Keepoint.
Home/Legal/Privacy

Privacy policy.

Effective Sep 21, 2026 Version 2.1 Read ~6 min

Plain-language summary. We collect what you send us through the consultation form and what you tell us while we work together. We use it to respond to you and do the work you hired us for. We don't sell it, we don't advertise with it, and we run no cookies or cross-site trackers on this site — just a cookieless visit counter.

Our pledge

We will never sell your personal information. Period.

01Who We Are

Keepoint Solutions LLC ("Keepoint," "we," "us") is a California limited liability company providing independent IT consulting services — cloud migration, security and access reviews, backup and recovery, networks, and related advisory work, delivered remotely. This policy explains what we do with personal information collected through this website and in the course of our consulting work.

It applies to visitors to keepointsolutions.com, people who submit a consultation request, and our clients.

02Information We Collect

We collect three kinds of information, and no more than we need:

  • What you send us through the consultation form. Your name and email address, and — if you choose to provide them — your phone number, organization name, organization size, a description of what you need help with, and your preferred contact time.
  • What you share with us during an engagement. Whatever you tell us or show us while scoping and doing the work: system inventories, network layouts, cloud tenant details, vendor relationships, invoices, and the like. See Section 4 for how we handle access to your systems.
  • Basic server logs. Our web server records the requested URL, timestamp, IP address, and browser user-agent for every request. This is standard operational logging used for security and troubleshooting, not for building a profile of you.

We also use cookieless, aggregate website analytics (Section 7) to count visits. We do not run advertising pixels or cross-site trackers.

03How We Use It

We use the information we collect to:

  • Respond to your consultation request and arrange a conversation.
  • Prepare a written scope and quote for work you're considering.
  • Perform the work you engage us for, and communicate with you about it.
  • Send invoices and keep the accounting and tax records the law requires us to keep.
  • Protect our systems against abuse, spam, and fraud.
  • Comply with legal obligations and respond to lawful requests.

04Access During an Engagement

Consulting work requires access to systems that contain other people's information — your employees' email, your customers' records, files on your servers and in your cloud tenants. We take that seriously.

  • We ask for the least access that will do the job, and we ask you to grant it rather than helping ourselves to broader permissions.
  • We do not copy, export, or retain your data beyond what is strictly necessary to complete the agreed work.
  • We do not take custody of your data. Migrations land in cloud accounts you own, and backups we configure run under your subscriptions, not ours.
  • Anything we see incidentally stays confidential. We treat it as your confidential information and do not disclose or use it for any purpose other than the engagement.
  • Access ends when the engagement ends. We will tell you which credentials and permissions to revoke, and we ask that you revoke them.

If your organization is subject to sector-specific rules — HIPAA, PCI-DSS, CJIS, FERPA, or similar — tell us before work begins. Those obligations may require a separate written agreement, and we would rather establish that up front than discover it later.

05Who We Share It With

We do not sell your personal information. We share it only where necessary to operate:

  • Hosting and infrastructure. This website and its lead records run on Google Cloud Platform. Google processes that data on our behalf under its data processing terms.
  • Website analytics. Cloudflare Web Analytics receives basic request details (page address, referrer, browser and device type, IP address) to produce aggregate visit statistics for us. It sets no cookies.
  • Email delivery. Our transactional email provider transmits the confirmation you receive after submitting the form, and the notification we receive.
  • Invoicing and banking. Invoices are issued through our business banking provider, which processes the billing details necessary to send an invoice and receive payment.
  • Legal compliance. When required by valid legal process, or to protect the rights, safety, or property of Keepoint, our clients, or the public.
  • Business transfer. If Keepoint is ever merged, acquired, or sells its assets, information may transfer as part of that transaction, subject to the protections in this policy.

06What We Don't Do

Some commitments are easier to state as negatives:

  • We do not sell, rent, or trade your personal information to anyone.
  • We do not use your information for advertising or behavioral profiling.
  • We do not provide your information to train third-party artificial intelligence models.
  • We do not install monitoring software on your devices as part of this website or a consultation. If an engagement calls for a tool that reports system data, we will tell you what it is, what it collects, and get your agreement first.
  • We do not access your systems without your knowledge or outside an agreed engagement.

07Cookies & Analytics

This website sets no cookies and embeds no cross-site trackers. Its typefaces are served from our own server. We use Cloudflare Web Analytics, a cookieless service, to see aggregate visit counts, popular pages, and referring sites; it does not identify you or follow you to other websites.

See our Cookie Policy for the full detail, including the three display preferences (accessibility settings, light or dark mode, and whether you've dismissed the cookie notice) stored in your browser.

08Security

We take reasonable, industry-standard precautions to protect the information we hold:

  • All traffic to and from this website is encrypted in transit using TLS.
  • Consultation records are stored in an access-controlled database with no public read access.
  • Credentials you provide for an engagement are handled through the access method you choose and are not stored in plain text by us.
  • Only the firm's principals handle client information. There is no wider staff with access.

No security program is perfect. If a breach affects your personal information, we will notify you and the applicable regulators as required by law.

09How Long We Keep It

Consultation requests that don't lead to an engagement are retained for up to twenty-four (24) months, so we have context if you come back to us, and then deleted.

Client records — scopes, quotes, invoices, and correspondence — are retained for at least seven (7) years after the engagement ends, because tax and accounting rules require it.

Server logs are retained on a rolling basis, typically thirty (30) days.

You can ask us to delete information about you at any time by writing to hello@keepointsolutions.com. We'll honor verified requests within thirty (30) days, except where we're legally required to keep a record.

10California Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to:

  • Know what categories and specific pieces of personal information we've collected about you, where we got it, and why.
  • Delete personal information we've collected, subject to legal exceptions.
  • Correct inaccurate personal information we hold.
  • Opt out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of — but you may submit a request and we will confirm this in writing.
  • Limit use of sensitive personal information. We do not collect sensitive personal information as that term is defined in the statute.
  • Non-discrimination. We will not deny service, charge a different price, or provide a different level of service because you exercised a privacy right.

To exercise any of these, email hello@keepointsolutions.com with "Privacy Request" in the subject line. We may need to verify your identity first.

11Other Jurisdictions

We are a United States business serving clients in the United States, and our systems are hosted in the United States. We do not market to or knowingly solicit clients in the European Economic Area or the United Kingdom.

If you are located outside the United States and contact us anyway, you should understand that your information will be transferred to and processed in the United States, where privacy laws differ from those in your country. If you would like your information removed, write to us and we will delete it.

12Children's Privacy

Our services are directed to adults and to organizations. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact hello@keepointsolutions.com and we will delete it promptly.

13Changes & Contact

We may update this policy. When we do, we'll revise the effective date at the top of the page, and for material changes we'll give reasonable notice — by email where we have your address, or by a notice on this site.

Questions, requests, or concerns:

Keepoint Solutions LLC
Email: hello@keepointsolutions.com

↑ Back to top

Questions about your data?

Plain English, real answer, no runaround.

Get a free consultation