1. Data Lifecycle
- Capture. Consumers submit information on a proprietary or partner landing page after reviewing the express opt-in disclosure identifying Powerful Proximity Consulting and its marketing partners.
- Verification. The record is tokenized with TrustedForm and/or Jornaya LeadiD, IP address, timestamp, and source URL. Records that fail verification are rejected.
- Storage. Records are stored in access-controlled databases in the United States. Consent artifacts are linked one-to-one with the underlying record.
- Delivery. Records are delivered to licensed clients via TLS-secured API, ping-post, or SFTP under a signed insertion order.
- Retention. Records are retained for up to five (5) years for delivery, dispute, and regulatory purposes, then purged from active systems.
2. Technical Safeguards
- TLS 1.2 or higher for all client-facing endpoints.
- Role-based access control (RBAC) with unique administrator credentials.
- Segregated production, staging, and analytics environments.
- Monitored logging on data-access endpoints.
- Regular review of vendor security posture and access logs.
3. Administrative Safeguards
- Written data-handling policies and mandatory personnel training on TCPA, CCPA, and DNC obligations.
- Confidentiality obligations for all employees and contractors.
- Named compliance point of contact reachable via our contact form.
4. Subprocessors
We engage a limited set of subprocessors to operate the Services, including cloud infrastructure providers, consent-verification vendors (ActiveProspect / TrustedForm, Jornaya), telecommunications providers, and CRM platforms. Each subprocessor is bound by written data-protection terms. A current list is available on request through our contact form.
5. Consumer Rights Handling
Consumers may exercise access, correction, deletion, and opt-out rights by submitting a request through our contact form. We verify the identity of the requester and respond within the timeframes required by applicable law (typically 45 days for CCPA/CPRA and 30 days for GDPR). Deletion propagates to active systems within 30 days of verification; consent artifacts required for legal recordkeeping may be retained in an archival state.
6. Do Not Call and Do Not Contact
We maintain an internal Do Not Contact list scoped across our data programs. Consumers may add themselves by submitting a request through our contact form with the subject "DO NOT CONTACT" and listing the phone numbers and email addresses to suppress. Suppression takes effect within 10 business days.
7. Incident Response
In the event of a suspected security incident affecting consumer information, we will investigate promptly, contain the incident, and notify affected clients and, where required, regulators and consumers within the timeframes required by applicable breach-notification law. Security requests may be submitted through our contact form.
8. Client Obligations
Data protection is a shared responsibility. Clients that receive our records must maintain their own reasonable safeguards, honor consumer opt-out requests, and comply with all applicable laws governing outreach to consumers.
9. International Transfers
Our Services are operated from the United States. Consumers submitting information from outside the United States acknowledge that their information will be transferred to and processed in the United States.
10. Contact
For data-protection questions or requests, please use our contact form.
This page is maintained by Powerful Proximity Consulting to answer common data-protection questions. It describes current practices and enabled controls; it is not an independent certification or audit report. Specific regulatory obligations should be reviewed with qualified counsel.
