Privacy Policy
How we collect, use, and protect personal information.
DOCUMENT
LG-02
OWNER
Data Protection Officer
EFFECTIVE
January 1, 2026
REVIEWED
April 1, 2026
Who we are
Escalation Holding LLC (DBA Alexa Cybersecurity) ("Alexa", "we", "our", or "us") is the data controller for personal information collected through this website and through our commercial engagements, except where we act as a processor on behalf of a client (see "Services data" below).
Headquarters: 5900 Balcones Dr, Suite 100, Austin, Texas. Branch: 11501 W. 81st St, Apt 234, Lenexa, Kansas. Contact: privacy@alexasecurity.net.
Information we collect
- 01Identity and contact data — name, business email, business phone, employer, role.
- 02Inquiry content — the message you submit through our contact form, the topic, and any attachments.
- 03Technical data — IP address, browser type, device identifiers, referring URL, pages visited, timestamps.
- 04Engagement data — emails opened, links clicked, content downloaded, webinars attended (when you opt-in).
- 05Cookies and similar — see our Cookie Policy.
- 06Authentication data — when you create an account on a client portal, your credentials and access logs.
How we use your information
- 01To respond to your inquiries and deliver requested information or services.
- 02To enter into and perform contracts with you or the entity you represent.
- 03To send service announcements, security advisories, and (where you have opted in) marketing communications.
- 04To improve, secure, and operate our website, products, and services.
- 05To comply with legal obligations, including sanctions screening, anti-money-laundering, and tax reporting.
- 06To establish, exercise, or defend legal claims.
Legal bases (GDPR, where applicable)
- 01Performance of a contract with you or the entity you represent.
- 02Our legitimate interests in operating and securing the business, balanced against your rights.
- 03Compliance with a legal obligation.
- 04Your consent, where required (e.g., non-essential cookies, marketing email).
Services data (controller / processor)
When we process personal data on behalf of a client as part of a service engagement, the client is the data controller and Alexa is the data processor. Our processing in that role is governed by a written Data Processing Agreement (DPA), and we follow the client's documented instructions.
Sharing and transfers
- 01Service providers acting on our instructions (cloud hosting, email infrastructure, billing, support tooling) under written contracts that include confidentiality and security obligations.
- 02Professional advisors (legal, audit, insurance) under confidentiality.
- 03Government authorities where required by law or valid legal process.
- 04In connection with a corporate transaction (merger, acquisition, financing) under appropriate confidentiality.
- 05International transfers — where personal data is transferred outside the EEA / UK, we use Standard Contractual Clauses or another lawful transfer mechanism, supplemented by additional safeguards as required.
Retention
We retain personal data only for as long as needed for the purposes described above, to comply with our legal, accounting, or regulatory obligations, and as needed to assert or defend legal claims. Inquiry data is generally retained for 24 months; client account data for the duration of the relationship plus seven years.
Your rights
- 01Access — request a copy of the personal data we hold about you.
- 02Rectification — correct inaccurate or incomplete data.
- 03Erasure — request deletion, subject to legal exceptions.
- 04Restriction — limit how we use your data while a dispute is resolved.
- 05Portability — receive your data in a machine-readable format.
- 06Objection — object to processing based on legitimate interests or for direct marketing.
- 07Withdraw consent — at any time, where processing is based on consent.
- 08Lodge a complaint with a supervisory authority.
Security
We apply technical and organizational measures aligned with ISO/IEC 27001, SOC 2, and CMMC L2 to protect personal data, including encryption in transit and at rest, MFA, least-privilege access, continuous monitoring, and a formal incident response program.
Contacting us
To exercise your rights or to ask questions about this Policy, please contact privacy@alexasecurity.net. We respond within 30 days; complex requests may require a 60-day extension under applicable law.
/CONTROLLED_DOCUMENT
This document is the official, controlled version of LG-02 — Privacy Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.
VERSION
2026.1
REVIEWED
April 1, 2026
NEXT REVIEW
Annual


