Privacy Policy

Cloudbyz, Inc. Privacy Policy

Last updated: August 19, 2026

1. Introduction and Scope

Cloudbyz, Inc. and its subsidiary entities ("Cloudbyz," "Company," "we," "us," or "our") respects your privacy. This Privacy Policy ("Policy") describes how we collect, use, disclose, and protect personal information in connection with our website (www.cloudbyz.com), mobile applications, social media pages, HTML-formatted email communications, offline sales and marketing activities, and the events and programs we operate (collectively, the "Platform"), as well as the corporate/marketing-facing aspects of the services we offer (collectively, the "Services"). This Policy applies to Platform visitors, prospects, event attendees, marketing contacts, and registered users.

This Policy does not describe how we process Customer Data. If you are an end user of a Cloudbyz customer’s Salesforce instance, or a Cloudbyz customer, the personal information submitted to or processed through the Cloudbyz application (including any personal information of a customer’s end users) is addressed by our Master Subscription Agreement and Data Processing terms with that customer, and by that customer’s own privacy notice, not by this Policy. This Policy also does not apply to personal information submitted by job applicants, which is addressed by our separate careers/recruiting privacy notice.

We encourage you to read this Policy in full. Section 9 (Your California Privacy Rights) and Section 10 (European Economic Area, United Kingdom, and Swiss Privacy Rights) describe the specific rights available to residents of those jurisdictions and how to exercise them.

2. Children's Privacy

Our Services are directed to businesses and are not intended or designed for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18, and we do not knowingly sell or share the personal information of consumers we know to be younger than 18 years of age. If you believe a child has provided us with personal information, please contact us at privacy@cloudbyz.com so we can take appropriate action.

3. Personal Information We Collect

"Personal Information" means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual or household.

3.1 Information You Provide to Us
  • Content you submit. Feedback, survey responses, and content submitted through interactive features, promotions, or events.
  • Account information. You may create an account by authenticating through a third-party identity provider such as Salesforce.com, Inc. ("Salesforce") or the Salesforce AppExchange. We never receive or store your password for that third-party account.
  • Support communications. Contact details, technical-contact designations, support tickets, and any documentation, screenshots, or information you provide to our support team.
  • Payment-related information. Services are purchased through your employer or via Salesforce/AppExchange; those parties may collect name, company, address, and billing/payment information necessary to process your order. We do not directly collect or store your credit card number.
  • Promotions and events. Information submitted to enter a contest or sweepstakes, complete a survey, or engage with us at a corporate event (e.g., Dreamforce).
  • Information about others. If you provide us with personal information about a third party (e.g., a colleague as a technical contact), you represent that you have the authority to do so and that you have provided any notice, and obtained any consent, required by law before sharing that information with us.
3.2 Information We Receive From Other Sources
  • Company administrators. An administrator at your organization may designate you as a billing or technical contact.
  • Cloudbyz partners. Consulting, implementation, training, referral, and reseller partners provide us billing/technical contact information, company name, products purchased or of interest, evaluation information, event attendance, and country.
  • Advertising and market-research partners. We receive information about your engagement with our advertisements and Services from advertising and market-research partners. As described in Section 6 and Section 8 below, this exchange may constitute “sharing” for cross-context behavioral advertising under California law, and is subject to the opt-out rights described in Sections 6 and 9.
  • Publicly available sources. Information available in publicly accessible government records or widely distributed media, consistent with the purpose for which it was made public.
3.3 Information Collected Automatically

Categories of information collected automatically, and their sources, are described in the table at Section 4. In summary:

  • Device and browser information: operating system, browser type/version, screen resolution, device identifiers, and language.
  • Application usage information: date/time of access and features used within our mobile applications.
  • Usage information: pages requested, search terms entered on our site, marketing emails opened, and features used. We do not sell this information to data brokers; where we disclose it to advertising or analytics partners for cross-context behavioral advertising, that disclosure may be considered a share under California law and is addressed in Sections 6–9.
  • Cookies, pixels, and similar technologies: described in Section 6.
  • IP address: logged automatically and used to calculate usage levels, diagnose problems, administer the Services, and derive approximate (city/region-level, not precise) location.

4. Categories of Personal Information, Sources, and Retention (California-Aligned Table)

The following table organizes our collection, sourcing, disclosure, and retention practices by the statutory personal-information categories defined at Cal. Civ. Code § 1798.140(v), consistent with Cal. Civ. Code § 1798.100(a)(3) and 11 C.C.R. §§ 7002 and 7012(e)(4).

Category (Cal. Civ. Code § 1798.140(v)) Examples We Collect Source Disclosed To (Business Purpose / “Sharing”) Retention Criteria
Identifiers (name, email, IP address, account ID) Name, work email, IP address You; automatically collected Service providers (hosting, email); advertising partners Account holders: duration of the account relationship, plus 12 months. Non-account visitors: work email retained for 24 months from last engagement; IP address retained in server logs for 90 days. Retained longer only where a legal obligation, litigation hold, or applicable limitations period requires.
Customer records information (Cal. Civ. Code §1798.80(e)) Billing/technical contact info You; your employer's administrator; Salesforce/AppExchange Service providers processing payment/orders Duration of the account relationship, plus the period required by applicable tax and transaction record-keeping laws (generally 7 years), or a longer period where required by federal law or contract.
Commercial information Products purchased or evaluated, event attendance You; Cloudbyz partners Service providers; Cloudbyz partners Duration of the business relationship, plus 24 months from your last purchase, evaluation, or event interaction, after which records are deleted or de-identified.
Internet or other electronic network activity Pages viewed, searches on our site, emails opened, cookie identifiers Automatically collected Analytics and advertising partners (“shared”) Cookie and pixel identifiers: until the cookie expires or you withdraw consent, and in no event longer than 13 months from being set. Site and email engagement logs: 24 months from collection. Not tied to account tenure, because this information is also collected from visitors who have no account.
Geolocation data (approximate, non-precise) City/region derived from IP address Automatically collected Analytics providers Retained only within aggregate analytics reporting; the underlying city/region value is deleted or de-identified within 14 months of collection, consistent with our analytics provider's configured retention setting.
Professional or employment-related information Job title, company, technical-contact designation You; your employer's administrator Service providers Duration of the business relationship, plus 24 months from your last engagement with us, unless you ask us to delete it sooner.
Inferences Aggregate product-interest inferences for marketing Derived from the above Not disclosed outside Cloudbyz. Aggregate and de-identified data is not personal information and is outside the scope of this table. Deleted or de-identified within 12 months of the inference being generated, or upon your deletion request.
Sensitive personal information Not requested, and not collected by design — see §5 N/A N/A N/A

In the preceding twelve (12) months, we have not exchanged personal information for monetary consideration. We have shared, and, as described in Section 6, may be deemed to have sold for other valuable consideration, the categories of personal information marked “shared” above with advertising and analytics partners for cross-context behavioral advertising, within the meaning of Cal. Civ. Code § 1798.140(ad) and (ah). See Sections 6–9 for how to opt out.

5. Sensitive Personal Information

We ask that you not submit Social Security numbers, government identification numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic or biometric data processed for identification, health information, or information concerning sex life or sexual orientation (“Sensitive Personal Information”) through the Platform, and by design our marketing website and account-registration flows do not request it. We do not use or disclose Sensitive Personal Information for purposes other than those permitted by law (i.e., purposes for which a right to limit does not apply, such as providing the goods or services requested). If this changes, we will update this Policy and, where required, provide a “Limit the Use of My Sensitive Personal Information” mechanism.

6. Cookies, Pixels, and Similar Technologies

We and our service providers use cookies, pixel tags (web beacons), SDKs, and similar technologies (collectively, “Cookies”) on the Platform.

By accepting non-essential Cookies through our consent banner or cookie preference center, you authorize Cloudbyz and the service providers and advertising partners identified in our cookie table to place, read, and store Cookies and similar identifiers on your device and to access that information for the purposes described in this Section 6 and Section 7. That authorization extends only to the Cookie categories you have enabled, together with the Strictly Necessary Cookies described below, and you may withdraw it at any time through our cookie preference center or by transmitting a recognized opt-out preference signal. We do not access files, data, applications, or systems on your device other than the Cookies and identifiers described in this Policy. We classify Cookies into the following categories:

Strictly Necessary / Essential Cookies

Required for the Platform to function—e.g., session-security tokens, load-balancing, and the cookie that records your cookie-banner choice. These deploy automatically and do not require consent.

Functional Cookies

Remember preferences and improve usability. Deploy only after you accept, or affirmatively enable, non-essential cookies.

Analytics Cookies

Including Google Analytics, used to understand aggregate usage of the Platform. Learn about Google's practices at https://policies.google.com/technologies/partner-sites and opt out via https://tools.google.com/dlpage/gaoptout. Deploy only after consent.

Advertising / Targeting Cookies

Including pixel tags used to measure marketing-campaign performance and enable retargeting (which may include tags from advertising platforms where deployed—see the current list at [cookie preference center / cookie table URL]). Use of these Cookies, and any corresponding exchange of information with the advertising partner, constitutes “selling” or “sharing” under California law. These deploy only after consent, and are disabled if you decline or opt out.

6.1 Opt-Out Preference Signals (Global Privacy Control)

We honor opt-out preference signals, such as the Global Privacy Control (“GPC”), as a valid request to opt out of the sale/sharing of personal information for the browser or device that sent the signal. We do not charge a fee, degrade your experience, or require additional information beyond what is necessary to process the signal, and we do not treat the absence of a signal as consent to sell or share.

6.2 Managing Cookies Through Your Browser

Most browsers let you block or delete Cookies independent of any preference you set with us. Because browser controls operate at the device level and are not a substitute for the choices in Section 6 and Section 9, we do not treat browser cookie settings alone (other than a recognized opt-out preference signal) as a request to opt out of sale/sharing.

7. How We Use Personal Information

We use personal information for the following purposes, each tied to a business or commercial purpose and, where applicable, a legal basis as noted:

  • Providing and administering the Services (contractual necessity/performance of a contract);
  • Customer support and troubleshooting (contractual necessity; legitimate interests);
  • Marketing communications about products, features, and events, with an unsubscribe option in every message (consent, where required; otherwise legitimate interests, subject to your right to object);
  • Analytics and product improvement (legitimate interests, subject to the cookie consent described in Section 6 for cookie-based analytics);
  • Fraud prevention, security, and enforcement of our agreements (legitimate interests; legal obligation);
  • Aggregation/de-identification for internal reporting. We may aggregate or de-identify personal information; once information no longer identifies or is reasonably linkable to you, we maintain and use it consistent with all relevant law and do not attempt to re-identify it except to test our de-identification methods.

We do not use personal information for materially different, unrelated, or incompatible purposes without providing notice consistent with applicable law. Where an automated decision-making technology is used to make a decision that produces a legal or similarly significant effect concerning you, we will provide the pre-use notice, opt-out, and access rights required by relevant law; as of the date of this Policy, we do not use automated decision-making technology in that manner.

8. How We Share Personal Information

We disclose personal information as follows:

  • Service providers and contractors (e.g., hosting, email-delivery, and support-ticketing vendors), under written contracts that prohibit the recipient from selling or sharing the information, using it outside the specific business purpose for which it was disclosed, or combining it with information from other sources.
  • Advertising and market-research partners, for cross-context behavioral advertising. This is a may constitute a share as defined by California law. See Section 6 for the associated cookies, and Sections 6.1 and 9 for how to opt out.
  • Salesforce and joint-offering partners, where you purchase Services in conjunction with such a partner, limited to the information necessary for that joint offering.
  • Corporate transactions, such as a merger, acquisition, financing, or sale of assets, subject to the transferee's assumption of obligations consistent with this Policy or applicable law.
  • Legal process and safety, where we are required to respond to a subpoena, court order, or other legal process, or where disclosure is reasonably necessary to protect the rights, property, or safety of Cloudbyz, our users, or the public.
  • With your consent, for any other disclosure not described above.

As stated in Section 2, we do not knowingly sell or share the personal information of consumers we know to be under 18 years of age. If we learn that we have collected personal information from a consumer under 18, we will delete it.

9. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights with respect to your personal information, subject to certain exceptions provided by law:

  • Right to Know/Access: the categories and specific pieces of personal information we have collected, the categories of sources, the business/commercial purpose for collecting it, and the categories of third parties to whom we have disclosed, sold, or shared it.
  • Right to Delete: deletion of personal information we have collected from you, subject to certain statutory exceptions (for example, to complete a transaction, detect security incidents, debug, exercise free speech, comply with a legal obligation, or make other internal and lawful uses compatible with the context in which you provided the information). We do not invoke exceptions beyond this statutory list—in particular, we do not decline a deletion request merely because it would require disproportionate technical effort.
  • Right to Correct: correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: you may opt out at any time by (i) clicking the “Do Not Sell or Share My Personal Information” link in the footer of www.cloudbyz.com, (ii) setting your preferences in our cookie preference center (Section 6), (iii) transmitting a recognized opt-out preference signal such as GPC (Section 6.1), or (iv) emailing privacy@cloudbyz.com with “Do Not Sell or Share” in the subject line. We do not require you to create an account or verify your identity in order to submit an opt-out request, and we will act on your request no later than 15 business days after we receive it.
  • Right to Limit Use and Disclosure of Sensitive Personal Information: as described in Section 5, we do not use Sensitive Personal Information beyond the purposes exempted from this right.
  • Right to Non-Discrimination: we will not deny goods or services, charge different prices, or provide a different level of service because you exercised a right under this section.
  • Right to Data Portability: receipt of a copy of your personal information in a portable format, to the extent required by law.
  • Right to Designate an Authorized Agent to submit a request on your behalf.
9.1 How to Exercise Your Rights

You may submit a Request to Know, Delete, or Correct by writing to us at the address in Section 17 or by emailing privacy@cloudbyz.com with the subject line “CCPA Request” and the specific right you wish to exercise. We will verify your identity using information already associated with your account (or, for non-account holders, by matching the information provided in your request to information we hold) before acting on it. An authorized agent may submit a request on your behalf with proof of your written authorization or power of attorney; we may still require you to verify your own identity directly with us.

9.2 Response Timing

We will confirm receipt of a verifiable request within 10 business days and substantively respond within 45 calendar days of receipt. If needed, we may extend the response period by an additional 45 days (90 days total), and will notify you of the extension and the reason for it within the initial 45-day period.

9.3 Shine the Light (Cal. Civ. Code § 1798.83)

Separately from the CCPA/CPRA rights above, California Civil Code § 1798.83 lets California residents request certain information about disclosures of personal information to third parties for those third parties' direct marketing purposes in the preceding calendar year. To make such a request, email privacy@cloudbyz.com with “Shine the Light Request” in the subject line. Not all information sharing is covered by this statute; only covered sharing will be included in our response.

10. European Economic Area, United Kingdom, and Swiss Privacy Rights (GDPR / UK GDPR)

If you are located in the European Economic Area (“EEA”), United Kingdom, or Switzerland, the following applies in addition to the sections above. For purposes of the EU General Data Protection Regulation and the UK GDPR (together, “GDPR”), Cloudbyz, Inc., together with any Cloudbyz subsidiary entity that independently determines the purposes and means of processing your personal data, is the controller of personal information described in this Policy.

10.1 Legal Bases for Processing
  • Contract: to provide the Services or Platform features you request.
  • Consent: for non-essential cookies (Section 6) and marketing communications where consent is the applicable basis under local law; you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legitimate interests: for analytics, security, and business-to-business marketing, balanced against your interests and rights (you may object at any time — see Section 10.2).
  • Legal obligation: where processing is necessary to comply with law.
10.2 Your Rights

Subject to applicable conditions and exemptions, you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict processing; receive your data in a portable format; object to processing based on legitimate interests or for direct marketing; and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not currently make such decisions about you, see Section 7). You also have the right to withdraw consent at any time where processing is based on consent (Section 10.1) and the right to lodge a complaint with a supervisory authority (Section 10.4). To exercise these rights, email privacy@cloudbyz.com or use the request methods described in Section 9.1. We will respond within one month of receipt; where a request is complex or numerous, we may extend that period by up to two further months and will inform you of the extension and the reasons for it within the first month.

10.3 International Transfers

Personal information may be transferred to, and processed in, the United States and other countries that may not have data protection laws equivalent to those of your home jurisdiction. Where we transfer personal information out of the EEA, UK, or Switzerland to a country not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum) as the transfer mechanism. You may request a copy by emailing privacy@cloudbyz.com.

10.4 Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at https://www.edpb.europa.eu/about-edpb/our-members_en; UK residents may contact the Information Commissioner's Office (ico.org.uk).

11. Other U.S. State Privacy Rights

If you reside in Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or another state with a comprehensive consumer privacy law, you may have rights similar to those described in Section 9 (access, deletion, correction, portability, and opt-out of targeted advertising, sale, or certain profiling), including, in some states, the right to appeal a denial of your request. To appeal, reply to our written response or email privacy@cloudbyz.com with “Privacy Request Appeal” in the subject line. We will respond in writing within the period required by your state's law and, where that law requires it, will tell you how to contact your state attorney general if the appeal is denied. To exercise these rights, email privacy@cloudbyz.com identifying your state of residence and the right you wish to exercise; we will apply the process and timelines required under the law of your state.

12. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including network firewalls, encryption of sensitive data in transit (TLS), and internal access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Sensitive information. We ask that you not send Social Security numbers, government identification numbers, or other Sensitive Personal Information described in Section 5 through unsecured channels such as email.

13. Steps You Can Take to Protect Your Information

  • Use only secure (“https”) pages when submitting personal information.
  • Use strong, unique passwords.
  • Never respond to unsolicited requests for your Social Security number or financial information.
  • Do not share your account credentials with others, and sign off shared devices when finished.
  • Exercise caution before posting personal information in public forums, chat, or social media, which may be collected and used by others.

Other websites linked from the Platform, and third-party advertising displayed on the Platform, are governed by those parties' own privacy practices; we encourage you to review them. We are not responsible for the privacy practices of third parties, including Salesforce, Google, LinkedIn, Apple, Microsoft, or any other platform provider.

14. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, and in any event no longer than permitted by law. The criteria used to determine retention periods for each category are set out in the table at Section 4, and generally include: the duration of your relationship with us; whether we are subject to a legal obligation to retain the information (e.g., tax or transaction recordkeeping); and whether retention is reasonably necessary in light of our legal position (e.g., statutes of limitation, litigation holds, or regulatory inquiries).

15. Changes to This Policy

We may update this Policy from time to time. If we make changes that we consider material, we will notify you by posting the updated Policy with a new “Last Updated” date and, where required by law, by additional notice (such as an email to the address associated with your account) before the change takes effect. Your continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the update, to the extent permitted by applicable law.

16. Miscellaneous

Claims period. Any claim or cause of action arising out of or related to your use of the Platform must be filed within one (1) year after the claim or cause of action arose, except to the extent a shorter period is barred, or a longer period is required, by applicable law, including, without limitation, any statute of limitations applicable to claims under the CCPA/CPRA, GDPR, or other data protection law that cannot be shortened by private agreement. This clause does not limit any non-waivable statutory right.

Dispute resolution. Any dispute relating to this Policy, including a dispute arising from our collection or use of information through the Platform in any form, whether or not the dispute also involves your use of the Site as defined in our Website Terms of Use, is subject to the binding arbitration, class-action-waiver, and jury-trial-waiver provisions of Section 9 of the Cloudbyz Website Terms of Use, which are incorporated into this Policy by reference for that purpose. By providing personal information to us or otherwise interacting with the Platform, you agree to those provisions.

Severability. If a provision of this Policy is found unenforceable, that provision will be severed and the remaining provisions will continue in effect.

No waiver. Our failure to enforce a provision is not a waiver of our right to do so later.

17. How to Contact Us

Questions about this Policy or our privacy practices may be directed to: privacy@cloudbyz.com.

Cloudbyz, Inc.
4320 Winfield Road, Suite 200
Warrenville, IL 60555, USA

Because email is not a fully secure channel, please do not include payment-card numbers or other Sensitive Personal Information in messages to us.

Still can't find what are you looking for?

We are always happy to help with any questions