Privacy Policy
Working policy draft. Review with counsel before public launch.
Last Updated: December 3, 2025 · Effective Date: December 3, 2025
1. Overview
Milenial Procurments Inc. ("we," "us," or "our") operates the Milenial Compliance Platform, an AI-powered Compliance-as-a-Service (CaaS) solution and public SaaS document library. We are committed to protecting your privacy and handling your data with transparency and care. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, company name, job title, phone number
- Payment Information: Billing address, payment card details (processed securely by payment processors)
- Compliance Data: Documents, supplier information, procurement data, audit trails, compliance check results
- Communications: Support tickets, chat logs, email correspondence
- Profile Information: User preferences, notification settings, API keys
2.2 Information Collected Automatically
- Usage Data: IP address, browser type, device information, operating system
- Platform Activity: Feature usage, session duration, audit logs, compliance checks performed
- Cookies and Tracking: Authentication tokens, session IDs, analytics cookies
- AI Interaction Data: Anonymized compliance patterns and readiness assessment results
2.3 Information from Third Parties
- Integration Partners: Data from procurement platforms via API connections
- Authentication Providers: Information from Single Sign-On (SSO) services
- Government Databases: Public procurement data and compliance regulations where legally accessible
3. How We Use Your Information
3.1 To Provide and Maintain Our Services
- Process compliance checks and risk assessments
- Generate audit reports and documentation
- Maintain account security and authentication
- Provide customer support and troubleshooting
- Process payments and tier access
3.2 To Improve and Develop Our Platform
- Improve AI compliance guidance using anonymized data
- Analyze usage patterns to enhance user experience
- Develop new features and functionality
- Conduct security monitoring and threat detection
3.3 For Communication
- Send service notifications and updates
- Provide compliance alerts and deadline reminders
- Respond to support requests and inquiries
- Send administrative information (terms changes, policy updates)
3.4 Legal and Compliance Purposes
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service and other agreements
- Protect against fraudulent or illegal activity
- Exercise legal rights and defend claims
4. How We Share Your Information
4.1 With Your Consent
We share information when you direct us to, such as integrating with third-party platforms, sharing compliance reports with auditors, or collaborating within your organization.
4.2 With Service Providers
We engage trusted third parties for cloud infrastructure, payment processing, customer support, analytics, and email communications.
4.3 For Legal and Security Reasons
We may disclose information to comply with applicable laws, protect safety or property, enforce our Terms, or investigate security incidents or fraud.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.
5. Data Security
5.1 Security Measures
- Encryption: AES-256 for data at rest and TLS 1.2+ in transit
- Access Controls: Role-based access control and least privilege principles
- Network Security: Firewalls, intrusion detection systems, and DDoS protection
- Regular Audits: Third-party security assessments and penetration testing
- Employee Training: Security awareness and data handling procedures
5.2 Incident Response
In the event of a data incident, we will investigate and contain the issue, notify affected users as required by law, report to relevant authorities where required, and take steps to reduce recurrence.
6. Data Retention
6.1 Retention Periods
- Account Data: Retained while account is active plus periods needed for legal compliance
- Compliance Records: Retained per applicable procurement requirements
- Payment Records: Retained per financial regulations
- Usage Logs: Retained for security and analytics purposes
- Support Communications: Retained for support operations
6.2 Deletion
Upon account termination, personal data is deleted or anonymized within a defined period except where retention is required by law.
7. Your Rights
7.1 Access and Portability
You may request a copy of personal data, export compliance data in a portable format, and access account activity logs.
7.2 Correction and Deletion
You may correct inaccurate information and request deletion, subject to legal retention requirements.
7.3 Opt-Out Rights
You may unsubscribe from marketing communications and disable non-essential cookies.
7.4 California Privacy Rights (CCPA)
California residents may have additional rights under applicable law. See our California Privacy Notice.
8. International Data Transfers
Data may be transferred to and processed in the United States with appropriate safeguards in place.
9. Children's Privacy
The Platform is not intended for users under 18, and we do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes are communicated through appropriate channels.
11. Contact Us
- Email: privacy@milenialinc.com
- Data Protection Officer: dpo@milenialinc.com
- Mail: Milenial Procurments Inc., Privacy Office, 1181 Rock Elm Dr, Auburn, GA 30011