Legal
Privacy Policy
In plain language
Who we are: Mobilyze, Inc., a Delaware corporation that operates a partner revenue SaaS platform with AI-powered features (the “Platform”).
What we collect: Account information, content you upload (Contributed Data), activity data, and limited technical and cookie data.
Why we collect it: To provide the Platform and its features, secure it, and comply with applicable law. Certain optional features require your separate consent.
What this Policy covers: How we collect, use, share, and protect Personal Data when you use the Platform as a personal account user or as an Authorized User of a Corporate Workspace.
Your rights: Depending on where you live, you may have rights to access, correct, delete, port, object to, or restrict our processing of your Personal Data, and to withdraw consent. See Section 10.
How to reach us: privacy@mobilyze.net or dpo@mobilyze.net.
Jump to section ▾
- 1 Scope & relationship
- 2 Controller & processor roles
- 3 Personal data we collect
- 4 How & why we use data
- 5 Personal-No-Link data
- 6 Sharing & disclosure
- 7 International transfers
- 8 Data retention
- 9 Security
- 10 Your rights
- 11 Cookies & technologies
- 12 Automated decisions & AI
- 13 Contact & representatives
- 14 Changes to this Policy
- Jurisdiction addenda
1 Scope and Relationship to Other Documents
This Privacy Policy applies to:
- Visitors to Mobilyze’s website;
- Users of a Mobilyze Personal Account; and
- Authorized Users of a Corporate Workspace.
This Policy is incorporated by reference into the Personal Account Terms of Service (the “Personal Terms”) and supplements the Cookie Policy. Defined terms used but not defined in this Policy have the meanings given to them in the Personal Terms or, for Corporate Workspace contexts, the Corporate Customer Agreement (the “CCA”).
Order of precedence
In the event of any conflict between this Policy and the Personal Terms or the CCA, the Personal Terms or CCA, as applicable, control. This Policy does not create contractual commitments beyond those set forth in the Personal Terms or CCA.
2 Controller and Processor Roles
Personal account users and website visitors. For Personal Account users and website visitors, Mobilyze, Inc. is the data controller (or “business” under CCPA/CPRA).
Corporate Workspace data. For Personal Data uploaded to or processed within a Corporate Workspace, the Corporate Customer is the controller and Mobilyze is the processor, acting solely on the Corporate Customer’s instructions as set forth in the CCA and the applicable Data Processing Addendum (“DPA”). Individual Authorized Users should contact their Corporate Customer administrator regarding processing of their data within a Corporate Workspace.
Personal-No-Link-to-Company Data. Personal Data designated as Personal-No-Link-to-Company Data under the Personal Terms is processed by Mobilyze as controller, solely to deliver the individual user’s personalized Platform experience within their active session, as described in Section 5 below.
3 Personal Data We Collect
We collect the following categories of Personal Data, depending on how you use the Platform:
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email address, username, user ID | You; Corporate Customer administrator |
| Account and Profile Data | Role, preferences, MFA factors, career history | You |
| Contact and Network Data | Contact records uploaded for partner relationship management | You; integrations you authorize |
| Commercial and CRM Data | Deal pipelines, opportunity data, revenue figures | You; CRM integrations you authorize |
| Usage and Device Data | IP address, browser type, operating system, session logs, clickstreams | Automated collection |
| Cookie and Tracking Data | Cookie identifiers, local storage values, pixel data | Automated collection; see Cookie Policy |
| Communications Data | Support tickets, emails, in-platform messages | You |
| Payment Data | Billing contact information, payment token (payment card data is processed directly by our payment processor and is not stored by Mobilyze) | You; payment processor |
| Inferences | AI-derived scores, partner match recommendations, PTAM calculations | Automated; Platform AI Features |
Sensitive Personal Data. We do not intentionally collect Sensitive Personal Data (as defined under GDPR Article 9 or CPRA) through the Platform. If you believe Sensitive Personal Data has been submitted, contact us at privacy@mobilyze.net.
Children. The Platform is not directed to persons under 18. We do not knowingly collect Personal Data from minors. If you believe a minor has provided Personal Data, contact us at privacy@mobilyze.net for deletion.
4 How and Why We Use Personal Data
4.1 Purposes and Legal Bases
| Purpose | Legal Basis (GDPR/UK GDPR) | US Law Equivalent |
|---|---|---|
| Provide and operate the Platform, including all Platform AI Features as core service delivery | Performance of contract (Art. 6(1)(b)) | Necessary to perform the contract |
| Authenticate users and secure accounts | Legitimate interests (Art. 6(1)(f)) — security and fraud prevention | Legitimate operational purpose |
| Communicate Platform updates, support responses, and policy changes | Performance of contract / Legitimate interests (Art. 6(1)(b)/(f)) | Necessary to perform the contract |
| Comply with legal, regulatory, tax, and accounting obligations | Legal obligation (Art. 6(1)(c)) | Legal duty |
| Detect and prevent fraud, abuse, and policy violations | Legitimate interests (Art. 6(1)(f)) | Legitimate operational purpose |
| Personalization Learning (optional) | Consent (Art. 6(1)(a)) — separately obtained, unbundled opt-in | Opt-in consent |
| Tier 1 Aggregated Improvement (Corporate Workspace opt-in) | Consent from Corporate Customer administrator (Art. 6(1)(a)) | Opt-in consent |
| Tier 2 Proprietary Model Training (Order Form opt-in) | Separate written consent in Order Form (Art. 6(1)(a)) | Opt-in consent |
| Marketing to prospects | Consent or legitimate interests, depending on jurisdiction | Opt-in where required by applicable law |
4.2 Platform AI Features
Platform AI Features — including Partner Match Scoring, PTAM Scoring, Program Recommendation Engine, Deal Room Intelligence, Territory Mapping Analysis, Co-Sell Motion Suggestions, Presentation Generation, and Anomaly Detection — are integral, named components of the Platform. They are not optional add-ons, secondary data uses, or data monetization activities. Processing by Platform AI Features constitutes core service delivery under the Personal Terms and the CCA, and does not require a separate consent or opt-in. A full description of each Platform AI Feature and how it processes your data is set forth in Section 6.2 of the Personal Terms.
Platform AI Features generate probabilistic outputs that are decision-support tools only. They do not constitute professional, legal, financial, or commercial advice, and do not constitute automated decision-making with legal or similarly significant effects within the meaning of GDPR Article 22. Where any Platform AI Feature is classified as high-risk under the EU AI Act or the Colorado AI Act, Mobilyze will cooperate with the applicable Corporate Customer to satisfy classification, documentation, transparency, human oversight, and impact assessment obligations, as provided in the CCA.
4.3 Personalization Learning
Personalization Learning is an optional feature that is OFF by default. It is activated only by your affirmative, unbundled, specific opt-in through your personal account settings. When enabled, Personalization Learning uses your own Platform activity signals — navigation patterns, feature usage, search history, and content interaction history — to improve your individual experience. It does not use raw CRM contact data, commercial transaction amounts, or data from any other user or customer. Full details of what Personalization Learning does and does not do, and how to withdraw consent, are set forth in Section 6.3 of the Personal Terms and are summarized in Section 10.4 of this Policy.
4.4 Tier 1 and Tier 2
Tier 1 (Aggregated Improvement) and Tier 2 (Proprietary Model Training) are Corporate Workspace-level data use elections described in the CCA. They are OFF by default and require separate, affirmative opt-in by the Corporate Customer. Individual users cannot activate Tier 1 or Tier 2. This Policy does not restate the full Tier 1 and Tier 2 terms, which are set forth in the CCA.
5 Personal-No-Link-to-Company Data
Contributed Data that you upload to your Personal Account is, by default, designated as Personal-No-Link-to-Company Data under the Personal Terms. Mobilyze processes Personal-No-Link-to-Company Data solely to deliver your individual personalized Platform experience — specifically, search, retrieval, and on-demand summarization scoped to your active session. It is not shared with any Corporate Workspace, other user, or third party, and is not used for Tier 1 or Tier 2 processing. Mobilyze’s role with respect to Personal-No-Link-to-Company Data is analogous to that of a consumer cloud storage provider. Full details are set forth in Sections 4.7 and 6.2.5 of the Personal Terms.
7 International Data Transfers
Mobilyze is based in the United States. If you are located in the EU, EEA, or UK, your Personal Data may be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home country.
For transfers of Personal Data out of the EEA, UK, or other jurisdictions requiring transfer safeguards, we rely on the following mechanisms as applicable:
- EU Standard Contractual Clauses (Module 2 or Module 3, as applicable) approved by the European Commission;
- UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as approved by the UK Information Commissioner’s Office;
- Adequacy decisions issued by the European Commission or UK Secretary of State, where available.
Transfer Impact Assessments and data transfer summaries are available upon request at /privacy/transfers.
8 Data Retention
We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. The following general retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account and profile data | Duration of account, plus up to 12 months following account deletion for legal and audit purposes |
| Contributed Data (Personal Account) | Until deleted by you; deleted within 30 days of account deletion |
| Contributed Data (Corporate Workspace) | Until deleted by Corporate Customer administrator; deleted within 30 days of contract termination per the CCA |
| Usage and security logs | Up to 24 months |
| Support and communications data | Up to 36 months |
| Billing and tax records | As required by applicable law, typically 7 years |
| Personalization Learning behavioral data | Deleted within 30 days of consent withdrawal |
| Backup copies | Overwritten on a rolling basis within 35 days |
Retention periods may be extended where required by applicable law, valid legal process, or to resolve an active dispute.
9 Security
We implement administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Personal Data. These measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, multi-factor authentication for administrative access, vulnerability scanning, intrusion detection and anomaly monitoring, tenant isolation, and per-tenant encryption key management. Full details of our security measures are set forth in Section 9.1 of the CCA.
No security measure is impenetrable. We do not warrant that the Platform will be free from all security vulnerabilities.
Data breach notification. In the event of a confirmed Security Incident involving unauthorized access to Personal Data, we will notify affected Corporate Customers and, where required by applicable law, relevant supervisory authorities and affected individuals, in accordance with applicable legal requirements including GDPR Articles 33 and 34 and applicable US state breach notification laws. Notification timing will be in accordance with applicable law.
10 Your Rights
10.1 Rights Available to All Users
Subject to applicable law and certain exceptions, you may have the right to:
- Access the Personal Data we hold about you;
- Correct inaccurate or incomplete Personal Data;
- Delete your Personal Data (subject to legal retention obligations);
- Restrict certain processing of your Personal Data;
- Object to processing based on legitimate interests;
- Port your Personal Data in a machine-readable format; and
- Withdraw consent at any time for processing based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@mobilyze.net or use our rights request portal at /privacy/requests. We will respond within applicable statutory timeframes, typically within 30 days.
10.2 EU and EEA Users — GDPR Rights
If you are located in the EU or EEA, you have the rights described in Section 10.1 as provided by GDPR Articles 15 through 22. You also have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
For data processed within a Corporate Workspace, your rights requests should be directed to the Corporate Customer as controller. We will assist the Corporate Customer in fulfilling data subject rights requests as required by the DPA.
10.3 UK Users — UK GDPR Rights
If you are located in the United Kingdom, you have equivalent rights under the UK GDPR and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk.
10.4 California Users — CCPA/CPRA Rights
If you are a California resident, you have the following rights under the CCPA/CPRA:
- Right to Know: The categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it;
- Right to Delete: Deletion of your Personal Information, subject to certain exceptions;
- Right to Correct: Correction of inaccurate Personal Information;
- Right to Opt Out of Sale or Sharing: We do not sell Personal Information or share it for cross-context behavioral advertising. To submit a request regarding these rights, visit /privacy/do-not-sell;
- Right to Limit Use of Sensitive Personal Information: We do not use or disclose Sensitive Personal Information beyond the purposes permitted by the CPRA without your consent;
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To submit a CCPA/CPRA rights request, contact us at privacy@mobilyze.net or visit /privacy/requests. We will verify your identity before processing your request.
Categories of Personal Information collected in the past 12 months (CCPA/CPRA disclosure):
| CCPA Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, user ID, IP address | Yes |
| Personal information under Cal. Civ. Code §1798.80 | Name, address, payment information | Yes (limited) |
| Commercial information | Transaction history, subscription data | Yes |
| Internet or electronic network activity | Usage logs, clickstreams, session data | Yes |
| Inferences | AI-derived scores and recommendations | Yes |
| Sensitive personal information | Not intentionally collected | No |
10.5 Other US State Privacy Rights
If you are a resident of Colorado, Virginia, Texas, Connecticut, Oregon, or another US state with a comprehensive privacy law, you may have rights similar to those described in Sections 10.1 and 10.4, including the right to appeal a denied request. To submit a request or appeal, contact us at privacy@mobilyze.net. We will respond in accordance with applicable state law.
10.6 Personalization Learning — Withdrawal of Consent
If you have opted into Personalization Learning, you may withdraw your consent at any time by toggling the Personalization Learning control to OFF in your personal account settings. Upon withdrawal, Mobilyze will immediately cease collecting new activity signals for Personalization Learning purposes, and behavioral data used solely for Personalization Learning will be deleted within 30 days. Withdrawal does not affect your access to any Platform AI Feature or any other aspect of the Platform. Full details are set forth in Section 6.3.4 of the Personal Terms.
12 Automated Decision-Making and AI
Platform AI Features generate probabilistic outputs — including partner match scores, PTAM calculations, program recommendations, territory maps, and co-sell suggestions — that are decision-support tools only. They are not automated decisions with legal or similarly significant effects within the meaning of GDPR Article 22 or equivalent laws, and do not constitute professional, legal, financial, or commercial advice. You retain sole responsibility for any decisions made based on Platform AI Feature outputs. A full description of Platform AI Features is set forth in Section 6.2 of the Personal Terms.
Where any Platform AI Feature is or becomes subject to the EU AI Act, the Colorado AI Act, or equivalent AI governance regulation, Mobilyze will cooperate with the applicable Corporate Customer to satisfy applicable obligations. Individual users who have questions about AI-driven outputs affecting them should contact their Corporate Customer administrator or us at privacy@mobilyze.net.
13 Contact and Representatives
| Role | Contact |
|---|---|
| Mobilyze Privacy Team | [object Object] |
| Data Protection Officer (DPO) | [object Object] |
| EU Representative (GDPR Art. 27) | [EU_REP_NAME], [EU_REP_CONTACT] |
| UK Representative (UK GDPR Art. 27) | [UK_REP_NAME], [UK_REP_CONTACT] |
| Mailing Address | [ADDRESS] |
14 Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated at least 30 days before the effective date where feasible, by email to the address on your account or by prominent notice on the Platform. Continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the revised Policy. If you do not agree to a material change, you may terminate your Personal Account under Section 13.2 of the Personal Terms.
Jurisdiction Addenda
A.1 EU/EEA — GDPR
Legal bases for processing are set forth in Section 4.1. Special categories of Personal Data are not intentionally collected (GDPR Article 9). Data subject rights are described in Section 10.2. Our EU Article 27 representative is identified in Section 13. Processor obligations are set forth in the DPA attached to the CCA as Exhibit A. Cross-border transfers rely on EU SCCs (Chapter V). Breach notification follows GDPR Articles 33 and 34 and applicable law.
A.2 United Kingdom — UK GDPR
UK GDPR applies to UK users. We rely on the UK IDTA or the UK Addendum to the EU SCCs for international transfers from the UK. Users may complain to the ICO at https://ico.org.uk. Our UK Article 27 representative is identified in Section 13.
A.3 California — CCPA/CPRA
CCPA/CPRA disclosures and consumer rights are set forth in Section 10.4. We do not sell Personal Information or share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals as an opt-out of sale and sharing. Service provider terms are incorporated into the CCA and DPA.
A.4 Other US States
Texas (TDPSA), Colorado (CPA and AI Act), Virginia (VCDPA), Connecticut (CTDPA), Oregon (OCPA), and other US state privacy laws are addressed through the rights framework in Section 10.5 and the appeal mechanism available at privacy@mobilyze.net.
