Privacy Policy
01Overview
This Privacy Policy explains how Operating Security Solutions ("OSS", "we", "us", or "our") collects, uses, shares, and protects personal information through this website and its consultation request form (together, the "Site"), and the choices you have.
Protection work depends on discretion. We collect only what we need to respond to you and plan an engagement, and we share it only with people who need it.
This policy does not cover information we handle while performing services for a client. That information is governed by the service agreement and any non-disclosure agreement for the engagement.
02Summary
- We collect what you type into the contact form and basic technical data from your visit.
- We use it to respond to you, prepare a consultation or proposal, and run and secure the Site.
- We do not sell your personal information or share it for targeted advertising.
- We share it only with service providers that help us operate, with professional advisers, or when the law requires it.
- You can ask to see, correct, or delete your information at any time.
03Information you give us
When you send a consultation request, we collect:
- your name;
- your role (creator, manager, agency, or event contact);
- your email address;
- your phone number, if you provide it;
- the service you are interested in;
- the date of the appearance or event, if you provide it;
- the city or venue, if you provide it;
- anything you write in the message field.
If you email, call, or message us, we collect the contents of that communication and your contact details.
04Sensitive details and information about others
Requests for protection can involve schedules, locations, travel plans, threats, or past incidents. Share only what is needed for a first conversation. Once we know how we can help, we will ask for more detail, under confidentiality terms if you want them.
Please do not send government ID numbers, financial account information, health information, or passwords through the Site.
If you send information about a principal or another person, such as a creator you manage, you confirm that you have their permission or the legal right to share it. We use that information only to respond to your request.
05Information collected automatically
When you visit the Site, our hosting provider automatically records technical information such as your IP address, browser type and version, device type, operating system, the pages you request, the referring page, and the date and time of each request.
This information is used to deliver the Site, keep it secure, and diagnose problems. We do not use it to identify you unless that is needed to investigate misuse or a security incident.
06Information from other sources
To research and contact potential clients, we may collect business contact information that is publicly available, such as names, roles, business email addresses, and social media profiles of creators, managers, agencies, venues, and event organizers, from public websites, social media, and business directories.
We do not buy personal information from data brokers. If we contact you based on public information, you can ask us to stop and to delete that information at any time, and we will.
07Cookies and similar technologies
The Site does not currently use advertising cookies, cross-site tracking, or analytics cookies.
If we add analytics, such as Google Analytics, we will update this policy before we do, to describe the cookies used, the information collected, and how to opt out. You can also block or delete cookies in your browser settings.
We treat a Global Privacy Control signal from your browser as a request to opt out of any sale or sharing of your personal information. We do not sell or share personal information for targeted advertising in any case. Because there is no common standard for Do Not Track signals, the Site does not respond to them, and we do not track you across other websites.
08How we use information
We use personal information to:
- respond to your consultation request and communicate with you;
- assess whether and how OSS can help, and prepare a consultation, plan, or proposal;
- provide services if you or your organization become a client, under the service agreement;
- keep records of our communications and our business;
- operate, maintain, secure, and improve the Site, including preventing spam, fraud, and abuse;
- send marketing email, only if you have agreed to receive it;
- comply with the law, respond to lawful requests, and protect the rights, property, and safety of OSS, our clients, and others.
09Information we do not collect or use
- We do not knowingly collect sensitive personal information, such as government ID numbers, financial account details, health information, precise geolocation from your device, or biometric data, through the Site.
- We do not use personal information to infer characteristics about you, and we do not use automated decision-making or profiling that has legal or similarly significant effects on you.
- We do not record phone or video calls without telling you first.
We may use information that has been de-identified or combined so that it no longer identifies you, for example to count how many requests we receive for each service. We will not try to re-identify it.
10How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only as follows:
- Service providers. Companies that host the Site, process form submissions, deliver and store email, and manage our client records, only to perform services for us and under obligations to protect the information. Today this includes Vercel, which hosts the Site and processes the contact form. Once active, it will also include our email delivery provider, our business email provider, and our customer relationship management system. Each processes information under its own privacy and security terms.
- OSS personnel. People on the OSS team who need the information to respond or to plan an engagement, under confidentiality obligations.
- Professional advisers. Lawyers, accountants, insurers, and similar advisers, under duties of confidentiality.
- Legal requirements. When we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process.
- Safety. When we believe in good faith that disclosure is necessary to prevent imminent death or serious physical harm to a person.
- Business transfers. In connection with a merger, acquisition, financing, or sale of all or part of our business, subject to this policy.
- With your consent. In any other case where you ask us to or agree that we may.
11Requests from law enforcement
We disclose information to law enforcement or government agencies only when the law requires it, or when we believe in good faith that there is an imminent risk of death or serious physical injury. Where the law allows, we will notify the affected person before disclosing their information.
12Email and text messages
We use your email address and phone number to respond to your request. Any marketing email will identify OSS, include our physical mailing address, and include a working unsubscribe link, and we honor unsubscribe requests within 10 business days, as the CAN-SPAM Act requires.
We send text messages only with your prior express consent, as the Telephone Consumer Protection Act requires. Message frequency varies, message and data rates may apply, and you can reply STOP to opt out or HELP for help at any time. We do not share phone numbers with third parties for their own marketing.
13How long we keep information
- Consultation requests that do not lead to an engagement: up to 24 months after our last contact, then deleted.
- Client and engagement records: for the term of the service agreement and afterward for as long as needed to meet legal, tax, insurance, and licensing requirements.
- Technical logs: for the limited period set by our hosting provider.
- Marketing preferences, including unsubscribe requests: for as long as needed to honor them.
We may keep information longer when the law requires it or when it is needed for a legal claim.
14How we protect information
We use administrative, technical, and physical safeguards suited to the sensitivity of the information, including encrypted connections (HTTPS) for the Site and the contact form, access limited to people who need it, and strong account security on the systems we use.
Email and web forms are not a fully secure way to send highly sensitive information. Until we have agreed on a secure way to share them, please do not send details you would not want exposed, such as exact addresses, travel itineraries, or specific threats.
No method of transmission or storage is completely secure, and we cannot guarantee the security of information you send us. If a security breach affects your personal information, we will notify you and the authorities as required by law, including the Florida Information Protection Act (s. 501.171, Florida Statutes).
15Your choices and rights
You may ask us to:
- confirm whether we hold personal information about you and give you a copy;
- correct information that is inaccurate;
- delete your information, subject to legal exceptions;
- stop sending you marketing messages.
To make a request, use the contact form on this site. We will verify the request using information we already hold, such as by confirming your email address, and we aim to respond within 30 days and no later than 45 days.
You may use an authorized agent to make a request, and we may ask for proof of the agent's authority. We will not treat you differently for exercising any of these rights.
16Your responsibilities
You are responsible for the accuracy of the information you send us, for having permission or the legal right to share any information about other people, and for keeping your own devices, email, and accounts secure.
17Limits of our responsibility
To the fullest extent permitted by law, OSS is not responsible for: (a) unauthorized access to or use of information that results from causes outside our reasonable control; (b) information you choose to send through unsecured channels or to post publicly; or (c) the privacy or security practices of third-party websites, platforms, or services that you use directly, including social media platforms.
Our overall liability in connection with the Site is limited as described in our Terms of Service. Nothing in this policy limits any obligation we have under applicable law, including our obligation to notify you of a data breach.
18State privacy laws
OSS is a small business based in Florida. Under their current thresholds, comprehensive state consumer privacy laws such as the Florida Digital Bill of Rights and the California Consumer Privacy Act do not currently apply to OSS. We still honor the requests described in this policy for everyone, and we will update this policy if those laws come to apply to us.
19Children
The Site is intended for adults. We do not knowingly collect personal information from children under 16 through the Site. If a principal is a minor, a parent, legal guardian, or authorized manager should contact us.
If you believe a child has sent us personal information, contact us and we will delete it.
20Visitors outside the United States
OSS is based in the United States, and the Site is intended for people in the United States. Information is processed and stored in the United States, where privacy laws may differ from those in your country.
21Links to other websites
The Site may link to other websites. Their privacy practices are governed by their own policies, not this one.
22Changes to this policy
We may update this policy. We will post the updated version on this page, update the effective date, and, for material changes, give notice on the Site or by email where appropriate.
23Contact
Questions or requests about this policy: use the contact form on this site.