Legal
Privacy Policy
Effective date: June 1, 2026
1. Who we are
ARIA Hotline is operated by ReMyll Group LLC, a Michigan limited liability company ("ARIA," "we," "us"). Our principal place of business is 625 Kenmoor Ave SE, Ste 350, Grand Rapids, MI 49546. We operate ariahotline.com and the ARIA Hotline platform.
2. Information we collect
We collect information you provide directly (name, email, organization when you contact us or book a demo), information about how you use our marketing site (page views, referrers, browser type via Plausible Analytics — no cookies, no personal identifiers), and information submitted to us by our clients for the purpose of operating the ARIA intake platform. We are a data processor for our clients' case data, not a data controller.
3. How we use your information
We use contact information to respond to inquiries, schedule demos, and send service-related communications. We use aggregated site analytics to improve ariahotline.com. We process client intake data solely to provide the services described in the applicable order form and Business Associate Agreement.
4. HIPAA and Business Associate Agreements
ARIA executes a HIPAA Business Associate Agreement (BAA) with every client before any protected health information (PHI) is processed. We maintain appropriate administrative, physical, and technical safeguards as required under 45 CFR Parts 160 and 164. PHI is stored in US-based data centers and is not transferred to EU infrastructure unless an Enterprise addendum specifies otherwise.
5. Data sharing
We do not sell personal information. We share data only with subprocessors necessary to operate the platform (cloud infrastructure, email delivery, telephony) under contractual data processing agreements. A current list of subprocessors is available upon request. We disclose data when required by law or to protect rights, safety, and property.
6. Data retention
Case data is retained for the period specified in your order form or, absent a specification, for seven (7) years from case closure. Marketing contact data is retained for the duration of our relationship plus two (2) years. You may request deletion of your personal data at any time by emailing hello@ariahotline.com.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict processing. To exercise these rights, contact us at hello@ariahotline.com. We respond within 30 days. If you are a reporter who submitted a report through a client's ARIA intake line, contact the client organization directly — they are the data controller for your report.
8. Cookies
ariahotline.com uses no tracking cookies. We use a privacy-preserving analytics tool (Plausible) that collects no personal data and sets no cookies. See our Cookie Policy for full details.
9. Security
We maintain a SOC 2 Type I-aligned security program and are pursuing SOC 2 Type II certification. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access controls are enforced at the database layer using Row Level Security. We conduct annual penetration testing.
10. Contact
Privacy inquiries: hello@ariahotline.com · ReMyll Group LLC · 625 Kenmoor Ave SE, Ste 350 · Grand Rapids, MI 49546 · United States
11. Updates
We may update this policy from time to time. Material changes will be communicated via email to active clients and posted at ariahotline.com/legal/privacy with a revised effective date.