Draft for legal review. This document is a starting point written for Responder's counsel to review and complete. It is not in effect and must not be published as-is. Bracketed items need decisions.
Privacy Policy
Last updated [date]
How [Responder legal entity] handles personal information about the people who use Responder and visit this site. Proposal content and other Customer Data is governed by our Terms of Service and the customer's instructions.
1. What we collect
- Account details: name, work email, organization, role.
- Sign-in and security data: multi-factor enrollment, sign-in times, IP address, and an audit log of actions in your organization.
- Billing details: billing contact, plan and usage counts. Card and bank details are collected and held by Stripe, not by us.
- Content you or your organization upload, which may contain personal information (for example resumes of key personnel).
2. How we use it
- To provide, secure and support the service.
- To bill for subscriptions and usage.
- To send service notices and the notifications you choose.
- We don't sell personal information, use it for advertising, or use customer content to train AI models.
3. Where it's processed, and who helps
Customer Data is stored and processed in AWS US regions. AI features use Anthropic's Claude through Amazon Bedrock in US regions; Bedrock doesn't store prompts or use them for training.
Subprocessors:
- Amazon Web Services (US regions): hosting, storage, email (SES).
- Stripe: payments. Receives only billing contact, organization name, plan and usage counts; never proposal content.
- [Any others, e.g. support tooling.]
4. Retention
Account and audit records are kept while the organization is a customer and for [N years] after, for security and legal obligations. Customer content is deleted as described in the Terms after a subscription ends.
5. Your choices and rights
You can update your profile and notification preferences in the app. To access, correct or delete personal information, contact your organization's admin or us at [privacy@…]. [State-law disclosures (e.g. CCPA) as applicable.]
6. Security
See our Security page for how we protect data: encryption with per-organization keys, multi-factor authentication, role- and team-based access, and audit logging.
7. Contact
[Legal entity, address, privacy@… ]