Hynds AI LLCVersion 1.0

Privacy Policy

Effective April 26, 2026 · Last updated April 26, 2026 · Next review April 26, 2027

At a glance
  • We don't sell or share your personal information for advertising or any other purpose.
  • We process information you give us, plus data from services you connect (Microsoft 365, and Plaid where enabled), strictly to operate the application.
  • Financial records are retained for at least seven (7) years to comply with U.S. tax and accounting requirements; everything else is governed by the Retention & Deletion Policy below.
  • You can request access, correction, deletion, or portability of your personal information — see Your Rights.
  • Plaid users: review the Plaid End User Privacy Policy.

1. Introduction

This Privacy Policy describes how Hynds AI LLC ("Hynds AI," "we," "us," or "our") collects, uses, shares, retains, and deletes information in connection with the Hynds AI Ops application (the "Application"), available at https://corp.hynds.ai.

The Application is an internal customer relationship management (CRM) and accounting platform used by Hynds AI personnel and authorized affiliates to operate the Hynds AI business. It is not a consumer-facing product.

We are committed to protecting the privacy and security of the information processed by the Application. This Policy is reviewed and reapproved at least annually, and is updated whenever we make a material change to how we collect, use, share, retain, or delete information.

2. Scope

This Policy applies to information processed by the Application, including:

This Policy does not apply to:

3. Information We Collect

3.1 Information You Provide

3.2 Information Collected Automatically

3.3 Information from Third-Party Services

With your explicit authorization (via OAuth or an equivalent flow), the Application may receive:

We do not collect or process payment card numbers. We do not collect biometric data, government-issued ID numbers, or precise geolocation.

3.4 Information We Do Not Collect

The Application is not directed to and does not knowingly collect information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold). See Section 11.

4. How We Use Information

We use the information described in Section 3 for the following purposes:

We do not sell personal information. We do not use your information for advertising, profiling for advertising, or to build third-party data products. We do not rent or lease your information.

5. How We Share Information

We share information only in the limited circumstances described below.

5.1 Service Providers (Subprocessors)

We engage a small set of vetted service providers to operate the Application. Each is bound by contractual confidentiality and security obligations, and each is granted access only to the data necessary to perform its function.

SubprocessorPurposeData Processed
Abacus.AIApplication hosting, hosted Postgres database, hosted LLM APIAll Application data at rest; email body content during AI contact extraction
Microsoft CorporationEmail, calendar, and contact synchronization for users who connect Microsoft 365OAuth-scoped read access to the connecting user’s Microsoft 365 mailbox, calendar, and contacts
Plaid Inc. (when enabled)Bank account linking, transaction and balance retrievalBank account metadata, transactions, balances, and liability details for accounts you explicitly link

A current list of subprocessors is maintained in our Information Security Policy and can be requested via the contact in Section 13.

5.2 Legal Requirements

We may disclose information if we are required to do so by law, valid legal process (such as a subpoena or court order), or to comply with regulatory obligations. We will give you notice of such disclosure unless legally prohibited.

5.3 Protection of Rights

We may disclose information when we believe in good faith that disclosure is necessary to investigate, prevent, or respond to suspected fraud, security incidents, or violations of our terms.

5.4 Business Transfers

If Hynds AI is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred to the successor entity. We will give notice and require the successor to honor the commitments in this Policy.

5.5 With Your Direction

We share information with third parties when you direct us to (for example, when you connect a Microsoft 365 account or link a bank via Plaid).

We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

6. Plaid-Specific Disclosures

When you elect to link a financial institution to the Application, we use Plaid Inc. ("Plaid") to gather your data from that financial institution. By using the Application's bank-linking feature, you grant Hynds AI and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from your relevant financial institution.

You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy:

https://plaid.com/legal/#end-user-privacy-policy

Plaid's processing of your information is governed by Plaid's own privacy policy, which we encourage you to review. Plaid is independently responsible for its data practices.

Within the Application, we use the Plaid-provided data only for the purposes described in Section 4, including: displaying your bank balances and transactions, supporting reconciliation against journal entries, and (where you choose to use it) auto-categorizing transactions to the chart of accounts.

You can disconnect a linked institution at any time from Settings → Integrations. When you disconnect, we revoke our access token at Plaid, stop pulling new data, and delete or anonymize the related Plaid data we hold per Section 7 below.

7. Data Retention and Deletion Policy

We maintain a defined and enforced data retention and deletion policy that is reviewed at least annually. Our retention practices are set in accordance with applicable U.S. federal and state recordkeeping and privacy laws, including the CCPA/CPRA, and are summarized below.

7.1 Retention Periods

Data CategoryRetention PeriodReason
Account credentials (bcrypt hashes only)While the account is active. Deleted within 30 days of account closure.Authentication
Audit logs (login events, privileged actions)At least 12 months; longer where required for security investigation or legal hold.Security, compliance, incident response
CRM records (contacts, companies, deals, activities, tags, notes)While the account is active and for as long as needed for legitimate business operations; deleted on user request or account closure subject to legal-hold exceptions.Business operations
Financial records (journal entries, invoices, bills, expenses, budgets, chart of accounts)At least seven (7) years from the end of the relevant tax year.U.S. federal and state tax and accounting recordkeeping requirements
Email content (synced from Microsoft 365)While the originating Outlook connection is active; deleted on disconnect.Provided as a working copy; the canonical copy lives in Microsoft 365
Calendar events (synced from Microsoft 365)While the originating Outlook connection is active; deleted on disconnect.As above
Outlook OAuth tokensWhile the connection is active. Encrypted at rest. Deleted immediately on disconnect.Authentication
Plaid access_token (when enabled)While the linked institution is connected. Encrypted at rest. Deleted immediately on disconnect.Authentication
Plaid bank transaction and balance data (when enabled)While the linked institution is connected, plus the seven-year retention applicable to journal entries derived from those transactions. Raw Plaid records may be deleted earlier on disconnect; posted journal entries are retained per the financial-records line above.Tax and accounting recordkeeping
Application diagnostic logsRetained by our hosting provider per its standard retention window (typically 30–90 days).Operations, debugging
BackupsPer the hosting provider’s snapshot retention. Records present in a backup but no longer in production are purged from backups when the backup itself rotates out of retention.Disaster recovery

7.2 Deletion on Request

Subject to applicable legal-retention obligations, you may request deletion of your account and associated personal information by contacting us at the address in Section 13. We will:

  1. Acknowledge your request within 10 business days.
  2. Verify the request to ensure it comes from the authorized account holder.
  3. Delete or anonymize the requested data within 30 days of verification, except for:
    • Records we are required to retain by law (e.g., the seven-year financial-records line above);
    • Records subject to an active legal hold; and
    • De-identified or aggregated data that can no longer be reasonably linked to you.
  4. Notify you when deletion is complete.

7.3 Automatic Deletion

The Application performs the following automatic deletions in code:

7.4 Periodic Review

The Security Officer reviews this retention and deletion policy at least annually and updates it to reflect changes in applicable law, integrated services, or business operations. The most recent review date is shown at the top of this document.

8. Your Rights

Depending on where you reside, you may have the following rights regarding your personal information.

8.1 Rights Under U.S. State Privacy Laws (e.g., California, Virginia, Colorado, Connecticut, Utah)

8.2 How to Exercise These Rights

Submit a request to the contact in Section 13 from the email address associated with your account. We will verify your identity and respond within the timeframe required by applicable law (generally 45 days, with one optional 45-day extension). There is no charge for a reasonable request.

8.3 Authorized Agents

You may designate an authorized agent to make a request on your behalf. We will require written authorization and may need to verify your identity directly.

8.4 Appeals

If we decline a request, you may appeal by replying to our response. We will reconsider and provide a written explanation within 60 days.

9. Security

We implement administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, alteration, disclosure, and destruction. These include:

These controls are described in detail in our Information Security Policy, which is reviewed annually. No system is perfectly secure; we cannot guarantee the security of information transmitted to or stored by the Application, but we will respond promptly and in good faith to any incident affecting your data.

10. International Data Transfers

The Application and its primary subprocessors are located in the United States. If you access the Application from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Application, you consent to this transfer.

11. Children's Privacy

The Application is intended exclusively for adult business users. We do not knowingly collect personal information from anyone under the age of 16. If we learn that we have collected such information, we will delete it promptly. Contact us at the address in Section 13 if you believe we have collected information from a minor.

12. Changes to This Policy

We may update this Policy from time to time. When we make a material change, we will:

  1. Update the Last Updated date at the top of the document.
  2. Provide notice through the Application or by email to active account holders at least 14 days before the change takes effect, unless an immediate change is required to comply with law or to address a security risk.
  3. Maintain prior versions on request.

Continued use of the Application after the effective date of an update constitutes acceptance of the updated Policy.

13. Contact Us

For questions, requests, or complaints regarding this Policy or our handling of your information:

Hynds AI LLC
Attn: Privacy / Security Officer (John Hynds)

We acknowledge requests within 10 business days and respond within the timeframe required by applicable law.


© 2026 Hynds AI LLC · Version 1.0 · Effective April 26, 2026