Privacy notice
We collect what you send us through a form and nothing else. This site sets no cookies. We measure traffic in aggregate with a tool that cannot identify you. We do not sell your data, we do not run advertising trackers, and we do not build profiles. That is the whole of it; the rest is the detail you are entitled to.
1. Who we are
Itaca Technologies LLC is a technology architecture and implementation firm. We are the controller of the personal data described here.
Headquarters: 2387 W 68th St #604, Hialeah, FL 33016, United States
Office: 501 E Las Olas Blvd, Suites 200 & 300, Fort Lauderdale, FL 33301, United States
Office: 8 Kitchener Street, Port of Spain, Trinidad & Tobago
Phone: +1 786 568 8890
Privacy, data requests, and anything else about these pages: compliance@itacatech.com
This notice covers itacatech.com. It does not cover work we do under a signed client agreement, where the data terms of that agreement apply, and it does not cover our client portal, which has its own terms.
2. What we collect
When you use the contact form, we receive your name, email address, company, role, phone number, the area you want help with, your timeline, which office you are writing to, the language you are reading in, and your message.
When you apply for a role, we receive your name, email address, phone number, your LinkedIn or portfolio links if you provide them, your message, and your CV file. We also record the date you accepted this notice.
When you load any page, our host records the request in a server log: your IP address, the page requested, the time, your browser and operating system, and the site you came from. This is standard web server behaviour and we do not connect it to form submissions.
When you submit a form, Cloudflare receives your IP address as part of the bot check described in section 5.
What we never collect: we do not use cookies, we do not read anything already stored on your device, we do not fingerprint your browser, and we do not track you across other websites.
3. What we measure, and how
We use Plausible to count traffic. It is configured so that it:
- sets no cookies and writes nothing to your device
- does not store your IP address
- derives a visitor count from a hash of your IP address and browser made with a salt it deletes and replaces every 24 hours, so the hash cannot be reversed into either and stops matching anything the next day
- records only page views, a small number of interactions (a form opened, a form submitted, a link followed), the site you arrived from, and country, region, city, browser and device type in aggregate
- keeps no data that can be traced back to a person
- never combines your visit with data from any other website
Plausible is a European company, and it processes and stores these counts in the European Union, on servers in Germany. We serve its script from our own domain rather than loading it from theirs, so your browser never contacts plausible.io. Our server passes each count on, and your IP address goes with it so that Plausible can produce the hash and look up the country. Plausible discards the address rather than storing it.
We use this to answer questions like which service pages get read and how many people who open the contact form finish it. We cannot use it to find out who you are, and neither can we ask Plausible to.
Because nothing is written to or read from your device, this does not require your consent under the ePrivacy rules. We rely on legitimate interest under the GDPR to process the IP address in transit, and you can object at any time using the contact routes in section 9. There is more detail on the cookies and tracking page.
4. Why we process your data, and on what basis
| What we do | Data used | Legal basis |
|---|---|---|
| Reply to your enquiry and prepare a first conversation | Contact form fields | Steps prior to a contract, and legitimate interest in responding to you |
| Send you a copy of what you submitted | Name, email | Legitimate interest in giving you a record |
| Assess your application for a role | Application fields, CV | Steps prior to an employment contract, and your consent |
| Keep the site available and block abuse | IP address, server logs, bot check | Legitimate interest in security |
| Understand how the site is used | Aggregate analytics | Legitimate interest in improving the site |
| Meet legal and accounting obligations | Whatever the obligation requires | Legal obligation |
5. Who processes data for us
We do not sell your data, we do not trade it, and we do not share it for anyone else's marketing. We do use service providers who process data on our instructions and cannot use it for their own purposes:
| Provider | What it does | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, databases, and email delivery for form submissions and CVs | United States (Ohio) |
| Cloudflare | Bot check on the contact and application forms | Global network |
| Plausible Analytics | Aggregate traffic measurement | European Union (Germany) |
We disclose data beyond this only when the law requires it, or to establish or defend a legal claim. If that ever happens and we are permitted to tell you, we will.
6. International transfers
Our hosting, storage, and email run in the United States. If you write to us from the European Economic Area, the United Kingdom, or Trinidad & Tobago, what you send us is transferred to the United States. We rely on the European Commission's standard contractual clauses with those providers, plus encryption in transit and at rest, to protect it, and you can ask us for the detail of those safeguards. Analytics is the exception: Plausible keeps the counts described in section 3 in the European Union, on servers in Germany, not in the United States.
7. How long we keep it
We keep what you send us for as long as it serves the purpose you sent it for, and for as long as the law requires us to keep it. In practice:
- an enquiry stays while the conversation is live, and afterwards as the context we would want if you came back to us
- an application stays while the role is open, and afterwards while you might be a fit for something similar
- server access logs are short-lived operational records, not a history of you
- analytics holds no personal data at any point, so there is nothing there to keep
We do not keep data because it might be useful one day. When it stops serving the purpose it was collected for, it goes.
You do not have to wait for us to reach that point. Ask us to delete anything we hold about you and we will, using the routes in section 9.
8. Your rights
Wherever you are, you can ask us to:
- tell you what we hold about you and give you a copy
- correct anything that is wrong
- delete it
- stop processing it, or restrict how we do
- send it to you or another provider in a portable format
- object to processing we base on legitimate interest, including our analytics
If you are in the European Economic Area or the United Kingdom, these are your rights under Articles 15 to 22 of the GDPR, and you can complain to your national data protection authority. If you are in Trinidad & Tobago, the Data Protection Act, Chap. 22.04 applies. If you are in Florida, you have rights under the Florida Information Protection Act, Fla. Stat. 501.171, including notification if a breach affects your data.
We never charge for a request and we never make you give a reason. We do not use your data for automated decisions or profiling, so there is nothing to opt out of there.
9. How to exercise your rights
Write to compliance@itacatech.com or call +1 786 568 8890. We answer within 30 days. If your request is complex we will tell you inside those 30 days and explain how much longer we need.
We will ask you to confirm your identity before we act on a request, because handing your data to the wrong person would be the worse failure. We only ask for as much as we need to be sure.
10. How we protect it
Data is encrypted in transit and at rest. Access is limited to the people who need it, and every account that can read an application or a CV requires multi-factor authentication. CVs are stored in a private bucket that is never publicly reachable, and the site itself has no credentials that can read it. We review access on a schedule.
We are a security firm, so we will say the honest thing: no set of controls removes risk entirely. If a breach affects your data we will notify you and the relevant authority within the deadlines the law sets, which is 72 hours under the GDPR.
11. Children
This site is for people doing business with us, and we do not direct it at children. We do not knowingly collect data from anyone under 13, or under 16 in the European Economic Area where local law sets that age. If you believe a child has sent us data, write to compliance@itacatech.com and we will delete it.
12. Other sites
Where we link out, those sites have their own privacy practices and we are not responsible for them.
13. Changes
If we change this notice and the change is material, we will say what changed rather than making you compare versions.