Legal
Privacy
What we collect, why, and how to make us delete it. Short, because we collect very little.
Who we are
Hyrax LLC d/b/a Computing America is the entity behind this site and the party you contract with. Where this notice says "we", that is who it means.
This notice covers our public websites: computingamerica.com, hardware.computingamerica.com, it.computingamerica.com and cyber.computingamerica.com. All four are operated by the same company and handled the same way.
Two different roles, and which one applies to you
We handle personal information in two capacities, and your rights differ depending on which one you are in.
For visitors to this site and people who contact us, we are the controller: we decide what is collected and why, and this notice describes it in full.
For data inside client systems we build, host or manage — the IT division's managed estates especially — we are a processor acting on that client's instructions. We do not decide what is collected there and this notice does not govern it; the client's contract and data processing agreement do. If your employer is our client and you have a question about your own data in a system we run for them, ask them first: they hold the answer and the authority.
What we collect
As controller, only what you give us and what a web server necessarily sees.
- Inquiry form: name, work email, organization, and optionally role, phone, budget range, timeline and the message you write.
- Job applications sent by email: whatever you choose to include.
- Anti-spam check: submitting the inquiry form runs a challenge that reads your IP address and browser characteristics to tell a person from a script. It is there so that the mailbox stays usable, it sets no tracking cookie, and it is not used to identify you. We also count recent submissions against a one-way fingerprint of your address and IP so that nobody can flood the form; that value cannot be turned back into either.
- Server logs: IP address, user agent, requested URL and timestamp, retained for a short period for security and diagnostics.
- Analytics: none. This deployment loads no analytics or performance-measurement script at all, so beyond the server logs above, visiting a page records nothing about you anywhere.
What we do not collect
We do not collect sensitive personal data through this site — no government identifiers, health, biometric, precise geolocation, or data revealing racial or ethnic origin, religion, or sexual orientation. Please do not put any of that in the inquiry form; if you do, we will delete it.
We do not sell personal data and we do not share it for targeted advertising or cross-context behavioural advertising. Under the Texas Data Privacy and Security Act that means the specific notices a seller of sensitive or biometric data must post do not apply to us, and we would have to change this page before they could.
Why we collect it
To reply to you, to assess a possible engagement, to consider an application, and to keep the site working and secure. We do not add you to a mailing list because you filled in a form.
Where the EU or UK GDPR applies to you, our lawful bases are: performing or preparing to enter a contract, for handling your inquiry; our legitimate interest in operating and securing the site and in understanding which pages are read; and legal obligation where one applies. Where we ever rely on consent, we will ask for it plainly and you can withdraw it.
How long we keep it
Inquiries are retained for up to twenty-four months after your last contact with us, so that we can pick up a conversation where it left off, then deleted. Applications are retained for twelve months unless you ask us to keep them longer. Server logs are retained for thirty days.
Records relating to an actual engagement are kept for the life of the engagement and then for seven years, which is what tax, professional-liability and contractual obligations require of us. That is a business record retention period, not a marketing one.
Who else processes it
The following providers process data on our behalf, under contract, for the purposes listed. This is the complete list for this website:
- Vercel — hosting and content delivery for all four sites.
- Resend — delivery of the email your inquiry becomes.
- Cloudflare — the Turnstile anti-spam challenge on the inquiry form.
- Upstash — the rate-limit counter that stops the form being flooded. It stores a one-way fingerprint and a count, not your message.
Where it goes
We are a United States company and the providers above process data in the United States. If you contact us from the EU, the UK or elsewhere, your information will be transferred to the US. Where that transfer needs a safeguard, it is made under the European Commission's Standard Contractual Clauses (and the UK Addendum) in our agreements with those providers.
Your rights
Write to us at info@computingamerica.com and we will tell you what we hold about you, correct it, delete it, or give you a portable copy. We will not treat you differently for asking.
Texas residents have these rights under the TDPSA, and residents of other states with comprehensive privacy laws — California, Colorado, Connecticut, Virginia and others — have equivalent rights under theirs. People in the EU and UK have them under the GDPR, plus the right to object to processing based on legitimate interests and the right to complain to a supervisory authority.
We respond within forty-five days. If the request is complex we may take one further forty-five days and will tell you why before the first period is up. We may need to verify who you are before we act, and we will only ask for what is necessary to do that.
If we say no
You can appeal. Reply to our decision saying you want it reviewed, and a different person will look at it and respond within sixty days with the outcome and the reasoning. If we still decline, you may complain to the Texas Attorney General at texasattorneygeneral.gov, or to your own state's regulator or, in the EU or UK, your supervisory authority.
Automated decisions
We do not profile you and we make no automated decision that produces a legal or similarly significant effect. The anti-spam challenge decides whether a form submission looks like a script, and a person reads every inquiry that reaches us.
Cookies
This site sets no advertising or cross-site tracking cookies, and our analytics are cookieless. See the cookie policy for the detail.
How we protect it
The site is served over HTTPS only. Access to inquiries is limited to the people who need to answer them. No system is perfectly secure, and we will not claim otherwise; if a breach affects your information we will tell you as promptly as the law requires and as promptly as we can.
Children
This is a business-to-business site. It is not directed at children under sixteen and we do not knowingly collect their information. If you believe a child has sent us something, write to us and we will delete it.
Changes to this notice
If we change what we collect or why, we update this page and move the effective date at the top. Material changes are described here rather than folded in silently.
Contact
Privacy questions, requests and appeals: info@computingamerica.com. The entity responsible is Hyrax LLC d/b/a Computing America.