Privacy Policy
How We Handle Your Information
This Privacy Policy explains what information Blevins Holdings LLC collects about you, how we use it, who we share it with, and the rights you have over your personal information. We’ve written it to be readable. If anything is unclear, contact us.
Who This Policy Covers
This policy applies to information collected through Blevins Holdings LLC websites, applications, and services, as well as information collected from our customers, vendors, contractors, and business partners in the course of operations.
It applies to Blevins Holdings LLC and our subsidiaries and controlled affiliates. Where a specific service has its own privacy notice, that notice controls for that service.
Information We Collect
Information You Provide
- Identifiers: name, email, postal address, phone number, account credentials
- Professional information: employer, job title, business contact details
- Commercial information: services purchased, contract terms, payment records
- Communications: emails, support tickets, form submissions
Information Collected Automatically
- Network identifiers: IP address, device identifiers, session metadata
- Device and browser data: user agent, operating system, screen resolution, language
- Usage data: pages viewed, features used, timestamps, referring URLs
- Security and diagnostic data: error logs, authentication events, access patterns
Information From Third Parties
- Business partners and referral sources
- Identity verification and fraud prevention providers
- Publicly available business directories and registries
How We Use Your Information
We use information for the following purposes, each tied to a defined legal basis (contract performance, legitimate interest, legal obligation, or consent where required):
- Delivering services, fulfilling contracts, and managing customer accounts
- Managing vendor, contractor, and business partner relationships
- Operating, securing, and improving our systems and infrastructure
- Detecting, investigating, and preventing fraud, abuse, and security incidents
- Complying with legal, regulatory, and audit obligations
- Communicating with you about services, updates, and policy changes
Who We Share Information With
We share personal information only with the following categories of recipients, and only as needed for the purposes above:
- Affiliates and subsidiaries within the Blevins Holdings group, under shared data protection standards
- Service providers (hosting, payment processing, analytics, support tools) bound by written data protection agreements
- Business partners and enterprise customers where required to deliver contracted services
- Government and regulatory authorities when required by law, subpoena, or court order
- Successors and counterparties in connection with a merger, acquisition, financing, or sale of assets
A current list of subprocessors is available on request from privacy@blevinsholdings.com.
Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to operate our sites, remember preferences, and measure usage. The categories we use:
| Category | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly necessary | Authentication, security, session management | No — required for the site to function |
| Functional | Remembering preferences and settings | Yes, via browser settings |
| Analytics | Aggregated usage measurement and performance monitoring | Yes, via our cookie banner or browser settings |
We honor Global Privacy Control (GPC) signals as a valid opt-out request where applicable law requires. We do not use cookies for cross-site behavioral advertising.
How Long We Keep Information
We retain personal information only as long as needed for the purposes it was collected, or as required by law. Our standard retention periods:
| Data Category | Retention Period |
|---|---|
| Customer account records | Duration of relationship + 3 years |
| Financial and tax records | 7 years (IRS and statutory requirements) |
| Contracts and procurement records | Term of contract + 6 years |
| Government contracting records (FAR/DFARS) | Per applicable contract clause, typically 3–6 years post-final payment |
| System logs and security telemetry | 13 months |
| Marketing communications data | Until you opt out, then deleted within 30 days |
| Support tickets and correspondence | 3 years from closure |
After the retention period, data is deleted or de-identified. Backups containing personal data are retained for up to 90 days beyond the active retention period and then purged on a rolling cycle.
How We Protect Information
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. These include encryption in transit and at rest for sensitive data, access controls based on least privilege, multi-factor authentication for system access, continuous logging and monitoring, and regular security reviews.
No system is perfectly secure. If a security incident affects your personal information, we will notify you and applicable authorities as required by law.
Your Privacy Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Right to know what personal information we collect, use, and disclose
- Right to access a copy of your personal information
- Right to correct inaccurate personal information
- Right to delete personal information, subject to legal exceptions
- Right to opt out of sharing or sale (we do not sell or share for advertising)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
- Right to appeal a denied request
For California Residents (CCPA/CPRA)
California residents have the rights listed above. In the past 12 months, we have collected the categories of information described in Section 02 for the purposes described in Section 03, and disclosed information only to the categories of recipients listed in Section 04. We have not sold or shared personal information as defined under the CCPA.
For EU/UK Residents (GDPR/UK GDPR)
You have the rights listed above plus the right to data portability and the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are contract performance, legitimate interest, legal obligation, and consent (where required).
How to Exercise Your Rights
Submit requests to privacy@blevinsholdings.com. We will verify your identity before fulfilling a request and respond within 45 days (CCPA) or 30 days (GDPR), with one extension if reasonably needed. You may use an authorized agent; we will require written authorization.
International Data Transfers
Blevins Holdings is based in the United States. If you access our services from outside the U.S., your information will be transferred to, stored in, and processed in the United States, which may not provide the same level of data protection as your country.
For transfers of personal data from the EU, UK, or Switzerland to the United States, we rely on Standard Contractual Clauses approved by the European Commission and equivalent safeguards, supplemented by additional technical and organizational measures where required.
Children’s Privacy
Our services are directed to businesses and adult professionals. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that threshold applies). If you believe a child has provided us with personal information, contact privacy@blevinsholdings.com and we will delete it.
Government Contracting Systems
Certain Blevins Holdings systems support federal contracting and related regulated workflows. These environments are governed by applicable contract clauses (including FAR, DFARS, and CMMC requirements where in scope) and additional access controls.
Changes to This Policy
We may update this policy from time to time. When we do, we’ll update the “Last Updated” date at the top of the page. For material changes that affect your rights or how we use your information, we’ll provide additional notice — by email to account holders, by prominent notice on our site, or both — at least 30 days before the changes take effect.
Prior versions of this policy are available on request.