1. About this Policy and who is responsible
1.1 This Privacy Policy explains how Mara Studio LLC, an Illinois limited liability company ("Mara Studio", "we", "us" or "our"), collects, uses, shares, retains and protects personal information. We present our business publicly under the brand name Systems Curator.
1.2 Mara Studio LLC is the business responsible for the personal information described in this Policy. We decide why and how that information is handled.
1.3 This Policy applies to the websites we operate at https://helenalemayo.com and https://www.systemscurator.com (the "Website"), to enquiries and bookings made through them, to our email and scheduling correspondence, and to the strategy and operations advisory services we provide to clients.
1.4 This Policy should be read with our Terms of Use, our Cookie Policy and, where you are a client, the confidentiality and data provisions of your client agreement. Where a client agreement contains a specific data protection or confidentiality provision, that provision prevails over this Policy for that engagement.
1.5 If you have a question about this Policy or about how we handle your information, contact us at hello@systemscurator.com. Section 25 explains how to raise a concern.
2. Who and what this Policy covers
2.1 This Policy covers visitors to the Website, people who make an enquiry or book an appointment with us, clients and prospective clients, and the individual representatives of client organizations.
2.2 We focus our business on the United States. We do not target or actively market our services to individuals or businesses in the European Economic Area, the United Kingdom or other jurisdictions outside the United States, and we do not monitor the behavior of individuals located there. This Policy is written for United States law and is not written to satisfy the requirements of the European Union or United Kingdom General Data Protection Regulation.
2.3 The Website is accessible internationally. If you access it from outside the United States, you do so on your own initiative and section 23 explains what that means for your information.
2.4 This Policy does not cover the privacy practices of any third party website, tool or service that we link to. Those services are governed by their own privacy notices.
2.5 In this Policy, "personal information" means information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual. It does not include information that has been aggregated or de identified so that it can no longer reasonably be linked to an individual.
3. A short summary
3.1 We collect the information you give us when you make an enquiry, book an appointment or become a client, together with limited technical information collected automatically when you visit the Website.
3.2 We use that information to respond to you, to schedule and run appointments, to deliver our services, to take payment, to keep proper business records, to send communications you have asked for, and to protect and improve the Website.
3.3 We do not sell personal information. We do not share personal information for cross context behavioral advertising. We do not use advertising pixels or third party advertising technology on the Website.
3.4 We share information only with the service providers who help us operate, which are named in section 15, and in the limited further circumstances described in section 16.
3.5 This summary is for convenience only. The rest of this Policy is the full description and prevails over anything in this section.
4. Personal information you give us
4.1 When you contact us, complete a form, request a resource, book an appointment or engage us, we collect the information you choose to provide. Depending on what you do, this may include:
- your name and the name of your business or organization;
- your email address and, if you provide it, your telephone number;
- your role, your website address and other business details you choose to give;
- a description of the business issue you want to discuss, the service you are interested in, and your desired timing;
- appointment and calendar details, including the date, time, time zone and any information you enter into the booking form;
- the content of emails, messages and documents you send us;
- billing details, including the billing name, billing address and the information needed to raise an invoice; and
- client materials that you provide during an engagement, which are described in section 7.
4.2 Some fields in our forms are required in order for us to respond or to complete a booking. Where a field is optional, you can leave it blank.
4.3 You should not send us confidential, commercially sensitive, legally privileged or specially protected information through a Website form or by unencrypted email before we have a written engagement or a non-disclosure agreement in place. Our booking and intake forms are not a secure channel for that kind of material.
4.4 We do not ask for, and we ask that you do not send us, information about health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, trade union membership, biometric or genetic data, precise geolocation, government identification numbers, or financial account credentials. If you send such information to us unprompted, we will not use it beyond what is necessary to respond to you and we will delete it when it is no longer needed.
4.5 The information you give us must be accurate. Please tell us if it changes.
5. Information we collect automatically
5.1 When you visit the Website, limited technical information is collected automatically by our hosting provider and by the embedded services described in section 15. This may include your Internet Protocol address, browser type and version, device and operating system information, language preference, referring page, the pages you request, the date and time of your request, and an approximate location derived from your Internet Protocol address.
5.2 We use this information to deliver the Website, to keep it secure, to detect and investigate abuse and technical faults, and to understand at a general level how the Website is being used.
5.3 We do not currently use Google Analytics or any advertising or social media pixel on the Website. If we introduce analytics or similar technology, we will update this Policy and our Cookie Policy before or at the time we do so, and we will implement any consent mechanism required by the law that applies to that technology.
5.4 Approximate location derived from an Internet Protocol address is not precise geolocation. We do not collect precise geolocation data from your device.
5.5 Our Cookie Policy explains the cookies and similar technologies used on the Website and how you can control them.
6. Information from other sources
6.1 Most of the information we hold comes directly from you. We do not buy personal information, and we do not obtain personal information from data brokers.
6.2 We may receive limited information about you from the service providers we use, for example a booking confirmation from our scheduling provider, a payment confirmation or a chargeback notice from our payment processor, or an email delivery failure notice from our email provider.
6.3 If a client, a colleague or a contact refers you to us, or introduces you on an email thread, we will receive the information contained in that introduction. If you would prefer that we delete it, tell us and we will.
6.4 Where necessary to assess a prospective engagement, to prepare for a meeting or to check for a conflict of interest, we may look at publicly available sources such as your business website, a public professional profile or a public company register. We record only what is relevant to the engagement.
7. Client materials and business information
7.1 During an engagement you may give us access to business documents, operational data, systems and records. These materials may contain personal information relating to your staff, contractors, customers or suppliers.
7.2 Where we handle personal information contained in your client materials, we do so on your instructions and for the purpose of the engagement. You remain responsible for that information and for having a lawful basis to disclose it to us.
7.3 Client materials are exchanged electronically or through an access-controlled document sharing service. We will tell you which service applies to your engagement before you send material.
7.4 You should provide only the information we need for the engagement. Where we can do the work with information that has been redacted, aggregated or de identified, we would prefer to receive it in that form, and we are happy to discuss this before you send material.
7.5 Client materials are subject to the confidentiality obligations in the applicable client agreement. We do not use client materials to market to your staff, customers or suppliers.
8. Cookies and similar technologies
8.1 The Website uses a small number of cookies and similar technologies. These are principally cookies that are strictly necessary to deliver the Website securely, together with cookies set by the embedded scheduling and payment services described in section 15 when you interact with them.
8.2 We do not use cookies or similar technologies for advertising, for building advertising profiles or for cross site tracking.
8.3 You can control cookies through your browser settings, including by blocking or deleting them. Blocking cookies that are strictly necessary may prevent parts of the Website, including booking and payment, from working.
8.4 Because we do not use tracking technology for advertising or for the sale or sharing of personal information, a browser Do Not Track signal or a Global Privacy Control signal does not change what we collect on the Website. We honor opt out preference signals to the extent required by any law that applies to us.
8.5 Our Cookie Policy, published on the Website, describes each category of cookie in more detail.
9. How and why we use personal information
9.1 We use personal information for the following purposes:
- to respond to your enquiry and to assess whether an engagement is a good fit;
- to schedule, confirm, reschedule and run appointments, including sending reminders;
- to provide the advisory services described in the applicable client agreement, and to prepare and deliver work product;
- to process payments, issue invoices and receipts, and manage refunds, cancellations and chargebacks;
- to communicate with you about a live enquiry, booking or engagement, including administrative and service messages;
- to send you a resource you have requested and, where you have asked for them, marketing communications about our services;
- to keep proper business, accounting and tax records;
- to operate, secure, troubleshoot and improve the Website;
- to detect, investigate and prevent fraud, misuse, security incidents and breaches of our Terms of Use;
- to establish, exercise or defend legal claims, to respond to legal process, and to comply with our legal obligations; and
- to evaluate, plan and, if it happens, complete a sale, financing or reorganization of our business.
9.2 We may create aggregated or de identified information from personal information, for example general statistics about Website use or anonymized examples of the kinds of problems we work on. We do not attempt to re identify that information, and we will maintain it in de identified form.
9.3 We will not use your personal information for a materially different purpose without first telling you and, where the law requires it, obtaining your consent.
9.4 We do not use personal information to make automated decisions about you that produce legal effects or similarly significant effects, and we do not carry out profiling for advertising purposes.
10. Payments
10.1 Payments made to us through the Website are processed by Stripe, Inc. Stripe collects and processes the payment card or bank account details you enter.
10.2 We do not receive or store your full payment card number, card expiry date or card security code. We receive confirmation of the payment together with limited details such as the transaction identifier, the amount, the date, the payment method type and the last four digits of the card.
10.3 Stripe processes payment information as a payment services provider under its own terms and privacy notice, which is published at https://stripe.com/privacy.
10.4 We retain payment and invoicing records for the period described in section 18 because we are required to keep accounting and tax records.
11. Scheduling, email and calendars
11.1 Appointment scheduling is provided through Cal.com. When you continue from an enquiry form to scheduling, the information you enter in the booking flow is transmitted to that provider so the booking can be created.
11.2 A confirmed booking is written into our calendar and generates confirmation and reminder emails. The information in a calendar entry, including your name, email address and any note you added when booking, is processed by our email and calendar provider, Microsoft 365.
11.3 Email correspondence with us is processed and stored by Microsoft 365. Emails are retained in our mailbox and archive in accordance with section 18.
11.4 Appointments are held by video conference or telephone. We do not record appointments unless we tell you in advance and you agree, and we ask that you do not record or use an automated transcription or artificial intelligence notetaking tool on a call with us without telling us first.
11.5 Notes we take during a call are our own business records. They are used to progress the enquiry or the engagement and are retained in accordance with section 18.
12. Marketing communications and your choices
12.1 We send marketing email only to people who have asked to receive it, for example by requesting a resource or subscribing, or where we are otherwise permitted to send it under applicable law.
12.2 Every marketing email contains an unsubscribe link. You can also opt out at any time by writing to hello@systemscurator.com. We act on opt out requests promptly.
12.3 Opting out of marketing does not stop administrative or transactional messages relating to a live enquiry, a booking, an invoice or an engagement. Those messages are part of providing the service.
12.4 We do not sell, rent or license our mailing list, and we do not share your email address with third parties for their own marketing.
12.5 Our commercial email practices are intended to be consistent with the federal CAN SPAM Act, 15 U.S.C. section 7701 and following.
13. Interactive tools and free resources
13.1 The Clarity Check and our other interactive tools run within your browser. We do not receive or store the information you enter unless you separately choose an action that sends it to us. Results are calculated in the page and are not stored by the Website.
13.2 Information you enter into an enquiry or fit call form is not stored by the Website itself. If you continue to scheduling, the information is transmitted to our scheduling provider to create the booking, and it may then be processed by our connected email and calendar providers.
13.3 Where a free resource is delivered by email, we collect the email address you give us in order to send it, and we tell you at the point of collection whether you are also subscribing to further emails.
13.4 You should not enter confidential, commercially sensitive or specially protected information into an interactive tool or a booking form.
14. Artificial intelligence and automated processing
14.1 We may use artificial intelligence tools to support research, drafting, summarization, analysis and administration in the course of our work. A person reviews the output before it is used or released.
14.2 We do not submit client confidential information or personal information contained in client materials to a general purpose artificial intelligence tool unless the client has agreed, or unless the tool is provided under a business agreement that prohibits the provider from using the input to train its models. We do not knowingly permit our providers to use client materials to train general purpose artificial intelligence models.
14.3 We do not use artificial intelligence to make decisions about you that produce legal effects or similarly significant effects without human involvement.
14.4 If you use an artificial intelligence assistant, transcription tool or notetaker in your dealings with us, you are responsible for the information that tool receives and for telling us that it is in use.
15. Service providers we share information with
15.1 We share personal information with service providers that help us operate our business. Depending on the service and the circumstances, they may process information on our behalf or under their own terms and privacy notices.
15.2 The categories of provider we currently use are:
- website hosting and delivery: Vercel;
- appointment scheduling and intake: Cal.com;
- payment processing, invoicing and billing: Stripe;
- business email, calendar and document exchange: Microsoft 365.
15.3 We may also share information with our professional advisers, such as our accountant, tax adviser, insurers and lawyers, where they need it to advise us, and they are bound by professional duties of confidence.
15.4 We review the providers we use from time to time and may add, change or remove a provider. The current list of providers is available on request from hello@systemscurator.com, and we will update this Policy when we make a material change.
15.5 We do not disclose personal information to any third party for that third party to use for its own purposes, except as described in section 16.
16. Other circumstances in which we may disclose information
16.1 We may disclose personal information where we are required to do so by law, by a court order, by a subpoena or by another valid legal process, or where a regulator or government authority makes a lawful request.
16.2 We may disclose personal information where we reasonably consider it necessary to establish, exercise or defend a legal claim, to enforce our Terms of Use or a client agreement, or to collect a debt.
16.3 We may disclose personal information where we reasonably consider it necessary to investigate or prevent fraud, a security incident, or conduct that is unlawful or that threatens the rights, property or safety of any person.
16.4 If we are involved in a merger, acquisition, financing, reorganization, insolvency or a sale of all or part of our business or assets, personal information may be disclosed to the counterparty and its advisers as part of that process, subject to appropriate confidentiality protections, and may be transferred as part of the transferred assets. We will tell you if your information becomes subject to a materially different privacy policy as a result.
16.5 Where we can lawfully do so, and where it is reasonable in the circumstances, we will tell you before disclosing your information in response to legal process.
17. We do not sell or share personal information for advertising
17.1 We do not sell personal information, and we have not sold personal information. We do not receive money or other valuable consideration in exchange for disclosing personal information.
17.2 We do not share personal information for cross context behavioural advertising or targeted advertising, and we do not disclose personal information to advertising networks, data brokers or analytics providers for their own purposes.
17.3 We do not sell or share the personal information of any individual, and we do not knowingly collect the personal information of anyone under sixteen years of age.
17.4 Disclosures to the service providers named in section 15, made so that they can perform a service for us, are not sales.
18. How long we keep personal information
18.1 We keep personal information only for as long as we need it for the purpose for which it was collected, or for as long as we are required or permitted to keep it by law.
18.2 Our current retention practice is as follows:
- enquiries and bookings that do not become engagements: up to twelve months from the last contact;
- routine client working materials: the duration of the engagement plus three years;
- client agreements, approvals and core engagement records: the duration of the engagement plus ten years;
- financial, invoicing and tax records: seven years from the end of the relevant tax year;
- marketing subscription records, including proof of your opt in and any opt out: for as long as you remain subscribed and for a reasonable period afterwards to honor your opt out;
- records subject to a legal hold: until the relevant matter and any appeal period has concluded.
18.3 The retention periods for core engagement records and for financial records are set by reference to the periods within which claims may be brought and within which records may need to be produced. We keep them under review with our professional advisers and will update this Policy if they change.
18.4 Information held by a service provider is also subject to that provider retention and deletion practices, including backup cycles. Information may persist in secure backups for a limited period after deletion from our active systems and will be deleted or overwritten in the ordinary course of the backup cycle.
18.5 When we no longer need personal information we delete it or de identify it so that it can no longer reasonably be linked to you.
19. How we protect personal information
19.1 We use administrative, technical and physical measures designed to protect personal information against loss, misuse, unauthorized access, disclosure, alteration and destruction. These include access controls, multi factor authentication on our business accounts, encryption in transit, use of reputable providers, and limiting access to the people who need it.
19.2 We do not claim compliance with, or certification under, any particular security standard or framework. Where a client requires a specific security control, we are happy to discuss it before the engagement begins and to record it in the client agreement.
19.3 No method of transmission over the internet and no method of electronic storage is completely secure. While we work to protect your information, we cannot guarantee its absolute security, and you send information to us at your own risk.
19.4 You are responsible for protecting your own devices, email account and any credentials used to access a document sharing service we make available to you, and for telling us promptly if you believe access has been compromised.
19.5 If a security incident affects personal information we hold, we will investigate and will notify affected individuals and any relevant authority where required. In Illinois, notification of a breach involving specified categories of personal information is governed by the Personal Information Protection Act, 815 ILCS 530. Other states have their own notification requirements, and we will comply with those that apply.
20. Children
20.1 The Website and our services are intended for business owners and operators, and are directed to adults. They are not directed to children.
20.2 We do not knowingly collect personal information from anyone under the age of eighteen, and we do not knowingly collect personal information from children under thirteen within the meaning of the federal Children Online Privacy Protection Act, 15 U.S.C. sections 6501 to 6506, and its implementing rule at 16 C.F.R. Part 312.
20.3 If you believe that a child has provided personal information to us, contact us at hello@systemscurator.com and we will delete it promptly.
21. Your choices and how to exercise them
21.1 Whatever your location, we make the following available to you as a matter of practice:
- to ask what personal information we hold about you and to obtain a copy of it;
- to ask us to correct information that is inaccurate or incomplete;
- to ask us to delete information that we no longer need;
- to opt out of marketing communications at any time; and
- to ask us how we obtained your information and who we have disclosed it to.
21.2 To exercise any of these, email hello@systemscurator.com with enough detail for us to identify your information and understand what you are asking for. We will acknowledge your request and aim to respond within thirty days. If we need more time because your request is complex, we will tell you and explain why.
21.3 We may need to take reasonable steps to verify your identity before acting on a request, particularly a request for a copy or for deletion. We will only use the information you provide for verification for that purpose.
21.4 An authorized agent may make a request on your behalf if the agent provides evidence of your authorization and we are able to verify your identity.
21.5 We may decline a request, in whole or in part, where we are required or permitted by law to keep the information, where it relates to a live or anticipated legal claim, where it is contained in client materials belonging to a client organization rather than to you personally, or where complying would adversely affect the rights of another person. If we decline, we will tell you why. We will not discriminate against you for making a request.
22. Residents of United States with privacy statutes
22.1 A number of United States have enacted comprehensive consumer privacy statutes. Those statutes generally apply only to businesses that process personal data above specified volume or revenue thresholds, or that derive a substantial part of their revenue from selling personal data. Mara Studio LLC is a small business that does not sell personal data, and we do not believe we currently meet the applicability thresholds of those statutes.
22.2 We nevertheless make the choices described in section 21 available to all individuals, regardless of where they live, as a matter of policy rather than because a particular statute compels it. If our business grows to the point where a state statute applies to us, we will update this Policy and provide the specific rights, disclosures and response times that statute requires.
22.3 Illinois, where we are established, has not enacted a comprehensive consumer privacy statute. Illinois does regulate the notification of security breaches involving specified categories of personal information under the Personal Information Protection Act, 815 ILCS 530, and we address that in section 19. Illinois also regulates biometric information under the Biometric Information Privacy Act, 740 ILCS 14. We do not collect, capture, purchase, receive or store biometric identifiers or biometric information.
22.4 California Civil Code section 1798.83, sometimes called the Shine the Light law, allows certain California residents to request information about personal information disclosed to third parties for those third parties own direct marketing purposes. We do not make disclosures of that kind, so there would be nothing to report in response to such a request.
22.5 We are also subject to section 5 of the Federal Trade Commission Act, 15 U.S.C. section 45, which prohibits unfair or deceptive acts or practices. The statements in this Policy are statements on which you are entitled to rely.
23. Visitors outside the United States
23.1 We operate from the United States and our service providers process information in the United States and, in some cases, in other countries where they or their sub processors maintain infrastructure.
23.2 If you access the Website or contact us from outside the United States, your information will be transferred to, stored in and processed in the United States. Data protection law in the United States differs from the law of your country and may offer different protections.
23.3 By using the Website or contacting us from outside the United States, you understand that your information will be processed as described in this Policy.
23.4 We do not offer goods or services to, and we do not monitor the behavior of, individuals in the European Economic Area or the United Kingdom. If you are located in one of those jurisdictions and you have a question about your information, contact us and we will deal with it fairly. Where an obligation under a law outside the United States applies to a particular engagement, we would need to take specific advice on that jurisdiction before agreeing to it.
24. Changes to this Policy
24.1 We may update this Policy from time to time, for example if we change a service provider, introduce a new feature, or if the law changes.
24.2 The current version is always published on the Website and the effective date at the top shows when it last changed.
24.3 If a change is material, we will take reasonable steps to bring it to your attention before it takes effect, for example by a notice on the Website or by email to clients and subscribers.
24.4 We keep previous versions of this Policy. If you would like a copy of the version that applied at a particular time, ask us.
25. How to contact us and how to raise a concern
25.1 For any question, request or concern about this Policy or about how we handle personal information, contact us at hello@systemscurator.com.
25.2 Our details are as follows.
Legal entity: Mara Studio LLC, an Illinois limited liability company. The company operates publicly under the brand name Systems Curator. An application to register Systems Curator as an assumed name under section 1-20 of the Illinois Limited Liability Company Act, 805 ILCS 180, has been submitted and is pending.
Email: hello@systemscurator.com
Websites: https://helenalemayo.com
25.3 If you are not satisfied with our response, tell us and we will review the matter again.
25.4 We aim to acknowledge a privacy enquiry within five business days and to give a substantive response within thirty days.