1. Introduction

BrownPeak Legacy LP respects the privacy of every person who visits our website, contacts our office or engages our consulting services. This Privacy Policy explains what information we collect, why we collect it, how we use it, with whom we share it and what choices you have. The policy is issued by the developer and operator BrownPeak, acting for BrownPeak Legacy LP, and it applies to our website, our business communications and our professional engagements.

We have written this policy in plain language on purpose. Privacy notices are frequently long and vague, and we do not believe that is good practice. If any part of this document is unclear, you are welcome to write to us and we will explain it in ordinary words. We would rather answer a question than have a reader give up halfway through.

This policy should be read together with our Terms of Service, which govern the use of this website and the delivery of our consulting work. Where a client engagement agreement contains privacy commitments that are stricter than this policy, the engagement agreement governs for that engagement.

2. Scope of This Policy

This policy covers personal information processed by BrownPeak Legacy LP through the following channels: the public website at brownpeak.buzz and its subpages, email and telephone contact with our office, proposals and contracts exchanged with prospective and current clients, event and meeting participation, and recruitment enquiries. It also covers personal information that we handle incidentally while delivering legacy systems assessment, modernisation planning, data migration engineering, cloud transition, knowledge capture and managed transition support.

This policy does not apply to third party websites that we may link to, nor to software platforms operated by our clients or their other suppliers. When we work inside a client environment, the client normally remains the controller of the personal data held in that environment, and our processing is governed by the engagement agreement and the client own privacy notice.

3. Data Controller and Contact

For the purposes of applicable data protection law, the controller of the personal information described in this policy is BrownPeak Legacy LP. Our registered and operating address is 897 W 230 N, Orem - 84057-4527, United States (US). Our general contact email is hello@brownpeak.buzz and our telephone number is +14845493783.

Privacy questions, access requests and complaints should be directed to the same contact points. We ask that written privacy requests be sent by email so that we have a clear record of the request, the date it was made and the response we provided. We aim to acknowledge every privacy request within five business days.

BrownPeak Legacy LP
897 W 230 N
Orem - 84057-4527
United States (US)
Email: hello@brownpeak.buzz
Phone: +14845493783

4. Information We Collect

We collect several categories of information, and the category depends on how you interact with us. The main categories are identity and contact information, professional information, correspondence content, technical information about your use of the website, and project information supplied during an engagement.

Identity and contact information includes your name, employer, job title, email address, postal address and telephone number. We typically collect this when you contact us, request a proposal, subscribe to an update, attend a meeting or sign an engagement agreement.

Professional information includes the role you perform, the team you work within and the technical systems you are responsible for. This helps us route your enquiry to the right engineer and prepare relevant material.

Correspondence content includes the messages you send to us, the notes we take during calls and meetings, and any attachments you provide. Technical information includes internet protocol addresses, browser type, device characteristics, referring pages and the pages viewed on our website.

Project information includes configuration details, system inventories, dependency data and other technical material supplied while we perform an engagement. Project information may incidentally contain personal data, for example user identifiers held in a legacy database. Where that happens, we handle it strictly under the instructions of the client.

5. How We Collect Information

We collect information directly from you when you complete a contact form, send an email, call our office, participate in a meeting, respond to a proposal or enter an agreement with us. We collect information automatically from your browser when you visit the website, as described in the cookies section below.

We may also receive information from your colleagues or from a client organisation when they nominate you as a point of contact for a project. We may receive limited professional information from publicly available sources such as a company website or a professional networking profile when preparing for a business meeting. We do not purchase consumer marketing lists and we do not use data brokers to build profiles of website visitors.

6. Purposes of Processing

We process personal information for the following purposes: responding to enquiries and providing information about our services, preparing proposals and statements of work, delivering and administering consulting engagements, maintaining business and financial records, managing our relationship with clients and suppliers, operating and improving the website, protecting our systems and our legal position, and complying with legal, tax and accounting obligations.

We also process information to send service updates and occasional professional articles to people who have asked to receive them. We may process information to detect and prevent fraud, to investigate security incidents and to enforce our agreements. Finally, we process information to understand how our website is used in aggregate so that we can improve its structure, content and accessibility.

We do not sell personal information. We do not rent contact lists. We do not use client project data for any purpose other than delivering the engagement for which it was supplied, unless the client gives us specific written permission to do otherwise.

8. Cookies and Similar Technologies

Our website is intentionally lightweight and uses cookies sparingly. Cookies are small text files placed on your device by a website. We use strictly necessary cookies to support basic functionality such as remembering that you have opened a navigation panel. These cookies do not require consent in most jurisdictions because the website cannot function properly without them.

If we introduce analytics cookies in future, we will do so in a manner that respects applicable consent requirements, and we will update this policy to describe the change. We do not use advertising cookies, cross site tracking pixels or fingerprinting techniques. You can control cookies through your browser settings, and disabling cookies will not prevent you from reading any page on this website.

9. How We Share Information

We share personal information only where it is necessary and only with appropriate safeguards. We share information with members of our own team who need it to respond to you or to deliver an engagement. We share information with professional advisers such as accountants, auditors and lawyers when required for the proper conduct of our business.

We share information with service providers who support our operations, for example email hosting, document storage and information technology support. These providers act on our instructions and are bound by confidentiality and data protection obligations. We do not permit them to use personal information for their own purposes.

We may disclose information where we are required to do so by law, by a court order, or by a regulator with lawful authority. We may disclose information to protect the rights, property or safety of BrownPeak Legacy LP, our clients, our staff or the public. If our business is ever reorganised, merged or transferred, information may form part of the transferred assets, and we will notify affected individuals where the law requires it.

10. Service Providers and Subprocessors

We keep our supply chain deliberately small so that we can understand and monitor it. We use reputable providers for email, cloud infrastructure, document collaboration and accounting. Before engaging a provider that will handle personal information, we assess its security posture, its data protection commitments and its ability to assist us with individual rights requests.

Where we act as a processor for a client, we flow down the client instructions to any subprocessor we engage and we remain accountable to the client for the subprocessor performance. We maintain a register of subprocessors used in client engagements and we make that register available to clients on request. Clients who need to approve subprocessors in advance may do so through their engagement agreement.

11. International Data Transfers

BrownPeak Legacy LP is based in the United States, and information we collect is generally stored and processed in the United States. Some of our service providers operate infrastructure in other countries. Where personal information originating in the European Economic Area, the United Kingdom or Switzerland is transferred outside those regions, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.

If you would like more detail about the safeguards that apply to a specific transfer, please contact us at hello@brownpeak.buzz and we will provide the relevant information. We review our transfer arrangements regularly and update them when the legal framework changes.

12. Data Retention

We keep personal information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. Enquiry correspondence is normally retained for two years from the last contact so that we can maintain continuity if you return to us. Contract and financial records are retained for at least seven years to satisfy tax and accounting obligations.

Recruitment information is retained for twelve months unless you ask us to keep it longer. Website server logs are retained for a short operational period and then deleted or aggregated. Client project data is retained according to the engagement agreement and is returned or destroyed at the end of the engagement in line with the client instructions.

When information reaches the end of its retention period, we delete it securely or irreversibly anonymise it. Where deletion is not immediately possible, for example because information is held in a backup archive, we isolate the information and delete it when the archive cycle permits.

13. How We Protect Information

We apply technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. These measures include encryption of data in transit, access controls limited to personnel who need the information, strong authentication for our business systems, regular software updates and secure configuration of the services we operate.

Our personnel receive confidentiality obligations and privacy awareness guidance. We restrict the use of removable media and we maintain procedures for granting, reviewing and revoking access. We test our backup and recovery arrangements periodically. No security programme is perfect, and we do not claim otherwise, but we work continuously to reduce risk and to respond quickly when issues arise.

14. Client Project Data

During a legacy transition engagement we may access client systems that contain personal information belonging to the client customers, employees or partners. In those situations the client is normally the controller and BrownPeak Legacy LP acts as a processor or a service provider. We process that information only on the documented instructions of the client and only for the purposes of the engagement.

Our engineers work under least privilege principles, using read only access wherever the work allows it. Where we must copy data for testing or migration purposes, we use de-identified or masked datasets unless the client has approved the use of production data. Any production extract is stored in an encrypted environment, is restricted to named engineers, and is destroyed at the close of the work.

We assist clients in responding to individual rights requests that relate to data we process on their behalf, and we notify the client without undue delay if we become aware of a security incident affecting their data. The specific allocation of responsibility is set out in the engagement agreement and, where applicable, in a separate data processing agreement.

15. Marketing Communications

We send marketing communications only to people who have a genuine professional interest in our services. This includes existing clients, people who have asked to receive updates and professional contacts with whom we have an ongoing relationship. Every marketing message includes a clear way to opt out, and we honour opt out requests promptly.

We do not share contact details with third parties for their own marketing purposes. If you receive a message that appears to come from us but does not relate to our services, please let us know, because it may be a fraudulent communication that misuses our name. We will never ask you for payment card details or account passwords by email.

16. Your Privacy Rights

Depending on your location, you may have the right to access the personal information we hold about you, to request correction of inaccurate information, to request deletion of information that we no longer need, to request restriction of processing, to object to processing based on legitimate interests, and to receive information in a portable format.

You may also have the right to withdraw consent where processing is based on consent, and the right to lodge a complaint with a supervisory authority in your country. We do not discriminate against individuals who exercise their privacy rights. To make a request, please contact us at hello@brownpeak.buzz or write to our address at 897 W 230 N, Orem - 84057-4527, United States (US).

We will verify your identity before acting on a request, using information already in our possession wherever possible. We will respond within the timeframe required by applicable law, and we will explain our reasoning if we are unable to comply with any part of a request.

17. Privacy for Children

Our website and services are intended for professional and business audiences. They are not directed at children, and we do not knowingly collect personal information from children. If you believe that a child has provided personal information to us, please contact us and we will take appropriate steps to delete the information promptly.

Where a client engagement involves systems that hold data relating to children, we handle that data strictly under the client instructions and in accordance with the additional safeguards the client has adopted for such data.

18. Automated Decision Making

We do not use personal information to make automated decisions that produce legal effects or similarly significant effects concerning individuals. Our consulting work may involve building systems that support client decision making, but those systems are designed and operated under the client control, and their use is governed by the client own policies and notices.

Where a client asks us to design automation that profiles individuals, we require the client to confirm that the processing has a lawful basis and that appropriate safeguards, including human review where required, are in place.

19. Third Party Websites

Our website may contain links to third party websites that we do not control. This policy does not apply to those websites, and we are not responsible for their privacy practices or their content. We encourage you to read the privacy notice of any website you visit before providing personal information.

Similarly, when we work with client systems, those systems may contain integrations with third party products. We assess those integrations as part of our engineering work, but their privacy practices remain the responsibility of their respective operators.

20. Data Breach Response

We maintain a documented procedure for responding to suspected or confirmed personal data breaches. The procedure covers containment, assessment of risk, notification to affected clients and, where required, notification to supervisory authorities and affected individuals within the timeframes set by applicable law.

If you believe you have discovered a security vulnerability or a potential breach involving BrownPeak Legacy LP, please contact us immediately at hello@brownpeak.buzz or by telephone at +14845493783. We welcome responsible disclosure and we will work with you to investigate and resolve the matter.

21. Changes to This Policy

We review this policy regularly and update it when our practices, our services or the law change. The effective date at the top of the page indicates when the current version took effect. If we make a material change that affects how we use personal information, we will provide a prominent notice on the website and, where appropriate, contact affected individuals directly.

We encourage you to review this policy from time to time. Continued use of our website or services after an update takes effect indicates your acceptance of the revised policy to the extent permitted by law.

22. How to Contact Us

If you have a question about this policy, a concern about how we have handled your information, or a request to exercise any privacy right, please contact us. We take every privacy enquiry seriously and we aim to resolve concerns quickly and fairly.

BrownPeak Legacy LP
897 W 230 N
Orem - 84057-4527
United States (US)
Email: hello@brownpeak.buzz
Phone: +14845493783

This policy is issued on behalf of BrownPeak Legacy LP and applies to all processing carried out by our team in Orem, Utah and at client locations. Thank you for taking the time to read it.