This policy explains the principles, safeguards, and governance we apply to protect personal data across Local Florida Directory. It complements — and doesn't replace — our Privacy Policy.
Last updated: January 1, 2025.
Florida Local Directory Service Inc. (“we,” “us,” “Local Florida”) handles personal data belonging to the people who use Local Florida Directory — consumers searching the directory, people who write reviews, and representatives of businesses listed on it. This policy sets out the principles and safeguards we apply to that data, so anyone can understand how we approach data protection as an organization, not just what data we collect (which our Privacy Policy covers in detail).
This policy applies to personal data we process in connection with the Service — consumer accounts, business accounts, reviews and other User Content, and the technical and support data generated by using the Service. It applies to us directly and to the vendors we rely on to operate the Service, described in Vendor & Service Provider Oversight.
We apply the following principles to any personal data we process:
In summary — see our Privacy Policy for full detail — we process:
Depending on where you live, you may have the right to:
See Exercising Your Rights below for how to make a request.
For most of the personal data described in this policy, Local Florida acts as the data controller— we decide why and how it's processed. The vendors that support our infrastructure (hosting and database, payment processing, mapping, email delivery) act as data processors on our behalf, only under our instructions and for the purposes we direct — see Vendor & Service Provider Oversight.
Access to personal data is restricted using database-level row security rules, so an account's private data — like saved favorites or notifications — is readable only by that account, not by other users querying the same tables. Administrative access to production data is limited to those who need it to operate the Service.
Data in transit between your browser and our servers is encrypted (HTTPS/TLS). Payment card details are handled directly by our payment processor and never pass through or get stored on our own servers.
Our hosting and database infrastructure includes automated backups, so data can be recovered in the event of an infrastructure failure.
We review access permissions and vendor configurations as part of ongoing operations, and maintain an incident response process for handling suspected security issues — see Data Breach Response.
We retain personal data for as long as your account is active, or as needed to provide the Service. When you close your account, we remove or de-identify personal information within a reasonable period, except where we need to retain specific records to meet a legal obligation, resolve a dispute, or enforce our agreements. See our Privacy Policy for more detail.
The Service is currently offered to users located in the United States, and personal data is processed and stored in the United States by us and our processors. If we expand the Service internationally, or engage a processor that stores data outside the U.S., we'll update this policy to describe the safeguards that apply to that transfer.
We maintain an internal process for triaging and responding to suspected data security incidents, including containing the issue, assessing what data and users may be affected, and taking corrective action to prevent recurrence.
We rely on a limited set of vendors to operate the Service — for hosting and our database, payment processing, mapping, and email delivery. Before relying on a vendor to process personal data, we consider their security and privacy practices, and we require them, contractually, to use personal data only to provide their service to us and to protect it consistent with this policy and applicable law.
Access to systems containing personal data is limited to team members and contractors who need it to do their job — such as responding to support requests or maintaining the Service — and is removed when it's no longer needed. Anyone with that access is expected to understand and follow this policy and our Privacy Policy.
Responsibility for data protection sits with Local Florida's leadership, who oversee how this policy is applied across the Service. Questions, requests, or concerns about data protection can be directed to us using the contact details below; we treat data protection as an ongoing responsibility of the business, not a one-time compliance exercise.
We review this policy periodically, and whenever we make a significant change to how we collect or process personal data, to keep it accurate and up to date. We'll update the “Last updated” date above whenever we revise it.
To exercise any of the rights described above, or to ask a question about this policy, contact us at ducct.quangbinh@gmail.com or through our Contact page. For security purposes, we may take reasonable steps to confirm your identity before completing a request.
Search trusted local businesses, or list yours for free in minutes.
