1Who we are
This Privacy Policy (the “Policy”) explains how DX Clouditive LLC, a Florida limited liability company (“Clouditive”, “we” or “us”), handles personal data when you use dxclouditive.com (the “Site”). It applies to the Site and to the emails we send you from it.
Controller (data controller; “responsable” in Mexico and Colombia; “controlador” in Brazil): DX Clouditive LLC, 7901 4th St N, Ste 300, St Petersburg, FL 33702, United States. Founder and CEO: Mat Caniglia.
Privacy contact (including the “encarregado” required by Brazil’s LGPD, art. 41): [email protected]. Send every privacy request, question or complaint to that address.
We are a business-to-business engineering company. The Site is meant for people who contact us on behalf of a company, and for readers of our articles.
We direct the Site at the Americas. We do not knowingly target individuals in the European Union or the United Kingdom. If you are in those regions and the GDPR or the UK GDPR applies to our processing, your rights are in Section 9.2.
2The data we collect, and where it comes from
We collect the data you give us and the technical data your browser sends. We do not obtain personal data about you from other sources, and we do not collect sensitive data (such as health, biometric or financial-account data) on purpose. Please do not send it to us.
| Where | What we collect | From |
|---|---|---|
| Contact form | Name, work email, company (optional), what you need, your message, your reply language, your agreement to this Policy, and the time of sending. We also record the page you sent it from, the button or link that brought you to the form, the campaign tags (utm_) in the address if there are any and, if you started from our rate estimator, what you typed in it. We also send you an automatic acknowledgement by email. | You |
| Newsletter | Email address, the language of the list, the page you subscribed from, and the dates you subscribed, confirmed and unsubscribed. As proof of consent we keep the version of the consent text and of this Policy you saw, and the IP address and browser details (user agent) of your sign-up and of your confirmation. | You, and your browser |
| Chat | Your name, work email, company, the topic you choose and the messages you write. If you close the page before we answer, we send our reply to your work email. A thread identifier is kept in your browser for the session so the conversation continues. We also record the page you were on and the campaign tags in its address, if any. | You |
| Booking a call | Your name, work email, company (optional), what you need (optional), a note (optional), the time you choose and your time zone, plus the page and campaign tags described for the contact form. The page shows you only the free times of our calendar, never what the busy times hold. Booking creates an entry with a Microsoft Teams link in our Microsoft 365 calendar, and Microsoft sends you the invitation. If our calendar cannot load, the page links to Microsoft’s own scheduling page, where what you enter is handled by Microsoft. | You |
| Our emails to you | Your address and the content of the message. Our emails contain no tracking pixels. | Us |
| Visit and click counts | Which page was viewed and which button or link was pressed, added up per day: each count holds the event name, the page path, the button’s id and the date, and nothing else. No cookie, no device storage, no IP address, no identifier and no browser fingerprint is stored with it. Our server uses your IP address in memory for a few minutes, scrambled with a key that is discarded when the server restarts, only to limit abuse. Nothing is counted if your browser sends Global Privacy Control or Do Not Track. | Your browser |
| Security and delivery | IP address, browser type, the page requested, the time, and the signals Cloudflare Turnstile reads (IP address, TLS fingerprint, user agent) to tell people from bots. | Your browser |
Providing the data marked on a form is optional in the sense that you can choose not to contact us, but we cannot answer a request or send a newsletter without it. If you do not accept this Policy on the contact form, the form cannot be sent.
3Why we use it, and on what legal basis
We use personal data only for the purposes below and not for others that are incompatible with them. For each purpose we state the legal basis under the EU and UK GDPR (art. 6(1)), and the equivalent basis elsewhere.
| Purpose | Data | GDPR / UK GDPR basis | Elsewhere |
|---|---|---|---|
| Answer your contact request and follow up on it | Contact form data; our reply | Art. 6(1)(b), steps at your request before a contract; and 6(1)(a), your agreement on the form | Brazil LGPD art. 7, I and V; Mexico and Colombia: your authorization; Argentina Law 25,326 art. 5 |
| Answer a chat message and reply by email | Chat data | Art. 6(1)(b) and 6(1)(f), our interest in answering enquiries | Brazil LGPD art. 7, I, V and IX; your authorization elsewhere |
| Book and hold a call you request | Booking data | Art. 6(1)(b) | Brazil LGPD art. 7, V |
| Send the newsletter you confirmed (new posts and a weekly digest) | Email, language | Art. 6(1)(a), consent | Brazil LGPD art. 7, I; Canada CASL s. 6(1)(a) express consent; Mexico, Argentina and Colombia: your authorization |
| Prove that you consented and when, and honor your unsubscription | Consent record; unsubscribe record | Art. 6(1)(f), our interest in demonstrating consent (art. 7(1)); art. 6(1)(c) where a law requires it | Brazil LGPD art. 8 §2 and art. 7, II, VI, IX; Canada CASL s. 13 |
| Keep the Site and forms secure, and stop spam and abuse | Technical data; Turnstile signals | Art. 6(1)(f), our interest in security | Brazil LGPD art. 7, IX |
| Understand which pages and buttons lead to enquiries | Anonymous daily counts of visits and clicks | Not personal data, because no identifier is stored; if a count were personal data, art. 6(1)(f), our interest in improving the Site | Brazil LGPD art. 12, anonymized data |
| Establish, exercise or defend legal claims; comply with law | Any data above, as needed | Art. 6(1)(c) and 6(1)(f) | Brazil LGPD art. 7, II and VI |
Where we rely on legitimate interests, we have weighed them against your rights and expect them not to override your rights, because the data is limited and used in ways you would reasonably expect when you contact a company. You can object (Section 9.2).
We do not sell your personal data. We do not share it for advertising or cross-context behavioral advertising, and we do not use it to profile you or to make automated decisions about you (Section 13).
4Consent and how to withdraw it
Where we rely on your consent, you give it by an affirmative act: you tick the agreement box on the contact form or in the chat, or you enter your address in the newsletter form and then click the confirmation button in the email we send you (double opt-in). Until you confirm, you are not subscribed and we send you nothing else.
Before you consent, we tell you who is asking (DX Clouditive LLC), for what (new posts and a weekly digest), and that you can withdraw. You can withdraw consent at any time, free of charge and as easily as you gave it: use the unsubscribe link in any newsletter email (one click, no login), or write to [email protected]. We stop the newsletter immediately. Withdrawing does not affect the lawfulness of what we did before.
We keep a record of each subscription so that we can demonstrate your consent: your email address, language, the page you subscribed from, the version of the consent text and of this Policy that applied, and the time, IP address and browser details of your sign-up and of your confirmation, and later the time and method of unsubscription. The record is append-only. We keep it for the period in Section 8.
Newsletter emails also carry our postal address, as United States (CAN-SPAM) and Canadian (CASL) law require, and are sent only to confirmed addresses. If someone entered your address without your permission, ignore the confirmation email and you will not be subscribed, or write to [email protected].
5Chat and messages relayed to WhatsApp
The Site’s chat lets you write to our team. To start a conversation we ask for your name and work email, and optionally your company. Your messages and our replies are stored in our systems on Google Cloud and are relayed to our team’s WhatsApp number through the WhatsApp Business Platform (Cloud API), which Meta provides. If you close the page before we answer, we send our reply to the work email you gave. If the WhatsApp relay is not active or fails, your message reaches our team by email instead.
A scripted assistant, not an artificial-intelligence model, asks for your details and passes your message on. It does not make decisions about you.
A thread identifier is kept in your browser’s session storage so that the conversation continues while the tab is open (Section 14).
Meta processes the messages we exchange through WhatsApp as our service provider under its WhatsApp Business Data Processing Terms. Its own terms and privacy documentation describe what else it does with data, which we do not control. Please do not send sensitive information in the chat. We keep chat messages for the period in Section 8.
6Who receives your data
We share personal data only with the people and companies below. We do not sell it, rent it or give it to advertisers or data brokers.
Service providers that process data on our behalf (processors), under written terms that bind them to protect it and to use it only for our purposes:
- Microsoft (Microsoft 365: Exchange Online email, Graph API, and the calendar that holds the call you book with its Microsoft Teams meeting): sends and receives our email, including replies, the newsletter and its confirmation, delivers contact-form messages to our inbox, and holds booking entries.
- Google Cloud (Cloud Run and Firestore): runs the service that receives contact-form and newsletter submissions, and stores leads, subscribers and consent records.
- Cloudflare: serves the Site and its DNS, protects it against abusive traffic, and runs Turnstile, the human check on our forms. For Turnstile, Cloudflare acts as our processor for security and as an independent controller of the signals it uses to improve bot detection, as its Turnstile Privacy Notice explains.
- Meta (WhatsApp Business Platform / WhatsApp Cloud API): delivers chat messages to our team’s WhatsApp number, if you use the chat. WhatsApp acts as our processor under its Business Data Processing Terms.
Other recipients: our own staff and contractors who need the data to answer you, bound by confidentiality; our professional advisers (lawyers, accountants, insurers); public authorities, courts or other parties where the law requires or allows it; and a buyer or successor if our business is sold or reorganized, who must honor this Policy.
Links on the Site to other sites, including social-network share links and the Microsoft scheduling page, take you to services with their own privacy notices. We load no social-network or advertising scripts on the Site.
7International transfers
We are a United States company and our team works from the United States and Latin America. The data you send reaches us in the United States, and our providers may process it in the United States and in other countries where they operate. Those countries may not give your data the same level of protection as the law of the place where you live.
When data covered by European, UK or Swiss law is transferred, we rely on the safeguards of our providers: the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which Google Cloud, Microsoft and Cloudflare offer in their data processing terms, and, for Cloudflare, its certification under the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) with its UK and Swiss extensions. WhatsApp provides its own data transfer addenda.
For data from Brazil, we rely on contractual clauses that give the safeguards the LGPD requires (art. 33, II). For data from Argentina, where Law 25,326 art. 12 restricts transfers to countries without adequate protection and the United States is not among the countries the AAIP lists as adequate (Disposición 60-E/2016, art. 3, as amended by Resolution 34/2019), we rely on contractual safeguards. For data from Colombia, we rely on your express and unequivocal authorization to the transfer (Law 1581 art. 26(a)), which you give when you accept this Policy on the contact form or confirm the newsletter after reading it. For data from other countries we rely on contractual safeguards and, where the local law allows it, your consent.
You can ask us for a copy of the safeguards we use by writing to [email protected].
8How long we keep it
We keep personal data only as long as needed for the purpose it was collected for, and then delete or anonymize it. These are our periods:
| Data | How long |
|---|---|
| Contact requests and the email thread | 24 months after our last communication with you. If you become a client, the agreement and the law set how long the client records are kept. |
| Chat messages | 12 months after the last message in the thread. |
| Copies of chat messages in our email and on our team’s WhatsApp | 24 months after the last message, as with contact requests. |
| Newsletter subscriber record (email, language, status) | While you are subscribed. After you unsubscribe, we keep the address and the date only as a suppression record so we do not email you again, for 3 years. |
| Unconfirmed newsletter sign-ups | Deleted within 30 days if you do not confirm. |
| Consent record (texts and versions, dates, IP address, browser details) | While you are subscribed and for 3 years after you unsubscribe, the period in which a claim about consent may be brought (for example the three-year limitation period in CASL s. 23). |
| Booking entries | As long as the call needs, then with the contact request thread, 24 months after our last communication. |
| Anonymous daily counts of visits and clicks | 24 months. They hold no personal data. |
| Server and security logs | Up to 30 days, the default retention of Google Cloud request logs. |
| Data we must keep by law or to defend a claim | As long as the law requires or the claim period runs. |
If you ask us to delete data, we delete it earlier, except what we must keep by law or to defend a claim, including the consent record, which is our proof that we honored your unsubscription.
9Your rights
9.1How to exercise them
Write to [email protected] from the address we hold, saying what you want. We may ask you to confirm your identity so that we do not give your data to someone else. We do not charge for requests, except that where your law allows we may charge reasonable costs for repeated or manifestly unfounded requests or for copies.
We reply within the period your law sets, listed below, and in any case within one month of receiving your request (extendable where the law allows). If we refuse, we tell you why and how to complain.
You can withdraw consent, unsubscribe and object to marketing at any time (Section 4).
9.2European Union, European Economic Area and United Kingdom (GDPR and UK GDPR)
You have the right to access your data (art. 15), to have it corrected (art. 16), erased (art. 17), restricted (art. 18) or ported (art. 20), to object to processing based on legitimate interests (art. 21(1)) and to object to direct marketing at any time (art. 21(2)–(3)), and to withdraw consent at any time (art. 7(3)). We reply within one month (art. 12(3)).
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (art. 77). In the United Kingdom, the authority is the Information Commissioner’s Office (ico.org.uk/make-a-complaint). We would appreciate the chance to address your concern first.
9.3Brazil (LGPD)
Under art. 18 of Law 13,709/2018 you may, at any time and on request, obtain: confirmation that we process your data; access; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or excessive data or data processed in breach of the Law; portability; deletion of data processed with your consent; information about the entities with which we share data; information about the possibility of refusing consent and the consequences; and revocation of consent. You may also object to processing carried out without consent where the Law is breached.
We confirm processing or give access in a simplified format immediately, or by a complete declaration within 15 days (art. 19). Requests are free of charge.
Our encarregado is the privacy contact in Section 1: [email protected]. You may petition the Autoridade Nacional de Proteção de Dados (ANPD) against us (art. 18 §1) and consumer-protection bodies (art. 18 §8). If a security incident may cause you relevant risk or damage, we will notify you and the ANPD (art. 48).
9.4Mexico (LFPDPPP)
This section is our privacy notice (aviso de privacidad) under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares, in the text in force since 2025, to the extent that law applies to us. Controller (responsable) and domicile: DX Clouditive LLC, 7901 4th St N, Ste 300, St Petersburg, FL 33702, United States. The personal data we process, and our purposes, are in Section 2 and Section 3. We process no sensitive personal data on purpose. The purposes that require your consent are the newsletter and, for the contact form and chat, the use of your data to answer you; security and legal-claim uses do not.
You may exercise the rights of access, rectification, cancellation and opposition (ARCO) at any time (art. 27) by writing to [email protected] with your name and a way to notify you, a document proving your identity (or your representative’s), a clear description of the data and the right you wish to exercise, and any document that supports the request (art. 28). We tell you our decision within 20 days of receiving the request, and carry it out within 15 days after that; both periods can be extended once for an equal period if the circumstances justify it (art. 31). The exercise of the rights is free, except for costs of reproduction, copies or shipping (art. 34).
You can revoke your consent at any time (art. 7) with the same mechanism, or with the unsubscribe link in every newsletter email, which is also how you limit the use or disclosure of your data. We tell you about changes to this notice by publishing them on this page. If you consider your rights were not respected, you may file a data-protection request with the Secretaría Anticorrupción y Buen Gobierno, the authority that now holds this function, within 15 days after our reply (art. 40).
9.5Argentina (Law 25,326)
The controller of the database and its domicile are in Section 1. The purposes, recipients and categories of data are in Section 2, Section 3 and Section 6. Giving us the data is voluntary, but without it we cannot answer or subscribe you. You have the rights of access, rectification, updating and deletion (arts. 14 and 16), and you may withdraw or block your name from marketing databases at any time (art. 27(3)).
We answer an access request within 10 calendar days and a rectification, update or deletion request within 5 business days (arts. 14(2) and 16(2)).
El titular de los datos personales tiene la facultad de ejercer el derecho de acceso a los mismos en forma gratuita a intervalos no inferiores a seis meses, salvo que se acredite un interés legítimo al efecto conforme lo establecido en el artículo 14, inciso 3 de la Ley Nº 25.326. La AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, en su carácter de Órgano de Control de la Ley Nº 25.326, tiene la atribución de atender las denuncias y reclamos que interpongan quienes resulten afectados en sus derechos por incumplimiento de las normas sobre protección de datos personales.
In English: the data subject may exercise the right of access free of charge at intervals of not less than six months, unless a legitimate interest is shown (Law 25,326 art. 14(3)). The Agencia de Acceso a la Información Pública, the control body of Law 25,326, hears complaints about non-compliance with the data-protection rules (argentina.gob.ar/aaip).
9.6Colombia (Law 1581 of 2012)
Controller (Responsable del Tratamiento): DX Clouditive LLC. Physical address: 7901 4th St N, Ste 300, St Petersburg, FL 33702, United States. Email: [email protected]. The purposes of the processing are in Section 3. Answering questions about sensitive data or data of children and adolescents is optional, and we ask for neither. Your authorization is prior and informed, and we keep proof of it (Section 4).
Under art. 8 you have the right to know, update and rectify your data; to ask for proof of the authorization; to be told how we have used your data; to complain to the Superintendencia de Industria y Comercio (SIC) about infringements; to revoke the authorization and ask for deletion where the processing does not respect the principles, rights and guarantees, and to access your data free of charge.
We answer a consultation (art. 14) within 10 business days and a claim to correct, update or delete (art. 15) within 15 business days, extendable as the law allows. You may complain to the SIC only after you have gone through the consultation or claim with us (art. 16).
9.7Chile (Law 21,719)
Law 21,719, which replaces Law 19,628 and creates the Agencia de Protección de Datos Personales, enters into force on 1 December 2026. From that date, and to the extent it applies to us, you may exercise the rights of access, rectification, erasure, objection, portability and blocking, and the right to object to decisions based solely on automated processing, by writing to [email protected]. We make no such decisions (Section 13). You may complain to the Agencia de Protección de Datos Personales.
9.8Canada (PIPEDA and CASL)
We handle personal information in line with the ten principles of Schedule 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA). You may ask for access to your information and challenge its accuracy and completeness (clause 4.9), and withdraw consent (clause 4.3.8) subject to legal restrictions. We respond to a written access request with due diligence and no later than 30 days after receiving it (s. 8(3)).
We send commercial electronic messages only with your express consent (Canada’s Anti-spam Legislation, CASL, s. 6(1)(a)) and every message identifies us, gives our postal address and a contact and carries an unsubscribe mechanism that works at no cost and that we honor no later than 10 business days (CASL s. 11); in practice, immediately.
If we have not resolved your concern, you may file a complaint with the Office of the Privacy Commissioner of Canada (PIPEDA s. 11; priv.gc.ca).
9.9United States
We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in US state privacy laws, including the California Consumer Privacy Act (CCPA, as amended). We are a small company and we do not believe the CCPA’s thresholds for a “business” apply to us today (annual gross revenue above USD 25 million, as adjusted, handling the data of 100,000 or more consumers or households, or earning half our revenue from selling or sharing personal information; Cal. Civ. Code § 1798.140(d)). If a US state privacy law applies to us, you may ask us to tell you what personal information we hold and to give you a copy, correct it, delete it, and not to sell or share it, and we will not discriminate against you for asking. Use [email protected].
For the newsletter, we follow the CAN-SPAM Act: our messages identify us, show our valid physical postal address, and include an unsubscribe link that we honor within 10 business days, in practice immediately.
9.10Elsewhere
If you live in another country, we apply the rights above that best match the law that protects you, and we do not reduce the rights your own law gives you.
11Children
The Site is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18 (or under the age of digital consent in your country, if it is higher). If you believe a child has sent us data, write to [email protected] and we will delete it.
12Security
We protect personal data with technical and organizational measures that fit the risk: encrypted connections (HTTPS) for the Site and the service behind it; human verification on forms to limit abuse; random, single-purpose confirmation and unsubscribe tokens; double opt-in; access to the systems that hold data limited to the people who need it; secrets kept out of the code; and application logs that do not record the IP address and browser details held in the consent record.
No system is completely secure. If a breach of personal data occurs, we will assess it and notify you and the authorities where the law requires.
13Automated decisions and profiling
We do not make decisions about you based solely on automated processing that have legal effects or similarly significant effects, and we do not profile you. A scripted assistant in the chat only asks for your details and passes your message to our team. It does not decide anything about you.
15Changes to this Policy
We may update this Policy. The effective date and the version at the top of this page show which text applies, and the version is the one we record with your newsletter consent. If a change is material, we will say so on this page before it takes effect where reasonably practicable. A new version does not reduce your rights and does not apply retroactively to data collected under an earlier one unless the law allows it.
16Contact
DX Clouditive LLC, 7901 4th St N, Ste 300, St Petersburg, FL 33702, United States. Email: [email protected]. Our Terms of Service govern your use of the Site.