Privacy Policy
Effective Date: January 1, 2025
1) Scope
This policy explains how Socium IT, LLC ("Socium," "we," "us") handles personal information across:
- Website & marketing (sociumit.com, forms, cookies, email/SMS)
- SaaS/app experiences we host for our customers
- Vigilis implementation & managed services: when customers give us data to perform services, we act as their processor under a separate services agreement; this policy describes our general practices but your company's contract controls those engagements
2) What we collect
- Identifiers & contact: name, email, phone, company, job title, business address
- Account data (if you register): login, roles
- Commercial & contract data (Vigilis): invoices, contracts; limited employee info for user management
- Internet/technical: IP address, device/browser info, pages viewed, referrals, and interactions
- Communications: support tickets, emails, call/SMS logs (consent-based)
- Cookies & similar tech: used for analytics, site performance, and advertising/identity resolution (see §6)
3) Why we use data (business purposes)
- Provide and secure our site, products, and services
- Customer service and account administration
- Business operations, analytics, and product improvement
- Marketing (email/SMS/newsletters) with required opt-outs; advertising/retargeting where allowed
- Legal, security, fraud prevention
4) SMS & email marketing
- Email: every message includes one-click unsubscribe and our physical postal address. We maintain a suppression list for opt-outs.
- SMS: we send texts only with prior express written consent; messages include STOP to opt out and HELP for help. As of Jan 27, 2025, consent must be one-to-one (specific to Socium). Standard rates may apply.
5) How we share information
We do not sell your information in the common sense of the word. Some states define "sell" or "share" to include certain advertising and identity-resolution uses of cookies/hashed emails. We may disclose data to:
- Service providers/processors (hosting, CRM, analytics, ticketing, email/SMS)
- Advertising/identity resolution partners (see §6) where permitted
- Legal/security reasons (subpoenas, fraud, safety)
We disclose categories of third parties rather than an exhaustive vendor list. Examples we currently use: HubSpot (CRM/marketing), Google Analytics, Microsoft Clarity (session replay/heatmaps), Retention.com (identity resolution).
6) Cookies, analytics, ads, and identity resolution
- Analytics: We use Google Analytics to understand site traffic and performance.
- Session replay: We use Microsoft Clarity to record clicks, scrolls, and page performance to improve UX; Clarity masks designated fields.
- Identity resolution / targeted ads: We use Retention.com and similar tools that may associate your visit with your email for marketing. This may be considered "sale" or "sharing" under certain state laws. Use Your Privacy Choices to opt out; you can also use the vendor's opt-out.
- Your controls: Manage cookies in your browser and visit Your Privacy Choices – Do Not Sell/Share to opt out of sale/sharing/targeted advertising; we honor Global Privacy Control (GPC) and other recognized Universal Opt-Out Mechanisms.
7) Your privacy rights
Depending on your state, you may have rights to access, delete, correct, port, and to opt out of sale/sharing/targeted advertising and certain profiling.
- Submit requests via email at comms@sociumit.com
- We will verify your identity and respond within the required time (generally 45 days)
- If we deny your request, you may appeal by replying "Appeal" to your request confirmation email
Your Privacy Choices – Do Not Sell/Share: Contact us at comms@sociumit.com to opt out. We process browser GPC/UOOM signals as valid opt-outs.
8) Retention
We keep personal information only as long as necessary for the purposes above, then delete or de-identify it. Current schedule:
- Leads & marketing contacts: 24 months of inactivity
- Support tickets: 24 months after closure
- Product telemetry & web logs: 12 months rolling
- Contracts, invoices, and financial records: 7 years (accounting/legal)
If a fixed period isn't possible, we apply documented criteria (legal, security, and business needs).
9) Security
We use industry-standard safeguards (encryption in transit/at rest where applicable, 2FA for key systems, least-privilege access, vendor due diligence). No method is 100% secure.
10) Children
Our services are for business use; we do not knowingly collect data from children under 16 and we do not knowingly sell/share their information.
11) International
Data may be processed in the United States or other locations where our providers operate. We use appropriate safeguards for cross-border transfers where required.
12) Updates
We may update this policy; we'll post changes here and note the Effective Date.
13) Contact
Socium IT, LLC
Email: comms@sociumit.com
Website: sociumit.com
