Operational privacy
Purpose and relationship to our Privacy Policy
This page explains how data-protection roles work when TEA supports a business customer's platform, product, automation, website, campaign, implementation, or managed service. It supplements our Privacy Policy and does not replace a signed data-processing agreement (“DPA”) or product-specific terms.
Privacy terminology varies by law. “Controller” includes a business that determines why and how personal data is processed. “Processor” includes a service provider that processes personal data under that controller's instructions.
Who decides what
Controller and processor roles
Ask Michael Chandler LLC generally acts as a controller for information used to operate TEA's own websites, sales, accounts, billing, support, security, analytics, and business relationships.
A TEA business customer generally acts as controller for personal data it collects, uploads, connects, generates, or directs through a TEA-supported system. For that data, TEA may act as a processor or service provider, while platform, hosting, communications, AI, and integration providers may act as subprocessors.
Customer obligations
Lawful instructions and responsible configuration
Business customers are responsible for providing required privacy notices; identifying a lawful basis; collecting valid consent where needed; honoring opt-outs; limiting access; selecting appropriate retention; keeping data accurate; assessing sensitive or regulated uses; and ensuring their instructions comply with applicable privacy, employment, marketing, communications, and industry laws.
Customers should not place sensitive personal data into a Service unless the applicable agreement and configuration expressly support it. Payment-card credentials, protected health information, government identity credentials, biometric data, precise location, children's data, and other regulated categories may require separate safeguards or may be prohibited.
TEA may refuse an instruction that appears unlawful, insecure, outside the agreed scope, or incompatible with provider terms. We may ask the customer to clarify, correct, or document the instruction.
The service chain
Processing, confidentiality, and service providers
TEA processes customer data to provide, configure, support, secure, troubleshoot, measure, and improve the Services; follow documented customer instructions; prevent fraud and abuse; and meet legal obligations. Authorized personnel are expected to handle data confidentially and only for approved business purposes.
TEA relies on providers for functions such as cloud hosting, CRM and platform infrastructure, communications, scheduling, payment processing, identity, analytics, AI, integrations, security, and professional operations. The providers involved depend on the spokes a customer activates. We evaluate service providers appropriate to their role and use contractual or technical controls where reasonably available.
A signed DPA may provide a current subprocessor list, notice method, processing details, and additional commitments. If a customer requires a DPA, contact TEA before placing regulated personal data into the Services.
Requests from individuals
Access, correction, deletion, and other rights
Individuals may have rights to access, correct, delete, restrict, port, object to, or receive information about processing, and to withdraw consent or complain to a supervisory authority. The available rights and exceptions depend on applicable law and the processing context.
When TEA controls the relevant information, submit a request to support@ask4tea.com. We may verify identity and authority before acting. When a TEA customer controls the information, the individual should contact that customer first. TEA will provide reasonable assistance to the customer as required by the agreement and law.
Customers are responsible for ensuring their account settings, workflows, connected systems, archives, and downstream exports are included when responding to a request.
Risk-based safeguards
Security, availability, and incident response
TEA uses measures designed for the nature of the information and Services involved. Depending on context, these may include role-based access, authentication, secure transmission, logging, backups, vendor controls, employee or contractor confidentiality, change management, monitoring, and incident procedures.
No environment is immune from error, attack, provider failure, or interruption. Customers share responsibility for configuring users and permissions, protecting credentials, maintaining appropriate backups, reviewing security notices, and using supported integrations.
If TEA confirms a personal-data incident affecting customer-controlled data, TEA will notify the affected customer as required by the applicable agreement and law and provide reasonably available information to support the customer's response. The customer remains responsible for notifications it must provide as controller unless law assigns that duty otherwise.
Data may cross borders
International processing and transfers
TEA is based in the United States, and TEA or its providers may process information in the United States and other countries. Those countries may have privacy laws different from the place where the information originated.
Where the GDPR, UK GDPR, or another law requires a transfer mechanism, the applicable agreement may use Standard Contractual Clauses, a recognized certification framework, an adequacy decision, or another lawful safeguard. Provider-specific transfer terms and locations may also apply.
From collection through deletion
Retention, return, deletion, and backups
Customers should configure retention based on purpose, law, and business need. During an active relationship, TEA retains customer data as needed to provide and secure the Services. After termination, export, return, deletion, or continued retention depends on the agreement, product capability, provider lifecycle, legal duties, dispute needs, and backup schedules.
Customers should request eligible exports before access ends and maintain independent records where continuity matters. Residual copies may remain temporarily in backups, logs, fraud-prevention systems, financial records, or legal archives and will be isolated or deleted according to applicable retention processes.
Contracts and questions
Data-processing agreements and contact
To ask a privacy question, submit a rights request, report a suspected incident, or request a DPA for an eligible service relationship, email support@ask4tea.com or call 1 (855) 912-7563.
Ask Michael Chandler LLC operates The Entrepreneurs Advantage. Visit the Legal Center for our Privacy Policy, Terms of Service, and Disclaimers.
