Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how IOSHA Ventures LLC, a New Mexico limited liability company operating the IOSHA platform ("IOSHA", "we", "us"), as data controller, collects, uses, shares, and protects your personal data when you use our website and Services. It also describes your privacy rights, including under the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).

1. Information we collect

  • Account data: name, email, and password (stored only as a secure hash).
  • Transaction data: purchases, amounts, and payment status. Card details are handled by Stripe; we never receive or store full card numbers.
  • Formation intake data: the information you provide to prepare documents, which may include names, addresses, and other details you choose to submit.
  • Usage data: pages viewed, course progress, and basic device and log information.
  • Communications: messages you send us for support.

2. How we use your data

  • To provide the Services: create your account, deliver courses, process payments, and prepare requested documents.
  • To operate and improve the Services and maintain security.
  • To communicate with you about your account, purchases, and support requests.
  • To comply with legal, tax, and accounting obligations.

3. Legal bases (EU/UK GDPR)

Where the GDPR applies, we process personal data on these legal bases: performance of a contract (to provide the Services you buy); legitimate interests (to secure and improve the Services); consent (for optional communications, where required); and legal obligation (for tax and accounting records).

4. How we share data (processors)

We do not sell your personal data. We share it only with service providers that process it on our behalf under contract:

  • Stripe (payment processing).
  • Amazon Web Services (hosting, database, and document storage).
  • Email/communication providers used to send account and support messages.
  • Legal or governmental authorities where required by law.

5. Cookies

We use strictly necessary cookies for authentication and security. See our Cookie Policy for details.

6. Data retention

We keep personal data for as long as your account is active and as needed to provide the Services, then for the period required to meet legal, tax, and accounting obligations or to resolve disputes. Generated formation documents may contain sensitive information and are retained under access controls.

7. Security

We use technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, hashed passwords, role-based access controls, and least-privilege access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. International transfers

We are based in the United States and our providers may process data there. Where we transfer personal data from the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

9. Your GDPR rights (EEA/UK)

If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or object to processing of your personal data, the right to data portability, and the right to withdraw consent. You may also lodge a complaint with your local data protection authority.

10. Your California rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and share it, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising these rights. We do not sell or share your personal information for cross-context behavioral advertising.

11. How to exercise your rights

To exercise any of these rights, email privacy@iosha.net. We will verify your request and respond within the time required by applicable law. You may use an authorized agent where permitted.

12. Children's privacy

The Services are intended for adults 18 and older. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Do Not Track and Global Privacy Control

Because we do not track you across third-party sites for advertising, we do not respond differently to browser Do Not Track signals. Where required, we honor recognized opt-out preference signals such as Global Privacy Control.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted here with an updated date.

15. Contact

Privacy questions or requests: privacy@iosha.net. General support: support@iosha.net.