Legal
Privacy
What we collect, why, and how to make us delete it. Short, because we collect almost nothing.
Who we are
Hyrax LLC d/b/a Computing America is the entity behind this site and the party you contract with. Where this notice says "we", that is who it means.
This notice covers our public website, computingamerica.com, including all four of its sections: computingamerica.com, computingamerica.com/hardware, computingamerica.com/it and computingamerica.com/cyber. They are one site, operated by one company, and handled the same way throughout. The client portal linked from the footer is a separate signed-in service for existing clients; this notice does not describe it. The portal privacy notice does.
Two different roles, and which one applies to you
We handle personal information in two capacities, and your rights differ depending on which one you are in.
For visitors to this site and people who contact us, we are the controller: we decide what is collected and why, and this notice describes it in full.
For data inside client systems we build, host or manage (the IT division’s managed estates especially), we are a processor acting on that client’s instructions. We do not decide what is collected there and this notice does not govern it; the client’s contract and data processing agreement do. If your employer is our client and you have a question about your own data in a system we run for them, ask them first: they hold the answer and the authority.
What we collect
As controller, only what you give us and what a web server necessarily sees.
- Inquiry form: name, work email, organization, and optionally role, phone, budget range, timeline and the message you write.
- Anti-spam check: submitting the inquiry form runs a challenge that reads your IP address and browser characteristics to tell a person from a script. It is there so that the mailbox stays usable, it sets no tracking cookie, and it is not used to identify you. We also count recent submissions against a one-way fingerprint of your address and IP so that nobody can flood the form; that value cannot be turned back into either.
- Server logs: IP address, user agent, requested URL and timestamp, retained for a short period for security and diagnostics.
- Google Analytics: which pages you viewed and in what order, how long you stayed, which site or search linked you here, the country and approximate city your visit came from, and your device, browser and screen size. Google receives your IP address in order to derive that location and to protect the service, and does not store it. We have not enabled Google Signals, ad personalization or any advertising integration on the property, so nothing collected here is used to target advertising or joined to your Google account.
- Google Analytics sets two first-party cookies, _ga and _ga_4JW6T4PQWW. They hold a random identifier and session state so that three page views in one sitting are counted as one visit and a return next week is counted as a returning reader. They expire after two years, they carry nothing you typed, and because they are set on computingamerica.com, moving between the four sections of the site counts as one visit and not four.
What we do not collect
We do not collect sensitive personal data through this site: no government identifiers, health, biometric, precise geolocation, or data revealing racial or ethnic origin, religion, or sexual orientation. Please do not put any of that in the inquiry form; if you do, we will delete it.
We do not sell personal data and we do not share it for targeted advertising or cross-context behavioral advertising. Under the Texas Data Privacy and Security Act that means the specific notices a seller of sensitive or biometric data must post do not apply to us, and we would have to change this page before they could.
Why we collect it
To reply to you, to assess a possible engagement, and to keep the site working and secure. We do not add you to a mailing list because you filled in a form.
Where the EU or UK GDPR applies to you, our lawful bases are: performing or preparing to enter a contract, for handling your inquiry; our legitimate interest in operating and securing the site and in understanding which pages are read; and legal obligation where one applies. Where we ever rely on consent, we will ask for it plainly and you can withdraw it.
How long we keep it
Inquiries are retained for up to twenty-four months after your last contact with us, so that we can pick up a conversation where it left off, then deleted. Server logs are retained for thirty days.
Records relating to an actual engagement are kept for the life of the engagement and then for seven years, which is what tax and contractual obligations require of us. That is a business record retention period, not a marketing one.
Who else processes it
The following providers process data on our behalf, under contract, for the purposes listed. This is the complete list for this website:
- Vercel: hosting and content delivery for computingamerica.com.
- Google (Google Analytics 4): audience measurement, under Google’s data processing terms. We are the controller and Google is our processor for it; we have not enabled any advertising feature that would make Google an independent controller of it.
- Neon: the Postgres database that stores your inquiry so we can pick the conversation up where it left off. It holds the name, email, organization, phone number and message you submitted.
- Resend: delivery of the email your inquiry becomes.
- Cloudflare: the Turnstile anti-spam challenge on the inquiry form.
- Upstash: the rate-limit counter that stops the form being flooded. It stores a one-way fingerprint and a count, not your message.
Where it goes
We are a United States company and the providers above process data in the United States, except that Google operates a global network and may process measurement data in other countries as well. If you contact us from the EU, the UK or elsewhere, your information will be transferred to the US. Where that transfer needs a safeguard, it is made under the European Commission’s Standard Contractual Clauses (and the UK Addendum) in our agreements with those providers.
Your rights
Write to us at info@computingamerica.com and we will tell you what we hold about you, correct it, delete it, or give you a portable copy. We will not treat you differently for asking.
Texas residents have these rights under the TDPSA, and residents of other states with comprehensive privacy laws (California, Colorado, Connecticut, Virginia and others) have equivalent rights under theirs. People in the EU and UK have them under the GDPR, plus the right to object to processing based on legitimate interests and the right to complain to a supervisory authority.
We respond within forty-five days. If the request is complex we may take a further forty-five days and will tell you why before the first period is up. We may need to verify who you are before we act, and we will only ask for what is necessary to do that.
If we say no
You can appeal. Reply to our decision saying you want it reviewed, and a different person will look at it and respond within sixty days with the outcome and the reasoning. If we still decline, you may complain to the Texas Attorney General at texasattorneygeneral.gov, or to your own state’s regulator or, in the EU or UK, your supervisory authority.
Automated decisions
We do not profile you and we make no automated decision that produces a legal or similarly significant effect. The anti-spam challenge decides whether a form submission looks like a script, and a person reads every inquiry that reaches us.
How we protect it
The site is served over HTTPS only. Access to inquiries is limited to the people who need to answer them. No system is perfectly secure, and we will not claim otherwise; if a breach affects your information we will tell you as promptly as the law requires and as promptly as we can.
Children
This is a business-to-business site. It is not directed at children under sixteen and we do not knowingly collect their information. If you believe a child has sent us something, write to us and we will delete it.
Changes to this notice
If we change what we collect or why, we update this page and move the effective date at the top. Material changes are described here rather than folded in silently.
Contact
Privacy questions, requests and appeals: info@computingamerica.com. The entity responsible is Hyrax LLC d/b/a Computing America.