PRIVACY POLICY
Releo Risk Advisory LLC
1. Introduction
Releo Risk Advisory LLC ("Releo," "Company," "we," "us," or "our") respects the privacy of individuals who visit our website, communicate with us, request information, schedule consultations, or engage with us in connection with our cybersecurity compliance advisory services. This Privacy Policy explains what personal information we collect, how and why we use it, when we disclose it, how long we retain it, the safeguards we use to protect it, and the choices and rights that may be available to you.
This Privacy Policy is intended to provide a clear and accurate description of our website and business privacy practices. It should be read together with any applicable engagement letter, statement of work, nondisclosure agreement, client services agreement, Cookie Policy, Terms & Conditions, or other written agreement between you or your organization and Releo. If a written client agreement contains privacy or confidentiality terms that conflict with this Privacy Policy, the written agreement will govern with respect to the information covered by that agreement, unless applicable law requires otherwise.
By accessing or using our website, submitting information to us, or otherwise interacting with us, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will obtain your consent before using non-essential cookies or processing personal information for the relevant purpose.
2. About Releo Risk Advisory LLC
Releo Risk Advisory LLC is a Texas-based cybersecurity compliance advisory firm. Our services may include SOC 2 audit readiness, ISO/IEC 27001 audit readiness, NIST Cybersecurity Framework gap assessments, cybersecurity risk assessments, vendor risk assessments, policy and documentation advisory, and virtual Chief Information Security Officer advisory services.
Releo provides advisory and readiness services. Releo is not an accredited certification body, does not issue ISO certifications, and does not perform independent SOC 2 attestations. Certification and attestation decisions are made by independent accredited certification bodies or licensed CPA firms, as applicable.
For purposes of this Privacy Policy, Releo generally acts as the business or controller for personal information collected through its public website and direct business communications. In some client engagements, Releo may process information on behalf of a client under the client's instructions. In those circumstances, the client may be the business or controller and Releo may act as a service provider or processor, subject to the applicable contract.
3. Scope and Applicability
This Privacy Policy applies to personal information collected through:
- Our public website and associated webpages;
- Website contact forms and consultation request forms;
- Scheduling tools (Microsoft Bookings or Calendly) used to arrange meetings;
- Email, telephone, video conference, and other business communications;
- Business development, proposals, onboarding, and client relationship management;
- Website analytics and session-behavior tools described in this Policy; and
- Other online services that link to or expressly incorporate this Privacy Policy.
This Privacy Policy does not automatically apply to:
- Information processed solely on behalf of a client under a separate written agreement;
- Employment or applicant information, unless a separate applicant notice is not provided and applicable law requires disclosure here;
- Information collected by third-party websites, platforms, certification bodies, CPA firms, or service providers that operate under their own privacy notices; or
- De-identified or aggregated information that cannot reasonably be linked to an identifiable individual, except where applicable law treats such information as personal information.
4. Definitions
- Personal Information or Personal Data: Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identifiable individual or household. The precise definition varies by law.
- Sensitive Personal Information: Personal information that applicable law gives heightened protection, such as precise geolocation, government identifiers, account credentials, financial account information, health information, biometric information, racial or ethnic origin, religious beliefs, sexual orientation, or information from private communications.
- Processing: Any operation performed on personal information, including collection, use, storage, organization, analysis, disclosure, transfer, deletion, or destruction.
- Controller or Business: An organization that determines the purposes and means of processing personal information.
- Processor or Service Provider: An organization that processes personal information on behalf of and under the instructions of a controller or business.
- Cookies: Small text files or similar technologies stored on or accessed from a device to enable website functionality, remember preferences, support security, or measure website usage.
- Services: The website, communications, and advisory services offered by Releo.
- You: The individual whose personal information is processed, including a website visitor, prospect, client contact, vendor contact, or other business contact.
5. Privacy Principles
Releo aims to handle personal information in accordance with the following principles, subject to applicable law and contractual requirements:
- Purpose limitation: collect and use personal information for specified, legitimate business purposes.
- Data minimization: collect only information reasonably relevant to the stated purpose.
- Accuracy: take reasonable steps to maintain accurate and current information.
- Retention limitation: retain information only as long as reasonably necessary.
- Security: apply administrative, technical, and organizational safeguards appropriate to the nature of the information and risk.
- Transparency: provide understandable information about our practices.
- Accountability: document and periodically review our privacy and security practices.
6. Categories of Personal Information We Collect
6.1 Information You Provide Directly
- Identifiers and contact information, such as name, business email address, telephone number, mailing address, and online identifiers;
- Professional information, such as employer, company name, job title, department, industry, and business role;
- Inquiry and consultation information, such as services of interest, compliance goals, project timing, company size, and messages submitted through forms;
- Communications, including emails, meeting notes, call records, support requests, and correspondence;
- Proposal and engagement information, including scope details, authorized contacts, contract information, invoicing contacts, and business requirements;
- Documents or evidence you voluntarily provide, including policies, questionnaires, screenshots, reports, or other materials related to an advisory engagement; and
- Any other information you choose to provide.
6.2 Information Collected Automatically
- Internet Protocol address and approximate geographic region;
- Browser type, browser version, operating system, device type, screen resolution, and language;
- Date and time of access, pages viewed, links clicked, referring webpage, exit page, and time spent on pages;
- Cookie identifiers, session identifiers, and similar technical identifiers;
- Diagnostic, security, error, and performance information; and
- Interaction data generated through Google Analytics 4 or Microsoft Clarity, as described below
6.3 Information From Third Parties
We may receive limited personal information from service providers, professional referrals, business partners, public business directories, social or professional networking platforms, scheduling platforms, or organizations whose representatives ask us to contact you. We use such information only for legitimate business purposes and subject to applicable law.
6.4 Information We Do Not Intentionally Collect Through the Public Website
Our public website is not designed to collect Social Security numbers, passport numbers, driver's license numbers, payment card data, bank credentials, medical records, biometric identifiers, passwords, private cryptographic keys, or other highly sensitive information. Do not submit such information through an ordinary website form or unencrypted email. If sensitive or confidential materials are needed for an engagement, we will establish an appropriate method for transmission where reasonably available.
7. Sources of Personal Information
- Directly from you;
- From your employer or organization;
- From referrals and business partners;
- From publicly available business sources;
- From website hosting, analytics, scheduling, email, security, and productivity providers; and
- From records generated during our business relationship.
8. Purposes for Which We Use Personal Information
We may use personal information for the following purposes:
- Responding to inquiries and providing requested information;
- Scheduling consultations and meetings;
- Evaluating whether our services fit your needs;
- Preparing proposals, engagement letters, statements of work, and related documents;
- Delivering cybersecurity compliance advisory services;
- Managing client, vendor, and business partner relationships;
- Maintaining project records and communicating about deliverables;
- Administering billing, accounting, taxes, insurance, and business records;
- Operating, maintaining, troubleshooting, and improving our website;
- Measuring website traffic, performance, and usability;
- Protecting the confidentiality, integrity, and availability of our systems and information;
- Detecting, preventing, and responding to fraud, abuse, security incidents, or unlawful activity;
- Complying with laws, legal process, professional obligations, and contractual requirements;
- Establishing, exercising, or defending legal claims;
- Conducting internal planning, quality assurance, risk management, and service improvement; and
- Carrying out other purposes disclosed at the time of collection or with your consent.
We do not use personal information obtained through the public website to make decisions that produce legal or similarly significant effects on individuals solely through automated processing.
9. Legal Bases for Processing
Where a law requires us to identify a legal basis for processing, we rely on one or more of the following, as appropriate:
- Consent, where you have given clear permission and may withdraw it as permitted by law;
- Contractual necessity, where processing is needed to take steps at your request, enter into an agreement, or perform an agreement;
- Legitimate interests, such as operating and securing our business, responding to business inquiries, improving services, preventing fraud, and maintaining professional relationships, provided those interests are not overridden by your rights;
- Legal obligation, where processing is necessary to comply with applicable law, regulation, court order, tax, accounting, or reporting requirement; and
- Protection of rights and vital interests, where reasonably necessary to protect individuals, systems, property, or legal rights.
The applicable legal basis depends on the context and jurisdiction. Contact us if you need information about the legal basis for a particular processing activity.
10. Cookies and Similar Technologies
Our website may use cookies, pixels, local storage, scripts, tags, and similar technologies. These technologies may be placed by us or by service providers acting on our behalf.
10.1 Essential Technologies
Essential technologies support core website operations, security, network management, form functionality, load balancing, fraud prevention, and user-requested services. Where permitted by law, they may operate without consent because the website cannot function properly without them.
10.2 Analytics Technologies
Analytics technologies help us understand website traffic, visitor interactions, technical performance, and areas for improvement. Where required, these technologies will be activated only after consent through a cookie banner or preference tool.
10.3 Functional Technologies
Functional technologies may remember preferences or improve convenience. Their use may depend on the website features implemented at the time.
10.4 Advertising Technologies
As of the effective date of this draft, Releo does not intend to use advertising cookies, remarketing pixels, or cross-context behavioral advertising technologies. If that changes, we will revise this Policy and implement any required notice, consent, and opt-out mechanisms before or when the technology is deployed.
10.5 Managing Cookies
You may be able to manage cookies through a website consent banner and through your browser settings. Blocking or deleting cookies may affect website functionality. Browser settings vary, so review the help materials for your browser. Choices made through one browser or device may not automatically apply to another browser or device.
11. Google Analytics 4
We plan to use Google Analytics 4 (GA4) to understand how visitors use our website and to improve website content, performance, and navigation. GA4 may collect or generate information such as page views, events, session duration, traffic source, approximate geography, browser characteristics, device characteristics, and cookie or device identifiers.
We will configure GA4 in a manner intended to reduce unnecessary collection and sharing, including limiting advertising features unless expressly needed, selecting appropriate retention settings, and avoiding intentional transmission of names, email addresses, passwords, or other directly identifying information in analytics event fields. Google may process analytics information in accordance with its own terms and privacy documentation.
Where required by applicable law, GA4 will not be activated until you consent to analytics cookies. You may also use browser settings or tools made available by Google to limit analytics collection, subject to their availability and terms.
12. Microsoft Clarity
We plan to use Microsoft Clarity to better understand website usability. Clarity may provide heatmaps, click information, scroll information, navigation paths, technical information, and session replays. Session replay tools are intended to show how a website is used so that we can identify broken links, confusing navigation, or other usability issues.
We will use available masking and privacy settings intended to prevent or reduce capture of text entered into sensitive fields. Nevertheless, no masking control is guaranteed to identify every type of sensitive content in every configuration. Visitors should not enter highly sensitive information into ordinary website forms. Microsoft processes information in accordance with its own terms and privacy practices.
Where required by law, Microsoft Clarity will be activated only after appropriate consent.
13. Contact Forms, Scheduling, and Email
13.1 Contact Forms
When you submit a contact form, we use the information to review and respond to your request, determine whether our services are appropriate, and maintain a record of the communication. Required fields will be identified where practical. Do not submit confidential security evidence, credentials, regulated data, or sensitive personal information through a general contact form.
13.2 Scheduling
We may use a scheduling feature provided by Hostinger or another scheduling provider. The scheduling provider may collect your name, email address, selected appointment time, time zone, and any message you submit. The provider's privacy notice and terms may also apply. Before publication, this section should be updated to identify the actual scheduling provider and link used by the website.
13.3 Email
Email is not always encrypted in transit and may pass through multiple service providers. Do not send passwords, private keys, regulated data, or highly sensitive documents through ordinary email unless an appropriate secure method has been agreed. We may retain business emails as part of our records and for legal, contractual, security, and customer service purposes.
14. Client and Prospect Information
During a prospective or active client relationship, we may collect information about the organization, authorized contacts, scope of work, applicable compliance frameworks, systems in scope, project timelines, evidence requests, control owners, and project communications. This may include business contact information and limited personal information contained in security documentation.
We ask clients to avoid providing personal information that is not relevant to the engagement. Where possible, clients should redact or minimize personal information in evidence submitted for review. The treatment of client confidential information should also be governed by the applicable nondisclosure agreement, engagement letter, client services agreement, or statement of work.
Releo does not claim ownership of client materials. Access to client materials will be limited to persons and service providers with a legitimate need, subject to applicable contractual and legal obligations.
15. Sensitive Personal Information and Confidential Materials
We do not intentionally request sensitive personal information through our public website. If a client engagement requires review of materials containing sensitive personal information or confidential security information, the parties should agree on appropriate scope, data minimization, access, transmission, storage, retention, and deletion requirements.
Unless expressly agreed in writing, clients should not provide Releo with production credentials, full payment-card data, unredacted government identifiers, protected health information, biometric templates, classified information, export-controlled technical data, or other specially regulated information. Releo may refuse, return, quarantine, or securely delete information that is outside the agreed scope or creates an unreasonable security or legal risk.
16. How We Disclose Personal Information
We may disclose personal information in the following circumstances:
- To hosting, analytics, scheduling, email, cloud, productivity, security, accounting, legal, insurance, and other service providers that support our operations;
- To professional advisers, including attorneys, accountants, auditors, insurers, and consultants, when reasonably necessary;
- To a client or your organization where you act as its representative and the disclosure relates to the business relationship;
- With your direction or consent;
- To comply with law, regulation, subpoena, court order, governmental request, or other legal process;
- To investigate, prevent, or address fraud, security incidents, violations of agreements, threats to safety, or unlawful activity;
- To establish, exercise, or defend legal claims; and
- In connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable safeguards.
We do not disclose personal information to third parties for their own unrelated marketing purposes unless we provide notice and obtain consent where required.
17. Service Providers and Third Parties
We select service providers based on factors such as functionality, security, reliability, privacy practices, contractual terms, and business necessity. Depending on our operations, providers may include Hostinger, Google, Microsoft, email and productivity providers, cloud storage providers, accounting providers, electronic signature providers, legal advisers, and security vendors.
Where appropriate, we seek contractual terms requiring service providers to use personal information only to provide contracted services, protect the information, and comply with applicable law. We cannot guarantee the independent practices of every third party, and third-party services remain subject to their own terms and privacy notices.
We may update this Privacy Policy from time to time to reflect changes to the third-party service providers we use.
18. No Sale of Personal Information
Releo does not sell personal information for monetary consideration. As of the effective date, Releo also does not knowingly share personal information for cross-context behavioral advertising. If our practices change, we will update this Policy and provide any opt-out rights required by law before or at the time the new practice begins.
19. Data Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, maintain business and tax records, comply with legal and contractual obligations, resolve disputes, enforce agreements, support security investigations, and protect legal rights.
Retention periods vary by category and context. Factors include the length of the relationship, whether an inquiry becomes a client engagement, legal limitation periods, tax and accounting requirements, professional obligations, client instructions, security needs, and the sensitivity of the information.
When information is no longer needed, we may delete it, anonymize it, securely destroy it, or retain it in a restricted backup until the backup is overwritten according to normal cycles. Deletion from active systems may not immediately remove information from disaster recovery or immutable backups, but access to retained backups will be limited and the information will not be restored except for legitimate continuity, security, or legal purposes.
21. Security Incident and Breach Response
If we become aware of a suspected security incident involving personal information under our control, we will take steps appropriate to the circumstances. These may include triage, containment, investigation, evidence preservation, remediation, assessment of legal and contractual obligations, and coordination with affected clients, service providers, insurers, legal counsel, regulators, or law enforcement.
Where applicable law or contract requires notification, we will provide notice to affected individuals, clients, or authorities within the required time and in the required manner. Notification obligations depend on the jurisdiction, the type of information involved, the likelihood of harm, and other circumstances. Nothing in this Policy creates a contractual promise to provide notice beyond what applicable law or a written agreement requires.
22. International Data Transfers
Releo is located in the United States. If you access the website from another country, your information may be transferred to and processed in the United States and in other countries where our providers operate. These countries may have privacy laws that differ from those in your jurisdiction.
Where required, we will use an appropriate transfer mechanism or contractual safeguard, such as standard contractual clauses or another legally recognized mechanism. The availability and necessity of a transfer mechanism depends on the processing activity, the parties, and applicable law.
23. Privacy Rights and Requests
Depending on your residence and the law that applies, you may have rights to:
- Confirm whether we process your personal information;
- Access or obtain a copy of personal information;
- Correct inaccurate personal information;
- Delete certain personal information;
- Receive certain information in a portable format;
- Restrict or object to certain processing;
- Withdraw consent for processing based on consent;
- Opt out of sale, targeted advertising, or certain profiling, where applicable;
- Limit certain uses of sensitive personal information, where applicable; and
- Appeal a decision regarding a privacy request, where applicable.
23.1 Submitting a Request
Submit a privacy request by emailing info@releorisk.com with the subject line "Privacy Request." Include your name, contact information, relationship to Releo, the right you wish to exercise, and enough detail for us to understand the request. Do not send identity documents unless we specifically request them through an appropriate method.
23.2 Verification
We may verify your identity and authority before fulfilling a request. Verification may include confirming control of an email address, requesting information that matches our records, or obtaining authorization from an agent. We will request only information reasonably necessary for verification.
23.3 Authorized Agents
Where applicable law permits an authorized agent to submit a request, we may require proof of authorization and may verify your identity directly, unless law provides otherwise.
23.4 Response and Exceptions
We will respond within the time required by applicable law. Rights are not absolute. We may deny or limit a request when an exception applies, such as when information is needed to complete a transaction, comply with law, protect security, exercise legal rights, maintain privileged information, or protect the rights of others. We will not discriminate against you for exercising an applicable privacy right.
24. Texas Privacy Notice
The Texas Data Privacy and Security Act may provide Texas consumers with rights regarding personal data, subject to applicability thresholds, definitions, and exemptions. Where the law applies to Releo's processing, Texas consumers may have rights to confirm processing, access personal data, correct inaccuracies, delete personal data, obtain portable data, and opt out of certain sale, targeted advertising, or profiling activities.
Releo does not sell personal data and does not currently use personal data for targeted advertising or qualifying profiling. A Texas consumer whose request is denied may have a right to appeal. To appeal, reply to our decision or email info@releorisk.com with "Texas Privacy Appeal" in the subject line and explain why you believe the decision should be reconsidered.
Business-to-business contact information, employee information, information processed solely on behalf of another business, and other categories may be excluded or exempt depending on the circumstances. This section does not state that every provision of the Texas law applies to Releo in every circumstance.
25. California Privacy Notice
California privacy laws may apply only if Releo meets applicable statutory thresholds and no exemption applies. This section is provided for transparency and future readiness and should not be interpreted as an admission that Releo is currently a covered "business" under the California Consumer Privacy Act, as amended.
25.1 Categories
Depending on your interaction, we may collect identifiers, professional or employment-related information, internet or electronic network activity, approximate geolocation, commercial or engagement information, and inferences about website usage. We collect these categories from you, your organization, referrals, public business sources, and service providers. We use and disclose them for the business purposes described in this Policy.
25.2 Sale and Sharing
Releo does not sell personal information for monetary consideration and does not knowingly share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of consumers under 16.
25.3 California Rights
Where applicable, California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment. Requests may be submitted using the procedure in Section 23.
25.4 Sensitive Personal Information
Releo does not use or disclose sensitive personal information collected through the public website for purposes requiring a right to limit under California law. If that changes, we will provide the required notice and mechanism.
26. EEA, United Kingdom, and Switzerland Notice
If you are in the European Economic Area, United Kingdom, or Switzerland and applicable data protection law applies, Releo may act as a controller for website and direct business contact information. The purposes and legal bases are described in Sections 8 and 9.
Subject to applicable law, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also have the right to lodge a complaint with a competent supervisory authority. We encourage you to contact us first so we can attempt to address your concern.
Releo is based in the United States. International transfers are addressed in Section 22. If Releo begins intentionally offering services to individuals in the EEA or UK at a scale that triggers additional obligations, this notice should be reviewed for representative, data protection officer, and transfer requirements.
27. Global Privacy Control and Do Not Track
Some browsers or extensions transmit Global Privacy Control (GPC) or Do Not Track signals. Where applicable law requires recognition of a valid opt-out preference signal and our website engages in the covered activity, we will process the signal as required. Because Releo does not currently sell personal information or use it for cross-context behavioral advertising, a GPC signal may not change our current processing.
There is no universally accepted standard for general Do Not Track signals. Our website may not respond differently to a Do Not Track signal except where required by law.
28. Children's Privacy
Our website and services are directed to businesses and adults and are not intended for children under 13. We do not knowingly collect personal information from children under 13 through the website. If you believe a child has provided personal information to us, contact us. We will take reasonable steps to investigate and delete the information where required.
We do not knowingly sell or share the personal information of minors for targeted advertising.
29. Artificial Intelligence and Automated Technologies
Releo may use productivity tools that include artificial intelligence-assisted features for limited internal purposes, such as drafting support, summarization, research organization, or administrative efficiency. Any such use should be subject to confidentiality, access, security, and human-review controls appropriate to the information involved.
Releo does not use artificial intelligence or automated decision-making on website visitor information to make decisions that produce legal or similarly significant effects. Client confidential information should not be submitted to public or consumer AI services unless specifically authorized and protected by appropriate contractual, technical, and organizational controls.
If Releo materially changes its use of AI in a way that affects personal information, this Policy will be updated and additional notice or consent will be provided where required.
30. Third-Party Links and Embedded Content
Our website may link to or embed content from third-party websites, including standards organizations, government agencies, professional associations, social media platforms, scheduling services, or educational resources. Third parties may collect information when you interact with their content. Releo does not control their privacy or security practices. Review their notices before providing information.
31. Business Transfers
If Releo is involved in a merger, acquisition, reorganization, financing, due diligence process, sale of assets, bankruptcy, or similar transaction, personal information may be reviewed or transferred as part of the transaction. We will take reasonable steps to require the recipient to protect the information and use it consistently with applicable law and this Policy, unless you receive notice of a different policy.
32. Required Disclosures and Legal Process
We may preserve, use, or disclose information when we reasonably believe it is necessary to comply with applicable law, legal process, or a valid governmental request; enforce agreements; protect rights, property, systems, or safety; investigate suspected wrongdoing; or respond to an emergency. Where legally permitted and appropriate, we may seek to narrow requests or notify affected parties, but we are not obligated to do so when prohibited, impractical, or inconsistent with security or legal obligations.
33. Changes to This Privacy Policy
We may revise this Privacy Policy to reflect changes in our business, technology, service providers, website features, legal requirements, or privacy practices. The "Last Updated" date will be changed when revisions are published. If changes are material, we may provide additional notice through the website, email, or another appropriate method. Where consent is required for a new processing activity, we will request consent rather than relying only on an updated Policy.
You should review this Policy periodically. Historical versions may be retained in our records.
34. Contact Information
Questions, complaints, or privacy requests may be submitted to:
Releo Risk Advisory LLC
Texas, United States
Email: info@releorisk.com
Website: www.releorisk.com
Subject line for privacy requests: Privacy Request
35. Governing Law and General Provisions
This Privacy Policy is intended to describe privacy practices and does not create contractual rights beyond those provided by applicable law or an executed agreement. To the extent a governing-law provision is enforceable for a privacy notice, this Policy is governed by the laws of the State of Texas, without regard to conflict-of-law principles, together with applicable federal law.
If any provision of this Policy is found invalid or unenforceable, the remaining provisions will continue in effect. A failure to enforce a provision is not a waiver. Headings are for convenience and do not limit interpretation.
This Policy does not replace any client-specific privacy, security, confidentiality, data processing, or breach notification terms contained in a signed agreement.