Legal

Privacy Policy

How we collect, use, disclose and protect information across our website, marketing, and client engagements — including data handled on behalf of HIPAA covered entities and business associates.

Monday.com Master HubSpot Solutions Google Partner Meta Business WordPress VIP Lovable Platinum Shopify Partner Stripe Verified Semrush Agency Partner Google Analytics (GA4) Klaviyo Pro Salesforce Partner Webflow Enterprise AWS Certified Monday.com Master HubSpot Solutions Google Partner Meta Business WordPress VIP Lovable Platinum Shopify Partner Stripe Verified Semrush Agency Partner Google Analytics (GA4) Klaviyo Pro Salesforce Partner Webflow Enterprise AWS Certified Monday.com Master HubSpot Solutions Google Partner Meta Business WordPress VIP Lovable Platinum Shopify Partner Stripe Verified Semrush Agency Partner Google Analytics (GA4) Klaviyo Pro Salesforce Partner Webflow Enterprise AWS Certified

Effective date: July 1, 2026 · Last updated: July 1, 2026

This Privacy Policy is maintained by ParkWest Creative Solutions ("ParkWest", "we", "us", or "our"), a business growth partner headquartered in San Diego, California. It describes how we collect, use, disclose and safeguard personal information across (a) our website at parkwest.solutions and any subdomains, (b) our marketing, sales and recruiting activities, and (c) the professional services we deliver to clients — including branding, creative, digital marketing, printing, web and software development, sales enablement, automations, AI workflows and business operations consulting.

This page is maintained by ParkWest to answer common privacy questions about our website and services. It is not a certification and is not legal advice. For engagements involving Protected Health Information (PHI), the specific terms of the signed Business Associate Agreement (BAA) and Statement of Work (SOW) control over anything summarized here.

1. Scope & our role

We act in two different capacities depending on context, and different rules apply:

  • Controller — for information we collect directly through our website, marketing forms, sales conversations, careers applications, and our own internal operations. We decide the purposes and means of processing.
  • Processor / Service Provider / Business Associate — for information we handle on behalf of a client under a signed Master Services Agreement (MSA), Data Processing Addendum (DPA), or Business Associate Agreement (BAA). The client remains the controller (or covered entity), and we process the data only on their documented instructions.

2. Information we collect

2.1 Information you provide directly

  • Contact & inquiry data — name, company, business email, phone, and the content of your message when you use the general inquiry, growth consultation, or request-a-service forms.
  • Career applications — name, contact details, role of interest, LinkedIn / portfolio URLs, cover letter, and anything you email us as a resume attachment.
  • Client account data — the information you or your team provide when engaging us or logging into a client workspace, including billing details processed by our payment processors.
  • Correspondence — records of emails, calls, meetings, and support tickets you exchange with our team.

2.2 Information collected automatically

  • Device, browser, operating system, referring URL, pages viewed, session timing, and approximate location derived from IP address.
  • Cookies, pixels, local storage, and similar technologies used for essential functionality, remembering accessibility preferences, and analytics.
  • Diagnostic logs and error reports needed to keep the site secure and reliable.

2.3 Information from third parties

  • Business contact enrichment (e.g., firmographics) used solely for B2B outreach where legally permitted.
  • OAuth or single-sign-on providers you use to authenticate with tools we integrate (e.g., Google, Microsoft, Meta, HubSpot, Salesforce, Monday.com, Klaviyo, Stripe, Shopify, Webflow, WordPress VIP, AWS).
  • Publicly available professional information (e.g., LinkedIn) used to evaluate candidates or research prospects.

2.4 Client data we process on your behalf

When we deliver services, our clients may route their end-user, employee, customer or patient data through systems we help build or operate. The type of data varies by engagement and can include names, contact details, purchase history, marketing preferences, analytics events, support conversations, form submissions, financial identifiers, and — where a BAA is in place — Protected Health Information. We process this data only on the client's documented instructions and only for as long as the engagement requires.

3. How we use information

  • Respond to inquiries, provide quotes, and schedule growth consultations.
  • Deliver and improve the services described in a signed SOW or MSA.
  • Operate, secure, monitor, and improve our website and internal tools.
  • Send transactional confirmations, service updates, and — where permitted — occasional business communications from which you can unsubscribe at any time.
  • Evaluate candidates and manage recruiting workflows.
  • Meet legal, tax, accounting, audit, and regulatory obligations.
  • Detect, investigate, prevent, and respond to fraud, abuse, and security incidents.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use client data or PHI to train third-party generative AI models.

Where the GDPR or UK GDPR applies, we rely on the following legal bases: (a) performance of a contract with you or your organization; (b) legitimate interests in running and marketing our business, kept in balance with your rights; (c) consent, where required (e.g., certain cookies or marketing); and (d) compliance with legal obligations.

5. HIPAA, PHI & healthcare engagements

For clients that are HIPAA covered entities or business associates — including behavioral health, telehealth, payer, provider, and life-sciences clients we serve in industries like Health & Wellness — ParkWest will execute a Business Associate Agreement (BAA) before creating, receiving, maintaining, or transmitting Protected Health Information on the client's behalf.

  • Minimum necessary. We request, access, and use only the minimum PHI required to perform the contracted service.
  • Encryption. PHI is encrypted in transit (TLS 1.2 or higher) and at rest using industry-standard algorithms on HIPAA-eligible infrastructure (e.g., AWS services covered under AWS's HIPAA BAA).
  • Access controls. Role-based access, unique user IDs, MFA on all administrative accounts, session timeouts, and audit logging on systems that touch PHI.
  • Workforce training. Personnel who may access PHI complete HIPAA privacy and security training and sign confidentiality obligations.
  • Subcontractors. We flow down BAA obligations to any subcontractor that may access PHI, and we maintain a list of PHI-eligible subprocessors available on request.
  • Breach notification. We will notify the covered entity without unreasonable delay, and in no case later than the timeframes required by 45 CFR § 164.410 (and any shorter contractual deadlines), following discovery of a Breach of Unsecured PHI.
  • De-identification. When we need production-like data for testing or analytics, we prefer synthetic or de-identified data per 45 CFR § 164.514.
  • Return / destruction. At termination we return or securely destroy PHI in our possession, or extend BAA protections for any PHI we cannot feasibly return or destroy.

Nothing on this page is offered as legal advice, and this website is not intended to receive PHI. Please do not send PHI through our contact forms or general email. If you need to transmit PHI, contact us first so we can provision a secure channel under a signed BAA.

6. How we share information

We disclose personal information only in the ways described below and only when necessary:

  • Service providers & subprocessors that host infrastructure, send email, process payments, run analytics, or otherwise support our services under written contracts requiring confidentiality and appropriate safeguards.
  • Clients, when the information relates to their engagement (for example, campaign performance data or leads generated on their behalf).
  • Professional advisors (auditors, insurers, lawyers, accountants) bound by confidentiality.
  • Corporate transactions — in the event of a merger, financing, reorganization, or asset sale, subject to continued protection of your information.
  • Legal & safety — where required by law, court order, or to protect the rights, property, or safety of ParkWest, our clients, our users, or the public.

7. Subprocessors we typically rely on

Depending on the engagement, we may rely on the following categories of providers. A current, per-engagement subprocessor list is available on request:

  • Cloud & hosting: Amazon Web Services, Cloudflare, Vercel.
  • Marketing & CRM: HubSpot, Salesforce, Klaviyo, Google (Ads, Analytics, Workspace), Meta Business, Semrush.
  • Commerce & payments: Stripe, Shopify.
  • Web & product platforms: WordPress VIP, Webflow, Lovable, Monday.com.
  • Communications: transactional email providers used to send confirmations and notifications.

8. International transfers

We are based in the United States. If you are located outside the U.S., your information may be transferred to, stored in, and processed in the U.S. or in any other country where we or our subprocessors operate. Where required, we rely on lawful transfer mechanisms such as the EU Standard Contractual Clauses and the UK IDTA, together with supplementary safeguards.

9. Data retention

We retain personal information for as long as needed to fulfill the purposes described in this policy, satisfy our legal, tax, accounting, or reporting obligations, and enforce our agreements. Typical guidelines:

  • Inquiry and marketing contacts: up to 24 months after last interaction, unless you unsubscribe or ask us to delete sooner.
  • Client and financial records: as long as the engagement is active, plus the retention period required by applicable law (typically 7 years for U.S. tax records).
  • PHI and client-owned data: for the term of the SOW/BAA, then returned or destroyed as described in Section 5.
  • Website logs and analytics: typically 13 months, or the shorter period configured by the client.

10. Your rights & choices

Depending on where you live (including under the GDPR, UK GDPR, CCPA/CPRA, and other U.S. state privacy laws), you may have the right to:

  • Access, correct, port, or delete personal information we hold about you.
  • Opt out of certain uses of your information, including targeted advertising and any "sale" or "share" as those terms are defined by law (note: we do not sell personal information).
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a data protection authority.

To exercise a right, email privacy@parkwest.solutions. We will verify your request and respond within the timeframes required by law. If your data was submitted to us by a client (for example, through a form or product we operate on their behalf), we will refer you to that client as the controller of your data.

11. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Controls include encryption in transit and at rest, role-based access, MFA on privileged accounts, secrets management, dependency and vulnerability scanning, network segmentation, logging and monitoring, backups, and incident response procedures. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Cookies & tracking

We use a small number of essential cookies (for accessibility preferences and theme), plus first- and third-party analytics cookies to understand how the site is used. Where required by law, we ask for consent before setting non-essential cookies. You can disable cookies in your browser or through any consent banner we display; some features may not work as expected.

13. Children

Our website and services are directed to businesses and are not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, provide additional notice (for example, an email or a banner on the site).

15. Contact us

ParkWest Creative Solutions
HQ: San Diego, California, USA
Privacy inquiries: privacy@parkwest.solutions
General: hello@parkwest.solutions
Direct line: (858) 216-8833