Privacy Policy
This policy explains what information Human Centered Agility collects, how we use it, and the choices you have. We aim to collect only what we need and to be clear about why.
Draft pending legal review. This page is standard boilerplate provided as a starting point, not legal advice. Highlighted PLACEHOLDERS must be replaced with verified details, and the full text reviewed by counsel before publication.
Overview
This Privacy Policy applies to LEGAL ENTITY NAME ("HCA," "we," "us") and the websites, applications, and services that link to it (the "Services"). By using the Services, you agree to the collection and use of information as described here.
We are the controller of the personal information processed under this policy. If you have questions, contact us using the details in the Contact section below.
Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third parties.
Information you provide
- Account and contact details: such as your name, email address, organization, and role, when you register, subscribe, or contact us.
- Content you submit: such as form responses, assessment inputs, reflections, or messages you send through the Services.
- Payment information: processed by our payment provider; we do not store full card numbers on our servers.
Information collected automatically
- Usage data: pages visited, features used, and timestamps, used to operate and improve the Services.
- Device and log data: IP address, browser type, and general location inferred from IP.
- Cookies and similar technologies: see the Cookies section below.
Information from third parties
We may receive information from service providers, single sign-on or identity providers you choose to use, and analytics partners, consistent with their terms and your settings.
How We Use Information
We use personal information to:
- Provide, maintain, and improve the Services;
- Create and manage accounts and authenticate users;
- Respond to inquiries and provide support;
- Send administrative messages and, where permitted, relevant updates;
- Monitor security, prevent fraud, and enforce our terms;
- Comply with legal obligations.
Where required by law, we rely on a lawful basis for each purpose, such as performance of a contract, your consent, our legitimate interests, or compliance with a legal obligation.
Data Retention
We keep personal information only as long as needed for the purposes described here, then delete or anonymize it. Typical retention periods are: RETENTION SCHEDULE. Where we are required to retain data for legal, tax, or accounting reasons, we retain it for the required period.
Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us using the details below. We will respond within the timeframe required by applicable law.
US state privacy rights
If you are a resident of a US state with a comprehensive privacy law (such as California), you may have the right to know, delete, and correct personal information, and to opt out of sale or sharing and certain targeted advertising. We do not sell personal information. To exercise these rights, contact privacy@domain.
EEA/UK rights
If you are in the European Economic Area or the United Kingdom, you have the rights described above under the GDPR/UK GDPR, and the right to lodge a complaint with your local supervisory authority.
Security
We use administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you and regulators as required by law.
International Transfers
We may process and store information in countries other than where you live, including STATE / COUNTRY. Where we transfer personal information across borders, we use appropriate safeguards such as standard contractual clauses.
Children's Privacy
The Services are not directed to children under the age of 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date and, for material changes, provide a more prominent notice. Your continued use of the Services after an update means you accept the revised policy.
Contact Us
If you have questions about this policy or our privacy practices, contact us:
LEGAL ENTITY NAME
REGISTERED ADDRESS
Email: privacy@domain