Privacy Policy
Important Notice
This Privacy Policy describes how John Meola Consulting, LLC collects, uses, and protects personal information obtained through jmeolaconsulting.com. Please read this document carefully. By using this website, you acknowledge that you have read and understood this Privacy Policy.
1.0 Introduction and Overview
John Meola Consulting, LLC (“John Meola Consulting,” “we,” “us,” or “our”) is a professional consulting business located in Fairfield, Connecticut, USA. We operate the website jmeolaconsulting.com (the “Website”) to provide information about our services and to facilitate inquiries from prospective and current clients.
We are committed to protecting your privacy and handling your personal information with transparency, integrity, and respect. This Privacy Policy explains:
- What personal information we collect when you visit our Website;
- How we use, store, and protect that information;
- With whom we may share your information;
- Your rights with respect to your personal information; and
- How to contact us with privacy-related questions or requests.
This Privacy Policy applies to all personal information collected through jmeolaconsulting.com. It does not apply to information collected through other channels (such as in-person meetings or paper forms) except where such information is later processed in connection with our Website.
This Privacy Policy is effective as of September 8, 2026. We reserve the right to update this policy from time to time; please see Section 14 (Changes to This Privacy Policy) for details.
We take a privacy-by-design approach. We collect only the personal information necessary to operate our Website and provide our services, and we retain it only as long as necessary for the purposes described in this policy.
2.0 Information We Collect
We collect personal information in the following ways when you interact with our Website.
2.1 Information You Provide Directly
When you voluntarily contact us through our Website — for example, by completing a contact form or sending an email inquiry — we may collect the following categories of personal information:
- Name (first and last name);
- Email address;
- Phone number (if provided);
- Company or organization name (if applicable);
- Message content — the substance of your inquiry or communication; and
- Any other information you voluntarily include in your message or form submission.
You are not required to provide any of the above information to browse our Website. However, if you choose not to provide certain information, we may be unable to respond to your inquiry or provide consulting services.
2.2 Information Collected Automatically
When you visit jmeolaconsulting.com, certain technical information is collected automatically through standard server logs and analytics technologies. This may include:
- IP address (Internet Protocol address of your device);
- Browser type and version;
- Device type (desktop, tablet, mobile) and operating system;
- Pages visited on our Website and the order in which they were visited;
- Referring URLs (the webpage that directed you to our Website);
- Date and time of your visit; and
- Session duration and general navigation patterns.
This automatically collected information is used in aggregate and is primarily used to maintain and improve the performance and security of our Website. Where collected through analytics services, IP addresses may be anonymized (see Section 5).
2.3 Cookies and Tracking Technologies
Our Website may use cookies and similar tracking technologies to improve your browsing experience and to collect analytics data. Cookies are small text files placed on your device by your web browser when you visit a website. We use the following types of cookies:
- Session Cookies: Temporary cookies that expire when you close your browser. These are used to support basic website functionality.
- Persistent Cookies: Cookies that remain on your device for a set period or until you delete them. These help us recognize returning visitors and remember preferences.
- Analytics Cookies: Cookies placed by third-party analytics services (such as Google Analytics) to help us understand how visitors interact with our Website. These cookies collect aggregated, anonymized data about traffic patterns, page views, and user behavior.
For more detailed information about our use of cookies and how to manage them, please see Section 5 (Cookies and Tracking Technologies).
2.4 No Sensitive Personal Information Collected
We do not knowingly collect, request, or require any of the following categories of sensitive personal information through our Website:
- Social Security numbers or government-issued identification numbers;
- Financial account numbers, credit or debit card numbers, or banking information;
- Health or medical data;
- Biometric data;
- Racial or ethnic origin, political opinions, religious beliefs, or philosophical beliefs;
- Sexual orientation or gender identity; or
- Precise geolocation data.
Please do not submit sensitive personal information of the above types through our Website contact forms or email. If you inadvertently do so, we will take reasonable steps to delete such information promptly.
2.5 Children’s Privacy
Our Website is not directed to, and is not intended for use by, children under the age of 13. We do not knowingly collect personal information from children under 13 years of age. If you are under 13, please do not submit any personal information through our Website. Please see Section 11 (Children’s Privacy) for our full COPPA compliance statement.
3.0 How We Use Your Information
We use the personal information we collect for specific, limited, and legitimate purposes. We do not use your personal information for purposes incompatible with those described in this Privacy Policy.
Specifically, we use your personal information for the following purposes:
- Responding to inquiries: To receive, review, and respond to questions, requests, and messages submitted through our Website or by email.
- Providing consulting services: To deliver professional consulting services to clients who engage us through or in connection with our Website.
- Website performance and improvement: To analyze website traffic patterns, diagnose technical issues, and improve the functionality, usability, and content of jmeolaconsulting.com.
- Analytics: To use aggregated, anonymized analytics data (collected through tools such as Google Analytics) to understand how visitors navigate our Website and to make informed improvements.
- Sending requested information: To send follow-up communications, informational materials, or other content you have specifically requested.
- Legal compliance: To comply with applicable federal and state laws, regulations, and legal processes, including recordkeeping obligations.
- Security and fraud prevention: To detect, investigate, and prevent unauthorized access, fraudulent activity, and other security incidents affecting our Website or business.
- Legitimate business interests: For other purposes consistent with our legitimate business interests, where such interests are not overridden by your fundamental rights and freedoms (see Section 4 for GDPR lawful bases).
We will not use your personal information for purposes materially different from those listed above without providing you with prior notice and, where required, obtaining your consent.
4.0 Lawful Bases for Processing (GDPR – EU/EEA Residents)
If you are a resident of the European Union or European Economic Area, the General Data Protection Regulation (GDPR) requires us to identify a lawful legal basis for each processing activity involving your personal data. The following table sets out our processing activities and the corresponding lawful bases under GDPR Article 6.
| Processing Activity | Lawful Basis (GDPR Art. 6) | Explanation |
|---|---|---|
| Responding to contact form inquiries and email messages | Legitimate Interests (Art. 6(1)(f)); or Contract Performance (Art. 6(1)(b)) where applicable | We have a legitimate interest in responding to prospective and current client inquiries. Where the inquiry relates to an existing service engagement, processing is necessary for contract performance. |
| Delivering consulting services | Contract Performance (Art. 6(1)(b)) | Processing is necessary to perform our contractual obligations to clients who have engaged our services. |
| Website analytics (anonymized/aggregated) | Legitimate Interests (Art. 6(1)(f)) | We have a legitimate interest in understanding how our Website is used in order to improve it. Analytics data is anonymized or aggregated to minimize privacy impact. This interest is balanced against, and does not override, your rights and freedoms. |
| Setting strictly necessary cookies | Legitimate Interests (Art. 6(1)(f)) | Strictly necessary cookies are essential to the functioning of our Website. No consent is required for these. |
| Setting analytics/performance cookies | Consent (Art. 6(1)(a)) | We will seek your consent via a cookie consent notice before placing non-essential cookies, including analytics cookies. |
| Compliance with legal obligations | Legal Obligation (Art. 6(1)(c)) | Processing is necessary to comply with applicable law, including responding to lawful requests from courts or regulatory authorities. |
| Security and fraud prevention | Legitimate Interests (Art. 6(1)(f)) | We have a legitimate interest in maintaining the security of our Website and business operations and in preventing unauthorized access or fraud. |
| Sending requested follow-up communications | Consent (Art. 6(1)(a)) or Legitimate Interests (Art. 6(1)(f)) | Where you have specifically requested information or follow-up, we rely on your implicit consent or our legitimate business interest. For commercial marketing emails, we rely on explicit consent (see Section 12). |
Balancing Test for Legitimate Interests: Where we rely on legitimate interests as a lawful basis, we have assessed that our interests are not overridden by your fundamental rights and freedoms, taking into account the nature of the data, the likely impact on you, and the safeguards we have in place (including data minimization and anonymization where appropriate). You have the right to object to processing based on legitimate interests; see Section 10.B for details.
Where we rely on consent as the lawful basis, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Data Controller: For EU/EEA residents, John Meola Consulting, LLC, Fairfield, Connecticut, USA, acts as the Data Controller within the meaning of the GDPR. We do not have a designated Data Protection Officer (DPO), as one is not required for a business of our size and nature. Privacy inquiries may be directed to [email protected].
5.0 Cookies and Tracking Technologies
5.1 What are Cookies?
A cookie is a small text file that a website places on your computer, tablet, or mobile device when you visit. Cookies are widely used to make websites work more efficiently and to provide website owners with analytical information about how visitors use their sites.
5.2 Types of Cookies We Use
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Essential for the Website to function. These cookies do not collect personal information and cannot be switched off in our systems. Examples include session management cookies. | No — functionally required |
| Functional | Enable enhanced functionality and personalization, such as remembering your preferences. These cookies may be set by us or by third-party providers whose services we use. | Consent preferred |
| Analytics / Performance | Collect anonymized information about how visitors use our Website — including pages visited, time spent, and traffic sources — to help us improve the Website. These cookies do not identify individual users. | Yes — consent required |
5.3 Google Analytics
Our Website may use Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses cookies to help us analyze how visitors use our Website. The information generated by the cookie about your use of the Website (including your IP address) is transmitted to and stored by Google on servers in the United States.
We have enabled IP anonymization (IP masking) in Google Analytics, which means your IP address is truncated before storage, so it cannot be used to identify you. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf.
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, available at tools.google.com/dlpage/gaoptout. Analytics data is generally retained in accordance with Google’s default retention settings (typically 26 months), after which it is automatically deleted.
5.4 No Advertising or Cross-Site Tracking Cookies
We do not use advertising cookies, behavioral tracking cookies, retargeting cookies, or any cookies designed to track your activity across third-party websites. We do not engage in cross-context behavioral advertising.
5.5 Managing and Disabling Cookies
You can control and manage cookies through your web browser settings. Most browsers allow you to:
- View what cookies are stored on your device and delete them individually;
- Block third-party cookies;
- Block cookies from specific websites;
- Block all cookies from being set; or
- Delete all cookies when you close your browser.
Please note that disabling or blocking certain cookies may affect the functionality of our Website. To learn how to manage cookies in your specific browser, please refer to your browser’s help documentation (e.g., Chrome, Firefox, Safari, Edge).
5.6 Cookie Consent Mechanism
Upon your first visit to jmeolaconsulting.com, you may be presented with a cookie consent notice or banner that describes the cookies we use and allows you to accept or decline non-essential cookies (including analytics cookies). Your preferences will be respected and stored for future visits. You may update your cookie preferences at any time through the cookie settings available on our Website.
5.7 Global Privacy Control
Consistent with requirements under the Connecticut Data Privacy Act (effective January 1, 2025), our Website recognizes and honors the Global Privacy Control (GPC) signal. If your browser or browser extension is configured to transmit a GPC opt-out preference signal, we will treat that signal as a valid opt-out request from the sale of personal data or processing of personal data for targeted advertising, to the extent such activities occur.
6.0 Sharing and Disclosure of Personal Information
We value your privacy. We do not sell, rent, or trade your personal information to third parties for their own commercial purposes. The limited circumstances under which we may share your information are described below.
6.1 We Do Not Sell Your Personal Data
We explicitly state: We do not sell your personal data. This applies to all visitors and is consistent with our obligations under the Connecticut Data Privacy Act (CTDPA) and the General Data Protection Regulation (GDPR). We do not engage in the sale of personal information as defined under any applicable state or federal privacy law.
6.2 Service Providers and Data Processors
We may share your personal information with trusted third-party service providers who assist us in operating our Website and conducting our business. These service providers act as data processors on our behalf and are contractually required to:
- Process personal information only on our documented instructions;
- Maintain appropriate technical and organizational security measures; and
- Not use your personal information for their own independent purposes.
Categories of service providers we may use include:
- Web Hosting Providers: Companies that host and maintain our Website infrastructure;
- Email Service Providers: Services used to receive, send, and manage business communications;
- Analytics Providers: Services such as Google Analytics that provide anonymized website usage data; and
- IT and Security Vendors: Providers who assist with the security and maintenance of our systems.
Where required by the GDPR or other applicable law, data processing agreements are in place with our service providers.
6.3 Legal Requirements
We may disclose your personal information if required to do so by law, or in good-faith belief that such action is necessary to:
- Comply with a legal obligation, court order, subpoena, or other governmental or regulatory request;
- Protect and defend the rights, property, or safety of John Meola Consulting, LLC, our clients, or the public; or
- Detect, investigate, or prevent fraud, security incidents, or other illegal activity.
6.4 Business Transfers
In the event that John Meola Consulting, LLC is involved in a merger, acquisition, sale of assets, reorganization, or other business transfer, personal information held by us may be among the assets transferred. In such circumstances, we will endeavor to provide reasonable notice (for example, by posting a notice on our Website), and the acquiring party will be required to honor the commitments made in this Privacy Policy or provide you with a new privacy notice before any material changes take effect.
6.5 With Your Consent
We may share your personal information with third parties when you have expressly consented to such sharing. You may withdraw your consent at any time; however, withdrawal will not affect the lawfulness of sharing that occurred prior to withdrawal.
7.0 Data Retention
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, to comply with applicable legal obligations, and to resolve any disputes that may arise. Our general retention practices are as follows:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Contact form submissions and email inquiries | Retained as long as necessary to respond to and fulfill the inquiry, then deleted or securely anonymized. Typically no longer than 12–24 months from last contact unless a client relationship is established. | Legitimate interest; contract performance |
| Client-related communications and records | For the duration of the client engagement and for a reasonable period thereafter as required by applicable law or professional best practice (typically 3–7 years). | Legal obligation; legitimate interest |
| Website analytics data | Per the applicable analytics provider’s retention settings. For Google Analytics, data is typically retained for up to 26 months before automatic deletion. | Legitimate interest |
| Server log files (automatically collected technical data) | Typically 30–90 days, after which logs are deleted or anonymized. | Security; legitimate interest |
| Cookie consent records | Retained for a sufficient period to demonstrate compliance with consent requirements — typically up to 12 months. | Legal obligation; legitimate interest |
Legal Hold: Notwithstanding the above retention periods, we may retain personal information for longer periods where required by applicable law, regulation, or court order, or where retention is necessary for the establishment, exercise, or defense of legal claims.
When personal information is no longer required for its original purpose and no legal hold applies, we will securely delete, destroy, or anonymize the information in a manner that prevents unauthorized reconstruction or re-identification.
8.0 International Data Transfers
John Meola Consulting, LLC is based in the United States. If you are visiting our Website from outside the United States — including from the European Union, European Economic Area (EEA), or United Kingdom — please be aware that any personal information you provide to us will be transferred to, processed, and stored in the United States.
The United States may not provide the same level of data protection as your country of residence. However, we take the following steps to ensure that your personal information receives an adequate level of protection:
- EU Standard Contractual Clauses (SCCs): Where we transfer personal data from the EU/EEA to third-party service providers located in countries not recognized as providing an adequate level of protection, we rely on the European Commission’s Standard Contractual Clauses (SCCs) as a transfer mechanism. These clauses contractually obligate the recipient to protect personal data to standards equivalent to those required under the GDPR.
- EU–U.S. Data Privacy Framework: Where applicable, we may rely on the EU–U.S. Data Privacy Framework (DPF) as a basis for data transfers to U.S. service providers that are certified under that framework.
- GDPR Chapter V Compliance: All transfers of personal data from the EU/EEA are conducted in compliance with Chapter V of the GDPR, which governs transfers of personal data to third countries or international organizations.
By submitting personal information to us through our Website, you acknowledge that your information will be transferred to and processed in the United States in accordance with this Privacy Policy and applicable data protection law.
If you have questions about the safeguards we use for international data transfers, please contact us at [email protected].
9. Security
We take the security of your personal information seriously and have implemented reasonable and appropriate technical and organizational measures designed to protect it against unauthorized access, disclosure, alteration, loss, or destruction. These measures include, but are not limited to:
- HTTPS / SSL Encryption: Our Website uses Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption to protect data transmitted between your browser and our Website;
- Access Controls: Access to personal information is restricted to individuals who have a legitimate need to access it in connection with their role;
- Secure Email Practices: We use established, reputable email service providers with security features enabled; and
- Regular Review: We periodically review our security practices to ensure they remain appropriate and effective.
No Guarantee of Absolute Security: While we strive to use commercially reasonable means to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee the absolute security of any information transmitted to or from our Website or stored in our systems. You provide personal information at your own risk, and we encourage you not to share sensitive personal information through our Website contact forms.
Data Breach Notification: In the event of a personal data breach that is reasonably likely to result in risk to the rights and freedoms of affected individuals, we will take prompt action as required by applicable law. This may include notifying affected individuals and/or relevant supervisory authorities within the timeframes prescribed by law (e.g., 72 hours under GDPR Article 33 for notification to supervisory authorities where required, and without undue delay for notification to affected individuals under GDPR Article 34; and in accordance with applicable Connecticut and federal breach notification requirements).
10. Your Privacy Rights
Depending on your location and the applicable laws, you may have specific rights with respect to your personal information. We are committed to honoring those rights in a timely and transparent manner.
10.0 Rights of Connecticut Residents (CTDPA)
The Connecticut Data Privacy Act (CTDPA), codified at Conn. Gen. Stat. §§ 42-515 to 42-525 (effective July 1, 2023), grants Connecticut residents the following rights with respect to their personal data. Although John Meola Consulting, LLC is a small business and may not meet the CTDPA’s applicability thresholds (which apply to controllers that process data of 100,000 or more consumers, or 25,000 or more consumers while deriving more than 25% of gross revenue from data sales), we nonetheless extend these rights to Connecticut residents as a matter of best practice and our commitment to privacy.
Rights Under Conn. Gen. Stat. § 42-519:
- Right to Access: You have the right to confirm whether we are processing your personal data and, if so, to obtain a copy of that personal data in a format that is readily usable.
- Right to Correction: You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and the purposes for which it is processed.
- Right to Deletion: You have the right to request that we delete personal data we have collected about you, subject to certain exceptions (e.g., where retention is required by law or necessary for the establishment or defense of legal claims).
- Right to Data Portability: Where processing is carried out by automated means, you have the right to receive a copy of your personal data in a portable and readily usable format that allows you to transmit the data to another controller.
- Right to Opt Out of:
- The sale of your personal data (note: we do not sell personal data);
- Targeted advertising (note: we do not engage in targeted advertising); and
- Profiling in furtherance of decisions that produce legal or similarly significant effects (note: we do not engage in such profiling).
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CTDPA rights. We will not deny you goods or services, charge different prices, or provide a different level of quality based on your exercise of privacy rights.
How to Submit a CTDPA Request:
To exercise any of the above rights, please contact us by email at [email protected] with a description of your request. We may need to verify your identity before processing your request.
Response Timeline: We will respond to a verifiable consumer request within 45 days of receipt. If we reasonably require more time, we may extend the response period by an additional 45 days, in which case we will notify you of the extension within the initial 45-day period and explain the reason for the delay.
Right to Appeal: If we decline to act on your request, we will inform you of our reasons and of your right to appeal our decision. To appeal a denied request, please email us at [email protected] with the subject line “CTDPA Appeal” and a description of the request you submitted and the response you received. We will respond to your appeal within 60 days.
Complaint to the Connecticut Attorney General: If you are dissatisfied with the outcome of an appeal, you may lodge a complaint with the Connecticut Attorney General’s Office. Information about filing a complaint is available at portal.ct.gov/AG.
10.1 Rights of EU/EEA Residents (GDPR)
If you are a resident of the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR). These rights apply to personal data for which John Meola Consulting, LLC acts as the Data Controller.
- Right of Access (Art. 15): The right to obtain confirmation of whether we process your personal data, and if so, to receive a copy of that data along with supplementary information about how it is processed.
- Right to Rectification (Art. 16): The right to have inaccurate personal data corrected and incomplete personal data completed without undue delay.
- Right to Erasure / “Right to Be Forgotten” (Art. 17): The right to request that we erase your personal data without undue delay, where one of the grounds specified in Article 17 applies (e.g., the data is no longer necessary for the purposes for which it was collected, you withdraw consent, or the data has been unlawfully processed).
- Right to Restriction of Processing (Art. 18): The right to request that we restrict the processing of your personal data in certain circumstances — for example, while you contest the accuracy of the data, or while we assess an objection you have raised.
- Right to Data Portability (Art. 20): The right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and the right to transmit that data to another controller, where processing is based on consent or a contract and is carried out by automated means.
- Right to Object (Art. 21): The right to object, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (Article 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defense of legal claims. You have an absolute right to object to processing for direct marketing purposes.
- Rights Related to Automated Decision-Making (Art. 22): We do not engage in solely automated decision-making (including profiling) that produces legal effects or similarly significant effects concerning you. No decision is made about you through fully automated means without human involvement.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the supervisory authority in your EU/EEA member state of habitual residence, place of work, or place of the alleged infringement. A list of EU data protection authorities is available at edpb.europa.eu.
How to Submit a GDPR Request:
To exercise any of the above rights, please contact us at [email protected]. We will respond to your request within 30 days of receipt, in accordance with Article 12 of the GDPR. In cases of complexity or volume, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the initial 30-day period.
Data Controller: John Meola Consulting, LLC, Fairfield, Connecticut, USA. Privacy contact: [email protected].
10.2 General U.S. Rights and Other State Residents
Even if you reside in a U.S. state that does not currently have a comprehensive consumer privacy law applicable to our business, we respect general privacy principles and extend the following commitments to all Website visitors:
- Opt-Out of Marketing Communications: If you have received marketing or promotional emails from us, you may opt out at any time by clicking the unsubscribe link included in the email or by contacting us at [email protected]. We will honor all opt-out requests promptly (see Section 12 for CAN-SPAM details).
- Access and Correction Requests: We will make reasonable efforts to honor requests to access or correct personal information we hold about you, to the extent practicable.
- Non-Retaliation: We will not treat you differently or deny you services based on your exercise of any privacy rights.
11. Children’s Privacy (COPPA Compliance)
Our Website, jmeolaconsulting.com, is a business-to-business and professional services website. It is not directed to children under the age of 13, and we do not knowingly collect, solicit, or maintain personal information from any person under 13 years of age.
In compliance with the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, and the FTC’s COPPA Rule, 16 C.F.R. Part 312:
- We do not knowingly collect personal information from children under 13;
- If we discover that we have inadvertently received personal information from a child under 13, we will take prompt steps to delete that information from our records; and
- We do not direct any content, advertising, or outreach toward children under 13.
If you are a parent or legal guardian and believe that your child under the age of 13 may have submitted personal information to us through our Website, please contact us immediately at [email protected]. We will promptly investigate and, if confirmed, delete the information.
If you are under 13 years of age, please do not use or access our Website and do not submit any personal information through our Website.
12. Email Communications and CAN-SPAM Compliance
We comply with the CAN-SPAM Act, 15 U.S.C. § 7701 et seq., and the FTC’s implementing regulations. With respect to any commercial email communications we send:
- Accurate Sender Information: We will not use false or misleading header information. Our “From,” “To,” and “Reply-To” fields will accurately identify us as the sender.
- Non-Deceptive Subject Lines: We will not use deceptive subject lines. The subject line of each commercial email will accurately reflect the content of the message.
- Physical Address: Each commercial email we send will include our valid physical postal address: John Meola Consulting, LLC, Fairfield, Connecticut, USA.
- Opt-Out Mechanism: Each commercial email will contain a clear and conspicuous explanation of how the recipient can opt out of receiving future commercial emails from us, such as a clearly visible unsubscribe link or reply option.
- Prompt Opt-Out Processing: We will honor opt-out requests within 10 business days of receipt. Once you opt out, we will not send you further commercial emails unless you subsequently opt back in.
- No Third-Party Opt-Out Selling: We will not sell, transfer, or assign email addresses of individuals who have opted out to any third party for the purpose of contacting that individual with commercial emails.
Please note that transactional or relationship messages (e.g., direct responses to your inquiries) are not subject to CAN-SPAM’s opt-out requirements, though we will always respect your communication preferences.
To opt out of any marketing or commercial emails from us, please email [email protected] with the subject line “Unsubscribe” or use the unsubscribe link provided in the email.
13. Third-Party Links
Our Website may contain hyperlinks to third-party websites, resources, or services that are not owned or controlled by John Meola Consulting, LLC. These links are provided for your convenience and informational purposes only.
We have no control over, and assume no responsibility for, the content, privacy policies, data practices, or practices of any third-party websites or services. The inclusion of a hyperlink on our Website does not imply our endorsement of the linked website or any association with its operators.
We strongly encourage you to review the privacy policy of every website you visit, particularly before submitting any personal information. This Privacy Policy applies only to jmeolaconsulting.com and does not govern your activities on any third-party websites.
14. Changes to This Privacy Policy
We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Post the updated Privacy Policy on this page at jmeolaconsulting.com;
- Update the Effective Date at the top of this document to reflect the date of the most recent revision; and
- For material changes — meaning changes that meaningfully affect your rights or the way in which we process your personal information — provide you with reasonable advance notice, which may include a prominent notice on our Website homepage or, where we have your email address and it is appropriate, direct notification by email.
Your continued use of our Website following the posting of an updated Privacy Policy constitutes your acknowledgment of the changes and your agreement to be bound by the revised terms. If you do not agree with any updates to this Privacy Policy, please discontinue your use of our Website.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. If you have questions about any changes, please contact us at [email protected].
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our personal data practices, please do not hesitate to contact us. We are committed to resolving privacy-related inquiries promptly and transparently.
| Business Name | John Meola Consulting, LLC |
| Location | Fairfield, Connecticut, USA |
| Website | jmeolaconsulting.com |
| Privacy Inquiries Email | [email protected] |
| Role Under GDPR | Data Controller |
| Role Under CTDPA | Controller |
How to Submit a Privacy Rights Request
To exercise any of your privacy rights as described in Section 10 of this Privacy Policy — including rights under the CTDPA or GDPR — please send an email to [email protected] with the following information:
- Your full name;
- Your email address or other contact information;
- Your state or country of residence (to help us identify the applicable legal framework);
- A clear description of the right you wish to exercise (e.g., “I am requesting a copy of my personal data” or “I am requesting deletion of my personal data”); and
- Any additional information that may help us locate your records (e.g., the email address you used to contact us).
We may ask you to verify your identity before processing your request to ensure that we do not disclose or delete information based on a fraudulent or erroneous request. We will not use information provided in a verification request for any purpose other than verification.
We do not currently have a designated Data Protection Officer (DPO), as one is not required for a business of our size and nature under the GDPR. All privacy-related inquiries should be directed to [email protected].
Applicable Legal Frameworks Referenced in This Policy
- Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. §§ 42-515 to 42-525, effective July 1, 2023
- EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679
- Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506
- CAN-SPAM Act, 15 U.S.C. § 7701 et seq.
- Federal Trade Commission Act, 15 U.S.C. § 45 (FTC Act / FTC Guidance on Privacy)
