Privacy Policy
Effective date: July 29, 2026
This Privacy Policy explains how AllTech (“AllTech,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with askalltech.com (the “Site”) and the managed IT, cybersecurity, network, and cloud services we provide (the “Services”).
AllTech is located at 865 West Center Street, Bldg F, Hyde Park, UT 84318 and serves businesses across Northern Utah, the Wasatch Front, and southern Idaho.
1. Scope of this policy
This policy covers information we collect as a controller of our own business records — for example, information submitted through the Site by prospective and current clients.
It does not govern client data we process on a client’s behalf while delivering Services (for example, data inside a client’s Microsoft 365 tenant, endpoints, backups, or network logs). We handle that data as a service provider under the client’s Master Services Agreement, statement of work, or data processing addendum, and the terms of those agreements control. If you are an employee or customer of an AllTech client and you have a question about your personal information, contact that organization directly.
2. Information we collect
2.1 Information you provide
- Contact form. Name, company name, email address, phone number, the service categories you select, and any free-text details you include in your message.
- Security gap assessment. Your responses to assessment questions across the assessed domains, your resulting score, and the contact details you supply to receive results.
- Direct communications. Information contained in emails, phone calls, support tickets, and on-site conversations, including any records or recordings we maintain of them.
- Business relationship records. Billing contacts, purchase orders, service addresses, and payment details you provide to establish or maintain an account.
2.2 Information collected automatically
- Log and device data. IP address, browser type and version, operating system, referring URL, pages viewed, and timestamps.
- Security telemetry. Our hosting and security provider records request metadata to detect and mitigate bot traffic, abuse, and denial-of-service attacks.
- Cookies and similar technologies. See Section 6.
2.3 Information we do not seek
The Site is a business-to-business resource. Please do not submit government identifiers, financial account credentials, health information, or other sensitive personal information through the contact or assessment forms. If you need to share sensitive material, ask us for a secure transfer method.
3. How we use information
- Respond to inquiries and route them to the right engineer.
- Prepare quotes, proposals, assessments, and statements of work.
- Deliver, support, monitor, and invoice for the Services.
- Generate and follow up on security gap assessment results.
- Operate, secure, and improve the Site, including fraud prevention, abuse detection, and troubleshooting.
- Send service, maintenance, incident, and administrative notices.
- Send occasional business communications about our services. You can opt out at any time using the unsubscribe link or by contacting us; transactional and service notices will continue.
- Comply with legal, tax, insurance, and regulatory obligations, and establish or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. Legal bases (EEA/UK visitors)
Where the GDPR or UK GDPR applies, we rely on: contract (to provide Services you have requested or to take pre-contractual steps); legitimate interests (to operate and secure the Site, respond to inquiries, and market our services to businesses); legal obligation (recordkeeping and tax); and consent where required, which you may withdraw at any time.
5. When we disclose information
We disclose personal information only as described below.
- Service providers. Vendors who process information on our instructions under written agreements, including hosting and network security (Cloudflare), business email and productivity (Microsoft 365), remote monitoring and management (Datto), remote support tooling, ticketing and CRM systems, and accounting and payment processors.
- Professional advisors. Attorneys, accountants, auditors, and insurers bound by confidentiality obligations.
- Legal and safety. Where required by law, subpoena, court order, or governmental request, or where necessary to investigate a security incident, enforce our agreements, or protect the rights, property, or safety of AllTech, our clients, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy’s continued application to transferred information.
- With your direction. When you ask us to share information with a third party, such as a hardware vendor or another provider you use.
6. Cookies and analytics
The Site uses strictly necessary cookies to deliver pages, balance load, and protect against automated abuse. We may also use privacy-oriented analytics to measure aggregate traffic and page performance.
You can block or delete cookies through your browser settings. Strictly necessary cookies cannot be disabled without affecting Site functionality. We do not currently respond to Do Not Track browser signals; we do honor recognized opt-out preference signals such as Global Privacy Control where legally required.
7. Third-party sites and tools
The Site links to properties we do not control, including our remote assistance portal and embedded Google Maps. Their own privacy policies govern the information they collect. Embedded map content may load resources from Google and transmit your IP address to Google.
8. Retention
- Inquiry and assessment submissions: retained while we evaluate the inquiry and for a reasonable follow-up period, generally up to 24 months from last contact, unless a client relationship forms.
- Client account and billing records: retained for the term of the engagement and for the period required by tax, accounting, insurance, and statute-of-limitations rules.
- Site and security logs: retained for a limited period consistent with our security monitoring needs.
We delete or de-identify information once it is no longer needed for the purposes described here, subject to any applicable legal hold.
9. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including multi-factor authentication, least-privilege access controls, endpoint protection, encryption in transit, patch management, monitoring, and vendor due diligence.
No system is completely secure. We cannot guarantee that information transmitted to or from the Site will be free from unauthorized access. If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulator as required by law.
10. Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion, a portable copy, restriction of or objection to certain processing, and the right not to be discriminated against for exercising these rights.
How to submit a request. Email us or call the number in Section 13. We will acknowledge your request and respond within the time frame required by applicable law. We may need to verify your identity before acting, using information already in our possession, and we will not use verification information for any other purpose. An authorized agent may submit a request on your behalf with written proof of authorization.
California residents. If we hold personal information about you, you may request the categories and specific pieces of personal information collected, the categories of sources, the business purposes for collection, and the categories of third parties to whom it was disclosed. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
EEA and UK residents. You may lodge a complaint with your supervisory authority, including the UK Information Commissioner’s Office. We store and process information in the United States; where we transfer personal information out of the EEA or UK, we rely on Standard Contractual Clauses or another approved mechanism.
11. Children’s privacy
The Site and Services are intended for businesses and individuals age 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy to reflect changes in our practices, services, or legal obligations. We will revise the effective date above and, for material changes, provide additional notice on the Site or by email to active clients. Continued use of the Site after an update constitutes acceptance of the revised policy.
13. Contact us
AllTech
865 West Center Street, Bldg F
Hyde Park, UT 84318
Phone: (435) 557-3232
Email: privacy@askalltech.com
You can also reach us through our contact form.