DM QAF
  • Home
  • About
  • Services
  • Solutions
  • Analytics
  • Growth
  • Contact
  • AI Audit
Legal

Privacy Policy

This Privacy Policy explains how DM with QAF LLC ("QAF," "we," "us," or "our") collects, uses, discloses, and safeguards information when you visit our website, use our AI-powered marketing platform, or engage us as a client.

Last updated: September 2, 2026 Version 1.0 Applies globally, with region-specific rights below
On this page
  1. Scope & who we are
  2. Information we collect
  3. How we use information
  4. Legal bases for processing
  5. AI & automated decision-making
  6. Cookies & tracking
  7. How we share information
  8. International data transfers
  9. Data retention
  10. Security & compliance
  11. HIPAA & healthcare clients
  12. Your privacy rights
  13. U.S. state privacy rights
  14. Children's privacy
  15. Data breach notification
  16. Changes to this policy
  17. Contact us
SOC 2 Type II – aligned controls ISO/IEC 27001 – aligned ISMS HIPAA – available for covered clients GDPR & UK GDPR CCPA / CPRA
Plain-language summary: We collect the information you give us and the information generated when you use our site or platform, we use it to run and improve our marketing services (including AI-assisted features), we do not sell your personal information, and we give you tools to access, correct, or delete it. The sections below cover the full legal detail.

1Scope & who we are

DM with QAF LLC is a digital marketing agency headquartered at 7901 4TH ST N STE 22876, St Petersburg, FL 33702-4305, USA. This Policy applies to personal information we process through:

  • Our marketing website (dmwithqaf.com) and any subdomains, including our chatbot widget;
  • Client-facing dashboards, reporting tools, and analytics platforms we operate;
  • Marketing campaigns, forms, and communications you engage with; and
  • Data our clients ask us to process on their behalf as part of our services (in which case we act as a "processor" or "service provider," and our client's own privacy notice also applies).

If you are an individual interacting with a campaign run by one of our clients, please also review that client's privacy notice — they control that data as the "controller" or "business," and we process it under contract on their instructions.

2Information we collect

2.1 Information you provide directly

  • Contact details (name, email, phone, company, job title) submitted through forms, the chatbot, or email;
  • Account credentials for client dashboards;
  • Billing and payment details, processed through PCI DSS–compliant payment processors;
  • Content of messages, support tickets, and chatbot conversations;
  • Any data your organization uploads to our platform for campaign execution or analysis.

2.2 Information collected automatically

  • Device and browser information (IP address, browser type, operating system);
  • Usage data (pages visited, links clicked, session duration, referring URLs);
  • Cookies and similar technologies, described in our Cookie Policy;
  • Approximate location derived from IP address.

2.3 Information from third parties

  • Advertising and analytics platforms (e.g., ad networks, search engines, social platforms) connected to campaigns we run;
  • Data enrichment and B2B intelligence providers used to qualify leads;
  • Publicly available sources, where lawful.
CategoryExamplesSource
IdentifiersName, email, phone, IP addressYou; automatically
Commercial informationServices purchased, billing historyYou; our systems
Internet activityBrowsing behavior, click dataAutomatically; cookies
Professional informationJob title, company, industryYou; third parties
InferencesPredicted interests, engagement scoresOur AI models

3How we use information

We use personal information to:

  • Provide, operate, and improve our website, platform, and marketing services;
  • Respond to inquiries and provide customer support, including through our AI chatbot;
  • Deliver, personalize, and measure marketing campaigns on behalf of our clients;
  • Train, fine-tune, and evaluate the predictive and generative models that power our analytics and automation features, in accordance with Section 5 below;
  • Process payments and manage billing;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Comply with legal obligations and enforce our agreements; and
  • Send administrative communications and, where you have opted in, marketing communications.

4Legal bases for processing (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing services under contract with a clientPerformance of a contract
Responding to inquiries, operating the chatbotLegitimate interests
Analytics, product improvement, model evaluationLegitimate interests
Marketing emails to prospectsConsent, or legitimate interests where permitted by local law
Fraud prevention and securityLegitimate interests; legal obligation
Special category or sensitive data (rare, e.g., health-related campaigns)Explicit consent, or another Article 9 condition

Where we rely on legitimate interests, we have assessed that our processing does not override your fundamental rights and freedoms. You can object to processing based on legitimate interests as described in Section 12.

5AI & automated decision-making

As an AI-first marketing agency, we use machine learning and generative AI (including third-party foundation models such as those provided by OpenAI, Anthropic, and Google, and open models via Hugging Face) to power features including predictive analytics, lead scoring, content generation, and our chatbot.

  • No solely-automated decisions with legal or similarly significant effects. We do not use these systems to make decisions that produce legal or similarly significant effects about individuals (e.g., credit, employment, or eligibility decisions) without meaningful human review.
  • Model training. We do not use client campaign data or end-user personal information to train third-party foundation models for the benefit of other customers. Where we fine-tune internal models, we use de-identified or aggregated data wherever feasible.
  • Human oversight. AI-generated content, scores, and recommendations are reviewed by our team before being used in client-facing decisions of consequence.
  • Your controls. You may request more information about the logic involved in a specific automated feature, or request human review of an output, by contacting us using the details in Section 17.

6Cookies & tracking technologies

We use cookies, pixels, and similar technologies to operate our site, remember preferences, measure performance, and support advertising. Full details, including a category-by-category breakdown and instructions for managing your preferences, are available in our Cookie Policy.

7How we share information

We do not sell personal information for money. We may share information as follows:

  • Service providers / subprocessors: cloud hosting, analytics, email delivery, payment processing, customer support tooling, and AI model providers, each bound by written data processing terms;
  • Clients: where we run campaigns on a client's behalf, campaign performance and lead data is shared with that client;
  • Advertising & analytics partners: for campaign delivery and measurement, subject to the choices described in our Cookie Policy;
  • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections;
  • Legal & safety: where required to comply with law, respond to lawful requests, or protect the rights, property, or safety of QAF, our clients, or others.

Under U.S. state privacy laws, sharing personal information with advertising partners for cross-context behavioral advertising may be considered a "sale" or "share." See Section 13 for your opt-out rights.

8International data transfers

We are based in the United States and may process information in the U.S. and other countries where our service providers operate. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. Contact us for a copy of the relevant safeguards.

9Data retention

We retain personal information for as long as needed to provide our services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Typical retention periods:

Data typeTypical retention
Client account & billing recordsDuration of contract, plus 7 years for tax/accounting purposes
Marketing leads & form submissionsUp to 24 months from last engagement, or until you opt out
Website analytics & log dataUp to 14 months
Chatbot conversation logsUp to 12 months
Security & audit logsUp to 12 months, longer if required for an active investigation

10Security & compliance

We maintain a written information security program with administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our program is built around widely recognized frameworks:

  • SOC 2 Type II – aligned controls: our internal control environment for security, availability, and confidentiality is designed with reference to the AICPA's Trust Services Criteria. Ask your account manager for our current audit status and, where available, our SOC 2 report under NDA.
  • ISO/IEC 27001 – aligned ISMS: our information security management practices — risk assessment, access control, encryption, incident response, and vendor management — are designed with reference to ISO/IEC 27001 Annex A controls.
  • Encryption: data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption (e.g., AES-256) where supported by our infrastructure providers.
  • Access control: role-based access, multi-factor authentication for administrative systems, and least-privilege principles for staff and contractors.
  • Vendor management: subprocessors are assessed for security posture and bound by data processing agreements before onboarding.
  • Incident response: a documented incident response plan, including breach notification procedures described in Section 15.
Note on certification status: references to SOC 2 and ISO/IEC 27001 above describe the frameworks that inform our control design. They do not, by themselves, constitute a claim of current third-party certification unless confirmed in writing by our compliance team. Contact security@dmwithqaf.com for our current audit and certification status, and copies of available reports under NDA.

11HIPAA & healthcare clients

Some of our clients operate in healthcare and may be "covered entities" or "business associates" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Where a client engagement involves creating, receiving, maintaining, or transmitting Protected Health Information (PHI) on their behalf, we:

  • Enter into a Business Associate Agreement (BAA) with the client before processing any PHI;
  • Limit PHI use strictly to the purposes authorized in that BAA;
  • Apply administrative, physical, and technical safeguards consistent with the HIPAA Security Rule; and
  • Report any suspected breach of unsecured PHI to the applicable covered entity without unreasonable delay, and in any event within the timeframe specified in the governing BAA.

We do not process PHI for marketing purposes outside the scope of an executed BAA. If your organization needs a BAA in place, contact us before sharing any PHI with our team or platform.

12Your privacy rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Delete your personal information, subject to legal exceptions;
  • Restrict or object to certain processing, including processing based on legitimate interests or for direct marketing;
  • Port your data to another provider in a structured, commonly used format;
  • Withdraw consent at any time, where processing is based on consent; and
  • Lodge a complaint with your local data protection authority (for EEA/UK residents) or applicable regulator.

To exercise any of these rights, contact us using the details in Section 17. We will verify your identity before fulfilling a request and will respond within the timeframe required by applicable law (generally 30 days, extendable where permitted).

13U.S. state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive privacy law, you may have additional rights, including the right to:

  • Know the categories and specific pieces of personal information we have collected about you;
  • Opt out of the "sale" or "sharing" of personal information, including for cross-context behavioral advertising;
  • Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects;
  • Limit the use of "sensitive personal information" (as defined under applicable law); and
  • Not receive discriminatory treatment for exercising your privacy rights.

To submit a request, use our contact form, email privacy@dmwithqaf.com, or use the cookie preference tool described in our Cookie Policy to opt out of targeted advertising cookies. Authorized agents may submit requests on your behalf with appropriate proof of authorization.

14Children's privacy

Our website and services are directed at businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.

15Data breach notification

In the event of a security incident affecting personal information, we will investigate promptly, take steps to contain and remediate the incident, and notify affected individuals and/or regulators as required under applicable law (including, where relevant, GDPR's 72-hour supervisory authority notification requirement and applicable U.S. state breach notification statutes). Where an incident affects PHI processed under a Business Associate Agreement, notification will follow the timeline specified in that agreement.

16Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated version with a revised "Last updated" date, and where changes are material, we will provide additional notice (such as a website banner or direct email) before the changes take effect.

17Contact us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us:

DM with QAF LLC

7901 4TH ST N STE 22876, St Petersburg, FL 33702-4305, USA

Privacy inquiries: privacy@dmwithqaf.com

Security & compliance: security@dmwithqaf.com

General: info@dmwithqaf.com · +64 210 911 9584

This Privacy Policy is provided as a general-purpose template reflecting common industry and regulatory practice. It is not a substitute for legal advice. Please have qualified counsel review and tailor it before publishing, particularly the sections on certifications, HIPAA, and jurisdiction-specific rights.

DM QAF

AI-powered digital marketing agency delivering complete solutions with automation, analytics, and growth strategies.

Quick Links

  • Home
  • About Us
  • Services
  • Solutions
  • Contact

Our Services

  • AI Automation
  • Performance Marketing
  • Marketing Analytics
  • Growth Strategy
  • Digital Marketing

Contact Us

  • 7901 4TH ST N STE 22876
    St Petersburg, FL 33702-4305
  • info@dmwithqaf.com
  • +64 210 911 9584

© 2026 DM with QAF LLC. All rights reserved.

Privacy Policy Terms of Service Cookie Policy