CloudPGP | Keystone Management Group LLC
Privacy Policy
1. Who we are
CloudPGP is a website operated by Keystone Management Group LLC (“Keystone,” “we,” “us,” or “our”). The website is available at https://cloudpgp.com/ and provides information about cloud-hosted email encryption, including PGP and S/MIME technologies.
Data controller for this website:
Keystone Management Group LLC2220 County Road 210, Suite 108
Jacksonville, Florida 32259
United States
For privacy questions and requests concerning your personal data, use the contact form at https://cloudpgp.com/contact/ or write to the postal address above. Please do not submit sensitive personal information through the public contact form.
This notice covers personal data handled in connection with the public CloudPGP website. It does not describe processing of customers’ encrypted email, encryption keys, certificate material, or service-platform accounts by the underlying Echoworx platform. Applicable service documentation and contractual data-processing terms govern those activities separately.
2. Information we collect
We may process the following categories of personal data when you use the website:
- Information you provide: Your name, business email address, organization, contact details and the contents of an inquiry, support request or other message you send through a website form.
- Technical and security information: IP address, request date and time, requested page or resource, browser or device information, referring URL, security events, and related server or content-delivery logs necessary to serve and protect the website.
- Cookie and preference information: Essential website settings and the choices you make in the cookie-preference interface; optional analytics or similar data only if such technologies are implemented and the applicable consent requirements are satisfied.
- Correspondence: Messages and records of follow-up communications when we respond to you.
We do not ask visitors to provide passwords, private encryption keys, payment-card information or special-category personal data through public website forms. Please do not include such information in submissions.
3. Purposes and lawful bases
Under the EU General Data Protection Regulation (GDPR), we process personal data only where a lawful basis applies:
| Purpose | Lawful basis |
|---|---|
| Responding to contact, product and support inquiries | Legitimate interests in communicating with people who contact us (Article 6(1)(f)); pre-contractual steps at your request where applicable (Article 6(1)(b)) |
| Operating and securing the website, preventing abuse and investigating malicious requests | Legitimate interests in maintaining a safe, functioning website (Article 6(1)(f)) |
| Remembering essential privacy or interface settings | Legitimate interests in operating requested website functions (Article 6(1)(f)); compliance with legal obligations where applicable (Article 6(1)(c)) |
| Setting or reading nonessential cookies and using associated analytics or similar tools | Consent, where required (Article 6(1)(a) and applicable electronic-communications rules) |
| Responding to data-protection requests and fulfilling applicable legal requirements | Legal obligation (Article 6(1)(c)) |
Where processing is based on legitimate interests, we consider the necessity of the processing and its effect on your rights. You may object in the circumstances described below.
4. Forms and service providers
Our public contact forms are designed to use Formspree for form submission and delivery. Submitting a form will transmit the information you enter and associated technical data to the form-processing provider so that your message can be delivered and handled. Do not send confidential encryption material or regulated sensitive information through these forms.
The website may use Cloudflare for content delivery and protection against abusive traffic. Cloudflare may process network and security data, including IP addresses, to operate its services. Website hosting and infrastructure providers may also process technical data where necessary to deliver the site.
We disclose personal data to service providers only for legitimate operational purposes, subject to appropriate contractual and security protections where required, and to authorities or other recipients where disclosure is legally required. We do not sell personal data.
5. International transfers
Keystone is located in the United States. Website messages, technical information and other personal data may therefore be processed outside the European Economic Area, including in the United States. Some service providers may also process information in multiple countries. Where GDPR transfer restrictions apply, we must rely on an applicable adequacy decision, approved contractual safeguards such as the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with any required supplementary protections. The precise safeguards depend on the provider and processing arrangement. You may request information about applicable safeguards using the contact details above.
6. Retention
We keep personal data only for as long as necessary for the purposes described in this notice, applying the following criteria:
- Inquiry and correspondence records are retained while an inquiry is active and thereafter for the period reasonably necessary to maintain business records, resolve disputes or satisfy applicable legal obligations.
- Technical and security logs are retained according to operational security requirements and the retention settings of the relevant infrastructure provider, then deleted or anonymized when no longer needed.
- Cookie-preference choices remain until they expire, are cleared, or you change your settings, subject to the consent-management configuration.
- Records needed to meet legal obligations or defend legal claims may be kept longer when justified.
We do not promise a specific retention period where the live service configuration has not established one. Upon a valid request, we will explain the applicable retention period or criteria as required by law.
7. Cookies and similar technologies
Please see our Cookie Policy for information about essential and optional cookies, purposes, controls and consent. Where required by applicable law, nonessential cookies and comparable tracking technologies must not be activated until you give valid consent. You can withdraw that consent through Cookie settings in the website footer.
8. Your data-protection rights
Subject to the conditions and exceptions in applicable law, individuals in the EEA may have the right to:
- Obtain access to their personal data and information about its processing.
- Request correction of inaccurate or incomplete data.
- Request erasure of personal data.
- Request restriction of processing.
- Receive data in a portable format where the portability right applies.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Object to direct marketing, if any is conducted.
- Lodge a complaint with a competent supervisory authority in an EU or EEA country.
We do not use website-submission data for decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
To exercise your rights, contact us through https://cloudpgp.com/contact/ or by post. We may need to verify your identity before acting. We will respond within applicable legal time limits, generally one month under GDPR, subject to permitted extensions.
9. Security
We use technical and organizational measures appropriate to the risks associated with operating a public informational website. No transmission or storage environment can be guaranteed completely secure. Public web forms are not intended as a secure channel for transmitting private keys or highly sensitive data.
10. Children
The CloudPGP website is designed for professional and organizational audiences, not children. We do not intentionally solicit personal data from children through this website. If you believe a child has submitted personal data, please contact us.
11. Third-party websites
Links to third-party websites are provided for convenience. Their data practices are governed by their own notices, not this policy.
12. Changes to this notice
We may update this policy when the website, service providers or applicable legal obligations change. The revised version will be posted here with its effective date. Material changes will be communicated as legally required.
13. Contact
2220 County Road 210, Suite 108
Jacksonville, Florida 32259
United States
Contact CloudPGP