Privacy Policy
This Policy describes how Capsid Systems, LLC, a Georgia limited liability company doing business as Regulatory Impact collects, uses, discloses, and retains information through RegulatoryImpact.com and related services.
1. Information collected
We collect account and profile data such as name, email, organization, role, country, credentials, preferences, verification status, and marketing choices; billing and transaction data such as billing contact, invoice, tax, subscription, and Stripe customer identifiers; and technical data such as IP address, browser/device information, authentication events, pages/features used, search queries, error logs, and security events.
We process prompts, queries, saved projects, notes, uploaded files, annotations, support messages, and generated outputs that you choose to submit. Do not submit PHI, patient-level data, confidential regulatory submissions, trade secrets, or export-controlled material. We do not intentionally store full card numbers.
2. Purposes and providers
- Authentication and account administration: email, credentials, sessions, and security logs.
- Hosting and storage: accounts, workspaces, projects, and content needed to provide the Service.
- Billing: Stripe processes payment details and transaction identifiers; we receive customer, subscription, invoice, and payment status data.
- Analytics and security: first-party usage events, IP/device signals, fraud prevention, diagnostics, and performance data. Optional analytics are controlled by account preferences; we do not use session replay unless separately disclosed before activation.
- AI features: selected regulatory data-processing jobs may send the minimum necessary public or operational input to the configured provider. We do not send Customer Content to general-purpose model training and do not permit providers to do so.
- Email and support: contact details and the contents needed to respond to requests.
- Public sharing: content and metadata deliberately published or shared may be available to link recipients or the public until revoked, expired, or deleted.
We may use deidentified or aggregated information for security, measurement, and product improvement. We do not sell personal information or use it for targeted advertising under this Policy.
3. Cookies and choices
Strictly necessary cookies and local storage support authentication, security, preferences, and the Service. Optional analytics or advertising technologies will not be activated without the notices and controls required by applicable law. You may disable cookies in your browser, though some features may stop working. Contact us for access, correction, deletion, portability, or privacy-choice requests.
4. Sharing and retention
We share information with hosting, database, storage, payment, email, security, monitoring, analytics, and AI subprocessors only as needed for the disclosed purposes and under contractual restrictions. We may disclose information for legal process, safety, fraud prevention, corporate transactions, or with your direction.
We retain account and subscription records while the account is active and as needed for legal, accounting, fraud-prevention, dispute, and backup purposes. Workspace content is deleted according to account deletion and backup cycles, subject to enterprise terms. Public or link-shared content remains available until the publisher revokes, expires, unpublishes, or deletes it; copies made by recipients may remain.
5. Security and sensitive data
We use reasonable administrative, technical, and organizational safeguards, access controls, logging, and vendor controls. No system is completely secure. Notify support@regulatoryimpact.com of suspected incidents. The standard Service is not HIPAA-compliant, we do not provide a BAA, and we do not authorize PHI or directly identifiable patient data.
6. US scope, international processing, and children
The Service is initially offered for US business use. Information may be processed in the United States by our service providers. We do not intentionally offer the Service to children; eligibility is limited to people 18 or older, and we do not knowingly collect information from anyone under 18.
7. Changes and contact
We will post changes with a new version date and provide additional notice for material changes. If a material change expands Customer Content or AI processing, we will obtain renewed consent where appropriate.