Privacy Policy

Last Updated: August 19, 2026

Scope of This Privacy Policy

SACA Technologies, Inc. dba IronOrbit (“IronOrbit,” “we,” “our,” or “us”) is committed to handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information we control in connection with our website, marketing activities, and managed information technology services (collectively, the “Services”).

This Policy applies to personal information about website visitors, prospective customers, customer contacts, business partners, and other individuals whose information we process for our own business purposes (“Business Personal Information”). It also explains, at a high level, our role when we process personal information for a customer while providing managed services (“Customer Data”).

Customer Data and Our Role as an MSP

IronOrbit provides managed IT, support, cybersecurity, and related services to organizations. In providing those Services, authorized IronOrbit personnel may access, store, transmit, or otherwise process Customer Data, which may include information in support tickets, communications, attachments, security logs, device inventories, email systems, remote-support sessions, and other customer-managed systems.

For Customer Data, the applicable customer generally determines the purposes and means of processing and is responsible for providing privacy notices to its employees, customers, and other individuals. IronOrbit acts as a service provider or processor on the customer’s behalf and processes Customer Data only as authorized by the applicable customer agreement, documented instructions, and applicable law. The customer’s privacy notice and contract with IronOrbit govern Customer Data. Individuals seeking to exercise privacy rights relating to Customer Data should contact the relevant customer directly; IronOrbit will assist the customer as required by the applicable agreement and law.

Personal Information We Collect

We may collect the following categories of Business Personal Information: identifiers and contact information, such as name, business email address, telephone number, company, job title, and business address; professional information, such as role and company affiliation; commercial information, such as information about an inquiry, account, or Services requested or received; communications, such as information included in a webform, email, support request, or other correspondence; and internet or other electronic network activity, such as IP address, browser type, operating system, referring pages, device information, website interactions, and date/time information.

We collect Business Personal Information directly from you, from your organization or its representatives, through our website and Services, and from business partners, service providers, or publicly available sources where permitted by law. We may also receive information from a customer or its authorized users in connection with establishing, administering, supporting, or securing the Services.

How We Use Personal Information

We use Business Personal Information to respond to inquiries; provide, operate, maintain, support, secure, and improve the Services; manage our business relationships and customer accounts; communicate service, account, transactional, and marketing information; understand website and Service use; prevent fraud, misuse, security incidents, and other unlawful activity; comply with legal obligations; establish, exercise, or defend legal claims; and complete a merger, acquisition, financing, or similar corporate transaction.

We do not offer text-message marketing, push notifications, consumer self-service accounts, or public account activity through the Services. We will not use Business Personal Information for materially different purposes without providing notice or obtaining consent when required by law.

How We Disclose Personal Information

We may disclose Business Personal Information to service providers that support our operations, including providers of customer relationship management, marketing automation, and professional services automation/ticketing systems. We may also disclose information to professional advisers, insurers, auditors, government authorities or other parties when required or permitted by law, and parties involved in a corporate transaction. We require service providers to process information only for authorized purposes and under appropriate contractual safeguards.

We may use and disclose aggregated or de-identified information where permitted by law. We do not sell personal information and do not share personal information for cross-context behavioral advertising or other targeted advertising purposes.

Cookies and Analytics

Like most websites, we use cookies and similar technologies to operate our website and understand how it is used. We use Google Analytics to collect information about website usage, including the pages viewed, browser and device information, and general interaction data. Google Analytics uses cookies and similar technologies as described in Google’s privacy materials.

You may control cookies through your browser settings. Disabling cookies may affect certain website features. Because IronOrbit does not sell or share personal information for targeted advertising, we do not use website data for cross-context behavioral advertising.

Security and Incident Response

We use reasonable administrative, technical, and physical safeguards designed to protect Business Personal Information and Customer Data from unauthorized access, use, alteration, and disclosure. Our safeguards are designed to be appropriate to the nature of the information and the risks involved. No system or transmission is completely secure, and we cannot guarantee absolute security.

If we become aware of an incident involving Business Personal Information that we control, we will investigate and provide notice as required by applicable law. If an incident involves Customer Data, we will work with the affected customer in accordance with the applicable agreement and law.

Retention

We retain Business Personal Information for as long as reasonably necessary for the purposes described in this Policy, including to provide and support the Services, maintain business records, comply with legal obligations, resolve disputes, and enforce agreements. We may retain limited information for longer periods where required or permitted by law.

Customer Data is retained and deleted or returned in accordance with the applicable customer agreement, documented customer instructions, legal obligations, and our backup and disaster-recovery processes. Backup copies may persist for a limited period while they remain protected and are not used for active processing.

California Privacy Rights

This section supplements this Policy for California residents to the extent the California Consumer Privacy Act, as amended (“CCPA”), applies to IronOrbit’s processing of their Business Personal Information. In the preceding 12 months, we may have collected the following categories of Business Personal Information: identifiers; professional or employment-related information; commercial information; internet or other electronic network activity; and communications or other information you provide to us. We may disclose these categories for business purposes to the service providers and other recipients described in the How We Disclose Personal Information section.

IronOrbit does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information that we control for purposes that would trigger a right to limit under the CCPA. Customer Data that IronOrbit processes as a service provider is governed by the applicable customer agreement and the customer’s privacy notice.

Subject to applicable law and verification requirements, California residents may have the right to know/access personal information, request deletion, request correction, receive information about our disclosure practices, and not be discriminated against for exercising privacy rights. California residents may submit a request by emailing [email protected] or through our website contact form. An authorized agent may submit a request on a resident’s behalf, subject to appropriate verification and proof of authority. We will verify requests and respond within the period required by applicable law.

Children’s Privacy

Our website and Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe that a child has provided personal information to us in violation of this Policy, please contact us at [email protected] so that we may take appropriate action.

Regulated Customer Environments

IronOrbit may provide Services to customers in regulated industries, including healthcare, financial services, and government. Industry-specific privacy, security, confidentiality, and data-handling obligations are addressed through the applicable customer agreement and any required addendum or business associate agreement. This Policy does not replace those contractual or legal requirements.

United States Hosting and International Transfers

IronOrbit is based in California, and our data is hosted in the United States. Our current operations do not involve EU or UK personal-data transfers. If our services, data-hosting locations, or international processing activities change, we will update this Policy and our contractual safeguards as appropriate.

Changes to This Privacy Policy

We may update this Policy from time to time. We will post the updated version on our website and revise the “Last Updated” date. Where required by applicable law, we will provide additional notice of material changes.

Contact Us

If you have questions, comments, concerns, or a privacy request relating to this Policy, please contact us at [email protected].

IronOrbit
5101 E La Palma Ave
Anaheim Hills, CA 92807, USA