Privacy Policy
Effective Date: March 29, 2026
1. Introduction
Decision & Law LLC ("Company", "we", "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website decisionandlaw.com (the "Site").
We comply with the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA) and the California Consumer Privacy Act (CCPA) for residents of California.
2. Information We Collect
2.A No User Registration or Mandatory Data Collection
We do not require or maintain user accounts. We do not collect personal information through:
- User registration
- Account profiles
- Mandatory login systems
Decision & Law is a read‑only, public information platform. You do not need to provide any information to access our content.
2.B Voluntarily Provided Information – Email Inquiries
If you voluntarily contact us via email, we collect:
- Your name
- Your email address
- Your message content
- Any attachments you send
- IP address and timestamp of your email
Where to contact: artificialderecho@gmail.com
Legal Basis: Your explicit consent to communicate with us and our legitimate interest in responding to inquiries.
Retention: We retain email correspondence for the duration of our conversation, plus 12 months for compliance and dispute resolution purposes. After 12 months, we delete your email unless required to retain for legal reasons.
Use: We use your information only to: respond to your inquiry, troubleshoot issues, address your concern or request, and improve our services based on feedback.
We will NOT: share your email with third parties, use your email for marketing or promotional purposes, sell your contact information, or add you to mailing lists without explicit consent.
2.C Automatically Collected Information (Usage Data)
When you visit the Site, our web server and analytics tools automatically collect:
- IP address (partially anonymized by Google Analytics)
- Browser type and version
- Operating system
- Device type
- Pages visited and time spent on each page
- Referrer URL
- Approximate geographic location (country and city level)
- Timestamp and duration of your visit
- Links clicked within the Site
Data Minimization: IP Anonymization enabled, No Cross‑Device Tracking, No User Profiling, No Sensitive Data Collection.
Legal Basis: GDPR (EEA users): Legitimate interest (Article 6.1.f). CCPA (California residents): Your visit constitutes reasonable notice and opt‑in.
Retention: Usage data retained for 13 months in Google Analytics. Server logs purged after 30 days. Aggregated analytics may be retained indefinitely.
2.D Information We Do NOT Collect
We do not collect: credit card or payment information, phone number (unless voluntarily provided), full name (unless voluntarily provided), precise location data, biometric or health information, browsing history outside of our Site, cross‑site tracking data, or email addresses unless you contact us.
3. Cookies and Tracking Technologies
3.A What Are Cookies
Cookies are small text files placed on your device when you visit a website.
3.B How We Use Cookies
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Required for Site security, SSL/TLS encryption, load balancing | Session |
| Analytics | Collect anonymized data about site traffic via Google Analytics and Vercel Analytics | 2 years |
| Marketing | We currently do NOT use marketing or conversion tracking cookies | N/A |
3.C Cookie Consent and Your Choices
Upon your first visit to the Site, you will see a Cookie Consent Banner with the following options:
- Accept All Cookies: Accepts both essential and analytics cookies.
- Reject Non‑Essential: Accepts only essential cookies.
- Customize Preferences: Opens a detailed menu where you can individually accept or reject analytics cookies.
Your preference is stored in a cookie on your device and is respected across visits for up to 12 months. You can change your preferences at any time using the "Cookie Preferences" link in the footer.
3.D Third‑Party Analytics Providers
Google Analytics 4: Collects aggregated data about how visitors interact with the Site. Data shared: Anonymized IP address, browser type, device type, pages visited, time on Site. Retention: 13 months. Opt‑out: Google Analytics Opt‑out Browser Add‑on
Vercel Analytics: Collects anonymized performance metrics about Site reliability and speed. Data retention: 30 days.
3.E Do Not Track (DNT)
We do not respond to DNT signals because we already provide explicit cookie consent controls and do not engage in cross‑site tracking. You can manage your preferences via our Cookie Banner.
4. Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis | Your Rights |
|---|---|---|
| Responding to email inquiry | Your explicit consent | Right to erasure, access, portability |
| Analytics cookies | Your explicit consent | Right to withdraw consent |
| Usage tracking | Legitimate interest | Right to object, access, erasure |
| Retaining email for 12 months | Legitimate interest | Right to erasure (subject to legal holds) |
5. Your Rights and How to Exercise Them
5.A Right to Access (GDPR Art. 15 / CCPA § 1798.100)
You may request a copy of all personal data we hold about you. How to request: Email artificialderecho@gmail.com with subject line: "GDPR Access Request" or "CCPA Access Request". Timeline: We will respond within 10 business days with your data in a structured, portable format.
5.B Right to Rectification (GDPR Art. 16)
If personal data we hold is inaccurate or incomplete, you may request correction.
5.C Right to Erasure (GDPR Art. 17 / CCPA § 1798.105)
You may request deletion of personal data we hold about you. We will delete the data unless we have a legal obligation to retain it.
5.D Right to Restrict Processing (GDPR Art. 18)
You may ask us to pause processing of your data while we verify accuracy or resolve a dispute.
5.E Right to Data Portability (GDPR Art. 20 / CCPA § 1798.100)
You may request your data in a machine‑readable format to transfer to another service.
5.F Right to Object (GDPR Art. 21)
You may object to processing of your data for legitimate interests, including analytics.
5.G Right to Opt‑Out of "Sale" or "Sharing" (CCPA § 1798.100 / CPRA)
Decision & Law does NOT sell or share personal information for marketing purposes. To opt out of analytics "sharing", use our Cookie Banner or email artificialderecho@gmail.com with subject: "CCPA Opt‑Out".
5.H Right to Nondiscrimination (CCPA § 1798.125)
We will not discriminate against you for exercising your privacy rights.
5.I Right to Appeal (GDPR Art. 77)
If you believe we have violated your privacy rights, you have the right to lodge a complaint with the relevant data protection authority.
6. Data Security
We implement industry‑standard technical and organizational measures: Encryption in Transit (HTTPS/SSL 256‑bit), Web Application Firewall, Access Controls, Data Minimization, Regular Audits.
No transmission over the Internet is 100% secure. If a security breach occurs, we will investigate promptly and notify affected users within 72 hours as required by law.
7. Children's Privacy (COPPA Compliance)
Our Site is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will delete that information immediately.
8. International Users
If you are located outside the United States, your personal data may be transferred to and processed in the United States. By using the Site, you consent to such transfers. For EEA Users: Transfers are governed by Standard Contractual Clauses (SCCs). We have implemented supplementary measures (IP anonymization, data minimization) to mitigate risks.
9. Third‑Party Links and Services
The Site may link to third‑party websites. We are not responsible for their privacy practices. Review their privacy policies before providing information.
10. Data Retention Schedule
| Data Type | Retention Period | Reason |
|---|---|---|
| Email communications | 12 months after last communication | Compliance and dispute resolution |
| Analytics data | 13 months | Site improvement |
| Server access logs | 30 days | Security and troubleshooting |
| Cookies (essential) | Session | Required for site to function |
| Cookies (analytics) | 2 years | User consent basis |
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be effective upon posting. If material changes occur, we will provide prominent notice.
12. Contact Us
For privacy‑related questions, requests, or complaints:
Email: artificialderecho@gmail.com
Subject Line Examples: "GDPR Access Request", "CCPA Opt‑Out Request", "Privacy Complaint"
We will acknowledge your request within 10 business days and fulfill it according to the applicable legal timeline (30 days GDPR, 45 days CCPA).
Last Updated: March 29, 2026