Privacy Policy

Effective date: July 1, 2025

This Privacy Policy describes how Databloid, LLC (“Databloid,” “we,” “us,” or “our”) collects, uses, and shares information, particularly Personal Data (as defined below), in connection with our business operations and the provision of our data analytics services (the “Services”).

We understand the importance of your privacy and are committed to protecting your Personal Data. This policy aims to be transparent about our data practices.

  1. Definitions
    • Client Data: All electronic data, information, or material submitted by our clients to our Services, or collected by us on our clients’ behalf as part of the Services, which may include Personal Data of their customers, employees, or other individuals.
    • Personal Data: Any information relating to an identified or identifiable natural person. This includes, for example, names, email addresses, IP addresses, and other identifiers.
    • Processing: Any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
    • Data Controller: The entity that determines the purposes and means of the Processing of Personal Data. When Databloid collects data for its own purposes (e.g., website analytics, client billing), we are the Data Controller.
    • Data Processor: The entity that Processes Personal Data on behalf of the Data Controller. When Databloid provides Services to our clients and processes their data (which may include Personal Data), we act as a Data Processor on behalf of our clients (who are the Data Controllers).
    • On-Premise Services: Our data analytics services where our personnel or tools operate directly within a client’s internal systems and infrastructure, and Client Data (including Personal Data) remains solely within the client’s control and environment. Databloid does not generally store Client Data on its own systems for On-Premise Services.
    • Cloud-Based Services (or Databloid System Services): Our data analytics services where Client Data (including Personal Data) is securely transferred to, stored, and processed by Databloid’s proprietary systems, cloud infrastructure, or third-party data processing tools hosted and managed by Databloid.
    • Applicable Data Protection Laws: All laws, regulations, and industry standards relating to data privacy, data protection, and cybersecurity, including, but not limited to, the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and any specific industry regulations relevant to Client’s operations (e.g., HIPAA for healthcare data).
  2. Data We Collect and Our Role (Databloid as a Data Controller)
    • When you visit our website, contact us, or engage with us in ways that are not part of us processing data for our clients, Databloid acts as a Data Controller for the Personal Data collected directly from you.
      1. Types of Personal Data We Collect Directly:
        • Contact Information: Name, email address, phone number, company name, job title (e.g., when you fill out a contact form, request a consultation, or interact with our team).
        • Communication Data: Records of your correspondence with us (e.g., emails, chat transcripts, meeting recordings).
        • Website Usage Data: Information about how you interact with our website, such as IP address, browser type, operating system, referring URLs, pages viewed, and access times. This is often collected through cookies and similar technologies (see Section 2.3).
        • Marketing Data: Your preferences for receiving marketing communications and your interactions with our marketing materials.
        • Billing Information: If you are a client, we collect necessary billing details such as billing address and payment information.
      2. How We Use This Personal Data:
        • To provide and manage our Services (e.g., setup, billing, technical support for our clients).
        • To respond to your inquiries and requests (e.g., sales inquiries, support tickets)
        • To improve our website and Services
        • To send you marketing communications, updates, and promotional materials (with your consent where required)
        • To monitor and analyze website usage and trends
        • To comply with legal obligations (e.g., tax, accounting, regulatory requirements)
        • To prevent fraud and ensure security
      3. Cookies and Similar Technologies:
        • We use cookies and similar tracking technologies on our website to collect and use Personal Data about you.
          • What are cookies? Cookies are small text files placed on your device to store data that can be recalled by a web server in the domain that issued the cookie.
        • How we use them: We use cookies for:
          • Essential functionality: To make our website work correctly (e.g., remembering your preferences).
          • Marketing and advertising: To deliver relevant ads to you on third-party platforms.
        • Your Choices: You can manage your cookie preferences through your browser settings. Blocking certain types of cookies may impact your experience on our website.
  3. Client Data We Process (Databloid as a Data Processor)
    • When we provide our data analytics Services to our clients, we process Client Data, which may contain Personal Data, on their behalf. In this context, our clients are the Data Controllers, and Databloid is the Data Processor.
      1. What Kind of Client Data Do We Process? The types of Client Data we process are entirely dependent on the specific services our clients request and the nature of their business. This could include, but is not limited to:
        • Customer relationship management (CRM) data.
        • Sales and marketing data.
        • Operational and performance data.
        • Financial data.
        • Website or application usage data.
        • Other specific data sets provided by the client. This data may include Personal Data such as names, contact information, user IDs, or other identifiers as determined by our client.
      2. How We Process Client Data (Service Models): the method of processing Client Data depends on the agreed-upon Service Model as specified in our contract (Statement of Work) with the client:
        1. On-Premise Services:
          • Where Data Resides: For On-Premise Services, Client Data (including Personal Data) remains entirely within our client’s own internal systems and infrastructure. Databloid’s personnel or tools access and process this data directly within the client’s secure environment.
          • Our Role: Databloid performs analytical tasks and provides insights by working within the client’s system. We do not transfer or store Client Data on our own systems or cloud infrastructure for these services. Any temporary working files are securely managed and deleted from Databloid’s devices upon project completion or as per client instructions.
          • Client’s Primary Responsibility: Our client retains primary responsibility for the security, privacy, and compliance of the Personal Data within their systems.
        2. Cloud-Based Services (Databloid System Services):
          • Where Data Resides: For Cloud-Based Services, Client Data (including Personal Data) is securely transferred to and processed within Databloid’s managed cloud infrastructure. This infrastructure may utilize reputable third-party cloud providers (e.g., Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP)) and specialized data processing tools (e.g., Alteryx, SAS, Power BI) hosted and managed by Databloid.
          • Our Role: We process the Client Data strictly in accordance with our client’s documented instructions as outlined in our contract and the applicable Statement of Work (SOW) and Data Processing Addendum (DPA). We act solely as a Data Processor.
          • Databloid’s Responsibility: For these services, Databloid is responsible for the security and integrity of the Client Data while it is within our managed systems, as detailed in our Terms of Service.
      3. Purposes of Processing Client Data. We process Client Data solely for the specific purposes for which our client (the Data Controller) has engaged us. These purposes are always defined in the contract between Databloid and the client. Generally, this may involve:
        • Performing data analysis and generating insights.
        • Creating reports, dashboards, and visualizations.
        • Developing predictive models.
        • Providing data-driven recommendations to the client.
        • Supporting the client’s business objectives as mutually agreed upon.
      4. Your Rights Regarding Client Data. If your Personal Data is part of Client Data that Databloid processes on behalf of a client, you should direct any requests or inquiries regarding your privacy rights (e.g., access, rectification, erasure, restriction, objection) directly to the respective client (the Data Controller). Databloid will cooperate with our clients to fulfill their obligations under Applicable Data Protection Laws, as outlined in our Data Processing Addendum.
  4. How We Share Data
    • We may share your Personal Data (both data where we are Controller and Client Data where we are Processor) in the following circumstances:
      • With Our Service Providers (Subprocessors): We may engage third-party companies and individuals to perform services on our behalf (e.g., cloud hosting, payment processing, website analytics, customer relationship management, email services, or specialized data processing tools like Alteryx, SAS, Power BI for Cloud-Based Services). These third parties will have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. For Cloud-Based Services, a list of our subprocessors is available upon request.
      • With Our Clients: As part of our Services, the results of our analytics (which may be derived from Client Data) are shared directly with our clients.
      • Legal Requirements: We may disclose your Personal Data if required to do so by law or in the good faith belief that such action is necessary to (a) comply with a legal obligation, (b) protect and defend the rights or property of Databloid, (c) prevent or investigate possible wrongdoing in connection with the Services, (d) protect the personal safety of users of the Services or the public, or (e) protect against legal liability.
      • Business Transfers: If Databloid is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred as a business asset. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
      • With Your Consent: We may share your Personal Data for any other purpose with your explicit consent.
  5. Data Security
    • Databloid implements and maintains commercially reasonable technical and organizational security measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures vary depending on the Service Model:
      • For On-Premise Services: Our security measures focus on the secure conduct of our personnel and tools within the client’s secured environment. The client is primarily responsible for the overall security of their own systems where the data resides.
      • For Cloud-Based Services: We implement comprehensive security measures for data residing in our managed cloud infrastructure, including encryption (in transit and at rest), access controls, network security, regular security monitoring, and vulnerability management.
      • While we strive to use commercially acceptable means to protect your Personal Data, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security.
  6. Data Retention
    • We retain Personal Data for as long as necessary to fulfill the purposes for which it was collected, including to comply with our legal obligations, accounting, or reporting requirements.
      • For data where Databloid is the Controller: Client will maintain control of its Client Data within its systems. Databloid will securely delete any temporary copies or working files containing Client Data that may have been created on Databloid’s personnel devices during the engagement.
      • For Client Data where Databloid is the Processor: We retain this data strictly in accordance with the terms of our contract with our clients (the Data Controllers), including specific data retention and deletion instructions. Databloid will complete such return or deletion within [e.g., 60] days of the termination, expiration, or request as stipulated in our agreements, unless otherwise required by law. Databloid may retain a copy of Client Data for a limited period solely for backup, archival, or legal compliance purposes, provided such retention is subject to the same security and confidentiality obligations as set forth herein.
  7. International Data Transfers
    • For Cloud-Based Services, Client Data may be transferred to and processed in countries outside of your or our client’s country of residence, including to the United States where Databloid’s operations are based (McKinney, Texas, USA). For Personal Data transferred from the European Economic Area (EEA), the UK, or Switzerland, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or other lawful mechanisms to ensure a similar level of protection as in your home country.
  8. Your Data Protection Rights
    • Depending on your location and Applicable Data Protection Laws, you may have the following rights regarding your Personal Data where Databloid acts as the Data Controller (i.e., for data we collect directly about you):
      • Right to Access: Request a copy of the Personal Data we hold about you.
      • Right to Rectification: Request correction of inaccurate or incomplete Personal Data.
      • Right to Erasure (“Right to be Forgotten”): Request deletion of your Personal Data under certain circumstances.
      • Right to Restrict Processing: Request the restriction of processing of your Personal Data under certain circumstances.
      • Right to Data Portability: Request transfer of your Personal Data to another organization or to you, in a structured, commonly used, machine-readable format.
      • Right to Object to Processing: Object to the processing of your Personal Data under certain circumstances (e.g., for direct marketing).
      • Right to Withdraw Consent: If we are relying on your consent to process your Personal Data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing carried out before you withdraw your consent.
      • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority (data protection authority) if you believe your rights have been violated.
    • To exercise any of these rights regarding data where Databloid is the Data Controller, please email us at info@databloid.com with the subject “Privacy Rights.” We may need to verify your identity before fulfilling your request.
    • As noted in Section 3.4, if your Personal Data is part of Client Data, you must contact the relevant Databloid client directly to exercise your data protection rights.
  9. Children’s Privacy
    • Our Services are not intended for individuals under the age of 16. We do not knowingly collect Personal Data from children under 16. If we become aware that we have collected Personal Data from a child under 16 without verifiable parental consent, we will take steps to remove that information from our servers.
  10. Changes to This Privacy Policy
    • We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any services or continued participation on our Website, email communication, or our online meetings after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically for any changes.
  11. Contact Us
    • If you have any questions or concerns about this Privacy Policy or our data practices, please email us at info@databloid.com with the subject “Privacy Policy.”