BIRCHLINE CONSULTING LLC PRIVACY POLICY
Effective Date: September 3, 2026
Last Updated: October 5, 2026
1. INTRODUCTION AND SCOPE
1.1 Who We Are. BirchLine Consulting LLC (“BirchLine,” “we,” “us” or “our”) is a Wisconsin limited liability company. Our mailing address is PO Box 81682, Racine, Wisconsin 53408, United States. We provide software consulting services to business clients.
1.2 Purpose of This Policy. This Privacy Policy explains how we collect, use, disclose, retain and protect personal data, and describes the rights available to individuals whose personal data we handle. “Personal data” means any information relating to an identified or identifiable natural person, and includes “personal information” as that term is used under United States state privacy laws.
1.3 What This Policy Covers. This Policy applies to personal data we process:
through our website at www.birchlineconsulting.com and any successor or related site (the “Site”);
in connection with our marketing, business development and communications;
in the course of establishing and administering client, vendor and partner relationships; and
in connection with recruitment and applications for engagement with us.
1.4 What This Policy Does Not Cover. This Policy does not govern personal data that we process on behalf of and under the instructions of a client in the course of delivering consulting services. In that context we act as a processor, also called a service provider, the client is the controller, and the client’s own privacy notice governs. Our handling of that data is governed by our written agreement with the client, including the data processing addendum described in Section 4.2. If you believe your personal data was provided to us by one of our clients and you wish to exercise rights in relation to it, please contact that organization directly. We will refer any request we receive to the relevant client and will assist that client in responding.
1.5 Third Party Sites. The Site may link to third party websites and services that we do not control. This Policy does not apply to them, and we are not responsible for their privacy practices. We encourage you to read their notices.
1.6 Children. Our Site and services are directed to businesses and business professionals and are not intended for children. We do not knowingly collect personal data from any person under 16 years of age. If you believe a child has provided us with personal data, please contact us using the details in Section 15 and we will delete it.
2. THE PERSONAL DATA WE COLLECT
2.1 Data You Provide to Us.
(a) Identity and contact data
Examples: Name, job title, employer, business email address, business telephone number, postal address
When Collected: Contact form; email; consultation request; newsletter signup; event registration
(b) Professional data
Examples: Industry, company size, role, technical environment, project requirements, budget range
When Collected: Inquiry forms; discovery calls; proposals
(c) Client relationship data
Examples: Engagement correspondence, meeting notes, statements of work, deliverables, feedback
When Collected: Course of the engagement
(d) Financial and billing data
Examples: Billing contact, billing address, tax identifiers (including VAT number), payment records
When Collected: Contracting and invoicing
(e) Recruitment data
Examples: Resume or CV, work history, qualifications, references, work authorization information
When Collected: Applications for engagement
(f) Communications data
Examples: The content of your emails, messages, calls and support requests to us
When Collected: Whenever you contact us
2.2 Data We Collect Automatically. When you visit the Site we and our service providers may collect: IP address; device type, operating system and browser; referring and exit pages; pages viewed and time spent; date and time of access; approximate location derived from IP address; and interaction data such as clicks and scrolling. Some of this data is collected using cookies and similar technologies. See Section 8.
2.3 Data from Third Party Sources. We may receive personal data from: our clients and partners, including business contacts introduced to us; referral partners, including under alliance or partner program arrangements; publicly available sources such as company websites, professional networking platforms and business directories; and event organizers where you have attended an event at which we participated.
2.4 Special Category and Sensitive Data. We do not seek to collect special categories of personal data under Article 9 of the GDPR, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation, and we ask that you do not provide it to us. If we must process such data, for example to accommodate a disability at a meeting, we will do so only with your explicit consent or as otherwise permitted by law. We likewise do not collect sensitive personal information as that term is defined under United States state privacy laws, and we do not use or disclose any such information for purposes that would give rise to a right to limit its use.
2.5 If You Do Not Provide Data. Where we need personal data to enter into or perform a contract with you and you do not provide it, we may be unable to provide our services. We will tell you if that is the case.
3. HOW AND WHY WE USE PERSONAL DATA
3.1 Purposes and Legal Bases. Where the GDPR or the UK GDPR applies, we must have a legal basis for each processing activity. Our purposes and bases are:
(a) Purpose: Responding to inquiries and providing information you request
Categories used: Identity, contact, professional, communications
Legal basis (GDPR Art. 6): Art. 6(1)(b) steps at your request before entering a contract; or Art. 6(1)(f) our legitimate interest in responding to business inquiries
(b) Purpose: Providing consulting services and administering the engagement
Categories used: Identity, contact, professional, client relationship
Legal basis (GDPR Art. 6): Art. 6(1)(b) performance of a contract
(c) Purpose: Invoicing, payment and credit control
Categories used: Identity, contact, financial
Legal basis (GDPR Art. 6): Art. 6(1)(b); Art. 6(1)(c) legal obligation (tax and accounting)
(d) Purpose: Marketing our services to business contacts
Categories used: Identity, contact, professional
Legal basis (GDPR Art. 6): Art. 6(1)(f) legitimate interest in promoting our business; or Art. 6(1)(a) consent, where required by local law
(e) Purpose: Operating, securing and improving the Site
Categories used: Automatically collected data
Legal basis (GDPR Art. 6): Art. 6(1)(f) legitimate interest in a secure and functional website
(f) Purpose: Analytics and understanding how the Site is used
Categories used: Automatically collected data
Legal basis (GDPR Art. 6): Art. 6(1)(a) consent, where cookie consent is required; otherwise Art. 6(1)(f)
(g) Purpose: Recruitment and engagement of personnel and subcontractors
Categories used: Recruitment data
Legal basis (GDPR Art. 6): Art. 6(1)(b); Art. 6(1)(f) legitimate interest in building our team
(h) Purpose: Complying with law and responding to lawful requests
Categories used: Any
Legal basis (GDPR Art. 6): Art. 6(1)(c) legal obligation
(i) Purpose: Establishing, exercising or defending legal claims; maintaining insurance
Categories used: Any
Legal basis (GDPR Art. 6): Art. 6(1)(f) legitimate interest in protecting our legal position
(j) Purpose: Business transfer (merger, acquisition, financing, sale of assets)
Categories used: Any
Legal basis (GDPR Art. 6): Art. 6(1)(f) legitimate interest in corporate transactions
3.2 Our Legitimate Interests. Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests, rights and freedoms. Our interests are: operating and growing a professional services business; maintaining and developing client and partner relationships; securing our systems and information; and protecting our legal and commercial position. You may object to processing based on legitimate interests at any time. See Section 9.1(f). You may request a summary of the relevant balancing assessment using the contact details in Section 15.
3.3 Marketing and Your Choices. We may send business to business marketing communications about our services. You may opt out at any time by using the unsubscribe link in any message or by contacting us. We will honor the request promptly and in any event within the period required by applicable law. We will continue to send you transactional and relationship messages relating to an active engagement, which are not marketing.
Where you are in the European Economic Area or the United Kingdom, we will obtain your consent before sending electronic marketing where required by applicable law, including the ePrivacy Directive as implemented locally, and we will rely on the soft opt in for existing clients only where the conditions for it are satisfied. In the United States, our commercial email complies with the CAN SPAM Act, 15 U.S.C. section 7701 et seq.
3.4 Automated Decision Making. We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing, and we do not engage in profiling of that kind.
3.5 No Sale of Personal Data and No Targeted Advertising. We do not sell personal data. We do not share personal data for cross context behavioral advertising or targeted advertising, as those terms are defined under United States state privacy laws. We have not done so in the preceding twelve months. We do not place advertising, retargeting or social media tracking tags on the Site, and we do not disclose Site visitor data to advertising networks or social media platforms.
4. HOW WE SHARE PERSONAL DATA
4.1 Categories of Recipients. We disclose personal data to:
(a) Service providers and processors who perform functions on our behalf, including website hosting and site analytics, email, calendar, video conferencing, document and file storage, accounting and invoicing, electronic signature, backup, and professional advisers. As of the Last Updated date, our principal providers are Squarespace (website hosting and site analytics), and Google Workspace (email, calendar, video conferencing and file storage). Each is bound by written contract to process personal data only on our instructions and to maintain appropriate security. A current list of our providers is available on request using the details in Section 15.
(b) Professional advisers, including but not limited to lawyers, accountants, auditors and insurers, where necessary for the services they provide to us.
(c) Clients, where you are a contact at a client organization or where personal data forms part of a deliverable.
(d) Partners and referral sources, where you have asked to be introduced, where you have consented, or where we have a legitimate interest in making an introduction you would reasonably expect. Where we refer a prospective customer to a technology partner, we disclose only the contact and opportunity information necessary to make the referral, and we do so only where we have a lawful basis to do so.
(e) Subcontractors, including independent consultants engaged to deliver part of a project, each bound by written confidentiality and data protection obligations no less protective than those we owe.
(f) Government authorities, courts and regulators, where required by law, legal process, or lawful request, or where necessary to establish, exercise or defend legal claims. Where we are legally permitted, we will notify you before making such a disclosure.
(g) Acquirers and their advisers, in connection with a merger, acquisition, reorganization, financing, or sale of all or substantially all of our assets, subject to appropriate confidentiality protections. If personal data becomes subject to a different privacy policy as a result, we will notify you.
4.2 Data Processing Agreements. Where we act as a processor for a client, our processing is governed by a written data processing addendum containing the terms required by Article 28(3) of the GDPR, including obligations of confidentiality, security, subprocessor control, assistance with data subject rights, breach notification, and deletion or return of data at the end of the engagement. We in turn maintain written data processing terms with each of the providers identified in Section 4.1.
4.3 No Sale. See Section 3.5.
5. INTERNATIONAL TRANSFERS
5.1 Where Data Is Processed. We are established in the United States. Personal data we collect may be transferred to, stored in and processed in the United States and in other countries where we or our service providers operate. These countries may have data protection laws that differ from those of your country.
5.2 Transfer Mechanisms for EEA, UK and Swiss Data. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision, we rely on one or more of the following:
the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, incorporated into our agreements with the relevant recipient, together with any supplementary measures identified by a transfer impact assessment;
for transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses, or the UK International Data Transfer Agreement, issued under section 119A of the Data Protection Act 2018;
for transfers from Switzerland, the Standard Contractual Clauses as adapted in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner; or
where the recipient is self certified and the transfer is within the scope of its certification, the EU U.S. Data Privacy Framework, the UK Extension to the EU U.S. Data Privacy Framework, or the Swiss U.S. Data Privacy Framework.
5.3 Copies. You may request a copy of the safeguards we have put in place for a particular transfer by contacting us using the details in Section 15. We may redact commercial terms.
5.4 Establishment and Representatives. We are established solely in the United States. We have no branch, office, subsidiary or other establishment in the European Economic Area, the United Kingdom or Switzerland. Our services are offered to business organizations, we do not offer goods or services to individuals located in the European Economic Area or the United Kingdom, and we do not monitor the behavior of individuals located there. On that basis we have not appointed a representative under Article 27 of the GDPR or under Article 27 of the UK GDPR. If our activities change so that Article 27 applies to us, we will appoint representatives and publish their names and addresses in this Section. Where we process personal data on behalf of a client under Section 1.4, the client remains responsible for its own obligations under Article 27.
6. HOW LONG WE KEEP PERSONAL DATA
6.1 Retention Principle. We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, insurance and reporting requirements, and to establish, exercise or defend legal claims.
6.2 Retention Periods.
(a) Website inquiries that do not lead to an engagement - 24 months from last contact
(b) Marketing contact data - Until you opt out, or 36 months without engagement, whichever is earlier
(c) Client engagement records and deliverables - 7 years after the end of the engagement
(d) Contracts and related records - 7 years after expiry or termination
(e) Invoices, payment and tax records - 7 years, consistent with applicable tax and accounting requirements
(f) Unsuccessful applications for engagement - 12 months from decision, unless you consent to a longer period
(g) Website analytics data - 26 months, or such shorter period as our analytics provider applies
(h) Data processed on behalf of a client - As directed by the client under the applicable data processing addendum; deleted or returned at the end of the engagement
(i) Records relating to a legal claim or investigation - Until the matter is finally resolved and the applicable limitation period has expired
6.3 Suppression Lists. Where you ask us to stop marketing to you, we retain the minimum data necessary, typically your email address on a suppression list, to ensure we honor that request. This is a legal obligation and cannot be deleted at your request.
6.4 Anonymization. We may retain aggregated or anonymized data, from which you cannot be identified, without time limit.
7. SECURITY
7.1 Our Measures. We maintain technical and organizational measures appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. These include: encryption of data in transit and at rest; multi factor authentication on business systems; role based access control on a need to know basis; endpoint protection and patch management; secure, tested backups; vendor due diligence and written data protection terms with service providers; confidentiality obligations binding on all personnel and subcontractors; periodic review of access rights; and an incident response procedure.
7.2 No Absolute Guarantee. No method of transmission over the internet or method of electronic storage is completely secure. While we take the measures described above, we cannot guarantee absolute security.
7.3 Breach Notification. In the event of a personal data breach we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons under Article 33 of the GDPR, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to them under Article 34 of the GDPR. Where a breach involves personal information of Wisconsin residents, we will provide notice in accordance with Wis. Stat. section 134.98, and we will comply with the breach notification laws of each other jurisdiction whose residents are affected. Where we act as a processor for a client, we will notify the client without undue delay and will not notify individuals or authorities on the client’s behalf except at the client’s direction.
7.4 Your Role. Please help us keep your data secure: use a strong, unique password for any account you hold with us, do not send sensitive information by unencrypted email, and tell us immediately if you suspect unauthorized access.
8. COOKIES AND SIMILAR TECHNOLOGIES
8.1 What We Use. We use cookies and similar technologies on the Site. Cookies are small text files placed on your device. The Site is hosted on the Squarespace platform, and cookies are set by Squarespace on our behalf.
8.2 Categories.
(a) Type: Necessary
Purpose: Enable core Site functionality, including security, load balancing, network management, and remembering your language preferences, customized settings and cookie choices
Consent required: No
(b) Type: Performance and Analytics
Purpose: Provide quantitative measures of Site visitors, including visit counts and traffic sources, so that we can improve the Site
Consent required: Yes, where required
(c) Type: Advertising
Purpose: Serve advertising relevant to your interests. We do not currently use cookies in this category. If we begin to use them, we will update this Policy and they will be set only where you have consented
Consent required: Yes
8.3 Managing Cookies. We present a consent banner on your first visit. Non essential cookies are not set unless and until you consent to them. You may accept all cookies, decline all non essential cookies, or select Manage Cookies to make category by category choices. You may change your choices at any time by selecting the Cookie Settings link in the footer of the Site, which reopens the same preference controls. You may also control cookies through your browser settings, although disabling cookies may affect Site functionality.
8.4 Do Not Track and Global Privacy Control. Our Site does not respond to browser Do Not Track signals, because no common standard for them has been adopted. As stated in Section 3.5, we do not sell or share personal information, so there is no sale or sharing for a Global Privacy Control signal to opt out of. Where applicable law requires us to treat a Global Privacy Control signal as an opt out, we will honor it.
9. YOUR RIGHTS
9.1 Rights Under the GDPR and UK GDPR. If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights:
Access, to obtain confirmation whether we process your personal data and, if so, a copy of it and information about the processing (Art. 15);
Rectification, to have inaccurate personal data corrected and incomplete data completed (Art. 16);
Erasure, to have personal data deleted where one of the grounds in Art. 17 applies, sometimes called the right to be forgotten;
Restriction, to have processing restricted in the circumstances set out in Art. 18;
Portability, to receive personal data you provided to us in a structured, commonly used, machine readable format and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means (Art. 20);
Objection, to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21(1)), and to object at any time, absolutely and without needing to give a reason, to processing for direct marketing purposes (Art. 21(2));
Withdrawal of consent, where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
Not to be subject to automated decision making producing legal or similarly significant effects (Art. 22). See Section 3.4; and
Complaint, to complain to a supervisory authority. See Section 9.5.
9.2 Rights Under United States State Privacy Laws. Depending on your state of residence, you may have rights to: know what personal information we collect, use and disclose; access a copy of it; correct inaccuracies; delete it; opt out of sale, sharing for cross context behavioral advertising, targeted advertising, and certain profiling; limit the use of sensitive personal information; and obtain the services we offer without discrimination for exercising your rights. Where an applicable law provides a right to appeal a decision on your request, we will inform you of that right and how to exercise it when we respond. We do not sell or share personal information as those terms are defined under these laws. See Section 3.5.
9.3 How to Exercise Your Rights. Contact us using the details in Section 15. We will:
verify your identity before acting, and may ask for additional information for that purpose, which we will not use for any other purpose;
respond within one month of receipt where the GDPR or the UK GDPR applies, extendable by two further months where the request is complex or numerous, in which case we will tell you within one month and explain why;
respond within 45 days where a United States state privacy law applies, extendable once by a further 45 days with notice to you; and
act free of charge, except that where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee reflecting our administrative costs, or refuse to act, and will explain our reasoning.
9.4 Authorized Agents. You may use an authorized agent to submit a request where applicable law permits. We may require written proof of the agent’s authority and may require you to verify your own identity directly.
9.5 Complaints. If you are unhappy with how we have handled your personal data, please contact us first. We would like the opportunity to make it right. You also have the right to complain to a supervisory authority:
European Union: the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement.
United Kingdom: the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom, ico.org.uk.
Switzerland: the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland.
United States: the Attorney General of your state of residence.
9.6 Requests Relating to Client Data. If your request concerns personal data we process on behalf of a client, as described in Section 1.4, we will refer it to that client without undue delay and assist the client in responding. We are not able to act on such a request without the client’s instruction.
10. CHANGES TO THIS POLICY
10.1 We may update this Policy from time to time. The Last Updated date at the top shows when it was last revised. Where a change is material, for example a change in the purposes for which we process personal data, the recipients to whom we disclose it, or your rights, we will provide prominent notice on the Site and, where required by law or where the change materially affects you, notify you directly before the change takes effect. Where a change requires your consent, we will obtain it. We encourage you to review this Policy periodically. Prior versions are available on request.
11. GOVERNING LAW
11.1 This Policy and any dispute arising out of it are governed by the laws of the State of Wisconsin, United States, without regard to its conflict of laws principles, except that nothing in this Policy limits any right or remedy available to you, or any obligation imposed on us, under the mandatory law of your jurisdiction of residence, including the GDPR and the UK GDPR.
12. ACCESSIBILITY
12.1 If you need this Policy in an alternative format, please contact us using the details in Section 15 and we will provide it.
13. NOTICE AT COLLECTION
13.1 This Policy, together with any short form notice presented at the point of collection, constitutes our notice at collection for the purposes of applicable United States state privacy laws. The categories of personal data we collect, the purposes for which we use them, and our retention periods are set out in Sections 2, 3 and 6.
14. LANGUAGE
14.1 This Policy is published in English. Where we provide a translation and there is any inconsistency, the English version governs, except where applicable law requires otherwise.
15. HOW TO CONTACT US
15.1 Controller. BirchLine Consulting LLC is the controller of the personal data described in this Policy, except where Section 1.4 applies.
15.2 Privacy Contact. BirchLine Consulting LLC, Attn: Privacy, PO Box 81682, Racine, Wisconsin 53408, United States. Email: info@birchlineconsulting.com.
15.3 Data Protection Officer. We are not required to appoint a Data Protection Officer under Article 37 of the GDPR and have not appointed one. Privacy inquiries should be directed to the contact in Section 15.2.