Legal
Privacy Policy
Effective Date: October 5, 2026 · Applicable Regions: United States (including California & New York)
1. Scope
This Privacy Policy applies to:
- Website visitors
- Prospective clients
- Business contacts
Client-specific data handling is governed by separate agreements (MSA/DPA).
2. Categories of Data Collected
(A) Personal Information
- Name
- Phone
- Employer / Firm
(B) Technical Data
- IP address
- Device identifiers
- Browser metadata
(C) Business & Infrastructure Data — if engaged as a client:
- Network architecture
- Security controls
- Vendor ecosystem
- Logs and system data
3. Purpose of Processing
We process data for:
- Service delivery
- Cybersecurity monitoring
- Regulatory alignment support
- Website analytics and conversion measurement (active by default; opt out via the consent banner)
- Legal compliance
- Delivering the quarterly Newsletter after you confirm your subscription by email
4. Legal Basis
Processing is based on:
- Legitimate business interests
- Contractual necessity
- Legal obligations
5. Data Sharing & Subprocessors
We may share data with:
- Cloud infrastructure providers
- Security vendors
- Professional advisors (legal, audit)
- Analytics and advertising measurement platforms (active by default; you may opt out via the consent banner)
All vendors are subject to confidentiality obligations and security review where applicable.
Sender processes Newsletter email addresses, subscription status, and messages. Email opens and link clicks are measured; confirmation-link clicks are also used to verify your subscription request. You can unsubscribe using the link in each Newsletter; suppression records may be retained to prevent further sends.
Our consultation, document request, Chat fallback, and Newsletter forms use Google reCAPTCHA for spam protection. The verification widget connects to Google separately from our optional analytics. Google's Privacy Policy and Terms of Service apply.
6. No Sale of Personal Information
Chadsel LLC does not sell personal information, as defined under CCPA / CPRA.
7. Data Security Program
We maintain a security program aligned with:
- NIST Cybersecurity Framework
- Industry-standard controls
- Least privilege access model
Controls may include:
- Encryption (at rest / in transit)
- Endpoint protection
- Monitoring & logging
- Incident response procedures
8. Incident Response
In the event of a data incident:
- We will investigate promptly
- Notify affected parties where legally required
- Coordinate with clients under contractual obligations
9. Data Retention
We retain data only as necessary for business or legal purposes, in accordance with contractual obligations. Secure deletion practices are applied where appropriate.
10. AI Chat, Analytics & Session Data
Our website includes an AI chat assistant powered by our own AI bot runtime (currently OpenClaw), a private AI agent running on Chadsel LLC-operated infrastructure. When you use the chat feature:
- Analytics & advertising measurement: We load analytics and conversion-measurement tags through Google Tag Manager by default, including Google Analytics 4 and ad-platform measurement tools for site performance, call clicks, downloads, and form submissions. If you click Decline on the consent banner, all analytics and ad storage consent signals are set to denied and no measurement data is collected.
- Transcripts: Conversation messages are processed in memory to generate responses. If you choose to submit your email at the end of a session, a brief AI-generated summary of the conversation (not the full transcript) may be stored in our lead records file alongside your email address.
- Session data: A session ID is stored in your browser's localStorage for up to 4 hours to maintain conversation continuity. This requires your consent (via the banner on our site). If you decline consent, no session data is written to localStorage.
- Third-party AI: That runtime is operated by Chadsel LLC on our own infrastructure. No conversation data is transmitted to OpenAI, Anthropic, or any third-party AI provider.
- Azure Communication Services (ACS): If you submit your email via the chat widget or contact form, a notification email is sent to our sales team via Microsoft Azure Communication Services. ACS processes your email address solely to deliver this notification and does not retain it for advertising purposes.
- Email campaign links: Links in business outreach emails may contain a random, opaque identifier. When the link is requested, our website records the request time, limited browser metadata, and the intended recipient associated with that identifier in our own lead system. The identifier is removed by a server-side redirect before the destination page loads. We use aggregate UTM campaign labels with Google Analytics and do not send the recipient's name, email address, lead identifier, or opaque link identifier to Google Analytics.
- Automated link checks: Email security products may request links before a person clicks them. We label activity as suspected automation using request-method, prefetch-header, and user-agent heuristics; that label is not treated as definitive proof of human activity.
- Retention: Lead records (email + AI summary) are retained for 12 months and then deleted. You may request deletion at any time by emailing privacy@chadsel.com.
11. California Privacy Rights (CCPA/CPRA)
California residents may:
- Request access
- Request deletion
- Request correction
Submit requests via: privacy@chadsel.com
We will respond within legally required timeframes.
12. New York Data Considerations
For New York-based financial clients, data handling may align with NYDFS cybersecurity expectations. Additional obligations are governed by contract.
13. Cross-Border Data
Data may be processed within the United States. We do not intentionally transfer data internationally unless required for service delivery.
14. Third-Party Services
We are not responsible for third-party privacy practices. Users should review external policies separately.
15. Children's Data
We do not knowingly collect data from individuals under 18.
16. Updates
We may update this Policy periodically. Continued use of the Site constitutes acceptance of the current version.
17. Contact
Chadsel LLC
New York, NY & Long Beach, CA
privacy@chadsel.com
Chadsel LLC