Website Privacy Policy: Iron Pen Studios LLC

1. ENTITY IDENTIFICATION AND OPERATIONAL SCOPE

This Privacy Policy establishes the comprehensive regulatory and cybersecurity framework governing data processing for the official digital properties and integrated service components of Iron Pen Studios LLC. As a 100% P&T Service-Disabled Veteran-Owned Small Business (SDVOSB), the firm operates under a mandate of rigorous confidentiality and federal compliance.

Organizational Identifiers:

  • Legal Entity: Iron Pen Studios LLC

  • Socioeconomic Status: Service-Disabled Veteran-Owned Small Business (SDVOSB)

  • Location of Registry: Ocala, Florida

  • Commercial and Government Entity (CAGE) Code: 219W4

  • Unique Entity ID (UEI): FYA3ZBT3BX35

2. COLLECTION OF PERSONALLY IDENTIFIABLE INFORMATION (PII)

Iron Pen Studios LLC utilizes standardized intake channels to facilitate service procurement. Data collection is strictly limited to information necessary for project execution and federal reporting requirements.

Primary Intake Channels:

  • Web Interface: Official Squarespace-hosted domain.

  • Project Management Integration: Embedded HoneyBook Lead capture iframe.

Data Classifications Collected: Data points include, but are not limited to: Legal Name, Contact Information (Electronic Mail and Telephonic), and Project-Specific Technical Requirements.

Privacy Act Logic and Mandatory Disclosures: In alignment with the logic established in 38 U.S.C. 5701 and the Privacy Act of 1974, the provision of PII is voluntary; however, failure to furnish requested information constitutes a waiver of eligibility for service. Iron Pen Studios LLC will be unable to process procurement requests or fulfill project deliverables without the requisite data. This intake process mirrors the "Notice of Systems of Records" protocols, ensuring that all submissions are utilized solely for the determination of eligibility and technical execution.

3. TECHNICAL DATA PROCESSING AND AUTOMATION ARCHITECTURE

The firm employs a serverless, event-driven backend architecture hosted on the Google Cloud Platform (GCP). This environment is engineered to ensure high availability and cryptographic integrity.

Deterministic Asset Generation: The "transcribe-on-upload" logic is executed via a proprietary Python Cloud Function. The architecture triggers the deterministic generation of accessibility assets through the following sequence:

  • Trigger Mechanism: Automated execution is initiated by GCS Bucket event triggers upon file ingestion.

  • Processing Environment: Logic is executed within ephemeral environments, ensuring that processing instances exist only for the duration of the task, thereby minimizing the attack surface.

  • Technical Logic: Dual-channel stereo transcription is achieved via Google’s Speech-to-Text API.

  • Regulatory Deliverables: The architecture is designed to produce Section 508 and WCAG 2.2 Level AA compliant assets (SRT and VTT formats) as a standard output.

4. DATA SECURITY AND CRYPTOGRAPHIC ISOLATION

Iron Pen Studios LLC utilizes a defense-in-depth strategy to maintain the confidentiality and integrity of client data.

  • Cloud Isolation: Client data is stored within Google Cloud Storage (GCS) client vaults. These vaults utilize IAM-level isolation (Identity and Access Management) and Encryption at Rest through Customer-Managed Encryption Keys (CMEK) to ensure that project-level data remains segregated.

  • 3-Tier Storage Architecture:

    1. Tier 1 (Active Production): Secured GCP environments utilizing the aforementioned cryptographic controls.

    2. Tier 2 (Internal Management): A secondary administrative layer within Google Drive for project coordination.

    3. Tier 3 (Physical Redundancy): For disaster recovery, data is moved to "air-gapped" offline storage.

  • Hardware Specifications: Physical backups are maintained on high-performance, secure, APFS-formatted 2TB Samsung T7 SSDs.

5. DATA LIFECYCLE MANAGEMENT: RETENTION AND SANITIZATION

To ensure data integrity and prevent the corruption of master assets, the following protocols are enforced:

  • The "Never Overwrite" Rule: A primary integrity standard where original source files are maintained in a read-only state throughout the production lifecycle.

  • Deterministic Versioning: Strict file versioning protocols are utilized to track changes without compromising the master data set.

  • Sanitization Protocols: Upon project conclusion and the expiration of the defined retention period, data undergoes sanitization or permanent deletion in accordance with NIST-aligned security standards to ensure no residual data remains on active or backup tiers.

6. MULTIMEDIA CONTENT AND SECURE DISTRIBUTION

The firm maintains a strict non-publication mandate. Iron Pen Studios LLC does not host, publish, or permit third-party or user-uploaded multimedia content on public-facing platforms.

  • Private Asset Classification: All generated deliverables and source media are classified as strictly private.

  • Secure Delivery Gate: Distribution is conducted exclusively via Samply links. These links serve as a secure access gate requiring unique authentication/authorization; they are not public URLs and are restricted to authorized recipients only.

7. COMPLIANCE CONTACT BLOCK

Inquiries regarding data rights, policy adherence, or the firm’s cybersecurity posture should be directed to the Principal Engineer:

Jovan Willis Owner & Principal Engineer Phone: (352) 566-4179 Email: jovanwillis@ironpenstudios.com Address: 16282 SW 16th Ct, Ocala, FL 34473

8. GOVERNING LAW AND REGULATORY ALIGNMENT

This policy is governed by and construed in accordance with the laws of the State of Florida. The exclusive venue for any disputes arising from this policy or data processing activities shall be the courts of Marion County, Florida.

Iron Pen Studios LLC affirms its commitment to Federal Section 508 standards and the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA. Furthermore, this policy’s PII handling and confidentiality procedures are designed to mirror the rigorous standards of the Privacy Act of 1974 and 38 U.S.C. 5701, adapted for private-sector LLC operations.