Privacy Policy
Effective: May 30, 2026
We are a security and compliance consultancy, not a data business. We collect as little personal information as possible — essentially, whatever you choose to send us when you get in touch.
We have never sold or shared personal information, and we don’t intend to. We don’t advertise, we don’t run tracking pixels, we don’t follow you around the internet, and we don’t buy contact lists or use data enrichment services. Everything we hold about you came from you.
The rest of this page explains the details.
What we collect
When you contact us. Our contact form asks for your first name, last name, email address, and your message. Company name is optional. If you email us directly instead, we receive whatever you write and the address you send it from.
When you book a meeting. Our scheduling tool records your name, email address, the meeting details you provide, and your time zone.
When you use our Trust Center. You accept a non-disclosure agreement before viewing our security documentation. We keep a record of who accepted it, when, and which documents were accessed.
When we meet by video. We sometimes record client and prospect meetings. When we do, everyone in the meeting is notified before recording starts.
When you visit our website. Our analytics tool records standard information about site usage — pages viewed, the site that referred you, and an approximate location based on your IP address. This tells us which pages are useful. It does not tell us who you are.
That is the complete list. We don’t collect payment details through this site, we don’t run a newsletter, and we don’t operate a live chat.
What we don’t do
We think this matters as much as what we do collect:
We have never sold personal information, and we never will.
We don’t share your information with anyone for their own marketing or business purposes. No lead swaps, no partner lists, no co-marketing data exchanges.
We don’t run advertising or retargeting pixels. No social media trackers, no ad platform tags.
We don’t track you across other websites.
We don’t buy contact data, scrape it, or use enrichment services.
We don’t build profiles about you or make automated decisions about you.
We don’t collect sensitive information — no government identifiers, financial credentials, health information, or precise location.
Please don’t send confidential or security-sensitive details through our contact form. If you need to share something sensitive, get in touch and we’ll set up a secure channel.
Why we have your information
We use what we collect for four things:
To answer you — responding to your inquiry, sending information you asked for, arranging a meeting.
To do the work — delivering our services, managing the relationship, and invoicing.
To keep things secure — protecting our site and forms from automated abuse.
To meet our obligations — keeping financial and contractual records, and responding where the law requires it.
We also use website analytics to understand how our site is used and improve it.
Who else can see it
We use a small number of established service providers to run our business — website hosting, business email and calendar, file storage, video conferencing, electronic signature, accounting and invoicing, and our Trust Center. They process information on our instructions, under contracts requiring confidentiality, and only to provide their service to us.
Our affiliated companies, Atlas One Cyber Ltd and Atlas One Group Ltd, may handle information where needed to deliver our services.
We may also disclose information where the law requires it — for example, in response to valid legal process. We have not had to do this. And if Atlas One were ever acquired or merged, information could transfer as part of that transaction; we’d tell you before your information became subject to a different policy.
We are based in the United States, and information we hold is stored there.
Cookies
We use a handful of cookies:
Security cookies to protect our forms from request forgery for the duration of your session
Analytics cookies to measure how the site is used for up to 2 years
reCAPTCHA to prevent automated abuse of our contact form for about 6 months
Font loading to display our typefaces
We don’t use advertising cookies of any kind. Our analytics is deliberately configured without advertising features or cross-device tracking — it measures our own site and nothing else.
You can block or delete cookies through your browser settings. Blocking the security cookie may stop parts of our site working properly.
How long we keep things
We keep information only as long as we actually need it:
Inquiries that don’t lead to work — about a year
Client and business contacts — for as long as we’re working together, and afterwards while there’s a genuine business or legal reason
Financial and contractual records — up to five years, or longer where the law requires
Website analytics — a few months
Meeting recordings — only as long as they’re useful to the engagement
When we no longer need something, we delete it.
Your choices
You can ask us to:
Tell you what we hold about you
Correct anything that’s wrong
Delete what we hold, unless we’re required to keep it
Stop using your information for a particular purpose
Send you a copy of what you gave us
Email privacy@atlasonesecurity.com and we’ll take care of it. We’ll usually respond within a month. If we need longer because a request is complicated, we’ll tell you why.
To protect you, we’ll want to be reasonably sure the request is really from you — normally by confirming it comes from an email address we already have on file. We won’t ask for more than we need. You’re welcome to have someone act for you, provided you give them written permission.
We won’t treat you differently for asking. There is no penalty for exercising any of this.
If you’re in the UK or Europe and you’re unhappy with how we’ve handled something, you can complain to the data protection authority where you live. We’d appreciate the chance to sort it out first.
Security
We take this seriously, as you’d expect from a firm that advises others on it. We encrypt information in transit and at rest, limit access to people who need it, review our service providers before we engage them, train our people, and maintain incident response procedures.
No system is perfectly secure, and we won’t claim otherwise. If a security incident affected your information, we would tell you and the relevant authorities where the law requires it.
You can learn more about our security posture through our Trust Center.
A few other things
Children. We work with businesses. Our services are not directed to children, and we don’t knowingly collect information from anyone under 16. If you think we have, tell us and we’ll delete it.
Links to other sites. Our site links to other places, including our social profiles and Trust Center. Those sites have their own policies, and this one doesn’t cover them.
Changes. If we update this policy, we’ll change the date at the top and post the new version here. If we ever make a significant change — collecting something new, or using information differently — we’ll say so clearly on our website first.
Contact us
Atlas One Security, Inc.
532 W. 1st Street
Claremont, CA 91711
United States
For anything that isn’t a privacy question, use our contact form or inquiries@atlasonesecurity.com.
