Skip to main content

Privacy Policy

Last updated: May 31, 2026

Document owner: Chief Privacy Officer (DPO delegate) Review cadence: Quarterly; ad hoc upon material product, vendor, or regulatory change Effective date: 2026-05-31 Controller / Legal entity: EthicPages, Inc. Registered address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ Primary contact: ethicpages+contact@invictosoft.com

Overview

EthicPages, Inc. ("EthicPages," "we," "us," or "our") provides a B2B SaaS platform that helps organizations generate, publish, and maintain procurement-ready Trust Centers — including privacy policies, security overviews, subprocessors lists, DPAs, and related compliance documentation. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal data when you visit ethicpages.com, create an account, subscribe to paid plans, use our AI-assisted document generation, or interact with our support and marketing channels.

This policy applies to personal data for which EthicPages acts as data controller. When we process personal data on behalf of our customers as part of hosted Trust Center or document generation services, our Data Processing Agreement and customer instructions govern. See also our Cookie Policy, Subprocessor List, and Data Retention Schedule.

We do not sell personal data. We do not use personal data for cross-context behavioral advertising.

Roles and scope

EthicPages operates in distinct processing roles depending on context:

RoleContextExamplesGoverning document
ControllerAccount, billing, website, marketing, securityAdmin name, email, Stripe customer ID, analyticsThis Privacy Policy
ProcessorCustomer-directed Trust Center content and hosted pagesEnd-user data described in customer documentsDPA
ProcessorAI document generation from onboarding profilesCompany name, industry, compliance postureDPA; AI Usage Policy

Who this policy covers

AudienceDescription
Account holdersUsers who register, subscribe, or administer EthicPages workspaces
Authorized usersTeam members invited to a customer workspace
Website visitorsIndividuals who browse ethicpages.com without an account
ProspectsIndividuals who submit contact forms or request demos
Job applicantsIndividuals applying via Careers channels

Categories of personal data we collect

CategoryExamplesSourceRequired?
Account & identityName, work email, password hash, job titleYouYes, for account creation
Organization profileCompany name, industry, size, compliance frameworksYou (onboarding)Yes, for document generation
Billing & subscriptionStripe customer ID, plan tier, invoice history, tax identifiersYou; StripeYes, for paid plans
Authentication & securitySession tokens, MFA metadata, login timestamps, IP addressAutomaticYes, for secure access
Usage & product analyticsPages viewed, feature usage, device type, referrerAutomatic; cookiesNo (non-essential analytics require consent where required)
Generated contentTrust Center documents, markdown exports, hosted page contentYou; AI generationService delivery
Support & communicationsTicket content, email threads, call notesYouOptional
Marketing preferencesNewsletter opt-in, campaign engagementYou; cookiesOptional

We instruct customers not to include unnecessary personal data in free-text onboarding fields. Our AI Usage Policy describes how profile data is sent to model providers.

Purposes and lawful bases (EEA/UK GDPR)

PurposeData usedLawful basis (GDPR Art. 6)
Provide and operate the ServiceAccount, profile, generated content, usageContract (Art. 6(1)(b))
Process subscriptions and invoicesBilling, identityContract; Legal obligation (tax)
Authenticate users and prevent fraudAuth, security logs, IPLegitimate interests (security); Contract
Improve product quality (aggregated)Usage analyticsLegitimate interests; consent where required
Send service and transactional emailEmail, nameContract; Legitimate interests
Send marketing (where permitted)Email, preferencesConsent (Art. 6(1)(a)) or soft opt-in where permitted
Comply with law and respond to authoritiesAny relevant dataLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claimsRelevant account and billing dataLegitimate interests

Where we rely on legitimate interests, we balance our interests against your rights and provide objection rights as described below.

How we use personal data

Service delivery

We use account and onboarding data to generate Trust Center documents calibrated to your industry and compliance posture. Hosted Trust Centers (on eligible plans) display content you approve. We process this data solely to provide the service described in our Terms of Service.

Billing and account management

We use Stripe for payment processing. EthicPages does not store full payment card numbers. We retain billing metadata for subscription management, dunning, refunds (per our Refund Policy), and tax compliance. See Billing Terms.

Security and abuse prevention

We process security logs, IP addresses, and device signals to detect unauthorized access, enforce our Acceptable Use Policy, and protect the platform. See our Security Overview for technical controls.

Communications

We send transactional emails (account verification, password reset, billing receipts) via Resend. Marketing emails are sent only where permitted by law and your preferences. You may unsubscribe from marketing at any time.

Cookies and similar technologies

We use cookies and similar technologies as described in our Cookie Policy. Non-essential cookies require consent in the EEA, UK, and similar jurisdictions. Essential cookies are required for authentication and checkout.

Sharing and subprocessors

We share personal data with:

Recipient typePurposeSafeguards
SubprocessorsHosting, database, email, payments, AI inferenceDPAs; see Subprocessor List
Professional advisorsLegal, accounting, auditConfidentiality agreements
AuthoritiesLawful requestsVerified per Law Enforcement Guidelines
Business transfereesMerger, acquisition, asset saleNotice where required by law

We maintain data processing agreements with subprocessors that handle personal data. Material subprocessor changes are notified to active customers per our DPA.

International transfers

EthicPages is operated by EthicPages, Inc. with infrastructure primarily in the United States. Personal data may be transferred to the US and other countries where subprocessors operate.

Transfer mechanismApplicability
EU Standard Contractual Clauses (2021 modules)EEA transfers to third countries
UK International Data Transfer AddendumUK transfers
Supplementary measuresEncryption in transit and at rest; access controls; transfer impact assessments

Copies of transfer mechanisms are available upon request to ethicpages+contact@invictosoft.com with subject line "Transfer Mechanisms."

Retention

Detailed retention periods are in our Data Retention Schedule. Summary:

Data typeRetention periodDeletion trigger
Active account & profileDuration of subscriptionAccount closure request
Generated Trust Center contentUntil deleted by you or account closureUser deletion or termination
Billing & tax records7 years after last transactionLegal retention requirement
Application logs90 daysAutomated purge
Security logs12 months (then archived 24 months)Automated lifecycle
Marketing preferencesUntil opt-out + 30 daysUnsubscribe
Support tickets3 years after resolutionAutomated purge

Upon account termination, we delete or anonymize personal data within 30 days except where retention is required by law or legitimate business need (e.g., billing disputes).

Your privacy rights

Depending on your jurisdiction, you may have the following rights:

RightDescriptionHow to exercise
AccessObtain a copy of your personal dataEmail ethicpages+contact@invictosoft.com
RectificationCorrect inaccurate dataAccount settings or email us
ErasureRequest deletionAccount closure or email us
RestrictionLimit processing in certain casesEmail us
PortabilityReceive data in machine-readable formatEmail us
ObjectionObject to legitimate-interest processingEmail us
Withdraw consentWhere processing is consent-basedUnsubscribe or email us

We respond to verified requests within 30 days (45 days for complex requests with notice). We may request identity verification. You may lodge a complaint with your supervisory authority.

California (CCPA/CPRA) notice

California residents have rights to know, delete, correct, and opt out of "sale" or "sharing." EthicPages does not sell or share personal data for cross-context behavioral advertising. To exercise rights, contact ethicpages+contact@invictosoft.com. We do not discriminate against consumers exercising privacy rights.

Children's privacy

EthicPages is a B2B service not directed to individuals under 18. We do not knowingly collect personal data from children. Contact us to request deletion if you believe we have collected a child's data.

Security

We implement administrative, technical, and organizational measures described in our Security Overview. No method of transmission or storage is 100% secure. Report suspected vulnerabilities via our Responsible Disclosure Policy.

Changes to this policy

We update this Privacy Policy when our practices, products, or legal requirements change. Material changes are communicated via email or in-app notice at least 14 days before effective date where required. The "Last updated" date at the top of this page reflects the latest revision.

Contact and data protection inquiries

Inquiry typeContact
Privacy & data subject requestsethicpages+contact@invictosoft.com (subject: Privacy)
DPA & processor questionsethicpages+contact@invictosoft.com (subject: DPA)
Security incidentsethicpages+contact@invictosoft.com (subject: Security)
PostalEthicPages, Inc., 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Related documents: Terms of Service · Cookie Policy · DPA · Subprocessors · Data Retention · AI Usage Policy

Template for operational transparency; not legal advice. Consult qualified counsel for your jurisdiction.