Privacy Policy

Effective Date: August 25, 2026 Last Updated: August 25, 2026 Version: 3.0

Pidalia LLC (“Pidalia”) collects the personal information you give us and the technical information your device generates when you use our website, software, and services. We use it to run our business, deliver and secure our services, communicate with you, and meet our legal obligations. We do not sell your personal information. We do not share it for cross-context behavioral advertising. We never share your mobile phone number, SMS opt-in status, or any other text-messaging opt-in data with third parties or affiliates. You have rights over your information, and this policy tells you exactly how to exercise them.

1. Who We Are and Scope of This Policy

1.1 Who we are

Pidalia LLC is a limited liability company organized under the laws of the Commonwealth of Massachusetts, United States. Our principal place of business is:

Pidalia LLC 101 Federal Street, Suite 1900 Boston, Massachusetts 02110 United States

In this Privacy Policy, “Pidalia,” “we,” “us,” and “our” refer to Pidalia LLC only. For clarity, and notwithstanding any prior version of this policy, these terms do not include any affiliate, subsidiary, parent, investor, partner, client, or other entity.

1.2 What this policy covers

This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with:

  • Our public website at com and any subdomains (the “Site”);
  • The software applications, platforms, portals, application programming interfaces (APIs), and hosted environments that we own and operate and that display or link to this policy (the “Platform”);
  • Text-messaging (SMS/MMS) programs that we operate, including multi-factor authentication (MFA) and account-security messages (the “SMS Program”);
  • Our consulting, design, engineering, marketing, and related professional services (the “Professional Services”);
  • Communications you have with us by email, telephone, video conference, chat, form submission, or in person; and
  • Our recruiting and hiring activities.

The Site, Platform, SMS Program, Professional Services, and related activities are collectively the “Services.”

1.3 What this policy does not cover

This policy does not cover:

  • Client-controlled data. When we build, host, maintain, or operate software or systems on behalf of a client, and process personal information under that client’s instructions, the client’s privacy policy governs that information, and we act as a service provider or processor. See Section 3.
  • Third-party websites and services. Any website, application, or service that we do not own or operate, even if we link to it or integrate with it. See Section 32.
  • Employees and contractors. Personnel of Pidalia are covered by separate internal notices.

1.4 Acceptance

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires your consent for a specific processing activity (for example, non-essential cookies or SMS messaging), we will obtain that consent separately and you may withdraw it at any time.

2. Definitions

Capitalized terms not otherwise defined have the meanings below. Where a term is defined by an applicable privacy law and that definition is broader than ours, the statutory definition controls for individuals protected by that law.

  • “Personal Information” (also “personal data”) means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include information that has been de-identified, aggregated, or anonymized in accordance with applicable law, or information that is publicly available as defined by applicable law.
  • “Sensitive Personal Information” has the meaning in Section 16.
  • “Mobile Information” means any personal information collected through or in connection with the SMS Program, including your mobile telephone number, the fact and date/time of your opt-in, your opt-in method, your consent status, your carrier, message logs, delivery receipts, and any responses you send by text message.
  • “Opt-In Data” means Mobile Information that evidences or relates to your consent to receive text messages from us.
  • “Third Party” means any person or entity other than (a) you, (b) Pidalia LLC, or (c) a Service Provider or Processor acting on our documented instructions.
  • “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with Pidalia LLC, including any entity that shares common ownership, management, or branding with Pidalia LLC.
  • “Service Provider” or “Processor” means a vendor that processes personal information on our behalf, under a written contract, solely for the purpose of providing services to us, and that is prohibited from using that information for its own purposes.
  • “Sell” means to exchange personal information with a third party for monetary or other valuable consideration, as defined by applicable law.
  • “Share” (in the California sense) means to disclose personal information to a third party for cross-context behavioral advertising, whether or not for consideration.
  • “Controller” or “Business” means the entity that determines the purposes and means of processing personal information.
  • “Processing” means any operation performed on personal information, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, and destruction.
  • “You” means the individual whose personal information we process, whether you are a Site visitor, Platform user, SMS Program participant, client representative, prospective client, vendor representative, job applicant, or other person interacting with us.

3. Our Role: Controller vs. Processor

Pidalia operates in two distinct capacities, and your rights and our obligations differ depending on which applies.

3.1 Pidalia as Controller / Business

We are the controller (or “business” under U.S. state law) for personal information we collect for our own purposes, including:

  • Information collected through the Site;
  • Information about users of Platform features that we own and operate for our own account (including account-security and MFA functionality);
  • Information about our clients’ representatives, prospective clients, vendors, and other business contacts;
  • Information about SMS Program participants;
  • Information about job applicants; and
  • Information we generate from your interactions with us (for example, support tickets, call notes, and usage logs).

This Privacy Policy applies in full to this information.

3.2 Pidalia as Processor / Service Provider

When we design, build, host, maintain, operate, or support software, websites, marketing programs, or other systems for a client, and in doing so process personal information that the client has collected or that end users provide to the client’s systems, we act as a processor or service provider. In that role:

  • The client is the controller and determines why and how the information is processed;
  • We process the information only on the client’s documented instructions and under a written data processing agreement;
  • We do not use the information for our own purposes;
  • The client’s privacy policy, not this one, governs that information; and
  • Individuals seeking to exercise rights over that information should contact the client. If you contact us instead, we will refer your request to the client where we can identify them, and we will assist the client in responding.

3.3 Mixed contexts

Some Platform features involve both roles. For example, if we host a client application that uses our MFA functionality, the client controls the application’s user data while we control the security-event logs and the SMS Program data needed to deliver authentication codes. We maintain records that identify which role applies to each processing activity and will tell you which applies if you ask.

4. Personal Information We Collect

The categories below describe what we may collect. Not every category applies to every person. Appendix A maps these categories to the statutory categories used by U.S. state privacy laws.

4.1 Identifiers and contact information

  • Full name, preferred name, and title
  • Postal address (home and/or business)
  • Email address(es)
  • Telephone number(s), including mobile telephone number
  • Company or organization name and your role there
  • Account username and internal user ID
  • Unique identifiers we assign (customer number, ticket number, project code)
  • Online identifiers, including IP address, device ID, advertising ID (where enabled), cookie ID, and similar identifiers
  • Social media handles you provide
  • Signatures (electronic or handwritten) on agreements

4.2 Account and authentication information

  • Login credentials (passwords are stored only in salted, hashed form; we never store plaintext passwords)
  • Multi-factor authentication settings, enrolled factors, and the mobile telephone number used for SMS-based MFA
  • One-time passcodes (retained only for the brief validity window needed to verify them)
  • Security questions and answers (stored hashed)
  • Authentication and session logs, including login attempts, timestamps, IP addresses, and device fingerprints
  • Password reset and account recovery requests

4.3 Commercial and transactional information

  • Products and services purchased, considered, or inquired about
  • Statements of work, proposals, contracts, change orders, and related correspondence
  • Purchase history, invoices, payment history, and account balances
  • Billing address and tax identification numbers where required
  • Payment card information, which is collected and processed by PCI-DSS-compliant payment processors; we retain only the last four digits, card brand, expiration date, and a processor-issued token
  • Bank account information for ACH or wire transactions, retained only as necessary to process payment and comply with financial recordkeeping laws

4.4 Internet and network activity information

  • Browser type and version, operating system, device type and model, screen resolution, language preference, and time zone
  • IP address and inferred approximate geographic location (city/region level)
  • Referring and exit pages and URLs, pages viewed, links clicked, time spent on pages, scroll depth, and navigation paths
  • Search terms entered on the Site
  • Date and time of visits and interactions
  • Crash reports, error logs, and diagnostic data
  • Interactions with emails we send (opens, clicks, and rendering data, where you have not disabled such tracking)
  • Information collected through cookies, pixels, tags, software development kits (SDKs), local storage, and similar technologies as described in Section 11

4.5 Geolocation information

  • Approximate geolocation derived from IP address
  • Precise geolocation only if you affirmatively enable location services for a specific Platform feature that requires it; we do not collect precise geolocation by default

4.6 Communications and content

  • The content of emails, chat messages, support tickets, form submissions, voicemails, and text messages you send to us
  • Notes and summaries of telephone calls, video meetings, and in-person meetings
  • Recordings and transcripts of calls or meetings, only where we have notified you and, where required, obtained your consent
  • Feedback, survey responses, testimonials, and reviews
  • Files, documents, images, and other content you upload to the Platform or send to us

4.7 Professional and employment-related information

  • Employer, job title, department, professional responsibilities, and decision-making authority (for business contacts)
  • Résumé/CV, cover letter, work history, education, certifications, references, portfolio, and interview notes (for job applicants; see Section 31)
  • Professional licenses and credentials where relevant to a service engagement

4.8 Inferences

  • Inferences we draw from the information above to understand your preferences, interests, and needs as a client or prospective client (for example, which service lines are relevant to your organization)

We do not draw inferences for the purpose of creating consumer profiles for targeted advertising.

4.9 Mobile Information

See Section 8. Mobile Information is subject to the strictest handling rules in this policy.

4.10 Information we do not collect by default

We do not intentionally collect, and ask that you not provide: Social Security numbers or other national identification numbers (except where legally required for tax reporting of vendors or contractors); driver’s license numbers; passport numbers; health or medical information; genetic information; biometric identifiers; information about racial or ethnic origin, religious or philosophical beliefs, sexual orientation, sex life, trade union membership, or immigration status; or precise geolocation. If you provide such information voluntarily (for example, in a free-text field), we will handle it as Sensitive Personal Information under Section 16 and delete it where it is not necessary for the purpose for which you provided it.

5. Sources of Personal Information

We collect personal information from the following sources:

5.1 Directly from you

When you fill out a form, create an account, enroll in MFA, opt in to the SMS Program, request a proposal, sign a contract, pay an invoice, contact support, attend a meeting, respond to a survey, apply for a job, or otherwise communicate with us.

5.2 Automatically from your device

When you visit the Site, use the Platform, open an email from us, or interact with our content, we and our Service Providers collect information automatically through server logs, cookies, and similar technologies (see Section 11).

5.3 From your organization

If you use our Services in your capacity as an employee or representative of a client, prospective client, or vendor, your organization may provide your business contact information and role to us.

5.4 From Service Providers acting on our behalf

For example, our hosting providers generate logs; our email delivery provider records delivery and engagement events; our payment processor confirms transaction status.

5.5 From publicly available sources and business information providers

We may supplement business contact records with information from public sources (for example, your company’s website, professional networking sites, corporate registries, press releases) and reputable business-to-business data providers, solely to verify business contact details and understand your organization. We do not purchase consumer marketing lists.

5.6 From referral partners and introductions

If someone refers you to us, we may receive your name, contact information, and the context of the referral.

5.7 From third-party platforms you choose to connect

If you connect a third-party account (for example, a cloud storage, code repository, analytics, or advertising account) to a Platform feature or engagement, we receive the information that platform makes available under the permissions you grant. You can revoke those permissions through the third-party platform at any time.

6. How We Use Personal Information

We use personal information for the purposes described below. Where a purpose is specific to a jurisdiction’s legal-basis requirements, see Section 7.

6.1 Providing and operating the Services

  • Creating, maintaining, authenticating, and securing your account
  • Sending MFA codes and account-security notifications by SMS, email, or in-app notification
  • Delivering the Professional Services you or your organization have engaged us to perform
  • Hosting, operating, maintaining, monitoring, and supporting the Platform and client deliverables
  • Processing transactions, issuing invoices, and collecting payment
  • Providing customer and technical support and responding to your inquiries
  • Managing projects, schedules, deliverables, and communications with you and your organization

6.2 Security, integrity, and fraud prevention

  • Detecting, investigating, preventing, and responding to security incidents, unauthorized access, fraud, abuse, spam, malware, and other malicious or illegal activity
  • Verifying identity and enforcing access controls
  • Maintaining audit logs required by our security program and by our contractual obligations to clients
  • Debugging and repairing errors that impair intended functionality

6.3 Communicating with you

  • Sending transactional and service messages, including confirmations, receipts, security alerts, scheduled maintenance notices, policy updates, and responses to your requests
  • Sending marketing communications about our services, thought leadership, events, and offerings where permitted by law and subject to your choices (Section 13)
  • Responding to feedback, questions, and complaints

6.4 Improving and developing the Services

  • Understanding how the Site and Platform are used, identifying usability issues, and improving design, content, and functionality
  • Performing analytics, research, and testing, using aggregated or de-identified data wherever feasible
  • Developing new features, products, and services

6.5 Business operations

  • Managing our relationships with clients, prospective clients, vendors, and partners
  • Conducting internal reporting, planning, forecasting, and quality assurance
  • Maintaining business records and complying with accounting, tax, and audit requirements
  • Protecting our rights, property, and safety and those of our clients, personnel, and the public
  • Enforcing our agreements and terms

6.6 Legal compliance

  • Complying with applicable laws, regulations, legal process, and governmental requests
  • Responding to privacy rights requests and maintaining the records required to demonstrate compliance
  • Meeting recordkeeping obligations under tax, corporate, employment, and financial laws

6.7 Recruiting

  • Evaluating job applications, conducting interviews, checking references, and making hiring decisions (Section 31)

6.8 With your consent

  • For any other purpose that we describe to you at the time of collection and for which you provide consent

6.9 Purpose limitation

We collect personal information only for the specified, explicit, and legitimate purposes described in this policy. We do not further process personal information in a manner incompatible with those purposes without notifying you and, where required, obtaining your consent. Our collection, use, and retention are reasonably necessary and proportionate to achieve the purposes for which the information was collected.

7. Legal Bases for Processing

If you are located in the European Economic Area (EEA), the United Kingdom (UK), Switzerland, or another jurisdiction that requires a legal basis for processing, we rely on the following bases:

  • Creating and managing your account; delivering contracted services; processing payments: Performance of a contract with you, or steps at your request before entering a contract
  • Sending MFA codes and security alerts: Performance of a contract and legitimate interests in securing our systems; where SMS is used, your consent to receive text messages
  • Security monitoring, fraud prevention, and incident response: Legitimate interests in protecting our systems, our clients, and the public; legal obligation where applicable
  • Analytics using essential or first-party data: Legitimate interests in understanding and improving the Services
  • Non-essential cookies and tracking technologies: Consent
  • Direct marketing by email: Consent, or legitimate interests in marketing to existing business customers where permitted by applicable e-privacy rules
  • Business-to-business relationship management: Legitimate interests in operating our business and maintaining client and vendor relationships
  • Recordkeeping, tax, and accounting: Legal obligation
  • Responding to legal process and government requests: Legal obligation and legitimate interests in protecting our rights
  • Recruiting: Steps prior to entering a contract (employment) and legitimate interests in evaluating candidates; consent where we retain your application for future openings
  • Processing sensitive data you voluntarily provide: Explicit consent

Where we rely on legitimate interests, we have conducted a balancing assessment to confirm that our interests are not overridden by your interests, rights, and freedoms. You may request a summary of that assessment and may object to processing based on legitimate interests (Section 27).

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8. SMS / Text Messaging and Mobile Information

This section governs all text messages we send and all Mobile Information we collect. It applies in addition to, and in the event of conflict prevails over, every other section of this policy.

8.1 Mobile Information is never shared with third parties or affiliates

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All categories of personal information described in this Privacy Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates.

To state this without qualification:

  • We do not sell Mobile Information or Opt-In Data.
  • We do not rent, lease, license, trade, or otherwise share Mobile Information or Opt-In Data with any third party.
  • We do not share Mobile Information or Opt-In Data with any affiliate, parent, subsidiary, investor, partner, or other related entity.
  • We do not share Mobile Information or Opt-In Data with our clients.
  • We do not use Mobile Information or Opt-In Data for advertising, lead generation, list building, or any purpose other than operating the SMS Program described in this section.
  • We do not disclose your mobile telephone number to anyone for the purpose of enabling them to send you text messages.
  • Your opt-in to the SMS Program is an opt-in to receive messages from Pidalia LLC only. It is not, and will never be treated as, consent to receive messages from anyone else.

The only exception is disclosure compelled by valid legal process as described in Section 36, and even then we disclose only what is legally required.

8.2 What the SMS Program is

We send text messages for the following purposes only:

  • Multi-factor authentication (MFA) and one-time passcodes (OTP): verification codes to confirm your identity when you sign in, change security settings, or perform sensitive account actions.
  • Account-security alerts: notifications of new-device logins, password changes, or suspicious activity.
  • Transactional and service messages you have requested: for example, a code you requested to verify your phone number.

We do not send marketing or promotional text messages. If we ever introduce a marketing text program in the future, it will be a separate program requiring separate, express written consent, and this policy will be updated before that program launches.

8.3 How you opt in

You opt in to the SMS Program by affirmatively taking one of the following actions:

  • Entering your mobile telephone number in an MFA enrollment screen in the Platform and confirming that you agree to receive verification codes by text message;
  • Checking an unchecked consent box next to a clear disclosure of the SMS Program terms; or
  • Replying to a verification message with the confirmation code or keyword requested.

Consent to receive text messages is not a condition of purchasing any goods or services from us. Where MFA is required for account security, you may choose an alternative MFA method (such as an authenticator app or email) that does not require text messaging, where such an alternative is offered.

8.4 Information we collect through the SMS Program

  • Your mobile telephone number
  • The date, time, method, and source (screen or form) of your opt-in
  • Your consent status (active, opted out) and the history of changes
  • Your mobile carrier (as reported by the messaging network)
  • Message logs: message content, timestamps, delivery status, and error codes
  • Any text message you send to us, including STOP, HELP, and other replies

8.5 How we use Mobile Information

We use Mobile Information solely to:

  • Send the messages described in Section 8.2;
  • Verify that you control the mobile number you provided;
  • Honor your opt-out and opt-in choices;
  • Respond to HELP requests;
  • Detect and prevent fraud, abuse, and unauthorized use of the SMS Program;
  • Troubleshoot delivery problems;
  • Maintain records demonstrating your consent as required by applicable law and industry rules; and
  • Comply with applicable law.

8.6 How to opt out

  • Reply STOP to any message from us to cancel. You will receive a single confirmation message and then no further messages unless you opt in again.
  • You may also opt out by updating your MFA settings in the Platform or by contacting us at the address in Section 39.
  • If SMS is your only enrolled MFA method, opting out may require you to enroll an alternative method before you can sign in again. We will explain this when you opt out.

Reply HELP to any message for assistance, or contact us as described in Section 39.

8.7 Message frequency, costs, and carriers

  • Message frequency varies based on your account activity (for example, one message per login attempt that requires verification).
  • Message and data rates may apply according to your plan with your mobile carrier.
  • Carriers are not liable for delayed or undelivered messages.
  • The SMS Program is available on major U.S. carriers. Availability on specific carriers may change without notice.

8.8 Retention of Mobile Information

  • Consent records (proof of opt-in, opt-out, and related timestamps) are retained for as long as your consent is active and for four (4) years after opt-out, to demonstrate compliance with the Telephone Consumer Protection Act and related requirements.
  • One-time passcodes are retained only until they expire or are used, and in no event longer than fifteen (15) minutes.
  • Message logs are retained for twelve (12) months for security, fraud-prevention, and troubleshooting purposes, then deleted or de-identified.

8.9 Full program terms

The complete SMS Program Terms and Conditions are set out in Appendix D and are incorporated into this policy.

9. How We Disclose Personal Information

Subject always to Section 8 (Mobile Information is excluded from every disclosure category below), we disclose personal information only as follows:

9.1 Service Providers and Processors

We disclose personal information to vendors that perform services on our behalf under written contracts that (a) limit their use of the information to the services they provide to us, (b) prohibit them from selling or sharing the information, (c) require them to protect the information with appropriate safeguards, and (d) require them to assist us in honoring your privacy rights. Categories of Service Providers include:

  • Cloud infrastructure and hosting providers
  • Messaging and email delivery providers
  • Payment processors and billing platforms
  • Customer relationship management (CRM) and support ticketing platforms
  • Analytics and performance-monitoring providers
  • Security, identity, and fraud-prevention providers
  • Document signature and contract management platforms
  • Accounting, tax, and bookkeeping providers
  • Professional advisors (attorneys, accountants, auditors, insurers)
  • Recruiting and applicant-tracking platforms

A current list of sub-processor categories is available on request (Section 34).

9.2 Clients (in our capacity as their Processor)

When we act as a processor for a client, personal information that belongs to the client is, by definition, accessible to that client. This is not a disclosure by us; it is the client’s own data. We do not disclose our own controller data (including Mobile Information) to clients.

9.3 Your organization

If you use the Services on behalf of an organization, that organization’s authorized administrators may access information about your use, such as your account status, activity logs, and the deliverables associated with the engagement.

9.4 Professional advisors

We disclose personal information to our attorneys, accountants, auditors, bankers, and insurers as necessary for them to provide professional services to us.

9.5 Legal, safety, and rights protection

We disclose personal information when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, regulation, subpoena, court order, or other legal process (Section 36);
  • Respond to a lawful request from a governmental or regulatory authority;
  • Enforce our agreements and policies;
  • Detect, prevent, or address fraud, security, or technical issues;
  • Protect the rights, property, or safety of Pidalia, our clients, our personnel, you, or the public; or
  • Establish, exercise, or defend legal claims.

9.6 Business transfers

See Section 35.

9.7 With your direction or consent

We disclose personal information to third parties when you direct us to do so or otherwise consent (for example, when you ask us to introduce you to a partner or share a deliverable with a vendor).

9.8 De-identified and aggregated information

We may disclose de-identified or aggregated information that cannot reasonably be used to identify you, for any purpose. We maintain and use de-identified data in de-identified form, take reasonable measures to prevent re-identification, publicly commit to not attempting to re-identify it, and contractually obligate recipients to do the same.

9.9 Disclosures in the preceding 12 months

In the twelve months preceding the Last Updated date, we disclosed the categories of personal information listed in Appendix A to the categories of Service Providers listed in Section 9.1 for business purposes. We did not sell or share personal information, and we did not disclose Mobile Information to any third party or affiliate.

10. We Do Not Sell or Share Personal Information

  • We do not sell personal information, and have not sold personal information in the preceding twelve months.
  • We do not share personal information for cross-context behavioral advertising, and have not done so in the preceding twelve months.
  • We do not sell or share the personal information of anyone under the age of 18, and we have no actual knowledge of doing so.
  • We do not process personal information for targeted advertising as defined by U.S. state privacy laws.
  • We do not sell, share, or process Mobile Information for any of these purposes under any circumstances.

Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” link. If our practices change, we will update this policy, provide the required notice and opt-out mechanism, and treat Global Privacy Control signals as opt-out requests (Section 12).

11. Cookies, Tracking Technologies, and Your Choices

11.1 What we use

We and our Service Providers use the following technologies on the Site and Platform:

  • Cookies: small text files stored by your browser. Session cookies expire when you close your browser; persistent cookies remain until they expire or you delete them.
  • Local storage and session storage: browser storage used for application state and preferences.
  • Pixels, web beacons, and tags: small code snippets or images that record that a page or email was viewed.
  • Server logs: records generated by our web servers of requests made to them.
  • SDKs: software libraries in our applications that collect diagnostic and usage data.

11.2 Categories of technologies and purposes

Strictly necessary. Required for the Site or Platform to function: authentication, session management, security, load balancing, consent recording, fraud prevention Examples: Session ID, CSRF token, MFA state, consent-preference cookie. Your choice: Cannot be disabled; legitimate interests / contract.

Functional. Remember your preferences and settings: language, time zone, display options Examples: Preference cookies, UI state. Your choice: Consent (where required) or legitimate interests.

Analytics / performance. Understand how visitors use the Site: pages viewed, time on page, errors, performance metrics. We configure analytics to minimize data collection (IP anonymization where available, no cross-site tracking) Examples: First-party analytics, performance monitoring, error tracking. Your choice: Consent (where required).

Advertising / targeting. Not used. We do not deploy third-party advertising cookies, retargeting pixels, or cross-site tracking technologies on the Site or Platform. Examples: None. Your choice: Not applicable.

A current inventory of the specific cookies we set is in Appendix C.

11.3 Your choices

  • Consent banner (where required): Visitors from jurisdictions that require consent for non-essential cookies will see a consent tool that lets you accept, reject, or customize non-essential categories. You can change your choice at any time through the “Cookie Settings” link in the Site footer.
  • Browser controls: Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent parts of the Site and Platform from working, including signing in.
  • Global Privacy Control: See Section 12.
  • Analytics opt-outs: Where we use a third-party analytics provider, we will identify it in Appendix C along with that provider’s opt-out mechanism.
  • Email tracking: You can disable image loading in your email client to prevent open-tracking pixels from loading.

11.4 Third-party cookies

We do not permit third parties to set cookies on the Site or Platform for their own purposes. Service Providers that set cookies on our behalf (for example, analytics) do so only under contracts that restrict their use of the resulting data.

12. Global Privacy Control and Do Not Track

12.1 Global Privacy Control (GPC)

We recognize the Global Privacy Control browser signal. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale and sharing of personal information and of targeted advertising, to the extent required by applicable law. Because we do not sell, share, or process for targeted advertising, honoring the signal does not change our data practices; we record the signal to demonstrate compliance. Where technically feasible, we will also treat a GPC signal as a decline of non-essential cookies.

If you are logged in to a Platform account, we will associate the GPC signal with your account so that it applies across devices where we can reasonably do so.

12.2 Do Not Track (DNT)

There is no industry consensus on how to interpret DNT signals. We do not currently respond to DNT signals. Because we do not engage in cross-site tracking, our practices are consistent with the intent of DNT regardless.

13. Email and Marketing Communications

13.1 Types of email we send

  • Transactional and service emails: account notices, security alerts, receipts, invoices, project communications, support responses, and legal notices. You cannot opt out of these while you have an account or an active engagement with us, because they are necessary to provide the Services.
  • Marketing emails: newsletters, thought leadership, event invitations, and information about our services. We send these only (a) with your consent, or (b) to existing business customers about similar services, where permitted by law.

13.2 How to opt out of marketing emails

  • Click the “unsubscribe” link at the bottom of any marketing email. We process unsubscribe requests within ten (10) business days as required by the CAN-SPAM Act, and typically immediately.
  • Email us at the address in Section 39.
  • Opting out of marketing emails does not opt you out of transactional or service emails.

13.3 CAN-SPAM compliance

All commercial emails we send include our valid physical postal address, accurate header and subject-line information, clear identification as an advertisement where applicable, and a functioning opt-out mechanism.

13.4 Email engagement tracking

Marketing emails may contain a pixel that tells us whether the email was opened and which links were clicked. We use this to measure the effectiveness of our communications and to comply with engagement-based sending requirements of mailbox providers. You can prevent open tracking by disabling image loading in your email client.

13.5 Referral and forwarding

If you use a “send to a colleague” or referral feature, we will send a one-time email to the address you provide and will not use that address for marketing unless the recipient separately opts in.

14. Telephone Communications

  • We may call you in connection with an existing or prospective business relationship. We do not make automated telemarketing calls or use prerecorded voice messages for marketing.
  • We may record telephone or video calls for training, quality, and record-keeping purposes. Where we do, we will notify you at the start of the call and, where required by law (including Massachusetts, which requires all-party consent), obtain your consent. You may decline to be recorded.
  • We honor the National Do Not Call Registry and maintain an internal do-not-call list. To be added, contact us as described in Section 39.

15. Artificial Intelligence and Automated Decision-Making

15.1 Our use of AI tools

We may use artificial intelligence and machine-learning tools, including large language models, in the course of our business, for example to draft documents, summarize meetings, analyze code, assist with customer support, and analyze usage data. When we do:

  • We use enterprise or API versions of AI services under contracts that prohibit the provider from training its models on our data or retaining our data beyond the processing session, or we use self-hosted models;
  • We do not input Mobile Information into third-party AI tools;
  • We do not input Sensitive Personal Information into third-party AI tools without your explicit consent;
  • We apply data-minimization practices, redacting or pseudonymizing personal information where feasible before it is processed by an AI tool;
  • AI-generated output that concerns you is reviewed by a human before it is used for any decision that affects you; and
  • Where we use AI tools to process client data in our capacity as processor, we do so only as permitted by the client’s instructions and our data processing agreement.

15.2 Automated decision-making and profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (for example, decisions about eligibility for services, credit, employment, housing, insurance, or education). Security systems may automatically flag or block activity that appears fraudulent or malicious; those determinations are reviewed by a human on request and you may contest them by contacting us.

If we begin to engage in automated decision-making that has legal or similarly significant effects, we will update this policy, provide the information required by applicable law about the logic involved, conduct any required risk assessment, and give you the right to opt out or to obtain human review, as applicable.

15.3 AI features in the Platform

If a Platform feature uses AI to process your information, we will disclose that in the feature’s interface, explain what the feature does, and, where required, obtain your consent before use.

16. Sensitive Personal Information

16.1 Definition

“Sensitive Personal Information” includes: government-issued identification numbers (Social Security, driver’s license, state ID, passport); account log-in credentials in combination with the means of accessing the account; financial account numbers and payment card numbers in combination with access credentials; precise geolocation; racial or ethnic origin; religious or philosophical beliefs; union membership; citizenship or immigration status; the contents of mail, email, or text messages where we are not the intended recipient; genetic data; biometric information processed to identify an individual; health information (including mental health, reproductive health, and disability status); information about sex life or sexual orientation; information about criminal convictions; and any personal information of a known child.

16.2 What we collect

We collect the following Sensitive Personal Information, only for the limited purposes stated:

  • Account log-in credentials: to authenticate you to the Platform. Passwords are hashed.
  • Payment card and bank account information: to process payments, via PCI-DSS-compliant processors.
  • Tax identification numbers: from vendors and contractors, solely for tax reporting.

We do not collect any other category of Sensitive Personal Information by design.

16.3 Limited use

We use Sensitive Personal Information only as necessary to perform the Services you request, to ensure security and integrity, to prevent fraud, to comply with law, and for other purposes permitted without a right to limit under applicable law. We do not use or disclose Sensitive Personal Information to infer characteristics about you. Accordingly, we do not offer a “Limit the Use of My Sensitive Personal Information” link; if our practices change, we will provide one.

16.4 Voluntarily provided sensitive information

If you voluntarily provide Sensitive Personal Information in a free-text field, attachment, or conversation, you consent to our processing of that information for the purpose for which you provided it. We will delete it once that purpose is fulfilled or on request.

17. Biometric Information

We do not collect, capture, purchase, receive, or otherwise obtain biometric identifiers or biometric information (such as fingerprints, facial geometry, voiceprints, retina or iris scans, or hand geometry) for the purpose of identifying you. If a Platform feature ever uses device-native biometrics (for example, a fingerprint or face unlock on your own device), the biometric data is processed by your device’s operating system and never transmitted to us; we receive only a success or failure signal. If we ever collect biometric information, we will first publish a written biometric policy with retention and destruction schedules and obtain your written consent as required by applicable law.

18. Data Retention

18.1 General principle

We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, contractual, or reporting requirements, to resolve disputes, and to enforce our agreements. When we no longer need personal information, we securely delete it, anonymize it, or, where deletion is not immediately practicable (for example, in backups), isolate it from further processing until deletion is possible.

18.2 Criteria we use

To determine retention periods we consider: the nature and sensitivity of the information; the purposes for which we process it; whether we can achieve those purposes through other means; the risk of harm from unauthorized use or disclosure; applicable statutes of limitations; and applicable legal, regulatory, tax, accounting, and industry requirements.

18.3 Retention schedule

A detailed retention schedule is in Appendix B.

18.4 Backups

Personal information may persist in encrypted backup media for up to ninety (90) days after deletion from production systems, after which the backups are overwritten or destroyed. Backup media is not used for any purpose other than disaster recovery, and information restored from backups is subject to deletion in accordance with this policy.

18.5 Legal holds

If we are subject to a litigation hold, regulatory inquiry, or legal obligation to preserve information, we will retain the relevant information until the hold is released, notwithstanding any other retention period.

19. Information Security

19.1 Our security program

We maintain a written information security program containing administrative, technical, and physical safeguards appropriate to the size and scope of our business, the nature of our business, the resources available to us, the amount of stored data, and the need for security and confidentiality of personal information. Our program is designed to comply with the Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth, 201 CMR 17.00, and with our contractual obligations to clients.

19.2 Safeguards

Our safeguards include, as appropriate:

  • Encryption of personal information in transit over public networks (TLS 1.2 or higher) and at rest;
  • Multi-factor authentication for all administrative access and, where offered, for user accounts;
  • Role-based access controls and least-privilege principles, with access reviewed periodically and revoked promptly upon role change or termination;
  • Secure software development practices, including code review, dependency scanning, and vulnerability management;
  • Logging and monitoring of access to systems containing personal information, with retention of audit logs;
  • Network security including firewalls, segmentation, and intrusion detection;
  • Endpoint protection and device management for personnel devices;
  • Vendor risk management, including security review and contractual security requirements for Service Providers;
  • Personnel security, including confidentiality obligations, security awareness training, and disciplinary measures for violations;
  • Business continuity and disaster recovery planning, including encrypted backups;
  • Incident response procedures (Section 20); and
  • Regular review of our security program at least annually and whenever there is a material change in our business practices that may affect the security of personal information.

19.3 Your responsibilities

You are responsible for keeping your account credentials confidential, enabling MFA where available, using strong and unique passwords, and notifying us promptly at the address in Section 39 if you suspect unauthorized access to your account.

19.4 No guarantee

No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.

20. Data Breach Notification

If we discover a security incident that results in the unauthorized acquisition or use of unencrypted personal information, or of encrypted personal information together with the means to decrypt it, we will:

  • Contain and investigate the incident;
  • Notify affected individuals without unreasonable delay and within the timeframes required by applicable law, including the Massachusetts data breach notification law (M.G.L. c. 93H) and the laws of other states or countries whose residents are affected;
  • Notify applicable regulators, including the Massachusetts Attorney General and Office of Consumer Affairs and Business Regulation, and, where required, supervisory authorities in the EEA or UK within seventy-two (72) hours of becoming aware of a personal data breach;
  • Where we act as a processor, notify the affected client without undue delay in accordance with our data processing agreement; and
  • Provide the information required by law, which may include a description of the incident, the categories of information involved, steps we have taken, steps you can take to protect yourself, and, where required, an offer of credit monitoring or identity-theft protection services.

We will never send you an unsolicited email or text message asking for your password, full payment card number, or Social Security number. If you receive such a message claiming to be from Pidalia, do not respond and report it to us.

21. International Data Transfers

21.1 Where we process information

We are headquartered in the United States. Personal information we collect is stored and processed primarily in the United States, and may be processed in other countries where our Service Providers operate. The data protection laws of those countries may differ from, and may be less protective than, the laws of the country in which you reside.

21.2 Transfers from the EEA, UK, and Switzerland

When we transfer personal information from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on one or more of the following mechanisms:

  • The EU Standard Contractual Clauses adopted by the European Commission, together with any required supplementary measures;
  • The UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
  • The Swiss adaptations of the EU Standard Contractual Clauses;
  • Your explicit consent to the transfer after being informed of the risks; or
  • Another lawful transfer mechanism, such as necessity for the performance of a contract with you.

We conduct transfer impact assessments where required. You may request a copy of the relevant transfer mechanism by contacting us (Section 39). We will redact commercial terms.

21.3 Data Privacy Framework

Pidalia LLC is not certified under the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, and relies on the mechanisms described in Section 21.2 for any such transfers.

21.4 Transfers from other jurisdictions

Where the law of another jurisdiction (for example, Canada, Brazil, Australia, Japan, or Singapore) imposes conditions on cross-border transfers, we comply with those conditions, which may include contractual safeguards, notice, or consent.

22. Children’s Privacy

The Services are designed for businesses and adults. We do not knowingly collect personal information from children under the age of thirteen (13), and we do not knowingly collect personal information from anyone under the age of eighteen (18) without the consent of a parent or guardian where such consent is required by law. We do not sell or share the personal information of anyone under the age of eighteen (18).

If you are a parent or guardian and believe that a child has provided us with personal information, contact us at the address in Section 39. If we learn that we have collected personal information from a child in violation of applicable law, we will delete it promptly. We comply with the Children’s Online Privacy Protection Act (COPPA) and applicable state laws concerning minors.

23. Your Privacy Rights

Depending on where you live and the nature of your relationship with us, you may have some or all of the following rights. We extend the core rights below to everyone whose personal information we hold as a controller, regardless of location, subject to applicable law and to the verification and exception procedures in Section 24.

23.1 Right to know / access

You may request that we disclose: the categories and specific pieces of personal information we have collected about you; the categories of sources; the business or commercial purposes for collecting, selling, or sharing it; the categories of third parties to whom we disclose it; and the categories of personal information disclosed for a business purpose. You may also request a copy of the personal information we hold about you.

23.2 Right to data portability

You may request a copy of the personal information you have provided to us in a portable, readily usable, structured, and commonly used machine-readable format, to the extent technically feasible.

23.3 Right to correction / rectification

You may request that we correct inaccurate or incomplete personal information we maintain about you.

23.4 Right to deletion / erasure

You may request that we delete personal information we have collected from you, subject to exceptions permitted by law (for example, where we need the information to complete a transaction, detect security incidents, comply with a legal obligation, or exercise or defend legal claims).

23.5 Right to opt out of sale, sharing, and targeted advertising

You may opt out of the sale of your personal information, the sharing of your personal information for cross-context behavioral advertising, and the processing of your personal information for targeted advertising. We do not engage in these activities, but we will honor and record your request.

23.6 Right to opt out of profiling

You may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in such profiling.

23.7 Right to limit use of sensitive personal information

You may limit our use of Sensitive Personal Information to purposes necessary to provide the Services. We already limit our use in this way.

23.8 Right to withdraw consent

Where we rely on your consent, you may withdraw it at any time. This includes consent to receive SMS messages (Section 8.6), marketing emails (Section 13.2), and non-essential cookies (Section 11.3).

23.9 Right to object and to restrict processing

Residents of the EEA, UK, and similar jurisdictions may object to processing based on legitimate interests (including direct marketing, which we will stop immediately on objection) and may request restriction of processing in certain circumstances.

23.10 Right to non-discrimination

We will not discriminate against you for exercising any of your privacy rights. We will not deny you services, charge different prices, provide a different level or quality of service, or suggest that you may receive different treatment because you exercised your rights. Because we do not offer financial incentives in exchange for personal information, no such incentive terms apply.

23.11 Right to appeal

If we decline to act on your request, you may appeal our decision (Section 24.6).

23.12 Right to lodge a complaint

You may lodge a complaint with a supervisory authority or regulator (Sections 25–29).

23.13 Right to information about automated decision-making

You may request meaningful information about the logic involved in any automated decision-making that has legal or similarly significant effects on you, and request human review. We do not currently engage in such decision-making (Section 15).

24. How to Exercise Your Rights

24.1 How to submit a request

You may submit a privacy rights request by any of the following methods:

  • Email: [email protected]
  • Mail: Pidalia LLC, Attn: Privacy, 101 Federal Street, Suite 1900, Boston, MA 02110

We operate exclusively online and interact with individuals primarily through electronic means; accordingly, we provide email and postal mail request channels rather than a toll-free telephone number, as permitted by applicable law.

Please include your name, the email address or phone number associated with your relationship with us, the right(s) you wish to exercise, and enough detail for us to locate your information.

24.2 Verification

To protect your information, we must verify your identity before fulfilling access, portability, correction, or deletion requests. We will match information you provide against information we already hold. Depending on the sensitivity of the request, we may ask you to confirm control of the email address or phone number on file, answer questions about your relationship with us, or provide additional documentation. We will use information provided for verification solely for that purpose and will delete it once verification is complete unless we are required to retain it. We will not require you to create an account to submit a request, though if you have an account we may ask you to submit the request while logged in.

If we cannot verify your identity to the degree of certainty required, we will tell you and explain why. Opt-out requests do not require verification, but we may ask for information necessary to complete the request.

24.3 Authorized agents

You may designate an authorized agent to submit requests on your behalf. We will require the agent to provide written, signed permission from you, and we may require you to verify your identity directly with us or to confirm that you gave the agent permission. An agent holding a valid power of attorney under applicable state law need not provide separate written permission.

24.4 Timing

We will confirm receipt of your request within ten (10) business days. We will respond substantively within forty-five (45) days of receipt (or thirty (30) days for EEA/UK residents). If we need more time, we will notify you of the reason and the extension period, which will not exceed an additional forty-five (45) days (or two additional months for EEA/UK residents where the request is complex).

24.5 Fees

We do not charge a fee to process or respond to a verifiable request unless it is manifestly unfounded, excessive, or repetitive. If we determine that a request warrants a fee, we will tell you why and provide a cost estimate before completing the request. You may make two free requests within any twelve-month period under applicable U.S. state law.

24.6 Appeals

If we decline to act on your request in whole or in part, we will explain why. You may appeal by replying to our response or emailing [email protected] with the subject line “Privacy Request Appeal” within thirty (30) days. A person not involved in the original decision will review the appeal and respond in writing within forty-five (45) days (or sixty (60) days where permitted), including a written explanation of the reasons. If your appeal is denied, we will provide you with a method to contact your state Attorney General or other applicable regulator to submit a complaint.

24.7 Records

We maintain records of privacy rights requests and our responses for at least twenty-four (24) months, as required by applicable law. These records are used only for compliance purposes.

24.8 Requests about client-controlled data

If your request concerns personal information we process on behalf of a client (Section 3.2), we will identify the client where we can and forward your request to them, or direct you to contact them.

25. United States State-Specific Disclosures

Residents of U.S. states with comprehensive consumer privacy laws, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and any state that enacts a similar law, have the rights described in Section 23, subject to the specific scope and exceptions of their state’s law. The following additional disclosures apply:

  • Categories of personal information collected and purposes: See Sections 4 and 6 and Appendix A.
  • Categories of personal information disclosed to third parties, and categories of third parties: See Section 9 and Appendix A. We do not disclose Mobile Information to any third party.
  • Sale, sharing, and targeted advertising: We do not engage in these activities (Section 10).
  • Sensitive data: We process only the Sensitive Personal Information listed in Section 16.2 and only for the purposes stated there. Where your state requires consent to process sensitive data, we obtain it.
  • Data protection assessments: We conduct and document data protection assessments for processing activities that present a heightened risk of harm, as required by applicable law, and will make them available to regulators on request.
  • De-identified data: See Section 9.8.
  • Appeals: See Section 24.6.
  • Universal opt-out signals: See Section 12.
  • Maryland residents: We do not sell Sensitive Personal Information, and we do not process the personal information of consumers we know to be under eighteen (18) for targeted advertising or sale.
  • Minnesota residents: You may request a list of the specific third parties to which we have disclosed your personal information. Because we disclose personal information only to Service Providers and not to third parties, that list is empty; we will confirm this in writing on request. You may also question the result of any profiling in furtherance of a decision that produces legal or similarly significant effects; we do not engage in such profiling.
  • Oregon residents: You may request a list of the specific third parties (not just categories) to which we have disclosed personal information. Because we disclose only to Service Providers, we will confirm in writing that no such third parties exist.
  • Texas residents: We do not sell personal information. We do not engage in targeted advertising.
  • Nevada residents: We do not sell “covered information” as defined by Nevada law. You may nevertheless submit an opt-out request, which we will record.
  • Massachusetts residents: In addition to the security program described in Section 19, you have the rights described in Section 20 regarding breach notification and may contact the Massachusetts Office of Consumer Affairs and Business Regulation or the Attorney General with concerns.
  • Washington, Nevada, and Connecticut consumer health data: We do not collect consumer health data as defined by the Washington My Health My Data Act, Nevada SB 370, or Connecticut’s health data provisions. If you believe we have inadvertently collected such data, contact us and we will delete it.

To lodge a complaint with your state regulator, contact your state Attorney General’s office. Contact information for each state Attorney General is available at https://www.naag.org.

26. California Privacy Rights (CCPA/CPRA)

This section supplements the rest of this policy for California residents, as required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”) and its regulations.

26.1 Notice at collection

We collect the categories of personal information listed in Appendix A for the purposes described in Section 6. We do not sell or share personal information. We retain each category for the periods described in Appendix B.

26.2 Your CCPA rights

You have the right to know, to delete, to correct, to opt out of sale/sharing, to limit use of sensitive personal information, and to non-discrimination, each as described in Section 23. Because we do not sell or share personal information and do not use Sensitive Personal Information for purposes that trigger the right to limit, we do not post the “Do Not Sell or Share” or “Limit the Use” links. We nevertheless honor opt-out requests and GPC signals.

26.3 Categories sold or shared in the preceding 12 months

None.

26.4 Categories disclosed for a business purpose in the preceding 12 months

See Section 9.9 and Appendix A.

26.5 Minors

We have no actual knowledge that we sell or share the personal information of consumers under sixteen (16) years of age.

26.6 Financial incentives

We do not offer financial incentives or price or service differences in exchange for the retention, sale, or sharing of personal information.

26.7 Verification and agents

See Sections 24.2 and 24.3.

26.8 “Shine the Light”

California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

26.9 Removal of content by minors

California residents under eighteen (18) who are registered users may request removal of content they posted. We do not offer public posting features; if you believe such content exists, contact us.

26.10 Contact for California-specific questions

Use any method in Section 24.1. You may also contact the California Privacy Protection Agency at https://cppa.ca.gov or the California Attorney General at https://oag.ca.gov/privacy.

27. Notice to Residents of the EEA, UK, and Switzerland

27.1 Controller

Pidalia LLC, at the address in Section 1.1, is the controller of personal information described in Section 3.1.

27.2 Representative

We do not offer services targeted at, or monitor the behavior of, individuals in the EEA, UK, or Switzerland, and therefore have not appointed a representative under Article 27 GDPR or UK GDPR. Section 27 is provided for completeness in the event that residents of those jurisdictions interact with us incidentally.

27.3 Data Protection Officer

We are not required to appoint a Data Protection Officer. Privacy inquiries should be directed to [email protected].

27.4 Legal bases

See Section 7.

27.5 Your rights

You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and rights related to automated decision-making, as described in Section 23. We will respond within one month, extendable by two further months for complex requests.

27.6 Right to object to direct marketing

You may object at any time to processing for direct marketing, and we will stop immediately.

27.7 Complaints

You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement. A list of EEA authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en. The UK authority is the Information Commissioner’s Office (https://ico.org.uk). The Swiss authority is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch).

27.8 International transfers

See Section 21.

27.9 Obligation to provide data

Providing personal information is generally voluntary; however, we cannot provide certain Services, including creating an account, without the information necessary to do so. Where information is required by contract or law, we will indicate this at the point of collection.

28. Notice to Canadian Residents

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including Quebec’s Law 25. Your personal information may be transferred to and processed in the United States and other countries, where it may be subject to access by courts, law enforcement, and national security authorities under the laws of those countries. You have the right to access and correct your personal information, to withdraw consent subject to legal and contractual restrictions, and to lodge a complaint with the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or the applicable provincial commissioner. Quebec residents may also request information about the categories of persons with access to their information within our organization and about any automated decision-making. Our Privacy Officer can be reached at [email protected].

We comply with Canada’s Anti-Spam Legislation (CASL) and send commercial electronic messages to Canadian recipients only with express or implied consent as defined by CASL.

29. Notice to Residents of Other Jurisdictions

If you reside in a jurisdiction not specifically addressed above (for example, Brazil, Australia, Japan, Singapore, South Korea, India, or South Africa), you have the rights afforded by your local law, which generally include rights of access, correction, deletion, and complaint to your local data protection authority. We will honor those rights in accordance with applicable law. Contact us using the methods in Section 24.1.

30. Business Contacts, Client Personnel, and Prospective Clients

If you interact with us as a representative of a client, prospective client, vendor, or partner:

  • We collect your business contact information (name, title, employer, business email, business phone, business address) and the content of our communications with you;
  • We use it to manage the relationship between Pidalia and your organization, to perform contracts, to send relevant business communications, and to comply with law;
  • We may retain it for the duration of the relationship and for a reasonable period thereafter, as set out in Appendix B;
  • Business-to-business marketing communications are sent in compliance with applicable law and you can opt out at any time; and
  • Where your local law exempts business contact information from certain requirements, we nevertheless apply the protections in this policy.

31. Job Applicants

If you apply for a position with us:

  • We collect the information in your application materials, information from interviews and assessments, reference information, and, where permitted and relevant to the role, background check information obtained with your separate written consent under the Fair Credit Reporting Act and applicable state law;
  • We use it to evaluate your application, communicate with you, make hiring decisions, comply with legal obligations (including equal-opportunity reporting), and, with your consent, consider you for future roles;
  • We do not use fully automated tools to reject candidates; any AI-assisted screening is subject to human review, and where required by law (for example, New York City Local Law 144 or Illinois law), we will provide notice and any required bias audit information;
  • We retain application materials for unsuccessful candidates for two (2) years after the decision, or longer where required by law or where you consent to be considered for future roles; and
  • Successful candidates’ information becomes part of their personnel file and is governed by our internal employee privacy notice.

32. Third-Party Websites, Links, and Integrations

The Site and Platform may contain links to, or integrations with, third-party websites, applications, and services that we do not control. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policy of any third party before providing information to it. A link or integration does not imply our endorsement.

Where a Platform feature integrates with a third-party service at your request (for example, connecting a cloud account), the third party’s privacy policy governs its processing of your information, and you can revoke the integration through that third party.

33. Social Media

We maintain profiles on social media platforms. When you interact with those profiles, the platform operator collects information under its own privacy policy, and we may receive aggregated insights and any information you choose to make available to us (for example, public comments or direct messages). We do not use social media plug-ins on the Site that transmit your browsing data to social media platforms; any social media icons on the Site are simple links.

34. Sub-Processors and Service Providers

We maintain a list of the categories of sub-processors and Service Providers that process personal information on our behalf, including the category of service, the location of processing, and the safeguards in place. Clients for whom we act as processor receive the full list under their data processing agreement and are notified of changes in accordance with that agreement. Other individuals may request the list of categories by contacting us (Section 39).

Every Service Provider is bound by a written contract that:

  • Specifies the limited and specified purposes for which the information is disclosed;
  • Prohibits selling or sharing the information;
  • Prohibits retaining, using, or disclosing the information for any purpose other than the specified purposes, or outside the direct business relationship with us;
  • Prohibits combining the information with information from other sources except as permitted by law;
  • Requires compliance with applicable privacy law and provision of the same level of privacy protection required of us;
  • Grants us the right to take reasonable steps to ensure compliant use;
  • Requires notification if the Service Provider can no longer meet its obligations;
  • Grants us the right to stop and remediate unauthorized use; and
  • Requires the Service Provider to flow down equivalent obligations to any sub-processor.

Mobile Information is not disclosed to any Service Provider for any purpose other than the transmission of the specific messages described in Section 8.2, and no Service Provider may retain, use, or disclose it for any other purpose.

35. Business Transfers

If Pidalia is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, dissolution, or sale of all or a portion of its assets or equity, personal information may be disclosed to the counterparty and its advisors during due diligence (under confidentiality obligations) and transferred to the successor entity as part of the transaction. Any successor will be bound by this policy with respect to previously collected personal information, or will provide notice and, where required, obtain consent before using the information in a materially different way.

Mobile Information and Opt-In Data will not be transferred to any successor for any purpose other than continuing to operate the SMS Program under terms no less protective than this Section 8, and only if the successor operates the same account-security functionality for which you opted in. If those conditions are not met, Mobile Information will be deleted rather than transferred.

36. Legal Requests and Government Access

We disclose personal information in response to legal process only when we believe in good faith that we are legally required to do so. Our practices are:

  • We require valid legal process (subpoena, court order, warrant, or the equivalent) before disclosing personal information to law enforcement or government authorities, except in emergencies involving imminent risk of death or serious physical injury where we may disclose limited information to prevent that harm;
  • We review each request for legal sufficiency, scope, and proper jurisdiction, and we narrow or challenge overbroad requests;
  • We disclose only the information specifically required;
  • Where permitted by law and where doing so would not endanger anyone, we notify affected individuals or clients before disclosure so they may seek protective relief;
  • Where we act as processor, we redirect requests to the client where possible and notify the client unless legally prohibited; and
  • We maintain records of requests received and our responses.

37. Accessibility

We are committed to making this policy accessible. If you have difficulty accessing this policy or need it in an alternative format (for example, large print or a screen-reader-compatible document), contact us using the methods in Section 39 and we will provide it.

38. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do:

  • We will post the updated policy on the Site with a new “Last Updated” date and, where the changes are material, a summary of the changes;
  • We will review and update this policy at least once every twelve (12) months;
  • If changes materially reduce your rights or materially expand our use or disclosure of previously collected personal information, we will provide prominent notice (for example, by email to registered users or a banner on the Site) at least thirty (30) days before the changes take effect and, where required by law, obtain your consent; and
  • Any change to Section 8 that would permit sharing of Mobile Information with third parties or affiliates will never be applied retroactively to previously collected Mobile Information; such information will be governed by the version of this policy in effect when you opted in unless you affirmatively re-consent.

Prior versions of this policy are available on request.

39. How to Contact Us

If you have questions, concerns, or complaints about this policy or our privacy practices, or wish to exercise your rights, contact us:

Pidalia LLC Attn: Privacy 101 Federal Street, Suite 1900 Boston, Massachusetts 02110 United States

Email: [email protected] SMS Program help: Reply HELP to any message, or email [email protected]

We will acknowledge your inquiry within ten (10) business days and aim to resolve it promptly. If you are not satisfied with our response, you may lodge a complaint with the regulator identified in the jurisdiction-specific sections above.

Appendix A: Categories of Personal Information (Statutory Categories)

  1. Identifiers
  • Examples: Name, postal address, email, phone, IP address, account ID, cookie ID
  • Collected: Yes
  • Sources: You; your device; your organization; Service Providers; public sources
  • Purposes: see Section(s) 6.1–6.7
  • Disclosed for a business purpose to: Hosting, messaging, email, CRM, support, security, payment, analytics, advisors
  • Sold or shared: No
  1. Customer records (Cal. Civ. Code §1798.80(e))
  • Examples: Name, address, phone, payment card (tokenized), bank account
  • Collected: Yes
  • Sources: You; payment processor
  • Purposes: see Section(s) 6.1, 6.5, 6.6
  • Disclosed for a business purpose to: Payment processors, accounting, advisors
  • Sold or shared: No
  1. Protected classifications
  • Examples: Age, race, religion, disability, etc.
  • Collected: No (unless voluntarily provided, or for legally required EEO recruiting reports)
  • Sources: You
  • Purposes: see Section(s) 6.6, 6.7
  • Disclosed for a business purpose to: Recruiting platforms; regulators where required
  • Sold or shared: No
  1. Commercial information
  • Examples: Services purchased, contracts, invoices, payment history
  • Collected: Yes
  • Sources: You; your organization; our records
  • Purposes: see Section(s) 6.1, 6.5, 6.6
  • Disclosed for a business purpose to: Payment, accounting, CRM, advisors
  • Sold or shared: No
  1. Biometric information
  • Examples: Fingerprints, faceprints, voiceprints
  • Collected: No
  • Sources: —
  • Purposes: see Section(s) —
  • Disclosed for a business purpose to: —
  • Sold or shared: No
  1. Internet or network activity
  • Examples: Browsing history on the Site, interactions, device info, logs
  • Collected: Yes
  • Sources: Your device; Service Providers
  • Purposes: see Section(s) 6.1, 6.2, 6.4
  • Disclosed for a business purpose to: Hosting, analytics, security
  • Sold or shared: No
  1. Geolocation
  • Examples: Approximate location from IP
  • Collected: Yes (approximate only)
  • Sources: Your device
  • Purposes: see Section(s) 6.2, 6.4
  • Disclosed for a business purpose to: Hosting, security, analytics
  • Sold or shared: No
  1. Sensory data
  • Examples: Call and meeting recordings
  • Collected: Yes (with notice/consent)
  • Sources: You
  • Purposes: see Section(s) 6.1, 6.3, 6.5
  • Disclosed for a business purpose to: Meeting/recording platforms
  • Sold or shared: No
  1. Professional or employment information
  • Examples: Employer, title, résumé, references
  • Collected: Yes
  • Sources: You; your organization; references; public sources
  • Purposes: see Section(s) 6.1, 6.5, 6.7
  • Disclosed for a business purpose to: CRM, recruiting platforms, advisors
  • Sold or shared: No
  1. Non-public education information
  • Examples: Transcripts, student records
  • Collected: No (except education history on résumés)
  • Sources: You
  • Purposes: see Section(s) 6.7
  • Disclosed for a business purpose to: Recruiting platforms
  • Sold or shared: No
  1. Inferences
  • Examples: Preferences and needs as a client
  • Collected: Yes (limited)
  • Sources: Our analysis of A, D, F, I
  • Purposes: see Section(s) 6.4, 6.5
  • Disclosed for a business purpose to: CRM
  • Sold or shared: No
  1. Sensitive personal information
  • Examples: Log-in credentials; payment/bank account with credentials; tax ID
  • Collected: Yes (limited, per Section 16)
  • Sources: You
  • Purposes: see Section(s) 6.1, 6.2, 6.6
  • Disclosed for a business purpose to: Hosting, payment, accounting, security
  • Sold or shared: No
  1. Mobile Information / Opt-In Data
  • Examples: Mobile number, opt-in records, consent status, message logs
  • Collected: Yes
  • Sources: You; messaging network
  • Purposes: see Section(s) 8.5 only
  • Disclosed for a business purpose to: None. Never disclosed to any third party or affiliate.
  • Sold or shared: No — never.

Appendix B: Retention Schedule

  • Account information (active accounts): Duration of account. (Service delivery.)
  • Account information (closed accounts): 12 months after closure, then deleted; financial records retained per below. (Reactivation, wind-down, dispute resolution.)
  • Authentication and security logs: 12 months. (Security, incident investigation, contractual audit requirements.)
  • One-time passcodes: Until used or expired; max 15 minutes. (Verification only.)
  • SMS consent records (opt-in/opt-out): Duration of consent + 4 years. (TCPA statute of limitations; proof of consent.)
  • SMS message logs: 12 months. (Delivery troubleshooting, fraud prevention.)
  • Contracts, SOWs, and related correspondence: Term + 7 years. (Contract statute of limitations; audit.)
  • Invoices, payment records, tax records: 7 years. (Tax and accounting law.)
  • Payment card tokens: Until account closure or card update. (Payment processing.)
  • Support tickets and communications: 3 years after resolution. (Service quality, dispute resolution.)
  • Marketing consent and suppression lists: Suppression records retained indefinitely (to honor opt-outs); consent records for 3 years after last contact. (Legal compliance.)
  • Website analytics (identifiable): 14 months, then aggregated. (Service improvement.)
  • Website server logs: 90 days. (Security.)
  • Cookie consent records: 12 months, or until preference changed. (Proof of consent.)
  • Call/meeting recordings: 12 months unless part of a deliverable or dispute. (Training, record-keeping.)
  • Business contact records: Duration of relationship + 3 years after last meaningful contact. (Relationship management.)
  • Job applicant records (unsuccessful): 2 years after decision. (Anti-discrimination law; future roles with consent.)
  • Privacy rights request records: 24 months minimum. (Regulatory compliance.)
  • Data protection assessments: Duration of processing + 3 years. (Regulatory compliance.)
  • Encrypted backups: Rolling 90 days. (Disaster recovery.)
  • Information under legal hold: Until hold released. (Legal obligation.)

Appendix C: Cookie Inventory

  • session cookie (Pidalia (first-party); Strictly necessary): Maintains your authenticated session in the Platform. Duration: Session. Type: HTTP cookie.
  • CSRF token (Pidalia (first-party); Strictly necessary): Protects against cross-site request forgery. Duration: Session. Type: HTTP cookie.
  • cookie_consent (Pidalia (first-party); Strictly necessary): Records your cookie preferences. Duration: 12 months. Type: HTTP cookie.
  • **_ga** (Google Analytics; Analytics): Distinguishes unique visitors for aggregate usage statistics. Duration: 2 years. Type: HTTP cookie.
  • ga (Google Analytics; Analytics): Maintains session state for Google Analytics 4. Duration: 2 years. Type: HTTP cookie.
  • (none) (Cloudflare Web Analytics; Analytics): Privacy-first page-performance measurement; sets no cookies and collects no personal information. Duration: N/A. Type: Script beacon.

Google Analytics is loaded directly on the Site. We do not use Google Signals, advertising features, remarketing, or Google Ads conversion tracking, and we do not link Google Analytics to any advertising account. Data-sharing settings with Google are set to the minimum required for the service to operate. Google’s privacy policy is at https://policies.google.com/privacy. You can prevent Google Analytics from collecting your data by installing the Google Analytics opt-out browser add-on at https://tools.google.com/dlpage/gaoptout, or by declining analytics cookies in our consent tool. Cloudflare Web Analytics does not use cookies or track individuals; see https://www.cloudflare.com/privacypolicy/.

Appendix D: SMS Program Terms and Conditions

Program name: Pidalia Secure Product Dashboard Access Program sponsor: Pidalia LLC, 101 Federal Street, Suite 1900, Boston, MA 02110

  1. Program description. By opting in, you agree to receive text messages from Pidalia LLC containing one-time verification codes, multi-factor authentication codes, and account-security alerts related to your access to the Pidalia Secure Product Dashboard. This program does not send marketing or promotional messages.
  2. You consent to receive these messages at the mobile number you provided. Consent is not a condition of purchase. You represent that you are the account holder or authorized user of the mobile number provided and are at least eighteen (18) years old.
  3. Message frequency. Message frequency varies and depends on your account activity. For example, you will typically receive one message per sign-in or sensitive action that requires verification.
  4. Message and data rates may apply. Contact your wireless carrier for details about your plan.
  5. Opt out. Text STOP to any message to cancel at any time. You will receive one final confirmation message. After that, you will not receive further messages unless you opt in again. You may also opt out through your account settings or by contacting us at [email protected].
  6. Text HELP to any message for assistance, or contact [email protected].
  7. Supported carriers include major U.S. carriers. Carriers are not liable for delayed or undelivered messages.
  8. Your Mobile Information is governed by Section 8 of the Pidalia Privacy Policy, available at https://pidalia.com/privacy. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties or affiliates.
  9. We may modify or terminate the program at any time. Material changes will be communicated in accordance with the Privacy Policy.
  10. Governing law. These terms are governed by the laws of the Commonwealth of Massachusetts, without regard to conflict-of-law principles.

Appendix E: Glossary

  • 10DLC: 10-digit long code, the type of standard telephone number used to send application-to-person text messages in the United States, subject to carrier registration requirements.
  • Aggregated information: Information about a group of individuals from which individual identities have been removed and that is not linked or reasonably linkable to any individual.
  • CAN-SPAM Act: The U.S. federal law governing commercial email.
  • CASL: Canada’s Anti-Spam Legislation.
  • CCPA/CPRA: The California Consumer Privacy Act, as amended by the California Privacy Rights Act.
  • COPPA: The U.S. Children’s Online Privacy Protection Act.
  • Cross-context behavioral advertising: Targeting advertising to a consumer based on personal information obtained from the consumer’s activity across businesses, distinctly branded websites, applications, or services other than the one with which the consumer intentionally interacts.
  • De-identified information: Information that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, provided the holder takes reasonable measures to prevent re-identification, publicly commits not to re-identify, and contractually obligates recipients to do the same.
  • GDPR / UK GDPR: The EU General Data Protection Regulation and its UK counterpart.
  • GPC: Global Privacy Control, a browser-based signal that communicates a user’s opt-out preference.
  • MFA: Multi-factor authentication.
  • OTP: One-time passcode.
  • PCI-DSS: Payment Card Industry Data Security Standard.
  • PIPEDA: Canada’s Personal Information Protection and Electronic Documents Act.
  • Profiling: Any form of automated processing of personal information to evaluate, analyze, or predict personal aspects concerning an individual.
  • Pseudonymization: Processing personal information so that it can no longer be attributed to a specific individual without the use of additional information kept separately and subject to safeguards.
  • TCPA: The U.S. Telephone Consumer Protection Act, which governs calls and text messages to mobile numbers.
  • Targeted advertising: Displaying advertisements to a consumer where the advertisement is selected based on personal information obtained from that consumer’s activities over time and across nonaffiliated websites or online applications to predict the consumer’s preferences or interests.

© 2026 Pidalia LLC. All rights reserved.


hire us

we can do anything, baby