PRIVACY POLICY

PRIVACY POLICY

Last Updated: September 9, 2026

This Privacy Policy explains how Concorda, Inc., a Delaware corporation (“we,” “us,” or “our”), handles personal information when you visit our website, use our product, or otherwise interact with us. It works alongside our Terms and Conditions, which govern your use of our services and include our Data Processing Addendum as Attachment A.

California Notice at Collection. We collect the categories of personal information in Section 2 for the purposes in Section 4. We do not sell personal information or share it for cross-context behavioral advertising. Your California rights are in Sections 9 and 10.

1. Scope. This policy covers information we control: your account, login, billing, and support information, and how you use our site and product. Documents, matter data, and other content you or your organization submit to the product are Customer Data. We process Customer Data only on the customer’s behalf under our Terms and Conditions and their Data Processing Addendum, and requests about it should go to your organization first. This policy does not cover third-party sites or services we do not control.

2. What We Collect. Using the categories defined under California law:

  • Identifiers. Name, email address, IP address.

  • Customer records. Billing address. Payment information is processed by our payment processor (currently Stripe); we do not store full payment card numbers.

  • Usage data. Features used, pages viewed, and actions taken in our product and on our site.

  • Geolocation data. Approximate location derived from IP address.

  • Content you send us directly. Support requests, form submissions, and other communications you send us outside of a customer account.

Outside of Customer Data governed by our customer agreements, our services are not intended for sensitive personal information as defined under California law, and we ask that you not submit it to us directly. We do not use sensitive personal information to infer characteristics about you, and we use login credentials only to provide, secure, and authenticate the services.

3. How We Collect It. Directly from you when you create an account, fill out a form, or contact support; automatically through cookies and similar technologies; and from third parties, including our payment processor, analytics providers, single sign-on providers you choose to use, public sources, and marketing or referral partners.

4. Why We Use It. To provide, maintain, and improve our services; authenticate accounts and prevent fraud and abuse; process payments; communicate with you about your account, our services, and product updates; respond to inquiries and provide support; and comply with law, enforce our terms, and protect our rights. We may create aggregated or de-identified data that cannot reasonably be re-identified, use it for any lawful purpose, and will not attempt to re-identify it.

5. Who We Share It With.

  • Service providers and subprocessors that run our infrastructure, payments, analytics, and communications, bound by written agreements limiting their use of personal information to providing services to us. A current list is published at trust.delve.co/concorda, where you can subscribe to notice of changes.

  • Affiliates. Entities under common control with us that provide services to us, subject to this policy.

  • Professional advisors such as auditors, lawyers, and accountants.

  • Government authorities when required by law, subpoena, or other legal process.

  • A successor in a merger, acquisition, or sale of assets, who will be bound by this policy or one materially similar.

  • Third-party services you connect or sign in with (for example, a single sign-on provider), at your direction. Their use of information is governed by their own privacy policies.

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not disclose it to third parties for their own direct marketing. Our Data Processing Addendum is included in our Terms and Conditions as Attachment A and applies automatically to business customers.

6. AI and Machine Learning. We do not use your personal information or content to train artificial intelligence or machine learning models, whether our own or a third party’s. We may use aggregated and de-identified data to evaluate and improve our product.

7. Cookies. We use essential cookies (authentication and security), functional cookies (your preferences), and analytics cookies (how our services are used). You can control cookies through your browser settings; disabling non-essential cookies will not prevent core features from working. We do not respond to “Do Not Track” signals because there is no industry consensus on how to interpret them. Because we do not sell or share personal information, there is nothing to opt out of; if that changes, we will honor recognized opt-out preference signals, including the Global Privacy Control.

8. Marketing Emails. Unsubscribe using the link in any marketing message or by emailing security@concordahq.com. Service emails about your account, billing, security, or required notices will continue.

9. Your Rights and How to Exercise Them. Depending on where you live, you may have the right to access, correct, or delete your personal information, receive a portable copy, opt out of sale, sharing, or certain automated decision-making, and be free from discrimination for exercising these rights. To make a request, email security@concordahq.com. We will verify your identity, respond within forty-five days (with one extension where the law permits), and tell you if we cannot fulfill a request and why. You may use an authorized agent if you provide written permission and identification for the agent. If we deny a request, you may appeal by emailing us with “Appeal” in the subject line; we will respond within sixty days, and if we deny the appeal you may contact your state attorney general.

10. State-Specific Notices. California. In the preceding twelve months we collected the categories of personal information in Section 2 and disclosed them for business purposes to the recipients in Section 5. We have not sold or shared any category. You may request the specific pieces of personal information we hold about you and may limit our use of sensitive personal information if we collect it. Under California’s “Shine the Light” law, we confirm that we do not disclose personal information to third parties for their own direct marketing. Nevada. You may direct us not to sell covered information by emailing security@concordahq.com with “Nevada Opt-Out” in the subject line. Other states. Residents of states with comprehensive privacy laws have the rights in Section 9, with the differences each state’s law requires. Where a state gives you a right not listed here, we honor it.

11. Retention. We keep personal information as long as needed for the purposes above, considering the type of information, why we collected it, legal obligations such as tax and accounting, and our relationship with you. When you close your account, we delete or anonymize associated information promptly, except records kept for legal, accounting, fraud-prevention, or dispute-resolution reasons.

12. Security. We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity. Our security program has been examined by an independent auditor under SOC 2 Type 2. No system is perfectly secure, and we will notify you of a breach affecting your personal information as required by law.

13. Children. Our services are not directed to anyone under 18, and we do not knowingly collect personal information from them. If you believe someone under 18 has provided it, email security@concordahq.com and we will delete it.

14. International Users. We process personal information in the United States, and our services are intended for users in the United States. If you use them from elsewhere, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

15. Changes. We may update this policy. The “Last Updated” date reflects the most recent change, and for material changes we will take reasonable steps to notify you.

16. Contact. Concorda, Inc., 21936 North Tall Oaks Drive, Kildeer, IL 60047. security@concordahq.com.

See How Concorda Works
for Your Practice

See How Concorda Works for Your Practice