Sloancode AI is an enterprise artificial intelligence platform, product, and services brand operated by Sloancode Technology Group LLC (“Sloancode Technology Group,” “Sloancode,” “Sloancode AI,” “we,” “us,” or “our”).
This Privacy Policy explains how Sloancode Technology Group LLC collects, receives, accesses, uses, processes, generates, stores, retains, discloses, transfers, protects, and deletes Personal Information in connection with Sloancode AI.
For purposes of this Privacy Policy, “Sloancode AI Services” means Sloancode AI websites, enterprise AI platforms, applications, AI solutions, Industry Clouds, artificial intelligence agents, conversational and voice AI capabilities, workflow automation capabilities, analytics and intelligence services, integrations, administrative interfaces, demonstrations, communications, and other Sloancode AI products and services.
Sloancode Technology Group LLC also provides consulting, technology, artificial intelligence, data, automation, strategy, transformation, and other services outside the Sloancode AI platform and brand. Those activities may be governed by the separate Sloancode Technology Group privacy policy, contractual terms, or another applicable notice.
This Privacy Policy should be read together with any applicable Sloancode AI Terms of Service, Master Services Agreement, Data Processing Addendum, product-specific terms, consent notice, Voice and Audio Privacy Notice, Cookie Policy, or other supplemental privacy notice.
Where a supplemental notice conflicts with this Privacy Policy for a particular processing activity, the more specific notice will govern that activity to the extent stated in that notice and permitted by law.
1. Purpose and Scope
This Privacy Policy applies to Personal Information processed by Sloancode in connection with Sloancode AI when you:
- visit a Sloancode AI website;
- contact Sloancode AI;
- request information, a demonstration, assessment, or sales consultation;
- create or administer an account;
- use a Sloancode AI product or platform;
- use or interact with an Industry Cloud;
- use an AI assistant, copilot, agent, chatbot, voice assistant, or automated workflow;
- place or receive a telephone call facilitated by a Sloancode AI service;
- exchange SMS, chat, messaging, email, or other communications through a Sloancode AI-enabled service;
- submit documents, prompts, questions, files, images, recordings, or other content;
- connect a third-party system to Sloancode AI;
- interact with a business or organization that uses Sloancode AI;
- participate in a demonstration, pilot, evaluation, or other Sloancode AI program;
- apply for employment specifically through a Sloancode AI recruitment channel; or
- otherwise interact with the Sloancode AI Services.
The Sloancode AI portfolio includes both cross-industry enterprise AI capabilities and industry-specific Industry Clouds.
Industry Clouds may include solutions designed for restaurants, field services, facilities operations, construction, property management, and other industries.
This Privacy Policy does not automatically apply to every service offered separately by Sloancode Technology Group LLC.
2. Definitions
For purposes of this Privacy Policy:
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual, household, or other protected person where applicable law provides such protection.
“Customer” means a business, enterprise, organization, or other entity that purchases, licenses, evaluates, configures, or uses Sloancode AI Services.
“Customer Content” means data, information, documents, communications, recordings, prompts, files, records, or other content supplied to or made available through Sloancode AI by or on behalf of a Customer or its users.
“End User” means an individual interacting with Sloancode AI directly or through a Customer, including a customer, caller, employee, contractor, resident, tenant, vendor, applicant, visitor, or other person, depending upon the Customer’s implementation.
“Processing” has the meaning assigned under applicable privacy law and includes collection, use, analysis, storage, transmission, generation, disclosure, alteration, retrieval, or deletion of Personal Information.
“Sensitive Personal Information” includes information treated as sensitive under applicable law, which may include certain government identifiers, account credentials, precise geolocation, financial information, health information, racial or ethnic information, religious beliefs, biometric identifiers, sexual orientation or sex-life information, citizenship or immigration status, genetic information, and certain information concerning children.
“De-identified Data” means information processed so that it cannot reasonably be associated with an identified or identifiable individual, subject to applicable law.
3. When Sloancode Acts as a Controller or Business
Sloancode may determine the purposes and means of Processing Personal Information when we process information for our own legitimate business purposes.
Examples may include website administration, account creation and administration, security and fraud prevention, platform authentication, billing and commercial administration, sales and marketing, product demonstrations, partner communications, customer-support administration, legal compliance, internal business operations, recruiting, platform telemetry and diagnostics, service reliability, abuse prevention, and certain product analytics.
Depending on the applicable law, Sloancode may be referred to in these circumstances as a controller, business, or similar regulated entity.
4. When Sloancode Acts as a Processor or Service Provider
A substantial portion of the information processed by Sloancode AI may be processed on behalf of our Customers.
For example, a Customer may use Sloancode AI to process customer orders, reservations, service appointments, calls, messages, work orders, maintenance requests, property records, operational information, customer support interactions, scheduling information, documents, or other Customer-controlled information.
When Sloancode processes Personal Information solely on the Customer’s documented instructions, the Customer generally determines the purpose and means of that Processing.
Sloancode may therefore act as a processor, service provider, or similar entity under applicable law.
Our processing of Customer Personal Information in this capacity may also be governed by a Data Processing Addendum or other contractual terms.
When Sloancode acts on behalf of a Customer, the Customer is generally responsible for:
- determining whether the Processing is lawful;
- providing applicable privacy notices;
- establishing an appropriate legal basis;
- obtaining required consents;
- responding to individuals’ privacy rights;
- configuring the service appropriately;
- determining appropriate retention periods;
- determining which individuals may access information;
- ensuring that connected systems are lawfully used; and
- complying with industry-specific requirements applicable to the Customer.
We will assist Customers with applicable privacy obligations to the extent required by law or contract.
5. Information We Collect or Process
The specific categories of information depend upon the Sloancode AI Service being used.
A. Identity Information
Examples include first and last name, customer or user identifier, account identifier, username, organization identifier, job title, and role.
B. Contact Information
Examples include email address, telephone number, business telephone number, mailing address, service address, business address, and other contact information.
C. Account and Authentication Information
Examples include account identifiers, authentication status, login timestamps, organizational membership, user permissions, user roles, multifactor authentication status, authentication and session information, and security events.
Authentication credentials may be processed through appropriate authentication systems and are not intended to be exposed through ordinary application interfaces.
D. Commercial and Transaction Information
Depending on the service, this may include purchases, orders, reservations, service requests, products or services requested, transaction identifiers, transaction status, pricing information, invoices, customer preferences, service history, and transaction-related records.
E. Customer and Operational Information
This may include business records, customer records, operational records, appointments, schedules, dispatch information, project information, work orders, asset information, maintenance information, property information, facility information, vendor information, workflow status, approvals, task history, and related operational records.
F. Communications Information
This may include messages, SMS communications, chat messages, emails, customer-support communications, social or messaging interactions, communication preferences, sender and recipient identifiers, delivery information, timestamps, and conversation history.
G. Voice and Audio Information
This may include telephone audio, voice recordings where recording is enabled, speech-to-text transcripts, call metadata, caller and recipient numbers, call duration, timestamps, call-routing information, conversation content, AI-generated voice responses, and call disposition or workflow information.
H. AI Interaction Information
This may include prompts, questions, instructions, conversational context, AI responses, model outputs, summaries, classifications, recommendations, evaluations, user feedback, tool requests, tool responses, agent actions, workflow results, and related contextual information.
I. Documents and Uploaded Content
This may include documents, PDFs, spreadsheets, text, images, business records, knowledge-base materials, forms, attachments, and other content intentionally uploaded or connected.
J. Integration Information
Where an authorized integration is used, we may process connected-account identifiers, integration configuration, API-related metadata, permitted records retrieved from a connected service, information transmitted to a connected service, and synchronization or event information.
K. Technical and Usage Information
This may include IP address, device type, browser type, operating system, application version, referring URL, pages viewed, actions taken, session identifiers, event logs, error information, performance data, approximate location inferred from IP address, diagnostic information, and security telemetry.
L. Preference and Consent Information
This may include privacy preferences, marketing preferences, cookie choices, SMS opt-in and opt-out status, recording consent where applicable, communication consent, consent timestamps, consent source, and withdrawal records.
M. Support Information
This may include support tickets, correspondence, troubleshooting information, screenshots, logs, diagnostic records, and other information submitted when obtaining support.
N. Professional and Business Information
This may include employer, business name, title, business responsibilities, professional interests, organization size, and business contact details.
6. Data-Category and Processing-Purpose Framework
The following table summarizes major processing categories.
| Information | Typical Purpose | Typical Source | Potential Recipients |
|---|---|---|---|
| Account / identity data | Authentication, account administration, support | User / Customer | Hosting, authentication, support providers |
| Contact information | Service delivery, communications, sales, support | Individual / Customer | Communications and service providers |
| Customer Content | Provide configured AI and product functions | Customer, End User, integration | Authorized subprocessors and integrations |
| Voice / audio | Provide voice AI, transcription, call workflows | Caller / Customer | Communications, speech, and AI providers |
| AI interactions | Generate responses, perform authorized workflows | User / Customer | Authorized AI and model infrastructure providers |
| Operational data | Fulfill Customer workflows and analytics | Customer / connected systems | Authorized integrations and subprocessors |
| Transaction data | Facilitate requested commercial workflows | Customer / End User / payment provider | Customer and payment provider |
| Technical data | Security, reliability, fraud prevention | Automatically collected | Hosting, security, monitoring providers |
| Consent / preference data | Honor communication and privacy choices | Individual / Customer | Communications and compliance providers |
| Sales / support data | Business communications and service support | Customer / prospect | CRM and support providers |
The precise Processing may differ by product configuration and Customer instructions.
7. Sources of Personal Information
We may obtain Personal Information directly from you; from a Customer; from authorized users; from End Users; automatically through use of the Services; from authorized connected systems; from service providers; from communications providers; from authentication providers; from payment providers; from partners; from publicly available sources; from Customer-authorized data sources; and from other lawful sources.
We do not authorize third parties to provide Sloancode with Personal Information that they do not have the right to provide.
8. How We Use Personal Information
Subject to our role, applicable agreements, and applicable law, Sloancode may process Personal Information to provide Sloancode AI Services; configure and administer accounts; authenticate users; provide AI responses; operate authorized AI agents; automate Customer workflows; process voice interactions; transcribe speech; facilitate communications; process service requests; maintain conversation context; retrieve authorized information; perform customer-authorized actions; support connected systems; maintain integrations; deliver operational analytics; produce reports or summaries; administer transactions; provide customer support; diagnose errors; monitor service availability; prevent fraud and abuse; secure Sloancode systems; investigate security incidents; enforce contractual terms; maintain business records; comply with law; respond to lawful governmental requests; manage our business; improve service reliability; conduct approved product development; communicate regarding Sloancode products and services; conduct sales and demonstrations; administer partnerships; perform recruiting activities; and protect Sloancode, Customers, End Users, and others.
We will not intentionally use Personal Information for a materially incompatible new purpose without providing any additional notice or obtaining consent required by applicable law.
9. Artificial Intelligence Processing
Sloancode AI uses artificial intelligence and related computational technologies to provide certain Services.
AI-related Processing may include natural-language understanding, speech recognition, speech generation, classification, summarization, retrieval, reasoning, recommendation generation, document analysis, structured data extraction, knowledge retrieval, workflow orchestration, tool invocation, agent execution, anomaly detection, analytics, and other AI-assisted functions.
Depending on the applicable Service, an AI system may process Customer Content together with conversation history, system instructions, Customer policies, configured knowledge, retrieved information, operational records, tool responses, and authorized third-party data.
AI-generated results may contain errors. Customers remain responsible for determining the appropriate degree of human review and oversight for their use case.
10. Customer Content and AI Model Training
Sloancode does not acquire ownership of Customer Content merely because Customer Content is processed through Sloancode AI.
Unless the Customer has affirmatively opted in, provided separate authorization, or entered into an agreement expressly permitting such use, Sloancode will not use Customer Content, including customer communications, prompts, documents, voice recordings, or transcripts, to train generalized Sloancode AI models for use across unrelated Customers.
Sloancode may process Customer Content as reasonably necessary to provide the contracted service, fulfill Customer instructions, maintain security, prevent abuse, troubleshoot service issues, meet legal obligations, and perform other processing expressly permitted by agreement or applicable law.
Where Sloancode offers an optional product-improvement, evaluation, fine-tuning, or model-improvement program involving Customer Content, participation will be governed by applicable contractual terms, notice, consent, and/or account settings.
Sloancode may use aggregated or De-identified Data for lawful analytics, security, performance measurement, capacity planning, and service improvement, provided that such Processing complies with applicable law.
11. Third-Party AI and Model Providers
Certain Sloancode AI Services may use third-party artificial intelligence, speech, cloud, infrastructure, or model providers.
Where used, Sloancode seeks to configure such providers in accordance with applicable Customer agreements, provider enterprise/API data controls, confidentiality obligations, data-protection requirements, security requirements, and Sloancode’s applicable subprocessor framework.
Sloancode does not rely solely on a provider’s public consumer terms when materially different enterprise or API terms govern the applicable service.
A current list of applicable subprocessors may be made available separately.
12. Retrieval-Augmented Generation, Knowledge Bases, and Embeddings
Some Sloancode AI Services may permit Customers to connect documents, databases, structured information, knowledge bases, or other content to AI functions.
Information may be indexed, segmented, transformed, embedded into numerical representations, retrieved, cached, or otherwise processed to permit authorized AI retrieval.
Such representations remain subject to applicable security, retention, access, and deletion controls.
Sloancode will not intentionally use one Customer’s private knowledge base to answer another unrelated Customer’s requests unless expressly authorized.
13. AI Memory and Conversational Context
Certain AI functions may retain conversation context or other information to provide continuity.
Depending on product configuration, context may be session-only, temporarily retained, retained as part of Customer records, or stored according to Customer-controlled retention settings.
The existence and duration of persistent memory may vary by product.
Sloancode will not represent transient model context as deleted if persistent copies are retained elsewhere in the Service.
14. AI Agents and Automated Actions
Some Sloancode AI Services may permit AI systems to interact with authorized tools, systems, APIs, or workflows.
Depending on Customer configuration, an AI agent may retrieve information, create records, update records, trigger workflows, schedule activities, send authorized communications, request approvals, generate recommendations, or perform other configured actions.
Access is intended to be limited to permissions and functions authorized for the applicable system and Customer.
Sloancode does not intend an AI agent to have unrestricted authority over Customer systems.
Customers are responsible for configuring appropriate authorization boundaries, permissions, human approvals, escalation rules, business policies, workflow limits, and supervisory controls.
15. Automated Decisionmaking and Profiling
Certain Sloancode AI functions may analyze information, generate recommendations, rank items, identify patterns, predict outcomes, or assist business decisionmaking.
Customers must determine whether a particular implementation constitutes regulated automated decisionmaking, profiling, or another legally regulated activity.
Where Sloancode itself uses covered automated decisionmaking technology and applicable law requires notice, access, opt-out rights, explanation, risk assessment, or other safeguards, Sloancode will implement applicable requirements.
Where Sloancode provides technology used by a Customer to make significant decisions, the Customer remains responsible for determining its legal obligations except to the extent Sloancode has expressly assumed obligations under applicable law or contract.
Sloancode AI should not be configured to make legally significant decisions concerning employment, housing, lending, insurance, healthcare access, education, criminal justice, or similarly consequential matters without appropriate legal review, safeguards, transparency, testing, and human oversight.
16. Voice, Telephone Calls, and Audio Processing
Certain Sloancode AI Services may support voice and telephone interactions.
Depending on the applicable Service and configuration, Sloancode may process live audio, telephone numbers, call routing, speech, transcriptions, recordings, call metadata, AI-generated speech, interaction history, and information communicated by participants.
The fact that audio is processed for speech recognition does not necessarily mean that a persistent recording is retained.
Where a call is recorded, appropriate notice or consent must be provided when required by applicable law.
Customer obligations may include determining whether calls may lawfully be recorded, whether one-party or all-party consent rules apply, what notice is required, whether recording must be disabled when consent is withheld, whether a recording may be retained, and how long it may be retained.
Sloancode may provide technical functionality to support compliant implementation, but Customers remain responsible for evaluating communications laws applicable to their own use.
17. Biometric and Voiceprint Data
Ordinary audio or a voice recording is not necessarily biometric information merely because it contains a person’s voice.
However, certain laws regulate voiceprints or other biometric identifiers when technology is used to identify or authenticate individuals based on biological characteristics.
Sloancode will not intentionally use voice recordings to create voiceprints or other biometric identifiers for identification or authentication unless the applicable Sloancode AI product expressly supports that functionality, the use has been approved for the Customer implementation, required notices are provided, required consent or written release is obtained, required retention and destruction rules are implemented, and applicable contractual and legal requirements are satisfied.
If Sloancode introduces voice-biometric authentication or identification, a dedicated Biometric Information and Retention Policy should be implemented before deployment.
18. SMS, Messaging, Chat, Email, and Communications
Sloancode AI may facilitate communications over SMS, voice, email, web chat, messaging applications, supported social messaging channels, and other communications channels.
Information may include content, telephone numbers, email addresses, identifiers, timestamps, delivery status, conversation history, opt-in status, opt-out status, consent records, and channel metadata.
Customers are responsible for establishing legally appropriate communication practices, including distinguishing transactional or service communications from marketing communications when legally relevant.
Where applicable, Sloancode and its Customers must honor legally valid revocation or opt-out requests.
19. Third-Party Integrations
Customers may authorize Sloancode AI to connect with third-party platforms, including point-of-sale platforms, scheduling systems, CRM platforms, ERP platforms, property-management systems, facilities-management systems, field-service platforms, delivery services, communications providers, payment providers, accounting systems, workforce systems, cloud applications, storage platforms, databases, and other business applications.
Once enabled, information may flow between Sloancode AI and the connected system as necessary to perform Customer-authorized functions.
Customers are responsible for ensuring that they have authority to connect and disclose data from third-party systems.
Independent third parties may process information under their own privacy policies and contractual terms.
20. Payments and Payment-Related Data
Sloancode AI may facilitate workflows involving purchases or payments.
Where payment processing is provided through an independent payment processor, Sloancode seeks to avoid unnecessary receipt or storage of complete payment-card credentials.
Sloancode may process transaction-related information such as amount, currency, transaction identifier, status, merchant identifier, time, payment-method category, invoice or order association, and other transaction metadata.
Payment information directly submitted to an independent payment processor is also governed by that provider’s policies and terms.
Nothing in this Privacy Policy represents that all Sloancode AI Services are certified under the Payment Card Industry Data Security Standard.
21. Sensitive and Regulated Information
Sloancode AI may be capable of processing information that is legally sensitive. However, technical capability does not mean that every Sloancode AI Service is approved for every category of regulated information.
Unless Sloancode expressly authorizes a use through applicable product documentation or agreement, Customers should not submit specially regulated information requiring specialized contractual or technical treatment, including where applicable protected health information, biometric identifiers, genetic information, full payment-card credentials, Social Security numbers, government-issued identifiers, highly sensitive financial credentials, consumer health data, information regarding children, criminal-history information, or other specially regulated information.
Where a Customer requires processing regulated by HIPAA, GLBA, FERPA, biometric laws, consumer-health-data laws, or other specialized regimes, the Customer must confirm with Sloancode that the applicable product and contractual framework support the proposed Processing before use.
Sloancode does not represent through this Privacy Policy alone that it is a HIPAA Business Associate, PCI-certified service provider, regulated financial institution, or otherwise qualified for a particular regulated workload.
22. Children’s Privacy
Sloancode AI Services are principally intended for businesses and organizations and are not directed to children under 13.
Sloancode does not knowingly solicit Personal Information directly from children under 13 through its general-purpose business services.
Customers must not configure general-purpose Sloancode AI Services to intentionally collect Personal Information from children where doing so would violate applicable law.
Where a specific product legitimately supports interactions involving minors, Sloancode and the Customer must establish any required parental consent, age verification, privacy notice, restricted processing, retention, and deletion mechanisms.
If Sloancode learns that Personal Information from a child was collected in violation of applicable law, we will take appropriate steps to address the information.
23. Cookies and Similar Technologies
Sloancode AI websites may use cookies, pixels, local storage, SDKs, or similar technologies for purposes such as essential site functionality, authentication, security, preferences, performance, diagnostics, analytics, and other disclosed purposes.
Where legally required, non-essential cookies will be subject to applicable consent or opt-out controls.
Detailed information regarding categories of cookies, specific providers, duration, and user choices should be maintained in a separate Cookie Policy or consent-management interface.
Cookie disclosures must reflect the technologies actually deployed on the website.
24. Online Advertising and Targeted Advertising
Sloancode must disclose its actual advertising practices accurately.
If Sloancode processes Personal Information for targeted advertising, cross-context behavioral advertising, sale, or sharing as those terms are defined under applicable law, Sloancode will provide applicable disclosure and opt-out mechanisms.
Before this Privacy Policy goes live, Sloancode must verify whether the production Sloancode AI website deploys advertising pixels, retargeting technologies, or other technologies that constitute sale, sharing, or targeted advertising under applicable law.
This cannot be resolved through legal drafting alone; it must be validated against the live website configuration.
25. Sale or Sharing of Personal Information
Sloancode does not treat disclosures to processors or service providers acting under appropriate contractual restrictions as a “sale” merely because information is transmitted to those providers.
However, statutory definitions of sale and sharing vary.
Where Sloancode engages in Processing legally defined as sale or sharing, affected individuals will be provided the disclosures and rights required by applicable law.
The final published version of this section must affirmatively state whether Sloancode presently sells or shares Personal Information after the website’s analytics and advertising configuration is verified.
26. Global Privacy Control and Universal Opt-Out Signals
Where required by applicable law, Sloancode will recognize legally applicable browser-based or device-based universal opt-out preference signals.
If Sloancode’s activities trigger such obligations, the technical platform—not merely this Privacy Policy—must honor qualifying signals.
27. De-Identified and Aggregated Information
Sloancode may create or receive De-identified or aggregated information.
Where information is maintained as legally de-identified, Sloancode will take measures required by applicable law, which may include maintaining it in de-identified form, not attempting to re-identify individuals except as permitted for testing de-identification controls, and requiring recipients to comply with applicable restrictions.
Sloancode may use properly aggregated or De-identified Data for lawful purposes including security, service performance, reliability analysis, product analytics, benchmarking where lawful, capacity planning, research, and service improvement.
De-identification will not be used as a label for data that can readily be re-associated with an individual.
28. How We Disclose Personal Information
Sloancode may disclose Personal Information to service providers and subprocessors; Customer-authorized third parties; Customers; professional advisers; legal authorities; parties involved in security and protection activities; and parties to corporate transactions, in each case as permitted by applicable law and relevant agreements.
We do not authorize service providers to use Personal Information for unrelated purposes merely because they receive information from Sloancode.
29. Subprocessors
Enterprise Customers may depend upon third-party subprocessors for portions of the Sloancode AI service.
Rather than permanently embedding a vendor list into this Privacy Policy, Sloancode should maintain a separate, current Subprocessor List containing appropriate information concerning material subprocessors.
Where contractually required, Customers may receive notice of certain material changes to subprocessors.
30. Data Retention
Sloancode retains Personal Information only for as long as reasonably necessary for legitimate and disclosed purposes, subject to Customer instructions, Customer configuration, applicable contracts, legal obligations, security requirements, dispute preservation, fraud prevention, backup lifecycle, audit requirements, and technical limitations reasonably necessary to operate the service.
Different categories of information may have different retention periods.
Retention may depend upon the nature of the data, the applicable Industry Cloud, the sensitivity of the information, whether an account remains active, Customer-selected configuration, legal requirements, security considerations, and the purpose of Processing.
Where applicable, information may be deleted, anonymized, de-identified, archived under restricted access, or otherwise disposed of when retention is no longer required.
Sloancode should maintain an internal Data Retention Schedule corresponding to the public commitments in this section.
31. Backups and Deletion
Deletion from an active production environment may not result in instantaneous deletion from every backup.
Information may remain in encrypted or protected backups until overwritten or deleted in accordance with applicable backup-retention schedules.
Backup copies should not be restored for ordinary business use after an applicable deletion request except where necessary for security, disaster recovery, legal obligations, or other lawful purposes.
Where restored, applicable deletion controls should be reapplied where technically and legally appropriate.
32. Information Security
Sloancode maintains administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, loss, misuse, or compromise.
Depending on the applicable system, safeguards may include authentication controls, role-based access controls, least-privilege principles, encryption, tenant-separation controls, credential protection, production/environment separation, logging, security monitoring, vulnerability management, secure development practices, access review, backup and recovery, incident-response procedures, vendor-risk controls, and other security measures.
No information system is completely secure. Accordingly, Sloancode cannot guarantee absolute security.
This Privacy Policy does not claim that Sloancode holds SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or any other certification or attestation unless and until that status is separately verified and expressly published.
33. Security and Privacy Incidents
Sloancode maintains processes designed to identify, investigate, contain, remediate, and document security or privacy incidents.
Where a breach or security incident triggers a notification obligation under applicable law or contract, Sloancode will provide notification in accordance with applicable requirements.
When Sloancode acts as a processor for a Customer, incident-notification responsibilities may also be governed by the applicable Data Processing Addendum or customer agreement.
Nothing in this policy should be interpreted as promising notification for events that do not legally or contractually constitute reportable incidents.
34. International Data Processing
Sloancode Technology Group LLC operates from the United States.
Personal Information may be processed in the United States and other locations where Sloancode or its approved service providers operate.
Those jurisdictions may have privacy laws different from the jurisdiction where information originated.
Where applicable law requires a recognized transfer mechanism, Sloancode will implement an appropriate mechanism before relying upon the transfer.
Sloancode does not claim universal compliance with the GDPR, UK GDPR, or another international privacy regime merely because its website may be accessible internationally.
Where Sloancode deliberately offers covered services into jurisdictions requiring additional controller/processor terms, international-transfer mechanisms, representatives, or notices, those requirements will be addressed through appropriate supplemental documentation and contracts.
35. Privacy Rights
Depending upon applicable law and Sloancode’s role, individuals may have rights to confirm whether Personal Information is processed; access Personal Information; obtain a copy; correct inaccurate information; request deletion; request portability; opt out of sale; opt out of sharing; opt out of targeted advertising; opt out of certain profiling; limit certain uses of Sensitive Personal Information; withdraw consent; obtain information concerning certain automated decisions; appeal a denied privacy request; and exercise other rights provided by law.
Rights may be subject to jurisdictional limitations, statutory exemptions, identity verification, legal retention requirements, contractual restrictions, security requirements, and other lawful exceptions.
Sloancode will not unlawfully discriminate against an individual for exercising applicable privacy rights.
36. How to Exercise Privacy Rights
Where Sloancode is responsible for responding to your request, you may submit a request through:
- Privacy Email: [INSERT DEDICATED PRIVACY EMAIL]
- Privacy Request Form: [INSERT PRIVACY REQUEST URL]
- Telephone: [INSERT NUMBER IF USED FOR RIGHTS REQUESTS]
Sloancode may request information reasonably necessary to identify the request, authenticate the requester, locate applicable records, prevent fraudulent requests, and determine which law applies.
We will not require collection of unnecessary Personal Information merely to verify a request.
37. Request Verification
We may verify a privacy request by comparing information provided with information already maintained by Sloancode.
The level of verification may vary depending on the nature of the request, the sensitivity of the information, risk of unauthorized disclosure, and applicable law.
If we cannot reasonably verify a request, we may deny or limit the request where permitted by law and explain the basis for that decision.
38. Authorized Agents
Where applicable law permits an authorized agent to make a request on an individual’s behalf, Sloancode may require evidence that the agent has authority to act, the individual’s identity can be verified, and applicable statutory requirements have been satisfied.
We will not impose verification requirements inconsistent with applicable law.
39. Response Timing
Sloancode will respond to validated privacy requests within the period required by applicable law.
Many U.S. comprehensive state privacy statutes use an initial 45-day response period, subject to authorized extensions in certain circumstances.
Where required, we will notify the requester if additional time is reasonably necessary and provide the reason for the extension.
40. Appeals
Where applicable law provides a right to appeal a denied privacy request, Sloancode will provide an appeal mechanism.
Appeals may be submitted through: [INSERT APPEAL PROCESS/PRIVACY REQUEST FORM].
If an appeal is denied, Sloancode will provide additional information required by applicable law, which may include information concerning how to contact the appropriate state regulator.
41. Requests Involving Customer-Controlled Information
If Sloancode processes your Personal Information solely on behalf of a Customer, you should normally submit your request directly to that Customer.
Examples may include information processed for a restaurant, property manager, field-service provider, facilities organization, construction organization, or another Sloancode AI Customer.
Where legally or contractually required, Sloancode will assist the Customer in responding to the request.
We will not independently override a Customer’s lawful instructions where Sloancode acts solely as processor unless required by applicable law.
42. California Privacy Disclosures
Where the California Consumer Privacy Act, as amended, applies, California residents may have rights concerning access/knowledge, correction, deletion, portability, sale or sharing, certain uses of Sensitive Personal Information, non-discrimination, and certain automated decisionmaking activities.
The categories of Personal Information Sloancode may process, sources, purposes, and categories of recipients are described throughout this Privacy Policy.
Where legally required, Sloancode will provide a Notice at Collection at or before the applicable point of collection.
If Sloancode sells or shares Personal Information as those terms are defined by California law, applicable opt-out functionality will be provided.
If Sloancode engages in activities subject to California risk-assessment, cybersecurity-audit, or automated decisionmaking requirements, applicable compliance procedures will be implemented according to the required timetable.
43. Other U.S. State Privacy Rights
Residents of other U.S. states may have additional rights where comprehensive state privacy laws apply.
Depending on the applicable law, these may include rights concerning access, deletion, correction, portability, targeted advertising, sale, profiling, sensitive information, consent, appeals, and universal opt-out mechanisms.
Sloancode will apply jurisdiction-specific requirements where applicable.
Privacy rights differ by state, and not all rights apply to all individuals, businesses, information, or processing activities.
44. Consumer Health Data
Some jurisdictions regulate consumer health information outside traditional HIPAA frameworks.
Unless an applicable Sloancode AI product is expressly approved for such Processing, Customers should not use Sloancode AI to intentionally collect or process specially regulated consumer health data requiring specialized notices, consent, geofencing restrictions, authorization, or other controls without confirming that the applicable legal and product requirements have been satisfied.
Where Sloancode intentionally offers a product within the scope of a consumer-health-data statute, Sloancode will provide any additional consumer health data privacy policy or consent mechanisms required by law.
45. Job Applicants and Workforce Information
Where Sloancode AI itself collects information from applicants, employees, contractors, or other workforce participants, information may include contact details, employment history, education, qualifications, résumé information, interview information, professional references, work eligibility information, and other recruitment-related information.
Additional workforce or applicant privacy notices may apply where required.
Customer use of Sloancode AI in employment contexts remains subject to the Customer’s own legal obligations, including any applicable laws governing automated employment decision tools, discrimination, notice, consent, or human review.
46. Business-to-Business Contact Information
We may process business contact information concerning employees, representatives, or agents of Customers, prospects, vendors, and partners for purposes including business communications, contract administration, demonstrations, relationship management, support, invoicing, security, and legitimate business development.
Where applicable privacy laws grant rights concerning such information, those rights will be honored as required.
47. Marketing Communications
Sloancode may send information regarding Sloancode AI products, services, events, resources, or business developments where legally permitted.
Recipients may unsubscribe from applicable marketing communications by using the provided opt-out mechanism.
An opt-out from marketing communications does not necessarily prevent Sloancode from sending security notices, service notifications, transaction-related messages, account communications, legal notices, or other non-marketing communications reasonably necessary to provide a service.
48. Do Not Track
Browser “Do Not Track” signals historically have not had a uniform legal or technical standard.
Where applicable law requires Sloancode to recognize a legally valid opt-out preference mechanism such as Global Privacy Control, we will do so as described above.
This distinction should not be confused with legacy Do Not Track browser settings.
49. Third-Party Websites
Sloancode AI may link to independent websites or services.
Sloancode does not control the privacy practices of independent third parties merely because a link appears on a Sloancode website.
Individuals should review the third party’s privacy terms before providing information to that provider.
50. Corporate Transactions
Personal Information may be transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, change of control, bankruptcy, or similar corporate transaction.
Any successor’s use of Personal Information remains subject to applicable law and any continuing enforceable privacy obligations.
51. Legal Requests and Preservation
Sloancode may preserve or disclose information when reasonably necessary to comply with law; comply with court orders; respond to valid legal process; enforce contractual rights; investigate unlawful activity; protect Sloancode; protect Customers; protect End Users; protect public safety; or establish, exercise, or defend legal claims.
Where legally permitted and appropriate, Sloancode may seek to limit overly broad requests.
52. Data Minimization and Purpose Limitation
Sloancode’s privacy program is intended to support collection and Processing proportionate to legitimate business purposes.
Sloancode seeks to avoid collecting information that is unnecessary for the relevant service.
Customers should likewise configure Sloancode AI to avoid unnecessary collection of Personal Information.
Privacy disclosures and product configurations should be reassessed when a material new category of data or materially different processing purpose is introduced.
53. Privacy by Design and Default
Where appropriate to the applicable service, Sloancode seeks to incorporate privacy safeguards into product design, including consideration of minimization, access control, retention, consent, user choice, customer configuration, data isolation, deletion, auditability, transparency, security, and human oversight.
Privacy by design does not eliminate the Customer’s obligation to determine whether its own use of Sloancode AI complies with applicable law.
54. Privacy Risk Assessments
Where applicable law requires a data-protection or privacy risk assessment for particular Processing, Sloancode will perform or support applicable assessments within the scope of its legal responsibility.
Potentially relevant Processing may include Sensitive Personal Information, targeted advertising, sale of Personal Information, significant automated decisionmaking, certain profiling, biometric Processing, systematic monitoring, and other higher-risk Processing defined by applicable law.
Customers remain responsible for their own legally required assessments when they determine the relevant purposes and means of Processing.
55. Customer Responsibilities
Customers must use Sloancode AI lawfully.
Without limiting other contractual obligations, Customers are responsible for providing legally required notices; obtaining legally required consent; establishing lawful Processing purposes; obtaining permission to submit Customer Content; honoring individual rights; honoring communication preferences; configuring recording appropriately; managing user access; protecting Customer credentials; configuring retention; securing connected systems; supervising users; establishing human review; establishing appropriate AI authority; determining whether sensitive information may be processed; and complying with laws applicable to the Customer’s industry.
Sloancode AI does not replace legal, regulatory, professional, or compliance advice.
56. Changes to This Privacy Policy
Sloancode may update this Privacy Policy to reflect changes to our Services, new products, new Industry Clouds, changes to technology, changes to subprocessors, changes to Processing, legal developments, regulatory requirements, security changes, or business developments.
We will update the Last Updated date when the Privacy Policy changes.
Where legally required, we will provide additional notice before material changes take effect.
We will not rely on a silent or retroactive privacy-policy amendment to materially expand the use of previously collected Personal Information where notice, consent, or other legal authorization is required.
57. Relationship to Sloancode Technology Group LLC
Sloancode AI is operated by Sloancode Technology Group LLC.
Sloancode Technology Group LLC independently offers technology, consulting, artificial intelligence, data, automation, transformation, and industry-related solutions that are not necessarily part of Sloancode AI.
This Privacy Policy applies specifically to the Sloancode AI Services described herein.
Other Sloancode Technology Group websites, services, consulting engagements, assessments, solutions, or business activities may be governed by the Sloancode Technology Group Privacy Policy or another applicable notice.
This separation is intentional and does not establish Sloancode AI as the umbrella for all services offered by Sloancode Technology Group LLC.
58. Contact and Privacy Requests
Questions about this Privacy Policy or Sloancode AI privacy practices may be directed to:
Sloancode Technology Group LLC
Attn: Sloancode AI Privacy
99 Wall Street
Suite 3772
New York, NY 10005
United States
Privacy Email: Privacy@sloancode.com
Privacy Request Portal: www.sloancode.com
Telephone: (888) 419-2452
If you believe Sloancode is processing your information solely on behalf of a Sloancode AI Customer, you may also contact that Customer directly.
59. Supplemental Notices
Depending upon the applicable feature, jurisdiction, or Customer implementation, Sloancode may provide additional notices concerning cookies, voice and audio, biometric information, consumer health data, AI and automated decisionmaking, California collection practices, international privacy, workforce data, specific Industry Clouds, or other specialized Processing.
Such notices supplement this Privacy Policy.
60. Effective Implementation
This Privacy Policy describes Sloancode’s intended privacy framework.
Sloancode’s production systems, contracts, administrative practices, Customer documentation, subprocessors, website technologies, consent mechanisms, retention schedules, and privacy workflows must be configured consistently with the representations made in this Privacy Policy.
Where an implementation differs materially from this Privacy Policy, Sloancode must correct the implementation or revise the disclosure, subject to applicable law, rather than knowingly maintaining an inaccurate privacy representation.
Additional Contact Information:
Legal: legal@sloancode.com
Support: support@sloancode.com
Privacy: privacy@sloancode.com