Commteck

Privacy

What we collect, and why

Written to be read rather than skimmed. If anything here is unclear, ask us and we will explain it in plain English.

Last reviewed 5 October 2026

Who we are

Commteck (“we”) provides managed IT, cybersecurity and compliance support to businesses in Utah. This notice covers commteck.net — this website, the forms on it, and the assistant — and the enquiries those forms send us.

It does not cover data we hold on behalf of a client practice. That is governed by your services agreement and, where protected health information could be involved, by the Business Associate Agreement we sign with you. Our security page describes how that boundary is drawn.

What we collect

Three things, and only three:

  • What you type in. Your practice or company name, your name, work e-mail, phone number, state, the services you picked, the answers you gave, the message you wrote, and your consent choice.
  • What your browser sends with it. An anonymous visitor id we generate and keep in your browser, the page the form was sent from, and — when you arrived from an ad or another website — the campaign parameters or referring URL that brought you here.
  • What our server sees. The request itself: IP address and browser string, kept with the submission. We use it to rate-limit abuse and to screen spam.

Please do not send us patient information through this website. The forms and the assistant are for business enquiries, not medical records. If you need to discuss a clinical system, tell us and we will set up a proper channel with a Business Associate Agreement in place first.

Cookies, storage and analytics

We do not run advertising on this site, and we set no advertising cookies. No analytics or marketing tag loads before you accept the notice — the scripts are only added to the page once you press Accept analytics, and Google Consent Mode starts with every storage signal denied.

What is in your browser today

Three values in your browser's local storage. None of them identifies you by name and none is readable by another website:

Values this website stores in your browser
KeyWhat it holds
ct-cookie-consentYour answer to the cookie notice — "granted" or "denied".
commteck_visitor_idA random id we generate so a form you send can be tied to the visit that brought you here. It is not a name, not a login, and we share it with no advertising network.
commteck_attributionThe campaign parameters we saw on your first page view (utm_source, gclid and similar) or the referring site, so an enquiry can be credited to the ad or source that produced it.

If you accept analytics

We then load Google Analytics 4 (pages viewed, how you moved through the site — IP anonymised for us) and Microsoft Clarity (heatmaps and session replays of how pages are used). Those tools set their own cookies — _ga and _ga_<id> from Google, _clck and _clsk from Clarity — and their own retention settings apply to what they store.

If you decline, neither tool is loaded and Clarity is told not to store anything, so nothing about your visit is recorded beyond the anonymous form attribution above.

Changed your mind? Analytics is a choice, not a default, and you can reverse it whenever you like: reopen the notice with the button below, or with the Cookie settings link in the footer. Clearing your browser's site data has the same effect — the notice will simply ask again.

Who else sees it

We do not sell personal data, and we do not share it for anyone else's advertising. We use the following services to run this site and answer enquiries:

Service providers that can see part of what this website collects
ServiceUsed forWhat it can see
Microsoft 365 / Exchange OnlineMail and calendarThe enquiries we receive at our own mailboxes — your name, e-mail address, phone number and message.
DigitalOceanHostingThe server this site and our CRM run on, including the enquiry records described above.
CalendlyAppointment bookingOnly if you book a time yourself: your name, e-mail address, phone number and the slot you chose.
Google Analytics 4Website analyticsPage views and how you moved through the site. Loaded only after you accept the notice; IP addresses are anonymised for us.
Microsoft ClarityWebsite analyticsHeatmaps and session replays of how pages are used. Loaded only after you accept the notice.
OpenAIWebsite assistant and lead summariesWhatever is typed into the assistant or a form. That is why the assistant tells you not to include patient or medical information.
Encrypted offsite backup storageBackup copiesOnly encrypted archives. The decryption key stays with us, on equipment we control.

Where we hold data on a client's behalf, the list also records which providers are covered by a Business Associate Agreement and which are not, and the answer is not always yes — we name the exceptions rather than implying coverage we do not have. Ask us and we will send you the current list and its agreement status.

How long we keep it

We keep data for as short a time as it is useful, and the purge runs on a schedule rather than when someone remembers:

How long each kind of data is kept
DataKept for
Website analytics pings180 days
Anonymous visit records (source, landing page)180 days
Assistant transcripts you typed365 days
Your enquiry and the quote trail that followed it3 years
Internal audit trail (logins, approvals, sends)2 years
A request to stop contacting youKept indefinitely — see “Your choices”

Backups are kept for 30 days (daily copies) and 84 days (weekly copies). They are encrypted before they leave our server and are not edited afterwards, so if you ask us to delete your data a copy can remain in a backup for up to 30 days before it rotates out.

Your choices and requests

Write to helpdesk@commteck.net and ask, in whatever words you like, for any of the following. We do not ask you to fill in a form to exercise them.

  • A copy of what we hold about you. We will send what our records contain for your name, e-mail address and phone number.
  • A correction. Tell us what is wrong and we will fix it.
  • Deletion. We delete your e-mail address and phone number, anonymise the contact record, redact the wording you typed into the website, and create an opt-out so nothing ever contacts you again. One thing survives: the record that you asked us to stop. Deleting that would mean we could contact you again by mistake, so we keep it permanently — and we would rather tell you that plainly than quietly keep more.
  • To stop hearing from us. A marketing opt-out is honoured immediately and permanently, and it applies even if you asked to be deleted.

Depending on where you live you may have further rights by law — for instance over marketing or the sale of personal information. We do not sell personal information at all, but if you make a request we will honour it as far as we are able and tell you if we cannot.

How we protect it

In transit everything is TLS. Internally the safeguards are the ones an IT provider ought to hold itself to: least-privilege admin access, multi-factor authentication on everything an administrator touches, an audit trail of logins, approvals and sends, nightly encrypted backups stored off our own server with a rehearsed restore, and a written incident-response procedure.

Our security page sets out what is tested, and — just as importantly — what we do not yet claim.

Children

This site is for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us something through this website, write to us and we will delete it.

Changes to this notice

We update the wording when our practices change and move the last reviewed date at the top of this page with it. If a change would materially affect what we do with your data, we will say so here rather than burying it.

Contact

Questions about privacy, or a request under the section above, go to helpdesk@commteck.net. You can also use the contact form; the same caveat applies — please do not include patient or medical information.

Read alongside: Terms of Service · Security · Accessibility