01Who we are
This Privacy Notice describes how HarborOS, LLC ("HarborOS", "we", "us", "our") collects, uses, and shares personal data when you use our contract intelligence service ("Service"). HarborOS, LLC acts as the data controller for personal data we collect about our account holders.
02Personal data we collect
- Account data — name, email address, login credentials, and authentication identifiers (e.g. Google sign-in).
- Organization data — company name, team members you invite, roles.
- Connected source data — OAuth tokens and metadata from Google Drive (or other sources you connect), and the contents of contract files you choose to import.
- Usage and telemetry — pages visited, features used, errors, device and browser information, IP address.
- Support communications — messages you send us and our responses.
- Billing identifiers — the customer and subscription IDs issued by Stripe. Card details and full billing addresses are collected and stored by Stripe, not by us.
03Why we use your data and our legal basis
- Provide the Service (contract performance) — create your account, ingest and extract data from your contracts, render dashboards.
- Security and fraud prevention (legitimate interests) — detect abuse, protect accounts, maintain audit logs.
- Customer support (contract performance) — respond to your requests.
- Product improvement (legitimate interests) — diagnose bugs, measure feature usage in aggregate.
- Billing and tax compliance (legal obligation, contract performance) — managed by Stripe as Merchant of Record.
- Marketing communications (consent or legitimate interests) — occasional product updates. You can opt out at any time.
04How we share data
We share personal data only with:
- Service providers / subprocessors — cloud hosting, database and storage providers, analytics, error monitoring, email delivery, and AI model providers used to extract data from contracts.
- Stripe (Merchant of Record) — for sale of subscriptions, payment processing, subscription management, invoicing, and tax compliance.
- Professional advisers — legal, accounting, and audit advisers, under confidentiality.
- Authorities — where required by law, court order, or to protect rights and safety.
We do not sell your personal data.
05International transfers
Your data may be processed in countries outside your own, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
06Data retention
We keep personal data only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When you close your account, we delete or anonymize your data within a reasonable period, subject to legal retention requirements (for example, billing records).
07Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request deletion ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent at any time;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@harboros.co. We respond within one month.
08Security
We use appropriate technical and organizational measures to protect your data, including encryption in transit, access controls, and regular review of our security posture. No system is 100% secure; we encourage strong passwords and enabling sign-in protections on your account.
09Cookies
We use a small number of strictly necessary cookies for authentication and to remember your preferences. We may use privacy-respecting analytics cookies to understand product usage in aggregate. We do not use advertising cookies.
10Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
11Changes
We may update this Privacy Notice from time to time. Material changes will be announced through the Service or by email.
12Contact
For privacy questions or to exercise your rights: privacy@harboros.co.