Contents
- Scope and our role
- Information we collect
- Sources of information
- How we use information
- Managed services and customer systems
- Cookies, analytics, and online technologies
- When we disclose information
- Retention and deletion
- Security
- Privacy rights and requests
- State and international privacy rights
- Communications
- Children
- Third-party services and links
- Changes and contact information
1. Scope and Our Role
This Privacy Policy applies to information handled by CyberTek Solutions through cyberteks.ai, our quote and contact forms, customer onboarding, support interactions, service delivery, billing and account administration, and other direct interactions with CyberTek Solutions.
For information we collect for our own business purposes, CyberTek Solutions generally acts as the business, controller, or similar responsible party under applicable privacy law. Examples include website inquiries, prospective-customer information, billing contacts, and our own account records.
For some managed IT, cybersecurity, email, hosting, VoIP, backup, monitoring, website-management, or similar services, we may process information on behalf of a business, government office, nonprofit organization, or other customer. In those circumstances, the customer may act as the controller or business and CyberTek Solutions may act as its processor, service provider, contractor, or subprocessor. Requests concerning information controlled by one of our customers may need to be directed to that customer.
A signed master services agreement, service order, statement of work, data processing agreement, business associate agreement, government procurement document, or other written agreement may contain additional privacy and security terms. If a signed agreement conflicts with this policy for a particular service relationship, the signed agreement controls to the extent of that conflict.
2. Information We Collect
The information we collect depends on how you interact with CyberTek Solutions and which services you use. We may collect the following categories of information:
Contact and identifying information
- Name, business or organization name, job title, department, email address, telephone number, mailing address, service address, and other contact details.
- Authorized contacts, account administrators, employees, end users, technical contacts, billing contacts, and emergency contacts supplied by a customer.
Account, authentication, and support information
- Account identifiers, usernames, authentication records, service entitlements, customer numbers, account preferences, support-ticket history, and communications with our technicians.
- Credentials, access tokens, API keys, remote-access information, or administrative access details when reasonably necessary to configure or support a customer's systems. We encourage customers to use secure credential-sharing methods whenever available.
Commercial, billing, and transaction information
- Quotes, estimates, orders, subscriptions, license counts, equipment selections, service history, invoices, payment status, tax information, purchase history, and related records.
- Payment-card and bank information may be collected by a third-party payment processor. CyberTek Solutions may receive transaction confirmations, tokens, limited account details, or payment-status information rather than full payment credentials.
IT, device, network, and security information
- Device names, device identifiers, IP addresses, MAC addresses, operating-system and software information, patch status, hardware inventory, network topology, configuration information, logs, system health, security events, vulnerability information, malware detections, login events, and similar technical telemetry.
- Information generated by remote monitoring and management tools, endpoint security products, managed detection and response services, firewalls, email-security systems, backup platforms, network equipment, and other tools used to provide contracted services.
VoIP and communications information
- Telephone numbers, extensions, device identifiers, call-routing settings, voicemail settings, call-detail records, timestamps, calling and called numbers, fax-related records, number-porting information, emergency-service location information, and similar service data.
- If a customer enables features such as call recording, voicemail transcription, fax storage, or message transcription, the content of those communications may be processed or stored as needed to provide the enabled feature. Customers are responsible for using recording and monitoring features in accordance with applicable law and required notices or consents.
Website, hosting, domain, and email information
- Domain names, DNS records, website files, databases, content, media, analytics information, hosting configuration, email addresses, aliases, mailbox configuration, delivery logs, spam and security events, and other information reasonably necessary to provide hosting, website, domain, or email services.
- Content supplied by customers for websites, email systems, file storage, or other hosted services. Depending on the service, this content may contain personal information about the customer's employees, users, patients, residents, customers, vendors, or other third parties.
Information visible during support
Remote or onsite technical support may incidentally expose files, emails, applications, documents, browser content, customer records, security footage, credentials, or other information displayed on a device or system. Our personnel are expected to access only the information reasonably necessary to diagnose, support, secure, or administer the systems within the scope of the requested or contracted service.
Website and technical usage information
- IP address, browser type, device type, operating system, referring page, pages visited, timestamps, approximate geographic information derived from IP address, error information, and similar logs generated when you use our website or online services.
- Cookie identifiers, session information, preferences, and analytics data where such technologies are enabled.
Sensitive information
CyberTek Solutions does not seek sensitive personal information unless it is necessary for a specific service, required by law, supplied by the customer, or encountered while supporting customer-controlled systems. Depending on the service, customer systems may contain financial, health, government identifier, precise location, authentication, or other sensitive information. We process such information only as reasonably necessary for the applicable service, legal obligation, or authorized purpose.
3. Sources of Information
We may obtain information from:
- You directly, including through forms, telephone calls, email, support tickets, onboarding, contracts, quotes, and service requests.
- Your employer, organization, account administrator, department, or another authorized representative.
- Devices, networks, software, security tools, telephone systems, websites, and other systems we manage or support.
- Technology vendors, telecommunications carriers, payment processors, domain registrars, cloud providers, security providers, distributors, and other service partners.
- Publicly available sources, business directories, government records, websites, and professional or commercial sources where appropriate for legitimate business purposes.
4. How We Use Information
CyberTek Solutions may use information to:
- Respond to inquiries and prepare estimates, proposals, and quotes.
- Create, provision, configure, maintain, support, monitor, secure, troubleshoot, repair, migrate, or terminate services.
- Manage user seats, licenses, subscriptions, devices, phone numbers, domains, hosting, email accounts, and related service inventory.
- Authenticate users, administer accounts, control access, and maintain audit records.
- Provide technical support and communicate about incidents, maintenance, outages, service changes, billing, renewals, and projects.
- Process orders, payments, invoices, credits, refunds where applicable, collections, taxes, and accounting records.
- Detect, prevent, investigate, and respond to malware, fraud, unauthorized access, abuse, spam, security threats, policy violations, and other harmful activity.
- Improve our website, services, support processes, documentation, customer experience, and internal operations.
- Maintain records, enforce agreements, establish or defend legal claims, comply with law, and respond to lawful requests.
- Send service-related communications and, where permitted, informational or marketing communications. You may opt out of nonessential marketing messages at any time.
- Evaluate or complete a merger, acquisition, financing, reorganization, sale of assets, or other business transaction, subject to applicable confidentiality and legal requirements.
5. Managed Services and Customer-Controlled Systems
Many CyberTek services require administrative or technical access to customer systems. Depending on the service, CyberTek personnel or automated tools may have access to servers, workstations, mobile devices, cloud platforms, Microsoft 365 or other productivity systems, email systems, websites, firewalls, switches, wireless networks, backups, telephone systems, security consoles, or other customer-controlled environments.
When we process information solely to provide services on a customer's behalf, we use that information according to the customer's documented instructions, the applicable service agreement, our legal obligations, and reasonable steps needed to protect the service and our systems. We do not claim ownership of customer content merely because we host, transmit, back up, monitor, or support it.
Customers are responsible for having appropriate authority to provide us access to their systems and data and for providing any notices or obtaining any consents required for their own employees, users, customers, residents, patients, callers, or other individuals. This is especially important for call recording, employee monitoring, security logging, video systems, health information, financial information, and other regulated or sensitive data.
6. Cookies, Analytics, and Online Technologies
Our website may use cookies, local storage, server logs, analytics technologies, embedded content, security services, or similar technologies. These technologies may be used to keep the site functioning, remember preferences, protect forms and accounts, measure performance, diagnose errors, understand traffic, and improve our services.
You can often control cookies through your browser settings. Blocking all cookies may affect website functionality. Third-party content or services embedded on our website may set their own cookies or collect information under their own privacy policies.
CyberTek Solutions does not knowingly sell personal information for monetary consideration. Some privacy laws define “sale,” “sharing,” or targeted advertising more broadly than an exchange for money. If our use of advertising, analytics, or similar technology becomes subject to an applicable opt-out requirement, we will provide the legally required choice mechanism and update this policy as appropriate.
Where applicable law requires us to recognize a qualifying browser-based opt-out preference signal, such as Global Privacy Control, we will process the signal as required for the browser or device from which it is received. If no legally regulated sale or sharing is occurring, such a signal may not change the operation of the site.
7. When We Disclose Information
We may disclose information only as reasonably necessary for the purposes described in this policy, including to:
- Service providers and subprocessors: hosting providers, cloud platforms, security vendors, remote-management vendors, backup providers, software vendors, payment processors, email providers, telecommunications carriers, distributors, domain registrars, analytics providers, and other vendors that help us operate or deliver services.
- Customer organizations: administrators, authorized contacts, managers, departments, or other representatives of the organization that purchased or controls the service.
- Professional advisors: attorneys, accountants, insurers, auditors, consultants, and financial institutions where reasonably necessary.
- Government and legal recipients: courts, law enforcement, regulators, government agencies, or other parties when we reasonably believe disclosure is required by law, subpoena, court order, lawful process, contract, or to protect rights, safety, systems, or property.
- Business transaction participants: actual or prospective buyers, sellers, lenders, investors, or advisors involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate safeguards.
- At your direction or with your consent: when you ask us to coordinate with another vendor, employee, consultant, carrier, or third party, or otherwise authorize a disclosure.
We may also disclose aggregated or de-identified information that is not reasonably linked to an identifiable individual, subject to applicable law.
8. Payment Information
Payments may be processed through third-party payment providers. Their handling of payment credentials is governed by their own privacy and security terms. CyberTek Solutions may retain invoice records, payment status, transaction identifiers, limited payment metadata, and other records needed for accounting, tax, customer service, fraud prevention, and legal compliance.
9. Retention and Deletion
We retain information for only as long as reasonably necessary for the purposes for which it was collected, to provide and secure services, maintain business and accounting records, comply with legal or contractual obligations, resolve disputes, enforce agreements, and establish or defend legal claims.
Retention periods vary by data type and service. For example, active customer records may be retained throughout the service relationship; invoices and accounting records may be retained for legally required periods; security logs may be retained according to operational or contractual needs; and backups may continue to contain information until they are overwritten through normal backup-rotation processes.
Termination of a service does not always cause immediate deletion from every system. Data may remain temporarily in backups, archives, logs, fraud-prevention records, legal holds, or records we are required to retain. When information is no longer needed, we may delete, anonymize, aggregate, or securely dispose of it consistent with our systems and legal obligations.
10. Security
CyberTek Solutions uses administrative, technical, and physical safeguards designed to protect information based on its sensitivity, the service involved, and reasonably available security practices. Measures may include access controls, authentication controls, encryption where appropriate, network segmentation, endpoint security, monitoring, logging, backup controls, least-privilege access, vendor security measures, and personnel procedures.
No security program, network, cloud platform, website, email system, backup, encryption method, or transmission method can be guaranteed to be completely secure. CyberTek Solutions therefore cannot guarantee that unauthorized access, loss, misuse, interruption, or disclosure will never occur.
Customers also play an important role in security. Customers should maintain accurate user lists, promptly report terminated or compromised accounts, use multifactor authentication where available, protect credentials, follow security recommendations, maintain supported systems, and notify us promptly of suspected incidents affecting services we manage.
11. Privacy Rights and Requests
Depending on where you live, the nature of your relationship with us, and whether a particular privacy law applies to CyberTek Solutions, you may have rights to request access to personal information, obtain a copy, correct inaccuracies, request deletion, request portability, opt out of certain processing, withdraw consent where processing depends on consent, or appeal a decision concerning a privacy request.
To submit a privacy request, contact us at [email protected] or call 931-967-3010. Please clearly state that your request concerns privacy and describe the right you wish to exercise.
We may need to verify your identity or authority before completing a request. Verification may depend on the sensitivity of the requested information and can include matching information already associated with your account, confirming control of an email address or telephone number, or requesting additional information reasonably necessary to prevent unauthorized disclosure or deletion.
An authorized agent may submit a request where permitted by law. We may require evidence of the agent's authority and may verify the request directly with the individual unless applicable law provides otherwise.
We may deny, limit, or charge for a request where permitted by law, including when we cannot reasonably verify the request, the request is manifestly unfounded or excessive, an exception applies, or fulfilling the request would interfere with legal obligations, security, fraud prevention, another person's rights, privileged information, or data that we process solely on behalf of another controller.
We will not unlawfully discriminate against an individual for exercising an applicable privacy right.
12. State and International Privacy Rights
Tennessee residents
The Tennessee Information Protection Act applies only to covered controllers that meet statutory thresholds and contains exemptions and limitations. If that law applies to CyberTek Solutions and to your information, eligible Tennessee consumers may have rights that include confirming whether personal information is processed, accessing information, correcting inaccuracies, deleting information provided by or obtained about the consumer, obtaining a portable copy, and opting out of certain sales, targeted advertising, or qualifying profiling. Applicable requests and appeals will be handled as required by law.
California residents
If the California Consumer Privacy Act applies to CyberTek Solutions and your information, California residents may have rights that include knowing or accessing categories and specific pieces of personal information, correcting inaccurate information, requesting deletion, obtaining information about categories of sources and recipients, opting out of sale or sharing where applicable, limiting certain uses or disclosures of sensitive personal information where applicable, and receiving equal service and pricing when exercising privacy rights, subject to statutory exceptions.
CyberTek Solutions does not knowingly sell personal information for money. If we engage in activity that constitutes a “sale” or “sharing” under California law, we will provide the notices and opt-out methods required for a covered business.
Other U.S. states
Other state privacy laws may provide similar rights. Where a state privacy law applies to CyberTek Solutions, we will process eligible requests consistent with that law, including applicable authentication, response, appeal, and exception requirements.
EEA, United Kingdom, and other international visitors
CyberTek Solutions is based in the United States and primarily provides services in the United States. If the EU General Data Protection Regulation, UK GDPR, or another international privacy law applies to a particular processing activity, our lawful basis may include performance of a contract, steps requested before entering a contract, legitimate interests such as operating and securing our business and services, compliance with legal obligations, or consent where required. Applicable individuals may have additional rights under local law.
Information may be processed and stored in the United States or other locations where our service providers operate. Those jurisdictions may have different data-protection laws than your home jurisdiction.
13. Email, Telephone, and Other Communications
We may contact customers and prospective customers about inquiries, quotes, service activation, support, maintenance, outages, security issues, billing, renewals, projects, account administration, and other transactional or service-related matters. These communications may be necessary to provide or administer the service and may not be subject to marketing opt-out requests.
Where permitted, we may also send promotional or informational communications. You may opt out of marketing emails by using an unsubscribe method included in the message when available or by contacting us. Opting out of marketing does not prevent service, security, billing, or other non-marketing communications.
14. Children's Privacy
Our website and services are intended for businesses, organizations, government offices, and adults seeking technology services. They are not directed to children under 13. We do not knowingly collect personal information online from children under 13 for our own marketing purposes. If you believe a child has provided personal information directly to us without appropriate authorization, contact us so we can review and take appropriate action.
A customer may operate systems that contain information about minors, such as schools, government programs, healthcare organizations, or family accounts. When we encounter that information while providing services to a customer, the customer is generally responsible for determining the lawful basis and required notices or consents, and we process the information within the scope of our service relationship.
15. Third-Party Services, Integrations, and Links
Our website and services may link to, embed, integrate with, resell, configure, or rely on third-party products and services. Examples can include telecommunications carriers, hardware manufacturers, cloud platforms, payment processors, email providers, cybersecurity vendors, domain registrars, software publishers, and other technology providers.
Third parties may collect and use information under their own terms and privacy policies. CyberTek Solutions is not responsible for the independent privacy practices of a third party acting outside our direction or control. Customers should review the terms and privacy practices of third-party services relevant to their deployment.
16. Legal Requests and Incident Response
We may preserve or disclose information when reasonably necessary to comply with law, respond to lawful process, investigate suspected fraud or security incidents, protect users or the public, enforce agreements, or protect the rights, property, systems, and safety of CyberTek Solutions, our customers, service providers, or others.
If a security incident involving information under our control triggers a legal or contractual notification obligation, we will provide notices as required by applicable law or contract. When we act as a processor or service provider for a customer, incident notification responsibilities may be governed by the applicable customer agreement.
17. Business Transfers
Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction. A successor may continue to use information in accordance with this policy unless it provides a different notice as required by law.
18. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, our services, vendors, or business practices. The “last updated” date at the top identifies the current version. If a change materially affects how we use personal information and applicable law requires additional notice or consent, we will provide that notice or obtain consent as required.
19. Contact CyberTek Solutions
Questions, privacy requests, complaints, or appeals concerning this policy may be submitted to:
If your request concerns information CyberTek Solutions processes only on behalf of one of our customers, we may direct you to that customer so the request can be handled by the organization responsible for the information.