Privacy Policy — Station House

← back to the homepage

1. Who governs this policy

This policy is issued and administered by Stephenson Brian Head LLC, a company organised and operating under the laws of the United States, registered for business at 3378 S Noble Dr, Washington — 84780-3195, United States (US). The developer name frequently associated with the project is StephensonBrian; the two names refer to the same operating office and the same hand on the desk. Any duty found in this policy binds that single office and any contractors working under its explicit instruction.

The office acts as the controller of personal information received through the website stephensonbrian.buzz and through systems designed, configured or managed for clients under a separate written agreement. When the office merely carries data under a client agreement, the client remains the owner and the office follows the client instruction. This policy explains the office approach in the plain role of controller and describes the reasonable limits placed on any subordinate processor role.

2. Scope of this policy

The policy applies to visitors of the homepage and its service pages, to people who write through the email box or the website form, to people whose employer engages the office, and to the employees and contractors of clients whose working accounts are administered by the office. It does not apply to data held solely by a third party on its own infrastructure, even where a link from this site leads to that third party.

The policy is not a substitute for a separate agreement. Where an engagement with Stephenson Brian Head LLC is governed by a signed contract, the contract and its own privacy schedule control that specific work. This web policy stands for the general handling of anything sent directly to the site or the public contact points.

3. Information we collect

Information falls into two classes. First, information a person gives deliberately: a name on a form, an email address, a phone number, a subject line, a message body, or any attached details described in a support or sales enquiry. Second, information a browser or device sends as a matter of course: type of browser, operating system, approximate region, pages requested, time of the visit and the network path used to reach the site.

The office never buys mailing lists, never harvests contact details from social directories and never merges purchased profiles with site records. What is not collected is as important as what is collected. Payment card numbers are entered on the payment processor page, never on an office server. Contents of private mailboxes are accessed only in the course of performing the agreed support role.

4. Information you volunteer

Contact details are collected when a person uses the website form, sends an email to inquiry@stephensonbrian.buzz, calls +16065865913, or signs a paper or electronic engagement form. The minimum we need is usually a name and a reliable reply path. The message itself is stored because a description of a problem is hard to reproduce if the working notes are discarded at once.

Volunteer information may also arrive as resumés sent by candidates, as invoices mailed by suppliers, or as testimonials sent for display. Each of these is treated under the same shelf rules: used to complete the request, held no longer than needed, and never flogged onward. A resumé is read only by the hiring lane it reached and deleted if the application does not proceed past review.

5. Automatic technical data

Like most web offices, small technical records accompany a page view. These include the browser and its version, the display size, the language preference and the reverse lookup of the network used. Such logs help the office keep the wire healthy, spot a hostile burst of requests and measure whether the site is legible on the devices people actually carry.

Logs are ordinary line text and are not woven back together into a detailed personal biography. The office resists building those rich profiles that the largest platforms assemble, because the office has no hand in selling the attention of a visitor. Aggregated counts, such as how many people visited in a month, are safe to cite because they cannot single out a person.

6. Cookies and station keepers

A small number of cookies and similar short-lived markers may be placed to remember a navigation choice or to keep a session coherent. None of them exist to trade behaviour across unrelated sites, and none are set by an advertising network on this property. Where a privacy feature of this site depends on remembering a visitor choice, a functional cookie makes that memory possible.

A visitor can refuse these markers in the browser settings and the site still renders. The only cost is that a repeated choice may have to be made again on the next visit. Readers who want a deeper check of the markers active on their machine are welcome to ask the operative desk; a plain spoken answer will be sent rather than a forest of jargon.

7. How collected information is used

Information is used to answer a question, to prepare a proposal, to deliver a contracted service, to keep that service running, to send a legitimate account notice, to improve the working of the site, to meet a request made under the law, and to defend a right of the company or a right of a client. Each use is tied to a reason given in the next heading.

A direct marketing note is only ever sent to a person who asked for one. Unsubscribing is a single click on the same note, and the wish to be free of future mail is honoured without a quarrel. Nobody is pressured to keep a newsletter subscription in exchange for a support answer, because support answers are earned by good engineering, not by mailing lists.

8. Legal basis for processing

When a law such as the European General Data Protection Regulation applies, the office relies on a matching basis for each act of processing. A request for a contract or a reply to a question proceeds on the basis of steps to a contract or the legitimate interest of answering. Performance of an existing agreement proceeds on the basis of that agreement itself.

Compliance with a statutory duty, such as an obligation to keep tax books, proceeds on the legal obligation. Communication about a security incident proceeds on the protection of vital interests or on legitimate interest. Where someone has not yet decided and a basis is not otherwise clear, the office asks plainly for consent and never fakes consent by a pre-ticked box. Withdrawal of consent is simple and respected at once.

9. When information is shared

The general rule is stark: the office does not rent, sell or swap personal information to anyone for anyone else. Sharing happens only in a short list of events. It may happen to a processor that carries out an explicit task for the office under contract and confidentiality. It may happen to a public authority when the authority has demanded it in a lawful and specific way and the demand has been reviewed by the office.

It may happen when a person directs the office to hand the information onward, for example to a chosen subcontractor. It may happen in a corporate sale as part of an asset transfer, with the buyer bound to the same privacy promises. In every case the recipient receives the smallest slice needed for the purpose, nothing ornamental.

10. Service providers and processors

Being a technology office does not mean every byte lives on a machine owned by the office. Storage, mailing, metrics, payment and backup are carried by reputable processors chosen after a review of their own safeguards. The office signs data processing terms with each, and reserves the right to withdraw work from one that cannot show its duty of care.

A processor receives personal data only so it can run a described service. It must not mine that data for its own model, sell it or combine it with what it holds elsewhere. Where a processor is found to have drifted from the agreement, a winding-down plan is applied and records are pulled back before the relationship ends.

11. Privacy for Children

The site and the services of Stephenson Brian Head LLC are aimed at working adults who run or support a business. They are not built for children and do not hold entertainment, games, lessons or chat for children. The office makes no deliberate effort to collect information from a person under the age of thirteen.

If a school, a guardian or a child alerts the office that a record of a minor has reached the wrong drawer, the record is deleted after a reasonable verification that the age claim is genuine, and a short confirmation is offered to the adult who reported it. Because the property contains nothing to draw a child in, the chance of such a record is deliberately small.

12. Safeguards on the wire

Records are protected with measures suited to a professional office rather than a museum. Access to systems that hold personal data is limited to people whose job makes the access necessary, guarded by individual credentials and by a rule that privileges are removed when the job changes. Communication with the site and with the email gateway runs over encrypted connections.

Backups are taken on a schedule and are stored apart from the primary copies, with the restore path tested so a recovery is a procedure and not a prayer. Workstations are patched, accounts carry sensible phishing resistance, and vendor accounts are watched for the kind of quiet change that signals a compromise. No defence is perfect, which is why an honest incident response sits near the end of this page.

13. How long records are kept

A record is kept only as long as the purpose that justified it is still alive. A contact enquiry is kept until the exchange is answered and the matter is closed, then removed within a quarter. A signed engagement record is kept for the period the governing law insists on for business and tax books, then deleted. A log entry is tamed automatically and kept for a bounded window.

Choosing to keep less is safer than keeping too much, so the office leans toward shorter retention whenever the law allows. When an old record has no lawful keeper and no reason to stay, it is erased or, where erasure is not possible in a backup rotation, made inaccessible and overwritten on the next cycle. Note that a deletion request is honoured for future records but cannot unwrite a legal obligation to keep a ledger.

14. Your rights over your data

Within the limits set by law and by the security of other people, a person may ask for a copy of the personal records the office holds about them, may ask for an error to be corrected, may ask for a copy in a portable and readable form, and may ask for processing to be limited where its accuracy or lawfulness is in dispute. Each of these requests is answered honestly and in good time.

Verifying a person before releasing records matters, because handing a stranger the records of another person would itself be a breach. A lawful request from a person who can prove identity is honoured at no charge unless the requests are plainly repetitive or excessive. To raise a request, use the channel in the final section of this page and mark the subject line with the word request so the lane is not mistaken for sales mail.

15. State privacy notices

People in states with their own privacy laws, such as California, Colorado, Connecticut and Virginia, enjoy the extra protections those laws grant. The office collects no personal information for sale, does not sell personal information and does not deploy the kind of advertising profiles that the term sharing is meant to catch in those laws.

A resident who asks to opt out of any practice caught by their local law is told the plain truth: there is nothing to opt out of beyond the settings described above, because the offence the laws target is not part of the office business model. Authorised agents acting on clear written authority are treated with the same care as the resident and a verification step guards against abuse of an agent role.

16. Cross border transmissions

The office works from the United States and many of its processors hold records there or in other countries in which they lawfully operate. A person who lives outside those borders understands that the data they send may cross an international boundary as part of the normal working of the internet and of shared office tools.

Where a transfer crosses a border into a region that a protection law treats as different, the office applies whatever transfer mechanism the law accepts, such as model clauses or an adequacy finding, and documents the choice rather than hoping nobody looks. The aim is that the level of protection follows the record rather than the border.

18. Security incident alerts

An incident is a case where a record has plainly been read by someone with no right to read it. If such an event touches personal information, the office acts without delay: contain the path, preserve evidence, assess the reach and then notify the people whose records were involved together with any authority whose law requires a notice.

Notification explains what is known, what the office did and what affected people can watch for, such as a suspicious login or an odd invoice. Honest news beats comfortable silence. The office never withholds word of a breach to protect irritation, because a quiet office that swallows a breach is the swiftest way to lose the trust this station survives on.

19. Changes to this policy

Words on a page age. When the law or the office practice changes in a way that affects the meaning of this policy, the page is revised and the effective date at the top is moved forward. A material change, one that alters how data is handled rather than merely tidies a sentence, is announced through a visible notice on the site.

Continuing to use the site after a revision means a person accepts the updated wording from the date it stands. Any person who finds a change unwelcome may ask to have their standing preferences applied or their records removed under the terms above. The older version of this policy is kept available for comparison if the change is ever argued about.

20. How to reach the Privacy Desk

Questions, correction wishes, deletion requests and incident reports all land on the same open channel. Write to inquiry@stephensonbrian.buzz, call +16065865913, or post a letter to 3378 S Noble Dr, Washington — 84780-3195, United States (US). The operative desk answers inside one business day with a named person, not a department number.

If a person believes their records were handled wrongly, the first step is to raise it with the office so the point can be set right in good faith. Should the office fail to satisfy the concern, a resident of a law that grants appeal may complain to the authority named in that law. The office accepts that a complaint is not an insult but the proper final gear of a privacy culture that claims to care.