Privacy Policy
How Sierra Miles Group collects, uses, protects, shares, and retains information across our website, business operations, managed services, cybersecurity, compliance, cloud, support, and AI-enabled services.
Purpose and scope.
Sierra Miles Group, LLC ("Sierra Miles," "we," "us," or "our") provides managed IT, cybersecurity, help desk, backup and disaster recovery, cloud, compliance, AI-enabled, and professional services. This Privacy Policy explains our general privacy practices for our public website, sales and marketing activity, client services, vendor relationships, and business operations.
This policy applies to website visitors, prospects, customers, client personnel, authorized users, vendors, partners, and other people who interact with Sierra Miles. Client contracts, orders, service attachments, data processing agreements, business associate agreements, or other written agreements may include additional or different requirements. If those documents conflict with this policy, the applicable signed agreement controls for that client relationship.
How Sierra Miles acts in different roles.
Sierra Miles may handle information in different roles depending on the context. For our website, marketing, billing, and business operations, we generally decide why and how information is used. For many managed IT and support services, we handle client data on behalf of the client and follow the client's documented instructions and applicable contract terms.
| Context | Typical role | Examples |
|---|---|---|
| Website and marketing | Business collecting information for its own operations | Website visits, contact forms, calls, newsletters, analytics, advertising measurement. |
| Client services | Service provider or processor acting for the client | Help desk support, endpoint monitoring, remote administration, backups, security tools, compliance evidence. |
| Regulated clients | Role defined by contract or law | HIPAA business associate obligations when a BAA applies; privacy-law processor obligations when included in an agreement. |
| AI-enabled services | Service provider using client-provided AI data for agreed purposes | AI consulting, automation, reporting, data analysis, generated outputs, workflow assistance. |
Information we collect.
The information we collect depends on how a person or organization interacts with us.
- Contact and identity information: name, business email, phone number, company, title, mailing address, and communication preferences.
- Business and service information: service interests, requests, proposals, contracts, orders, billing details, authorized contacts, and account notes.
- Support and help desk information: support tickets, diagnostic notes, device names, usernames, screenshots or attachments, call recordings or transcripts if used, and issue history.
- Technical and device information: asset inventories, workstation and server details, network information, software versions, logs, telemetry, IP addresses, configuration data, backup status, security alerts, and remote access records.
- Client data handled during services: client files, system data, mailboxes, account information, application data, backups, credentials or secrets when provided for support, and other data accessible through managed systems.
- Security and compliance information: risk assessment data, audit evidence, policy artifacts, incident data, vulnerability information, training records, vendor assessments, and compliance documentation.
- Website and tracking information: pages visited, referring URLs, form events, phone-link clicks, booking-link clicks, chat or AI lead-form events, cookies, device/browser metadata, and advertising or analytics identifiers.
- AI data: data provided for AI-enabled services, prompts, inputs, generated outputs, workflow context, and aggregated or anonymized service-improvement data when permitted by contract.
Sources of information.
- Information provided directly by visitors, prospects, clients, authorized users, vendors, and partners.
- Information generated through our website, forms, chat tools, phone links, booking links, and analytics or advertising measurement tools.
- Information made available through client systems, devices, networks, cloud environments, SaaS platforms, backups, logs, and security tools when Sierra Miles provides services.
- Information received from third-party service providers, distributors, software vendors, labor networks, communication platforms, payment or accounting systems, and managed service tools.
- Information created through support, compliance, security, AI, reporting, and documentation work performed by Sierra Miles.
How we use information.
- Respond to inquiries, provide proposals, schedule consultations, and communicate about services.
- Deliver managed IT, help desk, cybersecurity, backup, disaster recovery, cloud, compliance, AI-enabled, and professional services.
- Monitor, maintain, secure, troubleshoot, configure, and document client systems when authorized.
- Create support tickets, service records, reports, recommendations, compliance artifacts, risk assessments, training records, and business documentation.
- Administer billing, vendor management, contracts, insurance, accounting, procurement, and internal operations.
- Improve our website, service quality, workflows, security posture, training, and customer experience.
- Measure website performance, form activity, lead quality, advertising effectiveness, chat interactions, phone clicks, and booking activity.
- Comply with legal, regulatory, contractual, insurance, security, and professional obligations.
- Detect, prevent, investigate, and respond to suspected security incidents, fraud, abuse, policy violations, or service misuse.
Client data and managed services.
In managed IT and related services, Sierra Miles may need access to client systems, facilities, devices, accounts, applications, files, logs, backups, and security tools. We use this access to provide the services ordered by the client, such as help desk support, monitoring, troubleshooting, security recommendations, remote administration, backup and recovery support, compliance assistance, and reporting.
Client data remains the client's data. Sierra Miles should not use, edit, or disclose client data except as needed to provide services, as authorized by the client, as required by an applicable agreement, or as required by law. Sierra Miles maintains the security and integrity of client data under its direct control using administrative, technical, and physical safeguards appropriate to the service and risk.
Client responsibility note. Managed services improve visibility, support, and recovery readiness, but they do not eliminate all risk. Clients remain responsible for their own compliance obligations, user behavior, system changes, approvals, software licensing, data backup decisions, and adoption of recommended safeguards unless a written agreement says otherwise.
Security and compliance services.
When Sierra Miles provides managed compliance or security services, we may collect and process nonpublic information, protected information, policies, audit evidence, risk findings, vendor records, training records, incident details, and information about administrative, technical, and physical safeguards. We use this information to perform risk assessments, help develop or maintain written information security programs, review privacy notices and policies, support employee training, support vendor management, assist with incident response planning, and provide reporting and documentation.
Sierra Miles may provide guidance and support for compliance activities, but clients remain responsible for their own compliance with applicable laws, regulations, industry standards, and client-specific obligations unless a written agreement states otherwise.
HIPAA and regulated information.
Sierra Miles provides IT services to healthcare organizations and other regulated clients. When required and agreed in writing, Sierra Miles may enter into a Business Associate Agreement or other regulated-data agreement with a client. In that case, the applicable agreement controls how protected health information or other regulated data is handled.
This Privacy Policy does not replace any Business Associate Agreement, Data Processing Agreement, service attachment, or client-specific compliance agreement. It is a public and general-purpose privacy policy, not a complete HIPAA policy or client compliance program.
Cookies, analytics, advertising, and website tracking.
Our website uses cookies and similar technologies for analytics, site performance, form functionality, advertising measurement, chat and lead-form functionality, and to understand how visitors interact with pages, forms, phone links, booking links, and service-related content. These tools may include services from Google, Meta, Microsoft, and website or chat service providers.
The website tracking inventory observed for this update includes Google Tag Manager, Google Analytics event tracking, Meta Pixel lead events, Microsoft Ads UET pageview and lead events, chat or AI lead-form events, form submissions, phone-click tracking, Book Now click tracking, and server-side Meta Conversions API functionality. Tags, triggers, consent settings, and vendors can change over time.
You can control cookies through browser settings and platform-level privacy controls. Disabling cookies may affect some site functionality. Sierra Miles maintains consent, opt-out, and disclosure mechanisms where required by applicable law.
AI-enabled services.
Sierra Miles may provide AI-enabled services, automation, analysis, documentation, meeting support, reporting, or workflow assistance. For those services, clients may provide data, prompts, documents, system context, or other information necessary to perform the service. Clients are responsible for ensuring they have the right to provide that data and that their use of AI-enabled services complies with applicable laws, contracts, and industry requirements.
Client-provided AI data remains the client's data unless a written agreement states otherwise. Sierra Miles may use client AI data and AI-generated outputs to provide the agreed services. Where permitted by agreement, Sierra Miles may use aggregated or anonymized information to analyze, benchmark, improve, or develop services, provided the use does not identify the client, its employees, its customers, or other individuals.
AI technologies may involve third-party platforms, cloud infrastructure, and service providers. Sierra Miles should not sell or lease client AI data to third parties. Any training, model-improvement, retention, or vendor-specific AI use is governed by the applicable client agreement and vendor terms.
Third-party services and vendors.
Sierra Miles uses third-party services to help operate the business and deliver services. These may include communication platforms, backup and disaster recovery tools, cybersecurity vendors, remote monitoring and management tools, cloud providers, hardware and software vendors, email and signature tools, labor networks, AI platforms, accounting systems, and website or advertising platforms.
Third-party service providers may process information under their own terms and privacy policies. Sierra Miles maintains third-party service schedules or subprocessors lists where required by contract or law. When Sierra Miles uses a third party to process client personal data as a service provider or processor, the applicable contract should require appropriate confidentiality, security, and data protection obligations.
When we share information.
- With vendors and service providers that help us operate our business or provide services.
- With client-authorized third parties, including software vendors, cloud providers, distributors, auditors, insurers, legal advisors, and other service providers.
- With a client's designated contacts, administrators, or successor service provider during service delivery, off-boarding, or transition.
- When required to comply with law, legal process, regulatory inquiry, contractual obligation, insurance requirement, or security investigation.
- To protect Sierra Miles, clients, users, systems, networks, or the public from security threats, fraud, misuse, or unlawful activity.
- In connection with a business transaction such as a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.
Sierra Miles does not sell personal information for money. Some advertising or measurement technologies may be considered a sale, sharing, or targeted advertising under certain privacy laws. Where applicable, Sierra Miles will provide required notices and choices.
Data protection and security.
Sierra Miles uses administrative, technical, and physical safeguards designed to protect information under our control. Safeguards may include encrypted connections, access controls, secure storage, monitoring, role-based access, vendor controls, incident response practices, and security tools used in our managed IT work.
No method of transmission, storage, monitoring, backup, recovery, or security control is guaranteed to be error-free or perfectly secure. Clients and users are responsible for using strong credentials, enabling recommended security controls, keeping information accurate, and notifying Sierra Miles promptly about suspected issues.
Retention, return, and deletion.
Sierra Miles retains information for as long as necessary to provide services, maintain business records, comply with legal, tax, accounting, contractual, insurance, security, and operational obligations, resolve disputes, and enforce agreements. We aim to retain only the amount of data reasonably needed for those purposes.
Client contracts may contain specific return, deletion, off-boarding, or data-copy terms. After termination and completion of any required off-boarding obligations, Sierra Miles may have no obligation to maintain or provide client data after the period stated in the applicable agreement, unless legally prohibited from deletion or otherwise required to retain it.
Privacy rights and requests.
Depending on where a person lives and the context in which information is processed, privacy laws may provide rights to access, correct, delete, obtain a copy of, restrict, object to, or opt out of certain processing of personal information. Sierra Miles will respond to applicable rights requests as required by law and may need to verify the requestor's identity and authority.
For personal information Sierra Miles processes on behalf of a client, requests should usually be directed to that client. Sierra Miles may assist the client in responding to requests when required by contract or applicable law.
Requests may be sent to [email protected] or to Sierra Miles Group, LLC, 6490 S McCarran Blvd, Ste C-21, Reno, NV 89509.
Incident response and breach notification.
Sierra Miles maintains practices to detect, investigate, contain, and remediate potential security incidents. If an incident involves information for which notice is legally or contractually required, Sierra Miles will follow applicable law and agreement terms. For client data, notice obligations may depend on the client's role, the applicable agreement, the type of data involved, and the facts of the incident.
International data transfers.
Sierra Miles is based in the United States. Some vendors, service providers, cloud systems, or client environments may process or store information in other jurisdictions. Where required by applicable law or contract, Sierra Miles uses appropriate transfer mechanisms and data processing terms.
Children's privacy.
Sierra Miles does not direct its website or services to children under 13 and does not knowingly collect personal information from children through the public website. If we learn that a child has provided personal information through the website without appropriate consent, we will take reasonable steps to delete it.
Changes to this policy.
Sierra Miles may update this Privacy Policy from time to time. The effective date will be updated when material changes are made. Where required by law or contract, Sierra Miles will provide additional notice or obtain consent before applying material changes.
Contact.
Questions or requests about this Privacy Policy may be directed to:
Sierra Miles Group, LLC
6490 S McCarran Blvd, Ste C-21
Reno, NV 89509
(775) 420-4224
[email protected]