
Compliance
Compliance Responsibilities
We configure the safeguards. You own the legal compliance. It starts with what we turn down: we do not sign business associate agreements, and we do not accept data that would require one.
On this page · 8 sections
What we will not take
Most agencies tell you what they can do. This is the part we get asked about least and that matters most, so it goes first.
We do not sign business associate agreements, and we do not accept data that would require one.
Taking regulated data means taking on a security program, an audit trail, a signed chain of agreements with every vendor beneath us, and direct liability under a federal statute. Doing that properly is a different business from ours, and doing it badly is worse than not doing it at all. So we do not do it, and we tell you before you ask rather than after you have paid a deposit.
The categories below are the ones that trigger a business associate agreement or its equivalent. None of them may be collected by, stored in, transmitted through or displayed by anything we build or manage for you.
| We do not accept | Under | Because it would require |
|---|---|---|
| Protected health informationAnything identifying a person and relating to their health, care or payment for care. | HIPAA | A business associate agreement |
| Substance use disorder recordsTreatment records from a federally assisted program. | 42 CFR Part 2 | A Qualified Service Organization Agreement |
| Student education recordsAnything identifying a student and held by a school or district. | FERPA | A written school official agreement |
| Consumer financial account dataAccount numbers, balances, credit files, loan applications. | GLBA and the FTC Safeguards Rule | A service provider contract with a written security program |
| Cardholder dataA full card number in a form, an email, a call recording or a support ticket. | PCI DSS | A service provider agreement and an annual attestation |
| Criminal justice informationRecord checks, case data, anything sourced from a law enforcement system. | CJIS | A CJIS security addendum and personnel screening |
| Biometric identifiersFace, fingerprint or voiceprint templates, including from a photo or a recording. | Illinois BIPA, Texas CUBI and similar | A written release and a published retention schedule |
| Data knowingly collected from children under 13Any form, quiz or signup aimed at children. | COPPA | Verifiable parental consent and a direct notice flow |
| Consumer health dataBroader than HIPAA and it reaches businesses that are not covered entities at all. See the note below. | Washington My Health My Data, Nevada SB 370 | Separate written authorization before collection or sharing |
What that rules out, concretely
- Intake forms that ask a clinical question. No condition, symptom, diagnosis, medication, insurance or reason-for-visit field, and no free-text box that invites one.
- Upload fields for regulated documents. No medical records, insurance cards, financial statements, benefit letters or identity documents.
- Patient portals and member areas. No authenticated surface that holds any category in the table above.
- Call recording on a clinical or payment line. Covered in full under call recording below.
- CRM, email or SMS carrying regulated content. The automation we build moves names, contact details and inquiry source. It does not move clinical or financial detail.
- Analytics or advertising tags behind a login. No pixel, tag or session recorder on an authenticated page, for any client, in any industry.
Not being a HIPAA covered entity does not clear you. Washington My Health My Data and Nevada SB 370 define consumer health data far more broadly and apply to ordinary businesses, not just to healthcare. A gym, a supplement shop, a med spa, a chiropractor or a wellness coach can generate it without ever touching HIPAA. If your marketing would infer something about a person’s health, including from which page they visited, that is the law to read first and it is yours to answer for.
What we do sign
Declining a business associate agreement is not the same as declining to put our obligations in writing. Ordinary business contact data, a name, a work email, a phone number, the inquiry itself, is the entire point of a lead-generation system and we handle it under written terms.
- A data processing agreement. Standard Article 28 processor terms under the UK and EU GDPR. Ask and we will provide one.
- Service provider terms under US state privacy law. Including the CCPA and CPRA restrictions on retaining, using or disclosing personal information for anything other than your instructions.
- Confidentiality. Set out in the Terms and Conditions and applying to everything you give us, regulated or not.
Those are processor terms. They are not a business associate agreement and they do not carry one hiding inside them. If a document you have been sent calls itself a DPA but obliges us to handle protected health information, we will decline to sign it and tell you which clause is the problem.
The general division
You are the controller of every inquiry your website produces. We are your processor and we act on your instructions. That is not a formality, it decides who is answerable to the person who filled in the form.
-
The technical safeguards
Ours to get right. Encryption in transit, access controls, form handling, consent banners actually wired to the tags they gate, opt-out handling, backups, and keeping the stack patched. If a safeguard we configured fails, that is on us.
-
The vendors underneath us
Ours to choose and contract. Hosting, CDN, mail, SMS, analytics. We contract with each one, limit what they may do with the data, and keep the list current so you can see who touches what.
-
Telling you when we think you have a problem
Ours to raise. If something you have asked for looks like it puts you on the wrong side of a rule, we say so before we build it, not after. We are not your lawyer and we will tell you to get one.
-
Telling you fast if something goes wrong
Ours to report. If a system we manage is breached we tell you promptly with what we know, and we keep telling you as we learn more. Notifying anybody else is a decision only you can make.
-
Whether you may lawfully hold the data at all
Yours to establish. The lawful basis, the industry rules that apply to you, and whether a particular field should be on the form in the first place. We will build what you specify and flag what worries us.
-
Your privacy policy and your notices
Yours to publish and maintain. We supply the notice wording for anything we build and we place it at the point of collection. Keeping it there, and keeping your policy consistent with it, is yours.
-
Consent records and proof of opt-in
Yours to hold and produce. We build the capture and the timestamp. When a regulator or a plaintiff asks you to evidence consent, the record is in your systems and the answer comes from you.
-
Requests from people who ask what you hold
Yours to answer. Access, correction, deletion, opt-out. We will help you action any of them inside the systems we built. We cannot answer on your behalf and we will not pretend to.
Configuring a system correctly is not the same as being a compliant business. Any vendor who tells you otherwise is selling you a false sense of security.
Frameworks that still apply
Taking regulated data off the table removes the agreements. It does not remove these, and every one of them reaches an ordinary local business running ordinary marketing.
TCPA and A2P messaging
We configure the opt-in capture and its timestamp, the STOP and HELP handling, quiet-hours settings, and the carrier brand and campaign registration that lets your messages deliver at all.
You own the consent itself, and the record proving it. Marketing texts to a mobile need prior express written consent, revocation has to be honored promptly, and you need an internal do-not-contact list. This is the highest-volume litigation area in US marketing and the damages are per message.
CAN-SPAM and CASL
We configure a working one-click unsubscribe, your physical postal address in the footer, accurate headers, and suppression that actually suppresses.
You own the list and where it came from. CAN-SPAM is an opt-out regime and lets you send until someone objects. CASL is not. If you email anyone in Canada you need express or implied consent before the first message, with records, and the penalties are materially higher.
GDPR and UK GDPR
We configure consent-gated tracking that genuinely blocks until consent, data minimization in the forms, and we will sign an Article 28 data processing agreement on request.
You own the lawful basis, your privacy notice, and answering data subject requests. It applies if you offer services to or monitor people in the EU or UK, which a website can do without you intending it.
US state privacy laws
We configure the opt-out mechanism, honoring the Global Privacy Control browser signal, and the notice at collection.
You own working out which states you are in scope for, and answering the requests. Sharing data with an advertising platform counts as a sale or share under several of these acts even though no money changes hands, which is the part that surprises people.
PCI DSS
We configure payments through a hosted checkout so the card number never reaches your website or ours. That keeps you in the simplest self-assessment category and keeps cardholder data out of our scope entirely.
You own the merchant account and the attestation your acquirer asks for. We will not build a form that accepts a card number directly, and we will not take one by email, text or phone.
State consumer health data laws
We configure to avoid generating it: no condition-specific audience building, no tracking on pages that would infer a health status, and no pixel behind a login.
You own the call on whether your marketing infers something about health. Washington My Health My Data and Nevada SB 370 reach businesses that are nowhere near HIPAA, and Washington carries a private right of action.
HIPAA is absent from this list on purpose. It does not appear as a shared responsibility because we do not put ourselves in a position where it could apply. See what we will not take, and what we can still build you if you are in healthcare.
Lead verification and enrichment
This runs on every Foundation and Growth site, and it creates an obligation for you that most vendors never mention.
Where your build includes lead verification or enrichment, information submitted through your website is processed automatically before it reaches your team. It is checked for spam, the email address is verified as deliverable, the phone number is validated as a working line, publicly available business information may be added, and the inquiry may be scored and routed according to criteria you set.
What we handle
- Configuring the verification and enrichment steps to your specification
- Contracting with the providers who perform each step, and limiting their use of the data to that purpose
- Building the notice language into the forms we deliver
- Ensuring enrichment results are stored in systems you control
- Telling you what data each step adds, and from where
What you own
- You are the data controller for every inquiry submitted through your website. We act as your processor. This is not a formality. It determines who is answerable to the person who submitted the form.
- Disclosing that enrichment happens. Your privacy policy must describe it, and notice must appear at the point of collection. We will supply the notice text and place it on the forms we build. Keeping it there, and keeping your privacy policy consistent with it, is yours.
- Responding to requests from people who ask what you hold about them, or ask you to delete it. We will help you action a request. We cannot answer it on your behalf.
- Deciding what to enrich. If you ask us to append information beyond business data, property records or household information for example, that decision and its lawful basis are yours.
- Your retention periods for inquiry data, and applying them.
What we will not do
- Append a regulated attribute. Enrichment adds business and property context. It does not add health status, condition, diagnosis, prescription history, credit file, income or any other category from what we will not take. We will decline the request and say why.
- Infer a health status from behavior. Scoring an inquiry higher because of which service page they landed on is legitimate for a roofer and is consumer health data for a clinic. We will not build the second one.
- Use your inquiry data for our own purposes, or for any other client.
- Sell, rent or share it. Ever, to anyone.
- Retain it after our engagement ends, beyond what we are required to keep.
If a visitor asks why you know where they work, the answer has to come from you, and it has to be in your privacy policy before they ask.
Call tracking and recording
A genuine exposure that varies by state rather than by anything you control, and it is the one clients are most surprised by.
Call tracking assigns a phone number to a marketing source so a call can be attributed to what produced it. That is the part we recommend. Recording is separate, it is off by default, and we turn it on only if you ask.
What we handle
- Configuring tracking numbers, routing and attribution
- Enabling or disabling recording according to your instruction
- Configuring an announcement at the start of a recorded call where you require one
- Ensuring recordings are stored in an account you control
What you own
- Whether to record at all. We will enable it if you ask and we will tell you what it involves. The decision is yours.
- Consent. Recording consent law varies by state. Some states require only one party to consent, which is you. Others require every party on the call to consent, and the stricter state’s law may apply when a call crosses a state line. A business recording calls from customers in another state can be subject to that state’s rules.
- Announcing it. Where all-party consent is required, the usual approach is an announcement at the start and continuing with the call as consent. If you record, we strongly recommend the announcement stays on for every call regardless of state. It is a small cost against a real risk.
- Retention and access. How long recordings are kept, who can listen to them, and responding to anyone who asks for a copy or asks you to delete one.
Where we say no
A recording is a copy of whatever was said. If a caller describes a symptom, reads out a card number or gives an account number, the recording becomes regulated data, and it lands in a system we configured. That is exactly the position we have decided not to be in.
- We will not enable recording on a line that takes clinical detail. Appointment lines for clinics, practices, therapists and treatment providers included, whether or not you are a HIPAA covered entity.
- We will not enable recording on a line that takes payments. If you take card numbers by phone, that line stays off the recorded set.
- We will not transcribe or run analysis over recordings that could surface a regulated attribute, and we will not feed them into enrichment or scoring.
Our default is that recording is off unless you ask for it, and where it is on, the announcement is on with it. Call tracking without recording gives you the attribution data anyway, which is what most clients actually wanted.
Reviews and testimonials
Where your build includes a review request funnel, it asks customers for a public review at the point they are most likely to leave one. That is the whole mechanism, and it works because the reviews are real.
What we handle
- Building the request flow and the timing
- Making the review link available to every customer, not only to those who rated you highly
- Configuring reminders and monitoring
What you own
- Never buying, incentivizing or writing reviews. Offering a discount, a gift card or a prize draw entry in exchange for a review is prohibited by the major platforms and treated as deceptive by the FTC. It is also the fastest way to lose a profile you spent years building.
- Never filtering who gets asked. Showing the public review link only to customers who rated you well, known as review gating, violates Google’s terms and is treated as deceptive. Our funnels do not do it and you should not add it.
- Disclosure of any material connection. If a reviewer is an employee, a relative, or received anything of value, that relationship has to be disclosed in the review under FTC rules.
- Permission before publishing. A testimonial used on your website needs the customer’s agreement, and a name or photograph needs it explicitly.
- Accuracy of results claims. A testimonial describing a specific result implies it is typical. If it is not, that has to be clear.
A testimonial can be regulated data. A patient naming their condition in a review you publish on your own site is health information you have chosen to display. Getting permission is necessary but it is not the whole answer, and in a healthcare setting it is a question for your counsel rather than for us. Our funnels point customers at the public platform, where the customer decides what to write and publishes it themselves.
We will decline to build a gated review funnel, and we will say why. It is not a preference, it breaks the platform terms our clients depend on.
Advertising and tracking
Accounts in your name, spend paid by you to the platforms, claims you can substantiate, and tags placed only where they cannot see something they should not.
What we handle
- Building and managing campaigns, landing pages and conversion tracking
- Operating within the advertising platforms’ policies to the best of our knowledge
- Reporting on spend, cost per lead and outcomes
- Never touching or marking up your advertising spend. It is billed by the platforms directly to you
What you own
- The accounts. They are in your name with your billing. We hold delegated access. If we part ways, the accounts and their history stay with you.
- The spend. You set the budget and you pay the platforms. We do not fund advertising and we do not extend credit for it.
- The truth of your claims. Advertising is subject to truth-in-advertising rules. Claims about pricing, availability, guarantees, licensing, credentials or results are yours, and you must be able to substantiate them. We will refuse to run a claim we believe is unsubstantiated, and we may ask you to evidence one.
- Regulated categories. Some industries carry additional advertising rules. Healthcare claims, legal services, financial products and contractor licensing disclosures among them. Your obligations under those rules are yours.
- Platform policy compliance in your industry. We know the general rules. We are not specialists in the restricted-category requirements that may apply to you.
Where we place tags, and where we refuse to
Google and Meta will not sign a business associate agreement for their advertising and analytics products. There is therefore no configuration in which their tags may sit on a page carrying regulated data. This is not a judgment call we make per client, it is a fixed rule.
- No tag on an authenticated page. No pixel, tag, heatmap or session recorder behind a login, on a portal, or on a confirmation screen that names a service received.
- No condition-specific audience building. No remarketing list built from who visited a page about a diagnosis, a treatment or a symptom.
- No form field piped into a conversion event. Conversion events carry that a conversion happened, not what the person typed.
Regulator guidance in this area has been litigated and partly set aside, and the position may move again. State wiretapping and session-recording claims were unaffected by any of it and are where most of the actual filings are. We build to the conservative reading and we would rather lose an attribution signal than put you in that pile.
What neither of us controls. Advertising platforms suspend accounts, disapprove ads and change policies without warning or explanation. We will work an appeal with you. We cannot guarantee an outcome and neither can anyone else who tells you they can.
If you are in a regulated industry
None of this means we will not work with you. Clinics, practices, clinicians, advisers and firms are good clients. It means the regulated half of your operation stays where it already lives, and we build the half that brings you the phone call.
What we build you
- The whole public marketing site. Service pages, locations, team pages, insurance and pricing information, FAQs, everything a prospective patient or client reads before they decide to call.
- A request-to-be-contacted form. Name, phone, email, preferred time, and how they found you. No condition, no reason for visit, no free-text box inviting either.
- Click to call, and call tracking without recording. You still get full attribution for which campaign produced the call.
- Local SEO and the map pack. Profile, categories, service areas, reviews, the work that decides whether you appear at all.
- Advertising on public pages. Campaigns, landing pages and conversion tracking that records a conversion happened, never what was typed.
- A clean handoff link to your booking or portal system. We send people there. We do not rebuild it and we do not put our tags on it.
What stays with your practice software
- Intake and clinical history. Your EHR or practice management vendor already signs a BAA and already carries the obligation. That is the right home for it.
- The patient portal. Records, results, messaging, billing. We link to it and stop at the door.
- Anything requiring a record of treatment. Including appointment systems that capture a reason for the appointment.
- Payment collection that takes a card number directly. Hosted checkout only, or your existing merchant tooling.
A dental practice, concretely. We build the site, the implant and orthodontics service pages, the new-patient page and the map-pack presence. The form says “request a call back” and collects a name, a phone number and a preferred time. The button next to it says “book online” and goes to your existing scheduling system, where the clinical questions are asked under an agreement that vendor has already signed. You get the lead flow and the attribution. Nobody has to argue afterwards about whose systems held what.
If what you need genuinely requires a vendor who will sign a business associate agreement, we will tell you that at the first call rather than the fifth, and we would rather point you at somebody who does it properly than take the work and improvise. That is not us being modest, it is the honest read on what this shop is built to carry.
Ask before you sign, not after
Tell us what data your business actually handles and we will tell you on the first call whether we are the right shop. It takes ten minutes and it costs nothing.
-
We are a fit
Your regulated systems are already somewhere else and you want the marketing side built properly. This is most of our work.
-
We are a fit with a change
One form field or one recorded line is the only thing in scope. Usually a five-minute conversation and we build the rest.
-
We are not a fit
You need a vendor who signs a BAA. We will say so straight away and point you at someone who does it properly.
Nothing on this page is legal advice, and we are not your lawyer. It describes what we do and what we decline, so you can take an informed question to someone who is.
- Processor only, never a controller of your customer data
- No regulated data, no BAA, no pretending
- DPA on request