PRIVACY & DATA POLICY
Effective Date: September 5, 2026
Last Updated: September 5, 2026
Version: 1.0
This Privacy & Data Policy ("Privacy Policy") explains how Purpura Quadrum, LLC ("Company," "we," "our," or "us") collects, uses, stores, shares, protects, and otherwise processes information relating to the AnnexusX Services ("Services").
By creating a User Account, accessing, or using the Services, Users acknowledge that they have read and understood this Privacy Policy.
This Privacy Policy should be read together with the Company's Terms & Conditions, which govern the use of the Services.
ARTICLE 1 – SCOPE
1.1 Purpose
This Privacy Policy describes how the Company processes information relating to the Services, including information Users provide directly, information generated through use of the Services, information received from connected Third-Party Services, and other information processed in connection with providing, maintaining, securing, improving, and supporting the Services.
1.2 Scope
This Privacy Policy applies to:
the Services;
Company-operated websites relating to the Services;
mobile applications;
desktop applications;
support interactions;
communications relating to the Services; and
any other Company-operated experiences that reference this Privacy Policy.
Where a separate privacy policy is expressly provided for a particular product or service, that policy shall govern instead.
1.3 Definitions
Capitalized terms not defined in this Privacy Policy have the meanings assigned to them in the Terms & Conditions.
ARTICLE 2 – INFORMATION WE COLLECT
2.1 Categories of Information
The Company processes different categories of information depending on how the Services are used.
For clarity, this Privacy Policy distinguishes between:
User Content, which consists of information, materials, files, communications, prompts, and other content created, submitted, uploaded, imported, connected, or otherwise provided by a User through the Services;
Usage Data, which consists of information generated through interaction with the Services, including operational, diagnostic, security, performance, and usage information; and
Account Information, which consists of information reasonably necessary to establish, maintain, secure, support, and administer a User Account.
The categories described below may include personal information where applicable under relevant law.
2.2 Account Information
The Company may collect information reasonably necessary to create, authenticate, administer, secure, support, and maintain User Accounts.
Depending on how the Services are used, this may include information such as:
name;
email address;
account credentials;
authentication information;
subscription status;
billing status;
account preferences;
communication preferences;
campaign and landing-page identifiers associated with Account creation;
subscription and transaction records;
identifiers associated with connected Third-Party Services; and
other information necessary to provide the Services.
Payment processing, when offered through the Services, may be performed by an authorized payment provider.
Full payment card numbers and other payment credentials collected directly by a payment provider are not stored by the Company.
The Company may retain transaction identifiers, subscription status, invoice information, payment status, and other billing records reasonably necessary to administer Subscriptions, respond to billing questions, prevent fraud, and comply with applicable accounting, tax, and legal obligations.
2.3 User Content
Users may create, connect, synchronize, generate, or otherwise provide text-based content through the Services.
Depending on the Product Features used, User Content may include:
notes;
tasks;
projects;
text created within the Services;
calendar events and related scheduling information;
contact records;
email message text and associated metadata;
prompts or information intentionally submitted to Intelligent Features;
Generated Content created for the User;
text-based information received through connected Third-Party Services; and
other text-based content Users choose to provide through the Services.
The Company does not currently provide general file-upload functionality and does not retrieve or store email attachments, images, screenshots, or other attached files from connected email services.
Where an email contains an attachment, the Services may process metadata indicating that an attachment exists or provide a reference directing the User to the original email within the connected Third-Party Service, where such functionality is available.
The Company does not represent that attachments or other files available through a connected Third-Party Service are scanned, analyzed, or secured by AnnexusX.
Ownership of User Content is governed by the Terms & Conditions.
2.4 Usage Data
The Company automatically collects certain operational information relating to the use of the Services.
Usage Data may include:
feature usage;
interaction patterns;
performance information;
crash reports;
diagnostic information;
device characteristics;
browser information;
operating system information;
network information;
authentication events;
timestamps;
error logs;
security information; and
other technical information reasonably necessary to operate, secure, maintain, analyze, and improve the Services.
Usage Data generally describes how the Services are used rather than the substance of User Content.
2.5 Connected Services
When a User chooses to connect Third-Party Services, the Company may receive information made available through those authorized connections.
The Company processes only the information reasonably necessary to provide the requested integration and in accordance with permissions granted by the User.
Users may disconnect Third-Party Services at any time, subject to applicable limitations described in the Services or the Terms & Conditions.
2.6 Google Services and Google User Data
When a User connects a Google Account, the Company may receive information authorized by the User through Google Account authentication and connected Google services, including Gmail, Google Calendar, and Google Contacts.
The specific information accessed and actions available depend on the permissions granted by the User and the Product Features the User chooses to use.
2.7 Google Workspace User Data and Limited Use
The Company's use and transfer of information received through Google APIs adheres to the Google API Services User Data Policy and, where applicable, the Google Workspace User Data and Developer Policy, including the Limited Use requirements.
Google user data is accessed and used only to provide or support User-facing Product Features that the User has requested, enabled, or authorized.
The Company does not:
sell Google user data;
use Google user data for advertising, retargeting, personalized advertising, or interest-based advertising;
transfer Google user data to advertising platforms, data brokers, or information resellers;
use Google user data to determine creditworthiness or for lending purposes; or
use Google user data to create, train, or improve generalized artificial intelligence or machine learning models.
The Company may transfer Google user data only where permitted under applicable Google policies, including where reasonably necessary to provide or support an authorized User-facing Product Feature, for security purposes, to comply with applicable law, or in connection with a qualifying business transaction where any consent required by Google policy has been obtained.
The Company does not permit humans to read Google user data except where:
the User has expressly authorized access to specific messages or other specific information;
access is necessary for security purposes, including investigating abuse, unauthorized access, or security incidents;
access is necessary to comply with applicable law or valid legal process; or
the information has been aggregated and anonymized and is used for lawful internal operations.
Access to Google user data is limited to the minimum information reasonably necessary for the applicable permitted purpose.
Users may revoke AnnexusX access to their Google Account through their Google Account connection settings. Additional information concerning disconnection and revocation following Account deletion is provided in Article 6.
2.8 Communications
The Company may collect information contained in communications between Users and the Company, including support requests, account inquiries, bug reports, feature requests, and other correspondence relating to the Services.
Communications sent to Company email addresses may include files or attachments a sender voluntarily chooses to include. Such communications are processed through the Company's business communication provider as described in the Service Providers and Subprocessors Disclosure.
2.9 Feedback
Users may voluntarily submit comments, suggestions, recommendations, feature requests, bug reports, surveys, or other feedback regarding the Services.
The Company may use such feedback to evaluate, improve, develop, maintain, and support the Services.
Submission of feedback does not obligate the Company to implement, respond to, acknowledge, or compensate Users, and ownership and licensing of feedback are governed by the Terms & Conditions.
2.10 Information from Other Sources
The Company may receive information from identity providers, payment providers, connected Third-Party Services, service providers, or other sources authorized by the User or otherwise permitted by applicable law.
2.11 Sensitive Information Within User Content
Because Users may connect communications, calendars, contacts, and other Third-Party Services, User Content may incidentally contain information that is considered sensitive or subject to special protection under applicable law.
The Company does not use the contents of such information to create advertising profiles, infer sensitive characteristics about Users for unrelated purposes, or make decisions producing legal or similarly significant effects.
Where sensitive information appears within User Content, the Company processes it only as reasonably necessary to provide User-requested Product Features, secure and operate the Services, comply with applicable law, or as otherwise described in this Privacy Policy.
ARTICLE 3 – HOW WE USE INFORMATION
3.1 Providing the Services
The Company processes Account Information, User Content, and Usage Data as reasonably necessary to provide, operate, maintain, and support the Services requested by the User.
Depending on the features used, this may include authenticating Users, synchronizing information, enabling Intelligent Features, maintaining User Accounts, processing subscriptions, facilitating connected services, and otherwise delivering the functionality of the Services.
3.2 Service Operations
The Company may process information to:
maintain and improve the reliability of the Services;
monitor system performance;
troubleshoot technical issues;
detect, investigate, and resolve errors;
maintain security;
prevent fraud, abuse, unauthorized access, or misuse;
administer User Accounts; and
otherwise operate the Services.
3.3 Intelligent Features
Information intentionally submitted to an Intelligent Feature is processed only as reasonably necessary to provide the functionality requested by the User.
The Company does not use User Content to train generalized artificial intelligence or machine learning models.
Usage Data relating to Intelligent Features may be analyzed to understand feature adoption, performance, reliability, errors, and interaction patterns and to improve the Services. Such analysis is based on Usage Data and operational information rather than the substance of User Content unless expressly disclosed otherwise.
Ownership of User Content and Generated Content is governed by the Terms & Conditions.
3.4 Support Assistant
The Company may provide an artificial-intelligence-assisted support feature designed to answer questions about AnnexusX and its functionality.
The support assistant processes information intentionally submitted by the User directly to the support interaction for the purpose of responding to that request.
The support assistant does not independently access, retrieve, read, or receive User Content stored within the User's Account and does not access information from Gmail, Google Calendar, Google Contacts, or other connected Third-Party Services.
The support assistant cannot independently create, modify, send, delete, schedule, or otherwise take actions within a User's Account.
The Company does not use support conversations or User Content submitted through support interactions to train generalized artificial intelligence or machine learning models.
Where the technologies or providers used to operate the support assistant materially change, the Company will update this Privacy Policy or the Service Providers and Subprocessors Disclosure as appropriate.
3.5 Product Improvement
The Company may analyze Usage Data to better understand how the Services are used, identify opportunities for improvement, develop new functionality, enhance reliability, improve accessibility, optimize performance, and inform future product decisions.
Unless otherwise expressly stated in this Privacy Policy, Product Improvement activities are based on Usage Data, aggregated information, and operational information rather than the substance of User Content.
The Company does not use the substance of User Content to develop advertising profiles or train generalized artificial intelligence or machine learning models.
3.6 Communications
The Company may process Account Information to communicate with Users regarding:
account administration;
authentication;
security;
billing;
subscriptions;
onboarding;
customer support;
legal notices;
changes to the Services;
updates to legal agreements; and
other communications reasonably necessary to provide the Services.
Optional product-update or promotional communications will provide a reasonable method to unsubscribe or opt out.
Opting out of product-update or promotional communications does not affect operational, authentication, security, billing, legal, or other communications reasonably necessary to provide or administer the Services.
3.7 Legal Compliance
The Company may process information as reasonably necessary to:
comply with applicable law;
respond to lawful governmental requests;
comply with court orders or legal process;
enforce the Company's legal rights;
investigate suspected violations of the Terms & Conditions;
protect the safety, rights, property, Users, or the Company; or
fulfill other legal obligations.
3.8 User Feedback
The Company may review feedback voluntarily submitted by Users to evaluate, maintain, improve, and develop the Services.
Submission of feedback does not obligate the Company to implement any suggestion, respond to the feedback, acknowledge its receipt, or provide compensation.
The Company's rights relating to submitted feedback are governed by the Terms & Conditions.
3.9 Aggregated and De-Identified Information
The Company may create, use, analyze, and retain aggregated, statistical, or de-identified information derived from Usage Data for lawful business purposes, including improving, maintaining, securing, measuring, and developing the Services.
The Company will not intentionally use aggregated or de-identified information in a manner intended to identify an individual User.
3.10 Legal Bases for Processing
Where the data protection laws of the European Economic Area, Switzerland, or the United Kingdom apply, the Company relies on one or more of the following legal bases depending on the processing involved:
Performance of a Contract
The Company processes information where reasonably necessary to:
create and administer an Account;
authenticate a User;
provide Product Features requested or enabled by the User;
synchronize authorized Third-Party Services;
maintain a Subscription; and
provide account, support, and service functionality.
Legitimate Interests
The Company may process information where reasonably necessary for legitimate interests including:
protecting the security and integrity of the Services;
preventing fraud, abuse, and unauthorized access;
diagnosing errors and maintaining Service reliability;
analyzing Usage Data to understand and improve the Services;
measuring campaign effectiveness and analyzing campaign cohorts;
establishing, exercising, or defending legal claims; and
maintaining reasonable business and operational records.
Where the Company relies on legitimate interests, it considers those interests in relation to the rights and reasonable expectations of affected individuals.
Legal Obligations
The Company may process information where reasonably necessary to comply with applicable legal, regulatory, accounting, tax, court, or governmental requirements.
Consent
The Company does not currently rely on consent as the legal basis for providing the core Services or for the routine processing described in this Privacy Policy.
Where the Company introduces a processing activity for which consent is the appropriate or legally required basis, the Company will request that consent before beginning the applicable processing.
Where processing is based on consent, the individual may withdraw that consent as permitted by applicable law. Withdrawal of consent does not affect processing lawfully performed before consent was withdrawn.
Authorization granted to connect a Third-Party Service, including authorization through Google OAuth, permits the technical connection requested by the User and does not necessarily mean that consent is the Company's legal basis for processing under applicable data protection law.
The Company will identify additional or different legal bases where required before materially new processing begins.
3.11 Campaign Attribution and Cohort Analysis
The Company may associate campaign and landing-page identifiers with an Account when a visitor creates an Account after arriving through a Company marketing campaign.
The Company may analyze those identifiers together with Account Information and Usage Data to understand matters such as:
which campaigns result in Account creation;
which landing experiences are effective;
how groups of Users acquired through different campaigns use the Services;
retention and engagement patterns among campaign groups; and
the overall effectiveness of Company marketing activities.
This analysis is intended to evaluate campaigns and groups of Accounts rather than to make decisions about individual Users.
The Company does not use campaign attribution to determine eligibility for the Services, alter legal rights, determine creditworthiness, or make other decisions producing legal or similarly significant effects.
3.12 Automated Decision-Making
The Company does not currently use personal information to make decisions based solely on automated processing that produce legal effects concerning a User or similarly significantly affect a User.
If the Company introduces Product Features involving such decision-making, it will provide any notice, explanation, rights, or consent required by applicable law before or when that processing begins.
ARTICLE 4 – COOKIES, SIMILAR TECHNOLOGIES, AND AUTOMATED DATA COLLECTION
4.1 Operational Technologies
Within the authenticated Services, the Company may use cookies, local storage, session information, or similar technologies where reasonably necessary to authenticate Users, maintain secure sessions, maintain operational settings, prevent fraud or abuse, protect the Services, or provide functionality requested by the User.
These technologies are used for operation and security rather than advertising, behavioral profiling, or campaign attribution.
The Company does not currently use local storage, session storage, cookies, or similar device-storage technologies on its marketing pages to persist campaign identifiers.
4.2 No Advertising or Behavioral Tracking Technologies
The Company does not currently use advertising cookies, third-party behavioral analytics cookies, advertising pixels, retargeting pixels, or similar technologies on Company-operated properties to track Users across unrelated websites or services.
The Company does not permit advertising platforms to place technologies within the Services for personalized or interest-based advertising.
If the Company introduces non-essential tracking or advertising technologies in the future, this Privacy Policy will be updated and consent or other controls will be provided where required by applicable law.
4.3 Campaign Measurement
The Company measures the effectiveness of marketing using campaign identifiers contained in the web address of a landing page.
These identifiers may describe information such as the referring platform, campaign, audience group, region, language, creative version, or landing experience. A campaign identifier describes the marketing source or experience and is not a unique identifier assigned to an individual visitor.
The Company's campaign-measurement system does not use campaign identifiers to recognize a visitor when the visitor later returns independently to the Company's website.
If a visitor creates an Account during a campaign-associated visit, the applicable campaign identifier and landing-page identifier may be recorded as part of the Account record.
Campaign identifiers used for this purpose are carried through the applicable visit without being stored in local storage, session storage, advertising cookies, or similar device-storage technologies for campaign attribution.
The Company may associate those values with Usage Data in order to understand conversion, engagement, retention, and other patterns among groups of Accounts acquired through different campaigns.
Campaign analysis is performed to evaluate marketing campaigns and cohorts. It is not used to make decisions producing legal or similarly significant effects concerning individual Users.
The Company does not assign a persistent marketing identifier to an unauthenticated visitor and does not use campaign identifiers to recognize that visitor on a later independent visit.
The Company does not currently transmit Account information, conversion events, or campaign-attribution records to advertising platforms for retargeting, personalized advertising, or interest-based advertising.
4.4 Server and Infrastructure Logs
As with other internet services, the Company and its infrastructure providers may process technical information generated when browsers, devices, and networks communicate with the Services.
Such information may include IP addresses, timestamps, request information, browser or device characteristics, network information, authentication events, security information, and error information.
This information is processed for purposes such as security, abuse prevention, troubleshooting, performance, availability, and reliable operation of the Services.
4.5 Changes to Tracking Technologies
If the Company materially changes the technologies used to measure marketing, analyze visitors, or track activity across websites or services, the Company will update this Privacy Policy and provide any consent mechanism, opt-out, or other control required by applicable law.
ARTICLE 5 – HOW INFORMATION IS SHARED
5.1 General Principle
The Company does not sell or rent Users' personal information.
The Company does not currently share personal information for cross-context behavioral advertising or use personal information for targeted advertising based on activity across unrelated businesses, websites, or services.
The Company discloses information only as reasonably necessary to provide and secure the Services, operate authorized Third-Party Service connections, comply with legal obligations, complete User-directed actions, or otherwise as described in this Privacy Policy.
5.2 Service Providers
The Company may share information with third-party service providers that perform services on the Company's behalf.
These services may include, without limitation:
authentication;
payment processing;
hosting;
cloud infrastructure;
communications;
customer support;
security;
analytics;
monitoring;
data storage;
backup;
and other operational functions reasonably necessary to provide the Services.
Service providers receive only the information reasonably necessary to perform their respective services.
A current list of material service providers and subprocessors used in operating the Services is available in the Company's Service Providers and Subprocessors Disclosure.
5.3 Connected Third-Party Services
When a User voluntarily connects a Third-Party Service, the Company may exchange information with that Third-Party Service as reasonably necessary to establish, maintain, and operate the requested integration.
The Company's processing of information received through connected Third-Party Services remains subject to this Privacy Policy, while the User's relationship with the Third-Party Service remains subject to that provider's own terms and privacy practices.
5.4 Legal Requirements
The Company may disclose information where reasonably necessary to:
comply with applicable law;
respond to valid legal process;
satisfy lawful governmental requests;
enforce this Privacy Policy or the Terms & Conditions;
protect the rights, property, or safety of the Company, Users, or others; or
investigate fraud, security incidents, or suspected unlawful activity.
The Company reviews requests for information and discloses only the information reasonably necessary to satisfy the applicable legal obligation or request.
5.5 Business Transactions
Information governed by this Privacy Policy may be transferred in connection with a merger, acquisition, financing, corporate restructuring, reorganization, bankruptcy, sale of assets, or similar business transaction involving the Company, subject to applicable law and contractual restrictions governing the information.
Any transfer of Google user data in connection with a merger, acquisition, or sale of assets will be handled in accordance with applicable Google policies, including obtaining prior User consent where required.
A successor or acquiring entity receiving personal information remains subject to applicable legal obligations governing that information.
5.6 With User Direction
The Company may disclose or transmit information where expressly directed or authorized by the User through the Services.
5.7 Aggregated and De-Identified Information
The Company may share aggregated or de-identified information that does not intentionally identify an individual User for lawful business purposes, including research, reporting, analytics, service improvement, and operational planning.
5.8 Government and Legal Process Requests
The Company requires valid legal process or another lawful basis before disclosing personal information in response to a request from law enforcement, a governmental authority, or another party seeking information through compulsory legal process.
The Company reviews requests for legal sufficiency and scope and discloses only information reasonably necessary to respond to the applicable lawful request.
Where appropriate and legally permitted, the Company may seek clarification, narrowing, or other appropriate relief with respect to a request that appears overbroad, unclear, or legally defective.
Where permitted by law, the Company may notify an affected User before information is disclosed. Notice may not be provided where prohibited by law, where an emergency involving risk of death or serious physical injury exists, or where notice would otherwise be legally inappropriate.
Certain information displayed through AnnexusX originates from Third-Party Services. The Company's ability to respond to a request is limited to information maintained within systems under the Company's control.
ARTICLE 6 – DATA RETENTION
6.1 Retention Principles
The Company retains information only for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, preserve business records, or fulfill other legitimate business purposes.
Retention periods may vary depending on the type of information involved and applicable legal requirements.
6.2 Active User Accounts
While a User Account remains active, the Company generally retains Account Information, User Content, and Usage Data as reasonably necessary to provide the Services.
6.3 Account Deletion
When a User requests permanent deletion of an Account, the Company begins the Account deletion process.
The Company generally retains Account Information and User Content for approximately thirty (30) days following the end of Account access, subject to applicable deletion requests and the exceptions described in this Article.
During this period, the Company may make account-management, data-access, portability, or reactivation options available where supported by the Services.
Signing in alone does not restart a cancelled paid Subscription or authorize a new charge.
A User may request permanent deletion during this period, subject to applicable legal, security, backup, and operational requirements.
Following the applicable retention period, the Company deletes or permanently de-identifies User Content and Account Information from active systems, subject to the exceptions described in this Article.
6.4 Google Authorization Following Account Deletion
When a User permanently deletes an AnnexusX Account, the Company attempts to revoke the authorization previously granted through Google OAuth.
Revocation is intended to prevent the Company from accessing the User's connected Google services in the future.
Revoking authorization does not delete emails, calendar events, contacts, or other information remaining within the User's Google Account.
In some circumstances, Google may not confirm that authorization was successfully revoked, including because an authorization has already expired or become invalid, because of a network interruption, provider error, or another circumstance outside the Company's reasonable control.
If revocation cannot be confirmed, the Company may direct the User to remove AnnexusX manually through the third-party connection settings within the User's Google Account.
The Company will not delay or prevent deletion of the User's AnnexusX Account and locally maintained AnnexusX data solely because revocation of the separate Google authorization could not be confirmed.
6.5 Information Retained After Deletion
Certain information may be retained after account deletion where reasonably necessary to:
comply with applicable law;
satisfy tax or accounting obligations;
resolve disputes;
enforce agreements;
detect or prevent fraud;
investigate security incidents;
maintain backup or disaster recovery systems;
protect the integrity, security, and reliability of the Services; or
fulfill other legitimate legal or operational obligations.
Such retained information shall be limited to what is reasonably necessary for those purposes.
6.6 Backups
Information may continue to exist within secure backup systems for a reasonable period following deletion before being overwritten through the Company's normal backup lifecycle.
The Company limits access to backup data and does not restore deleted information except where reasonably necessary for disaster recovery, security, legal compliance, or other legitimate operational purposes.
6.7 Retention by Category
The Company applies the following general retention principles:
User Content: generally retained while the Account is active and for approximately thirty (30) days following the end of Account access, subject to applicable deletion requests, backup procedures, and legal exceptions.
Account Information: generally retained while necessary to maintain and administer the Account and for approximately thirty (30) days following the end of Account access, except for records that must reasonably be retained for security, fraud prevention, dispute resolution, accounting, tax, or legal purposes.
Google authorization credentials: retained only while reasonably necessary to maintain the authorized Google connection and are revoked or deleted when the connection or Account is permanently terminated, subject to technical and legal limitations.
Usage Data and security logs: retained for periods reasonably necessary to protect the Services, investigate security or operational issues, maintain reliability, detect abuse, and satisfy legal requirements.
Campaign and landing-page identifiers associated with an Account: retained as part of applicable Account Information and Usage Data according to the retention practices applicable to those categories.
Billing and transaction records: retained for the period reasonably necessary to satisfy accounting, tax, fraud-prevention, dispute-resolution, and other applicable legal requirements.
Support records: retained for the period reasonably necessary to resolve support matters, maintain appropriate business records, improve support operations, protect security, and comply with applicable law.
The Company does not retain personal information longer than reasonably necessary for the purposes for which it is processed, subject to applicable legal, security, backup, and operational requirements.
ARTICLE 7 – SECURITY
7.1 Security Program
The Company implements administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, and destruction, appropriate to the nature of the information and the risks involved. These measures include access controls, encryption in transit, authentication requirements, and limits on internal access to User Content as described in the Terms & Conditions.
7.2 User Responsibilities
Users are responsible for maintaining the confidentiality of their account credentials, safeguarding devices used to access the Services, and promptly notifying the Company of any suspected unauthorized access to their User Account.
7.3 Security Incidents
If the Company becomes aware of a security incident affecting personal information, it will investigate and respond using measures appropriate to the nature, scope, and risk of the incident.
The Company will make notifications to affected Users, governmental authorities, supervisory authorities, or other parties where required by applicable law.
Where the General Data Protection Regulation applies and notification to a supervisory authority is legally required, the Company will make that notification without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of the incident.
Where applicable law requires notification to affected Users, the Company will provide notice within the period and in the manner required by that law.
7.4 No Guarantee
While the Company continuously works to protect the Services and User information, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure.
Accordingly, the Company cannot guarantee that unauthorized access, disclosure, alteration, or destruction of information will never occur.
ARTICLE 8 – YOUR PRIVACY RIGHTS
8.1 Privacy Rights
Depending on applicable law and the User's jurisdiction, Users may have certain rights regarding information processed by the Company.
These rights may include the ability to:
access certain information;
correct inaccurate information;
request deletion of certain information;
receive certain information in a portable format where reasonably available;
object to or restrict certain processing activities;
withdraw consent where processing is based on consent; and
exercise other rights provided under applicable law.
The availability of these rights may vary based on the User's location and applicable legal requirements.
8.2 Access Requests
Users may request access to certain information the Company maintains about their User Account by submitting a request through legal@annexusx.com.
The Company may request reasonable verification of identity before fulfilling an access request.
8.3 Correction of Information
Users may update certain Account Information directly through the Services where functionality is available.
Where information cannot reasonably be updated through the Services, Users may request correction through legal@annexusx.com.
The Company may decline requests that are fraudulent, technically impracticable, legally prohibited, or that would adversely affect the rights or safety of others.
8.4 Deletion Requests
Users may request deletion of their User Account and associated information in accordance with the Terms & Conditions.
Deletion requests are subject to the Company's retention practices described in Article 6, including information retained to comply with legal obligations, resolve disputes, maintain security, prevent fraud, enforce agreements, preserve backup systems, or fulfill other legitimate operational purposes.
8.5 Data Portability
Where applicable law provides a right to data portability, Users may request an export of qualifying personal information maintained by the Company.
Where technically feasible and legally required, qualifying information will be provided in a structured, commonly used, and machine-readable format.
The scope of an export may depend on the applicable Product Feature, the source of the information, technical limitations, the rights of other individuals, and requirements imposed by connected Third-Party Services.
Information originating from a Third-Party Service may remain available directly through that provider and may be subject to that provider's own export tools, technical limitations, and legal obligations.
Where self-service export functionality is made available through the Services, the Company may permit Users to obtain supported information directly without submitting a separate request.
Privacy or portability requests may be submitted through the Company's designated privacy channels.
8.6 Communications
Users may manage certain communication preferences through the Services where available.
Users may opt out of optional communications where applicable.
Operational, security, billing, onboarding, legal, and other communications reasonably necessary to provide the Services may continue regardless of marketing preferences.
8.7 Exercising Privacy Rights
Privacy requests may be submitted through legal@annexusx.com.
To protect Users and the Services, the Company may require reasonable verification of identity before fulfilling requests.
The Company will respond to verified requests within the timeframes required by applicable law.
8.8 California Privacy Rights
To the extent the California Consumer Privacy Act, as amended, applies to the Company processing activities, California residents may have the right to:
request information about the categories and specific pieces of personal information the Company has collected about them;
request information about the sources, purposes, and categories of third parties associated with that information;
request deletion of personal information, subject to applicable exceptions;
request correction of inaccurate personal information;
opt out of the sale or sharing of personal information;
limit certain uses or disclosures of sensitive personal information where applicable; and
receive equal service and treatment without unlawful discrimination for exercising applicable privacy rights.
The categories of personal information the Company may collect, the sources of that information, the purposes for which it is used, and the categories of recipients are described elsewhere in this Privacy & Data Policy and in the Service Providers and Subprocessors Disclosure.
The Company does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under applicable California law. The Company does not currently provide a financial-incentive program in exchange for personal information.
California residents may submit applicable privacy requests to **legal@annexusx.com**. The Company may take reasonable steps to verify the identity and authority of the person submitting a request before acting on it. An authorized agent may submit a request where permitted by law, but the Company may require evidence of the agent authority and verification of the affected consumer.
The Company will respond to verified requests within the time and in the manner required by applicable law. Certain information may be retained or excluded from a request where an applicable legal exception permits or requires it.
8.9 Other United States Privacy Rights
Residents of U.S. states that have enacted applicable comprehensive consumer privacy laws may have rights concerning personal information maintained by the Company.
Depending on the applicable law, those rights may include the ability to:
confirm whether the Company processes personal information concerning the individual;
access personal information;
correct inaccurate personal information;
request deletion;
receive certain information in a portable format;
opt out of the sale of personal information;
opt out of certain targeted advertising;
opt out of certain profiling or automated decision-making activities; and
exercise other rights provided by applicable state law.
The Company does not currently sell personal information, share personal information for cross-context behavioral advertising, or use personal information for targeted advertising based on activity across unrelated businesses.
Requests may be submitted to legal@annexusx.com.
The availability and scope of particular rights depend on applicable law and whether that law applies to the Company and the requesting individual.
8.10 Appeals of Privacy Requests
Where applicable law provides a right to appeal the Company's decision concerning a privacy request, the User may submit an appeal to legal@annexusx.com and identify the request being appealed.
The Company will review and respond to an appeal within the period required by applicable law.
Where required by applicable law, a response denying an appeal will provide information concerning any available method for contacting the applicable Attorney General, regulator, or supervisory authority.
8.11 Universal Opt-Out Preference Signals
The Company does not currently sell personal information or use personal information for processing that requires an opt-out through a universal browser-based privacy preference signal.
If the Company introduces processing to which a legally recognized universal opt-out signal applies, the Company will recognize and process such signals as required by applicable law.
8.12 European Economic Area and United Kingdom Privacy Rights
Where the General Data Protection Regulation, United Kingdom GDPR, or similar applicable data protection law applies, Users may have rights to:
access personal data concerning them;
correct inaccurate personal data;
request deletion of personal data;
restrict certain processing;
object to processing based on legitimate interests;
receive applicable personal data in a portable format;
withdraw consent where processing is based on consent; and
exercise other rights provided under applicable law.
Where processing is based on legitimate interests, a User may object on grounds relating to the User's particular situation.
Where personal data is processed for direct marketing purposes, a User may object to that processing at any time where such a right applies.
8.13 Right to Lodge a Complaint
Users whose personal information is subject to the General Data Protection Regulation have the right to lodge a complaint with an applicable data protection supervisory authority, including an authority in the User's habitual residence, place of work, or place of the alleged infringement.
Users in the United Kingdom may lodge an applicable complaint with the Information Commissioner's Office.
The Company encourages Users to contact legal@annexusx.com regarding a privacy concern so the Company has an opportunity to address the matter directly, but contacting the Company first is not a condition of exercising a legal right to complain to a supervisory authority.
ARTICLE 9 – INTERNATIONAL PROCESSING
9.1 International Processing
Purpura Quadrum, LLC is established in the United States.
Information processed in connection with the Services may therefore be stored, processed, or accessed in the United States and in other jurisdictions where authorized service providers operate.
Data protection and privacy laws in those jurisdictions may differ from the laws applicable in a User's country or region of residence.
9.2 Applicable Safeguards
Where the Company or an authorized service provider transfers personal data in circumstances requiring an international data-transfer mechanism under applicable law, the Company will use or require legally recognized safeguards as applicable.
Depending on the circumstances, such safeguards may include:
an applicable adequacy decision;
approved standard contractual clauses;
an applicable United Kingdom international data-transfer mechanism;
another legally recognized certification, framework, or contractual safeguard; or
another transfer mechanism permitted by applicable law.
Information concerning applicable transfer safeguards may be requested by contacting legal@annexusx.com.
Authorized service providers may maintain their own legally recognized international transfer mechanisms, as described in their applicable privacy, data-processing, or legal documentation.
9.3 Global Operations
The Company will process personal information across jurisdictions only in accordance with this Privacy Policy and applicable law.
Nothing in this Article limits any privacy right or international-transfer protection that cannot lawfully be waived or limited.
ARTICLE 10 – CHILDREN'S PRIVACY
10.1 Minimum Age
The Services are intended solely for individuals who are at least eighteen (18) years of age.
The Company does not knowingly permit individuals under 18 to create an Account and does not knowingly collect personal information from individuals under 18 through the creation or use of an Account.
10.2 Inadvertent Collection
If the Company becomes aware that an individual under 18 has created an Account or provided personal information through the Services, the Company may suspend or terminate the Account and will take reasonable steps to delete the associated information, subject to applicable law and legitimate security or recordkeeping requirements.
Questions or reports concerning information believed to have been provided by an individual under 18 may be submitted to legal@annexusx.com.
ARTICLE 11 – CHANGES TO THIS PRIVACY POLICY
11.1 Policy Updates
The Company may update this Privacy Policy from time to time to reflect changes in the Services, applicable law, operational practices, or other legitimate business needs.
11.2 Notice of Material Changes
Where changes to this Privacy Policy are material, the Company will provide reasonable notice through the Services, by electronic communication, or through another reasonable method before or when the revised processing begins, as appropriate under applicable law.
Where a change introduces processing for which applicable law requires consent or another affirmative authorization, the Company will obtain that authorization before beginning the applicable processing.
11.3 Effective Date
The Effective Date and Last Updated date displayed at the beginning and end of this Privacy Policy identify when the current version became effective and when it was most recently revised.
Continued use of the Services following an update to this Privacy Policy constitutes acknowledgment of the updated Privacy Policy to the extent permitted by applicable law.
Continued use does not constitute consent to processing where applicable law independently requires affirmative consent or another form of authorization.
ARTICLE 12 – CONTACT INFORMATION
12.1 Contacting the Company
Questions regarding this Privacy Policy, the Company's privacy practices, or the processing of personal information may be submitted to:
The Company may make additional privacy or support contact methods available through the Services or its official website.
12.2 Privacy Requests
Requests concerning access, correction, deletion, portability, objection, restriction, withdrawal of consent, or other privacy rights may be submitted to:
The Company may take reasonable steps to verify the identity or authority of a person submitting a request before disclosing information or acting upon the request.
The Company will respond to verified requests within the period required by applicable law.
12.3 Business Information
This Privacy Policy applies to the Services provided by:
Purpura Quadrum, LLC
a Delaware limited liability company
Privacy inquiries and requests may be submitted to:
Additional business and contact information may be made available through the Services or the Company's official website.
EFFECTIVE DATE
Effective Date: September 5, 2026
Last Updated: September 5, 2026
Version: 1.0