privacy_policy

Privacy policy

Effective: August 16, 2026
Last reviewed: August 16, 2026

Carnation Tech LLC provides managed IT services to businesses in California. This page explains what information we collect through carnationtech.ai, why we collect it, who else handles it, and what you can do about it.

We have written this in plain English rather than legal boilerplate, and everything in it describes what we actually do. If anything here is unclear, email hello@carnationtech.ai and we will explain it.


Scope — the two kinds of information we handle

We handle information in two distinct roles, and they are governed by two different documents.

Website and marketing information — covered by this page. When you visit carnationtech.ai, submit our contact form, or book a call, we decide what to collect and why. That makes us the business responsible for it, and this policy describes how we handle it.

Client information — not covered by this page. When we deliver managed IT services, we access information inside our clients' systems: email, files, accounts, device and security data. We handle that information only on the client's instructions and only to deliver the services they hired us for. It is governed by the service agreement and data processing terms between us and that client, not by this page.

If you are an employee or customer of one of our clients and you want to know how your information is handled, contact that organization directly. They decide; we act on their instructions. If they direct us to act, we will.

For clients in regulated industries, we execute the additional agreements those industries require — including a Business Associate Agreement where protected health information is involved.


What we collect

Information you give us. Our contact form asks for your name, company, email address, phone number, and your message. Our booking page asks for your name and email address, plus any details you add when scheduling a call. All of it is voluntary — you choose what to send, and you can call or email us instead.

Information collected automatically. Our web server keeps standard access logs: the IP address of the visiting device, the browser and operating system it reports, the pages requested, and the time of each request. These logs exist to keep the site running and to identify abuse. We do not use them to build profiles of visitors or to track anyone across other websites.

What we do not collect. We do not run analytics, advertising cookies, tracking pixels, session recording, or heat mapping on this site. We do not have a marketing automation platform tracking your visits. We do not buy contact lists.


How we use it

We use what you send us to respond to your inquiry, schedule and prepare for a call, and provide the assessment or proposal you asked for. If you become a client, we use it to deliver and administer the services.

We use server logs to operate the site, diagnose problems, and identify abuse.

We do not use your information for automated decision-making or profiling.


We do not sell or share your information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We have never done either. We do not disclose your information to advertisers or data brokers.


Cookies and tracking

This site sets no cookies of its own and runs no tracking technologies.

The Microsoft services embedded on our contact page — the booking calendar and the contact form — may set their own cookies in your browser when you interact with them. Those are Microsoft's, governed by Microsoft's terms, and necessary for those tools to function.

Do Not Track. Some browsers send a Do Not Track signal. We do not respond to it, because we do not do the tracking it is designed to limit. There is nothing on this site for that signal to switch off.


Who else handles your information

Microsoft. Our contact form and booking page are Microsoft 365 services, and the messages you send arrive in a Microsoft-hosted mailbox. Microsoft processes this information on our behalf.

Google Fonts. Our pages load typefaces from Google's font service, which means Google receives your device's IP address when a page loads. We send Google nothing else. We are working to serve these typefaces from our own servers and remove this entirely.

Hosting. The site runs on servers we manage at a European hosting provider.

Every provider we use is bound to handle information only to provide the service we engaged them for. We do not share your information with anyone else. If we add a provider that touches visitor information — a customer relationship management system, analytics, or anything similar — we will update this page before turning it on.


Where your information is stored

Our website and its server logs are hosted in Europe. Contact form submissions and booking data are held in Microsoft 365, which stores and processes data in facilities Microsoft operates in multiple countries.

If you are contacting us from outside the United States, your information will be transferred to and handled in the United States and Europe, where privacy laws differ from those in your country.


How long we keep it

Inquiries that don't become business. If you contact us and do not become a client, we delete your information after twelve months without contact.

Booking data. Scheduling records are retained on the same twelve-month basis unless a client relationship begins.

Server access logs. Retained only as long as they are useful for operating and securing the site, then discarded.

Client records. Governed by the service agreement, not by this page.

You can ask us to delete your information sooner. See below.


How we protect it

We are a security company, so we will be specific rather than reassuring.

  • All traffic to this site is encrypted in transit using TLS.
  • Access to systems holding your information requires multi-factor authentication.
  • Information we hold in Microsoft 365 is encrypted at rest.
  • Our systems are backed up nightly, and we test that those backups actually restore.
  • We review the security configuration of our own systems on a recurring basis and remediate what we find.
  • Everyone on our team completes security awareness training.
  • We maintain a documented process for responding to security incidents.

No system is perfectly secure, and any company that tells you otherwise is selling something. We do not guarantee that information sent over the internet cannot be intercepted. What we commit to is applying the same standards to our own environment that we apply to our clients'.


If something goes wrong

If we discover a breach affecting your personal information, we will notify you and the appropriate authorities as required by law, within the timeframes the law sets. California law requires notice to affected residents within thirty days of discovery, and we will meet that standard regardless of where you live.


Your rights and how to use them

Email hello@carnationtech.ai to:

  • Know what information we hold about you and what we do with it
  • Correct anything that is wrong
  • Delete what we hold
  • Get a copy of what you have given us

We will respond within thirty days. You do not need to give a reason, and asking will not affect any conversation we are having with you or any service we provide.

California residents. California law gives residents specific rights over personal information, including the rights above and the right to opt out of the sale or sharing of personal information. As stated above, we do not sell or share personal information, so there is nothing to opt out of — but the request channel is the same, and we will honor any request you make. We will never discriminate against you for exercising a privacy right.

We extend these rights to everyone who contacts us, not only California residents, whether or not the law requires it of a company our size.


Children's privacy

Our services are sold to businesses. This site is not directed to children, and we do not knowingly collect information from anyone under eighteen. If you believe a minor has sent us information, email hello@carnationtech.ai and we will delete it.


Other sites

Our site links to other organizations' websites, including Microsoft's. This policy does not cover them. Read theirs.


Changes to this page

If we add analytics, a customer relationship management system, or any other service that touches visitor information, we will update this page before turning it on and change the effective date above. We review this page at least once a year whether or not anything has changed.


Contact

Carnation Tech LLC
hello@carnationtech.ai

For privacy questions about information we handle on behalf of a client, contact that client directly.