Privacy Policy
1. Introduction and Scope
MILLER & ASSOCIATES, INC. (hereinafter referred to as the Company, we, us, or our) is a Computer Systems Design and Related Services firm headquartered at 110 Robinson Rd, Aspen - 81611, United States (US). This Privacy Policy explains in comprehensive detail how we collect, use, store, share, transfer, and protect personal information obtained from visitors to our website (millerass.rest), prospective and current clients, applicants for employment, and any other natural persons whose personal data may come into our possession in the course of providing our professional services. This document constitutes a binding disclosure of our data handling practices and is intended to satisfy the transparency requirements of applicable data protection legislation, including but not limited to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), the Colorado Privacy Act (CPA), and other state-level comprehensive privacy laws within the United States.
By accessing our website, engaging our services, submitting information through our contact forms, or otherwise interacting with us in any capacity that involves the transmission of personal data, you acknowledge that you have read and understood this Privacy Policy and you consent to the collection, use, and disclosure practices described herein. If you do not agree with any provision of this policy, you must immediately discontinue use of our website and refrain from providing us with any personal information. We reserve the right to modify this policy at any time, and such modifications shall become effective immediately upon posting to this page. It is your responsibility to review this policy periodically to remain informed of any changes. Your continued use of our website or services following the posting of any changes constitutes acceptance of those changes.
2. Information We Collect
We collect several categories of information from and about you, both directly and through automated means. The information we collect depends on the nature of your interaction with us and the specific context in which the data is provided. We strive to limit our collection to information that is strictly necessary to fulfill the purposes for which it was collected and to deliver the services you have requested. We do not collect sensitive personal information such as government-issued identification numbers, biometric data, precise geolocation data, or health information unless such collection is explicitly required for a specific engagement and we have obtained your prior written consent to do so.
The categories of personal information we may collect include: identifiers such as your full name, email address, postal address, telephone number, and Internet Protocol (IP) address; professional or employment-related information such as your job title, company name, industry sector, and professional qualifications; commercial information such as records of services purchased or considered; internet or other electronic network activity information such as your browsing history on our website, search queries, and interaction with our content; and any inferences we may draw from the information you provide to create a profile reflecting your preferences and potential business needs. When you submit our contact form, we collect the information you voluntarily provide in the form fields. When you browse our website, our servers automatically log certain technical information including your IP address, browser type and version, operating system, referring URL, pages visited, time and date of your visit, and the duration of your session. This information is collected through standard server logs and does not, by itself, identify you personally.
3. How We Use Your Information
We use the personal information we collect for a variety of legitimate business purposes, all of which are designed to enhance your experience, improve the quality of our services, and maintain the operational integrity of our business. The primary uses of your information include responding to your inquiries and fulfilling requests you make through our website, including providing information about our computer systems design and consulting services; evaluating your suitability as a prospective client and determining whether we are able to assist with your specific technology needs; negotiating, entering into, and performing contracts for the provision of our professional services; communicating with you about project updates, service changes, and relevant industry developments that may affect your technology infrastructure or business operations; processing payments and managing our billing and accounting functions; complying with applicable legal obligations, including responding to lawful requests from public authorities and enforcing our contractual rights; and improving our website, services, and overall client experience through analytics and data-driven insights.
We may also use your information for internal research and development purposes, including the development of new service offerings, the refinement of our methodologies and frameworks, and the measurement of client satisfaction and engagement outcomes. Additionally, we may use aggregated and de-identified information derived from your data for statistical analysis, industry benchmarking, and the publication of thought leadership content, provided that such aggregated data cannot reasonably be re-identified or linked back to you. We do not use your personal information for automated decision-making that produces legal or similarly significant effects concerning you without human intervention and appropriate safeguards. Furthermore, we do not sell your personal information to third parties for monetary consideration, nor do we share your information with third parties for cross-context behavioral advertising purposes.
4. Cookies and Tracking Technologies
Our website may use cookies and similar tracking technologies, including web beacons, pixels, and local storage objects, to collect and store certain information about your browsing activity. Cookies are small text files that are placed on your device by a web server when you visit a website and are used to remember your preferences, authenticate your session, and analyze how you interact with the site. We classify the cookies we use into several categories: strictly necessary cookies that are essential for the operation of our website and cannot be disabled in our systems; performance and analytics cookies that help us understand how visitors interact with our website by collecting and reporting information anonymously; and functional cookies that enable enhanced functionality and personalization, such as remembering your language preferences or the region you are in.
You have the ability to control the use of cookies through your browser settings. Most web browsers allow you to refuse to accept cookies, delete cookies that have already been set, or set your browser to alert you when a cookie is being placed on your device. The methods for doing so vary from browser to browser, and we encourage you to consult your browser's help documentation for specific instructions. Please be aware that if you choose to block or delete cookies, certain features of our website may not function properly or may become unavailable to you, and your overall user experience may be diminished. We do not currently respond to browser-based Do Not Track (DNT) signals because no universally accepted standard for interpreting and acting upon such signals has been established. Third-party services that we may integrate into our website, such as analytics providers, may independently set their own cookies, and we encourage you to review their respective privacy policies for detailed information about their practices.
5. Data Sharing and Disclosure
We share your personal information only in the limited circumstances described in this section and always in a manner consistent with the purposes for which the data was originally collected. We may disclose your information to our trusted service providers and contractors who perform functions on our behalf and are contractually obligated to use your information solely for the purpose of providing the services we have engaged them to perform. These service providers may include cloud hosting and infrastructure providers, email delivery services, customer relationship management platform operators, payment processors, analytics providers, and professional advisors such as attorneys and accountants. Each of these service providers is subject to written agreements that impose data protection obligations at least as stringent as those set forth in this Privacy Policy, and we conduct due diligence on each provider to ensure their compliance with applicable data protection laws.
We may also disclose your personal information if we believe in good faith that such disclosure is necessary to comply with a legal obligation, including responding to subpoenas, court orders, or other legal process; to protect and defend our rights, property, or safety, and that of our clients, employees, and the public; to detect, prevent, or otherwise address fraud, security breaches, or technical issues; or to enforce our Terms of Service and other contractual agreements. In the event of a merger, acquisition, reorganization, asset sale, or similar corporate transaction, personal information held by us may be among the assets transferred to the successor entity. You will be notified via email or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information. We do not sell, rent, or lease your personal information to any third party for their own direct marketing purposes.
6. Data Security Measures
We implement and maintain a comprehensive set of administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of the personal information in our possession. Our security program is built upon industry-recognized frameworks including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and is continuously reviewed and updated to address emerging threats and vulnerabilities. Administrative safeguards include our internal data governance policies, employee training programs on data protection and privacy, role-based access controls that limit access to personal information to authorized personnel with a legitimate business need, and regular security awareness training for all employees and contractors. Technical safeguards include the use of Transport Layer Security (TLS) encryption for data transmitted between your browser and our servers, encryption of personal information at rest using AES-256 or equivalent standards, multi-factor authentication for access to systems containing personal information, intrusion detection and prevention systems, regular vulnerability scanning and penetration testing, and enterprise-grade endpoint protection across all devices that access our network. Physical safeguards include controlled access to our facilities, surveillance systems, and secure destruction procedures for physical media containing personal information.
Despite our best efforts, no method of electronic transmission or storage is one hundred percent secure, and we cannot guarantee absolute security of your personal information against all possible threats. If we become aware of a data breach that compromises your personal information, we will notify you without undue delay and in any event within the timeframes required by applicable law. Our notification will describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences of the breach, and the measures we have taken or propose to take to address the breach and mitigate its potential adverse effects. We also maintain a detailed incident response plan that has been tested and refined through regular tabletop exercises. In the event of a security incident, we will cooperate fully with law enforcement authorities and regulatory bodies as required. We encourage you to take steps to protect your own information, including using strong and unique passwords, keeping your software updated, and being vigilant against phishing and other social engineering attempts.
7. Data Retention
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required to comply with applicable legal, regulatory, tax, accounting, or reporting requirements. The specific retention period for any given category of personal information depends on the nature of the information, the purpose for which it was collected, and any applicable statutory retention obligations. When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal information; the potential risk of harm from unauthorized use or disclosure of the information; the purposes for which we process the information and whether we can achieve those purposes through other means; and the applicable legal, regulatory, and contractual requirements that mandate the preservation of certain records for specified periods.
As a general guideline, we retain client engagement records, including correspondence, contracts, and project documentation, for a period of seven years following the conclusion of the client relationship, which is consistent with standard business record-keeping practices and statutes of limitation for contractual claims. Technical log data is typically retained for a period of twelve to twenty-four months, after which it is aggregated or permanently deleted. Marketing communications data is retained until you unsubscribe or opt out of receiving such communications, at which point we will retain only the minimum information necessary to honor your opt-out preference. When personal information is no longer required for the purposes described in this policy, we will take reasonable steps to securely delete, destroy, or permanently de-identify the information in accordance with our data disposal procedures, provided that we are not required to retain it by applicable law. You may request the deletion of your personal information at any time by contacting us using the details provided in this policy, and we will respond to your request in accordance with applicable law.
8. Your Privacy Rights
Depending on your jurisdiction of residence, you may have certain rights regarding your personal information under applicable data protection laws. These rights may include the right to know what personal information we have collected about you, including the categories of information, the sources from which it was collected, the business purpose for collection, and the categories of third parties with whom we have shared it; the right to access and obtain a copy of the personal information we hold about you in a portable and readily usable format; the right to request correction of any inaccurate or incomplete personal information we maintain about you; the right to request deletion of your personal information, subject to certain legal exceptions that permit us to retain information; the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising, though as stated above we do not engage in such practices; the right to limit the use and disclosure of sensitive personal information, where applicable; and the right not to receive discriminatory treatment for exercising any of your privacy rights, including denial of services, different pricing, or a different quality of service.
To exercise any of these rights, or if you have questions about the rights available to you under your specific jurisdiction's laws, please contact us at the email address or telephone number provided in the Contact Information section of this policy. We will respond to your request within the timeframe prescribed by applicable law, typically within forty-five days of receipt, though we may extend this period by an additional forty-five days when reasonably necessary, provided we notify you of the extension within the initial response period. We may need to verify your identity before processing your request, which may require you to provide additional information so that we can match it against the information we have on file. If we are unable to verify your identity, we may deny your request and will inform you of the reason for the denial. You may designate an authorized agent to submit a request on your behalf, provided that the agent provides proof of your signed authorization and we are able to verify your identity directly with you. We do not charge a fee to process your privacy requests unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act on the request.
9. Children's Privacy
Our website and services are not directed to, intended for, or knowingly marketed to individuals under the age of eighteen. We do not knowingly collect, solicit, or maintain personal information from anyone under the age of eighteen, and we do not sell the personal information of minors under the age of sixteen without affirmative authorization. If we become aware that a person under the age of eighteen has provided us with personal information without verifiable parental consent, we will take immediate steps to delete such information from our records and terminate the associated account or interaction, if applicable. If you are a parent or legal guardian and you believe that your child has provided us with personal information without your consent, please contact us immediately at the email address or telephone number provided in this policy, and we will work expeditiously to remove the information from our systems.
We encourage parents and guardians to take an active role in their children's online activities and to educate them about the importance of protecting their personal information and privacy online. We recommend that minors under the age of eighteen consult with their parents or guardians before submitting any personal information through any website or online service. Our commitment to protecting children extends to our internal practices as well: we do not market our professional services to minors, and our consulting engagements are exclusively with businesses, organizations, and adult decision-makers. Any inadvertent collection of a minor's personal information will be treated as a data incident and handled in accordance with our incident response procedures, including notification to the appropriate parties as required by law.
10. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms, applications, and services that are not owned, operated, or controlled by MILLER & ASSOCIATES, INC. These links are provided solely for your convenience and informational purposes and do not constitute an endorsement, sponsorship, or recommendation of the linked content, products, services, or privacy practices of those third parties. We have no control over, and assume no responsibility for, the content, privacy policies, data collection practices, or security measures of any third-party websites or services that you may access through links on our website. We strongly encourage you to review the privacy policies and terms of service of every website you visit before providing any personal information to them.
When you click on a link to a third-party website, you will be leaving our website, and any information you provide to that third party will be governed by their privacy policy and terms, not by this Privacy Policy. We make no representations or warranties regarding the accuracy, completeness, or reliability of any information, products, or services offered by third-party websites, and we disclaim all liability for any loss or damage arising from your use of or reliance on such third-party content. This also applies to any social media platforms, professional networks, or business directories on which we may maintain a presence. Our interactions with you on those platforms are governed by both this Privacy Policy and the privacy policy of the respective platform. If you have a dispute with any third party regarding their handling of your personal information, you agree that you will pursue any legal remedies directly against that third party and not against MILLER & ASSOCIATES, INC.
11. International Data Transfers
MILLER & ASSOCIATES, INC. is headquartered in the United States, and our website and services are operated and managed on servers located within the United States. If you are accessing our website or providing personal information to us from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where our servers are located and our central operations are conducted. The data protection laws of the United States may differ from the laws of your country of residence, and in some cases they may not provide the same level of protection as the laws of your jurisdiction. By using our website, submitting information to us through any means, or engaging our services from outside the United States, you explicitly consent to the transfer of your personal information to the United States and to the processing of that information in accordance with this Privacy Policy and applicable United States law.
We take reasonable steps to ensure that any personal information transferred internationally receives an adequate level of protection consistent with the standards described in this policy. Where required by applicable law, we will implement appropriate contractual mechanisms, such as Standard Contractual Clauses (SCCs) as approved by the relevant regulatory authorities, to govern the transfer and processing of your personal information. We also conduct transfer impact assessments where required to evaluate the laws and practices of the destination country and to identify any supplementary measures that may be necessary to bring the level of protection of the transferred data up to the standard required by the originating jurisdiction. If you have questions about the specific safeguards we have in place for international data transfers, please contact us using the details provided in this policy.
12. Changes to This Privacy Policy
We reserve the right to update, amend, or replace this Privacy Policy at any time and for any reason, in our sole discretion. Changes may be made to reflect updates in our data processing practices, changes in applicable law or regulatory guidance, developments in technology, or for other operational, legal, or regulatory reasons. When we make material changes to this policy, we will post the updated version on this page and update the Last Updated date at the top of the document. For changes that we determine to be material in nature, we may also provide additional notice, such as by sending an email to the address you have provided to us or by placing a prominent notice on our website for a reasonable period prior to the change becoming effective. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information.
Your continued use of our website or services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the changes. If you do not agree with the revised policy, you must discontinue your use of our website and services and, where applicable, contact us to request the deletion of your personal information, subject to any legal obligations that may require us to retain certain data. We will not retroactively apply material changes to your personal information without providing you with notice and, where required by law, obtaining your consent. Archived versions of this Privacy Policy will be made available upon request for a reasonable period following any update, so that you can review the historical evolution of our data practices. If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be severed and the remaining provisions shall continue in full force and effect.
13. Contact Information and Dispute Resolution
If you have any questions, concerns, comments, or requests regarding this Privacy Policy, our data handling practices, or your privacy rights, we encourage you to contact us directly. We are committed to engaging with you in good faith to resolve any concerns you may have. You may reach our Data Privacy Office through any of the following channels. By email at stenoekkannelotobj@gmail.com, which is monitored during regular business hours, Mountain Time, Monday through Friday, excluding federal holidays. By telephone at +6282310681447, where you may speak with a representative regarding privacy-related matters. By postal mail at MILLER & ASSOCIATES, INC., Attn: Data Privacy Office, 110 Robinson Rd, Aspen - 81611, United States (US). We endeavor to acknowledge all privacy-related inquiries within five business days of receipt and to provide a substantive response within thirty calendar days. If your inquiry is complex or requires detailed investigation, we will inform you of the expected timeline for resolution and keep you updated on our progress.
In the unlikely event that you are not satisfied with our response to your privacy concern, you may have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. In the United States, privacy enforcement is conducted at both the federal level by agencies such as the Federal Trade Commission (FTC) and at the state level by Attorneys General and specialized privacy enforcement bodies. We are committed to cooperating with all applicable regulatory authorities in the investigation and resolution of any privacy complaints. Before escalating a matter to a regulatory body, we respectfully request the opportunity to address your concern directly, as we believe the vast majority of issues can be resolved through direct dialogue. For disputes arising under this Privacy Policy that cannot be resolved through informal negotiation, you agree to submit to binding arbitration administered by the American Arbitration Association in accordance with its Commercial Arbitration Rules, with the arbitration to take place in Pitkin County, Colorado. You waive any right to participate in a class action or representative proceeding against us, and you agree that any arbitration shall be conducted on an individual basis only.