Privacy Policy — JSBC
About Services + Contact + FAQ Articles Calculator 7% Tax Map Pricing Book a Free Consultation

Privacy Policy

How JSBC collects, uses, discloses, retains, and protects personal data.

Version 2026-08-19. Last updated: August 19, 2026

This Privacy Policy explains how JSBC collects, uses, discloses, retains, and protects personal data, and sets out JSBC's binding commitments where it processes personal data on a client's behalf. It applies wherever JSBC handles personal data and is written to be read consistently with the data protection laws that apply, including Regulation (EU) 2016/679 (GDPR), the UK GDPR and the Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable federal, state, and international data protection laws.

This policy forms part of our Terms and Conditions. In this policy, “we,” “us,” and “our” refer to JS Bongiovanni Company.

Who We Are

JS Bongiovanni Company (“JSBC”) is a U.S.–Italy cross-border accounting and tax consulting firm. We operate offices in the United States and Italy and serve clients internationally.

Controller: JS Bongiovanni Company, 1908 Thomes Ave STE 79585, Cheyenne, WY 82001, United States
U.S. Office: 4616 N Drake Ave, Chicago, IL 60625
Italian Mailing Address: Corso Umberto I, 78, 92020 San Biagio Platani (AG), Italy

Roles

For personal data that JSBC processes on the Client's behalf to deliver the services, the Client is the controller and JSBC is the processor. To the extent JSBC processes personal data for its own purposes, including developing and improving its tools and models on a de-identified basis, JSBC acts as an independent controller for those purposes and is responsible for its own compliance.

The personal data we collect and its sources

Depending on the relationship, we may collect the following categories of personal data:

Some of this data may be sensitive or special category data under applicable law, which we process only where a lawful basis and, where required, an appropriate condition or explicit consent applies. Categories of data subjects include Client personnel, owners, contractors, and related individuals. We collect personal data directly from clients and their personnel, from individuals who contact us or use our sites, from authorized representatives, and from third parties such as government authorities, financial institutions, prior advisors, and service providers, in each case as needed to provide and administer our services.

Why we use personal data, and our legal bases

We use personal data for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each purpose is indicated.

Where we rely on legitimate interests, we balance those interests against the rights and freedoms of individuals. Where we rely on consent, you may withdraw it at any time as described below, without affecting the lawfulness of processing before withdrawal and without affecting services provided under our Terms and Conditions.

Consultation Call Recording and AI Processing

When you book and attend a consultation with JSBC, you acknowledge and expressly consent to the following:

By scheduling a consultation, attending the call, and/or remaining on the call after being notified that recording is in progress, you provide your informed consent to the recording, transcription, AI processing, storage, and internal reuse described above. If you do not consent, please notify us in writing before the call begins (privacy@jsbc.it) and we will either conduct the meeting without recording or reschedule.

You retain the right at any time to (i) withdraw consent for future recordings, (ii) request access to recordings or transcripts of meetings in which you participated, and (iii) request deletion of recordings, transcripts, and AI-derived material that personally identify you, subject to legitimate business and legal-retention exceptions described in “How long we keep personal data” below.

Artificial intelligence, automated processing, and model training

JSBC uses automated tools, including artificial intelligence and machine learning, to deliver, analyze, and improve its services. Subject to the safeguards below, we may collect, record, transcribe, store, and reprocess Engagement Data to operate these tools and to train and improve our models and workflows. The Client authorizes this processing; where any use of personal data in identifiable form requires an individual's consent under applicable law, the Client warrants that it has obtained that consent, including consent to recording where required. This authorization is severable: the Client may withdraw it on written notice without affecting the services provided under our Terms and Conditions.

De-identification first. Wherever feasible we use de-identified or aggregated data for model training and product development. Once data has been anonymized so that individuals are no longer reasonably identifiable, it is no longer personal data, and we may retain and use it without time limit. Anonymized data is distinct from pseudonymized data, which we continue to treat as personal data.

Legal basis and separable consent. Where model training or product development uses personal data in identifiable form, we rely on our legitimate interests, assessed against the rights of the individuals concerned. Where applicable law requires consent for such use, we rely on consent that is sought separately from the services. That consent is severable: an individual or client may decline or withdraw it without affecting the professional services we provide.

No qualifying automated decisions. We do not use these tools to make decisions producing legal or similarly significant effects about an individual based solely on automated processing without human involvement. Where any such processing might occur, we will provide the safeguards required by applicable law, including meaningful human review.

Our binding commitments when acting as your data processor (Article 28)

Where JSBC acts as processor, the following terms are binding and form part of our Terms and Conditions. JSBC shall: (a) process personal data only on the Client's documented instructions, including that agreement, unless required by law, in which case JSBC will inform the Client unless legally prohibited; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; (d) engage sub-processors, including artificial intelligence platform and cloud providers, only under written terms at least as protective as these, the Client granting general authorization to JSBC to appoint sub-processors subject to notice of intended changes and a reasonable opportunity to object; (e) assist the Client, taking account of the nature of processing, with data subject rights requests and with the Client's obligations regarding security, breach notification, impact assessments, and prior consultation; (f) notify the Client of a personal data breach affecting the Client's data without undue delay and, in any event, within 72 hours of becoming aware of it; (g) at the Client's choice, delete or return the personal data at the end of the services, except where retention is required by law or where data has been anonymized; and (h) make available information necessary to demonstrate compliance and allow for reasonable audits.

Processing particulars: the subject matter and purpose of processing are the accounting, tax, payroll, compliance, AI-assisted advisory, and related professional services described in our Terms and Conditions; the duration is as set out under How long we keep personal data below; the nature of processing includes collection, storage, use, automated reprocessing, disclosure where necessary to service providers or authorities, and secure deletion; and the categories of personal data and of data subjects are those identified above.

Sharing and disclosure

We do not sell personal data. We disclose personal data only as follows:

Third-Party Services

Our website, client engagement, and consultation workflow use the following third-party services that may process your data, including (where indicated) recordings, transcripts, and content derived from consultation calls:

Client engagement, document handling, and communications

ServicePurposePrivacy Policy
TaxDomeTax practice management: secure client portal, document collection and storage, tax-return delivery, e-signature, engagement letters, billing, messagingtaxdome.com/privacy
HubSpotCRM, lead management, marketing automation, and client communicationslegal.hubspot.com/privacy-policy
Microsoft 365 (Outlook, OneDrive, Teams, SharePoint)Business email, document storage and sharing, calendaring, video conferencing, and internal collaboration. Files, emails, and call recordings related to your matter may be stored on Microsoft cloud infrastructure.privacy.microsoft.com/privacystatement
OpenPhoneBusiness telephony and SMS: calls and texts with our team may be logged, recorded (where lawful), and transcribedopenphone.com/privacy
CalendlyConsultation schedulingcalendly.com/privacy
FormspreeWebsite form submission processingformspree.io/legal/privacy-policy

Recording, transcription, and AI processing

ServicePurposePrivacy Policy
Fireflies.aiConsultation call recording, transcription, and AI summarizationfireflies.ai/privacy
OpenAIAI processing of transcripts, notes, summaries, and derived insightsopenai.com/policies/privacy-policy
Anthropic (Claude)AI processing of transcripts, notes, summaries, and derived insightsanthropic.com/legal/privacy
Google (Gemini / Google AI)AI processing of transcripts, notes, summaries, and derived insightspolicies.google.com/privacy
n8nWorkflow automation: routing of form submissions, lead alerts, and data between the systems listed in this policyn8n.io/legal/privacy
SupabaseBackend database and file storage: stores form submissions, article content, and chunked transcripts/embeddings used for our internal AI knowledge basesupabase.com/privacy
PushoverInternal staff notifications when new leads or messages are receivedpushover.net/privacy

Hosting, analytics, and advertising

ServicePurposePrivacy Policy
VercelWebsite hosting and edge deliveryvercel.com/legal/privacy-policy
GitHubSource-code hosting for this website (does not process visitor personal data, but listed for transparency)github.com privacy statement
Google Tag ManagerTag management: loads the analytics and marketing tags listed belowpolicies.google.com/privacy
Google Analytics (GA4)Site-traffic and behavior analytics (loaded via Google Tag Manager)policies.google.com/privacy
Microsoft ClaritySession replay and heatmap analytics to help us understand how visitors use the siteprivacy.microsoft.com/privacystatement
Meta (Facebook) PixelConversion measurement and audience targeting on advertising landing pagesfacebook.com/privacy/policy
Google FontsTypographypolicies.google.com/privacy

This list reflects the third-party services in use as of the "Last updated" date above. JSBC may add, substitute, or remove comparable AI, transcription, CRM, telephony, document-management, hosting, analytics, or workflow vendors over time. Where a new vendor is materially different in nature from those listed above, we will update this Privacy Policy.

Cookies and Tracking

Our website uses Google Tag Manager (which may load Google Analytics, Microsoft Clarity, and HubSpot tracking) and the Meta (Facebook) Pixel for analytics, attribution, and advertising-conversion measurement on certain pages. You can decline non-essential cookies via the cookie banner shown on first visit. Third-party embeds (Calendly, Google Fonts) may set their own cookies according to their respective privacy policies listed above.

International data transfers

We operate across the United States, the European Union, the United Kingdom, and other jurisdictions, and personal data may be transferred to and processed in countries other than the one in which it was collected. Where we transfer personal data out of the European Economic Area or the United Kingdom to a country without an adequacy decision, we use appropriate safeguards, such as the European Commission Standard Contractual Clauses and the UK International Data Transfer Agreement or Addendum, together with any supplementary measures required. A copy of the relevant safeguard is available on request.

How long we keep personal data

We retain personal data for as long as needed to provide the services and thereafter for the period required to meet our legal, regulatory, tax, and professional obligations and to establish, exercise, or defend legal claims. When personal data is no longer required, we delete or anonymize it. Anonymized or aggregated data may be retained indefinitely because it is no longer personal data.

How we protect personal data

We implement appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These include access controls, encryption where appropriate, monitoring, and staff confidentiality obligations. Our website is served over HTTPS, and form submissions are transmitted securely. However, no method of internet transmission is completely secure, and we cannot guarantee absolute security. Where JSBC acts as a processor, its security and breach-notification commitments are set out in the processor commitments above.

Your privacy rights (EEA and UK)

If you are in the European Economic Area or the United Kingdom, you have the following rights, subject to conditions and exemptions in applicable law:

Where JSBC processes your data on behalf of a client (as a processor), please direct requests to that client; we will assist them as required by law. Where JSBC is the controller, you may contact us using the details at the end of this policy. If we do not have an establishment in the EEA or the UK but are subject to the GDPR or UK GDPR, our representative under Article 27, where appointed, is identified at the end of this policy.

Your privacy rights (California)

If you are a California resident, the CCPA/CPRA gives you the following rights, subject to exceptions:

Much of the personal information we handle is collected on behalf of, or is subject to, the client relationship and to exemptions for professional, business-to-business, and regulated financial or tax information. Where JSBC uses personal information beyond performing services for a client, we do so consistent with the notice and choice requirements of the CCPA/CPRA. To exercise a right, use the contact details at the end of this policy. We will verify your request and may act through an authorized agent.

Your privacy rights (other US states)

Residents of other US states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, and Texas, may have rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling. We honor these rights where they apply. Use the contact details at the end of this policy, and where a law provides an appeal process we will inform you of it.

Children's privacy

Our services are directed to businesses and professionals, not to children. We do not knowingly collect personal data from children. If we learn that we have collected such data without a required consent, we will delete it.

Changes

We may update this Privacy Policy from time to time, posting the updated version with a new effective date and, where required, providing additional notice. Changes to the binding processor commitments set out above take effect only by agreement of the parties, as provided in our Terms and Conditions.

How to contact us

Controller:
JS Bongiovanni Company (JSBC)
1908 Thomes Ave STE 79585
Cheyenne, WY 82001
United States

Privacy contact: privacy@jsbc.it
Data Protection Officer: Paul Joseph Rausch, CISSP-ISSMP, privacy@jsbc.it

Back to home