DOWNPROOF Back To Home

Legal Document

Privacy Policy

Last updated: 1 January 2026

Contents

  • 1. Introduction
  • 2. Who We Are
  • 3. Scope Of This Policy
  • 4. Information We Collect
  • 5. How We Collect Information
  • 6. Why We Use Information
  • 7. Legal Bases For Processing
  • 8. Cookies And Similar Technologies
  • 9. How We Share Information
  • 10. Client Data And Integration Work
  • 11. How Long We Keep Information
  • 12. How We Protect Information
  • 13. International Transfers
  • 14. Your Privacy Rights
  • 15. Privacy For Children
  • 16. Third Party Services
  • 17. Changes To This Policy
  • 18. How To Reach Us

1. Introduction

This Privacy Policy explains how Downproof LLC collects, uses, stores and protects information when you visit our website, contact our team or engage our services. Downproof LLC is a computer integrated systems design practice based in South Jordan, Utah, and our work depends on trust. We treat the information entrusted to us with the same care we apply to the architecture of the systems we study. This document describes in plain language what we do with information, why we do it and the choices available to you.

We have written this policy to be read rather than skipped. It covers the information gathered through this website, the information shared when you request a session or send an enquiry, and the information we encounter while delivering integration services to client organisations. We encourage you to read it in full and to contact us at any time if a point remains unclear. Our contact details appear at the end of this page and we welcome questions about our handling of personal information.

Downproof LLC will not sell personal information. We will not rent it, trade it or exchange it for advertising. We collect only what we need to serve you, we keep it only as long as it serves a defined purpose, and we explain each of those purposes below. If we ever change that approach, this policy will be updated before the change takes effect.

2. Who We Are

Downproof LLC is the data controller responsible for the personal information described in this policy. The company is registered in the United States and operates from a studio office in South Jordan, Utah. Our full postal address is 2059 W Spruce Creek Ln, South Jordan - 84095-2409, United States (US). The developer and operating name behind this website is DOWNPROOF, and all references to we, us or our in this document refer to Downproof LLC.

Our practice concentrates on computer integrated systems design and related professional, scientific and technical services. We help client organisations understand the systems they already run and route those systems into a coherent whole. Because that work touches data architecture, migration and integration, we think carefully about how data is moved and who can reach it. The same discipline shapes how we handle the personal information described here.

For privacy matters you can reach us by email at congming.song@downproof.rest or by telephone at +13095983050. Written correspondence may be sent to the postal address above. We aim to acknowledge every privacy enquiry within one business day.

3. Scope Of This Policy

This policy applies to personal information processed through the Downproof LLC website and through the ordinary conduct of our business. It covers enquiries, proposals, contracts, support conversations and the administrative records that any professional practice must keep. It also covers the limited technical information that web servers and analytics tools record when a visitor loads a page.

This policy does not apply to personal information that a client organisation stores inside its own systems, even where Downproof LLC is engaged to study, migrate or integrate those systems. In that situation the client remains the controller and Downproof LLC acts on the client instructions. Section ten of this policy explains that arrangement in more detail, including the safeguards we apply when handling client data during an engagement.

Where a separate written agreement between Downproof LLC and a client addresses personal information, the terms of that agreement take precedence for the work it covers. This policy continues to govern website visitors, prospective clients and general business correspondence that falls outside any such agreement.

4. Information We Collect

We collect several categories of information depending on how you interact with Downproof LLC. Not every category applies to every person, and we collect only what is relevant to the relationship at hand.

  • Identity and contact information such as your name, job title, organisation, email address, telephone number and postal address.
  • Enquiry content such as the subject of your message, the systems you describe, your objectives and any deadlines you mention.
  • Contract and billing information such as service scope, purchase references, invoicing details and payment records.
  • Correspondence records including emails, call notes, meeting summaries and proposal versions exchanged during a project.
  • Technical information such as internet protocol address, browser type, device type, referring page and the pages viewed on our site.
  • Recruitment information where you apply to work with us, including the history and references you choose to provide.

We do not seek special categories of personal information such as health details, biometric identifiers, political opinions or religious beliefs. If such information reaches us unintentionally, we will delete it unless a legal obligation requires us to retain it. We ask that you do not send sensitive information to us through the website contact form or by ordinary email.

5. How We Collect Information

Most information reaches Downproof LLC directly from you. You provide it when you complete the contact form, send an email, telephone the studio, sign a proposal or correspond with us during a project. You may also provide information when you attend a meeting, share documents for review or invite us into a procurement process.

A smaller amount of information is collected automatically. When your browser requests a page from our website, the server records the technical details needed to deliver the response and to protect the service from abuse. These records may include your internet protocol address, the time of the request and the resource requested. We use this information to keep the site available and secure rather than to build a profile of you.

We may receive information about you from a colleague at your organisation, from a mutual contact who introduces us or from a public professional profile that you maintain. Where a third party provides your details, we treat the information with the same care as if you had sent it yourself and we use it only for the purpose for which it was shared.

6. Why We Use Information

Downproof LLC uses personal information for specific and legitimate purposes. We use contact details to respond to your enquiry, to prepare a proposal and to administer any engagement you choose to begin. We use correspondence records to keep projects coherent and to make sure a decision made in one conversation is not lost before the next.

We use technical information to operate the website, to diagnose faults and to defend against malicious traffic. We use billing information to issue invoices and to meet our accounting obligations. We use recruitment information to assess applications and to communicate with candidates about the progress of their application.

We also use information to improve our services. Aggregated and de-identified figures may help us understand which service pages are most useful, which topics generate the most questions and how visitors move through the site. This analysis never seeks to identify an individual and never overrides the choices you have made about your own information.

7. Legal Bases For Processing

Where applicable law requires a legal basis for processing, Downproof LLC relies on one or more of the following. We process information to perform a contract when you engage us for services, because we cannot deliver an engagement without knowing who to contact and what work is required. We process information on the basis of our legitimate interests when we respond to enquiries, maintain business records and protect our website, provided those interests are not overridden by your rights.

We rely on your consent where consent is the appropriate basis, for example when you ask to receive occasional updates from the studio. You may withdraw consent at any time and we will stop the related processing without affecting the lawfulness of what came before. We process certain information to comply with legal obligations such as tax, accounting and record keeping requirements.

When we handle client data in the course of an integration engagement, our processing is governed by the client instructions and the written agreement between us. In those cases the client organisation determines the purpose and Downproof LLC provides the technical means, subject to the safeguards described later in this policy.

8. Cookies And Similar Technologies

The Downproof LLC website is built to work without tracking cookies. We do not set advertising cookies and we do not allow third party advertising networks to place cookies through our pages. Any cookie that is set serves a functional purpose such as remembering a display preference or protecting a form submission from automated abuse.

You can control cookies through your browser settings. Most browsers allow you to block cookies entirely, to delete existing cookies or to be warned before a cookie is stored. Blocking functional cookies may affect how parts of the site behave, but the core content and the contact form remain usable.

If we ever introduce an analytics service that relies on cookies or similar identifiers, we will update this policy and, where required, ask for your consent before the technology is activated. We prefer measurement methods that respect visitor privacy and we will choose them wherever a suitable option exists.

9. How We Share Information

Downproof LLC does not sell personal information and does not share it for cross-context behavioural advertising. We share information only in the limited circumstances described here, and only to the extent needed for a defined purpose.

  • Service providers who support our operations, such as email hosting, document storage, accounting software and information technology support, each bound by confidentiality terms.
  • Professional advisers such as lawyers and accountants where their advice is required, subject to their own duties of confidence.
  • Authorities where we are legally required to disclose information, or where disclosure is necessary to establish, exercise or defend a legal claim.
  • A successor entity in the event of a merger, acquisition or transfer of the business, provided the recipient remains bound by this policy or an equivalent standard.

Every service provider is selected with care and is required to protect information to a standard consistent with this policy. We do not permit a provider to use our information for its own marketing purposes and we review the arrangement if the provider changes hands or changes its practices.

10. Client Data And Integration Work

Integration projects often involve access to client systems that hold personal information belonging to the client customers or employees. When Downproof LLC performs such work, the client organisation remains the controller of that information and Downproof LLC acts only on the client documented instructions. We do not use client data for our own purposes and we do not disclose it to anyone except as the engagement requires.

We apply strict handling rules during an engagement. Access is limited to the engineers who need it for the agreed task, work is performed in environments approved by the client, and data is returned or securely destroyed at the end of the engagement unless a written agreement requires otherwise. Where we must copy data for analysis, we minimise the copy, restrict where it lives and remove it once the analysis is complete.

If a client asks us to do something that would conflict with applicable data protection law, we will raise the concern before acting. We would rather pause an engagement than expose a client to avoidable regulatory risk. This commitment reflects our wider view that good integration practice and good privacy practice are the same discipline viewed from two angles.

11. How Long We Keep Information

Downproof LLC keeps personal information only for as long as it is needed for the purpose that justified its collection, or for as long as the law requires. Enquiries that do not lead to an engagement are typically removed within twenty four months so that we are not holding a record we no longer need. Information relating to a completed engagement is retained for the period required by contract and by applicable accounting and limitation rules.

Technical server records are kept for a short period sufficient to diagnose faults and to investigate security events, after which they are overwritten or deleted. Recruitment information is retained for the duration of the process and for a limited period afterwards in case a suitable role opens, unless you ask us to delete it sooner.

When a retention period ends, we delete the information or render it permanently unreadable. Where information has been shared with a service provider, we take reasonable steps to ensure the provider applies a matching retention limit.

12. How We Protect Information

Downproof LLC maintains technical and organisational measures designed to protect personal information against loss, misuse and unauthorised access. These measures include encryption of data in transit, access controls that follow the principle of least privilege, and secure configuration of the systems we operate. We keep our software current, we monitor for suspicious activity and we review our practices as the threat landscape changes.

Our team members receive guidance on handling personal information and understand that confidentiality is a condition of their work. Where an engagement involves client systems, we follow the client security requirements in addition to our own. We test our own arrangements periodically and we act quickly when a weakness is identified.

No method of transmission or storage is completely secure. If a security incident affects your personal information in a way that is likely to result in risk to you, we will notify you and the relevant authorities without undue delay, and we will explain what happened, what we have done and what you can do to protect yourself.

13. International Transfers

Downproof LLC is based in the United States and processes most information there. Some service providers we rely on may store or process information in other countries. Where information moves across a border, we take steps to ensure it continues to receive an appropriate level of protection.

Those steps may include contractual commitments that require the recipient to protect information, a review of the legal environment in the destination country, and the use of providers that offer recognised safeguards. Where a transfer would create an unacceptable risk, we will seek an alternative arrangement or discuss the constraint openly with the affected client.

If you are located outside the United States and choose to contact us, you understand that your information will be processed in the United States and in the locations where our providers operate, subject to the safeguards described in this policy.

14. Your Privacy Rights

Depending on where you live, you may have rights over the personal information we hold about you. These rights commonly include the ability to request access to your information, to ask for a correction when something is inaccurate, and to request deletion where no legal reason requires us to keep it. You may also have the right to object to certain processing, to ask us to restrict it, and to request a portable copy of information you provided.

To exercise a right, contact us using the details in the final section of this policy. We will verify your identity before acting so that we do not disclose information to the wrong person. We respond within the period required by applicable law and we do not charge a fee except where a request is manifestly unfounded or excessive.

You also have the right to complain to a supervisory authority in your jurisdiction. We would welcome the chance to resolve a concern directly before you escalate, and we will cooperate fully with any regulator that examines our handling of your information.

15. Privacy For Children

The Downproof LLC website and services are intended for business and professional audiences. We do not knowingly collect personal information from children. If you believe that a child has provided information to us, please contact us so that we can investigate and delete the information promptly.

Where our services touch systems that contain information about children, those systems belong to the client organisation and our handling follows the client instructions and applicable law. We apply the same minimisation and access principles to that work as to any other engagement, and we raise any concern about the lawful basis for processing before the work proceeds.

We encourage parents and guardians to speak with children about online privacy and to contact us if they have questions about how our website handles information.

16. Third Party Services

Our website may contain links to third party sites and may rely on third party providers for email, hosting and document storage. Those providers operate under their own privacy policies, and we encourage you to review them. Downproof LLC is not responsible for the privacy practices of a third party site that we do not control, though we choose our providers with care.

Where a client asks us to integrate a third party platform, that platform may process information under its own terms. During an engagement we identify the parties involved in each data flow so that responsibilities are clear and so that the client can make informed decisions about vendor selection. Our architecture studies and risk reviews routinely surface these third party relationships as part of the analysis.

If we become aware that a provider is handling information in a way that conflicts with this policy or with applicable law, we will raise the matter with the provider and, where necessary, replace the provider.

17. Changes To This Policy

We may update this policy from time to time to reflect changes in our practices, in technology or in the law. When we make a material change we will update the date at the top of the page and, where appropriate, notify affected clients directly. We will not reduce the protections described here without giving notice.

We encourage you to review this page periodically so that you remain informed about how Downproof LLC protects personal information. Continued use of our website after an update means that you accept the revised policy, to the extent that acceptance is a valid legal basis in your jurisdiction.

Earlier versions of this policy remain available on request for a reasonable period after they are replaced, so that you can see what changed and when.

18. How To Reach Us

If you have a question about this Privacy Policy, a request concerning your personal information or a concern about how Downproof LLC has handled information, please contact us. We take privacy enquiries seriously and we aim to acknowledge each one within one business day.

Downproof LLC
2059 W Spruce Creek Ln
South Jordan - 84095-2409
United States (US)
Email: congming.song@downproof.rest
Phone: +13095983050

This policy forms part of our wider commitment to professional practice. If a privacy issue arises during an engagement, raise it with your usual contact at Downproof LLC and we will address it directly and promptly.

Back To Home Privacy Policy Terms of Service Services Contact

Downproof LLC, 2059 W Spruce Creek Ln, South Jordan - 84095-2409, United States (US).

Email: congming.song@downproof.rest | Phone: +13095983050

Copyright 2026 Downproof LLC. All rights reserved.