////PRIVACY & DATA PROTECTION

Privacy Policy & Data Protection Agreement.

EFFECTIVE JULY 10, 2026 · LAST UPDATED JULY 10, 2026

This Privacy Policy and Data Protection Agreement explains what information Vecturae Consultants, LLC (the "Company," "we," "us") collects through the PursuitIQ platform, how we protect it, and the confidentiality commitments we make to every subscriber. This policy includes NDA-equivalent protections for your organizational data.

Your data is org-scoped and isolated. No cross-tenant sharing, ever.

Customer data is treated as Confidential Information under NDA-equivalent protections.

AI inputs and outputs are per-org — never used to train foundation models.

§1

Overview

PursuitIQ is a GovCon decision-intelligence platform operated by Vecturae Consultants, LLC. This policy covers the PursuitIQ web application, the AURA reasoning engine, PursuitIQ Agents, and all related APIs (together, the "Service"), accessible at https://www.getpursuitiq.ai.

By creating an account or using the Service, you agree to the collection, use, and protection of information as described in this policy. If you are using the Service on behalf of an organization, you confirm authority to accept this policy on that organization's behalf.

This policy incorporates NDA-equivalent confidentiality protections (Section 5) that apply to all Customer Data from the moment of ingestion through deletion.

§2

Data we collect

Account and company profile data

Name, work email, organization name, role, NAICS codes, capabilities, contract vehicles, past performance references, and billing information provided during signup or through Settings.

Pursuit and capture data

Saved searches, watchlists, pipeline notes, teaming records, uploaded proposal documents, bid/no-bid decisions, and any other content you create or input into the Service.

Usage and interaction data

Pages visited, features used, session duration, API calls made, AURA queries submitted, Agent interactions, click patterns, and device/browser metadata — collected automatically to operate and improve the Service.

API interaction data

Request payloads, response metadata, rate limit status, and error logs associated with your use of PursuitIQ APIs.

Cookies and similar technologies

Session cookies to maintain authentication, and first-party analytics cookies to understand product usage. We do not use third-party advertising cookies or cross-site tracking.

§3

How we use data

We use collected data for the following purposes:

  • Opportunity scoring and analysis. Processing your company profile, capabilities, and past performance to calculate Pursuit Score and deliver personalized opportunity recommendations.
  • AI-powered analysis. Providing AURA-generated briefs, chat responses, competitive analysis, and capture intelligence based on your organizational context.
  • Platform improvement. Analyzing aggregated, de-identified usage patterns to improve features, reliability, and user experience. Individual Customer Data is never used for this purpose.
  • Service delivery. Authenticating accounts, enforcing entitlements, processing payments, and delivering notifications.
  • Security and compliance. Detecting fraud, preventing abuse, maintaining audit logs, and fulfilling legal obligations.
  • Support. Responding to support requests and providing onboarding assistance.
§4

Data isolation

PursuitIQ operates a multi-tenant architecture with strict organizational-scope isolation:

  • Tenant boundary. Each Workspace is an isolated tenant. All Customer Data is scoped to and accessible only within the owning Workspace.
  • No cross-tenant data sharing. Data from one organization is never visible to, shared with, or used to benefit another organization. This includes pursuit data, AI outputs, scoring inputs, pipeline information, and any uploaded content.
  • Infrastructure enforcement. Tenant isolation is enforced at the database, API, and application layers through row-level security, scoped access tokens, and organization-keyed data partitioning.
  • Internal access controls. Company personnel access Customer Data only when necessary to provide support or maintain the Service, under strict role-based access controls and audit logging.
§5

Confidentiality (NDA-equivalent protections)

The Company treats all Customer Data as Confidential Information, subject to the following binding commitments:

5.1 — Definition of Confidential Information

All non-public data uploaded to, created within, or processed by the Service on behalf of your organization constitutes "Confidential Information." This includes but is not limited to: company profiles, capabilities statements, proposal content, bid strategies, teaming arrangements, pricing data, pipeline notes, and organizational decisions.

5.2 — Non-disclosure commitment

The Company shall not disclose your Confidential Information to any third party except: (a) as strictly necessary for service delivery by bound sub-processors (Section 9); (b) as required by law, subpoena, or valid legal process, with advance notice to you where permitted; or (c) with your explicit written consent.

5.3 — Competitor protection

Confidential Information belonging to one subscriber is never shared with, disclosed to, accessible by, or used to derive insights for any competing subscriber. The Company maintains strict information barriers. No employee or system may access or cross-reference data between competing organizations.

5.4 — AI input/output isolation

All AI model inputs (prompts, context, documents) and outputs (responses, scores, analysis) are processed per-organization and are never: (a) shared across tenants; (b) used to train, fine-tune, or improve any foundation model; (c) stored in any shared embedding space or vector database accessible by other organizations; or (d) used for any purpose other than delivering the Service to the owning organization.

5.5 — Standard of care

The Company shall protect your Confidential Information with at least the same degree of care it uses for its own confidential information, and in no event less than reasonable care, including encryption, access controls, and audit logging.

5.6 — Duration

Confidentiality obligations survive termination of your subscription and continue for as long as the information remains non-public, including through the data retention and deletion period described in Section 8.

§6

AI data handling

AURA and PursuitIQ Agents process Customer Data to deliver AI-powered features. The following commitments apply:

  • No model training. Customer Data is NOT used to train, fine-tune, retrain, or improve any foundation model — whether operated by the Company, Amazon (Bedrock), Anthropic, or any other provider.
  • Per-org processing. AI inference is scoped to your organization. Your data is never co-mingled with another organization's data during processing.
  • AWS boundary. All AI processing occurs within the AWS environment. Customer Data does not leave the AWS boundary for AI inference. Model providers (via Amazon Bedrock) are contractually prohibited from retaining or training on request data.
  • Ephemeral context. AI model context windows are ephemeral — populated per-request and discarded after response generation. No persistent memory is shared across organizations.

See our AI Usage Policy for additional details on AI systems, accuracy, and opt-out options.

§7

Data storage & encryption

All Customer Data is stored and processed within the following security perimeter:

  • Region. AWS us-east-1 (N. Virginia). All primary data storage, compute, and AI inference occur within this region.
  • Encryption at rest. AES-256 encryption for all stored data, including databases, object storage, backups, and logs.
  • Encryption in transit. TLS 1.2+ for all data in transit, including API calls, web sessions, inter-service communication, and connections to sub-processors.
  • Key management. Encryption keys managed through AWS KMS with automatic rotation.
  • Backup encryption. All backups are encrypted with the same AES-256 standard and stored within the same AWS region.
§8

Data retention

  • Active subscription. Customer Data is retained for the duration of your active subscription with no automatic purging.
  • Post-cancellation. Following cancellation or termination, Customer Data is retained for thirty (30) days to allow export or account reactivation. After this window, data is permanently deleted from production systems.
  • Backup purge. Residual copies in encrypted backups are purged within ninety (90) days of production deletion.
  • Usage and analytics data. De-identified, aggregated usage data may be retained beyond account deletion for service improvement purposes. This data cannot be re-identified to any individual or organization.
  • Legal holds. Data subject to a valid legal hold, regulatory requirement, or ongoing dispute may be retained beyond the standard deletion timeline as required by law.
§9

Sub-processors

The following sub-processors may process Customer Data in connection with the Service:

ProviderPurposeData boundary
Amazon Web Services (AWS)Infrastructure, compute, storage, AI inference (Bedrock)us-east-1
StripePayment processing and subscription billingBilling data only
Anthropic (via Bedrock)AI model inference (Claude)Within AWS boundary — no data retention by Anthropic

Key constraint: No Customer Data leaves the AWS boundary for AI inference. Anthropic model access is provisioned through Amazon Bedrock, which contractually ensures that request data is not retained, logged, or used for training by the model provider.

Stripe receives only billing-related information (name, email, payment method, invoice history) and does not have access to pursuit data, AI outputs, or organizational content.

We will notify account administrators at least 30 days before adding a new sub-processor that handles Customer Data.

§10

Your rights (CCPA/GDPR)

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you and your organization.

Deletion

Request deletion of your personal data. We will comply within 30 days, subject to legal retention requirements.

Portability

Export your data in a structured, machine-readable format at any time from Settings, or by request.

Correction

Request correction of inaccurate personal data.

Restriction and objection

Object to or restrict certain processing activities.

Non-discrimination

We will not discriminate against you for exercising any of these rights.

How to exercise

Submit requests to [email protected]. We will verify your identity and respond within 30 days (or 45 days for complex requests, with notice). California residents may designate an authorized agent to make requests on their behalf.

CCPA-specific disclosures

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. In the preceding 12 months, we have collected the categories of information described in Section 2.

§11

Security measures

The Company maintains a security program aligned with industry standards:

  • SOC 2 alignment. Security controls aligned with SOC 2 Type II criteria (Trust Services Criteria). Formal audit in progress.
  • CMMC posture. Security practices aligned with CMMC Level 2 requirements to support customers operating in the defense industrial base.
  • Access controls. Role-based access control (RBAC) with least-privilege principles for all internal systems. Multi-factor authentication required for all Company personnel.
  • Audit logging. Comprehensive audit trails for all data access, administrative actions, and security events. Logs are immutable, encrypted, and retained for a minimum of 12 months.
  • Vulnerability management. Regular vulnerability scanning, dependency monitoring, and penetration testing.
  • Incident response. Documented incident response procedures with defined escalation paths and communication protocols.
  • Employee security. Background checks, security awareness training, and confidentiality agreements for all personnel with access to Customer Data.

For our full security posture, see the Trust & Security page.

§12

Breach notification

In the event of a confirmed data breach affecting your Customer Data:

  • Timing. We will notify affected account administrators within seventy-two (72) hours of confirming the breach.
  • Content. Notification will include: the nature of the breach, categories of data affected, approximate number of records involved, measures taken to contain the breach, and recommended steps for affected users.
  • Ongoing updates. We will provide timely updates as our investigation progresses and additional information becomes available.
  • Regulatory notification. We will cooperate with you in meeting any regulatory notification obligations arising from the breach.
§13

Children's privacy

The Service is intended for business use by adults and is not directed to children under 16. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child under 16, we will delete it promptly.

§14

Changes to this policy

We will update the effective date above when this policy changes. For material changes, we will notify account administrators by email at least thirty (30) days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

§15

Contact

Questions about this policy, data protection requests, or privacy concerns:

[email protected]

Vecturae Consultants, LLC
3801 N Capital of Texas Hwy, Ste E240-3267
Austin, TX 78746
(737) 377-6440