ROCKY AIR

Privacy Policy

ROCKY MOUNTAIN AIR, LLC | LAFAYETTE, COLORADO
Effective and last revised: January 1, 2026
  • Home
  • Services
  • Contact
  • Privacy
  • Terms of Service

This Privacy Policy explains how ROCKY MOUNTAIN AIR, LLC, a company organized under the laws of Colorado with its registered address at 605 Mills St, Lafayette - 80026, United States (US), collects, uses, stores, discloses and protects information relating to visitors of the website located at https://www.rockyair.lat/ and to users of the air monitoring, environmental sensing and reporting services described throughout the site. The services described on this website are developed and operated by the independent software developer Rocky Air, who acts on behalf of ROCKY MOUNTAIN AIR, LLC. This Privacy Policy is intended to give individuals a clear and thorough account of the data lifecycle that governs the public website, the account portals, the station portals and any supporting applications that connect to the mountain air monitoring networks that the company builds and maintains. Please read this document carefully. By continuing to browse the website, to contact the company or to use any paid or free monitoring service, you acknowledge the practices described below and the choices available to you. If you do not agree with any provision of this Privacy Policy, please do not submit information or use the services.

1. Scope of this Privacy Policy

This Privacy Policy applies to information collected via the public site, any branded subdomain, any linked mobile page, the contact form, account creation flows, ticketing and support correspondence, marketing communications, and the analytical tools used to understand how the site is navigated. The policy also covers information we receive when you call the number listed on the site, write to the support address or interact with our operational team at a monitored facility.

This policy does not apply to third party websites that may be reached through links found on our pages. When you leave our site and arrive at another service, the privacy practices of that operator govern your information, and we encourage you to review those policies independently. We are not responsible for the content or the data handling of any external website.

Where our services transport or process air quality data on behalf of a customer, for instance sensor readings gathered at a customer owned station, we act as a processor of the customer data. The customer remains the party that decides the purpose and the lawful basis for that processing, and this Privacy Policy describes our role as the custodian of that data rather than as its creator.

2. Information We Collect Directly

We collect information in several straightforward ways. When you visit the website we record routine technical data, and when you actively provide information we store only what is necessary to respond to you. The following list describes the direct channels:

  • Contact and enquiry details. When you use the contact form, we collect your name, your email address, your phone number if you choose to give it, the subject of your message and the body of your message.
  • Account information. If the company offers portal access that you request, we ask for a username, an email address, a password and an organisation name so we can provision secure access.
  • Billing and invoicing details. For paid services, we collect the invoiced company name, a billing contact, a postal address and confirmation of payment. We direct card payments through established payment providers and do not store your card number on our own servers.
  • Support correspondence. Messages exchanged by email, phone or the site form become a record that we retain for service continuity and for legal protection.
  • Location references you share. You might share a site location, a station name or a postal reference so that we can design or schedule a monitoring deployment.

We only request the information that is genuinely needed to provide a useful response. Optional fields are clearly marked, and you may decline to complete them without losing access to the core pages of the website.

3. Information We Collect Automatically

Like most responsible websites, we record ordinary technical signals when a browser requests a page. These signals help us keep the site reliable and to understand broad usage patterns without the need to identify any individual person.

The automatic records may include the Internet Protocol address of the device, the type and version of the browser, the operating system, the referring page, the date and time of each request, the specific pages visited, the approximate geographic region implied by the IP address, and standard server logs produced by the hosting environment. We may use temporary markers known as cookies or session storage to remember preferences such as language and to reduce repeated prompts. These markers are explained in greater detail in a later section of this document. We do not collect precise device identifiers, camera feeds or ambient sound.

The automatic data is evaluated at an aggregate level to inform design choices, to detect outages and to defend the website against abusive traffic. Where a particular log entry is needed to investigate a security incident, it may be preserved beyond the normal retention period in a limited and controlled fashion.

4. Information Relating to Monitoring Data

A meaningful share of what the company handles relates to environmental readings rather than to people. Particle counts, ozone concentrations, humidity, pressure, wind speed and temperature are the core currency of our networks. Where those measurements are made at a location that a customer controls, ownership of the reading stays with the customer, and the company processes the reading under the contract that governs the station.

Public observation pages may display aggregated or current readings without revealing who operates a station or where a private sensor sits. If a customer asks us to keep a station private, we honour that request and withhold the coordinates from public views. We never sell raw or processed environmental readings to third parties without the consent of the owning customer, and we never attach a person identity to a public observation.

5. Purposes of Processing

The company processes information only for the purposes that brought you to our services. The central purposes are listed below so that the lawful basis for each activity is visible and understandable:

  • To answer enquiries submitted through the contact form and to follow up by email or telephone.
  • To prepare proposals, quotations and statements of work for monitoring network design.
  • To establish and maintain user accounts and privileged portal access.
  • To invoice for services, to issue receipts and to reconcile payments.
  • To operate and to secure the website, its portals and its underlying pipelines.
  • To produce anonymised statistics about traffic and service availability.
  • To comply with accounting, tax, safety and applicable regulatory obligations.
  • To defend the legitimate interests of the company in the operation of its business and to prevent fraud, abuse or unlawful use of the services.

Where consent is required by law before we can send certain marketing or place certain markers, we will obtain consent in advance and will offer an easy route to withdraw it. Where we rely on a legitimate interest, we balance that interest against the rights of individuals and keep processing limited to what is fair and necessary.

6. Legal Basis for Processing

Different activities rest on different legal grounds. For residents of the European Economic Area, the United Kingdom and other territories that recognise the concept, the legal bases we rely on are summarised here:

  • Consent. Used where you actively agree to receive non-essential communications or to accepting non-essential markers. You may withdraw consent at any time without any penalty to the level of service you receive.
  • Performance of a contract. Used to deliver a service you ordered, to manage your account and to maintain the station or portal that is the subject of an agreement.
  • Legitimate interest. Used for security, fraud prevention, network reliability, and limited analytics, always balanced against your interests.
  • Legal obligation. Used where tax, accounting, public safety or a lawful request compels us to retain or to disclose information.

If you have questions about which basis applies to a specific activity, you are welcome to contact us using the details at the end of this policy and we will explain.

7. Cookies and Similar Technologies

We use a small number of browser markers to make the site behave well. Essential markers remember preferences such as whether you have dismissed a notice or which display mode you selected. Analytics markers, if enabled, help us understand which sections are most useful so we can improve navigation and content.

Third parties that host our analytics or form tooling may place their own markers in accordance with their own privacy notices. We choose providers that limit cross site tracking and that allow us to remove markers as soon as they are no longer needed.

Most browsers allow you to block or delete markers through their settings pages. If you disable all cookies, the core pages of the site will continue to work, although some convenience features may require you to choose preferences more than once. We do not use markers to build advertising profiles of you or to follow you across unrelated websites for commercial advertisements.

8. How We Share Information

We never sell personal information. We share information only where it is functionally necessary, legally required or explicitly requested. The sharing scenarios that occur in practice are:

  • Service subprocessors. Hosting vendors, email providers, form processors, mapping services and payment processors receive only the segment of data that they require to perform their role.
  • Professional advisers. Lawyers, accountants and insurers may receive information in connection with a claim, an audit or a dispute.
  • Regulators and authorities. We respond to lawful requests from courts, regulators or public authorities where we are obliged to do so, and we verify the validity of every request before any disclosure.
  • Business transactions. If the company is acquired, merges or transfers part of its business, customer and visitor records may be transferred to the successor along with the assets that rely on those records, subject to obligations substantially similar to those in this policy.
  • With your direction. If you ask us to share a report or a reading with a named party, we honour that instruction for the narrow purpose you intend.

Before sharing any record with a third party, we assess the minimum necessary scope, we select vendors that commit to confidentiality, and we record what was shared and why.

9. International Transfers

The services and the supporting infrastructure operate from data centres that may be located in the United States and in other countries. When you provide information from a location outside the United States, your data may be transmitted to and stored in systems that are geographically distant from where you are situated.

Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on recognised safeguards such as standard contractual clauses, adequacy decisions or equivalent mechanisms that meet the requirements of applicable law. We choose infrastructure that applies encryption in transit and encryption at rest for the portions we control. If you prefer more detail on the specific safeguards applied to a given service, contact us and we will provide the summary that applies.

10. Data Retention

We keep information only for as long as there is a continuing reason to do so. Contact records are retained while an enquiry is active and for a reasonable period afterwards so that we can provide consistent follow up. Invoices and accounting records are retained for the period required by applicable tax law, which is typically several years after the end of the financial year to which they relate.

Server logs and analytical records are retained in a form that supports security review and then are rotated or deleted according to a schedule measured in weeks or months rather than in years. Environmental readings that a customer owns are retained in line with the relevant service agreement and are removed or returned when that agreement ends, subject to lawful obligations.

When a retention period lapses, records are deleted in a way that renders them unrecoverable or are anonymised so that they can no longer be connected to an individual. Our deletion process covers email accounts, backups and secondary copies.

11. Security of Information

Protecting mountain air data and personal records calls for care equal to the care we give a field station in a winter storm. We apply administrative, technical and physical safeguards that are proportionate to the sensitivity of the information:

  • Encryption in transit using current transport layer security for all pages and all portal traffic.
  • Encryption at rest for stored personal data and for account credentials.
  • Role based access so that only staff who genuinely need a record can view it.
  • Strong password rules, optional multi factor authentication and session timeouts in the portals.
  • Regular software updates, controlled change management and tested backup recovery.
  • Staff training on privacy, phishing and the careful handling of enquiries.

No method of transmission or storage is completely secure. While we work hard to guard your information, we cannot promise absolute security against every conceivable attack. If a breach is discovered that poses a risk to individuals, we will notify the relevant supervisory authority and the affected people in accordance with applicable law and without undue delay.

12. Your Rights and Choices

Depending on where you live, the law may grant you specific rights over your personal information. Where those rights apply, we honour them promptly. The rights we commonly recognise include the right to ask what personal data we hold about you, to request a copy in a portable form, to correct inaccuracies, to ask for deletion, to restrict or object to certain processing, and to withdraw consent where processing rests on consent.

To exercise any of these rights, send a clearly worded request to the support address listed at the end of this policy. We will verify your identity before acting, generally by matching the details you provide against the records we hold. We aim to respond within the time allowed by local law, which is usually one month, and we will tell you if a particular request cannot be fulfilled and why.

If you are not satisfied with how we handle a request, you may have the right to raise a complaint with your local data protection authority. We would ask that you first give us the chance to resolve the matter, because a direct conversation usually corrects any misunderstanding quickly.

13. Children Privacy

The website and its services are intended for adults and for organisations acting in a professional capacity. We do not knowingly collect personal information from children under the age of thirteen, and we do not design any feature to engage children to provide such information.

If you believe that a child has submitted personal information to us without the consent of a parent or guardian, please contact us immediately. Upon verification, we will delete the child data from our systems as soon as reasonably possible and we will confirm once the removal is complete. Parents and guardians may also make the same request on behalf of a child and are entitled to review any record that we may hold.

14. Links to Other Websites

Our pages occasionally link to external resources such as partner sites, open data portals or public agencies that publish complementary environmental information. These links are provided for your convenience and do not imply that we endorse or control the linked service. When you follow a link away from our domain, our Privacy Policy no longer applies to the information that the external operator collects. Each external site is governed by its own notices, and we recommend that you review them before sharing anything sensitive.

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in the services, in technology or in legal requirements. When we make material changes, we will revise the effective date at the top of this page and will make reasonable efforts to notify active account holders in advance by the channel that we used for the last private correspondence.

We encourage you to revisit this page occasionally so that you remain aware of how your information is handled. Continued use of the website or the services after a revision takes effect constitutes acceptance of the updated policy, except where the law requires fresh consent, in which case we will ask for it separately.

16. Contact Information

Questions, requests and concerns about this Privacy Policy or about your information may be directed to the company at any of the channels below. Our team reviews privacy enquiries during normal business hours and responds as quickly as the matter allows.

ROCKY MOUNTAIN AIR, LLC
605 Mills St, Lafayette - 80026, United States (US)
help@rockyair.lat
+6282282324357
https://www.rockyair.lat/

This Privacy Policy was prepared with the care of a summer fair weather forecast and the guard of a winter storm watch. Thank you for trusting Rocky Air with your information.

ROCKY AIR
Home Services Contact Privacy Terms of Service
© 2026 ROCKY MOUNTAIN AIR, LLC · Lafayette, Colorado · Return to the home page of Rocky Air.