Privacy Statement
Last updated: July 31, 2026
1. Introduction
Dresden Direct, Inc. ("Dresden Direct," "we," "us," or "our") respects privacy and is committed to describing its personal-information practices in a clear and accessible manner. This Privacy Statement explains how we collect, use, retain, disclose, sell or share personal information in connection with our Website, business communications, consulting activities and data-related services. It also explains the privacy rights available to California consumers under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA").
2. Scope
This Privacy Statement applies to personal information processed through dresdendirect.com, contact and privacy request forms, email and telephone communications, client and supplier relationships, consulting activities, and data-service operations for which Dresden Direct determines the purposes and means of processing. It does not apply where Dresden Direct processes personal information solely as a service provider or contractor on behalf of another business under a written agreement. In that situation, the other business’s privacy notice may govern the consumer relationship.
3. Personal Information We Collect
The personal information we collect depends on how a person interacts with us and on the services involved. During the preceding 12 months, Dresden Direct may have collected the following CCPA categories, subject to confirmation against the company’s final data inventory:
| CCPA category | Examples | Sources | Purposes | Disclosure / sale or sharing |
|---|---|---|---|---|
| Identifiers | Name, postal address, email, phone, IP address, online identifiers and record identifiers. | Directly from individuals; clients; data suppliers; public and commercial sources; Website systems. | Respond to inquiries; provide services; match, maintain and suppress records; security; legal compliance; consumer requests. | Service providers, contractors, clients and recipients of data services. May be sold or shared in data-service activities, subject to opt-out rights. |
| Customer records information | Contact details and other information described in California Civil Code section 1798.80(e). | Individuals; clients; data suppliers; public or commercial sources. | Business operations, data services, verification, compliance and record management. | Service providers, contractors, clients and data-service recipients. May be sold or disclosed depending on the service. |
| Protected classification characteristics | Age range, gender or other characteristics where lawfully included in a client or supplier dataset. | Clients, data suppliers, public or commercial sources. | Audience analysis, data hygiene, permitted marketing and compliance. | Clients or data-service recipients where lawful and contractually permitted. Confirm whether any such category was sold or shared in the preceding 12 months. |
| Commercial information | Service inquiries, customer or supplier relationship records, transaction information, consumer preferences and purchasing indicators. | Individuals; clients; data suppliers; commercial sources. | Provide services, maintain accounts, analytics, record matching and permitted marketing. | Service providers, contractors, clients and data-service recipients. May be sold or shared depending on the service. |
| Internet or electronic network activity | Pages visited, referring URL, browser, device, IP-derived information, timestamps, form activity and cookie or consent signals. | Website, hosting, security and analytics technologies. | Operate and secure the Website, diagnose issues, measure performance and honor privacy choices. | Hosting, security, analytics and technology providers. May be shared for cross-context behavioral advertising only if such technology is enabled and not opted out. |
| Geolocation data | Approximate location derived from IP address or general location indicators contained in lawfully sourced data. | Website systems; clients; data suppliers; public or commercial sources. | Security, fraud prevention, geographic analysis, record matching and service delivery. | Service providers, clients and data-service recipients where lawful. Precise geolocation is not intentionally collected through the Website. |
| Professional or employment-related information | Company, job title, business contact details, industry and professional role. | Individuals; business clients; suppliers; public and commercial sources. | B2B communications, consulting, client service, data services and relationship management. | Service providers, clients and data-service recipients. May be sold or disclosed in B2B data services where lawful. |
| Inferences | Segments, interests, likely characteristics or preferences derived from available information. | Created from other information described above or received from clients and suppliers. | Analysis, data services, audience selection and permitted marketing. | Clients and data-service recipients. May be sold or shared depending on the service. |
4. Sensitive Personal Information
Dresden Direct does not intentionally request government identification numbers, account credentials, precise geolocation, biometric information, genetic information, health information, or information about sex life or sexual orientation through the Website. If sensitive personal information is received in a client or supplier dataset, we process it only for documented, lawful and proportionate purposes. Dresden Direct will provide a “Limit the Use of My Sensitive Personal Information” method if it uses or discloses sensitive personal information for purposes that trigger that right under the CCPA.
5. Information You Provide Directly
When you contact us, submit a Website form, make a privacy request or communicate with us, we may collect your name, email address, phone number, postal address, company, subject, message, request details and any information you choose to provide. Please do not submit sensitive or confidential information through a general contact form unless specifically requested through a secure process.
6. Information Collected Automatically
Website hosting, security and related technologies may automatically process IP address, browser and device information, pages viewed, referral information, timestamps, error logs, cookie choices and similar usage information. We use this information to operate, protect and improve the Website, investigate misuse and honor privacy preferences. See the Cookie Policy for additional information.
7. Information Used in Data and Consulting Services
Dresden Direct may receive information from business clients, data suppliers, publicly available sources, commercial sources and other permitted sources in connection with consulting, list management, data aggregation, data hygiene, record matching, suppression and related services. The exact categories and uses depend on the applicable engagement, source, contract and legal restrictions. We require appropriate contractual terms and expect clients and suppliers to provide information lawfully and to honor applicable consumer choices.
8. Purposes for Processing Personal Information
- Provide, administer and improve consulting and data-related services.
- Respond to questions, service inquiries and privacy requests.
- Manage client, supplier and business relationships.
- Authenticate, match, correct, update, suppress, deidentify or delete records.
- Operate, maintain, analyze and secure the Website and business systems.
- Prevent fraud, misuse, unauthorized access and security incidents.
- Comply with legal obligations, enforce agreements and establish or defend legal claims.
- Create aggregate or deidentified information that is not reasonably linkable to an individual.
- Conduct other compatible activities disclosed at or before collection, or activities authorized by consent.
9. Sale, Sharing and Business-Purpose Disclosures
Under the CCPA, a “sale” may include making personal information available to another party for monetary or other valuable consideration. “Sharing” generally refers to making personal information available for cross-context behavioral advertising, whether or not money is exchanged. These definitions are broader than ordinary usage.
Because Dresden Direct provides data-related services, certain transfers to clients or data-service recipients may constitute a sale under the CCPA. If advertising, analytics or other third-party technology is used for cross-context behavioral advertising, related online transfers may constitute sharing. California consumers may opt out as described below.
We may also disclose personal information to service providers and contractors for business purposes, including hosting, security, communications, professional services, data processing, record management and request fulfillment. Contractually restricted disclosures to service providers or contractors are not treated as sales or sharing when CCPA requirements are satisfied.
Before publication, Dresden Direct must confirm and list the exact categories sold, shared and disclosed for a business purpose during the preceding 12 months. If a category was not sold or shared, the final policy should state that fact prominently.
10. Retention
We retain personal information only for as long as reasonably necessary and proportionate to fulfill the disclosed purposes, meet contractual requirements, honor opt-out and deletion choices, maintain suppression records, comply with law, resolve disputes and protect legal rights. Retention periods vary based on the type of record, source, contractual restrictions, legal requirements, security needs and whether continued retention is required to prevent reintroduction of an opted-out record. Backup information is deleted or rendered inaccessible according to the applicable backup lifecycle.
11. Data Security
We maintain reasonable administrative, technical and physical safeguards appropriate to the nature of the personal information we process. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Individuals should avoid sending sensitive information through unencrypted email or general Website forms.
12. Children and Minors
The Website and services are directed to businesses and adults and are not intended for children under 13. We do not knowingly collect personal information directly from children through the Website. Dresden Direct does not knowingly sell or share personal information of consumers under 16 without the affirmative authorization required by law. Please contact us if you believe information relating to a minor has been processed improperly.
13. California Privacy Rights
Subject to legal exceptions and verification requirements, California consumers may have the following rights:
Right to Know and Access: Request the categories and specific pieces of personal information collected, sources, purposes, categories of recipients, and sale, sharing or disclosure information.
Right to Delete: Request deletion of personal information collected from the consumer, subject to exceptions.
Right to Correct: Request correction of inaccurate personal information maintained by Dresden Direct.
Right to Opt Out of Sale or Sharing: Direct Dresden Direct not to sell or share personal information.
Right to Limit Use and Disclosure of Sensitive Personal Information: Limit covered uses or disclosures of sensitive personal information when the right applies.
Rights Relating to Certain Automated Decisionmaking Technology: Receive applicable notice and exercise access or opt-out rights if Dresden Direct uses covered automated decisionmaking technology for a significant decision.
Right to Non-Discrimination: Receive equal service and not be retaliated against for exercising CCPA rights.
14. How to Exercise Your Rights
California consumers, or authorized agents acting on their behalf, may submit requests through the following methods:
- Online privacy request form: use the “Privacy Request” or “Do Not Sell or Share My Personal Information” link in the Website footer.
- Email: phil@dresdendirect.com.
- Mail: Dresden Direct, Inc., Attn: Privacy Contact, 109 St. Edward Place, Palm Beach Gardens, FL 33418.
- Phone: 561-236-4449. This number may be used as a supplemental contact method. Add a toll-free request number if required under the company’s final CCPA applicability analysis.
A request to opt out of sale or sharing should not require account creation or identity verification beyond information reasonably needed to identify the relevant record or apply the request. Requests to know, delete or correct may require verification appropriate to the sensitivity of the information requested. Information collected for verification will be used only for verification and request fulfillment.
15. Global Privacy Control and Online Opt-Out Signals
We process recognized opt-out preference signals, including Global Privacy Control, as required by the CCPA. An opt-out signal will apply to the browser or device and to any consumer profile we can reasonably associate with that signal. Where additional information is needed to apply the choice to offline records, we may invite the consumer to provide that information without interfering with the browser-level opt-out. The Website should display a clear confirmation that the opt-out request has been honored.
16. Response Timing
We will confirm receipt of requests to know, delete and correct no later than 10 business days and generally respond no later than 45 calendar days after receipt. If reasonably necessary, the response period may be extended by an additional 45 calendar days with notice and an explanation. Requests to opt out of sale or sharing will be implemented as soon as feasibly possible and no later than 15 business days. These timeframes are subject to applicable law and may change if the law is amended.
17. Authorized Agents
An authorized agent may submit a request on a consumer’s behalf. We may require proof that the consumer authorized the agent and may contact the consumer directly to verify identity or confirm authorization, except where the agent has a valid power of attorney or another exception applies. An authorized agent should identify the consumer, provide contact information and submit documentation sufficient to demonstrate authority.
18. Third-Party Websites and Services
The Website may link to third-party websites or services. Dresden Direct is not responsible for the privacy, security, content or practices of third parties. Review the privacy notice of each third party before providing personal information.
19. Changes to this Privacy Statement
We may update this Privacy Statement to reflect changes in our practices, services, technology or legal requirements. The revised statement will be posted with a new “Last updated” date. Material changes will be communicated through an appropriate notice when required.
20. Contact
Dresden Direct, Inc.
Attn: Privacy Contact
109 St. Edward Place
Palm Beach Gardens, FL 33418
Phone: 561-236-4449
Email: phil@dresdendirect.com
Website: dresdendirect.com