1. Who We Are
SAINT Management Group LLC (d/b/a SAINT Technology Services) (“SAINT,” “we,” “us,” or “our”) is a managed service provider headquartered in Lincoln, Nebraska, serving clients throughout Nebraska, Kansas, Missouri, Iowa, and remotely across the United States. We provide managed IT, co-managed IT, cybersecurity, business security cameras, access control, video surveillance, network design, backup and disaster recovery, Microsoft 365 and Google Workspace management, risk advisory and vCISO services, and related physical security services.
Contact:
- Mailing address: Shamrock Plaza, Lincoln, Nebraska (full street + suite on request)
- Phone: 531-625-2112
- Email: [email protected]
2. Scope of This Policy
This Policy applies to personal information we collect through saintsecured.com (the “Site”), our marketing and sales communications, our client onboarding and support workflows, and our SMS, voice, and email channels. When SAINT processes personal information on behalf of a client under a Master Services Agreement, Business Associate Agreement, or Data Processing Addendum, that agreement governs and this Policy is secondary to the extent of any conflict.
3. Information We Collect
3.1 Information You Provide
- Contact details submitted through web forms, email, phone, or in-person meetings, including name, business name, job title, business email, business phone, and the substance of your inquiry.
- Account and billing information for clients, including authorized-signer identity, billing contacts, purchase orders, and payment instrument metadata (we do not store full payment card numbers; card processing occurs through our PCI-DSS compliant payment processor).
- Content of correspondence with us, including support tickets, emails, chat messages, and voicemail.
- Information you provide when scheduling calls, requesting quotes, downloading resources, or subscribing to updates.
3.2 SMS Opt-In Data
If you provide your mobile number and opt in to receive SMS from SAINT, we collect and store the mobile number, the date and time of consent, the source of consent (web form, written agreement, or verbal confirmation logged in our ticketing system), the specific program you opted into, and the IP address associated with a web opt-in. Mobile opt-in data and consent records are stored solely to operate the SMS program and to demonstrate compliance to carriers and regulators. See Section 10 for the full SMS terms.
3.3 Phone Call Information
We may record inbound and outbound phone calls for quality assurance, training, dispute resolution, and creation of accurate ticket documentation. Nebraska is a one-party consent jurisdiction under Neb. Rev. Stat. § 86-290, as are our other primary service states (Iowa, Kansas, Missouri). When we call or receive calls from residents of two-party consent states, we announce the recording at the start of the call or disable recording for that call. Recordings and associated metadata (caller number, called number, timestamp, duration) are retained per Section 8.
3.4 Client Service Data
To deliver managed IT, cybersecurity, and physical security services, we collect and process data from client systems, including:
- Endpoint inventory, hardware and software configuration, patch status, and event logs collected through our remote monitoring and management (RMM) platform.
- Security telemetry from endpoint detection and response (EDR), managed detection and response (MDR), email security, identity, and network sensors.
- Administrative and service credentials, API tokens, and shared secrets required to manage client environments, stored in an access-controlled password management system.
- Ticket contents, attachments, and communications from client end users seeking support.
- Video, audio, and access-control event data from client physical security systems when SAINT is contracted to host, monitor, or maintain such systems.
For healthcare clients, SAINT executes a HIPAA Business Associate Agreement before creating, receiving, maintaining, or transmitting Protected Health Information. For municipal and law-enforcement clients whose systems fall within Criminal Justice Information Services (CJIS) scope, SAINT complies with the applicable CJIS Security Policy and executes any required addenda.
3.5 Website Analytics, Cookies, and Similar Technologies
The Site is hosted on Cloudflare Pages. We use Cloudflare's privacy-preserving web analytics, which measures aggregate traffic without setting user-identifying cookies and without cross-site tracking. We may set strictly necessary cookies to support form submissions, security controls, and load balancing. If we deploy any advertising, remarketing, or analytics cookies that are not strictly necessary, we will present a consent mechanism before setting them and will honor Global Privacy Control and other recognized universal opt-out signals where required by law.
3.6 Information From Third Parties
We may receive information about you from your employer when you are a designated contact for a client organization, from cybersecurity threat-intelligence providers, from public records for KYB/AML checks on prospective clients, and from tools that identify the organization associated with a business IP address that visits the Site.
4. How We Use Information
We use the categories of information above to:
- Provide, maintain, monitor, and improve our services.
- Communicate with you about proposals, contracts, invoices, tickets, incidents, security advisories, scheduled maintenance, and service changes.
- Send transactional and service-related SMS, email, and phone communications you have consented to receive.
- Investigate, detect, prevent, and respond to security incidents, fraud, and abuse.
- Meet legal, regulatory, contractual, tax, insurance, and audit obligations.
- Enforce our Terms of Service and Master Services Agreement.
- Conduct internal research, business analytics, capacity planning, and product development on aggregated or de-identified data.
We do not use client service data to train third-party generative AI models, and we do not use it for marketing to your end users.
5. Legal Bases for Processing
For visitors and clients protected by the EU or UK General Data Protection Regulation, we rely on the following legal bases:
- Performance of a contract, for delivery of services under a signed engagement.
- Legitimate interests, for security monitoring, service improvement, business communications with existing clients, and enforcement of our rights, balanced against your interests.
- Consent, for marketing SMS and email, non-essential cookies, and any processing of special-category data where consent is the appropriate basis.
- Compliance with a legal obligation, for tax records, incident-reporting duties, and lawful demands from public authorities.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
7. Data Security
We maintain a written information security program aligned with industry frameworks (NIST CSF, CIS Controls, and, where applicable to the engagement, SOC 2, HIPAA Security Rule, and CJIS Security Policy). Controls include:
- Encryption of personal information in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent) in our production systems.
- Role-based access control, least-privilege provisioning, and multifactor authentication for all administrative access.
- Secrets management for client credentials with per-technician access logging and rotation.
- Vulnerability management, endpoint hardening, EDR/MDR on staff endpoints, and continuous logging with a 24/7 SOC workflow.
- Documented incident response, tabletop testing, and vendor risk management.
- Background checks on personnel with access to client environments, and mandatory security awareness training.
No system is perfectly secure. If we experience a breach of security involving personal information, we will notify affected individuals and clients as required by applicable state breach-notification laws (including Nebraska's Financial Data Protection and Consumer Notification of Data Security Breach Act, Neb. Rev. Stat. § 87-801 et seq.), applicable federal law (including HIPAA for PHI), and our contractual commitments to clients.
8. Data Retention
We retain personal information only for as long as needed to fulfill the purposes described in this Policy or as required by law.
| Category | Retention |
|---|---|
| Website inquiry submissions | 24 months after last contact |
| Marketing email and SMS lists | Until opt-out; suppression record kept indefinitely |
| Client ticket data and correspondence | Duration of engagement plus 7 years |
| Billing and tax records | 7 years, or longer where required |
| Call recordings | 90 days by default; longer for active matters |
| Security telemetry and logs | 12 months, or longer for active investigations |
| Backups of client data | Per the Statement of Work retention schedule |
| SMS consent records | Duration of consent plus 4 years (carrier / CTIA expectation) |
At the end of a client engagement, we return or destroy client data in accordance with the offboarding provisions of the applicable agreement.
9. Your Rights and Choices
Depending on where you reside, you may have some or all of the following rights: to confirm whether we process your personal information; to access it; to correct inaccuracies; to delete it; to obtain a portable copy; to opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and certain profiling; and to appeal a denial of your request. We will not discriminate against you for exercising any of these rights.
These rights are established under state comprehensive privacy laws including:
- Nebraska Data Privacy Act (effective January 1, 2025)
- California Consumer Privacy Act / CPRA
- Virginia Consumer Data Protection Act
- Colorado Privacy Act
- Connecticut Data Privacy Act
- Utah Consumer Privacy Act
- Texas Data Privacy and Security Act
- Oregon Consumer Privacy Act
- Montana Consumer Data Privacy Act
- Florida Digital Bill of Rights
- Delaware Personal Data Privacy Act
- Iowa Consumer Data Protection Act
- New Hampshire Privacy Act
- New Jersey Data Privacy Act
- Maryland Online Data Privacy Act
- Minnesota Consumer Data Privacy Act
- Tennessee Information Protection Act
- Indiana Consumer Data Protection Act
- Kentucky Consumer Data Protection Act
- Rhode Island Data Transparency & Privacy Protection Act
To exercise a right, email [email protected] with the subject line “Privacy Request” or call 531-625-2112. We will verify your identity through reasonable means proportionate to the request (for example, matching information you provide to information we already hold, or, for account-holders, authenticated login). We will respond within the timeframe required by the applicable law, generally 45 days, with one 45-day extension when reasonably necessary. If we decline your request, we will explain why and, where applicable, how to appeal.
You may also designate an authorized agent to make a request on your behalf. We may require the agent to provide written authorization signed by you and, in some cases, verification of your identity.
Where we process personal information on behalf of a client, we will refer your request to that client and assist them in responding.
10. SMS and Text Messaging
SAINT operates SMS programs through Twilio in compliance with the Application-to-Person 10DLC framework and CTIA Messaging Principles and Best Practices.
10.1 What You Are Consenting To
By providing your mobile number to SAINT and completing an opt-in (checking an unchecked box on a web form, texting an opt-in keyword to us, signing an agreement that authorizes SMS, or verbally consenting during a recorded call), you agree to receive SMS from SAINT Technology Services LLC related to one or more of the following programs, as applicable:
- Service and support: ticket updates, technician arrival notices, incident and outage alerts, appointment confirmations and reminders, maintenance windows.
- Account and billing: invoice availability, payment reminders, account changes.
- Security notices: multifactor challenges, phishing simulation follow-ups, urgent security advisories.
- Informational updates: policy changes, feature releases, periodic client newsletters.
We do not send purely promotional or third-party marketing SMS through this program.
10.2 Message Frequency
Message frequency varies based on your relationship with SAINT and the events triggering messages. Ticket and incident volumes can produce multiple messages per day; informational messages are typically no more than a few per month.
10.3 Message and Data Rates
Message and data rates may apply. Check your mobile plan for details. SAINT does not charge for the SMS itself.
10.4 HELP
Reply HELP to any SAINT SMS to receive a message identifying SAINT Management Group LLC (d/b/a SAINT Technology Services), our support email ([email protected]), and our support phone (531-625-2112).
10.5 STOP
Reply STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any SAINT SMS to opt out. Opt-out requests are processed immediately, and you will receive one final confirmation message. After that, we will not send further SMS from that program to your number, except that you will still receive any legally required communications by other means. To rejoin, opt in again by the same method you used originally, or contact us.
10.6 Carriers
Carriers, including but not limited to AT&T, T-Mobile, Verizon, and their subsidiaries and MVNOs, are not liable for delayed or undelivered messages.
10.7 No Sharing of Mobile Opt-In Data
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as our SMS platform provider (Twilio) and our ticketing platform (Syncro), is permitted solely to deliver the messages you have requested. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
10.8 Consent Records
We record the date, time, source, and specific program of each opt-in and each opt-out and retain those records to demonstrate compliance to carriers and regulators.
10.9 SMS Support
For questions about our SMS program, email [email protected] or call 531-625-2112.
11. Phone Call Recording
As described in Section 3.3, SAINT may record telephone calls for quality assurance, training, and accurate documentation. Nebraska and our other primary service states permit recording with the consent of one party to the call, and our participation on the call constitutes that consent. If you do not wish to be recorded, tell the SAINT team member on the call and we will either disable recording for that call or complete the call by email or written ticket instead.
12. Children's Privacy
The Site and our services are directed to businesses and their authorized personnel. We do not knowingly collect personal information from children under 13, and our services are not designed for use by children. If we learn we have collected personal information from a child under 13 in violation of the Children's Online Privacy Protection Act (COPPA), we will delete it. If you believe we have collected such information, contact [email protected].
13. International Users
SAINT is based in the United States and processes information in the United States. If you access the Site or communicate with us from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, which may have data-protection laws different from those in your country. Where required, we implement appropriate safeguards for cross-border transfers, including standard contractual clauses.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will change the “Effective” date at the top and, if the changes are material, we will provide additional notice such as a Site banner or email to clients. Your continued use of the Site or our services after the effective date of the updated Policy constitutes acceptance of the changes.
15. Contact Us
For privacy questions or to exercise your rights, contact:
SAINT Management Group LLC (d/b/a SAINT Technology Services)
Attn: Privacy
Shamrock Plaza, Lincoln, Nebraska
Email: [email protected]
Phone: 531-625-2112
