Privacy Policy
Version 1.0. Effective date: September 23, 2026. Replaces the earlier privacy notice at this address.
This Privacy Policy explains what personal information IT of United States, LLC ("IT of US," "we," "us," "our") collects, how we use, share, and protect it, and the choices you have. It is written in plain language. Where our agreements refer to our "privacy notice," they mean this document.
1. What this policy covers
We provide managed IT and managed security services, together with on-demand and project support, help desk, cloud and software subscriptions, licensing, backup, and related equipment. Our clients are businesses, government entities, and nonprofits. We also sell to consumers, meaning individuals buying for personal, family, or household purposes; a consumer purchase is a one-time purchase or a fixed-term license, never a subscription. "Personal information" means information that identifies, relates to, or could reasonably be linked to you.
Two roles. When you visit our websites, contact us, buy from us, work at an organization we serve, supply us, or apply for a job, we determine how your information is used, and this policy governs that use. When we manage, use, monitor, back up, secure, or support a client's systems, we treat the information in those systems as "Client Data" and handle it only on the client's documented instructions under its agreement with us; §4 explains how, and the agreement controls where it differs.
Not covered. Third-party sites and products we link to or administer for you have their own privacy terms. Our clients' privacy practices are their own; if you are a client's employee or customer, your organization's notices explain how it uses your information.
2. What we collect
We collect only what we need to run our business and deliver our services:
- Contact and account details: name, title, employer, email addresses, telephone numbers, mailing address, credentials for our portals and systems, roles, and contact preferences. We also record the trusted contacts your organization designates to approve work and changes.
- Service records: tickets, chats, emails, technician notes, device names and identifiers, screenshots and files you send us, call recordings, transcripts, and AI-generated call notes and summaries, remote-session logs and, where enabled, session recordings, and photographs taken to document on-site work.
- Billing records: quotes, orders, contracts, invoices, payment records, card type and last four digits, a stored payment credential where you keep a card on file, your authorizations for individual charges, bank payment confirmations, tax forms, and collection history.
- Consent and preference records: marketing opt-ins and opt-outs, text-message consent with its date, time, source, number, and wording, and do-not-call requests.
- Technical data: IP address, device and browser type, pages visited, timestamps, cookie identifiers, error logs, and open and click data for emails we send.
- Security telemetry from the environments we manage: device inventories, sign-in events, IP addresses, DNS and web requests, process and file metadata, flagged emails, vulnerability and patch status, alerts, and incident records, plus threat intelligence and breach exposure for your domains.
- Credentials and secrets: credentials your organization entrusts to us, stored securely with restricted access.
- Other records: identity verification when we change contacts, release information, or grant access, including an identification document where a contract requires it; recruiting information, including references and background checks with your consent; and visitor records at the offices we use.
Most of this comes from you, your organization, and our own tools; some comes from public business sources, referrals, payment processors, screening providers, and our security platforms. For our own purposes, we do not seek precise geolocation, biometrics, or information about race, religion, health, or sexual orientation unless a specific legal, employment, security, or accessibility purpose requires it. Some information we do collect, such as account credentials and government identification documents, is treated as sensitive under some privacy laws; we collect it only to deliver, secure, and administer our services, and we do not use it to draw conclusions about you as a person. If we receive other sensitive information incidentally, we handle it under this policy. Client Data may contain sensitive information, which is handled under §4. If you provide information about someone else, you confirm that you are authorized to do so. Statistics that no longer identify anyone, such as ticket volumes, may be used and shared freely; we keep them de-identified and do not try to re-identify them.
3. How we use it
We use personal information to:
- deliver and support our services;
- secure our clients and ourselves, including monitoring for threats, investigating incidents, verifying identity, and preventing fraud;
- quote, invoice, collect, and keep accounting and tax records;
- send service, outage, security, billing, renewal, and policy notices;
- market our services within the choices in §5;
- analyze and improve our services and train our team, using de-identified data where possible;
- meet legal, audit, and insurance obligations and establish or defend claims;
- recruit; and
- evaluate a merger, financing, or sale under confidentiality.
Where a law, such as the GDPR, requires a legal basis for processing, the basis depends on the activity: performance of a contract or steps toward one, our legitimate interests in operating and securing our business, legal obligations, and consent where required.
We do not make decisions about you solely by automated means that have legal or similarly significant effects. Our security tools may take automatic protective actions on managed systems, such as blocking a sign-in. Those actions protect systems and are not used to make employment, credit, eligibility, or similarly significant decisions about you. Where the service permits, an authorized technician or your organization's administrator can review actions that affect your access.
4. Client Data: when we work for your organization
Our role. We process Client Data only to deliver the contracted services, in accordance with your organization's documented instructions, and as required by law. Your organization decides what we manage and who may access it, and it is responsible for telling its own people what it has asked us to do, including any monitoring notice the law where they work requires. We do not sell Client Data or use it to market to anyone outside your organization, and we segregate client data through tenant boundaries and access controls. We may analyze security telemetry from the environments we manage, in aggregate and without disclosing one client's information to another, to detect threats and improve protection across our clients. We may also use knowledge of your environment to advise your organization about risks, improvements, and services relevant to our existing service relationship. We may decline an instruction that would break the law.
Technician access. To support you, our technicians may see your screen, open a mailbox or file share, sign in to an administrator console, or connect to a device. Remote control asks for on-screen consent unless your organization has authorized unattended access to its managed devices. Technicians access only what the task reasonably requires and do not intentionally copy or retain personal content outside approved systems. Information captured in approved tickets, logs, recordings, or other service records is retained under §9. Technicians do not disclose personal content they encounter except as needed to resolve the issue or as required by law. Administrative access is individually attributable and logged, and the credentials your organization entrusts to us are stored in dedicated vaults, with clients kept separate from one another.
Security monitoring. Managed security works by monitoring activity, including sign-ins, devices, processes, files, web requests, suspicious emails, and vulnerabilities. That telemetry includes personal information about the people who use your systems. We use it solely to detect, investigate, respond to, and prevent threats and to report to your organization. We keep it for the period your agreement states or, if the agreement states none, under §9. We share it only with the security platforms that process it for us, with your organization, and with authorities or incident responders when an incident requires it.
Automation and AI. Automation and artificial intelligence are part of how we deliver: routing and summarizing tickets, transcribing and summarizing calls, analyzing logs, automating provisioning, and learning the patterns of your environment, such as normal sign-in behavior or maintenance schedules. What our tools learn about your environment's normal patterns is used for your environment. The AI services approved for Client Data run under company-managed business accounts whose terms protect confidentiality and do not permit our data to be used to train generally available models. We do not put Client Data into free, personal, or unmanaged AI services. If your organization asks us not to use AI-assisted tools with its data, we will honor that request; because our standard workflows rely on them, we will first agree in writing on the scope and any impact on response times and fees.
Providers and locations. Service providers (subprocessors) host, back up, monitor, and support Client Data under written security and confidentiality obligations. We provide clients, on request, a list of providers that process their Client Data. Some provider reports and details are confidential, and we cannot share those. Where Client Data is stored and who can access it are described in §8. Clients may ask to be notified before we add or replace a provider that processes their Client Data, and the agreement states how.
Regulated data. "Regulated data" means information subject to specific legal, regulatory, or contractual security requirements, such as Controlled Unclassified Information (CUI), protected health information, and payment card data. Some Client Data is regulated data and has its own rules: protected health information is handled under a business associate agreement; financial institutions' customer information is handled under the federal safeguards that apply to their service providers; and payment card data is handled in accordance with applicable payment-card security requirements and the responsibilities our agreement assigns. Data subject to government security requirements is accepted only where your agreement provides for it. Tell us before services begin if your environment contains regulated data, so the required agreement and handling are in place first, as required by our billing and payment terms. Never send regulated data through billing or general support channels; ask us for a secure channel.
Requests about Client Data. If you are a client's employee or customer and want to access, correct, or delete information in the systems we manage for that client, ask your organization; we act on its instructions and help it respond. A court, agency, or other third party that requests Client Data is referred to your organization where the law permits; we notify your organization before disclosing anything unless the law prohibits it, and we disclose only what the request validly requires.
End of service. When a service ends, we return or delete Client Data as the agreement provides. For Client Data in systems under our control, we give you at least thirty (30) days to export it unless your agreement requires a different period. We then delete the remaining Client Data from systems under our control using the sanitization standard required by your contract or regulation or, if none applies, NIST SP 800-88 Revision 1 guidance. Backup copies expire on their normal schedule or are overwritten, and data in third-party subscriptions follows the vendor's schedule, which we do not control. Our billing and payment terms govern data on unpaid accounts. We confirm deletion in writing on request.
5. Marketing, texts, and calls
Our approach. We market primarily to businesses, business contacts, and people who have asked to hear from us, mainly via email and personal written outreach. We may make business-to-business sales calls, ourselves or through a partner calling on our behalf, to business telephone numbers; we do not call consumers to market, we do not call any number on our do-not-call list, and we do not use text messages for marketing. We keep a record of every opt-in and opt-out with its date, time, source, and wording. We may obtain business contact details from public professional sources and business data providers for business-to-business outreach; we do not buy consumer lists. Consent to marketing is never a condition of buying from us. Service, billing, security, and legal communications are not marketing and continue throughout our relationship.
Email. Every marketing email identifies us, includes our postal address, and carries a working unsubscribe link. We honor unsubscribes within ten (10) business days, at no charge, and require no information beyond your email address.
Text messages. We use text messages to deliver and coordinate service, not to market. When you provide a mobile number for account, support, onboarding, or service communications, we may send non-marketing texts about that purpose where permitted by law, including ticket updates, scheduling and visit coordination, identity verification codes and onboarding notifications, outage and security alerts, and billing reminders. A billing reminder sent by text is a courtesy. Formal notices, including suspension and termination notices, are sent through the channels our billing and payment terms require. Where applicable law requires consent, we obtain it before sending the messages. Message frequency varies with your activity, message and data rates may apply, and carriers are not liable for delayed or undelivered messages. Reply STOP to any text to stop texts from that number, or HELP for help. A STOP is processed by the messaging platform on receipt, and we honor any other opt-out request within ten (10) business days. After you opt out, we send one confirmation message and then reach you about your account by email or phone instead. Mobile information, text-messaging opt-in data, and consent will not be shared with or sold to third parties or affiliates for marketing or promotional purposes; we share it only with the messaging platforms, carriers, and aggregators that deliver our texts, and every other form of sharing in this policy excludes text-messaging originator opt-in data and consent.
Calls, recording, and AI notes. We do not use automated dialing or ringless voicemail to reach you. We call you about your account, tickets, orders, scheduling, security, or something you asked for, including returning your calls, and, if you are a business contact, about our services; we identify ourselves. Our phone system uses automated menus, prerecorded instructions, and AI features to route and assist calls. Every call with our lines, incoming or outgoing, is recorded, transcribed, and summarized into notes by our phone system's AI tools by default, for quality, security, record-keeping, and to document the work. We give notice before recording and transcription begin and obtain consent as applicable law requires; continuing the call after the notice is your consent. AI notes help our technicians document your request; they make no decisions about you. If you prefer not to be recorded or transcribed, tell us and we will continue by email or another available channel. If you ask us not to call you or a particular number, we add the request to our do-not-call list and honor it within ten (10) business days. Remote support sessions are logged, and when your organization enables session recording, the on-screen prompt indicates this.
Reviews and testimonials. Reviews you post on public platforms, such as Google, are public, and we may show or quote them on our website and in our marketing materials. Beyond reviews you post publicly, we publish a testimonial, name, title, or organization's logo only with written permission, which you can withdraw for future use.
Changing your choices. Use the unsubscribe link, reply STOP, tell the person you are speaking with, email privacy@itofus.com, call (855) 554-8872, or write to the §12 address. We honor a withdrawal of consent made in any reasonable way and keep a record to ensure we continue honoring it.
6. Cookies and website analytics
Our websites and portals use cookies and similar technologies. Strictly necessary cookies keep you signed in, remember your preferences, and protect the sites; our own client portals, including Nexus, our account management system, use them to run your session securely. Analytics and measurement tools, such as Google Analytics, tell us how our sites are used so that we can improve them. Marketing and social tools, such as those from Google and Meta, help us understand and reach the people who interact with us across our sites and our social media, and may connect your activity on our sites with your accounts on those platforms, under those platforms' own privacy terms. Some of our portals, such as our support desk and knowledge base, run on providers' platforms that set their own cookies, which we do not control. We do not place third-party advertising networks on our sites. You can limit cookies in your browser and in those platforms' own settings, and §11 explains how to ask us to stop using your email address in those tools. Emails we send may contain an image or link that records opens and clicks; blocking images prevents that. Our sites may not respond to browser "Do Not Track" signals because there is no common standard for them. Where applicable law requires us to recognize a legally valid browser-based opt-out preference signal, we honor that signal as required.
7. Who we share it with
We do not sell personal information, and, except for the measurement and marketing tools described in §6, we do not share it with anyone for advertising purposes. We share it only with:
- Service providers. They host, run, or support our tools: cloud and backup platforms; productivity, email, and document tools; ticketing and client portals; telephony, texting, and remote support; security platforms; payment processors and banks; accounting, e-signature, marketing, outreach, and analytics providers; AI-assisted tools under business agreements; and recruiting and screening providers. Each provider may process personal information only as permitted by its agreement with us and applicable law. We require protections appropriate to the service and information involved, including incident notification where the risk of the service warrants it. We provide clients, on request, a list of providers that process Client Data, as described in §4.
- Your organization. When you are a client's user, your organization owns the relationship: it receives the records of our work for it, such as your tickets, session logs, and alerts involving your account, and under a managed services agreement, its designated owner and administrators may access all the information we hold about the organization.
- Manufacturers, software vendors, and carriers. At your direction, we share what is needed to open a support case, warranty claim, or order; when we resell or administer a vendor's cloud subscription for you, the vendor receives the account and contact details needed to provision and bill it under its own terms.
- Our parent company and affiliates. IT of US is part of a group of companies. Our parent company receives governance, risk, incident, and audit reporting about our business, which may include personal information where an incident or a claim requires it, and affiliates may provide shared administrative, financial, or professional support. Both are bound by confidentiality and by this policy, and neither receives personal information for its own marketing.
- Others when needed. Our accountants, auditors, lawyers, and insurers, under confidentiality; authorities and other parties when the law requires or permits, where we disclose only what is required and tell you when the law allows; a successor in a merger, financing, or sale of assets, under confidentiality and bound by this policy; and anyone else at your direction or with your consent.
8. Where it is stored and who can access it
We are a United States company with a global workforce. We store personal information, including Client Data, in the United States whenever the service lets us choose where data is stored. Some providers may process limited operational, support, or service data in other countries under applicable contractual and security safeguards. Authorized members of our team may also access personal information from other countries through company-controlled systems, subject to the same security, authentication, access-control, and confidentiality requirements. If your agreement restricts who may access your environment, we apply that restriction; state it in the agreement before services begin. If applicable law restricts transfers to the United States, we use legally recognized safeguards where required and provide relevant transfer information to clients on request.
9. How long we keep it
We keep personal information only as long as we need it for the purposes above, as long as our agreements and the law require, and as long as we need it to establish or defend claims. When retention ends, we securely delete it or, where appropriate and lawful, irreversibly de-identify it. When we delete information or dispose of storage devices, we follow the standard named in §4. Copies in our backups expire on the backup's normal schedule or are overwritten; we use backups only to recover from a loss, and if a restore brings back information we had deleted, we delete it again. A legal hold, litigation, or investigation suspends deletion; a longer period required by your agreement, a law, or a regulator prevails; and our billing and payment terms set their own periods for data on unpaid accounts. Identity verification and office visitor records are kept no longer than twelve (12) months unless a longer period above applies. Our standard periods:
| What | How long |
|---|---|
| Account, contract, order, billing, payment, and tax records, including records of the notices we send you and of changes to your notice contacts | Seven (7) years after the relationship ends, or longer where tax or contract rules require. |
| A card you keep on file | Deleted within thirty (30) days after your order ends and no undisputed amount remains due, as our billing and payment terms provide. |
| Tickets, service notes, reports, and on-site photographs | The term of your agreement plus the retention period it states; three (3) years after the relationship ends if it states none. |
| Call recordings, transcripts, and AI-generated call notes in our phone system, remote-session logs and recordings, website and portal logs, and managed-environment security telemetry | No longer than twelve (12) months, unless your agreement states otherwise or an open ticket, dispute, incident, or legal matter requires it to be longer; call notes copied into a ticket follow the ticket period above. |
| Marketing, text, and call consent and opt-out records | Five (5) years after the relationship ends or your last interaction, whichever is later; opt-out and do-not-call records for as long as needed to honor them. |
| Job applicant information | Two (2) years after the hiring decision, unless you are hired or ask us to keep it. |
| Credentials and secrets your organization entrusts to us | For as long as the service requires them, then removed from our credential systems at the end of service under §4. |
| Client Data after a service ends | As §4 and your agreement provide; backup copies expire on their normal schedule. |
10. How we protect it, and what happens in a breach
We protect personal information with reasonable administrative, technical, and physical safeguards under an information security program aligned with ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria. We are building a Trust Center to publish our current audit and certification status. Until it is available, we share that status, and the details of our controls, with clients and auditors on request under confidentiality. No storage or transmission method is completely secure, and we cannot guarantee absolute security. Help us by using the secure channels we provide, never sending passwords, card numbers, or regulated data via email, chat, or billing channels, and by contacting us at support@itofus.com or (855) 554-8872 if you suspect a problem.
Breaches. We follow a defined incident management process: every suspected incident is reported, assessed, contained, investigated, and recorded. If a breach affects personal information for which we are responsible, we notify affected individuals and regulators as required by law; under Florida law, that means notifying affected individuals no later than thirty (30) days after we determine that a breach occurred or have reason to believe one occurred, and notifying state regulators when required. If a breach affects Client Data we hold for a client, we notify the client as quickly as we can and, in any case, no later than ten (10) days after we determine that a breach occurred or have reason to believe one occurred. We support the client's own investigation and notifications as reasonably required. A shorter deadline in a law or in your agreement controls.
11. Your rights and how to ask
If we hold personal information about you, you can ask us what it is and obtain a copy, correct any inaccuracies, ask us to delete what we no longer need (§9 explains what we must keep), stop marketing to you, and withdraw any consent you have given. If your state's privacy law gives you more, such as portability, opting out of targeted advertising, limiting the use of sensitive information, or an appeal, we honor it as that law provides. We do not sell personal information. The measurement and marketing tools described in §6 are the only way information about you reaches another company for advertising purposes; you can limit that in your browser and in those platforms' settings, and you may email privacy@itofus.com to ask us to stop using your email address in them. Where a privacy law treats our use of those tools as a sale or sharing of personal information, we honor opt-out requests as that law provides, including a valid browser opt-out preference signal. If a law outside the United States, such as the GDPR, applies to you, we honor the rights it grants you, and you may file a complaint with your local authority.
How to ask. Email privacy@itofus.com, call (855) 554-8872, or write to the §12 address, and tell us what you want and how to reach you. We act on requests we can verify: we match you to our records; for sensitive requests, we may confirm through a second channel or with your organization's administrator; and we ask only for what we need. We may decline a request we cannot verify, a request made on behalf of someone else without authority, or a request that is manifestly unfounded or excessive; where a law requires more of us, we follow the law. An authorized agent must provide written permission or other proof of authority required or permitted by applicable law. When we provide copies or delete information, we protect other people's information, our clients' confidential information, and the integrity of security investigations, and we may withhold or redact where the law allows. We respond within the time required by applicable law. Where no shorter period applies, we respond within forty-five (45) days and will let you know if an additional period is reasonably necessary and permitted by law. There is no charge for a normal request. If we decline, we tell you why, and you may ask us to reconsider by replying to our response; we answer within forty-five (45) days and, where a law gives you the right to complain to a regulator, we tell you how to reach it. Requests about information in the systems we manage for a client go to that client (§4).
12. The fine print
Children. Our websites and services are for businesses and adults and are not directed to anyone under eighteen (18). If you believe we have collected a child's information for our own purposes, please tell us, and we will delete it unless applicable law requires us to retain it. If the information is Client Data, we refer the request to the client and act on its instructions.
Installed systems. If we install or configure cameras, recorders, or access control systems for your organization, your organization operates them, decides placement, retention, signage, and consents, and is responsible for their recordings and access records.
Our agreements. This policy does not change any agreement between us; a signed agreement, order, data processing agreement, or business associate agreement governs the information it covers, subject to applicable law. Where this policy and our billing and payment terms address the same handling of personal information, this policy controls; our billing and payment terms continue to govern payment, suspension, and data on unpaid accounts. This policy is offered in English, and the English version takes precedence over any courtesy translation; ask us if you need it in another format.
Changes. We may update this policy by publishing a revised version at https://itofus.com/privacy with a new version number and effective date. If a change materially reduces your rights or expands what we do with information we already hold, we give at least thirty (30) days' notice by notifying our clients' contacts on record and posting notice on our websites before the change takes effect. We seek fresh consent where the law requires it. We retain every version with its effective date, so that the version in force on any date can be proven, and we provide any prior version upon request.
Contact. Privacy questions, requests, and complaints: privacy@itofus.com or (855) 554-8872; by mail, IT of United States, LLC, Attn: Privacy, PO Box 140515, Coral Gables, Florida 33114, USA. Send legal notices to the legal-notice address listed in your order or, if none is listed, to our registered agent on file with the Florida Department of State.