Skip to main content
Blue Ridge FederalBuilt for government contractors
Business line: (917) 412-1478sales@blue-ridge-federal.com
  • Solutions & Capabilities
  • Pricing
  • Demo
  • Security
  • Company
  • Client sign in
System Notice: Assessment databases are actively synced with current NDAA, FCC, and Consolidated Screening List rulings.
Home / Privacy Policy

Blue Ridge Federal LLC

Privacy Policy

Effective October 8, 2026 · Version 2026-10-08

This policy explains how Blue Ridge Federal LLC handles personal information, customer files, optional processing, retention, and privacy requests. Acknowledging this notice does not give blanket consent to optional processing or waive your privacy rights.

Terms of ServiceSecurity & TrustCurrent Privacy Policy
Contents · 25 sections
  1. Who We Are and How to Contact Us
  2. Scope, Customer Data, and Our Different Roles
  3. Information You Provide Directly
  4. Accounts, Authentication, and Acceptance Records
  5. Payments, Subscriptions, and Usage
  6. Technical Information and Sources
  7. Cookies, Browser Storage, and External Fonts
  8. How and Why We Use Information
  9. Lawful Bases Where Required
  10. Customer Files, Confidentiality, and Government Data
  11. Supplier Catalogs and Government Sources
  12. Optional AI and Document Processing
  13. Service Providers and Other Recipients
  14. Organization Administration and Support Access
  15. Legal Disclosures and Business Transfers
  16. Retention of Files, Monitoring, and Archives
  17. Retention of Accounts and Other Business Records
  18. Security and Incident Handling
  19. International Processing and Transfer Requirements
  20. Your Choices and Communications
  21. Access, Correction, Deletion, and Other Privacy Rights
  22. Regional Rights, Appeals, and Complaints
  23. Children and Age Restrictions
  24. Third-Party Sites and Integrations
  25. Changes to This Policy and the Meaning of Acknowledgment

1. Who We Are and How to Contact Us

1.1 Responsible business

Blue Ridge Federal LLC ("BRF," "we," "us," or "our") provides software development, data intake, document workflows, supplier and compliance screening, and related business and government contracting services. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through blue-ridge-federal.com, our client portal, APIs, demonstrations, and associated communications (the "Services"). Personal information means information that identifies, relates to, or can reasonably be linked to a person, including business contact information where applicable law protects it.

1.2 Privacy contact

Blue Ridge Federal LLC 2504 Ditmars Blvd Astoria, NY 11105-3121, United States Email: jbenson@blue-ridge-federal.com Telephone: +1 917 412 1478 For privacy requests, use the subject "Privacy request" and identify the relevant account or interaction without attaching confidential files, passwords, or government-controlled information.

2. Scope, Customer Data, and Our Different Roles

2.1 Our own business records

We generally determine the purposes and means of processing website, inquiry, account administration, service security, billing, and business relationship information. Where applicable law uses these terms, we act as a controller or business for that processing. This policy applies to personal information in these records even when you are also a customer.

2.2 Processing for customers

A customer may upload documents, parts lists, instructions, notes, or other content containing personal information ("Customer Content"). For processing performed on that customer's instructions, the customer generally acts as controller or business and BRF acts as processor or service provider, as applicable. The relevant order, confidentiality terms, data-processing agreement, and lawful documented instructions govern that processing. A data-processing agreement controls a conflict about processing on the customer's behalf; mandatory law always controls. This policy does not grant us independent permission to repurpose Customer Content.

2.3 Other environments

For separately contracted enterprise, customer-hosted, or on-premises deployments, the agreement identifies what information BRF receives and which party operates the system. The customer's own privacy notices also apply to its collection and use. This public policy does not establish a government data authorization, a processing agreement, or a promise that a particular vendor or deployment is suitable for restricted data.

3. Information You Provide Directly

3.1 Inquiries and business communications

We collect the information you choose to send, such as your name, organization, role, work email, telephone number, correspondence, requested services, and scheduling or support details. Initial inquiries must use public or synthetic examples. General contact forms and email are not channels for controlled government information or confidential attachments.

3.2 Briefing and enterprise questionnaires

After you create an account, a briefing or enterprise request may include your organization, expected volumes, destination systems, intended use, integration requirements, and other answers. We associate the request with your account and workspace so that authorized BRF personnel can review it and respond. A request does not itself establish a contract or activate paid access.

3.3 Customer Content and review activity

When you submit an authorized file or request processing, we receive the file, its name and format, submitted rows or queries, manufacturer and supplier identifiers, instructions, selected data packs, and associated context. We also process generated results, source references, reviewer decisions, and notes you enter. These materials can contain personal or confidential information depending on what you submit; avoid including information the task does not need.

4. Accounts, Authentication, and Acceptance Records

4.1 Account information

We process your name, email, account identifier, organization affiliation, membership and permissions, authentication status, and account changes. Our sign-in system uses WorkOS AuthKit. Sign-in, email verification, password reset, and optional authenticator enrollment involve WorkOS processing the credentials, verification factors, and security information needed for those functions. BRF does not retain plaintext passwords in its application records or include them in routine logs. Do not share individual sign-ins or verification codes.

4.2 Agreement evidence

When you select "Agree and create account," the signup request indicates agreement to the Terms of Service and acknowledgment of this Privacy Policy. We record the document versions, a server-generated time, and the identified acceptance action with the new account in WorkOS account metadata. The record is linked to the account identifier and its email. We use it to administer the relationship, demonstrate the notice and agreement presented, and resolve legal or support questions. This record does not represent consent to marketing, optional AI processing, optional catalogs, or an extended file-retention period.

4.3 API and security records

We maintain API key identifiers and hashes, permissions, issuance and revocation information, login or authentication events, and relevant security activity. Application access keys are stored in hashed form; a key cannot be retrieved after issuance. Authentication and infrastructure providers may maintain additional security records under their own applicable terms and notices.

5. Payments, Subscriptions, and Usage

5.1 Payment processing

Stripe processes payments. Payment details entered into Stripe's secure fields go directly to Stripe; BRF does not receive or store full payment card numbers or card security codes. We receive or retain customer and payment references, billing contact information, invoice and transaction amounts, payment status, subscription periods, selected plans, cancellation events, and other records needed to administer purchases. Stripe and an optional wallet you choose also process information for their own payment, fraud prevention, and legal purposes under their respective notices.

5.2 Usage measurement

We record job and document references, attempted and processed row counts, allowance reservations and releases, selected packs, processing outcomes, timestamps, and related usage events. These support delivery, capacity planning, invoices, disputes, and the purchased allowance. Enabling a paid service or overage remains subject to the purchase and authorization steps shown in the interface.

5.3 Metered billing

When metered overage is explicitly enabled and activated, Metronome receives billing identifiers, aggregate attempted-SKU counts, billing periods, and agreed rates to calculate charges. This usage pipeline does not send Metronome your BOM files, result contents, or reviewer notes. Billing records are retained separately from the underlying processing files.

6. Technical Information and Sources

6.1 Information collected automatically

Our hosting, delivery, authentication, and security systems process request information such as IP address, browser and device characteristics, operating system, requested page or endpoint, referrer when supplied, timestamps, response status, and security signals. These systems need some of this information to deliver pages, maintain sessions, troubleshoot failures, and distinguish legitimate activity from abuse. Provider logs may contain a full network address even where an application feature stores only a digest.

6.2 Other sources

We receive information from your organization or its administrators, authentication and payment providers, service integrations you authorize, and publicly available business or government sources relevant to a requested workflow. Supplier catalogs and government lists provide evidence for screening results. Public-source information can still be personal information, and its public availability does not remove applicable legal protections.

6.3 Abuse prevention

Certain application submissions use a one-way digest of the submitting network address to limit abuse. Such a digest is a security identifier, not a guarantee of anonymity. We do not intentionally solicit personal information from data brokers for advertising or build consumer advertising profiles.

7. Cookies, Browser Storage, and External Fonts

7.1 Essential technologies

We use cookies and similar storage needed for authentication, pending verification steps, session security, request protection, and necessary interface state. Some cookies are restricted to encrypted connections and inaccessible to ordinary page scripts. Hosting and security providers may use additional essential technologies to operate and protect the Services. Blocking essential cookies or storage can prevent sign-in, uploads, or payment functions.

7.2 Browser drafts

The intake workflow can save an encrypted draft in your browser's IndexedDB with a key tied to the current tab's session storage. The draft includes the fields and selected file needed to continue your submission. It expires after 24 hours and is removed when the application next checks expired drafts; expiry does not remotely erase an offline browser. Saving that draft does not send it to our processing service. Submitting it or using an expressly identified online processing tool transmits the information needed for that action. Clearing site storage removes local drafts and can make them unrecoverable.

7.3 Fonts and checkout

This website loads fonts from Google Fonts. Google receives connection information, including your IP address and browser request details, when those resources load. Opening Stripe checkout or choosing a wallet can also involve that provider's cookies and fraud prevention signals. These providers operate under their own notices for their independent activities.

7.4 Advertising and browser signals

We do not use advertising cookies or cross-site advertising trackers, and we do not sell personal information or share it for cross-context behavioral advertising. The Services do not change their essential processing in response to a Do Not Track signal. Because we do not conduct sale or advertising sharing, there is no such activity to opt out of through a Global Privacy Control signal. We will honor applicable legally required opt-outs if our practices change, with the required notice and controls before that change.

8. How and Why We Use Information

8.1 Providing requested services

We use information to respond to inquiries, assess requirements, create and secure accounts, provision organization access, process authorized files and queries, generate and deliver results, support review workflows, and administer the features and integrations you request. Providing account and billing details is necessary for the corresponding operational service; declining to provide them may prevent us from creating an account, taking payment, or fulfilling a request. Browsing public pages does not require purchasing a service.

8.2 Administration and protection

We use information to measure usage, administer subscriptions and invoices, respond to support and privacy requests, keep agreement records, detect misuse, investigate incidents, enforce valid agreements, and meet legal, tax, accounting, and contractual obligations. We may preserve relevant evidence for a dispute or required investigation.

8.3 Improvement and limited analysis

We use operational performance information, error patterns, aggregate counts, and feedback to maintain and improve the Services. We do not treat removal of names alone as sufficient de-identification where a record remains identifiable or discloses a customer's confidential information. BRF does not use Customer Content, or authorize providers to use it, to train general-purpose AI models. Improving the service does not authorize unrestricted reuse of customer files.

9. Lawful Bases Where Required

9.1 Contract and requested steps

Where the GDPR, UK GDPR, or a similar law requires a lawful basis, we rely on performance of a contract with the individual, or requested steps before that contract, for processing objectively necessary for that relationship. For organization accounts where the individual is not the contracting party, appropriate business administration may instead rely on legitimate interests, subject to the required balancing and rights.

9.2 Legitimate interests and legal duties

Our legitimate interests include responding to business inquiries, administering organization relationships, securing the Services, preventing fraud, maintaining proportionate business records, and establishing or defending legal claims. We consider the impact on individuals and apply relevant safeguards. We rely on compliance with legal obligations where processing is required by applicable law.

9.3 Consent and customer instructions

Where consent is legally required, we seek specific, informed consent for the relevant purpose and permit withdrawal. Withdrawal does not affect earlier lawful processing or another applicable legal basis. A customer instructing us as processor is responsible for its own lawful basis, transparency, and required permissions. Clicking the signup button acknowledges the policy and accepts the Terms; it is not a blanket consent to every use of information or a waiver of privacy rights.

10. Customer Files, Confidentiality, and Government Data

10.1 Authorized commercial information

Use the authorized portal or API for commercial files you are entitled to submit. The processing license is limited to providing the agreed Services and meeting applicable obligations. Confidentiality duties in an applicable agreement remain in effect; public website browsing or an initial inquiry does not itself create an NDA. Provide only the personal information necessary for the task and use effective redaction where appropriate.

10.2 Prohibited submissions

Do not transmit classified information, Controlled Unclassified Information (CUI), covered defense information, export-controlled technical data, passwords, private keys, or unnecessary sensitive personal information through public forms, general email, demonstrations, or the ordinary commercial cloud service. Initial examples should be public, synthetic, or effectively redacted. A separate NDA, account, payment, GovCloud location, or on-premises installation does not by itself authorize restricted processing.

10.3 Separate authorization

Restricted government or regulated work requires a separately executed agreement identifying the permitted data, applicable controls, approved users and locations, providers, and security authorization before processing. This policy does not claim any particular CMMC assessment, SPRS affirmation, certification, or regulatory approval. If prohibited data is submitted, contact us promptly without retransmitting it. We may restrict access and coordinate lawful containment, preservation, reporting, or deletion; mandatory obligations still apply.

11. Supplier Catalogs and Government Sources

11.1 Query disclosures

A requested supplier lookup may send manufacturer part numbers and supplier codes to approved catalogs, such as Mouser and Digi-Key, to retrieve evidence. The supplier-query path does not transmit the original source file or internal item numbers. Optional catalog paths, including LCSC where offered, require the organization owner's authorization. Review the relevant data controls before enabling a source.

11.2 Provider and source responsibilities

Catalog operators may retain request and technical information under their own terms. Government portals, published lists, and linked websites have their own privacy practices. A screening result is an evidence-based aid for human review; it does not transfer responsibility for a procurement or regulatory decision to the source or establish government endorsement. Do not place confidential or controlled information in a query identifier.

12. Optional AI and Document Processing

12.1 Separate authorization

AI assistance is disabled by default and requires the relevant organization owner's or administrator's explicit authorization for the enabled workflow. Account creation and acceptance of the Terms or this policy do not turn it on. Where offered, you can change organization data controls or contact us about disabling assistance. Disabling it stops future authorized calls; it does not recall a request already sent or automatically erase lawful provider security records.

12.2 Information transmitted

Approved OpenAI or Anthropic APIs may process the information needed for a selected AI task. Supplier-evidence assistance uses limited part identifiers, evidence, and opaque row labels, excluding organization names, internal item identifiers, and job notes from that path. Optional intake mapping may transmit column headers and up to 30 sample rows. Optional document reading transmits the document you choose. Selected documents and sample rows may contain personal or confidential information; inspect and minimize them before authorizing the tool. These flows differ from isolated supplier catalog queries.

12.3 Training, location, and provider retention

BRF does not use Customer Content, or authorize its providers to use it, to train general-purpose models. Approved API processing remains subject to provider contractual and security terms. Turning response storage off, as BRF does for OpenAI requests, does not necessarily eliminate abuse-monitoring logs or other provider retention. Do not assume zero retention or a particular inference location. Where location, retention, or regulated handling is material, obtain current, verified provider and deployment details and the required written terms before processing.

12.4 Human review

AI output may be incomplete or incorrect. Users must review sourced findings before relying on them. BRF does not use these tools to make solely automated decisions with legal or similarly significant effects about individuals, such as hiring, credit eligibility, or access to essential services. The Services are not offered for those uses without a separate lawful arrangement.

13. Service Providers and Other Recipients

13.1 Operational providers

We disclose information reasonably necessary to vendors that deliver hosting, storage, security, authentication, payment processing, usage billing, and communications. These include Cloudflare for site infrastructure, WorkOS for authentication and account records, Stripe for payments, Metronome for activated metered billing, and Resend when service email delivery is configured. Approved catalogs and optional model providers receive the limited information described above. A feature or provider may be unavailable until configured and authorized.

13.2 Limits and independent activities

We require appropriate contractual restrictions for providers processing information on our behalf. Some providers, especially payment networks, catalog operators, and linked services, also act independently for their own legal, security, or service purposes. Their notices govern those independent activities. We do not promise that all providers use identical retention periods or process in the same location.

13.3 Advisers and authorized recipients

We may provide relevant information to professional advisers, auditors, insurers, or contractors subject to appropriate duties of confidentiality and need-to-know limits. We also disclose information when you or an authorized customer administrator directs an integration, invites a user, requests delivery to a recipient, or otherwise authorizes disclosure. Enabling a provider is limited to the identified workflow and does not authorize unrelated uses.

14. Organization Administration and Support Access

14.1 Organization visibility

Authorized owners, administrators, and members can access the workspace information their permissions allow, such as submissions, results, usage, organization settings, and audit activity. Your employer or contracting organization may manage your account affiliation and have separate policies for its information. Do not treat a company workspace as a personal storage service.

14.2 BRF access

BRF personnel can review account, billing, request, and operational metadata needed to administer the service. Routine support access to protected client artifacts requires an explicit, revocable, time-limited organization grant through supported controls, generally 24 hours, three days, or seven days. The processing service accesses content as necessary to perform the authorized job. Support grants, processing activity, and relevant administrative actions are logged. These access controls do not prevent lawful incident containment, compulsory disclosure, or other handling required by an applicable agreement or law.

14.3 Revocation and authority

An authorized owner can end a support grant and disable optional processing through available controls. Ending a grant prevents future support access under that grant; it does not reverse completed processing or erase required audit records. We may verify authority before changing ownership, releasing content, or acting on a conflicting instruction.

15. Legal Disclosures and Business Transfers

15.1 Required or protective disclosure

We may disclose information to comply with applicable law, lawful government requests, subpoenas, court orders, mandatory incident reporting, or other binding legal process; investigate fraud or abuse; or protect rights, safety, and system security. We assess requests and limit disclosure as appropriate. Where legally permitted and appropriate, we notify the affected customer of a compulsory request so it can seek protection. No provision promises advance notice when law prohibits it or urgent circumstances prevent it.

15.2 Business transactions

Information may be reviewed or transferred in a merger, financing, acquisition, restructuring, insolvency, or sale of relevant business assets, subject to appropriate confidentiality and legal restrictions. A successor must honor applicable privacy and contractual obligations for transferred information. A transaction does not authorize a prohibited government-data transfer or remove required notices or consents.

15.3 No advertising sale

BRF does not sell personal information, rent customer contact lists, share personal information for cross-context behavioral advertising, or disclose customer files to advertisers. Service-provider disclosures for requested operations remain subject to the purposes and limits described in this policy.

16. Retention of Files, Monitoring, and Archives

16.1 Standard processing files

Unless a separately authorized extension or agreement applies, standard processing inputs and result files are scheduled for deletion 30 days after the job finishes. Supported customer deletion or a verified request can remove them earlier, subject to necessary legal preservation. Canceling before processing removes source files under the applicable workflow. Buying a one-time report does not by itself extend retention. Download records you need before their availability ends.

16.2 Monitoring retention

When Watch or another monitoring feature is offered, each watched BOM revision requires explicit owner acceptance of the retention extension, logged with the policy version and document revision. The ordinary monitoring deadline is 30 days after the earliest applicable event: stopping that BOM's enrollment, the subscription ending, or its paid coverage expiring. A separately purchased archive can authorize a later deadline. Retaining a revision does not itself confer active monitoring or processing rights.

16.3 Purchased archives

An optional paid encrypted archive retains eligible files from purchased periods for the selected one-, three-, or seven-year term after completion, as specified in the order. Canceling a subscription does not by itself end an already purchased archive term. Authorized earlier deletion may end availability sooner, subject to required preservation. An archive does not include files outside its purchased scope or replace the customer's own recordkeeping.

16.4 Separate audit records

Deleting a source file does not automatically delete job metadata, file fingerprints, access logs, usage events, reviewer decisions, or encrypted review notes. These serve separate audit, support, security, and legal purposes. Counts and hashes differ from file contents, but file names and reviewer notes may themselves contain personal or confidential information. Do not assume that every audit record is content-free.

17. Retention of Accounts and Other Business Records

17.1 Retention criteria

We retain account records while needed to provide and secure the account. Inquiry and support correspondence is retained as needed to respond, administer a continuing relationship, and resolve related issues. Billing, transaction, tax, agreement acceptance, and dispute records may remain after an account closes for applicable legal requirements, contractual limitation periods, audit needs, fraud prevention, or an unresolved claim. We consider the record's purpose, sensitivity, age, legal requirements, and whether a less identifying record will suffice. These categories do not share the 30-day processing-file deadline.

17.2 Deletion and preservation

You may request account closure or deletion using the contact details below. We verify identity and authority and identify information we must retain, rather than promising immediate erasure of all records. Legal holds, incident preservation, and mandatory contractual or regulatory recordkeeping can postpone routine deletion; preserved information is restricted to the relevant purpose. When information is no longer needed, we delete it or de-identify it appropriately.

17.3 Residual copies and providers

Where protected backups or recovery copies exist, deletion from active systems may precede removal through their normal retention cycle. Residual copies are protected and are not used to restore ordinary access to deleted content. Independent providers may retain records under their own lawful duties and notices. We cannot recover files once deletion is complete. Request specific retention details before using a workflow with a mandatory recordkeeping requirement.

18. Security and Incident Handling

18.1 Safeguards

We apply administrative and technical safeguards appropriate to authorized information and the agreed service. These include encrypted connections, tenant-isolated encryption of stored client artifacts under the applicable workflow, restricted permissions, hashed application API keys, and append-only access auditing available through supported controls. Our Security & Trust page explains the deployed controls and scope. Security measures reduce risk; no method of transmission or storage provides absolute protection.

18.2 Your responsibilities

Use a unique password, protect verification factors and devices, review memberships and data controls, revoke credentials you no longer need, and use the authorized channels. Optional authenticator protection can help secure your account. Do not include unnecessary sensitive information in file names, notes, support requests, or email.

18.3 Incident response

Report suspected compromise promptly to jbenson@blue-ridge-federal.com. We investigate, contain, preserve relevant evidence, and provide notices required by applicable law and agreements. Our published response plan includes notification within 72 hours of confirming that a client's data was affected; an earlier or differently triggered mandatory deadline controls where applicable. This operational commitment does not delay a legal duty measured from discovery or create authorization to process restricted data. Notices will use appropriate channels and avoid unnecessary disclosure of affected information.

19. International Processing and Transfer Requirements

19.1 Locations

BRF is based in the United States. Information may be processed in the United States and other locations where authorized providers operate, depending on the feature, provider account configuration, and applicable agreement. A website visit, payment, catalog request, and optional AI call can involve different recipients and locations. A U.S. company address or cloud region label does not by itself establish U.S.-only access, inference, or retention.

19.2 Required safeguards

Where applicable law requires a transfer mechanism, the necessary contractual safeguards and supplementary measures must be established before the covered customer-directed transfer. Ask us for the relevant provider, location, and processing terms before submitting information subject to these restrictions. We will not treat acceptance of the Terms or acknowledgment of this policy as a substitute for a required data-processing agreement, transfer mechanism, or export authorization.

19.3 Your information and requests

Where a legally required transfer safeguard applies, you may request information about it and an available copy, subject to lawful redactions protecting security and others' rights. If a requested deployment or transfer cannot meet the applicable requirements, it must not be used for that restricted information.

20. Your Choices and Communications

20.1 Account and service controls

You can update available account details, manage authorized users and keys, change supported data controls, end support grants, and delete eligible content through the portal. Contact us for corrections or actions that are unavailable there. Your organization's authority and legal duties may limit an individual's ability to delete shared business records.

20.2 Service messages and marketing

We send verification, reset, security, billing, delivery, and other operational messages needed for the account or requested relationship. Those messages are separate from promotional email. If we send promotional communications, you can opt out using an available unsubscribe control or by contacting us. Account creation does not enroll you in optional marketing or waive any consent requirement. We may retain a minimal suppression record to honor an opt-out.

20.3 Optional permissions

AI assistance, additional catalogs, monitoring retention, and metered overage have their own authorization controls. You may decline them while using the features that remain available under your order. Withdrawing an optional authorization can prevent the corresponding future feature from operating, but does not by itself cancel a paid subscription, erase records, or undo a completed transaction. Use the specific cancellation and deletion controls for those actions.

21. Access, Correction, Deletion, and Other Privacy Rights

21.1 Available requests

You may contact us to ask what personal information we hold about you, obtain an appropriate copy, correct inaccuracies, request deletion, or raise a privacy concern. Depending on applicable law, you may also have rights to restrict processing, object to particular processing (including direct marketing), receive portable information, withdraw consent, opt out of specified uses, or challenge certain automated decisions. Rights depend on the applicable law and BRF's role; this policy does not limit a mandatory right.

21.2 How to request

Email jbenson@blue-ridge-federal.com or write to the address in Section 1. Describe the request, the account or interaction, and your connection to the information. Please do not send passwords, complete payment details, government ID copies, or controlled data in an initial request. We verify identity and, where relevant, an agent's authority using information proportionate to the request. We may ask for clarification, but will not request more information than reasonably needed for verification.

21.3 Handling requests

We respond within the period required by applicable law and explain any lawful extension or refusal. Restrictions can apply to protecting another person, security, privileged material, mandatory records, ongoing legal claims, or duties owed to a customer. We do not charge for requests unless permitted by applicable law and explained in advance. We will not discriminate against you for exercising applicable privacy rights.

21.4 Customer-controlled content

If your request concerns information an organization controls and BRF processes on its behalf, direct it to that organization. We will help identify the appropriate customer where reasonably possible and assist it under the applicable agreement and law. We do not release another customer's files or override lawful instructions merely because a request includes a person's name.

22. Regional Rights, Appeals, and Complaints

22.1 United States state laws

Where a state privacy law applies to you, the information, and BRF, you may have additional rights to know categories and specific pieces of information, correct or delete information, obtain a portable copy, or opt out of sale, targeted advertising, sharing, or certain profiling. BRF does not sell personal information or share it for cross-context behavioral advertising, and does not use sensitive personal information to infer personal characteristics for advertising. We use submitted sensitive information only for authorized necessary operations and legally permitted purposes. The categories, sources, purposes, recipients, and retention criteria in this policy describe our current practices; the applicable legal definitions and exceptions control.

22.2 California requests and authorized agents

California residents may use the contact methods above for applicable requests and may use an authorized agent where the law permits. We may require appropriate proof of authorization and identity verification. California laws have different scopes and eligibility requirements; we do not assume that every law applies to every interaction. We do not disclose personal information to third parties for their own direct marketing. Contact us about any applicable California marketing-disclosure request.

22.3 EEA, United Kingdom, and similar protections

Where the GDPR, UK GDPR, or similar rules apply, the rights described in Section 21 include applicable access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. You may complain to your competent data protection authority, including the authority in your habitual residence, place of work, or place of an alleged infringement. UK individuals may contact the Information Commissioner's Office. You do not have to contact BRF first to exercise a right to complain to a regulator.

22.4 Appeals

If we deny a request, you can reply to our decision or email the privacy contact with the subject "Privacy appeal." Explain the decision you contest and any relevant facts. We review and respond as required by applicable law and provide information about an available regulator complaint process where required. This process does not replace or shorten a mandatory right or deadline.

23. Children and Age Restrictions

23.1 Intended audience

The operational Services are intended for business and government users who are at least 18 and legally able to enter the agreement, subject to a lawful organizational arrangement expressly approved in writing. We do not direct the Services to children or knowingly seek personal information from children under 13 or another protected age under applicable law.

23.2 Unintended collection

If you believe a child has supplied personal information without an appropriate lawful basis, contact us. We will assess the report, restrict further use where appropriate, and delete information as required by law. Do not include the child's sensitive information in the initial report.

24. Third-Party Sites and Integrations

24.1 Separate notices

Links to government resources, supplier catalogs, payment services, professional networks, or other websites lead to services operated by others. Their own terms and privacy notices govern information they collect independently. Choosing to link an account or send information to a recipient can disclose information outside BRF's control. Review those permissions and notices before proceeding.

24.2 No blanket authorization

An integration does not authorize onward disclosure of information outside its stated scope, and this policy does not warrant a third party's privacy practices. BRF remains responsible for its own applicable provider-selection, contractual, and legal duties. You remain responsible for having authority to direct the requested disclosure.

25. Changes to This Policy and the Meaning of Acknowledgment

25.1 Versioned notice

We may update this policy to reflect changes in the Services, law, or information practices. The current policy shows its effective date and version. We maintain published versions linked from this page so that an account's acknowledgment can be matched to the notice presented. Material changes affecting existing users will receive appropriate additional notice, such as an account message or email, before the change takes effect where required.

25.2 Required consent and existing commitments

We will obtain a new consent when applicable law requires it before a materially different use. A revised policy does not retroactively authorize incompatible uses of previously collected information or reduce an applicable contractual commitment. Continuing to browse or accepting the Terms is not a substitute for a separately required consent. An acknowledgment confirms that the notice was presented; it does not waive your legal rights.

25.3 Further information

For current operational safeguards, see the Security & Trust page. The Terms of Service govern the commercial relationship and authorized use. For a privacy question, request, or complaint, use jbenson@blue-ridge-federal.com or the mailing address in Section 1.

Published versions

  • Privacy Policy · 2026-10-08
Back to top ↑

Company

  • Solutions & Capabilities
  • Company information
  • Contact
  • Client sign in
  • Security & Trust
  • Incident response plan
  • Privacy Policy
  • Terms of Service
  • Accessibility

Resources

  • NDAA §848 lookup
  • FCC Covered List lookup
  • DoD §1260H lookup
  • Blue UAS lookup
  • SAM.gov entity registration
  • NIST SP 800-171 Rev. 3
  • CMMC Program
  • DFARS 252.211-7003: Item Unique Identification
  • FAR Part 19: Small Business Programs
  • Section 508 standards

© 2026 Blue Ridge Federal LLC | UEI RFZ3TK7E35P6 | CAGE 19PB1

Blue Ridge Federal

Software by Blue Ridge Federal LLC

Privacy Policy · 2026-10-08 | Blue Ridge Federal