Last updated: 2 October 2026
Last reviewed against the law in force on: 1 October 2026
1. Who we are and what this notice covers
1.1 Controllers. This notice is issued jointly by T&T Consulting Business, LLC and Tudor & Tudor, LLC, Florida limited liability companies, 13575 58th St N, Suite 200, Clearwater, Florida 33760 ("T&T", "we", "us"). The two companies act as joint controllers. T&T Consulting Business, LLC contracts, invoices and collects payment for all our services. Our operations are directed from Split, Croatia.
1.2 Privacy contact. Dinko Anton Tudor, Managing Member, legal@tudorsgroup.com, telephone +1 813 384 8490.
1.3 Function of this notice. This notice supplements our general Privacy Policy for individuals who reside in the United States and prevails over it where they differ. It is our privacy policy under Cal. Civ. Code §1798.130(a)(5) and Cal. Code Regs. tit. 11, §7011; our notice at collection under Cal. Civ. Code §1798.100(a) and §7012 of those regulations; and our privacy notice under the other state laws listed in section 12. Defined terms have the meaning given in Cal. Civ. Code §1798.140 and the equivalent state definitions.
1.4 Business contacts. We serve only businesses and professionals. Most state laws exclude individuals acting in a commercial or employment context. California does not: since 1 January 2023 the CCPA covers business contacts and job applicants. We treat everyone who contacts us, in any capacity, as entitled to the rights in this notice.
2. Notice at collection
2.1 We link to this notice at or before every point where our website collects personal information. In summary:
| Item | Summary |
|---|---|
| Categories collected | Identifiers; customer records; commercial information; professional information; limited education history (CVs only). See section 3. |
| Sensitive personal information | Not requested. May appear in documents you choose to send. Not used to infer characteristics about you. See section 5. |
| Purposes | Answering your request; performing, invoicing and collecting payment for the service; assessing applications; transactional messages; legal records and claims; security. See clause 4.1. |
| Sold or shared | No. We do not sell or share personal information and have not done so in the preceding 12 months. |
| Retention | Requests without an engagement: 24 months from last contact. Applications: 12 months from the close of the selection process. Client files, contracts and invoices: the legal accounting and tax period or, if longer, the limitation period for contractual claims. See section 6. |
| Your rights | Know and access, delete, correct, portability, opt out, limit, non-discrimination, appeal. See sections 7 to 10. |
2.2 We will not collect further categories, or use personal information for purposes materially different from those stated, without first giving you a new notice (Cal. Civ. Code §1798.100(a)(1) and (2)).
3. Categories of personal information (preceding 12 months)
3.1 The table follows Cal. Civ. Code §1798.140(v)(1)(A) to (K). Purpose codes are in clause 4.1 and recipient codes in clause 4.3.
| Category | Collected | Examples | Source | Purposes | Disclosed for a business purpose to |
|---|---|---|---|---|---|
| (A) Identifiers | Yes | Name, email, telephone, company address, company tax or VAT number | You | P1 to P7 | R1 to R5, R7, R8 |
| (B) Customer records (§1798.80(e)) | Yes | Name, telephone, employment, documents you send | You | P1, P2, P3, P6 | R1 to R4, R7, R8 |
| (C) Protected classifications | Not requested | Only if you include them in a CV or document (for example age, nationality) | You | P4 (incidental) | R1, R4 |
| (D) Commercial information | Yes | Services requested or bought, booking details, payment status, transaction details (product, volume, Incoterms, origin, target price, frequency), invoices | You; Stripe (payment status) | P1, P2, P3, P6 | R1 to R4, R7, R8 |
| (E) Biometric information | No | ||||
| (F) Internet or network activity | No | See clause 3.3 | |||
| (G) Geolocation | No | Our visit counter records countries only in aggregate | |||
| (H) Audio, visual or similar | Live only | Image and voice transmitted during a Google Meet consultation; consultations are not recorded | You | P2 | R5 |
| (I) Professional or employment | Yes | Company, role, CV, mandate and company documents | You | P1, P2, P4 | R1, R2, R4, R7, R8 |
| (J) Education | Limited | Education history in a CV; no non-public education records under 20 U.S.C. §1232g | You | P4 | R1, R4 |
| (K) Inferences | No | We do not build profiles. See clause 4.5 |
3.2 Sources. We collect personal information (a) from you, through our forms, the site assistant, email, bookings and video calls; (b) from Stripe, which tells us whether a payment succeeded; and (c) in due diligence engagements, from the documents you give us about a counterparty and from public sources consulted to verify it: company registers, official sanctions lists, publicly accessible court and insolvency registers, and the counterparty's own website and documents.
3.3 Website activity. We set no cookies of our own and use no advertising or third-party analytics trackers. Our own visit counter keeps only daily totals per page, country, network and referring source, with no cookie, IP address or identifier: our server adds each page it serves to these totals, and the script that confirms that a person viewed the page runs only if you accept "Analytics". These totals are aggregate consumer information (§1798.140(b)), not personal information. Our host, Cloudflare, processes your IP address to deliver and protect the site. Our form handler keeps no request logs containing your IP address. On the consultation booking page, once you choose a time, Stripe's payment form is loaded from Stripe, which receives your IP address and device data and may set its own cookies to prevent fraud.
4. Use and disclosure
4.1 Purposes. We use personal information only for the following business purposes (§1798.140(e)) or purposes compatible with the context of collection (§1798.100(c); Cal. Code Regs. tit. 11, §7002):
- P1 Receiving, classifying and answering your request (commodities, Adriatic, FDA, permits, OFAC, due diligence, site assistant).
- P2 Performing the service you ordered.
- P3 Processing payments, issuing receipts and invoices, and handling refunds under our Terms.
- P4 Assessing job applications.
- P5 Sending transactional messages, such as booking confirmations and reminders.
- P6 Keeping accounting, tax and contractual records, and establishing, exercising or defending legal claims.
- P7 Securing our website and systems, preventing fraud and debugging.
We do not use personal information for advertising or third-party marketing.
4.2 No sale, no sharing. We do not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising, and we have not done so in the preceding 12 months. For that reason we do not display a "Do Not Sell or Share My Personal Information" link (Cal. Code Regs. tit. 11, §7013(a)). We have no actual knowledge of selling or sharing the personal information of consumers under 16 (§1798.120(c)). We do not disclose personal information to third parties for their own direct marketing (Cal. Civ. Code §1798.83).
4.3 Recipients for a business purpose. Each recipient is bound by a written contract limiting its use of the information to the services it provides to us (§1798.100(d); §7051):
| Code | Recipient | Function |
|---|---|---|
| R1 | Cloudflare, Inc. | Hosting; receives form submissions and stores them in Cloudflare R2 |
| R2 | Stripe, Inc. | Payment form, hosted checkout and card processing. We never see your card details |
| R3 | ZeptoMail, Zoho Corporation (United States data centre) | Transactional email |
| R4 | Zoho Mail, Zoho Corporation (United States data centre) | Our mailbox, including legal@tudorsgroup.com |
| R5 | Google Meet, under our Google Workspace business account | Consultations, not recorded |
| R7 | Professional advisers, where we engage them | Accounting, tax and legal advice, under confidentiality |
| R8 | Courts, regulators, law enforcement | Only where required by law or to establish, exercise or defend claims |
Internal alerts through Telegram contain no names and no content of your request, so no personal information is disclosed to Telegram. Food and beverage products are sold by Tudor Adriatic d.o.o. (Split, Croatia), a group company, under its own terms of sale. When you send an Adriatic request, you direct us to pass it to Tudor Adriatic d.o.o. so that it can answer you and sell you the products; this disclosure at your direction is not a sale (§1798.140(ad)(2)(A)). If our business is transferred, personal information may pass to the acquirer under §1798.140(ad)(2)(C).
4.4 Our own systems and location. Submissions are copied from Cloudflare R2 to our own client management system on a server owned by T&T in Croatia, reachable only from our internal network. Personal information is therefore processed in the United States and in Croatia, where the GDPR also applies (see section 22 of our Privacy Policy).
4.5 Automated processing. A language model running on that server (Ollama) assigns each request a category from a closed list (for example: request, out of scope, spam, commercial, press or supplier) and writes a one-line summary for our staff. For requests to buy a service it also flags, quoting the words concerned, warning signs of trade fraud defined in our own verification protocol, each with a fixed weight set by the protocol. It makes no decision about you, does not score, accept, reject, rank or price any request, does not process applications received through Careers, and does not evaluate personal aspects of you. A person reads every request and application in full and makes every decision. Your information is not used to train any model and no third-party AI service receives it. It is therefore neither automated decisionmaking technology for a significant decision (Cal. Code Regs. tit. 11, §7200 et seq.) nor profiling with legal or similarly significant effects. The site assistant answers from a fixed set of questions without any AI model.
5. Sensitive personal information
5.1 None of our forms asks for any category in §1798.140(ae). Sensitive information may reach us only if you include it in a document you choose to send, for example an officer's passport in due diligence or company formation documents, a Social Security number used as a sole proprietor's tax number, or personal details in a CV. We ask you not to send sensitive information the service does not require, and to give an EIN rather than a Social Security number where one exists.
5.2 We use any sensitive personal information we receive only to perform the service you requested and for the other purposes permitted by Cal. Code Regs. tit. 11, §7027(m). We do not use it to infer characteristics about you, so under §1798.121(d) and §7014(h) we are not required to offer a "Limit the Use of My Sensitive Personal Information" link. We will nevertheless honor any request to limit (clause 7.5). Where another state requires opt-in consent for sensitive data, we will ask for it before any use beyond the service you requested. We never sell or share sensitive personal information.
6. Retention
6.1 We keep personal information only as long as reasonably necessary and proportionate to the purpose (§1798.100(a)(3)):
| Record (categories) | Retention | From |
|---|---|---|
| Requests and enquiries without an engagement (A, B, D, I) | 24 months | Last contact |
| Job applications and CVs (A, C, I, J) | 12 months | Close of the selection process |
| Client files, contracts and invoices (A, B, D, I) | The statutory accounting and tax period that applies to T&T Consulting Business, LLC or, if longer, the limitation period for contractual claims (five years for an action on a written contract, Fla. Stat. §95.11(2)(b)) | End of the financial year in which the engagement ends |
| Sensitive information received in documents | As for the file it belongs to; deleted earlier on request if not required | Receipt |
| Privacy requests and responses | 24 months (Cal. Code Regs. tit. 11, §7101) | Our response |
| Visit counter totals (not personal information) | 400 days | Recording |
6.2 At the end of the period we delete or deidentify the information. Information under a legal hold is kept until the matter ends.
7. Your rights
7.1 Know and access (§§1798.100, 1798.110, 1798.115). You may ask for the categories of personal information we hold about you, its sources, our purposes, the categories of recipients, and the specific pieces of information. You may ask for information collected from 1 January 2022 onward (§7024), and we will provide it in a portable, readily usable format (portability). On request we will name the specific third parties to which we have disclosed your personal information.
7.2 Delete (§1798.105). We will delete personal information collected from you and instruct our service providers to do so, except where §1798.105(d) allows us to keep it (for example to complete the service, to meet accounting and tax obligations, for security, or for legal claims). We will tell you what we keep and why.
7.3 Correct (§1798.106; §7023). We will correct inaccurate personal information, considering the totality of the circumstances, and instruct our service providers to do the same.
7.4 Opt out (§1798.120 and equivalent state rights) of sale, sharing, targeted advertising and profiling. We do none of these, but we will record any opt-out request and apply it to any future processing.
7.5 Limit the use of sensitive personal information (§1798.121), and ask us to delete sensitive information the service does not require.
7.6 Non-discrimination (§1798.125). We will not deny you services, charge a different price, provide a different quality of service, or retaliate against you, because you exercised your rights. We offer no financial incentives in exchange for personal information.
7.7 Withdraw consent at any time, for the website through "Cookie settings" in the footer and otherwise by email.
8. How to exercise your rights
8.1 Method. Email legal@tudorsgroup.com with your name, the email address you used with us and the right you wish to exercise. As we operate exclusively online and have a direct relationship with the people whose information we hold, email is a sufficient method under §1798.130(a)(1)(A). Requests are free of charge, unless manifestly unfounded or excessive (§1798.145(h)(3)).
8.2 Time limits.
| Step | Time limit |
|---|---|
| Acknowledge a request to know, delete or correct | Within 10 business days (Cal. Code Regs. tit. 11, §7021(a)). We aim to acknowledge within 7 days, as in our Privacy Policy |
| Respond | Within 45 calendar days of receipt (§1798.130(a)(2); §7021(b)). We do not use the statutory extension |
| Opt-out and limit requests | As soon as feasibly possible and within 15 business days (§7026(f); §7027(g)) |
| Appeal decision | Within 45 calendar days of receipt of the appeal (section 10) |
8.3 Verification (§§7060 to 7062). We verify identity by matching information you give us against information we already hold: two data points for categories, deletion or correction of non-sensitive information (reasonable degree of certainty); three data points and a signed declaration under penalty of perjury for specific pieces of information or sensitive information (reasonably high degree of certainty). We use verification information only for that purpose. If we cannot verify you, we will say why and, for a deletion request, treat it as an opt-out where applicable. Opt-out and limit requests need no verification.
8.4 Authorized agents (§1798.130(a)(3); §7063). An agent may act for you with your signed permission. We may ask you to verify your identity directly or confirm the permission, except where the agent holds a power of attorney under Cal. Prob. Code §§4121 to 4130.
8.5 Our response. If we refuse a request in whole or in part, we will explain why and how to appeal. We will not disclose Social Security, government ID or financial account numbers, passwords or security answers; we will confirm instead that we hold that type of information (§7024(d)).
9. Global Privacy Control
9.1 We treat a Global Privacy Control (GPC) signal as a valid request to opt out of sale, sharing and targeted advertising, for the browser and, where known, for you (§1798.135(b); Cal. Code Regs. tit. 11, §7025; and the universal opt-out provisions of the other states). On our website, a GPC signal keeps the "Analytics" category switched off for that browser.
9.2 As required by §7025(c)(6) and §7026(g), our consent banner and cookie settings display whether the signal has been processed, with the message "Opt-out request honored", followed by an explanation that analytics and marketing are switched off and will stay off.
9.3 Do Not Track (Cal. Bus. & Prof. Code §22575(b)(5)). We do not track visitors across third-party websites over time and do not allow third parties to do so on our site. We do not respond differently to "Do Not Track" signals, which have no agreed standard; we do honor Global Privacy Control (Section 9).
10. Appeals and complaints
10.1 Appeal. If we decline to act on your request, in whole or in part, you may appeal by replying to our answer with "Appeal" in the subject line. We will tell you in writing, within 45 calendar days, what action we have taken and why. If we deny the appeal, we will give you the contact details of your state Attorney General. California, Utah and Alabama law provide no statutory appeal; we offer it to all.
10.2 California regulator. California residents may contact the California Privacy Protection Agency (CalPrivacy), https://privacy.ca.gov, which receives complaints at https://privacy.ca.gov/submit-a-complaint/, or the California Attorney General, oag.ca.gov/privacy. Residents of other states may contact the authority listed in section 12.
11. Children
11.1 Our services are for businesses and professionals. We do not knowingly collect personal information from anyone under 18, and we do not sell or share that of anyone under 16. If we learn we have collected it, we will delete it. Our website is not directed to children under 13 (15 U.S.C. §§6501 to 6506).
12. Other states
12.1 Thresholds. Each state law applies only to businesses above its thresholds. For example, the CCPA applies to a for-profit business doing business in California with annual gross revenue above USD 26,625,000 (as adjusted for 2025 and 2026), or that buys, sells or shares the personal information of 100,000 or more consumers or households, or derives 50% or more of its revenue from selling or sharing it. The Connecticut law, as amended with effect from 1 July 2026, applies to businesses that process the personal data of 35,000 or more Connecticut consumers, or any sensitive data (other than for payment), or that sell personal data. T&T is a micro-enterprise and its revenue is well below the California revenue threshold. Section 12.2 applies whether or not any threshold is met.
12.2 Our commitment. Whether or not a threshold is met, we give every US resident the rights in sections 7 to 10, with a response within 45 days and an appeal decision within 45 days, the time limits that satisfy every law below. This commitment does not concede that any law applies to us and creates no right of action the law does not otherwise give.
12.3 Comprehensive state privacy laws. Response times are those of each statute (calendar days, plus any extension it allows); we apply 45 and 45 in all cases.
| State | Law | Response | Appeal | Authority |
|---|---|---|---|---|
| California | CCPA/CPRA, Cal. Civ. Code §1798.100 et seq. | 45 + 45 | None | CalPrivacy (privacy.ca.gov); Attorney General (oag.ca.gov) |
| Virginia | VCDPA, Va. Code §59.1-575 et seq. | 45 + 45 | 60 | Attorney General (oag.state.va.us) |
| Colorado | CPA, Colo. Rev. Stat. §6-1-1301 et seq. | 45 + 45 | 45 + 60 | Attorney General (coag.gov) |
| Connecticut | CTDPA, Conn. Gen. Stat. §42-515 et seq. | 45 + 45 | 60 | Attorney General (portal.ct.gov/ag) |
| Utah | UCPA, Utah Code §13-61-101 et seq. | 45 + 45 | None | Attorney General; Division of Consumer Protection (dcp.utah.gov) |
| Texas | TDPSA, Tex. Bus. & Com. Code ch. 541 | 45 + 45 | 60 | Attorney General (texasattorneygeneral.gov) |
| Oregon | OCPA, ORS 646A.570 to 646A.589 | 45 + 45 | 45 | Department of Justice (doj.state.or.us) |
| Montana | MCDPA, Mont. Code Ann. §30-14-2801 et seq. | 45 + 45 | 60 | Department of Justice (dojmt.gov) |
| Iowa | ICDPA, Iowa Code ch. 715D | 90 + 45 | 60 | Attorney General (iowaattorneygeneral.gov) |
| Delaware | DPDPA, Del. Code Ann. tit. 6, ch. 12D | 45 + 45 | 60 | Department of Justice (attorneygeneral.delaware.gov) |
| New Hampshire | RSA ch. 507-H | 45 + 45 | 60 | Department of Justice (doj.nh.gov) |
| New Jersey | N.J. Stat. Ann. §56:8-166.4 et seq. | 45 + 45 | 45 | Division of Consumer Affairs (njconsumeraffairs.gov) |
| Nebraska | NDPA, Neb. Rev. Stat. §87-1101 et seq. | 45 + 45 | 60 | Attorney General (ago.nebraska.gov) |
| Tennessee | TIPA, Tenn. Code Ann. §47-18-3201 et seq. | 45 + 45 | 60 | Attorney General (tn.gov/attorneygeneral) |
| Minnesota | MCDPA, Minn. Stat. §325M.10 et seq. | 45 + 45 | 45 + 60 | Attorney General (ag.state.mn.us) |
| Maryland | MODPA, Md. Code, Com. Law §14-4701 et seq. | 45 + 45 | 60 | Attorney General (marylandattorneygeneral.gov) |
| Indiana | ICDPA, Ind. Code art. 24-15 | 45 + 45 | 60 | Attorney General (in.gov/attorneygeneral) |
| Kentucky | KCDPA, Ky. Rev. Stat. §367.3611 et seq. | 45 + 45 | 60 | Attorney General (ag.ky.gov) |
| Rhode Island | RIDTPPA, R.I. Gen. Laws ch. 6-48.1 | 45 + 45 | 60 | Attorney General (riag.ri.gov) |
| Oklahoma (from 1 Jan 2027) | Consumer Data Privacy Act (SB 546, 2026) | 45 + 45 | 60 | Attorney General (oag.ok.gov) |
| Louisiana (from 1 Jan 2027) | Data Privacy Act (SB 386, Act 502 of 2026) | 45 + 45 | 60 | Attorney General (ag.louisiana.gov) |
| Alabama (from 1 May 2027) | Personal Data Protection Act (HB 351, 2026) | 45 + 45 | None | Attorney General (alabamaag.gov) |
| Vermont (from 1 Jan 2028) | Data Privacy and Online Surveillance Act (S.71, 2026) | 45 | 60 | Attorney General (ago.vermont.gov) |
12.4 Rights under these laws. These laws grant rights to access, correct, delete, portability, opt out of targeted advertising, sale and significant profiling, and appeal, and some add the list of named third parties (Oregon, Delaware, Minnesota, Maryland) or the right to question profiling (Minnesota; Connecticut). We grant all of them to every US resident, including in states whose laws are not yet in force.
13. Security, changes and contact
13.1 Security. We maintain reasonable security procedures appropriate to the nature of the information (§1798.100(e); §1798.81.5; Fla. Stat. §501.171(2)). If a breach affects you, we will notify you as required by the law of your state.
13.2 Changes. We review this notice at least every 12 months (§1798.130(a)(5)) and whenever our processing or the law changes. Material changes will be reflected in the effective date and notified where the law requires it.
13.3 Contact. T&T Consulting Business, LLC and Tudor & Tudor, LLC, 13575 58th St N, Suite 200, Clearwater, Florida 33760, United States; telephone +1 813 384 8490. Privacy contact: Dinko Anton Tudor, Managing Member, legal@tudorsgroup.com. This notice is available in an accessible format on request to legal@tudorsgroup.com (§7003(a); §7011(a)).