Last Updated: September 2026
ENLIGHTEN values the privacy, confidentiality, and security of information processed through its products and services.
This Privacy Policy (“Privacy Policy” or “Policy”) describes how ENLIGHTEN collects, uses, stores, transmits, shares, discloses, and protects Personal Information in connection with its business activities, websites, commercial relationships, and services, including the ENSPACE platform, applications, interfaces, APIs, integrations, workflow automation functionality, artificial intelligence features, AI Agents, and the ENSPACE Add-in for Microsoft Word.
This Policy should be read together with the ENSPACE Terms of Use and any applicable Master Subscription Agreement (“MSA”), Data Processing Agreement (“DPA”), Order Form, Proposal, product-specific terms, Usage-Based Services Terms, and other Contract Documents entered into by ENLIGHTEN and its Customers.
ENSPACE is an enterprise software platform developed and provided by companies within The ENLIGHTEN Company group.
For purposes of this Policy, “ENLIGHTEN” means the ENLIGHTEN group entity responsible for providing ENSPACE to the applicable Customer, as identified in the applicable MSA, Order Form, Proposal, contract, or another Contract Document.
Depending on Customer location and the structure of the applicable transaction, different ENLIGHTEN group entities may participate in the provision, administration, operation, security, development, or support of the Services, subject to applicable confidentiality, privacy, and data protection obligations.
Where applicable, the entity identified in Customer’s applicable Contract Documents will be the primary ENLIGHTEN contracting entity.
This Policy applies to ENLIGHTEN’s processing of Personal Information in connection with:
This Policy does not govern independent processing activities performed by ENLIGHTEN Customers or third parties whose products and services are governed by their own privacy policies.
ENLIGHTEN’s role with respect to Personal Information depends on the context in which the information is processed.
ENLIGHTEN may act as a controller, business, or equivalent entity under applicable privacy law when it determines the purposes and essential means of processing Personal Information in connection with its own business activities.
This may include, for example:
When a Customer uses ENSPACE to submit, store, organize, transmit, analyze, or otherwise process Personal Information in connection with the Customer’s own business activities, ENLIGHTEN generally acts on behalf of that Customer.
Depending on applicable law, ENLIGHTEN may be referred to as a:
In this context, Customer generally determines the purposes for which Personal Information is processed and is responsible for establishing an appropriate legal basis, authorization, notice, or other legal requirement applicable to its processing activities.
The respective rights and obligations of Customer and ENLIGHTEN may be further governed by a DPA or equivalent Contract Document.
For purposes of this Policy:
“Authorized User” or “User” means an individual authorized by a Customer to access or use ENSPACE.
“Customer” means the business, organization, or other entity that purchases, subscribes to, or otherwise obtains access to ENSPACE.
“Customer Content” has the meaning described in Section 5.3.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household, and includes “personal data” and equivalent concepts under applicable privacy laws.
“Sensitive Personal Information” means information treated as sensitive, special-category, or otherwise subject to additional protection under applicable privacy law.
“Services” means ENSPACE and the related services, websites, applications, APIs, integrations, AI Features, AI Agents, Word Add-in, support services, and other products or services covered by this Policy.
Depending on the manner in which ENSPACE and ENLIGHTEN services are used, we may process the categories of information described below.
This may include:
This may include:
ENLIGHTEN may use third-party payment providers and does not necessarily receive or store complete payment card information.
Customers and their Authorized Users may submit, transmit, generate, store, or process through ENSPACE information including:
Collectively, this information is referred to in this Policy as “Customer Content.”
Customer Content may contain Personal Information, Sensitive Personal Information, confidential information, privileged information, trade secrets, or information relating to third parties depending on Customer’s use of ENSPACE.
We may process information relating to use of the Services, such as:
When Customer or a User requests support, we may process:
When individuals interact with ENLIGHTEN websites, forms, events, or commercial teams, we may process:
We may obtain information:
Depending on the context and ENLIGHTEN’s legal role, we may process Personal Information to:
Where applicable law requires a legal basis for processing and ENLIGHTEN acts as a controller, ENLIGHTEN may rely on one or more legal bases, including:
Where ENLIGHTEN acts as a processor or service provider on behalf of Customer, Customer is generally responsible for determining the appropriate legal basis, authorization, notice, or other legal requirement applicable to the Customer’s processing activities.
Customer retains all rights it possesses in Customer Content.
ENLIGHTEN does not acquire ownership of Customer documents, data, records, or other Customer Content merely because such information is submitted to, transmitted through, stored in, generated within, or processed through ENSPACE.
ENLIGHTEN may process Customer Content as reasonably necessary to:
ENLIGHTEN does not use the contents of Customer documents, contracts, playbooks, prompts, tasks, or similar Customer Content to target behavioral advertising to Users.
ENSPACE may provide functionality based on artificial intelligence, machine learning, large language models, generative AI, AI Agents, proprietary models, and third-party models.
When a User activates an AI Feature, ENLIGHTEN may process information such as:
The information processed depends on the feature used, Customer configuration, User actions, permissions, and the AI model or provider selected.
Certain AI Features may use models, infrastructure, APIs, or technology provided by third parties.
Where applicable, information necessary to perform the requested functionality may be transmitted to the applicable provider or technical infrastructure.
Such processing is subject to:
Where ENSPACE allows Customer to select between different AI models or providers, data processing characteristics may vary based on the selected technology.
ENLIGHTEN may provide information regarding relevant providers or subprocessors through its DPA, subprocessors page, security documentation, privacy documentation, or another appropriate channel.
Unless Customer expressly agrees otherwise in writing, ENLIGHTEN does not use Customer Content to train generalized artificial intelligence models for the independent benefit of ENLIGHTEN, unrelated Customers, or third parties.
Customer Content may nevertheless be processed through AI models where reasonably necessary to provide an AI Feature requested, enabled, or configured by Customer.
Aggregated or de-identified information may be used for:
provided that the information does not reasonably identify Customer or an individual and does not reveal Customer Confidential Information.
AI-generated outputs may be inaccurate, incomplete, inconsistent, or inappropriate.
Use of artificial intelligence does not eliminate the need for appropriate human review.
ENLIGHTEN does not independently use Customer Content to make decisions for ENLIGHTEN’s own purposes that produce legal or similarly significant effects concerning individuals.
A Customer may choose to configure workflows, AI Agents, automation, or other functionality in connection with its own decision-making processes.
Customer is responsible for evaluating applicable legal obligations and ensuring appropriate human oversight where required.
ENLIGHTEN provides or may provide the ENSPACE Add-in for Microsoft Word (“Word Add-in”), which allows Authorized Users to access certain ENSPACE functionality directly within Microsoft Word.
This Privacy Policy expressly applies to information processed by ENLIGHTEN through the Word Add-in.
When a User activates or authorizes functionality within the Word Add-in, the Add-in may access relevant content within the Microsoft Word document currently in use.
Depending on the requested functionality, this may include:
The Word Add-in may transmit relevant information to ENLIGHTEN systems to perform the requested operation.
Content accessed or transmitted through the Word Add-in is treated as Customer Content.
Depending on available functionality, the Word Add-in may process document content to:
The Word Add-in may insert, replace, supplement, or modify document content when such action forms part of functionality requested or authorized by the User.
ENLIGHTEN seeks to design the Word Add-in so that material document changes result from User actions or functionality clearly presented to the User.
When a User activates AI functionality through the Word Add-in, relevant document content may be transmitted to ENSPACE systems and AI Agents and, where applicable, to third-party AI infrastructure or models used to perform the requested action.
Such processing is subject to this Policy, applicable Contract Documents, Customer configuration, and the provisions regarding artificial intelligence described above.
The Word Add-in may retrieve and use templates, playbooks, rules, clauses, parameters, and other content maintained within Customer’s ENSPACE environment.
This information may be combined with the document currently in use to perform actions requested by the User.
Users may use the Word Add-in to transmit documents, excerpts, instructions, or other information to ENSPACE for purposes such as creating or updating:
Information transmitted in this manner may be stored within Customer’s Account.
The Word Add-in may require the User to authenticate and be authorized to access a valid ENSPACE Account.
Permissions requested by the Word Add-in are intended to permit the functionality made available and the corresponding access required to perform User-requested actions.
ENLIGHTEN does not request that Users disclose Microsoft account passwords directly to ENLIGHTEN for purposes of authenticating their Microsoft identity.
Where Microsoft authentication is used, it will occur through authentication mechanisms made available or authorized by Microsoft.
Communications between the Word Add-in and ENSPACE external services are protected through secure communication protocols, including HTTPS/TLS, as applicable.
Microsoft Word and Microsoft 365 are products and services provided by Microsoft.
Microsoft may independently process information in connection with its products and services under Microsoft’s applicable agreements and privacy policies.
This Policy describes ENLIGHTEN’s processing in connection with ENSPACE and the Word Add-in and does not replace Microsoft’s privacy terms.
Microsoft is not responsible for the operation of ENSPACE, ENLIGHTEN’s AI functionality, or ENLIGHTEN’s data-processing practices described in this Policy.
ENSPACE may allow Customer to connect its Account to external applications, services, APIs, systems, databases, or platforms.
When Customer enables an integration, information may be transmitted between ENSPACE and the integrated service to perform requested functionality.
The scope of information exchanged depends on:
Third-party services may independently process information under their own agreements and privacy policies.
Customer is responsible for evaluating and authorizing integrations enabled within its Account.
ENLIGHTEN websites and certain web interfaces may use:
Where required by applicable law, ENLIGHTEN will provide appropriate consent or preference-management mechanisms.
Some third-party technologies may independently collect information through ENLIGHTEN websites. Information about such technologies may be provided through a cookie notice or privacy preference tool where applicable.
ENLIGHTEN does not sell Customer Content.
Personal Information may be disclosed in the circumstances described below.
Information may be shared among ENLIGHTEN group entities where reasonably necessary for:
We may disclose information to service providers and subprocessors that assist with:
Such providers are subject to contractual and legal obligations applicable to the services they provide.
Information may be disclosed where Customer or a User requests, enables, or configures an integration or service that requires transmission of information.
Information may be disclosed where reasonably necessary to:
subject to appropriate confidentiality obligations.
ENLIGHTEN may disclose information when reasonably necessary to:
Information may be disclosed or transferred in connection with:
subject to appropriate confidentiality and privacy protections.
ENLIGHTEN may engage subprocessors to provide portions of the Services.
Where ENLIGHTEN acts as a processor, service provider, or contractor on behalf of Customer, use of subprocessors will be governed by the applicable DPA or Contract Documents.
ENLIGHTEN may maintain an updated list of subprocessors through:
ENSPACE is a global technology platform and may use infrastructure, Affiliates, service providers, and subprocessors located in different countries.
As a result, Personal Information may be processed outside the country in which Customer or User is located.
Where required by applicable law, ENLIGHTEN will use appropriate mechanisms for international data transfers, which may include:
ENLIGHTEN retains Personal Information and Customer Content for periods reasonably necessary for the applicable processing purposes, taking into account:
Following termination of Customer’s Subscription, export, retention, and deletion of Customer Content will be handled in accordance with the applicable Contract Documents.
Deletion from active systems may not immediately remove all information from backups, security records, or business continuity systems.
Residual copies will remain protected and will be deleted or overwritten according to applicable retention cycles unless retention is legally required.
ENLIGHTEN maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized:
No technological system can eliminate all security risks.
Where a security incident affects Personal Information or Customer Content, ENLIGHTEN will respond in accordance with applicable law and applicable Contract Documents.
Authorized ENLIGHTEN personnel may access Customer Content where reasonably necessary to:
ENLIGHTEN seeks to limit human access to Customer Content to personnel and circumstances reasonably necessary for the applicable purpose.
ENLIGHTEN may generate statistics, metrics, telemetry, and aggregated or de-identified information relating to use of ENSPACE.
Such information may be used for:
ENLIGHTEN will take reasonable measures designed to prevent such information from reasonably identifying Customer or an individual when used outside the provision of Services to Customer.
Where required by applicable law, ENLIGHTEN will not attempt to re-identify information that has been maintained as de-identified, except where legally permitted for testing or verifying de-identification processes.
ENLIGHTEN does not use Customer documents, contracts, playbooks, prompts, tasks, or similar Customer Content for cross-context behavioral advertising or behavioral advertising targeted based on the contents of Customer Content.
Business contact information may be used to communicate regarding ENLIGHTEN products, services, events, or commercial activities where permitted by applicable law.
Recipients may opt out of marketing communications through available unsubscribe mechanisms.
Administrative, transactional, security, and service communications are not treated as marketing communications.
ENSPACE is primarily intended for enterprise and professional use.
Where an individual accesses ENSPACE through an organization, that organization may be able to:
ENLIGHTEN does not control the internal privacy, employment, compliance, or information-management policies adopted by its customers.
Requests concerning Personal Information processed by ENLIGHTEN solely on behalf of a customer may need to be directed to that Customer.
Depending on the jurisdiction and applicable law, individuals may have rights concerning their Personal Information.
Such rights may include:
Available rights and conditions for exercising them depend on the applicable law and ENLIGHTEN’s role in the relevant processing activity.
Where ENLIGHTEN processes Personal Information on behalf of Customer, Customer will generally be responsible for responding to privacy requests relating to that information.
If an individual submits a request directly to ENLIGHTEN concerning information processed exclusively on behalf of Customer, ENLIGHTEN may:
Privacy requests, questions, or requests to exercise rights may be submitted to: dpo@be-enlighten.com
ENLIGHTEN may request information reasonably necessary to:
Requests will be handled within the periods required by applicable law.
Where permitted, ENLIGHTEN may deny or limit requests where an applicable exception applies.
Where Brazil’s Law No. 13,709/2018, the Lei Geral de Proteção de Dados Pessoais (“LGPD”), applies, the terms controlador, operador, titular, dados pessoais, dados pessoais sensíveis, and tratamento will have the meanings provided by the LGPD.
ENLIGHTEN will comply with applicable LGPD principles and obligations according to its role in the relevant processing activity.
Where ENLIGHTEN acts as controller, applicable processing may rely on the legal bases permitted under the LGPD.
Where ENLIGHTEN acts as processor on behalf of Customer, Customer will generally determine the purposes and legal basis of the processing and ENLIGHTEN will process Personal Information subject to Customer instructions and applicable Contract Documents.
Data subjects may exercise applicable LGPD rights through the channels identified in this Policy.
Where the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR (“UK GDPR”), or similar legislation applies, ENLIGHTEN will process Personal Information on an appropriate legal basis.
Depending on the applicable circumstances, individuals may have rights including:
provided such interests are not overridden by applicable individual rights and interests.
Where required for international transfers, ENLIGHTEN may rely on recognized transfer mechanisms, including Standard Contractual Clauses and applicable supplementary safeguards.
Residents of certain U.S. states may have additional rights under applicable state privacy laws.
Depending on the applicable state and ENLIGHTEN’s legal role, rights may include the right to:
The availability and scope of rights depend on the state law applicable to the individual and ENLIGHTEN.
ENLIGHTEN does not sell Customer Content.
ENLIGHTEN does not sell or share Personal Information contained in Customer Content for cross-context behavioral advertising.
Where ENLIGHTEN acts solely as a processor, service provider, or contractor for a Customer, privacy requests concerning Customer Content should generally be directed to the applicable Customer.
Where applicable state law provides a right to appeal ENLIGHTEN’s refusal to take action on a privacy request, the requester may submit an appeal by contacting: dpo@be-enlighten.com
The request should identify the original request and explain the basis for the appeal.
ENLIGHTEN will respond within the period required by applicable law.
Where permitted by applicable law, an individual may designate an authorized agent to submit a privacy request on the individual’s behalf.
ENLIGHTEN may require:
except where applicable law provides otherwise.
This Section supplements the remainder of this Privacy Policy and applies to California residents to the extent ENLIGHTEN is subject to the California Consumer Privacy Act, as amended (“CCPA”), in connection with the relevant processing.
Depending on an individual’s interaction with ENLIGHTEN, ENLIGHTEN may collect the following categories of Personal Information described under California law:
Identifiers, such as:
Customer Records Information, such as:
Commercial Information, such as:
Internet or Other Electronic Network Activity, such as:
Professional or Employment-Related Information, such as:
Audio, Electronic, Visual, or Similar Information, where voluntarily provided through:
Inferences, where generated from business or Platform usage information for purposes such as:
Sensitive Personal Information, where processed in applicable circumstances.
Customer Content may contain additional categories of Personal Information depending on the information submitted by Customer.
Where ENLIGHTEN processes Customer Content solely as a service provider or contractor, Customer is responsible for determining the categories of information processed through its ENSPACE environment.
ENLIGHTEN may obtain Personal Information from:
ENLIGHTEN may collect, use, and disclose Personal Information for purposes including:
Depending on the applicable processing, Personal Information may be disclosed to categories of recipients including:
ENLIGHTEN does not sell Customer Content.
ENLIGHTEN does not sell or share Personal Information contained in Customer Content for cross-context behavioral advertising.
ENLIGHTEN does not use Customer Content for behavioral advertising based on the contents of Customer documents, contracts, playbooks, prompts, tasks, or similar information.
ENLIGHTEN’s practices concerning website cookies, analytics technologies, or advertising technologies may depend on the technologies deployed on the applicable website.
Where ENLIGHTEN engages in activity that constitutes a “sale” or “sharing” of Personal Information under the CCPA, ENLIGHTEN will provide the notices, opt-out mechanisms, and privacy choices required by applicable law.
ENLIGHTEN may process Sensitive Personal Information where:
Where ENLIGHTEN acts as a service provider or contractor for Customer, Sensitive Personal Information contained in Customer Content is processed on Customer’s behalf.
Where applicable law grants a right to limit certain uses or disclosures of Sensitive Personal Information and ENLIGHTEN engages in such processing, ENLIGHTEN will provide an applicable mechanism for exercising that right.
Subject to applicable exceptions and verification requirements, California residents may have the right to:
ENLIGHTEN may provide Customers with AI, automation, workflow, and AI Agent functionality.
ENLIGHTEN does not independently use Customer Content for its own purposes to make decisions concerning individuals that produce legal or similarly significant effects.
Customers may configure ENSPACE functionality for their own decision-making processes.
To the extent California law provides applicable rights relating to ENLIGHTEN’s own use of automated decisionmaking technology, ENLIGHTEN will provide notices and mechanisms required by applicable law.
California residents may use an authorized agent to submit certain requests.
ENLIGHTEN may require verification of:
as permitted by California law.
ENLIGHTEN will not unlawfully discriminate against an individual for exercising rights under the CCPA.
ENLIGHTEN retains categories of Personal Information for periods reasonably necessary and proportionate to the purposes for which they were collected or processed, taking into account:
California privacy requests may be submitted through: dpo@be-enlighten.com
Where required by applicable law, ENLIGHTEN may provide additional request methods or privacy-choice mechanisms.
Customers may use ENSPACE in business activities involving confidential information or categories of data subject to heightened legal requirements.
Customer is responsible for determining whether it has appropriate authority, legal basis, notices, consents, and safeguards to submit or process such information through ENSPACE.
Where ENLIGHTEN acts as a processor, service provider, or contractor, ENLIGHTEN processes such information subject to:
Additional requirements concerning particular categories of information may be established by separate agreement.
ENSPACE is an enterprise software platform intended primarily for professional and business use.
ENLIGHTEN does not knowingly direct ENSPACE to children for purposes of creating independent consumer accounts.
If ENLIGHTEN becomes aware that Personal Information relating to a minor has been processed in circumstances inconsistent with applicable law or the intended use of the Services, ENLIGHTEN may take appropriate steps to restrict, delete, or otherwise address the processing.
This Section does not prohibit a Customer from processing information relating to minors where the Customer has lawful authority to do so and the processing is consistent with the Contract Documents.
ENSPACE may provide links or connections to third-party websites, products, and services.
ENLIGHTEN is not responsible for independent privacy practices of third-party services.
Users should review applicable third-party privacy policies before independently submitting information to such providers.
If ENLIGHTEN participates in:
information relating to the Services may be disclosed or transferred as part of the transaction.
ENLIGHTEN will apply appropriate confidentiality and privacy protections to such information as required by applicable law.
Where ENLIGHTEN and Customer have entered into a DPA, that DPA supplements this Privacy Policy with respect to Personal Information processed by ENLIGHTEN on Customer’s behalf.
In the event of a conflict concerning ENLIGHTEN’s obligations as a processor, service provider, or contractor with respect to Customer Personal Information, the applicable DPA will control to the extent specified in that DPA.
ENLIGHTEN may update this Privacy Policy periodically to reflect:
The current version will identify the date of its most recent update.
Where a change materially affects ENLIGHTEN’s privacy practices, ENLIGHTEN may provide additional notice through:
This Privacy Policy may be made available in different languages.
Where applicable Contract Documents specify a controlling language, that provision will apply in the event of an inconsistency between translated versions.
Questions, requests, or complaints concerning this Privacy Policy, privacy, or data protection may be directed to ENLIGHTEN’s privacy contact at: dpo@be-enlighten.com
Where a request relates to Personal Information processed by ENLIGHTEN on behalf of a Customer organization, the individual may need to direct the request to the applicable Customer or Account Administrator.
ENLIGHTEN seeks to develop and operate ENSPACE according to principles of privacy, security, transparency, accountability, and appropriate Customer control consistent with the enterprise nature of the Services.
Our objective is to enable organizations to use technology, automation, and artificial intelligence responsibly while protecting ownership, confidentiality, integrity, and privacy of information processed through the Platform.

