Effective Date: September 1, 2025 · Last Updated: September 4, 2026
This policy governs how SmartXperiences handles personal information across all of its services. For the practices of this website specifically, including cookies and online tracking, see our Privacy Policy.
1. Purpose
Smart Xperiences, LLC (“SmartXperiences,” “we,” “our,” or “us”) is committed to respecting consumer privacy and protecting the personal information entrusted to us.
This policy establishes the principles and safeguards SmartXperiences follows when collecting, accessing, using, storing, transmitting, sharing, retaining, and disposing of personal information. It applies to information handled through our websites, marketing services, analytics systems, communications platforms, customer relationship management systems, call-tracking technologies, artificial-intelligence-enabled tools, and services performed for our clients.
2. Our Privacy Commitments
SmartXperiences will:
- Collect and process personal information only for legitimate, disclosed, and authorized business purposes.
- Limit collection to information reasonably necessary to provide the requested service or fulfill a defined business purpose.
- Use personal information consistently with applicable privacy laws, contractual obligations, client instructions, and consumer choices.
- Maintain reasonable administrative, technical, and physical safeguards appropriate to the nature and sensitivity of the information.
- Restrict access to authorized personnel, service providers, and contractors with a legitimate business need.
- Retain personal information only as long as reasonably necessary for the authorized purpose, contractual requirements, dispute resolution, or legal obligations.
- Securely delete, destroy, anonymize, or return information when it is no longer required.
- Provide reasonable assistance with valid consumer privacy requests when SmartXperiences is responsible for responding or processes information for a client.
- Review privacy and information-security practices periodically and update safeguards as business operations, technologies, and legal requirements evolve.
3. Information Covered by This Policy
“Personal information” means information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an individual or household.
Depending on the service provided, this may include:
- Names, mailing addresses, email addresses, and telephone numbers.
- Customer, prospect, and lead information.
- Appointment, enquiry, and service-request information.
- Website activity, device information, IP addresses, cookies, advertising identifiers, and similar online activity data.
- Call recordings, call transcripts, text messages, emails, form submissions, and other communications, when lawfully collected.
- Marketing-source, campaign, attribution, engagement, and conversion information.
- Customer relationship management records.
- Transaction or revenue information supplied by a client for attribution and performance measurement.
- Consumer preferences, consent records, and opt-out requests.
- Inferences created from the information above for authorized marketing, analytics, qualification, or customer-service purposes.
SmartXperiences does not intentionally collect Social Security numbers, complete payment-card credentials, government identification numbers, medical records, or other highly sensitive information unless collection is specifically authorized, necessary for a defined service, legally permitted, and protected by appropriate contractual and security safeguards.
4. How Information Is Collected
Personal information may be collected:
- Directly from consumers who contact SmartXperiences or one of our clients.
- Through websites, forms, telephone calls, text messages, emails, scheduling tools, and customer-service interactions.
- From clients that engage SmartXperiences to perform marketing, analytics, attribution, lead-management, or related services.
- From advertising platforms, analytics providers, customer relationship management systems, call-tracking services, and other authorized technology providers.
- From lawfully obtained business, public, or commercial sources.
- Through cookies and similar technologies, subject to applicable notice and consent requirements.
5. Permitted Uses
SmartXperiences may process personal information to:
- Respond to enquiries and provide requested information.
- Schedule appointments or facilitate communications between consumers and businesses.
- Deliver, operate, maintain, and improve contracted services.
- Attribute enquiries, customers, appointments, and revenue to marketing sources.
- Measure campaign effectiveness and improve marketing performance.
- Qualify and route enquiries based on the consumer’s stated needs.
- Maintain customer and prospect records.
- Communicate about services when legally permitted and consistent with applicable consent and opt-out requirements.
- Detect fraud, misuse, security incidents, or technical problems.
- Maintain records of consent, preferences, and privacy requests.
- Satisfy contractual, accounting, legal, regulatory, and reporting requirements.
SmartXperiences will not use client-provided consumer information for unrelated purposes unless the use is separately authorized and legally permitted.
6. SmartXperiences as a Service Provider or Contractor
When SmartXperiences processes personal information on behalf of a client, SmartXperiences will act according to the applicable agreement and documented instructions of that client.
Unless otherwise legally permitted and expressly agreed, SmartXperiences will not:
- Sell client-provided personal information.
- Share client-provided personal information for cross-context behavioral advertising.
- Retain, use, or disclose client-provided information outside the defined business relationship.
- Use client-provided information for purposes unrelated to the contracted services.
- Combine client-provided information with information obtained from unrelated sources when prohibited by applicable law or contract.
SmartXperiences will reasonably assist clients in responding to consumer-access, correction, deletion, restriction, and opt-out requests relating to information processed on their behalf.
7. Advertising, Telephone, Email, and Text Communications
SmartXperiences requires marketing communications to be conducted in accordance with applicable consent, disclosure, identification, suppression, and opt-out requirements.
Where applicable:
- Telephone calls, prerecorded messages, and text messages must have the legally required level of consent.
- Consent records must identify what the consumer authorized and how and when authorization was obtained.
- Consumers must be given a clear way to opt out of future marketing communications.
- Opt-out and do-not-contact requests must be honored within the period required by applicable law.
- Suppression records may be retained to prevent future unauthorized contact.
- Purchased, licensed, or third-party contact data may be used only when its source and permitted use have been reasonably evaluated.
- Deceptive subject lines, caller identification, sender information, claims, or representations are prohibited.
8. Artificial Intelligence and Automated Systems
SmartXperiences may use artificial intelligence or automated technologies to support activities such as call handling, transcription, enquiry qualification, message drafting, analysis, routing, reporting, and marketing optimization.
When these technologies process personal information, SmartXperiences will:
- Limit their use to authorized business purposes.
- Apply appropriate access and vendor controls.
- Avoid submitting sensitive information to unauthorized public AI systems.
- Require appropriate human oversight for consequential or sensitive uses.
- Disclose automated or recorded interactions when required.
- Review material automated outputs before relying on them for significant business decisions.
- Avoid representing an automated system as a human when doing so would be deceptive or unlawful.
9. Information Sharing
SmartXperiences may disclose personal information to:
- The client on whose behalf the information was collected or processed.
- Authorized technology, hosting, analytics, communications, advertising, and professional-service providers.
- Contractors that require access to perform authorized services.
- Government authorities or other parties when required by law, legal process, or a valid regulatory request.
- Appropriate parties when reasonably necessary to protect consumers, clients, SmartXperiences, or others from fraud, abuse, security threats, or unlawful activity.
- A successor organization in connection with a merger, acquisition, financing, reorganization, or sale of business assets, subject to applicable privacy requirements.
Service providers and contractors must be subject to appropriate confidentiality, data-use, security, and deletion obligations.
SmartXperiences does not sell personal information for monetary compensation. If an activity is legally classified as “selling” or “sharing” personal information, SmartXperiences will provide any notices and opt-out mechanisms required by applicable law.
10. Consumer Privacy Rights
Depending on the consumer’s location and the applicable law, a consumer may have the right to:
- Know whether personal information is being processed.
- Request access to specified personal information.
- Request correction of inaccurate information.
- Request deletion of personal information, subject to legal exceptions.
- Receive information about collection, use, and disclosure practices.
- Opt out of certain sales, sharing, targeted advertising, or marketing communications.
- Limit certain uses or disclosures of sensitive personal information.
- Withdraw consent when processing is based on consent.
- Receive portable copies of eligible information.
- Appeal certain decisions concerning a privacy request.
- Exercise privacy rights without unlawful discrimination or retaliation.
When SmartXperiences holds information solely for a client, the consumer may be directed to submit the request to that client. SmartXperiences will cooperate with the client as required by applicable law and contract.
Requests may be submitted using the contact information in Section 18. SmartXperiences may take reasonable steps to verify the requestor’s identity and authority before acting.
11. Global Privacy Control and Tracking Preferences
When applicable law requires recognition of browser-based opt-out preference signals, including Global Privacy Control, SmartXperiences will take reasonable steps to recognize and process those signals through the relevant website and technology systems.
Not all browser “Do Not Track” signals have a uniform legal or technical standard. SmartXperiences will describe its practices in the applicable website privacy notice.
12. Security Safeguards
SmartXperiences maintains a risk-based information-security program designed to protect personal information against unauthorized access, acquisition, loss, disclosure, alteration, destruction, or misuse.
Safeguards may include, as appropriate:
- Role-based access controls and least-privilege access.
- Strong passwords and multifactor authentication.
- Encryption during transmission and, where appropriate and supported, while stored.
- Secure configuration and timely software updates.
- Endpoint, account, email, and network protections.
- Secure backup and recovery procedures.
- Vendor security and privacy reviews.
- Confidentiality and data-protection agreements.
- Employee and contractor privacy and security training.
- Logging, monitoring, testing, and review of material systems.
- Secure deletion and disposal procedures.
- Documented incident-response and notification procedures.
No system can guarantee absolute security. SmartXperiences therefore reviews and improves its safeguards based on risk, operational changes, available technology, and applicable legal requirements.
13. Data Minimization and Retention
SmartXperiences will collect and retain only the personal information reasonably necessary for authorized business purposes.
Retention periods will consider:
- The purpose for which the information was collected.
- Client instructions and contractual requirements.
- Consumer expectations and consent.
- Legal, accounting, tax, regulatory, and dispute-resolution requirements.
- The sensitivity of the information.
- Security and operational considerations.
When information is no longer reasonably required, SmartXperiences will delete, destroy, anonymize, or return it using methods appropriate to its sensitivity and format.
14. Security Incidents
Suspected loss, unauthorized access, disclosure, or misuse of personal information must be reported promptly to the designated SmartXperiences privacy or security contact.
SmartXperiences will:
- Investigate and contain the incident.
- Preserve relevant records.
- Assess the nature, scope, and potential consequences.
- Take reasonable remediation measures.
- Notify affected clients, consumers, insurers, regulators, or law-enforcement authorities when required by law or contract.
- Document material findings and corrective actions.
- Review safeguards following a material incident.
15. Vendors and Third Parties
Before giving a vendor material access to personal information, SmartXperiences will reasonably evaluate the vendor’s role, access requirements, privacy practices, security measures, and contractual commitments.
Applicable agreements should address:
- Authorized processing purposes.
- Confidentiality and information-security requirements.
- Restrictions on secondary use, sale, sharing, or combining of information.
- Assistance with consumer privacy requests.
- Incident reporting.
- Retention, deletion, and return of information.
- Use of subcontractors.
- Audit, assessment, or compliance-verification rights where appropriate.
16. Children’s Information
SmartXperiences’ general services are not directed to children under 13, and SmartXperiences does not knowingly collect personal information directly from children under 13 without legally valid parental authorization.
If SmartXperiences learns that such information was collected without appropriate authorization, it will take reasonable steps to delete or otherwise address it as required by law.
17. Accountability and Training
All personnel and contractors with access to personal information must:
- Follow this policy and applicable client requirements.
- Access information only when required for authorized work.
- Protect account credentials and confidential information.
- Complete appropriate privacy and security training.
- Report suspected incidents, policy violations, or improper information use promptly.
Violations may result in removal of access, contract termination, disciplinary action, or other appropriate corrective measures.
SmartXperiences will periodically review this policy and its supporting procedures. Material changes will be documented and communicated when appropriate.
18. Privacy Contact
Questions, concerns, or privacy requests may be submitted to:
Smart Xperiences, LLC
Attention: Privacy Officer
Email: privacy@smartxperiences.com
Telephone: 1-218-947-6278
Mailing Address: 11 Elliot Ln., Coto de Caza, CA 92679
19. Applicable Requirements
SmartXperiences intends to conduct its personal-information practices consistently with the privacy, data-security, communications, and consumer-protection requirements applicable to its operations and contractual role.
This policy does not claim that every privacy or industry-specific law applies to SmartXperiences. Requirements such as HIPAA, the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, payment-card standards, or international privacy laws apply only when the company’s activities, information, contractual obligations, or jurisdiction bring them within scope.
Approved by Andrew Yudin, Founder & CEO. Next scheduled review: September 3, 2027.