Detailed Data Governance, Privacy Rights (GDPR / CCPA / CPRA), Cookie Compliance, and Data Processing Framework for DOTCHATER LLC
For technical security controls, vulnerability management, and incident SLAs, visit our Partner Security Policy.
DOTCHATER LLC ("Company", "We", "Us", or "Our") is committed to maintaining the trust and confidence of our website visitors, software application users, B2B corporate clients, and marketplace partners. This Privacy Policy outlines the types of personal data we collect, why we collect it, how we process and store it securely, and your explicit statutory rights regarding your personal information.
This policy applies to all websites hosted under the dotchater.com domain, custom software platforms developed and maintained by DOTCHATER LLC, and any partner integrations or cloud API endpoints operated by our engineering team.
We process personal data in accordance with the principles of data minimization and purpose limitation. Data collected falls under three primary categories:
Under regulations such as the General Data Protection Regulation (GDPR Article 6), we process personal information only where a valid legal basis exists:
DOTCHATER LLC utilizes enterprise cloud hosting environments (e.g. AWS and GCP) hosted in secure tier-3 data centers located in the United States and European Union. All stored database assets and user data are encrypted at rest using AES-256 encryption.
Where personal data is transferred across international borders outside the European Economic Area (EEA), DOTCHATER LLC ensures appropriate safeguards are in place, including standard contractual clauses (SCCs) approved by the European Commission or equivalent cross-border data transfer mechanisms.
DOTCHATER LLC DOES NOT SELL, RENT, LEASE, OR TRADE PERSONAL DATA TO THIRD PARTIES OR DATA BROKERS UNDER ANY CIRCUMSTANCES.
We share personal data strictly with trusted third-party infrastructure subprocessors necessary to deliver our services (e.g., cloud hosting providers, payment gateways, and error monitoring tools). All subprocessors are vetted for security compliance and operate under strict data processing addendums requiring equal or greater privacy protection standards.
Depending on your location, you hold specific statutory rights regarding your personal information:
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Upon expiration of the retention period, data is securely deleted or anonymized in accordance with NIST data sanitization guidelines.
Our website utilizes essential functional cookies required for site navigation, security token verification, and form state preservation. We do not use intrusive cross-site tracking or third-party behavioral advertising cookies.
To submit a Data Subject Access Request (DSAR) or contact our privacy governance team, please reach out to:
privacy@dotchater.com
Attn: Data Protection Officer — DOTCHATER LLC
New Mexico, USA