Privacy Policy

CyberSoul SecurITy, LLC

Effective Date: 8/4/2026 Last Updated: 8/4/2026

1. Introduction

CyberSoul SecurITy, LLC ("CyberSoul SecurITy," "we," "us," or "our") is a California-organized limited liability company providing information technology and cybersecurity services. We respect your privacy and are committed to protecting the personal information you entrust to us.

This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you. It applies to:

  • Our website at CyberSoulSecurITy.com and any subdomains (the "Site");

  • Our managed IT, cybersecurity, consulting, and related services (the "Services");

  • Our communications with clients, prospective clients, vendors, and job applicants.

This Policy does not apply to third-party websites or services we link to, or to information we process on behalf of our business clients as a service provider (see Section 8).

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamplesIdentifiersName, email address, phone number, mailing address, company name, job titleCommercial informationServices purchased or inquired about, billing records, contract detailsFinancial informationPayment card or ACH details (processed by our payment processor; we do not store full card numbers)Professional informationResume, work history, and references if you apply for employmentCommunicationsSupport tickets, emails, chat messages, call notes, survey and form responses

2.2 Information Collected Automatically

When you visit the Site, we and our service providers may automatically collect:

  • IP address and approximate geolocation derived from it

  • Browser type, operating system, device identifiers, and screen resolution

  • Pages viewed, referring URL, links clicked, and time spent

  • Cookie and similar tracking identifiers (see Section 6)

2.3 Information Collected Through Delivery of Services

To deliver security monitoring, incident response, endpoint management, and similar Services, our tools may collect technical and security telemetry from client environments, which can include:

  • System, network, and application log data

  • Endpoint configuration, running processes, and installed software inventory

  • Authentication events, user account names, and access records

  • Security alerts, detected threat indicators, and forensic artifacts

  • Email metadata and, where a client enables such features, message content flagged by security filtering

This data may incidentally contain personal information about a client's employees, contractors, or customers. We process it under our client's direction as described in Section 8.

2.4 Information from Third Parties

We may receive information from business partners, referral sources, publicly available sources, threat intelligence feeds, credit or background check providers (where permitted and with consent), and analytics or advertising providers.

2.5 Sensitive Information

We do not intentionally collect sensitive personal information (such as government identifiers, health data, precise geolocation, or biometric data) except where necessary for employment or as incidentally present in client environments we are engaged to protect. We do not use or disclose sensitive personal information for purposes of inferring characteristics about individuals.

3. How We Use Information

We use personal information to:

  1. Provide, operate, maintain, and improve the Services;

  2. Detect, investigate, contain, and remediate security incidents and threats;

  3. Set up accounts, provision access, and provide technical support;

  4. Process payments, invoice clients, and manage our contractual relationships;

  5. Respond to inquiries, requests for proposals, and support requests;

  6. Send service, administrative, and security notifications;

  7. Send marketing communications, where permitted and subject to your right to opt out;

  8. Analyze usage of the Site to improve content, performance, and user experience;

  9. Evaluate job applicants and administer employment;

  10. Comply with legal obligations, enforce our agreements, and establish, exercise, or defend legal claims;

  11. Protect the rights, property, and safety of CyberSoul SecurITy, our clients, and the public.

4. Legal Bases for Processing (EEA/UK Individuals)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract — to provide Services you or your employer has engaged us for.

  • Legitimate interests — to secure our systems and our clients' systems, prevent fraud, market to business contacts, and operate our business, balanced against your rights.

  • Legal obligation — to comply with applicable law, including breach notification requirements.

  • Consent — for certain cookies, marketing emails, and other optional processing. You may withdraw consent at any time.

5. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We disclose personal information to:

  • Service providers and subprocessors who perform functions on our behalf — cloud hosting, security tooling vendors, EDR/SIEM platforms, ticketing and CRM systems, payment processors, email delivery, and professional advisors. These parties are contractually bound to use the information only to provide services to us and to protect it appropriately.

  • Clients — where the information relates to their environment, users, or a security incident affecting them.

  • Legal and regulatory authorities — when required by law, subpoena, court order, or other valid legal process, or where necessary to investigate suspected illegal activity or security incidents.

  • Business transferees — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy's continued protections.

  • With your direction or consent — in any other case where you ask or authorize us to share.

A current list of our subprocessors is available on request at hello@cybersoulsecurity.com.

6. Cookies and Tracking Technologies

The Site uses cookies, pixels, and similar technologies for:

  • Strictly necessary functions — security, session management, load balancing;

  • Analytics — understanding how visitors use the Site;

  • Preferences — remembering your settings.

You can control cookies through your browser settings and, where offered, through our cookie banner. Blocking cookies may impair Site functionality.

Global Privacy Control (GPC). We honor GPC and similar browser-based opt-out preference signals as a valid request to opt out of sale/sharing where applicable law requires. We do not otherwise respond to Do Not Track signals, as no common standard exists.

7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, multi-factor authentication, network segmentation, logging and monitoring, vulnerability management, personnel background screening, security awareness training, and a documented incident response plan.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you share information with us at your own risk. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.

8. Our Role as a Service Provider / Processor

When we process data within a client's systems in the course of delivering the Services, we act as a service provider (under U.S. state privacy laws) or processor (under the GDPR/UK GDPR) on behalf of that client, who acts as the business or controller. In that role we:

  • Process personal information only on documented instructions from the client and as necessary to perform the Services;

  • Do not sell, share, retain, use, or disclose that information outside the direct business relationship or for any purpose other than performing the Services and permitted business purposes;

  • Assist the client in responding to individual rights requests and in meeting security and breach-notification obligations;

  • Bind our subprocessors to equivalent obligations.

If you are an employee, contractor, or customer of one of our clients and want to exercise rights over your personal information, please contact that organization directly. We will forward such requests to the relevant client where we can identify them.

9. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, including to satisfy legal, accounting, tax, contractual, and security requirements.

Our general retention periods are:

Client contract and billing records - 7 years after the end of the engagement

Security logs and telemetry - As specified in the applicable client agreement; where not specified, no longer than 12 months

Incident response and forensic records - 3 years after the matter is closed, or longer where a legal hold or client agreement requires

Website analytics - No longer than 14 months

Marketing contacts - Until you unsubscribe, or after 24 months of inactivity

Support tickets and correspondence - No longer than 3 years after the matter is resolved

Where a longer period is required by law, contract, or an active legal hold, that period controls. When retention is no longer required, we delete or de-identify the information.

10. Your Privacy Rights

Depending on where you live, you may have the right to:

  • Know / Access — request the categories and specific pieces of personal information we hold about you, the sources, purposes, and recipients;

  • Delete — request deletion of your personal information;

  • Correct — request correction of inaccurate personal information;

  • Portability — receive a copy in a portable, machine-readable format;

  • Opt out — of the sale or sharing of personal information and of targeted advertising (note: we do not engage in these activities);

  • Limit — the use of sensitive personal information;

  • Object or restrict — processing based on legitimate interests (EEA/UK);

  • Withdraw consent — at any time, without affecting prior processing;

  • Non-discrimination — we will not deny services, charge different prices, or provide a different quality of service because you exercised your rights;

  • Appeal — if we deny your request, you may appeal by replying to our decision. We will respond within the timeframe required by your state's law.

How to Exercise Your Rights

Email hello@cybersoulsecurity.com or write to us at the address in Section 15. We will verify your identity before acting, typically by confirming information already in our records or by asking you to respond from an email address we have on file. An authorized agent may submit a request on your behalf with written permission and proof of identity.

We respond to verifiable requests within 45 days (extendable by an additional 45 days with notice) under U.S. state laws, or within one month (extendable by two months) under the GDPR/UK GDPR.

EEA/UK residents may also lodge a complaint with their local supervisory authority. UK residents may contact the Information Commissioner's Office (ico.org.uk).

11. International Data Transfers

We are based in the United States and process information there. If you access the Site or Services from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data protection laws than your jurisdiction. Where required, we use appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Copies are available on request.

12. Children's Privacy

The Site and Services are directed to businesses and are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact hello@cybersoulsecurity.com and we will delete it.

13. Third-Party Links and Services

The Site may link to third-party websites, tools, or platforms we do not control. This Policy does not apply to them. We encourage you to review the privacy policies of any third party before providing information.

14. Changes to This Policy

We may update this Policy from time to time. We will revise the "Last Updated" date above and, for material changes, provide additional notice by email or a prominent notice on the Site. Your continued use of the Site or Services after the effective date constitutes acceptance of the updated Policy.