Privacy Policy
Company: IQ Harvest, Inc. (a Delaware corporation) (“IQ Harvest,” “we,” “us,” “our”)
Contact: privacy@iqharvest.com
This Privacy Policy explains how IQ Harvest collects, uses, discloses, and protects personal information when you visit our website, create an account, or use our AI enablement platform and related services (collectively, the “Services”).
This Privacy Policy is intended to be used alongside our Terms of Service, End User License Agreement, or other in-application user terms (collectively, the “End User Terms”). If you use the Services through an organization-managed workspace, your organization’s policies may also apply.
Effective Date: December 17, 2025
Last Updated: June 21, 2026
1. Scope: Who and What This Policy Covers
This Privacy Policy applies to personal information we process in connection with:
- Website Visitors – when you visit our public websites or marketing pages.
- Service Users – when you register for, access, or use the IQ Harvest platform.
- Business Contacts – when you interact with us about partnerships, managed services, sales, support, or events.
- Professional Services Contacts and Participants – when we provide onboarding, implementation, training, AI policy assistance, use case harvesting, prompt engineering, automation engineering, fractional AI Director services, support, workshops, or related consulting services.
Organization-Managed Workspaces: If you access IQ Harvest through a workspace provisioned by your employer or another organization (“Organization”), that Organization may control how certain data is configured, accessed, retained, and exported within the workspace (including via administrators or a third-party administrator such as a managed service provider). See Section 6.
2. Information We Collect
We collect information in four primary ways: (a) information you provide, (b) information collected automatically, (c) information from your Organization or integrations (when enabled), and (d) information processed in connection with professional services or implementation services.
2.1 Information you provide
Depending on how you use the Services, you may provide:
- Account and profile information: name, email address, password, job title, department, organization name, and similar identifiers.
- Survey responses and form inputs: responses you submit through surveys, questionnaires, prompts, or forms in the platform.
- User content: use cases, posts, comments, attachments, and other content you submit within the platform (including content you choose to share internally or in a global community area, if enabled).
- Compliance acknowledgements and knowledge-check results: confirmations and sign-offs you complete within the platform (for example, acknowledging an acceptable use, AI, or compliance policy). Where your Organization deploys a policy that asks you to confirm you have read and understood it, or that includes a knowledge check, we also collect your per-statement acknowledgements, the answers you select to comprehension and quiz questions, whether each answer was correct, the number of attempts you make, your score (as a percentage), whether you passed, and the related timestamps. We record these on your Organization’s behalf as its attestation that you completed its policy sign-off, bound to the exact version of the policy you signed. A policy sign-off is always recorded against your identity and cannot be made anonymous (see Section 6); your Organization and its administrators may view this information (see Section 7.2), and these records are retained as an audit trail (see Section 9). They record that a sign-off occurred against a specific policy version — they are not an assessment of you by IQ Harvest.
- Support and communications: information you provide when you contact us (emails, chat messages, tickets, recordings or transcripts if provided, and related metadata).
2.2 Information collected automatically (device, usage, logs)
When you visit our website or use the platform, we may automatically collect:
- Device and connection data: IP address, device type, browser type, operating system, language, and approximate location (derived from IP).
- Log and event data: timestamps, pages/screens viewed, features used, clicks, referring URLs, and actions taken in the Services.
- Security and audit logs: login events, authentication data, fraud or abuse indicators, and administrative events.
- End User Terms/privacy acceptance records: version identifiers, acceptance timestamp, and technical metadata (e.g., IP address and user agent) associated with acceptance where relevant for audit, security, and compliance.
2.3 Information from your Organization or integrations (when enabled)
If your Organization connects third-party tools or systems to IQ Harvest (or provides data into the workspace), we may process:
- Workspace provisioning details: workspace identifiers, user lists, role/permission settings, and admin configurations.
- Integration data and telemetry metadata: information from connected tools (for example, AI tool usage signals, governance-related information, identity or user metadata, application access metadata, connector logs, audit events, or other data your Organization authorizes to be shared with IQ Harvest). Examples may include data from Microsoft 365, Google Workspace, Slack, Microsoft Teams, identity providers, endpoint telemetry, browser telemetry, or similar systems, depending on what your Organization enables.
The specific integration data depends on the integrations your Organization enables and configures. Unless expressly agreed in an applicable order form, statement of work, connector schedule, data processing addendum, or other written agreement, IQ Harvest does not intentionally collect or process the body content of emails, chat messages, files, or documents through telemetry integrations.
2.4 Information processed in professional services and implementation services
When IQ Harvest provides professional services, implementation services, automation engineering, prompt engineering, fractional AI Director services, onboarding, training, workshops, support, or related consulting, we may process information provided by your Organization or accessed through customer-authorized systems. This may include business requirements, meeting notes, implementation materials, configuration data, workflow information, system metadata, logs, test data, support materials, user lists, role information, customer-approved policy materials, use case information, automation specifications, and other information reasonably necessary to perform the services.
Unless expressly agreed in an order form, statement of work, data processing addendum, business associate agreement, government addendum, or other written agreement, customers should not provide PHI, payment card data, government IDs, controlled unclassified information (CUI), classified information, student education records, children’s data, biometric data, or other regulated sensitive data.
3. How We Use Information
We use personal information to operate, maintain, and improve the Services, including to:
3.1 Provide and operate the Services
- Create and manage accounts and user authentication
- Provide platform features (surveys, analytics, benchmarking, governance workflows, community features)
- Deliver customer support and respond to requests
- Administer workspaces and enforce settings as configured by Organizations and their administrators
- Provide AI policy and compliance sign-off workflows. Where your Organization deploys an AI, acceptable-use, or compliance policy for sign-off, we present the policy for click-wrap acknowledgement, record your per-statement read-and-understood acknowledgements, and automatically score any knowledge-check answers to show you your result and offer remediation if you answer incorrectly. We capture your score, whether you passed, and the exact policy version and content checksum you signed, and we make these attestation records available to your Organization as proof of acknowledgement. In doing this, IQ Harvest acts only as a neutral system of record for your Organization: we record that a sign-off occurred against a specific policy version — we do not assess you and do not make or contribute to any employment, disciplinary, or other decision about you. Any such decision is made by your Organization under its own policies, and questions about it should be directed to your Organization (see Section 11).
3.2 Provide professional services and implementation services
When we provide professional services, implementation services, automation engineering, prompt engineering, fractional AI Director services, training, onboarding, workshops, support, or related consulting, we use information as reasonably necessary to plan, configure, test, troubleshoot, deploy, document, train, support, and improve those services and related customer implementations.
3.3 Improve, secure, and troubleshoot
- Monitor performance, diagnose issues, and improve reliability
- Protect against fraud, misuse, and security incidents
- Enforce the End User Terms and applicable policies and terms
3.4 Analytics, benchmarking, and reporting
- Generate insights about platform usage and AI enablement trends
- Produce benchmarking and aggregated reporting
Important: When we use data for benchmarking, reporting, and certain improvements, we may convert data into Deidentified Data and/or Aggregated Data (as described in Section 5).
3.5 Communications and marketing
- Send administrative communications (service updates, security notices, support messages)
- Send marketing communications where permitted by law (you may opt out at any time; see Section 10)
3.6 Legal and compliance
- Comply with applicable laws and regulations
- Respond to lawful requests and legal process
- Establish, exercise, or defend legal claims
4. Legal Bases for Processing (EEA/UK/Switzerland)
If GDPR, UK GDPR, or similar laws apply, we process personal information under the following legal bases, as applicable:
- Contract: to provide the Services you request and administer your account
- Legitimate interests: to secure, maintain, and improve the Services; prevent fraud; support business operations; and generate analytics/benchmarks (balanced against your rights)
- Consent: for certain cookies/marketing where required (you may withdraw consent)
- Legal obligation: to comply with applicable laws
See Appendix A for additional EEA/UK/Switzerland terms.
5. Deidentified Data, Aggregated Data, and AI/ML Model Training
5.1 Deidentified and aggregated processing
We may create Deidentified Data and Aggregated Data from information processed through the Services. This means we apply measures intended to reduce identifiability (such as removal of direct identifiers and aggregation across users, groups, time periods, or organizations).
We use Deidentified Data and/or Aggregated Data to:
- Improve Service performance and features
- Create benchmarking insights and statistical reports
- Understand trends in AI enablement and tool adoption
5.2 Model training is limited to Deidentified Data only
IQ Harvest will only train or tune AI/ML models using Deidentified Data (and/or Aggregated Data that is also Deidentified).
We do not train general-purpose AI models on identifiable personal information, confidential workspace content, Customer-identified customer data, or organization-identified survey responses. Deidentified Data and Aggregated Data used for these purposes is not intended to identify a customer, organization, end customer, workspace, or individual.
5.3 No intentional re-identification
We do not intentionally attempt to re-identify individuals or Organizations from Deidentified Data.
6. Organization Workspaces, Administrators, and Third-Party Administrators (Including MSPs)
If you use IQ Harvest through an Organization-managed workspace:
Your Organization may designate Administrators and may authorize a Third-Party Administrator (including an MSP) to manage the workspace.
Administrators and Third-Party Administrators may be able to:
- Manage your access and permissions
- Configure surveys and settings (including whether survey responses are collected anonymously or in an identifiable form)
- Access, export, or delete workspace content and logs based on workspace configuration and the Organization’s policies
Anonymity does not apply to compliance or AI policy sign-offs. Unlike survey responses, which your Organization may choose to collect anonymously, a policy sign-off is always recorded against your identity and attributed specifically to you — it is your Organization’s record that you acknowledged that policy version, including any knowledge-check result. Anonymous sign-off is not available (see Section 7.2).
If you have questions about how your Organization uses or monitors workspace data, you should review your Organization’s internal policies and/or contact your Organization or its administrator.
9. Data Retention
We retain personal information for as long as reasonably necessary to:
- Provide the Services and maintain accounts
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain security and prevent fraud
Workspace data retention may be controlled by your Organization’s workspace settings and applicable agreements.
Information processed in connection with professional services or implementation services may be retained for as long as reasonably necessary to provide the services, maintain project records, support customer implementations, comply with legal obligations, resolve disputes, enforce agreements, and maintain security, subject to applicable agreements and law.
Compliance sign-off and attestation records are an exception. Because your individual policy sign-off serves as your Organization’s evidence that you acknowledged a specific policy version at a specific time, your prior sign-off record — including incomplete or failed attempts — is not deleted when a newer policy version supersedes it; it is marked as no longer current but kept as part of the audit trail. Your Organization, as controller of this workspace data, determines how long these records are retained for its compliance, audit, and legal-proof purposes, so a request to delete your data may not remove a completed attestation (see Section 11 and Appendix A).
Deidentified and Aggregated Data may be retained longer for benchmarking and product improvement, to the extent permitted by law.
10. Your Choices
10.1 Account information
You may be able to update certain profile fields within the platform. Some information may be controlled by your Organization (for example, your role or workspace membership).
10.2 Marketing communications
You can opt out of marketing emails by using the “unsubscribe” link in those messages or contacting us at privacy@iqharvest.com. You may still receive non-marketing, service-related communications.
10.3 Community posting choices
If community features are enabled, you control whether you post content internally or publicly (where available). Do not post sensitive information in public areas.
11. Your Privacy Rights (Summary)
Your rights depend on where you live and applicable law. You may have the right to:
- Access personal information we hold about you
- Correct inaccurate information
- Delete personal information (subject to certain exceptions)
- Object to or restrict certain processing
- Receive a copy of your information (data portability)
- Opt out of certain disclosures or uses (where applicable)
Workspace users: If your request relates to data in an Organization-managed workspace (including survey responses or compliance policy sign-offs collected in that workspace), your Organization may be the proper point of contact and may control the response. You can also contact us at privacy@iqharvest.com and we will route or respond as appropriate.
Appendix A provides additional details for EEA/UK/Switzerland.
12. International Data Transfers
IQ Harvest is based in the United States. If you access the Services from outside the U.S., your information may be transferred to and processed in the U.S. and other locations where we or our service providers operate.
Where required by law (including for EEA/UK/Switzerland transfers), we use appropriate safeguards, such as Standard Contractual Clauses or other valid transfer mechanisms.
13. Security
We maintain administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. However, no system can be guaranteed 100% secure.
14. Children’s Privacy
The Services are not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us at privacy@iqharvest.com.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law (for example, by posting an updated policy with a new effective date). Your continued use of the Services after the effective date means you have read the updated policy.
16. Contact Us
If you have questions or requests about this Privacy Policy or our privacy practices, contact:
IQ Harvest, Inc.
Email: privacy@iqharvest.com
Appendix A — EEA/UK/Switzerland Privacy Addendum
This Appendix applies to the extent the processing of Personal Data is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and/or the UK GDPR.
A1. Roles: Controller vs. Processor
- Workspace Data: Where you use an Organization-managed workspace, your Organization is typically the Controller and IQ Harvest acts as a Processor for workspace data (including survey responses, AI policy compliance attestations and sign-off records (including per-statement read-and-understood acknowledgements, knowledge-check answers and scores, sign-off and pass/fail status, attempt counts, and the policy version identifiers and checksum that bind a sign-off to the exact policy text signed), and workspace usage data), generally under an organizational agreement and/or DPA with the Organization. We do not use identifiable Workspace Data to train AI or machine-learning models. We may use Deidentified Data and/or Aggregated Data as described in Section 5.
- Professional Services Data: Where we process personal information in connection with professional services or implementation services, our role depends on the context and the applicable agreement. We typically act as a Processor when processing customer-provided personal information on behalf of an Organization under its documented instructions, and as a Controller for certain account, billing, security, business contact, and service administration data.
- Account/Security Data: IQ Harvest may act as a Controller for certain personal information necessary to operate the Services (for example, account registration information and security logs).
A2. Data Subject Requests
- Workspace Data: Requests relating to workspace data (including survey responses and compliance policy sign-offs, knowledge-check answers, scores, and attempts) should generally be directed to your Organization (the Controller) or its administrator/Third-Party Administrator.
- IQ Harvest Controlled Data: Requests relating to IQ Harvest-controlled account/security data may be sent to privacy@iqharvest.com.
A3. Your Rights
Subject to applicable law and exceptions, you may have rights to:
- Access, rectify, erase, restrict, or object to processing
- Data portability (in certain cases)
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with a supervisory authority
A4. International Transfers
If personal information is transferred outside the EEA/UK/Switzerland to jurisdictions without an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses and/or other valid mechanisms recognized by applicable law.
A5. Supervisory Authority Complaints
If you are in the EEA/UK/Switzerland, you may lodge a complaint with your local supervisory authority. We encourage you to contact us first at privacy@iqharvest.com so we can try to address your concern.