Privacy Notice
How GrantPilot collects, uses, shares, retains, and protects personal data. Operational draft pending counsel approval and publication of the controller’s registered address.
1. Who is responsible
Ironhand Technology and Consulting LLC operates the controlled U.S. GrantPilot MVP. Privacy contact: support@ironhand.org. The operator’s registered address and applicable U.S. state disclosures must be inserted before commercial production.
2. Data we collect
Account and contact data; company profiles and memberships; grant opportunities, applications, documents, correspondence, tasks, approvals, billing and support records; authentication and security events; device, IP-derived security, usage, diagnostic, and audit data; and content intentionally connected through authorized providers. We do not intentionally collect children’s data.
3. Sources of data
We receive data directly from users and authorized organization members; from configured mailboxes, storage, portals, and other connectors; from official or publicly available grant sources; and automatically from service use, security controls, and device interactions. Do not connect a source unless you have authority to do so.
4. Purposes and legal grounds
We process data to provide and secure the service, authenticate users, isolate tenants, discover and prepare grants, manage documents and correspondence, process billing, provide support, meet legal obligations, prevent abuse, and improve reliability. Depending on jurisdiction, grounds may include contract performance, consent, legitimate interests, and legal obligations. Sensitive or optional processing must use appropriate authorization.
5. AI and automated processing
Authorized content may be processed to retrieve evidence, classify records, identify possible matches, extract fields, translate, and draft material. Imported content is treated as untrusted. GrantPilot does not make final grant, employment, credit, insurance, or similarly consequential decisions. Users receive explanations, warnings, correction controls, and human approval gates. Customer content is not sent to a production AI/OCR/embedding provider until the provider and data policy are approved and configured.
6. Sharing and international transfers
We share data only with authorized users; processors needed for hosting, storage, communications, security, analytics, billing, and configured AI/connectors; professional advisers; or authorities when legally required. Provider identity, region, transfer safeguards, and subprocessors must be documented before activation. We do not sell personal data or share it for cross-context behavioral advertising.
7. Retention and deletion
Retention follows tenant settings, legal holds, contracts, security needs, and applicable law. Account, audit, approval, submission, billing, and backup records may have different periods. Deletion requests enter a verified workflow; legal holds and required records take precedence. Backups expire through controlled rotation rather than immediate selective deletion.
8. Security
Controls include tenant authorization, encryption, hashed credentials/tokens, MFA/passkeys, malware scanning, audit trails, bounded provider access, secret references, backups, monitoring, and incident procedures. No system is risk-free. Report suspected incidents to support@ironhand.org and do not include credentials in email.
9. Your choices and rights
You may access and correct profile data, manage provider connections and communication preferences, export data, and request deletion through authenticated workflows. U.S. state residents may have access, correction, deletion, portability, opt-out, appeal, and nondiscrimination rights depending on the law and its applicability. We verify identity and authority before acting.
10. Privacy requests
Send a request to support@ironhand.org with your name, organization, right requested, affected data, state of residence, and a safe contact method. Do not email passwords, tax IDs, or full identity documents. We will provide a secure verification channel and respond within applicable periods. Authorized agents must establish authority.
11. Service communications
We send operational messages needed for authentication, security, connected-mailbox activity, applications, deadlines, approvals, support, and material policy changes. Where marketing messages are introduced, they must be separately identified and provide the controls required by applicable law.
12. Cookies and changes
We use essential session and security cookies. Optional analytics/marketing cookies are disabled unless separately disclosed and consented where required. Material notice changes receive a new version and effective date.