Privacy Policy
Effective July 16, 2026; last updated August 26, 2026
This Privacy Policy explains how Paul Nederhoed Consulting, LLC ("PNC," "we," "our," or "us") handles personal information through paulnederhoed.com, its resources, and its secure client portal (collectively, the "Services"). PNC is a Massachusetts limited liability company based in the Greater Boston area. PNC is the controller or business responsible for the personal information described here unless a contract states otherwise.
This policy describes practices and rights under applicable United States privacy laws, the EU General Data Protection Regulation ("EU GDPR"), and the United Kingdom GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (together, "UK data-protection law"). A particular law applies only when its jurisdictional and other requirements are met.
Privacy at a glance
- We do not sell personal information or use it for targeted advertising.
- We do not use third-party analytics, heatmaps, session recording, or advertising pixels.
- Our public pages do not intentionally set cookies. The client portal uses one essential, secure session cookie to keep signed-in users authenticated.
- Calendly, LinkedIn, and the OpenAI interview assistant are external links. Those services do not receive information from this website unless you choose to visit them.
- Checklist entries stay in your browser until you choose “Send Report” to create a private report link, or copy, print, or save your responses. Creating a link stores an encrypted report for 30 days.
1. Information we collect
Public website and communications
- Messages you send: your name, email address, organization, and anything you include when you contact us.
- Scheduling: if you follow our Calendly link, Calendly collects the information you enter and shares the appointment details with us so we can hold the meeting.
- Interactive checklists: “Email Paul” opens a local review panel. Choosing “Send Report” uploads a snapshot to our hosting server, where it is encrypted and made available through an unguessable link for 30 days. Anyone who has the link can view or permanently delete the report; it does not require a login. The link opens a report, not a verified assessment. Avoid confidential, regulated, or sensitive personal information. Your own email application sends the message to Paul only when you choose Send; the website does not send checklist emails or verify the sender's identity. Creating a link stores the report even if you do not send the email. You may instead copy a no-private-link plain-text version and paste it directly into an email. Copying places text on your device’s clipboard, which may sync according to your settings. Printing or saving as PDF is handled by your browser.
- Report abuse prevention: the private-link service temporarily records request times and keyed hashes of network addresses for rate limiting; it does not retain raw addresses in that rate-limit record. Hosting access logs may separately include network addresses. Report-link access tokens are passed in URL fragments and request bodies rather than normal URL request logs.
- Basic server logs: our hosting infrastructure may record an IP address, timestamp, requested page or file, browser or user-agent information, and referring page for security, troubleshooting, and reliable delivery.
Secure client portal
For clients and administrators, we may process:
- Account and profile information, including name, business email, organization, job title, and phone number.
- Engagement information, including projects, updates, documents, invoice records, and secure issue conversations between a client and PNC. The portal does not collect or process payment-card details.
- Security information, including password hashes, one-time token hashes, sign-in attempts, IP addresses, browser information, session records, and an administrative audit log.
2. How we use information
We use information as reasonably necessary to:
- Respond to inquiries, schedule meetings, and provide consulting services.
- Create and administer client accounts, projects, documents, invoices, and secure client-support issues; send related service notifications to the client and PNC.
- Authenticate users, send invitations and password resets, prevent abuse, investigate problems, and maintain the security of the Services.
- Maintain business and financial records, enforce agreements, protect legal rights, and meet applicable legal obligations.
Where EU or UK data-protection law requires a legal basis, we rely on: contract or requested pre-contract steps to provide services; legitimate interests to respond to business inquiries, administer and secure the Services, maintain records, and protect legal rights; legal obligations for tax, accounting, security, and lawful requests; and consent where we specifically request it. We consider whether our legitimate interests are necessary and appropriately balanced against the individual's rights. Consent may be withdrawn at any time without affecting earlier lawful use.
PNC normally acts as controller for website, inquiry, account, security, billing, and client- relationship information. If PNC processes personal information solely on a client's documented instructions while delivering consulting services, the client may be the controller and PNC may act as its processor or service provider. In that situation, the applicable services agreement or data-processing terms also govern the processing.
3. Cookies and tracking
The public website does not use advertising or analytics cookies. The client portal uses an
essential cookie named pnc_sid to maintain a secure session. It is configured with
Secure, HttpOnly, and SameSite=Lax protections. Disabling this cookie will prevent the portal from
working. We do not use portal cookies for advertising or cross-site tracking.
4. When we disclose information
We may disclose information only as described below:
- Hosting and email: Hosting.com provides the website, database, storage, and system-email infrastructure used to operate the Services.
- Scheduling: Calendly processes information after you choose its scheduling link. It provides appointment information to us.
- Professional support: accountants, attorneys, insurers, or technical providers may receive information when necessary and subject to appropriate confidentiality duties.
- Legal and safety reasons: we may disclose information when reasonably necessary to comply with law, legal process, or a valid government request; enforce agreements; or protect rights, safety, and security.
- Business changes: information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of all or part of the business, subject to applicable law.
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
5. External services and links
The public website contains ordinary links to external services. Their privacy practices apply once you leave our website. Review the policies for Calendly, OpenAI, and LinkedIn before providing information to them.
6. Retention
We retain information only as long as reasonably necessary for the purposes described here, including providing services, maintaining business records, resolving disputes, securing the Services, and meeting legal, accounting, or tax requirements. In particular:
- You can permanently delete a checklist report from its link page. This removes the live report and disables its link for everyone; an irreversible hash-only revocation marker is retained to prevent retries from restoring that link. Otherwise, private checklist links expire after 30 days. Expired reports are deleted by daily maintenance (normally within 24 hours after expiry) or when the service next creates a report. Report rate-limit records expire after 24 hours and are removed during creation or daily maintenance. Copies you or Paul save, send, print, or receive by email are separate records and do not expire with the link.
- Client accounts, engagement records, documents, invoices, and issue conversations are generally kept for the engagement and any appropriate business or legal retention period.
- Invitation links expire after 72 hours, password-reset links after 60 minutes, and administrator verification codes after 10 minutes.
- The portal's routine maintenance removes expired or used security tokens after seven days and sign-in/rate-limit events after two days. Administrative audit records are normally retained for two years, subject to a minimum 90-day security period and any legal need.
- Deleted information may remain in protected backups until overwritten through the ordinary backup cycle.
7. Security
We use reasonable administrative and technical safeguards appropriate to a small consulting business. These include HTTPS, access controls, password hashing, hashed and expiring security tokens, restricted private document storage outside the public website, secure session settings, administrator verification, and security logging. These safeguards are designed to protect personal information consistently with applicable requirements, including Massachusetts requirements where they apply. No Internet transmission or storage system is completely secure, so absolute security cannot be guaranteed.
The portal is intended for ordinary consulting and business records. Do not upload payment-card details, account passwords, Social Security numbers, protected health information, export-controlled data, or other specially regulated information unless we have agreed in writing to appropriate handling requirements.
8. International processing and transfers
PNC is based in Massachusetts, and the Services are hosted and administered in the United States. If you access the Services from the European Economic Area ("EEA"), United Kingdom, or another country, personal information may be transferred to and processed in the United States, where laws may differ from those in your location.
Hosting.com states that it participates in the EU-US Data Privacy Framework and provides data processing terms for its hosting services. When EU or UK transfer restrictions otherwise require a transfer mechanism, we use one appropriate to the transfer, such as an applicable adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another mechanism permitted by law. Contact us to request information about safeguards applicable to a particular transfer.
9. Your choices and privacy rights
Depending on applicable law and where you live, you may have rights to:
- know whether and how we process personal information and obtain access to it;
- correct inaccurate or incomplete information;
- request deletion or restriction of processing, subject to lawful exceptions;
- receive certain information in a portable format;
- object to processing based on legitimate interests or for direct marketing;
- withdraw consent where processing relies on consent; and
- appeal a denied request where applicable state law provides that right.
We do not use personal information for solely automated decisions that produce legal or similarly significant effects. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We do not use sensitive personal information to infer characteristics. Accordingly, an opt-out signal such as Global Privacy Control does not change these practices.
To exercise a right, email Paul@PaulNederhoed.com. Describe your request and the email address or account involved. We may verify identity and authority before responding. An authorized agent may submit a request where permitted, but we may require proof of authorization. Rights are not absolute and may be limited by contract, legal privilege, security, tax, accounting, record-retention, or other lawful exceptions. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
10. Regional information
United States
United States privacy rights vary by state. The categories collected, sources, purposes, recipients, and retention criteria are described in Sections 1, 2, 4, and 6. These may include identifiers and contact details, professional information, commercial and engagement records, Internet or device activity used for security, communications, portal credentials, and client-provided documents. We collect information directly from individuals and clients, automatically through basic hosting and security functions, and from service providers involved in scheduling or communications. We honor verified requests as required by applicable state law, including California law when it applies. California residents can review the California Attorney General's CCPA information.
EEA and United Kingdom
PNC has no establishment in the EEA or United Kingdom but may provide services to business customers there. If the EU GDPR or UK data-protection law applies, PNC normally acts as controller for the website, inquiry, account, security, billing, and client-relationship processing described in this policy, and may act as a processor for client-directed processing as described in Section 2. The purposes, categories, legal bases, recipients, retention criteria, and transfer information are stated above.
PNC has not appointed an EEA or UK representative because its current processing connected with individuals there is occasional, does not include large-scale processing of special-category or criminal-offence data, and is not expected to create a risk to individuals' rights and freedoms that would make the representative exemptions unavailable. PNC will reassess this position and appoint a representative if its processing changes or applicable law requires one.
You may exercise applicable rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also submit a privacy complaint to PNC using the email address below. Where UK data-protection law applies, PNC will acknowledge a complaint within 30 days, investigate it without undue delay, and communicate the outcome. You also may lodge a complaint with the data-protection authority where you live or work. The European Commission provides an overview of EU GDPR rights. In the UK, the supervisory authority is the Information Commissioner's Office. EEA authorities are listed by the European Data Protection Board.
11. Children's privacy
The Services are business services and are not directed to people under 18. We do not knowingly collect personal information from children. We do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
12. Changes to this policy
We may update this policy when our practices, services, or legal obligations change. We will post the revised policy here and update the date above. If a change materially affects how we handle existing client information, we will provide additional notice when appropriate.
13. Contact us
Contact us with privacy questions, requests, objections, or concerns:
Paul Nederhoed Consulting, LLC
Greater Boston, Massachusetts, United States
Email: Paul@PaulNederhoed.com