Who we are
Data Science & Engineering Experts, Inc. ("DSE," "we," "us," or "our") is a Delaware corporation (registered to do business in Georgia) providing data, AI, and AI-governance consulting services, located at 8735 Dunwoody Place #5714, Atlanta, GA 30350. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information in connection with our website at thedataexperts.us (the "Site") and our professional services.
Questions about this policy may be directed to legal@thedataexperts.us or submitted through the privacy request form available on this Site.
This policy applies to personal information we handle as a business acting on our own behalf. Where we process personal information on behalf of a client under a services agreement, we act as that client's service provider, and the client's own privacy notices and instructions govern that data. See "Client-engagement data" below.
Scope of this policy
This policy covers three categories of individuals:
- Site visitors, people who browse the Site or interact with its forms.
- Prospects and contacts, people who inquire about our services, subscribe to our communications, or whose business-contact information we process for outbound marketing and relationship management.
- Client-engagement contacts, individuals whose personal information we encounter while delivering services to a client, where the client determines the purposes and means of processing.
Information we collect
We may collect the following categories of personal information, depending on how you interact with us:
- Identifiers and contact data you provide through forms (for example, when you request a consultation, subscribe, or contact us): name, business email, company name, job title, telephone number, and any details you include in your message.
- Prospect and relationship data: business-contact information sourced from you, from your organization, from professional networks, or from third-party business-information providers, used to evaluate and pursue potential engagements.
- Analytics and usage data: when you enable analytics through our cookie controls, aggregated and de-identified usage information collected via analytics providers (see our Cookie Policy). No analytics or marketing tags load before you permit their matching purpose.
- Server and security logs: standard request metadata such as IP address, user agent, and timestamp, processed for security, fraud prevention, and operations, and retained for a limited period.
We do not intentionally collect sensitive personal information through the Site, and we ask that you not submit it through our forms.
How we use information
We use personal information for the following business purposes:
- To respond to inquiries and provide requested information;
- To scope, negotiate, and deliver professional-services engagements;
- To manage our client and prospect relationships, including outbound marketing consistent with applicable law;
- To operate, secure, maintain, and improve the Site through aggregated analytics;
- To comply with legal, tax, regulatory, and contractual obligations; and
- To establish, exercise, or defend legal claims.
We rely on our legitimate business interests, the performance of a contract with you or your organization, your consent (where required), and compliance with legal obligations as the bases for these uses.
Marketing communications (CAN-SPAM)
We may send commercial email to business contacts about our services, insights, and events. Consistent with the CAN-SPAM Act:
- Every marketing email identifies DSE as the sender and includes our valid physical postal address (8735 Dunwoody Place #5714, Atlanta, GA 30350);
- We do not use false or misleading header information or deceptive subject lines;
- Every marketing email includes a clear and conspicuous unsubscribe mechanism; and
- We honor opt-out requests promptly and will stop sending marketing email to an address after it opts out, retaining that address only as needed to suppress future messages.
You may opt out at any time using the unsubscribe link in any marketing email, by emailing legal@thedataexperts.us, or through the privacy request form on this Site. Opting out of marketing does not stop transactional or relationship messages necessary to an active engagement.
Client-engagement data (service-provider posture)
DSE serves clients in regulated sectors, including financial-services and other institutions subject to sector-specific privacy laws. When we perform services for such a client, we typically act as the client's service provider and process personal information only under the client's documented instructions and our engagement agreement.
- Gramm-Leach-Bliley Act (GLBA). Where we handle nonpublic personal information of a financial institution's customers, we do so as a service provider supporting the institution's obligations under the GLBA Safeguards and Privacy Rules. We maintain administrative, technical, and physical safeguards appropriate to the data and use such information only to provide the contracted services.
- Fair Credit Reporting Act (FCRA). Where an engagement involves consumer-report information, we support the client's permissible-purpose and accuracy obligations and process such information solely as directed by the client. DSE does not act as a consumer reporting agency.
- Client control. For client-engagement data, the client is the controlling party. Requests to access, correct, or delete such data should be directed to the client; we will assist our clients in responding to verified data-subject requests as provided in our agreements.
The specific data-handling, retention, and security terms for each engagement are governed by the applicable services agreement and any data processing addendum.
How we share information
We do not sell personal information for monetary consideration. We disclose personal information only as follows:
- Service providers and vendors that support our operations, by category: cloud infrastructure and hosting providers, identity and authentication providers, analytics providers, customer-communication and email providers, customer-relationship-management (CRM) providers, and professional advisors. These parties are bound by contract to process the information only for the purposes we specify.
- Legal and safety. We may disclose information to comply with law, legal process, or lawful requests from public authorities, and to protect the rights, property, or safety of DSE, our clients, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, personal information may be transferred as a business asset, subject to this policy.
A list of the specific vendors we engage is available to clients under a data processing addendum on written request.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the CPRA. The following table summarizes the categories of personal information (as defined in Cal. Civ. Code § 1798.140) that we may have collected in the preceding 12 months, and the purposes for which they are used.
| CCPA category | Examples | Collected | Purpose |
|---|---|---|---|
| Identifiers | Name, email, phone, company, IP address | Yes | Respond to inquiries; deliver services; marketing; security |
| Customer records (§ 1798.80(e)) | Contact and business information you submit | Yes | Deliver services; relationship management |
| Commercial information | Services inquired about or engaged | Yes | Deliver services; relationship management |
| Internet/network activity | Site usage, analytics data | Yes (with consent) | Operate and improve the Site |
| Geolocation data | Approximate location inferred from IP | Yes | Security; regional consent handling |
| Professional/employment information | Job title, employer | Yes | Relationship management; service delivery |
| Inferences | Prospect fit and interest inferences | Yes | Relationship management; marketing |
| Sensitive personal information | Not intentionally collected | No | , |
We do not use or disclose sensitive personal information for purposes that would require offering a "right to limit."
Sources of this information include you, your organization, your device and browser, and third-party business-information and analytics providers.
Your California rights include the right to know, access, delete, and correct personal information; the right to opt out of "sharing" for cross-context behavioral advertising; and the right to non-discrimination for exercising these rights. We do not sell personal information for money. Certain analytics/advertising cookies may constitute "sharing" under the CPRA, see our Do Not Sell or Share page and Cookie Policy for opt-out options, including honoring the Global Privacy Control (GPC) signal.
To exercise these rights, submit a request through the privacy request form on this Site or email legal@thedataexperts.us. We will verify your request and may act through an authorized agent who provides proof of authorization. We will respond within the timeframes required by law.
Other U.S. state privacy rights
Residents of other states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Texas, and similar states) may have comparable rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising and certain profiling. To exercise these rights, use the privacy request form on this Site or email legal@thedataexperts.us. We honor the Global Privacy Control as an opt-out of targeted advertising and "sharing" where applicable.
New York SHIELD Act
For New York residents, we maintain reasonable administrative, technical, and physical safeguards to protect private information consistent with the New York SHIELD Act, and we will provide breach notification as required by that law without undue delay and as required by applicable law.
GDPR / UK GDPR rights
UK and EEA visitors. This Site and its contact paths are available to visitors in the United Kingdom and European Economic Area. DSE does not launch country-specific marketing campaigns or make country-specific service claims until it completes a documented country-specific launch review with counsel review. Where UK or EU privacy law applies, we process personal information using the appropriate legal basis, which may include legitimate interests, performance of a contract, consent, or compliance with a legal obligation. Such individuals may request access, rectification, erasure, restriction, portability, or object to processing, and may withdraw consent where processing is based on consent. Requests may be submitted through the privacy request form on this Site or to legal@thedataexperts.us.
Cookies and analytics
We use strictly necessary cookies for Site functionality and optional analytics and marketing cookies only after you permit each purpose. Our controls provide purpose-specific choices, so enabling analytics does not enable marketing. We honor Global Privacy Control signals by denying optional tracking. See our Cookie Policy to review categories and manage your choices.
Data retention
We retain personal information only as long as necessary for the purposes described in this policy, to maintain our business relationships, and to meet legal, tax, and contractual obligations. Server and security logs are retained for a limited operational period. When information is no longer needed, we delete or de-identify it, except where a longer retention period is required by law or a legal hold.
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access controls, multi-factor authentication, secrets held in managed secret storage, audit logging, and documented incident-response procedures. DSE operates a SOC 2-aligned control environment, and a SOC 2 Type II examination is in progress. No system can be guaranteed perfectly secure, and we cannot warrant absolute security. See our Security Overview for detail.
Children's privacy
The Site is directed to businesses and is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
International users
We operate in the United States, and personal information we collect is processed in the United States. If you access the Site from outside the United States, you understand that your information will be transferred to and processed in the United States.
Changes to this policy
We may update this policy from time to time. Material changes will be indicated by a revised "Last updated" date at the top of this page, and where appropriate we will provide additional notice. Your continued use of the Site after an update constitutes acceptance of the revised policy.
Contact us
Data Science & Engineering Experts, Inc.
8735 Dunwoody Place #5714, Atlanta, GA 30350
Email: legal@thedataexperts.us
Privacy requests: the privacy request form available on this Site