Collablynx
  • Products
    • Vantage
    • Cadence
    • DocuForge
    • Compare Products
  • Pricing
  • Resources
    • Platform Architecture
    • Product Guides
    • Integrations
    • Security & Trust
    • FAQs
    • Release Notes
  • Request Demo
  • Products
    • Vantage
    • Cadence
    • DocuForge
    • Compare Products
  • Pricing
  • Resources
    • Platform Architecture
    • Product Guides
    • Integrations
    • Security & Trust
    • FAQs
    • Release Notes
  • Request Demo
  1. Home
  2. Privacy Policy
PRIVACY · SECURITY · RESPONSIBLE DATA USE

Privacy and Data Protection Policy

This Policy explains how Collablynx handles personal information, Customer Data, regulated information, product telemetry, account activity, and AI-enabled content across Collablynx websites and products.

Effective: August 1, 2026·Policy version: 2.1.0
On this page Core commitmentsScope and rolesInformation categoriesCustomer and product dataRegulated and sensitive dataHealth data and HIPAAAI-enabled processingAccounts and license securityUses and legal basesDisclosuresCookies and controlsRetention and deletionSecurity and incidentsInternational transfersRights and choicesJurisdiction-specific noticesChildrenLegal processPolicy changesContact

Our core commitments

Purpose limitationWe use information for disclosed product, security, licensing, support, legal, and business purposes—not to build unrelated advertising profiles.
Data minimizationWe seek to collect and retain only information reasonably necessary for the applicable purpose, configuration, legal obligation, or customer instruction.
No data brokerageWe do not sell Customer Data or personal information and do not share it for cross-context behavioral advertising.
Customer governanceCustomer organizations control their submitted content, connected environments, authorized users, retention settings, and approved integrations.
Regulated-data boundariesProtected, classified, or highly regulated data may be submitted only when expressly authorized in a signed agreement and approved product configuration.
AI restrictionsCustomer Content is not used to train generalized public models unless expressly authorized in writing.
Individual accountabilityEvery authorized user must use an individually assigned account; shared credentials and unlicensed access are prohibited.

1. Scope, entities, and privacy roles

This Policy applies to Collablynx websites, product portals, forms, communications, support channels, APIs, product applications, and related experiences that link to it (the “Services”). It covers Vantage, Cadence, DocuForge, the Collablynx product portal, licensing and entitlement systems, and associated audit and security services.

For this Policy, “Personal Information” or “Personal Data” means information relating to an identified or reasonably identifiable person; “Customer Data” means data submitted to, collected through, or otherwise processed by the Services on a customer’s behalf; and “Customer Personal Data” means Personal Information contained within Customer Data. Terms may have additional meanings under applicable law.

For marketing, account administration, licensing, billing contacts, security operations, and our own business activities, Collablynx generally acts as a controller or business. For Customer Personal Data processed to provide a paid product, Collablynx generally acts as a processor or service provider on the customer organization’s documented instructions, subject to the customer agreement, order form, and applicable Data Processing Addendum.

If you use the Services through an employer or another organization, that organization may control your account, permissions, content, activity logs, integrations, and retention. Its privacy notice may also apply. This Policy does not replace a customer agreement, Business Associate Agreement, Data Processing Addendum, security addendum, sector-specific addendum, or product-specific notice. Where a subject-specific signed agreement conflicts with this Policy, that agreement controls for the subject matter it governs.

2. Categories and sources of information

CategoryExamplesSources
Identity and professional dataName, business email, telephone, employer, title, department, country, and professional profile.You, your organization, identity providers, resellers, marketplaces, and business communications.
Account and entitlement dataUser and organization IDs, roles, purchased products, license seats, authentication events, MFA status, session and device signals, and account preferences.You, organization administrators, Microsoft Entra External ID, the portal, and product systems.
Commercial dataOrders, subscription tier, renewal status, invoices, billing contact, tax information, transaction status, and limited payment metadata.Customers, payment processors, cloud marketplaces, and authorized resellers. Full card numbers should be handled by the payment provider, not submitted to Collablynx forms.
Device, network, and usage dataIP address, browser, device, operating system, timestamps, approximate location from IP, pages, features, API activity, diagnostics, and performance events.Automatically through products, logs, cookies, SDKs, and security systems.
Support, security, and audit dataTickets, attachments, troubleshooting data, sign-in outcomes, audit trails, threat indicators, abuse reports, and incident communications.Users, administrators, products, integrations, monitoring systems, and security vendors.
Customer Data and contentTelemetry, schedules, approvals, documents, prompts, outputs, templates, comments, configurations, and connected-system metadata.Customers, authorized users, collectors, agents, APIs, and customer-selected integrations.
Sensitive or regulated dataHealth, financial, government, education, biometric, genetic, precise location, or other sensitive information only when authorized for an approved use.Customers and integrations when permitted by contract and product configuration.

Do not place passwords, private keys, secrets, full payment-card data, medical records, government identifiers, or other sensitive data in public inquiry forms. Free-text fields should contain only information necessary and authorized for the stated purpose.

3. Customer Data and product-specific processing

  • Vantage: infrastructure inventory, service health, metrics, alerts, cost and utilization signals, configuration metadata, dashboards, integration events, and operational observations.
  • Cadence: schedules, approvals, maintenance windows, runbook references, execution metadata, notifications, job outcomes, and audit records.
  • DocuForge: project descriptions, source documents, templates, prompts, generated content, review comments, approvals, document metadata, and exports.

Customers retain their rights in Customer Data. We process it to provide and secure the selected products, follow documented instructions, enforce entitlements, troubleshoot, prevent misuse, meet contractual and legal obligations, and maintain reliable operations. We do not use Customer Data for data brokerage, unrelated advertising, or cross-customer profiling.

Access to Customer Data by Collablynx personnel or contractors is limited to authorized persons with a legitimate business need, such as product support, security response, reliability, legal compliance, or another customer-authorized purpose. Such access is subject to role-based controls, confidentiality obligations, and applicable logging or review procedures.

Customers are responsible for the lawfulness, accuracy, permissions, notices, retention choices, and data classification of Customer Data they submit or connect. Customers must configure collectors and integrations to avoid excessive or unauthorized collection.

When we create aggregated or de-identified information for analytics, security, service reliability, capacity planning, or product improvement, we will take reasonable measures designed to prevent the information from identifying a customer or individual and will not attempt to re-identify it except to test or validate de-identification where permitted by law.

4. Regulated, confidential, and restricted data

The Services are not automatically authorized for every class of regulated information. Unless an order form or signed addendum expressly states otherwise, customers must not submit:

  • classified information, controlled unclassified information, export-controlled technical data, ITAR-controlled data, or information subject to government handling restrictions;
  • criminal justice information, law-enforcement-sensitive data, or data requiring a specific CJIS environment;
  • full payment-card numbers, card verification values, magnetic-stripe data, PINs, or authentication data governed by payment-card rules;
  • nonpublic financial information subject to specialized financial-services safeguards, except in an approved configuration and agreement;
  • education records, biometric identifiers, genetic information, precise geolocation, or children’s data except where specifically authorized and appropriately protected; or
  • trade secrets, privileged material, or third-party confidential information without authority to process it.

Where an approved enterprise order authorizes regulated data, the applicable contract, security schedule, Data Processing Addendum, Business Associate Agreement, or sector-specific addendum controls over any inconsistent general statement in this Policy. Product marketing, an integration listing, or technical ability to transmit a data type does not by itself constitute authorization to process regulated or restricted information.

5. Health information, HIPAA, and consumer health data

Collablynx products are not HIPAA-enabled by default. Customers must not submit Protected Health Information (“PHI”) or electronic PHI unless: (1) Collablynx and the customer have signed a Business Associate Agreement (“BAA”); (2) the applicable order form expressly authorizes PHI; and (3) the customer uses the approved product, region, identity, encryption, logging, retention, and AI-provider configuration.

When Collablynx creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity or business associate under a signed BAA, Collablynx will act only as permitted by that BAA and applicable HIPAA requirements. The BAA—not this Policy—defines permitted uses, safeguards, security-incident duties, subcontractor requirements, return or destruction obligations, and breach-notification responsibilities. Where required, subcontractors that create, receive, maintain, or transmit PHI on Collablynx’s behalf must be subject to appropriate written business-associate obligations.

Customers without a signed BAA must de-identify health information or avoid submitting it. Health or wellness information that is not PHI may still be protected by state consumer-health laws, general privacy laws, or breach-notification requirements. Where the FTC Health Breach Notification Rule or a similar consumer-health breach law applies to a particular activity, Collablynx will follow the applicable notification obligations. Collablynx is a software provider and does not provide medical diagnosis, treatment, emergency services, or clinical advice.

PHI and sensitive health data must not be routed to an AI provider unless the route is expressly approved for that data, contractually authorized, and covered by all required agreements.

6. AI-enabled features and automated processing

DocuForge and selected features may generate, summarize, classify, transform, or review content using Azure OpenAI, OpenAI, Anthropic, Google, or a customer-controlled private model endpoint, depending on configuration. Prompts, relevant Customer Content, outputs, and technical metadata may be transmitted to the selected provider only as reasonably necessary to perform the requested function.

Collablynx does not use Customer Content to train generalized public AI models unless the customer expressly authorizes that use in writing. Where Collablynx selects or configures an AI provider for a product, Collablynx will not authorize that provider to use Customer Content for generalized model training unless the customer expressly agrees in writing. Customer-controlled or customer-selected AI accounts remain subject to the customer’s agreement and configuration with that provider.

Customers must approve the model route, region, retention settings, data classification, and provider terms before submitting sensitive or regulated information. Collablynx may restrict AI routes for particular data classifications when necessary to satisfy contractual, security, privacy, or regulatory requirements.

AI output can be inaccurate, incomplete, biased, or unsuitable for a specific purpose. Human review is required before using output for legal, healthcare, regulatory, financial, security, employment, architectural, or operational decisions. The Services are not intended to make solely automated decisions that produce legal or similarly significant effects unless expressly agreed and lawfully configured.

7. Accounts, identity, and license security

Customer authentication is provided through the Collablynx portal and approved identity services. Each account is assigned to one identifiable Authorized User. Users must protect credentials, complete required multifactor authentication, maintain accurate account information, and promptly report suspected compromise.

When a device or identity provider uses a fingerprint, face scan, or other local biometric to unlock a passkey or device credential, Collablynx does not intentionally receive the underlying biometric template from the user’s device. Biometric processing performed by the device, operating system, or identity provider is governed by that provider’s applicable terms and settings.

Credential sharing, pooled logins, resale, rental, sublicensing, impersonation, or allowing an unlicensed person to use an account is prohibited. The organization that purchases a Team, Business, or Enterprise subscription may assign purchased seats to Authorized Users, but every person must use a separate account. For an Individual or single-user license, the purchaser is the sole Authorized User unless Collablynx approves a reassignment.

Collablynx may use identity, device, session, IP, concurrency, entitlement, and audit signals to detect suspicious or unauthorized access. We may require re-verification, revoke sessions, suspend accounts, restrict features, charge for unlicensed seats where contractually permitted, preserve relevant logs, notify the organization owner, or terminate access. Unauthorized access or credential sharing is a material breach of the applicable terms and may also violate civil or criminal laws depending on the facts and jurisdiction.

Detailed license and acceptable-use requirements appear in our Terms of Use and Subscription License.

8. How and why we use information

  • provide, authenticate, license, administer, maintain, and support the Services;
  • verify organizations, roles, entitlements, subscriptions, seats, and product access;
  • process inquiries, demos, orders, billing, renewals, support, and customer communications;
  • monitor reliability, performance, security, abuse, fraud, account sharing, and policy violations;
  • troubleshoot, test, improve usability, and develop features using appropriately limited data;
  • send transactional, security, product, legal, and requested marketing communications;
  • comply with law, sanctions, export controls, legal process, and contractual obligations;
  • protect Collablynx, customers, users, systems, and the public; and
  • create aggregated or de-identified information that cannot reasonably identify an individual.

Where law requires a legal basis, the basis depends on the purpose. We generally rely on contract performance for account and product administration; legitimate interests for proportionate security, fraud prevention, service reliability, product improvement, and business communications where those interests are not overridden by individual rights; consent for optional marketing or nonessential technologies where required; and legal obligations where processing is required by law. We may rely on another lawful basis when appropriate and will provide additional notice where required.

9. Disclosures, subprocessors, and integrations

We may disclose information to hosting, cloud, identity, cybersecurity, communications, analytics, payment, support, AI, and professional-service providers acting under contractual restrictions; to customer administrators and Authorized Users; to customer-selected integrations; when required by law or necessary to protect rights and safety; in a corporate transaction; or at the customer’s direction.

We require processors and subprocessors to protect information consistent with their role and applicable agreements and limit their processing to authorized purposes. Customer-selected integrations are governed by the customer’s configuration and the third party’s terms. A current subprocessor list should be made available before enterprise production use. Where required by contract or applicable law, we will provide notice of material new subprocessors and any applicable objection process.

We do not sell personal information, share it for cross-context behavioral advertising, or disclose Customer Data to data brokers. We also do not permit service providers to use Customer Personal Data for their own unrelated advertising or data-brokerage purposes.

10. Cookies and similar technologies

Essential cookies and similar technologies support authentication, security, session continuity, preferences, load balancing, and form protection. Analytics technologies, when enabled, help measure aggregate website and product usage. Marketing technologies, if introduced, will be subject to applicable consent and opt-out requirements. Blocking essential cookies may prevent product access.

Where applicable law requires recognition of a browser-based opt-out preference signal, such as a legally recognized Global Privacy Control signal, we will process the signal as required by law. Because Collablynx does not sell personal information or share it for cross-context behavioral advertising, some sale/share opt-out mechanisms may not apply to our current practices.

11. Retention, deletion, export, and backups

We retain information only as long as reasonably necessary for the purpose collected, customer instructions, account and subscription status, security, audit integrity, legal obligations, dispute resolution, and enforcement. Specific retention periods may be established by product settings, an Order, a Data Processing Addendum, a Business Associate Agreement, or a published retention schedule.

Retention is determined by data category and purpose. Public inquiry and marketing records are retained for the relationship, follow-up, suppression, and legal needs; account, entitlement, billing, and transaction records are retained for subscription administration and applicable accounting or legal requirements; security and audit records are retained for documented security, fraud-prevention, evidentiary, and compliance purposes; and Customer Data follows customer-configured or contractually agreed retention where available.

At termination, export and deletion rights are governed by the applicable agreement. Data may remain temporarily in encrypted backups, immutable security logs, legal holds, or disaster-recovery systems until those systems cycle out under documented retention processes. We may retain minimal account, transaction, entitlement, fraud-prevention, and audit records where legally permitted or required. When deletion is required, we apply it to active systems and allow protected backups to age out unless earlier deletion is technically feasible and legally required.

12. Security, incident response, and customer responsibilities

We use administrative, technical, and organizational safeguards designed to protect confidentiality, integrity, and availability. Measures may include encryption, least privilege, multifactor authentication, tenant isolation, secure development, logging, monitoring, vulnerability management, backup, recovery, change control, vendor review, and incident response.

No system is completely secure. Customers must manage users and roles, secure endpoints, classify data, review integrations, protect credentials, maintain lawful configurations, and promptly report suspected incidents to security@collablynx.com.

When Collablynx confirms a security incident affecting Personal Information or Customer Data for which notice is required, we will provide notice without unreasonable delay and in accordance with applicable law and any controlling DPA, BAA, security addendum, or customer agreement. Notice obligations, recipients, content, timing, and cooperation requirements may differ by law and contract. See Security & Trust.

13. International transfers and data localization

Collablynx operates from the United States and may use providers in other countries or customer-selected regions. Where required, we use recognized transfer safeguards such as the European Commission Standard Contractual Clauses, the applicable UK transfer addendum or agreement, Data Processing Addendum terms, regional controls, transfer assessments, or other lawful mechanisms. We do not claim participation in a certification or transfer framework unless Collablynx is actually certified or otherwise eligible to rely on it.

Customers with localization or sovereignty requirements must select an approved region and contract configuration before submitting regulated data. A selected hosting region does not necessarily mean every support, security, identity, billing, or customer-selected integration operation occurs only in that region unless the applicable agreement expressly provides that restriction.

14. Privacy rights and choices

Depending on location and relationship, individuals may have rights to access, correct, delete, restrict, object, obtain portability, withdraw consent, limit certain uses of sensitive information, opt out of sale or sharing, appeal a decision, or complain to a regulator.

To exercise a right, privacy@collablynx.com. We may verify identity, residency, and authority using information appropriate to the sensitivity of the request. Authorized agents must provide proof where permitted. We will respond within the period required by applicable law and will explain material reasons for a denial or limitation where required. If applicable law provides an appeal right, instructions for appeal will be included in our response.

We will not unlawfully discriminate against an individual for exercising an applicable privacy right. Exceptions may apply for security, fraud prevention, legal compliance, contractual records, privileged information, or legal claims.

For Customer Data controlled by an employer or customer organization, direct the request to that organization first. We will assist as required by our agreement and applicable law. Promotional messages include an unsubscribe option; transactional, security, billing, and legal notices may continue.

15. Jurisdiction-specific notices

United States state privacy laws

Where applicable, our notices describe categories collected, sources, purposes, disclosures, retention criteria, and consumer rights. We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer unrelated characteristics. Where a legally recognized opt-out preference signal applies, we will honor it as required by law. Applicable state laws may also provide rights to appeal certain privacy-request decisions and protections against discriminatory treatment for exercising privacy rights.

Consumer health privacy

Where a state consumer-health privacy law applies to health information outside HIPAA, we will apply the notices, consent or authorization, processor-contract, deletion, and other requirements applicable to our role and processing. Authorization to process PHI under HIPAA does not automatically authorize processing under every state consumer-health law, and vice versa.

EEA, United Kingdom, and Switzerland

Where applicable, individuals may contact the relevant supervisory authority. We process Personal Data as controller or processor depending on context, facilitate applicable rights, and use lawful transfer mechanisms for restricted international transfers.

Canada, Brazil, and other regions

We honor applicable access, correction, deletion, consent, transparency, portability, objection, and complaint rights as required by law. Additional local notices, representatives, or contract terms may apply.

16. Children

The Services are intended for business and professional users and are not directed to children. We do not knowingly collect personal information from anyone under 18 through public or self-service channels. Customers must not create child accounts or submit children’s data unless expressly authorized by contract and applicable law. If we learn that personal information was submitted through a public or self-service channel in violation of this restriction, we may disable the account and take reasonable steps to delete or otherwise lawfully handle the information.

17. Legal process, protection, and corporate events

We may preserve, access, or disclose information when we reasonably believe it is necessary to comply with law or valid legal process, enforce agreements, investigate fraud or abuse, protect rights or safety, or complete a merger, financing, acquisition, reorganization, or sale.

For governmental or law-enforcement demands, where reasonably practicable and legally permitted, we will review the request for facial validity and scope, seek clarification or narrowing of overbroad requests, disclose only information we are legally required to provide, and notify the affected customer before disclosure when permitted by law and required by contract. Nothing in this statement requires Collablynx to challenge a lawful request when doing so would be unlawful, impracticable, or materially threaten safety or security.

In a corporate transaction, we will use reasonable measures to require the recipient to protect Personal Information and Customer Data consistently with applicable law and any continuing contractual obligations.

18. Changes to this Policy

We may update this Policy as products, providers, laws, and practices change. The effective date identifies the current version. Material changes will receive additional notice where required. We will not retroactively use Customer Data or previously collected Personal Information for a materially different purpose when applicable law or a contractual commitment requires additional notice, authorization, or consent.

We will maintain reasonable records of material policy revisions and may make prior versions available on request or through a public policy archive.

19. Contact us

Questions, complaints, privacy requests, or concerns about this Policy may be sent to:

Collablynx
Email: privacy@collablynx.com

This Policy describes general practices and does not represent that every Collablynx product configuration is authorized for every regulated data type. Contract-specific terms, approved product configurations, and applicable law control where relevant.

Collablynx

Vantage operations intelligence, Cadence orchestration, and DocuForge enterprise AI documentation for cloud, on-premise, and mainframe-adjacent environments.

VantageCadenceDocuForge

Products

  • Vantage
  • Cadence
  • DocuForge
  • Pricing

Resources

  • Platform Architecture
  • Product Guides
  • Integrations
  • Security & Trust
  • FAQs
  • Release Notes

Customer

  • Request a Demo
  • Product Inquiry
  • Product Support

Legal

  • Privacy Policy
  • Terms
  • Cookie Policy
  • Accessibility
  • Security
© 2026 Collablynx Independent software products for governed enterprise operations.