Privacy Architecture & Data Handling Policy

Effective Date: July 2026 | Jurisdiction: Florida, USA

This Privacy Policy outlines the data handling architecture, security protocols, and legal frameworks under which Dymetra Solutions LLC ("Platform," "we," "our," or "us") operates. We provide Conversational AI Reactivation services strictly for B2B Clients.

1. Legal Status: Data Processor vs. Data Broker

Dymetra Solutions LLC is headquartered and registered in the State of Florida. However, to provide maximum national protection for our B2B Clients, our platform infrastructure strictly adheres to the definitions set forth by the California Consumer Privacy Act (CCPA/CPRA), which currently serves as the highest national standard for data privacy.

Explicit Declaration: We are explicitly not a data broker. Under applicable state and federal laws, Dymetra Solutions LLC operates exclusively in the capacity of a Service Provider and a Data Processor. The B2B Client utilizing our Platform remains the sole Data Controller of all consumer information.

All processing of consumer CRM databases (including phone numbers, names, and call transcriptions) is executed strictly on behalf of our B2B Clients, governed by a binding Data Processing Agreement (DPA) implicitly executed via our Terms of Service.

2. Anti-Sale and Anti-Sharing Prohibitions

To ensure strict compliance and protect consumer privacy, the Platform enforces the following limitations on Personal Information (PI):

3. AI Training Rights & Security Architecture

To prevent Large Language Model (LLM) data leakage and maintain absolute confidentiality, our platform is built on advanced security architecture:

4. Data Subject Access Requests (DSAR)

As a Service Provider, we assist our B2B Clients in fulfilling their obligations regarding consumer privacy rights. We provide dedicated mechanisms allowing our Clients to rapidly extract, correct, or permanently delete consumer data (including SMS logs and call transcriptions).

All DSAR protocols are designed to enable the Client to fulfill consumer requests well within the mandatory 45-day Service Level Agreement (SLA).

5. Delegation of Responsibility: Client Obligations (A2P 10DLC)

While the Platform provides the technology, the B2B Client (Data Controller) assumes full legal responsibility for data acquisition and opt-in consent. As a condition of using our services, B2B Clients are contractually obligated to include a strict Data Sharing Clause within their own corporate Privacy Policy.

Mandatory A2P 10DLC Requirement: To satisfy AT&T, T-Mobile, and Verizon network registration audits, Clients must publicly display the following exact clause on their own website: "No mobile information and SMS consent will be shared with third parties/affiliates for marketing/promotional purposes." Failure to maintain this clause will result in carrier rejection of messaging campaigns, for which Dymetra Solutions LLC assumes zero liability.

6. Data Retention

Upon termination of our Master Services Agreement or written request by the Client, Dymetra Solutions LLC will securely purge or irreversibly anonymize all associated consumer CRM data within a commercially reasonable timeframe (typically 30 to 60 days), unless prolonged retention is mandated by federal or state law.

7. Contact Information

If you have any questions, DSAR inquiries, or compliance requests regarding this Privacy Policy, please contact our administrative team:

← Back to Home