Mahoney Control platform, operated by Mahoney IT Group USA LLC. Effective June 17, 2026.
Mahoney Control (the “Platform”) is a cybersecurity and managed-services operations platform operated by Mahoney IT Group USA LLC (“Mahoney”, “we”, “us”), 200 East Las Olas Boulevard, 14th Floor, Fort Lauderdale, FL 33301, USA. For privacy questions contact legal@mahoney-it.com.
We process data to provide, secure, support and bill the Platform; to detect and respond to security incidents; to meet legal and contractual obligations; and to improve the service. Processing is grounded in the contract with the customer (the Master Service Agreement) and our legitimate interest in operating a secure platform.
We share data only as needed with vetted providers that process it on our behalf:
Each provider is bound by confidentiality and data-protection terms at least as protective as those we offer. Within the Mahoney IT Group, data may be shared among affiliates under common control solely to deliver and support the service.
When a customer connects QuickBooks, we use Intuit’s APIs only to create and reconcile invoices and to process payments the customer authorises. We access the minimum QuickBooks data needed for those functions, do not sell it, and retain it only as long as needed for billing and legal record-keeping. Disconnecting QuickBooks (in QuickBooks or via the Platform) revokes our access; see our disconnect page.
We keep data for as long as the account is active and as required to meet legal, tax and audit obligations, then delete or anonymise it. Audit and acceptance records (e.g. MSA acceptances) are retained for their evidentiary value.
We protect data with encryption in transit and at rest, strict role-based access control (default-deny row-level security), secret vaulting and audit logging. No system is perfectly secure, but we apply controls aligned to recognised frameworks (ISO 27001, SOC 2, NIST).
Each customer is recorded under a residency region (EU, US or Asia). Today that region determines how the customer is billed and reported, and it does not yet place their data in a separate regional database: the Platform runs one production database, and data is processed where our sub-processors operate. Per-region data storage is planned and not built, and we say so here rather than imply otherwise. The sub-processor list names every processor, what it processes and where.
Where data is transferred across borders, we rely on appropriate safeguards. We comply with applicable laws including the GDPR, the California Consumer Privacy Act (CCPA), and the Florida Information Protection Act (FIPA) / Florida Digital Bill of Rights (FDBR).
Subject to applicable law you may request access, correction, deletion or portability of your personal data, and may object to or restrict certain processing. For customer-account data we act on the instructions of the customer (the data controller). Contact legal@mahoney-it.com to exercise a right.
We may update this policy; material changes will be notified through the Platform or by email. Continued use after the effective date of an update constitutes acceptance.