Privacy Policy
Have counsel review before publishing
Legal entity: [Legal entity name and state of formation pending] ("Azroth," "we," "us," or "our")
Effective date: [Effective date pending]
Azroth respects the privacy of the people who visit our website, request a Lifecycle Risk Assessment, create an account, or engage with us about our independent third-party maintenance and lifecycle support services. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
This policy applies to the Azroth website at www.azroth.com and related online forms, accounts, and communications that link to this policy (collectively, the "Site"). It does not replace the privacy, confidentiality, or data-handling terms in a signed agreement between Azroth and a customer. If a signed agreement conflicts with this policy as to customer service data, the signed agreement controls.
Information We Collect
We collect information you choose to provide and limited information generated when you use the Site.
Information you provide
Contact and inquiry information. When you contact us or submit a form, we may collect your name, work email address, company, job title or role, phone number, message, and other information you choose to provide.
Lifecycle Risk Assessment information. If you request a Lifecycle Risk Assessment, we may collect your name, work email address, company, role, phone number, storage-environment details, NetApp system models, and anticipated decision timeline. Please provide only the information reasonably needed for the assessment. Do not include credentials, patient information, payment-card data, or other sensitive personal information in a web form.
Account registration information. If account registration is available, we may collect your name, email address, password, and, if you choose to provide them, company and role. Passwords are hashed using Django's built-in one-way password hasher, and authentication uses a per-session API token stored in an httpOnly cookie that is never exposed to client-side JavaScript [Authentication implementation description pending counsel review].
Service-delivery information. When a customer engages Azroth under a signed services agreement, we may receive information needed to provide the agreed services. Depending on the engagement, this can include technical configuration, inventory, support-case, diagnostics, performance, capacity, and contact information relating to the customer environment. The signed services agreement and any applicable statement of work govern the scope of that information.
Information collected automatically
When you visit the Site, we or our service providers may collect limited technical and usage information, such as IP address, browser type, device information, pages viewed, referring page, approximate location derived from IP address, and timestamps. We use this information to operate, secure, understand, and improve the Site.
Cookies and analytics. As of this policy's last review, the Site does not use third-party analytics or advertising trackers; the only cookie set is a first-party, httpOnly session cookie used to keep you signed in. If that changes, this section will be updated to disclose the specific technology and the consent mechanism used [Confirm no analytics/advertising cookies have been added since this review].
How We Use Information
We use personal information to:
- respond to questions, contact requests, and assessment submissions;
- schedule and deliver a Lifecycle Risk Assessment;
- communicate about prospective or active service engagements;
- provide, administer, secure, and improve our services and the Site;
- create and manage accounts, where available;
- send marketing or business communications that may be relevant to your professional role, subject to your communication preferences and applicable law;
- investigate misuse, protect our rights and the Site, and comply with legal obligations; and
- maintain internal business records.
You may opt out of promotional email at any time by using the unsubscribe link in the email or contacting us at [Privacy contact email pending]. Opting out of marketing messages does not prevent us from sending non-promotional messages about an active relationship, service request, account, or transaction.
How We Share Information
Azroth does not sell personal information. We also do not share personal information for cross-context behavioral advertising. (Have counsel confirm applicability of California "sale" and "sharing" definitions before publishing.)
We may share information only as reasonably necessary with:
- Service providers that help us operate our business, such as hosting, analytics, email, customer-relationship management, scheduling, and support tools: [Specific analytics, email, and CRM tools pending confirmation — none beyond a standard SMTP relay are currently integrated]. These providers may process information only on our behalf and subject to appropriate contractual obligations.
- Qualified service or field partners when needed to deliver a customer-authorized service, subject to appropriate confidentiality and data-handling obligations.
- Professional advisers such as legal, accounting, insurance, and financial advisers, where necessary for business operations.
- Authorities or other parties when we reasonably believe disclosure is required by law, legal process, or to protect the rights, security, and safety of Azroth, our customers, users, or others.
- Successors or transaction participants in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar corporate transaction, subject to applicable law.
Data Retention and Deletion
We retain personal information for only as long as reasonably necessary for the purposes described in this policy, including to respond to your request, provide services, maintain records, resolve disputes, enforce agreements, and meet legal obligations.
In practice, inquiry and assessment information is retained while the request is active and for a reasonable follow-up and recordkeeping period afterward. Customer service information is retained according to the applicable signed agreement, statement of work, legal requirements, and operational needs. We may retain de-identified or aggregated information where permitted by law.
When information is no longer needed, we will delete it, de-identify it, or take other appropriate steps to render it inaccessible, subject to our backup, legal, security, and recordkeeping practices. [Retention schedule pending approval]
Your Choices and Privacy Requests
Subject to applicable law, you may request to:
- access personal information we hold about you;
- correct inaccurate information;
- delete personal information; or
- opt out of marketing communications.
To make a request, email [Privacy contact email pending] with the subject line Privacy Request. We may need to verify your identity and may decline or limit a request where permitted or required by law, including where we must retain information for legal, security, contractual, or recordkeeping purposes.
Depending on where you live, you may have additional rights under applicable privacy law. Azroth will handle requests in accordance with applicable law. (Have counsel add any jurisdiction-specific notices, including California or GDPR disclosures, if applicable.)
Security
We use reasonable administrative, technical, and organizational measures designed to protect information appropriate to the nature of the information and our business. No website, transmission, or storage system is completely secure. Please do not submit passwords, remote-access credentials, patient information, payment-card information, or other sensitive information through general website forms.
For more information about our security approach, see our Security Overview.
International Data Transfers
Azroth is a U.S.-based company. Information collected through the Site may be processed in the United States and in other locations where Azroth or its service providers operate. (Have counsel confirm international transfer language and safeguards based on actual processors.)
Children's Privacy
The Site and services are intended for business professionals and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact [Privacy contact email pending] so we can take appropriate action.
Third-Party Links
The Site may link to third-party websites or services. Their privacy practices are governed by their own policies, not this Privacy Policy. We encourage you to review those policies before providing information to third parties.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we do, we will post the updated policy on this page and update the effective date above. If changes are material, we will provide additional notice when required by law.
Contact Us
For questions about this Privacy Policy or our privacy practices, contact:
[Legal entity name pending]
[Business mailing address pending]
Email: [Privacy contact email pending]
This template must be completed with Azroth's legal entity, effective date, active processors, actual cookie and consent practices, retention schedule, privacy contact, authentication implementation, and any required jurisdiction-specific notices before publication.