Privacy Policy
Introduction
Baywell Advanced Systems LLC (“Company,” “we,” “us,” or “our”) is a Managed Service Provider (“MSP”) offering managed IT services, cybersecurity, cloud solutions, and related consulting services. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website or engage with our services.
This policy applies to:
- Visitors to our website
- Prospective clients
- Clients receiving managed or professional services
Scope and role of the Company
2.1 Website and marketing data (controller role)
For personal information collected through our website or marketing activities, Baywell Advanced Systems LLC acts as a data controller/business, determining the purposes and means of processing.
2.2 Managed services data (processor/service provider role)
When providing managed services to clients, Baywell Advanced Systems LLC acts as a service provider/processor on behalf of its clients. In these cases:
- The client is the data controller/business
- We process data strictly in accordance with client instructions and contractual agreements (e.g., MSA, SOW, BAA)
California privacy rights (CCPA/CPRA)
If you are a California resident, you may have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
Rights for direct interactions with us
For personal information we collect directly (e.g., via our website or marketing activities), you may have the right to:
- Request access to the personal information we collect about you
- Request deletion of your personal information
- Request correction of inaccurate information
- Opt out of the sale or sharing of personal information (note: we do not sell personal information)
- Limit the use of sensitive personal information (if applicable)
To exercise these rights, please contact us at: contact@baywell.net
Information processed on behalf of clients
When we process personal information as part of managed services:
- We act as a service provider under CCPA/CPRA
- We process data solely on behalf of our clients
If your personal information is maintained by one of our clients, you must direct your request to that client (the data controller/business). We will assist our clients in responding to such requests as required by law and our contractual obligations.
Non-discrimination
We will not discriminate against you for exercising your privacy rights.
Information we collect
3.1 Information you provide
- Name, email, phone number
- Company name and job title
- Information submitted via contact forms or communications
3.2 Automatically collected information
- IP address
- Browser type and device information
- Website usage data (e.g., pages visited, session duration)
3.3 Client service data
In the course of providing services, we may process:
- System configurations and network data
- User account and authentication data
- IT infrastructure and security logs
- Business data hosted or managed on client systems
We do not use client service data for our own independent purposes.
Use of information
We use collected information to:
- Respond to inquiries and provide services
- Manage client relationships and contracts
- Maintain and secure IT systems
- Improve our website and service offerings
- Comply with legal and regulatory obligations
We do not sell personal information.
HIPAA and protected health information (PHI)
We are not a healthcare provider. However, we may act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when supporting covered entities.
- We only handle PHI pursuant to a signed Business Associate Agreement (BAA)
- PHI is processed solely under client direction
- Our website is not intended for submission of PHI
If PHI is submitted outside of authorized channels, it will be handled in accordance with applicable laws and contractual obligations.
Client responsibilities
Clients are solely responsible for:
- Ensuring lawful collection and use of personal data
- Providing appropriate privacy notices to their end users
- Obtaining required consents or authorizations
- Complying with applicable laws (e.g., HIPAA, PCI-DSS, CCPA)
Baywell Advanced Systems LLC does not assume responsibility for client compliance obligations beyond those explicitly defined in written agreements.
Disclosure of information
We may disclose information to:
7.1 Service providers (subprocessors)
We engage trusted third-party providers (e.g., cloud hosting, IT tools, legal/accounting services). These providers:
- Are contractually bound by confidentiality obligations
- Must implement appropriate security safeguards
- May only process data for authorized purposes
7.2 Legal and regulatory authorities
We may disclose information:
- To comply with legal obligations
- To protect rights, property, or safety
- In connection with lawful requests by public authorities
Data security
We implement administrative, technical, and physical safeguards designed to protect information, including:
- Role-based access controls (RBAC)
- Multi-factor authentication (MFA)
- Encryption in transit and at rest
- Logging and monitoring systems
- Periodic security reviews and risk assessments
No system can be guaranteed to be 100% secure.
Data retention
We retain information as follows:
- Website inquiries up to 24 months
- Client data duration of the engagement plus applicable legal retention periods
- System logs typically 90 days unless required longer for security or compliance
Data breach and incident response
In the event of a data incident, we will:
- Investigate and contain the issue promptly
- Notify affected clients without undue delay in accordance with contractual obligations (e.g., MSA, BAA)
- Comply with applicable breach notification laws
Clients are responsible for notifying their end users unless otherwise agreed in writing.
Cookies and tracking technologies
We may use limited cookies or similar technologies to:
- Ensure website functionality
- Analyze basic usage trends
We do not use invasive tracking or sell behavioral data.
Your privacy rights
Depending on your jurisdiction, you may have rights to:
- Access personal information
- Request correction or deletion
- Opt out of certain data uses
Requests can be submitted to: contact@baywell.net
Nevada privacy rights
Under Nevada law (NRS 603A), Nevada residents have the right to request that a business not sell certain personal information to third parties.
Baywell Advanced Systems LLC does not sell personal information as defined under Nevada law.
However, Nevada residents may submit a verified request to opt out of any potential future sale of their personal information by contacting us at: contact@baywell.net
Data location and transfers
Data is primarily stored and processed in the United States using secure cloud providers. We do not intentionally transfer data internationally unless required for service delivery and subject to appropriate safeguards.
Third-party links
Our website may contain links to third-party websites. We are not responsible for their privacy practices.
Children’s privacy
This website and our services are directed at businesses, not children. We do not knowingly collect personal information from individuals under 16 years of age (or the applicable age of consent in their jurisdiction). If you believe a child has provided us with personal information, please contact us at contact@baywell.net and we will promptly delete it.
Contractual supremacy
This Privacy Policy is provided for transparency purposes only.
In the event of a conflict between this Privacy Policy and any executed agreement (including but not limited to a Master Service Agreement (MSA), Statement of Work (SOW), or Business Associate Agreement (BAA)), the terms of the executed agreement shall control.
Changes to this policy
We may update this Privacy Policy periodically. Updates will be posted on this page with a revised effective date.
Contact information
- Company Baywell Advanced Systems LLC
- Address2880 Bicentennial Pkwy, Suite 100, PMB 210
Henderson, NV 89044 - Email contact@baywell.net
- Phone (408) 229-9355
For privacy-related inquiries, please contact us at the email above.