Privacy Policy

Effective Date: 7/1/2026

Company: Open InfoTech Solutions

Website: oitsol.com

Contact: info@oitsol.com

Open InfoTech Solutions (“Company,” “we,” “our,” or “us”) provides software development,
web and application hosting, IT consulting, outsourced CTO/CIO services, and traditional
IT support services. This Privacy Policy explains how we collect, use, store, and share
information in connection with our website, client services, hosted systems, and support
activities.

We do not sell client information or personal information.

1. Information We Collect

The information we collect depends on how you interact with us and which services we provide.

Website Information

When you visit our website, we may collect information that you voluntarily provide, such as:

  • Contact form submissions
  • Comments or inquiries
  • Newsletter signups
  • Event registrations or similar submissions
  • Email addresses and other information provided for communications

We may also collect basic technical information commonly associated with website operation,
such as IP address, browser type, device type, pages visited, referral information, and
general usage data. We use this information to operate, maintain, and improve our website
and to protect it from abuse.

Client and Project Information

When we provide consulting, software development, hosting, support, or outsourced CTO/CIO
services, we may receive or access information such as:

  • Client contact information
  • Business records, documents, workflows, and process information
  • Software requirements, project notes, credentials, configuration files, logs, databases, and technical documentation
  • Hosted application data
  • Website files, application files, backups, and system data
  • Network, device, server, and user account information
  • Vendor, system, and infrastructure information needed to perform our services

For hosting and application management, client systems may store data supplied by the client,
the client’s users, or the client’s customers. That data remains the client’s data. We access
it only as needed to provide hosting, support, maintenance, troubleshooting, development,
security, backup, or administrative services.

2. How We Use Information

We use information for the following purposes:

  • To respond to inquiries
  • To provide software development, hosting, IT support, consulting, and outsourced technology leadership services
  • To operate, maintain, troubleshoot, and secure client systems
  • To communicate with clients about projects, support requests, billing, renewals, and service matters
  • To prepare proposals, estimates, statements of work, and project documentation
  • To manage newsletter subscriptions or other requested communications
  • To improve our website, services, processes, and internal operations
  • To comply with legal, contractual, security, and business obligations

We do not use client data for unrelated marketing purposes unless the client has separately
provided permission.

3. Hosted Client Data

For hosted applications, websites, databases, or systems, we may store client data as part
of the service. This may include application data, user-submitted data, uploaded files,
system logs, backups, and operational records.

Unless otherwise stated in a written agreement, the client is responsible for determining
what data is collected through its own websites, applications, forms, systems, or users.
The client is also responsible for providing any required notices, obtaining any required
consents, and complying with laws applicable to its own customers, users, employees, or
business operations.

We act as a service provider, contractor, processor, or similar operational support provider
for hosted client data, unless a written agreement states otherwise.

4. Internal Copies of Client Materials

Some projects or support processes may require us to temporarily copy client materials to
our internal systems or network. These materials may include files, databases, exports,
screenshots, credentials, logs, configuration data, or other project-related information.

When such copies are no longer needed, we make reasonable efforts to purge them within
approximately 90 to 180 days, depending on project requirements, support needs, contractual
obligations, backup cycles, legal requirements, or legitimate business needs.

This retention period may be extended when materials are still needed for active work,
troubleshooting, warranty support, security review, documentation, dispute resolution,
compliance, or client-authorized follow-up work.

5. How We Share Information

We do not sell client information or personal information.

We may share limited information in the following circumstances:

Third-Party Partners and Vendors

When working with third-party vendors, consultants, hosting providers, software providers,
or integration partners, we may disclose that we have a mutual client when necessary to
coordinate services, support, implementation, troubleshooting, licensing, or project delivery.

We limit this sharing to what is reasonably needed for the business purpose.

Service Providers

We may use third-party services to help operate our business, such as cloud hosting providers,
email providers, backup systems, domain registrars, payment processors, project management
tools, analytics tools, newsletter platforms, and security tools. These providers may process
information only as needed to provide their services to us.

Client Direction

We may share information when a client asks us to do so, such as sending project materials
to a vendor, integration partner, employee, contractor, or other authorized recipient.

Legal, Security, or Business Requirements

We may disclose information when we believe it is reasonably necessary to:

  • Comply with law, regulation, subpoena, court order, or legal process
  • Protect our rights, property, clients, systems, or business operations
  • Investigate fraud, abuse, security incidents, or unauthorized activity
  • Enforce contracts or collect amounts owed
  • Respond to an emergency or prevent harm

6. Newsletter and Marketing Communications

If you sign up for a newsletter, announcement list, event notice, or similar communication,
we use the information you provide to send the requested communication.

You may unsubscribe from marketing or newsletter communications using the unsubscribe process
provided in the message or by contacting us directly. We may still send non-marketing
communications related to active services, billing, support, security, or contractual matters.

7. Cookies and Website Tools

Our website may use cookies or similar technologies for basic site functionality, security,
analytics, spam prevention, or user experience. If we use third-party analytics, newsletter
signup forms, embedded content, or similar tools, those third-party services may collect
information according to their own privacy policies.

We do not use website data to sell personal information.

8. Security

We use reasonable administrative, technical, and physical safeguards designed to protect
information under our control. These may include access controls, authentication, backups,
network security tools, encryption where appropriate, monitoring, secure development practices,
and internal procedures.

No system, network, transmission, or storage method is completely secure. We cannot guarantee
absolute security, but we work to protect information in a manner appropriate to the type of
information and the services being provided.

9. Data Retention

We retain information only as long as reasonably needed for the purposes described in this
Privacy Policy, unless a longer period is required or permitted by law, contract, backup process,
dispute resolution need, security requirement, or legitimate business purpose.

General retention practices include:

  • Website inquiries: retained as long as needed to respond, maintain business records, or manage follow-up
  • Newsletter information: retained until unsubscribed or otherwise removed
  • Client records: retained as needed for active services, business records, accounting, support, legal, and contractual purposes
  • Hosted data: retained according to the applicable hosting agreement, service terms, backup schedule, or client instruction
  • Temporary internal project materials: purged when no longer needed, with reasonable efforts to remove them within approximately 90 to 180 days depending on need

Backup copies may persist for a limited time after active deletion until backup rotation or
archival processes remove them.

10. Client Responsibilities for Regulated or Sensitive Data

Clients should not provide regulated, highly sensitive, or legally restricted data unless it
is necessary for the services and appropriate safeguards have been agreed to in writing.

Examples may include protected health information, financial account information, payment card
data, government identification numbers, confidential personnel records, children’s data, or
other sensitive personal information.

If a project requires handling regulated or sensitive data, the client should notify us before
providing the data so that appropriate contractual, technical, and operational requirements can
be reviewed.

11. Access, Correction, and Deletion Requests

Depending on where you live and the nature of the information involved, you may have the right
to request access to, correction of, or deletion of certain personal information.

To make a request, contact us at:
[Insert Privacy Contact Email].

We may need to verify your identity before responding. If the information relates to a
client-controlled hosted system, application, website, or database, we may refer the request
to the applicable client because the client controls that data.

We may deny or limit requests when permitted by law, including when information must be retained
for legal, contractual, security, accounting, backup, or legitimate business purposes.

12. Children’s Privacy

Our website and services are not directed to children under 13. We do not knowingly collect
personal information from children through our website. If we learn that we have collected
personal information from a child without appropriate consent, we will take reasonable steps
to delete it.

Client-controlled hosted systems may collect information according to the client’s own business
practices and privacy obligations.

13. Data Breach and Security Incidents

If we become aware of a security incident involving information under our control, we will
evaluate the incident and take appropriate steps based on the nature of the information, our
role, applicable law, and any relevant client agreement.

For hosted client systems, we will work with the affected client as appropriate to investigate
and respond to the incident.

14. Third-Party Websites and Services

Our website or client work may involve links to third-party websites, tools, platforms,
vendors, or services. We are not responsible for the privacy practices, security, or content
of third-party websites or services. Their use is governed by their own terms and privacy policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we update it, we will revise the
effective date above. Continued use of our website or services after an update means the updated
policy applies going forward.

16. Contact Us

Questions about this Privacy Policy may be sent to:

Open InfoTech Solutions
Email: info@oitsol.com
Website: oitsol.com
Mailing Address: PO BOX 311967, New Braunfels, TX 78131