Privacy Policy — Public Website
This policy explains how CoAdapta Advisors LLC ("we," "us," "our") collects, uses, discloses, and protects personal information through our public website at https://coadapta.com**,**https://coadapta.net, https://coadapta.io and their subdomains, including landing pages, scheduling links, and short links (together, the "Site").
If you are a client user signing in to our secure client portal, a separate policy governs that application. It is available at https://coadapta.com/privacy-client-apps.
For everything described here, we are the controller of your information — we decide why and how it is used.
1. Information we collect
1.1 Information you give us
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and inquiry | Name, business email, phone, company, job title, message content, budget or timeline details you choose to share | Contact and inquiry forms, "request a call" forms |
| Scheduling | Name, email, meeting time, time zone, answers to booking questions, any notes you add | Our online scheduling links |
| Subscription | Email address, name, company, topic preferences | Newsletter and report sign-up forms |
| Event and assessment interest | Name, email, organization, role, registration answers | Workshop, webinar, and assessment interest forms |
| Correspondence | The content of emails, voicemails, and messages you send us, and our replies | Direct contact with us |
| Documents you send | Files, attachments, and materials you provide during a sales conversation | Email or upload links we send you |
Providing this information is voluntary. If you leave a form field blank, we may not be able to answer your question or schedule a meeting.
We do not process payments on the Site. [If you engage us, invoicing and payment happen through our client portal or direct invoice — see the portal policy.]
1.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and connection | IP address, browser type and version, operating system, device type, screen resolution, language, general region inferred from IP |
| Usage | Pages viewed, time on page, scroll depth, links and buttons clicked, files downloaded, referring URL, exit page |
| Campaign attribution | UTM parameters, referring campaign, search terms that brought you to the Site, short-link click data |
| Email engagement | Whether you opened an email we sent and which links you clicked, where your email client permits this |
| Diagnostics | Error and performance data used to keep the Site working |
1.3 Information from other sources
We build and maintain a business prospect list. Where you have not contacted us directly, we may collect business contact information — name, job title, employer, business email, business phone, and publicly reported company details — from:
- Public company websites, press releases, and public filings
- Professional networking and business directory sites
- Industry associations, conference attendee lists, and trade publications
- Business contact data providers and list vendors
- Referrals and introductions from mutual professional contacts
We collect this information about people in their professional capacity only, to assess whether our services are relevant to their organization and to make a business introduction. We do not build profiles of individuals' personal lives, and we do not collect this information about consumers.
1.4 Personalized landing pages
We sometimes create a landing page tailored to a specific company or prospect, reachable only through a link we send directly to you. Such a page may display your name, your company name, your industry, and details drawn from public sources or from a prior conversation with us. The link is unlisted and not indexed by search engines, but it is not password protected — anyone you forward it to can view it. We remove these pages [90] days after the related conversation ends, or sooner on request.
1.5 What we do not collect
We do not knowingly collect sensitive personal data through the Site — no health, biometric, genetic, precise geolocation, racial or ethnic origin, religious belief, sexual orientation, immigration status, or government identifier information. Please do not include such details in a form or message to us.
2. Cookies and similar technologies
| Type | What it does | Set before consent? |
|---|---|---|
| Strictly necessary | Security, load balancing, form submission, remembering your cookie choice | Yes — the Site cannot work without these |
| Functional | Remembering preferences and previously entered form details | Only with consent |
| Analytics | Measuring traffic, page performance, and which content is useful | Only with consent |
We present a consent banner on your first visit and set non-essential cookies only after you accept. You can change or withdraw your choice at any time through the cookie settings link in the footer. You can also block or delete cookies through your browser, and most browsers offer a "do not track" signal — we [honor / do not currently respond to] such signals, and will update this policy if that changes.
3. How we use information
We use personal information to:
- Respond to you — answer inquiries, return calls, schedule and prepare for meetings, and follow up on conversations.
- Prepare proposals and materials — research your organization and draft proposals, agendas, and pre-meeting materials relevant to your situation.
- Send the communications you asked for — our newsletter, monthly economic report, event invitations, and other content you subscribed to.
- Conduct business development — introduce our services to organizations we believe would benefit, and follow up where there is genuine interest.
- Operate and improve the Site — measure which pages and topics are useful, fix errors, test changes, and improve navigation and content.
- Measure marketing — understand which campaigns and channels produce meaningful conversations.
- Protect the Site — detect and prevent spam, form abuse, fraud, and attacks, and keep records for security purposes.
- Comply with law — meet legal and regulatory obligations and respond to lawful requests.
We do not sell personal information. We do not disclose personal information to third parties for their own marketing purposes, and we do not conduct profiling that produces legal or similarly significant effects about anyone.
AI-assisted work. We use AI tools to help draft and summarize business correspondence and research. These tools operate under agreements that prohibit the provider from using our data to train their models, and a person reviews the output before it reaches you. No decision about you is made by an automated system alone.
Legal bases (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Responding to your inquiry or scheduling a meeting | Steps at your request prior to entering a contract (Art. 6(1)(b)) |
| Business development outreach, Site security, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Newsletter and marketing emails; non-essential cookies | Consent (Art. 6(1)(a)) |
| Record retention required by law | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and use only business contact information, in a professional context, with an opt-out in every message. You may object to this processing at any time by emailing [email protected], and we will stop.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out.
4. How and to whom we disclose information
We do not sell your personal information, and we do not rent, trade, or share our contact lists with other businesses. We disclose information only as follows:
4.1 Service providers
Vendors that operate parts of the Site and our marketing operations on our behalf. Each is bound by a written contract limiting their use of the data to serving us, requiring confidentiality and appropriate security, and requiring return or deletion when the engagement ends.
| Category | Purpose | Provider |
|---|---|---|
| Website hosting and CDN | Serving the Site | Vercel Inc |
| Website analytics | Traffic and usage measurement | |
| Form handling and database | Receiving and storing form submissions | Supabase |
| Transactional email delivery | Confirmations and replies | Resend |
| Online scheduling | Booking meetings | Calendly |
| CRM and business records | Tracking conversations and opportunities | Vercel & Supabase |
| Link shortening and tracking | Campaign attribution | [Vercel & Supabase] |
| AI and language model providers | Drafting and research assistance | [Anthropic & Open AI] |
| Cloud file storage | Storing documents you send us | [Supabase & AWS] |
A current list is available on request to [email protected].
4.2 Professional advisors
Our attorneys, accountants, auditors, and insurers, where reasonably necessary and subject to duties of confidentiality.
4.3 Corporate affiliates
Information may be shared among our affiliated entities: CoAdapta Advisors LLC, CoAdapta Edge Technologies LLC, where necessary to respond to your inquiry or deliver a service. Each affiliate handles it consistently with this policy.
4.4 Legal and safety
We may disclose information when we believe in good faith it is necessary to comply with a law, subpoena, warrant, or court order; to enforce our agreements; or to protect the rights, property, or safety of our business, our clients, our personnel, or the public.
4.5 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. The receiving party remains bound by this policy or will give notice before materially changing it.
4.6 Method of disclosure
Disclosures happen through controlled channels only:
- Encrypted connections (TLS 1.2 or higher) between the Site, our systems, and our service providers — form submissions travel over HTTPS and are never sent as plain text.
- Authenticated vendor accounts with role-based access, restricted to personnel who need them.
- Encrypted email or a secure document link for materials sent to you, to advisors, or in response to a legal request.
- Aggregate or de-identified reporting wherever a purpose can be met without identifying anyone — most of our marketing analysis works this way.
We do not transmit personal information over unsecured FTP, consumer file-sharing links, or removable media, and we do not put personal information into URLs or query strings that could end up in logs or referrer headers.
5. International transfers
We operate from the United States, and information collected through the Site is processed there.
If you are in the European Economic Area, the United Kingdom, or Switzerland, we transfer your data to the United States under the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum. We assess the risk of each transfer and apply technical measures including encryption in transit and at rest. A copy of the safeguards is available on request to [email protected].
6. How we protect information
The Site collects far less sensitive data than our client portal, but we protect it with:
Technical
- HTTPS with TLS 1.2 or higher across the entire Site, with HSTS enabled
- Encryption at rest for form submissions, contact records, and stored documents
- Access to our marketing systems and CRM protected by strong, unique credentials and multi-factor authentication
- Reputable managed platforms for hosting and email rather than self-managed servers, so security patching is continuous
- Spam filtering, rate limiting, and bot protection on public forms
- Regular dependency and vulnerability scanning of Site code before deployment
Administrative
- Access limited to the small number of personnel with a business need
- Confidentiality obligations and security awareness practices for anyone with access
- Written contracts with every vendor covering confidentiality, security, and breach notification
- Periodic review of who has access to which systems, with prompt removal when it is no longer needed
Incident response
- We maintain a written incident response plan. If a breach affects personal information, we will notify affected individuals and regulators as required by law — including notice under Kentucky's breach notification statute, KRS 365.732, and within 72 hours to the relevant supervisory authority where the GDPR or UK GDPR applies.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Please do not send confidential or sensitive information through a public form. If you believe you have found a security issue with the Site, tell us at [email protected].
7. How long we keep information
| Data | Retention |
|---|---|
| Inquiry and contact form submissions | [24] months from last contact, unless a client relationship begins |
| Scheduling records | [24] months from the meeting date |
| Newsletter subscribers | Until you unsubscribe, then [12] months to honor your opt-out |
| Prospect and business development records | [36] months from last meaningful contact, then reviewed and deleted or refreshed |
| Personalized landing pages | [90] days after the related conversation ends |
| Website analytics | [14] months in identifiable form, then aggregated |
| Email engagement data | [24] months |
| Correspondence | [3] years from last exchange |
| Security and server logs | [90] days |
We delete or de-identify information when it is no longer needed for the purpose it was collected for, unless a longer period is required by law or needed to establish, exercise, or defend a legal claim. Opt-out and suppression records are kept indefinitely so we can continue honoring your choice.
8. Your rights and choices
8.1 Everyone
- Unsubscribe. Every marketing email has an unsubscribe link at the bottom. It takes effect immediately, and you can also email [email protected].
- Stop outreach. If we contacted you and you would rather we did not, reply and say so, or email [email protected]. We will add you to our suppression list and stop.
- Access, correct, or delete. Ask us what business contact information we hold about you, correct it, or have it deleted. Email [email protected].
- Cookies. Use the cookie settings link in the footer or your browser controls.
We do not discriminate against anyone for exercising these rights.
8.2 Kentucky residents (KCDPA)
Under the Kentucky Consumer Data Protection Act, KRS 367.3611 to 367.3629, Kentucky consumers have the right to confirm whether we process their personal data and to access it; correct inaccuracies; delete it; obtain a portable copy where technically feasible; and opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.
We do not sell personal data or conduct such profiling. [We do not engage in targeted advertising. / Where we use advertising cookies, you can opt out through the cookie settings link in the footer.]
Submitting a request. Email [email protected] or write to us at the address in Section 11, with "Privacy Request" in the subject line. We verify identity by reasonable means before acting — usually by confirming details we already hold. We respond free of charge, up to twice in any twelve-month period, within 45 days, extendable once by another 45 days where reasonably necessary, and we will tell you if we need the extension.
Appeals. If we decline your request, we will explain why and tell you how to appeal. We respond to appeals in writing within 60 days. If we deny an appeal, you may complain to the Kentucky Attorney General's Office of Data Privacy at https://www.ag.ky.gov.
The KCDPA covers Kentucky residents acting in a personal capacity and does not extend to people acting in a commercial or employment context. Most of the information on this Site is business contact information, but we honor these requests regardless of which category you fall into.
8.3 EEA, UK, and Swiss residents (GDPR / UK GDPR)
You have the right to access your personal data; rectify inaccuracies; erase it; restrict or object to processing, including objecting to direct marketing at any time; receive it in a portable format; and withdraw consent.
Email [email protected] to exercise any of these. We respond within one month, extendable by two further months for complex requests. You may also complain to your local supervisory authority — in the UK, the Information Commissioner's Office at https://ico.org.uk.
[Our Article 27 representative in the EEA/UK is [REPRESENTATIVE NAME AND CONTACT].]
9. Third-party links
The Site links to other websites — client sites, publications, scheduling tools, and social platforms. Once you follow a link, this policy no longer applies. We do not control those sites and are not responsible for their privacy practices. Read their policies before providing information.
10. Children
The Site is aimed at business audiences and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it. Contact [email protected] if you believe a child has provided us information.
11. Changes to this policy
We may update this policy as our practices or the law change. The revised version will be posted here with a new effective date. If a change materially affects how we use information already collected, we will give notice on the Site — and by email to subscribers — before it takes effect.
12. Contact us
CoAdapta Advisors LLC [MAILING ADDRESS] [CITY, KY ZIP]
Privacy inquiries and rights requests: [email protected] General: [email protected]
We aim to acknowledge every privacy inquiry within five business days.