Human Performance Consulting — guidedgrowthleadershipmodel.com
Human Performance Consulting, operated by Dr. Linda Yarick ("we," "us," or "our"), respects the privacy of everyone who visits this website, contacts us about consulting or speaking work, participates in an organizational engagement, or comes to us for Substance Abuse Professional (SAP) services under U.S. Department of Transportation regulations.
This Policy explains what information we collect, why we collect it, who it is shared with, how long it is kept, and what control you have over it. It also explains — clearly and without hedging — the specific circumstances in which federal law requires us to disclose information about individuals in the DOT return-to-duty process, regardless of consent.
Please read Section 5 carefully if you are a safety-sensitive employee, CDL driver, or owner-operator. It applies to you specifically.
Different rules apply depending on how you interact with us. Locating yourself here first will make the rest of this Policy far easier to follow.
Stream A — Website visitors and general inquirers. You browse the Site, read Insights articles, download the free book sample, submit the contact form, or book a discovery call. Ordinary commercial privacy practices apply. This is covered in Sections 3, 4, 6, 7, and 9.
Stream B — Organizational and consulting clients. Your organization engages us for leadership alignment, organizational development, culture and engagement work, emotional intelligence development, workforce performance consulting, speaking, training, or an assessment pilot. We may process information about your employees on your behalf. This is covered in Section 8.
Stream C — SAP and DOT return-to-duty participants. You are an employee, driver, or employer engaged with us for a SAP evaluation, follow-up evaluation, return-to-duty guidance, or Clearinghouse-related process. This information is governed primarily by 49 CFR Part 40, not by this Policy's general practices. Where this Policy and Part 40 differ, Part 40 controls. This is covered in Section 5.
When you visit the Site, our hosting environment and any analytics tooling we use may automatically record:
This information is used to keep the Site secure and functioning, to understand which topics readers find useful, and to improve navigation. It is not used to build advertising profiles.
Important: we do not attempt to link automatically collected browsing data to any individual's SAP file, clinical record, or return-to-duty status. These systems are kept separate.
4.1 The contact form. The form on the Site collects your full name, organization, email address, phone number, your selection from the "I'm interested in" menu (Organizational consulting, Leadership coaching, SAP services for employers, SAP evaluation for individuals, Keynote/speaking, Workshop or training, Book inquiry/media, or Other), and whatever you type into the free-text message field.
Your selection alone can indicate that you may have a substance-use-related matter. We therefore treat inquiries submitted under the SAP-related options as sensitive from the moment they arrive, restrict internal access to them, and do not use them for marketing.
4.2 Please do not send clinical details through the form. The contact form and ordinary email are not secure clinical channels. Do not submit test results, violation dates, medical or substance use history, treatment records, diagnoses, Social Security numbers, CDL numbers, or Clearinghouse credentials through the Site or by unencrypted email. Tell us only that you need assistance and how to reach you. Clinical intake takes place afterward, through a consented process with appropriate safeguards. Anything you volunteer beyond what we ask for is submitted at your own risk.
4.3 Scheduling. Booking a consultation uses a third-party scheduling platform (Calendly). Information you enter there — name, email, timezone, any notes you add — is collected by that provider under its own privacy policy and transmitted to us.
4.4 The free book sample. If we require an email address before delivering the sample chapter, that address is used to deliver the file and, only where you have affirmatively opted in, to send occasional updates about new writing, speaking dates, or assessment availability. Every marketing email includes an unsubscribe link. Unsubscribing never affects service delivery.
4.5 Insights comments and submissions. If the blog permits comments or submissions, anything you post may be publicly visible along with the name you supply. Do not post personal health information, another person's information, or details of an employment or testing matter in a public comment.
4.6 Engagement and intake information. Once an engagement begins, we collect the information necessary to perform it — which varies enormously between a keynote booking and a SAP evaluation, and is described in the applicable agreement or consent form.
This section governs information about identifiable individuals in the DOT drug and alcohol testing process. It is the most protective and, in specific respects, the most constrained part of this Policy.
5.1 The baseline rule is confidentiality. As a service agent participating in the DOT drug and alcohol testing process, we are prohibited by 49 CFR §40.321 from releasing individual test results or medical information about an employee to third parties without that employee's specific written consent.
5.2 "Specific written consent" means specific. Under §40.321(b), a valid consent identifies a particular piece of information, released to a particular, explicitly identified person or organization, at a particular time. Blanket releases are prohibited — we cannot and will not accept an authorization that permits release of "all records" or release to a category of recipients such as "any prospective employer" or "any member of a consortium." If you are asked to sign such a release in connection with our services, it is invalid under Part 40.
5.3 Disclosures that occur without your consent — and cannot be waived. Federal law requires or expressly authorizes certain disclosures. You should understand these before you begin the process:
5.4 What we do not do with this information. We do not sell it. We do not use it for marketing. We do not disclose it to prospective employers, insurers, lenders, family members, attorneys, or unions absent a valid specific written consent or a legal requirement. We do not use it to train machine-learning or artificial intelligence systems. We do not publish it, even in de-identified form, without separate written permission.
5.5 Records we receive from others. In the course of an evaluation we may receive records from treatment programs, counselors, or laboratories. Where those records are protected by 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) or comparable law, we handle and re-disclose them only as those rules permit — which is often more restrictive than Part 40 alone.
5.6 Retention is set by federal law, not by preference. Under 49 CFR §40.311(g), we maintain copies of our reports to employers for five (5) years, and maintain employee clinical records in accordance with applicable federal, state, and local laws governing record maintenance, confidentiality, and release of information. State licensure rules may require longer retention. A request to delete these records cannot be honoured during the mandated retention period. See Section 11.
5.7 Employers, we hold you to the same standard. Information you provide about your employees is used solely to perform the engagement. Employers have their own independent obligations under Part 40 and Part 382, including their own record-retention duties.
The Site runs on WordPress and may use:
We do not use the Site for behavioural advertising or cross-site ad targeting. Third-party embeds — scheduling, video, social widgets — may set their own cookies under their own policies.
You can block or delete cookies in your browser settings; some Site functionality may degrade. We honour Global Privacy Control (GPC) signals where applicable law requires it.
We share information with a limited set of vendors strictly as needed to operate:
Vendors are permitted to use information only to provide services to us. SAP and clinical information is deliberately kept outside general marketing, analytics, and CRM systems.
The Site links to Amazon, LinkedIn, and the FMCSA Clearinghouse. Following those links takes you to services we do not control, each with its own privacy practices.
When an organization engages us for culture work, engagement diagnostics, leadership development, or an assessment pilot, we may collect information from or about that organization's employees — survey responses, interview notes, 360-style feedback, or assessment results.
In those engagements:
Where an organization requires a data processing agreement or additional confidentiality terms, we will execute one.
We use information to respond to inquiries; schedule and conduct consultations; deliver contracted consulting, coaching, training, and speaking services; conduct SAP evaluations and meet the associated regulatory obligations; deliver requested materials such as the book sample; send opted-in updates; operate, secure, and improve the Site; maintain business records; and comply with legal, regulatory, tax, licensure, and insurance requirements.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not use client, participant, or SAP information to train artificial intelligence models.
| Category | Retention |
|---|---|
| Website analytics | [Insert, e.g., 14 months] in aggregate form |
| General inquiries with no engagement | [Insert, e.g., 24 months], then deleted |
| Marketing list subscriptions | Until you unsubscribe, plus a suppression record to honour your opt-out |
| Consulting and speaking engagement records | Duration of engagement plus [insert, e.g., 7 years] for contractual, tax, and insurance purposes |
| Consulting-related employee survey and assessment data | Per the engagement agreement; typically returned or destroyed at close-out |
| SAP reports to employers | Five (5) years, per 49 CFR §40.311(g) |
| SAP clinical records | As required by applicable federal, state, and local law and professional licensure |
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of your personal information, to opt out of sale or targeted advertising (we conduct neither), and to be free from discrimination for exercising these rights.
To make a request, contact us using the details in Section 16. We will verify your identity before acting, and will respond within the timeframe required by applicable law.
Two important limits:
11.1 Regulated records are exempt from deletion. We cannot delete SAP evaluation records, reports to employers, Clearinghouse-reported information, or clinical records during any period in which federal or state law requires us to retain them, nor can we retract information already reported to the FMCSA Clearinghouse, which is governed by FMCSA — not by us. Requests to remove or amend a Clearinghouse record must be directed to FMCSA under its own procedures.
11.2 Access to clinical records follows clinical rules. Requests by an individual for their own evaluation records are handled under 49 CFR Part 40, 42 CFR Part 2 where applicable, and applicable state law and licensure standards — not under general consumer privacy procedures.
Residents of states with comprehensive privacy statutes — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect — may have additional rights, including with respect to sensitive personal information. Residents of states with dedicated consumer health data laws (such as Washington's My Health My Data Act and Nevada's SB 370) may have additional rights regarding health-related information that falls outside federally regulated categories. We treat substance-use-related inquiry information as sensitive across all jurisdictions rather than parsing state lines.
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including encrypted transmission for the Site, access controls limiting SAP and clinical information to Dr. Yarick and authorised personnel with a professional need to know, separation of clinical records from general business and marketing systems, secure storage and disposal, and confidentiality obligations for any contractor with incidental access.
No system is perfectly secure. We cannot guarantee the security of information transmitted over the public internet — which is precisely why Section 4.2 asks you not to send clinical details by web form or ordinary email.
If a breach affecting your personal information occurs, we will notify affected individuals and applicable regulators as required by law and, where clinical or regulated records are involved, in accordance with the notification standards applicable to those records.
The Site is not directed to children under 13 and our services are intended for adults. We do not knowingly collect information from children. If you believe a child has provided information, contact us and we will delete it.
We may update this Policy to reflect changes in our services, technology, or legal obligations. The "Last Updated" date will change accordingly. Material changes affecting active engagements will be communicated directly. Changes to this Policy never reduce the protections that federal regulation independently guarantees to individuals in the DOT return-to-duty process.