1. Operator, scope, and roles
PCGROUP, LLC operates JBComm, OmniReach, and the related AIMarket Services. This Policy addresses information processed for our own purposes separately from Customer Personal Data processed on behalf of tenants. Shared definitions are in the Master Terms.
Roles depend on the purpose of each activity. We generally act as processor or service provider for Customer Personal Data processed on the Customer’s behalf through its tenant. We may act as an independent controller or business for our own account administration, billing, security, fraud and abuse prevention, legal compliance, service administration, website visitors, and business contacts. Prospect or enrichment activities may involve separate-controller relationships where the facts and applicable law support that allocation.
Tenant instructions, customer notices, and the applicable DPA govern tenant-directed processing. This Policy does not expand contractual data rights or establish a lawful basis by itself.
2. A — Information processed for our own purposes
- Website and business contacts: inquiry identity/contact details, business needs, selected service/request type, website origin, and technical device/browser/network request information.
- Customer administration: business/user contacts, designated administrators, subscription records, necessary permissions-administration information, and correspondence.
- Our billing: contracted fees, invoices, transaction references, billing contacts, balances, and necessary administrative usage records. Use intended payment channels for payment credentials.
- Support/security: support correspondence and necessary access, use, device, and security information. Tenant content included in support remains subject to its confidentiality and processing restrictions.
Categories apply only to actual activities. Tenant communications, prospect records, and AI interactions are not all reclassified as our independent Operational Data.
3. A — Sources, purposes, and lawful basis
Sources may include you, your organization or administrator, website requests, use of enabled Services, support interactions, and authorized integrations. Independent purposes include inquiry responses, account/contract administration, our billing, support, security, fraud/abuse prevention, legal compliance, and necessary service administration.
Where law requires a lawful basis, determine it for the actual purpose: contract performance, legal obligation, a properly assessed legitimate interest, or consent where required. These are conditional possibilities, not blanket reliance. Consent-dependent processing must not be inferred merely from accepting Terms.
4. B — Customer Personal Data processed for tenants
Depending on contracted, enabled functions, tenant data may include professional contacts/company records, account records, documents, notes, activity, communications content/metadata and permitted recordings, portal messages/files/tickets, subscriptions and billing records, payment references, integration data, and AI Input, AI Output, or Tenant Intelligence. These are potential categories, not universal feature availability.
We process such information for the Customer’s functions under documented instructions, assigned permissions, and the Data Processing Addendum. Customers determine their independent business/campaign purposes, give required notices, establish permissions/lawful basis, and honor recipient, client, and user rights. We retain our own applicable duties.
5. Prospect and enrichment information
Prospect/Enriched Data may be Customer-supplied or obtained from authorized business-information sources where enabled, including information about people without a direct relationship with AIMarket. Public/professional information may remain Personal Data; source access does not establish consent to contact.
Customer-directed processing follows the DPA. Any distinct activity with our independently determined purposes requires assessed separate-controller roles, source/use rights, lawful basis, notices, recipients, sale/sharing or data-broker duties where applicable, and rights handling before that activity begins. This Policy creates no independent data-commercialization permission.
The Prospect Service Terms require accuracy review, lawful use, deletion/correction, and respect for opt-outs and suppression.
6. AI interactions
Enabled AI may process authorized Input and Customer Data for tenant-specific functions. Data access and actions remain permission-aware and subject to tenant policies. Third-party model/service processing is subject to applicable contracts and the AI Addendum.
We will not use identifiable Customer Data, Customer Content, Prospect Data, or tenant-specific data to train a shared or general model for unrelated customers unless the Customer separately authorizes that use.
Tenant-specific context, memory, and derived intelligence may support that Customer’s authorized functions. Improvement must follow the AI Addendum and cannot expose one tenant’s identifiable information to another. Public website assistance is distinct from tenant AI and confers no tenant-data access; visitor collection requires appropriate notice.
7. Recipients and disclosures
Information may be provided as necessary to authorized personnel, contracted service providers, appropriate advisers, or parties as law requires. Tenant disclosures and our Subprocessors follow the DPA. Independently selected integrations receive only authorized information under applicable restrictions and may have their own notices.
Business transfers and compelled disclosures must respect confidentiality, law, and purpose limits. The Subprocessor Policy provides the process for obtaining the approved contractual list; its public list is not currently populated. No blanket claim that all business-information disclosures are exempt from sale/sharing is made; those classifications require factual analysis. In-scope service-provider data must not be sold/shared contrary to the DPA.
8. Cookies, external resources, and analytics
Websites and enabled Services may use session/preference technologies and technical information needed for operation. Optional analytics, advertising, or tracking require accurate disclosures and any required consent, choices, or preference-signal handling before use.
The current website loads external font resources, which receive technical information needed to serve requests. External links do not automatically make independent operators our Subprocessors. Browser controls may affect storage/resource requests but are not a substitute for legally required choices.
9. Retention and deletion
Retention must be necessary for the actual purpose, legal requirement, Customer instructions, and agreed obligations. Tenant return/deletion follows the DPA; independent records require their own documented basis. Possible future usefulness alone is insufficient for indefinite retention. Pseudonymous data is not presumed anonymous.
Retention criteria depend on the category and purpose:
- Website inquiries/support: retention class, follow-up purpose, applicable legal requirements, deletion schedule.
- Our account/invoice/payment/tax records: actual legal recordkeeping requirements and retention/deletion criteria.
- Tenant communications, recordings, documents, portal records, and AI context: instruction-based duration, service term, exit handling, and deletion schedule.
- Usage/security logs: role/purpose distinctions and necessary retention.
- Backups: expiry/deletion schedule, isolation, and continued respect for deletion/suppression after restoration.
- Suppression: minimum information, lawful purpose, review criterion, and deletion schedule.
Legally required retained records must be restricted to that purpose and deleted when its justified basis ends.
10. Privacy rights and request handling
Depending on law and circumstances, individuals may have rights to access/know, correct, delete, obtain a portable copy, object/restrict processing, withdraw consent, limit sensitive use, or opt out of sale, sharing, targeted advertising, or specified automated decisions. Not every right applies to every activity or jurisdiction.
Send a request to sales@jbcomm.net, identifying “Privacy request” and the relevant relationship/activity. Verification must be proportionate where required, unnecessary sensitive information avoided, and authorized agents recognized as required. Opt-outs must not face verification prohibited by law. Responses and permitted denial explanations must follow applicable legal deadlines.
For tenant records, the Customer generally directs the response; we will route/coordinate and assist under the DPA and law. This does not limit our direct legal duties or require a person to navigate an impossible chain of contacts.
11. State rights, appeals, and preference signals
Where applicable law grants an appeal, reply to a denial or send “Privacy appeal” to the same contact. Provide reviewed responses and regulator-complaint routes within applicable requirements. We will not unlawfully discriminate or retaliate for protected privacy requests.
Applicable jurisdiction-specific disclosures, appeals, required contacts, sensitive-data limits, sale/sharing/targeted-advertising opt-outs, and preference signals govern the relevant activity. These rights vary by jurisdiction and circumstances; this Policy does not assert that every state law applies to every activity.
12. Marketing preferences and suppression
A website inquiry asks for a response about that request; it is not a general marketing subscription. You may request an end to our marketing through available opt-outs or the existing contact. Necessary lawful account, billing, contract, or security notices may continue. Tenant marketing requests should be directed to that business or routed appropriately through us.
Where lawful and necessary, deleting a prospect or contact may leave a minimum suppression record solely to prevent renewed contact, re-importing, or re-enrichment of that person. An identifiable suppression record remains Personal Data, must be restricted to honoring the request and protected against other use, and may be retained only for its justified purpose.
Deletion must not defeat a valid do-not-contact request. Suppression is not permission for renewed profiling, enrichment, or unrelated targeting, and must be assessed by purpose and role.
13. Sensitive data
Do not use enrichment, prospecting, or AI to target people by health, race or ethnicity, religion, sexual orientation, biometric identifiers, citizenship or immigration status, precise geolocation, children’s information, or similarly sensitive characteristics by default. Any specifically supported sensitive processing requires a lawful purpose, required notices and permissions, appropriate safeguards, and express contractual authorization. Legal definitions and requirements vary by jurisdiction and context.
Billing/account activity may contain sensitive information without authorizing its use for enrichment, targeting, or AI. Do not submit passwords or complete payment credentials in general website, support, or AI messages.
14. Children
AIMarket is a business/professional service and is not directed to children. Do not target/profile children or submit their Personal Data by default. Any specifically supported processing requires separate contractual approval, lawful authority, required parent/guardian or other permissions, and appropriate safeguards under the applicable law.
If children’s information was improperly provided, contact us for evaluation and lawful handling under applicable instructions. This Policy does not provide general authorization to process children’s data.
15. Security
Tenant security duties follow the DPA and agreed commitments. The Security & Data Handling Overview describes safeguard categories; binding scope and measures follow applicable agreements and completed DPA Annex E. No method eliminates all risk. No certification, guaranteed compliance, or uptime commitment is asserted.
16. International users and transfers
Applicability depends on actual activities, locations, and individuals. Parties must assess lawful basis, notice, location, safeguards, and required transfer conditions before relevant processing. No international availability or residency guarantee is made.
The DPA transfer schedule requires completed, agreed safeguards before restricted transfers. SCC references do not mean execution or completed modules/annexes. Arizona commercial law does not replace any mandatory transfer-clause law/forum; required representatives or regulator contacts must be confirmed.
17. Changes and contact
This Policy is effective 2026-10-07. Updates will state an effective or updated date and provide notices required by applicable law. New purposes or consent-dependent uses require appropriate authorization; posting cannot expand processing contrary to the DPA or AI Addendum.
Contact PCGROUP, LLC / JBComm at sales@jbcomm.net. Existing account support may use support@jbcomm.net. We will route requests and provide additional channels or representative information where required by applicable law.