Privacy Policy
This Policy explains how PITON-Global Inc. collects, uses, discloses, and safeguards personal information when you visit our website or engage our advisory services, and describes the rights available to you under applicable U.S. state privacy laws and the EU/UK General Data Protection Regulation.
We collect only the information we need to respond to your inquiries and deliver our advisory services. We do not sell your personal information. You have the right to access, correct, and delete your information, and — depending on where you live — additional rights under the CCPA/CPRA and the GDPR. The full Policy below explains each in detail.
1. Scope & Who We Are
This Privacy Policy (the “Policy”) applies to personal information processed by PITON-Global Inc., a Philippine corporation (“PITON-Global,” “we,” “us,” or “our”), in connection with our website, communications, and advisory services (collectively, the “Services”). For the purposes of applicable data-protection law, PITON-Global acts as the “controller” (or “business”) of the personal information described in this Policy. This Policy does not apply to the practices of any third-party Provider or website that we do not own or control.
2. Information We Collect
We collect personal information that you provide to us, that is generated automatically through your use of the Services, and that we receive from third parties. The categories include:
- Identity & contact data — name, job title, employer, business email address, business telephone number, and postal address;
- Inquiry & engagement data — the contents of forms, requests for proposals, requirements you share, and correspondence with us;
- Usage & device data — IP address, browser type, operating system, referring URLs, pages viewed, and dates and times of access, collected automatically through cookies and similar technologies;
- Marketing & communications data — your preferences in receiving communications from us;
- Third-party data — information from business-contact databases, analytics providers, and publicly available sources.
We do not intentionally collect special categories of sensitive personal information through the Services, and we ask that you not submit such information to us unless specifically requested in the context of an engagement.
3. How We Use Your Information
We use personal information to: (a) provide, operate, and maintain the Services; (b) respond to your inquiries and deliver advisory and vendor-sourcing support; (c) communicate with you, including sending administrative information and, where permitted, marketing communications; (d) improve, personalize, and analyze the Services; (e) maintain the security and integrity of the Services and prevent fraud; (f) comply with legal obligations and enforce our agreements; and (g) establish, exercise, or defend legal claims. We do not use your personal information for automated decision-making that produces legal or similarly significant effects without a lawful basis and appropriate safeguards.
4. Legal Bases for Processing (EEA/UK)
Where the GDPR applies, we rely on the following legal bases: (i) consent, which you may withdraw at any time; (ii) performance of a contract with you or to take steps at your request before entering into a contract; (iii) compliance with a legal obligation to which we are subject; and (iv) our legitimate interests, namely operating and growing our business, securing the Services, and communicating with business contacts, provided such interests are not overridden by your rights and freedoms.
5. Cookies & Tracking Technologies
We and our service providers use cookies, web beacons, and similar technologies to operate the Services, remember your preferences, understand usage, and improve performance. You can set your browser to refuse some or all cookies, or to alert you when cookies are being sent; however, certain portions of the Services may not function properly without them. Where required by law, we obtain your consent before placing non-essential cookies. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), where applicable.
6. How We Disclose Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may disclose personal information in the following circumstances:
- Service providers. To vendors and contractors who perform services on our behalf — such as hosting, analytics, email delivery, and customer-relationship management — under contractual obligations of confidentiality and data protection;
- Professional advisors. To our auditors, lawyers, bankers, and insurers where necessary in the course of the professional services they render to us;
- Business transfers. In connection with a merger, financing, acquisition, reorganization, or sale of assets, or in the event of insolvency, in which personal information may be transferred as a business asset;
- Legal compliance & protection. Where required by law, regulation, legal process, or governmental request, or to enforce our agreements and protect the rights, property, or safety of PITON-Global, our users, or others.
7. International Data Transfers
PITON-Global is headquartered in the United States, and we operate across a global delivery footprint. Your personal information may be transferred to, stored, and processed in the United States and other countries that may not provide the same level of data protection as your jurisdiction. Where we transfer personal information out of the EEA, the United Kingdom, or Switzerland, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to protect that information consistent with applicable law.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including to provide the Services, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we will delete, anonymize, or de-identify it in accordance with our retention schedules and applicable law.
9. Information Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include access controls, encryption in transit, network protections, and ongoing monitoring. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials used to access the Services.
10. Your U.S. State Privacy Rights (CCPA/CPRA & Others)
Depending on your state of residence — including California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws — you may have the following rights, subject to certain exceptions:
To exercise these rights, contact us at contactus@piton-global.com. We will verify your request consistent with applicable law, and you may use an authorized agent to submit a request on your behalf. We will not discriminate against you for exercising any of your rights. If we deny your request, you may appeal by replying to our response; where required, you may also contact your state attorney general.
11. Your Rights Under the GDPR (EEA/UK)
If you are located in the EEA or the United Kingdom, you have the rights to: access your personal information; request rectification or erasure; restrict or object to processing; data portability; and to withdraw consent at any time without affecting the lawfulness of prior processing. Where you believe our processing infringes data-protection law, you have the right to lodge a complaint with your local supervisory authority. We will respond to all requests consistent with applicable law and without undue delay.
12. Children’s Privacy
The Services are directed to businesses and professionals and are not intended for children under the age of sixteen (16). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child, we will take reasonable steps to delete it. If you believe a child has provided us with personal information, please contact us at contactus@piton-global.com.
13. Third-Party Links & Services
The Services may contain links to third-party websites, Providers, plug-ins, and applications that we do not operate or control. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We are not responsible for, and this Policy does not apply to, the privacy practices of any third party. We encourage you to read the privacy policy of every website you visit.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will revise the “Last Updated” date above and, where required by law, provide additional notice or seek your consent. Your continued use of the Services after a revised Policy becomes effective constitutes your acknowledgment of the changes to the extent permitted by law.
15. How to Contact Us
If you have questions about this Policy or wish to exercise your privacy rights, please contact our privacy team:
Privacy & Data Requests: contactus@piton-global.com
Telephone: +1 402-598-8740