Privacy Policy
Effective Date: February 25, 2025
Last Updated: August 24, 2026
Total Care IT (“Company,” “we,” “our,” or “us”) values your privacy and is committed to protecting your personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website, totalcareit.com (“Website”), when you interact with us as a prospective or current client, and, as described below, in connection with the managed IT services we provide. By using our Website, you agree to the terms of this Privacy Policy.
This Privacy Policy does not govern our processing of data belonging to our clients and their end users that we access, host, or process while delivering managed IT services. That processing is governed by the applicable Master Services Agreement, Statement of Work, or Data Processing Agreement between Total Care IT and the client, as described further in Section 1(c) below.
1. Information We Collect
We may collect the following types of information when you interact with our Website: In addition, when we deliver managed IT services to our clients, we may collect and process additional information as described in Section 1(c) below.
a. Personal Information:
- Name
- Email address
- Phone number
- Company name
- Any other information you voluntarily provide via our contact forms
- Billing and payment details (e.g., billing contact, invoice, and payment information) processed on our behalf by a third-party payment processor
- Information you provide when requesting a quote, submitting a support or help desk ticket, or otherwise engaging our services
b. Non-Personal Information:
- IP address
- Browser type and version
- Pages visited and time spent on the Website
- Device information
- Cookies and tracking technologies
- Approximate geographic location derived from your IP address
c. Information We Process on Behalf of Our Clients (“Client Data”):
As a managed IT services provider, we may access, host, or process data belonging to our clients and their employees, customers, or other end users while delivering services such as remote monitoring and management, help desk and technical support, backup and disaster recovery, cybersecurity monitoring, cloud administration, and network management (“Client Data”). Client Data may include personal information about individuals associated with our clients. We process Client Data solely on behalf of, and under the instructions of, our clients, who act as the data controller (or “business,” as applicable) for that information. Our handling of Client Data is governed by the applicable Master Services Agreement, Statement of Work, or Data Processing Agreement with the client, and not by this Privacy Policy. Individuals with questions about how their personal information is handled within a client environment should contact that client directly.
d. Information from Other Sources:
We may also obtain information about you from third parties, such as business partners, referral sources, and publicly available sources, which we may combine with information we collect directly.
e. Job Applicant and Employment-Related Information:
If you apply for a position with us through our Website or otherwise submit an employment application, we may collect information such as your resume, work history, references, and contact details. We use this information for recruitment and employment purposes. Where applicable, this information is treated as personal information subject to this Privacy Policy, including under the California Consumer Privacy Act.
2. How We Use Your Information
We use the information collected for the following purposes:
- To respond to inquiries submitted through our contact forms
- To provide customer support and service updates
- To improve our Website and services
- To send promotional emails or newsletters (only if you have opted in)
- To comply with legal obligations
- To deliver and support managed IT services under an active client agreement
- To detect, investigate, and help prevent security incidents, fraud, and misuse of our systems
- To maintain business records and manage our vendor and client relationships
We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement.
3. Legal Basis for Processing (EEA, UK, and Similar Jurisdictions)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on one or more of the following: performance of a contract with you or your organization; our legitimate interests in operating, securing, and improving our business and Website, provided those interests are not overridden by your data protection interests or fundamental rights; your consent, where required (for example, for marketing emails or non-essential cookies); and compliance with a legal obligation.
4. How We Share Your Information
We do not sell or rent your personal information. However, we may share your data with:
- Service providers: Third-party vendors who help operate our Website and services
- Legal authorities: If required to comply with applicable laws, regulations, or legal processes
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred
- Professional advisors: Attorneys, accountants, auditors, and insurers, as needed
- Subprocessors: IT infrastructure, remote monitoring and management, ticketing, cloud hosting, and cybersecurity vendors that support our managed services operations, each bound by confidentiality and data protection obligations
We require our service providers and subprocessors to protect personal information consistent with this Privacy Policy and applicable law, and we do not permit them to use personal information for their own marketing purposes.
5. International Data Transfers
We are based in the United States, and information we collect may be transferred to, stored, and processed in the United States or other countries that may have data protection laws different from those of your jurisdiction. Where required, we implement appropriate safeguards, such as standard contractual clauses, to protect personal information transferred internationally.
6. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, including to provide our services, maintain business and tax records, resolve disputes, enforce our agreements, and comply with legal obligations. Retention periods vary depending on the type of information and the purpose for which it was collected; Client Data is retained in accordance with the applicable client agreement. When personal information is no longer needed, we take reasonable steps to securely delete, destroy, or anonymize it.
7. Regulated Data and Subcontractor Status (HIPAA, GLBA, and Similar Frameworks)
Some of our clients operate in regulated industries, such as healthcare or financial services. Where we access, host, or process protected health information on behalf of a client subject to the Health Insurance Portability and Accountability Act (“HIPAA”), we do so as a Business Associate under a Business Associate Agreement with that client. Where we process nonpublic personal information on behalf of a client subject to the Gramm-Leach-Bliley Act (“GLBA”), or support a client’s compliance with the Payment Card Industry Data Security Standard (PCI-DSS) or a similar framework, our obligations are governed by the applicable service provider addendum or agreement with that client, and not by this Privacy Policy.
8. Data Security
We implement appropriate security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. However, no data transmission over the Internet is 100% secure, and we cannot guarantee absolute security. These measures may include encryption, access controls, network monitoring, and employee training. In the event of a security incident affecting personal information, we will notify affected individuals and/or regulators as required by applicable law (see Section 13, Data Breach Notification).
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance user experience and analyze Website traffic. You can control cookie preferences through your browser settings. We may use the following categories of cookies: (i) strictly necessary cookies required for the Website to function; (ii) analytics cookies that help us understand how visitors use the Website; and (iii) functional cookies that remember your preferences. Disabling certain cookies may affect the functionality of the Website. We do not currently respond to browser “Do Not Track” signals.
10. Text Message (SMS) Communications
If you provide your mobile phone number and opt in to receive text messages from us, we will use that number only for the purposes you consented to, such as appointment reminders or support updates. Message and data rates may apply. You may opt out at any time by replying “STOP” to any text message, or by contacting us using the information in Section 18. We do not sell or share mobile opt-in information with third parties for their own marketing purposes.
11. Your Privacy Rights and Choices
Depending on your location, you may have the right to:
- Request access to or correction of your personal information
- Request deletion of your data
- Opt-out of marketing communications
- Restrict or object to data processing
California Residents (CCPA/CPRA):
If you are a California resident, you have the right to know what personal information we have collected about you, request deletion or correction of that information, opt out of the “sale” or “sharing” of personal information (we do not sell or share personal information for cross-context behavioral advertising), limit the use of sensitive personal information, and not be discriminated against for exercising these rights.
“Sensitive personal information” under California law includes information such as government identifiers, precise geolocation, and account log-in credentials. We only use sensitive personal information as reasonably necessary to provide our Website and services and do not use it to infer characteristics about you.
You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may still require you to directly verify your own identity with us.
U.S. State Privacy Rights (Other States):
If you reside in a state that has enacted a comprehensive consumer privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another such state, you may have similar rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of targeted advertising, the sale of personal information, or certain profiling. You may exercise these rights using the contact information in Section 18.
Nevada Residents:
Nevada law permits Nevada residents to opt out of the sale of certain covered information. We do not sell personal information as defined under Nevada law. You may still submit a request using the contact information in Section 18.
European Economic Area, United Kingdom, and Other Jurisdictions:
If applicable law provides you with additional rights, such as the right to data portability or the right to lodge a complaint with a data protection supervisory authority, you may exercise those rights by contacting us using the information in Section 18 or by contacting your local supervisory authority.
To exercise these rights, contact us at privacy@totalcareit.com. We will respond to verifiable requests within the timeframe required by applicable law.
12. Children’s Privacy
Our Website and services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without verified parental consent, we will take steps to delete that information.
13. Data Breach Notification
In the event of a breach of security affecting personal information for which we are responsible, we will notify affected individuals and applicable regulators without undue delay and in accordance with applicable law. Notification obligations relating to Client Data are governed by the applicable client agreement.
14. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites.
15. Website Accessibility
We strive to make our Website accessible to individuals with disabilities. If you experience difficulty accessing any part of our Website, please contact us using the information in Section 18 so we can assist you.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with the updated effective date. For material changes, we will provide additional notice, such as a notice on our Website or via email, prior to the change becoming effective.
17. Governing Law
This Privacy Policy is governed by the laws of the State of Florida, without regard to its conflict-of-laws principles, except to the extent applicable data protection law requires otherwise.
18. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at:
Total Care IT
Website: totalcareit.com
Email: privacy@totalcareit.com
Phone: (321) 259-5500
This Privacy Policy addresses matters within our control as a business. It does not apply to Client Data that we process on behalf of our clients under a separate services agreement, as described in Section 1(c).