Privacy Policy
This Privacy Policy explains how Solutions Plus Consulting, Inc. (“SPCI,” “Solutions Plus,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with our websites and our SPAI Platform.
On this page
- What This Policy Covers
- Our Data & Our Customers’ Data
- Information We Collect
- How We Use Information
- How We Share Information
- Cookies & Local Storage
- Service Providers (Subprocessors)
- Artificial Intelligence
- Data Retention & Security
- International Data Transfers
- Your Privacy Rights
- Children’s Privacy
- Changes to This Policy
- Contact Us
- Changes in This Version
1. What This Policy Covers
This Privacy Policy applies to:
- Our websites — solutionsplus.ai, solutionsplusconsulting.com, and SPCReports.com (the “Sites”), our public marketing and informational pages, including the report subscription features of SPCReports.com; and
- The SPAI Platform — our hosted software applications and related services, available at subdomains of solutionsplus.ai (for example insights.solutionsplus.ai and login.solutionsplus.ai) (the “Platform,” and together with the Sites, the “Services”).
By using the Services, you acknowledge the practices described in this Privacy Policy. If you do not agree with it, please do not use the Services.
2. Two Kinds of Data: Our Data and Our Customers’ Data
The Platform is business software used by organizations (“Customers”) under a master services agreement, order form, and/or data processing agreement (together, “Customer Agreements”). That creates two distinct roles, and this policy is explicit about which applies where:
- Where we are the controller. We decide how and why to process: information about visitors to the Sites; information about prospective customers; account and usage information about the individuals who sign in to the Platform (identity, sessions, security logs, support records); and billing/relationship records. Sections 3–12 of this policy govern that processing.
- Where we are a processor (service provider). Customer Content — the business data a Customer connects to or stores in the Platform, such as records, documents, digital assets, and report data drawn from the Customer’s own systems (for example their Aprimo or Microsoft 365 environments) — is processed on the Customer’s behalf and under the Customer’s instructions, as set out in the Customer Agreements. The Customer is the controller of Customer Content; their privacy notices govern it. If you have questions or requests about Customer Content (including access or deletion), direct them to the organization that provided your access; we support Customers in fulfilling such requests.
Where this policy describes Customer Content below (for example in the security section), it does so to explain our safeguards, not to claim controller rights over that data.
3. Information We Collect
On the Sites
- Information you provide — when you fill out a form, schedule a meeting, or contact us: your name, business email address, phone number, company name, job title, and the content of your message. Our contact forms and meeting scheduler are powered by HubSpot, acting as our service provider.
- Collected automatically — standard web log information generated by our hosting infrastructure: IP address and approximate location derived from it, browser and device type, pages viewed, referring pages, and timestamps. The Sites are static websites on Microsoft Azure; this information comes from the hosting and networking infrastructure in the ordinary course of serving pages, not from a dedicated analytics product.
On the Platform
- Account and identity information — when your organization gives you access, we process the identity your organization’s sign-in system asserts about you. Depending on how your organization connects, that may include: your name and business email address; your username or login identifier in your organization’s systems (for example an Aprimo login id); a stable user identifier issued by that system; your organization (tenant) membership; and the applications and roles you are entitled to.
- Authentication and session data — sign-in events, session identifiers and their validity windows, and the security tokens needed to keep you signed in (see the cookies section for exactly what is stored in your browser).
- Usage, log, and diagnostic data — server request logs and application telemetry (timestamps, request paths, response codes, IP addresses, and correlation identifiers), plus security audit events such as failed or refused sign-ins and session validations. Audit and diagnostic logs record event metadata; they are designed never to contain passwords, security tokens, or secret values.
- Registration information — if your organization registers for the Platform through our self-service flow, we collect the business contact details of the person registering, the organization’s system identifiers needed to connect (for example an Aprimo environment address), and the integration credentials your organization creates for the connection. Integration credentials are stored in a hardened secrets vault, are write-only from the application’s perspective, and are never displayed back, logged, or included in support communications.
- Preferences — interface settings you choose, such as light/dark theme, your selected workspace or tenant, and saved view layouts. These are stored in your browser and/or your account profile.
- Email delivery data — if your organization subscribes to scheduled reports or alerts, we process the recipient email addresses your organization configures and the delivery metadata (sent/delivered/bounced events) returned by our email delivery provider.
- Support and communications — the content of support requests and business correspondence.
We do not collect special categories of personal data (such as health, biometric, or precise geolocation data) through the Services, and we ask that you not submit such data through our forms.
4. How We Use Information
- To provide the Services — authenticate you, maintain your session, resolve your organization and entitlements, render dashboards and reports, deliver subscribed reports and alerts, and remember your preferences;
- To secure the Services — detect, investigate, and prevent unauthorized access, abuse, and fraud; enforce tenant isolation; and maintain audit trails of security-relevant events;
- To operate and improve — diagnose technical issues, understand usage at an aggregate level, and improve reliability and performance;
- To respond to you — answer inquiries, schedule meetings and demos, and provide support;
- To communicate — send service communications (for example scheduled reports your organization configured, or notices about the Services) and, separately, marketing communications you can opt out of at any time;
- To comply with legal obligations — accounting, tax, regulatory, and legal requirements, and establishing, exercising, or defending legal claims.
We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not use Customer Content for advertising or sell it to anyone.
7. Service Providers (Subprocessors)
We use the following categories of providers to operate the Services:
- Microsoft Azure — cloud hosting for all Services: web hosting, application compute, databases, file storage, secrets management, and logging/telemetry. Production infrastructure is hosted in United States Azure regions.
- Microsoft Power BI — embedded analytics and report rendering inside the Platform.
- Microsoft Azure OpenAI Service — powers optional AI features (see Section 8).
- Twilio SendGrid — delivery of Platform emails such as scheduled reports and alerts, including processing of delivery/bounce events.
- HubSpot, Inc. — CRM, contact form, and meeting scheduling for the Sites.
- Abuse-prevention services — we may use bot-detection or rate-limiting services (for example a CAPTCHA) on public forms such as self-service registration.
Where the Platform connects to systems your organization controls — such as your Aprimo environment or Microsoft 365 tenant — we access those systems as your organization’s service provider, using credentials and authorization your organization grants, and your organization’s own agreements with those vendors govern the data held there.
8. Artificial Intelligence
AI features in the Platform. Some Platform features use large language models via the Microsoft Azure OpenAI Service (for example, assistant and data-extraction features). When you use these features, the content you submit to them and the generated output are processed by that service within our Azure environment. Prompts and outputs are not used to train the underlying models, and these features are used to assist you — outputs are presented for human review, not to make automated decisions with legal or similarly significant effects.
AI in how we build and deliver services. AI tools may also assist our team in building and delivering the Services. Our standards distinguish two tiers of use:
- Productivity use. AI tools that support our internal work — such as code analysis, development efficiency, research, and technical documentation — are never given customer confidential information or Customer Content.
- Engagement-authorized use. Where an engagement calls for AI tools to process a customer’s data — for example, to build, update, or troubleshoot reports, which can require analyzing the data within them — that processing occurs only with the customer’s prior written authorization, only within approved environments covered by our contractual and security obligations to that customer, and the customer’s data is never used to train AI models. The specific tools, environments, and safeguards involved are described to the customer as part of that authorization.
In every case, AI remains a supporting resource: all deliverables — including reports generated or modified with AI assistance — are reviewed, validated, and tested by our professionals before delivery, and SPCI retains full responsibility for the quality, accuracy, and performance of all work product.
9. Data Retention & Security
Retention. We retain personal information for as long as reasonably necessary for the purposes described above: account information for the life of the Customer relationship; security and diagnostic logs for a bounded operational window; contact and CRM records for the duration of our prospective or ongoing business relationship; and Customer Content for as long as the Customer Agreements provide, after which it is returned or deleted in accordance with those agreements — and in all cases, customer data is destroyed within 30 days of a valid written destruction request, per our data destruction policy. We delete or anonymize sooner upon a valid request where no legal obligation requires retention.
Security. The Platform is built for security-sensitive industries, and we apply safeguards that include:
- Tenant isolation — each Customer’s data is stored in its own dedicated database, and each Customer’s integration secrets are stored in a dedicated secrets vault; every data request is scoped server-side to the requesting user’s organization;
- Encryption — all traffic is encrypted in transit (HTTPS/TLS); data is encrypted at rest by the hosting platform, and delivered report archives are additionally encrypted at the application layer;
- Credential handling — integration credentials and signing keys live in hardened secrets vaults with least-privilege access; secrets are write-only from the application’s perspective and are excluded from logs, responses, and error messages by design;
- Access control and audit — authentication is enforced at the API layer on every request (deny by default); security-relevant events are logged; and administrative access is limited and reviewed;
- US hosting — production systems run in United States Azure regions.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify affected parties as required by law and by the Customer Agreements.
10. International Data Transfers
SPCI is based in the United States, and the Services are hosted there. If you use the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and any other countries where our service providers operate. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to support these transfers.
11. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal information. We honor applicable rights requests regardless of where you are located, subject to identity verification and legal exceptions.
- EEA, United Kingdom, and Switzerland (GDPR/UK GDPR). You may have the right to access, correct, or erase your personal information; to restrict or object to certain processing; to portability; and to lodge a complaint with your supervisory authority. Our legal bases are: performance of a contract (providing the Platform to you and your organization); legitimate interests (operating, securing, and improving the Services, and following up on business inquiries); consent (where you submit a contact request or opt in to marketing); and legal obligation.
- California (CCPA/CPRA). California residents may have the right to know, delete, and correct personal information, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioral advertising. The categories we collect are: identifiers (name, email, phone, IP address, usernames and account identifiers); professional information (company, job title); commercial information (business relationship records); internet activity (usage and log data described above); and inferences limited to routine CRM record-keeping.
- Platform users. If your access to the Platform was provided by your organization, requests concerning Customer Content — and account information your organization controls — should be directed to your organization’s administrator; we will support your organization in responding, as the Customer Agreements provide.
To exercise a right, contact us as described in Section 14. We will verify your request and respond within the time required by applicable law. Authorized agents may submit requests on your behalf where the law provides.
12. Children’s Privacy
The Services are business tools, are not directed to children, and we do not knowingly collect personal information from anyone under the age of sixteen. If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL with a new “Last updated” date and, for material changes affecting Platform users, provide notice through the Services or to Customer administrators. Your continued use of the Services after an update constitutes acknowledgment of the revised policy.
14. Contact Us
We have appointed a Data Privacy Director responsible for overseeing questions and concerns about this Privacy Policy and our privacy practices.
Questions, concerns, or rights requests: privacy@solutionsplusconsulting.com
If you are a Platform user, please include the name of your organization so we can route your request correctly (and, for Customer Content, involve your organization as controller).
15. Changes in This Version
Version 2.0 (August 6, 2026) expanded this policy to cover the SPAI Platform in addition to our websites. Specifically, it:
- Added the SPAI Platform (applications at subdomains of solutionsplus.ai) to the policy’s scope, alongside the Sites;
- Added the distinction between data we control and Customer Content we process on Customers’ behalf (Section 2);
- Described the information collected on the Platform: account and identity information, authentication and session data, usage and audit logs, registration information, preferences, and email delivery data (Section 3);
- Added the Platform cookies and local-storage table (Section 6);
- Published the list of service providers (subprocessors) (Section 7);
- Added the Artificial Intelligence section covering AI features and our AI-use standards (Section 8);
- Added Platform retention and security commitments, including tenant isolation, encryption, credential handling, and destruction of customer data within 30 days of a valid written request (Section 9); and
- Changed the privacy contact to privacy@solutionsplusconsulting.com.
The superseded July 29, 2026 version (1.0), which covered the websites only, is archived unchanged at /legal/archive/privacy/1.0.