Exordia Cloud
Why ExordiaPricingBlog

Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your information.

Effective Date: February 17, 2026

Last Updated: February 18, 2026

Quick Navigation

Information We CollectLegal Basis for ProcessingHow We Use Your InformationAI and Automated ProcessingData SharingData LocationData RetentionYour RightsInformation for EEA/UK Residents

1. Introduction and Data Practices

This Privacy Policy describes how Exordia Cloud LLC ("Exordia," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our B2B SaaS platform for consulting discovery workshops (the "Service").

This policy is provided in accordance with the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), the Colorado Privacy Act ("CPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Connecticut Data Privacy Act ("CTDPA"), and other applicable US state privacy laws (collectively, "US Privacy Laws").

Data Practices Contact

Exordia Cloud LLC
Email: admin@exordiacloud.com

2. Information We Collect

We collect information that you provide directly to us, information collected automatically when you use the Service, and information from third-party sources. The categories of personal information we have collected in the preceding 12 months include:

2.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Profile information (optional, such as profile picture)
  • Organization name and role
  • Authentication credentials (managed securely via OAuth providers)

2.2 Authentication Providers and Google API Services Disclosure

Exordia Cloud authenticates users through supported identity providers, including Google OAuth and Microsoft Entra ID. We access identity-provider profile information (such as name, email address, and profile image) solely for account creation and authentication purposes.

Google API Limited Use Disclosure

Exordia Cloud's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, sell it to third parties, or use it to determine creditworthiness.

2.3 Business Content (Customer Data)

When you use the Service, you may submit:

  • Workshop notes and session content
  • Discovery templates and questions
  • Requirements and user stories
  • Project and client information
  • Stakeholder details and contact information

Note: This content may contain personal data of third parties (e.g., your clients' stakeholders). You are responsible for ensuring you have appropriate consent or legal basis to share such information.

When business customers submit Customer Data through the Service, Exordia generally processes that Customer Data as a processor or service provider on behalf of the customer organization (the controller or business). If you are a data subject included in a customer's data, privacy requests relating to that data may need to be directed to the relevant customer organization first.

2.4 Usage and Analytics Data

We automatically collect:

  • Log data (IP addresses, browser type, device information, pages visited)
  • Usage patterns and feature interactions
  • Performance metrics and error reports
  • Session duration and navigation paths

2.5 AI Processing Data

When you use AI features, we process:

  • Input content you submit for AI processing
  • AI-generated outputs
  • Usage metrics (tokens consumed, operations performed)

2.6 Payment Information

When you subscribe to a paid plan, payment is processed by our third-party payment processor, Stripe. We collect:

  • Stripe customer and subscription identifiers
  • Subscription status, plan type, and billing period
  • Seat allocation and AI credit usage

We do not store credit card numbers, bank account details, or other sensitive payment credentials. All payment data is handled directly by Stripe in accordance with Stripe's Privacy Policy.

2.7 Communications

We collect information when you:

  • Contact our support team
  • Submit feedback through the Service
  • Respond to surveys or communications

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

Contractual Necessity

To provide and maintain the Service, process your transactions, and fulfill our contractual obligations to you.

Examples: Account management, service delivery, customer support

Legitimate Business Interests

For our legitimate business interests, provided these do not override your fundamental rights.

Examples: Product improvement, security monitoring, fraud prevention, analytics

Legal Obligations

To comply with applicable laws, regulations, and legal processes.

Examples: Tax compliance, responding to lawful requests, audit requirements

Consent

Where you have given specific consent for particular processing activities. AI-assisted content generation requires explicit opt-in consent and is blocked without it. Other consent preferences (analytics, marketing communications, and third-party sharing) are recorded for compliance and applied as described in this Policy and product settings; some processing necessary to provide, secure, and operate the Service may continue regardless of those preferences.

Examples: AI content generation (required opt-in), marketing communications, optional analytics

4. How We Use Your Information

We use the information we collect to:

4.1 Provide and Improve the Service

  • Create and manage your account
  • Deliver the features and functionality you request
  • Process your workshop content through AI features
  • Provide customer support and respond to inquiries
  • Maintain and improve the Service's performance and security
  • Develop new features and services

4.2 Communications

  • Send service-related notifications (e.g., security alerts, updates)
  • Respond to your requests, comments, and questions
  • Send administrative information about your account

4.3 Analytics and Research

  • Analyze usage patterns to improve user experience
  • Generate aggregated, anonymized insights
  • Conduct research to enhance our products

4.4 Security and Compliance

  • Detect, prevent, and address technical issues
  • Protect against fraud, abuse, and security threats
  • Enforce our Terms of Service and policies
  • Comply with legal obligations

5. AI and Automated Decision-Making

The Service uses artificial intelligence and automated processing to enhance your experience. In accordance with applicable privacy laws, we provide the following disclosures:

5.1 AI Features We Use

Our AI features include:

  • Note Mapping: Automatically linking workshop notes to template questions
  • Requirements Generation: Creating user stories from workshop content
  • Template Enhancement: Suggesting improvements to discovery templates
  • Gap Analysis: Identifying missing coverage areas

5.2 Third-Party AI Providers

We use the following AI service providers:

Anthropic (Claude)

Purpose: Natural language processing for requirements generation and content analysis

Data Processed: Text content from workshops submitted by users

Location: United States

Google Cloud Vertex AI

Purpose: Machine learning models for content processing and analysis

Data Processed: Text content from workshops submitted by users

Location: United States

AI processing is currently performed in United States regions. EU data residency for AI processing is not currently available.

5.3 AI Data Handling

Important Notice

  • Your data is not used by Exordia to train AI models. Our AI service providers process your data under enterprise agreements that restrict use for model training or improvement.
  • For details on AI provider data handling terms, contact admin@exordiacloud.com.
  • AI outputs are suggestions only and require human review.
  • You may opt out of AI features and use the Service manually.

5.4 Your Rights Regarding Automated Processing

Under applicable privacy laws, you have the right to:

  • Request information about the logic involved in automated decisions
  • Object to automated processing in certain circumstances
  • Request human review of automated decisions
  • Opt out of AI features entirely

6. Data Sharing and Third-Party Recipients

We share your information only as described in this policy. We do not sell your personal information to third parties.

6.1 Service Providers (Subprocessors)

We engage third-party service providers to perform functions on our behalf. These providers have access to personal information only to perform their functions and are obligated to maintain confidentiality.

ProviderPurposeLocation
Google Cloud PlatformInfrastructure, hosting, databaseUnited States
AnthropicAI processing (Claude)United States
Google Vertex AIAI processingUnited States
Google OAuthAuthenticationGlobal
Microsoft Entra IDAuthenticationGlobal
StripePayment processingUnited States
PostmarkTransactional email deliveryUnited States
Upstash RedisRate limiting and application cachingUnited States

6.2 Organization Members

If you use the Service as part of an Organization, other members of your Organization (particularly administrators) may access certain information about your account and activities.

6.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal process (e.g., subpoenas, court orders)
  • Government requests that meet applicable legal requirements
  • Protection of our rights, privacy, safety, or property
  • Emergency situations involving potential threats to persons

6.4 Business Transfers

If Exordia is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your personal information.

7. Data Location

Core application data is stored and processed in the United States. Our primary infrastructure and databases are hosted in US data centers.

7.1 Your Acknowledgment

By using the Service, you acknowledge that your information will be stored and processed in the United States. Some authentication-related processing by third-party identity providers may occur globally, subject to those providers' own infrastructure and policies.

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Data TypeRetention PeriodBasis
Account informationDuration of account; deleted upon eligible request, subject to platform integrity constraintsService provision
Workshop contentDuration of account; deleted upon eligible request, subject to platform integrity constraintsService provision
Usage logsAutomatically purged (default 90 days, configurable per deployment)Security, debugging
AI usage recordsAutomatically purged (default 12 months, configurable per deployment)Billing, compliance
Audit logsAutomatically purged (default 90 days, configurable per deployment); may be archived per legal requirementsSecurity, legal compliance
Backup dataUp to 30 days after source deletionDisaster recovery

Upon account deletion request, we will delete or anonymize your personal information within a commercially reasonable timeframe (typically within 30 days), subject to eligibility requirements (e.g., sole organization administrators must first transfer administrative rights), legal obligations, and platform integrity constraints. Automated log cleanup runs on a scheduled basis for usage logs, AI usage records, and audit logs.

9. Information for EEA/UK Residents

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), the General Data Protection Regulation (GDPR) and UK GDPR apply to our processing of your personal data. This section provides additional information required under Articles 13 and 14.

9.1 Lawful Basis for Processing

Performance of Contract (Art. 6(1)(b))

Processing necessary to provide the Service you have subscribed to.

Examples: Account creation, workshop functionality, AI processing of your content, customer support

Legitimate Interests (Art. 6(1)(f))

Processing necessary for our legitimate business interests, balanced against your rights.

Examples: Product improvement, security monitoring, fraud prevention, aggregated analytics

Legal Obligation (Art. 6(1)(c))

Processing necessary to comply with applicable laws and regulations.

Examples: Tax compliance, responding to lawful requests, audit log retention

Consent (Art. 6(1)(a))

Where you have given explicit consent for specific processing activities. You may withdraw consent at any time.

Examples: Marketing communications, optional analytics, feedback surveys

9.2 Data Protection Contact

For GDPR-related inquiries, you may contact our data protection point of contact:

Data Protection Contact
Exordia Cloud LLC
Email: admin@exordiacloud.com

9.3 Your GDPR Rights

In addition to the rights listed in Section 10, EEA/UK residents have the right to:

Right of Access

Art. 15

Obtain confirmation of whether we process your data and receive a copy of it.

Right to Rectification

Art. 16

Have inaccurate personal data corrected and incomplete data completed.

Right to Erasure

Art. 17

Request deletion of your personal data, subject to legal retention obligations.

Right to Restriction

Art. 18

Request restriction of processing in certain circumstances.

Right to Data Portability

Art. 20

Receive your data in a structured, machine-readable format.

Right to Object

Art. 21

Object to processing based on legitimate interests or for direct marketing.

9.4 Supervisory Authority

You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. A list of EU Data Protection Authorities can be found on the European Data Protection Board website.

9.5 International Data Transfers

Your personal data may be transferred to and processed in the United States. For transfers of personal data from the EEA/UK to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the data processing terms of our infrastructure and AI service providers.

Enterprise customers requiring dedicated data processing terms may review and request execution of our Data Processing Addendum (DPA), which includes Standard Contractual Clauses and UK transfer terms. Contact us at the address above to initiate a DPA.

9.6 Automated Decision-Making

In accordance with GDPR Article 22, we inform you that the Service uses AI-assisted processing to generate requirements and map workshop notes. These outputs are recommendations only and are not used to make decisions that produce legal effects or similarly significantly affect you. All AI outputs require human review before use. You may opt out of AI features at any time.

9.7 Data Retention and Lawful Basis

We retain personal data only for as long as necessary for the purposes set out in this policy and as required by applicable law. When the lawful basis for processing is consent, we will delete or anonymize the data promptly upon withdrawal of consent, unless another lawful basis applies. See Section 8 for specific retention periods.

10. Your Rights

You have the following rights regarding your personal information:

10.1 Your Privacy Rights

Right to Know

Request disclosure of personal information collected, used, disclosed, or sold.

Right to Delete

Request deletion of personal information, subject to certain exceptions.

Right to Correct

Request correction of inaccurate personal information.

Right to Opt-Out

Opt out of the sale or sharing of personal information. Note: We do not sell personal information.

Right to Non-Discrimination

Not be discriminated against for exercising your privacy rights.

Right to Limit Use of Sensitive Personal Information

Limit use and disclosure of sensitive personal information.

Sensitive Personal Information Disclosure

The Service collects account credentials (via OAuth — we do not store passwords) and email addresses. We do not collect or process other categories of sensitive personal information as defined under the CPRA (e.g., Social Security numbers, financial account details, precise geolocation, racial/ethnic origin, biometric data, health information, or contents of private communications). Any sensitive personal information incidentally present in user-submitted workshop content is processed solely for purposes of providing the Service and is not used for profiling, advertising, or purposes beyond those permitted under Cal. Civ. Code § 1798.121.

California "Shine the Light" Law: California residents may request information regarding disclosure of personal information to third parties for direct marketing purposes.

10.2 Exercising Your Rights

To exercise any of these rights, please:

  • Email us at admin@exordiacloud.com
  • Use the account settings within the Service (for data export and deletion). Note: system administrators should contact us directly via email for privacy-related requests.

We will respond to your request within 45 days. We may need to verify your identity before processing your request. If we require additional time, we will notify you of the extension and the reason within the initial 45-day period. For access and data portability requests specifically, you may make up to two requests per 12-month period. Deletion, correction, and opt-out requests are not subject to this limit.

Operational note: At present, withdrawal of AI processing consent immediately disables AI features. Other preference withdrawals are honored where applicable to optional processing activities and communications, but do not disable processing that is strictly necessary for service delivery, security, legal compliance, or core business operations.

10.3 Authorized Agent Requests

You may designate an authorized agent to submit privacy requests on your behalf. To do so, you must provide the agent with written permission signed by you and submit proof of the authorization when making the request. We may still require you to verify your own identity directly with us. Authorized agent requests should be sent to admin@exordiacloud.com with the subject line "Authorized Agent Request."

10.4 Appeal Process

If we decline to take action on a privacy request, you may appeal that decision by emailing admin@exordiacloud.com with the subject line "Privacy Appeal." We will respond to appeals within 60 days. If we deny your appeal, we will provide information on how to contact the relevant state attorney general if you wish to submit a complaint.

10.5 Categories Disclosed for Business Purposes

In the preceding 12 months, we have disclosed the following categories of personal information for business purposes (e.g., to service providers and sub-processors):

CategoryDisclosed ToPurpose
Identifiers (name, email)Auth providers, email providerAuthentication, transactional email
Commercial information (subscription data)Payment processor (Stripe)Billing and subscription management
Internet activity (usage logs)Infrastructure provider (GCP)Service delivery, security monitoring
Professional information (workshop content)AI providers (Google Vertex AI, Anthropic)AI-assisted content processing

We have not sold or shared (as defined by CPRA) personal information in the preceding 12 months. We do not sell personal information or share it for cross-context behavioral advertising.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

Encryption

Data encrypted in transit (TLS 1.3) and at rest (AES-256)

Access Controls

Role-based access control and principle of least privilege

Infrastructure

Hosted on Google Cloud Platform with enterprise-grade security controls

Monitoring

Continuous security monitoring and incident response

While we strive to protect your information, no method of transmission over the Internet or electronic storage is completely secure. For more information, please visit our Trust & Security page.

11.1 Authorized Personnel Access

Authorized Exordia personnel may access your data as necessary to provide the Service, investigate support requests, and ensure platform security. Such access is logged, time-limited, and subject to confidentiality obligations.

11.2 Data Breach Notification

If we determine that an unauthorized breach of security has resulted in unauthorized access to your personal data, we will notify you without unreasonable delay and within 72 hours of determination where feasible. Notification will describe the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach. We will also notify relevant supervisory authorities as required by applicable law.

12. Cookies and Tracking Technologies

We use only strictly necessary cookies for authentication and security. We do not use advertising, marketing, or third-party tracking cookies. For full details, see our Cookie Policy.

12.1 Cookies We Use

Our essential authentication cookies include:

  • __Host-authjs.session-token (production) / authjs.session-token (development) — Maintains your authenticated session (7-day duration, Secure, HttpOnly)
  • __Host-authjs.callback-url (production) / authjs.callback-url (development) — Stores the redirect URL during OAuth sign-in (session duration, Secure, HttpOnly)
  • __Host-authjs.csrf-token (production) / authjs.csrf-token (development) — Protects against cross-site request forgery (session duration, Secure, HttpOnly)

12.2 Managing Cookies

You can control cookies through your browser settings. Blocking essential cookies will prevent you from logging in. See our Cookie Policy for details.

12.3 Do Not Track and Global Privacy Control

Since we do not use tracking or advertising cookies, Do Not Track (DNT) browser signals do not change your experience on our platform. We recognize Global Privacy Control (GPC) browser signals as a valid expression of your privacy preferences. Because we do not sell personal information or share it for cross-context behavioral advertising, the activities that GPC is designed to restrict do not occur on our platform. For additional privacy rights requests, see Section 10.

13. Children's Privacy

The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at admin@exordiacloud.com, and we will take steps to delete such information.

14. Regulated Data Categories

The Service is not designed for use with data regulated under HIPAA, FERPA, GLBA, or similar sector-specific regulations unless a separate written agreement is in place. If you believe your use case involves regulated data categories, please contact us at admin@exordiacloud.com before submitting such data.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. If we make material changes, we will:

  • Post the updated policy on this page with a new "Last Updated" date
  • Notify you via email or through the Service at least 30 days before changes take effect
  • Obtain your consent where required by law

We encourage you to review this Privacy Policy periodically for any changes.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Exordia Cloud LLC

Privacy Inquiries: admin@exordiacloud.com

General Support: admin@exordiacloud.com

We will respond to your inquiry within a reasonable timeframe and in accordance with applicable law.

← Back to Home
Terms of ServiceCookie PolicyTrust & Security
Exordia Cloud

The discovery workshop platform for requirements professionals.

Product

  • Why Exordia
  • Pricing
  • Use Cases
  • Blog

Features

  • Discovery Templates
  • AI Requirements
  • Collaboration
  • Exports

Company

  • Contact
  • Trust & Security
  • Privacy
  • Terms
  • Cookie Policy
  • Accessibility
  • Do Not Sell My Information
© 2026 Exordia Cloud LLC. All rights reserved.