Legal

Data Policy

This policy explains how data in Benefit Connect is classified, processed, secured, retained, and deleted, and the rights available to you.

1. Data Classification

1.1 Company Data

Data we collect about your account, billing, and usage. This includes:

  • Account registration info
  • Payment history
  • Login credentials and security settings
  • Usage logs and analytics
  • Support communications

Ownership: Company owns this data; you have limited rights to access, correct, and delete per applicable law.

1.2 Customer Data

Contact information and communications you upload to the Service. This includes:

  • Contact names, phone numbers, emails, addresses
  • Interaction history and engagement metrics
  • Messages sent through the Service
  • Tags, notes, and custom fields you assign

Ownership: You own customer data; we hold it as a data processor.

1.3 Aggregate Data

De-identified, aggregated statistics and analytics derived from the Service. This includes:

  • Industry benchmarks
  • Feature usage trends
  • Engagement rates and response times
  • De-identified performance metrics

Ownership: Company owns aggregate data and may use it to improve the Service and provide public reports.

2. Data Processing & Location

  • Data is processed in the United States
  • We may use service providers located outside the US
  • All data transfers are protected by standard contractual clauses and data processing agreements
  • International users consent to US-based processing

3. Data Access & Security

  • Company employees access data only on a need-to-know basis
  • All access is logged and monitored
  • Employees sign confidentiality agreements
  • We use multi-factor authentication, encryption, and network security
  • We conduct regular security assessments

4. Customer Data Responsibility

You are fully responsible for:

  • Obtaining lawful consent for all customer data
  • Complying with TCPA, GDPR, CAN-SPAM, and similar regulations
  • Accurate representation of data sources
  • Deleting expired or non-consenting contacts
  • Data quality and accuracy
  • TCPA compliance and do-not-call registry compliance

We are not liable for:

  • Your violations of data protection laws
  • Regulatory fines or penalties you incur
  • Claims from recipients regarding unsolicited messages
  • Inaccurate or outdated contact data

5. Data Retention & Deletion

5.1 Active Accounts

  • Account data is retained as long as your subscription is active
  • Customer data remains in your account for retrieval
  • You may export or delete customer data at any time

5.2 Terminated Accounts

  • Data is retained for 30 days post-termination in backups
  • After 30 days, all data is permanently deleted
  • Regulatory holds may extend retention
  • We make no guarantee of data recovery after deletion

5.3 Backups & Disaster Recovery

  • We maintain encrypted backups for up to 30 days
  • Backups are used only for disaster recovery
  • Backups are automatically purged per our retention schedule

6. Data Requests & Exports

  • You can request a data export of your account at any time
  • Export requests are fulfilled within 5 business days
  • Exports are provided in CSV or JSON format
  • Large exports may incur a nominal processing fee

7. Third-Party Data Sharing

We share data with:

  • Payment processors (for billing)
  • Hosting providers (for service delivery)
  • SMS/email carriers (for message delivery)
  • Analytics providers (with aggregation)
  • Law enforcement (when legally required)

We do not:

  • Sell customer data to third parties
  • Share customer data for marketing purposes
  • Provide access to contact lists to competitors
  • Disclose customer data except as required by law or necessary to provide the Service

8. GDPR & Data Subject Rights

For individuals in the EU, GDPR provides:

  • Right to Access: Request copy of your personal data
  • Right to Correction: Request correction of inaccurate data
  • Right to Erasure: Request deletion (with exceptions)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive data in portable format
  • Right to Object: Object to processing for marketing
  • To exercise these rights: privacy@benefitconnect.app
  • Response time: 30 days

9. CCPA & California Rights

California consumers have rights to:

  • Know what personal information is collected
  • Delete personal information (with exceptions)
  • Opt-out of data sales (we do not sell data)
  • Non-discrimination for exercising these rights
  • To exercise these rights: privacy@benefitconnect.app

10. Data Breach Notification

In the event of a data breach:

  • We will notify affected users within 30 days
  • We will notify relevant authorities per applicable law
  • We will provide information about the breach and recommended actions
  • Notification will include our incident response steps

11. Sub-processors & Vendors

Vendors with access to data include:

  • Amazon Web Services (hosting)
  • Stripe (payment processing)
  • Twilio (SMS delivery)
  • SendGrid (email delivery)

Full vendor list available upon request. We review vendors annually and update as needed.

12. Data Processing Agreement

For business customers subject to GDPR or similar regulations, we will execute a Data Processing Agreement (DPA) upon request at no additional cost.

13. Contact & Inquiries

For data-related inquiries, requests, or concerns:

  • Email: privacy@benefitconnect.app
  • Response time: 5 business days
  • Include account details and specific request

Last updated: September 2026. Questions about this policy: support@benefitconnect.app