Legal
Privacy Policy
How Modern Labyrinth collects, uses, and protects your information. Covers CCPA/CPRA and GDPR rights.
Last updated: September 11, 2026
Scope and contact
Modern Labyrinth is the trading name of Three Teeth, Inc., based in Orange County, California. This notice describes information handled through our website, business inquiries and service administration. Information we process for a client follows the actual engagement and any applicable data agreement or Business Associate Agreement (BAA).
For privacy questions or requests, email privacy@modernlabyrinth.com. You can also contact hello@modernlabyrinth.com. Please do not include patient information, credentials or identity documents in an initial request.
Information and purposes
- Business inquiries and correspondence: contact details, company, selected service, timeline and other business information you choose to provide. We use this to respond, scope work and keep correspondence. Form fields vary by service.
- Service administration: agreed project materials, billing and transaction records, authorized account/access information and work records. Access and transfer methods are set for the actual engagement; public inquiry forms are not a credential-transfer channel.
- Site operation and security: hosting and security providers may process request information such as IP address, browser details, requested URL and time to deliver and protect the site. This is separate from optional audience measurement.
- Optional measurement: with analytics permission, page and interaction events and campaign parameters help us understand website use. With separate marketing permission, advertising identifiers and marketing measurement may help attribute an inquiry. We do not include typed inquiry names, email addresses, company names or patient information in our designed analytics events.
- Legal and accounting records: information reasonably needed for tax, accounting, lawful requests, disputes and preservation obligations.
Where data-protection law requires a lawful basis, the basis depends on the activity: requested services or steps before a contract, legitimate interests in responding and securing operations, consent for optional measurement, or a legal obligation. Consent for optional tracking is separate from sending a business inquiry.
Providers and disclosures
The providers receiving information depend on the service and enabled configuration. Categories include:
- Hosting, delivery and security providers, including Vercel.
- Google services for website font delivery, and Google Workspace or the configured email provider for business correspondence and inquiry delivery.
- Google Analytics for optional measurement and LinkedIn marketing measurement where enabled and permitted.
- A configured CRM or lead-delivery integration, which may include HubSpot or Salesforce, for responding to business inquiries.
- Payment providers such as Stripe where offered, and accounting/tax providers such as QuickBooks and our advisers. Card details entered into a hosted payment service are handled by that service; do not send card details in an inquiry.
- Approved personnel, contractors and professional advisers who need information for the agreed work, subject to the applicable confidentiality and data arrangements.
We may disclose information when legally required or reasonably necessary to establish or defend legal rights. Provider privacy notices describe their separate practices; our choice of a provider does not remove our own applicable obligations. Ask us about the providers relevant to your inquiry or engagement.
Cookies and advertising choices
Use Cookie Settings to choose analytics and marketing separately or withdraw a choice. Optional scripts and advertising attribution follow those choices. A Global Privacy Control signal disables the marketing category. Some advertising-related disclosures may be treated as sharing under applicable privacy law; use the marketing control or contact us to exercise the applicable opt-out right.
Withdrawal applies to future optional collection; it does not itself recall information already transmitted or delete required business records. The page may reload to stop a previously loaded optional script. Business inquiry delivery remains available when optional categories are declined. See the Cookie Policy for storage details.
Requests and your rights
Depending on applicable law and the information involved, you may request access or a copy, correction, deletion, portability, restrictions on processing, or an objection to certain uses. California rights may include opting out of sale or sharing, limiting qualifying uses of sensitive personal information, and exercising rights without unlawful discrimination. EU/UK rights may include withdrawing consent and complaining to the appropriate data-protection authority. These rights have conditions and exceptions; this notice does not assume every law applies to every interaction.
Send a request to the privacy address above. We will assess the request, use proportionate verification where needed, and respond within the applicable legal deadline, explaining a permitted extension or exception when required. An authorized agent should identify their authority. Do not send sensitive verification material until an appropriate method is agreed.
Further information: California privacy rights.
Retention and safeguards
Retention depends on the purpose, engagement, category of information and applicable legal obligations. Relevant factors include whether an inquiry is active, the agreed service/return terms, accounting requirements, security needs and a dispute or preservation obligation. When retention is no longer required or justified, disposition follows the applicable process and agreement. No single automatic deletion period covers every mailbox, log, analytics provider or client record.
We use safeguards appropriate to the activity, including protected transmission and restricted account access. Actual client-data controls and approved tools are defined for the engagement. No website or communication method is risk-free; avoid sending sensitive information through public forms. Ask us for the retention and security information relevant to a proposed service.
Healthcare and sensitive information
Public inquiries are for business information. Do not submit patient names, medical information, files or credentials. Work involving protected health information requires the applicable scope, agreements, approved services and safeguards before access; a privacy notice or a vendor BAA alone does not authorize it.
Patient requests about records should ordinarily be directed to the relevant healthcare provider. If a request reaches us, we handle or route it according to our actual role, agreement and applicable law. This notice does not replace the provider’s privacy notice or limit obligations under a BAA.
Children and international processing
Our business services are not directed to children. If you believe a child supplied information, contact us so we can assess the record and handle it under applicable requirements.
We operate in the United States, and providers or approved personnel may process information in the locations relevant to the service. Where cross-border transfer requirements apply, the actual parties, destinations and required safeguards must be addressed for that processing. This notice does not represent that a particular transfer agreement has been executed for every service.
Updates
The date above identifies this version. We may update the notice as practices change and provide additional notice where required. A website update does not amend a signed service agreement or BAA.
Modlab-PEAK and Google API data
Modlab-PEAK is the Google-connected application used by Modern Labyrinth for PEAK Technologies' advertising and analytics work. This section supplements our privacy notice for that connection. The actual engagement and applicable data agreements continue to govern client information.
With the account holder's authorization, the connection accesses Google Ads account identifiers, account and campaign settings, and performance and conversion reports. The connection may retrieve billing documents when Google's API access rules and the authorizing account's billing arrangement permit it. Its existing Google Analytics permissions allow reading reports and editing Analytics management settings. These permissions support agreed advertising operations, measurement, reporting and account-support work. Account changes require the separate approval applicable to the engagement.
Google-derived information is used in dashboards, reports, monitoring and account-change records. Working records, snapshots and reports are stored in Modern Labyrinth's local workspaces and server systems; workflow execution records and backups may also contain that information. OAuth authorization credentials are stored in the operational configuration used by the integrations.
The configured automated briefing workflow uses Anthropic's Claude API to process collected reporting data and generate a draft brief. Its output is configured for storage in Modern Labyrinth's systems and delivery through the designated project channel in Modern Labyrinth's Mattermost service. Reports are made available to the people handling the engagement through its configured work and delivery systems. Hosting, storage, workflow and communication services process information needed to provide those functions.
Retention follows the purposes and conditions described in our privacy notice, including the engagement's applicable return/deletion terms and accounting, security, legal or preservation needs. Routine workflow-log cleanup does not delete exported reports, account-change records or preserved backups. Removing a Google connection does not itself delete previously exported records. Contact privacy@modernlabyrinth.com about access, deletion or retention for this engagement.