Privacy Notice

Effective date: October 31, 2025
Who we are: Estrak, LLC (“Estrak” d/b/a Strividian), 5009 Beatties Ford Rd Ste 107-253; Charlotte, NC 28216
Contact: support@strividian.com

This Privacy Notice explains how we collect, use, disclose, and safeguard personal information when you use our services (mock interviews, resume writing, materials development, discovery sessions, coaching), visit our website, or interact with us via SMS.

1. Information we collect

  • Identity & contact: name, email, phone number, billing address.
  • Booking & communications: calendar details, emails, SMS messages (transactional only), chat messages.
  • Resume and materials data: resumes, cover letters, job targets, work history, coaching artifacts, interview notes.
  • Session recordings: audio/video and related transcripts or notes from mock interviews and discovery sessions. Recordings only occur with prior notice and consent.
  • Payment information: handled by our payment processor. We receive payment status, amount, and limited billing details (e.g., last four digits, card brand). We do not collect or store full card numbers.
  • Device/usage data (website): IP address, device/browser details, pages viewed, timestamps.
    • Analytics and advertising tags may be used to measure performance and improve our website (see §5).

2. How we use information (purposes + typical legal bases)

  • Provide and improve services (e.g., resume writing, schedule sessions, conduct and review mock interviews, deliver feedback).
    Legal basis: contract; legitimate interests (service quality).
  • Transactional communications (confirmations, reminders, rescheduling).
    Legal basis: contract; legitimate interests (keeping appointments on track).
  • Payments and invoicing.
    Legal basis: contract; legal obligation (tax/records).
  • Analytics and reach measurement to understand site performance and campaign attribution.
    Legal basis: consent where required; otherwise legitimate interests.
  • Security, fraud prevention, and compliance with applicable laws and requests from authorities.
    Legal basis: legal obligation; legitimate interests.

3. Where your data lives (storage & security)

We use a combination of reputable cloud platforms, communication systems, and local storage with strong security measures:

  • Cloud services for file storage, client data, scheduling, and productivity.
  • Local storage (when used): encrypted hard drive protected by MFA, VPN, and firewall.
  • Access controls: least privilege, MFA enforced, change-controlled devices.
  • Encryption in transit and at rest.
  • Resilience: provider-level backup and periodic integrity checks.

Note on roles: We act as an independent controller for client data provided directly to us. Where we deliver services under a corporate contract, we can operate as a processor under a Data Processing Addendum (DPA) upon request.

4. Disclosures to third parties

We share personal information only as needed to deliver our services or comply with legal obligations:

  • Service providers: This includes vendors supporting video conferencing, file storage, communications, payment processing, website analytics, customer relationship management, and booking systems.
    Our contracts require service providers to use data only for contracted purposes, maintain appropriate safeguards, prohibit resale, and cooperate with rights requests.
  • Compliance and safety: to authorities when required by law or to protect rights, safety, or security.
  • No selling of personal information. We do not sell your data. Some analytics or advertising tools we use may be considered “sharing” under certain state privacy laws (see §8).

5. Analytics and tracking technologies

We use tools to evaluate site traffic, user engagement, and campaign performance. These may collect:

  • IP address, browser/device details, pages visited, session timestamps.
  • Cookies or tags from advertising or analytics services that may associate activity with other platforms.

Controls:

  • Where required, these tools only activate after cookie consent.
  • You can change ad settings in your browser or platform account.
  • We honor Global Privacy Control (GPC) and other opt-out signals recognized under applicable laws.
  • Our “Do Not Sell or Share My Personal Information” link is available in our footer and cookie banner.

6. SMS terms (transactional only)

We send SMS strictly for transactional purposes (e.g., confirmations, reminders, urgent updates).

  • Message frequency varies based on activity.
  • Message/data rates may apply.
  • Opt out: reply STOP; you will receive a confirmation.
  • Help: reply HELP or email support@strividian.com.
  • Carriers are not liable for delayed or undelivered messages.
  • SMS consent is not a condition of purchase.
  • By providing a mobile number, you agree to receive transactional messages for your services.
  • We do not send promotional SMS without your explicit opt-in.

7. Data retention

We retain information only as long as needed for service delivery or legal compliance.

  • Session recordings/transcripts: 12 months unless requested longer, then deleted or anonymized.
  • Client files (resumes, notes): kept for engagement duration plus 24 months, then deleted or anonymized.
  • Billing records: 7 years.
  • Analytics data: per provider settings and your preferences.

You can request earlier deletion when applicable (see §8).

8. Your privacy choices & rights

Depending on your location, your rights may include:

  • Access, correct, delete, or port your personal data.
  • Restrict or object to processing (e.g., analytics/ads).
  • Withdraw consent (e.g., tracking).
  • U.S. state laws (e.g., CA, CO, VA): opt out of “sharing” for cross-context advertising.
    • Use our opt-out link to exercise this right.
    • We honor browser-based opt-out signals like GPC.
    • We will not discriminate against you for exercising your rights.
    • You may appeal a denied request by replying to our decision or emailing with “Appeal” in the subject. We respond within 45 days.

To exercise rights, email support@strividian.com. We may verify your identity. Authorized agents may act on your behalf.

9. International transfers

If your data is transferred across borders (e.g., to U.S.-based services), we implement safeguards such as Standard Contractual Clauses or other approved protections.

10. Children

Our services are not directed to children under 16 (or the age set by local law). We do not knowingly collect data from children. If you believe we have, please contact us to delete it.

11. Changes to this notice

We may update this Notice periodically. Any major changes will be posted on our site or sent to you by email or SMS, along with the new effective date.