are responsible for identifying, before you provide it, any information subject to a special regulatory regime, and for not transmitting such information to us except under an arrangement we have agreed in writing. If regulated data reaches us without such an arrangement, we may quarantine, return, or delete it, decline to Process it, and require an appropriate addendum before continuing, and you remain responsible for any consequence of having provided it outside the agreed arrangement. Nothing in this Section expands the categories of data we agree to accept or the liability we accept, which remain governed by the Terms.

The Site and the Services reference, integrate with, and may link to third-party sites, Platforms, plug-ins, and services that we do not own or control, including social-media features, payment pages, scheduling tools, and advertising and analytics services. This Policy does not apply to those third parties, and we are not responsible for their content, security, or privacy practices. Their handling of information is governed by their own policies, which you should review. The inclusion of a link or integration does not imply our endorsement.

Some pages contain embedded content and features served by third parties, such as videos, buttons, pixels, and widgets, which may collect information about your interaction with them and set their own cookies, whether or not you engage with them, in accordance with their policies. If you follow a link away from the Site, or authorize a connection between the Services and a third-party account or Platform, you do so at your own discretion and subject to that third party terms.

24. Children and Minors

The Site and the Services are intended for businesses and for individuals who are at least eighteen (18) years of age, and are not directed to children. We do not knowingly collect, use, or Sell the Personal Information of children under the age at which parental consent is required by applicable law, and we do not knowingly Sell or Share the Personal Information of individuals under sixteen (16). If you are under the applicable age, you must not use the Site or the Services or provide any information. If we learn that we have collected information from a child without appropriate authorization, we will take reasonable steps to delete it. A parent or guardian who believes a child has provided information to us may contact us to request its deletion.

25. Your Privacy Rights

Rights we provide. Depending on where you are located and subject to applicable law and its exceptions, you may have rights to know and access the Personal Information we Process, to correct inaccurate information, to delete information, to obtain a portable copy, to opt out of the Sale or Sharing of Personal Information and of targeted advertising and certain profiling, to limit the use and disclosure of Sensitive Information, to withdraw consent, and to be free from unlawful discrimination for exercising a right. We provide the rights that applicable law requires and reserve all other rights concerning the information we Process.

How to submit a request. You may submit a request using the contact details in Section 34. To help us respond, please tell us the right you wish to exercise and provide information reasonably necessary to verify your identity and locate your information. Where we act as a Processor for a client, we will refer your request to the relevant Controller and assist as the law and any data-processing addendum require.

Verification and response. We will acknowledge and respond to requests within the timeframes applicable law provides, and we may extend those timeframes where permitted. We may decline or limit a request where an exception applies, where we cannot verify your identity, where the request is manifestly unfounded, excessive, or repetitive, or where honoring it would be inconsistent with our legal obligations, our obligations to a Controller, the rights of others, or our own rights. Where permitted, we may charge a reasonable fee or decline to act on excessive requests.

Authorized agents and appeals. An authorized agent may submit a request on your behalf with proof of authority, and we may require you to verify your identity directly. Where applicable law provides a right to appeal a decision, you may appeal by contacting us at the address in Section 34, and if your appeal is denied you may contact the relevant authority.

Non-discrimination. We will not discriminate against you for exercising a privacy right in a manner that applicable law prohibits. We do not offer financial incentives for the Processing of Personal Information at this time.

Preference signals. The Site does not respond to browser Do-Not-Track signals. We honor recognized opt-out preference signals, such as Global Privacy Control, only where and to the extent applicable law requires us to treat them as a valid opt-out.

Information we may require. To verify a request, we may ask you to provide information we can match against what we hold, such as your name, email, and details of your dealings with us, and for certain requests we may require a signed declaration or additional proof. We use information provided for verification only to process the request.

Timeframes. We aim to acknowledge requests promptly and to respond within the period the applicable law provides, commonly within forty-five (45) days under United States state laws and one (1) month under the General Data Protection Regulation, in each case extendable as the law permits where a request is complex or numerous, in which case we will tell you.

Fees. We handle requests free of charge except where applicable law permits a reasonable fee, such as for manifestly unfounded, excessive, or repetitive requests or for additional copies, in which case we will tell you before proceeding.

Records. We keep records of requests and our responses as the law requires and to demonstrate our compliance.

26. Categories of Personal Information Collected and Disclosed

The following table summarizes, for the purposes of United States state privacy laws, the statutory categories of Personal Information we may collect, the purposes for which we use them, the categories of recipient to whom we may disclose them, and whether we may Sell or Share them. This table is provided for transparency and does not limit the broad rights set out elsewhere in this Policy.

CategoryExamplesPurposesRecipientsSold or shared
IdentifiersName, business name, email, address, phone and WhatsApp, IP and online identifiersProvide the Services, operate, secure, marketProviders, affiliates, advertising and analytics partnersYes, for advertising
Customer records and financial dataBilling details, payment-method information, invoices, reserve and transaction historyBilling, provide the Services, prevent fraudPayment processors, providers, advisersNo
Commercial informationServices purchased or considered, preferences, feedbackProvide, analyze, marketProviders, advertising partnersYes, for advertising
Internet and network activityBrowsing and usage data, interactions, cookie and pixel dataOperate, analyze, advertiseAnalytics and advertising partnersYes, for advertising
GeolocationApproximate location from IP addressSecurity, analyticsProvidersNo
Professional and business informationJob title, business role, company and account contextProvide, marketProvidersNo
Sensitive personal informationGovernment identifiers, financial-account information, credentials, verification documentsProvide the Services, verify identity, prevent fraud, comply with lawProviders, at your direction Platforms and banksNo
Audio, electronic, and communicationsContent of calls, messages, intake, and correspondenceProvide, quality assurance, securityProvidersNo
Inferences and derived dataProfiles, assessments, scores, and conclusionsProvide, improve, develop systemsProviders, affiliatesNo

We collect these categories from the sources in Section 8, use and disclose them for the business and commercial purposes in Sections 9 through 15, and retain them for the periods in Section 18. We may also disclose any category to comply with law, respond to legal process, protect rights, and carry out a corporate transaction.

27. United States State Privacy Rights

This Section describes rights under United States state privacy laws. It applies to residents of states with applicable laws, subject to each law thresholds and exceptions, and to the extent those laws apply to our Processing. Many of these laws exempt information Processed in a business-to-business or employment context, information subject to other federal laws, and de-identified and publicly available information, and we rely on those exemptions where they apply.

27.1 California

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights described below, subject to exceptions. The categories of Personal Information we collect, use, disclose, and Sell or Share are described in Section 26.

Right to know and access. You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of source, the business or commercial purposes for collecting, selling, or sharing it, and the categories of third parties to whom we disclose it.

Right to delete. You may request that we delete Personal Information we collected from you, subject to the exceptions the law provides, including where the information is necessary to complete a transaction, provide the Services, detect or prevent fraud, comply with law, or exercise or defend legal claims.

Right to correct. You may request that we correct inaccurate Personal Information we maintain about you, taking into account the nature of the information and the purposes of Processing.

Right to opt out of Sale and Sharing. You may opt out of our Sale and Sharing of your Personal Information, including for cross-context behavioral advertising, using the mechanism we provide and recognized opt-out preference signals.

Right to limit Sensitive Personal Information. You may direct us to limit the use and disclosure of your Sensitive Personal Information to the purposes the law permits. As described in Section 28, we do not use or disclose Sensitive Personal Information for purposes beyond those permitted, so this right does not further restrict our use.

Right to non-discrimination. We will not discriminate against you for exercising your rights. We do not offer financial incentives for the Processing of Personal Information at this time.

Shine the Light. California Civil Code Section 1798.83 allows California residents to request information about our disclosures, if any, of Personal Information to third parties for their own direct-marketing purposes. You may make such a request using the contact details in Section 34.

How to exercise and verify. Submit a request using the contact details in Section 34 or any opt-out mechanism we provide. We will verify your request as the law requires, respond within the statutory timeframe, and allow an authorized agent to act for you with proof of authority.

27.2 Virginia, Colorado, Connecticut, and Utah

If you are a resident of Virginia (Consumer Data Protection Act), Colorado (Colorado Privacy Act), Connecticut (Connecticut Data Privacy Act), or Utah (Utah Consumer Privacy Act), and to the extent the law applies, you may have rights to confirm whether we Process your Personal Information and to access it, to correct inaccuracies, to delete Personal Information, to obtain a portable copy of information you provided, and to opt out of Targeted Advertising, the Sale of Personal Information, and Profiling in furtherance of decisions that produce legal or similarly significant effects. Under the Virginia, Colorado, and Connecticut laws you may appeal a denial by contacting us, and if the appeal is denied you may contact your state attorney general. Under the Colorado and Connecticut laws we honor recognized universal opt-out mechanisms.

27.3 Texas, Oregon, Montana, and additional states

If you are a resident of Texas (Data Privacy and Security Act), Oregon (Consumer Privacy Act), Montana (Consumer Data Privacy Act), Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Maryland, Minnesota, or Rhode Island, then as and when each law takes effect and to the extent it applies to us, you may have rights substantially similar to those described above, including to access, correct, delete, and port Personal Information and to opt out of Targeted Advertising, Sale, and certain Profiling, together with an appeal right where the law provides one. Some of these laws require us to honor universal opt-out preference signals, and we do so where required. The specific rights, exceptions, and thresholds are those the applicable state law provides.

27.4 Nevada

Nevada law gives certain residents the right to direct a covered operator not to sell certain covered information. You may submit such a request using the contact details in Section 34.

28. California Notice at Collection and Retention

This Section serves as our notice at collection for California residents. At or before the point of collection, we collect the categories of Personal Information described in Sections 5, 6, and 26, including Sensitive Personal Information such as government identifiers, financial-account information, and account credentials. We collect it for the purposes described in Sections 9 through 15, we may Sell or Share the categories indicated in Section 26 for advertising, and we retain each category for the periods described in Section 18 or, where a fixed period is not practicable, for as long as reasonably necessary for the disclosed purposes and to comply with law. We do not use or disclose Sensitive Personal Information for purposes other than those permitted by the California Privacy Rights Act, and therefore the right to limit does not restrict our use beyond those permitted purposes.

29. European Economic Area and United Kingdom

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation, the United Kingdom GDPR, or comparable law gives you the following rights, subject to conditions and exceptions:

  • Right of access: to obtain confirmation of whether we Process your Personal Information and a copy of it, together with information about the Processing.

  • Right to rectification: to have inaccurate Personal Information corrected and incomplete information completed.

  • Right to erasure: to have Personal Information deleted in certain circumstances, such as where it is no longer necessary or where you withdraw consent and no other basis applies.

  • Right to restriction: to have Processing restricted in certain circumstances, such as while a dispute about accuracy or our legitimate interests is resolved.

  • Right to object: to object to Processing based on our legitimate interests on grounds relating to your situation, and to object at any time to Processing for direct marketing.

  • Right to data portability: to receive Personal Information you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.

  • Right to withdraw consent: to withdraw consent at any time where Processing is based on consent, without affecting Processing already carried out.

  • Rights regarding automated decisions: not to be subject to a decision based solely on automated Processing that produces legal or similarly significant effects, except as the law permits, and to obtain human intervention, express your view, and contest the decision.

  • Right to complain: to lodge a complaint with your local Supervisory Authority.

Our legal bases are described in Section 10, and where we rely on legitimate interests you may ask about the balancing we performed. You may exercise your rights using the contact details in Section 34, and we ask that you contact us first so that we can try to resolve your concern before you approach a Supervisory Authority. Where we are required to designate a representative or a data protection officer, the relevant contact is set out in Section 34. Where we Process your information as a Processor for a client, we will refer your request to that client as the Controller and assist as the law and any Data-Processing Addendum require.

30. Other Regions

Canada. Where Canadian privacy law applies, including the Personal Information Protection and Electronic Documents Act and comparable provincial laws, you may have rights to access and correct your Personal Information and to withdraw consent subject to legal and contractual restrictions, and you may contact us and, if unsatisfied, the Office of the Privacy Commissioner of Canada.

Australia and New Zealand. Where the Australian Privacy Principles or the New Zealand Privacy Act applies, you may have rights to access and correct your Personal Information and to complain to us and, if unsatisfied, to the relevant information commissioner.

Brazil. Where the Lei Geral de Proteo de Dados applies, you may have rights to confirmation and access, correction, anonymization or deletion, portability, information about sharing, and to object to or withdraw consent for certain Processing, exercisable using the contact details in Section 34.

Switzerland. Where the Swiss Federal Act on Data Protection applies, you may have rights of access and correction and other rights that law provides, and you may contact the Swiss Federal Data Protection and Information Commissioner. We rely on the Swiss addendum to the Standard Contractual Clauses where required for transfers.

Other jurisdictions. Where the law of another jurisdiction grants you privacy rights, we honor those the law requires. In every case, we provide only the rights applicable law requires and reserve all others, and this Policy is to be read as granting the broadest use of information the applicable law permits.

31. Your Choices and Controls

You have choices about how we and our partners collect and use information. The availability and effect of these choices depend on your jurisdiction and the technologies in use.

Cookies and tracking. You can manage cookies through our consent tool where presented and through your browser settings, and you can clear or block cookies, although doing so may impair the Site. Where required, we treat recognized opt-out preference signals such as Global Privacy Control as a valid opt-out of Sale and Sharing for the browser or device that transmits them.

Advertising choices. You can opt out of certain interest-based advertising through industry programs, including the Digital Advertising Alliance, the Network Advertising Initiative, and, in Europe, Your Online Choices, and through the settings offered by advertising platforms such as Google and Meta. On mobile devices you can reset or limit the use of your advertising identifier through your device settings.

Marketing communications. You can opt out of marketing emails using the unsubscribe link, opt out of marketing texts by replying STOP where offered, and contact us to opt out of other marketing. Service and transactional communications will continue.

Account and device controls. You can review and update certain information by contacting us, and you can control location and notification permissions through your device and browser settings.

Opt-out of Sale and Sharing. Where the law grants it, you may opt out of the Sale and Sharing of your Personal Information and limit the use of Sensitive Information as described in Sections 15 and 25 through 27.

32. Data-Processing Terms When We Act as a Processor

This Section applies where we Process Personal Information as your Processor or service provider, and supplements any Data-Processing Addendum executed with you, which controls in the event of conflict. It reflects the data-processing terms our agreements contemplate.

Documented instructions. We Process such Personal Information only on your documented instructions, including as set out in the Terms, this Policy, and any Data-Processing Addendum and Statement of Work, and as required by law, in which case we will inform you where the law permits. We do not sell such Personal Information and do not retain, use, or disclose it for any purpose other than performing the Services, except as permitted by applicable law.

Confidentiality. We ensure that persons authorized to Process such Personal Information are bound by appropriate obligations of confidentiality.

Security. We implement technical and organizational measures as described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing.

Subprocessors. You provide general authorization for us to engage subprocessors on the terms in Section 14, and we impose data-protection obligations on them by contract and remain responsible for their performance to the extent required by law.

Assistance. Taking into account the nature of the Processing and the information available to us, we provide reasonable assistance with your obligations to respond to data-subject requests and with your security, breach-notification, and assessment obligations, at your expense where the law permits.

Breach. We notify you without undue delay after becoming aware of a confirmed personal-data breach affecting your Personal Information, as described in Section 21.

Return and deletion. At the end of the provision of the Services, we return or delete such Personal Information as described in Section 18 and any Data-Processing Addendum, except for copies required or permitted by law or held in routine backups.

Records and audit. We make available information reasonably necessary to demonstrate compliance with these terms and, subject to confidentiality and reasonable notice and frequency limits, allow for audits as the law requires and any Data-Processing Addendum provides.

Liability tie-back. Our liability under these terms and any Data-Processing Addendum is subject in the aggregate to the disclaimers, limitation of liability, and liability cap in the Terms, to the fullest extent permitted by law.

33. Annex A: Details of Processing

This Annex describes the Processing we carry out, for transparency and to support any Data-Processing Addendum.

Subject matter and duration. The subject matter is the provision of the Services; the duration is the term of the engagement and any period thereafter permitted or required by law.

Nature and purpose. Assessment, diagnosis, preparation, submission, escalation, and management of reinstatement, dispute, funds-release, brand-protection, and reputation matters, and the operation, security, improvement, and marketing of the Site and the Services.

Categories of data subject. You and your representatives and personnel, your customers and counterparties where reflected in case materials, visitors to the Site, and other individuals whose information appears in the materials you provide.

Categories of Personal Information. The categories set out in Sections 5, 6, and 26, including identifiers, contact, account and case data, financial and transaction data, communications, commercial data, device and usage data, Sensitive Information provided to work a matter, and inferences and derived data.

Recipients. The categories of recipient set out in Sections 13 and 14.

Transfers. To the United States, the Philippines, Armenia, and other jurisdictions, subject to Section 19.

34. Annex B: Technical and Organizational Measures

We maintain a program of administrative, technical, and organizational measures reasonably designed to protect information, which may include the following, as appropriate to the Services and subject to change as our program evolves:

  • Access control: role-based and least-privilege access, unique credentials, and prompt revocation on role change or engagement end.

  • Authentication: strong authentication controls for administrative and remote access where appropriate.

  • Encryption: encryption of Personal Information in transit over public networks, and at rest where appropriate.

  • Network and endpoint security: firewalls, segmentation where appropriate, and endpoint protections.

  • Logging and monitoring: logging of relevant events and monitoring for anomalous activity.

  • Secure development and change management: review and change-control practices for systems we operate.

  • Vendor management: due diligence and contractual data-protection obligations on Subcontractors.

  • People: confidentiality obligations, background checks where appropriate and lawful, and security awareness for personnel.

  • Resilience: backup and, where appropriate, business-continuity and incident-response procedures.

  • Credential handling: prompt rotation or revocation of client credentials shared with us at the conclusion of an engagement.

No set of measures guarantees absolute security, and this Annex does not expand the warranties or liability we accept, which are governed by Section 20 and by the Terms.

35. Annex C: Categories of Subprocessors and International Transfers

The categories of Subcontractor and subprocessor we engage, and the general purposes for which we engage them, include the following. Specific providers may change from time to time, and where required by law we will make available the current list and a mechanism for notice of changes.

CategoryPurposeTypical location
Cloud hosting and storageHosting the Site, storing data, and running our systemsUnited States
Communications and messagingEmail, SMS, WhatsApp, telephony, and schedulingUnited States and elsewhere
AnalyticsSite and Services analytics and performanceUnited States
Advertising and marketingAdvertising, campaign measurement, and marketing operationsUnited States
Payment processingBilling, payments, and fraud preventionUnited States
Customer support and case handlingSupporting clients and working mattersPhilippines, Armenia, United States
Identity and verificationAuthentication and identity verificationUnited States
Professional advisersLegal, accounting, audit, and insuranceUnited States

Transfers to Subcontractors outside your jurisdiction are made subject to Section 19, including, where required, the Standard Contractual Clauses and any supplementary measures.

36. Accessibility of This Policy

We seek to make this Policy accessible. If you have a disability and require this Policy in an alternative format, or need assistance exercising a right, contact us using the details in Section 34 and we will provide a reasonable accommodation.

37. Changes to This Policy

We may amend this Policy at any time by posting the revised Policy on the Site and updating the “Last updated” date, and we may notify you of material changes by other means where the law requires. Changes take effect upon posting or upon such later date as we may state. Your continued use of the Site or the Services after the effective date of any change constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically. Prior versions are available on request.

38. Governing Law; Dispute Resolution; Liability

This Policy, and any dispute arising out of or relating to it or to our Processing of information, is governed by the internal laws of the State of New York, without regard to conflict-of-laws rules, and is subject to the negotiation, binding arbitration, jury-trial and class-action waiver, and other dispute-resolution provisions of the Terms, which are incorporated by reference, except to the extent a mandatory provision of applicable law provides otherwise. Our liability arising out of or relating to this Policy, and under any data-processing addendum, is subject in the aggregate to the disclaimers, the limitation of liability, and the liability cap set out in the Terms, to the fullest extent permitted by law.

39. How to Contact Us; Data Protection Officer; Complaints

For any question, request, or complaint about this Policy or our Processing of information, contact us:

Basilio Inc, operating the brand “Got Suspended?”

Attention: Data Protection Officer

301 Bayview Circle, Suite A5151, Newport Beach, CA 92660, United States

Data Protection Officer: DPO@gotsuspendedclients.com

Privacy inquiries: privacy@gotsuspendedclients.com

Support: support@gotsuspendedclients.com

Telephone: +1 833 357 2888 WhatsApp: +1 661 670 7558

If you are in the European Economic Area or the United Kingdom and we are required to designate a representative, you may address correspondence to our Data Protection Officer at the details above, and we will direct it appropriately. You may also lodge a complaint with your local supervisory authority, though we ask that you contact us first so we can address your concern.

ACKNOWLEDGMENT. By using the Site or the Services, you affirm that you have read and understood this Policy and consent, on your own behalf and on behalf of the individuals whose information you provide, to the collection, use, sharing, retention, sale, and Processing of information as described, to the fullest extent permitted by applicable law.