Trust & privacy
Your privacy, choices, and security matter
Clear, visitor-focused information about privacy policy and California privacy notice, including the commitments, choices, review boundaries, and contact path people should be able to understand.
CISO-led guidance from Ali Hassani, backed by 25+ years of IT, cybersecurity, compliance, and infrastructure experience.
This notice is written to provide clear, practical information about our website practices. It does not replace legal advice and does not describe data handling for a separately documented client engagement, which may be governed by an agreement, statement of work, confidentiality terms, or other engagement-specific requirements.
1. Information we collect
Information you provide
We may collect information you choose to submit, such as your name, business name, email address, telephone number, preferred contact method, service interests, consultation details, and the contents of a message. Please do not submit passwords, authentication codes, payment-card data, protected health information, government identifiers, sensitive security configurations, vulnerability details, or confidential client data through a public website form.
Website and device information
When you use the website, our hosting, security, analytics, advertising, and consent-management technologies may process limited technical information. Depending on your choices and configuration, this can include IP address, browser and device type, operating system, referring page, pages viewed, approximate region, timestamps, interactions with website features, diagnostic events, and cookie or similar identifiers.
Security information
Security controls may process IP addresses, request details, login attempts, suspicious behavior, and related technical data to detect abuse, protect the website, investigate security events, and maintain service availability.
2. How we use information
We use information for legitimate business and operational purposes, including to:
- Respond to inquiries, consultation requests, and service questions.
- Provide, maintain, secure, and troubleshoot the website.
- Understand site performance and improve content, usability, and visitor experience.
- Measure outreach and advertising effectiveness when permitted by your consent choices.
- Prevent fraud, spam, malicious activity, and unauthorized access.
- Maintain business records, fulfill contractual obligations, and comply with applicable law.
- Establish, exercise, or defend legal claims.
3. Cookies, analytics, and advertising
The website may use essential technologies required for security, site operation, load balancing, preference storage, and consent management. With the choices offered through our consent banner, optional technologies may support statistics, measurement, embedded media, and advertising.
Services in use or detected on the website may include Google Analytics, Google Tag Manager, Google Ads, Google Site Kit, Microsoft Advertising Universal Event Tracking, YouTube or other embedded media, WordPress, Elementor, The7, Wordfence, and hosting or performance services. These providers may process data under their own terms and privacy notices.
4. When information may be disclosed
We do not sell personal information for money. We may disclose limited information to service providers that help operate, secure, measure, or communicate through the website; to professional advisers where necessary; in connection with a business transaction subject to appropriate safeguards; or when required to comply with law, protect rights and safety, or investigate misuse.
Some privacy laws use “sell,” “share,” or “targeted advertising” broadly. Optional advertising and measurement technologies may be treated as sharing for cross-context behavioral advertising. You may opt out through Privacy Choices and any other control presented on the website.
5. California privacy notice
California residents may have rights, subject to applicable exceptions and verification requirements, to know or access categories and specific pieces of personal information, request deletion, request correction, receive information about collection and disclosure practices, and opt out of sale or sharing. You may also have the right to limit certain uses of sensitive personal information and to receive equal service and pricing after exercising privacy rights.
OC Security Audit does not intentionally use sensitive personal information from this public website to infer characteristics. We do not knowingly sell personal information for money. To exercise an applicable right, use our secure contact page and clearly label the request “Privacy Request.” We may need to verify the request and your authority before responding. An authorized agent may submit a request where permitted by law, subject to verification.
6. Data retention
We retain information only for as long as reasonably necessary for the purpose collected, including responding to inquiries, maintaining business and security records, meeting legal or contractual obligations, resolving disputes, and enforcing agreements. Retention periods vary by record type, service-provider configuration, security need, and applicable law. Information that is no longer required is deleted, anonymized, or securely disposed of where practical.
7. Data security
We use administrative, technical, and organizational safeguards designed to protect information appropriate to its nature and the risks involved. No website, transmission method, or storage system can be guaranteed completely secure. If you believe information submitted through this website may have been exposed or misused, please contact us promptly without including additional sensitive data in the initial message.
8. External links and embedded services
The website may link to third-party resources or display embedded content. A third party may collect information when you choose to interact with its content. This policy does not control third-party websites, platforms, products, or privacy practices. Review the applicable provider’s notice before submitting information.
9. Children’s privacy
This website is intended for business professionals and is not directed to children under 13. We do not knowingly collect personal information from children through the public website. If you believe a child has provided personal information, contact us so we can review and delete it where required.
10. International visitors
The website is operated for a United States business audience. If you visit from another jurisdiction, information may be processed in the United States or other locations used by our service providers. Where applicable, you may have additional privacy rights under local law.
11. Changes to this notice
We may update this policy to reflect changes in technology, services, legal requirements, or business practices. The effective date above identifies the current version. Material changes may be highlighted through the website or consent interface when appropriate.
Contact and privacy requests
To ask a privacy question or submit a request, use the OC Security Audit contact page. Please identify the request as a privacy matter and do not include passwords, client evidence, protected health information, or other sensitive data.
Learn about Ali Hassani, CISO, the cybersecurity and IT professional behind OC Security Audit.