Privacy Policy
Last updated: August 3, 2026
1. Who we are
Tyl Consulting LLC (“we,” “us,” or “our”) is a limited liability company formed in Wyoming, United States. Our office is at 30 N Gould St STE R, Sheridan, WY 82801. You can reach us at usa35@e-min.co.kr or +1 (205) 419-5578.
We provide immigration case management services. To do this work, we operate an internal case management system.
2. What this policy covers
This policy explains how Tyl Consulting LLC handles personal information in our immigration case management work.
Our case management system is not a public product. It is an internal system. Only our authorized employees and contracted professionals can log in. Clients do not have accounts and cannot log in.
This policy covers two groups of people:
- Clients. People who hire us for immigration services. We store their case records in the system.
- Staff users. Our employees and contracted professionals who use the system to do their work.
3. Information we collect
We collect information directly from clients during consultation and case work. We also receive documents that clients send us. We do not buy personal information from data brokers.
About clients and their family members
| Category | Examples |
|---|---|
| Identity | Name, date of birth, gender, nationality, passport number |
| Contact | Email address, phone numbers, home address, messaging IDs |
| Background | Occupation, field of study, education, criminal record status |
| Family | Names, dates of birth, and relationships of the spouse and dependent children listed on a petition |
| Case records | Case type, status, milestones, USCIS receipt numbers, consultation notes, call logs |
| Documents | Files clients send us for a petition, such as passports, certificates, financial records, employment records, and health documents a petition requires |
| Contracts | Service agreements and related records |
About staff users
| Category | Examples |
|---|---|
| Account | Name, work email, phone number, job title, team, role and permissions |
| Security | Password (stored only as a one-way hash), login times, IP address |
| Activity | Audit logs of records viewed, created, changed, or deleted |
Children
We store information about dependent children when a client lists them on a petition. We receive this information from the client, who is the parent or legal guardian. We do not collect information directly from children, and the system has no accounts for children.
Categories we do not collect
We do not collect geolocation or device-location data, biometric identifiers, advertising identifiers, browsing history across other websites, or the contents of a device address book, contact list, calendar, or photo library. The only location-related item we store is the IP address in a staff login log. We use it for security only, never to work out where a person is.
The only financial information we hold is the financial evidence a client sends us for a petition. That includes bank statements, tax returns, payroll and employment records, and proof of investment funds.
Some petitions require a health document, such as a Form I-693 medical examination report or a vaccination record. We store that document with the case and use it only to prepare and file that petition. We do not collect genetic or DNA test results unless USCIS asks for them for a specific filing. We never use health information for any other purpose.
4. How we use information
We use personal information to:
- Prepare, file, and track immigration petitions for our clients
- Check case status with U.S. Citizenship and Immigration Services (USCIS)
- Communicate with clients about their case
- Keep records required by law and by our professional duties
- Secure the system, investigate misuse, and keep audit trails
- Manage staff accounts and access rights
We do not use client information for advertising. We do not use it to make automated decisions that produce legal effects.
De-identified, anonymized, and pseudonymized data
We do not build de-identified, anonymized, pseudonymized, or aggregated data sets from client or staff information for any purpose other than our own internal case-volume statistics. We do not share, sell, license, publish, or transfer such data to anyone outside Tyl Consulting LLC and the recipients named in Section 5. Where Section 7 says we make a record permanently anonymous at the end of a retention period, that record is stripped of every identifier, kept only as a count, and never sent outside our systems.
5. How we share information
We do not sell personal information. We have never sold personal information. We do not sell it for profit, for money, or for any other monetary transaction or valuable consideration. We do not rent, trade, barter, or license it.
Who receives information, and what they may do with it
We share personal information only with these recipients:
| Recipient | What they receive and how they use it |
|---|---|
| USCIS and other government agencies | Petition data and USCIS receipt numbers. They use them to decide filings and to return case status, under their own rules. |
| Kookmin Emigration Corporation (Republic of Korea), our affiliate | Full case records. It operates our servers and performs case work for us. It may use the information only for those purposes. |
| Outside professionals we engage for a specific case | The records for that case only, and only for the work we engage them to do. The U.S.-licensed attorneys who handle our clients' cases are our own staff, not outside counsel. |
We also disclose information when the law requires it, for example under a valid subpoena, a court order, or a legal claim.
We do not share personal information with marketers, advertising networks, analytics resellers, data brokers, affiliate partners, or resellers of any kind. We have no such relationships. If we ever add a recipient, we will update this section before the sharing begins.
Whether we sell data
Is personal information sold? No. Is any of it sold for profit? No. Is any of it exchanged for money, credits, discounts, services, data in return, or any other valuable consideration? No. This applies to client information, staff information, case documents, and to any de-identified, anonymized, pseudonymized, or aggregated data made from them.
Neither Tyl Consulting LLC nor Kookmin Emigration Corporation has sold or otherwise monetized such data, at any time, and we have no plans to do so. If this ever changes, we will amend this section, tell affected clients by email at least 30 days before the change takes effect, and get their written consent first. We will never apply such a change to information we already hold without that consent.
How sharing affects other people
An immigration petition is rarely about one person alone. The information you give us normally includes your spouse and your dependent children. It sometimes includes your parents, siblings, employer, or financial sponsor. It may include family history that a petition requires, such as a family relationship chart, a marriage, birth, or adoption record, or, where USCIS asks for one, the result of a DNA relationship test.
When we file that petition, information about those relatives goes to USCIS. It becomes part of a United States government record about them, not only about you. Once submitted, it cannot be recalled from USCIS.
This can affect those relatives directly:
- It can influence their own current or future immigration filings.
- It can reveal a family relationship, or a family or genetic history, that a relative did not intend to disclose.
- Information about a shared genetic history also says something about blood relatives who are not part of your case at all.
Before you send us information about another person, please make sure that person knows and agrees. Any relative who contacts us may ask what we hold about them. They may use the rights in Section 8 by writing to usa35@e-min.co.kr, even though they hold no account in our system.
Limits on third parties
No third party that receives information from us may use it or disclose it beyond the specific service it performs for us. It may not do so for any reason without the active, opt-in consent of the person the information is about. This ban applies equally to de-identified, anonymized, pseudonymized, and aggregated data made from that information. A third party may not re-identify, enrich, resell, publish, or independently analyze it.
Our case management system has no client accounts, so active consent is not collected through an app screen. For clients we obtain it directly in writing, either in the signed engagement letter or by a written confirmation the client sends to usa35@e-min.co.kr naming the recipient and the purpose. For staff users we obtain it through the acceptance step described in Section 13.
Consent given for one filing or one purpose never carries over to another. The only exceptions are disclosures compelled by law, subpoena, or court order. We will tell the affected person about such a disclosure unless the law forbids us from doing so.
Every third party listed above is bound by a written contract with us. Each contract requires the third party to comply with the terms and conditions of this Privacy Policy and to apply protections at least as strict as those described here.
Each contract also requires the third party to:
- Use the information only for the service it performs for us
- Never disclose it onward, and never use it independently, including to de-identify or re-identify it
- Apply the safeguards listed in Section 10
- Tell us without delay about any suspected breach
- Bind its own subcontractors to the same terms in writing
- Return or permanently delete the information when the engagement ends
We review these commitments. We end the relationship and require deletion if a third party breaks them.
Change of ownership, sale, or closure of the business
If we merge with another company, are acquired, sell all or part of our business, or transfer our assets, the personal information we hold may pass to the buyer or the successor as part of that transaction. Two protections apply.
Alignment. We will require, in a written agreement, that the buyer or successor apply this Privacy Policy, or a policy that protects you at least as strongly, to the information it receives. We will also require that it use the information only for the immigration services you engaged us for.
Your choice before the transfer. We will email affected clients and staff users at least 30 days before the transfer takes effect. Before the transfer date you may ask us to do one of the following:
- Securely destroy your records
- Send you a downloadable copy of your records in a common electronic format
- Transmit your records directly to another law firm, agency, or provider that you name
This choice covers all of your records. That includes health information such as immigration medical examination results (Form I-693), civil surgeon reports, vaccination records, and any other medical document you gave us for a petition or a waiver. We do not charge for the first request.
If we close. If we close the business without a successor, we will securely destroy all personal information within 90 days of closing. The only exception is a record that a law or an active legal claim requires us to keep. We will tell you before we do this.
We will tell you. We will notify you of any change in the ownership or control of Tyl Consulting LLC. That includes a merger, an acquisition, a sale of our business or our assets, a change of control of the affiliate that operates our servers, or the appointment of an administrator or trustee.
We send the notice by email to the address we have on file, and we post it on this page, at least 30 days before the change takes effect. The notice names the new owner, gives the effective date, says whether this Privacy Policy still applies, and explains the choices above.
If a transaction closes faster than the law lets us announce it, we will notify you within 10 business days after it closes. You keep the same choices for 30 days after that notice.
6. Where we store information
We store information on servers located in the Republic of Korea. Our affiliate Kookmin Emigration Corporation operates these servers and performs case work on our behalf under a written agreement. That agreement requires the same protections described in this policy.
Some of the recipients in Section 5 are in the United States.
If you are outside Korea, your information will be transferred to Korea. By using our services, you understand that these transfers take place.
7. How long we keep information
| Record type | Retention period |
|---|---|
| Client case records and documents | 7 years after the case closes or the engagement ends |
| Consultation records for people who did not become clients | 3 years after the last contact |
| Staff user accounts | Deactivated on the last day of employment or engagement, then the account record is deleted after 90 days |
| Dormant staff accounts | Disabled after 90 days without a login, then deleted 365 days later |
| Audit and security logs | 5 years |
Dormant accounts. We treat a staff account as dormant after 90 days with no login. We disable it at that point. We delete the account record and its personal contents 365 days after we disabled it. Clients hold no accounts in our system, so no client account can become dormant. A client's case records follow the 7-year period above, counted from the day the case closes or the engagement ends.
We check records and accounts against these periods on a regular schedule, and we delete the ones that have passed. We may keep information longer when a law, a regulation, or an active legal claim requires it. When a retention period ends, we delete the information or make it permanently anonymous.
8. Your rights
You may ask us to:
- Tell you what personal information we hold about you
- Give you a copy of it
- Correct information that is wrong
- Delete your information
- Stop or limit certain uses of your information
- Withdraw consent you gave earlier
How to make a request. Send an email to usa35@e-min.co.kr with the subject line “Privacy Request.” Tell us what you want us to do. We may ask you for proof of identity so that we do not give your information to the wrong person.
How fast we respond. We confirm receipt of your request within 10 business days. We complete the request within 30 calendar days. If we need more time, we will tell you why and finish within 60 calendar days in total.
Deleting your data permanently
You may ask us at any time to delete your personal information permanently. Send an email to usa35@e-min.co.kr with the subject line “Delete My Data,” or call +1 (205) 419-5578 and ask for the Privacy Officer. You do not need an account, a form, or a fee.
Permanent deletion means we erase the record from our live systems and remove it from our backups. Any copy that still sits in a backup until then is isolated and is not used for any purpose. We confirm in writing when the deletion is complete. Deletion is permanent: we cannot restore a deleted record.
How soon we delete. We erase the records from our live systems within 30 calendar days of the day we verify your identity, and from our backups within 90 calendar days. We do not extend the 30-day live-system deadline.
Step by step:
- Send an email to usa35@e-min.co.kr with the subject line “Delete My Data.”
- Give us your full name, your date of birth, the email address or phone number we have on file, and your case number if you know it.
- Tell us whether you want everything deleted or only certain records, and list the records if it is only some.
- We reply within 10 business days. We may ask for a copy of a photo ID so that we do not delete the wrong person's file.
- We erase the records on the schedule above and email you a written confirmation when we are done.
Our system is an internal tool and clients have no login, so there is no self-service delete button. Email is the only channel, and we treat a request sent there exactly as we would treat an in-app delete request. Staff users send the same email or ask their administrator.
When we cannot delete. Immigration law and our professional duties require us to keep some records for a set period. If we cannot delete a record, we will tell you which rule requires us to keep it, and the date it becomes deletable. We delete everything else on the schedule above.
Your data-sharing choices, and what they mean
Sharing your case information with USCIS, and with the attorney and case staff assigned to your case, is required to do the work you hired us for. The benefit is that we can prepare, file, and track your petition, retrieve your case status directly from USCIS, and warn you about deadlines. You may refuse or withdraw this sharing at any time by writing to usa35@e-min.co.kr.
The limits and risks of that choice are these. We cannot prepare or file a petition without sharing the required information with USCIS. A petition already filed may be delayed, denied, or treated as abandoned if we can no longer respond to USCIS on your behalf. Information already submitted stays in United States government records under USCIS rules, so we cannot withdraw or delete it. Any transfer of information over the internet also carries the residual risk described in Section 10.
Sharing is entirely optional for our newsletters, seminar invitations, and satisfaction surveys. You may refuse or withdraw those at any time, with no effect on your case.
No penalty. We will not deny you service or charge you a different price because you used these rights.
9. Closing an account
Staff users. We disable an account on the last day of employment or engagement. The account owner or an administrator may also request closure at any time by writing to usa35@e-min.co.kr.
We disable the account within 3 business days and delete the account record after 90 days. Audit logs that name the account are kept for the period in Section 7.
Clients. Clients do not hold accounts. A client may end the engagement at any time and may then ask us to delete their records under Section 8.
10. How we protect information
We use these safeguards:
- Encryption in transit (HTTPS)
- Encryption of stored credentials, including third-party interface keys and OAuth client secrets. These are held only on our backend servers. They are never placed in browser code, mobile apps, or any other client-side component.
- Role-based access control, so a user sees only the records their job requires
- One-way hashing of passwords
- Audit logging of access to records and files
- Access reviews and prompt removal of access when a person leaves
No system is perfectly secure. We cannot promise that a breach will never happen.
11. If a breach happens
If a breach affects your personal information, we will notify you as soon as we can. We will notify you no later than 72 hours after we confirm the breach. We will wait longer only if a law enforcement agency asks us to.
We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. We will also notify regulators when the law requires it. We notify clients at the email address or phone number on file for their case, and staff users at their work email address and on the system login screen. A client does not need an account to receive this notice.
Our notice will name a contact for questions and list the steps we recommend. Those steps may include changing a password, turning on additional login security, watching for phishing messages that refer to your case or to USCIS, contacting USCIS about your receipt number, and reporting suspected identity misuse at identitytheft.gov. You may request a copy of the incident report at any time by writing to usa35@e-min.co.kr.
12. Your California privacy rights
We have reviewed the California Consumer Privacy Act. We do not sell or share personal information, and we do not offer a consumer product to California residents. Our system is an internal tool used only by our own staff, so we may not meet the definition of a “business” under that Act. We do not rely on that.
We grant every California resident whose information we hold the rights listed below. We honor their requests through the process in Section 8 and apply the same timelines. We do not charge for these requests, and we do not treat anyone differently for making one.
- Right to know. You may ask which categories of personal information we collected, why we collected them, and with whom we shared them.
- Right to delete. You may ask us to delete personal information we collected about you.
- Right to correct. You may ask us to fix inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- Right to limit use of sensitive personal information. We use sensitive information, such as passport numbers, only to deliver the service you asked for. We do not use it for any other purpose.
- Right not to be discriminated against. We will not treat you differently for using these rights.
To use these rights, write to usa35@e-min.co.kr. An authorized agent may make a request for you if they give us written permission signed by you. You may appeal a decision we make on your request by replying to our written answer. We respond to an appeal within 45 calendar days.
13. Changes to this policy
We may update this policy. We post the current version on this page and show the date at the top. Our Terms of Service are at tylhub.com/terms.
We get your active consent before any change to this Privacy Policy takes effect for you, whether or not we consider the change material. Active consent means you click “I Agree” on the notice we show you. Continuing to use the system, staying silent, or not replying is never consent. Until you give active consent, we keep handling your information under the version you last accepted.
- Staff users must read and accept the new policy at their next login. Until they accept, they cannot use the system.
- Clients receive an email at least 30 days before the change takes effect. They give consent by replying with their agreement or by clicking the confirmation link in that email. If a client does not consent, we keep handling their information under the version they last accepted, and we contact them to agree on next steps.
What the notice contains. Every notice of a change comes with a plain-language summary. The summary lists each change in short sentences, says why we made it, and says what it means for you and for the information we already hold.
Next to the summary we show a link to the full new text, and a marked-up comparison against the version it replaces, so you can see exactly what was added, changed, or removed. You see this summary on the same screen where you click “I Agree,” so you never have to consent to a document you have not had a chance to understand.
We keep every past version together with its summary. We record the date, the version, and the person for every consent we receive. Past versions stay available on this page.
14. Contact us
Tyl Consulting LLC
30 N Gould St STE R, Sheridan, WY 82801
Email: usa35@e-min.co.kr
Phone: +1 (205) 419-5578
If you are not satisfied with our answer, you may contact your local data protection authority.