Privacy Policy
Futurestrategypr Advisory Group, LLC ('we') operates the website futurestrategypr.com and provides advisory services related to federal and state programs in Puerto Rico. This policy explains what data we collect, how we use it and the rights you have as a user under Puerto Rico Act No. 27-2024 on Personal Data Protection, the HIPAA Act where applicable and, when appropriate, principles analogous to the European GDPR.
1. Data controller
Controller: Futurestrategypr Advisory Group, LLC. Postal address: 256 Tetuán Street, Suite 304, Old San Juan, PR 00901. EIN 66-0873214. Privacy contact: privacy@futurestrategypr.com.
2. Data we collect
a) Contact data (name, email, phone) provided voluntarily through forms. b) Operational information needed to prepare files (ID, income, household composition) only when the service requires it and with explicit consent. c) Technical data: truncated IP, browser, pages visited, date and time. d) Cookie consent data stored locally in your browser.
3. Purpose of processing
We use your data to (i) respond to your requests and deliver the advisory service; (ii) comply with legal, accounting and anti-fraud obligations; (iii) improve the security and performance of the site; (iv) with your consent, send updates on new federal programs relevant to Puerto Rico.
4. Legal basis
Legal bases: contract performance or pre-contractual measures, explicit consent, compliance with local and federal legal obligations, and the legitimate interest of operating the site securely.
5. Data sharing
We never sell personal data. We share it only with (a) government agencies designated by you for filing purposes; (b) certified technology providers bound by confidentiality clauses (hosting, email, support); (c) authorities when required by court order or applicable law.
6. Retention
We retain advisory data for seven (7) years, as required by Puerto Rico Treasury Department audits. Marketing data is deleted after 24 months of inactivity.
7. Your rights
You may request access, rectification, deletion, portability, objection and limitation of processing. To exercise these rights, write to privacy@futurestrategypr.com with proof of identity. We respond within 30 calendar days.
8. International transfers
Some providers operate from the continental United States. In all cases, we require data protection agreements and equivalent technical safeguards.
9. Security
We apply encryption in transit (TLS 1.3), role-based access control, annual independent audits and an Incident Response Plan aligned with NIST SP 800-61.
10. Changes
We may update this policy. The current version will be published with the update date. Material changes will be notified by email or through a visible notice on the site for 30 days.