Last Updated: September 22, 2026
1. About This Privacy Policy
This Privacy Policy is intended to describe how Susan B Silverman Consulting, LLC (hereafter “Our,” “We,” “Us,” or “Company”), collects, uses, shares, stores, and otherwise processes your Personal Information when you visit our Website, request information or a proposal, engage us for consulting or advisory services, participate in meetings, assessments, training or events, create or use a client account, submit project materials, make payments, communicate with us, or otherwise use our Services (collectively, the “Services”).
This Privacy Policy also explains your privacy rights, the choices available to you, and how you may contact us with questions or requests regarding your Personal Information.
This Privacy Policy should be read together with our applicable terms of service, engagement agreements, and any other terms, policies, or service-specific notices that apply to the Services. Where we process Client Data solely on a Client’s behalf as a Processor or Service Provider, the Client’s instructions and our applicable data processing agreement govern that processing. This Policy does not expand our rights to use Client Data beyond those instructions or agreements. Separate workforce or other supplemental notices apply where provided.
Definitions
For purposes of this Privacy Policy, the following terms have the meanings set forth below:
“Automated Features” means automated tools, including artificial intelligence (“AI”), used in connection with the Services. “Automated Decision-Making Technology” (“ADMT”) means technology that processes Personal Data to make or substantially replace human decisions, or otherwise falls within the definition applicable to the processing under governing law. “Profiling” means automated processing that evaluates or predicts personal aspects of an individual. These terms do not imply that every automated tool is subject to the same legal requirements.
"Consent" means a clear, freely given, specific, informed, and unambiguous affirmative act signifying agreement to the processing of Personal Data, obtained without the use of dark patterns, deception, or coercion. Consent may be provided by a written statement (including electronic means) or other clear affirmative action.
"Controller" means the person or entity that, alone or jointly with others, determines the purposes and means of processing Personal Data.
“Cross-Context Behavioral Advertising” and “Targeted Advertising” refer to advertising based on Personal Data obtained from your activities over time and across nonaffiliated websites, applications, or online services to predict your preferences or interests. The precise definitions and exclusions differ under applicable state law; each term has its applicable statutory meaning when determining your rights.
"Deidentified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, provided the Controller: (a) takes reasonable measures to ensure the data cannot be associated with a consumer; (b) publicly commits to process the data only in deidentified form; and (c) contractually obligates recipients to comply with these provisions.
"Personal Data" (also referred to as "Personal Information") means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to a particular consumer or household. Personal Data includes online identifiers, biometric information, geolocation data, inferences, and any other information defined as personal data or personal information under applicable state privacy laws.
“Processor” means a person or entity that processes Personal Data on behalf of a Controller pursuant to a written contract. “Service Provider” refers to the corresponding role under California law, subject to its specific contractual and processing restrictions.
“Sensitive Data” (also referred to as “Sensitive Personal Information”) means Personal Data subject to heightened protection under applicable law, including government identification numbers; account credentials or financial-account access information; precise geolocation; racial or ethnic origin; religious or philosophical beliefs; health information; sex life or sexual orientation; citizenship or immigration status; union membership; genetic, biometric, or neural data where covered; protected communications content; and Personal Data concerning children where designated sensitive. Applicable definitions and age or location thresholds vary by state. Listing a category here does not mean we collect it.
“Sale” or “Sell” means a disclosure of Personal Data for monetary or other valuable consideration to the extent defined as a sale under applicable law, subject to its exclusions. “Sharing” has its California statutory meaning when used in connection with Cross-Context Behavioral Advertising; ordinary references to sharing elsewhere in this Policy mean disclosure.
“Services” means all Websites, client portals, consulting and advisory engagements, assessments, research, strategic planning, workshops, training, events, reports, recommendations, digital resources, communications, and other services offered by the Company.
“User,” “you,” or “your” means any person who accesses the Website, communicates with us, represents a prospective or current Client, participates in an engagement, meeting, assessment, training or event, submits information, or otherwise uses the Services. A “Client” is a person or organization that requests, purchases, or receives our consulting or advisory services. “Client Data” means Personal Information supplied by or on behalf of a Client, or collected for a Client, that we process on the Client’s behalf in providing the Services.
“User Submissions” means any content, information, files, documents, presentations, business records, survey or assessment responses, photographs, recordings, comments, messages, project instructions, feedback, or other materials submitted, uploaded, entered, or provided by you in connection with the Services.
“Website” means https://susanbsilvermanconsulting.com/ and any related web pages, client portals, dashboards, or digital experiences operated by the Company.
2. Personal Information We Collect
We collect information you provide directly, information collected automatically when you use the Services, and information from third-party tools or service providers that help us operate the Services, and from publicly available sources.
A. Categories of Personal Information Collected. Depending on how you use the Services, we collect the following categories of Personal Information.
- Identifiers. Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, or other similar identifiers.
- Personal Information under Contact and Financial Information laws such as the California Customer Records Law. Name, signature, postal address, telephone number, financial information, and other customer-record information.
- Commercial Information. Records of consulting or advisory services requested, proposed, purchased, received, canceled, refunded, or considered; engagement and transaction history; contracts, statements of work, invoices, payment status, and other purchasing or service histories.
- Communications and Customer Service Information. Includes emails, messages, inquiry forms, support requests, meeting notes, and correspondence relating to proposals and engagements.
- Internet or Other Electronic Network Activity Information. Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.
- Geolocation Data. Approximate location inferred from an IP address, such as city or region.
- Audio, Electronic, Visual, Thermal, Olfactory, or Similar Information. Where used, photographs, webinar or meeting recordings, and associated transcripts. We provide notice and obtain consent to recording where required by law.
- Engagement, Client, User Content, and Uploaded Materials. Project briefs, business records, research and interview responses, surveys, assessments, reports, deliverables, meeting details, schedules, notes, messages, and other User Submissions provided in connection with the Services.
- Preferences and Personalization Information. Service interests, communication preferences, event or training selections, scheduling preferences, accessibility requests, and other similar information that may lead to inferences.
- Inferences Drawn From Personal Information. Inferences about service interests, communication preferences, or business needs based on your interactions with us.
- Interaction Data. This may include Website searches, selections, feedback, event participation, and interactions with any automated support, survey, or assessment tools used in connection with the Services.
- Information You Voluntarily Provide. Any additional personal information that you choose to submit through forms, uploads, account settings, surveys, emails, customer support interactions, or other communications with us.
- Sensitive Personal Information. Depending on how you use the Services, we may collect the following categories of sensitive personal information:
- Account log-in credentials, if a client portal is offered; financial-account access information where required for payments; and government-issued identification or tax information where required for a particular engagement or legal compliance.
- Precise geolocation is not ordinarily needed to provide consulting or advisory services. Any collection of that information must be specifically identified in Section 2 above.
- Health-related or disability information that you choose to provide for accessibility accommodation, and other Sensitive Data contained in Client Data where necessary for an agreed engagement and permitted by law. Please do not submit Sensitive Data that is not needed for the Services.
- Professional or Employment and Education Information. Organization, job title, role, business contact details, professional background, credentials, and education or training information you provide in connection with an engagement, event, assessment, or application.
We do not collect every type of Sensitive Personal Information from every User. The categories collected depend on your relationship with us, the nature of the engagement, and applicable legal requirements. We do not collect biometric information for the purpose of uniquely identifying an individual unless separately disclosed and permitted by applicable law.
3. Sources of Personal Information
We collect personal information from the following categories of sources:
Directly From You. Information you provide when you request a consultation or proposal, engage us, use a client portal, submit project materials, participate in interviews, surveys, assessments, meetings, training or events, make a payment, subscribe to marketing, or otherwise communicate with us in person, by telephone, text, email, or through the Services.
Automatically Through Your Use of Our Services. We collect certain Personal Data automatically when you interact with our Website, client portals, or other digital Services through:
- Cookies, web beacons, pixel tags, and similar tracking technologies;
- Server logs and analytics tools that record IP addresses, device identifiers, browser types, operating systems, referring URLs, and usage patterns, Pages viewed, Links clicked, Referring and exit pages, Date and time of visits;
- Information made available through your device when you choose to enable a camera or microphone for a meeting or other requested feature, subject to applicable permissions and recording notices.
From Third-Party Sources. We collect Personal Data from third parties, including:
- Analytics providers and, where used, data providers that provide demographic, interest-based, attribution, or online activity data;
- Social media platforms when you interact with our social media pages or use social login features;
- Marketing and event partners, referral sources, and advertising networks, where used;
- Identity-verification, fraud-prevention, and business-verification providers, where used for Client onboarding, payments, or legal compliance;
- Clients, their authorized representatives, business partners, and calendar or communications integrations;
- Third parties with your consent or at your direction, such as a payment provider, calendar provider, or an advisor participating in your engagement.
- Automated Technology Providers. If used in an engagement or Website feature, third-party technology providers may process information on our behalf, subject to applicable contractual restrictions and notices.
- We may receive and store limited payment-related information, such as billing name, billing email, billing address, transaction status, payment history, refund or dispute information, invoice information, the last four digits of a payment card, and payment method type. Payment processing is subject to the payment processor’s own terms and privacy policy.
Publicly Available Information. Public records and publicly available sources, such as business registries, professional directories, public business listings, social media profiles, and company websites.
We do not collect all categories of Personal Data from all consumers. The specific categories collected depend on the nature of your relationship with us and the products, services, or interactions involved.
We use this information to operate, protect, analyze, improve, and personalize the Services.
4. How We Use Your Personal Information
A. Legitimate Business and Operational Purposes. We may use collected information for the following purposes:
- Providing and Managing Products and Services. To evaluate inquiries, prepare proposals, onboard Clients, plan and perform engagements, conduct research and assessments, prepare analyses and recommendations, deliver reports and training, coordinate meetings, manage client accounts, process invoices and payments, provide support, and respond to inquiries.
- Communicating With You. To communicate about proposals, engagements, project progress, meetings, events, deliverables, payments, refunds, disputes, service or policy changes, and administrative matters; coordinate with authorized Client representatives; and respond to requests and questions.
- Marketing and Advertising. To send you marketing communications, promotional materials, newsletters, and advertisements about our Services, events, and offers, and to conduct market research and satisfaction surveys. You may opt out of marketing communications as described in Section 14.
- Personalization and Customization. To tailor consulting resources, service recommendations, training content, and communications to your stated interests and needs, and remember settings and preferences.
- Analytics and Research. To conduct analytics, research, and statistical analysis to understand how consumers use our services, identify trends, measure the effectiveness of our marketing campaigns, and improve our products, services, and business operations.
- Product Development and Feature Testing. To develop and improve consulting methodologies, service offerings, digital resources, training materials, and Website functionality, subject to our confidentiality and data processing obligations.
- Security and Fraud Prevention. To detect, prevent, investigate, and respond to security incidents, fraud, malicious or illegal activity, and violations of our terms of service or policies, and to protect the safety and security of our systems, consumers, employees, and the public.
- Debugging and Quality Assurance. To identify and repair errors, bugs, and technical issues that impair the functionality of our products and services, and to perform quality control and testing.
- Legal and Regulatory Compliance. To comply with applicable laws, regulations, legal processes, and governmental requests, including responding to subpoenas, court orders, law enforcement requests, and regulatory inquiries.
- Contractual Obligations. To perform our contractual obligations to you, including fulfilling the terms of agreements, processing payments, and delivering goods and services.
- Auditing and Verification. To conduct audits, verify the accuracy and quality of our services, perform accounting and financial reporting, and ensure compliance with internal policies and external standards.
- Business Transactions. To evaluate, negotiate, and complete mergers, acquisitions, asset sales, reorganizations, and other business transactions, and to transfer Personal Data as part of such transactions.
- Employment and Workforce Management. Where applicable, to recruit, engage, and manage employees or contractors and comply with employment-related legal obligations. Separate applicant or workforce notices govern processing described in those notices.
We may use aggregated or de-identified information for business, analytics, product development, research, reporting, and service improvement purposes. Aggregated or de-identified information does not reasonably identify you.
Automated Features and Profiling. If we use covered ADMT or Profiling for consequential decisions, we provide the notices and rights mechanisms required by applicable law. This general Policy does not replace any required pre-use or decision-specific notice. Client-directed processing remains subject to our agreement and the Client’s instructions.
5. Data Minimization
We process Personal Data only for specified, explicit, and legitimate purposes and do not further process Personal Data in a manner incompatible with those purposes. In accordance with data minimization principle, we collect and process only the Personal Data that is adequate, relevant, and reasonably necessary to accomplish the disclosed purposes.
Before using Personal Data for a new purpose that is materially different from the original purpose, we will:
- Update this Privacy Policy to disclose the new purpose;
- Provide you with notice of the new purpose at or before the time of collection or use; and
- Obtain your Consent where required by applicable law.
We limit our collection and processing of Personal Data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which it is processed. We do not collect excessive or irrelevant Personal Data. We periodically review the categories of Personal Information we collect to determine whether continued collection remains reasonably necessary and proportionate for the purposes described in this Privacy Policy and to ensure continued adherence to data minimization principles.
Accuracy of Personal Information. We take reasonable steps to maintain Personal Information in an accurate, complete, and current form appropriate for the purposes for which it is processed. Where appropriate, we provide mechanisms that allow you to review, update, or correct your Personal Information.
Privacy by Design and Default. We incorporate privacy and security considerations into the design, development, and operation of our products and Services. Where reasonably practicable, we configure our Services to collect and process only the Personal Information necessary for the requested functionality and to provide privacy-protective default settings.
Accountability and Governance. We maintain a privacy governance program designed to support compliance with applicable privacy laws. This program includes periodic reviews of our data practices, vendor oversight, employee training, data retention procedures, and ongoing monitoring of legal and regulatory developments affecting our privacy obligations.
6. Deidentified, Aggregated, and Anonymized Information
Deidentified. We may create, use, and disclose information that has been deidentified, aggregated, anonymized, or otherwise processed so that it cannot reasonably be used to identify, relate to, describe, or be linked to you or your household. Where required by applicable law, we maintain such information in deidentified form and take reasonable measures to prevent it from being reidentified.
Aggregated Information. We may use deidentified or aggregated information to better understand how our Services are used and to improve the overall user experience. For example, we may analyze information regarding:
- How Clients and other Users interact with our Services;
- General service, scheduling, training, and resource preferences and trends;
- Client portal usage patterns and user engagement;
- Website traffic;
- Performance metrics and error rates;
- Customer support trends;
- Aggregate engagement, invoicing, payment, event, and service activity; and
- Other statistical or analytical information that does not reasonably identify an individual.
We may also use aggregated or deidentified information to prepare internal reports, business analytics, research, forecasting, security monitoring, operational reporting, and other legitimate business purposes.
Product Improvement. We may use deidentified or aggregated information to develop, maintain, improve, and enhance our products and Services. This may include evaluating:
- Feature usage and adoption;
- Product performance and reliability;
- Performance and response quality;
- System functionality and stability;
- User experience improvements;
- Consulting resource, training, and service recommendation effectiveness;
- Security and fraud detection capabilities;
- Service quality and customer satisfaction; and
- New products, services, or features.
Where practicable, we use deidentified or aggregated information for these purposes rather than information that directly identifies an individual.
No Reidentification. We do not attempt to reidentify Deidentified Data except to test whether our deidentification methods satisfy applicable legal requirements, where permitted by law.
We maintain deidentified information in deidentified form and contractually require recipients to do the same where required by applicable law.
7. How We Share Your Personal Information
For the business purposes described in Section 4, we disclose the categories below to the corresponding recipients, subject to the limitations in Sections 8 and 9.
Identifiers — disclosed to Website and client portal hosting providers, database and authentication providers, payment and communications providers, and authorized Client representatives as needed to provide the Services;
California Customer Records Information — disclosed to hosting and records-management providers, payment processors, authorized Client representatives, and Professional Advisors;
Protected Classification Characteristics — where collected for an authorized purpose, disclosed only as necessary to Service Providers, the relevant Client, Professional Advisors, and Government Authorities as permitted or required by law;
Commercial Information — disclosed to Service Providers, payment processors, authorized Client representatives, and Professional Advisors for engagement administration, billing, and related purposes;
Biometric Information — We do not collect or disclose biometric information for identification purposes;
Internet or Network Activity — disclosed to Website, security, and analytics providers and, if used as described in Section 8, advertising partners;
Geolocation Data — approximate location disclosed to Website, security, and analytics providers; any precise location disclosures are described in Section 2;
Sensory Data — disclosed to meeting, transcription, storage, and communications providers, and authorized engagement participants, where a recording or other sensory record is created and sharing is authorized;
Professional or Employment Information — disclosed to Service Providers, authorized Client representatives and engagement participants, Professional Advisors, and Government Authorities as necessary for the disclosed purpose;
Education Information — where collected, disclosed to Service Providers and authorized Client representatives as necessary for the engagement, assessment, or training;
Inferences — disclosed to Service Providers and the relevant Client as necessary for the engagement, and to analytics or marketing providers only as described in this Policy;
Sensitive Personal Information — disclosed only as necessary and legally permitted to Service Providers, payment or verification providers, the relevant Client, Professional Advisors, and Government Authorities.
8. Third-Party Service Providers
We do not sell Personal Information for monetary compensation.
We may share information only as needed for the purposes described in this Privacy Policy, including with the following categories of recipients:
Service Providers. Entities that perform services on our behalf, including Website and client portal hosting, data storage, authentication, payment processing, scheduling, videoconferencing, email and communications, document management, electronic signatures, customer relationship management, customer support, marketing administration, analytics, security, and other business operations.
These Service Providers are authorized to process Personal Information only for the contracted purposes, subject to applicable agreements and legal requirements, including restrictions on sale, sharing, independent use, and combining data where required by law.
Payment Processors. Payment, refund, dispute, and related financial information may be processed by third-party payment processors as described in Section 3.
Content and Infrastructure Providers. We may use professional versions of generally available generative AI tools, such as ChatGPT, Claude, and Grammarly, to support document collaboration, meetings, research, analysis, reporting, and other engagement activities. In connection with these activities, we may disclose relevant User Submissions to technology providers acting on our behalf, subject to applicable confidentiality, security, and data-processing restrictions.
Affiliates and Subsidiaries. NOT APPLICABLE
Advertising and Marketing Partners. If used as disclosed above, advertising networks, social media platforms, marketing agencies, and analytics firms that assist in delivering advertisements and measuring campaign effectiveness, subject to applicable consent and opt-out rights.
Business Transaction Counterparties. Potential or actual buyers, investors, lenders, advisors, and other parties involved in mergers, acquisitions, financings, asset sales, or other business transactions.
Professional Advisors. Attorneys, accountants, auditors, consultants, and other professional advisors who provide legal, tax, accounting, audit, compliance, risk-management purposes, and consulting services.
Government Authorities and Legal Entities. Law enforcement agencies, regulatory authorities, courts, arbitrators, and other governmental or quasi-governmental entities in response to lawful requests, subpoenas, court orders, or legal obligations. We may disclose information if we believe it is necessary or appropriate to:
- Comply with applicable law, regulation, legal process, subpoena, or government request;
- Enforce our Terms of Service or other agreements;
- Protect our rights, property, privacy, safety, or security;
- Protect Users, service providers, or the public;
- Detect, prevent, or address fraud, security, technical, or abuse issues; or
- Defend against legal claims or pursue available remedies.
Third Parties With Your Consent. Other third parties to whom you authorize or direct us to disclose your Personal Data.
Third-Party Services and Websites. The Services may contain links to or integrations with social media platforms, calendar or meeting services, payment processors, identity providers, or other third-party services. This Privacy Policy applies to the Company’s processing. Third parties acting independently have their own privacy policies and terms, which you should review before submitting information to them.
Client and Engagement Sharing. We share information with a Client’s authorized representatives and other authorized engagement participants as needed to perform the engagement. This may include business contact information, scheduling details, project communications, and agreed reports or deliverables. Where a Client sponsors your participation in an assessment, interview, workshop, or other activity, the applicable notice or engagement terms describe the information or results made available to that Client. We do not represent that responses are anonymous unless expressly stated.
Independent Client Records. A Client may maintain its own copy of engagement records, reports, and communications and process that information for its own purposes. When the Client independently determines the purposes and means of processing, it is responsible for its own privacy practices. For Client Data we process solely on the Client’s behalf, we act under the Client’s instructions and applicable contractual restrictions.
Client Responsibility and Requests. This Privacy Policy does not govern a Client’s independent processing. Requests concerning Client Data controlled by a Client should be directed to that Client. If we receive such a request, we will direct it to the relevant Client or assist the Client as required by our agreement and applicable law. We remain responsible for requests relating to information we control for our own purposes.
Third Party Integrations. If supported, you may choose to access a client portal or other Services using a third-party authentication or single sign-on (“SSO”) provider. We may receive your name, email address, profile identifier, or other information you authorize that provider to disclose, subject to your settings and permissions.
9. Sensitive Personal Information
A. Definition and Categories. Sensitive Data includes the categories set forth in the Definitions above. We recognize that Sensitive Data requires heightened protections due to the increased risk of harm to consumers if such data is compromised or misused.
B. Consent. We will not collect or process Sensitive Personal Data unless the processing is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumer, or otherwise permitted by applicable law.
For Maryland Personal Data subject to its additional restrictions, we limit Sensitive Data processing to what is strictly necessary to provide or maintain the specific product or service requested by the consumer, subject to applicable statutory exceptions. We do not sell such Sensitive Data.
Where required, we obtain affirmative, freely given, specific, informed, and unambiguous opt-in Consent before processing Sensitive Data. An exception applies only where the law governing the particular processing permits it. The California permitted-use categories do not create a general exception to another state’s Consent requirement.
C. Consent Characteristics. When we request your Consent to process Sensitive Data, we ensure that:
- The Consent request is presented separately from other terms of service, agreements, or disclosures and is not bundled with acceptance of general terms;
- The request clearly identifies the specific categories of Sensitive Data to be processed and the specific purposes for which it will be used;
- The request uses plain, understandable language appropriate for the target audience;
- The Consent mechanism is as easy to withdraw as it is to provide;
- The request does not use dark patterns, manipulative design, or coercion;
You are informed of your right to withdraw Consent at any time without penalty.
D. No Sale or Sharing Without Consent. We do not sell Sensitive Data or use or disclose it for Targeted Advertising. Other disclosures of Sensitive Data are limited to the purposes described in this Policy, subject to any required Consent and applicable legal restrictions. Consent does not authorize processing that applicable law prohibits.
E. Sensitive Data Security. We implement reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information.
F. Retention and Deletion. We retain Sensitive Data only for as long as necessary to fulfill the permitted purposes for which it was collected or as required by law. Upon expiration of the retention period or a valid deletion request, subject to applicable exceptions, we securely delete or deidentify Sensitive Data in accordance with Section 12.
10. Cookies, Analytics, and Online Tracking Technologies and Similar Technologies
Cookies are small text files placed on your device that help websites work properly, remember preferences, analyze traffic, support payments, protect against fraud, and improve user experience. We and our service providers use cookies, pixels, web beacons, tags, local storage, and similar technologies (collectively, “Cookies and Similar Technologies”) to operate, secure, improve, personalize, analyze, and support the Website and digital Services.
Types of Cookies We May Use
Strictly Necessary Cookies
These cookies are required for the Services to function. They support core features such as security, account login, page navigation, checkout, and form submissions.
Analytics Cookies
Where enabled, analytics tools help us understand pages visited, time spent, traffic sources, device information, and Website performance. We currently use Google Analytics, provided by Google LLC.
Payment and Fraud Prevention Cookies
If you make a payment online, our payment processors may use cookies or similar technologies to process transactions, prevent fraud, and secure payment processing.
Social Media and Embedded Content Cookies
If the Services include embedded social content, such as Instagram or Meta content, those third parties may use cookies or similar technologies to display content, measure interactions, or collect information if you are logged into their platforms.
Preference Cookies
These cookies may help remember account settings, language, scheduling preferences, or other user choices.
Advertising Cookies.
These cookies may be used to deliver advertisements that are more relevant to your interests, measure advertising effectiveness, prevent repetitive advertisements, and support our marketing activities where permitted by applicable law.
Your Cookie Choices
Where required by applicable law, we recognize browser-based universal opt-out preference signals, such as Global Privacy Control (GPC), with respect to applicable processing activities.
You can control cookies through your browser settings, including deleting cookies or blocking certain types of cookies. You may also manage available preferences through Cookie Preferences. We obtain Consent for nonessential tracking where applicable law requires it.
Blocking certain cookies may affect how the Services function, and blocking payment, security, or account-related cookies may prevent checkout or account features from working properly.
11. Children’s Privacy
We are committed to protecting the privacy of children.
A. Children under the age of 13
The Services are intended for adults and business representatives and are not directed to children under the age of 13. We do not knowingly collect Personal Information directly from children under 13 through the Website or ordinary client intake.
If we learn that we have collected personal information from a child under 13, we will take reasonable steps to delete that information.
Obtain Verifiable Parental Consent. If an expressly agreed engagement involves children’s Personal Information, we and the relevant Client will establish the applicable roles, notices, safeguards, and legally required parental consent before that processing begins. We do not rely on this general Policy alone as a COPPA notice or consent mechanism.
Honor Parental Rights. Where COPPA or other applicable law applies, parents may:
- Review the personal information collected from their child
- Request deletion of their child's personal information
- Refuse to permit further collection or use of their child's personal information
Limit Collection. Any authorized processing of children’s data is limited to information reasonably necessary for the disclosed purpose and subject to applicable law.
If you believe a child under the age of 13 has provided us with Personal Information without verifiable parental consent, please contact us at privacy@susanbsilvermanconsulting.com so we can delete the information.
B. Known Minors Under 16
We do not knowingly sell or share Personal Information of consumers under 16 or use that information for Targeted Advertising.
We apply any additional protections required by applicable law for consumers under 18.
C. General Protections for Minors Under 16
For all consumers we have actual knowledge are under 16 years of age:
- Heightened Sensitive Data Protections. We apply the consent, minimization, and other Sensitive Data protections required by applicable law.
- No Profiling for Significant Decisions. We do not use Personal Information of known minors under 16 for profiling in furtherance of decisions producing legal or similarly significant effects.
- We do not knowingly use Personal Information collected from children to develop, improve, fine-tune, or evaluate generative artificial intelligence systems unless expressly permitted by applicable law and any required consent has been obtained.
- No Targeted Advertising. We do not direct Targeted Advertising to known minors under 16.
Age-Gating Mechanisms. Where legally required for a particular service, we use proportionate age-assurance measures that do not encourage false age responses or collect more information than necessary.
12. Data Retention
A. Retention Principles. We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected including to provide the Services, maintain your account, complete transactions, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, support business operations, and improve the Services.
Account information may be retained while your account is active and for a reasonable period afterward as needed for legal, billing, security, support, backup, tax, accounting, fraud prevention, dispute resolution, or operational purposes.
Engagement records, User Submissions, project materials, reports, meeting notes, assessment responses, calendars, communications, transaction records, and related content are retained only as needed for the engagement, applicable contractual instructions, support, legal compliance, billing, security, and dispute resolution.
Purpose Limitation. We do not retain Personal Data longer than necessary for the disclosed purposes.
Legal and Regulatory Compliance. We retain Personal Data as required by applicable laws, regulations, legal holds, and governmental requests.
Operational Necessity. We retain Personal Data to maintain accurate business records, support ongoing customer relationships, and enable legitimate business functions.
Security and Risk Management. We retain Personal Data necessary to detect and prevent fraud, security incidents, and abuse, and to establish, exercise, or defend legal claims.
We may retain aggregated or de-identified information for analytics, reporting, product improvement, and business purposes.
B. Retention Periods by Category. Identifiers, business contact details, and account information are retained for the active relationship and any necessary follow-up or recordkeeping period. Commercial, billing, and payment records are retained for the applicable tax, accounting, and claims periods. Engagement materials, professional or education information, and related inferences are retained for delivery and support of the engagement and any legally required period; Client Data is subject to the Client’s instructions and our agreement. Recordings and transcripts are retained only as needed for the disclosed meeting or engagement purpose. Website activity and approximate location data are retained for the period needed for security, performance, and analytics. Sensitive Data is retained only for the permitted purpose and any legally required period. Marketing contact data is retained until you opt out or it is no longer needed; a minimal suppression record may be retained to honor your choice.
C. Criteria for Determining Retention Periods. We determine retention periods based on:
- The length of our ongoing relationship with you;
- The nature of the Personal Data and sensitivity level;
- Applicable legal, regulatory, tax, accounting, or reporting requirements;
- Applicable statutes of limitations for legal claims;
- Industry standards and best practices;
- The purposes for which the Personal Data was collected;
- Whether retention is necessary to establish, exercise, or defend legal claims;
- Whether you have requested deletion (subject to applicable exceptions).
D. Deletion and Deidentification. Upon expiration of the applicable retention period, or upon receipt of a verified deletion request (subject to applicable exceptions below), we:
- Securely delete Personal Data using industry-standard data destruction methods (e.g., overwriting, degaussing, physical destruction of media); or
- Deidentify Personal Data in accordance with Section 6 so that it can no longer reasonably be used to identify you.
- We direct our Service Providers and Processors to delete or deidentify Personal Data in accordance with the same standards.
E. Legal Holds and Exceptions. Notwithstanding the retention periods, we may retain Personal Data for longer periods where:
- Required by law, regulation, or legal process;
- Necessary to comply with a legal hold, litigation, investigation, audit, or governmental request;
- Necessary to establish, exercise, or defend legal claims;
- You have provided Consent to longer retention;
- Retention is necessary to protect the vital interests of you or another person.
We periodically review our retention practices to ensure Personal Information is not retained longer than reasonably necessary for the purposes described in this Privacy Policy.
13. Data Security
We use reasonable technical, administrative, and organizational measures designed to protect personal information from unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Our information security program includes administrative, technical, and physical safeguards designed to protect Personal Information appropriate to its sensitivity and the nature of our business.
These measures may include secure servers, access controls, encryption where appropriate, third-party security practices, password protection, and other safeguards.
However, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security of information transmitted to or stored through the Services.
You are responsible for keeping your account credentials confidential and for using secure devices, networks, and passwords.
Incident Response. We maintain procedures designed to identify, investigate, respond to, and mitigate suspected security incidents and will provide notifications where required by applicable law.
14. Your Privacy Choices and Rights
Depending on where you live and applicable law, you may have certain rights regarding your personal information. These include the following:
Right to Know and Access. You have the right to request that we disclose to you:
- The categories of Personal Data we have collected about you;
- The categories of sources from which the Personal Data was collected;
- The business or commercial purpose for collecting, selling, or sharing Personal Data;
- The categories of third parties to whom we disclose Personal Data;
- The specific pieces of Personal Data we have collected about you;
- Meaningful information about covered Profiling or Automated Decision-Making Technology, where applicable law provides that right;
We provide access at the frequency and within the timeframes required by applicable law. See Section 15 for response timing. Any fee or limitation for repeated requests will apply only as permitted by law.
Right to Correct. You may request correction of inaccurate personal information that we maintain about you. Upon receipt of a verifiable correction request, we will use commercially reasonable efforts to correct the inaccurate Personal Data as directed by you, taking into account the nature of the Personal Data and the purposes of processing.
Right to Delete. You may request deletion of Personal Data we maintain about you, to the extent provided by applicable law and subject to its exceptions. Upon a verified request, as applicable, we will:
- Delete your Personal Data from our records;
- Direct our Service Providers and Processors to delete your Personal Data from their records;
- Direct third parties to whom we have sold or shared your Personal Data to delete your Personal Data (California only).
We may deny or limit deletion only where an exception under the law applicable to your request permits retention. Depending on that law, exceptions may include where retaining information is reasonably necessary to:
- Complete the transaction for which the Personal Data was collected, provide a good or service requested by you, or fulfill the terms of a written warranty or product recall;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activity;
- Debug to identify and repair errors that impair existing intended functionality;
- Exercise free speech rights or ensure the right of another consumer to exercise free speech rights;
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.);
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all applicable ethics and privacy laws;
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us;
- Comply with a legal obligation; or
- Carry out another purpose expressly permitted as an exception under applicable law. General operational convenience does not by itself create an exception.
Right to Data Portability. You have the right to request that we provide your Personal Data to you in a portable, structured, commonly used, and machine-readable format that allows you to transmit the data to another entity without hindrance. Where technically feasible, we will provide the data in JSON, CSV, or another readily usable electronic format.
Right to Opt Out. Where applicable, you may opt out of sale, sharing for Cross-Context Behavioral Advertising, Targeted Advertising, and Profiling in furtherance of decisions producing legal or similarly significant effects. We honor applicable requests and any restrictions on seeking a subsequent opt-in. You may exercise these rights by:
- Using your cookie and privacy choices, including the “Do Not Sell or Share My Personal Information” control where applicable;
- Enabling a universal opt-out preference signal recognized by our systems (e.g., Global Privacy Control);
- Contacting us at .
Right to Limit Sensitive Data. Where California law provides this right, you may limit use and disclosure of your Sensitive Personal Information to:
- Uses necessary to perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services;
- Certain enumerated business purposes permitted under California law, including:
- Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted Personal Data;
- Resisting malicious, deceptive, fraudulent, or illegal actions directed at us and prosecuting those responsible;
- Ensuring the physical safety of natural persons;
- Short-term, transient use (including non-personalized advertising);
- Performing services on our behalf;
- Verifying or maintaining the quality or safety of our products or services.
You may exercise an applicable limitation right through your cookie and privacy choices or privacy@susanbsilvermanconsulting.com. Other states may require opt-in Consent rather than a right to limit; see Section 9.
Right to Withdraw Consent. You may withdraw Consent where processing is based on Consent by contacting or using the mechanism through which you provided Consent. We stop the relevant processing within the period required by applicable law.
Right to Appeal. If we deny your privacy rights request, in whole or in part, we will notify you of the reason for our decision and, where required by applicable law, inform you of your right to appeal.
To submit an appeal, contact with “Privacy Appeal” in the subject line and describe the request and your reason for appealing. We review and respond within the period required by applicable law. See Section 15.
If your appeal is denied, and applicable law provides for additional recourse, we will inform you of any available complaint process, including, where required, how to contact the appropriate state Attorney General, consumer protection agency, or other applicable regulatory authority.
Right Against Discrimination. We will not discriminate against you for exercising any of your privacy rights under this Policy or applicable law. We will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including through the use of discounts or other benefits or by imposing penalties;
- Provide you a different level or quality of goods or services; or
- Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
If we offer a financial incentive program in the future, we may offer you financial incentives or price or service differences if the difference is reasonably related to the value of your Personal Data and you provide opt-in consent. You may withdraw from any financial incentive program at any time.
Marketing Choices. You may unsubscribe from promotional emails using the link in the message or contact . If we send promotional text messages, you may use the stated opt-out instructions. Opting out of marketing does not prevent necessary engagement, billing, security, or other nonpromotional communications.
Residents of some States may have additional rights under their state privacy laws, depending on whether those laws apply to the Company at the time of the request. These rights may include the right to request information about categories of Personal Information collected, disclosed, or shared; the right to request access, correction, or deletion; and the right to opt out of certain disclosures or uses where applicable. Please see the last section titled “State-Specific Privacy Rights and Additional Disclosures.”
15. How to Exercise Your Rights
A. Submitting Requests. You may exercise your rights by writing to us at:
Email: privacy@susanbsilvermanconsulting.com
Postal Mail:
Susan B Silverman Consulting, LLC
Attn: Privacy Officer
150 N. Michigan Ave., Suite 1230
Chicago, Illinois 60601
Online Request Form: https://susanbsilvermanconsulting.com/contact/
B. Verification of Identity. For access, correction, or deletion requests requiring verification, we use a risk-based approach appropriate to the nature of the request and sensitivity of the information. We do not require identity verification for sale or sharing opt-outs or limitation requests where prohibited by law. We request only the information reasonably necessary to process your request.
- For requests for categories of Personal Data, we may match information you provide with information we already maintain, such as your name and business email address, as permitted by law.
- For requests for specific pieces of Personal Data or deletion, additional verification may be necessary depending on the sensitivity of the information and risk of harm. We use applicable verification standards and do not impose the same verification requirements on every request.
- For account holders: We verify your identity through your existing account credentials and authentication mechanisms.
If we cannot verify your identity after good-faith efforts, we will notify you and explain how you may remedy the verification failure. To protect your privacy and security, we may request additional information reasonably necessary to verify your identity or authority to submit the request.
C. Authorized Agent Requests. You may designate an authorized agent to submit requests on your behalf. We require the authorized agent to:
- Provide proof of written authorization signed by you; or
- Provide a valid power of attorney under applicable state law.
We may ask you to verify your identity or confirm the agent’s authority only where permitted by law. A valid power of attorney is handled under applicable law. Opt-out requests submitted by an authorized agent are not subject to access-request verification requirements.
D. Response Timing. We generally respond to access, correction, deletion, and portability requests within forty-five (45) days and may extend that period by an additional forty-five (45) days where permitted and reasonably necessary, with notice and an explanation. A different statutory deadline controls where applicable. For California requests to know, delete, or correct, we acknowledge receipt within ten (10) business days. We process opt-outs, limitation requests, and Consent withdrawals within their applicable deadlines; California sale/sharing opt-outs and limitation requests are processed as soon as feasibly possible and no later than fifteen (15) business days. Requests are free except where applicable law permits a fee, which we explain before charging.
E. Appeal. Where applicable, you may appeal a denial using the same contact methods in this Section. Identify the original request and explain why you believe the decision should be reconsidered. We respond within the applicable statutory period, including forty-five (45) days where required or sixty (60) days where allowed, with any legally permitted extension explained to you. If an appeal is denied, we provide the available complaint mechanism for the relevant Attorney General or regulator. No general forty-five-day deadline for submitting an appeal limits a longer period available under applicable law.
F. Exceptions. We may deny or limit requests only to the extent permitted by applicable law, including applicable legal, security, fraud-prevention, or claims-related exceptions. Where we retain information under an exception, we limit its use to that permitted purpose. Backups are handled in accordance with applicable deletion requirements.
16. Recognition of Universal Opt-Out Preference Signals
UNIVERSAL OPT-OUT MECHANISM
A. Recognition of Opt-Out Preference Signals. Where required by applicable law, we recognize qualifying universal opt-out preference signals, including Global Privacy Control (“GPC”), as requests to opt out of:
- The sale of Personal Data;
- The sharing of Personal Data for cross-context behavioral advertising;
- Processing of Personal Data for Targeted Advertising purposes.
- Profiling opt-outs may be submitted through Section 15. A browser signal does not necessarily communicate a choice about all Profiling or other processing.
B. Recognized Opt-Out Signals. Qualifying signals include:
- Global Privacy Control (GPC) signals transmitted by browsers, browser extensions, or privacy-focused applications;
- Other universal opt-out mechanisms that meet the requirements of applicable law.
- A signal applies to the browser or device sending it and, where we can associate it with an identified account and applicable law requires, to that account. Enable it on each browser or device you use as appropriate.
You may still control certain tracking technologies through your browser settings, cookie settings, or third-party platform controls.
Do Not Track. Because there is not currently an industry-wide consensus regarding "Do Not Track" browser signals, our Services do not respond to such signals except to the extent required by applicable law. Where required, we recognize browser-based universal opt-out preference signals, such as Global Privacy Control.
17. Important Notice to Users Outside the U.S.
the Company and the Services are operated from the United States. If you are located outside the United States or access our Services from outside the United States, please be aware that your Personal Information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. By using the Services, you acknowledge that your Personal Information may be transferred to countries that may have different data protection laws than your country of residence.
Where required by applicable law, we implement appropriate safeguards for international transfers.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by updating the "Last Updated" date at the top of this Privacy Policy.
The “Last Updated” date at the top of this Privacy Policy indicates when it was last revised. Where required, we provide additional notice of material changes through:
- Posting a conspicuous notice on our Website homepage;
- Sending an email to the email address associated with your account (if applicable);
- Providing notices through a client portal, if applicable;
- Other means reasonably calculated to inform you of the changes.
Where required by law, we obtain your Consent to changed practices before applying them to Personal Data collected before the change.
19. Contact Us
For questions, privacy requests, complaints, or concerns about this Privacy Policy or how we handle Personal Information, contact our Privacy Office at: Email: privacy@susanbsilvermanconsulting.com
Mailing address:
Susan B Silverman Consulting, LLC
Attn: Privacy Officer
150 N. Michigan Ave., Suite 1230
Chicago, Illinois 60601
You have the right to lodge a complaint with the relevant data protection or privacy regulatory authority if you believe we have violated your privacy rights or applicable law. Regulatory authorities include:
- California: California Privacy Protection Agency,
- Colorado: Colorado Attorney General's Office,
- Maryland: Maryland Attorney General's Office,
- Texas: Texas Attorney General's Office,
- Oregon: Oregon Department of Justice,
If you need this Policy or assistance submitting a request in an accessible format, please contact privacy@susanbsilvermanconsulting.com.
20. State-Specific Privacy Rights and Additional Disclosures
Residents of certain states may have additional privacy rights or disclosures under applicable state privacy laws. This section supplements the remainder of this Privacy Policy and applies only where the identified state law applies to our processing activities and to you.
Unless otherwise stated below, the rights described in the Section titled Your Privacy Choices and Rights apply to residents of all states that provide comprehensive consumer privacy rights. If a conflict exists between this section and another provision of this Privacy Policy, this section will control to the extent required by applicable law.
California- California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CPRA"), including:
- The right to know the categories and specific pieces of Personal Information we collect, use, disclose, sell, or share.
- The right to request correction of inaccurate Personal Information.
- The right to request deletion of Personal Information, subject to applicable exceptions.
- The right to opt out of the sale or sharing of Personal Information.
- The right to limit the use and disclosure of Sensitive Personal Information, where applicable.
- The right not to receive discriminatory treatment for exercising your privacy rights.
California Collection and Disclosure Details. Sections 2 and 3 identify the categories and sources of Personal Information; Section 4 explains purposes; Sections 7 and 8 identify disclosures and recipients; and Section 12 describes retention criteria.
Sensitive Personal Information.
We do not knowingly sell or share Personal Information of consumers under 16.
California's "Shine the Light" law (California Civil Code § 1798.83) permits California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To submit such a request, please contact us using the information provided in the Contact Us Section.
Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia
Residents of these states may have rights described in Section 14, subject to each law’s scope, thresholds, exemptions, and effective dates. These rights generally concern individuals acting in an individual or household capacity; most of these laws exclude commercial and employment contexts. California’s coverage differs. A Client’s location alone does not determine whether a right applies.
Where applicable, you may also have the right to:
- Appeal our decision if we deny your privacy rights request.
- Opt out of targeted advertising.
- Opt out of certain profiling in furtherance of decisions that produce legal or similarly significant effects.
- Opt out of the sale of Personal Information where applicable.
- Withdraw consent for processing Sensitive Personal Information where processing is based on consent.
- Receive notices or explanations concerning covered Automated Decision-Making Technology or Profiling, where required;
- Obtain information about specific third-party recipients, where required; and
- Question or seek review of covered Profiling decisions, where the applicable law provides that right.
If we deny your appeal, we will provide information regarding any additional complaint mechanism or regulatory authority available under applicable law.
Certain states provide additional protections regarding sensitive data, profiling, children’s data, biometric information, or universal opt-out mechanisms. Where applicable, the Company honors those rights in accordance with applicable law.
Iowa and Utah. Where the applicable law covers our processing, residents may request access, deletion, and a portable copy of covered Personal Data and opt out of sales. Utah also provides a Targeted Advertising opt-out and an opportunity to opt out of covered Sensitive Data processing after notice. Iowa requires notice and an opportunity to opt out of covered Sensitive Data processing. The scope of deletion and portability differs by state. Neither state generally provides correction or Profiling opt-out rights. Utah does not provide a statutory appeal right. Iowa residents may appeal under Section 15; we respond to appeals within sixty (60) days. Iowa requests have a ninety (90)-day response period, extendable by forty-five (45) days where permitted.
Minnesota. Where applicable, you may obtain a list of specific third parties to which we disclosed Personal Data and question a covered Profiling decision, receive an explanation, review the information used, and seek correction and reevaluation where inaccurate information caused the decision. Where feasible, you may request information about actions that could produce a different outcome.
Maryland. The additional Sensitive Data and minimization restrictions described in Sections 5 and 9 apply where Maryland law governs. Consent does not override a statutory prohibition on processing or sale.
Vermont. The comprehensive consumer privacy provisions enacted in Act 145 take effect January 1, 2028. The applicable rights and obligations will apply from the relevant effective date if the Company and processing are covered; this Policy does not describe those future statutory rights as already effective.
Washington and Other Consumer Health Privacy Laws. Where we collect consumer health data subject to a separate state consumer health privacy law, we provide the required supplemental notice and any distinct collection, sharing, or sale consent or authorization before the relevant processing. The general Sensitive Data provisions of this Policy do not substitute for those requirements.
Nevada. Nevada law permits certain Nevada residents to opt out of the future sale of certain covered information that a website operator has collected or will collect. Although we do not currently sell Personal Information for monetary consideration as defined under Nevada law, Nevada residents may submit an opt-out request by contacting us at .
