This Privacy Policy explains how NBVINEYARD LLC collects, uses, stores and protects personal information. NBVINEYARD LLC is an integrated computer systems design and technology consulting studio based in Orem, Utah, and this policy applies to our website, our client engagements and every service row we cultivate. The developer known as NB Vineyard maintains this policy on behalf of the company and reviews it each season so that it continues to reflect how we actually work.
We wrote this document in plain language because privacy notices should be readable. If any part of it is unclear, please write to bookings@nbvineyard.mom and a member of our team will explain it. This policy applies to visitors, prospective clients, current clients, suppliers and anyone else whose information reaches us through the channels described below.
1. Scope Of This Policy
This policy covers personal information processed through the NBVINEYARD LLC website, through email and telephone conversations, through proposals and contracts, and through the delivery of our six service rows. It also covers information we receive from suppliers, candidates who apply to work with us, and visitors who request information about our work.
This policy does not cover the internal practices of our clients. When NBVINEYARD LLC engineers a system for a client, the client remains responsible for the personal information inside that system. We act as a processor for that data and follow the written instructions in the relevant agreement. A separate data processing addendum governs those engagements and takes precedence where it conflicts with this notice.
Some parts of our website are informational and do not require an account. Other interactions, such as sending a message through the contact form, involve voluntary sharing of information. Where you choose to share, this policy explains what happens next.
2. Who Controls Your Information
The data controller for the information described in this policy is NBVINEYARD LLC. The company is registered and operates from 343 W Lakeview Ct, Orem - 84059-5572, United States (US). The company can be reached by email at bookings@nbvineyard.mom and by telephone at +14844924432.
The developer named NB Vineyard is the internal owner of this policy and is responsible for answering questions about it. Where this document refers to the Company, it means NBVINEYARD LLC. Where it refers to we, us or our, it means the same company. Where it refers to you, it means the individual whose personal information is being described.
If your enquiry concerns a system that NBVINEYARD LLC built or manages on behalf of another organisation, the first point of contact is usually that organisation. We will assist it promptly and will route your request correctly if you reach us first.
3. Information We Collect
We collect information that is necessary for the work we do, and we try to keep the list short. The categories below describe what we typically hold.
Identity and contact information
Your name, job title, organisation name, email address, postal address and telephone number. These details arrive when you contact us, request a proposal, or become a client.
Contract and billing information
The terms of an engagement, agreed fees, purchase order references, invoicing contacts and payment status. We keep financial records because the law requires it and because clear records prevent disputes.
Project information
Notes from meetings, requirements, system descriptions, architecture decisions, support tickets and correspondence. This material often contains business facts rather than personal information, but it can include the names and work details of the people involved in a project.
Technical information
When you visit our website, our hosting infrastructure records standard technical data such as the requested page, the time of the request, the referring page and an approximate region. This data is used for security and capacity planning rather than for profiling individuals.
Support and communication records
Emails, call notes and ticket threads connected to managed support. These records help us resolve issues consistently and prove what was agreed when a request is fulfilled.
Recruitment information
If you apply to work with NBVINEYARD LLC, we hold the materials you send, such as a resume and references, for the duration of the hiring process and a reasonable period afterwards.
4. How We Obtain Information
Most personal information reaches us directly from you. You send a message through our contact form, write to our booking address, call the studio, or share requirements during a survey. You provide the information when you choose to make contact.
Some information arrives automatically through our web infrastructure, such as the technical data described above. Some information is created during a project, for example when we record a decision in a register or open a support ticket on your behalf.
In limited cases we receive information from third parties. A client may introduce us to a colleague who becomes the technical contact for an engagement. A partner may share a reference during a joint project. A public source may confirm a company address for an invoice. We do not buy personal information, and we do not obtain it from data brokers.
We ask that you share only the information that is needed. If you send us sensitive material that we did not request, we will handle it carefully but we may delete it if it is not relevant to our work.
5. Purposes Of Processing
We process personal information for a defined set of purposes. Each purpose is tied to a real activity of the studio, and we do not process information beyond what those activities require.
- Responding to enquiries, questions and requests for proposals.
- Preparing contracts, statements of work and commercial documentation.
- Delivering integration, software, cloud, data, security and support engagements.
- Managing projects, including scheduling, reporting and quality control.
- Providing managed support and maintaining service level commitments.
- Issuing invoices and maintaining statutory financial records.
- Protecting our systems, our clients and our website from misuse and attack.
- Meeting legal, tax, audit and regulatory obligations.
- Improving our services through aggregated, non identifying review.
- Recruiting and assessing candidates who apply to join the studio.
We do not sell personal information. We do not use it to build advertising profiles, and we do not share it with advertising networks. The studio earns its living from engineering work, not from data.
6. Legal Bases For Processing
Where data protection law requires a legal basis, we rely on the following grounds. Performance of a contract applies when processing is needed to deliver work you have engaged us to do. Legitimate interests apply when processing supports the running of the studio, such as securing our systems or responding to a business enquiry, and we balance those interests against your rights.
Consent applies where you have clearly agreed to a specific use, such as receiving a newsletter. You may withdraw consent at any time, and withdrawal does not affect processing that already took place lawfully.
Legal obligation applies where we must keep or disclose information to satisfy tax, accounting or regulatory duties. Where none of these grounds fits, we will ask for your consent before we proceed.
9. Service Providers And Subprocessors
Like most studios, we rely on specialist providers for infrastructure. Email is delivered through a reputable mail provider, the website is served from professionally managed hosting, and project material is stored in access controlled repositories. Each provider is chosen with care and is bound by a contract that limits its use of the information to the service it provides to us.
We keep a register of subprocessors who may touch personal information. The register records the provider, the purpose, the location of processing and the safeguards in place. Clients who need to review the register for their own compliance work may request it through their account contact, and we will provide it promptly.
When a subprocessor is replaced, we assess the change for risk and update the register. Where a client agreement gives a right to object to a new subprocessor, we honour that right and will discuss alternatives in good faith.
10. International Data Transfers
NBVINEYARD LLC is based in the United States, and our primary processing takes place there. Some providers operate infrastructure in other countries, so personal information may be transferred across borders as part of ordinary hosting and email delivery.
Where information moves from a jurisdiction with transfer restrictions, we rely on appropriate safeguards. These may include standard contractual clauses approved by the relevant authority, an adequacy decision, or another lawful mechanism. We review the safeguards each year and update them when the law or the provider changes.
You may ask for more detail about the safeguards used for a specific transfer by writing to bookings@nbvineyard.mom. We will explain the mechanism in plain language and provide the relevant documentation where we are able to do so.
11. Data Retention
We keep personal information only as long as it serves the purpose for which it was collected, plus any period required by law. Retention is reviewed on a schedule so that old material is removed rather than left to accumulate.
- Enquiries that do not lead to an engagement are kept for up to twenty four months.
- Contract and project records are kept for the duration of the relationship and then for seven years to meet tax and audit duties.
- Support tickets are kept for three years so that recurring issues can be recognised.
- Recruitment material is kept for twelve months unless a candidate asks us to remove it sooner.
- Website technical logs are kept for a short period and then deleted or aggregated.
When a retention period ends, we delete the information or render it permanently unreadable. Where deletion is not immediately possible because data sits in a backup, we isolate the backup and delete it when the backup cycle next completes.
12. Security Measures
Security is one of our six service rows, so we hold our own house to the same standard we recommend to clients. Access to personal information is limited to team members who need it, protected by strong authentication and reviewed when roles change.
Data is encrypted in transit and at rest using current standards. Endpoints are patched on a defined schedule, backups are verified rather than merely scheduled, and recovery is tested so that a restore is a practised routine rather than an experiment. Changes to production systems follow a review process, and administrative activity is logged.
We train our team on privacy and security each year, and we run internal exercises that test how we respond to phishing and account compromise. No security programme is perfect, and we do not claim otherwise, but we work continuously to reduce risk and to detect problems early.
13. Breach Notification
If we become aware of a personal data breach that poses a risk to individuals, we act quickly. The first steps are to contain the incident, preserve evidence and establish what information was affected. A small response team coordinates the work and keeps a written timeline.
Where the law requires it, we notify the relevant supervisory authority without undue delay and within the applicable deadline. Where a breach is likely to result in a high risk to individuals, we notify the affected people directly, describing what happened, what we have done, and what they can do to protect themselves.
Clients whose systems we manage are informed through the contact route agreed in their contract. After an incident we produce a written review with corrective actions, and we track those actions to completion rather than closing the file at the first sign of calm.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights. We honour these rights for everyone who asks, regardless of location, because respecting people is simpler than sorting them by postcode.
- The right to be informed about how your information is used.
- The right to access the personal information we hold about you.
- The right to correct information that is inaccurate or incomplete.
- The right to request deletion where there is no overriding legal reason to keep it.
- The right to restrict or object to certain processing.
- The right to receive your information in a portable format.
- The right to withdraw consent where processing relies on it.
- The right to lodge a complaint with a supervisory authority.
These rights are not absolute. A retention duty, a legal claim or a security need can limit a request, and we will explain any limitation clearly rather than hiding behind a template refusal.
15. Exercising Access And Deletion
To exercise a right, write to bookings@nbvineyard.mom with enough detail for us to understand the request. Telling us which email address you used and what the request concerns helps us find the right records. You do not need to use special wording or a particular form.
We respond within thirty days in most cases. If a request is complex, we may extend that period and will tell you why. We do not charge a fee for a reasonable request, though we may charge for repetitive or excessive requests where the law permits.
To protect your information, we may ask you to confirm your identity before we act. We use the minimum verification necessary and do not demand identity documents unless there is a genuine doubt about who is asking.
16. Privacy For Children
Our services are designed for organisations and professionals. We do not knowingly collect personal information from children, and we do not direct our website at them. If you believe a child has sent information to NBVINEYARD LLC, please contact us and we will delete it promptly.
Where a client system that we build serves younger users, the client is responsible for obtaining any required parental consent and for configuring the system appropriately. We support that work through our security and data engineering rows, and we follow the client instructions set out in the relevant agreement.
17. Marketing Communications
We send occasional studio notes to people who ask for them. These notes describe new service rows, seasonal booking windows and practical articles drawn from our project work. We do not send them to anyone who has not opted in, and we do not pass addresses to marketing partners.
Every note includes a simple way to unsubscribe. When you unsubscribe, we record the request so that you are not contacted again, and we retain only the minimum record needed to honour it. If you are a client, we will still send service messages that are necessary to deliver the work you have engaged, such as maintenance notices.
18. Analytics And Measurement
We measure the website in a way that respects visitors. Aggregate counts of page views and referrers tell us which pages are useful and which need improvement. This measurement does not build individual profiles, and it is not combined with client records.
Where a tool would identify individuals, we either avoid it or configure it to reduce the data it keeps. We review our measurement setup each year and remove anything that no longer earns its place. The same restraint applies to the systems we design for clients, and our Data Platform Engineering row treats data minimisation as a design rule rather than an afterthought.
19. Third Party Websites
Our website may link to external resources that we think are useful. We do not control those sites, and this policy does not apply to them. When you follow a link away from our pages, the destination operator becomes responsible for your information.
We choose links carefully and avoid pointing to partners with weak privacy practices, but a change on another site is outside our control. We encourage you to read the privacy notice of any site before sharing personal information with it.
20. Changes To This Policy
This policy is reviewed each season and whenever our practices change. When we make a material change, we update the effective date at the top of this page and, where the change is significant, we notify clients and subscribers by email.
Previous versions are available on request so that you can see how the policy has evolved. We keep the wording precise and avoid silent edits, because a privacy notice that shifts without notice is of little use to the people who rely on it.
21. How To Contact Us
Questions, requests and complaints about privacy are welcome. The fastest route is email to bookings@nbvineyard.mom. You can also call +14844924432 during business hours, Monday to Friday, 8:00 to 17:30 Mountain Time.
Written correspondence may be sent to NBVINEYARD LLC, 343 W Lakeview Ct, Orem - 84059-5572, United States (US). Please mark privacy requests clearly so they reach the right person without delay.
If you are not satisfied with our response, you may raise the matter with the supervisory authority that covers your jurisdiction. We would rather resolve the issue directly first, and we will work in good faith to do so.