EU/UK/CAN Privacy Policy

Effective Date: September 29, 2026

Last Modified: September 29, 2026

1. Introduction

Donald Miller Words LLC and its related companies (“DM Words,” “we,” “us,” or “our”) operate numerous websites, including, without limitation, storybrand.com, businessmadesimple.com, thecustomeristhehero.com, 5minutemarketingmakeover.com, heroonamission.com, storybrandmastermind.com, onlinesalesscript.com, app.businessmadesimple.com, app.heroonamission.com, app.onlinesalesscript.com, storybrandmarketingreport.com, community.businessmadesimple.com, app.storybrandmastermind.com (collectively, the “Site”), and all related services (collectively, our “Services”). For purposes of the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and the UK General Data Protection Regulation (the “UK GDPR”), as applicable, DM Words is the data controller responsible for your Personal Data (as defined below). This Privacy Policy applies to users (“user(s),” “you,” or “your”) located in the European Economic Area (the “EEA”), the United Kingdom (the “UK”), Gibraltar, and Canada, and describes how we collect, use, disclose, and protect your Personal Data or personal information, as applicable, in the course of conducting our business and providing our Services. The provisions of this Privacy Policy addressing the GDPR and UK GDPR apply to users located in the EEA, the UK, and Gibraltar, while the provisions specifically addressing Canadian privacy laws apply to users located in Canada.

Please read this Privacy Policy carefully.  This Privacy Policy describes how we process your Personal Data; it does not form a contract between you and DM Words. This Privacy Policy is incorporated into our Terms of Use. Any capitalized terms that are not defined in this Privacy Policy have the meaning given to them in our Terms of Use.  Your use of our Services and any Personal Data (as hereafter defined) you provide through the Services are subject to this Privacy Policy at all times. 

For clarity, this Privacy Policy is only applicable to our Site and Services, and not to any other website that you may be able to access therefrom, each of which may have different data collection and use practices. Please consult the policies of those websites to understand your data privacy rights on those websites.

If you have any questions about this Privacy Policy, please contact us at hello@storybrand.com or at the contact information below.

2. Information We Collect

When you use the Site, we process certain types of Information, as described below.

a. Personal Data

“Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”), as defined in Article 4(1) of the GDPR. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. Personal Data includes, but is not limited to: (i) information that identifies or can be used to identify an individual, such as names, signatures, addresses, telephone numbers, email addresses, online identifiers (including IP addresses), and other unique identifiers; and (ii) information that can be used to authenticate an individual, such as passwords or PINs, user identification and account access credentials, and similar data.

Personal Data that we collect on the Site includes, but is not limited to, first and last name, phone number, email address, IP address, and any other information you provide to us. 

When you access or use the Services, you may provide Personal Data to us, such as when you request to receive information or support, complete online forms and surveys, or communicate with us or our representatives, whether through standard mail, email, telephone, or live chat.

Under the GDPR and UK GDPR, online identifiers such as IP addresses and cookie identifiers constitute Personal Data. We process such identifiers for the same purposes as other Personal Data under this Privacy Policy. 

In accordance with the principle of data minimization under Article 5(1)(c) of the GDPR, we collect only Personal Data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. We also take reasonable steps to ensure that Personal Data is accurate and, where necessary, kept up to date, in accordance with the accuracy principle under Article 5(1)(d) of the GDPR.

b.Non-Personal Information

“Non-Personal Information” means information that has been fully anonymized or aggregated such that it can no longer be used, whether alone or in combination with other information, to identify a natural person. For example, we may collect aggregated information about the use of our Site, including but not limited to browser type, operating system, date/time stamps, and similar usage data, where such information does not identify you as a Data Subject.

Personal Data and Non-Personal Information are collectively referenced as “Information.”

Information we collect about you may be aggregated with other users’ Information. It may also be combined with associated Personal Data that you provide to us or that we receive from third parties. If we combine or associate information from other sources with Personal Data that we collect through the Site, we will treat the combined Information as Personal Data in accordance with this Privacy Policy.

c. Geolocation Information

You may choose to allow us to access your location by granting the Site access to your location when prompted or through your device’s location services settings. You may change these settings on your device, but this may impact your use of and access to the Services.

d. Third-Party Social Networking Service(s)

If you choose to access, visit, and/or use any third-party social networking service(s) that may be integrated with our Site, we may receive your Personal Data and other information about you and your computer, mobile, or other device that you have made available to those social networking services, including information about your contacts through those services. Your decision to use a social networking service in connection with our Site is voluntary. However, you should make sure you are comfortable with the information your third-party social networking services may make available by reviewing privacy policies of those providers and/or modifying your privacy settings directly with those networking sites/services.

3. Where/How We Collect Information

We collect Personal Data and Non-Personal Information about you from a number of sources, as described below.

a. From You

When you register to use our Services, complete online forms or surveys, request to receive information or support, initiate a transaction, or communicate with us or our representatives, whether through standard mail, email, or telephone, you may provide your Information to us.

b. From Third Parties

We may obtain Information, including Personal Data, from third parties and sources other than the Services, such as our service providers and data partners. If we combine or associate information from other sources with Personal Data that we collect through the Services, we will treat the combined information as Personal Data in accordance with this Privacy Policy.

Zoom integration. Where you authorize the Zoom integration, we may receive meeting links and meeting transcription data (with your consent).

c. Cookies and Other Technology

We also use “cookies” to enhance your use of our Services. A cookie is information either temporarily or permanently stored in a file on your computer. In accordance with applicable EU and UK ePrivacy laws (Directive 2002/58/EC as implemented in EU Member States, and the UK Privacy and Electronic Communications Regulations 2003), we obtain your prior consent before placing any non-essential cookies on your device.  Strictly necessary cookies, which are required for the operation of our Site, do not require consent.

You may withdraw your cookie consent at any time through https://storybrand.com/#manage_cookies. For more information on cookies and how our Services use cookies, please see our Cookie Policy.

4. Use of Information

We use Non-Personal Information collected by cookies, web beacons, and other Internet tracking technology to store your preferences, improve website navigation, make personalized features and other services available to you, to generate statistical information, monitor and analyze user traffic and usage patterns, monitor and prevent fraud, investigate complaints and potential violations of our policies, to improve the products, services, materials, and other content that we describe or make available through the Services, and otherwise help administer and improve the Services.

We may identify you from your Personal Data and merge or co-mingle Personal Data and Non-Personal Information. Except as otherwise stated, we may use Information we collect from you for the purposes set out below, on the legal bases described in Section 10(a) of this Privacy Policy, including, but not limited to:

• To fulfill or meet the reason you provided the Personal Data.  For example, if you share your name and contact information to ask a question about our Services, we will use that Personal Data to respond to your inquiry.

• To provide the Services to you, as further described in our Terms of Use.

• To establish and secure accounts to use the Services, check on your account status, and to validate your username, e-mail, password, and/or other login credentials.

• To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.

• To provide, support, personalize, and develop our Services, including without limitation, to conduct aggregate or research analysis and develop business intelligence that helps us to enhance, improve, evaluate, operate, protect, make informed decisions about, and report on the performance of our Services.

• To communicate information and promotional materials to you, where you have not expressed a preference otherwise, and to send you information and updates about the Services.

• To notify you of any changes to relevant agreements, policies, or other terms, and to enforce such terms.

• To work with our service providers, who perform certain business functions or services on our behalf and who are bound by contractual obligations consistent with this Privacy Policy.

• To prevent or investigate fraud, or for risk management purposes, and to help maintain the safety, security, and integrity of our Services, databases and other technology assets, and business.

• To comply with legal obligations, court orders, or in order to exercise any legal claim or to defend against any legal claim.

• To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by us about our users is among the assets transferred.

• As otherwise described to you when collecting your Personal Data.

The provision of your Personal Data (including your name and email address) is a contractual requirement necessary to access the Services. If you do not provide the required Personal Data, you will not be able to create an account or access the Services. 

In addition, we may use third-party e-mail providers to deliver communications to you.  This is an opt-in e-mail program.  If you no longer want to receive these e-mail communications, you may opt-out of receiving e-mail communications through the “unsubscribe” link or by contacting us at hello@storybrand.com.

We may, from time to time, invite you to participate in online surveys.  The information requested in these surveys may include, but is not limited to, your opinions, beliefs, insights, ideas, activities, experience, purchase history, and purchase intent regarding products, events, and Services.  The information collected by these surveys is used to research market trends, company growth, community needs, and similar matters.  Your input will help us to improve customer experience and shape development of our products and Services.

We do not intentionally collect or process special categories of Personal Data as defined in Article 9 of the GDPR (i.e., data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation). Please do not submit any such data to us through the Services.

We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, as described in Article 22 of the GDPR.

5. How We Share Information

We do not sell your Personal Data.  We may share Non-Personal Information, such as impressions and click data, with business partners and service providers. We may share traffic and transaction Information with them on an aggregated and anonymized basis.

We may share your Personal Data with the following parties:

• Corporate affiliates, including corporate parents, subsidiaries, other affiliated entities, and associated entities for the purposes described in this Privacy Policy, which are required to treat the information in accordance with this Privacy Policy.

• Service providers that help us administer and provide the Services (for example, a web hosting company whose services we use to host our platform). These third-party service providers have access to your Personal Data only for the purpose of performing services on our behalf and act as data processors under Article 28 of the GDPR.  We have entered into data processing agreements with these service providers and require them to comply with the GDPR, the UK GDPR, and all other applicable data protection laws and regulations and to use the Information only for the purposes for which it was disclosed. A list of these third parties is available upon request.

• Authorized third parties, who are parties directly authorized by you to receive the applicable Information, such as when you authorize a third-party application provider to access your account. The use of your Information by an authorized third party is subject to the third party’s privacy policy, and we are not responsible for any misuse by them of your Information.

• Third parties in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings), in which case we will require the recipient to use such information in accordance with this Privacy Policy.

• As we believe necessary: (i) under applicable law; (ii) to enforce applicable terms and conditions; (iii) to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others; (iv) to detect, prevent, or otherwise address fraud, security, or technical issues; (v) to respond to claims that contact information (e.g., name, e-mail address, etc.) of a third party has been posted or transmitted without their consent or as a form of harassment; and (vi) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.

• Pursuant to your express consent.

6. Information Security

In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing your Personal Data, including, for example:

• Hosting our applications on reputable cloud infrastructure providers, including DigitalOcean and Amazon Web Services (AWS);

• Restricting server access through secure authentication mechanisms such as SSH key-based access and multi-factor authentication (MFA);

• Maintaining logical access controls to limit access to Personal Data to authorized personnel only;

• Using encryption in transit (e.g., HTTPS/TLS) to protect data transmitted between users and our systems;

• Leveraging managed database services and infrastructure-level security controls provided by our hosting providers;

• Applying regular software updates and security patches to our application stack and dependencies;

• Monitoring systems for potential vulnerabilities and unauthorized access; and

• Following internal policies and practices designed to safeguard Personal Data.

It is common knowledge that transmission of information via the Internet is not wholly secure, and we cannot guarantee or warrant the security of your Personal Data, or any other information, transmitted to or through our Site or Services or otherwise provided to us.  Any transmission of Personal Data, or other information, is at your own risk. By using our Site and/or Services, you acknowledge and accept these risks.

It is your responsibility to safeguard any passwords, ID numbers, or other special access features associated with your use of the Services.  If you have any questions about security on our Services, or if you become aware of any unauthorized use of an account, loss of your account credentials, or suspect a security breach, notify us immediately via email at hello@storybrand.com. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR 

7. Information Retention

In accordance with the storage limitation principle under Article 5(1)(e) of the GDPR, we retain the Personal Data we receive as described in this Privacy Policy for no longer than is necessary for the purposes for which it was collected.  Specifically, we retain your Personal Data for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected, provide our products and services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.  If you cancel or terminate your account, we may retain your Personal Data for a reasonable period thereafter to facilitate your return to the Services without friction, unless you request deletion of your data. Upon receipt of a deletion request, we will securely delete or anonymize your Personal Data without undue delay, subject to any overriding legal obligation to retain such data.

8. Links to Third-Party Sites

The Site may contain links to other sites that are not operated by us.  If you click on a link to another site, you will be directed to that third party’s site. Such links do not constitute an endorsement by us of those other websites, their content or services, or the persons or entities associated with those websites.  This Privacy Policy does not apply to third-party websites.  We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies and terms of all third-party websites or services that you may visit.

9. Children’s Privacy

The Services are not intended for use by children. Under Article 8 of the GDPR, where we rely on consent as the legal basis for processing, we will not knowingly process Personal Data of any person under the age of sixteen (16) without verifiable parental or guardian consent. Please note that individual EEA Member States may set a lower age threshold (but no lower than thirteen (13)). Under the UK GDPR, the applicable age of consent is thirteen (13). In the event that we receive actual knowledge that we have collected Personal Data from a child without the requisite parental or guardian consent, we will delete that data from our systems without undue delay. We reserve the right to request proof of age at any stage so that we can verify that children are not using the Service(s).

10. Your Rights Under the GDPR and UK GDPR

a, Legal Bases for Processing Your Personal Data

We process your Personal Data for the purposes set forth in Section 4, above, on one or more of the following legal bases under Article 6(1) of the GDPR:

• Legitimate Interests (Article 6(1)(f)). We may process your Personal Data where it is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your rights and freedoms.  For example, we process your Personal Data to administer the Services, help diagnose problems with our Services and provide support, to communicate information to you, to improve and customize our Services, to work with our service providers, to prevent or investigate fraud, and for other purposes identified to you and as requested by you.  Where we rely on this legal basis, we have conducted a balancing test to ensure that our interests do not override your fundamental rights.

• Performance of a Contract (Article 6(1)(b)). We process your Personal Data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.  For example, if you have agreed to our Terms of Use and created an account, we use your Personal Data to establish your account, validate your account credentials, respond to your requests, provide you with the products or services you have requested, and to notify you of any changes to relevant agreements or policies.

• Consent (Article 6(1)(a)). Where we have obtained your explicit consent, we may process your Personal Data to send you marketing communications, share your information with our corporate parents, subsidiaries, and affiliated entities for the purposes described in this Privacy Policy, and to otherwise process your Personal Data as described throughout this Privacy Policy and as consented to by you.  You have the right to withdraw your consent at any time pursuant to Article 7(3) of the GDPR, and such withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.

• Legal Obligation (Article 6(1)(c)). We may process your Personal Data where it is necessary for compliance with a legal obligation to which we are subject under EU or Member State law, or UK law.

b. Your Rights as a Data Subject

As a Data Subject located in the EEA, the UK, or Gibraltar, you have the following rights under the GDPR and UK GDPR with regard to your Personal Data.  We will respond to any request without undue delay and in any event within one (1) month of receipt of the request, in accordance with Article 12(3) of the GDPR.

• Right of Access (Article 15). You have the right to obtain confirmation as to whether your Personal Data is being processed, and, where that is the case, access to the Personal Data together with information about the purposes of the processing, the categories of data concerned, the recipients or categories of recipients, and the envisaged period of storage.  You may request access by contacting us using the details provided below.  We may ask for proof of identity before fulfilling your request. The first copy of your Personal Data will be provided free of charge; additional copies may be subject to a reasonable fee.

• Right to Rectification (Article 16). You have the right to obtain the rectification of inaccurate Personal Data and to have incomplete Personal Data completed. You can update your account information by contacting us at hello@storybrand.com.

• Right to Erasure / Right to Be Forgotten (Article 17). You have the right to request the erasure of your Personal Data where, among other grounds, the data is no longer necessary for the purposes for which it was collected, you withdraw consent on which the processing is based, or you exercise your right to object and there are no overriding legitimate grounds for the processing.  Please note that if you request erasure of your account, we shall also delete any data that has been submitted to us through our Services, subject to any overriding legal obligation to retain such data.

• Right to Object (Article 21). You have the right to object, on grounds relating to your particular situation, to processing of your Personal Data based on legitimate interests under Article 6(1)(f). Where Personal Data is processed for direct marketing purposes, you have the right to object at any time, and we shall cease processing your Personal Data for such purposes without exception.  If you do not wish to have your Personal Data shared with third parties, contact our Data Protection Officer as described at the end of this section. If you do not wish to receive future commercial messages from us, simply follow the unsubscribe instructions contained within the message you receive. (Note that you may continue to receive certain transactional or relationship communications from us.)

• Right to Restriction of Processing (Article 18). You have the right to obtain the restriction of processing where you contest the accuracy of the Personal Data, the processing is unlawful, we no longer need the Personal Data but you require it for the establishment, exercise, or defense of legal claims, or you have objected to processing pending verification of whether our legitimate grounds override yours.

• Right to Data Portability (Article 20). You have the right to receive the Personal Data you have provided to us in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance, where the processing is based on consent or a contract and is carried out by automated means.

• Right to Withdraw Consent (Article 7(3)). Where we rely on consent as the legal basis for processing your Personal Data, you have the right to withdraw your consent at any time.  Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

• Right to Lodge a Complaint (Article 77). You have the right to lodge a complaint with a supervisory authority if you consider that our processing of your Personal Data infringes the GDPR or UK GDPR. A list of EU National Data Protection Authorities can be found here: http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.  For UK residents, you may contact the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/.

c. International Data Transfers

As DM Words is based in the United States, your Personal Data will be transferred to, processed, and stored in the United States.  The United States has not received an adequacy decision from the European Commission under Article 45 of the GDPR, nor from the UK Secretary of State under the UK GDPR. 

When you access our Services and provide your Personal Data to us, that data is transferred directly to the United States because our servers and infrastructure are located there.  This transfer is necessary for the performance of the contract between you and DM Words (i.e., our Terms of Use), and we rely on Article 49(1)(b) of the GDPR as the legal basis for this transfer.  Without this transfer, we would be unable to provide you with access to the Services, maintain your account, or fulfill our contractual obligations to you. 

We take appropriate steps to ensure that your Personal Data is treated securely and in accordance with this Privacy Policy regardless of where it is processed. Where we receive requests for information from law enforcement or regulators, we carefully validate these requests before disclosing any Personal Data.

d. EU and UK Representative

DM Words has appointed Data Protection Representative Limited (trading as DataRep) as its Data Protection Representative in the EU/EEA under the GDPR and in the United Kingdom under the UK GDPR. Data subjects may contact DataRep regarding data subject requests by email at datarequest@datarep.com, online at www.datarep.com/data-request, by post in the EU at DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland, or by post in the UK at DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom. DM Words has also appointed DataRep as its Legal Representative under the Digital Services Act (DSA) in the EU/EEA, contactable at digitalrequest@datarep.com.

e. Data Protection Officer

If you have an inquiry regarding your Personal Data pursuant to the rights listed in this Section 10, please send your message to the following:

DM Words Attention: Data Protection Officer E-mail: hello@storybrand.com

11. Canadian Privacy

a. Scope and Relationship to This Privacy Policy

This Canadian Privacy section supplements this Privacy Policy for individuals in Canada and for Personal Information collected, used, disclosed, retained, or otherwise processed in connection with our Services. For purposes of this Addendum, “Personal Information” means information about an identifiable individual and includes the Personal Data described in this Privacy Policy. It addresses the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and, where applicable, Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25.  Sections 2 through 12 continue to apply; this Addendum provides Canadian-specific information and controls and governs to the extent of any inconsistency for Canadian Personal Information.  Where a substantially similar provincial privacy law applies, this Addendum should be read with that law.

b. Accountability and Privacy Contact

DM Words is accountable for Personal Information under its control, including Personal Information handled by a service provider on DM Words’ behalf.  We maintain reasonable policies, procedures, and contractual controls for privacy, security, retention, and handling of requests.  For Canadian privacy inquiries and requests, contact DM Words at hello@storybrand.com, Attention: Emily Pastina, VP of Operations, emily@storybrand.com; other contact details appear in Section 12. 

c. Information We Collect and the Sources of Collection

For Canadian users, Sections 2 and 3 describe the categories and sources of Information we collect, including names, telephone numbers, e-mail addresses, IP addresses, account credentials, information submitted through forms, surveys, support requests and communications, geolocation where enabled, information received through third-party social networking services, and cookie and usage data such as browser and operating system information, timestamps, URLs, browsing activity, and cookie identifiers. Where you authorize an integration, we may receive meeting links and meeting transcription data from Zoom with your consent.  We may collect Information directly from you, through your use of the Services, or from service providers, data partners, and authorized third parties.

d. Purposes of Collection, Use, and Disclosure

We collect, use, and disclose Canadian Personal Information only for purposes that a reasonable person would consider appropriate in the circumstances and that we identify at or before collection, including to: provide and administer the Services; create and secure accounts and validate credentials; respond to inquiries and provide support; enable authorized Zoom features; communicate with you; personalize, improve, analyze, and develop the Services; administer cookies and other tracking technologies as described in our Cookie Policy; prevent fraud and protect the safety, security, and integrity of the Services; comply with law and manage disputes; evaluate corporate transactions; and carry out other purposes described when the Information is collected or with your consent.  We may use aggregated or anonymized Information as described in Section 4.

e. Meaningful Consent

We seek meaningful consent by explaining, in plain language, what Personal Information is collected, why it is collected, how it will be used or disclosed, and the choices available to you.  Consent may be express or implied where permitted by applicable law and reasonable in the circumstances; we will seek express consent where required, where Information is sensitive, or where the purpose would not reasonably be expected. We will not condition access to a Service on consent to an unrelated purpose unless permitted by law.  Marketing communications are part of an opt-in program.  For cookies and other tracking technologies, the Cookie Policy describes the available settings and opt-out process.

f. Disclosures and Service Providers

Section 5 describes the recipients and circumstances for disclosure.  For Canadian users, these may include corporate affiliates; service providers that host or administer the Services or support e-mail, Zoom, analytics, security, or other functions; third parties you authorize; parties involved in a corporate transaction; and courts, regulators, law enforcement, or other public authorities where permitted or required.  We do not sell your Personal Data as stated in Section 5.  Service providers receive access only as needed to perform services for us and are required to protect the Information and use it only for authorized purposes.  The Cookie Policy separately describes disclosures to digital analytics and advertising providers and available preference-based advertising opt-outs.

g. Access, Correction, and Withdrawal of Consent

You may request access to Personal Information under DM Words’ control and information about its use and disclosure, including the purposes for which it was collected, the sources from which it was obtained, and the individuals or organizations to which it has been disclosed.  You may also request correction of inaccurate or incomplete Personal Information.  Send a request to hello@storybrand.com.  We may ask for information reasonably necessary to verify your identity and locate the requested Information.  We generally respond within thirty (30) days, subject to extensions and exceptions permitted by applicable law; if we deny a request, we will explain the basis for the denial to the extent permitted.  We will correct or annotate Information where appropriate and, where reasonable, notify relevant recipients of a correction.

You may withdraw consent on reasonable notice by contacting us or, for marketing communications, using the unsubscribe link.  Withdrawal does not affect processing already carried out with consent and may affect our ability to provide a Service or feature.  We may continue to collect, use, disclose, or retain Information where permitted or required by applicable law, including to perform a contract, protect the Services, or address security, dispute-resolution, or other legal needs.

h. Retention and Safeguards

Sections 6 and 7 describe our safeguards and retention approach.  For Canadian Personal Information, we retain Information for as long as reasonably necessary to fulfill the identified purposes, provide the Services, resolve disputes, establish or defend legal claims, conduct audits, enforce agreements, and comply with law. When Information is no longer necessary, we will securely delete, destroy, or anonymize it, subject to applicable retention obligations.

Our disclosed safeguards include hosting applications on DigitalOcean and Amazon Web Services, restricting server access through SSH key-based authentication and multi-factor authentication, logical access controls, HTTPS/TLS encryption in transit, managed database and infrastructure security controls, regular software updates and patches, vulnerability and access monitoring, and internal safeguarding practices.  Safeguards may vary with the sensitivity and context of the Information.

i. Security Incidents and Breach Response

If we become aware of a security incident involving Canadian Personal Information, we will assess, contain, investigate, and remediate it.  Where a breach of security safeguards involving Personal Information under our control creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and will notify other organizations or public institutions where required to reduce the risk of harm.  We will maintain records of breaches for at least twenty-four (24) months, or longer where required by applicable law.  If you suspect unauthorized use of an account or a breach, notify us immediately at hello@storybrand.com. 

j. Processing in the United States

DM Words is based in the United States, and our servers and infrastructure are located there.  Canadian Personal Information may therefore be transferred to, stored, processed, or accessed in the United States by DM Words and by service providers acting on its behalf.  The Information may be subject to the laws of the United States and may be accessible to courts, law enforcement, or regulators there.  DM Words remains accountable for Personal Information under its control and will use contractual, organizational, and technical measures appropriate to the circumstances and carefully validate requests for disclosure. 

k. Complaints

If you have a concern about our handling of your Personal Information, please contact us first at hello@storybrand.com or using the contact information in Section 12.  We will investigate and respond to complaints in a reasonable manner. If your concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/ or the privacy regulator with jurisdiction in your province. If you are in Quebec, you may contact the Commission d’accès à l’information du Québec at https://www.cai.gouv.qc.ca/.

12. Changes in the Privacy Policy

We reserve the right to modify and update this Privacy Policy at any time by posting an amended version of the statement on our Site.  Please refer to this Privacy Policy regularly.  If at any time we decide to use Personal Data in a manner materially different from that stated at the time it was collected, we will notify you via e-mail or prominent notice on our Site prior to the change becoming effective.  Where the GDPR or UK GDPR requires consent for such changes, we will obtain your consent before implementing any material change to the processing of your Personal Data.

13. How to Contact Us

If you have any questions or comments about our Privacy Policy, please contact us at:

By e-mail: hello@storybrand.com 

By telephone: (615) 915-1541

By regular mail: DM Words Attn: Website Inquiry 1009 51st Ave N, Nashville, TN 37209

CLOSE VIDEO