Privacy Policy

Last updated: Nov 20, 2025

1. Introduction

OnPath Testing (“we”, “us”, “our”) provides software consulting and related services to clients in various countries. This Privacy and Security Policy explains how we collect, use, disclose, and protect personal information when you visit our website, interact with our content, or communicate with us.

By using our website, submitting information through our forms, or otherwise providing personal information to us, you acknowledge that you have read and understood this Policy.

2. Who we are and contact details

The data controller responsible for your personal information is:

  • Legal entity: OnPath Testing Inc, a State of Colorado corporation within the USA
  • Address: 2525 Arapahoe Ave E4-150, Boulder, CO 80302
  • Email: info@onpathtesting.com
  • Phone: +1-303-479-4994

If you have questions about this Policy or how your information is handled, you can contact us at the details above.

3. Information we collect

3.1 Information you provide directly
When you use our website or interact with us, we may collect personal information that you choose to provide, including but not limited to:
  • Name and contact details (such as email address and phone number).
  • Job title, company name, and industry.
  • Content of messages you send through contact forms, email, or chat.
  • Marketing preferences and subscription details for newsletters or updates.

If you engage us for services, we may also collect billing details and limited account administration information for you and your team.

3.2 Information collected automatically
When you visit our website, we may automatically collect certain technical information, such as, but not limited to:
  • IP address, browser type, device identifiers, and operating system.
  • Pages viewed, links clicked, referring/exit pages, and visit timestamps.
  • General location information derived from your IP address.

This information is usually collected via cookies, analytics tools, and similar technologies (see “Cookies and similar technologies” below).

3.3 Information from third parties

We may receive limited personal information about you from:

  • Business partners or referrals (for example, when another client introduces you).
  • Publicly available sources such as LinkedIn or company websites, in a B2B context.

4. Legal bases for processing (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases to process personal information:

  • Performance of a contract: To take steps at your request before entering into a contract or to perform a contract with you.
  • Legitimate interests: To operate, secure, and improve our business and services, provided these interests are not overridden by your rights and interests.
  • Consent: For certain marketing or optional cookies where required by law.
  • Legal obligations: To comply with applicable laws, regulations, and court orders.

5. How we use personal information

We use the personal information described above for the following purposes:

  • To respond to your inquiries, demo requests, and contact form submissions.
  • To provide, administer, and manage consulting services and projects.
  • To operate, maintain, and improve our website, including analytics and troubleshooting.
  • To send you marketing communications about our services, events, or content where permitted by law and according to your preferences.
  • To manage our business relationships, CRM records, invoicing, and client communications.
  • To detect, prevent, and respond to security incidents, fraud, and misuse of our website.
  • To comply with applicable legal and regulatory requirements and enforce our agreements.

6. Cookies and similar technologies

Our website may use cookies, pixels, and similar technologies to:

  • Enable core site functionality (for example, form submissions and session management).
  • Collect analytics about how visitors use our website to help us improve content and performance.
  • Remember your preferences (such as language or cookie choices).

Where required by law, you will be presented with a cookie banner or consent tool that allows you to accept or manage non-essential cookies. You can also configure your browser to refuse or delete cookies, though this may affect some website features.

7. How we share information

We do not sell personal information for monetary compensation. We may share personal information with the following categories of recipients where appropriate:

  • Service providers and vendors that assist with website hosting, analytics, email delivery, CRM, project management, and similar functions.
  • Onshore and offshore engineers and subcontractors engaged to deliver services to you, subject to contractual confidentiality and data protection obligations.
  • Professional advisers (such as legal, tax, or accounting advisers) where necessary to support our business.
  • Potential buyers, investors, or other third parties in connection with a corporate transaction, subject to appropriate safeguards.
  • Public authorities or other third parties where required by law, regulation, legal process, or to protect our rights or the rights of others.

Where we engage third parties, they are only allowed to process personal information as necessary to perform services on our behalf and must implement appropriate security measures.

8. International transfers

Because we work with clients and engineering teams in multiple countries, your personal information may be transferred to and processed in jurisdictions outside your own, including countries that may not provide the same level of data protection as your home country.

Where required by GDPR or UK GDPR, we implement appropriate safeguards for such transfers, such as:

  • Relying on adequacy decisions for certain countries, where applicable.
  • Using standard contractual clauses or similar safeguards for transfers to our service providers or partners.
  • Implementing internal policies and procedures to protect personal information across our group and contractor network.

9. Data retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Policy or as required by law. Factors that influence retention periods include:

  • The duration of our business relationship with you or your company.
  • Legal, tax, and regulatory requirements for record-keeping.
  • The time needed to resolve disputes, enforce agreements, and maintain security logs.

When personal information is no longer required, we will delete, anonymize, or otherwise securely dispose of it.

10. Your rights

Depending on your location and applicable law (for example, GDPR, UK GDPR, CCPA/CPRA, and other national laws), you may have rights such as:
  • Access: To request confirmation of whether we process your personal information and to obtain a copy.
  • Rectification: To request correction of inaccurate or incomplete information.
  • Erasure: To request deletion of your personal information in certain circumstances.
  • Restriction: To request that we limit use of your information in certain circumstances.
  • Objection: To object to processing based on legitimate interests or for direct marketing.
  • Portability: To receive certain information in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Withdrawal of consent: Where processing is based on consent, to withdraw that consent at any time without affecting prior processing.

If you are a resident of California or certain other US states with privacy laws, you may also have specific rights regarding “sale” or “sharing” of personal information, sensitive information, and the right not to be discriminated against for exercising your rights.

You can exercise your rights by contacting us using the details in Section 2, and we will respond as required by applicable law. We may need to verify your identity before fulfilling your request.

11. Marketing communications

Where permitted by law, we may send you emails or other communications about our services, events, or content that we think may be relevant to your role or organization. You can opt out at any time by:

  • Clicking the “unsubscribe” link in marketing emails; or
  • Contacting us at info@onpathtesting.com with your request.

Opting out of marketing will not affect important service or transactional communications related to active projects or contracts.

12. Children’s privacy

Our website and services are directed at business professionals and are not intended for children under the age of 16. We do not knowingly collect personal information from children; if you believe a child has provided us with personal information, please contact us so we can delete it where required.

13. Security measures

We use a combination of technical, organizational, and physical safeguards to help protect personal information from unauthorized access, use, alteration, or destruction. These measures may include:

  • HTTPS/TLS encryption for data in transit on our website.
  • Access controls and authentication for internal systems and tools.
  • Role-based access for our staff and contractors, following the principle of least privilege.
  • Use of reputable hosting providers and security configurations aligned with industry best practices.
  • Regular patching and updates of key systems and dependencies.
  • Employee and contractor confidentiality agreements and security awareness practices.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we aim to maintain safeguards proportionate to the risks associated with our processing activities.

14. Use of onshore and offshore engineers

In delivering consulting and engineering services, we may use both onshore and offshore personnel and subcontractors. These individuals or entities may access limited personal information where necessary to perform their work, such as contact details and project-related context.

All such access is governed by written agreements that include confidentiality, data protection, and security obligations, as well as internal policies that restrict access to what is necessary for the assigned tasks.

15. Third‑party websites and services

Our website may contain links to third‑party websites, content, or services (including external blogs, social media, or partner sites). This Policy does not govern those third parties, and we are not responsible for their privacy or security practices.

You should review the privacy policies of any third‑party websites or services you visit or use.

16. Changes to this Policy

We may update this Privacy and Security Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, provide additional notice.

Your continued use of our website or services after changes take effect will signify that you have read and understood the updated Policy, to the extent permitted by law.

17. How to contact us or lodge a complaint

If you have questions or concerns about this Policy or how we handle personal information, you can contact us using the details in Section 2.

If you are in the EU, EEA, UK, or another jurisdiction with a supervisory authority, you may also have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal information violates applicable law.

document.addEventListener("DOMContentLoaded", function () { var shareMailBtn = document.getElementById('shareMail'); if (!shareMailBtn) return; shareMailBtn.addEventListener('click', function (e) { e.preventDefault(); const subject = encodeURIComponent(document.title); const body = encodeURIComponent( `Hi, I came across this article on OnPath Testing and thought it would be worth sharing with you. ${window.location.href} Hope you find it useful. Best regards,` ); window.location.href = `mailto:?subject=${subject}&body=${body}`; }); });