• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

Privacy Statement (US)

You are here: Home / Privacy Statement (US)

This privacy statement was last changed on July 13, 2024, last checked on July 13, 2024, and applies to citizens and legal permanent residents of the United States.

In this privacy statement, we explain what we do with the data we obtain about you via https://www.controlcase.com. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions, or want to know exactly what data we keep of you, please contact us.

1. Purpose and categories of data

We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)

1.1 To sell or share data with a third party

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Geolocation data
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.2 Contact - Through phone, mail, email and/or webforms

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Geolocation data
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.3 Registering an account

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
  • Geolocation data

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.4 Newsletters

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
  • Geolocation data

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.5 To support services or products that a customer wants to buy or has purchased

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
  • Geolocation data

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.6 Compiling and analyzing statistics for website improvement.

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
  • Geolocation data

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

1.7 To be able to offer personalized products and services

The following categories of data are collected

  • A first and last name
  • Account name or alias
  • A home or other physical address, including street name and name of a city or town
  • An email address
  • A telephone number
  • IP Address
  • Internet activity information, including, but not limited to, browsing history, search history, and information regarding a consumer's interaction with an Internet Web site, application, or advertisement
  • Geolocation data

Retention period

We determine the retention period according to fixed objective criteria: As per the data retention requirements specific to each country.

2. Disclosure practices

We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.

If our website or organisation is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.

3. How we respond to Do Not Track signals & Global Privacy Control

Our website responds to and supports the Do Not Track (DNT) header request field. If you turn DNT on in your browser, those preferences are communicated to us in the HTTP request header, and we will not track your browsing behavior.

4. Cookies

Our website uses cookies. For more information about cookies, please refer to our Cookie Policy on our Privacy Statement (US) webpage. 

We have concluded a data processing agreement with Google.

5. Security

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorized access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

6. Third-party websites

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

7. Amendments to this privacy statement

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

8. Accessing and modifying your data

If you have any questions or want to know which personal data we have about you, please contact us. Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person. We shall provide the requested information only upon receipt of a verifiable consumer request. You can contact us by using the information below. You have the following rights:

8.1 You have the following rights with respect to your personal data

  1. You may submit a request for access to the data we process about you.
  2. You may object to the processing.
  3. You may request an overview, in a commonly used format, of the data we process about you.
  4. You may request correction or deletion of the data if it is incorrect or not or no longer relevant, or to ask to restrict the processing of the data.

8.2 Supplements

This section, which supplements the rest of this Privacy Statement, applies to citizens and legal permanent residents of California (CPRA), Colorado (CPA), Nevada (NRS 603A), Utah (UCPA), Virginia (CDPA) and Connecticut (CTDPA)

California

Right to know what personal information is being collected about you

A consumer shall have the right to request that a business that collects personal information about the consumer disclose to the consumer the following:

  1. The categories of personal information it has collected about that consumer.
  2. The categories of sources from which the personal information is collected.
  3. The business or commercial purpose for collecting or selling personal information.
  4. The categories of third parties with whom the business shares personal information.
  5. The specific pieces of personal information it has collected about that consumer.

The right to know whether personal information is sold or disclosed and to whom

A consumer shall have the right to request that a business that sells the consumer’s personal information, or that discloses it for a business purpose, disclose to that consumer:

  1. The categories of personal information that the business collected about the consumer.
  2. The categories of personal information that the business sold about the consumer and the categories of third parties to whom the personal information was sold, by category or categories of personal information for each third party to whom the personal information was sold.
  3. The categories of personal information that the business disclosed about the consumer for a business purpose.

The Right to equal service and price, even if you exercise your privacy rights


A consumer shall have the right to request that a business delete any personal information about the consumer which the business has collected from the consumer.


A business that receives a verifiable request from a consumer to delete the consumer’s personal information pursuant to subdivision (a) of this section shall delete the consumer’s personal information from its records and direct any service providers to delete the consumer’s personal information from their records.


A business or a service provider shall not be required to comply with a consumer’s request to delete the consumer’s personal information if it is necessary for the business or service provider to maintain the consumer’s personal information in order to:

  1. Complete the transaction for which the personal information was collected, provide a good or service requested by the consumer, or reasonably anticipated within the context of a business’s ongoing business relationship with the consumer, or otherwise perform a contract between the business and the consumer.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
  3. Debug to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses’ deletion of the information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
  7. Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  8. To enable solely internal uses that are reasonably aligned with the expectations of the consumer based on the consumer’s relationship with the business.
  9. Comply with a legal obligation.
  10. Otherwise use the consumer’s personal information, internally, in a lawful manner that is compatible with the context in which the consumer provided the information.

Right to opt-out

You may submit a request directing us not to make certain disclosures of personal information we maintain about you. For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

Financial incentives

Selling of personal data to third parties

We have not sold consumers’ personal data in the preceding 12 months

    We have not disclosed consumers’ personal information for a business purpose in the preceding 12 months.

      Colorado

      Right to Data Portability

      When exercising the right to Access personal data , you have the right to obtain the personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance. You may exercise this right no more than two times per calendar year.

      Right to opt-out

      You may submit a request directing us not to make certain disclosures of personal information we maintain about you.

      Under Colorado law this concerns the following purposes:

      1. targeted advertising;
      2. the sale of personal data; or
      3. profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.

      For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

      Connecticut

      Right to Data Portability

      When exercising the right to Access personal data , you have the right to obtain the personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.

      We are not required to reveal any trade secret.

      Right to opt-out

      You may submit a request directing us not to make certain disclosures of personal information we maintain about you.

      Under the CTDPA this concerns the following purposes:

      1. targeted advertising; or
      2. the sale of personal data; or
      3. profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.

      For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

      Nevada

      Right to opt-out

      You may submit a request directing us not to make certain disclosures of personal information we maintain about you.

      For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

      Utah

      Right to Data Portability

      When exercising the right to Access personal data, you have the right to obtain the personal data that you previously provided to us as a controller in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.

      Right to opt-out

      You may submit a request directing us not to make certain disclosures of personal information we maintain about you.

      Under the UCPA this concerns the following purposes:

      1. targeted advertising; or
      2. the sale of personal data.

      For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

      Virginia

      Right to Data Portability

      When exercising the right to Access personal data , you have the right to obtain the personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance. You may exercise this right no more than two times per calendar year.

      Right to opt-out

      You may submit a request directing us not to make certain disclosures of personal information we maintain about you.

      Under the CDPA this concerns the following purposes:

      1. targeted advertising;
      2. the sale of personal data; or
      3. profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer.

      For more information about the possibility of submitting an opt-out request, please refer to our Opt-out preferences page.

      9. Children

      Our website is not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us.

      10. Contact details

      ControlCase
      Fifty West Corporate Center
      3975 Fair Ridge Drive, Suite D T25s, Fairfax, VA 22033
      United States
      Website: https://www.controlcase.com
      Email: privacy@controlcase.com
      Toll free phone number: +1-703-483-6383
      Phone number: +1-703-483-6383

      11. Data Requests

      For the most frequently submitted requests, we also offer you the possibility to use our data request form

      ×

      • Facebook
      • LinkedIn
      • Twitter
      • YouTube

      Footer

      Connect

      Corporate Headquarters
      3975 FAIR RIDGE DR STE T25S-D
      FAIRFAX, VA 22033

      Send us a message

      Call Us

      Search

      About Us

      ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

      Quick Links

      • Company
      • Careers
      • Locations
      • Covid-19 Notice

      Certifications, Assessments and Reports

      • PCI DSS Certification
      • CSA STAR Certification
      • GDPR Assessment
      • HIPAA Assessment
      • HITRUST Certification
      • ISO 27001 Certification
      • FedRAMP and 3PAO Services
      • MARS-E Assessment
      • PCI SSF
      • P2PE Certification
      • SOC2 Report

      © ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

      • English
      Manage Consent
      To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
      Functional Always active
      The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
      Preferences
      The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
      Statistics
      The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
      Marketing
      The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
      Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
      View preferences
      {title} {title} {title}
      Manage Consent
      To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
      Functional Always active
      The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
      Preferences
      The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
      Statistics
      The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
      Marketing
      The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
      Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
      View preferences
      {title} {title} {title}