Josh, LLC (“we”, “us”, “our”) operates the website at siua.io and associated subdomains. This Privacy Policy explains what information we collect when you use those properties, how we use it, and what rights you have. We try to be plain about it.
1. Who we are
Siua is the name of the technology practice operated by Josh, LLC. Our website is at siua.io. Contact us for privacy matters at legal@siua.io.
2. Information we collect
2.1 Contact form submissions
When you send a note through the Start page, we collect:
- Name and email address — so we can respond to you.
- Your note and any optional follow-up detail you review and choose to include.
- Your reply preference and, if you request a call, any optional availability you provide.
- A pseudonymous identifier derived from your IP address — we apply a one-way SHA-256 hash with a site-specific salt before storing anything. We never store your raw IP address in connection with form submissions.
- Timestamp.
This data is stored in Cloudflare D1 (our database, described in §4). We retain contact submissions until you request deletion or we wind down the service. To request deletion, email legal@siua.io from the address you submitted.
2.2 Email correspondence
When you email an address at siua.io, we collect and retain the information needed to receive and respond to your message:
- Your email address, display name, recipients, subject, message content, and standard email headers.
- Files you attach and the original email message, stored privately for delivery, troubleshooting, and conversation history.
- Internal handling information such as the Siua team member assigned to the conversation, replies, notes, and delivery status.
Email correspondence is available only to authorized Siua staff through an access-controlled inbox. It is stored in Cloudflare D1 and private R2 object storage and retained until you request deletion or we wind down the service. Do not send PHI or other regulated information unless we have agreed in writing to an appropriate compliant process.
2.3 AI-assisted note review
When you select “Review my note” on the Start page, your note is sent to an automated review service hosted on Cloudflare infrastructure. The review decides whether one optional question would help before you add contact details.
- Automated review — the review begins only after you select “Review my note.” Cloudflare may process operational metadata, but payload logging is disabled. We do not store abandoned drafts or generated questions in our database.
- Material you choose to send — only the original note, plus the optional question and answer when you select them, are stored as a contact submission and routed to authorized Siua staff.
- Your IP address is used by rate-limiting infrastructure to prevent abuse. It is not stored with the note submitted for automated review.
Do not include passwords, private records, health information, or confidential company data in a Start note.
2.4 Infrastructure and server-side request data
This website runs on Cloudflare Workers. Cloudflare processes every HTTP request and may log standard request metadata (IP addresses, user-agent strings, URLs, timestamps) as part of operating the network. This is governed by Cloudflare’s Privacy Policy. We do not receive persistent server logs; we rely on Cloudflare’s analytics aggregates.
2.5 Cookies and local storage
We do not set advertising or analytics tracking cookies. We may use cookies or localStorage for:
- Remembering acknowledgement and interface preferences for public Labs playgrounds.
- Cloudflare security tokens (e.g.,
__cf_bm,cf_clearance) set automatically by Cloudflare’s bot-management system. These are necessary for the site to function and are governed by Cloudflare’s policy.
2.6 EDI Labs playground
The EDI Core playground at siua.io/labs/edi processes EDI payloads entirely within your browser using WebAssembly. No EDI payload data is transmitted to our servers. See the EDI Labs Data Handling document for full details.
3. How we use your information
- To respond to you — contact submissions and email correspondence are routed to authorized Siua staff and replied to by email.
- To help clarify a note before contact — automated review checks whether one optional question would help.
- To protect the service — IP-based rate limiting prevents abuse of the review endpoint.
- To operate the infrastructure — standard server-side request processing via Cloudflare.
We do not sell your information. We do not use your information for targeted advertising. We do not build behavioral profiles.
4. Data storage and sub-processors
We use the following third-party processors:
- Cloudflare, Inc. (San Francisco, CA) — CDN, DNS, Cloudflare Workers, Workers AI inference for the optional note review, Email Service, D1 (database), R2 (private object storage), Rate Limiting, AI Gateway, and access control for the staff inbox. Privacy Policy ↗
Our database (Cloudflare D1) stores data at rest in Cloudflare’s infrastructure. We do not currently use any marketing, advertising, or analytics platforms.
5. Data retention
- Contact form submissions — retained until you request deletion or the service is wound down.
- Email correspondence and attachments — retained until you request deletion or the service is wound down.
- Unsent Start drafts and generated questions — kept in the current page session and not stored in our contact database.
- EDI payloads — never sent to our servers; any local retention is controlled by your browser storage.
6. Your rights
Depending on where you are located, you may have the right to:
- Access a copy of your personal data.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Data portability (where applicable).
These rights apply under regulations including the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and the California Consumer Privacy Act (CCPA/CPRA). To exercise any of these rights, email legal@siua.io. We will respond within 30 days.
Note: because contact form IP addresses are stored as one-way hashes, we cannot identify submissions from an IP address alone — please email from the address you submitted, or include identifying information you provided in the form.
7. Children’s privacy
This service is not directed at children under 13 (or 16 where applicable under GDPR). We do not knowingly collect personal data from children. If you believe a child has submitted information to us, please contact legal@siua.io.
8. HIPAA notice
Josh, LLC is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA) for use of this public website. Do not submit Protected Health Information (PHI) through any public part of siua.io. Any separately contracted production arrangement requires its own written terms and compliance review.
9. Changes to this policy
We will update the effective date at the top of this page when we make material changes. We will not retroactively reduce your rights for data already collected without notice.
10. Contact
Privacy inquiries: legal@siua.io
Website: siua.io