Hawk Site Amp
Trust & Compliance

Data Handling Policy

How Hawk Site Amp handles customer data, vendor access, retention, deletion, and security processes.

Effective Date: May 24, 2025Last Updated: May 24, 2025

1. Purpose

This policy describes how Hawk Site Amp handles operational, customer, project, support, and platform data. It establishes expectations for how data is classified, accessed, retained, and protected across the platform and its associated services and vendors.

2. Types of Data Handled

Hawk Site Amp may handle the following categories of data:

  • Customer contact data (name, email, phone)
  • Account and authentication data
  • Billing references and subscription records
  • Project files, website content, and client assets
  • Support messages and communication logs
  • Platform analytics and feature usage data
  • Vendor and subprocessor records
  • Audit logs and internal compliance records

3. Data Classification

We classify data into four categories to guide handling and access decisions:

  • Public — Information intentionally made publicly available, such as published website content or public-facing documentation.
  • Internal — Information used within normal business operations, not intended for public disclosure but not highly sensitive. Examples include general feature usage analytics and internal documentation.
  • Confidential — Sensitive business or customer information that requires controlled access. Examples include customer account data, support communications, and project files.
  • Restricted — Highly sensitive data requiring the strictest controls. Examples include credentials, API keys, payment tokens, and security-related incident records.

4. Access Control

Access to customer data is limited to authorized team members, administrators, vendors, and service providers who need it to deliver services, support customers, secure the platform, or meet legal obligations. Access is role-based and reviewed periodically. Admin-only features within the platform require authenticated admin sessions to access sensitive operational data.

5. Payment Data

Hawk Site Amp uses approved third-party payment processors to handle payment card transactions. We avoid storing sensitive payment card numbers, CVVs, or full card data directly within the application. Payment processors used by the platform maintain their own compliance programs appropriate to their service. We store only the billing references, subscription status, and transaction metadata necessary to manage customer accounts.

6. Vendor and Subprocessor Handling

Vendors and subprocessors that access or process customer data are tracked in the internal compliance center. Each vendor record includes: name, purpose, data accessed, risk level, review status, and last reviewed date. Vendors are selected based on their ability to meet reasonable security and data handling standards. Our vendor register is maintained and reviewed periodically as services change or new vendors are added.

7. Data Retention

Data is retained only for as long as needed to fulfill the following purposes:

  • Delivering and supporting active services
  • Maintaining accurate business records
  • Responding to customer support needs
  • Meeting legal, regulatory, or contractual obligations
  • Resolving disputes or handling claims
  • Fraud prevention and platform security

When data is no longer needed, we take reasonable steps to delete or anonymize it.

8. Data Deletion

Customers may request deletion of their data by contacting us at support@hawksiteamp.io. We will review and process deletion requests in a reasonable timeframe. Note that some data may need to be retained for legal, billing, dispute resolution, fraud prevention, or security purposes even after a deletion request is made.

9. Data Requests

Customers may submit the following types of data requests by contacting support@hawksiteamp.io:

  • Access Request — Request a summary of the personal data we hold about you.
  • Correction Request — Request that inaccurate or outdated information be corrected.
  • Deletion Request — Request that your personal data be deleted, subject to applicable retention requirements.
  • Export Request — Request a copy of your data in a portable format where feasible.

We will acknowledge and respond to requests within a reasonable timeframe. Some requests may take additional time depending on complexity.

10. Incident Response

If a suspected security incident is identified, Hawk Site Amp will investigate, contain, and document the event according to its internal incident response procedures. Response severity and actions will depend on the nature and scope of the incident. Affected parties will be notified as appropriate and in accordance with applicable obligations. All incidents are logged in the internal compliance center for tracking and review.

11. Backups and Recovery

Backup and recovery capabilities for customer data may depend on the hosting infrastructure and approved vendors used to deliver the platform. We work to ensure reasonable data durability and availability. Specific backup guarantees, if any, are defined within applicable service agreements or hosting arrangements.

12. Internal Review

This policy will be reviewed periodically — at minimum annually or when significant changes occur to the platform, services, vendor roster, or applicable legal requirements. The compliance team is responsible for keeping this policy current and maintaining supporting records in the internal compliance center.

13. Contact

For data handling questions, data requests, or compliance inquiries, please contact us:

support@hawksiteamp.io

This policy is provided for transparency and operational guidance. Hawk Site Amp may update this policy as services, vendors, and legal requirements evolve.
base44
Edit with Base44