East Sky MSP ("East Sky MSP," "we," "us," or "our") provides managed IT, cybersecurity, cloud, network, and business voice services to companies in the Dallas Fort Worth area and across the United States.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what choices you have. It applies to:
This policy does not govern personal information that we process on behalf of our business clients when we deliver services to them. That information is covered in Section 9 below and is governed by our written agreement with the client, not by this policy.
We do not store full payment card numbers on our systems. Card payments are processed by a third party payment processor that maintains its own PCI DSS compliance.
When you visit our website we automatically collect:
We do not intentionally collect sensitive personal data through our website or marketing. Sensitive personal data includes racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, citizenship or immigration status, genetic or biometric data, and precise geolocation.
We do not sell your sensitive personal data. We do not sell your biometric data.
If you volunteer sensitive information to us in a support ticket or email, we process it only as needed to respond to you.
We use personal information for the following purposes:
To deliver and support our services. Provisioning accounts, responding to tickets, dispatching technicians, monitoring devices, managing endpoints, restoring backups, and resolving incidents.
To communicate with you. Answering inquiries, sending service notifications, maintenance windows, security advisories, incident notices, and scheduling confirmations.
To bill and administer accounts. Generating invoices, collecting payment, and maintaining accounting records.
To secure our systems and yours. Detecting and investigating suspicious activity, authenticating users, preventing fraud, and enforcing our terms.
To improve our services. Analyzing aggregate usage patterns, measuring website performance, and developing new offerings.
To market our services. Sending relevant content about managed IT and cybersecurity to business contacts. Every marketing email includes an unsubscribe link.
To evaluate job applicants. Reviewing applications, conducting interviews, and completing lawful pre employment screening.
To meet legal obligations. Responding to lawful requests, complying with tax and recordkeeping requirements, and establishing or defending legal claims.
Our website uses cookies and similar technologies in the following categories:
Strictly necessary cookies. Required for the site to function. These handle session state, load balancing, and security features such as bot detection. These cannot be disabled through our site.
Analytics cookies. Help us understand how visitors find and use the site so we can improve it. These record pages viewed, session duration, and traffic sources in aggregate.
Functional cookies. Remember preferences such as form entries and display settings.
You can control cookies through your browser settings. Most browsers let you refuse new cookies, delete existing cookies, and alert you when a cookie is set. Instructions are in your browser's help documentation. Blocking strictly necessary cookies may prevent parts of the site from working.
We honor the Global Privacy Control signal and other recognized universal opt out mechanisms transmitted by your browser or extension. When we receive a valid signal, we treat it as a request to opt out of targeted advertising and any sharing of your personal data that would qualify as a sale.
Browsers also send a Do Not Track signal. There is no common industry standard for how to interpret it, so we do not respond to Do Not Track signals separately. We do honor Global Privacy Control as described above.
We share personal information only in the circumstances described below. We do not sell personal information, and we do not share personal information for cross context behavioral advertising.
We use vendors to operate our business. Each is bound by contract to protect the information we share and to use it only to perform services for us. Our principal categories of service providers are:
A current list of the specific subprocessors we use to deliver services to a client is available to that client on request to support@eastskymsp.com.
If you are an employee, contractor, or authorized user of one of our business clients, we share information about your support requests and device activity with that client's authorized administrators. Your employer, not East Sky MSP, controls that information.
We disclose personal information when we reasonably believe disclosure is necessary to:
If East Sky MSP is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will require the receiving party to honor the commitments in this policy or provide notice before your information becomes subject to a materially different policy.
We share information with third parties when you ask us to, for example when you authorize us to coordinate with your software vendor, telecom carrier, insurance broker, or auditor.
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include:
No system is completely secure. We cannot guarantee that unauthorized parties will never defeat our safeguards. If we become aware of a security breach affecting your personal information, we will notify you and any required regulator as the law requires and within the timelines the law sets.
We keep personal information only as long as we need it for the purposes described in this policy, or longer where the law requires.
When a retention period ends, we delete the information or de identify it so it can no longer reasonably be linked to you.
The Texas Data Privacy and Security Act gives Texas residents the following rights regarding personal data we control:
You will not be discriminated against or denied service for exercising these rights.
If you reside in a state with a comprehensive consumer privacy law, including California, Colorado, Connecticut, Virginia, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island, you may have rights comparable to those described above. We extend the rights in Section 8.1 to residents of all United States jurisdictions regardless of whether a specific law applies to us. Where your state grants a right we have not listed, contact us and we will honor it if the law requires.
California residents may also request disclosure of the categories of personal information collected, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom it is shared. That information is set out in Sections 2, 3, and 5 of this policy. We do not sell personal information and we do not share it for cross context behavioral advertising, so no opt out of sale is required. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit.
Submit a request by either of these methods:
Tell us which right you are exercising and give us enough information to locate your records. We will verify your identity before acting. Verification usually means confirming information we already hold, such as the email address associated with your record. We will not ask you for more sensitive information than is necessary to verify you.
An authorized agent may submit a request on your behalf with written authorization signed by you. We may still contact you directly to confirm the agent's authority.
Response time. We respond without undue delay and no later than 45 days after receiving a verified request. If we need more time, we will tell you within that first 45 day window and may extend by an additional 45 days. There is no charge for up to two requests in any 12 month period. For additional or manifestly unfounded requests we may charge a reasonable fee or decline, and we will explain why.
If we decline your request, we will tell you why. You may appeal our decision within a reasonable period by emailing support@eastskymsp.com with the subject line "Privacy Appeal" and referencing your original request.
We will respond to your appeal in writing within 60 days and explain the reasons for our decision. If we deny your appeal, we will provide you a method to contact the Texas Attorney General to submit a complaint. Texas residents may file a complaint with the Office of the Attorney General at www.texasattorneygeneral.gov.
You may unsubscribe from marketing email at any time using the link in any marketing message, or by emailing support@eastskymsp.com. We will continue to send transactional and service messages, including maintenance notices, security advisories, incident notifications, and billing communications, because those relate to services you receive.
When we deliver managed services, we act as a processor or service provider for our business clients. We access systems, mailboxes, files, endpoints, and network traffic that may contain personal information about our clients' employees, customers, patients, and contacts.
For that information:
If you are an individual whose data we process for a client, direct your privacy requests to that company. We will refer your request to them and support them in responding. We do not have authority to grant access, correction, or deletion for data we hold on a client's behalf without that client's instruction.
Some of our clients are HIPAA covered entities. Where we create, receive, maintain, or transmit protected health information for such a client, we act as a business associate under a signed Business Associate Agreement. That agreement, not this Privacy Policy, governs our handling of that protected health information.
Our website and services are directed to businesses, not to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact support@eastskymsp.com and we will delete it promptly.
Our website may link to third party sites, including vendor documentation, social media profiles, and partner pages. We do not control those sites and are not responsible for their privacy practices. Review their privacy policies before providing information to them.
We operate in the United States and store personal information on systems located in the United States. Some of our service providers may process data in other countries. If you access our website from outside the United States, understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Our services are directed to businesses in the United States. We do not target our services to individuals in the European Economic Area or the United Kingdom.
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes we will update the Effective Date at the top and post a notice on our website. If the changes materially affect how we handle personal information we have already collected about you, we will notify you by email or through a prominent notice before the changes take effect.
Continued use of our website or services after the effective date of an update means you accept the revised policy.
Questions, requests, or concerns about this policy or our privacy practices:
East Sky MSP
2741 E Belt Line Rd
Carrollton, TX 75006
Phone:(214) 851-3050
Email:support@eastskymsp.com
Web: www.eastskymsp.com