
Privacy Policy
DEROR Advisors LLC and DEROR Advisors USA LLC (“DEROR,” “we,” “our,” or “us”) are committed to protecting the privacy, confidentiality, and security of personal and organizational information. This Privacy Policy outlines how we collect, use, store, disclose, and safeguard information obtained through our websites, digital platforms, communications, and professional services.
As a strategic consulting and capacity-building firm, DEROR recognizes that responsible information management is essential to maintaining trust and meeting our professional, contractual, and legal obligations. We process information transparently and in accordance with applicable U.S. federal, state, territorial, and other privacy requirements.
This Privacy Policy describes:
-
The types of personal and organizational information we collect;
-
How and why we use, process, and retain information;
-
How information is stored and protected;
-
When information may be shared with authorized service providers or other parties;
-
The safeguards implemented to protect confidential information; and
-
The rights and choices available to individuals regarding their personal information.
Information We Collect
DEROR collects only the information necessary to provide requested services, manage client relationships, operate our business, comply with legal and contractual obligations, and improve our services and digital platforms.
Depending on the nature of the engagement, information collected may include the following:
-
Contact and identification information;
-
Organizational records and business information;
-
Governance and board documentation;
-
Financial, accounting, and funding information;
-
Grant, donor, and compliance documentation;
-
Human resources information provided by clients;
-
Project files, assessments, reports, communications, and consulting deliverables;
-
Website, portal, and customer support information.
We do not collect unnecessary personal information or retain information beyond its intended purpose, unless required for legal, contractual, regulatory, or legitimate business reasons.
How We Use Your Information
DEROR uses personal and organizational information only for legitimate business, contractual, operational, and legal purposes, including the following:
-
Delivering consulting, advisory, training, accounting support, compliance, and capacity-building services;
-
Preparing proposals, agreements, reports, assessments, invoices, and client deliverables;
-
Communicating with clients, prospective clients, and stakeholders;
-
Managing payments, billing, records, and business administration;
-
Operating, maintaining, securing, and improving our websites, systems, and technology platforms;
-
Conducting analytics and improving user experience through cookies and similar technologies;
-
Detecting, preventing, and responding to security incidents, fraud, or unauthorized activity;
-
Complying with applicable laws, regulations, contractual obligations, and professional standards; and
-
Protecting DEROR’s, our clients’, and other parties’ legal rights and interests.
Information Processing and Transfer
DEROR collects, reviews, organizes, stores, transmits, and securely disposes of information as needed to perform contracted services and operate our business.
Because we operate through DEROR Advisors LLC in Puerto Rico and DEROR Advisors USA LLC in the United States, information may be securely accessed, processed, or transferred between these affiliated entities when necessary to:
-
Deliver contracted services;
-
Coordinate client support;
-
Maintain operational continuity;
-
Perform quality assurance;
-
Process billing; or
-
Administer business operations.
These transfers are limited to legitimate business purposes and subject to confidentiality and security safeguards.
Sharing Information with Third Parties
DEROR may share limited information with carefully selected third party, service providers that support our operations, including providers of:
-
Cloud hosting and secure data storage;
-
Client relationship management systems;
-
Accounting and financial platforms;
-
Payment processing services;
-
Communication and collaboration tools;
-
Cybersecurity and information technology services;
-
Electronic signature and workflow platforms;
-
Backup and disaster recovery services; and
-
Professional legal, accounting, auditing, or compliance services.
Third party, service providers receive only the information needed to perform contracted services and must maintain appropriate confidentiality, security, and data protection measures. They are not authorized to use personal information for their own marketing or independent commercial purposes.
DEROR does not sell personal information or disclose personal information for cross-context behavioral advertising.
Information Security and Confidentiality
DEROR maintains administrative, technical, physical, and organizational safeguards to protect information from unauthorized access, disclosure, alteration, misuse, loss, or destruction.
Security practices may include:
-
Access controls based on business need;
-
Multi-factor authentication and secure credential practices;
-
Encryption and secure transmission methods;
-
Secure cloud-based technology platforms;
-
Backup and recovery procedures;
-
Confidentiality agreements and information-handling policies;
-
Employee and contractor security awareness practices; and
-
Periodic review of security practices and third-party providers.
Sensitive information, such as financial records, governance documents, personnel information, donor information, tax documentation, and compliance materials, receives additional safeguards appropriate to its nature and confidentiality level.
While DEROR implements security measures, no electronic transmission, storage method, or information system can be guaranteed completely secure.
Information Storage and Secure Disposal
DEROR may store information in secure cloud-based applications, document management systems, accounting platforms, client management systems, communication platforms, backup systems, and other business technologies maintained by DEROR or authorized third party, service providers. We retain the information as long as required to:
-
Fulfill contractual obligations;
-
Maintain business and professional records;
-
Comply with tax, accounting, legal, regulatory, and audit requirements; and
-
Protect legitimate business interests.
When the information is no longer required, DEROR will securely delete, destroy, anonymize, or render it inaccessible according to applicable retention practices. Information in secure backup systems may remain protected until deleted through routine system processes.
Your Rights Regarding Information
Depending on applicable laws, individuals may have rights regarding their personal information, including:
-
Requesting access to personal information maintained by DEROR;
-
Requesting correction of inaccurate information;
-
Requesting deletion of personal information, subject to legal and contractual exceptions;
-
Requesting information regarding how personal information is used or disclosed;
-
Restricting or objecting to certain processing activities where applicable;
-
Withdrawing consent where processing is based on consent; and
-
Requesting a portable copy of certain information where required by law.
Organizations that collaborate with DEROR retain ownership and control of their organizational records unless otherwise agreed by contract. Clients may request access to, correction of, return of, or secure disposal of organizational information, subject to legal, contractual, and retention requirements.
Privacy rights vary depending on jurisdiction, the type of information involved, and DEROR’s role in processing the information.
Privacy Requests
Individuals may submit requests regarding this privacy policy by contacting DEROR at privacy@deror-advisors.net.
To protect confidential information, DEROR may require identity verification before processing requests. We will respond within the timeframe required by the applicable law. Requests may be limited or denied when permitted by law, including when compliance would conflict with legal obligations, contractual responsibilities, security requirements, confidential business information, or the rights of others.
Where permitted by law and where appropriate documentation of authorization is provided, authorized representatives may submit requests on behalf of individuals.
Updates to This Privacy Policy
DEROR may update this Privacy Policy to reflect changes in our services, technology, operational practices, or legal requirements. Updates become effective when posted on our website with the revised effective date.
We encourage users and clients to review this Privacy Policy periodically to remain informed about how DEROR protects information.
Effective Date: July 24, 2026

© 2026 DEROR Advisors LLC. All rights reserved.

