1. Scope
This Privacy Policy explains what All Access Executive Services ("AAES", "we", "us") collects through this website, why, who sees it, how long it is kept, and what choices you have. It covers this website only — the inquiry form, the membership application, and the analytics/cookie behaviour described below. It does not cover information AAES may collect through other channels (a phone call, an in-person meeting, or a future member app), which will be addressed separately if and when those channels exist.
The registered business entity name, state of formation, and mailing address for AAES have not yet been confirmed for publication (tracked with TBD-001 and TBD-003 — see docs/00 §12) and are not stated as fact anywhere on this page. Once confirmed, this section will name the controlling entity and its registered address directly.
2. Information We Collect
We collect only what an inquiry or application actually needs (data minimisation):
- Contact form submissions — name, email, phone number, the division you're asking about, and whatever you write in the message field.
- Membership application submissions — the same contact details, plus whatever the application itself asks for.
- Consent records — if you check the SMS/phone consent box, we store the value (checked), a timestamp, your IP address, and the exact wording you were shown, so we can demonstrate what you actually agreed to if that is ever in question.
- Basic technical data — standard web server logs and, once you've made a cookie choice, privacy-preserving analytics events (see §4).
We do not ask about, and do not want you to submit, any medical condition, diagnosis, or health need through this website. AAES is not a healthcare provider (see Regulatory Disclosures), and any medical information volunteered in a free-text field is not something this site is built to receive or protect appropriately — please don't include it.
3. How We Use Information
We use the information above to:
- Respond to your inquiry or application and route it to the right specialist;
- Confirm and manage a membership relationship, once one exists;
- Contact you by phone, text, or email about your own inquiry — never for unrelated marketing without separately obtained consent;
- Keep the operational and compliance records described in §6; and
- Understand, in aggregate and privacy-preserving form, how the site is used (§4).
We do not sell personal information, and we do not use it to train any third-party AI model.
4. Cookies, Analytics & Your Choices
This section is written to match exactly what the site does — not a generic cookie-policy template.
- Vercel Analytics — cookieless page-view and Core Web Vitals measurement. It runs before any cookie choice because it sets no cookie and identifies no individual visitor.
- Google Analytics 4 (GA4) — behavioural analytics. This does not load until you actively accept analytics cookies in the banner. If you decline, or don't respond, GA4 never loads.
- Sentry — error monitoring, so we know when something on the site breaks. It is configured to scrub personal data from error reports before we ever see them, and it is not a behavioural tracker, so it isn't gated by the cookie choice above.
- We do not run session recording or heatmap tools (deliberately — see Regulatory Disclosures and docs/06 for why).
You can accept or decline analytics cookies with one click each — declining is exactly as easy as accepting — and you can change your mind at any time using Cookie preferences in the site footer. Your choice is remembered for future visits. No personal data (names, emails, phone numbers, or message text) is ever included in an analytics event or a URL.
5. How We Share Information
We share your information only as needed to do what you asked:
- With the specific contracted vendor, agency, or provider your request requires, under the same confidentiality standard described in our Terms of Use and on About;
- With service providers who process data on our behalf (e.g. email delivery, form-security, and hosting infrastructure), bound to protect it and use it only for that purpose; and
- Where required by law, or to protect the rights, property, or safety of AAES, our members, or others.
We do not share information with any medical or healthcare provider in exchange for anything of value — see the Patient Brokering Act disclosure on the Regulatory Disclosures page.
6. Data Retention & Deletion
Inquiry and application records are kept for as long as needed to respond to you, maintain an accurate business record, and meet the record-keeping this business's regulatory posture requires (for example, TCPA consent records — see §4 and Regulatory Disclosures) — and are deleted or anonymised after that. Exact retention periods (in months/years, by record type) are not yet finalised and will be published here, specifically, once confirmed with the client and counsel rather than left as a general statement.
To request deletion of your information, contact us using the details in §12. We will honour a deletion request except where we're legally required or permitted to retain a record (for example, a consent record relevant to a live TCPA question).
7. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain uses. This includes rights that may arise under the Florida Digital Bill of Rights, and — for visitors connecting from California or the EU/UK — the CCPA/CPRA and GDPR/UK GDPR respectively. AAES's applicability thresholds under some of these frameworks have not yet been confirmed by counsel; this section is written to a good standard regardless of whether a given threshold is met. To exercise any of these rights, contact us using the details in §12.
8. Security
We use encryption in transit (HTTPS) for everything this site sends and receives, and we restrict access to the systems that store your information to the people who need it to do their jobs. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. Confidentiality
Discretion is central to how AAES operates, not just a legal position. Every member relationship begins with a non-disclosure agreement, and every contracted vendor agrees to the same confidentiality standard before working with a member — see About for specifics.
10. Children's Privacy
This site is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, contact us using the details in §12 and we will delete it.
11. Changes to This Policy
We may update this policy as the site, the business, or the law changes. The "Last updated" date at the top of this page always reflects the most recent substantive change, and — once this page is final and version-controlled content history is public — prior versions remain available in the site's version history, since what this policy said on a given date can matter (see docs/04, docs/06 §11).
12. Contact Us
Questions about this policy, or a request to exercise a privacy right described in §7, can be sent through the contact page, or by phone or email using the details in the site footer. A dedicated privacy contact/mailbox has not yet been assigned — noted here as an open item rather than publishing an unmonitored address.
