Medical Targets
Legal

Privacy Policy

What we collect on medicaltargets.com, how we use it, and the choices you have.

Last updated: [DATE — to be set at publication]
Data Services Direct, LLC, a California limited liability company doing business as Medical Targets.

Data Services Direct, LLC, a California limited liability company doing business as Medical Targets (“Medical Targets,” “we,” “us,” or “our”), operates the website at https://www.medicaltargets.com and our own marketing landing pages (the “Site”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

This policy covers the Site only. It does not cover information we process on behalf of our clients when providing services to them, and it does not cover websites or landing pages we build or operate for a client under that client’s brand — those are governed by the client’s own privacy policy. In that context we act as a service provider under our client’s instructions. See Section 10.

Section 1

Who This Policy Is For

The Site is a business-to-business marketing website intended for practice owners, operators, and other business users. It is not directed to patients or consumers seeking aesthetic treatment, and it is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, email privacy@medicaltargets.com and we will delete it.

We do not sell products or services through the Site. No account can be created and no purchase can be made on it.

Section 2

Information We Collect

Notice at Collection

What we collect: identifiers (name, business email, telephone), professional information (company, role, practice details), commercial information (what you downloaded or asked about), and internet activity (pages viewed, referring source, device and browser).

Why: to send you what you requested, respond to you, market our services to you, secure and improve the Site, and meet our legal and recordkeeping obligations.

Do we sell or share it? No. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Sensitive personal information: we do not collect it.

How long: see Section 7.3.

We collect only the information reasonably necessary for the purposes described in this policy. We do not ask for more than we need, and we do not collect information simply because we could.

2.1 Information you give us

Gated content. If we offer a field guide, white paper, or similar material behind a form, we ask for your name, business email address, company name, and role, and may ask for your telephone number and practice details.

Scheduling a call. Every request on the Site goes to our scheduling page. When you book, we collect your name, email address, and anything you enter in the booking form.

Meeting scheduling. When you book a call, our scheduling provider collects your name, email address, and any information you enter in the booking form, and adds the meeting to our calendar.

Direct contact. If you email or call us, we keep the contents of that correspondence and our record of it.

2.2 Information collected automatically

When you visit the Site we and our providers may collect: IP address, browser type and version, operating system and device type, referring URL and exit pages, pages viewed and time spent, approximate location derived from IP address, and the date and time of your visit.

We and our service providers may use cookies, browser local storage and session storage, pixels and tracking images, software development kits, server logs, and similar technologies to collect this information. Section 5 describes which of these we use and which we do not.

Email measurement. When we send you email, we use standard first-party measurement — a small tracking image that records whether the message was opened, and links that record whether they were clicked. We use this to understand which content is useful and whether our messages are being delivered. You can prevent open tracking by setting your email client not to load remote images, and you can stop the emails entirely at any time (Section 6.1).

2.3 Information from other sources

We may supplement what you give us with business information from publicly available sources and licensed business data providers — for example, company size, industry, location, and professional role. This is business information about your practice and your professional role. We do not build consumer profiles about site visitors, and we do not purchase consumer data.

2.4 What we do not collect

We do not collect health, medical, or treatment information through the Site. We do not knowingly collect Social Security numbers, government identification numbers, financial account numbers, biometric data, precise geolocation, or information about your race, religion, health, sexual orientation, union membership, or political views. Please do not send us any of this. Payment for our services is handled outside the Site.

Section 3

How We Use Your Information

We use the information described above to:

  • send you the gated content you requested;
  • respond to your inquiries and schedule and hold meetings;
  • send marketing communications about our services, which you can stop at any time (see Section 6);
  • understand which content and pages are effective, and improve the Site;
  • maintain the security and integrity of the Site and prevent fraud and abuse;
  • keep business and accounting records; and
  • comply with law and enforce our Terms of Use.

We do not use information collected through the Site to make any automated decision that produces a legal or similarly significant effect about you.

Section 4

How We Share Information

We do not sell your personal information for money, and we do not share it for cross-context behavioral advertising.

We share information with:

Service providers who work on our behalf, under contract, and are limited to using the information for that purpose. We use providers in the following categories:

Category
What they do
Examples of providers we use
CRM and marketing platform
Forms, contact records, email delivery, campaign records
HubSpot
Business productivity and email
Business email, calendar, documents, file storage
Google Workspace, Microsoft 365
Website and landing page hosting
Hosting and delivery of our own site and marketing pages
Hosting platforms and content delivery networks
Site security and performance
Security filtering, load handling, traffic measurement
Cloudflare
Meeting scheduling
Booking and calendar coordination
Scheduling providers integrated with our calendar
Telephony and messaging
Business telephone and text messaging
Business communications providers
Professional services
Accounting, payments, and administration
Business software providers

We use more than one provider in some categories, and our providers change over time. Whatever the platform, every page covered by this policy follows the rule in Section 5: strictly necessary and first-party technologies only, with no third-party advertising or cross-site tracking.

We will identify our current providers on request — email privacy@medicaltargets.com.

Professional advisors — attorneys, accountants, and insurers, where reasonably necessary.

Legal and safety — where required by law, subpoena, or other legal process, or where necessary to protect our rights, safety, or property or those of others.

Business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not share personal information with advertising networks or for cross-context behavioral advertising.

Section 5

Cookies and Similar Technologies

We and our service providers use cookies, browser local and session storage, and similar technologies on the Site.

Category
Purpose
Set by
Strictly necessary
Security, load balancing, page delivery, and site function. The Site does not work without these.
Us and our hosting provider
First-party analytics and marketing platform
Our CRM recognizes returning visitors and measures which pages and content are effective. Used by us, in our own systems.
HubSpot, on our behalf

We do not currently run third-party advertising, retargeting, or cross-site tracking tags on the Site. We do not share Site visitor information with advertising networks.

We do not use session replay or session recording technology. We do not record, reconstruct, or play back your visit, and we do not capture your mouse movements, scrolling, keystrokes, or anything you type into a field before you submit it.

5.1 Managing cookies

Most browsers let you block or delete cookies and offer a private browsing mode. Blocking strictly necessary cookies may prevent parts of the Site from working. You can opt out of HubSpot’s tracking through your browser settings.

5.2 Global Privacy Control

We honor the Global Privacy Control (“GPC”) signal where your browser sends one. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing further for a GPC signal to opt you out of.

5.3 Email measurement

The measurement described in Section 2.2 — open tracking and click tracking in our email — is first-party and is not affected by browser cookie settings. Stop it by turning off remote images in your email client, or by unsubscribing (Section 6.1).

5.4 If this changes

If we add advertising or analytics tags in the future, we will update this policy before doing so and will implement a consent tool that blocks those tags until you allow them and that automatically honors Global Privacy Control. The commitment above not to use session replay is not conditional and does not change.

Section 6

Your Choices

6.1 Marketing email

Every marketing email includes an unsubscribe link. You can also email privacy@medicaltargets.com and ask to be removed. We will honor the request promptly. We may still send you transactional messages about a service you have requested.

6.2 Telephone and text

If you gave us a telephone number and would rather we did not call or text, tell us — by reply, on a call, or by email to privacy@medicaltargets.com — and we will add you to our internal do-not-contact list. You may revoke consent to calls or texts by any reasonable means, and we will honor it across all channels we control. To honor a do-not-contact request, we retain the minimum record needed to keep the suppression in effect.

6.3 Advertising cookies

We do not currently use advertising or retargeting cookies on the Site. If that changes, we will update this policy first and provide a consent control — see Section 5.4.

6.4 Deletion and other requests

See Section 7.

Section 7

California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended, gives you the rights below. We extend these rights to all Site visitors regardless of where you live.

  • Right to know — what personal information we collected about you, the sources, our purposes, the categories of third parties we disclosed it to, and the specific pieces we hold.
  • Right to delete — ask us to delete personal information we collected from you, subject to legal exceptions.
  • Right to correct — ask us to correct inaccurate personal information.
  • Right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of. If that changes we will update this policy and provide a control before it does.
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information through the Site, so there is nothing to limit.
  • Right against discrimination — we will not deny you service, charge a different price, or provide a lesser quality of service because you exercised a privacy right.

7.1 How to make a request

Email privacy@medicaltargets.com with the subject line “Privacy Request.” Tell us which right you are exercising and give us an email address or telephone number we can match to our records.

We will confirm receipt within 10 business days and respond within 45 calendar days. If we need more time we will tell you and may take up to 90 days in total.

Verification. We will ask you to confirm information we already hold — typically the email address you submitted and the content you requested — so that we do not disclose or delete anyone’s information on the wrong person’s say-so. We will not ask for sensitive documents.

Authorized agents. An agent may submit a request on your behalf with written permission signed by you. We may contact you directly to confirm.

7.2 Categories of information collected in the last 12 months

CCPA category
Collected?
Examples
Identifiers
Yes
Name, business email, phone, IP address
Customer records (Cal. Civ. Code § 1798.80)
Yes
Name, business contact details
Commercial information
Yes
Content downloaded, services inquired about
Internet or network activity
Yes
Pages viewed, referring URL, browser and device
Geolocation
Coarse only
Approximate city or region from IP address
Professional or employment information
Yes
Company, role, practice details
Protected classifications
No
Biometric information
No
Sensitive personal information
No
Education information
No
Inferences used to build a profile
Limited
Advertising platforms may build audience segments from Site activity, subject to your cookie choices

Sources, purposes, and disclosure recipients are described in Sections 2, 3, and 4.

7.3 Retention

We keep information only as long as needed for the purposes described in this policy.

Marketing contact. If you do not engage with us — no opens, clicks, replies, or meetings — for twelve (12) months, we stop sending you marketing communications. We do this automatically; you do not have to ask.

Business records. After that point we retain your business contact record — name, business email, company, role, and the history of our dealings — as an ongoing business record for as long as we operate, unless you ask us to delete it. We keep it because business relationships in our industry develop over long periods, and a contact who is not in market this year may be next year. A retained record is not a marketing record: we will not resume sending you marketing communications based on it unless you re-engage with us or ask us to.

You can end this at any time. Ask us to delete your information under Section 7.1 and we will, subject to the exceptions below.

Information
Retention
Marketing communications to you
Stops after 12 months with no engagement
Business contact record in our CRM
Retained as a business record until you request deletion
Meeting and correspondence records
Retained as a business record until you request deletion
Site analytics
Aggregate and non-identifying; retained up to 26 months
Do-not-contact and unsubscribe records
Retained indefinitely and never deleted, because deleting them would cause us to contact you again. We keep only the minimum needed to keep the suppression in effect.
Business and accounting records
As required by law, generally 7 years

Exceptions to deletion. Where we must retain information to comply with a legal obligation, to keep accounting records, to honor your do-not-contact request, or to establish or defend a legal claim, we will keep only what is necessary for that purpose and will tell you when we respond to your request.

Section 8

Other State Privacy Rights

If you live in a state with a comprehensive privacy law — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others — you have comparable rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising and profiling. Use the same process in Section 7.1. Where your state provides a right to appeal a denied request, you may appeal by replying to our response, and we will answer within the time your state’s law requires.

Section 9

Data Security

We maintain administrative, technical, and physical safeguards appropriate to the limited information we collect through the Site, including access controls, multi-factor authentication on business systems, encryption in transit, and vendor review. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please do not send sensitive personal or health information to us by email.

9.1 Security incidents

If we experience a security incident affecting personal information we hold, we will investigate promptly, take steps to contain and remediate it, and — where required by applicable law — notify affected individuals and the relevant regulators within the timeframes that law requires. Where the incident affects information we process on behalf of a client, we will notify that client so they can meet their own obligations.

Section 10

Information We Process for Our Clients

When we provide services to a client practice, we process information at that client’s direction and on their behalf. In that role we are a service provider under the CCPA and a processor under comparable laws. We do not sell or share that information, we do not use it for our own purposes, and we do not combine it with information from other sources except as the CCPA permits.

Our services are not intended to process Protected Health Information (“PHI”), and our client agreements instruct clients not to provide PHI to us. We are not engaged as a HIPAA Business Associate. If PHI reaches us unintentionally, our agreements require prompt notification and deletion, and we do not use or further disclose it.

If you were contacted by us on behalf of a practice and want to know how your information is handled, or want to be removed, email privacy@medicaltargets.com. We will suppress you from further contact across our programs and will pass your request to the relevant client. For requests about that client’s own records, contact the practice directly — their privacy policy governs.

Section 11

Artificial Intelligence

We use artificial intelligence tools to help draft and refine content, summarize conversations, research and organize business contact data, and automate routine workflow steps.

We do not use your personal information to train, fine-tune, or improve any artificial intelligence model. We select AI services whose terms, at the service tier we use, provide that customer content is not used to train that provider’s publicly available models, and we configure available settings to that effect. Providers may retain content for a limited period for security, abuse monitoring, and legal compliance as described in their own terms; those retention periods are set by the provider and are not within our control.

A person reviews content produced with AI assistance before it is sent or published. We do not use AI to make automated decisions that produce legal or similarly significant effects about you. We limit what we submit to AI tools to what is reasonably necessary for the task.

Section 12

International Visitors and Legal Bases

The Site is operated in the United States and intended for United States businesses. If you access it from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those of your country.

Legal bases. Where a data protection law applies to our processing and requires us to identify a legal basis, we rely on: our legitimate interests in operating, securing, and marketing our business to other businesses; your consent, where consent is required and you have given it; performance of a contract with you or steps taken at your request before entering one; and compliance with a legal obligation. Where we rely on legitimate interests, you may object to that processing, and where we rely on consent, you may withdraw it at any time, in each case by emailing privacy@medicaltargets.com. We are not established in the European Union or the United Kingdom and do not offer goods or services to individuals there.

Section 13

Third-Party Sites

The Site links to third-party websites, research sources, and scheduling tools that we do not control. This policy does not apply to them. Review their privacy policies before providing information.

Section 14

Changes to This Policy

We may update this policy. We will post the revised version with a new “Last updated” date, and for material changes we will provide notice on the Site. Your continued use of the Site after the effective date means you accept the revised policy.

Section 15

Governing Law and Accessibility

Governing law. This policy is governed by the laws of the State of California, except where another applicable privacy law provides you with additional or different rights, in which case that law applies to the extent it does so.

Accessibility. If you need this policy in an alternative format, or need assistance exercising any right described in it, email privacy@medicaltargets.com and we will accommodate the request.

Section 16

Contact Us

Questions, requests, or complaints:

Contact
Data Services Direct, LLC d/b/a Medical Targets
2160 Ridgemont Drive
Los Angeles, CA 90046
privacy@medicaltargets.com

For privacy requests, use the subject line “Privacy Request.”