Last updated: 2026-07-21 (working draft) Effective date: To be set at commercial launch
1. Introduction
1.1 This Privacy Policy explains how Podiyem, Inc. ("Podiyem", "we", "us") collects, uses, discloses, and protects personal data in connection with the Podiyem platform (the "Service").
1.2 Our two roles. Depending on the data:
- We act as a controller for personal data of our account holders and Authorised Users (for example, registration and billing data, and data we use to run and secure the Service).
- We act as a processor (service provider) for the personal data that our customers upload or generate within their Workspaces and for the analytics we collect on their behalf about Viewers of their Public Share Links. For that data, the customer is the controller, and our processing is governed by this Policy and, where applicable, a Data Processing Agreement ("DPA").
1.3 If you are a Viewer/Prospect who opened a public presentation link, please note that the organisation that sent you the link is the controller of your personal data; we process it on their behalf. Contact them, or us at [email protected], for questions.
2. Personal Data We Collect
2.1 Account and profile data (we are controller)
- Name (first and last), email address.
- Password, stored only as a salted hash — we never store your password in plain text.
- Account role and Workspace membership.
- Email-verification status and tokens; password-reset tokens.
- Last login time and authentication/session tokens (stored as hashes where applicable).
2.2 Workspace / Company data (customer is controller; we process)
- Company name, branding (logos, colours, fonts), address, email, phone, website.
- Subscription plan, billing cycle, and trial status.
- Billing/transaction data. Full payment card details are never collected or stored by Podiyem. Payment is handled directly by our payment provider, Paddle, which acts as the Merchant of Record for your purchase. Paddle collects billing details (such as name, billing address, email, and payment method) and processes them under its own privacy policy, as an independent controller for the payment transaction, fraud prevention, and tax-compliance purposes. See https://www.paddle.com/legal/privacy.
2.3 Customer Content (customer is controller; we process)
- Projects / case studies, which may include client names, sectors, countries, regions, dates, contract values and currencies, narratives, milestones, and images. This content may contain third-party personal data and confidential commercial information provided by the customer.
- Pitches / presentations, including prospect names ("prepared for"), intro text, and curated selections of Projects.
- Uploaded files (images, logos), stored with server-generated file names and associated metadata (original name, MIME type, size).
2.4 Public presentation analytics — Viewer/Prospect data (customer is controller; we process)
- When a Viewer opens a Public Share Link, the Service records view events: the time of the view and a browser-generated session identifier stored on the Viewer's device. This identifier is not, by itself, linked by the Service to a named individual or a login; it is used to distinguish repeat visits and distinct Viewers for engagement analytics shown to the customer.
- Standard server logs may also capture technical data such as IP address, user agent, and request metadata.
2.5 Usage, device, and technical data (we are controller for operating the Service)
- Log data, error and diagnostic data, and technical identifiers generated when you use the Service, including via our error-monitoring provider.
2.6 Communications data
- Records of your communications with us (support requests, emails).
We do not intentionally collect special-category / sensitive personal data, and the Service is not intended for storing it.
3. How and Why We Use Personal Data, and Legal Bases
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Create and manage Accounts and Workspaces; authenticate users | Account/profile data | Performance of a contract |
| Provide core Service features (Projects, Pitches, publishing, branding) | Workspace data, Customer Content | Contract; for customer-controlled data, the customer's chosen basis |
| Send transactional emails (verification, reset, invites, security, billing) | Email, name | Contract; legal obligation |
| Provide engagement analytics for Public Share Links | Viewer session id, view times | Processed on behalf of the customer; the customer must establish the basis/consent |
| Secure the Service; prevent fraud/abuse; rate-limiting | Technical/usage data, IP | Legitimate interests (security) / legal obligation |
| Error monitoring and debugging | Diagnostic/technical data | Legitimate interests (reliability) |
| Billing and payments | Billing records | Contract; legal obligation |
| Marketing communications (if any) | Contact data, preferences | Consent, or legitimate interests where permitted |
| Comply with legal obligations; establish/defend legal claims | As relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object as described in Section 9.
4. Sub-processors and Third-Party Providers
We use other companies to help us operate the Service. In keeping with data- minimisation practice, we describe them below by category and purpose rather than publishing our full internal infrastructure list. A current list of named sub-processors, including processing locations, is available on request at [email protected] and is included in our Data Processing Agreement for business customers.
| Category | Purpose |
|---|---|
| Payment provider (Merchant of Record) | Paddle bills and collects payment for subscriptions, handles refunds/disputes, and determines/remits applicable transaction taxes. Named specifically because it will appear as the merchant on your card or bank statement. |
| Cloud object storage provider | Stores uploaded images and logos |
| Transactional email provider | Sends verification, password-reset, invite, and notification emails |
| Error monitoring / diagnostics provider | Captures errors and technical diagnostics to keep the Service reliable |
| Application hosting provider(s) | Runs and serves the Service (web app and API) |
| Database hosting provider | Stores application data |
| Marketing-site analytics provider | Aggregate, non-account usage analytics for our public marketing website only |
4.1 We enter into data-processing terms with sub-processors as required by law. We remain responsible for their processing of personal data on our behalf, except where a provider (such as Paddle, for the payment transaction) acts as an independent controller as described in Section 2.2.
4.2 We do not sell personal data. We do not "share" personal data for cross-context behavioural advertising as defined under US state privacy laws.
4.3 Changes to sub-processors. We will update the sub-processor list made available on request when we add or replace a sub-processor, and will notify business customers under a Data Processing Agreement as required by its terms.
5. Cookies and Similar Technologies
5.1 Application. The Service uses cookies and/or browser storage that are strictly necessary to authenticate you and keep you signed in (for example, session/refresh tokens).
5.2 Public presentation links. When a Viewer opens a Public Share Link, a browser-stored session identifier is used to power engagement analytics for the customer (see 2.4). Depending on configuration and jurisdiction, this may require a notice and/or consent to the Viewer.
5.3 Marketing site. The marketing website may use analytics to understand aggregate usage of this site.
6. Disclosure of Personal Data
We may disclose personal data:
- to sub-processors and service providers (Section 4), under contract;
- to a customer's Authorised Users, within their Workspace, according to configured roles/permissions;
- to Viewers of Public Share Links, limited to the content the customer chooses to publish;
- in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and continuity of this Policy;
- to comply with law, legal process, or lawful requests, and to protect rights, safety, and security; and
- with your consent or at your direction.
7. International Data Transfers
7.1 We and our sub-processors may process personal data in countries other than your own, including the United States, where several of our service providers are based. These countries may have different data-protection laws.
7.2 Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or another lawful transfer mechanism. You may request more information at [email protected].
8. Data Retention
8.1 We retain personal data for as long as needed to provide the Service and for the purposes described, then delete or anonymise it, unless a longer period is required by law or to establish/defend legal claims.
8.2 Soft deletion and backups. The Service uses "soft deletion" for many records (a record is marked deleted and hidden before permanent removal) and file deletions remove the stored object while retaining a deletion record. Deleted data may persist in backups for a limited period before being overwritten.
8.3 Indicative retention periods:
- Account data: for the life of the Account, then deleted within 30 days of Account closure, subject to legal-hold and billing-record requirements.
- Customer Content: deleted within 30 days of Workspace termination or on customer request, subject to the DPA.
- Public presentation view events: retained for up to 12 months for analytics purposes.
- Server/error logs: retained for up to 90 days.
- Billing records: retained for 7 years, as required by applicable tax/accounting law.
9. Your Rights
9.1 Depending on your location, you may have rights to: access; rectify; erase; restrict or object to processing; data portability; withdraw consent; and lodge a complaint with a supervisory authority. Under EU GDPR / UK GDPR, these rights apply as described in those laws.
9.2 US state privacy rights (e.g. California CCPA/CPRA, and similar laws). If you are a resident of a US state with a comprehensive privacy law, you may have rights to know, access, correct, delete, and opt out of "sale"/"sharing" and certain profiling, and a right against discrimination for exercising these rights. As noted, we do not sell personal data.
9.3 How to exercise. Account holders can access and update much of their data in the Service. For other requests, contact [email protected]. We will verify your identity and respond within the timeframe required by law.
9.4 Customer-controlled data. If your personal data is within a customer's Workspace (for example, you are a client named in a Project, or a Viewer of a Public Share Link), the customer is the controller. We will refer your request to the relevant customer and assist them as required by law and the DPA.
9.5 Data deletion requests. You may request deletion of your personal data as described above. Some data may be retained where permitted or required (Section 8).
10. Security
10.1 We implement technical and organisational measures appropriate to the risk, including: passwords stored only as salted hashes; token-based authentication with session/refresh-token handling; transport encryption (HTTPS); HTTP security headers; rate limiting; input validation; access controls; and error monitoring.
10.2 No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you are responsible for safeguarding your credentials and for the content you choose to publish.
10.3 Breach notification. In the event of a personal-data breach, we will notify affected parties and authorities as required by applicable law and any DPA.
11. Children's Privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. If we learn we have collected such data without appropriate consent, we will delete it.
12. Marketing Communications
Where we send marketing communications, we do so in accordance with applicable law and, where required, with your consent. You can opt out at any time via the unsubscribe link or by contacting us. Opting out of marketing does not stop transactional/service messages.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice as required by law.
14. Contact and Complaints
Controller / Privacy contact: Podiyem, Inc. Registered business address to be added prior to launch. Email: [email protected]
- EU/UK representative: Not currently appointed — to be assessed based on EU/UK customer volume ahead of launch.
- Data Protection Officer: Not currently appointed.
- Supervisory authority: You may lodge a complaint with your local data-protection authority (in the UK, the ICO; in the EU, your national authority).