Privacy policy

How DELALLi handles your information

Effective date: August 25, 2026

Last updated: August 25, 2026

The short version

  • We do not sell or share your personal information — not for money, and not for cross-context behavioral advertising.
  • We measure which pages get read, and nothing more. We use one cookieless analytics tool. There are no advertising pixels, no tag manager, no session recording, and no tracking cookies — so there is no cookie banner, because there is still nothing to consent to.
  • We collect what you type into a form — and, if you buy or enroll, the records needed to deliver the training and issue your certificate. Nothing is bought from data brokers. Four things we collect that you did not type: the record of what you bought, your progress through a course, the IP address a contact-form message came from, and — if you apply for restricted material — the notes we write while reviewing that application. All four are in section 3.
  • You can ask us what we hold, correct it, or have it deleted, at privacy@delalli.com.

The sections below are the full statement. Where the two differ, the full statement governs.

1.Who we are

This site and the training, advisory, and intelligence products offered on it are operated by 825WS, LLC, a Texas limited liability company doing business as DELALLi. “DELALLi,” “we,” “us,” and “our” in this policy mean that company.

825WS, LLC is the controller of the personal information described in this policy — it decides why and how that information is processed, and it is accountable for it. Questions, requests, and complaints about this policy go to privacy@delalli.com, which is the address designated for that purpose.

2.Scope

This policy covers delalli.com and the services reached through it. Our products, our pricing, and our marketing are directed to the United States only. We do not offer goods or services to people in the European Union or the United Kingdom, we do not price in euros or pounds, and we do not monitor anyone’s behavior there. Our site being reachable from outside the US does not change that.

This policy does not cover sites we link to. If you follow a link to an outside site, that site’s own policy applies.

This policy covers information. What you may do with our courses, briefs, and materials is covered by our Terms of use, and what happens to a purchase by our Sales and delivery policy.

3.What we collect, and why

Almost everything we hold about you is something you typed into a form. The exceptions are small and named below: the record of what you bought, the progress our system records as you work through a course, the IP address attached to a contact-form message, the IP address and browser recorded when you accept an agreement, an anonymous count of which pages get viewed, and — if you apply for restricted material — the notes we write while reviewing that application. We do not buy personal information from data brokers, and we do not build profiles of site visitors — the page counts carry no identifier, so they cannot be assembled into a picture of any individual.

CategoryWhat it actually isWhy we have it
IdentifiersName, email address, and — only if you type it into the contact form — phone number.To answer you, to deliver what you asked for, and to send you the updates you asked for.
Professional informationAgency or organization, role or title, US state, and agency size band.To route your question to the right answer, and to understand which kinds of agencies need which kinds of training.
What you tell us in free textYour inquiry, the compliance task that worries you most, what you want a report to answer, and similar open questions.To respond, and to decide what we build next. Please do not put sensitive or operationally restricted details in a web form.
Account informationIf you create an account, an account identifier and sign-in credentials held by our authentication provider. We never see your password.To sign you in and keep your course access yours.
Training recordsEnrollment and status, lesson progress, assessment answers and scores, course evaluation responses, and certificate records.To deliver the course, to issue and verify a certificate, and to support an agency that needs proof its people completed training.
Purchase informationWhether a purchase completed, and the payment processor’s reference for it. Card numbers never touch our site — checkout happens on the processor’s own page.To give you access to what you bought, and for our own accounting.
Eligibility screening informationOnly if you apply for access to our restricted intelligence products: your legal name, your organization, the country you operate from, and what you intend to use the material for. We also write our own review notes onto that application.To decide whether we can lawfully sell you that material. This is a screening step — we check applications against sanctions and denied-party considerations and we may refuse. No application is approved automatically; a person reviews every one.
Market and product researchYour answers to optional questions — what you would expect to pay, which vendors you are evaluating, what you want covered next.To decide what we build and what we charge. We use these answers commercially, in aggregate, and we would rather say so than bury it. Every one of these questions is optional and skipping them costs you nothing.
Technical informationYour IP address and ordinary server logs. If you send us a message through the contact form, we store the IP address that message came from on the record of it — see section 7 for exactly where your IP does and does not end up.To stop automated abuse of our forms, to trace it if it happens anyway, and to keep the site running.

We use this information only for the purposes listed beside it, and for closely related purposes you would reasonably expect — such as security, accounting, and responding to a legal obligation. If we ever want to use it for something materially different, we will ask you first.

4.Sensitive information — what we refuse to collect

We do not collect sensitive personal information, and we have deliberately built our forms so that we cannot. Specifically, we never ask for a Social Security number, a driver’s license number, a state identification number, or any other government-issued identification number. We do not ask about health, biometrics, precise geolocation, race, religion, union membership, sexual orientation, or immigration status.

If you send us any of that anyway — in a free-text field or by email — be aware that it is saved with the rest of your message the moment you hit send; nothing screens it out in advance. When we read it, we delete it rather than keep it, unless you are asking us to act on it. You can also just tell us it is there and we will remove it.

5.Who we share it with

We share personal information with a small number of vendors that run parts of our service for us. Each one below may use it only to perform that job for us, under contract, and not for its own purposes. These are the categories, and the actual companies in each:

  • Website hosting — Vercel Inc. Every request to this site passes through it.
  • Page analytics — Vercel Web Analytics, also Vercel Inc. It records which pages are viewed. It is cookieless and gives you no identifier, so it cannot recognise you on a return visit or on any other site. Section 7 describes exactly what it does and does not do.
  • Database and file storage — Supabase, Inc. This is where form submissions and training records live.
  • Account sign-in — Clerk, Inc. Handles credentials and sessions for account areas.
  • Payment processing — Stripe, Inc. If you buy something, you complete payment on Stripe’s own checkout page and Stripe — not us — handles your card details.
  • Email delivery — Resend, Inc. for transactional messages, and MailerLite for list mail and newsletters.

Three hosts that are not our vendors. The photographs on our article pages load straight from the stock-image libraries they came from, so your browser contacts Pexels, Unsplash, and Wikimedia Commons directly and they see your IP address. We have no contract with them and they are not covered by the paragraph above. Section 7 explains what they can and cannot see. We would rather list them than let the sentence above quietly overstate our control.

We may also disclose information when the law requires it — a subpoena, a court order, a lawful government demand — or where we must to protect our rights or someone’s safety. If our business is ever sold or merged, information may transfer as part of it, and this policy travels with it until it is replaced.

We do not sell or share personal information. We have never sold personal information to anyone, we do not share it for cross-context behavioral advertising, and we do not disclose it to third parties for their own marketing. There is no list of buyers to publish here, because there are none — and that is why you will not find a “Do Not Sell or Share My Personal Information” link on this site. There is nothing for it to turn off.

6.Certificate verification

If you complete a course, we issue a certificate with an identifier on it. Anyone holding that identifier — an employer, an academy, a background investigator — can enter it on our verification page to confirm the certificate is genuine. That page returns the student’s name, the course title and code, the completion date, and whether the certificate is still valid. Nothing else: no email address, no agency, no assessment scores, no contact information.

Certificate identifiers are randomly generated, not sequential, so no one can guess one identifier from another or work through a roster. The verification page is excluded from search-engine indexing. Verification only ever works from an identifier someone already has.

If publishing your name against a certificate would create a risk for you — for example, if you work in an undercover or protective assignment — write to us at privacy@delalli.com and we will suppress it, without asking you to explain why. We will treat the request itself as confidential — we will not put a reason in your record, we will delete the message once we have acted on it, and we will not tell your agency you asked. You do not need to tell us why, and we would rather you did not.

Being straight about how that works today: there is no self-service switch for it yet. A person handles your request by hand, which means it takes days rather than seconds, and we will write back and tell you exactly what we changed. If you need it done urgently, say so and we will prioritize it.

7.Cookies, tracking, and what this site does not do

We use one analytics tool, and it is cookieless. Vercel Web Analytics tells us which pages are read, roughly where visitors come from at country level, and which links brought them here. It sets no cookie, assigns you no identifier, and cannot follow you to any other website. We use it to find out which of our material is actually useful, which is a question we would otherwise be guessing at.

What we still do not run: no advertising pixel, no tag manager, no session recording or replay, no heatmaps, no cross-site tracking, and no advertising identifier of any kind. We do not track you across other websites and we have nothing that would let us. That is why you will not see a cookie banner here — a banner is for consenting to tracking cookies, and we set none.

The only cookies this site may set are the ones our sign-in provider uses to keep you logged in and to protect forms against cross-site request forgery. They exist to make the service work; they are not used to advertise to you or to profile you.

Our emails are a different matter, and we would rather say so plainly. Everything above is about this website. The email we send you is handled by MailerLite and by Resend, and those services record whether a message was opened and whether a link in it was clicked. That happens by an invisible image and by links that pass through the sender’s domain before arriving where they say they are going. We have left it switched on. We use it for one thing — to see whether what we send is worth sending — and we do not use it to build a profile of you, to score you as a lead, or to pass anything to an advertiser.

Two honest notes about it. Open tracking is unreliable in both directions: many mail clients block the image or fetch it automatically, so an “open” can be wrong either way, and we do not treat it as fact about you. And if you would rather not be counted, your mail client’s setting to block remote images stops the open pixel without our involvement — or unsubscribe, and we stop sending. Every message carries an unsubscribe link and we honour it.

One thing we would rather tell you than have you find: our sign-in provider’s code currently loads on every page, including pages with nothing to sign in to, which means it can set its own identifier for a visitor who never creates an account. That is broader than it needs to be, and we intend to narrow it to the pages that actually have accounts. We are describing it here because it is true today, not because it is fixed.

Do Not Track. Some browsers send a “Do Not Track” signal. There is no common standard for how a site should answer it, and we do not respond to Do Not Track signals. We say so plainly because the honest answer matters more than a reassuring one — and because we do not do the tracking that a DNT signal is meant to stop.

Global Privacy Control and other opt-out preference signals. We do not sell or share personal information and we do not run targeted advertising, so there is nothing for such a signal to switch off here. Your information is not sold or shared whether you send one or not. If that ever changes, this section changes with it, in the same release.

Do other parties collect information about you across sites through our site? No. We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites through this site.

Your IP address — precisely. Two different things happen to it, and they are worth separating.

  • On our public forms. Our server reads your IP address to enforce a submission rate limit, so a script cannot flood us. That counter lives in the server’s memory, expires within minutes, and is not written to our database.
  • On the contact form specifically, we go further, and you should know it. When you send us a message, we store the IP address it came from on the same record as your name, email, and message. It is there so that if we are targeted by abusive or fraudulent submissions we can tell them apart from real ones. We do not use it to work out where you are, we do not look it up against anything, and we do not use it for advertising. It is deleted when we delete the message, and you can ask us to remove it sooner.
  • When you accept an agreement, we record the circumstances. If you tick a box to accept our terms — enrolling in a course, subscribing to DELALLi Vantage, or accepting a non-disclosure agreement — we store, alongside the fact and the time, the IP address and browser the acceptance came from, and which version of the document you were shown. This is what makes an agreement provable: without it we have a note saying someone agreed to something, which is worth very little to you or to us if it is ever disputed. It is not used for advertising, it is not shared, and it is not used to follow you anywhere. It is kept as long as the agreement matters.

No other form writes your IP address to our database. Separately, the vendors named in section 5 keep their own records — signing in, or paying, means our sign-in and payment providers see and log your IP the way any service you log into does. If we ever move the rate-limit counter to an outside service, that service will be named in section 5 and this paragraph will change with it.

Images on our articles. Article pages load their photographs directly from the stock-image libraries they come from — Pexels, Unsplash, and Wikimedia Commons. Your browser therefore contacts those sites, and they can see your IP address and browser type, exactly as if you had visited them. We send them no cookie and we do not tell them which page you were reading. They are not our vendors and we have no contract with them; they are named here because you are entitled to know who your browser talks to.

8.Your choices and your rights

You can ask us to do any of the following, whatever state you live in. We do not make you prove you are covered by a particular law first.

  • Know what personal information we hold about you, and get a copy of it.
  • Correct anything that is wrong.
  • Delete it. We will, except where we must keep something — a certificate record an employer may need to verify, or a transaction record we are required to retain. We will tell you if that applies and to what.
  • Opt out of marketing email at any time. Every message we send has an unsubscribe link, and it works; you can also just write to us. We honor it within ten business days at the outside, and in practice immediately. Opting out of marketing does not stop messages we must send you about something you bought.
  • Direct us not to sell or share your information. We already do not, for anyone. You do not need to ask.

How to make a request. Email privacy@delalli.com and say what you want. That address is our designated request address. We may need to verify that the request really comes from you — usually by replying to the email address already on the record — and we will not ask you for more information than that takes. We respond within 60 days of receiving a request. If something genuinely takes longer, we will tell you why before that 60 days is up and finish within another 30.

If we say no. You can appeal. Reply to our decision saying you are appealing, and we will review the decision again from the start and answer you in writing, with our reasons, within 60 days. We are a very small company, so we will not pretend an independent reviewer looks at your appeal — today the same people run the business and read the appeals. What we can promise is a genuine second look and a written answer. If we still say no, we will tell you how to complain to your state attorney general, and you may do so regardless of what we say.

We will never charge you for exercising any of this, and we will never give you a worse price or a worse service because you did.

9.Reviewing and changing your information

If you hold an account, your name and email address are shown on your account page at /account. That page shows them; it does not edit them. To change them yourself, use the round profile button at the top right of any page and choose “Manage account” — that panel is where your name, email address and password are edited, and those changes take effect immediately without anyone approving them. If that panel does not offer the change you need, the email route below always works and we will not treat it as a lesser request.

Everything else we hold is changed by writing to privacy@delalli.com and describing the change — a form you submitted, a training record, a certificate, or anything on your account you cannot reach yourself. A person makes those changes by hand, which is slower than a button but means you can describe what you want in your own words rather than fitting it into a form. We will make the change, or explain why we cannot, within the same 60 days described above.

Between the two — the account menu for your own identity details, and that email address for everything else — that is the complete process for reviewing and requesting changes to your personally identifiable information.

10.How long we keep things

We keep information only as long as it is doing a job, then delete it. These are the periods we work to:

  • Inquiries and contact messages — while we are dealing with your question, and for up to two years afterward as a record of the conversation.
  • Waitlist and newsletter subscriptions — until you unsubscribe or ask us to remove you.
  • Training and certificate records no less than 30 years from the date you complete a course. That is the standard for law-enforcement training records: it is what the IADLEST National Certification Program asks of an accredited course, and it is longer than the five-year minimum Texas sets for law-enforcement training providers. A certificate is meant to be checkable by a supervisor decades after you earned it, which is the whole point of issuing one. This is the category we most often cannot delete on request, and section 8 explains why.
  • Purchase records — for as long as tax and accounting law requires.
  • Server logs and rate-limit counters — days, not months. The IP address stored with a contact-form message is the exception: it lives on that message and is deleted with it.

How this actually happens, honestly: we do not yet run an automated job that deletes records on a schedule. Today these periods are enforced by a person. That makes the timing approximate rather than exact, and it is why a deletion request from you is the fastest route — those we act on directly. We would rather tell you that than print a retention schedule that implies machinery we have not built.

11.Security

Site traffic is encrypted in transit. Access to the database is restricted, and administrative access is limited to people who need it. We use established providers for the parts of the job that carry the most risk — payments and sign-in — rather than building our own.

No system is perfect and we will not claim ours is. If we ever learn that your information was exposed in a way that requires it, we will tell you, and we will tell you what actually happened.

12.Children

This site is for working professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@delalli.com and we will delete it.

13.Changes to this policy

When we change this policy we update the Last updated date at the top, and the new version takes effect when it is posted. Continuing to use the site after that means the new version applies to you.

If a change is material — if it meaningfully changes what we collect, who we share it with, or what we do with it — we will do more than change a date. We will post a notice on this page for at least 30 days, and we will email everyone on our list before the change takes effect.

14.How to reach us

Everything in this policy — questions, requests, appeals, complaints — goes to one address, and a person reads it:

825WS, LLC d/b/a DELALLi
Attn: Privacy
6 Country Place Dr.
Wimberley, TX 78676-3114
privacy@delalli.com

Email reaches us fastest. The postal address is there because you are entitled to know where the company actually is, and because our email has to carry it by law.

If you write to us about privacy and do not hear back, that is a failure on our part, not a policy — tell us again through the contact form and we will fix it.