Privacy Policy
ELMIDA Solutions is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your information.
We collect contact details you give us, and basic analytics about how you use this site. No third-party tracking loads until you consent. Our website platform keeps a simple, cookieless count of page visits that runs either way. We do not sell your information and we do not share it for advertising. Our forms and CRM run on GoHighLevel. We use Google Analytics and Microsoft Clarity to understand how the site is used. You can change your cookie choices any time from the footer.
1. Introduction
ELMIDA Solutions ("we," "us," or "our") provides managed IT and cybersecurity services to small and mid-sized law firms in New York City. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit www.elmidasolutions.com and our other tools hosted on subdomains of elmidasolutions.com (together, the "Site"), or engage us for services.
We take this seriously for a reason beyond compliance. Our clients are attorneys with confidentiality obligations to their own clients. Handling data carefully is the product.
ELMIDA Solutions
6614 Avenue U, Ste #1056
Brooklyn, NY 11234
[email protected]
(646) 825-3900
2. Information We Collect
2.1 Information you provide
- Contact information: First name, last name, email address, phone number
- Firm information: Firm name, firm size, practice area, current IT setup, anything you tell us in a form or conversation
- Account information: Login credentials, billing information, service preferences (clients only)
- Communication records: Correspondence with our team, support tickets, service requests, feedback
Our contact, assessment, and booking forms are hosted by GoHighLevel (LeadConnector) and submit directly to GoHighLevel's platform. Information you type into those forms goes to GoHighLevel, which is our CRM and email/SMS provider.
2.2 Information collected automatically
Everything in this section is blocked until you consent, with one exception: our website platform collects basic first-party analytics on every visit. That exception is described in 2.4.
- Device and connection data: IP address, browser type and version, operating system, device type, screen size
- Usage data: Pages viewed, time on page, referring URL, links clicked, navigation paths
- Approximate location: City or region, derived from IP address
- Session recordings: Mouse movement, scrolling, clicks, page interactions (see 2.3)
2.3 Third-party tracking technologies (consent required)
We use the following. None of them load until you consent. If you decline, they are never downloaded and these companies receive nothing.
Google Analytics 4 (Google LLC). Measures traffic and how visitors move through the Site. Collects IP address, device and browser data, pages viewed, and events such as form submissions. The Google Analytics script is not downloaded at all unless you consent, so Google receives nothing before then. Privacy policy: https://policies.google.com/privacy
Microsoft Clarity (Microsoft Corporation). A session replay and heatmap tool. Clarity records a reconstruction of your visit, including mouse movement, clicks, scrolling, and page interactions, and lets us play it back to understand where the Site is confusing. Clarity is configured with "Strict" masking enabled, which obscures page text in recordings. Clarity cannot record inside third-party embedded frames, which is where all of our forms are hosted, so anything you type into our contact, assessment, or booking forms is not captured by Clarity. Privacy statement: https://privacy.microsoft.com/privacystatement
GoHighLevel / LeadConnector (HighLevel Inc.). Our CRM. Besides hosting our forms, LeadConnector places a tracking script that associates visits with contact records, so that if you later submit a form we can see which pages you viewed. Collects IP address, device data, and page views. Privacy policy: https://www.gohighlevel.com/privacy-policy
2.4 First-party platform analytics (always on)
Our website is built and hosted on Lovable (Lovable Labs). The platform collects basic analytics on every visit, and this is not gated by the cookie banner. It records pages viewed, the referring source, approximate country, device type, and session length.
We keep it running for two reasons. It is first-party, meaning it reports to our own website address rather than sending your activity to an outside advertising or analytics company. And it is cookieless, meaning it stores nothing on your device and cannot follow you to any other website. It tells us how many people read a given page. It does not build a profile of you.
If you decline cookies, this is the only measurement that still runs.
2.5 Information from third parties
- Referral sources and business partners
- Public databases and professional directories
2.6 Client system data
As a managed service provider, delivering contracted services gives us access to client systems. Depending on scope, this can include:
- System data: network configuration, device inventories, software inventories, patch status, security telemetry
- User information: employee names, email addresses, authentication and access logs
- Business data: files, email, and other information on systems we manage, which for a law firm may include privileged and confidential client material
We do not own or control this data. We act as a service provider and access it only as needed to deliver contracted services. Our handling of it is governed by our Master Service Agreement, not by this Privacy Policy. See Section 10.
3. How We Use Information
- Deliver services: IT support, cybersecurity monitoring, backup, Microsoft 365 administration, and other contracted work
- Respond to inquiries: Answer questions submitted through forms, email, or phone
- Improve the Site: Analyze aggregate usage to fix what is confusing or broken
- Service communications: Security alerts, maintenance notices, incident notifications, account matters
- Marketing: Information about our services, industry guidance, and resources, where you have opted in or where permitted by law
- Security: Threat monitoring, fraud prevention, protecting our systems and clients
- Legal and regulatory: Meeting our obligations and responding to lawful requests
- Business operations: Billing, account management, documentation, records
3.1 Email marketing
Marketing emails include a clear unsubscribe link, our physical address, and an accurate subject line. Opt out any time via the unsubscribe link, or contact [email protected] or (646) 825-3900. We honor opt-outs within 10 business days. We comply with the CAN-SPAM Act.
Unsubscribing from marketing does not stop service or security communications to active clients.
3.2 SMS
If you opt in to SMS, we may send customer care messages, appointment reminders, account notifications, service alerts, and verification codes. Message frequency varies. Message and data rates may apply. Text STOP to opt out, HELP for help. SMS consent is not a condition of purchasing services.
Phone numbers collected for SMS, and your SMS consent, are never shared with third parties or affiliates for their own marketing purposes.
4. How We Disclose Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We disclose information to:
Service providers, under contract, for the purposes above:
- Google LLC: Analytics
- Microsoft Corporation: Analytics and session replay
- HighLevel Inc. (GoHighLevel): CRM, forms, email, SMS
- Lovable Labs: Website platform, hosting, first-party analytics
- Content delivery providers: Serving the Site and its content
Business transfers. In a merger, acquisition, or sale of assets, information may transfer as part of the transaction.
Legal requirements. To comply with law, respond to lawful requests or court orders, protect the rights, property, or safety of ELMIDA Solutions, our clients, or others, and enforce our agreements.
With your consent. For anything else.
5. Data Security
We maintain technical and organizational safeguards, including:
- Encryption of data in transit and at rest where applicable
- Access controls limiting who can reach client data, on a least-privilege basis
- Security monitoring for threats and vulnerabilities
- Employee training on security awareness
- Vendor management, including due diligence and contractual safeguards
These are designed to meet the reasonable safeguards requirement of the New York SHIELD Act (Section 9).
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and any policy claiming otherwise is not being straight with you.
6. Data Retention
- Website inquiries: As long as needed to respond, plus our business records period
- Marketing list: Until you unsubscribe or request deletion
- Lovable platform analytics: Per Lovable's retention policy
- Google Analytics data: 14 months
- Microsoft Clarity session recordings: 30 days
- Microsoft Clarity aggregate and heatmap data: Up to 13 months
- Client data: Duration of the service relationship
- Client data post-termination: 30 days after termination unless law or agreement requires otherwise, then securely deleted
- Billing and tax records: As required by law
Microsoft Clarity retention periods are set by Microsoft and are not configurable by us.
7. Your Privacy Rights
7.1 Everyone
Wherever you live, you may:
- Access a copy of the personal information we hold about you
- Correct inaccurate information
- Delete information, subject to legal and contractual limits
- Object to certain processing
- Opt out of marketing at any time
- Port your information to another provider
Email [email protected] or call (646) 825-3900. We respond promptly and will tell you if we need more information to locate your records or verify your identity.
This mailbox is kept separate from our marketing systems.
We will not treat you differently for exercising any of these rights.
7.2 Global Privacy Control
We honor GPC and other browser-level opt-out preference signals. If your browser sends GPC, we treat it as an opt-out automatically.
7.3 California residents
We are not a business subject to the CCPA/CPRA, which applies to companies meeting revenue or data-volume thresholds we do not meet. We extend the rights in Section 7.1 to California residents as a matter of practice regardless, and as stated in Section 4, we do not sell or share personal information.
7.4 New York and other states
New York has no comprehensive consumer privacy statute at this time. Our security obligations under the SHIELD Act are in Section 9. Residents of any state may exercise the rights in Section 7.1.
8. Cookies and Tracking
8.1 Consent
We do not load analytics, session replay, or CRM tracking until you consent. On your first visit you will see a consent banner listing each category. Nothing beyond strictly necessary cookies fires until you choose.
8.2 Categories
- Strictly necessary: Security, load balancing, remembering your cookie choice. Consent required: No
- Statistics: Google Analytics, Microsoft Clarity. Consent required: Yes
- Marketing: GoHighLevel / LeadConnector visit tracking. Consent required: Yes
- Preferences: Remembering settings. Consent required: Yes
8.3 Changing your mind
Change or withdraw consent any time via the cookie settings link in the footer of every page. Withdrawal takes effect immediately for future collection.
You can also control cookies through your browser settings, though that is a blunter instrument and may affect how the Site works.
8.4 Seeing the full list
Every cookie and tracker on this Site is listed by name, provider, purpose, and duration in the Details tab of the cookie banner, which you can open at any time from the cookie settings link in the footer. That list is generated by an automated scan of the Site and updates when the Site changes.
9. New York SHIELD Act
The New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act requires businesses holding the private information of New York residents to maintain reasonable administrative, technical, and physical safeguards.
We maintain a data security program including designated security coordination, risk assessment, workforce training, vendor due diligence with contractual safeguards, access controls and encryption, secure disposal of information no longer needed, and incident detection and response procedures.
In the event of a breach of private information as defined by the SHIELD Act, we will notify affected New York residents and, where required, the New York Attorney General, Department of State, and State Police, in the most expedient time possible and without unreasonable delay.
10. Law Firm Clients and Confidentiality
Our clients are law firms. Systems we manage routinely hold information protected by the attorney-client privilege, the work product doctrine, and Rule 1.6(c) of the New York Rules of Professional Conduct, which requires attorneys to make reasonable efforts to prevent unauthorized access to information relating to the representation of a client.
We support our clients' obligations under that rule by:
- Treating all client system data as confidential by default
- Limiting access to authorized personnel on a documented, least-privilege basis
- Logging administrative access to client systems
- Entering confidentiality provisions in our Master Service Agreement
- Conducting vendor due diligence on any subprocessor with potential access to client environments
- Notifying the firm promptly of any incident affecting the confidentiality of its data, so the firm can meet its own obligations to its clients
We do not access client data except as necessary to deliver contracted services. We never use client data for marketing, analytics, model training, or any purpose outside the engagement.
11. Third-Party Links
The Site links to third-party websites, including vendor partners and industry resources. We do not control their privacy practices and are not responsible for them. Review their policies before providing information.
12. Children
The Site and our services are directed to businesses, not to individuals under 16. We do not knowingly collect personal information from children. If we learn we have, we will delete it promptly. Contact [email protected].
13. Where We Operate
The Site is operated from the United States and is directed to businesses in the United States. It is not directed to the European Union or the United Kingdom. Our service providers are primarily US-based. If you access the Site from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those where you are.
14. Changes
We may update this Policy. Updates are posted here with a revised "Last updated" date. For material changes we will provide additional notice, such as a notice on the Site or an email to active clients, before the change takes effect.
15. Contact
If you have questions or requests regarding this Privacy Policy, contact us:
ELMIDA Solutions
6614 Avenue U, Ste #1056
Brooklyn, NY 11234
Privacy requests and questions about this Policy: [email protected]
General inquiries: [email protected]
Phone: (646) 825-3900
Questions about how we handle your data?
Reach out — we are happy to walk you through anything in this policy in plain language.
