Eyeclone Privacy Policy
Last Updated: May 1, 2026
About Eyeclone
Eyeclone LLC (“Eyeclone”, “we” or “us”) operates a cloud-based financial intelligence platform (“Platform”) designed to assist businesses and advisors in accessing, analyzing, and interpreting financial and operational data.
The Platform uses software automation and artificial intelligence to organize financial information, generate analytical insights, produce reports and dashboards, and support business decision-making. It is offered exclusively to business customers and is not intended for personal, family, or household use.
The Platform is designed to provide informational tools and analytical support. It does not provide accounting, tax, legal, or investment advice, and users are responsible for independently evaluating any outputs before making business or financial decisions.
WE DO NOT AND WILL NOT SELL YOUR PERSONAL INFORMATION.
Introduction to Our Privacy Policy
Eyeclone’s products, services and websites can be accessed by users across various locations including in jurisdictions which have specific privacy requirements.
Your privacy is important to us. This Privacy Policy (“Privacy Policy”) describes how we collect, use, protect, share, and transfer your information that we collect when you use the Platform, our website, other offerings or otherwise interact with us (“Services”). This Policy also includes jurisdiction-specific disclosures for individuals in California (CCPA/CPRA), Canada (PIPEDA and Quebec Law 25), South Africa (POPIA), and Australia (Privacy Act 1988 and the Australian Privacy Principles). See the Regional Privacy Disclosures section for details. It does not modify the terms of your Subscription Agreement or any other agreement with Eyeclone.
By accessing the Services, you acknowledge that you have read and understood this Policy. If you do not agree with the practices described here, please do not use the Services. We will notify you of material changes by posting an updated version at https://eyeclone.io/privacy-policy/ and, where appropriate, by email. We encourage you to review this Policy periodically. Continued use of the Services after an update is published does not constitute consent to any data processing; all processing remains subject to the lawful bases described in this Policy. Where a material change to this Policy involves a new purpose for processing personal data, a new category of personal data, or a new third-party recipient that requires consent as a lawful basis under applicable law, Eyeclone will seek affirmative consent from affected individuals prior to commencing such processing, and will not rely on continued use of the Services as a substitute for that consent.
“Personal data” and “personal information” are used interchangeably throughout this Policy and refer to any information that identifies or is reasonably capable of identifying an individual, either alone or in combination with other information. Where applicable law provides a specific definition (including under the CCPA/CPRA, PIPEDA, POPIA, or the Australian Privacy Act), that definition applies to processing subject to that law.
Personal data can include information such as: your name, email address and username; information about your device (e.g., IP address); and information relating to how you use and interact with our site, apps and services.
We process personal information in two legally distinct roles:
As a Data Controller: when we collect and process personal information from visitors to our website, individuals who submit contact or demo request forms, and business contacts of prospective or current customers. In this role, Eyeclone determines the purposes and means of processing.
As a Data Processor: when Customers subscribe to the Platform and upload, input, or integrate data that may contain personal information. In this role the subscribing Customer is the data controller and Eyeclone processes that data solely on the Customer’s instructions, pursuant to the applicable Subscription Agreement and any associated data processing addendum.
This Policy primarily applies to Eyeclone’s activities as a Data Controller. If you interact with us through the Platform, we will only process certain information as described in the Terms of Service (“Subscription Agreement”) with the subscribing organization (“Customer”) governing that subscription. In the event of a conflict between this Privacy Policy and the Subscription Agreement, the Subscription Agreement will control.
Eyeclone’s products and services are designed exclusively for business use and are not intended for personal, family, or household purposes.
If you have any questions about this Privacy Policy or the way in which we use your personal data, please contact us at privacy@eyeclone.io.
What Information Do We Collect?
We collect all information that you provide, information you provide via the Services, your devices (e.g., computers, smartphones, and tablets), telephone, and email as well as information we receive from partners. We also use cookies and other such technologies to collect information about you and how you engage with the Services.
Information you provide directly
When you interact with our website or contact us we may collect:
- Business contact details: name, work email address, phone number, job title, and company name. These are usually submitted via contact forms, demo requests, or direct correspondence.
- Inquiry and communication content: the content of questions, messages, or feedback you send us.
- Subscription and billing information: billing name, business address, and payment method details. Payment card and bank account details are handled by Stripe. Eyeclone does not store full payment card numbers.
Information collected automatically
When you visit our website, we and our service providers may automatically collect:
- Usage and device data: IP address, browser type, operating system, referring URLs, pages visited, and session duration.
- Cookie and tracking data: as described in the Cookies and Tracking Technologies section below.
Customer Platform data
Customers may upload, integrate, or input data into the Platform that contains personal information relating to their employees, end-clients, or other individuals. Eyeclone processes that data as a data processor acting solely on the Customer’s instructions under the applicable Subscription Agreement. The categories of personal information processed within the Platform depend entirely on what the Customer submits. Eyeclone does not control or direct Customer data collection practices.
Third-Party Integrations
Where a Customer connects a third-party accounting or financial platform, (i.e. QuickBooks, operated by Intuit Inc.) to the Platform, Eyeclone accesses data from that platform through an authorized API connection using OAuth 2.0. The categories of data accessed depend on the scopes authorized by the Customer at the time of connection. Eyeclone requests only the minimum permission scopes necessary to deliver the connected features. Data retrieved through such integrations is treated as customer data under the applicable Subscription Agreement.
Payment processing is handled by Stripe, Inc. When you provide payment information, Stripe collects and processes your name, email address, billing address, payment card or bank account details, IP address, and device information directly. Stripe may also collect behavioral and transactional data across its payment network for fraud prevention and security purposes. Eyeclone does not store full payment card numbers or bank account numbers. Stripe’s collection and use of your data is governed by Stripe’s Privacy Policy, available at stripe.com/privacy.
Non-identifiable operational data
Eyeclone may generate and retain aggregated or de-identified data derived from Platform activity. Where data is de-identified or anonymized, Eyeclone implements appropriate technical and organizational measures to prevent re-identification and does not attempt to re-identify such data. Eyeclone does not treat properly anonymized or de-identified data as personal information. Where applicable law imposes specific requirements on de-identified data (including under CCPA/CPRA), Eyeclone will comply with those requirements.
How We Use Your Information
Eyeclone processes personal information on one or more of the following lawful bases: performance of a contract, compliance with legal obligations, legitimate interests, or consent (where applicable). The specific basis applicable to each category of processing is described below.
In our capacity as a data controller, Eyeclone uses personal information for the following purposes:
- To provide and operate the Platform, including processing subscriptions, managing accounts, and delivering core functionality.
- To optimize and improve the Services based on the information and feedback we receive from you and our other users, including by optimizing the content on or functionalities of the Services.
- To personalize the user experience and measure engagement with and interaction with the Services.
- To improve customer service and more effectively develop the Services and respond to your support needs.
- To respond to website inquiries, contact requests, and product demonstration requests.
- To process payments and manage billing in coordination with Stripe.
- To manage and authenticate user accounts, including Single Sign-On (SSO) support.
- To communicate with customers and authorized users about service updates, account matters, and support issues.
- To send transactional communications such as billing confirmations, service notifications, and policy updates.
- To detect, investigate, and prevent fraud, security incidents, and violations of our Subscription Agreement or other policies.
- To maintain and improve the security, integrity, and performance of the Platform and infrastructure.
- To generate and use aggregated, anonymized operational data for internal analytics and product improvement.
- To comply with legal obligations, respond to lawful governmental requests, and protect our legal rights.
Eyeclone does not use personal information from Platform users for any purpose beyond providing the Platform and related services and does not use such information for advertising or marketing to third parties.
Our legal grounds for using your personal data
Eyeclone will only use your personal data when the law allows us to. The legal grounds we rely on are:
- Performance of contract: where processing is necessary to provide the Platform and services you have subscribed to.
- Legitimate interests: where we have a legitimate business interest, such as improving our Platform, detecting fraud, and maintaining security, and that interest is not overridden by your rights.
- Legal obligation: where we are required by law to process your data.
- Consent: where you have given explicit consent for a specific purpose. For Eyeclone, this applies narrowly to marketing communications. You may withdraw consent at any time by following the unsubscribe instructions in any marketing communication or by contacting privacy@eyeclone.io. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not affect processing carried out on any other lawful basis.
Who Do We Share Your Information With?
We share your information with our partners, service providers, contractors, agents, and third-party vendors as needed to provide the Services.
Third-party vendors who provide products, services or functions on our behalf may include business analytics companies, communications service vendors, marketing vendors, and security vendors. We may also authorize third-party vendors to collect information on our behalf, including as necessary to operate features of the Services or serve content. Third-party vendors have access to and may collect personal information only as needed to perform their functions, may only use personal information consistent with this Privacy Policy and other appropriate confidentiality and security measures, and are not permitted to share or use the information for any other purpose.
Eyeclone does not sell personal information. We may share personal information only in the following circumstances:
Service providers and sub-processors
Eyeclone engages third-party vendors that act as sub-processors or service providers. These vendors are authorized to access personal information only as necessary to perform services on Eyeclone’s behalf, subject to confidentiality and security obligations.
Service providers include:
- Stripe: payment processing, billing management, and fraud detection. Stripe acts as an independent data controller with respect to data it collects directly from customers during checkout and for its fraud prevention network. Stripe stores tokenized payment credentials on Eyeclone’s behalf to facilitate recurring subscription billing for the duration of the Customer’s subscription.
- Microsoft Azure: cloud hosting and infrastructure provider.
- Anthropic: AI model provider powering content generation, data analysis, predictive modelling, and conversational features.
- Open AI: AI model provider powering content generation, data analysis, predictive modelling, and conversational features.
- Postmark: transactional email delivery service used to send billing confirmations, service notifications, account communications, and policy updates.
Eyeclone maintains an up-to-date list of sub-processors engaged to process personal information on its behalf. Customers may request the current sub-processor list by contacting privacy@eyeclone.io. Eyeclone will provide reasonable advance notice of material changes to its sub-processor list.
Third-Party Accounting Platforms and Integrated Services
The Platform is designed to integrate with third-party accounting platforms and other external services that you have independently selected and contracted for, including QuickBooks Online (provided by Intuit Inc.) and, when generally available, Xero (provided by Xero Limited) (each, an “Integrated Service”). When you authorize Eyeclone to connect to your account on an Integrated Service, you are granting Eyeclone limited access, typically through OAuth 2.0, to read data from that account in order to provide the Platform’s features and analytics. Our access to QuickBooks Online is read-only.
The provider of each Integrated Service (such as Intuit for QuickBooks Online or Xero Limited for Xero) is an independent controller of the data held in your account on that service. Eyeclone does not select, engage, or contract with these providers on your behalf, and we do not act as a sub-processor for, or on behalf of, these providers. The collection, use, storage, security, and other processing of your data by an Integrated Service provider is governed by that provider’s own terms of service and privacy policy, which are independent of this Privacy Policy and over which Eyeclone has no control. Eyeclone is not responsible for the data practices, security, availability, or compliance posture of any Integrated Service provider.
When Eyeclone receives data from an Integrated Service through your authorized connection, that data becomes Customer Data under your subscription agreement and is handled by Eyeclone in accordance with this Privacy Policy and the Data Processing Addendum located at https://eyeclone.io/data-processing-agreement. Eyeclone’s processing of such data is limited to the purposes described in this Privacy Policy and the scope of access you have authorized.
You may revoke Eyeclone’s access to any Integrated Service at any time through that service’s account settings or connection management features. Revoking access will not delete data that Eyeclone has already received and stored prior to revocation.
Customer access
Eyeclone provides the Platform to the Customer. Authorized users within the Customer’s organization may access data within the Platform according to permissions the Customer configures. The Customer is solely responsible for managing user access, including access granted to third-party advisors, consultants, or non-employee personnel.
Channel and distribution partners
Eyeclone may make the Platform available through authorized channel or distribution partners. Where a Customer subscribes to the Platform through an authorized channel or distribution partner, that partner may receive Customer contact information (including name, business email, and company name) and transaction information (including subscription tier and billing status) solely to manage the commercial and support relationship. Channel partners are not authorized to use this information for any other purpose and are contractually required to handle it in accordance with applicable data protection law. Channel partners do not receive access to the Customer’s Platform data or the personal information of the Customer’s end-users.
Legal obligations and protection of rights
Eyeclone may disclose personal information to government or law enforcement authorities where required by applicable law, in response to valid legal process, or where Eyeclone reasonably believes disclosure is necessary to investigate, prevent, or take action regarding illegal or suspected illegal activities; protect the rights, property, or safety of Eyeclone, its customers, or others; or in connection with a Subscription Agreement.
Business transfers
In connection with a corporate transaction, such as a divestiture, merger, acquisition, restructuring, or sale of assets, personal information held by Eyeclone may be transferred as part of that transaction. Where a corporate transaction results in a change of the entity that controls your personal information, Eyeclone will, to the extent required by applicable law, notify affected individuals and provide information about any material changes to how their personal information is processed. Any successor entity will be required to handle your personal information in a manner consistent with applicable law and this Policy, or to provide you with a new privacy notice prior to any material change in data practices.
Eyeclone will not share personal information with third parties in ways materially different from those described in this Policy without providing you with prior notice and, where required by applicable law, obtaining your consent.
Tracking Technologies and Cookies
We may use cookies, heat mapping, log files, and similar tracking technologies, including those from third-party service providers such as Google Analytics, Google Tag Manager, HubSpot, and other cloud-based tools, to automatically collect preferences, performance data, and information about your web usage when you visit the Services. We may also collect information about your online activity, such as pages viewed and interactions with certain parts of the Services. By collecting and using this information, we may operate and personalize the Services for you.
Where advertising or lead-intelligence tools (such as Google Ads or 6Sense) are used on our website, they are activated only upon your consent (where required by applicable law) and are disclosed in our cookie consent tool. California residents who wish to opt out of any sharing of their personal information for cross-context behavioral advertising purposes may do so by activating the Global Privacy Control (GPC) signal in their browser, which Eyeclone will honor as a valid opt-out request under the CPRA. You may also submit an opt-out request by contacting privacy@eyeclone.io.
The Services do not currently respond to browser-level “Do Not Track” (DNT) signals. California residents may use the Global Privacy Control (GPC) signal as described above to exercise their opt-out right under the CPRA.
You can control the information collected by such tracking technologies or be alerted when cookies are sent by adjusting the settings on your Internet browser or devices, but such adjustments may affect or disable certain functionality of the Services. You can learn more about targeted ads and your ability to opt out of receiving interest-based ads at optout.aboutads.info and www.networkadvertising.org/choices.
Cookies, also known as tracking cookies or browser cookies, and similar technologies such as web beacons, clear GIFs, pixel tags, and JavaScript (collectively, “Cookies”) are small pieces of data, usually text files, placed on a computer, tablet, phone, or similar device when you use that device to access the Services. We use the following types of Cookies:
- Strictly Necessary Cookies. Essential Cookies are necessary for providing you with the Services. These Cookies are required to make the Services available to you, so they cannot be disabled. They do not store personally identifiable information.
- Functional Cookies. Functional Cookies enable enhanced functionality and preferences, such as session settings and recognizing you when you return to our Services. These Cookies help us personalize our content for you, greet you by name, and remember your preferences.
- Performance/Analytical Cookies. Performance/Analytical Cookies allow Eyeclone to measure website performance and aggregate visitor behavior. They allow Eyeclone to understand how users use the Services. These Cookies accomplish this by collecting information about the number of users to the Services, what pages users view the most, and how long users view specific pages. You have the option to opt-out of Google’s use of Cookies by visiting the Google advertising opt-out page at http://www.google.com/privacy_ads.html or the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout/.
- Advertising/Marketing Cookies. Where advertising or lead-intelligence tools are activated with your consent, these Cookies enable interest-based advertising and website visitor analytics. They are only set after you have provided consent through our cookie consent tool, and you may withdraw consent at any time by updating your preferences through the consent tool on the website.
When you first visit the website, a cookie consent banner allows you to accept or decline non-essential cookies. You may update your preferences at any time through the consent tool on the website or by adjusting your browser settings.
Eyeclone’s cookie consent mechanism is implemented through a Consent Management Platform (“CMP”) Zoho Technologies. Non-essential cookies, including functional, performance/analytical, and advertising/marketing cookies , are technically blocked and not loaded until you have actively consented through the banner. Eyeclone applies a strict cookie consent posture as a matter of practice: non-essential cookies are technically blocked and not loaded until you have actively consented through the banner, regardless of your jurisdiction. All consent choices are timestamped and logged as evidence of valid, informed consent. A full list of cookies in use on the website, including each cookie’s name, provider, purpose, type (session or persistent), and maximum retention period, is available within the cookie settings panel on the website.
To find out more information about Cookies, including information about how to manage and delete Cookies generally, please visit http://www.allaboutcookies.org/.
Our Services may link to third-party websites and services. Eyeclone is not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
How Long Do We Retain Your Information?
Eyeclone retains personal information for as long as necessary to fulfil the purposes described in this Privacy Policy, to maintain the customer relationship, to satisfy legal obligations, and to resolve disputes, and for a commercially reasonable time thereafter for backup, archival, fraud prevention or detection or audit purposes or as permitted by applicable law. We will never retain your information for a period longer than permitted by law.
We determine the appropriate retention period for personal information based on the amount, nature, and sensitivity of the personal information being processed; the potential risk of harm from unauthorized use or disclosure of the personal information; whether we can achieve the purposes of the processing through other means; and applicable legal requirements.
After expiration of the applicable retention periods, your personal information will be deleted.
Customer Platform data
- Upon subscription termination, active customer data will be deleted from live production systems upon written request by the Customer.
- Data may persist in encrypted backup systems for up to 180 days following deletion from live systems, after which it is permanently deleted in accordance with Eyeclone’s backup rotation schedule. Eyeclone does not access or use backup data except to restore service continuity in the event of a critical system failure.
- Eyeclone does not retain customer platform data for any purpose beyond maintaining the subscription and complying with legal obligations.
Website and controller data
- Business contact and inquiry data is retained for as long as necessary to respond to the relevant inquiry and to maintain the ongoing business relationship, and for a period of three years thereafter. Where a prospective customer does not enter into a subscription, inquiry data is deleted or anonymized within twelve months of the last meaningful contact. Existing customers’ contact data is retained for the duration of the subscription and for three years following termination to satisfy legal and contractual obligations. Aggregated and anonymized data may be retained indefinitely.
Third-Party Retention
Payment method tokens stored by Stripe for recurring billing are retained for the duration of the active subscription and are subject to Stripe’s own data retention practices. Customers may update or remove stored payment methods through their account settings at any time.
Your Rights
Individuals whose personal information Eyeclone processes as a data controller may have rights under applicable law. Your rights include:
- Access: the right to request a copy of the personal information Eyeclone holds about you.
- Correction: the right to request correction of inaccurate or incomplete personal information.
- Erasure: the right to request deletion of your personal information, subject to applicable legal retention obligations.
- Restriction of processing: the right to request that we restrict processing in certain circumstances.
- Data portability: the right to receive your personal information in a structured, machine-readable format where applicable.
- Objection: the right to object to processing based on legitimate interests, or to processing for direct marketing purposes.
- Withdrawal of consent: where processing is based on consent, the right to withdraw at any time without affecting the lawfulness of prior processing.
- Right to Limit Use of Sensitive Personal Information (California): California residents have the right to direct Eyeclone to limit the use of sensitive personal information to what is necessary to perform the services requested. Eyeclone uses sensitive personal information (including payment data) solely for the purpose of payment processing and does not use it for any secondary purpose that would trigger this right. To submit a request, contact privacy@eyeclone.io.
Customers may disconnect any third-party integration at any time through their account settings, which will terminate Eyeclone’s ongoing access to data from that platform.
You can request to exercise these rights, and any other rights you may have, by contacting us as set forth in the Contact Us section below. You may request to exercise these rights by yourself or via an authorized agent who meets the agency requirements of applicable law. Eyeclone will respond to verifiable rights requests within the timeframe required by applicable law. For reference: CCPA/CPRA requests within 45 days (extendable to 90 days with notice); PIPEDA requests within 30 days (extendable with notice); and Australian Privacy Act requests within a reasonable time. Response timeframes for South African POPIA requests will comply with applicable regulatory guidance. Identity verification may be required before processing certain requests. We will not fulfil any request unless you have provided sufficient information for us to reasonably verify your identity and sufficient details necessary to help us handle the request.
Rights regarding customer Platform data
Where Eyeclone processes personal information as a data processor on behalf of a Customer, requests from individuals regarding that data (access, deletion, correction) should be directed to the Customer. The Customer is the data controller for Platform data. Eyeclone will assist Customers in fulfilling verified requests as required by the applicable Subscription Agreement.
Marketing communications
Where Eyeclone sends marketing or promotional communications, recipients may opt out at any time by following the unsubscribe instructions in the communication or by contacting privacy@eyeclone.io. Opting out of marketing does not affect transactional or service communications.
How We Store and Secure Your Information
Security measures
Personal information collected by Eyeclone may be stored and processed in the United States and in other countries where Eyeclone or its sub-processors operate, including through Microsoft Azure cloud infrastructure. Where personal information is transferred outside your country of residence, Eyeclone maintains appropriate safeguards as described in the International Data Transfers section of this Policy.
Eyeclone implements technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest using AES-256.
- Secure credential and token management using Azure Key Vault.
- OAuth 2.0 authentication using minimum required permission scopes.
- Per-tenant data isolation to prevent cross-customer data access.
- Tenant-level audit logging of system actions and access events.
- Real-time anomaly and error detection through application monitoring.
- Security controls aligned with SOC 2 Type II Trust Service Criteria. Eyeclone is pursuing SOC 2 Type II certification. Upon completion, relevant sections of the audit report will be made available to customers upon request under NDA.
The specific technical measures described above reflect current practice and may be updated as technology evolves. Eyeclone will maintain security standards consistent with or exceeding applicable industry benchmarks. No transmission or storage method is completely secure, and Eyeclone does not guarantee the absolute security of any information. Eyeclone complies with applicable data protection laws, including applicable security breach notification requirements.
Cloud infrastructure and data location
The Platform is hosted on Microsoft Azure cloud infrastructure. The Azure regions used to store and process Customer data may vary depending on the Customer’s geographic location and applicable data residency requirements. Details of the specific regions applicable to a Customer’s deployment, and the transfer mechanisms governing any cross-border processing, are set out in the applicable Data Processing Addendum. Customers may request a copy of the Data Processing Addendum by contacting privacy@eyeclone.io.
Sub-processor transfers
Where Eyeclone engages sub-processors that may access or store personal information, those sub-processors are required by contract to maintain appropriate data protection standards. Eyeclone maintains an up-to-date sub-processor list, available upon request.
International Data Transfers
Eyeclone is a U.S.-based company. Personal information we collect and process is stored and handled primarily in the United States. Eyeclone currently serves customers in the United States, Canada, South Africa, and Australia. Because customers in those jurisdictions provide personal information to Eyeclone, that information may be transferred to and processed in the United States and in other countries where Eyeclone or its sub-processors operate. Eyeclone maintains appropriate safeguards for all such transfers as described below.
Payment data processed through Stripe may be transferred to and stored in the United States and other jurisdictions in which Stripe operates, regardless of the Customer’s country of residence. Such transfers are subject to Stripe’s privacy and data transfer mechanisms.
Transfers of personal information from, Canada, South Africa, and Australia to the United States are conducted pursuant to the specific legal mechanisms described for each jurisdiction below.
Basis for transfers from each jurisdiction
United States: Personal information from U.S.-based individuals is processed domestically. No cross-border transfer mechanism is required.
Canada: Personal information from Canadian individuals is transferred to the United States. Eyeclone relies on contractual protections and legitimate business interests as the transfer basis, consistent with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. Sub-processors that access Canadian personal data are subject to contractual data protection obligations.
South Africa: Personal information from South African data subjects is transferred to the United States. Eyeclone relies on contractual protections as the transfer basis under the Protection of Personal Information Act, 2013 (POPIA). Transfers are conducted only where the recipient is subject to a law, binding corporate rules, or binding agreement providing comparable protection as required by POPIA Section 72. Where required, Eyeclone will enter into appropriate operator agreements with sub-processors.
Australia: Personal information from Australian individuals is transferred to the United States. Eyeclone handles such information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Eyeclone takes reasonable steps to ensure that overseas recipients handle Australian personal information consistently with the APPs. Eyeclone discloses to Australian individuals at or before the time of collection that their personal information may be transferred to and stored in the United States, and that recipients are contractually required to handle it consistently with the APPs.
Regional Privacy Disclosures
United States
California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). The following disclosures apply to California residents whose personal information Eyeclone processes as a data controller.
Categories of personal information collected: Eyeclone collects the following categories of personal information from California residents: identifiers (name, email address, IP address); commercial information (billing and transaction records); internet or network activity information (usage and device data, cookie data); and professional or employment-related information (job title, company name). Payment card numbers, bank account numbers, and routing numbers constitute sensitive personal information under the CPRA and are processed solely by Stripe for payment fulfilment. Eyeclone does not store this data.
Purposes of collection: The purposes for which each category is collected are described in the How We Use Your Information section of this Policy.
Categories of third parties with whom personal information is shared: Eyeclone shares personal information with the service providers and sub-processors identified in the Who Do We Share Your Information With section of this Policy, including Stripe, Microsoft Azure, Anthropic, Open AI, OpenCo LLC, and Postmark.
Sale or sharing of personal information: Eyeclone does not sell personal information. To the extent Eyeclone uses advertising or lead-intelligence cookies (such as Google Ads or 6Sense) on its website, such use may constitute “sharing” personal information for cross-context behavioral advertising under the CPRA. California residents may opt out of such sharing by activating the Global Privacy Control (GPC) signal in their browser or by contacting privacy@eyeclone.io.
Rights of California residents: In addition to the rights described in the Your Rights section of this Policy, California residents have the right to:
- Know the categories and specific pieces of personal information collected about them.
- Request deletion of their personal information, subject to legal exceptions.
- Request correction of inaccurate personal information.
- Opt out of the sale or sharing of their personal information.
- Limit the use and disclosure of sensitive personal information to what is necessary to perform the services requested.
- Not be discriminated against for exercising any of these rights. Eyeclone will not deny, charge different prices for, or provide a different level of service to any individual because they exercised a CCPA/CPRA right.
To submit a CCPA/CPRA request, contact privacy@eyeclone.io. Eyeclone will respond within 45 days, extendable to 90 days with notice.
Bank account numbers, routing numbers, and payment card information collected in connection with ACH or card payments constitute sensitive personal information under the CPRA. Eyeclone does not sell or share this information. Such data is processed solely by Stripe for payment fulfilment purposes.
Canada
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec’s Act respecting the protection of personal information in the private sector (Law 25). Eyeclone collects and uses Canadian personal information for the purposes described in this Policy.
In addition to the general rights described in the Your Rights section of this Policy, Quebec residents have the following rights under Law 25:
- The right to data portability in a structured technological format, including the right to have personal information communicated directly to another organization.
- The right to de-indexation of personal information made public through technological means where retention is no longer justified by the original collection purpose.
- The right to be informed of, and to request human review of, decisions made exclusively through automated processing, including profiling.
Eyeclone conducts Privacy Impact Assessments before communicating Quebec residents’ personal information outside Quebec as required by Law 25. Eyeclone has designated a Privacy Officer responsible for compliance with applicable Canadian privacy law. The Privacy Officer may be contacted at privacy@eyeclone.io.
Individuals may request access to or correction of their personal information by contacting privacy@eyeclone.io. If you are not satisfied with Eyeclone’s response to a privacy request or concern, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca. Quebec residents may also file complaints with the Commission d’accès à l’information du Québec at www.cai.gouv.qc.ca.
South Africa
Eyeclone processes personal information of South African data subjects in accordance with the Protection of Personal Information Act, 2013 (POPIA). Processing is performed on the lawful grounds of contractual necessity and legitimate business interest.
South African data subjects have the right to request access to, correction of, or objection to the processing of their personal information. Data subjects also have the right to submit a complaint to the Information Regulator of South Africa if they believe their personal information has been processed in violation of POPIA. The Information Regulator may be contacted at www.inforegulator.org.za or complaints.IR@justice.gov.za.
Cross-border transfers of South African data subjects’ personal information are conducted only where the recipient is subject to a law, binding corporate rules, or binding agreement that provides comparable protection as required by POPIA Section 72.
In the event of a security compromise affecting South African data subjects’ personal information, Eyeclone will notify the Information Regulator and affected data subjects as required by POPIA Section 22.
Information Officer (name): Darren Zidel
Information Officer (email / contact):privacy@eyeclone.io
Australia
Eyeclone handles personal information of Australian individuals in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The purposes for which personal information is collected, and the consequences of not providing it, are described in the What Information Do We Collect and How We Use Your Information sections of this Policy.
Australian individuals are notified at or before the time of collection that their personal information may be transferred to and stored in the United States, and that Eyeclone takes reasonable steps to ensure overseas recipients handle Australian personal information consistently with the APPs, including through contractual obligations on sub-processors.
Individuals may submit access or correction requests by contacting privacy@eyeclone.io. Eyeclone will respond within a reasonable time. If you are not satisfied with Eyeclone’s handling of a privacy matter, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Additional Privacy Information
Eyeclone’s Platform and website are directed exclusively at businesses and professionals. The Services are not for use by children under the age of 16 or the lowest age permitted by applicable law, and we do not knowingly collect or process the personal information of any children under the age of 16 or the lowest age permitted by applicable law. You may have additional rights under applicable law where you reside. If you have any questions about this Privacy Policy, please contact us via the contact information below. If you believe Eyeclone has collected information from a minor, please contact privacy@eyeclone.io.
Artificial Intelligence and Automated Processing
Artificial intelligence is a feature of the Eyeclone Platform. The Platform uses AI and machine learning for content generation, data analysis and insights, predictive modelling, and conversational tools. These features are powered in part by Anthropic, PBC and OpenAI OpCo, LLC (each, an “AI Provider”), each of which is an artificial intelligence services provider. Personal information processed within the Platform may be transmitted to one or both AI Providers as part of delivering AI-powered features. Each AI Provider processes such data subject to its own data processing terms, which include international data transfer mechanisms appropriate to the jurisdictions in which Eyeclone operates.
The Platform generates outputs including reports, visualizations, recommendations, and AI-generated text based on data provided by or processed on behalf of the Customer. These outputs are informational support tools only.
Eyeclone does not use Customer Data to train, fine-tune, or improve AI models beyond what is necessary to deliver the contracted services to that Customer. Where AI-generated outputs involve personal information processed within the Platform, that processing is performed as a data processor acting solely on the Customer’s instructions.
To the extent the Platform makes or facilitates automated decisions that produce legal or similarly significant effects, Eyeclone will inform affected individuals of: (a) the existence of such automated decision-making; (b) the logic involved; and (c) the significance and envisaged consequences for the individual. Individuals have the right to request human review of any such decision, to express their point of view, and to contest the decision. If you have questions about whether and how automated processing affects you, contact privacy@eyeclone.io.
Changes to This Policy
Eyeclone may update this Privacy Policy to reflect changes in our practices, services, or applicable legal requirements. When we make material changes, we will notify users by email and by posting a prominently visible notice at https://eyeclone.io/privacy-policy/. The updated Policy takes effect as of the date shown at the top of this document. Previous versions are available upon request. We encourage you to review this Policy periodically. Continued use of the Services after an update is published does not constitute consent to any data processing; all processing remains subject to the lawful bases described in this Policy.
Contact Us
Privacy Contact
Eyeclone LLC
9011 Dulcetto Ct, Boca Raton, Florida 33496
Email: privacy@eyeclone.io
For privacy-specific inquiries (including rights requests, data subject queries, and Data Processing Addendum requests), you may also contact us at privacy@eyeclone.io.
© 2026 Eyeclone LLC. All Rights Reserved.