Who We Are
HOURO ("Company", "we", "us") is an IT consulting and technology company headquartered at 12301 Branford St, Sun Valley, CA 91352-1012, United States. We provide solution architecture, DevOps, cloud engineering, cybersecurity, data & AI consulting, and squad-as-a-service solutions for businesses worldwide.
This Privacy & Legal document describes how we collect, use, store and protect the personal data of our clients, prospects, platform users and website visitors in compliance with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the GDPR and other applicable regulations.
By using HOURO services or accessing our website, you agree to the practices described in this policy. We recommend reading it in full before providing us with any personal data.
Personal Data We Collect
We collect personal data necessary to deliver our IT consulting services, manage client engagements and operate our website:
When HOURO deploys engineers or consultants within client environments, we may process employee and system data on behalf of our clients as a Data Processor. In those cases, our clients act as Data Controllers and are responsible for their own compliance obligations.
- Contact & Identity Data — Name, email address, phone number, job title and company name.
- Client & Project Data — Technical requirements, system architecture details, SLA parameters and project scope documentation.
- Candidate & Team Data — CV/resume, technical skills, certifications and professional background for squad placement.
- Billing & Financial Data — Invoice details, payment records and contract information processed through secure providers.
- Technical & Usage Data — IP address, browser type, device identifiers, operating system and website interaction logs.
- Communication Data — Emails, support tickets, consultation recordings (with consent) and project correspondence.
- Free Diagnosis Data — Technical questionnaire responses, system descriptions and vulnerability assessment information provided through our free diagnosis service.
How We Use Your Data
We use your data exclusively for legitimate, specific and informed purposes with the appropriate legal basis:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Delivering IT consulting and squad services | Client, Project, Team | Contract Performance |
| Free technical diagnosis and assessment | Contact, Diagnosis | Contract Performance |
| Project management and SLA compliance | Client, Project | Contract Performance |
| Invoice processing and billing management | Contact, Billing | Contract Performance |
| Security monitoring and vulnerability assessment | Technical, Project | Contract Performance |
| Website analytics and performance improvement | Technical, Usage | Legitimate Interest |
| Marketing, newsletters and case study updates | Contact, Profile | Consent |
| Fraud prevention and platform security | Technical, Contact | Legitimate Interest |
| Legal compliance and regulatory obligations | Contact, Billing | Legal Obligation |
Data Sharing & Disclosure
HOURO does not sell your personal data. We share information only where necessary to deliver our services and with appropriate contractual safeguards:
- Cloud infrastructure partners — AWS, Azure and Google Cloud for hosting, data processing and security tooling under appropriate Data Processing Agreements.
- Development and DevOps tool providers — GitLab, Datadog, PagerDuty and similar platforms used in client project delivery.
- Payment processors — Stripe and other PCI-DSS certified processors for secure billing and invoice payment.
- Background check providers — For engineer placement verification, subject to candidate consent and applicable privacy protections.
- Analytics providers — Google Analytics and similar tools for website performance monitoring under appropriate DPAs.
- Regulatory and legal authorities — When required by US federal or California state law, court order or regulatory investigation.
- International transfers — Data transferred outside the US is protected using Standard Contractual Clauses (SCCs) or other approved mechanisms.
Cookies & Tracking Technologies
Our website uses cookies and similar technologies to improve user experience, analyse traffic and support our marketing activities.
| Type | Purpose | Duration |
|---|---|---|
| Essential | Core website functionality, contact forms and session management. Cannot be disabled. | Session |
| Analytics | Website traffic analysis, page performance and user journey measurement (e.g. Google Analytics). | Up to 2 years |
| Functional | Remembering user language preferences and form pre-fills. | Up to 1 year |
| Marketing | Retargeting and personalised advertising. Activated only with your explicit prior consent. | Up to 90 days |
Manage your cookie preferences via the consent banner on our website or through your browser settings. Disabling essential cookies may prevent access to certain contact and diagnosis forms.
Data Retention
We retain personal data only as long as necessary to deliver services and meet legal obligations:
- Active client and project data: for the duration of the engagement, plus 5 years after project completion for warranty and dispute resolution purposes.
- Security audit and vulnerability assessment records: 3 years or as required by client contractual obligations.
- Financial records and invoices: 7 years per IRS requirements and California state tax law.
- Engineer and candidate placement records: 3 years from last application or engagement.
- Website access logs and technical data: 12 months for security monitoring and performance analysis.
- Free diagnosis questionnaire data: 12 months from submission, then deleted unless a project engagement follows.
- Marketing consent and newsletter data: 3 years from last engagement or until opt-out is received.
Your Privacy Rights (CCPA / CPRA)
As a California-based company, we uphold all rights under the CCPA and CPRA. Depending on your location, additional rights may apply under GDPR or other laws:
- Right to Know — Request disclosure of the categories and specific pieces of personal data we have collected, used, disclosed or sold.
- Right to Access — Obtain a copy of your personal data in a portable, machine-readable format.
- Right to Delete — Request deletion of personal data we hold, subject to applicable legal retention obligations.
- Right to Correction — Request correction of inaccurate or incomplete personal information in our records.
- Right to Opt-Out of Sale — HOURO does not sell personal data. This right is upheld by default.
- Right to Limit Sensitive Data Use — Limit our use of sensitive personal information to purposes strictly necessary to provide services.
- Right to Non-Discrimination — Exercising your privacy rights will not result in denial of service or any adverse treatment.
- Right to Withdraw Consent — Withdraw marketing consent at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@houro.com. We will respond within 45 days as required by CCPA (or 30 days for GDPR requests). Identity verification may be required before processing your request.
Security Measures
As a security-focused IT consultancy, we apply the same rigour to protecting our own data as we recommend to our clients:
- TLS 1.3 encryption for all data in transit between users, our systems and third-party integrations.
- AES-256 encryption for sensitive client and project data at rest across all storage systems.
- Role-based access control (RBAC) ensuring only authorised personnel access client project data.
- Multi-factor authentication (MFA) required for all staff access to systems handling client data.
- Regular security audits aligned with OWASP Top 10 and NIST Cybersecurity Framework standards.
- Incident response plan with mandatory breach notification within 72 hours to regulatory authorities and affected parties.
- Zero-trust network architecture for internal systems and client project environments.
- Regular penetration testing of our own infrastructure by independent third parties.
External Links & Tool Integrations
HOURO's website and project work may involve links or integrations with external platforms including GitHub, GitLab, cloud consoles, monitoring tools and client systems. When you access external links or connect third-party tools, you are subject to those providers' own privacy policies.
HOURO is not responsible for the privacy practices of external websites or tool providers. This Privacy & Legal document applies exclusively to data processed directly by HOURO within our own systems and engagements.
Children's Privacy
HOURO's services are directed exclusively at business professionals and organisations. We do not knowingly collect personal data from individuals under the age of 16.
If you believe a minor has provided data through our website or contact forms, please notify us immediately at privacy@houro.com and we will take prompt action to delete the data.
Changes to This Policy
We may update this Privacy & Legal document periodically to reflect changes in our services, legal obligations or business practices. When material changes are made:
- The "Last Updated" date at the top of this page will be revised accordingly.
- Active clients will be notified by email with at least 30 days advance notice for material changes.
- A prominent notice will be displayed on our homepage for a minimum of 30 days.
- Previous versions of this policy are available upon written request.
Continued use of HOURO services after the effective date of any changes constitutes your acceptance of the updated policy.
Contact & Privacy Team
For any questions, rights requests or concerns regarding how HOURO processes your personal data, please reach out through any of the following channels:
Privacy Team
privacy@houro.comGeneral Enquiries
hello@houro.comOrganisation Address
12301 Branford StSun Valley, CA 91352-1012
United States
Compliance
CCPA · CPRA · GDPROWASP · NIST CSF
SOC 2 Ready
California residents may submit privacy rights requests to the California Privacy Protection Agency (CPPA) at cppa.ca.gov. EU/UK residents may contact the relevant supervisory authority in their member state.