Privacy Policy

Protecting Your Data, Earning Your Trust — UniBright Solutions

Effective Date

April 1, 2026

Last Updated

April 1, 2026

Website

unibrightsolutions.com

1
Introduction

UniBright Solutions ("we," "us," or "our") operates the website unibrightsolutions.com and provides digital marketing, web and mobile application development, and AI automation services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or engage with us in any capacity.

This policy applies to all users, clients, website visitors, and third parties who interact with our services, including but not limited to AI-powered marketing platforms, web development portals, and automated workflow systems.

Your Consent

By accessing our website or using our services, you consent to the data practices described in this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please discontinue use of our website and services immediately.

2
Information We Collect

2.1 Personal Information

We may collect personally identifiable information that you voluntarily provide to us, including but not limited to:

  • Full name, email address, phone number, and mailing address
  • Company name, job title, and professional contact details
  • Billing and payment information (credit card numbers, billing addresses)
  • Account credentials (usernames and encrypted passwords)
  • Social media handles and profile information
  • Government-issued identification (when required for identity verification)
  • Tax identification numbers (for contractor and vendor relationships)

2.2 Health and Protected Health Information (PHI)

HIPAA Business Associate

In the course of providing AI automation and digital services to healthcare clients, we may process Protected Health Information (PHI) as defined under HIPAA. We process PHI only as a Business Associate under a signed Business Associate Agreement (BAA) and in strict compliance with HIPAA regulations.

PHI processed may include:

  • Patient names, dates of birth, and contact information
  • Medical record numbers and health plan beneficiary numbers
  • Diagnosis codes, treatment records, and clinical notes
  • Insurance and billing information related to healthcare services
  • Any other information classified as PHI under 45 CFR §160.103

2.3 Non-Personal and Technical Information

We automatically collect certain technical information when you visit our website or use our services:

  • IP address, browser type, operating system, and device identifiers
  • Pages visited, time spent on pages, click patterns, and referral URLs
  • Cookies, pixel tags, web beacons, and similar tracking technologies
  • Geolocation data (approximate location based on IP)
  • Log files and server analytics data

2.4 Information from AI and Automation Services

When you use our AI automation solutions, we may collect:

  • Data inputs provided to AI models and workflow automation tools
  • Interaction logs with chatbots, virtual assistants, and automated systems
  • Performance metrics, model outputs, and error logs
  • Integration data from connected third-party platforms (CRM, ERP, etc.)
  • Document processing data including OCR outputs and extracted metadata

2.5 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Analytics providers (Google Analytics, Meta Pixel, etc.)
  • Advertising networks and marketing platforms
  • Social media platforms when you interact with our content
  • Public databases, credit reporting agencies, and data brokers
  • Client-provided data for marketing campaign execution

3
How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery & Client Management

  • Providing, operating, and improving our digital marketing, web development, and AI automation services
  • Processing transactions and managing client accounts and billing
  • Communicating service updates, project milestones, and deliverable notifications
  • Technical support and responding to client inquiries

Marketing & Business Development

  • Sending marketing communications and promotional materials (with opt-out available)
  • Personalizing content and user experience on our website
  • Running advertising campaigns on behalf of clients or for our own business
  • Analyzing campaign performance and optimizing marketing strategies

AI & Automation Operations

  • Training, testing, and improving AI models specific to client configurations
  • Operating automated lead generation, qualification, and outreach systems
  • Processing documents, conversations, and workflows on behalf of clients
  • Generating analytics, insights, and performance dashboards

Legal, Security & Compliance

  • Complying with applicable laws, regulations, and legal processes
  • Detecting, preventing, and addressing fraudulent, unauthorized, or illegal activity
  • Maintaining the security and integrity of our systems and services
  • Exercising or defending legal claims and rights

4
Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process personal data under the following lawful bases:

  • Contractual Necessity: Processing required to perform our services under a client agreement
  • Legitimate Interests: Business operations, fraud prevention, security monitoring, and service improvement
  • Consent: Marketing communications, cookies, and certain data processing activities where consent is obtained
  • Legal Obligation: Compliance with tax, financial, healthcare (HIPAA), and other regulatory requirements

Withdrawing Consent

Where we process data based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw consent, contact us at support@unibrightsolutions.com.

5
Your Data Rights

Depending on your location, you may have the following rights regarding your personal data:

Rights Available to All Users

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Data Portability: Receive your data in a structured, commonly used format

California Residents — CCPA Rights

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information (with exceptions for service operations)
  • Right to opt out of the sale of personal information (we do not sell personal data)
  • Right to non-discrimination for exercising CCPA rights

How to Exercise Your Rights

To submit a data rights request, email support@unibrightsolutions.com with the subject line "Data Rights Request." We will verify your identity and respond within 30 days (or 45 days for complex requests with written notice). There is no charge for submitting a request.

6
Cookies & Tracking Technologies

We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our website and to analyze performance.

Types of Cookies We Use

  • Essential Cookies: Required for website functionality and security. Cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics, with 26-month default retention).
  • Marketing Cookies: Used to deliver relevant ads and track campaign performance (e.g., Google Ads, Meta Pixel, LinkedIn Insight Tag).
  • Preference Cookies: Remember your settings and preferences for a personalized experience.

You can manage or disable cookies through your browser settings or via our cookie consent tool. Note that disabling certain cookies may affect the functionality of our website. For more information, visit allaboutcookies.org.

7
International Data Transfers

UniBright Solutions operates in the United States and may transfer your personal data to, or process it in, countries outside your jurisdiction — including countries that may have different data protection standards.

When we transfer data from the EEA, UK, or Switzerland to the United States or other countries, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Your explicit consent for specific transfers
  • Data processing agreements with all international sub-processors

Delivery Team (VJ Overseas — India)

Our delivery operations are supported by VJ Overseas, a contracted team based in India. All personnel are bound by confidentiality agreements and data processing terms consistent with GDPR and applicable privacy regulations. PHI and sensitive client data are handled in compliance with our BAA and least-privilege access controls.

8
Data Security

We implement industry-standard and enterprise-grade security measures to protect your information against unauthorized access, disclosure, alteration, and destruction.

  • SSL/TLS encryption for all data transmitted to and from our website
  • AES-256 encryption for sensitive data at rest
  • Regular security audits, penetration testing, and vulnerability assessments
  • Firewalls, intrusion detection systems, and DDoS protection
  • Employee background checks and ongoing security awareness training
  • Access controls based on the principle of least privilege
  • Secure software development lifecycle (SDLC) practices
  • Regular encrypted data backups with off-site storage

Security Limitations

While we strive to protect your personal information using industry best practices, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data. In the event of a data breach affecting your rights and freedoms, we will notify affected parties as required by applicable law.

9
Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements.

Data Category Retention Period Basis
Client project dataDuration of engagement + 3 yearsContract / Legitimate interests
Marketing analytics data26 monthsGoogle Analytics default alignment
Financial and billing records7 yearsTax compliance (IRS / GAAP)
Protected Health Information (PHI)Minimum 6 years from creation or last effective dateHIPAA 45 CFR §164.530(j) / BAA terms
Website server logs12 monthsSecurity monitoring
Cookie dataVaries by cookie typeSee Cookie Policy (Section 6)
Marketing email listsUntil unsubscription or 3 years of inactivityConsent / Legitimate interests
AI model training dataDuration of client engagement + 1 yearContract / Service improvement

Upon expiration of the applicable retention period, data is securely deleted using industry-standard data destruction methods or irreversibly anonymized so it can no longer be associated with an individual.

10
Third-Party Sharing and Disclosures

We do not sell your personal information. We may share your information with the following categories of third parties:

Service Providers & Technology Partners

Cloud hosting (AWS, Google Cloud), payment processors (Stripe), email platforms (Mailchimp, SendGrid), analytics tools, and CRM systems. All service providers are bound by data processing agreements and are required to maintain confidentiality and security standards consistent with this policy.

Advertising Partners

Google Ads, Meta/Facebook, LinkedIn, and other advertising networks for campaign execution on behalf of our clients or for our own marketing purposes. These partners may use cookies and tracking technologies subject to their own privacy policies.

Legal and Regulatory Disclosure

We may disclose your information when required by law, subpoena, court order, or government request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers

In connection with a merger, acquisition, restructuring, or sale of assets, your information may be transferred to successor entities. We will notify you of any such transfer and any choices you may have.

Client-Directed Sharing

When specifically instructed by clients for campaign or project requirements, we may share data on their behalf with designated third parties as part of contracted service delivery.

11
Children's Privacy

Our services are not directed to individuals under the age of 16 (or 13 where applicable under COPPA — the Children's Online Privacy Protection Act). We do not knowingly collect, maintain, or use personal information from children under these age thresholds.

If You Believe a Child Has Provided Data

If we learn that we have collected personal information from a child under the applicable age threshold, we will delete it promptly and take appropriate steps to prevent further collection. If you believe a child has provided us with personal information, please contact us immediately at admin@unibrightsolutions.com.

12
Changes to This Privacy Policy

We reserve the right to update or revise this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When changes are made:

  • The updated policy will be posted on this page with a revised "Last Updated" date
  • Material changes will be communicated via email to registered clients or users, or via a prominent notice on our website
  • For significant changes affecting your rights, we will seek renewed consent where required

Continued Use Constitutes Acceptance

Your continued use of our website or services after the posting of changes constitutes your acceptance of the revised Privacy Policy. If you do not agree to the updated terms, please discontinue use of our services and contact us to discuss your options.

13
Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

UniBright Solutions — Data & Privacy Contacts

Company
UniBright Solutions LLC
Data Protection & Privacy Inquiries
HIPAA Inquiries: For any matters related to Protected Health Information (PHI), Business Associate Agreements (BAAs), or HIPAA compliance, please mark your email with the subject line "HIPAA Inquiry" to ensure proper routing to our compliance team at support@unibrightsolutions.com.

We aim to respond to all privacy-related inquiries within 5 business days. For data rights requests (access, deletion, portability), we will respond within 30 days as required by applicable law.

UniBot

Digital Marketing Consultant