Privacy Policy
Effective Date: January 1, 2026
Last Updated: December 30, 2025
1. Introduction
Adaptive Solutions Group LLC (doing business as ADSG) ("ADSG," "we," "us," or "our") operates the ADSG Health Check service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Email address, full name, company name
- NetSuite Integration Credentials: RESTlet URL, OAuth 2.0 Client ID, Client Secret (encrypted), Certificate ID (optional), NetSuite Account ID
- Billing Information: Collected and processed by Stripe (we do not store payment card data)
- Communication Data: Email correspondence, support requests
2.2 Information Collected from NetSuite
IMPORTANT: We ONLY collect configuration metadata, NOT your business data.
What We Collect (By Default):
- Script metadata (names, types, owners, descriptions)
- Workflow metadata (names, record types, statuses - NOT execution data)
- Saved search metadata (titles, types, owners - NOT search results)
- Custom field metadata (field IDs, types - NOT field values)
- Custom record type metadata (names, structures - NOT records)
- Role metadata (role names - NOT permissions or user assignments)
- Integration metadata (RESTlet/Suitelet names, statuses - NOT API keys or tokens)
Optional: Script Source Code Review
For deeper analysis, Professional and Enterprise plans offer optional script source code review. This feature is disabled by default and requires your explicit consent to enable. When enabled, script source code is processed in memory for AI analysis and is never permanently stored. You can enable or disable this feature at any time in your organization settings.
What We DO NOT Collect:
- ❌ Customer or client data
- ❌ Transactional data (sales orders, invoices, etc.)
- ❌ Financial records (accounting entries, payments, etc.)
- ❌ Personally Identifiable Information (PII) from your NetSuite
- ❌ Payment or credit card information
- ❌ Employee personal data (salaries, benefits, etc.)
- ❌ Proprietary business data (contracts, pricing, etc.)
- ❌ Email message contents
- ❌ File contents or uploaded documents
2.3 Automatically Collected Information
- Usage Data: IP addresses, browser type, pages visited, time stamps
- Cookies: Session cookies for authentication (required for Service functionality)
3. How We Use Your Information
We use collected information for the following purposes:
- Service Provision: Perform NetSuite health checks and generate reports
- Account Management: Create and manage your account
- Billing: Process subscription payments via Stripe
- Communication: Send service updates, audit notifications, support responses
- AI Analysis: Analyze NetSuite metadata using Anthropic Claude to generate insights and recommendations
- Improvement: Improve our Service, features, and user experience
- Security: Monitor and prevent fraud, unauthorized access, and security issues
- Compliance: Comply with legal obligations and enforce our Terms of Service
We DO NOT sell your data to third parties.
4. Data Retention
- Active Accounts: Data retained while your subscription is active
- Audit Results: Automatically deleted after 1 year from audit completion date
- Deleted Accounts: All data deleted within 90 days of account deletion request
- Encrypted Credentials: Deleted immediately upon account deletion or credential update
- Legal Holds: Data may be retained longer if required by law
You can request data deletion at any time by contacting support@adaptivesuitesolutions.com
5. Data Security
5.1 Encryption
- In Transit: All data transmitted using SSL/TLS encryption
- At Rest: OAuth credentials encrypted using AES-256-CBC encryption
- Database: PostgreSQL with encryption at rest (Supabase)
5.2 Access Controls
- Row Level Security (RLS): Database policies ensure you can only access your organization's data
- OAuth 2.0: Secure authentication for NetSuite integration
- Multi-Tenant Isolation: Complete data separation between organizations
No security system is 100% secure. While we implement industry-standard measures, we cannot guarantee absolute security.
6. Your Rights
6.1 GDPR Rights (EU Users)
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Delete your data ("right to be forgotten")
- Right to Portability: Export your data in machine-readable format
- Right to Object: Object to certain data processing
- Right to Restrict Processing: Limit how we use your data
6.2 CCPA Rights (California Users)
- Right to Know: Disclosure of data collection and sharing practices
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do NOT sell personal information (opt-out not applicable)
- Non-Discrimination: No discrimination for exercising your rights
6.3 Exercising Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@adaptivesuitesolutions.com
- Subject Line: "Data Rights Request"
We will respond within 30 days.
7. Third-Party Services
| Provider | Data Shared | Purpose | Certifications |
|---|---|---|---|
| Supabase | Account data, audit results (metadata only), encrypted credentials | Database & authentication | Enterprise security |
| Stripe | Email, company name, subscription tier | Payment processing | PCI DSS Level 1 |
| Anthropic | NetSuite metadata (scripts, workflows, configs) | AI-powered analysis | Enterprise privacy |
| Vercel | Application code, anonymized logs | Hosting & infrastructure | Enterprise security |
No customer data, transactions, or financial records are shared with any third party.
8. Transparency
What Data We See
When you connect your NetSuite account, we see:
- ✅ Names of your scripts, workflows, and customizations
- ✅ Configuration settings and metadata
- ✅ User IDs and role names (NOT detailed permissions)
We NEVER see (unless you explicitly enable optional features):
- ❌ Your customer names, emails, or contact information
- ❌ Sales orders, invoices, or transaction details
- ❌ Financial data, accounting entries, or payments
- ❌ Script source code (unless you enable optional Script Source Review)
- ❌ Data stored in your custom fields or records
How We Use AI
We use Anthropic Claude (a large language model) to analyze your NetSuite metadata and generate recommendations. The metadata sent to Anthropic includes:
- Script names and descriptions
- Workflow configurations
- Customization structures
Anthropic's privacy commitment: Enterprise data is not used to train models.
9. Contact Us
For questions about this Privacy Policy or our privacy practices:
Adaptive Solutions Group LLC
- Email: privacy@adaptivesuitesolutions.com
- Support: support@adaptivesuitesolutions.com
- Website: adaptivesuitesolutions.com
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via email notification to registered users.
Continued use of the Service after changes constitutes acceptance of the updated policy.
Last Reviewed: December 30, 2025
Effective Date: January 1, 2026