GJReyes LLC
Privacy Policy
Last Updated: July 31, 2026 — Effective Date: July 31, 2026
Table of Contents
- Introduction and Scope
- Definitions and Interpretation
- Information We Collect
- How We Collect Information
- Purposes of Processing
- Legal Bases for Processing
- Cookies and Tracking Technologies
- Information Sharing and Disclosure
- Data Retention and Deletion
- Data Security Measures
- International Data Transfers
- Your Rights and Choices
- Children--s Privacy
- Third-Party Services
- Changes to This Policy
- Contact Information and Complaints
1. Introduction and Scope
GJReyes LLC (we, our, or us) is committed to protecting the privacy and security of individuals who interact with our website, services, and business operations. This Privacy Policy explains in detail how we collect, use, disclose, retain, and safeguard information about visitors to our website located at https://www.gjreyes.hair (the Website), individuals who contact us through the Website or by other means, clients who engage our computer systems design and professional technical services, and any other person whose information we may process in the course of our business activities.
This policy was drafted under the direction of GJ Reyes, founder of GJReyes LLC, and reflects our organizational commitment to transparent data practices. As a firm operating within the Computer Systems Design and Related Services industry (NAICS 541512), we understand the critical importance of data governance -- not only for our clients but for every individual whose information touches our systems.
By accessing or using the Website, engaging our services, or otherwise providing information to us, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. If you do not agree with any provision of this policy, you must discontinue use of the Website and refrain from providing personal information to us.
This Privacy Policy applies to all information collected through: (a) the Website; (b) email and other electronic communications between you and GJReyes LLC; (c) telephone and in-person interactions; (d) client engagement and service delivery processes; (e) any offline collection points where this policy is referenced or made available; and (f) third-party platforms and services integrated with our Website or operations, to the extent we control the data flows involved.
This policy does not apply to information collected by third-party websites, applications, or services that may link to or be accessible from our Website, even if we reference or recommend them. We encourage you to review the privacy policies of any third-party services before providing them with your information.
1.1 Geographic Scope
GJReyes LLC is headquartered in Layton, Utah, United States, and our primary operations are conducted within the United States. However, because the Internet is inherently global, individuals from any jurisdiction may access our Website. We endeavor to comply with applicable data protection laws in jurisdictions where we offer our services or where our users are located, including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR) to the extent applicable, and other relevant state and federal privacy statutes. If the data protection laws of your jurisdiction impose requirements beyond those described in this policy, we will make reasonable efforts to accommodate your rights as required by law.
1.2 Policy Updates and Versioning
We reserve the right to modify, amend, or replace this Privacy Policy at any time in our sole discretion. When we make material changes, we will update the --Last Updated-- date at the top of this page and, where appropriate, provide a more prominent notice on the Website or via direct communication. We encourage you to review this policy periodically to stay informed about our data practices. Your continued use of the Website after any changes constitutes acceptance of the revised policy. Archived versions of this policy are available upon request.
2. Definitions and Interpretation
For the purposes of this Privacy Policy, the following terms have the meanings set forth below. Capitalized terms not defined in this section shall have the meanings given elsewhere in this policy.
2.1 Personal Information
Personal Information means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This includes, but is not limited to: name, email address, postal address, telephone number, IP address, device identifiers, online activity data, professional or employment-related information, and any other data that could be used to distinguish or trace an individual--s identity. For residents of California, Personal Information has the meaning given in the California Consumer Privacy Act and its implementing regulations. For individuals in the European Economic Area, Personal Information corresponds to personal data as defined in Article 4 of the GDPR.
2.2 Processing
Processing means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
2.3 Sensitive Information
Sensitive Information includes data elements that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed solely to identify a human being, health-related data, or data concerning a person--s sex life or sexual orientation. GJReyes LLC does not knowingly collect or process Sensitive Information through the Website or in the ordinary course of providing our computer systems design services.
2.4 Data Controller and Data Processor
For purposes of this policy, GJReyes LLC acts as the Data Controller with respect to Personal Information collected directly through the Website and our marketing activities. In the context of client engagements where we provide professional technical services, we may act as a Data Processor or Service Provider on behalf of our clients, in which case the client--s privacy policy governs the processing of data within the scope of the engagement, and we process such data solely in accordance with the client--s documented instructions and our contractual obligations.
3. Information We Collect
We collect several categories of information, each described in detail below. The specific information we collect depends on the nature of your interaction with us and the services you request.
3.1 Identity and Contact Information
When you fill out a contact form, request a consultation, subscribe to communications, or otherwise engage with us, we may collect: full name (first and last), email address, telephone number, company or organization name, job title or role, postal or business address (including street, city, state, postal code, and country), and any other identifying details you voluntarily provide in your message or communication. This information is necessary for us to respond to your inquiries, provide requested services, and maintain our business relationship.
3.2 Technical and Usage Information
When you visit the Website, our servers automatically collect certain technical data about your device and browsing activity. This includes: Internet Protocol (IP) address, browser type and version, operating system and platform, device type and screen resolution, referring source and exit pages, date and time of visit, pages viewed and time spent on each page, clickstream data and navigation patterns, language preferences, and approximate geographic location derived from your IP address. This information is collected through server logs and analytics tools and is used to maintain and improve the Website, diagnose technical issues, and understand aggregate usage trends.
3.3 Communication Data
We retain records of communications you send to us, including emails sent to hello@gjreyes.hair, messages submitted through our contact forms, telephone call records (with notification where required), and any attachments, documents, or other materials transmitted in the course of such communications. We also maintain records of our responses to your inquiries and any follow-up correspondence. This data may include the content of the communication itself, timestamps, and metadata associated with the transmission.
3.4 Client Engagement Data
In the course of providing computer systems design, IT consulting, and professional technical services, we may receive or generate information related to our clients-- technology environments. This may include system architecture diagrams, network configurations, infrastructure specifications, software inventory, vendor contracts, and other technical documentation. While this information is typically organizational rather than personal in nature, it may incidentally contain personal information of client personnel, such as system administrator contact details or user account information within client-managed systems.
3.5 Marketing and Preference Data
If you opt in to receive marketing communications from us, we may collect and maintain your communication preferences, subscription status, topics of interest, event attendance history, and engagement with our marketing emails (such as open rates and click-through data). You may unsubscribe from marketing communications at any time using the link provided in each email or by contacting us directly.
4. How We Collect Information
We collect information through multiple channels and methods, each of which is described below to provide full transparency into our data collection practices.
4.1 Direct Collection from You
The primary method by which we obtain Personal Information is through your voluntary submission. This occurs when you: complete and submit a contact form on the Website; send an email to any GJReyes LLC email address; call our business telephone number (+1 (601) 996-7918) and provide information verbally; correspond with us through postal mail at our business address (364 Hillgate Way, Layton, Utah 84041-1374); provide a business card or contact details during a meeting, conference, or networking event; or register for or participate in any event, webinar, or consultation organized by GJReyes LLC.
4.2 Automated Collection
As described in Section 3.2, certain information is automatically collected when you interact with the Website. This collection occurs through standard web server logging, analytics scripts that execute in your browser, and similar passive collection mechanisms. Automated collection does not require any affirmative action on your part beyond visiting the Website. You may limit certain types of automated collection through browser settings (such as disabling cookies or enabling --Do Not Track-- signals), though doing so may affect the functionality and user experience of the Website.
4.3 Collection from Third Parties
In limited circumstances, we may receive Personal Information about you from third-party sources. These may include: publicly available sources such as business registries and professional networking platforms; referral sources, where an existing client or business contact introduces you to our services; social media platforms, where you interact with GJReyes LLC content; and service providers who assist with marketing, analytics, or business development functions and share data with us in accordance with their own privacy policies and applicable law. When we receive information from third parties, we apply the same protections described in this policy.
5. Purposes of Processing
We process Personal Information for specific, explicit, and legitimate purposes. We do not process Personal Information in a manner that is incompatible with the purposes for which it was collected unless we obtain your consent or are required or permitted to do so by law.
5.1 Service Delivery and Client Engagement
We use Personal Information to: respond to inquiries and provide information about our services; prepare proposals, statements of work, and engagement agreements; perform computer systems design, architecture, consulting, and integration services; manage client relationships and communicate about project progress, milestones, and deliverables; process payments and manage billing and invoicing; and provide post-engagement support, maintenance notifications, and follow-up services as agreed upon with clients.
5.2 Website Operation and Improvement
We process technical and usage information to: operate, maintain, and optimize the Website; monitor and analyze usage patterns and trends to improve content, navigation, and user experience; detect, prevent, and address technical issues, errors, and security vulnerabilities; conduct aggregate analytics to understand how visitors interact with the Website; and test and deploy new features, pages, and functionality.
5.3 Communication and Marketing
Subject to applicable consent requirements, we use Personal Information to: send newsletters, thought leadership content, and informational materials about the computer systems design industry; notify you about changes to our services, policies, or terms; invite you to events, webinars, or professional gatherings; respond to your comments, questions, and requests for support; and administer surveys, feedback requests, and market research initiatives.
5.4 Legal and Regulatory Compliance
We may process Personal Information as necessary to: comply with applicable laws, regulations, legal processes, and governmental requests; enforce our Terms of Service and other contractual agreements; investigate and defend against legal claims, disputes, or regulatory actions; maintain records required by tax authorities, corporate registries, and other regulatory bodies; and protect the rights, property, or safety of GJReyes LLC, our clients, employees, and the public.
5.5 Business Operations
We process Personal Information to support internal business functions, including: financial accounting, auditing, and reporting; business planning, forecasting, and strategy development; insurance procurement and management; professional development and training of our personnel; and evaluating and improving our business processes, service quality, and client satisfaction. Where possible, we aggregate or de-identify information used for these purposes so that it no longer constitutes Personal Information.
6. Legal Bases for Processing
For individuals located in jurisdictions that require a legal basis for processing Personal Information (including the European Economic Area and the United Kingdom), we rely on the following legal bases.
6.1 Contractual Necessity
We process Personal Information where it is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This includes processing required to provide our computer systems design and professional technical services as described in an engagement letter, statement of work, or service agreement.
6.2 Legitimate Interests
We process Personal Information where we have a legitimate interest in doing so, provided that such interest is not overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include: operating and improving the Website; responding to inquiries and providing information requested by you; conducting business development and marketing activities to grow our client base; protecting the security and integrity of our systems and data; and defending against legal claims and enforcing our contractual rights. You have the right to object to processing based on legitimate interests as described in Section 12.
6.3 Consent
Where required by applicable law, we obtain your explicit, informed consent before processing your Personal Information for specific purposes, such as sending direct marketing communications or deploying non-essential cookies and tracking technologies on the Website. You may withdraw your consent at any time by contacting us or using the opt-out mechanisms described in this policy. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
6.4 Legal Obligation
We process Personal Information where necessary to comply with a legal obligation to which GJReyes LLC is subject. This includes obligations under tax law, employment law, corporate law, and any other applicable statutes, regulations, court orders, or governmental mandates.
7. Cookies and Tracking Technologies
The Website uses cookies, web beacons, pixels, and similar tracking technologies (collectively, Cookies) to enhance user experience, analyze Website performance, and support certain functionality. This section explains what Cookies are, how we use them, and how you can manage your preferences.
7.1 What Are Cookies
Cookies are small text files that are placed on your device (computer, smartphone, tablet, or other Internet-connected device) when you visit a website. Cookies serve various functions: they enable websites to remember your preferences, recognize your device on subsequent visits, and collect information about your browsing behavior. Cookies may be session cookies (which expire when you close your browser) or persistent cookies (which remain on your device until they expire or are manually deleted). Cookies may be set by the website you are visiting (first-party cookies) or by other domains that provide services to the website (third-party cookies).
7.2 Categories of Cookies We Use
Essential Cookies: These Cookies are necessary for the basic operation and security of the Website. They enable core functionality such as page navigation, form submission, and access to secure areas. The Website cannot function properly without these Cookies, and they do not require consent under most data protection frameworks.
Performance and Analytics Cookies: These Cookies collect aggregated, anonymized information about how visitors use the Website -- which pages are visited most frequently, how long visitors spend on each page, whether they encounter errors, and how they arrived at the Website. We use this information to improve the Website--s content, structure, and performance. We currently use privacy-respecting analytics tools that minimize the collection of Personal Information.
Functional Cookies: These Cookies enable the Website to remember choices you make, such as your preferred language, region, or accessibility settings, and to provide enhanced, more personalized features. Functional Cookies may be set by us or by third-party providers whose services we have integrated into the Website.
7.3 Managing Cookies
Most web browsers allow you to control Cookies through the browser--s settings. You may configure your browser to: accept all Cookies by default; notify you when a Cookie is being set; block all Cookies; block third-party Cookies only; delete Cookies when you close your browser; or view and selectively delete stored Cookies. The specific steps vary by browser and version. Please consult your browser--s help documentation for detailed instructions. You may also use browser extensions and privacy tools to manage tracking and advertising Cookies. Please note that disabling certain categories of Cookies may affect the functionality and performance of the Website, and some features may become unavailable.
7.4 Do Not Track Signals
Some web browsers offer a --Do Not Track-- (DNT) setting that sends a signal to websites indicating that the user does not wish to be tracked. At this time, there is no universally accepted standard for how websites should respond to DNT signals. Our Website does not currently respond to browser DNT signals. However, we do not engage in behavioral advertising or sell Personal Information, and our tracking activities are limited to essential Website operations and aggregate analytics as described in this policy.
8. Information Sharing and Disclosure
We do not sell, rent, lease, or trade Personal Information to third parties for monetary or other valuable consideration. We do not share Personal Information with third parties except as described in this section and in compliance with applicable data protection laws.
8.1 Service Providers
We engage carefully selected third-party vendors, contractors, and service providers to perform certain business functions on our behalf. These functions may include: website hosting and infrastructure; email hosting and communication platforms; data storage and backup; analytics and performance monitoring; payment processing; professional services such as legal and accounting; and security services. We share with these providers only the minimum Personal Information necessary for them to perform their designated functions. All service providers are contractually bound to: process Personal Information solely on our documented instructions; implement appropriate technical and organizational security measures; maintain confidentiality and not disclose Personal Information to unauthorized parties; and delete or return Personal Information upon completion of the services, unless retention is required by law.
8.2 Legal Disclosures
We may disclose Personal Information where required or permitted by law, including: in response to a valid subpoena, court order, search warrant, or other legal process; to comply with applicable laws, regulations, or governmental requests; to establish, exercise, or defend legal claims; to investigate, prevent, or take action regarding suspected illegal activities, fraud, or threats to safety; and to protect the rights, property, or personal safety of GJReyes LLC, our clients, employees, or the public. We will, where legally permissible, make reasonable efforts to notify you of any such disclosure unless notification is prohibited by law or court order.
8.3 Business Transfers
In the event that GJReyes LLC is involved in a merger, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, Personal Information may be transferred as part of that transaction. We will require the acquiring entity or successor organization to honor the commitments made in this Privacy Policy, and we will provide notice before Personal Information becomes subject to a different privacy policy.
8.4 With Your Consent
We may share Personal Information with third parties where you have provided your explicit consent for us to do so. Consent may be obtained in writing, electronically, or through other means as permitted by applicable law. You may revoke your consent at any time, subject to legal or contractual restrictions, by contacting us using the details provided in Section 16.
8.5 Aggregate and De-Identified Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify any individual with third parties for research, marketing, analytics, and other lawful purposes. This information is not considered Personal Information under this policy and is not subject to the restrictions on sharing set forth in this section.
9. Data Retention and Deletion
We retain Personal Information only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law, regulation, or contractual obligation. Our retention practices are governed by a formal data retention schedule, and we periodically review and purge data that has exceeded its retention period.
9.1 Retention Criteria
The specific retention period for any category of Personal Information is determined by evaluating the following criteria: the nature and sensitivity of the information; the purpose(s) for which it was collected and the duration required to fulfill those purposes; the potential risk of harm from unauthorized use or disclosure; applicable legal, tax, accounting, and regulatory requirements that mandate retention for a minimum period; contractual obligations to clients and third parties; and whether the information is necessary to establish, exercise, or defend against legal claims. When these criteria no longer support retention, we securely delete, destroy, or irreversibly anonymize the Personal Information.
9.2 Retention Periods by Category
Contact and inquiry data: Retained for the duration of the business relationship plus three (3) years after the last interaction, unless a longer period is agreed upon or required by law.
Client engagement data: Retained for the duration of the engagement plus seven (7) years after termination of the client relationship, consistent with standard business record-keeping practices and applicable statutes of limitation.
Technical and usage data: Retained in identifiable form for up to twenty-six (26) months from the date of collection. After this period, data is aggregated or anonymized for long-term trend analysis.
Marketing data: Retained until you withdraw your consent, unsubscribe, or otherwise indicate that you no longer wish to receive marketing communications, after which your data is promptly removed from active marketing lists. Records of consent and unsubscribe requests are retained indefinitely as evidence of compliance.
Communication records: Retained for seven (7) years following the conclusion of the communication thread, in line with general business documentation practices.
9.3 Deletion Procedures
When Personal Information reaches the end of its retention period, we employ secure deletion methods appropriate to the data format: physical documents are shredded or incinerated; electronic records are deleted from active systems and, where technically feasible, from backups; data stored with third-party service providers is deleted in accordance with our data processing agreements; and anonymized or aggregated datasets are reviewed to confirm that re-identification is not reasonably possible. In some cases, legal or operational requirements may prevent immediate deletion of certain data from backup archives; in such cases, we will restrict processing of that data until deletion can be completed.
10. Data Security Measures
GJReyes LLC takes the security of Personal Information seriously and implements a comprehensive set of technical, administrative, and physical safeguards designed to protect data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. As a company specializing in computer systems design, we bring professional-grade security expertise to our own data protection practices.
10.1 Technical Safeguards
Our technical security measures include: encryption of data in transit using Transport Layer Security (TLS) protocols for all Website traffic and electronic communications; encryption of data at rest using industry-standard encryption algorithms for stored databases and backup archives; network security controls including firewalls, intrusion detection and prevention systems, and regular vulnerability scanning; access control mechanisms including strong authentication, role-based access controls, and the principle of least privilege; secure software development practices including code review, dependency scanning, and regular security patching; endpoint protection on all devices used to access or process Personal Information; and automated monitoring and alerting for anomalous system activity, unauthorized access attempts, and potential security incidents.
10.2 Administrative Safeguards
Our administrative security measures include: written information security policies and procedures that are reviewed and updated at least annually; mandatory privacy and security training for all personnel with access to Personal Information; confidentiality agreements binding employees, contractors, and third-party service providers; a designated individual responsible for overseeing data protection and security governance; periodic risk assessments to identify and mitigate threats to Personal Information; documented incident response procedures to ensure timely detection, containment, and notification of data breaches; and vendor risk management processes to evaluate the security posture of third-party service providers before engagement and on an ongoing basis.
10.3 Physical Safeguards
Our physical security measures include: controlled access to facilities where Personal Information is stored or processed; secure storage areas for physical records and hardware; visitor management and logging procedures; environmental controls (fire suppression, climate control, uninterruptible power supply) for server and data storage equipment; and secure disposal procedures for physical media and decommissioned hardware.
10.4 Limitations and User Responsibility
While we implement robust security measures, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security of Personal Information. You also play an important role in protecting your information: we encourage you to use strong, unique passwords; keep your devices and software updated; exercise caution when sharing personal information online; and notify us immediately if you suspect any unauthorized access to your information or accounts. In the unlikely event of a data breach involving your Personal Information, we will notify you and relevant regulatory authorities in accordance with applicable breach notification laws.
11. International Data Transfers
GJReyes LLC is based in the United States, and our servers and service providers are primarily located in the United States. If you are accessing the Website or communicating with us from outside the United States, please be aware that your Personal Information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
11.1 Transfer Safeguards
When we transfer Personal Information across international borders, we implement appropriate safeguards to ensure that the data receives a level of protection consistent with this Privacy Policy and applicable law. These safeguards may include: relying on adequacy decisions issued by relevant data protection authorities; entering into standard contractual clauses approved by the European Commission or other competent authorities; implementing binding corporate rules or codes of conduct approved by supervisory authorities; and obtaining your explicit consent to the transfer after informing you of the possible risks. For transfers to the United States, we also assess the legal framework applicable to our data processing activities and implement supplementary measures where necessary to ensure compliance with international data protection standards.
11.2 European Economic Area Visitors
For individuals located in the European Economic Area (EEA), Switzerland, or the United Kingdom: by providing your Personal Information to us, you acknowledge that your information will be transferred to and processed in the United States. We rely on European Commission-approved standard contractual clauses and, where applicable, the UK International Data Transfer Agreement as the legal mechanism for such transfers. You may request a copy of the relevant transfer safeguards by contacting us using the details in Section 16.
12. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your Personal Information. GJReyes LLC respects these rights and provides mechanisms for you to exercise them. This section describes the primary rights that may be available to you and how to invoke them.
12.1 Right to Access
You have the right to request confirmation as to whether we hold Personal Information about you and, where that is the case, to access that information. Upon a verifiable request, we will provide you with: the categories of Personal Information we have collected about you; the categories of sources from which the information was collected; the business or commercial purpose for collecting the information; the categories of third parties with whom we have shared the information; and the specific pieces of Personal Information we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
12.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete Personal Information that we hold about you. We will make reasonable efforts to verify the accuracy of the corrected information and to notify any third parties to whom we have disclosed the information of the correction, where feasible and appropriate. You may also update certain information directly by contacting us, and we encourage you to do so promptly when your contact details or other information changes.
12.3 Right to Deletion
You have the right to request deletion of Personal Information that we have collected about you, subject to certain exceptions. We will comply with your deletion request unless retention is necessary to: complete the transaction or provide the services for which the information was collected; detect, prevent, or investigate security incidents or illegal activity; comply with a legal obligation; exercise or defend legal claims; enable solely internal uses reasonably aligned with consumer expectations; or fulfill other purposes permitted by applicable law. Where we deny a deletion request based on an applicable exception, we will explain the basis for the denial.
12.4 Right to Restrict Processing
You have the right, in certain circumstances, to request that we restrict the processing of your Personal Information. These circumstances include: where you contest the accuracy of the information and we are verifying it; where the processing is unlawful and you oppose deletion and request restriction instead; where we no longer need the information for the processing purposes but you require it for the establishment, exercise, or defense of legal claims; or where you have objected to processing based on legitimate interests and we are considering whether our legitimate grounds override yours.
12.5 Right to Data Portability
You have the right to receive Personal Information that you have provided to us, in a structured, commonly used, and machine-readable format, and to transmit that information to another controller without hindrance from us, where: the processing is carried out by automated means; and the processing is based on your consent or on the performance of a contract with you.
12.6 Right to Object
You have the right to object, on grounds relating to your particular situation, to the processing of your Personal Information that is based on our legitimate interests (as described in Section 6.2). Upon receiving an objection, we will cease processing the relevant Personal Information unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defense of legal claims. You also have the absolute right to object at any time to processing of your Personal Information for direct marketing purposes, and we will comply with such objection without undue delay.
12.7 California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights, including: the right to know what Personal Information we collect, use, disclose, and sell (we do not sell Personal Information); the right to request deletion of your Personal Information; the right to opt out of the sale or sharing of your Personal Information for cross-context behavioral advertising; the right to correct inaccurate Personal Information; the right to limit the use and disclosure of Sensitive Personal Information (we do not use or disclose Sensitive Personal Information for purposes requiring a limit-right); and the right to non-discrimination for exercising any of your CCPA rights. You may designate an authorized agent to submit requests on your behalf. We will respond to verifiable consumer requests within the timeframes required by the CCPA. To exercise your California privacy rights, please contact us using the methods described in Section 16.
12.8 Exercising Your Rights
To exercise any of the rights described in this section, please submit a verifiable request to us using the contact details provided in Section 16. To verify your identity and ensure the security of your information, we may require you to provide sufficient information to confirm that you are the individual to whom the Personal Information relates, or that you are an authorized representative of such individual. We will respond to your request within the timeframe required by applicable law (generally thirty to forty-five days, with the possibility of extension where permitted). If we require additional time, we will inform you of the extension and the reasons for the delay. We will not charge a fee for processing your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
12.9 Right to Lodge a Complaint
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. In the United States, this may include the Federal Trade Commission, your state attorney general--s office, or the data protection authority in your state. For individuals in the European Economic Area, you may lodge a complaint with the supervisory authority in your member state of residence, place of work, or the place of the alleged infringement. We encourage you to contact us first so that we may attempt to resolve your concerns directly.
13. Children--s Privacy
The Website and our services are not directed at, marketed to, or intended for children under the age of sixteen (16). We do not knowingly collect, solicit, or maintain Personal Information from anyone under the age of sixteen, and we do not sell or share for cross-context behavioral advertising the Personal Information of consumers we actually know to be under sixteen years of age.
If we become aware that we have inadvertently collected Personal Information from a child under the age of sixteen without verified parental consent, we will take prompt steps to delete that information from our systems. If you are a parent or legal guardian and believe that your child has provided Personal Information to us, please contact us immediately using the details in Section 16 so that we can take appropriate action. We do not condition a child--s participation in any activity on the child disclosing more Personal Information than is reasonably necessary to participate in that activity.
For educational institutions or youth-oriented organizations that engage our services, we require that appropriate parental consent mechanisms be in place before any personal information of minors is shared with us in the course of an engagement.
14. Third-Party Services and External Links
The Website may include links to third-party websites, plugins, services, and applications that are not owned, operated, or controlled by GJReyes LLC. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. This Privacy Policy applies solely to information collected by GJReyes LLC through the Website and our direct interactions with you.
14.1 Third-Party Websites
We do not control and are not responsible for the privacy practices, content, or security of third-party websites. When you leave the Website by following an external link, we encourage you to read the privacy policy of every website you visit. The inclusion of a link on our Website does not constitute an endorsement of the linked website or its privacy practices.
14.2 Embedded Content
The Website may incorporate embedded content (such as videos, images, maps, or interactive widgets) hosted by third-party platforms. Embedded content from third-party websites behaves in the same way as if you had visited the third-party website directly. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with the embedded content, including tracking your interaction if you have an account and are logged in to that website.
14.3 Social Media Features
GJReyes LLC may maintain profiles and pages on social media platforms such as LinkedIn, Twitter, and other professional networking services. Interactions with these platforms are governed by the privacy policies and terms of the respective platform, not by this Privacy Policy. Information you share publicly on social media is not subject to the protections described in this policy, and we may view, engage with, or reference such publicly available information in the course of our business activities.
15. Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or the operational environment. This section describes how we manage policy changes and communicate them to you.
15.1 Notification of Changes
When we make changes to this Privacy Policy, we will: update the --Last Updated-- date appearing at the top of this page; post the revised policy on the Website with a clear revision date; and, for material changes that significantly affect your rights or our obligations, provide a more prominent notice on the Website homepage or send a direct notification to the email address we have on file for you, where we are legally required to do so. Material changes may include, but are not limited to: changes to the categories of information we collect; changes to the purposes for which we process information; changes to the parties with whom we share information; and changes to the rights available to you under this policy.
15.2 Effective Date and Transition
Changes to this Privacy Policy become effective on the date specified as the --Effective Date-- or, if no date is specified, immediately upon posting. Your continued use of the Website or engagement with our services after the effective date constitutes your acceptance of the revised Privacy Policy. If you do not agree with the changes, you must discontinue use of the Website and may contact us to request deletion of your Personal Information, subject to the exceptions described in Section 9 and Section 12.3. We encourage you to bookmark this page and review it regularly so that you remain informed of our current privacy practices.
15.3 Historical Versions
Upon written request, we can provide access to previous versions of this Privacy Policy for a reasonable period after changes have been made. Maintaining a version history supports transparency and allows individuals to understand how our data practices have evolved over time.
16. Contact Information and Complaints
GJReyes LLC welcomes your questions, comments, and concerns regarding this Privacy Policy and our data protection practices. If you have any inquiries or wish to exercise your legal rights, please do not hesitate to reach out to us using the contact channels below. We are committed to addressing your concerns promptly and transparently.
16.1 General Contact
For general questions about this Privacy Policy, inquiries about our data practices, or requests to exercise your data subject rights, please contact us at:
GJReyes LLC
Attention: Privacy Office
364 Hillgate Way
Layton, Utah 84041-1374
United States of America
Email: hello@gjreyes.hair
Phone: +1 (601) 996-7918
Website: www.gjreyes.hair
Please include --Privacy Policy Inquiry-- in the subject line of your email or written correspondence to help us route your communication to the appropriate team member. We endeavor to acknowledge all privacy-related inquiries within five (5) business days and to provide a substantive response within thirty (30) calendar days.
16.2 Data Protection Requests
To submit a formal data subject request (including access, deletion, correction, or portability requests), please send a written communication to the email or postal address above that includes: your full name and contact information; a clear description of the right you wish to exercise and the scope of your request; sufficient information to allow us to identify you and locate the relevant Personal Information in our systems; and, if you are acting on behalf of another individual, documentation demonstrating your authority to act as an authorized agent. We may contact you for additional verification before processing your request, as described in Section 12.8.
16.3 Complaints and Escalation
If you are not satisfied with our response to a privacy concern or data subject request, you may escalate the matter by: requesting that your concern be reviewed by a senior member of our team; or filing a complaint with the relevant data protection supervisory authority in your jurisdiction, as described in Section 12.9. We encourage you to contact us before filing a complaint with a regulatory body so that we have the opportunity to address your concerns through our internal review process. We do not retaliate or discriminate against any individual who raises a privacy concern in good faith or cooperates with a regulatory investigation.