Privacy Policy

Last Updated: [Month Day, Year]

This policy explains how Responsible Cloud collects, uses, shares, retains, and protects information across our website, advertising, free Cloud Risk Check, communications, and professional services.

Responsible Cloud LLC ("Responsible Cloud," "we," "us," or "our") respects your privacy. This policy applies when you visit ResponsibleCloud.com, interact with our advertising, submit a Facebook or Instagram lead form, complete the free Cloud Risk Check, submit a website form, communicate with us, or become a prospective or paying client.

Our typical customer journey: Facebook advertisement → Free Cloud Risk Check → Website form or email follow-up → Paid consulting engagement.

1. Information We Collect

Information you provide

We may collect your name, work email, telephone number, role, organization, team size, industry, technology concerns, requested service, partner type, referral-code request, messages, marketing preferences, scheduling information, and—during a paid engagement—contract, billing, payment, business, technology, policy, evidence, and assessment information within the agreed scope.

Do not submit passwords, security keys, regulated personal data, customer records, confidential system details, or active-incident information through a general form, Meta lead form, or initial email.

Facebook and Instagram leads

If you submit a lead form through Facebook or Instagram, we receive the information you choose to provide. Meta may separately process account, device, advertising-interaction, and service-use data under the Meta Privacy Policy.

Free Cloud Risk Check

The Risk Check creates answers, progress, scores, recommendations, remediation status, reassessment history, before-and-after comparisons, Risk Reduction Record information, dates, evidence references you enter, and optional referral attribution. The current version stores assessment state in your browser's local storage so you can resume and reassess. It is not transmitted to Responsible Cloud unless you separately choose to send or share it with us. Anyone using the same browser profile may be able to view it. You can clear it from the Risk Check page or browser settings.

Forms, clients, and automatic data

Assessment and partner forms currently use Formspree, which processes submissions under its own terms and privacy practices. A submission does not create a client or partner relationship. For prospective and paying clients, we may collect the records reasonably needed to scope, deliver, administer, bill for, and document the agreed work. Our website or providers may also receive IP address, browser and device type, operating system, general region, referring source, pages visited, actions, timestamps, session information, cookie identifiers, and performance or security logs.

2. How We Use Information

We use information to operate the website and Risk Check; save progress; generate scores, recommendations, comparisons, and records; answer inquiries; qualify leads; schedule meetings; recommend and scope services; prepare proposals; deliver engagements; administer contracts and billing; send service or marketing communications; measure advertising and funnel performance; attribute referrals; improve our services; prevent misuse; protect rights and systems; meet legal obligations; and establish or defend claims.

Risk Check results do not prove that a business is secure, compliant, certified, insurable, or protected against a breach.

3. Facebook and Advertising Data

Lead Ads

We may use Facebook and Instagram Lead Ads. We may use submitted lead information to provide a requested resource, respond, follow up about services, assess fit, and measure campaign performance. Submitting a lead form does not require a purchase.

Meta Pixel

Responsible Cloud may use the Meta Pixel or similar Meta Business Tools. When enabled, they may collect page views, advertisement referrals, general funnel actions, browser and device data, IP address, and cookie or advertising identifiers. Meta may use this information for measurement, reporting, ad delivery, personalization, and audience creation. Where required, we will request consent before activating non-essential advertising technologies.

Custom Audiences

Where permitted, we may use website activity or contact information to create Meta Custom Audiences and similar or lookalike audiences. We will use customer-list audiences only when we have the necessary rights, permissions, and lawful basis. You may manage advertising preferences through Meta or object by contacting us.

We do not intentionally send individual Risk Check answers, scores, findings, evidence, or Risk Reduction Records to Meta. Advertising events should be limited to general actions rather than private assessment content.

4. Cookies, Local Storage, and Analytics

We use browser storage needed to save Risk Check progress and history, preserve referral attribution, remember privacy choices, and support site functions. Clearing it may erase saved assessments and records.

With permission where required, we may measure events such as visits, assessment starts and completions, score generation, recommendation views, documented remediation, reassessments, record generation or download, sharing, referrals, and service-link selections. Current first-party measurement is designed not to include assessment answers, scores, organization names, evidence, form contents, or the referral-code value. If an external analytics provider is enabled, this policy and our privacy controls should identify it.

You can use the site's Privacy choices control, browser settings, legally recognized opt-out signals where supported, and platform advertising settings. Browser Do Not Track signals are not interpreted consistently across the industry.

5. Email Communications

We may send requested, scheduling, proposal, engagement, billing, administrative, and other service-related messages. Where permitted, we may also send educational or promotional email.

You can stop promotional email at any time through its unsubscribe link or by emailing hello@responsiblecloud.com with the subject "Unsubscribe." We may keep a limited suppression record to honor your choice. Opting out of marketing does not stop necessary inquiry, transaction, contract, or engagement communications.

6. Data Sharing and Third Parties

Responsible Cloud does not sell assessment answers or individual Risk Check results. We may share information with providers supporting hosting, forms, email, analytics, advertising, scheduling, customer management, storage, payments, accounting, security, and professional advice; with Meta when its ads or Business Tools are used; when you direct us; or when reasonably necessary for law, safety, fraud prevention, contract enforcement, claims, or a business transaction.

A referral link may identify its source, but partners do not receive individual answers, scores, findings, evidence, or records without the business's explicit authorization. Aggregate or de-identified reporting may be used with safeguards against re-identification.

7. Sale, Sharing, and Targeted Advertising

We do not sell personal information for money. Some laws may treat advertising pixels, identifiers, or audience tools as "sharing," targeted advertising, or a regulated sale. Where applicable, you may opt out through our privacy control, a supported recognized preference signal, Meta settings, or an email to hello@responsiblecloud.com with the subject "Privacy Opt-Out." We do not knowingly sell or share children's information or use individual Risk Check results for targeted advertising.

8. Data Retention

We retain information only as reasonably needed for the purposes described here. Browser-based Risk Check data remains until you clear it. Inquiry data is kept while active and for a reasonable business-record period. Marketing data is kept until it is no longer needed or you unsubscribe, subject to a suppression record. Client records may be kept for contractual, accounting, tax, insurance, security, and legal needs. Provider-held analytics and advertising data follows configured settings and provider practices. When no longer needed, information may be deleted, anonymized, or securely disposed of.

9. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of information; withdraw consent; opt out of marketing, sale, sharing, or targeted advertising; appeal a denial; and receive equal service without unlawful discrimination. Exceptions may apply for contracts, transactions, security, law, or claims.

Send requests to hello@responsiblecloud.com with the subject "Privacy Request." We may verify your identity and an agent's authority. You may also have the right to contact your privacy regulator.

10. Legal Bases

Where applicable law requires a legal basis, we rely on consent; steps requested before or performance of a contract; legitimate interests in operating, securing, improving, measuring, and proportionately marketing our business; legal obligations; and protection of rights and safety. You may withdraw consent, but that does not affect earlier lawful processing.

11. International Data Transfers

We and our providers may process information in the United States or other countries whose laws differ from yours. Where required, we use appropriate contractual or other legally recognized safeguards.

12. Data Security

We use reasonable administrative, technical, and physical safeguards appropriate to the information, including access controls, limited collection, browser-based private assessment storage, provider review, and contractual protections. No transmission or system can be guaranteed completely secure. Report suspected misuse promptly to hello@responsiblecloud.com.

13. Client Confidentiality and Assessment Boundaries

Paid engagements may also be governed by a proposal, statement of work, confidentiality agreement, data-processing agreement, or other contract. If an applicable client contract conflicts with this general policy, that contract controls to the extent stated and permitted by law. Assessment records document information reported, supplied, or observed within scope; they do not independently establish security, certification, compliance, insurance eligibility, or breach prevention.

14. Third-Party Links

We may link to third-party services we do not control. Review their privacy practices before providing information.

15. Children's Privacy

Responsible Cloud is intended for adults and business users, not children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child submitted information. We apply a higher local consent age where required.

16. Changes to This Policy

We may update this policy as our services, providers, advertising, or obligations change. We will post the revision and update the date. We will provide additional notice or seek consent for material changes when required.

17. Contact Information

Responsible Cloud
Email: hello@responsiblecloud.com
Mailing address: [Responsible Cloud mailing address]
Telephone: [privacy contact telephone number, if offered]

Placeholders to complete before publishing

Legal business name: [Responsible Cloud legal entity name] · Mailing address: [Responsible Cloud mailing address] · Telephone: [privacy contact telephone number, if offered] · Primary jurisdiction: [state and country]

  • Website hosting: [hosting provider]
  • Analytics: [analytics provider, or "None currently configured"]
  • Email and marketing: [email service provider] / [email marketing provider]
  • Scheduling or CRM: [scheduling/CRM provider]
  • Payments: [payment processor]
  • Cloud storage or collaboration: [business-service provider]
  • Consent controls: [consent provider, or "Responsible Cloud first-party privacy controls"]
  • Meta Pixel: [currently active / planned / not currently active]
  • Customer-list Custom Audiences: [currently used / planned / not used]