New: CentriCall AI voice agents that answer, qualify, and book around the clock

Privacy Policy

What we collect, why we collect it, who sees it, how long we keep it, and what you can make us do about it.

Effective Last updated
The short version
  • The only information this website collects from you directly is what you type into the contact form. There is no analytics, no advertising, and no tracking on this site.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising — under any definition, in any jurisdiction.
  • When we build software for a client, any personal data inside that system belongs to the client. We process it on their instructions, under a written agreement.
  • You can ask us what we hold, correct it, delete it, or get a copy. Write to privacy@centriconetechnologies.com and we will answer within the time the law allows.

A summary, not a substitute. The sections below are what actually applies.

Who we are, and what this policy covers

Centricone Technologies (“Centricone”, “we”, “us”) is a custom software development company operating in the United States and Canada. Our registered office is [Registered office address].

This policy covers personal information we handle as a controller — that is, where we decide why and how it is processed. In practice that means visitors to this website, people who contact us, job applicants, and the individual contacts at our client and supplier organisations.

Information we collect

Information you give us

The contact form on this site asks for your name, email address, and a description of what you need. Company name, phone number, and enquiry topic are optional. Nothing on the form asks for sensitive information, and we would rather you did not put any into the message box — if your enquiry involves regulated data, tell us the shape of the problem and we will arrange a secure channel before you send details.

We also receive whatever you choose to put in an email, a job application, a signed agreement, or a document you share with us during a project.

Information collected automatically

Our hosting provider records standard server logs for every request: IP address, the page requested, timestamp, referring page, and browser user-agent string. These exist to keep the site available and to investigate abuse and faults. They are not used to build a profile of you, and they are not joined to anything you submit.

This site runs no analytics, no advertising pixels, no session recording, no fingerprinting, and no third-party embeds. Typefaces are compiled into the site at build time rather than fetched from a font service, so loading a page here does not tell any third party that you visited. The only thing stored on your device is a single record of your cookie-banner choice — see the Cookie Policy for the detail.

Information from other sources

We may receive your business contact details from a colleague who refers you, from a public professional profile, or from a partner who introduces us. Where we use a recruitment platform to advertise a role, we receive the application you submitted there.

We only use personal information for the purposes below. The third column is the lawful basis required under the EU and UK GDPR; if you are in a jurisdiction that does not use that framework, read it as a plain statement of why we consider the processing justified.

PurposeWhat we useLawful basis
Answering your enquiry and preparing a proposalContact form fields, email correspondenceSteps taken at your request before entering a contract
Delivering a project and supporting what we have builtClient contact details, project correspondencePerformance of our contract with your organisation
Invoicing, accounting, and tax recordsBilling contacts, transaction recordsLegal obligation, and our legitimate interest in running the business
Keeping the site available and investigating abuseServer logsLegitimate interest in the security and integrity of our systems
RecruitmentApplication, CV, interview and assessment notesSteps taken at your request before entering a contract
Sending an occasional update to an existing client contactName, business emailLegitimate interest, with an unsubscribe link in every message
Defending legal claims and meeting regulatory requestsWhatever is relevant to the matterLegal obligation, and our legitimate interest in defending claims
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can object — see “Your rights” below.

We do not use your personal information to make automated decisions that produce legal or similarly significant effects about you. No profiling, no automated scoring of enquiries, no algorithmic sift of job applications — a person reads each one.

Who we share it with

We share personal information only in the situations listed here, and only to the extent needed for that purpose.

Recipient categoryWhyWhat they receive
Hosting and infrastructure providersTo serve this website and store our working dataWhatever passes through or is stored on the platform
Form delivery serviceContact form submissions are forwarded to the inbox or CRM that our team monitorsThe contents of your enquiry
Email, calendar, and collaboration toolsOrdinary business correspondenceCorrespondence and documents you send us
Accounting and payment processorsInvoicing and bookkeepingBilling contact and transaction details
Professional advisersLegal, accounting, and insurance adviceOnly what is relevant to the advice sought
Authorities and courtsWhere the law requires it, or to establish or defend a legal claimOnly what is legally required
An acquirerIf the business is sold, merged, or reorganisedRecords relevant to the transaction, under confidentiality

Every supplier that handles personal information for us is bound by a written contract that limits them to our instructions, requires appropriate security, and forbids them from using the data for their own purposes.

International transfers

We operate in the United States and Canada, and our suppliers are largely based there. If you are in the EEA, the UK, or Switzerland and you contact us, your information will be transferred outside your country.

Where we make such a transfer we rely on an approved safeguard — usually the European Commission’s Standard Contractual Clauses together with the UK Addendum, plus any supplementary measures the transfer risk assessment calls for. If you are in Quebec, note that we assess the protection available in the receiving jurisdiction before personal information leaves the province, as Law 25 requires. You can ask us for a copy of the safeguards that apply to your data.

How long we keep it

We keep personal information only as long as it is doing a job. The periods below are our defaults; a specific record may be kept longer where a legal hold, an active dispute, or a statutory retention rule requires it.

RecordKept for
Enquiries that do not become a projectUp to 24 months from the last contact, then deleted
Client project records and correspondenceFor the life of the engagement, then up to 7 years for warranty, audit, and limitation-period reasons
Contracts, invoices, and accounting recordsAs long as tax and company law require — commonly 7 years
Unsuccessful job applications12 months, so we can come back to you about a later role. Ask us and we will delete it sooner
Server logsA rolling window, typically 30 to 90 days
Your cookie-banner choiceHeld on your own device until you clear it — see the Cookie Policy

How we protect it

The site is served over HTTPS. Access to our systems requires multi-factor authentication and is granted on a least-privilege basis. Client environments and credentials are kept separate from one another. Devices are encrypted, and access is revoked when someone leaves. Engineers work against non-production data wherever the task allows it.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information and is likely to result in a risk to your rights, we will notify you and the relevant regulator within the deadline that applies — 72 hours under the GDPR and under Quebec’s Law 25, and without unreasonable delay under the applicable US state and Canadian federal rules.

Your rights

Rights everyone has with us

  • Access — ask what we hold about you and get a copy of it.
  • Correction — have inaccurate or incomplete information fixed.
  • Deletion — have your information erased, where we have no overriding reason or legal duty to keep it.
  • Opt out of marketing — unsubscribe from any update we send, at any time, with no effect on anything else.

If you are in the EEA, the UK, or Switzerland

In addition to the above, you have the right to restrict processing, to object to processing based on legitimate interests, to data portability, and to withdraw consent at any time where consent is the basis we rely on — withdrawal does not affect processing already carried out. You also have the right to lodge a complaint with your local supervisory authority, and we would ask that you give us the chance to put it right first.

If you are a California resident

Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use, disclose, and retain; to obtain a copy of it; to correct it; to delete it; to opt out of its sale or sharing; and to limit the use of sensitive personal information. As set out above, we do not sell or share personal information and we do not use sensitive personal information for any purpose that triggers the right to limit — so those last two rights have nothing to act on here, but you may still exercise them.

We will not discriminate against you for exercising any of these rights: no denial of service, no different pricing, no lesser quality of service. You may use an authorised agent, and we will ask for proof that you gave them permission. Opt-out preference signals such as Global Privacy Control have nothing to act on here, because there is no sale or sharing to stop — see the Cookie Policy.

If you are in another US state with a privacy law

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and the other states whose comprehensive privacy laws are in force have broadly the same set of rights: to confirm processing and access, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling. If we refuse a request you may appeal it, free of charge, by replying to our decision — we will respond to the appeal within the statutory window and tell you how to contact your state Attorney General if you are still unsatisfied.

If you are in Canada

Under PIPEDA you may ask for access to your personal information and challenge its accuracy and completeness, and you may challenge our compliance with the Act — first to us, and then to the Office of the Privacy Commissioner of Canada. If you are in Quebec, Law 25 additionally gives you the right to withdraw consent, to have information de-indexed or deleted in defined circumstances, to portability, and to be informed if a decision about you is made exclusively by automated processing. As noted above, we make no such decisions.

How to exercise any of this

Email privacy@centriconetechnologies.com, or write to [Privacy requests — postal address]. Tell us what you want and enough about yourself that we can find your records. We will verify who you are before we act — usually by replying to the email address already on the record, and we will not ask for more information than the request needs.

We answer within 30 days in most jurisdictions, and within 45 days for requests under US state privacy laws, extending only where the law permits and telling you if we do. There is no charge, unless a request is manifestly unfounded or excessive — in which case we will explain the charge before doing the work.

Children

This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information, tell us and we will delete it.

Where we link out — to a client’s site, a partner, or a source we cite — that site has its own privacy practices, and this policy does not cover them. Read theirs before you hand anything over.

Changes to this policy

We update this policy when what we do changes, and we revise the “last updated” date at the top of the page whenever we do. If a change materially affects how we use information we already hold about you, we will tell you directly rather than relying on you to notice — by email where we have an address for you, or by a notice on the site where we do not.

Contact us

For anything in this policy, including rights requests and complaints: privacy@centriconetechnologies.com. For everything else: info@centriconetechnologies.com. Post reaches us at [Registered office address].

If you are unhappy with how we have handled a privacy matter, tell us and we will look at it properly. You are entitled to go to your data protection authority at any point, whether or not you raise it with us first.