Privacy Policy
01Information We Collect
We collect information from Clients and site visitors through the following means:
- Contact and identity information — name, email address, phone number, company name, and business type submitted through the contact form, scheduling tools, or Statements of Work.
- Account credentials — email address and authentication tokens generated for access to the Ergon Labs client dashboard. We do not store passwords in plaintext.
- Business and engagement data — information shared during an engagement including process documentation, workflow configurations, third-party account credentials required for integrations, and deliverables exchanged.
- Communications — emails, messages, notes, and support requests exchanged with Ergon Labs during or after an engagement.
- Usage data — pages visited on the client dashboard, features accessed, request timestamps, and error events captured by our monitoring infrastructure.
- Payment information — billing address and payment method details processed by Stripe. Ergon Labs does not store credit card numbers or full bank account details on its own infrastructure.
- Scheduling data — appointment details collected when booking a discovery or project call through Cal.com.
We do not collect Protected Health Information (“PHI”) as defined under HIPAA, and our infrastructure is not designed to store it. Engagements involving healthcare clients are scoped to keep PHI within Client-controlled systems.
02How We Use Your Information
We use the information we collect for the following purposes:
- Delivering services — building, configuring, testing, and maintaining automation workflows described in a Statement of Work.
- Account management — creating and maintaining dashboard access, sending magic-link invitations, and managing team members within a Client account.
- Billing and invoicing — generating invoices, processing payments through Stripe, and maintaining financial records required by law.
- Communications — sending project updates, invoices, system notifications, retainer reports, and responses to support requests via Resend.
- Support — triaging and resolving requests submitted through the client dashboard.
- Security and operations — authenticating users, detecting fraud, monitoring for errors (via Sentry), and maintaining the reliability of the platform.
- Legal compliance and record-keeping — maintaining business records as required by New York law and applicable regulations, typically for seven (7) years following final invoice.
We do not use Client data to train AI models, sell advertising, or for any purpose beyond performing services under these Terms.
03Sharing and Disclosure
We do not sell, rent, or broker Client data to any third party. We share information only in the following circumstances:
Service providers (data processors). We share data with third-party vendors solely as necessary to provide our services — including infrastructure hosting, payment processing, transactional email, error monitoring, appointment scheduling, electronic signatures, and AI model inference. These vendors are contractually prohibited from using Client data for any purpose other than performing services on our behalf.
Legal disclosure. We may disclose information if required by law, subpoena, court order, or to protect the rights, property, or safety of Ergon Labs, its Clients, or others. Where legally permitted, we will provide prior notice before complying.
Business transfer. In the event of a merger, acquisition, or sale of substantially all of Ergon Labs' assets, Client data may be transferred to the successor entity. We will provide notice to affected Clients before their data is subject to a different privacy policy.
04Cookies and Tracking
Client dashboard. We use httpOnly, Secure, SameSite=Lax session cookies to authenticate users on the client dashboard. These cookies are essential to operate the service and cannot be disabled while using the dashboard.
Marketing website. We do not use third-party advertising cookies or cross-site tracking tools on our marketing website (ergonlabs.co). We collect basic server-side request logs (IP address, user agent, page path, timestamp) for security and operational purposes. These logs are retained for 90 days.
Do Not Track. We honor Do Not Track signals from browsers on the marketing website and do not engage in cross-site behavioral tracking.
05Data Retention
We retain personal and business data for the following periods:
- Active Client accounts — retained for the duration of the engagement and for seven (7) years after the final invoice, as required for New York business records.
- Inactive accounts — accounts with no associated active engagement will be scheduled for deletion after two (2) years of inactivity. We will provide thirty (30) days advance notice before deletion.
- Server logs — operational request logs retained for 90 days.
- Payment records — billing and transaction records retained for seven (7) years per New York tax and business record requirements.
Clients may request earlier deletion of account data. Requests are subject to our legal record-keeping obligations, which may require us to retain certain records regardless of Client preference.
06Your Rights
Clients and site visitors have the following rights with respect to their information:
- Access — request a copy of the personal and business information we hold about you or your organization.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion of your account and associated data, subject to legal retention requirements.
- Portability — receive your business data in a structured, machine-readable format (e.g., JSON or CSV).
- Objection — object to processing of your information for specific purposes.
To exercise any of these rights, submit a written request to hello@ergonlabs.co identifying yourself and specifying your request. We will respond within thirty (30) days. We may need to verify your identity before processing requests.
07Data Security
We implement administrative, technical, and organizational safeguards appropriate to the sensitivity of the information we handle:
- Encryption in transit — all web traffic between Clients and our platform is encrypted via TLS.
- Encryption at rest — data stored in Supabase is encrypted at rest by the infrastructure provider.
- Row-level security — each Client organization can only read and write their own data; access across organizations is enforced at the database layer.
- Authentication tokens — session tokens are stored in httpOnly cookies and are never accessible to browser-side JavaScript.
- Access controls — dashboard access is limited to authenticated users with a verified role (client or admin); all API endpoints enforce authentication at both the application and database layers.
- Error monitoring — Sentry captures application errors and is configured to redact personally identifiable information from error reports.
No method of transmission or storage is 100% secure. In the event of a data breach that materially affects Client information, we will notify affected Clients within seventy-two (72) hours of discovery where technically feasible, and will cooperate with any required regulatory notification.
08Third-Party Services
Our automation workflows are designed to integrate with platforms and tools selected by or for the Client (e.g., email platforms, CRM systems, calendar providers, payment processors, and AI services). Data processed by those platforms is governed by their own privacy policies and terms of service.
Ergon Labs will identify third-party integrations in the Statement of Work and will not connect Client systems to additional platforms without written authorization. Clients are responsible for reviewing and accepting the terms of third-party platforms used in their workflows.
Our marketing website contains a Cal.com scheduling embed and may link to third-party sites. We are not responsible for the privacy practices of those services.
09Children's Privacy
Our services are designed for and directed exclusively to business professionals and organizations. We do not knowingly collect personal information from individuals under the age of eighteen (18). If we become aware that we have inadvertently collected information from a minor, we will promptly delete it. If you believe we have collected information from a minor, please contact us at hello@ergonlabs.co.
10Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, services, or applicable law. For material changes, we will provide at least thirty (30) days advance notice via email to Clients before the updated Policy takes effect.
Non-material clarifications or formatting changes may take effect immediately and will be reflected in the “Last updated” date at the top of this page. Continued use of our services after the effective date of a material change constitutes acceptance of the updated Policy.
11Contact
Questions, data access requests, or concerns about this Privacy Policy should be directed to Ergon Labs LLC at the contact below.