Snapshot 44975
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Legal
Privacy Policy
Last updated: September 2025
Overview
Morphed Pty Limited ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered strategic co-pilot platform designed for teams using HubSpot.
We comply with South Africa's Protection of Personal Information Act, 2013 (POPIA), the European Union's General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) to ensure the highest standards of data protection.
Information We Collect
What We Store
OAuth Tokens: Encrypted HubSpot access/refresh tokens for API access
Portal IDs: HubSpot portal identifiers for tenant isolation
Audit Logs: Request metadata with hashed payloads (no personally identifiable information)
Team Content: Methodologies, frameworks, and templates you upload
Usage Analytics: Platform interaction data for service improvement
What We Don't Store
User names, emails, or personal information beyond what's necessary for service delivery
HubSpot CRM data beyond necessary identifiers and metadata
Detailed webhook payloads (only hashed for deduplication)
Session data beyond OAuth state management
How We Use Your Information
Legal Basis for Processing (POPIA/GDPR): We process your personal information based on:
Consent: You have given clear consent for us to process your data for specific purposes
Contractual Necessity: Processing is necessary to fulfill our service agreement with you
Legitimate Interests: For platform improvement and security, balanced against your rights
Legal Obligation: To comply with applicable laws and regulations
Specific Uses:
Service Delivery: To provide AI-powered strategic insights and team enablement within the HubSpot ecosystem
Platform Improvement: To analyze usage patterns and improve our services
Security: To detect and prevent unauthorized access or abuse
Compliance: To meet legal and regulatory requirements under POPIA, GDPR, and CCPA
Data Protection & Security
Encryption
• TLS 1.3 for all data in transit
• AES-256-GCM for token encryption
• PostgreSQL encryption at rest
• Quarterly key rotation
Access Control
• Multi-tenant isolation
• Role-based access controls
• Audit logging for all access
• Least privilege principles
Data Retention
Audit Logs: 90 days (automatic purging)
OAuth Tokens: Until revoked or expired
Team Content: Until account deletion requested
Usage Analytics: 2 years for service improvement
Third-Party Services
AI Processing: OpenAI (US region) for strategic analysis and recommendations
Vector Database: Pinecone (US region) for content search and matching
Hosting: Render.com (global) for platform infrastructure
CRM Integration: HubSpot APIs for data access and synchronization
Your Rights
POPIA Rights (SA Users)
• Right to access your personal information
• Right to correction of inaccurate data
• Right to deletion (right to be forgotten)
• Right to object to processing
• Right to data portability
• Right to lodge a complaint with the Information Regulator
GDPR Rights (EU Users)
• Right to access your data
• Right to rectification
• Right to erasure
• Right to data portability
• Right to object
• Right to restrict processing
CCPA Rights (CA Users)
• Right to know what data we collect
• Right to delete personal information
• Right to opt-out of sale (we don't sell data)
• Right to non-discrimination
Exercising Your Rights: To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by law.
Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: [email protected]
Subject: Privacy Policy Inquiry
We will respond to your request within 30 days as required by applicable law.
This Privacy Policy may be updated from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.