GDPR Statement
Last updated: September 5, 2026
This policy is in draft while the practice’s legal and contact details are finalised. It has not been reviewed by an attorney.
This statement covers personal data of individuals in the European Union, European Economic Area, and United Kingdom. It supplements the Privacy Policy, which applies to everyone.
1. Controller
For data submitted through this website, the controller is Entelechy Security, Inc., the one-person practice of Coco Bloom in California, United States. Requests and questions go through the details on the Contact page. Where I process personal data on behalf of a client during a consulting engagement, the client is the controller and I act as a processor under the terms of that engagement.
2. What is processed, why, and on what basis
Direct enquiries
Name, the way to reach you, organization, and message content. Purpose: responding to your enquiry and, if it proceeds, scoping the work. Article 6(1)(a) consent and 6(1)(f) legitimate interests; 6(1)(b) once a contract is in view.
Server logs
Request data including IP address, retained by the hosting provider. Purpose: availability and security of the site. Article 6(1)(f) legitimate interests.
No special category data is requested, and no automated decision-making or profiling with legal or similarly significant effects takes place. Please do not include sensitive personal data in any message. A contact form and a newsletter are planned; their processing will be described here before they go live.
3. Retention
Enquiries that do not become engagements are deleted once they are no longer needed; engagement records follow the retention terms of the relevant contract. The specific retention period for general enquiries is being confirmed and will be stated here.
4. International transfers
Entelechy Security operates from the United States, so data you submit is processed there and may be handled by US-based providers such as the website host and my email provider. Transfers rely on the safeguards available for each provider, such as standard contractual clauses or an applicable adequacy mechanism. The specific providers and safeguards will be named here once selected.
5. Your rights
- Access to your data
- Rectification of inaccuracies
- Erasure
- Restriction of processing
- Data portability
- Objection to legitimate-interests processing
- Withdrawal of consent at any time
- Complaint to a supervisory authority
6. Making a request
Contact me through the details on the Contact page with the words “data request” and tell me what you would like done. I respond within one month and will tell you if I need an extension for a complex request. I may ask a question or two to confirm your identity before acting. Requests are free unless they are manifestly unfounded or excessive.
You can also complain to your national data protection authority, or to the UK Information Commissioner’s Office if you are in the United Kingdom. I would prefer the chance to resolve it first.
7. Security and breach notification
Access to website submissions is limited to me and protected by multi-factor authentication and encrypted transport. If a personal data breach affecting your rights occurred, I would notify the relevant supervisory authority within 72 hours of becoming aware of it and inform affected individuals where required.
Also see the Privacy Policy, Terms of Service, Cookie Policy, and GDPR Statement.
