Privacy Policy
Effective October 6, 2026
1. Who we are and what this policy covers
DropAudit (Lamill Web Systems, "DropAudit," "we," "us") provides compliance operations software to California-registered data brokers. This policy explains how we handle personal information in two different roles:
- As a business (controller) for information about visitors to dropaudit.co, prospects who contact us, and the business contact details of our customers' users. Sections 2–6 cover this.
- As a service provider (processor) for the consumer identifiers and records our customers upload to DropAudit. Our customer is the business responsible for that data; we process it only on their behalf. Section 7 covers this.
2. Information we collect as a business
- Information you give us: whatever you choose to include when you email us. Our contact form and penalty calculator both compose a message in your own email app and send nothing from this page; the exposure figure is calculated in your browser. If you become a customer, we also hold your account and billing contact details.
- Information collected automatically: when you visit dropaudit.co, our hosting provider (Cloudflare) processes standard request data such as IP address, browser user agent, and pages requested, and may set strictly necessary security cookies. Our pages load fonts from Google Fonts, which receives your IP address and browser details.
We do not use advertising cookies or cross-site tracking on dropaudit.co.
3. How we use it
- To respond to inquiries and send the summaries or reports you request
- To provide, support, secure, and bill for the DropAudit service
- To send service and product communications to customer contacts
- To protect our site and service and comply with legal obligations
4. Sale, sharing, and disclosure
We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose personal information only to service providers that help us operate (listed on our Security page), when required by law, or in connection with a merger, acquisition, or sale of assets.
5. Retention
We keep business-contact and inquiry information for as long as we need it to respond to you and to keep ordinary business records, or longer where required by law. You can ask us to delete it at any time by emailing hello@dropaudit.co. Defined retention periods will be published here before DropAudit begins processing customer data.
6. Your rights
California residents have the right to know what personal information we hold about them, to request deletion or correction, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising these rights. To make a request, email hello@dropaudit.co. We will verify your request before acting on it, and you may use an authorized agent.
7. Customer data we process as a service provider
DropAudit is pre-launch and is not yet processing customer data. This section describes how customer data will be handled and takes effect when the service launches.
Customers upload DROP deletion lists they have retrieved from DROP themselves, along with identifiers from their own systems, so that DropAudit can match, route, and document deletions. DropAudit never accesses DROP.
For this customer data:
- Our customer is the business that determines why and how the data is processed. We act as its service provider under our customer agreement. A data processing addendum will be available when DropAudit becomes generally available.
- We process customer data only to provide the DropAudit service to that customer. We do not sell it, share it for advertising, or combine it with data from other customers or sources.
- We engage subprocessors only under written obligations at least as protective as ours, and list them on our Security page.
- When a customer's contract ends, we delete customer data within the period set in the customer agreement, subject to legal retention requirements. That period will be published before DropAudit begins processing customer data.
If you are a consumer whose information may be held by a data broker that uses DropAudit, please submit your request through DROP or to that data broker directly. If you contact us, we will refer your request to the relevant customer where we can identify it.
8. Security
See our Security page for how we host and protect data.
9. Where data is processed
Personal information we handle as a business is processed in the United States. Because dropaudit.co is served by Cloudflare's global content-delivery network, standard request data — IP address, browser user agent, and the page requested — may be processed at edge locations outside the United States.
10. Children
DropAudit is a business service and is not directed to children under 16. We do not knowingly collect their personal information.
11. Changes and contact
We will post any changes to this policy on this page and update the effective date. Questions: hello@dropaudit.co