INSTITUTION OF THE AMERICAS
Privacy Policy
Effective October 3, 2026
Make a privacy request · Contact form
Who operates this website
Institution of the Americas (IOTA), operated by Rick Alonzo between the United States and Colombia, determines how information submitted to this website and its linked contact form is used. This notice covers institutionoftheamericas.com and the IOTA contact site hosted on ChatGPT Sites. Effective and last updated: October 3, 2026. For privacy questions, use the privacy request form linked below.
Information collected and why
The contact form collects your name, email address, optional organization, and message. We use these details to review your inquiry and respond. The form records when you consented and the version of this notice. Providing contact details is voluntary, but a name, valid email, message, and consent are needed to send a general inquiry. Do not include passwords, government identifiers, financial account details, medical information, or other sensitive data. Reading the published work does not require an account or subscription.
Technical information and cookies
Squarespace and our contact-site hosting providers process technical information such as IP addresses, browser/device information, requested pages, timestamps, and security logs to deliver and protect the websites. Our contact application stores a hashed IP-derived identifier to limit repeated submissions; this is pseudonymous information, not anonymous data. The identifier is cleared after 24 hours on the next form or inbox access. Squarespace optional analytics cookies are restricted until accepted. You can reject optional cookies and change your choice through Cookie Preferences. Necessary security, session, and preference cookies may remain. The contact application adds no advertising pixels or analytics cookies. Hosting and sign-in providers may use their own necessary technologies. Fonts in the contact application are served from that site rather than Google.
Purposes and legal bases
General contact inquiries are processed on your specific consent. You may withdraw consent at any time, without affecting processing that was lawful before withdrawal. Withdrawal may prevent us from continuing the inquiry. Where applicable, requested steps toward an engagement may be processed to enter or perform a contract. Security and abuse prevention serve our legitimate interest in protecting the website and messages. Privacy requests and records required by law are processed to meet legal obligations where applicable. We do not add inquiry senders to a mailing list or use contact messages for automated decision-making that has legal or similarly significant effects.
Providers and disclosures
Squarespace hosts the main website. OpenAI ChatGPT Sites and its hosting subprocessors, including Cloudflare for the contact application, provide hosting, storage, security, and sign-in for the private inbox. Email providers handle replies when we contact you. Authorized access to the inquiry inbox is limited to Rick. Providers receive data needed for their functions, subject to their applicable terms and privacy arrangements. We may disclose information when legally required or needed to establish or defend legal claims. We do not sell personal information or share it for cross-context behavioral advertising.
External platforms and existing accounts
Instagram, Patreon, and Substack are external links, not embedded advertising tools in the contact application. Their own policies apply when you visit, subscribe, or interact there. Existing Squarespace course or customer accounts and billing records, if any, remain separate from the open article library and the new inquiry form. Relevant website, payment, and email providers process those records for access, transactions, support, and legally required records. This form does not collect payment card details or cancel existing accounts.
International processing
IOTA operates in the United States and Colombia, and its service providers may process information in other countries. Where European data-protection rules apply, provider transfer arrangements can include adequacy mechanisms and standard contractual clauses. Squarespace and OpenAI publish data-processing addenda that describe their transfer safeguards. Contact us for information about safeguards relevant to your data. This notice does not mean that every provider stores data exclusively in Europe.
Retention and security
General inquiries in the contact application expire 12 months after submission and are removed on the next form or inbox access. Consent records follow the same period. Earlier deletion can be requested. Copies used for an active engagement, email correspondence, legal claims, accounting, or privacy-request records may need longer retention according to the purpose and applicable law. Provider backups and operational logs follow their own retention schedules. We use HTTPS, server-side inbox authorization, limited data fields, and submission controls. No website can guarantee absolute security.
Your privacy choices and rights
You may request access, correction, deletion, or a copy of your information, withdraw consent, or object to or request restriction of processing where applicable. European rights may include portability and a complaint to your local supervisory authority. California rights, where the CCPA applies, may include knowing/accessing collected information, correction, deletion, opt-out of sale/sharing, limiting certain sensitive-information uses, and non-discrimination. We do not sell or share data for cross-context behavioral advertising or use sensitive information for profiling. Global Privacy Control therefore has no sale/sharing activity to disable. Traditional Do Not Track signals do not separately change necessary processing; cookie choices remain available.
How to make a request
Use the privacy request form and provide the email address associated with your inquiry and the request type. We may verify identity through that email and request only the information reasonably needed to protect your data. Authorized representatives can identify their role in the request. Do not submit identity documents through the form. Where GDPR applies, the usual response deadline is one month; where CCPA applies, it is generally 45 days, with permitted extensions and notice. Other requests are handled reasonably promptly. Request information is used to handle the request, not for marketing.
Children and changes
These websites and inquiry forms are not directed to children under 16. Please contact us if a child has provided information so we can assess removal. We post changes to this notice here with an updated effective date and explain material changes as required by applicable law.