Effective Date: October 13, 2020
Last Updated: November 21, 2025
J.S. Held LLC, its affiliates and related entities (hereinafter known as “J.S. Held”, “we”, “our”, or “us”) is committed to protecting your privacy and providing you with a secure experience as practically possible in the use of our website, mobile apps, and the provision of our diverse business services that we offer (“Services”).
J.S. Held is a global consulting firm that combines technical, scientific, financial, and strategic expertise to advise clients seeking to realize value and mitigate risk, and navigate complex, contentious, and often catastrophic situations. J.S. Held serves a wide range of sectors including, but not limited to, insurance, financial services, construction, technology, environmental health and safety, and energy. found in more details at: https://jsheld.com/consulting-expertise.
This Online Privacy Notice (“Privacy Notice”) explains how we may collect, use, disclose and protect your Personal Information (as defined in Section IV). This Privacy Notice also explains what to do if you do not want to receive marketing e-mails from us. If J.S. Held uses your Personal Information, you may exercise various rights depending on where you are located. See Section VI. for more detailed information.
Please read this Privacy Notice carefully. Each time you visit our Website, Mobile Apps (as defined in Section IV) or use our Services, you consent to the collection, use, storage and sharing of your Personal Information, unless you have previously opted-out, consistent with our then-current Privacy Notice.
This Privacy Notice applies to Personal information which is collected and/or used by J.S. Held in its capacity as a Controller and as a Processor (as defined in Section IV). As a Processor, when we provide Services to our clients and handle Personal Information, we are only processing that information solely on the instruction of our clients, who ultimately are the Controllers of that Personal Information.
We also process Personal Information that has been collected by or provided to us through our Website, other Communications and Mobile Apps and Services that link to or post this Privacy Notice, as well as potential clients that we market to, recruitment applicants, attendees at J.S. Held conferences and related individuals. This Privacy Notice does not apply to our collection, use and disclosure of Personal Information regarding current or former employees.
BY USING OUR WEBSITE, MOBILE APPS, OR COMMUNICATIONS, AND WHEN YOU PURCHASE AND USE OUR SERVICES, YOU UNDERSTAND AND ACKNOWLEDGE THAT WE WILL COLLECT AND USE YOUR PERSONAL INFORMATION IN ACCORDANCE WITH THIS PRIVACY NOTICE. If you have questions, you can always reach out to us by using any of the ways described in the Contact Us Section.
We reserve the right to revise, amend, or modify this Privacy Notice at any time with prior notice and will post the updated version and its effective date at jsheld.com. Where required by applicable law, we will notify individuals of material changes. All interactions with J.S. Held will be governed by the most current version of this Privacy Notice and/or applicable contractual obligations. Please review the Privacy Notice periodically for updates.
Most capitalized terms are defined within this Privacy Notice, however other important terms are included here.
a. Legal Requirements around Personal Information
Our collection, use, sharing, and security of Personal Information are conducted in accordance with this Privacy Notice and applicable law. We collect Personal Information solely when necessary and utilize it for its intended purposes. We endeavor to ensure that the Personal Information processed by the Company is accurate, complete, timely, and pertinent to its purpose.
We retain Personal Information as required by applicable laws and regulations. Your Personal Information will be stored to achieve the objective outlined in this Privacy Notice and subsequently destroyed following the Company’s data retention policies and in compliance with applicable laws and regulations, unless we have a lawful basis to retain it for a longer duration. Additionally, we maintain records as required by law and where required, retain records of processing activities. To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorised use or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve such purposes through other means, and the applicable legal requirements.
b. Data transfers
J.S. Held is headquartered in the United States and information we collect about you may be processed in the United States. By using our services, you acknowledge that your Personal Information may be processed in the United States and, depending on the circumstances, that may involve a transfer of your information to the United States. To the extent that any of your Personal Information is transferred, we will take reasonable measures to ensure that such transfers are lawful, and fulfil the applicable conditions. This includes providing safeguards by entering binding, standard data protection clauses where appropriate for the data subjects’ location. We also enter into data processing agreements and model clauses with suppliers whenever feasible and appropriate.
c. Transparency and notice
We may collect Personal Information directly from individuals for our own business purposes, outside of any contractual relationship. When we do, we aim to be transparent about how we handle that information. To support this, we provide this Privacy Notice, which is available on our website at jsheld.com. We will provide this Privacy Notice at or before the time we collect Personal Information.
If we make significant changes to our privacy practices that affect how we collect or use Personal Information, we will notify you in advance of such changes through appropriate means (e.g., direct communication, website notice, or other effective method) when required by law. In addition, we will update this Privacy Notice accordingly. Updates will be reflected by revising the “Last Updated” date at the top of the page or through other appropriate means. We encourage you to review this Privacy Notice periodically to stay informed about how we protect your Personal Information. Where applicable, this Privacy Notice is optimized for viewing on mobile devices.
d. Data Protection Officer
The Company has appointed an internal data protection officer (DPO) who is responsible for overseeing questions in relation to this Privacy Notice. If you have any questions or concerns about J.S. Held’s Personal Information policies and practices or would like to exercise your privacy rights, please direct your inquiry to the DPO, Nisreen Faddoul at [email protected] and [email protected].
You have the right to make a complaint at any time to the applicable supervisory authority for data protection designated as having jurisdiction to receive such matters at any time. However, we would appreciate the opportunity to address your concerns first, so we encourage you to contact us through any of the methods listed above before doing so.
Under applicable laws and regulations, you may have various rights to your Personal Information such as the right to access, review, modify, obtain a copy, stop sharing, or, in certain instances, delete the Personal Information that J.S. Held has collected, used, or disclosed about you which may vary based on your applicable jurisdiction and are set out in detail in the ‘Your Rights and Choices’ schedule of this Privacy Notice.
If you reside in a state or country that provides you with Data Subject Rights, you can submit a Data Subject Rights Request by completing this form or emailing us at [email protected]. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly or inform you if we require further information, within any applicable statutory deadlines, in order to process your request.
We may ask you for additional information to confirm your identity before disclosing any Personal Information to you. We reserve the right to charge a fee or reject a request, where permitted by law, for instance if your request is manifestly unfounded or excessive.
If you are located in any of the locations listed below, please click on the link for additional state/country specific privacy disclosures and more information on how you can exercise your Data Subject Rights Request.
Depending on your relationship with J.S. Held, we may collect the following categories of Personal Information:

*The legal basis for processing may vary depending on your location and applicable law. Where more than one basis applies, we will rely on the most appropriate basis for each processing activity.
Where we receive Sensitive Personal Information from our clients or other individuals, we expect that such data has been collected and shared with us in compliance with all applicable legal and regulatory requirements. J.S. Held does not use or disclose Sensitive Personal Information for any purposes other than those necessary to provide the relevant services or as permitted by relevant law and in accordance with its requirements.
Collection of Personal Information is optional to browse the website. However, in order to receive our services, collection of your Personal Information may be required unless stated otherwise.
In cases where you do not provide the requested Personal Information, then we may not be able to comply with our obligations under applicable data protection law, and it may affect your use of the website or our services. For example, if you do not accept cookies then the website may not function as intended.
We will not process your Personal Information in a manner that is inconsistent with the purpose for which we have collected the data or the basis on which we have relied to collect your Personal Information, unless we have your consent or a legal basis to process the Personal Information for an additional purpose.
The types of Personal Information we collect about you and how we collect it will depend on your relationship with J.S. Held. For example, in many cases, we may collect Personal Information from our business clients during an engagement to provide Services to our clients, and our collection and use of Personal Information is governed by our contractual obligation with that third-party, as well as applicable legislation.
In other cases, we may collect Personal Information directly and indirectly from activity on our Website, Mobile Apps, and our Communications with you, or from third parties that interact with us in connection with the Services we or the third parties perform, or from job applicants.

If you register for our Website, Mobile Apps or Communications, we will send you promotional messages with your consent. You will be asked to actively choose (opt-in) whether you wish to receive such messages. If you provide your consent, you may withdraw at any time by sending an e-mail to [email protected]. You may also click on the UNSUBSCRIBE link contained in any promotional e-mails that may be sent to you by J.S. Held. If you would like to opt-out of receiving tailored online advertisements from us, please send us an e-mail to [email protected].
To tailor your experience and provide content and services that match your interests—including targeted offers and ads on our Website, Mobile Apps, communications, third-party sites, or other devices—we may request your consent to share information about your interests, demographics, experiences with our Services, and contact preferences. This helps us customize what we offer you. You can withdraw your consent for such marketing or profiling at any time by following the instructions in this section.
We may use or disclose the Personal Information we collect for one or more of the following business purposes and/or to fulfil a legitimate interest:
We will not use the Personal Information we collected for materially different, unrelated, or incompatible purposes without first providing you with notice.
We do not share Personal Information with unaffiliated third-parties, except as stated in this Privacy Notice, including as necessary for our legitimate professional and business needs, to carry out your requests, to market our Services, as required or permitted by law, or otherwise with your consent.
In some instances, we may share Personal Information about you with various third-party service providers and vendors working on our behalf. These third-parties include providers of website hosting, infrastructure provisioning, IT services, customer service, e-mail delivery services, marketing and advertising services, and other similar service providers. We may share your usage and Personal Information with mobile carriers, platform providers and other similar entities in connection with the operation of the Website, Mobile Apps or Communications. Each third-party is required to safeguard Personal Information in accordance with its contractual obligations and data protection legislation applicable to its provision of services.
We may share your Personal Information with subsidiaries or affiliates of J.S. Held, so that they may send you information about special interests or Services that may be of interest to you based on your purchase history, activity on our Website, Mobile Apps, Communications and other information that you have given us. If required under applicable laws, we will seek your prior consent.
We may share your Personal Information with law enforcement and regulatory authorities or other third-parties as required or permitted by law, including for the purpose of: 1) responding to a subpoena, court order or other legal processes; 2) defending, protecting or enforcing our rights; 3) assisting in the event of an emergency; and 4) complying with applicable law or regulation.
If we sell, transfer, or otherwise share some or all our assets in connection with a merger, reorganization, liquidation, dissolution, or sale of assets, we may transfer your Personal Information, subject to compliance with the requirements under applicable laws and regulations.
We may share some aggregated, anonymized, and statistical non-Personal Information with third-parties to better understand how our Website and Mobile Apps are used and to improve user experience.
In the previous 12 months, we have not sold Personal Information as most people would typically understand that term. However, we do work with certain networks, social media companies and other third-party businesses to collect and disclose your Personal Information directly from your browser or device through cookies and related technologies when you visit or interact with our Website, Mobile Apps and otherwise engage with us online. This information is used to provide and inform targeted marketing materials, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research. See Section XV. Information about your Website and Mobile Apps Activity for more detailed information about how third-parties use cookies and related technologies to collect information automatically on our Website, Mobile Apps and other online services, and the choices you may have in relation to those practices.
Depending on the jurisdiction in which you are located, we may be required to obtain your prior consent, or you may have the right to request that we do not disclose the Personal Information we hold on you. To exercise your right to opt-out or withdraw consent, you may submit a request by emailing us at [email protected], visiting the Do Not Sell My Personal Information link on our website, and call 1(877) 871-4113.
J.S. Held recognizes the importance of protecting your Personal Information and we endeavor to maintain reasonable security measures to protect against unauthorized disclosure or access.
J.S. Held has achieved SOC 2 Type II compliance in accordance with the American Institute of Certified Public Accountants (AICPA) which demonstrates that J.S Held manages data with the highest standard of security and compliance. The SOC 2 framework is a set of security standards designed to ensure confidentiality, availability, and privacy of data. Achieving this standard with an unqualified opinion, serves as third-party industry validation that J.S. Held provides enterprise-level security for customer data secured in our systems. However, despite J.S. Held’s efforts, no method of data transmission or storage is 100% secure, so we cannot guarantee against all threats.
We limit access to your Personal Information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Information on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
a. Links to Other Sites
The jsheld.com Website, Mobile Apps and Communications may provide links to other websites, mobile applications or social media pages operated by other third-parties. If you click through to another website, mobile application or webpage, your activity will be subject to the privacy notice of that website, mobile application, or webpage, and not to the J.S. Held Privacy Notice. We recommend that you review the privacy notices of those websites, mobile applications, or webpages before you use them.
b. Use of the J.S. Held Website and Mobile Apps by a Child
The content posted on the J.S. Held Website and Mobile Apps is intended for use by adults. J.S. Held does not knowingly collect information from children who are under the minimum age required by applicable data protection laws in their jurisdiction. If a child provides us with any Personal Information, the parent or guardian should notify J.S. Held by sending an e-mail to [email protected]. Upon receipt of the e-mail, we will delete the child’s information and will remove it from any promotional contact list and database.
If you use the J.S. Held Website or Mobile Apps, we may use cookies and other technologies to collect anonymous information, such as your browser and domain data, navigation history and other information. Location data may be used to find nearby offices, send notifications, and improve marketing services. For further data on the cookies that we collect, please see our Cookie Policy.
We may use anonymized information for advertising purposes and general analytics. If you click through to another website, application or webpage, your activity will be subject to the privacy notices of that website, application or webpage, and not to the J.S. Held Online Privacy Notice or this Policy. We recommend that you review the privacy notices of those websites, applications or webpages before you use them.
a. Information that Third-Parties May Collect About Your Activity on the Website and Mobile Apps
Third-party services, such as Facebook tracking pixels, Google Analytics, or other data aggregators may collect your information on J.S. Held Website and Mobile Apps. They do not provide information back to J.S. Held that links user website activity data to specific individuals. Some of these services may be able to link the user’s activity on the J.S. Held Website and Mobile Apps with other data and target a message to a specific user when the user is on another web or social media site.
In addition to the above, we have implemented on our websites certain Google Analytics features that support display advertising, including re-targeting. Visitors to our Website may opt-out of certain types of Google Analytics tracking, customize the Google display network ads by using the Google ad preferences manager and learn more about how Google serves ads by viewing Google’s Customer Ads Help Center. If you do not wish to participate in Google Analytics, you may also download the Google Analytics opt-out browser add-on.
If you have questions about an ad or other targeted content that you receive, or how third-party services use your data, you should contact the third-party services directly.
The following are the core applications that J.S. Held systems utilize that may process Personal Information.

Different practice areas may use additional tools that process Personal Information as part of the provision of Services. All third-party tools and applications undergo a thorough due diligence process to ensure the security of confidential data as part of our third-party risk management program.
If you have any questions regarding this Privacy Notice, the ways in which we may collect and use your Personal Information, how to update or correct any outdated or inaccurate information, your choices and rights regarding such use, or wish to exercise your Data Subject Rights Request with respect to your Personal Information, please contact us at [email protected], visit the Do Not Sell My Personal Information Link on our website, or call (877) 871-4113.
This California Privacy Notice (“CA Disclosures”) supplements our Privacy Policy and applies only to California residents. It explains how you can exercise your rights under the California Consumer Privacy Act of 2018 (CCPA). Unless stated otherwise, terms follow their definitions in our Privacy Policy or the CCPA. If you have any questions regarding this section of the Privacy Policy, please contact us at [email protected] or call (877) 871-4113.
The following table summarizes your key rights under the CCPA and provides a brief description of each:

a. Exercising Your Rights & Opt-Out Requests
To exercise your rights to access, correct, delete, or transfer your data, please submit a Data Subject Rights Request by emailing [email protected]; completing this Data Subject Access Request form, or calling us toll-free at (877) 871-4113.
Only you, or an authorized agent registered with the California Secretary of State, may make such a request related to your Personal Information, including for a minor child. Requests for access or data portability can be made up to twice per year. We must verify your identity before processing the request and will use your information only for this purpose. If we cannot verify your identity or authority, we cannot fulfill your request. Please note, certain laws may impact the ability to fulfill requests, such as those requiring employee data retention.
J.S. Held does not sell your Sensitive Personal Information and has not done so in the preceding twelve (12) months. To inquire about your rights including exercise the Right to Opt-Out of Personal Information Sales, you may submit a request by emailing us at [email protected] or by calling us at (877) 871-4113.
b. Response Timing
We strive to respond to a Data Subject Rights Request within 45 days of its receipt. If we require additional time, we will inform you of the reason and extension period in writing. Written responses will be provided based upon the information you provide to us. In certain circumstances, we may decline a request to exercise the rights described above, particularly where we are unable to verify your identity, if the rights of another individual might be violated or as otherwise permitted by law. If we are unable to comply with all or a portion of your request, we will explain the reasons for declining to comply with the request.
c. Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by California law, we will not: deny you goods or services; charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; provide you a different level or quality of goods or services; or suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
d. Use of the J.S. Held Website and Mobile Apps by a Child Under Age 16
The content posted on the J.S. Held Website and Mobile Apps is intended for use by adults. J.S. Held does not knowingly collect information from children under the age of 16. If a parent or guardian becomes aware that a child provides us with any Personal Information, the parent or guardian should notify J.S. Held by sending an e-mail to [email protected]. Upon receipt of the e-mail, we will delete the child’s information, and will remove it from any promotional contact list and database.
If you have any questions regarding this section of this Privacy Notice, please contact us at [email protected] or call (877) 871-4113.
Depending on the state where you reside (i.e., Virginia, Colorado, Utah, Connecticut, etc.), you may have certain rights regarding your Personal Information. If you have any questions regarding this section of this Privacy Notice, please contact us at [email protected] or call (877) 871-4113.
The following table summarizes your key rights and provides a brief description of each:

a. Exercising Your Rights & Opt-Out Requests
To exercise your rights, please submit a Data Subject Rights Request by emailing [email protected]; completing this Data Subject Access Request form, or calling us toll-free at (877) 871-4113.
Only you, or an authorized agent registered with the California Secretary of State, may make such a request related to your Personal Information, including for a minor child. Requests for access or data portability can be made up to twice per year. We must verify your identity before processing the request and will use your information only for this purpose. If we cannot verify your identity or authority, we cannot fulfill your request. Please note, certain laws may impact the ability to fulfill requests, such as those requiring employee data retention.
J.S. Held does not sell your Sensitive Personal Information and has not done so in the preceding twelve (12) months. To inquire about your rights including exercise the Right to Opt-Out of Personal Information Sales, you may submit a request by emailing us at [email protected] or by calling us at (877) 871-4113.
b. Response Timing & Appeals
We aim to respond to a Data Subject Rights Request within the timeframe required by the applicable data protection laws. If more time is needed, we will provide the reason and extension period in writing. Written responses will be based on the information you supply.
In certain situations, a request to exercise the rights described above may be declined, especially if identity verification is not possible, if another individual's rights could be affected, or as allowed by law. If full or partial compliance with your request is not possible, the reasons for declining will be communicated.
You also have the right to request an appeal if we are unable to comply with your request. We strive to respond to your appeal within 60 days of its receipt, including a written explanation of the reasons for the decisions. If the appeal is denied, you have the right to submit a complaint with the relevant regulator or data protection authority.
c. Non-Discrimination
We will not discriminate against you for exercising any of your rights. We will not: deny you goods or services; charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; provide you a different level or quality of goods or services; or suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
This EU and UK Privacy Notice (the “EU and UK Disclosures”) supplements our Privacy Policy and applies only to residents of the European Union and UK. It explains how you can exercise your Data Subject Rights under GDPR, the Data Protection Act 2018, and UK GDPR. Unless stated otherwise, terms here follow our Privacy Policy or the GDPR. If you have any questions regarding this section of the Privacy Policy, please contact us at [email protected] or call (877) 871-4113.
The following table summarizes your key rights and provides a brief description of each:

For any processing of personal data relating to individuals located in the Kingdom of Saudi Arabia (KSA), J S Held is the registered entity and data controller. The registered address for J S Held is 1st Floor, Office 111, Riyadh Park Al Aqiq, 11564.
KSA residents, under Saudi Arabia’s Personal Data Protection Law (PDPL), have the following core data subject rights:

a. Exercising Your Rights
If you would like to exercise any of the above rights, complete this Data Subject Access Request form, or, you can contact us in writing. Please refer to “Contact Us” section in the Privacy Notice to obtain the relevant contact data. We will endeavor to get back to you as soon as possible and in line with statutory deadlines. If any request is repetitive, manifestly unfounded, or requires disproportionate efforts, we reserve the right to refuse it, in which case we will notify you of the refusal and the reason behind it.
Please note: We may need to request specific data from you if we receive a request from you. This is to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). It is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it.
You have the right to lodge a complaint with the competent data protection authority in Saudi Arabia, currently SDAIA (Saudi Data and Artificial Intelligence Authority), via https://sdaia.gov.sa, or any other authority later designated. However, we encourage you to contact us first at [email protected] so we can address your concerns promptly.
b. Response Timing
We aim to respond to Data Subject Rights Requests within 30 days. If more time is needed, we will notify you in writing with the reason and extension period. We use your information only to process your request.