Skip to main content
Robles Consulting
Legal

PrivacyPolicy

What we collect when you use this site, why we collect it, who processes it on our behalf, and how to make us delete it.

Last updated 10 September 2026

1. Who we are

Robles Consulting LLC (“Robles Consulting”, “we”, “us”) is an IT consulting firm registered in Texas, United States, operating this website at roblesconsultingllc.com.

For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the personal data described in this policy. Our registered contact details are:

Robles Consulting LLC100 Plaza Pl, Ste 300, PMB 58Northlake, TX 76226USAprivacy@roblesconsultingllc.com

Email is the fastest route for anything in this policy, including requests to see or delete what we hold about you.

This policy covers website enquiries and the personal data we use to administer consulting sessions. When we process data on a client’s behalf under a separate agreement, that agreement also governs how we handle the client’s data.

2. What we collect

Information you give us

Our inquiry forms ask for the information needed to reply and assess your request. Where email verification is available, we send a short-lived code to confirm that you control the address; no password is required.

The contact form collects your name, email address, and message, plus your business name and an indicative project budget if you choose to provide them.

Previously submitted site review requests include theaddress of your current website, your name and your email address, plus your phone number if you choose to give it. If you do, we also record whether you ticked the box agreeing to receive text messages from us about the review; you can withdraw that at any time by replying STOP.

A verified consulting scope request also collects the problem, desired outcome, existing system and development stage, budget range, timing, and your role in the decision. We keep it with your consulting contact and review task. You may choose an existing advisory draft to reuse its saved system context. Verification and submitting a request do not subscribe you to marketing.

If you email us directly, we hold that correspondence for as long as we need it to deal with the matter.

Website purchase preparation

Starting a website purchase saves a selected plan, catalog version, a permitted page path and a random purchase reference. It does not create a contact or subscribe you to marketing. A random token in your tab lets you recover that selection; the server stores only its hash. Payment and customer-account access require separate verification.

With analytics consent, that purchase context can include a bounded source, medium and campaign category, plus the version and time of your choice. It excludes raw URLs, arbitrary query text, advertising click IDs and email addresses. A referral from a link is captured only with this consent; a code you explicitly enter is processed as your purchase instruction. Recording a code does not promise a discount or commission.

Unused contexts expire after 24 hours and are removed by scheduled cleanup. Optional attribution expires after 30 days or is cleared when you withdraw consent; an explicitly entered referral remains a separate purchase instruction. A context already attached to checkout keeps the minimum recovery references until payment has been reconciled and its durable record saved, or the attempt is confirmed closed. Required payment records follow the retention rules below. We do not erase a potentially paid order merely because its attribution expires.

Information collected automatically

When you submit the contact or site review form, we also record:

  • Your IP address and browser user-agent string. These are stored alongside your submission and are used to investigate abuse and spam.
  • A timestamp of the submission.

For email verification, we retain short-lived challenge and session records, timestamps, and hashed rate-limit identifiers to prevent abuse. The verification service does not store your raw IP address or browser user-agent with the scope request. Codes expire after 10 minutes and verified sessions after 30 minutes; expired verification records are removed by scheduled cleanup. Necessary cookies keep verification tied to your browser. See our Cookie Policy.

Cloudflare, which serves this site, processes request data including IP addresses to deliver pages and to protect against attacks. Cloudflare Turnstile runs on our forms to distinguish humans from bots; it is a privacy-focused alternative to a traditional CAPTCHA and does not profile you across sites.

Analytics: only with your consent

We load no analytics and set no analytics cookie unless you accept it. If you do, PostHog records page categories, selected offers and durations, calls-to-action, and inquiry starts, attempts, failures and successful submissions. For online session purchases, we also record which step is viewed, checkout attempts and failures, clicks to Google scheduling, and acknowledged help requests. These observations do not establish a payment or confirmed appointment.We also record a broad referral-source category, an optional project-budget range and whether company or phone information was provided, not those details themselves. We do not send names, email addresses, phone numbers, message contents, raw URLs, query strings or private links to analytics. Session recording, surveys and automatic text capture are disabled. An inquiry is not a payment or confirmed booking.

If your browser sends a Global Privacy Control signal, we treat that as a refusal and never ask again unless you opt in yourself. See our Cookie Policy for the full list.

What we never collect here

This site takes no payments, so we hold no card or bank details. We do not ask for special-category data (health, biometrics, political or religious views, and so on), we do not buy personal data from data brokers, and we do not build advertising profiles.

3. Why we use it, and our legal basis

Where the GDPR applies, we rely on the following bases. Where it does not, we still limit ourselves to these purposes.

Purposes for processing personal data and the corresponding legal basis
PurposeData usedLegal basis
Reply to your enquiry and scope potential workName, email, business name, budget, message and scope qualification detailsLegitimate interests, and steps preparatory to a contract at your request
Keep a record of enquiries so we can pick up the thread laterThe submission and its timestampLegitimate interests in running our business
Stop spam and abuse of our formsIP address, user-agent, Turnstile resultLegitimate interests in the security of our systems
Understand which pages are useful and improve the siteAnalytics eventsYour consent, which you can withdraw at any time
Meet legal, tax, and accounting obligationsCorrespondence relating to an engagementCompliance with a legal obligation

We do not use your data to make automated decisions that have a legal or similarly significant effect on you, and we do not use it to train machine learning models.

We will only send you marketing email if you ask us to. Replying to your enquiry is not marketing.

Our CRM emails currently use neither invisible open-tracking pixels nor click-tracking link rewriting. We record operational delivery, bounce, complaint, unsubscribe, and direct reply events needed to deliver and respond to the communication. We will update this notice before enabling additional email engagement tracking.

4. Who we share it with

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We use a small number of service providers who process data on our instructions, under contract:

Service providers that process personal data on our behalf
ProviderWhat it doesWhat it sees
CloudflareHosting, CDN, the database that stores form submissions, and Turnstile bot protectionRequest metadata including IP address; the contents of your submission
ResendDelivers form notifications and CRM email, receives replies, and reports operational delivery or suppression eventsYour name, email, business details, message, and subsequent email correspondence
PostHogProduct analytics (only runs if you accept analytics cookies)Analytics events and a randomly generated visitor identifier
Our email providerHosts the business mailbox where your enquiry lands and is readYour enquiry and any subsequent correspondence

Fonts on this site are served from our own domain, not from a third party, so loading a page does not tell any font provider that you visited.

Beyond these providers, we disclose personal data only where we are legally required to (for example a valid legal request), where we need to establish or defend a legal claim, or as part of a merger or sale of the business. In which case we will tell you before your data becomes subject to a different policy.

5. International transfers

We are established in the United States, and the providers listed above are predominantly US-based. If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your personal data is transferred outside your home jurisdiction when you contact us.

Where such a transfer happens, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our agreements with those providers, or on their certification under the EU-US Data Privacy Framework where they hold one. You can ask us for details of the safeguards that apply to a specific provider.

6. How long we keep it

  • Nonessential intake and correspondence: we review and remove unnecessary content by 24 months after our last contact with you. We retain specific records longer when needed for an open engagement or a documented hold.
  • Consulting working copies and temporary access: we remove our working copies and revoke our temporary access within 30 days after the work is completed or the engagement is closed by agreement, unless a documented legal obligation requires retention. We prefer customer-controlled materials and screen sharing, with no recording by default.
  • Purchase and payment evidence: we retain the minimum records of accepted terms, purchases, payments, tax and disputes for seven years after the transaction’s tax year, then review them for disposal. We keep specific records longer where legally required or needed to resolve an outstanding obligation. A retention date does not make a paid consulting session expire.
  • IP addresses and user-agent strings held for security: 12 months from the submission.
  • Analytics data: 12 months, if you consented to it.
  • Your cookie choice: stored in your own browser and never sent to us. We ask again after twelve months.

Restricted recovery copies may retain removed data until their recovery window ends. If we restore a backup, we reconcile recorded removals before returning the data to normal use. Providers may retain records under their own legal obligations; we explain any applicable limits when handling a deletion request.

You can ask us to delete your data sooner; see below. We will do so unless we are required to keep it.

7. Your rights

If the EU or UK GDPR applies to you, you have the right to: be told what we hold about you and get a copy of it; have inaccurate data corrected; have your data deleted; restrict how we use it; object to processing we base on legitimate interests; receive your data in a portable format; and withdraw consent at any time, which is as easy to do as it was to give. Use the Cookie settings link in the footer of any page.

To exercise any of these, email privacy@roblesconsultingllc.com. We will respond within one month. We may ask you to confirm your identity before we act, and we will not charge you for a reasonable request.

If you are unhappy with how we have handled your data, you can complain to your national data protection authority. In the EU, the supervisory authority where you live or work; in the UK, the Information Commissioner’s Office. We would appreciate the chance to put it right first.

8. US state privacy rights

If you are a resident of California, Colorado, Connecticut, Texas, Virginia, or another state with a comprehensive privacy law, you may have the right to know what personal information we have collected about you, to have it corrected or deleted, to receive a copy of it, and not to be discriminated against for exercising those rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. There is therefore nothing to opt out of on that front, though we honour Global Privacy Control signals regardless.

To make a request, email privacy@roblesconsultingllc.com. You may use an authorised agent; we will ask for proof of their authority.

9. Cookies and analytics

The strictly necessary items, Cloudflare’s security check and the record of your cookie choice, are always active because the site cannot work properly or respect your preference without them. Everything else waits for your consent.

Our Cookie Policy lists each cookie and storage entry, what it is for, and how long it lasts, and lets you change your choice.

10. Security

The site is served over HTTPS. Form submissions are validated and bot-checked before they are accepted, and stored in an access-controlled database. Access to enquiry data is limited to the people at Robles Consulting who need it in order to respond to you.

No system is perfect. If you believe you have found a security issue with this site, please email privacy@roblesconsultingllc.com and we will look at it promptly. If a breach affects your personal data and poses a risk to you, we will notify you and the relevant regulator as the law requires.

11. Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

12. Changes to this policy

If we change how we handle personal data, we will update this page and the “last updated” date above. Where a change materially affects you, we will do more than that. For a change that requires consent, we will ask again rather than assume.

Contact us

Questions about this policy, or want us to delete what we hold about you? Email us and we will get back to you within one month, usually much sooner.

privacy@roblesconsultingllc.com

Prefer to start somewhere else? Use the contact form, or write to us at 100 Plaza Pl, Ste 300, PMB 58, Northlake, TX 76226, USA.