Cybersecurity, Compliance, and Virtual CIO as a Service – Red Cup IT, Inc.

Privacy Policy

Red Cup IT, Inc.

Version 2.1 | Last Updated: June 25, 2026

Purpose

We at Red Cup IT (Red Cup IT, Inc. and our subsidiaries and affiliates) are committed to protecting your privacy. This privacy policy applies to our websites, products, and services (as defined below, collectively, our “Services”). This privacy policy (“Privacy Policy”) explains how we collect, use, and disclose Personal Data.

This Privacy Policy governs our data collection, processing, and usage practices. It also describes your choices regarding using, accessing, and correcting your personal information. If you disagree with the data practices described in this Privacy Policy, you should not use our Services.

1.0 Sources of the Information We Collect

This Privacy Policy outlines the types of information we gather as part of our Service, encompassing:

  • Our internet sites (www.redcupit.com), along with our emails and marketing communications;
  • Data obtained via our commercial allies and suppliers; and
  • Data collected through our service offerings (Red Cup IT Services).

2.0 Information We Collect About You

We may collect Personal Information, Usage, and Device Information (collectively, “information”) about you in connection with your (or your organization’s) use of our Services that link to this Privacy Policy.

2.1 Account Information

Some information is required to create an account on Services, such as your name, email address, password, company, and phone number.

2.2 Additional Information

To help improve your experience or enable certain features of the Services, you may choose to provide us with additional information, such as a profile photo, biography, mailing address, country information, mobile phone numbers, or social media username. We do not collect sensitive personal data (such as government identification numbers, financial account details, health information, or biometric data).

2.3 Information We Collect or Generate About You

  • Maintain a file of your interaction history for inquiry purposes to ensure satisfaction with our Services;
  • Via our security offerings, generate traffic and security analyses detailing the internet behaviors of the organization’s computer users (for example, tracking which sites were accessed by each user, any documents downloaded, security events, and the protective actions executed by the gateway);
  • Data on actions taken with secured documents, including changes to a document’s permissions and details about who carried out these actions;
  • Details about you gathered from external sources;
  • Management of Email & Office services, encompassing files and email exchanges (including the content within) present in your accounts associated with such services.

2.4 Information Provided by Other Individuals

While using our Services, individuals may provide information about another individual, or an authorized user (such as an account administrator) creating an account on your behalf may provide information about you. Any individual providing personal information about another person must confirm they have the legal authority and consent to do so, and must ensure that the other individual is informed about how their data will be used in accordance with this Privacy Policy. Please contact us immediately at infosec@redcupit.com if you become aware of unauthorized disclosure of another individual’s personal information, and we will act consistently with this Privacy Policy.

3.0 Cookies and Similar Technologies

We may use “cookies” and similar technologies to help deliver our Services. This technology may involve placing small files/code on your device or browser that serve a number of purposes, such as remembering your preferences and offering you a more personalized user experience. We encode our cookies so that only we can interpret the information stored in them. You may manage or withdraw your cookie consent at any time via our cookie preference center or your browser settings. Declining non-essential cookies may interfere with some website features.

4.0 Marketing and Analytics Communication

We work with partners who provide us with marketing analytics and communications services. This includes helping us understand how users interact with our Services, communicating with you about our Services and features, and measuring the performance of those communications. These companies may use cookies and similar technologies, only with your prior consent to collect information about your interactions with the Services and other websites and applications. To learn more about your privacy choices, please see the How We Use Your Information and How We Share Your Information sections below.

5.0 How We Use Your Information

5.1 Red Cup IT may process your Personal Data for various purposes, including:

  • Continuously reviewing and enhancing the information on Red Cup IT websites to make them user-friendly and safeguard against potential interruptions or cyber threats;
  • Enabling your access to the functionalities offered by Red Cup IT Services;
  • Evaluating your application for Red Cup IT Products and Services, as relevant;
  • Configuring customer access to Red Cup IT applications and Services;
  • Registering and onboarding new users on our platforms;
  • Performing analyses necessary to identify malicious data and its potential impact on your IT systems;
  • Statistically monitoring and analyzing current attacks on devices and systems, and adjusting our solutions to protect against these threats;
  • Gathering feedback on Red Cup IT Products and Services to enhance the ease and speed of obtaining information on their use;
  • Communicating with you to provide our Services, information about our offerings, or marketing materials;
  • Sending email updates about the latest cybersecurity trends, news, events, and other promotional content (with your consent where required);
  • Conducting thorough threat analyses;
  • Understanding your needs and preferences for better service delivery;
  • Managing and administering our business operations;
  • Improving our products and services;
  • Ensuring compliance with legal and regulatory requirements and internal policies;
  • Data backup and loss prevention.

5.2 In processing Personal Data, Red Cup IT confirms the existence of a valid legal basis, such as:

  • Fulfilling our contractual duties;
  • Obtaining explicit consent;
  • Meeting legal or regulatory obligations;
  • Protecting or asserting our legal rights;
  • Legitimate business interests, which include:
    • Efficiently managing and administering our business operations;
    • Adhering to internal policies and procedures;
    • Monitoring the usage of our copyrighted content;
    • Facilitating easy access to information about our Services;
    • Providing optimal, current security solutions;
    • Offering email updates on our Services, cybersecurity trends, news, events, and promotional content; and
    • Gaining insights into current network threats to enhance our security solutions.

5.3 Red Cup IT commits to ensuring that your Personal Data is accessed solely by individuals who need to do so for the purposes outlined in this Privacy Policy.

6.0 How We Share Your Information

We may share your information with our business units, affiliates, business partners, service providers (including cloud hosting providers, analytics platforms, and cybersecurity tool vendors), and/or your representatives, to provide or improve our Services to you.

We do not share information with third parties so that they can independently market their own products or services to you unless we have explicitly given you the option to opt in to such disclosures.

We may share your information with companies that we plan to merge with or be acquired by. Should such a situation arise, we will require that the new entity follow this Privacy Policy with respect to your personal information. If your personal information could be used contrary to this policy, you will receive prior notice.

We may share your information with law enforcement, government officials, or third parties when we are compelled to do so due to legal procedures, to comply with the law, or with your consent or at your direction.

Red Cup IT will never sell your Personal Information to any third party.

7.0 International Data Transfers

Red Cup IT is a U.S.-based company that offers our Services to U.S. and international customers. As a result, information that we collect, including personal information, may be transferred to our data centers or service providers in the U.S.

For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States or other jurisdictions, we rely on the following legal transfer mechanisms:

  • EU-U.S. Data Privacy Framework (DPF): Red Cup IT complies with the EU-U.S. Data Privacy Framework as administered by the U.S. Department of Commerce. Our compliance can be investigated and enforced by the U.S. Federal Trade Commission.
  • Standard Contractual Clauses (SCCs): Where required, we execute the European Commission’s approved Standard Contractual Clauses with our service providers and data processors.
  • UK International Data Transfer Agreements (IDTAs): For transfers from the United Kingdom, we rely on the UK IDTA or UK Addendum to the EU SCCs, as applicable.

If you have a concern about the transfer of your data, please contact us at infosec@redcupit.com.

8.0 Your Rights Regarding Your Personal Information

We provide you with the opportunity to be informed of whether we are processing your information and to access, correct, update, oppose, delete, block, limit, or object, upon request and free of charge, to our use of your Personal Information to the extent required by applicable law.

You can unsubscribe from our promotional emails via the link provided in the emails. Even if you opt out of receiving promotional messages from us, you will continue to receive administrative messages from us.

We will respond to all verified rights requests within 30 days of receipt. In complex cases, we may extend this period by a further 30 days and will notify you of any such extension with the reason for the delay.

Your European Privacy Rights

  • You may request access to the Personal Data we maintain about you, update and correct inaccuracies, restrict or object to the processing of your Personal Data, have your Personal Data anonymized or deleted, as appropriate, or exercise your right to data portability to easily transfer your Personal Data to another company.
  • You have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work, or where an incident took place.
  • You may withdraw any consent you previously provided to us regarding the processing of your Personal Data at any time and free of charge. We will apply your preferences going forward, and this will not affect the lawfulness of processing before your withdrawal.
  • You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you.

Your California Privacy Rights

The right to know and access: You have the right to be notified about which categories of personal data are being collected, the purposes for which they are being used, and to request disclosure of the specific pieces of personal data we hold about you.

The right to correct: Under the CPRA, you have the right to request that we correct inaccurate personal information we maintain about you.

The right to opt out of sale or sharing: You have the right to direct us not to sell or share your personal data. To submit an opt-out request, please email infosec@redcupit.com. Note that any opt-out is specific to the browser you use; you may need to opt out on every browser you use.

The right to delete: Once a request is received from you, we will delete (and direct our service providers to delete) your personal data from our records unless an exception applies, such as completing a transaction, legal compliance, or preventing fraud.

The right to limit use of sensitive personal information: Although we do not collect sensitive personal information, you have the right to limit its use if we ever do so in the future.

The right not to be discriminated against: You have the right not to be discriminated against for exercising your consumer rights.

California Privacy Rights for Minor Users: California Business and Professions Code Section 22581 allows California residents under the age of 18 who are registered users of online sites, services, or applications to request removal of content or information that has been publicly posted. To request removal of such data, please contact infosec@redcupit.com.

You may exercise these rights by contacting us at infosec@redcupit.com. Before fulfilling your request, we may ask you to provide reasonable information to verify your identity. Please note there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases promptly, we may retain Personal Data for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe we have a legitimate reason to do so.

9.0 Retention of Your Information

We keep your account information, like your name, email address, and password, for as long as your account is in existence because we need it to operate your account.

Upon termination, deletion or expiration of your account or contract, we will retain your Personal Data for a period of 3 years, after which it will be securely deleted or anonymized, unless:

  • A longer retention period is required by applicable law or regulation;
  • The data is needed to resolve a dispute or enforce a legal agreement; or
  • You have provided consent for a longer retention period.

In some cases, when you provide information for a specific feature of the Services, we delete the data after it is no longer needed for that feature. We also keep information about you and your use of the Services for as long as necessary for our legitimate business interests, for legal reasons, and to prevent harm.

10.0 Security of Your Information

We work hard to keep your data safe. We use a combination of technical and administrative controls to protect the confidentiality, integrity, and availability of your data in compliance with applicable federal and state regulations. This includes using Transport Layer Security (“TLS”) to encrypt data transmission and Advanced Encryption Standard (“AES”) to encrypt data storage. No method of transmitting or storing data is completely secure, however. If you have a security-related concern, please contact our Security team at infosec@redcupit.com.

11.0 “Do Not Track” Policy (CalOPPA)

Our Service does not currently respond to Do Not Track (DNT) signals, as there is no universally accepted standard for how companies should respond to such signals. However, you may manage your tracking preferences through our cookie preference center or your browser’s privacy settings. Some third-party websites may also track your browsing activities independently.

12.0 Situations Where This Privacy Policy Does Not Apply

This Privacy Policy does not apply to job applicants or employees, which are subject to relevant privacy notices. This Privacy Policy does not apply to the extent that:

  • Our products and services set forth an additional or alternative Privacy Policy; or
  • Applicable law imposes different processing or privacy requirements on your information.

13.0 Changes to This Privacy Policy

We periodically update this Privacy Policy. We will notify you of any material changes by posting the updated policy on this page and, where required by law or where feasible, by sending you a notification via email or a prominent notice within our Services. We encourage you to review this Privacy Policy periodically. We will also keep prior versions of this Privacy Policy in an archive for your review.

Questions, Concerns, and Updates

If you need further assistance regarding your rights or have any privacy-related questions or concerns, please contact our Data Protection Officer:

Email: infosec@redcupit.com
Website: www.redcupit.com

We will consider your request under applicable laws and respond within 30 days of receipt.