Privacy Policy
Top Floor Security, LLC
Effective Date: March 26, 2026 · Last Updated: August 24, 2026
1. Introduction
Top Floor Security, LLC ("TFS," "we," "us," or "our") is a boutique governance, risk, and compliance (GRC) consulting firm. This Privacy Policy describes how we collect, use, disclose, and protect personal information through our website at topfloorsecurity.com (the "Site") and related services.
By using the Site or our services, you agree to the practices described in this policy. If you do not agree, please discontinue use of the Site.
2. Information We Collect
2.1 Information You Provide Directly
- Contact Form Submissions: Name, email address, phone number (if provided), company name, and the content of your message.
- Email Notification Signup: Email address and, optionally, your name and company (notification list for upcoming content).
- Tool, Template, and Help Widget Submissions: When you use the budget planner, the readiness assessment, a compliance template request, the monthly compliance digest signup, or the help widget, we collect your email address and, where that surface asks for them, your name and company, together with what you told the tool: the answers and selections you made, the estimate or score we calculated from them and whether we emailed you the resulting report, the template you requested, the digest month you chose, or the topic you were browsing in the help widget. Contact form and notification signup entries are stored in this same lead record as well, so an inquiry exists somewhere other than an email to us.
- Emergency Intake Form: When you report an active security incident through our emergency page, we collect your name, email address, phone number (if provided), company name, and the incident description you write, which the form accepts up to 5,000 characters. That description is free text and may contain sensitive details about your environment or an ongoing breach; please share only what is necessary to get you help. We also store the page you submitted from and a one-time acknowledgement token used to confirm a responder picked up the request.
- Service Engagements: When you engage our services, we collect your name, email address, company affiliation, and any information you provide in connection with the engagement.
Most of our web forms (the contact form, the help widget, and the notification signup) require a business email address, and submissions from free email providers (e.g., Gmail, Yahoo, Outlook.com) are not accepted. This restriction helps us maintain the quality of our business communications and is not used for any other purpose. The Emergency Intake Form is the deliberate exception: it accepts any deliverable email address, because someone reporting an active incident may not have access to their corporate mail.
2.2 Information Collected Automatically
When you visit the Site, we automatically collect certain technical information, including:
- Analytics Data: Pages visited, referring URLs, session duration, general geographic region (city/country level), device type, browser type, and operating system.
- Campaign Attribution Attached to Submissions: When you submit the contact form, the notification signup, the compliance digest signup, a template request, the budget planner, the readiness assessment, or the help widget, we store on the same record as the details you submitted (your email address and, where that surface collected them, your name and company): the page you submitted from, any utm_source, utm_medium, and utm_campaign values carried in that page's address (the tags added to a link in an email, an advertisement, or a social post), and the referring URL your browser reports, which names the site or search page you arrived from. We record this so we can tell which campaign, page, or referral produced an inquiry; because it sits on the same record, that attribution is tied to you as an identified person rather than counted anonymously. Each field is stored only when it is actually present, and nothing is substituted when one is missing. The emergency intake form is the exception: it records the page you submitted from and nothing further about how you arrived.
- Server Logs: IP address, request timestamps, and HTTP headers. These logs are retained for security monitoring and are purged on a rolling basis.
- Abuse-Prevention Hashes: When you submit the contact form or the emergency intake form, we compute a salted, irreversible SHA-256 hash of your IP address and store that hash so we can rate limit submissions from the same source. We do not store the address itself, and the hash cannot be reversed back to it.
- Cookies and Similar Technologies: See Section 5 below.
2.3 Information from Third Parties
We may receive information about you from publicly available sources, referral partners, or your employer or organization when they engage us for services on your behalf.
3. How We Use Your Information
- Service Delivery: To respond to inquiries, onboard clients, and deliver consulting engagements.
- Communications: To send you requested information, engagement updates, invoices, and, if you have opted in, our email notifications.
- Site Operations and Improvement: To monitor Site performance, analyze usage patterns, troubleshoot issues, and improve user experience.
- Security: To detect, prevent, and respond to fraud, unauthorized access, and other security incidents.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following limited circumstances:
- Service Providers: With third-party vendors who perform services on our behalf, subject to contractual obligations to protect your data.
- Professional Obligations: Where required in connection with a client engagement, with appropriate confidentiality protections in place.
- Legal Requirements: When disclosure is required by law, regulation, subpoena, court order, or other legal process.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets.
- With Your Consent: In any other circumstance where you have provided explicit consent.
Our current service providers include: Supabase (database hosting and backend functions), Resend (transactional email delivery), Google (analytics, after you consent), LinkedIn (advertising measurement and audience matching, after you consent), and Cloudflare (website hosting and content delivery). We review the security practices of our service providers and require contractual data protection commitments.
Enterprise clients requiring a Data Processing Agreement (DPA) may request one by contacting info@topfloorsecurity.com.
5. Cookies and Tracking Technologies
5.1 Cookies We Use
Top Floor's own code sets no cookies. It is a static site with no user accounts and no sign-in, so there is no session to maintain and no authentication token to store. The only cookies that can appear are set by the third-party services listed below, and only after you consent to them. Your own preferences (your cookie choice, display theme, language, and dismissed banners) are kept in your browser's local and session storage, which is described in our Cookie Policy.
| Category | Purpose | Examples |
|---|---|---|
| Strictly Necessary | None. No cookie is required for the Site to work | No first-party cookies are set |
| Analytics | Understanding Site usage and performance (loaded only with your consent) | Google Analytics (_ga, _ga_<container id>) |
| Advertising | Measuring LinkedIn campaign conversions and reaching Site visitors on LinkedIn (loaded only with your consent; Global Privacy Control honored) | LinkedIn Insight Tag (li_fat_id, ln_or) |
| Privacy-Friendly Analytics | Aggregate, cookieless usage metrics | Plausible (sets no cookies and stores nothing on your device when it is enabled) |
5.2 Managing Cookies
When you first visit the Site, a cookie consent banner allows you to accept or reject non-essential cookies. Nothing is loaded until you choose. Your preference is stored in your browser's local storage and respected on subsequent visits.
You can change or withdraw your choice at any time using the "Cookie settings" link in the page footer, which reopens the banner. Rejecting also removes the first-party analytics and advertising cookies set during any earlier visit. You can control cookies through your browser settings as well; because the Site sets none of its own, blocking cookies does not affect how it works.
5.3 Do Not Track
We honor Global Privacy Control (GPC) signals: when your browser sends one, we treat it as an opt-out of advertising cookies regardless of any stored banner preference. We do not act on the older, unmaintained "Do Not Track" header, which conveys no comparable legal signal. You can also manage your cookie preferences at any time through our consent banner.
6. Data Retention
- Contact form submissions: Retained for up to 24 months, then deleted automatically. Deleted sooner on request.
- Emergency intake requests: Retained for up to 24 months, then deleted automatically, because an incident record may be needed for follow-up or evidentiary purposes. Deleted sooner on request unless we are required to keep it.
- Tool and resource submissions: Retained for up to 24 months, then deleted automatically. This covers the details you give us through the budget planner, the readiness assessment, a template request, a newsletter or digest request, or the help widget, together with the answers you selected, the page you were on, and the attribution described in Section 2.2 (any utm_source, utm_medium, and utm_campaign tags in that page's address, and the referring URL your browser reported). Those attribution fields are columns on the same record, so they are deleted with it and never outlive it. A contact form or notification signup entry is stored in this record as well, on the same 24 month window. Deleted sooner on request.
- Email delivery logs: Retained for up to 12 months for deliverability and abuse monitoring.
- Unsubscribe tokens: Retained for up to 24 months, and for as long as an address remains suppressed so that unsubscribe links in mail already sent keep working.
- Abuse-prevention records: We store a salted, irreversible hash of the IP address that submits a form, never the address itself, and prune these within 24 hours (emergency intake) or 12 months (email logs).
- Automated test records: Contact form submissions created by our own end-to-end tests are marked [E2E] and deleted within 7 days rather than kept for the full 24 months. They contain no personal information belonging to a visitor.
- Client engagement data: Retained for the duration of the engagement and for a minimum of seven (7) years thereafter.
- Analytics data: Retained per configured retention settings (default: 14 months).
- Server logs: Retained for up to 90 days, unless extended for an active security investigation.
7. Data Security
We implement administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, or destruction. These include encryption in transit (TLS), hashed credential storage, role-based access controls, and regular security reviews.
No method of transmission or storage is 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
In the event of a data breach involving your personal information, we will notify affected individuals and applicable regulatory authorities in accordance with applicable law, including GDPR Article 33/34 timelines where applicable.
8. Your Privacy Rights
8.1 General Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information, subject to legal and contractual exceptions.
- Opt out of marketing communications at any time.
- Withdraw consent where processing is based on consent.
We will respond to verified data subject access requests within 30 days (GDPR) or 45 days (CCPA/CPRA). If additional time is needed, we will notify you of the extension and the reasons.
8.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know: You may request the categories and specific pieces of personal information we have collected.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale/Sharing: We never sell your personal information for money. We do "share" it in the CCPA/CPRA sense when, and only when, you consent to advertising cookies: our LinkedIn tag then allows LinkedIn to measure campaigns and match audiences, which counts as cross-context behavioral advertising. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our footer, which reopens your cookie choices, or by rejecting advertising cookies in the banner. We also honor Global Privacy Control signals automatically.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
We do not sell personal information for monetary consideration. We do engage in "sharing" as the CCPA/CPRA defines it, limited to the consented LinkedIn advertising cookies described in our Cookie Policy. No advertising or analytics cookie is set before you consent, a Global Privacy Control signal is treated as an opt-out on its own, and the "Do Not Sell or Share My Personal Information" link in our footer lets you withdraw consent at any time.
8.3 Other U.S. State Privacy Laws
Residents of states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out. Contact us to exercise these rights.
8.4 European Economic Area and United Kingdom (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) provides you with additional rights regarding your personal data. Top Floor Security, LLC acts as the data controller for personal information collected through the Site and our services.
Lawful Bases for Processing: We process your personal data on the following lawful bases:
- Legitimate Interests: Service delivery, Site operations, security monitoring, and business development, where these interests are not overridden by your data protection rights.
- Consent: Email notification subscriptions and non-essential cookies, which you may withdraw at any time.
- Contractual Necessity: Processing required to fulfill client engagements and service agreements.
Your Rights as an EU/UK Data Subject: You have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete personal data.
- Erasure of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Restriction of processing in certain circumstances.
- Data portability, receiving your data in a structured, commonly used, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable law.
Cross-Border Data Transfers: Your personal data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for personal data transferred outside the EEA or UK.
EEA and UK Representative: Top Floor Security, LLC is established in the United States and has not appointed a representative in the EEA under Article 27 of the GDPR or in the UK under Article 27 of the UK GDPR. Our processing of personal data relating to individuals in the EEA and UK is occasional, does not include large-scale processing of special categories of data or of data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons, so we rely on the exemption in Article 27(2)(a). If the nature of our processing changes such that this exemption no longer applies, we will appoint a representative and name them here. You may exercise any of the rights described in this section by contacting us directly at the address in Section 12.
9. Children's Privacy
The Site and our services are not directed to individuals under the age of 16. We use 16 as a single worldwide threshold because it is at or above every age of consent applicable to us: the GDPR permits EEA member states to set the age for a child's own consent to information society services anywhere from 13 to 16, the UK GDPR sets it at 13, and the U.S. COPPA statute (15 U.S.C. 6501) protects children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will promptly delete it.
10. Third-Party Links
The Site may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last Updated" date at the top of this page. Continued use of the Site after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint, please contact us at:
Top Floor Security, LLC
30 N Gould St, Ste N, Sheridan, WY 82801, USA
Email: info@topfloorsecurity.com
Website: topfloorsecurity.com
Revision History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.7 | August 24, 2026 | Added the EEA and UK Representative statement to Section 8.4: no Article 27 representative is appointed, stating the Article 27(2)(a) exemption relied on and the commitment to appoint and name one if the exemption ceases to apply. Recorded in Section 9 why 16 is the children's age threshold: it sits at or above the GDPR age-of-consent range (13 to 16), the UK GDPR age (13), and the COPPA under-13 threshold. |
| 1.6 | August 22, 2026 | Disclosed the lead record that every conversion surface writes to. Section 2.1 previously named only the contact form, the notification signup, the emergency intake form, and service engagements, so the budget planner, the readiness assessment, template requests, the compliance digest, and the help widget collected an email address, a name, a company, and the visitor's tool answers with no entry in this notice at all. Section 2.2 now also names the attribution stored on that same record (the submitting page, the utm_source, utm_medium, and utm_campaign tags, and the referring URL), which ties campaign data to an identified person and appeared nowhere in the previous version. Retention already deleted these records at 24 months; that entry now names the attribution fields deleted with them. |
| 1.5 | August 14, 2026 | Corrected Section 5 to state that the Site sets no first-party cookies: the strictly necessary row previously described session cookies and CSRF tokens that do not exist, since there are no user accounts and no sign-in. Pointed the opt-out at the footer "Cookie settings" link rather than at clearing browser storage. Disclosed the salted IP hash used for abuse prevention under Information We Collect, not only under Retention. Named the 5,000 character limit and the submitting page recorded by the emergency intake form. Added the 7 day window for records our own automated tests create. |
| 1.4 | August 3, 2026 | Corrected the named email delivery processor to Resend. Disclosed the emergency intake form: what it collects (incident narrative, contact details, acknowledgement tokens, salted IP hashes), why, and how long it is kept. Added retention windows for every table. Added Global Privacy Control handling and CPRA "sharing" language for cross-context behavioral advertising, with the corresponding opt-out. |
| 1.3 | July 17, 2026 | Added the LinkedIn Insight Tag to the third-party processor list. |
| 1.2 | March 26, 2026 | Removed EU-U.S. Data Privacy Framework reference; cross-border transfers now rely on SCCs only. Clarified newsletter references as email notification list. |
| 1.1 | March 26, 2026 | Added GDPR data subject rights, data breach notification, cookie consent banner reference, third-party processor list, DPA availability. |
| 1.0 | March 26, 2026 | Initial publication |