Logo

Decisive Resources

A Bespoke Privacy Management and Consulting Firm

Privacy Policy

Last updated: July 22, 2026

Decisive Resources ("Decisive Resources," "we," "us," or "our") is a Wyoming LLC headquartered in Austin, Texas, providing privacy management, virtual CISO (vCISO), and investigative services. This Privacy Policy explains how we collect, use, and protect information when you visit decisiveresources.com (the "Site") or engage us for services, and describes the choices available to you.

By using the Site or our services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site or our services.

1. Information We Collect

Information you provide directly. We collect information you voluntarily provide, such as when you:

  • Book a consultation or meeting through our scheduling tool (name, email address, phone number, and any details you include about your inquiry);
  • Contact us by email or through the Site;
  • Sign up to receive updates or newsletters from us; or
  • Engage us as a client, in which case we collect the information necessary to perform the engagement, which may include sensitive personal, financial, or business information depending on the scope of work.

Information collected automatically. Like most websites, our hosting and content delivery infrastructure may automatically log standard technical information (such as IP address, browser type, device information, and pages visited) for security, performance, and analytics purposes. We do not currently use advertising or cross-site tracking cookies on the Site.

Information from third parties. Our scheduling tool is provided by a third-party vendor (Cal.com). When you book a consultation, information you enter is also subject to that provider's own privacy practices.

2. How We Use Information

  • To respond to inquiries and schedule consultations or meetings;
  • To deliver, manage, and improve our privacy management, vCISO, and investigative services;
  • To communicate with current and prospective clients, including service updates and, where you have opted in, newsletters or marketing communications;
  • To maintain the security, integrity, and proper functioning of the Site and our systems; and
  • To comply with legal obligations and enforce our agreements.

3. OSINT, Background, and Breach-Exposure Reviews

In connection with our privacy management, vCISO, and investigative services, we may conduct limited background checks, open-source intelligence (OSINT) reviews, public-records searches, and information-availability assessments relating to our clients. These reviews draw only on information that is publicly available or otherwise lawfully accessible, including commercially available databases and other lawful sources, and are conducted to identify a client's exposure, validate risk assumptions, and manage the professional, legal, and operational aspects of delivering our services. The scope and depth of these reviews vary by engagement and are described further in the applicable Engagement Agreement.

This activity does not constitute a consumer report, employment background check, or investigative consumer report as defined under the Fair Credit Reporting Act (FCRA), and is not used to make employment, credit, insurance underwriting, or eligibility determinations.

As part of our services, we may also check whether a client's information has been exposed in known data breaches. We do this solely to notify clients of risk and help them respond — we do not sell, share, or profit from breached data in any way.

4. How We Protect Information

Given the sensitive nature of our work, security is core to how we operate, both for the Site and for client engagements. Our practices include:

  • Encryption of data in transit and at rest;
  • Independent third-party penetration testing of our systems;
  • Secure, encrypted backups of the information we hold, maintained on a regular basis;
  • Access to client and internal information restricted on a need-to-know, least-privilege basis, with information compartmentalized among employees according to their role in an engagement; and
  • Ongoing adherence to industry security best practices as our services and infrastructure evolve.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. However, we are committed to using commercially reasonable, industry-standard safeguards appropriate to the sensitivity of the information we handle. Where an engagement involves access to your own organization's network, systems, or data — for example, under a vCISO engagement — you remain responsible for backing up and protecting that data; our responsibilities with respect to any such systems are defined in the applicable Engagement Agreement.

5. How We Share Information

We do not sell your personal information. We may share information with:

  • Vetted subcontractors, investigators, or partners engaged to help deliver a specific client engagement, bound by confidentiality obligations and provided information on a need-to-know basis;
  • Service providers who support our operations (such as scheduling, communications, and hosting providers), solely to perform functions on our behalf;
  • Professional advisors (such as legal or accounting) where necessary; and
  • Authorities or third parties where required by law, or to protect the rights, safety, or property of Decisive Resources, our clients, or others.

6. Data Retention

We retain information for as long as necessary to fulfill the purposes described in this Policy, including to provide services, satisfy legal and contractual obligations, resolve disputes, and enforce our agreements. Retention periods for client engagement data are generally governed by the terms of the applicable engagement agreement.

7. Your Choices and Rights

You may contact us at any time to ask what information we hold about you, to request corrections, or to request deletion of information we are not otherwise required or entitled to retain (for example, to meet legal, contractual, or engagement-related obligations). If you are located in the European Economic Area (EEA), United Kingdom, or California, you may have additional rights under laws such as the GDPR or the California Consumer Privacy Act (CCPA), including the right to access, correct, or delete your personal information and to opt out of certain uses. To exercise any of these rights, contact us using the information in Section 10 below and we will respond as required by applicable law.

You may unsubscribe from marketing or newsletter emails at any time using the link provided in those emails, or by contacting us directly.

8. Children's Privacy

The Site and our services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to remove it.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated version on this page with a revised "Last updated" date. Your continued use of the Site or our services after a change becomes effective constitutes acceptance of the revised Policy.

10. Contact Us

If you have questions about this Privacy Policy or how we handle information, please contact us at [email protected].

Need Help?