This Privacy Policy describes how SoftFinity Corp. ("Company," "we," "us," or "our"), operating under the trade name GenieMode.ai, collects, uses, discloses, and protects your personal information when you visit our website, engage our services, or otherwise interact with us. By using our Service, you consent to the practices described herein.
1. Information We Collect
Information You Provide
- Contact information: Name, email address, company name, phone number, and job title provided through our contact form or during engagement discussions.
- Engagement information: Project requirements, business data, technical specifications, and other materials shared during the course of our consulting services.
- Payment information: Billing details necessary for processing payments. We do not directly store credit card numbers; payment processing is handled by our third-party payment processor.
- Communications: Emails, messages, and other correspondence between you and our team.
Information Collected Automatically
- Usage data: Pages visited, time spent on pages, referring URLs, and navigation patterns on our website.
- Device information: Browser type, operating system, screen resolution, and language preferences.
- Network information: IP address, approximate geographic location (city/region level).
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and deliver our consulting services.
- Communicate with you about engagements, proposals, and deliverables.
- Process payments and manage billing.
- Respond to inquiries submitted through our contact form.
- Improve our website and service offerings.
- Comply with legal obligations and protect our rights.
- Detect and prevent fraud or unauthorized access.
3. Client Data & Engagement Materials
During the course of our consulting engagements, clients may share proprietary data, systems access, and business information with us. We treat all client engagement data with the highest level of confidentiality:
- Client data is used solely for the purpose of delivering the contracted services.
- We do not use client data to train our own AI models or for any purpose beyond the scope of the engagement.
- Access to client data is restricted to authorized team members on a need-to-know basis.
- Upon engagement completion or termination, client data is returned or securely destroyed within 30 days, unless otherwise agreed.
4. Information Sharing
We do not share your personal information except in the following limited circumstances:
- Service providers: Trusted third parties who assist in operating our business (e.g., payment processors, cloud hosting providers). These providers are contractually bound to protect your data.
- Legal requirements: When required by law, subpoena, court order, or government regulation.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
- With your consent: When you explicitly authorize us to share your information.
5. Data Sale Prohibition
We do not sell, rent, lease, or trade your personal information to any third party, under any circumstances. This applies to all categories of personal information we collect.
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit: All data transmitted to and from our systems is encrypted using TLS 1.2 or higher.
- Encryption at rest: Stored data is encrypted using AES-256 encryption.
- Access controls: Role-based access controls and multi-factor authentication for all systems containing personal or client data.
- Security testing: Regular vulnerability assessments and penetration testing.
- Incident response: Documented incident response procedures with notification within 72 hours of discovering a breach affecting personal data.
7. Data Retention
- Contact form submissions: Retained for 2 years from the date of submission, then deleted.
- Client engagement data: Returned or securely destroyed within 30 days of engagement completion, unless a longer retention period is agreed upon.
- Account and billing data: Retained for 7 years as required for tax and accounting purposes.
- Website analytics: Aggregated and anonymized; raw data retained for no more than 26 months.
8. Cookies & Tracking
Our website uses minimal cookies:
- Essential cookies: Required for basic website functionality (e.g., form submissions).
- Analytics cookies: Used to understand how visitors interact with our website. We use privacy-focused analytics that do not track individuals across sites.
We do not use third-party advertising cookies or retargeting pixels. You can configure your browser to block cookies, though some website functionality may be affected.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Withdrawal of consent: Withdraw consent for data processing at any time.
- Objection: Object to the processing of your personal information for certain purposes.
To exercise any of these rights, contact us at privacy@geniemode.ai. We will respond within 30 days.
10. CCPA / CPRA (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- The right to know what personal information is collected, used, and shared.
- The right to delete personal information.
- The right to opt out of the sale of personal information (we do not sell personal information).
- The right to non-discrimination for exercising your privacy rights.
- The right to correct inaccurate personal information.
- The right to limit use and disclosure of sensitive personal information.
11. GDPR (EEA Residents)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:
- Contractual necessity: Processing required to deliver our services.
- Legitimate interests: Processing for business operations, security, and service improvement.
- Consent: Where you have given explicit consent.
- Legal obligation: Processing required by law.
For international data transfers, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your data.
12. HIPAA & Protected Health Information
If our services involve processing Protected Health Information (PHI) on behalf of a healthcare organization, we will:
- Enter into a Business Associate Agreement (BAA) prior to accessing PHI.
- Implement HIPAA-compliant administrative, physical, and technical safeguards.
- Restrict access to PHI to authorized personnel only.
- Ensure PHI is encrypted both in transit and at rest.
- Report any security incidents involving PHI promptly in accordance with HIPAA breach notification requirements.
13. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will delete that information promptly.
14. Third-Party Links
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. For active clients, we will also provide notice via email. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
16. Contact Information
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
SoftFinity Corp. (DBA GenieMode.ai)
Email: privacy@geniemode.ai
Web: geniemode.ai/contact