Privacy Policy

Effective Date: January 1, 2025 • Last Updated: September 8, 2026

1. Introduction and Scope

This Privacy Policy describes how Data Hippo (a service of Paz Technologies LLC, "we," "our," or "us") collects, uses, and shares information when you use our websites, request or use an evaluation sandbox, or otherwise interact with us (together, the "Service"). Website analytics choices are separate from accepting our Terms; Section 4 explains the regional defaults and how to opt out.

This policy covers our websites, evaluation sandboxes, and marketing activities. Production deployments of the Data Hippo platform are governed by separate written agreements with our customers, including business associate agreements where applicable, and typically run in the customer's own cloud environment.

The Service is not intended to collect protected health information or patient data. Do not submit patient information to our websites, sandboxes, or setup conversations.

2. Information We Collect

Information You Provide

  • Contact and signup information: your email address and sign-in details when you request a sandbox, book a demo, or contact us
  • Setup and conversation information: information you share in conversations with our setup assistant and on setup forms, such as your name, role, and details about your organization, its systems, and its needs
  • Business communications: the contents of emails, calls, and meetings you have with us

Publicly Available Business Information

To review sandbox requests and prepare and personalize sandbox environments, we may supplement the information you provide with publicly available business information about you and your organization, such as your organization's website, business directories, news coverage, and professional profiles. We collect only business-related information from these sources.

Information Collected Automatically

  • Service usage patterns, feature usage, performance metrics, and error reports
  • Device and technical information, such as IP address, browser type and version, operating system, and time zone
  • Session information, such as pages visited, session duration, and referring pages

Partner Identity Information

For organizations entering a partner relationship with us, we collect identity information to verify access eligibility, including organization details, contact person information, and business credentials.

3. How We Use Your Information

Service Provision

  • Providing and maintaining the Service
  • Reviewing sandbox requests and deciding whether to grant access
  • Preparing and personalizing sandbox environments
  • Verifying partner access and authorization

Communications

  • Sending service communications, such as sign-in links and notifications about your sandbox
  • Following up about your sandbox, our services, and relevant product updates
  • Responding to your inquiries and providing support

You may opt out of marketing communications at any time by using the unsubscribe link in our emails or contacting us. Service communications, such as sign-in links, are sent as needed to provide the Service.

Improvement and Analytics

  • Analyzing usage to improve the Service and develop new features
  • Understanding the needs and priorities of the organizations we serve

Security, Fraud Prevention, and Legal

  • Protecting the Service against abuse, fraud, and security threats
  • Enforcing our Terms of Service
  • Complying with legal obligations

AI Processing

Parts of the Service, including the sandbox setup assistant and our review of sandbox requests, use artificial intelligence operated by us and by our service providers. Our service providers process this information on our behalf under agreements that restrict their use of it, and we do not permit them to use your information to train their general-purpose models.

4. Cookies and Analytics

Necessary storage supports functions such as sign-in, your theme preference, and remembering your analytics choice. For visitors identified as being in the United States, optional website analytics is enabled unless you opt out. For visitors outside the United States, or when we cannot determine the country, it stays off until you accept. We use Cloudflare's country-level request information to select this default, not precise location. Rejecting analytics does not prevent you from browsing, contacting us, or booking a demo.

When analytics is enabled, we use PostHog to understand how people find, navigate, and use this website and where the demo booking experience can be improved. We measure page visits, public navigation and contact-link clicks, active engagement, product interest, visible video playback and errors, page performance, and booking progress. Measurements include session identifiers, public page paths, referring domains, approved source and medium categories, language, theme, browser and operating-system families, and general device size. We do not send complete query strings, arbitrary campaign text, or form contents to analytics.

To distinguish new and returning browsers, we store a random first-party browser identifier with a fixed lifetime of up to 90 days; visiting another page does not extend it. It is not your name or email address and is not created using fingerprinting. Browser recognition does not identify the person using the device. Session information uses session-scoped browser storage. A first-party endpoint operated through Cloudflare forwards the permitted measurements to PostHog. We do not use third-party advertising networks or identity-enrichment services for these website measurements.

Public website analytics includes recorded page interactions to help us understand the browsing experience. We also collect error categories and code locations, not form contents, raw error messages, console recordings, or network request and response bodies. Global Privacy Control and Do Not Track signals keep this collection off. Login, sandbox, and private proposal routes are excluded from public website analytics.

You can turn analytics on or off using , also available in the footer. Opting out stops future analytics collection and removes our analytics identifiers from accessible browser storage; it does not automatically delete measurements already received by PostHog. The browser identifier's 90-day limit is not a server-side deletion schedule. Contact us using Section 8 to request deletion. Your browser stores your choice, its version, and its date. An opt-out remains in effect until you change it or clear that storage; an explicit acceptance lasts up to 90 days, after which analytics pauses until you renew it.

5. Information Sharing

We do not sell your personal information.

Service Providers

We share information with third-party service providers who assist us with service hosting and maintenance, identity and sign-in, email delivery, analytics processing, AI processing, and technical support. Service providers are permitted to use information only to provide services to us.

For this website, Cloudflare provides hosting, security, and the analytics forwarding endpoint; PostHog processes the permitted website measurements; and Calendly processes the contact details and scheduling information needed to book and manage your demo. Meeting invitations and video calls use the configured Google Calendar and Google Meet services. Your submitted booking contact details and free-text answers are used for scheduling and follow-up, not sent to PostHog.

Business Transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy's protections.

Legal Requirements

We may disclose information if required by law or court order, or as necessary to comply with legal obligations, protect our rights and property, prevent fraud or security issues, or protect user safety.

6. Data Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and audit logging. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Data Retention

We retain information for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law. Sandbox request records are retained while your request is active and for a reasonable period afterward to support follow-up and to prevent abuse. Analytics retention depends on our configured service settings and our need to understand website usage over time. Opting out of analytics stops future collection; it does not automatically erase earlier records. You can contact us to request deletion. We delete or de-identify information when it is no longer needed.

8. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

  • Access and Correction: request access to or correction of your personal information
  • Deletion: request deletion of your personal information, subject to legal and business requirements
  • Data Portability: request a copy of your data in a structured, machine-readable format
  • Opt-Out: opt out of marketing communications at any time
  • Objection and Restriction: object to or request restriction of certain processing where applicable law provides these rights

To exercise any of these rights, contact us at legal@datahippo.ai. We will verify your request and respond within the time required by applicable law.

9. International Data Transfers

If you are located outside of the United States, please note that your information may be transferred to and processed in the United States, where our servers and service providers are located. We ensure appropriate safeguards are in place for such transfers.

10. Children's Privacy

The Service is intended for business use and is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will take steps to delete the information.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect (described in Section 2), the right to delete personal information, the right to correct inaccurate personal information, and the right to non-discrimination for exercising these rights. We do not sell personal information and do not share personal information for cross-context behavioral advertising.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date. Significant changes will be communicated through the Service or other appropriate means.

13. Third-Party Services

The Service may contain links to third-party services. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices.

14. Contact Information

If you have any questions about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us:

Email: legal@datahippo.ai

15. Governing Law

This Privacy Policy is governed by the laws of the United States without regard to conflict of law principles.