Privacy Policy

Last Updated: August 11, 2026

Vantis Decision Intelligence, Inc. (“Company,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, use our platform and services, or otherwise interact with us. This Privacy Policy applies to individuals in the United States and, where applicable, the European Economic Area (“EEA”) , the United Kingdom (“UK”), or Switzerland.

1. Personal Information We Collect About You

(We may collect and use the following categories of personal information:

• Identifiers: Name, business email address, telephone number, business address, IP address, username, and other account identifiers.

• Professional or Employment-Related Information: Job title, employer, and other business contact information.

• Commercial Information: Subscription, billing, payment, and transaction information.

• Internet or Other Electronic Network Activity Information: Browser type, device information, operating system, login information, and information regarding use of our website and services.

• Communications: Information provided when you contact us, request support, or otherwise communicate with us.Our AI-enabled features are not intended to receive or process personal information. Users should not submit personal information through those features.

2. How Your Personal Information is Collected

We collect personal information from the following sources:

• Directly from you, including when you create an account, use the services, communicate with us, or request support.

• From your organization, including when it creates or administers your account.

• Automatically, through cookies and similar technologies when you use our website or services.

• From service providers, including payment, authentication, analytics, and hosting providers.

Payment card information may be collected and processed directly by our payment processor. We do not directly access, receive, or store payment card information.Certain personal information is required to create and administer an account, process payments, and provide the services. If you do not provide this information, we may be unable to create your account, process your payment, or provide the services.

Cookies and Similar Technologies

We use cookies and similar technologies to operate, secure, and improve our website and services and understand how users interact with them. These technologies may collect information such as IP address, browser type, device information, operating system, and website or service activity.

Where required by applicable law, we obtain consent before using nonessential cookies or similar technologies. You may manage your preferences through [cookie settings link — to be added when the website is live].

For more information about the cookies and similar technologies we use, including their purposes and duration, please review our Cookie Policy at [cookie policy link — to be added when the website is live].

3. How and Why We Use Your Personal Information

We may use personal information for the following purposes:

• To provide and administer the services, including creating and managing accounts;

• To process subscriptions, payments, and other transactions;

• To communicate with you about your account, the services, and support requests;

• To operate, maintain, troubleshoot, and improve our website and services;

• To authenticate users and protect the security and integrity of our website, services, and systems;

• To prevent and detect fraud, unauthorized activity, and other misuse;

• To maintain our business and transaction records;

• To comply with applicable laws, regulations, legal processes, and governmental requests;

• To establish, exercise, or defend legal claims; and

• To send you information about our services, subject to your communication preferences and applicable law.

EEA, UK, and Swiss Individuals

If the EU General Data Protection Regulation (“EU GDPR”), UK General Data Protection Regulation (“UK GDPR”), or Swiss Federal Act on Data Protection (“Swiss FADP”) applies, we process personal information only when we have a valid legal basis. Depending on the purpose, we rely on the following legal bases:

Purpose
Categories of Personal Information
Legal Basis
Providing and administering the services
Identifiers, professional or employment-related information, account information, commercial information, and communications
Performance of a contract or our legitimate interest in providing the services to your organization
Processing subscriptions, payments, and transactions
Identifiers and commercial information
Performance of a contract and compliance with legal obligations
Communicating with users and providing support
Identifiers, professional or employment-related information, account information, and communications
Performance of a contract or our legitimate interest in supporting users and customer organizations
Operating, maintaining, troubleshooting, and improving the services
Identifiers and internet or other electronic network activity information
Our legitimate interest in operating and improving the services
Authentication, security, and fraud prevention
Identifiers, account information, commercial information, and internet or other electronic network activity information
Our legitimate interest in protecting our business, users, and systems and, where applicable, compliance with legal obligations
Maintaining records and complying with legal obligations
Any categories of personal information relevant to the applicable requirement
Compliance with legal obligations and our legitimate interest in maintaining appropriate business records
Establishing, exercising, or defending legal claims
Any categories of personal information relevant to the claim
Our legitimate interest in protecting our legal rights
Marketing our services
Identifiers, professional or employment-related information, commercial information, and communications
Our legitimate interest in promoting our services or consent where required by applicable law

A legitimate interest is a business or commercial reason for processing personal information that is not overridden by your rights and interests. Where we rely on consent, you may withdraw your consent at any time.

We do not intend to collect or process special categories of personal information.

4. EEA Data Subjects: Promotional Communications

We may use your business contact information to send you information about our services, including new features, updates, and other business-related communications.For individuals in the EEA, UK, or Switzerland, we rely on our legitimate interest in promoting our services or consent where required by applicable law. Where consent is required, we will request your consent before sending electronic marketing communications, and you may withdraw that consent at any time. We send electronic marketing communications in accordance with applicable EEA laws and, in the UK, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”).We do not sell your personal information or disclose it to third parties for their own marketing purposes.

You may opt out of receiving marketing communications from us at any time by:

• Contacting us at privacy@vantisdi.com; or

• Using the “unsubscribe” link in our marketing emails.

If you opt out of marketing communications, we may continue to send you nonmarketing communications concerning your account, transactions, or use of the services.

5. Who We Share Your Personal Information With

We may share personal information with:

• Our affiliates;

• service providers we use to operate and provide the services, including hosting, infrastructure, authentication, security, technical support, communications, and analytics providers;

• Payment processors that process subscription and payment transactions;

• Other third parties we use to help operate our business, such as marketing agencies, consultants, and other business service providers;

• Professional advisers, including attorneys, accountants, auditors, and insurers;

• Government authorities, regulators, courts, and law enforcement agencies where required or permitted by law; and

• Potential or actual parties to a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets.

We require our service providers to process personal information only for the purposes of providing services to us and in accordance with applicable data protection laws and contractual obligations.

We do not sell personal information or disclose it to third parties for their own marketing purposes.

6. Categories of Personal Information We Disclose

We may disclose the following categories of personal information to the parties identified in Section 5:

• Identifiers;

• Professional or employment-related information;

• Account information;

• Commercial information;

• Commercial information;

• Communications.

We may disclose personal information to provide and operate the services, process transactions, protect our rights and systems, comply with applicable law, and conduct the other activities described in this Privacy Policy.

7. California and Other U.S. State Privacy Rights

Depending on your state of residence and applicable law, you may have the right to:

• Confirm whether we process your personal information;

• Access the personal information we maintain about you;

• Correct inaccurate personal information;

• Delete personal information;

• Obtain a portable copy of personal information you provided to us;

• Obtain information regarding the categories of personal information we collect, the sources of that information, the purposes for which we use it, and the categories of third parties to whom we disclose it;

• Opt out of the sale or sharing of personal information, targeted advertising, or certain profiling;

• Limit certain uses and disclosures of sensitive personal information;

• Appeal our denial of a privacy request; and

• Exercise your privacy rights without unlawful discrimination or retaliation.

These rights are subject to applicable exceptions and may vary by state. We do not sell personal information, disclose personal information for cross-context behavioral or targeted advertising, or use personal information to profile individuals in furtherance of decisions that produce legal or similarly significant effects.

8. EEA, UK, and Swiss Privacy Rights

If the EU GDPR, UK GDPR, or Swiss FADP applies to our processing of your personal information, you may have the right to:

• Access your personal information;

• Correct inaccurate or incomplete personal information;

• Request deletion of your personal information;

• Restrict our processing of your personal information;

• Receive certain personal information in a structured, commonly used, and machine-readable format and transmit it to another controller;

• Object to processing based on our legitimate interests;

• Object at any time to processing for direct marketing;

• Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing conducted before withdrawal;

• Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects; and

• Lodge a complaint with the supervisory authority in the EEA country where you live, work, or believe a violation occurred.These rights are subject to the conditions and limitations provided by applicable data protection law. We do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects.

9. How to Exercise Your Rights

To exercise any applicable privacy right described in Sections 7 or 8, contact us using one of the following methods:

Your request must provide sufficient information for us to identify you, verify your identity, and understand the nature of your request. We will use personal information submitted in connection with a request only to verify and respond to that request.

Where permitted by applicable law, you may use an authorized agent to submit a request on your behalf. We may require proof of the agent’s authority and verification of your identity.

We will respond within the period required by applicable law. If we deny your request, we will explain the basis for the denial and, where applicable, provide instructions for appealing our decision.

We generally do not charge a fee to process privacy requests. We may charge a reasonable fee or decline to act if permitted by applicable law, including where a request is manifestly unfounded, excessive, or repetitive.

10. Where We Process Personal Information

Personal information may be processed at our offices and through the systems of our affiliates and service providers, including those identified in Section 5.We are based in the United States. If you access or use the services from outside the United States, your personal information may be transferred to and processed in the United States and other countries where we or our service providers operate.

11. International Transfers of Personal Information

When we transfer personal information from the EEA to a country that has not been recognized as providing an adequate level of protection, we use safeguards required by applicable law.

For transfers from the EEA, these safeguards may include an adequacy decision, the European Commission’s Standard Contractual Clauses, or another legally recognized transfer mechanism.

For transfers from the UK, these safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or another legally recognized transfer mechanism.

You may contact us using the information in Section 9 to obtain additional information regarding the safeguards applicable to your personal information.

12. Retention

We retain personal information only for as long as reasonably necessary to provide the services, comply with legal obligations, resolve disputes, enforce our agreements, and establish, exercise, or defend legal claims.

During an evaluation, we retain personal information for the period necessary to deliver and discuss the assessment and for up to ninety (90) days thereafter. If the customer does not purchase a paid subscription during that period, we delete the personal information unless the customer requests earlier deletion or the parties agree to extend the period.

During an active subscription, we retain personal information and assessment history to provide the services, support reassessments, and maintain the customer’s historical results. If a subscription expires or terminates, we retain personal information for thirty (30) days to permit renewal without loss of assessment history and then delete it.

A customer may request deletion of personal information at any time. We will complete deletion within thirty (30) days after receiving the request, subject to applicable legal, regulatory, contractual, and technical requirements. To the extent we process personal information on behalf of a customer, retention and deletion are also governed by our Data Processing Agreement.

Deletion removes personal information and information derived from it from our active systems. Residual copies may remain in routine backups until deleted through our standard backup cycle. We may retain limited information where required by law or subject to a legal hold.

We may retain account, transaction, communication, and other business records for as long as reasonably necessary to comply with applicable law, maintain appropriate business records, resolve disputes, and enforce our agreements. When personal information is no longer required, we delete or anonymize it.

13. Security

We maintain appropriate administrative, technical, and organizational safeguards designed to protect personal information against loss, destruction, alteration, unauthorized disclosure, or access. Access is limited to personnel and service providers with a business need who are subject to confidentiality and security obligations.We maintain procedures to identify and respond to security incidents. Where required by law, we will notify affected customers, individuals, and authorities of a personal data breach.

Additional security obligations are set forth in our Data Processing Agreement.

14. Changes to This Privacy Policy

The “Last Updated” date at the beginning of this Privacy Policy indicates when it was last revised.

We may update this Privacy Policy from time to time. We will post the updated Privacy Policy on our website and, where required by law, notify you of material changes at the email address you provided.

15. How to Contact Us

If you have questions about this Privacy Policy or our privacy practices, or wish to exercise your privacy rights, contact us at:

Vantis Decision Intelligence Inc.


25844 Cypress St, Lomita, CA 90717


Email: privacy@vantisdi.com


Telephone: 310-426-8584

If you are located in the EEA, you may lodge a complaint with the supervisory authority in the country where you live, work, or believe a violation occurred.

If you are located in the UK, you may lodge a complaint with the UK Information Commissioner's Office at www.ico.org.uk

If you are located in Switzerland, you may contact the Swiss Federal Data Protection and Information Commissioner at www.edoeb.admin.ch​