NETRIDIUM PRIVACY POLICY
Last updated: August 16, 2026
This Privacy Policy explains how Netridium, LLC, a Michigan limited liability company ("Netridium," "we," "us," "our"), collects, uses, and discloses personal information in connection with our website, our multi-tenant software-as-a-service platform, and related services (together, the "Service").
1. SCOPE — AND AN IMPORTANT DISTINCTION
Netridium handles personal information in two very different roles, and this Policy covers only the first:
-
Information we control (covered by this Policy). Personal information we collect and use for our own purposes — for example, to register and manage accounts, bill customers, operate and secure the Service, run our website, and communicate with you. For this information, Netridium is the controller (or business).
-
Customer Data we process on our customers' behalf (NOT covered by this Policy). When a customer connects its systems and runs prompts, scripts, and agents, the Service reads, processes, stores, and — where the customer enables it — writes data, which may include personal information about the customer's own employees, clients, contacts, vendors, and account holders. For that data, Netridium acts as a processor (or service provider) on the customer's documented instructions. That processing is governed by our Data Processing Addendum ("DPA") and the customer's own privacy notices, not by this Policy. If you are an individual whose data appears in a customer's connected systems and you have questions or want to exercise your rights, please contact that customer (the organization that controls your data); we will refer such requests to the relevant customer.
2. INFORMATION WE COLLECT
2.1 Information you provide. - Account and profile information — name, business email address, username, job title or role, organization name, and authentication information when you register, are invited as a User, or sign in (including via single sign-on). - Billing and transaction information — billing contact details, plan and subscription selections, and records of purchases, credits, and usage. Payment card processing is handled by our billing provider; we do not store full payment card numbers. - Communications and support — information you provide when you contact us, request support, respond to a survey, or otherwise correspond with us.
2.2 Information we collect automatically. - Usage and telemetry — technical and operational data about how the Service is configured and used, such as feature usage, run and job metadata, log and diagnostic data, performance metrics, and error reports. This helps us operate, secure, and improve the Service. (Where this reflects a customer's use, we handle it consistently with the DPA.) - Device and connection data — IP address, browser and device type, operating system, and similar identifiers. - Cookies and similar technologies — see Section 6.
2.3 Information from third parties. - Identity and sign-in providers — where you authenticate through single sign-on or an identity provider, we receive the account identifiers and directory attributes that provider shares. - Service providers — our infrastructure, email, and billing providers may share operational information (such as delivery, payment, or security signals) needed to run the Service.
We do not intentionally collect special categories of personal data (such as health, biometric, or government identification data) about our own account holders through this Service, and we ask that customers not submit such data except as expressly agreed (see the DPA and Section 11.4 of the Terms of Service).
3. HOW WE USE INFORMATION
We use the personal information described above to: - provide, operate, maintain, and secure the Service, and provision and manage accounts and Users; - authenticate Users and enforce role-based access, tenant isolation, and usage and cost controls; - process subscriptions, credits, and payments, and manage billing; - provide support, respond to inquiries, and send service, security, and administrative communications; - monitor, analyze, and improve the Service, develop new features, and troubleshoot; - send product updates and marketing communications where permitted (you can opt out at any time); - detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms; and - comply with legal obligations and enforce our agreements.
4. LEGAL BASES (EEA / UK / SWITZERLAND)
Where the GDPR, UK GDPR, or Swiss FADP applies, we rely on the following legal bases: - Performance of a contract — to provide the Service to you or the organization you represent and to manage the account relationship. - Legitimate interests — to operate, secure, analyze, and improve the Service, to communicate with our business customers, and to prevent fraud and abuse, where those interests are not overridden by your rights. - Consent — for certain marketing communications and non-essential cookies, where required; you may withdraw consent at any time. - Legal obligation — to comply with applicable law, tax, and accounting requirements.
5. HOW WE SHARE INFORMATION
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We disclose personal information only as follows:
- Service providers / subprocessors — vendors that host, operate, secure, communicate, or bill on our behalf, under contracts that limit their use of the information to providing services to us. Our current subprocessors include our database and application hosting, email delivery, billing, and AI model providers (see our Subprocessor List and the DPA subprocessor annex for the operative list as it applies to Customer Data).
- Within your organization — account administrators and other authorized Users in your organization may see account, usage, and billing information consistent with their roles.
- Legal and safety — where required by law or valid legal process, or to protect the rights, property, or safety of Netridium, our customers, or others.
- Business transfers — in connection with a merger, reorganization, financing, conversion to a corporation, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy.
6. COOKIES AND ANALYTICS
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. Strictly necessary cookies are required for the Service to function. We may also use limited analytics to measure and improve performance. You can control cookies through your browser settings; disabling some cookies may affect functionality. Where required by law, we will present a cookie choice mechanism.
7. DATA RETENTION
We retain personal information for as long as needed to provide the Service, maintain your account, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Account and billing records are generally retained for the life of the account and for a reasonable period afterward. Customer Data processed on a customer's behalf is retained and deleted in accordance with the DPA and Section 9.6 of the Terms of Service. Backup copies persist for our routine, non-targeted backup cycles.
8. SECURITY
We maintain a written information security program with administrative, technical, physical, and organizational safeguards appropriate to the nature of the information, including multi-tenant isolation, encryption of data in transit and at rest, encrypted storage of credentials, role-based access control, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for enabling available security controls, including multi-factor authentication where offered.
9. YOUR PRIVACY RIGHTS
Depending on where you live and the role in which we hold your information, you may have some or all of the following rights. If your information is part of a customer's connected data (Section 1), please direct your request to that customer; for information we control, contact us as described in Section 13.
9.1 EEA / UK / Switzerland. You may request access to, correction of, deletion of, or restriction of your personal information; object to certain processing; request portability; and lodge a complaint with your Supervisory Authority. Where processing is based on consent, you may withdraw it at any time.
9.2 California (CCPA/CPRA). California residents may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; request deletion; request correction; and are entitled to non-discrimination for exercising these rights. Because we do not sell or share personal information (as defined by the CCPA/CPRA), no opt-out of sale/sharing is required, but you may still exercise the rights above. The categories of personal information we collect are described in Section 2; the purposes in Section 3; and the categories of recipients in Section 5.
9.3 Other U.S. states. Residents of states with comprehensive privacy laws may have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling — none of which we engage in with respect to the personal information we control.
9.4 How we handle requests. We will verify your request as required by law and respond within the timeframes the applicable law provides. You may use an authorized agent where the law permits.
10. INTERNATIONAL TRANSFERS
We are based in the United States and use service providers located in the United States and potentially elsewhere. Where we transfer personal information across borders in a way that requires a safeguard under applicable law, we rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses. For Customer Data, transfer mechanisms are addressed in the DPA.
11. CHILDREN
The Service is intended for business use by individuals who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, please contact us and we will take appropriate steps to delete it.
12. CHANGES TO THIS POLICY
We may update this Policy from time to time. We will post the updated version with a revised "Last updated" date and, where a change materially affects your rights, provide additional notice as required by law or the Terms of Service. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
13. CONTACT US
For questions about this Policy or to exercise your rights regarding information we control, contact:
Netridium, LLC Attn: Privacy 2222 W Grand River Ave, Ste A Okemos, Michigan 48864 Email: privacy@netridium.com
If you are an individual whose data is held within a Netridium customer's account, please contact that customer directly; we will forward or refer such requests to the responsible customer as appropriate.
Version: August 16, 2026