Legal & Compliance

Our commitments to you,
in writing.

Every document that governs how we work, what we promise, and how we protect both parties. Read them here or open the full version.

Privacy Policy
How we collect, store, and protect your data
01 — Who we are

About Us

Your Local Tech Guy is a tech services business based in Oranjestad, Aruba. Contact: (297) 563-9903 · localtechguy.aua@gmail.com

02 — What we collect

Data We Collect & Why

We collect only what is needed to book and complete a service:

  • Name, phone number, email address — to confirm and communicate about your appointment
  • Service type, device type, and issue description — to prepare for the repair
  • Appointment date and time — to schedule the service

We do not collect payment card numbers, passwords, client business data, or your customers' data.

03 — How we use it

Purpose of Processing

Your data is used exclusively to confirm appointments, communicate about your repair, and send invoices. We do not use it for marketing, profiling, or any other purpose. We will never sell or share it.

04 — Retention

How Long We Keep It

Booking and contact details are kept for the duration of the service and for up to 12 months afterward for invoice and warranty purposes. You may request deletion at any time — we will action it within 14 days.

05 — System access

Setup & Troubleshooting Access

For web and automation clients, we may temporarily access your accounts or platforms during active work. This access is temporary, purpose-limited, and non-retentive — we do not keep copies of your business data after the session ends.

06 — Third parties

Infrastructure & Hosting

  • GitHub Pages — hosts this website
  • Cloudflare — handles data in transit to our booking system
  • Google Fonts — serves website fonts
  • Trustpilot — powers the review widget

We do not use analytics platforms or place our own tracking cookies on this website.

07 — Your rights

Your Data Rights

  • Access — request a copy of your personal data
  • Correction — ask us to correct inaccurate information
  • Deletion — request that we delete your personal data
  • Withdrawal of consent — stop processing (may affect service delivery)

Email localtechguy.aua@gmail.com to exercise any of these rights. We respond within 14 days.

Terms of Service
Web design, automation & managed services
01 — Our business

Who We Are

Your Local Tech Guy is a tech services business based in Oranjestad, Aruba. We provide custom web design, automation setup, and ongoing managed website services to businesses and individuals in Aruba and the Dutch Caribbean.

02 — Scope

What We Provide

Website Design & Development

Custom websites built from scratch — no templates, no builders. Includes front-end code, responsive design, SEO structure, and deployment.

Automation Setup & Configuration

We design, build, and configure automation systems connecting your existing tools. Built to your specification, tested thoroughly, and handed over fully operational. We do not store, manage, or retain your business or customer data.

Managed Website Maintenance

For retainer clients — ongoing monitoring, security management, and maintenance. Full scope defined in the SLA.

03 — Pricing

How Pricing Works

All projects are custom scoped and custom priced. No fixed tiers — pricing is determined by complexity and timeline, agreed in writing before work begins. Payment plans including monthly and quarterly billing are available. Accepted methods: cash and direct bank transfer only.

04 — Handoff

Project Delivery & Handoff

Every project ends with a formal handoff including a walkthrough, transfer of all credentials and assets, and a signed Project Completion & Handoff Certificate.

Once the certificate is signed, the project is formally concluded. Any further work is a new engagement billed accordingly — unless you are on an active maintenance retainer.
05 — Retainer

Maintenance Retainer

Retainer clients are onboarded from the start of the project. Either party may cancel with 30 days written notice.

06 — Data

How We Handle Your Data

We operate in alignment with GDPR principles. Temporary system access during setup is limited in duration, purpose, and scope — no copies are retained. You are the data controller. If our access is ever connected to a breach, we notify you within 24 hours.

07 — IP

Intellectual Property

Upon full payment, all custom code, designs, and assets become your property. Third-party libraries remain subject to their own terms.

08 — Liability

Limitation of Liability

Our total liability is limited to the total amount paid in the three months preceding the claim. We are not liable for lost revenue, data loss, third-party outages, or issues caused by your own changes post-handoff.

09 — Law

Governing Law

These terms are governed by the laws of Aruba. Disputes are referred to the competent courts of Aruba.

Service Level Agreement
Monitoring, response times & incident protocol — retainer clients
01 — Monitoring

What We Monitor

  • Website Uptime — automated checks 24/7, tracking response time, uptime %, and open incidents
  • SSL Certificate — validity and expiry monitoring, renewal actioned before expiry
  • Security Scans — monthly automated scans for malware, suspicious scripts, and known attack signatures
  • Performance — monthly Core Web Vitals review, regressions flagged and investigated
  • Automation Health — we monitor operational health and patch as needed
02 — Response times

When You Can Expect to Hear From Us

Business hours: Monday – Friday, 9:00 AM – 5:00 PM AST. Response time = initial acknowledgement and triage, not full resolution.

PriorityResponseDefinitionHours
CRITICAL4 hoursSite completely down or returning errors7 days/week
CRITICAL4 hoursActive malware or confirmed breach7 days/week
HIGH24 hoursKey functionality broken (booking, forms, checkout)Business hours
STANDARD48 hoursMinor bugs, content updates, general questionsBusiness hours
For CRITICAL issues outside business hours — call (297) 563-9903 directly. Do not wait for email.
03 — Incident protocol

How We Handle Outages

Step 1 — Within 2 hours

Internal diagnosis. We determine whether the issue originated from our systems or an external source.

Step 2 — Within 4 to 6 hours

All affected clients are contacted directly by phone or email with a status update.

Step 3 — If unresolved after 6 hours

A formal incident acknowledgement statement is issued confirming we are aware and actively working.

Step 4 — Resolution

Updates continue until full resolution is confirmed. A final notification is sent when the issue is closed.

04 — Exclusions

Outside the Retainer

  • Your hosting provider going down (GitHub Pages, Netlify, Vercel, etc.)
  • Domain registrar issues or DNS propagation problems
  • Third-party service failures for services we did not set up or manage
  • Issues caused by changes you or another party made to managed systems
  • Force majeure events
Handoff Certificate — Standard
Project completion without ongoing retainer

This certificate is signed at the completion of every project where the client does not have an ongoing maintenance retainer. It formally records what was built, confirms acceptance, and establishes the transfer of operational responsibility.

What It Covers

  • Project reference, client details, and handoff date
  • Full list of deliverables with status confirmation
  • Credentials and assets transferred at handoff
  • Post-handoff terms — client assumes full operational responsibility
  • Confirmation that a retainer was offered and declined
  • Signature blocks for both parties
Once this certificate is signed, Your Local Tech Guy's obligations under the project are fulfilled. Any future support is a new engagement billed at current rates.

Signature Block

Your Local Tech Guy
Signature
Full Name
Date
Client
Signature
Full Name
Date

The full printable version is available as a Word document from your project manager.

Handoff Certificate — Retainer
Project completion with active managed services retainer

This certificate is used when the client has an active maintenance retainer. It records project completion and confirms the transition into ongoing managed services.

What It Covers

  • Project reference, client details, handoff date, and retainer start date
  • Billing cycle confirmation (monthly or quarterly)
  • Full list of deliverables with status confirmation
  • Retainer scope confirmation — what is actively covered
  • Credentials and assets transferred at handoff
  • Post-handoff terms — client owns the systems, we continue to manage them
  • Signature blocks for both parties
Unlike a standard handoff, retainer clients do not enter a "goodbye" moment. The certificate marks project completion and the formal beginning of the managed services relationship. The SLA governs all ongoing obligations.

Signature Block

Your Local Tech Guy
Signature
Full Name
Date
Client
Signature
Full Name
Date

The full printable version is available as a Word document from your project manager.

Educational Institution Pricing Policy
Reduced-rate plans for schools & educational institutions in Aruba

Effective Date: June 2026 · Document Version 1.0

01 — Purpose & scope

Purpose & Scope

Your Local Tech Guy ("YLTG") is committed to supporting educational institutions in Aruba by providing professional web design, development, and managed technology services at reduced rates. This policy governs how educational pricing is applied, assessed, and formalized.

This policy applies to:

  • Schools and educational institutions registered and operating in Aruba
  • Public and private institutions at all levels (SPO, MAVO, HAVO, VWO, University, and equivalent)
  • Both full project implementations and website-only engagements
  • Ongoing managed maintenance retainer agreements
02 — Standard pricing

Standard Educational Pricing

All qualifying educational institutions are entitled to the following pricing structure, subject to the terms outlined in this document.

ServiceStandard RateSchool RateSaving
Full Maintenance Package (all services included)ƒ 1,369 /moƒ 900 /moƒ 469 /mo
Website / Project ImplementationStandard pricingMin. 10% reductionAssessed per school
Minimum Retainer PeriodFlexible24 months

The school maintenance rate of ƒ 900/mo is a fixed flat rate inclusive of all services included in the standard ƒ 1,369/mo maintenance package. No services are removed or downgraded — schools receive the same level of care, responsiveness, and deliverables as any standard business client.

03 — Enhanced discounts

Enhanced Discount Authorization

In addition to the standard educational rate, YLTG reserves the right to authorize a discount exceeding the standard reduction on a case-by-case basis. This applies to both the maintenance package and any project or website implementation fees.

Authorization

Any discount beyond the standard educational rate must be personally reviewed and approved by Caleb de Palm, Owner & Operator of Your Local Tech Guy. No other staff member, contractor, or representative of YLTG is authorized to approve or commit to a discount beyond the standard educational rate without written authorization from the above.

Assessment Criteria

When evaluating whether an enhanced discount is appropriate, YLTG will assess the institution across the following criteria:

Factor / ConditionCategoryTypical Outcome
Public schoolType of InstitutionHigher reduction likely
Private schoolType of InstitutionStandard 10% baseline
SPO (Special Education)School TypeHigher reduction likely
MAVO / HAVOSchool TypeStandard assessment
VWO / UniversitySchool TypeStandard assessment
Under 300 studentsEnrollment SizeHigher reduction likely
300 – 800 studentsEnrollment SizeStandard assessment
Over 800 studentsEnrollment SizeStandard 10% baseline
Documented limited budgetFinancial SituationHigher reduction likely
These factors are considered holistically — no single factor guarantees a higher discount, and YLTG retains full discretion in determining the final rate. Any financial documentation provided voluntarily by an institution is handled confidentially and never shared with third parties.
04 — Retainer term

Minimum Retainer Period

All educational institution engagements — whether a full project implementation, website-only build, or maintenance-only agreement — are subject to a minimum retainer period of 24 months (2 years). This minimum reflects the reduced pricing extended to educational institutions and ensures continuity of service for the institution.

Early termination prior to the 24-month period may result in a retroactive adjustment to standard pricing for services already rendered, at YLTG's discretion.

05 — What's included

What Is Included

The educational maintenance package at ƒ 900/mo includes, without limitation, all of the following — at the same standard as the full-rate business package:

  • Uptime & workflow monitoring — 24/7 automated checks, human-reviewed daily
  • Meta token renewals (Facebook & Instagram)
  • 24-hour response on major issues; 4-hour response on critical or site-down events
  • Server & platform patching — hosting and Vercel kept current
  • Monthly performance report — uptime, traffic summary, post success rate
  • API change management — Meta API updates are never billed as extras

YLTG will not reduce, limit, or deprioritize services rendered to educational clients on account of the reduced rate.

06 — Modifications

Policy Modifications

YLTG reserves the right to modify this pricing policy at any time. Changes do not affect agreements already signed and in force. Institutions will be notified in writing no less than 60 days before any change takes effect on new or renewing agreements.

07 — Signatures

Agreement & Signatures

By signing below, both parties acknowledge that they have read, understood, and agree to the terms set out in this Educational Institution Pricing Policy, and confirm the pricing and retainer terms applicable to their engagement with Your Local Tech Guy.

Your Local Tech Guy
Signature
Full Name
Date
Educational Institution
Signature
Full Name & Title
Date

The full printable version is available as a Word document from your project manager.

Honeypot & Threat Intelligence Services
Managed Services Agreement — Addendum A

Version 1.0 · Effective June 2026

This Addendum forms part of and is subject to the Managed Services Agreement between Your Local Tech Guy ("YLTG") and the Client. In the event of conflict, this Addendum prevails with respect to the services described herein. This document should be read together with Addendum B (Data Processing Agreement — Honeypot & Threat Intelligence Data).

01 — Definitions

Definitions

  • Honeypot — a passive security mechanism, comprising hidden form fields, concealed hyperlinks, or trap endpoints, deployed on the Client's web infrastructure to detect and log automated or malicious access attempts.
  • Threat Data — any data collected by a Honeypot, including IP addresses, timestamps, HTTP request headers, user agent strings, submitted form values, and derived geographic metadata.
  • Threat Intelligence Network — the centralized system operated by YLTG that aggregates Threat Data from all participating client sites to maintain shared security lists, including IP blocklists and email blacklists.
  • Malicious Actor — any automated script, bot, crawler, vulnerability scanner, or human threat actor whose activity is captured by a Honeypot.
  • VerifyIQ — the email verification API product operated by YLTG, whose blacklist and threat intelligence feeds may be enriched by Threat Data collected under this Addendum.
02 — Scope of services

Scope of Services

Honeypot Deployment

Subject to the Client's written authorization, YLTG is authorized to deploy, configure, and maintain Honeypot mechanisms on Client web infrastructure under YLTG's management, including:

  • Hidden form fields on Client web forms that detect automated form submission by bots
  • Concealed trap endpoints disguised as common admin and configuration paths that log unauthorized access attempts
  • Hidden hyperlinks in page markup that are invisible to human users but accessible to automated crawlers

Threat Data Collection

YLTG will collect and process Threat Data generated by Honeypot activity on Client infrastructure. The Client acknowledges that:

  • Threat Data is generated solely by Malicious Actors and automated systems, not by legitimate human visitors to the Client's site
  • YLTG will log Threat Data in a centralized system for the purposes described in Section 03
  • The Client will receive a monthly Threat Intelligence Report summarizing Honeypot activity on their infrastructure

What YLTG Will Not Do

  • Actively probe, attack, or retaliate against any IP address or system identified through Honeypot activity
  • Use Honeypot mechanisms to collect data from legitimate human users of the Client's website
  • Redirect legitimate users to Honeypot endpoints
  • Share individually identifiable Threat Data with third parties outside the Threat Intelligence Network without Client consent
03 — Threat intelligence network

Threat Intelligence Network

Network Participation

By executing this Addendum, the Client consents to YLTG incorporating anonymized and aggregated Threat Data collected from Client infrastructure into the Threat Intelligence Network. IP addresses, domains, and email addresses identified as malicious on the Client's site may be added to shared blocklists and blacklists — including VerifyIQ's email blacklist — to protect all participating clients. Threat Data is contributed on an anonymized basis; the Client's identity as the source of a specific data point is never disclosed to other network participants.

Mutual Benefit

Participation provides a mutual benefit: Threat Data collected on other participating client sites similarly enriches the protection applied to the Client's own infrastructure. The more sites participating in the Network, the more comprehensive the threat intelligence available to all participants.

Opt-Out

The Client may opt out of contributing Threat Data to the shared Threat Intelligence Network at any time by written notice to YLTG. Opting out does not affect Honeypot deployment or the monthly Threat Intelligence Report. Threat Data already incorporated into the Network prior to opt-out cannot be retroactively removed.

04 — Data handling & privacy

Data Handling & Privacy

The parties acknowledge that IP addresses may constitute personal data under applicable privacy legislation, including the Personal Data Protection Ordinance of Aruba (Landsverordening bescherming persoonsgegevens) and, where applicable, the GDPR. YLTG will handle all Threat Data in accordance with its Data Processing Agreement (Addendum B), which forms part of this agreement.

Threat Data is retained for a maximum of 24 months from the date of collection, after which it is permanently deleted — except where retention is required by law, or where the data has been incorporated into anonymized aggregate threat intelligence lists, in which case the individual record may be removed while the list entry persists.

The Client is responsible for ensuring their website's Privacy Policy discloses the use of security monitoring mechanisms, including passive Honeypot tools, in accordance with applicable law. YLTG will provide standard disclosure language on request. Maintaining an accurate Privacy Policy remains the Client's sole responsibility.

05 — Authorization & liability

Authorization & Liability

By executing this Addendum, the Client provides explicit written authorization to YLTG to deploy Honeypot mechanisms across all domains, subdomains, and web properties listed in the parent Managed Services Agreement.

YLTG's liability in connection with the services provided under this Addendum is limited to the total fees paid by the Client in the three (3) months preceding the event giving rise to the claim. YLTG is not liable for any indirect, consequential, or incidental damages arising from the operation of Honeypot mechanisms or the use of Threat Data.

YLTG does not warrant that all Threat Data collected represents confirmed malicious activity, nor that Honeypot mechanisms will capture all malicious activity. These services are provided on a best-efforts basis as part of a layered security strategy.
06 — Term & termination

Term & Termination

This Addendum takes effect on the date of signing and remains in force for the duration of the parent Managed Services Agreement. Either party may terminate this Addendum with 30 days written notice without terminating the parent agreement. On termination, YLTG will cease Honeypot operations on Client infrastructure within 14 days and provide a final Threat Intelligence Report.

07 — Signatures

Agreement & Signatures

By signing below, both parties confirm they have read, understood, and agree to the terms of this Addendum.

Your Local Tech Guy
Signature
Full Name
Date
Client
Signature
Full Name & Title
Date

The full printable version is available as a Word document from your project manager.

Data Processing Agreement — Honeypot & Threat Intelligence Data
Addendum B to the Managed Services Agreement

Version 1.0 · Effective June 2026

01 — Parties & roles

Parties & Roles

RoleDescription
Data ControllerClient — determines the purposes and means of processing personal data collected on their web infrastructure
Data ProcessorYour Local Tech Guy, operated by Caleb de Palm, Oranjestad, Aruba — processes data on behalf of and under the instruction of the Controller
Subject MatterProcessing of Threat Data (including IP addresses and associated metadata) collected via Honeypot mechanisms deployed on Controller web infrastructure
DurationFor the term of MSA Addendum A, plus the retention period defined in Article 06
02 — Definitions

Definitions

Terms defined in MSA Addendum A carry the same meaning in this Agreement. Additionally:

  • Personal Data — any information relating to an identified or identifiable natural person, including IP addresses to the extent they constitute personal data under applicable law.
  • Processing — any operation performed on Personal Data, including collection, recording, storage, use, disclosure, or deletion.
  • Sub-processor — any third party engaged by YLTG to process Personal Data on behalf of the Client.
  • Applicable Law — the Personal Data Protection Ordinance of Aruba (Landsverordening bescherming persoonsgegevens), and where applicable, the GDPR and any successor legislation.
03 — Instructions for processing

Instructions for Processing

YLTG will process Personal Data only on documented instructions from the Client, as set out in this Agreement and MSA Addendum A, and will not process Personal Data for any other purpose without the Client's prior written consent.

AspectDetail
PurposeDetection and logging of malicious automated access attempts on Client web infrastructure; enrichment of shared threat intelligence lists
Type of DataIP addresses, HTTP request metadata (headers, user agents, request paths, timestamps), submitted honeypot form values
Data SubjectsAutomated systems, bots, and threat actors accessing Client web infrastructure (not legitimate human users)
Legal BasisLegitimate interest (security monitoring of own infrastructure); Controller's authorization under Addendum A

If YLTG considers that any instruction from the Client infringes Applicable Law, YLTG will immediately notify the Client and may suspend processing of the relevant instruction until a lawful alternative is provided.

04 — Confidentiality

Confidentiality

YLTG ensures that persons authorized to process Personal Data under this Agreement are bound by appropriate confidentiality obligations. YLTG will not disclose Threat Data to any third party except:

  • As required by Applicable Law or a binding order of a competent authority (with advance notice to the Client where legally permitted)
  • To sub-processors authorized under Article 07 of this Agreement
  • In anonymized, aggregated form as part of the Threat Intelligence Network described in MSA Addendum A
05 — Security measures

Security Measures

YLTG will implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

Technical Measures

  • Encryption of Threat Data at rest and in transit (TLS 1.2 minimum)
  • Access controls limiting Threat Data access to authorized YLTG personnel only
  • Centralized logging and audit trails for all access to Threat Data systems
  • Regular security reviews of Honeypot infrastructure

Organizational Measures

  • Defined data handling procedures for Threat Data
  • Incident response procedure for unauthorized access to Threat Data
  • Retention and deletion schedules enforced as defined in Article 06
06 — Retention & deletion

Retention & Deletion

CategoryRetention
Standard retention24 months from date of collection
Aggregated / anonymized dataMay be retained indefinitely as part of threat intelligence lists, as individual records are not recoverable from aggregated data
On terminationAll identifiable Personal Data deleted within 30 days of Addendum A termination
Legal holdRetention extended only where required by applicable law or binding legal process

On expiry of the retention period or termination of Addendum A, YLTG will securely delete all identifiable Personal Data and provide written confirmation of deletion to the Client within 14 days.

07 — Sub-processors

Sub-processors

The Client provides general written authorization for YLTG to engage sub-processors for the purpose of providing the services under Addendum A. YLTG maintains an up-to-date list of sub-processors and will make it available to the Client on request.

Sub-processorFunctionLocation
Cloudflare, Inc.Infrastructure, CDN, DDoS protectionUSA (EU SCCs / adequacy decision applies)
Hetzner Online GmbHServer hosting (if applicable)Germany (GDPR compliant)
Vercel, Inc.Frontend hosting (if applicable)USA (EU SCCs apply)

YLTG will notify the Client of any intended addition or replacement of sub-processors at least 14 days in advance. The Client may object on reasonable grounds within 7 days; if unresolved, either party may terminate Addendum A with 30 days notice. YLTG imposes data protection obligations on all sub-processors equivalent to those in this Agreement, by written contract.

08 — Security incidents

Security Incidents

In the event of a security incident involving Personal Data processed under this Agreement, YLTG will notify the Client without undue delay and within 72 hours of becoming aware of the incident, including (to the extent known): the nature of the incident and categories of data affected, the approximate number of individuals and records affected, YLTG's incident point of contact, likely consequences, and measures taken or proposed to address it. YLTG will reasonably assist the Client in meeting any notification obligations to supervisory authorities or affected data subjects.

09 — Data subject rights

Data Subject Rights

To the extent Threat Data constitutes Personal Data of identifiable individuals (noting that data subjects are primarily bots and automated systems, not typical data subjects), YLTG will promptly notify the Client of any data subject rights requests received, assist the Client in responding within applicable legal timeframes, and not respond to such requests directly without the Client's prior written authorization.

10 — Audit rights

Audit Rights

The Client may, on no less than 14 days written notice, request an audit of YLTG's data processing activities under this Agreement, either through document review or by appointing an independent auditor at the Client's expense. Audits may not unreasonably interfere with YLTG's operations and will be conducted no more than once per calendar year unless a security incident warrants otherwise.

11 — Governing law

Governing Law

This Agreement is governed by the laws of Aruba. Disputes arising under this Agreement are subject to the exclusive jurisdiction of the competent courts of Aruba. Where GDPR applies by virtue of the data subjects' location or the Client's operations, the parties agree to interpret this Agreement consistently with GDPR requirements.

12 — Signatures

Agreement & Signatures

By signing below, both parties confirm acceptance of this Data Processing Agreement as Addendum B to the Managed Services Agreement.

Data Processor — Your Local Tech Guy
Signature
Full Name
Date
Data Controller — Client
Signature
Full Name & Title
Date

The full printable version is available as a Word document from your project manager.