1. Introduction and Scope
HJVS Consulting LLC is an independent computer systems design and digital advisory practice. In the ordinary course of advising clients on strategy roadmaps, systems integration, cloud readiness, data governance, vendor selection and managed transformation, we receive personal information. This policy sets out the principles we follow whenever that happens.
The policy applies to information collected through our website at hjvsconsulting.mom, through email and telephone conversations, through written advisory reports and assessments, and through any other channel that leads a person to our practice. It applies to prospective clients, current clients, former clients, supplier contacts, website visitors and any other individual who interacts with us.
We have written this policy in plain language on purpose. A privacy notice should be a document a reader can finish, and it should answer the practical questions people actually ask: what is held, why it is held, who can see it and how it can be removed.
2. Who Controls Your Information
The data controller responsible for personal information described in this policy is HJVS Consulting LLC. The registered address is 920 W 1100 N, Pleasant Grove - 84062-8099, United States (US). Questions about this policy, or about any specific record we may hold, should be directed to advisory@hjvsconsulting.mom or to the telephone number +16813034685.
Where HJVS Consulting LLC advises a client on systems that hold personal information belonging to that client, we act as an advisor and sometimes as a processor on the client behalf. In those situations the client remains the controller of the underlying data and our handling follows the written terms of the engagement, together with the instructions we are given. This policy continues to govern any personal information we hold about the client contacts themselves.
3. Information We Collect
We collect only the information required to advise, communicate and operate a professional practice. The categories are deliberately narrow.
- Identity information such as name, professional title, employer and the role a person holds in a programme.
- Contact information such as business email address, business telephone number and postal address.
- Enquiry information such as the subject of a request, the systems involved and the outcomes a client is seeking.
- Engagement information produced during advisory work, including meeting notes, decision records, requirements and assessment findings that may name individuals.
- Billing information such as purchase order references, invoicing addresses and payment correspondence, held only where an engagement has been agreed.
- Technical information generated when our website is visited, described separately in this policy.
We do not seek sensitive categories of personal information, and we ask that clients and website visitors do not send such information to us unless it is genuinely necessary for a piece of advisory work. Where a special category of information becomes relevant to a systems programme, we will discuss the appropriate handling before any record is created.
4. How We Obtain Information
Most information reaches us directly. A person sends an email, completes an enquiry through the website contact form, telephones the office or provides details during an advisory session. In each case the individual chooses what to share and can ask us to reduce the record at any point.
Some information arrives indirectly. A client may introduce a colleague to an engagement, or a supplier may provide a list of named contacts who will attend design sessions. Public professional sources such as company websites and business directories may be consulted when preparing for a first conversation. Where information is obtained indirectly, we limit our use of it to the purpose for which it was provided and we do not build unrelated profiles from it.
5. Why We Use Information
Personal information is used for a small number of clearly defined purposes.
- To respond to enquiries and arrange advisory conversations.
- To deliver, manage and document advisory engagements.
- To maintain accurate business records and meeting notes.
- To issue invoices and manage payment for services rendered.
- To meet legal, accounting and professional record keeping obligations.
- To protect the practice against fraud, misuse and security incidents.
- To send relevant practice updates to people who have asked to receive them.
We do not sell personal information. We do not rent contact lists. We do not use information gathered during an advisory engagement to market unrelated services to the individuals named in it. Any new purpose that is materially different from the list above will be explained before the information is used for it.
6. Legal Bases for Processing
Where data protection law requires a legal basis for processing, HJVS Consulting LLC relies on one or more of the following.
- Consent, where an individual has freely given clear permission, such as when subscribing to practice updates.
- Performance of a contract, where processing is necessary to deliver advisory services that have been agreed.
- Legitimate interests, where processing supports the operation of a professional practice in a way that is expected and does not override individual rights.
- Legal obligation, where records must be kept or disclosures must be made to comply with applicable law.
Where consent is the basis, it may be withdrawn at any time by writing to advisory@hjvsconsulting.mom. Withdrawal does not affect processing carried out before the request, and it does not remove obligations to retain records where the law requires retention.
7. Information in Advisory Engagements
Advisory work can involve access to system inventories, architecture diagrams, contracts, organisational charts and operational statistics. These materials frequently name individuals and describe their responsibilities. We treat such material as confidential to the client and use it only to deliver the engagement that produced it.
Engagement records are stored in the practice document system, restricted to the advisors assigned to the work. Where external specialists are brought into an engagement, access is granted only to the material that specialist needs, and the specialist is bound by confidentiality obligations at least as strict as our own. No client material is reused for another client, and no client material is used to build shared benchmarks unless the client gives written permission and the material is fully anonymised first.
8. Website Data and Server Records
Our website is a static informational site. It does not host a database of visitor records, it does not accept payments, and it does not create user accounts. The contact form prepares a message in the visitor own email application rather than transmitting content to a server controlled by us, so the information a visitor types remains on the visitor device until that person chooses to send it.
Standard server records may still be generated by the hosting provider for security and diagnostic purposes. These records can include an internet protocol address, a request time, a browser description and the page requested. Such records are used to keep the site available and secure, are retained only as long as the hosting provider requires, and are not combined with any other information to identify a visitor.
10. Disclosure to Third Parties
HJVS Consulting LLC does not trade in personal information. Disclosure occurs only in the limited circumstances set out below.
- Service providers who support the practice, such as email hosting, document storage and accounting services, each bound by contract to protect what they handle.
- Professional advisers such as accountants and legal counsel, where a specific matter requires their input.
- Public authorities, where disclosure is required by law or by a valid legal process.
- Parties to a business transaction, where the practice is transferred and records must move with it, subject to the same protections described here.
- Any other recipient, only with the clear permission of the individual concerned.
Every supplier that handles personal information on our behalf is assessed before engagement and reviewed periodically. Where a supplier cannot demonstrate adequate safeguards, we do not use that supplier regardless of any commercial advantage.
11. International Transfers
Our practice is based in the United States, and information is generally stored there. Some service providers operate infrastructure in other countries, which means information may be transferred or accessed outside the jurisdiction in which it was collected. Where such a transfer occurs, we take reasonable steps to ensure that the receiving party is subject to contractual protections that are consistent with this policy and with applicable law.
Clients with specific residency requirements should raise them at the start of an engagement. Where an arrangement cannot be made to satisfy those requirements, we will say so before work begins rather than after a transfer has occurred.
12. Retention Periods
Information is kept only as long as it is needed for the purpose it was collected, and thereafter only where a legal or professional duty requires it. As a general rule, enquiry correspondence is retained for two years, engagement records for seven years to satisfy accounting and professional standards, and billing records for the period required by applicable tax law.
When a retention period ends, records are deleted or destroyed in a controlled manner. Where information has been incorporated into a statistical summary that no longer identifies anyone, the summary may be kept beyond the period because it can no longer be linked to an individual. Requests for earlier deletion are considered in line with the section on privacy rights below.
13. Security Measures
We protect personal information with a combination of organisational and technical controls. Access is restricted to advisors who need the information for a specific engagement. Accounts are protected by strong authentication, devices are encrypted, and documents are stored in repositories that support access logging and version history.
Staff and contractors receive guidance on confidentiality and on the handling of sensitive materials, and that guidance is refreshed periodically. Despite these measures, no system can be guaranteed to be entirely secure. If a security incident affecting personal information occurs, we will investigate promptly, take steps to contain the impact, and notify affected individuals and relevant authorities where the law requires it. Incidents can be reported at any time on +16813034685.
14. Your Privacy Rights
Depending on where an individual lives, privacy law may grant specific rights over personal information. HJVS Consulting LLC honours the following rights for everyone who asks, regardless of jurisdiction, because they reflect fair practice.
- The right to be informed about how personal information is used.
- The right to request a copy of the information we hold.
- The right to request correction of information that is inaccurate or incomplete.
- The right to request deletion where no legal duty requires retention.
- The right to object to or restrict certain processing.
- The right to withdraw consent where consent was the basis for processing.
- The right to receive information in a portable format where technically feasible.
- The right not to be subject to decisions based solely on automated processing.
To exercise any right, write to advisory@hjvsconsulting.mom with enough detail for us to locate the record. We will acknowledge the request promptly and will normally respond within thirty days. We may ask for verification of identity to prevent the disclosure of information to the wrong person. There is no charge for a reasonable request.
15. Privacy for Children
Our services are provided to organisations and to professionals acting in a business capacity. The website and the practice are not directed at children, and we do not knowingly collect personal information from anyone under the age of sixteen. If we become aware that such information has been received, we will delete it promptly and confirm the deletion to the person who raised the matter.
A parent or guardian who believes that a child has provided information to HJVS Consulting LLC should contact advisory@hjvsconsulting.mom or call +16813034685 so that the record can be reviewed and removed without delay.
16. Marketing and Communications
We send practice updates rarely, and only to people who have asked for them or who have an existing professional relationship with the practice. Every update includes a straightforward way to stop receiving further messages, and a request to stop is honoured immediately without any need to give a reason.
We do not purchase contact lists, and we do not add individuals to a mailing list because their details appeared in a document produced during an engagement. Transactional messages connected to an active engagement, such as scheduling notes and invoices, are not marketing and continue while the engagement is live.
17. Automated Decision Making
HJVS Consulting LLC does not make decisions with legal or similarly significant effects about individuals through automated processing alone. Advisory judgements are formed by people, and any tooling used during an assessment supports human analysis rather than replacing it. Where a client asks us to review an automated decision process as part of an engagement, we report on that process and recommend safeguards, but we do not operate it.
If this position ever changes for a specific service, this policy will be updated first and the change will be described in plain language so that affected individuals understand what is happening and what rights remain available to them.
18. Changes to This Policy
This policy is reviewed at least once each year and whenever a material change occurs in the way we handle information. When a change is made, the effective date at the top of the page is updated. Where a change significantly affects how personal information is used, we will provide a clearer notice, such as a message to clients with active engagements or a prominent statement on the website.
Continued use of the website or continued engagement with the practice after an update indicates acceptance of the revised policy. Anyone who does not accept a revision may contact us to discuss the alternatives, which may include restricting the handling of their information or ending an engagement where that is practicable.
19. Complaints and Supervision
If an individual believes that their information has been mishandled, we want to hear about it directly so that it can be investigated and, where necessary, corrected. A complaint should be sent to advisory@hjvsconsulting.mom or raised by telephone on +16813034685. We will acknowledge the complaint, explain the steps being taken, and provide a written response once the review is complete.
Where local law provides a right to complain to a supervisory authority, that right is unaffected by contacting us first. We do encourage a direct approach, because most concerns can be resolved quickly once the facts are clear, and because it helps us improve the way the practice handles information for everyone.
20. How to Contact Us
Questions about this policy, requests concerning personal information and reports of a possible privacy issue should be directed to the practice using the details below. Please include enough context for us to identify the relevant record, and state clearly what outcome you are seeking.
HJVS Consulting LLC
920 W 1100 N
Pleasant Grove - 84062-8099
United States (US)
Email: advisory@hjvsconsulting.mom
Telephone: +16813034685
This policy is published by HJVS Consulting LLC and applies from the effective date shown at the top of this page. It forms part of the wider commitment the practice makes to act fairly, transparently and with care whenever personal information is entrusted to it.