Privacy Policy
Favela Digital Consulting LLC — operating as Favela Consult — is committed to protecting your privacy. This document explains how we collect, handle, store, and safeguard your personal information when you use our website, communicate with us, or engage our consulting services.
Contents
- Introduction and scope
- Definitions and key terms
- Information we collect
- How we collect information
- Purposes and legal bases for processing
- Cookies and tracking technologies
- How we share and disclose information
- Data retention and deletion
- Data security measures
- International data transfers
- Your rights and choices
- Children's privacy
- Third-party services and links
- Updates to this policy
- Contact information and complaints
01 Introduction and scope
Favela Digital Consulting LLC, a Utah limited liability company with its registered office at 1615 E Blaine Ave, Salt Lake City, UT 84105-3802, United States — operating under the trade name Favela Consult — respects your right to privacy. This Privacy Policy sets out the foundation upon which we process any personal data we collect from you, or that you provide to us, when you visit our website at www.favelaconsult.lol (the Site), send us an email, call our telephone number, submit a contact form, or otherwise engage with us in the course of our computer integrated systems design and consulting business.
This policy applies to all individuals whose personal data we process — including prospective clients, current clients, website visitors, vendors, job applicants, and business partners — in any jurisdiction where we operate or where our services are accessible. By accessing or using our Site, or by providing us with your information through any channel, you acknowledge that you have read and understood the practices described in this policy. If you do not agree with any part of this policy, you must refrain from using our Site and from submitting personal information to us.
Favela Consult is the data controller for the personal data processed under this policy. This means we determine the purposes for which and the manner in which your personal data is processed. Our NAICS classification is 541512 — Computer Systems Design and Related Services — which includes the design, development, integration, and implementation of computer systems. The scope of this policy is deliberately broad because our consulting engagements often involve access to client infrastructure, logs, and operational data that may incidentally contain personal information.
1.1 Relationship with other documents
This Privacy Policy should be read together with our Terms of Service, which govern the use of our Site and the provision of our consulting services. In the event of any conflict between this Privacy Policy and a specific contractual agreement with a client, the contractual terms shall prevail to the extent of the inconsistency. Nothing in this policy limits your statutory rights under applicable data protection legislation — including the Utah Consumer Privacy Act (UCPA), the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), or any other law that applies to you based on your jurisdiction.
1.2 Policy availability and accessibility
We make this Privacy Policy freely available on our Site at all times via a clearly labeled link in the footer of every page. If you require this policy in an alternative format — for example, large print, audio recording, or a language other than English — please contact us at talk@favelaconsult.lol and we will use reasonable efforts to accommodate your request. The most current version of this policy will always be available at https://www.favelaconsult.lol/privacy.html.
02 Definitions and key terms
For the purposes of this Privacy Policy, the following capitalized terms shall have the meanings set forth below. These definitions are intended to provide clarity and are consistent with prevailing data protection frameworks, including the UCPA, CCPA, and GDPR, to the extent applicable.
03 Information we collect
We collect several categories of information in connection with the operation of our Site and the delivery of our consulting services. The specific data points we collect depend on the nature of your interaction with us. Below is a comprehensive taxonomy of the information we may collect.
3.1 Identity and contact information
This category includes information that identifies you as an individual and allows us to communicate with you. It encompasses your full name, job title, company or organization name, business email address, personal email address (if provided), business telephone number, mobile telephone number, postal address (including street, city, state or province, postal code, and country), and any other contact details you voluntarily share with us. For example, when you send an inquiry to talk@favelaconsult.lol or call +1 (959) 998-2580, we receive your email address or phone number and any additional information you choose to include.
3.2 Correspondence and communication data
We collect and retain records of all communications between you and Favela Consult. This includes the content of emails, messages sent through any contact form on our Site, notes from telephone calls, records of in-person meetings, and any attachments or documents you share with us. If you participate in a video conference, we may keep a record of the date, participants, and high-level topics discussed, though we do not record audio or video without your explicit prior consent.
3.3 Technical and usage data
When you visit our Site, our servers automatically collect certain technical information. This includes your Internet Protocol (IP) address, browser type and version, operating system and platform, device type and screen resolution, referring source (the website or search engine that directed you to us), pages you view and the time spent on each page, date and time stamps of your visit, clicked links and navigation paths, and any search terms you enter on the Site. We also collect information about how you interact with our Site through server logs, analytics scripts, and error-reporting tools — all of which are essential for maintaining and improving our digital presence.
3.4 Business and engagement data
If you engage Favela Consult for consulting services, we collect information necessary to perform those services and manage the client relationship. This may include your organization's technical infrastructure details, system architecture documentation, access credentials (handled with heightened security), project requirements, statements of work, invoices and payment records, contractual documents, and records of service delivery. We treat all client business information with the strictest confidentiality and use it exclusively for the purpose of delivering our services.
3.5 Marketing and subscription data
If you choose to subscribe to any newsletter, mailing list, or marketing communication from Favela Consult, we collect your name and email address. We also maintain a record of your marketing preferences, including which types of communications you wish to receive and your opt-in and opt-out history. We do not purchase marketing lists or engage in unsolicited bulk email campaigns. Every marketing communication includes a clear and functional unsubscribe mechanism.
3.6 Information we do not collect
We do not knowingly collect, and we specifically request that you do not provide, Sensitive Personal Data through our Site or in unsolicited communications. We do not collect biometric data, genetic information, government-issued identification numbers (such as Social Security numbers), financial account credentials, or health information through our Site. If we inadvertently receive such information, we will either securely delete it or, where required by law, limit its processing to the minimum necessary to comply with our legal obligations.
04 How we collect information
We collect information through a variety of methods, each of which is designed to be transparent and proportionate to the purpose for which the information is gathered. The primary collection channels are described below.
4.1 Direct collection from you
The majority of the Personal Data we process is provided directly by you, voluntarily and with your knowledge. This occurs when you send us an email, complete a contact form on our Site, call our office, meet with us in person or via video conference, subscribe to a mailing list, respond to a survey, or provide feedback about our services. In each of these interactions, you control what information you share, and we collect only the information necessary to respond to your inquiry or fulfill the purpose of the interaction.
4.2 Automated collection via our Site
As is standard practice across the web, we use server logs, analytics scripts, and cookies to automatically collect Technical and Usage Data when you visit our Site. This automated collection occurs regardless of whether you actively submit any information to us. The purpose of automated collection is to understand how visitors use our Site, diagnose technical problems, prevent fraud and abuse, and improve the content and structure of our pages. We do not use automated collection to build profiles of individual visitors for behavioral advertising purposes.
4.3 Collection from third parties
On occasion, we may receive Personal Data about you from third parties. This may include information from publicly available sources (such as company websites, professional networking platforms like LinkedIn, and business registries), referral sources (such as existing clients who recommend our services to you), and service providers who assist us with business development. When we receive information from third parties, we verify that the source obtained the information lawfully and that the transfer to us is consistent with applicable data protection laws.
4.4 Collection in the course of service delivery
During consulting engagements, we may incidentally access Personal Data stored in our clients' systems as part of our architecture review, integration, or migration activities. In such cases, we act as a Data Processor on behalf of our client (the Data Controller), and our processing of that data is governed by the terms of our client agreement, not by this Privacy Policy. We implement strict access controls and data minimization practices to ensure we access only the data necessary for the engagement and for no longer than required.
05 Purposes and legal bases for processing
We process Personal Data only for specified, explicit, and legitimate purposes. We do not process Personal Data in a manner that is incompatible with the purposes for which it was collected. The table below sets out the purposes for which we process Personal Data and — where applicable under the GDPR and similar laws — the legal basis we rely upon.
5.1 Service delivery and contract performance
We process Identity and Contact Information, Correspondence Data, and Business Data to perform our obligations under a contract with you or to take steps at your request prior to entering into a contract. This includes responding to inquiries about our services, preparing proposals and statements of work, delivering consulting engagements, managing billing and payments, and providing ongoing client support. Where we process data on this basis, the processing is necessary for the performance of the contract; if you choose not to provide the required information, we may be unable to fulfill the contract or respond to your inquiry.
5.2 Legitimate interests
We process certain Personal Data on the basis of our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include: operating, maintaining, and improving our Site; protecting the security and integrity of our IT systems; conducting business development and marketing to existing and prospective clients (in compliance with applicable anti-spam laws); analyzing Site usage to understand visitor behavior and improve our content; managing and administering our business, including record-keeping and compliance; and defending or pursuing legal claims.
5.3 Consent
Where we rely on your Consent as the legal basis for processing, we will obtain that Consent before commencing the processing activity. You have the right to withdraw your Consent at any time by contacting us at talk@favelaconsult.lol. Withdrawal of Consent does not affect the lawfulness of processing carried out before the withdrawal. We primarily rely on Consent for direct marketing communications (where not otherwise permitted by law) and for the use of non-essential cookies.
5.4 Legal obligation
We may process Personal Data to comply with a legal obligation to which we are subject, such as tax and accounting requirements, court orders, regulatory reporting obligations, and compliance with anti-money laundering, anti-bribery, and sanctions laws. Where processing is necessary for compliance with a legal obligation, you may not have the right to object to or restrict that processing.
5.5 Vital interests and public interest
In rare circumstances, we may process Personal Data to protect your vital interests or those of another natural person (for example, in a medical emergency). We may also process data for tasks carried out in the public interest, though such scenarios are unlikely in the normal course of our business.
06 Cookies and tracking technologies
Our Site uses cookies and similar tracking technologies to improve your browsing experience, analyze Site traffic, and understand where our visitors come from. This section explains what cookies are, which cookies we use, and how you can manage your cookie preferences.
6.1 What are cookies?
A cookie is a small text file — typically consisting of letters and numbers — that a website stores on your computer or mobile device when you visit a page. Cookies are designed to hold a modest amount of data specific to a particular client and website, and can be accessed either by the web server or the client computer. This allows the server to deliver a page tailored to a particular user, or the page itself can contain some script that is aware of the data in the cookie and so is able to carry information from one visit to the website (or related site) to the next.
Cookies may be either first-party cookies — set by the website you are visiting — or third-party cookies — set by a domain other than the one you are visiting. The lifespan of a cookie is determined by its type: session cookies are temporary and are deleted when you close your browser, while persistent cookies remain on your device for a predetermined period or until you manually delete them.
6.2 Cookies we use
We use a limited set of cookies on the Site, all of which fall into the categories of strictly necessary, performance, or functionality cookies. Specifically:
- Strictly necessary cookies — These are essential for the Site to function properly. They enable core features such as page navigation and access to secure areas. The Site cannot operate without these cookies. They do not gather information about you that could be used for marketing or remembering where you have been on the internet.
- Performance and analytics cookies — These cookies collect anonymized information about how visitors use the Site, such as which pages are visited most often and whether visitors encounter error messages. We use this information to improve the way the Site works. These cookies do not collect information that identifies you.
- Functionality cookies — These cookies allow the Site to remember choices you make — such as your preferred language or the region you are in — and provide enhanced, more personalized features. The information these cookies collect is typically anonymized.
We do not use advertising cookies, social media tracking cookies, or any other cookies designed to build a profile of your browsing habits across multiple websites for targeted advertising purposes.
6.3 Managing and disabling cookies
Most web browsers allow you to manage your cookie preferences through the browser settings. You can typically set your browser to refuse all cookies, to accept only certain types of cookies, or to alert you when a cookie is being set. The procedure for managing cookies varies from browser to browser; please consult the help function of your browser for specific instructions. You may also visit www.allaboutcookies.org for comprehensive guidance on cookie management across all major browsers.
Please note that disabling strictly necessary cookies may impair the functionality of the Site and limit your ability to use certain features. Disabling other types of cookies will not prevent you from browsing the Site, though it may reduce the personalization of your experience.
6.4 Do Not Track signals
Some browsers offer a Do Not Track (DNT) setting that sends a signal to websites indicating your preference not to be tracked. As there is no universally accepted standard for how DNT signals should be interpreted, our Site does not currently respond to DNT signals. We will continue to monitor developments in this area and may adjust our practices if a consensus emerges among regulators, browser vendors, and the technology industry.
6.5 Web beacons and other tracking technologies
In addition to cookies, we may use web beacons (also known as clear GIFs, pixel tags, or tracking pixels) in our marketing emails. These are tiny, transparent graphic images embedded in HTML-formatted email messages that allow us to determine whether an email has been opened and which links within it have been clicked. We use web beacons to measure the effectiveness of our communications and to refine our messaging. You can prevent web beacons from functioning by disabling HTML images in your email client or by reading your emails in plain-text mode.
07 How we share and disclose information
Favela Consult does not sell, rent, lease, or trade Personal Data to third parties for monetary or other valuable consideration. We share Personal Data only in the limited circumstances described below and only to the extent necessary to fulfill the purpose for which the data was collected or as required by law.
7.1 Service providers and data processors
We engage a carefully selected set of third-party service providers who perform functions on our behalf, including website hosting, email delivery, analytics, cloud storage, payment processing, accounting, and legal services. These providers act as Data Processors and are contractually bound to process Personal Data only on our documented instructions, to implement appropriate technical and organizational security measures, and to comply with all applicable data protection laws. We conduct due diligence on all service providers before engagement and periodically review their compliance.
7.2 Professional advisors
We may share Personal Data with our professional advisors, including lawyers, accountants, auditors, and insurers, where necessary for the purposes of seeking professional advice, establishing or defending legal claims, or complying with audit and regulatory requirements. These advisors are bound by professional obligations of confidentiality.
7.3 Business transfers
In the event that Favela Digital Consulting LLC is involved in a merger, acquisition, reorganization, sale of all or substantially all of its assets, financing, or similar transaction, Personal Data may be transferred as part of that transaction. We will use reasonable efforts to ensure that any recipient of Personal Data agrees to treat it in a manner consistent with this Privacy Policy and applicable law. You will be notified via email and/or a prominent notice on our Site of any change in ownership or transfer of your Personal Data, as well as any choices you may have regarding your information.
7.4 Legal and regulatory disclosures
We may disclose Personal Data if we believe in good faith that such disclosure is necessary to comply with a legal obligation, court order, subpoena, or governmental request; to protect the rights, property, or safety of Favela Consult, our clients, or others; to prevent or investigate possible wrongdoing in connection with our Site or services; or to enforce our contractual rights. We will, where permitted by law, make reasonable efforts to notify you of any such disclosure unless doing so would violate the law, court order, or governmental directive.
7.5 With your consent
We may share your Personal Data with third parties for purposes not described in this policy if we obtain your prior explicit Consent. You may withdraw your Consent at any time, and we will cease the relevant sharing activity going forward.
7.6 Aggregated and de-identified data
We may share aggregated, anonymized, or de-identified data — from which no individual can be identified — for any purpose, including research, marketing, and publication. For example, we may publish statistics about the number of visitors to our Site or the most frequently requested service categories, without revealing any Personal Data.
08 Data retention and deletion
We retain Personal Data only for as long as is necessary to fulfill the purposes for which it was collected, or as required to comply with legal, regulatory, accounting, or reporting obligations. The criteria we use to determine retention periods include the nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.
8.1 Retention periods by category
- Inquiry and correspondence data — Retained for up to three (3) years after the last communication, unless a client relationship is established, in which case the data is retained in accordance with our client data retention policy.
- Client engagement data — Retained for the duration of the client relationship plus seven (7) years following the termination of the engagement, consistent with applicable statutes of limitations for contract claims and tax record-keeping requirements.
- Website analytics data — Retained in identifiable form for up to twenty-six (26) months, after which it is anonymized or aggregated. Aggregated data may be retained indefinitely for trend analysis.
- Marketing subscription data — Retained until you withdraw your Consent and unsubscribe, after which we maintain only a record of your opt-out to ensure we do not inadvertently contact you again in the future.
- Server logs — Retained for up to ninety (90) days for security monitoring purposes, after which they are automatically purged.
8.2 Deletion and anonymization
Upon the expiration of the applicable retention period, we will securely delete, destroy, or irreversibly anonymize the Personal Data. If deletion is not technically feasible (for example, because the data resides in encrypted backup archives that cannot be selectively modified), we will isolate the data from further processing and implement enhanced access restrictions until deletion becomes feasible. You may request earlier deletion of your Personal Data by contacting us at talk@favelaconsult.lol, subject to the limitations described in Clause 11.
09 Data security measures
We take the security of your Personal Data seriously. We implement and maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of the Personal Data we process. Our security measures are proportionate to the sensitivity of the data and the risk of harm that could result from unauthorized access, use, alteration, disclosure, or destruction.
9.1 Technical safeguards
Our technical security measures include: encryption of data in transit using Transport Layer Security (TLS) 1.3; encryption of data at rest using industry-standard encryption algorithms (AES-256 where applicable); network firewalls and intrusion detection systems; regular vulnerability scanning and penetration testing conducted by qualified independent security professionals; multi-factor authentication for access to systems that store Personal Data; role-based access controls and the principle of least privilege; secure software development practices, including code review and dependency scanning; and endpoint protection, anti-malware, and device management policies for all company equipment.
9.2 Organizational safeguards
Our organizational security measures include: mandatory data protection and security training for all personnel who handle Personal Data; background checks as permitted by applicable law; confidentiality agreements with all employees, contractors, and service providers; a documented incident response plan that is tested and updated at least annually; regular security audits and compliance reviews; and a designated individual responsible for data protection compliance.
9.3 Physical safeguards
Physical security measures include controlled access to our office at 1615 E Blaine Ave, Salt Lake City, UT 84105-3802; secure, locked storage for physical records containing Personal Data; visitor logging and escorting procedures; and policies governing the secure disposal of physical media and devices.
9.4 Security incident notification
Despite our best efforts, no method of transmission over the Internet or electronic storage is one hundred percent secure. In the event of a data breach that affects your Personal Data and poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay — and, where required by law, within seventy-two (72) hours of becoming aware of the breach. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take to address the breach and mitigate its effects.
10 International data transfers
Favela Digital Consulting LLC is based in the United States, and our primary data processing activities take place within the United States. However, we may use service providers located in other countries, and our Site may be accessible from anywhere in the world. Where Personal Data is transferred from a jurisdiction with data protection laws (such as the European Economic Area, the United Kingdom, or Switzerland) to a jurisdiction that may not provide an equivalent level of protection, we implement appropriate safeguards to ensure that the data remains protected.
10.1 Transfer safeguards
We rely on the following transfer mechanisms, as appropriate: European Commission Standard Contractual Clauses (SCCs) incorporated into data processing agreements with our service providers; adequacy decisions by the relevant regulatory authority (where available); binding corporate rules (where adopted by our service providers); and, in limited circumstances, your explicit Consent to the transfer after having been informed of the possible risks.
10.2 Transfers to the United States
For data subjects in the European Economic Area, the United Kingdom, or Switzerland, we acknowledge that the transfer of Personal Data to the United States may not benefit from an adequacy decision. We therefore implement the Standard Contractual Clauses (Module Two: controller-to-processor, and Module One: controller-to-controller, as applicable) together with supplementary technical and organizational measures to ensure a level of protection essentially equivalent to that guaranteed within your jurisdiction.
10.3 Additional information
If you would like further details about the specific safeguards we have in place for international data transfers, or if you wish to obtain a copy of the relevant contractual clauses, please contact us at talk@favelaconsult.lol. We may redact commercially confidential information from any documents we provide in response to such a request.
11 Your rights and choices
Depending on your jurisdiction, you may have certain rights regarding the Personal Data we hold about you. We are committed to honoring these rights and will respond to any valid request without undue delay and in any event within the timeframes prescribed by applicable law — typically thirty (30) calendar days, extendable by an additional thirty (30) days for complex or numerous requests, in which case we will inform you of the extension within the initial period.
11.1 Right of access
You have the right to request confirmation as to whether we process Personal Data relating to you and, if so, to obtain a copy of that data together with information about the purposes of processing, the categories of data concerned, the recipients or categories of recipients to whom the data has been or will be disclosed, the envisaged retention period, and the source of the data (if not collected directly from you). The first copy will be provided free of charge; we may charge a reasonable fee for additional copies.
11.2 Right of rectification
You have the right to request the correction of inaccurate Personal Data we hold about you and to have incomplete Personal Data completed — including by providing a supplementary statement. We will use reasonable efforts to verify the accuracy of the corrected data before implementing the rectification.
11.3 Right of erasure (right to be forgotten)
You have the right to request the deletion of your Personal Data in certain circumstances, such as where the data is no longer necessary for the purposes for which it was collected, where you withdraw Consent on which the processing is based, where you object to processing and there are no overriding legitimate grounds, or where the data has been processed unlawfully. This right is not absolute — we may retain data where necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
11.4 Right to restriction of processing
You have the right to request that we restrict the processing of your Personal Data in certain situations, including where you contest the accuracy of the data (restriction for a period enabling us to verify accuracy), where the processing is unlawful and you oppose erasure and request restriction instead, where we no longer need the data but you require it for legal claims, or where you have objected to processing pending verification of whether our legitimate grounds override yours.
11.5 Right to data portability
You have the right to receive your Personal Data — which you have provided to us — in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us, where the processing is based on Consent or a contract and is carried out by automated means. We will, where technically feasible, transmit the data directly to another controller at your request.
11.6 Right to object
You have the right to object, on grounds relating to your particular situation, to the processing of your Personal Data based on our legitimate interests or the performance of a task carried out in the public interest. Upon receiving your objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims. You also have an absolute right to object to the processing of your Personal Data for direct marketing purposes at any time.
11.7 Automated decision-making and profiling
We do not use Personal Data to make decisions based solely on automated processing — including profiling — that produce legal effects concerning you or similarly significantly affect you. Should this change in the future, we will update this policy and provide you with meaningful information about the logic involved, as well as the significance and envisaged consequences.
11.8 Exercising your rights
To exercise any of the rights described above, please send a written request to talk@favelaconsult.lol with the subject line Data Subject Request. To protect your privacy, we may request proof of identity before acting on any request. We will acknowledge receipt of your request within seven (7) business days and provide a substantive response within the statutory deadline.
11.9 Right to complain
If you believe that our processing of your Personal Data violates applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your jurisdiction. For Utah residents, the relevant authority is the Utah Attorney General. For California residents, the relevant authority is the California Privacy Protection Agency. For data subjects in the European Economic Area, you may lodge a complaint with the data protection authority in your Member State of habitual residence, place of work, or place of the alleged infringement. We encourage you to contact us first at talk@favelaconsult.lol so we can attempt to resolve your concerns directly.
12 Children's privacy
Our Site is not directed to individuals under the age of eighteen (18), and we do not knowingly collect Personal Data from children under the age of sixteen (16). If you are a parent or guardian and you become aware that your child has provided us with Personal Data without your consent, please contact us immediately at talk@favelaconsult.lol. Upon verification, we will take prompt steps to delete such information from our systems and terminate any associated accounts.
12.1 Age verification
We do not currently implement age-gating or age-verification mechanisms on our Site because our services are designed for business-to-business (B2B) audiences and are not expected to appeal to minors. If we introduce features or content that may appeal to a broader audience, we will implement appropriate age-verification measures.
12.2 Educational institutions
In the event that we provide services to an educational institution or other organization that serves children, any Personal Data about children that we access in the course of that engagement is processed strictly as a Data Processor on behalf of the institution, and the institution bears the responsibility for obtaining any required parental consents.
13 Third-party services and links
Our Site may contain links to third-party websites, plug-ins, and applications — including social media platforms, partner sites, and resources we reference in our content. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. Favela Consult does not control these third-party websites and is not responsible for their privacy practices or content.
13.1 External websites
When you leave our Site via an external link, we encourage you to read the privacy policy of every website you visit. The inclusion of a link does not constitute an endorsement of the linked website or its privacy practices. We exercise no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party website or service.
13.2 Embedded content
Our Site does not currently embed content (such as videos, images, articles, or social media feeds) from third-party websites that might collect data about you. If we add embedded content in the future, we will update this policy to describe the nature of the content and the data collection implications.
13.3 Social media
Favela Consult may maintain a presence on professional social media platforms such as LinkedIn. Any information you share with us through social media is subject to the privacy policy of the respective platform. We encourage you to review the privacy settings and policies of any social media platform you use to understand how your data may be collected, used, and shared.
14 Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations, or other factors. When we make updates, we will revise the Last reviewed date at the top of this page and post the updated policy on our Site. We will also indicate the version number for ease of reference.
14.1 Material changes
If we make material changes to this policy — such as changes to the purposes for which we process Personal Data, the categories of data we collect, or the parties with whom we share data — we will provide prominent notice on our Site at least thirty (30) days before the changes take effect. For existing clients, we may also notify you by email. Your continued use of our Site or services after the effective date of the updated policy constitutes your acceptance of the changes.
14.2 Archived versions
We maintain an archive of previous versions of this Privacy Policy for a period of at least three (3) years. If you wish to review a prior version, please contact us at talk@favelaconsult.lol and specify the date or version you are interested in.
15 Contact information and complaints
Favela Digital Consulting LLC is the entity responsible for the Personal Data collected through the Site and in the course of our business. If you have questions, comments, or concerns about this Privacy Policy, our data practices, or if you wish to exercise any of your data subject rights, we welcome you to contact us using any of the channels below.
1615 E Blaine Ave
Salt Lake City, UT 84105-3802
United States
Email: talk@favelaconsult.lol
Phone: +1 (959) 998-2580
Web: https://www.favelaconsult.lol
15.1 Data protection inquiries
All data protection inquiries should be directed to the email address above with the subject line beginning with Privacy or Data Protection. We aim to acknowledge all inquiries within two (2) business days and to provide a substantive response within fourteen (14) calendar days. Complex inquiries that require consultation with our legal advisors may take longer, and we will keep you informed of our progress.
15.2 Dispute resolution
If a dispute arises relating to this Privacy Policy or our handling of your Personal Data, we encourage you to first contact us directly so we may seek an amicable resolution. Our Terms of Service contain additional provisions relating to dispute resolution, governing law, and venue, which are incorporated herein by reference. Nothing in this policy limits your right to seek relief from a competent court or regulatory authority.
15.3 California-specific disclosures
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have additional rights, including the right to know what Personal Information we have collected, used, shared, or sold (we do not sell Personal Information); the right to delete Personal Information; the right to correct inaccurate Personal Information; and the right to non-discrimination for exercising CCPA rights. To exercise your CCPA rights, please email talk@favelaconsult.lol with CCPA Request in the subject line. We will verify your identity using information we already hold and respond within forty-five (45) calendar days.
15.4 Utah-specific disclosures
Under the Utah Consumer Privacy Act (UCPA), Utah residents have the right to confirm whether we process their Personal Data, to access and delete their Personal Data, to obtain a portable copy of their Personal Data, and to opt out of the processing of Personal Data for targeted advertising or the sale of Personal Data (we do not engage in either activity). To exercise your UCPA rights, please email talk@favelaconsult.lol with UCPA Request in the subject line.
15.5 EU and UK representatives
As a company based in the United States that does not have an establishment in the European Union or the United Kingdom, we are not required to designate an EU or UK representative under Article 27 of the GDPR. However, we are committed to cooperating with EU and UK data protection authorities and will respond to inquiries from such authorities promptly. EU and UK data subjects may direct inquiries to talk@favelaconsult.lol, and we will ensure your concern is addressed with due regard to the GDPR and UK GDPR.