Privacy Policy

Effective September 15, 2026 Last updated September 15, 2026

Who we are and what this covers

Breakaway Cyber, LLC ("Breakaway," "we," "us") is a Virginia limited liability company providing artificial intelligence and cybersecurity advisory, go-to-market, technology evaluation, and personnel recruiting services to federal government and commercial clients.

This policy explains how we handle personal information collected through 2breakaway.com and through the ordinary course of our business relationships. It does not govern information we process on behalf of a client under a separate services agreement; in those engagements the client is the controller of the data and its own privacy terms apply.

Information we collect

Information you give us

Our contact form asks for your name, work email address, company (optional), the category that best describes you, and your message. We collect what you choose to put in those fields. You may also send us information directly by email, by phone, or during meetings and engagements.

Information collected automatically

When you visit the site, our hosting provider records standard technical information including IP address, browser type and version, operating system, referring page, pages viewed, and the date and time of the request. This is generated automatically by web servers and is used for security, troubleshooting, and aggregate traffic measurement.

Candidate and referral information

Our recruiting practice involves collecting information about candidates for leadership, revenue, and delivery roles. This may include résumés, employment and education history, professional certifications, clearance eligibility as disclosed by the candidate, compensation expectations, references, and interview notes. We collect this from candidates directly, from referrals, and from professional networking and job platforms where a candidate has made the information available.

Business contact information

We maintain a professional network of technology vendors, contracting organizations, security leaders, and enterprise decision makers. Records typically include name, employer, role, business contact details, and notes about professional interests relevant to our work.

We ask that you not send sensitive personal information — government identification numbers, financial account details, health information, or classified or controlled material — through the contact form or unencrypted email.

Cookies and analytics

We use a small number of cookies and similar technologies:

  • Strictly necessary. Required for the site to function and to protect it against abuse. These cannot be switched off.

We do not currently use analytics or advertising cookies, and we do not permit third parties to use our site to build advertising profiles. If we add analytics in future, we will update this policy first, name the provider, and — where the law requires it — ask for your consent before any non-essential cookie is set.

You can control cookies through your browser settings, though blocking strictly necessary cookies may prevent parts of the site from working.

Some browsers transmit a Global Privacy Control or similar opt-out preference signal. Where we are required to honor such a signal, we treat it as a valid request to opt out of targeted advertising and the sharing of personal information.

How we use information

  • To respond to inquiries submitted through the contact form or sent to us directly.
  • To provide advisory, evaluation, go-to-market, staffing, and recruiting services, and to manage the resulting client and vendor relationships.
  • To match candidates with roles, and to present candidates to clients with the candidate's knowledge.
  • To make introductions between the technologies we represent and members of our professional network, where relevant to that person's role and interests.
  • To send business communications about our services. Where these are marketing messages, you can opt out at any time using the unsubscribe link or by emailing us.
  • To operate, secure, and improve the website, and to detect and prevent fraud or abuse.
  • To meet legal, regulatory, contractual, and government contracting obligations, and to establish or defend legal claims.

Legal bases for processing

For individuals in the European Economic Area and the United Kingdom, we process personal information on the following bases:

  • Legitimate interests — operating and securing our website, conducting business-to-business outreach relevant to a recipient's professional role, managing client and vendor relationships, and carrying out recruiting activity. We balance these interests against your rights and expectations.
  • Performance of a contract — delivering services and managing engagements with clients, vendors, and contractors.
  • Consent — where required, such as non-essential cookies and certain marketing communications. You may withdraw consent at any time.
  • Legal obligation — record keeping, tax, and compliance requirements, including those arising from government contracting.

How we share information

We share personal information only as described here:

  • Service providers. Hosting, email, customer relationship management, analytics, applicant tracking, scheduling, and similar vendors that process information on our instructions and under contract.
  • Clients and prospective employers. Candidate information is shared with the client considering that candidate, with the candidate's knowledge.
  • Technology partners and contracting organizations. Where you have asked for an introduction, or where the exchange is a necessary part of an engagement.
  • Professional advisers. Lawyers, accountants, auditors, and insurers, subject to confidentiality obligations.
  • Legal and safety. Where required by law, court order, or lawful government request, or to protect the rights, property, or safety of Breakaway, our clients, or others.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the protections in this policy.

No sale of personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under sixteen.

How long we keep information

We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires. In practice: contact form submissions and related correspondence are retained for two years; candidate records are retained for one year unless the candidate asks us to remove them sooner; client engagement records are retained for the term of the engagement and the period required by contract, tax, and government contracting rules; and server logs are generated and retained by our hosting provider on its own schedule, which we do not control. When information is no longer needed we delete it or render it anonymous.

How we protect information

Security is our professional discipline, and we apply it to our own systems. We use access controls and least-privilege permissions, multi-factor authentication on business accounts, encryption in transit and at rest where supported by our providers, vendor security review, and logging and monitoring appropriate to a firm of our size.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires it.

International transfers

We operate from the United States, and information we collect is processed there. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data transfer restrictions, your information will be transferred to a country whose data protection laws may differ from your own. Where such transfers require a safeguard, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism. You may request a copy of the relevant safeguard using the contact details below.

Your privacy rights

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, disclose, and retain; to request access to it in a portable form; to request correction of inaccurate information; to request deletion; to opt out of sale or sharing (we do neither); and to limit the use of sensitive personal information (we do not use it for purposes that trigger this right). We will not discriminate against you for exercising any of these rights, and we do not offer financial incentives in exchange for personal information. You may use an authorized agent, and we may ask that agent for proof of authorization.

EEA and UK residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right to access your personal information; to have inaccurate information corrected; to have it erased in certain circumstances; to restrict or object to processing, including processing based on legitimate interests and direct marketing; to data portability; and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your national supervisory authority or, in the United Kingdom, the Information Commissioner's Office.

Virginia residents (VCDPA)

If you are a Virginia resident and the Virginia Consumer Data Protection Act applies to our processing of your information, you have the right to confirm whether we process your personal data and to access it, to correct inaccuracies, to request deletion, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling. You may appeal a decision we make about your request by replying to our response; if we deny the appeal, you may contact the Virginia Attorney General.

Other states

Residents of other states with comprehensive privacy laws may have comparable rights. We extend the rights described above to any individual who requests them, regardless of where they live, to the extent we are able.

Exercising your rights

Email info@2breakaway.com with the subject line "Privacy request" and tell us what you would like us to do. We will acknowledge your request and respond within the period the applicable law requires — generally forty-five days under United States state privacy laws and one month under the GDPR, each extendable where a request is complex.

We will take reasonable steps to verify your identity before acting, usually by confirming that you control the email address associated with the information, and we may ask for additional detail if the request is broad. Verification is a safeguard for you: we will not hand personal information to someone who cannot demonstrate a right to it.

Children

Our website and services are directed to businesses and working professionals, not to children. We do not knowingly collect personal information from anyone under sixteen. If you believe a child has provided us with personal information, contact us and we will delete it.

Third-party sites

Our site may link to websites operated by partners, clients, or other organizations. We do not control those sites and are not responsible for their privacy practices. Review the privacy policy of any site before providing personal information to it.

Changes to this policy

We may update this policy as our practices, technology, or legal obligations change. The effective date at the top of the page shows when the current version took effect. If we make a material change, we will take reasonable steps to notify you, which may include posting a notice on the site or contacting you directly. Continued use of the site after a change takes effect means you accept the updated policy.

Contact us

Questions about this policy, or about how we handle your personal information, can go to:

Entity
Breakaway Cyber, LLC
Email
info@2breakaway.com
Website
2breakaway.com