Effective Date: August 14, 2026 · Last Revised: September 9, 2026
This Corporate Privacy Policy and Data Protection Disclosure (hereinafter designated as “the Privacy Policy” or “this Policy”) governs the personal data processing activities executed by Legacy Training & Consulting (hereinafter designated as “the Company”) on its website, specifically regarding information collected through the website’s digital interfaces, including but not limited to the “Contact Us” communication portal.
The Company acts as the Data Controller (or “Covered Entity” under applicable state regulations) and is committed to protecting the privacy, confidentiality, and security of its Users, Clients, and Data Subjects. This Policy has been harmonized to align with the Florida Information Protection Act of 2014 (FIPA), the Florida Digital Bill of Rights (FDBR), and the European Union’s General Data Protection Regulation (GDPR).
1. Identification of the Data Controller and Contact Structure
The personal data processing activities governed by this Policy are executed by:
Any natural person whose personal data is processed by the Company (hereinafter designated as “the Data Subject” or “the User”) may address inquiries, data rights requests, or compliance-related concerns directly to the Company’s Compliance Director via the email or telephone contact provided above.
2. Categories of Personal Data Collected
The Company limits the collection of personal data to information that is adequate, relevant, and reasonably necessary to fulfill the commercial and operational purposes disclosed within this Policy, satisfying the core principles of data minimization. The personal data collected through the “Contact Us” page and digital website operations include:
A. Direct Personal Identifiers (Voluntarily Provided)
- Full Names (First Name and Last Name)
- Electronic Mail Addresses (Personal and/or Corporate)
- Telephone Numbers
- Company/Employer Name
- Inquiry and Message Data: Any textual descriptions, business training requirements, or miscellaneous comments voluntarily inputted by the User into the open text fields of the contact form.
B. Technical and Electronic Identifiers (Automatically Collected)
- Internet Protocol (IP) Addresses
- Browser and Device Characteristics: Browser type, version, operating system, and unique device identifiers.
- Usage and Navigation Behavior: Date and timestamp of the connection, referring uniform resource locators (URLs), search queries within the Company’s web interface, and automated diagnostic logging compiled during site interaction.
- Cookies and Tracking Technologies: Small text files and similar tracking technologies (including tracking pixels) placed on the User’s device to support standard site navigation, personalize content, and compile statistical analytics. This includes Google Analytics (measuring site traffic and usage) and the Meta (Facebook) Pixel (measuring the effectiveness of the Company’s Facebook/Instagram advertising and how visitors arriving from those ads use the website). These tools may share technical and usage data — such as pages viewed, device/browser information, and IP address — with Google and Meta respectively, for these measurement and advertising purposes.
C. Sensitive Personal and Special Category Data (Universal Exclusion)
In strict compliance with GDPR Article 9 and Florida Statutes Section 501.715, the Company does not actively process biometric records, genetic data, precise geolocation data (identifying a physical location within a radius of 1,750 feet or less), or information revealing racial or ethnic origin, religious or philosophical beliefs, sexual orientation, or physical or mental health diagnoses. The Company’s website is not intended for the collection of sensitive data, and Users are instructed not to submit such information through the “Contact Us” interface.
3. Lawful Bases and Purposes of Processing
To satisfy regulatory standards (including GDPR Article 6), the Company executes all personal data processing activities under one or more of the following established lawful bases:
- Consent: The User provides explicit, unambiguous consent when voluntarily submitting their contact details and inquiry details through the “Contact Us” form, allowing the Company to contact them and respond to their request.
- Contractual Necessity: Processing is required to execute the terms of a written contract, deliver requested training or consulting services, establish client accounts, or process standard business transactions.
- Legal Obligation: Processing is mandatory to comply with statutory duties, including corporate tax reporting, regulatory disclosures, or responding to lawful warrants or subpoenas.
- Legitimate Interests: Processing supports the Company’s legitimate business operations, specifically maintaining network security, preventing fraud or malicious activities, optimizing website performance, and conducting direct business-to-business communications, provided these activities do not override the fundamental rights of the Data Subject.
4. Data Sharing and Third-Party Disclosures
The Company maintains strict limits on data sharing. The Company does not sell personal data to third parties for monetary or other valuable consideration. Third-party disclosures are limited to:
- Service Providers (Data Processors): The Company may share limited personal identifiers with trusted third-party vendors, subcontractors, or cloud-hosting providers (such as website hosts, customer relationship management (CRM) facilitators, and email delivery platforms) acting as Data Processors. These Processors operate under strict contractual Data Processing Agreements (DPAs) requiring full compliance with applicable state and federal laws, maintaining duties of confidentiality, and implementing measures to secure the data.
- Judicial and Statutory Disclosures: The Company will disclose personal data to law enforcement agencies, judicial tribunals, or regulatory bodies when mandated by federal, state, or international laws, rules, or valid warrants.
- Business Transfers: In the event of a corporate merger, acquisition, or sale of assets, personal data may be transferred as a business asset, subject to standard confidentiality obligations.
- Analytics and Advertising Technology Providers: The Company uses third-party analytics and advertising-measurement tools — currently Google Analytics and the Meta (Facebook) Pixel — that automatically collect technical and usage data (such as pages visited, device/browser information, and IP address) via cookies and similar technologies. This data is used to measure website traffic and the performance of the Company’s advertising, and may be used by Google or Meta to inform future ad delivery. The Company does not sell this data for monetary or other valuable consideration; it is shared only for these measurement and advertising purposes.
5. Data Retention and Secure Disposal
The Company retains personal data only for the duration necessary to satisfy the specific purposes of collection, deliver training or consulting services, resolve legal disputes, or comply with statutory retention laws.
In strict accordance with the Florida Information Protection Act (FIPA) (Fla. Stat. § 501.171(8)), the Company enforces precise protocols for the secure disposal of personal records:
- Physical records containing personal identifiers are permanently destroyed using industrial shredding technologies.
- Electronic and digital files containing personal information are permanently deleted, overwritten, or de-identified using industry-standard digital sanitation technologies to render the data unreadable and undecipherable.
The Company’s default retention schedule prohibits the use or retention of personal data beyond a three-year period following the User’s last active interaction with the Company, unless a longer retention period is mandated by state or federal statutory retention laws.
6. Statutory Disclosures Under the Florida Digital Bill of Rights (FDBR)
- Corporate Position on Revenue Thresholds: While the Company is a for-profit commercial entity operating in the State of Florida, its global gross annual revenues are substantially below the $1 billion threshold established by the FDBR (Fla. Stat. § 501.702(9)) to qualify as a covered “controller” subject to the law’s broader administrative mandates.
- Universal Consent Mandate Under FDBR Section 501.715: Regardless of revenue size, the Company is legally bound by Florida’s universal prohibition on the sale of sensitive personal data.
- Notice of Non-Sale of Sensitive Data: In compliance with Fla. Stat. § 501.715, the Company declares that it does not sell sensitive personal data, genetic data, or biometric personal data to third parties. Consequently, the statutory website notices mandated by Fla. Stat. § 501.711(2) and Fla. Stat. § 501.715(2) (specifically, “NOTICE: This website may sell your sensitive personal data” and “NOTICE: This website may sell your biometric personal data”) are not displayed on the Company’s web domain. Any future modification to this posture will require immediate policy revision and the visible implementation of these notices.
7. Incident Response and Breach Notification
The Company has implemented a formal Incident Response Plan to identify, contain, and mitigate potential cybersecurity incidents. In the event of a confirmed or reasonably suspected security breach compromising unencrypted personal information (including name paired with email address, financial details, or other personal identifiers), the Company will execute notifications in strict compliance with FIPA (Fla. Stat. § 501.171) and GDPR Article 33:
- Notice to Affected Florida Residents: The Company will deliver written or electronic notification to all affected Florida residents whose personal information was accessed as expeditiously as possible and no later than thirty (30) days after determining a breach occurred. The notice will contain a plain-language synopsis of the incident, the categories of data compromised, remedial steps taken by the Company, corporate contact information, and contact details for nationwide consumer reporting agencies.
- Notice to the Florida Attorney General (Department of Legal Affairs): If a single security incident affects five hundred (500) or more Florida residents, the Company will notify the Department of Legal Affairs electronically within the same thirty (30) day window. A 15-day extension may be requested in writing only if good cause for delay is shown within the initial 30 days.
- Notice to Consumer Reporting Agencies: If a single breach affects one thousand (1,000) or more individuals, the Company will notify all nationwide consumer credit reporting agencies of the breach.
- Notice to European Supervisory Authorities (GDPR): In the event of a personal data breach impacting natural persons physically located in the EEA, the Company will notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the incident, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
8. Data Subject Rights and Appeal Protocols
The Company recognizes and honors the privacy rights of its Users. Natural persons residing within the State of Florida (under FIPA) or located in the EEA/UK (under the GDPR) are granted specific rights regarding their personal data, which can be exercised free of charge:
- The Right to Access & Portability: The right to confirm whether the Company is processing personal data and to receive a portable, structured, and machine-readable copy of the personal data held about the User.
- The Right to Rectification (Correction): The right to request the immediate correction of inaccurate or incomplete personal data.
- The Right to Erasure (Deletion / Right to be Forgotten): The right to request the permanent deletion of personal data under defined legal conditions (e.g., when the original purpose of collection is satisfied or consent is withdrawn), subject to statutory record-retention duties.
- The Right to Object & Restrict Processing: The right to object to processing based on legitimate interests or direct business-to-business communications, and to restrict processing operations under certain legal scenarios.
- The Right to Withdraw Consent: The right to withdraw consent for data processing at any time, without affecting the lawfulness of processing executed prior to the withdrawal.
How to Submit a Request
Data Subjects may submit a verified data rights request to the Company’s compliance contact at maria@legacytrainingconsulting.com or via the contact form on our website. The Company will utilize commercially reasonable measures to authenticate the identity of the requester prior to disclosing or deleting any data.
Response Timelines and Appeal Protocols
- Response Window: The Company will respond to verified Data Subject requests within thirty (30) days of receipt under GDPR standards, or without undue delay and no later than forty-five (45) days under FIPA standards.
- Right to Appeal: If the Company declines to act upon a validated privacy request, the Data Subject has the right to initiate a formal appeal. The appeal must be submitted within thirty (30) days of receiving the denial. The Company will review the appeal and deliver a final, written determination within sixty (60) days of receipt, detailing the reasons and justification for the decision.
- Right to Complain: Users retain the right to file a formal complaint regarding the Company’s processing activities directly with the Florida Department of Legal Affairs (Attorney General’s Office) or their local European Data Protection Authority (DPA).
9. Children’s Privacy Safeguards
The Company’s website and consulting/training services are directed exclusively to adults and professional enterprises. In compliance with the Children’s Online Privacy Protection Act (COPPA) and the Children’s Online Safety provisions of the FDBR, the Company does not knowingly collect, process, or sell the personal data of minors. Under the FDBR, a “child” is defined as any individual under eighteen (18) years of age. If the Company becomes aware that personal data of a child has been inadvertently collected through the “Contact Us” page, it will take immediate steps to permanently delete the records. Parents or guardians who believe a minor has submitted personal information may contact the Company’s compliance contact to request immediate deletion.
10. Do Not Track (DNT) and Browser Privacy Controls
The Company’s own website scripts honor browser-level Do Not Track (DNT) signals and Global Privacy Controls (GPC) where technically feasible. Third-party analytics and advertising tools used on the website — currently Google Analytics and the Meta (Facebook) Pixel — are operated by those providers under their own privacy practices and may not independently respond to DNT/GPC browser signals. Users who wish to limit this tracking can do so through their browser’s cookie and tracking-protection settings, ad-blocking extensions, or the opt-out tools each provider offers directly (e.g., Google Analytics’ opt-out, Meta’s Ad Preferences).
11. Policy Amendments and Updates
The Company reserves the right to revise this Privacy Policy at any time to reflect modifications in data-handling practices or changes in state, federal, or international laws. The “Last Revised” date at the top of this Policy will indicate when the latest modifications were applied. The Company recommends that Users review this Policy periodically to stay informed of how their data is protected.
12. Legal Disclaimer
The information provided on this website, and the submission of inquiries via the “Contact Us” form, does not establish an attorney-client relationship, a formal fiduciary partnership, or a contractually binding consulting agreement between Legacy Training & Consulting and the User. A contract is established only upon the formal execution of a written Master Services Agreement or statement of work.