Legal

Privacy Policy

Version 2.0Effective July 1, 2026Last updated May 1, 2026

In plain language

Who we are: Mobilyze, Inc., a Delaware corporation that operates a partner revenue SaaS platform with AI-powered features (the “Platform”).

What we collect: Account information, content you upload (Contributed Data), activity data, and limited technical and cookie data.

Why we collect it: To provide the Platform and its features, secure it, and comply with applicable law. Certain optional features require your separate consent.

What this Policy covers: How we collect, use, share, and protect Personal Data when you use the Platform as a personal account user or as an Authorized User of a Corporate Workspace.

Your rights: Depending on where you live, you may have rights to access, correct, delete, port, object to, or restrict our processing of your Personal Data, and to withdraw consent. See Section 10.

How to reach us: privacy@mobilyze.net or dpo@mobilyze.net.

Jump to section
  1. 1 Scope & relationship
  2. 2 Controller & processor roles
  3. 3 Personal data we collect
  4. 4 How & why we use data
  5. 5 Personal-No-Link data
  6. 6 Sharing & disclosure
  7. 7 International transfers
  8. 8 Data retention
  9. 9 Security
  10. 10 Your rights
  11. 11 Cookies & technologies
  12. 12 Automated decisions & AI
  13. 13 Contact & representatives
  14. 14 Changes to this Policy
  15. Jurisdiction addenda

1 Scope and Relationship to Other Documents

This Privacy Policy applies to:

  • Visitors to Mobilyze’s website;
  • Users of a Mobilyze Personal Account; and
  • Authorized Users of a Corporate Workspace.

This Policy is incorporated by reference into the Personal Account Terms of Service (the “Personal Terms”) and supplements the Cookie Policy. Defined terms used but not defined in this Policy have the meanings given to them in the Personal Terms or, for Corporate Workspace contexts, the Corporate Customer Agreement (the “CCA”).

Order of precedence

In the event of any conflict between this Policy and the Personal Terms or the CCA, the Personal Terms or CCA, as applicable, control. This Policy does not create contractual commitments beyond those set forth in the Personal Terms or CCA.

2 Controller and Processor Roles

Personal account users and website visitors. For Personal Account users and website visitors, Mobilyze, Inc. is the data controller (or “business” under CCPA/CPRA).

Corporate Workspace data. For Personal Data uploaded to or processed within a Corporate Workspace, the Corporate Customer is the controller and Mobilyze is the processor, acting solely on the Corporate Customer’s instructions as set forth in the CCA and the applicable Data Processing Addendum (“DPA”). Individual Authorized Users should contact their Corporate Customer administrator regarding processing of their data within a Corporate Workspace.

Personal-No-Link-to-Company Data. Personal Data designated as Personal-No-Link-to-Company Data under the Personal Terms is processed by Mobilyze as controller, solely to deliver the individual user’s personalized Platform experience within their active session, as described in Section 5 below.

3 Personal Data We Collect

We collect the following categories of Personal Data, depending on how you use the Platform:

CategoryExamplesSource
IdentifiersName, email address, username, user IDYou; Corporate Customer administrator
Account and Profile DataRole, preferences, MFA factors, career historyYou
Contact and Network DataContact records uploaded for partner relationship managementYou; integrations you authorize
Commercial and CRM DataDeal pipelines, opportunity data, revenue figuresYou; CRM integrations you authorize
Usage and Device DataIP address, browser type, operating system, session logs, clickstreamsAutomated collection
Cookie and Tracking DataCookie identifiers, local storage values, pixel dataAutomated collection; see Cookie Policy
Communications DataSupport tickets, emails, in-platform messagesYou
Payment DataBilling contact information, payment token (payment card data is processed directly by our payment processor and is not stored by Mobilyze)You; payment processor
InferencesAI-derived scores, partner match recommendations, PTAM calculationsAutomated; Platform AI Features

Sensitive Personal Data. We do not intentionally collect Sensitive Personal Data (as defined under GDPR Article 9 or CPRA) through the Platform. If you believe Sensitive Personal Data has been submitted, contact us at privacy@mobilyze.net.

Children. The Platform is not directed to persons under 18. We do not knowingly collect Personal Data from minors. If you believe a minor has provided Personal Data, contact us at privacy@mobilyze.net for deletion.

4 How and Why We Use Personal Data

4.1 Purposes and Legal Bases

PurposeLegal Basis (GDPR/UK GDPR)US Law Equivalent
Provide and operate the Platform, including all Platform AI Features as core service deliveryPerformance of contract (Art. 6(1)(b))Necessary to perform the contract
Authenticate users and secure accountsLegitimate interests (Art. 6(1)(f)) — security and fraud preventionLegitimate operational purpose
Communicate Platform updates, support responses, and policy changesPerformance of contract / Legitimate interests (Art. 6(1)(b)/(f))Necessary to perform the contract
Comply with legal, regulatory, tax, and accounting obligationsLegal obligation (Art. 6(1)(c))Legal duty
Detect and prevent fraud, abuse, and policy violationsLegitimate interests (Art. 6(1)(f))Legitimate operational purpose
Personalization Learning (optional)Consent (Art. 6(1)(a)) — separately obtained, unbundled opt-inOpt-in consent
Tier 1 Aggregated Improvement (Corporate Workspace opt-in)Consent from Corporate Customer administrator (Art. 6(1)(a))Opt-in consent
Tier 2 Proprietary Model Training (Order Form opt-in)Separate written consent in Order Form (Art. 6(1)(a))Opt-in consent
Marketing to prospectsConsent or legitimate interests, depending on jurisdictionOpt-in where required by applicable law

4.2 Platform AI Features

Platform AI Features — including Partner Match Scoring, PTAM Scoring, Program Recommendation Engine, Deal Room Intelligence, Territory Mapping Analysis, Co-Sell Motion Suggestions, Presentation Generation, and Anomaly Detection — are integral, named components of the Platform. They are not optional add-ons, secondary data uses, or data monetization activities. Processing by Platform AI Features constitutes core service delivery under the Personal Terms and the CCA, and does not require a separate consent or opt-in. A full description of each Platform AI Feature and how it processes your data is set forth in Section 6.2 of the Personal Terms.

Platform AI Features generate probabilistic outputs that are decision-support tools only. They do not constitute professional, legal, financial, or commercial advice, and do not constitute automated decision-making with legal or similarly significant effects within the meaning of GDPR Article 22. Where any Platform AI Feature is classified as high-risk under the EU AI Act or the Colorado AI Act, Mobilyze will cooperate with the applicable Corporate Customer to satisfy classification, documentation, transparency, human oversight, and impact assessment obligations, as provided in the CCA.

4.3 Personalization Learning

Personalization Learning is an optional feature that is OFF by default. It is activated only by your affirmative, unbundled, specific opt-in through your personal account settings. When enabled, Personalization Learning uses your own Platform activity signals — navigation patterns, feature usage, search history, and content interaction history — to improve your individual experience. It does not use raw CRM contact data, commercial transaction amounts, or data from any other user or customer. Full details of what Personalization Learning does and does not do, and how to withdraw consent, are set forth in Section 6.3 of the Personal Terms and are summarized in Section 10.4 of this Policy.

4.4 Tier 1 and Tier 2

Tier 1 (Aggregated Improvement) and Tier 2 (Proprietary Model Training) are Corporate Workspace-level data use elections described in the CCA. They are OFF by default and require separate, affirmative opt-in by the Corporate Customer. Individual users cannot activate Tier 1 or Tier 2. This Policy does not restate the full Tier 1 and Tier 2 terms, which are set forth in the CCA.

6 Sharing and Disclosure

We share Personal Data only as described below. We do not sell Personal Data. We do not share Personal Data for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.

RecipientPurposeSafeguard
Sub-processors (cloud infrastructure, AI model API providers, analytics tools, support tooling)Providing and maintaining the PlatformWritten agreements prohibiting unauthorized use; sub-processor list at [SUBPROCESSOR_LIST_URL]
Corporate Customer administratorsManaging access and configuration within the Corporate WorkspaceCCA and DPA
Professional advisors (legal, accounting, audit)Obtaining professional adviceConfidentiality obligations
Governmental authorities and law enforcementCompliance with valid legal process or applicable lawDisclosed to you where legally permitted
Parties to a corporate transactionMerger, acquisition, financing, or sale of assetsConfidentiality obligations; notice where required by law

Sub-processor changes. We will provide at least thirty (30) days’ prior notice before engaging a new sub-processor that processes Contributed Data. The current sub-processor list is maintained at [SUBPROCESSOR_LIST_URL].

7 International Data Transfers

Mobilyze is based in the United States. If you are located in the EU, EEA, or UK, your Personal Data may be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home country.

For transfers of Personal Data out of the EEA, UK, or other jurisdictions requiring transfer safeguards, we rely on the following mechanisms as applicable:

  • EU Standard Contractual Clauses (Module 2 or Module 3, as applicable) approved by the European Commission;
  • UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as approved by the UK Information Commissioner’s Office;
  • Adequacy decisions issued by the European Commission or UK Secretary of State, where available.

Transfer Impact Assessments and data transfer summaries are available upon request at /privacy/transfers.

8 Data Retention

We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. The following general retention periods apply:

Data CategoryRetention Period
Account and profile dataDuration of account, plus up to 12 months following account deletion for legal and audit purposes
Contributed Data (Personal Account)Until deleted by you; deleted within 30 days of account deletion
Contributed Data (Corporate Workspace)Until deleted by Corporate Customer administrator; deleted within 30 days of contract termination per the CCA
Usage and security logsUp to 24 months
Support and communications dataUp to 36 months
Billing and tax recordsAs required by applicable law, typically 7 years
Personalization Learning behavioral dataDeleted within 30 days of consent withdrawal
Backup copiesOverwritten on a rolling basis within 35 days

Retention periods may be extended where required by applicable law, valid legal process, or to resolve an active dispute.

9 Security

We implement administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Personal Data. These measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, multi-factor authentication for administrative access, vulnerability scanning, intrusion detection and anomaly monitoring, tenant isolation, and per-tenant encryption key management. Full details of our security measures are set forth in Section 9.1 of the CCA.

No security measure is impenetrable. We do not warrant that the Platform will be free from all security vulnerabilities.

Data breach notification. In the event of a confirmed Security Incident involving unauthorized access to Personal Data, we will notify affected Corporate Customers and, where required by applicable law, relevant supervisory authorities and affected individuals, in accordance with applicable legal requirements including GDPR Articles 33 and 34 and applicable US state breach notification laws. Notification timing will be in accordance with applicable law.

10 Your Rights

10.1 Rights Available to All Users

Subject to applicable law and certain exceptions, you may have the right to:

  • Access the Personal Data we hold about you;
  • Correct inaccurate or incomplete Personal Data;
  • Delete your Personal Data (subject to legal retention obligations);
  • Restrict certain processing of your Personal Data;
  • Object to processing based on legitimate interests;
  • Port your Personal Data in a machine-readable format; and
  • Withdraw consent at any time for processing based on consent, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@mobilyze.net or use our rights request portal at /privacy/requests. We will respond within applicable statutory timeframes, typically within 30 days.

10.2 EU and EEA Users — GDPR Rights

If you are located in the EU or EEA, you have the rights described in Section 10.1 as provided by GDPR Articles 15 through 22. You also have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

For data processed within a Corporate Workspace, your rights requests should be directed to the Corporate Customer as controller. We will assist the Corporate Customer in fulfilling data subject rights requests as required by the DPA.

10.3 UK Users — UK GDPR Rights

If you are located in the United Kingdom, you have equivalent rights under the UK GDPR and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk.

10.4 California Users — CCPA/CPRA Rights

If you are a California resident, you have the following rights under the CCPA/CPRA:

  • Right to Know: The categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it;
  • Right to Delete: Deletion of your Personal Information, subject to certain exceptions;
  • Right to Correct: Correction of inaccurate Personal Information;
  • Right to Opt Out of Sale or Sharing: We do not sell Personal Information or share it for cross-context behavioral advertising. To submit a request regarding these rights, visit /privacy/do-not-sell;
  • Right to Limit Use of Sensitive Personal Information: We do not use or disclose Sensitive Personal Information beyond the purposes permitted by the CPRA without your consent;
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To submit a CCPA/CPRA rights request, contact us at privacy@mobilyze.net or visit /privacy/requests. We will verify your identity before processing your request.

Categories of Personal Information collected in the past 12 months (CCPA/CPRA disclosure):

CCPA CategoryExamplesCollected
IdentifiersName, email, user ID, IP addressYes
Personal information under Cal. Civ. Code §1798.80Name, address, payment informationYes (limited)
Commercial informationTransaction history, subscription dataYes
Internet or electronic network activityUsage logs, clickstreams, session dataYes
InferencesAI-derived scores and recommendationsYes
Sensitive personal informationNot intentionally collectedNo

10.5 Other US State Privacy Rights

If you are a resident of Colorado, Virginia, Texas, Connecticut, Oregon, or another US state with a comprehensive privacy law, you may have rights similar to those described in Sections 10.1 and 10.4, including the right to appeal a denied request. To submit a request or appeal, contact us at privacy@mobilyze.net. We will respond in accordance with applicable state law.

10.6 Personalization Learning — Withdrawal of Consent

If you have opted into Personalization Learning, you may withdraw your consent at any time by toggling the Personalization Learning control to OFF in your personal account settings. Upon withdrawal, Mobilyze will immediately cease collecting new activity signals for Personalization Learning purposes, and behavioral data used solely for Personalization Learning will be deleted within 30 days. Withdrawal does not affect your access to any Platform AI Feature or any other aspect of the Platform. Full details are set forth in Section 6.3.4 of the Personal Terms.

11 Cookies and Similar Technologies

We use cookies and similar technologies on the Platform. A full description of the cookies we use, the purposes for which we use them, how we obtain consent, and how you can manage your cookie preferences is set forth in our Cookie Policy, which is incorporated by reference into this Policy.

12 Automated Decision-Making and AI

Platform AI Features generate probabilistic outputs — including partner match scores, PTAM calculations, program recommendations, territory maps, and co-sell suggestions — that are decision-support tools only. They are not automated decisions with legal or similarly significant effects within the meaning of GDPR Article 22 or equivalent laws, and do not constitute professional, legal, financial, or commercial advice. You retain sole responsibility for any decisions made based on Platform AI Feature outputs. A full description of Platform AI Features is set forth in Section 6.2 of the Personal Terms.

Where any Platform AI Feature is or becomes subject to the EU AI Act, the Colorado AI Act, or equivalent AI governance regulation, Mobilyze will cooperate with the applicable Corporate Customer to satisfy applicable obligations. Individual users who have questions about AI-driven outputs affecting them should contact their Corporate Customer administrator or us at privacy@mobilyze.net.

13 Contact and Representatives

RoleContact
Mobilyze Privacy Team[object Object]
Data Protection Officer (DPO)[object Object]
EU Representative (GDPR Art. 27)[EU_REP_NAME], [EU_REP_CONTACT]
UK Representative (UK GDPR Art. 27)[UK_REP_NAME], [UK_REP_CONTACT]
Mailing Address[ADDRESS]

14 Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated at least 30 days before the effective date where feasible, by email to the address on your account or by prominent notice on the Platform. Continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the revised Policy. If you do not agree to a material change, you may terminate your Personal Account under Section 13.2 of the Personal Terms.

Jurisdiction Addenda

A.1 EU/EEA — GDPR

Legal bases for processing are set forth in Section 4.1. Special categories of Personal Data are not intentionally collected (GDPR Article 9). Data subject rights are described in Section 10.2. Our EU Article 27 representative is identified in Section 13. Processor obligations are set forth in the DPA attached to the CCA as Exhibit A. Cross-border transfers rely on EU SCCs (Chapter V). Breach notification follows GDPR Articles 33 and 34 and applicable law.

A.2 United Kingdom — UK GDPR

UK GDPR applies to UK users. We rely on the UK IDTA or the UK Addendum to the EU SCCs for international transfers from the UK. Users may complain to the ICO at https://ico.org.uk. Our UK Article 27 representative is identified in Section 13.

A.3 California — CCPA/CPRA

CCPA/CPRA disclosures and consumer rights are set forth in Section 10.4. We do not sell Personal Information or share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals as an opt-out of sale and sharing. Service provider terms are incorporated into the CCA and DPA.

A.4 Other US States

Texas (TDPSA), Colorado (CPA and AI Act), Virginia (VCDPA), Connecticut (CTDPA), Oregon (OCPA), and other US state privacy laws are addressed through the rights framework in Section 10.5 and the appeal mechanism available at privacy@mobilyze.net.

Privacy Policy — mobilyze