DemandVector Security and Data Policy
Effective Date: August 18, 2026
DemandVector Inc (hereinafter, "DemandVector," "we," "us," or "our") is committed to protecting the security, confidentiality, and integrity of Client data. This Security and Data Policy describes the technical, organizational, and procedural measures we employ to safeguard your data when you use our Services. This Policy supplements and should be read in conjunction with our Terms of Service and Privacy Policy.
1. OUR COMMITMENT TO DATA SECURITYDemandVector understands that you are entrusting us with your partner demand and organizational data, which may include sensitive business information. We take this responsibility seriously. This Policy documents our commitments to you regarding how we handle, protect, and limit our use of your data.
CORE COMMITMENTS:
(a) YOUR DATA IS YOURS: You retain full ownership of all data you provide to DemandVector. We claim no ownership rights over your Platform Data.
(b) WE NEVER SELL YOUR DATA: DemandVector does not sell, rent, lease, or trade your data to any third party for any purpose whatsoever.
(c) WE LIMIT SHARING OF YOUR DATA: DemandVector shares your Platform Data only as necessary to provide the Services, as directed or authorized by you, as required by law, and as disclosed in our Privacy Policy.
(d) WE NEVER USE YOUR DATA FOR OUR BENEFIT: DemandVector does not use your Platform Data for analytics, benchmarking, machine learning training, product development insights, or any other purpose that benefits DemandVector or other clients.
(e) YOUR DATA IS ISOLATED: Your data is logically isolated from other clients' data. Another client can access your data only when you authorize sharing or collaboration through the Services.
2. ENCRYPTION2.1 Encryption in TransitDemandVector uses industry-standard transport encryption to protect data in transit across:
(a) Communications between your browser and our Website
(b) API communications between our Services and third-party integrations
(c) Internal communications between DemandVector systems
(d) Communications with our cloud infrastructure providers
DemandVector enforces encrypted transport for these connections using currently supported protocols and configurations.
2.2 Encryption at RestDemandVector uses industry-standard encryption controls to protect data at rest, including:
(a) Platform Data stored in our databases
(b) Account information and credentials
(c) Backup data
(d) Log files containing potentially sensitive information
Encryption keys are managed using industry-standard key-management practices, including appropriate separation and lifecycle controls.
3. DATA ISOLATION AND MULTI-TENANCYDemandVector operates a multi-tenant architecture with strict logical isolation between clients:
(a) Logical Isolation: Each client's data is logically separated at the database level. Access controls ensure that queries return only data the authenticated user is authorized to access.
(b) Authentication Boundary: All data access requires authentication. No data is accessible without valid credentials tied to a specific client account.
(c) Client-Authorized Sharing: A client cannot access another client's Platform Data unless the client that controls the data has configured or authorized sharing or collaboration through the Services.
(d) Administrative Access Controls: DemandVector personnel access to client data is strictly limited, logged, and auditable. Access is granted only on a need-to-know basis and with appropriate authorization when necessary to provide, secure, support, or administer the Services or meet legal obligations.
4. DATA HANDLING COMMITMENTS4.1 What We Do NOT Do With Your DataDemandVector makes the following binding commitments regarding your Platform Data:
(a) NO ANALYTICS ON YOUR DATA: We do not perform analytics, data mining, or statistical analysis on your Platform Data for any purpose other than providing the Services directly to you.
(b) NO MACHINE LEARNING TRAINING: We do not use your Platform Data to train machine learning models, artificial intelligence systems, or other automated learning systems. This includes our AI-powered features, which use third-party AI services subject to the use, training, and retention limitations described in Section 4.2(c).
(c) NO AGGREGATION: We do not aggregate your Platform Data with other clients' data for benchmarking, research, or any other purpose.
(d) NO PROFILING: We do not create profiles or insights about your organization based on your Platform Data for any purpose other than providing the Services to you.
(e) NO SECONDARY USES: We do not use your Platform Data for any purpose other than providing the Services as described in our Terms of Service.
4.2 AI and Machine Learning FeaturesDemandVector may offer AI-powered features such as content analysis, partner scoring, site summarization, and campaign generation. These features work as follows:
(a) Processing Only: AI features process your data only as necessary to provide the applicable AI-powered feature, subject to the restrictions stated in the applicable Client agreement.
(b) No Training: Your data is not used to train or improve AI models. Any AI models we use are either pre-trained on public data or are general-purpose models provided by third parties.
(c) Third-Party AI Providers: DemandVector will use third-party AI service providers to process Client Data only under written terms that (i) limit the provider's use of Client Data to providing the applicable services to DemandVector and (ii) prohibit the provider from using Client Data to train or improve any artificial-intelligence or machine-learning model. Any retention of Client Data by such a provider is subject to the retention terms applicable to the specific service used, including permitted retention for security, abuse prevention, or legal compliance.
(d) Bring Your Own Key: DemandVector supports the use of Client-provided API keys for third-party AI services. When a Client provides their own key, AI inference occurs under the Client's own commercial agreement with the AI provider. DemandVector stores the prompts and responses generated through these AI interactions as part of the Platform Data necessary to provide the Services, but does not gain any independent rights to data processed through Client-provided keys beyond what is required to deliver the Services.
(e) Transparency: We will clearly identify which features are AI-powered and provide information about how they work.
5. ACCESS CONTROLS5.1 Client Access ControlsDemandVector provides the following access control mechanisms for clients:
(a) Role-Based Access: Clients can use available roles and permissions.
(b) Authentication: We support secure authentication methods including strong passwords with complexity requirements.
(c) Session Management: Sessions are secured with cryptographically verifiable tokens, automatic timeout after periods of inactivity, and the ability to terminate active sessions.
5.2 DemandVector Personnel AccessAccess to client data by DemandVector personnel is strictly controlled:
(a) Principle of Least Privilege: Employees are granted the minimum access necessary to perform their job functions.
(b) Access Logging: Access to production systems and Client Data is logged and auditable.
(c) Personnel Screening: DemandVector may conduct background checks as appropriate for an employee's role and as permitted by law.
(d) Training: DemandVector provides security awareness guidance and training appropriate to personnel roles and responsibilities.
(e) Need-Based Access: Production data access requires documented business justification and management approval.
6. INFRASTRUCTURE SECURITY6.1 Cloud InfrastructureDemandVector Services are hosted on reputable cloud infrastructure providers that maintain industry-standard security certifications. Our infrastructure includes:
(a) Geographically distributed data centers for reliability
(b) Physical security controls including access restrictions, surveillance, and environmental controls
(c) Network security including firewalls and DDoS protection
6.2 Network Security(a) Firewall Protection: Internet-facing systems are protected by firewalls configured to allow only necessary traffic.
(b) DDoS Protection: Our infrastructure includes protection against distributed denial-of-service attacks.
(c) Network Segmentation: Production systems are segmented from development and testing environments.
7. DATA BACKUP AND RECOVERY7.1 Backup Practices(a) Regular Backups: Client data is backed up regularly to ensure recoverability.
(b) Encrypted Backups: All backup data is encrypted using the same standards as production data.
(c) Backup Storage: Backups are stored separately from primary data.
(d) Recovery Procedures: DemandVector maintains procedures intended to support restoration from backups.
7.2 Disaster RecoveryDemandVector maintains disaster recovery procedures designed to support restoration of the Services following a significant incident. Actual recovery times and recovery points depend on the nature and scope of the affected systems and incident.
(a) Recovery Time: We work to restore affected Services as reasonably practicable after a significant incident.
(b) Recovery Point: We work to minimize data loss using available backup and recovery measures.
(c) Program Review: We review and update recovery procedures as our systems and security program evolve.
8. INCIDENT RESPONSE8.1 Security Incident HandlingFor purposes of this Policy, "Security Incident" means confirmed unauthorized access to, acquisition, use, disclosure, alteration, loss, or destruction of Platform Data processed by DemandVector or its subprocessors. A Security Incident does not include unsuccessful attempts or events that do not compromise Platform Data.
In the event of a Security Incident, DemandVector will:
(a) Containment: Take commercially reasonable steps to contain the Security Incident.
(b) Investigation: Take commercially reasonable steps to investigate the scope and impact of the Security Incident.
(c) Notification: Notify each affected Client without undue delay after confirming the Security Incident and within any period required by applicable law.
(d) Mitigation and Remediation: Take commercially reasonable steps to mitigate and remediate the Security Incident.
(e) Documentation: Maintain records of the Security Incident and response actions.
8.2 Client NotificationSecurity Incident notifications will include, to the extent reasonably available:
(a) A description of the nature of the incident
(b) The categories and approximate number of records concerned
(c) The likely consequences of the incident
(d) The measures taken or proposed to address the incident
(e) Contact information for further inquiries
9. DATA RETENTION AND DELETION9.1 Retention PeriodsDemandVector retains data only as long as necessary to provide the Services:
(a) Platform Data: Retained while your account is active. After termination, Platform Data is subject to the export and deletion provisions in Section 9.2.
(b) Account Data: Retained while your account is active and for a reasonable period thereafter for legal and business purposes.
(c) Billing Records: Retained as required by applicable tax and financial regulations.
(d) Logs: System and security logs are used for security and troubleshooting purposes.
9.2 Data DeletionUpon termination of your account, DemandVector provides the applicable export period and deletes Platform Data from active systems and backups according to the applicable written agreement and DemandVector's documented deletion and backup lifecycle, subject to legal-retention requirements. Completed deletion is permanent and irreversible.
9.3 Right to DeletionYou may request deletion of your Platform Data at any time by contacting security@demandvector.io. DemandVector processes verified deletion requests according to the applicable written agreement and its documented deletion and backup lifecycle, subject to legal-retention requirements.
10. THIRD-PARTY INTEGRATIONS10.1 Integration SecurityWhen you connect DemandVector to third-party tools such as HubSpot, LinkedIn, or Google:
(a) Authorized Access Only: We access third-party tools only through APIs and methods authorized by you and the third-party provider.
(b) Minimal Permissions: We request only the permissions necessary to provide the Services.
(c) Credential Security: API keys and access tokens are encrypted at rest and in transit.
(d) No Credential Storage Beyond Necessity: We do not store your third-party credentials longer than necessary to provide the Services.
10.2 Third-Party Data HandlingData retrieved from third-party integrations is subject to this Security Policy:
(a) Same protections as directly uploaded data
(b) Same encryption standards
(c) Same access controls
(d) Same deletion procedures
11. COMPLIANCE AND CERTIFICATIONS11.1 Regulatory ComplianceDemandVector will perform its applicable U.S. data-protection obligations as stated in an executed U.S. Data Processing Addendum. Processing subject to non-U.S. data-protection law requires a separate written amendment.
11.2 Security Assessments(a) Vulnerability Management: We use risk-based processes to identify, assess, and address vulnerabilities in our systems.
(b) Code Review: Security is considered throughout our development process, including code reviews.
12. CLIENT RESPONSIBILITIESWhile DemandVector implements robust security measures, security is a shared responsibility. Clients are responsible for:
(a) Credential Security: Maintaining the confidentiality of account credentials and API keys.
(b) Access Management: Managing user access within their organization, including promptly removing access for departed employees.
(c) Data Classification: Ensuring that data uploaded to DemandVector is appropriate for cloud storage under the Client's own policies.
(d) Reporting: Promptly reporting any suspected security incidents or vulnerabilities to security@demandvector.io.
(e) Third-Party Authorization: Ensuring proper authorization before connecting third-party tools to DemandVector.
13. CHANGES TO THIS POLICYDemandVector reserves the right to update this Security and Data Policy. Material changes will be communicated to Clients via email or through the Services at least 30 days before taking effect. Continued use of the Services after changes become effective constitutes acceptance of the updated Policy.
14. CONTACT INFORMATIONFor questions about this Security and Data Policy, to report a security concern, or to exercise your data rights, please contact:
DemandVector Security Team
Email: security@demandvector.io
For general inquiries:
DemandVector Inc
Email: support@demandvector.io
Website: https://www.demandvector.com
15. SUMMARY OF COMMITMENTSFor quick reference, here are DemandVector's core security and data commitments:
DATA OWNERSHIP: Your data belongs to you. Always.
ENCRYPTION: Platform Data is encrypted in transit and at rest using industry-standard encryption controls.
NO SELLING: We never sell your data. Period.
NO UNAUTHORIZED SHARING: We share your data only as needed to provide Services, as directed or authorized by you, or as required by law.
NO TRAINING: We never use your data to train AI or ML models.
NO ANALYTICS: We never analyze your data for our benefit.
ISOLATION: Your data is logically isolated from other clients except when you authorize sharing or collaboration.
DELETION: Your data is deleted according to the applicable written agreement and our documented deletion and backup lifecycle.
TRANSPARENCY: We will notify you of security incidents affecting your data.
DemandVector Inc (hereinafter, "DemandVector," "we," "us," or "our") is committed to protecting the security, confidentiality, and integrity of Client data. This Security and Data Policy describes the technical, organizational, and procedural measures we employ to safeguard your data when you use our Services. This Policy supplements and should be read in conjunction with our Terms of Service and Privacy Policy.
1. OUR COMMITMENT TO DATA SECURITYDemandVector understands that you are entrusting us with your partner demand and organizational data, which may include sensitive business information. We take this responsibility seriously. This Policy documents our commitments to you regarding how we handle, protect, and limit our use of your data.
CORE COMMITMENTS:
(a) YOUR DATA IS YOURS: You retain full ownership of all data you provide to DemandVector. We claim no ownership rights over your Platform Data.
(b) WE NEVER SELL YOUR DATA: DemandVector does not sell, rent, lease, or trade your data to any third party for any purpose whatsoever.
(c) WE LIMIT SHARING OF YOUR DATA: DemandVector shares your Platform Data only as necessary to provide the Services, as directed or authorized by you, as required by law, and as disclosed in our Privacy Policy.
(d) WE NEVER USE YOUR DATA FOR OUR BENEFIT: DemandVector does not use your Platform Data for analytics, benchmarking, machine learning training, product development insights, or any other purpose that benefits DemandVector or other clients.
(e) YOUR DATA IS ISOLATED: Your data is logically isolated from other clients' data. Another client can access your data only when you authorize sharing or collaboration through the Services.
2. ENCRYPTION2.1 Encryption in TransitDemandVector uses industry-standard transport encryption to protect data in transit across:
(a) Communications between your browser and our Website
(b) API communications between our Services and third-party integrations
(c) Internal communications between DemandVector systems
(d) Communications with our cloud infrastructure providers
DemandVector enforces encrypted transport for these connections using currently supported protocols and configurations.
2.2 Encryption at RestDemandVector uses industry-standard encryption controls to protect data at rest, including:
(a) Platform Data stored in our databases
(b) Account information and credentials
(c) Backup data
(d) Log files containing potentially sensitive information
Encryption keys are managed using industry-standard key-management practices, including appropriate separation and lifecycle controls.
3. DATA ISOLATION AND MULTI-TENANCYDemandVector operates a multi-tenant architecture with strict logical isolation between clients:
(a) Logical Isolation: Each client's data is logically separated at the database level. Access controls ensure that queries return only data the authenticated user is authorized to access.
(b) Authentication Boundary: All data access requires authentication. No data is accessible without valid credentials tied to a specific client account.
(c) Client-Authorized Sharing: A client cannot access another client's Platform Data unless the client that controls the data has configured or authorized sharing or collaboration through the Services.
(d) Administrative Access Controls: DemandVector personnel access to client data is strictly limited, logged, and auditable. Access is granted only on a need-to-know basis and with appropriate authorization when necessary to provide, secure, support, or administer the Services or meet legal obligations.
4. DATA HANDLING COMMITMENTS4.1 What We Do NOT Do With Your DataDemandVector makes the following binding commitments regarding your Platform Data:
(a) NO ANALYTICS ON YOUR DATA: We do not perform analytics, data mining, or statistical analysis on your Platform Data for any purpose other than providing the Services directly to you.
(b) NO MACHINE LEARNING TRAINING: We do not use your Platform Data to train machine learning models, artificial intelligence systems, or other automated learning systems. This includes our AI-powered features, which use third-party AI services subject to the use, training, and retention limitations described in Section 4.2(c).
(c) NO AGGREGATION: We do not aggregate your Platform Data with other clients' data for benchmarking, research, or any other purpose.
(d) NO PROFILING: We do not create profiles or insights about your organization based on your Platform Data for any purpose other than providing the Services to you.
(e) NO SECONDARY USES: We do not use your Platform Data for any purpose other than providing the Services as described in our Terms of Service.
4.2 AI and Machine Learning FeaturesDemandVector may offer AI-powered features such as content analysis, partner scoring, site summarization, and campaign generation. These features work as follows:
(a) Processing Only: AI features process your data only as necessary to provide the applicable AI-powered feature, subject to the restrictions stated in the applicable Client agreement.
(b) No Training: Your data is not used to train or improve AI models. Any AI models we use are either pre-trained on public data or are general-purpose models provided by third parties.
(c) Third-Party AI Providers: DemandVector will use third-party AI service providers to process Client Data only under written terms that (i) limit the provider's use of Client Data to providing the applicable services to DemandVector and (ii) prohibit the provider from using Client Data to train or improve any artificial-intelligence or machine-learning model. Any retention of Client Data by such a provider is subject to the retention terms applicable to the specific service used, including permitted retention for security, abuse prevention, or legal compliance.
(d) Bring Your Own Key: DemandVector supports the use of Client-provided API keys for third-party AI services. When a Client provides their own key, AI inference occurs under the Client's own commercial agreement with the AI provider. DemandVector stores the prompts and responses generated through these AI interactions as part of the Platform Data necessary to provide the Services, but does not gain any independent rights to data processed through Client-provided keys beyond what is required to deliver the Services.
(e) Transparency: We will clearly identify which features are AI-powered and provide information about how they work.
5. ACCESS CONTROLS5.1 Client Access ControlsDemandVector provides the following access control mechanisms for clients:
(a) Role-Based Access: Clients can use available roles and permissions.
(b) Authentication: We support secure authentication methods including strong passwords with complexity requirements.
(c) Session Management: Sessions are secured with cryptographically verifiable tokens, automatic timeout after periods of inactivity, and the ability to terminate active sessions.
5.2 DemandVector Personnel AccessAccess to client data by DemandVector personnel is strictly controlled:
(a) Principle of Least Privilege: Employees are granted the minimum access necessary to perform their job functions.
(b) Access Logging: Access to production systems and Client Data is logged and auditable.
(c) Personnel Screening: DemandVector may conduct background checks as appropriate for an employee's role and as permitted by law.
(d) Training: DemandVector provides security awareness guidance and training appropriate to personnel roles and responsibilities.
(e) Need-Based Access: Production data access requires documented business justification and management approval.
6. INFRASTRUCTURE SECURITY6.1 Cloud InfrastructureDemandVector Services are hosted on reputable cloud infrastructure providers that maintain industry-standard security certifications. Our infrastructure includes:
(a) Geographically distributed data centers for reliability
(b) Physical security controls including access restrictions, surveillance, and environmental controls
(c) Network security including firewalls and DDoS protection
6.2 Network Security(a) Firewall Protection: Internet-facing systems are protected by firewalls configured to allow only necessary traffic.
(b) DDoS Protection: Our infrastructure includes protection against distributed denial-of-service attacks.
(c) Network Segmentation: Production systems are segmented from development and testing environments.
7. DATA BACKUP AND RECOVERY7.1 Backup Practices(a) Regular Backups: Client data is backed up regularly to ensure recoverability.
(b) Encrypted Backups: All backup data is encrypted using the same standards as production data.
(c) Backup Storage: Backups are stored separately from primary data.
(d) Recovery Procedures: DemandVector maintains procedures intended to support restoration from backups.
7.2 Disaster RecoveryDemandVector maintains disaster recovery procedures designed to support restoration of the Services following a significant incident. Actual recovery times and recovery points depend on the nature and scope of the affected systems and incident.
(a) Recovery Time: We work to restore affected Services as reasonably practicable after a significant incident.
(b) Recovery Point: We work to minimize data loss using available backup and recovery measures.
(c) Program Review: We review and update recovery procedures as our systems and security program evolve.
8. INCIDENT RESPONSE8.1 Security Incident HandlingFor purposes of this Policy, "Security Incident" means confirmed unauthorized access to, acquisition, use, disclosure, alteration, loss, or destruction of Platform Data processed by DemandVector or its subprocessors. A Security Incident does not include unsuccessful attempts or events that do not compromise Platform Data.
In the event of a Security Incident, DemandVector will:
(a) Containment: Take commercially reasonable steps to contain the Security Incident.
(b) Investigation: Take commercially reasonable steps to investigate the scope and impact of the Security Incident.
(c) Notification: Notify each affected Client without undue delay after confirming the Security Incident and within any period required by applicable law.
(d) Mitigation and Remediation: Take commercially reasonable steps to mitigate and remediate the Security Incident.
(e) Documentation: Maintain records of the Security Incident and response actions.
8.2 Client NotificationSecurity Incident notifications will include, to the extent reasonably available:
(a) A description of the nature of the incident
(b) The categories and approximate number of records concerned
(c) The likely consequences of the incident
(d) The measures taken or proposed to address the incident
(e) Contact information for further inquiries
9. DATA RETENTION AND DELETION9.1 Retention PeriodsDemandVector retains data only as long as necessary to provide the Services:
(a) Platform Data: Retained while your account is active. After termination, Platform Data is subject to the export and deletion provisions in Section 9.2.
(b) Account Data: Retained while your account is active and for a reasonable period thereafter for legal and business purposes.
(c) Billing Records: Retained as required by applicable tax and financial regulations.
(d) Logs: System and security logs are used for security and troubleshooting purposes.
9.2 Data DeletionUpon termination of your account, DemandVector provides the applicable export period and deletes Platform Data from active systems and backups according to the applicable written agreement and DemandVector's documented deletion and backup lifecycle, subject to legal-retention requirements. Completed deletion is permanent and irreversible.
9.3 Right to DeletionYou may request deletion of your Platform Data at any time by contacting security@demandvector.io. DemandVector processes verified deletion requests according to the applicable written agreement and its documented deletion and backup lifecycle, subject to legal-retention requirements.
10. THIRD-PARTY INTEGRATIONS10.1 Integration SecurityWhen you connect DemandVector to third-party tools such as HubSpot, LinkedIn, or Google:
(a) Authorized Access Only: We access third-party tools only through APIs and methods authorized by you and the third-party provider.
(b) Minimal Permissions: We request only the permissions necessary to provide the Services.
(c) Credential Security: API keys and access tokens are encrypted at rest and in transit.
(d) No Credential Storage Beyond Necessity: We do not store your third-party credentials longer than necessary to provide the Services.
10.2 Third-Party Data HandlingData retrieved from third-party integrations is subject to this Security Policy:
(a) Same protections as directly uploaded data
(b) Same encryption standards
(c) Same access controls
(d) Same deletion procedures
11. COMPLIANCE AND CERTIFICATIONS11.1 Regulatory ComplianceDemandVector will perform its applicable U.S. data-protection obligations as stated in an executed U.S. Data Processing Addendum. Processing subject to non-U.S. data-protection law requires a separate written amendment.
11.2 Security Assessments(a) Vulnerability Management: We use risk-based processes to identify, assess, and address vulnerabilities in our systems.
(b) Code Review: Security is considered throughout our development process, including code reviews.
12. CLIENT RESPONSIBILITIESWhile DemandVector implements robust security measures, security is a shared responsibility. Clients are responsible for:
(a) Credential Security: Maintaining the confidentiality of account credentials and API keys.
(b) Access Management: Managing user access within their organization, including promptly removing access for departed employees.
(c) Data Classification: Ensuring that data uploaded to DemandVector is appropriate for cloud storage under the Client's own policies.
(d) Reporting: Promptly reporting any suspected security incidents or vulnerabilities to security@demandvector.io.
(e) Third-Party Authorization: Ensuring proper authorization before connecting third-party tools to DemandVector.
13. CHANGES TO THIS POLICYDemandVector reserves the right to update this Security and Data Policy. Material changes will be communicated to Clients via email or through the Services at least 30 days before taking effect. Continued use of the Services after changes become effective constitutes acceptance of the updated Policy.
14. CONTACT INFORMATIONFor questions about this Security and Data Policy, to report a security concern, or to exercise your data rights, please contact:
DemandVector Security Team
Email: security@demandvector.io
For general inquiries:
DemandVector Inc
Email: support@demandvector.io
Website: https://www.demandvector.com
15. SUMMARY OF COMMITMENTSFor quick reference, here are DemandVector's core security and data commitments:
DATA OWNERSHIP: Your data belongs to you. Always.
ENCRYPTION: Platform Data is encrypted in transit and at rest using industry-standard encryption controls.
NO SELLING: We never sell your data. Period.
NO UNAUTHORIZED SHARING: We share your data only as needed to provide Services, as directed or authorized by you, or as required by law.
NO TRAINING: We never use your data to train AI or ML models.
NO ANALYTICS: We never analyze your data for our benefit.
ISOLATION: Your data is logically isolated from other clients except when you authorize sharing or collaboration.
DELETION: Your data is deleted according to the applicable written agreement and our documented deletion and backup lifecycle.
TRANSPARENCY: We will notify you of security incidents affecting your data.