Do Not Sell My Personal Information
Effective Date: May 27, 2025
PrintsWizard (https://printswizard.live) is committed to protecting the personal information of our customers and users. This Data Breach Notification Policy describes how we detect, respond to, and notify affected individuals and authorities in the event of a data security breach, in compliance with the Florida Information Protection Act (FIPA), Fla. Stat. § 501.171, applicable US state data breach notification laws, and Federal Trade Commission (FTC) guidelines.
Florida law (FIPA) requires businesses to notify affected individuals within 30 days of discovering a data breach involving personal information. This policy outlines how PrintsWizard fulfills that obligation
1. Scope & Definitions
For purposes of this policy:
- “Personal Information” means an individual’s first name or first initial and last name, in combination with any one or more of the following: Social Security number, driver’s license or ID card number, financial account number, credit or debit card number, medical information, online login credentials, or biometric data.
- “Security Breach” or “Data Breach” means an unauthorized access to, or acquisition of, unencrypted personal information that compromises the security, confidentiality, or integrity of that information.
- “Affected Individual” means any customer, employee, or user whose personal information was exposed or potentially exposed in a security breach.
2. How We Protect Your Data
PrintsWizard implements the following technical and organizational safeguards to protect personal information:
- SSL/TLS encryption for all data transmitted through our website.
- Secure server infrastructure with access controls and firewall protection.
- PCI-DSS compliant payment processing (we do not store full credit card numbers).
- Role-based access controls — only authorized employees can access customer data.
- Regular security assessments and vulnerability scans.
- Employee training on data security and breach prevention.
3. Breach Detection & Internal Response
If a potential data breach is detected or suspected, PrintsWizard will immediately:
- Assemble an internal incident response team (including management and IT personnel).
- Isolate and contain the breach to prevent further unauthorized access.
- Preserve all evidence related to the breach for investigation and legal purposes.
- Engage qualified cybersecurity professionals to investigate the nature and scope of the breach.
- Determine what personal information was accessed or acquired, and whose information was affected.
- Assess the risk level and determine whether notification is legally required.
- Document all actions taken during the incident response.
4. Notification to Affected Individuals
If a breach involves personal information that is likely to cause harm, we will notify affected individuals:
- Timeline: We will provide notice within 30 days of discovering the breach (as required by Florida FIPA, Fla. Stat. § 501.171). If investigation requires additional time, we will provide preliminary notice within 30 days and a follow-up notice when more information becomes available.
- Method: Notice will be provided by email (using the email address in our records), written notice by first-class mail, or — if contact information is unavailable — by conspicuous notice on our website homepage or a press release in major statewide media.
Required content of the breach notification will include:
- The date, estimated date, or date range during which the breach occurred.
- A description of the personal information that was accessed or acquired.
- The name and contact information of the entity reporting the breach.
- The telephone numbers and website addresses that affected individuals may use to contact consumer reporting agencies and request credit freezes, if applicable.
- The toll-free numbers and addresses for major consumer reporting agencies if the breach included Social Security numbers or financial information.
- Steps individuals can take to protect themselves from identity theft.
5. Notification to Regulatory Authorities
In addition to notifying affected individuals, PrintsWizard will notify applicable regulatory authorities as required:
- Florida Attorney General: If a breach affects 500 or more Florida residents, we will notify the Florida Attorney General’s office no later than 30 days after the determination of a breach, consistent with Fla. Stat. § 501.171(3)(b).
- Federal Trade Commission (FTC): We will notify the FTC as required by applicable federal law and FTC guidelines.
- Other State Authorities: If residents of other states are affected, we will comply with each affected state’s breach notification law requirements (all 47 US states with breach notification laws).
- Consumer Reporting Agencies: If the breach affects more than 1,000 individuals, we will notify all major consumer reporting agencies (Equifax, Experian, TransUnion) within the required timeframe.
6. Exceptions to Notification
Notification may not be required in the following circumstances:
- If, after a thorough investigation and written opinion from qualified cybersecurity professionals, we determine that the breach did not result in, or is not reasonably likely to result in, identity theft or any other financial harm to the affected individuals.
- If the personal information was encrypted or otherwise rendered unreadable or unusable, and the encryption key was not also acquired.
All such determinations will be documented in writing and retained for at least 5 years.
7. Post-Breach Remediation
Following a confirmed breach, PrintsWizard will:
- Take immediate corrective action to fix the security vulnerability that led to the breach.
- Review and update security policies and procedures to prevent future breaches.
- Offer affected individuals appropriate remediation services, which may include credit monitoring services at no cost, depending on the nature of the breach.
- Conduct a full post-incident review to identify lessons learned.
- Work with law enforcement and regulatory authorities as required.
8. Employee Training
PrintsWizard provides regular training to all employees who handle personal information regarding their obligations under this policy, how to recognize and report potential security incidents, and proper data handling procedures. Employees are required to immediately report any suspected or confirmed data security incident to management.
9. Data Retention of Incident Records
All records related to security incidents, including documentation of breach investigations, notifications sent, and remediation actions taken, will be retained for a minimum of 5 years from the date of the incident, consistent with Florida law and FTC recordkeeping guidance.
10. Updates to This Policy
This Data Breach Notification Policy will be reviewed and updated annually or following any material changes to applicable law or our data processing practices. The most current version will always be posted at https://printswizard.live/data-breach-policy
11. Contact Our Security Team
To report a suspected data breach or security vulnerability, contact us immediately:
PrintsWizard
335 W 47th ST, Miami, Florida, United States 33140
Email: contact@printswizard.live
Phone: +1(888)-392-6308
Website: https://printswizard.live
Email Subject Line: SECURITY INCIDENT — URGENT
We treat all security reports seriously and will respond within 24 hours.