Legal

Privacy Policy

Qorban Consulting LLC

Effective Date: July 28, 2026 Last Updated: July 28, 2026

1. Two Different Roles — Read This First

Qorban Consulting LLC ("Qorban," "we," "us") handles personal information in two very different roles, and this policy treats them separately.

Role 1 — We are the controller. Information about visitors to www.qorbanconsulting.com, prospective clients, people who fill out our forms, subscribe to our emails, or contact us, and our own personnel and vendors. Sections 2 through 12 describe this.

Role 2 — We are a processor / service provider. Information belonging to our clients, including data about our clients' customers, employees, and end users, which we access or process only to perform services under contract. We do not own this data and we do not decide how it is used. Our handling of it is governed by our signed agreement with that client — the Master Services Agreement and Data Processing Addendum — not by this policy. Section 13 describes this.

If you are a customer of one of our clients and you want to exercise privacy rights over your information, contact that business directly. They are the controller. We will support their response, but we cannot act on your request without their instruction. See Section 13.

2. Information We Collect (Controller Role)

Information you give us directly:

  • Name, business name, job title
  • Email address, phone number, mailing address
  • Information you include in a contact form, discovery questionnaire, intake form, or email — including descriptions of your business, systems, processes, and challenges
  • Meeting scheduling information and availability
  • Recordings, transcripts, and notes from calls and meetings, where we have told you we are recording and you have consented (see Section 5)
  • Billing and payment information — processed by Stripe; we do not store full payment card numbers
  • Any other information you choose to send us

Information collected automatically when you visit the Site:

  • IP address and approximate location derived from it
  • Browser type, device type, operating system, screen size
  • Pages visited, time on page, referring URL, exit pages
  • Date and time of access
  • Interactions with forms, buttons, and links
  • Cookie and similar identifiers, including advertising identifiers (see Sections 6 and 7)

Information from third parties:

  • Business contact information from professional networks, public business directories, and business data providers
  • Referral information from mutual contacts and partners
  • Analytics and advertising platform data about how visitors reach and interact with the Site

We do not knowingly collect sensitive personal information in our controller role. Please do not send us Social Security numbers, financial account numbers, health information, biometric data, precise geolocation, or information about your race, religion, health, sexual orientation, immigration status, or union membership through our Site forms or general email. If you do, we will delete it.

Do not send protected health information to us at all. See Section 14.

3. How We Use It (Controller Role)

  • Respond to your inquiry and communicate with you
  • Evaluate whether we are a fit for your needs, and prepare proposals and statements of work
  • Deliver and administer services, including invoicing and payment
  • Maintain records of what was discussed, agreed, scoped, and delivered
  • Send marketing emails, newsletters, and updates where you have opted in or where otherwise permitted by law, with an unsubscribe link in every marketing message
  • Advertising and remarketing — to measure the performance of our advertising and to show our ads to people who have visited our Site (see Sections 6 and 7)
  • Improve the Site, our offerings, and our internal processes
  • Maintain the security and integrity of our systems
  • Comply with legal, tax, accounting, and contractual obligations
  • Establish, exercise, or defend legal claims

Advertising and "sharing" of personal information. We use Google and Meta advertising technologies on our Site. These technologies set identifiers in your browser and transmit information about your visit to Google and Meta, which use it to measure our advertising and to show you our ads on other websites and platforms. Under California law and several other state privacy laws, this activity is treated as "sharing" personal information for cross-context behavioral advertising, or as a "sale."

We do not sell personal information for money. But because the activity above may be treated as a sale or sharing under those laws, we provide an opt-out. You can opt out by:

  • Using the "Your Privacy Choices" link in our Site footer;
  • Declining or withdrawing consent to marketing cookies in our cookie banner;
  • Sending a Global Privacy Control signal from your browser, which we honor; or
  • Emailing privacy@qorbanconsulting.com.

We do not use information collected in our controller role to train artificial intelligence models, and we do not permit our vendors to use it to train their models where their terms allow us to make that election.

4. Legal Bases (For Visitors in the EU, UK, and Similar Jurisdictions)

Where required, we rely on: contract (to provide services you requested), legitimate interests (business communications, security, service improvement, defense of legal claims), consent (marketing emails, non-essential and advertising cookies, call recording), and legal obligation (tax and recordkeeping). You may withdraw consent at any time; withdrawal does not affect processing already carried out.

5. Call and Meeting Recording

We use Zoom for meetings and may record or transcribe calls for note-taking and accuracy. We will tell you before recording and you may decline. If you decline, we will take manual notes instead. Recordings and transcripts are treated as confidential, stored in access-controlled systems, and retained per Section 9.

Tennessee is a one-party-consent state, but our practice is to obtain the consent of all participants regardless, since participants may be located in states requiring all-party consent.

6. Cookies and Similar Technologies

We use:

  • Strictly necessary cookies — required for the Site to function and to remember your cookie preferences.
  • Analytics cookies — Google Analytics, to understand aggregate traffic and how the Site is used.
  • Advertising and remarketing cookies and pixelsGoogle Ads / Google Tag Manager and the Meta Pixel, used for conversion measurement and remarketing.

Consent. We display a cookie banner. Analytics and advertising cookies and pixels are not set until you consent, and you may change your preferences at any time through the banner or the "Your Privacy Choices" link in our footer.

You can also control cookies through your browser settings. Blocking strictly necessary cookies may break Site functionality.

Global Privacy Control. We honor the Global Privacy Control (GPC) signal where our systems can detect it. We do not respond to legacy "Do Not Track" browser headers, because there is no common industry standard for them.

7. Who We Share It With

We share personal information with the following categories of service providers and partners:

CategoryProviderPurpose
Hosting and deploymentVercelRunning the Site
Database and backendSupabaseStoring business and application data
AI and model providersAnthropic, GoogleAssisting with analysis, drafting, and service delivery
CRM and salesHubSpotManaging inquiries and client records
Marketing and communicationsGoHighLevelEmail, SMS, and campaign delivery
Meetings and transcriptionZoomCalls, recording, transcription
Payment processingStripeInvoicing and payment collection
Project managementMonday.comManaging engagements and internal work
AnalyticsGoogle AnalyticsAggregate Site usage measurement
AdvertisingGoogle, MetaAdvertising measurement and remarketing
Productivity and storageGoogle WorkspaceEmail, documents, file storage
Professional advisorsAs neededLegal, accounting, insurance
SubcontractorsAs neededPerforming parts of services, under written confidentiality terms

We require our vendors and subcontractors to protect the information, to use it only for the purposes we specify, and — where their terms permit that election — not to use it to train their models. Advertising partners (Google, Meta) process data for their own purposes as described in their own privacy policies, which is why we treat that activity as "sharing" and provide an opt-out.

We also disclose information: to comply with law, subpoena, or lawful government request; to enforce our terms; to protect the rights, safety, or property of Qorban, our clients, or others; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor commitments no less protective than this policy.

8. Security

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle, including:

  • Multi-factor authentication on our business-critical accounts, including Vercel, Supabase, HubSpot, Google, and Stripe
  • Credentials and secrets stored in an access-controlled secrets manager — never in plaintext documents, spreadsheets, chat messages, or email
  • Row-level security enabled on database tables containing client data
  • Encryption in transit, and encryption at rest on our primary data store
  • Least-privilege access, limited to the personnel who require it for their work
  • Logging and periodic review of access to sensitive systems
  • A written incident response process, including notification to affected clients and individuals as required by contract and law
  • Vendor review before granting any new vendor access to client or personal data
  • Written confidentiality obligations for all personnel and subcontractors

No system is perfectly secure. We cannot guarantee absolute security. Information sent to us over the internet or by email travels at your own risk until it reaches our systems.

9. How Long We Keep It

CategoryRetention
Inquiries that do not become engagements24 months from last contact
Client engagement records, contracts, deliverables7 years after the engagement ends
Billing and financial records7 years
Marketing contactsUntil you unsubscribe, then a minimal suppression record so we do not re-contact you
Call recordings and transcripts12 months, unless part of an engagement record
Site analytics14 months, in aggregated or de-identified form
BackupsOverwritten on a rolling 90-day cycle

Where a longer period is required by law, contract, or an ongoing legal matter, we keep it longer.

Client Data retention is governed by the applicable client agreement, not by this section. See Section 13.

10. Your Rights

Depending on where you live, you may have the right to: know what personal information we hold about you and how we use it; access a copy of it; correct inaccuracies; delete it; opt out of targeted advertising, sale or sharing, and certain profiling; withdraw consent; and not be discriminated against for exercising these rights.

Tennessee. The Tennessee Information Protection Act took effect July 1, 2025. It applies only to businesses exceeding $25 million in annual revenue that also meet a large consumer-volume threshold, so it does not currently apply to Qorban. We honor Tennessee residents' requests as a matter of policy regardless.

Other states. We honor requests from residents of California, Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws, to the extent those laws apply to us and to the categories of information involved.

How to exercise a right. Email privacy@qorbanconsulting.com with your request and enough information for us to locate your records. We will acknowledge within 5 business days and respond within 45 days, and may extend once by another 45 days with notice to you. We may need to verify your identity before acting, and we will not use verification information for any other purpose. An authorized agent may submit a request on your behalf with proof of authorization.

Opting out of targeted advertising. Use the "Your Privacy Choices" link in our Site footer, adjust your cookie preferences, send a Global Privacy Control signal, or email us.

If we deny a request, we will explain why, and you may appeal by replying to our response. We will respond to an appeal within 45 days. If we deny the appeal, you may contact the Tennessee Attorney General or the attorney general of your state.

Requests about client data. If your information is held by us on behalf of one of our clients, we will forward your request to that client and support their response. We cannot delete or alter their records on our own authority. See Section 13.

Marketing opt-out. Every marketing email includes an unsubscribe link. You may also email privacy@qorbanconsulting.com. We will still send transactional and engagement-related messages.

11. Children

The Site is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18 in our controller role. If you believe a child has provided us information, email privacy@qorbanconsulting.com and we will delete it.

12. Third-Party Links and International Visitors

The Site may link to third-party websites and tools. Their privacy practices are their own and we are not responsible for them.

We operate in the United States, and information we hold is processed and stored in the United States. If you access the Site from outside the U.S., you understand your information will be transferred to and processed in the U.S., which may have different data protection rules than your jurisdiction. Where a cross-border transfer mechanism is required, we will implement an appropriate one.

13. Client Data — Our Processor Role

When we perform services, we may access or process personal information that belongs to our client and relates to our client's customers, employees, or end users ("Client Data").

This commonly includes access to platforms our clients own and license, such as job and project management systems, field service platforms, CRM systems, and communications tools — for example JobNimbus, AccuLynx, Proline, JobTread, HubSpot, and GoHighLevel. We access these platforms inside our client's own account, under our client's own agreement with that platform. We are not the customer of record for our clients' instances of those platforms, and those platforms are not our subprocessors when accessed this way.

For Client Data:

  • Our client is the controller. We are the processor or service provider.
  • We process Client Data only on our client's documented instructions and only to perform the contracted services.
  • We do not use Client Data for our own purposes, do not sell or share it, do not use it for our own marketing, and do not use it to train artificial intelligence models. Where we route Client Data through an AI provider, we contract for terms that exclude that data from the provider's model training where such terms are available; where they are not available, we tell the client before routing data to that provider.
  • We access client systems using named user accounts with the minimum permissions needed, time-limited to the work, and we confirm in writing when access is no longer required.
  • We hold Client Data subject to the confidentiality, security, subprocessor, breach notification, and deletion terms of the signed agreement and Data Processing Addendum.
  • On termination, we return or securely delete Client Data as directed by the client, except copies in routine backups that expire on their normal cycle and material we must retain by law.

If you are an individual whose information one of our clients holds: contact that business. They control the data and the decision. We will assist them in responding, and where we hold a copy on their behalf we will act on their instruction promptly.

14. Protected Health Information

We do not accept protected health information.

Qorban does not currently accept, process, store, or transmit protected health information ("PHI") as defined under HIPAA, does not act as a HIPAA business associate, and does not execute Business Associate Agreements at this time.

  • Do not transmit PHI to us through our Site forms, our email addresses, chat widgets, text messages, or any other channel.
  • Do not grant us access to any system containing PHI.
  • If PHI reaches us despite this, we will notify the sender, refuse to process it, and securely delete or return it.

This is a deliberate limitation on our current scope of services. If it changes, we will update this policy, and we will not accept PHI before both an executed Business Associate Agreement and appropriate insurance coverage are in place.

If you are a patient: your rights under HIPAA are exercised through your healthcare provider or health plan. Contact them directly.

15. Changes to This Policy

We may update this policy. We will post the revised version with a new "Last Updated" date. For material changes affecting how we use information we already hold, we will provide notice by email or a prominent Site notice before the change takes effect, where required by law. Changes to this policy do not modify any signed Data Processing Addendum.

16. Contact Us

Privacy questions, requests, and appeals:

Qorban Consulting LLC 15011 Ambiance Way Franklin, TN 37067 privacy@qorbanconsulting.com +1 615-909-4725

We aim to acknowledge privacy inquiries within 5 business days and to respond to formal rights requests within 45 days.