// scope
This policy applies to the website at empowered.guru and www.empowered.guru, to the consulting and software services provided by empowered.guru, LLC, and to the personal information we receive in operating those services. It does not apply to third-party services we link to or to data we process on behalf of a client under a separate Data Processing Agreement.
Last updated: August 16, 2026 · Effective immediately
1. Who is the controller
The data controller for the information described in this policy is empowered.guru, LLC, a California limited liability company (the "Company", "we", "us", "our"). Our principal place of business is in the State of California, United States. You can reach our privacy team at privacy@empowered.guru.
Where we process personal information on behalf of a client under a written services agreement, we act as the client's processor and the client is the controller. In that case, this policy does not describe the client's processing. The client's own privacy notice does, and any privacy request should be sent to the client directly.
2. Scope of this policy
This policy describes our handling of personal information collected through:
- This website, including the contact form, newsletter signup, blog, and chatbot.
- Email, calendar, messaging, and video-call communications with us.
- Engagements, invoices, and the back-office systems that support them.
- Recruiting, contractor onboarding, and alumni outreach.
It does not describe processing we perform as a processor under a client's Data Processing Agreement. That processing is governed by the DPA, not this policy.
3. What information we collect
We collect the following categories of personal information:
3.1 Information you give us directly
- Name, email, phone, company, role, country, and similar identifiers.
- Free-text content you send in forms, chat, email, or other messages.
- Billing and tax information (for invoicing), which we collect only when needed.
- Job-application content (CV, references, work samples) when you apply.
3.2 Information we receive from your device
- IP address, user agent, referrer, and approximate location derived from the IP.
- Pages visited, time on page, clicks, scroll depth, and similar usage events.
- Theme preference, cookie consent state, and other values in your browser's local storage.
3.3 Information from third parties
- Identity, profile, or company information from CRMs, recruiting tools, payment processors, and identity-verification providers.
- Calendar and meeting metadata (attendees, time, recording status) when you book a meeting with us.
3.4 Information we do not collect
We do not knowingly collect government identifiers (SSN, passport, driver license), financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, genetic data, health data, or sex-life or sexual-orientation information. If you choose to send us such information voluntarily in the course of an engagement, we treat it as confidential client material and protect it under the applicable Data Processing Agreement.
4. Where the information comes from
- Directly from you when you fill out a form, send a message, or join a call.
- From your browser when you load a page or interact with an embedded element.
- From service providers (CRM, scheduling, email, payment, hosting) that we use to operate the business.
- From public sources (your company website, LinkedIn, GitHub) when you have made the information public and we have a legitimate interest in preparing for a conversation.
5. Why we use the information
We use personal information for the following purposes:
- To respond to your inquiry or deliver the service you requested.
- To send you operational notices (booking confirmations, invoices, security alerts).
- To send you a newsletter or other marketing, only if you opted in, and to honor opt-out.
- To operate, secure, and improve the website and our internal tools.
- To meet legal, tax, accounting, and audit obligations.
- To enforce our agreements and protect our rights, users, and the public.
- To recruit and evaluate candidates, where you have applied for a role.
6. Legal basis (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR:
- Contract: to take steps at your request before entering a contract, and to perform the contract we have with you.
- Legitimate interests: to operate and improve our business, in a way that does not override your rights and freedoms.
- Consent: for marketing communications and for any optional cookies or analytics; you can withdraw consent at any time.
- Legal obligation: to comply with tax, accounting, anti-money-laundering, and law-enforcement requests.
7. How we share information
We do not sell personal information. We do not share personal information with third parties except as follows:
- Service providers (subprocessors) that process information on our behalf under a written contract that limits their use to the purpose we specify. The current list is published at /legal/subprocessors.
- Professional advisors (accountants, lawyers, insurers) bound by professional confidentiality.
- Government, law enforcement, or courts, when we believe in good faith that disclosure is necessary to comply with a law, court order, or valid subpoena, after challenging or narrowing the request where appropriate.
- A successor entity in the event of a merger, acquisition, reorganization, or sale of assets, with notice to you and the same level of protection.
- With your consent or at your direction, for any other purpose disclosed at the time of collection.
We do not share personal information with advertising networks, data brokers, or social-media platforms for cross-context behavioral advertising.
8. Subprocessors
We engage a small set of subprocessors to operate the business and deliver services. Each is contractually required to protect personal information at a level no less protective than this policy and applicable law. The current list, with the data each one processes and where they process it, is maintained at /legal/subprocessors. We provide advance notice of new subprocessors and a 15-day objection window for clients with a Data Processing Agreement.
9. Cookies and similar technologies
We use cookies and browser local storage for the categories described in our Cookie Policy: strictly necessary (consent state, theme preference), and optional analytics (Google Analytics 4, loaded only after consent). We do not use advertising cookies. You can manage cookies through our consent banner and your browser settings.
10. Retention
We retain personal information only for as long as needed for the purpose for which it was collected, plus a period required for tax, accounting, audit, legal-defense, and warranty obligations. Default retention windows are:
- Inquiry and contact-form submissions: 24 months from last contact.
- Engagement and contract records: 7 years from the end of the engagement.
- Financial and tax records: 7 years from the tax year (per IRS and FTB).
- Recruiting records for candidates we do not hire: 12 months from the application.
- Server logs and analytics events: 13 months from the event.
Where data is processed on behalf of a client under a DPA, retention is governed by the DPA and the client's documented instructions.
11. International data transfers
empowered.guru, LLC is based in the United States. When personal information of individuals in the European Economic Area, the United Kingdom, or Switzerland is transferred to us in the U.S., we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and equivalent safeguards where required. Where we transfer personal information to a subprocessor outside the country of origin, we apply the same or stronger safeguards. You can request a copy of the executed transfer mechanism by emailing privacy@empowered.guru.
12. Security
We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity. Specific controls include least-privilege access, audit logging, encryption in transit (HTTPS) and at rest where supported, mandatory code review, automated dependency scanning, and an incident-response procedure with notification commitments. Our full security posture is described at /security and our incident-response commitments are described at /legal/incident-response.
No system is perfectly secure. Where we determine that a security incident has materially affected your personal information, we will notify you and the competent authorities in accordance with applicable law.
13. Your rights
Depending on where you live, you may have some or all of the following rights with respect to your personal information:
- Access: request a copy of the personal information we hold about you.
- Correction: request that we correct inaccurate or incomplete information.
- Deletion: request that we delete your information, subject to our legal-record obligations.
- Portability: receive your information in a structured, commonly used, machine-readable format.
- Restriction or objection: restrict or object to certain processing.
- Withdraw consent: where processing is based on consent.
- Opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising, but you can confirm this on request.
- Non-discrimination: we will not penalize you for exercising your rights.
- Complain to a supervisory authority: you can lodge a complaint with the data-protection authority in your jurisdiction.
To exercise any right, email privacy@empowered.guru from the email address you want us to verify, and include enough context for us to locate your information. We respond within 30 days (45 days in California where extension is permitted).
14. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), provides the rights described in Section 13. Additional disclosures:
- Categories of personal information collected in the preceding 12 months: identifiers (name, email, phone, IP), commercial information (purchase history), internet activity (browsing on our website), geolocation (coarse, derived from IP), professional information (role, employer), and inferences (preferences).
- Categories of sources: directly from you; from your browser; from service providers.
- Business or commercial purposes: those described in Section 5.
- Categories shared: identifiers and internet activity are shared with our analytics and infrastructure subprocessors solely to operate the service. We do not sell or share for cross-context behavioral advertising.
- Retention: per Section 10.
- Shine the Light (Cal. Civ. Code § 1798.83): we do not share with third parties for their direct-marketing purposes.
15. Children's privacy
Our services are not directed to children under 16 (or under 13 in the United States), and we do not knowingly collect personal information from them. If you believe a child has provided us information, please email privacy@empowered.guru and we will delete it.
16. Changes to this policy
We may update this policy. When a change is material, we will provide reasonable notice before it takes effect, for example, by updating the effective date at the top, posting a notice on the homepage, or emailing clients with a Data Processing Agreement. The current version always lives at this URL.
17. Contact us
Questions, requests, and complaints about this policy can be sent to privacy@empowered.guru or by mail to:
empowered.guru, LLC
Attn: Privacy
California, United States
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data-protection authority. For EU residents, the list of supervisory authorities is at edpb.europa.eu; for UK residents, the Information Commissioner's Office at ico.org.uk.
