Demers & Associates, Inc. – Privacy Policy
Effective date: August 24, 2026
1. Introduction
Demers & Associates, Inc. ("we", "our", or "us") operates the website at https://www.demersassociates.com/. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our services. 340B Compliance and consulting
2. Scope of This Policy
This Privacy Policy applies to all personal information collected through https://www.demersassociates.com/ and any related applications, services, APIs, or communications provided by Demers & Associates, Inc.. It does not apply to third-party websites, products, or services even if they are linked from our platform. By using our services you acknowledge that you have read and understood this policy.
3. Information We Collect
We may collect the following categories of information: Full name Email address IP address Device information Usage data.
4. How We Use Information
We use personal information to:
provide, maintain, and improve our services;
respond to support requests and communicate about the service;
secure the platform and detect fraud or abuse;
comply with legal obligations;
understand usage patterns and improve product performance through analytics;
5. Cookies and Tracking
We use cookies and similar technologies to keep users signed in, remember preferences, and improve site performance. We also use analytics tools to understand feature usage and performance trends.
6. Third-Party Service Providers
We work with trusted service providers to operate the platform. Current providers may include: We use trusted third-party service providers to support our operations, such as hosting, analytics, and communications. These providers may process personal information on our behalf subject to contractual and legal safeguards.. These providers may process personal information on our behalf subject to contractual and legal safeguards.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy; it is then securely deleted or anonymised.
8. Your Privacy Rights
Depending on where you are located and the laws that apply, you may have the right to:
Right of Access: request a copy of the personal information we hold about you;
Right to Rectification: request correction of inaccurate or incomplete information;
Right to Erasure: request deletion of personal information, subject to legal exceptions;
Right to Data Portability: receive a machine-readable copy of your data where applicable;
Right to Object: object to processing based on legitimate interests or direct marketing;
Right to Restriction: request that we limit how we process your information in certain circumstances;
Right to Withdraw Consent: withdraw consent at any time where we rely on consent as our legal basis;
How to exercise your rights: You may submit a Data Subject Access Request (DSAR) or any other privacy request by emailing us at Debra.Demers@DemersAssociates.com. We will acknowledge your request within 5 business days and provide a substantive response within 30 days of receipt (or such shorter period as required by applicable law). In complex cases we may extend this by a further 60 days and will notify you accordingly.
9. Legal Basis and Jurisdiction
We process personal information in accordance with applicable privacy laws in United States. The table below sets out the legal basis we rely on for each category of processing activity:
Processing activityLegal basisAccount creation and core service deliveryContract performance: processing is necessary to perform our agreement with youTransaction records and regulatory complianceLegal obligation: processing is required to meet applicable legal requirementsSecurity monitoring, fraud prevention, and abuse detectionLegitimate interests: we have a legitimate interest in keeping the service and our users securePlatform analytics and product improvementLegitimate interests: we have a legitimate interest in understanding how the service is used; anonymised or aggregated data is used where possible
Privacy contact: We have not appointed a formal DPO but have designated a responsible person to oversee privacy compliance. All privacy enquiries should be directed to the contact address in Section 12.
10. Security
We implement reasonable technical and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction.
11. International Transfers
If personal information is transferred across borders, we take steps to ensure the information receives an adequate level of protection under applicable law.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise a privacy right, contact us:
Postal address: 30 Kennedy Blvd Lincoln, RI 02865
Privacy requests: Debra.Demers@DemersAssociates.com
We aim to respond to all privacy enquiries within 5 business days.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and provide notice where required.
Annex A. Jurisdiction-Specific Privacy Disclosures
The following provisions supplement this Privacy Policy and apply where the relevant law governs your relationship with us.
California (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (Cal. Civ. Code §§ 1798.100–1798.199):
Right to Know what personal information we collect, the sources, the purposes, and the categories of third parties to whom it is disclosed (12-month look-back, extendable to longer with verification).
Right to Delete personal information we have collected, subject to enumerated exceptions in § 1798.105(d).
Right to Correct inaccurate personal information.
Right to Opt Out of Sale or Sharing of personal information for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal as a valid opt-out request. As required by Cal. Civ. Code § 7025(c)(6) (effective January 1, 2026), when we detect an opt-out preference signal from your browser we display a visible "Opt-Out Request Honored" confirmation so you can verify your signal was received and applied.
Right to Limit Use of Sensitive Personal Information (§ 1798.121), including precise geolocation, government IDs, financial credentials, genetic/biometric data, racial or ethnic origin, religious beliefs, sex life or sexual orientation, and content of mail/email/text messages not addressed to us.
Right to Non-Discrimination for exercising privacy rights (§ 1798.125).
Right to opt out of automated decision-making (forthcoming under CCPA Regs, Article 11 ADMT rules) where applicable.
You may submit a verifiable consumer request via Debra.Demers@DemersAssociates.com, or by emailing "Do Not Sell or Share My Personal Information" to Debra.Demers@DemersAssociates.com. We respond within 45 days (extendable by 45 with notice). Authorized agents may act on your behalf with written authorization.
Categories of personal information collected and disclosed are described in Sections 3–4 above.
Other U.S. State Privacy Laws
Residents of states with comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa, Tennessee, Indiana, Florida (FDBR), Delaware, New Jersey, New Hampshire, Minnesota, and Maryland, have the right to access, correct, delete, port, and opt out of targeted advertising, sale, and certain profiling. To exercise these rights, contact Debra.Demers@DemersAssociates.com or visit our privacy request page. We respond within 45 days as required by law and honor authorized agent requests.
CalOPPA (California Online Privacy Protection Act)
Pursuant to Cal. Bus. & Prof. Code §§ 22575–22579, this Privacy Policy is conspicuously posted on our website. We notify users of material changes by updating the effective date. We disclose how we respond to Do Not Track ("DNT") browser signals: at present, no industry-standard interpretation of DNT exists, but we do honor the Global Privacy Control (GPC) signal as an opt-out of sale/sharing under CCPA/CPRA.
Data Breach Notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and notify affected individuals without undue delay where required by applicable breach-notification law (including U.S. state breach laws, Australia's NDB scheme, PIPEDA breach reporting, and LGPD Article 48).
Sub-Processors
We engage the following categories of sub-processors to provide the Service: cloud hosting, transactional email, payment processing, customer support, analytics, error monitoring, and security services. Each sub-processor is bound by a written contract requiring confidentiality, security, and processing only on our documented instructions, including the GDPR Article 28 / UK GDPR / LGPD Article 39 requirements. Current sub-processors include: We use trusted third-party service providers to support our operations, such as hosting, analytics, and communications. These providers may process personal information on our behalf subject to contractual and legal safeguards.. We provide reasonable advance notice of new sub-processors where required by enterprise customer DPAs.
This privacy policy was generated with PrivacyTerms.io.