LEGAL · PRIVACY POLICY

Privacy Policy

Empire Data Solutions LLC ("EDS," "we," "us") publishes commercial datasets compiled from federal, state, and local government public records. This policy describes how we collect, use, share, and protect information — and the rights you have over data we hold.

Effective: April 25, 2026 Last updated: April 25, 2026 Version: 1.0

01 Scope & who this policy covers

This policy applies to:

  • Visitors to empiredatasolution.com and our subdomains
  • Customers who purchase or license our datasets, ML APIs, or services
  • Subjects whose information appears in our compiled datasets (typically because that information is part of a public government record)

EDS is a B2B data infrastructure company. We do not sell consumer marketing data, residential phone lists, household demographics, geolocation data, or any data sourced from consumer-facing surveillance products. Every record we license comes from a documented federal, state, or local government public-record source.

Plain-English summary. If you bought a product from us, this policy explains how we handle your account info. If your name appears in one of our datasets because you're a federally-registered contractor, a licensed professional, a political donor of public record, or similar, this policy explains your rights and how to exercise them.

02 Data sources & how we collect

EDS collects information in three distinct ways:

A. Public government records (the data we license)

We acquire data through official bulk-extract APIs, FOIA requests, and authorized state-government data services. Every dataset we publish ships with a Data Dictionary identifying the exact source, extract method, and refresh cadence. Sources include but are not limited to:

SourceProviderLegal basis
SAM.gov Entity RegistryU.S. General Services AdministrationFOIA / GSA bulk extract API
SAM.gov ExclusionsGSAFOIA / public disclosure under FAR
USAspending.gov contract awardsU.S. Treasury / Bureau of Fiscal ServiceDATA Act, FFATA
FEC individual contributionsFederal Election Commission52 U.S.C. 30104(b)(3)(A); see §9 below for use restrictions
FMCSA carrier registrationsU.S. DOT / FMCSAPublic DOT register
NPI Healthcare Provider RegistryCMS NPPESHIPAA-aligned public registry (professional capacity only)
IRS Form 990 nonprofit filingsInternal Revenue ServiceIRC § 6104 public disclosure
SBA loan disclosuresU.S. Small Business AdministrationSBA FOIA reading room
State professional license rollsState licensing boards (FL DBPR, TX DOI, etc.)State public-records statutes

B. Information you provide directly

When you inquire, request a sample, or purchase a license, we collect: name, business email, company name, role, billing address, and any context you provide in free-text fields. We do not collect Social Security numbers, government ID numbers, or financial account details directly — payments are processed by Stripe under their privacy policy.

C. Information collected automatically when you use the site

Server logs (IP address, user agent, requested URL, response code, timestamp) for security and debugging. Optional analytics cookies (only with your consent — see §15).

03 How we use information

We use information for the following purposes only:

  • Compiling and licensing datasets sourced from public records to verified business and institutional buyers (the core business)
  • Order fulfillment, billing, and customer support
  • Product improvement, ML model training, and feature engineering on aggregated, de-identified, or public-record-sourced inputs
  • Compliance with legal obligations (tax, AML/sanctions, valid legal process, FEC permitted-use enforcement)
  • Site security and fraud prevention
  • Direct B2B communications about our products (customers and inquiry contacts only; opt-out always provided)

We do not use information for: behavioral advertising, profiling for ad networks, sale to consumer marketing brokers, or any purpose unrelated to our published business.

04 When we share information

We share information only as follows:

  • Sub-processors who provide infrastructure under written Data Processing Agreements: Stripe (payments), Railway (web hosting), Cloudflare (CDN/security), our self-hosted compute cluster (storage and ML inference), email infrastructure for transactional messages
  • Licensees of our datasets — but the data we license is, by definition, public-record data. We do not share customer account data with dataset licensees.
  • Legal compliance — when required by valid legal process, regulator inquiry, or to protect our rights and the rights of others
  • Business transfer — if EDS is acquired or merges, customer information may transfer subject to this policy

We do not sell customer account data to third parties. Our published datasets are licensed for permitted use under written license terms; that licensing activity is the only "sale" within the meaning of CCPA, and customer account data is not part of that sale.

05 Public-records carve-out

Why this matters. Most of what appears in our datasets is information that the federal or state government has already published as a public record — typically because the underlying entity (a federal contractor, political donor, licensed professional, registered nonprofit) is required by law to disclose it. Multiple state privacy laws explicitly exempt this category of information.

Information sourced directly from federal, state, or local government records is generally excluded from "personal information" under:

  • California Civil Code § 1798.140(v)(2) (CCPA / CPRA)
  • Virginia Consumer Data Protection Act § 59.1-571
  • Colorado Privacy Act § 6-1-1303(17)(b)
  • Connecticut Data Privacy Act, Maryland MODPA, Oregon OCPA, Texas TDPSA, and most other state comprehensive privacy laws

This exemption applies to the raw underlying records. Inferences, scores, or derived analytics built on top of those records do not automatically inherit the exemption. We disclose this distinction transparently and treat ML-derived outputs (such as our Federal Contractor Win Score) as personal information subject to all rights described in this policy where they identify natural persons.

06 Your privacy rights

Subject to applicable law and verification of your identity, you have the following rights with respect to information we hold about you:

  • Right to know. Confirm whether we hold information about you and obtain a copy.
  • Right to delete. Request that we delete information we hold about you, subject to legal exceptions (compliance, fraud, ongoing transactions).
  • Right to correct. Request correction of inaccurate information.
  • Right to opt out of "sale" or "sharing" as those terms are defined under CCPA/CPRA.
  • Right to limit use of sensitive personal information (CCPA § 1798.121).
  • Right to portability. Receive your information in a portable, machine-readable format.
  • Right to non-discrimination for exercising any of the above.

To exercise any right, use our Data Subject Request form or email privacy@empiredatasolution.com. We respond within 45 days (extendable by 45 days for complex requests, with notice). There is no fee for the first request in any 12-month period.

We do not honor requests that would require us to violate the federal disclosure mandate that placed information in the public record in the first place. For example, we will not remove a federal contractor's UEI from our SAM-derived dataset if SAM.gov continues to publish it — but we will pause our re-publication of that record where law permits and direct you to SAM.gov for source-level removal.

07 California rights (CCPA / CPRA / Delete Act)

California residents have the rights enumerated in §6 plus the following:

  • "Do Not Sell or Share My Personal Information" — exercise via the link in the site footer or by submitting a request through the Data Subject Request form
  • Delete Act / DROP integration — when EDS meets the threshold defining a "data broker" under Cal. Civ. Code § 1798.99.80, we will register with the California Privacy Protection Agency and integrate with the Data Request and Opt-out Platform (DROP) so that California residents may make a single deletion request honored across all registered data brokers
  • Authorized agents — California residents may designate an authorized agent to make requests on their behalf with proof of authorization
  • Sensitive Personal Information — we do not knowingly collect or process sensitive personal information as defined in Cal. Civ. Code § 1798.140(ae)
  • Global Privacy Control — we honor GPC signals as opt-out-of-sale requests

Categories of personal information we have collected, sold, or shared in the prior 12 months (CCPA § 1798.130(a)(5)):

CategoryCollected?Sold/Shared?
Identifiers (name, email, address)Yes (account)No
Public-record identifiers (UEI, CAGE, NPI)Yes (public records)Yes (licensed datasets)
Commercial information (purchase history)YesNo
Internet activity (server logs)YesNo
Geolocation dataNoNo
Sensitive personal informationNoNo
Biometric dataNoNo

08 Other state rights

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Maryland, Washington (My Health My Data Act, where applicable), Tennessee, Iowa, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights under those laws comparable to those described above. Use the Data Subject Request form and identify your state of residence; we will respond under the applicable state framework.

09 FEC contributor data — special restrictions

Federal restriction notice. Information sourced from Federal Election Commission contributor disclosures is subject to 52 U.S.C. § 30111(a)(4), which prohibits sale or use of FEC contributor names and addresses for commercial purposes other than (a) political fundraising by candidates, parties, or PACs; (b) journalism, academic, or nonprofit research; or (c) issue advocacy.

EDS sells FEC-derived datasets and ML scores only to verified buyers in permitted-use categories. FEC-derived products are sold through a sales-led process — not automated checkout — and we confirm and document the buyer's permitted-use category in the signed license agreement before delivery. We will not sell FEC-derived products for ordinary commercial solicitation regardless of price offered.

If your name appears in our FEC-derived datasets and you wish to be removed, note that the underlying FEC disclosure remains a public federal record beyond our control. We can stop further re-publication of your record in our datasets, but the original FEC filing persists at fec.gov.

10 Sensitive data & what we don't collect

EDS does not collect or process the following categories:

  • Social Security numbers, government ID numbers, taxpayer ID numbers (other than entity-level EINs that are public)
  • Precise geolocation data
  • Biometric or genetic data
  • Consumer health records (we license NPI provider registry data — that's a professional registry, not patient data)
  • Children's data (we have no products directed at minors)
  • Account credentials, financial account numbers, or credit reports
  • Race, religious affiliation, sexual orientation, or political beliefs of natural persons (party affiliation in FEC data is the donor's voluntarily disclosed political-committee preference, not protected belief data)

11 Data retention

  • Customer account data — retained while account is active plus 7 years for tax/audit, then deleted
  • Inquiry form submissions — 18 months unless converted to customer
  • Server logs — 90 days, then deleted or aggregated
  • DSAR audit trail — 24 months minimum (state law requirement)
  • Buyer permitted-use attestations — life of license + 7 years
  • Public-record datasets — refreshed against authoritative source on stated cadence; superseded versions retained for verification only

12 Security

We use commercially reasonable technical and organizational safeguards: TLS for all data in transit, access controls, encrypted at-rest storage for sensitive customer data, audit logging on data access, segmented infrastructure, and incident-response procedures aligned with NIST SP 800-61. Despite these measures, no system is 100% secure; if a breach occurs, we will notify affected individuals and applicable regulators consistent with state breach-notification laws (NY SHIELD, CA, TX, etc.) within statutory timeframes.

13 Children's privacy

EDS products are directed at business and institutional buyers. We do not knowingly collect information from individuals under 16. If you believe a child's information has been provided to us, contact us and we will delete it.

14 International users

EDS is based in the United States and our infrastructure is hosted in the United States. We do not knowingly market our services to individuals in the European Economic Area, United Kingdom, or other jurisdictions with data-localization or transfer restrictions. If you are accessing the site from such a jurisdiction, you do so on your own initiative and at your own risk.

15 Cookies & tracking

We use the minimum cookies necessary for site functionality. Optional analytics cookies are set only with your explicit consent through our cookie banner. We honor the Global Privacy Control (GPC) browser signal as a "Do Not Sell or Share" request. We do not use third-party advertising cookies, fingerprinting, or behavioral profiling.

16 Policy changes

We will update this policy when our practices change. The "Effective" and "Last updated" dates at the top of this page reflect the current version. For material changes affecting your rights, we will notify customers by email and post a banner on the site for 30 days prior to the change taking effect.

17 Contact & how to exercise rights

Empire Data Solutions LLC
Kentucky-registered limited liability company
UEI: HMMYRMPX6XK3 · EIN: 42-1863044

Privacy contact: privacy@empiredatasolution.com
General inquiries: support@empiredatasolution.com
To exercise privacy rights: use the Data Subject Request form

For unresolved concerns, California residents may contact the California Privacy Protection Agency at cppa.ca.gov. Other state residents may contact their state Attorney General's consumer protection division.