This policy describes how 48 Advisory Group ("48ag", "we", "us", "our") collects, uses, and protects personal information when you visit 48ag.com, contact us, or work with us as a client.
Website analytics
We want to process as little personal information as possible when you use our website. That is why we useFathom Analytics, which does not use cookies and complies with the GDPR, ePrivacy (including PECR), COPPA, and CCPA. With Fathom, your IP address is only briefly processed and we have no way of identifying you. As per the CCPA, your personal information is de-identified.
We use this software to understand our website traffic in the most privacy-friendly way possible so we can keep improving our website and business. The lawful basis under the GDPR is Article 6(1)(f): our legitimate interest in continually improving our website and business. No personal data is stored over time.
Because Fathom does not set cookies, this website does not show a cookie banner. We do not use Google Analytics, advertising pixels, or session-recording tools on 48ag.com.
Booking a discovery call
When you book a call through the scheduling tool embedded on our site, you provide your name, email address, and anything you choose to write in the notes. That information goes to the scheduling provider under its own privacy policy and to us so we can hold the call and follow up. We use it to contact you about the call and about our services. You can ask us to stop at any time by replying to any email or writing tohello@48ag.com.
Correspondence
When you email us with a question or to ask for help, we keep that correspondence, including your email address, so we have a history to refer to if you reach out again.
Video calls may be recorded, transcribed, and shared among 48ag team members to help us understand and serve your needs. We will tell you when a call is being recorded. If you would rather not be recorded, say so and we will turn it off.
We also keep information you volunteer, such as survey responses. When we run customer interviews, we may ask for your permission to record the conversation for later reference. We only record with your express consent.
Billing information
When you pay for a 48ag service, we ask for your credit card or bank account details and your billing address so we can charge you, calculate any taxes due, and send invoices. Card and bank details are passed directly to our payment processor and never pass through our servers. We keep a record of each transaction, including the last four digits of the card and the billing address at the time, for account history, invoicing, and billing support. We keep your billing address to calculate sales tax due in the United States, to detect fraudulent transactions, and to print on invoices.
Client business data
Our services involve connecting to and analyzing your business systems: accounting, project management, CRM, analytics, payments, and similar tools. The data in those systems ("Client Data") belongs to you. This section explains how we handle it.
- What we access. Only the systems and data you authorize, and only to the extent needed to build your dashboards, write your operating review, or deliver the project you engaged us for.
- Personal information inside Client Data. Your systems may contain personal information about your customers, employees, or vendors. We process that information on your behalf and under your instructions. You remain responsible for having the right to share it with us.
- How we store it. Client Data is held in access-controlled systems, encrypted in transit and at rest where the platform supports it. Access is limited to the 48ag team members working on your engagement.
- What we do not do. We do not sell Client Data. We do not use it to market to your customers. We do not share it with other clients. We do not use it to train machine-learning models.
- Sub-processors. We use third-party infrastructure, such as cloud hosting, data warehousing, dashboard software, and AI-assisted analysis tools, to deliver the work. These providers process data only as needed to provide their service to us. A current list is available on request.
- When the engagement ends. We disconnect from your systems within 30 days of the end of an engagement. We delete or return Client Data on request, except for records we must keep for legal, tax, or accounting reasons, and except for anonymized, aggregated information that no longer identifies you.
Information we do not collect
We do not collect characteristics of protected classifications, including age, race, gender, religion, sexual orientation, gender identity, or gender expression. You may volunteer such information, for example in an email signature, but we do not ask for it or use it. We do not collect biometric data.
When we access or share your information
Our default is not to access your information beyond what the work requires. The only times we will access or share it are:
- To provide the services you requested. We use third-party services to run our business and, only to the extent necessary, process some of your information through them.
- To troubleshoot with your permission. If we need to look at your data or account to help with a support question, we will ask first.
- To investigate, prevent, or act on restricted uses. Accessing data to investigate potential abuse is a last resort. If we discover our services are being used for a restricted purpose, we may report it to the appropriate authorities.
- When required by law. If law enforcement presents a valid warrant, subpoena, or court order, we must comply. Otherwise we decline requests for data. Unless we are legally prevented from doing so, we will tell you when such a request is made.
If 48ag is acquired by or merged with another company, we will notify you before any information about you is transferred and becomes subject to a different privacy policy.
Your rights
We apply the same data rights to everyone, regardless of location. Two of the most protective regulations are the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). We recognize the rights granted in both, except as limited by applicable law:
- Right to know what personal information is collected, used, shared, or sold. This policy sets out the categories and specifics.
- Right of access to the personal information we hold about you and to information about how it is shared, stored, secured, and processed.
- Right to correction of your personal information.
- Right to erasure, subject to limits under applicable law, of your personal information from our possession and, by extension, our service providers. Some deletion requests may make it impossible to continue an engagement.
- Right to complain to the appropriate supervisory authority about our handling of your personal information.
- Right to restrict processing, including opting out of the sale of personal information. We never have sold personal data and never will.
- Right to object, in certain situations, to how or why your personal information is processed.
- Right to portability: to receive the personal information we hold about you and transmit it to another party.
- Right not to be subject to automated decision-making that has a legal or similarly significant effect on you, except where necessary for a contract with you, allowed by law, or based on your explicit consent.
- Right to non-discrimination. We will not charge you more, offer different discounts, or give you a lower level of service because you exercised your privacy rights.
To exercise any of these rights, email hello@48ag.com. We will respond within 30 days.
How long we keep information
- Website analytics: Fathom stores only aggregated, anonymous statistics. There is no personal data to retain.
- Correspondence and booking information: for as long as we have an ongoing relationship, and up to three years after our last contact unless you ask us to delete it sooner.
- Billing records: seven years, as required for tax and accounting purposes.
- Client Data: for the length of the engagement and up to 30 days after, then deleted or returned as described above.
How we secure your data
All data is encrypted with TLS in transit between our systems and your browser. Systems that hold Client Data use access controls, multi-factor authentication for our team, and encryption at rest where the platform supports it. No method of transmission or storage is perfectly secure, but we take reasonable steps to protect your data and will tell you promptly if we learn of a breach affecting it.
Location of site and data
Our services and web properties are operated from Wisconsin in the United States. If you are located in the European Union, the United Kingdom, or elsewhere outside the United States, any information you provide to us will be transferred to and processed in the United States. Where required, we rely on standard contractual clauses or your consent for those transfers. By using our site or services, or by providing us with your information, you consent to this transfer.
Children
Our website and services are for businesses and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes and questions
We may update this policy as regulations change and as our practices change. The date at the top shows when it last changed. Questions, comments, or concerns about this policy, your data, or your rights can be sent tohello@48ag.com. See also our Terms of Service.
