top of page

Privacy Policy

 

Effective: September 17, 2026

Last updated: September 17, 2026

Carr Allison (“Company”, “we”, “our”, or “us”) respects and values your privacy. This Privacy Policy (“Policy”) describes our policies and practices regarding the collection, use, and sharing of Personal Information of the visitors to our websites (www.carrallison.com and www.carrallisonmsa.com) and services that link to this Policy (our “Services”).

Please read this policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our Services or providing us with your information, you agree to the terms of this Policy. If you do not agree with this Policy, do not access, view, or use any of the Services. This policy may change from time to time (see How We Retain Your Personal Information). Your continued use of the Services after we make changes as described here is acceptance of those changes; so please check the policy periodically for updates.

What Information Does This Policy Apply To?

This policy applies only to information we collect:

  • Through the Services.

  • In communications, including email, text, chat, and other electronic messages, between you and the Services.

  • Via our newsletters, client alerts, and other like publications and disseminated information (our “Content”).

It does not apply to information collected by:

  • Us offline, not through the Services, or through any other means, including on any other website operated by Company or any third party that does not link to this policy.

  • Our clients that is provided to us in the course of an attorney client relationship (even if provided through online forms or file uploads hosted on our websites), in which case it is our clients’ responsibility to comply with applicable law, rules, and contractual obligations as to the data they share with us.

  • Any third party, including through any application or content (including advertising) that may link to or be accessible from or through the Services.

Children’s and Minors’ Data

Our Services are not intended for, and we do not knowingly collect any Personal Information from, children under the age of 18. If we learn we have collected or received Personal Information from a child under 18 years old without verification of parental consent, we will delete that information.

What Information Do We Collect?

We collect and process a range of Personal Information. “Personal Information” is information that identifies, relates to, or describes, directly or indirectly, you as an individual, such as your name, email address, telephone number, home address, or payment information.

The types and categories of personal data we collect or process through the Services include:

  • Identifiers.

    • Contact information, including a real name, alias, address (such as home address, work address, or other address), email address, phone number, and other similar information you provide us, including through the “Contact Us” forms on our websites or your subscription to our Content lists.

    • Device information. IP addresses, device identifiers, operating system and version, hardware identifiers, browser type and settings, unique personal identifier, online identifier, referring URLs, pages visited, and other general usage and device information or information arising from your interactions with the Services or that we collect through cookies or similar tracking technologies deployed by our websites’ hosting platform or third-party analytics tools (see How We Collect Information and Your Rights and Choices About Your Information).

We also collect non-Personal Information through the Services, such as:

  • Statistical or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from Personal Information. For example, we may aggregate Personal Information to calculate the percentage of users accessing a specific Services feature.

  • Technical information. Technical information includes information about your internet connection and usage details about your interactions with the Services, such as clickstream information to, through, and from our Services (including date and time), products that you view or search for, page response times, download errors, length of your visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods used to browse away from a page.

If we combine or connect non-personal statistical or technical data with Personal Information so that it directly or indirectly identifies an individual, we treat the combined information as Personal Information.

What Information Do We Not Collect?

There are many types of Personal Information that we do not collect through the Services, including:

  • Protected class characteristics or information related to race, ethnicity, religion, sexual orientation, or citizenship/immigration status.

  • Commercial information.

  • Biometric information.

  • Sensory data.

  • Precise geolocation.

  • Financial account information.

  • Government-issued identifiers.

  • Professional or employment-related information.

  • Non-public education information.

  • Inferences drawn from other Personal Information.

Some Personal Information may be considered sensitive Personal Information, such as social security numbers, racial or ethnic origin, union membership, genetic information, health information, or sexual orientation. We do not collect sensitive Personal Information through the Services. While we may hold sensitive Personal Information, including health information or PHI, that our clients provide to us in the course of an attorney-client relationship via file uploads hosted on our websites, that information is not collected through your use of the Services and is not subject to this Policy (see What Information Does This Policy Apply To? and Important Notice About Sensitive Information, HIPAA, and PHI).

How Do We Collect Information?

We collect information in three ways:

  • When you provide it to us.

  • Automatically when you use our Services.

  • From third parties.

Information You Provide Us

We collect information about you when you interact with our Services, such as when you complete contact and subscription forms on our websites or otherwise subscribe to Content, participate in webinars, conferences, or other events hosted by us.

Information Collected Automatically

As you navigate through and interact with our Services, we may use automatic data collection technologies to collect information that may include personal data. Information collected automatically may include usage details and patterns, IP addresses, operating system, and browser type, and information collected through cookies, web beacons, and other tracking technologies including details of your interactions with our Services, such as traffic data, location data, logs, and other communication data, and which resources and Services features that you access and use.

We do not, however, use these automatic collection technologies to collect information about your online activities over time and across third-party sites or other online services (behavioral tracking).

Using automatic collection technologies helps us to improve our Services and to deliver a better and more personalized experience.

The technologies we use for this automatic data collection may include:

  • Cookies (or Browser Cookies). A cookie is a small file placed on your device when you interact with the Services. You may refuse to accept or disable cookies by activating the appropriate setting on your browser or device. However, if you select this setting, you may be unable to access certain features of the Services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Services.

  • Web Beacons. Some parts of the Services and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those parts or opened an email and for other related statistics (for example, recording the popularity of certain content and verifying system and server integrity).

To the extent any of these automated technologies are considered a personal data sale, targeted advertising, or profiling, under applicable laws, depending on where you live, you may opt out from use of these automated technologies for such uses by emailing privacy@carrallison.com. Please note that some Services features may be unavailable as a result.

Information Collected from Third Parties

We may receive Personal Information about you from other sources and combine that with information we collect directly from you. For example, we may obtain information about you from service providers that we engage to perform services on our behalf, such as email platform providers, and services related to content delivery, analytics, security, and anti-fraud measures. We do not, however, receive personal information from third-party data brokers or analytics providers. And, other than the automatic collection technologies discussed in this Policy, we do not allow third parties to collection information from you when using the Services.

When you interact with the Services, there are third parties that may use automatic collection technologies to collect information about you or your device. These third parties include:

  • Analytics companies.

  • Your internet or mobile service provider.

These third parties may use tracking technologies to collect information about you when you use the Services. The information they collect may be associated with your Personal Information or they may collect information, including Personal Information, about your online activities over time and across different websites, apps, platforms, and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the provider responsible directly.

How Do We Use Your Information?

We use information that we collect about you or that you provide to us, including any personal data, to:

  • Provide you with the Services and any contents, features, information, products, or services that we make available through the Services.

  • Communicate with you, for example, by responding to inquiries submitted through “Contact Us” forms on the websites.

  • Conduct client intake and evaluate potential legal matters submitted to us.

  • Provide legal advice, representation, and services to our clients.

  • Communicate with clients regarding their matters, case status, and related legal services.

  • Distribute news, alerts, and updates to subscribers who opt in to our email mailing list or other Content.

  • Fulfill the purposes for which you provided your personal information or that were described to you at collection, and as the CCPA otherwise permits.

  • Improve our Services, including by analyzing your information and creating aggregated data derived from your information to develop, maintain, analyze, improve, optimize, measure, and report on our Services and their features and how users interact with them.

  • Market our legal services, the Services, or employment opportunities.

  • Maintain our websites’ security and prevent fraud or abuse.

  • Comply with applicable legal obligations, including our professional and ethical obligations as attorneys and responding to law enforcement requests, court orders, or demands made under applicable law.

  • Promote our Services, business, and offerings by publishing advertising on our own Services. We may use your information to model, segment, target, offer, market, and advertise our Services (however, we will not engage in targeted advertising to you).

  • Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.

  • Notify you when Services updates are available and about changes to any services we offer or provide through them.

  • Administer our systems and conduct internal operations, including for troubleshooting, data analysis, testing, research, statistical, and survey purposes.

  • Protect our Company, employees, or operations.

  • Exercise or defend the legal rights of the Company and its employees, customers, and agents.

  • In any other way we may describe when you provide the information.

  • For any other purpose with your consent.

The usage information we collect, whether connected to your personal data or not, helps us improve our Services and deliver a better and more personalized experience by enabling us to:

  • Estimate our audience sizes and usage patterns.

  • Understanding how visitors use the Services.

  • Store information about your preferences, allowing us to customize the Services according to your individual needs and interests.

  • Speed up your searches.

  • Recognize you when you return to our Services.

We do not use personal information collected through the Services for direct marketing, profiling, or targeted advertising.

We do not collect, use, or sell personal data for the purpose of training large language models or other AI tools nor do we use automated decision-making technologies.

Who Do We Disclose Information To?

We do not sell, rent, trade, or otherwise disclose Personal Information other than as described in this Policy, and we do not sell, share, rent, trade or otherwise disclose personal information for monetary or other valuable consideration.  None of our revenue is derived from data sales. We do not disclose personal information to third parties for their own marketing purposes, and we do not share personal information for cross-context behavioral advertising. The only commercial purposes for which we may disclose Personal Information are disclosed in this Policy.

We may disclose aggregated information about our users and information that does not identify any individual without restriction.

We may also disclose personal data that we collect or you provide as described in this privacy policy:

  • To website hosting providers.

  • To contractors, service providers, and other third parties we use to support our organization and who are bound by contractual obligations to keep personal data confidential and use it only for the purposes for which we disclose it to them, for example, email marketing service providers, analytics providers, and IT service providers and vendors, cloud storage providers, and communications tools providers.

  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Carr Allison’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal data held by Carr Allison is among the assets transferred.

  • To fulfill the purpose for which you provide it.

  • For any other purpose disclosed by us when you provide the information.

  • With your consent.

We may also disclose your personal data:

  • To comply with any court order, law, or legal process, including to respond to any government or regulatory request.

  • To enforce or apply our terms of use and other agreements, including for billing and collection purposes.

  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of our organization, our clients, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

Your Rights and Choices About Your Information

This section describes mechanisms you can use to control certain uses and disclosures of your information and rights you may have under state law, depending on where you live.

Tracking Technologies, Content, Promotion, and Targeted Advertising

  • Cookies and Other Tracking Technologies. You can set your browser to refuse all or some browser cookies or other tracking technology files, or to alert you when these files are being sent. If you disable or refuse cookies or similar tracking files, some Services features may be inaccessible or not function properly. Some browsers include a “Do Not Track” (DNT) setting that can send a signal to the online services you visit indicating you do not wish to be tracked. Because there is not a common understanding of how to interpret the DNT signal, our Services may not respond to all browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the cookie controls and advertising controls described in this policy and the Cookie Policy located on the websites.

  • Google Analytics. Google Analytics collects Personal Information through the Services, including through the use of cookies. For information about how Google Analytics collects and processes data, please click here. To opt out of having your information used by Google Analytics, please click here. For more information, please visit Google’s privacy policy here.

  • Emails, Alerts, Newsletters, and Promotion. If you do not wish us to use your Personal Information to promote our products or services, you can opt out by sending an email to privacy@carrallison.com. If we have sent you a promotional email or you have otherwise received emails, alerts, newsletters, or other Content from us, you may unsubscribe directly via the channel through which you received such email or Content. For example, you may send us a return email asking to be omitted from future email distributions or click “unsubscribe” in the relevant communications.

  • Targeted Advertising. We do not conduct targeted advertising nor do we disclose your personal information to third-parties for their advertising purposes. However, we do not control third parties’ collection or use of your information to serve interest-based advertising. These third parties may provide you with ways to choose not to have your information collected or used in this way. To learn more about opting out of receiving targeted ads from members of the Network Advertising Initiative (“NAI”), including how to add the NAI Global Privacy Control (GPC) extension to your Chrome web browser, see NAI: How to Opt Out.

Your State Privacy Rights

Depending on your state of residency, you may have certain rights related to your personal data, including:

  • Access and Data Portability. You may confirm whether we process your personal data and access a copy of the personal data we process. To the extent feasible and required by state law, depending on your state, data will be provided in a portable format. Depending on your state, you may have the right to receive additional information and it will be included in the response to your access request.

  • Correction. You may request that we correct inaccuracies in your personal data that we maintain, taking into account the information’s nature and processing purpose.

  • Deletion. You may request that we delete personal data about you that we maintain, subject to certain exception under applicable law.

  • Opt Out of Using Personal Data for Sales, Targeted Advertising, and Profiling for Certain Legal or Similarly Significant Decisions. You may request that we do not use your personal data for these purposes. Some states may also grant you the ability to learn more about or challenge those automated decisions.

Important: The exact scope of these rights vary by state. There are also several exceptions where we may not have an obligation to fulfill your request.

To exercise any of these rights, please email privacy@carrallison.com. To appeal a decision regarding a consumer rights request email privacy@carrallison.com.

Some browsers and browser extensions support the Global Privacy Control (“GPC”) that can send a signal to process your request to opt out from certain types of data processing, including data “sales” as defined under certain laws. When we detect such a signal, we will make reasonable efforts to respect your choices indicated by a GPC setting as required by applicable law.

Nevada provides its residents with a limited right to opt out of certain personal data sales. Residents who wish to exercise their sale opt-out rights may submit a request to this designated address: email privacy@carrallison.com. However, please know we do not currently sell data triggering that statute’s opt-out requirements.

If you are a California resident, additional information applies to you. To access our supplemental California privacy statement and learn more about California residents’ privacy rights, see the California-Specific Privacy Disclosures section below.

Links to Other Sites

Occasionally, we provide links to other third-party websites for your convenience and information. These websites operate independently from our Sites and are not under our control or direction. These sites may have their own privacy notices or terms of use. We are not responsible for the content of these sites, any products or services that may be offered through these sites, or any other use of these sites. We strongly encourage you to carefully review the privacy policies and other terms and conditions of these third-party Sites upon visiting them.

How We Protect Your Personal Information

We use commercially reasonable administrative, physical, and technical measures designed to protect your personal data from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure.  However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal data transmitted to, through, using, or in connection with the Services. In particular, email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal data is at your own risk.

The safety and security of your information also depends on you. You are responsible for taking steps to protect your personal data against unauthorized use, disclosure, and access.

Important Notice About Sensitive Information, HIPAA, and PHI

We represent a wide range of clients, including those that are “covered entities” under the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”).  During those representations, our covered-entity clients may submit PHI to us through designated online forms or file uploads hosted on our website. When we receive and handle PHI in connection with representing a covered-entity client, our use and disclosure of that PHI is governed by the agreement between us and that client, applicable law, and our professional responsibilities, not this policy. To be clear, this policy does not apply to that information (see What Information Does this Policy Apply To?), and none of your health information is automatically collected by your use of the websites.

If you are a client whom we have requested to do so, you may submit PHI to us only through the designated secure forms and uploads we provide for that purpose. Do not submit PHI through general contact forms, general inquiry forms, or unsolicited file uploads on our website. If you are unsure whether or how to submit such information, please contact us first using the contact information provided at the end of this Policy. You may also contact us by telephone or mail as alternative methods of communication if you prefer not to submit sensitive information electronically.

If you are not a client or are a visitor to our website, do not submit health information, PHI, or other sensitive personal information to us, including through any website form or file upload.

If you are an individual who, despite the instruction above not to, voluntarily submits your own health information to us through our website outside of a covered-entity client relationship, that information may not be protected by HIPAA’s privacy and security rules in the same manner as health information held by your healthcare providers. We will handle any such information in accordance with this Policy and applicable law. We do not use or disclose it as a HIPAA business associate.

We treat all PHI and health information that we receive from our covered-entity clients, or from their other service providers acting for them, as sensitive and confidential, and we maintain policies and procedures to implement reasonable administrative, physical, and technical safeguards to protect the confidentiality, integrity, and security of PHI, consistent with our obligations under our agreements with those clients, applicable law, and our professional responsibilities.

How We Retain Your Personal Information

We keep the categories of personal data described in this policy for as long as reasonably necessary to fulfill the purposes described or for as otherwise legally permitted or required, such as maintaining the Services, operating our organization, complying with our legal obligations, resolving disputes, and for safety, security, and fraud prevention.  This means that we consider our legal and business obligations, potential risks of harm, and nature of the information when deciding how long to retain personal data. At the end of the retention period, personal data will be deleted, destroyed, or deidentified. For health information and protected health information (PHI) that we receive from our clients in the course of an attorney-client relationship (which is not subject to this Policy), we retain such information only as long as necessary to provide legal services, fulfill our professional and ethical obligations as attorneys, and comply with applicable legal and regulatory requirements.

If you are a California resident, visit the California-Specific Privacy Disclosures section below for more information about the retention periods that apply to the personal data categories we collect.

Global Data Transfer, Storage, and Processing Practices

Our target audience is within the United States. Our headquarters is in the United States. We store or Process your Personal Information in the cloud in locations within the United States. We will not transfer or store your Personal Information in “countries of concern,” as currently designated by the U.S. government. Personal Information may also be stored on the servers of our service providers and agents.

Wherever your Personal Information is transferred, stored or processed by us, we will take reasonable steps to safeguard the privacy of your Personal Information. These steps also may include, if applicable, implementing standard contractual clauses (e.g. the “Standard Contractual Clauses” approved by the European Commission), obtaining your consent, or other lawful means of transferring Personal Information. By using the Services, you acknowledge that your Personal Information will be stored and/or processed as set forth above. If you have any concerns about how your data is being transferred, stored, or processed, please contact us as provided in the “Contact Information” section below.

Changes to Our Privacy Policy

We may update this policy from time to time, and we will provide notice of any such changes to the policy as required by law. The date the privacy policy was last updated is identified at the top of the page. We will notify you of changes to this policy by updating the “last updated” date and posting the updated policy on the Services. We may email or otherwise communicate reminders about this policy, but you should check our Services periodically to see the current policy and any changes we have made to it.

Contact Information

To exercise your rights or ask questions or comment about this privacy policy or our privacy practices, contact us at:

By mail:

Carr Allison

Attn: Andy Wood, Chief Information Officer

100 Vestavia Parkway Birmingham, AL 35216

By email: privacy@carrallison.com

By phone: (205) 822-2006

To register a complaint or concern, please email us at privacy@carrallison.com.

California-Specific Privacy Disclosures and Notice at Collection

This section provides additional information for California residents as required by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Personal Information Categories We Collect

The chart below identifies the categories of personal information we have collected from California consumers within the last 12 months, using the specific categories defined by the CCPA:

Category

Sources of Collection

Business or Commercial Purpose

Sold or Shared

Retention Period

Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers.

Directly from you; indirectly from you as you use the Services; data analytics providers.

For job applicants: recruiters; background check providers.

Communicate with and market to you; protect and secure our digital and physical environments; improve and make the Services available.

For job applicants: assess applications; satisfy legal obligations.

Technology service providers; data analytics providers.

For job applicants: background check providers.

For employees: human recourses providers.

Length of business relationship with you, if any, plus the longer of 6 years or any applicable legal requirement.

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, signature, address, telephone number, or any other financial information. Some personal information included in this category may overlap with other categories.

Directly from you.

For job applicants: recruiters; background check providers.

Communicate with you; protect and secure our digital and physical environments.

For job applicants: process applications; satisfy legal obligations.

Technology service providers; data analytics providers.

For job applicants: background check providers.

For employees: human recourses providers.

Length of business relationship with you, if any, plus the longer of 6 years or any applicable legal requirement.

Protected classification characteristics under California or federal law. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, reproductive health decision-making, military and veteran status, or genetic information (including familial genetic information).

Directly from you.

For job applicants: recruiters; background check providers.

Satisfy legal obligations.

Technology service providers.

For job applicants: background check providers.

For employees: human recourses providers.

Length of business relationship with you, if any, plus the longer of 6 years or any applicable legal requirement.

Commercial information. Records of personal property, products, or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

We do not collect.

Not applicable.

Not applicable.

Not applicable.

Biometric information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.

We do not collect.

Not applicable.

Not applicable.

Not applicable.

Internet or other similar network activity. Activity on our websites, mobile apps, or other digital systems, such as internet browsing history, search history, system usage, electronic communications with us, postings on our social media sites.

Indirectly from you as you use the Services; data analytics providers.

Protect and secure our physical and digital environment; improve and make Services available; perform analytics.

Technology service providers; data analytics providers.

For employees: human resources providers.

Longer of 6 years or any applicable legal requirement. 

Geolocation data. Physical location or movements.

We do not collect.

Not applicable.

Not applicable.

Not applicable.

Sensory data. Audio, electronic, visual, thermal, olfactory, or similar information.

We do not collect.

Not applicable.

Not applicable.

Not applicable.

Professional or employment-related information. Current or past job history or performance evaluations.

Directly from you.

For job applicants: recruiters; background check providers.

Satisfy legal obligations.

For job applicants: process applications.

For employees: human resources management.

Technology service providers.

For job applicants: background check providers.

For employees: human recourses providers.

Length of business relationship with you, if any, plus the longer of 6 years or any applicable legal requirement.

Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

Directly from you.

For job applicants: recruiters.

Satisfy legal obligations.

For job applicants: process applications.

For employees: human resources management.

For job applicants: background check providers.

For employees: human recourses providers.

Length of business relationship with you, if any, plus the longer of 6 years or any applicable legal requirement.

Inferences drawn from other personal information. Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.

We do not collect.

Not applicable.

Not applicable.

Not applicable.

Sensitive Personal Information Categories

The chart below identifies which sensitive personal information categories we have collected from California consumers in the last 12 months:

Category

Sources of Collection

Business or Commercial Purpose

Sold or Shared

Retention Period

Government identifiers, such as Social Security number, driver's license, state identification card, or passport number.

Directly from you.

For job applicants: recruiters, background check providers.

Process job applications; satisfy legal obligations.

For job applicants: background check providers.

As long as you are employed here plus 6 years, absent contrary contractual or legal requirement.

If non-hired applicant, 6 years, absent contrary contractual or legal requirement.

Complete account access credentials, such as usernames, account logins, account numbers, or card numbers combined with required access/security code or password.

We only collect if you are our employee; if so, directly from you.

Physical and digital security.

Technology service providers.

As long as you are employed here plus 6 years, absent contrary contractual or legal requirement.

Racial or ethnic origin.

We typically don’t collect unless you’re our employee and voluntarily disclose; if so, directly from you.

For job applicants: recruiters.

Satisfy legal obligation; perform human resources management.

Not applicable.

As long as you are employed here plus 6 years, absent contrary contractual or legal requirement.

Citizenship or immigration status.

We only collect if you are our employee and voluntarily disclose; if so, directly from you.

Satisfy legal obligation; perform human resources management.

Not applicable.

As long as you are employed here plus 6 years, absent contrary contractual or legal requirement.

Religious or philosophical beliefs.

We only collect if you are our employee and voluntarily disclose; if so, directly from you.

Satisfy legal obligation; perform human resources management.

Not applicable.

As long as you are employed here plus 6 years, absent contrary contractual or legal requirement.

Mail, email, or text messages not directed to the Company.

We only collect if you are our employee and voluntarily disclose; if so, directly from you.

Satisfy legal obligation; perform human resources management.

Not applicable.

As long as you are employed here plus 90 days to 1 year, depending on your position.

We do not collect: precise geolocation, union membership, genetic data, neural data, unique identifying biometric information, health information, sex life or sexual orientation information, or children’s personal information.

Sources of Personal Information

We obtain the categories of personal information listed above from the following categories of sources:

  • Directly from you, such as from the forms or other information you provide to the Company.

  • Indirectly from you, such as from your interactions with the Company’s websites.

  • From our service providers, such as website hosting providers, email platform providers, IT service providers, cloud storage providers, and analytics providers.

How We Use Personal Information

The above charts show how we may use and disclose specific personal information that we collect through the Services to advance the Company’s business and commercial purposes. As shown above, we use and disclose personal information to:

  • Provide you with the Services and any contents, features, information, products, or services that we make available through the Services.

  • Communicate with you, for example, by responding to inquiries submitted through “Contact Us” forms on the websites.

  • Conduct client intake and evaluate potential legal matters submitted to us.

  • Provide legal advice, representation, and services to our clients.

  • Communicate with clients regarding their matters, case status, and related legal services.

  • Distribute news, alerts, and updates to subscribers who opt in to our email mailing list or other Content.

  • Fulfill the purposes for which you provided your personal information or that were described to you at collection, and as the CCPA otherwise permits.

  • Improve our Services, including by analyzing your information and creating aggregated data derived from your information to develop, maintain, analyze, improve, optimize, measure, and report on our Services and their features and how users interact with them.

  • Market our legal services, the Services, or employment opportunities.

  • Maintain our websites’ security and prevent fraud or abuse.

  • Comply with applicable legal obligations, including our professional and ethical obligations as attorneys and responding to law enforcement requests, court orders, or demands made under applicable law.

  • Promote our Services, business, and offerings by publishing advertising on our own Services. We may use your information to model, segment, target, offer, market, and advertise our Services (however, we will not engage in targeted advertising to you).

  • Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.

  • Notify you when Services updates are available and about changes to any services we offer or provide through them.

  • Administer our systems and conduct internal operations, including for troubleshooting, data analysis, testing, research, statistical, and survey purposes.

  • Protect our Company, employees, or operations.

  • Exercise or defend the legal rights of the Company and its employees, customers, and agents.

  • In any other way we may describe when you provide the information.

  • For any other purpose with your consent.

Use of Sensitive Personal Information

While we may hold sensitive Personal Information, including health information or PHI, that our clients provide to us in the course of an attorney-client relationship via file uploads hosted on our websites, that information is not collected through your use of the Services and is not subject to this Policy (see What Information Does This Policy Apply To? and Important Notice About Sensitive Information, HIPAA, and PHI).

We also do not process sensitive personal information for the purpose of inferring characteristics about a consumer or disclose sensitive personal information for purposes other than those specified in section 7027(m) of the CCPA regulations promulgated by the California Privacy Protection Agency.  Therefore, we do not offer consumers the option to limit the use of their sensitive personal information.

Disclosure of Personal Information

We may disclose the personal information we collect, to service providers and contractors for the business purposes described in the “How We Use Your Information” section above.  We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet the CCPA’s other contract requirements for engaging service providers or contractors.

The personal information categories we have disclosed to service providers or contractors for a business purpose over the preceding 12 months include:

  • Identifiers

  • California Customer Records

  • Internet or other similar network activity

  • Protected classification characteristics

  • Professional or employment-related information

  • Non-public education information

We disclosed these categories to the following types of service providers and contractors:

  • Technology service providers (e.g., website hosting, IT service, cloud storage, communication, and email platform providers)

 

  • Data analytics providers

  • Background check providers

  • Human resources providers

Sales and Sharing of Personal Information

We do not sell your personal information to third parties and have not sold it in the preceding 12 months.

We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.

We do not have actual knowledge that we sell or share the personal information of consumers under age 16.

Your California Privacy Rights

If you are a California resident, the CCPA grants you the following rights regarding your personal information:

Right to Know and Data Portability

You have the right to request that we disclose certain information to you about our collection and use of your personal information (the “right to know”), including the specific pieces of personal information we have collected about you (a “data portability request”).  Our response will cover the 12-month period preceding the request. You may exercise your right to know twice in any 12-month period.

Once we receive your request and confirm your identity, we will disclose to you:

  • The categories of personal information we collected about you and sources from which we collected your personal information.

  • The business or commercial purpose for collecting your personal information and, if applicable, selling or sharing your personal information.

  • If applicable, the categories of persons, including third parties, to whom we disclosed your personal information, including separate disclosures identifying the categories of your personal information that we disclosed for a business purpose to each category of persons.

  • When your right to know submission includes a data portability request, a copy of your personal information, subject to any permitted redactions.

Right to Delete

You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions and limitations.  Once we receive your request and confirm your identity, we will delete your personal information from our systems unless an exception allows us to retain it. We will also notify our service providers and contractors to take appropriate action.

Right to Correct

You have the right to request correction of personal information we maintain about you that you believe is inaccurate.  We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct personal information that our review determines is inaccurate and notify our service providers and contractors to take appropriate action.

Right to Opt-Out of Sales and Sharing

You have the right to request that businesses stop selling or sharing your personal information at any time (the “right to opt-out”), including through a user-enabled opt-out preference signal.  As we do not sell or share consumers’ personal data, we do not currently provide this consumer right.

Right to Non-Discrimination

You have the right not to be discriminated or retaliated against for exercising any of your privacy rights under the CCPA.

ADMT Rights

We do not currently use ADMT to make significant decisions about consumers, so we do not provide ADMT access, opt-out, or appeal rights.

How to Exercise Your California Privacy Rights

To exercise your right to know (including data portability), delete, or correct described above, please submit a verifiable request to us by either:

You or your authorized agent may only submit a request to know, including for data portability, twice in a 12-month period.

Verification Process

Only you, or someone legally authorized to act on your behalf, may make a request to know, delete, or correct related to your personal information.  To designate an authorized agent, please provide written authorization signed by you authorizing the agent to act on your behalf.

We may request specific information from you or your authorized representative to confirm your or their identity before we can process your right to know, delete, or correct your personal information.  We cannot respond to your request to know, delete, or correct if we cannot verify your identity or authority to make the request and confirm the personal information relating to you. We will only use personal information provided in the request to verify the requestor’s identity or authority to make the request.

You do not need to create an account with us to submit a request to know, correct, or delete.

Response Timing and Format

We will confirm receipt of your request within ten business days. If you do not receive confirmation within the ten-day timeframe, please contact us at privacy@carrallison.com.

We endeavor to substantively respond to a verifiable request within 45 days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing.

We will deliver our written response to your verified email address or password-protected account. Our substantive response will tell you whether or not we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions.

Any disclosures we provide will cover information for the 12-month period preceding the request’s receipt date.

For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.

We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Contact for California Privacy Rights

To exercise your California privacy rights or ask questions about this California-specific disclosure, please contact us using the contact information provided in the Contact Information section of this Policy.

© 2026 Carr Allison Medicare Compliance Group

100 Vestavia Parkway

Birmingham, AL 35216

P: 205.822.2006

F: 205.822.2057

E: referral@carrallison.com

FOLLOW US:

  • LinkedIn - White Circle
  • Twitter - White Circle

 

Required statement from the AL State Bar:  No representation is made that the quality of legal services to be performed is greater than the quality of legal services provided by other lawyers.  Any recoveries and testimonials are not an indication of future results. Every case is different, and regardless of what friends, family, or other individuals may say about what a case is worth, each case must be evaluated on its own facts and circumstances as they apply to the law. The valuation of a case depends on the facts, the injuries, the jurisdiction, the venue, the witnesses, the parties, and the testimony, among other factors.  Disclaimer.

bottom of page