Privacy Policy

Introduction

The Conduct Management System, also known as “TCMS,” is a product of Smith Enterprises and Endeavors Company, Inc. This Privacy Policy explains how TCMS collects, uses, stores, protects, and discloses information when users access or use our website, mobile application, software platform, communications, and related services.

By accessing or using TCMS, you acknowledge the practices described in this Privacy Policy.

1. About TCMS

TCMS provides digital tools for Applied Behavior Analysis professionals, technicians, organizations, parents, caregivers, educators, and other authorized stakeholders to collect, manage, track, and analyze behavioral information.

TCMS is intended to support professional workflows. It does not replace professional medical, psychological, educational, behavioral, or legal advice, diagnosis, or treatment.

2. Information We Collect

Depending on how you use TCMS, we may collect the following categories of information.

Account and Profile Information

We may collect:

  • Full name
  • Email address
  • Mobile phone number
  • Username
  • Password or authentication credentials
  • Organization or employer information
  • Professional role or account type
  • Billing and subscription information
  • Account preferences
  • Support and communication records

Passwords are stored using security safeguards and are not maintained in plain-text form.

Client, Student, Patient, or Behavioral Data

Authorized users may enter information relating to their clients, students, patients, or other individuals receiving services. This information may include:

  • Behavioral observations
  • Session records
  • Treatment-related information
  • Progress information
  • Goals and intervention data
  • Educational information
  • Assessments
  • Notes
  • Reports
  • Attachments
  • Other information entered by authorized account holders

Depending on the context, some of this information may constitute Protected Health Information under HIPAA, education records under FERPA, or other sensitive or regulated information.

The organization or professional entering this information is responsible for confirming that they have the necessary authorization, consent, and lawful basis to collect and process it through TCMS.

Billing and Transaction Information

When users purchase a subscription or paid service, we or our payment service providers may collect:

  • Billing name and address
  • Payment method details
  • Transaction history
  • Subscription plan
  • Payment status
  • Invoice information

TCMS may use third-party payment processors. TCMS generally does not directly store complete payment-card numbers or card security codes when payments are processed by an authorized payment provider.

Device and Usage Information

We may automatically collect certain technical and usage information, including:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • App version
  • Login date and time
  • Pages or features accessed
  • Session duration
  • Error and diagnostic information
  • Security and audit logs
  • Approximate location derived from IP address
  • Cookie and similar technology information

Communications and Support Information

When you contact us, we may collect:

  • Your name and contact details
  • The content of your message
  • Support-ticket information
  • Call or email records
  • Technical information needed to investigate your request

Mobile Phone and SMS Information

When you register, sign in, verify your phone number, reset a password, or perform another account-security action, TCMS may collect your mobile phone number.

TCMS uses mobile phone information to send one-time passcodes and transactional security messages requested by the user. The TCMS Account Verification SMS Program is used for authentication and account security and is not used for marketing or promotional messages.

3. How We Use Information

TCMS may use collected information to:

  • Create and manage user accounts
  • Authenticate users and verify phone numbers
  • Send one-time passcodes and security notifications
  • Provide access to the TCMS platform
  • Process subscriptions and payments
  • Store and synchronize authorized behavioral data
  • Generate reports and analytics requested by users
  • Provide customer and technical support
  • Communicate about accounts, services, security, and important operational updates
  • Improve the functionality, accessibility, reliability, and usability of TCMS
  • Detect, investigate, and prevent unauthorized access, fraud, misuse, and security incidents
  • Maintain records, audit logs, and compliance documentation
  • Enforce our Terms and Conditions
  • Comply with legal and regulatory obligations
  • Protect the rights, safety, security, and property of TCMS, its users, and others

TCMS does not use SMS verification consent as consent to send promotional or marketing communications.

4. SMS Messaging and Consent

Users may receive SMS messages from the TCMS Account Verification Program after entering their mobile phone number and actively requesting a verification code.

Messages may be sent when users:

  • Register for an account
  • Sign in to an account
  • Verify a mobile phone number
  • Reset a password
  • Confirm a sensitive account action
  • Complete another authentication or security process

Message frequency varies based on the number of verification requests initiated by the user. Message and data rates may apply according to the user’s mobile carrier and service plan.

Users may reply STOP to opt out and HELP for assistance.

Opting out may prevent the user from receiving verification codes and may limit access to features that require SMS authentication.

TCMS records or may record evidence associated with SMS consent, including the phone number submitted, date and time of the request, source of consent, version of the disclosure shown, and related technical records.

5. Mobile Information and Marketing Restrictions

TCMS does not sell or rent mobile phone information.

Mobile information will not be shared with third parties or affiliates for their own marketing or promotional purposes.

SMS opt-in information and consent will not be shared with third parties or affiliates for marketing or promotional purposes.

Text-message originator opt-in data and consent will not be sold, rented, or disclosed to third parties for their own marketing purposes.

TCMS may provide mobile information to service providers that support the operation and delivery of the TCMS messaging program, including telecommunications providers, messaging platforms, hosting providers, fraud-prevention providers, and technical infrastructure providers. Such information is provided only as reasonably necessary to deliver or support the requested messages and services.

The above mobile-information restrictions do not prevent disclosure when required by law, necessary to prevent fraud or security threats, or required to protect the rights and safety of TCMS, its users, or others.

6. How We Share Information

TCMS does not sell or rent personal information or client behavioral data.

We may share information in the following limited circumstances.

Service Providers and Subprocessors

We may work with service providers that support:

  • Cloud hosting
  • Data storage
  • SMS delivery
  • Email delivery
  • Payment processing
  • Analytics
  • Security monitoring
  • Customer support
  • Software maintenance
  • Data backup
  • Identity and authentication services

These providers may access information only as reasonably necessary to perform services for TCMS and are expected to protect the information according to applicable contractual and legal obligations.

Authorized Users and Stakeholders

Information entered into TCMS may be shared with users who have been authorized by the relevant account holder or organization, such as:

  • Supervisors
  • Clinicians
  • Technicians
  • Parents
  • Guardians
  • Teachers
  • Administrators
  • Other authorized stakeholders

Access depends on the permissions, roles, invitations, and account settings configured by the account holder or organization.

Legal and Safety Requirements

We may disclose information when we reasonably believe disclosure is necessary to:

  • Comply with applicable law, regulation, subpoena, court order, or governmental request
  • Enforce our agreements
  • Investigate fraud, misuse, or security incidents
  • Protect the rights, property, safety, or security of TCMS, our users, or others
  • Respond to an emergency involving a threat of serious harm

Business Transactions

If TCMS or its operating company undergoes a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, information may be transferred as part of that transaction, subject to applicable confidentiality and privacy requirements.

7. HIPAA and FERPA Considerations

TCMS may be used by healthcare, behavioral, or educational professionals in contexts where HIPAA, FERPA, or similar laws apply.

The user or subscribing organization is responsible for:

  • Determining which laws apply to its activities
  • Obtaining required authorizations and consents
  • Assigning appropriate user access
  • Protecting account credentials
  • Configuring the platform appropriately
  • Ensuring that data entered into TCMS is collected and processed lawfully
  • Entering into any required agreements, including a Business Associate Agreement, where applicable

TCMS implements administrative, technical, and organizational safeguards intended to protect sensitive information. However, use of TCMS does not automatically make a user or organization compliant with HIPAA, FERPA, or any other law.

Where TCMS qualifies as a business associate and the parties agree that HIPAA applies, the applicable customer and TCMS may enter into a separate Business Associate Agreement.

8. Data Security

TCMS uses reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, misuse, destruction, or loss.

These safeguards may include:

  • Encryption in transit
  • Encryption at rest, where appropriate
  • Authentication controls
  • Role-based access
  • Access logging
  • Security monitoring
  • Backup procedures
  • Session controls
  • Vulnerability management
  • Restricted administrative access

No method of electronic transmission or storage is completely secure. Therefore, TCMS cannot guarantee absolute security.

Users must protect their credentials, avoid sharing passwords, use secure devices, and log out of shared or unattended systems.

9. Data Retention

We retain information for as long as reasonably necessary to:

  • Provide the TCMS services
  • Maintain active accounts
  • Fulfill contractual obligations
  • Comply with legal and regulatory requirements
  • Resolve disputes
  • Enforce agreements
  • Maintain security and audit records
  • Protect against fraud and misuse

Retention periods may depend on the type of information, account configuration, contractual requirements, organizational instructions, and applicable laws.

When information is no longer required, we may delete, de-identify, or securely archive it as permitted by law.

10. Data Deletion Requests

Users may request deletion of eligible account information by contacting TCMS support.

Some information may not be immediately deleted when:

  • It must be retained by law
  • It is part of a legal or security record
  • It is controlled by an organization or professional account
  • It is needed to resolve a dispute
  • It is maintained in a secure backup for a limited retention period

Where an individual’s information is managed by a healthcare provider, school, employer, clinician, or other organization, the individual may need to submit the request directly to that organization.

11. User Privacy Rights

Depending on applicable law and location, users may have the right to:

  • Request access to personal information
  • Request correction of inaccurate information
  • Request deletion of eligible information
  • Request restriction of certain processing
  • Object to certain uses
  • Request a copy of eligible information
  • Withdraw consent where processing relies on consent

These rights may be subject to legal limitations and identity-verification requirements.

To submit a request, contact us using the details below.

12. Cookies and Similar Technologies

The TCMS website may use cookies, local storage, pixels, and similar technologies to:

  • Maintain login sessions
  • Remember user preferences
  • Protect account security
  • Measure website functionality
  • Diagnose errors
  • Analyze performance and usage

Users may manage cookies through their browser settings. Disabling essential cookies may affect website functionality.

13. Children’s Privacy

TCMS is intended for use by authorized adults, professionals, organizations, and other legally permitted users.

TCMS is not intended to allow children to independently create general consumer accounts unless specifically authorized and implemented in compliance with applicable law.

Information about minors may be entered by an authorized professional, parent, guardian, school, healthcare organization, or other authorized account holder. The person or organization entering the information is responsible for obtaining any required parental consent, authorization, or lawful basis.

14. Third-Party Services and Links

TCMS may integrate with or link to third-party services. Those services operate under their own privacy policies and terms.

TCMS is not responsible for the privacy, security, content, or practices of third-party services that are not controlled by TCMS.

15. International Data Processing

Information may be processed or stored in jurisdictions other than the jurisdiction where the user resides.

Where required, TCMS will apply appropriate safeguards for international transfers. Users and organizations remain responsible for determining whether their use of TCMS complies with data-transfer requirements applicable to them.

16. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, legal obligations, security practices, or operational requirements.

When material changes are made, we may provide notice through the website, application, email, account notification, or another reasonable method. The “Last Updated” date at the top of this policy will identify the latest revision.

Continued use of TCMS after an updated Privacy Policy becomes effective constitutes acknowledgment of the revised policy, to the extent permitted by law.

17. Contact Us

Questions, privacy requests, or concerns may be directed to:

The Conduct Management System—TCMS
A product of Smith Enterprises and Endeavors Company, Inc.


Address: 120 Einstein Loop North Building 28B, Suite 24D
Bronx, NY 10475


Phone: (917) 231-1182

Email: info@tcms.systems, support@tcms.systems.

Scroll to Top