Introduction
BLUFFDALE CHILD CARE HOLDINGS, LLC respects the privacy of every person who visits this website, contacts the practice, or engages its computer systems design and technology consulting services. This Privacy Policy explains what information is collected, why it is collected, how it is used, how it is protected, and what choices are available to the people whose information is held. The policy is published by Bluffdale Care, the trading identity used by BLUFFDALE CHILD CARE HOLDINGS, LLC, a company operating from 4289 S El Camino St, Taylorsville - 84129-5506, United States (US). By using this website or contacting the practice, a visitor confirms that the practices described below are understood and accepted.
1. Scope of This Policy
This Privacy Policy applies to the website published at bluffdalecare.buzz and to the business operations of BLUFFDALE CHILD CARE HOLDINGS, LLC, including enquiry handling, contract administration, billing, support, and the professional technology services the firm provides. The policy does not apply to websites operated by other organisations, even where those websites are linked from this one, and it does not govern the internal privacy practices of client organisations that receive services from the firm.
Where the firm provides technology services under a written agreement, the handling of information inside the delivered systems is governed primarily by that agreement. This policy operates alongside such agreements and describes the general standards the firm applies to its own operations. In the event of a direct conflict between a signed client agreement and this policy, the signed agreement takes precedence for the work it covers, and this policy continues to govern the general business conduct of the firm.
This policy is written to be readable by people who are not lawyers. Where a term of art is unavoidable, it is explained in ordinary language. The firm believes that privacy notices should be understood by the people they describe, and it welcomes questions about any part of this document.
2. Information We Collect
The firm collects information that visitors and clients choose to provide, together with a limited amount of technical information that is generated automatically when a website is used. The categories of information are set out below.
Information Provided Directly
When a person completes the contact form, sends an email, or telephones the practice, the firm receives the details supplied in that communication. This commonly includes a name, an email address, a telephone number, the name of an organisation, the subject of the enquiry, and the content of the message. Where a person is a client, the firm also holds the information required to administer the relationship, such as billing contacts, contract references, service scope, and correspondence history.
Information Generated Automatically
When this website is visited, the web server records ordinary technical information, including the internet protocol address, the browser type, the operating system, the pages requested, and the time of each request. This information is used to keep the website secure, to diagnose faults, and to understand in aggregate which parts of the site are useful. It is not used to build advertising profiles and it is not combined with information from other sources to identify individual visitors.
Information From Business Interactions
During a professional engagement, the firm may receive technical configuration details, architecture descriptions, and system documentation belonging to a client. Such material is handled as confidential business information under the relevant agreement and is not treated as personal information about website visitors. Where that material happens to contain personal data, it is processed only for the purpose of delivering the agreed services.
3. How Information Is Collected
The firm collects information through a small number of clearly defined channels, and it does not gather personal information by stealth.
- Through the contact form on this website, which prepares an email in the visitor browser and sends it to the practice.
- Through email messages sent directly to the published practice address.
- Through telephone calls made to the published practice number.
- Through written correspondence and signed agreements exchanged with clients.
- Through ordinary server logs generated whenever a page of this website is requested.
- Through support tickets and status updates created during a managed service engagement.
Each channel exists for a clear operational reason. The contact form and published contact details allow prospective clients to begin a conversation. Contracts and correspondence allow the firm to deliver and administer agreed work. Server logs allow the website to remain available and secure. No channel is used to collect information for its own sake.
4. Lawful Bases for Processing
Where the law requires a lawful basis for handling personal information, the firm relies on one or more of the following grounds. The basis that applies depends on the nature of the interaction and the purpose being served.
Consent
When a person submits an enquiry, that person consents to the firm using the supplied details to respond. Consent can be withdrawn at any time by contacting the practice, though withdrawal does not affect processing carried out before the request.
Contract
Where a person or organisation engages the firm under a written agreement, the firm processes the necessary information to negotiate, perform, and administer that agreement. This includes billing, scheduling, and the delivery of the agreed services.
Legitimate Interests
The firm has a legitimate interest in operating a secure and functional website, protecting its systems from misuse, maintaining accurate business records, and communicating with existing clients about work in progress. Any such processing is balanced against the rights and interests of the individuals concerned.
Legal Obligation
The firm may process information where necessary to comply with applicable law, including tax, accounting, and record keeping requirements, or to respond to a lawful request from a public authority.
5. How Information Is Used
Information collected by the firm is used only for the purposes for which it was gathered and for closely related purposes that a reasonable person would expect. The principal uses are described below.
- To respond to enquiries and provide requested information about services.
- To prepare proposals, statements of work, and contractual documents.
- To deliver, support, and improve the professional services the firm provides.
- To administer billing, invoicing, and financial record keeping.
- To maintain the security, availability, and integrity of websites and systems.
- To comply with legal, regulatory, and professional obligations.
- To communicate about scheduled reviews, maintenance windows, and service changes.
The firm does not sell personal information. It does not rent contact lists. It does not use personal information to train advertising systems, and it does not share personal information with data brokers. Where information is used for a purpose not described here, the firm seeks consent first unless the law provides another lawful basis and the new purpose is compatible with the original one.
6. Data Held Inside Client Systems
Much of the technical work performed by the firm involves systems that belong to clients and that contain data about the client customers, employees, or operations. The firm treats that data according to a strict separation of roles.
In most engagements the client remains the owner and controller of the data held inside its systems, and the firm acts as a processor or service provider that accesses the data solely to deliver the agreed services. Access is limited to the engineers and specialists who need it to complete a defined task, is granted for a limited period, and is recorded. Where privileged access is required for administrative work, it is exercised through controlled channels and reviewed after use.
The firm does not use client data for its own commercial purposes, does not disclose it to third parties except as required to deliver the service or as the law demands, and does not retain it beyond the period set out in the applicable agreement. When an engagement ends, client data is returned or securely destroyed according to the agreed exit plan, and written confirmation is provided on request.
Where a client system is hosted in a cloud environment, the firm configures encryption, access controls, and backup routines so that the client retains meaningful control over its own information. The firm documents these configurations so that the client can verify them independently.
9. Service Providers and Subprocessors
The firm works with a small number of carefully selected service providers. Each provider is assessed before onboarding and reviewed periodically afterwards. The assessment considers the sensitivity of the information handled, the security controls in place, the provider location, and the provider own privacy commitments.
Written agreements with providers require them to process information only on documented instructions, to apply appropriate technical and organisational safeguards, to assist with requests from individuals, to notify the firm of any incident without undue delay, and to delete or return information when the relationship ends. Where a provider engages a subcontractor, the same obligations flow down to that subcontractor.
A current list of the categories of providers used by the firm is available to clients on request, and clients with specific requirements about provider location or subcontracting are encouraged to raise those requirements during contract negotiation so that they can be addressed in writing.
10. Data Retention
Information is retained only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. The specific periods depend on the type of information and the context in which it is held.
- Enquiries that do not lead to an engagement are typically removed within twelve months of the last contact.
- Client contract records are retained for the duration of the engagement and for a further period required by tax and accounting rules.
- Support tickets and incident records are kept long enough to identify recurring problems and to demonstrate service performance, then archived or deleted.
- Server logs are retained for a short operational window and are then discarded.
- Information subject to a legal hold is retained until the hold is lifted.
When a retention period ends, information is deleted or irreversibly anonymised in a manner appropriate to the medium on which it is stored. Backups are handled on a rolling schedule, and information deleted from live systems is removed from backups as those backups expire.
11. How Information Is Protected
The firm applies technical and organisational safeguards designed to protect information against accidental loss and against unauthorised access, alteration, or disclosure. Because the firm is itself a computer systems practice, these controls are treated as a core professional responsibility rather than an administrative afterthought.
Technical Controls
Information in transit is protected with modern encryption, and information at rest is encrypted where the storage platform supports it. Access to systems is governed by individual accounts and the principle of least privilege, with multi factor authentication required for administrative access. Networks are segmented, endpoints are kept patched, and backups are scheduled and tested through periodic restore rehearsals.
Organisational Controls
Personnel receive privacy and security training, work under written confidentiality obligations, and follow documented procedures for handling incidents. Access rights are reviewed on a regular schedule and revoked promptly when a role changes or a person leaves. Physical records are stored in controlled locations and disposed of securely.
Incident Response
The firm maintains an incident response procedure that covers detection, containment, investigation, notification, and remediation. Where a personal data breach presents a risk to individuals, affected parties and the relevant authorities are notified as required by applicable law, and a written account of the incident and the response is prepared.
12. International Transfers
The firm is based in the United States and primarily processes information within that country. Some service providers used by the firm may store or process information in other jurisdictions. Where information is transferred across a border, the firm takes steps to ensure that the protection it receives remains consistent with the commitments made in this policy.
These steps may include contractual clauses that require the recipient to apply equivalent safeguards, an assessment of the legal environment in the destination country, and technical measures such as encryption that reduce the sensitivity of information in transit. Where a client has specific requirements about the location of its data, those requirements are documented in the applicable agreement and respected in the configuration of the delivered systems.
13. Privacy Rights and Choices
Depending on where a person lives, the law may grant specific rights over personal information. The firm honours these rights for all individuals it deals with, regardless of location, because the same standards should apply to everyone.
Right to Know and Access
A person may ask what information the firm holds about them, why it is held, and with whom it has been shared. The firm responds with a clear written explanation and, where appropriate, a copy of the information.
Right to Correction
A person may ask the firm to correct information that is inaccurate or incomplete. Where a correction is made, any party that received the original information is informed where practicable.
Right to Deletion
A person may ask the firm to delete information that is no longer necessary, subject to legal and contractual retention requirements. Where deletion cannot be completed immediately because of an active legal obligation, the person is told why and when the information will be removed.
Right to Object and Restrict
A person may object to certain processing activities or ask that processing be restricted while a concern is investigated. The firm stops or limits the processing unless it has compelling grounds that override the request.
Right to Portability
Where processing is based on consent or contract and is carried out by automated means, a person may request a copy of the information in a structured, commonly used, machine readable format.
Right to Withdraw Consent
Where processing relies on consent, that consent may be withdrawn at any time. Withdrawal is as simple as giving the consent in the first place, and it does not affect the lawfulness of processing that already took place.
To exercise any of these rights, contact the practice using the details at the end of this policy. Requests are acknowledged promptly and answered within the period required by applicable law. The firm does not charge a fee for a reasonable request and does not discriminate against anyone who exercises a privacy right.
14. Privacy for Children
This website and the professional services described on it are intended for businesses, organisations, and adult professionals. The firm does not knowingly collect personal information from children through this website, and the website is not designed to appeal to children.
Despite the corporate name under which the firm trades, the firm does not operate child care services, does not solicit information from minors, and does not maintain accounts for minors. If a parent or guardian believes that a child has submitted personal information through this website, that person should contact the practice immediately. The firm will verify the concern and delete the information promptly unless a legal obligation requires it to be retained.
Where a client project happens to involve systems that serve young people, the firm works within the client own compliance framework and applies additional safeguards, including data minimisation and strict access limitation, so that the interests of the young people concerned are protected throughout the engagement.
15. California Privacy Notice
Residents of California have specific rights under state privacy law. This section summarises those rights and explains how they apply to the firm.
The categories of personal information the firm has collected in the past twelve months include identifiers such as a name and email address, commercial information such as service history, internet activity such as server log entries, and professional information such as an employer name and job role. This information is collected for the business purposes described earlier in this policy and is disclosed only to service providers bound by written confidentiality terms.
The firm does not sell personal information and does not share it for cross context behavioural advertising. A California resident may request to know what information is held, may request its deletion, may request correction, and may designate an authorised agent to make a request on that person behalf. Requests are verified before information is released, and the firm will not discriminate against anyone who exercises these rights.
16. Do Not Track Signals
Some browsers can send a signal indicating that a visitor prefers not to be tracked across websites. Because this website does not track visitors across other websites and does not use advertising technology, there is no cross site tracking to disable. The firm respects browser based signals and does not attempt to circumvent them.
If the firm introduces analytics in the future, the analytics will be configured to honour browser privacy signals and will collect the minimum data needed to understand whether the published pages are useful. Visitors will be told about the change through an update to this policy.
17. Third Party Links
This website may contain links to external websites, documents, or resources that are operated by other organisations. The firm provides such links for convenience and does not control the privacy practices of the destinations.
A person who follows an external link leaves this website and becomes subject to the privacy policy of the destination. The firm encourages visitors to read the privacy notice of any site they visit before providing personal information. The firm is not responsible for the content, security, or privacy practices of external websites, and a link does not imply endorsement of the destination.
18. Changes to This Policy
The firm reviews this Privacy Policy on a regular schedule and updates it when practices, technology, or legal requirements change. When an update is made, the effective date shown with the policy is revised and a short summary of the change is prepared for the firm internal records.
Where a change is material, the firm takes reasonable steps to bring it to the attention of people who may be affected, for example by publishing a prominent notice on this website or by contacting active clients directly. Continued use of the website after an update takes effect indicates that the revised policy is understood and accepted. A person who does not agree with a revised policy may choose to stop using the website and may contact the firm to discuss any information already held.
19. How to Contact the Practice
Questions, requests, and concerns about privacy may be directed to the firm using any of the channels below. The firm welcomes the opportunity to resolve any concern directly and promptly.
Privacy Contact
BLUFFDALE CHILD CARE HOLDINGS, LLC
4289 S El Camino St, Taylorsville - 84129-5506, United States (US)
Email: accounts@bluffdalecare.buzz
Telephone: +17863058297
Written requests are acknowledged on receipt and answered within the timeframe required by applicable law. Where a request relates to information held inside a client system operated under a service agreement, the firm may direct the request to the client organisation, because that organisation is the controller of the information and the firm acts on its instructions.
This Privacy Policy is effective from the date shown below and remains in force until a revised version replaces it.