PRIVACY POLICY: 303 BLUE
Effective Date: May 4, 2026
At 303 Blue, we recognize that data is the lifeblood of your business. This Privacy Policy outlines how we collect, use, and protect information for our Small Business and High-Risk Industry clients.
SECTION I: GENERAL PRIVACY PRACTICES
1. INFORMATION WE COLLECT
We collect information necessary to provide our analytics services, including:
- Account Data: Contact information, billing addresses, and login credentials.
- Client-Provided Data: Any raw data sets you upload to our platform for analysis.
- Usage Data: IP addresses, browser types, and interaction logs within the 303 Blue platform.
2. HOW WE USE DATA
We use your data strictly to:
- Provide, maintain, and improve our analytics engine.
- Process payments and prevent fraud.
- Communicate updates or security alerts.
- We do not sell your personal or business data to third parties.
3. DATA RETENTION
We retain data only as long as your account is active. Upon termination of service, we will delete all client-provided data within 30 days, except for information we are legally required to keep for tax or audit purposes.
SECTION II: HIGH-RISK & COMPLIANCE PROVISIONS
These provisions apply to clients in the Cannabis, Psychedelic-assisted therapy, and Wellness sectors.
1. SENSITIVE DATA & HIPAA
If you are a medical provider or clinic:
- BAA Required: You must notify 303 Blue if you intend to upload Protected Health Information (PHI). A separate Business Associate Agreement (BAA) must be signed to ensure HIPAA compliance.
- De-identification: We strongly recommend de-identifying patient data before upload to minimize risk.
2. LAW ENFORCEMENT & SUBPOENAS
Because you operate in high-risk industries, 303 Blue may be subject to legal requests for data.
- Notification: To the extent legally permitted, we will notify you of any subpoena or government request for your data before disclosure, allowing you to seek a protective order.
- Compliance: We will comply with valid legal processes (subpoenas, warrants) as required by law. 303 Blue is not responsible for legal consequences resulting from your data being turned over to authorities.
3. THIRD-PARTY INTEGRATIONS
If you connect 303 Blue to state-mandated "Seed-to-Sale" software (e.g., Metrc), you acknowledge that those third parties have their own privacy policies. 303 Blue is not responsible for data breaches or leaks occurring within those third-party systems.
4. DATA SECURITY
We employ industry-standard encryption (\(AES-256\)) for data at rest and (\(TLS\ 1.2+\)) for data in transit. However, given the high-risk nature of your industry, you acknowledge that no system is 100% secure.
SECTION III: YOUR RIGHTS
Depending on your jurisdiction (e.g., CCPA/CPRA in California or GDPR in Europe), you may have the right to:
- Access the data we hold about you.
- Request deletion of your data.
- Opt-out of automated decision-making.
CONTACT US
For privacy-related inquiries or to report a suspected data incident:
Email: privacy@303blue.com
FAQs
General
Tell us what you are trying to understand.
You do not need clean files or the technical terms. A few sentences is enough.
- What are you trying to understand?
- Where does the information live now?
- What would become easier if the answer were clear?
Send your data problem.
Include where the data lives right now and what is not working.