Privacy Policy

AKTA Treasures, the developer and operator of this website, publishes this Privacy Policy on behalf of AKTA TREASURES, LLC to explain how personal information is collected, used, stored and protected when you visit www.aktatreasures.lol or engage the practice for services. The policy applies to the website, to email correspondence, to telephone conversations and to information exchanged during a professional engagement. Please read it in full before submitting any information to the practice. If any part of this policy is unclear, contact the office at shop@aktatreasures.lol and a principal will explain it.

1. Scope and Controller Identity

This Privacy Policy governs the processing of personal information by AKTA TREASURES, LLC, a company whose registered address is 4244 S 4000 W, West Valley City - 84120-5340, United States (US). The company acts as the controller for personal information that it collects directly from clients, prospective clients, website visitors, suppliers and professional contacts. Where the company processes information on behalf of a client during a systems design or integration engagement, the client is the controller and the company acts as a processor under the terms of the relevant engagement agreement.

The policy covers all interactions with the practice, whether through the website, by email at shop@aktatreasures.lol, by telephone at +12799994093, or in person at the West Valley City office. It does not cover third party websites that may be linked from this site, each of which maintains its own privacy practices. The practice encourages visitors to review the privacy notices of any external resource before submitting personal information to it.

This policy is written to be as plain as possible. It avoids ambiguous phrasing and sets out the practical consequences of each commitment. Where the company must rely on a legal basis that carries conditions, those conditions are described in the relevant section rather than left implicit.

2. Information We Collect

The practice collects information that visitors and clients choose to provide, together with limited technical information generated automatically when the website is used. Information provided voluntarily includes names, email addresses, telephone numbers, company names, job titles and the content of messages sent through the contact form or by email. When a client engages the practice, additional information may be collected that is necessary to perform the engagement, such as system inventories, network diagrams, architectural documentation and the names of staff who participate in workshops.

Information collected automatically includes the internet protocol address from which a request is made, the browser type and version, the operating system family, the pages viewed and the time of the visit. This information is used in aggregate to understand how the site is used and to protect it from abuse. The practice does not attempt to identify individual visitors from this technical data except where necessary to investigate a security incident or to comply with a legal obligation.

The practice does not seek to collect special category information such as health data, biometric identifiers, political opinions, religious beliefs or trade union membership. Visitors should not send such information through the website or by email. If a client engagement genuinely requires the processing of sensitive information, the practice will agree the appropriate safeguards in writing before any such information is transferred.

3. How We Use Information

Personal information is used to answer enquiries, prepare proposals, deliver services, maintain professional records, issue invoices, comply with tax and accounting obligations and improve the quality of the website. When a visitor sends a message, the information in that message is used to understand the request and to reply. When a client engages the practice, information is used to plan and deliver the engagement, to communicate about progress and to produce the deliverables that were agreed.

The practice also uses information to maintain the integrity of its own record keeping, which is central to the way the practice works. Correspondence, decisions and deliverables are retained as part of the engagement archive so that work can be explained and audited long after it concludes. This archive discipline is described in more detail in the retention section below.

Information is never sold, rented or traded. The practice does not use personal information to build advertising profiles, and it does not permit third parties to use information collected through this website for their own marketing purposes. Any use of information beyond the purposes described here would require a fresh legal basis and would be communicated in advance.

Where data protection law requires a lawful basis, the practice relies on one or more of the following. Consent applies where a visitor actively agrees to receive information or to allow a specific use that is not otherwise necessary. Performance of a contract applies where processing is required to deliver services that have been agreed with a client. Legitimate interests apply where the practice needs to respond to enquiries, protect its systems, maintain professional records or improve its services in ways that do not override the rights of individuals.

Legal obligation applies where the practice must retain or disclose information to satisfy tax, accounting, regulatory or court requirements. Vital interests would apply only in an emergency where processing is necessary to protect life. Where the practice relies on legitimate interests, it carries out a balancing assessment and records the outcome so that the reasoning can be reviewed if circumstances change.

Individuals may withdraw consent at any time where consent is the basis for processing. Withdrawal does not affect processing that took place before the withdrawal, and it does not affect processing that rests on another lawful basis such as a legal obligation to retain records.

5. Cookies and Similar Technologies

The website is designed to operate with the smallest possible data footprint. Essential cookies may be used to remember a navigation preference or to protect a form against cross site request forgery. These cookies do not track visitors across other websites and are not used for advertising. Where a cookie is strictly necessary for the site to function, it is set on the basis of the legitimate interest in operating a secure and reliable service.

Analytics, where used at all, is configured to avoid identifying individuals. Measurement data is aggregated and reviewed only to understand which pages are useful and where visitors encounter difficulty. The practice does not embed advertising networks, social media pixels or cross site tracking tools on this website. Visitors may block or delete cookies through their browser settings; doing so may affect the operation of some features but will not prevent access to the informational content of the site.

The practice reviews its use of cookies regularly and removes any technology that is no longer necessary. A change in the categories of cookies used would be reflected in an update to this policy, and any cookie that requires consent would be presented with a clear choice before it is set.

6. Sharing and Disclosure

Personal information is shared only where it is necessary and where appropriate safeguards are in place. The practice may share information with professional advisers such as accountants and lawyers, with insurers, and with service providers who support the operation of the website and the delivery of services. Each of these recipients receives only the information needed for the specific task and is bound by confidentiality obligations.

The practice may disclose information where required by law, by a valid court order, by a regulator or by a public authority acting within its powers. Where disclosure is compelled, the practice will disclose only what is legally required and will, where permitted, inform the affected individual so that a challenge can be considered. The practice does not disclose information to third parties for their own marketing purposes under any circumstances.

If the practice is involved in a merger, acquisition, reorganisation or sale of assets, information may be transferred as part of that transaction. Any successor would be required to honour this policy in respect of information collected before the transfer, and affected individuals would be notified of any material change in the controlling entity.

7. Service Providers and Sub-processors

The practice uses a small number of service providers for hosting, email, accounting and document management. These providers are selected for reliability and for their ability to meet recognised security standards. Each provider is engaged under a written agreement that requires confidentiality, limits processing to the instructions of the practice, imposes security obligations and sets out the terms on which information is returned or deleted at the end of the relationship.

Where a provider processes information outside the country of the individual concerned, the practice relies on appropriate transfer mechanisms and applies additional safeguards where the legal environment requires them. The practice maintains a current list of providers and reviews it at least annually to confirm that each relationship remains necessary and that each provider still meets the required standard.

Clients who need to understand which providers may touch their information during an engagement can request a summary from shop@aktatreasures.lol. The practice will provide this information subject to any confidentiality obligations it owes to the providers themselves and to any security considerations that apply to the disclosure.

8. Data Retention

Information is retained only for as long as it is needed for the purpose for which it was collected, for as long as the law requires, or for as long as is necessary to protect the legitimate interests of the practice. Enquiry correspondence is normally retained for three years so that a continuing relationship can be understood and so that previous advice can be located. Engagement records, including architectural documentation and decision registers, are retained for the life of the relevant system and for a defined period afterwards, because the value of such records lies in their availability many years later.

Financial records are retained for the period required by tax and accounting law. Where information is no longer needed, it is deleted or anonymised in a controlled manner. Deletion is carried out across live systems, backups and archives within a reasonable period, and the practice records that the deletion took place.

Where a client requests deletion of engagement records before the end of the retention period, the practice will comply to the extent permitted by law and by its professional obligations. In some cases a minimum record must be kept to evidence that work was performed and to defend against future claims; the practice will explain any such limitation clearly when it applies.

9. Security Measures

The practice applies technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure or destruction. Measures include encrypted transport for data in transit, access controls that limit information to staff who need it, unique credentials for each system, routine patching of infrastructure, protected backups and the logging of administrative activity. Physical records held at the West Valley City office are kept in locked storage with controlled access.

Staff and contractors receive confidentiality obligations and are trained on the practical handling of information. Access is reviewed regularly, and accounts are removed promptly when a person leaves the practice or changes role. Providers are held to equivalent standards through their agreements and through periodic review.

No method of transmission or storage is completely secure, and the practice cannot guarantee absolute security. It commits instead to maintaining defences proportionate to the sensitivity of the information, to testing those defences, and to acting promptly and transparently if an incident occurs. Individuals who suspect a security issue should contact shop@aktatreasures.lol immediately so that it can be investigated.

10. Your Privacy Rights

Depending on where an individual lives, privacy law may grant specific rights over personal information. These commonly include the right to be informed about processing, the right of access to information held, the right to correction of inaccurate information, the right to deletion in defined circumstances, the right to restrict processing, the right to object to processing based on legitimate interests, and the right to data portability. The practice honours these rights for all individuals regardless of location, because consistent treatment is simpler to maintain and easier to explain.

Requests to exercise a right can be made by email to shop@aktatreasures.lol or by post to AKTA TREASURES, LLC, 4244 S 4000 W, West Valley City - 84120-5340, United States (US). The practice will acknowledge a request promptly and will respond within the period required by applicable law, normally within thirty days. Where a request is complex or where several requests are received, the response may take longer, and the individual will be told why.

The practice may ask for information to confirm identity before acting on a request, to ensure that information is not disclosed or deleted in error. A request will not be refused on the basis of identity alone where the individual can reasonably demonstrate that the information relates to them.

11. Access, Correction and Deletion

An individual may ask what personal information the practice holds about them, why it is held, who it has been shared with and how long it will be retained. The practice will provide a copy of the relevant information together with an explanation of the processing. Where information has been shared with a provider or adviser, the practice will identify the recipient so that the individual can follow up if they wish.

If information is inaccurate or incomplete, the individual may ask for it to be corrected. The practice will make the correction and, where the information was previously shared, will notify the recipient where that is possible and lawful. If the practice disagrees that information is inaccurate, it will explain its reasoning and record the disagreement so that it is visible in future.

An individual may ask for information to be deleted. The practice will delete information that is no longer necessary, unless it must be kept to comply with a legal obligation, to resolve a dispute or to enforce an agreement. Where deletion cannot be completed immediately, the practice will explain the reason and the expected timeframe. Where information has been made public, the practice will take reasonable steps to inform others who hold it that deletion has been requested.

12. Data Portability

Where processing is based on consent or on the performance of a contract and is carried out by automated means, an individual may ask to receive their information in a structured, commonly used and machine readable format. The practice will provide the information in such a format and, where technically feasible, will transmit it directly to another controller at the request of the individual.

Portability applies only to information that the individual provided to the practice. It does not extend to information that the practice generated as part of an engagement, such as architectural analysis or derived records, although the practice will usually provide such material to a client on request as part of the engagement archive. Any refusal will be explained and will be limited to the extent permitted by law.

Requests for portability are handled through the same contact route as other rights. The practice will confirm the format and the method of delivery before preparing the export, so that the information arrives in a usable condition.

13. Privacy for Children

This website and the services of the practice are intended for businesses and professional audiences. The practice does not knowingly collect personal information from children under the age of sixteen. If the practice becomes aware that information has been collected from a child without appropriate consent, it will delete that information promptly and will take steps to prevent a recurrence.

Parents and guardians who believe that a child has submitted information to the practice should contact shop@aktatreasures.lol so that the matter can be investigated and resolved. The practice will not require a parent or guardian to provide more information than is necessary to confirm the request and to complete the deletion.

Where a legitimate business need involves information about minors, for example in an education sector engagement, the practice will handle that information under the client contract and will apply additional safeguards, including minimisation and restricted access, as agreed in writing with the client.

14. International Transfers

The practice is based in the United States and primarily processes information there. Where information is transferred from another country, the practice ensures that an appropriate transfer mechanism is in place before the transfer occurs. Such mechanisms may include standard contractual clauses, an adequacy decision, or another lawful basis recognised by the relevant jurisdiction.

Where a transfer could expose information to laws that do not provide an equivalent level of protection, the practice assesses the risk and applies supplementary measures such as encryption, pseudonymisation or restricted access. The outcome of each assessment is recorded so that the reasoning can be reviewed if the legal environment changes.

Individuals who wish to understand the transfer arrangements that apply to their information may contact shop@aktatreasures.lol. The practice will explain the mechanism in use and the safeguards applied, subject to any confidentiality obligations that apply to the underlying agreements.

15. Marketing Communications

The practice sends occasional updates about services and about significant developments in systems design and enterprise integration. These messages are sent only where an individual has requested them or where an existing professional relationship makes them relevant, and every message includes a simple method to stop receiving further communications. Requests to unsubscribe are honoured promptly and without requiring a reason.

The practice does not share contact details with third parties for marketing purposes and does not purchase contact lists. Where an individual opts out of marketing, the practice may still contact them about an active engagement, a contractual matter or a legal obligation, because those communications are necessary rather than promotional.

If an individual is unsure why they are receiving a message, they may contact shop@aktatreasures.lol and the practice will explain how the contact details were obtained and will remove them if they wish.

16. Automated Decision Making

The practice does not use personal information to make automated decisions that produce legal effects or that significantly affect an individual. Decisions about engagements, proposals and service delivery are made by people, with the support of documentation and analysis that is open to review. Profiling for advertising purposes is not carried out.

If a future service requires automated decision making, the practice will describe the logic involved, the significance of the decision and the envisaged consequences before the processing begins. Individuals would be offered a route to request human intervention, to express a point of view and to contest a decision. This policy would be updated before any such change took effect.

Any analysis the practice performs is directed at systems and architectures rather than at individuals, and its purpose is to improve reliability and security rather than to evaluate people.

17. Third Party Links

This website may contain links to external resources that the practice considers useful. The practice does not control those resources and is not responsible for their privacy practices, their content or their availability. Visiting an external site is done at the visitor own discretion, and the privacy notice of that site will govern the handling of any information provided to it.

The practice recommends that visitors review the privacy notice of any external site before submitting personal information. A link from this website does not imply endorsement of the practices of the destination, and the practice cannot guarantee that a destination will handle information in a manner consistent with this policy.

If a visitor believes that a linked resource is inappropriate or unsafe, they may report it to shop@aktatreasures.lol and the practice will review the link and remove it where removal is warranted.

18. Data Breach Notification

The practice maintains procedures to detect, investigate and respond to security incidents. If a breach occurs that is likely to result in a risk to the rights and freedoms of individuals, the practice will notify the relevant supervisory authority without undue delay and, where required, will notify affected individuals directly. Notifications will describe the nature of the breach, the likely consequences and the measures taken or proposed to address it.

The practice will also take immediate steps to contain a breach, to preserve evidence, to assess the scope and to reduce the risk of recurrence. Internal records of all incidents are kept, including those that do not meet the threshold for external notification, so that patterns can be identified and addressed.

Individuals who notice unusual activity connected with the practice should contact shop@aktatreasures.lol so that the matter can be investigated quickly. Early reporting materially improves the ability to contain an incident and to protect others.

19. Changes to This Policy

The practice may update this policy to reflect changes in law, in technology or in the way services are delivered. The date at the top of the page indicates when the current version took effect. Material changes will be communicated through a prominent notice on the website and, where appropriate, by direct communication to clients and contacts.

Continued use of the website or continued engagement with the practice after a change takes effect indicates acceptance of the revised policy. Individuals who do not agree with a change may stop using the website or may contact the practice to discuss their concerns and, where applicable, to exercise their rights.

Previous versions of this policy are retained in the engagement archive and may be requested from shop@aktatreasures.lol. This retention is consistent with the record keeping discipline that the practice applies to all of its work.

20. How to Contact the Practice

Questions, requests and complaints about privacy may be sent to AKTA TREASURES, LLC by email at shop@aktatreasures.lol, by telephone at +12799994093, or by post at 4244 S 4000 W, West Valley City - 84120-5340, United States (US). The practice aims to acknowledge every privacy enquiry promptly and to resolve it within the period required by applicable law.

Where an individual is not satisfied with the response, they may raise the matter with the supervisory authority in their jurisdiction. The practice will cooperate fully with any such authority and will provide the records needed to resolve the concern.

The practice welcomes feedback on this policy. Clear comments from clients and visitors help to keep the policy accurate and useful, and every suggestion is read by a principal.