Privacy Policy

Effective Date: September 12, 2026 · Last Updated: September 12, 2026

Continued Compliance, Inc. (“Continued Compliance,” “we,” “us,” or “our”) provides behavioral health accreditation and licensing compliance consulting services, including with respect to CARF/ASAM 3.7 accreditation, Joint Commission accreditation, and state licensing for substance use disorder and behavioral health providers. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit continuedcompliance.com or blog.continuedcompliance.com (the “Site”), submit an inquiry or intake form, subscribe to our newsletter, or use our client portal to exchange documents and case materials with us (collectively, the “Services”).

This Policy is designed to address the requirements of applicable United States federal and state privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and comparable comprehensive privacy statutes in other states — as well as the European Union and United Kingdom General Data Protection Regulation (collectively, “GDPR”) for visitors and clients located in the European Economic Area, the United Kingdom, or Switzerland. Some sections of this Policy therefore apply only to residents of specific jurisdictions, as noted.

By using the Site or our Services, you acknowledge the practices described in this Policy. If you do not agree with this Policy, please do not use the Site or submit personal information to us.

1. Introduction and Scope

See introductory paragraphs above.

2. Information We Collect

2.1 Information You Provide Directly

We collect information you choose to give us, including:

  • Contact and intake forms: name, job title, organization/facility name, email address, phone number, mailing address, state(s) of operation, license or accreditation status, and the content of your message or inquiry.
  • Newsletter and marketing sign-ups: name and email address, and your subscription preferences.
  • Client portal and engagement materials: for active or prospective clients, documents, policies, procedures, personnel records, and other case or engagement materials you upload or share with us in connection with accreditation, licensing, or compliance consulting work. These materials may contain personal information about your own staff, clients, or patients, and in some cases may include protected health information (PHI) — see Section 7 below.
  • Communications: information you provide when you call, email, or otherwise correspond with us.
  • Payment information: if you engage us for paid services, billing name, address, and payment details, which are processed by our third-party payment processor(s); we do not store full payment card numbers on our own systems.

2.2 Information Collected Automatically

When you visit the Site, we and our service providers may automatically collect:

  • Device and usage data: IP address, browser type, operating system, referring/exit pages, pages viewed, time spent on pages, and general location (e.g., city/region inferred from IP address).
  • Cookies and similar technologies: as described in Section 5 (Cookies and Tracking Technologies) and our Cookie Policy.
  • Analytics data: aggregated and individual usage statistics collected through analytics tools (e.g., Google Analytics or similar services) to help us understand how visitors use the Site.

2.3 Information from Other Sources

We may also receive information about you from third parties, such as referral partners, industry associations, publicly available regulatory or licensing databases, or other clients who identify you as a point of contact.

3. How We Use Your Information

We use personal information for the following purposes:

  • To provide, operate, and improve our consulting Services, including accreditation and licensing engagements.
  • To respond to inquiries, schedule consultations, and communicate about engagements.
  • To prepare accreditation applications, policies, and compliance materials on behalf of clients.
  • To send requested newsletters, updates on regulatory changes, and marketing communications (with an option to unsubscribe at any time).
  • To operate, secure, and improve the Site, including diagnosing technical issues and understanding usage trends through analytics.
  • To bill and collect payment for services rendered.
  • To comply with legal obligations, enforce our agreements, and protect the rights, property, and safety of Continued Compliance, our clients, and others.
  • For any other purpose disclosed to you at the time information is collected, or with your consent.

4. Legal Bases for Processing (EEA, UK, and Swiss Users)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data only where we have a valid legal basis to do so under the GDPR, including:

  • Performance of a contract — to provide consulting services you or your organization have engaged us to perform.
  • Legitimate interests — to operate and improve the Site and our business, respond to inquiries, and maintain the security of our systems, provided those interests are not overridden by your data protection interests or fundamental rights.
  • Consent — for newsletter sign-ups, optional cookies, and other processing where we ask for your affirmative consent, which you may withdraw at any time.
  • Legal obligation — where processing is necessary to comply with a legal or regulatory requirement.

5. Cookies and Tracking Technologies

The Site uses cookies and similar technologies (such as web beacons and local storage) to operate the Site, remember preferences, and analyze traffic. These generally fall into the following categories:

  • Strictly necessary cookies: required for core Site functionality (e.g., security, load balancing); these cannot be disabled.
  • Analytics/performance cookies: help us understand how visitors use the Site (e.g., Google Analytics).
  • Functional cookies: remember choices you make to enhance your experience.
  • Marketing cookies: used, if applicable, to measure the effectiveness of our outreach; we do not use these to build advertising profiles for sale to third parties.

You can control cookies through your browser settings, and where required by law (including for EEA/UK/Swiss visitors), we will request your consent via a cookie banner before setting non-essential cookies. Because there is no common industry standard for recognizing browser “Do Not Track” signals, the Site does not currently respond to them, except where required by applicable law (e.g., recognized opt-out preference signals such as the Global Privacy Control for California residents, which we honor as a valid request to opt out of the sale/sharing of personal information). For more detail on the specific cookies used on this Site, see our Cookie Policy.

6. How We Share Your Information

We do not sell your personal information for money, and we do not share personal information for cross-context behavioral advertising. We may disclose personal information in the following circumstances:

  • Service providers: vendors who perform functions on our behalf, such as website hosting, email/newsletter delivery, analytics, IT support, payment processing, and document storage, under contractual confidentiality and data protection obligations.
  • Professional advisors: attorneys, accountants, auditors, and insurers as needed.
  • Accrediting and licensing bodies: where a client engagement requires us to submit or coordinate materials with organizations such as CARF, the Joint Commission, or state licensing agencies, and the client has authorized us to do so.
  • Legal and safety reasons: to comply with applicable law, respond to lawful requests from public authorities, or protect the rights, property, or safety of Continued Compliance, our clients, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • With your consent: for any other purpose disclosed to you at the time of collection or with your agreement.

7. Health-Related and Compliance Information (HIPAA Notice)

Continued Compliance is a consulting firm, not a healthcare provider, health plan, or clearinghouse, and this Site is not intended to collect protected health information (PHI) from patients. However, because our consulting work supports substance use disorder and behavioral health providers, materials shared with us by clients through the client portal or otherwise may contain PHI regulated by the Health Insurance Portability and Accountability Act (HIPAA).

Where we create, receive, maintain, or transmit PHI on behalf of a client that is a HIPAA-covered entity, we do so as a business associate under a Business Associate Agreement (BAA) with that client, and such PHI is handled in accordance with HIPAA’s Privacy, Security, and Breach Notification Rules and the terms of the applicable BAA — not merely under this general Privacy Policy. If you are a client with questions about our BAA or PHI-handling practices, please contact us using the information in Section 15.

8. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including to provide services, maintain business and engagement records, comply with legal, tax, licensing, and accreditation-related recordkeeping obligations, resolve disputes, and enforce our agreements. Client engagement records and related compliance documentation may be retained for extended periods consistent with applicable professional, regulatory, or contractual recordkeeping requirements. When personal information is no longer needed, we take reasonable steps to securely delete, anonymize, or de-identify it.

9. Data Security

We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction, including access controls, encryption where appropriate, and confidentiality obligations for personnel and vendors handling sensitive client materials. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.

10. International Data Transfers

We are based in the United States, and personal information we collect — including from visitors and clients in the European Economic Area, the United Kingdom, or Switzerland — may be transferred to, stored, and processed in the United States or other countries that may not have data protection laws equivalent to those in your home jurisdiction. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards recognized under GDPR, such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable), or another legally recognized transfer mechanism. You may contact us for more information about the safeguards we use for a specific transfer.

11. Your Privacy Rights

11.1 U.S. State Privacy Rights

Depending on where you live, you may have rights under U.S. state comprehensive privacy laws — including California’s CCPA/CPRA and similar laws in states such as Virginia, Colorado, Connecticut, Utah, and others that have since enacted comparable statutes. Subject to applicable exceptions, these rights generally include the right to:

  • Know/Access — request confirmation of whether we process your personal information and access to that information, including the categories collected, sources, purposes, and categories of third parties with whom it is shared.
  • Delete — request deletion of personal information we hold about you, subject to legal exceptions (e.g., information needed to complete a transaction or comply with a legal obligation).
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale or sharing — opt out of any sale of personal information or sharing for cross-context behavioral advertising (as noted above, we do not currently engage in either).
  • Opt out of profiling — opt out of automated decision-making with significant legal or similarly significant effects, where applicable.
  • Non-discrimination — we will not discriminate or retaliate against you for exercising these rights.
  • Appeal — in applicable states, appeal a denial of a rights request.

To exercise these rights, contact us using the information in Section 15. We will verify your identity before responding and may ask you to confirm certain details for that purpose. You may also designate an authorized agent to submit a request on your behalf, subject to verification.

11.2 GDPR Rights (EEA, UK, and Swiss Residents)

If you are located in the EEA, UK, or Switzerland, you have the right to:

  • Access the personal data we hold about you and obtain a copy of it.
  • Rectify inaccurate or incomplete personal data.
  • Erase your personal data (“right to be forgotten”), subject to certain exceptions.
  • Restrict or object to our processing of your personal data, including processing based on legitimate interests and, where applicable, direct marketing.
  • Data portability — receive your personal data in a structured, commonly used, machine-readable format, where technically feasible.
  • Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us using the information in Section 15.

12. Children’s Privacy

The Site and our Services are directed to businesses and professionals and are not intended for, or knowingly directed to, children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

13. Third-Party Links

The Site may contain links to third-party websites, including accrediting bodies, state licensing agencies, and industry resources. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing personal information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the revised Policy on this page with an updated “Last Updated” date, and, where required by law, provide additional notice of material changes.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:

Continued Compliance, Inc.
Email: ant@continuedcompliance.com
Mailing Address: 4715 N. Grand Canyon Dr. Las Vegas, NV 89129
Phone:310-749-0978

Top