Privacy Policy
This Privacy Policy explains how DM with QAF LLC ("QAF," "we," "us," or "our") collects, uses, discloses, and safeguards information when you visit our website, use our AI-powered marketing platform, or engage us as a client.
1Scope & who we are
DM with QAF LLC is a digital marketing agency headquartered at 7901 4TH ST N STE 22876, St Petersburg, FL 33702-4305, USA. This Policy applies to personal information we process through:
- Our marketing website (dmwithqaf.com) and any subdomains, including our chatbot widget;
- Client-facing dashboards, reporting tools, and analytics platforms we operate;
- Marketing campaigns, forms, and communications you engage with; and
- Data our clients ask us to process on their behalf as part of our services (in which case we act as a "processor" or "service provider," and our client's own privacy notice also applies).
If you are an individual interacting with a campaign run by one of our clients, please also review that client's privacy notice — they control that data as the "controller" or "business," and we process it under contract on their instructions.
2Information we collect
2.1 Information you provide directly
- Contact details (name, email, phone, company, job title) submitted through forms, the chatbot, or email;
- Account credentials for client dashboards;
- Billing and payment details, processed through PCI DSS–compliant payment processors;
- Content of messages, support tickets, and chatbot conversations;
- Any data your organization uploads to our platform for campaign execution or analysis.
2.2 Information collected automatically
- Device and browser information (IP address, browser type, operating system);
- Usage data (pages visited, links clicked, session duration, referring URLs);
- Cookies and similar technologies, described in our Cookie Policy;
- Approximate location derived from IP address.
2.3 Information from third parties
- Advertising and analytics platforms (e.g., ad networks, search engines, social platforms) connected to campaigns we run;
- Data enrichment and B2B intelligence providers used to qualify leads;
- Publicly available sources, where lawful.
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email, phone, IP address | You; automatically |
| Commercial information | Services purchased, billing history | You; our systems |
| Internet activity | Browsing behavior, click data | Automatically; cookies |
| Professional information | Job title, company, industry | You; third parties |
| Inferences | Predicted interests, engagement scores | Our AI models |
3How we use information
We use personal information to:
- Provide, operate, and improve our website, platform, and marketing services;
- Respond to inquiries and provide customer support, including through our AI chatbot;
- Deliver, personalize, and measure marketing campaigns on behalf of our clients;
- Train, fine-tune, and evaluate the predictive and generative models that power our analytics and automation features, in accordance with Section 5 below;
- Process payments and manage billing;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our agreements; and
- Send administrative communications and, where you have opted in, marketing communications.
4Legal bases for processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing services under contract with a client | Performance of a contract |
| Responding to inquiries, operating the chatbot | Legitimate interests |
| Analytics, product improvement, model evaluation | Legitimate interests |
| Marketing emails to prospects | Consent, or legitimate interests where permitted by local law |
| Fraud prevention and security | Legitimate interests; legal obligation |
| Special category or sensitive data (rare, e.g., health-related campaigns) | Explicit consent, or another Article 9 condition |
Where we rely on legitimate interests, we have assessed that our processing does not override your fundamental rights and freedoms. You can object to processing based on legitimate interests as described in Section 12.
5AI & automated decision-making
As an AI-first marketing agency, we use machine learning and generative AI (including third-party foundation models such as those provided by OpenAI, Anthropic, and Google, and open models via Hugging Face) to power features including predictive analytics, lead scoring, content generation, and our chatbot.
- No solely-automated decisions with legal or similarly significant effects. We do not use these systems to make decisions that produce legal or similarly significant effects about individuals (e.g., credit, employment, or eligibility decisions) without meaningful human review.
- Model training. We do not use client campaign data or end-user personal information to train third-party foundation models for the benefit of other customers. Where we fine-tune internal models, we use de-identified or aggregated data wherever feasible.
- Human oversight. AI-generated content, scores, and recommendations are reviewed by our team before being used in client-facing decisions of consequence.
- Your controls. You may request more information about the logic involved in a specific automated feature, or request human review of an output, by contacting us using the details in Section 17.
6Cookies & tracking technologies
We use cookies, pixels, and similar technologies to operate our site, remember preferences, measure performance, and support advertising. Full details, including a category-by-category breakdown and instructions for managing your preferences, are available in our Cookie Policy.
7How we share information
We do not sell personal information for money. We may share information as follows:
- Service providers / subprocessors: cloud hosting, analytics, email delivery, payment processing, customer support tooling, and AI model providers, each bound by written data processing terms;
- Clients: where we run campaigns on a client's behalf, campaign performance and lead data is shared with that client;
- Advertising & analytics partners: for campaign delivery and measurement, subject to the choices described in our Cookie Policy;
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections;
- Legal & safety: where required to comply with law, respond to lawful requests, or protect the rights, property, or safety of QAF, our clients, or others.
Under U.S. state privacy laws, sharing personal information with advertising partners for cross-context behavioral advertising may be considered a "sale" or "share." See Section 13 for your opt-out rights.
8International data transfers
We are based in the United States and may process information in the U.S. and other countries where our service providers operate. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. Contact us for a copy of the relevant safeguards.
9Data retention
We retain personal information for as long as needed to provide our services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Typical retention periods:
| Data type | Typical retention |
|---|---|
| Client account & billing records | Duration of contract, plus 7 years for tax/accounting purposes |
| Marketing leads & form submissions | Up to 24 months from last engagement, or until you opt out |
| Website analytics & log data | Up to 14 months |
| Chatbot conversation logs | Up to 12 months |
| Security & audit logs | Up to 12 months, longer if required for an active investigation |
10Security & compliance
We maintain a written information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our program is built around widely recognized frameworks:
- SOC 2 Type II – aligned controls: our internal control environment for security, availability, and confidentiality is designed with reference to the AICPA's Trust Services Criteria. Ask your account manager for our current audit status and, where available, our SOC 2 report under NDA.
- ISO/IEC 27001 – aligned ISMS: our information security management practices — risk assessment, access control, encryption, incident response, and vendor management — are designed with reference to ISO/IEC 27001 Annex A controls.
- Encryption: data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption (e.g., AES-256) where supported by our infrastructure providers.
- Access control: role-based access, multi-factor authentication for administrative systems, and least-privilege principles for staff and contractors.
- Vendor management: subprocessors are assessed for security posture and bound by data processing agreements before onboarding.
- Incident response: a documented incident response plan, including breach notification procedures described in Section 15.
11HIPAA & healthcare clients
Some of our clients operate in healthcare and may be "covered entities" or "business associates" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Where a client engagement involves creating, receiving, maintaining, or transmitting Protected Health Information (PHI) on their behalf, we:
- Enter into a Business Associate Agreement (BAA) with the client before processing any PHI;
- Limit PHI use strictly to the purposes authorized in that BAA;
- Apply administrative, physical, and technical safeguards consistent with the HIPAA Security Rule; and
- Report any suspected breach of unsecured PHI to the applicable covered entity without unreasonable delay, and in any event within the timeframe specified in the governing BAA.
We do not process PHI for marketing purposes outside the scope of an executed BAA. If your organization needs a BAA in place, contact us before sharing any PHI with our team or platform.
12Your privacy rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information, subject to legal exceptions;
- Restrict or object to certain processing, including processing based on legitimate interests or for direct marketing;
- Port your data to another provider in a structured, commonly used format;
- Withdraw consent at any time, where processing is based on consent; and
- Lodge a complaint with your local data protection authority (for EEA/UK residents) or applicable regulator.
To exercise any of these rights, contact us using the details in Section 17. We will verify your identity before fulfilling a request and will respond within the timeframe required by applicable law (generally 30 days, extendable where permitted).
13U.S. state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive privacy law, you may have additional rights, including the right to:
- Know the categories and specific pieces of personal information we have collected about you;
- Opt out of the "sale" or "sharing" of personal information, including for cross-context behavioral advertising;
- Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects;
- Limit the use of "sensitive personal information" (as defined under applicable law); and
- Not receive discriminatory treatment for exercising your privacy rights.
To submit a request, use our contact form, email privacy@dmwithqaf.com, or use the cookie preference tool described in our Cookie Policy to opt out of targeted advertising cookies. Authorized agents may submit requests on your behalf with appropriate proof of authorization.
14Children's privacy
Our website and services are directed at businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
15Data breach notification
In the event of a security incident affecting personal information, we will investigate promptly, take steps to contain and remediate the incident, and notify affected individuals and/or regulators as required under applicable law (including, where relevant, GDPR's 72-hour supervisory authority notification requirement and applicable U.S. state breach notification statutes). Where an incident affects PHI processed under a Business Associate Agreement, notification will follow the timeline specified in that agreement.
16Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated version with a revised "Last updated" date, and where changes are material, we will provide additional notice (such as a website banner or direct email) before the changes take effect.
17Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
DM with QAF LLC
7901 4TH ST N STE 22876, St Petersburg, FL 33702-4305, USA
Privacy inquiries: privacy@dmwithqaf.com
Security & compliance: security@dmwithqaf.com
General: info@dmwithqaf.com · +64 210 911 9584
This Privacy Policy is provided as a general-purpose template reflecting common industry and regulatory practice. It is not a substitute for legal advice. Please have qualified counsel review and tailor it before publishing, particularly the sections on certifications, HIPAA, and jurisdiction-specific rights.