CoAdapta Advisors & Edge Technologies | Change DeliveryServing the Midwest & Southeast
Legal

Privacy Policy — Client Portal

Effective August 1st, 2026Last updated August 19th, 2026

This policy explains how CoAdapta Edge Technologies LLC ("we," "us," "our") collects, uses, discloses, and protects personal information in connection with [PORTAL NAME], the secure client application available at [CLIENTNAME].coadapta.app, [app].coadapta.net (the "App").

This policy covers the Portal only. Our public marketing website at https://coadapta.com is governed by a separate notice available at https://coadapta.com/privacy.


1. Scope and our role

The Portal is a business application made available to our clients and their authorized users. Our role depends on the data involved:

  • We act as a controller for account, billing, and usage information — the data we collect to create accounts, secure the Portal, bill for the service, and improve it. This policy describes those practices.
  • We act as a processor (service provider) for the content our clients load into their workspace, including information about their employees, customers, and operations. We handle that content on the client's written instructions under our services agreement and data processing agreement. If you are an employee or contact of one of our clients and want to exercise rights over that content, please contact the client directly; we will refer your request to them and assist as our agreement requires.

2. Information we collect

2.1 Information you give us

CategoryExamples
Account and profileName, business email address, phone number, job title, employer, username, password credential, profile photo, role and permission assignments
Client contentDocuments, records, notes, assessment data, and any other information you or your organization upload to or generate in your workspace
Inquiry and supportMessages sent through contact, request, or support forms; the contents of emails and support tickets; onboarding and configuration details
Billing and paymentBilling contact, billing address, invoice history, plan and subscription details, and the last four digits, card brand, and expiration date of a payment card
Communication preferencesNotification settings, marketing consents, and opt-out choices

Payment card handling. We do not collect or store full payment card numbers, CVV codes, or bank account credentials on our systems. Card and bank details are entered directly into a PCI-DSS compliant payment processor, which returns only a token and limited card metadata to us. We cannot see or reconstruct the full card number.

2.2 Information collected automatically

CategoryExamples
Device and connectionIP address, browser type and version, operating system, device type, screen size, language, time zone
Usage and activityPages and features accessed, actions taken, timestamps, referring page, session duration, search queries within the Portal
Security and audit logsSign-in attempts (successful and failed), IP address at sign-in, session identifiers, permission changes, record-level audit trail entries
DiagnosticsError reports, crash data, and performance measurements

2.3 Information from third parties

  • Identity providers. If you sign in through a single sign-on provider, we receive your name, email address, and an account identifier from that provider.
  • Your employer. Client administrators may create your account and assign your role, supplying your name, work email, and job information.
  • Payment processor. Transaction status, authorization results, and limited card metadata.

2.4 Sensitive information

We do not seek sensitive personal data (such as health, biometric, racial or ethnic origin, religious belief, precise geolocation, or immigration status) for our own purposes. Where a client's workspace configuration causes such data to be processed, we handle it solely as a processor on that client's instructions, and the client is responsible for obtaining any consent the law requires.


3. Cookies and similar technologies

We use the following categories of cookies and local storage on the Portal:

  • Strictly necessary — session management, authentication, load balancing, CSRF protection, and remembering your consent choices. The Portal will not function without these.
  • Functional — remembering preferences such as language, layout, and saved filters.
  • Analytics and performance — measuring feature usage and diagnosing errors so we can improve the Portal.

We do not use advertising, cross-site tracking, or retargeting cookies on the Portal.

Where required by law, we present a consent banner on your first visit and set non-essential cookies only after you accept. You can change your choice at any time through the cookie settings link in the Portal footer, and you can block or delete cookies through your browser. Blocking strictly necessary cookies will prevent you from signing in.


4. How we use information

We use personal information to:

  1. Provide the service — create and authenticate accounts, deliver Portal features, store and display your workspace content, and enable collaboration among your organization's users.
  2. Support you — respond to inquiries, troubleshoot problems, and provide training and onboarding.
  3. Secure the service — verify identity, enforce permissions, monitor for unauthorized access, detect fraud and abuse, maintain audit trails, and investigate incidents.
  4. Bill and administer — process subscription payments, issue invoices, collect amounts owed, and maintain business records.
  5. Improve the service — analyze aggregate usage patterns, diagnose errors, test changes, and develop new features.
  6. Communicate — send service, security, billing, and maintenance notices; and, where you have opted in, send product updates and other business communications you can unsubscribe from at any time.
  7. Comply with law — meet legal, tax, accounting, and regulatory obligations and respond to lawful requests.

We do not sell personal information, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects.

Automated processing. The Portal may use automated analysis, including AI-assisted features, to summarize, classify, or draft content within your workspace. These features assist users and do not make decisions about individuals without human review. Where we use third-party AI providers, we do so under agreements that prohibit them from using your data to train their models.

Legal bases (GDPR / UK GDPR)

Where the EU or UK GDPR applies, we rely on:

PurposeLegal basis
Providing the Portal and support under an agreementPerformance of a contract (Art. 6(1)(b))
Security, fraud prevention, service improvement, business communications to existing business contactsLegitimate interests (Art. 6(1)(f))
Non-essential cookies and opt-in marketingConsent (Art. 6(1)(a))
Tax, accounting, and regulatory records; responding to lawful requestsLegal obligation (Art. 6(1)(c))

You may withdraw consent at any time; withdrawal does not affect processing already carried out.


5. How and to whom we disclose information

We disclose personal information only in the situations below. We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.

5.1 Within your organization

Portal content is visible to other authorized users of your organization's workspace according to the roles and permissions your administrators configure. Your administrator can access, export, restrict, or delete content and accounts in that workspace.

5.2 Service providers (sub-processors)

We use vetted vendors to operate the Portal. Each acts on our documented instructions under a written contract that limits their use of the data to providing services to us, imposes confidentiality and security obligations, and requires deletion or return of the data at the end of the engagement.

CategoryPurposeProvider
Cloud hosting and managed databaseApplication and data storageVercel & Supabase
Application deployment and CDNServing the PortalVercel & Cloudflare
Transactional email deliveryNotifications, invitations, alertsResend
Payment processingSubscription billingStripe
Product analytics and error monitoringUsage measurement, diagnosticsVercel
AI and language model providersIn-Portal AI featuresAnthropic & Open AI
Identity and authenticationSign-in and session managementSupabase

A current list of sub-processors is available on request to [email protected]. We provide advance notice of material changes to this list to client administrators.

5.3 Professional advisors

Our attorneys, accountants, auditors, and insurers, where reasonably necessary and subject to professional or contractual duties of confidentiality.

5.4 Legal and safety disclosures

We may disclose information when we believe in good faith it is necessary to comply with a law, subpoena, warrant, court order, or other lawful request; to enforce our agreements; or to protect the rights, property, or safety of our clients, our personnel, or the public. Where we are legally permitted, we will notify the affected client before responding to a request for their data so they may seek protective relief.

5.5 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. The receiving party will remain bound by this policy or provide notice before materially changing it.

5.6 Method of disclosure

All disclosures occur through controlled technical channels, never by unsecured means:

  • Encrypted API and database connections between the Portal and our service providers, over TLS 1.2 or higher.
  • Authenticated, permissioned access within the Portal itself for users in your organization.
  • Encrypted file transfer or secure export links for data exports and migrations, issued with expiration and access controls.
  • Encrypted email or a secure document channel for professional advisors and legal responses.

We do not transmit personal information over unencrypted email, consumer file-sharing links, unsecured FTP, or removable media. Access is limited to the minimum data required for the specific purpose.


6. International transfers

We are based in the United States and process information there. If you are in the European Economic Area, the United Kingdom, or Switzerland, transferring your information to the United States means it may be accessible to authorities under laws different from those in your country.

Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out transfer risk assessments and apply supplementary technical measures including encryption in transit and at rest. A copy of the relevant safeguards is available on request to [email protected].


7. How we protect information

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data:

Technical

  • Encryption in transit using TLS 1.2 or higher, and encryption at rest for databases, file storage, and backups
  • Passwords stored only as salted cryptographic hashes; we never store them in readable form
  • Multi-factor authentication available on all accounts and required for administrative access
  • Row-level security and role-based access control enforcing tenant isolation, so a user can reach only the records their role and organization permit
  • Secrets and API keys held in a managed secrets store, rotated on a defined schedule
  • Continuous logging and monitoring of authentication events, permission changes, and record access
  • Automated backups with restoration testing, and a documented recovery plan

Administrative

  • Access to production systems restricted to personnel with a business need, granted on least-privilege principles and reviewed periodically
  • Background-appropriate onboarding, confidentiality agreements, and security awareness training for personnel
  • Written contracts with all sub-processors covering confidentiality, security, and breach notification
  • Change management, code review, and dependency vulnerability scanning before deployment
  • Periodic security reviews and remediation tracking

Physical

  • Production infrastructure hosted in providers' certified data centers with 24/7 physical access control, environmental protection, and independent audit attestations

Incident response. We maintain a written incident response plan. If a breach affecting personal information occurs, we will notify affected clients without undue delay and will provide the information they need to meet their own notification obligations. Where we are the controller and the law requires it, we will notify affected individuals and regulators within the applicable deadlines — including within 72 hours to the relevant supervisory authority where the GDPR or UK GDPR applies.

No system is perfectly secure. You are responsible for keeping your credentials confidential, enabling multi-factor authentication, and notifying us promptly at [email protected] if you suspect unauthorized access to your account.


8. How long we keep information

DataRetention
Account and profileFor the life of the account, then [X] days after deactivation
Client workspace contentFor the term of the client agreement; deleted or returned within [X] days of termination, per that agreement
Security and audit logs[X] months
Billing and transaction records[7] years, to meet tax and accounting requirements
Support communications[X] years from resolution
BackupsOverwritten on a rolling [X]-day cycle

We delete or de-identify information when it is no longer needed for the purposes described here, except where a longer period is required by law or necessary to establish, exercise, or defend legal claims.


9. Your rights and choices

9.1 Kentucky residents (KCDPA)

Under the Kentucky Consumer Data Protection Act, KRS 367.3611 to 367.3629, Kentucky consumers have the right to:

  • Confirm whether we are processing their personal data and access that data
  • Correct inaccuracies in their personal data
  • Delete personal data they provided or that we obtained about them
  • Obtain a portable copy of their personal data, to the extent technically feasible
  • Opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects

We do not sell personal data, engage in targeted advertising, or conduct profiling of that kind, so there is nothing to opt out of — but the request channel below remains open.

How to submit a request. Email [email protected] or write to the address in Section 12 with the subject line "Privacy Request." We will verify your identity through your registered account or other reasonable means before acting. We respond free of charge, up to twice in any twelve-month period, within 45 days; we may extend once by another 45 days where reasonably necessary, and will tell you if we do.

Appeals. If we decline to act on your request, we will explain why and give you instructions for appealing. We will respond to an appeal in writing within 60 days. If we deny the appeal, you may submit a complaint to the Kentucky Attorney General's Office of Data Privacy at https://www.ag.ky.gov.

Note that the KCDPA applies to individuals acting in a personal capacity, not to people acting in a commercial or employment context. Most Portal users are business users, but we honor these requests regardless.

9.2 EEA, UK, and Swiss residents (GDPR / UK GDPR)

You have the right to access, rectify, erase, restrict, and object to processing of your personal data; the right to data portability; the right to withdraw consent; and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise these rights, contact [email protected]. We respond within one month, extendable by two further months for complex requests. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office at https://ico.org.uk.

9.3 Everyone

  • Access and correction. You can view and update most account and profile information directly in your Portal settings.
  • Marketing. Every marketing email includes an unsubscribe link. Service, security, and billing messages are not optional while your account is active.
  • Cookies. Adjust your choices through the cookie settings link in the Portal footer or your browser controls.
  • Workspace content. If your account was created by your employer or another client organization, requests about content in that workspace should go to that organization, which controls it. We will forward your request and assist them in responding.

We will not discriminate against you for exercising any of these rights.


10. Children

The Portal is a business application not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn we have collected such information, we will delete it. Contact [email protected] if you believe a child has provided us information.


11. Changes to this policy

We may update this policy to reflect changes in our practices or the law. We will post the revised version here with a new effective date. For material changes, we will notify client administrators by email or in-Portal notice at least [30] days before the change takes effect. Continued use of the Portal after the effective date means you accept the updated policy.


12. Contact us

CoAdapta Edge Technologies LLC PO BOX 422 Danville, KY 40223

Privacy inquiries and rights requests: [email protected] General: [email protected]

We aim to acknowledge every privacy inquiry within five business days.