PSY Logistics Technology Partners, Inc.
PSY Logistics Technology Partners, Inc. (“PSY Logistics,” “we,” “us,” or “our”) is a Texas corporation providing cybersecurity compliance advisory services, including CMMC readiness and assessment support, NIST SP 800-171 implementation, maritime cybersecurity, and fractional/virtual CISO services.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit www.psylogistics.com (the “Site”), submit a form, schedule a consultation, subscribe to our communications, or otherwise interact with us in connection with our marketing and business development activities (collectively, the “Services”).
What this policy does not cover. This policy does not govern information we process on behalf of clients under a services agreement, statement of work, master services agreement, or non-disclosure agreement. Client data — including any Federal Contract Information (FCI), Controlled Unclassified Information (CUI), assessment evidence, or system artifacts we access in the course of an engagement — is governed by the terms of that engagement, applicable federal contract clauses (including DFARS 252.204-7012 where flowed down), and our internal safeguarding obligations, not by this Site policy. We do not accept, request, or process FCI or CUI through this Site or through unencrypted email or text message.
By using the Site, you acknowledge that you have read and understand this Privacy Policy.
PSY Logistics Technology Partners, Inc.
Houston Office: 440 Louisiana St., Ste. 900, Houston, TX 77002
Denver Office: 1500 N. Grant St., Ste. R, Denver, CO 80203
Privacy inquiries and rights requests:
[email protected]
Telephone: (713) 539-3719
PSY Logistics is the “controller” (GDPR) and “business” (CCPA/CPRA) responsible for the personal information described in this policy.
We collect the following categories of personal information. Not every category applies to every individual — what we hold about you depends on how you interact with us.
| Category | Examples | Typical Source |
|---|---|---|
| Identifiers and contact data | First and last name, business email address, telephone or mobile number, mailing address, company name, job title | Contact form, consultation booking, email, business card, events |
| Communication preferences and consent records | Your selected preferred method of communication (phone, SMS, or email); the date, time, IP address, and page on which you provided consent to be contacted; opt-in and opt-out history | Contact form and consent checkboxes |
| Inquiry and engagement content | Brief scope of work, compliance objectives, contract vehicle or framework of interest, message content, meeting notes, and any other information you choose to include | Forms, email, calls, meetings |
| Professional and commercial information | Employer, industry, role, contracting status (e.g., prime or subcontractor), procurement timeline, budget range you disclose | Discovery calls, proposals, RFP/RFI responses |
| Business transaction information | Billing contact, purchase order or invoice references, remittance details | Client onboarding and billing |
| Recruiting information | Resume, work history, certifications, references, if you apply for a role or subcontractor position | Direct submission |
When you visit the Site, we and our service providers may automatically collect:
We may receive personal information from:
We do not intentionally collect Social Security numbers, driver’s license or government identification numbers, financial account credentials, precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs, union membership, or information about sexual orientation through the Site. Please do not submit such information to us through the Site, email, or text message.
The Site uses cookies and similar technologies to function, to remember your preferences, to measure traffic, and to understand which content and campaigns are effective.
Your choices. Most browsers let you refuse or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the Site from working. You may also opt out of certain interest-based advertising through the Digital Advertising Alliance (optout.aboutads.info) and the Network Advertising Initiative (optout.networkadvertising.org).
Global Privacy Control and universal opt-out signals. We recognize and honor opt-out preference signals, including Global Privacy Control (GPC), transmitted by your browser or device, where required by applicable state law. When we receive such a signal, we treat it as a request to opt out of the sale of personal data and targeted advertising for that browser or device.
Do Not Track. Because no common industry standard for “Do Not Track” browser signals has been adopted, the Site does not respond to DNT headers. We do honor GPC signals as described above.
We use personal information for the following purposes:
We do not use personal information collected through the Site to make decisions producing legal or similarly significant effects about you through solely automated means, and we do not use it for profiling of that kind.
If you provide your mobile number and check a consent box on our forms, you may receive text messages and/or AI-assisted voice calls from PSY Logistics Technology Partners, Inc.
Mobile opt-in data. No mobile information will be sold, rented, or shared with any third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are excluded from every category of information sharing described elsewhere in this policy; this information will not be shared with any third party. Information may be shared only with the subprocessors that are strictly necessary to deliver the messages themselves — for example, our messaging platform and telecommunications carriers — and those parties are contractually prohibited from using it for any other purpose.
We disclose personal information in the following circumstances:
We share personal information with vendors that perform services for us under written contracts limiting their use of the information to the services they provide. These include:
| Function | Purpose |
|---|---|
| CRM, website hosting, and marketing automation | Operating the Site, hosting forms and landing pages, managing leads and pipeline, delivering email and SMS |
| Telecommunications and messaging carriers | Delivering text messages and voice calls |
| Email and productivity platforms | Business correspondence, calendaring, and document collaboration |
| Scheduling and conferencing tools | Booking and conducting consultations |
| Analytics providers | Measuring Site traffic and content performance |
| Payment processing and accounting | Invoicing, collections, and financial recordkeeping |
| Professional advisors | Legal, accounting, insurance, and audit services |
| Security and IT support | Endpoint protection, backup, monitoring, and secure file exchange |
We may disclose personal information when we reasonably believe it is necessary to: comply with a law, regulation, subpoena, court order, or other legal process; respond to a lawful request from a government or regulatory authority, including federal contracting authorities; enforce our agreements; or protect the rights, safety, or property of PSY Logistics, our clients, or others.
If PSY Logistics is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy or provide notice of any material change.
We share information with third parties — such as teaming partners, prime contractors, or assessment bodies — when you ask us to or when doing so is necessary to perform an engagement you have requested.
We may create and use aggregated or de-identified information that cannot reasonably be used to identify you. We maintain such information in de-identified form and do not attempt to re-identify it.
PSY Logistics does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising in a manner that would require an opt-out under the California Consumer Privacy Act, except as may occur through standard analytics and advertising cookies as described in Section 4. We do not sell or share the personal information of consumers we know to be under 16 years of age. As stated in Section 6, mobile opt-in and consent data are never sold or shared with any third party.
We keep personal information only as long as necessary for the purposes described in this policy, and then delete or de-identify it. Our general practice:
| Record type | Retention |
|---|---|
| Website inquiries that do not become opportunities | Up to 24 months from last contact |
| Marketing contacts and subscribers | Until you opt out, plus a suppression record retained indefinitely to honor your opt-out |
| SMS consent and opt-out records | At least 4 years from the date of the last message, per TCPA guidance |
| Prospect and opportunity records | Duration of the relationship plus 3 years |
| Client engagement records, contracts, and deliverables | Duration of the engagement plus the longer of 7 years or the retention period required by the applicable contract, federal acquisition regulation, or accreditation body |
| Financial and tax records | 7 years |
| Website server and analytics logs | Up to 24 months |
| Applicant records | 2 years, unless a longer period is required by law |
Retention may be extended where required by legal hold, contract, audit, or accreditation obligations.
We maintain an information security program aligned to NIST SP 800-171 and NIST Cybersecurity Framework practices, appropriate to the sensitivity of the information we hold. Controls include access control and least privilege, multifactor authentication, encryption of data in transit and at rest, endpoint protection, logging and monitoring, vendor due diligence, personnel security and training, and incident response procedures.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and any transmission of information to us is at your own risk. If we become aware of a security incident affecting your personal information, we will notify you and applicable regulators as required by law.
Depending on the state in which you reside, you may have some or all of the following rights regarding personal information we hold about you:
These rights are available to residents of states with comprehensive consumer privacy laws in effect, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as well as any additional state whose law takes effect after the date of this policy. Specific rights, exemptions, and thresholds vary by state, and we will apply the standard that applies to you.
Email [email protected] with the subject line “Privacy Rights Request” and tell us:
Verification. We will take reasonable steps to verify your identity before acting on a request, typically by confirming information already in our records or by sending a confirmation to the email address or phone number associated with the record. We will not use information provided for verification for any other purpose.
Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require written authorization signed by you and verification of the agent’s identity.
Timing. We will respond within 45 days of receipt, and may extend once by an additional 45 days where reasonably necessary, with notice to you.
Appeals. If we decline your request, our response will explain why and how to appeal. To appeal, reply to our response or email [email protected] with the subject line “Privacy Rights Appeal.” We will respond to appeals within 45 days (or 60 days in Colorado). If your appeal is denied, you may contact your state attorney general to submit a complaint. Texas residents may contact the Office of the Texas Attorney General; Colorado residents may contact the Colorado Attorney General.
Nevada residents may submit a verified request directing us not to sell certain covered information by emailing [email protected]. We do not currently sell covered information as defined by Nevada law.
This section supplements the above and applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
Categories of personal information collected in the preceding 12 months:
| CCPA Category | Collected | Disclosed To |
|---|---|---|
| Identifiers (name, email, phone, address, IP address, unique identifiers) | Yes | Service providers |
| Customer records information (Cal. Civ. Code § 1798.80) | Yes | Service providers, professional advisors |
| Commercial information (services considered or obtained, transaction records) | Yes | Service providers |
| Internet or other electronic network activity | Yes | Analytics providers |
| Geolocation data (approximate, IP-derived) | Yes | Analytics providers |
| Audio, electronic, or visual information (call and meeting recordings, where disclosed and consented to) | Yes | Service providers |
| Professional or employment-related information | Yes | Service providers |
| Education information | Only if you provide it in an application | Professional advisors |
| Sensitive personal information | Not intentionally collected | — |
| Inferences drawn from the above | Limited (service interest and fit) | Service providers |
Sources of this information are described in Section 3, the purposes in Section 5, and retention in Section 9. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by the CCPA, other than as may occur through the cookies described in Section 4, which you may control through your browser or by transmitting a GPC signal.
California residents have the rights described in Section 11 and may exercise them at [email protected]. Shine the Light: California residents may request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
If you are located in the EEA, the United Kingdom, or Switzerland, this section applies to you.
Legal bases for processing. We process personal data on the following bases:
| Purpose | Legal basis |
|---|---|
| Responding to your inquiry and providing requested information | Performance of a contract or steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Providing services under an engagement | Performance of a contract (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)), withdrawable at any time; or legitimate interests in business-to-business marketing (Art. 6(1)(f)) where permitted |
| Site operation, security, and fraud prevention | Legitimate interests in operating and protecting our business (Art. 6(1)(f)) |
| Analytics and non-essential cookies | Consent (Art. 6(1)(a)) |
| Legal, tax, accounting, and contractual compliance | Legal obligation (Art. 6(1)(c)) |
Your rights. You have the right to access, rectify, erase, restrict processing of, and port your personal data; to object to processing based on legitimate interests or for direct marketing; and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Requests go to [email protected]. You also have the right to lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner’s Office (ico.org.uk).
International transfers. PSY Logistics is based in the United States, and personal data you provide will be transferred to and processed in the United States. Where we transfer personal data from the EEA or UK, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures. You may request a copy of the relevant safeguards by emailing [email protected].
Retention is described in Section 9. We do not engage in automated decision-making producing legal or similarly significant effects.
The Site is intended for business audiences and is not directed to children. We do not knowingly collect personal information from anyone under 16 years of age. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
The Site links to third-party sites and platforms, including LinkedIn, Facebook, X, Instagram, and scheduling or conferencing tools. We are not responsible for the privacy practices or content of those third parties. Review their privacy policies before providing information to them.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date above and post the revised policy on this page. If we make material changes, we will provide additional notice, such as by email or a prominent notice on the Site. Your continued use of the Site after the effective date of a revised policy constitutes acceptance of the changes.
Questions, concerns, or requests regarding this Privacy Policy or our handling of personal information:
PSY Logistics Technology Partners, Inc.
Attn: Privacy
440 Louisiana St., Ste. 900
Houston, TX 77002
Email: [email protected]
Phone: (713) 539-3719
© 2026 PSY Logistics Technology Partners, Inc. All rights reserved.