1. Introduction and Scope
Acute Behavior Academy LLC respects the privacy of every person who visits this website, contacts our intake team, enrols in a training cohort or engages us for systems work. This Privacy Policy explains what information we collect, why we collect it, how we use it, who we share it with and what choices you have. It applies to the website located at acutebehavior.mom and to every service described on it, including behavior technician training, systems integration delivery, data collection platforms, custom software builds, progress analytics dashboards and managed IT support.
This Policy is written for a general audience. It covers visitors, prospective trainees, enrolled trainees, staff of partner organisations, clients and the individuals whose records may be processed inside systems we build or support. Where a client provides us with information about the learners they serve, that client remains responsible for obtaining the consents and permissions required in its own jurisdiction, and we act according to the written instructions we receive.
By using this website or engaging our services, you acknowledge that you have read this Privacy Policy. If you do not agree with the practices described here, please contact us before using the site or submitting any information. This Policy does not create rights beyond those granted by applicable law, and it does not override any stricter obligation imposed on us by a client contract or by professional standards that govern behavior analysis practice.
2. Who We Are and Our Roles
Acute Behavior Academy LLC is a limited liability company organised in the United States and located at 191 E 200 N, Providence - 84332-9607, United States (US). We operate as an academy and as a computer integrated systems design practice. Depending on the activity, we may act as a controller that determines the purposes and means of processing, or as a processor that handles information on behalf of a client under written instruction.
When you browse this website, request information or apply to a training cohort, we act as a controller. When we host, integrate or support a clinical or operational system for a client, that client is generally the controller and we are the processor. When we build a custom platform that a client will operate independently after handover, the client becomes the controller of the data placed in that platform once it is live. We describe these distinctions so that you know whom to approach with a request, and we help route requests to the correct party whenever we can.
Our registered place of business and our principal point of contact for privacy matters are the same address and email shown throughout this Policy. A named privacy contact can be reached using the details in the final section.
3. Information We Collect
We collect several categories of information, and we try to limit each category to what is genuinely needed for the purpose it serves. The categories are described below so that you can recognise what may apply to you.
Identity and contact information
This includes names, job titles, organisation names, email addresses, telephone numbers and postal addresses. We collect it when you complete an enquiry form, correspond with intake, register for a cohort or enter into a service agreement.
Training and enrolment information
This includes attendance records, assessment scores, fidelity checklist results, practice logs, supervisor notes and the progress milestones a trainee reaches during a programme. We keep this information so that we can verify competence and issue a training record.
Technical and usage information
This includes internet protocol addresses, browser type, device category, operating system, referring pages, pages viewed and the dates and times of visits. We use this information to keep the website available, secure and reasonably fast.
Communications content
This includes the content of emails, form submissions, notes of telephone conversations and any attachments you choose to send. We retain correspondence so that we can answer questions consistently and maintain an accurate service history.
Operational and system information
In the course of integration and support work, we may process configuration details, field mappings, log files, error reports, access records and similar operational metadata. This information describes how systems behave rather than what any individual person did.
We do not intentionally collect special category information through this website. We ask that visitors do not submit health details, government identifiers or other sensitive information through the public enquiry form. Where sensitive information is necessary for a service engagement, we collect it through a controlled channel with appropriate safeguards and clear instructions.
4. How We Obtain Information
We obtain information directly from you when you submit a form, send an email, call our office or participate in a training session. We also obtain information automatically from your device when you use the website, through standard server logging and the limited technologies described in the cookies section.
We may receive information from a client organisation that engages us, for example when a partner provides a roster of trainees or grants access to a system we will integrate or support. We may also receive information from a supervisor, instructor or authorised colleague who corresponds with us about a programme. In every case where we receive information from another party, we expect that party to have the authority to share it and to have provided any notice that law requires.
5. Purposes of Processing
We process information for a defined set of purposes. We deliver training and assess trainee competence. We respond to enquiries and prepare proposals. We perform integration, build and support work under contract. We operate, secure and improve this website. We maintain business records, issue invoices and meet accounting obligations. We detect and prevent fraud, misuse and unauthorised access. We comply with legal, regulatory and professional requirements. We communicate service updates and, where permitted, information that we believe is relevant to your interests.
Where we wish to use information for a purpose that is new and unrelated to those listed above, we will provide notice before doing so, or seek consent where consent is the appropriate basis.
6. Lawful Bases for Processing
Where data protection law requires a lawful basis, we rely on one or more of the following. We process information to perform a contract with you or to take steps at your request before entering a contract. We process information for our legitimate interests in operating an academy and a systems practice, provided those interests are not outweighed by your rights. We process information to comply with legal obligations, including record keeping and tax requirements. We rely on consent where we have asked for it specifically, and you may withdraw that consent at any time without affecting processing that already occurred.
Where we process information that relates to health or another sensitive category as part of a managed service, we do so under the instruction of the responsible client and the legal basis that client has established, together with the contractual protections described in this Policy.
7. Clinical and Learner Records
Some of the systems we build or support hold records about learners who receive behavior analysis services. We treat that category of information with particular care. Access is restricted to staff who require it for a defined task, and access is logged wherever the platform allows. We do not use learner records for our own marketing, we do not sell them, and we do not disclose them except as the responsible client instructs in writing or as law compels.
Where we design a data collection platform, we build in safeguards such as role based access, versioned edits, attribution of every entry and validation that rejects impossible values. These measures protect the integrity of the clinical record as well as the privacy of the person described in it. Where a client asks us to de-identify information before use in analysis or testing, we apply documented de-identification steps and confirm the result before proceeding.
If you are a learner or a family member seeking access to, correction of or deletion of a record held by one of our clients, please raise the request with that organisation first. If you contact us, we will help identify the responsible party and pass the request along without unnecessary delay.
10. Service Providers and Subprocessors
We engage a small number of trusted providers to run our operations. These providers may include cloud hosting, email and collaboration platforms, accounting software and security monitoring tools. Each provider is bound by a written agreement that requires confidentiality, appropriate security and use of information only for the purpose we specify.
Where a client engagement requires a specific provider, we will name that provider in the engagement documents. If we need to add a subprocessor that will handle client information, we will give notice as the client contract requires and provide an opportunity to object where that right exists. We review our provider list periodically and remove any provider that no longer meets our standards.
11. International Data Transfers
Our operations are based in the United States. If you contact us from another country, your information will be processed in the United States, where privacy law may differ from the law of your home jurisdiction. Where we transfer information out of a jurisdiction that restricts such transfers, we use the safeguards that law provides, such as standard contractual clauses or an equivalent mechanism.
Where a client requires information to remain in a particular region, we will document that requirement during intake and configure hosting accordingly. We encourage clients with regional obligations to raise them early so that architecture decisions can respect them from the first day of a project.
12. Data Retention
We keep information only as long as it is needed for the purpose that justified its collection, or as long as law or a client contract requires. Enquiry correspondence is generally retained for a reasonable period so that we can follow up and maintain a service history. Training records are retained for a longer period so that competence can be verified after a programme ends. Billing and tax records are retained for the period required by accounting law.
When a retention period ends, we delete or de-identify the information using methods appropriate to its format and sensitivity. Where information is held on behalf of a client, we follow the retention schedule in the client contract and return or delete the information at the end of the engagement as instructed.
13. Security Measures
We protect information with a combination of technical, organisational and physical measures. These include access controls based on role, encryption of data in transit, encryption of data at rest where the platform supports it, logging of administrative actions, regular review of accounts and prompt removal of access when a person leaves a role. We harden the devices and endpoints we control and we apply updates on a planned schedule.
We also rely on good practice by the people who use our systems. We train staff on confidentiality and on recognising attempts to obtain information through deception. No security programme can guarantee absolute protection, so we combine preventive controls with detection, backup and recovery so that we can respond effectively if an incident occurs. We test our backups by restoring them, because an untested backup is an assumption rather than a safeguard.
14. Your Privacy Rights
Depending on where you live, you may have the right to request access to the information we hold about you, to request correction of information that is inaccurate, to request deletion of information we no longer need, to request restriction of certain processing, to object to processing based on legitimate interests and to request portability of information you provided to us. You may also have the right to withdraw consent where consent was the basis for processing and the right to lodge a complaint with a supervisory authority.
To exercise a right, contact us using the details in the final section or email intake@acutebehavior.mom. We will respond within the time allowed by applicable law, generally within thirty days. We may need to verify your identity before acting, and we may need to redirect a request to a client organisation where that client is the controller. We will explain any such step clearly and will not charge a fee unless the law permits one and the request is manifestly unfounded or excessive.
15. Privacy for Children
This website is intended for professional and adult audiences. We do not knowingly collect personal information through this website from children. Where our services involve children, that involvement occurs in the context of a client programme, under the authority of the responsible organisation and with the consents that law and professional standards require.
If you believe that a child has provided personal information to us through this website, please contact us so that we can investigate and delete the information promptly. Parents and guardians who wish to understand how a particular programme handles a learner record should contact the organisation that operates that programme, and we will assist that organisation in responding.
16. Marketing and Communications
We send service communications that are necessary to deliver a service, such as scheduling notes, assessment outcomes and platform notices. These communications are part of the service and are not optional while an engagement is active. We send promotional communications only where we have a lawful basis to do so, and every promotional message includes a clear way to opt out.
If you no longer wish to receive promotional email from us, you can use the unsubscribe link in the message or write to intake@acutebehavior.mom. We will honour the request promptly and will keep a minimal record of the preference so that we do not contact you again in error.
17. Automated Decision Making
We do not make decisions that produce legal or similarly significant effects about individuals through automated processing alone. Some systems we build include scoring or flagging features, such as fidelity scoring or plateau detection. These features support human judgement; they do not replace it. A qualified person reviews any result that could affect a learner, a trainee or a client before a decision is taken.
If a future engagement were to involve automated decision making, we would describe it in the engagement documents, explain the logic in plain language and provide a route to request human review.
18. Third Party Websites
This website may link to websites operated by other organisations. We do not control those websites and we are not responsible for their privacy practices. When you follow a link away from our site, we encourage you to read the privacy notice of the destination site before providing any information.
A link from our website does not imply that we endorse the content, products or practices of the destination. We include links only where we believe they are useful to our visitors, and we remove them if we learn that a destination has become unreliable or unsafe.
19. Incident Response and Notification
We maintain an incident response process that covers detection, containment, assessment, notification and review. If we become aware of a breach affecting information we control, we will investigate promptly, take steps to limit harm and notify affected individuals and authorities where law requires. If we become aware of a breach affecting information we process for a client, we will notify that client without undue delay so that the client can meet its own obligations.
After an incident we conduct a review to identify the cause and to strengthen the controls that failed. We document what we learn and we share relevant findings with affected clients, because the purpose of an incident review is to reduce the chance of a repeat rather than to assign blame.
20. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in technology or in the law. When we make a material change, we will revise the effective date at the top of the page and, where appropriate, provide a more prominent notice on the website or by email.
We encourage you to review this page periodically so that you remain aware of how we protect information. Continued use of the website after an update takes effect indicates that you accept the revised Policy, to the extent that acceptance is the appropriate legal mechanism.
21. How to Contact Us
If you have a question about this Privacy Policy, wish to exercise a privacy right or need to report a concern, please contact Acute Behavior Academy LLC at the details below. We take every privacy enquiry seriously and we aim to respond within one business day.
Company: Acute Behavior Academy LLC
Address: 191 E 200 N, Providence - 84332-9607, United States (US)
Email: intake@acutebehavior.mom
Phone: +19146269296
If you are not satisfied with our response, you may have the right to complain to the data protection authority in your jurisdiction. We will cooperate fully with any such authority and will provide the information it needs to review the matter.