Privacy Policy
- Effective Date
- 13 September 2026
- Last Updated
- 14 September 2026
- Registered Entity
- UTM SOLUTIONS LLC
30 N Gould St, Ste R, Sheridan, WY 82801, United States of America · Wyoming Filing #2026-001960932
Introduction
This Privacy Policy explains how UTM SOLUTIONS LLC ("the Company," "we," "us," or "our") collects, uses, discloses, retains, transfers, and protects personal data in connection with our website (the "Website") and our professional services (the "Services").
This Privacy Policy is incorporated by reference into, and forms an integral part of, our Terms of Service (Document Reference UTM-TOS-2026-01). Capitalized terms not defined herein bear the meanings given to them in the Terms of Service.
By accessing the Website, submitting an inquiry, engaging with our conversational interface, or engaging us for Services, you acknowledge that you have read and understood this Privacy Policy.
IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, PLEASE DO NOT USE THE WEBSITE OR SUBMIT ANY PERSONAL DATA TO US.
Scope and Application
What This Policy Covers. This Policy applies to personal data we collect: (a) through the Website; (b) through our conversational or chat interface; (c) through direct communication channels including email and WhatsApp; (d) in the course of negotiating, entering into, and performing client engagements; and (e) through our billing, invoicing, and payment processes.
What This Policy Does Not Cover. This Policy does not apply to:
personal data collected by our clients through websites, applications, chatbots, or systems we have built or configured for them. In respect of such data, our client is the data controller and that client's own privacy policy governs. Our role, where we process such data at all, is limited to that of a processor acting on the client's documented instructions, as set out in Section 16 of the Terms of Service;
personal data collected by any third-party website, platform, or service linked from the Website or from any deliverable, each of which maintains its own independent privacy practices; and
information that does not identify, and cannot reasonably be used to identify, any individual, including fully anonymized and aggregated statistics.
Our Role. In respect of the data described in Section 1.1, we act as the data controller (or "business" under United States state privacy legislation). In respect of the data described in Section 1.2.1, we act as a data processor (or "service provider").
Categories of Personal Data We Collect
2.1 Information You Provide Directly.
Inquiry and Contact Data — full name, business or trading name, email address, telephone or WhatsApp number, country of residence or operation, job title or role, website address, and any other information you voluntarily include in an inquiry form, email, or message.
Project and Engagement Data — business description, industry, target market, project requirements, design preferences, competitor references, brand materials, technical specifications, timelines, and budget parameters.
Contractual and Identity Data — legal name, registered business address, billing address, tax identification number where applicable, company registration details, authorized signatory details, and electronic signature records.
Payment and Transaction Data — invoice records, payment method elected, transaction references, bank transfer confirmations, remittance advices, and, where digital asset settlement is elected, the public blockchain wallet address and transaction hash associated with your payment. We do not collect or store full payment card numbers, card verification values, or bank account credentials — these are handled directly by our third-party payment processors.
Credentials and Access Data — where necessary to perform the Services and where you choose to provide them, access credentials, API keys, administrative logins, DNS control details, and repository access tokens relating to your own systems and accounts.
Communication Records — the content and metadata of correspondence with us, including emails, WhatsApp messages, chat transcripts, meeting notes, and feedback submissions.
2.2 Information Collected Automatically.
Technical and Device Data — internet protocol (IP) address, approximate geographic location derived from IP address, browser type and version, operating system, device type, screen resolution, language and locale settings, and referring URL.
Usage Data — pages viewed, time spent on pages, navigation paths, scroll depth, clicks and interactions, form engagement, session duration, date and time of access, and exit points.
Cookie and Similar Technology Data — as described in Section 7.
2.3 Information from Third Parties.
analytics and advertising platforms that provide aggregated or pseudonymized audience and performance data;
payment processors and banking providers that confirm settlement and provide transaction status;
publicly available sources, including business registries, professional networking platforms, and company websites, used for the limited purpose of verifying business information provided to us; and
compliance and screening providers, as described in Section 3.9.
Sensitive Personal Data. We do not seek, and ask that you do not provide, special category or sensitive personal data — including data revealing health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sexual orientation, or criminal records. Where such data is provided unsolicited, we will delete it promptly unless retention is required by law.
Purposes of Processing and Legal Bases
We process personal data only where we have a valid legal basis to do so. The table below sets out each purpose and the corresponding legal basis under the EU/UK General Data Protection Regulation and equivalent legislation.
| # | Purpose | Legal Basis |
|---|---|---|
| 3.1 | Responding to inquiries, preparing quotations and proposals | Steps taken at your request prior to entering a contract; legitimate interests |
| 3.2 | Negotiating, forming, and performing client engagements | Performance of a contract |
| 3.3 | Invoicing, collecting payment, and managing accounts receivable | Performance of a contract; legal obligation |
| 3.4 | Accounting, bookkeeping, tax filing, and statutory record-keeping | Legal obligation |
| 3.5 | Providing technical support and remediating defects | Performance of a contract |
| 3.6 | Operating, securing, maintaining, and improving the Website | Legitimate interests |
| 3.7 | Analytics, performance measurement, and conversion tracking | Consent (where required); legitimate interests |
| 3.8 | Marketing communications and remarketing | Consent; legitimate interests (existing clients) |
| 3.9 | Sanctions screening, anti-money laundering checks, fraud prevention, and blockchain address screening | Legal obligation; legitimate interests |
| 3.10 | Establishing, exercising, or defending legal claims; evidencing performance in payment disputes and chargebacks | Legitimate interests; legal obligation |
| 3.11 | Corporate transactions, including merger, acquisition, or asset sale | Legitimate interests |
Legitimate Interests Assessment. Where we rely on legitimate interests, those interests are: operating and growing a lawful professional services business; securing our systems and preventing fraud; recovering amounts properly due to us; defending ourselves against claims; and understanding how our Website is used in order to improve it. We have assessed in each case that these interests are not overridden by your rights and freedoms. You may object to such processing as described in Section 10.
No Automated Decision-Making. We do not carry out automated decision-making producing legal or similarly significant effects concerning you, nor do we engage in profiling for such purposes.
No Sale of Personal Data. We do not sell personal data, and we have not sold personal data in the preceding twelve (12) months. We do not share personal data for cross-context behavioral advertising in a manner constituting a "sale" or "share" under the California Consumer Privacy Act as amended, except to the extent that the operation of third-party advertising cookies may be construed as such, in which case you may exercise the opt-out right described in Section 11.
No Processing of Children's Data. Our Services are directed exclusively at businesses and at adults. We do not knowingly collect personal data from any person under sixteen (16) years of age. If we become aware that we have collected such data, we will delete it without undue delay. If you believe a child has provided us with personal data, please contact us using the details in Section 15.
Our Conversational Interface and Ai-related Processing
Chat Interface on Our Website. Our Website may make available a conversational or chat interface for the purpose of answering questions about our Services and qualifying inquiries.
What We Collect Through It. We may collect and retain the content of your messages, the timestamps of the conversation, and associated technical data as described in Section 2.2.
Third-Party Model Providers. Where the interface uses an artificial intelligence model, the content of your messages may be transmitted to a third-party model provider for the sole purpose of generating a response. Such providers process the data under their own terms and privacy policies, and we select providers that contractually commit not to use business API inputs to train their models. Transmission may involve transfer to servers located outside your country of residence, including in the United States.
DO NOT SUBMIT SENSITIVE INFORMATION. Please do not submit through the chat interface any password, credential, API key, payment card number, bank account detail, government identification number, health information, or confidential material belonging to you or to a third party. The chat interface is not a secure channel for such information.
Outputs Are Not Binding. Responses generated by the interface are informational only. They do not constitute a binding offer, quotation, representation, warranty, or professional advice, and do not bind the Company, as set out in Section 14.4 of the Terms of Service.
AI Tools in Our Production Workflow. We use artificial intelligence tools internally as part of our production workflow, including for code generation, code review, content structuring, and quality assurance. Where client material is processed through such tools, we use enterprise or business-tier services that contractually exclude the use of inputs for model training, and we remain bound by the confidentiality obligations in Section 15 of the Terms of Service.
Disclosure of Personal Data
5.1 We Disclose Personal Data To:
Service Providers and Sub-processors — hosting and deployment providers, content delivery networks, domain registrars, source code repository providers, email and communication providers, customer relationship management providers, analytics providers, and artificial intelligence model providers, in each case solely to the extent necessary for them to provide services to us.
Payment and Financial Providers — payment processors, merchant acquirers, and banking providers, for the purpose of processing payments, issuing invoices, and reconciling accounts.
Professional Advisers — accountants, bookkeepers, tax advisers, auditors, insurers, and legal counsel, under obligations of professional confidentiality.
Subcontractors — independent contractors, freelancers, affiliates, subsidiaries, or related entities engaged by us to perform any part of the Services, as permitted by Section 18 of the Terms of Service, each bound by confidentiality obligations substantially equivalent to our own.
Compliance and Screening Providers — providers of sanctions screening, identity verification, fraud detection, and blockchain analytics services, where required to meet our legal and regulatory obligations.
Legal and Regulatory Recipients — courts, tribunals, arbitrators, law enforcement agencies, tax authorities, and regulatory bodies, where required by applicable law, court order, subpoena, or lawful request, or where necessary to establish, exercise, or defend legal claims.
Acquirers — any actual or prospective purchaser, investor, successor, or assignee in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate confidentiality protections.
We Do Not Disclose Personal Data To: data brokers, list rental services, or any third party for the purpose of that party's own independent marketing.
Public Blockchain Disclosure. Where you elect to settle an invoice using digital assets, you acknowledge that the transaction — including the sending address, receiving address, amount, asset, and timestamp — is recorded on a public, permanent, and immutable distributed ledger that is visible to anyone worldwide. This record is outside our control and cannot be deleted, amended, or erased by us or by any other party. Any right of erasure you may hold under applicable law cannot be exercised in respect of on-chain data.
International Data Transfers
Cross-Border Processing. We are established in the United States and operate internationally. The provision of our Services necessarily involves the transfer, storage, and processing of personal data in multiple jurisdictions, including jurisdictions outside your country of residence and outside the European Economic Area and the United Kingdom.
Transfer Safeguards. Where we transfer personal data from the European Economic Area, the United Kingdom, or any other jurisdiction imposing transfer restrictions, we implement appropriate safeguards, which may include: (a) the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable; (b) an adequacy decision of the relevant authority; (c) reliance on a derogation permitted by applicable law, including where the transfer is necessary for the performance of a contract with you; or (d) equivalent contractual protections with our sub-processors.
Acknowledgment of Risk. You acknowledge that the legal frameworks governing data protection and government access to data differ between jurisdictions, and may not offer protections equivalent to those available in your own jurisdiction.
Copy of Safeguards. You may request further information about the specific safeguards applied to transfers of your personal data by contacting us using the details in Section 15.
Cookies and Similar Technologies
What Cookies Are. Cookies are small text files placed on your device by a website. We may also use similar technologies including local storage, pixels, tags, and software development kits.
7.2 Categories We Use.
Strictly Necessary Cookies — required for the Website to function, including security, load balancing, network routing, form submission, and preference persistence such as your selected language or theme. These cannot be disabled and are set on the basis of legitimate interests, without requiring consent.
Analytics Cookies — used to understand how visitors interact with the Website, including page views, session duration, traffic sources, and navigation patterns. These may be set by third-party analytics providers.
Advertising and Conversion Cookies — used to measure the effectiveness of advertising campaigns, attribute conversions, and enable remarketing. These may be set by third-party advertising platforms and may involve the transfer of data to those platforms.
Functional Cookies — used to enable enhanced features such as the conversational interface and embedded third-party content.
Consent. Where required by applicable law, including in the European Economic Area and the United Kingdom, we place non-essential cookies only after obtaining your consent through our cookie banner. Consent is not bundled: you may accept some categories and reject others, and rejecting is as easy as accepting.
Withdrawing Consent. You may withdraw or modify your cookie consent at any time through the cookie preference control available on the Website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Browser Controls. You may also configure your browser to block or delete cookies. Note that blocking strictly necessary cookies may impair the functioning of the Website.
Do Not Track and Global Privacy Control. Our Website does not currently respond to browser "Do Not Track" signals, as no uniform standard has been adopted. We do, however, honor the Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing where applicable law so requires.
Data Retention
Retention Principle. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, to resolve disputes, and to enforce our agreements.
8.2 Indicative Retention Periods.
| Category | Indicative Retention Period |
|---|---|
| Unsuccessful inquiries and lapsed quotations | 24 months from last contact |
| Client engagement and project records | 7 years from conclusion of the engagement |
| Contracts, statements of work, and signature records | 10 years from conclusion |
| Invoices, payment records, and accounting data | 7 years, or longer where required by tax law |
| Chat interface transcripts | 12 months |
| Website analytics data | 14 months, or as configured in the analytics platform |
| Marketing contact records | Until you withdraw consent or object, plus 12 months |
| Client project files, repositories, and deliverables | 90 days following termination, per Section 23.6 of the Terms of Service |
| Records relating to an actual or threatened legal claim | Until final resolution plus the applicable limitation period |
| Sanctions and compliance screening records | 5 years from the relevant transaction |
Deletion and Anonymization. At the end of the applicable retention period, we delete personal data or irreversibly anonymize it so that it can no longer be associated with any individual.
Backups. Data may persist in routine encrypted backup and archival systems for a limited period following deletion from active systems. Such data remains subject to this Privacy Policy and is deleted in the ordinary course of backup rotation.
On-Chain Data. As set out in Section 5.3, data recorded on a public blockchain cannot be deleted and is retained permanently by the network, outside our control.
Data Security
Our Measures. We implement commercially reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction. These include: encryption of data in transit using industry-standard transport layer security; access controls on a least-privilege and need-to-know basis; multi-factor authentication on administrative accounts; credential management practices; confidentiality obligations imposed on all personnel and subcontractors; and periodic review of our security practices.
NO ABSOLUTE GUARANTEE. NO METHOD OF ELECTRONIC TRANSMISSION OR STORAGE IS ENTIRELY SECURE. WHILE WE APPLY REASONABLE SAFEGUARDS, WE CANNOT AND DO NOT GUARANTEE THE ABSOLUTE SECURITY OF ANY PERSONAL DATA, AND ANY TRANSMISSION IS AT YOUR OWN RISK.
Your Responsibilities. You are responsible for maintaining the confidentiality of any credentials you hold, for securing the email account through which you correspond with us, and for promptly notifying us of any suspected compromise.
Breach Notification. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required by applicable law, affected individuals, without undue delay and in accordance with applicable statutory timeframes.
Post-Handover Security. Following handover of any deliverable, the security, patching, monitoring, credential management, and access control of that deliverable and its hosting environment are the exclusive responsibility of the client, as set out in Section 16.8 of the Terms of Service.
Your Rights under EU and UK Data Protection Law
Available Rights. Where the EU or UK General Data Protection Regulation applies to our processing of your personal data, you hold the following rights:
Right of Access — to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of it together with prescribed information about the processing.
Right to Rectification — to have inaccurate personal data corrected and incomplete personal data completed.
Right to Erasure — to have your personal data deleted where one of the statutory grounds applies. This right does not extend to data we are required to retain by law, data necessary for the establishment or defense of legal claims, or data recorded on a public blockchain.
Right to Restriction of Processing — to have processing restricted in specified circumstances, including while the accuracy of data is being verified.
Right to Data Portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible, in respect of processing based on consent or contract and carried out by automated means.
Right to Object — to object at any time to processing based on legitimate interests, on grounds relating to your particular situation. You may object to direct marketing at any time, absolutely and without needing to give a reason.
Right to Withdraw Consent — to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
Right to Lodge a Complaint — to lodge a complaint with the supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, this is the Information Commissioner's Office.
How to Exercise. Submit your request to the email address in Section 15, stating clearly which right you wish to exercise and providing sufficient information for us to identify you and locate the relevant data.
Verification. We may request additional information to verify your identity before acting on a request. This is a security measure to ensure personal data is not disclosed to any person who has no right to receive it.
Timeframe. We will respond within one (1) month of receipt of a valid request. This period may be extended by up to two (2) further months where the request is complex or where we have received multiple requests, in which case we will inform you of the extension and the reasons for it within the initial month.
Cost. Requests are handled free of charge. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, stating our reasons.
Your Rights under United States State Privacy Laws
Applicability. This Section applies to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, and other states that have enacted comprehensive consumer privacy legislation, to the extent such legislation applies to us.
Rights. Subject to verification and to statutory exceptions, you may have the right to: (a) know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties to whom it is disclosed; (b) request deletion of personal information we have collected from you; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of personal information and of targeted advertising; (e) limit the use and disclosure of sensitive personal information; and (f) not be subjected to unlawful discrimination for exercising any of these rights.
Non-Discrimination. We will not deny you Services, charge you a different price, provide a different level or quality of Service, or suggest that we will do any of these things, because you exercised a privacy right.
Sale and Sharing. As stated in Section 3.14, we do not sell personal information. To the extent that the operation of third-party advertising cookies may constitute a "sale" or "share," you may opt out through our cookie preference control or by transmitting a Global Privacy Control signal.
Authorized Agents. You may designate an authorized agent to submit a request on your behalf. We will require written proof of authorization and may require you to verify your own identity directly.
Appeals. Where we decline to act on your request and the law of your state provides an appeal mechanism, you may appeal our decision by writing to the address in Section 15 with the subject line "Privacy Request Appeal." We will respond to the appeal within the statutory period and, if the appeal is denied, will provide information about how to contact your state Attorney General.
Shine the Light. California residents may request information regarding our disclosure of personal information to third parties for those parties' direct marketing purposes. We do not make such disclosures.
Rights under Other Applicable Laws
Where the data protection law of any other jurisdiction applies to our processing of your personal data, we will honor the rights conferred by that law to the extent it applies. If you believe you hold rights under a law not expressly addressed in this Policy, please contact us using the details in Section 15 and we will respond in accordance with that law.
Third-party Links and Services
External Links. The Website may contain links to third-party websites, platforms, and resources. We do not control, and are not responsible for, the privacy practices, content, or security of any such third party.
Independent Policies. Each third-party service maintains its own privacy policy, which governs your interaction with it. We encourage you to review those policies before providing personal data to any third party.
No Endorsement. The inclusion of any link or reference does not constitute endorsement, certification, partnership, or affiliation.
Changes to This Privacy Policy
Right to Amend. We may update this Privacy Policy from time to time to reflect changes in our practices, our technology, applicable law, or regulatory guidance.
Notification. We will post the updated Policy on the Website with a revised "Last Updated" date. Where changes are material, we will provide more prominent notice, which may include a notice on the Website or a direct communication to active clients.
Effective Date of Changes. Changes take effect upon publication. Your continued use of the Website or continued engagement of our Services following publication constitutes acceptance of the updated Policy.
Review. We encourage you to review this Policy periodically.
Contact and Complaints
Contact Details. For any question, request, or complaint relating to this Privacy Policy or to our processing of personal data:
Please mark privacy-related correspondence with the subject line "Privacy Request."
Response. We aim to acknowledge all privacy correspondence within five (5) business days and to resolve it within the timeframes set out in Sections 10.4 and 11.6.
Escalation. If you are dissatisfied with our response, you retain the right to lodge a complaint with your competent supervisory authority or state Attorney General, as applicable. We would, however, appreciate the opportunity to address your concerns directly in the first instance.
Language and Governing Provisions
Language. This Privacy Policy is drafted in the English language. Any translation is provided for convenience only. IN THE EVENT OF ANY DISCREPANCY, INCONSISTENCY, OR CONFLICT BETWEEN THE ENGLISH VERSION AND ANY TRANSLATION, THE ENGLISH VERSION SHALL PREVAIL.
Relationship to the Terms of Service. This Privacy Policy forms an integral part of our Terms of Service. In the event of conflict between this Policy and the Terms of Service on a matter of data protection, this Policy shall prevail in respect of that matter. All other matters are governed by the Terms of Service, including the governing law and dispute resolution provisions in Section 25 thereof.
Mandatory Local Law. Nothing in this Policy limits any right you hold under mandatory data protection law in your jurisdiction that cannot be derogated from by agreement.