Legal
Privacy policy
Last updated: 24 June 2026
Mastascusa Holdings LLC ("Mastascusa Holdings", "we", "us") operates this website at mastascusa.com. This policy explains what personal data we collect through the site, why we collect it, and the choices you have. It covers the website only.
Information you provide
When you contact us or request something through a form on this site — the contact and inquiry forms, the readiness scan, or the AI answer feature — we collect what you enter: typically your name, email address, an optional company name, and the contents of your message or question. You choose what to include. Please do not send sensitive personal information (such as health data, government identifiers, or financial account numbers) through these forms.
Information collected automatically
We use a privacy-friendly analytics measurement (Vercel Web Analytics) that reports aggregate, anonymized usage and does not set advertising or cross-site tracking cookies. We also process your IP address transiently to rate-limit forms and prevent abuse. Your theme preference (light or dark) is stored locally in your browser and is never sent to us.
How we use your information
- Respond to your inquiry and provide what you asked for — an audit conversation, a scan result, or an answer.
- Operate, secure, and improve the website, including preventing spam and abuse.
- Keep reasonable records of our communications with you.
Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on: taking steps at your request and performing any resulting engagement (Article 6(1)(b)); your consent when you voluntarily submit a message (Article 6(1)(a)); and our legitimate interests in responding to enquiries and keeping the site secure (Article 6(1)(f)).
The AI answer feature
If you use the "ask" feature, your question is sent to our AI provider, Anthropic, to generate a response. Do not include personal data about yourself or others that you would not want processed for that purpose.
Who we share it with
We do not sell your personal information. We share it only with the service providers that run this site, acting on our instructions:
- Vercel — hosting, our database (Vercel KV), and analytics.
- Resend — delivering your form submission to us by email.
- Anthropic — generating responses in the "ask" feature.
We may also disclose information where required by law.
How long we keep it
Inquiries are stored in our database and emailed to us. We keep them only as long as needed to handle your request and maintain reasonable business records, then delete them. You can ask us to delete your data sooner — see your rights below.
Where your data is processed
We operate from the United States, and our providers may process data in the United States and other countries. Where required for transfers from the EEA or UK, we rely on appropriate safeguards such as the relevant Standard Contractual Clauses.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, and to restrict or object to certain processing. California residents may request to know, delete, or correct their information and to opt out of any sale or sharing — we do not sell or share personal information as those terms are defined under California law.
To exercise any of these, use our data request form or email kevin@mastascusa.com. We verify your identity before acting and respond within the time the law allows (generally 30 days under the GDPR, 45 days under the CCPA). We will not discriminate against you for exercising your rights.
Cookies
We do not use advertising or cross-site tracking cookies, and our analytics is cookieless. The only thing we store in your browser is your theme preference, in local storage.
Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children
This site is not directed to children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We may update this policy from time to time. The "last updated" date above reflects the latest version.
Contact us
Mastascusa Holdings LLC — Philadelphia, PA, USA. Privacy questions: kevin@mastascusa.com.