Privacy Policy
How we collect, use, store and protect information — on this site and in the services we run for clients.
JuvinTech Inc. ("JuvinTech," "we," "our," or "us"), a New York corporation headquartered at 60 East 42nd Street, Suite 4600, New York, NY 10165, is committed to the responsible collection, use, and protection of personal and organizational information. This Privacy Policy applies to our website at www.juvintech.com (the "Site") and to the managed IT, cybersecurity, cloud, AI/fintech application development, and professional services we provide to clients (collectively, "Services").
By using the Site or engaging our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Site.
1. Scope and Applicability
This Privacy Policy governs personal and organizational data collected through the Site and in connection with our Services. It does not govern data processed under a separate Master Service Agreement (MSA) or Data Processing Agreement (DPA) with a client — those agreements control in the event of conflict. JuvinTech acts as a data processor with respect to client data it processes on behalf of clients, and as a data controller with respect to data it collects independently through the Site or its own business operations.
2. Information We Collect
A. Information You Provide Voluntarily
We collect information you submit directly, including through our contact and assessment request forms, email and telephone inquiries, and contractual engagements. This may include: full name; business email address; phone number; company name and title; details about your technology environment, security posture, or project requirements; and payment and billing information where applicable.
B. Automatically Collected Technical Data
When you visit the Site, we automatically collect: IP address and approximate geographic location; browser type, version, and operating system; referring URLs and exit pages; pages viewed and time spent; and device identifiers. We collect this information through standard web server logs and our hosting provider's security and performance records.
C. Client and Managed Services Data
In delivering managed IT, cybersecurity, and professional services, JuvinTech may process technical and operational data relating to client systems, networks, user accounts, endpoints, and security events. This data is processed solely to deliver contracted services and is governed by the applicable MSA, which incorporates confidentiality and data protection obligations consistent with applicable law, including the New York SHIELD Act, Regulation S-P (where applicable), and NIST SP 800-53 security controls.
D. Data from Third-Party Sources
We may receive information from technology partners, referral sources, or publicly available professional directories solely for legitimate business development purposes. We do not purchase data from data brokers.
3. How We Use Your Information
JuvinTech uses collected information to: respond to inquiries, provide assessments, and deliver contracted Services; communicate service-related updates, renewal notices, and relevant industry information; conduct security monitoring, incident detection, and response activities on behalf of managed services clients; process billing and maintain business records; improve the Site and our service offerings through aggregated, de-identified analytics; comply with applicable legal obligations including subpoenas, regulatory examinations, and court orders; and defend against legal claims and enforce our agreements.
We do not sell personal information to third parties. We do not use personal information for third-party behavioral advertising without explicit consent.
4. Legal Bases for Processing (New York and Federal Law)
JuvinTech processes personal information on the following bases: performance of a contract (delivery of Services); compliance with legal obligations (including NY SHIELD Act, Reg S-P, NYDFS 23 NYCRR 500 where applicable, and federal data security requirements); legitimate business interests (improving services, security monitoring, fraud prevention); and consent, where expressly obtained.
5. Disclosure of Information
JuvinTech may share information in the following circumstances:
Service Providers and Subprocessors: We engage vetted third-party vendors — including cloud infrastructure providers (Microsoft Azure, Amazon Web Services), remote monitoring platforms (N-able, Kaseya), security operations (Arctic Wolf), and productivity platforms (Microsoft 365) — under written agreements that require equivalent data protection standards. These vendors process data only as directed by JuvinTech and are prohibited from using it for their own purposes.
Regulatory and Legal Compliance: We may disclose information to law enforcement agencies, regulatory bodies (including the SEC, FINRA, or NYDFS), or courts where required by applicable law, subpoena, or regulatory examination — including disclosures required under Regulation S-P's breach notification provisions.
Business Transfers: In the event of a merger, acquisition, sale of assets, or reorganization, personal information may be transferred as a business asset. Affected individuals will be notified as required by law.
Professional Advisors: We may share information with our legal counsel, accountants, and insurers under binding confidentiality obligations.
With Your Consent: In any other circumstance, only with your express prior consent.
6. Cookies and Tracking Technologies
The Site does not use analytics cookies, advertising cookies, or cross-site tracking technologies. We run no third-party measurement, advertising, or behavioral profiling scripts, and we do not sell personal information or share it for cross-context behavioral advertising.
The Site loads two components provided by Cloudflare, our hosting and security provider:
Cloudflare Turnstile, on our contact form, which distinguishes human visitors from automated submissions. Cloudflare may set cookies that are strictly necessary to deliver and secure the Site, as described in Cloudflare's Turnstile privacy policy.
Cloudflare Web Analytics, which records aggregate page views, referring sites, and country-level location so we can see which pages are useful. It sets no cookies, stores nothing on your device, assigns no persistent identifier, and does not follow you across other websites. We cannot identify an individual visitor from it.
You may configure your browser to refuse all cookies or to alert you when cookies are set. Blocking them may prevent the contact form's security check from completing.
Global Privacy Control. Several state privacy laws allow you to signal an opt-out of the sale or sharing of personal information through a browser setting or extension, most commonly Global Privacy Control (GPC). We recognize these signals as a valid expression of that choice.
In practice there is nothing for such a signal to disable on this Site. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising or automated profiling. Should any of those practices change, we will update this policy and honor GPC signals at the point of collection before the change takes effect.
7. Data Security
JuvinTech maintains a written Information Security Program (ISP) aligned to the NIST Cybersecurity Framework (CSF 2.0) and the requirements of the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb). Our security controls include: AES-256 encryption for data at rest; TLS 1.2/1.3 for data in transit; multi-factor authentication across all administrative systems; role-based access controls and least-privilege principles; continuous endpoint detection and response (EDR); and 24×7 security operations monitoring via Arctic Wolf MDR.
In the event of a security breach involving personal information, JuvinTech will notify affected individuals and relevant government agencies as required by the NY SHIELD Act, and, where applicable, within 72 hours as required under Regulation S-P (as amended effective 2024). Notification will be provided via email and, where required, via written notice or substitute notice procedures.
8. Data Retention
We retain personal information only as long as necessary to fulfill the purposes described in this Policy, maintain business records, comply with legal obligations (including applicable statutes of limitations), and resolve disputes. Client service data retention periods are specified in the applicable MSA. When information is no longer required, we securely delete or anonymize it using industry-standard methods. Financial records are retained for a minimum of seven (7) years in compliance with applicable tax and accounting requirements.
9. Your Rights
Depending on applicable law, you may have rights including the right to: access personal information we hold about you; request correction of inaccurate or incomplete information; request deletion of your personal information, subject to our legal retention obligations; object to or restrict certain processing activities; receive a portable copy of your data in machine-readable format; and withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at privacy@juvintech.com or by mail at the address below. We will respond within 30 days. We may require identity verification before fulfilling requests.
New York Residents: JuvinTech maintains a written information security program that includes reasonable administrative, technical, and physical safeguards appropriate to the size and complexity of our business and the nature of the information we handle, as required by the NY SHIELD Act.
Financial Services Clients: Where JuvinTech provides services to SEC-registered investment advisers, broker-dealers, or other Regulation S-P covered entities, the applicable MSA governs data handling obligations. JuvinTech provides annual service provider certifications upon request.
10. Children's Privacy
The Site and our Services are directed exclusively to business clients and their personnel. We do not knowingly collect personal information from individuals under the age of 18. If we become aware of such collection, we will promptly delete the information.
11. Third-Party Links
The Site may contain links to third-party websites, tools, or platforms. JuvinTech is not responsible for the privacy practices, content, or security of those sites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Policy
JuvinTech reserves the right to update this Privacy Policy at any time. Material changes will be communicated by posting an updated version to this page with a revised effective date and, where required by law, by direct notification to affected individuals. Continued use of the Site or Services following posting of changes constitutes acceptance of the updated Policy.
13. Contact and Data Privacy Inquiries
For questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact:
JuvinTech Inc. — Privacy Officer
60 East 42nd Street, Suite 4600
New York, NY 10165
Email: privacy@juvintech.com
Phone: +1 (888) 590-2152
Response time: within 30 days of receipt