Contents
- Who we are & scope
- Information we collect
- How we use information
- Legal bases for processing (GDPR)
- Sharing & third-party services
- Cookies & tracking technologies
- Data retention
- International data transfers
- Security
- Your rights — EU/UK (GDPR)
- Your rights — California (CCPA/CPRA)
- Other U.S. state privacy rights
- Children's privacy
- Do Not Track & Global Privacy Control
- Automated decision-making
- Data breach notification
- Changes to this policy
- Contact & complaints
1. Who We Are & Scope
BLD Technology Co. ("BLD," "we," "us," "our") is the data controller responsible for personal information collected through this website and through any direct communications with us (collectively, the "Services"). We are headquartered in Port Washington, New York, United States.
This Privacy Policy explains what information we collect about you, how we use it, who we share it with, how long we keep it, and the rights you have under U.S. and international privacy laws — including the EU and UK General Data Protection Regulation (GDPR/UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and other applicable U.S. state laws.
By accessing or using the Services, you acknowledge you have read and understood this Privacy Policy.
2. Information We Collect
2.1 Information you provide directly
- Identity & contact data — name, business name, email address, phone number when you submit our contact form or email us.
- Project information — the contents of messages and any project details you choose to share.
- Communications — records of correspondence (email, calls, video calls, written notes).
2.2 Information collected automatically
- Device & usage data — IP address (or a truncated version), browser type and version, operating system, referring/exit pages, pages viewed, date and time of visit, and approximate location derived from IP.
- Cookies and similar technologies — only where you have given consent (see Section 6).
- Bot-protection signals — if Cloudflare Turnstile is enabled, the widget collects minimal device/behavior signals to verify you are a human; processed by Cloudflare under its own privacy policy.
2.3 Information from third parties
We may receive limited information about you from service providers (for example, our form processor) and from publicly available sources you have chosen to make public (e.g., LinkedIn).
2.4 Sensitive personal information
We do not request, collect, or process special categories of personal data (e.g., racial or ethnic origin, religious beliefs, biometric data, health data, sexual orientation) or "sensitive personal information" as defined under U.S. state laws.
3. How We Use Your Information
We use personal information only for the following purposes:
- To respond to your inquiries and provide the Services you request;
- To prepare quotes, proposals, statements of work, invoices, and receipts;
- To deliver and support active projects;
- To send transactional communications related to ongoing work;
- To comply with legal obligations and enforce our agreements;
- To detect, prevent, and address fraud, security incidents, or technical issues;
- To improve the Services (using aggregated, non-identifying analytics — only where you have consented to non-essential cookies).
We do not sell your personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not use your information for unsolicited marketing without your explicit, opt-in consent.
4. Legal Bases for Processing (GDPR)
If you are in the EU, UK, EEA, or Switzerland, we process your personal data on the following lawful bases:
- Performance of a contract — to provide services you have requested or are negotiating with us;
- Legitimate interests — to operate, secure, and improve our website and respond to inquiries, balanced against your rights;
- Consent — for non-essential cookies and any future marketing communications (you may withdraw consent at any time);
- Legal obligation — to comply with applicable law, tax, accounting, and regulatory requirements.
5. Sharing & Third-Party Services
We do not sell or rent personal information. We share information only with the following categories of recipients, and only as necessary:
- Service providers (processors) who help us run the business under contract — e.g., Formspree (our contact-form processor, headquartered in the United States), Cloudflare (DDoS mitigation, Turnstile bot challenge), email and cloud-storage providers, accounting and payment providers.
- Professional advisors such as lawyers, accountants, and auditors, where required.
- Authorities when required by law, valid legal process, or to protect the rights, property, or safety of BLD, our clients, or the public.
- Successors in connection with a merger, acquisition, financing, or sale of all or substantially all of our assets — subject to standard confidentiality protections.
A current list of our material sub-processors is available on request by emailing Leedesignco2026@gmail.com.
6. Cookies & Tracking Technologies
Our website uses a minimal cookie-consent banner. We use two categories of storage:
- Strictly necessary — small entries in your browser's local storage that remember your cookie-consent choice and basic site preferences. These cannot be disabled and do not require consent under GDPR Article 5(3) / ePrivacy.
- Analytics & functional — only set after you click "Accept" on our cookie banner. If you click "Reject," none of these are set, and any optional analytics scripts are not loaded for your session.
You can change your choice at any time by clicking or by clearing your browser storage. We do not use third-party advertising cookies, do not engage in cross-site behavioral tracking, and do not "share" personal information for behavioral advertising under U.S. state laws.
7. Data Retention
We retain personal information only as long as necessary for the purposes set out in this policy or as required by law:
- Active client records — for the duration of the engagement and seven (7) years thereafter for tax, accounting, and dispute-resolution purposes;
- Inactive inquiries — up to twelve (12) months from last contact, then deleted or fully anonymized;
- Server logs — up to thirty (30) days for security and diagnostic purposes;
- Cookie-consent records — twelve (12) months from your most recent choice.
When retention periods expire, we delete or irreversibly anonymize the information.
8. International Data Transfers
BLD is based in the United States. If you access the Services from outside the U.S., your information will be transferred to and processed in the United States, which may have different data-protection laws than your country.
Where we transfer personal data of EU/UK/EEA residents to the U.S. or other third countries, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable), with supplementary measures as required. Copies are available on request.
9. Security
We use reasonable and appropriate technical and organizational safeguards to protect personal information — including encryption in transit (TLS), encryption at rest where supported, access controls, principle-of-least-privilege, vendor due diligence, Content Security Policy on this site, bot-mitigation challenges on our contact form, and periodic review of our security posture. No system is perfectly secure; if we ever suffer a security incident affecting your data, we will notify you and the relevant authorities in line with Section 16.
10. Your Rights — EU / UK (GDPR & UK GDPR)
If you are in the EU, UK, EEA, or Switzerland, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting prior lawful processing;
- Lodge a complaint with your local supervisory authority (e.g., the UK ICO, France CNIL, Ireland DPC).
To exercise any right, email Leedesignco2026@gmail.com. We will respond within thirty (30) days and free of charge unless requests are manifestly unfounded or excessive.
11. Your Rights — California (CCPA / CPRA)
California residents have the following rights:
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it;
- Right to delete personal information we have collected from you, subject to exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing — BLD does not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of;
- Right to limit use of sensitive personal information — we do not collect or use sensitive personal information for inferring characteristics;
- Right to non-discrimination for exercising your rights.
You may exercise these rights yourself or through an authorized agent by emailing Leedesignco2026@gmail.com. We will verify your identity by matching identifying details against information already held. We do not charge a fee for verified requests.
Categories collected in the last 12 months: identifiers (name, email, phone), commercial information (project inquiries), internet/network activity (server logs, optional analytics with consent). Sold or shared: none.
12. Other U.S. State Privacy Rights
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another U.S. state with a comprehensive privacy law, you generally have rights similar to those listed in Sections 10–11, including the rights to access, correct, delete, opt out of targeted advertising and the sale of personal data, and (in some states) appeal a denial of a request. To exercise these rights or to submit an appeal, email Leedesignco2026@gmail.com.
13. Children's Privacy
The Services are intended for business users and are not directed to children under sixteen (16). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it promptly.
14. Do Not Track & Global Privacy Control
Some browsers transmit "Do Not Track" (DNT) and Global Privacy Control (GPC) signals. Because we do not engage in cross-site tracking or "sale" / "sharing" for behavioral advertising, these signals do not change our behavior in a meaningful way — however, we honor GPC as a valid opt-out signal for any future analytics or advertising that may be added.
15. Automated Decision-Making & Profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you.
16. Data Breach Notification
In the unlikely event of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify affected individuals and the relevant supervisory authority without undue delay, and in any case within seventy-two (72) hours of becoming aware, in accordance with GDPR Article 33–34 and applicable U.S. state breach-notification laws.
17. Changes to This Policy
We may update this policy from time to time. Material changes will be announced on this page with an updated "Effective" date, and where required by law, by direct notice. Continued use of the Services after a change becomes effective constitutes acceptance of the revised policy.
18. Contact & Complaints
To exercise your rights, ask questions, or file a complaint, contact:
BLD Technology Co.
Attn: Privacy
Port Washington, NY, USA
Email: Leedesignco2026@gmail.com
We will acknowledge your request within seven (7) business days and substantively respond within thirty (30) days (or longer where allowed by law, with notice). If you are not satisfied with our response, you have the right to contact your local data-protection authority.