Legal Information for USA
Legal Information for USA
Section titled “Legal Information for USA”Last Updated: October 1, 2025
1. US Legal Framework
Section titled “1. US Legal Framework”1.1 Jurisdiction and Applicable Law
Section titled “1.1 Jurisdiction and Applicable Law”Legal Status
Section titled “Legal Status”- Company: InitiumX
- Headquarters: San Pedro Sula, Honduras
- US Operations: Remote services to US clients
- Registered Agent: Available upon request for contract purposes
Applicable Laws for US Clients
Section titled “Applicable Laws for US Clients”| Regulation | Application |
|---|---|
| CCPA | California Consumer Privacy Act (CA residents) |
| CPRA | California Privacy Rights Act (effective 2023) |
| CAN-SPAM Act | Email marketing compliance |
| DMCA | Digital Millennium Copyright Act |
| COPPA | Children’s Online Privacy Protection (if applicable) |
| State Laws | Applicable state-specific regulations |
1.2 Regulatory Authorities
Section titled “1.2 Regulatory Authorities”Federal Trade Commission (FTC)
Section titled “Federal Trade Commission (FTC)”- Function: Consumer protection and business practices
- Applicability: Advertising, data security, consumer rights
- Website: www.ftc.gov
State Attorneys General
Section titled “State Attorneys General”- Function: Enforcement of state consumer protection laws
- CCPA Enforcement: California Attorney General
- Data Breach Notification: State-specific requirements
2. California Consumer Privacy Act (CCPA/CPRA)
Section titled “2. California Consumer Privacy Act (CCPA/CPRA)”2.1 Applicability to California Residents
Section titled “2.1 Applicability to California Residents”Who is Protected
Section titled “Who is Protected”California Residents have enhanced rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access personal information
- Right to equal service and price (non-discrimination)
- Right to deletion of personal information
InitiumX CCPA Compliance
Section titled “InitiumX CCPA Compliance”✅ We commit to:
- Not selling personal information of California residents
- Providing clear privacy notice to California users
- Honoring all CCPA/CPRA rights requests
- Maintaining records of data processing activities
2.2 CCPA Rights for California Residents
Section titled “2.2 CCPA Rights for California Residents”Right to Know
Section titled “Right to Know”What you can request:
- Categories of personal information collected
- Specific pieces of personal information we have
- Sources of personal information
- Business or commercial purpose for collecting
- Categories of third parties we share with
How to request:
- Email: privacy@initiumx.dev
- Subject: “CCPA Right to Know Request”
- Response time: 45 days (extendable to 90 days)
Right to Delete
Section titled “Right to Delete”What can be deleted:
- Personal information collected from you
- Subject to legal exceptions (contracts, legal obligations, etc.)
- Includes data shared with service providers
Exceptions to deletion:
- Complete transaction or provide requested service
- Comply with legal obligations
- Exercise free speech or legal rights
- Engage in research (if deletion would impair research)
Timeline:
- Acknowledgment: 10 days
- Completion: 45 days (extendable to 90 days)
Right to Opt-Out of Sale
Section titled “Right to Opt-Out of Sale”If this changes in the future:
- “Do Not Sell My Personal Information” link will be provided
- Opt-out honored immediately
- No discrimination for opting out
Right to Non-Discrimination
Section titled “Right to Non-Discrimination”You have the right to:
- Same service and prices whether you exercise CCPA rights or not
- No denial of goods or services for exercising rights
- No different price or quality of service
- No suggestion that you will receive different service
Permitted practices:
- Different prices for loyalty programs (if disclosed)
- Financial incentives consistent with value of data
- Good-faith estimates of value provided
2.3 CCPA Verification Process
Section titled “2.3 CCPA Verification Process”Identity Verification
Section titled “Identity Verification”For Right to Know requests:
- Verify via email confirmation
- Match 2-3 data points we have on file
- May require additional documentation for sensitive data
For Deletion requests:
- Enhanced verification required
- May need government-issued ID
- Additional security measures for high-risk deletions
Authorized Agent Requests
Section titled “Authorized Agent Requests”Requirements for authorized agents:
- Signed permission from consumer
- Proof of authorization (power of attorney or written consent)
- Consumer verification still required
- Agent may need business license or registration
3. State-Specific Privacy Laws
Section titled “3. State-Specific Privacy Laws”3.1 Virginia Consumer Data Protection Act (VCDPA)
Section titled “3.1 Virginia Consumer Data Protection Act (VCDPA)”Effective: January 1, 2023
Rights for Virginia Residents:
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to obtain copy of data
- Right to opt-out of targeted advertising and sale
Compliance: Same process as CCPA requests
3.2 Colorado Privacy Act (CPA)
Section titled “3.2 Colorado Privacy Act (CPA)”Effective: July 1, 2023
Rights for Colorado Residents:
- Right to access and portability
- Right to correct inaccuracies
- Right to deletion
- Right to opt-out of sale and targeted advertising
- Right to opt-out of profiling
Compliance: privacy@initiumx.dev
3.3 Connecticut Data Privacy Act (CTDPA)
Section titled “3.3 Connecticut Data Privacy Act (CTDPA)”Effective: July 1, 2023
Rights for Connecticut Residents:
- Confirm processing of personal data
- Access personal data
- Correct inaccuracies
- Delete personal data
- Obtain copy of data
- Opt-out of sale and targeted advertising
3.4 Utah Consumer Privacy Act (UCPA)
Section titled “3.4 Utah Consumer Privacy Act (UCPA)”Effective: December 31, 2023
Rights for Utah Residents:
- Access to personal data
- Deletion of personal data
- Opt-out of sale and targeted advertising
- Data portability
3.5 Other State Laws
Section titled “3.5 Other State Laws”States with pending or enacted privacy laws:
- Montana
- Oregon
- Texas
- Tennessee
- Iowa
Our commitment: Monitor and comply with all state privacy laws as they take effect.
4. Data Transfer and Storage
Section titled “4. Data Transfer and Storage”4.1 Cross-Border Data Transfer
Section titled “4.1 Cross-Border Data Transfer”International Data Transfer
Section titled “International Data Transfer”InitiumX operates from Honduras:
- Data may be transferred to Honduras for processing
- Data may be stored on US-based servers (AWS, Google Cloud)
- European servers available for EU/UK data
Protections for US Data
Section titled “Protections for US Data”Safeguards implemented:
- ✅ Standard Contractual Clauses (SCC)
- ✅ Encryption in transit (TLS 1.3)
- ✅ Encryption at rest (AES-256)
- ✅ Access controls and monitoring
- ✅ Regular security audits
Data Processing Agreement
Section titled “Data Processing Agreement”All US clients covered by comprehensive DPA:
- Data Processing Agreement
- Includes cross-border transfer provisions
- Details sub-processors and their locations
- Specifies security measures
4.2 Data Residency Options
Section titled “4.2 Data Residency Options”US-Based Hosting
Section titled “US-Based Hosting”For clients requiring US data residency:
- AWS US-East (Virginia)
- AWS US-West (California/Oregon)
- Google Cloud US regions
- Premium pricing may apply
Benefits:
- Data remains in United States
- Lower latency for US users
- Compliance with certain regulations
How to request:
- Specify during project planning
- May require infrastructure cost adjustment
- Available for all service levels
5. Email Marketing and CAN-SPAM
Section titled “5. Email Marketing and CAN-SPAM”5.1 CAN-SPAM Compliance
Section titled “5.1 CAN-SPAM Compliance”Requirements for Commercial Emails
Section titled “Requirements for Commercial Emails”Every email must:
- ✅ Include accurate “From” and “To” information
- ✅ Include accurate subject line (no deception)
- ✅ Identify message as an advertisement (if applicable)
- ✅ Include valid physical postal address
- ✅ Provide clear opt-out mechanism
- ✅ Honor opt-out requests within 10 business days
InitiumX Email Practices
Section titled “InitiumX Email Practices”We commit to:
- No purchased email lists
- Only emailing those who consented
- Clear unsubscribe link in every email
- Immediate opt-out processing (within 24 hours)
- Separate lists for different email types
5.2 Opt-Out Rights
Section titled “5.2 Opt-Out Rights”How to Opt-Out
Section titled “How to Opt-Out”Multiple methods:
- Click “Unsubscribe” link in any email
- Email: unsubscribe@initiumx.dev
- Account settings (for registered users)
- Reply “STOP” to marketing emails
Timeline:
- Opt-out honored within 24 hours
- No further marketing emails
- Transactional emails may continue (order confirmations, service updates)
6. Intellectual Property
Section titled “6. Intellectual Property”6.1 Digital Millennium Copyright Act (DMCA)
Section titled “6.1 Digital Millennium Copyright Act (DMCA)”Copyright Protection
Section titled “Copyright Protection”InitiumX respects copyright:
- Does not host infringing content knowingly
- Responds to valid DMCA takedown notices
- Maintains DMCA safe harbor compliance
DMCA Takedown Process
Section titled “DMCA Takedown Process”If you believe your copyright is infringed:
Send notice to: dmca@initiumx.dev
Must include:
- Your signature (physical or electronic)
- Identification of copyrighted work
- Identification of infringing material and location
- Your contact information
- Statement of good faith belief
- Statement of accuracy under penalty of perjury
- Statement of authority to act
Response timeline:
- Acknowledgment: 24-48 hours
- Action: 5-7 business days
- Counter-notice period: 10-14 days
Counter-Notice
Section titled “Counter-Notice”If your content was removed:
- Send counter-notice to dmca@initiumx.dev
- Must include identification, contact, good faith statement
- Content may be restored in 10-14 business days
- Unless copyright owner files lawsuit
6.2 Trademark Protection
Section titled “6.2 Trademark Protection”US Trademark Law
Section titled “US Trademark Law”Trademark considerations:
- InitiumX respects registered US trademarks
- Clients must ensure they have rights to trademarks used
- No development of infringing trademark applications
Disputes:
- Cease and desist process
- Trademark clearance required for sensitive projects
- Legal consultation available
7. Consumer Protection and Contracts
Section titled “7. Consumer Protection and Contracts”7.1 Contract Formation
Section titled “7.1 Contract Formation”Electronic Signatures
Section titled “Electronic Signatures”E-SIGN Act (2000) compliance:
- Electronic signatures are legally binding
- Digital contracts have same validity as paper
- Consent to electronic records documented
- Right to paper copies available upon request
Contract Terms
Section titled “Contract Terms”US-specific provisions:
- English language controls
- Dollar amounts in USD
- Choice of law and venue clauses
- Arbitration agreements (when applicable)
7.2 Consumer Rights
Section titled “7.2 Consumer Rights”Federal Trade Commission Act
Section titled “Federal Trade Commission Act”Protections against:
- Deceptive advertising
- Unfair business practices
- False claims about services
- Bait-and-switch tactics
InitiumX Commitments:
- Transparent pricing
- Accurate service descriptions
- No hidden fees
- Clear terms and conditions
7.3 Warranty and Liability
Section titled “7.3 Warranty and Liability”Uniform Commercial Code (UCC)
Section titled “Uniform Commercial Code (UCC)”For software as goods:
- Warranties as described in contracts
- Limitation of implied warranties (when permitted)
- Limitation of liability provisions
See also:
8. Payment and Taxation
Section titled “8. Payment and Taxation”8.1 Payment Processing
Section titled “8.1 Payment Processing”Accepted Payment Methods
Section titled “Accepted Payment Methods”For US clients:
- Credit/Debit cards (Visa, MasterCard, Amex, Discover)
- ACH bank transfers
- Wire transfers
- PayPal
- Check (for amounts > $5,000)
Payment Security
Section titled “Payment Security”PCI DSS Compliance:
- We do not store credit card information
- Payment processed via Stripe (PCI Level 1)
- Tokenization for recurring payments
- Secure transmission (TLS 1.3)
8.2 Sales Tax
Section titled “8.2 Sales Tax”Sales Tax Collection
Section titled “Sales Tax Collection”Current policy:
- InitiumX does not collect US state sales tax
- Services performed internationally
- No physical presence in US states
Client responsibility:
- Clients may owe use tax in their state
- Consult with tax advisor
- InitiumX provides invoices for tax reporting
Future Changes
Section titled “Future Changes”If nexus is established:
- Will notify affected clients
- Sales tax collection may begin
- 30 days notice before implementation
8.3 Tax Reporting
Section titled “8.3 Tax Reporting”Form W-9 Requests
Section titled “Form W-9 Requests”For US businesses:
- May request W-9 for their records
- InitiumX provides upon request
- International company - EIN not applicable
- Foreign entity classification
Form 1099 Reporting
Section titled “Form 1099 Reporting”US clients’ obligations:
- May need to report payments > $600/year
- Classify as payments to foreign contractor
- Use InitiumX foreign address
- Consult tax advisor for specific requirements
9. Data Breach Notification
Section titled “9. Data Breach Notification”9.1 State Breach Notification Laws
Section titled “9.1 State Breach Notification Laws”Multi-State Obligations
Section titled “Multi-State Obligations”All 50 states have data breach laws:
- Notification requirements vary by state
- InitiumX complies with strictest standards
- California standard typically used as baseline
Notification Timeline
Section titled “Notification Timeline”By state (examples):
- California: Most expedient time possible, no unreasonable delay
- Florida: 30 days of determination
- New York: Most expedient time possible
- Texas: Without unreasonable delay
InitiumX standard:
- Notification within 72 hours of confirmation
- Exceeds most state requirements
- Email and postal mail (when addresses available)
9.2 Breach Notification Content
Section titled “9.2 Breach Notification Content”Required Information
Section titled “Required Information”What we disclose:
- Date of breach discovery
- Type of information compromised
- Steps taken to secure data
- Contact information for questions
- Resources for identity protection
- Steps individuals should take
Credit Monitoring
Section titled “Credit Monitoring”For significant breaches:
- May offer free credit monitoring
- Identity theft protection services
- Dedicated support line
- Regular updates on investigation
10. Accessibility Compliance
Section titled “10. Accessibility Compliance”10.1 ADA and Digital Accessibility
Section titled “10.1 ADA and Digital Accessibility”Americans with Disabilities Act (ADA)
Section titled “Americans with Disabilities Act (ADA)”Web accessibility standards:
- WCAG 2.1 Level AA target compliance
- Screen reader compatibility
- Keyboard navigation support
- Color contrast requirements
- Alt text for images
Section 508 Compliance
Section titled “Section 508 Compliance”For federal contractors:
- Enhanced accessibility requirements
- VPAT (Voluntary Product Accessibility Template) available
- Regular accessibility audits
- Remediation of issues
10.2 Accessibility Features
Section titled “10.2 Accessibility Features”Standard implementations:
- Semantic HTML structure
- ARIA labels where appropriate
- Focus indicators
- Resizable text
- Alternative text for non-text content
Request accommodations:
- Email: accessibility@initiumx.dev
- Alternative formats provided upon request
- Accessibility statement available
11. Dispute Resolution
Section titled “11. Dispute Resolution”11.1 Choice of Law and Venue
Section titled “11.1 Choice of Law and Venue”Governing Law
Section titled “Governing Law”Standard provision:
- Honduras law governs contract interpretation
- US federal law for IP and certain protections
- State law for state-specific requirements
Venue for Disputes
Section titled “Venue for Disputes”Hierarchy:
- Negotiation: Good faith attempt (30 days)
- Mediation: Neutral third party (60 days)
- Arbitration: Binding arbitration (preferred)
- Litigation: Honduras courts or mutually agreed US venue
11.2 Arbitration Agreement
Section titled “11.2 Arbitration Agreement”Arbitration Provisions
Section titled “Arbitration Provisions”For disputes > $25,000:
- Binding arbitration under AAA rules
- One arbitrator unless parties agree otherwise
- Location: Virtual or mutually agreed
- Language: English
- Costs shared unless otherwise determined
Exceptions to arbitration:
- Small claims court matters
- IP injunctive relief
- Emergency remedies
Class Action Waiver
Section titled “Class Action Waiver”Individual disputes only:
- No class actions
- No class arbitrations
- No representative actions
- Individual arbitration only
Opt-out rights:
- 30 days to opt-out of arbitration clause
- Written notice to legal@initiumx.dev
- Still bound by other contract terms
12. Industry-Specific Regulations
Section titled “12. Industry-Specific Regulations”12.1 HIPAA (Healthcare)
Section titled “12.1 HIPAA (Healthcare)”If client operates in healthcare:
- Business Associate Agreement (BAA) required
- HIPAA-compliant infrastructure available
- Additional security measures
- Higher service tier pricing
- PHI handling protocols
Contact for HIPAA projects:
- Email: healthcare@initiumx.dev
- Separate BAA execution required
- Compliance audit provided
12.2 FERPA (Education)
Section titled “12.2 FERPA (Education)”For educational institutions:
- Student data protection measures
- FERPA compliance protocols
- Limited access to education records
- Parent/student rights respected
12.3 GLBA (Financial Services)
Section titled “12.3 GLBA (Financial Services)”For financial institutions:
- Gramm-Leach-Bliley Act compliance
- Safeguards Rule adherence
- Privacy Notice requirements
- Information security program
12.4 SOC 2 and Compliance Certifications
Section titled “12.4 SOC 2 and Compliance Certifications”Available for enterprise clients:
- SOC 2 Type II report (in progress)
- ISO 27001 certification (planned)
- Custom compliance certifications
- Third-party audit facilitation
13. Contact Information
Section titled “13. Contact Information”13.1 US Client Support
Section titled “13.1 US Client Support”Primary Contact
Section titled “Primary Contact”- Email: usa@initiumx.dev
- Phone: +504 3253-6271 (WhatsApp enabled)
- Hours: Monday-Friday, 7:00 AM - 4:00 PM CST
- Time Zone: Central Standard Time (Honduras = US Central)
13.2 Legal and Compliance
Section titled “13.2 Legal and Compliance”Legal Inquiries
Section titled “Legal Inquiries”- Email: legal@initiumx.dev
- For: Contract questions, disputes, legal compliance
Privacy and CCPA Requests
Section titled “Privacy and CCPA Requests”- Email: privacy@initiumx.dev
- For: Privacy rights, CCPA requests, data questions
DMCA Notices
Section titled “DMCA Notices”- Email: dmca@initiumx.dev
- For: Copyright infringement claims only
14. Resources
Section titled “14. Resources”14.1 Related Documents
Section titled “14.1 Related Documents”US clients should review:
14.2 External Resources
Section titled “14.2 External Resources”Regulatory Agencies
Section titled “Regulatory Agencies”- FTC: www.ftc.gov
- California AG (CCPA): oag.ca.gov/privacy/ccpa
- USPTO: www.uspto.gov
- Copyright Office: www.copyright.gov
Industry Associations
Section titled “Industry Associations”- Better Business Bureau: www.bbb.org
- US Chamber of Commerce: www.uschamber.com
15. Updates and Changes
Section titled “15. Updates and Changes”15.1 Policy Updates
Section titled “15.1 Policy Updates”Review schedule:
- Quarterly: State law changes
- Annually: Comprehensive review
- As needed: Federal law changes
Notification:
- Email to US clients (30 days advance)
- Website publication
- Opt-out rights for material changes
Last Updated: October 1, 2025 Version: 1.0 Next Review: January 2026
US Client Support: usa@initiumx.dev | +504 3253-6271