Privacy Policy

Effective Date: 05/10/2026
Business Name: Herman Cybersecurity & Technology Services
Website: www.hermancts.com
Contact: privacy@hermancts.com

Herman Cybersecurity & Technology Services respects your privacy and is committed to handling personal information responsibly. This Privacy Policy explains what information we collect, how we use it, how we protect it, and how you can request access, correction, deletion, or other actions regarding information we may have collected about you.

This Privacy Policy applies to information collected through our website, inquiry forms, booking forms, consultations, service engagements, email communications, and related business interactions.

1. Information We Collect

We may collect the following types of information:

Contact Information
Name, email address, phone number, business name, and other information you provide when contacting us, booking a consultation, or requesting services.

Consultation and Service Information
Information you choose to provide about your technology goals, cybersecurity concerns, devices, accounts, business processes, software tools, website, or other relevant context needed to evaluate your needs and provide services.

Business Information
For small business clients, we may collect information about business operations, technology systems, workflows, vendors, policies, risks, or other information relevant to the requested service.

Website and Usage Information
We may collect basic website usage information through Squarespace or similar tools, such as pages visited, browser type, device type, referral source, approximate location, and interactions with the website.

Payment and Billing Information
We may collect billing contact information, invoice details, payment status, and related transaction records. Payment card or banking information, if used, is generally processed by third-party payment processors and is not intentionally stored by Herman Cybersecurity & Technology Services.

2. Information You Should Not Submit Through Forms

Please DO NOT submit passwords, security codes, sensitive account credentials, full financial account numbers, Social Security numbers, confidential business data, medical information, or other highly sensitive information through website forms, booking forms, or general email.

If sensitive information is needed for a service engagement, we will discuss an appropriate method for handling that information before it is shared.

3. How We Use Information

We use information to:

  • Respond to inquiries and consultation requests

  • Schedule and manage appointments

  • Understand your goals, needs, risks, and concerns

  • Provide cybersecurity and technology consulting services

  • Prepare reports, recommendations, action plans, and related deliverables

  • Communicate with you about services, next steps, billing, or support

  • Improve our website, services, and client experience

  • Maintain business records

  • Comply with legal, accounting, security, or contractual obligations

  • Send optional updates or Client Community communications, if you choose to opt in

We do not sell your personal information.

4. Use of AI Solutions

Herman Cybersecurity & Technology Services may use artificial intelligence solutions to support internal business activities, such as drafting general content, organizing non-sensitive notes, summarizing non-sensitive information, improving service materials, or creating templates.

We DO NOT input passwords, financial account information, payment card information, Social Security numbers, highly sensitive personal information, confidential business data, or other sensitive client information into AI solutions.

When AI solutions are used, they are used to support efficiency and quality, not to replace professional judgment. Recommendations, reports, and client-facing deliverables are developed with AI solutions, not by them, and reviewed before being provided to clients.

5. How We Share Information

We may share limited information with trusted service providers when needed to operate the business, provide services, manage scheduling, process payments, host the website, communicate with clients, or maintain business records.

These providers may include:

  • Website hosting and website analytics providers

  • Microsoft 365, Microsoft Bookings/Forms, email, calendar, and productivity tools

  • Payment processors, invoicing tools, or banking providers

  • Cloud storage or document management providers

  • Professional advisors, such as legal, tax, or accounting professionals

  • Other providers necessary to support requested services

We may also disclose information if required by law, legal process, security investigation, or to protect our rights, clients, systems, or business operations.

We do not share personal information for third-party marketing without your consent.

6. Client Community and Optional Communications

If you choose to participate in the Client Community or receive updates, we may use your contact information to send technology updates, cybersecurity awareness content, resources, event invitations, or related communications.

Participation is optional. You may opt out at any time by using the unsubscribe option, changing your preferences, or contacting us directly.

Client success stories, testimonials, or public-facing references will only be shared with permission.

7. Cookies and Website Analytics

Our website may use cookies or similar technologies through Squarespace or other website tools to support site functionality, improve performance, understand website traffic, and enhance the visitor experience.

You can control cookies through your browser settings. Disabling cookies may affect some website functionality.

8. Data Retention

We retain information for as long as reasonably necessary to provide services, maintain business records, resolve disputes, comply with legal or tax obligations, and support legitimate business purposes.

When information is no longer needed, we will take reasonable steps to delete, de-identify, or securely store it.

9. Security

We use reasonable administrative, technical, and organizational safeguards to protect information from unauthorized access, misuse, loss, or disclosure.

However, no website, email system, cloud service, or digital communication method is completely secure. You should avoid sending highly sensitive information through general forms or standard email unless an appropriate secure method has been discussed.

10. Your Privacy Choices and Data Requests

Even if certain privacy laws do not currently apply to Herman Cybersecurity & Technology Services due to business size or data volume, we aim to provide a clear path for clients and website visitors to make privacy-related requests.

You may contact us to request that we:

  • Confirm whether we have information about you

  • Provide a copy of information you previously submitted

  • Correct inaccurate information

  • Delete information, where appropriate

  • Opt you out of optional communications

  • Explain how your information has been used

  • Restrict or object to certain uses, where applicable

To submit a request, contact:

privacy@hermancts.com

Please include your name, contact information, and a brief description of your request. We may need to verify your identity before fulfilling certain requests.

We will aim to respond within 45 days where reasonably possible. Some requests may be denied or limited if we need to retain information for legal, security, accounting, contractual, dispute-resolution, or legitimate business purposes.

11. Colorado and California Privacy Notice

Herman Cybersecurity & Technology Services is a small business and may not meet the applicability thresholds under the Colorado Privacy Act or the California Consumer Privacy Act/California Privacy Rights Act.

However, residents of Colorado, California, or other states may still contact us using the process above to request access, correction, deletion, or information about how their data is used.

We do not sell personal information. We do not intentionally process personal information for targeted advertising based on sensitive client service information.

12. Children’s Privacy

Our services are intended for adults, families, and businesses. We do not knowingly collect personal information from children under 13 through our website. If you believe a child has provided personal information, please contact us so we can review and delete it where appropriate.

13. Third-Party Links and Services

Our website may link to third-party websites, platforms, tools, booking pages, payment processors, or other services. We are not responsible for the privacy practices, security, or content of third-party services. You should review their privacy policies before providing information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. Material changes may be communicated through the website or other reasonable methods.

15. Contact Us

For privacy questions or data requests, contact:

Herman Cybersecurity & Technology Services
Email: privacy@hermancts.com
Website: www.hermancts.com