Flectech ← Back to site

Privacy Policy

Flec Tech, Inc. · Last reviewed: 1/03/2022 Version: 1.0

1. About this Policy

Flec Tech, Inc. ("Flec Tech", "we", "us" or "our") is a managed service provider (MSP) delivering managed IT services, cybersecurity operations, cloud and infrastructure management, and technology consulting to organizations in the United States, Latin America and Europe.

This Policy explains how we handle personal information when you:

  • Visit flectech.com or any Flec Tech subdomain, portal or landing page (the "Site");
  • Contact us, request a proposal, or subscribe to our communications;
  • Attend a webinar, briefing or event we host or co-host;
  • Work for, or on behalf of, a Flec Tech client, prospect, partner or supplier; or
  • Apply for a role with us.

This Policy does not replace the confidentiality and data protection terms in your service agreement. If you are a Flec Tech client and there is a conflict between this Policy and your Master Services Agreement, Statement of Work or Data Processing Addendum, those contractual terms prevail for the data we handle on your behalf.

2. Two Very Different Roles - Please Read This Section

Because of the nature of managed services, Flec Tech handles personal information in two distinct capacities. Understanding which one applies to you determines who you should contact and what rights apply.

2.1 When we act for ourselves (controller / business)

We decide why and how information is used when we operate our Site, market our services, manage commercial relationships, invoice, recruit, and run our own internal systems. Sections 3 through 9 describe this activity.

2.2 When we act for a client (processor / service provider)

When we monitor endpoints, administer identity and email tenants, respond to security incidents, run backups, manage firewalls, operate a service desk or migrate systems, we access data that belongs to our client. Our client determines the purpose; we act on documented instructions.

In that capacity we do not decide what that data is used for, we do not use it for our own purposes, and we do not sell or share it for advertising. Our obligations are governed by the Data Processing Addendum executed with each client and, where applicable, by Standard Contractual Clauses or equivalent transfer instruments.

If you are an employee, customer, patient, student or contact of one of our clients and you want to exercise a privacy right over your data, please contact that organization directly. They are controllers. We will support them in responding, but we are generally not permitted to act on your request without their authorization. If you contact us in error, we will tell you so and, where we can identify the client, forward your request to them.

3. Information We Collect

We aim to collect the minimum necessary for each purpose. Depending on how you interact with us, we may collect:

Identification and contact data Name, business email address, telephone number, employer, job title, department, business postal address.

Commercial and relationship data Proposals and quotes issued, contracts, purchase orders, service tier, renewal dates, billing contacts, payment and remittance details, tax identifiers where required for invoicing or withholding.

Service and support data Service desk tickets and their contents, call and chat transcripts, remote session records, asset inventories, configuration records, license assignments, change records, and correspondence relating to the delivery of services.

Technical and telemetry data IP address, device and browser type, operating system, referring URL, pages viewed, session duration, and similar data collected through cookies and comparable technologies on the Site (see Section 10).

Security and operational data Authentication and access logs for systems we administer, alert and detection data, endpoint telemetry, network flow records, and forensic artifacts collected while monitoring or responding to an incident.

Recruitment data CV or résumé, employment and education history, certifications, references, right-to-work and work-authorization information, and interview notes.

Marketing preferences Subscription status, consent records, opt-outs, and engagement with our communications.

We do not intentionally seek out special category or sensitive data through the Site or our marketing. Sensitive information may nonetheless appear incidentally inside client systems we administer; where it does, we treat it strictly under our client's instructions and our contractual and technical safeguards.

4. How We Obtain Information

Directly from you — forms, email, telephone, meetings, contracts, support requests, event registrations, job applications.

From your employer or organization — when a client or partner designates you as a contact, administrator, approver or end user.

Automatically — through cookies, analytics and server logs when you use the Site.

From the systems we administer — telemetry and logs generated by managed endpoints, tenants and network devices, in each case as a processor for the relevant client.

From third-party sources — business directories, professional networks, vendor and distributor portals, publicly available registries, and lawfully obtained business contact databases used for B2B outreach.

5. Why We Use It, and Our Legal Basis

Where the GDPR, UK GDPR or Brazil's LGPD applies, we rely on the legal bases indicated below.

PurposeLegal basis (GDPR / UK GDPR)Legal basis (LGPD)
Delivering managed, security and consulting servicesContract; legitimate interestsExecution of contract
Operating the service desk and responding to requestsContract; legitimate interestsExecution of contract
Onboarding, account administration, invoicing and collectionsContract; legal obligationExecution of contract; legal obligation
Monitoring, detecting and responding to security threatsLegitimate interests (protecting our own and our clients' systems)Legitimate interests
Maintaining service quality, capacity planning and reportingLegitimate interestsLegitimate interests
B2B marketing to business contactsLegitimate interests, subject to opt-outLegitimate interests, subject to opt-out
Email marketing where consent is requiredConsentConsent
Site analytics and non-essential cookiesConsentConsent
Recruitment and hiringPre-contractual steps; legitimate interestsPre-contractual steps
Regulatory, tax, audit and legal defense obligationsLegal obligation; legitimate interestsLegal obligation; exercise of rights in proceedings

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You may ask us for a summary of that assessment.

Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.

6. We Do Not Sell Your Personal Information

Flec Tech does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended, or under comparable US state privacy laws. We have not done so in the preceding twelve months.

We do not use client data - including data held in client tenants, ticketing systems or endpoints - to train artificial intelligence or machine learning models. Where we use AI-assisted tooling internally to improve service delivery, we do so under enterprise agreements that prohibit vendor training on our inputs, and in accordance with our internal AI governance policy.

7. When We Disclose Information

We disclose personal information only in the following circumstances:

Service providers and sub-processors. Cloud hosting, security platforms, remote monitoring and management tooling, ticketing and PSA systems, identity providers, backup and recovery services, communications platforms, accounting and payment processors, and professional advisers. Each is bound by written terms requiring confidentiality, security and processing limited to our instructions. A current list of sub-processors used in service delivery is available to clients on request.

Technology vendors and distributors. Where necessary to register licenses, raise support cases on your behalf, or validate entitlements.

Affiliates. We may share information with affiliated entities under common ownership for administration and service delivery, subject to the same protections described here.

Legal and regulatory. Where required by law, subpoena, court order or lawful request from a public authority, or where necessary to establish, exercise or defend legal claims. We evaluate every such request and, unless legally prohibited, notify the affected client before disclosing data we hold on their behalf.

Corporate transactions. In connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and to this Policy continuing to apply to the transferred information.

We do not disclose personal information to third parties for their own independent marketing purposes.

8. International Transfers

We are headquartered in the United States and our clients operate across the Americas and Europe. Personal information may therefore be transferred to, stored in, or accessed from countries other than your own, including the United States and Brazil.

Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of the following:

  • The European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant;
  • An adequacy decision covering the destination country;
  • The EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, where we or the receiving party are certified; or
  • Another transfer mechanism recognized under applicable law.

Where personal information is transferred out of Brazil, we rely on the mechanisms recognized under Articles 33 to 36 of the LGPD, including standard contractual clauses approved by the ANPD and specific contractual guarantees.

We carry out transfer risk assessments where required and apply supplementary technical measures - including encryption in transit and at rest, key management controls and access restriction - to protect data in transit between jurisdictions.

Clients with data residency requirements should raise these during onboarding so we can configure services accordingly. We can accommodate region-pinned tenants, in-region backup targets and restricted administrative access models where the underlying platforms support them.

9. How Long We Keep Information

We keep personal information only as long as necessary for the purpose it was collected for, plus any period required by law, contract, or the establishment or defense of legal claims. Our current standards are:

Category

Retention

Prospect and marketing contact records

Until opt-out, or 24 months without engagement

Client contract and commercial records

Term of the agreement plus 7 years

Service desk tickets and service records

Term of the agreement plus 3 years

Security, audit and authentication logs (our own systems)

12 months, longer where under investigation

Client data held as processor

As instructed by the client; returned or deleted on termination per the DPA

Unsuccessful job applications

12 months, or longer with the applicant's consent

Financial, tax and accounting records

As required by applicable law, typically 7 years

Bracketed periods are subject to confirmation against Flec Tech's records retention schedule.

Data held in backups is deleted on the ordinary backup expiry cycle rather than immediately on request; until then it remains protected and is not returned to active use.

10. Cookies, Analytics and Site Technologies

The Site uses cookies and similar technologies. Strictly necessary cookies are required for the Site to function and cannot be switched off. Analytics, performance and marketing cookies are used only where you have given consent through our cookie banner, or where consent is not required in your jurisdiction and you have not opted out.

You can manage your preferences at any time through the cookie settings link on the Site, or through your browser controls. Disabling cookies may reduce Site functionality.

We honor Global Privacy Control and comparable opt-out preference signals where legally required.

Further details are available in our Cookie Policy at flectech.com/cookie-policy.

11. Security

We maintain an information security program with administrative, technical and physical controls appropriate to the risk, including:

  • Multi-factor authentication and conditional access for all administrative accounts;
  • Role-based and least-privileged access, with privileged access reviewed periodically and just-in-time elevation where supported;
  • Encryption of data in transit using current TLS standards, and encryption at rest on managed platforms;
  • Centralized logging, endpoint detection and response, and continuous monitoring;
  • Network segmentation and firewall management across managed environments;
  • Vulnerability management and patching within defined service windows;
  • Documented incident response and business continuity procedures, tested periodically;
  • Background screening, confidentiality obligations and mandatory security awareness training for personnel;
  • Security assessment of vendors and sub-processors before onboarding.

No system can be guaranteed completely secure. Email and other internet communications are not secure unless encrypted, and we cannot accept responsibility for interception outside our control. If you need to send sensitive material, ask us for a secure transfer link.

If we become aware of a personal data breach affecting information we hold as a controller, we will notify affected individuals and regulators where required and within the timeframes set by applicable law. Where we hold data as a processor, we notify the affected client without undue delay in accordance with the DPA so they can meet their own notification obligations.

12. Monitoring and Recording of Communications

We may monitor and record calls, service desk sessions, remote support sessions and electronic communications for quality assurance, training, security, dispute resolution and compliance purposes, where permitted by applicable law. Where consent or notice is required in your jurisdiction, we will obtain or provide it before recording.

13. Your Privacy Rights

The rights available to you depend on where you are located and on which capacity we are acting in (see Section 2).

13.1 EEA, United Kingdom and Switzerland

Subject to conditions and exemptions, you may request access to your personal data; correction of inaccurate or incomplete data; erasure; restriction of processing; portability; objection to processing based on legitimate interests; objection to direct marketing at any time; and withdrawal of consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects - we do not carry out such processing.

You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office if you are in the United Kingdom. We would appreciate the opportunity to address your concern first.

Our representative in the European Union for the purposes of Article 27 GDPR is [name and address, if applicable].

13.2 Brazil (LGPD)

You may request confirmation that processing takes place; access to your data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or excessive data or data processed unlawfully; portability to another provider; deletion of data processed with consent; information about entities with whom we have shared your data; information about the consequences of refusing consent; revocation of consent; and review of decisions taken solely by automated processing.

Requests may be addressed to the contact in Section 16. You may also petition the Autoridade Nacional de Proteção de Dados (ANPD).

13.3 California and other US states

Depending on your state of residence, you may have the right to: know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients; delete personal information, subject to exceptions; correct inaccurate personal information; opt out of sale, sharing for cross-context behavioral advertising, and certain targeted advertising and profiling - noting that we do not engage in these activities; limit the use of sensitive personal information; obtain a portable copy; and not be discriminated or retaliated against for exercising these rights.

You may designate an authorized agent to submit a request on your behalf. We will require proof of authorization and will verify your identity independently.

13.4 How to exercise your rights

Send your request to the contact in Section 16 and tell us what you are asking for and which relationship you have with us. We will verify your identity using information already in our possession before acting and will not use that information for any other purpose.

We respond within the timeframes set by applicable law - generally thirty days under the GDPR and LGPD, and forty-five days under US state laws, each extendable where permitted if we tell you why. There is no charge unless a request is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline, explaining our reasoning.

14. Job Applicants

We process application data to assess suitability, conduct interviews, check references and comply with employment and work-authorization requirements. Applications are visible only to those involved in the hiring process. Unsuccessful applications are retained as set out in Section 9 so we can consider you for future openings and evidence a fair process; you may ask us to delete your file at any time.

15. Children

Our Site and services are directed at businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16, or under 13 where a lower threshold applies. If you believe a child has provided us with personal information, contact us and we will delete it. Where we administer systems for education-sector clients, any student data involved is processed strictly as a processor under that client's instructions and the applicable education privacy laws.

16. Contact Us

Questions, requests and complaints about this Policy or our privacy practices:

Flec Tech, Inc. Attn: Privacy Team 1501 Biscayne Blvd. Ste 501 – Miami, FL 33132, United States

Email: privacy@flectech.com Telephone: +1 (305) 771-7538

For matters relating to data we process on behalf of a client, please also identify the client organization so we can route your request correctly.

17. Changes to This Policy

We review this Policy at least annually and update it when our practices or the law change. The current version is always published at flectech.com/privacy-policy with the effective date above. Where changes are material, we will provide additional notice - by email to registered contacts or by a prominent notice on the Site - before they take effect. Continued use of the Site after the effective date constitutes acknowledgment of the revised Policy.

18. Related Documents

Cookie Policy - flectech.com/cookie-policy

Terms of Use - flectech.com/terms

Data Processing Addendum - available to clients on request

Sub-processor list - available to clients on request

Acceptable Use Policy - available to clients on request

Flec Tech, Inc. is a company incorporated in Florida, United States. Flec Tech, Inc.

Privacy Policy · Terms of Service · Cookie Policy

© 2026 Flectech. All rights reserved.

Cookies

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking “Accept”, you consent to our use of cookies. Learn more