Privacy Policy
This Privacy Policy explains how TOOJMAC LLC collects, uses, stores, shares and protects personal information. The policy was prepared by the developer Too J Mac on behalf of TOOJMAC LLC and describes the practices that apply to the website at www.toojmac.lat and to the professional services delivered by the firm. It is written to be read in full, and it applies to every visitor, client, supplier and applicant who interacts with the company.
TOOJMAC LLC is a computer integrated systems design and technology consulting practice. The company operates from 11901 S Elm Ridge Rd, Sandy - 84094-5666, United States (US). Throughout this policy the terms the Company, we, us and our refer to TOOJMAC LLC. The terms you and your refer to any individual whose personal information the Company handles. The policy describes the categories of information collected, the purposes for which it is used, the legal bases that support processing, the parties with whom information may be shared, the retention periods applied, the security measures maintained and the rights available to individuals.
1. Scope of This Policy
This policy applies to personal information that TOOJMAC LLC collects through its website, through email and telephone communications, through proposals and contracts, and through the delivery of its services. It also applies to information collected in the course of recruiting, supplier onboarding and general business administration. The policy does not apply to information that is processed by a client on the client own systems, because in those cases the client remains responsible for the data and the Company acts only under the client instructions.
The policy covers all channels through which the Company interacts with individuals, including the public website, the contact form, the published email address, the published telephone number, written correspondence and any future service portal operated by the Company. Where a specific service requires additional privacy terms, those terms are presented separately and this policy continues to apply to the extent it is not superseded.
The Company does not sell personal information. The Company does not rent personal information. The Company does not trade personal information for advertising revenue. Any statement to the contrary found outside this document does not reflect the practices of the Company.
2. Who Controls Your Information
TOOJMAC LLC is the controller of the personal information described in this policy. The registered and operating address is 11901 S Elm Ridge Rd, Sandy - 84094-5666, United States (US). The company can be reached by email at concierge@toojmac.lat and by telephone at +17866657335.
Where the Company delivers services to a business client and processes personal information belonging to that client customers or employees, the client is the controller and the Company is a processor acting on documented instructions. In that situation the Company handles the information only as the contract and the client instructions require, applies the confidentiality obligations described in this policy and returns or deletes the information at the end of the engagement.
Questions about this policy, about the role of the Company in a particular engagement or about the exercise of individual rights should be directed to the contact details above. The Company maintains an internal privacy contact who is responsible for monitoring compliance with this policy and for coordinating responses to individual requests.
3. Information We Collect
The Company collects information that individuals provide directly, information generated automatically when the website is used and information received from clients and suppliers in the course of business. The categories are described below.
Identity and contact information includes name, job title, employer, email address, postal address and telephone number. This information is collected when an individual submits the contact form, sends an email, calls the office or is named as a contact in a contract or proposal.
Correspondence information includes the content of messages, the date and time of communication, the subject matter and any attachments. The Company retains this material so that it can respond accurately and maintain a record of the services requested.
Commercial information includes the services requested, the scope of an engagement, billing details, purchase order references and payment status. Billing information is limited to what is required to raise and settle an invoice, and full payment card numbers are not stored by the Company.
Technical information includes internet protocol address, browser type and version, operating system, device type, referring pages, pages viewed, the date and time of each request and the general geographic region indicated by the network address. This information is generated by the web server and by any analytics tooling that the Company elects to use.
Recruitment information includes a resume, employment history, qualifications, references and the notes taken during an interview process, where an individual applies for a role with the Company.
The Company does not seek to collect special category information such as health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership, and asks that such information not be submitted through the website or by email.
4. Sources of Information
The Company obtains personal information from several sources. The most common source is the individual, who provides information through the contact form, by email, by telephone or in the course of a professional engagement. A second source is the client organization that engages the Company, which may provide contact details for employees, contractors and authorized representatives who need to participate in a project.
A third source is automated collection by the web server and any analytics service that records visits to the public website. A fourth source is publicly available material such as a company website, a professional directory or a public register, which the Company may consult when preparing a proposal or verifying a business relationship. A fifth source is suppliers and partners who provide services to the Company and who share the contact details of their own representatives.
Where information is received from a source other than the individual, the Company takes reasonable steps to ensure that the information is accurate and that the individual is made aware of this policy when they first interact with the Company or within a reasonable period thereafter.
5. How We Use Information
The Company uses personal information to respond to enquiries and to provide the services that clients request. This includes preparing proposals, agreeing scope, delivering engineering work, managing projects, raising invoices and providing support during and after an engagement.
The Company uses information to operate and improve the website, to understand which pages are useful and to maintain the security and availability of the site. The Company uses information to communicate about services, changes to this policy and matters relating to an existing engagement.
The Company uses information to meet legal, tax, accounting and regulatory obligations, to maintain business records, to resolve disputes and to enforce agreements. The Company uses information to protect the rights, property and safety of the Company, its clients and the public, and to detect and prevent fraud, abuse and unauthorised access.
The Company uses information for recruitment when an individual applies for a role, for supplier management when a business relationship is established and for general administration of the practice. The Company does not use personal information for automated decision making that produces legal effects, and it does not build advertising profiles of website visitors.
6. Legal Bases for Processing
Where the General Data Protection Regulation or a comparable framework applies, the Company relies on one or more legal bases for each processing activity. The bases are described here so that individuals understand why the processing is permitted.
Contract performance is the basis for processing that is necessary to enter into or perform an agreement with a client, a supplier or an employee. This covers proposal preparation, project delivery, invoicing and support.
Legitimate interests is the basis for processing that supports the ordinary operation of the business, including responding to enquiries, maintaining the security of systems, improving services, preventing fraud and managing business relationships, in each case balanced against the rights and expectations of the individual.
Legal obligation is the basis for processing that is necessary to comply with tax, accounting, employment and other statutory requirements. Consent is the basis where an individual has given clear permission, such as subscribing to a newsletter, and consent may be withdrawn at any time by contacting the Company.
Vital interests and public interest are relied upon only in the rare circumstances where they apply, such as protecting someone from serious harm or cooperating with a lawful public authority.
8. Website Analytics
The Company may use a privacy conscious analytics service to measure traffic to the website. The information collected in that context is aggregated and is used to understand which pages are visited, how visitors arrive and where the site can be improved. The Company configures analytics to minimise the collection of personal information and to avoid the recording of full network addresses where the tooling allows.
Analytics reports are reviewed internally by the Company and are not sold or shared for advertising purposes. Where an analytics provider processes information on behalf of the Company, the relationship is governed by a written agreement that limits the use of the information to the service provided.
Individuals who prefer not to be measured may use the opt out controls offered by the analytics provider, adjust browser privacy settings or enable a recognised tracking protection feature. The content of the website does not depend on analytics and remains available when measurement is disabled.
10. Service Providers and Subprocessors
The Company engages a limited number of service providers to operate its business. Each provider is assessed before engagement and is required to maintain appropriate technical and organisational measures, to process information only on documented instructions and to assist the Company in meeting its own obligations.
Providers support functions such as website hosting, business email, file storage and backup, accounting and invoicing, and communication tools. Where a provider engages a subprocessor, the provider remains responsible to the Company for the performance of that subprocessor, and the Company seeks to be informed of material changes to the subprocessor chain.
The Company maintains a register of its processors and reviews the register at least annually. A provider that cannot meet the required standard is replaced. Individuals may contact the Company to request further information about the categories of providers used for a particular service.
11. International Data Transfers
The Company is based in the United States and primarily processes information within the United States. Where information is transferred to a provider or a group entity located in another country, the Company takes steps to ensure that the transfer is protected by appropriate safeguards.
Those safeguards may include standard contractual clauses approved by a competent authority, an adequacy decision covering the destination country, or another lawful transfer mechanism. The Company assesses the legal environment of a destination before relying on a mechanism and applies supplementary measures where they are needed.
Individuals who wish to know more about the safeguards applied to a specific transfer may contact the Company using the details in this policy. The Company will provide a summary of the relevant mechanism and, where appropriate, a copy of the contractual terms that protect the information.
12. Data Retention
The Company retains personal information only for as long as it is needed for the purpose for which it was collected, for the period required by law or for the period necessary to establish, exercise or defend legal claims. Retention periods differ according to the category of information and the context in which it was collected.
Enquiry and correspondence information is retained for a reasonable period so that the Company can follow up on a request and maintain continuity if the individual returns. Contract and billing information is retained for the period required by tax and accounting rules, which is typically several years after the end of the financial year in which the engagement closed. Recruitment information is retained for the duration of the process and for a limited period afterwards, unless the individual asks the Company to keep it for longer.
Technical and analytics information is retained for a short period in identifiable form and is then aggregated or deleted. When a retention period ends, the Company deletes the information securely or irreversibly anonymises it so that it can no longer be associated with an individual. Where information must be kept beyond the normal period for legal reasons, it is isolated and access is restricted.
13. Security of Information
The Company maintains technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. The measures reflect the nature of the information, the risks of processing and the state of the art.
Measures include access control based on role and least privilege, encryption of data in transit, protection of credentials, regular patching of systems, monitored backups with periodic restore testing, network protections and logging of administrative activity. Staff and contractors are bound by confidentiality obligations and receive guidance on the secure handling of information.
Because the Company is a systems engineering practice, it applies the same disciplines to its own estate that it applies to client estates, including documented change control, staged deployment and periodic security review. No method of transmission or storage is completely secure, and the Company cannot guarantee absolute security, but it works continuously to reduce risk and to respond promptly when an issue is identified.
14. Your Privacy Rights
Depending on the law that applies, individuals may have the right to access the personal information the Company holds about them, to request a copy, to ask for correction of inaccurate information and to request deletion where there is no continuing lawful reason for retention.
Individuals may have the right to request restriction of processing, to object to processing based on legitimate interests, to withdraw consent where consent is the basis, and to request portability of information provided by the individual in a structured and commonly used format. Individuals may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Where the California Consumer Privacy Act or a comparable state law applies, individuals may have the right to know the categories and specific pieces of personal information collected, the sources, the purposes and the categories of third parties with whom information is shared, as well as the right to request deletion and the right to non discrimination for exercising privacy rights. The Company does not sell personal information and does not share it for cross context behavioural advertising.
Rights are not absolute. A request may be refused in whole or in part where the law permits, for example where the information is subject to a legal privilege, where it belongs to another person, where it must be retained to comply with an obligation or where disclosure would harm an ongoing investigation. Where a request is refused, the Company explains the reason.
15. How to Exercise Your Rights
An individual may exercise a privacy right by writing to the Company at concierge@toojmac.lat or by post to TOOJMAC LLC, 11901 S Elm Ridge Rd, Sandy - 84094-5666, United States (US). A request should describe the right being exercised and provide enough information for the Company to verify the identity of the requester and to locate the relevant information.
The Company responds to requests within the period required by applicable law, which is generally thirty days for many frameworks and forty five days for certain state laws, subject to a permitted extension where a request is complex. If more time is needed, the Company explains why and provides a new date.
There is no charge for a reasonable request. Where a request is manifestly unfounded or excessive, the Company may charge a reasonable fee or refuse to act, and will explain the reason. An individual who is not satisfied with the response may contact the Company again so that the matter can be reviewed, and may also complain to the supervisory authority or the attorney general of the relevant jurisdiction.
16. Privacy for Children
The services of the Company are provided to businesses and professionals. The website is not directed at children, and the Company does not knowingly collect personal information from anyone under the age of sixteen. Individuals are asked not to submit information about a child through the website or by email.
If the Company becomes aware that it has collected personal information from a child without appropriate authorization, it will delete that information promptly. A parent or guardian who believes that a child has provided information to the Company should contact concierge@toojmac.lat so that the matter can be investigated and the information removed where appropriate.
Where a client engagement involves systems that process information about minors, the Company acts under the instructions of the client, and the client is responsible for obtaining any consent required by law and for ensuring that the processing complies with the rules that protect children.
17. Marketing Communications
The Company sends service communications to clients and business contacts where there is an existing relationship or where the recipient has asked to receive them. Service communications may include information about new services, changes to the practice and periodic reviews relevant to an active engagement.
Every marketing communication includes a way to opt out, and an individual may ask the Company at any time to stop sending marketing material. An opt out request is honoured promptly. The Company may continue to send communications that are necessary for the performance of a contract or that are required by law, because those are not marketing.
The Company does not purchase marketing lists and does not share contact details with third parties for their own marketing purposes. Where a communication tool processes contact information on behalf of the Company, the processing is limited to the delivery and measurement of the Company own communications.
18. Client Data and Confidentiality
When the Company delivers services, it may encounter information belonging to a client, including information about the client customers, employees, suppliers and systems. This information is treated as confidential and is used only to deliver the agreed services. The Company does not use client information for its own purposes and does not disclose it except as the contract requires or as the law demands.
Access to client information is limited to the engineers who need it to perform the work. Where the Company must reproduce client data for testing or migration, the reproduction is minimised, protected and removed once the work is complete. Data is returned or deleted at the end of an engagement in line with the contract and with the retention rules described in this policy.
The Company maintains separate security controls for production and test environments, records access to sensitive systems and reviews privileged accounts periodically. Where a client requires additional safeguards, those requirements are agreed in writing and reflected in the engagement documentation.
19. Breach Notification
The Company maintains a documented process for detecting, investigating and responding to a personal data breach. The process names the people responsible, sets out the steps to contain an incident, preserve evidence, assess the risk to individuals and restore normal operations.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the Company notifies the relevant supervisory authority within the period required by law, which is generally seventy two hours for frameworks that follow the General Data Protection Regulation. Where the breach is likely to result in a high risk, the Company notifies the affected individuals without undue delay and provides clear information about the nature of the incident and the steps being taken.
Where the Company acts as a processor, it notifies the responsible client without undue delay so that the client can meet its own notification obligations. After an incident, the Company reviews what happened, updates its controls and records the lessons learned so that the same failure is less likely to recur.
20. Third Party Websites
The website may contain links to websites operated by other organizations. Those websites are not controlled by the Company and are not covered by this policy. The Company is not responsible for the privacy practices, the content or the security of a third party website.
An individual who follows a link to another website should read the privacy notice of that website before providing personal information. A link from the Company website does not imply endorsement of the practices of the destination, and the Company has no ability to alter the way a third party handles information.
Where the Company operates a service on a platform provided by a third party, the relevant privacy terms of that platform may also apply. In that case the Company remains responsible for the information it collects through the service and handles it in line with this policy.
21. Changes to This Policy
The Company may update this policy to reflect changes in its practices, in the services it offers or in the law that applies to it. When the policy is updated, the revised version is published on the website with a new effective date, and the date at the top of the page is amended so that readers can see when the document last changed.
Where a change is material, the Company takes reasonable steps to bring it to the attention of individuals who have an ongoing relationship with the practice, either by email, by a notice on the website or through a communication about the affected service. Continued use of the website or continued engagement of the services after a change takes effect indicates acceptance of the revised policy.
Previous versions of the policy are retained internally so that the Company can demonstrate the practices that applied at a given time. An individual who wishes to see an earlier version may contact the Company and, where appropriate, the Company will provide it.
22. Contacting the Company
Questions, comments and requests relating to this Privacy Policy are welcome and should be directed to TOOJMAC LLC using the details below. The Company aims to answer every privacy enquiry promptly and to resolve concerns directly wherever possible.
- Company: TOOJMAC LLC
- Address: 11901 S Elm Ridge Rd, Sandy - 84094-5666, United States (US)
- Email: concierge@toojmac.lat
- Phone: +17866657335
- Website: https://www.toojmac.lat
If an individual is not satisfied with the response of the Company, they may contact the supervisory authority or the attorney general of the relevant jurisdiction. The Company will cooperate with the authority and provide the information needed to resolve the matter.