Ethical Competitive Intelligence with Zero-Knowledge Privacy Protection
Our privacy-first architecture ensures we cannot access your strategic data, while our ethical collection practices respect both your privacy and your competitors' rights.
Last Updated: October 8, 2024 • Built with Zero-Knowledge Architecture • SOC 2 Type II Certified
🎯 Our Privacy Philosophy
At Predixy, we believe competitive intelligence should be ethical, transparent, and privacy-first.
Zero-Knowledge Architecture
We cannot access your strategic competitive intelligence - it's encrypted before leaving your browser
Ethical Collection
Only publicly available information, respecting robots.txt and website owner preferences
Enterprise Security
SOC 2 Type II certified with GDPR and CCPA compliance built-in
📊 What Data We Collect and Why
✅ What We Monitor:
- • Public Website Behavior - DOM changes, JavaScript frameworks, CSS modifications
- • A/B Testing Indicators - Platform detection signals, variant identification
- • Technical Architecture - Publicly available technology stack information
- • User Experience Changes - Layout modifications, content variations, flow changes
❌ What We DO NOT Collect:
- • Personal Information (PII) - No names, emails, addresses, phone numbers
- • User Behavior Data - No individual visitor tracking or analytics
- • Private Information - No passwords, payment data, or confidential content
- • Unauthorized Access - No login attempts or behind-paywall content
⚖️ Legal Basis:
2) Our Public‑Data Focus
- Our analysis targets publicly accessible pages and publicly exposed signals (e.g., scripts, markup, non‑authenticated content, observable UI differences).
- We do not require login to third‑party sites, do not ask for credentials for target websites, and do not intentionally process non‑public or confidential information.
- If the Service incidentally receives personal information, we seek to promptly delete or de‑identify it.
3) Information We Collect
- Account & Workspace Data: Email address, name, company, authentication state, plan, usage counters, and related metadata you provide.
- Service Logs: Device/browser info, IP address, timestamps, request/response metadata, diagnostic logs for reliability and security.
- Scan Artifacts: Publicly available page screenshots, DOM snippets, and derived metrics. We apply retention limits consistent with your plan or BETA defaults.
- Support Communications: Content you choose to share with us.
4) How We Use Information
- Provide, operate, secure, and improve the Service.
- Enable features (e.g., experiment detection, screenshots) restricted to public content.
- Detect, prevent, and address fraud, abuse, or security incidents.
- Comply with legal requirements and enforce agreements.
- Develop aggregated, de‑identified insights to improve accuracy and performance.
5) Legal Bases
Depending on your location, we rely on one or more legal bases: your consent; performance of a contract; legitimate interests (e.g., service integrity, product development); and compliance with legal obligations.
7) Retention
We retain personal information no longer than necessary for the purposes described and to meet legal obligations. BETA defaults may apply stricter limits to scan artifacts and logs. You may request deletion subject to legal exceptions.
8) Security
We implement reasonable technical and organizational safeguards (e.g., access controls, encryption in transit, least‑privilege). No method of transmission or storage is perfectly secure; use the Service accordingly.
9) California Privacy Rights (CCPA/CPRA)
- Categories Collected: Identifiers (email, IP), internet activity (logs), and limited geolocation (approximate from IP). Sensitive personal information is not required, and we limit processing where incidentally received.
- Purposes: Provide and secure the Service, improve features, and comply with law.
- No Selling or Sharing: We do not sell/share personal information for cross‑context behavioral advertising.
- Your Rights: Right to know/access, delete, correct, limit sensitive PI, and non‑discrimination. Submit requests at privacy@predixy.ai. We will verify requests consistent with law and respond within required timelines.
10) India – DPDP 2023 Disclosures
- Notice & Consent: We provide notice of purposes and obtain consent where required. You may withdraw consent by contacting us; withdrawal will not affect prior lawful processing.
- Data Principal Rights: Access, correction, erasure, grievance redressal, and nomination in accordance with the DPDP. Contact: grievance@predixy.ai.
- Grievance Officer: We designate a grievance officer reachable at the address above and endeavor to resolve complaints within reasonable timelines.
- Cross‑Border Transfers: We may transfer personal data internationally subject to applicable restrictions and safeguards.
11) Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us to request deletion.
12) Your Choices and Controls
- Account settings allow changes to profile details. You may request access/deletion via privacy@predixy.ai.
- Scanning targets: configure scans to include only publicly accessible pages; avoid login‑only or paywalled areas.
- Opt‑out of marketing communications by using unsubscribe links or contacting us.
13) Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new effective date. Your continued use of the Service after changes become effective constitutes acceptance.
14) Contact
Privacy Questions: privacy@predixy.ai. Grievance (India): grievance@predixy.ai. General Legal: legal@predixy.ai.