Legal & Compliance
Privacy Policy
Last Updated: August 21, 2026
WatchUr6, Inc. ("WatchUr6," "we," "us," or "our") is a veteran-owned cybersecurity firm headquartered in Folsom, California, providing audit readiness and related security services to organizations in healthcare, government contracting, and technology. Protecting information is our profession — and that discipline extends to how we handle your own. This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, and the rights you have over it. For the terms governing use of our website, see our Terms & Conditions.
01 Information We Collect
We collect information to respond to your inquiries, deliver our services, operate our website, and meet our legal and contractual obligations. The personal information we collect falls into two categories.
A. Information you provide to us directly
We collect information you voluntarily provide when you:
- Complete a contact or strategy-call form. This may include your first and last name, business email address, phone number, company name, job title, and the content of your message.
- Request a consultation, assessment, or proposal. When you inquire about our audit readiness services — such as SOC 2, HIPAA, or CMMC / NIST 800-171 preparation — we collect the information needed to scope and respond to your request.
- Subscribe to communications. If you opt in to our newsletter, the Sitrep, or other marketing, we collect your email address and, optionally, your name.
- Communicate with us. Any information you include when you contact us by email, phone, or other means.
B. Information we collect automatically
When you visit our website, we and our service providers may automatically collect certain technical information using cookies and similar technologies:
- Log and usage data. Your IP address, browser type and version, operating system, referring pages, the pages you visit, and the time, date, and duration of your visit.
- Cookies and tracking technologies. Small data files stored on your device that help the site function, remember your preferences, and measure usage. You can control cookies through your browser and, where offered, our cookie banner. See our Cookie Policy for detail on the specific cookies we use.
// A note on client engagement data
When we deliver services, a client may share information about its own systems, security posture, personnel, or — in regulated settings — data such as protected health information (PHI) or controlled unclassified information (CUI). We handle that information as a service provider / processor under the terms of the applicable engagement agreement, Business Associate Agreement, or data processing addendum, and we do not use it for our own purposes. This Privacy Policy governs the information described above; engagement data is governed by the relevant contract.
02 How We Use Your Information
We use the information we collect for the following purposes:
- To provide and maintain our services. Responding to your inquiries and fulfilling requests for information about our audit readiness and related security services.
- To communicate with you. Sending administrative messages, service updates, newsletters, and marketing you have asked to receive. You can opt out of marketing at any time using the unsubscribe link in our emails.
- To operate and improve our website. Understanding how the site is used so we can improve its performance, functionality, and content.
- For security and fraud prevention. Protecting the integrity of our site and systems, detecting and preventing malicious activity, and safeguarding our clients and personnel.
- To meet legal and contractual obligations. Complying with applicable law, enforcing our agreements, and responding to lawful requests from public authorities.
03 Our Legal Bases for Processing
Where the GDPR or UK GDPR applies (see Section 8), we rely on one or more of the following legal bases to process your personal information:
- Consent — for example, when you opt in to marketing communications. You may withdraw consent at any time.
- Contract — where processing is necessary to respond to your request or to perform a services agreement with you or your organization.
- Legitimate interests — to operate, secure, and improve our business and website, provided those interests are not overridden by your rights.
- Legal obligation — where we are required to process information to comply with the law.
04 How We Share Your Information
As a cybersecurity firm, we treat confidentiality as a core obligation. We do not sell your personal information. We share information only in the limited circumstances below:
- With service providers. Third parties that perform functions on our behalf — such as website hosting, customer-relationship management, email delivery, scheduling, and analytics. These providers are bound by contract to protect your information and to use it only to provide services to us. Our current providers include website hosting infrastructure, Google Analytics, and our CRM and marketing platform.
- For legal reasons. When required by law or in response to valid requests by public authorities, such as a court order or government demand.
- In a business transfer. In connection with a merger, acquisition, financing, or sale of assets, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.
- With your consent. For any other purpose disclosed to you and to which you consent.
05 Data Retention
We keep personal information only for as long as necessary to fulfill the purposes described in this policy, including to satisfy legal, accounting, tax, or reporting requirements. Retention periods vary by context:
- Inquiry and prospect data is retained while we are in contact and for a reasonable period afterward in case you re-engage, unless you ask us to delete it sooner.
- Client and contractual records are retained for the life of the engagement and for the period required by applicable law and our professional obligations.
- Marketing data is retained until you unsubscribe or request deletion.
When information is no longer needed, we securely delete or anonymize it.
06 Data Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect the personal information we process, including SSL/TLS encryption for data in transit and access controls appropriate to the sensitivity of the data. Security is our discipline, and we apply it to our own environment as rigorously as we do for clients.
That said, no method of transmission over the Internet or method of electronic storage is completely secure. While we work to protect your information using commercially acceptable means, we cannot guarantee its absolute security.
07 California Privacy Rights (CCPA / CPRA)
WatchUr6 is based in California and complies with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). If you are a California resident, you have the following rights regarding your personal information:
- Right to know / access. Request that we disclose the categories and specific pieces of personal information we have collected about you, and how we use and disclose it.
- Right to delete. Request deletion of the personal information we hold about you, subject to legal exceptions.
- Right to correct. Request correction of inaccurate personal information we maintain about you.
- Right to opt out of sale / sharing. We do not sell personal information. You may opt out of the "sharing" of personal information for cross-context behavioral advertising (see Section 7.1).
- Right to limit use of sensitive personal information. Direct us to limit the use and disclosure of any sensitive personal information to what is necessary to provide our services.
- Right to non-discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights.
7.1 Do Not Sell or Share My Personal Information
WatchUr6 does not sell your personal information for money, and we do not knowingly "sell" or "share" it as those terms are defined under the CCPA/CPRA. To the extent any analytics or advertising cookies could be considered "sharing" for cross-context behavioral advertising, you have the right to opt out. To exercise that right, email us at [email protected] with the subject line "Do Not Sell or Share," or adjust your cookie preferences where our cookie banner is available. We will also honor recognized opt-out preference signals (such as Global Privacy Control) where required.
To submit any California privacy request, contact us using the details in Section 11. We will verify your identity before acting on your request, and you may use an authorized agent to submit a request on your behalf.
08 European & UK Privacy Rights (GDPR / UK-GDPR)
WatchUr6 maintains a presence in the United Kingdom and may process the personal information of individuals in the United Kingdom and the European Economic Area. Where the EU GDPR or UK GDPR applies, you have the following rights over your personal information:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your data in certain circumstances ("right to be forgotten").
- Restriction — request that we limit how we process your data.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests or to direct marketing.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.
For the purposes of the GDPR and UK GDPR, WatchUr6, Inc. is the data controller of the personal information described in this policy. Where we transfer personal information out of the UK or EEA — for example, to our systems and service providers in the United States — we rely on appropriate safeguards, such as Standard Contractual Clauses, where required.
You have the right to lodge a complaint with your local supervisory authority, including the UK Information Commissioner's Office (ICO) or your EEA data protection authority. We would, however, appreciate the chance to address your concerns first — please contact us using the details below.
09 Children's Privacy
Our website and services are intended for businesses and professionals, and are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
10 Links to Other Websites
Our website may contain links to sites we do not operate. If you follow a link to a third-party site, you will be subject to that site's own privacy policy. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party sites or services. We encourage you to review the privacy policy of every site you visit.
11 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version on this page and update the "Last Updated" date above. Material changes may be communicated through additional notice where appropriate. We encourage you to review this policy periodically.
12 Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your privacy rights, contact us at:
WatchUr6, Inc.
- Phone+1 916-647-7553
- Email[email protected]
- Webwww.watchur6.com/contact
- Address1024 Iron Point Rd, Folsom, CA 95630, USA
Have a privacy request or a security question? Our team responds directly — no ticket maze.