Privacy Policy for Analitica Defense
Effective Date: April 1, 2025
Updated Date: June 20, 2025
At Analitica Defense LLC ("Analitica Defense," "we," "us," or "our"), your privacy and the protection of your personal data are incredibly important to us. This Data Protection & Privacy Policy ("Policy") explains how we collect, use, store, share, and protect your personal information.
This Policy applies to everyone who interacts with Analitica Defense, including:
-
Visitors to our website
-
Our current and future clients
-
Business partners
-
Our employees and job applicants
Our Compliance & Global Reach
Based in Massachusetts, our data analytics, data science, and cybersecurity services often involve global data. Therefore, this Policy aims to comply with various data privacy laws, including:
-
Applicable Massachusetts state laws
-
US federal laws like the Children's Online Privacy Protection Act (COPPA) and the California Consumer Privacy Act (CCPA), where relevant
-
The General Data Protection Regulation (GDPR) of the European Union, especially when processing data of individuals located within the EU.
We also strive to comply with any other relevant regulations based on our client base and the type of data we handle.
Questions? Contact Our Privacy Team:
If you have any questions, requests, or concerns about your privacy, please reach out to us:
-
Email: [email protected]
-
Postal Address: 82 Wendell Ave, STE 100, Pittsfield, MA 01201, United States
1. Key Definitions
To help you understand this Policy, here are some important terms:
-
Personal Data: Any information that can identify you directly or indirectly. This includes things like your name, email address, IP address, location data, professional titles, company affiliations, and any other data you provide when using our services.
-
Processing: Any action performed on Personal Data, such as collecting, storing, using, sharing, or deleting it.
-
Data Controller: When Analitica Defense decides why and how your Personal Data is processed for our own business (e.g., managing client relationships, marketing), we are the Data Controller.
-
Data Processor: When we process Personal Data strictly on behalf of our clients and follow their instructions (e.g., as part of a cybersecurity service), we act as a Data Processor. Our responsibilities in these cases are covered by specific contracts called Data Processing Agreements (DPAs).
2. Our Data Processing Principles
We follow these core principles when handling your Personal Data:
-
Lawfulness, Fairness, & Transparency: We process your data legally, fairly, and openly.
-
Purpose Limitation: We collect data for specific, clear, and legitimate reasons and only use it for those purposes.
-
Data Minimization: We only collect the data that is truly necessary for our stated purposes.
-
Accuracy: We take steps to ensure your Personal Data is accurate and up-to-date, promptly correcting any inaccuracies.
-
Storage Limitation: We only keep Personal Data for as long as needed to fulfill the purposes for which it was collected, as per our data retention policies.
-
Integrity & Confidentiality: We process your data securely, protecting it from unauthorized access, loss, or damage using appropriate technical and organizational measures.
3. What Personal Data We Collect & How
The Personal Data we collect depends on how you interact with us. Generally, we collect data in these ways:
-
Directly From You:
-
When you fill out forms on our website (e.g., "Contact Us," job applications).
-
When you subscribe to newsletters or respond to surveys.
-
When you communicate with us via email or during service engagements.
-
This may include your name, email address, phone number, company name, job title, and other information you choose to provide.
-
-
Automatically Through Our Website:
-
When you visit our website, we may collect non-personal information like your browser type, device type, and technical connection details (e.g., operating system).
-
We use cookies and similar tracking technologies (like pixels) to improve your experience, analyze website traffic, personalize content, and remember your preferences.
-
You can adjust your browser settings to refuse cookies, but some parts of the website might not function correctly.
-
-
From Third Parties:
-
We may receive Personal Data from business partners, public databases, or service providers, where legally permissible and relevant to our services (e.g., for lead generation or background checks).
-
4. Why We Process Your Personal Data
We process Personal Data for specific and legitimate reasons, always based on a valid legal ground:
-
To Provide Our Services: To fulfill our contracts and deliver the data analytics, data science, and cybersecurity services you or your organization request.
-
Legal Basis: Performance of a contract, Legitimate Interests.
-
-
To Communicate With You: To respond to your inquiries, provide support, send important service updates, or for other customer service needs.
-
Legal Basis: Performance of a contract, Legitimate Interests, Consent.
-
-
For Marketing & Promotions: To send you company news, updates, and information about our products, services, and events. You can opt-out of marketing communications at any time.
-
Legal Basis: Legitimate Interests, Consent.
-
-
For Website Improvement & Analytics: To analyze how our website is used, improve its functionality, optimize your experience, and refine our services.
-
Legal Basis: Legitimate Interests, Consent.
-
-
For Recruitment & Employment: To process job applications, manage recruitment, and for internal HR administration.
-
Legal Basis: Legitimate Interests, Performance of a contract (for employees).
-
-
To Comply with Legal Obligations: To meet our legal duties, such as tax reporting or responding to lawful requests from authorities.
-
Legal Basis: Legal Obligation.
-
-
To Ensure System & Data Security: To protect our website, systems, and data, and to prevent fraud and unauthorized access.
-
Legal Basis: Legitimate Interests, Legal Obligation.
-
5. Our Legal Basis for Processing
We rely on the following legal grounds for processing Personal Data, as applicable under relevant data protection laws:
-
Consent: When you clearly agree to us processing your Personal Data for a specific purpose (e.g., for certain marketing or non-essential cookies). You can withdraw your consent at any time by contacting us.
-
Performance of a Contract: When processing is necessary for a contract with you, or to take steps you request before a contract (e.g., providing our services, processing your job application).
-
Legal Obligation: When processing is necessary to comply with a law Analitica Defense is subject to (e.g., tax laws, anti-money laundering).
-
Legitimate Interests: When processing is necessary for our legitimate business interests or those of a third party, provided your rights and freedoms don't override those interests. Our legitimate interests include improving services, ensuring security, direct marketing, and preventing fraud. We conduct a balancing test to ensure your rights are protected.
-
Other Legal Bases: We may also rely on other lawful bases permitted by applicable laws.
6. How We Share Personal Data
We do not sell, trade, or rent your Personal Data to others. We may share Personal Data with the following types of third parties for the purposes outlined in this Policy:
-
Service Providers: Trusted third-party vendors who perform services for us (e.g., IT hosting, cloud services, marketing). They are contractually bound to protect your information.
-
Business Partners: In specific cases, with trusted business partners for joint offerings or complementary services, always with appropriate safeguards and your consent if required.
-
Legal & Regulatory Authorities: If required by law, court order, or to protect our rights, property, or public safety.
-
Affiliates: With our affiliated entities for internal business operations.
-
Business Transfers: If we merge, are acquired, reorganize, or sell assets, your information may be transferred as part of that transaction. We will notify you of any such change.
-
With Your Consent: We may share your information with other third parties with your explicit consent.
Important Note on SMS Consent: SMS consent data and personal information collected for SMS communication will NOT be shared with third parties or affiliates for marketing or promotional purposes. This data is strictly used for the purposes for which it was collected, including customer support and delivering important service-related announcements.
International Data Transfers: If we transfer Personal Data outside of your country (e.g., outside the EU), we ensure appropriate safeguards are in place for adequate protection, such as relying on EU Commission adequacy decisions or Standard Contractual Clauses (SCCs).
7. How We Secure Your Data
As a cybersecurity company, Analitica Defense uses robust technical and organizational measures to ensure the security and confidentiality of your Personal Data. These measures protect against unauthorized or unlawful processing, and against accidental loss, destruction, or damage.
Technical Measures Include:
-
Encryption: Data encryption both during transmission and when stored.
-
Access Controls: Strict controls limiting access to Personal Data only to authorized personnel.
-
Firewalls & Intrusion Detection: Protecting our networks and systems from unauthorized access.
-
Regular Security Assessments: Periodic vulnerability scanning, penetration testing, and security audits.
-
Data Backup & Recovery: Robust plans for data backup and disaster recovery.
Organizational Measures Include:
-
Data Governance Policies: Comprehensive internal policies for data handling, security, and privacy.
-
Employee Training: Mandatory data protection and cybersecurity awareness training for all employees.
-
Data Breach Procedures: Defined internal procedures for identifying, containing, investigating, and reporting data breaches.
-
Confidentiality Agreements: Obligations for all employees and contractors handling Personal Data.
While we strive for the highest level of security, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we cannot guarantee absolute security.
8. Data Retention
We only keep your Personal Data for as long as necessary to fulfill the purposes for which it was collected, including meeting any legal, accounting, or reporting requirements.
Factors determining retention periods include:
-
Legal obligations that require us to retain certain data.
-
Ongoing business needs, service provision, or record-keeping.
-
If processing is based on consent, data is retained until consent is withdrawn, unless other legal bases apply.
-
Specific retention periods outlined in contractual agreements.
We regularly review and update our internal data retention schedules.
9. Your Rights & Choices
Under applicable data protection laws, you have certain rights regarding your Personal Data:
-
Right to Access: Request copies of your Personal Data we hold.
-
Right to Rectification: Ask us to correct inaccurate or incomplete information.
-
Right to Erasure (Right to be Forgotten): Request deletion of your Personal Data under certain circumstances.
-
Right to Restriction of Processing: Ask us to limit how we process your Personal Data under certain conditions.
-
Right to Data Portability: Receive your Personal Data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, where feasible.
-
Right to Object: Object to our processing of your Personal Data under certain circumstances, especially for direct marketing.
-
Rights in Relation to Automated Decision-Making & Profiling: Not to be subject to decisions based solely on automated processing (including profiling) that significantly affect you.
How to Exercise Your Rights: To exercise any of these rights, please contact our Privacy Team using the contact information at the top of this Policy. We may need to verify your identity to ensure the security of your data. We will respond to your request as required by law.
10. Cookies & Other Tracking Technologies
Our website uses "cookies" and similar tracking technologies (e.g., pixels, web beacons) to enhance your experience, analyze website usage, and for marketing.
-
What are Cookies? Small text files placed on your device by a website. They help websites work efficiently and provide information to site owners.
-
How We Use Them: To analyze traffic, personalize content and ads, remember preferences, and facilitate navigation.
-
Your Choices: You can set your web browser to refuse cookies or alert you when they're sent. Please note, some website features may not work properly if cookies are disabled.
For more detailed information about our cookies, their purposes, and how to manage your preferences, please refer to our dedicated Cookie Policy: https://analiticadefense.com/cookie-policy
11. Third-Party Links
Our website may contain links to third-party websites. Please be aware that Analitica Defense is not responsible for their privacy practices or content. We encourage you to review the privacy policies of any third-party websites you visit.
12. Data Breach Procedures
Analitica Defense has robust internal procedures for quickly identifying, containing, investigating, and reporting data breaches.
In the unfortunate event of a data breach that poses a high risk to your rights and freedoms, we will notify affected individuals and relevant data protection authorities as required by law. This notification will be timely and transparent, providing clear information about the breach, its potential impact, and the steps we're taking to address it.
13. Children's Privacy
Our services and website are not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will promptly delete that information. If you believe this has occurred, please contact our Privacy Team immediately.
14. Updates to This Privacy Policy
We may update this Data Protection & Privacy Policy periodically to reflect changes in our data processing, legal requirements, or technology. We will notify you of any significant changes by posting the updated Policy on our website with a new "Effective Date" at the top of the page. We may also send an email notification if appropriate.
We review and update this Policy at least annually, or more frequently if laws or our business operations change. It is your responsibility to review this Policy periodically to stay informed of modifications.
