Legal

Privacy Policy

This policy explains what information we collect through our website, how we use it, and the choices you have. It applies to darkanalytics.com and the marketing and contact features on it, not to client engagements governed by a separate agreement.

About This Policy

Important: This Privacy Policy is a general, plain-English template provided for transparency about how Dark Analytics handles information collected through our marketing website. It is not legal advice. It should be reviewed and tailored by qualified legal counsel before you rely on it. Privacy obligations vary by jurisdiction and by the specifics of how a business actually collects and uses data, and this document has not been adapted to every law that may apply.

Dark Analytics is a cybersecurity firm based in Tampa Bay, Florida, focused exclusively on healthcare. We secure hospitals, clinics, and connected medical devices (IoMT). This policy covers information gathered when you visit darkanalytics.com, submit a contact or inquiry form, or subscribe to updates.

This policy does not govern protected health information (PHI/ePHI) or other regulated data we may access while delivering services to a healthcare client. That information is handled under the contract, statement of work, and any Business Associate Agreement (BAA) in place for that engagement, consistent with the HIPAA Security Rule and the client's instructions. Nothing here changes those agreements.

Information We Collect

We collect only what we need to respond to you and operate the site. The information falls into a few simple categories.

Information you submit. When you fill out a contact or inquiry form, request an assessment, or email us, we receive the details you choose to provide. That typically includes your name, work email, phone number, organization, role, and whatever you write in the message. For a healthcare audience this often includes high-level context about your environment. Please do not include patient information or sensitive clinical data in a website form.

Subscription information. If you subscribe to updates or a newsletter, we collect the email address you provide and your subscription preferences so we can send what you asked for.

Automatically collected data. Like most websites, our servers and analytics tools record basic technical information when you visit, such as IP address, browser type and version, device and operating system, pages viewed, referring URL, and timestamps. We also use cookies and similar technologies as described below.

  • Contact and inquiry details you submit (name, work email, phone, organization, role, message)
  • Subscription email address and preferences, if you opt in
  • Log and device data (IP address, browser, OS, pages viewed, referrer, timestamps)
  • Cookie and analytics identifiers used to understand site usage

How We Use Your Information

We use the information above to run our website and to communicate with prospective and existing clients. We do not sell your personal information.

Specifically, we use it to respond to inquiries and provide the information or proposal you requested; to schedule and prepare for conversations such as a discovery call or scoping discussion; to send updates you subscribed to and to let you unsubscribe; to operate, secure, maintain, and improve the website; to detect and prevent fraud, abuse, and security threats; and to comply with legal obligations and enforce our agreements.

Because we are a security firm, some processing exists specifically to protect the site and our visitors, for example reviewing log data to identify suspicious activity. We handle your information in a way consistent with the standards we advise our own clients to follow.

Cookies & Analytics

Cookies are small files placed on your device that help a website function and help the owner understand how it is used. We use a limited set of cookies and similar technologies, including ones necessary for the site to work and ones that support analytics so we can see which pages are useful and where to improve.

We use website analytics to understand aggregate trends such as which pages are visited and how visitors arrive. Depending on configuration, these tools may set cookies or collect identifiers tied to your browser or device. In practice, we currently use Cloudflare Web Analytics, which is privacy-focused, does not set cookies, and does not track you across other websites.

You can usually control cookies through your browser settings, including blocking or deleting them, and through any cookie or consent controls presented on the site. Blocking some cookies may affect how parts of the site function. Because our analytics are cookieless and we do not track you across sites, we treat every visitor the same; we do not sell personal information and aim to honor Global Privacy Control and Do Not Track signals where applicable.

How We Share Information

We share information only as needed to operate, and not to enable third parties' own marketing. We do not sell personal information.

Service providers and processors. We use trusted vendors to run the website and our communications, such as web and cloud hosting, form handling, email and newsletter delivery, analytics, and customer relationship management. These providers process information on our behalf and under contract, and are expected to use it only to provide their service to us. Our key providers include our website hosting and content-delivery network (Cloudflare), the service that delivers contact-form inquiries you send us, and our privacy-focused analytics.

Legal and protective disclosures. We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, safety, or property, or that of our visitors or the public, including to investigate or prevent security incidents and fraud.

Business transfers. If Dark Analytics is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to reasonable confidentiality protections.

Data Security

Security is our profession, and we apply reasonable administrative, technical, and physical safeguards designed to protect the information we collect against unauthorized access, disclosure, alteration, and loss. These measures include access controls, encryption in transit, and limiting who can see submitted information to those who need it to do their jobs.

No method of transmission over the internet or method of electronic storage is perfectly secure, and we cannot guarantee absolute security. This is one reason we ask that you never submit patient information, clinical records, credentials, or other highly sensitive data through a public website form. If you need to share sensitive details for an engagement, we will arrange a secure, agreed-upon channel.

If we become aware of a security incident affecting personal information you provided through the site, we will respond consistent with applicable law and, where required, notify affected individuals or authorities.

Data Retention

We keep personal information only for as long as it is needed for the purposes described in this policy, and then dispose of it or anonymize it. Retention periods depend on the type of information and the context.

For example, inquiry and contact information is generally retained while we are in active discussion and for a reasonable period afterward to maintain a record of the relationship and to follow up appropriately. Subscription information is retained until you unsubscribe or ask us to remove it. Log and analytics data is typically retained for a limited period for security and operational purposes.

We may retain certain information longer where necessary to comply with legal, tax, or regulatory obligations, to resolve disputes, or to enforce our agreements. We keep information you submit through the site only as long as needed to respond to and follow up on your inquiry, and then for a reasonable period for our business records, unless a longer period is required by law.

Your Choices & Rights

You have meaningful control over your information, and we want to make exercising it straightforward.

You can unsubscribe from our emails at any time using the link in any message or by contacting us. You can ask us to access, correct, update, or delete the personal information you submitted through the site, and we will respond to reasonable requests consistent with applicable law and our legal obligations. You can also control cookies through your browser and any consent tools on the site.

Depending on where you live, you may have additional rights under applicable privacy laws regarding your personal information, such as rights to access, correct, delete, or limit certain uses, and the right not to be discriminated against for exercising them. We will honor applicable rights as required by the law that applies to you. To make a request, contact us at info@darkanalytics.com. We may need to verify your identity before acting.

  • Unsubscribe from emails at any time via the link or by emailing us
  • Request access to, correction of, or deletion of information you submitted
  • Manage cookies through your browser and on-site controls
  • Contact info@darkanalytics.com to exercise applicable privacy rights

Third-Party Links

Our website may contain links to third-party websites, tools, or resources that we do not own or control, such as industry references, vendor documentation, or social profiles. We provide these for convenience and information only.

This Privacy Policy does not apply to those third-party sites. We are not responsible for their content, privacy practices, or security. When you follow a link off our site, we encourage you to read the privacy policy of the destination before providing any personal information.

Children's Privacy

Our website and services are intended for businesses and professionals, and are directed to healthcare IT, security, compliance, and clinical engineering audiences. They are not directed to children.

We do not knowingly collect personal information from children. Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information through the site, please contact us at info@darkanalytics.com and we will take reasonable steps to delete it.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we do, we will revise the date below and post the updated version on this page.

If we make material changes, we will take reasonable steps to provide additional notice where appropriate. We encourage you to review this page periodically so you stay aware of how we handle your information.

Last updated: June 2026.

How to Contact Us

If you have questions about this Privacy Policy, want to exercise a privacy choice, or want to understand how your information is handled, we are glad to help.

Email: info@darkanalytics.com. Phone: (727) 800-0329. Location: Tampa Bay, Florida. For requests related to a specific client engagement or regulated data such as ePHI, please reference the relevant agreement so we can route your request correctly.