Privacy Policy
Last updated: 25 September 2026
This Privacy Policy explains how ECS Technology Solutions ("ECS", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you interact with any of our Services, including:
- Website: https://ecs.rocks and any sub-domains.
- Managed Service Provider (MSP) offerings: remote monitoring & management, help-desk, cloud hosting, security operations, professional services, and any other solutions we deliver to customers (collectively, the "MSP Service").
By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
1. Definitions
| Term | Meaning |
|---|---|
| Account | A unique profile enabling access to portions of the Website or MSP Service. |
| Cookies | Small text files stored on your device that hold information about your visit. |
| Country | Nebraska, United States. |
| Device | Any device capable of accessing the Services (computer, phone, tablet, server, IoT device). |
| Personal Data | Information that identifies or can reasonably be linked to an individual. |
| Service(s) | The Website and the MSP Service. |
| Service Provider | Third parties that process data on our behalf (e.g., cloud hosts, ticketing platforms). |
| Usage Data | Data collected automatically from your interaction with the Services (e.g., log files, telemetry). |
| You / Customer / End-User | The individual or organisation using the Services. |
2. Information We Collect
2.1 Personal Data You Provide
- Name, email address, phone number, company name.
- Credentials you supply for system integrations (stored securely in approved secrets managers).
- Any Personal Data you include in service tickets, chat sessions, or project documentation.
2.2 Usage Data
- IP address, browser type/version, pages visited, time stamps.
- The organisation associated with your network. On our Website we may look up the organisation that owns the network your visit came from, so we can tell which businesses are interested in our services. This identifies a company, not a person, and it is derived from the IP address above rather than from anything stored on your device. Networks that are not registered to a business — many home, mobile, and VPN connections — generally cannot be matched to an organisation this way. How the lookup works: we read our web server logs every few hours and send each visit's IP address to an IP-data provider (currently ipinfo.io, with ipapi.co as a backup). The provider tells us which organisation owns that network. We discard visits from home and mobile internet providers, cloud and hosting networks, VPNs, and automated traffic such as search-engine crawlers. For the organisations that remain, we keep the organisation's name, web domain, and general location as the provider reports them, the pages visited on our Website, the referring websites, and visit counts per day. These records are deleted automatically after about 180 days. We do not store the IP address in these records. To avoid looking up the same address twice, we keep a hashed form of it for 7 days; after that we no longer use it, and it is deleted automatically, usually within about two further days. Only ECS staff can see these records.
- Device and telemetry data from agents installed as part of the MSP Service (e.g., OS version, hardware health, security alerts).
2.3 Tracking Technologies
We use Cookies, pixel tags, and similar technologies to:
- Keep you signed in to dashboards or portals.
- Remember preferences (language, theme).
- Analyse Website performance and improve user experience.
- Identify business visitors to our Website, only if you allow Marketing cookies (see §2.4).
Cookie choices are managed through the cookie banner on our Website and through your browser settings; essential cookies are required for core functionality. MSP agents do not rely on browser cookies.
What declining cookies does and does not change. Declining optional cookies stops the optional tools that check your choice before they load, such as our session-replay analytics, our live-chat widget, and the RB2B visitor-identification service described in §2.4. It does not stop our web servers recording the ordinary request information listed in §2.2 — an IP address, the pages requested, and a timestamp are part of how any website answers a request, and they are logged before any cookie choice is made. The organisation lookup described in §2.2 is derived from those server logs, so it also continues to apply. If you would rather your organisation was not identified this way, contact us using §12 and we will exclude your network.
2.4 Website Visitor Identification (RB2B)
If you allow Marketing cookies in our cookie banner, our Website loads a script from RB2B, a third-party service that identifies business visitors to websites. RB2B uses cookies and the information your browser sends, such as your IP address, the pages you view, and when you view them, to try to recognise who is visiting. It may link your visit to your company and to your professional identity, for example your name, job title, employer, work email address, or professional networking profile. It then gives that information to us along with the pages you viewed.
- Why we use it: business-to-business marketing and sales outreach. It helps us understand which businesses and people are interested in our services so we can follow up with them.
- Who receives your data: RB2B receives the information about your visit and uses its own data sources to make the match. RB2B processes it on our behalf, and its own privacy policy also applies. We receive the results.
- It is off unless you allow it: Marketing cookies are off by default. The RB2B script does not load until you choose to allow them.
- How to opt out: leave Marketing cookies off, or turn them off at any time. If you withdraw your consent using the button below, we reload the page without the RB2B script, which stops it running, and it is not loaded again unless you allow Marketing cookies again. The button clears your saved cookie choice, reloads the page, and shows the cookie banner again, where you can choose "Reject All", or choose "Customize" and turn Marketing cookies off. Clearing this website's stored data in your browser does the same thing.
- What opting out does not undo: withdrawing consent stops RB2B collecting new information on our Website. It does not remove information RB2B has already collected or shared with us. To ask us to delete that information, or to object to this processing, email support@ecs.rocks (see §8).
3. How We Use Personal Data
| Purpose | Examples |
|---|---|
| Provide & Maintain Services | Deploy monitoring agents, manage backups, patch endpoints, host cloud workloads, maintain the Website. |
| Account Management | Create/modify user accounts, authenticate logins, set roles & permissions. |
| Contract Performance | Deliver projects, support tickets, statements of work, SLAs. |
| Communications | Service alerts, security notices, maintenance windows, marketing (opt-out available). |
| Improvement & Analytics | Aggregate statistics, feature usage trends, capacity planning. |
| Marketing & Business Development | Identifying the organisations that visit our Website, from the network a visit came from, so we can understand which businesses are interested in our services and follow up with them. This network lookup (§2.2) is company-level only; we do not use it to identify individual visitors. Separately, and only if you allow Marketing cookies, RB2B may identify you as an individual business visitor so we can contact you about our services (§2.4). |
| Legal & Security | Detect fraud, respond to lawful requests, enforce agreements. |
4. Sharing of Personal Data
We only share Personal Data:
- With Service Providers that help operate our infrastructure (e.g., AWS, Microsoft 365, ticketing SaaS) under strict contractual obligations.
- With website visitor-identification and IP-data providers. RB2B, only if you allow Marketing cookies, receives information about your visit to identify business visitors (§2.4). ipinfo.io and ipapi.co receive the IP address of a Website visit and tell us which organisation owns that network (§2.2).
- With business partners when jointly delivering solutions and only as necessary.
- During business transfers subject to continuity of equivalent privacy protections.
- For legal reasons – to comply with law, protect rights, investigate wrongdoing.
- With your consent for any other purpose you authorise.
We never sell Personal Data.
5. Data Retention
ECS retains Personal Data indefinitely in customer environments to ensure service continuity, historical troubleshooting, and compliance, unless:
- A legal obligation requires deletion, or
- You instruct us to delete or anonymise data and such deletion is technically feasible.
Ticket metadata and system logs are retained for at least 30 days; security logs may be kept longer if required for investigations.
6. International Transfers
We may process and store data in the United States and other countries where we or our providers operate. We implement contractual and technical safeguards (e.g., encryption in transit and at rest, access controls) to protect data regardless of location.
7. Security
We apply the controls outlined in our Data Protection Policy including:
- AES-256 encryption at rest (or strongest available algorithm).
- TLS 1.3 encryption in transit.
- IAM with least privilege and MFA on systems holding Highly Confidential data.
- Real-time vulnerability scanning and immediate critical patching.
- Centralised logging & SIEM with 30-day retention.
- Approved secrets managers (AWS Secrets Manager, Azure Key Vault, Keeper, Hudu).
8. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, erase, restrict, or object to processing of your Personal Data, or to receive a copy of it. To exercise these rights, email support@ecs.rocks. We respond within 30 calendar days.
9. Children’s Privacy
The Services are not directed to children under 13. We do not knowingly collect data from them. If you believe we have, please contact us and we will delete it.
10. Third-Party Links
Our Website or MSP tools may link to external sites we do not control. We are not responsible for their content or privacy practices. Review the privacy policy of every site you visit.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will post the new version here and, if the changes are material, notify managed clients and persons who are subscribed to relevant email channels via email or a notice in the relevant portals before they take effect. “Last updated” reflects the revision date.
12. Contact Us
Questions or concerns? Contact our security & privacy team at:
ECS Technology Solutions2720 N 206th St
Omaha, NE 68022, USA
Email: support@ecs.rocks
Phone: +1 (402) 350-0372