BFC SECURE LLC

Privacy Policy

How BFC Secure LLC collects, uses, protects and retains personal information across its website, its engineering engagements and its managed support services. Return to the homepage

Contents

  1. Introduction And Scope
  2. Identity Of The Controller
  3. Personal Data We Collect
  4. Sources Of Personal Data
  5. Purposes Of Processing
  6. Lawful Bases For Processing
  7. Website Forms And Email Contact
  8. Cookies And Local Storage
  9. Data Held Within Client Systems
  10. Disclosure To Third Parties
  11. Service Providers And Subprocessors
  12. International Data Transfers
  13. Retention Periods
  14. Security Measures
  15. Incident And Breach Response
  16. Your Privacy Rights
  17. Exercising A Request
  18. Privacy For Children
  19. Marketing Communications
  20. Telephone And Text Records
  21. Automated Decision Making
  22. Third Party Links
  23. Changes To This Policy
  24. Contacting The Practice

Introduction And Scope

BFC Secure LLC respects the privacy of every person who visits this website, contacts the practice, or uses services delivered by the firm. This Privacy Policy explains what personal information is collected, why it is collected, how it is protected and how long it is kept. The policy has been written by the developer and engineering team trading as BFC Secure so that readers can understand the commitments the practice makes without needing legal training. It applies to the website published at bfcsecure.buzz and to the professional services provided by the firm. It does not apply to systems that a client owns and operates independently, although the practice does describe how it treats client system data in a dedicated section below.

Where this policy refers to personal data or personal information, it means any information relating to an identified or identifiable natural person. Where it refers to processing, it means any operation performed on personal data, including collection, storage, use, disclosure, alteration and deletion. The practice processes personal data only for the purposes set out in this policy and only where a lawful basis exists.

Identity Of The Controller

The controller responsible for personal data processed through this website and through the professional services described on it is BFC Secure LLC, a computer systems design and technology engineering firm within the Professional, Scientific, and Technical Services sector. The registered address of the firm is 134 N Welden Way, Layton - 84041-8870, United States (US). The practice can be reached by email at security@bfcsecure.buzz and by telephone on +12705189782. Questions about this policy, requests relating to personal data, and complaints are handled through those contact points. The firm does not operate a separate data protection officer role at this time because the scale and nature of processing do not require one, but every privacy enquiry is routed to a named member of the practice who is accountable for the response.

Personal Data We Collect

The practice collects only the categories of personal data that are needed to answer enquiries, deliver engagements and operate the business lawfully. The categories are described below.

  • Identity information such as a person name, job title, employer name and role within an organisation.
  • Contact information such as an email address, a business telephone number, a postal address and a preferred method of contact.
  • Enquiry information that a person chooses to provide when describing a technical problem, a project requirement or a commercial need.
  • Engagement records created during a project, including correspondence, meeting notes, decisions, approvals and acceptance records.
  • Technical information generated when the website is used, such as the internet protocol address that reaches the server, the browser type, the device category, the referring page and the time of the request.
  • Financial and billing information where a person or organisation purchases services, limited to what is required for invoicing and accounting.
  • Support records created when a client reports a fault, including diagnostic details and the resolution history.

The practice does not knowingly collect special category data such as health information, biometric data, political opinions, religious beliefs or trade union membership through this website. If special category data is ever required for a specific engagement, it is requested only where a lawful condition applies and it is handled under heightened controls.

Sources Of Personal Data

Personal data reaches the practice through several routes. The most common route is a direct message from a person who completes a contact form on this website, sends an email, places a telephone call or hands over a business card. A second route is a commercial relationship, where a client organisation provides the details of its staff so that an engagement can be delivered. A third route is the ordinary operation of the website, which records limited technical information whenever a page is requested. A fourth route is a referral, where an existing client or a professional contact introduces the practice to a new organisation and shares a working email address. In every case the practice asks for no more information than the situation requires and does not purchase personal data from data brokers.

Purposes Of Processing

Personal data is processed for the following purposes:

  • To respond to enquiries, questions and requests for information, and to provide a quotation or proposal when one is asked for.
  • To plan, deliver, test and document engineering engagements across integrated systems, networks, security, cloud and integration work.
  • To provide managed technology support under an agreed service arrangement, including monitoring, maintenance and incident handling.
  • To maintain accurate business records, issue invoices, reconcile payments and meet accounting and tax obligations.
  • To keep the website secure, available and functioning correctly, and to diagnose faults or abuse.
  • To improve the clarity and usefulness of the information published on this website.
  • To send service related notifications and, where consent has been given, occasional professional updates.
  • To establish, exercise or defend legal claims where that becomes necessary.

The practice does not use personal data for any purpose that is incompatible with the purposes listed above without first informing the person concerned and, where required, obtaining fresh authorisation.

Lawful Bases For Processing

Different lawful bases apply to different activities. Where a person asks a question or requests a proposal, processing is necessary to take steps at that person request before entering a contract, and later to perform the contract. Where the practice maintains records, secures its systems or protects against fraud, processing rests on the legitimate interests of the firm in operating a sound and safe business, balanced against the rights of the individual. Where the practice complies with tax, accounting or regulatory duties, processing is necessary to meet a legal obligation. Where the practice sends optional professional updates, processing rests on consent, which can be withdrawn at any time. Where the practice relies on legitimate interests, a balancing assessment is retained so that the reasoning can be explained on request.

Website Forms And Email Contact

The contact form on this website is deliberately simple. When a person completes the name, email address, subject and message fields and submits the form, the browser side script on the page assembles those values and opens the visitor own email application with the message addressed to security@bfcsecure.buzz. This means the enquiry travels from the visitor email account directly to the practice mailbox, and the website itself does not store the contents of the form. The practice receives the message as ordinary email, together with whatever information the mail system records, such as the sending address and the time of transmission. Email sent to the practice is stored in the secure mailbox of the firm and is retained in line with the retention rules described later in this policy. Visitors who prefer not to use a web form may write directly to the same address or call the duty desk on +12705189782.

Cookies And Local Storage

The public pages of this website are built to function without advertising trackers. The site does not set behavioural advertising cookies and does not build cross site profiles of visitors. Any cookies or local storage entries that a web server or a content delivery layer creates are used for security, load balancing and basic availability rather than for marketing. Strictly necessary cookies support functions such as protecting forms against abuse and remembering a navigation choice for the duration of a visit. A visitor may block or delete cookies through browser settings, and the site will continue to display its content, though some conveniences may be lost. Where any non essential cookie is introduced in future, it will be described in an updated version of this policy before it begins to operate.

Data Held Within Client Systems

During engineering and support engagements, the practice may access systems that belong to a client and that contain personal data of the client staff, customers or suppliers. In those situations the client remains the controller of that data and the practice acts as a processor on the documented instructions of the client. Access is limited to what is necessary to perform the agreed work, is granted only to engineers who need it, and is removed when the task is complete. The practice does not copy client production data to personal devices, does not use client data for its own purposes and does not disclose client data to third parties except where the client instructs it or where the law compels it. Written processing terms, confidentiality commitments and deletion obligations are agreed with each client before access is granted.

Disclosure To Third Parties

The practice does not sell personal data and does not rent, trade or barter it. Disclosure happens only in limited and defined circumstances. Data may be shared with a service provider that supports the operation of the business, such as a hosting provider, an email provider, an accounting platform or a professional adviser, always under contract and always limited to what the provider needs. Data may be shared with a client organisation where the practice is delivering an engagement and the client needs the information to make a decision. Data may be shared with a competent authority where the practice is legally required to do so, or where disclosure is necessary to establish, exercise or defend a legal claim. Data may be shared with a successor organisation if the business is ever restructured, merged or sold, in which case the recipients remain bound by this policy until it is lawfully replaced.

Service Providers And Subprocessors

Where a service provider handles personal data on behalf of the practice, the relationship is governed by a written agreement that sets out the subject matter of the processing, its duration, its nature and purpose, the type of personal data involved, the categories of data subject, and the obligations of the provider. Providers are required to process data only on the documented instructions of the practice, to apply appropriate technical and organisational security measures, to assist with requests from individuals, to notify the practice without undue delay if a personal data breach occurs, and to delete or return data at the end of the relationship. The practice reviews its providers periodically and will replace any provider that cannot demonstrate adequate safeguards. A current list of subprocessors relevant to a particular engagement is made available to clients on request.

International Data Transfers

The practice is established in the United States. Where personal data originates outside the United States and must be processed by the practice, transfers are conducted only with an appropriate safeguard in place. Depending on the circumstances, the safeguard may be a contractual data transfer agreement incorporating recognised standard clauses, an adequacy decision that covers the destination, or the explicit consent of the individual after being informed of the possible risks. Where a service provider stores data in more than one region, the practice confirms which regions are in use and ensures that the same safeguards follow the data. A person who wishes to know which safeguard applies to a specific transfer may ask through the contact points given in this policy and will receive a clear explanation.

Retention Periods

Personal data is kept only for as long as it is needed for the purpose it was collected for, plus any additional period required by law. Enquiries that do not lead to an engagement are normally removed within twenty four months of the last contact. Engagement records, including designs, drawings and acceptance documents, are retained for the duration of the client relationship and for a further period because they serve as the technical history of an environment and may be needed for support, warranty, audit or legal reasons. Accounting records are kept for the period required by applicable tax and company law. Support records are kept while a service agreement is active and for a defined period afterwards. When a retention period ends, data is securely deleted or irreversibly anonymised so that it can no longer be linked to an individual.

Security Measures

The practice applies technical and organisational measures appropriate to the risk of the data it handles. Measures include encryption of data in transit for email and file exchange, encryption of storage volumes that hold engagement records, multi factor authentication for administrative accounts, role based access control so that engineers see only the systems they need, unique credentials rather than shared logins, and prompt removal of access when a person leaves a role or a project. Physical documents are kept in locked storage and are shredded when no longer required. Endpoints are patched on a scheduled cycle and are protected against malicious software. The practice maintains backups of its own business records and tests that restores work. Staff and contractors receive confidentiality commitments and regular reminders about secure handling of information, and security incidents are logged so that patterns can be reviewed and controls improved.

Incident And Breach Response

If a personal data breach occurs, the practice follows a defined response sequence. The incident is contained first, so that further exposure is stopped, and evidence is preserved so that the cause can be understood. The nature and scope of the breach is then assessed, including the categories of data involved and the likely consequences for affected individuals. Where the practice is acting as a processor, the relevant client is notified without undue delay and is supported with the information needed to meet the client own notification duties. Where the practice is acting as a controller, affected individuals and any competent supervisory authority are notified where the law requires it, together with a description of what happened and what is being done in response. After the immediate response, a review identifies the root cause and the changes needed to reduce the chance of recurrence, and those changes are tracked to completion. Lessons from incidents are folded back into the security measures described in this policy.

Your Privacy Rights

Depending on where a person lives and on the basis used for processing, a range of rights may apply. These rights are honoured by the practice wherever they apply.

  • The right to be informed about how personal data is used, which this policy provides.
  • The right of access to personal data held about the individual, together with related details.
  • The right to correction of inaccurate or incomplete personal data.
  • The right to erasure of personal data in defined circumstances, often called the right to be forgotten.
  • The right to restrict processing so that data is held but not actively used while a question is resolved.
  • The right to object to processing based on legitimate interests or carried out for direct marketing.
  • The right to data portability, allowing a copy of certain data to be obtained in a common machine readable format.
  • The right to withdraw consent at any time where processing rests on consent.
  • The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

These rights are not absolute. Some are limited by the interests of others, by legal obligations that require data to be kept, or by the need to establish and defend legal claims. Where a right cannot be honoured in full, the practice explains the reason clearly and in writing.

Exercising A Request

A person who wishes to exercise a right may write to security@bfcsecure.buzz or call +12705189782. A request should describe what is being asked for and should include enough information to confirm identity. The practice does not charge a fee for a reasonable request and aims to respond within thirty days, although complex requests may take longer, in which case the person is told why and given a revised date. Where a request affects data that a client controls and the practice processes on the client behalf, the practice passes the request to the client promptly and supports the client response. A person who is unhappy with the outcome may raise a complaint with the practice first so that the matter can be addressed directly, and may also complain to the competent supervisory authority in the relevant jurisdiction.

Privacy For Children

This website and the services of the practice are intended for businesses and professional users, not for children. The practice does not knowingly collect personal data from a child below the age at which consent can be given in the relevant jurisdiction, and does not direct advertising or profiling at children. If the practice becomes aware that personal data of a child has been collected without appropriate authorisation, the data is deleted promptly. A parent or guardian who believes that a child has provided personal data to the practice may contact security@bfcsecure.buzz so that the matter can be investigated and resolved without delay.

Marketing Communications

The practice sends professional updates about its own services only where a person has asked to receive them or where an existing business relationship makes the message relevant and the law permits it. Every such message contains a simple way to stop receiving further messages, and a request to stop is honoured promptly. The practice does not sell contact details to marketing companies, does not add a person to a list because that person appeared in a purchased database, and does not use personal data obtained during a client engagement for unrelated promotion. Where consent has been given for updates, it can be withdrawn at any time without affecting the delivery of any contracted service.

Telephone And Text Records

Telephone calls to the practice may be logged so that technical instructions, approvals and commitments can be recorded accurately. A short record of a call may include the date, the parties involved, the subject discussed and any decision reached. Telephone numbers provided for support purposes are used to return calls and to send service notifications related to an active engagement. The practice does not use telephone numbers for unsolicited marketing and does not share them with third parties for that purpose. Where a number is no longer needed, it is removed from active records in line with the retention rules in this policy.

Automated Decision Making

The practice does not make decisions about individuals using solely automated means where those decisions produce legal effects or similarly significant effects. Engineering designs and commercial proposals are prepared and reviewed by people. Tooling may assist with monitoring, alerting or capacity forecasting inside a client environment, but the resulting recommendations are reviewed by an engineer before they are acted upon. Where a client operates automated tooling inside its own systems, that tooling is governed by the client own privacy notices rather than by this policy.

Third Party Links

This website may link to external resources that are operated by other organisations. The practice does not control those resources and is not responsible for their content, their security or their privacy practices. A person who follows an external link should read the privacy notice of the destination site before providing personal data. Links are provided because they may be useful or relevant, and their presence does not imply endorsement of every statement or practice found there.

Changes To This Policy

This policy may be updated to reflect changes in the way the practice works, changes in technology, or changes in the law. When an update is made, the revised policy is published on this page with a new effective date. Where a change is significant and affects how personal data is used, the practice takes reasonable steps to bring the change to the attention of affected individuals, either by a notice on the website or by direct communication where a relationship exists. Continued use of the website or continued engagement with the practice after an update indicates acceptance of the revised policy. A person who does not accept a revision may contact the practice to discuss the options available.

Contacting The Practice

Questions, requests and complaints about privacy are welcome and are handled directly by the practice. The dedicated email address is security@bfcsecure.buzz and the telephone number is +12705189782. Written correspondence may be sent to BFC Secure LLC, 134 N Welden Way, Layton - 84041-8870, United States (US). A message that includes a clear description of the issue and a preferred method of reply will receive the fastest response. The practice aims to resolve every privacy matter fairly, promptly and in plain language, and it records the outcome so that its handling of personal data keeps improving over time.

Controller: BFC Secure LLC

Address: 134 N Welden Way, Layton - 84041-8870, United States (US)

Email: security@bfcsecure.buzz

Phone: +12705189782

BFC Secure LLC, 134 N Welden Way, Layton - 84041-8870, United States (US)

security@bfcsecure.buzz · +12705189782

© 2026 BFC Secure LLC. All rights reserved.

Back To Homepage