Privacy Policy

SCZ Enterprises, LLC · 6518 S Rothmoor Dr, Murray - 84121-2514, United States (US) · Return to the homepage

This Privacy Policy explains how SCZ Enterprises, LLC collects, uses, stores and protects information in the course of providing computer systems design, integration and technical support services. It was prepared by the developer SCZ Enterprises for clients and visitors, and it describes the practices that apply to this website and to the services delivered from our Murray office.

Contents

  1. Scope of this Policy
  2. Who We Are
  3. Information We Collect
  4. Sources of Information
  5. Why We Hold Information
  6. Basis for Processing
  7. Information Collected on This Website
  8. Cookies and Similar Technologies
  9. Contact Forms and Email
  10. Client Records and System Data
  11. How Information Is Shared
  12. Service Providers
  13. How Long Information Is Kept
  14. How Information Is Protected
  15. Breach Notification
  16. Your Choices and Rights
  17. Access, Correction and Deletion
  18. Privacy for Children
  19. Visitors Outside the United States
  20. Links to Other Sites
  21. Changes to this Policy
  22. How to Contact Us

1. Scope of this Policy

This Privacy Policy applies to the website published at sczenterprises.mom and to the professional services offered by SCZ Enterprises, LLC from its office at 6518 S Rothmoor Dr, Murray - 84121-2514, United States (US). It covers the information we gather when a person visits this website, submits an enquiry, requests a systems review, or engages us for design, integration, migration, documentation, networking or support work.

The Policy does not apply to software or services owned and operated by third parties, even where we have recommended them or connected them on your behalf. Those providers publish their own privacy notices, and we encourage every client to read them before adopting a product. Where our work touches a third party service, we explain the arrangement in the project documentation and identify which provider is responsible for which category of information.

This Policy is written to be read by a business owner rather than a lawyer. Where a term has a specific meaning we explain it in plain English in the sentence that follows. If any part of this Policy is unclear, we would rather answer a question directly than have a client proceed on an assumption.

2. Who We Are

SCZ Enterprises, LLC is a computer systems design and related services practice registered in the United States and operating from Murray, Utah. The company designs, integrates and supports back-office systems for small and medium businesses, with particular experience in the professional, scientific and technical services sector.

For the purposes of applicable data protection law, SCZ Enterprises, LLC is the controller of the personal information described in this Policy, which means the company decides why the information is held and how it is used. Where we process records on behalf of a client inside a system we have designed, the client remains the controller of that data and we act as a processor under the client instructions and the terms of the engagement.

Our postal address is 6518 S Rothmoor Dr, Murray - 84121-2514, United States (US). The telephone number is +16812620720. The contact email address is office@sczenterprises.mom. These details appear on every page of this website so that a question about privacy can always be directed to the right place.

3. Information We Collect

We collect information in a small number of clearly defined categories. The first category is contact information, which includes a name, a business name, an email address, a telephone number and any postal address a person provides when requesting a review or engaging our services. The second category is enquiry content, meaning the text of the message a person sends and any files or documents attached to it.

The third category is project information, which includes the technical details gathered during a systems review: the software a business uses, the layout of its network, the structure of its files, the forms in circulation and the workflow that connects them. This category can contain personal information where records identify individuals, for example a customer list or an employee rota.

The fourth category is billing information, which includes the invoice details needed to charge for work and to satisfy bookkeeping obligations. The fifth category is website technical information, which includes the internet protocol address a browser presents, the page requested, the time of the request and the agent string that identifies the browser type. The sixth category is correspondence, which includes emails, call notes and meeting records created while a project is in progress.

We do not seek sensitive categories of personal information such as health details, religious beliefs, political opinions or biometric identifiers, and our services are not designed to process them. Where a client system happens to contain such information, we handle it under the client instructions and we minimise our exposure to it by working where possible with masked or summarised data.

4. Sources of Information

Most information reaches us directly from the person concerned. A visitor submits an enquiry through the contact form, sends an email, or calls the office. A prospective client provides details during a systems review. A client supplies records and access details so that integration, migration or support work can proceed.

A second source is the client organisation itself. Where a business engages us, its authorised staff may provide information about colleagues, customers or suppliers for the purpose of the project. In that situation the client is responsible for ensuring it is entitled to share the information with us, and we hold it only for the purposes the client has described.

A third source is automatic collection by this website and by the infrastructure that delivers it. Server logs and similar records capture the technical information described above. We do not use that information to build a profile of an individual, and we do not attempt to identify a visitor from it except where a security incident makes identification necessary.

A fourth source is public or professional material, such as a business website or a public register, which we may consult to confirm the correct name and address of a prospective client before preparing a proposal.

5. Why We Hold Information

We hold information in order to answer enquiries, prepare proposals, deliver agreed services, issue invoices, keep accurate business records and maintain a professional relationship with clients. Each of these purposes is specific, and we do not repurpose information for an unrelated reason without first explaining the change and, where required, obtaining consent.

Information is also held to keep the systems we design secure and reliable. Logs and health records allow us to detect a failing integration, trace the source of an error and prove that a backup completed. This purpose benefits the client directly, because a system that cannot be diagnosed cannot be supported.

Finally, we hold a limited amount of information to meet legal and accounting obligations, including tax records and records of work performed. Those obligations set a minimum retention period rather than a maximum, and we do not keep information longer than the applicable period requires.

6. Basis for Processing

Where the law requires us to identify a lawful basis for handling personal information, we rely on the following grounds. Processing is necessary to perform a contract when the information is needed to deliver services a client has engaged us to provide. Processing is necessary for our legitimate interests when we answer an enquiry, keep our systems secure or manage a professional relationship, provided those interests are not overridden by the rights of the individual.

Processing is necessary to comply with a legal obligation when we retain billing records or respond to a lawful request from an authority. Where none of the above applies and consent is the appropriate basis, we ask for it clearly and separately, and we make it as easy to withdraw as it was to give.

Where a client instructs us to process records inside a system we support, the client determines the basis for that processing and we act only on the client documented instructions. We will tell a client if an instruction appears to conflict with applicable law.

7. Information Collected on This Website

This website is deliberately simple. It consists of static pages that present our services and legal notices. There is no account system, no shopping facility and no behavioural advertising. The information the site collects is limited to what is required to deliver the pages and to receive a message from a visitor.

When a browser requests a page, the hosting infrastructure records the request. A typical record includes the internet protocol address of the requesting device, the date and time, the address of the page requested and the browser identification string. These records are used for security, capacity planning and fault diagnosis. They are not combined with any other data to identify an individual visitor.

If you prefer not to have any technical information recorded, you can browse with privacy tools enabled in your browser. The pages will still display correctly, because no feature of this site depends on tracking a visitor.

8. Cookies and Similar Technologies

This website does not set advertising cookies and does not run third party analytics that follow a visitor across other websites. The site is built to function without relying on cookies for its core content, and no part of the service offering is withheld if cookies are refused.

Where a cookie or a similar storage mechanism is used at all, it is a strictly functional device that helps a browser remember a display preference or complete a form. Such a device carries no advertising identifier and is not shared with a marketing network. You can clear or block cookies in your browser settings at any time, and doing so will not prevent you from reading this site or contacting us.

Some hosting providers insert their own technical cookies for load balancing and security. Those devices are controlled by the provider rather than by SCZ Enterprises, LLC, and we select providers that limit their use to operational purposes.

9. Contact Forms and Email

The contact form on this website does not transmit your message to a database we operate. When you submit the form, your own email program opens with the message prepared and addressed to office@sczenterprises.mom. The message travels through your email provider and ours, and it arrives in our mailbox in the ordinary way.

This design is intentional. It means that the content of your message is never stored on a web server we control, and it reduces the number of places where your details could be exposed. The trade is that you must send the prepared email yourself, which the form tells you clearly when it runs.

Once an email reaches us, it is handled like any other business correspondence. It is read by the person best placed to answer it, stored in our mailbox under our normal access rules, and retained only for as long as the enquiry, the project or the applicable record keeping obligation requires. If you would rather not use email, telephone +16812620720 during business hours.

10. Client Records and System Data

During a systems design, integration or migration engagement we may access records that belong to a client, including customer lists, supplier files, order histories and financial extracts. In these situations the client remains the controller of the data and SCZ Enterprises, LLC acts as a processor. We access client records only to the extent needed to complete the agreed work.

We follow a short set of practical rules when handling client records. We work from copies wherever possible rather than from the live system. We avoid exporting personal information that the project does not require. We keep working copies in an encrypted location that is protected by named access controls. We delete working copies at the end of the engagement unless the client asks us to retain them for support.

Where a migration is carried out, the original data is preserved in its untouched form and is never discarded by us. The reconciliation report and the cleaning rules applied are documented so that a client can demonstrate, later, exactly what changed and what did not.

If a client instructs us to process records in a way that we believe conflicts with applicable law or with the rights of the individuals concerned, we raise the matter before proceeding and record the resolution in writing.

11. How Information Is Shared

We do not sell personal information, and we do not rent or trade it. Information is shared only in the narrow circumstances described in this section, and only to the extent needed to deliver a service, meet an obligation or protect a legitimate interest.

The first circumstance is a service provider acting on our instructions, described in the next section. The second is a legal requirement, such as a valid court order, a subpoena or a demand from a regulator with authority over the matter. Where we are permitted to notify a client of such a demand, we do so before disclosing anything, so that the client can respond.

The third circumstance is the protection of rights and safety, including the investigation of fraud, the response to a security incident, or the defence of a legal claim. The fourth is a change in the structure of the business, such as a merger or an acquisition, in which case information may transfer to a successor that agrees to honour this Policy.

Apart from those situations, we share nothing about a client or a visitor with a third party without a clear instruction or a separate consent, and we never disclose the identity of a client as a reference without written permission.

12. Service Providers

Like most small professional practices, we rely on a limited set of suppliers to operate. These may include an email host, a website host, a backup provider, an accounting service and, where a project requires it, a specialist contractor bound by confidentiality. Each supplier sees only the information needed for its own function.

We choose providers with care. Before engaging a supplier that will touch client information, we satisfy ourselves that it applies reasonable technical and organisational safeguards, that it limits access to authorised personnel, and that it accepts written obligations of confidentiality and security. Where a provider would transfer information outside the United States, we take account of the additional risks and we tell the client what arrangement applies.

Where a client requires a specific provider to be excluded, we record that requirement in the engagement documentation and we hold to it. We also tell clients which providers are in use for a given engagement so that the chain is never a mystery.

13. How Long Information Is Kept

We keep personal information only for as long as it is needed for the purpose for which it was collected, plus any period required by law. Because the purposes differ, so do the periods, and the summary below explains the ordinary approach.

  • Enquiries that do not lead to a project are kept for up to twelve months and are then deleted, so that a later question can be answered with context.
  • Project records and client correspondence are kept for the duration of the engagement and for six years afterwards, to support support work, warranty questions and legal defence.
  • Billing records are kept for the period required by tax and accounting law, which is currently seven years for the relevant records.
  • Website server logs are kept for a short operational period, ordinarily no more than ninety days, and are then overwritten.
  • Working copies of client data are deleted at the end of the engagement unless the client asks for retention as part of a support agreement.

When a retention period ends we delete the information or render it unreadable, and we confirm the deletion to the client on request. Where information sits in a backup, it is removed from live systems immediately and disappears from the backup as the backup cycle rolls forward.

14. How Information Is Protected

We apply technical and organisational measures that are proportionate to the sensitivity of the information and to the risks of a small professional practice. These measures include encryption of data in transit, encryption of working copies at rest, unique named accounts rather than shared logins, multi factor authentication on the services that support it, and a least privilege rule so that access is granted only where a task requires it.

Physical measures matter as much as digital ones. Paper working notes are kept in a locked cabinet and are shredded when the engagement ends. Portable devices are encrypted and are not left unattended in public places. Access to the office and to equipment is limited to authorised staff.

Organisational measures include written confidentiality obligations for staff and contractors, a short internal procedure for handling a suspected incident, and a practice of testing backups for restoration rather than assuming they work. We also review the access list at the end of each engagement and remove permissions that are no longer needed.

No method of storage or transmission is perfectly secure, and we do not claim otherwise. What we do claim is that we design for security from the start, that we limit the information we hold, and that we will tell affected parties promptly if something goes wrong.

15. Breach Notification

If we become aware of a security incident that affects personal information, we follow a short written procedure. The incident is contained first, so that the exposure is stopped before anything else is done. The scope is then established: what information was involved, whose information it was and what the likely consequences are.

Where a client is affected, we notify the client without undue delay and give the facts we have, including what happened, what we have done, and what we recommend. Where the law requires notification to a regulator or to affected individuals, we make that notification within the applicable period and we keep a record of what was sent and when.

We do not conceal an incident to protect a reputation. A breach handled honestly and quickly is a manageable event; a breach concealed is not.

16. Your Choices and Rights

Depending on where you live, you may have a set of rights over the personal information we hold about you. These commonly include the right to know what is held, the right to receive a copy, the right to have inaccurate information corrected, the right to ask for deletion, the right to restrict or object to certain processing, and the right to withdraw consent where consent was the basis for processing.

You also have the right not to be discriminated against for exercising a privacy right. We will not refuse service, charge a different price or provide a lower quality of service because you have asked about your information or asked us to correct it.

To exercise a right, contact office@sczenterprises.mom or call +16812620720. We will confirm your identity before acting, because we do not want to release information to the wrong person. We will respond within the period the applicable law allows, ordinarily within thirty days, and we will explain any reason why a request cannot be fully met.

17. Access, Correction and Deletion

An access request asks us to confirm what personal information we hold and to provide a copy. We will describe the categories held, the purposes, the recipients and the retention period, and we will supply the information in a readable format. Where a request covers information held on behalf of a client, we will direct the request to that client as the controller.

A correction request asks us to fix information that is wrong or incomplete. We will correct our own records promptly, and where the information came from a client system we will pass the request to the client and record that we did so. A deletion request asks us to remove information. We will delete what we are able to delete, and we will explain where a legal or contractual obligation requires us to keep something, together with the period involved.

There is no charge for a reasonable request. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, and we will give our reasons in writing.

18. Privacy for Children

Our services are provided to businesses, and this website is not directed at children. We do not knowingly collect personal information from a child under the age of thirteen, and we do not create accounts for children. Where a client system contains information about a minor, that information is held under the client instructions and is subject to the client own obligations.

If you believe that a child has sent personal information to us, please contact office@sczenterprises.mom or call +16812620720. Once we confirm the situation, we will delete the information promptly and confirm the deletion to you. If we learn that we have inadvertently collected information from a child without the appropriate consent, we take the same step.

19. Visitors Outside the United States

This website and our services are operated from the United States, and the information we hold is stored and processed in the United States. If you contact us from another country, you understand that your information will be transferred to and handled in the United States, where privacy law may differ from the law of your own country.

Where a client engagement requires information to be transferred from another jurisdiction, we agree the safeguards in the engagement documentation before any transfer takes place. Those safeguards may include standard contractual clauses or an equivalent mechanism, and we will explain which mechanism applies when we prepare the proposal.

Where local law gives you rights that are stronger than those described in this Policy, we will honour those rights for the information concerned, and nothing in this Policy is intended to reduce a protection that the applicable law guarantees.

20. Links to Other Sites

This website may link to software vendors, industry bodies or other resources that we believe are useful to a client. Those sites are not under our control, and their privacy practices are their own. A link is not an endorsement of the way a third party handles personal information.

We encourage every client to read the privacy notice of any product before adopting it, particularly where the product will hold customer records. Where we recommend a product as part of a project, we will say clearly which party is responsible for the data inside it and what that means for the client obligations.

21. Changes to this Policy

We review this Privacy Policy from time to time to reflect changes in our practices, in the services we offer, or in the law that applies to us. When we make a change, we publish the revised Policy on this page and update the effective date shown in the header area of the site.

If a change is material, we will take reasonable steps to bring it to the attention of clients who may be affected, for example by including a notice with a project communication. Continuing to use this website or to engage our services after a change takes effect means that the revised Policy applies.

We keep earlier versions of this Policy so that a person can see what applied at a particular time, and we will provide a copy of a previous version on request.

22. How to Contact Us

Questions, requests and complaints about privacy are welcome and are handled by the same small team that delivers our services. You can reach us using any of the details below. We aim to acknowledge every privacy enquiry within two working days.

SCZ Enterprises, LLC

6518 S Rothmoor Dr, Murray - 84121-2514, United States (US)

Email: office@sczenterprises.mom

Phone: +16812620720

This Policy is effective as of January 2026 and applies to all information held by SCZ Enterprises, LLC at that date and afterwards.

Home Services Contact Privacy Policy Terms of Service

SCZ Enterprises, LLC · 6518 S Rothmoor Dr, Murray - 84121-2514, United States (US) · +16812620720 · office@sczenterprises.mom