Privacy Policy
Last updated: August 7, 2026
This policy explains what Biz Systems LLC, operating as Sam Eye Am, collects, why it is used, which providers help process it, how AI-assisted work is handled, and the choices and rights available to you.
1. Who is responsible
Biz Systems LLC, operating as Sam Eye Am (“Sam Eye Am”, “we”, “us” or “our”), operates sameyeam.info and provides services internationally. For personal information we decide how and why to use, Biz Systems LLC is the controller or responsible organisation.
Biz Systems LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
[email protected]
For some client projects, we process information only on the client’s documented instructions. In that situation, the client is normally the controller or organisation and we act as its processor, service provider or data intermediary under the applicable agreement.
2. Scope
This policy covers visitors to this website, people who contact us, book a call, submit a form, join a course or mailing list, buy a product or service, participate in a recorded meeting, or provide material for a project. A client agreement, project privacy notice or platform notice may add more specific terms.
Third-party websites and platforms have their own privacy practices. This policy describes our use of those services, but it does not control what an independent platform does for its own purposes.
3. Information we collect
3.1 Information you provide
- Identity and contact information: name, email address, telephone number, location and billing address where needed.
- Business information: company, role, website, social profile, goals, challenges, budget, project requirements and questionnaire answers.
- Account and transaction information: course or customer account details, purchases, invoices, payment status and related records. Payment card data is entered with the payment provider and is not stored by us.
- Communications: emails, messages, meeting notes, support history, recordings and transcripts when a meeting is recorded.
- Project material: documents, images, video, audio, brand assets, content, customer or prospect information, access details and other material you choose to provide for agreed work.
- Feedback and publicity material: testimonials, case-study information, results, photos, voice or video where you have permitted that use.
3.2 Information collected automatically
- Technical and security data: IP address and request data, browser, device, operating system, timestamps, pages requested, referrer and security events.
- Consent and usage data: your privacy choice and, only after consent where required, page views, interactions, approximate location, campaign information, heatmaps or session analytics.
- Application attribution record: when you voluntarily submit the Start form, we keep a separate local measurement record containing the landing page or path, referrer domain, campaign parameters if present, broad source category and timestamp. This local record does not contain your name, email address, email hash, CRM contact ID or advertising click ID. Your application itself is processed separately through our customer-management and notification systems.
3.3 Information from other sources
We may receive payment confirmation from Stripe, booking or form details from LeadConnector or CourseCreator360, account and message information from a platform you use to contact us, and information from a client or collaborator who is authorised to provide it.
4. Required, optional and sensitive information
Contact, billing and project information may be required to answer an enquiry, enter a contract, take payment or deliver work. If required information is not provided, we may not be able to proceed. Other fields are optional.
Please do not send health, biometric, government-identifier, financial-account, children’s or other sensitive information unless it is necessary for agreed work and we have confirmed an appropriate way to handle it. If sensitive information is genuinely required, we use an additional lawful condition or permission where applicable.
5. Purposes and legal bases
| Purpose | Information | Basis where GDPR or similar law applies |
|---|---|---|
| Answer enquiries, assess fit, prepare proposals and book calls | Contact, business, form and booking data | Steps requested before a contract; legitimate interests in responding and operating the business |
| Provide services, courses, products, support and accounts | Contact, account, communication and project data | Contract; legitimate interests; legal obligation where relevant |
| Process payments and keep tax, accounting and transaction records | Billing, transaction and payment-status data | Contract and legal obligation |
| Record or transcribe a meeting after notice | Voice, video, transcript and meeting data | Consent where required; otherwise contract or legitimate interests in accurate records and delivery, after considering participant rights |
| Review a recording or transcript, including with AI-assisted tools, to write notes and follow-ups, check quality, train ourselves and improve how we work, and understand patterns across many conversations, including publishing aggregated or anonymised findings about our own work | Voice, video, transcript and meeting data | Consent where required for the recording itself; legitimate interests in service quality and improvement, after considering participant rights |
| Secure the website, prevent abuse and diagnose failures | Technical, request and security data | Legitimate interests and legal obligation where applicable |
| Measure and improve the website and understand which pages lead to voluntary applications | Consent choice, optional analytics data and the privacy-minimized application attribution record described in Section 3.2 | Consent for optional analytics; legitimate interests for privacy-preserving operational measurement, security and performance data where permitted |
| Send service messages and permitted marketing | Contact, account, purchase and engagement data | Contract, consent, or legitimate interests where direct marketing is legally permitted |
| Publish a testimonial, result, image, clip or case study | Approved identity, business, media and result data | Consent or a separate written permission or licence |
| Establish, exercise or defend legal claims and comply with authorities | Relevant records | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we consider the purpose, necessity and effect on the person. You may object as described below. Consent can be withdrawn at any time without affecting earlier lawful processing.
6. AI-assisted work
We use AI-assisted tools for research, organisation, analysis, transcription, drafting, coding, quality checks and parts of service delivery. This includes reviewing meeting recordings and transcripts as described in Section 7, and drafting and sending some of our email as described in Section 13. Depending on the task and project restrictions, selected tools may be provided by Anthropic, OpenAI, Google or a specialist transcription or production provider.
- We use the minimum information reasonably needed for the task and remove or generalise identifying details where practical.
- Human review is applied before an AI output is relied on for client delivery or a meaningful business decision.
- We do not sell client information or use private client material to train a public AI model of our own.
- Where provider controls, account settings or contracts are available, we use settings intended to prevent submitted business data from being used to train general public models.
- Confidential material, approved providers and additional restrictions are governed by the client agreement and written permissions for that project.
We do not make decisions about a person that produce legal or similarly significant effects solely through automated processing without meaningful human involvement. If that changes for a specific service, we will provide the additional information and choices required by law.
7. Calls, recordings and transcripts
A meeting may be recorded or transcribed when notice is provided in the booking page, the invitation, the meeting tool or the conversation itself. Recording may support delivery, accurate notes, follow-up, quality review and dispute records. You can ask questions or object before recording begins, and you can ask us at the start of any call not to record it. If recording is important to an agreed service, we will explain the consequence and consider a practical alternative.
7.1 AI-assisted review of recordings
We use AI-assisted tools to transcribe recordings and to help us review them. That review is used to produce notes, summaries and follow-ups, to check and improve the quality of our own work, and to understand patterns across many conversations, in aggregated or anonymised form that is not intended to identify any participant. We use this review internally. Where we publish what we have learned, we publish only aggregated or anonymised findings, as described in 7.2. The providers we use for it are covered by Section 6, and we use the account settings and contract terms available to us to stop this material being used to train general public AI models.
7.2 What we do not do with a recording
A recording, transcript or excerpt is not made public merely because the meeting was recorded. Public use of a name, image, voice, quote or identifiable excerpt requires separate permission or another clear written licence. Where we describe what we have learned from our work in general terms, we use aggregated or anonymised material that is not intended to identify any participant. Confidential client material remains subject to the applicable agreement.
8. Testimonials, case studies and photographs of people
8.1 Client testimonials and case studies. We publish approved feedback, results or media only where the person has given a clear, active yes for it. Accepting our terms, staying silent or carrying on with the work is not a yes. The approved scope may include a name, business, role, general location, photo, logo, quote or result, and a narrower permission is possible, including a result with the identifying details removed. Where a client has signed an agreement, that agreement sets the scope. You can withdraw at any time by writing to [email protected]. We stop new use within seven days and remove the material from the channels we control. Search caches, archives and copies made by others may remain outside our control. Withdrawal does not affect use that was lawful before it. Section 13 of our Terms and Conditions sets out the same permission in full.
8.2 Photographs and video from our own photography work. Sam Eye Am has worked as a photographer and filmmaker, and some images on this site come from that work. Where a person is recognisable and the image is used to promote a product or service, we use it only with that person’s permission, or we remove or crop the person so they are not identifiable. We do not treat a client’s permission as permission from anyone else who appears in the same photograph.
8.3 Asking us to take an image down. If you appear in a photograph or video on this website or on our social channels and you want it removed, write to [email protected] with a link or a description. We will remove it from the channels we control without asking you to explain why, and we aim to do it within seven days. Copies made by other people, search caches and archives can remain outside our control.
9. Providers and recipients
We share information only as reasonably needed for a purpose in this policy, an agreement, a legal requirement or a business reorganisation with appropriate safeguards. Principal provider categories currently include:
| Provider or category | Purpose and typical information |
|---|---|
| SiteGround and WordPress | Website hosting and content management; request, security, account and submitted website data |
| Cloudflare | DNS, content delivery, security, email-address protection and privacy-preserving performance measurement; request and performance data |
| LeadConnector / GoHighLevel and CourseCreator360 | Booking, forms, course access, customer management, email and support; contact, booking, account and engagement data |
| Stripe | Checkout, payment processing, fraud checks, receipts and payment status; billing and payment data |
| Business email, files, calendar and optional Google Analytics after consent; communication, account, file and analytics data | |
| PostHog | Optional analytics, heatmaps and session analytics after consent; usage and device data, with form inputs masked in our configuration |
| Automattic / Jetpack | Website services and optional site statistics after consent; site, request and usage data |
| Meeting, transcription and production providers, currently including Google Meet, Zoom and Fathom | Calls, scheduling, recording, transcription and production when used; contact, meeting, audio, video and transcript data |
| Selected AI providers, currently including Anthropic and Google, reached directly or through a model-routing provider | Task-specific AI processing under Sections 6, 7 and 13; the minimum prompt, file, transcript or project context needed for the task |
| Professional advisers, contractors and authorities | Confidential delivery support, legal/accounting advice, claims, safety or legal compliance; only relevant information |
Providers and features can change. We will update this policy when a change materially affects the description of our processing.
10. Cookies, analytics and embedded services
The site stores a necessary sea_consent cookie for 180 days to remember whether optional analytics were accepted or declined. Google Analytics, PostHog and Jetpack Stats are held until Accept is chosen. Advertising storage remains denied because no advertising pixel is currently enabled.
| Technology | Purpose | When it operates |
|---|---|---|
| sea_consent | Remember the privacy choice | Necessary; 180 days |
| Cloudflare security and RUM beacon | Protect and deliver the site and measure page performance. Cloudflare states that its RUM beacon does not use browser storage and discards the source IP from RUM processing. | Operational; may run without optional analytics consent |
| Google Analytics | Traffic and usage measurement | Only after Accept |
| PostHog | Usage analytics, heatmaps and session analytics; configured to mask form inputs | Only after Accept |
| Jetpack Stats | Basic site statistics | Only after Accept |
| LeadConnector / CourseCreator360 embeds | Display a calendar, form or course function requested on that page | When the relevant booking, form or course feature is opened; necessary functional storage may be used by the provider |
| Stripe checkout | Payment and fraud prevention | When you open or use Stripe checkout |
You can accept or decline optional analytics with equal prominence in the banner. Use the Privacy choices link in the footer to change your choice, or clear the sea_consent cookie in your browser. Declining optional analytics does not block the main website. If you prefer not to open an embedded booking or form provider, contact [email protected].
11. International processing
We and our providers may process information in the United States, the European Economic Area, Singapore and other countries. Those countries may have different privacy laws.
Where a restricted transfer from the EEA, United Kingdom or Singapore requires safeguards, the applicable arrangement may use an adequacy decision, a valid Data Privacy Framework certification, approved standard contractual clauses, comparable contractual protection, or another permitted mechanism. Additional technical or organisational measures are used where appropriate. Contact us for information about the safeguard relevant to your information or an available copy, subject to lawful redactions.
12. Client-controlled data
When a client gives us personal information to process only for that client’s system or instructions, the client remains responsible for its own notices, lawful basis and instructions. We use the information to provide the agreed service, apply agreed confidentiality and provider restrictions, assist with rights or incidents as required by the agreement, and delete or return information as required by the agreement or law. A data-processing addendum is used where the relationship and applicable law require one.
13. Email and direct marketing
Service messages, receipts and project communications are sent as needed for an enquiry, account or contract. Marketing is sent with consent where consent is required. Where law permits business-to-business outreach based on legitimate interests, we use relevant business contact information, identify the sender and provide a simple opt-out. We keep a minimal suppression record after an opt-out so the choice is respected.
13.1 Email written and sent by our AI assistant
Some of our email is written and sent by an AI assistant we operate under the name Emma. Emma is an AI assistant operated by Biz Systems LLC on behalf of Sam Eye Am, and every message it sends says so. Emma is not a person and does not present itself as one. A reply to one of those emails reaches our normal inbox and may be read and answered by a person or with AI assistance. You can ask us to stop sending you these emails by replying, and we will honour that. If you would rather deal with a person, email [email protected].
You can unsubscribe with the link in a marketing email or contact us. We do not sell personal information, and we do not use personal telephone numbers for automated or bulk telemarketing in breach of applicable do-not-call rules.
14. Retention
| Record | Retention approach |
|---|---|
| Enquiries and proposals | While the opportunity is active and afterwards for follow-up, suppression, security or potential claims; records are deleted or minimised when those purposes no longer apply |
| Client, contract and project records | For the relationship and afterwards while needed for delivery records, support, rights, tax, accounting or legal claims; core records may normally be kept up to 7 years where those obligations apply |
| Accounting and transaction records | For the period required by applicable tax and accounting law, commonly 7 years and longer where a specific rule requires it |
| Recordings, transcripts and working files | While needed for the agreed purpose, quality review, records or a claim, then deleted or anonymised; a project agreement may set a shorter period. We review stored recordings periodically and delete or anonymise those no longer needed for these purposes. You can ask us to delete a recording or transcript of a call you took part in. We will delete it from our active systems unless we still need it for a legal claim, a legal obligation or an agreement you are party to, and routine backups are overwritten on their normal cycle |
| Optional analytics | According to the configured provider retention and only while useful for site measurement; identifiers and session data are reviewed for minimisation |
| Application attribution record | Only while useful for understanding which pages lead to voluntary applications. It is reviewed for minimisation and contains no name, email address, email hash, CRM contact ID or advertising click ID |
| Marketing and suppression records | Until opt-out or the purpose ends; a minimal suppression record may be retained to prevent future contact |
| Testimonials and published material | For the approved period or until the permission or licence ends, subject to lawful archives and records |
| Backups and security logs | For limited rolling cycles or while needed to investigate security, then overwritten or deleted |
We may keep a record longer when law, an active dispute, fraud prevention, safety or a legal hold requires it. Where possible, we delete, anonymise or minimise information when the purpose ends.
15. Security and incidents
We use proportionate technical and organisational measures such as encrypted connections, access controls, account authentication, provider security features, backups and data minimisation. No internet service can guarantee absolute security. Please use secure channels and do not send unnecessary credentials or sensitive information.
If an incident occurs, we investigate, contain and document it. We notify an authority, client or affected person when the applicable risk and legal threshold requires notification. Under GDPR, notification to the supervisory authority may be required within 72 hours after awareness; notice to affected people depends on the level of risk. Singapore notification rules apply where a breach is likely to cause significant harm or is of significant scale.
16. Rights under GDPR and similar laws
Where the GDPR, UK GDPR or a similar law applies, you may have the right to be informed, access information, correct it, delete it, restrict processing, receive portable information, object to processing based on legitimate interests or direct marketing, withdraw consent, and ask for human review of a qualifying automated decision.
Email [email protected] with the request. We may verify identity and ask for enough detail to locate the information. GDPR requests are normally answered within one month, with a permitted extension for complex or numerous requests. Rights have exceptions, including legal retention, another person’s rights and legal claims.
You may complain to the data protection authority where you live or work, or where the issue occurred. The European Data Protection Board lists EEA authorities. In the Netherlands, the authority is the Autoriteit Persoonsgegevens.
17. Singapore privacy rights
Where Singapore’s Personal Data Protection Act applies, we notify you of reasonable purposes for collection, use or disclosure and obtain or rely on consent or another permitted basis. You may withdraw consent with reasonable notice and ask for access to personal data in our possession or control, information about relevant use or disclosure, or correction of an error, subject to legal exceptions.
We stop retaining information when it is no longer needed for a legal or business purpose, and we use required protection for transfers outside Singapore. You may contact us first or raise a concern with Singapore’s Personal Data Protection Commission.
18. California and other regional rights
Privacy laws in California and other US states may provide rights to know, access, correct, delete or obtain a copy of personal information, and to opt out of certain sale, sharing, targeted advertising or profiling. These rights and thresholds vary. Where a law applies to us and your request, we will honour the applicable right and will not discriminate against you for using it.
We do not sell personal information. We do not currently enable an advertising pixel on this website. If those practices change, we will update this notice and provide any legally required opt-out method.
19. Children
The website and services are directed to businesses and adults, not children under 16. We do not knowingly collect a child’s personal information through this website. Contact us if you believe a child supplied information so we can investigate and take appropriate action.
20. Changes and contact
We update this policy when our services, providers or legal obligations materially change. The date at the top identifies the current version. For a material change affecting an existing service or permission, we will provide additional notice where appropriate.
Biz Systems LLC, operating as Sam Eye Am
30 N Gould St Ste N, Sheridan, WY 82801, United States
[email protected]