LSJ Consultation, LLC  ·  Return to the homepage

Privacy Policy

Effective across all pages of this web property. Queries about this policy may be addressed to order@lsjconsult.lat. Regulated office of the practising company: LSJ Consultation, LLC, 1204 W 160 N, Orem - 84057-5108, United States (US).

  1. Introduction and scope of the policy
  2. About the developer and practising company
  3. The personal information the company collects
  4. How personal information is gathered
  5. How the company uses personal information
  6. The lawful foundations for processing
  7. Privacy for Children
  8. When information is shared with others
  9. Service providers and sub-processors
  10. Retention periods for personal records
  11. Security measures and safeguards
  12. Cookies and browser technologies
  13. Automated decision making and profiles
  14. Rights of residents under applicable law
  15. How to exercise your rights
  16. Verification of identity for requests
  17. Appeals and complaints
  18. International transfers of information
  19. Third party links and pages
  20. Changes to this privacy policy
  21. Contacting the office about privacy

Introduction and scope of the policy

This Privacy Policy describes how LSJ Consultation, LLC, with a registered office at 1204 W 160 N, Orem - 84057-5108, United States (US), handles personal information connected to the web pages the company operates and to the consulting engagements the company delivers. The pages were built and are maintained by the developer LSJConsult for the firm that practises the design work. The policy is written in plain English and records honestly what the office does with the details an individual leaves behind when reading the pages, filing an intake card, sending electronic mail or placing a telephone call.

The scope is deliberately broad enough to cover the full practical path of an asking enquiry. It begins when a person first lands on a page, continues through each conversation about a possible engagement, and carries on after a project closes, because some records must be kept so the company can answer to the law and to its own past work. Where a separate legal rule applies to a specific region or operator, that rule is honoured in addition to anything in this policy.

The company encourages every visitor, customer, partner and supplier to read this entire document once. The most important idea appears early and is repeated through the pages: personal information is only ever held for a defined reason, kept for only as long as the reason lasts, shown to only those with a need to see it, and never sold. Anyone who reads the policy and afterwards cannot see a clear reason for a particular collection is invited to write to the office and ask. An answer is owed inside two working days.

About the developer and practising company

This web property was designed, built and is operated for LSJ Consultation, LLC by the developer LSJConsult. The developer name belongs to the same office that practises computer integrated systems design in the United States. Throughout this policy the short term the company always means LSJ Consultation, LLC, the practising entity named at the masthead, doing business in computer integrated systems design including enterprise systems integration, custom software architecture, cloud infrastructure design, legacy system modernisation, data pipeline engineering and IT service management platforms.

The company holds itself accountable for the practical lives of the pages. Where this policy names a duty, that duty sits with the company and not with any unnamed third party. Individuals writing to the office can address a question either to order@lsjconsult.lat or, where the topic is entirely about privacy, to the same address with the word privacy in the subject line. Each message is handled by a real person who reads, not by an automated answer.

The personal information the company collects

The company collects only that information which serves an identified purpose. On the intake forms the fields are usually the name of the enquirer, an email address, a subject line and the message body. Where a caller telephones, the office may record the number, the name and a short note of the subject, so the conversation can be continued after the first call ends. Where a visitor uses the go to top button or reads a section link, technical details such as browser type, device type and viewport size may be seen in visiting statistics, but these are aggregated and normally carry no name.

The company specifically does not set out to collect social security numbers, account credentials, passport details, medical records or any sensitive category of personal information in connection with this web property. If an enquirer volunteers such details inside a message, the contact should be treated as accidental. The office will ask the enquirer to remove the sensitive content rather than filing it, unless the detail is genuinely necessary to the delivery of a signed engagement, in which case a separate and explicit consent conversation will take place first.

There is also an ordinary business category of information. When the company delivers work, the record set will naturally include names and addresses of client contacts, invoices, correspondence and account references. That business information becomes part of the wider engagement record and is described under the retention section further down. The principle is unchanged: collect the least, keep the least, and state the reason.

How personal information is gathered

Most personal information reaches the company through actions the individual chooses to take. Filing an intake card sends a name and an email address. Writing to the order mailbox sends a return address and the content of the letter. Calling the telephone line shares a caller number with the office. These are the open doors and the company records what must walk through them.

A second, lesser route is technical and largely passive. Hosting logs, ordinary web statistics and browser support information can reveal an internet address, the type of device and rough location up to the town level. That information is used only to keep the pages working and to understand broad visiting patterns; it is collected at the level of the service provider and is not used to profile an individual person.

A third route is public. When the company researches a named business operator as part of preparing a proposal, it may consult sources the operator has published, such as a company page or a public register. That activity happens on the public internet and does not pull information into any private file beyond a note of what was read and when. Individuals do not need to take any action to avoid this; the information consulted is already public by the operator own choosing.

How the company uses personal information

The company uses personal information for a short and honest list of purposes. First, to answer enquiries. A name and an email address allow the office to reply to an intake card, to arrange a scope conversation and to continue an active negotiation. Second, to deliver signed engagements, which requires the company to correspond with named client contacts, issue invoices and keep the project record. Third, to keep the pages safe and working, which uses technical logs to notice breakdowns and attempted abuse. Fourth, to comply with legal and accounting duties, which requires some records to be held for a fixed number of years after an engagement closes.

Contact details already provided by an individual may be used to share factual updates about that same enquiry or engagement. The company does not add a person to a marketing mailing list without an express and separate agreement. If a newsletter is ever introduced, it will have its own opt in field and its own easy way out, and no mailing will ever be sent to a person who did not ask for it. Honesty about the absence of marketing is part of the consulting character the company wants to keep.

Personal information is not used for any purpose the individual could not reasonably have expected when the information was handed over. Where a new purpose arises that falls outside the original reason, the company will not silently press the old information into that new use. Instead it returns to the individual for a fresh decision, because repurposed information is exactly the kind of quiet surprise this policy exists to prevent.

The lawful foundations for processing

Under the legal framework that governs the office, each act of collecting or holding personal information rests on at least one recognised foundation. The first foundation is consent. Where a visitor files an intake card or agrees to a newsletter, the action itself carries a clear consent to the stated use. The consent can always be withdrawn by writing to the office, and withdrawal applies from the moment the office acts on it.

The second foundation is the performance of a contract. When an engagement moves from enquiry to signed delivery, the company needs the contact and project details to carry the work it has promised. The third foundation is a legal obligation. Tax and accounting law require certain financial records to be kept for a defined period, and where such a rule exists it overrides any shorter personal preference for deletion because the law has spoken.

The fourth foundation is legitimate interest, used sparingly and only where the interest clearly outweighs any downside to the individual. Keeping a working server, issuing an invoice and answering an email are ordinary legitimate interests that every visitor already relies upon. The company weighs each one and can explain the weighing on request. No foundation is ever chosen simply to widen what may be collected; the least is collected, records are kept only as long as needed, and the individual stays able to object in the ways described below.

Privacy for Children

The services on these pages are not directed at children. Personal information about children is not knowingly collected, filed or used. The intake forms and the contact channels serve adults who are commissioning computer systems design work for a business or an organisation, and the natural age of the person acting for that business or organisation is adult.

If the office learns that details of a child have been sent to it by mistake, the information will be removed from active files promptly and without question. A parent or guardian who believes such detail may exist is asked to write to the office so the removal can be confirmed in writing. No commercial profiling, advertising or marketing of any kind is ever aimed at children through these pages, and no child is asked to part with any personal detail as a condition of reading anything the company publishes.

The spirit of this section continues beyond the letter. Even where an enquirer is comfortably adult, the company treats the handling of any unexpectedly personal detail with care, because the standard for protecting the least able should raise the standard for everyone.

When information is shared with others

The company shares personal information only in four tightly defined situations. The first is where the individual asks for the sharing to happen, such as instructing the office to put them in touch with a named partner or supplier. The second is where a service provider needs the information to perform a task the company has asked it to perform, detailed in the next section. The third is where the law compels disclosure, such as a lawful court order or a request from a competent regulator. The fourth is a genuine business transfer, where the practising operation or a significant part of it is sold, merged or reorganised and the records move with it under a written duty to honour this policy.

Beyond these four doorways the company does not share. In particular, personal information is never sold, never traded for another benefit and never licensed to an advertiser. No partner receives a copy of an intake card for any commercial committee, and no data broker ever receives a feed. Where an external party asks for a person detail, the standard answer is to decline and to explain why privacy is not a negotiating chip.

Where sharing does occur through one of the four doors, only the minimum needed for the specific task is handed over, and records of what was shared, with whom and why are kept in the office notes so the account can be given later without guesswork.

Service providers and sub-processors

The company uses a small number of service providers to run its technical and administrative machinery. These commonly include the web host that serves the pages, the provider of the email accounts that carry the order mailbox, the software behind ordinary document creation and, where used, payment processing for invoices. Each provider receives only the information its specific task requires and no more.

Before a provider is chosen the company reviews its ability to protect information and its willingness to keep it confidential. Written agreements with providers hold them to a level of care no lower than the level in this policy. Providers are not free to pass information to their own suppliers without a further review, and none is permitted to use personal data for advertising or for building a profile about a person that the company serves.

The list of active providers changes rarely and is not published as a permanent register because the operational detail dates quickly. Any visitor who wants the current list of providers and their locations may ask the office and will be given a written answer naming each provider and the country in which the information is likely to be held.

Retention periods for personal records

Records are not kept forever. The company follows a simple rule: hold personal information only for as long as the reason for holding it still stands, then delete it in a way that cannot be quietly reversed. Intake cards and enquiry messages that do not grow into an engagement are normally removed from active systems within twelve months of the final exchange, unless the individual has asked to be contacted again about a future opening.

When an enquiry grows into a signed engagement, the project record and its supporting correspondence become part of the practised archive. Accounting law commonly requires financial documents, including invoices and payment records, to be retained for several years after the end of the tax year to which they belong. The company honours that legal period and, once the period expires, reviews and removes the records on schedule rather than leaving them to drift.

Technical logs are retained only for as long as they are genuinely useful for security and fault finding, normally a short window measured in weeks, after which they are rolled over. This staged and scheduled approach means there is no single delete that wipes a whole history in one motion, but there is also no endless shelf where old details live on out of habit. Each record has a calendar date, and the calendar is the one the company follows.

Security measures and safeguards

Protecting the records the company is given starts with ordinary discipline. Access to order mailbox accounts and to the systems that hold project files is limited to people who need access for their role, and each person uses a separate sign in rather than a shared password. Strong and unique credentials are the baseline, and where a provider offers an extra verification layer the office uses it.

Data on the pages travels over encrypted connections whenever the technical environment allows, because the pages are served under encrypted transfer protocols by default. Information held in active project stores sits behind the credentials above, and copies kept for recovery are protected to the same standard as the live files. When a record ends its life it is removed thoroughly, not merely marked as gone, so that deletion means deletion.

The company keeps the safeguarding practical rather than theatrical. No amount of locks makes an office honest on its own, so the social side matters too: people are told not to repeat client details in public spaces, not to carry whole databases on personal machines and not to open suspicious attachments. Where a security event does reach the information of an individual, the company will assess the risk honestly and tell those affected what happened and what was done, without burying the account in evasive language.

Cookies and browser technologies

The web pages themselves are built to be light. They do not rely on advertising networks, and they do not load cross site trackers that follow a visitor from page to page across the internet. The pages may use small storage features known as cookies or similar local storage where that helps a single visit work properly, such as remembering a paper setting inside the current session. Any such use is functional and short lived.

Where the hosting provider or a statistics tool places its own technical markers, those markers exist to count visits and notice faults, and they do not build an advertising profile of a named person. Distinct controlling banners are not thrown in front of every visitor for ordinary functional storage, because the office sees no honest reason to interrupt a person just before they read the pages. Should a technology be added later that does watch a person across many unrelated sites, a clear choice will be offered first rather than after the fact.

Visitors who wish to clear their own browser storage can do so through the standard controls of their own browser at any time. Clearing such storage does not prevent the pages from displaying; it may only forget a small visual preference until the next visit.

Automated decision making and profiles

The company does not make decisions that produce legal or similarly significant effects about a person purely by automated means, and it does not build selling profiles about individuals from the enquiries that arrive. An intake card is read by a person. A scope choice is confirmed by a person in conversation. A quality determination about delivered work is reached by people at review, even where software assists in checking a technical test result.

Automated tools are used in a supporting role only: for example, a script may filter out obviously fraudulent or automated messages before human eyes, and an accounting system may calculate figures an invoice already records. Neither of these turns a person into a statistic or reaches a conclusion about the person as an individual that closes a real door without a human in the room. If the office ever introduces a genuinely automated decision that affects a person legal position, the person will be told, the logic will be explained and a route to a human review will be offered without obstruction.

Rights of residents under applicable law

Depending on where a person lives, the law of that place may grant a set of rights over the personal information the company holds. The rights commonly named include the right to know what is held and why, the right to ask for a copy, the right to ask for a correction where a record is wrong or out of date, the right to ask for deletion where no legal reason requires the record to stay, the right to ask for the flow of information to be restricted or objected to in defined circumstances, and the right to receive a structured copy of information provided to the company so it can be moved to another service.

The company honours these rights wherever they lawfully apply to its records. Where a person lives in a region whose law does not grant a particular right, the company still applies the underlying good practice: it answers politely, it explains what is stored and why, and it never refuses a simple request purely because no judge ordered the answer. Rights belong to people, and the office prefers to be generous about the detail it gives about its own conduct.

Nothing in the exercise of any right removes the legal duties that sit above a personal wish. Certain records must be kept for tax and accounting reasons, and those stay regardless of a request for deletion, with an honest explanation given of exactly why they stay and when they will go.

How to exercise your rights

A request about privacy rights may be made to the office in writing at order@lsjconsult.lat with privacy in the subject line, or by post to LSJ Consultation, LLC, 1204 W 160 N, Orem - 84057-5108, United States (US). The office will acknowledge every request within a normal working window and will resolve it without unreasonable delay, with the answer delivered in the same language in which the matter was raised.

The request does not need to follow any set form. A person may simply explain in their own words what they wish to know, to correct or to delete, and the office will interpret the wish helpfully rather than pedantically. Where a request is broad enough that the company cannot be sure what is being asked, it will reply asking a single clarifying question rather than guessing or refusing.

No fee is charged for a genuine and reasonable first request. Where repeated identical requests arrive clearly aimed at burdening the office rather than resolving a real concern, the company may apply a reasonable charge to cover its time, but it will say so before the work begins and will keep any charge modest and proportionate.

Verification of identity for requests

Before handing out records to a named person, the company must be sure the person asking really is the person the records describe. This is not bureaucracy for its own sake; it is the protection of the very privacy this policy promises. A request to see or delete records will be answered only after the office reasonably confirms the identity of the requester against the details already held.

The confirmation is usually light. The requester may be asked to reply from the email address on record, to confirm the name they used when they wrote originally, or to answer one detail that only they would know. Where a request concerns a sensitive record the office may need a firmer confirmation and will explain what form that should take. The office asks for the smallest proof that is genuinely enough.

Where a person is acting on behalf of someone else, such as a parent for a child or a lawfully appointed agent, the office will ask to see evidence of the authority to act before releasing anything. This single rule prevents the most personal records from being pulled out of the archive by someone merely claiming a connection.

Appeals and complaints

If an answer given to a privacy request does not satisfy the person who asked, that person may ask the office to look again. A simple request to review will be treated seriously and handled by someone other than the person who gave the first answer where the size of the office allows, so the second look is a fresh look rather than a repeat of the first.

The company will respond to a review request with its reasoning, set out in plain words, and will honour the conclusion whether it confirms the first answer or changes it. Where an individual still disagrees, the laws of the relevant place may also allow the matter to be raised with a competent supervisory authority or an appropriate court. The company cooperates with any lawful regulator that asks about its handling of personal information and will not act as though a fair inquiry is an enemy.

International transfers of information

Records are ordinarily held and processed in the United States, where the practising office is located. If a service provider or a legitimate administrative need requires information to pass into another country, the company will make sure the transfer is protected by safeguards recognised in the law of the place from which the information leaves, so that the practical level of care does not drop at the border.

The safeguards commonly in use include standard contractual language that binds the receiving party to the same protective promises, a finding by a competent authority that the destination offers adequate protection, or another lawful basis that stands up to scrutiny. The company does not send personal information to a country simply because it is cheaper there; the deciding question is always whether the protection travels with the information.

Where full technical transfers are unavoidable but unusual, a note is kept of the route so that a later question can be answered about where a record has been. Individuals are welcome to ask where their particular information is held, and the answer will be given without treating the question as an accusation.

Third party links and pages

The pages may, from time to time, carry links to outside web pages such as a professional directory, a standards body or a business register. This Privacy Policy applies only to the pages and services that the company itself operates. When a visitor follows a link away from the company pages, whatever that next page does with a visitor details is governed by that next page own rules and not by this policy.

The company therefore encourages a quick look at the privacy statement of any outside page before handing over personal information there. A link on these pages is not an endorsement of another page collection habits, and the office does not accept responsibility for the practices of sites it merely points toward. Where the company becomes aware that a regularly linked page has changed its reputation for the worse, the link is reconsidered rather than left standing out of inertia.

Changes to this privacy policy

This policy is kept under review and may be updated when the practical working of the office changes, when the law changes, or when a genuine lesson from running the pages shows a better way. Material changes will be dated and described, and the date of the latest change will be shown plainly at the top of the policy so a returning visitor can see at a glance whether anything has moved.

Where a change narrows the promises the company makes, the older and more protective version stays in effect for information already gathered under it, because trust is not something an updated paragraph may quietly dissolve. Where a change is judged significant enough to matter to the people who use the pages, the changed outline will be flagged on the homepage for a reasonable period, rather than being filed away where only a careful reader would notice it.

Contacting the office about privacy

Questions, requests and concerns about this Privacy Policy are welcome and will be answered by a person. Write to order@lsjconsult.lat with privacy in the subject line, or send post to LSJ Consultation, LLC, 1204 W 160 N, Orem - 84057-5108, United States (US). The telephone line, +16604946728, is open Monday to Friday during the office hours stated on the contact page, and privacy matters may be raised there as well.

When you write, mention the page you were reading and the question you brought to it. The office will reply inside two working days with a straight answer, and where the answer is not the one you hoped for it will still be given plainly, with the reasoning attached. Privacy at the company is treated as one of the practiced crafts: it is measured, documented and kept honest by the same standard as the ledgers the office files for its engineering work.

This policy is provided for general information. It does not replace legal advice for a specific situation, and the company is happy to discuss any point raised in it. Effective date of this policy is noted at the masthead. Pages and services of LSJ Consultation, LLC, 1204 W 160 N, Orem - 84057-5108, United States (US).

LSJ Consultation, LLC

1204 W 160 N, Orem - 84057-5108, United States (US). Registered and practising office of the company.

order@lsjconsult.lat  ·  +16604946728

Return to the homepage  ·  Privacy Policy  ·  Terms of Service

Copyright 2026 LSJ Consultation, LLC

Back to the top of this policy