Legal

Privacy Policy

Policy update

Privacy Policy v1.13 is now effective

Privacy Policy v1.13 became effective on August 10, 2026. It consolidates the Calendar disclosure previously presented through v1.12 plus the private Email-grounded preparedness disclosure. Product activation remains subject to separate operational, privacy, provider, and access gates.

Effective date
August 10, 2026
Previous version
Privacy Policy v1.1 — effective July 13 through August 9, 2026

Current and effective

Privacy Policy v1.13

Effective August 10, 2026

DOSSIRI LLC

Evidence Before Action

Privacy Policy

v1.13

Status
EFFECTIVE — AUGUST 10, 2026. This consolidated v1.13 text is the current Privacy Policy. It consolidates the Calendar disclosure previously presented through v1.12 plus the private Email-grounded preparedness disclosure. This version applies prospectively, does not retroactively repurpose previously collected external-user data, and was approved through documented corporate change control before cutover. Future users receive this Policy before affected processing. Legal effectiveness does not activate Email preparedness, Calendar Checkpoint B, provider access, or customer Calendar availability.
Notice Date
Not applicable to this prospective initial-use cutover; corporate approval recorded August 10, 2026
Effective Date
August 10, 2026
Governing Entity
Dossiri LLC (Maryland Limited Liability Company)
Platform
app.dossiri.com / www.dossiri.com
Version
v1.13
Change from v1.12
Adds the private Email-grounded Brief use: Email is excluded from shared Briefs by default; a requester may deliberately select one requester-owned mailbox; eligible Account/Contact-associated sanitized message text may be used as untrusted context for a private Brief; source-owner/OWNER/ADMIN visibility and nondisclosing usage rules apply. No autonomous send, provider-scope expansion, Timeline/Account History copy, model training for other customers, or logging/job/telemetry content disclosure is permitted. David classifies this as material. This effective Policy does not itself activate Email preparedness and does not change v1.12's Calendar disclosure or DEC-065.
Change from v1.11
V1.11 was the separately approved, never-effective DEC-065/Sentry prepublication candidate. V1.12 does not publish or activate that Sentry change: it is rebuilt from canonical v1.10, retains v1.10's Sentry-under-evaluation language, and adds only the Phase 14 Calendar disclosure below. V1.11 remains recoverable in Canon Git history and DEC-065 remains open, independent, and unchanged.
Change from v1.10
Adds the Phase 14 Calendar Integration disclosure before any provider consent, token issuance, Calendar or Graph data access, Google watch channel, or Microsoft subscription. It describes the exact user-authorized Google Calendar and organizational Microsoft Calendar permissions; Microsoft's broader delegated-permission ceiling; owned-calendar-only application enforcement; event, attendee, availability, booking, notification, CRM-association, and user-directed provider-write processing; private/excluded busy-only treatment; raw-data visibility; the rolling 90-day-past/365-day-future sync window; and disconnect/retention behavior. It also corrects the public-deployment record: the live website served v1.1 before this cutover, so v1.10 was not represented as publicly deployed or effective without separate evidence. David initially classified this combined correction as material and selected a 30-day path; DEC-076 superseded that delivery interval before any external-user notice or new processing after confirming zero external active users and recording sole-founder corporate approval. No Sentry, Email, AI, subscription, pricing, or customer-availability decision changes.
Change from v1.9
Corrects §6.1's provider operational-status sentences after the controlled Phase 13 completion validation accepted in DEC-062: Gmail and Outlook synchronization and deliberate human send tests completed; production Vercel Private Blob upload/removal/post-send cleanup completed; and Outlook inbound attachment metadata/on-demand retrieval completed. The existing least-privilege, Contact-gated ingestion, transient outbound storage, provider-hosted inbound bytes, no-auto-send, and no-general-availability boundaries are unchanged.
Change from v1.8
Corrects §6.1's Microsoft (Outlook) operational-status sentence, per DEC-060: one controlled production Outlook OAuth connection has succeeded for a licensed organizational test mailbox, with synchronization disabled; no message synchronization or import, attachment retrieval, or sending test has occurred. All existing least-privilege, identity, permission, and access boundaries for Microsoft are unchanged. Core Email Integration has not generally shipped as of this Policy's effective date. See DECISIONS.md DEC-060.
Change from v1.7
Corrects two §6.1 subprocessor status statements, both per DEC-058: (1) Google (Gmail) — following the earlier successful production connection test (recorded at v1.6), one controlled production synchronization has since completed successfully, importing eligible messages under the same Contact-gated ingestion rules already described in this Section; no automated or production-data send test has occurred. (2) Microsoft (Outlook) — corrects the prior "not yet implemented" status now that Workstream 6 is implemented, validated, committed, pushed, and accepted (implementation commit b79caeb7, closeout commit 480612da); no live Outlook OAuth connection, mailbox synchronization, attachment retrieval, or sending test has occurred. Core Email Integration has not generally shipped as of this Policy's effective date for either provider. No change to Google or Microsoft scope, permissions, or access boundaries. See DECISIONS.md DEC-058.
Change from v1.6
Clarifies the existing Microsoft Graph disclosure for Phase 13 Workstream 6: organizational accounts only, delegated least-privilege mailbox read/send access, and a narrowly bounded basic-profile lookup (id, mail, userPrincipalName) used solely to verify and bind the connected mailbox identity. No Calendar, directory-wide, application, shared-mailbox, or delegated-mailbox access is added. Outlook remains unimplemented and not in production as of this effective date. See DEC-055.
Change from v1.5
Clarifies §6.1's existing Vercel subprocessor purpose for Phase 13 Workstream 5: private, transient storage of user-uploaded outbound-email draft attachments. Attachment bytes are retained only while the user's draft requires them and are deleted after successful send or discard; failed drafts retain their attachments so the user can correct and retry. Inbound-email attachment bytes remain provider-hosted and are not durably stored by DOSSIRI. Also corrects Google's status from the prior forward-looking “not yet in production” statement: a production Gmail connection test has now succeeded. This introduces no new subprocessor and does not broaden Google or Microsoft mailbox permissions. See DECISIONS.md DEC-050.
Change from v1.4
Records Phase 13 (Core Email Integration)'s initial email synchronization lookback extension from 30 to 90 days, 2026-07-28 (David, DECISIONS.md DEC-044). §6.1's Google and Microsoft subprocessor entries already describe read/send access to a connected mailbox without stating a specific lookback figure, so no wording change to §6.1 is required by this amendment — this entry exists to keep the version history accurate and traceable to DEC-044, strictly limited to the lookback matter. Phase 13 still has not shipped as of this Policy's effective date; the "not yet in production" status of both entries is unchanged, and neither entry's scope of access is broadened by this version. See DECISIONS.md DEC-044.
Change from v1.3
Adds Google and Microsoft to §6.1's subprocessor list, disclosing Gmail/Outlook email content access under Phase 13 (Core Email Integration): read access to connected mailboxes (subject to Contact-gated, 30-day-lookback ingestion) and send access for in-app-composed messages, both via user-authorized OAuth, least-privilege scoped, restricted internally to the connecting user plus OWNER/ADMIN. Phase 13 has not shipped as of this Policy's effective date — this disclosure precedes production use, consistent with the Policy's practice of disclosing a subprocessor before it receives production data. Existing users notified via a standard "policy updated" notice (banner/email), per Section 13. See DECISIONS.md, 2026-07-24.
Change from v1.2
Corrects §6.1's Plausible subprocessor entry from "not yet active in production" to confirmed active in production, per Plausible's already-canonical activation being completed. No other substantive change. Existing users notified via a standard "policy updated" notice (banner/email), per Section 13. See DECISIONS.md, 2026-07-23.
Change from v1.1
Corrects §6.1's subprocessor list to add Stripe (payment processing, configured for production use but not yet processing live customer payments as of this effective date) and Anthropic (AI model provider, already an undisclosed production subprocessor prior to this correction); adds a qualified, status-labeled Plausible entry and a forward-looking Sentry evaluation disclosure; corrects §9.4 to stop implying an analytics cookie exists to disable, consistent with Plausible's cookieless design already described in §3.5; reframes stale waitlist-era language in §1, §3.1, and §7.5 to past tense, reflecting the deprecation of /waitlist in favor of direct signup. Existing users are notified of this update via a standard "policy updated" notice (banner/email), consistent with Section 13's 30-day advance-notice practice for material changes. See DECISIONS.md, 2026-07-22.

1. Introduction and Scope

Dossiri LLC ("DOSSIRI," "we," "us," or "our") is a Maryland limited liability company that develops and operates a compliance-aware, intelligence-native customer relationship management platform available at app.dossiri.com (the "Service"). DOSSIRI is designed for life sciences and regulated-industry sales professionals.

This Privacy Policy explains how we collect, use, store, share, and protect information in connection with your use of the Service and our marketing website at www.dossiri.com (the "Website"). It applies to all users of the Service and all visitors to the Website.

By accessing the Service or Website, or by registering for or using the Service, you acknowledge that you have read and understood this Privacy Policy.

1.1 What This Policy Covers

This Privacy Policy covers:

  • Information you provide directly to DOSSIRI when registering, using the Service, or requesting access
  • Information collected automatically when you access the Service or Website
  • Information collected through your organization's account on the Service
  • How we process, store, and protect that information
  • Your rights regarding your information
  • How to contact us with questions or requests

1.2 What This Policy Does Not Cover

This Privacy Policy does not cover:

  • The data practices of third-party websites or services linked from our Service or Website
  • Data processed by your organization as the controller of its CRM records — see Section 4

2. Key Definitions

The following terms are used throughout this Privacy Policy:

Account: An organizational account on the Service, created when an individual or team registers for DOSSIRI. The Organization is the tenant boundary for all CRM data.

Customer Content: All data, records, and information that users enter into or deliberately connect to the Service, including account records, contact records, lead records, deal records, task records, evidence entries, connected Calendar data, and public scheduling submissions. Customer Content belongs to the Organization, not to DOSSIRI.

Organization: The business entity that holds an Account on the Service. All CRM records are scoped to an Organization. Individual users access the Service through their Organization's Account.

Service: The DOSSIRI platform available at app.dossiri.com, including all CRM Core features and Intelligence Layer features.

User: An individual who accesses the Service through an Organization's Account.

Website: The DOSSIRI marketing website at www.dossiri.com, which is separate from the Service.

3. Information We Collect

3.1 Information You Provide Directly

When you register for the Service, request early access, or communicate with us, we collect:

  • Name and email address
  • Company or organization name
  • Job role or title
  • Information submitted through the registration process, including current tools used, team size, and primary challenges
  • Communications you send to us, including support requests and feedback
  • Historical waitlist or early access data: DOSSIRI previously operated an early-access waitlist, since replaced by direct signup. Section 7.5 describes how any such historical data is retained.

3.2 Account and Profile Information

When you use the Service, we collect:

  • Account credentials managed through Clerk, our authentication provider
  • User profile information, including display name, email address, and optional representative style preferences
  • Organization profile information, including organization name, Ideal Customer Profile (ICP) settings, and monitoring tag preferences

3.3 Customer Content

The Service is a CRM platform. Users enter, store, or deliberately connect Customer Content including account records, contact records, lead records, deal records, task records, evidence entries, connected Calendar data, and public scheduling submissions. This content belongs to the Organization. See Section 4 for a complete description of how we treat Customer Content.

3.3.1 Connected Calendar Data

If a user deliberately connects Google Calendar or an organizational Microsoft Calendar, DOSSIRI processes:

  • The connected provider identity, owned-calendar inventory, safe calendar label, selected-calendar state, consent/permission snapshot, encrypted refresh token, synchronization cursor and window, and authenticated notification-channel or subscription identity. Provider access tokens are used only in memory and are not stored.
  • For a non-private event: title, start and end time, timezone, recurrence and provider-lifecycle linkage, organizer identity, attendee email addresses used for exact CRM matching, event origin, privacy state, and explicit CRM association state.
  • For a provider-private or user-excluded event: only the time range, timezone, and minimum lifecycle/version state required to represent a busy block and keep synchronization accurate. DOSSIRI does not retain its title, attendee data, CRM association, Task link, or Account History detail.
  • For public scheduling: the guest's name, email address, selected slot, and privacy-safe booking/idempotency state needed to create or safely retry the requested booking. A public booking does not automatically create a Contact or Account.

DOSSIRI does not durably store Calendar event descriptions or bodies, locations, attachments, conference passcodes, or unrestricted conference metadata. Calendar Integration does not analyze, transcribe, or record meetings and does not use meeting content for generative AI.

3.3.2 Private Email-Grounded Brief Data (Proposed; Not Active)

If this separately gated feature is activated and a user explicitly requests it, the requester may select one mailbox that the requester personally connected. DOSSIRI may then use sanitized message text from eligible Account-associated Email threads, prioritizing a selected Contact's eligible threads for Pre-Call preparation. Email is excluded from shared Briefs by default.

The resulting Brief and generation record are private to the requester. Other users cannot infer the mailbox, messages, private Brief, generation count, timing, token use, or failure from shared totals or denials. Email content is not copied into Timeline or Account History, included in shared outputs, logged, placed in job payloads or telemetry, used for autonomous sending, or used to train models for other customers.

3.4 Usage and Operational Data

When you access the Service or Website, we automatically collect:

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Pages visited, features accessed, and time spent on the Service
  • Referring URLs and navigation paths
  • Usage event records, including intelligence features accessed and types of content generated
  • Error logs and diagnostic information

3.5 Cookies and Similar Technologies

We and our service providers use cookies and similar technologies to operate the Service, maintain sessions, and understand how the Service is used. We use:

  • Strictly necessary cookies required to authenticate users and maintain session state. These cannot be disabled without preventing access to the Service.
  • Privacy-focused, cookieless analytics (Plausible) to understand aggregate usage patterns on our Website. This analytics approach does not use cookies, does not track individuals across sites, and does not require a cookie-consent banner.

We do not use advertising cookies or share cookie data with advertising networks.

4. Customer Content and Organizational Data

4.1 You Own Your Customer Content

Customer Content belongs to the Organization that creates it. DOSSIRI does not claim ownership of Customer Content. When you enter account records, contact records, lead records, deal records, task records, or evidence into the Service, that information remains yours.

4.2 How We Use Customer Content

DOSSIRI processes Customer Content solely to provide the Service. Specifically:

  • CRM Core features store and retrieve Customer Content at your direction
  • Calendar Integration synchronizes the owned calendars a user deliberately connects; displays meeting and availability information; supports explicit CRM association and CRM-safe Account History; and performs only user-directed meeting create, update, or cancellation and requested public scheduling
  • Intelligence Layer features process Customer Content as context for generating intelligence outputs, including Account Briefs, Pre-Call Briefs, Territory Digest summaries, Signals, and Opportunity Assessments
  • If private Email-grounded preparation is separately activated and the user explicitly chooses it, DOSSIRI may process eligible sanitized Email text from one requester-owned mailbox as described in Section 3.3.2; ordinary/shared Briefs continue to exclude Email
  • We do not sell Customer Content
  • We do not share Customer Content with third parties except as described in Section 6 or as required by law
  • We do not use Customer Content to train machine learning models for use by other customers or organizations without your explicit consent

4.3 Organizational Access to Customer Content

The Service is designed around organizational accounts. When you create Customer Content within an Organization, that content may be accessible to other members of your Organization based on their assigned role (Owner, Admin, Member, or Viewer). You should not enter personal information into the Service that you would not want other members of your Organization to access.

DOSSIRI does not control how your organization manages internal access to Customer Content within the Service. Questions about internal access policies should be directed to your organization's account owner or administrator.

4.4 Aggregated and De-identified Data

DOSSIRI may create aggregated or de-identified information derived from Customer Content and usage data for the purpose of operating, improving, and developing the Service. Aggregated data does not identify any individual user or organization and is not Customer Content. Examples include aggregate usage statistics, feature adoption rates, and performance benchmarks. We may use such aggregated data without restriction.

4.5 Intelligence Outputs

Intelligence outputs generated by the Service (including Briefs, Signals, Opportunity Assessments, and Suggested Contacts) are derived from Customer Content but are distinct from it. These outputs are provided as decision-support information and are subject to the disclaimer in Section 11. Customer Content used as input to intelligence generation remains the property of the Organization.

4.6 Calendar Visibility and Organizational Access

Raw synchronized Calendar data, including unmatched attendee email addresses and provider-lifecycle detail, is available only to the connecting user and active Owners or Administrators of the same Organization. This visibility does not permit another user to act as the connecting user's provider identity or use that user's provider token.

When a non-private meeting is associated with a CRM Account, other Organization members who can already access that Account may see only a CRM-safe meeting summary: title, start/end time and timezone, lifecycle status, whether it was imported or created through DOSSIRI, matched existing Contacts, and linked Tasks. The summary excludes provider calendar identifiers or names, unmatched attendee addresses, raw recurrence/provider payloads, descriptions, locations, attachments, conference metadata, private/excluded-event detail, and synchronization diagnostics.

Availability and public scheduling expose only free/busy or eligible slot information. They do not expose event titles, attendees, private/excluded details, provider identifiers, internal user or Organization identifiers, or calendar names.

4.7 Email-Grounded Brief Visibility (Proposed; Not Active)

An Email-grounded Brief is not Organization-shared Customer Content. It is limited to its requester, and the source mailbox remains governed by connecting-user plus same-Organization Owner/Administrator access. Ordinary Member or Viewer access to the associated Account does not grant access to the Email source or private Brief. Private generations may count toward an Organization limit, but user-visible totals and denial responses are filtered so they do not disclose another user's private activity.

5. How We Use Information

We use the information we collect for the following purposes:

5.1 Providing and Operating the Service

  • Authenticating users and maintaining sessions
  • Storing and retrieving Customer Content at user direction
  • Connecting, synchronizing, and displaying user-authorized owned calendars; computing free/busy availability; associating non-private meetings with CRM records; supporting scheduling links; and carrying out explicit meeting actions or requested public bookings
  • Processing intelligence generation requests, including Account Briefs, Pre-Call Briefs, Signal analysis, and Territory Digest generation
  • Delivering email notifications, including Territory Digest notifications and other service communications
  • Monitoring platform health and diagnosing errors

5.2 Communications

  • Responding to support requests and inquiries
  • Sending transactional messages required to operate the Service, including account notifications and service announcements
  • Sending marketing communications about DOSSIRI products and features, where you have not opted out (see Section 9)

5.3 Improvement and Development

  • Analyzing usage patterns to improve the Service
  • Identifying features that are used frequently or infrequently
  • Developing new features and capabilities
  • Creating aggregated and de-identified benchmarks as described in Section 4.4

5.4 Legal and Compliance

  • Complying with applicable laws and regulations
  • Responding to lawful legal process or government requests
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Protecting the rights, safety, and security of users and third parties

6. Information Sharing and Disclosure

We do not sell your personal information. We do not share your personal information except as described in this section.

6.1 Service Providers and Subprocessors

We share information with third-party service providers who help us operate the Service. These providers are contractually required to process your information only for the purposes we specify and to maintain appropriate security standards. Our current subprocessors include:

  • Clerk — User authentication and identity management (clerk.com)
  • Neon — Database hosting and storage (neon.tech)
  • Vercel — Application hosting, content delivery, and private transient storage of user-uploaded outbound-email draft attachments. Those attachment bytes are deleted after successful send or discard; failed drafts retain them for user correction/retry. Inbound-email attachment bytes are not durably stored by DOSSIRI (vercel.com)
  • Resend — Transactional and notification email delivery (resend.com)
  • Railway — Background processing and AI worker infrastructure (railway.app)
  • Google (Gmail API and Google Calendar API) — For users who connect Gmail under Core Email Integration, DOSSIRI has the mailbox read/send access and Phase 13 status described in v1.10, unchanged by this version. Separately, for users who deliberately connect Google Calendar, DOSSIRI requests identity/email metadata plus only owned-event read/write, calendar-list read, and event free/busy access. It rejects broader Calendar, shared-calendar-write, Gmail, Drive, Contacts, ACL-write, and calendar-property-write permissions from the Calendar authorization. DOSSIRI uses the grant only for calendars the connecting user owns, selected Calendar synchronization, free/busy, explicit DOSSIRI-created meeting actions, public bookings requested through an active link, and authenticated notification-driven synchronization. No Google Calendar consent, token issuance, Calendar-data access, or watch channel has occurred as of this effective release (google.com)
  • Microsoft (Outlook / Microsoft Graph) — For users who connect organizational Outlook under Core Email Integration, DOSSIRI has the mailbox read/send access and Phase 13 status described in v1.10, unchanged by this version; Phase 13 still requests no Calendar permission. Separately, for users who deliberately connect an organizational Microsoft Calendar, DOSSIRI requests OpenID/profile/offline access, the narrow User.Read identity lookup, and delegated Calendars.ReadWrite. Microsoft does not offer an owned-calendar-only delegated permission: the Graph permission can technically reach more calendars than DOSSIRI's intended feature. DOSSIRI therefore independently restricts selection, synchronization, free/busy, and writes to calendars it freshly verifies the connecting user owns, and it rejects personal accounts, application permissions, directory-wide access, shared-calendar permission, Mail permission in the Calendar grant, and any unlisted permission. No Microsoft Calendar consent, token issuance, Graph Calendar-data access, or subscription has occurred as of this effective release (microsoft.com)
  • Stripe — Payment processing and subscription billing (stripe.com). Configured for production use as of this Policy's effective date; not yet processing live customer payments. This Policy will be updated if that status changes materially.
  • Anthropic — AI model provider for Account Briefs, Pre-Call Briefs, Opportunity Assessments, and other intelligence-generation features (anthropic.com)
  • Plausible Analytics — Privacy-focused, cookieless website usage analytics (plausible.io). Active in production as of July 23, 2026.

DOSSIRI may in the future use an error-monitoring/observability subprocessor (currently under evaluation: Sentry) to help identify and resolve technical issues. Any such service will be added to this list, with this Policy updated accordingly, before it receives any production data, and will be configured to exclude Customer Content, authentication credentials, and other sensitive personal data from transmission.

We may add or replace subprocessors as the Service evolves. We will update this section when material changes to our subprocessor list occur.

6.2 Business Transfers

If DOSSIRI is involved in a merger, acquisition, asset sale, or reorganization, Customer Content and personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any resulting changes to this Privacy Policy.

6.3 Legal Requirements

We may disclose information when required to do so by law, court order, or other legal process, or when we believe disclosure is necessary to protect the rights, property, or safety of DOSSIRI, our users, or the public.

6.4 Consent

We may share information with your consent or at your direction in circumstances not described above.

7. Data Retention

7.1 Active Accounts

We retain Customer Content and account information for as long as your Organization maintains an active Account on the Service. If individual records are deleted within an active Account, those records are marked as deleted but may be retained in our systems for a recovery period before permanent deletion.

7.2 After Account Termination

When an Organization's Account is terminated or cancelled, we retain Customer Content and associated account data for a period of 90 days. This retention period exists to facilitate account restoration in the event of accidental cancellation and to satisfy any outstanding contractual or legal obligations. After the 90-day retention period, Customer Content becomes eligible for permanent deletion from our systems.

Note on this Policy's relationship to product behavior: consistent with the Service's data-retention architecture, records are marked for deletion (soft-deleted) rather than immediately and irrecoverably purged, which supports account restoration and audit needs. This is distinct from, and should not be conflated with, a formal data-erasure request under applicable law (see Section 9.3) — a formal erasure request is handled through a separate confirmed process.

7.3 Hard Deletion Requests

Account holders may request permanent deletion of their Customer Content after Account closure. Upon receiving a verified deletion request following Account closure, we will use commercially reasonable efforts to permanently delete Customer Content from our systems and to request deletion from subprocessors, subject to any legal retention obligations. We will confirm completion of deletion upon request.

7.4 Calendar Window, Privacy, and Disconnect

For a connected Calendar account, DOSSIRI synchronizes a rolling window from 90 days in the past through 365 days in the future. Raw event mirrors outside the confirmed rolling window are pruned through bounded reconciliation.

Marking an event private at the provider or excluding it in DOSSIRI reduces the stored event to busy-only state and removes Calendar-derived attendee, association, Account History, and Task-link detail. Removing an exclusion starts a fresh lifecycle from a newly verified provider snapshot; DOSSIRI does not reconstruct deleted history.

Disconnecting Calendar is not the same as closing an Organization Account or making a formal legal-erasure request. Disconnect immediately prevents new Calendar activity, then allows only bounded disposition of an already authorized in-flight provider attempt. After disposition, DOSSIRI clears provider credentials, synchronization cursors, notification identities, and all raw event and attendee rows. DOSSIRI may retain sanitized connection/source configuration, valid CRM-safe meeting history and linked Tasks under the ordinary Account-retention rules, and a non-displayable keyed correlation used only to prevent duplicate history on an explicit reconnect. Limited content-free authenticated-operation records may remain for no more than 30 days to support truthful, privacy-safe retry responses. Guest details and readable provider commands/responses are erased when privacy or disconnect rules require it.

7.5 Usage and Operational Data

Usage and operational data (such as logs, error reports, and usage event records) may be retained for a longer period than Customer Content for operational, security, and diagnostic purposes. Aggregated and de-identified data derived from Customer Content may be retained indefinitely.

7.6 Historical Waitlist and Early Access Data

DOSSIRI previously operated a waitlist and early access request process at www.dossiri.com; this has been replaced by direct registration for the Service. Information previously submitted through that waitlist or early access process is retained under this Policy on the same basis as other information you provided directly (Section 3.1). If you previously requested removal from the waitlist, that request remains honored. Contact us at privacy@dossiri.com with any question about historical waitlist data specifically.

8. Security

We implement commercially reasonable technical and organizational measures to protect information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encrypted transmission via HTTPS for all data in transit
  • Versioned authenticated encryption for stored Calendar refresh tokens and sensitive retry commands; provider access tokens are memory-only
  • Access controls limiting Service access to authenticated and authorized users
  • Organizational data isolation — each Organization's Customer Content is scoped to that Organization's Account and is not accessible to other Organizations
  • Third-party service providers that maintain their own security programs appropriate to the data they process

No security system is perfect. We cannot guarantee that unauthorized access, data loss, or other security incidents will never occur. If we become aware of a security breach that affects your personal information, we will notify you as required by applicable law.

DOSSIRI is not designed to store Protected Health Information (PHI) as defined under HIPAA. Users must not enter PHI into the Service under any circumstances. DOSSIRI is not a HIPAA Business Associate and does not execute Business Associate Agreements.

DOSSIRI is not currently represented as a 21 CFR Part 11 compliant system. Users in FDA-regulated environments are solely responsible for evaluating whether DOSSIRI is appropriate for use within their regulated workflows. Nothing in this Privacy Policy represents that the Service meets any regulatory validation standard.

9. Your Rights and Choices

9.1 Access and Correction

You may access and update your personal profile information within the Service at any time. If you are unable to access or correct your information through the Service, you may contact us at privacy@dossiri.com and we will assist you.

9.2 Marketing Communications

If you receive marketing communications from us, you may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@dossiri.com. Opting out of marketing communications does not affect transactional messages required to operate the Service.

9.3 Account and Data Deletion

You may request deletion of your Account and associated Customer Content by contacting us at privacy@dossiri.com. Deletion is subject to the retention periods described in Section 7. We may retain certain information as required by applicable law or for legitimate business purposes following account deletion.

You may disconnect a Calendar provider through the Service. As Section 7.4 explains, disconnect revokes and removes the live Calendar connection and raw synchronized data but is not itself a request to delete all CRM-safe meeting history, linked Tasks, or other Customer Content. Contact privacy@dossiri.com for a verified deletion request.

9.4 Cookies

Because our website analytics (Plausible) do not use cookies, there is no analytics cookie to disable through your browser settings. Disabling strictly necessary cookies will prevent you from accessing the Service.

9.5 California Residents (CCPA/CPRA)

California residents may have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know what personal information we have collected about you
  • Right to delete personal information we have collected from you, subject to certain exceptions
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information (DOSSIRI does not sell or share personal information for cross-context behavioral advertising)
  • Right to limit use of sensitive personal information (where applicable — see Counsel Review Flag above)
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, contact us at privacy@dossiri.com. We will respond to verified requests within 45 days as required by applicable law.

9.6 Non-U.S. Users

DOSSIRI is operated from the United States and governed by United States law. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer and processing.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data protection laws, you may have additional rights under applicable law. Contact us at privacy@dossiri.com to inquire about your rights.

10. Third-Party Links and Services

The Service and Website may contain links to third-party websites, services, or content. We are not responsible for the privacy practices of third parties. Links to third-party resources do not constitute endorsement of those resources or their privacy practices.

The intelligence features of the Service surface information derived from publicly available third-party data sources including FDA databases, ClinicalTrials.gov, and SEC EDGAR filings. DOSSIRI does not control these sources, does not guarantee the accuracy or completeness of information derived from them, and is not responsible for errors, omissions, or outdated information in such sources. See Section 11 for important disclaimers about intelligence outputs.

11. Intelligence Output Disclaimer

This section is a material term of this Privacy Policy and applies to all intelligence features of the Service, including Account Briefs, Pre-Call Briefs, Territory Digest summaries, Onboarding Briefs, Signals, Opportunity Assessments, and Suggested Contacts.

DOSSIRI outputs do not constitute compliance advice, legal advice, regulatory advice, validation guidance, quality advice, or professional advice of any kind. All outputs are provided solely as decision-support information. Users are solely responsible for independently evaluating, validating, and verifying any DOSSIRI output before acting upon it. DOSSIRI does not guarantee the accuracy, completeness, timeliness, or fitness for any particular purpose of any output generated by the Service. Human judgment remains responsible for all decisions and actions taken in connection with information provided by DOSSIRI.

DOSSIRI is:

  • A compliance-aware, intelligence-native customer relationship management platform
  • Decision-support software designed to help life sciences and regulated-industry sales professionals prepare for conversations, assess opportunities, accumulate account intelligence, and monitor territory signals
  • A tool that assists professional judgment — it does not replace it

DOSSIRI is not:

  • Legal advice or a substitute for legal counsel
  • Compliance advice or a substitute for compliance professionals or compliance management systems
  • Regulatory advice or a substitute for regulatory affairs professionals
  • Validation consulting or a substitute for validation engineers or quality professionals
  • Quality management software or a quality management system (QMS)
  • A 21 CFR Part 11 compliant system — DOSSIRI is not represented as such and users in FDA-regulated environments are responsible for evaluating its appropriateness for their regulated workflows
  • A system designed to store, process, or transmit Protected Health Information (PHI) as defined under HIPAA
  • An autonomous agent — DOSSIRI does not take actions on your behalf or make decisions for you
  • A guarantee of any business, sales, compliance, regulatory, or validation outcome

Specifically:

  • Intelligence outputs, including Briefs and Signals, are generated in part from publicly available data sources. DOSSIRI does not independently verify the accuracy or currency of third-party data used in generating intelligence outputs.
  • Opportunity Assessments (High Potential, Moderate Potential, Low Potential, Insufficient Information) reflect decision-support classifications based on available information. They are not predictions, guarantees, or professional assessments of any business, regulatory, or compliance outcome.
  • Signal information reflecting regulatory activity, clinical trial postings, procurement notices, or company events is derived from public sources and may be delayed, incomplete, or inaccurate. Users in regulated environments must independently verify any signal information before relying on it for business, compliance, or regulatory purposes.

Use of the Service does not create an attorney-client, consultant-client, compliance advisory, regulatory advisory, quality advisory, or other professional services relationship between DOSSIRI and any User or Organization.

12. Children

The Service is intended for business use by adults. The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected personal information from an individual under 18, we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice within the Service at least 30 days prior to the change becoming effective. The effective date at the top of this document reflects when this version took effect.

Continued use of the Service after a revised Privacy Policy takes effect constitutes acceptance of the revised Policy.

14. Contact Information

For privacy questions, requests to exercise your rights, or other inquiries related to this Privacy Policy, contact us at:

Privacy Inquiries: privacy@dossiri.com

General: hello@dossiri.com

End of Document — DOSSIRI LLC — Privacy Policy v1.13 (effective August 10, 2026)

Previous version

Privacy Policy v1.1

Effective July 13 through August 9, 2026

DOSSIRI LLC

Evidence Before Action

Privacy Policy

v1.1

Effective Date
July 13, 2026
Governing Entity
Dossiri LLC (Maryland Limited Liability Company)
Platform
app.dossiri.com / www.dossiri.com
Version
v1.1

1. Introduction and Scope

Dossiri LLC ("DOSSIRI," "we," "us," or "our") is a Maryland limited liability company that develops and operates a compliance-aware, intelligence-native customer relationship management platform available at app.dossiri.com (the "Service"). DOSSIRI is designed for life sciences and regulated-industry sales professionals.

This Privacy Policy explains how we collect, use, store, share, and protect information in connection with your use of the Service and our marketing website at www.dossiri.com (the "Website"). It applies to all users of the Service and all visitors to the Website.

By accessing the Service or Website, or by submitting a waitlist or early access request, you acknowledge that you have read and understood this Privacy Policy.

1.1 What This Policy Covers

This Privacy Policy covers:

  • Information you provide directly to DOSSIRI when registering, using the Service, or requesting access
  • Information collected automatically when you access the Service or Website
  • Information collected through your organization's account on the Service
  • How we process, store, and protect that information
  • Your rights regarding your information
  • How to contact us with questions or requests

1.2 What This Policy Does Not Cover

This Privacy Policy does not cover:

  • The data practices of third-party websites or services linked from our Service or Website
  • Data processed by your organization as the controller of its CRM records — see Section 4

2. Key Definitions

The following terms are used throughout this Privacy Policy:

Account: An organizational account on the Service, created when an individual or team registers for DOSSIRI. The Organization is the tenant boundary for all CRM data.

Customer Content: All data, records, and information that users enter into the Service, including account records, contact records, lead records, deal records, task records, and evidence entries. Customer Content belongs to the Organization, not to DOSSIRI.

Organization: The business entity that holds an Account on the Service. All CRM records are scoped to an Organization. Individual users access the Service through their Organization's Account.

Service: The DOSSIRI platform available at app.dossiri.com, including all CRM Core features and Intelligence Layer features.

User: An individual who accesses the Service through an Organization's Account.

Website: The DOSSIRI marketing website at www.dossiri.com, which is separate from the Service.

3. Information We Collect

3.1 Information You Provide Directly

When you register for the Service, request early access, or communicate with us, we collect:

  • Name and email address
  • Company or organization name
  • Job role or title
  • Information submitted through waitlist or early access forms, including current tools used, team size, and primary challenges
  • Communications you send to us, including support requests and feedback

3.2 Account and Profile Information

When you use the Service, we collect:

  • Account credentials managed through Clerk, our authentication provider
  • User profile information, including display name, email address, and optional representative style preferences
  • Organization profile information, including organization name, Ideal Customer Profile (ICP) settings, and monitoring tag preferences

3.3 Customer Content

The Service is a CRM platform. Users enter and store Customer Content including account records, contact records, lead records, deal records, task records, and evidence entries. This content belongs to the Organization. See Section 4 for a complete description of how we treat Customer Content.

3.4 Usage and Operational Data

When you access the Service or Website, we automatically collect:

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Pages visited, features accessed, and time spent on the Service
  • Referring URLs and navigation paths
  • Usage event records, including intelligence features accessed and types of content generated
  • Error logs and diagnostic information

3.5 Cookies and Similar Technologies

We and our service providers use cookies and similar technologies to operate the Service, maintain sessions, and understand how the Service is used. We use:

  • Strictly necessary cookies required to authenticate users and maintain session state. These cannot be disabled without preventing access to the Service.
  • Privacy-focused, cookieless analytics (Plausible) to understand aggregate usage patterns on our Website. This analytics approach does not use cookies, does not track individuals across sites, and does not require a cookie-consent banner.

We do not use advertising cookies or share cookie data with advertising networks.

4. Customer Content and Organizational Data

4.1 You Own Your Customer Content

Customer Content belongs to the Organization that creates it. DOSSIRI does not claim ownership of Customer Content. When you enter account records, contact records, lead records, deal records, task records, or evidence into the Service, that information remains yours.

4.2 How We Use Customer Content

DOSSIRI processes Customer Content solely to provide the Service. Specifically:

  • CRM Core features store and retrieve Customer Content at your direction
  • Intelligence Layer features process Customer Content as context for generating intelligence outputs, including Account Briefs, Pre-Call Briefs, Territory Digest summaries, Signals, and Opportunity Assessments
  • We do not sell Customer Content
  • We do not share Customer Content with third parties except as described in Section 6 or as required by law
  • We do not use Customer Content to train machine learning models for use by other customers or organizations without your explicit consent

4.3 Organizational Access to Customer Content

The Service is designed around organizational accounts. When you create Customer Content within an Organization, that content may be accessible to other members of your Organization based on their assigned role (Owner, Admin, Member, or Viewer). You should not enter personal information into the Service that you would not want other members of your Organization to access.

DOSSIRI does not control how your organization manages internal access to Customer Content within the Service. Questions about internal access policies should be directed to your organization's account owner or administrator.

4.4 Aggregated and De-identified Data

DOSSIRI may create aggregated or de-identified information derived from Customer Content and usage data for the purpose of operating, improving, and developing the Service. Aggregated data does not identify any individual user or organization and is not Customer Content. Examples include aggregate usage statistics, feature adoption rates, and performance benchmarks. We may use such aggregated data without restriction.

4.5 Intelligence Outputs

Intelligence outputs generated by the Service (including Briefs, Signals, Opportunity Assessments, and Suggested Contacts) are derived from Customer Content but are distinct from it. These outputs are provided as decision-support information and are subject to the disclaimer in Section 11. Customer Content used as input to intelligence generation remains the property of the Organization.

5. How We Use Information

We use the information we collect for the following purposes:

5.1 Providing and Operating the Service

  • Authenticating users and maintaining sessions
  • Storing and retrieving Customer Content at user direction
  • Processing intelligence generation requests, including Account Briefs, Pre-Call Briefs, Signal analysis, and Territory Digest generation
  • Delivering email notifications, including Territory Digest notifications and other service communications
  • Monitoring platform health and diagnosing errors

5.2 Communications

  • Responding to support requests and inquiries
  • Sending transactional messages required to operate the Service, including account notifications and service announcements
  • Sending marketing communications about DOSSIRI products and features, where you have not opted out (see Section 9)

5.3 Improvement and Development

  • Analyzing usage patterns to improve the Service
  • Identifying features that are used frequently or infrequently
  • Developing new features and capabilities
  • Creating aggregated and de-identified benchmarks as described in Section 4.4

5.4 Legal and Compliance

  • Complying with applicable laws and regulations
  • Responding to lawful legal process or government requests
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Protecting the rights, safety, and security of users and third parties

6. Information Sharing and Disclosure

We do not sell your personal information. We do not share your personal information except as described in this section.

6.1 Service Providers and Subprocessors

We share information with third-party service providers who help us operate the Service. These providers are contractually required to process your information only for the purposes we specify and to maintain appropriate security standards. Our current subprocessors include:

  • Clerk — User authentication and identity management (clerk.com)
  • Neon — Database hosting and storage (neon.tech)
  • Vercel — Application hosting and content delivery (vercel.com)
  • Resend — Transactional and notification email delivery (resend.com)
  • Railway or Render — Background processing and AI worker infrastructure. Final provider selection between these two is an internal operational decision not yet finalized; this Policy will be updated to name the specific provider once selected, consistent with our practice of updating this section when subprocessors change.

We may add or replace subprocessors as the Service evolves. We will update this section when material changes to our subprocessor list occur.

6.2 Business Transfers

If DOSSIRI is involved in a merger, acquisition, asset sale, or reorganization, Customer Content and personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any resulting changes to this Privacy Policy.

6.3 Legal Requirements

We may disclose information when required to do so by law, court order, or other legal process, or when we believe disclosure is necessary to protect the rights, property, or safety of DOSSIRI, our users, or the public.

6.4 Consent

We may share information with your consent or at your direction in circumstances not described above.

7. Data Retention

7.1 Active Accounts

We retain Customer Content and account information for as long as your Organization maintains an active Account on the Service. If individual records are deleted within an active Account, those records are marked as deleted but may be retained in our systems for a recovery period before permanent deletion.

7.2 After Account Termination

When an Organization's Account is terminated or cancelled, we retain Customer Content and associated account data for a period of 90 days. This retention period exists to facilitate account restoration in the event of accidental cancellation and to satisfy any outstanding contractual or legal obligations. After the 90-day retention period, Customer Content becomes eligible for permanent deletion from our systems.

Note on this Policy's relationship to product behavior: consistent with the Service's data-retention architecture, records are marked for deletion (soft-deleted) rather than immediately and irrecoverably purged, which supports account restoration and audit needs. This is distinct from, and should not be conflated with, a formal data-erasure request under applicable law (see Section 9.3) — a formal erasure request is handled through a separate confirmed process.

7.3 Hard Deletion Requests

Account holders may request permanent deletion of their Customer Content after Account closure. Upon receiving a verified deletion request following Account closure, we will use commercially reasonable efforts to permanently delete Customer Content from our systems and to request deletion from subprocessors, subject to any legal retention obligations. We will confirm completion of deletion upon request.

7.4 Usage and Operational Data

Usage and operational data (such as logs, error reports, and usage event records) may be retained for a longer period than Customer Content for operational, security, and diagnostic purposes. Aggregated and de-identified data derived from Customer Content may be retained indefinitely.

7.5 Waitlist and Early Access Data

Information submitted through the waitlist or early access form at www.dossiri.com is retained for the purpose of managing early access communications. If you request removal from the waitlist, we will remove your contact information from active communications within a commercially reasonable time.

8. Security

We implement commercially reasonable technical and organizational measures to protect information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encrypted transmission via HTTPS for all data in transit
  • Access controls limiting Service access to authenticated and authorized users
  • Organizational data isolation — each Organization's Customer Content is scoped to that Organization's Account and is not accessible to other Organizations
  • Third-party service providers that maintain their own security programs appropriate to the data they process

No security system is perfect. We cannot guarantee that unauthorized access, data loss, or other security incidents will never occur. If we become aware of a security breach that affects your personal information, we will notify you as required by applicable law.

DOSSIRI is not designed to store Protected Health Information (PHI) as defined under HIPAA. Users must not enter PHI into the Service under any circumstances. DOSSIRI is not a HIPAA Business Associate and does not execute Business Associate Agreements.

DOSSIRI is not currently represented as a 21 CFR Part 11 compliant system. Users in FDA-regulated environments are solely responsible for evaluating whether DOSSIRI is appropriate for use within their regulated workflows. Nothing in this Privacy Policy represents that the Service meets any regulatory validation standard.

9. Your Rights and Choices

9.1 Access and Correction

You may access and update your personal profile information within the Service at any time. If you are unable to access or correct your information through the Service, you may contact us at privacy@dossiri.com and we will assist you.

9.2 Marketing Communications

If you receive marketing communications from us, you may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@dossiri.com. Opting out of marketing communications does not affect transactional messages required to operate the Service.

9.3 Account and Data Deletion

You may request deletion of your Account and associated Customer Content by contacting us at privacy@dossiri.com. Deletion is subject to the retention periods described in Section 7. We may retain certain information as required by applicable law or for legitimate business purposes following account deletion.

9.4 Cookies

You may disable analytics cookies through your browser settings. Disabling strictly necessary cookies will prevent you from accessing the Service.

9.5 California Residents (CCPA/CPRA)

California residents may have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know what personal information we have collected about you
  • Right to delete personal information we have collected from you, subject to certain exceptions
  • Right to correct inaccurate personal information
  • Right to opt out of the sale or sharing of personal information (DOSSIRI does not sell or share personal information for cross-context behavioral advertising)
  • Right to limit use of sensitive personal information (where applicable — see Counsel Review Flag above)
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, contact us at privacy@dossiri.com. We will respond to verified requests within 45 days as required by applicable law.

9.6 Non-U.S. Users

DOSSIRI is operated from the United States and governed by United States law. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer and processing.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data protection laws, you may have additional rights under applicable law. Contact us at privacy@dossiri.com to inquire about your rights.

10. Third-Party Links and Services

The Service and Website may contain links to third-party websites, services, or content. We are not responsible for the privacy practices of third parties. Links to third-party resources do not constitute endorsement of those resources or their privacy practices.

The intelligence features of the Service surface information derived from publicly available third-party data sources including FDA databases, ClinicalTrials.gov, and SEC EDGAR filings. DOSSIRI does not control these sources, does not guarantee the accuracy or completeness of information derived from them, and is not responsible for errors, omissions, or outdated information in such sources. See Section 11 for important disclaimers about intelligence outputs.

11. Intelligence Output Disclaimer

This section is a material term of this Privacy Policy and applies to all intelligence features of the Service, including Account Briefs, Pre-Call Briefs, Territory Digest summaries, Onboarding Briefs, Signals, Opportunity Assessments, and Suggested Contacts.

DOSSIRI outputs do not constitute compliance advice, legal advice, regulatory advice, validation guidance, quality advice, or professional advice of any kind. All outputs are provided solely as decision-support information. Users are solely responsible for independently evaluating, validating, and verifying any DOSSIRI output before acting upon it. DOSSIRI does not guarantee the accuracy, completeness, timeliness, or fitness for any particular purpose of any output generated by the Service. Human judgment remains responsible for all decisions and actions taken in connection with information provided by DOSSIRI.

DOSSIRI is:

  • A compliance-aware, intelligence-native customer relationship management platform
  • Decision-support software designed to help life sciences and regulated-industry sales professionals prepare for conversations, assess opportunities, accumulate account intelligence, and monitor territory signals
  • A tool that assists professional judgment — it does not replace it

DOSSIRI is not:

  • Legal advice or a substitute for legal counsel
  • Compliance advice or a substitute for compliance professionals or compliance management systems
  • Regulatory advice or a substitute for regulatory affairs professionals
  • Validation consulting or a substitute for validation engineers or quality professionals
  • Quality management software or a quality management system (QMS)
  • A 21 CFR Part 11 compliant system — DOSSIRI is not represented as such and users in FDA-regulated environments are responsible for evaluating its appropriateness for their regulated workflows
  • A system designed to store, process, or transmit Protected Health Information (PHI) as defined under HIPAA
  • An autonomous agent — DOSSIRI does not take actions on your behalf or make decisions for you
  • A guarantee of any business, sales, compliance, regulatory, or validation outcome

Specifically:

  • Intelligence outputs, including Briefs and Signals, are generated in part from publicly available data sources. DOSSIRI does not independently verify the accuracy or currency of third-party data used in generating intelligence outputs.
  • Opportunity Assessments (High Potential, Moderate Potential, Low Potential, Insufficient Information) reflect decision-support classifications based on available information. They are not predictions, guarantees, or professional assessments of any business, regulatory, or compliance outcome.
  • Signal information reflecting regulatory activity, clinical trial postings, procurement notices, or company events is derived from public sources and may be delayed, incomplete, or inaccurate. Users in regulated environments must independently verify any signal information before relying on it for business, compliance, or regulatory purposes.

Use of the Service does not create an attorney-client, consultant-client, compliance advisory, regulatory advisory, quality advisory, or other professional services relationship between DOSSIRI and any User or Organization.

12. Children

The Service is intended for business use by adults. The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected personal information from an individual under 18, we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice within the Service at least 30 days prior to the change becoming effective. The effective date at the top of this document reflects when this version took effect.

Continued use of the Service after a revised Privacy Policy takes effect constitutes acceptance of the revised Policy.

14. Contact Information

For privacy questions, requests to exercise your rights, or other inquiries related to this Privacy Policy, contact us at:

Privacy Inquiries: privacy@dossiri.com

General: hello@dossiri.com

End of Document — DOSSIRI LLC — Privacy Policy v1.1