Legal

GDPR Notice

Last updated: July 4, 2026

1. Overview

This GDPR Notice explains how Regional Security Group ("we," "our," or "us") collects, uses, and protects personal data of individuals located in the European Economic Area (EEA) and the United Kingdom, in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR. It is provided in addition to our Privacy Policy; where this notice provides greater detail for EEA and UK residents, it governs.

2. Data Controller

Regional Security Group, 77 Monroe Center St NW, Suite 600, Grand Rapids, MI 49503, USA, is the data controller responsible for your personal data within the meaning of the GDPR. For questions about this notice or your data, contact us at office@regional-security.com or 1-866-485-8776.

We do not currently have a designated EU or UK Article 27 representative. Because our processing of EEA and UK personal data is occasional and does not involve large-scale or special-category data, no representative is required under Article 27. If this changes, we will update this notice.

3. Personal Data We Collect

We collect personal data only when you choose to provide it, including:

  • Contact & Quote Requests: Name, company, email, phone, site location, and message, submitted via our contact forms or chat lead form.
  • AI Feature Inputs: Text you enter into the Odin chat assistant or ODIN Search, along with the page you are viewing, as described in our AI Notice.
  • Technical Data: IP address, browser type, and usage data collected automatically when you visit our website.

We do not process special categories of personal data (Article 9) or criminal-conviction data (Article 10).

4. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Legitimate Interests (Art. 6(1)(f)): Responding to inquiries, providing service information, and operating and securing our website and AI features, where these interests are not overridden by your rights.
  • Contractual Necessity (Art. 6(1)(b)): Processing required to take steps before entering into a contract with you, or to perform a contract once formed.
  • Consent (Art. 6(1)(a)): Where you opt in to marketing communications or voluntarily submit information via our forms or AI features.
  • Legal Obligation (Art. 6(1)(c)): Where we must comply with a legal or regulatory requirement.

5. Purposes of Processing

We use your personal data to: respond to your inquiries and quote requests; provide information about our security services; operate, monitor, and improve our website and AI features; communicate with you where you have consented; and comply with legal obligations.

6. Data Retention

We retain personal data only as long as necessary for the purposes described above. Contact and quote-request data is retained while your inquiry is active and for a reasonable period thereafter for record-keeping, then deleted or anonymized. AI feature inputs are held for your browser session and deleted when you close the tab, except where you submit a quote request (the relevant context is then retained with that submission). Technical usage data is aggregated or deleted on a rolling basis.

7. International Data Transfers

Your personal data is processed in the United States. When we transfer personal data out of the EEA or UK, we rely on appropriate safeguards. In particular, we use Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum where applicable) with our service providers, supplemented by transfer impact assessments where required. Where a provider offers an approved certification such as the EU-U.S. Data Privacy Framework, we rely on that as well.

8. Your Rights Under the GDPR

EEA and UK residents have the following rights regarding their personal data:

  • Access: Confirmation of what data we hold and a copy of it.
  • Rectification: Correction of inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): Deletion of your data where there is no compelling reason to retain it.
  • Restriction: Temporary limitation of processing while a request is verified.
  • Data Portability: Receipt of your data in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.
  • Objection: Objection to processing based on legitimate interests or for direct marketing.
  • Withdrawal of Consent: Withdrawing consent at any time where processing relies on it, without affecting processing already carried out.
  • Automated Decision-Making: The right not to be subject to solely automated decisions with legal or similarly significant effects — we do not engage in such processing.

To exercise any right, contact us at office@regional-security.com. We will respond within one month, extendable by two further months where necessary for complex requests, and will inform you of any extension and the reason.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data, including access controls, encryption in transit, and limited need-to-know access. No method of transmission or storage is completely secure, but we strive to protect your data using commercially acceptable means.

10. Data Sharing & Processors

We share personal data only with service providers (processors) who act on our behalf under written agreements requiring GDPR-compliant handling — for example, hosting, email, analytics, and our AI model providers. We do not sell your personal data. We may disclose data to legal authorities where required by law.

11. Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority, or — if you are in the UK — with the Information Commissioner's Office (ICO) at ico.org.uk, if you believe our processing of your personal data infringes the GDPR. We encourage you to contact us first so we can address your concerns.

12. Changes to This Notice

We may update this GDPR Notice as our practices evolve or to reflect legal changes. The "Last updated" date above indicates the most recent revision. Continued use of our website or services after changes signifies acceptance of the updated notice.

13. Contact

For any questions about this GDPR Notice or your personal data, contact Regional Security Group at office@regional-security.com or 1-866-485-8776.

Regional Security Group · 77 Monroe Center St NW, Suite 600 · Grand Rapids, MI 49503