Legal
Privacy Policy
This policy explains what information Rosado Management Solutions, Inc. ("we," "us," or "our") collects when you visit rosadomgmtsolutions.com or our campaign landing pages, when you request a guide or resource from us, and when you contact us or book a call — how we use it, and the choices you have.
Last updated: 31 August 2026
If you are in the European Economic Area, Switzerland or the United Kingdom, the EEA and UK residents section below applies to you in addition to everything here, and governs where the two differ.
Information we collect
We keep data collection to a minimum. We collect:
- Information you give us. When you request a guide, book a call or contact us, you may provide your name, email address, company, and anything you choose to include in a message or form.
- Information from a social message. If you ask for a guide by messaging us on Instagram or replying to one of our posts, we receive your handle, the content of that conversation, and the email address you give us in it.
- Scheduling information. Calls are booked through Calendly, which collects the details you enter to schedule and manage your appointment on our behalf.
- Email engagement. With your consent, we record whether an email we sent was opened and which links in it were clicked, so we can tell which of our material is useful.
- Campaign parameters. The campaign, source and medium values carried in the link you arrived through, so we know which of our own posts or pages sent you.
- Automatically collected data. Like most websites, our hosting providers record standard technical logs — such as IP address, browser type, and pages requested — for security and reliability.
We do notrun first-party advertising or analytics trackers, and this site sets no first-party marketing cookies. Embedded third-party tools (for example, the Calendly scheduler) may set their own cookies, governed by their policies. If we introduce analytics or marketing pixels in the future, we will disclose them here and update this policy. We conduct our practices consistent with the Federal Trade Commission Act's prohibition on unfair or deceptive practices.
How we use your information
- To respond to your inquiries and schedule and conduct calls.
- To send you the guide or resource you asked for.
- To send you follow-up emails about our work — only if you opt in, and you can unsubscribe from any of them at any time.
- To provide, maintain, and secure the website.
- To comply with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Service providers
We rely on a small set of vetted providers who process data only to provide their service to us, each under a written contract:
- Brevo (Sendinblue SAS, Paris, France) — email delivery, list management and automated sequences.
- ManyChat (Manychat, Inc., Austin, Texas, USA) — social messaging automation.
- Calendly (Calendly LLC, USA) — appointment scheduling.
- Vercel (Vercel Inc., USA) — website hosting and delivery.
- GitHub (GitHub, Inc., USA) — landing page hosting.
- Google Workspace (Google LLC, USA) — email correspondence.
We may also disclose personal information to our professional advisers, or to an authority or court where we are legally required to.
Separately: when you interact with our accounts or content on Instagram, Facebook, LinkedIn or other social platforms, the platform handles your data under its own policies and for its own purposes. We do not control that processing.
Data retention
We keep personal information only as long as we need it:
- Inquiries and calls — 24 months from our last contact with you.
- Subscriber records — until you unsubscribe or ask us to delete them.
- After you unsubscribe — your email address stays on a suppression list so that we do not contact you again, and the record of your opt-in and opt-out is kept for 3 years so we can show that our emails to you were lawful.
- Server logs — held by our hosting providers under their own retention schedules. We do not export, copy or separately retain them.
When a period ends, we delete or anonymize the information.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to opt out of certain processing or of the sale or sharing of your data, and to withdraw consent. These rights are provided under laws such as the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the Colorado Privacy Act (CPA), and the Virginia Consumer Data Protection Act (VCDPA), among others, to the extent they apply to us. To exercise any of these, email us at privacy@rosadomgmtsolutions.com and we will respond as required by applicable law and will not discriminate against you for doing so. You can unsubscribe from any marketing email using the link in that email.
If you are in the EEA, Switzerland or the UK, see the next section — you have additional rights there.
EEA and UK residents
This section applies in addition to the rest of this policy if you are in the European Economic Area, Switzerland or the United Kingdom. Where it differs from anything above, this section governs for you. It is provided under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR) and, for the United Kingdom, the UK GDPR and the Data Protection Act 2018.
Who is responsible for your data
Rosado Management Solutions, Inc. is the controller of the personal data described in this policy. The company is incorporated in Wyoming, USA, and carries out its marketing activities for European audiences through its establishment in Málaga, Spain. Because that processing is carried out in the context of the activities of an establishment in the Union, the GDPR applies under Article 3(1), and we are not required to appoint a representative under Article 27.
You can reach us about anything in this section at privacy@rosadomgmtsolutions.com, or by post at the address at the end of this policy. We have not appointed a Data Protection Officer; Article 37 does not require one for our processing.
What we collect and where it comes from
The categories are listed under “Information we collect” above. In summary: what you give us directly in a form, message or booking; your handle and the content of a social message if you request a guide that way; whether our emails were opened and which links were clicked; the campaign parameters in the link you arrived through; and technical data recorded in our hosts' server logs.
Why we process it, and on what legal basis
- Answering your enquiry and scheduling a call. Article 6(1)(b) — steps taken at your request before entering into a contract; or Article 6(1)(f), our legitimate interest in responding to people who contact us.
- Sending you the guide or resource you asked for. Article 6(1)(b) — delivering what you requested.
- Sending you follow-up marketing emails. Article 6(1)(a), your consent, which we confirm by a double opt-in before any marketing is sent. In Spain this also reflects Article 21 of Law 34/2002 (LSSI-CE), which requires prior consent for commercial communications by electronic means.
- Measuring whether our emails were opened and which links were clicked. Article 6(1)(a), your consent, given separately when you sign up. Tracking pixels and click redirects involve storage and access on your device within the meaning of Article 5(3) of the ePrivacy Directive and Article 22.2 LSSI-CE.
- Keeping the site available and secure, and preventing abuse. Article 6(1)(f), our legitimate interest in the integrity of our own infrastructure. We have balanced that interest against your rights and use the minimum data our hosts record by default.
- Keeping records we are required to keep, and handling legal claims. Article 6(1)(c) and Article 6(1)(f).
Where we rely on consent, you can withdraw it at any time under Article 7(3) — by using the unsubscribe link in any email or by writing to us. Withdrawal does not affect the lawfulness of what we did before you withdrew. Where we rely on legitimate interests, you can object under Article 21; if you object to direct marketing we will stop, without exception and without asking why.
Providing your data is not a statutory or contractual requirement. You are not obliged to give it to us — but if you do not, we cannot send you the guide, answer your enquiry, or book your call.
How long we keep it
The periods under “Data retention” above apply.
Who receives your data
The providers listed under “Service providers” above act as our processors, each under a written contract meeting Article 28. Where a social platform provides us with aggregated audience statistics, that processing may be a joint controllership between the platform and us; we are reviewing those arrangements and will describe them here.
International transfers
Brevo processes our email data within the European Union. Our other processors are established in the United States, so using them involves a transfer of personal data outside the EEA and the UK. Those transfers are made under Article 46(2)(c) on the basis of the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, controller-to-processor module), supplemented for UK data by the ICO's International Data Transfer Addendum, and — where the recipient is certified — under the EU-U.S. Data Privacy Framework adequacy decision. We assess each transfer and apply additional measures where our assessment calls for them.
You can ask us for a copy of the safeguards we rely on for any specific transfer by writing to the address below.
Your rights
Under the GDPR and UK GDPR you have the right to:
- access your personal data and receive a copy of it (Article 15);
- have inaccurate data corrected and incomplete data completed (Article 16);
- have your data erased (Article 17);
- restrict our processing in the circumstances set out in Article 18;
- receive the data you gave us in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20);
- object to processing based on legitimate interests, and to object to direct marketing at any time (Article 21);
- withdraw your consent at any time (Article 7(3)).
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you, within the meaning of Article 22.
To exercise any of these, email privacy@rosadomgmtsolutions.com. We will respond within one month of receiving your request, and will tell you if we need to extend that period as Article 12(3) permits. Exercising your rights is free of charge.
Complaints
If you think we have handled your personal data incorrectly, we would like the chance to put it right — but you can complain to a supervisory authority at any time, and you do not have to contact us first.
In Spain, the authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es, with complaints filed through its electronic office at sedeaepd.gob.es. If you are elsewhere in the EEA you may complain to the authority in your country of residence or workplace. In the United Kingdom, the authority is the Information Commissioner's Office, ico.org.uk.
Personal data breaches
If a breach of security leads to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of your personal data, we will notify the AEPD within 72 hours where Article 33 requires it, and will tell you directly where Article 34 requires it.
Data security
We use reasonable administrative and technical safeguards to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. In the event of a data breach affecting personal information, we will notify affected individuals and authorities as required by applicable law — including Wyoming's data breach notification statute where relevant, and Articles 33 and 34 GDPR for individuals in the EEA and the UK.
Children's privacy
This site is intended for businesses and professionals and is not directed to children under 16. We do not knowingly collect information from children. In Spain, a person must be at least 14 years old to consent to the processing of their own personal data (Article 7 of Organic Law 3/2018); elsewhere in the EEA the age is between 13 and 16 under Article 8 GDPR. We do not knowingly collect data from anyone below the applicable age, and will delete it if we learn that we have.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact us
Questions about this policy or your data? Email privacy@rosadomgmtsolutions.com, or write to us:
Rosado Management Solutions, Inc.
30 N Gould St, Suite R
Sheridan, WY 82801