Privacy Policy
Effective Date: June 19, 2026 — SagaIQ, Inc. / ExcelaDoc
1. Introduction; Scope; Relationship to Terms of Service
1.1 This Privacy Policy (this “Policy”) is issued by SagaIQ, Inc., a corporation duly organized and existing under the laws of the State of Delaware, with its principal place of business in the State of Tennessee (hereinafter, “Company,” “we,” “us,” or “our”), and applies to the ExcelaDoc cloud-based software-as-a-service platform and all related features, websites, and services (collectively, the “Service”), as more fully described in the Terms of Service.
1.2 This Policy applies to: (a) individuals who access or use the Service as Customer’s authorized users (hereinafter, “Customer,” “you,” or “your,” consistent with the meaning given to such terms in the Terms of Service); (b) prospective customers who interact with Company’s website, request a demo, join a waitlist, or otherwise communicate with Company; and (c) any other individual whose Personal Information Company processes in connection with operating the Service.
1.3 This Policy does not apply to Customer Data except to the extent such Customer Data constitutes Personal Information of identifiable individuals. With respect to such Personal Information contained within Customer Data, Company acts solely as a processor or “service provider” (as such terms are defined under Applicable Data Protection Laws) on behalf of Customer, who acts as the controller or “business” with respect to such Personal Information. Customer’s collection, use, and disclosure of such Personal Information, and Customer’s compliance with Applicable Data Protection Laws with respect thereto, are governed by the Terms of Service (including, without limitation, Sections 10.4 and 11.1 thereof) and, where applicable, a separately executed Data Processing Agreement (“DPA”), and not by this Policy.
1.4 This Policy is incorporated by reference into the Terms of Service pursuant to Section 10.2 thereof. In the event of any conflict between this Policy and the Terms of Service with respect to data privacy and security matters, this Policy shall control; in all other respects, the Terms of Service shall control.
2. Definitions
As used in this Policy, the following capitalized terms shall have the meanings ascribed to them below. Capitalized terms used but not defined in this Policy shall have the meanings ascribed to them in the Terms of Service.
- “Account Data”
- means information that Customer or Customer’s authorized users provide directly to Company in connection with registering for, administering, or maintaining an Account, including without limitation names, email addresses, job titles, organization names, telephone numbers, and billing-related information.
- “AI Model Provider”
- means a third-party provider of artificial intelligence or machine learning models that Company engages, under a multi-model routing architecture, to process Customer Data solely for the purpose of generating outputs requested through the Service, as more fully described in Section 6.
- “Applicable Data Protection Laws”
- means any and all Applicable Law relating to the privacy, confidentiality, or security of Personal Information, including without limitation the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”), and other applicable U.S. state privacy laws, in each case as amended from time to time.
- “Cookies”
- means small text files and similar tracking technologies (including pixels, web beacons, and local storage) placed on a device when a user visits a website, as more fully described in Section 4.
- “Customer Data”
- shall have the meaning ascribed to it in the Terms of Service, namely all data, content, information, materials, documents, files, text, images, and other inputs that Customer uploads, submits, transmits, or otherwise provides to, or makes available through, the Service.
- “Data Subject”
- means an identified or identifiable natural person to whom Personal Information relates.
- “Personal Information”
- means any information that identifies, relates to, describes, or is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Data Subject, as more fully defined under Applicable Data Protection Laws.
- “Process” or “Processing”
- means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, dissemination, combination, restriction, erasure, or destruction.
- “Sub-processor”
- means any third-party service provider engaged by Company to Process Personal Information in connection with providing the Service, as further described in Section 7.
- “Usage Data”
- means information automatically collected by Company in connection with Customer’s or a visitor’s access to or use of the Service or Company’s website, as more fully described in Section 3.3.
3. Information We Collect
3.1 Information You Provide Directly (Account Data)
In connection with registering for an Account, administering Customer’s organization within the Service, or communicating with Company, Company collects Account Data, including: (a) name, business email address, job title, and organization name; (b) telephone number, where voluntarily provided; (c) billing name, billing address, and billing-related information necessary to process payment for a Subscription Plan (Company does not itself store full payment card numbers; such information is collected and processed directly by Company’s payment processor as described in Section 7.2); and (d) the contents of any communications Customer or its authorized users send to Company, including support requests, feedback, and correspondence.
3.2 Customer Data
Customer Data may include Personal Information of Customer’s personnel, subcontractors, references, or other third parties (for example, names, titles, resumes, or past-performance references contained within an RFP response). As described in Section 1.3, Company Processes such Personal Information solely as a processor or service provider on behalf of Customer, in accordance with the Terms of Service and, where applicable, a DPA. Customer is solely responsible for ensuring it has obtained all necessary rights, consents, and legal bases required under Applicable Data Protection Laws before submitting such Personal Information to the Service.
3.3 Information Collected Automatically (Usage Data)
When Customer or a visitor accesses or uses the Service or Company’s website, Company automatically collects certain information, including: (a) Internet Protocol (IP) address; (b) browser type and version, device type, and operating system; (c) pages or screens viewed, features used, referring and exit pages, and timestamps; (d) session duration and click-stream data; and (e) information collected through Cookies and similar technologies, as described in Section 4.
Product Usage and Event Data. Company collects information about how Customer’s authorized users interact with the Service — features used, actions taken (for example, creating a proposal or uploading an RFP), pages viewed, and general device and browser information. This data is associated with the user’s Account but does not include the content of Customer’s proposals, RFPs, or other documents.
3.4 Information from Third Parties
Company may receive information about Customer or its authorized users from third parties, including: (a) confirmation of payment status and limited billing information from Company’s payment processor; (b) information submitted through Company’s website forms (for example, waitlist sign-ups, demo requests, or contact forms), which is processed through Company’s email and marketing automation platform; and (c) to the extent the Service offers authentication via a third-party identity provider, basic profile information (such as name and email address) made available by that provider with Customer’s authorization.
4. Cookies and Similar Tracking Technologies
4.1 Types of Cookies Used
Company’s website and Service use the following categories of Cookies:
- (a) Strictly Necessary Cookies — required for the Service to function, including cookies used to maintain Customer’s authenticated session (consistent with the JWT-based session mechanism described in Section 8), enforce security controls, and remember user preferences within the Service. These Cookies cannot be disabled without impairing the Service’s functionality.
- (b) Analytics Cookies — Company uses Google Analytics to understand how visitors interact with Company’s website and the Service, including which pages are viewed, how long visitors remain on a page, and which content is most engaging. Google Analytics uses Cookies to collect this information in pseudonymous form.
4.2 Google Analytics
Information collected via Google Analytics Cookies is transmitted to and processed by Google LLC in accordance with Google’s own privacy policy. Visitors who wish to opt out of Google Analytics tracking across all websites may install the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout.
4.3 PostHog Product Analytics
Within the Service, Company uses PostHog to understand how features are used so Company can improve the Service. PostHog data is routed through Company’s own domain (first-party) and is limited to interaction events. Company does not enable session recording, and masks text and form-input values so that the content of Customer’s documents is never captured. Customer’s authorized users may opt out of this product analytics at any time in Account settings (Account → Security → Data & Privacy), and Company honors browser “Do Not Track” signals with respect to this in-Service analytics.
4.4 Managing Cookies
Most web browsers allow Customer to control Cookies through browser settings, including blocking or deleting Cookies. Disabling Cookies may affect the availability or functionality of certain features of the Service. With respect to Google Analytics Cookies used on Company’s website, Company does not currently respond to “Do Not Track” browser signals or Global Privacy Control signals because Company does not engage in the “sale” or “sharing” of Personal Information as those terms are defined under the CCPA, as further described in Section 10.2. With respect to in-Service product analytics, Company honors “Do Not Track” signals as described in Section 4.3.
5. How We Use Information
Company uses Account Data and Usage Data for the following purposes:
- (a) to provide, operate, maintain, secure, and improve the Service;
- (b) to create and administer Accounts, authenticate users, and provide customer support;
- (c) to process payments and manage billing for Subscription Plans in accordance with Section 8 of the Terms of Service;
- (d) to send transactional and account-related communications, including confirmations, security alerts, billing notices, and changes to this Policy or the Terms of Service;
- (e) where Customer or a website visitor has consented or as otherwise permitted by Applicable Law, to send marketing communications regarding the Service, including product updates and promotional offers, via Company’s email and marketing automation platform; recipients may opt out of marketing communications at any time using the unsubscribe mechanism included in such communications;
- (f) to monitor, analyze, and understand usage trends in order to improve the Service’s features, performance, and user experience;
- (g) to detect, investigate, and prevent fraudulent transactions, security incidents, and violations of the Acceptable Use Policy set forth in Section 4 of the Terms of Service;
- (h) to comply with Applicable Law, respond to lawful requests from public authorities, and enforce the Terms of Service.
6. Artificial Intelligence; No Training on Customer Data
6.1 No Training on Customer Data
6.2 How AI Model Providers Process Customer Data
To deliver the document analysis, drafting assistance, compliance evaluation, and other AI-powered features of the Service, Company transmits relevant portions of Customer Data to one or more AI Model Providers under a multi-model routing architecture designed to select the most suitable underlying model for a given task. Each AI Model Provider Processes such Customer Data solely as necessary to generate the specific output requested (for example, a drafted section, an analysis, or a compliance check) and to return that output to the Service. Company’s agreements with each AI Model Provider contractually prohibit such AI Model Provider from retaining Customer Data beyond the period necessary to generate the requested output, or from using Customer Data to train, fine-tune, or otherwise improve any model.
6.3 AI-Generated Outputs
Outputs generated by the Service using artificial intelligence are provided to assist Customer’s personnel and remain subject to human review. As set forth in Section 11.2(d) of the Terms of Service, Company makes no warranty as to the accuracy, completeness, or suitability of any AI-generated output, and Customer remains solely responsible for reviewing and validating any such output before relying upon it.
7. How We Disclose Information; Sub-processors
7.1 General
Company discloses Account Data, Usage Data, and, where applicable, Personal Information contained within Customer Data, only as described in this Section 7. Company requires each Sub-processor to be bound by written obligations of confidentiality and to implement appropriate technical and organizational measures to protect such information, consistent with this Policy and, where Customer has executed a DPA, the terms of that DPA.
7.2 Categories of Sub-processors
| Category | Sub-processor | Purpose |
|---|---|---|
| Cloud hosting and infrastructure | Amazon Web Services, Inc. (“AWS”); Vercel Inc. | Application hosting, database hosting, file storage, and content delivery |
| Email and marketing communications | Brevo (Sendinblue SAS) | Sending transactional emails (e.g., account notifications) and, where consented to, marketing communications |
| Payment processing | Stripe, Inc. | Processing Subscription Plan payments; Company does not store full payment card numbers |
| AI Model Providers | One or more third-party large language model providers (multi-model routing architecture) | Generating AI-powered outputs from Customer Data, as described in Section 6 |
| Website analytics | Google LLC (Google Analytics) | Understanding website and Service usage trends, as described in Section 4 |
| Product analytics | PostHog, Inc. | Understanding in-app feature usage, as described in Section 4 |
7.3 Other Disclosures
Company may also disclose Account Data, Usage Data, and, where applicable, Personal Information contained within Customer Data: (a) to comply with Applicable Law, legal process, or governmental requests; (b) to professional advisors (such as attorneys, accountants, and auditors) bound by confidentiality obligations; (c) in connection with a merger, acquisition, financing, reorganization, or sale of all or substantially all of Company’s assets, consistent with Section 17.4 of the Terms of Service; and (d) with Customer’s consent.
7.4 No Sale or Sharing of Personal Information
8. Data Security
Company implements and maintains administrative, physical, and technical safeguards designed to protect Personal Information from unauthorized access, acquisition, disclosure, alteration, or destruction, consistent with Section 10.1 of the Terms of Service. These safeguards include, without limitation:
- (a) encryption of data at rest using AES-256;
- (b) encryption of data in transit using TLS 1.3;
- (c) role-based access controls (“RBAC”) restricting internal access to Customer Data on a need-to-know basis;
- (d) password storage using bcrypt hashing, and session management using JSON Web Tokens (“JWT”) with a 30-day expiration;
- (e) daily encrypted backups and point-in-time recovery capabilities.
Company has designed its security program with reference to the SOC 2 Trust Services Criteria and is working toward formal SOC 2 certification; Company does not currently represent that it holds SOC 2 certification. Geographic redundancy of Company’s infrastructure is on Company’s roadmap but is not yet generally available.
9. Data Retention
9.1 Active Accounts
Company retains Account Data and Customer Data for as long as Customer’s Account remains active, or as otherwise necessary to provide the Service.
9.2 Post-Cancellation Retention
Following the termination or expiration of Customer’s Account for any reason, Company retains Customer Data and Account Data for a period not to exceed thirty (30) calendar days (the “Data Retention Period”), consistent with Section 9.5(b) of the Terms of Service, after which Company has no obligation to retain such information and may delete it. Customer may request retrieval of Customer Data during the Data Retention Period by contacting Company at info@sagaiq.ai.
9.3 Deletion Requests
Upon receipt of a verified deletion request from Customer or, where applicable, a Data Subject (as described in Section 10), Company will delete the relevant Account Data and Customer Data within thirty (30) calendar days, except to the extent Company is required to retain such information to comply with Applicable Law (for example, financial or tax recordkeeping requirements) or for legitimate business purposes such as fraud prevention or the establishment, exercise, or defense of legal claims.
9.4 Backups
Residual copies of deleted information may persist in encrypted backups for a limited period following deletion, in accordance with Company’s backup rotation schedule, and will be permanently purged in the ordinary course of that schedule.
10. Your Privacy Rights
10.1 Rights Under GDPR / UK GDPR
If Customer or a Data Subject is located in the European Economic Area, the United Kingdom, or Switzerland, such individual has the right to:
- (a) request access to, and a copy of, their Personal Information;
- (b) request rectification of inaccurate or incomplete Personal Information;
- (c) request erasure of their Personal Information;
- (d) request restriction of, or object to, Processing of their Personal Information;
- (e) request portability of their Personal Information in a structured, commonly used, machine-readable format;
- (f) withdraw consent at any time, where Processing is based on consent; and
- (g) lodge a complaint with a supervisory authority.
10.2 Rights Under CCPA / CPRA
If Customer or a Data Subject is a California resident, such individual has the right to:
- (a) know and access the categories and specific pieces of Personal Information Company has collected;
- (b) request deletion of their Personal Information;
- (c) request correction of inaccurate Personal Information; and
- (d) not be discriminated against for exercising any of these rights.
As described in Section 7.4, Company does not sell or share Personal Information, and accordingly there is no “opt-out of sale or sharing” mechanism to provide.
10.3 Other U.S. State Privacy Laws
Residents of other U.S. states with comprehensive consumer privacy laws have rights substantially similar to those described in Section 10.2. Company will honor verifiable requests from such individuals consistent with this Section 10, regardless of the requestor’s state of residence.
10.4 Exercising Your Rights
To exercise any of the rights described in this Section 10, Customer or a Data Subject may submit a request to Company at info@sagaiq.ai with the subject line “Privacy Rights Request.” Company may request information reasonably necessary to verify the identity of the requestor before acting on a request. Company will respond to verified requests within the timeframe required by Applicable Data Protection Laws.
Analytics opt-out: Customer’s authorized users may disable product-usage analytics for their Account at any time in Account settings (Account → Security → Data & Privacy). Company also honors browser “Do Not Track” signals with respect to such in-Service analytics, as described in Section 4.3.
10.5 Authorized Agents
A Data Subject may designate an authorized agent to submit a request on their behalf. Company may require the agent to provide proof of authorization and may require the Data Subject to independently verify their identity directly with Company.
11. International Data Transfers
Company is headquartered in the United States, and the Sub-processors described in Section 7 may Process information in the United States and other countries. Where Company transfers Personal Information originating in the European Economic Area, the United Kingdom, or Switzerland to the United States or another country not deemed to provide an adequate level of data protection, Company relies on Standard Contractual Clauses or other legally recognized transfer mechanisms with its Sub-processors. A DPA incorporating such transfer mechanisms is available upon written request to info@sagaiq.ai, consistent with Section 10.3 of the Terms of Service.
12. Children’s Privacy
Consistent with Section 5.3 of the Terms of Service, the Service is not intended for, and may not be used by, individuals under the age of eighteen (18). Company does not knowingly collect Personal Information from children under the age of thirteen (13), or such other age threshold as may be specified under Applicable Law. If Company becomes aware that it has collected Personal Information from a child in violation of this Section 12, Company will take reasonable steps to delete such information promptly.
13. Changes to This Privacy Policy
Company reserves the right to modify, amend, or replace this Policy at any time. In the event Company makes a material change to this Policy, Company will provide at least thirty (30) calendar days’ advance notice by sending notice to the email address associated with Customer’s Account, posting a prominent notice on Company’s website or within the Service, or both, consistent with the notice procedures set forth in Section 15 of the Terms of Service. Continued access to or use of the Service following the effective date of any modification constitutes acceptance of the modified Policy. Non-material changes, including corrections of typographical errors, clarifications, and changes required by Applicable Law, may be made without prior notice.
14. Governing Law; Relationship to Terms of Service
This Policy is incorporated into and forms part of the Terms of Service and is governed by the same governing law, jurisdiction, venue, and dispute resolution provisions set forth in Section 16 of the Terms of Service, including the laws of the State of Delaware and the exclusive jurisdiction and venue of the courts of Shelby County, Tennessee.
15. Contact Information
Questions, requests, or notices regarding this Policy, or requests to exercise the privacy rights described in Section 10, should be directed to:
SagaIQ, Inc.
Legal Department
Email: info@sagaiq.ai
All requests should reference “Privacy Policy” or “Privacy Rights Request” in the subject line.
END OF PRIVACY POLICY
SagaIQ, Inc. — ExcelaDoc Privacy Policy — June 19, 2026