Home/Privacy Policy
Table of Contents
This Privacy Policy explains how NPH Solutions LLC collects, uses, stores, shares, and protects information when you visit www.nphsolutions.buzz, communicate with our team, or engage our information technology services. The website and the services described on it are developed and operated by the developer NPHSolutions on behalf of NPH Solutions LLC, a limited liability company organized under the laws of the United States with a principal place of business at 635 E 650 S, Layton - 84041-4279, United States (US).
In this document we refer to NPH Solutions LLC as NPH Solutions, we, us, or our. We refer to you as a visitor, a prospective client, a client, or a representative of a client organization, depending on how you interact with us. By using this website, submitting a form, calling our office, or entering into a service agreement with us, you acknowledge the practices described in this policy. If you do not agree with any part of this policy, please discontinue use of the website and contact us so we can answer your questions before you share any personal information with us.
This policy applies to information we handle through our public website, through direct communications such as email and telephone, and through the administrative and support functions that surround our service engagements. It applies to visitors who merely read our pages as well as to representatives of organizations that purchase services from us.
Where we provide managed services to a client organization, that organization remains the controller or owner of the data residing in its own systems, and our handling of that data is additionally governed by the written service agreement between us, including any data protection addendum the engagement includes. Nothing in this policy reduces the commitments we make in a signed contract. Where a contract term and this policy conflict for a specific engagement, the contract term controls for that engagement, and this policy continues to govern everything else.
We collect several categories of information depending on how you interact with us:
We ask that you do not send us sensitive personal information that a given interaction does not require, such as government identification numbers, health details, or financial account numbers, unless we have specifically requested such information for a defined purpose.
We use three broad methods of collection. First, we collect information directly from you when you fill in a contact form, request a proposal, subscribe to an update, call our office, or otherwise correspond with us. Second, we collect certain technical information automatically as you use the website, through server logs, cookies, and similar technologies described in the cookie section of this policy. Third, we may receive information about you from third parties, such as a colleague who includes you on a project, a referral partner who suggests you contact us, or a vendor who provides service tooling that contains your contact details.
When information reaches us through a third party, we treat it under this policy from the moment we receive it. If you believe a third party shared your information with us without a proper basis, contact us and we will review the record and, where appropriate, delete it.
Where privacy law requires a legal basis for processing, we rely on the following, as applicable to the interaction:
We do not carry out automated decision-making that produces legal effects concerning you without human involvement. Security monitoring may use automated tools to flag events, but a qualified engineer reviews and decides before any consequential action is taken.
We use the information we hold to provide and improve our services. Concretely, we use it to respond to inquiries and consultations; to prepare proposals and deliver engagements; to operate, maintain, and secure our infrastructure and this website; to send administrative messages such as invoices, service notices, and appointment confirmations; to send marketing updates where permitted; to analyze usage so we can improve content and performance; to detect, prevent, and address technical issues, misuse, and security incidents; and to comply with legal and regulatory duties.
We aim to collect only what is adequate and relevant for these purposes. When a project ends and no legal or contractual reason requires us to keep a given record, we retire it under the retention schedule described later in this policy.
We host this website with reputable hosting infrastructure and may use analytics tooling to measure aggregate traffic. These providers process limited technical data, such as IP address, device characteristics, and page interactions, on our instructions and under contractual confidentiality and security obligations. We select providers that maintain recognized security certifications and we review their practices before onboarding them.
Analytics reports show us trends such as which service pages are read most and which regions visitors come from, in a form that does not require us to identify individual readers. We do not combine website analytics with advertising profiles, and we do not attempt to identify visitors beyond what technical support and security require.
We keep personal information only as long as the purposes described in this policy require it and as long as legal, accounting, or contractual obligations demand. Typical periods include engagement records and invoices for seven years after the relevant fiscal period, consistent with tax and audit requirements; support tickets for twenty-four months after closure so recurring problems can be diagnosed; marketing contact records until you unsubscribe or until twenty-four months of inactivity, whichever comes first; and web server logs for ninety days unless a security investigation requires longer.
When a retention period ends, we delete the information or de-identify it so it can no longer be associated with you. Backups follow their own lifecycle, and information removed from active systems may persist in encrypted backups until those backups age out on schedule. Our systems are hosted in facilities with physical and environmental controls operated by established providers.
We apply the same engineering discipline to our own systems that we sell to clients. Administrative safeguards include background-checked staff, written security policies, confidentiality agreements, and recurring security training. Technical safeguards include encryption of data in transit using modern transport protocols, encryption of data at rest where supported, multi-factor authentication on administrative access, least-privilege access models, centralized logging, vulnerability patching on a fixed schedule, and immutable backups. Physical safeguards are provided by our hosting partners, whose facilities use controlled entry, video monitoring, and environmental protections.
We maintain an incident response plan so that suspected incidents are contained, investigated, and, where required, reported to affected parties and authorities within applicable timeframes. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we design our controls so that a single failure does not expose information and so that every access leaves a record.
When we manage systems on behalf of a client organization, the credentials that reach us are stored in an encrypted credential vault with access limited to the engineers assigned to that account. Administrative actions are logged, changes follow the change-control procedure agreed in the statement of work, and evidence of who changed what and when is available to the client on request.
Client data remains the property of the client at all times. We do not mine client data, we do not use client environments to train external products, and at the end of an engagement we return or securely destroy credentials and artifacts according to the exit terms of the agreement. These commitments exist alongside, and never instead of, the obligations in the signed contract.
Depending on your location and applicable law, you may have some or all of the following rights concerning personal information we hold about you:
Residents of states and countries with specific statutes, such as California, Colorado, Connecticut, Virginia, Utah, and members of the European Economic Area, may exercise these rights through the channels in the contact section. To respond, we must verify your identity, which we do by matching details you provide against records we already hold, or by confirming a request through the email address on file. You may designate an authorized agent to submit a request with written permission. We acknowledge requests promptly and aim to substantively respond within forty-five days, with a possible extension where the law allows and we notify you. If you are unhappy with our response, you may appeal by replying to our decision, and we will explain any further steps available to you.
This website and our services are directed to organizations and professionals, not to children. We do not knowingly collect personal information from children under thirteen years of age, and we do not knowingly allow children to submit information through our forms. If you are a parent or guardian and believe a child has provided us with personal information, contact us at call@nphsolutions.buzz or +13189377877, and we will delete the information promptly. Consistent with the United States Children Online Privacy Protection Act, we will never condition a service on a child providing more information than is reasonably necessary, and we maintain practices designed to avoid collecting such data in the first place.
NPH Solutions LLC operates from the United States, and our primary processing and storage occur in the United States. Visitors from other regions should understand that information submitted through this website will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those of your jurisdiction.
Where we must transfer personal information out of a region that restricts such transfers, we use recognized safeguards, such as standard contractual clauses or equivalent mechanisms, together with supplementary technical measures appropriate to the data involved. If you have questions about the safeguards applied to a specific transfer, contact us and we will describe the mechanism used.
We send two kinds of email. Administrative email concerns transactions and engagements: proposals, invoices, appointment confirmations, service notices, and security alerts. These messages are necessary for us to serve you and are not promotional. Marketing email, where you have opted in, shares service updates, security advisories, and invitations, and every such message carries an unsubscribe link that takes effect promptly.
You can change your preferences at any time by using the unsubscribe link, by replying to a message, or by contacting us directly. Unsubscribing from marketing email does not stop administrative messages required for an active engagement, and we do not sell or share email lists with advertisers. Records of your preferences are kept so that your choices are respected across our systems.
Our website may link to third-party resources, such as platform documentation, vendor status pages, or industry references, that we believe are useful. Those websites operate under their own privacy policies, and this policy does not extend to them. We encourage you to read the privacy notice of every website you visit, especially before submitting information to it.
A link from our site is not an endorsement of every practice on the destination site, and we are not responsible for the content or the data handling of websites we do not control. If you find that a linked resource mishandles data in a way that concerns you, let us know; we review feedback and remove links where warranted.
We may update this policy to reflect changes in our practices, our services, or applicable law. The current version is always published on this page, and the effective date at the top of the page tells you when it was last revised. For material changes that affect your rights or the way we use information you have already provided, we will take reasonable additional steps, such as a notice on the website homepage or an email to affected contacts, before the change takes effect.
Continued use of the website after a revised policy takes effect constitutes acceptance of the revised policy for new interactions. If a change materially reduces protections for information already held, we will obtain any consent that the law requires before applying the change to that information.
Questions, requests, and complaints about privacy are handled directly by our team. Reach us through any of the following channels:
We aim to acknowledge privacy inquiries within three business days and to resolve substantive requests within the periods described in the rights section. If your matter concerns a managed service engagement, please also reference the account or agreement name so we can route your question to the right engineers without delay.
This policy describes the practices of NPH Solutions LLC only. The services it describes are developed and operated by the developer NPHSolutions for NPH Solutions LLC. © 2026 NPH Solutions LLC. All rights reserved.