Privacy Policy

Last Updated: May 4, 2025

IMPORTANT NOTICE

This Privacy Policy describes how Pencive LLC collects, uses, shares, and protects your personal and financial information. Please read this Privacy Policy carefully before using our Service or submitting any information to us.

At Pencive LLC ("Pencive," "we," "our," or "us"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile applications, and services (collectively, the "Service"). Given the financial nature of our Service, we understand the sensitivity of the information you entrust to us and are committed to protecting your privacy and maintaining the security of your information.

1. INFORMATION WE COLLECT

We collect the following categories of information:

1.1 Personal Information

Personal Information is information that identifies, relates to, describes, or can be reasonably linked to a particular individual. We may collect the following types of Personal Information:

  • Contact Information: Name, email address, postal address, phone number.
  • Account Information: Username, password, account preferences, authentication data.
  • Demographic Information: Age, date of birth, gender, location.
  • Identity Verification Information: Social security number (last four digits), government-issued identification (when required for verification purposes).
  • User Content: Information you provide in feedback, testimonials, reviews, survey responses, or other communications with us.

1.2 Financial Information

Given the nature of our Service, we collect and process various types of financial information, which may include:

  • Account Information: Financial institution names, account types, account numbers (typically partially masked), account balances, account ownership information.
  • Transaction Information: Transaction dates, amounts, categories, merchant names, descriptions, and locations.
  • Financial Goals: Retirement planning objectives, savings goals, investment targets, and related financial preferences that you input into the Service.
  • Asset Information: Information about your investments, property holdings, and other assets that you choose to track through the Service.
  • Liability Information: Information about your debts, loans, and other liabilities that you choose to track through the Service.

1.3 Authentication Credentials

When you connect your financial accounts to our Service, you may provide us with credentials (such as usernames and passwords) for these accounts. We handle these credentials with the utmost security, as detailed in the "Data Security" section below.

1.4 Usage Information

We collect information about how you interact with our Service, including:

  • Access Information: Dates and times of access, page views, features used, and the referring website or application.
  • Device Information: Device type, operating system, browser type, browser settings, IP address, language settings, mobile device identifiers, and mobile network information.
  • Location Information: General location information derived from your IP address or more precise location information if you grant us permission through your device settings.
  • Log Data: Error reports, activity logs, and performance data.

1.5 Cookies and Similar Technologies

We use cookies, web beacons, pixels, and similar technologies to collect information about your browsing behavior, enhance your experience, and improve our Service.

These technologies may collect information such as your IP address, browser type, operating system, referring URLs, device information, pages visited, and time spent on the Service. We use this information to analyze trends, administer the Service, track users' movements around the Service, and gather demographic information about our user base as a whole.

Types of cookies we use:

  • Essential Cookies: Required for the Service to function properly. These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with our Service so we can improve it.
  • Preference Cookies: Allow us to remember your preferences and settings.
  • Marketing Cookies: Used to track users across websites for the purpose of displaying relevant advertisements.

You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse to accept cookies and to delete cookies. However, if you do not accept cookies, you may not be able to use some portions of our Service.

2. HOW WE COLLECT INFORMATION

We collect information through various methods, including:

2.1 Direct Collection

We collect information directly from you when you:

  • Register for an account or create a profile
  • Connect your financial accounts to the Service
  • Input financial information, goals, or preferences
  • Respond to surveys or provide feedback
  • Contact our customer support
  • Subscribe to our newsletters or marketing communications

2.2 Automated Collection

We automatically collect certain information when you use our Service, including:

  • Usage data through cookies and similar technologies
  • Device information when you access our Service
  • Log data generated by your use of the Service

2.3 Financial Connections

For certain features of our Services, we use secure third-party data aggregators such as Plaid ("Plaid") to facilitate connections to your financial accounts. When you connect your financial accounts through Plaid, you are also subject to Plaid's Privacy Policy.

2.4 Third-Party Collection

We may receive information about you from third parties, including:

  • Financial Institutions: We collect financial information from the financial institutions or third-party providers you authorize us to connect with.
  • Identity Verification Services: We may verify your identity through third-party identity verification services.
  • Analytics Providers: We use third-party analytics providers to help us understand how users interact with our Service.
  • Marketing Partners: We may receive information from marketing partners to enhance our marketing efforts.

3. HOW WE USE YOUR INFORMATION

We use the information we collect for various purposes, including:

3.1 Providing and Improving the Service

  • Creating and managing your account
  • Connecting to your financial accounts and retrieving financial information
  • Displaying your financial data and tracking your progress toward financial goals
  • Personalizing your experience and content
  • Analyzing and improving the functionality of our Service
  • Developing new features and services
  • Providing customer support and responding to your inquiries

3.2 Communications

  • Sending administrative communications about your account or the Service
  • Providing important notices and updates
  • Sending security alerts and transaction notifications
  • Delivering marketing communications, newsletters, and promotional materials (subject to your preferences and applicable law)
  • Conducting surveys and collecting feedback

3.3 Security and Compliance

  • Protecting against unauthorized access and ensuring data security
  • Detecting, preventing, and addressing fraud, abuse, or technical issues
  • Verifying your identity and authenticating access to your account
  • Complying with legal obligations, regulatory requirements, and law enforcement requests
  • Enforcing our Terms of Service, this Privacy Policy, and other agreements
  • Establishing, exercising, or defending legal claims

3.4 Analytics and Research

  • Analyzing usage patterns and trends
  • Measuring the effectiveness of our Service and marketing campaigns
  • Conducting research and development to enhance user experience
  • Generating aggregated, de-identified, or statistical data for various purposes, including research and business intelligence

4. HOW WE SHARE YOUR INFORMATION

We are committed to maintaining your trust, and we want you to understand when and with whom we may share your information. We do not sell your personal information.

4.1 Service Providers

We may share your information with third-party service providers who help us deliver and improve our Service, including:

  • Financial Data Aggregators: Service providers that help us connect to financial institutions and retrieve financial information. We partner with secure third-party data aggregators such as Teller.io ("Teller") to facilitate connections to your financial accounts. When you connect your financial accounts through Teller, you are also subject to Teller's Privacy Policy and Terms of Service.
  • Cloud Service Providers: Providers of cloud storage, hosting, and computing infrastructure.
  • Analytics Providers: Services that help us analyze how our Service is used.
  • Payment Processors: Companies that process payments for subscription services.
  • Customer Support Services: Providers of customer support and communication tools.
  • Marketing and Communication Services: Providers that help us deliver email communications and marketing campaigns.

These service providers are bound by contractual obligations to keep your information confidential and use it only for the purposes for which we disclose it to them.

4.2 Business Transfers

If Pencive is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information via email or through a prominent notice on our Service.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We may also disclose your information to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of Pencive
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

4.4 With Your Consent

We may share your information with third parties when you have given us your consent to do so. For example, we may ask for your permission to feature your testimonial or success story on our Service or marketing materials.

5. DATA SECURITY

Protecting your information is of the utmost importance to us. We implement robust security measures to protect your information, including:

5.1 Technical Safeguards

  • Encryption: We use industry-standard encryption technologies (such as TLS/SSL) to protect data in transit and at rest.
  • Authentication: We implement strong authentication mechanisms, including multi-factor authentication for sensitive operations.
  • Access Controls: We restrict access to personal information to authorized personnel on a need-to-know basis.
  • Monitoring: We continuously monitor our systems for potential security breaches and unauthorized access attempts.
  • Secure Development: We follow secure development practices and regularly test our systems for vulnerabilities.

8.2 Financial Connection Security

For connecting to your financial institutions, we use Plaid, a secure third-party data aggregator. Plaid is designed with security as a priority and uses bank-level security and encryption to protect your credentials and financial information.

When you connect your accounts through Plaid:

  • Plaid securely retrieves read-only data from your financial institutions
  • Your bank credentials are never stored on our servers
  • Plaid maintains their own security protocols and compliance with financial regulations

For more information about how Plaid handles your data, please review their Privacy Policy.

5.3 Data Security Limitations

While we implement appropriate security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee absolute security. You are responsible for:

  • Keeping your account credentials confidential
  • Using strong, unique passwords for your Pencive account
  • Enabling additional security features we offer, such as multi-factor authentication
  • Using secure networks when accessing our Service

5.4 Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify you and the appropriate regulatory authorities as required by applicable law. We will provide information about the breach and steps you can take to protect yourself from potential harm.

6. DATA RETENTION

We retain your information for as long as necessary to fulfill the purposes for which we collected it, including to provide you with the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

6.1 Account Information

We retain your account information for as long as your account is active. If you close your account, we will retain certain information associated with your account for:

  • Analytical purposes
  • Financial record-keeping
  • Compliance with legal obligations
  • Resolving disputes
  • Preventing fraud and abuse

6.2 Financial Information

We retain financial information retrieved from your connected accounts for as long as necessary to provide you with the Service. If you disconnect a financial account or close your Pencive account, we will delete or de-identify your financial information in accordance with our data retention policies and applicable laws.

6.3 Usage Information

We may retain de-identified or aggregated usage information for longer periods for legitimate business purposes, such as analyzing trends, improving our Service, and developing new features.

7. YOUR RIGHTS AND CHOICES

Depending on your location, you may have various rights regarding your personal information. These may include:

7.1 Access and Portability

You have the right to access the personal information we hold about you and, in some cases, receive a copy of this information in a structured, machine-readable format.

7.2 Correction

You have the right to correct inaccurate or incomplete personal information we hold about you.

7.3 Deletion

You have the right to request the deletion of your personal information in certain circumstances, such as when the information is no longer necessary for the purposes for which it was collected.

7.4 Restriction and Objection

You have the right to restrict or object to our processing of your personal information in certain circumstances.

7.5 Consent Withdrawal

Where we process your information based on your consent, you have the right to withdraw that consent at any time.

7.6 Exercising Your Rights

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within the timeframe required by applicable law.

Please note that certain legal and contractual obligations may limit your rights. For example, we may retain certain information for legal, security, or fraud-prevention purposes even if you request its deletion.

7.7 Account Settings

You can update certain personal information and privacy preferences directly through your account settings. These options may include:

  • Updating your profile information
  • Changing your password
  • Managing connected financial accounts
  • Adjusting notification preferences
  • Controlling marketing communications

7.8 Do Not Track

Some browsers feature a "Do Not Track" (DNT) setting that signals to websites that you do not want your online activity tracked. Because there is not yet a common understanding of how to interpret DNT signals, we do not currently respond to DNT signals on our Service.

8. INTERNATIONAL DATA TRANSFERS

Pencive is based in the United States, and we process and store information on servers located in the United States. If you are located outside the United States, your information may be transferred to, stored, and processed in a country where the privacy laws may not be as comprehensive as those in your country.

By using our Service, you consent to the transfer of your information to the United States and the processing of your information in the United States. Where required by applicable law, we implement appropriate safeguards for international data transfers, such as standard contractual clauses or other legal mechanisms.

9. CHILDREN'S PRIVACY

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to delete that information as quickly as possible.

If you believe we might have any information from or about a child under 18, please contact us immediately using the information provided in the "Contact Us" section below.

10. DATA CONTROLLER INFORMATION

For the purposes of applicable data protection laws, Pencive LLC is the data controller of your personal information. This means we determine the purposes and means of the processing of your personal information collected through the Service.

As a data controller, we are committed to respecting your data protection rights and handling your information responsibly and transparently. We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions regarding this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details provided in the "Contact Us" section.

11. AUTOMATED DECISION MAKING AND PROFILING

We may use automated decision-making processes, including profiling, for the following purposes:

  • Personalization: We may analyze your financial information and usage patterns to personalize your experience, including displaying relevant content, features, and recommendations.
  • Financial Insights: We may automatically categorize transactions, analyze spending patterns, and generate financial insights based on your financial information.
  • Security: We may use automated systems to detect and prevent fraudulent activities and security threats.

These automated processes help us provide you with a more relevant and secure experience. However, we do not make decisions that would have a significant impact on you based solely on automated processing without human oversight.

In jurisdictions where you have the right, you may:

  • Obtain human intervention in the decision-making process
  • Express your point of view regarding automated decisions
  • Obtain an explanation of the decision and challenge it

12. CROSS-BORDER DATA TRANSFERS

We may transfer your personal information to countries other than the one in which you reside. We primarily store and process data in the United States, but we may engage service providers or operate infrastructure in other countries.

When we transfer personal information outside of your country of residence, we implement appropriate safeguards to ensure your information receives an adequate level of protection. These safeguards may include:

  • Standard Contractual Clauses: We may use approved standard contractual clauses for data transfers to third countries.
  • Privacy Shield: We may rely on the EU-U.S. or Swiss-U.S. Privacy Shield Frameworks for certain transfers, where applicable.
  • Binding Corporate Rules: We may adopt and implement binding corporate rules for transfers within our corporate group.
  • Consent: We may transfer your data based on your explicit consent to the proposed transfer, where permitted by law.

For more information about these safeguards or to obtain a copy of them, you can contact us using the information provided in the "Contact Us" section.

13. DATA PROCESSING AGREEMENTS

When we engage third-party service providers to process personal information on our behalf, we enter into data processing agreements that require these providers to:

  • Process personal information only in accordance with our documented instructions
  • Implement appropriate technical and organizational measures to protect personal information
  • Assist us in responding to data subject requests and meeting our obligations under applicable data protection laws
  • Delete or return all personal information at the end of the service provision
  • Submit to audits and inspections to verify compliance with data protection obligations
  • Notify us of any data breaches without undue delay

We carefully select our service providers to ensure they provide sufficient guarantees to implement appropriate technical and organizational measures to meet the requirements of applicable data protection laws.

14. THIRD-PARTY LINKS AND SERVICES

Our Service may contain links to third-party websites, services, or applications that are not owned or controlled by Pencive. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We strongly advise you to review the privacy policy of every website you visit.

If you connect your Pencive account with a third-party service, we may receive information from that service. This Privacy Policy does not apply to information collected by third parties, and we encourage you to read their privacy policies.

15. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.

For material changes to this Privacy Policy, we will make reasonable efforts to provide notice before the changes take effect, such as through a prominent notice on our Service or by sending you an email. We encourage you to review this Privacy Policy periodically for any changes.

Your continued use of the Service after we post changes to this Privacy Policy means you accept those changes.

16. CALIFORNIA PRIVACY RIGHTS

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information. This section describes your CCPA/CPRA rights and explains how to exercise those rights.

16.1 Access and Data Portability Rights

You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months.

16.2 Deletion Request Rights

You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions.

16.3 Correction Request Rights

You have the right to request that we correct inaccurate personal information that we maintain about you.

16.4 Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. Unless permitted by the CCPA/CPRA, we will not:

  • Deny you goods or services.
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  • Provide you a different level or quality of goods or services.
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

16.5 Exercising Your California Privacy Rights

To exercise your rights described above, please submit a verifiable consumer request to us by contacting us using the information provided in the "Contact Us" section below. Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information.

You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative and describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

We will respond to your request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing.

17. CONTACT US

If you have any questions about this Privacy Policy or our privacy practices, please contact us using the following methods:

Email:

privacy@pencive.com

For Data Subject Rights Requests:

Please email privacy@pencive.com with the subject line "Privacy Request."

Accessibility

We are committed to ensuring that our Privacy Policy is accessible to individuals with disabilities. If you require this Privacy Policy in an alternative format due to a disability, please contact us at accessibility@pencive.com, and we will provide you with the information in a format that meets your needs.

18. ADDITIONAL DATA SECURITY MEASURES

Given the sensitive nature of financial information, we implement robust security measures beyond the standard practices mentioned earlier:

18.1 Encryption Standards

We use industry-leading encryption standards to protect your data:

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • End-to-end encryption for sensitive financial data transmission
  • Encrypted database backups

18.2 Infrastructure Security

Our infrastructure security includes:

  • Regular security audits and penetration testing by independent security firms
  • Continuous vulnerability scanning and remediation
  • Intrusion detection and prevention systems
  • Real-time monitoring and alerting for suspicious activities
  • Geographically distributed, redundant data centers with physical security measures

18.3 Access Controls

We implement strict access controls:

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication for employee access to production systems
  • Principle of least privilege for all system access
  • Regular access reviews and prompt revocation of access upon employee departure
  • Detailed access logs with tamper-proof storage

18.4 Employee Security

Our employee security practices include:

  • Background checks for all employees who may access sensitive data
  • Regular security awareness training and testing
  • Confidentiality agreements with all employees and contractors
  • Clear desk and clear screen policies

19. EUROPEAN UNION DATA PROTECTION RIGHTS

If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). These rights include:

  • Right to Access: You have the right to request copies of your personal data.
  • Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
  • Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
  • Right Not to Be Subject to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

If you wish to exercise any of these rights, please contact us using the information provided in the "Contact Us" section. We will respond to your request within one month, which may be extended by up to two additional months where necessary, taking into account the complexity and number of requests.

You also have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for Pencive is the Delaware Department of Justice, Division of Consumer Protection, though you may contact your local data protection authority.

19.1 Legal Basis for Processing

We only process your personal data when we have a legal basis to do so. The legal bases we rely on include:

  • Consent: You have given clear consent for us to process your personal data for a specific purpose.
  • Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
  • Legal Obligation: Processing is necessary for us to comply with the law.
  • Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.

20. UK DATA PROTECTION RIGHTS

If you are a resident of the United Kingdom, your personal data is protected under the UK GDPR and the Data Protection Act 2018. You have similar rights to those described in the European Union Data Protection Rights section, including the right to access, rectify, erase, restrict processing, object to processing, and data portability.

The UK Information Commissioner's Office (ICO) is the supervisory authority for data protection issues in the UK. You have the right to lodge a complaint with the ICO if you believe that we have not complied with the requirements of the UK data protection legislation.

21. GLOSSARY OF TERMS

To help you understand this Privacy Policy, we've defined some key terms:

  • Personal Information/Personal Data: Any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, or an online identifier.
  • Processing: Any operation performed on personal data, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
  • Data Controller: The entity that determines the purposes and means of processing personal data. Pencive LLC is the data controller for personal information collected through our Service.
  • Data Processor: An entity that processes personal data on behalf of the data controller. Our service providers are data processors for Pencive.
  • Data Subject: An identified or identifiable natural person to whom personal data relates. Users of our Service are data subjects.
  • Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of their personal data.
  • Legitimate Interest: A lawful basis for processing personal data where the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, rights, or freedoms of the data subject.
  • Special Categories of Personal Data: Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a natural person's sex life or sexual orientation.
  • Cookies: Small text files placed on your device that allow websites to remember your preferences, track your activities, and enable certain features to work.

22. FINANCIAL DATA REGULATIONS

As a provider of financial data aggregation services, we comply with various financial regulations that may apply to our collection, processing, and storage of financial information. These include:

22.1 Gramm-Leach-Bliley Act (GLBA)

The GLBA requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data. As a financial technology company that processes financial information, we adhere to GLBA requirements, including:

  • Providing this Privacy Policy to explain how we collect, use, and protect your financial information
  • Implementing comprehensive safeguards to protect the security and confidentiality of your financial information
  • Ensuring that our service providers maintain appropriate safeguards for your financial information

22.2 Consumer Financial Protection Bureau (CFPB) Regulations

We monitor and comply with applicable CFPB regulations regarding financial data access, consumer financial data rights, and data security requirements.

22.3 Third-Party Financial Data Integration

For connecting to your financial institutions, we use Teller.io, a secure third-party data aggregator. Teller.io is designed with security as a priority and uses bank-level security and encryption to protect your credentials and financial information.

When you connect your accounts through Teller.io:

  • Teller.io securely retrieves read-only data from your financial institutions
  • Your bank credentials are never stored on our servers
  • Teller.io maintains their own security protocols and compliance with financial regulations
  • You can revoke access to your financial accounts at any time through your account settings

For more information about how Teller.io handles your data, please review their Privacy Policy and Terms of Service.

22.4 Bank Secrecy Act and Anti-Money Laundering Requirements

Where applicable, we comply with requirements related to anti-money laundering (AML) and countering the financing of terrorism (CFT), which may include:

  • Implementing Know Your Customer (KYC) procedures
  • Monitoring for suspicious activities
  • Maintaining records as required by law

23. DATA BREACH NOTIFICATION PROCEDURES

We take the security of your information seriously and have established comprehensive procedures to address potential data breaches:

23.1 Breach Detection and Response

We have implemented systems to detect potential security incidents and data breaches. Upon detection of a breach or suspected breach, we will:

  • Activate our incident response team to investigate and contain the breach
  • Assess the nature and scope of the breach, including the types of information involved and the risk of harm to affected individuals
  • Take steps to mitigate any potential harm to affected individuals
  • Document the breach and our response actions

23.2 Notification Timeline

If we determine that a breach has occurred that requires notification under applicable law, we will notify affected individuals and relevant regulatory authorities within the timeframes required by law, which may vary depending on the jurisdiction. For example:

  • Under the GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible
  • Under various U.S. state laws, notification timeframes may range from 30 to 60 days

23.3 Notification Content

Our breach notifications will include, to the extent known:

  • A description of the breach
  • The types of information involved
  • Steps we are taking to investigate, mitigate harm, and protect against further breaches
  • Steps individuals can take to protect themselves
  • Contact information for questions or additional information

24. DOCUMENT HISTORY

We maintain a record of changes to this Privacy Policy to help you understand how our privacy practices have evolved:

May 4, 2025:

Initial Privacy Policy published.

Effective Date: May 4, 2025

© 2025 Pencive LLC. All rights reserved.