Privacy Policy

Legal

Privacy Policy

Effective date: October 2, 2026

Moonscape Business Solutions, Inc. (“Moonscape”, “we”, “us”) is an IT services company in Boca Raton, Florida. This policy explains what personal information we collect through our websites and online tools, what we do with it, and the choices you have. It covers moonscape.biz, app.moonscape.cloud (our booking and forms tool) and any client help desk or portal we run (together, the “Sites”), plus information we collect when you contact us, book a call, request a quote, or become a client, and information we gather about businesses we’d like to work with.

1. The two hats we wear

Most of the time we act as the “controller” of your information: you’re a visitor, a prospect, a client contact or a job applicant, and we decide how your details are used. That is what this policy is about.

When we provide IT services to a client company, we also handle data that belongs to that client and to its staff and customers (mailboxes, files, tickets, logs). There we act as a “processor” or “service provider” on the client’s instructions, under our Master Service Agreement and its Data Processing Addendum (and, for healthcare clients, a Business Associate Agreement). If you are an employee or customer of one of our clients and have a question about your data, please contact that company first; we’ll help them answer it.

2. What we collect

Information you give us. When you fill in a contact or quote form, book a call, open a support ticket, apply for a job, chat with an assistant on the Sites, or email us, we receive what you type: typically your name, company, work email, phone number, the service you’re interested in, and anything you add in a message, chat or notes field. Job applications may include a résumé. If you buy something through an online store on the Sites, we receive your billing and shipping details; payment card numbers go directly to the payment processor and we never store them.

Information collected automatically. Like most websites, the Sites record standard technical data in server logs: IP address, browser and device type, pages viewed, the page you came from, and timestamps. If you accept analytics cookies (section 7), we also collect interaction data through Microsoft Clarity: which pages you visit and in what order, where you click, scroll and move the mouse, how long you stay, your approximate location derived from your IP address, and a replay of your session with typed text and sensitive fields masked. We use this to see where the Sites confuse people and to fix it.

Information about businesses we’d like to work with. We look for companies in South Florida that may need IT help. We find them, and the people who handle IT there, on public and/or aggregator sources: company websites, job postings, business directories, professional profiles and business-data aggregators, sometimes with software that automates the searching. The information we collect is limited to business contact details (name, role, company, work email, work phone, office location) and what the source says about the company’s technology or hiring. We don’t collect personal email addresses, home addresses or anything about people’s private lives. Section 11 explains how to have your details removed from our systems.

Information from clients and vendors. If your company becomes a client, we keep business contact details for the people we work with there, plus records of the services we provide (tickets, configuration notes, invoices). When you ask us to quote hardware or licences, we may share the minimum needed with the relevant vendor or distributor to obtain pricing.

We don’t knowingly collect information from children under 16, and the Sites aren’t directed at them.

3. How we use it

We use personal information to: answer your enquiry and schedule the call you booked; prepare quotes and proposals and deliver the services you’ve asked for; run client accounts, including support, billing and vendor orders; send service notices, and marketing emails you can opt out of (section 8); contact businesses we think we can help, by email or phone, with an easy way to say no; understand how the Sites are used so we can improve them; protect the Sites, our systems and our clients from fraud, abuse and security threats; and meet legal, tax and accounting obligations.

Where a legal basis is required (for example for visitors in the EU or UK), we rely on: performance of a contract or steps you ask us to take before one; our legitimate interests in running and promoting our business and keeping it secure; your consent, for analytics cookies and session replay; and compliance with legal obligations.

We do not sell personal information. Section 7 describes the one case where a partner (Microsoft) receives usage data that it may also use for its own purposes, and how to turn that off.

4. Automated tools and AI

We use software, including AI assistants and agents, in parts of how we market and deliver our services. In plain terms, this is what that involves.

Drafting and research. Our staff use AI tools from Microsoft (Copilot) and Anthropic (Claude) to draft emails, summarize notes and research companies. Information about you may be included in what we give those tools. We use them under commercial terms that don’t allow the provider to train its models on what we submit, and we don’t use personal AI accounts for client or prospect information. We don’t put client credentials, card numbers or health information into them.

Agents that act for us. Some routine tasks may be carried out by AI agents we build and run ourselves or through third-party platforms: for example finding businesses that match the profile in section 2, writing a first-contact email for a person on our team to review, sorting incoming enquiries, or answering common questions on the Sites. If you’re talking to an assistant rather than a person, it will say so, and asking for a human in any message gets you to one.

Decisions. We don’t make decisions that have a legal or similarly significant effect on you (whether to offer a service, on what terms, or at what price) by automated means alone. A person on our team reviews anything an agent proposes before it reaches you as an offer or a contract.

Where the data goes. When an AI tool processes information about you, the data goes to that provider (currently Microsoft and Anthropic) as a processor for us, under their commercial terms, and is kept by them only as long as needed to provide the service and keep it safe. If we add a provider, we’ll name it here.

5. Who we share it with

We share personal information only with:

Service providers who host and run our tools: our email and productivity platform is Microsoft 365; our website is hosted by Hostinger on servers in the United States; our booking and forms tool runs on infrastructure we control; and the AI providers in section 4.

Microsoft, for website analytics. If you accept analytics cookies, Microsoft Clarity collects the interaction data described in section 2 on our behalf. Microsoft also uses that data for its own purposes, including to operate and improve Clarity and Microsoft Advertising, which makes Microsoft an independent controller of it rather than only our processor. Microsoft’s handling of it is described in the Microsoft Privacy Statement at microsoft.com/privacy.

Vendors and distributors, when you ask for a quote or order a product (for example Microsoft, Dell Technologies, Cisco, Lenovo, Fortinet, Trend Micro, Arctic Wolf and 8x8), limited to what they need to price or fulfil the order.

Payment processors, where a store is offered; professional advisers (accountants, lawyers, insurers) under confidentiality; and authorities or other parties when the law requires it, or to protect our rights, our clients or the public.

If Moonscape is sold or merges with another company, client and contact records may transfer to the new owner under the same commitments.

6. Where it's stored

We are based in the United States and store information here. Our platforms may use data centres in other countries; where personal information from the EU, UK or Switzerland is transferred, we rely on the recipient’s standard contractual clauses or an equivalent safeguard. Fonts on the Sites are loaded from Google Fonts, which means your browser sends its IP address to Google when a page loads; Google’s privacy policy applies to that request.

7. Cookies, analytics and session replay

The Sites use two kinds of cookies.

Essential cookies are set by WordPress to keep you signed in to a client portal and to protect forms, and, if you use the online store, by WooCommerce to remember a cart and complete a checkout. These don’t track you across other websites and can’t be switched off without breaking those features. The booking tool at app.moonscape.cloud runs inside the Book a Call page and sets no cookies of its own.

Analytics cookies are set only if you accept them. When we enable website analytics, we will use Microsoft Clarity to capture how people use the Sites through behavioural metrics, heatmaps and session replay, so we can improve the Sites and our services. Clarity loads only after you accept analytics cookies in a banner on your first visit; until that banner appears on the Sites, no analytics cookies are set. Clarity sets two cookies on our domain (_clck, which remembers a Clarity user ID for this site, and _clsk, which links the page views in one session) and, through Microsoft, cookies on Microsoft domains (MUID, CLID, ANONCHK, MR and SM) that Microsoft uses to recognise browsers across Microsoft services for analytics, advertising and operational purposes. Session replays mask what you type into forms and other sensitive fields, and we don’t record the booking tool or any signed-in portal pages. For more about how Microsoft collects and uses this data, see the Microsoft Privacy Statement.

Your choices. The banner lets you accept or decline analytics cookies, and you can change your mind at any time with the “Manage cookies” link in the footer; declining keeps everything on the Sites working. We honour the Global Privacy Control signal, which we treat as declining analytics cookies and as an opt-out under US state privacy laws. We don’t respond to the older “Do Not Track” header, because there is no agreed standard for it.

8. Marketing choices

We send marketing email only to business contacts who have enquired with us, are clients, or have opted in, and first-contact emails to businesses we’ve identified as described in section 2. A first-contact email says that we found your details on public and/or aggregator sources and tells you how to opt out. Follow-up messages after a booking or an enquiry come from our own system at app.moonscape.cloud or from our Microsoft 365 mailboxes. Every marketing or first-contact email has an unsubscribe link, and you can also email info@moonscape.biz to be removed; we keep a record of the request so we don’t contact you again. Service emails (ticket updates, invoices, security notices) continue while you’re a client because they’re part of the service.

9. How long we keep it

We keep enquiry and booking records for up to 24 months after our last contact with you, unless you become a client. Business contact details we’ve gathered for prospecting are deleted 12 months after we last used them if there has been no reply, and promptly when you ask. Client records are kept for the length of the engagement and for 7 years afterwards for tax, accounting and legal reasons. Support tickets and configuration documentation are handed over at the end of an engagement and our copies are deleted on the schedule in the Master Service Agreement. Job applications are kept for 12 months unless you ask us to delete them sooner. Website logs are kept for 90 days. Chat transcripts with an assistant on the Sites are kept for 90 days unless they become part of an enquiry or a ticket. Microsoft keeps Clarity session recordings for 30 days and heatmap data for 13 months under its current documentation. Where we’re required to keep something longer by law, we do.

10. How we protect it

We use the same controls we recommend to clients: multi-factor authentication on every account, encryption in transit and at rest on our platforms, least-privilege access, endpoint protection on our devices, logging, and tested backups. No system is perfectly secure, and we can’t guarantee the security of information sent to us over the internet. If we discover a breach affecting your personal information, we will notify you and the relevant authorities as required by law, including the Florida Information Protection Act (notice to affected individuals within 30 days of determining a breach occurred, unless law enforcement asks us to delay).

11. Your rights and choices

Depending on where you live, you may have rights to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing (including our use of public and aggregator sources to contact you), withdraw consent, and opt out of marketing. We extend these rights to everyone who asks, whether or not a specific law requires it.

If we found your details on public and/or aggregator sources and you’d rather not hear from us, tell us by replying to the email, using its unsubscribe link, or writing to info@moonscape.biz. Opting out removes your details from our systems and puts you on our do-not-contact list; we can’t remove them from the public or aggregator sources where we found them, because those aren’t ours.

To make a request, email info@moonscape.biz with “Privacy request” in the subject line. We’ll confirm your identity (usually by replying to the email address on file) and respond within 30 days, or tell you if we need longer. We won’t treat you differently for making a request. If you’re not satisfied with our response, you may complain to your local data protection authority or state attorney general. If you’ve authorized an agent to make a request for you, we’ll ask for proof of that authorization.

For residents of California and other US states with privacy laws: we don’t sell personal information. Sharing usage data with Microsoft through Clarity may count as “sharing” for cross-context behavioural advertising under some state laws; declining analytics cookies in the banner, or sending a Global Privacy Control signal, opts you out. We don’t use sensitive personal information for anything other than providing the service you asked for. Moonscape is below the size thresholds of these laws, so they don’t currently apply to us, but we honour the same requests from anyone.

The Sites link to vendor websites, documentation and tools that we don’t control. Their privacy practices are their own, and we encourage you to read their policies.

13. Changes to this policy

We’ll post any changes here with a new effective date, keep a short note of what changed at the bottom of this page, and tell clients and registered account holders by email when a change is material. The latest version always lives at moonscape.biz/privacy-policy/.

14. Contact

Moonscape Business Solutions, Inc.
1501 Yamato Rd, Suite 200, PMB 2036, Boca Raton, FL 33431, United States
info@moonscape.biz

Change history. October 2, 2026: first version, revised the same day to add website analytics and session replay (Microsoft Clarity), automated tools and AI, and how we find businesses to contact.