This Privacy Policy explains how Stipulex, Inc. ("Stipulex," "we," "us" or "our") collects, uses, shares and protects personal information when you visit our marketing website at www.stipulex.com (the "Site"). It also explains the choices and rights you have.
The Site is a marketing website for contract analysis software that is still in development. This policy covers the Site only. When the product launches, product accounts will be governed by a separate privacy policy or by an update to this one (see Section 14).
1. Who We Are
Stipulex, Inc. is a Delaware corporation headquartered in Redwood City, California. For the purposes of privacy law, Stipulex, Inc. is the business, controller and decision-maker for the personal information described in this policy.
Registered address: 8 The Green, Suite B, Dover, Delaware 19901. Privacy contact: privacy@stipulex.com
2. Summary
- The Site sets no cookies and runs no analytics, advertising pixels or third-party scripts. Fonts are self-hosted.
- We collect personal information in only three places: the "Get a demo" email capture, the contact form, and ordinary web server logs.
- We do not sell personal information, share it for advertising, or use it to build a marketing list.
- The Site does not accept contract uploads. The interactive demo plays back synthetic sample contracts bundled with the Site. Nothing you type on the Site is analyzed.
- We use one email service provider (Brevo, in France) to send transactional email and one hosting provider (IONOS, in the United States) for our servers and the team inbox.
- You can ask us what we hold about you, ask us to correct it, or ask us to delete it by emailing privacy@stipulex.com.
3. Information We Collect and Why
We collect personal information only when you give it to us or when your browser sends it as part of an ordinary web request. We do not buy personal information or obtain it from data brokers.
3.1 "Get a demo" requests
When you enter your email address in a "Get a demo" field, we collect:
- your email address;
- the section of the page the form was submitted from;
- your IP address and browser user agent at the time of submission.
Before storing the address we check its format and compare its domain against a list of known temporary-inbox providers; addresses from those providers are rejected and not stored. We store accepted requests in a database on our own server. We send you one confirmation email with a link. If you do not click the link within 7 days, the token expires and the unconfirmed record is deleted automatically by a scheduled nightly database job. If you confirm, we keep your address so that we can email you once when the product goes live. There is no newsletter and no marketing list. We do not send further marketing email unless you separately ask for it.
We record the IP address and user agent so we can investigate abuse, spam and automated submissions.
3.2 Contact form
When you use the contact form, we collect:
- your name;
- your email address;
- your company (optional);
- the topic you select;
- the text of your message;
- your IP address and browser user agent at the time of submission.
We store the message in a database on our own server, deliver a copy to our team inbox with your email address set as the reply address, and send you a one-time acknowledgement email. We use this information to read and respond to your message.
Please do not include sensitive personal information (for example government identification numbers, health information, financial account numbers or the contents of a confidential contract) in a contact message. We do not need it to respond to you.
3.3 Server logs and rate limiting
Like almost every website, our web server (nginx) records an access log for each request. Each entry contains your IP address, browser user agent, the URL requested and a timestamp. Logs rotate on a standard schedule (see Section 7). We use them to keep the Site running, diagnose problems and detect abuse.
To protect the forms from automated abuse, our application keeps an in-memory count of recent form submissions per IP address. Depending on the form, a count covers between one minute and 24 hours. Counts are never written to disk and are discarded when they expire or when the application restarts.
3.4 What we do not collect
- No cookies. The Site sets no cookies of any kind, including session, preference, analytics or advertising cookies.
- No analytics or tracking. There is no analytics software, advertising pixel, tag manager, session recording or third-party script on the Site.
- No third-party fonts or embeds. Fonts are served from our own server, so no font provider sees your requests.
- No contract uploads. The Site has no upload feature. The interactive demo uses synthetic sample contracts that ship with the Site and does not read, store or analyze anything you type.
- No account data. There are no user accounts on the Site.
3.5 Categories of personal information (California notice at collection)
For California residents, the information above falls into the following categories defined in Cal. Civ. Code § 1798.140:
| Category | What we collect | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, email address, IP address | You; your browser | Respond to you; send demo confirmation and launch email; security |
| Professional or employment information | Company name (optional) | You | Understand and respond to your inquiry |
| Internet or other electronic network activity | User agent, URL requested, timestamp, page section of form submission | Your browser | Site operation, diagnostics, abuse prevention |
| Contents of communications | Contact message text and topic | You | Respond to you |
We do not collect sensitive personal information as defined by the CPRA, and we ask you not to send any. We do not collect precise geolocation, biometric information, or inferences used to build a profile about you.
4. How We Use Information and Our Legal Bases
We use personal information only for the purposes listed below. For visitors in the European Economic Area, the United Kingdom and Switzerland, we also identify the legal basis we rely on.
| Purpose | Information used | Legal basis (EEA/UK/Switzerland) |
|---|---|---|
| Confirming your demo request and, later, sending one email when the product goes live | Email address, confirmation token | Your consent, given when you submit the form and confirmed when you click the confirmation link. You can withdraw it at any time (Section 11). |
| Reading and responding to a contact message | Name, email, company, topic, message | Our legitimate interest in answering inquiries, and where relevant, taking steps at your request before entering into a contract. |
| Keeping the Site secure and preventing abuse | IP address, user agent, URL, timestamp, rate-limit counters | Our legitimate interest in the security and integrity of the Site. |
| Complying with law and responding to lawful requests | Any of the above, as required | Compliance with a legal obligation. |
| Establishing, exercising or defending legal claims | Any of the above, as required | Our legitimate interest in protecting our legal rights. |
We do not use personal information for automated decision-making that produces legal or similarly significant effects. We do not use it to train machine learning models. We do not combine it with information from other sources to build profiles.
5. Who We Share Information With
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not give it to data brokers, advertising networks or analytics companies.
We share personal information only with the service providers below, who process it on our behalf and under our instructions, and in the limited legal circumstances described afterward.
| Provider | Role | What they receive | Location |
|---|---|---|---|
| Brevo (Sendinblue SAS) | Transactional email delivery over SMTP | Recipient email address and the content of the confirmation and acknowledgement emails we send you, together with delivery metadata | France |
| IONOS, Inc. | Hosting of our self-managed Linux servers where the database, website(s), and logs reside | All information described in Section 3, as stored on the server's disk and memory | United States |
| IONOS, Inc. | Hosts the team inbox that receives a copy of each contact message | Name, email, company, topic and message text | United States |
| Let's Encrypt (Internet Security Research Group) | Issues the TLS certificate that encrypts your connection to the Site | Our domain name only; no visitor personal information | United States |
We may also disclose personal information:
- To comply with law. When we believe in good faith that disclosure is required by law, regulation, subpoena, court order or other legal process.
- To protect rights and safety. When reasonably necessary to investigate or prevent fraud, abuse, security incidents or threats to the safety of any person, or to enforce our terms.
- In a business transfer. If Stipulex is involved in a merger, acquisition, financing, reorganization or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
6. Where Information Is Processed and International Transfers
Our server is located in the United States. If you visit the Site from outside the United States, including from the European Economic Area, the United Kingdom or Switzerland, the information you submit is transmitted to and stored in the United States, where privacy laws may differ from those of your country.
Transactional email is sent through Brevo, whose servers are in France. For EEA visitors this processing takes place within the European Union. For UK and Swiss visitors, the European Union is recognized as providing adequate protection.
For transfers to the United States, we rely on the fact that you submit your information directly to us in the United States, and on the safeguards described in Section 9. We do not currently participate in the EU-U.S. Data Privacy Framework.
7. How Long We Keep Information
We keep personal information only as long as needed for the purpose we collected it. The table below describes our current practice.
| Information | Retention period | What happens at the end |
|---|---|---|
| Unconfirmed demo request (email, page section, IP, user agent, token) | 7 days from submission | Deleted automatically in a nightly purge |
| Confirmed demo request (email, page section, IP, user agent) | Until we send the single product launch email, and for 30 days afterward, or until you ask us to delete it, whichever is sooner | Deleted from the database |
| Contact form message (name, email, company, topic, message, IP, user agent) | 24 months after the message was received or last marked handled, whichever is later | Deleted automatically by a scheduled nightly database job, or earlier on request |
| Copy of contact message in team inbox | Kept in the team inbox until the inquiry is closed, then deleted by hand | Deleted under the inbox retention policy |
| Emails sent through Brevo (delivery logs and message content held by Brevo) | For as long as Brevo keeps transactional delivery logs under its own retention policy | Deleted by Brevo |
| nginx access logs (IP, user agent, URL, timestamp) | Standard log rotation, currently 14 days | Rotated out and deleted |
| In-memory rate-limit counters (IP address) | Between one minute and 24 hours depending on the form; never written to disk | Discarded on expiry or application restart |
When you ask us to delete your information (Section 11), we delete it from our live database and ask our service providers to do the same, subject to the exceptions in Section 10. Copies in rotated logs or backups are removed when those files expire.
8. Cookies, Tracking and Do Not Track
The Site does not set cookies and does not use any tracking technology. Because we do not track visitors across sites or over time, there is nothing for a "Do Not Track" browser setting or a Global Privacy Control signal to switch off. We disclose this in accordance with the California Online Privacy Protection Act (Cal. Bus. & Prof. Code § 22575). If we ever add cookies or tracking, we will update this policy first and, where required, ask for your consent.
9. Security
We use technical and organizational measures appropriate to a small marketing site that handles a limited amount of personal information, including:
- TLS encryption for all connections to the Site, using certificates issued by Let's Encrypt;
- encrypted (TLS) connections to our email provider;
- a self-managed server with access restricted to authorized personnel using key-based authentication;
- server-side validation and rate limiting on all forms;
- automatic deletion of unconfirmed demo requests.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of security affects your unencrypted personal information, we will notify you and any regulator as required by applicable law, including Cal. Civ. Code § 1798.82 and, for EEA and UK residents, the GDPR and UK GDPR.
We do not hold any third-party security certification such as SOC 2 or ISO 27001, and nothing in this policy should be read as a claim that we do.
10. Your Rights
10.1 Everyone
Regardless of where you live, you can email privacy@stipulex.com to:
- ask whether we hold personal information about you and receive a copy;
- ask us to correct information that is inaccurate;
- ask us to delete your information;
- withdraw consent to the product launch email, at any time, by replying to any email we send or by writing to us.
10.2 California residents
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies to businesses that meet certain revenue, data volume or data sale thresholds. We believe that Stipulex, Inc. currently falls below all of those thresholds and is not a "business" subject to the CCPA.
Whether or not the CCPA applies, we honor the following rights for California residents:
- Right to know what personal information we have collected about you, the categories of sources, the purposes, and the categories of third parties with whom we have shared it, and to receive the specific pieces of information.
- Right to delete personal information we have collected from you, subject to the exceptions in the CCPA (for example, where we need to keep it to complete a transaction you requested, detect security incidents, or comply with a legal obligation).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. See Section 12.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information.
- Right to non-discrimination. We will not deny you services, charge you a different price or provide a different level of service because you exercised a privacy right.
Shine the Light. Under Cal. Civ. Code § 1798.83, California residents may ask once per year whether we have disclosed personal information to third parties for their direct marketing purposes. We do not.
10.3 European Economic Area, United Kingdom and Switzerland
If the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies to you, you have the right to:
- access the personal information we hold about you and receive a copy;
- have inaccurate information rectified;
- have your information erased in the circumstances set out in Article 17;
- restrict processing in the circumstances set out in Article 18;
- object to processing based on our legitimate interests, including at any time to processing for direct marketing;
- receive the information you provided to us in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority. In the EEA, a list is available at edpb.europa.eu. In the UK, the authority is the Information Commissioner's Office (ico.org.uk). In Switzerland, it is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
We have not appointed a Data Protection Officer, because our processing is small in scale and does not involve regular and systematic monitoring or special categories of data. We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR.
10.4 Other United States residents
Several other states have consumer privacy laws with thresholds that Stipulex, Inc. does not currently meet. We will still respond to access, correction and deletion requests from any US resident under the process in Section 11.
11. How to Exercise Your Rights
Send your request by email to privacy@stipulex.com and include:
- what you would like us to do (access, correct, delete, withdraw consent, or another request);
- the email address you used on the Site, so that we can find your records.
Verification. Because the only identifier we hold for most visitors is an email address, we verify requests by sending a confirmation message to the address on file and acting once you reply from that address. We will not ask you to create an account or provide more information than we need to verify you. If we cannot verify a request, we will tell you why.
Authorized agents. If someone submits a request on your behalf, we will ask for written proof that you authorized them, and we may still confirm the request with you directly.
Timing. We will acknowledge your request within 10 business days and respond within 45 calendar days. If we need more time, we will tell you why and respond within a further 45 days (90 days total). For EEA, UK and Swiss residents, we will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
Cost. Requests are free. If a request is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or decline it, and we will explain our decision.
Appeals. If we decline all or part of your request, you may ask us to reconsider by replying to our response. We will review the appeal and respond within 45 days. You may also complain to the California Privacy Protection Agency, the California Attorney General, or your local supervisory authority.
12. Do Not Sell or Share My Personal Information
Stipulex does not sell personal information and does not share it for cross-context behavioral advertising, and has not done so in the preceding 12 months. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age. We include this section because the CCPA requires it of covered businesses and because we want to state our position plainly. If this ever changes, we will add a "Do Not Sell or Share" link to the Site and honor opt-out preference signals such as Global Privacy Control before doing so.
13. Children
The Site is intended for business professionals and is not directed to anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13 as defined by the Children's Online Privacy Protection Act. If you believe a person under 18 has submitted personal information to the Site, email privacy@stipulex.com and we will delete it.
14. Forward-Looking Statements About the Stipulex Product
Stipulex is building software that analyzes contracts. When that product launches, we intend it to work as follows:
- In-memory processing by default. Contracts uploaded for analysis are intended to be processed in memory, without being written to disk, and discarded when the analysis is complete. We refer to this internally as a zero disk footprint.
- Optional Contract Vault. Customers who choose to store documents will be able to do so in a Contract Vault that encrypts documents at rest using AES-256. Storage will be at the customer's election, not the default
- No training on customer documents. Customer documents and the analysis of them will not be used to train machine learning models, whether our own or a third party's.
- Separate governance. Product accounts, uploaded documents and analysis output will be governed by a separate privacy policy or by an update to this one, published before the product accepts customer documents.
15. Stipulex Is Not a Law Firm
Stipulex, Inc. is a software company. It is not a law firm, does not provide legal advice or legal representation, and is not licensed to practice law in any jurisdiction. Nothing on the Site, in the interactive demo, or in any communication from us is legal advice, and no attorney-client relationship is created by using the Site or contacting us. The sample analyses shown in the interactive demo are produced from synthetic contracts for illustration only and should not be relied on for any real contract. Consult a licensed attorney before making legal or business decisions about a contract.
16. Other Provisions
Links to other websites. The Site may link to websites we do not operate, such as the sites of our email or hosting providers or of supervisory authorities. This policy does not cover those sites. We are not responsible for their content or privacy practices, and we encourage you to read their privacy policies.
Governing law. This policy and any dispute about it are governed by the laws of the State of California and applicable United States federal law, without regard to conflict-of-law rules, except where the privacy law of your place of residence gives you rights that cannot be waived. Nothing in this section limits the rights of EEA, UK or Swiss residents under their local law.
Third-party services outside our control. When you email us directly, or reply to an email we send, that message travels through your own email provider and ours. Those providers process the message under their own policies.
17. Changes to This Policy
We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, for material changes, post a notice on the Site for at least 30 days before the change takes effect. If we hold your email address because you requested a demo or contacted us, and a material change affects how we use that address, we will email you before the change takes effect. Earlier versions are available on request. Your continued use of the Site after a change takes effect means the updated policy applies to information we collect from that point on; it does not apply retroactively to information already collected without your consent where consent is required.
18. Contact
Stipulex, Inc. Registered Address: 8 The Green, Suite B, Dover, Delaware 19901. Headquarters: Redwood City, California
Email: privacy@stipulex.com Website: www.stipulex.com
If you are in the EEA, the UK or Switzerland and are not satisfied with our response, you may contact your local supervisory authority (see Section 10.3).