Privacy
What we collect, and why
Written to be read rather than skimmed. If anything here is unclear, ask us and we will explain it in plain English.
Last reviewed 5 October 2026
Who we are
Commteck (“we”) provides managed IT, cybersecurity and compliance support to businesses in Utah. This notice covers commteck.net — this website, the forms on it, and the assistant — and the enquiries those forms send us.
It does not cover data we hold on behalf of a client practice. That is governed by your services agreement and, where protected health information could be involved, by the Business Associate Agreement we sign with you. Our security page describes how that boundary is drawn.
What we collect
Three things, and only three:
- What you type in. Your practice or company name, your name, work e-mail, phone number, state, the services you picked, the answers you gave, the message you wrote, and your consent choice.
- What your browser sends with it. An anonymous visitor id we generate and keep in your browser, the page the form was sent from, and — when you arrived from an ad or another website — the campaign parameters or referring URL that brought you here.
- What our server sees. The request itself: IP address and browser string, kept with the submission. We use it to rate-limit abuse and to screen spam.
Please do not send us patient information through this website. The forms and the assistant are for business enquiries, not medical records. If you need to discuss a clinical system, tell us and we will set up a proper channel with a Business Associate Agreement in place first.
Who else sees it
We do not sell personal data, and we do not share it for anyone else's advertising. We use the following services to run this site and answer enquiries:
| Service | Used for | What it can see |
|---|---|---|
| Microsoft 365 / Exchange Online | Mail and calendar | The enquiries we receive at our own mailboxes — your name, e-mail address, phone number and message. |
| DigitalOcean | Hosting | The server this site and our CRM run on, including the enquiry records described above. |
| Calendly | Appointment booking | Only if you book a time yourself: your name, e-mail address, phone number and the slot you chose. |
| Google Analytics 4 | Website analytics | Page views and how you moved through the site. Loaded only after you accept the notice; IP addresses are anonymised for us. |
| Microsoft Clarity | Website analytics | Heatmaps and session replays of how pages are used. Loaded only after you accept the notice. |
| OpenAI | Website assistant and lead summaries | Whatever is typed into the assistant or a form. That is why the assistant tells you not to include patient or medical information. |
| Encrypted offsite backup storage | Backup copies | Only encrypted archives. The decryption key stays with us, on equipment we control. |
Where we hold data on a client's behalf, the list also records which providers are covered by a Business Associate Agreement and which are not, and the answer is not always yes — we name the exceptions rather than implying coverage we do not have. Ask us and we will send you the current list and its agreement status.
How long we keep it
We keep data for as short a time as it is useful, and the purge runs on a schedule rather than when someone remembers:
| Data | Kept for |
|---|---|
| Website analytics pings | 180 days |
| Anonymous visit records (source, landing page) | 180 days |
| Assistant transcripts you typed | 365 days |
| Your enquiry and the quote trail that followed it | 3 years |
| Internal audit trail (logins, approvals, sends) | 2 years |
| A request to stop contacting you | Kept indefinitely — see “Your choices” |
Backups are kept for 30 days (daily copies) and 84 days (weekly copies). They are encrypted before they leave our server and are not edited afterwards, so if you ask us to delete your data a copy can remain in a backup for up to 30 days before it rotates out.
Your choices and requests
Write to helpdesk@commteck.net and ask, in whatever words you like, for any of the following. We do not ask you to fill in a form to exercise them.
- A copy of what we hold about you. We will send what our records contain for your name, e-mail address and phone number.
- A correction. Tell us what is wrong and we will fix it.
- Deletion. We delete your e-mail address and phone number, anonymise the contact record, redact the wording you typed into the website, and create an opt-out so nothing ever contacts you again. One thing survives: the record that you asked us to stop. Deleting that would mean we could contact you again by mistake, so we keep it permanently — and we would rather tell you that plainly than quietly keep more.
- To stop hearing from us. A marketing opt-out is honoured immediately and permanently, and it applies even if you asked to be deleted.
Depending on where you live you may have further rights by law — for instance over marketing or the sale of personal information. We do not sell personal information at all, but if you make a request we will honour it as far as we are able and tell you if we cannot.
How we protect it
In transit everything is TLS. Internally the safeguards are the ones an IT provider ought to hold itself to: least-privilege admin access, multi-factor authentication on everything an administrator touches, an audit trail of logins, approvals and sends, nightly encrypted backups stored off our own server with a rehearsed restore, and a written incident-response procedure.
Our security page sets out what is tested, and — just as importantly — what we do not yet claim.
Children
This site is for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us something through this website, write to us and we will delete it.
Changes to this notice
We update the wording when our practices change and move the last reviewed date at the top of this page with it. If a change would materially affect what we do with your data, we will say so here rather than burying it.
Contact
Questions about privacy, or a request under the section above, go to helpdesk@commteck.net. You can also use the contact form; the same caveat applies — please do not include patient or medical information.
Read alongside: Terms of Service · Security · Accessibility
