Last Updated: May 26, 2026 | Effective Date: May 26, 2026 | Governing Law: State of Florida, United States of America

Privacy Policy

ArisGate, Inc. is a Florida-based managed cybersecurity company serving solo, small, and mid-sized law firms across the State of Florida. Protecting sensitive information is the foundation of everything we do for our clients and for every individual who interacts with our website and services.

This Privacy Policy describes what personal information we collect, how we use it, who we share it with, and the rights you hold under Florida and federal law. By accessing https://www.arisgate.com or engaging with any ArisGate service, you agree to the practices described in this Policy.

If you have questions at any time, please contact us at privacy@arisgate.com.

Table of Contents

  1. Who We Are
  2. Scope of This Policy
  3. Information We Collect
  4. How We Use Your Information
  5. How We Share Your Information
  6. Third-Party Technology Partners - Security Standard
  7. Cookies and Tracking Technologies
  8. Data Security and Encryption
  9. Data Breach Notification - FIPA 501.171
  10. Your Rights as a Florida Resident
  11. Data Retention
  12. Email Communications and CAN-SPAM Compliance
  13. Children's Privacy - COPPA Compliance
  14. ArisGate AI Chatbot - Advance Notice
  15. ArisGate Client Portal - Advance Notice
  16. Links to Third-Party Websites
  17. Changes to This Privacy Policy
  18. Contact Information

1. Who We Are

ArisGate, Inc. is a managed cybersecurity company incorporated and headquartered in the State of Florida. We provide 24/7 threat detection and response, Security Operations Centre (SOC) monitoring, endpoint protection, identity and access management, vulnerability and patch management, phishing and email security, zero trust secure remote access, immutable backup and disaster recovery, compliance support, and security awareness training designed exclusively for Florida law firms.

Legal Name: ArisGate, Inc. | Address: 7901 4th St N #32327, St. Petersburg, Florida 33702, United States of America | County: Pinellas County | Phone: +1 (727)-870-1750 | General Email: info@arisgate.com | Privacy Email: privacy@arisgate.com | SOC and Security: soc@arisgate.com | Sales: sales@arisgate.com | Website: https://www.arisgate.com

2. Scope of This Policy

This Privacy Policy applies to all personal information collected through or in connection with: (a) The ArisGate website at https://www.arisgate.com and all associated subpages including /services, /pricing, /contact, /faq, /about, /submit-a-ticket, /privacy, and /terms-of-service; (b) Contact forms, free security audit request forms, ticket submission forms, and any lead capture mechanism on our site; (c) Email communications initiated through info@arisgate.com, sales@arisgate.com, soc@arisgate.com, or any ArisGate representative; (d) CRM and outreach activity conducted through HubSpot and Apollo.io on behalf of ArisGate; (e) Onboarding and service delivery activities for clients who have engaged ArisGate under a service agreement; (f) The ArisGate AI Chatbot when deployed (see Section 14); (g) The ArisGate Client Portal when deployed (see Section 15).

This Policy does not govern the data practices of any third-party website, application, or service that we link to but do not operate.

3. Information We Collect

3.1 Information You Provide Directly

We collect personal information that you voluntarily submit to us, which may include: full name; law firm name and business address; work email address; business phone number; job title or role at the firm; message content submitted via contact forms, the free security audit request, or ticket submissions; details about your firm's size, current technology environment, and cybersecurity concerns; billing and payment information for active service clients (processed securely - ArisGate does not store raw payment card data).

3.2 Information Collected Automatically

When you visit https://www.arisgate.com, our website infrastructure automatically collects: IP address and approximate geographic location (city and state level only); browser type, version, and language preference; device type and operating system; pages visited, time spent on each page, and navigation path; referring URL; date and time of each visit; cookie identifiers and session data (see Section 7); Google Tag Manager event data (GTM-MZDZ5RQ7).

3.3 Information Received from Third-Party Platforms

Apollo.io: Contact enrichment data including verified job title, law firm name, business email address, business phone number, and LinkedIn profile URL for prospective clients.

HubSpot, Inc.: CRM activity records including email open and click history, website visit tracking, form submission logs, and deal stage data for contacts in our sales pipeline.

3.4 Information We Do NOT Collect

ArisGate does not collect, solicit, or intentionally receive the following categories of sensitive personal information through this website: Social Security numbers or government-issued identification documents; financial account numbers, credit card numbers, or banking credentials; protected health information (PHI) or medical records; biometric identifiers of any kind; confidential client legal matter information, case files, or privileged attorney-client communications; personal information from individuals under the age of 13.

4. How We Use Your Information

ArisGate uses personal information collected from you exclusively for the following purposes: (a) To respond to your inquiry, contact form submission, or free security audit request; (b) To evaluate your law firm's cybersecurity needs and recommend the appropriate Shield, Fortress, or Vault service plan; (c) To schedule and conduct your complimentary security assessment; (d) To route your contact record to the appropriate ArisGate specialist using our HubSpot CRM platform; (e) To conduct sales outreach and follow-up communications - you may opt out at any time (see Section 12); (f) To onboard and deliver managed cybersecurity services to law firms that have executed a service agreement with ArisGate; (g) To deliver monthly security monitoring reports and compliance documentation to active clients; (h) To send relevant cybersecurity updates, Florida Bar compliance reminders, and service announcements; (i) To analyze website traffic and improve the performance and user experience of arisgate.com; (j) To detect, investigate, and prevent fraudulent activity, unauthorized access, or abuse of our website and systems; (k) To comply with all applicable Florida and federal legal obligations, including FIPA 501.171 and Florida Bar Rule 4-1.6.

We do NOT sell, rent, trade, or transfer your personal information to any third party for their own independent marketing or commercial purposes.

5. How We Share Your Information

5.1 Authorized Service Providers

We share personal information only with third-party service providers that process data strictly on our behalf under written agreements that prohibit them from using your data for any independent purpose.

HubSpot, Inc. - Purpose: CRM, contact management, email marketing, lead routing, and sales pipeline tracking. Privacy Policy: https://legal.hubspot.com/privacy-policy

Apollo.io - Purpose: Contact data enrichment, outreach email sequencing, and sales prospecting for Florida law firm clients. Privacy Policy: https://www.apollo.io/privacy-policy

Microsoft Corporation - Purpose: Email delivery via Microsoft Outlook and Microsoft 365, calendar scheduling, and business communication tools. Privacy Policy: https://privacy.microsoft.com

Webflow, Inc. - Purpose: Website hosting, content delivery, and page rendering for https://www.arisgate.com. Privacy Policy: https://webflow.com/legal/privacy

Google LLC (Google Tag Manager) - Purpose: Website analytics event tracking via GTM-MZDZ5RQ7. Privacy Policy: https://policies.google.com/privacy

HubSpot Meetings (connect.arisgate.com) - Purpose: Scheduling free security audit and consultation calls on behalf of ArisGate.

5.2 Technology Partners Delivering Security Services

For clients who have signed a service agreement, ArisGate deploys and manages the following security platforms on behalf of your firm, each operating within a secured, managed environment under ArisGate's direct supervision: Huntress (Endpoint detection and response); IRONSCALES (Email security and anti-phishing); Twingate (Zero trust secure remote access); Action1 (Vulnerability and patch management); MSP360 (Immutable backup and disaster recovery); Microsoft 365 (Identity protection, email, productivity); Cloudflare (DNS filtering and web security layer).

These platforms process security telemetry, event logs, and system data from your firm's environment solely for the purpose of delivering contracted cybersecurity services. They do not receive personal information from our marketing website unless you are an active client and that information is directly relevant to service delivery.

5.3 Legal Compliance and Law Enforcement

We may disclose personal information when required by law or in good faith belief that disclosure is necessary to: comply with a valid legal obligation, court order, subpoena, or governmental request under Florida or federal law; cooperate with an active law enforcement investigation; protect the rights, property, or safety of ArisGate, our clients, or the public; fulfill data breach notification obligations under FIPA 501.171, Florida Statutes; respond to a Florida Attorney General inquiry or audit.

5.4 Business Transfers

In the event of a merger, acquisition, sale of company assets, or corporate reorganization involving ArisGate, Inc., personal information held by ArisGate may be transferred to the successor entity. You will be notified via a prominent website notice and direct email no fewer than 30 days before any such transfer becomes effective. The acquiring entity will be bound by the terms of this Privacy Policy.

5.5 With Your Express Consent

We may share your information with parties not identified above when you have provided express written or digital consent for a specific sharing purpose. You may withdraw such consent at any time by contacting privacy@arisgate.com.

6. Third-Party Technology Partners - Security Standard

ArisGate conducts due diligence on all third-party technology partners and service providers before engagement. Each partner is contractually required to: maintain data security standards that meet or exceed the requirements of FIPA 501.171(2), Florida Statutes; process personal or firm data only within the scope of instructions provided by ArisGate; notify ArisGate of any security breach involving our clients' data within 10 days of discovery, consistent with FIPA's third-party agent notification obligations; execute written data processing or vendor agreements with ArisGate prior to receiving access to any data; undergo periodic security review as part of ArisGate's ongoing vendor risk management program.

7. Cookies and Tracking Technologies

7.1 Essential Cookies (Always Active)

These cookies are strictly necessary for the website to function correctly and cannot be disabled without breaking core site features. They are used solely for operational purposes and do not track users for advertising: session security tokens for form submissions; CSRF protection tokens to prevent cross-site request forgery attacks; load balancing and server routing identifiers; Webflow platform operational cookies.

7.2 Analytics Cookies (Optional)

We use Google Tag Manager (GTM-MZDZ5RQ7) and HubSpot analytics to understand how visitors interact with our website, helping us improve content, navigation, and page performance. Data collected includes: pages visited, time on page, traffic source, device type, and general geographic region at city level. This data is aggregated and does not personally identify individual visitors.

7.3 Marketing and CRM Cookies (Optional)

HubSpot and Apollo.io use cookies and tracking pixels to log form submission activity and email engagement data for contacts in our sales pipeline. This allows our team to follow up appropriately with law firms that have expressed interest in our services.

7.4 Managing Your Cookie Preferences

You may control, limit, or disable non-essential cookies at any time through your browser settings: Chrome: Settings - Privacy and Security - Cookies; Firefox: Settings - Privacy and Security - Cookies; Safari: Preferences - Privacy - Manage Website Data; Edge: Settings - Cookies and Site Permissions. Disabling cookies may limit certain features of our website. We do not currently respond to Do Not Track (DNT) browser signals.

8. Data Security and Encryption

As a managed cybersecurity company, ArisGate applies the same level of security discipline to visitor and client personal information as we do to our clients' environments. Our technical and organizational safeguards include:

Encryption at Rest: All personal data and client records stored in ArisGate systems are encrypted using AES-256 encryption.

Encryption in Transit: All data transmitted between your browser and our website, and between our systems and third-party processors, uses TLS 1.3 protocol. Deprecated protocols (TLS 1.0, TLS 1.1, and SSL) are not supported.

Access Controls: Access to personal information is restricted to authorized ArisGate personnel on a strict need-to-know basis, enforced through role-based access controls (RBAC) and multi-factor authentication (MFA) on all internal systems.

Cloudflare Security Layer: All traffic to arisgate.com is routed through Cloudflare's DNS filtering and DDoS protection infrastructure, providing an additional security layer at the network edge.

Internal Security Monitoring: ArisGate's own 24/7 SOC continuously monitors our internal systems using the same Huntress EDR and threat detection tools deployed for our law firm clients.

Incident Response Preparedness: ArisGate maintains a written Incident Response Plan (IRP) tested on a regular basis, consistent with the requirements we help our clients fulfill under Florida Bar Recommendation 25-1.

Vendor Risk Management: All third-party processors are assessed for security posture before onboarding and subject to ongoing vendor risk review at least annually.

Framework Alignment: Our internal security program substantially aligns with the NIST Cybersecurity Framework (CSF 2.0) and the Center for Internet Security (CIS) Critical Security Controls.

Despite these measures, no security system provides absolute protection. If you believe personal information submitted through arisgate.com may have been compromised, contact soc@arisgate.com immediately.

9. Data Breach Notification - FIPA 501.171, F.S.

ArisGate, Inc. complies fully with the Florida Information Protection Act (FIPA), 501.171, Florida Statutes. In the event of a security breach of our systems that involves personal information collected through this website or our service delivery operations, ArisGate will take the following steps:

9.1 Notification to Affected Individuals - 30-Day Requirement

We will notify all affected individuals as expeditiously as possible, and in no case later than 30 calendar days after determining that a breach of security has occurred, unless a law enforcement agency provides written authorization to delay notification in connection with an active criminal investigation, as permitted under FIPA 501.171(3)(c), Florida Statutes.

Each individual breach notification will include: (a) a clear description of the type of personal information that was accessed, acquired, or potentially exposed; (b) the known or estimated date or date range during which the breach occurred; (c) a description of what happened and how the breach occurred; (d) the steps ArisGate has taken to contain the breach and secure affected systems; (e) recommended steps the recipient can take to protect themselves; (f) direct contact information for ArisGate's privacy team: privacy@arisgate.com | +1 (727)-870-1750; (g) contact information for the Florida Attorney General's Office and relevant federal consumer protection agencies.

Notification will be delivered by email to the address on file, or by written first-class mail if email is unavailable or if required by the nature of the breach.

9.2 Notification to the Florida Attorney General

If a breach affects 500 or more Florida residents, ArisGate will submit written notification to the Florida Department of Legal Affairs within 30 calendar days of determining that the breach occurred, as required by FIPA 501.171(3), Florida Statutes. Florida Department of Legal Affairs, Office of the Attorney General, PL-01 The Capitol, Tallahassee, Florida 32399-1050. Website: myfloridalegal.com. Phone: (850) 414-3990.

9.3 Extended Notification Timeline

If extraordinary circumstances prevent ArisGate from completing notification within 30 calendar days, we may submit a written request for an extension of up to 15 additional days to the Florida Department of Legal Affairs within the original 30-day window, as authorized under FIPA 501.171(3)(b), Florida Statutes.

9.4 Third-Party Agent Breach Obligations

ArisGate contractually requires all third-party agents and technology vendors who process personal information on our behalf to report any breach involving our data within 10 calendar days of discovery. Upon receiving such notice, ArisGate assumes full responsibility for providing all required individual and regulatory notifications within the applicable statutory period.

10. Your Rights as a Florida Resident

Under the Florida Information Protection Act (FIPA, 501.171, F.S.) and the Florida Digital Bill of Rights (SB 262, effective July 1, 2024), Florida residents whose personal information is held by ArisGate have the following rights:

Right to Access: You have the right to request confirmation of whether ArisGate holds personal information about you and to receive a copy of that information, including details about how it is used and with whom it is shared.

Right to Correction: You have the right to request that we correct any personal information we hold about you that is inaccurate, incomplete, or out of date.

Right to Deletion: You have the right to request that we delete personal information we hold about you, subject to legal, contractual, or regulatory retention obligations that require us to retain certain records (see Section 11).

Right to Data Portability: You have the right to request that we provide your personal information in a structured, commonly used, and machine-readable format.

Right to Opt Out: You have the right to opt out of: (a) the sale or sharing of your personal information (ArisGate does not sell personal data, but this right applies regardless); (b) the use of your personal information for targeted advertising purposes; (c) profiling based on your personal information that produces legal or similarly significant effects on you.

Right to Non-Discrimination: You have the right to exercise any of the rights listed above without receiving discriminatory treatment, reduced service quality, or differential pricing from ArisGate as a result.

10.1 How to Submit a Rights Request

To exercise any of the rights described above, please contact ArisGate: Email: privacy@arisgate.com | Subject: Florida Privacy Rights Request - [Your Name]. Mail: ArisGate, Inc., Attn: Privacy Compliance, 7901 4th St N #32327, St. Petersburg, Florida 33702. We will acknowledge receipt within 5 business days and fulfill all verified requests within 30 calendar days of receipt. Identity verification may be required before processing any request.

11. Data Retention

ArisGate retains personal information only for as long as is necessary to fulfill the purpose for which it was collected, or as required by Florida or federal law, regulatory obligation, or legitimate business necessity. Our retention schedule is as follows:

Website Lead and Inquiry Data: 24 months from the date of last interaction, after which the record is anonymized or securely deleted.

Free Security Audit Request Data: 24 months from the date of the assessment request, whether or not the firm became an active client.

Active Client Service Data: Retained for the full duration of the service engagement plus seven (7) years following termination, consistent with Florida general business record retention standards and applicable tax obligations.

Security Monitoring Logs and Incident Records: Retained for a minimum of 12 months for active clients and as required by applicable compliance frameworks, including FIPA, NIST CSF 2.0, and Florida Bar Recommendation 25-1.

Email Correspondence: Retained for 3 years from the date of the most recent communication in the thread.

Website Analytics Data: Retained on a rolling 13-month basis before automatic deletion or anonymization by the applicable platform.

Billing and Payment Records: Retained for 7 years from the date of the transaction, consistent with Florida tax and business record retention requirements.

Compliance Documentation: Incident Response Plans, Data Mapping Assessments, and related compliance records retained for the duration of the client engagement plus 5 years.

Upon expiration of the applicable retention period, personal information is securely deleted or anonymized in a manner consistent with NIST SP 800-88 guidelines for media sanitization. You may request early deletion by contacting privacy@arisgate.com (see Section 10), subject to legal or contractual obligations that prevent immediate deletion.

12. Email Communications and CAN-SPAM Compliance

ArisGate sends commercial and transactional email communications through Microsoft Outlook, HubSpot, and Apollo.io. All commercial email communications comply fully with the federal CAN-SPAM Act (15 U.S.C. 7701 et seq.) as follows:

Sender Identification: Every email from ArisGate clearly and accurately identifies ArisGate, Inc. as the sender. We do not use deceptive From names, sender addresses, or email routing headers.

Subject Line Accuracy: Subject lines in all ArisGate emails accurately reflect the content of the message. Misleading or deceptive subject lines are not used under any circumstances.

Physical Mailing Address: Every commercial email includes our valid postal address: 7901 4th St N #32327, St. Petersburg, Florida 33702.

Unsubscribe Mechanism: Every commercial email includes a clear, functional, and accessible unsubscribe link or opt-out instruction.

Opt-Out Processing: All unsubscribe requests are processed and honored within 10 business days of receipt. No further commercial email will be sent to any address that has opted out.

Transactional Communications: Emails sent in connection with your active service account, security monitoring alerts, SOC incident notifications, monthly reports, or support ticket responses are transactional in nature and are not subject to commercial opt-out preferences, as they are essential to service delivery.

To unsubscribe from all ArisGate marketing and outreach communications, you may: (a) click the Unsubscribe or Opt Out link in any marketing email from ArisGate, OR (b) email privacy@arisgate.com with the subject line: Unsubscribe - [Your Email Address].

13. Children's Privacy - COPPA Compliance

The ArisGate website and all associated services are designed exclusively for legal professionals and business decision-makers. Our services are not directed at, marketed to, or intended for use by individuals under the age of 13.

ArisGate does not knowingly collect, solicit, or retain personal information from any individual under 13 years of age. If we discover that personal information has been submitted by a child under 13, we will delete that information from all our systems promptly and without delay.

If you believe a child under the age of 13 has submitted personal information to ArisGate through this website or any communication channel, please notify us immediately at privacy@arisgate.com. We will investigate and take immediate corrective action.

14. ArisGate AI Chatbot - Advance Notice (Coming Soon)

Status Notice: The ArisGate AI Chatbot is currently in development and is not yet active on arisgate.com. This section is published in advance to ensure full legal disclosure before the feature launches.

ArisGate is developing an AI-powered chatbot assistant that will be embedded on arisgate.com to help Florida law firm clients and prospects receive immediate answers, request assessments, and connect with the right specialist.

When deployed, the ArisGate AI Chatbot will collect only the following information voluntarily provided during a conversation: full name and law firm name; work email address; brief description of your cybersecurity question or service need; conversation topic selections from guided menus.

Data handling for the chatbot will include: TLS 1.3 encryption for all chatbot communications; session-only data storage, cleared automatically when your session ends or after 30 minutes of inactivity; lead capture data routed through a secure server-side proxy to HubSpot CRM - never transmitted directly from your browser to any third-party platform.

This section will be updated with full operational detail prior to the chatbot's launch. ArisGate will never request passwords, payment data, or confidential case information through the chatbot under any circumstances.

15. ArisGate Client Portal - Advance Notice (Coming Soon)

Status Notice: The ArisGate Client Portal is currently in development and is not yet active. This section is published in advance to ensure complete legal disclosure before the portal launches.

ArisGate is developing a secure, encrypted Client Portal that will provide active law firm clients with authenticated access to their security monitoring reports, incident records, compliance documentation, and communications with the ArisGate SOC team.

When deployed, all Client Portal data will be: encrypted at rest using AES-256 encryption; transmitted exclusively over TLS 1.3 encrypted connections; accessible only via authenticated, session-limited login with automatic timeout after 30 minutes of inactivity; protected by role-based access controls ensuring each user accesses only their own firm's data; logged with a full audit trail for security and compliance review purposes.

ArisGate will never request Client Portal login credentials via email, phone, or any external communication channel. Any such request should be treated as a phishing attempt and reported immediately to soc@arisgate.com. This section will be updated with full operational detail prior to the portal's launch.

16. Links to Third-Party Websites

arisgate.com may contain links to third-party websites, tools, or resources, including our technology partner sites, scheduling tools, and industry reference sources. These links are provided for informational and convenience purposes only.

ArisGate does not operate, control, or endorse those third-party sites and is not responsible for their content, security practices, or privacy policies. We encourage you to review the privacy policy of any third-party site before submitting personal information.

The presence of a link on arisgate.com does not imply any partnership, endorsement, or affiliation beyond what is explicitly stated on our website.

17. Changes to This Privacy Policy

ArisGate reserves the right to update or modify this Privacy Policy at any time to reflect changes in our business practices, technology stack, legal requirements, or regulatory guidance from the Florida Attorney General or applicable federal agencies.

Material changes to this Policy will be communicated through: (a) a prominent notice on arisgate.com for a minimum of 30 days following the effective date of the change; (b) direct email notification to all active clients and individuals who have submitted a contact form or security audit request within the prior 12 months; (c) an updated Last Updated date at the top of this page.

Non-material changes, such as grammar corrections, formatting updates, or clarifications that do not affect your rights or obligations, may be made without advance notice.

Continued use of our website or services following the effective date of any Policy update constitutes acceptance of the revised terms. If you do not agree to the updated Policy, you must discontinue use of our services and notify us at privacy@arisgate.com.

18. Contact Information

For all privacy-related inquiries, rights requests, data breach reports, or compliance questions, please contact us through any of the following:

ArisGate, Inc.
Privacy and Legal Compliance
7901 4th St N #32327
St. Petersburg, Florida 33702
United States of America

Privacy and Legal: privacy@arisgate.com
SOC and Security: soc@arisgate.com
General: info@arisgate.com
Sales: sales@arisgate.com
Phone: +1 (727)-870-1750
Website: https://www.arisgate.com

For Florida data protection regulatory matters:

Florida Department of Legal Affairs
Office of the Attorney General
PL-01 The Capitol
Tallahassee, Florida 32399-1050
Phone: (850) 414-3990
Website: myfloridalegal.com