Privacy Policy

Effective date: July 30, 2026 · Last updated: July 30, 2026

This policy describes how Networkz IT, LLC ("NIT," "we," "us," or "our") collects, uses, stores, shares, and protects personal data. It applies to NIT in its capacity as a data controller for employee data, client contact data, and website visitor data. It fulfills transparency obligations under the EU General Data Protection Regulation (GDPR) Articles 13 and 14 and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

This policy does not govern NIT's handling of Protected Health Information (PHI) under HIPAA, which is addressed through Business Associate Agreements, or data we process on behalf of clients in a processor or Business Associate capacity. That processing is governed by our client agreements.

1. Who We Are

Networkz IT, LLC is a managed IT services provider based in San Diego, California, United States, serving life sciences and regulated-industry clients.

Privacy contact:
Email: [email protected]
Phone: (858) 758-7700

For questions about this policy or to exercise your data rights, contact us using the information above.

2. Personal Data We Collect

NIT primarily collects personal data directly from individuals (GDPR Art. 13). In limited cases we may receive personal data indirectly, for example client-provided employee contact lists or publicly available business contact information (GDPR Art. 14). Where data is obtained indirectly, we will inform the data subject within one month of obtaining the data, or at the time of first communication, whichever is earlier.

Website Visitor Data

Data typeExamples
Technical dataIP address, browser type, operating system, device type
Usage dataPages visited, time on site, referring URL (collected in aggregate)
Form submission dataName, work email, company, phone (optional), and message content from our contact form

Client Contact Data

Data typeExamples
Identity dataFull name, job title, company name
Contact dataBusiness email, business phone, office address
Service dataSupport tickets, project records, communication logs
Billing dataBilling contact information, invoice records

Employee and Job Applicant Data

Data typeExamples
Identity dataFull name, date of birth, government-issued ID numbers
Contact dataHome address, personal email, phone number
Employment dataJob title, department, compensation, performance data
Financial dataBank account details (for payroll), tax information
IT usage dataCorporate email, device identifiers, access logs
Background check dataCriminal history, employment verification (where permitted by law)

3. Why We Process Your Data

PurposeData categoriesLegal basis (GDPR Art. 6)
Employment administration and payrollEmployee dataContract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Recruitment and hiringApplicant dataLegitimate interest (Art. 6(1)(f)); consent for background checks (Art. 6(1)(a))
IT security and access managementEmployee IT usage dataLegitimate interest (Art. 6(1)(f))
Service delivery and supportClient contact dataContract performance (Art. 6(1)(b))
Billing and invoicingClient billing dataContract performance (Art. 6(1)(b))
Client relationship managementClient contact dataLegitimate interest (Art. 6(1)(f))
Website operation and improvementVisitor technical dataLegitimate interest (Art. 6(1)(f))
Website analytics (aggregate, cookieless)Visitor usage dataLegitimate interest (Art. 6(1)(f))
Responding to inquiriesForm submission dataLegitimate interest (Art. 6(1)(f))
Legal complianceAll categoriesLegal obligation (Art. 6(1)(c))

Where legitimate interest is the legal basis, NIT has conducted a balancing test to ensure that our interests do not override the rights and freedoms of the data subject.

4. How Long We Keep Your Data

We retain personal data only as long as necessary for the purposes described in this policy or as required by law, in line with our internal records retention standard.

Data categoryRetention period
Employee recordsDuration of employment plus 7 years (tax/labor law)
Job applicant data2 years from application date (or per consent)
Client contact dataDuration of client relationship plus 3 years
Billing and financial data7 years (tax compliance)
Website analytics dataAggregate only; no individual-level records retained
Contact form submissions1 year from submission
Access and security logsMinimum 1 year

When the retention period expires, data is securely deleted or anonymized.

5. Your Rights

Individuals whose personal data NIT controls have the following rights, subject to applicable law:

RightDescriptionGDPRCCPA/CPRA
AccessObtain confirmation of processing and a copy of your personal dataArt. 15§ 1798.100
RectificationRequest correction of inaccurate personal dataArt. 16§ 1798.106
ErasureRequest deletion of personal data (subject to legal retention obligations)Art. 17§ 1798.105
Data portabilityReceive your data in a structured, machine-readable formatArt. 20N/A
RestrictionRequest limitation of processing in certain circumstancesArt. 18N/A
ObjectionObject to processing based on legitimate interestArt. 21N/A
Opt out of sale or sharingDirect NIT not to sell or share your personal informationN/A§ 1798.120
Non-discriminationNot receive discriminatory treatment for exercising rightsN/A§ 1798.125
Withdraw consentWhere processing is based on consent, withdraw it at any time without affecting prior processingArt. 7(3)N/A
Lodge a complaintLodge a complaint with your local data protection supervisory authorityArt. 77N/A

How to exercise your rights

To submit a request, email [email protected] with your full name, the email address associated with our records, and a description of your request. We will verify your identity before fulfilling any request and may ask for additional information to confirm it.

RegulationInitial responseExtension (if needed)
GDPRWithin one monthExtendable by two further months, with notice and reasons given within the first month
CCPA/CPRA45 calendar daysUp to 45 additional days with notification

For California requests, we will confirm receipt within 10 business days and respond within 45 calendar days, extendable by another 45 days with notice.

We do not charge a fee to handle your request. Under GDPR, we may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive. Under CCPA, we are not required to provide the same information to you more than twice in a 12-month period.

NIT does not use automated decision-making or profiling that produces legal or similarly significant effects.

6. Cookies and Tracking

We do not use tracking or advertising cookies, and we do not track you across other websites.

Strictly necessary technologies. Our contact form uses Cloudflare Turnstile to prevent spam and abuse. This is required for the form to function securely and does not require consent.

Analytics. We use Cloudflare Web Analytics, a privacy-first, cookieless analytics service. It measures aggregate traffic and performance without setting cookies, storing information on your device, using fingerprinting, or building individual visitor profiles. Because it sets no cookies and collects no personal identifiers, no cookie consent banner is required.

Marketing. We do not use marketing or advertising cookies.

You can manage or block cookies through your browser settings. We will update this section if our practices change.

7. Third Parties and Subprocessors

We share personal data with the following categories of third parties as necessary to operate our business. All third-party data sharing is governed by our vendor risk management process, and we require subprocessors to maintain appropriate security measures and, where applicable, to sign data processing agreements.

CategoryExamplesPurpose
Cloud platformMicrosoft 365 (Exchange, SharePoint, OneDrive, Teams)Email, file storage, collaboration
Identity providerMicrosoft Entra IDAuthentication, access control
Device managementMicrosoft Intune, NinjaOneEndpoint management, security
PSA / ticketingHaloPSAService delivery, ticket management
Workflow automationn8n CloudRouting contact-form submissions to our helpdesk (HaloPSA) and Microsoft Teams notifications
DocumentationHuduIT documentation
Security toolsHuntress, ThreatLocker, Microsoft DefenderEndpoint security, threat detection
Website hosting, security & analyticsCloudflare (Pages hosting, edge security, Turnstile, cookieless Web Analytics)Website operation and aggregate analytics
Web fontsGoogle FontsFont delivery (receives visitor IP address)
Accounting / payrollAccounting and payroll providersPayroll processing, tax filing

8. International Data Transfers

NIT is based in the United States. If personal data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission where required, data processing agreements with subprocessors that include appropriate transfer mechanisms, and any applicable adequacy decisions.

If you are located outside the United States and provide personal data to NIT, you acknowledge that your data will be processed in the United States, where data protection laws may differ from those in your jurisdiction.

9. California (CCPA/CPRA) Disclosures

The following disclosures are provided to California residents as required by the CCPA as amended by the CPRA.

Categories of personal information collected

CCPA categoryCollectedSource
IdentifiersYesDirectly from individuals, clients
Customer records (Cal. Civ. Code 1798.80(e))YesDirectly from individuals
Professional or employment informationYesDirectly from individuals
Internet or network activityYesAutomatically via website
Geolocation dataNoN/A
Sensory data (audio, visual)NoN/A
Sensitive personal informationLimitedEmployment context only

Sale or sharing of personal information

NIT does not sell personal information as defined by CCPA, and does not share personal information for cross-context behavioral advertising. Because we do not sell or share personal information for behavioral advertising, a "Do Not Sell or Share My Personal Information" mechanism is not required. If our practices change, this section will be updated and a prominent opt-out link will be provided.

Non-discrimination

We will not discriminate against any individual for exercising their CCPA/CPRA rights. We will not deny goods or services, charge different prices or rates, provide a different level or quality of service, or suggest that any of the above will occur.

10. Updates to This Policy

We may update this policy from time to time to reflect changes in our practices, legal requirements, or business operations. Material changes will be communicated to affected individuals (employees, active clients) at least 30 days before the effective date, and the updated policy will be posted here with a new effective date. Non-material changes (formatting, clarification) may be made without advance notice.

11. Contact

Networkz IT, LLC · San Diego, California, United States
Email: [email protected]
Phone: (858) 758-7700