OculusIT Privacy Notice
OculusIT Privacy Notice
Policy Title: OculusIT Privacy Notice
Policy Owner: Chief Information Security Officer / Privacy Lead
Approval Authority: Chief Operating Officer (delegated via Board of Directors)
Effective Date: Sept 9, 2026
Last Reviewed: Sept 9, 2026
Next Review: Annual review, or sooner following material changes to processing activities, applicable law, contractual obligations, or the OculusIT Information Security Management System
Version: Public view
Scope: Public privacy notice covering website visitors, business contacts, prospective clients, clients, authorized users, and other individuals whose personal information may be processed by OculusIT in connection with its website, communications, services, and business operations.
This Privacy Notice explains how OculusIT LLC and its affiliates collect, use, disclose, retain, protect, and otherwise process personal information. It also explains the privacy rights available to individuals under applicable laws and describes how OculusIT aligns its privacy practices with its Information Security Management System, ISO/IEC 27001:2022 control obligations, and applicable Gramm-Leach-Bliley Act requirements when processing customer information for covered clients.
This policy is intended as a public-facing privacy notice. It does not replace OculusIT’s internal Information Security Program, written information security program, incident response procedures, record-retention procedures, vendor management procedures, data classification standards, client contracts, or other operational controls.
1. OculusIT Identity and Role
OculusIT LLC provides information technology, managed services, cybersecurity, compliance, application, infrastructure, and related services, focusing on higher education and client service delivery. Depending on the context, OculusIT may process personal information in different roles.
For website, marketing, recruiting, corporate, vendor, and general business-contact information, OculusIT may determine the purposes and means of processing and may act as a controller, business, data fiduciary, or equivalent role under applicable law.
For client data processed as part of contracted services, OculusIT generally acts as a service provider, processor, data processor, or similar role, processing information on documented client instructions and subject to the applicable client agreement. Where a client is a financial institution or otherwise subject to GLBA, OculusIT may process nonpublic personal information or customer information as a service provider and will use that information only to perform contracted services, support security, comply with law, and meet contractual obligations.
Client agreements, data-processing addenda, statements of work, institutional policies, and applicable law control role allocation where they impose more specific requirements.
2. Applicability and Jurisdiction
This Privacy Notice applies to personal information OculusIT processes through its website, business communications, digital forms, client engagements, vendor relationships, marketing activities, and service delivery activities where OculusIT is responsible for the policy notice or processing activity.
Privacy rights and obligations may vary depending on the individual’s location, relationship with OculusIT, the service involved, the type of information processed, the location of processing, contractual commitments, and applicable law. Relevant requirements may include United States federal and state privacy and security laws, Illinois privacy requirements, GLBA where applicable, FERPA where applicable through client relationships, contractual privacy obligations, and India Digital Personal Data Protection Act requirements where applicable.
Where OculusIT processes personal information on behalf of a client, individuals may need to contact the client institution directly to exercise rights, unless OculusIT is authorized to respond directly.
3. Information We Collect
OculusIT may collect the following categories of information:- Contact and identity information: Name, business title, employer, institution, email address, phone number, mailing address, and similar business-contact details.
- Account and service information: Account identifiers, authorized-user details, service requests, support tickets, communication records, and service-related metadata.
- Website and usage information: IP address, browser type, device information, pages visited, referring pages, visit date and time, session activity, and similar usage data.
- Communications information: Information submitted through contact forms, email, chat, webinars, events, surveys, sales inquiries, support requests, and other communications.
- Client service information: Information provided by clients or authorized users for contracted services, which may include institutional data, user records, support data, technical logs, student-related or employee-related information, and regulated information depending on the client environment.
- Nonpublic personal information and customer information: Where OculusIT supports clients subject to GLBA, OculusIT may process customer information or nonpublic personal information only as required to perform contracted services and subject to applicable contractual safeguards.
- Security and compliance information: Authentication, access, logging, monitoring, vulnerability, audit, investigation, incident, and compliance evidence records.
- Vendor and business relationship information: Contact, due diligence, contractual, financial, and operational information relating to vendors, partners, and business contacts.
- Sensitive or special-category information: OculusIT does not seek to collect sensitive or special-category information through its public website unless necessary for a specific lawful purpose. If OculusIT processes such information in connection with client services or business operations, it applies appropriate safeguards and limits processing to authorized purposes.
OculusIT seeks to minimize the personal information it collects and processes to what is reasonably necessary for defined business, contractual, legal, security, and operational purposes.
4. Sources of Information
OculusIT may collect information directly from individuals, clients, authorized users, business contacts, vendors, service providers, public sources, event registrations, website interactions, security tools, monitoring systems, client systems, and approved third-party platforms.
When a client provides information, OculusIT processes it according to the client agreement, documented instructions, and applicable law.
5. Purposes and Legal Bases for Processing
OculusIT may use personal information for the following purposes: to provide, operate, maintain, support, secure, and improve services; respond to inquiries, service requests, and business communications; manage client, vendor, partner, and business relationships; conduct sales, marketing, events, webinars, and educational outreach subject to applicable opt-out rights; administer accounts, contracts, billing, procurement, and service delivery; protect systems, data, networks, users, and services; conduct logging, monitoring, vulnerability management, incident response, investigations, compliance reviews, and audits; satisfy legal, regulatory, contractual, accounting, insurance, dispute-resolution, and risk-management obligations; evaluate and improve website performance, user experience, service quality, and business operations; perform privacy, security, vendor, transfer, data-protection, and information-security risk assessments; comply with client instructions and contractual obligations; and support business continuity, backup, disaster recovery, and service resilience.
Depending on the jurisdiction and processing activity, OculusIT may rely on contract necessity, consent, legitimate organizational purposes, compliance with law, protection of rights and security, performance of client instructions, or other lawful bases recognized by applicable law. OculusIT will not treat use of the website as blanket consent for all processing activities where another lawful basis is more appropriate or where specific consent is required. Where consent is used, OculusIT will seek to ensure that consent is informed, specific, freely given where required, and capable of withdrawal through a reasonable mechanism.
6. Cookies, Analytics, and Tracking Methods
OculusIT may employ cookies, pixels, web beacons, tags, scripts, and similar technologies to operate the website, retain preferences, understand site usage, improve content, support security, and measure communications effectiveness. Cookies may include strictly necessary cookies, preference or functionality cookies, analytics cookies, and marketing or communication cookies, subject to applicable consent and opt-out rules.
OculusIT ought to maintain a current cookie inventory that identifies cookie name, provider, purpose, category, duration, consent status, and whether the cookie is first-party or third-party. Where required by law, nonessential cookies and similar tracking technologies should be withheld until appropriate consent is obtained. Individuals should be provided a practical way to manage preferences and withdraw nonessential consent. Browser settings may allow individuals to block or delete certain cookies. Blocking cookies may affect webpage functionality.
7. How We Share Information
OculusIT may share personal information only as reasonably necessary and subject to applicable safeguards. Categories of recipients may include OculusIT affiliates and personnel who require access for authorized business, security, compliance, or service purposes; client institutions and their authorized representatives where the information relates to contracted services; service providers, subprocessors, vendors, consultants, contractors, and professional advisers; cloud, hosting, security, analytics, communication, ticketing, CRM, and business-operations providers; regulatory authorities, law enforcement, courts, auditors, insurers, or other third parties where required or permitted by law; and parties to a business transaction such as merger, acquisition, restructuring, financing, or sale of assets, subject to appropriate confidentiality and legal safeguards.
OculusIT does not sell client nonpublic personal information. OculusIT does not use client-provided GLBA nonpublic personal information for its own marketing or disclose it to nonaffiliated third parties outside the contracted service scope except as permitted or required by the client agreement, applicable law, or documented client instructions.
8. Service Provider and Supplier Oversight
OculusIT uses third-party service providers and suppliers to support service delivery and business operations. OculusIT seeks to manage supplier risk through due diligence, contractual safeguards, data-processing terms, confidentiality obligations, security requirements, vendor risk assessments, subprocessor review, and periodic reassessment based on risk. Where a service provider processes personal information, customer information, or regulated client data, OculusIT expects the service provider to protect the information, restrict use and disclosure, support required privacy and security obligations, and notify OculusIT of relevant security or privacy events as required by contract. This supports ISO/IEC 27001 supplier controls and, where GLBA applies, service-provider oversight expectations for securing customer information.
9. International Data Transfers
OculusIT may process and transfer information in the United States, India, and other locations where OculusIT, its affiliates, clients, or service providers operate. Transfer practices depend on the data type, processing role, applicable law, client agreement, and service location. Where required, OculusIT uses appropriate transfer procedures and safeguards, which may include contractual commitments, data-processing agreements, client instructions, risk assessments, access restrictions, encryption, approved subprocessors, and other lawful mechanisms. OculusIT should avoid depending exclusively on generalized consent language for international transfers where a specific legal transfer mechanism is required. For India-subject processing under the DPDP Act, cross-border transfers should be handled in accordance with applicable restrictions and government-notified limitations, if any.
10. Data Security Safeguards
OculusIT maintains administrative, technical, and physical safeguards designed to secure personal information against unauthorized access, disclosure, alteration, loss, misuse, and destruction. Safeguards are risk-based and consistent with OculusIT’s Information Security Program, ISO/IEC 27001:2022 control framework, client obligations, and applicable legal requirements. Safeguards may include governance oversight and defined security responsibilities; risk assessments and risk treatment plans; access control, least privilege, authentication, and multi-factor authentication if required; encryption of information in transit and at rest where appropriate; logging, monitoring, alerting, and security-event review; vulnerability management, patching, and secure configuration practices; data classification, handling, masking, and minimization controls; data loss prevention and secure information-transfer practices; backup, restore, business-continuity, and disaster-recovery controls; security awareness training and personnel responsibilities; vendor and third-party security oversight; incident response and evidence preservation procedures; and periodic compliance review, audit, and control evidence maintenance.
No method of transmission or storage is completely secure. OculusIT uses reasonable safeguards appropriate to the risk, but cannot provide total security.
11. GLBA Safeguards and Customer Information
Where OculusIT is directly subject to GLBA or processes customer information for a client that is subject to GLBA, OculusIT maintains or supports safeguards appropriate to its role, contract, and legal obligations. These safeguards may include a written information security program, designation of an accountable security leader or qualified individual, periodic risk assessments, access controls, encryption where appropriate, multi-factor authentication if required, secure disposal practices, monitoring and testing, personnel training, service-provider oversight, incident response planning, and reporting to senior leadership or governance bodies. Where OculusIT acts as a service provider to a GLBA-covered client, OculusIT uses client customer information only to perform contracted services, support security, comply with law, or meet documented contractual obligations. OculusIT will not redisclose or reuse nonpublic personal information beyond the purpose for which it was provided unless permitted by the client agreement and applicable law.
12. GLBA Privacy Rule Considerations
Where GLBA Privacy Rule requirements apply directly to OculusIT, OculusIT will provide required privacy notices and all required opt-out mechanisms concerning the collection, disclosure, and protection of nonpublic personal information. Where OculusIT acts as a service provider to a financial institution or covered client, the client generally remains responsible for issuing its own GLBA consumer privacy notices and managing consumer opt-out rights unless the contract states otherwise. OculusIT will process nonpublic personal information received from such clients only for authorized service purposes and subject to applicable redisclosure and reuse restrictions.
13. Anti-Pretexting and Verified Requests
OculusIT prohibits obtaining or attempting to obtain customer information, nonpublic personal information, account information, or other protected information through false, fictitious, fraudulent, misleading, forged, stolen, or unauthorized means. OculusIT also prohibits inducing or soliciting another person to obtain protected information through false pretenses. Requests for customer, client, user, or personal information must be submitted through verified channels and may require identity verification, authorization validation, contractual confirmation, or client approval. Suspected pretexting, social engineering, impersonation, or fraudulent attempts to obtain information should be reported through OculusIT’s security or privacy reporting channels and handled through the incident-response process.
14. Retention, Deletion, Legal Holds, and Backups
OculusIT retains personal information only for as long as reasonably necessary for the purposes described in this policy, including service delivery, business operations, legal compliance, security, audit, dispute resolution, contractual obligations, and legitimate recordkeeping. Retention periods may vary by data category, client agreement, legal requirement, system, and operational purpose. OculusIT has to maintain an internal retention schedule covering website data, business-contact data, support records, client-service records, security logs, audit evidence, contracts, financial records, and regulated records. When information is no longer required, OculusIT will delete, anonymize, archive, or securely dispose of it in accordance with applicable policies and legal requirements. Deletion may be delayed or limited where information is subject to legal hold, contractual retention, security investigation, backup retention, regulatory obligations, or other lawful exceptions. Information may remain in protected backups or archives until ordinary expiration or secure overwrite, provided it is not restored for routine use except where necessary for legal, security, continuity, or compliance purposes.
15. Privacy and Security Incidents
OculusIT maintains incident response procedures for identifying, assessing, escalating, investigating, containing, remediating, and documenting security and privacy incidents. If OculusIT determines that a privacy or security incident requires notification, it will provide notices to affected clients, individuals, regulators, or authorities as required by applicable law, contract, and role. Notification timing and content may differ by jurisdiction and obligation. Where GLBA notification requirements apply directly to OculusIT, OculusIT will evaluate whether a security event meets the applicable notification-event threshold and follow the required process. Where OculusIT processes information as a service provider, OculusIT will notify the client as required by contract and support the client’s legal and regulatory response.
16. Personal Privacy Rights
Depending on applicable law, individuals may have rights to request access to personal information; request correction or updating of incorrect or incomplete information; request deletion or erasure of personal information; request restriction or objection to certain processing; withdraw consent where processing is based on consent; object to direct marketing where applicable; request information about categories of information processed, purposes, recipients, or sharing; request portability where applicable; authorize a representative to submit a request where permitted by law; submit a privacy complaint or grievance; and exercise additional jurisdiction-specific rights, including rights under India’s DPDP Act where applicable, such as grievance redressal and nomination rights. Rights are not absolute and may be subject to identity verification, legal exceptions, client instructions, contractual restrictions, security considerations, or retention obligations. Where OculusIT processes personal information on behalf of a client, OculusIT may refer the request to the client or coordinate with the client before responding.
17. Privacy Request Process
Individuals may submit privacy requests through the appointed OculusIT privacy contact or other published request mechanism. OculusIT ought to maintain an internal privacy request workflow that records request date, requester identity, request type, jurisdiction, applicable system, verification status, responsible owner, due date, disposition, approvals, response, and closure evidence. OculusIT may request information necessary to verify identity, confirm authority, locate relevant records, and protect against unauthorized disclosure. Authorized representatives may be required to provide proof of authority. OculusIT will respond within the timeframe required by applicable law. Requests may be denied or limited where OculusIT cannot verify identity, where the request conflicts with legal or contractual obligations, where the data is controlled by a client, where security or fraud risks exist, or where an exception applies.
18. Marketing Communications and Opt-Out
OculusIT may send marketing communications, event invitations, service updates, thought leadership, or similar business communications where permitted by law. Individuals may opt out of marketing communications by using unsubscribe mechanisms or contacting OculusIT. Opting out of marketing communications does not prevent OculusIT from sending non-marketing communications, such as service notices, security alerts, transactional messages, contractual communications, support updates, or legal notices. Where applicable law provides a right to object to direct marketing, OculusIT will honor that right within the required timeframe.
19. Children’s Privacy
OculusIT’s website and services are not directed to children. OculusIT does not knowingly collect personal information from children through the public website without appropriate authorization. Where information relating to minors is processed as part of client services, OculusIT processes that information according to the client agreement, client instructions, applicable education privacy requirements, and applicable law. Where India DPDP Act requirements apply to children’s data, OculusIT will follow applicable requirements for verifiable parental or guardian consent and restrictions on tracking, behavioral monitoring, or targeted advertising directed at children, subject to applicable exceptions.
20. Automated Decision-Making and Profiling
OculusIT does not intend to use personal information collected through the public website for automated decisions that produce legal or similarly significant effects on individuals without appropriate notice, lawful basis, and safeguards. If OculusIT uses automated tools, analytics, or AI-supported processes in business or service operations, such use should be governed by applicable internal policies, client agreements, human monitoring requirements, privacy risk assessment, data minimization, and security controls.
21. Records of Processing, Privacy Risk Assessment, and Compliance Review
OculusIT maintains internal records and control evidence describing relevant categories of information, processing purposes, recipients, systems, transfers, retention requirements, security measures, and accountable owners, as appropriate for its role and legal obligations. New or materially changed processing activities involving personal information should be evaluated for privacy, security, legal, contractual, and operational risk before launch. Where required by law or warranted by risk, OculusIT should perform a privacy impact assessment or data protection impact assessment. OculusIT’s Privacy Notice and supporting procedures should be reviewed at planned intervals and after significant changes. Compliance with the policy and related controls should be subject to periodic internal review, independent review where appropriate, and evidence maintenance under the ISMS.
22. Changes to This Privacy Notice
OculusIT may update this Privacy Notice from time to from time to time to reflect changes in law, services, processing activities, security practices, contracts, or business operations. The current version should include an effective date, last reviewed date, policy owner, version number, and review cycle. Material changes should be reviewed and approved through OculusIT’s policy governance process before publication. Prior versions should be retained where required by policy or legal obligation.
23. Contact Information
Questions, requests, complaints, or concerns about this Privacy Notice or OculusIT’s privacy practices may be directed to the designated OculusIT privacy contact.Privacy Contact: privacy@oculusit.com
Security Contact: secops@oculusit.com
Mailing Address: OculusIT LLC, 55 E Monroe St, Chicago, IL, 60603-5765
Privacy Owner: Chief Information Security Officer / Privacy Lead
India DPDP Grievance Contact, where applicable: legal@oculusit.com To be completed
Individuals should not include sensitive personal information, passwords, confidential client data, or regulated records in an unprotected email or web form unless specifically instructed through an approved secure channel.