Dr. Linda YarickHuman Performance Consulting
  • About
  • Consulting
  • SAP
  • Books
  • Speaking
  • Insights
  • Assessments
Schedule a Consultation
Legal

Privacy Policy

Human Performance Consulting — guidedgrowthleadershipmodel.com

Effective Date: [Insert Date] Last Updated: [Insert Date]

Contents

  1. Introduction
  2. The Three Information Streams — a Map
  3. Information We Collect Automatically
  4. Information You Provide Directly
  5. SAP Services and DOT Return-to-Duty Information — Special Rules
  6. Cookies and Similar Technologies
  7. Service Providers Who Process Information for Us
  8. Employee Data in Consulting Engagements
  9. How We Use Information
  10. Data Retention
  11. Your Privacy Rights — and Their Limits
  12. Security
  13. Data Breach
  14. Children's Privacy
  15. Changes to This Policy
  16. Contact Us

01 Introduction

Human Performance Consulting, operated by Dr. Linda Yarick ("we," "us," or "our"), respects the privacy of everyone who visits this website, contacts us about consulting or speaking work, participates in an organizational engagement, or comes to us for Substance Abuse Professional (SAP) services under U.S. Department of Transportation regulations.

This Policy explains what information we collect, why we collect it, who it is shared with, how long it is kept, and what control you have over it. It also explains — clearly and without hedging — the specific circumstances in which federal law requires us to disclose information about individuals in the DOT return-to-duty process, regardless of consent.

Please read Section 5 carefully if you are a safety-sensitive employee, CDL driver, or owner-operator. It applies to you specifically.

02 The Three Information Streams — a Map

Different rules apply depending on how you interact with us. Locating yourself here first will make the rest of this Policy far easier to follow.

Stream A — Website visitors and general inquirers. You browse the Site, read Insights articles, download the free book sample, submit the contact form, or book a discovery call. Ordinary commercial privacy practices apply. This is covered in Sections 3, 4, 6, 7, and 9.

Stream B — Organizational and consulting clients. Your organization engages us for leadership alignment, organizational development, culture and engagement work, emotional intelligence development, workforce performance consulting, speaking, training, or an assessment pilot. We may process information about your employees on your behalf. This is covered in Section 8.

Stream C — SAP and DOT return-to-duty participants. You are an employee, driver, or employer engaged with us for a SAP evaluation, follow-up evaluation, return-to-duty guidance, or Clearinghouse-related process. This information is governed primarily by 49 CFR Part 40, not by this Policy's general practices. Where this Policy and Part 40 differ, Part 40 controls. This is covered in Section 5.

03 Information We Collect Automatically

When you visit the Site, our hosting environment and any analytics tooling we use may automatically record:

  • IP address (which may be truncated or anonymized depending on configuration)
  • browser type, operating system, device type, and screen size
  • pages viewed, time on page, referring URL, and exit pages
  • date and time of access
  • general geographic region inferred from IP address (typically city or region level, not precise location)

This information is used to keep the Site secure and functioning, to understand which topics readers find useful, and to improve navigation. It is not used to build advertising profiles.

Important: we do not attempt to link automatically collected browsing data to any individual's SAP file, clinical record, or return-to-duty status. These systems are kept separate.

04 Information You Provide Directly

4.1 The contact form. The form on the Site collects your full name, organization, email address, phone number, your selection from the "I'm interested in" menu (Organizational consulting, Leadership coaching, SAP services for employers, SAP evaluation for individuals, Keynote/speaking, Workshop or training, Book inquiry/media, or Other), and whatever you type into the free-text message field.

Your selection alone can indicate that you may have a substance-use-related matter. We therefore treat inquiries submitted under the SAP-related options as sensitive from the moment they arrive, restrict internal access to them, and do not use them for marketing.

4.2 Please do not send clinical details through the form. The contact form and ordinary email are not secure clinical channels. Do not submit test results, violation dates, medical or substance use history, treatment records, diagnoses, Social Security numbers, CDL numbers, or Clearinghouse credentials through the Site or by unencrypted email. Tell us only that you need assistance and how to reach you. Clinical intake takes place afterward, through a consented process with appropriate safeguards. Anything you volunteer beyond what we ask for is submitted at your own risk.

4.3 Scheduling. Booking a consultation uses a third-party scheduling platform (Calendly). Information you enter there — name, email, timezone, any notes you add — is collected by that provider under its own privacy policy and transmitted to us.

4.4 The free book sample. If we require an email address before delivering the sample chapter, that address is used to deliver the file and, only where you have affirmatively opted in, to send occasional updates about new writing, speaking dates, or assessment availability. Every marketing email includes an unsubscribe link. Unsubscribing never affects service delivery.

4.5 Insights comments and submissions. If the blog permits comments or submissions, anything you post may be publicly visible along with the name you supply. Do not post personal health information, another person's information, or details of an employment or testing matter in a public comment.

4.6 Engagement and intake information. Once an engagement begins, we collect the information necessary to perform it — which varies enormously between a keynote booking and a SAP evaluation, and is described in the applicable agreement or consent form.

05 SAP Services and DOT Return-to-Duty Information — Special Rules

This section governs information about identifiable individuals in the DOT drug and alcohol testing process. It is the most protective and, in specific respects, the most constrained part of this Policy.

5.1 The baseline rule is confidentiality. As a service agent participating in the DOT drug and alcohol testing process, we are prohibited by 49 CFR §40.321 from releasing individual test results or medical information about an employee to third parties without that employee's specific written consent.

5.2 "Specific written consent" means specific. Under §40.321(b), a valid consent identifies a particular piece of information, released to a particular, explicitly identified person or organization, at a particular time. Blanket releases are prohibited — we cannot and will not accept an authorization that permits release of "all records" or release to a category of recipients such as "any prospective employer" or "any member of a consortium." If you are asked to sign such a release in connection with our services, it is invalid under Part 40.

5.3 Disclosures that occur without your consent — and cannot be waived. Federal law requires or expressly authorizes certain disclosures. You should understand these before you begin the process:

  • FMCSA Clearinghouse reporting. For CDL drivers subject to 49 CFR Part 382, we are required by §382.705(d) to report to the FMCSA Drug and Alcohol Clearinghouse the driver's identifying information and the date the initial substance abuse assessment was initiated — by the close of the business day following that assessment — and the date on which we determine the driver has demonstrated successful compliance and is eligible for return-to-duty testing, by the close of the business day following that determination. We are also required to report truthfully and accurately, and are expressly prohibited from reporting anything we know or should know is inaccurate. No agreement, request, or payment can suspend, delay, or alter these reports.
  • Reports to the employer or designated employer representative. Part 40 Subpart O requires the SAP to provide specified written reports to the employer, including the recommended course of education and/or treatment, the follow-up testing plan, and the compliance determination.
  • DOT and NTSB access. Under §40.311(g), we must make SAP reports and related records available on request to Department of Transportation agency representatives — for example, inspectors conducting an audit or safety investigation — and to representatives of the National Transportation Safety Board in the course of an accident investigation.
  • Other disclosures expressly authorized by Part 40 Subpart P, including disclosures in certain legal proceedings brought by or on behalf of an employee arising from a positive test or refusal to test.
  • Disclosures required by other law, such as a valid court order or subpoena, or mandatory reporting obligations imposed by state law or professional licensure.

5.4 What we do not do with this information. We do not sell it. We do not use it for marketing. We do not disclose it to prospective employers, insurers, lenders, family members, attorneys, or unions absent a valid specific written consent or a legal requirement. We do not use it to train machine-learning or artificial intelligence systems. We do not publish it, even in de-identified form, without separate written permission.

5.5 Records we receive from others. In the course of an evaluation we may receive records from treatment programs, counselors, or laboratories. Where those records are protected by 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) or comparable law, we handle and re-disclose them only as those rules permit — which is often more restrictive than Part 40 alone.

5.6 Retention is set by federal law, not by preference. Under 49 CFR §40.311(g), we maintain copies of our reports to employers for five (5) years, and maintain employee clinical records in accordance with applicable federal, state, and local laws governing record maintenance, confidentiality, and release of information. State licensure rules may require longer retention. A request to delete these records cannot be honoured during the mandated retention period. See Section 11.

5.7 Employers, we hold you to the same standard. Information you provide about your employees is used solely to perform the engagement. Employers have their own independent obligations under Part 40 and Part 382, including their own record-retention duties.

06 Cookies and Similar Technologies

The Site runs on WordPress and may use:

  • Strictly necessary cookies — session management, security, form submission integrity, and load balancing. These cannot be switched off without breaking the Site.
  • Functional cookies — remembering preferences and enabling embedded features such as the scheduling widget or the sample-download modal.
  • Analytics cookies — [specify, e.g., Google Analytics 4] used in aggregate to understand traffic patterns and content performance.

We do not use the Site for behavioural advertising or cross-site ad targeting. Third-party embeds — scheduling, video, social widgets — may set their own cookies under their own policies.

You can block or delete cookies in your browser settings; some Site functionality may degrade. We honour Global Privacy Control (GPC) signals where applicable law requires it.

07 Service Providers Who Process Information for Us

We share information with a limited set of vendors strictly as needed to operate:

  • website hosting and security [insert provider]
  • email and business communications [insert provider]
  • appointment scheduling (Calendly)
  • email marketing, if used [insert provider]
  • analytics [insert provider]
  • professional advisors — accountants, attorneys, insurers — under confidentiality obligations

Vendors are permitted to use information only to provide services to us. SAP and clinical information is deliberately kept outside general marketing, analytics, and CRM systems.

The Site links to Amazon, LinkedIn, and the FMCSA Clearinghouse. Following those links takes you to services we do not control, each with its own privacy practices.

08 Employee Data in Consulting Engagements

When an organization engages us for culture work, engagement diagnostics, leadership development, or an assessment pilot, we may collect information from or about that organization's employees — survey responses, interview notes, 360-style feedback, or assessment results.

In those engagements:

  • the client organization determines the purpose of the work; we process the information on its behalf under the engagement agreement;
  • individual responses are reported to the client in aggregated or de-identified form unless the individual has knowingly consented otherwise, or unless the format of the engagement (for example, named executive coaching) makes attribution inherent and understood in advance;
  • we apply a minimum group-size threshold before reporting segment-level results, so that small teams cannot be re-identified by inference;
  • coaching conversations are treated as confidential; we report themes and progress to a sponsoring organization, not verbatim disclosures, unless there is a safety or legal obligation to do otherwise;
  • assessment results are not used for hiring, promotion, discipline, or termination decisions unless the engagement expressly contemplates that use and the instrument has been validated for it.

Where an organization requires a data processing agreement or additional confidentiality terms, we will execute one.

09 How We Use Information

We use information to respond to inquiries; schedule and conduct consultations; deliver contracted consulting, coaching, training, and speaking services; conduct SAP evaluations and meet the associated regulatory obligations; deliver requested materials such as the book sample; send opted-in updates; operate, secure, and improve the Site; maintain business records; and comply with legal, regulatory, tax, licensure, and insurance requirements.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not use client, participant, or SAP information to train artificial intelligence models.

10 Data Retention

CategoryRetention
Website analytics[Insert, e.g., 14 months] in aggregate form
General inquiries with no engagement[Insert, e.g., 24 months], then deleted
Marketing list subscriptionsUntil you unsubscribe, plus a suppression record to honour your opt-out
Consulting and speaking engagement recordsDuration of engagement plus [insert, e.g., 7 years] for contractual, tax, and insurance purposes
Consulting-related employee survey and assessment dataPer the engagement agreement; typically returned or destroyed at close-out
SAP reports to employersFive (5) years, per 49 CFR §40.311(g)
SAP clinical recordsAs required by applicable federal, state, and local law and professional licensure

11 Your Privacy Rights — and Their Limits

Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of your personal information, to opt out of sale or targeted advertising (we conduct neither), and to be free from discrimination for exercising these rights.

To make a request, contact us using the details in Section 16. We will verify your identity before acting, and will respond within the timeframe required by applicable law.

Two important limits:

11.1 Regulated records are exempt from deletion. We cannot delete SAP evaluation records, reports to employers, Clearinghouse-reported information, or clinical records during any period in which federal or state law requires us to retain them, nor can we retract information already reported to the FMCSA Clearinghouse, which is governed by FMCSA — not by us. Requests to remove or amend a Clearinghouse record must be directed to FMCSA under its own procedures.

11.2 Access to clinical records follows clinical rules. Requests by an individual for their own evaluation records are handled under 49 CFR Part 40, 42 CFR Part 2 where applicable, and applicable state law and licensure standards — not under general consumer privacy procedures.

Residents of states with comprehensive privacy statutes — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — may have additional rights, including with respect to sensitive personal information. Residents of states with dedicated consumer health data laws (such as Washington's My Health My Data Act and Nevada's SB 370) may have additional rights regarding health-related information that falls outside federally regulated categories. We treat substance-use-related inquiry information as sensitive across all jurisdictions rather than parsing state lines.

12 Security

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including encrypted transmission for the Site, access controls limiting SAP and clinical information to Dr. Yarick and authorised personnel with a professional need to know, separation of clinical records from general business and marketing systems, secure storage and disposal, and confidentiality obligations for any contractor with incidental access.

No system is perfectly secure. We cannot guarantee the security of information transmitted over the public internet — which is precisely why Section 4.2 asks you not to send clinical details by web form or ordinary email.

13 Data Breach

If a breach affecting your personal information occurs, we will notify affected individuals and applicable regulators as required by law and, where clinical or regulated records are involved, in accordance with the notification standards applicable to those records.

14 Children's Privacy

The Site is not directed to children under 13 and our services are intended for adults. We do not knowingly collect information from children. If you believe a child has provided information, contact us and we will delete it.

15 Changes to This Policy

We may update this Policy to reflect changes in our services, technology, or legal obligations. The "Last Updated" date will change accordingly. Material changes affecting active engagements will be communicated directly. Changes to this Policy never reduce the protections that federal regulation independently guarantees to individuals in the DOT return-to-duty process.

16 Contact Us

Human Performance Consulting

Dr. Linda Yarick

Email: yarickln@aol.com

Phone: 419-704-7683

Dr. Linda YarickHuman Performance Consulting

Bridging the gap between potential and performance — through aligned people, culture, and systems.

Consulting
  • Leadership Alignment
  • Organizational Development
  • Culture & Engagement
  • Emotional Intelligence
  • Workforce Performance
SAP
  • SAP Evaluations
  • Return-to-Duty
  • Follow-Up Testing
  • Supervisor Training
  • Employee Training
  • Employer Consultation
Connect
  • Books
  • Speaking
  • Insights
  • Contact
  • Linkedin
© 2026 Human Performance Consulting. All rights reserved. The Human Performance Consulting™ Organizational Intelligence Assessment System™, assessment frameworks, methodologies, and related content are proprietary and protected by applicable intellectual property laws.
Privacy · Terms · Intellectual Property Notice · Copyright Notice · Disclaimer
Guided Growth — Free Sample