
We believe in Collecting & Protecting your Privacy but "NOT" Sharing or Selling It.
We Treat Your Data Like Ours.
THANK YOU
Thank you for visiting our website (www.LorenzoZesati.com). LorenzoZesati or LorenzoZesati.com ("we," "us," "our," or the "Company") is committed to treating the personal and corporate information of our Site users, customers, and vendors with respect and sensitivity.
We've updated our Privacy Policy and improved our privacy practices so we can better safeguard your data.
LorenzoZesati provides Business Technology Architecture solutions that involve comprehensive business architecture across 13 dimensions including AI automation, AI integration, smart websites, CRM systems, brand development, financial systems, and strategic architecture solutions aligned with our Business Technology Architect's Blueprint framework. We also provide business consulting, technology implementation, cybersecurity guidance, and software-integration services to clients around the world, with a specific focus on serving Married Christian Businessmen with Children (MCBC). Our goal is to support your Business Technology needs while respecting your privacy.
This Privacy Policy (together with our Terms of Service and any other policies referenced) identifies how we will collect and process any personally identifiable information, such as your name, email, address, phone number, SMS information, financial account information, business information, and data collected through AI interactions and automated systems, that we collect from you, or that you provide to us. It applies to our websites (including www.LorenzoZesati.com), remote-support services, marketing activities, email communications, SMS messaging, AI chatbot interactions, appointment booking systems, newsletter subscriptions, webinars, live events, online forms, and any other services linking to this Policy.
By using our services, submitting information through any format (e.g., website forms, email, telephone, SMS, fax, AI chat interactions, or in person), or continuing to visit our Site, you agree to the practices described here. If you do not agree, please do not use our services.
If you are a California resident, our privacy practices comply with the California Consumer Privacy Act of 2018 ("CCPA"), the California Privacy Rights Act ("CPRA"), and any regulations adopted by the California Privacy Protection Agency ("CPPA"), including regulations governing automated decision-making technology, risk assessments, and cybersecurity audits that became effective January 1, 2026. Any CCPA/CPRA-specific information is identified in this Policy.
If you are a resident of the European Economic Area ("EEA") or United Kingdom ("UK"), this Privacy Policy also outlines additional policies applicable to our collection and processing of your personal information under the General Data Protection Regulation ("GDPR").
If you are a resident of a U.S. state with a comprehensive consumer data privacy law, including but not limited to Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Kentucky, Rhode Island, Texas, Tennessee, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Delaware, Oregon, or Florida, this Privacy Policy describes how we comply with applicable rights and obligations under those laws. See Section 10 for details.
As our services evolve and we perceive the need or desirability of using your personal data collected in other ways, we may from time to time amend this Privacy Policy. The effective date appears at the beginning of this Privacy Policy. We encourage you to check our Site frequently to review the current Privacy Policy in effect and any changes that may have been made to it.
By providing your Personal Information to us in any format (e.g., via email, telephone, fax, SMS, online forms, AI interactions, or in person) and/or continuing to use any of our services or visiting our Site you accept and consent to the practices described in this Privacy Policy and Information Notice.
TABLE OF CONTENTS
Introduction
Information We Collect
How We Use Your Information
Legal Bases for Processing (GDPR and International Users)
Data Sharing and Onward Transfers
Our Storage of Your Personal Information
Cookies and Tracking Technologies
Your Rights and Choices
California Consumer Rights (CCPA/CPRA)
Multi-State Privacy Law Compliance
GDPR and UK GDPR Rights (EEA/UK Residents)
Children's Privacy (COPPA)
Third-Party Websites and Services
Data Security
International Transfers
Conditions of Use and Changes to Our Privacy Policy
Contact Us
INTRODUCTION
This Privacy Policy describes how the Company collects, uses, and shares information about visitors to our website at www.LorenzoZesati.com, attendees of our programs and webinars, individuals who contact us to purchase materials or request information, subscribers to our newsletters and SMS communications, users of our AI-powered tools and chatbots, those who book appointments through our systems, and other users of our services. The Website and our other programs and services are the "Services." This Policy describes how we obtain and use personal data (which can be used to identify a specific individual) and anonymous data (which cannot).
For purposes of this Policy, "Personal Information" means information (whether stored electronically or in paper-based filing systems) relating to a living individual who can be identified from that data (or from that data and other information in our possession). Personal Information comprises the categories of Personal Information defined by the CCPA, GDPR, and other applicable privacy laws.
AI-Powered Interactions Disclosure: Our website and services may include AI-powered chatbots, automated assistants, and other artificial intelligence tools that interact directly with you. When you engage with these AI systems, you are interacting with automated technology (not a human representative) unless otherwise stated. Information you provide during these interactions is collected and processed in accordance with this Privacy Policy. We use AI as an assistive tool to enhance your experience, and final business decisions and recommendations are reviewed and made by our human team.
Region-Specific Provisions: Certain provisions of this Policy, which are clearly labelled, apply only to users who are citizens or residents of particular regions (e.g., the EU, UK, California, or other U.S. states with comprehensive privacy laws). Otherwise, the Policy applies to all users of our Services, regardless of location.
Children: The Services of LorenzoZesati are not designed for nor are they intended to be used by children. We do not knowingly collect, use, or disclose Personal Information from children under 16 (or under 13 in the United States). If we learn that we have collected the Personal Information of a child without parental consent, we will take steps to delete the information as soon as possible. If you are under 16 (or under 13 in the United States), do not provide any Information about yourself to us, including your name, address, telephone number, or email address. If you become aware that a child has provided us with Personal Information without parental consent, contact us at the location identified below in the Contact Us section.
INFORMATION WE COLLECT
We collect information so that we can deliver services, maintain security, provide personalized experiences, and meet our legal obligations. The categories below apply whether you contact us through the website, speak with a support representative, use our remote-management tools, interact with our AI systems, subscribe to our newsletters, book appointments, submit forms, or engage with our SMS communications.
LorenzoZesati collects only that Personal Information that is relevant for the purposes for which the data is requested. We do not use your Personal Information in any way that is incompatible with the purposes for which it was collected or for which you have consented.
2.1. INFORMATION YOU PROVIDE VOLUNTARILY
Contact and Account Information: When you request information, sign up for a webinar, newsletter, or SMS communications, place an order, create an account, book an appointment, or engage with our AI systems, we may collect your name, company name, mailing address, email address, phone number, and similar identifiers. We ask only for the data needed to perform the requested service.
Payment and Billing Information: If you purchase services or products, we collect billing details (such as credit card number, expiration date, card security code, and billing address) to process your payment. We generally rely on our payment processors to handle this information and do not store full card numbers on our systems.
Business and Professional Information: When you engage our Business Technology Architecture services, we may collect information about your business including business name, industry, revenue information, number of employees, business challenges, technology systems in use, and other information necessary to provide consulting and implementation services.
Support and Troubleshooting Data: While providing remote support or technology implementation services, we may collect device identifiers, system logs, configuration details, user credentials (if you grant us access), and other technical data necessary to troubleshoot problems or implement solutions. We may remotely view or control your device only with your explicit permission, and may record session logs for quality, training, and security purposes. You should avoid sharing any sensitive information not relevant to the support issue.
Assessment and Self-Evaluation Data: When you participate in business assessments, self-assessment quizzes, strategic planning exercises, or utilize our Business Technology Architect's Blueprint framework, we collect the information you input and the results generated. This may include information about your business goals, challenges, aspirations, strategic priorities, and responses to assessment questions.
Communications and Marketing Preferences: If you subscribe to newsletters, SMS updates, or request marketing materials, we collect your email address, phone number, and other information you choose to provide. This includes preferences for how you wish to receive communications from us. You may opt out of marketing at any time (see Section 8).
SMS Information: When you opt-in to receive SMS messages from us, we collect your mobile phone number and carrier information. We use this information solely to send you the text messages you've requested, such as appointment reminders, event notifications, or marketing messages (if you've consented). You can opt-out at any time by texting STOP to any message you receive from us.
AI Interaction Data: When you interact with our AI-powered tools, chatbots, or automated systems on our website or through other channels, we may collect the content of your conversations, questions asked, information provided, and preferences expressed. This data helps us provide personalized responses, improve our AI systems, and better understand client needs. Please note that our AI systems are designed to assist and enhance your experience. They do not make autonomous decisions that produce legal or similarly significant effects on you without human review.
Appointment and Calendar Information: When you book appointments through our scheduling systems, we collect information about your preferred dates and times, time zone, appointment purpose, and any specific topics or questions you wish to discuss.
Event and Webinar Information: When you register for or attend our webinars, workshops, live events, or BreakthruPreneurs mastermind meetings, we collect registration information, attendance records, and may collect information about your participation and engagement.
Employment Information: For those considering careers with LorenzoZesati, we collect professional data and education information such as resume or C.V., salary history, education history, citizenship information, position sought, and other relevant employment information. Additional Personal Information may be collected during the employment process, as set forth in our Employee Privacy Policy.
2.2. INFORMATION COLLECTED AUTOMATICALLY
Usage and Device Data: Our servers automatically record information such as your IP address, browser type and version, operating system, device type, referring URLs, pages visited, time zone setting, browser plug-in types and versions, and how you interact with our site and services. This information includes:
The Internet protocol (IP) address used to connect your computer to the Internet Referring website address Browser type and version Time zone setting Browser plug-in types and versions Operating system and platform Information about your visit, including the full Uniform Resource Locators (URL) Clickstream to, through and from our site (including date and time) Pages on our Site you viewed Page response times Download errors Duration of page visits Page interaction information (such as scrolling, clicks, and mouse-overs) Methods used to browse away from the page Any phone number used to call our customer service number
This helps us maintain security, detect fraud, improve our services, and provide you with better user experience. We do not link usage data to your identity unless needed for security or support purposes.
Cookies and Tracking Technologies: We use cookies and similar technologies to remember preferences, measure usage, personalize content, and provide targeted advertising. Some cookies are necessary for site functionality; others are optional and may be used for analytics or targeted advertising. You can control cookies via your browser settings. Disabling cookies may limit certain features (see Section 7).
Remote Monitoring Data: If you use our remote monitoring and management (RMM) tools (e.g., ConnectWise, Datto, or other technology management platforms), we may collect device performance metrics, installed software versions, security status, system health indicators, and other telemetry needed to ensure your systems are up to date, secure, and functioning optimally. We configure our RMM tools to capture only the data necessary for maintenance and security.
Analytics Data: We use analytics services such as Google Analytics to collect aggregated information on how our services are used and help us improve performance. This includes tracking website traffic, user behavior patterns, conversion rates, and other metrics that help us optimize your experience.
2.3 INFORMATION FROM THIRD PARTIES
We may obtain information from business partners (such as payment processors, marketing platforms, CRM systems), analytics providers, social media platforms, or integrated software platforms that you authorize (e.g., project-management tools, email marketing services, calendar applications, or other business tools). We use this data consistently with this Policy and any restrictions imposed by the original source.
We work closely with third parties, including business partners, promoters, affiliates, sub-contractors in technical services, payment and delivery services, advertising networks, marketing analytics providers, and search information providers. We will notify you when we receive information about you from them and the purposes for which we intend to use that information.
2.4. SPECIAL CATEGORIES OF DATA
We do not intentionally collect sensitive personal data (such as health information, race/ethnicity, religious beliefs, biometric data, or genetic information) unless you choose to provide it, or it is required for service delivery, employment, or legal compliance. If we must process sensitive data, we will request your explicit consent or rely on another lawful basis permitted by law (see Section 4).
For purposes of the CCPA, Personal Information includes the following categories:
Identifiers: Name, address, email, phone, social security number, driver's license, federal tax ID number, or other relevant identifiers
Other Data (California Civil Code § 1798.80(e)): Financial information (bank account number, credit card number, debit card number), medical information, health insurance information, insurance policy number
Protected Classes: Race, gender, age (40 years or older), ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information
Commercial Information: Records of personal property, products or services purchased, obtained, or considered, purchasing or consuming histories or tendencies
Biometric Information: We do not collect or receive biometric information such as fingerprints, retina scans, or face prints
Internet Activity: Browsing history, search history, IP address, website interactions, information on interaction with websites, applications, or advertisements
Geolocation Data: Physical location information
Sensory Data: We do not collect audio, electronic, visual, thermal, or olfactory information unless specifically required for service delivery and with your explicit consent
Professional Data: CV, resume, employment history, current employment information
Education Data: Educational background, grades, scores, degrees obtained
Inferences: Preferences, characteristics, psychological traits, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes drawn from the above categories
The examples given above are not meant to provide an exhaustive list, but are examples of the kinds of data included in each category.
HOW WE USE YOUR INFORMATION
We process personal data for the following purposes and lawful bases:
Provide and Improve Our Services: We use your information to deliver Business Technology Architecture services, business consulting, technology implementation, cybersecurity guidance, integration services, AI-powered solutions, appointment scheduling, event registration, newsletter delivery, SMS communications, and other services you request from us.
We use your information to:
Process payments and manage accounts Schedule and manage appointments Communicate about your requests and service delivery Provide customer support and respond to inquiries Deliver newsletters, webinars, and educational content Administer self-assessments and business evaluations Implement and support technology solutions Provide AI-powered recommendations and assistance Improve our offerings and develop new services Present our Platform and content to you in the most effective manner Assess your suitability for participation in our programs, meetings, live events, and webinars Determine additional materials, services, or events to recommend to you.
These activities are necessary to perform our contract with you or to pursue our legitimate interests in running and improving our business.
Security and Fraud Prevention: We use data to authenticate users, protect against unauthorized access, secure our infrastructure, detect and respond to cyber-threats, prevent fraud, and comply with industry standards (including NIST recommendations). This includes the use of multi-factor authentication for remote sessions, encryption of stored data, monitoring for suspicious activity, and maintaining audit logs.
Compliance with Law: We may process your data to comply with laws, regulations, court orders, or legal requests (e.g., consumer privacy laws, tax obligations, accounting requirements, regulatory reporting). When legally required, we will disclose information to law-enforcement authorities, regulators, or other governmental entities.
Marketing and Communications: With your consent or where allowed by the law, we may send you promotional emails, SMS messages, newsletters, or invitations to webinars and events. We may also tailor marketing based on your interactions with us, business needs, industry, and expressed interests. You can opt out of marketing at any time (see Section 8).
Analytics and Research: We analyze usage patterns to understand how visitors interact with our services and to improve our design, content, and offerings. We conduct research to develop new frameworks, refine our Business Technology Architect's Blueprint, and create educational materials. Aggregated or de-identified data may be used for statistical or research purposes.
Artificial Intelligence and Automation: We may use AI-powered tools to assist with diagnostics, provide personalized recommendations, automate routine tasks, detect security threats, improve user experience, and develop better solutions for our clients. Personal data used for AI training is limited to what is needed for these purposes. We do not use AI to make decisions that have legal or similarly significant effects without human review. When required by law (e.g., certain U.S. states including California and Colorado), you can opt out of automated decision-making (see Section 8). We are committed to using AI responsibly and in compliance with applicable federal and state AI governance requirements, including the California CCPA regulations on automated decision-making technology (effective January 1, 2026), the Colorado Artificial Intelligence Act (effective June 30, 2026), and the Texas Responsible AI Governance Act (effective January 1, 2026).
Training and Quality Assurance: We may use information for training purposes, quality assurance, and to record details about the products and services you order from us to ensure we're delivering excellent service and continuously improving.
Credit Reference and Risk Assessment: We may make inquiries about you for credit reference purposes when necessary to assess financial risks in our business relationships.
Data Analysis: We perform data analyses (including anonymization and aggregation of Personal Information) to understand trends, improve services, and make data-driven business decisions.
LEGAL BASES FOR PROCESSING (GDPR AND INTERNATIONAL USERS)
For residents of the European Economic Area (EEA), United Kingdom, or other jurisdictions requiring a lawful basis, we rely on one or more of the following bases when we process your data:
Contractual Necessity: We process data to perform our contract with you (e.g., providing Business Technology Architecture services, consulting, technology implementation, delivering purchased products) or to take steps at your request before entering a contract.
Legitimate Interests: We have a legitimate interest in operating, securing, and improving our services, communicating with clients, preventing fraud, conducting business development, providing direct marketing of products and services that may interest you, analyzing usage patterns, developing new offerings, maintaining business relationships, and managing our business operations, provided that such interests are not overridden by your rights. This includes legitimate interests of our third-party partners, promoters, affiliates, distributors, suppliers, vendors, and subcontractors.
Consent: We rely on your consent to send marketing communications, deploy non-essential cookies, process sensitive data (if any), conduct certain AI or profiling activities, and for other processing where consent is required by law. You may withdraw your consent at any time without affecting the lawfulness of prior processing.
Legal Obligation: We may process data to comply with our legal obligations (such as tax laws, accounting requirements, regulatory reporting, data retention obligations) or to protect vital interests (e.g., recording necessary information for security purposes, responding to legal requests).
Performance of a Task in the "Public" Interest: In limited circumstances, we may process data to perform a task carried out in the public interest.
In accordance with the purposes for which we collect and use your Personal Information, as set out above, the legal basis for processing your Personal Information will typically be one of the bases described in this section.
DATA SHARING AND ONWARD TRANSFERS
We do not sell personal data. LorenzoZesati does not sell your Personal Information to any third parties.
We may share your information in the following limited circumstances:
5.1 SERVICE PROVIDERS AND CONTRACTORS
To provide the Services, we sometimes disclose Personal Information to service providers for business purposes. We engage trusted third parties, such as hosting providers, cloud storage services (e.g., Amazon Web Services), payment processors, identity verification services, email marketing platforms, SMS delivery services, calendar and scheduling platforms, CRM systems, remote-support platforms (e.g., Anydesk, TeamViewer, ConnectWise, Datto), analytics providers (e.g., Google Analytics), AI service providers, webinar platforms, and other technology vendors, to perform functions on our behalf.
These service providers are contractually obligated to comply with all applicable laws (e.g., the CCPA, GDPR), and all such third parties use your Personal Information only on behalf of LorenzoZesati and under our instructions. They are contractually required to safeguard your data, act only on our instructions, not use your data for their own purposes, and implement appropriate security measures. We take reasonable steps to ensure these third parties use your Personal Information only for the purposes for which they have been engaged by us, that they do not share or sell your Personal Information to anyone else, and that they maintain adequate security.
Under the California Consumer Privacy Rights Act (CPRA), disclosure to service providers for a business purpose is not considered a "sale" or "share."
By enjoying our Services and sharing your Personal Information, you agree that we have the right to share the categories of Personal Information we collect with our service providers for the following business purposes:
Sales and Transaction Processing: For fulfilling requests to purchase goods and services from our Site or at our events, processing payments, managing orders Service Delivery: For delivering Business Technology Architecture services, consulting, technology implementation, remote support, and other professional services Communication: For sending emails, SMS messages, newsletters, appointment reminders, service updates Targeted Advertising: To provide advertising of our programs and services on other Sites and platforms Marketing: For direct marketing of goods and services offered by LorenzoZesati and our affiliates that you may be interested in Self-Assessment Testing: For administering and providing self-assessment testing services, business evaluations, and strategic planning tools Cloud Services: For provision of cloud storage, computing, and infrastructure services Contractual Performance: For the performance of any contract, we enter with you, or they enter with you on behalf of LorenzoZesati Web Analytics: Analytics and search engine service providers that assist us in the improvement and optimization of our site AI Services: For providing AI-powered recommendations, chatbot functionality, automated responses, and intelligent assistance Calendar and Scheduling: For managing appointment bookings, calendar integrations, and scheduling coordination Event Management: For managing webinar registrations, event attendance, and participant communications
5.2. THIRD-PARTY INTEGRATIONS
If you instruct us to integrate your systems with other software (e.g., CRM, project management, accounting, calendar applications, email platforms, ticketing systems, or security tools), we will share only the data necessary to perform that integration. You are responsible for reviewing the privacy practices of any third-party platforms you connect to our services.
5.3. BUSINESS PARTNERS
We may share information with channel partners, resellers, or affiliates who co-market or co-deliver our services, provided they agree to comply with relevant privacy laws and use the information solely for the agreed purpose.
5.4. LEGAL OBLIGATIONS AND PROTECTION OF RIGHTS
We may disclose data where required by law or court order, in response to lawful requests by public authorities (including meeting national security or law enforcement requirements), or to protect our rights, property, or safety and those of our clients or others (e.g., to investigate fraud, cyber-incidents, security breaches, or potential violations of our Terms). We will notify you of such requests when legally permissible.
5.5. CORPORATE TRANSACTIONS
If we merge, sell, or transfer our assets, or undergo any business reorganization, restructuring, dissolution, or other corporate transactions, your data may be transferred to the acquiring entity as part of the purchase, transfer, or sale of services or assets, subject to this Policy and applicable laws. We may also disclose your Personal Information to prospective buyers or sellers during due diligence for such transactions.
5.6. WITH YOUR CONSENT
For any other purpose disclosed by us when you provide the Information, or with your consent for specific purposes.
5.7. AGGREGATED OR DE-IDENTIFIED DATA
We may use and disclose Non-Personal Information (aggregated, anonymized, or de-identified data that cannot be used to identify you) about our users without restriction for research, statistical analysis, marketing, or any other purpose.
5.8. DO NOT SELL OR SHARE MY DATA (CALIFORNIA / CPRA)
We do not sell personal data in exchange for money. CPRA also covers "sharing" personal data for targeted advertising. We do not share data for cross-context behavioral advertising outside the context of our own marketing. If this changes, we will provide a clear "Do Not Sell or Share My Personal Information" link allowing California residents to opt out, and we will honor Global Privacy Control or other legally recognized opt-out signals. We will maintain opt-out preferences for at least twelve months as required by California law.
We only use the data collected to understand clients' needs regarding our website products, programs, and services, and to deliver and improve those services. To provide the Products, Programs, and Services, we sometimes disclose personal data to service providers for business purposes as described in this section.
No mobile information is shared with third parties/affiliates for marketing or promotional purposes.
All other categories exclude text messaging originator opt-in data and consent. This information is not shared with any third parties.
5.9. INTERNATIONAL TRANSFERS
Our servers and many of our service providers are located in the United States. If you are located outside the U.S., your data may be transferred to and processed in the United States or other countries with different privacy laws.
Where required by the GDPR or UK GDPR, we implement appropriate safeguards to ensure adequate protection, such as:
Using Standard Contractual Clauses approved by the European Commission Relying on adequacy decisions where applicable Implementing additional technical and organizational measures to protect your data
If we participate in the EU-U.S. Data Privacy Framework or Swiss-U.S. Data Privacy Framework, we will adhere to their principles, including purpose limitation, choice, data accuracy, security, transparency, individual rights, and restrictions on onward transfers.
By submitting your Personal Information, you agree to this transfer, storing, and processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
OUR STORAGE OF YOUR PERSONAL INFORMATION
6.1. DATA SECURITY
LorenzoZesati uses reasonable and appropriate administrative, technical, and physical measures to protect your Personal Information from loss, misuse, and unauthorized access, disclosure, alteration, and destruction, taking into due account the risks involved in the processing undertaken and the nature of the Personal Information we collect.
Unfortunately, the internet is not completely secure. Although we are working to protect your Information, we cannot guarantee the security of your Information either in transmission or when stored. We are not responsible for circumvention of any privacy settings or security measures contained on the Platform.
We have implemented measures designed to protect your Information from accidental loss and from unauthorized access, use, alteration, and disclosure. Protecting our clients' information is integral to our mission. Measures include:
Encrypted Communications: Remote-support sessions and data transmissions use peer-to-peer or server-brokered tunnels with TLS/SSL (256-bit or higher encryption) to protect data in transit. All sensitive communications are encrypted.
Multi-Factor Authentication and Session Management: We require multi-factor authentication for remote access and sensitive system accounts, as recommended by NIST. Sessions time out after periods of inactivity, and credentials are unique to our remote-access environment.
Device Health Checks: We assess client devices for up-to-date operating systems, antivirus signatures, and other security baselines before allowing remote connections. Access may be denied to out-of-compliance devices.
Data Encryption at Rest: We use full-disk and file-level encryption on our systems and encrypt sensitive backups, as recommended by NIST. Sensitive paper records are stored in secure facilities or are digitized and securely destroyed when no longer needed.
Access Controls and Logging: Access to personal data is restricted to authorized personnel with a legitimate business need. We maintain audit logs of support sessions, server access, and administrative actions and review them regularly for suspicious activity.
Employee Training: All staff receive privacy and security training, including phishing awareness, secure remote-support practices, data handling procedures, and compliance requirements.
Incident Response and Breach Notification: We maintain an incident-response plan based on FTC guidance and industry best practices that includes identifying and containing security events, assembling a response team, fixing vulnerabilities, and notifying affected individuals and regulators as required by law.
Regular Security Assessments: We conduct regular security reviews, vulnerability assessments, and updates to our security practices to address emerging threats.
6.2. DATA RETENTION
We will keep your personal data for as long as we need it, or as otherwise prescribed by law, for the purposes set out above. This period will vary depending on your relationship with us. We may also keep a record of all correspondence related to you, such as email communications, purchases, returns, and complaints about our Products, Programs, and Services for as long as is necessary to help and protect us from a legal claim.
We retain personal data only as long as necessary for the purposes described in this Policy or as required by law. In general:
Account and Contact Data: Retained for the duration of our relationship and a reasonable period thereafter responding to requests, maintaining business records, and satisfying legal obligations. If you close your account or request deletion, we delete or anonymize your data unless required to retain it for legal reasons (such as ongoing contractual obligations, pending transactions, or legal claims).
IT Support Logs and Remote Sessions: Retained for up to 12 months for troubleshooting, quality control, security audits, and compliance. Logs related to security incidents may be retained longer if needed for investigations or legal proceedings.
Communication Records: Email correspondence, SMS messages, chat transcripts, and other communications are retained for the duration of our relationship and for a reasonable period thereafter to maintain service records and respond to inquiries.
Billing and Financial Records: Retained for at least seven years to comply with accounting, tax requirements, and financial regulations.
Marketing Preferences: Remain active until you opt out, after which we keep a record of your "opt-out" request to ensure compliance and prevent future marketing communications.
Assessment and Evaluation Data: Results from business assessments, self-evaluations, and strategic planning exercises are retained for as long as they are relevant to providing ongoing services and recommendations, unless you request deletion.
AI Interaction Data: Conversations and interactions with our AI systems may be retained to improve service quality, train AI models, and provide personalized experiences, unless you request deletion or as required by law.
When data is no longer required, we securely delete or anonymize it according to industry best practices. We will take appropriate measures to properly destroy your personal data when we reach a point where your personal data is no longer needed.
In some circumstances, you can ask us to delete your data: see your legal rights below for further information. In some circumstances, we will anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we process your Personal Information, and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements.
In some cases, there is a legal requirement to keep Personal Information for a minimum period of time. Except in those circumstances, we do not keep your Personal Information for any longer than is necessary for the purposes for which the Personal Information was collected or for which it is to be further processed.
6.3 UNSUBSCRIBING FROM COMMUNICATIONS
You may unsubscribe from any of our online email updates and marketing by following the unsubscribe instructions in the body of any email message we have sent to you. For SMS messages, you can reply STOP to any text message to unsubscribe.
We will take commercially reasonable steps to implement your unsubscribe requests promptly, but you may still receive promotional information from us by mail for up to 60 days, and up to 10 days for email. You may also continue to receive information from those third parties to whom we have previously disclosed your Personal Information.
Please note that when you unsubscribe from our marketing communications, we will keep a record of your email address and/or phone number to ensure we do not send you marketing emails or SMS messages in future. You will continue to receive transactional emails and messages related to services you have purchased or requested.
COOKIES AND TRACKING TECHNOLOGIES
We use cookies, web beacons, and similar technologies to enhance your experience and analyze the use of our services, collect data to deliver a better experience while you are on our website, personalize your experience, target advertising, improve the performance of our website, and provide you with better user experience.
7.1. WHAT ARE COOKIES?
Cookies are small text files that a web server (such as LorenzoZesati or our chosen web hosting company server) place on a user's computer or device. When accessing a cookie, our server reads a number associated with a browser but is unable to determine any personal data about a user. With that number, our web server can tailor its content to the needs of the specific browser, and we can optimize the Platform for your use.
Cookies are batch files with small amounts of data that a website stores on your computer or mobile device so that certain data about your visit and web-browsing preferences will be recognized upon your return. Cookies serve functions like "remembering" login names and passwords or saving shopping cart contents for future purchases on our website.
7.2. CATEGORIES OF COOKIES WE USE
Essential Cookies: Help operate the site and cannot be disabled in our systems. These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in, or filling in forms.
Analytics Cookies: Collect aggregated information on how our services are used and help us improve performance. We use providers such as Google Analytics (subject to their own privacy policies). These cookies help us understand visitor behavior, identify popular content, and improve our website design and functionality.
Functional Cookies: Remember choices you make (e.g., language, region, user preferences) and provide enhanced features. These cookies enable the website to provide enhanced functionality and personalization.
Advertising Cookies: May be set by our marketing partners to show you relevant ads on other websites and platforms. We obtain your consent where required. These cookies may be used to build a profile of your interests and show you relevant advertisements on other sites.
7.3 MANAGING COOKIES
You can control cookies through your browser settings. For example, most browsers allow you to delete or block cookies; some allow you to set preferences for certain websites. If you disable cookies, parts of our site may not function properly, and you may not be able to use all features of our services.
We recommend you review our complete Cookies Policy for detailed information about the specific cookies we use and how to manage them.
7.4. GOOGLE ANALYTICS ADVERTISING FEATURES
We may have the following Google Analytics Advertising Features implemented: Demographics and Interest reporting, Remarketing, GDN Impression Reporting, and DoubleClick Campaign Manager. These features collect data using Google advertising cookies and anonymous identifiers.
LorenzoZesati and third-party vendors use these first-party cookies to assess the success of online marketing campaigns, inform future campaigns, and improve usability on the Platform. To learn how to opt-out of the Google Analytics Advertising Features we use, please visit Google Analytics' currently available opt-outs for the web at https://tools.google.com/dlpage/gaoptout.
7.5. DO NOT TRACK
Some browsers incorporate a "Do Not Track" ("DNT") feature that, when turned on, signals to websites and online services that you do not want to be tracked. Currently, the Platform does not respond to DNT signals. However, we provide you with choices about tracking and advertising through the methods described in this Privacy Policy. We do honor Global Privacy Control (GPC) signals as required by applicable state privacy laws, including the CCPA/CPRA.
YOUR RIGHTS AND CHOICES
Your rights depend on your place of residence. This section summarizes the key rights provided by U.S. and international laws. We will not discriminate against you for exercising these rights.
Subject to certain exceptions and applicable law, you may have the right to:
Access: Request that we disclose what personal information we have collected, used, disclosed about you, and request a copy of the Personal Information we hold about you Correct: Request that any inaccurate or incomplete Personal Information be corrected or supplemented Delete: Request that we delete the personal data we have collected, subject to certain exceptions (e.g., completing transactions, detecting security incidents, exercising free speech, complying with legal obligations) Opt-Out: Opt-out of the sale or sharing of personal data for targeted advertising, and in some cases, opt out of profiling for decisions producing legal or significant effects Opt-Out of Automated Decision-Making: Where we use automated decision-making technology that makes or substantially contributes to significant decisions affecting you, you may have the right to opt out of such processing or request human review of the decision.
Portability: Receive your data in a portable and usable format (where technically feasible) Restrict Processing: Ask us not to process your Personal Information for a particular purpose, including for marketing Object: Object to processing based on legitimate interests or direct marketing Non-Discrimination: We will not discriminate against you for exercising your privacy rights Withdraw Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing
All these rights are subject to certain conditions and exemptions. For example, we will not be obligated to erase your Personal Information if we need to retain it to complete a transaction, protect ourselves in the event of a legal claim, comply with legal obligations, or for other legally permitted reasons.
8.1. EXERCISING YOUR RIGHTS
To exercise any of these rights, please submit a verifiable request by:
Email: [email protected] Phone: 602-456-7632 (call or text) Mail: PO Box 44, Gilbert, AZ 85299
When contacting us, please provide enough information to identify yourself, describe the nature of your request, and specify which rights you wish to exercise.
We may require proof of your identity to process your request. If you use an authorized agent to submit a request on your behalf, we may require evidence of their authority.
We aim to respond within 45 days of receiving your request and may extend the period once by an additional 45 days when reasonably necessary (we will tell you why and how long). If we deny your request, we will provide reasons for the denial and information about your appeal rights.
8.2. MARKETING COMMUNICATIONS
If you no longer wish to receive marketing or promotional communications from us, you can:
Click on the "unsubscribe link" provided in marketing emails Reply STOP to any SMS message Email us at [email protected] Login to your account and change the applicable communication settings
If you opt out of receiving marketing/promotional emails or SMS messages, we may still send you non-promotional communications, such as emails or messages about your accounts, purchases, service updates, appointment confirmations, or our ongoing business relations.
CALIFORNIA CONSUMER RIGHTS (CCPA/CPRA)
9.1. OVERVIEW OF CALIFORNIA RIGHTS
Under California law, California residents have certain rights regarding their Personal Information, including the rights listed below. California law requires us to identify these rights to you. Subject to some exceptions, California residents have:
Right to Know: The right to know the categories of Personal Information that we have collected, the sources from which we obtained the Information, the business purposes for sharing Personal Information, the categories of third parties with whom we have shared Personal Information, and the right to access the specific pieces of Personal Information we have collected Right to Delete: The right to request the deletion of your Information, subject to certain exceptions Right to Correct: The right to correct your Personal Information Right to Opt-Out: The right to opt-out of the sale of your Personal Information, as a "sale" is defined under the California Consumer Privacy Act (Note that LorenzoZesati does not sell your Personal Information), and in some cases the sharing of your Personal Information Right to Restrict: The right to restrict the processing of sensitive Personal Information, such as social security numbers, passport numbers, driver's license numbers, precise geolocation, racial or ethnic origin, religious beliefs, and financial account and payment card information Right to Non-Discrimination: The right to not be discriminated against for exercising any of these rights
9.2. AUTOMATED DECISION-MAKING TECHNOLOGY (ADMT)
Effective January 1, 2026, updated CCPA regulations established new requirements for businesses that use automated decision-making technology (ADMT). ADMT is defined as technology that processes personal information and uses computation to replace or substantially replace human decision-making.
LorenzoZesati may use AI-powered tools and automated systems as part of our service delivery, including AI chatbots on our website, automated scheduling and communication systems, AI-assisted business analysis and recommendations, and automated marketing personalization.
We do not use ADMT to make "significant decisions" (as defined by the CCPA regulations) concerning California consumers, including decisions related to financial services, housing, education, employment, or healthcare, without meaningful human review and oversight.
If we expand our use of ADMT in ways that trigger the CCPA's ADMT requirements, we will provide you with a Pre-use Notice before using such technology, the ability to opt out of ADMT processing, access to information about how ADMT is used with respect to you, and the right to appeal any ADMT-based outcome affecting you.
To learn more about our use of automated systems or to exercise your rights related to ADMT, please contact us at [email protected].
9.3. RISK ASSESSMENTS AND CYBERSECURITY AUDITS
The updated CCPA regulations also require certain businesses to conduct privacy risk assessments for high-risk processing activities and to complete annual cybersecurity audits. LorenzoZesati is committed to conducting appropriate risk assessments for any processing activities that present a significant risk to consumer privacy, and to maintaining a robust cybersecurity program that protects your Personal Information. Compliance deadlines for these requirements are phased based on business size, and we will meet all applicable deadlines as they apply to our operations.
9.4. CATEGORIES OF PERSONAL INFORMATION COLLECTED
We may collect the following categories of Personal Information about you:
Identifiers: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver's license number, passport number, or other similar identifiers.
Personal Information Categories Listed in California Customer Records Statute (Cal. Civ. Code § 1798.80(e)): Name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
Protected Classification Characteristics Under California or Federal Law: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Commercial Information: Products or services purchased, obtained, or considered, records of personal property, or other purchasing or consuming histories or tendencies.
Internet or Other Similar Network Activity: Information on a consumer's interaction with a website, application, or advertisement, browsing history, search history, and information regarding interaction with an internet website, application, or advertisement.
Geolocation Data: Physical location information.
Inferences Drawn From Other Personal Information: Profiles reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Additional information about the categories of Personal Information collected and the categories of sources from which Personal Information is collected is in Section 2 of this Privacy Notice. The purpose for collecting the Personal Information listed above is in Section 3 of this Privacy Notice. The third parties with which LorenzoZesati may share the Personal Information listed above is in Section 5 of this Privacy Notice.
9.5. SUBMITTING A CCPA DATA REQUEST
To exercise your rights under the CCPA, please submit a verifiable request by:
Email: [email protected] Phone: 602-456-7632 (call or text)
Only you, or someone legally authorized to act on your behalf may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child.
Verification Process: We are required to verify the identity of the individual requesting access to a consumer's data or requesting deletion of a consumer's data. To verify your identity, you must provide some form of Two-Factor Authentication:
User ID and password for our website; or If we have previously received your email address, we may verify that you have access to that email address by sending a verification code; or If we have received your mobile number, we may text you with a verification code.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to an additional 45 days), we will inform you of the reason and extension period. If we deny your request, we will provide reasons for the denial and information about your appeal rights.
9.6. AUTHORIZED AGENT
California consumers may designate an authorized agent to exercise a CCPA right on the consumer's behalf. If you utilize an authorized agent to exercise a CCPA right, the following proof that the agent has been authorized to act on your behalf will need to be provided:
Proof of written permission by you for the authorized agent to act on your behalf and separate verification of your identity; or Proof that the authorized agent holds the power of attorney to act on your behalf pursuant to California Probate Code §§ 4000-4465.
9.7. NOTICE OF FINANCIAL INCENTIVE
LorenzoZesati may offer certain programs, promotions, or benefits that involve the collection of personal information. Participation in these programs is voluntary, and you may opt-in or opt-out at any time. If we offer a financial incentive program, we will provide a separate notice describing the material terms of the program, including how to opt-in and opt-out.
9.8. CALIFORNIA "SHINE THE LIGHT" LAW
California's "Shine the Light" law (Civil Code Section § 1798.83) permits users of the Platform that are California residents to request certain information regarding LorenzoZesati.com's disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please contact us at [email protected].
9.9. NON-DISCRIMINATION
LorenzoZesati will not discriminate against you for exercising any of your CCPA rights. We will not:
Deny goods or services to you Charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties Provide a different level or quality of goods or services Suggest that you receive a different price or rate for goods or services or a different level or quality of goods or services
However, we may charge different prices or rates or provide a different level or quality of goods or services, if that difference is reasonably related to the value provided to our business by your data.
MULTI-STATE PRIVACY LAW COMPLIANCE:
10.1. OVERVIEW OF U.S. STATE PRIVACY LAWS
As of the effective date of this Privacy Policy, nineteen (19) U.S. states have enacted comprehensive consumer data privacy laws. Because LorenzoZesati provides services to clients nationwide and our website is accessible from any state, we are committed to complying with all applicable state privacy laws.
The following states currently have comprehensive consumer privacy laws in effect:
California (CCPA/CPRA, effective 2020/2023, see Section 9 for details) Virginia (VCDPA, effective January 1, 2023) Colorado (CPA, effective July 1, 2023) Connecticut (CTDPA, effective July 1, 2023) Utah (UCPA, effective December 31, 2023) Oregon (OCPA, effective July 1, 2024) Texas (TDPSA, effective July 1, 2024) Montana (MCDPA, effective October 1, 2024) Iowa (ICDPA, effective January 1, 2025) Delaware (DPDPA, effective January 1, 2025) Nebraska (NEDPA, effective January 1, 2025) New Hampshire (NHCDPA, effective January 1, 2025) New Jersey (NJDPA, effective January 15, 2025) Tennessee (TIPA, effective July 1, 2025) Minnesota (MCDPA, effective July 31, 2025) Maryland (MODPA, effective October 1, 2025) Indiana (ICDPA, effective January 1, 2026) Kentucky (KCDPA, effective January 1, 2026) Rhode Island (RIDTPPA, effective January 1, 2026)
Additional states may enact comprehensive privacy laws after the effective date of this Policy. We monitor legislative developments and will update this Policy as needed to reflect new requirements.
10.2. YOUR RIGHTS UNDER STATE PRIVACY LAWS
Residents of the states listed above generally have rights similar to those described in Section 8 (Your Rights and Choices) and Section 9 (California Consumer Rights). While the specific rights and requirements vary by state, common rights include:
Access and Obtain a Copy: The right to access and obtain a copy of your personal data we have collected Correct Inaccuracies: The right to correct inaccurate personal information Delete Data: The right to request deletion of personal data, subject to certain exceptions Portability: The right to receive your data in a portable and usable format (where technically feasible) Opt-Out of Sale: The right to opt out of the sale of personal data (Note: LorenzoZesati does not sell your Personal Information) Opt-Out of Targeted Advertising: The right to opt out of targeted advertising Opt-Out of Profiling: The right to opt out of profiling for decisions producing legal or similarly significant effects Appeal: The right to appeal if we refuse to act on your request, and the right to contact your state's attorney general if your appeal is denied
10.3. EXERCISING YOUR STATE PRIVACY RIGHTS
To exercise any of the rights described above, regardless of your state of residence, please contact us using the methods described in Section 8.1 (Exercising Your Rights) or Section 17 (Contact Us).
We aim to respond to all state privacy law requests within the timeframes required by applicable law (generally 45 days, extendable by an additional 45 days with notice). If we deny your request, we will provide reasons for the denial and information about how to appeal.
10.4. STATE-SPECIFIC AI AND AUTOMATED DECISION-MAKING REQUIREMENTS
Several states have enacted or are implementing requirements related to artificial intelligence and automated decision-making, including:
Colorado Artificial Intelligence Act (effective June 30, 2026): Requires deployers of high-risk AI systems to use reasonable care to protect consumers from algorithmic discrimination. LorenzoZesati uses AI tools as assistive technology in our consulting services. We do not use AI to make high-risk consequential decisions (such as employment, lending, housing, or healthcare decisions) about consumers without human oversight.
Texas Responsible AI Governance Act (effective January 1, 2026): Prohibits certain harmful uses of artificial intelligence and requires documentation of AI risk governance. LorenzoZesati complies with applicable requirements under this Act.
As additional state AI regulations take effect, we will update our practices and this Policy accordingly.
10.5. NON-DISCRIMINATION
LorenzoZesati will not discriminate against any consumer for exercising their privacy rights under any applicable state law. We will not deny services, charge different prices, or provide a different level of service quality based on your exercise of privacy rights.
GDPR AND UK GDPR RIGHTS (EEA/UK RESIDENTS)
In addition to the other policies described in this Privacy Policy, residents of the European Union, European Economic Area (EEA), or United Kingdom (UK) are afforded the following additional rights and protections as required by the General Data Protection Regulation ("GDPR") and UK GDPR. The additional rights and protections set forth in this section of this Policy apply only to residents of the European Union, EEA, or UK.
11.1. GDPR DEFINITIONS
The following additional definitions apply to this section of the Privacy Policy:
Controller: Means LorenzoZesati, which is the organization that determines the purposes for which, and the manner in which, any Personal Information is processed and used in its business.
Processor: Means any person or entity processing Personal Information on behalf of the Controller.
Person: Means a natural person, corporation, association, organization, partnership, or other legal entity.
Processing: Is any activity that involves use of Personal Information. It includes, without limitation, obtaining, recording, or holding the Personal Information, or carrying out any operation or set of operations on the Personal Information including organizing, amending, retrieving, using, disclosing, erasing, or destroying it. Processing also includes transferring Personal Information to third parties.
11.2. CONTROLLER OF PERSONAL INFORMATION
LorenzoZesati is the Controller of your Personal Information. LorenzoZesati's primary place of business is PO Box 44, Gilbert, AZ 85299, United States.
11.3. YOUR RIGHTS UNDER GDPR
If you are in the EEA or UK, you have the following rights under the GDPR and UK GDPR, subject to certain exceptions:
Right to be Informed: The right to be informed about how we use your personal data (which is provided in this Privacy Policy) Right of Access: The right to access your data and receive a copy of the Personal Information we hold about you Right to Rectification: The right to request that any inaccurate or incomplete Personal Information be corrected or supplemented Right to Erasure (Right to be Forgotten): The right to have your Personal Information erased, unless we have a legitimate reason to retain the Personal Information (such as if we are required to do so for legal reasons, to complete a transaction, to establish or defend legal claims, or to exercise free speech rights) Right to Restrict Processing: The right to ask us not to process your Personal Information for a particular purpose under certain circumstances (e.g., if you contest the accuracy of the data, if processing is unlawful but you don't want erasure, if we no longer need the data but you need it for legal claims) Right to Data Portability: The right to receive your data in a machine-readable format and transmit it to another controller where technically feasible Right to Object: The right to object to processing based on legitimate interests, direct marketing, or processing for research/statistical purposes Rights Related to Automated Decision-Making: The right not to be subject to automated decision-making, including profiling, that produces legal or similarly significant effects without human intervention
All of these rights are subject to certain conditions and exemptions. For example, we will not be obligated to erase your Personal Information if we need to retain it to complete a transaction, protect ourselves in the event of a legal claim, comply with legal obligations, exercise free speech rights, or for other legally permitted reasons.
11.4. EXERCISING YOUR GDPR RIGHTS
To exercise any of these rights, please submit a written request to us using the contact information in Section 17 (Contact Us). We may require proof of your identity to process your request.
We respond to requests within one month, which may be extended by two additional months, when necessary, due to the complexity or number of requests. We will inform you of any extension within one month of receiving your request.
The Company reserves the right to charge a fee in dealing with such a request as permitted by applicable law and regulations, particularly for manifestly unfounded or excessive requests.
You may also opt out of receiving additional marketing information by using the unsubscribed feature in any marketing email we send you or by contacting us directly.
11.5. RIGHT TO LODGE A COMPLAINT
You have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe our processing of your personal data violates applicable law. Contact information for EEA data protection authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. For the UK, contact the Information Commissioner's Office at https://ico.org.uk/.
11.6. INTERNATIONAL TRANSFERS FROM EEA/UK
If you are a resident of the EEA or UK, your Personal Information may be transferred within or outside the EEA/UK to areas where privacy laws may be less strict than in the EEA/UK (including transfers to our systems in the United States).
By submitting your Personal Information, you agree to this transfer, storing, and processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
Where required by law, we implement appropriate safeguards to ensure adequate protection for international transfers, such as:
Using Standard Contractual Clauses approved by the European Commission Relying on adequacy decisions where applicable Implementing additional technical and organizational measures Participating in recognized data transfer frameworks (such as the EU-U.S. Data Privacy Framework, if applicable)
Unfortunately, the transmission of information via the Internet is not completely secure. Although we will do our best to protect your Personal Information, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
CHILDREN'S PRIVACY (COPPA)
Our services are not directed at children under 16 years old (or under 13 in the United States), and we do not knowingly collect, use, or disclose personal information from children under these ages without parental consent.
We are strongly committed to protecting the safety and privacy of children who visit our Site. Our Site is not designed for children under 13 in the United States (or under 16 in other jurisdictions), and we do not knowingly collect personal information online from children and have adopted techniques to ensure compliance with this Privacy Policy and the Children's Online Privacy Protection Act of 1998 ("COPPA"). Our Site includes content that we believe to be unsuitable for children under these ages.
If we learn that we have collected the Personal Information of a child without parental consent, we will take steps to delete the information as soon as possible. If you become aware that a child has provided us with Personal Information without parental consent, please contact us immediately at [email protected].
If you are under 16 years old (or under 13 in the United States), do not:
Use or provide any information on this website Make any purchases through this website Use any interactive features of this website Provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or username you may use
We encourage all parents and guardians to:
Talk to their children about online safety Monitor their children's use of the Internet Use parental control tools to restrict children's access to certain websites
Before collecting information from a child under 13 (in the United States) or under 16 (in other jurisdictions), if we were to do so as part of a specific program designed for children, we would:
Provide parents with a notice describing our data practices Obtain verifiable parental consent through methods recognized by COPPA (e.g., signed form, credit card transaction, video call, or other FTC-approved methods) Give parents the choice to consent to our collection and use of the child's information without consenting to disclosure to third parties Providing parents with access to their child's personal information and the ability to request deletion Not condition a child's participation in activities or providing more information than is reasonably necessary
THIRD-PARTY WEBSITES AND SERVICES
Our Site and services may contain links to and from other websites, including our partner networks, affiliates, business partners, and social media platforms. We may also integrate with third-party services and platforms.
If you follow a link to any of these websites or use integrated third-party services, please note that these websites and services are not covered by this Privacy Policy. We are not responsible for the privacy practices employed by these third parties or the content of linked sites, although we do encourage you to read the applicable privacy policies and terms and conditions of such parties or websites.
This Privacy Policy only applies to how LorenzoZesati deals with your Personal Information, and it does not apply to any other company or any other company's websites even if you access them via our Site. Please check those websites' policies before you submit any Personal Information to them. We highly recommend that you check the security indicators (such as the lock icon) next to their URL to ensure the connection is secure.
Examples of third-party services we may link to or integrate with include:
Social media platforms (LinkedIn, Facebook, Instagram, YouTube) Payment processors Email marketing platforms Calendar and scheduling services CRM systems Analytics providers Webinar platforms Cloud storage services AI service providers and Community platforms (e.g., Skool)
When you interact with these third-party services, their own privacy policies and terms of service will apply to your use of those services and any information you provide to them.
DATA SECURITY
Protecting our clients' information is integral to our mission. We adopt administrative, technical, and physical safeguards to secure personal data against accidental or unlawful destruction, loss, unauthorized access, use, alteration, or disclosure.
While we use reasonable and appropriate measures to protect your Personal Information, we cannot guarantee absolute security. Unfortunately, the transmission of information via the internet is not completely secure, and we cannot guarantee the security of your Information either in transmission or when stored. Any transmission is at your own risk.
We have implemented comprehensive security measures as described in Section 6.1 (Data Security), including:
Encryption of data in transit and at rest Multi-factor authentication for sensitive access Regular security assessments and updates Employee training on security practices Incident response procedures Access controls and audit logging Secure backup procedures Physical security for facilities and equipment
We are not responsible for circumvention of any privacy settings or security measures contained on the Platform. If you become aware of any security breach or unauthorized access to your account, please notify us immediately at [email protected].
INTERNATIONAL TRANSFERS
This section supplements the information in Section 5.9 (International Transfers) regarding data transfers outside your country of residence.
Our servers and service providers are in various countries, including the United States. When you provide personal information to us, that information may be transferred to and stored in countries that may not have data protection laws equivalent to those in your country of residence.
We take steps to ensure that your personal information continues to receive appropriate protection. For transfers from the EEA or UK, we rely on:
Standard Contractual Clauses: Approved by the European Commission for transfers to countries without an adequacy decision Adequacy Decisions: Relying on European Commission findings that certain countries provide adequate data protection Additional Safeguards: Implementing supplementary technical and organizational measures where needed
For transfers from other jurisdictions, we implement appropriate safeguards as required by applicable law.
By using our services and providing your personal information, you consent to the transfer of your information to countries outside your country of residence, including the United States, which may have different data protection rules.
CONDITIONS OF USE AND CHANGES TO OUR PRIVACY POLICY
16.1. UPDATES TO THIS PRIVACY POLICY
We may update this Policy periodically to reflect changes in our practices, legal requirements, or technology. We will post the updated Policy with a new "Effective date" at the beginning of this document and may notify you of material changes via email, SMS, prominent notice on our website, or other appropriate communication channels.
We encourage you to review this Policy regularly to stay informed about how we are protecting your information. Unless stated otherwise, the current version applies to all the data we hold about you.
Please review the Privacy Policy when you visit our Website to remain updated on our current policy. We have no intention of making any changes to our Privacy Policy and practices to make them less protective of personal data collected. By accessing the website and/or using our products, programs, and/or services after we make any changes to this Privacy Policy, you are deemed to have accepted such changes.
Please be aware that, to the extent permitted by applicable law, our use of the data is governed by the Privacy Policy in effect at the time we collect the data. You are advised to review this Privacy Policy periodically for any changes. Whenever we make changes to this Privacy Policy, we will update the effective date at the top.
16.2. CONDITIONS OF USE
If you choose to visit our Site, attend our events or webinars, use our services, or otherwise engage with LorenzoZesati, your visit and any dispute over privacy is subject to this Privacy Policy and our Terms of Service, including:
Limitations on damages Resolution of disputes Application of the law of the State of Arizona Arbitration provisions (if applicable) Other terms and conditions governing your use of our services
As our business changes and evolves, our Privacy Policy and Terms of Service may change also. We may send periodic reminders of our notices and conditions, but you should check our Site frequently to see recent changes.
16.3 NO LIABILITY FOR THIRD-PARTY ACTIONS
We are not responsible for the actions of third parties, including:
Service providers who may violate this Policy or applicable law Third-party websites or services you access through our Site Unauthorized access to your information despite our security measures Interception of communications over the internet
While we take reasonable steps to work with trustworthy service providers and implement security measures, we cannot guarantee the security practices of third parties or prevent all unauthorized access.
CONTACT US
If you have questions or suggestions with respect to this Privacy Policy, our privacy practices, or wish to exercise your rights, please contact us (LorenzoZesati, LLC):
Email: [email protected] Phone: 602-456-7632 (call or text) Mail: PO Box 44, Gilbert, AZ 85299 Website: www.LorenzoZesati.com
17.1. SUBMITTING REQUESTS
When contacting us to exercise your privacy rights, please provide:
Your full name and contact information Sufficient detail to identify yourself and verify your identity A description of the nature of your request Specific rights you wish to exercise (e.g., access, deletion, correction) Any relevant account information or transaction details
For CCPA-specific requests, please follow the procedures set forth in Section 9.5 (Submitting a CCPA Data Request).
For GDPR-specific requests, please follow the procedures set forth in Section 11.4 (Exercising Your GDPR Rights).
For other state-specific privacy requests, please follow the procedures set forth in Section 10.3 (Exercising Your State Privacy Rights).
17.2. RESPONSE TIMEFRAMES
We endeavor to respond to your inquiries and requests promptly:
General inquiries: Within 5 to 10 business days CCPA requests: Within 45 days (extendable by another 45 days if needed) GDPR requests: Within one month (extendable by two additional months if needed) Other state law requests: Within timeframes required by applicable law (generally 45 days, extendable by an additional 45 days with notice)
If we need additional time to respond, we will notify you of the reason for the delay and the expected response timeframe.
17.3. COMPLAINTS AND CONCERNS
If you have concerns about our privacy practices or believe we have violated applicable privacy laws, please contact us first using the information above. We will work to address your concerns and resolve any issues.
If you are not satisfied with our response, you may:
California Residents: Contact the California Attorney General at https://oag.ca.gov EEA/UK Residents: Lodge a complaint with your local data protection authority Other U.S. Residents: Contact your state attorney general or applicable privacy regulator. A directory of state attorneys general can be found at https://www.naag.org/find-my-ag/
This Privacy Policy represents our commitment to protecting your personal information and respecting your privacy. By working with Lorenzo Zesati, you're partnering with a Business Technology Architect who understands that your data is an extension of your business and deserves the highest level of protection and respect. We're here to serve you with integrity, transparency, and excellence in all aspects of our relationship, including how we handle your personal information.
If you have any questions about this Privacy Policy or our data practices, we encourage you to reach out. Your trust is foundational to our mission of helping Married Christian Businessmen with Children build thriving businesses without sacrificing what matters most.
God bless you and your business,
Lorenzo Zesati Business Technology Architect www.LorenzoZesati.com
Effective Date and last updated on April 01, 2026

Lorenzo Zesati Business Technology Architect, based in Gilbert, Arizona is on a mission to "Help to Built and Organize your Business that Honors God, Protects your Health & Family"