Data, Privacy & Communications

How Blackvine Media Handles Data, Access, and Client Communications

This page explains our operational approach to system access, account ownership, email and SMS consent, credentials, and healthcare-related information. It describes how we work — it is not a legal document and should not be read as legal advice.

How We Access Your Systems

Blackvine follows a minimum-necessary approach to system access: we request only the access required to organize contact records, build segments, configure lifecycle stages and pipelines, build email and SMS workflows, manage rebooking and reactivation, and track sources and conversions.

  • Access is limited by user role and follows the minimum-necessary principle.
  • Sensitive information is not placed in URLs, tracking parameters, or unnecessary custom fields.
  • Sensitive information is not included in message content beyond what the approved purpose requires.
  • Segmentation uses only the data needed for the approved purpose.
  • We do not use clinical or sensitive details merely because they happen to be available.

Client Account Ownership

When you already have the required CRM, email, SMS, analytics, advertising, form, or scheduling accounts, we work inside them. When you don’t, we may help create and configure new accounts — always structured around your ownership, not ours.

  • New accounts are created in the client’s legal business name whenever practical.
  • The client is the primary owner or administrator; billing stays under client control.
  • Blackvine is added through individual user access with appropriate permissions — shared passwords are avoided whenever individual access is available.
  • The client retains ownership of its accounts, data, contacts, domains, phone numbers, workflows, reporting assets, and approved message content.
  • Blackvine may administer accounts during implementation or ongoing management, but access is reduced or removed when it is no longer required.
  • Credentials and system access are not withheld from the client. Any exception is disclosed and agreed to in writing.

Creating or configuring an account on a client’s behalf does not make that account Blackvine’s property.

Credentials & Access Security

  • Individual user accounts are used whenever possible; shared passwords are avoided.
  • Multifactor authentication is enabled where available.
  • Broad administrative access is not granted when a lower permission level is sufficient.
  • Access is removed or reduced when a task or engagement ends.

Healthcare-Related Information

Because several of the industries we work with (dental, med spa, chiropractic) involve health-related contact, our standard operating procedure is to avoid accessing protected health information unless it is genuinely necessary for the approved scope and separately evaluated.

Blackvine generally works with the contact, status, source, appointment, and communication data needed to organize CRM records, segment audiences, and operate approved follow-up systems. Our standard approach is to avoid accessing clinical or protected health information unless it is necessary for the agreed scope and appropriate safeguards are established.

We should not intentionally request or use:

  • Diagnoses
  • Treatment notes
  • Medical histories
  • Clinical records
  • Prescription information
  • Insurance details
  • Other detailed health-condition data

…unless a project specifically requires it and the legal, contractual, platform, access-control, and Business Associate Agreement requirements have been addressed in advance. Whether a Business Associate Agreement is required is evaluated before any protected health information is accessed. Blackvine does not claim universal HIPAA compliance.

Team & Contractor Access

Client-system access may be granted only to people who need it for the approved work. Authorized access may include Jack Romrell, Eli Kaufman, Blackvine team members, approved contractors, and associated specialists engaged for a defined project need.

  • Access follows the minimum-necessary principle — each person receives only the permissions required for their role.
  • Individual user accounts are used whenever possible; shared passwords are avoided.
  • Multifactor authentication is enabled where available.
  • Contractors receive access only when needed for an approved business purpose, and access is removed or reduced when the task or engagement ends.
  • Anyone with access is expected to protect client information and follow Blackvine’s confidentiality and data-handling requirements.
  • Broad administrative access is not granted when a lower permission level is sufficient, and sensitive or protected information is not accessed merely because it is available.
  • A client may be informed when outside contractors or specialists require meaningful access to sensitive systems or data, where appropriate.

We do not claim that only the founders will ever access client accounts, and we do not imply that every contractor automatically receives access. We do not currently claim a formal security certification, a contractor background-check program, or a formal compliance program — unless one is later established and verified.

Shared Responsibilities

Data handling and communications compliance are a shared responsibility between Blackvine and the client:

  • The client remains responsible for confirming the accuracy and appropriateness of services, offers, pricing, clinical statements, appointment policies, consent language, legal disclosures, industry-specific claims, and geographic or licensing restrictions.
  • The client remains responsible for determining which information may lawfully be used for marketing and operational communication.
  • For regulated communications, qualified legal or compliance review may be appropriate.

Message Drafting & Approval, in Short

Blackvine drafts the message, conducts an internal quality and risk review, and the client reviews and confirms accuracy before approving it for launch — unless a different written approval process applies. Material changes may require renewed client review. The full message-approval process is documented on the Services page.

Questions About How We Handle Your Data?

The Revenue Leak Audit conversation is a good place to ask about access, ownership, and communications specifics for your business.