NFD OFFICE LLC Back to home

Privacy Policy

Last updated 30 September 2026

Contents

  1. 1. Who We Are
  2. 2. Scope of This Policy
  3. 3. Information We Collect
  4. 4. How We Collect Information
  5. 5. Why We Use Information
  6. 6. Lawful Bases for Processing
  7. 7. Cookies and Similar Technologies
  8. 8. Correspondence and Filing Records
  9. 9. Bookkeeping and Financial Data
  10. 10. Sharing and Disclosure
  11. 11. Service Providers
  12. 12. Data Retention
  13. 13. Security of Information
  14. 14. International Data Transfers
  15. 15. Your Privacy Rights
  16. 16. Privacy for Children
  17. 17. Do Not Track and Analytics Choices
  18. 18. Third Party Links
  19. 19. Data Breach Response
  20. 20. Changes to This Policy
  21. 21. How to Contact Us

This Privacy Policy explains how NFD OFFICE LLC handles information in the course of running its office operations and bookkeeping desk. The developer name behind this website is NFDOffice, and the firm that operates the desk is NFD OFFICE LLC, 837 E 1200 S, Orem - 84097-6603, United States (US). We wrote this policy in plain language so that any client, visitor or supplier can read it once and understand what happens to the information placed in our care.

1. Who We Are

NFD OFFICE LLC is a professional office operations and bookkeeping practice based in Orem, Utah. We keep records for small firms across Utah County, and we treat the information those firms entrust to the desk as the core of our work. The firm described here is the controller of the personal information discussed in this policy, meaning that the firm decides why the information is held and how it is used. The desk can be reached at the address above, by email at office@nfdoffice.lol, and by telephone on +17123454799.

Because our clients run on paper as well as screens, our privacy practice is shaped by the habits of a working clerical desk. We collect only what a task requires, we keep it under lock, we write things down once, and we destroy what has reached the end of its retention period. The same discipline that keeps a register legible keeps information safe.

2. Scope of This Policy

This policy applies to information gathered through our website at nfdoffice.lol, through email and telephone contact with the desk, and through the delivery of our six service lines to clients. It also covers information contained in correspondence, forms, invoices and retention records that we handle on behalf of a client firm.

This policy does not apply to third party websites that a visitor may reach from a link on our pages, and it does not apply to the internal privacy practices of a client firm that shares records with us. Where we process records on behalf of a client firm, that firm remains responsible for its own notices to the people whose information appears in those records.

3. Information We Collect

The information we hold falls into a small number of categories. The first is contact information such as a name, a business name, a postal address, an email address and a telephone number. The second is service information such as the services a firm has asked us to perform, the billing date agreed, and the names of the people authorised to instruct the desk.

The third category is record information, which is the substance of the bookkeeping work: entries, invoices, receipts, statements, payroll notes and correspondence. The fourth category is technical information generated when someone visits our website, such as the pages viewed and the type of device used. Technical information is limited to what a standard web server records to keep the site working and is described further in the sections on cookies and analytics.

4. How We Collect Information

Most information reaches the desk directly from a client. Someone writes to us through the enquiry form, calls the telephone number published on this site, or delivers a folder of records to the Orem office. In each case the information is supplied voluntarily by the person or firm that contacts us.

A smaller part of the information is collected automatically. When a visitor loads a page, the web server records the request in order to deliver the page and to protect the site from abuse. We do not buy personal information from data brokers, and we do not gather information from social networks for marketing purposes. Where a client firm sends us records that contain the details of its own customers or employees, we receive that information as a processor and handle it only on the instructions of the client firm.

5. Why We Use Information

We use information to answer enquiries, to prepare an engagement, to perform the bookkeeping and office operations work a client has asked for, to run invoice cycles on the agreed date, and to produce month-end closeups. We also use it to keep our own records in order, to meet accounting and tax obligations, and to protect the desk against fraud or misuse.

A second purpose is communication. We use contact details to reply to questions, to confirm instructions, to raise an item that needs a document, and to send the signed trial sheet that closes each month. We keep that communication narrow: we do not send marketing to people who have not asked for it, and we do not add a client to a mailing list as a condition of service.

6. Lawful Bases for Processing

Where the law requires a lawful basis, we rely on a small set. We process information to perform a contract when a firm has engaged us to keep its books or run its invoices. We rely on legitimate interests to operate and secure our website and to answer the enquiries that arrive at the desk. We rely on legal obligation to keep accounting records for the periods the law requires and to respond to lawful requests.

Where we handle the customer or employee details of a client firm, we do so on the documented instructions of that firm and not for our own independent purposes. If a person wishes to withdraw consent that was the basis for a particular communication, they may write to the desk and the communication will stop, subject to any record we must keep for accounting reasons.

7. Cookies and Similar Technologies

Our website is deliberately simple and does not rely on advertising cookies. We may use a small number of strictly necessary cookies or local storage entries to remember a preference such as an open navigation state. These entries do not identify a person and are not used to build a profile or to track a visitor across other sites.

A visitor may block or delete cookies through browser settings at any time. Blocking strictly necessary entries will not prevent the pages from loading, because the site is built to work without them. We do not sell cookie data, and we do not permit third parties to set advertising cookies through our pages.

8. Correspondence and Filing Records

Correspondence and filing is one of our service lines, and it means we handle the letters, statements and notices that pass between a client firm and the outside world. When we process that correspondence we see the names, addresses and business details that appear on it. We date-stamp each item, file it against the correct client sheet, and use it only for the administration of the engagement.

Correspondence is kept for the period set out in the retention ledger agreed with the client firm. At the end of that period the item is listed and destroyed according to plan. Where an item is subject to a dispute or a review, it is added to a do-not-destroy list and held until the matter is closed, after which the normal schedule resumes.

9. Bookkeeping and Financial Data

Bookkeeping in triplicate means that financial information is written once and pressed through carbon into three copies. The information in those copies includes transactions, amounts, counterparty names and the dates on which money moved. That information is confidential, and it is held under the same access controls as every other client record at the desk.

We do not use client financial information for our own purposes. We do not lend it, sell it or trade it. Where a client asks us to share a closeup with an accountant, a lender or a tax preparer, we do so on the written instruction of the client firm, and we confirm the identity of the recipient before anything is sent. Financial records are retained for the period the law requires and for no longer than the engagement needs.

10. Sharing and Disclosure

We share information only in a narrow set of circumstances. We share it with a client firm when performing the services that firm has requested. We share it with a professional adviser, such as an accountant, when the client has instructed us to do so. We share it when the law requires, such as in response to a valid court order or a lawful request from a regulator.

We do not sell personal information. We do not rent it, trade it or exchange it for marketing access. If the firm is ever reorganised, merged or sold, records may transfer as part of that transaction, and any successor would be bound by this policy or by a policy at least as protective as this one. In every case where we disclose information, we disclose the minimum that the purpose requires.

11. Service Providers

A working desk uses a small number of service providers, such as an email host, a web hosting company and a payment or banking service. Those providers may process information on our behalf while delivering their service. We select providers carefully and we require them to protect information and to use it only for the purpose for which they were engaged.

A provider that supports our email or our website will not be permitted to use client information for its own marketing. Where a provider is located outside the United States, we take reasonable steps to ensure the information remains protected, as described in the section on international data transfers. We review our provider list from time to time and remove any provider that no longer meets our standard.

12. Data Retention

We keep information only for as long as a purpose requires. Enquiry messages that do not lead to an engagement are kept for a short period and then removed. Engagement records are kept for the duration of the relationship and for the retention period agreed with the client firm. Financial and tax records are kept for the periods required by accounting and tax rules.

Destruction is planned rather than incidental. When a retention period ends, the record is listed, approved and destroyed on a set date, and the destruction itself is recorded in the retention ledger. This habit means that a client can ask what is held, why it is held and for how long, and receive a clear answer from the same book that governs the desk.

13. Security of Information

We protect information with a set of ordinary and effective measures. Paper records are kept in locked cabinets in the office at 837 E 1200 S, Orem - 84097-6603, United States (US). Digital records are held on access-controlled systems protected by strong credentials, and access is limited to the people who need it to perform a task. We keep backups so that records survive an equipment failure.

No method of storage or transmission is perfectly secure, and we do not claim otherwise. We review our measures regularly, we train the people who work at the desk on confidentiality, and we act promptly when a weakness is found. If a security incident ever affects personal information, we respond under the section on data breach response below.

14. International Data Transfers

The desk operates in the United States, and the information we hold is normally stored within the United States. If a service provider stores information in another country, we take reasonable steps to ensure the same level of protection travels with it. Those steps include reviewing the provider security program and relying on contractual protections where they are available.

A person who wishes to know where a particular record is stored may write to the desk and we will answer plainly. Where a transfer would create a risk that we cannot reasonably manage, we will look for an alternative provider or an alternative method of handling the record.

15. Your Privacy Rights

Depending on where a person lives, the law may grant rights over their personal information. Those rights can include the right to know what is held, the right to request a copy, the right to correct an error, the right to request deletion, and the right to object to certain uses. We honour these rights for everyone who asks, whether or not a particular law compels us, subject to the records we must keep for accounting and legal reasons.

To exercise a right, write to office@nfdoffice.lol or send a letter to the Orem address. We will confirm what we hold and act on a valid request within a reasonable period, normally within thirty days. We may ask for enough information to verify identity before we release a record, because we will not hand a client file to someone who cannot show they are entitled to it. If we decline a request, we will explain the reason in writing.

16. Privacy for Children

Our services are designed for businesses and are not directed at children. We do not knowingly collect personal information from a child under the age of thirteen, and we do not market to children. If a parent or guardian believes that a child has sent information to the desk, they may contact us and we will remove it promptly.

Because our work is a business service, the people whose details appear in a client record are normally adults acting in a commercial or employment capacity. Where a client firm provides information about a minor, that firm is responsible for obtaining any consent the law requires before sharing it with us.

17. Do Not Track and Analytics Choices

Some browsers can send a do not track signal. Our website does not track visitors across other sites, and we do not use a third party advertising network that would respond to such a signal. Where we measure site use at all, we do so in aggregate to keep the pages working, and not to follow an individual from one site to the next.

A visitor who wishes to limit measurement may use the privacy settings of their browser or an extension that blocks third party requests. Such a choice will not prevent the site from working, because the essential pages are served without tracking scripts.

18. Third Party Links

Our pages may link to another website, such as a professional body or a resource a client has asked us to reference. When a visitor follows such a link they leave our site and become subject to the privacy policy of the destination. We do not control that policy and we cannot vouch for the practices of a site we do not operate.

We choose links with care and review them from time to time, but a link is not an endorsement of every practice at the destination. We encourage a visitor to read the privacy notice of any site before providing personal information to it.

19. Data Breach Response

If we become aware of a security incident that affects personal information, we act quickly. We contain the incident, assess what was affected, and take steps to prevent a repeat. Where the law requires notification, we notify the affected people and the relevant authorities without undue delay, and we describe what happened in plain language.

We keep an incident record so that lessons are not lost. That record notes what was found, how it was handled and what changed as a result. A client who wishes to ask about an incident that may have affected their records may contact the desk at any time and we will answer honestly.

20. Changes to This Policy

We may update this policy when our practice changes or when the law requires. The date at the top of the page shows when the current version took effect. If a change is material, we will make it clear on this page and, where we hold contact details, we will notify the firms affected.

Continued use of our website or services after an update means that the current version applies. We encourage a reader to return to this page from time to time, and we keep every version so that a client can compare what was promised at the time they engaged us.

21. How to Contact Us

If you have a question about this policy, a request about your information, or a concern about how the desk has handled a record, please contact us. We answer every privacy message, and we answer it plainly.

NFD OFFICE LLC 837 E 1200 S
Orem - 84097-6603
United States (US)
Email: office@nfdoffice.lol
Telephone: +17123454799

A written request is best, because it creates a dated record that we can trace through the desk. We will acknowledge your message, tell you what we can do, and keep you informed until the matter is closed. That promise is the same one we make to every client firm whose paper passes across this desk.

NFD OFFICE LLC, 837 E 1200 S, Orem - 84097-6603, United States (US)

Return to the homepage