Itaca Technologies

Privacy notice

We collect what you send us through a form and nothing else. This site sets no cookies. We measure traffic in aggregate with a tool that cannot identify you. We do not sell your data, we do not run advertising trackers, and we do not build profiles. That is the whole of it; the rest is the detail you are entitled to.

1. Who we are

Itaca Technologies LLC is a technology architecture and implementation firm. We are the controller of the personal data described here.

Headquarters: 2387 W 68th St #604, Hialeah, FL 33016, United States

Office: 501 E Las Olas Blvd, Suites 200 & 300, Fort Lauderdale, FL 33301, United States

Office: 8 Kitchener Street, Port of Spain, Trinidad & Tobago

Phone: +1 786 568 8890

Privacy, data requests, and anything else about these pages: compliance@itacatech.com

This notice covers itacatech.com. It does not cover work we do under a signed client agreement, where the data terms of that agreement apply, and it does not cover our client portal, which has its own terms.

2. What we collect

When you use the contact form, we receive your name, email address, company, role, phone number, the area you want help with, your timeline, which office you are writing to, the language you are reading in, and your message.

When you apply for a role, we receive your name, email address, phone number, your LinkedIn or portfolio links if you provide them, your message, and your CV file. We also record the date you accepted this notice.

When you load any page, our host records the request in a server log: your IP address, the page requested, the time, your browser and operating system, and the site you came from. This is standard web server behaviour and we do not connect it to form submissions.

When you submit a form, Cloudflare receives your IP address as part of the bot check described in section 5.

What we never collect: we do not use cookies, we do not read anything already stored on your device, we do not fingerprint your browser, and we do not track you across other websites.

3. What we measure, and how

We use Plausible to count traffic. It is configured so that it:

  • sets no cookies and writes nothing to your device
  • does not store your IP address
  • derives a visitor count from a hash of your IP address and browser made with a salt it deletes and replaces every 24 hours, so the hash cannot be reversed into either and stops matching anything the next day
  • records only page views, a small number of interactions (a form opened, a form submitted, a link followed), the site you arrived from, and country, region, city, browser and device type in aggregate
  • keeps no data that can be traced back to a person
  • never combines your visit with data from any other website

Plausible is a European company, and it processes and stores these counts in the European Union, on servers in Germany. We serve its script from our own domain rather than loading it from theirs, so your browser never contacts plausible.io. Our server passes each count on, and your IP address goes with it so that Plausible can produce the hash and look up the country. Plausible discards the address rather than storing it.

We use this to answer questions like which service pages get read and how many people who open the contact form finish it. We cannot use it to find out who you are, and neither can we ask Plausible to.

Because nothing is written to or read from your device, this does not require your consent under the ePrivacy rules. We rely on legitimate interest under the GDPR to process the IP address in transit, and you can object at any time using the contact routes in section 9. There is more detail on the cookies and tracking page.

4. Why we process your data, and on what basis

What we doData usedLegal basis
Reply to your enquiry and prepare a first conversationContact form fieldsSteps prior to a contract, and legitimate interest in responding to you
Send you a copy of what you submittedName, emailLegitimate interest in giving you a record
Assess your application for a roleApplication fields, CVSteps prior to an employment contract, and your consent
Keep the site available and block abuseIP address, server logs, bot checkLegitimate interest in security
Understand how the site is usedAggregate analyticsLegitimate interest in improving the site
Meet legal and accounting obligationsWhatever the obligation requiresLegal obligation

5. Who processes data for us

We do not sell your data, we do not trade it, and we do not share it for anyone else's marketing. We do use service providers who process data on our instructions and cannot use it for their own purposes:

ProviderWhat it doesWhere
Amazon Web ServicesHosting, storage, databases, and email delivery for form submissions and CVsUnited States (Ohio)
CloudflareBot check on the contact and application formsGlobal network
Plausible AnalyticsAggregate traffic measurementEuropean Union (Germany)

We disclose data beyond this only when the law requires it, or to establish or defend a legal claim. If that ever happens and we are permitted to tell you, we will.

6. International transfers

Our hosting, storage, and email run in the United States. If you write to us from the European Economic Area, the United Kingdom, or Trinidad & Tobago, what you send us is transferred to the United States. We rely on the European Commission's standard contractual clauses with those providers, plus encryption in transit and at rest, to protect it, and you can ask us for the detail of those safeguards. Analytics is the exception: Plausible keeps the counts described in section 3 in the European Union, on servers in Germany, not in the United States.

7. How long we keep it

We keep what you send us for as long as it serves the purpose you sent it for, and for as long as the law requires us to keep it. In practice:

  • an enquiry stays while the conversation is live, and afterwards as the context we would want if you came back to us
  • an application stays while the role is open, and afterwards while you might be a fit for something similar
  • server access logs are short-lived operational records, not a history of you
  • analytics holds no personal data at any point, so there is nothing there to keep

We do not keep data because it might be useful one day. When it stops serving the purpose it was collected for, it goes.

You do not have to wait for us to reach that point. Ask us to delete anything we hold about you and we will, using the routes in section 9.

8. Your rights

Wherever you are, you can ask us to:

  • tell you what we hold about you and give you a copy
  • correct anything that is wrong
  • delete it
  • stop processing it, or restrict how we do
  • send it to you or another provider in a portable format
  • object to processing we base on legitimate interest, including our analytics

If you are in the European Economic Area or the United Kingdom, these are your rights under Articles 15 to 22 of the GDPR, and you can complain to your national data protection authority. If you are in Trinidad & Tobago, the Data Protection Act, Chap. 22.04 applies. If you are in Florida, you have rights under the Florida Information Protection Act, Fla. Stat. 501.171, including notification if a breach affects your data.

We never charge for a request and we never make you give a reason. We do not use your data for automated decisions or profiling, so there is nothing to opt out of there.

9. How to exercise your rights

Write to compliance@itacatech.com or call +1 786 568 8890. We answer within 30 days. If your request is complex we will tell you inside those 30 days and explain how much longer we need.

We will ask you to confirm your identity before we act on a request, because handing your data to the wrong person would be the worse failure. We only ask for as much as we need to be sure.

10. How we protect it

Data is encrypted in transit and at rest. Access is limited to the people who need it, and every account that can read an application or a CV requires multi-factor authentication. CVs are stored in a private bucket that is never publicly reachable, and the site itself has no credentials that can read it. We review access on a schedule.

We are a security firm, so we will say the honest thing: no set of controls removes risk entirely. If a breach affects your data we will notify you and the relevant authority within the deadlines the law sets, which is 72 hours under the GDPR.

11. Children

This site is for people doing business with us, and we do not direct it at children. We do not knowingly collect data from anyone under 13, or under 16 in the European Economic Area where local law sets that age. If you believe a child has sent us data, write to compliance@itacatech.com and we will delete it.

12. Other sites

Where we link out, those sites have their own privacy practices and we are not responsible for them.

13. Changes

If we change this notice and the change is material, we will say what changed rather than making you compare versions.

Founded in 2011
No software resale
No vendor commissions