Privacy Policy

Effective date: 2026-09-26

1. Introduction & Scope

This Privacy Policy explains how Persoon.ai Inc. ("scm.cc", "we", "us") collects, uses, discloses, and safeguards personal data when you visit our websites, create an account, or use the scm.cc platform and related services (the "Services"). It applies to personal data we process as a controller - for example, account data and website-visitor data.

When a customer uses the Services to process personal data contained in their connected sources (for example, repository, cloud, or scanner data ingested through our connectors), the customer is the controller of that data and we act as a processor on their behalf. Our processing in that role is governed by the customer agreement and, where executed, a Data Processing Agreement (DPA) rather than by this Policy.

2. Personal Data We Collect

We collect the categories of personal data below, depending on how you interact with the Services. Connected-source content is processed under the customer agreement, not as data we collect for our own purposes.

3. How We Use Personal Data

4. Legal Bases for Processing

Where the GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases: providing the Services under your agreement (performance of a contract); security, fraud prevention, and product improvement (legitimate interests); marketing emails and non-essential analytics (consent, where required); tax and regulatory records (legal obligation).

5. How We Share Personal Data

We do not sell personal data. We share personal data only as described below:

Subprocessors are bound by contractual confidentiality and data-protection obligations consistent with this Policy.

6. International Data Transfers

Our infrastructure and subprocessors process personal data primarily in the United States, and may process it in other regions. Where personal data is transferred across borders from jurisdictions that restrict such transfers, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum where applicable) as made available through our subprocessors' data-processing terms. We have not appointed an EU or UK representative under Article 27; EU/UK users with questions about that posture can reach us at info@persooninc.com.

7. Data Retention

We retain personal data for as long as needed to provide the Services and for legitimate business and legal purposes. Account data is retained for the life of the account and deleted or anonymized after account closure; security logs and audit-trail entries are retained per our internal retention schedule. Connector content processed on a customer's behalf is retained while the source remains connected and is deleted under the customer agreement on disconnection or account deletion.

Deletion is applied to live systems immediately. Copies can persist in vendor-managed backups for a limited period until those backups expire on the provider's schedule; erasure is re-applied after any recovery from backup.

8. Your Privacy Rights

Depending on your jurisdiction (for example, under the GDPR/UK GDPR or U.S. state privacy laws), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. You may also have the right to lodge a complaint with a supervisory authority.

To exercise these rights - including requesting deletion or export of your account and personal data - contact us at info@persooninc.com. Where we act as a processor for connected-source data, please direct requests to the relevant customer (controller); we will assist them as required. We will verify your identity before acting on a request and will respond within the timeframes required by applicable law.

9. U.S. State Privacy Laws & Do Not Track

Comprehensive state privacy laws apply only above defined thresholds. We do not currently meet the applicability thresholds of the CCPA/CPRA (California) or the Virginia, Colorado, Connecticut, Utah, or similar state statutes (for example, 100,000+ consumers or the revenue tests those laws set). We say that plainly rather than pretending otherwise - and we voluntarily extend the access, correction, deletion, and portability rights in Section 8 to all users regardless of state.

For California residents (CalOPPA): this Policy identifies the categories of personal data we collect (Section 2), how we use and share it (Sections 3 and 5), and how to review or request changes to your information (Section 8). We do not respond to browser "Do Not Track" signals; no third-party advertising trackers run on authenticated pages.

We do not sell or share personal data for cross-context behavioral advertising, and we do not use or disclose sensitive personal information outside the purposes these laws permit without an opt-out.

10. Email, Breach Notice & Accessibility

Service email (sign-in verification, security alerts, receipts) is transactional. Any marketing email we send includes a working unsubscribe link honored promptly and our physical postal address, as the CAN-SPAM Act requires; unsubscribing never affects service email.

If a breach of our systems results in unauthorized acquisition of your personal data, we will notify affected users consistent with applicable state breach-notification laws (including Wyoming's) without unreasonable delay, and will notify regulators where the law requires it.

We strive to keep the Services usable with current assistive technologies (WCAG 2.1 AA as our target) and treat accessibility barriers as bugs; report them to info@persooninc.com.

11. Security, Children & Changes

We apply administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit (TLS) and at rest, role-based access controls, and append-only audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

The Services are intended for business use and are not directed to children; we do not knowingly collect personal data from anyone under 16, and never from a child under 13 (COPPA). If we learn we hold a child's data, we delete it.

We may update this Policy from time to time. Material changes will be communicated through the Services or by email, and the effective date above will be updated. Questions may be directed to Persoon.ai Inc. at info@persooninc.com.