U.S. Privacy Policy
Effective and last updated: September 20, 2026
This Privacy Policy explains how Opulentus Management Group ("Opulentus," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when people in the United States visit our website, create or use an account, request or receive services, book an appointment, communicate with us, or pay an invoice. It also explains choices and rights available under applicable U.S. federal and state law.
1. Scope and our role
This Policy covers information we control through our website, client portal, staff and owner workspaces, booking and invoicing tools, and direct client relationships. When we process payroll, employee, accounting, tax, or other records solely on a business client's instructions, that client may be the business responsible for the information and its own privacy notice may also apply. This Policy does not replace an engagement letter or a business client's lawful instructions.
2. Personal information we collect
The information we collect depends on how you interact with us. During the preceding 12 months, we may have collected the following categories:
- Identifiers and contact information: name, email, telephone number, account identifier, login credentials, mailing address, Internet Protocol address, and business name.
- Customer and commercial records: service requests, proposals, engagement details, appointments, correspondence, feedback, invoices, payment status, and transaction history.
- Financial and tax information: bank, ledger, vendor, payroll, withholding, tax-return, and supporting records provided for an engagement. Our payment processor, rather than Opulentus, collects complete payment-card details during checkout.
- Employment-related information: employee identity, contact, wage, hour, deduction, benefits, and payroll information supplied by a client when needed for contracted services.
- Internet and device activity: browser and device type, pages viewed, referring page, date and time, security events, approximate location inferred from IP address, and interactions measured by optional analytics.
- Inferences and service preferences:preferences derived from requests, appointments, and account activity so we can provide and improve the requested service.
- Sensitive personal information: account login data and, only when required for contracted payroll, tax, screening, or financial work, government identifiers and financial-account information. We do not use sensitive personal information to infer characteristics about you.
We collect information directly from you or your authorized business, automatically from your device, from payment and service providers, and from public agencies or records when an engagement lawfully requires it.
3. Why we use personal information
- respond to inquiries, evaluate requests, and provide contracted services;
- create and secure accounts, verify identity, and provide two-factor authentication;
- schedule, approve, change, and communicate about appointments;
- prepare records, payroll, reports, invoices, and authorized filings;
- process payments and maintain transaction and accounting records;
- send service notices and, where permitted, marketing communications;
- detect fraud, prevent abuse, maintain audit trails, and protect our systems;
- comply with legal, tax, employment, professional, and recordkeeping duties; and
- measure and improve the site when optional analytics is enabled.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or process it for targeted advertising. We do not use personal information for profiling that produces legal or similarly significant effects.
4. When we disclose information
We may disclose the categories described above to hosting, security, communications, analytics, accounting, payroll, document-management, professional-adviser, and payment providers that perform services for us; to government agencies and taxing authorities for authorized filings; to parties you direct us to contact; and to courts, regulators, law enforcement, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud, or complete a merger, financing, reorganization, or sale. Service providers receive only the information reasonably necessary for their work and are subject to contractual restrictions where required.
Where Internal Revenue Code § 7216 applies, tax return information is used or disclosed only as federal law permits or with the taxpayer's required consent. Where the Fair Credit Reporting Act applies to a consumer report, it is obtained and used only for a permissible purpose with required notices and authorization.
5. U.S. state privacy rights
Depending on your state of residence and whether the relevant law applies to us or to the information involved, you may have the right to confirm whether we process your personal information; access it; obtain a portable copy; correct inaccuracies; delete information; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; and receive equal service without unlawful discrimination for exercising a privacy right. Because we do not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out needed for our current practices.
California residents may also request the categories and specific pieces of personal information collected, the sources, business or commercial purposes, and categories of recipients for the preceding 12 months. We do not offer financial incentives for personal information. California's "Shine the Light" law permits eligible residents to request information about certain disclosures for third parties' direct marketing; we do not make those disclosures. California's Online Privacy Protection Act also requires us to explain browser signals: we honor legally recognized opt-out preference signals, including Global Privacy Control, where they apply. There is no uniform legal standard for other "Do Not Track" signals, so the site does not respond to them.
Submit a request by emailing info@opulentusmanagementgroup.com or +1 (770) 750-4802. We may ask for information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where state law allows, subject to proof of authorization and identity verification. If we deny a request, residents of states that provide an appeal right may appeal by replying to our decision with "Privacy Appeal" in the subject line. We will respond within the period required by applicable law. You may also contact your state attorney general.
6. Retention
We retain personal information only as long as reasonably necessary for the purpose stated here, an active engagement, legal claims, fraud prevention, and applicable tax, professional, employment, and recordkeeping duties. Retention depends on the record: accounting and tax engagement records are generally kept for seven years, and payroll tax records for at least four years, unless a longer or shorter period is required. Unconverted inquiries and optional analytics are deleted or de-identified when no longer needed. We securely dispose of records, including consumer-report information subject to the FTC Disposal Rule.
7. Security and data incidents
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including role-based access, encryption in transit and at rest, mandatory two-factor authentication for accounts, audit logs, vendor review, backups, restricted network access, and incident-response procedures. Where applicable to our activities, our safeguards are designed with the Gramm-Leach-Bliley Act Safeguards Rule in mind. No system is completely secure. If a breach triggers federal or state notice duties, we will provide notice within the time and in the form required by applicable law.
8. Communications and marketing
We send account, appointment, invoice, security, and service messages as part of the relationship. Commercial email includes the identification and opt-out mechanism required by the CAN-SPAM Act. You may unsubscribe from marketing without stopping necessary service communications. We do not treat providing a telephone number as consent to automated marketing calls or texts. If we seek such consent, it will be separately disclosed as required by the Telephone Consumer Protection Act and applicable state law, and consent will not be a condition of purchase where prohibited.
9. Cookies and browser storage
We use essential browser storage for security, account sessions, language, requested features, and your privacy choice. Optional Google Analytics remains off unless you accept it. Details, retention, and controls are in our Cookie Policy. A recognized opt-out signal is treated as an opt-out where applicable law requires it.
10. Children
Our site and services are directed to businesses and adults and are not directed to children under 13. We do not knowingly collect personal information online from a child under 13 in a manner covered by the Children's Online Privacy Protection Act. Contact us if you believe a child submitted information, and we will review and delete it as required.
11. External services and interstate processing
Our providers maintain their own privacy practices. Payment checkout is provided by Stripe, and Stripe's privacy notice applies to information it collects directly. Information may be processed in U.S. states other than your own, subject to applicable safeguards and law. Links to third-party sites are governed by those parties' notices.
12. Sub-processors and our Data Processing Agreement
Every third party that touches personal information in our systems is named, with its purpose, the categories of data it receives and its location, in the annex to our Data Processing Agreement. Our servers can only reach those destinations: outbound requests pass a fixed allowlist and anything else is refused. Where we handle personal information on a business client's instructions — payroll, HR files, bookkeeping — that Agreement, not this Policy, governs the relationship, and the client remains the controller.
13. Visitors in the European Economic Area and the United Kingdom
Opulentus is established in the United States and does not target the EEA or the UK. If the GDPR or UK GDPR applies to our processing of your information, we rely on these legal bases: performance of a contract (creating your account, scheduling, invoicing and delivering services), legal obligation (tax, accounting and payroll record-keeping), legitimate interests (securing the service, preventing abuse, answering enquiries) and consent (optional analytics cookies and marketing email, withdrawable at any time).
You may request access, rectification, erasure, restriction, portability and objection, and may object to direct marketing at any time. We answer within one month, extendable by two for complex requests. We do not use automated decision-making that produces legal or similarly significant effects. Transfers to the United States rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, plus the technical measures described in section 8. You may also complain to your national supervisory authority or, in the United Kingdom, the Information Commissioner's Office.
14. Clients and visitors in Brazil
Where the LGPD (Lei nº 13.709/2018) applies, the legal bases we rely on are execution of a contract, compliance with a legal or regulatory obligation, legitimate interests and consent. You may confirm processing, access your data, correct it, request anonymisation, blocking or deletion, obtain portability, be told with whom we share data, and withdraw consent — we answer within 15 days. Requests and complaints may be sent to info@opulentusmanagementgroup.com or +1 (770) 750-4802 or to the Autoridade Nacional de Proteção de Dados. Data relating to Brazilian clients is processed on United States infrastructure under Article 33 international transfer provisions, with contractual and technical safeguards in place.
Legal basis, your rights and processors (GDPR / CCPA)
- Legal basis
- Consent for optional analytics and for the contact form; contract for client services we deliver to you; legitimate interest for security and audit logs.
- Your rights
- Access, correction, deletion, portability, objection to processing, and opt-out of sale or sharing. We do not sell personal data and do not share it for cross-context behavioral advertising.
- How to exercise them
- Email info@opulentusmanagementgroup.com. We verify your identity and respond within 30 days (45 days under the CCPA). You will not be treated differently for using your rights.
- Retention
- Contact enquiries: up to 24 months. Client and billing records: 7 years for tax and accounting duties. Security and audit logs: up to 12 months. Analytics: up to 14 months, only with consent.
- Processors
- Supabase (database and sign-in), Stripe (payments), Google Workspace / Gmail (email), Lovable (hosting), and Lovable AI Gateway and OpenAI (AI model for the portal assistant; requests are sent with storage disabled). Each acts only on our instructions.
15. Changes and contact
We will post revisions on this page and update the effective date. If a material change requires additional notice or consent, we will provide it as required by law. Questions, privacy requests, and accessibility or alternate-format requests may be sent to info@opulentusmanagementgroup.com or +1 (770) 750-4802.
State privacy laws contain thresholds, exemptions, and exceptions, including for employment, business-to-business, regulated financial, and client-directed data. Rights described here apply only when the relevant law covers the person, information, and Opulentus activity.