How BFC Secure LLC collects, uses, protects and retains personal information across its website, its engineering engagements and its managed support services. Return to the homepage
BFC Secure LLC respects the privacy of every person who visits this website, contacts the practice, or uses services delivered by the firm. This Privacy Policy explains what personal information is collected, why it is collected, how it is protected and how long it is kept. The policy has been written by the developer and engineering team trading as BFC Secure so that readers can understand the commitments the practice makes without needing legal training. It applies to the website published at bfcsecure.buzz and to the professional services provided by the firm. It does not apply to systems that a client owns and operates independently, although the practice does describe how it treats client system data in a dedicated section below.
Where this policy refers to personal data or personal information, it means any information relating to an identified or identifiable natural person. Where it refers to processing, it means any operation performed on personal data, including collection, storage, use, disclosure, alteration and deletion. The practice processes personal data only for the purposes set out in this policy and only where a lawful basis exists.
The controller responsible for personal data processed through this website and through the professional services described on it is BFC Secure LLC, a computer systems design and technology engineering firm within the Professional, Scientific, and Technical Services sector. The registered address of the firm is 134 N Welden Way, Layton - 84041-8870, United States (US). The practice can be reached by email at security@bfcsecure.buzz and by telephone on +12705189782. Questions about this policy, requests relating to personal data, and complaints are handled through those contact points. The firm does not operate a separate data protection officer role at this time because the scale and nature of processing do not require one, but every privacy enquiry is routed to a named member of the practice who is accountable for the response.
The practice collects only the categories of personal data that are needed to answer enquiries, deliver engagements and operate the business lawfully. The categories are described below.
The practice does not knowingly collect special category data such as health information, biometric data, political opinions, religious beliefs or trade union membership through this website. If special category data is ever required for a specific engagement, it is requested only where a lawful condition applies and it is handled under heightened controls.
Personal data reaches the practice through several routes. The most common route is a direct message from a person who completes a contact form on this website, sends an email, places a telephone call or hands over a business card. A second route is a commercial relationship, where a client organisation provides the details of its staff so that an engagement can be delivered. A third route is the ordinary operation of the website, which records limited technical information whenever a page is requested. A fourth route is a referral, where an existing client or a professional contact introduces the practice to a new organisation and shares a working email address. In every case the practice asks for no more information than the situation requires and does not purchase personal data from data brokers.
Personal data is processed for the following purposes:
The practice does not use personal data for any purpose that is incompatible with the purposes listed above without first informing the person concerned and, where required, obtaining fresh authorisation.
Different lawful bases apply to different activities. Where a person asks a question or requests a proposal, processing is necessary to take steps at that person request before entering a contract, and later to perform the contract. Where the practice maintains records, secures its systems or protects against fraud, processing rests on the legitimate interests of the firm in operating a sound and safe business, balanced against the rights of the individual. Where the practice complies with tax, accounting or regulatory duties, processing is necessary to meet a legal obligation. Where the practice sends optional professional updates, processing rests on consent, which can be withdrawn at any time. Where the practice relies on legitimate interests, a balancing assessment is retained so that the reasoning can be explained on request.
The contact form on this website is deliberately simple. When a person completes the name, email address, subject and message fields and submits the form, the browser side script on the page assembles those values and opens the visitor own email application with the message addressed to security@bfcsecure.buzz. This means the enquiry travels from the visitor email account directly to the practice mailbox, and the website itself does not store the contents of the form. The practice receives the message as ordinary email, together with whatever information the mail system records, such as the sending address and the time of transmission. Email sent to the practice is stored in the secure mailbox of the firm and is retained in line with the retention rules described later in this policy. Visitors who prefer not to use a web form may write directly to the same address or call the duty desk on +12705189782.
During engineering and support engagements, the practice may access systems that belong to a client and that contain personal data of the client staff, customers or suppliers. In those situations the client remains the controller of that data and the practice acts as a processor on the documented instructions of the client. Access is limited to what is necessary to perform the agreed work, is granted only to engineers who need it, and is removed when the task is complete. The practice does not copy client production data to personal devices, does not use client data for its own purposes and does not disclose client data to third parties except where the client instructs it or where the law compels it. Written processing terms, confidentiality commitments and deletion obligations are agreed with each client before access is granted.
Where a service provider handles personal data on behalf of the practice, the relationship is governed by a written agreement that sets out the subject matter of the processing, its duration, its nature and purpose, the type of personal data involved, the categories of data subject, and the obligations of the provider. Providers are required to process data only on the documented instructions of the practice, to apply appropriate technical and organisational security measures, to assist with requests from individuals, to notify the practice without undue delay if a personal data breach occurs, and to delete or return data at the end of the relationship. The practice reviews its providers periodically and will replace any provider that cannot demonstrate adequate safeguards. A current list of subprocessors relevant to a particular engagement is made available to clients on request.
The practice is established in the United States. Where personal data originates outside the United States and must be processed by the practice, transfers are conducted only with an appropriate safeguard in place. Depending on the circumstances, the safeguard may be a contractual data transfer agreement incorporating recognised standard clauses, an adequacy decision that covers the destination, or the explicit consent of the individual after being informed of the possible risks. Where a service provider stores data in more than one region, the practice confirms which regions are in use and ensures that the same safeguards follow the data. A person who wishes to know which safeguard applies to a specific transfer may ask through the contact points given in this policy and will receive a clear explanation.
Personal data is kept only for as long as it is needed for the purpose it was collected for, plus any additional period required by law. Enquiries that do not lead to an engagement are normally removed within twenty four months of the last contact. Engagement records, including designs, drawings and acceptance documents, are retained for the duration of the client relationship and for a further period because they serve as the technical history of an environment and may be needed for support, warranty, audit or legal reasons. Accounting records are kept for the period required by applicable tax and company law. Support records are kept while a service agreement is active and for a defined period afterwards. When a retention period ends, data is securely deleted or irreversibly anonymised so that it can no longer be linked to an individual.
The practice applies technical and organisational measures appropriate to the risk of the data it handles. Measures include encryption of data in transit for email and file exchange, encryption of storage volumes that hold engagement records, multi factor authentication for administrative accounts, role based access control so that engineers see only the systems they need, unique credentials rather than shared logins, and prompt removal of access when a person leaves a role or a project. Physical documents are kept in locked storage and are shredded when no longer required. Endpoints are patched on a scheduled cycle and are protected against malicious software. The practice maintains backups of its own business records and tests that restores work. Staff and contractors receive confidentiality commitments and regular reminders about secure handling of information, and security incidents are logged so that patterns can be reviewed and controls improved.
If a personal data breach occurs, the practice follows a defined response sequence. The incident is contained first, so that further exposure is stopped, and evidence is preserved so that the cause can be understood. The nature and scope of the breach is then assessed, including the categories of data involved and the likely consequences for affected individuals. Where the practice is acting as a processor, the relevant client is notified without undue delay and is supported with the information needed to meet the client own notification duties. Where the practice is acting as a controller, affected individuals and any competent supervisory authority are notified where the law requires it, together with a description of what happened and what is being done in response. After the immediate response, a review identifies the root cause and the changes needed to reduce the chance of recurrence, and those changes are tracked to completion. Lessons from incidents are folded back into the security measures described in this policy.
Depending on where a person lives and on the basis used for processing, a range of rights may apply. These rights are honoured by the practice wherever they apply.
These rights are not absolute. Some are limited by the interests of others, by legal obligations that require data to be kept, or by the need to establish and defend legal claims. Where a right cannot be honoured in full, the practice explains the reason clearly and in writing.
A person who wishes to exercise a right may write to security@bfcsecure.buzz or call +12705189782. A request should describe what is being asked for and should include enough information to confirm identity. The practice does not charge a fee for a reasonable request and aims to respond within thirty days, although complex requests may take longer, in which case the person is told why and given a revised date. Where a request affects data that a client controls and the practice processes on the client behalf, the practice passes the request to the client promptly and supports the client response. A person who is unhappy with the outcome may raise a complaint with the practice first so that the matter can be addressed directly, and may also complain to the competent supervisory authority in the relevant jurisdiction.
This website and the services of the practice are intended for businesses and professional users, not for children. The practice does not knowingly collect personal data from a child below the age at which consent can be given in the relevant jurisdiction, and does not direct advertising or profiling at children. If the practice becomes aware that personal data of a child has been collected without appropriate authorisation, the data is deleted promptly. A parent or guardian who believes that a child has provided personal data to the practice may contact security@bfcsecure.buzz so that the matter can be investigated and resolved without delay.
The practice sends professional updates about its own services only where a person has asked to receive them or where an existing business relationship makes the message relevant and the law permits it. Every such message contains a simple way to stop receiving further messages, and a request to stop is honoured promptly. The practice does not sell contact details to marketing companies, does not add a person to a list because that person appeared in a purchased database, and does not use personal data obtained during a client engagement for unrelated promotion. Where consent has been given for updates, it can be withdrawn at any time without affecting the delivery of any contracted service.
Telephone calls to the practice may be logged so that technical instructions, approvals and commitments can be recorded accurately. A short record of a call may include the date, the parties involved, the subject discussed and any decision reached. Telephone numbers provided for support purposes are used to return calls and to send service notifications related to an active engagement. The practice does not use telephone numbers for unsolicited marketing and does not share them with third parties for that purpose. Where a number is no longer needed, it is removed from active records in line with the retention rules in this policy.
The practice does not make decisions about individuals using solely automated means where those decisions produce legal effects or similarly significant effects. Engineering designs and commercial proposals are prepared and reviewed by people. Tooling may assist with monitoring, alerting or capacity forecasting inside a client environment, but the resulting recommendations are reviewed by an engineer before they are acted upon. Where a client operates automated tooling inside its own systems, that tooling is governed by the client own privacy notices rather than by this policy.
This website may link to external resources that are operated by other organisations. The practice does not control those resources and is not responsible for their content, their security or their privacy practices. A person who follows an external link should read the privacy notice of the destination site before providing personal data. Links are provided because they may be useful or relevant, and their presence does not imply endorsement of every statement or practice found there.
This policy may be updated to reflect changes in the way the practice works, changes in technology, or changes in the law. When an update is made, the revised policy is published on this page with a new effective date. Where a change is significant and affects how personal data is used, the practice takes reasonable steps to bring the change to the attention of affected individuals, either by a notice on the website or by direct communication where a relationship exists. Continued use of the website or continued engagement with the practice after an update indicates acceptance of the revised policy. A person who does not accept a revision may contact the practice to discuss the options available.
Questions, requests and complaints about privacy are welcome and are handled directly by the practice. The dedicated email address is security@bfcsecure.buzz and the telephone number is +12705189782. Written correspondence may be sent to BFC Secure LLC, 134 N Welden Way, Layton - 84041-8870, United States (US). A message that includes a clear description of the issue and a preferred method of reply will receive the fastest response. The practice aims to resolve every privacy matter fairly, promptly and in plain language, and it records the outcome so that its handling of personal data keeps improving over time.
Controller: BFC Secure LLC
Address: 134 N Welden Way, Layton - 84041-8870, United States (US)
Email: security@bfcsecure.buzz
Phone: +12705189782