Privacy Policy
How information is collected, used, retained, and protected in connection with this site, authorized consulting engagements, and voluntary communication preference requests.
Effective date: August 20261. Scope
IHeartInfoSec is an independent cybersecurity consulting practice operated as a sole proprietorship in Texas. This Privacy Policy describes how IHeartInfoSec ("we," "us," or "our") handles information collected through this website, during authorized information security consulting engagements, and in connection with voluntary communication preference requests submitted through this site.
2. Information we collect
Depending on the nature of the interaction, we may collect business contact information, telephone numbers, email addresses, technical logs, message-delivery information, assessment metrics, and limited interaction data. For authorized security consulting engagements, collection is limited to what is necessary to perform the contracted services. For voluntary SMS enrollment, we collect the client or business-contact name, business email address, and mobile number provided through the Communication Preferences form.
3. How we use information
We use information to communicate with clients, perform contracted security services, administer authorized awareness or social-engineering exercises, produce engagement reports, process voluntary SMS opt-in requests, maintain business records, protect our systems, and comply with legal or contractual obligations.
4. SMS and mobile information
IHeartInfoSec sends transactional SMS messages only to clients and business contacts who voluntarily enroll through the Communication Preferences form. Messages may include consultation scheduling, meeting reminders, engagement coordination, project-status updates, requests for client action, and secure report or deliverable availability notifications. Consent is voluntary and is not required to obtain services.
- Message frequency varies.
- Message and data rates may apply.
- Reply STOP to opt out of future messages.
- Reply HELP for assistance.
- Mobile telephone numbers and SMS consent information are not sold, rented, or shared with third parties or affiliates for marketing or promotional purposes.
- Service providers may process messaging information only to provide communications infrastructure and support.
5. Information sharing
We may disclose information to service providers that support hosting, communications, security, or engagement delivery, but only as necessary for those services and subject to appropriate restrictions. We may also disclose information when required by law or with the relevant client's authorization.
6. Data retention
Information is retained only for as long as reasonably necessary to complete the engagement, satisfy contractual requirements, maintain required records, resolve disputes, or comply with law. Engagement-specific retention periods may be defined in the applicable agreement.
7. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information. No method of storage or transmission is completely secure, and absolute security cannot be guaranteed.
8. Individual choices
Individuals may contact us to ask about information associated with them or request correction or deletion where applicable. Certain records may need to be retained for legal, contractual, or security reasons.
9. Policy changes
We may update this policy periodically. The effective date indicates the most recent revision.
10. Contact
IHeartInfoSecsupport@iheartinfosec.com