Políticas e Termos de Uso
ÍNDICE
  1. Capítulo1

Privacy Policy

Last Updated: September 2026

ENLIGHTEN values the privacy, confidentiality, and security of information processed through its products and services.

This Privacy Policy (“Privacy Policy” or “Policy”) describes how ENLIGHTEN collects, uses, stores, transmits, shares, discloses, and protects Personal Information in connection with its business activities, websites, commercial relationships, and services, including the ENSPACE platform, applications, interfaces, APIs, integrations, workflow automation functionality, artificial intelligence features, AI Agents, and the ENSPACE Add-in for Microsoft Word.

This Policy should be read together with the ENSPACE Terms of Use and any applicable Master Subscription Agreement (“MSA”), Data Processing Agreement (“DPA”), Order Form, Proposal, product-specific terms, Usage-Based Services Terms, and other Contract Documents entered into by ENLIGHTEN and its Customers.

1. WHO WE ARE

ENSPACE is an enterprise software platform developed and provided by companies within The ENLIGHTEN Company group.

For purposes of this Policy, “ENLIGHTEN” means the ENLIGHTEN group entity responsible for providing ENSPACE to the applicable Customer, as identified in the applicable MSA, Order Form, Proposal, contract, or another Contract Document.

Depending on Customer location and the structure of the applicable transaction, different ENLIGHTEN group entities may participate in the provision, administration, operation, security, development, or support of the Services, subject to applicable confidentiality, privacy, and data protection obligations.

Where applicable, the entity identified in Customer’s applicable Contract Documents will be the primary ENLIGHTEN contracting entity.

2. SCOPE OF THIS POLICY

This Policy applies to ENLIGHTEN’s processing of Personal Information in connection with:

  1. access to and use of ENSPACE;
  1. creation and administration of Accounts;
  1. ENSPACE applications and interfaces;
  1. APIs and integrations provided or operated by ENLIGHTEN;
  1. artificial intelligence functionality and AI Agents;
  1. the ENSPACE Add-in for Microsoft Word;
  1. support, administration, security, and operation of the Services;
  1. ENLIGHTEN websites and digital channels that reference this Policy;
  1. commercial, administrative, and support interactions relating to ENSPACE;
  1. ENLIGHTEN corporate websites, contact forms, demo requests, events, and commercial activities relating to its products and services.

This Policy does not govern independent processing activities performed by ENLIGHTEN Customers or third parties whose products and services are governed by their own privacy policies.

3. ENLIGHTEN’S ROLE IN PROCESSING PERSONAL INFORMATION

ENLIGHTEN’s role with respect to Personal Information depends on the context in which the information is processed.

3.1 ENLIGHTEN as Controller or Business

ENLIGHTEN may act as a controller, business, or equivalent entity under applicable privacy law when it determines the purposes and essential means of processing Personal Information in connection with its own business activities.

This may include, for example:

  1. Customer and Authorized User account information;
  1. business contact information;
  1. Customer representatives and administrative contacts;
  1. contracting and billing information;
  1. support and relationship-management information;
  1. technical, security, fraud-prevention, and audit information;
  1. information relating to use of ENLIGHTEN websites;
  1. corporate communications;
  1. product communications;
  1. marketing communications, where permitted by law; and
  1. information required to administer the commercial relationship.

3.2 ENLIGHTEN as Processor, Service Provider, or Contractor

When a Customer uses ENSPACE to submit, store, organize, transmit, analyze, or otherwise process Personal Information in connection with the Customer’s own business activities, ENLIGHTEN generally acts on behalf of that Customer.

Depending on applicable law, ENLIGHTEN may be referred to as a:

  1. processor;
  1. service provider;
  1. contractor; or
  1. equivalent data-processing entity.

In this context, Customer generally determines the purposes for which Personal Information is processed and is responsible for establishing an appropriate legal basis, authorization, notice, or other legal requirement applicable to its processing activities.

The respective rights and obligations of Customer and ENLIGHTEN may be further governed by a DPA or equivalent Contract Document.

4. DEFINITIONS

For purposes of this Policy:

“Authorized User” or “User” means an individual authorized by a Customer to access or use ENSPACE.

“Customer” means the business, organization, or other entity that purchases, subscribes to, or otherwise obtains access to ENSPACE.

“Customer Content” has the meaning described in Section 5.3.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household, and includes “personal data” and equivalent concepts under applicable privacy laws.

“Sensitive Personal Information” means information treated as sensitive, special-category, or otherwise subject to additional protection under applicable privacy law.

“Services” means ENSPACE and the related services, websites, applications, APIs, integrations, AI Features, AI Agents, Word Add-in, support services, and other products or services covered by this Policy.

5. CATEGORIES OF INFORMATION WE MAY PROCESS

Depending on the manner in which ENSPACE and ENLIGHTEN services are used, we may process the categories of information described below.

5.1 Account and User Information

This may include:

  1. name;
  1. email address;
  1. company or organization;
  1. title or role;
  1. User identifier;
  1. authentication information;
  1. language;
  1. Account preferences;
  1. User permissions;
  1. access profiles; and
  1. other information required to administer an Account.

5.2 Administrative and Commercial Information

This may include:

  1. Customer identity;
  1. Customer representatives;
  1. billing and administrative contacts;
  1. contracting information;
  1. Subscription plan;
  1. products, modules, or services purchased;
  1. usage and consumption information;
  1. invoicing information;
  1. transaction information; and
  1. payment-related information, where applicable.

ENLIGHTEN may use third-party payment providers and does not necessarily receive or store complete payment card information.

5.3 Customer Content

Customers and their Authorized Users may submit, transmit, generate, store, or process through ENSPACE information including:

  1. documents;
  1. text;
  1. contracts;
  1. files;
  1. forms;
  1. records;
  1. structured data;
  1. unstructured data;
  1. workflow information;
  1. tasks;
  1. databases;
  1. prompts and instructions;
  1. AI inputs and outputs;
  1. playbooks;
  1. templates;
  1. comments;
  1. information transmitted through integrations, APIs, or add-ins; and
  1. other information submitted or processed by Customer.

Collectively, this information is referred to in this Policy as “Customer Content.”

Customer Content may contain Personal Information, Sensitive Personal Information, confidential information, privileged information, trade secrets, or information relating to third parties depending on Customer’s use of ENSPACE.

5.4 Usage, Device, and Telemetry Information

We may process information relating to use of the Services, such as:

  1. features used;
  1. date and time of access;
  1. system events;
  1. logs;
  1. IP address;
  1. device type;
  1. browser type;
  1. operating system;
  1. session information;
  1. technical identifiers;
  1. performance metrics;
  1. errors and failures;
  1. security logs;
  1. audit logs;
  1. API usage; and
  1. technical information relating to integrations or AI functionality.

5.5 Support Information

When Customer or a User requests support, we may process:

  1. contact information;
  1. description of the issue;
  1. communications;
  1. screenshots;
  1. files provided for troubleshooting;
  1. technical records;
  1. logs; and
  1. other information reasonably necessary to investigate and resolve the request.

5.6 Website and Commercial Interaction Information

When individuals interact with ENLIGHTEN websites, forms, events, or commercial teams, we may process:

  1. name;
  1. business email;
  1. employer;
  1. title;
  1. phone number;
  1. country or region;
  1. demo requests;
  1. communications;
  1. marketing preferences;
  1. event registration information;
  1. website interactions; and
  1. other information voluntarily provided.

6. HOW WE OBTAIN INFORMATION

We may obtain information:

  1. directly from Customers or Users;
  1. through use of ENSPACE;
  1. from Customer Account Administrators;
  1. through APIs and integrations configured by Customer;
  1. through the ENSPACE Add-in for Microsoft Word;
  1. from services or systems authorized by Customer;
  1. automatically through logs, cookies, local storage, and similar technologies;
  1. through support interactions;
  1. through commercial or administrative interactions;
  1. from ENLIGHTEN Affiliates;
  1. from service providers; and
  1. from publicly available business sources where permitted by law.

7. HOW WE USE PERSONAL INFORMATION

Depending on the context and ENLIGHTEN’s legal role, we may process Personal Information to:

  1. provide and operate ENSPACE;
  1. authenticate Users;
  1. create and administer Accounts;
  1. manage permissions and access;
  1. perform functionality requested by Customers or Users;
  1. store, organize, transmit, and process Customer Content;
  1. operate workflows, automations, tasks, and integrations;
  1. provide AI functionality and AI Agents;
  1. provide the ENSPACE Add-in for Microsoft Word;
  1. provide technical support;
  1. investigate and resolve technical issues;
  1. identify, prevent, and investigate security incidents;
  1. detect fraud, abuse, or unauthorized use;
  1. maintain logs and audit records;
  1. measure usage and consumption;
  1. administer billing and Customer relationships;
  1. provide transaction and account communications;
  1. maintain, develop, and improve the Services;
  1. analyze performance, stability, usage patterns, and capacity;
  1. protect the rights, safety, property, and security of ENLIGHTEN, Customers, Users, and third parties;
  1. comply with legal and regulatory obligations;
  1. establish, exercise, or defend legal claims;
  1. communicate with business contacts;
  1. provide product or marketing communications where permitted by law; and
  1. perform other activities authorized by Customer, the Contract Documents, or applicable law.

8. LEGAL BASES FOR PROCESSING

Where applicable law requires a legal basis for processing and ENLIGHTEN acts as a controller, ENLIGHTEN may rely on one or more legal bases, including:

  1. performance of a contract or steps related to entering into a contract;
  1. compliance with legal or regulatory obligations;
  1. ENLIGHTEN’s or a third party’s legitimate interests, where permitted;
  1. consent, where required or appropriate;
  1. establishment, exercise, or defense of legal claims;
  1. fraud prevention and information security;
  1. protection of rights and interests recognized by law; and
  1. other legal bases available under applicable law.

Where ENLIGHTEN acts as a processor or service provider on behalf of Customer, Customer is generally responsible for determining the appropriate legal basis, authorization, notice, or other legal requirement applicable to the Customer’s processing activities.

9. CUSTOMER CONTENT

Customer retains all rights it possesses in Customer Content.

ENLIGHTEN does not acquire ownership of Customer documents, data, records, or other Customer Content merely because such information is submitted to, transmitted through, stored in, generated within, or processed through ENSPACE.

ENLIGHTEN may process Customer Content as reasonably necessary to:

  1. provide the Services;
  1. perform actions requested or configured by Customer or User;
  1. operate workflows, automations, AI Agents, and integrations;
  1. provide support;
  1. maintain security, reliability, and integrity of the Platform;
  1. prevent fraud or misuse;
  1. comply with legal obligations;
  1. exercise rights under the Contract Documents; and
  1. perform other activities expressly authorized by Customer.

ENLIGHTEN does not use the contents of Customer documents, contracts, playbooks, prompts, tasks, or similar Customer Content to target behavioral advertising to Users.

10. ARTIFICIAL INTELLIGENCE FEATURES AND AI AGENTS

ENSPACE may provide functionality based on artificial intelligence, machine learning, large language models, generative AI, AI Agents, proprietary models, and third-party models.

When a User activates an AI Feature, ENLIGHTEN may process information such as:

  1. prompts and instructions;
  1. selected text;
  1. portions or the entirety of documents submitted to the feature;
  1. information and records stored in ENSPACE;
  1. templates;
  1. playbooks;
  1. Customer-configured rules and parameters;
  1. information retrieved from integrated systems where authorized;
  1. generated outputs;
  1. tool calls;
  1. AI Agent activity; and
  1. technical metadata required to perform the operation.

The information processed depends on the feature used, Customer configuration, User actions, permissions, and the AI model or provider selected.

10.1 Third-Party AI Providers

Certain AI Features may use models, infrastructure, APIs, or technology provided by third parties.

Where applicable, information necessary to perform the requested functionality may be transmitted to the applicable provider or technical infrastructure.

Such processing is subject to:

  1. applicable Customer configuration;
  1. ENLIGHTEN’s contractual arrangements with the relevant provider;
  1. applicable Contract Documents;
  1. applicable DPA requirements; and
  1. applicable privacy and data protection laws.

Where ENSPACE allows Customer to select between different AI models or providers, data processing characteristics may vary based on the selected technology.

ENLIGHTEN may provide information regarding relevant providers or subprocessors through its DPA, subprocessors page, security documentation, privacy documentation, or another appropriate channel.

10.2 AI Model Training

Unless Customer expressly agrees otherwise in writing, ENLIGHTEN does not use Customer Content to train generalized artificial intelligence models for the independent benefit of ENLIGHTEN, unrelated Customers, or third parties.

Customer Content may nevertheless be processed through AI models where reasonably necessary to provide an AI Feature requested, enabled, or configured by Customer.

Aggregated or de-identified information may be used for:

  1. security;
  1. performance evaluation;
  1. quality monitoring;
  1. product analytics;
  1. capacity planning; and
  1. improvement of the Services,

provided that the information does not reasonably identify Customer or an individual and does not reveal Customer Confidential Information.

10.3 AI Outputs

AI-generated outputs may be inaccurate, incomplete, inconsistent, or inappropriate.

Use of artificial intelligence does not eliminate the need for appropriate human review.

ENLIGHTEN does not independently use Customer Content to make decisions for ENLIGHTEN’s own purposes that produce legal or similarly significant effects concerning individuals.

A Customer may choose to configure workflows, AI Agents, automation, or other functionality in connection with its own decision-making processes.

Customer is responsible for evaluating applicable legal obligations and ensuring appropriate human oversight where required.

11. ENSPACE ADD-IN FOR MICROSOFT WORD

ENLIGHTEN provides or may provide the ENSPACE Add-in for Microsoft Word (“Word Add-in”), which allows Authorized Users to access certain ENSPACE functionality directly within Microsoft Word.

This Privacy Policy expressly applies to information processed by ENLIGHTEN through the Word Add-in.

11.1 Information the Word Add-in May Access

When a User activates or authorizes functionality within the Word Add-in, the Add-in may access relevant content within the Microsoft Word document currently in use.

Depending on the requested functionality, this may include:

  1. text selected by the User;
  1. specific portions of the document;
  1. broader portions or the entirety of the document where reasonably necessary to perform the requested operation;
  1. document structure and document elements;
  1. information entered by the User through the Add-in; and
  1. information generated through interaction with the Add-in.

The Word Add-in may transmit relevant information to ENLIGHTEN systems to perform the requested operation.

Content accessed or transmitted through the Word Add-in is treated as Customer Content.

11.2 Purposes of Word Add-in Processing

Depending on available functionality, the Word Add-in may process document content to:

  1. analyze documents;
  1. review documents;
  1. suggest edits, additions, corrections, or alternative language;
  1. use AI Agents;
  1. apply playbooks defined or made available in ENSPACE;
  1. consult clauses, rules, instructions, or parameters stored in ENSPACE;
  1. locate and use document templates;
  1. generate or insert content;
  1. process information extracted from a document;
  1. create, submit, or update ENSPACE tasks;
  1. create or update records or workflow information; and
  1. perform other actions expressly initiated or authorized by the User.

11.3 Changes to Documents

The Word Add-in may insert, replace, supplement, or modify document content when such action forms part of functionality requested or authorized by the User.

ENLIGHTEN seeks to design the Word Add-in so that material document changes result from User actions or functionality clearly presented to the User.

11.4 AI Through the Word Add-in

When a User activates AI functionality through the Word Add-in, relevant document content may be transmitted to ENSPACE systems and AI Agents and, where applicable, to third-party AI infrastructure or models used to perform the requested action.

Such processing is subject to this Policy, applicable Contract Documents, Customer configuration, and the provisions regarding artificial intelligence described above.

11.5 Templates and Playbooks

The Word Add-in may retrieve and use templates, playbooks, rules, clauses, parameters, and other content maintained within Customer’s ENSPACE environment.

This information may be combined with the document currently in use to perform actions requested by the User.

11.6 Tasks and Information Sent to ENSPACE

Users may use the Word Add-in to transmit documents, excerpts, instructions, or other information to ENSPACE for purposes such as creating or updating:

  1. tasks;
  1. records;
  1. workflows;
  1. requests; or
  1. other information within Customer’s ENSPACE environment.

Information transmitted in this manner may be stored within Customer’s Account.

11.7 Authentication and Permissions

The Word Add-in may require the User to authenticate and be authorized to access a valid ENSPACE Account.

Permissions requested by the Word Add-in are intended to permit the functionality made available and the corresponding access required to perform User-requested actions.

ENLIGHTEN does not request that Users disclose Microsoft account passwords directly to ENLIGHTEN for purposes of authenticating their Microsoft identity.

Where Microsoft authentication is used, it will occur through authentication mechanisms made available or authorized by Microsoft.

11.8 Security of Transmission

Communications between the Word Add-in and ENSPACE external services are protected through secure communication protocols, including HTTPS/TLS, as applicable.

11.9 Relationship with Microsoft

Microsoft Word and Microsoft 365 are products and services provided by Microsoft.

Microsoft may independently process information in connection with its products and services under Microsoft’s applicable agreements and privacy policies.

This Policy describes ENLIGHTEN’s processing in connection with ENSPACE and the Word Add-in and does not replace Microsoft’s privacy terms.

Microsoft is not responsible for the operation of ENSPACE, ENLIGHTEN’s AI functionality, or ENLIGHTEN’s data-processing practices described in this Policy.

12. INTEGRATIONS, APIs, AND THIRD-PARTY SERVICES

ENSPACE may allow Customer to connect its Account to external applications, services, APIs, systems, databases, or platforms.

When Customer enables an integration, information may be transmitted between ENSPACE and the integrated service to perform requested functionality.

The scope of information exchanged depends on:

  1. the integration selected;
  1. permissions granted;
  1. Customer configuration;
  1. functionality enabled; and
  1. User actions.

Third-party services may independently process information under their own agreements and privacy policies.

Customer is responsible for evaluating and authorizing integrations enabled within its Account.

13. COOKIES AND SIMILAR TECHNOLOGIES

ENLIGHTEN websites and certain web interfaces may use:

  1. cookies;
  1. local storage;
  1. session technologies;
  1. pixels;
  1. SDKs; and
  1. similar technologies.
  1. These technologies may be used to:
  1. maintain authenticated sessions;
  1. preserve User preferences;
  1. provide security;
  1. prevent fraud;
  1. measure performance;
  1. understand use of the Services;
  1. diagnose problems;
  1. improve User experience; and
  1. perform analytics.

Where required by applicable law, ENLIGHTEN will provide appropriate consent or preference-management mechanisms.

Some third-party technologies may independently collect information through ENLIGHTEN websites. Information about such technologies may be provided through a cookie notice or privacy preference tool where applicable.

14. HOW WE DISCLOSE INFORMATION

ENLIGHTEN does not sell Customer Content.

Personal Information may be disclosed in the circumstances described below.

14.1 ENLIGHTEN Affiliates

Information may be shared among ENLIGHTEN group entities where reasonably necessary for:

  1. service delivery;
  1. administration;
  1. support;
  1. security;
  1. product operations;
  1. billing; or
  1. other legitimate corporate purposes.

14.2 Service Providers and Subprocessors

We may disclose information to service providers and subprocessors that assist with:

  1. cloud infrastructure;
  1. hosting;
  1. security;
  1. monitoring;
  1. communication;
  1. support;
  1. data processing;
  1. artificial intelligence and language models;
  1. authentication;
  1. analytics;
  1. billing; and
  1. other operational functions necessary to provide the Services.

Such providers are subject to contractual and legal obligations applicable to the services they provide.

14.3 Customer-Enabled Services and Integrations

Information may be disclosed where Customer or a User requests, enables, or configures an integration or service that requires transmission of information.

14.4 Professional Advisers

Information may be disclosed where reasonably necessary to:

  1. attorneys;
  1. accountants;
  1. auditors;
  1. insurers;
  1. consultants; and
  1. other professional advisers,

subject to appropriate confidentiality obligations.

14.5 Legal and Government Requests

ENLIGHTEN may disclose information when reasonably necessary to:

  1. comply with applicable law;
  1. respond to valid legal process;
  1. comply with court orders;
  1. respond to legally valid requests from governmental authorities;
  1. protect legal rights; or
  1. protect against fraud, abuse, security threats, or unlawful activity.

14.6 Corporate Transactions

Information may be disclosed or transferred in connection with:

  1. mergers;
  1. acquisitions;
  1. financing;
  1. investment;
  1. restructuring;
  1. reorganization;
  1. sale of assets; or
  1. similar corporate transactions,

subject to appropriate confidentiality and privacy protections.

15. SUBPROCESSORS

ENLIGHTEN may engage subprocessors to provide portions of the Services.

Where ENLIGHTEN acts as a processor, service provider, or contractor on behalf of Customer, use of subprocessors will be governed by the applicable DPA or Contract Documents.

ENLIGHTEN may maintain an updated list of subprocessors through:

  1. its website;
  1. privacy documentation;
  1. security documentation;
  1. a subprocessors page; or
  1. another mechanism made available to Customers.

16. INTERNATIONAL DATA TRANSFERS

ENSPACE is a global technology platform and may use infrastructure, Affiliates, service providers, and subprocessors located in different countries.

As a result, Personal Information may be processed outside the country in which Customer or User is located.

Where required by applicable law, ENLIGHTEN will use appropriate mechanisms for international data transfers, which may include:

  1. contractual safeguards;
  1. Standard Contractual Clauses;
  1. adequacy decisions;
  1. recognized transfer mechanisms;
  1. data protection agreements; and
  1. other safeguards permitted under applicable law.

17. DATA RETENTION

ENLIGHTEN retains Personal Information and Customer Content for periods reasonably necessary for the applicable processing purposes, taking into account:

  1. duration of the commercial relationship;
  1. Customer configuration;
  1. Contract Documents;
  1. security needs;
  1. legal and regulatory obligations;
  1. applicable statutes of limitation;
  1. dispute-resolution requirements; and
  1. establishment, exercise, or defense of legal claims.

Following termination of Customer’s Subscription, export, retention, and deletion of Customer Content will be handled in accordance with the applicable Contract Documents.

Deletion from active systems may not immediately remove all information from backups, security records, or business continuity systems.

Residual copies will remain protected and will be deleted or overwritten according to applicable retention cycles unless retention is legally required.

18. INFORMATION SECURITY

ENLIGHTEN maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized:

  1. access;
  1. use;
  1. alteration;
  1. destruction; or
  1. disclosure.
  1. Depending on the Services and technical environment, such measures may include:
  1. identity and access management;
  1. permission controls;
  1. authentication mechanisms;
  1. encryption of communications;
  1. event logging;
  1. security monitoring;
  1. infrastructure controls;
  1. secure development practices;
  1. backup and continuity mechanisms;
  1. vulnerability management;
  1. internal policies and procedures; and
  1. training of authorized personnel.

No technological system can eliminate all security risks.

Where a security incident affects Personal Information or Customer Content, ENLIGHTEN will respond in accordance with applicable law and applicable Contract Documents.

19. ENLIGHTEN ACCESS TO CUSTOMER CONTENT

Authorized ENLIGHTEN personnel may access Customer Content where reasonably necessary to:

  1. respond to a support request;
  1. diagnose technical issues;
  1. investigate security incidents;
  1. perform maintenance;
  1. protect the Platform or Users;
  1. comply with legal obligations; or
  1. perform another activity authorized under the Contract Documents.

ENLIGHTEN seeks to limit human access to Customer Content to personnel and circumstances reasonably necessary for the applicable purpose.

20. AGGREGATED AND DE-IDENTIFIED INFORMATION

ENLIGHTEN may generate statistics, metrics, telemetry, and aggregated or de-identified information relating to use of ENSPACE.

Such information may be used for:

  1. performance analysis;
  1. security;
  1. trend analysis;
  1. capacity planning;
  1. development and improvement of products;
  1. benchmarking;
  1. research;
  1. statistical analysis; and
  1. service analytics.

ENLIGHTEN will take reasonable measures designed to prevent such information from reasonably identifying Customer or an individual when used outside the provision of Services to Customer.

Where required by applicable law, ENLIGHTEN will not attempt to re-identify information that has been maintained as de-identified, except where legally permitted for testing or verifying de-identification processes.

21. ADVERTISING AND COMMERCIAL USE OF INFORMATION

ENLIGHTEN does not use Customer documents, contracts, playbooks, prompts, tasks, or similar Customer Content for cross-context behavioral advertising or behavioral advertising targeted based on the contents of Customer Content.

Business contact information may be used to communicate regarding ENLIGHTEN products, services, events, or commercial activities where permitted by applicable law.

Recipients may opt out of marketing communications through available unsubscribe mechanisms.

Administrative, transactional, security, and service communications are not treated as marketing communications.

22. ENTERPRISE CUSTOMERS AND ACCOUNT ADMINISTRATORS

ENSPACE is primarily intended for enterprise and professional use.

Where an individual accesses ENSPACE through an organization, that organization may be able to:

  1. administer the Account;
  1. create or remove Users;
  1. assign permissions;
  1. configure workflows and functionality;
  1. access information stored in its environment;
  1. administer integrations;
  1. configure AI functionality;
  1. establish internal policies; and
  1. otherwise manage its ENSPACE environment.

ENLIGHTEN does not control the internal privacy, employment, compliance, or information-management policies adopted by its customers.

Requests concerning Personal Information processed by ENLIGHTEN solely on behalf of a customer may need to be directed to that Customer.

23. PRIVACY RIGHTS

Depending on the jurisdiction and applicable law, individuals may have rights concerning their Personal Information.

Such rights may include:

  1. confirming whether Personal Information is processed;
  1. accessing Personal Information;
  1. obtaining copies of Personal Information;
  1. correcting inaccurate or incomplete information;
  1. requesting deletion;
  1. requesting restriction of processing;
  1. requesting portability;
  1. obtaining information concerning disclosure or sharing;
  1. objecting to certain processing;
  1. withdrawing consent where processing is based on consent;
  1. opting out of certain processing;
  1. requesting review of certain automated decisions where applicable;
  1. appealing certain decisions concerning privacy requests where applicable; and
  1. submitting a complaint to a competent privacy or data protection authority.

Available rights and conditions for exercising them depend on the applicable law and ENLIGHTEN’s role in the relevant processing activity.

24. REQUESTS RELATING TO CUSTOMER-CONTROLLED INFORMATION

Where ENLIGHTEN processes Personal Information on behalf of Customer, Customer will generally be responsible for responding to privacy requests relating to that information.

If an individual submits a request directly to ENLIGHTEN concerning information processed exclusively on behalf of Customer, ENLIGHTEN may:

  1. direct the individual to Customer;
  1. notify Customer of the request;
  1. assist Customer in responding; or
  1. take other action required by the applicable DPA or law.

25. HOW TO EXERCISE PRIVACY RIGHTS

Privacy requests, questions, or requests to exercise rights may be submitted to: dpo@be-enlighten.com

ENLIGHTEN may request information reasonably necessary to:

  1. verify the identity of the requester;
  1. verify authority to act on another person’s behalf;
  1. locate relevant information;
  1. distinguish between different Customers or Accounts; and
  1. prevent fraudulent or abusive requests.

Requests will be handled within the periods required by applicable law.

Where permitted, ENLIGHTEN may deny or limit requests where an applicable exception applies.

26. BRAZIL – LEI GERAL DE PROTEÇÃO DE DADOS

Where Brazil’s Law No. 13,709/2018, the Lei Geral de Proteção de Dados Pessoais (“LGPD”), applies, the terms controlador, operador, titular, dados pessoais, dados pessoais sensíveis, and tratamento will have the meanings provided by the LGPD.

ENLIGHTEN will comply with applicable LGPD principles and obligations according to its role in the relevant processing activity.

Where ENLIGHTEN acts as controller, applicable processing may rely on the legal bases permitted under the LGPD.

Where ENLIGHTEN acts as processor on behalf of Customer, Customer will generally determine the purposes and legal basis of the processing and ENLIGHTEN will process Personal Information subject to Customer instructions and applicable Contract Documents.

Data subjects may exercise applicable LGPD rights through the channels identified in this Policy.

27. EUROPEAN ECONOMIC AREA AND UNITED KINGDOM

Where the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR (“UK GDPR”), or similar legislation applies, ENLIGHTEN will process Personal Information on an appropriate legal basis.

Depending on the applicable circumstances, individuals may have rights including:

  1. access;
  1. rectification;
  1. erasure;
  1. restriction;
  1. portability;
  1. objection;
  1. withdrawal of consent; and
  1. filing a complaint with a competent supervisory authority.
  1. Where ENLIGHTEN relies on legitimate interests, such interests may include:
  1. providing and administering the Services;
  1. securing the Services;
  1. preventing fraud or misuse;
  1. improving the Platform;
  1. managing business relationships; and
  1. communicating with business contacts,

provided such interests are not overridden by applicable individual rights and interests.

Where required for international transfers, ENLIGHTEN may rely on recognized transfer mechanisms, including Standard Contractual Clauses and applicable supplementary safeguards.

28. UNITED STATES PRIVACY RIGHTS

Residents of certain U.S. states may have additional rights under applicable state privacy laws.

Depending on the applicable state and ENLIGHTEN’s legal role, rights may include the right to:

  1. confirm whether ENLIGHTEN processes Personal Information;
  1. access Personal Information;
  1. correct inaccuracies;
  1. request deletion;
  1. obtain a portable copy of Personal Information;
  1. obtain information concerning categories of Personal Information processed;
  1. obtain information concerning categories of third parties to whom Personal Information is disclosed;
  1. opt out of certain sales of Personal Information;
  1. opt out of certain sharing or processing for targeted advertising;
  1. opt out of certain profiling or automated decision-making activities producing legal or similarly significant effects, where applicable;
  1. limit certain uses of Sensitive Personal Information where applicable;
  1. appeal a denial of a privacy request where applicable; and
  1. exercise rights without unlawful discrimination or retaliation.

The availability and scope of rights depend on the state law applicable to the individual and ENLIGHTEN.

ENLIGHTEN does not sell Customer Content.

ENLIGHTEN does not sell or share Personal Information contained in Customer Content for cross-context behavioral advertising.

Where ENLIGHTEN acts solely as a processor, service provider, or contractor for a Customer, privacy requests concerning Customer Content should generally be directed to the applicable Customer.

28.1 Appeals

Where applicable state law provides a right to appeal ENLIGHTEN’s refusal to take action on a privacy request, the requester may submit an appeal by contacting: dpo@be-enlighten.com

The request should identify the original request and explain the basis for the appeal.

ENLIGHTEN will respond within the period required by applicable law.

28.2 Authorized Agents

Where permitted by applicable law, an individual may designate an authorized agent to submit a privacy request on the individual’s behalf.

ENLIGHTEN may require:

  1. evidence of the agent’s authority;
  1. verification of the individual’s identity; or
  1. direct confirmation from the individual,

except where applicable law provides otherwise.

29. CALIFORNIA PRIVACY NOTICE

This Section supplements the remainder of this Privacy Policy and applies to California residents to the extent ENLIGHTEN is subject to the California Consumer Privacy Act, as amended (“CCPA”), in connection with the relevant processing.

29.1 Categories of Personal Information

Depending on an individual’s interaction with ENLIGHTEN, ENLIGHTEN may collect the following categories of Personal Information described under California law:

Identifiers, such as:

  1. name;
  1. business email address;
  1. IP address;
  1. Account identifier; and
  1. online identifiers.

Customer Records Information, such as:

  1. business contact information;
  1. billing information; and
  1. transaction-related information.

Commercial Information, such as:

  1. ENSPACE products or plans purchased;
  1. Subscription information;
  1. usage information; and
  1. commercial relationship history.

Internet or Other Electronic Network Activity, such as:

  1. Platform interactions;
  1. website activity;
  1. logs;
  1. device information;
  1. browser information; and
  1. security events.

Professional or Employment-Related Information, such as:

  1. company;
  1. job title;
  1. professional role; and
  1. organizational affiliation.

Audio, Electronic, Visual, or Similar Information, where voluntarily provided through:

  1. support materials;
  1. screenshots;
  1. recordings; or
  1. other interactions.

Inferences, where generated from business or Platform usage information for purposes such as:

  1. service administration;
  1. security;
  1. analytics; or
  1. product improvement.

Sensitive Personal Information, where processed in applicable circumstances.

Customer Content may contain additional categories of Personal Information depending on the information submitted by Customer.

Where ENLIGHTEN processes Customer Content solely as a service provider or contractor, Customer is responsible for determining the categories of information processed through its ENSPACE environment.

29.2 Sources of Personal Information

ENLIGHTEN may obtain Personal Information from:

  1. individuals directly;
  1. Customers;
  1. Customer Account Administrators;
  1. Authorized Users;
  1. use of ENSPACE;
  1. websites;
  1. integrations and third-party systems authorized by Customer;
  1. ENLIGHTEN Affiliates;
  1. service providers; and
  1. publicly available business sources where permitted by law.

29.3 Business or Commercial Purposes

ENLIGHTEN may collect, use, and disclose Personal Information for purposes including:

  1. providing ENSPACE;
  1. Account administration;
  1. authentication;
  1. Customer support;
  1. billing;
  1. transaction processing;
  1. security;
  1. fraud prevention;
  1. debugging;
  1. maintaining and improving the Services;
  1. internal analytics;
  1. auditing;
  1. communicating with Customers and Users;
  1. legal compliance;
  1. protecting rights and security;
  1. product development;
  1. providing requested AI functionality; and
  1. other purposes described in this Policy.

29.4 Categories of Third Parties

Depending on the applicable processing, Personal Information may be disclosed to categories of recipients including:

  1. ENLIGHTEN Affiliates;
  1. cloud infrastructure providers;
  1. security providers;
  1. communications providers;
  1. support providers;
  1. authentication providers;
  1. analytics providers;
  1. artificial intelligence providers;
  1. subprocessors;
  1. professional advisers;
  1. Customer-selected integrations; and
  1. governmental or legal authorities where required.

29.5 Sale and Sharing

ENLIGHTEN does not sell Customer Content.

ENLIGHTEN does not sell or share Personal Information contained in Customer Content for cross-context behavioral advertising.

ENLIGHTEN does not use Customer Content for behavioral advertising based on the contents of Customer documents, contracts, playbooks, prompts, tasks, or similar information.

ENLIGHTEN’s practices concerning website cookies, analytics technologies, or advertising technologies may depend on the technologies deployed on the applicable website.

Where ENLIGHTEN engages in activity that constitutes a “sale” or “sharing” of Personal Information under the CCPA, ENLIGHTEN will provide the notices, opt-out mechanisms, and privacy choices required by applicable law.

29.6 Sensitive Personal Information

ENLIGHTEN may process Sensitive Personal Information where:

  1. provided by or on behalf of Customer through Customer Content;
  1. reasonably necessary for security or authentication;
  1. legally required; or
  1. otherwise disclosed in this Policy.

Where ENLIGHTEN acts as a service provider or contractor for Customer, Sensitive Personal Information contained in Customer Content is processed on Customer’s behalf.

Where applicable law grants a right to limit certain uses or disclosures of Sensitive Personal Information and ENLIGHTEN engages in such processing, ENLIGHTEN will provide an applicable mechanism for exercising that right.

29.7 California Consumer Rights

Subject to applicable exceptions and verification requirements, California residents may have the right to:

  1. know categories of Personal Information collected;
  1. know specific pieces of Personal Information collected;
  1. know categories of sources;
  1. know business or commercial purposes for collection, use, disclosure, sale, or sharing;
  1. know categories of third parties to whom Personal Information is disclosed;
  1. request correction;
  1. request deletion;
  1. opt out of sale or sharing;
  1. limit certain uses and disclosures of Sensitive Personal Information;
  1. receive equal treatment for exercising privacy rights; and
  1. exercise other rights available under the CCPA.

29.8 Automated Decisionmaking Technology

ENLIGHTEN may provide Customers with AI, automation, workflow, and AI Agent functionality.

ENLIGHTEN does not independently use Customer Content for its own purposes to make decisions concerning individuals that produce legal or similarly significant effects.

Customers may configure ENSPACE functionality for their own decision-making processes.

To the extent California law provides applicable rights relating to ENLIGHTEN’s own use of automated decisionmaking technology, ENLIGHTEN will provide notices and mechanisms required by applicable law.

29.9 Authorized Agents

California residents may use an authorized agent to submit certain requests.

ENLIGHTEN may require verification of:

  1. the consumer;
  1. the agent’s authority; or
  1. both,

as permitted by California law.

29.10 Non-Discrimination

ENLIGHTEN will not unlawfully discriminate against an individual for exercising rights under the CCPA.

29.11 Retention

ENLIGHTEN retains categories of Personal Information for periods reasonably necessary and proportionate to the purposes for which they were collected or processed, taking into account:

  1. Customer relationships;
  1. contractual requirements;
  1. security obligations;
  1. legal and regulatory requirements;
  1. dispute-resolution needs; and
  1. applicable retention policies.

29.12 California Requests

California privacy requests may be submitted through: dpo@be-enlighten.com

Where required by applicable law, ENLIGHTEN may provide additional request methods or privacy-choice mechanisms.

30. SENSITIVE PERSONAL INFORMATION AND CONFIDENTIAL INFORMATION

Customers may use ENSPACE in business activities involving confidential information or categories of data subject to heightened legal requirements.

Customer is responsible for determining whether it has appropriate authority, legal basis, notices, consents, and safeguards to submit or process such information through ENSPACE.

Where ENLIGHTEN acts as a processor, service provider, or contractor, ENLIGHTEN processes such information subject to:

  1. Customer instructions;
  1. applicable Contract Documents;
  1. the applicable DPA; and
  1. applicable law.

Additional requirements concerning particular categories of information may be established by separate agreement.

31. CHILDREN

ENSPACE is an enterprise software platform intended primarily for professional and business use.

ENLIGHTEN does not knowingly direct ENSPACE to children for purposes of creating independent consumer accounts.

If ENLIGHTEN becomes aware that Personal Information relating to a minor has been processed in circumstances inconsistent with applicable law or the intended use of the Services, ENLIGHTEN may take appropriate steps to restrict, delete, or otherwise address the processing.

This Section does not prohibit a Customer from processing information relating to minors where the Customer has lawful authority to do so and the processing is consistent with the Contract Documents.

32. EXTERNAL LINKS AND THIRD-PARTY SERVICES

ENSPACE may provide links or connections to third-party websites, products, and services.

ENLIGHTEN is not responsible for independent privacy practices of third-party services.

Users should review applicable third-party privacy policies before independently submitting information to such providers.

33. CORPORATE TRANSACTIONS AND CHANGE OF CONTROL

If ENLIGHTEN participates in:

  1. a merger;
  1. acquisition;
  1. corporate reorganization;
  1. financing;
  1. investment;
  1. sale of assets; or
  1. similar transaction,

information relating to the Services may be disclosed or transferred as part of the transaction.

ENLIGHTEN will apply appropriate confidentiality and privacy protections to such information as required by applicable law.

34. RELATIONSHIP WITH THE DATA PROCESSING AGREEMENT

Where ENLIGHTEN and Customer have entered into a DPA, that DPA supplements this Privacy Policy with respect to Personal Information processed by ENLIGHTEN on Customer’s behalf.

In the event of a conflict concerning ENLIGHTEN’s obligations as a processor, service provider, or contractor with respect to Customer Personal Information, the applicable DPA will control to the extent specified in that DPA.

35. CHANGES TO THIS PRIVACY POLICY

ENLIGHTEN may update this Privacy Policy periodically to reflect:

  1. changes to its products or Services;
  1. new functionality;
  1. technological developments;
  1. changes in processing practices;
  1. legal or regulatory developments;
  1. security improvements;
  1. governance improvements; or
  1. other legitimate operational changes.

The current version will identify the date of its most recent update.

Where a change materially affects ENLIGHTEN’s privacy practices, ENLIGHTEN may provide additional notice through:

  1. the Platform;
  1. email;
  1. website notice; or
  1. another appropriate method.

36. LANGUAGES

This Privacy Policy may be made available in different languages.

Where applicable Contract Documents specify a controlling language, that provision will apply in the event of an inconsistency between translated versions.

37. PRIVACY CONTACT

Questions, requests, or complaints concerning this Privacy Policy, privacy, or data protection may be directed to ENLIGHTEN’s privacy contact at: dpo@be-enlighten.com

Where a request relates to Personal Information processed by ENLIGHTEN on behalf of a Customer organization, the individual may need to direct the request to the applicable Customer or Account Administrator.

38. OUR COMMITMENT TO PRIVACY AND DATA PROTECTION

ENLIGHTEN seeks to develop and operate ENSPACE according to principles of privacy, security, transparency, accountability, and appropriate Customer control consistent with the enterprise nature of the Services.

Our objective is to enable organizations to use technology, automation, and artificial intelligence responsibly while protecting ownership, confidentiality, integrity, and privacy of information processed through the Platform.