Legal
Privacy Policy
Notice: This policy is operational. Have qualified counsel review before high-volume SMS/voice programs or regulated niches. Submitting information or checking consent constitutes acknowledgment of this policy and our Terms of Service.
Jump to: Communications consent · AI chat & voice · Call recording · De-identified data · Your rights & Do Not Sell · Health information (MedSync PM) · Security · Security incidents · Contact
1. Overview
PM Media (“we,” “us,” “our”) operates pmmedia-source.com and related REV DE$K™ surfaces. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit, submit forms, unlock kits, use chat or voice (including AI-assisted REV DE$K Voice / Lilly), request callbacks, claim directory listings, apply as an affiliate, or become a client.
By using the site or providing information, you understand processing may occur in the United States and that commercial communications may follow where you have consented.
2. Information we collect
- Identity & business: name, email, phone, company/DBA, role, language, niche, service area, revenue or deal-size band, goals, timeline, decision-maker status, and other questionnaire or chat answers you provide.
- Intent & qualification signals: stated needs, objections, page interests, offer paths, magnet unlocks, and similar context used to route help and scope services.
- Usage & device: pages, scroll/dwell, referral/UTM, affiliate codes, IP address, browser/user agent, timestamps, session and visitor IDs.
- Communications content: form text, chat transcripts, voice/call metadata when connected, SMS/email records related to your request.
- Consent proof (Consent_Log): affirmative checkbox state, consent version ID, consent text fingerprint/snippet, channel, page, language, visitor/session IDs, truncated user agent, server-observed IP where available, and related proof IDs — retained to demonstrate agreement if needed.
- Client / billing records: under separate agreements when you license services.
3. How we use information
We use information to:
- Respond to inquiries; deliver complimentary or paid audits, kits, consultations, and licensed REV DE$K™ services;
- Qualify, score, route, and follow up on signals (including deciding when human or AI-assisted contact is appropriate);
- Operate chat, voice, SMS, email, calendar, vault, and fulfillment systems;
- Improve quality, safety, routing, prompts, and site performance;
- Attribute affiliates; prevent fraud/abuse; enforce Terms; meet legal obligations;
- Send service and marketing communications where you consented;
- Match or refer you to qualified partners or providers when relevant to your request and permitted by law and this policy;
- Maintain audit trails of consent and material interactions for compliance and dispute defense.
Analytics and pulse signals from entitled client surfaces are used to operate and advise on that client’s engine under their agreement — not to cold-contact strangers without consent.
4. Communications consent (calls · SMS · email · AI voice)
Where you check an affirmative consent box (or equivalent), you authorize PM Media and its authorized agents to contact you about your inquiry and related services by:
- Telephone (human);
- Automated and AI-assisted voice calls and voice messages (including REV DE$K Voice / Lilly);
- SMS / text (including automated);
- Email (including automated).
Message and data rates may apply. Frequency varies. Consent is not a condition of purchasing where prohibited. You may opt out of marketing (e.g., STOP on SMS; unsubscribe on email). Transactional messages about an active request or licensed service may continue as allowed by law. We may retain proof of your opt-in and opt-out.
No cold AI outbound to numbers that have not opted in through our flows.
5. How we share information
- Processors / service providers who host, automate, message, voice, analyze, or bill on our instructions under confidentiality obligations;
- Qualified partners when needed to fulfill your request or a consented referral — not unrestricted list brokerage;
- Legal, safety, and enforcement recipients when required or to protect rights, security, and integrity;
- Successors in a corporate transaction with continued protections consistent with this policy.
We do not sell personal information in ways prohibited by applicable law. Where “sale” or “share” is defined by state law, we honor required opt-outs and disclosures for our then-current programs. High-volume commercial data programs remain gated until compliance review.
6. Legal bases
Depending on context: consent; contract / pre-contract steps; legitimate interests (security, service improvement, fraud prevention, B2B follow-up where lawful); and legal obligations. You may withdraw marketing consent without voiding processing already lawfully performed or records we must keep.
7. Security
We apply administrative, technical, and organizational safeguards appropriate to the nature of the data — including access controls, tenant/client isolation on entitled engines, encrypted transport (HTTPS/TLS) on public sites, logging, and vendor diligence for processors. No method of transmission or storage is perfectly secure. You are responsible for safeguarding credentials we issue to you. Report suspected incidents to connect@pmmedia-source.com promptly.
We may suspend access that presents a security, abuse, or legal risk.
8. Cookies & local storage
We use first-party storage for language, attribution, accessibility, visitor/session IDs, consent mirrors, and site function. Disabling storage may limit features. Cookie/consent acceptance may create a Consent_Log entry.
9. AI chat & voice (Lilly / REV DE$K Voice)
With consent, Lilly may answer using AI and may speak replies. Interactions may be logged for quality, safety, routing, and compliance. Live phone handoff occurs only when you request it or systems you opted into initiate contact. Client-facing engines do not expose internal vendor names.
We disclose that it is AI. An AI assistant identifies itself as an AI at the start of an interaction and will confirm it if you ask. You can reach a human at any time by saying or typing “human,” “agent,” or “representative.” AI responses are informational only, can be inaccurate, and are not legal, medical, clinical, tax, or financial advice. Do not use our AI surfaces for emergencies — call 911.
Model providers. To generate replies and speech we send conversation content to third-party model and voice providers acting as our processors under contract. We instruct these providers not to use your content to train their general-purpose models, and we select enterprise or no-training configurations where offered. We do not sell conversation content.
Automated decisions. We use automated scoring to prioritize, route, and time follow-up. These decisions affect service order and outreach — they do not produce legal or similarly significant effects, and they are not used for credit, insurance, employment, housing, or eligibility for care. A human reviews any consequential outcome. You may ask us to review a routing decision by emailing us.
No voiceprints. We do not create, store, or use voiceprints, faceprints, or other biometric identifiers to identify you, and we do not sell or trade biometric information. Audio is processed to convert speech to text and to generate replies, not to build a biometric template.
9A. Recording, transcription, and monitoring
PM Media is based in Florida, which requires the consent of all parties to record a communication. Calls and voice sessions may be recorded, transcribed, and stored for quality, training, routing, accuracy, safety, compliance, and dispute defense. You receive notice before recording begins, and continuing the session after that notice is your consent. If you decline, tell us and we will proceed without recording where technically possible or switch channels.
Chat transcripts, SMS threads, and email correspondence are retained as business records. You may request a copy or deletion of a recording of your own conversation at connect@pmmedia-source.com; we may decline where retention is required by law, by a signed agreement, or to preserve evidence for an actual or anticipated claim.
9B. De-identified and aggregated data
We create de-identified and aggregated data from submissions and system telemetry, and use it to operate, benchmark, evaluate, and improve our services, routing logic, and prompts, and to publish industry statistics. This data is stripped of direct identifiers. We do not attempt to re-identify it and we contractually require the same of recipients. Where a client agreement, Business Associate Agreement, or law imposes stricter limits, those limits control. Protected health information is de-identified only under the applicable HIPAA standard, and we do not sell data containing health information.
10. Retention
We retain data as needed for the purposes above, contractual terms, affiliate windows, legal holds, tax/accounting, and consent/dispute records — then delete or de-identify where reasonable. Consent_Log and similar proof may be kept longer than marketing lists when needed to demonstrate compliance.
Our general targets, absent a legal hold, a longer contractual term, or an active dispute:
- Inquiry and questionnaire records: up to 3 years after last contact.
- Chat transcripts and call recordings/transcripts: up to 2 years, unless flagged for quality, safety, or dispute review.
- Consent_Log proof (opt-in and opt-out): at least 5 years, to defend TCPA and consent claims — this is deliberately longer than the marketing list itself.
- Client and billing records: 7 years, for tax and accounting.
- Security and access logs: 12–24 months.
- De-identified and aggregated data: indefinitely, per Section 9B.
- Protected health information: per the applicable Business Associate Agreement and the covered entity's instructions — returned or destroyed at termination where feasible.
Suppression records — the fact that you opted out — are retained indefinitely so we can keep honoring the opt-out. Deleting them would cause us to contact you again.
11. Your choices & rights
Subject to applicable law, you may request access, correction, deletion, portability, or restriction, and opt out of marketing or certain sharing. Email connect@pmmedia-source.com. We may verify identity and deny requests that are unlawful, abusive, or would impair security, fraud prevention, or legal claims.
How to submit a request. Email connect@pmmedia-source.com with the subject line “Privacy Request,” tell us which right you are exercising, and give us enough detail to locate your records. We respond within the period required by your jurisdiction — generally 45 days, extendable once where permitted. There is no fee for a reasonable request. We will not discriminate against you for exercising a privacy right: no denial of service, different pricing, or reduced quality.
Authorized agents. An agent may submit on your behalf with written, signed permission; we may still verify directly with you.
State rights (California, Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, Montana, and similar). Where your state law grants them, you have the right to know and access the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of recipients; to correct inaccuracies; to delete; to obtain a portable copy; to opt out of targeted advertising, profiling with legal or similarly significant effects, and any “sale” or “share” as your state defines those terms; and to limit use of sensitive personal information. Several states let you appeal a denial — reply to our decision email with “Appeal” and we will respond in writing with our reasoning within the statutory period. California residents may also contact the California Privacy Protection Agency or Attorney General; Florida residents may contact the Florida Department of Legal Affairs.
Do Not Sell or Share. We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. To opt out of any activity that qualifies as a “sale” or “share” — including cross-context behavioral advertising — email us with the subject line “Do Not Sell or Share.” We honor Global Privacy Control and similar browser opt-out signals as an opt-out for the browser that sends them.
Sensitive information. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit — namely providing the service you requested, security, fraud prevention, safety, and legal compliance. Please do not send us sensitive information you were not asked for.
EU, UK, and other non-U.S. residents. Where GDPR or similar law applies, you also have the rights to object to processing based on legitimate interests, to withdraw consent at any time without affecting prior lawful processing, and to lodge a complaint with your supervisory authority. Where we transfer personal data out of the EEA or UK, we rely on Standard Contractual Clauses or another lawful mechanism and apply supplementary safeguards as needed. Contact us for a summary of the safeguards for a specific transfer.
11A. Security incidents and notification
We maintain a written incident-response process covering detection, containment, investigation, remediation, and notification. If a security incident affects your personal information, we will notify you and any required regulator without unreasonable delay and within the timeframe your law requires, describing what happened, the categories of information involved, what we are doing, and what you can do. For engagements covered by a Business Associate Agreement, breach notification follows the HIPAA Breach Notification Rule and the timelines in that agreement. Report a suspected incident to connect@pmmedia-source.com.
11B. Health information (MedSync PM and clinical engines)
When we operate patient-intake or clinical-communication infrastructure for a healthcare provider, that provider is the covered entity and PM Media acts as a business associate. In that role we handle protected health information only as permitted by a signed Business Associate Agreement and applicable law — not under this Policy's general marketing provisions. We apply minimum-necessary practices, tenant isolation, access controls, and audit logging, and we do not use or disclose PHI for our own marketing or sell it.
If you are a patient, your rights over your medical record run through the provider that treats you — contact them directly for access, amendment, an accounting of disclosures, or restrictions, and we will support them in responding. We do not claim any universal “HIPAA certification,” because no such certification exists; we describe our approach as HIPAA-aligned architecture and will document specific safeguards on request.
Health information you volunteer to us outside a provider relationship — for example, in a general website inquiry — is treated as sensitive information under Section 11 and is not part of a medical record.
12. Children · international · regulated niches
Services are for business adults. We do not knowingly collect from children under 16. Non-U.S. visitors understand U.S. processing may apply. Medical or other regulated niches use minimum-necessary practices; we do not claim universal “HIPAA certification.”
13. Changes
We may update this policy. The version identifier will change when we revise this policy. Continued use after posting constitutes acceptance of the updated policy where permitted. Material consent text changes receive a new consent_v… version ID logged at collection.
14. Contact
House: hello@pmmedia-source.com
Privacy: connect@pmmedia-source.com
PM Media · Miami, FL · United States