1.About This Policy
The development and operation of the websites and the underlying compliance tools are provided by the developer Kyuvor. Kyuvor acts as the technical builder and operator for each online property linked under this privacy statement, while KYUVOR SECURITY COMPLIANCE LLC is the company that offers professional computer systems design and security compliance advisory services. When this policy refers to the company, KYUVOR SECURITY COMPLIANCE LLC, the developer Kyuvor, or the term we or us, it means the same coordinated organisation that maintains digital properties and delivers the consulting programs described on the homepage.
We have written this Privacy Policy in plain English whenever possible so that you can make an informed decision about the personal information you choose to share with us. We treat your trust as a required control inside our operating environment, and we extend the same rigour we apply to our clients to the data we handle on this property.
This policy is effective as of the date shown at the top of the page. It replaces any earlier version of the privacy statement that may have appeared on this website. By continuing to use the site after a revision, you accept the updated wording as it appears at that time.
2.Scope and Who We Are
KYUVOR SECURITY COMPLIANCE LLC is a limited liability company formed under the laws of the United States. Our registered and principal mailing address is 7533 S Center View Ct PMB R, West Jordan - 84084-5526, United States (US). We operate within the professional, scientific and technical services sector, specialising in computer integrated systems design and related services, including security compliance program advisory work for organisations that handle sensitive information.
This Privacy Policy applies to all personal information collected through this website, through the related services and contact pages, through email correspondence sent to chat@kyuvor.buzz, through telephone calls made to +14127836452, and through any engagement form, consultation call or advisory project that a client undertakes with the company.
The policy does not apply to information that is collected by third-party websites that we may link to from our own pages. It also does not apply to information that is already in the public domain through your own publishing decisions elsewhere.
3.Information We Collect
Information you provide directly
When you reach out to us, we collect the details that you choose to send us. This typically includes your name, your company name, your professional email address, your telephone number, and any detail contained in the message body or project description that you share with our advisors.
Information collected automatically
Like most websites, our servers and hosting configuration may record basic technical data when a browser requests a page. This can include the internet protocol address of the device, the type and version of the web browser, the operating system in use, the referring web page, the date and time of the request, and the pages of our site that you view.
Information collected through services
When you become a consulting client, we collect the information needed to perform the agreed advisory work. For a SOC 2 readiness program or an ISO 27001 gap assessment, this can include an inventory of your information assets, descriptions of your security controls, ownership details for systems and data, and copies of policies or configurations that you provide for review. We treat this material as confidential and process it strictly for the purpose of the engagement.
We do not intentionally collect special categories of sensitive personal data, such as government identifiers, health records or biometric templates, unless you choose to provide them in the course of an advisory project.
4.How Information Is Collected
Personal information is collected through a limited set of deliberate entry points. The first is the contact form or the direct email address used to begin a conversation. The second is a telephone conversation either inbound or outbound. The third is direct correspondence with a named security advisor assigned to your account. The fourth is the automatic collection of technical logs described in the previous section.
We do not purchase third-party marketing lists, and we do not obtain personal information about you from data brokers. Where a prospective client has been referred to us by a mutual contact, we process only the referring details that the contact chooses to share, such as a name and an email address, and we always make clear how that introduction was obtained.
Collected information flows into a controlled evidence-style record that is only accessible to personnel who need it to answer your enquiry or to deliver your project.
5.Purposes of Processing
We process personal information for clear and bounded purposes. We use your details to respond to enquiries, to schedule consultations, to prepare proposals and engagement letters, to deliver the advisory services you request, to invoice for completed work, to comply with tax and accounting obligations, and to maintain a record of the advice provided so that our internal quality review can confirm accuracy.
We may also process basic technical logs to keep the website secure, to diagnose faults, to protect against fraudulent or abusive traffic, and to understand high level trends in how visitors discover our content. We use aggregated statistics that do not identify any single visitor whenever we describe website usage.
Where you have given separate, clear consent, we may send you occasional updates about compliance program changes or industry events. We do not send marketing without that permission, and every such message includes a simple way to opt out.
6.Legal Bases for Processing
Where the principles of the European General Data Protection Regulation or a similar framework apply to a relationship with a partner or client based outside the United States, we rely on appropriate legal grounds for each kind of processing. For most enquiries we rely on our legitimate interest in operating a professional consultancy and answering the queries that adults send to us.
Where we conclude a contract with you, we process the information necessary to perform that contract. Where we are subject to a legal, regulatory or tax obligation, we process data to meet that duty. Where no other ground applies and your data is not required for contract performance, we base the activity on your consent and respect your right to withdraw that consent at any time.
We keep a light internal record of the ground relied upon for each material processing activity so that the reasoning remains traceable to an auditor who asks.
7.Sharing and Disclosure
We do not sell personal information to any party, and we do not rent your details for advertising purposes. We share personal information only in tightly defined circumstances.
We may share an introduction message with a partner deliverer when a named requirement of your project is performed by a vetted sub-consultant who has agreed to the same confidentiality standard. We may disclose information to a government body where the law compels us to do so and where we are satisfied the request is lawful. We may also transfer records in connection with a proposed reorganisation or sale of the company, provided the receiving entity agrees to honour the protections in this policy.
Before any unusual disclosure, we assess whether the disclosure is proportionate, necessary and lawful. We keep shared copies to the minimum needed to satisfy the legitimate recipient.
8.Service Providers and Processors
To deliver the website and the services, we rely on a small number of processors. This includes domain and email hosting, web hosting, a document collaboration platform, a scheduling tool where one is offered, and a secure file transfer method used to exchange evidence with clients.
Each processor is selected with attention to its security posture and its published data handling commitments. We expect each processor to process your information only on our documented instructions and to maintain appropriate technical safeguards. None of the processors are authorised to sell, reuse or otherwise exploit your data for reasons unrelated to our service.
If a processor is located outside the jurisdiction where you reside, we rely on a lawful transfer mechanism so that your rights are not weakened by geography.
9.Cookies and Tracking
This website is kept intentionally lean and does not depend on advertising cookies to function. We may set a small number of strictly necessary technical cookies, such as one that records whether you opened the navigation menu or accepted a settings notice, so that the page behaves consistently during a visit.
We do not run behavioural advertising networks on this property, and we do not feed browsing histories into a profile for cross-site marketing. Any analytics we use are configured in a privacy-friendly manner that limits identification of individual visitors and respects the do not track signals your browser may send.
You can clear cookies at any time through your browser settings without losing access to the services described on this website.
10.Security Safeguards
Because our business is the review of security controls, we hold our own environment to a high standard. Access to systems that store personal information is restricted to named personnel who have signed confidentiality commitments and who use unique credentials with multi-factor authentication where the platform supports it.
Communications with our site are served over encrypted transport, and sensitive exchanges with clients use a protected channel rather than unencrypted email when the material warrants it. We apply the principle of least privilege, meaning each staff member can reach only the records needed for their role.
No method of electronic transmission or storage is completely infallible, so we cannot promise absolute security. What we can promise is a disciplined control environment, regular review of access, and prompt attention whenever we learn of a concern affecting the services we operate.
11.Retention of Data
We keep personal information only as long as it serves a genuine purpose and no longer than the law allows. Basic enquiry records are retired once the matter is closed and no active relationship or statutory record duty remains, which is typically within a reasonable number of years.
Client engagement records are retained for a longer window because tax law, professional liability protection and the need to reconstruct the advice given all require an appropriate archive. When a retention period ends, records are deleted or rendered permanently unreadable through a secure process.
Technical logs are kept for a short window that is set by the hosting provider and used only for fault diagnosis and abuse response.
12.Privacy for Children
Our websites and advisory services are directed at business professionals and are not designed to attract anyone under the age of sixteen. We do not knowingly collect personal information from children, and the advisory programs are not relevant to users below the majority age for contracts.
If you believe that a child has submitted personal information to us through a web form or message, please contact us at chat@kyuvor.buzz and we will investigate promptly and take reasonable steps to remove the data if we confirm it came from a child.
13.International Transfers
Our principal operations are in the United States, and our primary hosting and processing largely stays within North America. If you engage us from another country, your personal information may be transferred to and processed in the United States.
Where a transfer involves a territory that a regulator does not recognise as offering equivalent protection, we apply supplementary safeguards, such as documented contractual terms that preserve your rights, so that the transfer does not lower the standard of protection you would otherwise expect.
By submitting your information, you acknowledge this potential transfer while retaining the full set of rights described in this policy.
14.Your Privacy Rights
Depending on where you live, you may hold a range of rights over your personal information. These commonly include the right to request access to the data we hold, the right to ask for a correction where a detail is inaccurate, the right to request deletion in certain circumstances, and the right to object to or restrict certain processing activities.
Where processing is based on consent, you may withdraw that consent at any time without penalty. Where you believe the processing is unlawful, you may also lodge a complaint with your own data protection supervisory authority.
To exercise any of these rights, contact us using the details in the final section of this policy. We respond to verifiable requests without undue delay and normally within the timeframe required by applicable law. We may ask you to verify your identity before we act, so that we do not hand your records to someone pretending to be you.
15.California Residents
If you are a resident of California, the California Consumer Privacy Act and related rules give you specific rights over the personal information we may hold about you. These include the right to know the categories and specific pieces of information we have collected, the right to request deletion, and the right to opt out of the sale of personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising in a way that would trigger a sale opt-out. We will not discriminate against you for exercising any of your California rights.
To make a verifiable request, please write to us at chat@kyuvor.buzz with the subject line describing your request, and we will confirm receipt and respond within the period the statute permits. You may also designate an authorised agent to act on your behalf.
16.Automated Decision-Making
We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you. Any grading of your security maturity that happens during an ISO 27001 gap assessment is based on a documented methodology reviewed by a qualified advisor, not by an autonomous algorithm that operates without human oversight.
If we ever introduce a scoring or decisioning tool that affects you, we will disclose it clearly beforehand and ensure that a person remains able to review and contest the outcome.
17.Third-Party Links
This website may contain links to external destinations, such as professional networks, standards bodies or client homepages that we mention in content. Once you leave our domain, this Privacy Policy no longer governs the information you provide to that external site.
We encourage you to read the privacy statement of each destination you visit. We are not responsible for the content or the data practices of any third-party website that we do not operate.
18.Changes to This Policy
We review this Privacy Policy on a regular cycle and update it whenever our practices or the law meaningfully change. Any revision takes effect immediately upon publication of the new wording at this location, and we note the date of the latest revision at the top of the page.
Where a change materially narrows your rights or expands what we collect, we highlight the addition on our homepage so that returning visitors see that a statement has been amended. Continued use of the website after a revision indicates acceptance of the updated terms.
19.Breach Notifications
In the unlikely event that we discover a security incident that compromises the confidentiality of personal information we hold, we will act without delay. We will investigate the scope of the incident, take steps to contain any further exposure, and notify the individuals and relevant authorities where the law requires such notification.
Because part of our role is advising clients on incident response, we bring particular discipline to handling any event on our own estate. We treat the protection of client data with the same seriousness that we ask our own clients to show toward their end users.
20.Contact Information
If you have a question about this Privacy Policy, wish to exercise a privacy right, or simply want to discuss how we protect information, you may reach the responsible team through the channels below.
KYUVOR SECURITY COMPLIANCE LLC
7533 S Center View Ct PMB R
West Jordan - 84084-5526
United States (US)
Email: chat@kyuvor.buzz
Telephone: +14127836452
Unified business hours span Monday through Friday and we return privacy enquiries without unreasonable delay. You can also raise a general question through the contact page on this website.