1. Introduction

BUSINESS AUTOMATION, INC. (“we,” “our,” “us”) is committed to protecting the privacy of individuals who visit our website, use our services, or interact with us in any way. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use any of our business automation, software development, IT consulting, or related services.

We understand that privacy is a fundamental right, and we take our responsibility to protect your personal data seriously. This policy applies to all information collected through our website, email communications, service engagements, and any other interactions you may have with BUSINESS AUTOMATION, INC.

Please read this Privacy Policy carefully. By accessing our website or using our services, you acknowledge that you have read and understood the practices described herein. If you do not agree with any part of this policy, you should discontinue use of our website and services immediately.

2. Information We Collect

2.1 Personal Information You Provide

We collect personal information that you voluntarily provide to us when you fill out forms on our website, subscribe to our newsletters, request a quote, communicate with us via email or phone, or enter into a service agreement with us. This information may include, but is not limited to, your full name, email address, telephone number, company name, job title, billing address, and payment information.

When you engage us for services, we may collect additional information necessary to fulfill our contractual obligations, such as project requirements, technical specifications, business processes, and system access credentials required to deliver our automation and IT solutions. We only collect information that is relevant and reasonably necessary for the purposes for which it is provided.

2.2 Information Collected Automatically

When you visit our website, we may automatically collect certain information about your device and browsing actions. This includes your IP address, browser type and version, operating system, referring URLs, pages viewed, time and date of visits, time spent on each page, and other diagnostic data. We collect this information using cookies, server logs, and similar tracking technologies as described in Section 9 below.

This automatically collected information helps us understand how visitors interact with our website, allows us to improve user experience, diagnose technical issues, and maintain the security and integrity of our systems. This data is generally aggregated and anonymized and is not used to personally identify you unless required by law or necessary for security investigations.

2.3 Information from Third Parties

In some circumstances, we may receive personal information about you from third-party sources. This includes business partners with whom we collaborate on joint projects, payment processors that handle financial transactions on our behalf, credit reference agencies for the purpose of credit checks when establishing accounts, and publicly available databases for the purpose of verifying business credentials. We combine this information with data we already hold about you only where it is lawful and necessary for our business purposes.

We also may receive information from referral partners or marketing platforms when they refer potential clients to us, provided that such referral complies with applicable privacy laws. When we receive information from third parties, we ensure that the third party has obtained your consent or is otherwise legally permitted to share your information with us.

3. How We Use Your Information

We use the information we collect for the following purposes:

4. Legal Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA), we process your personal data based on the following lawful bases under the General Data Protection Regulation (GDPR):

Consent: We may process your data when you have given explicit consent for one or more specific purposes, such as receiving marketing communications or cookies that are not strictly necessary. You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Contractual Necessity: We process personal data when it is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This includes providing our services, processing payments, and communicating about your projects.

Legal Obligation: We may process your personal data where it is necessary for compliance with a legal obligation to which we are subject, such as tax laws, anti-money laundering regulations, or responding to lawful requests from public authorities.

Legitimate Interests: We may process your personal data where it is necessary for our legitimate interests or those of a third party, provided that your interests, rights, and freedoms do not override those interests. Our legitimate interests include improving our services, ensuring network and information security, fraud prevention, direct marketing (where permitted), and internal administrative purposes.

5. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. However, we may share your information in the following circumstances:

Service Providers: We may share your information with trusted third-party service providers who assist us in operating our business, delivering our services, and serving our clients. These include cloud hosting providers, payment processors, email marketing platforms, customer relationship management (CRM) systems, analytics providers, and IT security vendors. All such providers are contractually obligated to maintain the confidentiality and security of your information and are prohibited from using it for any purpose other than the services they provide to us.

Professional Advisors: We may share your information with our legal counsel, accountants, auditors, and insurance providers where necessary for professional advice, compliance, and risk management purposes.

Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity as part of the transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or the use of your personal information.

Legal Requirements: We may disclose your information if required to do so by law, court order, or governmental regulation, or if we believe in good faith that such disclosure is necessary to comply with legal processes, protect our rights or property, enforce our Terms of Service, investigate fraud, or protect the personal safety of our users or the public.

With Your Consent: We may share your information with third parties for any other purpose with your explicit consent. You will be given the opportunity to opt in or out of such sharing at the time consent is requested.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period varies depending on the type of data and the nature of our relationship with you.

For client and prospect data, we generally retain information for the duration of our contractual relationship plus a period of seven (7) years following termination or completion of services, to comply with tax, legal, and regulatory obligations, and to address any potential disputes or claims that may arise.

For website analytics data, we retain anonymized aggregated data indefinitely for analytical purposes, while personal identifiers associated with analytics data are retained for a maximum of twenty-six (26) months. For marketing communications data, we retain your information until you unsubscribe or request deletion, at which point we will remove you from our active marketing lists.

When we no longer need to retain your personal information, we will securely delete or anonymize it in accordance with our data retention and disposal policies. In some circumstances, we may retain your data for longer periods where required by law or where deletion is not technically feasible.

7. Data Security

We implement a comprehensive set of technical, organizational, and administrative security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security measures include:

Encryption: All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) 1.2 or higher. Sensitive data stored in our databases is encrypted at rest using AES-256 encryption. Payment card information is handled by PCI-DSS compliant payment processors and is never stored on our servers in unencrypted form.

Firewalls and Network Security: Our systems are protected by enterprise-grade firewalls, intrusion detection and prevention systems (IDS/IPS), and virtual private networks (VPNs) for remote access. We conduct regular vulnerability assessments and penetration testing to identify and remediate potential security weaknesses.

Access Controls: Access to personal information is restricted to employees, contractors, and agents who need that information to perform their job functions. We implement role-based access controls (RBAC), multi-factor authentication (MFA), and maintain detailed access logs that are regularly audited.

Employee Training: All employees receive mandatory security awareness training upon hire and annually thereafter, covering topics such as data protection best practices, phishing awareness, password hygiene, and incident reporting procedures.

Incident Response: We maintain a documented incident response plan to quickly address any security breaches or data incidents. In the event of a data breach that affects your personal information, we will notify you and the relevant supervisory authorities as required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

Right of Access: You have the right to request confirmation of whether we process your personal data and, if so, to access that data along with information about how it is processed. We will provide a copy of the data in a commonly used electronic format.

Right to Correction: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will make the correction promptly and notify any third parties with whom we have shared the inaccurate data.

Right to Deletion (Right to Be Forgotten): You have the right to request the deletion of your personal data where there is no compelling reason for its continued processing. This right applies in circumstances such as where the data is no longer necessary, you withdraw consent, or the data has been unlawfully processed.

Right to Object: You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller without hindrance, where the processing is based on consent or contract and is carried out by automated means.

CCPA Rights (California Residents): If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect about you, the right to request deletion of your personal information, the right to opt out of the sale of your personal information (we do not sell personal information), and the right to non-discrimination for exercising your CCPA rights.

To exercise any of these rights, please contact us using the information provided in Section 14. We will respond to your request within thirty (30) days or as otherwise required by applicable law. We may need to verify your identity before processing certain requests.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. A cookie is a small text file that is placed on your device when you visit a website. We use the following categories of cookies:

Strictly Necessary Cookies: These cookies are essential for the proper functioning of our website and enable you to navigate our site and use its features. Without these cookies, certain services cannot be provided. These cookies do not collect any personal information and are set automatically when you access our site.

Functional Cookies: These cookies allow our website to remember choices you make (such as your language preference, region, or login information) and provide enhanced, more personalized features. The information collected by these cookies is anonymized and cannot track your browsing activity on other websites.

Analytics and Performance Cookies: We use analytics cookies, including those from Google Analytics, to collect information about how visitors use our website. These cookies help us understand which pages are most popular, how users navigate the site, and identify areas for improvement. The data collected is aggregated and anonymized.

Managing Cookies: Most web browsers allow you to control cookies through their settings preferences. You can configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is set. Please note that if you disable cookies, some features of our website may not function properly. You can also opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

10. Third-Party Links

Our website may contain links to third-party websites, plugins, and applications that are not owned or controlled by BUSINESS AUTOMATION, INC. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices, content, or security.

When you leave our website, we encourage you to read the privacy policy and terms of service of every website you visit. This Privacy Policy applies solely to information collected by BUSINESS AUTOMATION, INC. and does not cover the data collection practices of any third party, even if you access their services through links on our website. We recommend that you review the privacy policies of those third parties before providing them with any personal information.

11. Children's Privacy

Our services are not directed to individuals under the age of 18 (eighteen). We do not knowingly collect personal information from children. If you are a parent or guardian and you believe that your child has provided us with personal information without your consent, please contact us immediately using the information provided in Section 14 below.

If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information from our systems as promptly as possible. We encourage parents and guardians to monitor their children's online activities and to instruct their children never to provide personal information through our website without parental permission.

12. International Data Transfers

BUSINESS AUTOMATION, INC. is based in the United States. Your information may be transferred to, stored, and processed in the United States or any other country where we or our service providers maintain facilities. By using our services or providing us with your information, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.

When we transfer personal data from the European Economic Area (EEA), Switzerland, or the United Kingdom to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards to protect your data. These safeguards include entering into Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring that the recipient implements appropriate technical and organizational measures to protect your data.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable data protection laws, regardless of where it is processed.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make material changes, we will update the "Last Updated" date at the top of this policy and take appropriate steps to notify you, such as posting a notice on our website or sending you an email notification.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after any changes to this policy constitutes your acceptance of the updated terms. If we make changes that require your consent under applicable law, we will obtain your consent before implementing those changes.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us:

Email: support@businessau.shop

Phone: +1 (253) 461-5703

Address: 1100 W TOWN AND COUNTRY RD STE 1250, ORANGE, OH 92868, United States

We are committed to addressing your concerns promptly. If you have a complaint about how we handle your personal data, we will investigate and respond to you within a reasonable timeframe. If you are located in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.