Skip to content
itogai Back to itogai.app ↗
itogai·Legal·Privacy Policy

Data & privacy

Privacy Policy

Effective May 11, 2026Last modified May 11, 2026Version PP-2026-05-11 v2.0

This Privacy Policy describes how Itogai LLC, a Florida limited liability company with its principal office in Lake Worth, Florida, United States of America (“itogai,” “we,” “us,” or “our”), collects, uses, shares, retains, and protects Personal Data, and explains the rights of individuals whose Personal Data we process.

This Privacy Policy applies to:

  • the itogai Subscription Service (the “Subscription Service”), accessed at platform.itogai.app;
  • the itogai Marketing Website at itogai.app and its sub-domains (the “Marketing Website”);
  • the Trustbound™ Revenue Program and other Professional Services described in our Customer Terms of Service; and
  • our other relationships with prospective customers, accelerator partners, podcast guests, event attendees, and the general public.

If you have questions about this Privacy Policy or how we process Personal Data, write to privacy@itogai.com.

On this page

  1. 1.Introduction, Who We Are, and Our Roles
  2. 2.Personal Data We Collect
  3. 3.Data Sources and How We Receive Data
  4. 4.How We Use Personal Data
  5. 5.The itogai Data Architecture
  6. 6.Google API Limited Use Disclosure
  7. 7.How We Share Personal Data
  8. 8.Service Providers and Sub-processors
  9. 9.International Data Transfers
  10. 10.Data Retention and Deletion
  11. 11.Security
  12. 12.Your Privacy Rights
  13. 13.Third-Party Sites and Services
  14. 14.Cookies and Similar Technologies
  15. 15.Children’s Privacy
  16. 16.Changes to This Policy
  17. 17.Region-Specific Disclosures
  18. 18.How to Contact Us

1. Introduction, Who We Are, and Our Roles

1.1 Who We Are. itogai is a relationship-intelligence platform. We help our customers (typically founders, sales leaders, and professionals) understand, organize, and act on their professional networks through the TrustGraph™ scoring algorithm, TrustCircles™ network organization, TrustReach™ warm-network action layer, and Akai™, our relationship-intelligence co-pilot.

1.2 Our Roles Under Data-Protection Law.

  • For information about our customers, our Marketing Website visitors, our event attendees, our podcast audience, and other prospective customers, itogai acts as a controller (under the GDPR, UK GDPR, and Swiss FADP), as a business (under the CCPA), and as a controller (controlador, under the LGPD).
  • For Customer Data that our customers import or that we receive from authorized Data Sources on our customers’ behalf, itogai generally acts as a processor (under the GDPR, UK GDPR, and Swiss FADP), as a service provider (under the CCPA), and as a processor (operador, under the LGPD). In those cases, our processing is governed by our Customer Terms of Service and, where executed, our Data Processing Agreement.

2. Personal Data We Collect

The categories of Personal Data we collect depend on how you interact with itogai.

2.1 Account Data. Information you provide when you create an Account or invite Users, including name, work email address, employer, role, time zone, and authentication credentials (for example, OAuth tokens issued by Google or Microsoft).

2.2 Billing Data. Information necessary to bill you for the Subscription Service, including billing entity name, billing contact, billing address, country of legal-entity headquarters (relevant for region-adjusted pricing eligibility), and tax identifiers. Payment-card and bank-account information is collected and processed by Stripe, Inc. as our payment processor. itogai does not store payment-card or bank-account information.

2.3 Usage Data. Information about how you interact with the Subscription Service and the Marketing Website, including pages or screens viewed, features used, Spark consumption, date and time of activity, referrer URLs, and similar telemetry.

2.4 Device and Log Data. Technical information collected automatically, including IP address, browser type and version, operating system, device identifiers, language preference, and access logs.

2.5 Communications. The content of messages you send to itogai (for example, by writing to support inboxes such as info@itogai.com, legal@itogai.com, privacy@itogai.com, or demo@itogai.com), responses to surveys, and inputs to in-product feedback channels.

2.6 Customer Data. Information that you or your Users submit, upload, import, or authorize itogai to read from a connected Data Source, including:

  • contact records (names, email addresses, phone numbers, employer, role, location);
  • relationship metadata derived from email, calendar, and messaging activity (sender, recipient, timestamp, subject line, and similar fields);
  • structured signals derived from content channels (for example, sentiment and engagement signals derived from message bodies, then discarded as described in Section 5); and
  • enrichment data added through enrichment services authorized by you (Section 3).

2.7 Data About Non-Users. When you import a contact record or authorize a Data Source, itogai may receive Personal Data about individuals who are not themselves Users of the Subscription Service. We process such data on your behalf and in accordance with Section 12.6.

2.8 Enriched Data. itogai may enrich contact records with publicly available business information through licensed enrichment providers (Section 3 and Section 8).

2.9 What We Do Not Collect. itogai does not knowingly collect, and asks Customers not to submit, the following categories of data: protected health information under HIPAA; payment-card data subject to PCI-DSS (other than what Stripe collects in connection with payment processing); social-security or government-issued identifiers; biometric data; precise geolocation; or information about children under sixteen (16). itogai is not a HIPAA-covered entity or business associate.

3. Data Sources and How We Receive Data

itogai receives Personal Data directly from you, automatically through your use of the Subscription Service, and from authorized third-party Data Sources you connect.

Data Source What We Read How
Google Workspace (Gmail, Calendar) Message metadata (sender, recipient, timestamp, subject), calendar attendees and times Restricted-scope OAuth, metadata-only
Microsoft 365 (Outlook, Calendar) Equivalent message metadata and calendar data OAuth
Slack Channel and direct-message metadata; message bodies are processed and discarded OAuth
HubSpot Contact, company, deal, and engagement data OAuth
Day.ai Meeting summaries and call transcripts (transcripts processed and discarded) OAuth
Zoom Meeting attendees and call metadata OAuth
LinkedIn Connection data the Customer exports from LinkedIn and uploads as a CSV Customer-initiated upload only
People Data Labs (PDL) Publicly available business contact data used to enrich existing contacts in the Customer’s network API call initiated by the Customer
Public news and content APIs Publicly available news and content references about contacts, used to surface relationship signals API call initiated by the Subscription Service on the Customer’s behalf

itogai requests only the OAuth scopes necessary to provide the Subscription Service, and you may revoke any third-party authorization at any time as described in Section 13.

4. How We Use Personal Data

We use Personal Data for the purposes described below. The legal bases under the GDPR, UK GDPR, and LGPD are noted in parentheses.

4.1 Provide the Subscription Service. To create and operate Accounts; to compute TrustGraph™ scores, TrustCircles™ assignments, and TrustReach™ recommendations; to deliver Professional Services; and to enable User-initiated network actions. (Performance of a contract; legitimate interests; consent where required.)

4.2 Bill and Manage Payments. To bill Customers for the Subscription Service and Professional Services, to verify region-adjusted pricing eligibility, and to administer refunds. (Performance of a contract; legal obligation.)

4.3 Communicate with You. To respond to support requests; to send transactional messages (account notifications, security alerts, billing notifications); and, where you have opted in, to send marketing or product update messages. You can unsubscribe from marketing messages at any time. (Performance of a contract; legitimate interests; consent for marketing where required.)

4.4 Improve and Develop the Subscription Service. To analyze how the Subscription Service is used, to identify and fix issues, to model and improve the TrustGraph™ scoring algorithm, and to develop new features. We use aggregated and de-identified data wherever feasible. (Legitimate interests; consent where required.)

4.5 Security and Fraud Prevention. To monitor for, prevent, investigate, and respond to security incidents, abuse, fraud, and unauthorized access. (Legitimate interests; legal obligation.)

4.6 Comply with Law and Enforce Rights. To comply with applicable law, lawful requests by public authorities, and our legal obligations; to enforce our agreements; and to protect the rights, property, or safety of itogai, our customers, or others. (Legal obligation; legitimate interests.)

4.7 No Use of Customer Data for Advertising or Model Training. We do not use Customer Data, including data received from any restricted Google API scope, for advertising or for training generalized AI or machine-learning models. See Section 6 for our Google API Limited Use commitments.

5. The itogai Data Architecture

5.1 Metadata-Only Architecture for Restricted Google API Scopes. For Data Sources that include restricted Google API scopes (including Gmail), itogai operates a metadata-only architecture: we read and store only message metadata (sender, recipient, timestamp, subject line, and similar fields) necessary to compute relationship signals. We do not store the body of email messages. This architecture is the subject of itogai’s App Defense Alliance Tier 2 CASA (Cloud Application Security Assessment) verification.

5.2 Process-and-Discard Architecture for Content Channels. For Data Sources that include content channels (for example, Slack message bodies, replies to messages our customers’ Users send through TrustReach™, and Day.ai call transcripts), itogai operates a process-and-discard architecture: we temporarily process raw content for the limited purpose of extracting relationship signals (for example, sentiment, topic, and engagement signals), and then permanently delete the raw content. Only the structured, derivative signals are retained in your TrustGraph™.

5.3 Encryption. itogai encrypts data at rest and in transit using industry-standard encryption (currently AES-256 for data at rest and TLS 1.2 or higher for data in transit). itogai may update the specific encryption algorithms or protocols from time to time, provided that any update does not materially decrease the overall level of security.

5.4 Tenant Isolation. itogai operates a multi-tenant architecture with logical tenant isolation. Customer Data is logically segregated from the data of other customers.

5.5 Akai™ and Generative-AI Processing. Akai™, our relationship-intelligence co-pilot, and other generative-AI features of the Subscription Service, process Personal Data on a strictly bounded basis. Akai™ uses your Customer Data to (a) draft messages for your review, (b) surface warm-introduction paths, (c) generate context briefs and summaries, and (d) answer questions you ask about your network. Akai™ does not send messages on your behalf. Every outbound message that Akai™ drafts must be reviewed and explicitly clicked-to-send by you or another authorized User before it is delivered. Akai™ relies on the generative-AI sub-processors listed in our Sub-processors page (currently Anthropic, PBC and OpenAI, L.L.C.), each of which is engaged under an AI-training opt-out: those providers do not use itogai data to train their general-purpose models. Akai™ and the other generative-AI features operate under the rules in our Customer Terms of Service Section 7.5 and the Acceptable Use Policy Section 2.

6. Google API Limited Use Disclosure

itogai’s use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  1. We use Google user data only to provide or improve the user-facing features of the Subscription Service that are visible to and prominent in our application.
  2. We do not transfer Google user data to others except as necessary to provide or improve the user-facing features that are visible to and prominent in our application; to comply with applicable law; or as part of a merger, acquisition, or sale of assets, in each case after we obtain the user’s explicit consent or as otherwise permitted by Google.
  3. We do not use Google user data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
  4. We do not allow humans to read Google user data, except (a) with the user’s affirmative agreement for specific messages; (b) when necessary for security purposes (for example, investigating abuse); (c) when necessary to comply with applicable law; or (d) when the data is aggregated and used for internal operations and only in accordance with applicable privacy policies.
  5. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine-learning models, and we do not transfer such data to third parties for that purpose. We also do not use such data to develop, improve, or train non-personalized AI or machine-learning models.

itogai’s Google API integration uses a metadata-only architecture for restricted scopes, as described in Section 5.1. Body content of email messages is not stored. itogai’s compliance with the Google API Services User Data Policy is the subject of our App Defense Alliance Tier 2 CASA verification.

7. How We Share Personal Data

We share Personal Data in the limited circumstances described below. We do not sell Personal Data, and we do not share Personal Data for cross-context behavioral advertising.

7.1 With Service Providers and Sub-processors. We share Personal Data with the service providers listed in Section 8, who process Personal Data on our behalf under written agreements that limit their use of the data to the services they provide to us.

7.2 With Other Users in Your Organization. Customer Data submitted under a Customer Account is accessible to Users authorized by that Customer Account, in accordance with the role-based access controls configured by the Account Owner.

7.3 With Third Parties You Authorize. We share Personal Data with third parties that you authorize, including third-party Data Sources you connect.

7.4 For Legal Reasons. We may disclose Personal Data where we believe in good faith that disclosure is necessary to (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our agreements; (c) protect the security or integrity of the Subscription Service; or (d) protect the rights, property, or safety of itogai, our customers, or others.

7.5 In a Business Transaction. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, Personal Data may be transferred to the acquiring entity, subject to the same protections set out in this Privacy Policy or to a notice of any changes.

7.6 With Your Consent. We may share Personal Data for any other purpose with your consent.

8. Service Providers and Sub-processors

itogai engages the service providers listed below to help operate the Subscription Service. Each provider is bound by a written agreement that limits its processing of Personal Data to the services it provides to us. The list is current as of the Effective Date and may be updated as described in Section 16.

Sub-processor Purpose Location
Vercel, Inc. Application hosting and edge delivery United States
Cloudflare, Inc. Content delivery network and DDoS protection United States (global edge)
Supabase, Inc. and Neon, Inc. Managed relational database hosting United States, European Union
Auth0 (Okta, Inc.) Authentication and identity management United States
Stripe, Inc. Payment processing United States
Brevo (Sendinblue SAS) Transactional email delivery European Union
Nylas, Inc. Email and calendar API integration United States
Anthropic, PBC Generative-AI model inference; AI training opt-out in effect for itogai data United States
OpenAI, L.L.C. Generative-AI model inference; AI training opt-out in effect for itogai data United States
People Data Labs, Inc. Contact enrichment based on publicly available business data United States
Amplitude, Inc. Product analytics United States
Sentry (Functional Software, Inc.) Application error monitoring United States

We may engage additional sub-processors from time to time. Material additions of new sub-processor categories will be communicated as described in Section 16.

9. International Data Transfers

itogai is based in the United States. Personal Data we process may be transferred to and processed in the United States and in other countries where itogai or our service providers operate. These countries may have data-protection laws that differ from those in your country.

9.1 Transfers from the European Economic Area, the United Kingdom, and Switzerland. When we transfer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of data protection, we rely on (a) the European Commission’s Standard Contractual Clauses (Module Two for controller-to-processor transfers and Module Four for processor-to-controller transfers, as applicable); (b) the United Kingdom International Data Transfer Addendum to the SCCs; and (c) where applicable, the Swiss Data Protection and Information Commissioner-approved transfer mechanism.

9.2 Transfers from Brazil. Transfers of Personal Data from Brazil rely on the legal bases set out in Article 33 of the Lei Geral de Proteção de Dados (LGPD), including the use of standard contractual clauses, the necessity of the transfer for the performance of a contract with the data subject, and the consent of the data subject where applicable.

9.3 Other Jurisdictions. Where applicable, we use other transfer mechanisms permitted under local law.

10. Data Retention and Deletion

We retain Personal Data only for as long as necessary to provide the Subscription Service and to fulfill the purposes set out in this Privacy Policy, including legal, accounting, and reporting obligations.

10.1 General Principle. We retain (a) Account Data and Billing Data for the duration of the customer relationship and for a reasonable period thereafter; (b) Customer Data for the duration of the customer relationship, subject to the deletion windows below; and (c) Usage Data, Device Data, and Log Data for a rolling period necessary for security, analytics, and product-improvement purposes.

10.2 Account Termination Data Export Window. Upon termination of an Account, itogai will, for thirty (30) days following the termination, make Customer Data available for export by the Customer, after which itogai may permanently delete Customer Data, subject to backup retention described in Section 10.5.

10.3 Disconnection of a Data Source. If you disconnect a Data Source, itogai will cease reading new data from that Data Source immediately. Metadata and structured signals previously derived from that Data Source during periods of authorized access are retained as part of the Customer’s TrustGraph™ unless and until you delete them or terminate the Account. Raw content that was part of the process-and-discard pipeline (Section 5.2) is, by design, not retained at any point. Within seven (7) days of disconnection, we delete cached metadata that has not been incorporated into the structured TrustGraph™.

10.4 Account Deletion. Upon a verified deletion request from the Account Owner, itogai will delete the Customer Data and Account Data within thirty (30) days, subject to backup retention and any legal obligations to retain.

10.5 Backups. Backups of Customer Data are retained for ninety (90) days for disaster-recovery purposes and are then overwritten on rolling schedules.

10.6 Legal Holds. We may retain Personal Data longer where necessary to comply with applicable law, to resolve disputes, to enforce our agreements, or to defend legal claims.

11. Security

itogai maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction.

11.1 Technical Controls. Our technical controls include industry-standard encryption in transit (currently TLS 1.2 or higher) and at rest (currently AES-256), role-based access controls, multi-factor authentication for itogai personnel, audit logging, network segmentation, and tenant isolation. itogai may update the specific encryption algorithms or protocols from time to time, provided that any update does not materially decrease the overall level of security.

11.2 Operational Controls. Our operational controls include least-privilege access for itogai personnel, periodic access reviews, vendor security reviews, and an incident-response procedure.

11.3 CASA Verification. itogai is App Defense Alliance Tier 2 CASA-verified, an independent security assessment that examines the security controls supporting our Google API integrations and the metadata-only architecture described in Section 5.1.

11.4 What We Do Not Claim. itogai is not, as of the Effective Date of this Privacy Policy, certified under SOC 2 Type II or ISO/IEC 27001. itogai is a small bootstrapped company and our security program is calibrated to the categories and volume of data we process. We track these certifications as future roadmap items but do not represent that we hold them today.

11.5 Reporting a Security Issue. If you believe you have discovered a security vulnerability in the Subscription Service, please write to legal@itogai.com. We will acknowledge receipt and work in good faith to investigate and remediate.

11.6 No Method Is Perfect. No method of transmission or storage is one-hundred-percent secure. While we work hard to protect Personal Data, we cannot guarantee absolute security.

12. Your Privacy Rights

Depending on your jurisdiction and your relationship with itogai, you have the rights described below. To exercise any right, write to privacy@itogai.com.

12.1 Universal Rights. Regardless of jurisdiction, you may request access to or deletion of Personal Data we hold about you, ask us to correct inaccurate Personal Data, and ask us to stop sending you marketing communications.

12.2 GDPR and UK GDPR. If the GDPR or UK GDPR applies to our processing of your Personal Data, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We respond to verifiable requests within thirty (30) days, with a possible extension where permitted by law.

12.3 LGPD (Brazil). If the LGPD applies to our processing of your Personal Data, you have the rights to confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, and revocation of consent. We respond to verifiable requests within fifteen (15) days, with a possible extension where permitted by law.

12.4 CCPA / CPRA (California). If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by the CPRA):

  • Right to know the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purpose, the categories of third parties with whom we share Personal Information, and the categories disclosed for a business purpose.
  • Right to delete Personal Information, subject to certain exceptions.
  • Right to correct inaccurate Personal Information.
  • Right to opt out of sale or sharing Personal Information.
  • Right to limit use of sensitive personal information to specified purposes.
  • Right to non-discrimination for exercising any of these rights.

Notice of “Sale” and “Sharing”: itogai does not sell Personal Information for monetary consideration and does not share Personal Information for cross-context behavioral advertising as those terms are defined under the CCPA. We have not sold or shared the Personal Information of California residents in the preceding twelve (12) months.

Notice of Sensitive Personal Information: We do not use or disclose Sensitive Personal Information for purposes that would trigger a right to limit under the CCPA.

To submit a verifiable consumer request, write to privacy@itogai.com. We respond within forty-five (45) days, with a possible forty-five (45) day extension if reasonably necessary.

12.5 Other U.S. State Privacy Laws. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other U.S. states with comprehensive consumer-privacy laws may have rights similar to those described in Section 12.4, subject to the specific definitions and exceptions of their respective state laws. To exercise rights under any U.S. state privacy law, write to privacy@itogai.com.

12.6 Rights of Non-Users (Third-Party Contacts). If you are not a User of the Subscription Service but believe a User has provided Personal Data about you to itogai (for example, by importing a contact record), you may submit a removal or access request at privacy@itogai.com. We will use reasonable efforts to honor such requests, including by removing your Personal Data or providing information about the User who imported it, subject to applicable law.

12.7 Verification. To protect your Personal Data, we will need to verify your identity before responding to a request. The verification process may include confirming the email address associated with your Account or requesting additional identifying information. We will not use information provided for verification for any other purpose.

12.8 Response Times. We respond to verifiable requests within the timeframes required by applicable law (generally thirty (30) days under GDPR, fifteen (15) days under LGPD, and forty-five (45) days under CCPA). We may extend these timeframes where permitted by applicable law and will notify you of any such extension.

13. Third-Party Sites and Services

The Subscription Service may contain links to, or be integrated with, third-party websites, products, or services (including the Data Sources you authorize, Stripe, and websites referenced from within the Subscription Service or our Marketing Website). This Privacy Policy does not apply to those third-party sites, products, or services. itogai is not responsible for the privacy practices, content, or security of any third-party site, product, or service.

OAuth scope review: When you connect a Data Source, the authorization screen presented by the third party (for example, the Google permissions screen or the Microsoft consent dialog) describes the specific permissions you are granting. itogai requests only the scopes necessary to provide the Subscription Service. You may revoke any third-party authorization at any time through the settings of the relevant third-party provider, or by disconnecting the Data Source within the Subscription Service. Revocation does not delete metadata or signals previously derived during periods of authorized access; please refer to Section 10 for the deletion timeline.

14. Cookies and Similar Technologies

itogai and our service providers use cookies, local storage, session storage, pixels, and similar technologies (collectively, “Cookies”) on the Marketing Website and on the Subscription Service.

14.1 Categories of Cookies We Use.

Category Purpose Examples
Strictly Necessary Required to operate the Subscription Service, authenticate Users, maintain session integrity, route requests, and enforce security. Authentication tokens, session identifiers, CSRF tokens.
Functional Remember your preferences and settings. UI language, time-zone preference, last-viewed TrustCircle.
Analytics and Performance Help us understand how Users interact with the Subscription Service. Where required by law, we rely on consent. Amplitude, Sentry.
Marketing (Marketing Website only) Measure marketing campaign effectiveness on the Marketing Website. We do not use marketing Cookies inside the authenticated Subscription Service. LinkedIn Insight Tag, X conversion tracking, Google Analytics.

14.2 Your Choices. You can control or disable Cookies through your browser settings, through our cookie-preference banner where available, or through opt-out mechanisms.

  • Browser controls. Most browsers let you delete or block Cookies.
  • Global Privacy Control. The Subscription Service responds to Global Privacy Control (GPC) signals to the extent required by applicable law. We do not currently respond to traditional Do-Not-Track signals because no industry standard has been adopted.
  • Analytics opt-outs. Where we rely on consent for analytics Cookies, you may withdraw consent through the cookie-preference banner. Withdrawing consent does not affect lawfulness of processing prior to withdrawal.

14.3 No Sale or Sharing for Cross-Context Behavioral Advertising. itogai does not sell Personal Information for monetary consideration and does not share Personal Information for cross-context behavioral advertising. We do not place advertising trackers inside the authenticated Subscription Service.

15. Children’s Privacy

The Subscription Service is a business-to-business product and is not directed to children. itogai does not knowingly collect Personal Data from any individual under the age of sixteen (16) (or such other age as may be the applicable threshold under local law, including thirteen (13) under COPPA in the United States and twelve (12) under the LGPD in Brazil). If you are under the applicable age threshold in your jurisdiction, you may not register for or use the Subscription Service.

If we become aware that we have collected Personal Data from a child without verifiable parental consent (where required), we will take reasonable steps to delete that Personal Data. If you are a parent or guardian and believe your child has provided Personal Data to itogai without your consent, write to privacy@itogai.com.

16. Changes to This Policy

itogai may update this Privacy Policy from time to time to reflect changes in our practices, the Subscription Service, applicable law, or for other operational, legal, or regulatory reasons.

16.1 How We Notify You.

  • Material changes (changes that materially expand the categories of Personal Data we process, the purposes for which we process Personal Data, or the categories of recipients with whom we share Personal Data): we provide reasonable advance notice, generally at least thirty (30) days, by email to the registered Account Owner, by an in-product notice on first sign-in after the change, or by a banner on the Marketing Website. Where required by applicable law, we will obtain renewed consent before such changes take effect.
  • Non-material changes (clarifications, corrections, or addition of new sub-processors that perform the same category of services as existing sub-processors): we update the “Last Modified” and “Effective Date” at the top of this Privacy Policy.

16.2 Versioning and History. Each version of this Privacy Policy bears a Document Version identifier (for example, PP-2026-05-09 v1.0) and an Effective Date. Upon written request to privacy@itogai.com, we will provide a prior version that was in effect as of a specified date.

16.3 Google API Disclosure Continuity. Any change to this Privacy Policy that would affect our compliance with the Google API Services User Data Policy, including the Limited Use requirements (Section 6), or that would affect the metadata-only architecture for restricted Google API scopes (Section 5), will be subject to the material-change notice procedure in Section 16.1 and will be made available for review by the App Defense Alliance and Google during any applicable Tier 2 CASA re-verification.

17. Region-Specific Disclosures

This Section sets out additional disclosures that apply to specific jurisdictions. These disclosures supplement, and do not replace, the rest of this Privacy Policy.

17.1 European Union, European Economic Area, United Kingdom, and Switzerland.

  • Controller and Processor. When you use the Subscription Service, itogai may act as a controller (for example, with respect to Account Data, Billing Data, Usage Data, and Communications) or as a processor (for example, with respect to Customer Data you import or that we receive from authorized Data Sources on your behalf). Where we act as a processor, our Data Processing Agreement governs.
  • Legal bases for processing. See Section 4.
  • International transfers. See Section 9.
  • Right to lodge a complaint. You may lodge a complaint with a competent supervisory authority. EU and EEA authorities are listed at edpb.europa.eu. UK residents may contact the Information Commissioner’s Office at ico.org.uk. Swiss residents may contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch.
  • EU/UK representative. itogai is a small bootstrapped Florida limited liability company. Our processing of EU/UK Personal Data is occasional, limited to business-to-business contact and relationship metadata, and does not, on our assessment, meet the threshold of Article 27(2) GDPR or the equivalent UK GDPR provision that would compulsorily require designation of a representative. We will reassess this position as the Subscription Service’s footprint changes and reserve the right to designate a representative voluntarily. EU/UK data subjects may contact itogai directly at privacy@itogai.com to exercise any right.

17.2 Brazil (LGPD).

  • Status under LGPD. itogai may act as a controller (controlador) or as a processor (operador).
  • Legal bases for processing. See Section 4.
  • International transfers. Transfers from Brazil rely on the legal bases described in Article 33 of the LGPD.
  • Right to file a complaint. You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
  • Encarregado / Privacy Contact. Brazilian data subjects may contact our privacy contact at privacy@itogai.com.

17.3 California (CCPA / CPRA).

  • Notice at Collection. The categories of Personal Information we collect, the purposes for which we collect them, and the categories of third parties with whom we share Personal Information are described in Sections 2, 4, 7, and 8.
  • Sensitive Personal Information. We do not use or disclose Sensitive Personal Information for purposes other than those permitted under CCPA Section 1798.121 and applicable regulations.
  • Sale and Sharing. We do not “sell” Personal Information for monetary consideration and do not “share” Personal Information for cross-context behavioral advertising.
  • Retention periods. See Section 10.
  • “Shine the Light” (California Civil Code § 1798.83). California residents may request information about disclosures, if any, of Personal Information to third parties for those parties’ direct-marketing purposes. itogai does not disclose Personal Information for direct-marketing purposes by third parties. Submit a Shine the Light request to privacy@itogai.com.
  • Submitting CCPA requests. See Section 12.4.

17.4 Nevada. Nevada residents may submit a verified request directing us not to make any sale of any “covered information” (as defined under Nevada Revised Statutes § 603A.340). itogai does not sell covered information. Submit a Nevada request to privacy@itogai.com.

17.5 Other U.S. States. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other U.S. states have rights similar to those described in Section 12.4, subject to the definitions, exceptions, and verification procedures of each state’s law. To exercise rights under any U.S. state privacy law, write to privacy@itogai.com. Where the applicable state law requires a designated appeals process, you may submit an appeal by replying to our denial notice or by writing to privacy@itogai.com with the subject line “Privacy Rights Appeal.” We will respond to appeals within the timeframe required by the applicable state law.

17.6 Latin America (Outside Brazil). itogai serves Users across Latin America. Where local data-protection laws (including Argentina’s Personal Data Protection Law No. 25,326, Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties, Colombia’s Law 1581 of 2012, and Chile’s Law 19,628) provide rights to data subjects, you may exercise those rights by writing to privacy@itogai.com.

18. How to Contact Us

The right inbox depends on what you need:

Privacy questions, data-subject access, deletion, correction, and portability requests, GDPR/UK GDPR/LGPD/CCPA/state-privacy-law rights requests, removal requests from non-Users, “Shine the Light” requests, Nevada opt-outs, appeals of denied privacy requests, and questions about the Google API Limited Use Disclosure: privacy@itogai.com

Legal notices, intellectual-property claims, DMCA notices, contract questions, security-vulnerability reports, and notices required to be served under the Customer Terms of Service: legal@itogai.com

General product support, account issues, billing assistance, and how-to questions: info@itogai.com

Product demos, pricing, accelerator partnerships, and sales inquiries: demo@itogai.com

Postal address: Itogai LLC Attn: Privacy Office 4821 Jumping Way Lake Worth, Florida 33467 United States of America

Itogai LLC is a Florida limited liability company. The Privacy Office routes incoming requests to the appropriate internal owner.

Related documents

Customer Terms of ServiceThe agreementAcceptable Use PolicyUsing itogaiCookie PolicyCookies & trackingData Processing AgreementData processingSub-processorsOur vendorsTrademark Notice and Usage GuidelinesBrand & trademarks
itogai

itogai is the relationship intelligence platform that makes the Trustbound™ motion real.

Built with care. Backed by trust.

Products

TrustGraph™TrustCircles™TrustReach™ Akai™Pricing

Trustbound™

Manifesto Our Principles Trustbound Podcast Revenue Program

Company

About Us Contact Us Help Center Legal

Follow us

© 2026 Itogai LLC. All rights reserved. itogai, the itogai logo, Trustbound, TrustGraph, TrustCircles, TrustReach, and Akai are trademarks of Itogai LLC.