Effective date: September 2, 2026 Last updated: September 2, 2026
About this policy
Superunit, Inc. (“Superunit,” “we,” “us”) provides AI-powered verification services to businesses. Our Ava product contacts employers, payroll departments, references, and medical facilities by phone, email, and fax to confirm employment, income, references, DOT records, and related information on behalf of our clients.
This policy applies to superunit.com, our client portal, and the verification services we provide. It covers two different situations, and the difference matters:
1. Information we handle for our clients. Our clients are consumer reporting agencies (CRAs), background screening companies, mortgage lenders, tenant screening firms, insurance carriers, third-party administrators, and investigative firms. When a client asks us to run a verification, we process information about the person being verified under that client’s instructions. We are a service provider (or, under some laws, a processor) for this information. We do not decide what it gets used for, and we do not use it for our own purposes beyond what is described in Section 4.
Superunit is not a consumer reporting agency. We do not issue consumer reports, make eligibility decisions, or determine what a client does with a verification result. If you are the subject of a verification and want to know how your information is being used, or want to correct or dispute something, contact the company that ordered the report. That company’s privacy notice governs, and if a consumer report was involved, the Fair Credit Reporting Act (FCRA) gives you rights against that company. See Section 9.
2. Information we handle for ourselves. This includes visitors to our website, people who contact our sales team, users of our client portal, and job applicants. We are the controller of this information, and this policy describes what we do with it.
1. Information we collect
Website visitors and business contacts
- Name, business email, phone number, company, and job title, when you fill out a form, request a demo, or email us
- Message content and correspondence history
- Device and usage data: IP address, browser type, pages viewed, referring URL, and similar log data
- Cookie and analytics data (see Section 6)
Client portal users
- Account credentials and authentication data
- Order history, request records, and activity logs
- Support requests
Verification subjects (processed for clients)
Depending on the verification type and what the client submits, this may include:
- Name, current and former names, date of birth, and partial or full Social Security number
- Contact details and address history
- Employer name, job title, dates of employment, employment status, and reason for separation
- Income, pay rate, pay frequency, hours, and bonus or commission detail
- DOT-related records, including drug and alcohol testing history and safety performance history where a client orders a DOT verification
- Reference responses and professional history
- Signed authorizations, releases, and supporting documents such as pay stubs or W-2s
- For medical canvassing assignments: whether a named individual is or was a patient at a facility, treatment dates, and related claim information. This can include protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). See Section 8.
Verifier and employer contact information
To reach the right person, we build and maintain records about employers, payroll providers, third-party verifiers, HR departments, and medical facilities. These records include business contact details, phone trees and IVR paths, hours, required forms, and fees. This is business information, though it sometimes includes the name and direct line of an individual employee acting in their professional capacity.
Calls, recordings, and transcripts
Ava places and receives phone calls, sends and receives faxes, and exchanges email. Ava identifies itself as an automated assistant calling on behalf of the requesting company. We record calls and generate transcripts in accordance with applicable federal and state law, including providing recording disclosure and obtaining consent where the law requires it. Call audio, transcripts, fax images, and email threads are retained as the record of the verification.
2. Where information comes from
- Directly from you
- From our clients, who submit verification requests along with the subject’s information and authorization
- From employers, payroll providers, third-party verification services, references, and medical facilities we contact
- From public and commercially available sources used to locate the correct employer or facility
- From cookies and analytics on our website
3. How we use information
For our own purposes:
- Operating, securing, and supporting our services and the client portal
- Responding to inquiries and sending service and account communications
- Billing, contract administration, and business records
- Marketing to businesses, including email outreach you can opt out of at any time
- Fraud prevention, abuse detection, and enforcing our terms
- Meeting legal, audit, and regulatory obligations
- Recruiting, if you apply for a job
For our clients, on their instructions:
- Completing the verification or canvass they requested
- Returning results, documentation, and call records to them
- Handling reverifications, escalations, and disputes they route to us
4. AI, quality, and service improvement
Ava uses automated speech, language, and document processing to conduct verifications. Human reviewers at Superunit listen to calls, read transcripts, and correct results as part of quality control and escalation handling.
We do not use client data or verification data to train or fine-tune AI models. We use call recordings, transcripts, and outcome data only to complete the verification, monitor accuracy, troubleshoot failures, and handle disputes and escalations for the client that ordered the work. Our AI and speech vendors are contractually prohibited from using data we send them to train their models.
We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising.
5. Who we disclose information to
- Our clients, for the verifications they order
- The parties we contact during a verification. Completing a verification requires disclosing the subject’s name and enough identifying detail for the employer, verifier, or facility to locate their record, along with any authorization or release that party requires.
- Service providers and subprocessors that support our operations, including cloud hosting and database providers, telephony and fax carriers, AI and speech model providers, email infrastructure, analytics, payment processing, and customer support tooling. A current list is available on request.
- Professional advisors, including counsel, auditors, and insurers
- Authorities, when required by law, subpoena, or valid legal process, or to protect rights and safety
- Acquirers, in connection with a merger, financing, acquisition, or sale of assets, subject to this policy
6. Cookies and analytics
Our website uses cookies and similar technologies for functionality, security, and analytics. We use Google Analytics to understand how visitors find and use our site. Google Analytics sets cookies and collects your IP address, device and browser details, pages viewed, and referring URL. Google processes this data as described in its own privacy policy, and you can opt out across all sites using the Google Analytics Opt-out Browser Add-on.
You can control cookies through your browser settings, and we honor Global Privacy Control signals where our tools support them. We do not use cookies for targeted advertising and we do not run advertising pixels on our site.
If you visit our site from the EEA, the UK, or another region that requires consent before non-essential cookies are set, we ask for that consent through our cookie banner and do not load Google Analytics until you accept.
7. Retention
We retain call audio, transcripts, and verification results for two years, then delete or de-identify them, unless a client agreement or a legal obligation requires a different period. Portal account and activity records are kept for the life of the account. Business contact and marketing records are kept until you opt out or the relationship ends, plus the period required for tax, audit, and legal purposes.
8. Health information
When we perform medical canvassing for insurance carriers, third-party administrators, or investigative firms, we may handle protected health information (PHI) under HIPAA. Where we act as a business associate, we enter into a business associate agreement with the client and apply the safeguards it requires. In those engagements, the client’s authorization, release, or claim-investigation authority is the basis for the request, and our HIPAA obligations and the business associate agreement control where they conflict with this policy.
9. If you are the subject of a verification
We work at the direction of the company that ordered the verification. If you want to see what was reported about you, correct an error, or dispute a result, contact that company. Under the FCRA, a consumer reporting agency must reinvestigate disputed information and give you a copy of your file on request. Superunit is not a consumer reporting agency and cannot change a report a client has issued.
If you do not know which company ordered the verification, email hello@superunit.com with what you do know and we will try to identify it and route your request.
10. Your privacy rights
Residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to appeal a denied request. California residents also have the right not to be retaliated against for exercising these rights.
To exercise a right regarding information we hold as a controller (website visitors, business contacts, portal users, applicants), email hello@superunit.com. We will verify your identity before acting and will respond within the time the applicable law allows. You can use an authorized agent where the law permits.
For verification-subject information, we act as a service provider and will forward your request to the client that ordered the verification, or direct you to them.
Some information is exempt from state privacy law requests. Information collected, processed, or reported under the FCRA and protected health information under HIPAA are the main examples relevant to our services.
11. Individuals outside the United States
We process information about individuals located outside the United States, including in Canada, the European Economic Area, the United Kingdom, Australia, New Zealand, and countries in South America. Our systems, staff, and vendors are in the United States, so information about you is transferred to and stored in the United States, where privacy laws differ from those in your country and where US courts, law enforcement, and national security authorities may be able to compel access.
In nearly all cases we process this information as a service provider, processor, or operator for the client that ordered the verification. That client is the controller. It decides what information to send us, and it is responsible for giving you notice, establishing a lawful basis or obtaining your consent, and answering your requests. If you contact us directly, we will route your request to that client.
Canada. We process personal information subject to PIPEDA and, for Quebec residents, Quebec’s Law 25. Your information is processed and stored outside Canada, in the United States. You can direct questions about our handling of Canadian personal information to hello@superunit.com.
European Economic Area and United Kingdom. Where the GDPR or UK GDPR applies, we act as a processor for our client, who is the controller and identifies the lawful basis under Article 6, along with any Article 9 or Article 10 condition where special category or criminal offence data is involved. Transfers from the EEA and UK to the United States are made under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, with supplementary measures where required. You have rights of access, rectification, erasure, restriction, objection, and portability. Exercise them with the controller, or write to us and we will forward the request. You also have the right to complain to your supervisory authority.
Australia and New Zealand. We handle personal information consistent with the Australian Privacy Principles under the Privacy Act 1988 and the Information Privacy Principles under New Zealand’s Privacy Act 2020, including the requirements that apply to disclosing personal information overseas. Complaints can be made to the Office of the Australian Information Commissioner or the New Zealand Office of the Privacy Commissioner.
South America. Where Brazil’s LGPD applies, we act as an operator (operador) for our client, who is the controller (controlador), and we process personal data only on that client’s documented instructions. Similar arrangements apply under the data protection laws of Argentina, Chile, Colombia, and other countries in the region.
12. Security
We use administrative, technical, and physical safeguards to protect personal information, including encryption in transit and at rest, access controls and least-privilege permissions, logging and monitoring, vendor review, and employee training. No system is completely secure. If a security incident affects your information, we will notify you and any affected client as required by law and by our contracts.
13. Children
Our services are for business use. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided information, email hello@superunit.com and we will delete it.
14. Changes to this policy
We may update this policy. If we make a material change, we will update the date above and, where required, notify clients or post a notice on our website. Continued use of our services after an update means you accept the revised policy.
15. Contact
Superunit, Inc. 14622 Ventura Blvd, Ste 2169 Sherman Oaks, CA 91403 Email: hello@superunit.com