Privacy Policy
Version 1.0 · Effective August 8, 2026
This Privacy Policy describes how SafeguardsMark (operated by Ellis Intelligence LLC, "we", "us") collects, uses, and shares information when you visit safeguardsmark.com or use the Service.
- 1. Scope
- 2. Information we collect
- 3. A note on financial data references
- 4. Information we do not want
- 5. How we use information
- 6. What we do NOT do with your information
- 7. Generated WISPs & third-party sharing
- 8. Retention
- 9. Security
- 10. Cookies
- 11. Your rights
- 12. Children
- 13. Changes to this policy
- 14. Contact
1. Scope
Marketing-site visitors (including free coverage quiz users); Customer account holders; team members a Customer invites under its tenant. SafeguardsMark is a flat multi-tenant service — each business is one tenant (Multi-Entity subscribers have up to 3 tenants).
2. Information we collect
(a) Directly (account + tenant data):
- Organization identity: legal business name, business type (auto dealer, tax preparer, mortgage broker, CPA, other), primary contact name and email.
- Business profile: Qualified Individual (as defined in the FTC Safeguards Rule) name, title, and email; incident response ("IR") contact name and phone number; employee count.
- Written Information Security Program ("WISP") Builder inputs: responses to the 9-element guided wizard (§314.4(a)–(i)), including: descriptions of the Customer's information security safeguards, risk assessment responses (what financial data does the Customer hold, where is it stored, what threats have been identified, what controls are in place), service provider inventory (vendor names, data types handled, oversight frequency, contract review dates), and annual assessment updates.
- Risk assessment data: self-reported asset inventory (types of customer financial data held, storage locations), threat catalog selections, controls in place, residual risk descriptions.
- Billing: Customer billing contact; payment details are tokenized via Stripe (we do not store card numbers). Pre-launch, Stripe is TEST mode only.
- Settings: notification preferences, team membership.
(b) Automatically: device and connection data, usage data, and cookies (strictly necessary + functional + aggregated analytics; no third-party advertising trackers).
(c) Generated under your tenant: issued WISPs (sealed, immutable), prior risk assessments, service provider inventory records, program element status history, annual assessment records, and the per-row audit log of WISP generation, download, re-issue, and annual assessment events.
3. A note on financial data references
SafeguardsMark's WISP Builder asks the Customer to describe the types of customer financial data their business holds (e.g., "we hold car-buyer credit applications with Social Security numbers ("SSNs") and bank routing numbers"). This information is a self-description of the Customer's data environment — it is NOT the actual customer financial data. We process the Customer's descriptions, not the underlying personal data of the Customer's customers. Do not upload actual customer records, credit applications, SSN files, or other sensitive personal data of natural persons through the SafeguardsMark Service.
4. Information we do not want
The Service is a compliance documentation tool. Do not upload through the Service:
- Actual customer financial records (real credit applications, actual SSN data, actual bank account numbers, actual tax return data)
- Social Security Numbers, personal Tax IDs, passport or driver's-license numbers of natural persons (other than as part of the Customer's Qualified Individual name and contact information)
- Protected health information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA")
- Personal data about consumers or end users of the Customer's business — SafeguardsMark captures the Customer's program descriptions, not the underlying financial data the Customer holds on its own customers
- Information about minors
If we discover such information uploaded inadvertently, we will notify the uploading Customer and request deletion, and may sanitize or delete it without prior notice to prevent regulatory exposure.
5. How we use information
We use the Customer's account data and WISP Builder inputs to:
- Generate the WISP — building each of the 9 required sections from the Customer's declared inputs, applying the generation gate, and producing the sealed PDF.
- Run the risk assessment module — organizing the Customer's asset inventory and threat responses into the risk assessment section of the WISP.
- Maintain the service provider tracker — organizing the Customer's service provider inventory for the §314.4(d) section of the WISP.
- Generate the IR plan — populating the incident response section with the Customer's named IR contact and both required notification provisions.
- Manage annual assessment reminders — tracking the annual review due date (one year from WISP generation) and notifying the Customer's account contact.
- Maintain the document vault — preserving issued WISPs and risk assessment records as the Customer's compliance history.
- Manage subscriptions and billing — process payments, manage tier state, send billing communications.
- Authenticate users, prevent unauthorized access, run aggregated/de-identified analytics, communicate about the Service and material changes, and comply with legal obligations.
SafeguardsMark does NOT connect to or scan the Customer's actual systems, dealer management system ("DMS"), accounting software, email server, or any other business technology. All WISP Builder inputs are self-reported by the Customer.
AI-assisted narrative generation. SafeguardsMark uses Anthropic, an AI model provider, to draft the narrative prose for each WISP program element from the Customer's WISP Builder inputs — the element's implementation status and the free-text survey responses recorded for it. Before any of that data reaches Anthropic, named contact fields — the Qualified Individual's name and the incident-response contact's name — and any value that looks like an email address, phone number, Social Security or Employer ID number, date of birth, street address, or account number are detected and replaced with placeholder tokens, and the call is refused outright if any of those still appear unmasked. After Anthropic returns a draft, we restore the real values locally, on our own infrastructure, before the narrative is shown to the Customer. This masking is a property of our own code, not a data-retention term of our contract with Anthropic, so it holds regardless of Anthropic's retention policy or any future change to it. It does not extend to a person's name typed into a free-text field (for example, the safeguards notes, primary-threats, asset-types, or training-topics fields) — those are sent to Anthropic as written.
6. What we do NOT do with your information
- We do not sell personal information. We do not share it for cross-context behavioral advertising.
- We do not use Customer Data to train AI/ML models. We do not use any Customer's WISP inputs, risk assessment responses, or service provider inventory to train, fine-tune, or improve any model or to generate outputs for other customers. One customer's program data never touches another's.
- We do not share Customer Data with third parties except as necessary to provide the Service (Stripe for billing, Anthropic for AI-assisted WISP narrative drafting — PII masked before send, see §5, cloud hosting for infrastructure) and as required by law. We do not share with data brokers, aggregators, or marketing platforms.
- We do not access the Customer's systems. SafeguardsMark never connects to, scans, reads, or integrates with the Customer's DMS, accounting software, email, or any other business system. Every declaration in the WISP Builder is self-reported by the Customer.
7. Generated WISPs and third-party sharing
7.1 WISPs are the Customer's property (see Terms of Service §8). When the Customer shares a WISP with a Federal Trade Commission ("FTC") examiner, state regulator, accountant, lender, dealer association, or other third party, that sharing is the Customer's act, not SafeguardsMark's. SafeguardsMark does not transmit WISPs to third parties on the Customer's behalf.
7.2 The SHA-256 hash on each WISP allows any third party who receives the WISP to verify its integrity by recomputing the hash over the document content. SafeguardsMark does not maintain a public hash registry in v1.
8. Retention
- Issued WISPs are retained indefinitely while the Customer has an active account; WISPs are immutable once issued and form the Customer's compliance record. On account deletion or Service discontinuation, SafeguardsMark provides export access for 30 days.
- Risk assessments are retained for the life of the account as the underlying evidence for each issued WISP.
- Service provider inventory records are retained for the life of the account.
- Billing records are retained as required for financial and legal compliance.
- Events log is retained for the life of the account; it is the audit trail for WISP lifecycle events.
9. Security
Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring being brought online ahead of launch. We use tenant isolation between customers. We do not claim SOC 2, ISO 27001, or any audited certification on this pre-launch product; we will update this section as our security program and independent assessments mature. No method of transmission or storage is perfectly secure.
Issued WISPs are immutable once issued (no UPDATE path post-issuance), and the SHA-256 seal on each WISP provides tamper-evidence for the document's integrity.
10. Cookies
We use strictly necessary cookies (session management, cross-site request forgery ("CSRF") protection) and functional cookies (user preferences). We do not use advertising cookies or third-party tracking. Aggregated analytics data (page views, quiz completion rates, funnel conversion) may be collected without identifying natural persons.
11. Your rights
Depending on your jurisdiction, applicable data protection law may give you the right to access, correct, delete, restrict the processing of, or receive a portable copy of the personal data we hold about you, and to lodge a complaint with a supervisory or regulatory authority. "Applicable data protection law" means, as relevant to you: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"); the Colorado Privacy Act ("CPA"); Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"); the UK GDPR; and any other data protection or privacy law that applies to our processing of your personal data.
We do not sell personal data and do not process it for targeted advertising, so there is nothing to opt out of — but the right is preserved. To exercise your rights, email [email protected]. We may need to verify your identity before responding, and we will respond within applicable statutory timeframes.
If you are a team member invited under a Customer's tenant, or an individual named in a Customer's tenant data (e.g., a Qualified Individual or IR contact), contact the Customer first: the Customer is the controller of the data under its tenant (including WISP Builder inputs, risk assessment data, and the service provider inventory), and Ellis Intelligence LLC processes that data on the Customer's behalf.
12. Children
The Service is not directed to individuals under the age of 13. We do not knowingly collect information from children under 13. If we learn we have collected information from a child under 13, we will delete it promptly.
13. Changes to this policy
We will provide 30-day notice of material changes via email to account holders and an in-app banner. Continued use after the effective date of a change constitutes acceptance.
14. Contact
Privacy questions, access/deletion requests, and data subject requests:
Ellis Intelligence LLC d/b/a SafeguardsMark
[email protected]