1. Scope
This Data Privacy Framework Privacy Notice describes how Hexsis Enterprise LLC, doing business as Hexsis (“Hexsis,” “we,” “us,” or “our”), collects, uses, discloses, retains, and otherwise processes personal data received in the United States:
- From the European Union and European Economic Area in connection with the EU-U.S. Data Privacy Framework; and
- From the United Kingdom and Gibraltar in connection with the UK Extension to the EU-U.S. Data Privacy Framework.
This Notice applies to personal data other than human resources data. It does not apply to personal data concerning current or former employees that is transferred in the context of an employment relationship.
This Notice supplements any other privacy notice or contractual privacy terms provided by Hexsis. Where this Notice conflicts with the EU-U.S. Data Privacy Framework Principles, the Principles will govern with respect to personal data covered by this Notice.
2. Data Privacy Framework participation
Hexsis Enterprise LLC has submitted an initial self-certification application to the U.S. Department of Commerce under the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”) and the UK Extension to the EU-U.S. DPF.
Hexsis’s self-certification has not yet been finalized by the U.S. Department of Commerce. Hexsis does not claim participation in or certification under the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF unless and until the U.S. Department of Commerce notifies Hexsis that its self-certification has been finalized.
Hexsis commits to apply the applicable EU-U.S. DPF Principles to personal data covered by this Notice following completion of its self-certification.
Further information about the Data Privacy Framework program is available on the U.S. Department of Commerce Data Privacy Framework website:
3. Hexsis’s roles
Depending on the circumstances, Hexsis may process covered personal data in one or both of the following capacities:
As a controller
Hexsis acts as a controller when it determines why and how personal data is processed, such as when managing its website, enquiries, prospective and existing customer relationships, contracts, invoicing, security, and business operations.
As a processor or service provider
Hexsis acts as a processor or service provider when it processes personal data on behalf of a customer in connection with software development, maintenance, support, hosting, consulting, project management, or related technology services.
When acting as a processor or service provider, Hexsis processes personal data according to the relevant customer’s documented instructions and applicable contractual requirements. The customer generally determines the purposes and means of that processing.
4. Personal data covered
The categories of personal data Hexsis may receive and process include:
Identity and business-contact information
- Names
- Business and personal email addresses
- Telephone numbers
- Postal addresses
- Job titles and professional roles
- Employer, customer, client, or other organization information
- Professional profile information
- Contact preferences
Customer, prospect, and relationship information
- Enquiries and requests for proposals
- Customer and prospect correspondence
- Meeting information
- Project requirements
- Contract and account information
- Customer relationship records
- Feedback and survey responses
Account and authentication information
- Usernames and account identifiers
- Passwords in encrypted or hashed form
- Authentication tokens
- Access permissions and roles
- Login and account activity
- Multi-factor authentication information
- Security-verification information
Communications and support information
- Email and other business communications
- Support tickets
- Chat messages
- Call or meeting records
- Technical-support requests
- Issue reports
- Files and attachments submitted in connection with services
Technical, device, and usage information
- Internet Protocol addresses
- Browser and device information
- Operating-system information
- Cookie and similar technology identifiers
- Application activity
- Website and service usage information
- Referring URLs
- Access dates and times
- Diagnostic information
- System, security, audit, and application logs
- Error reports
Financial, billing, and transaction information
- Billing names and addresses
- Invoice information
- Payment status
- Transaction records
- Tax and accounting information
- Limited payment information received from payment-service providers
Hexsis generally does not directly store complete payment-card details where payments are handled by a third-party payment processor.
Project and client-controlled data
Hexsis may process personal data contained in software applications, source systems, databases, development environments, testing environments, production environments, files, integrations, backups, support systems, and other technology resources belonging to or controlled by its customers.
The nature of this data depends on the customer, project, and software system involved. It may include:
- Customer or end-user records
- Account and profile information
- Transaction and activity information
- Communications
- Uploaded content
- Support information
- Analytics data
- Business records
- Data concerning a customer’s users, personnel, suppliers, partners, or other individuals
Visitor information
When an individual visits a Hexsis website or interacts with online services, Hexsis may process:
- IP address
- Browser and device data
- Website interactions
- Cookie identifiers
- Enquiry-form information
- Analytics and diagnostic information
- Marketing preferences
Sensitive personal data
Depending on the services Hexsis provides to a customer, client-controlled systems may contain personal data regarded as sensitive under applicable law or under the DPF Principles.
Hexsis does not use sensitive personal data received on behalf of a customer for Hexsis’s own independent purposes. Where required by the DPF Principles, Hexsis will obtain affirmative express consent before disclosing sensitive personal data to a non-agent third party or using it for a purpose materially different from the purpose for which it was originally collected or subsequently authorized.
Hexsis asks customers not to provide sensitive personal data unless it is necessary for the relevant services and appropriately protected.
5. Sources of personal data
Hexsis may receive personal data:
- Directly from the individual
- From customers and prospective customers
- From users of customer applications and services
- From organizations engaging Hexsis as a processor or service provider
- From authorized customer personnel
- From contractors, suppliers, and business partners
- Through websites, applications, integrations, and communication systems
- Through cloud, hosting, analytics, security, payment, and other service providers
- From publicly available professional or business sources
- Through automated technologies such as cookies, logs, and analytics tools
6. Purposes of processing
Hexsis may process covered personal data for the following purposes:
Providing professional and technology services
- Designing and developing software
- Building websites, web applications, mobile applications, APIs, platforms, and internal tools
- Software testing and quality assurance
- Software deployment and migration
- Hosting and infrastructure management
- Software maintenance
- Troubleshooting
- Technical support
- Consulting
- Project management
- Product and user-experience design
- Data migration and system integration
- Security monitoring
- Performance monitoring
- Service administration
- Providing other services requested by customers
Managing customer and prospect relationships
- Responding to enquiries
- Preparing proposals and quotations
- Conducting meetings
- Communicating about projects and services
- Managing customer accounts
- Providing customer service
- Maintaining business records
- Obtaining feedback
- Managing contracts and commercial relationships
Operating and improving Hexsis
- Administering websites and services
- Diagnosing technical problems
- Monitoring reliability and performance
- Improving products, services, processes, and security
- Conducting internal analytics
- Managing suppliers and service providers
- Business planning
- Protecting business continuity
Hexsis will not use client-controlled personal data to train generalized artificial-intelligence models unless the relevant customer has expressly authorized such use and all applicable DPF requirements have been satisfied.
Security and fraud prevention
- Authenticating users
- Managing permissions and access controls
- Detecting and investigating suspicious activity
- Preventing fraud and abuse
- Protecting systems, networks, users, customers, and data
- Maintaining audit and security logs
- Responding to security incidents
- Enforcing contractual and acceptable-use requirements
Billing and business administration
- Preparing and issuing invoices
- Processing and recording payments
- Accounting and financial reporting
- Tax administration
- Contract administration
- Recordkeeping
- Managing insurance, legal, and professional-adviser relationships
Legal and compliance purposes
- Complying with applicable laws and lawful government requests
- Responding to legal proceedings
- Establishing, exercising, or defending legal claims
- Enforcing agreements
- Conducting audits and compliance reviews
- Protecting the rights, property, safety, and interests of Hexsis, its customers, users, and others
- Supporting corporate transactions, subject to appropriate safeguards
Marketing and business development
Where permitted by law, Hexsis may use business-contact information to:
- Communicate about Hexsis services
- Send relevant business communications
- Manage event or meeting invitations
- Conduct business development
- Measure engagement with communications
Individuals may opt out of marketing communications at any time by using the unsubscribe mechanism provided in the communication or contacting Hexsis.
7. Data minimization and purpose limitation
Hexsis takes reasonable measures to limit personal data to information that is relevant for the purposes described in this Notice.
Hexsis will not process covered personal data in a manner incompatible with the purposes for which it was originally collected or subsequently authorized by the individual.
To the extent necessary for those purposes, Hexsis takes reasonable steps to ensure that covered personal data is reliable for its intended use, accurate, complete, and current.
Where Hexsis processes personal data on behalf of a customer, the customer is responsible for determining the purposes for which the data is collected and for providing appropriate instructions to Hexsis.
8. Disclosure of personal data
Hexsis may disclose covered personal data to the following categories of recipients:
Customers and authorized users
Hexsis may disclose personal data to the customer on whose behalf it processes the data and to users or personnel authorized by that customer.
Service providers and agents
Hexsis may engage service providers and agents that assist with:
- Cloud computing
- Website and application hosting
- Data storage and backup
- Content delivery
- Software development and deployment
- Communications and collaboration
- Customer support
- Project management
- Security, monitoring, and incident response
- Analytics
- Authentication and identity management
- Payment processing
- Accounting and invoicing
- Legal and professional services
- Business administration
These providers may access personal data only where reasonably necessary to provide services to Hexsis or its customers.
Contractors and subcontractors
Hexsis may disclose personal data to contractors and subcontractors supporting customer projects or Hexsis operations. Such parties are subject to appropriate confidentiality, security, and data-protection obligations.
Professional advisers
Hexsis may disclose relevant information to legal counsel, accountants, auditors, insurers, financial advisers, and other professional advisers where reasonably necessary.
Corporate transactions
Personal data may be disclosed in connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets, insolvency, or similar corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
Legal and public-authority requests
Hexsis may be required to disclose personal data in response to lawful requests by public authorities, including requests made to meet national-security or law-enforcement requirements.
Hexsis may also disclose personal data where it reasonably believes disclosure is necessary to:
- Comply with applicable law, regulation, subpoena, court order, or legal process
- Protect the rights, property, or safety of Hexsis, its customers, users, or others
- Investigate fraud, abuse, security incidents, or illegal activity
- Establish, exercise, or defend legal claims
9. Accountability for onward transfers
When Hexsis transfers covered personal data to a third party acting as an agent on its behalf, Hexsis will:
- Transfer the data only for limited and specified purposes;
- Require the agent to provide at least the same level of privacy protection required by the applicable DPF Principles;
- Take reasonable and appropriate steps to ensure that the agent processes the personal data consistently with Hexsis’s DPF obligations;
- Require the agent to notify Hexsis if it determines that it can no longer meet its privacy-protection obligations; and
- Upon notice, take reasonable and appropriate steps to stop and remediate unauthorized processing.
For transfers to non-agent third parties, Hexsis will comply with the Notice and Choice Principles and enter into appropriate contractual arrangements where required.
Hexsis remains responsible under the DPF Principles if an agent processes covered personal data in a manner inconsistent with the Principles, unless Hexsis proves that it was not responsible for the event giving rise to the damage.
10. Individual choice
Hexsis provides individuals with the opportunity to opt out before their covered personal data is:
- Disclosed to a non-agent third party; or
- Used for a purpose materially different from the purposes for which it was originally collected or subsequently authorized.
Requests may be submitted using the contact details in Section 18.
Hexsis may not be able to provide an opt-out where disclosure or processing is:
- Required or permitted by law;
- Necessary to provide a service requested by the individual or the relevant customer;
- Performed by an agent acting under appropriate contractual restrictions;
- Necessary for security, fraud prevention, legal claims, or compliance; or
- Otherwise permitted under the DPF Principles.
For sensitive personal data, Hexsis will obtain affirmative express consent where required by the DPF Principles.
Where Hexsis processes personal data solely as a processor or service provider, the relevant customer may be responsible for providing applicable choices. Hexsis will reasonably assist the customer in fulfilling those obligations.
11. Access, correction, and deletion rights
Individuals whose personal data is covered by this Notice may have the right to:
- Obtain confirmation of whether Hexsis processes their covered personal data;
- Access the covered personal data Hexsis holds about them;
- Request correction or amendment of inaccurate personal data; and
- Request deletion of personal data processed in violation of the DPF Principles or where deletion is otherwise appropriate.
These rights may be limited where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy, where another person’s rights would be violated, or where another exception under the DPF Principles applies.
Hexsis may take reasonable steps to verify the identity and authority of the person making a request before responding.
Where Hexsis processes personal data on behalf of a customer, individuals should generally direct their request to that customer. Hexsis will reasonably assist the customer in responding to the request as required by applicable contractual and legal obligations.
12. Security
Hexsis takes reasonable and appropriate technical, administrative, and organizational measures designed to protect covered personal data against:
- Loss
- Misuse
- Unauthorized access
- Unauthorized disclosure
- Alteration
- Destruction
The measures used depend on the nature of the personal data, the context of processing, and the risks involved. Measures may include access controls, authentication, encryption, logging, monitoring, backup procedures, vulnerability management, confidentiality obligations, and security policies.
No system or method of transmission is completely secure. Hexsis therefore cannot guarantee absolute security.
13. Data retention
Hexsis retains covered personal data only for as long as it serves a purpose of processing compatible with the purpose for which it was collected or as otherwise permitted under the DPF Principles.
Retention periods depend on factors including:
- The nature of the data
- The purpose for which it is processed
- Customer instructions
- Contractual requirements
- Security and operational requirements
- Applicable limitation periods
- Legal, tax, accounting, and compliance obligations
When Hexsis no longer needs personal data, it will delete, anonymize, return, or securely dispose of it, as appropriate.
Where Hexsis processes personal data for a customer, retention and deletion are generally governed by the relevant customer agreement and documented instructions.
14. Complaints and internal resolution
In connection with its pending self-certification under the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, Hexsis commits to resolve complaints about its collection or use of personal data that would be covered by those frameworks following completion of its self-certification.
Individuals with enquiries or complaints should first contact Hexsis at:
Email: privacy@hexsis.com
Postal address:
Hexsis Enterprise LLC
542 Washington Ave, Miami Beach, 33139, Florida, United States
Please include sufficient information for Hexsis to understand the enquiry or complaint. Hexsis will investigate and attempt to resolve DPF-related complaints in accordance with the DPF Principles.
15. Independent dispute resolution through JAMS
Hexsis has designated JAMS as its independent recourse mechanism for unresolved complaints concerning non-human-resources personal data covered by this Notice.
If a complaint concerning covered personal data cannot be resolved directly with Hexsis, an individual may submit the complaint to JAMS. JAMS dispute-resolution services under the DPF are provided at no cost to the individual.
Information about the JAMS Data Privacy Framework dispute-resolution process is available at:
https://www.jamsadr.com/DPF-Dispute-Resolution
A DPF complaint may be filed with JAMS at:
https://www.jamsadr.com/file-a-dpf-claim
Individuals may also contact their applicable EU data protection authority, the United Kingdom Information Commissioner’s Office, or the Gibraltar Regulatory Authority, as applicable. Those authorities may work with the U.S. Department of Commerce and the Federal Trade Commission to investigate and resolve complaints.
16. Binding arbitration
Under certain conditions, individuals may invoke binding arbitration for residual claims concerning Hexsis’s compliance with the DPF Principles when other available dispute-resolution procedures have been exhausted.
Binding arbitration is subject to the terms, conditions, and procedures set forth in Annex I of the EU-U.S. DPF Principles.
Further information is available through the U.S. Department of Commerce’s Data Privacy Framework website.
17. Regulatory oversight and enforcement
Hexsis is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Following completion of Hexsis’s self-certification, Hexsis’s commitments under the DPF Principles will be enforceable under United States law.
Hexsis will respond promptly to enquiries and requests from the U.S. Department of Commerce concerning its application for and, following completion of its self-certification, participation in the Data Privacy Framework program.
18. Contact Hexsis
Questions, requests, complaints, or concerns concerning this Notice or Hexsis’s handling of covered personal data may be submitted to:
Hexsis Enterprise LLC
Doing business as Hexsis
Privacy email: privacy@hexsis.com
Postal address: 542 Washington Ave, Miami Beach, 33139, Florida, United States
Website: https://hexsis.com
For access, correction, deletion, or choice requests, please include:
- Your name and contact information;
- The organization or customer associated with your data, where relevant;
- A description of the data or processing involved; and
- The action you are requesting.
Hexsis may request additional information where reasonably necessary to verify identity, locate the relevant information, or understand and respond to the request.
19. Changes to this Notice
Hexsis may update this Notice to reflect changes in its practices, legal obligations, services, or participation in the Data Privacy Framework program.
Hexsis will publish the revised Notice and update the “Last updated” date. Where required, Hexsis will provide additional notice or obtain consent before applying material changes to covered personal data previously collected.
Any amendment will remain consistent with the applicable DPF Principles.